{"schemaVersion":"1.0","name":"CopyCat IT Knowledge Base","description":"Searchable IT troubleshooting articles, error codes, diagnostic commands, and technician guidance.","canonicalUrl":"https://copycat.tech","generatedAt":"2026-09-15T16:24:40.290Z","articleCount":7412,"indexEntryCount":199,"usage":{"searchFields":["title","errorCode","eventId","product","category","tags","keywords","summary"],"articleUrlTemplate":"https://copycat.tech/#article-{id}","safetyNotice":"Verify critical, security, licensing, firmware, and product-specific changes against current official vendor guidance before applying them."},"articles":[{"id":1,"title":"Outlook Copy/Paste Formatting Issue","category":"Outlook","product":"Microsoft Outlook","tags":["Formatting","Clipboard","Email"],"keywords":["outlook","copy paste","font","rich text","html","plain text"],"errorCode":"","eventId":"","severity":"Low","summary":"Pasted content in Outlook uses unexpected fonts, colors, spacing, or layout. The issue usually appears when formatting from the source application conflicts with the message format or Outlook paste settings.","rootCause":"The copied content includes rich-text or HTML styles that Outlook attempts to preserve. Theme differences, Word-based editor settings, or a plain-text message format can change the result.","resolution":"1. In the message, use Paste Options and select Keep Text Only or Merge Formatting.\n2. Confirm Format Text > HTML is selected when formatting is required.\n3. In Outlook options, review Mail > Editor Options > Advanced > Cut, copy, and paste.\n4. Set the preferred default, restart Outlook, and test with a new message.","emailScript":"Hello,\n\nWe reviewed the Outlook formatting issue. The text being pasted contains formatting from the original application, which can conflict with Outlook's message style.\n\nPlease use the Paste Options button and select Keep Text Only or Merge Formatting. We have also provided steps to update the default paste behavior if needed.\n\nPlease let us know if you continue experiencing issues.\n\nThank you,\n\nIT Support","faqSteps":"1. Copy the text you want to use.\n2. Paste it into your Outlook message.\n3. Select the small Paste Options button beside the pasted text.\n4. Choose Keep Text Only for clean text, or Merge Formatting to match the email.\n5. Review the message before sending.","notes":"For classic Outlook, inspect File > Options > Mail > Editor Options > Advanced. Test WordMail behavior, add-ins, signatures, and message format. New Outlook has fewer editor controls; use paste-without-formatting (Ctrl+Shift+V) when supported.","sourceDocument":"Seed Data","platforms":["unknown"],"vendors":["Microsoft Outlook"],"technologies":["Formatting","Clipboard","Email"],"aliases":[]},{"id":2,"title":"Windows 11 Screenshot / Snipping Tool Guide","category":"Windows","product":"Windows 11","tags":["Snipping Tool","Screenshot","User Guide"],"keywords":["windows 11","screenshot","screen capture","snip","print screen","win shift s"],"errorCode":"","eventId":"","severity":"Low","summary":"Users can capture all or part of the screen with the built-in Windows 11 Snipping Tool. Captures can be copied, marked up, or saved as image files.","rootCause":"This is a user guidance article rather than a system fault. Users may be unfamiliar with the Windows 11 capture shortcut or where captures are stored.","resolution":"1. Press Windows key + Shift + S.\n2. Choose rectangular, freeform, window, or full-screen capture.\n3. Select the area to capture.\n4. Open the notification to edit or save the image.\n5. If the tool does not open, repair or reset Snipping Tool under Settings > Apps > Installed apps.","emailScript":"Hello,\n\nYou can take a screenshot in Windows 11 by pressing the Windows key + Shift + S. Select the part of the screen you want to capture, then use the notification that appears to save or mark up the image.\n\nPlease let us know if the Snipping Tool does not open or if you need help locating the saved image.\n\nThank you,\n\nIT Support","faqSteps":"1. Press Windows key + Shift + S at the same time.\n2. Select the capture type at the top of the screen.\n3. Click and drag around the area you want to capture.\n4. Select the pop-up notification to review the screenshot.\n5. Choose Save, or paste the screenshot into an email with Ctrl + V.","notes":"Clipboard captures remain available for immediate paste. Depending on configuration, screenshots may save under Pictures\\Screenshots. Confirm Snipping Tool notifications are enabled. For repair: Settings > Apps > Installed apps > Snipping Tool > Advanced options.","sourceDocument":"Seed Data","platforms":["windows"],"vendors":["Windows 11"],"technologies":["Snipping Tool","Screenshot","User Guide"],"aliases":[]},{"id":3,"title":"Password Reset / New User Onboarding","category":"Account Management","product":"Microsoft 365 / Active Directory","tags":["Password Reset","New User","Onboarding"],"keywords":["password","reset","onboarding","new user","account","mfa","license","active directory","entra id"],"errorCode":"","eventId":"","severity":"Medium","summary":"A standardized workflow for resetting passwords or preparing a new user account across on-premises and Microsoft 365 services. Verify requester authorization before making any account change.","rootCause":"Users may be unable to sign in because of an expired or forgotten password, account lockout, incomplete provisioning, missing licensing, or unregistered authentication methods.","resolution":"1. Verify the requester's identity and approval under company policy.\n2. Check account status, lockout, sign-in logs, and synchronization health.\n3. Reset the password and require a change at next sign-in when appropriate.\n4. For new users, assign required groups, licenses, mailbox, applications, and MFA methods.\n5. Validate sign-in and document all changes in the service ticket.","emailScript":"Hello,\n\nYour account has been prepared and the requested access has been assigned. For security, you will be prompted to change your temporary password and complete identity verification when you first sign in.\n\nPlease do not share your password with anyone. Let us know if you have trouble signing in or accessing a required application.\n\nThank you,\n\nIT Support","faqSteps":"1. Open your company sign-in page.\n2. Enter the temporary password provided through the approved secure method.\n3. Create a new, unique password when prompted.\n4. Follow the on-screen steps to set up identity verification.\n5. Contact IT Support if your account is locked or an expected application is missing.","notes":"Follow client-specific identity verification and approval procedures. Check AD userAccountControl, lockoutTime, group membership, Entra sign-in logs, license assignment, Conditional Access, MFA registration, and directory synchronization. Never include passwords in ordinary email.","sourceDocument":"Seed Data","platforms":["windows"],"vendors":["Microsoft 365"],"technologies":["Password Reset","New User","Onboarding"],"aliases":[]},{"id":4,"title":"Hyper-V VM Failed To Start","category":"Hyper-V","product":"Windows Server","tags":["Virtual Machine","Startup","Hyper-V"],"keywords":["hyper-v","vm","virtual machine","12150","0x80070020","vmms","avhdx","storage","vhdx","file lock","windows","general","the","file","use","another","process"],"errorCode":"0x80070020","eventId":"12150","severity":"Critical","summary":"A Hyper-V virtual machine cannot start because a required virtual disk or configuration file is being used by another process. The VM remains offline until the file lock or conflicting operation is cleared.","rootCause":"A backup agent, antivirus scanner, checkpoint operation, duplicate VM configuration, or another VM process may hold an exclusive lock on a VHDX or AVHDX file. Storage connectivity or an interrupted checkpoint merge can produce similar symptoms.","resolution":"1. Record the VM ID, disk paths, virtual switches, CPU, RAM, VLAN, and firmware settings.\n2. Confirm that the VHDX and AVHDX files are intact.\n3. Export the configuration if Hyper-V permits it.\n4. If the configuration cannot be repaired, create a replacement VM with matching generation and settings.\n5. Attach the existing disk chain only after verifying which disk is the active child.\n6. Reconfigure networking, CPU, RAM, boot order, VLAN, checkpoints, and integration settings.\n7. Do not attach both a parent VHDX and its active AVHDX child as separate disks.\n8. Start and test the recreated VM.","emailScript":"Hello,\n\nWe identified that the virtual server could not start because one of its storage files was in use by another process. We are clearing the conflicting operation and validating the server before returning it to service.\n\nWe will continue to monitor the system and will advise you if any further action is required.\n\nThank you,\n\nIT Support","faqSteps":"1. The affected server is temporarily unavailable while IT checks its storage files.\n2. Please save your work in any related applications.\n3. Wait for confirmation from IT Support before trying the service again.\n4. If access is still unavailable after confirmation, restart the application and contact IT Support.","notes":"Review Microsoft-Windows-Hyper-V-VMMS/Admin Event ID 12150 and the exact locked path. Use Get-VM, Get-VMHardDiskDrive, Get-VMSnapshot, and storage tooling to validate ownership. Do not delete AVHDX files manually. Coordinate backup-agent changes and restart VMMS only with an approved impact plan.\n\nAdditional source detail (WINDOWS SERVER AND HYPER-V VM ERROR.txt): - VHDX or AVHDX attached to another VM\n- Backup process is holding the disk\n- Antivirus or security software is scanning or locking the file\n- Stale VM worker process\n- Duplicate VM configuration references the same disk\n- Incomplete checkpoint operation\n- Disk is attached only to the intended VM\n- VM starts successfully\n- Backup and checkpoint operations complete normally\n\n===================================================\n\nAdditional source detail (WINDOWS SERVER AND HYPER-V VM ERROR.txt): - Corrupted VM configuration\n- Missing configuration files\n- Interrupted storage write\n- Failed host or VMMS operation\n- VM configuration references missing hardware or disks\n- Correct OS boots\n- Correct disk volumes appear\n- NIC and IP configuration are correct\n- Application and domain functions work\n- Backups recognize the replacement VM\n\n===================================================\n\nAdditional source detail (microsoft_windows_error_code_master_list.txt): Category: WINDOWS GENERAL\nDescription: The file is in use by another process.\n\nFixes:\n1. Capture the full message, operation, and matching Event Viewer entry.\n2. Verify permissions, paths, services, dependencies, network access, and pending restart state.\n3. Repair the affected component; for Windows corruption run DISM /Online /Cleanup-Image /RestoreHealth, then sfc /scannow.\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","sourceDocument":"Seed Data; WINDOWS SERVER AND HYPER-V VM ERROR.txt; microsoft_windows_error_code_master_list.txt","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"platforms":["windows"],"vendors":["Windows Server"],"technologies":["Virtual Machine","Startup","Hyper-V"],"aliases":["0x80070020","12150"]},{"id":5,"title":"DFSR Replication Offline Too Long","category":"Active Directory","product":"Windows Server / DFS Replication","tags":["DFSR","SYSVOL","Replication"],"keywords":["dfsr","replication","offline","9061","sysvol","active directory","maxoffline timeindays","wmic","event log"],"errorCode":"","eventId":"9061","severity":"Critical","summary":"DFSR has stopped replication because a replicated folder was offline longer than the configured maximum period. On a domain controller, this may prevent SYSVOL from replicating and can affect Group Policy availability.","rootCause":"The server remained disconnected, powered off, restored from an old snapshot, or unable to contact replication partners beyond the allowed offline interval. DFSR blocks replication to reduce the risk of stale data overwriting current content.","resolution":"1. Verify system time, DNS, network connectivity, disk health, and available replication partners.\n2. Review the DFS Replication event log and confirm the affected replicated folder.\n3. Determine whether the server's data is authoritative or stale and follow the approved DFSR recovery procedure.\n4. For SYSVOL, perform the appropriate non-authoritative or authoritative synchronization; do not simply extend the offline limit without validating data.\n5. Confirm DFSR events show successful initialization and validate AD and SYSVOL replication.","emailScript":"Hello,\n\nWe found that directory replication paused because the server was disconnected longer than its safety limit. We are validating the current data and restoring replication using the appropriate recovery process.\n\nThis work is being handled carefully to prevent older information from replacing current data. We will confirm once replication is healthy.\n\nThank you,\n\nIT Support","faqSteps":"1. IT Support is restoring communication between the affected servers.\n2. Group Policy changes or shared replicated data may take longer than normal to appear.\n3. Keep your computer connected to the company network.\n4. Contact IT Support if sign-in or policy issues continue after the recovery notice.","notes":"Review DFS Replication log Event ID 9061 and companion events. Validate repadmin /replsummary, repadmin /showrepl, dcdiag /test:dns, dfsrdiag ReplicationState, and SYSVOL/NETLOGON shares. Use Microsoft-supported D4/D2-style DFSR SYSVOL recovery procedures where applicable. Avoid changing MaxOfflineTimeInDays as a substitute for data validation.","sourceDocument":"Seed Data","platforms":["windows"],"vendors":["Windows Server"],"technologies":["DFSR","SYSVOL","Replication"],"aliases":["9061"]},{"id":6,"title":"ERROR_SUCCESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["0","0x0","error 0","ERROR_SUCCESS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","success","the","operation","completed","successfully"],"errorCode":"0","eventId":"","severity":"Low","summary":"The operation completed successfully.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 0; use the surrounding log entries to confirm it.","resolution":"1. Record where 0 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SUCCESS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 0 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation completed successfully.\n\nLookup forms: 0, 0x0, error 0, ERROR_SUCCESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["0"]},{"id":7,"title":"ERROR_INVALID_FUNCTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1","0x1","error 1","ERROR_INVALID_FUNCTION","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","invalid","function","incorrect"],"errorCode":"1","eventId":"","severity":"Low","summary":"Incorrect function.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1; use the surrounding log entries to confirm it.","resolution":"1. Record where 1 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_FUNCTION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Incorrect function.\n\nLookup forms: 1, 0x1, error 1, ERROR_INVALID_FUNCTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1"]},{"id":8,"title":"ERROR_FILE_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2","0x2","error 2","ERROR_FILE_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","file","not","found","the","system","cannot","find","specified"],"errorCode":"2","eventId":"","severity":"Medium","summary":"The system cannot find the file specified.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2; use the surrounding log entries to confirm it.","resolution":"1. Record where 2 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FILE_NOT_FOUND.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system cannot find the file specified.\n\nLookup forms: 2, 0x2, error 2, ERROR_FILE_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2"]},{"id":9,"title":"ERROR_PATH_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3","0x3","error 3","ERROR_PATH_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","path","not","found","the","system","cannot","find","specified"],"errorCode":"3","eventId":"","severity":"Medium","summary":"The system cannot find the path specified.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 3; use the surrounding log entries to confirm it.","resolution":"1. Record where 3 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PATH_NOT_FOUND.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system cannot find the path specified.\n\nLookup forms: 3, 0x3, error 3, ERROR_PATH_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3"]},{"id":10,"title":"ERROR_TOO_MANY_OPEN_FILES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4","0x4","error 4","ERROR_TOO_MANY_OPEN_FILES","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","too","many","open","files","the","system","cannot","file"],"errorCode":"4","eventId":"","severity":"Medium","summary":"The system cannot open the file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 4; use the surrounding log entries to confirm it.","resolution":"1. Record where 4 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TOO_MANY_OPEN_FILES.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system cannot open the file.\n\nLookup forms: 4, 0x4, error 4, ERROR_TOO_MANY_OPEN_FILES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4"]},{"id":11,"title":"ERROR_ACCESS_DENIED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5","0x5","error 5","ERROR_ACCESS_DENIED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","access","denied"],"errorCode":"5","eventId":"","severity":"Low","summary":"Access is denied.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 5; use the surrounding log entries to confirm it.","resolution":"1. Record where 5 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ACCESS_DENIED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Access is denied.\n\nLookup forms: 5, 0x5, error 5, ERROR_ACCESS_DENIED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5"]},{"id":12,"title":"ERROR_INVALID_HANDLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6","0x6","error 6","ERROR_INVALID_HANDLE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","invalid","handle","the"],"errorCode":"6","eventId":"","severity":"Medium","summary":"The handle is invalid.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6; use the surrounding log entries to confirm it.","resolution":"1. Record where 6 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_HANDLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The handle is invalid.\n\nLookup forms: 6, 0x6, error 6, ERROR_INVALID_HANDLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6"]},{"id":13,"title":"ERROR_ARENA_TRASHED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7","0x7","error 7","ERROR_ARENA_TRASHED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","arena","trashed","the","storage","control","blocks","were","destroyed"],"errorCode":"7","eventId":"","severity":"Low","summary":"The storage control blocks were destroyed.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 7; use the surrounding log entries to confirm it.","resolution":"1. Record where 7 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ARENA_TRASHED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The storage control blocks were destroyed.\n\nLookup forms: 7, 0x7, error 7, ERROR_ARENA_TRASHED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7"]},{"id":14,"title":"ERROR_NOT_ENOUGH_MEMORY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8","0x8","error 8","ERROR_NOT_ENOUGH_MEMORY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","not","enough","memory","resources","are","available","process","this","command"],"errorCode":"8","eventId":"","severity":"High","summary":"Not enough memory resources are available to process this command.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8; use the surrounding log entries to confirm it.","resolution":"1. Record where 8 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_ENOUGH_MEMORY.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Not enough memory resources are available to process this command.\n\nLookup forms: 8, 0x8, error 8, ERROR_NOT_ENOUGH_MEMORY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Not enough storage is available to process this command.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8"]},{"id":15,"title":"ERROR_INVALID_BLOCK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9","0x9","error 9","ERROR_INVALID_BLOCK","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","invalid","block","the","storage","control","address"],"errorCode":"9","eventId":"","severity":"Medium","summary":"The storage control block address is invalid.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 9; use the surrounding log entries to confirm it.","resolution":"1. Record where 9 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_BLOCK.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The storage control block address is invalid.\n\nLookup forms: 9, 0x9, error 9, ERROR_INVALID_BLOCK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9"]},{"id":16,"title":"ERROR_BAD_ENVIRONMENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10","0xA","error 10","ERROR_BAD_ENVIRONMENT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","bad","environment","the","incorrect"],"errorCode":"10","eventId":"","severity":"Low","summary":"The environment is incorrect.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 10; use the surrounding log entries to confirm it.","resolution":"1. Record where 10 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_ENVIRONMENT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The environment is incorrect.\n\nLookup forms: 10, 0xA, error 10, ERROR_BAD_ENVIRONMENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10"]},{"id":17,"title":"ERROR_BAD_FORMAT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11","0xB","error 11","ERROR_BAD_FORMAT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","bad","format","attempt","was","made","load","program","with","incorrect"],"errorCode":"11","eventId":"","severity":"Low","summary":"An attempt was made to load a program with an incorrect format.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 11; use the surrounding log entries to confirm it.","resolution":"1. Record where 11 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_FORMAT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt was made to load a program with an incorrect format.\n\nLookup forms: 11, 0xB, error 11, ERROR_BAD_FORMAT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11"]},{"id":18,"title":"ERROR_INVALID_ACCESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["12","0xC","error 12","ERROR_INVALID_ACCESS","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","invalid","access","the","code"],"errorCode":"12","eventId":"","severity":"Medium","summary":"The access code is invalid.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 12; use the surrounding log entries to confirm it.","resolution":"1. Record where 12 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_ACCESS.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 12 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The access code is invalid.\n\nLookup forms: 12, 0xC, error 12, ERROR_INVALID_ACCESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["12"]},{"id":19,"title":"ERROR_INVALID_DATA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13","0xD","error 13","ERROR_INVALID_DATA","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","data","the"],"errorCode":"13","eventId":"","severity":"Medium","summary":"The data is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13; use the surrounding log entries to confirm it.","resolution":"1. Record where 13 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_DATA.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The data is invalid.\n\nLookup forms: 13, 0xD, error 13, ERROR_INVALID_DATA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13"]},{"id":20,"title":"ERROR_OUTOFMEMORY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14","0xE","error 14","ERROR_OUTOFMEMORY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","outofmemory","not","enough","storage","available","complete","this","operation"],"errorCode":"14","eventId":"","severity":"Low","summary":"Not enough storage is available to complete this operation.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 14; use the surrounding log entries to confirm it.","resolution":"1. Record where 14 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_OUTOFMEMORY.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Not enough storage is available to complete this operation.\n\nLookup forms: 14, 0xE, error 14, ERROR_OUTOFMEMORY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14"]},{"id":21,"title":"ERROR_INVALID_DRIVE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15","0xF","error 15","ERROR_INVALID_DRIVE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","invalid","drive","the","system","cannot","find","specified"],"errorCode":"15","eventId":"","severity":"Medium","summary":"The system cannot find the drive specified.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 15; use the surrounding log entries to confirm it.","resolution":"1. Record where 15 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_DRIVE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system cannot find the drive specified.\n\nLookup forms: 15, 0xF, error 15, ERROR_INVALID_DRIVE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15"]},{"id":22,"title":"ERROR_CURRENT_DIRECTORY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["16","0x10","error 16","ERROR_CURRENT_DIRECTORY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","current","directory","the","cannot","removed"],"errorCode":"16","eventId":"","severity":"Medium","summary":"The directory cannot be removed.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 16; use the surrounding log entries to confirm it.","resolution":"1. Record where 16 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CURRENT_DIRECTORY.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 16 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory cannot be removed.\n\nLookup forms: 16, 0x10, error 16, ERROR_CURRENT_DIRECTORY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["16"]},{"id":23,"title":"ERROR_NOT_SAME_DEVICE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["17","0x11","error 17","ERROR_NOT_SAME_DEVICE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","not","same","device","the","system","cannot","move","file","different","disk","drive"],"errorCode":"17","eventId":"","severity":"Medium","summary":"The system cannot move the file to a different disk drive.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 17; use the surrounding log entries to confirm it.","resolution":"1. Record where 17 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_SAME_DEVICE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 17 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system cannot move the file to a different disk drive.\n\nLookup forms: 17, 0x11, error 17, ERROR_NOT_SAME_DEVICE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["17"]},{"id":24,"title":"ERROR_NO_MORE_FILES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["18","0x12","error 18","ERROR_NO_MORE_FILES","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","more","files","there","are"],"errorCode":"18","eventId":"","severity":"Low","summary":"There are no more files.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 18; use the surrounding log entries to confirm it.","resolution":"1. Record where 18 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_MORE_FILES.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 18 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There are no more files.\n\nLookup forms: 18, 0x12, error 18, ERROR_NO_MORE_FILES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["18"]},{"id":25,"title":"ERROR_WRITE_PROTECT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["19","0x13","error 19","ERROR_WRITE_PROTECT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","write","protect","the","media","protected"],"errorCode":"19","eventId":"","severity":"Low","summary":"The media is write protected.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 19; use the surrounding log entries to confirm it.","resolution":"1. Record where 19 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WRITE_PROTECT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 19 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The media is write protected.\n\nLookup forms: 19, 0x13, error 19, ERROR_WRITE_PROTECT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["19"]},{"id":26,"title":"ERROR_BAD_UNIT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["20","0x14","error 20","ERROR_BAD_UNIT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","bad","unit","the","system","cannot","find","device","specified"],"errorCode":"20","eventId":"","severity":"Medium","summary":"The system cannot find the device specified.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 20; use the surrounding log entries to confirm it.","resolution":"1. Record where 20 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_UNIT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 20 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system cannot find the device specified.\n\nLookup forms: 20, 0x14, error 20, ERROR_BAD_UNIT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["20"]},{"id":27,"title":"ERROR_NOT_READY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["21","0x15","error 21","ERROR_NOT_READY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","not","ready","the","device"],"errorCode":"21","eventId":"","severity":"Low","summary":"The device is not ready.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 21; use the surrounding log entries to confirm it.","resolution":"1. Record where 21 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_READY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 21 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The device is not ready.\n\nLookup forms: 21, 0x15, error 21, ERROR_NOT_READY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["21"]},{"id":28,"title":"ERROR_BAD_COMMAND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["22","0x16","error 22","ERROR_BAD_COMMAND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","bad","command","the","device","does","not","recognize"],"errorCode":"22","eventId":"","severity":"Low","summary":"The device does not recognize the command.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 22; use the surrounding log entries to confirm it.","resolution":"1. Record where 22 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_COMMAND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 22 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The device does not recognize the command.\n\nLookup forms: 22, 0x16, error 22, ERROR_BAD_COMMAND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["22"]},{"id":29,"title":"ERROR_CRC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["23","0x17","error 23","ERROR_CRC","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","crc","data","cyclic","redundancy","check"],"errorCode":"23","eventId":"","severity":"Low","summary":"Data error (cyclic redundancy check).","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 23; use the surrounding log entries to confirm it.","resolution":"1. Record where 23 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CRC.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 23 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Data error (cyclic redundancy check).\n\nLookup forms: 23, 0x17, error 23, ERROR_CRC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["23"]},{"id":30,"title":"ERROR_BAD_LENGTH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["24","0x18","error 24","ERROR_BAD_LENGTH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","bad","length","the","program","issued","command","but","incorrect"],"errorCode":"24","eventId":"","severity":"Low","summary":"The program issued a command but the command length is incorrect.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 24; use the surrounding log entries to confirm it.","resolution":"1. Record where 24 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_LENGTH.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 24 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The program issued a command but the command length is incorrect.\n\nLookup forms: 24, 0x18, error 24, ERROR_BAD_LENGTH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["24"]},{"id":31,"title":"ERROR_SEEK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["25","0x19","error 25","ERROR_SEEK","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","seek","the","drive","cannot","locate","specific","area","track","disk"],"errorCode":"25","eventId":"","severity":"Medium","summary":"The drive cannot locate a specific area or track on the disk.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 25; use the surrounding log entries to confirm it.","resolution":"1. Record where 25 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SEEK.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 25 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The drive cannot locate a specific area or track on the disk.\n\nLookup forms: 25, 0x19, error 25, ERROR_SEEK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["25"]},{"id":32,"title":"ERROR_NOT_DOS_DISK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["26","0x1A","error 26","ERROR_NOT_DOS_DISK","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","not","dos","disk","the","specified","diskette","cannot","accessed"],"errorCode":"26","eventId":"","severity":"Medium","summary":"The specified disk or diskette cannot be accessed.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 26; use the surrounding log entries to confirm it.","resolution":"1. Record where 26 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_DOS_DISK.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 26 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified disk or diskette cannot be accessed.\n\nLookup forms: 26, 0x1A, error 26, ERROR_NOT_DOS_DISK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["26"]},{"id":33,"title":"ERROR_SECTOR_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["27","0x1B","error 27","ERROR_SECTOR_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","sector","not","found","the","drive","cannot","find","requested"],"errorCode":"27","eventId":"","severity":"Medium","summary":"The drive cannot find the sector requested.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 27; use the surrounding log entries to confirm it.","resolution":"1. Record where 27 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SECTOR_NOT_FOUND.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 27 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The drive cannot find the sector requested.\n\nLookup forms: 27, 0x1B, error 27, ERROR_SECTOR_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["27"]},{"id":34,"title":"ERROR_OUT_OF_PAPER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["28","0x1C","error 28","ERROR_OUT_OF_PAPER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","out","paper","the","printer"],"errorCode":"28","eventId":"","severity":"Low","summary":"The printer is out of paper.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 28; use the surrounding log entries to confirm it.","resolution":"1. Record where 28 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_OUT_OF_PAPER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 28 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The printer is out of paper.\n\nLookup forms: 28, 0x1C, error 28, ERROR_OUT_OF_PAPER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["28"]},{"id":35,"title":"ERROR_WRITE_FAULT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["29","0x1D","error 29","ERROR_WRITE_FAULT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","write","fault","the","system","cannot","specified","device"],"errorCode":"29","eventId":"","severity":"Medium","summary":"The system cannot write to the specified device.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 29; use the surrounding log entries to confirm it.","resolution":"1. Record where 29 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WRITE_FAULT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 29 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system cannot write to the specified device.\n\nLookup forms: 29, 0x1D, error 29, ERROR_WRITE_FAULT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["29"]},{"id":36,"title":"ERROR_READ_FAULT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["30","0x1E","error 30","ERROR_READ_FAULT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","read","fault","the","system","cannot","from","specified","device"],"errorCode":"30","eventId":"","severity":"Medium","summary":"The system cannot read from the specified device.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 30; use the surrounding log entries to confirm it.","resolution":"1. Record where 30 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_READ_FAULT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 30 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system cannot read from the specified device.\n\nLookup forms: 30, 0x1E, error 30, ERROR_READ_FAULT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["30"]},{"id":37,"title":"ERROR_GEN_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["31","0x1F","error 31","ERROR_GEN_FAILURE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","gen","failure","device","attached","the","system","not","functioning"],"errorCode":"31","eventId":"","severity":"Low","summary":"A device attached to the system is not functioning.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 31; use the surrounding log entries to confirm it.","resolution":"1. Record where 31 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_GEN_FAILURE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 31 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A device attached to the system is not functioning.\n\nLookup forms: 31, 0x1F, error 31, ERROR_GEN_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["31"]},{"id":38,"title":"ERROR_SHARING_VIOLATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["32","0x20","error 32","ERROR_SHARING_VIOLATION","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","sharing","violation","the","process","cannot","access","file","because","being","used","another"],"errorCode":"32","eventId":"","severity":"Medium","summary":"The process cannot access the file because it is being used by another process.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 32; use the surrounding log entries to confirm it.","resolution":"1. Record where 32 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Confirm the user or service identity has the required permissions and is not locked or disabled.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SHARING_VIOLATION.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Confirm the user or service identity has the required permissions and is not locked or disabled.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 32 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The process cannot access the file because it is being used by another process.\n\nLookup forms: 32, 0x20, error 32, ERROR_SHARING_VIOLATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["32"]},{"id":39,"title":"ERROR_LOCK_VIOLATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["33","0x21","error 33","ERROR_LOCK_VIOLATION","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","lock","violation","the","process","cannot","access","file","because","another","has","locked","portion"],"errorCode":"33","eventId":"","severity":"High","summary":"The process cannot access the file because another process has locked a portion of the file.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 33; use the surrounding log entries to confirm it.","resolution":"1. Record where 33 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Confirm the user or service identity has the required permissions and is not locked or disabled.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOCK_VIOLATION.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Confirm the user or service identity has the required permissions and is not locked or disabled.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 33 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The process cannot access the file because another process has locked a portion of the file.\n\nLookup forms: 33, 0x21, error 33, ERROR_LOCK_VIOLATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["33"]},{"id":40,"title":"ERROR_WRONG_DISK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["34","0x22","error 34","ERROR_WRONG_DISK","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","wrong","disk","the","diskette","drive","insert","volume","serial","number","into"],"errorCode":"34","eventId":"","severity":"Low","summary":"The wrong diskette is in the drive. Insert %2 (Volume Serial Number: %3) into drive %1.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 34; use the surrounding log entries to confirm it.","resolution":"1. Record where 34 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WRONG_DISK.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 34 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The wrong diskette is in the drive. Insert %2 (Volume Serial Number: %3) into drive %1.\n\nLookup forms: 34, 0x22, error 34, ERROR_WRONG_DISK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["34"]},{"id":41,"title":"ERROR_SHARING_BUFFER_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["36","0x24","error 36","ERROR_SHARING_BUFFER_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","sharing","buffer","exceeded","too","many","files","opened","for"],"errorCode":"36","eventId":"","severity":"Low","summary":"Too many files opened for sharing.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 36; use the surrounding log entries to confirm it.","resolution":"1. Record where 36 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SHARING_BUFFER_EXCEEDED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 36 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Too many files opened for sharing.\n\nLookup forms: 36, 0x24, error 36, ERROR_SHARING_BUFFER_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["36"]},{"id":42,"title":"ERROR_HANDLE_EOF","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["38","0x26","error 38","ERROR_HANDLE_EOF","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","handle","eof","reached","the","end","file"],"errorCode":"38","eventId":"","severity":"Low","summary":"Reached the end of the file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 38; use the surrounding log entries to confirm it.","resolution":"1. Record where 38 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_HANDLE_EOF.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 38 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Reached the end of the file.\n\nLookup forms: 38, 0x26, error 38, ERROR_HANDLE_EOF. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["38"]},{"id":43,"title":"ERROR_HANDLE_DISK_FULL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["39","0x27","error 39","ERROR_HANDLE_DISK_FULL","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","handle","disk","full","the"],"errorCode":"39","eventId":"","severity":"Low","summary":"The disk is full.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 39; use the surrounding log entries to confirm it.","resolution":"1. Record where 39 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_HANDLE_DISK_FULL.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 39 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The disk is full.\n\nLookup forms: 39, 0x27, error 39, ERROR_HANDLE_DISK_FULL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["39"]},{"id":44,"title":"ERROR_NOT_SUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["50","0x32","error 50","ERROR_NOT_SUPPORTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","not","supported","the","request"],"errorCode":"50","eventId":"","severity":"Medium","summary":"The request is not supported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 50; use the surrounding log entries to confirm it.","resolution":"1. Record where 50 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_SUPPORTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 50 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The request is not supported.\n\nLookup forms: 50, 0x32, error 50, ERROR_NOT_SUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["50"]},{"id":45,"title":"ERROR_REM_NOT_LIST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["51","0x33","error 51","ERROR_REM_NOT_LIST","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","rem","not","list","windows","cannot","find","the","network","path","verify","that","correct","and","destination","computer","busy","turned","off","still","contact","your","administrator"],"errorCode":"51","eventId":"","severity":"High","summary":"Windows cannot find the network path. Verify that the network path is correct and the destination computer is not busy or turned off. If Windows still cannot find the network path, contact your network administrator.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 51; use the surrounding log entries to confirm it.","resolution":"1. Record where 51 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REM_NOT_LIST.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 51 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Windows cannot find the network path. Verify that the network path is correct and the destination computer is not busy or turned off. If Windows still cannot find the network path, contact your network administrator.\n\nLookup forms: 51, 0x33, error 51, ERROR_REM_NOT_LIST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["51"]},{"id":46,"title":"ERROR_DUP_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["52","0x34","error 52","ERROR_DUP_NAME","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","dup","name","you","were","not","connected","because","duplicate","exists","the","network","joining","domain","system","control","panel","change","computer","and","try","again","workgroup","choose","another"],"errorCode":"52","eventId":"","severity":"High","summary":"You were not connected because a duplicate name exists on the network. If joining a domain, go to System in Control Panel to change the computer name and try again. If joining a workgroup, choose another workgroup name.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 52; use the surrounding log entries to confirm it.","resolution":"1. Record where 52 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DUP_NAME.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 52 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: You were not connected because a duplicate name exists on the network. If joining a domain, go to System in Control Panel to change the computer name and try again. If joining a workgroup, choose another workgroup name.\n\nLookup forms: 52, 0x34, error 52, ERROR_DUP_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): You were not connected because a duplicate name exists on the network. Go to System in the Control Panel to change the computer name and try again.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["52"]},{"id":47,"title":"ERROR_BAD_NETPATH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["53","0x35","error 53","ERROR_BAD_NETPATH","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","bad","netpath","the","network","path","was","not","found"],"errorCode":"53","eventId":"","severity":"High","summary":"The network path was not found.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 53; use the surrounding log entries to confirm it.","resolution":"1. Record where 53 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_NETPATH.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 53 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The network path was not found.\n\nLookup forms: 53, 0x35, error 53, ERROR_BAD_NETPATH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["53"]},{"id":48,"title":"ERROR_NETWORK_BUSY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["54","0x36","error 54","ERROR_NETWORK_BUSY","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","network","busy","the"],"errorCode":"54","eventId":"","severity":"High","summary":"The network is busy.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 54; use the surrounding log entries to confirm it.","resolution":"1. Record where 54 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NETWORK_BUSY.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 54 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The network is busy.\n\nLookup forms: 54, 0x36, error 54, ERROR_NETWORK_BUSY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["54"]},{"id":49,"title":"ERROR_DEV_NOT_EXIST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["55","0x37","error 55","ERROR_DEV_NOT_EXIST","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","dev","not","exist","the","specified","network","resource","device","longer","available"],"errorCode":"55","eventId":"","severity":"High","summary":"The specified network resource or device is no longer available.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 55; use the surrounding log entries to confirm it.","resolution":"1. Record where 55 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEV_NOT_EXIST.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 55 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified network resource or device is no longer available.\n\nLookup forms: 55, 0x37, error 55, ERROR_DEV_NOT_EXIST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["55"]},{"id":50,"title":"ERROR_TOO_MANY_CMDS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["56","0x38","error 56","ERROR_TOO_MANY_CMDS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","too","many","cmds","the","network","bios","command","limit","has","been","reached"],"errorCode":"56","eventId":"","severity":"High","summary":"The network BIOS command limit has been reached.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 56; use the surrounding log entries to confirm it.","resolution":"1. Record where 56 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TOO_MANY_CMDS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 56 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The network BIOS command limit has been reached.\n\nLookup forms: 56, 0x38, error 56, ERROR_TOO_MANY_CMDS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["56"]},{"id":51,"title":"ERROR_ADAP_HDW_ERR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["57","0x39","error 57","ERROR_ADAP_HDW_ERR","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","adap","hdw","err","network","adapter","hardware","occurred"],"errorCode":"57","eventId":"","severity":"High","summary":"A network adapter hardware error occurred.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 57; use the surrounding log entries to confirm it.","resolution":"1. Record where 57 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ADAP_HDW_ERR.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 57 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A network adapter hardware error occurred.\n\nLookup forms: 57, 0x39, error 57, ERROR_ADAP_HDW_ERR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["57"]},{"id":52,"title":"ERROR_BAD_NET_RESP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["58","0x3A","error 58","ERROR_BAD_NET_RESP","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","bad","net","resp","the","specified","server","cannot","perform","requested","operation"],"errorCode":"58","eventId":"","severity":"Medium","summary":"The specified server cannot perform the requested operation.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 58; use the surrounding log entries to confirm it.","resolution":"1. Record where 58 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_NET_RESP.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 58 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified server cannot perform the requested operation.\n\nLookup forms: 58, 0x3A, error 58, ERROR_BAD_NET_RESP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["58"]},{"id":53,"title":"ERROR_UNEXP_NET_ERR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["59","0x3B","error 59","ERROR_UNEXP_NET_ERR","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","unexp","net","err","unexpected","network","occurred"],"errorCode":"59","eventId":"","severity":"High","summary":"An unexpected network error occurred.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 59; use the surrounding log entries to confirm it.","resolution":"1. Record where 59 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNEXP_NET_ERR.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 59 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An unexpected network error occurred.\n\nLookup forms: 59, 0x3B, error 59, ERROR_UNEXP_NET_ERR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["59"]},{"id":54,"title":"ERROR_BAD_REM_ADAP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["60","0x3C","error 60","ERROR_BAD_REM_ADAP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","bad","rem","adap","the","remote","adapter","not","compatible"],"errorCode":"60","eventId":"","severity":"Low","summary":"The remote adapter is not compatible.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 60; use the surrounding log entries to confirm it.","resolution":"1. Record where 60 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_REM_ADAP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 60 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The remote adapter is not compatible.\n\nLookup forms: 60, 0x3C, error 60, ERROR_BAD_REM_ADAP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["60"]},{"id":55,"title":"ERROR_PRINTQ_FULL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["61","0x3D","error 61","ERROR_PRINTQ_FULL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","printq","full","the","printer","queue"],"errorCode":"61","eventId":"","severity":"Low","summary":"The printer queue is full.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 61; use the surrounding log entries to confirm it.","resolution":"1. Record where 61 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PRINTQ_FULL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 61 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The printer queue is full.\n\nLookup forms: 61, 0x3D, error 61, ERROR_PRINTQ_FULL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["61"]},{"id":56,"title":"ERROR_NO_SPOOL_SPACE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["62","0x3E","error 62","ERROR_NO_SPOOL_SPACE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","spool","space","store","the","file","waiting","printed","not","available","server"],"errorCode":"62","eventId":"","severity":"Low","summary":"Space to store the file waiting to be printed is not available on the server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 62; use the surrounding log entries to confirm it.","resolution":"1. Record where 62 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Check available memory, disk capacity, quotas, and system resource pressure.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_SPOOL_SPACE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 62 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Space to store the file waiting to be printed is not available on the server.\n\nLookup forms: 62, 0x3E, error 62, ERROR_NO_SPOOL_SPACE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["62"]},{"id":57,"title":"ERROR_PRINT_CANCELLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["63","0x3F","error 63","ERROR_PRINT_CANCELLED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","print","cancelled","your","file","waiting","printed","was","deleted"],"errorCode":"63","eventId":"","severity":"Low","summary":"Your file waiting to be printed was deleted.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 63; use the surrounding log entries to confirm it.","resolution":"1. Record where 63 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PRINT_CANCELLED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 63 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Your file waiting to be printed was deleted.\n\nLookup forms: 63, 0x3F, error 63, ERROR_PRINT_CANCELLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["63"]},{"id":58,"title":"ERROR_NETNAME_DELETED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["64","0x40","error 64","ERROR_NETNAME_DELETED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","netname","deleted","the","specified","network","name","longer","available"],"errorCode":"64","eventId":"","severity":"High","summary":"The specified network name is no longer available.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 64; use the surrounding log entries to confirm it.","resolution":"1. Record where 64 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NETNAME_DELETED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 64 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified network name is no longer available.\n\nLookup forms: 64, 0x40, error 64, ERROR_NETNAME_DELETED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["64"]},{"id":59,"title":"ERROR_NETWORK_ACCESS_DENIED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["65","0x41","error 65","ERROR_NETWORK_ACCESS_DENIED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","network","access","denied"],"errorCode":"65","eventId":"","severity":"High","summary":"Network access is denied.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 65; use the surrounding log entries to confirm it.","resolution":"1. Record where 65 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NETWORK_ACCESS_DENIED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 65 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Network access is denied.\n\nLookup forms: 65, 0x41, error 65, ERROR_NETWORK_ACCESS_DENIED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["65"]},{"id":60,"title":"ERROR_BAD_DEV_TYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["66","0x42","error 66","ERROR_BAD_DEV_TYPE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","bad","dev","type","the","network","resource","not","correct"],"errorCode":"66","eventId":"","severity":"High","summary":"The network resource type is not correct.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 66; use the surrounding log entries to confirm it.","resolution":"1. Record where 66 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_DEV_TYPE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 66 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The network resource type is not correct.\n\nLookup forms: 66, 0x42, error 66, ERROR_BAD_DEV_TYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["66"]},{"id":61,"title":"ERROR_BAD_NET_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["67","0x43","error 67","ERROR_BAD_NET_NAME","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","bad","net","name","the","network","cannot","found"],"errorCode":"67","eventId":"","severity":"High","summary":"The network name cannot be found.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 67; use the surrounding log entries to confirm it.","resolution":"1. Record where 67 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_NET_NAME.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 67 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The network name cannot be found.\n\nLookup forms: 67, 0x43, error 67, ERROR_BAD_NET_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["67"]},{"id":62,"title":"ERROR_TOO_MANY_NAMES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["68","0x44","error 68","ERROR_TOO_MANY_NAMES","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","too","many","names","the","name","limit","for","local","computer","network","adapter","card","was","exceeded"],"errorCode":"68","eventId":"","severity":"High","summary":"The name limit for the local computer network adapter card was exceeded.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 68; use the surrounding log entries to confirm it.","resolution":"1. Record where 68 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TOO_MANY_NAMES.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 68 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The name limit for the local computer network adapter card was exceeded.\n\nLookup forms: 68, 0x44, error 68, ERROR_TOO_MANY_NAMES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["68"]},{"id":63,"title":"ERROR_TOO_MANY_SESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["69","0x45","error 69","ERROR_TOO_MANY_SESS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","too","many","sess","the","network","bios","session","limit","was","exceeded"],"errorCode":"69","eventId":"","severity":"High","summary":"The network BIOS session limit was exceeded.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 69; use the surrounding log entries to confirm it.","resolution":"1. Record where 69 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TOO_MANY_SESS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 69 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The network BIOS session limit was exceeded.\n\nLookup forms: 69, 0x45, error 69, ERROR_TOO_MANY_SESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["69"]},{"id":64,"title":"ERROR_SHARING_PAUSED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["70","0x46","error 70","ERROR_SHARING_PAUSED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","sharing","paused","the","remote","server","has","been","process","being","started"],"errorCode":"70","eventId":"","severity":"Low","summary":"The remote server has been paused or is in the process of being started.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 70; use the surrounding log entries to confirm it.","resolution":"1. Record where 70 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SHARING_PAUSED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 70 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The remote server has been paused or is in the process of being started.\n\nLookup forms: 70, 0x46, error 70, ERROR_SHARING_PAUSED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["70"]},{"id":65,"title":"ERROR_REQ_NOT_ACCEP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["71","0x47","error 71","ERROR_REQ_NOT_ACCEP","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","req","not","accep","more","connections","can","made","this","remote","computer","time","because","there","are","already","many","the","accept"],"errorCode":"71","eventId":"","severity":"High","summary":"No more connections can be made to this remote computer at this time because there are already as many connections as the computer can accept.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 71; use the surrounding log entries to confirm it.","resolution":"1. Record where 71 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REQ_NOT_ACCEP.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 71 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No more connections can be made to this remote computer at this time because there are already as many connections as the computer can accept.\n\nLookup forms: 71, 0x47, error 71, ERROR_REQ_NOT_ACCEP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["71"]},{"id":66,"title":"ERROR_REDIR_PAUSED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["72","0x48","error 72","ERROR_REDIR_PAUSED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","redir","paused","the","specified","printer","disk","device","has","been"],"errorCode":"72","eventId":"","severity":"Low","summary":"The specified printer or disk device has been paused.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 72; use the surrounding log entries to confirm it.","resolution":"1. Record where 72 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REDIR_PAUSED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 72 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified printer or disk device has been paused.\n\nLookup forms: 72, 0x48, error 72, ERROR_REDIR_PAUSED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["72"]},{"id":67,"title":"ERROR_FILE_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["80","0x50","error 80","ERROR_FILE_EXISTS","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","file","exists","the"],"errorCode":"80","eventId":"","severity":"Low","summary":"The file exists.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 80; use the surrounding log entries to confirm it.","resolution":"1. Record where 80 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FILE_EXISTS.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 80 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file exists.\n\nLookup forms: 80, 0x50, error 80, ERROR_FILE_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["80"]},{"id":68,"title":"ERROR_CANNOT_MAKE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["82","0x52","error 82","ERROR_CANNOT_MAKE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","cannot","make","the","directory","file","created"],"errorCode":"82","eventId":"","severity":"Medium","summary":"The directory or file cannot be created.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 82; use the surrounding log entries to confirm it.","resolution":"1. Record where 82 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANNOT_MAKE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 82 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory or file cannot be created.\n\nLookup forms: 82, 0x52, error 82, ERROR_CANNOT_MAKE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["82"]},{"id":69,"title":"ERROR_FAIL_I24","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["83","0x53","error 83","ERROR_FAIL_I24","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","fail","i24","int"],"errorCode":"83","eventId":"","severity":"Low","summary":"Fail on INT 24.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 83; use the surrounding log entries to confirm it.","resolution":"1. Record where 83 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FAIL_I24.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 83 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Fail on INT 24.\n\nLookup forms: 83, 0x53, error 83, ERROR_FAIL_I24. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["83"]},{"id":70,"title":"ERROR_OUT_OF_STRUCTURES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["84","0x54","error 84","ERROR_OUT_OF_STRUCTURES","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","out","structures","storage","process","this","request","not","available"],"errorCode":"84","eventId":"","severity":"Low","summary":"Storage to process this request is not available.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 84; use the surrounding log entries to confirm it.","resolution":"1. Record where 84 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_OUT_OF_STRUCTURES.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 84 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Storage to process this request is not available.\n\nLookup forms: 84, 0x54, error 84, ERROR_OUT_OF_STRUCTURES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["84"]},{"id":71,"title":"ERROR_ALREADY_ASSIGNED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["85","0x55","error 85","ERROR_ALREADY_ASSIGNED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","already","assigned","the","local","device","name","use"],"errorCode":"85","eventId":"","severity":"Low","summary":"The local device name is already in use.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 85; use the surrounding log entries to confirm it.","resolution":"1. Record where 85 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ALREADY_ASSIGNED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 85 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The local device name is already in use.\n\nLookup forms: 85, 0x55, error 85, ERROR_ALREADY_ASSIGNED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["85"]},{"id":72,"title":"ERROR_INVALID_PASSWORD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["86","0x56","error 86","ERROR_INVALID_PASSWORD","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","invalid","password","the","specified","network","not","correct"],"errorCode":"86","eventId":"","severity":"High","summary":"The specified network password is not correct.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 86; use the surrounding log entries to confirm it.","resolution":"1. Record where 86 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_PASSWORD.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 86 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified network password is not correct.\n\nLookup forms: 86, 0x56, error 86, ERROR_INVALID_PASSWORD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["86"]},{"id":73,"title":"ERROR_INVALID_PARAMETER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["87","0x57","error 87","ERROR_INVALID_PARAMETER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","parameter","the","incorrect"],"errorCode":"87","eventId":"","severity":"Low","summary":"The parameter is incorrect.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 87; use the surrounding log entries to confirm it.","resolution":"1. Record where 87 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_PARAMETER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 87 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The parameter is incorrect.\n\nLookup forms: 87, 0x57, error 87, ERROR_INVALID_PARAMETER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["87"]},{"id":74,"title":"ERROR_NET_WRITE_FAULT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["88","0x58","error 88","ERROR_NET_WRITE_FAULT","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","net","write","fault","occurred","the","network"],"errorCode":"88","eventId":"","severity":"High","summary":"A write fault occurred on the network.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 88; use the surrounding log entries to confirm it.","resolution":"1. Record where 88 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NET_WRITE_FAULT.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 88 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A write fault occurred on the network.\n\nLookup forms: 88, 0x58, error 88, ERROR_NET_WRITE_FAULT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["88"]},{"id":75,"title":"ERROR_NO_PROC_SLOTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["89","0x59","error 89","ERROR_NO_PROC_SLOTS","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","proc","slots","the","system","cannot","start","another","process","this","time"],"errorCode":"89","eventId":"","severity":"Medium","summary":"The system cannot start another process at this time.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 89; use the surrounding log entries to confirm it.","resolution":"1. Record where 89 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_PROC_SLOTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 89 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system cannot start another process at this time.\n\nLookup forms: 89, 0x59, error 89, ERROR_NO_PROC_SLOTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["89"]},{"id":76,"title":"ERROR_TOO_MANY_SEMAPHORES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["100","0x64","error 100","ERROR_TOO_MANY_SEMAPHORES","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","too","many","semaphores","cannot","create","another","system","semaphore"],"errorCode":"100","eventId":"","severity":"Medium","summary":"Cannot create another system semaphore.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 100; use the surrounding log entries to confirm it.","resolution":"1. Record where 100 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TOO_MANY_SEMAPHORES.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 100 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot create another system semaphore.\n\nLookup forms: 100, 0x64, error 100, ERROR_TOO_MANY_SEMAPHORES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["100"]},{"id":77,"title":"ERROR_EXCL_SEM_ALREADY_OWNED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["101","0x65","error 101","ERROR_EXCL_SEM_ALREADY_OWNED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","excl","sem","already","owned","the","exclusive","semaphore","another","process"],"errorCode":"101","eventId":"","severity":"Low","summary":"The exclusive semaphore is owned by another process.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 101; use the surrounding log entries to confirm it.","resolution":"1. Record where 101 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EXCL_SEM_ALREADY_OWNED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 101 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The exclusive semaphore is owned by another process.\n\nLookup forms: 101, 0x65, error 101, ERROR_EXCL_SEM_ALREADY_OWNED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["101"]},{"id":78,"title":"ERROR_SEM_IS_SET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["102","0x66","error 102","ERROR_SEM_IS_SET","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sem","set","the","semaphore","and","cannot","closed"],"errorCode":"102","eventId":"","severity":"Medium","summary":"The semaphore is set and cannot be closed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 102; use the surrounding log entries to confirm it.","resolution":"1. Record where 102 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SEM_IS_SET.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 102 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The semaphore is set and cannot be closed.\n\nLookup forms: 102, 0x66, error 102, ERROR_SEM_IS_SET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["102"]},{"id":79,"title":"ERROR_TOO_MANY_SEM_REQUESTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["103","0x67","error 103","ERROR_TOO_MANY_SEM_REQUESTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","too","many","sem","requests","the","semaphore","cannot","set","again"],"errorCode":"103","eventId":"","severity":"Medium","summary":"The semaphore cannot be set again.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 103; use the surrounding log entries to confirm it.","resolution":"1. Record where 103 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TOO_MANY_SEM_REQUESTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 103 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The semaphore cannot be set again.\n\nLookup forms: 103, 0x67, error 103, ERROR_TOO_MANY_SEM_REQUESTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["103"]},{"id":80,"title":"ERROR_INVALID_AT_INTERRUPT_TIME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["104","0x68","error 104","ERROR_INVALID_AT_INTERRUPT_TIME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","interrupt","time","cannot","request","exclusive","semaphores"],"errorCode":"104","eventId":"","severity":"Medium","summary":"Cannot request exclusive semaphores at interrupt time.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 104; use the surrounding log entries to confirm it.","resolution":"1. Record where 104 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_AT_INTERRUPT_TIME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 104 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot request exclusive semaphores at interrupt time.\n\nLookup forms: 104, 0x68, error 104, ERROR_INVALID_AT_INTERRUPT_TIME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["104"]},{"id":81,"title":"ERROR_SEM_OWNER_DIED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["105","0x69","error 105","ERROR_SEM_OWNER_DIED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sem","owner","died","the","previous","ownership","this","semaphore","has","ended"],"errorCode":"105","eventId":"","severity":"Low","summary":"The previous ownership of this semaphore has ended.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 105; use the surrounding log entries to confirm it.","resolution":"1. Record where 105 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SEM_OWNER_DIED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 105 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The previous ownership of this semaphore has ended.\n\nLookup forms: 105, 0x69, error 105, ERROR_SEM_OWNER_DIED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["105"]},{"id":82,"title":"ERROR_SEM_USER_LIMIT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["106","0x6A","error 106","ERROR_SEM_USER_LIMIT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","sem","user","limit","insert","the","diskette","for","drive"],"errorCode":"106","eventId":"","severity":"Low","summary":"Insert the diskette for drive %1.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 106; use the surrounding log entries to confirm it.","resolution":"1. Record where 106 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SEM_USER_LIMIT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 106 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Insert the diskette for drive %1.\n\nLookup forms: 106, 0x6A, error 106, ERROR_SEM_USER_LIMIT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["106"]},{"id":83,"title":"ERROR_DISK_CHANGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["107","0x6B","error 107","ERROR_DISK_CHANGE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","disk","change","the","program","stopped","because","alternate","diskette","was","not","inserted"],"errorCode":"107","eventId":"","severity":"Low","summary":"The program stopped because an alternate diskette was not inserted.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 107; use the surrounding log entries to confirm it.","resolution":"1. Record where 107 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DISK_CHANGE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 107 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The program stopped because an alternate diskette was not inserted.\n\nLookup forms: 107, 0x6B, error 107, ERROR_DISK_CHANGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["107"]},{"id":84,"title":"ERROR_DRIVE_LOCKED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["108","0x6C","error 108","ERROR_DRIVE_LOCKED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","drive","locked","the","disk","use","another","process"],"errorCode":"108","eventId":"","severity":"High","summary":"The disk is in use or locked by another process.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 108; use the surrounding log entries to confirm it.","resolution":"1. Record where 108 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DRIVE_LOCKED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 108 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The disk is in use or locked by another process.\n\nLookup forms: 108, 0x6C, error 108, ERROR_DRIVE_LOCKED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["108"]},{"id":85,"title":"ERROR_BROKEN_PIPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["109","0x6D","error 109","ERROR_BROKEN_PIPE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","broken","pipe","the","has","been","ended"],"errorCode":"109","eventId":"","severity":"Low","summary":"The pipe has been ended.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 109; use the surrounding log entries to confirm it.","resolution":"1. Record where 109 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BROKEN_PIPE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 109 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The pipe has been ended.\n\nLookup forms: 109, 0x6D, error 109, ERROR_BROKEN_PIPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["109"]},{"id":86,"title":"ERROR_OPEN_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["110","0x6E","error 110","ERROR_OPEN_FAILED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","open","failed","the","system","cannot","device","file","specified"],"errorCode":"110","eventId":"","severity":"Medium","summary":"The system cannot open the device or file specified.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 110; use the surrounding log entries to confirm it.","resolution":"1. Record where 110 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_OPEN_FAILED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 110 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system cannot open the device or file specified.\n\nLookup forms: 110, 0x6E, error 110, ERROR_OPEN_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["110"]},{"id":87,"title":"ERROR_BUFFER_OVERFLOW","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["111","0x6F","error 111","ERROR_BUFFER_OVERFLOW","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","buffer","overflow","the","file","name","too","long"],"errorCode":"111","eventId":"","severity":"Low","summary":"The file name is too long.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 111; use the surrounding log entries to confirm it.","resolution":"1. Record where 111 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BUFFER_OVERFLOW.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 111 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file name is too long.\n\nLookup forms: 111, 0x6F, error 111, ERROR_BUFFER_OVERFLOW. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["111"]},{"id":88,"title":"ERROR_DISK_FULL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["112","0x70","error 112","ERROR_DISK_FULL","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","disk","full","there","not","enough","space","the"],"errorCode":"112","eventId":"","severity":"Low","summary":"There is not enough space on the disk.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 112; use the surrounding log entries to confirm it.","resolution":"1. Record where 112 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DISK_FULL.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 112 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There is not enough space on the disk.\n\nLookup forms: 112, 0x70, error 112, ERROR_DISK_FULL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["112"]},{"id":89,"title":"ERROR_NO_MORE_SEARCH_HANDLES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["113","0x71","error 113","ERROR_NO_MORE_SEARCH_HANDLES","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","more","search","handles","internal","file","identifiers","available"],"errorCode":"113","eventId":"","severity":"Low","summary":"No more internal file identifiers available.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 113; use the surrounding log entries to confirm it.","resolution":"1. Record where 113 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_MORE_SEARCH_HANDLES.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 113 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No more internal file identifiers available.\n\nLookup forms: 113, 0x71, error 113, ERROR_NO_MORE_SEARCH_HANDLES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["113"]},{"id":90,"title":"ERROR_INVALID_TARGET_HANDLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["114","0x72","error 114","ERROR_INVALID_TARGET_HANDLE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","invalid","target","handle","the","internal","file","identifier","incorrect"],"errorCode":"114","eventId":"","severity":"Low","summary":"The target internal file identifier is incorrect.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 114; use the surrounding log entries to confirm it.","resolution":"1. Record where 114 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_TARGET_HANDLE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 114 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The target internal file identifier is incorrect.\n\nLookup forms: 114, 0x72, error 114, ERROR_INVALID_TARGET_HANDLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["114"]},{"id":91,"title":"ERROR_INVALID_CATEGORY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["117","0x75","error 117","ERROR_INVALID_CATEGORY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","category","the","ioctl","call","made","application","program","not","correct"],"errorCode":"117","eventId":"","severity":"Low","summary":"The IOCTL call made by the application program is not correct.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 117; use the surrounding log entries to confirm it.","resolution":"1. Record where 117 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_CATEGORY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 117 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The IOCTL call made by the application program is not correct.\n\nLookup forms: 117, 0x75, error 117, ERROR_INVALID_CATEGORY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["117"]},{"id":92,"title":"ERROR_INVALID_VERIFY_SWITCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["118","0x76","error 118","ERROR_INVALID_VERIFY_SWITCH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","verify","switch","the","write","parameter","value","not","correct"],"errorCode":"118","eventId":"","severity":"Low","summary":"The verify-on-write switch parameter value is not correct.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 118; use the surrounding log entries to confirm it.","resolution":"1. Record where 118 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_VERIFY_SWITCH.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 118 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The verify-on-write switch parameter value is not correct.\n\nLookup forms: 118, 0x76, error 118, ERROR_INVALID_VERIFY_SWITCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["118"]},{"id":93,"title":"ERROR_BAD_DRIVER_LEVEL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["119","0x77","error 119","ERROR_BAD_DRIVER_LEVEL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","bad","driver","level","the","system","does","not","support","command","requested"],"errorCode":"119","eventId":"","severity":"Low","summary":"The system does not support the command requested.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 119; use the surrounding log entries to confirm it.","resolution":"1. Record where 119 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_DRIVER_LEVEL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 119 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system does not support the command requested.\n\nLookup forms: 119, 0x77, error 119, ERROR_BAD_DRIVER_LEVEL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["119"]},{"id":94,"title":"ERROR_CALL_NOT_IMPLEMENTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["120","0x78","error 120","ERROR_CALL_NOT_IMPLEMENTED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","call","not","implemented","this","function","supported","system"],"errorCode":"120","eventId":"","severity":"Medium","summary":"This function is not supported on this system.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 120; use the surrounding log entries to confirm it.","resolution":"1. Record where 120 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CALL_NOT_IMPLEMENTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 120 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This function is not supported on this system.\n\nLookup forms: 120, 0x78, error 120, ERROR_CALL_NOT_IMPLEMENTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["120"]},{"id":95,"title":"ERROR_SEM_TIMEOUT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["121","0x79","error 121","ERROR_SEM_TIMEOUT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sem","timeout","the","semaphore","period","has","expired"],"errorCode":"121","eventId":"","severity":"Medium","summary":"The semaphore timeout period has expired.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 121; use the surrounding log entries to confirm it.","resolution":"1. Record where 121 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SEM_TIMEOUT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 121 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The semaphore timeout period has expired.\n\nLookup forms: 121, 0x79, error 121, ERROR_SEM_TIMEOUT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["121"]},{"id":96,"title":"ERROR_INSUFFICIENT_BUFFER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["122","0x7A","error 122","ERROR_INSUFFICIENT_BUFFER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","insufficient","buffer","the","data","area","passed","system","call","too","small"],"errorCode":"122","eventId":"","severity":"Low","summary":"The data area passed to a system call is too small.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 122; use the surrounding log entries to confirm it.","resolution":"1. Record where 122 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSUFFICIENT_BUFFER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 122 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The data area passed to a system call is too small.\n\nLookup forms: 122, 0x7A, error 122, ERROR_INSUFFICIENT_BUFFER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["122"]},{"id":97,"title":"ERROR_INVALID_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["123","0x7B","error 123","ERROR_INVALID_NAME","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","invalid","name","the","filename","directory","volume","label","syntax","incorrect"],"errorCode":"123","eventId":"","severity":"Low","summary":"The filename, directory name, or volume label syntax is incorrect.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 123; use the surrounding log entries to confirm it.","resolution":"1. Record where 123 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_NAME.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 123 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The filename, directory name, or volume label syntax is incorrect.\n\nLookup forms: 123, 0x7B, error 123, ERROR_INVALID_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["123"]},{"id":98,"title":"ERROR_INVALID_LEVEL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["124","0x7C","error 124","ERROR_INVALID_LEVEL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","level","the","system","call","not","correct"],"errorCode":"124","eventId":"","severity":"Low","summary":"The system call level is not correct.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 124; use the surrounding log entries to confirm it.","resolution":"1. Record where 124 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_LEVEL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 124 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system call level is not correct.\n\nLookup forms: 124, 0x7C, error 124, ERROR_INVALID_LEVEL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["124"]},{"id":99,"title":"ERROR_NO_VOLUME_LABEL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["125","0x7D","error 125","ERROR_NO_VOLUME_LABEL","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","volume","label","the","disk","has"],"errorCode":"125","eventId":"","severity":"Low","summary":"The disk has no volume label.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 125; use the surrounding log entries to confirm it.","resolution":"1. Record where 125 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_VOLUME_LABEL.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 125 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The disk has no volume label.\n\nLookup forms: 125, 0x7D, error 125, ERROR_NO_VOLUME_LABEL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["125"]},{"id":100,"title":"ERROR_MOD_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["126","0x7E","error 126","ERROR_MOD_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","mod","not","found","the","specified","module","could"],"errorCode":"126","eventId":"","severity":"Low","summary":"The specified module could not be found.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 126; use the surrounding log entries to confirm it.","resolution":"1. Record where 126 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MOD_NOT_FOUND.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 126 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified module could not be found.\n\nLookup forms: 126, 0x7E, error 126, ERROR_MOD_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["126"]},{"id":101,"title":"ERROR_PROC_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["127","0x7F","error 127","ERROR_PROC_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","proc","not","found","the","specified","procedure","could"],"errorCode":"127","eventId":"","severity":"Low","summary":"The specified procedure could not be found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 127; use the surrounding log entries to confirm it.","resolution":"1. Record where 127 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PROC_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 127 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified procedure could not be found.\n\nLookup forms: 127, 0x7F, error 127, ERROR_PROC_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["127"]},{"id":102,"title":"ERROR_WAIT_NO_CHILDREN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["128","0x80","error 128","ERROR_WAIT_NO_CHILDREN","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","wait","children","there","are","child","processes","for"],"errorCode":"128","eventId":"","severity":"Low","summary":"There are no child processes to wait for.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 128; use the surrounding log entries to confirm it.","resolution":"1. Record where 128 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WAIT_NO_CHILDREN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 128 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There are no child processes to wait for.\n\nLookup forms: 128, 0x80, error 128, ERROR_WAIT_NO_CHILDREN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["128"]},{"id":103,"title":"ERROR_CHILD_NOT_COMPLETE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["129","0x81","error 129","ERROR_CHILD_NOT_COMPLETE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","child","not","complete","the","application","cannot","run","win32","mode"],"errorCode":"129","eventId":"","severity":"Medium","summary":"The %1 application cannot be run in Win32 mode.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 129; use the surrounding log entries to confirm it.","resolution":"1. Record where 129 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CHILD_NOT_COMPLETE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 129 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The %1 application cannot be run in Win32 mode.\n\nLookup forms: 129, 0x81, error 129, ERROR_CHILD_NOT_COMPLETE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["129"]},{"id":104,"title":"ERROR_DIRECT_ACCESS_HANDLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["130","0x82","error 130","ERROR_DIRECT_ACCESS_HANDLE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","direct","access","handle","attempt","use","file","open","disk","partition","for","operation","other","than","raw"],"errorCode":"130","eventId":"","severity":"Low","summary":"Attempt to use a file handle to an open disk partition for an operation other than raw disk I/O.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 130; use the surrounding log entries to confirm it.","resolution":"1. Record where 130 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DIRECT_ACCESS_HANDLE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 130 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Attempt to use a file handle to an open disk partition for an operation other than raw disk I/O.\n\nLookup forms: 130, 0x82, error 130, ERROR_DIRECT_ACCESS_HANDLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["130"]},{"id":105,"title":"ERROR_NEGATIVE_SEEK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["131","0x83","error 131","ERROR_NEGATIVE_SEEK","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","negative","seek","attempt","was","made","move","the","file","pointer","before","beginning"],"errorCode":"131","eventId":"","severity":"Low","summary":"An attempt was made to move the file pointer before the beginning of the file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 131; use the surrounding log entries to confirm it.","resolution":"1. Record where 131 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NEGATIVE_SEEK.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 131 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt was made to move the file pointer before the beginning of the file.\n\nLookup forms: 131, 0x83, error 131, ERROR_NEGATIVE_SEEK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["131"]},{"id":106,"title":"ERROR_SEEK_ON_DEVICE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["132","0x84","error 132","ERROR_SEEK_ON_DEVICE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","seek","device","the","file","pointer","cannot","set","specified"],"errorCode":"132","eventId":"","severity":"Medium","summary":"The file pointer cannot be set on the specified device or file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 132; use the surrounding log entries to confirm it.","resolution":"1. Record where 132 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SEEK_ON_DEVICE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 132 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file pointer cannot be set on the specified device or file.\n\nLookup forms: 132, 0x84, error 132, ERROR_SEEK_ON_DEVICE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["132"]},{"id":107,"title":"ERROR_IS_JOIN_TARGET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["133","0x85","error 133","ERROR_IS_JOIN_TARGET","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","join","target","subst","command","cannot","used","for","drive","that","contains","previously","joined","drives"],"errorCode":"133","eventId":"","severity":"Medium","summary":"A JOIN or SUBST command cannot be used for a drive that contains previously joined drives.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 133; use the surrounding log entries to confirm it.","resolution":"1. Record where 133 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IS_JOIN_TARGET.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 133 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A JOIN or SUBST command cannot be used for a drive that contains previously joined drives.\n\nLookup forms: 133, 0x85, error 133, ERROR_IS_JOIN_TARGET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["133"]},{"id":108,"title":"ERROR_IS_JOINED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["134","0x86","error 134","ERROR_IS_JOINED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","joined","attempt","was","made","use","join","subst","command","drive","that","has","already","been"],"errorCode":"134","eventId":"","severity":"Low","summary":"An attempt was made to use a JOIN or SUBST command on a drive that has already been joined.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 134; use the surrounding log entries to confirm it.","resolution":"1. Record where 134 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IS_JOINED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 134 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt was made to use a JOIN or SUBST command on a drive that has already been joined.\n\nLookup forms: 134, 0x86, error 134, ERROR_IS_JOINED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["134"]},{"id":109,"title":"ERROR_IS_SUBSTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["135","0x87","error 135","ERROR_IS_SUBSTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","substed","attempt","was","made","use","join","subst","command","drive","that","has","already","been","substituted"],"errorCode":"135","eventId":"","severity":"Low","summary":"An attempt was made to use a JOIN or SUBST command on a drive that has already been substituted.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 135; use the surrounding log entries to confirm it.","resolution":"1. Record where 135 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IS_SUBSTED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 135 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt was made to use a JOIN or SUBST command on a drive that has already been substituted.\n\nLookup forms: 135, 0x87, error 135, ERROR_IS_SUBSTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["135"]},{"id":110,"title":"ERROR_NOT_JOINED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["136","0x88","error 136","ERROR_NOT_JOINED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","not","joined","the","system","tried","delete","join","drive","that"],"errorCode":"136","eventId":"","severity":"Low","summary":"The system tried to delete the JOIN of a drive that is not joined.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 136; use the surrounding log entries to confirm it.","resolution":"1. Record where 136 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_JOINED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 136 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system tried to delete the JOIN of a drive that is not joined.\n\nLookup forms: 136, 0x88, error 136, ERROR_NOT_JOINED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["136"]},{"id":111,"title":"ERROR_NOT_SUBSTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["137","0x89","error 137","ERROR_NOT_SUBSTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","not","substed","the","system","tried","delete","substitution","drive","that","substituted"],"errorCode":"137","eventId":"","severity":"Low","summary":"The system tried to delete the substitution of a drive that is not substituted.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 137; use the surrounding log entries to confirm it.","resolution":"1. Record where 137 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_SUBSTED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 137 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system tried to delete the substitution of a drive that is not substituted.\n\nLookup forms: 137, 0x89, error 137, ERROR_NOT_SUBSTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["137"]},{"id":112,"title":"ERROR_JOIN_TO_JOIN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["138","0x8A","error 138","ERROR_JOIN_TO_JOIN","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","join","the","system","tried","drive","directory","joined"],"errorCode":"138","eventId":"","severity":"Low","summary":"The system tried to join a drive to a directory on a joined drive.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 138; use the surrounding log entries to confirm it.","resolution":"1. Record where 138 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_JOIN_TO_JOIN.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 138 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system tried to join a drive to a directory on a joined drive.\n\nLookup forms: 138, 0x8A, error 138, ERROR_JOIN_TO_JOIN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["138"]},{"id":113,"title":"ERROR_SUBST_TO_SUBST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["139","0x8B","error 139","ERROR_SUBST_TO_SUBST","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","subst","the","system","tried","substitute","drive","directory","substituted"],"errorCode":"139","eventId":"","severity":"Low","summary":"The system tried to substitute a drive to a directory on a substituted drive.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 139; use the surrounding log entries to confirm it.","resolution":"1. Record where 139 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SUBST_TO_SUBST.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 139 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system tried to substitute a drive to a directory on a substituted drive.\n\nLookup forms: 139, 0x8B, error 139, ERROR_SUBST_TO_SUBST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["139"]},{"id":114,"title":"ERROR_JOIN_TO_SUBST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["140","0x8C","error 140","ERROR_JOIN_TO_SUBST","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","join","subst","the","system","tried","drive","directory","substituted"],"errorCode":"140","eventId":"","severity":"Low","summary":"The system tried to join a drive to a directory on a substituted drive.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 140; use the surrounding log entries to confirm it.","resolution":"1. Record where 140 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_JOIN_TO_SUBST.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 140 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system tried to join a drive to a directory on a substituted drive.\n\nLookup forms: 140, 0x8C, error 140, ERROR_JOIN_TO_SUBST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["140"]},{"id":115,"title":"ERROR_SUBST_TO_JOIN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["141","0x8D","error 141","ERROR_SUBST_TO_JOIN","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","subst","join","the","system","tried","drive","directory","joined"],"errorCode":"141","eventId":"","severity":"Low","summary":"The system tried to SUBST a drive to a directory on a joined drive.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 141; use the surrounding log entries to confirm it.","resolution":"1. Record where 141 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SUBST_TO_JOIN.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 141 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system tried to SUBST a drive to a directory on a joined drive.\n\nLookup forms: 141, 0x8D, error 141, ERROR_SUBST_TO_JOIN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["141"]},{"id":116,"title":"ERROR_BUSY_DRIVE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["142","0x8E","error 142","ERROR_BUSY_DRIVE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","busy","drive","the","system","cannot","perform","join","subst","this","time"],"errorCode":"142","eventId":"","severity":"Medium","summary":"The system cannot perform a JOIN or SUBST at this time.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 142; use the surrounding log entries to confirm it.","resolution":"1. Record where 142 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BUSY_DRIVE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 142 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system cannot perform a JOIN or SUBST at this time.\n\nLookup forms: 142, 0x8E, error 142, ERROR_BUSY_DRIVE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["142"]},{"id":117,"title":"ERROR_SAME_DRIVE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["143","0x8F","error 143","ERROR_SAME_DRIVE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","same","drive","the","system","cannot","join","substitute","for","directory"],"errorCode":"143","eventId":"","severity":"Medium","summary":"The system cannot join or substitute a drive to or for a directory on the same drive.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 143; use the surrounding log entries to confirm it.","resolution":"1. Record where 143 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SAME_DRIVE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 143 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system cannot join or substitute a drive to or for a directory on the same drive.\n\nLookup forms: 143, 0x8F, error 143, ERROR_SAME_DRIVE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["143"]},{"id":118,"title":"ERROR_DIR_NOT_ROOT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["144","0x90","error 144","ERROR_DIR_NOT_ROOT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","dir","not","root","the","directory","subdirectory"],"errorCode":"144","eventId":"","severity":"Low","summary":"The directory is not a subdirectory of the root directory.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 144; use the surrounding log entries to confirm it.","resolution":"1. Record where 144 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DIR_NOT_ROOT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 144 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory is not a subdirectory of the root directory.\n\nLookup forms: 144, 0x90, error 144, ERROR_DIR_NOT_ROOT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["144"]},{"id":119,"title":"ERROR_DIR_NOT_EMPTY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["145","0x91","error 145","ERROR_DIR_NOT_EMPTY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","dir","not","empty","the","directory"],"errorCode":"145","eventId":"","severity":"Low","summary":"The directory is not empty.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 145; use the surrounding log entries to confirm it.","resolution":"1. Record where 145 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DIR_NOT_EMPTY.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 145 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory is not empty.\n\nLookup forms: 145, 0x91, error 145, ERROR_DIR_NOT_EMPTY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["145"]},{"id":120,"title":"ERROR_IS_SUBST_PATH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["146","0x92","error 146","ERROR_IS_SUBST_PATH","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","subst","path","the","specified","being","used","substitute"],"errorCode":"146","eventId":"","severity":"Low","summary":"The path specified is being used in a substitute.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 146; use the surrounding log entries to confirm it.","resolution":"1. Record where 146 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IS_SUBST_PATH.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 146 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The path specified is being used in a substitute.\n\nLookup forms: 146, 0x92, error 146, ERROR_IS_SUBST_PATH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["146"]},{"id":121,"title":"ERROR_IS_JOIN_PATH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["147","0x93","error 147","ERROR_IS_JOIN_PATH","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","join","path","not","enough","resources","are","available","process","this","command"],"errorCode":"147","eventId":"","severity":"Low","summary":"Not enough resources are available to process this command.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 147; use the surrounding log entries to confirm it.","resolution":"1. Record where 147 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IS_JOIN_PATH.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 147 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Not enough resources are available to process this command.\n\nLookup forms: 147, 0x93, error 147, ERROR_IS_JOIN_PATH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["147"]},{"id":122,"title":"ERROR_PATH_BUSY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["148","0x94","error 148","ERROR_PATH_BUSY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","path","busy","the","specified","cannot","used","this","time"],"errorCode":"148","eventId":"","severity":"Medium","summary":"The path specified cannot be used at this time.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 148; use the surrounding log entries to confirm it.","resolution":"1. Record where 148 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PATH_BUSY.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 148 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The path specified cannot be used at this time.\n\nLookup forms: 148, 0x94, error 148, ERROR_PATH_BUSY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["148"]},{"id":123,"title":"ERROR_IS_SUBST_TARGET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["149","0x95","error 149","ERROR_IS_SUBST_TARGET","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","subst","target","attempt","was","made","join","substitute","drive","for","which","directory","the","previous"],"errorCode":"149","eventId":"","severity":"Low","summary":"An attempt was made to join or substitute a drive for which a directory on the drive is the target of a previous substitute.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 149; use the surrounding log entries to confirm it.","resolution":"1. Record where 149 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IS_SUBST_TARGET.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 149 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt was made to join or substitute a drive for which a directory on the drive is the target of a previous substitute.\n\nLookup forms: 149, 0x95, error 149, ERROR_IS_SUBST_TARGET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["149"]},{"id":124,"title":"ERROR_SYSTEM_TRACE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["150","0x96","error 150","ERROR_SYSTEM_TRACE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","system","trace","information","was","not","specified","your","config","sys","file","tracing","disallowed"],"errorCode":"150","eventId":"","severity":"Low","summary":"System trace information was not specified in your CONFIG.SYS file, or tracing is disallowed.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 150; use the surrounding log entries to confirm it.","resolution":"1. Record where 150 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SYSTEM_TRACE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 150 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: System trace information was not specified in your CONFIG.SYS file, or tracing is disallowed.\n\nLookup forms: 150, 0x96, error 150, ERROR_SYSTEM_TRACE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["150"]},{"id":125,"title":"ERROR_INVALID_EVENT_COUNT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["151","0x97","error 151","ERROR_INVALID_EVENT_COUNT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","event","count","the","number","specified","semaphore","events","for","dosmuxsemwait","not","correct"],"errorCode":"151","eventId":"","severity":"Low","summary":"The number of specified semaphore events for DosMuxSemWait is not correct.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 151; use the surrounding log entries to confirm it.","resolution":"1. Record where 151 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_EVENT_COUNT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 151 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The number of specified semaphore events for DosMuxSemWait is not correct.\n\nLookup forms: 151, 0x97, error 151, ERROR_INVALID_EVENT_COUNT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["151"]},{"id":126,"title":"ERROR_TOO_MANY_MUXWAITERS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["152","0x98","error 152","ERROR_TOO_MANY_MUXWAITERS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","too","many","muxwaiters","dosmuxsemwait","did","not","execute","semaphores","are","already","set"],"errorCode":"152","eventId":"","severity":"Low","summary":"DosMuxSemWait did not execute; too many semaphores are already set.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 152; use the surrounding log entries to confirm it.","resolution":"1. Record where 152 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TOO_MANY_MUXWAITERS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 152 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DosMuxSemWait did not execute; too many semaphores are already set.\n\nLookup forms: 152, 0x98, error 152, ERROR_TOO_MANY_MUXWAITERS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["152"]},{"id":127,"title":"ERROR_INVALID_LIST_FORMAT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["153","0x99","error 153","ERROR_INVALID_LIST_FORMAT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","list","format","the","dosmuxsemwait","not","correct"],"errorCode":"153","eventId":"","severity":"Low","summary":"The DosMuxSemWait list is not correct.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 153; use the surrounding log entries to confirm it.","resolution":"1. Record where 153 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_LIST_FORMAT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 153 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The DosMuxSemWait list is not correct.\n\nLookup forms: 153, 0x99, error 153, ERROR_INVALID_LIST_FORMAT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["153"]},{"id":128,"title":"ERROR_LABEL_TOO_LONG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["154","0x9A","error 154","ERROR_LABEL_TOO_LONG","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","label","too","long","the","volume","you","entered","exceeds","character","limit","target","file","system"],"errorCode":"154","eventId":"","severity":"Low","summary":"The volume label you entered exceeds the label character limit of the target file system.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 154; use the surrounding log entries to confirm it.","resolution":"1. Record where 154 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LABEL_TOO_LONG.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 154 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The volume label you entered exceeds the label character limit of the target file system.\n\nLookup forms: 154, 0x9A, error 154, ERROR_LABEL_TOO_LONG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["154"]},{"id":129,"title":"ERROR_TOO_MANY_TCBS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["155","0x9B","error 155","ERROR_TOO_MANY_TCBS","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","too","many","tcbs","cannot","create","another","thread"],"errorCode":"155","eventId":"","severity":"Medium","summary":"Cannot create another thread.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 155; use the surrounding log entries to confirm it.","resolution":"1. Record where 155 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TOO_MANY_TCBS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 155 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot create another thread.\n\nLookup forms: 155, 0x9B, error 155, ERROR_TOO_MANY_TCBS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["155"]},{"id":130,"title":"ERROR_SIGNAL_REFUSED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["156","0x9C","error 156","ERROR_SIGNAL_REFUSED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","signal","refused","the","recipient","process","has"],"errorCode":"156","eventId":"","severity":"Low","summary":"The recipient process has refused the signal.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 156; use the surrounding log entries to confirm it.","resolution":"1. Record where 156 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SIGNAL_REFUSED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 156 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The recipient process has refused the signal.\n\nLookup forms: 156, 0x9C, error 156, ERROR_SIGNAL_REFUSED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["156"]},{"id":131,"title":"ERROR_DISCARDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["157","0x9D","error 157","ERROR_DISCARDED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","discarded","the","segment","already","and","cannot","locked"],"errorCode":"157","eventId":"","severity":"High","summary":"The segment is already discarded and cannot be locked.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 157; use the surrounding log entries to confirm it.","resolution":"1. Record where 157 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DISCARDED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 157 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The segment is already discarded and cannot be locked.\n\nLookup forms: 157, 0x9D, error 157, ERROR_DISCARDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["157"]},{"id":132,"title":"ERROR_NOT_LOCKED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["158","0x9E","error 158","ERROR_NOT_LOCKED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","not","locked","the","segment","already","unlocked"],"errorCode":"158","eventId":"","severity":"High","summary":"The segment is already unlocked.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 158; use the surrounding log entries to confirm it.","resolution":"1. Record where 158 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_LOCKED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 158 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The segment is already unlocked.\n\nLookup forms: 158, 0x9E, error 158, ERROR_NOT_LOCKED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["158"]},{"id":133,"title":"ERROR_BAD_THREADID_ADDR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["159","0x9F","error 159","ERROR_BAD_THREADID_ADDR","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","bad","threadid","addr","the","address","for","thread","not","correct"],"errorCode":"159","eventId":"","severity":"Low","summary":"The address for the thread ID is not correct.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 159; use the surrounding log entries to confirm it.","resolution":"1. Record where 159 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_THREADID_ADDR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 159 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The address for the thread ID is not correct.\n\nLookup forms: 159, 0x9F, error 159, ERROR_BAD_THREADID_ADDR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["159"]},{"id":134,"title":"ERROR_BAD_ARGUMENTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["160","0xA0","error 160","ERROR_BAD_ARGUMENTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","bad","arguments","one","more","are","not","correct"],"errorCode":"160","eventId":"","severity":"Low","summary":"One or more arguments are not correct.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 160; use the surrounding log entries to confirm it.","resolution":"1. Record where 160 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_ARGUMENTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 160 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: One or more arguments are not correct.\n\nLookup forms: 160, 0xA0, error 160, ERROR_BAD_ARGUMENTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The argument string passed to DosExecPgm is not correct.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["160"]},{"id":135,"title":"ERROR_BAD_PATHNAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["161","0xA1","error 161","ERROR_BAD_PATHNAME","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","bad","pathname","the","specified","path","invalid"],"errorCode":"161","eventId":"","severity":"Medium","summary":"The specified path is invalid.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 161; use the surrounding log entries to confirm it.","resolution":"1. Record where 161 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_PATHNAME.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 161 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified path is invalid.\n\nLookup forms: 161, 0xA1, error 161, ERROR_BAD_PATHNAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["161"]},{"id":136,"title":"ERROR_SIGNAL_PENDING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["162","0xA2","error 162","ERROR_SIGNAL_PENDING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","signal","pending","already"],"errorCode":"162","eventId":"","severity":"Low","summary":"A signal is already pending.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 162; use the surrounding log entries to confirm it.","resolution":"1. Record where 162 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SIGNAL_PENDING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 162 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A signal is already pending.\n\nLookup forms: 162, 0xA2, error 162, ERROR_SIGNAL_PENDING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["162"]},{"id":137,"title":"ERROR_MAX_THRDS_REACHED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["164","0xA4","error 164","ERROR_MAX_THRDS_REACHED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","max","thrds","reached","more","threads","can","created","the","system"],"errorCode":"164","eventId":"","severity":"Low","summary":"No more threads can be created in the system.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 164; use the surrounding log entries to confirm it.","resolution":"1. Record where 164 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MAX_THRDS_REACHED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 164 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No more threads can be created in the system.\n\nLookup forms: 164, 0xA4, error 164, ERROR_MAX_THRDS_REACHED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["164"]},{"id":138,"title":"ERROR_LOCK_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["167","0xA7","error 167","ERROR_LOCK_FAILED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","lock","failed","unable","region","file"],"errorCode":"167","eventId":"","severity":"Medium","summary":"Unable to lock a region of a file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 167; use the surrounding log entries to confirm it.","resolution":"1. Record where 167 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOCK_FAILED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 167 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to lock a region of a file.\n\nLookup forms: 167, 0xA7, error 167, ERROR_LOCK_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["167"]},{"id":139,"title":"ERROR_BUSY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["170","0xAA","error 170","ERROR_BUSY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","busy","the","requested","resource","use"],"errorCode":"170","eventId":"","severity":"Low","summary":"The requested resource is in use.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 170; use the surrounding log entries to confirm it.","resolution":"1. Record where 170 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BUSY.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 170 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested resource is in use.\n\nLookup forms: 170, 0xAA, error 170, ERROR_BUSY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["170"]},{"id":140,"title":"ERROR_DEVICE_SUPPORT_IN_PROGRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["171","0xAB","error 171","ERROR_DEVICE_SUPPORT_IN_PROGRESS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","device","support","progress","command","detection"],"errorCode":"171","eventId":"","severity":"Low","summary":"Device's command support detection is in progress.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 171; use the surrounding log entries to confirm it.","resolution":"1. Record where 171 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEVICE_SUPPORT_IN_PROGRESS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 171 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Device's command support detection is in progress.\n\nLookup forms: 171, 0xAB, error 171, ERROR_DEVICE_SUPPORT_IN_PROGRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["171"]},{"id":141,"title":"ERROR_CANCEL_VIOLATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["173","0xAD","error 173","ERROR_CANCEL_VIOLATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cancel","violation","lock","request","was","not","outstanding","for","the","supplied","region"],"errorCode":"173","eventId":"","severity":"Low","summary":"A lock request was not outstanding for the supplied cancel region.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 173; use the surrounding log entries to confirm it.","resolution":"1. Record where 173 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANCEL_VIOLATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 173 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A lock request was not outstanding for the supplied cancel region.\n\nLookup forms: 173, 0xAD, error 173, ERROR_CANCEL_VIOLATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["173"]},{"id":142,"title":"ERROR_ATOMIC_LOCKS_NOT_SUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["174","0xAE","error 174","ERROR_ATOMIC_LOCKS_NOT_SUPPORTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","atomic","locks","not","supported","the","file","system","does","support","changes","lock","type"],"errorCode":"174","eventId":"","severity":"Low","summary":"The file system does not support atomic changes to the lock type.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 174; use the surrounding log entries to confirm it.","resolution":"1. Record where 174 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ATOMIC_LOCKS_NOT_SUPPORTED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 174 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file system does not support atomic changes to the lock type.\n\nLookup forms: 174, 0xAE, error 174, ERROR_ATOMIC_LOCKS_NOT_SUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["174"]},{"id":143,"title":"ERROR_INVALID_SEGMENT_NUMBER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["180","0xB4","error 180","ERROR_INVALID_SEGMENT_NUMBER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","segment","number","the","system","detected","that","was","not","correct"],"errorCode":"180","eventId":"","severity":"Low","summary":"The system detected a segment number that was not correct.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 180; use the surrounding log entries to confirm it.","resolution":"1. Record where 180 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_SEGMENT_NUMBER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 180 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system detected a segment number that was not correct.\n\nLookup forms: 180, 0xB4, error 180, ERROR_INVALID_SEGMENT_NUMBER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["180"]},{"id":144,"title":"ERROR_INVALID_ORDINAL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["182","0xB6","error 182","ERROR_INVALID_ORDINAL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","ordinal","the","operating","system","cannot","run"],"errorCode":"182","eventId":"","severity":"Medium","summary":"The operating system cannot run %1.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 182; use the surrounding log entries to confirm it.","resolution":"1. Record where 182 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_ORDINAL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 182 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operating system cannot run %1.\n\nLookup forms: 182, 0xB6, error 182, ERROR_INVALID_ORDINAL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["182"]},{"id":145,"title":"ERROR_ALREADY_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["183","0xB7","error 183","ERROR_ALREADY_EXISTS","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","already","exists","cannot","create","file","when","that"],"errorCode":"183","eventId":"","severity":"Medium","summary":"Cannot create a file when that file already exists.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 183; use the surrounding log entries to confirm it.","resolution":"1. Record where 183 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ALREADY_EXISTS.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 183 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot create a file when that file already exists.\n\nLookup forms: 183, 0xB7, error 183, ERROR_ALREADY_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["183"]},{"id":146,"title":"ERROR_INVALID_FLAG_NUMBER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["186","0xBA","error 186","ERROR_INVALID_FLAG_NUMBER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","flag","number","the","passed","not","correct"],"errorCode":"186","eventId":"","severity":"Low","summary":"The flag passed is not correct.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 186; use the surrounding log entries to confirm it.","resolution":"1. Record where 186 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_FLAG_NUMBER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 186 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The flag passed is not correct.\n\nLookup forms: 186, 0xBA, error 186, ERROR_INVALID_FLAG_NUMBER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["186"]},{"id":147,"title":"ERROR_SEM_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["187","0xBB","error 187","ERROR_SEM_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sem","not","found","the","specified","system","semaphore","name","was"],"errorCode":"187","eventId":"","severity":"Medium","summary":"The specified system semaphore name was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 187; use the surrounding log entries to confirm it.","resolution":"1. Record where 187 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SEM_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 187 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified system semaphore name was not found.\n\nLookup forms: 187, 0xBB, error 187, ERROR_SEM_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["187"]},{"id":148,"title":"ERROR_INVALID_STARTING_CODESEG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["188","0xBC","error 188","ERROR_INVALID_STARTING_CODESEG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","starting","codeseg","the","operating","system","cannot","run"],"errorCode":"188","eventId":"","severity":"Medium","summary":"The operating system cannot run %1.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 188; use the surrounding log entries to confirm it.","resolution":"1. Record where 188 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_STARTING_CODESEG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 188 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operating system cannot run %1.\n\nLookup forms: 188, 0xBC, error 188, ERROR_INVALID_STARTING_CODESEG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["188"]},{"id":149,"title":"ERROR_INVALID_STACKSEG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["189","0xBD","error 189","ERROR_INVALID_STACKSEG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","stackseg","the","operating","system","cannot","run"],"errorCode":"189","eventId":"","severity":"Medium","summary":"The operating system cannot run %1.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 189; use the surrounding log entries to confirm it.","resolution":"1. Record where 189 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_STACKSEG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 189 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operating system cannot run %1.\n\nLookup forms: 189, 0xBD, error 189, ERROR_INVALID_STACKSEG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["189"]},{"id":150,"title":"ERROR_INVALID_MODULETYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["190","0xBE","error 190","ERROR_INVALID_MODULETYPE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","moduletype","the","operating","system","cannot","run"],"errorCode":"190","eventId":"","severity":"Medium","summary":"The operating system cannot run %1.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 190; use the surrounding log entries to confirm it.","resolution":"1. Record where 190 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_MODULETYPE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 190 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operating system cannot run %1.\n\nLookup forms: 190, 0xBE, error 190, ERROR_INVALID_MODULETYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["190"]},{"id":151,"title":"ERROR_INVALID_EXE_SIGNATURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["191","0xBF","error 191","ERROR_INVALID_EXE_SIGNATURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","exe","signature","cannot","run","win32","mode"],"errorCode":"191","eventId":"","severity":"Medium","summary":"Cannot run %1 in Win32 mode.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 191; use the surrounding log entries to confirm it.","resolution":"1. Record where 191 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_EXE_SIGNATURE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 191 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot run %1 in Win32 mode.\n\nLookup forms: 191, 0xBF, error 191, ERROR_INVALID_EXE_SIGNATURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["191"]},{"id":152,"title":"ERROR_EXE_MARKED_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["192","0xC0","error 192","ERROR_EXE_MARKED_INVALID","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","exe","marked","invalid","the","operating","system","cannot","run"],"errorCode":"192","eventId":"","severity":"Medium","summary":"The operating system cannot run %1.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 192; use the surrounding log entries to confirm it.","resolution":"1. Record where 192 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EXE_MARKED_INVALID.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 192 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operating system cannot run %1.\n\nLookup forms: 192, 0xC0, error 192, ERROR_EXE_MARKED_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["192"]},{"id":153,"title":"ERROR_BAD_EXE_FORMAT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["193","0xC1","error 193","ERROR_BAD_EXE_FORMAT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","bad","exe","format","not","valid","win32","application"],"errorCode":"193","eventId":"","severity":"Low","summary":"%1 is not a valid Win32 application.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 193; use the surrounding log entries to confirm it.","resolution":"1. Record where 193 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_EXE_FORMAT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 193 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: %1 is not a valid Win32 application.\n\nLookup forms: 193, 0xC1, error 193, ERROR_BAD_EXE_FORMAT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["193"]},{"id":154,"title":"ERROR_INVALID_MINALLOCSIZE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["195","0xC3","error 195","ERROR_INVALID_MINALLOCSIZE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","minallocsize","the","operating","system","cannot","run"],"errorCode":"195","eventId":"","severity":"Medium","summary":"The operating system cannot run %1.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 195; use the surrounding log entries to confirm it.","resolution":"1. Record where 195 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_MINALLOCSIZE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 195 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operating system cannot run %1.\n\nLookup forms: 195, 0xC3, error 195, ERROR_INVALID_MINALLOCSIZE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["195"]},{"id":155,"title":"ERROR_DYNLINK_FROM_INVALID_RING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["196","0xC4","error 196","ERROR_DYNLINK_FROM_INVALID_RING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dynlink","from","invalid","ring","the","operating","system","cannot","run","this","application","program"],"errorCode":"196","eventId":"","severity":"Medium","summary":"The operating system cannot run this application program.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 196; use the surrounding log entries to confirm it.","resolution":"1. Record where 196 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DYNLINK_FROM_INVALID_RING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 196 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operating system cannot run this application program.\n\nLookup forms: 196, 0xC4, error 196, ERROR_DYNLINK_FROM_INVALID_RING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["196"]},{"id":156,"title":"ERROR_IOPL_NOT_ENABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["197","0xC5","error 197","ERROR_IOPL_NOT_ENABLED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","iopl","not","enabled","the","operating","system","presently","configured","run","this","application"],"errorCode":"197","eventId":"","severity":"Low","summary":"The operating system is not presently configured to run this application.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 197; use the surrounding log entries to confirm it.","resolution":"1. Record where 197 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IOPL_NOT_ENABLED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 197 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operating system is not presently configured to run this application.\n\nLookup forms: 197, 0xC5, error 197, ERROR_IOPL_NOT_ENABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["197"]},{"id":157,"title":"ERROR_INVALID_SEGDPL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["198","0xC6","error 198","ERROR_INVALID_SEGDPL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","segdpl","the","operating","system","cannot","run"],"errorCode":"198","eventId":"","severity":"Medium","summary":"The operating system cannot run %1.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 198; use the surrounding log entries to confirm it.","resolution":"1. Record where 198 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_SEGDPL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 198 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operating system cannot run %1.\n\nLookup forms: 198, 0xC6, error 198, ERROR_INVALID_SEGDPL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["198"]},{"id":158,"title":"ERROR_RING2SEG_MUST_BE_MOVABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["200","0xC8","error 200","ERROR_RING2SEG_MUST_BE_MOVABLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ring2seg","must","movable","the","code","segment","cannot","greater","than","equal","64k"],"errorCode":"200","eventId":"","severity":"Medium","summary":"The code segment cannot be greater than or equal to 64K.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 200; use the surrounding log entries to confirm it.","resolution":"1. Record where 200 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RING2SEG_MUST_BE_MOVABLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 200 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The code segment cannot be greater than or equal to 64K.\n\nLookup forms: 200, 0xC8, error 200, ERROR_RING2SEG_MUST_BE_MOVABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["200"]},{"id":159,"title":"ERROR_RELOC_CHAIN_XEEDS_SEGLIM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["201","0xC9","error 201","ERROR_RELOC_CHAIN_XEEDS_SEGLIM","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","reloc","chain","xeeds","seglim","the","operating","system","cannot","run"],"errorCode":"201","eventId":"","severity":"Medium","summary":"The operating system cannot run %1.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 201; use the surrounding log entries to confirm it.","resolution":"1. Record where 201 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RELOC_CHAIN_XEEDS_SEGLIM.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 201 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operating system cannot run %1.\n\nLookup forms: 201, 0xC9, error 201, ERROR_RELOC_CHAIN_XEEDS_SEGLIM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["201"]},{"id":160,"title":"ERROR_INFLOOP_IN_RELOC_CHAIN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["202","0xCA","error 202","ERROR_INFLOOP_IN_RELOC_CHAIN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","infloop","reloc","chain","the","operating","system","cannot","run"],"errorCode":"202","eventId":"","severity":"Medium","summary":"The operating system cannot run %1.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 202; use the surrounding log entries to confirm it.","resolution":"1. Record where 202 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INFLOOP_IN_RELOC_CHAIN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 202 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operating system cannot run %1.\n\nLookup forms: 202, 0xCA, error 202, ERROR_INFLOOP_IN_RELOC_CHAIN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["202"]},{"id":161,"title":"ERROR_ENVVAR_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["203","0xCB","error 203","ERROR_ENVVAR_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","envvar","not","found","the","system","could","find","environment","option","that","was","entered"],"errorCode":"203","eventId":"","severity":"Low","summary":"The system could not find the environment option that was entered.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 203; use the surrounding log entries to confirm it.","resolution":"1. Record where 203 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ENVVAR_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 203 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system could not find the environment option that was entered.\n\nLookup forms: 203, 0xCB, error 203, ERROR_ENVVAR_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["203"]},{"id":162,"title":"ERROR_NO_SIGNAL_SENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["205","0xCD","error 205","ERROR_NO_SIGNAL_SENT","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","signal","sent","process","the","command","subtree","has","handler"],"errorCode":"205","eventId":"","severity":"Low","summary":"No process in the command subtree has a signal handler.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 205; use the surrounding log entries to confirm it.","resolution":"1. Record where 205 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_SIGNAL_SENT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 205 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No process in the command subtree has a signal handler.\n\nLookup forms: 205, 0xCD, error 205, ERROR_NO_SIGNAL_SENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["205"]},{"id":163,"title":"ERROR_FILENAME_EXCED_RANGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["206","0xCE","error 206","ERROR_FILENAME_EXCED_RANGE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","filename","exced","range","the","extension","too","long"],"errorCode":"206","eventId":"","severity":"Low","summary":"The filename or extension is too long.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 206; use the surrounding log entries to confirm it.","resolution":"1. Record where 206 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FILENAME_EXCED_RANGE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 206 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The filename or extension is too long.\n\nLookup forms: 206, 0xCE, error 206, ERROR_FILENAME_EXCED_RANGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["206"]},{"id":164,"title":"ERROR_RING2_STACK_IN_USE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["207","0xCF","error 207","ERROR_RING2_STACK_IN_USE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ring2","stack","use","the","ring"],"errorCode":"207","eventId":"","severity":"Low","summary":"The ring 2 stack is in use.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 207; use the surrounding log entries to confirm it.","resolution":"1. Record where 207 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RING2_STACK_IN_USE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 207 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The ring 2 stack is in use.\n\nLookup forms: 207, 0xCF, error 207, ERROR_RING2_STACK_IN_USE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["207"]},{"id":165,"title":"ERROR_META_EXPANSION_TOO_LONG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["208","0xD0","error 208","ERROR_META_EXPANSION_TOO_LONG","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","meta","expansion","too","long","the","global","filename","characters","are","entered","incorrectly","many","specified"],"errorCode":"208","eventId":"","severity":"Low","summary":"The global filename characters, * or ?, are entered incorrectly or too many global filename characters are specified.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 208; use the surrounding log entries to confirm it.","resolution":"1. Record where 208 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_META_EXPANSION_TOO_LONG.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 208 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The global filename characters, * or ?, are entered incorrectly or too many global filename characters are specified.\n\nLookup forms: 208, 0xD0, error 208, ERROR_META_EXPANSION_TOO_LONG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["208"]},{"id":166,"title":"ERROR_INVALID_SIGNAL_NUMBER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["209","0xD1","error 209","ERROR_INVALID_SIGNAL_NUMBER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","signal","number","the","being","posted","not","correct"],"errorCode":"209","eventId":"","severity":"Low","summary":"The signal being posted is not correct.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 209; use the surrounding log entries to confirm it.","resolution":"1. Record where 209 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_SIGNAL_NUMBER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 209 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The signal being posted is not correct.\n\nLookup forms: 209, 0xD1, error 209, ERROR_INVALID_SIGNAL_NUMBER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["209"]},{"id":167,"title":"ERROR_THREAD_1_INACTIVE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["210","0xD2","error 210","ERROR_THREAD_1_INACTIVE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","thread","inactive","the","signal","handler","cannot","set"],"errorCode":"210","eventId":"","severity":"Medium","summary":"The signal handler cannot be set.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 210; use the surrounding log entries to confirm it.","resolution":"1. Record where 210 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_THREAD_1_INACTIVE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 210 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The signal handler cannot be set.\n\nLookup forms: 210, 0xD2, error 210, ERROR_THREAD_1_INACTIVE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["210"]},{"id":168,"title":"ERROR_LOCKED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["212","0xD4","error 212","ERROR_LOCKED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","locked","the","segment","and","cannot","reallocated"],"errorCode":"212","eventId":"","severity":"High","summary":"The segment is locked and cannot be reallocated.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 212; use the surrounding log entries to confirm it.","resolution":"1. Record where 212 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOCKED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 212 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The segment is locked and cannot be reallocated.\n\nLookup forms: 212, 0xD4, error 212, ERROR_LOCKED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["212"]},{"id":169,"title":"ERROR_TOO_MANY_MODULES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["214","0xD6","error 214","ERROR_TOO_MANY_MODULES","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","too","many","modules","dynamic","link","are","attached","this","program","module"],"errorCode":"214","eventId":"","severity":"Low","summary":"Too many dynamic-link modules are attached to this program or dynamic-link module.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 214; use the surrounding log entries to confirm it.","resolution":"1. Record where 214 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TOO_MANY_MODULES.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 214 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Too many dynamic-link modules are attached to this program or dynamic-link module.\n\nLookup forms: 214, 0xD6, error 214, ERROR_TOO_MANY_MODULES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["214"]},{"id":170,"title":"ERROR_NESTING_NOT_ALLOWED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["215","0xD7","error 215","ERROR_NESTING_NOT_ALLOWED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","nesting","not","allowed","cannot","nest","calls","loadmodule"],"errorCode":"215","eventId":"","severity":"Medium","summary":"Cannot nest calls to LoadModule.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 215; use the surrounding log entries to confirm it.","resolution":"1. Record where 215 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NESTING_NOT_ALLOWED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 215 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot nest calls to LoadModule.\n\nLookup forms: 215, 0xD7, error 215, ERROR_NESTING_NOT_ALLOWED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["215"]},{"id":171,"title":"ERROR_EXE_MACHINE_TYPE_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["216","0xD8","error 216","ERROR_EXE_MACHINE_TYPE_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","exe","machine","type","mismatch","this","version","not","compatible","with","the","windows","you","running","check","your","computer","system","information","and","then","contact","software","publisher"],"errorCode":"216","eventId":"","severity":"Low","summary":"This version of %1 is not compatible with the version of Windows you're running. Check your computer's system information and then contact the software publisher.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 216; use the surrounding log entries to confirm it.","resolution":"1. Record where 216 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EXE_MACHINE_TYPE_MISMATCH.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 216 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This version of %1 is not compatible with the version of Windows you're running. Check your computer's system information and then contact the software publisher.\n\nLookup forms: 216, 0xD8, error 216, ERROR_EXE_MACHINE_TYPE_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The image file %1 is valid, but is for a machine type other than the current machine.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["216"]},{"id":172,"title":"ERROR_EXE_CANNOT_MODIFY_SIGNED_BINARY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["217","0xD9","error 217","ERROR_EXE_CANNOT_MODIFY_SIGNED_BINARY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","exe","cannot","modify","signed","binary","the","image","file","unable"],"errorCode":"217","eventId":"","severity":"Medium","summary":"The image file %1 is signed, unable to modify.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 217; use the surrounding log entries to confirm it.","resolution":"1. Record where 217 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EXE_CANNOT_MODIFY_SIGNED_BINARY.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 217 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The image file %1 is signed, unable to modify.\n\nLookup forms: 217, 0xD9, error 217, ERROR_EXE_CANNOT_MODIFY_SIGNED_BINARY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["217"]},{"id":173,"title":"ERROR_EXE_CANNOT_MODIFY_STRONG_SIGNED_BINARY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["218","0xDA","error 218","ERROR_EXE_CANNOT_MODIFY_STRONG_SIGNED_BINARY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","exe","cannot","modify","strong","signed","binary","the","image","file","unable"],"errorCode":"218","eventId":"","severity":"Medium","summary":"The image file %1 is strong signed, unable to modify.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 218; use the surrounding log entries to confirm it.","resolution":"1. Record where 218 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EXE_CANNOT_MODIFY_STRONG_SIGNED_BINARY.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 218 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The image file %1 is strong signed, unable to modify.\n\nLookup forms: 218, 0xDA, error 218, ERROR_EXE_CANNOT_MODIFY_STRONG_SIGNED_BINARY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["218"]},{"id":174,"title":"ERROR_FILE_CHECKED_OUT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["220","0xDC","error 220","ERROR_FILE_CHECKED_OUT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","file","checked","out","this","locked","for","editing","another","user"],"errorCode":"220","eventId":"","severity":"High","summary":"This file is checked out or locked for editing by another user.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 220; use the surrounding log entries to confirm it.","resolution":"1. Record where 220 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FILE_CHECKED_OUT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 220 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This file is checked out or locked for editing by another user.\n\nLookup forms: 220, 0xDC, error 220, ERROR_FILE_CHECKED_OUT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["220"]},{"id":175,"title":"ERROR_CHECKOUT_REQUIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["221","0xDD","error 221","ERROR_CHECKOUT_REQUIRED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","checkout","required","the","file","must","checked","out","before","saving","changes"],"errorCode":"221","eventId":"","severity":"Low","summary":"The file must be checked out before saving changes.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 221; use the surrounding log entries to confirm it.","resolution":"1. Record where 221 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CHECKOUT_REQUIRED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 221 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file must be checked out before saving changes.\n\nLookup forms: 221, 0xDD, error 221, ERROR_CHECKOUT_REQUIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["221"]},{"id":176,"title":"ERROR_BAD_FILE_TYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["222","0xDE","error 222","ERROR_BAD_FILE_TYPE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","bad","file","type","the","being","saved","retrieved","has","been","blocked"],"errorCode":"222","eventId":"","severity":"High","summary":"The file type being saved or retrieved has been blocked.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 222; use the surrounding log entries to confirm it.","resolution":"1. Record where 222 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_FILE_TYPE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 222 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file type being saved or retrieved has been blocked.\n\nLookup forms: 222, 0xDE, error 222, ERROR_BAD_FILE_TYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["222"]},{"id":177,"title":"ERROR_FILE_TOO_LARGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["223","0xDF","error 223","ERROR_FILE_TOO_LARGE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","file","too","large","the","size","exceeds","limit","allowed","and","cannot","saved"],"errorCode":"223","eventId":"","severity":"Medium","summary":"The file size exceeds the limit allowed and cannot be saved.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 223; use the surrounding log entries to confirm it.","resolution":"1. Record where 223 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FILE_TOO_LARGE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 223 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file size exceeds the limit allowed and cannot be saved.\n\nLookup forms: 223, 0xDF, error 223, ERROR_FILE_TOO_LARGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["223"]},{"id":178,"title":"ERROR_FORMS_AUTH_REQUIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["224","0xE0","error 224","ERROR_FORMS_AUTH_REQUIRED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","forms","auth","required","access","denied","before","opening","files","this","location","you","must","first","add","the","web","site","your","trusted","sites","list","browse","and","select"],"errorCode":"224","eventId":"","severity":"High","summary":"Access Denied. Before opening files in this location, you must first add the web site to your trusted sites list, browse to the web site, and select the option to login automatically.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 224; use the surrounding log entries to confirm it.","resolution":"1. Record where 224 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Confirm the user or service identity has the required permissions and is not locked or disabled.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FORMS_AUTH_REQUIRED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Confirm the user or service identity has the required permissions and is not locked or disabled.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 224 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Access Denied. Before opening files in this location, you must first add the web site to your trusted sites list, browse to the web site, and select the option to login automatically.\n\nLookup forms: 224, 0xE0, error 224, ERROR_FORMS_AUTH_REQUIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["224"]},{"id":179,"title":"ERROR_VIRUS_INFECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["225","0xE1","error 225","ERROR_VIRUS_INFECTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","virus","infected","operation","did","not","complete","successfully","because","the","file","contains","potentially","unwanted","software"],"errorCode":"225","eventId":"","severity":"Low","summary":"Operation did not complete successfully because the file contains a virus or potentially unwanted software.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 225; use the surrounding log entries to confirm it.","resolution":"1. Record where 225 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_VIRUS_INFECTED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 225 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Operation did not complete successfully because the file contains a virus or potentially unwanted software.\n\nLookup forms: 225, 0xE1, error 225, ERROR_VIRUS_INFECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["225"]},{"id":180,"title":"ERROR_VIRUS_DELETED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["226","0xE2","error 226","ERROR_VIRUS_DELETED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","virus","deleted","this","file","contains","potentially","unwanted","software","and","cannot","opened","due","the","nature","has","been","removed","from","location"],"errorCode":"226","eventId":"","severity":"Medium","summary":"This file contains a virus or potentially unwanted software and cannot be opened. Due to the nature of this virus or potentially unwanted software, the file has been removed from this location.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 226; use the surrounding log entries to confirm it.","resolution":"1. Record where 226 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_VIRUS_DELETED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 226 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This file contains a virus or potentially unwanted software and cannot be opened. Due to the nature of this virus or potentially unwanted software, the file has been removed from this location.\n\nLookup forms: 226, 0xE2, error 226, ERROR_VIRUS_DELETED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["226"]},{"id":181,"title":"ERROR_PIPE_LOCAL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["229","0xE5","error 229","ERROR_PIPE_LOCAL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","pipe","local","the"],"errorCode":"229","eventId":"","severity":"Low","summary":"The pipe is local.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 229; use the surrounding log entries to confirm it.","resolution":"1. Record where 229 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PIPE_LOCAL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 229 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The pipe is local.\n\nLookup forms: 229, 0xE5, error 229, ERROR_PIPE_LOCAL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["229"]},{"id":182,"title":"ERROR_BAD_PIPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["230","0xE6","error 230","ERROR_BAD_PIPE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","bad","pipe","the","state","invalid"],"errorCode":"230","eventId":"","severity":"Medium","summary":"The pipe state is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 230; use the surrounding log entries to confirm it.","resolution":"1. Record where 230 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_PIPE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 230 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The pipe state is invalid.\n\nLookup forms: 230, 0xE6, error 230, ERROR_BAD_PIPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["230"]},{"id":183,"title":"ERROR_PIPE_BUSY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["231","0xE7","error 231","ERROR_PIPE_BUSY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","pipe","busy","all","instances","are"],"errorCode":"231","eventId":"","severity":"Medium","summary":"All pipe instances are busy.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 231; use the surrounding log entries to confirm it.","resolution":"1. Record where 231 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PIPE_BUSY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 231 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: All pipe instances are busy.\n\nLookup forms: 231, 0xE7, error 231, ERROR_PIPE_BUSY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["231"]},{"id":184,"title":"ERROR_NO_DATA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["232","0xE8","error 232","ERROR_NO_DATA","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","data","the","pipe","being","closed"],"errorCode":"232","eventId":"","severity":"Low","summary":"The pipe is being closed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 232; use the surrounding log entries to confirm it.","resolution":"1. Record where 232 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_DATA.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 232 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The pipe is being closed.\n\nLookup forms: 232, 0xE8, error 232, ERROR_NO_DATA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["232"]},{"id":185,"title":"ERROR_PIPE_NOT_CONNECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["233","0xE9","error 233","ERROR_PIPE_NOT_CONNECTED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","pipe","not","connected","process","the","other","end"],"errorCode":"233","eventId":"","severity":"Low","summary":"No process is on the other end of the pipe.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 233; use the surrounding log entries to confirm it.","resolution":"1. Record where 233 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PIPE_NOT_CONNECTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 233 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No process is on the other end of the pipe.\n\nLookup forms: 233, 0xE9, error 233, ERROR_PIPE_NOT_CONNECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["233"]},{"id":186,"title":"ERROR_MORE_DATA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["234","0xEA","error 234","ERROR_MORE_DATA","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","more","data","available"],"errorCode":"234","eventId":"","severity":"Low","summary":"More data is available.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 234; use the surrounding log entries to confirm it.","resolution":"1. Record where 234 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MORE_DATA.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 234 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: More data is available.\n\nLookup forms: 234, 0xEA, error 234, ERROR_MORE_DATA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["234"]},{"id":187,"title":"ERROR_VC_DISCONNECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["240","0xF0","error 240","ERROR_VC_DISCONNECTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","disconnected","the","session","was","canceled"],"errorCode":"240","eventId":"","severity":"Low","summary":"The session was canceled.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 240; use the surrounding log entries to confirm it.","resolution":"1. Record where 240 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_VC_DISCONNECTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 240 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The session was canceled.\n\nLookup forms: 240, 0xF0, error 240, ERROR_VC_DISCONNECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["240"]},{"id":188,"title":"ERROR_INVALID_EA_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["254","0xFE","error 254","ERROR_INVALID_EA_NAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","name","the","specified","extended","attribute","was"],"errorCode":"254","eventId":"","severity":"Medium","summary":"The specified extended attribute name was invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 254; use the surrounding log entries to confirm it.","resolution":"1. Record where 254 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_EA_NAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 254 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified extended attribute name was invalid.\n\nLookup forms: 254, 0xFE, error 254, ERROR_INVALID_EA_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["254"]},{"id":189,"title":"ERROR_EA_LIST_INCONSISTENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["255","0xFF","error 255","ERROR_EA_LIST_INCONSISTENT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","list","inconsistent","the","extended","attributes","are"],"errorCode":"255","eventId":"","severity":"Low","summary":"The extended attributes are inconsistent.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 255; use the surrounding log entries to confirm it.","resolution":"1. Record where 255 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EA_LIST_INCONSISTENT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 255 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The extended attributes are inconsistent.\n\nLookup forms: 255, 0xFF, error 255, ERROR_EA_LIST_INCONSISTENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["255"]},{"id":190,"title":"WAIT_TIMEOUT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["258","0x102","error 258","WAIT_TIMEOUT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wait","timeout","the","operation","timed","out"],"errorCode":"258","eventId":"","severity":"Low","summary":"The wait operation timed out.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 258; use the surrounding log entries to confirm it.","resolution":"1. Record where 258 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WAIT_TIMEOUT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 258 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The wait operation timed out.\n\nLookup forms: 258, 0x102, error 258, WAIT_TIMEOUT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["258"]},{"id":191,"title":"ERROR_NO_MORE_ITEMS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["259","0x103","error 259","ERROR_NO_MORE_ITEMS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","more","items","data","available"],"errorCode":"259","eventId":"","severity":"Low","summary":"No more data is available.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 259; use the surrounding log entries to confirm it.","resolution":"1. Record where 259 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_MORE_ITEMS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 259 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No more data is available.\n\nLookup forms: 259, 0x103, error 259, ERROR_NO_MORE_ITEMS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["259"]},{"id":192,"title":"ERROR_CANNOT_COPY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["266","0x10A","error 266","ERROR_CANNOT_COPY","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","cannot","copy","the","functions","used"],"errorCode":"266","eventId":"","severity":"Medium","summary":"The copy functions cannot be used.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 266; use the surrounding log entries to confirm it.","resolution":"1. Record where 266 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANNOT_COPY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 266 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The copy functions cannot be used.\n\nLookup forms: 266, 0x10A, error 266, ERROR_CANNOT_COPY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["266"]},{"id":193,"title":"ERROR_DIRECTORY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["267","0x10B","error 267","ERROR_DIRECTORY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","directory","the","name","invalid"],"errorCode":"267","eventId":"","severity":"Medium","summary":"The directory name is invalid.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 267; use the surrounding log entries to confirm it.","resolution":"1. Record where 267 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DIRECTORY.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 267 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory name is invalid.\n\nLookup forms: 267, 0x10B, error 267, ERROR_DIRECTORY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["267"]},{"id":194,"title":"ERROR_EAS_DIDNT_FIT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["275","0x113","error 275","ERROR_EAS_DIDNT_FIT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","eas","didnt","fit","the","extended","attributes","did","not","buffer"],"errorCode":"275","eventId":"","severity":"Low","summary":"The extended attributes did not fit in the buffer.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 275; use the surrounding log entries to confirm it.","resolution":"1. Record where 275 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EAS_DIDNT_FIT.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 275 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The extended attributes did not fit in the buffer.\n\nLookup forms: 275, 0x113, error 275, ERROR_EAS_DIDNT_FIT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["275"]},{"id":195,"title":"ERROR_EA_FILE_CORRUPT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["276","0x114","error 276","ERROR_EA_FILE_CORRUPT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","file","corrupt","the","extended","attribute","mounted","system"],"errorCode":"276","eventId":"","severity":"Critical","summary":"The extended attribute file on the mounted file system is corrupt.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 276; use the surrounding log entries to confirm it.","resolution":"1. Record where 276 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EA_FILE_CORRUPT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 276 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The extended attribute file on the mounted file system is corrupt.\n\nLookup forms: 276, 0x114, error 276, ERROR_EA_FILE_CORRUPT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["276"]},{"id":196,"title":"ERROR_EA_TABLE_FULL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["277","0x115","error 277","ERROR_EA_TABLE_FULL","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","table","full","the","extended","attribute","file"],"errorCode":"277","eventId":"","severity":"Low","summary":"The extended attribute table file is full.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 277; use the surrounding log entries to confirm it.","resolution":"1. Record where 277 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EA_TABLE_FULL.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 277 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The extended attribute table file is full.\n\nLookup forms: 277, 0x115, error 277, ERROR_EA_TABLE_FULL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["277"]},{"id":197,"title":"ERROR_INVALID_EA_HANDLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["278","0x116","error 278","ERROR_INVALID_EA_HANDLE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","invalid","handle","the","specified","extended","attribute"],"errorCode":"278","eventId":"","severity":"Medium","summary":"The specified extended attribute handle is invalid.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 278; use the surrounding log entries to confirm it.","resolution":"1. Record where 278 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_EA_HANDLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 278 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified extended attribute handle is invalid.\n\nLookup forms: 278, 0x116, error 278, ERROR_INVALID_EA_HANDLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["278"]},{"id":198,"title":"ERROR_EAS_NOT_SUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["282","0x11A","error 282","ERROR_EAS_NOT_SUPPORTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","eas","not","supported","the","mounted","file","system","does","support","extended","attributes"],"errorCode":"282","eventId":"","severity":"Low","summary":"The mounted file system does not support extended attributes.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 282; use the surrounding log entries to confirm it.","resolution":"1. Record where 282 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EAS_NOT_SUPPORTED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 282 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The mounted file system does not support extended attributes.\n\nLookup forms: 282, 0x11A, error 282, ERROR_EAS_NOT_SUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["282"]},{"id":199,"title":"ERROR_NOT_OWNER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["288","0x120","error 288","ERROR_NOT_OWNER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","not","owner","attempt","release","mutex","owned","caller"],"errorCode":"288","eventId":"","severity":"Low","summary":"Attempt to release mutex not owned by caller.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 288; use the surrounding log entries to confirm it.","resolution":"1. Record where 288 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_OWNER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 288 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Attempt to release mutex not owned by caller.\n\nLookup forms: 288, 0x120, error 288, ERROR_NOT_OWNER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["288"]},{"id":200,"title":"ERROR_TOO_MANY_POSTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["298","0x12A","error 298","ERROR_TOO_MANY_POSTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","too","many","posts","were","made","semaphore"],"errorCode":"298","eventId":"","severity":"Low","summary":"Too many posts were made to a semaphore.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 298; use the surrounding log entries to confirm it.","resolution":"1. Record where 298 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TOO_MANY_POSTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 298 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Too many posts were made to a semaphore.\n\nLookup forms: 298, 0x12A, error 298, ERROR_TOO_MANY_POSTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["298"]},{"id":201,"title":"ERROR_PARTIAL_COPY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["299","0x12B","error 299","ERROR_PARTIAL_COPY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","partial","copy","only","part","readprocessmemory","writeprocessmemory","request","was","completed"],"errorCode":"299","eventId":"","severity":"Low","summary":"Only part of a ReadProcessMemory or WriteProcessMemory request was completed.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 299; use the surrounding log entries to confirm it.","resolution":"1. Record where 299 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PARTIAL_COPY.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 299 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Only part of a ReadProcessMemory or WriteProcessMemory request was completed.\n\nLookup forms: 299, 0x12B, error 299, ERROR_PARTIAL_COPY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["299"]},{"id":202,"title":"ERROR_OPLOCK_NOT_GRANTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["300","0x12C","error 300","ERROR_OPLOCK_NOT_GRANTED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","oplock","not","granted","the","request","denied"],"errorCode":"300","eventId":"","severity":"Low","summary":"The oplock request is denied.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 300; use the surrounding log entries to confirm it.","resolution":"1. Record where 300 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_OPLOCK_NOT_GRANTED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 300 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The oplock request is denied.\n\nLookup forms: 300, 0x12C, error 300, ERROR_OPLOCK_NOT_GRANTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["300"]},{"id":203,"title":"ERROR_INVALID_OPLOCK_PROTOCOL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["301","0x12D","error 301","ERROR_INVALID_OPLOCK_PROTOCOL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","oplock","protocol","acknowledgment","was","received","the","system"],"errorCode":"301","eventId":"","severity":"Medium","summary":"An invalid oplock acknowledgment was received by the system.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 301; use the surrounding log entries to confirm it.","resolution":"1. Record where 301 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_OPLOCK_PROTOCOL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 301 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An invalid oplock acknowledgment was received by the system.\n\nLookup forms: 301, 0x12D, error 301, ERROR_INVALID_OPLOCK_PROTOCOL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["301"]},{"id":204,"title":"ERROR_DISK_TOO_FRAGMENTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["302","0x12E","error 302","ERROR_DISK_TOO_FRAGMENTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","disk","too","fragmented","the","volume","complete","this","operation"],"errorCode":"302","eventId":"","severity":"Low","summary":"The volume is too fragmented to complete this operation.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 302; use the surrounding log entries to confirm it.","resolution":"1. Record where 302 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DISK_TOO_FRAGMENTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 302 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The volume is too fragmented to complete this operation.\n\nLookup forms: 302, 0x12E, error 302, ERROR_DISK_TOO_FRAGMENTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["302"]},{"id":205,"title":"ERROR_DELETE_PENDING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["303","0x12F","error 303","ERROR_DELETE_PENDING","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","delete","pending","the","file","cannot","opened","because","process","being","deleted"],"errorCode":"303","eventId":"","severity":"Medium","summary":"The file cannot be opened because it is in the process of being deleted.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 303; use the surrounding log entries to confirm it.","resolution":"1. Record where 303 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DELETE_PENDING.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 303 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file cannot be opened because it is in the process of being deleted.\n\nLookup forms: 303, 0x12F, error 303, ERROR_DELETE_PENDING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["303"]},{"id":206,"title":"ERROR_INCOMPATIBLE_WITH_GLOBAL_SHORT_NAME_REGISTRY_SETTING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["304","0x130","error 304","ERROR_INCOMPATIBLE_WITH_GLOBAL_SHORT_NAME_REGISTRY_SETTING","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","incompatible","with","global","short","name","registry","setting","settings","may","not","changed","this","volume","due","the"],"errorCode":"304","eventId":"","severity":"Low","summary":"Short name settings may not be changed on this volume due to the global registry setting.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 304; use the surrounding log entries to confirm it.","resolution":"1. Record where 304 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INCOMPATIBLE_WITH_GLOBAL_SHORT_NAME_REGISTRY_SETTING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 304 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Short name settings may not be changed on this volume due to the global registry setting.\n\nLookup forms: 304, 0x130, error 304, ERROR_INCOMPATIBLE_WITH_GLOBAL_SHORT_NAME_REGISTRY_SETTING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["304"]},{"id":207,"title":"ERROR_SHORT_NAMES_NOT_ENABLED_ON_VOLUME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["305","0x131","error 305","ERROR_SHORT_NAMES_NOT_ENABLED_ON_VOLUME","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","short","names","not","enabled","volume","are","this"],"errorCode":"305","eventId":"","severity":"Low","summary":"Short names are not enabled on this volume.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 305; use the surrounding log entries to confirm it.","resolution":"1. Record where 305 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SHORT_NAMES_NOT_ENABLED_ON_VOLUME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 305 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Short names are not enabled on this volume.\n\nLookup forms: 305, 0x131, error 305, ERROR_SHORT_NAMES_NOT_ENABLED_ON_VOLUME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["305"]},{"id":208,"title":"ERROR_SECURITY_STREAM_IS_INCONSISTENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["306","0x132","error 306","ERROR_SECURITY_STREAM_IS_INCONSISTENT","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","security","stream","inconsistent","the","for","given","volume","state","please","run","chkdsk"],"errorCode":"306","eventId":"","severity":"Low","summary":"The security stream for the given volume is in an inconsistent state. Please run CHKDSK on the volume.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 306; use the surrounding log entries to confirm it.","resolution":"1. Record where 306 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SECURITY_STREAM_IS_INCONSISTENT.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 306 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The security stream for the given volume is in an inconsistent state. Please run CHKDSK on the volume.\n\nLookup forms: 306, 0x132, error 306, ERROR_SECURITY_STREAM_IS_INCONSISTENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["306"]},{"id":209,"title":"ERROR_INVALID_LOCK_RANGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["307","0x133","error 307","ERROR_INVALID_LOCK_RANGE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","invalid","lock","range","requested","file","operation","cannot","processed","due","byte"],"errorCode":"307","eventId":"","severity":"Medium","summary":"A requested file lock operation cannot be processed due to an invalid byte range.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 307; use the surrounding log entries to confirm it.","resolution":"1. Record where 307 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_LOCK_RANGE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 307 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A requested file lock operation cannot be processed due to an invalid byte range.\n\nLookup forms: 307, 0x133, error 307, ERROR_INVALID_LOCK_RANGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["307"]},{"id":210,"title":"ERROR_IMAGE_SUBSYSTEM_NOT_PRESENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["308","0x134","error 308","ERROR_IMAGE_SUBSYSTEM_NOT_PRESENT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","image","subsystem","not","present","the","needed","support","type"],"errorCode":"308","eventId":"","severity":"Low","summary":"The subsystem needed to support the image type is not present.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 308; use the surrounding log entries to confirm it.","resolution":"1. Record where 308 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IMAGE_SUBSYSTEM_NOT_PRESENT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 308 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The subsystem needed to support the image type is not present.\n\nLookup forms: 308, 0x134, error 308, ERROR_IMAGE_SUBSYSTEM_NOT_PRESENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["308"]},{"id":211,"title":"ERROR_NOTIFICATION_GUID_ALREADY_DEFINED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["309","0x135","error 309","ERROR_NOTIFICATION_GUID_ALREADY_DEFINED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","notification","guid","already","defined","the","specified","file","has","associated","with"],"errorCode":"309","eventId":"","severity":"Low","summary":"The specified file already has a notification GUID associated with it.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 309; use the surrounding log entries to confirm it.","resolution":"1. Record where 309 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOTIFICATION_GUID_ALREADY_DEFINED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 309 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified file already has a notification GUID associated with it.\n\nLookup forms: 309, 0x135, error 309, ERROR_NOTIFICATION_GUID_ALREADY_DEFINED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["309"]},{"id":212,"title":"ERROR_INVALID_EXCEPTION_HANDLER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["310","0x136","error 310","ERROR_INVALID_EXCEPTION_HANDLER","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","invalid","exception","handler","routine","has","been","detected"],"errorCode":"310","eventId":"","severity":"Medium","summary":"An invalid exception handler routine has been detected.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 310; use the surrounding log entries to confirm it.","resolution":"1. Record where 310 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_EXCEPTION_HANDLER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 310 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An invalid exception handler routine has been detected.\n\nLookup forms: 310, 0x136, error 310, ERROR_INVALID_EXCEPTION_HANDLER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["310"]},{"id":213,"title":"ERROR_DUPLICATE_PRIVILEGES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["311","0x137","error 311","ERROR_DUPLICATE_PRIVILEGES","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","duplicate","privileges","were","specified","for","the","token"],"errorCode":"311","eventId":"","severity":"Low","summary":"Duplicate privileges were specified for the token.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 311; use the surrounding log entries to confirm it.","resolution":"1. Record where 311 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DUPLICATE_PRIVILEGES.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 311 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Duplicate privileges were specified for the token.\n\nLookup forms: 311, 0x137, error 311, ERROR_DUPLICATE_PRIVILEGES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["311"]},{"id":214,"title":"ERROR_NO_RANGES_PROCESSED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["312","0x138","error 312","ERROR_NO_RANGES_PROCESSED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","ranges","processed","for","the","specified","operation","were","able"],"errorCode":"312","eventId":"","severity":"Low","summary":"No ranges for the specified operation were able to be processed.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 312; use the surrounding log entries to confirm it.","resolution":"1. Record where 312 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_RANGES_PROCESSED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 312 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No ranges for the specified operation were able to be processed.\n\nLookup forms: 312, 0x138, error 312, ERROR_NO_RANGES_PROCESSED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["312"]},{"id":215,"title":"ERROR_NOT_ALLOWED_ON_SYSTEM_FILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["313","0x139","error 313","ERROR_NOT_ALLOWED_ON_SYSTEM_FILE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","not","allowed","system","file","operation","internal"],"errorCode":"313","eventId":"","severity":"Low","summary":"Operation is not allowed on a file system internal file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 313; use the surrounding log entries to confirm it.","resolution":"1. Record where 313 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_ALLOWED_ON_SYSTEM_FILE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 313 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Operation is not allowed on a file system internal file.\n\nLookup forms: 313, 0x139, error 313, ERROR_NOT_ALLOWED_ON_SYSTEM_FILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["313"]},{"id":216,"title":"ERROR_DISK_RESOURCES_EXHAUSTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["314","0x13A","error 314","ERROR_DISK_RESOURCES_EXHAUSTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","disk","resources","exhausted","the","physical","this","have","been"],"errorCode":"314","eventId":"","severity":"Low","summary":"The physical resources of this disk have been exhausted.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 314; use the surrounding log entries to confirm it.","resolution":"1. Record where 314 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DISK_RESOURCES_EXHAUSTED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 314 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The physical resources of this disk have been exhausted.\n\nLookup forms: 314, 0x13A, error 314, ERROR_DISK_RESOURCES_EXHAUSTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["314"]},{"id":217,"title":"ERROR_INVALID_TOKEN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["315","0x13B","error 315","ERROR_INVALID_TOKEN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","token","the","representing","data"],"errorCode":"315","eventId":"","severity":"Medium","summary":"The token representing the data is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 315; use the surrounding log entries to confirm it.","resolution":"1. Record where 315 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_TOKEN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 315 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The token representing the data is invalid.\n\nLookup forms: 315, 0x13B, error 315, ERROR_INVALID_TOKEN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["315"]},{"id":218,"title":"ERROR_DEVICE_FEATURE_NOT_SUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["316","0x13C","error 316","ERROR_DEVICE_FEATURE_NOT_SUPPORTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","device","feature","not","supported","the","does","support","command"],"errorCode":"316","eventId":"","severity":"Low","summary":"The device does not support the command feature.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 316; use the surrounding log entries to confirm it.","resolution":"1. Record where 316 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEVICE_FEATURE_NOT_SUPPORTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 316 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The device does not support the command feature.\n\nLookup forms: 316, 0x13C, error 316, ERROR_DEVICE_FEATURE_NOT_SUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["316"]},{"id":219,"title":"ERROR_MR_MID_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["317","0x13D","error 317","ERROR_MR_MID_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","mid","not","found","the","system","cannot","find","message","text","for","number","file"],"errorCode":"317","eventId":"","severity":"Medium","summary":"The system cannot find message text for message number 0x%1 in the message file for %2.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 317; use the surrounding log entries to confirm it.","resolution":"1. Record where 317 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MR_MID_NOT_FOUND.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 317 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system cannot find message text for message number 0x%1 in the message file for %2.\n\nLookup forms: 317, 0x13D, error 317, ERROR_MR_MID_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["317"]},{"id":220,"title":"ERROR_SCOPE_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["318","0x13E","error 318","ERROR_SCOPE_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","scope","not","found","the","specified","was"],"errorCode":"318","eventId":"","severity":"Medium","summary":"The scope specified was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 318; use the surrounding log entries to confirm it.","resolution":"1. Record where 318 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SCOPE_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 318 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The scope specified was not found.\n\nLookup forms: 318, 0x13E, error 318, ERROR_SCOPE_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["318"]},{"id":221,"title":"ERROR_UNDEFINED_SCOPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["319","0x13F","error 319","ERROR_UNDEFINED_SCOPE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","undefined","scope","the","central","access","policy","specified","not","defined","target","machine"],"errorCode":"319","eventId":"","severity":"Low","summary":"The Central Access Policy specified is not defined on the target machine.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 319; use the surrounding log entries to confirm it.","resolution":"1. Record where 319 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNDEFINED_SCOPE.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 319 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Central Access Policy specified is not defined on the target machine.\n\nLookup forms: 319, 0x13F, error 319, ERROR_UNDEFINED_SCOPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["319"]},{"id":222,"title":"ERROR_INVALID_CAP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["320","0x140","error 320","ERROR_INVALID_CAP","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","invalid","cap","the","central","access","policy","obtained","from","active","directory"],"errorCode":"320","eventId":"","severity":"Medium","summary":"The Central Access Policy obtained from Active Directory is invalid.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 320; use the surrounding log entries to confirm it.","resolution":"1. Record where 320 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Confirm the user or service identity has the required permissions and is not locked or disabled.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_CAP.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Confirm the user or service identity has the required permissions and is not locked or disabled.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 320 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Central Access Policy obtained from Active Directory is invalid.\n\nLookup forms: 320, 0x140, error 320, ERROR_INVALID_CAP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["320"]},{"id":223,"title":"ERROR_DEVICE_UNREACHABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["321","0x141","error 321","ERROR_DEVICE_UNREACHABLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","device","unreachable","the"],"errorCode":"321","eventId":"","severity":"Low","summary":"The device is unreachable.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 321; use the surrounding log entries to confirm it.","resolution":"1. Record where 321 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEVICE_UNREACHABLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 321 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The device is unreachable.\n\nLookup forms: 321, 0x141, error 321, ERROR_DEVICE_UNREACHABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["321"]},{"id":224,"title":"ERROR_DEVICE_NO_RESOURCES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["322","0x142","error 322","ERROR_DEVICE_NO_RESOURCES","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","device","resources","the","target","has","insufficient","complete","operation"],"errorCode":"322","eventId":"","severity":"Low","summary":"The target device has insufficient resources to complete the operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 322; use the surrounding log entries to confirm it.","resolution":"1. Record where 322 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEVICE_NO_RESOURCES.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 322 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The target device has insufficient resources to complete the operation.\n\nLookup forms: 322, 0x142, error 322, ERROR_DEVICE_NO_RESOURCES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["322"]},{"id":225,"title":"ERROR_DATA_CHECKSUM_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["323","0x143","error 323","ERROR_DATA_CHECKSUM_ERROR","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","data","checksum","integrity","occurred","the","file","stream","corrupt"],"errorCode":"323","eventId":"","severity":"Critical","summary":"A data integrity checksum error occurred. Data in the file stream is corrupt.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 323; use the surrounding log entries to confirm it.","resolution":"1. Record where 323 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DATA_CHECKSUM_ERROR.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 323 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A data integrity checksum error occurred. Data in the file stream is corrupt.\n\nLookup forms: 323, 0x143, error 323, ERROR_DATA_CHECKSUM_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["323"]},{"id":226,"title":"ERROR_INTERMIXED_KERNEL_EA_OPERATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["324","0x144","error 324","ERROR_INTERMIXED_KERNEL_EA_OPERATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","intermixed","kernel","operation","attempt","was","made","modify","both","and","normal","extended","attribute","the","same"],"errorCode":"324","eventId":"","severity":"Low","summary":"An attempt was made to modify both a KERNEL and normal Extended Attribute (EA) in the same operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 324; use the surrounding log entries to confirm it.","resolution":"1. Record where 324 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INTERMIXED_KERNEL_EA_OPERATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 324 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt was made to modify both a KERNEL and normal Extended Attribute (EA) in the same operation.\n\nLookup forms: 324, 0x144, error 324, ERROR_INTERMIXED_KERNEL_EA_OPERATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["324"]},{"id":227,"title":"ERROR_FILE_LEVEL_TRIM_NOT_SUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["326","0x146","error 326","ERROR_FILE_LEVEL_TRIM_NOT_SUPPORTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","file","level","trim","not","supported","device","does","support"],"errorCode":"326","eventId":"","severity":"Low","summary":"Device does not support file-level TRIM.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 326; use the surrounding log entries to confirm it.","resolution":"1. Record where 326 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FILE_LEVEL_TRIM_NOT_SUPPORTED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 326 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Device does not support file-level TRIM.\n\nLookup forms: 326, 0x146, error 326, ERROR_FILE_LEVEL_TRIM_NOT_SUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["326"]},{"id":228,"title":"ERROR_OFFSET_ALIGNMENT_VIOLATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["327","0x147","error 327","ERROR_OFFSET_ALIGNMENT_VIOLATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","offset","alignment","violation","the","command","specified","data","that","does","not","align","device","granularity"],"errorCode":"327","eventId":"","severity":"Low","summary":"The command specified a data offset that does not align to the device's granularity/alignment.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 327; use the surrounding log entries to confirm it.","resolution":"1. Record where 327 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_OFFSET_ALIGNMENT_VIOLATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 327 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The command specified a data offset that does not align to the device's granularity/alignment.\n\nLookup forms: 327, 0x147, error 327, ERROR_OFFSET_ALIGNMENT_VIOLATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["327"]},{"id":229,"title":"ERROR_INVALID_FIELD_IN_PARAMETER_LIST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["328","0x148","error 328","ERROR_INVALID_FIELD_IN_PARAMETER_LIST","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","field","parameter","list","the","command","specified","its"],"errorCode":"328","eventId":"","severity":"Medium","summary":"The command specified an invalid field in its parameter list.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 328; use the surrounding log entries to confirm it.","resolution":"1. Record where 328 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_FIELD_IN_PARAMETER_LIST.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 328 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The command specified an invalid field in its parameter list.\n\nLookup forms: 328, 0x148, error 328, ERROR_INVALID_FIELD_IN_PARAMETER_LIST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["328"]},{"id":230,"title":"ERROR_OPERATION_IN_PROGRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["329","0x149","error 329","ERROR_OPERATION_IN_PROGRESS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","operation","progress","currently","with","the","device"],"errorCode":"329","eventId":"","severity":"Low","summary":"An operation is currently in progress with the device.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 329; use the surrounding log entries to confirm it.","resolution":"1. Record where 329 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_OPERATION_IN_PROGRESS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 329 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An operation is currently in progress with the device.\n\nLookup forms: 329, 0x149, error 329, ERROR_OPERATION_IN_PROGRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["329"]},{"id":231,"title":"ERROR_BAD_DEVICE_PATH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["330","0x14A","error 330","ERROR_BAD_DEVICE_PATH","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","bad","device","path","attempt","was","made","send","down","the","command","via","invalid","target"],"errorCode":"330","eventId":"","severity":"Medium","summary":"An attempt was made to send down the command via an invalid path to the target device.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 330; use the surrounding log entries to confirm it.","resolution":"1. Record where 330 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_DEVICE_PATH.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 330 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt was made to send down the command via an invalid path to the target device.\n\nLookup forms: 330, 0x14A, error 330, ERROR_BAD_DEVICE_PATH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["330"]},{"id":232,"title":"ERROR_TOO_MANY_DESCRIPTORS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["331","0x14B","error 331","ERROR_TOO_MANY_DESCRIPTORS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","too","many","descriptors","the","command","specified","number","that","exceeded","maximum","supported","device"],"errorCode":"331","eventId":"","severity":"Low","summary":"The command specified a number of descriptors that exceeded the maximum supported by the device.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 331; use the surrounding log entries to confirm it.","resolution":"1. Record where 331 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TOO_MANY_DESCRIPTORS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 331 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The command specified a number of descriptors that exceeded the maximum supported by the device.\n\nLookup forms: 331, 0x14B, error 331, ERROR_TOO_MANY_DESCRIPTORS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["331"]},{"id":233,"title":"ERROR_SCRUB_DATA_DISABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["332","0x14C","error 332","ERROR_SCRUB_DATA_DISABLED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","scrub","data","disabled","the","specified","file"],"errorCode":"332","eventId":"","severity":"Low","summary":"Scrub is disabled on the specified file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 332; use the surrounding log entries to confirm it.","resolution":"1. Record where 332 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SCRUB_DATA_DISABLED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 332 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Scrub is disabled on the specified file.\n\nLookup forms: 332, 0x14C, error 332, ERROR_SCRUB_DATA_DISABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["332"]},{"id":234,"title":"ERROR_NOT_REDUNDANT_STORAGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["333","0x14D","error 333","ERROR_NOT_REDUNDANT_STORAGE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","not","redundant","storage","the","device","does","provide","redundancy"],"errorCode":"333","eventId":"","severity":"Low","summary":"The storage device does not provide redundancy.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 333; use the surrounding log entries to confirm it.","resolution":"1. Record where 333 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_REDUNDANT_STORAGE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 333 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The storage device does not provide redundancy.\n\nLookup forms: 333, 0x14D, error 333, ERROR_NOT_REDUNDANT_STORAGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["333"]},{"id":235,"title":"ERROR_RESIDENT_FILE_NOT_SUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["334","0x14E","error 334","ERROR_RESIDENT_FILE_NOT_SUPPORTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","resident","file","not","supported","operation"],"errorCode":"334","eventId":"","severity":"Medium","summary":"An operation is not supported on a resident file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 334; use the surrounding log entries to confirm it.","resolution":"1. Record where 334 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESIDENT_FILE_NOT_SUPPORTED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 334 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An operation is not supported on a resident file.\n\nLookup forms: 334, 0x14E, error 334, ERROR_RESIDENT_FILE_NOT_SUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["334"]},{"id":236,"title":"ERROR_COMPRESSED_FILE_NOT_SUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["335","0x14F","error 335","ERROR_COMPRESSED_FILE_NOT_SUPPORTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","compressed","file","not","supported","operation"],"errorCode":"335","eventId":"","severity":"Medium","summary":"An operation is not supported on a compressed file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 335; use the surrounding log entries to confirm it.","resolution":"1. Record where 335 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_COMPRESSED_FILE_NOT_SUPPORTED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 335 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An operation is not supported on a compressed file.\n\nLookup forms: 335, 0x14F, error 335, ERROR_COMPRESSED_FILE_NOT_SUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["335"]},{"id":237,"title":"ERROR_DIRECTORY_NOT_SUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["336","0x150","error 336","ERROR_DIRECTORY_NOT_SUPPORTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","directory","not","supported","operation"],"errorCode":"336","eventId":"","severity":"Medium","summary":"An operation is not supported on a directory.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 336; use the surrounding log entries to confirm it.","resolution":"1. Record where 336 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DIRECTORY_NOT_SUPPORTED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 336 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An operation is not supported on a directory.\n\nLookup forms: 336, 0x150, error 336, ERROR_DIRECTORY_NOT_SUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["336"]},{"id":238,"title":"ERROR_NOT_READ_FROM_COPY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["337","0x151","error 337","ERROR_NOT_READ_FROM_COPY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","not","read","from","copy","the","specified","requested","data","could"],"errorCode":"337","eventId":"","severity":"Low","summary":"The specified copy of the requested data could not be read.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 337; use the surrounding log entries to confirm it.","resolution":"1. Record where 337 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_READ_FROM_COPY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 337 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified copy of the requested data could not be read.\n\nLookup forms: 337, 0x151, error 337, ERROR_NOT_READ_FROM_COPY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["337"]},{"id":239,"title":"ERROR_FAIL_NOACTION_REBOOT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["350","0x15E","error 350","ERROR_FAIL_NOACTION_REBOOT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","fail","noaction","reboot","action","was","taken","system","required"],"errorCode":"350","eventId":"","severity":"Low","summary":"No action was taken as a system reboot is required.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 350; use the surrounding log entries to confirm it.","resolution":"1. Record where 350 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FAIL_NOACTION_REBOOT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 350 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No action was taken as a system reboot is required.\n\nLookup forms: 350, 0x15E, error 350, ERROR_FAIL_NOACTION_REBOOT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["350"]},{"id":240,"title":"ERROR_FAIL_SHUTDOWN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["351","0x15F","error 351","ERROR_FAIL_SHUTDOWN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","fail","shutdown","the","operation","failed"],"errorCode":"351","eventId":"","severity":"High","summary":"The shutdown operation failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 351; use the surrounding log entries to confirm it.","resolution":"1. Record where 351 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FAIL_SHUTDOWN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 351 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The shutdown operation failed.\n\nLookup forms: 351, 0x15F, error 351, ERROR_FAIL_SHUTDOWN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["351"]},{"id":241,"title":"ERROR_FAIL_RESTART","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["352","0x160","error 352","ERROR_FAIL_RESTART","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","fail","restart","the","operation","failed"],"errorCode":"352","eventId":"","severity":"High","summary":"The restart operation failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 352; use the surrounding log entries to confirm it.","resolution":"1. Record where 352 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FAIL_RESTART.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 352 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The restart operation failed.\n\nLookup forms: 352, 0x160, error 352, ERROR_FAIL_RESTART. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["352"]},{"id":242,"title":"ERROR_MAX_SESSIONS_REACHED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["353","0x161","error 353","ERROR_MAX_SESSIONS_REACHED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","max","sessions","reached","the","maximum","number","has","been"],"errorCode":"353","eventId":"","severity":"Low","summary":"The maximum number of sessions has been reached.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 353; use the surrounding log entries to confirm it.","resolution":"1. Record where 353 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MAX_SESSIONS_REACHED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 353 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The maximum number of sessions has been reached.\n\nLookup forms: 353, 0x161, error 353, ERROR_MAX_SESSIONS_REACHED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["353"]},{"id":243,"title":"ERROR_THREAD_MODE_ALREADY_BACKGROUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["400","0x190","error 400","ERROR_THREAD_MODE_ALREADY_BACKGROUND","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","thread","mode","already","background","the","processing"],"errorCode":"400","eventId":"","severity":"Low","summary":"The thread is already in background processing mode.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 400; use the surrounding log entries to confirm it.","resolution":"1. Record where 400 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_THREAD_MODE_ALREADY_BACKGROUND.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 400 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The thread is already in background processing mode.\n\nLookup forms: 400, 0x190, error 400, ERROR_THREAD_MODE_ALREADY_BACKGROUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["400"]},{"id":244,"title":"ERROR_THREAD_MODE_NOT_BACKGROUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["401","0x191","error 401","ERROR_THREAD_MODE_NOT_BACKGROUND","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","thread","mode","not","background","the","processing"],"errorCode":"401","eventId":"","severity":"Low","summary":"The thread is not in background processing mode.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 401; use the surrounding log entries to confirm it.","resolution":"1. Record where 401 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_THREAD_MODE_NOT_BACKGROUND.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 401 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The thread is not in background processing mode.\n\nLookup forms: 401, 0x191, error 401, ERROR_THREAD_MODE_NOT_BACKGROUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["401"]},{"id":245,"title":"ERROR_PROCESS_MODE_ALREADY_BACKGROUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["402","0x192","error 402","ERROR_PROCESS_MODE_ALREADY_BACKGROUND","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","process","mode","already","background","the","processing"],"errorCode":"402","eventId":"","severity":"Low","summary":"The process is already in background processing mode.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 402; use the surrounding log entries to confirm it.","resolution":"1. Record where 402 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PROCESS_MODE_ALREADY_BACKGROUND.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 402 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The process is already in background processing mode.\n\nLookup forms: 402, 0x192, error 402, ERROR_PROCESS_MODE_ALREADY_BACKGROUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["402"]},{"id":246,"title":"ERROR_PROCESS_MODE_NOT_BACKGROUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["403","0x193","error 403","ERROR_PROCESS_MODE_NOT_BACKGROUND","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","process","mode","not","background","the","processing"],"errorCode":"403","eventId":"","severity":"Low","summary":"The process is not in background processing mode.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 403; use the surrounding log entries to confirm it.","resolution":"1. Record where 403 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PROCESS_MODE_NOT_BACKGROUND.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 403 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The process is not in background processing mode.\n\nLookup forms: 403, 0x193, error 403, ERROR_PROCESS_MODE_NOT_BACKGROUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["403"]},{"id":247,"title":"ERROR_INVALID_ADDRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["487","0x1E7","error 487","ERROR_INVALID_ADDRESS","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","invalid","address","attempt","access"],"errorCode":"487","eventId":"","severity":"Medium","summary":"Attempt to access invalid address.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 487; use the surrounding log entries to confirm it.","resolution":"1. Record where 487 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_ADDRESS.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 487 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Attempt to access invalid address.\n\nLookup forms: 487, 0x1E7, error 487, ERROR_INVALID_ADDRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["487"]},{"id":248,"title":"ERROR_USER_PROFILE_LOAD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["500","0x1F4","error 500","ERROR_USER_PROFILE_LOAD","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","user","profile","load","cannot","loaded"],"errorCode":"500","eventId":"","severity":"Medium","summary":"User profile cannot be loaded.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 500; use the surrounding log entries to confirm it.","resolution":"1. Record where 500 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_USER_PROFILE_LOAD.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 500 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: User profile cannot be loaded.\n\nLookup forms: 500, 0x1F4, error 500, ERROR_USER_PROFILE_LOAD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["500"]},{"id":249,"title":"ERROR_ARITHMETIC_OVERFLOW","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["534","0x216","error 534","ERROR_ARITHMETIC_OVERFLOW","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","arithmetic","overflow","result","exceeded","bits"],"errorCode":"534","eventId":"","severity":"Low","summary":"Arithmetic result exceeded 32 bits.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 534; use the surrounding log entries to confirm it.","resolution":"1. Record where 534 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ARITHMETIC_OVERFLOW.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 534 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Arithmetic result exceeded 32 bits.\n\nLookup forms: 534, 0x216, error 534, ERROR_ARITHMETIC_OVERFLOW. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["534"]},{"id":250,"title":"ERROR_PIPE_CONNECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["535","0x217","error 535","ERROR_PIPE_CONNECTED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","pipe","connected","there","process","other","end","the"],"errorCode":"535","eventId":"","severity":"Low","summary":"There is a process on other end of the pipe.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 535; use the surrounding log entries to confirm it.","resolution":"1. Record where 535 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PIPE_CONNECTED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 535 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There is a process on other end of the pipe.\n\nLookup forms: 535, 0x217, error 535, ERROR_PIPE_CONNECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["535"]},{"id":251,"title":"ERROR_PIPE_LISTENING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["536","0x218","error 536","ERROR_PIPE_LISTENING","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","pipe","listening","waiting","for","process","open","the","other","end"],"errorCode":"536","eventId":"","severity":"Low","summary":"Waiting for a process to open the other end of the pipe.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 536; use the surrounding log entries to confirm it.","resolution":"1. Record where 536 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PIPE_LISTENING.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 536 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Waiting for a process to open the other end of the pipe.\n\nLookup forms: 536, 0x218, error 536, ERROR_PIPE_LISTENING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["536"]},{"id":252,"title":"ERROR_VERIFIER_STOP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["537","0x219","error 537","ERROR_VERIFIER_STOP","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","verifier","stop","application","has","found","the","current","process"],"errorCode":"537","eventId":"","severity":"Low","summary":"Application verifier has found an error in the current process.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 537; use the surrounding log entries to confirm it.","resolution":"1. Record where 537 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_VERIFIER_STOP.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 537 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Application verifier has found an error in the current process.\n\nLookup forms: 537, 0x219, error 537, ERROR_VERIFIER_STOP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["537"]},{"id":253,"title":"ERROR_ABIOS_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["538","0x21A","error 538","ERROR_ABIOS_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","abios","occurred","the","subsystem"],"errorCode":"538","eventId":"","severity":"Low","summary":"An error occurred in the ABIOS subsystem.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 538; use the surrounding log entries to confirm it.","resolution":"1. Record where 538 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ABIOS_ERROR.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 538 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An error occurred in the ABIOS subsystem.\n\nLookup forms: 538, 0x21A, error 538, ERROR_ABIOS_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["538"]},{"id":254,"title":"ERROR_WX86_WARNING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["539","0x21B","error 539","ERROR_WX86_WARNING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wx86","warning","occurred","the","subsystem"],"errorCode":"539","eventId":"","severity":"Low","summary":"A warning occurred in the WX86 subsystem.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 539; use the surrounding log entries to confirm it.","resolution":"1. Record where 539 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WX86_WARNING.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 539 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A warning occurred in the WX86 subsystem.\n\nLookup forms: 539, 0x21B, error 539, ERROR_WX86_WARNING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["539"]},{"id":255,"title":"ERROR_WX86_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["540","0x21C","error 540","ERROR_WX86_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wx86","occurred","the","subsystem"],"errorCode":"540","eventId":"","severity":"Low","summary":"An error occurred in the WX86 subsystem.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 540; use the surrounding log entries to confirm it.","resolution":"1. Record where 540 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WX86_ERROR.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 540 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An error occurred in the WX86 subsystem.\n\nLookup forms: 540, 0x21C, error 540, ERROR_WX86_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["540"]},{"id":256,"title":"ERROR_TIMER_NOT_CANCELED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["541","0x21D","error 541","ERROR_TIMER_NOT_CANCELED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","timer","not","canceled","attempt","was","made","cancel","set","that","has","associated","apc","and","the","subject","thread","originally","with","routine"],"errorCode":"541","eventId":"","severity":"Low","summary":"An attempt was made to cancel or set a timer that has an associated APC and the subject thread is not the thread that originally set the timer with an associated APC routine.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 541; use the surrounding log entries to confirm it.","resolution":"1. Record where 541 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TIMER_NOT_CANCELED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 541 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt was made to cancel or set a timer that has an associated APC and the subject thread is not the thread that originally set the timer with an associated APC routine.\n\nLookup forms: 541, 0x21D, error 541, ERROR_TIMER_NOT_CANCELED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["541"]},{"id":257,"title":"ERROR_UNWIND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["542","0x21E","error 542","ERROR_UNWIND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","unwind","exception","code"],"errorCode":"542","eventId":"","severity":"Low","summary":"Unwind exception code.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 542; use the surrounding log entries to confirm it.","resolution":"1. Record where 542 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNWIND.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 542 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unwind exception code.\n\nLookup forms: 542, 0x21E, error 542, ERROR_UNWIND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["542"]},{"id":258,"title":"ERROR_BAD_STACK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["543","0x21F","error 543","ERROR_BAD_STACK","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","bad","stack","invalid","unaligned","was","encountered","during","unwind","operation"],"errorCode":"543","eventId":"","severity":"Medium","summary":"An invalid or unaligned stack was encountered during an unwind operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 543; use the surrounding log entries to confirm it.","resolution":"1. Record where 543 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_STACK.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 543 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An invalid or unaligned stack was encountered during an unwind operation.\n\nLookup forms: 543, 0x21F, error 543, ERROR_BAD_STACK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["543"]},{"id":259,"title":"ERROR_INVALID_UNWIND_TARGET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["544","0x220","error 544","ERROR_INVALID_UNWIND_TARGET","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","unwind","target","was","encountered","during","operation"],"errorCode":"544","eventId":"","severity":"Medium","summary":"An invalid unwind target was encountered during an unwind operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 544; use the surrounding log entries to confirm it.","resolution":"1. Record where 544 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_UNWIND_TARGET.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 544 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An invalid unwind target was encountered during an unwind operation.\n\nLookup forms: 544, 0x220, error 544, ERROR_INVALID_UNWIND_TARGET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["544"]},{"id":260,"title":"ERROR_INVALID_PORT_ATTRIBUTES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["545","0x221","error 545","ERROR_INVALID_PORT_ATTRIBUTES","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","port","attributes","object","specified","ntcreateport","ntconnectport"],"errorCode":"545","eventId":"","severity":"Medium","summary":"Invalid Object Attributes specified to NtCreatePort or invalid Port Attributes specified to NtConnectPort","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 545; use the surrounding log entries to confirm it.","resolution":"1. Record where 545 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_PORT_ATTRIBUTES.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 545 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid Object Attributes specified to NtCreatePort or invalid Port Attributes specified to NtConnectPort\n\nLookup forms: 545, 0x221, error 545, ERROR_INVALID_PORT_ATTRIBUTES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["545"]},{"id":261,"title":"ERROR_PORT_MESSAGE_TOO_LONG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["546","0x222","error 546","ERROR_PORT_MESSAGE_TOO_LONG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","port","message","too","long","length","passed","ntrequestport","ntrequestwaitreplyport","was","longer","than","the","maximum","allowed"],"errorCode":"546","eventId":"","severity":"Low","summary":"Length of message passed to NtRequestPort or NtRequestWaitReplyPort was longer than the maximum message allowed by the port.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 546; use the surrounding log entries to confirm it.","resolution":"1. Record where 546 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PORT_MESSAGE_TOO_LONG.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 546 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Length of message passed to NtRequestPort or NtRequestWaitReplyPort was longer than the maximum message allowed by the port.\n\nLookup forms: 546, 0x222, error 546, ERROR_PORT_MESSAGE_TOO_LONG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["546"]},{"id":262,"title":"ERROR_INVALID_QUOTA_LOWER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["547","0x223","error 547","ERROR_INVALID_QUOTA_LOWER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","quota","lower","attempt","was","made","limit","below","the","current","usage"],"errorCode":"547","eventId":"","severity":"Low","summary":"An attempt was made to lower a quota limit below the current usage.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 547; use the surrounding log entries to confirm it.","resolution":"1. Record where 547 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_QUOTA_LOWER.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 547 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt was made to lower a quota limit below the current usage.\n\nLookup forms: 547, 0x223, error 547, ERROR_INVALID_QUOTA_LOWER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["547"]},{"id":263,"title":"ERROR_DEVICE_ALREADY_ATTACHED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["548","0x224","error 548","ERROR_DEVICE_ALREADY_ATTACHED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","device","already","attached","attempt","was","made","attach","that","another"],"errorCode":"548","eventId":"","severity":"Low","summary":"An attempt was made to attach to a device that was already attached to another device.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 548; use the surrounding log entries to confirm it.","resolution":"1. Record where 548 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEVICE_ALREADY_ATTACHED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 548 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt was made to attach to a device that was already attached to another device.\n\nLookup forms: 548, 0x224, error 548, ERROR_DEVICE_ALREADY_ATTACHED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["548"]},{"id":264,"title":"ERROR_INSTRUCTION_MISALIGNMENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["549","0x225","error 549","ERROR_INSTRUCTION_MISALIGNMENT","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","instruction","misalignment","attempt","was","made","execute","unaligned","address","and","the","host","system","does","not","support","references"],"errorCode":"549","eventId":"","severity":"Low","summary":"An attempt was made to execute an instruction at an unaligned address and the host system does not support unaligned instruction references.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 549; use the surrounding log entries to confirm it.","resolution":"1. Record where 549 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTRUCTION_MISALIGNMENT.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 549 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt was made to execute an instruction at an unaligned address and the host system does not support unaligned instruction references.\n\nLookup forms: 549, 0x225, error 549, ERROR_INSTRUCTION_MISALIGNMENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["549"]},{"id":265,"title":"ERROR_PROFILING_NOT_STARTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["550","0x226","error 550","ERROR_PROFILING_NOT_STARTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","profiling","not","started"],"errorCode":"550","eventId":"","severity":"Low","summary":"Profiling not started.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 550; use the surrounding log entries to confirm it.","resolution":"1. Record where 550 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PROFILING_NOT_STARTED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 550 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Profiling not started.\n\nLookup forms: 550, 0x226, error 550, ERROR_PROFILING_NOT_STARTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["550"]},{"id":266,"title":"ERROR_PROFILING_NOT_STOPPED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["551","0x227","error 551","ERROR_PROFILING_NOT_STOPPED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","profiling","not","stopped"],"errorCode":"551","eventId":"","severity":"Low","summary":"Profiling not stopped.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 551; use the surrounding log entries to confirm it.","resolution":"1. Record where 551 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PROFILING_NOT_STOPPED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 551 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Profiling not stopped.\n\nLookup forms: 551, 0x227, error 551, ERROR_PROFILING_NOT_STOPPED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["551"]},{"id":267,"title":"ERROR_COULD_NOT_INTERPRET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["552","0x228","error 552","ERROR_COULD_NOT_INTERPRET","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","could","not","interpret","the","passed","acl","did","contain","minimum","required","information"],"errorCode":"552","eventId":"","severity":"Low","summary":"The passed ACL did not contain the minimum required information.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 552; use the surrounding log entries to confirm it.","resolution":"1. Record where 552 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_COULD_NOT_INTERPRET.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 552 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The passed ACL did not contain the minimum required information.\n\nLookup forms: 552, 0x228, error 552, ERROR_COULD_NOT_INTERPRET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["552"]},{"id":268,"title":"ERROR_PROFILING_AT_LIMIT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["553","0x229","error 553","ERROR_PROFILING_AT_LIMIT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","profiling","limit","the","number","active","objects","maximum","and","more","may","started"],"errorCode":"553","eventId":"","severity":"Low","summary":"The number of active profiling objects is at the maximum and no more may be started.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 553; use the surrounding log entries to confirm it.","resolution":"1. Record where 553 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PROFILING_AT_LIMIT.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 553 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The number of active profiling objects is at the maximum and no more may be started.\n\nLookup forms: 553, 0x229, error 553, ERROR_PROFILING_AT_LIMIT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["553"]},{"id":269,"title":"ERROR_CANT_WAIT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["554","0x22A","error 554","ERROR_CANT_WAIT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","wait","used","indicate","that","operation","cannot","continue","without","blocking","for"],"errorCode":"554","eventId":"","severity":"Medium","summary":"Used to indicate that an operation cannot continue without blocking for I/O.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 554; use the surrounding log entries to confirm it.","resolution":"1. Record where 554 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANT_WAIT.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 554 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Used to indicate that an operation cannot continue without blocking for I/O.\n\nLookup forms: 554, 0x22A, error 554, ERROR_CANT_WAIT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["554"]},{"id":270,"title":"ERROR_CANT_TERMINATE_SELF","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["555","0x22B","error 555","ERROR_CANT_TERMINATE_SELF","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","cant","terminate","self","indicates","that","thread","attempted","itself","default","called","ntterminatethread","with","null","and","was","the","last","current","process"],"errorCode":"555","eventId":"","severity":"Low","summary":"Indicates that a thread attempted to terminate itself by default (called NtTerminateThread with NULL) and it was the last thread in the current process.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 555; use the surrounding log entries to confirm it.","resolution":"1. Record where 555 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANT_TERMINATE_SELF.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 555 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Indicates that a thread attempted to terminate itself by default (called NtTerminateThread with NULL) and it was the last thread in the current process.\n\nLookup forms: 555, 0x22B, error 555, ERROR_CANT_TERMINATE_SELF. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["555"]},{"id":271,"title":"ERROR_UNEXPECTED_MM_CREATE_ERR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["556","0x22C","error 556","ERROR_UNEXPECTED_MM_CREATE_ERR","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","unexpected","create","err","returned","which","not","defined","the","standard","fsrtl","filter","converted","one","following","errors","guaranteed","this","case","information","lost","however","correctly","handles","exception"],"errorCode":"556","eventId":"","severity":"Low","summary":"If an MM error is returned which is not defined in the standard FsRtl filter, it is converted to one of the following errors which is guaranteed to be in the filter. In this case information is lost, however, the filter correctly handles the exception.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 556; use the surrounding log entries to confirm it.","resolution":"1. Record where 556 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNEXPECTED_MM_CREATE_ERR.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 556 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: If an MM error is returned which is not defined in the standard FsRtl filter, it is converted to one of the following errors which is guaranteed to be in the filter. In this case information is lost, however, the filter correctly handles the exception.\n\nLookup forms: 556, 0x22C, error 556, ERROR_UNEXPECTED_MM_CREATE_ERR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["556"]},{"id":272,"title":"ERROR_UNEXPECTED_MM_MAP_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["557","0x22D","error 557","ERROR_UNEXPECTED_MM_MAP_ERROR","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","unexpected","map","returned","which","not","defined","the","standard","fsrtl","filter","converted","one","following","errors","guaranteed","this","case","information","lost","however","correctly","handles","exception"],"errorCode":"557","eventId":"","severity":"Low","summary":"If an MM error is returned which is not defined in the standard FsRtl filter, it is converted to one of the following errors which is guaranteed to be in the filter. In this case information is lost, however, the filter correctly handles the exception.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 557; use the surrounding log entries to confirm it.","resolution":"1. Record where 557 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNEXPECTED_MM_MAP_ERROR.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 557 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: If an MM error is returned which is not defined in the standard FsRtl filter, it is converted to one of the following errors which is guaranteed to be in the filter. In this case information is lost, however, the filter correctly handles the exception.\n\nLookup forms: 557, 0x22D, error 557, ERROR_UNEXPECTED_MM_MAP_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["557"]},{"id":273,"title":"ERROR_UNEXPECTED_MM_EXTEND_ERR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["558","0x22E","error 558","ERROR_UNEXPECTED_MM_EXTEND_ERR","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","unexpected","extend","err","returned","which","not","defined","the","standard","fsrtl","filter","converted","one","following","errors","guaranteed","this","case","information","lost","however","correctly","handles","exception"],"errorCode":"558","eventId":"","severity":"Low","summary":"If an MM error is returned which is not defined in the standard FsRtl filter, it is converted to one of the following errors which is guaranteed to be in the filter. In this case information is lost, however, the filter correctly handles the exception.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 558; use the surrounding log entries to confirm it.","resolution":"1. Record where 558 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNEXPECTED_MM_EXTEND_ERR.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 558 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: If an MM error is returned which is not defined in the standard FsRtl filter, it is converted to one of the following errors which is guaranteed to be in the filter. In this case information is lost, however, the filter correctly handles the exception.\n\nLookup forms: 558, 0x22E, error 558, ERROR_UNEXPECTED_MM_EXTEND_ERR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["558"]},{"id":274,"title":"ERROR_BAD_FUNCTION_TABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["559","0x22F","error 559","ERROR_BAD_FUNCTION_TABLE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","bad","function","table","malformed","was","encountered","during","unwind","operation"],"errorCode":"559","eventId":"","severity":"Low","summary":"A malformed function table was encountered during an unwind operation.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 559; use the surrounding log entries to confirm it.","resolution":"1. Record where 559 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_FUNCTION_TABLE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 559 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A malformed function table was encountered during an unwind operation.\n\nLookup forms: 559, 0x22F, error 559, ERROR_BAD_FUNCTION_TABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["559"]},{"id":275,"title":"ERROR_NO_GUID_TRANSLATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["560","0x230","error 560","ERROR_NO_GUID_TRANSLATION","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","guid","translation","indicates","that","attempt","was","made","assign","protection","file","system","directory","and","one","the","sids","security","descriptor","could","not","translated","into","stored","this"],"errorCode":"560","eventId":"","severity":"Low","summary":"Indicates that an attempt was made to assign protection to a file system file or directory and one of the SIDs in the security descriptor could not be translated into a GUID that could be stored by the file system. This causes the protection attempt to fail, which may cause a file creation attempt to fail.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 560; use the surrounding log entries to confirm it.","resolution":"1. Record where 560 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Confirm the user or service identity has the required permissions and is not locked or disabled.\n4. Review the response body, request permissions, rate limits, and service health before retrying.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_GUID_TRANSLATION.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Confirm the user or service identity has the required permissions and is not locked or disabled.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 560 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Indicates that an attempt was made to assign protection to a file system file or directory and one of the SIDs in the security descriptor could not be translated into a GUID that could be stored by the file system. This causes the protection attempt to fail, which may cause a file creation attempt to fail.\n\nLookup forms: 560, 0x230, error 560, ERROR_NO_GUID_TRANSLATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["560"]},{"id":276,"title":"ERROR_INVALID_LDT_SIZE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["561","0x231","error 561","ERROR_INVALID_LDT_SIZE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","ldt","size","indicates","that","attempt","was","made","grow","setting","its","the","not","even","number","selectors"],"errorCode":"561","eventId":"","severity":"Low","summary":"Indicates that an attempt was made to grow an LDT by setting its size, or that the size was not an even number of selectors.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 561; use the surrounding log entries to confirm it.","resolution":"1. Record where 561 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_LDT_SIZE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 561 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Indicates that an attempt was made to grow an LDT by setting its size, or that the size was not an even number of selectors.\n\nLookup forms: 561, 0x231, error 561, ERROR_INVALID_LDT_SIZE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["561"]},{"id":277,"title":"ERROR_INVALID_LDT_OFFSET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["563","0x233","error 563","ERROR_INVALID_LDT_OFFSET","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","ldt","offset","indicates","that","the","starting","value","for","information","was","not","integral","multiple","selector","size"],"errorCode":"563","eventId":"","severity":"Low","summary":"Indicates that the starting value for the LDT information was not an integral multiple of the selector size.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 563; use the surrounding log entries to confirm it.","resolution":"1. Record where 563 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_LDT_OFFSET.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 563 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Indicates that the starting value for the LDT information was not an integral multiple of the selector size.\n\nLookup forms: 563, 0x233, error 563, ERROR_INVALID_LDT_OFFSET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["563"]},{"id":278,"title":"ERROR_INVALID_LDT_DESCRIPTOR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["564","0x234","error 564","ERROR_INVALID_LDT_DESCRIPTOR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","ldt","descriptor","indicates","that","the","user","supplied","when","trying","set","descriptors"],"errorCode":"564","eventId":"","severity":"Medium","summary":"Indicates that the user supplied an invalid descriptor when trying to set up Ldt descriptors.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 564; use the surrounding log entries to confirm it.","resolution":"1. Record where 564 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_LDT_DESCRIPTOR.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 564 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Indicates that the user supplied an invalid descriptor when trying to set up Ldt descriptors.\n\nLookup forms: 564, 0x234, error 564, ERROR_INVALID_LDT_DESCRIPTOR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["564"]},{"id":279,"title":"ERROR_TOO_MANY_THREADS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["565","0x235","error 565","ERROR_TOO_MANY_THREADS","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","too","many","threads","indicates","process","has","perform","the","requested","action","for","example","assignment","primary","token","may","only","performed","when","zero","one"],"errorCode":"565","eventId":"","severity":"Low","summary":"Indicates a process has too many threads to perform the requested action. For example, assignment of a primary token may only be performed when a process has zero or one threads.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 565; use the surrounding log entries to confirm it.","resolution":"1. Record where 565 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TOO_MANY_THREADS.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 565 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Indicates a process has too many threads to perform the requested action. For example, assignment of a primary token may only be performed when a process has zero or one threads.\n\nLookup forms: 565, 0x235, error 565, ERROR_TOO_MANY_THREADS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["565"]},{"id":280,"title":"ERROR_THREAD_NOT_IN_PROCESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["566","0x236","error 566","ERROR_THREAD_NOT_IN_PROCESS","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","thread","not","process","attempt","was","made","operate","within","specific","but","the","specified"],"errorCode":"566","eventId":"","severity":"Low","summary":"An attempt was made to operate on a thread within a specific process, but the thread specified is not in the process specified.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 566; use the surrounding log entries to confirm it.","resolution":"1. Record where 566 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_THREAD_NOT_IN_PROCESS.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 566 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt was made to operate on a thread within a specific process, but the thread specified is not in the process specified.\n\nLookup forms: 566, 0x236, error 566, ERROR_THREAD_NOT_IN_PROCESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["566"]},{"id":281,"title":"ERROR_PAGEFILE_QUOTA_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["567","0x237","error 567","ERROR_PAGEFILE_QUOTA_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","pagefile","quota","exceeded","page","file","was"],"errorCode":"567","eventId":"","severity":"Low","summary":"Page file quota was exceeded.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 567; use the surrounding log entries to confirm it.","resolution":"1. Record where 567 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PAGEFILE_QUOTA_EXCEEDED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 567 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Page file quota was exceeded.\n\nLookup forms: 567, 0x237, error 567, ERROR_PAGEFILE_QUOTA_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["567"]},{"id":282,"title":"ERROR_LOGON_SERVER_CONFLICT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["568","0x238","error 568","ERROR_LOGON_SERVER_CONFLICT","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","logon","server","conflict","the","netlogon","service","cannot","start","because","another","running","domain","conflicts","with","specified","role"],"errorCode":"568","eventId":"","severity":"High","summary":"The Netlogon service cannot start because another Netlogon service running in the domain conflicts with the specified role.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 568; use the surrounding log entries to confirm it.","resolution":"1. Record where 568 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review the response body, request permissions, rate limits, and service health before retrying.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOGON_SERVER_CONFLICT.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 568 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Netlogon service cannot start because another Netlogon service running in the domain conflicts with the specified role.\n\nLookup forms: 568, 0x238, error 568, ERROR_LOGON_SERVER_CONFLICT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["568"]},{"id":283,"title":"ERROR_SYNCHRONIZATION_REQUIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["569","0x239","error 569","ERROR_SYNCHRONIZATION_REQUIRED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","synchronization","required","the","sam","database","windows","server","significantly","out","with","copy","domain","controller","complete"],"errorCode":"569","eventId":"","severity":"Low","summary":"The SAM database on a Windows Server is significantly out of synchronization with the copy on the Domain Controller. A complete synchronization is required.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 569; use the surrounding log entries to confirm it.","resolution":"1. Record where 569 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SYNCHRONIZATION_REQUIRED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 569 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The SAM database on a Windows Server is significantly out of synchronization with the copy on the Domain Controller. A complete synchronization is required.\n\nLookup forms: 569, 0x239, error 569, ERROR_SYNCHRONIZATION_REQUIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["569"]},{"id":284,"title":"ERROR_NET_OPEN_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["570","0x23A","error 570","ERROR_NET_OPEN_FAILED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","net","open","failed","the","ntcreatefile","api","this","should","never","returned","application","place","holder","for","windows","lan","manager","redirector","use","its","internal","mapping","routines"],"errorCode":"570","eventId":"","severity":"High","summary":"The NtCreateFile API failed. This error should never be returned to an application, it is a place holder for the Windows Lan Manager Redirector to use in its internal error mapping routines.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 570; use the surrounding log entries to confirm it.","resolution":"1. Record where 570 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NET_OPEN_FAILED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 570 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The NtCreateFile API failed. This error should never be returned to an application, it is a place holder for the Windows Lan Manager Redirector to use in its internal error mapping routines.\n\nLookup forms: 570, 0x23A, error 570, ERROR_NET_OPEN_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["570"]},{"id":285,"title":"ERROR_IO_PRIVILEGE_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["571","0x23B","error 571","ERROR_IO_PRIVILEGE_FAILED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","privilege","failed","the","permissions","for","process","could","not","changed"],"errorCode":"571","eventId":"","severity":"High","summary":"{Privilege Failed} The I/O permissions for the process could not be changed.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 571; use the surrounding log entries to confirm it.","resolution":"1. Record where 571 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IO_PRIVILEGE_FAILED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 571 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Privilege Failed} The I/O permissions for the process could not be changed.\n\nLookup forms: 571, 0x23B, error 571, ERROR_IO_PRIVILEGE_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["571"]},{"id":286,"title":"ERROR_CONTROL_C_EXIT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["572","0x23C","error 572","ERROR_CONTROL_C_EXIT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","control","exit","application","ctrl","the","terminated","result"],"errorCode":"572","eventId":"","severity":"Low","summary":"{Application Exit by CTRL+C} The application terminated as a result of a CTRL+C.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 572; use the surrounding log entries to confirm it.","resolution":"1. Record where 572 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CONTROL_C_EXIT.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 572 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Application Exit by CTRL+C} The application terminated as a result of a CTRL+C.\n\nLookup forms: 572, 0x23C, error 572, ERROR_CONTROL_C_EXIT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["572"]},{"id":287,"title":"ERROR_MISSING_SYSTEMFILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["573","0x23D","error 573","ERROR_MISSING_SYSTEMFILE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","missing","systemfile","system","file","the","required","bad"],"errorCode":"573","eventId":"","severity":"Low","summary":"{Missing System File} The required system file %hs is bad or missing.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 573; use the surrounding log entries to confirm it.","resolution":"1. Record where 573 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MISSING_SYSTEMFILE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 573 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Missing System File} The required system file %hs is bad or missing.\n\nLookup forms: 573, 0x23D, error 573, ERROR_MISSING_SYSTEMFILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["573"]},{"id":288,"title":"ERROR_UNHANDLED_EXCEPTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["574","0x23E","error 574","ERROR_UNHANDLED_EXCEPTION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","unhandled","exception","application","the","08lx","occurred","location"],"errorCode":"574","eventId":"","severity":"Low","summary":"{Application Error} The exception %s (0x%08lx) occurred in the application at location 0x%08lx.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 574; use the surrounding log entries to confirm it.","resolution":"1. Record where 574 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNHANDLED_EXCEPTION.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 574 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Application Error} The exception %s (0x%08lx) occurred in the application at location 0x%08lx.\n\nLookup forms: 574, 0x23E, error 574, ERROR_UNHANDLED_EXCEPTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["574"]},{"id":289,"title":"ERROR_APP_INIT_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["575","0x23F","error 575","ERROR_APP_INIT_FAILURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","app","init","failure","application","the","was","unable","start","correctly","click","close"],"errorCode":"575","eventId":"","severity":"Medium","summary":"{Application Error} The application was unable to start correctly (0x%lx). Click OK to close the application.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 575; use the surrounding log entries to confirm it.","resolution":"1. Record where 575 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_APP_INIT_FAILURE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 575 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Application Error} The application was unable to start correctly (0x%lx). Click OK to close the application.\n\nLookup forms: 575, 0x23F, error 575, ERROR_APP_INIT_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["575"]},{"id":290,"title":"ERROR_PAGEFILE_CREATE_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["576","0x240","error 576","ERROR_PAGEFILE_CREATE_FAILED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","pagefile","create","failed","unable","paging","file","the","creation","requested","size","was"],"errorCode":"576","eventId":"","severity":"High","summary":"{Unable to Create Paging File} The creation of the paging file %hs failed (%lx). The requested size was %ld.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 576; use the surrounding log entries to confirm it.","resolution":"1. Record where 576 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PAGEFILE_CREATE_FAILED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 576 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Unable to Create Paging File} The creation of the paging file %hs failed (%lx). The requested size was %ld.\n\nLookup forms: 576, 0x240, error 576, ERROR_PAGEFILE_CREATE_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["576"]},{"id":291,"title":"ERROR_INVALID_IMAGE_HASH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["577","0x241","error 577","ERROR_INVALID_IMAGE_HASH","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","invalid","image","hash","windows","cannot","verify","the","digital","signature","for","this","file","recent","hardware","software","change","might","have","installed","that","signed","incorrectly","damaged","malicious"],"errorCode":"577","eventId":"","severity":"Medium","summary":"Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 577; use the surrounding log entries to confirm it.","resolution":"1. Record where 577 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review the response body, request permissions, rate limits, and service health before retrying.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_IMAGE_HASH.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 577 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.\n\nLookup forms: 577, 0x241, error 577, ERROR_INVALID_IMAGE_HASH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["577"]},{"id":292,"title":"ERROR_NO_PAGEFILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["578","0x242","error 578","ERROR_NO_PAGEFILE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","pagefile","paging","file","specified","was","the","system","configuration"],"errorCode":"578","eventId":"","severity":"Low","summary":"{No Paging File Specified} No paging file was specified in the system configuration.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 578; use the surrounding log entries to confirm it.","resolution":"1. Record where 578 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_PAGEFILE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 578 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {No Paging File Specified} No paging file was specified in the system configuration.\n\nLookup forms: 578, 0x242, error 578, ERROR_NO_PAGEFILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["578"]},{"id":293,"title":"ERROR_ILLEGAL_FLOAT_CONTEXT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["579","0x243","error 579","ERROR_ILLEGAL_FLOAT_CONTEXT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","illegal","float","context","exception","real","mode","application","issued","floating","point","instruction","and","hardware","not","present"],"errorCode":"579","eventId":"","severity":"Low","summary":"{EXCEPTION} A real-mode application issued a floating-point instruction and floating-point hardware is not present.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 579; use the surrounding log entries to confirm it.","resolution":"1. Record where 579 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ILLEGAL_FLOAT_CONTEXT.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 579 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {EXCEPTION} A real-mode application issued a floating-point instruction and floating-point hardware is not present.\n\nLookup forms: 579, 0x243, error 579, ERROR_ILLEGAL_FLOAT_CONTEXT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["579"]},{"id":294,"title":"ERROR_NO_EVENT_PAIR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["580","0x244","error 580","ERROR_NO_EVENT_PAIR","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","event","pair","synchronization","operation","was","performed","using","the","thread","specific","client","server","object","but","associated","with"],"errorCode":"580","eventId":"","severity":"Low","summary":"An event pair synchronization operation was performed using the thread specific client/server event pair object, but no event pair object was associated with the thread.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 580; use the surrounding log entries to confirm it.","resolution":"1. Record where 580 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_EVENT_PAIR.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 580 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An event pair synchronization operation was performed using the thread specific client/server event pair object, but no event pair object was associated with the thread.\n\nLookup forms: 580, 0x244, error 580, ERROR_NO_EVENT_PAIR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["580"]},{"id":295,"title":"ERROR_DOMAIN_CTRLR_CONFIG_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["581","0x245","error 581","ERROR_DOMAIN_CTRLR_CONFIG_ERROR","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","domain","ctrlr","config","windows","server","has","incorrect","configuration"],"errorCode":"581","eventId":"","severity":"Low","summary":"A Windows Server has an incorrect configuration.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 581; use the surrounding log entries to confirm it.","resolution":"1. Record where 581 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DOMAIN_CTRLR_CONFIG_ERROR.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 581 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A Windows Server has an incorrect configuration.\n\nLookup forms: 581, 0x245, error 581, ERROR_DOMAIN_CTRLR_CONFIG_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["581"]},{"id":296,"title":"ERROR_ILLEGAL_CHARACTER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["582","0x246","error 582","ERROR_ILLEGAL_CHARACTER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","illegal","character","was","encountered","for","multi","byte","set","this","includes","lead","without","succeeding","trail","the","unicode","characters","0xffff","and","0xfffe"],"errorCode":"582","eventId":"","severity":"Low","summary":"An illegal character was encountered. For a multi-byte character set this includes a lead byte without a succeeding trail byte. For the Unicode character set this includes the characters 0xFFFF and 0xFFFE.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 582; use the surrounding log entries to confirm it.","resolution":"1. Record where 582 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ILLEGAL_CHARACTER.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 582 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An illegal character was encountered. For a multi-byte character set this includes a lead byte without a succeeding trail byte. For the Unicode character set this includes the characters 0xFFFF and 0xFFFE.\n\nLookup forms: 582, 0x246, error 582, ERROR_ILLEGAL_CHARACTER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["582"]},{"id":297,"title":"ERROR_UNDEFINED_CHARACTER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["583","0x247","error 583","ERROR_UNDEFINED_CHARACTER","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","undefined","character","the","unicode","not","defined","set","installed","system"],"errorCode":"583","eventId":"","severity":"Low","summary":"The Unicode character is not defined in the Unicode character set installed on the system.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 583; use the surrounding log entries to confirm it.","resolution":"1. Record where 583 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNDEFINED_CHARACTER.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 583 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Unicode character is not defined in the Unicode character set installed on the system.\n\nLookup forms: 583, 0x247, error 583, ERROR_UNDEFINED_CHARACTER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["583"]},{"id":298,"title":"ERROR_FLOPPY_VOLUME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["584","0x248","error 584","ERROR_FLOPPY_VOLUME","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","floppy","volume","the","paging","file","cannot","created","diskette"],"errorCode":"584","eventId":"","severity":"Medium","summary":"The paging file cannot be created on a floppy diskette.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 584; use the surrounding log entries to confirm it.","resolution":"1. Record where 584 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review the response body, request permissions, rate limits, and service health before retrying.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FLOPPY_VOLUME.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 584 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The paging file cannot be created on a floppy diskette.\n\nLookup forms: 584, 0x248, error 584, ERROR_FLOPPY_VOLUME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["584"]},{"id":299,"title":"ERROR_BIOS_FAILED_TO_CONNECT_INTERRUPT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["585","0x249","error 585","ERROR_BIOS_FAILED_TO_CONNECT_INTERRUPT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","bios","failed","connect","interrupt","the","system","device","bus","for","which","connected"],"errorCode":"585","eventId":"","severity":"High","summary":"The system BIOS failed to connect a system interrupt to the device or bus for which the device is connected.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 585; use the surrounding log entries to confirm it.","resolution":"1. Record where 585 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BIOS_FAILED_TO_CONNECT_INTERRUPT.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 585 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system BIOS failed to connect a system interrupt to the device or bus for which the device is connected.\n\nLookup forms: 585, 0x249, error 585, ERROR_BIOS_FAILED_TO_CONNECT_INTERRUPT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["585"]},{"id":300,"title":"ERROR_BACKUP_CONTROLLER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["586","0x24A","error 586","ERROR_BACKUP_CONTROLLER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","backup","controller","this","operation","only","allowed","for","the","primary","domain"],"errorCode":"586","eventId":"","severity":"Low","summary":"This operation is only allowed for the Primary Domain Controller of the domain.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 586; use the surrounding log entries to confirm it.","resolution":"1. Record where 586 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BACKUP_CONTROLLER.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 586 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation is only allowed for the Primary Domain Controller of the domain.\n\nLookup forms: 586, 0x24A, error 586, ERROR_BACKUP_CONTROLLER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["586"]},{"id":301,"title":"ERROR_MUTANT_LIMIT_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["587","0x24B","error 587","ERROR_MUTANT_LIMIT_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","mutant","limit","exceeded","attempt","was","made","acquire","such","that","its","maximum","count","would","have","been"],"errorCode":"587","eventId":"","severity":"Low","summary":"An attempt was made to acquire a mutant such that its maximum count would have been exceeded.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 587; use the surrounding log entries to confirm it.","resolution":"1. Record where 587 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MUTANT_LIMIT_EXCEEDED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 587 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt was made to acquire a mutant such that its maximum count would have been exceeded.\n\nLookup forms: 587, 0x24B, error 587, ERROR_MUTANT_LIMIT_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["587"]},{"id":302,"title":"ERROR_FS_DRIVER_REQUIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["588","0x24C","error 588","ERROR_FS_DRIVER_REQUIRED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","driver","required","volume","has","been","accessed","for","which","file","system","that","not","yet","loaded"],"errorCode":"588","eventId":"","severity":"Low","summary":"A volume has been accessed for which a file system driver is required that has not yet been loaded.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 588; use the surrounding log entries to confirm it.","resolution":"1. Record where 588 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Confirm the user or service identity has the required permissions and is not locked or disabled.\n4. Review the response body, request permissions, rate limits, and service health before retrying.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FS_DRIVER_REQUIRED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Confirm the user or service identity has the required permissions and is not locked or disabled.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 588 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A volume has been accessed for which a file system driver is required that has not yet been loaded.\n\nLookup forms: 588, 0x24C, error 588, ERROR_FS_DRIVER_REQUIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["588"]},{"id":303,"title":"ERROR_CANNOT_LOAD_REGISTRY_FILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["589","0x24D","error 589","ERROR_CANNOT_LOAD_REGISTRY_FILE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","cannot","load","registry","file","failure","the","hive","its","log","alternate","corrupt","absent","not","writable"],"errorCode":"589","eventId":"","severity":"Critical","summary":"{Registry File Failure} The registry cannot load the hive (file): %hs or its log or alternate. It is corrupt, absent, or not writable.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 589; use the surrounding log entries to confirm it.","resolution":"1. Record where 589 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANNOT_LOAD_REGISTRY_FILE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 589 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Registry File Failure} The registry cannot load the hive (file): %hs or its log or alternate. It is corrupt, absent, or not writable.\n\nLookup forms: 589, 0x24D, error 589, ERROR_CANNOT_LOAD_REGISTRY_FILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["589"]},{"id":304,"title":"ERROR_DEBUG_ATTACH_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["590","0x24E","error 590","ERROR_DEBUG_ATTACH_FAILED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","debug","attach","failed","unexpected","failure","debugactiveprocess","occurred","while","processing","api","request","you","may","choose","terminate","the","process","cancel","ignore"],"errorCode":"590","eventId":"","severity":"High","summary":"{Unexpected Failure in DebugActiveProcess} An unexpected failure occurred while processing a DebugActiveProcess API request. You may choose OK to terminate the process, or Cancel to ignore the error.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 590; use the surrounding log entries to confirm it.","resolution":"1. Record where 590 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEBUG_ATTACH_FAILED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 590 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Unexpected Failure in DebugActiveProcess} An unexpected failure occurred while processing a DebugActiveProcess API request. You may choose OK to terminate the process, or Cancel to ignore the error.\n\nLookup forms: 590, 0x24E, error 590, ERROR_DEBUG_ATTACH_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["590"]},{"id":305,"title":"ERROR_SYSTEM_PROCESS_TERMINATED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["591","0x24F","error 591","ERROR_SYSTEM_PROCESS_TERMINATED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","system","process","terminated","fatal","the","unexpectedly","with","status","08x","has","been","shut","down"],"errorCode":"591","eventId":"","severity":"Low","summary":"{Fatal System Error} The %hs system process terminated unexpectedly with a status of 0x%08x (0x%08x 0x%08x). The system has been shut down.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 591; use the surrounding log entries to confirm it.","resolution":"1. Record where 591 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SYSTEM_PROCESS_TERMINATED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 591 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Fatal System Error} The %hs system process terminated unexpectedly with a status of 0x%08x (0x%08x 0x%08x). The system has been shut down.\n\nLookup forms: 591, 0x24F, error 591, ERROR_SYSTEM_PROCESS_TERMINATED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["591"]},{"id":306,"title":"ERROR_DATA_NOT_ACCEPTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["592","0x250","error 592","ERROR_DATA_NOT_ACCEPTED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","data","not","accepted","the","tdi","client","could","handle","received","during","indication"],"errorCode":"592","eventId":"","severity":"Low","summary":"{Data Not Accepted} The TDI client could not handle the data received during an indication.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 592; use the surrounding log entries to confirm it.","resolution":"1. Record where 592 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DATA_NOT_ACCEPTED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 592 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Data Not Accepted} The TDI client could not handle the data received during an indication.\n\nLookup forms: 592, 0x250, error 592, ERROR_DATA_NOT_ACCEPTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["592"]},{"id":307,"title":"ERROR_VDM_HARD_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["593","0x251","error 593","ERROR_VDM_HARD_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","vdm","hard","ntvdm","encountered"],"errorCode":"593","eventId":"","severity":"Low","summary":"NTVDM encountered a hard error.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 593; use the surrounding log entries to confirm it.","resolution":"1. Record where 593 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_VDM_HARD_ERROR.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 593 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: NTVDM encountered a hard error.\n\nLookup forms: 593, 0x251, error 593, ERROR_VDM_HARD_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["593"]},{"id":308,"title":"ERROR_DRIVER_CANCEL_TIMEOUT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["594","0x252","error 594","ERROR_DRIVER_CANCEL_TIMEOUT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","driver","cancel","timeout","the","failed","complete","cancelled","request","allotted","time"],"errorCode":"594","eventId":"","severity":"High","summary":"{Cancel Timeout} The driver %hs failed to complete a cancelled I/O request in the allotted time.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 594; use the surrounding log entries to confirm it.","resolution":"1. Record where 594 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DRIVER_CANCEL_TIMEOUT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 594 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Cancel Timeout} The driver %hs failed to complete a cancelled I/O request in the allotted time.\n\nLookup forms: 594, 0x252, error 594, ERROR_DRIVER_CANCEL_TIMEOUT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["594"]},{"id":309,"title":"ERROR_REPLY_MESSAGE_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["595","0x253","error 595","ERROR_REPLY_MESSAGE_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","reply","message","mismatch","attempt","was","made","lpc","but","the","thread","specified","client","not","waiting","that"],"errorCode":"595","eventId":"","severity":"Low","summary":"{Reply Message Mismatch} An attempt was made to reply to an LPC message, but the thread specified by the client ID in the message was not waiting on that message.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 595; use the surrounding log entries to confirm it.","resolution":"1. Record where 595 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REPLY_MESSAGE_MISMATCH.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 595 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Reply Message Mismatch} An attempt was made to reply to an LPC message, but the thread specified by the client ID in the message was not waiting on that message.\n\nLookup forms: 595, 0x253, error 595, ERROR_REPLY_MESSAGE_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["595"]},{"id":310,"title":"ERROR_LOST_WRITEBEHIND_DATA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["596","0x254","error 596","ERROR_LOST_WRITEBEHIND_DATA","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","lost","writebehind","data","delayed","write","failed","windows","was","unable","save","all","the","for","file","has","been","this","may","caused","failure","your","computer","hardware","network"],"errorCode":"596","eventId":"","severity":"High","summary":"{Delayed Write Failed} Windows was unable to save all the data for the file %hs. The data has been lost. This error may be caused by a failure of your computer hardware or network connection. Please try to save this file elsewhere.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 596; use the surrounding log entries to confirm it.","resolution":"1. Record where 596 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review the response body, request permissions, rate limits, and service health before retrying.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOST_WRITEBEHIND_DATA.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 596 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Delayed Write Failed} Windows was unable to save all the data for the file %hs. The data has been lost. This error may be caused by a failure of your computer hardware or network connection. Please try to save this file elsewhere.\n\nLookup forms: 596, 0x254, error 596, ERROR_LOST_WRITEBEHIND_DATA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["596"]},{"id":311,"title":"ERROR_CLIENT_SERVER_PARAMETERS_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["597","0x255","error 597","ERROR_CLIENT_SERVER_PARAMETERS_INVALID","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","client","server","parameters","invalid","the","parameter","passed","shared","memory","window","were","too","much","data","may","have","been","put"],"errorCode":"597","eventId":"","severity":"Medium","summary":"The parameter(s) passed to the server in the client/server shared memory window were invalid. Too much data may have been put in the shared memory window.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 597; use the surrounding log entries to confirm it.","resolution":"1. Record where 597 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review the response body, request permissions, rate limits, and service health before retrying.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLIENT_SERVER_PARAMETERS_INVALID.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 597 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The parameter(s) passed to the server in the client/server shared memory window were invalid. Too much data may have been put in the shared memory window.\n\nLookup forms: 597, 0x255, error 597, ERROR_CLIENT_SERVER_PARAMETERS_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["597"]},{"id":312,"title":"ERROR_NOT_TINY_STREAM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["598","0x256","error 598","ERROR_NOT_TINY_STREAM","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","not","tiny","stream","the"],"errorCode":"598","eventId":"","severity":"Low","summary":"The stream is not a tiny stream.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 598; use the surrounding log entries to confirm it.","resolution":"1. Record where 598 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_TINY_STREAM.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 598 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The stream is not a tiny stream.\n\nLookup forms: 598, 0x256, error 598, ERROR_NOT_TINY_STREAM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["598"]},{"id":313,"title":"ERROR_STACK_OVERFLOW_READ","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["599","0x257","error 599","ERROR_STACK_OVERFLOW_READ","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","stack","overflow","read","the","request","must","handled","code"],"errorCode":"599","eventId":"","severity":"Low","summary":"The request must be handled by the stack overflow code.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 599; use the surrounding log entries to confirm it.","resolution":"1. Record where 599 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STACK_OVERFLOW_READ.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 599 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The request must be handled by the stack overflow code.\n\nLookup forms: 599, 0x257, error 599, ERROR_STACK_OVERFLOW_READ. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["599"]},{"id":314,"title":"ERROR_CONVERT_TO_LARGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["600","0x258","error 600","ERROR_CONVERT_TO_LARGE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","convert","large","internal","ofs","status","codes","indicating","how","allocation","operation","handled","either","retried","after","the","containing","onode","moved","extent","stream","converted"],"errorCode":"600","eventId":"","severity":"Low","summary":"Internal OFS status codes indicating how an allocation operation is handled. Either it is retried after the containing onode is moved or the extent stream is converted to a large stream.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 600; use the surrounding log entries to confirm it.","resolution":"1. Record where 600 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CONVERT_TO_LARGE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 600 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Internal OFS status codes indicating how an allocation operation is handled. Either it is retried after the containing onode is moved or the extent stream is converted to a large stream.\n\nLookup forms: 600, 0x258, error 600, ERROR_CONVERT_TO_LARGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["600"]},{"id":315,"title":"ERROR_FOUND_OUT_OF_SCOPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["601","0x259","error 601","ERROR_FOUND_OUT_OF_SCOPE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","found","out","scope","the","attempt","find","object","matching","volume","but","handle","used","for","operation"],"errorCode":"601","eventId":"","severity":"Low","summary":"The attempt to find the object found an object matching by ID on the volume but it is out of the scope of the handle used for the operation.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 601; use the surrounding log entries to confirm it.","resolution":"1. Record where 601 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FOUND_OUT_OF_SCOPE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 601 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The attempt to find the object found an object matching by ID on the volume but it is out of the scope of the handle used for the operation.\n\nLookup forms: 601, 0x259, error 601, ERROR_FOUND_OUT_OF_SCOPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["601"]},{"id":316,"title":"ERROR_ALLOCATE_BUCKET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["602","0x25A","error 602","ERROR_ALLOCATE_BUCKET","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","allocate","bucket","the","array","must","grown","retry","transaction","after","doing"],"errorCode":"602","eventId":"","severity":"Low","summary":"The bucket array must be grown. Retry transaction after doing so.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 602; use the surrounding log entries to confirm it.","resolution":"1. Record where 602 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ALLOCATE_BUCKET.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 602 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The bucket array must be grown. Retry transaction after doing so.\n\nLookup forms: 602, 0x25A, error 602, ERROR_ALLOCATE_BUCKET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["602"]},{"id":317,"title":"ERROR_MARSHALL_OVERFLOW","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["603","0x25B","error 603","ERROR_MARSHALL_OVERFLOW","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","marshall","overflow","the","user","kernel","marshalling","buffer","has","overflowed"],"errorCode":"603","eventId":"","severity":"Low","summary":"The user/kernel marshalling buffer has overflowed.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 603; use the surrounding log entries to confirm it.","resolution":"1. Record where 603 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MARSHALL_OVERFLOW.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 603 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The user/kernel marshalling buffer has overflowed.\n\nLookup forms: 603, 0x25B, error 603, ERROR_MARSHALL_OVERFLOW. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["603"]},{"id":318,"title":"ERROR_INVALID_VARIANT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["604","0x25C","error 604","ERROR_INVALID_VARIANT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","variant","the","supplied","structure","contains","data"],"errorCode":"604","eventId":"","severity":"Medium","summary":"The supplied variant structure contains invalid data.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 604; use the surrounding log entries to confirm it.","resolution":"1. Record where 604 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_VARIANT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 604 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The supplied variant structure contains invalid data.\n\nLookup forms: 604, 0x25C, error 604, ERROR_INVALID_VARIANT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["604"]},{"id":319,"title":"ERROR_BAD_COMPRESSION_BUFFER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["605","0x25D","error 605","ERROR_BAD_COMPRESSION_BUFFER","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","bad","compression","buffer","the","specified","contains","ill","formed","data"],"errorCode":"605","eventId":"","severity":"Low","summary":"The specified buffer contains ill-formed data.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 605; use the surrounding log entries to confirm it.","resolution":"1. Record where 605 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_COMPRESSION_BUFFER.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 605 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified buffer contains ill-formed data.\n\nLookup forms: 605, 0x25D, error 605, ERROR_BAD_COMPRESSION_BUFFER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["605"]},{"id":320,"title":"ERROR_AUDIT_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["606","0x25E","error 606","ERROR_AUDIT_FAILED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","audit","failed","attempt","generate","security"],"errorCode":"606","eventId":"","severity":"High","summary":"{Audit Failed} An attempt to generate a security audit failed.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 606; use the surrounding log entries to confirm it.","resolution":"1. Record where 606 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_AUDIT_FAILED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 606 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Audit Failed} An attempt to generate a security audit failed.\n\nLookup forms: 606, 0x25E, error 606, ERROR_AUDIT_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["606"]},{"id":321,"title":"ERROR_TIMER_RESOLUTION_NOT_SET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["607","0x25F","error 607","ERROR_TIMER_RESOLUTION_NOT_SET","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","timer","resolution","not","set","the","was","previously","current","process"],"errorCode":"607","eventId":"","severity":"Low","summary":"The timer resolution was not previously set by the current process.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 607; use the surrounding log entries to confirm it.","resolution":"1. Record where 607 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TIMER_RESOLUTION_NOT_SET.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 607 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The timer resolution was not previously set by the current process.\n\nLookup forms: 607, 0x25F, error 607, ERROR_TIMER_RESOLUTION_NOT_SET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["607"]},{"id":322,"title":"ERROR_INSUFFICIENT_LOGON_INFO","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["608","0x260","error 608","ERROR_INSUFFICIENT_LOGON_INFO","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","insufficient","logon","info","there","account","information","log","you"],"errorCode":"608","eventId":"","severity":"Low","summary":"There is insufficient account information to log you on.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 608; use the surrounding log entries to confirm it.","resolution":"1. Record where 608 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSUFFICIENT_LOGON_INFO.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 608 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There is insufficient account information to log you on.\n\nLookup forms: 608, 0x260, error 608, ERROR_INSUFFICIENT_LOGON_INFO. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["608"]},{"id":323,"title":"ERROR_BAD_DLL_ENTRYPOINT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["609","0x261","error 609","ERROR_BAD_DLL_ENTRYPOINT","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","bad","dll","entrypoint","invalid","the","dynamic","link","library","not","written","correctly","stack","pointer","has","been","left","inconsistent","state","should","declared","winapi","stdcall","select","yes"],"errorCode":"609","eventId":"","severity":"Medium","summary":"{Invalid DLL Entrypoint} The dynamic link library %hs is not written correctly. The stack pointer has been left in an inconsistent state. The entrypoint should be declared as WINAPI or STDCALL. Select YES to fail the DLL load. Select NO to continue execution. Selecting NO may cause the application to operate incorrectly.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 609; use the surrounding log entries to confirm it.","resolution":"1. Record where 609 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_DLL_ENTRYPOINT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 609 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Invalid DLL Entrypoint} The dynamic link library %hs is not written correctly. The stack pointer has been left in an inconsistent state. The entrypoint should be declared as WINAPI or STDCALL. Select YES to fail the DLL load. Select NO to continue execution. Selecting NO may cause the application to operate incorrectly.\n\nLookup forms: 609, 0x261, error 609, ERROR_BAD_DLL_ENTRYPOINT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["609"]},{"id":324,"title":"ERROR_BAD_SERVICE_ENTRYPOINT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["610","0x262","error 610","ERROR_BAD_SERVICE_ENTRYPOINT","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","bad","service","entrypoint","invalid","callback","the","not","written","correctly","stack","pointer","has","been","left","inconsistent","state","should","declared","winapi","stdcall","selecting","will","cause","continue"],"errorCode":"610","eventId":"","severity":"Medium","summary":"{Invalid Service Callback Entrypoint} The %hs service is not written correctly. The stack pointer has been left in an inconsistent state. The callback entrypoint should be declared as WINAPI or STDCALL. Selecting OK will cause the service to continue operation. However, the service process may operate incorrectly.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 610; use the surrounding log entries to confirm it.","resolution":"1. Record where 610 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_SERVICE_ENTRYPOINT.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 610 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Invalid Service Callback Entrypoint} The %hs service is not written correctly. The stack pointer has been left in an inconsistent state. The callback entrypoint should be declared as WINAPI or STDCALL. Selecting OK will cause the service to continue operation. However, the service process may operate incorrectly.\n\nLookup forms: 610, 0x262, error 610, ERROR_BAD_SERVICE_ENTRYPOINT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["610"]},{"id":325,"title":"ERROR_IP_ADDRESS_CONFLICT1","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["611","0x263","error 611","ERROR_IP_ADDRESS_CONFLICT1","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","address","conflict1","there","conflict","with","another","system","the","network"],"errorCode":"611","eventId":"","severity":"High","summary":"There is an IP address conflict with another system on the network.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 611; use the surrounding log entries to confirm it.","resolution":"1. Record where 611 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IP_ADDRESS_CONFLICT1.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 611 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There is an IP address conflict with another system on the network.\n\nLookup forms: 611, 0x263, error 611, ERROR_IP_ADDRESS_CONFLICT1. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["611"]},{"id":326,"title":"ERROR_IP_ADDRESS_CONFLICT2","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["612","0x264","error 612","ERROR_IP_ADDRESS_CONFLICT2","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","address","conflict2","there","conflict","with","another","system","the","network"],"errorCode":"612","eventId":"","severity":"High","summary":"There is an IP address conflict with another system on the network.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 612; use the surrounding log entries to confirm it.","resolution":"1. Record where 612 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IP_ADDRESS_CONFLICT2.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 612 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There is an IP address conflict with another system on the network.\n\nLookup forms: 612, 0x264, error 612, ERROR_IP_ADDRESS_CONFLICT2. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["612"]},{"id":327,"title":"ERROR_REGISTRY_QUOTA_LIMIT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["613","0x265","error 613","ERROR_REGISTRY_QUOTA_LIMIT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","registry","quota","limit","low","space","the","system","has","reached","maximum","size","allowed","for","part","additional","storage","requests","will","ignored"],"errorCode":"613","eventId":"","severity":"Low","summary":"{Low On Registry Space} The system has reached the maximum size allowed for the system part of the registry. Additional storage requests will be ignored.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 613; use the surrounding log entries to confirm it.","resolution":"1. Record where 613 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REGISTRY_QUOTA_LIMIT.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 613 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Low On Registry Space} The system has reached the maximum size allowed for the system part of the registry. Additional storage requests will be ignored.\n\nLookup forms: 613, 0x265, error 613, ERROR_REGISTRY_QUOTA_LIMIT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["613"]},{"id":328,"title":"ERROR_NO_CALLBACK_ACTIVE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["614","0x266","error 614","ERROR_NO_CALLBACK_ACTIVE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","callback","active","return","system","service","cannot","executed","when"],"errorCode":"614","eventId":"","severity":"Medium","summary":"A callback return system service cannot be executed when no callback is active.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 614; use the surrounding log entries to confirm it.","resolution":"1. Record where 614 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_CALLBACK_ACTIVE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 614 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A callback return system service cannot be executed when no callback is active.\n\nLookup forms: 614, 0x266, error 614, ERROR_NO_CALLBACK_ACTIVE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["614"]},{"id":329,"title":"ERROR_PWD_TOO_SHORT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["615","0x267","error 615","ERROR_PWD_TOO_SHORT","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","pwd","too","short","the","password","provided","meet","policy","your","user","account","please","choose","longer"],"errorCode":"615","eventId":"","severity":"Low","summary":"The password provided is too short to meet the policy of your user account. Please choose a longer password.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 615; use the surrounding log entries to confirm it.","resolution":"1. Record where 615 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PWD_TOO_SHORT.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 615 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The password provided is too short to meet the policy of your user account. Please choose a longer password.\n\nLookup forms: 615, 0x267, error 615, ERROR_PWD_TOO_SHORT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["615"]},{"id":330,"title":"ERROR_PWD_TOO_RECENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["616","0x268","error 616","ERROR_PWD_TOO_RECENT","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","pwd","too","recent","the","policy","your","user","account","does","not","allow","you","change","passwords","frequently","this","done","prevent","users","from","changing","back","familiar","but"],"errorCode":"616","eventId":"","severity":"Low","summary":"The policy of your user account does not allow you to change passwords too frequently. This is done to prevent users from changing back to a familiar, but potentially discovered, password. If you feel your password has been compromised then please contact your administrator immediately to have a new one assigned.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 616; use the surrounding log entries to confirm it.","resolution":"1. Record where 616 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PWD_TOO_RECENT.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 616 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The policy of your user account does not allow you to change passwords too frequently. This is done to prevent users from changing back to a familiar, but potentially discovered, password. If you feel your password has been compromised then please contact your administrator immediately to have a new one assigned.\n\nLookup forms: 616, 0x268, error 616, ERROR_PWD_TOO_RECENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["616"]},{"id":331,"title":"ERROR_PWD_HISTORY_CONFLICT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["617","0x269","error 617","ERROR_PWD_HISTORY_CONFLICT","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","pwd","history","conflict","you","have","attempted","change","your","password","one","that","used","the","past","policy","user","account","does","not","allow","this","please","select","previously"],"errorCode":"617","eventId":"","severity":"Low","summary":"You have attempted to change your password to one that you have used in the past. The policy of your user account does not allow this. Please select a password that you have not previously used.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 617; use the surrounding log entries to confirm it.","resolution":"1. Record where 617 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PWD_HISTORY_CONFLICT.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 617 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: You have attempted to change your password to one that you have used in the past. The policy of your user account does not allow this. Please select a password that you have not previously used.\n\nLookup forms: 617, 0x269, error 617, ERROR_PWD_HISTORY_CONFLICT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["617"]},{"id":332,"title":"ERROR_UNSUPPORTED_COMPRESSION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["618","0x26A","error 618","ERROR_UNSUPPORTED_COMPRESSION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","unsupported","compression","the","specified","format"],"errorCode":"618","eventId":"","severity":"Low","summary":"The specified compression format is unsupported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 618; use the surrounding log entries to confirm it.","resolution":"1. Record where 618 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNSUPPORTED_COMPRESSION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 618 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified compression format is unsupported.\n\nLookup forms: 618, 0x26A, error 618, ERROR_UNSUPPORTED_COMPRESSION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["618"]},{"id":333,"title":"ERROR_INVALID_HW_PROFILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["619","0x26B","error 619","ERROR_INVALID_HW_PROFILE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","invalid","profile","the","specified","hardware","configuration"],"errorCode":"619","eventId":"","severity":"Medium","summary":"The specified hardware profile configuration is invalid.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 619; use the surrounding log entries to confirm it.","resolution":"1. Record where 619 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_HW_PROFILE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 619 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified hardware profile configuration is invalid.\n\nLookup forms: 619, 0x26B, error 619, ERROR_INVALID_HW_PROFILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["619"]},{"id":334,"title":"ERROR_INVALID_PLUGPLAY_DEVICE_PATH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["620","0x26C","error 620","ERROR_INVALID_PLUGPLAY_DEVICE_PATH","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","invalid","plugplay","device","path","the","specified","plug","and","play","registry"],"errorCode":"620","eventId":"","severity":"Medium","summary":"The specified Plug and Play registry device path is invalid.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 620; use the surrounding log entries to confirm it.","resolution":"1. Record where 620 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_PLUGPLAY_DEVICE_PATH.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 620 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified Plug and Play registry device path is invalid.\n\nLookup forms: 620, 0x26C, error 620, ERROR_INVALID_PLUGPLAY_DEVICE_PATH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["620"]},{"id":335,"title":"ERROR_QUOTA_LIST_INCONSISTENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["621","0x26D","error 621","ERROR_QUOTA_LIST_INCONSISTENT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","quota","list","inconsistent","the","specified","internally","with","its","descriptor"],"errorCode":"621","eventId":"","severity":"Low","summary":"The specified quota list is internally inconsistent with its descriptor.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 621; use the surrounding log entries to confirm it.","resolution":"1. Record where 621 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_QUOTA_LIST_INCONSISTENT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 621 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified quota list is internally inconsistent with its descriptor.\n\nLookup forms: 621, 0x26D, error 621, ERROR_QUOTA_LIST_INCONSISTENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["621"]},{"id":336,"title":"ERROR_EVALUATION_EXPIRATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["622","0x26E","error 622","ERROR_EVALUATION_EXPIRATION","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","evaluation","expiration","windows","notification","the","period","for","this","installation","has","expired","system","will","shutdown","hour","restore","access","please","upgrade","using","licensed","distribution","product"],"errorCode":"622","eventId":"","severity":"Low","summary":"{Windows Evaluation Notification} The evaluation period for this installation of Windows has expired. This system will shutdown in 1 hour. To restore access to this installation of Windows, please upgrade this installation using a licensed distribution of this product.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 622; use the surrounding log entries to confirm it.","resolution":"1. Record where 622 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVALUATION_EXPIRATION.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 622 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Windows Evaluation Notification} The evaluation period for this installation of Windows has expired. This system will shutdown in 1 hour. To restore access to this installation of Windows, please upgrade this installation using a licensed distribution of this product.\n\nLookup forms: 622, 0x26E, error 622, ERROR_EVALUATION_EXPIRATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["622"]},{"id":337,"title":"ERROR_ILLEGAL_DLL_RELOCATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["623","0x26F","error 623","ERROR_ILLEGAL_DLL_RELOCATION","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","illegal","dll","relocation","system","the","was","relocated","memory","application","will","not","run","properly","occurred","because","occupied","address","range","reserved","for","windows","dlls","vendor","supplying"],"errorCode":"623","eventId":"","severity":"Low","summary":"{Illegal System DLL Relocation} The system DLL %hs was relocated in memory. The application will not run properly. The relocation occurred because the DLL %hs occupied an address range reserved for Windows system DLLs. The vendor supplying the DLL should be contacted for a new DLL.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 623; use the surrounding log entries to confirm it.","resolution":"1. Record where 623 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ILLEGAL_DLL_RELOCATION.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 623 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Illegal System DLL Relocation} The system DLL %hs was relocated in memory. The application will not run properly. The relocation occurred because the DLL %hs occupied an address range reserved for Windows system DLLs. The vendor supplying the DLL should be contacted for a new DLL.\n\nLookup forms: 623, 0x26F, error 623, ERROR_ILLEGAL_DLL_RELOCATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["623"]},{"id":338,"title":"ERROR_DLL_INIT_FAILED_LOGOFF","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["624","0x270","error 624","ERROR_DLL_INIT_FAILED_LOGOFF","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dll","init","failed","logoff","initialization","the","application","initialize","because","window","station","shutting","down"],"errorCode":"624","eventId":"","severity":"High","summary":"{DLL Initialization Failed} The application failed to initialize because the window station is shutting down.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 624; use the surrounding log entries to confirm it.","resolution":"1. Record where 624 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DLL_INIT_FAILED_LOGOFF.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 624 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {DLL Initialization Failed} The application failed to initialize because the window station is shutting down.\n\nLookup forms: 624, 0x270, error 624, ERROR_DLL_INIT_FAILED_LOGOFF. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["624"]},{"id":339,"title":"ERROR_VALIDATE_CONTINUE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["625","0x271","error 625","ERROR_VALIDATE_CONTINUE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","validate","continue","the","validation","process","needs","next","step"],"errorCode":"625","eventId":"","severity":"Low","summary":"The validation process needs to continue on to the next step.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 625; use the surrounding log entries to confirm it.","resolution":"1. Record where 625 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_VALIDATE_CONTINUE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 625 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The validation process needs to continue on to the next step.\n\nLookup forms: 625, 0x271, error 625, ERROR_VALIDATE_CONTINUE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["625"]},{"id":340,"title":"ERROR_NO_MORE_MATCHES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["626","0x272","error 626","ERROR_NO_MORE_MATCHES","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","more","matches","there","are","for","the","current","index","enumeration"],"errorCode":"626","eventId":"","severity":"Low","summary":"There are no more matches for the current index enumeration.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 626; use the surrounding log entries to confirm it.","resolution":"1. Record where 626 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_MORE_MATCHES.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 626 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There are no more matches for the current index enumeration.\n\nLookup forms: 626, 0x272, error 626, ERROR_NO_MORE_MATCHES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["626"]},{"id":341,"title":"ERROR_RANGE_LIST_CONFLICT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["627","0x273","error 627","ERROR_RANGE_LIST_CONFLICT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","range","list","conflict","the","could","not","added","because"],"errorCode":"627","eventId":"","severity":"Low","summary":"The range could not be added to the range list because of a conflict.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 627; use the surrounding log entries to confirm it.","resolution":"1. Record where 627 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RANGE_LIST_CONFLICT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 627 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The range could not be added to the range list because of a conflict.\n\nLookup forms: 627, 0x273, error 627, ERROR_RANGE_LIST_CONFLICT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["627"]},{"id":342,"title":"ERROR_SERVER_SID_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["628","0x274","error 628","ERROR_SERVER_SID_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","server","sid","mismatch","the","process","running","under","different","than","that","required","client"],"errorCode":"628","eventId":"","severity":"Low","summary":"The server process is running under a SID different than that required by client.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 628; use the surrounding log entries to confirm it.","resolution":"1. Record where 628 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVER_SID_MISMATCH.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 628 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The server process is running under a SID different than that required by client.\n\nLookup forms: 628, 0x274, error 628, ERROR_SERVER_SID_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["628"]},{"id":343,"title":"ERROR_CANT_ENABLE_DENY_ONLY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["629","0x275","error 629","ERROR_CANT_ENABLE_DENY_ONLY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","enable","deny","only","group","marked","use","for","cannot","enabled"],"errorCode":"629","eventId":"","severity":"Medium","summary":"A group marked use for deny only cannot be enabled.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 629; use the surrounding log entries to confirm it.","resolution":"1. Record where 629 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANT_ENABLE_DENY_ONLY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 629 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A group marked use for deny only cannot be enabled.\n\nLookup forms: 629, 0x275, error 629, ERROR_CANT_ENABLE_DENY_ONLY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["629"]},{"id":344,"title":"ERROR_FLOAT_MULTIPLE_FAULTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["630","0x276","error 630","ERROR_FLOAT_MULTIPLE_FAULTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","float","multiple","faults","exception","floating","point"],"errorCode":"630","eventId":"","severity":"Low","summary":"{EXCEPTION} Multiple floating point faults.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 630; use the surrounding log entries to confirm it.","resolution":"1. Record where 630 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FLOAT_MULTIPLE_FAULTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 630 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {EXCEPTION} Multiple floating point faults.\n\nLookup forms: 630, 0x276, error 630, ERROR_FLOAT_MULTIPLE_FAULTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["630"]},{"id":345,"title":"ERROR_FLOAT_MULTIPLE_TRAPS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["631","0x277","error 631","ERROR_FLOAT_MULTIPLE_TRAPS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","float","multiple","traps","exception","floating","point"],"errorCode":"631","eventId":"","severity":"Low","summary":"{EXCEPTION} Multiple floating point traps.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 631; use the surrounding log entries to confirm it.","resolution":"1. Record where 631 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FLOAT_MULTIPLE_TRAPS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 631 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {EXCEPTION} Multiple floating point traps.\n\nLookup forms: 631, 0x277, error 631, ERROR_FLOAT_MULTIPLE_TRAPS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["631"]},{"id":346,"title":"ERROR_NOINTERFACE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["632","0x278","error 632","ERROR_NOINTERFACE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","nointerface","the","requested","interface","not","supported"],"errorCode":"632","eventId":"","severity":"Medium","summary":"The requested interface is not supported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 632; use the surrounding log entries to confirm it.","resolution":"1. Record where 632 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOINTERFACE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 632 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested interface is not supported.\n\nLookup forms: 632, 0x278, error 632, ERROR_NOINTERFACE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["632"]},{"id":347,"title":"ERROR_DRIVER_FAILED_SLEEP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["633","0x279","error 633","ERROR_DRIVER_FAILED_SLEEP","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","driver","failed","sleep","system","standby","the","does","not","support","mode","updating","this","may","allow"],"errorCode":"633","eventId":"","severity":"High","summary":"{System Standby Failed} The driver %hs does not support standby mode. Updating this driver may allow the system to go to standby mode.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 633; use the surrounding log entries to confirm it.","resolution":"1. Record where 633 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DRIVER_FAILED_SLEEP.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 633 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {System Standby Failed} The driver %hs does not support standby mode. Updating this driver may allow the system to go to standby mode.\n\nLookup forms: 633, 0x279, error 633, ERROR_DRIVER_FAILED_SLEEP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["633"]},{"id":348,"title":"ERROR_CORRUPT_SYSTEM_FILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["634","0x27A","error 634","ERROR_CORRUPT_SYSTEM_FILE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","corrupt","system","file","the","has","become","and","been","replaced"],"errorCode":"634","eventId":"","severity":"Critical","summary":"The system file %1 has become corrupt and has been replaced.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 634; use the surrounding log entries to confirm it.","resolution":"1. Record where 634 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CORRUPT_SYSTEM_FILE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 634 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system file %1 has become corrupt and has been replaced.\n\nLookup forms: 634, 0x27A, error 634, ERROR_CORRUPT_SYSTEM_FILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["634"]},{"id":349,"title":"ERROR_COMMITMENT_MINIMUM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["635","0x27B","error 635","ERROR_COMMITMENT_MINIMUM","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","commitment","minimum","virtual","memory","too","low","your","system","windows","increasing","the","size","paging","file","during","this","process","requests","for","some","applications","may","denied","more"],"errorCode":"635","eventId":"","severity":"Low","summary":"{Virtual Memory Minimum Too Low} Your system is low on virtual memory. Windows is increasing the size of your virtual memory paging file. During this process, memory requests for some applications may be denied. For more information, see Help.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 635; use the surrounding log entries to confirm it.","resolution":"1. Record where 635 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Confirm the user or service identity has the required permissions and is not locked or disabled.\n4. Check available memory, disk capacity, quotas, and system resource pressure.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_COMMITMENT_MINIMUM.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Confirm the user or service identity has the required permissions and is not locked or disabled.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 635 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Virtual Memory Minimum Too Low} Your system is low on virtual memory. Windows is increasing the size of your virtual memory paging file. During this process, memory requests for some applications may be denied. For more information, see Help.\n\nLookup forms: 635, 0x27B, error 635, ERROR_COMMITMENT_MINIMUM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["635"]},{"id":350,"title":"ERROR_PNP_RESTART_ENUMERATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["636","0x27C","error 636","ERROR_PNP_RESTART_ENUMERATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","pnp","restart","enumeration","device","was","removed","must","restarted"],"errorCode":"636","eventId":"","severity":"Low","summary":"A device was removed so enumeration must be restarted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 636; use the surrounding log entries to confirm it.","resolution":"1. Record where 636 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PNP_RESTART_ENUMERATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 636 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A device was removed so enumeration must be restarted.\n\nLookup forms: 636, 0x27C, error 636, ERROR_PNP_RESTART_ENUMERATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["636"]},{"id":351,"title":"ERROR_SYSTEM_IMAGE_BAD_SIGNATURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["637","0x27D","error 637","ERROR_SYSTEM_IMAGE_BAD_SIGNATURE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","system","image","bad","signature","fatal","the","not","properly","signed","file","has","been","replaced","with","shut","down"],"errorCode":"637","eventId":"","severity":"Low","summary":"{Fatal System Error} The system image %s is not properly signed. The file has been replaced with the signed file. The system has been shut down.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 637; use the surrounding log entries to confirm it.","resolution":"1. Record where 637 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SYSTEM_IMAGE_BAD_SIGNATURE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 637 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Fatal System Error} The system image %s is not properly signed. The file has been replaced with the signed file. The system has been shut down.\n\nLookup forms: 637, 0x27D, error 637, ERROR_SYSTEM_IMAGE_BAD_SIGNATURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["637"]},{"id":352,"title":"ERROR_PNP_REBOOT_REQUIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["638","0x27E","error 638","ERROR_PNP_REBOOT_REQUIRED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","pnp","reboot","required","device","will","not","start","without"],"errorCode":"638","eventId":"","severity":"Low","summary":"Device will not start without a reboot.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 638; use the surrounding log entries to confirm it.","resolution":"1. Record where 638 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PNP_REBOOT_REQUIRED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 638 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Device will not start without a reboot.\n\nLookup forms: 638, 0x27E, error 638, ERROR_PNP_REBOOT_REQUIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["638"]},{"id":353,"title":"ERROR_INSUFFICIENT_POWER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["639","0x27F","error 639","ERROR_INSUFFICIENT_POWER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","insufficient","power","there","not","enough","complete","the","requested","operation"],"errorCode":"639","eventId":"","severity":"Low","summary":"There is not enough power to complete the requested operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 639; use the surrounding log entries to confirm it.","resolution":"1. Record where 639 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSUFFICIENT_POWER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 639 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There is not enough power to complete the requested operation.\n\nLookup forms: 639, 0x27F, error 639, ERROR_INSUFFICIENT_POWER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["639"]},{"id":354,"title":"ERROR_MULTIPLE_FAULT_VIOLATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["640","0x280","error 640","ERROR_MULTIPLE_FAULT_VIOLATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","multiple","fault","violation"],"errorCode":"640","eventId":"","severity":"Low","summary":"ERROR_MULTIPLE_FAULT_VIOLATION","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 640; use the surrounding log entries to confirm it.","resolution":"1. Record where 640 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MULTIPLE_FAULT_VIOLATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 640 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: ERROR_MULTIPLE_FAULT_VIOLATION\n\nLookup forms: 640, 0x280, error 640, ERROR_MULTIPLE_FAULT_VIOLATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["640"]},{"id":355,"title":"ERROR_SYSTEM_SHUTDOWN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["641","0x281","error 641","ERROR_SYSTEM_SHUTDOWN","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","system","shutdown","the","process","shutting","down"],"errorCode":"641","eventId":"","severity":"Low","summary":"The system is in the process of shutting down.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 641; use the surrounding log entries to confirm it.","resolution":"1. Record where 641 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SYSTEM_SHUTDOWN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 641 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system is in the process of shutting down.\n\nLookup forms: 641, 0x281, error 641, ERROR_SYSTEM_SHUTDOWN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["641"]},{"id":356,"title":"ERROR_PORT_NOT_SET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["642","0x282","error 642","ERROR_PORT_NOT_SET","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","port","not","set","attempt","remove","processes","debugport","was","made","but","already","associated","with","the","process"],"errorCode":"642","eventId":"","severity":"Low","summary":"An attempt to remove a processes DebugPort was made, but a port was not already associated with the process.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 642; use the surrounding log entries to confirm it.","resolution":"1. Record where 642 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PORT_NOT_SET.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 642 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt to remove a processes DebugPort was made, but a port was not already associated with the process.\n\nLookup forms: 642, 0x282, error 642, ERROR_PORT_NOT_SET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["642"]},{"id":357,"title":"ERROR_DS_VERSION_CHECK_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["643","0x283","error 643","ERROR_DS_VERSION_CHECK_FAILURE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","version","check","failure","this","windows","not","compatible","with","the","behavior","directory","forest","domain","controller"],"errorCode":"643","eventId":"","severity":"Low","summary":"This version of Windows is not compatible with the behavior version of directory forest, domain or domain controller.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 643; use the surrounding log entries to confirm it.","resolution":"1. Record where 643 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_VERSION_CHECK_FAILURE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 643 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This version of Windows is not compatible with the behavior version of directory forest, domain or domain controller.\n\nLookup forms: 643, 0x283, error 643, ERROR_DS_VERSION_CHECK_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["643"]},{"id":358,"title":"ERROR_RANGE_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["644","0x284","error 644","ERROR_RANGE_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","range","not","found","the","specified","could","list"],"errorCode":"644","eventId":"","severity":"Low","summary":"The specified range could not be found in the range list.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 644; use the surrounding log entries to confirm it.","resolution":"1. Record where 644 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RANGE_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 644 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified range could not be found in the range list.\n\nLookup forms: 644, 0x284, error 644, ERROR_RANGE_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["644"]},{"id":359,"title":"ERROR_NOT_SAFE_MODE_DRIVER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["646","0x286","error 646","ERROR_NOT_SAFE_MODE_DRIVER","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","not","safe","mode","driver","the","was","loaded","because","system","booting","into"],"errorCode":"646","eventId":"","severity":"Low","summary":"The driver was not loaded because the system is booting into safe mode.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 646; use the surrounding log entries to confirm it.","resolution":"1. Record where 646 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_SAFE_MODE_DRIVER.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 646 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The driver was not loaded because the system is booting into safe mode.\n\nLookup forms: 646, 0x286, error 646, ERROR_NOT_SAFE_MODE_DRIVER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["646"]},{"id":360,"title":"ERROR_FAILED_DRIVER_ENTRY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["647","0x287","error 647","ERROR_FAILED_DRIVER_ENTRY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","failed","driver","entry","the","was","not","loaded","because","its","initialization","call"],"errorCode":"647","eventId":"","severity":"High","summary":"The driver was not loaded because it failed its initialization call.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 647; use the surrounding log entries to confirm it.","resolution":"1. Record where 647 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FAILED_DRIVER_ENTRY.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 647 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The driver was not loaded because it failed its initialization call.\n\nLookup forms: 647, 0x287, error 647, ERROR_FAILED_DRIVER_ENTRY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["647"]},{"id":361,"title":"ERROR_DEVICE_ENUMERATION_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["648","0x288","error 648","ERROR_DEVICE_ENUMERATION_ERROR","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","device","enumeration","the","encountered","while","applying","power","reading","configuration","this","may","caused","failure","your","hardware","poor","connection"],"errorCode":"648","eventId":"","severity":"High","summary":"The \"%hs\" encountered an error while applying power or reading the device configuration. This may be caused by a failure of your hardware or by a poor connection.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 648; use the surrounding log entries to confirm it.","resolution":"1. Record where 648 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEVICE_ENUMERATION_ERROR.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 648 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The \"%hs\" encountered an error while applying power or reading the device configuration. This may be caused by a failure of your hardware or by a poor connection.\n\nLookup forms: 648, 0x288, error 648, ERROR_DEVICE_ENUMERATION_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["648"]},{"id":362,"title":"ERROR_MOUNT_POINT_NOT_RESOLVED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["649","0x289","error 649","ERROR_MOUNT_POINT_NOT_RESOLVED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","mount","point","not","resolved","the","create","operation","failed","because","name","contained","least","one","which","resolves","volume","specified","device","object","attached"],"errorCode":"649","eventId":"","severity":"High","summary":"The create operation failed because the name contained at least one mount point which resolves to a volume to which the specified device object is not attached.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 649; use the surrounding log entries to confirm it.","resolution":"1. Record where 649 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MOUNT_POINT_NOT_RESOLVED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 649 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The create operation failed because the name contained at least one mount point which resolves to a volume to which the specified device object is not attached.\n\nLookup forms: 649, 0x289, error 649, ERROR_MOUNT_POINT_NOT_RESOLVED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["649"]},{"id":363,"title":"ERROR_INVALID_DEVICE_OBJECT_PARAMETER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["650","0x28A","error 650","ERROR_INVALID_DEVICE_OBJECT_PARAMETER","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","invalid","device","object","parameter","the","either","not","valid","attached","volume","specified","file","name"],"errorCode":"650","eventId":"","severity":"Low","summary":"The device object parameter is either not a valid device object or is not attached to the volume specified by the file name.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 650; use the surrounding log entries to confirm it.","resolution":"1. Record where 650 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_DEVICE_OBJECT_PARAMETER.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 650 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The device object parameter is either not a valid device object or is not attached to the volume specified by the file name.\n\nLookup forms: 650, 0x28A, error 650, ERROR_INVALID_DEVICE_OBJECT_PARAMETER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["650"]},{"id":364,"title":"ERROR_MCA_OCCURED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["651","0x28B","error 651","ERROR_MCA_OCCURED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","mca","occured","machine","check","has","occurred","please","the","system","eventlog","for","additional","information"],"errorCode":"651","eventId":"","severity":"Low","summary":"A Machine Check Error has occurred. Please check the system eventlog for additional information.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 651; use the surrounding log entries to confirm it.","resolution":"1. Record where 651 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MCA_OCCURED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 651 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A Machine Check Error has occurred. Please check the system eventlog for additional information.\n\nLookup forms: 651, 0x28B, error 651, ERROR_MCA_OCCURED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["651"]},{"id":365,"title":"ERROR_DRIVER_DATABASE_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["652","0x28C","error 652","ERROR_DRIVER_DATABASE_ERROR","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","driver","database","there","was","processing","the"],"errorCode":"652","eventId":"","severity":"Low","summary":"There was error [%2] processing the driver database.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 652; use the surrounding log entries to confirm it.","resolution":"1. Record where 652 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DRIVER_DATABASE_ERROR.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 652 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There was error [%2] processing the driver database.\n\nLookup forms: 652, 0x28C, error 652, ERROR_DRIVER_DATABASE_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["652"]},{"id":366,"title":"ERROR_SYSTEM_HIVE_TOO_LARGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["653","0x28D","error 653","ERROR_SYSTEM_HIVE_TOO_LARGE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","system","hive","too","large","size","has","exceeded","its","limit"],"errorCode":"653","eventId":"","severity":"Low","summary":"System hive size has exceeded its limit.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 653; use the surrounding log entries to confirm it.","resolution":"1. Record where 653 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SYSTEM_HIVE_TOO_LARGE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 653 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: System hive size has exceeded its limit.\n\nLookup forms: 653, 0x28D, error 653, ERROR_SYSTEM_HIVE_TOO_LARGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["653"]},{"id":367,"title":"ERROR_DRIVER_FAILED_PRIOR_UNLOAD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["654","0x28E","error 654","ERROR_DRIVER_FAILED_PRIOR_UNLOAD","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","driver","failed","prior","unload","the","could","not","loaded","because","previous","version","still","memory"],"errorCode":"654","eventId":"","severity":"Low","summary":"The driver could not be loaded because a previous version of the driver is still in memory.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 654; use the surrounding log entries to confirm it.","resolution":"1. Record where 654 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DRIVER_FAILED_PRIOR_UNLOAD.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 654 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The driver could not be loaded because a previous version of the driver is still in memory.\n\nLookup forms: 654, 0x28E, error 654, ERROR_DRIVER_FAILED_PRIOR_UNLOAD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["654"]},{"id":368,"title":"ERROR_VOLSNAP_PREPARE_HIBERNATE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["655","0x28F","error 655","ERROR_VOLSNAP_PREPARE_HIBERNATE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","volsnap","prepare","hibernate","volume","shadow","copy","service","please","wait","while","the","prepares","for","hibernation"],"errorCode":"655","eventId":"","severity":"Low","summary":"{Volume Shadow Copy Service} Please wait while the Volume Shadow Copy Service prepares volume %hs for hibernation.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 655; use the surrounding log entries to confirm it.","resolution":"1. Record where 655 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_VOLSNAP_PREPARE_HIBERNATE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 655 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Volume Shadow Copy Service} Please wait while the Volume Shadow Copy Service prepares volume %hs for hibernation.\n\nLookup forms: 655, 0x28F, error 655, ERROR_VOLSNAP_PREPARE_HIBERNATE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["655"]},{"id":369,"title":"ERROR_HIBERNATION_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["656","0x290","error 656","ERROR_HIBERNATION_FAILURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","hibernation","failure","the","system","has","failed","hibernate","code","will","disabled","until","restarted"],"errorCode":"656","eventId":"","severity":"High","summary":"The system has failed to hibernate (The error code is %hs). Hibernation will be disabled until the system is restarted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 656; use the surrounding log entries to confirm it.","resolution":"1. Record where 656 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_HIBERNATION_FAILURE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 656 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system has failed to hibernate (The error code is %hs). Hibernation will be disabled until the system is restarted.\n\nLookup forms: 656, 0x290, error 656, ERROR_HIBERNATION_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["656"]},{"id":370,"title":"ERROR_PWD_TOO_LONG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["657","0x291","error 657","ERROR_PWD_TOO_LONG","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","pwd","too","long","the","password","provided","meet","policy","your","user","account","please","choose","shorter"],"errorCode":"657","eventId":"","severity":"Low","summary":"The password provided is too long to meet the policy of your user account. Please choose a shorter password.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 657; use the surrounding log entries to confirm it.","resolution":"1. Record where 657 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PWD_TOO_LONG.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 657 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The password provided is too long to meet the policy of your user account. Please choose a shorter password.\n\nLookup forms: 657, 0x291, error 657, ERROR_PWD_TOO_LONG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["657"]},{"id":371,"title":"ERROR_FILE_SYSTEM_LIMITATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["665","0x299","error 665","ERROR_FILE_SYSTEM_LIMITATION","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","file","system","limitation","the","requested","operation","could","not","completed","due"],"errorCode":"665","eventId":"","severity":"Low","summary":"The requested operation could not be completed due to a file system limitation.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 665; use the surrounding log entries to confirm it.","resolution":"1. Record where 665 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FILE_SYSTEM_LIMITATION.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 665 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested operation could not be completed due to a file system limitation.\n\nLookup forms: 665, 0x299, error 665, ERROR_FILE_SYSTEM_LIMITATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["665"]},{"id":372,"title":"ERROR_ASSERTION_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["668","0x29C","error 668","ERROR_ASSERTION_FAILURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","assertion","failure","has","occurred"],"errorCode":"668","eventId":"","severity":"High","summary":"An assertion failure has occurred.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 668; use the surrounding log entries to confirm it.","resolution":"1. Record where 668 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ASSERTION_FAILURE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 668 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An assertion failure has occurred.\n\nLookup forms: 668, 0x29C, error 668, ERROR_ASSERTION_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["668"]},{"id":373,"title":"ERROR_ACPI_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["669","0x29D","error 669","ERROR_ACPI_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","acpi","occurred","the","subsystem"],"errorCode":"669","eventId":"","severity":"Low","summary":"An error occurred in the ACPI subsystem.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 669; use the surrounding log entries to confirm it.","resolution":"1. Record where 669 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ACPI_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 669 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An error occurred in the ACPI subsystem.\n\nLookup forms: 669, 0x29D, error 669, ERROR_ACPI_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["669"]},{"id":374,"title":"ERROR_WOW_ASSERTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["670","0x29E","error 670","ERROR_WOW_ASSERTION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wow","assertion"],"errorCode":"670","eventId":"","severity":"Low","summary":"WOW Assertion Error.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 670; use the surrounding log entries to confirm it.","resolution":"1. Record where 670 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WOW_ASSERTION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 670 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: WOW Assertion Error.\n\nLookup forms: 670, 0x29E, error 670, ERROR_WOW_ASSERTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["670"]},{"id":375,"title":"ERROR_PNP_BAD_MPS_TABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["671","0x29F","error 671","ERROR_PNP_BAD_MPS_TABLE","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","pnp","bad","mps","table","device","missing","the","system","bios","this","will","not","used","please","contact","your","vendor","for","update"],"errorCode":"671","eventId":"","severity":"Low","summary":"A device is missing in the system BIOS MPS table. This device will not be used. Please contact your system vendor for system BIOS update.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 671; use the surrounding log entries to confirm it.","resolution":"1. Record where 671 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PNP_BAD_MPS_TABLE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 671 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A device is missing in the system BIOS MPS table. This device will not be used. Please contact your system vendor for system BIOS update.\n\nLookup forms: 671, 0x29F, error 671, ERROR_PNP_BAD_MPS_TABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["671"]},{"id":376,"title":"ERROR_PNP_TRANSLATION_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["672","0x2A0","error 672","ERROR_PNP_TRANSLATION_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","pnp","translation","failed","translator","translate","resources"],"errorCode":"672","eventId":"","severity":"High","summary":"A translator failed to translate resources.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 672; use the surrounding log entries to confirm it.","resolution":"1. Record where 672 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PNP_TRANSLATION_FAILED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 672 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A translator failed to translate resources.\n\nLookup forms: 672, 0x2A0, error 672, ERROR_PNP_TRANSLATION_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["672"]},{"id":377,"title":"ERROR_PNP_IRQ_TRANSLATION_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["673","0x2A1","error 673","ERROR_PNP_IRQ_TRANSLATION_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","pnp","irq","translation","failed","translator","translate","resources"],"errorCode":"673","eventId":"","severity":"High","summary":"A IRQ translator failed to translate resources.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 673; use the surrounding log entries to confirm it.","resolution":"1. Record where 673 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PNP_IRQ_TRANSLATION_FAILED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 673 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A IRQ translator failed to translate resources.\n\nLookup forms: 673, 0x2A1, error 673, ERROR_PNP_IRQ_TRANSLATION_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["673"]},{"id":378,"title":"ERROR_PNP_INVALID_ID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["674","0x2A2","error 674","ERROR_PNP_INVALID_ID","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","pnp","invalid","driver","returned","for","child","device"],"errorCode":"674","eventId":"","severity":"Medium","summary":"Driver %2 returned invalid ID for a child device (%3).","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 674; use the surrounding log entries to confirm it.","resolution":"1. Record where 674 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PNP_INVALID_ID.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 674 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Driver %2 returned invalid ID for a child device (%3).\n\nLookup forms: 674, 0x2A2, error 674, ERROR_PNP_INVALID_ID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["674"]},{"id":379,"title":"ERROR_WAKE_SYSTEM_DEBUGGER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["675","0x2A3","error 675","ERROR_WAKE_SYSTEM_DEBUGGER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wake","system","debugger","kernel","awakened","the","was","interrupt"],"errorCode":"675","eventId":"","severity":"Low","summary":"{Kernel Debugger Awakened} the system debugger was awakened by an interrupt.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 675; use the surrounding log entries to confirm it.","resolution":"1. Record where 675 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WAKE_SYSTEM_DEBUGGER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 675 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Kernel Debugger Awakened} the system debugger was awakened by an interrupt.\n\nLookup forms: 675, 0x2A3, error 675, ERROR_WAKE_SYSTEM_DEBUGGER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["675"]},{"id":380,"title":"ERROR_HANDLES_CLOSED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["676","0x2A4","error 676","ERROR_HANDLES_CLOSED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","handles","closed","objects","have","been","automatically","result","the","requested","operation"],"errorCode":"676","eventId":"","severity":"Low","summary":"{Handles Closed} Handles to objects have been automatically closed as a result of the requested operation.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 676; use the surrounding log entries to confirm it.","resolution":"1. Record where 676 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_HANDLES_CLOSED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 676 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Handles Closed} Handles to objects have been automatically closed as a result of the requested operation.\n\nLookup forms: 676, 0x2A4, error 676, ERROR_HANDLES_CLOSED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["676"]},{"id":381,"title":"ERROR_EXTRANEOUS_INFORMATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["677","0x2A5","error 677","ERROR_EXTRANEOUS_INFORMATION","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","extraneous","information","too","much","the","specified","access","control","list","acl","contained","more","than","was","expected"],"errorCode":"677","eventId":"","severity":"Low","summary":"{Too Much Information} The specified access control list (ACL) contained more information than was expected.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 677; use the surrounding log entries to confirm it.","resolution":"1. Record where 677 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EXTRANEOUS_INFORMATION.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 677 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Too Much Information} The specified access control list (ACL) contained more information than was expected.\n\nLookup forms: 677, 0x2A5, error 677, ERROR_EXTRANEOUS_INFORMATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["677"]},{"id":382,"title":"ERROR_RXACT_COMMIT_NECESSARY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["678","0x2A6","error 678","ERROR_RXACT_COMMIT_NECESSARY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","rxact","commit","necessary","this","warning","level","status","indicates","that","the","transaction","state","already","exists","for","registry","sub","tree","but","was","previously","aborted","has","not"],"errorCode":"678","eventId":"","severity":"Medium","summary":"This warning level status indicates that the transaction state already exists for the registry sub-tree, but that a transaction commit was previously aborted. The commit has NOT been completed, but has not been rolled back either (so it may still be committed if desired).","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 678; use the surrounding log entries to confirm it.","resolution":"1. Record where 678 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RXACT_COMMIT_NECESSARY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 678 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This warning level status indicates that the transaction state already exists for the registry sub-tree, but that a transaction commit was previously aborted. The commit has NOT been completed, but has not been rolled back either (so it may still be committed if desired).\n\nLookup forms: 678, 0x2A6, error 678, ERROR_RXACT_COMMIT_NECESSARY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["678"]},{"id":383,"title":"ERROR_MEDIA_CHECK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["679","0x2A7","error 679","ERROR_MEDIA_CHECK","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","media","check","changed","the","may","have"],"errorCode":"679","eventId":"","severity":"Low","summary":"{Media Changed} The media may have changed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 679; use the surrounding log entries to confirm it.","resolution":"1. Record where 679 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MEDIA_CHECK.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 679 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Media Changed} The media may have changed.\n\nLookup forms: 679, 0x2A7, error 679, ERROR_MEDIA_CHECK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["679"]},{"id":384,"title":"ERROR_GUID_SUBSTITUTION_MADE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["680","0x2A8","error 680","ERROR_GUID_SUBSTITUTION_MADE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","guid","substitution","made","during","the","translation","global","identifier","windows","security","sid","administratively","defined","prefix","was","found","substitute","used","which","will","not","compromise","system","however"],"errorCode":"680","eventId":"","severity":"Low","summary":"{GUID Substitution} During the translation of a global identifier (GUID) to a Windows security ID (SID), no administratively-defined GUID prefix was found. A substitute prefix was used, which will not compromise system security. However, this may provide a more restrictive access than intended.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 680; use the surrounding log entries to confirm it.","resolution":"1. Record where 680 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_GUID_SUBSTITUTION_MADE.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 680 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {GUID Substitution} During the translation of a global identifier (GUID) to a Windows security ID (SID), no administratively-defined GUID prefix was found. A substitute prefix was used, which will not compromise system security. However, this may provide a more restrictive access than intended.\n\nLookup forms: 680, 0x2A8, error 680, ERROR_GUID_SUBSTITUTION_MADE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["680"]},{"id":385,"title":"ERROR_STOPPED_ON_SYMLINK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["681","0x2A9","error 681","ERROR_STOPPED_ON_SYMLINK","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","stopped","symlink","the","create","operation","after","reaching","symbolic","link"],"errorCode":"681","eventId":"","severity":"Low","summary":"The create operation stopped after reaching a symbolic link.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 681; use the surrounding log entries to confirm it.","resolution":"1. Record where 681 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STOPPED_ON_SYMLINK.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 681 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The create operation stopped after reaching a symbolic link.\n\nLookup forms: 681, 0x2A9, error 681, ERROR_STOPPED_ON_SYMLINK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["681"]},{"id":386,"title":"ERROR_LONGJUMP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["682","0x2AA","error 682","ERROR_LONGJUMP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","longjump","long","jump","has","been","executed"],"errorCode":"682","eventId":"","severity":"Low","summary":"A long jump has been executed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 682; use the surrounding log entries to confirm it.","resolution":"1. Record where 682 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LONGJUMP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 682 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A long jump has been executed.\n\nLookup forms: 682, 0x2AA, error 682, ERROR_LONGJUMP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["682"]},{"id":387,"title":"ERROR_PLUGPLAY_QUERY_VETOED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["683","0x2AB","error 683","ERROR_PLUGPLAY_QUERY_VETOED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","plugplay","query","vetoed","the","plug","and","play","operation","was","not","successful"],"errorCode":"683","eventId":"","severity":"Low","summary":"The Plug and Play query operation was not successful.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 683; use the surrounding log entries to confirm it.","resolution":"1. Record where 683 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PLUGPLAY_QUERY_VETOED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 683 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Plug and Play query operation was not successful.\n\nLookup forms: 683, 0x2AB, error 683, ERROR_PLUGPLAY_QUERY_VETOED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["683"]},{"id":388,"title":"ERROR_UNWIND_CONSOLIDATE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["684","0x2AC","error 684","ERROR_UNWIND_CONSOLIDATE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","unwind","consolidate","frame","consolidation","has","been","executed"],"errorCode":"684","eventId":"","severity":"Low","summary":"A frame consolidation has been executed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 684; use the surrounding log entries to confirm it.","resolution":"1. Record where 684 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNWIND_CONSOLIDATE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 684 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A frame consolidation has been executed.\n\nLookup forms: 684, 0x2AC, error 684, ERROR_UNWIND_CONSOLIDATE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["684"]},{"id":389,"title":"ERROR_REGISTRY_HIVE_RECOVERED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["685","0x2AD","error 685","ERROR_REGISTRY_HIVE_RECOVERED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","registry","hive","recovered","file","was","corrupted","and","has","been","some","data","might","have","lost"],"errorCode":"685","eventId":"","severity":"Critical","summary":"{Registry Hive Recovered} Registry hive (file): %hs was corrupted and it has been recovered. Some data might have been lost.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 685; use the surrounding log entries to confirm it.","resolution":"1. Record where 685 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REGISTRY_HIVE_RECOVERED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 685 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Registry Hive Recovered} Registry hive (file): %hs was corrupted and it has been recovered. Some data might have been lost.\n\nLookup forms: 685, 0x2AD, error 685, ERROR_REGISTRY_HIVE_RECOVERED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["685"]},{"id":390,"title":"ERROR_DLL_MIGHT_BE_INSECURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["686","0x2AE","error 686","ERROR_DLL_MIGHT_BE_INSECURE","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","dll","might","insecure","the","application","attempting","run","executable","code","from","module","this","may","alternative","available","should","use","secure"],"errorCode":"686","eventId":"","severity":"Low","summary":"The application is attempting to run executable code from the module %hs. This may be insecure. An alternative, %hs, is available. Should the application use the secure module %hs?","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 686; use the surrounding log entries to confirm it.","resolution":"1. Record where 686 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DLL_MIGHT_BE_INSECURE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 686 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The application is attempting to run executable code from the module %hs. This may be insecure. An alternative, %hs, is available. Should the application use the secure module %hs?\n\nLookup forms: 686, 0x2AE, error 686, ERROR_DLL_MIGHT_BE_INSECURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["686"]},{"id":391,"title":"ERROR_DLL_MIGHT_BE_INCOMPATIBLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["687","0x2AF","error 687","ERROR_DLL_MIGHT_BE_INCOMPATIBLE","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","dll","might","incompatible","the","application","loading","executable","code","from","module","this","secure","but","may","with","previous","releases","operating","system","alternative","available","should","use"],"errorCode":"687","eventId":"","severity":"Low","summary":"The application is loading executable code from the module %hs. This is secure, but may be incompatible with previous releases of the operating system. An alternative, %hs, is available. Should the application use the secure module %hs?","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 687; use the surrounding log entries to confirm it.","resolution":"1. Record where 687 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DLL_MIGHT_BE_INCOMPATIBLE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 687 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The application is loading executable code from the module %hs. This is secure, but may be incompatible with previous releases of the operating system. An alternative, %hs, is available. Should the application use the secure module %hs?\n\nLookup forms: 687, 0x2AF, error 687, ERROR_DLL_MIGHT_BE_INCOMPATIBLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["687"]},{"id":392,"title":"ERROR_DBG_EXCEPTION_NOT_HANDLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["688","0x2B0","error 688","ERROR_DBG_EXCEPTION_NOT_HANDLED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","dbg","exception","not","handled","debugger","did","handle","the"],"errorCode":"688","eventId":"","severity":"Low","summary":"Debugger did not handle the exception.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 688; use the surrounding log entries to confirm it.","resolution":"1. Record where 688 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DBG_EXCEPTION_NOT_HANDLED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 688 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Debugger did not handle the exception.\n\nLookup forms: 688, 0x2B0, error 688, ERROR_DBG_EXCEPTION_NOT_HANDLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["688"]},{"id":393,"title":"ERROR_DBG_REPLY_LATER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["689","0x2B1","error 689","ERROR_DBG_REPLY_LATER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dbg","reply","later","debugger","will"],"errorCode":"689","eventId":"","severity":"Low","summary":"Debugger will reply later.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 689; use the surrounding log entries to confirm it.","resolution":"1. Record where 689 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DBG_REPLY_LATER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 689 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Debugger will reply later.\n\nLookup forms: 689, 0x2B1, error 689, ERROR_DBG_REPLY_LATER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["689"]},{"id":394,"title":"ERROR_DBG_UNABLE_TO_PROVIDE_HANDLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["690","0x2B2","error 690","ERROR_DBG_UNABLE_TO_PROVIDE_HANDLE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","dbg","unable","provide","handle","debugger","cannot"],"errorCode":"690","eventId":"","severity":"Medium","summary":"Debugger cannot provide handle.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 690; use the surrounding log entries to confirm it.","resolution":"1. Record where 690 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DBG_UNABLE_TO_PROVIDE_HANDLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 690 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Debugger cannot provide handle.\n\nLookup forms: 690, 0x2B2, error 690, ERROR_DBG_UNABLE_TO_PROVIDE_HANDLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["690"]},{"id":395,"title":"ERROR_DBG_TERMINATE_THREAD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["691","0x2B3","error 691","ERROR_DBG_TERMINATE_THREAD","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","dbg","terminate","thread","debugger","terminated"],"errorCode":"691","eventId":"","severity":"Low","summary":"Debugger terminated thread.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 691; use the surrounding log entries to confirm it.","resolution":"1. Record where 691 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DBG_TERMINATE_THREAD.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 691 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Debugger terminated thread.\n\nLookup forms: 691, 0x2B3, error 691, ERROR_DBG_TERMINATE_THREAD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["691"]},{"id":396,"title":"ERROR_DBG_TERMINATE_PROCESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["692","0x2B4","error 692","ERROR_DBG_TERMINATE_PROCESS","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","dbg","terminate","process","debugger","terminated"],"errorCode":"692","eventId":"","severity":"Low","summary":"Debugger terminated process.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 692; use the surrounding log entries to confirm it.","resolution":"1. Record where 692 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DBG_TERMINATE_PROCESS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 692 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Debugger terminated process.\n\nLookup forms: 692, 0x2B4, error 692, ERROR_DBG_TERMINATE_PROCESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["692"]},{"id":397,"title":"ERROR_DBG_CONTROL_C","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["693","0x2B5","error 693","ERROR_DBG_CONTROL_C","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dbg","control","debugger","got"],"errorCode":"693","eventId":"","severity":"Low","summary":"Debugger got control C.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 693; use the surrounding log entries to confirm it.","resolution":"1. Record where 693 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DBG_CONTROL_C.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 693 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Debugger got control C.\n\nLookup forms: 693, 0x2B5, error 693, ERROR_DBG_CONTROL_C. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["693"]},{"id":398,"title":"ERROR_DBG_PRINTEXCEPTION_C","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["694","0x2B6","error 694","ERROR_DBG_PRINTEXCEPTION_C","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dbg","printexception","debugger","printed","exception","control"],"errorCode":"694","eventId":"","severity":"Low","summary":"Debugger printed exception on control C.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 694; use the surrounding log entries to confirm it.","resolution":"1. Record where 694 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DBG_PRINTEXCEPTION_C.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 694 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Debugger printed exception on control C.\n\nLookup forms: 694, 0x2B6, error 694, ERROR_DBG_PRINTEXCEPTION_C. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["694"]},{"id":399,"title":"ERROR_DBG_RIPEXCEPTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["695","0x2B7","error 695","ERROR_DBG_RIPEXCEPTION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dbg","ripexception","debugger","received","rip","exception"],"errorCode":"695","eventId":"","severity":"Low","summary":"Debugger received RIP exception.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 695; use the surrounding log entries to confirm it.","resolution":"1. Record where 695 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DBG_RIPEXCEPTION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 695 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Debugger received RIP exception.\n\nLookup forms: 695, 0x2B7, error 695, ERROR_DBG_RIPEXCEPTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["695"]},{"id":400,"title":"ERROR_DBG_CONTROL_BREAK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["696","0x2B8","error 696","ERROR_DBG_CONTROL_BREAK","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dbg","control","break","debugger","received"],"errorCode":"696","eventId":"","severity":"Low","summary":"Debugger received control break.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 696; use the surrounding log entries to confirm it.","resolution":"1. Record where 696 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DBG_CONTROL_BREAK.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 696 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Debugger received control break.\n\nLookup forms: 696, 0x2B8, error 696, ERROR_DBG_CONTROL_BREAK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["696"]},{"id":401,"title":"ERROR_DBG_COMMAND_EXCEPTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["697","0x2B9","error 697","ERROR_DBG_COMMAND_EXCEPTION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dbg","command","exception","debugger","communication"],"errorCode":"697","eventId":"","severity":"Low","summary":"Debugger command communication exception.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 697; use the surrounding log entries to confirm it.","resolution":"1. Record where 697 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DBG_COMMAND_EXCEPTION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 697 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Debugger command communication exception.\n\nLookup forms: 697, 0x2B9, error 697, ERROR_DBG_COMMAND_EXCEPTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["697"]},{"id":402,"title":"ERROR_OBJECT_NAME_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["698","0x2BA","error 698","ERROR_OBJECT_NAME_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","object","name","exists","attempt","was","made","create","and","the","already","existed"],"errorCode":"698","eventId":"","severity":"Low","summary":"{Object Exists} An attempt was made to create an object and the object name already existed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 698; use the surrounding log entries to confirm it.","resolution":"1. Record where 698 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_OBJECT_NAME_EXISTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 698 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Object Exists} An attempt was made to create an object and the object name already existed.\n\nLookup forms: 698, 0x2BA, error 698, ERROR_OBJECT_NAME_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["698"]},{"id":403,"title":"ERROR_THREAD_WAS_SUSPENDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["699","0x2BB","error 699","ERROR_THREAD_WAS_SUSPENDED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","thread","was","suspended","termination","occurred","while","the","resumed","and","proceeded"],"errorCode":"699","eventId":"","severity":"Low","summary":"{Thread Suspended} A thread termination occurred while the thread was suspended. The thread was resumed, and termination proceeded.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 699; use the surrounding log entries to confirm it.","resolution":"1. Record where 699 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_THREAD_WAS_SUSPENDED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 699 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Thread Suspended} A thread termination occurred while the thread was suspended. The thread was resumed, and termination proceeded.\n\nLookup forms: 699, 0x2BB, error 699, ERROR_THREAD_WAS_SUSPENDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["699"]},{"id":404,"title":"ERROR_IMAGE_NOT_AT_BASE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["700","0x2BC","error 700","ERROR_IMAGE_NOT_AT_BASE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","image","not","base","relocated","file","could","mapped","the","address","specified","local","fixups","must","performed","this"],"errorCode":"700","eventId":"","severity":"Low","summary":"{Image Relocated} An image file could not be mapped at the address specified in the image file. Local fixups must be performed on this image.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 700; use the surrounding log entries to confirm it.","resolution":"1. Record where 700 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IMAGE_NOT_AT_BASE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 700 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Image Relocated} An image file could not be mapped at the address specified in the image file. Local fixups must be performed on this image.\n\nLookup forms: 700, 0x2BC, error 700, ERROR_IMAGE_NOT_AT_BASE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["700"]},{"id":405,"title":"ERROR_RXACT_STATE_CREATED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["701","0x2BD","error 701","ERROR_RXACT_STATE_CREATED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","rxact","state","created","this","informational","level","status","indicates","that","specified","registry","sub","tree","transaction","did","not","yet","exist","and","had"],"errorCode":"701","eventId":"","severity":"Low","summary":"This informational level status indicates that a specified registry sub-tree transaction state did not yet exist and had to be created.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 701; use the surrounding log entries to confirm it.","resolution":"1. Record where 701 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RXACT_STATE_CREATED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 701 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This informational level status indicates that a specified registry sub-tree transaction state did not yet exist and had to be created.\n\nLookup forms: 701, 0x2BD, error 701, ERROR_RXACT_STATE_CREATED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["701"]},{"id":406,"title":"ERROR_SEGMENT_NOTIFICATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["702","0x2BE","error 702","ERROR_SEGMENT_NOTIFICATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","segment","notification","load","virtual","dos","machine","vdm","loading","unloading","moving","win16","program","image","exception","raised","debugger","can","unload","track","symbols","and","breakpoints","within","these"],"errorCode":"702","eventId":"","severity":"Low","summary":"{Segment Load} A virtual DOS machine (VDM) is loading, unloading, or moving an MS-DOS or Win16 program segment image. An exception is raised so a debugger can load, unload or track symbols and breakpoints within these 16-bit segments.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 702; use the surrounding log entries to confirm it.","resolution":"1. Record where 702 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SEGMENT_NOTIFICATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 702 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Segment Load} A virtual DOS machine (VDM) is loading, unloading, or moving an MS-DOS or Win16 program segment image. An exception is raised so a debugger can load, unload or track symbols and breakpoints within these 16-bit segments.\n\nLookup forms: 702, 0x2BE, error 702, ERROR_SEGMENT_NOTIFICATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["702"]},{"id":407,"title":"ERROR_BAD_CURRENT_DIRECTORY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["703","0x2BF","error 703","ERROR_BAD_CURRENT_DIRECTORY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","bad","current","directory","invalid","the","process","cannot","switch","startup","select","set","cancel","exit"],"errorCode":"703","eventId":"","severity":"Medium","summary":"{Invalid Current Directory} The process cannot switch to the startup current directory %hs. Select OK to set current directory to %hs, or select CANCEL to exit.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 703; use the surrounding log entries to confirm it.","resolution":"1. Record where 703 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_CURRENT_DIRECTORY.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 703 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Invalid Current Directory} The process cannot switch to the startup current directory %hs. Select OK to set current directory to %hs, or select CANCEL to exit.\n\nLookup forms: 703, 0x2BF, error 703, ERROR_BAD_CURRENT_DIRECTORY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["703"]},{"id":408,"title":"ERROR_FT_READ_RECOVERY_FROM_BACKUP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["704","0x2C0","error 704","ERROR_FT_READ_RECOVERY_FROM_BACKUP","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","read","recovery","from","backup","redundant","satisfy","request","the","fault","tolerant","file","system","successfully","requested","data","copy","this","was","done","because","encountered","failure","member","volume"],"errorCode":"704","eventId":"","severity":"High","summary":"{Redundant Read} To satisfy a read request, the NT fault-tolerant file system successfully read the requested data from a redundant copy. This was done because the file system encountered a failure on a member of the fault-tolerant volume, but was unable to reassign the failing area of the device.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 704; use the surrounding log entries to confirm it.","resolution":"1. Record where 704 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FT_READ_RECOVERY_FROM_BACKUP.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 704 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Redundant Read} To satisfy a read request, the NT fault-tolerant file system successfully read the requested data from a redundant copy. This was done because the file system encountered a failure on a member of the fault-tolerant volume, but was unable to reassign the failing area of the device.\n\nLookup forms: 704, 0x2C0, error 704, ERROR_FT_READ_RECOVERY_FROM_BACKUP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["704"]},{"id":409,"title":"ERROR_FT_WRITE_RECOVERY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["705","0x2C1","error 705","ERROR_FT_WRITE_RECOVERY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","write","recovery","redundant","satisfy","request","the","fault","tolerant","file","system","successfully","wrote","copy","information","this","was","done","because","encountered","failure","member","volume","but","not"],"errorCode":"705","eventId":"","severity":"High","summary":"{Redundant Write} To satisfy a write request, the NT fault-tolerant file system successfully wrote a redundant copy of the information. This was done because the file system encountered a failure on a member of the fault-tolerant volume, but was not able to reassign the failing area of the device.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 705; use the surrounding log entries to confirm it.","resolution":"1. Record where 705 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FT_WRITE_RECOVERY.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 705 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Redundant Write} To satisfy a write request, the NT fault-tolerant file system successfully wrote a redundant copy of the information. This was done because the file system encountered a failure on a member of the fault-tolerant volume, but was not able to reassign the failing area of the device.\n\nLookup forms: 705, 0x2C1, error 705, ERROR_FT_WRITE_RECOVERY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["705"]},{"id":410,"title":"ERROR_IMAGE_MACHINE_TYPE_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["706","0x2C2","error 706","ERROR_IMAGE_MACHINE_TYPE_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","image","machine","type","mismatch","the","file","valid","but","for","other","than","current","select","continue","cancel","fail","dll","load"],"errorCode":"706","eventId":"","severity":"Low","summary":"{Machine Type Mismatch} The image file %hs is valid, but is for a machine type other than the current machine. Select OK to continue, or CANCEL to fail the DLL load.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 706; use the surrounding log entries to confirm it.","resolution":"1. Record where 706 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IMAGE_MACHINE_TYPE_MISMATCH.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 706 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Machine Type Mismatch} The image file %hs is valid, but is for a machine type other than the current machine. Select OK to continue, or CANCEL to fail the DLL load.\n\nLookup forms: 706, 0x2C2, error 706, ERROR_IMAGE_MACHINE_TYPE_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["706"]},{"id":411,"title":"ERROR_RECEIVE_PARTIAL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["707","0x2C3","error 707","ERROR_RECEIVE_PARTIAL","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","receive","partial","data","received","the","network","transport","returned","its","client","remaining","will","sent","later"],"errorCode":"707","eventId":"","severity":"High","summary":"{Partial Data Received} The network transport returned partial data to its client. The remaining data will be sent later.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 707; use the surrounding log entries to confirm it.","resolution":"1. Record where 707 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RECEIVE_PARTIAL.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 707 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Partial Data Received} The network transport returned partial data to its client. The remaining data will be sent later.\n\nLookup forms: 707, 0x2C3, error 707, ERROR_RECEIVE_PARTIAL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["707"]},{"id":412,"title":"ERROR_RECEIVE_EXPEDITED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["708","0x2C4","error 708","ERROR_RECEIVE_EXPEDITED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","receive","expedited","data","received","the","network","transport","returned","its","client","that","was","marked","remote","system"],"errorCode":"708","eventId":"","severity":"High","summary":"{Expedited Data Received} The network transport returned data to its client that was marked as expedited by the remote system.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 708; use the surrounding log entries to confirm it.","resolution":"1. Record where 708 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RECEIVE_EXPEDITED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 708 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Expedited Data Received} The network transport returned data to its client that was marked as expedited by the remote system.\n\nLookup forms: 708, 0x2C4, error 708, ERROR_RECEIVE_EXPEDITED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["708"]},{"id":413,"title":"ERROR_RECEIVE_PARTIAL_EXPEDITED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["709","0x2C5","error 709","ERROR_RECEIVE_PARTIAL_EXPEDITED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","receive","partial","expedited","data","received","the","network","transport","returned","its","client","and","this","was","marked","remote","system","remaining","will","sent","later"],"errorCode":"709","eventId":"","severity":"High","summary":"{Partial Expedited Data Received} The network transport returned partial data to its client and this data was marked as expedited by the remote system. The remaining data will be sent later.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 709; use the surrounding log entries to confirm it.","resolution":"1. Record where 709 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RECEIVE_PARTIAL_EXPEDITED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 709 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Partial Expedited Data Received} The network transport returned partial data to its client and this data was marked as expedited by the remote system. The remaining data will be sent later.\n\nLookup forms: 709, 0x2C5, error 709, ERROR_RECEIVE_PARTIAL_EXPEDITED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["709"]},{"id":414,"title":"ERROR_EVENT_DONE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["710","0x2C6","error 710","ERROR_EVENT_DONE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","event","done","tdi","the","indication","has","completed","successfully"],"errorCode":"710","eventId":"","severity":"Low","summary":"{TDI Event Done} The TDI indication has completed successfully.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 710; use the surrounding log entries to confirm it.","resolution":"1. Record where 710 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVENT_DONE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 710 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {TDI Event Done} The TDI indication has completed successfully.\n\nLookup forms: 710, 0x2C6, error 710, ERROR_EVENT_DONE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["710"]},{"id":415,"title":"ERROR_EVENT_PENDING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["711","0x2C7","error 711","ERROR_EVENT_PENDING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","event","pending","tdi","the","indication","has","entered","state"],"errorCode":"711","eventId":"","severity":"Low","summary":"{TDI Event Pending} The TDI indication has entered the pending state.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 711; use the surrounding log entries to confirm it.","resolution":"1. Record where 711 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVENT_PENDING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 711 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {TDI Event Pending} The TDI indication has entered the pending state.\n\nLookup forms: 711, 0x2C7, error 711, ERROR_EVENT_PENDING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["711"]},{"id":416,"title":"ERROR_CHECKING_FILE_SYSTEM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["712","0x2C8","error 712","ERROR_CHECKING_FILE_SYSTEM","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","checking","file","system"],"errorCode":"712","eventId":"","severity":"Low","summary":"Checking file system on %wZ.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 712; use the surrounding log entries to confirm it.","resolution":"1. Record where 712 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CHECKING_FILE_SYSTEM.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 712 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Checking file system on %wZ.\n\nLookup forms: 712, 0x2C8, error 712, ERROR_CHECKING_FILE_SYSTEM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["712"]},{"id":417,"title":"ERROR_FATAL_APP_EXIT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["713","0x2C9","error 713","ERROR_FATAL_APP_EXIT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","fatal","app","exit","application"],"errorCode":"713","eventId":"","severity":"Low","summary":"{Fatal Application Exit} %hs.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 713; use the surrounding log entries to confirm it.","resolution":"1. Record where 713 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FATAL_APP_EXIT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 713 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Fatal Application Exit} %hs.\n\nLookup forms: 713, 0x2C9, error 713, ERROR_FATAL_APP_EXIT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["713"]},{"id":418,"title":"ERROR_PREDEFINED_HANDLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["714","0x2CA","error 714","ERROR_PREDEFINED_HANDLE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","predefined","handle","the","specified","registry","key","referenced"],"errorCode":"714","eventId":"","severity":"Low","summary":"The specified registry key is referenced by a predefined handle.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 714; use the surrounding log entries to confirm it.","resolution":"1. Record where 714 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PREDEFINED_HANDLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 714 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified registry key is referenced by a predefined handle.\n\nLookup forms: 714, 0x2CA, error 714, ERROR_PREDEFINED_HANDLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["714"]},{"id":419,"title":"ERROR_WAS_UNLOCKED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["715","0x2CB","error 715","ERROR_WAS_UNLOCKED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","was","unlocked","page","the","protection","locked","changed","access","and","from","memory","process"],"errorCode":"715","eventId":"","severity":"High","summary":"{Page Unlocked} The page protection of a locked page was changed to 'No Access' and the page was unlocked from memory and from the process.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 715; use the surrounding log entries to confirm it.","resolution":"1. Record where 715 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WAS_UNLOCKED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 715 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Page Unlocked} The page protection of a locked page was changed to 'No Access' and the page was unlocked from memory and from the process.\n\nLookup forms: 715, 0x2CB, error 715, ERROR_WAS_UNLOCKED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["715"]},{"id":420,"title":"ERROR_SERVICE_NOTIFICATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["716","0x2CC","error 716","ERROR_SERVICE_NOTIFICATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","service","notification"],"errorCode":"716","eventId":"","severity":"Low","summary":"%hs","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 716; use the surrounding log entries to confirm it.","resolution":"1. Record where 716 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVICE_NOTIFICATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 716 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: %hs\n\nLookup forms: 716, 0x2CC, error 716, ERROR_SERVICE_NOTIFICATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["716"]},{"id":421,"title":"ERROR_WAS_LOCKED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["717","0x2CD","error 717","ERROR_WAS_LOCKED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","was","locked","page","one","the","pages","lock","already"],"errorCode":"717","eventId":"","severity":"High","summary":"{Page Locked} One of the pages to lock was already locked.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 717; use the surrounding log entries to confirm it.","resolution":"1. Record where 717 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WAS_LOCKED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 717 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Page Locked} One of the pages to lock was already locked.\n\nLookup forms: 717, 0x2CD, error 717, ERROR_WAS_LOCKED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["717"]},{"id":422,"title":"ERROR_LOG_HARD_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["718","0x2CE","error 718","ERROR_LOG_HARD_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","log","hard","application","popup"],"errorCode":"718","eventId":"","severity":"Low","summary":"Application popup: %1 : %2","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 718; use the surrounding log entries to confirm it.","resolution":"1. Record where 718 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_HARD_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 718 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Application popup: %1 : %2\n\nLookup forms: 718, 0x2CE, error 718, ERROR_LOG_HARD_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["718"]},{"id":423,"title":"ERROR_ALREADY_WIN32","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["719","0x2CF","error 719","ERROR_ALREADY_WIN32","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","already","win32"],"errorCode":"719","eventId":"","severity":"Low","summary":"ERROR_ALREADY_WIN32","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 719; use the surrounding log entries to confirm it.","resolution":"1. Record where 719 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ALREADY_WIN32.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 719 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: ERROR_ALREADY_WIN32\n\nLookup forms: 719, 0x2CF, error 719, ERROR_ALREADY_WIN32. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["719"]},{"id":424,"title":"ERROR_IMAGE_MACHINE_TYPE_MISMATCH_EXE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["720","0x2D0","error 720","ERROR_IMAGE_MACHINE_TYPE_MISMATCH_EXE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","image","machine","type","mismatch","exe","the","file","valid","but","for","other","than","current"],"errorCode":"720","eventId":"","severity":"Low","summary":"{Machine Type Mismatch} The image file %hs is valid, but is for a machine type other than the current machine.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 720; use the surrounding log entries to confirm it.","resolution":"1. Record where 720 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IMAGE_MACHINE_TYPE_MISMATCH_EXE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 720 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Machine Type Mismatch} The image file %hs is valid, but is for a machine type other than the current machine.\n\nLookup forms: 720, 0x2D0, error 720, ERROR_IMAGE_MACHINE_TYPE_MISMATCH_EXE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["720"]},{"id":425,"title":"ERROR_NO_YIELD_PERFORMED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["721","0x2D1","error 721","ERROR_NO_YIELD_PERFORMED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","yield","performed","execution","was","and","thread","available","run"],"errorCode":"721","eventId":"","severity":"Low","summary":"A yield execution was performed and no thread was available to run.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 721; use the surrounding log entries to confirm it.","resolution":"1. Record where 721 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_YIELD_PERFORMED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 721 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A yield execution was performed and no thread was available to run.\n\nLookup forms: 721, 0x2D1, error 721, ERROR_NO_YIELD_PERFORMED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["721"]},{"id":426,"title":"ERROR_TIMER_RESUME_IGNORED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["722","0x2D2","error 722","ERROR_TIMER_RESUME_IGNORED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","timer","resume","ignored","the","resumable","flag","api","was"],"errorCode":"722","eventId":"","severity":"Low","summary":"The resumable flag to a timer API was ignored.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 722; use the surrounding log entries to confirm it.","resolution":"1. Record where 722 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TIMER_RESUME_IGNORED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 722 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The resumable flag to a timer API was ignored.\n\nLookup forms: 722, 0x2D2, error 722, ERROR_TIMER_RESUME_IGNORED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["722"]},{"id":427,"title":"ERROR_ARBITRATION_UNHANDLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["723","0x2D3","error 723","ERROR_ARBITRATION_UNHANDLED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","arbitration","unhandled","the","arbiter","has","deferred","these","resources","its","parent"],"errorCode":"723","eventId":"","severity":"Low","summary":"The arbiter has deferred arbitration of these resources to its parent.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 723; use the surrounding log entries to confirm it.","resolution":"1. Record where 723 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ARBITRATION_UNHANDLED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 723 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The arbiter has deferred arbitration of these resources to its parent.\n\nLookup forms: 723, 0x2D3, error 723, ERROR_ARBITRATION_UNHANDLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["723"]},{"id":428,"title":"ERROR_CARDBUS_NOT_SUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["724","0x2D4","error 724","ERROR_CARDBUS_NOT_SUPPORTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cardbus","not","supported","the","inserted","device","cannot","started","because","configuration"],"errorCode":"724","eventId":"","severity":"Medium","summary":"The inserted CardBus device cannot be started because of a configuration error on \"%hs\".","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 724; use the surrounding log entries to confirm it.","resolution":"1. Record where 724 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CARDBUS_NOT_SUPPORTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 724 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The inserted CardBus device cannot be started because of a configuration error on \"%hs\".\n\nLookup forms: 724, 0x2D4, error 724, ERROR_CARDBUS_NOT_SUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["724"]},{"id":429,"title":"ERROR_MP_PROCESSOR_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["725","0x2D5","error 725","ERROR_MP_PROCESSOR_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","processor","mismatch","the","cpus","this","multiprocessor","system","are","not","all","same","revision","level","use","processors","operating","restricts","itself","features","least","capable","should","problems","occur"],"errorCode":"725","eventId":"","severity":"Low","summary":"The CPUs in this multiprocessor system are not all the same revision level. To use all processors the operating system restricts itself to the features of the least capable processor in the system. Should problems occur with this system, contact the CPU manufacturer to see if this mix of processors is supported.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 725; use the surrounding log entries to confirm it.","resolution":"1. Record where 725 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MP_PROCESSOR_MISMATCH.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 725 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The CPUs in this multiprocessor system are not all the same revision level. To use all processors the operating system restricts itself to the features of the least capable processor in the system. Should problems occur with this system, contact the CPU manufacturer to see if this mix of processors is supported.\n\nLookup forms: 725, 0x2D5, error 725, ERROR_MP_PROCESSOR_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["725"]},{"id":430,"title":"ERROR_HIBERNATED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["726","0x2D6","error 726","ERROR_HIBERNATED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","hibernated","the","system","was","put","into","hibernation"],"errorCode":"726","eventId":"","severity":"Low","summary":"The system was put into hibernation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 726; use the surrounding log entries to confirm it.","resolution":"1. Record where 726 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_HIBERNATED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 726 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system was put into hibernation.\n\nLookup forms: 726, 0x2D6, error 726, ERROR_HIBERNATED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["726"]},{"id":431,"title":"ERROR_RESUME_HIBERNATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["727","0x2D7","error 727","ERROR_RESUME_HIBERNATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","resume","hibernation","the","system","was","resumed","from"],"errorCode":"727","eventId":"","severity":"Low","summary":"The system was resumed from hibernation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 727; use the surrounding log entries to confirm it.","resolution":"1. Record where 727 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESUME_HIBERNATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 727 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system was resumed from hibernation.\n\nLookup forms: 727, 0x2D7, error 727, ERROR_RESUME_HIBERNATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["727"]},{"id":432,"title":"ERROR_FIRMWARE_UPDATED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["728","0x2D8","error 728","ERROR_FIRMWARE_UPDATED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","firmware","updated","windows","has","detected","that","the","system","bios","was","previous","date","current"],"errorCode":"728","eventId":"","severity":"Low","summary":"Windows has detected that the system firmware (BIOS) was updated [previous firmware date = %2, current firmware date %3].","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 728; use the surrounding log entries to confirm it.","resolution":"1. Record where 728 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FIRMWARE_UPDATED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 728 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Windows has detected that the system firmware (BIOS) was updated [previous firmware date = %2, current firmware date %3].\n\nLookup forms: 728, 0x2D8, error 728, ERROR_FIRMWARE_UPDATED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["728"]},{"id":433,"title":"ERROR_DRIVERS_LEAKING_LOCKED_PAGES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["729","0x2D9","error 729","ERROR_DRIVERS_LEAKING_LOCKED_PAGES","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","drivers","leaking","locked","pages","device","driver","causing","system","degradation","the","has","automatically","enabled","tracking","code","order","try","and","catch","culprit"],"errorCode":"729","eventId":"","severity":"High","summary":"A device driver is leaking locked I/O pages causing system degradation. The system has automatically enabled tracking code in order to try and catch the culprit.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 729; use the surrounding log entries to confirm it.","resolution":"1. Record where 729 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DRIVERS_LEAKING_LOCKED_PAGES.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 729 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A device driver is leaking locked I/O pages causing system degradation. The system has automatically enabled tracking code in order to try and catch the culprit.\n\nLookup forms: 729, 0x2D9, error 729, ERROR_DRIVERS_LEAKING_LOCKED_PAGES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["729"]},{"id":434,"title":"ERROR_WAKE_SYSTEM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["730","0x2DA","error 730","ERROR_WAKE_SYSTEM","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wake","system","the","has","awoken"],"errorCode":"730","eventId":"","severity":"Low","summary":"The system has awoken.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 730; use the surrounding log entries to confirm it.","resolution":"1. Record where 730 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WAKE_SYSTEM.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 730 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system has awoken.\n\nLookup forms: 730, 0x2DA, error 730, ERROR_WAKE_SYSTEM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["730"]},{"id":435,"title":"ERROR_WAIT_1","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["731","0x2DB","error 731","ERROR_WAIT_1","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wait"],"errorCode":"731","eventId":"","severity":"Low","summary":"ERROR_WAIT_1","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 731; use the surrounding log entries to confirm it.","resolution":"1. Record where 731 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WAIT_1.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 731 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: ERROR_WAIT_1\n\nLookup forms: 731, 0x2DB, error 731, ERROR_WAIT_1. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["731"]},{"id":436,"title":"ERROR_WAIT_2","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["732","0x2DC","error 732","ERROR_WAIT_2","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wait"],"errorCode":"732","eventId":"","severity":"Low","summary":"ERROR_WAIT_2","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 732; use the surrounding log entries to confirm it.","resolution":"1. Record where 732 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WAIT_2.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 732 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: ERROR_WAIT_2\n\nLookup forms: 732, 0x2DC, error 732, ERROR_WAIT_2. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["732"]},{"id":437,"title":"ERROR_WAIT_3","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["733","0x2DD","error 733","ERROR_WAIT_3","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wait"],"errorCode":"733","eventId":"","severity":"Low","summary":"ERROR_WAIT_3","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 733; use the surrounding log entries to confirm it.","resolution":"1. Record where 733 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WAIT_3.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 733 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: ERROR_WAIT_3\n\nLookup forms: 733, 0x2DD, error 733, ERROR_WAIT_3. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["733"]},{"id":438,"title":"ERROR_WAIT_63","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["734","0x2DE","error 734","ERROR_WAIT_63","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wait"],"errorCode":"734","eventId":"","severity":"Low","summary":"ERROR_WAIT_63","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 734; use the surrounding log entries to confirm it.","resolution":"1. Record where 734 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WAIT_63.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 734 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: ERROR_WAIT_63\n\nLookup forms: 734, 0x2DE, error 734, ERROR_WAIT_63. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["734"]},{"id":439,"title":"ERROR_ABANDONED_WAIT_0","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["735","0x2DF","error 735","ERROR_ABANDONED_WAIT_0","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","abandoned","wait"],"errorCode":"735","eventId":"","severity":"Low","summary":"ERROR_ABANDONED_WAIT_0","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 735; use the surrounding log entries to confirm it.","resolution":"1. Record where 735 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ABANDONED_WAIT_0.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 735 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: ERROR_ABANDONED_WAIT_0\n\nLookup forms: 735, 0x2DF, error 735, ERROR_ABANDONED_WAIT_0. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["735"]},{"id":440,"title":"ERROR_ABANDONED_WAIT_63","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["736","0x2E0","error 736","ERROR_ABANDONED_WAIT_63","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","abandoned","wait"],"errorCode":"736","eventId":"","severity":"Low","summary":"ERROR_ABANDONED_WAIT_63","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 736; use the surrounding log entries to confirm it.","resolution":"1. Record where 736 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ABANDONED_WAIT_63.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 736 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: ERROR_ABANDONED_WAIT_63\n\nLookup forms: 736, 0x2E0, error 736, ERROR_ABANDONED_WAIT_63. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["736"]},{"id":441,"title":"ERROR_USER_APC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["737","0x2E1","error 737","ERROR_USER_APC","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","user","apc"],"errorCode":"737","eventId":"","severity":"Low","summary":"ERROR_USER_APC","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 737; use the surrounding log entries to confirm it.","resolution":"1. Record where 737 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_USER_APC.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 737 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: ERROR_USER_APC\n\nLookup forms: 737, 0x2E1, error 737, ERROR_USER_APC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["737"]},{"id":442,"title":"ERROR_KERNEL_APC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["738","0x2E2","error 738","ERROR_KERNEL_APC","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","kernel","apc"],"errorCode":"738","eventId":"","severity":"Low","summary":"ERROR_KERNEL_APC","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 738; use the surrounding log entries to confirm it.","resolution":"1. Record where 738 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_KERNEL_APC.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 738 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: ERROR_KERNEL_APC\n\nLookup forms: 738, 0x2E2, error 738, ERROR_KERNEL_APC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["738"]},{"id":443,"title":"ERROR_ALERTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["739","0x2E3","error 739","ERROR_ALERTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","alerted"],"errorCode":"739","eventId":"","severity":"Low","summary":"ERROR_ALERTED","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 739; use the surrounding log entries to confirm it.","resolution":"1. Record where 739 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ALERTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 739 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: ERROR_ALERTED\n\nLookup forms: 739, 0x2E3, error 739, ERROR_ALERTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["739"]},{"id":444,"title":"ERROR_ELEVATION_REQUIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["740","0x2E4","error 740","ERROR_ELEVATION_REQUIRED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","elevation","required","the","requested","operation","requires"],"errorCode":"740","eventId":"","severity":"Low","summary":"The requested operation requires elevation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 740; use the surrounding log entries to confirm it.","resolution":"1. Record where 740 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ELEVATION_REQUIRED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 740 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested operation requires elevation.\n\nLookup forms: 740, 0x2E4, error 740, ERROR_ELEVATION_REQUIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["740"]},{"id":445,"title":"ERROR_REPARSE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["741","0x2E5","error 741","ERROR_REPARSE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","reparse","should","performed","the","object","manager","since","name","file","resulted","symbolic","link"],"errorCode":"741","eventId":"","severity":"Low","summary":"A reparse should be performed by the Object Manager since the name of the file resulted in a symbolic link.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 741; use the surrounding log entries to confirm it.","resolution":"1. Record where 741 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REPARSE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 741 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A reparse should be performed by the Object Manager since the name of the file resulted in a symbolic link.\n\nLookup forms: 741, 0x2E5, error 741, ERROR_REPARSE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["741"]},{"id":446,"title":"ERROR_OPLOCK_BREAK_IN_PROGRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["742","0x2E6","error 742","ERROR_OPLOCK_BREAK_IN_PROGRESS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","oplock","break","progress","open","create","operation","completed","while","underway"],"errorCode":"742","eventId":"","severity":"Low","summary":"An open/create operation completed while an oplock break is underway.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 742; use the surrounding log entries to confirm it.","resolution":"1. Record where 742 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_OPLOCK_BREAK_IN_PROGRESS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 742 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An open/create operation completed while an oplock break is underway.\n\nLookup forms: 742, 0x2E6, error 742, ERROR_OPLOCK_BREAK_IN_PROGRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["742"]},{"id":447,"title":"ERROR_VOLUME_MOUNTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["743","0x2E7","error 743","ERROR_VOLUME_MOUNTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","volume","mounted","new","has","been","file","system"],"errorCode":"743","eventId":"","severity":"Low","summary":"A new volume has been mounted by a file system.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 743; use the surrounding log entries to confirm it.","resolution":"1. Record where 743 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_VOLUME_MOUNTED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 743 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A new volume has been mounted by a file system.\n\nLookup forms: 743, 0x2E7, error 743, ERROR_VOLUME_MOUNTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["743"]},{"id":448,"title":"ERROR_RXACT_COMMITTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["744","0x2E8","error 744","ERROR_RXACT_COMMITTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","rxact","committed","this","success","level","status","indicates","that","the","transaction","state","already","exists","for","registry","sub","tree","but","commit","was","previously","aborted","has","now"],"errorCode":"744","eventId":"","severity":"Medium","summary":"This success level status indicates that the transaction state already exists for the registry sub-tree, but that a transaction commit was previously aborted. The commit has now been completed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 744; use the surrounding log entries to confirm it.","resolution":"1. Record where 744 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RXACT_COMMITTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 744 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This success level status indicates that the transaction state already exists for the registry sub-tree, but that a transaction commit was previously aborted. The commit has now been completed.\n\nLookup forms: 744, 0x2E8, error 744, ERROR_RXACT_COMMITTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["744"]},{"id":449,"title":"ERROR_NOTIFY_CLEANUP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["745","0x2E9","error 745","ERROR_NOTIFY_CLEANUP","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","notify","cleanup","this","indicates","that","change","request","has","been","completed","due","closing","the","handle","which","made"],"errorCode":"745","eventId":"","severity":"Low","summary":"This indicates that a notify change request has been completed due to closing the handle which made the notify change request.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 745; use the surrounding log entries to confirm it.","resolution":"1. Record where 745 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOTIFY_CLEANUP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 745 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This indicates that a notify change request has been completed due to closing the handle which made the notify change request.\n\nLookup forms: 745, 0x2E9, error 745, ERROR_NOTIFY_CLEANUP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["745"]},{"id":450,"title":"ERROR_PRIMARY_TRANSPORT_CONNECT_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["746","0x2EA","error 746","ERROR_PRIMARY_TRANSPORT_CONNECT_FAILED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","primary","transport","connect","failed","failure","attempt","was","made","the","remote","server","but","connection","computer","able","secondary"],"errorCode":"746","eventId":"","severity":"High","summary":"{Connect Failure on Primary Transport} An attempt was made to connect to the remote server %hs on the primary transport, but the connection failed. The computer WAS able to connect on a secondary transport.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 746; use the surrounding log entries to confirm it.","resolution":"1. Record where 746 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PRIMARY_TRANSPORT_CONNECT_FAILED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 746 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Connect Failure on Primary Transport} An attempt was made to connect to the remote server %hs on the primary transport, but the connection failed. The computer WAS able to connect on a secondary transport.\n\nLookup forms: 746, 0x2EA, error 746, ERROR_PRIMARY_TRANSPORT_CONNECT_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["746"]},{"id":451,"title":"ERROR_PAGE_FAULT_TRANSITION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["747","0x2EB","error 747","ERROR_PAGE_FAULT_TRANSITION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","page","fault","transition","was"],"errorCode":"747","eventId":"","severity":"Low","summary":"Page fault was a transition fault.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 747; use the surrounding log entries to confirm it.","resolution":"1. Record where 747 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PAGE_FAULT_TRANSITION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 747 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Page fault was a transition fault.\n\nLookup forms: 747, 0x2EB, error 747, ERROR_PAGE_FAULT_TRANSITION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["747"]},{"id":452,"title":"ERROR_PAGE_FAULT_DEMAND_ZERO","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["748","0x2EC","error 748","ERROR_PAGE_FAULT_DEMAND_ZERO","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","page","fault","demand","zero","was"],"errorCode":"748","eventId":"","severity":"Low","summary":"Page fault was a demand zero fault.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 748; use the surrounding log entries to confirm it.","resolution":"1. Record where 748 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PAGE_FAULT_DEMAND_ZERO.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 748 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Page fault was a demand zero fault.\n\nLookup forms: 748, 0x2EC, error 748, ERROR_PAGE_FAULT_DEMAND_ZERO. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["748"]},{"id":453,"title":"ERROR_PAGE_FAULT_COPY_ON_WRITE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["749","0x2ED","error 749","ERROR_PAGE_FAULT_COPY_ON_WRITE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","page","fault","copy","write","was","demand","zero"],"errorCode":"749","eventId":"","severity":"Low","summary":"Page fault was a demand zero fault.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 749; use the surrounding log entries to confirm it.","resolution":"1. Record where 749 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PAGE_FAULT_COPY_ON_WRITE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 749 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Page fault was a demand zero fault.\n\nLookup forms: 749, 0x2ED, error 749, ERROR_PAGE_FAULT_COPY_ON_WRITE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["749"]},{"id":454,"title":"ERROR_PAGE_FAULT_GUARD_PAGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["750","0x2EE","error 750","ERROR_PAGE_FAULT_GUARD_PAGE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","page","fault","guard","was","demand","zero"],"errorCode":"750","eventId":"","severity":"Low","summary":"Page fault was a demand zero fault.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 750; use the surrounding log entries to confirm it.","resolution":"1. Record where 750 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PAGE_FAULT_GUARD_PAGE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 750 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Page fault was a demand zero fault.\n\nLookup forms: 750, 0x2EE, error 750, ERROR_PAGE_FAULT_GUARD_PAGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["750"]},{"id":455,"title":"ERROR_PAGE_FAULT_PAGING_FILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["751","0x2EF","error 751","ERROR_PAGE_FAULT_PAGING_FILE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","page","fault","paging","file","was","satisfied","reading","from","secondary","storage","device"],"errorCode":"751","eventId":"","severity":"Low","summary":"Page fault was satisfied by reading from a secondary storage device.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 751; use the surrounding log entries to confirm it.","resolution":"1. Record where 751 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PAGE_FAULT_PAGING_FILE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 751 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Page fault was satisfied by reading from a secondary storage device.\n\nLookup forms: 751, 0x2EF, error 751, ERROR_PAGE_FAULT_PAGING_FILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["751"]},{"id":456,"title":"ERROR_CACHE_PAGE_LOCKED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["752","0x2F0","error 752","ERROR_CACHE_PAGE_LOCKED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cache","page","locked","cached","was","during","operation"],"errorCode":"752","eventId":"","severity":"High","summary":"Cached page was locked during operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 752; use the surrounding log entries to confirm it.","resolution":"1. Record where 752 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CACHE_PAGE_LOCKED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 752 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cached page was locked during operation.\n\nLookup forms: 752, 0x2F0, error 752, ERROR_CACHE_PAGE_LOCKED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["752"]},{"id":457,"title":"ERROR_CRASH_DUMP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["753","0x2F1","error 753","ERROR_CRASH_DUMP","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","crash","dump","exists","paging","file"],"errorCode":"753","eventId":"","severity":"Low","summary":"Crash dump exists in paging file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 753; use the surrounding log entries to confirm it.","resolution":"1. Record where 753 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CRASH_DUMP.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 753 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Crash dump exists in paging file.\n\nLookup forms: 753, 0x2F1, error 753, ERROR_CRASH_DUMP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["753"]},{"id":458,"title":"ERROR_BUFFER_ALL_ZEROS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["754","0x2F2","error 754","ERROR_BUFFER_ALL_ZEROS","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","buffer","all","zeros","specified","contains"],"errorCode":"754","eventId":"","severity":"Low","summary":"Specified buffer contains all zeros.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 754; use the surrounding log entries to confirm it.","resolution":"1. Record where 754 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BUFFER_ALL_ZEROS.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 754 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Specified buffer contains all zeros.\n\nLookup forms: 754, 0x2F2, error 754, ERROR_BUFFER_ALL_ZEROS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["754"]},{"id":459,"title":"ERROR_REPARSE_OBJECT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["755","0x2F3","error 755","ERROR_REPARSE_OBJECT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","reparse","object","should","performed","the","manager","since","name","file","resulted","symbolic","link"],"errorCode":"755","eventId":"","severity":"Low","summary":"A reparse should be performed by the Object Manager since the name of the file resulted in a symbolic link.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 755; use the surrounding log entries to confirm it.","resolution":"1. Record where 755 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REPARSE_OBJECT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 755 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A reparse should be performed by the Object Manager since the name of the file resulted in a symbolic link.\n\nLookup forms: 755, 0x2F3, error 755, ERROR_REPARSE_OBJECT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["755"]},{"id":460,"title":"ERROR_RESOURCE_REQUIREMENTS_CHANGED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["756","0x2F4","error 756","ERROR_RESOURCE_REQUIREMENTS_CHANGED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","resource","requirements","changed","the","device","has","succeeded","query","stop","and","its","have"],"errorCode":"756","eventId":"","severity":"Low","summary":"The device has succeeded a query-stop and its resource requirements have changed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 756; use the surrounding log entries to confirm it.","resolution":"1. Record where 756 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESOURCE_REQUIREMENTS_CHANGED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 756 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The device has succeeded a query-stop and its resource requirements have changed.\n\nLookup forms: 756, 0x2F4, error 756, ERROR_RESOURCE_REQUIREMENTS_CHANGED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["756"]},{"id":461,"title":"ERROR_TRANSLATION_COMPLETE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["757","0x2F5","error 757","ERROR_TRANSLATION_COMPLETE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","translation","complete","the","translator","has","translated","these","resources","into","global","space","and","further","translations","should","performed"],"errorCode":"757","eventId":"","severity":"Low","summary":"The translator has translated these resources into the global space and no further translations should be performed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 757; use the surrounding log entries to confirm it.","resolution":"1. Record where 757 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSLATION_COMPLETE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 757 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The translator has translated these resources into the global space and no further translations should be performed.\n\nLookup forms: 757, 0x2F5, error 757, ERROR_TRANSLATION_COMPLETE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["757"]},{"id":462,"title":"ERROR_NOTHING_TO_TERMINATE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["758","0x2F6","error 758","ERROR_NOTHING_TO_TERMINATE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","nothing","terminate","process","being","terminated","has","threads"],"errorCode":"758","eventId":"","severity":"Low","summary":"A process being terminated has no threads to terminate.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 758; use the surrounding log entries to confirm it.","resolution":"1. Record where 758 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOTHING_TO_TERMINATE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 758 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A process being terminated has no threads to terminate.\n\nLookup forms: 758, 0x2F6, error 758, ERROR_NOTHING_TO_TERMINATE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["758"]},{"id":463,"title":"ERROR_PROCESS_NOT_IN_JOB","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["759","0x2F7","error 759","ERROR_PROCESS_NOT_IN_JOB","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","process","not","job","the","specified","part"],"errorCode":"759","eventId":"","severity":"Low","summary":"The specified process is not part of a job.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 759; use the surrounding log entries to confirm it.","resolution":"1. Record where 759 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PROCESS_NOT_IN_JOB.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 759 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified process is not part of a job.\n\nLookup forms: 759, 0x2F7, error 759, ERROR_PROCESS_NOT_IN_JOB. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["759"]},{"id":464,"title":"ERROR_PROCESS_IN_JOB","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["760","0x2F8","error 760","ERROR_PROCESS_IN_JOB","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","process","job","the","specified","part"],"errorCode":"760","eventId":"","severity":"Low","summary":"The specified process is part of a job.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 760; use the surrounding log entries to confirm it.","resolution":"1. Record where 760 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PROCESS_IN_JOB.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 760 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified process is part of a job.\n\nLookup forms: 760, 0x2F8, error 760, ERROR_PROCESS_IN_JOB. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["760"]},{"id":465,"title":"ERROR_VOLSNAP_HIBERNATE_READY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["761","0x2F9","error 761","ERROR_VOLSNAP_HIBERNATE_READY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","volsnap","hibernate","ready","volume","shadow","copy","service","the","system","now","for","hibernation"],"errorCode":"761","eventId":"","severity":"Low","summary":"{Volume Shadow Copy Service} The system is now ready for hibernation.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 761; use the surrounding log entries to confirm it.","resolution":"1. Record where 761 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_VOLSNAP_HIBERNATE_READY.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 761 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Volume Shadow Copy Service} The system is now ready for hibernation.\n\nLookup forms: 761, 0x2F9, error 761, ERROR_VOLSNAP_HIBERNATE_READY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["761"]},{"id":466,"title":"ERROR_FSFILTER_OP_COMPLETED_SUCCESSFULLY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["762","0x2FA","error 762","ERROR_FSFILTER_OP_COMPLETED_SUCCESSFULLY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","fsfilter","completed","successfully","file","system","filter","driver","has","operation"],"errorCode":"762","eventId":"","severity":"Low","summary":"A file system or file system filter driver has successfully completed an FsFilter operation.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 762; use the surrounding log entries to confirm it.","resolution":"1. Record where 762 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FSFILTER_OP_COMPLETED_SUCCESSFULLY.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 762 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A file system or file system filter driver has successfully completed an FsFilter operation.\n\nLookup forms: 762, 0x2FA, error 762, ERROR_FSFILTER_OP_COMPLETED_SUCCESSFULLY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["762"]},{"id":467,"title":"ERROR_INTERRUPT_VECTOR_ALREADY_CONNECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["763","0x2FB","error 763","ERROR_INTERRUPT_VECTOR_ALREADY_CONNECTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","interrupt","vector","already","connected","the","specified","was"],"errorCode":"763","eventId":"","severity":"Low","summary":"The specified interrupt vector was already connected.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 763; use the surrounding log entries to confirm it.","resolution":"1. Record where 763 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INTERRUPT_VECTOR_ALREADY_CONNECTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 763 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified interrupt vector was already connected.\n\nLookup forms: 763, 0x2FB, error 763, ERROR_INTERRUPT_VECTOR_ALREADY_CONNECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["763"]},{"id":468,"title":"ERROR_INTERRUPT_STILL_CONNECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["764","0x2FC","error 764","ERROR_INTERRUPT_STILL_CONNECTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","interrupt","still","connected","the","specified","vector"],"errorCode":"764","eventId":"","severity":"Low","summary":"The specified interrupt vector is still connected.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 764; use the surrounding log entries to confirm it.","resolution":"1. Record where 764 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INTERRUPT_STILL_CONNECTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 764 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified interrupt vector is still connected.\n\nLookup forms: 764, 0x2FC, error 764, ERROR_INTERRUPT_STILL_CONNECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["764"]},{"id":469,"title":"ERROR_WAIT_FOR_OPLOCK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["765","0x2FD","error 765","ERROR_WAIT_FOR_OPLOCK","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wait","for","oplock","operation","blocked","waiting"],"errorCode":"765","eventId":"","severity":"High","summary":"An operation is blocked waiting for an oplock.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 765; use the surrounding log entries to confirm it.","resolution":"1. Record where 765 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WAIT_FOR_OPLOCK.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 765 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An operation is blocked waiting for an oplock.\n\nLookup forms: 765, 0x2FD, error 765, ERROR_WAIT_FOR_OPLOCK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["765"]},{"id":470,"title":"ERROR_DBG_EXCEPTION_HANDLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["766","0x2FE","error 766","ERROR_DBG_EXCEPTION_HANDLED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","dbg","exception","handled","debugger"],"errorCode":"766","eventId":"","severity":"Low","summary":"Debugger handled exception.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 766; use the surrounding log entries to confirm it.","resolution":"1. Record where 766 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DBG_EXCEPTION_HANDLED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 766 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Debugger handled exception.\n\nLookup forms: 766, 0x2FE, error 766, ERROR_DBG_EXCEPTION_HANDLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["766"]},{"id":471,"title":"ERROR_DBG_CONTINUE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["767","0x2FF","error 767","ERROR_DBG_CONTINUE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dbg","continue","debugger","continued"],"errorCode":"767","eventId":"","severity":"Low","summary":"Debugger continued.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 767; use the surrounding log entries to confirm it.","resolution":"1. Record where 767 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DBG_CONTINUE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 767 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Debugger continued.\n\nLookup forms: 767, 0x2FF, error 767, ERROR_DBG_CONTINUE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["767"]},{"id":472,"title":"ERROR_CALLBACK_POP_STACK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["768","0x300","error 768","ERROR_CALLBACK_POP_STACK","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","callback","pop","stack","exception","occurred","user","mode","and","the","kernel","frame","should","removed"],"errorCode":"768","eventId":"","severity":"Low","summary":"An exception occurred in a user mode callback and the kernel callback frame should be removed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 768; use the surrounding log entries to confirm it.","resolution":"1. Record where 768 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CALLBACK_POP_STACK.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 768 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An exception occurred in a user mode callback and the kernel callback frame should be removed.\n\nLookup forms: 768, 0x300, error 768, ERROR_CALLBACK_POP_STACK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["768"]},{"id":473,"title":"ERROR_COMPRESSION_DISABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["769","0x301","error 769","ERROR_COMPRESSION_DISABLED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","compression","disabled","for","this","volume"],"errorCode":"769","eventId":"","severity":"Low","summary":"Compression is disabled for this volume.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 769; use the surrounding log entries to confirm it.","resolution":"1. Record where 769 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_COMPRESSION_DISABLED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 769 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Compression is disabled for this volume.\n\nLookup forms: 769, 0x301, error 769, ERROR_COMPRESSION_DISABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["769"]},{"id":474,"title":"ERROR_CANTFETCHBACKWARDS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["770","0x302","error 770","ERROR_CANTFETCHBACKWARDS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cantfetchbackwards","the","data","provider","cannot","fetch","backwards","through","result","set"],"errorCode":"770","eventId":"","severity":"Medium","summary":"The data provider cannot fetch backwards through a result set.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 770; use the surrounding log entries to confirm it.","resolution":"1. Record where 770 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANTFETCHBACKWARDS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 770 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The data provider cannot fetch backwards through a result set.\n\nLookup forms: 770, 0x302, error 770, ERROR_CANTFETCHBACKWARDS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["770"]},{"id":475,"title":"ERROR_CANTSCROLLBACKWARDS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["771","0x303","error 771","ERROR_CANTSCROLLBACKWARDS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cantscrollbackwards","the","data","provider","cannot","scroll","backwards","through","result","set"],"errorCode":"771","eventId":"","severity":"Medium","summary":"The data provider cannot scroll backwards through a result set.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 771; use the surrounding log entries to confirm it.","resolution":"1. Record where 771 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANTSCROLLBACKWARDS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 771 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The data provider cannot scroll backwards through a result set.\n\nLookup forms: 771, 0x303, error 771, ERROR_CANTSCROLLBACKWARDS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["771"]},{"id":476,"title":"ERROR_ROWSNOTRELEASED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["772","0x304","error 772","ERROR_ROWSNOTRELEASED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","rowsnotreleased","the","data","provider","requires","that","previously","fetched","released","before","asking","for","more"],"errorCode":"772","eventId":"","severity":"Low","summary":"The data provider requires that previously fetched data is released before asking for more data.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 772; use the surrounding log entries to confirm it.","resolution":"1. Record where 772 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ROWSNOTRELEASED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 772 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The data provider requires that previously fetched data is released before asking for more data.\n\nLookup forms: 772, 0x304, error 772, ERROR_ROWSNOTRELEASED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["772"]},{"id":477,"title":"ERROR_BAD_ACCESSOR_FLAGS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["773","0x305","error 773","ERROR_BAD_ACCESSOR_FLAGS","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","bad","accessor","flags","the","data","provider","was","not","able","interpret","set","for","column","binding"],"errorCode":"773","eventId":"","severity":"Low","summary":"The data provider was not able to interpret the flags set for a column binding in an accessor.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 773; use the surrounding log entries to confirm it.","resolution":"1. Record where 773 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_ACCESSOR_FLAGS.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 773 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The data provider was not able to interpret the flags set for a column binding in an accessor.\n\nLookup forms: 773, 0x305, error 773, ERROR_BAD_ACCESSOR_FLAGS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["773"]},{"id":478,"title":"ERROR_ERRORS_ENCOUNTERED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["774","0x306","error 774","ERROR_ERRORS_ENCOUNTERED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","errors","encountered","one","more","occurred","while","processing","the","request"],"errorCode":"774","eventId":"","severity":"Low","summary":"One or more errors occurred while processing the request.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 774; use the surrounding log entries to confirm it.","resolution":"1. Record where 774 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ERRORS_ENCOUNTERED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 774 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: One or more errors occurred while processing the request.\n\nLookup forms: 774, 0x306, error 774, ERROR_ERRORS_ENCOUNTERED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["774"]},{"id":479,"title":"ERROR_NOT_CAPABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["775","0x307","error 775","ERROR_NOT_CAPABLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","not","capable","the","implementation","performing","request"],"errorCode":"775","eventId":"","severity":"Low","summary":"The implementation is not capable of performing the request.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 775; use the surrounding log entries to confirm it.","resolution":"1. Record where 775 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_CAPABLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 775 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The implementation is not capable of performing the request.\n\nLookup forms: 775, 0x307, error 775, ERROR_NOT_CAPABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["775"]},{"id":480,"title":"ERROR_REQUEST_OUT_OF_SEQUENCE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["776","0x308","error 776","ERROR_REQUEST_OUT_OF_SEQUENCE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","request","out","sequence","the","client","component","requested","operation","which","not","valid","given","state","instance"],"errorCode":"776","eventId":"","severity":"Low","summary":"The client of a component requested an operation which is not valid given the state of the component instance.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 776; use the surrounding log entries to confirm it.","resolution":"1. Record where 776 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REQUEST_OUT_OF_SEQUENCE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 776 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The client of a component requested an operation which is not valid given the state of the component instance.\n\nLookup forms: 776, 0x308, error 776, ERROR_REQUEST_OUT_OF_SEQUENCE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["776"]},{"id":481,"title":"ERROR_VERSION_PARSE_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["777","0x309","error 777","ERROR_VERSION_PARSE_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","version","parse","number","could","not","parsed"],"errorCode":"777","eventId":"","severity":"Low","summary":"A version number could not be parsed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 777; use the surrounding log entries to confirm it.","resolution":"1. Record where 777 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_VERSION_PARSE_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 777 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A version number could not be parsed.\n\nLookup forms: 777, 0x309, error 777, ERROR_VERSION_PARSE_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["777"]},{"id":482,"title":"ERROR_BADSTARTPOSITION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["778","0x30A","error 778","ERROR_BADSTARTPOSITION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","badstartposition","the","iterator","start","position","invalid"],"errorCode":"778","eventId":"","severity":"Medium","summary":"The iterator's start position is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 778; use the surrounding log entries to confirm it.","resolution":"1. Record where 778 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BADSTARTPOSITION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 778 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The iterator's start position is invalid.\n\nLookup forms: 778, 0x30A, error 778, ERROR_BADSTARTPOSITION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["778"]},{"id":483,"title":"ERROR_MEMORY_HARDWARE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["779","0x30B","error 779","ERROR_MEMORY_HARDWARE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","memory","hardware","the","has","reported","uncorrectable"],"errorCode":"779","eventId":"","severity":"Low","summary":"The hardware has reported an uncorrectable memory error.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 779; use the surrounding log entries to confirm it.","resolution":"1. Record where 779 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MEMORY_HARDWARE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 779 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The hardware has reported an uncorrectable memory error.\n\nLookup forms: 779, 0x30B, error 779, ERROR_MEMORY_HARDWARE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["779"]},{"id":484,"title":"ERROR_DISK_REPAIR_DISABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["780","0x30C","error 780","ERROR_DISK_REPAIR_DISABLED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","disk","repair","disabled","the","attempted","operation","required","self","healing","enabled"],"errorCode":"780","eventId":"","severity":"Low","summary":"The attempted operation required self healing to be enabled.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 780; use the surrounding log entries to confirm it.","resolution":"1. Record where 780 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DISK_REPAIR_DISABLED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 780 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The attempted operation required self healing to be enabled.\n\nLookup forms: 780, 0x30C, error 780, ERROR_DISK_REPAIR_DISABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["780"]},{"id":485,"title":"ERROR_INSUFFICIENT_RESOURCE_FOR_SPECIFIED_SHARED_SECTION_SIZE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["781","0x30D","error 781","ERROR_INSUFFICIENT_RESOURCE_FOR_SPECIFIED_SHARED_SECTION_SIZE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","insufficient","resource","for","specified","shared","section","size","the","desktop","heap","encountered","while","allocating","session","memory","there","more","information","system","event","log"],"errorCode":"781","eventId":"","severity":"Low","summary":"The Desktop heap encountered an error while allocating session memory. There is more information in the system event log.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 781; use the surrounding log entries to confirm it.","resolution":"1. Record where 781 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSUFFICIENT_RESOURCE_FOR_SPECIFIED_SHARED_SECTION_SIZE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 781 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Desktop heap encountered an error while allocating session memory. There is more information in the system event log.\n\nLookup forms: 781, 0x30D, error 781, ERROR_INSUFFICIENT_RESOURCE_FOR_SPECIFIED_SHARED_SECTION_SIZE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["781"]},{"id":486,"title":"ERROR_SYSTEM_POWERSTATE_TRANSITION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["782","0x30E","error 782","ERROR_SYSTEM_POWERSTATE_TRANSITION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","system","powerstate","transition","the","power","state","transitioning","from"],"errorCode":"782","eventId":"","severity":"Low","summary":"The system power state is transitioning from %2 to %3.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 782; use the surrounding log entries to confirm it.","resolution":"1. Record where 782 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SYSTEM_POWERSTATE_TRANSITION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 782 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system power state is transitioning from %2 to %3.\n\nLookup forms: 782, 0x30E, error 782, ERROR_SYSTEM_POWERSTATE_TRANSITION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["782"]},{"id":487,"title":"ERROR_SYSTEM_POWERSTATE_COMPLEX_TRANSITION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["783","0x30F","error 783","ERROR_SYSTEM_POWERSTATE_COMPLEX_TRANSITION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","system","powerstate","complex","transition","the","power","state","transitioning","from","but","could","enter"],"errorCode":"783","eventId":"","severity":"Low","summary":"The system power state is transitioning from %2 to %3 but could enter %4.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 783; use the surrounding log entries to confirm it.","resolution":"1. Record where 783 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SYSTEM_POWERSTATE_COMPLEX_TRANSITION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 783 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system power state is transitioning from %2 to %3 but could enter %4.\n\nLookup forms: 783, 0x30F, error 783, ERROR_SYSTEM_POWERSTATE_COMPLEX_TRANSITION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["783"]},{"id":488,"title":"ERROR_MCA_EXCEPTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["784","0x310","error 784","ERROR_MCA_EXCEPTION","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","mca","exception","thread","getting","dispatched","with","because"],"errorCode":"784","eventId":"","severity":"Low","summary":"A thread is getting dispatched with MCA EXCEPTION because of MCA.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 784; use the surrounding log entries to confirm it.","resolution":"1. Record where 784 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MCA_EXCEPTION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 784 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A thread is getting dispatched with MCA EXCEPTION because of MCA.\n\nLookup forms: 784, 0x310, error 784, ERROR_MCA_EXCEPTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["784"]},{"id":489,"title":"ERROR_ACCESS_AUDIT_BY_POLICY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["785","0x311","error 785","ERROR_ACCESS_AUDIT_BY_POLICY","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","access","audit","policy","monitored","rule"],"errorCode":"785","eventId":"","severity":"Low","summary":"Access to %1 is monitored by policy rule %2.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 785; use the surrounding log entries to confirm it.","resolution":"1. Record where 785 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ACCESS_AUDIT_BY_POLICY.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 785 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Access to %1 is monitored by policy rule %2.\n\nLookup forms: 785, 0x311, error 785, ERROR_ACCESS_AUDIT_BY_POLICY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["785"]},{"id":490,"title":"ERROR_ACCESS_DISABLED_NO_SAFER_UI_BY_POLICY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["786","0x312","error 786","ERROR_ACCESS_DISABLED_NO_SAFER_UI_BY_POLICY","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","access","disabled","safer","policy","has","been","restricted","your","administrator","rule"],"errorCode":"786","eventId":"","severity":"Low","summary":"Access to %1 has been restricted by your Administrator by policy rule %2.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 786; use the surrounding log entries to confirm it.","resolution":"1. Record where 786 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ACCESS_DISABLED_NO_SAFER_UI_BY_POLICY.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 786 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Access to %1 has been restricted by your Administrator by policy rule %2.\n\nLookup forms: 786, 0x312, error 786, ERROR_ACCESS_DISABLED_NO_SAFER_UI_BY_POLICY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["786"]},{"id":491,"title":"ERROR_ABANDON_HIBERFILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["787","0x313","error 787","ERROR_ABANDON_HIBERFILE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","abandon","hiberfile","valid","hibernation","file","has","been","invalidated","and","should","abandoned"],"errorCode":"787","eventId":"","severity":"Medium","summary":"A valid hibernation file has been invalidated and should be abandoned.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 787; use the surrounding log entries to confirm it.","resolution":"1. Record where 787 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ABANDON_HIBERFILE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 787 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A valid hibernation file has been invalidated and should be abandoned.\n\nLookup forms: 787, 0x313, error 787, ERROR_ABANDON_HIBERFILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["787"]},{"id":492,"title":"ERROR_LOST_WRITEBEHIND_DATA_NETWORK_DISCONNECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["788","0x314","error 788","ERROR_LOST_WRITEBEHIND_DATA_NETWORK_DISCONNECTED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","lost","writebehind","data","network","disconnected","delayed","write","failed","windows","was","unable","save","all","the","for","file","has","been","this","may","caused","connectivity","issues","please"],"errorCode":"788","eventId":"","severity":"High","summary":"{Delayed Write Failed} Windows was unable to save all the data for the file %hs; the data has been lost. This error may be caused by network connectivity issues. Please try to save this file elsewhere.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 788; use the surrounding log entries to confirm it.","resolution":"1. Record where 788 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOST_WRITEBEHIND_DATA_NETWORK_DISCONNECTED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 788 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Delayed Write Failed} Windows was unable to save all the data for the file %hs; the data has been lost. This error may be caused by network connectivity issues. Please try to save this file elsewhere.\n\nLookup forms: 788, 0x314, error 788, ERROR_LOST_WRITEBEHIND_DATA_NETWORK_DISCONNECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["788"]},{"id":493,"title":"ERROR_LOST_WRITEBEHIND_DATA_NETWORK_SERVER_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["789","0x315","error 789","ERROR_LOST_WRITEBEHIND_DATA_NETWORK_SERVER_ERROR","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","lost","writebehind","data","network","server","delayed","write","failed","windows","was","unable","save","all","the","for","file","has","been","this","returned","which","exists","please","try"],"errorCode":"789","eventId":"","severity":"High","summary":"{Delayed Write Failed} Windows was unable to save all the data for the file %hs; the data has been lost. This error was returned by the server on which the file exists. Please try to save this file elsewhere.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 789; use the surrounding log entries to confirm it.","resolution":"1. Record where 789 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOST_WRITEBEHIND_DATA_NETWORK_SERVER_ERROR.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 789 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Delayed Write Failed} Windows was unable to save all the data for the file %hs; the data has been lost. This error was returned by the server on which the file exists. Please try to save this file elsewhere.\n\nLookup forms: 789, 0x315, error 789, ERROR_LOST_WRITEBEHIND_DATA_NETWORK_SERVER_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["789"]},{"id":494,"title":"ERROR_LOST_WRITEBEHIND_DATA_LOCAL_DISK_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["790","0x316","error 790","ERROR_LOST_WRITEBEHIND_DATA_LOCAL_DISK_ERROR","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","lost","writebehind","data","local","disk","delayed","write","failed","windows","was","unable","save","all","the","for","file","has","been","this","may","caused","device","removed","media"],"errorCode":"790","eventId":"","severity":"High","summary":"{Delayed Write Failed} Windows was unable to save all the data for the file %hs; the data has been lost. This error may be caused if the device has been removed or the media is write-protected.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 790; use the surrounding log entries to confirm it.","resolution":"1. Record where 790 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOST_WRITEBEHIND_DATA_LOCAL_DISK_ERROR.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 790 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: {Delayed Write Failed} Windows was unable to save all the data for the file %hs; the data has been lost. This error may be caused if the device has been removed or the media is write-protected.\n\nLookup forms: 790, 0x316, error 790, ERROR_LOST_WRITEBEHIND_DATA_LOCAL_DISK_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["790"]},{"id":495,"title":"ERROR_BAD_MCFG_TABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["791","0x317","error 791","ERROR_BAD_MCFG_TABLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","bad","mcfg","table","the","resources","required","for","this","device","conflict","with"],"errorCode":"791","eventId":"","severity":"Low","summary":"The resources required for this device conflict with the MCFG table.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 791; use the surrounding log entries to confirm it.","resolution":"1. Record where 791 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_MCFG_TABLE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 791 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The resources required for this device conflict with the MCFG table.\n\nLookup forms: 791, 0x317, error 791, ERROR_BAD_MCFG_TABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["791"]},{"id":496,"title":"ERROR_DISK_REPAIR_REDIRECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["792","0x318","error 792","ERROR_DISK_REPAIR_REDIRECTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","disk","repair","redirected","the","volume","could","not","performed","while","online","please","schedule","take","offline","that","can","repaired"],"errorCode":"792","eventId":"","severity":"Low","summary":"The volume repair could not be performed while it is online. Please schedule to take the volume offline so that it can be repaired.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 792; use the surrounding log entries to confirm it.","resolution":"1. Record where 792 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DISK_REPAIR_REDIRECTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 792 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The volume repair could not be performed while it is online. Please schedule to take the volume offline so that it can be repaired.\n\nLookup forms: 792, 0x318, error 792, ERROR_DISK_REPAIR_REDIRECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["792"]},{"id":497,"title":"ERROR_DISK_REPAIR_UNSUCCESSFUL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["793","0x319","error 793","ERROR_DISK_REPAIR_UNSUCCESSFUL","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","disk","repair","unsuccessful","the","volume","was","not","successful"],"errorCode":"793","eventId":"","severity":"Low","summary":"The volume repair was not successful.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 793; use the surrounding log entries to confirm it.","resolution":"1. Record where 793 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DISK_REPAIR_UNSUCCESSFUL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 793 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The volume repair was not successful.\n\nLookup forms: 793, 0x319, error 793, ERROR_DISK_REPAIR_UNSUCCESSFUL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["793"]},{"id":498,"title":"ERROR_CORRUPT_LOG_OVERFULL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["794","0x31A","error 794","ERROR_CORRUPT_LOG_OVERFULL","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","corrupt","log","overfull","one","the","volume","corruption","logs","full","further","corruptions","that","may","detected","won","logged"],"errorCode":"794","eventId":"","severity":"Critical","summary":"One of the volume corruption logs is full. Further corruptions that may be detected won't be logged.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 794; use the surrounding log entries to confirm it.","resolution":"1. Record where 794 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CORRUPT_LOG_OVERFULL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 794 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: One of the volume corruption logs is full. Further corruptions that may be detected won't be logged.\n\nLookup forms: 794, 0x31A, error 794, ERROR_CORRUPT_LOG_OVERFULL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["794"]},{"id":499,"title":"ERROR_CORRUPT_LOG_CORRUPTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["795","0x31B","error 795","ERROR_CORRUPT_LOG_CORRUPTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","corrupt","log","corrupted","one","the","volume","corruption","logs","internally","and","needs","recreated","may","contain","undetected","corruptions","must","scanned"],"errorCode":"795","eventId":"","severity":"Critical","summary":"One of the volume corruption logs is internally corrupted and needs to be recreated. The volume may contain undetected corruptions and must be scanned.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 795; use the surrounding log entries to confirm it.","resolution":"1. Record where 795 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CORRUPT_LOG_CORRUPTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 795 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: One of the volume corruption logs is internally corrupted and needs to be recreated. The volume may contain undetected corruptions and must be scanned.\n\nLookup forms: 795, 0x31B, error 795, ERROR_CORRUPT_LOG_CORRUPTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["795"]},{"id":500,"title":"ERROR_CORRUPT_LOG_UNAVAILABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["796","0x31C","error 796","ERROR_CORRUPT_LOG_UNAVAILABLE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","corrupt","log","unavailable","one","the","volume","corruption","logs","for","being","operated"],"errorCode":"796","eventId":"","severity":"Critical","summary":"One of the volume corruption logs is unavailable for being operated on.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 796; use the surrounding log entries to confirm it.","resolution":"1. Record where 796 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CORRUPT_LOG_UNAVAILABLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 796 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: One of the volume corruption logs is unavailable for being operated on.\n\nLookup forms: 796, 0x31C, error 796, ERROR_CORRUPT_LOG_UNAVAILABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["796"]},{"id":501,"title":"ERROR_CORRUPT_LOG_DELETED_FULL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["797","0x31D","error 797","ERROR_CORRUPT_LOG_DELETED_FULL","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","corrupt","log","deleted","full","one","the","volume","corruption","logs","was","while","still","having","records","them","contains","detected","corruptions","and","must","scanned"],"errorCode":"797","eventId":"","severity":"Critical","summary":"One of the volume corruption logs was deleted while still having corruption records in them. The volume contains detected corruptions and must be scanned.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 797; use the surrounding log entries to confirm it.","resolution":"1. Record where 797 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CORRUPT_LOG_DELETED_FULL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 797 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: One of the volume corruption logs was deleted while still having corruption records in them. The volume contains detected corruptions and must be scanned.\n\nLookup forms: 797, 0x31D, error 797, ERROR_CORRUPT_LOG_DELETED_FULL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["797"]},{"id":502,"title":"ERROR_CORRUPT_LOG_CLEARED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["798","0x31E","error 798","ERROR_CORRUPT_LOG_CLEARED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","corrupt","log","cleared","one","the","volume","corruption","logs","was","chkdsk","and","longer","contains","real","corruptions"],"errorCode":"798","eventId":"","severity":"Critical","summary":"One of the volume corruption logs was cleared by chkdsk and no longer contains real corruptions.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 798; use the surrounding log entries to confirm it.","resolution":"1. Record where 798 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CORRUPT_LOG_CLEARED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 798 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: One of the volume corruption logs was cleared by chkdsk and no longer contains real corruptions.\n\nLookup forms: 798, 0x31E, error 798, ERROR_CORRUPT_LOG_CLEARED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["798"]},{"id":503,"title":"ERROR_ORPHAN_NAME_EXHAUSTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["799","0x31F","error 799","ERROR_ORPHAN_NAME_EXHAUSTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","orphan","name","exhausted","orphaned","files","exist","the","volume","but","could","not","recovered","because","more","new","names","created","recovery","directory","must","moved","from"],"errorCode":"799","eventId":"","severity":"Low","summary":"Orphaned files exist on the volume but could not be recovered because no more new names could be created in the recovery directory. Files must be moved from the recovery directory.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 799; use the surrounding log entries to confirm it.","resolution":"1. Record where 799 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ORPHAN_NAME_EXHAUSTED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 799 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Orphaned files exist on the volume but could not be recovered because no more new names could be created in the recovery directory. Files must be moved from the recovery directory.\n\nLookup forms: 799, 0x31F, error 799, ERROR_ORPHAN_NAME_EXHAUSTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["799"]},{"id":504,"title":"ERROR_OPLOCK_SWITCHED_TO_NEW_HANDLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["800","0x320","error 800","ERROR_OPLOCK_SWITCHED_TO_NEW_HANDLE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","oplock","switched","new","handle","the","that","was","associated","with","this","now","different"],"errorCode":"800","eventId":"","severity":"Low","summary":"The oplock that was associated with this handle is now associated with a different handle.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 800; use the surrounding log entries to confirm it.","resolution":"1. Record where 800 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_OPLOCK_SWITCHED_TO_NEW_HANDLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 800 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The oplock that was associated with this handle is now associated with a different handle.\n\nLookup forms: 800, 0x320, error 800, ERROR_OPLOCK_SWITCHED_TO_NEW_HANDLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["800"]},{"id":505,"title":"ERROR_CANNOT_GRANT_REQUESTED_OPLOCK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["801","0x321","error 801","ERROR_CANNOT_GRANT_REQUESTED_OPLOCK","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cannot","grant","requested","oplock","the","level","granted","lower","may","available"],"errorCode":"801","eventId":"","severity":"Medium","summary":"An oplock of the requested level cannot be granted. An oplock of a lower level may be available.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 801; use the surrounding log entries to confirm it.","resolution":"1. Record where 801 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANNOT_GRANT_REQUESTED_OPLOCK.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 801 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An oplock of the requested level cannot be granted. An oplock of a lower level may be available.\n\nLookup forms: 801, 0x321, error 801, ERROR_CANNOT_GRANT_REQUESTED_OPLOCK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["801"]},{"id":506,"title":"ERROR_CANNOT_BREAK_OPLOCK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["802","0x322","error 802","ERROR_CANNOT_BREAK_OPLOCK","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cannot","break","oplock","the","operation","did","not","complete","successfully","because","would","cause","broken","caller","has","requested","that","existing","oplocks"],"errorCode":"802","eventId":"","severity":"Low","summary":"The operation did not complete successfully because it would cause an oplock to be broken. The caller has requested that existing oplocks not be broken.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 802; use the surrounding log entries to confirm it.","resolution":"1. Record where 802 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANNOT_BREAK_OPLOCK.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 802 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation did not complete successfully because it would cause an oplock to be broken. The caller has requested that existing oplocks not be broken.\n\nLookup forms: 802, 0x322, error 802, ERROR_CANNOT_BREAK_OPLOCK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["802"]},{"id":507,"title":"ERROR_OPLOCK_HANDLE_CLOSED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["803","0x323","error 803","ERROR_OPLOCK_HANDLE_CLOSED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","oplock","handle","closed","the","with","which","this","was","associated","has","been","now","broken"],"errorCode":"803","eventId":"","severity":"Low","summary":"The handle with which this oplock was associated has been closed. The oplock is now broken.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 803; use the surrounding log entries to confirm it.","resolution":"1. Record where 803 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_OPLOCK_HANDLE_CLOSED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 803 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The handle with which this oplock was associated has been closed. The oplock is now broken.\n\nLookup forms: 803, 0x323, error 803, ERROR_OPLOCK_HANDLE_CLOSED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["803"]},{"id":508,"title":"ERROR_NO_ACE_CONDITION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["804","0x324","error 804","ERROR_NO_ACE_CONDITION","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ace","condition","the","specified","access","control","entry","does","not","contain"],"errorCode":"804","eventId":"","severity":"Low","summary":"The specified access control entry (ACE) does not contain a condition.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 804; use the surrounding log entries to confirm it.","resolution":"1. Record where 804 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_ACE_CONDITION.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 804 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified access control entry (ACE) does not contain a condition.\n\nLookup forms: 804, 0x324, error 804, ERROR_NO_ACE_CONDITION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["804"]},{"id":509,"title":"ERROR_INVALID_ACE_CONDITION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["805","0x325","error 805","ERROR_INVALID_ACE_CONDITION","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","invalid","ace","condition","the","specified","access","control","entry","contains"],"errorCode":"805","eventId":"","severity":"Medium","summary":"The specified access control entry (ACE) contains an invalid condition.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 805; use the surrounding log entries to confirm it.","resolution":"1. Record where 805 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_ACE_CONDITION.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 805 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified access control entry (ACE) contains an invalid condition.\n\nLookup forms: 805, 0x325, error 805, ERROR_INVALID_ACE_CONDITION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["805"]},{"id":510,"title":"ERROR_FILE_HANDLE_REVOKED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["806","0x326","error 806","ERROR_FILE_HANDLE_REVOKED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","file","handle","revoked","access","the","specified","has","been"],"errorCode":"806","eventId":"","severity":"Low","summary":"Access to the specified file handle has been revoked.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 806; use the surrounding log entries to confirm it.","resolution":"1. Record where 806 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Confirm the user or service identity has the required permissions and is not locked or disabled.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FILE_HANDLE_REVOKED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Confirm the user or service identity has the required permissions and is not locked or disabled.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 806 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Access to the specified file handle has been revoked.\n\nLookup forms: 806, 0x326, error 806, ERROR_FILE_HANDLE_REVOKED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["806"]},{"id":511,"title":"ERROR_IMAGE_AT_DIFFERENT_BASE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["807","0x327","error 807","ERROR_IMAGE_AT_DIFFERENT_BASE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","image","different","base","file","was","mapped","address","from","the","one","specified","but","fixups","will","still","automatically","performed"],"errorCode":"807","eventId":"","severity":"Low","summary":"An image file was mapped at a different address from the one specified in the image file but fixups will still be automatically performed on the image.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 807; use the surrounding log entries to confirm it.","resolution":"1. Record where 807 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IMAGE_AT_DIFFERENT_BASE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 807 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An image file was mapped at a different address from the one specified in the image file but fixups will still be automatically performed on the image.\n\nLookup forms: 807, 0x327, error 807, ERROR_IMAGE_AT_DIFFERENT_BASE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["807"]},{"id":512,"title":"ERROR_EA_ACCESS_DENIED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["994","0x3E2","error 994","ERROR_EA_ACCESS_DENIED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","access","denied","the","extended","attribute","was"],"errorCode":"994","eventId":"","severity":"Low","summary":"Access to the extended attribute was denied.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 994; use the surrounding log entries to confirm it.","resolution":"1. Record where 994 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EA_ACCESS_DENIED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 994 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Access to the extended attribute was denied.\n\nLookup forms: 994, 0x3E2, error 994, ERROR_EA_ACCESS_DENIED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["994"]},{"id":513,"title":"ERROR_OPERATION_ABORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["995","0x3E3","error 995","ERROR_OPERATION_ABORTED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","operation","aborted","the","has","been","because","either","thread","exit","application","request"],"errorCode":"995","eventId":"","severity":"Low","summary":"The I/O operation has been aborted because of either a thread exit or an application request.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 995; use the surrounding log entries to confirm it.","resolution":"1. Record where 995 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_OPERATION_ABORTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 995 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The I/O operation has been aborted because of either a thread exit or an application request.\n\nLookup forms: 995, 0x3E3, error 995, ERROR_OPERATION_ABORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["995"]},{"id":514,"title":"ERROR_IO_INCOMPLETE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["996","0x3E4","error 996","ERROR_IO_INCOMPLETE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","incomplete","overlapped","event","not","signaled","state"],"errorCode":"996","eventId":"","severity":"Low","summary":"Overlapped I/O event is not in a signaled state.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 996; use the surrounding log entries to confirm it.","resolution":"1. Record where 996 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IO_INCOMPLETE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 996 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Overlapped I/O event is not in a signaled state.\n\nLookup forms: 996, 0x3E4, error 996, ERROR_IO_INCOMPLETE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["996"]},{"id":515,"title":"ERROR_IO_PENDING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["997","0x3E5","error 997","ERROR_IO_PENDING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","pending","overlapped","operation","progress"],"errorCode":"997","eventId":"","severity":"Low","summary":"Overlapped I/O operation is in progress.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 997; use the surrounding log entries to confirm it.","resolution":"1. Record where 997 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IO_PENDING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 997 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Overlapped I/O operation is in progress.\n\nLookup forms: 997, 0x3E5, error 997, ERROR_IO_PENDING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["997"]},{"id":516,"title":"ERROR_NOACCESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["998","0x3E6","error 998","ERROR_NOACCESS","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","noaccess","invalid","access","memory","location"],"errorCode":"998","eventId":"","severity":"Medium","summary":"Invalid access to memory location.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 998; use the surrounding log entries to confirm it.","resolution":"1. Record where 998 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOACCESS.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 998 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid access to memory location.\n\nLookup forms: 998, 0x3E6, error 998, ERROR_NOACCESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["998"]},{"id":517,"title":"ERROR_SWAPERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["999","0x3E7","error 999","ERROR_SWAPERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","swaperror","performing","inpage","operation"],"errorCode":"999","eventId":"","severity":"Low","summary":"Error performing inpage operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 999; use the surrounding log entries to confirm it.","resolution":"1. Record where 999 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SWAPERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 999 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Error performing inpage operation.\n\nLookup forms: 999, 0x3E7, error 999, ERROR_SWAPERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["999"]},{"id":518,"title":"ERROR_STACK_OVERFLOW","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1001","0x3E9","error 1001","ERROR_STACK_OVERFLOW","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","stack","overflow","recursion","too","deep","the","overflowed","microsoft","365","apps","something","went","wrong","during","desktop","sign"],"errorCode":"1001","eventId":"","severity":"Low","summary":"Recursion too deep; the stack overflowed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1001; use the surrounding log entries to confirm it.","resolution":"1. Record where 1001 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STACK_OVERFLOW.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1001 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Recursion too deep; the stack overflowed.\n\nLookup forms: 1001, 0x3E9, error 1001, ERROR_STACK_OVERFLOW. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (microsoft_windows_error_code_master_list.txt): Category: MICROSOFT 365 APPS\nDescription: Something went wrong during Microsoft 365 desktop sign-in.\n\nFixes:\n1. Review Click-to-Run, activation, or WAM sign-in logs for the exact failure.\n2. Verify licensing, edition, account, time, network, proxy, Office CDN access, and conflicting Office installations.\n3. Repair or remove damaged Office components with Microsoft support tools, then reinstall or reactivate from the approved source.\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf; microsoft_windows_error_code_master_list.txt","commands":[],"platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1001"]},{"id":519,"title":"ERROR_INVALID_MESSAGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1002","0x3EA","error 1002","ERROR_INVALID_MESSAGE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","message","the","window","cannot","act","sent"],"errorCode":"1002","eventId":"","severity":"Medium","summary":"The window cannot act on the sent message.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1002; use the surrounding log entries to confirm it.","resolution":"1. Record where 1002 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_MESSAGE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1002 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The window cannot act on the sent message.\n\nLookup forms: 1002, 0x3EA, error 1002, ERROR_INVALID_MESSAGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1002"]},{"id":520,"title":"ERROR_CAN_NOT_COMPLETE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1003","0x3EB","error 1003","ERROR_CAN_NOT_COMPLETE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","can","not","complete","cannot","this","function"],"errorCode":"1003","eventId":"","severity":"Medium","summary":"Cannot complete this function.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1003; use the surrounding log entries to confirm it.","resolution":"1. Record where 1003 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CAN_NOT_COMPLETE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1003 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot complete this function.\n\nLookup forms: 1003, 0x3EB, error 1003, ERROR_CAN_NOT_COMPLETE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1003"]},{"id":521,"title":"ERROR_INVALID_FLAGS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1004","0x3EC","error 1004","ERROR_INVALID_FLAGS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","flags"],"errorCode":"1004","eventId":"","severity":"Medium","summary":"Invalid flags.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1004; use the surrounding log entries to confirm it.","resolution":"1. Record where 1004 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_FLAGS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1004 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid flags.\n\nLookup forms: 1004, 0x3EC, error 1004, ERROR_INVALID_FLAGS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1004"]},{"id":522,"title":"ERROR_UNRECOGNIZED_VOLUME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1005","0x3ED","error 1005","ERROR_UNRECOGNIZED_VOLUME","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","unrecognized","volume","the","does","not","contain","recognized","file","system","please","make","sure","that","all","required","drivers","are","loaded","and","corrupted"],"errorCode":"1005","eventId":"","severity":"Critical","summary":"The volume does not contain a recognized file system. Please make sure that all required file system drivers are loaded and that the volume is not corrupted.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1005; use the surrounding log entries to confirm it.","resolution":"1. Record where 1005 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNRECOGNIZED_VOLUME.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1005 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The volume does not contain a recognized file system. Please make sure that all required file system drivers are loaded and that the volume is not corrupted.\n\nLookup forms: 1005, 0x3ED, error 1005, ERROR_UNRECOGNIZED_VOLUME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1005"]},{"id":523,"title":"ERROR_FILE_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1006","0x3EE","error 1006","ERROR_FILE_INVALID","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","file","invalid","the","volume","for","has","been","externally","altered","that","opened","longer","valid"],"errorCode":"1006","eventId":"","severity":"Low","summary":"The volume for a file has been externally altered so that the opened file is no longer valid.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1006; use the surrounding log entries to confirm it.","resolution":"1. Record where 1006 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FILE_INVALID.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1006 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The volume for a file has been externally altered so that the opened file is no longer valid.\n\nLookup forms: 1006, 0x3EE, error 1006, ERROR_FILE_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1006"]},{"id":524,"title":"ERROR_FULLSCREEN_MODE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1007","0x3EF","error 1007","ERROR_FULLSCREEN_MODE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","fullscreen","mode","the","requested","operation","cannot","performed","full","screen"],"errorCode":"1007","eventId":"","severity":"Medium","summary":"The requested operation cannot be performed in full-screen mode.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1007; use the surrounding log entries to confirm it.","resolution":"1. Record where 1007 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FULLSCREEN_MODE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1007 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested operation cannot be performed in full-screen mode.\n\nLookup forms: 1007, 0x3EF, error 1007, ERROR_FULLSCREEN_MODE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1007"]},{"id":525,"title":"ERROR_NO_TOKEN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1008","0x3F0","error 1008","ERROR_NO_TOKEN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","token","attempt","was","made","reference","that","does","not","exist"],"errorCode":"1008","eventId":"","severity":"Low","summary":"An attempt was made to reference a token that does not exist.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1008; use the surrounding log entries to confirm it.","resolution":"1. Record where 1008 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_TOKEN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1008 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt was made to reference a token that does not exist.\n\nLookup forms: 1008, 0x3F0, error 1008, ERROR_NO_TOKEN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1008"]},{"id":526,"title":"ERROR_BADDB","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1009","0x3F1","error 1009","ERROR_BADDB","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","baddb","the","configuration","registry","database","corrupt"],"errorCode":"1009","eventId":"","severity":"Critical","summary":"The configuration registry database is corrupt.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1009; use the surrounding log entries to confirm it.","resolution":"1. Record where 1009 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BADDB.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1009 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The configuration registry database is corrupt.\n\nLookup forms: 1009, 0x3F1, error 1009, ERROR_BADDB. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1009"]},{"id":527,"title":"ERROR_BADKEY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1010","0x3F2","error 1010","ERROR_BADKEY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","badkey","the","configuration","registry","key","invalid"],"errorCode":"1010","eventId":"","severity":"Medium","summary":"The configuration registry key is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1010; use the surrounding log entries to confirm it.","resolution":"1. Record where 1010 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BADKEY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1010 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The configuration registry key is invalid.\n\nLookup forms: 1010, 0x3F2, error 1010, ERROR_BADKEY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1010"]},{"id":528,"title":"ERROR_CANTOPEN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1011","0x3F3","error 1011","ERROR_CANTOPEN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cantopen","the","configuration","registry","key","could","not","opened"],"errorCode":"1011","eventId":"","severity":"Low","summary":"The configuration registry key could not be opened.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1011; use the surrounding log entries to confirm it.","resolution":"1. Record where 1011 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANTOPEN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1011 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The configuration registry key could not be opened.\n\nLookup forms: 1011, 0x3F3, error 1011, ERROR_CANTOPEN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1011"]},{"id":529,"title":"ERROR_CANTREAD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1012","0x3F4","error 1012","ERROR_CANTREAD","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cantread","the","configuration","registry","key","could","not","read"],"errorCode":"1012","eventId":"","severity":"Low","summary":"The configuration registry key could not be read.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1012; use the surrounding log entries to confirm it.","resolution":"1. Record where 1012 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANTREAD.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1012 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The configuration registry key could not be read.\n\nLookup forms: 1012, 0x3F4, error 1012, ERROR_CANTREAD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1012"]},{"id":530,"title":"ERROR_CANTWRITE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1013","0x3F5","error 1013","ERROR_CANTWRITE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cantwrite","the","configuration","registry","key","could","not","written"],"errorCode":"1013","eventId":"","severity":"Low","summary":"The configuration registry key could not be written.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1013; use the surrounding log entries to confirm it.","resolution":"1. Record where 1013 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANTWRITE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1013 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The configuration registry key could not be written.\n\nLookup forms: 1013, 0x3F5, error 1013, ERROR_CANTWRITE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1013"]},{"id":531,"title":"ERROR_REGISTRY_RECOVERED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1014","0x3F6","error 1014","ERROR_REGISTRY_RECOVERED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","registry","recovered","one","the","files","database","had","use","log","alternate","copy","recovery","was","successful"],"errorCode":"1014","eventId":"","severity":"Low","summary":"One of the files in the registry database had to be recovered by use of a log or alternate copy. The recovery was successful.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1014; use the surrounding log entries to confirm it.","resolution":"1. Record where 1014 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REGISTRY_RECOVERED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1014 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: One of the files in the registry database had to be recovered by use of a log or alternate copy. The recovery was successful.\n\nLookup forms: 1014, 0x3F6, error 1014, ERROR_REGISTRY_RECOVERED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1014"]},{"id":532,"title":"ERROR_REGISTRY_CORRUPT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1015","0x3F7","error 1015","ERROR_REGISTRY_CORRUPT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","registry","corrupt","the","corrupted","structure","one","files","containing","data","system","memory","image","file","could","not","recovered","because","alternate","copy","log","was","absent"],"errorCode":"1015","eventId":"","severity":"Critical","summary":"The registry is corrupted. The structure of one of the files containing registry data is corrupted, or the system's memory image of the file is corrupted, or the file could not be recovered because the alternate copy or log was absent or corrupted.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1015; use the surrounding log entries to confirm it.","resolution":"1. Record where 1015 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REGISTRY_CORRUPT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1015 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The registry is corrupted. The structure of one of the files containing registry data is corrupted, or the system's memory image of the file is corrupted, or the file could not be recovered because the alternate copy or log was absent or corrupted.\n\nLookup forms: 1015, 0x3F7, error 1015, ERROR_REGISTRY_CORRUPT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1015"]},{"id":533,"title":"ERROR_REGISTRY_IO_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1016","0x3F8","error 1016","ERROR_REGISTRY_IO_FAILED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","registry","failed","operation","initiated","the","unrecoverably","could","not","read","write","out","flush","one","files","that","contain","system","image"],"errorCode":"1016","eventId":"","severity":"High","summary":"An I/O operation initiated by the registry failed unrecoverably. The registry could not read in, or write out, or flush, one of the files that contain the system's image of the registry.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1016; use the surrounding log entries to confirm it.","resolution":"1. Record where 1016 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REGISTRY_IO_FAILED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1016 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An I/O operation initiated by the registry failed unrecoverably. The registry could not read in, or write out, or flush, one of the files that contain the system's image of the registry.\n\nLookup forms: 1016, 0x3F8, error 1016, ERROR_REGISTRY_IO_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1016"]},{"id":534,"title":"ERROR_NOT_REGISTRY_FILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1017","0x3F9","error 1017","ERROR_NOT_REGISTRY_FILE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","not","registry","file","the","system","has","attempted","load","restore","into","but","specified","format"],"errorCode":"1017","eventId":"","severity":"Low","summary":"The system has attempted to load or restore a file into the registry, but the specified file is not in a registry file format.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1017; use the surrounding log entries to confirm it.","resolution":"1. Record where 1017 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_REGISTRY_FILE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1017 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system has attempted to load or restore a file into the registry, but the specified file is not in a registry file format.\n\nLookup forms: 1017, 0x3F9, error 1017, ERROR_NOT_REGISTRY_FILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1017"]},{"id":535,"title":"ERROR_KEY_DELETED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1018","0x3FA","error 1018","ERROR_KEY_DELETED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","key","deleted","illegal","operation","attempted","registry","that","has","been","marked","for","deletion"],"errorCode":"1018","eventId":"","severity":"Low","summary":"Illegal operation attempted on a registry key that has been marked for deletion.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1018; use the surrounding log entries to confirm it.","resolution":"1. Record where 1018 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_KEY_DELETED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1018 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Illegal operation attempted on a registry key that has been marked for deletion.\n\nLookup forms: 1018, 0x3FA, error 1018, ERROR_KEY_DELETED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1018"]},{"id":536,"title":"ERROR_NO_LOG_SPACE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1019","0x3FB","error 1019","ERROR_NO_LOG_SPACE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","log","space","system","could","not","allocate","the","required","registry"],"errorCode":"1019","eventId":"","severity":"Low","summary":"System could not allocate the required space in a registry log.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1019; use the surrounding log entries to confirm it.","resolution":"1. Record where 1019 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_LOG_SPACE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1019 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: System could not allocate the required space in a registry log.\n\nLookup forms: 1019, 0x3FB, error 1019, ERROR_NO_LOG_SPACE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1019"]},{"id":537,"title":"ERROR_KEY_HAS_CHILDREN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1020","0x3FC","error 1020","ERROR_KEY_HAS_CHILDREN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","key","has","children","cannot","create","symbolic","link","registry","that","already","subkeys","values"],"errorCode":"1020","eventId":"","severity":"Medium","summary":"Cannot create a symbolic link in a registry key that already has subkeys or values.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1020; use the surrounding log entries to confirm it.","resolution":"1. Record where 1020 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_KEY_HAS_CHILDREN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1020 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot create a symbolic link in a registry key that already has subkeys or values.\n\nLookup forms: 1020, 0x3FC, error 1020, ERROR_KEY_HAS_CHILDREN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1020"]},{"id":538,"title":"ERROR_CHILD_MUST_BE_VOLATILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1021","0x3FD","error 1021","ERROR_CHILD_MUST_BE_VOLATILE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","child","must","volatile","cannot","create","stable","subkey","under","parent","key"],"errorCode":"1021","eventId":"","severity":"Medium","summary":"Cannot create a stable subkey under a volatile parent key.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1021; use the surrounding log entries to confirm it.","resolution":"1. Record where 1021 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CHILD_MUST_BE_VOLATILE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1021 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot create a stable subkey under a volatile parent key.\n\nLookup forms: 1021, 0x3FD, error 1021, ERROR_CHILD_MUST_BE_VOLATILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1021"]},{"id":539,"title":"ERROR_NOTIFY_ENUM_DIR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1022","0x3FE","error 1022","ERROR_NOTIFY_ENUM_DIR","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","notify","enum","dir","change","request","being","completed","and","the","information","not","returned","caller","buffer","now","needs","enumerate","files","find","changes"],"errorCode":"1022","eventId":"","severity":"Low","summary":"A notify change request is being completed and the information is not being returned in the caller's buffer. The caller now needs to enumerate the files to find the changes.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1022; use the surrounding log entries to confirm it.","resolution":"1. Record where 1022 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOTIFY_ENUM_DIR.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1022 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A notify change request is being completed and the information is not being returned in the caller's buffer. The caller now needs to enumerate the files to find the changes.\n\nLookup forms: 1022, 0x3FE, error 1022, ERROR_NOTIFY_ENUM_DIR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1022"]},{"id":540,"title":"ERROR_DEPENDENT_SERVICES_RUNNING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1051","0x41B","error 1051","ERROR_DEPENDENT_SERVICES_RUNNING","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","dependent","services","running","stop","control","has","been","sent","service","that","other","are"],"errorCode":"1051","eventId":"","severity":"Low","summary":"A stop control has been sent to a service that other running services are dependent on.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1051; use the surrounding log entries to confirm it.","resolution":"1. Record where 1051 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEPENDENT_SERVICES_RUNNING.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1051 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A stop control has been sent to a service that other running services are dependent on.\n\nLookup forms: 1051, 0x41B, error 1051, ERROR_DEPENDENT_SERVICES_RUNNING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1051"]},{"id":541,"title":"ERROR_INVALID_SERVICE_CONTROL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1052","0x41C","error 1052","ERROR_INVALID_SERVICE_CONTROL","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","invalid","service","control","the","requested","not","valid","for","this"],"errorCode":"1052","eventId":"","severity":"Low","summary":"The requested control is not valid for this service.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1052; use the surrounding log entries to confirm it.","resolution":"1. Record where 1052 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_SERVICE_CONTROL.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1052 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested control is not valid for this service.\n\nLookup forms: 1052, 0x41C, error 1052, ERROR_INVALID_SERVICE_CONTROL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1052"]},{"id":542,"title":"ERROR_SERVICE_REQUEST_TIMEOUT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1053","0x41D","error 1053","ERROR_SERVICE_REQUEST_TIMEOUT","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","service","request","timeout","the","did","not","respond","start","control","timely","fashion","group","policy","could","determine","user","computer","name"],"errorCode":"1053","eventId":"","severity":"Low","summary":"The service did not respond to the start or control request in a timely fashion.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1053; use the surrounding log entries to confirm it.","resolution":"1. Record where 1053 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVICE_REQUEST_TIMEOUT.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1053 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The service did not respond to the start or control request in a timely fashion.\n\nLookup forms: 1053, 0x41D, error 1053, ERROR_SERVICE_REQUEST_TIMEOUT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (microsoft_windows_error_code_master_list.txt): Category: GROUP POLICY\nDescription: Group Policy could not determine the user or computer name.\n\nFixes:\n1. Review the GroupPolicy operational and System logs and note adjacent events.\n2. Verify domain DNS, time, secure channel, domain-controller discovery, SYSVOL access, DFSR, and permissions.\n3. Correct the directory, replication, or network issue and run gpupdate /force.\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf; microsoft_windows_error_code_master_list.txt","commands":["gpupdate /force"],"platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1053"]},{"id":543,"title":"ERROR_SERVICE_NO_THREAD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1054","0x41E","error 1054","ERROR_SERVICE_NO_THREAD","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","service","thread","could","not","created","for","the"],"errorCode":"1054","eventId":"","severity":"Low","summary":"A thread could not be created for the service.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1054; use the surrounding log entries to confirm it.","resolution":"1. Record where 1054 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVICE_NO_THREAD.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1054 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A thread could not be created for the service.\n\nLookup forms: 1054, 0x41E, error 1054, ERROR_SERVICE_NO_THREAD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1054"]},{"id":544,"title":"ERROR_SERVICE_DATABASE_LOCKED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1055","0x41F","error 1055","ERROR_SERVICE_DATABASE_LOCKED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","service","database","locked","the"],"errorCode":"1055","eventId":"","severity":"High","summary":"The service database is locked.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1055; use the surrounding log entries to confirm it.","resolution":"1. Record where 1055 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVICE_DATABASE_LOCKED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1055 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The service database is locked.\n\nLookup forms: 1055, 0x41F, error 1055, ERROR_SERVICE_DATABASE_LOCKED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1055"]},{"id":545,"title":"ERROR_SERVICE_ALREADY_RUNNING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1056","0x420","error 1056","ERROR_SERVICE_ALREADY_RUNNING","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","service","already","running","instance","the"],"errorCode":"1056","eventId":"","severity":"Low","summary":"An instance of the service is already running.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1056; use the surrounding log entries to confirm it.","resolution":"1. Record where 1056 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVICE_ALREADY_RUNNING.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1056 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An instance of the service is already running.\n\nLookup forms: 1056, 0x420, error 1056, ERROR_SERVICE_ALREADY_RUNNING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1056"]},{"id":546,"title":"ERROR_INVALID_SERVICE_ACCOUNT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1057","0x421","error 1057","ERROR_INVALID_SERVICE_ACCOUNT","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","invalid","service","account","the","name","does","not","exist","password","for","specified"],"errorCode":"1057","eventId":"","severity":"Medium","summary":"The account name is invalid or does not exist, or the password is invalid for the account name specified.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1057; use the surrounding log entries to confirm it.","resolution":"1. Record where 1057 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_SERVICE_ACCOUNT.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1057 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The account name is invalid or does not exist, or the password is invalid for the account name specified.\n\nLookup forms: 1057, 0x421, error 1057, ERROR_INVALID_SERVICE_ACCOUNT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1057"]},{"id":547,"title":"ERROR_SERVICE_DISABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1058","0x422","error 1058","ERROR_SERVICE_DISABLED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","service","disabled","the","cannot","started","either","because","has","enabled","devices","associated","with","group","policy","could","not","read","file"],"errorCode":"1058","eventId":"","severity":"Medium","summary":"The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1058; use the surrounding log entries to confirm it.","resolution":"1. Record where 1058 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVICE_DISABLED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1058 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.\n\nLookup forms: 1058, 0x422, error 1058, ERROR_SERVICE_DISABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (microsoft_windows_error_code_master_list.txt): Category: GROUP POLICY\nDescription: Group Policy could not read a policy file.\n\nFixes:\n1. Review the GroupPolicy operational and System logs and note adjacent events.\n2. Verify domain DNS, time, secure channel, domain-controller discovery, SYSVOL access, DFSR, and permissions.\n3. Correct the directory, replication, or network issue and run gpupdate /force.\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf; microsoft_windows_error_code_master_list.txt","commands":["gpupdate /force"],"platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1058"]},{"id":548,"title":"ERROR_CIRCULAR_DEPENDENCY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1059","0x423","error 1059","ERROR_CIRCULAR_DEPENDENCY","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","circular","dependency","service","was","specified"],"errorCode":"1059","eventId":"","severity":"Low","summary":"Circular service dependency was specified.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1059; use the surrounding log entries to confirm it.","resolution":"1. Record where 1059 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CIRCULAR_DEPENDENCY.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1059 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Circular service dependency was specified.\n\nLookup forms: 1059, 0x423, error 1059, ERROR_CIRCULAR_DEPENDENCY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1059"]},{"id":549,"title":"ERROR_SERVICE_DOES_NOT_EXIST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1060","0x424","error 1060","ERROR_SERVICE_DOES_NOT_EXIST","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","service","does","not","exist","the","specified","installed"],"errorCode":"1060","eventId":"","severity":"Low","summary":"The specified service does not exist as an installed service.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1060; use the surrounding log entries to confirm it.","resolution":"1. Record where 1060 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVICE_DOES_NOT_EXIST.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1060 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified service does not exist as an installed service.\n\nLookup forms: 1060, 0x424, error 1060, ERROR_SERVICE_DOES_NOT_EXIST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1060"]},{"id":550,"title":"ERROR_SERVICE_CANNOT_ACCEPT_CTRL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1061","0x425","error 1061","ERROR_SERVICE_CANNOT_ACCEPT_CTRL","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","service","cannot","accept","ctrl","the","control","messages","this","time"],"errorCode":"1061","eventId":"","severity":"Medium","summary":"The service cannot accept control messages at this time.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1061; use the surrounding log entries to confirm it.","resolution":"1. Record where 1061 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVICE_CANNOT_ACCEPT_CTRL.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1061 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The service cannot accept control messages at this time.\n\nLookup forms: 1061, 0x425, error 1061, ERROR_SERVICE_CANNOT_ACCEPT_CTRL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1061"]},{"id":551,"title":"ERROR_SERVICE_NOT_ACTIVE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1062","0x426","error 1062","ERROR_SERVICE_NOT_ACTIVE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","service","not","active","the","has","been","started"],"errorCode":"1062","eventId":"","severity":"Low","summary":"The service has not been started.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1062; use the surrounding log entries to confirm it.","resolution":"1. Record where 1062 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVICE_NOT_ACTIVE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1062 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The service has not been started.\n\nLookup forms: 1062, 0x426, error 1062, ERROR_SERVICE_NOT_ACTIVE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1062"]},{"id":552,"title":"ERROR_FAILED_SERVICE_CONTROLLER_CONNECT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1063","0x427","error 1063","ERROR_FAILED_SERVICE_CONTROLLER_CONNECT","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","failed","service","controller","connect","the","process","could","not"],"errorCode":"1063","eventId":"","severity":"Low","summary":"The service process could not connect to the service controller.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1063; use the surrounding log entries to confirm it.","resolution":"1. Record where 1063 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FAILED_SERVICE_CONTROLLER_CONNECT.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1063 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The service process could not connect to the service controller.\n\nLookup forms: 1063, 0x427, error 1063, ERROR_FAILED_SERVICE_CONTROLLER_CONNECT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1063"]},{"id":553,"title":"ERROR_EXCEPTION_IN_SERVICE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1064","0x428","error 1064","ERROR_EXCEPTION_IN_SERVICE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","exception","service","occurred","the","when","handling","control","request"],"errorCode":"1064","eventId":"","severity":"Low","summary":"An exception occurred in the service when handling the control request.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1064; use the surrounding log entries to confirm it.","resolution":"1. Record where 1064 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EXCEPTION_IN_SERVICE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1064 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An exception occurred in the service when handling the control request.\n\nLookup forms: 1064, 0x428, error 1064, ERROR_EXCEPTION_IN_SERVICE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1064"]},{"id":554,"title":"ERROR_DATABASE_DOES_NOT_EXIST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1065","0x429","error 1065","ERROR_DATABASE_DOES_NOT_EXIST","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","database","does","not","exist","the","specified"],"errorCode":"1065","eventId":"","severity":"Low","summary":"The database specified does not exist.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1065; use the surrounding log entries to confirm it.","resolution":"1. Record where 1065 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DATABASE_DOES_NOT_EXIST.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1065 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The database specified does not exist.\n\nLookup forms: 1065, 0x429, error 1065, ERROR_DATABASE_DOES_NOT_EXIST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1065"]},{"id":555,"title":"ERROR_SERVICE_SPECIFIC_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1066","0x42A","error 1066","ERROR_SERVICE_SPECIFIC_ERROR","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","service","specific","the","has","returned","code"],"errorCode":"1066","eventId":"","severity":"Low","summary":"The service has returned a service-specific error code.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1066; use the surrounding log entries to confirm it.","resolution":"1. Record where 1066 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVICE_SPECIFIC_ERROR.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1066 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The service has returned a service-specific error code.\n\nLookup forms: 1066, 0x42A, error 1066, ERROR_SERVICE_SPECIFIC_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1066"]},{"id":556,"title":"ERROR_PROCESS_ABORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1067","0x42B","error 1067","ERROR_PROCESS_ABORTED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","process","aborted","the","terminated","unexpectedly"],"errorCode":"1067","eventId":"","severity":"Low","summary":"The process terminated unexpectedly.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1067; use the surrounding log entries to confirm it.","resolution":"1. Record where 1067 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PROCESS_ABORTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1067 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The process terminated unexpectedly.\n\nLookup forms: 1067, 0x42B, error 1067, ERROR_PROCESS_ABORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1067"]},{"id":557,"title":"ERROR_SERVICE_DEPENDENCY_FAIL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1068","0x42C","error 1068","ERROR_SERVICE_DEPENDENCY_FAIL","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","service","dependency","fail","the","group","failed","start"],"errorCode":"1068","eventId":"","severity":"High","summary":"The dependency service or group failed to start.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1068; use the surrounding log entries to confirm it.","resolution":"1. Record where 1068 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVICE_DEPENDENCY_FAIL.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1068 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The dependency service or group failed to start.\n\nLookup forms: 1068, 0x42C, error 1068, ERROR_SERVICE_DEPENDENCY_FAIL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1068"]},{"id":558,"title":"ERROR_SERVICE_LOGON_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1069","0x42D","error 1069","ERROR_SERVICE_LOGON_FAILED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","service","logon","failed","the","did","not","start","due","failure"],"errorCode":"1069","eventId":"","severity":"High","summary":"The service did not start due to a logon failure.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1069; use the surrounding log entries to confirm it.","resolution":"1. Record where 1069 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVICE_LOGON_FAILED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1069 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The service did not start due to a logon failure.\n\nLookup forms: 1069, 0x42D, error 1069, ERROR_SERVICE_LOGON_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1069"]},{"id":559,"title":"ERROR_SERVICE_START_HANG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1070","0x42E","error 1070","ERROR_SERVICE_START_HANG","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","service","start","hang","after","starting","the","hung","pending","state"],"errorCode":"1070","eventId":"","severity":"Low","summary":"After starting, the service hung in a start-pending state.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1070; use the surrounding log entries to confirm it.","resolution":"1. Record where 1070 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVICE_START_HANG.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1070 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: After starting, the service hung in a start-pending state.\n\nLookup forms: 1070, 0x42E, error 1070, ERROR_SERVICE_START_HANG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1070"]},{"id":560,"title":"ERROR_INVALID_SERVICE_LOCK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1071","0x42F","error 1071","ERROR_INVALID_SERVICE_LOCK","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","invalid","service","lock","the","specified","database"],"errorCode":"1071","eventId":"","severity":"Medium","summary":"The specified service database lock is invalid.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1071; use the surrounding log entries to confirm it.","resolution":"1. Record where 1071 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_SERVICE_LOCK.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1071 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified service database lock is invalid.\n\nLookup forms: 1071, 0x42F, error 1071, ERROR_INVALID_SERVICE_LOCK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1071"]},{"id":561,"title":"ERROR_SERVICE_MARKED_FOR_DELETE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1072","0x430","error 1072","ERROR_SERVICE_MARKED_FOR_DELETE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","service","marked","for","delete","the","specified","has","been","deletion"],"errorCode":"1072","eventId":"","severity":"Low","summary":"The specified service has been marked for deletion.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1072; use the surrounding log entries to confirm it.","resolution":"1. Record where 1072 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVICE_MARKED_FOR_DELETE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1072 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified service has been marked for deletion.\n\nLookup forms: 1072, 0x430, error 1072, ERROR_SERVICE_MARKED_FOR_DELETE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1072"]},{"id":562,"title":"ERROR_SERVICE_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1073","0x431","error 1073","ERROR_SERVICE_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","service","exists","the","specified","already"],"errorCode":"1073","eventId":"","severity":"Medium","summary":"The specified service already exists.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1073; use the surrounding log entries to confirm it.","resolution":"1. Record where 1073 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVICE_EXISTS.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1073 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified service already exists.\n\nLookup forms: 1073, 0x431, error 1073, ERROR_SERVICE_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1073"]},{"id":563,"title":"ERROR_ALREADY_RUNNING_LKG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1074","0x432","error 1074","ERROR_ALREADY_RUNNING_LKG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","already","running","lkg","the","system","currently","with","last","known","good","configuration"],"errorCode":"1074","eventId":"","severity":"Low","summary":"The system is currently running with the last-known-good configuration.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1074; use the surrounding log entries to confirm it.","resolution":"1. Record where 1074 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ALREADY_RUNNING_LKG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1074 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system is currently running with the last-known-good configuration.\n\nLookup forms: 1074, 0x432, error 1074, ERROR_ALREADY_RUNNING_LKG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1074"]},{"id":564,"title":"ERROR_SERVICE_DEPENDENCY_DELETED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1075","0x433","error 1075","ERROR_SERVICE_DEPENDENCY_DELETED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","service","dependency","deleted","the","does","not","exist","has","been","marked","for","deletion"],"errorCode":"1075","eventId":"","severity":"Low","summary":"The dependency service does not exist or has been marked for deletion.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1075; use the surrounding log entries to confirm it.","resolution":"1. Record where 1075 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVICE_DEPENDENCY_DELETED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1075 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The dependency service does not exist or has been marked for deletion.\n\nLookup forms: 1075, 0x433, error 1075, ERROR_SERVICE_DEPENDENCY_DELETED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1075"]},{"id":565,"title":"ERROR_BOOT_ALREADY_ACCEPTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1076","0x434","error 1076","ERROR_BOOT_ALREADY_ACCEPTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","boot","already","accepted","the","current","has","been","for","use","last","known","good","control","set"],"errorCode":"1076","eventId":"","severity":"Low","summary":"The current boot has already been accepted for use as the last-known-good control set.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1076; use the surrounding log entries to confirm it.","resolution":"1. Record where 1076 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BOOT_ALREADY_ACCEPTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1076 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The current boot has already been accepted for use as the last-known-good control set.\n\nLookup forms: 1076, 0x434, error 1076, ERROR_BOOT_ALREADY_ACCEPTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1076"]},{"id":566,"title":"ERROR_SERVICE_NEVER_STARTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1077","0x435","error 1077","ERROR_SERVICE_NEVER_STARTED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","service","never","started","attempts","start","the","have","been","made","since","last","boot"],"errorCode":"1077","eventId":"","severity":"Low","summary":"No attempts to start the service have been made since the last boot.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1077; use the surrounding log entries to confirm it.","resolution":"1. Record where 1077 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVICE_NEVER_STARTED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1077 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No attempts to start the service have been made since the last boot.\n\nLookup forms: 1077, 0x435, error 1077, ERROR_SERVICE_NEVER_STARTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1077"]},{"id":567,"title":"ERROR_DUPLICATE_SERVICE_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1078","0x436","error 1078","ERROR_DUPLICATE_SERVICE_NAME","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","duplicate","service","name","the","already","use","either","display"],"errorCode":"1078","eventId":"","severity":"Low","summary":"The name is already in use as either a service name or a service display name.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1078; use the surrounding log entries to confirm it.","resolution":"1. Record where 1078 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DUPLICATE_SERVICE_NAME.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1078 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The name is already in use as either a service name or a service display name.\n\nLookup forms: 1078, 0x436, error 1078, ERROR_DUPLICATE_SERVICE_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1078"]},{"id":568,"title":"ERROR_DIFFERENT_SERVICE_ACCOUNT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1079","0x437","error 1079","ERROR_DIFFERENT_SERVICE_ACCOUNT","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","different","service","account","the","specified","for","this","from","other","services","running","same","process"],"errorCode":"1079","eventId":"","severity":"Low","summary":"The account specified for this service is different from the account specified for other services running in the same process.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1079; use the surrounding log entries to confirm it.","resolution":"1. Record where 1079 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DIFFERENT_SERVICE_ACCOUNT.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1079 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The account specified for this service is different from the account specified for other services running in the same process.\n\nLookup forms: 1079, 0x437, error 1079, ERROR_DIFFERENT_SERVICE_ACCOUNT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1079"]},{"id":569,"title":"ERROR_CANNOT_DETECT_DRIVER_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1080","0x438","error 1080","ERROR_CANNOT_DETECT_DRIVER_FAILURE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","cannot","detect","driver","failure","actions","can","only","set","for","win32","services","not","drivers"],"errorCode":"1080","eventId":"","severity":"High","summary":"Failure actions can only be set for Win32 services, not for drivers.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1080; use the surrounding log entries to confirm it.","resolution":"1. Record where 1080 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANNOT_DETECT_DRIVER_FAILURE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1080 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Failure actions can only be set for Win32 services, not for drivers.\n\nLookup forms: 1080, 0x438, error 1080, ERROR_CANNOT_DETECT_DRIVER_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1080"]},{"id":570,"title":"ERROR_CANNOT_DETECT_PROCESS_ABORT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1081","0x439","error 1081","ERROR_CANNOT_DETECT_PROCESS_ABORT","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","cannot","detect","process","abort","this","service","runs","the","same","control","manager","therefore","take","action","terminates","unexpectedly"],"errorCode":"1081","eventId":"","severity":"Medium","summary":"This service runs in the same process as the service control manager. Therefore, the service control manager cannot take action if this service's process terminates unexpectedly.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1081; use the surrounding log entries to confirm it.","resolution":"1. Record where 1081 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANNOT_DETECT_PROCESS_ABORT.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1081 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This service runs in the same process as the service control manager. Therefore, the service control manager cannot take action if this service's process terminates unexpectedly.\n\nLookup forms: 1081, 0x439, error 1081, ERROR_CANNOT_DETECT_PROCESS_ABORT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1081"]},{"id":571,"title":"ERROR_NO_RECOVERY_PROGRAM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1082","0x43A","error 1082","ERROR_NO_RECOVERY_PROGRAM","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","recovery","program","has","been","configured","for","this","service"],"errorCode":"1082","eventId":"","severity":"Low","summary":"No recovery program has been configured for this service.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1082; use the surrounding log entries to confirm it.","resolution":"1. Record where 1082 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_RECOVERY_PROGRAM.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1082 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No recovery program has been configured for this service.\n\nLookup forms: 1082, 0x43A, error 1082, ERROR_NO_RECOVERY_PROGRAM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1082"]},{"id":572,"title":"ERROR_SERVICE_NOT_IN_EXE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1083","0x43B","error 1083","ERROR_SERVICE_NOT_IN_EXE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","service","not","exe","the","executable","program","that","this","configured","run","does","implement"],"errorCode":"1083","eventId":"","severity":"Low","summary":"The executable program that this service is configured to run in does not implement the service.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1083; use the surrounding log entries to confirm it.","resolution":"1. Record where 1083 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVICE_NOT_IN_EXE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1083 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The executable program that this service is configured to run in does not implement the service.\n\nLookup forms: 1083, 0x43B, error 1083, ERROR_SERVICE_NOT_IN_EXE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1083"]},{"id":573,"title":"ERROR_NOT_SAFEBOOT_SERVICE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1084","0x43C","error 1084","ERROR_NOT_SAFEBOOT_SERVICE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","not","safeboot","service","this","cannot","started","safe","mode"],"errorCode":"1084","eventId":"","severity":"Medium","summary":"This service cannot be started in Safe Mode.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1084; use the surrounding log entries to confirm it.","resolution":"1. Record where 1084 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_SAFEBOOT_SERVICE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1084 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This service cannot be started in Safe Mode.\n\nLookup forms: 1084, 0x43C, error 1084, ERROR_NOT_SAFEBOOT_SERVICE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1084"]},{"id":574,"title":"ERROR_END_OF_MEDIA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1100","0x44C","error 1100","ERROR_END_OF_MEDIA","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","end","media","the","physical","tape","has","been","reached"],"errorCode":"1100","eventId":"","severity":"Low","summary":"The physical end of the tape has been reached.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1100; use the surrounding log entries to confirm it.","resolution":"1. Record where 1100 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_END_OF_MEDIA.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1100 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The physical end of the tape has been reached.\n\nLookup forms: 1100, 0x44C, error 1100, ERROR_END_OF_MEDIA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1100"]},{"id":575,"title":"ERROR_FILEMARK_DETECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1101","0x44D","error 1101","ERROR_FILEMARK_DETECTED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","filemark","detected","tape","access","reached"],"errorCode":"1101","eventId":"","severity":"Low","summary":"A tape access reached a filemark.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1101; use the surrounding log entries to confirm it.","resolution":"1. Record where 1101 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Confirm the user or service identity has the required permissions and is not locked or disabled.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FILEMARK_DETECTED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Confirm the user or service identity has the required permissions and is not locked or disabled.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1101 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A tape access reached a filemark.\n\nLookup forms: 1101, 0x44D, error 1101, ERROR_FILEMARK_DETECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1101"]},{"id":576,"title":"ERROR_BEGINNING_OF_MEDIA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1102","0x44E","error 1102","ERROR_BEGINNING_OF_MEDIA","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","beginning","media","the","tape","partition","was","encountered"],"errorCode":"1102","eventId":"","severity":"Low","summary":"The beginning of the tape or a partition was encountered.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1102; use the surrounding log entries to confirm it.","resolution":"1. Record where 1102 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BEGINNING_OF_MEDIA.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1102 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The beginning of the tape or a partition was encountered.\n\nLookup forms: 1102, 0x44E, error 1102, ERROR_BEGINNING_OF_MEDIA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1102"]},{"id":577,"title":"ERROR_SETMARK_DETECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1103","0x44F","error 1103","ERROR_SETMARK_DETECTED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","setmark","detected","tape","access","reached","the","end","set","files"],"errorCode":"1103","eventId":"","severity":"Low","summary":"A tape access reached the end of a set of files.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1103; use the surrounding log entries to confirm it.","resolution":"1. Record where 1103 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Confirm the user or service identity has the required permissions and is not locked or disabled.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SETMARK_DETECTED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Confirm the user or service identity has the required permissions and is not locked or disabled.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1103 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A tape access reached the end of a set of files.\n\nLookup forms: 1103, 0x44F, error 1103, ERROR_SETMARK_DETECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1103"]},{"id":578,"title":"ERROR_NO_DATA_DETECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1104","0x450","error 1104","ERROR_NO_DATA_DETECTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","data","detected","more","the","tape"],"errorCode":"1104","eventId":"","severity":"Low","summary":"No more data is on the tape.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1104; use the surrounding log entries to confirm it.","resolution":"1. Record where 1104 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_DATA_DETECTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1104 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No more data is on the tape.\n\nLookup forms: 1104, 0x450, error 1104, ERROR_NO_DATA_DETECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1104"]},{"id":579,"title":"ERROR_PARTITION_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1105","0x451","error 1105","ERROR_PARTITION_FAILURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","partition","failure","tape","could","not","partitioned"],"errorCode":"1105","eventId":"","severity":"Low","summary":"Tape could not be partitioned.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1105; use the surrounding log entries to confirm it.","resolution":"1. Record where 1105 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PARTITION_FAILURE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1105 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Tape could not be partitioned.\n\nLookup forms: 1105, 0x451, error 1105, ERROR_PARTITION_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1105"]},{"id":580,"title":"ERROR_INVALID_BLOCK_LENGTH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1106","0x452","error 1106","ERROR_INVALID_BLOCK_LENGTH","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","invalid","block","length","when","accessing","new","tape","multivolume","partition","the","current","size","incorrect"],"errorCode":"1106","eventId":"","severity":"Low","summary":"When accessing a new tape of a multivolume partition, the current block size is incorrect.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1106; use the surrounding log entries to confirm it.","resolution":"1. Record where 1106 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_BLOCK_LENGTH.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1106 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: When accessing a new tape of a multivolume partition, the current block size is incorrect.\n\nLookup forms: 1106, 0x452, error 1106, ERROR_INVALID_BLOCK_LENGTH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1106"]},{"id":581,"title":"ERROR_DEVICE_NOT_PARTITIONED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1107","0x453","error 1107","ERROR_DEVICE_NOT_PARTITIONED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","device","not","partitioned","tape","partition","information","could","found","when","loading"],"errorCode":"1107","eventId":"","severity":"Low","summary":"Tape partition information could not be found when loading a tape.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1107; use the surrounding log entries to confirm it.","resolution":"1. Record where 1107 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEVICE_NOT_PARTITIONED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1107 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Tape partition information could not be found when loading a tape.\n\nLookup forms: 1107, 0x453, error 1107, ERROR_DEVICE_NOT_PARTITIONED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1107"]},{"id":582,"title":"ERROR_UNABLE_TO_LOCK_MEDIA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1108","0x454","error 1108","ERROR_UNABLE_TO_LOCK_MEDIA","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","unable","lock","media","the","eject","mechanism"],"errorCode":"1108","eventId":"","severity":"Medium","summary":"Unable to lock the media eject mechanism.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1108; use the surrounding log entries to confirm it.","resolution":"1. Record where 1108 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNABLE_TO_LOCK_MEDIA.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1108 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to lock the media eject mechanism.\n\nLookup forms: 1108, 0x454, error 1108, ERROR_UNABLE_TO_LOCK_MEDIA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1108"]},{"id":583,"title":"ERROR_UNABLE_TO_UNLOAD_MEDIA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1109","0x455","error 1109","ERROR_UNABLE_TO_UNLOAD_MEDIA","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","unable","unload","media","the"],"errorCode":"1109","eventId":"","severity":"Medium","summary":"Unable to unload the media.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1109; use the surrounding log entries to confirm it.","resolution":"1. Record where 1109 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNABLE_TO_UNLOAD_MEDIA.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1109 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to unload the media.\n\nLookup forms: 1109, 0x455, error 1109, ERROR_UNABLE_TO_UNLOAD_MEDIA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1109"]},{"id":584,"title":"ERROR_MEDIA_CHANGED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1110","0x456","error 1110","ERROR_MEDIA_CHANGED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","media","changed","the","drive","may","have"],"errorCode":"1110","eventId":"","severity":"Low","summary":"The media in the drive may have changed.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1110; use the surrounding log entries to confirm it.","resolution":"1. Record where 1110 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MEDIA_CHANGED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1110 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The media in the drive may have changed.\n\nLookup forms: 1110, 0x456, error 1110, ERROR_MEDIA_CHANGED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1110"]},{"id":585,"title":"ERROR_BUS_RESET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1111","0x457","error 1111","ERROR_BUS_RESET","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","bus","reset","the","was"],"errorCode":"1111","eventId":"","severity":"Low","summary":"The I/O bus was reset.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1111; use the surrounding log entries to confirm it.","resolution":"1. Record where 1111 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BUS_RESET.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1111 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The I/O bus was reset.\n\nLookup forms: 1111, 0x457, error 1111, ERROR_BUS_RESET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1111"]},{"id":586,"title":"ERROR_NO_MEDIA_IN_DRIVE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1112","0x458","error 1112","ERROR_NO_MEDIA_IN_DRIVE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","media","drive"],"errorCode":"1112","eventId":"","severity":"Low","summary":"No media in drive.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1112; use the surrounding log entries to confirm it.","resolution":"1. Record where 1112 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_MEDIA_IN_DRIVE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1112 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No media in drive.\n\nLookup forms: 1112, 0x458, error 1112, ERROR_NO_MEDIA_IN_DRIVE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1112"]},{"id":587,"title":"ERROR_NO_UNICODE_TRANSLATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1113","0x459","error 1113","ERROR_NO_UNICODE_TRANSLATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","unicode","translation","mapping","for","the","character","exists","target","multi","byte","code","page"],"errorCode":"1113","eventId":"","severity":"Low","summary":"No mapping for the Unicode character exists in the target multi-byte code page.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1113; use the surrounding log entries to confirm it.","resolution":"1. Record where 1113 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_UNICODE_TRANSLATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1113 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No mapping for the Unicode character exists in the target multi-byte code page.\n\nLookup forms: 1113, 0x459, error 1113, ERROR_NO_UNICODE_TRANSLATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1113"]},{"id":588,"title":"ERROR_DLL_INIT_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1114","0x45A","error 1114","ERROR_DLL_INIT_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dll","init","failed","dynamic","link","library","initialization","routine"],"errorCode":"1114","eventId":"","severity":"High","summary":"A dynamic link library (DLL) initialization routine failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1114; use the surrounding log entries to confirm it.","resolution":"1. Record where 1114 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DLL_INIT_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1114 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A dynamic link library (DLL) initialization routine failed.\n\nLookup forms: 1114, 0x45A, error 1114, ERROR_DLL_INIT_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1114"]},{"id":589,"title":"ERROR_SHUTDOWN_IN_PROGRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1115","0x45B","error 1115","ERROR_SHUTDOWN_IN_PROGRESS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","shutdown","progress","system"],"errorCode":"1115","eventId":"","severity":"Critical","summary":"A system shutdown is in progress.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1115; use the surrounding log entries to confirm it.","resolution":"1. Record where 1115 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SHUTDOWN_IN_PROGRESS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1115 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A system shutdown is in progress.\n\nLookup forms: 1115, 0x45B, error 1115, ERROR_SHUTDOWN_IN_PROGRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1115"]},{"id":590,"title":"ERROR_NO_SHUTDOWN_IN_PROGRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1116","0x45C","error 1116","ERROR_NO_SHUTDOWN_IN_PROGRESS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","shutdown","progress","unable","abort","the","system","because","was"],"errorCode":"1116","eventId":"","severity":"Critical","summary":"Unable to abort the system shutdown because no shutdown was in progress.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1116; use the surrounding log entries to confirm it.","resolution":"1. Record where 1116 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_SHUTDOWN_IN_PROGRESS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1116 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to abort the system shutdown because no shutdown was in progress.\n\nLookup forms: 1116, 0x45C, error 1116, ERROR_NO_SHUTDOWN_IN_PROGRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1116"]},{"id":591,"title":"ERROR_IO_DEVICE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1117","0x45D","error 1117","ERROR_IO_DEVICE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","device","the","request","could","not","performed","because"],"errorCode":"1117","eventId":"","severity":"Low","summary":"The request could not be performed because of an I/O device error.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1117; use the surrounding log entries to confirm it.","resolution":"1. Record where 1117 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IO_DEVICE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1117 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The request could not be performed because of an I/O device error.\n\nLookup forms: 1117, 0x45D, error 1117, ERROR_IO_DEVICE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1117"]},{"id":592,"title":"ERROR_SERIAL_NO_DEVICE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1118","0x45E","error 1118","ERROR_SERIAL_NO_DEVICE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","serial","device","was","successfully","initialized","the","driver","will","unload"],"errorCode":"1118","eventId":"","severity":"Low","summary":"No serial device was successfully initialized. The serial driver will unload.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1118; use the surrounding log entries to confirm it.","resolution":"1. Record where 1118 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERIAL_NO_DEVICE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1118 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No serial device was successfully initialized. The serial driver will unload.\n\nLookup forms: 1118, 0x45E, error 1118, ERROR_SERIAL_NO_DEVICE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1118"]},{"id":593,"title":"ERROR_IRQ_BUSY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1119","0x45F","error 1119","ERROR_IRQ_BUSY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","irq","busy","unable","open","device","that","was","sharing","interrupt","request","with","other","devices","least","one","uses","already","opened"],"errorCode":"1119","eventId":"","severity":"Medium","summary":"Unable to open a device that was sharing an interrupt request (IRQ) with other devices. At least one other device that uses that IRQ was already opened.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1119; use the surrounding log entries to confirm it.","resolution":"1. Record where 1119 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IRQ_BUSY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1119 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to open a device that was sharing an interrupt request (IRQ) with other devices. At least one other device that uses that IRQ was already opened.\n\nLookup forms: 1119, 0x45F, error 1119, ERROR_IRQ_BUSY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1119"]},{"id":594,"title":"ERROR_MORE_WRITES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1120","0x460","error 1120","ERROR_MORE_WRITES","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","more","writes","serial","operation","was","completed","another","write","the","port","ioctl","xoff","counter","reached","zero"],"errorCode":"1120","eventId":"","severity":"Low","summary":"A serial I/O operation was completed by another write to the serial port. The IOCTL_SERIAL_XOFF_COUNTER reached zero.)","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1120; use the surrounding log entries to confirm it.","resolution":"1. Record where 1120 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MORE_WRITES.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1120 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A serial I/O operation was completed by another write to the serial port. The IOCTL_SERIAL_XOFF_COUNTER reached zero.)\n\nLookup forms: 1120, 0x460, error 1120, ERROR_MORE_WRITES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): A serial I/O operation was completed by another write to the serial port. (The IOCTL_SERIAL_XOFF_COUNTER reached zero.)","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1120"]},{"id":595,"title":"ERROR_COUNTER_TIMEOUT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1121","0x461","error 1121","ERROR_COUNTER_TIMEOUT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","counter","timeout","serial","operation","completed","because","the","period","expired","ioctl","xoff","did","not","reach","zero"],"errorCode":"1121","eventId":"","severity":"Medium","summary":"A serial I/O operation completed because the timeout period expired. The IOCTL_SERIAL_XOFF_COUNTER did not reach zero.)","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1121; use the surrounding log entries to confirm it.","resolution":"1. Record where 1121 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_COUNTER_TIMEOUT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1121 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A serial I/O operation completed because the timeout period expired. The IOCTL_SERIAL_XOFF_COUNTER did not reach zero.)\n\nLookup forms: 1121, 0x461, error 1121, ERROR_COUNTER_TIMEOUT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): A serial I/O operation completed because the timeout period expired. (The IOCTL_SERIAL_XOFF_COUNTER did not reach zero.)","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1121"]},{"id":596,"title":"ERROR_FLOPPY_ID_MARK_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1122","0x462","error 1122","ERROR_FLOPPY_ID_MARK_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","floppy","mark","not","found","address","was","the","disk"],"errorCode":"1122","eventId":"","severity":"Low","summary":"No ID address mark was found on the floppy disk.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1122; use the surrounding log entries to confirm it.","resolution":"1. Record where 1122 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FLOPPY_ID_MARK_NOT_FOUND.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1122 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No ID address mark was found on the floppy disk.\n\nLookup forms: 1122, 0x462, error 1122, ERROR_FLOPPY_ID_MARK_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1122"]},{"id":597,"title":"ERROR_FLOPPY_WRONG_CYLINDER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1123","0x463","error 1123","ERROR_FLOPPY_WRONG_CYLINDER","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","floppy","wrong","cylinder","mismatch","between","the","disk","sector","field","and","controller","track","address"],"errorCode":"1123","eventId":"","severity":"Low","summary":"Mismatch between the floppy disk sector ID field and the floppy disk controller track address.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1123; use the surrounding log entries to confirm it.","resolution":"1. Record where 1123 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FLOPPY_WRONG_CYLINDER.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1123 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Mismatch between the floppy disk sector ID field and the floppy disk controller track address.\n\nLookup forms: 1123, 0x463, error 1123, ERROR_FLOPPY_WRONG_CYLINDER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1123"]},{"id":598,"title":"ERROR_FLOPPY_UNKNOWN_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1124","0x464","error 1124","ERROR_FLOPPY_UNKNOWN_ERROR","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","floppy","unknown","the","disk","controller","reported","that","not","recognized","driver"],"errorCode":"1124","eventId":"","severity":"Low","summary":"The floppy disk controller reported an error that is not recognized by the floppy disk driver.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1124; use the surrounding log entries to confirm it.","resolution":"1. Record where 1124 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FLOPPY_UNKNOWN_ERROR.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1124 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The floppy disk controller reported an error that is not recognized by the floppy disk driver.\n\nLookup forms: 1124, 0x464, error 1124, ERROR_FLOPPY_UNKNOWN_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1124"]},{"id":599,"title":"ERROR_FLOPPY_BAD_REGISTERS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1125","0x465","error 1125","ERROR_FLOPPY_BAD_REGISTERS","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","floppy","bad","registers","the","disk","controller","returned","inconsistent","results","its"],"errorCode":"1125","eventId":"","severity":"Low","summary":"The floppy disk controller returned inconsistent results in its registers.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1125; use the surrounding log entries to confirm it.","resolution":"1. Record where 1125 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FLOPPY_BAD_REGISTERS.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1125 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The floppy disk controller returned inconsistent results in its registers.\n\nLookup forms: 1125, 0x465, error 1125, ERROR_FLOPPY_BAD_REGISTERS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1125"]},{"id":600,"title":"ERROR_DISK_RECALIBRATE_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1126","0x466","error 1126","ERROR_DISK_RECALIBRATE_FAILED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","disk","recalibrate","failed","while","accessing","the","hard","operation","even","after","retries"],"errorCode":"1126","eventId":"","severity":"High","summary":"While accessing the hard disk, a recalibrate operation failed, even after retries.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1126; use the surrounding log entries to confirm it.","resolution":"1. Record where 1126 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DISK_RECALIBRATE_FAILED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1126 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: While accessing the hard disk, a recalibrate operation failed, even after retries.\n\nLookup forms: 1126, 0x466, error 1126, ERROR_DISK_RECALIBRATE_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1126"]},{"id":601,"title":"ERROR_DISK_OPERATION_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1127","0x467","error 1127","ERROR_DISK_OPERATION_FAILED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","disk","operation","failed","while","accessing","the","hard","even","after","retries"],"errorCode":"1127","eventId":"","severity":"High","summary":"While accessing the hard disk, a disk operation failed even after retries.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1127; use the surrounding log entries to confirm it.","resolution":"1. Record where 1127 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DISK_OPERATION_FAILED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1127 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: While accessing the hard disk, a disk operation failed even after retries.\n\nLookup forms: 1127, 0x467, error 1127, ERROR_DISK_OPERATION_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1127"]},{"id":602,"title":"ERROR_DISK_RESET_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1128","0x468","error 1128","ERROR_DISK_RESET_FAILED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","disk","reset","failed","while","accessing","the","hard","controller","was","needed","but","even","that"],"errorCode":"1128","eventId":"","severity":"High","summary":"While accessing the hard disk, a disk controller reset was needed, but even that failed.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1128; use the surrounding log entries to confirm it.","resolution":"1. Record where 1128 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DISK_RESET_FAILED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1128 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: While accessing the hard disk, a disk controller reset was needed, but even that failed.\n\nLookup forms: 1128, 0x468, error 1128, ERROR_DISK_RESET_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1128"]},{"id":603,"title":"ERROR_EOM_OVERFLOW","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1129","0x469","error 1129","ERROR_EOM_OVERFLOW","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","eom","overflow","physical","end","tape","encountered","group","policy","could","not","reach","domain","controller"],"errorCode":"1129","eventId":"","severity":"Low","summary":"Physical end of tape encountered.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1129; use the surrounding log entries to confirm it.","resolution":"1. Record where 1129 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EOM_OVERFLOW.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1129 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Physical end of tape encountered.\n\nLookup forms: 1129, 0x469, error 1129, ERROR_EOM_OVERFLOW. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (microsoft_windows_error_code_master_list.txt): Category: GROUP POLICY\nDescription: Group Policy could not reach a domain controller.\n\nFixes:\n1. Review the GroupPolicy operational and System logs and note adjacent events.\n2. Verify domain DNS, time, secure channel, domain-controller discovery, SYSVOL access, DFSR, and permissions.\n3. Correct the directory, replication, or network issue and run gpupdate /force.\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf; microsoft_windows_error_code_master_list.txt","commands":["gpupdate /force"],"platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1129"]},{"id":604,"title":"ERROR_NOT_ENOUGH_SERVER_MEMORY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1130","0x46A","error 1130","ERROR_NOT_ENOUGH_SERVER_MEMORY","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","not","enough","server","memory","storage","available","process","this","command"],"errorCode":"1130","eventId":"","severity":"Low","summary":"Not enough server storage is available to process this command.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1130; use the surrounding log entries to confirm it.","resolution":"1. Record where 1130 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_ENOUGH_SERVER_MEMORY.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1130 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Not enough server storage is available to process this command.\n\nLookup forms: 1130, 0x46A, error 1130, ERROR_NOT_ENOUGH_SERVER_MEMORY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1130"]},{"id":605,"title":"ERROR_POSSIBLE_DEADLOCK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1131","0x46B","error 1131","ERROR_POSSIBLE_DEADLOCK","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","possible","deadlock","potential","condition","has","been","detected"],"errorCode":"1131","eventId":"","severity":"Low","summary":"A potential deadlock condition has been detected.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1131; use the surrounding log entries to confirm it.","resolution":"1. Record where 1131 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_POSSIBLE_DEADLOCK.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1131 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A potential deadlock condition has been detected.\n\nLookup forms: 1131, 0x46B, error 1131, ERROR_POSSIBLE_DEADLOCK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1131"]},{"id":606,"title":"ERROR_MAPPED_ALIGNMENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1132","0x46C","error 1132","ERROR_MAPPED_ALIGNMENT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","mapped","alignment","the","base","address","file","offset","specified","does","not","have","proper"],"errorCode":"1132","eventId":"","severity":"Low","summary":"The base address or the file offset specified does not have the proper alignment.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1132; use the surrounding log entries to confirm it.","resolution":"1. Record where 1132 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MAPPED_ALIGNMENT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1132 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The base address or the file offset specified does not have the proper alignment.\n\nLookup forms: 1132, 0x46C, error 1132, ERROR_MAPPED_ALIGNMENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1132"]},{"id":607,"title":"ERROR_SET_POWER_STATE_VETOED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1140","0x474","error 1140","ERROR_SET_POWER_STATE_VETOED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","set","power","state","vetoed","attempt","change","the","system","was","another","application","driver"],"errorCode":"1140","eventId":"","severity":"Low","summary":"An attempt to change the system power state was vetoed by another application or driver.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1140; use the surrounding log entries to confirm it.","resolution":"1. Record where 1140 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SET_POWER_STATE_VETOED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1140 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt to change the system power state was vetoed by another application or driver.\n\nLookup forms: 1140, 0x474, error 1140, ERROR_SET_POWER_STATE_VETOED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1140"]},{"id":608,"title":"ERROR_SET_POWER_STATE_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1141","0x475","error 1141","ERROR_SET_POWER_STATE_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","set","power","state","failed","the","system","bios","attempt","change"],"errorCode":"1141","eventId":"","severity":"High","summary":"The system BIOS failed an attempt to change the system power state.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1141; use the surrounding log entries to confirm it.","resolution":"1. Record where 1141 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SET_POWER_STATE_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1141 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system BIOS failed an attempt to change the system power state.\n\nLookup forms: 1141, 0x475, error 1141, ERROR_SET_POWER_STATE_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1141"]},{"id":609,"title":"ERROR_TOO_MANY_LINKS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1142","0x476","error 1142","ERROR_TOO_MANY_LINKS","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","too","many","links","attempt","was","made","create","more","file","than","the","system","supports"],"errorCode":"1142","eventId":"","severity":"Low","summary":"An attempt was made to create more links on a file than the file system supports.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1142; use the surrounding log entries to confirm it.","resolution":"1. Record where 1142 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TOO_MANY_LINKS.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1142 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt was made to create more links on a file than the file system supports.\n\nLookup forms: 1142, 0x476, error 1142, ERROR_TOO_MANY_LINKS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1142"]},{"id":610,"title":"ERROR_OLD_WIN_VERSION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1150","0x47E","error 1150","ERROR_OLD_WIN_VERSION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","old","win","version","the","specified","program","requires","newer","windows"],"errorCode":"1150","eventId":"","severity":"Low","summary":"The specified program requires a newer version of Windows.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1150; use the surrounding log entries to confirm it.","resolution":"1. Record where 1150 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_OLD_WIN_VERSION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1150 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified program requires a newer version of Windows.\n\nLookup forms: 1150, 0x47E, error 1150, ERROR_OLD_WIN_VERSION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1150"]},{"id":611,"title":"ERROR_APP_WRONG_OS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1151","0x47F","error 1151","ERROR_APP_WRONG_OS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","app","wrong","the","specified","program","not","windows","dos"],"errorCode":"1151","eventId":"","severity":"Low","summary":"The specified program is not a Windows or MS-DOS program.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1151; use the surrounding log entries to confirm it.","resolution":"1. Record where 1151 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_APP_WRONG_OS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1151 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified program is not a Windows or MS-DOS program.\n\nLookup forms: 1151, 0x47F, error 1151, ERROR_APP_WRONG_OS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1151"]},{"id":612,"title":"ERROR_SINGLE_INSTANCE_APP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1152","0x480","error 1152","ERROR_SINGLE_INSTANCE_APP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","single","instance","app","cannot","start","more","than","one","the","specified","program"],"errorCode":"1152","eventId":"","severity":"Medium","summary":"Cannot start more than one instance of the specified program.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1152; use the surrounding log entries to confirm it.","resolution":"1. Record where 1152 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SINGLE_INSTANCE_APP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1152 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot start more than one instance of the specified program.\n\nLookup forms: 1152, 0x480, error 1152, ERROR_SINGLE_INSTANCE_APP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1152"]},{"id":613,"title":"ERROR_RMODE_APP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1153","0x481","error 1153","ERROR_RMODE_APP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","rmode","app","the","specified","program","was","written","for","earlier","version","windows"],"errorCode":"1153","eventId":"","severity":"Low","summary":"The specified program was written for an earlier version of Windows.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1153; use the surrounding log entries to confirm it.","resolution":"1. Record where 1153 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RMODE_APP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1153 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified program was written for an earlier version of Windows.\n\nLookup forms: 1153, 0x481, error 1153, ERROR_RMODE_APP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1153"]},{"id":614,"title":"ERROR_INVALID_DLL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1154","0x482","error 1154","ERROR_INVALID_DLL","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","invalid","dll","one","the","library","files","needed","run","this","application","damaged"],"errorCode":"1154","eventId":"","severity":"Low","summary":"One of the library files needed to run this application is damaged.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1154; use the surrounding log entries to confirm it.","resolution":"1. Record where 1154 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_DLL.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1154 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: One of the library files needed to run this application is damaged.\n\nLookup forms: 1154, 0x482, error 1154, ERROR_INVALID_DLL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1154"]},{"id":615,"title":"ERROR_NO_ASSOCIATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1155","0x483","error 1155","ERROR_NO_ASSOCIATION","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","association","application","associated","with","the","specified","file","for","this","operation"],"errorCode":"1155","eventId":"","severity":"Low","summary":"No application is associated with the specified file for this operation.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1155; use the surrounding log entries to confirm it.","resolution":"1. Record where 1155 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_ASSOCIATION.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1155 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No application is associated with the specified file for this operation.\n\nLookup forms: 1155, 0x483, error 1155, ERROR_NO_ASSOCIATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1155"]},{"id":616,"title":"ERROR_DDE_FAIL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1156","0x484","error 1156","ERROR_DDE_FAIL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dde","fail","occurred","sending","the","command","application"],"errorCode":"1156","eventId":"","severity":"Low","summary":"An error occurred in sending the command to the application.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1156; use the surrounding log entries to confirm it.","resolution":"1. Record where 1156 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DDE_FAIL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1156 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An error occurred in sending the command to the application.\n\nLookup forms: 1156, 0x484, error 1156, ERROR_DDE_FAIL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1156"]},{"id":617,"title":"ERROR_DLL_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1157","0x485","error 1157","ERROR_DLL_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","dll","not","found","one","the","library","files","needed","run","this","application","cannot"],"errorCode":"1157","eventId":"","severity":"Medium","summary":"One of the library files needed to run this application cannot be found.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1157; use the surrounding log entries to confirm it.","resolution":"1. Record where 1157 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DLL_NOT_FOUND.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1157 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: One of the library files needed to run this application cannot be found.\n\nLookup forms: 1157, 0x485, error 1157, ERROR_DLL_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1157"]},{"id":618,"title":"ERROR_NO_MORE_USER_HANDLES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1158","0x486","error 1158","ERROR_NO_MORE_USER_HANDLES","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","more","user","handles","the","current","process","has","used","all","its","system","allowance","for","window","manager","objects"],"errorCode":"1158","eventId":"","severity":"Low","summary":"The current process has used all of its system allowance of handles for Window Manager objects.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1158; use the surrounding log entries to confirm it.","resolution":"1. Record where 1158 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_MORE_USER_HANDLES.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1158 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The current process has used all of its system allowance of handles for Window Manager objects.\n\nLookup forms: 1158, 0x486, error 1158, ERROR_NO_MORE_USER_HANDLES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1158"]},{"id":619,"title":"ERROR_MESSAGE_SYNC_ONLY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1159","0x487","error 1159","ERROR_MESSAGE_SYNC_ONLY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","message","sync","only","the","can","used","with","synchronous","operations"],"errorCode":"1159","eventId":"","severity":"Low","summary":"The message can be used only with synchronous operations.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1159; use the surrounding log entries to confirm it.","resolution":"1. Record where 1159 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MESSAGE_SYNC_ONLY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1159 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The message can be used only with synchronous operations.\n\nLookup forms: 1159, 0x487, error 1159, ERROR_MESSAGE_SYNC_ONLY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1159"]},{"id":620,"title":"ERROR_SOURCE_ELEMENT_EMPTY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1160","0x488","error 1160","ERROR_SOURCE_ELEMENT_EMPTY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","source","element","empty","the","indicated","has","media"],"errorCode":"1160","eventId":"","severity":"Low","summary":"The indicated source element has no media.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1160; use the surrounding log entries to confirm it.","resolution":"1. Record where 1160 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SOURCE_ELEMENT_EMPTY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1160 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The indicated source element has no media.\n\nLookup forms: 1160, 0x488, error 1160, ERROR_SOURCE_ELEMENT_EMPTY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1160"]},{"id":621,"title":"ERROR_DESTINATION_ELEMENT_FULL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1161","0x489","error 1161","ERROR_DESTINATION_ELEMENT_FULL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","destination","element","full","the","indicated","already","contains","media"],"errorCode":"1161","eventId":"","severity":"Low","summary":"The indicated destination element already contains media.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1161; use the surrounding log entries to confirm it.","resolution":"1. Record where 1161 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DESTINATION_ELEMENT_FULL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1161 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The indicated destination element already contains media.\n\nLookup forms: 1161, 0x489, error 1161, ERROR_DESTINATION_ELEMENT_FULL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1161"]},{"id":622,"title":"ERROR_ILLEGAL_ELEMENT_ADDRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1162","0x48A","error 1162","ERROR_ILLEGAL_ELEMENT_ADDRESS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","illegal","element","address","the","indicated","does","not","exist"],"errorCode":"1162","eventId":"","severity":"Low","summary":"The indicated element does not exist.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1162; use the surrounding log entries to confirm it.","resolution":"1. Record where 1162 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ILLEGAL_ELEMENT_ADDRESS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1162 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The indicated element does not exist.\n\nLookup forms: 1162, 0x48A, error 1162, ERROR_ILLEGAL_ELEMENT_ADDRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1162"]},{"id":623,"title":"ERROR_MAGAZINE_NOT_PRESENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1163","0x48B","error 1163","ERROR_MAGAZINE_NOT_PRESENT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","magazine","not","present","the","indicated","element","part","that"],"errorCode":"1163","eventId":"","severity":"Low","summary":"The indicated element is part of a magazine that is not present.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1163; use the surrounding log entries to confirm it.","resolution":"1. Record where 1163 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MAGAZINE_NOT_PRESENT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1163 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The indicated element is part of a magazine that is not present.\n\nLookup forms: 1163, 0x48B, error 1163, ERROR_MAGAZINE_NOT_PRESENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1163"]},{"id":624,"title":"ERROR_DEVICE_REINITIALIZATION_NEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1164","0x48C","error 1164","ERROR_DEVICE_REINITIALIZATION_NEEDED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","device","reinitialization","needed","the","indicated","requires","due","hardware","errors"],"errorCode":"1164","eventId":"","severity":"Low","summary":"The indicated device requires reinitialization due to hardware errors.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1164; use the surrounding log entries to confirm it.","resolution":"1. Record where 1164 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEVICE_REINITIALIZATION_NEEDED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1164 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The indicated device requires reinitialization due to hardware errors.\n\nLookup forms: 1164, 0x48C, error 1164, ERROR_DEVICE_REINITIALIZATION_NEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1164"]},{"id":625,"title":"ERROR_DEVICE_REQUIRES_CLEANING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1165","0x48D","error 1165","ERROR_DEVICE_REQUIRES_CLEANING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","device","requires","cleaning","the","has","indicated","that","required","before","further","operations","are","attempted"],"errorCode":"1165","eventId":"","severity":"Low","summary":"The device has indicated that cleaning is required before further operations are attempted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1165; use the surrounding log entries to confirm it.","resolution":"1. Record where 1165 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEVICE_REQUIRES_CLEANING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1165 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The device has indicated that cleaning is required before further operations are attempted.\n\nLookup forms: 1165, 0x48D, error 1165, ERROR_DEVICE_REQUIRES_CLEANING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1165"]},{"id":626,"title":"ERROR_DEVICE_DOOR_OPEN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1166","0x48E","error 1166","ERROR_DEVICE_DOOR_OPEN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","device","door","open","the","has","indicated","that","its"],"errorCode":"1166","eventId":"","severity":"Low","summary":"The device has indicated that its door is open.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1166; use the surrounding log entries to confirm it.","resolution":"1. Record where 1166 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEVICE_DOOR_OPEN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1166 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The device has indicated that its door is open.\n\nLookup forms: 1166, 0x48E, error 1166, ERROR_DEVICE_DOOR_OPEN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1166"]},{"id":627,"title":"ERROR_DEVICE_NOT_CONNECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1167","0x48F","error 1167","ERROR_DEVICE_NOT_CONNECTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","device","not","connected","the"],"errorCode":"1167","eventId":"","severity":"Low","summary":"The device is not connected.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1167; use the surrounding log entries to confirm it.","resolution":"1. Record where 1167 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEVICE_NOT_CONNECTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1167 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The device is not connected.\n\nLookup forms: 1167, 0x48F, error 1167, ERROR_DEVICE_NOT_CONNECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1167"]},{"id":628,"title":"ERROR_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1168","0x490","error 1168","ERROR_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","not","found","element"],"errorCode":"1168","eventId":"","severity":"Medium","summary":"Element not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1168; use the surrounding log entries to confirm it.","resolution":"1. Record where 1168 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1168 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Element not found.\n\nLookup forms: 1168, 0x490, error 1168, ERROR_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1168"]},{"id":629,"title":"ERROR_NO_MATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1169","0x491","error 1169","ERROR_NO_MATCH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","match","there","was","for","the","specified","key","index"],"errorCode":"1169","eventId":"","severity":"Low","summary":"There was no match for the specified key in the index.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1169; use the surrounding log entries to confirm it.","resolution":"1. Record where 1169 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_MATCH.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1169 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There was no match for the specified key in the index.\n\nLookup forms: 1169, 0x491, error 1169, ERROR_NO_MATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1169"]},{"id":630,"title":"ERROR_SET_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1170","0x492","error 1170","ERROR_SET_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","set","not","found","the","property","specified","does","exist","object"],"errorCode":"1170","eventId":"","severity":"Low","summary":"The property set specified does not exist on the object.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1170; use the surrounding log entries to confirm it.","resolution":"1. Record where 1170 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SET_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1170 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The property set specified does not exist on the object.\n\nLookup forms: 1170, 0x492, error 1170, ERROR_SET_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1170"]},{"id":631,"title":"ERROR_POINT_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1171","0x493","error 1171","ERROR_POINT_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","point","not","found","the","passed","getmousemovepoints","buffer"],"errorCode":"1171","eventId":"","severity":"Low","summary":"The point passed to GetMouseMovePoints is not in the buffer.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1171; use the surrounding log entries to confirm it.","resolution":"1. Record where 1171 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_POINT_NOT_FOUND.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1171 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The point passed to GetMouseMovePoints is not in the buffer.\n\nLookup forms: 1171, 0x493, error 1171, ERROR_POINT_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The point passed to GetMouseMovePointsEx is not in the buffer.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1171"]},{"id":632,"title":"ERROR_NO_TRACKING_SERVICE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1172","0x494","error 1172","ERROR_NO_TRACKING_SERVICE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","tracking","service","the","workstation","not","running"],"errorCode":"1172","eventId":"","severity":"Low","summary":"The tracking (workstation) service is not running.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1172; use the surrounding log entries to confirm it.","resolution":"1. Record where 1172 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_TRACKING_SERVICE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1172 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The tracking (workstation) service is not running.\n\nLookup forms: 1172, 0x494, error 1172, ERROR_NO_TRACKING_SERVICE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1172"]},{"id":633,"title":"ERROR_NO_VOLUME_ID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1173","0x495","error 1173","ERROR_NO_VOLUME_ID","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","volume","the","could","not","found"],"errorCode":"1173","eventId":"","severity":"Low","summary":"The Volume ID could not be found.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1173; use the surrounding log entries to confirm it.","resolution":"1. Record where 1173 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_VOLUME_ID.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1173 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Volume ID could not be found.\n\nLookup forms: 1173, 0x495, error 1173, ERROR_NO_VOLUME_ID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1173"]},{"id":634,"title":"ERROR_UNABLE_TO_REMOVE_REPLACED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1175","0x497","error 1175","ERROR_UNABLE_TO_REMOVE_REPLACED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","unable","remove","replaced","the","file"],"errorCode":"1175","eventId":"","severity":"Medium","summary":"Unable to remove the file to be replaced.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1175; use the surrounding log entries to confirm it.","resolution":"1. Record where 1175 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNABLE_TO_REMOVE_REPLACED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1175 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to remove the file to be replaced.\n\nLookup forms: 1175, 0x497, error 1175, ERROR_UNABLE_TO_REMOVE_REPLACED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1175"]},{"id":635,"title":"ERROR_UNABLE_TO_MOVE_REPLACEMENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1176","0x498","error 1176","ERROR_UNABLE_TO_MOVE_REPLACEMENT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","unable","move","replacement","the","file","replaced","has","retained","its","original","name"],"errorCode":"1176","eventId":"","severity":"Medium","summary":"Unable to move the replacement file to the file to be replaced. The file to be replaced has retained its original name.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1176; use the surrounding log entries to confirm it.","resolution":"1. Record where 1176 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNABLE_TO_MOVE_REPLACEMENT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1176 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to move the replacement file to the file to be replaced. The file to be replaced has retained its original name.\n\nLookup forms: 1176, 0x498, error 1176, ERROR_UNABLE_TO_MOVE_REPLACEMENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1176"]},{"id":636,"title":"ERROR_UNABLE_TO_MOVE_REPLACEMENT_2","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1177","0x499","error 1177","ERROR_UNABLE_TO_MOVE_REPLACEMENT_2","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","unable","move","replacement","the","file","replaced","has","been","renamed","using","backup","name"],"errorCode":"1177","eventId":"","severity":"Medium","summary":"Unable to move the replacement file to the file to be replaced. The file to be replaced has been renamed using the backup name.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1177; use the surrounding log entries to confirm it.","resolution":"1. Record where 1177 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNABLE_TO_MOVE_REPLACEMENT_2.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1177 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to move the replacement file to the file to be replaced. The file to be replaced has been renamed using the backup name.\n\nLookup forms: 1177, 0x499, error 1177, ERROR_UNABLE_TO_MOVE_REPLACEMENT_2. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1177"]},{"id":637,"title":"ERROR_JOURNAL_DELETE_IN_PROGRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1178","0x49A","error 1178","ERROR_JOURNAL_DELETE_IN_PROGRESS","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","journal","delete","progress","the","volume","change","being","deleted"],"errorCode":"1178","eventId":"","severity":"Low","summary":"The volume change journal is being deleted.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1178; use the surrounding log entries to confirm it.","resolution":"1. Record where 1178 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_JOURNAL_DELETE_IN_PROGRESS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1178 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The volume change journal is being deleted.\n\nLookup forms: 1178, 0x49A, error 1178, ERROR_JOURNAL_DELETE_IN_PROGRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1178"]},{"id":638,"title":"ERROR_JOURNAL_NOT_ACTIVE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1179","0x49B","error 1179","ERROR_JOURNAL_NOT_ACTIVE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","journal","not","active","the","volume","change"],"errorCode":"1179","eventId":"","severity":"Low","summary":"The volume change journal is not active.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1179; use the surrounding log entries to confirm it.","resolution":"1. Record where 1179 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_JOURNAL_NOT_ACTIVE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1179 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The volume change journal is not active.\n\nLookup forms: 1179, 0x49B, error 1179, ERROR_JOURNAL_NOT_ACTIVE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1179"]},{"id":639,"title":"ERROR_POTENTIAL_FILE_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1180","0x49C","error 1180","ERROR_POTENTIAL_FILE_FOUND","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","potential","file","found","was","but","may","not","the","correct"],"errorCode":"1180","eventId":"","severity":"Low","summary":"A file was found, but it may not be the correct file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1180; use the surrounding log entries to confirm it.","resolution":"1. Record where 1180 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_POTENTIAL_FILE_FOUND.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1180 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A file was found, but it may not be the correct file.\n\nLookup forms: 1180, 0x49C, error 1180, ERROR_POTENTIAL_FILE_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1180"]},{"id":640,"title":"ERROR_JOURNAL_ENTRY_DELETED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1181","0x49D","error 1181","ERROR_JOURNAL_ENTRY_DELETED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","journal","entry","deleted","the","has","been","from"],"errorCode":"1181","eventId":"","severity":"Low","summary":"The journal entry has been deleted from the journal.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1181; use the surrounding log entries to confirm it.","resolution":"1. Record where 1181 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_JOURNAL_ENTRY_DELETED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1181 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The journal entry has been deleted from the journal.\n\nLookup forms: 1181, 0x49D, error 1181, ERROR_JOURNAL_ENTRY_DELETED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1181"]},{"id":641,"title":"ERROR_SHUTDOWN_IS_SCHEDULED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1190","0x4A6","error 1190","ERROR_SHUTDOWN_IS_SCHEDULED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","shutdown","scheduled","system","has","already","been"],"errorCode":"1190","eventId":"","severity":"Critical","summary":"A system shutdown has already been scheduled.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1190; use the surrounding log entries to confirm it.","resolution":"1. Record where 1190 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SHUTDOWN_IS_SCHEDULED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1190 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A system shutdown has already been scheduled.\n\nLookup forms: 1190, 0x4A6, error 1190, ERROR_SHUTDOWN_IS_SCHEDULED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1190"]},{"id":642,"title":"ERROR_SHUTDOWN_USERS_LOGGED_ON","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1191","0x4A7","error 1191","ERROR_SHUTDOWN_USERS_LOGGED_ON","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","shutdown","users","logged","the","system","cannot","initiated","because","there","are","other","computer"],"errorCode":"1191","eventId":"","severity":"Critical","summary":"The system shutdown cannot be initiated because there are other users logged on to the computer.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1191; use the surrounding log entries to confirm it.","resolution":"1. Record where 1191 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SHUTDOWN_USERS_LOGGED_ON.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1191 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system shutdown cannot be initiated because there are other users logged on to the computer.\n\nLookup forms: 1191, 0x4A7, error 1191, ERROR_SHUTDOWN_USERS_LOGGED_ON. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1191"]},{"id":643,"title":"ERROR_BAD_DEVICE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1200","0x4B0","error 1200","ERROR_BAD_DEVICE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","bad","device","the","specified","name","invalid"],"errorCode":"1200","eventId":"","severity":"Medium","summary":"The specified device name is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1200; use the surrounding log entries to confirm it.","resolution":"1. Record where 1200 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_DEVICE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1200 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified device name is invalid.\n\nLookup forms: 1200, 0x4B0, error 1200, ERROR_BAD_DEVICE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1200"]},{"id":644,"title":"ERROR_CONNECTION_UNAVAIL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1201","0x4B1","error 1201","ERROR_CONNECTION_UNAVAIL","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","connection","unavail","the","device","not","currently","connected","but","remembered"],"errorCode":"1201","eventId":"","severity":"High","summary":"The device is not currently connected but it is a remembered connection.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1201; use the surrounding log entries to confirm it.","resolution":"1. Record where 1201 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CONNECTION_UNAVAIL.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1201 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The device is not currently connected but it is a remembered connection.\n\nLookup forms: 1201, 0x4B1, error 1201, ERROR_CONNECTION_UNAVAIL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1201"]},{"id":645,"title":"ERROR_DEVICE_ALREADY_REMEMBERED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1202","0x4B2","error 1202","ERROR_DEVICE_ALREADY_REMEMBERED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","device","already","remembered","the","local","name","has","connection","another","network","resource"],"errorCode":"1202","eventId":"","severity":"High","summary":"The local device name has a remembered connection to another network resource.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1202; use the surrounding log entries to confirm it.","resolution":"1. Record where 1202 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEVICE_ALREADY_REMEMBERED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1202 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The local device name has a remembered connection to another network resource.\n\nLookup forms: 1202, 0x4B2, error 1202, ERROR_DEVICE_ALREADY_REMEMBERED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1202"]},{"id":646,"title":"ERROR_NO_NET_OR_BAD_PATH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1203","0x4B3","error 1203","ERROR_NO_NET_OR_BAD_PATH","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","net","bad","path","the","network","was","either","typed","incorrectly","does","not","exist","provider","currently","available","please","try","retyping","contact","your","administrator"],"errorCode":"1203","eventId":"","severity":"High","summary":"The network path was either typed incorrectly, does not exist, or the network provider is not currently available. Please try retyping the path or contact your network administrator.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1203; use the surrounding log entries to confirm it.","resolution":"1. Record where 1203 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_NET_OR_BAD_PATH.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1203 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The network path was either typed incorrectly, does not exist, or the network provider is not currently available. Please try retyping the path or contact your network administrator.\n\nLookup forms: 1203, 0x4B3, error 1203, ERROR_NO_NET_OR_BAD_PATH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): No network provider accepted the given network path.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1203"]},{"id":647,"title":"ERROR_BAD_PROVIDER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1204","0x4B4","error 1204","ERROR_BAD_PROVIDER","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","bad","provider","the","specified","network","name","invalid"],"errorCode":"1204","eventId":"","severity":"High","summary":"The specified network provider name is invalid.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1204; use the surrounding log entries to confirm it.","resolution":"1. Record where 1204 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_PROVIDER.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1204 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified network provider name is invalid.\n\nLookup forms: 1204, 0x4B4, error 1204, ERROR_BAD_PROVIDER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1204"]},{"id":648,"title":"ERROR_CANNOT_OPEN_PROFILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1205","0x4B5","error 1205","ERROR_CANNOT_OPEN_PROFILE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","cannot","open","profile","unable","the","network","connection"],"errorCode":"1205","eventId":"","severity":"High","summary":"Unable to open the network connection profile.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1205; use the surrounding log entries to confirm it.","resolution":"1. Record where 1205 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANNOT_OPEN_PROFILE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1205 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to open the network connection profile.\n\nLookup forms: 1205, 0x4B5, error 1205, ERROR_CANNOT_OPEN_PROFILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1205"]},{"id":649,"title":"ERROR_BAD_PROFILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1206","0x4B6","error 1206","ERROR_BAD_PROFILE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","bad","profile","the","network","connection","corrupted"],"errorCode":"1206","eventId":"","severity":"Critical","summary":"The network connection profile is corrupted.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1206; use the surrounding log entries to confirm it.","resolution":"1. Record where 1206 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_PROFILE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1206 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The network connection profile is corrupted.\n\nLookup forms: 1206, 0x4B6, error 1206, ERROR_BAD_PROFILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1206"]},{"id":650,"title":"ERROR_NOT_CONTAINER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1207","0x4B7","error 1207","ERROR_NOT_CONTAINER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","not","container","cannot","enumerate","noncontainer"],"errorCode":"1207","eventId":"","severity":"Medium","summary":"Cannot enumerate a noncontainer.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1207; use the surrounding log entries to confirm it.","resolution":"1. Record where 1207 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_CONTAINER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1207 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot enumerate a noncontainer.\n\nLookup forms: 1207, 0x4B7, error 1207, ERROR_NOT_CONTAINER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1207"]},{"id":651,"title":"ERROR_EXTENDED_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1208","0x4B8","error 1208","ERROR_EXTENDED_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","extended","has","occurred"],"errorCode":"1208","eventId":"","severity":"Low","summary":"An extended error has occurred.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1208; use the surrounding log entries to confirm it.","resolution":"1. Record where 1208 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EXTENDED_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1208 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An extended error has occurred.\n\nLookup forms: 1208, 0x4B8, error 1208, ERROR_EXTENDED_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1208"]},{"id":652,"title":"ERROR_INVALID_GROUPNAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1209","0x4B9","error 1209","ERROR_INVALID_GROUPNAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","groupname","the","format","specified","group","name"],"errorCode":"1209","eventId":"","severity":"Medium","summary":"The format of the specified group name is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1209; use the surrounding log entries to confirm it.","resolution":"1. Record where 1209 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_GROUPNAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1209 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The format of the specified group name is invalid.\n\nLookup forms: 1209, 0x4B9, error 1209, ERROR_INVALID_GROUPNAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1209"]},{"id":653,"title":"ERROR_INVALID_COMPUTERNAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1210","0x4BA","error 1210","ERROR_INVALID_COMPUTERNAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","computername","the","format","specified","computer","name"],"errorCode":"1210","eventId":"","severity":"Medium","summary":"The format of the specified computer name is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1210; use the surrounding log entries to confirm it.","resolution":"1. Record where 1210 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_COMPUTERNAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1210 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The format of the specified computer name is invalid.\n\nLookup forms: 1210, 0x4BA, error 1210, ERROR_INVALID_COMPUTERNAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1210"]},{"id":654,"title":"ERROR_INVALID_EVENTNAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1211","0x4BB","error 1211","ERROR_INVALID_EVENTNAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","eventname","the","format","specified","event","name"],"errorCode":"1211","eventId":"","severity":"Medium","summary":"The format of the specified event name is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1211; use the surrounding log entries to confirm it.","resolution":"1. Record where 1211 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_EVENTNAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1211 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The format of the specified event name is invalid.\n\nLookup forms: 1211, 0x4BB, error 1211, ERROR_INVALID_EVENTNAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1211"]},{"id":655,"title":"ERROR_INVALID_DOMAINNAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1212","0x4BC","error 1212","ERROR_INVALID_DOMAINNAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","domainname","the","format","specified","domain","name"],"errorCode":"1212","eventId":"","severity":"Medium","summary":"The format of the specified domain name is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1212; use the surrounding log entries to confirm it.","resolution":"1. Record where 1212 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_DOMAINNAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1212 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The format of the specified domain name is invalid.\n\nLookup forms: 1212, 0x4BC, error 1212, ERROR_INVALID_DOMAINNAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1212"]},{"id":656,"title":"ERROR_INVALID_SERVICENAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1213","0x4BD","error 1213","ERROR_INVALID_SERVICENAME","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","invalid","servicename","the","format","specified","service","name"],"errorCode":"1213","eventId":"","severity":"Medium","summary":"The format of the specified service name is invalid.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1213; use the surrounding log entries to confirm it.","resolution":"1. Record where 1213 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_SERVICENAME.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1213 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The format of the specified service name is invalid.\n\nLookup forms: 1213, 0x4BD, error 1213, ERROR_INVALID_SERVICENAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1213"]},{"id":657,"title":"ERROR_INVALID_NETNAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1214","0x4BE","error 1214","ERROR_INVALID_NETNAME","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","invalid","netname","the","format","specified","network","name"],"errorCode":"1214","eventId":"","severity":"High","summary":"The format of the specified network name is invalid.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1214; use the surrounding log entries to confirm it.","resolution":"1. Record where 1214 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_NETNAME.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1214 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The format of the specified network name is invalid.\n\nLookup forms: 1214, 0x4BE, error 1214, ERROR_INVALID_NETNAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1214"]},{"id":658,"title":"ERROR_INVALID_SHARENAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1215","0x4BF","error 1215","ERROR_INVALID_SHARENAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","sharename","the","format","specified","share","name"],"errorCode":"1215","eventId":"","severity":"Medium","summary":"The format of the specified share name is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1215; use the surrounding log entries to confirm it.","resolution":"1. Record where 1215 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_SHARENAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1215 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The format of the specified share name is invalid.\n\nLookup forms: 1215, 0x4BF, error 1215, ERROR_INVALID_SHARENAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1215"]},{"id":659,"title":"ERROR_INVALID_PASSWORDNAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1216","0x4C0","error 1216","ERROR_INVALID_PASSWORDNAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","passwordname","the","format","specified","password"],"errorCode":"1216","eventId":"","severity":"Medium","summary":"The format of the specified password is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1216; use the surrounding log entries to confirm it.","resolution":"1. Record where 1216 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_PASSWORDNAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1216 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The format of the specified password is invalid.\n\nLookup forms: 1216, 0x4C0, error 1216, ERROR_INVALID_PASSWORDNAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1216"]},{"id":660,"title":"ERROR_INVALID_MESSAGENAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1217","0x4C1","error 1217","ERROR_INVALID_MESSAGENAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","messagename","the","format","specified","message","name"],"errorCode":"1217","eventId":"","severity":"Medium","summary":"The format of the specified message name is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1217; use the surrounding log entries to confirm it.","resolution":"1. Record where 1217 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_MESSAGENAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1217 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The format of the specified message name is invalid.\n\nLookup forms: 1217, 0x4C1, error 1217, ERROR_INVALID_MESSAGENAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1217"]},{"id":661,"title":"ERROR_INVALID_MESSAGEDEST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1218","0x4C2","error 1218","ERROR_INVALID_MESSAGEDEST","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","messagedest","the","format","specified","message","destination"],"errorCode":"1218","eventId":"","severity":"Medium","summary":"The format of the specified message destination is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1218; use the surrounding log entries to confirm it.","resolution":"1. Record where 1218 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_MESSAGEDEST.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1218 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The format of the specified message destination is invalid.\n\nLookup forms: 1218, 0x4C2, error 1218, ERROR_INVALID_MESSAGEDEST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1218"]},{"id":662,"title":"ERROR_SESSION_CREDENTIAL_CONFLICT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1219","0x4C3","error 1219","ERROR_SESSION_CREDENTIAL_CONFLICT","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","session","credential","conflict","multiple","connections","server","shared","resource","the","same","user","using","more","than","one","name","are","not","allowed","disconnect","all","previous","and","try"],"errorCode":"1219","eventId":"","severity":"High","summary":"Multiple connections to a server or shared resource by the same user, using more than one user name, are not allowed. Disconnect all previous connections to the server or shared resource and try again.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1219; use the surrounding log entries to confirm it.","resolution":"1. Record where 1219 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SESSION_CREDENTIAL_CONFLICT.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1219 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Multiple connections to a server or shared resource by the same user, using more than one user name, are not allowed. Disconnect all previous connections to the server or shared resource and try again.\n\nLookup forms: 1219, 0x4C3, error 1219, ERROR_SESSION_CREDENTIAL_CONFLICT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1219"]},{"id":663,"title":"ERROR_REMOTE_SESSION_LIMIT_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1220","0x4C4","error 1220","ERROR_REMOTE_SESSION_LIMIT_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","remote","session","limit","exceeded","attempt","was","made","establish","network","server","but","there","are","already","too","many","sessions","established","that"],"errorCode":"1220","eventId":"","severity":"High","summary":"An attempt was made to establish a session to a network server, but there are already too many sessions established to that server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1220; use the surrounding log entries to confirm it.","resolution":"1. Record where 1220 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REMOTE_SESSION_LIMIT_EXCEEDED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1220 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt was made to establish a session to a network server, but there are already too many sessions established to that server.\n\nLookup forms: 1220, 0x4C4, error 1220, ERROR_REMOTE_SESSION_LIMIT_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1220"]},{"id":664,"title":"ERROR_DUP_DOMAINNAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1221","0x4C5","error 1221","ERROR_DUP_DOMAINNAME","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","dup","domainname","the","workgroup","domain","name","already","use","another","computer","network"],"errorCode":"1221","eventId":"","severity":"High","summary":"The workgroup or domain name is already in use by another computer on the network.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1221; use the surrounding log entries to confirm it.","resolution":"1. Record where 1221 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DUP_DOMAINNAME.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1221 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The workgroup or domain name is already in use by another computer on the network.\n\nLookup forms: 1221, 0x4C5, error 1221, ERROR_DUP_DOMAINNAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1221"]},{"id":665,"title":"ERROR_NO_NETWORK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1222","0x4C6","error 1222","ERROR_NO_NETWORK","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","network","the","not","present","started"],"errorCode":"1222","eventId":"","severity":"High","summary":"The network is not present or not started.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1222; use the surrounding log entries to confirm it.","resolution":"1. Record where 1222 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_NETWORK.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1222 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The network is not present or not started.\n\nLookup forms: 1222, 0x4C6, error 1222, ERROR_NO_NETWORK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1222"]},{"id":666,"title":"ERROR_CANCELLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1223","0x4C7","error 1223","ERROR_CANCELLED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cancelled","the","operation","was","canceled","user"],"errorCode":"1223","eventId":"","severity":"Low","summary":"The operation was canceled by the user.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1223; use the surrounding log entries to confirm it.","resolution":"1. Record where 1223 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANCELLED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1223 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation was canceled by the user.\n\nLookup forms: 1223, 0x4C7, error 1223, ERROR_CANCELLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1223"]},{"id":667,"title":"ERROR_USER_MAPPED_FILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1224","0x4C8","error 1224","ERROR_USER_MAPPED_FILE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","user","mapped","file","the","requested","operation","cannot","performed","with","section","open"],"errorCode":"1224","eventId":"","severity":"Medium","summary":"The requested operation cannot be performed on a file with a user-mapped section open.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1224; use the surrounding log entries to confirm it.","resolution":"1. Record where 1224 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_USER_MAPPED_FILE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1224 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested operation cannot be performed on a file with a user-mapped section open.\n\nLookup forms: 1224, 0x4C8, error 1224, ERROR_USER_MAPPED_FILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1224"]},{"id":668,"title":"ERROR_CONNECTION_REFUSED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1225","0x4C9","error 1225","ERROR_CONNECTION_REFUSED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","connection","refused","the","remote","computer","network"],"errorCode":"1225","eventId":"","severity":"High","summary":"The remote computer refused the network connection.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1225; use the surrounding log entries to confirm it.","resolution":"1. Record where 1225 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CONNECTION_REFUSED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1225 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The remote computer refused the network connection.\n\nLookup forms: 1225, 0x4C9, error 1225, ERROR_CONNECTION_REFUSED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The remote system refused the network connection.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1225"]},{"id":669,"title":"ERROR_GRACEFUL_DISCONNECT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1226","0x4CA","error 1226","ERROR_GRACEFUL_DISCONNECT","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","graceful","disconnect","the","network","connection","was","gracefully","closed"],"errorCode":"1226","eventId":"","severity":"High","summary":"The network connection was gracefully closed.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1226; use the surrounding log entries to confirm it.","resolution":"1. Record where 1226 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_GRACEFUL_DISCONNECT.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1226 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The network connection was gracefully closed.\n\nLookup forms: 1226, 0x4CA, error 1226, ERROR_GRACEFUL_DISCONNECT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1226"]},{"id":670,"title":"ERROR_ADDRESS_ALREADY_ASSOCIATED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1227","0x4CB","error 1227","ERROR_ADDRESS_ALREADY_ASSOCIATED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","address","already","associated","the","network","transport","endpoint","has","with"],"errorCode":"1227","eventId":"","severity":"High","summary":"The network transport endpoint already has an address associated with it.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1227; use the surrounding log entries to confirm it.","resolution":"1. Record where 1227 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ADDRESS_ALREADY_ASSOCIATED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1227 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The network transport endpoint already has an address associated with it.\n\nLookup forms: 1227, 0x4CB, error 1227, ERROR_ADDRESS_ALREADY_ASSOCIATED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1227"]},{"id":671,"title":"ERROR_ADDRESS_NOT_ASSOCIATED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1228","0x4CC","error 1228","ERROR_ADDRESS_NOT_ASSOCIATED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","address","not","associated","has","yet","been","with","the","network","endpoint"],"errorCode":"1228","eventId":"","severity":"High","summary":"An address has not yet been associated with the network endpoint.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1228; use the surrounding log entries to confirm it.","resolution":"1. Record where 1228 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ADDRESS_NOT_ASSOCIATED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1228 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An address has not yet been associated with the network endpoint.\n\nLookup forms: 1228, 0x4CC, error 1228, ERROR_ADDRESS_NOT_ASSOCIATED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1228"]},{"id":672,"title":"ERROR_CONNECTION_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1229","0x4CD","error 1229","ERROR_CONNECTION_INVALID","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","connection","invalid","operation","was","attempted","nonexistent","network"],"errorCode":"1229","eventId":"","severity":"High","summary":"An operation was attempted on a nonexistent network connection.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1229; use the surrounding log entries to confirm it.","resolution":"1. Record where 1229 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CONNECTION_INVALID.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1229 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An operation was attempted on a nonexistent network connection.\n\nLookup forms: 1229, 0x4CD, error 1229, ERROR_CONNECTION_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1229"]},{"id":673,"title":"ERROR_CONNECTION_ACTIVE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1230","0x4CE","error 1230","ERROR_CONNECTION_ACTIVE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","connection","active","invalid","operation","was","attempted","network"],"errorCode":"1230","eventId":"","severity":"High","summary":"An invalid operation was attempted on an active network connection.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1230; use the surrounding log entries to confirm it.","resolution":"1. Record where 1230 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CONNECTION_ACTIVE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1230 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An invalid operation was attempted on an active network connection.\n\nLookup forms: 1230, 0x4CE, error 1230, ERROR_CONNECTION_ACTIVE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1230"]},{"id":674,"title":"ERROR_NETWORK_UNREACHABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1231","0x4CF","error 1231","ERROR_NETWORK_UNREACHABLE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","network","unreachable","the","location","cannot","reached","for","information","about","troubleshooting","see","windows","help"],"errorCode":"1231","eventId":"","severity":"High","summary":"The network location cannot be reached. For information about network troubleshooting, see Windows Help.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1231; use the surrounding log entries to confirm it.","resolution":"1. Record where 1231 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NETWORK_UNREACHABLE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1231 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The network location cannot be reached. For information about network troubleshooting, see Windows Help.\n\nLookup forms: 1231, 0x4CF, error 1231, ERROR_NETWORK_UNREACHABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1231"]},{"id":675,"title":"ERROR_HOST_UNREACHABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1232","0x4D0","error 1232","ERROR_HOST_UNREACHABLE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","host","unreachable","the","network","location","cannot","reached","for","information","about","troubleshooting","see","windows","help"],"errorCode":"1232","eventId":"","severity":"High","summary":"The network location cannot be reached. For information about network troubleshooting, see Windows Help.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1232; use the surrounding log entries to confirm it.","resolution":"1. Record where 1232 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_HOST_UNREACHABLE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1232 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The network location cannot be reached. For information about network troubleshooting, see Windows Help.\n\nLookup forms: 1232, 0x4D0, error 1232, ERROR_HOST_UNREACHABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1232"]},{"id":676,"title":"ERROR_PROTOCOL_UNREACHABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1233","0x4D1","error 1233","ERROR_PROTOCOL_UNREACHABLE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","protocol","unreachable","the","network","location","cannot","reached","for","information","about","troubleshooting","see","windows","help"],"errorCode":"1233","eventId":"","severity":"High","summary":"The network location cannot be reached. For information about network troubleshooting, see Windows Help.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1233; use the surrounding log entries to confirm it.","resolution":"1. Record where 1233 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PROTOCOL_UNREACHABLE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1233 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The network location cannot be reached. For information about network troubleshooting, see Windows Help.\n\nLookup forms: 1233, 0x4D1, error 1233, ERROR_PROTOCOL_UNREACHABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1233"]},{"id":677,"title":"ERROR_PORT_UNREACHABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1234","0x4D2","error 1234","ERROR_PORT_UNREACHABLE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","port","unreachable","service","operating","the","destination","network","endpoint","remote","system"],"errorCode":"1234","eventId":"","severity":"High","summary":"No service is operating at the destination network endpoint on the remote system.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1234; use the surrounding log entries to confirm it.","resolution":"1. Record where 1234 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PORT_UNREACHABLE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1234 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No service is operating at the destination network endpoint on the remote system.\n\nLookup forms: 1234, 0x4D2, error 1234, ERROR_PORT_UNREACHABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1234"]},{"id":678,"title":"ERROR_REQUEST_ABORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1235","0x4D3","error 1235","ERROR_REQUEST_ABORTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","request","aborted","the","was"],"errorCode":"1235","eventId":"","severity":"Low","summary":"The request was aborted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1235; use the surrounding log entries to confirm it.","resolution":"1. Record where 1235 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REQUEST_ABORTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1235 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The request was aborted.\n\nLookup forms: 1235, 0x4D3, error 1235, ERROR_REQUEST_ABORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1235"]},{"id":679,"title":"ERROR_CONNECTION_ABORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1236","0x4D4","error 1236","ERROR_CONNECTION_ABORTED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","connection","aborted","the","network","was","local","system"],"errorCode":"1236","eventId":"","severity":"High","summary":"The network connection was aborted by the local system.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1236; use the surrounding log entries to confirm it.","resolution":"1. Record where 1236 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CONNECTION_ABORTED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1236 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The network connection was aborted by the local system.\n\nLookup forms: 1236, 0x4D4, error 1236, ERROR_CONNECTION_ABORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1236"]},{"id":680,"title":"ERROR_RETRY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1237","0x4D5","error 1237","ERROR_RETRY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","retry","the","operation","could","not","completed","should","performed"],"errorCode":"1237","eventId":"","severity":"Low","summary":"The operation could not be completed. A retry should be performed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1237; use the surrounding log entries to confirm it.","resolution":"1. Record where 1237 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RETRY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1237 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation could not be completed. A retry should be performed.\n\nLookup forms: 1237, 0x4D5, error 1237, ERROR_RETRY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1237"]},{"id":681,"title":"ERROR_CONNECTION_COUNT_LIMIT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1238","0x4D6","error 1238","ERROR_CONNECTION_COUNT_LIMIT","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","connection","count","limit","the","server","could","not","made","because","number","concurrent","connections","for","this","account","has","been","reached"],"errorCode":"1238","eventId":"","severity":"High","summary":"A connection to the server could not be made because the limit on the number of concurrent connections for this account has been reached.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1238; use the surrounding log entries to confirm it.","resolution":"1. Record where 1238 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CONNECTION_COUNT_LIMIT.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1238 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A connection to the server could not be made because the limit on the number of concurrent connections for this account has been reached.\n\nLookup forms: 1238, 0x4D6, error 1238, ERROR_CONNECTION_COUNT_LIMIT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1238"]},{"id":682,"title":"ERROR_LOGIN_TIME_RESTRICTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1239","0x4D7","error 1239","ERROR_LOGIN_TIME_RESTRICTION","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","login","time","restriction","attempting","log","during","unauthorized","day","for","this","account"],"errorCode":"1239","eventId":"","severity":"Low","summary":"Attempting to log in during an unauthorized time of day for this account.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1239; use the surrounding log entries to confirm it.","resolution":"1. Record where 1239 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOGIN_TIME_RESTRICTION.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1239 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Attempting to log in during an unauthorized time of day for this account.\n\nLookup forms: 1239, 0x4D7, error 1239, ERROR_LOGIN_TIME_RESTRICTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1239"]},{"id":683,"title":"ERROR_LOGIN_WKSTA_RESTRICTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1240","0x4D8","error 1240","ERROR_LOGIN_WKSTA_RESTRICTION","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","login","wksta","restriction","the","account","not","authorized","log","from","this","station"],"errorCode":"1240","eventId":"","severity":"Low","summary":"The account is not authorized to log in from this station.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1240; use the surrounding log entries to confirm it.","resolution":"1. Record where 1240 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOGIN_WKSTA_RESTRICTION.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1240 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The account is not authorized to log in from this station.\n\nLookup forms: 1240, 0x4D8, error 1240, ERROR_LOGIN_WKSTA_RESTRICTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1240"]},{"id":684,"title":"ERROR_INCORRECT_ADDRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1241","0x4D9","error 1241","ERROR_INCORRECT_ADDRESS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","incorrect","address","the","network","could","not","used","for","operation","requested"],"errorCode":"1241","eventId":"","severity":"High","summary":"The network address could not be used for the operation requested.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1241; use the surrounding log entries to confirm it.","resolution":"1. Record where 1241 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INCORRECT_ADDRESS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1241 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The network address could not be used for the operation requested.\n\nLookup forms: 1241, 0x4D9, error 1241, ERROR_INCORRECT_ADDRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1241"]},{"id":685,"title":"ERROR_ALREADY_REGISTERED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1242","0x4DA","error 1242","ERROR_ALREADY_REGISTERED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","already","registered","the","service"],"errorCode":"1242","eventId":"","severity":"Low","summary":"The service is already registered.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1242; use the surrounding log entries to confirm it.","resolution":"1. Record where 1242 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ALREADY_REGISTERED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1242 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The service is already registered.\n\nLookup forms: 1242, 0x4DA, error 1242, ERROR_ALREADY_REGISTERED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1242"]},{"id":686,"title":"ERROR_SERVICE_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1243","0x4DB","error 1243","ERROR_SERVICE_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","service","not","found","the","specified","does","exist"],"errorCode":"1243","eventId":"","severity":"Low","summary":"The specified service does not exist.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1243; use the surrounding log entries to confirm it.","resolution":"1. Record where 1243 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVICE_NOT_FOUND.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1243 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified service does not exist.\n\nLookup forms: 1243, 0x4DB, error 1243, ERROR_SERVICE_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1243"]},{"id":687,"title":"ERROR_NOT_AUTHENTICATED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1244","0x4DC","error 1244","ERROR_NOT_AUTHENTICATED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","not","authenticated","the","operation","being","requested","was","performed","because","user","has","been"],"errorCode":"1244","eventId":"","severity":"Low","summary":"The operation being requested was not performed because the user has not been authenticated.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1244; use the surrounding log entries to confirm it.","resolution":"1. Record where 1244 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_AUTHENTICATED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1244 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation being requested was not performed because the user has not been authenticated.\n\nLookup forms: 1244, 0x4DC, error 1244, ERROR_NOT_AUTHENTICATED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1244"]},{"id":688,"title":"ERROR_NOT_LOGGED_ON","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1245","0x4DD","error 1245","ERROR_NOT_LOGGED_ON","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","not","logged","the","operation","being","requested","was","performed","because","user","has","network","specified","service","does","exist"],"errorCode":"1245","eventId":"","severity":"High","summary":"The operation being requested was not performed because the user has not logged on to the network. The specified service does not exist.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1245; use the surrounding log entries to confirm it.","resolution":"1. Record where 1245 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_LOGGED_ON.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1245 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation being requested was not performed because the user has not logged on to the network. The specified service does not exist.\n\nLookup forms: 1245, 0x4DD, error 1245, ERROR_NOT_LOGGED_ON. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1245"]},{"id":689,"title":"ERROR_CONTINUE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1246","0x4DE","error 1246","ERROR_CONTINUE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","continue","with","work","progress"],"errorCode":"1246","eventId":"","severity":"Low","summary":"Continue with work in progress.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1246; use the surrounding log entries to confirm it.","resolution":"1. Record where 1246 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CONTINUE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1246 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Continue with work in progress.\n\nLookup forms: 1246, 0x4DE, error 1246, ERROR_CONTINUE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1246"]},{"id":690,"title":"ERROR_ALREADY_INITIALIZED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1247","0x4DF","error 1247","ERROR_ALREADY_INITIALIZED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","already","initialized","attempt","was","made","perform","initialization","operation","when","has","been","completed"],"errorCode":"1247","eventId":"","severity":"Low","summary":"An attempt was made to perform an initialization operation when initialization has already been completed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1247; use the surrounding log entries to confirm it.","resolution":"1. Record where 1247 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ALREADY_INITIALIZED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1247 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt was made to perform an initialization operation when initialization has already been completed.\n\nLookup forms: 1247, 0x4DF, error 1247, ERROR_ALREADY_INITIALIZED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1247"]},{"id":691,"title":"ERROR_NO_MORE_DEVICES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1248","0x4E0","error 1248","ERROR_NO_MORE_DEVICES","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","more","devices","local"],"errorCode":"1248","eventId":"","severity":"Low","summary":"No more local devices.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1248; use the surrounding log entries to confirm it.","resolution":"1. Record where 1248 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_MORE_DEVICES.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1248 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No more local devices.\n\nLookup forms: 1248, 0x4E0, error 1248, ERROR_NO_MORE_DEVICES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1248"]},{"id":692,"title":"ERROR_NO_SUCH_SITE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1249","0x4E1","error 1249","ERROR_NO_SUCH_SITE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","such","site","the","specified","does","not","exist"],"errorCode":"1249","eventId":"","severity":"Low","summary":"The specified site does not exist.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1249; use the surrounding log entries to confirm it.","resolution":"1. Record where 1249 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_SUCH_SITE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1249 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified site does not exist.\n\nLookup forms: 1249, 0x4E1, error 1249, ERROR_NO_SUCH_SITE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1249"]},{"id":693,"title":"ERROR_DOMAIN_CONTROLLER_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1250","0x4E2","error 1250","ERROR_DOMAIN_CONTROLLER_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","domain","controller","exists","with","the","specified","name","already"],"errorCode":"1250","eventId":"","severity":"Medium","summary":"A domain controller with the specified name already exists.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1250; use the surrounding log entries to confirm it.","resolution":"1. Record where 1250 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DOMAIN_CONTROLLER_EXISTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1250 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A domain controller with the specified name already exists.\n\nLookup forms: 1250, 0x4E2, error 1250, ERROR_DOMAIN_CONTROLLER_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1250"]},{"id":694,"title":"ERROR_ONLY_IF_CONNECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1251","0x4E3","error 1251","ERROR_ONLY_IF_CONNECTED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","only","connected","this","operation","supported","when","you","are","the","server"],"errorCode":"1251","eventId":"","severity":"Low","summary":"This operation is supported only when you are connected to the server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1251; use the surrounding log entries to confirm it.","resolution":"1. Record where 1251 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ONLY_IF_CONNECTED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1251 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation is supported only when you are connected to the server.\n\nLookup forms: 1251, 0x4E3, error 1251, ERROR_ONLY_IF_CONNECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1251"]},{"id":695,"title":"ERROR_OVERRIDE_NOCHANGES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1252","0x4E4","error 1252","ERROR_OVERRIDE_NOCHANGES","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","override","nochanges","the","group","policy","framework","should","call","extension","even","there","are","changes"],"errorCode":"1252","eventId":"","severity":"Low","summary":"The group policy framework should call the extension even if there are no changes.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1252; use the surrounding log entries to confirm it.","resolution":"1. Record where 1252 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_OVERRIDE_NOCHANGES.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1252 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The group policy framework should call the extension even if there are no changes.\n\nLookup forms: 1252, 0x4E4, error 1252, ERROR_OVERRIDE_NOCHANGES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1252"]},{"id":696,"title":"ERROR_BAD_USER_PROFILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1253","0x4E5","error 1253","ERROR_BAD_USER_PROFILE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","bad","user","profile","the","specified","does","not","have","valid"],"errorCode":"1253","eventId":"","severity":"Low","summary":"The specified user does not have a valid profile.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1253; use the surrounding log entries to confirm it.","resolution":"1. Record where 1253 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_USER_PROFILE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1253 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified user does not have a valid profile.\n\nLookup forms: 1253, 0x4E5, error 1253, ERROR_BAD_USER_PROFILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1253"]},{"id":697,"title":"ERROR_NOT_SUPPORTED_ON_SBS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1254","0x4E6","error 1254","ERROR_NOT_SUPPORTED_ON_SBS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","not","supported","sbs","this","operation","computer","running","windows","server","2003","for","small","business"],"errorCode":"1254","eventId":"","severity":"Medium","summary":"This operation is not supported on a computer running Windows Server 2003 for Small Business Server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1254; use the surrounding log entries to confirm it.","resolution":"1. Record where 1254 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_SUPPORTED_ON_SBS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1254 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation is not supported on a computer running Windows Server 2003 for Small Business Server.\n\nLookup forms: 1254, 0x4E6, error 1254, ERROR_NOT_SUPPORTED_ON_SBS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): This operation is not supported on a Microsoft Small Business Server.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1254"]},{"id":698,"title":"ERROR_SERVER_SHUTDOWN_IN_PROGRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1255","0x4E7","error 1255","ERROR_SERVER_SHUTDOWN_IN_PROGRESS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","server","shutdown","progress","the","machine","shutting","down"],"errorCode":"1255","eventId":"","severity":"Low","summary":"The server machine is shutting down.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1255; use the surrounding log entries to confirm it.","resolution":"1. Record where 1255 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVER_SHUTDOWN_IN_PROGRESS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1255 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The server machine is shutting down.\n\nLookup forms: 1255, 0x4E7, error 1255, ERROR_SERVER_SHUTDOWN_IN_PROGRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1255"]},{"id":699,"title":"ERROR_HOST_DOWN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1256","0x4E8","error 1256","ERROR_HOST_DOWN","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","host","down","the","remote","system","not","available","for","information","about","network","troubleshooting","see","windows","help"],"errorCode":"1256","eventId":"","severity":"High","summary":"The remote system is not available. For information about network troubleshooting, see Windows Help.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1256; use the surrounding log entries to confirm it.","resolution":"1. Record where 1256 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_HOST_DOWN.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1256 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The remote system is not available. For information about network troubleshooting, see Windows Help.\n\nLookup forms: 1256, 0x4E8, error 1256, ERROR_HOST_DOWN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1256"]},{"id":700,"title":"ERROR_NON_ACCOUNT_SID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1257","0x4E9","error 1257","ERROR_NON_ACCOUNT_SID","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","non","account","sid","the","security","identifier","provided","not","from","domain"],"errorCode":"1257","eventId":"","severity":"Low","summary":"The security identifier provided is not from an account domain.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1257; use the surrounding log entries to confirm it.","resolution":"1. Record where 1257 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NON_ACCOUNT_SID.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1257 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The security identifier provided is not from an account domain.\n\nLookup forms: 1257, 0x4E9, error 1257, ERROR_NON_ACCOUNT_SID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1257"]},{"id":701,"title":"ERROR_NON_DOMAIN_SID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1258","0x4EA","error 1258","ERROR_NON_DOMAIN_SID","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","non","domain","sid","the","security","identifier","provided","does","not","have","component"],"errorCode":"1258","eventId":"","severity":"Low","summary":"The security identifier provided does not have a domain component.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1258; use the surrounding log entries to confirm it.","resolution":"1. Record where 1258 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NON_DOMAIN_SID.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1258 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The security identifier provided does not have a domain component.\n\nLookup forms: 1258, 0x4EA, error 1258, ERROR_NON_DOMAIN_SID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1258"]},{"id":702,"title":"ERROR_APPHELP_BLOCK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1259","0x4EB","error 1259","ERROR_APPHELP_BLOCK","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","apphelp","block","dialog","canceled","thus","preventing","the","application","from","starting"],"errorCode":"1259","eventId":"","severity":"Low","summary":"AppHelp dialog canceled thus preventing the application from starting.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1259; use the surrounding log entries to confirm it.","resolution":"1. Record where 1259 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_APPHELP_BLOCK.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1259 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: AppHelp dialog canceled thus preventing the application from starting.\n\nLookup forms: 1259, 0x4EB, error 1259, ERROR_APPHELP_BLOCK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1259"]},{"id":703,"title":"ERROR_ACCESS_DISABLED_BY_POLICY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1260","0x4EC","error 1260","ERROR_ACCESS_DISABLED_BY_POLICY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","access","disabled","policy","this","program","blocked","group","for","more","information","contact","your","system","administrator"],"errorCode":"1260","eventId":"","severity":"High","summary":"This program is blocked by group policy. For more information, contact your system administrator.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1260; use the surrounding log entries to confirm it.","resolution":"1. Record where 1260 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ACCESS_DISABLED_BY_POLICY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1260 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This program is blocked by group policy. For more information, contact your system administrator.\n\nLookup forms: 1260, 0x4EC, error 1260, ERROR_ACCESS_DISABLED_BY_POLICY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Windows cannot open this program because it has been prevented by a software restriction policy. For more information, open Event Viewer or contact your system administrator.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1260"]},{"id":704,"title":"ERROR_REG_NAT_CONSUMPTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1261","0x4ED","error 1261","ERROR_REG_NAT_CONSUMPTION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","reg","nat","consumption","program","attempt","use","invalid","register","value","normally","caused","uninitialized","this","itanium","specific"],"errorCode":"1261","eventId":"","severity":"Medium","summary":"A program attempt to use an invalid register value. Normally caused by an uninitialized register. This error is Itanium specific.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1261; use the surrounding log entries to confirm it.","resolution":"1. Record where 1261 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REG_NAT_CONSUMPTION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1261 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A program attempt to use an invalid register value. Normally caused by an uninitialized register. This error is Itanium specific.\n\nLookup forms: 1261, 0x4ED, error 1261, ERROR_REG_NAT_CONSUMPTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1261"]},{"id":705,"title":"ERROR_CSCSHARE_OFFLINE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1262","0x4EE","error 1262","ERROR_CSCSHARE_OFFLINE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cscshare","offline","the","share","currently","does","not","exist"],"errorCode":"1262","eventId":"","severity":"Low","summary":"The share is currently offline or does not exist.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1262; use the surrounding log entries to confirm it.","resolution":"1. Record where 1262 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CSCSHARE_OFFLINE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1262 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The share is currently offline or does not exist.\n\nLookup forms: 1262, 0x4EE, error 1262, ERROR_CSCSHARE_OFFLINE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1262"]},{"id":706,"title":"ERROR_PKINIT_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1263","0x4EF","error 1263","ERROR_PKINIT_FAILURE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","pkinit","failure","the","kerberos","protocol","encountered","while","validating","kdc","certificate","during","smartcard","logon","there","more","information","system","event","log"],"errorCode":"1263","eventId":"","severity":"High","summary":"The Kerberos protocol encountered an error while validating the KDC certificate during smartcard logon. There is more information in the system event log.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1263; use the surrounding log entries to confirm it.","resolution":"1. Record where 1263 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PKINIT_FAILURE.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1263 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Kerberos protocol encountered an error while validating the KDC certificate during smartcard logon. There is more information in the system event log.\n\nLookup forms: 1263, 0x4EF, error 1263, ERROR_PKINIT_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The kerberos protocol encountered an error while validating the KDC certificate during smartcard logon.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1263"]},{"id":707,"title":"ERROR_SMARTCARD_SUBSYSTEM_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1264","0x4F0","error 1264","ERROR_SMARTCARD_SUBSYSTEM_FAILURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","smartcard","subsystem","failure","the","kerberos","protocol","encountered","while","attempting","utilize"],"errorCode":"1264","eventId":"","severity":"Low","summary":"The Kerberos protocol encountered an error while attempting to utilize the smartcard subsystem.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1264; use the surrounding log entries to confirm it.","resolution":"1. Record where 1264 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SMARTCARD_SUBSYSTEM_FAILURE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1264 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Kerberos protocol encountered an error while attempting to utilize the smartcard subsystem.\n\nLookup forms: 1264, 0x4F0, error 1264, ERROR_SMARTCARD_SUBSYSTEM_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The kerberos protocol encountered an error while attempting to utilize the smartcard subsystem.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1264"]},{"id":708,"title":"ERROR_DOWNGRADE_DETECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1265","0x4F1","error 1265","ERROR_DOWNGRADE_DETECTED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","downgrade","detected","the","system","cannot","contact","domain","controller","service","authentication","request","please","try","again","later"],"errorCode":"1265","eventId":"","severity":"High","summary":"The system cannot contact a domain controller to service the authentication request. Please try again later.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1265; use the surrounding log entries to confirm it.","resolution":"1. Record where 1265 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DOWNGRADE_DETECTED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1265 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system cannot contact a domain controller to service the authentication request. Please try again later.\n\nLookup forms: 1265, 0x4F1, error 1265, ERROR_DOWNGRADE_DETECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The system detected a possible attempt to compromise security. Please ensure that you can contact the server that authenticated you.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1265"]},{"id":709,"title":"ERROR_MACHINE_LOCKED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1271","0x4F7","error 1271","ERROR_MACHINE_LOCKED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","machine","locked","the","and","cannot","shut","down","without","force","option"],"errorCode":"1271","eventId":"","severity":"High","summary":"The machine is locked and cannot be shut down without the force option.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1271; use the surrounding log entries to confirm it.","resolution":"1. Record where 1271 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MACHINE_LOCKED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1271 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The machine is locked and cannot be shut down without the force option.\n\nLookup forms: 1271, 0x4F7, error 1271, ERROR_MACHINE_LOCKED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1271"]},{"id":710,"title":"ERROR_CALLBACK_SUPPLIED_INVALID_DATA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1273","0x4F9","error 1273","ERROR_CALLBACK_SUPPLIED_INVALID_DATA","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","callback","supplied","invalid","data","application","defined","gave","when","called"],"errorCode":"1273","eventId":"","severity":"Medium","summary":"An application-defined callback gave invalid data when called.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1273; use the surrounding log entries to confirm it.","resolution":"1. Record where 1273 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CALLBACK_SUPPLIED_INVALID_DATA.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1273 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An application-defined callback gave invalid data when called.\n\nLookup forms: 1273, 0x4F9, error 1273, ERROR_CALLBACK_SUPPLIED_INVALID_DATA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1273"]},{"id":711,"title":"ERROR_SYNC_FOREGROUND_REFRESH_REQUIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1274","0x4FA","error 1274","ERROR_SYNC_FOREGROUND_REFRESH_REQUIRED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sync","foreground","refresh","required","the","group","policy","framework","should","call","extension","synchronous"],"errorCode":"1274","eventId":"","severity":"Low","summary":"The group policy framework should call the extension in the synchronous foreground policy refresh.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1274; use the surrounding log entries to confirm it.","resolution":"1. Record where 1274 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SYNC_FOREGROUND_REFRESH_REQUIRED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1274 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The group policy framework should call the extension in the synchronous foreground policy refresh.\n\nLookup forms: 1274, 0x4FA, error 1274, ERROR_SYNC_FOREGROUND_REFRESH_REQUIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1274"]},{"id":712,"title":"ERROR_DRIVER_BLOCKED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1275","0x4FB","error 1275","ERROR_DRIVER_BLOCKED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","driver","blocked","this","has","been","from","loading"],"errorCode":"1275","eventId":"","severity":"High","summary":"This driver has been blocked from loading.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1275; use the surrounding log entries to confirm it.","resolution":"1. Record where 1275 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DRIVER_BLOCKED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1275 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This driver has been blocked from loading.\n\nLookup forms: 1275, 0x4FB, error 1275, ERROR_DRIVER_BLOCKED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1275"]},{"id":713,"title":"ERROR_INVALID_IMPORT_OF_NON_DLL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1276","0x4FC","error 1276","ERROR_INVALID_IMPORT_OF_NON_DLL","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","invalid","import","non","dll","dynamic","link","library","referenced","module","that","was","neither","nor","the","process","executable","image"],"errorCode":"1276","eventId":"","severity":"Low","summary":"A dynamic link library (DLL) referenced a module that was neither a DLL nor the process's executable image.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1276; use the surrounding log entries to confirm it.","resolution":"1. Record where 1276 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_IMPORT_OF_NON_DLL.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1276 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A dynamic link library (DLL) referenced a module that was neither a DLL nor the process's executable image.\n\nLookup forms: 1276, 0x4FC, error 1276, ERROR_INVALID_IMPORT_OF_NON_DLL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1276"]},{"id":714,"title":"ERROR_ACCESS_DISABLED_WEBBLADE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1277","0x4FD","error 1277","ERROR_ACCESS_DISABLED_WEBBLADE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","access","disabled","webblade","windows","cannot","open","this","program","since","has","been"],"errorCode":"1277","eventId":"","severity":"Medium","summary":"Windows cannot open this program since it has been disabled.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1277; use the surrounding log entries to confirm it.","resolution":"1. Record where 1277 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ACCESS_DISABLED_WEBBLADE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1277 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Windows cannot open this program since it has been disabled.\n\nLookup forms: 1277, 0x4FD, error 1277, ERROR_ACCESS_DISABLED_WEBBLADE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1277"]},{"id":715,"title":"ERROR_ACCESS_DISABLED_WEBBLADE_TAMPER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1278","0x4FE","error 1278","ERROR_ACCESS_DISABLED_WEBBLADE_TAMPER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","access","disabled","webblade","tamper","windows","cannot","open","this","program","because","the","license","enforcement","system","has","been","tampered","with","become","corrupted"],"errorCode":"1278","eventId":"","severity":"Critical","summary":"Windows cannot open this program because the license enforcement system has been tampered with or become corrupted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1278; use the surrounding log entries to confirm it.","resolution":"1. Record where 1278 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ACCESS_DISABLED_WEBBLADE_TAMPER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1278 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Windows cannot open this program because the license enforcement system has been tampered with or become corrupted.\n\nLookup forms: 1278, 0x4FE, error 1278, ERROR_ACCESS_DISABLED_WEBBLADE_TAMPER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1278"]},{"id":716,"title":"ERROR_RECOVERY_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1279","0x4FF","error 1279","ERROR_RECOVERY_FAILURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","recovery","failure","transaction","recover","failed"],"errorCode":"1279","eventId":"","severity":"High","summary":"A transaction recover failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1279; use the surrounding log entries to confirm it.","resolution":"1. Record where 1279 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RECOVERY_FAILURE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1279 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A transaction recover failed.\n\nLookup forms: 1279, 0x4FF, error 1279, ERROR_RECOVERY_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1279"]},{"id":717,"title":"ERROR_ALREADY_FIBER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1280","0x500","error 1280","ERROR_ALREADY_FIBER","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","already","fiber","the","current","thread","has","been","converted"],"errorCode":"1280","eventId":"","severity":"Low","summary":"The current thread has already been converted to a fiber.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1280; use the surrounding log entries to confirm it.","resolution":"1. Record where 1280 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ALREADY_FIBER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1280 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The current thread has already been converted to a fiber.\n\nLookup forms: 1280, 0x500, error 1280, ERROR_ALREADY_FIBER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1280"]},{"id":718,"title":"ERROR_ALREADY_THREAD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1281","0x501","error 1281","ERROR_ALREADY_THREAD","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","already","thread","the","current","has","been","converted","from","fiber"],"errorCode":"1281","eventId":"","severity":"Low","summary":"The current thread has already been converted from a fiber.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1281; use the surrounding log entries to confirm it.","resolution":"1. Record where 1281 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ALREADY_THREAD.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1281 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The current thread has already been converted from a fiber.\n\nLookup forms: 1281, 0x501, error 1281, ERROR_ALREADY_THREAD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1281"]},{"id":719,"title":"ERROR_STACK_BUFFER_OVERRUN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1282","0x502","error 1282","ERROR_STACK_BUFFER_OVERRUN","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","stack","buffer","overrun","the","system","detected","based","this","application","could","potentially","allow","malicious","user","gain","control"],"errorCode":"1282","eventId":"","severity":"Low","summary":"The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1282; use the surrounding log entries to confirm it.","resolution":"1. Record where 1282 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STACK_BUFFER_OVERRUN.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1282 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.\n\nLookup forms: 1282, 0x502, error 1282, ERROR_STACK_BUFFER_OVERRUN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1282"]},{"id":720,"title":"ERROR_PARAMETER_QUOTA_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1283","0x503","error 1283","ERROR_PARAMETER_QUOTA_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","parameter","quota","exceeded","data","present","one","the","parameters","more","than","function","can","operate"],"errorCode":"1283","eventId":"","severity":"Low","summary":"Data present in one of the parameters is more than the function can operate on.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1283; use the surrounding log entries to confirm it.","resolution":"1. Record where 1283 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PARAMETER_QUOTA_EXCEEDED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1283 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Data present in one of the parameters is more than the function can operate on.\n\nLookup forms: 1283, 0x503, error 1283, ERROR_PARAMETER_QUOTA_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1283"]},{"id":721,"title":"ERROR_DEBUGGER_INACTIVE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1284","0x504","error 1284","ERROR_DEBUGGER_INACTIVE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","debugger","inactive","attempt","operation","debug","object","failed","because","the","process","being","deleted"],"errorCode":"1284","eventId":"","severity":"High","summary":"An attempt to do an operation on a debug object failed because the object is in the process of being deleted.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1284; use the surrounding log entries to confirm it.","resolution":"1. Record where 1284 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEBUGGER_INACTIVE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1284 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt to do an operation on a debug object failed because the object is in the process of being deleted.\n\nLookup forms: 1284, 0x504, error 1284, ERROR_DEBUGGER_INACTIVE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1284"]},{"id":722,"title":"ERROR_DELAY_LOAD_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1285","0x505","error 1285","ERROR_DELAY_LOAD_FAILED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","delay","load","failed","attempt","dll","get","function","address","loaded"],"errorCode":"1285","eventId":"","severity":"High","summary":"An attempt to delay-load a .dll or get a function address in a delay-loaded .dll failed.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1285; use the surrounding log entries to confirm it.","resolution":"1. Record where 1285 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DELAY_LOAD_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1285 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt to delay-load a .dll or get a function address in a delay-loaded .dll failed.\n\nLookup forms: 1285, 0x505, error 1285, ERROR_DELAY_LOAD_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1285"]},{"id":723,"title":"ERROR_VDM_DISALLOWED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1286","0x506","error 1286","ERROR_VDM_DISALLOWED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","vdm","disallowed","bit","application","you","not","have","permissions","execute","applications","check","your","with","system","administrator"],"errorCode":"1286","eventId":"","severity":"Low","summary":"%1 is a 16-bit application. You do not have permissions to execute 16-bit applications. Check your permissions with your system administrator.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1286; use the surrounding log entries to confirm it.","resolution":"1. Record where 1286 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_VDM_DISALLOWED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1286 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: %1 is a 16-bit application. You do not have permissions to execute 16-bit applications. Check your permissions with your system administrator.\n\nLookup forms: 1286, 0x506, error 1286, ERROR_VDM_DISALLOWED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1286"]},{"id":724,"title":"ERROR_UNIDENTIFIED_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1287","0x507","error 1287","ERROR_UNIDENTIFIED_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","unidentified","insufficient","information","exists","identify","the","cause","failure"],"errorCode":"1287","eventId":"","severity":"High","summary":"Insufficient information exists to identify the cause of failure.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1287; use the surrounding log entries to confirm it.","resolution":"1. Record where 1287 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNIDENTIFIED_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1287 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Insufficient information exists to identify the cause of failure.\n\nLookup forms: 1287, 0x507, error 1287, ERROR_UNIDENTIFIED_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1287"]},{"id":725,"title":"ERROR_INVALID_CRUNTIME_PARAMETER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1288","0x508","error 1288","ERROR_INVALID_CRUNTIME_PARAMETER","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","invalid","cruntime","parameter","the","passed","runtime","function","incorrect"],"errorCode":"1288","eventId":"","severity":"Low","summary":"The parameter passed to a C runtime function is incorrect.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1288; use the surrounding log entries to confirm it.","resolution":"1. Record where 1288 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_CRUNTIME_PARAMETER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1288 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The parameter passed to a C runtime function is incorrect.\n\nLookup forms: 1288, 0x508, error 1288, ERROR_INVALID_CRUNTIME_PARAMETER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1288"]},{"id":726,"title":"ERROR_BEYOND_VDL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1289","0x509","error 1289","ERROR_BEYOND_VDL","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","beyond","vdl","the","operation","occurred","valid","data","length","file"],"errorCode":"1289","eventId":"","severity":"Low","summary":"The operation occurred beyond the valid data length of the file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1289; use the surrounding log entries to confirm it.","resolution":"1. Record where 1289 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BEYOND_VDL.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1289 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation occurred beyond the valid data length of the file.\n\nLookup forms: 1289, 0x509, error 1289, ERROR_BEYOND_VDL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1289"]},{"id":727,"title":"ERROR_INCOMPATIBLE_SERVICE_SID_TYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1290","0x50A","error 1290","ERROR_INCOMPATIBLE_SERVICE_SID_TYPE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","incompatible","service","sid","type","the","start","failed","since","one","more","services","same","process","have","setting","with","restricted","can","only","coexist","other","for","this","was"],"errorCode":"1290","eventId":"","severity":"High","summary":"The service start failed since one or more services in the same process have an incompatible service SID type setting. A service with restricted service SID type can only coexist in the same process with other services with a restricted SID type. If the service SID type for this service was just configured, the hosting process must be restarted in order to start this service.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1290; use the surrounding log entries to confirm it.","resolution":"1. Record where 1290 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INCOMPATIBLE_SERVICE_SID_TYPE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1290 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The service start failed since one or more services in the same process have an incompatible service SID type setting. A service with restricted service SID type can only coexist in the same process with other services with a restricted SID type. If the service SID type for this service was just configured, the hosting process must be restarted in order to start this service.\n\nLookup forms: 1290, 0x50A, error 1290, ERROR_INCOMPATIBLE_SERVICE_SID_TYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1290"]},{"id":728,"title":"ERROR_DRIVER_PROCESS_TERMINATED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1291","0x50B","error 1291","ERROR_DRIVER_PROCESS_TERMINATED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","driver","process","terminated","the","hosting","for","this","device","has","been"],"errorCode":"1291","eventId":"","severity":"Low","summary":"The process hosting the driver for this device has been terminated.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1291; use the surrounding log entries to confirm it.","resolution":"1. Record where 1291 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DRIVER_PROCESS_TERMINATED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1291 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The process hosting the driver for this device has been terminated.\n\nLookup forms: 1291, 0x50B, error 1291, ERROR_DRIVER_PROCESS_TERMINATED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1291"]},{"id":729,"title":"ERROR_IMPLEMENTATION_LIMIT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1292","0x50C","error 1292","ERROR_IMPLEMENTATION_LIMIT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","implementation","limit","operation","attempted","exceed","defined"],"errorCode":"1292","eventId":"","severity":"Low","summary":"An operation attempted to exceed an implementation-defined limit.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1292; use the surrounding log entries to confirm it.","resolution":"1. Record where 1292 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IMPLEMENTATION_LIMIT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1292 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An operation attempted to exceed an implementation-defined limit.\n\nLookup forms: 1292, 0x50C, error 1292, ERROR_IMPLEMENTATION_LIMIT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1292"]},{"id":730,"title":"ERROR_PROCESS_IS_PROTECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1293","0x50D","error 1293","ERROR_PROCESS_IS_PROTECTED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","process","protected","either","the","target","thread","containing"],"errorCode":"1293","eventId":"","severity":"Low","summary":"Either the target process, or the target thread's containing process, is a protected process.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1293; use the surrounding log entries to confirm it.","resolution":"1. Record where 1293 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PROCESS_IS_PROTECTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1293 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Either the target process, or the target thread's containing process, is a protected process.\n\nLookup forms: 1293, 0x50D, error 1293, ERROR_PROCESS_IS_PROTECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1293"]},{"id":731,"title":"ERROR_SERVICE_NOTIFY_CLIENT_LAGGING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1294","0x50E","error 1294","ERROR_SERVICE_NOTIFY_CLIENT_LAGGING","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","service","notify","client","lagging","the","notification","too","far","behind","current","state","services","machine"],"errorCode":"1294","eventId":"","severity":"Low","summary":"The service notification client is lagging too far behind the current state of services in the machine.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1294; use the surrounding log entries to confirm it.","resolution":"1. Record where 1294 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVICE_NOTIFY_CLIENT_LAGGING.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1294 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The service notification client is lagging too far behind the current state of services in the machine.\n\nLookup forms: 1294, 0x50E, error 1294, ERROR_SERVICE_NOTIFY_CLIENT_LAGGING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1294"]},{"id":732,"title":"ERROR_DISK_QUOTA_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1295","0x50F","error 1295","ERROR_DISK_QUOTA_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","disk","quota","exceeded","the","requested","file","operation","failed","because","storage","was","free","space","move","files","different","location","delete","unnecessary","for","more","information","contact","your"],"errorCode":"1295","eventId":"","severity":"High","summary":"The requested file operation failed because the storage quota was exceeded. To free up disk space, move files to a different location or delete unnecessary files. For more information, contact your system administrator.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1295; use the surrounding log entries to confirm it.","resolution":"1. Record where 1295 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DISK_QUOTA_EXCEEDED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1295 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested file operation failed because the storage quota was exceeded. To free up disk space, move files to a different location or delete unnecessary files. For more information, contact your system administrator.\n\nLookup forms: 1295, 0x50F, error 1295, ERROR_DISK_QUOTA_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1295"]},{"id":733,"title":"ERROR_CONTENT_BLOCKED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1296","0x510","error 1296","ERROR_CONTENT_BLOCKED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","content","blocked","the","requested","file","operation","failed","because","storage","policy","blocks","that","type","for","more","information","contact","your","system","administrator"],"errorCode":"1296","eventId":"","severity":"High","summary":"The requested file operation failed because the storage policy blocks that type of file. For more information, contact your system administrator.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1296; use the surrounding log entries to confirm it.","resolution":"1. Record where 1296 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CONTENT_BLOCKED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1296 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested file operation failed because the storage policy blocks that type of file. For more information, contact your system administrator.\n\nLookup forms: 1296, 0x510, error 1296, ERROR_CONTENT_BLOCKED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1296"]},{"id":734,"title":"ERROR_INCOMPATIBLE_SERVICE_PRIVILEGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1297","0x511","error 1297","ERROR_INCOMPATIBLE_SERVICE_PRIVILEGE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","incompatible","service","privilege","that","the","requires","function","properly","does","not","exist","account","configuration","you","may","use","services","microsoft","management","console","mmc","snap","msc","and"],"errorCode":"1297","eventId":"","severity":"Low","summary":"A privilege that the service requires to function properly does not exist in the service account configuration. You may use the Services Microsoft Management Console (MMC) snap-in (services.msc) and the Local Security Settings MMC snap-in (secpol.msc) to view the service configuration and the account configuration.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1297; use the surrounding log entries to confirm it.","resolution":"1. Record where 1297 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INCOMPATIBLE_SERVICE_PRIVILEGE.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1297 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A privilege that the service requires to function properly does not exist in the service account configuration. You may use the Services Microsoft Management Console (MMC) snap-in (services.msc) and the Local Security Settings MMC snap-in (secpol.msc) to view the service configuration and the account configuration.\n\nLookup forms: 1297, 0x511, error 1297, ERROR_INCOMPATIBLE_SERVICE_PRIVILEGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1297"]},{"id":735,"title":"ERROR_APP_HANG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1298","0x512","error 1298","ERROR_APP_HANG","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","app","hang","thread","involved","this","operation","appears","unresponsive"],"errorCode":"1298","eventId":"","severity":"Low","summary":"A thread involved in this operation appears to be unresponsive.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1298; use the surrounding log entries to confirm it.","resolution":"1. Record where 1298 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_APP_HANG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1298 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A thread involved in this operation appears to be unresponsive.\n\nLookup forms: 1298, 0x512, error 1298, ERROR_APP_HANG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1298"]},{"id":736,"title":"ERROR_INVALID_LABEL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1299","0x513","error 1299","ERROR_INVALID_LABEL","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","invalid","label","indicates","particular","security","may","not","assigned","the","object"],"errorCode":"1299","eventId":"","severity":"Low","summary":"Indicates a particular Security ID may not be assigned as the label of an object.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1299; use the surrounding log entries to confirm it.","resolution":"1. Record where 1299 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_LABEL.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1299 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Indicates a particular Security ID may not be assigned as the label of an object.\n\nLookup forms: 1299, 0x513, error 1299, ERROR_INVALID_LABEL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1299"]},{"id":737,"title":"ERROR_NOT_ALL_ASSIGNED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1300","0x514","error 1300","ERROR_NOT_ALL_ASSIGNED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","not","all","assigned","privileges","groups","referenced","are","the","caller"],"errorCode":"1300","eventId":"","severity":"Low","summary":"Not all privileges or groups referenced are assigned to the caller.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1300; use the surrounding log entries to confirm it.","resolution":"1. Record where 1300 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_ALL_ASSIGNED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1300 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Not all privileges or groups referenced are assigned to the caller.\n\nLookup forms: 1300, 0x514, error 1300, ERROR_NOT_ALL_ASSIGNED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Not all privileges referenced are assigned to the caller.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1300"]},{"id":738,"title":"ERROR_SOME_NOT_MAPPED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1301","0x515","error 1301","ERROR_SOME_NOT_MAPPED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","some","not","mapped","mapping","between","account","names","and","security","ids","was","done"],"errorCode":"1301","eventId":"","severity":"Low","summary":"Some mapping between account names and security IDs was not done.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1301; use the surrounding log entries to confirm it.","resolution":"1. Record where 1301 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SOME_NOT_MAPPED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1301 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Some mapping between account names and security IDs was not done.\n\nLookup forms: 1301, 0x515, error 1301, ERROR_SOME_NOT_MAPPED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1301"]},{"id":739,"title":"ERROR_NO_QUOTAS_FOR_ACCOUNT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1302","0x516","error 1302","ERROR_NO_QUOTAS_FOR_ACCOUNT","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","quotas","for","account","system","quota","limits","are","specifically","set","this"],"errorCode":"1302","eventId":"","severity":"Low","summary":"No system quota limits are specifically set for this account.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1302; use the surrounding log entries to confirm it.","resolution":"1. Record where 1302 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_QUOTAS_FOR_ACCOUNT.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1302 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No system quota limits are specifically set for this account.\n\nLookup forms: 1302, 0x516, error 1302, ERROR_NO_QUOTAS_FOR_ACCOUNT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1302"]},{"id":740,"title":"ERROR_LOCAL_USER_SESSION_KEY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1303","0x517","error 1303","ERROR_LOCAL_USER_SESSION_KEY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","local","user","session","key","encryption","available","well","known","was","returned"],"errorCode":"1303","eventId":"","severity":"Low","summary":"No encryption key is available. A well-known encryption key was returned.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1303; use the surrounding log entries to confirm it.","resolution":"1. Record where 1303 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOCAL_USER_SESSION_KEY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1303 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No encryption key is available. A well-known encryption key was returned.\n\nLookup forms: 1303, 0x517, error 1303, ERROR_LOCAL_USER_SESSION_KEY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1303"]},{"id":741,"title":"ERROR_NULL_LM_PASSWORD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1304","0x518","error 1304","ERROR_NULL_LM_PASSWORD","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","null","password","the","too","complex","converted","lan","manager","returned","string"],"errorCode":"1304","eventId":"","severity":"Low","summary":"The password is too complex to be converted to a LAN Manager password. The LAN Manager password returned is a NULL string.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1304; use the surrounding log entries to confirm it.","resolution":"1. Record where 1304 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NULL_LM_PASSWORD.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1304 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The password is too complex to be converted to a LAN Manager password. The LAN Manager password returned is a NULL string.\n\nLookup forms: 1304, 0x518, error 1304, ERROR_NULL_LM_PASSWORD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1304"]},{"id":742,"title":"ERROR_UNKNOWN_REVISION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1305","0x519","error 1305","ERROR_UNKNOWN_REVISION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","unknown","revision","the","level"],"errorCode":"1305","eventId":"","severity":"Low","summary":"The revision level is unknown.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1305; use the surrounding log entries to confirm it.","resolution":"1. Record where 1305 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNKNOWN_REVISION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1305 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The revision level is unknown.\n\nLookup forms: 1305, 0x519, error 1305, ERROR_UNKNOWN_REVISION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1305"]},{"id":743,"title":"ERROR_REVISION_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1306","0x51A","error 1306","ERROR_REVISION_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","revision","mismatch","indicates","two","levels","are","incompatible"],"errorCode":"1306","eventId":"","severity":"Low","summary":"Indicates two revision levels are incompatible.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1306; use the surrounding log entries to confirm it.","resolution":"1. Record where 1306 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REVISION_MISMATCH.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1306 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Indicates two revision levels are incompatible.\n\nLookup forms: 1306, 0x51A, error 1306, ERROR_REVISION_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1306"]},{"id":744,"title":"ERROR_INVALID_OWNER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1307","0x51B","error 1307","ERROR_INVALID_OWNER","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","invalid","owner","this","security","may","not","assigned","the","object"],"errorCode":"1307","eventId":"","severity":"Low","summary":"This security ID may not be assigned as the owner of this object.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1307; use the surrounding log entries to confirm it.","resolution":"1. Record where 1307 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_OWNER.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1307 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This security ID may not be assigned as the owner of this object.\n\nLookup forms: 1307, 0x51B, error 1307, ERROR_INVALID_OWNER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1307"]},{"id":745,"title":"ERROR_INVALID_PRIMARY_GROUP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1308","0x51C","error 1308","ERROR_INVALID_PRIMARY_GROUP","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","invalid","primary","group","this","security","may","not","assigned","the","object"],"errorCode":"1308","eventId":"","severity":"Low","summary":"This security ID may not be assigned as the primary group of an object.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1308; use the surrounding log entries to confirm it.","resolution":"1. Record where 1308 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_PRIMARY_GROUP.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1308 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This security ID may not be assigned as the primary group of an object.\n\nLookup forms: 1308, 0x51C, error 1308, ERROR_INVALID_PRIMARY_GROUP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1308"]},{"id":746,"title":"ERROR_NO_IMPERSONATION_TOKEN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1309","0x51D","error 1309","ERROR_NO_IMPERSONATION_TOKEN","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","impersonation","token","attempt","has","been","made","operate","thread","that","not","currently","impersonating","client"],"errorCode":"1309","eventId":"","severity":"Low","summary":"An attempt has been made to operate on an impersonation token by a thread that is not currently impersonating a client.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1309; use the surrounding log entries to confirm it.","resolution":"1. Record where 1309 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_IMPERSONATION_TOKEN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1309 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt has been made to operate on an impersonation token by a thread that is not currently impersonating a client.\n\nLookup forms: 1309, 0x51D, error 1309, ERROR_NO_IMPERSONATION_TOKEN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1309"]},{"id":747,"title":"ERROR_CANT_DISABLE_MANDATORY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1310","0x51E","error 1310","ERROR_CANT_DISABLE_MANDATORY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","disable","mandatory","the","group","may","not","disabled"],"errorCode":"1310","eventId":"","severity":"Low","summary":"The group may not be disabled.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1310; use the surrounding log entries to confirm it.","resolution":"1. Record where 1310 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANT_DISABLE_MANDATORY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1310 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The group may not be disabled.\n\nLookup forms: 1310, 0x51E, error 1310, ERROR_CANT_DISABLE_MANDATORY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1310"]},{"id":748,"title":"ERROR_NO_LOGON_SERVERS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1311","0x51F","error 1311","ERROR_NO_LOGON_SERVERS","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","logon","servers","there","are","currently","available","service","the","request"],"errorCode":"1311","eventId":"","severity":"High","summary":"There are currently no logon servers available to service the logon request.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1311; use the surrounding log entries to confirm it.","resolution":"1. Record where 1311 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Verify the required service or agent is installed, running, and current; repair the component if needed.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_LOGON_SERVERS.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1311 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There are currently no logon servers available to service the logon request.\n\nLookup forms: 1311, 0x51F, error 1311, ERROR_NO_LOGON_SERVERS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1311"]},{"id":749,"title":"ERROR_NO_SUCH_LOGON_SESSION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1312","0x520","error 1312","ERROR_NO_SUCH_LOGON_SESSION","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","such","logon","session","specified","does","not","exist","may","already","have","been","terminated"],"errorCode":"1312","eventId":"","severity":"High","summary":"A specified logon session does not exist. It may already have been terminated.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1312; use the surrounding log entries to confirm it.","resolution":"1. Record where 1312 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_SUCH_LOGON_SESSION.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1312 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A specified logon session does not exist. It may already have been terminated.\n\nLookup forms: 1312, 0x520, error 1312, ERROR_NO_SUCH_LOGON_SESSION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1312"]},{"id":750,"title":"ERROR_NO_SUCH_PRIVILEGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1313","0x521","error 1313","ERROR_NO_SUCH_PRIVILEGE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","such","privilege","specified","does","not","exist"],"errorCode":"1313","eventId":"","severity":"Low","summary":"A specified privilege does not exist.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1313; use the surrounding log entries to confirm it.","resolution":"1. Record where 1313 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_SUCH_PRIVILEGE.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1313 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A specified privilege does not exist.\n\nLookup forms: 1313, 0x521, error 1313, ERROR_NO_SUCH_PRIVILEGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1313"]},{"id":751,"title":"ERROR_PRIVILEGE_NOT_HELD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1314","0x522","error 1314","ERROR_PRIVILEGE_NOT_HELD","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","privilege","not","held","required","the","client"],"errorCode":"1314","eventId":"","severity":"Low","summary":"A required privilege is not held by the client.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1314; use the surrounding log entries to confirm it.","resolution":"1. Record where 1314 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PRIVILEGE_NOT_HELD.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1314 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A required privilege is not held by the client.\n\nLookup forms: 1314, 0x522, error 1314, ERROR_PRIVILEGE_NOT_HELD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1314"]},{"id":752,"title":"ERROR_INVALID_ACCOUNT_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1315","0x523","error 1315","ERROR_INVALID_ACCOUNT_NAME","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","invalid","account","name","the","provided","not","properly","formed"],"errorCode":"1315","eventId":"","severity":"Low","summary":"The name provided is not a properly formed account name.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1315; use the surrounding log entries to confirm it.","resolution":"1. Record where 1315 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_ACCOUNT_NAME.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1315 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The name provided is not a properly formed account name.\n\nLookup forms: 1315, 0x523, error 1315, ERROR_INVALID_ACCOUNT_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1315"]},{"id":753,"title":"ERROR_USER_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1316","0x524","error 1316","ERROR_USER_EXISTS","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","user","exists","the","specified","account","already"],"errorCode":"1316","eventId":"","severity":"Medium","summary":"The specified account already exists.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1316; use the surrounding log entries to confirm it.","resolution":"1. Record where 1316 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_USER_EXISTS.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1316 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified account already exists.\n\nLookup forms: 1316, 0x524, error 1316, ERROR_USER_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The specified user already exists.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1316"]},{"id":754,"title":"ERROR_NO_SUCH_USER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1317","0x525","error 1317","ERROR_NO_SUCH_USER","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","such","user","the","specified","account","does","not","exist"],"errorCode":"1317","eventId":"","severity":"Low","summary":"The specified account does not exist.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1317; use the surrounding log entries to confirm it.","resolution":"1. Record where 1317 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_SUCH_USER.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1317 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified account does not exist.\n\nLookup forms: 1317, 0x525, error 1317, ERROR_NO_SUCH_USER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The specified user does not exist.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1317"]},{"id":755,"title":"ERROR_GROUP_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1318","0x526","error 1318","ERROR_GROUP_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","group","exists","the","specified","already"],"errorCode":"1318","eventId":"","severity":"Medium","summary":"The specified group already exists.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1318; use the surrounding log entries to confirm it.","resolution":"1. Record where 1318 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_GROUP_EXISTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1318 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified group already exists.\n\nLookup forms: 1318, 0x526, error 1318, ERROR_GROUP_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1318"]},{"id":756,"title":"ERROR_NO_SUCH_GROUP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1319","0x527","error 1319","ERROR_NO_SUCH_GROUP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","such","group","the","specified","does","not","exist"],"errorCode":"1319","eventId":"","severity":"Low","summary":"The specified group does not exist.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1319; use the surrounding log entries to confirm it.","resolution":"1. Record where 1319 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_SUCH_GROUP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1319 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified group does not exist.\n\nLookup forms: 1319, 0x527, error 1319, ERROR_NO_SUCH_GROUP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1319"]},{"id":757,"title":"ERROR_MEMBER_IN_GROUP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1320","0x528","error 1320","ERROR_MEMBER_IN_GROUP","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","member","group","either","the","specified","user","account","already","cannot","deleted","because","contains"],"errorCode":"1320","eventId":"","severity":"Medium","summary":"Either the specified user account is already a member of the specified group, or the specified group cannot be deleted because it contains a member.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1320; use the surrounding log entries to confirm it.","resolution":"1. Record where 1320 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MEMBER_IN_GROUP.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1320 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Either the specified user account is already a member of the specified group, or the specified group cannot be deleted because it contains a member.\n\nLookup forms: 1320, 0x528, error 1320, ERROR_MEMBER_IN_GROUP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1320"]},{"id":758,"title":"ERROR_MEMBER_NOT_IN_GROUP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1321","0x529","error 1321","ERROR_MEMBER_NOT_IN_GROUP","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","member","not","group","the","specified","user","account"],"errorCode":"1321","eventId":"","severity":"Low","summary":"The specified user account is not a member of the specified group account.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1321; use the surrounding log entries to confirm it.","resolution":"1. Record where 1321 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MEMBER_NOT_IN_GROUP.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1321 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified user account is not a member of the specified group account.\n\nLookup forms: 1321, 0x529, error 1321, ERROR_MEMBER_NOT_IN_GROUP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1321"]},{"id":759,"title":"ERROR_LAST_ADMIN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1322","0x52A","error 1322","ERROR_LAST_ADMIN","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","last","admin","this","operation","disallowed","could","result","administration","account","being","disabled","deleted","unable","log"],"errorCode":"1322","eventId":"","severity":"Medium","summary":"This operation is disallowed as it could result in an administration account being disabled, deleted or unable to log on.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1322; use the surrounding log entries to confirm it.","resolution":"1. Record where 1322 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LAST_ADMIN.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1322 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation is disallowed as it could result in an administration account being disabled, deleted or unable to log on.\n\nLookup forms: 1322, 0x52A, error 1322, ERROR_LAST_ADMIN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The last remaining administration account cannot be disabled or deleted.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1322"]},{"id":760,"title":"ERROR_WRONG_PASSWORD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1323","0x52B","error 1323","ERROR_WRONG_PASSWORD","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","wrong","password","unable","update","the","value","provided","current","incorrect"],"errorCode":"1323","eventId":"","severity":"Medium","summary":"Unable to update the password. The value provided as the current password is incorrect.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 1323; use the surrounding log entries to confirm it.","resolution":"1. Record where 1323 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WRONG_PASSWORD.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1323 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to update the password. The value provided as the current password is incorrect.\n\nLookup forms: 1323, 0x52B, error 1323, ERROR_WRONG_PASSWORD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1323"]},{"id":761,"title":"ERROR_ILL_FORMED_PASSWORD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1324","0x52C","error 1324","ERROR_ILL_FORMED_PASSWORD","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","ill","formed","password","unable","update","the","value","provided","for","new","contains","values","that","are","not","allowed","passwords"],"errorCode":"1324","eventId":"","severity":"Medium","summary":"Unable to update the password. The value provided for the new password contains values that are not allowed in passwords.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 1324; use the surrounding log entries to confirm it.","resolution":"1. Record where 1324 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ILL_FORMED_PASSWORD.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1324 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to update the password. The value provided for the new password contains values that are not allowed in passwords.\n\nLookup forms: 1324, 0x52C, error 1324, ERROR_ILL_FORMED_PASSWORD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1324"]},{"id":762,"title":"ERROR_PASSWORD_RESTRICTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1325","0x52D","error 1325","ERROR_PASSWORD_RESTRICTION","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","password","restriction","unable","update","the","value","provided","for","new","does","not","meet","length","complexity","history","requirements","domain"],"errorCode":"1325","eventId":"","severity":"Medium","summary":"Unable to update the password. The value provided for the new password does not meet the length, complexity, or history requirements of the domain.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 1325; use the surrounding log entries to confirm it.","resolution":"1. Record where 1325 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PASSWORD_RESTRICTION.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1325 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to update the password. The value provided for the new password does not meet the length, complexity, or history requirements of the domain.\n\nLookup forms: 1325, 0x52D, error 1325, ERROR_PASSWORD_RESTRICTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Unable to update the password. The value provided for the new password does not meet the length, complexity, or history requirement of the domain.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1325"]},{"id":763,"title":"ERROR_LOGON_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1326","0x52E","error 1326","ERROR_LOGON_FAILURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","logon","failure","the","user","name","password","incorrect"],"errorCode":"1326","eventId":"","severity":"Low","summary":"The user name or password is incorrect.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1326; use the surrounding log entries to confirm it.","resolution":"1. Record where 1326 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOGON_FAILURE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1326 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The user name or password is incorrect.\n\nLookup forms: 1326, 0x52E, error 1326, ERROR_LOGON_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Logon failure: unknown user name or bad password.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1326"]},{"id":764,"title":"ERROR_ACCOUNT_RESTRICTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1327","0x52F","error 1327","ERROR_ACCOUNT_RESTRICTION","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","account","restriction","restrictions","are","preventing","this","user","from","signing","for","example","blank","passwords","aren","allowed","sign","times","limited","policy","has","been","enforced"],"errorCode":"1327","eventId":"","severity":"Low","summary":"Account restrictions are preventing this user from signing in. For example: blank passwords aren't allowed, sign-in times are limited, or a policy restriction has been enforced.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1327; use the surrounding log entries to confirm it.","resolution":"1. Record where 1327 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ACCOUNT_RESTRICTION.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1327 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Account restrictions are preventing this user from signing in. For example: blank passwords aren't allowed, sign-in times are limited, or a policy restriction has been enforced.\n\nLookup forms: 1327, 0x52F, error 1327, ERROR_ACCOUNT_RESTRICTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Logon failure: user account restriction. Possible reasons are blank passwords not allowed, logon hour restrictions, or a policy restriction has been enforced.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1327"]},{"id":765,"title":"ERROR_INVALID_LOGON_HOURS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1328","0x530","error 1328","ERROR_INVALID_LOGON_HOURS","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","invalid","logon","hours","your","account","has","time","restrictions","that","keep","you","from","signing","right","now"],"errorCode":"1328","eventId":"","severity":"Low","summary":"Your account has time restrictions that keep you from signing in right now.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1328; use the surrounding log entries to confirm it.","resolution":"1. Record where 1328 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_LOGON_HOURS.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1328 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Your account has time restrictions that keep you from signing in right now.\n\nLookup forms: 1328, 0x530, error 1328, ERROR_INVALID_LOGON_HOURS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Logon failure: account logon time restriction violation.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1328"]},{"id":766,"title":"ERROR_INVALID_WORKSTATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1329","0x531","error 1329","ERROR_INVALID_WORKSTATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","workstation","this","user","isn","allowed","sign","computer"],"errorCode":"1329","eventId":"","severity":"Low","summary":"This user isn't allowed to sign in to this computer.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1329; use the surrounding log entries to confirm it.","resolution":"1. Record where 1329 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_WORKSTATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1329 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This user isn't allowed to sign in to this computer.\n\nLookup forms: 1329, 0x531, error 1329, ERROR_INVALID_WORKSTATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Logon failure: user not allowed to log on to this computer.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1329"]},{"id":767,"title":"ERROR_PASSWORD_EXPIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1330","0x532","error 1330","ERROR_PASSWORD_EXPIRED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","password","expired","the","for","this","account","has"],"errorCode":"1330","eventId":"","severity":"Low","summary":"The password for this account has expired.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1330; use the surrounding log entries to confirm it.","resolution":"1. Record where 1330 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PASSWORD_EXPIRED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1330 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The password for this account has expired.\n\nLookup forms: 1330, 0x532, error 1330, ERROR_PASSWORD_EXPIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Logon failure: the specified account password has expired.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1330"]},{"id":768,"title":"ERROR_ACCOUNT_DISABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1331","0x533","error 1331","ERROR_ACCOUNT_DISABLED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","account","disabled","this","user","can","sign","because","currently"],"errorCode":"1331","eventId":"","severity":"Low","summary":"This user can't sign in because this account is currently disabled.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1331; use the surrounding log entries to confirm it.","resolution":"1. Record where 1331 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ACCOUNT_DISABLED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1331 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This user can't sign in because this account is currently disabled.\n\nLookup forms: 1331, 0x533, error 1331, ERROR_ACCOUNT_DISABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Logon failure: account currently disabled.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1331"]},{"id":769,"title":"ERROR_NONE_MAPPED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1332","0x534","error 1332","ERROR_NONE_MAPPED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","none","mapped","mapping","between","account","names","and","security","ids","was","done"],"errorCode":"1332","eventId":"","severity":"Low","summary":"No mapping between account names and security IDs was done.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1332; use the surrounding log entries to confirm it.","resolution":"1. Record where 1332 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NONE_MAPPED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1332 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No mapping between account names and security IDs was done.\n\nLookup forms: 1332, 0x534, error 1332, ERROR_NONE_MAPPED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1332"]},{"id":770,"title":"ERROR_TOO_MANY_LUIDS_REQUESTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1333","0x535","error 1333","ERROR_TOO_MANY_LUIDS_REQUESTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","too","many","luids","requested","local","user","identifiers","were","one","time"],"errorCode":"1333","eventId":"","severity":"Low","summary":"Too many local user identifiers (LUIDs) were requested at one time.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1333; use the surrounding log entries to confirm it.","resolution":"1. Record where 1333 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TOO_MANY_LUIDS_REQUESTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1333 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Too many local user identifiers (LUIDs) were requested at one time.\n\nLookup forms: 1333, 0x535, error 1333, ERROR_TOO_MANY_LUIDS_REQUESTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1333"]},{"id":771,"title":"ERROR_LUIDS_EXHAUSTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1334","0x536","error 1334","ERROR_LUIDS_EXHAUSTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","luids","exhausted","more","local","user","identifiers","are","available"],"errorCode":"1334","eventId":"","severity":"Low","summary":"No more local user identifiers (LUIDs) are available.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1334; use the surrounding log entries to confirm it.","resolution":"1. Record where 1334 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LUIDS_EXHAUSTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1334 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No more local user identifiers (LUIDs) are available.\n\nLookup forms: 1334, 0x536, error 1334, ERROR_LUIDS_EXHAUSTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1334"]},{"id":772,"title":"ERROR_INVALID_SUB_AUTHORITY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1335","0x537","error 1335","ERROR_INVALID_SUB_AUTHORITY","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","invalid","sub","authority","the","subauthority","part","security","for","this","particular","use"],"errorCode":"1335","eventId":"","severity":"Medium","summary":"The subauthority part of a security ID is invalid for this particular use.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1335; use the surrounding log entries to confirm it.","resolution":"1. Record where 1335 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_SUB_AUTHORITY.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1335 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The subauthority part of a security ID is invalid for this particular use.\n\nLookup forms: 1335, 0x537, error 1335, ERROR_INVALID_SUB_AUTHORITY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1335"]},{"id":773,"title":"ERROR_INVALID_ACL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1336","0x538","error 1336","ERROR_INVALID_ACL","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","invalid","acl","the","access","control","list","structure"],"errorCode":"1336","eventId":"","severity":"Medium","summary":"The access control list (ACL) structure is invalid.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1336; use the surrounding log entries to confirm it.","resolution":"1. Record where 1336 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_ACL.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1336 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The access control list (ACL) structure is invalid.\n\nLookup forms: 1336, 0x538, error 1336, ERROR_INVALID_ACL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1336"]},{"id":774,"title":"ERROR_INVALID_SID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1337","0x539","error 1337","ERROR_INVALID_SID","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","invalid","sid","the","security","structure"],"errorCode":"1337","eventId":"","severity":"Medium","summary":"The security ID structure is invalid.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1337; use the surrounding log entries to confirm it.","resolution":"1. Record where 1337 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_SID.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1337 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The security ID structure is invalid.\n\nLookup forms: 1337, 0x539, error 1337, ERROR_INVALID_SID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1337"]},{"id":775,"title":"ERROR_INVALID_SECURITY_DESCR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1338","0x53A","error 1338","ERROR_INVALID_SECURITY_DESCR","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","invalid","security","descr","the","descriptor","structure"],"errorCode":"1338","eventId":"","severity":"Medium","summary":"The security descriptor structure is invalid.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1338; use the surrounding log entries to confirm it.","resolution":"1. Record where 1338 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_SECURITY_DESCR.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1338 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The security descriptor structure is invalid.\n\nLookup forms: 1338, 0x53A, error 1338, ERROR_INVALID_SECURITY_DESCR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1338"]},{"id":776,"title":"ERROR_BAD_INHERITANCE_ACL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1340","0x53C","error 1340","ERROR_BAD_INHERITANCE_ACL","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","bad","inheritance","acl","the","inherited","access","control","list","entry","ace","could","not","built"],"errorCode":"1340","eventId":"","severity":"Low","summary":"The inherited access control list (ACL) or access control entry (ACE) could not be built.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1340; use the surrounding log entries to confirm it.","resolution":"1. Record where 1340 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_INHERITANCE_ACL.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1340 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The inherited access control list (ACL) or access control entry (ACE) could not be built.\n\nLookup forms: 1340, 0x53C, error 1340, ERROR_BAD_INHERITANCE_ACL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1340"]},{"id":777,"title":"ERROR_SERVER_DISABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1341","0x53D","error 1341","ERROR_SERVER_DISABLED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","server","disabled","the","currently"],"errorCode":"1341","eventId":"","severity":"Low","summary":"The server is currently disabled.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1341; use the surrounding log entries to confirm it.","resolution":"1. Record where 1341 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVER_DISABLED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1341 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The server is currently disabled.\n\nLookup forms: 1341, 0x53D, error 1341, ERROR_SERVER_DISABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1341"]},{"id":778,"title":"ERROR_SERVER_NOT_DISABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1342","0x53E","error 1342","ERROR_SERVER_NOT_DISABLED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","server","not","disabled","the","currently","enabled"],"errorCode":"1342","eventId":"","severity":"Low","summary":"The server is currently enabled.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1342; use the surrounding log entries to confirm it.","resolution":"1. Record where 1342 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVER_NOT_DISABLED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1342 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The server is currently enabled.\n\nLookup forms: 1342, 0x53E, error 1342, ERROR_SERVER_NOT_DISABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1342"]},{"id":779,"title":"ERROR_INVALID_ID_AUTHORITY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1343","0x53F","error 1343","ERROR_INVALID_ID_AUTHORITY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","authority","the","value","provided","was","for","identifier"],"errorCode":"1343","eventId":"","severity":"Medium","summary":"The value provided was an invalid value for an identifier authority.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1343; use the surrounding log entries to confirm it.","resolution":"1. Record where 1343 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_ID_AUTHORITY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1343 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The value provided was an invalid value for an identifier authority.\n\nLookup forms: 1343, 0x53F, error 1343, ERROR_INVALID_ID_AUTHORITY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1343"]},{"id":780,"title":"ERROR_ALLOTTED_SPACE_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1344","0x540","error 1344","ERROR_ALLOTTED_SPACE_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","allotted","space","exceeded","more","memory","available","for","security","information","updates"],"errorCode":"1344","eventId":"","severity":"Low","summary":"No more memory is available for security information updates.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1344; use the surrounding log entries to confirm it.","resolution":"1. Record where 1344 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Verify the required service or agent is installed, running, and current; repair the component if needed.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ALLOTTED_SPACE_EXCEEDED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1344 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No more memory is available for security information updates.\n\nLookup forms: 1344, 0x540, error 1344, ERROR_ALLOTTED_SPACE_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1344"]},{"id":781,"title":"ERROR_INVALID_GROUP_ATTRIBUTES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1345","0x541","error 1345","ERROR_INVALID_GROUP_ATTRIBUTES","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","group","attributes","the","specified","are","incompatible","with","for","whole"],"errorCode":"1345","eventId":"","severity":"Medium","summary":"The specified attributes are invalid, or incompatible with the attributes for the group as a whole.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1345; use the surrounding log entries to confirm it.","resolution":"1. Record where 1345 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_GROUP_ATTRIBUTES.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1345 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified attributes are invalid, or incompatible with the attributes for the group as a whole.\n\nLookup forms: 1345, 0x541, error 1345, ERROR_INVALID_GROUP_ATTRIBUTES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1345"]},{"id":782,"title":"ERROR_BAD_IMPERSONATION_LEVEL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1346","0x542","error 1346","ERROR_BAD_IMPERSONATION_LEVEL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","bad","impersonation","level","either","required","was","not","provided","the","invalid"],"errorCode":"1346","eventId":"","severity":"Medium","summary":"Either a required impersonation level was not provided, or the provided impersonation level is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1346; use the surrounding log entries to confirm it.","resolution":"1. Record where 1346 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_IMPERSONATION_LEVEL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1346 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Either a required impersonation level was not provided, or the provided impersonation level is invalid.\n\nLookup forms: 1346, 0x542, error 1346, ERROR_BAD_IMPERSONATION_LEVEL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1346"]},{"id":783,"title":"ERROR_CANT_OPEN_ANONYMOUS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1347","0x543","error 1347","ERROR_CANT_OPEN_ANONYMOUS","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","cant","open","anonymous","cannot","level","security","token"],"errorCode":"1347","eventId":"","severity":"Medium","summary":"Cannot open an anonymous level security token.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1347; use the surrounding log entries to confirm it.","resolution":"1. Record where 1347 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANT_OPEN_ANONYMOUS.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1347 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot open an anonymous level security token.\n\nLookup forms: 1347, 0x543, error 1347, ERROR_CANT_OPEN_ANONYMOUS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1347"]},{"id":784,"title":"ERROR_BAD_VALIDATION_CLASS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1348","0x544","error 1348","ERROR_BAD_VALIDATION_CLASS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","bad","validation","class","the","information","requested","was","invalid"],"errorCode":"1348","eventId":"","severity":"Medium","summary":"The validation information class requested was invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1348; use the surrounding log entries to confirm it.","resolution":"1. Record where 1348 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_VALIDATION_CLASS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1348 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The validation information class requested was invalid.\n\nLookup forms: 1348, 0x544, error 1348, ERROR_BAD_VALIDATION_CLASS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1348"]},{"id":785,"title":"ERROR_BAD_TOKEN_TYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1349","0x545","error 1349","ERROR_BAD_TOKEN_TYPE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","bad","token","type","the","inappropriate","for","its","attempted","use"],"errorCode":"1349","eventId":"","severity":"Low","summary":"The type of the token is inappropriate for its attempted use.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1349; use the surrounding log entries to confirm it.","resolution":"1. Record where 1349 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_TOKEN_TYPE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1349 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The type of the token is inappropriate for its attempted use.\n\nLookup forms: 1349, 0x545, error 1349, ERROR_BAD_TOKEN_TYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1349"]},{"id":786,"title":"ERROR_NO_SECURITY_ON_OBJECT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1350","0x546","error 1350","ERROR_NO_SECURITY_ON_OBJECT","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","security","object","unable","perform","operation","that","has","associated"],"errorCode":"1350","eventId":"","severity":"Medium","summary":"Unable to perform a security operation on an object that has no associated security.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1350; use the surrounding log entries to confirm it.","resolution":"1. Record where 1350 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_SECURITY_ON_OBJECT.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1350 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to perform a security operation on an object that has no associated security.\n\nLookup forms: 1350, 0x546, error 1350, ERROR_NO_SECURITY_ON_OBJECT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1350"]},{"id":787,"title":"ERROR_CANT_ACCESS_DOMAIN_INFO","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1351","0x547","error 1351","ERROR_CANT_ACCESS_DOMAIN_INFO","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","cant","access","domain","info","configuration","information","could","not","read","from","the","controller","either","because","machine","unavailable","has","been","denied"],"errorCode":"1351","eventId":"","severity":"Low","summary":"Configuration information could not be read from the domain controller, either because the machine is unavailable, or access has been denied.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1351; use the surrounding log entries to confirm it.","resolution":"1. Record where 1351 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANT_ACCESS_DOMAIN_INFO.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1351 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Configuration information could not be read from the domain controller, either because the machine is unavailable, or access has been denied.\n\nLookup forms: 1351, 0x547, error 1351, ERROR_CANT_ACCESS_DOMAIN_INFO. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1351"]},{"id":788,"title":"ERROR_INVALID_SERVER_STATE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1352","0x548","error 1352","ERROR_INVALID_SERVER_STATE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","invalid","server","state","the","security","account","manager","sam","local","authority","lsa","was","wrong","perform","operation"],"errorCode":"1352","eventId":"","severity":"Low","summary":"The security account manager (SAM) or local security authority (LSA) server was in the wrong state to perform the security operation.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1352; use the surrounding log entries to confirm it.","resolution":"1. Record where 1352 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_SERVER_STATE.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1352 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The security account manager (SAM) or local security authority (LSA) server was in the wrong state to perform the security operation.\n\nLookup forms: 1352, 0x548, error 1352, ERROR_INVALID_SERVER_STATE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1352"]},{"id":789,"title":"ERROR_INVALID_DOMAIN_STATE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1353","0x549","error 1353","ERROR_INVALID_DOMAIN_STATE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","invalid","domain","state","the","was","wrong","perform","security","operation"],"errorCode":"1353","eventId":"","severity":"Low","summary":"The domain was in the wrong state to perform the security operation.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1353; use the surrounding log entries to confirm it.","resolution":"1. Record where 1353 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_DOMAIN_STATE.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1353 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The domain was in the wrong state to perform the security operation.\n\nLookup forms: 1353, 0x549, error 1353, ERROR_INVALID_DOMAIN_STATE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1353"]},{"id":790,"title":"ERROR_INVALID_DOMAIN_ROLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1354","0x54A","error 1354","ERROR_INVALID_DOMAIN_ROLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","domain","role","this","operation","only","allowed","for","the","primary","controller"],"errorCode":"1354","eventId":"","severity":"Low","summary":"This operation is only allowed for the Primary Domain Controller of the domain.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1354; use the surrounding log entries to confirm it.","resolution":"1. Record where 1354 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_DOMAIN_ROLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1354 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation is only allowed for the Primary Domain Controller of the domain.\n\nLookup forms: 1354, 0x54A, error 1354, ERROR_INVALID_DOMAIN_ROLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1354"]},{"id":791,"title":"ERROR_NO_SUCH_DOMAIN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1355","0x54B","error 1355","ERROR_NO_SUCH_DOMAIN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","such","domain","the","specified","either","does","not","exist","could","contacted"],"errorCode":"1355","eventId":"","severity":"Low","summary":"The specified domain either does not exist or could not be contacted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1355; use the surrounding log entries to confirm it.","resolution":"1. Record where 1355 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_SUCH_DOMAIN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1355 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified domain either does not exist or could not be contacted.\n\nLookup forms: 1355, 0x54B, error 1355, ERROR_NO_SUCH_DOMAIN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1355"]},{"id":792,"title":"ERROR_DOMAIN_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1356","0x54C","error 1356","ERROR_DOMAIN_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","domain","exists","the","specified","already"],"errorCode":"1356","eventId":"","severity":"Medium","summary":"The specified domain already exists.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1356; use the surrounding log entries to confirm it.","resolution":"1. Record where 1356 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DOMAIN_EXISTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1356 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified domain already exists.\n\nLookup forms: 1356, 0x54C, error 1356, ERROR_DOMAIN_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1356"]},{"id":793,"title":"ERROR_DOMAIN_LIMIT_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1357","0x54D","error 1357","ERROR_DOMAIN_LIMIT_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","domain","limit","exceeded","attempt","was","made","exceed","the","number","domains","per","server"],"errorCode":"1357","eventId":"","severity":"Low","summary":"An attempt was made to exceed the limit on the number of domains per server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1357; use the surrounding log entries to confirm it.","resolution":"1. Record where 1357 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DOMAIN_LIMIT_EXCEEDED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1357 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt was made to exceed the limit on the number of domains per server.\n\nLookup forms: 1357, 0x54D, error 1357, ERROR_DOMAIN_LIMIT_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1357"]},{"id":794,"title":"ERROR_INTERNAL_DB_CORRUPTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1358","0x54E","error 1358","ERROR_INTERNAL_DB_CORRUPTION","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","internal","corruption","unable","complete","the","requested","operation","because","either","catastrophic","media","failure","data","structure","disk"],"errorCode":"1358","eventId":"","severity":"Critical","summary":"Unable to complete the requested operation because of either a catastrophic media failure or a data structure corruption on the disk.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1358; use the surrounding log entries to confirm it.","resolution":"1. Record where 1358 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INTERNAL_DB_CORRUPTION.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1358 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to complete the requested operation because of either a catastrophic media failure or a data structure corruption on the disk.\n\nLookup forms: 1358, 0x54E, error 1358, ERROR_INTERNAL_DB_CORRUPTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1358"]},{"id":795,"title":"ERROR_INTERNAL_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1359","0x54F","error 1359","ERROR_INTERNAL_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","internal","occurred"],"errorCode":"1359","eventId":"","severity":"Low","summary":"An internal error occurred.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1359; use the surrounding log entries to confirm it.","resolution":"1. Record where 1359 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INTERNAL_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1359 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An internal error occurred.\n\nLookup forms: 1359, 0x54F, error 1359, ERROR_INTERNAL_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1359"]},{"id":796,"title":"ERROR_GENERIC_NOT_MAPPED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1360","0x550","error 1360","ERROR_GENERIC_NOT_MAPPED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","generic","not","mapped","access","types","were","contained","mask","which","should","already","nongeneric"],"errorCode":"1360","eventId":"","severity":"Low","summary":"Generic access types were contained in an access mask which should already be mapped to nongeneric types.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1360; use the surrounding log entries to confirm it.","resolution":"1. Record where 1360 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_GENERIC_NOT_MAPPED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1360 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Generic access types were contained in an access mask which should already be mapped to nongeneric types.\n\nLookup forms: 1360, 0x550, error 1360, ERROR_GENERIC_NOT_MAPPED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1360"]},{"id":797,"title":"ERROR_BAD_DESCRIPTOR_FORMAT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1361","0x551","error 1361","ERROR_BAD_DESCRIPTOR_FORMAT","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","bad","descriptor","format","security","not","the","right","absolute","self","relative"],"errorCode":"1361","eventId":"","severity":"Low","summary":"A security descriptor is not in the right format (absolute or self-relative).","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1361; use the surrounding log entries to confirm it.","resolution":"1. Record where 1361 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_DESCRIPTOR_FORMAT.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1361 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A security descriptor is not in the right format (absolute or self-relative).\n\nLookup forms: 1361, 0x551, error 1361, ERROR_BAD_DESCRIPTOR_FORMAT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1361"]},{"id":798,"title":"ERROR_NOT_LOGON_PROCESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1362","0x552","error 1362","ERROR_NOT_LOGON_PROCESS","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","not","logon","process","the","requested","action","restricted","for","use","processes","only","calling","has","registered"],"errorCode":"1362","eventId":"","severity":"High","summary":"The requested action is restricted for use by logon processes only. The calling process has not registered as a logon process.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1362; use the surrounding log entries to confirm it.","resolution":"1. Record where 1362 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_LOGON_PROCESS.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1362 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested action is restricted for use by logon processes only. The calling process has not registered as a logon process.\n\nLookup forms: 1362, 0x552, error 1362, ERROR_NOT_LOGON_PROCESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1362"]},{"id":799,"title":"ERROR_LOGON_SESSION_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1363","0x553","error 1363","ERROR_LOGON_SESSION_EXISTS","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","logon","session","exists","cannot","start","new","with","that","already","use"],"errorCode":"1363","eventId":"","severity":"High","summary":"Cannot start a new logon session with an ID that is already in use.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1363; use the surrounding log entries to confirm it.","resolution":"1. Record where 1363 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOGON_SESSION_EXISTS.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1363 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot start a new logon session with an ID that is already in use.\n\nLookup forms: 1363, 0x553, error 1363, ERROR_LOGON_SESSION_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1363"]},{"id":800,"title":"ERROR_NO_SUCH_PACKAGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1364","0x554","error 1364","ERROR_NO_SUCH_PACKAGE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","such","package","specified","authentication","unknown"],"errorCode":"1364","eventId":"","severity":"High","summary":"A specified authentication package is unknown.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1364; use the surrounding log entries to confirm it.","resolution":"1. Record where 1364 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_SUCH_PACKAGE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1364 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A specified authentication package is unknown.\n\nLookup forms: 1364, 0x554, error 1364, ERROR_NO_SUCH_PACKAGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1364"]},{"id":801,"title":"ERROR_BAD_LOGON_SESSION_STATE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1365","0x555","error 1365","ERROR_BAD_LOGON_SESSION_STATE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","bad","logon","session","state","the","not","that","consistent","with","requested","operation"],"errorCode":"1365","eventId":"","severity":"High","summary":"The logon session is not in a state that is consistent with the requested operation.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1365; use the surrounding log entries to confirm it.","resolution":"1. Record where 1365 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_LOGON_SESSION_STATE.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1365 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The logon session is not in a state that is consistent with the requested operation.\n\nLookup forms: 1365, 0x555, error 1365, ERROR_BAD_LOGON_SESSION_STATE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1365"]},{"id":802,"title":"ERROR_LOGON_SESSION_COLLISION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1366","0x556","error 1366","ERROR_LOGON_SESSION_COLLISION","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","logon","session","collision","the","already","use"],"errorCode":"1366","eventId":"","severity":"High","summary":"The logon session ID is already in use.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1366; use the surrounding log entries to confirm it.","resolution":"1. Record where 1366 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOGON_SESSION_COLLISION.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1366 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The logon session ID is already in use.\n\nLookup forms: 1366, 0x556, error 1366, ERROR_LOGON_SESSION_COLLISION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1366"]},{"id":803,"title":"ERROR_INVALID_LOGON_TYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1367","0x557","error 1367","ERROR_INVALID_LOGON_TYPE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","invalid","logon","type","request","contained","value"],"errorCode":"1367","eventId":"","severity":"High","summary":"A logon request contained an invalid logon type value.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1367; use the surrounding log entries to confirm it.","resolution":"1. Record where 1367 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_LOGON_TYPE.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1367 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A logon request contained an invalid logon type value.\n\nLookup forms: 1367, 0x557, error 1367, ERROR_INVALID_LOGON_TYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1367"]},{"id":804,"title":"ERROR_CANNOT_IMPERSONATE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1368","0x558","error 1368","ERROR_CANNOT_IMPERSONATE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cannot","impersonate","unable","using","named","pipe","until","data","has","been","read","from","that"],"errorCode":"1368","eventId":"","severity":"Medium","summary":"Unable to impersonate using a named pipe until data has been read from that pipe.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1368; use the surrounding log entries to confirm it.","resolution":"1. Record where 1368 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANNOT_IMPERSONATE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1368 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to impersonate using a named pipe until data has been read from that pipe.\n\nLookup forms: 1368, 0x558, error 1368, ERROR_CANNOT_IMPERSONATE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1368"]},{"id":805,"title":"ERROR_RXACT_INVALID_STATE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1369","0x559","error 1369","ERROR_RXACT_INVALID_STATE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","rxact","invalid","state","the","transaction","registry","subtree","incompatible","with","requested","operation"],"errorCode":"1369","eventId":"","severity":"Low","summary":"The transaction state of a registry subtree is incompatible with the requested operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1369; use the surrounding log entries to confirm it.","resolution":"1. Record where 1369 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RXACT_INVALID_STATE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1369 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The transaction state of a registry subtree is incompatible with the requested operation.\n\nLookup forms: 1369, 0x559, error 1369, ERROR_RXACT_INVALID_STATE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1369"]},{"id":806,"title":"ERROR_RXACT_COMMIT_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1370","0x55A","error 1370","ERROR_RXACT_COMMIT_FAILURE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","rxact","commit","failure","internal","security","database","corruption","has","been","encountered"],"errorCode":"1370","eventId":"","severity":"Critical","summary":"An internal security database corruption has been encountered.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1370; use the surrounding log entries to confirm it.","resolution":"1. Record where 1370 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RXACT_COMMIT_FAILURE.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1370 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An internal security database corruption has been encountered.\n\nLookup forms: 1370, 0x55A, error 1370, ERROR_RXACT_COMMIT_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1370"]},{"id":807,"title":"ERROR_SPECIAL_ACCOUNT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1371","0x55B","error 1371","ERROR_SPECIAL_ACCOUNT","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","special","account","cannot","perform","this","operation","built","accounts"],"errorCode":"1371","eventId":"","severity":"Medium","summary":"Cannot perform this operation on built-in accounts.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1371; use the surrounding log entries to confirm it.","resolution":"1. Record where 1371 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SPECIAL_ACCOUNT.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1371 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot perform this operation on built-in accounts.\n\nLookup forms: 1371, 0x55B, error 1371, ERROR_SPECIAL_ACCOUNT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1371"]},{"id":808,"title":"ERROR_SPECIAL_GROUP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1372","0x55C","error 1372","ERROR_SPECIAL_GROUP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","special","group","cannot","perform","this","operation","built"],"errorCode":"1372","eventId":"","severity":"Medium","summary":"Cannot perform this operation on this built-in special group.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1372; use the surrounding log entries to confirm it.","resolution":"1. Record where 1372 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SPECIAL_GROUP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1372 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot perform this operation on this built-in special group.\n\nLookup forms: 1372, 0x55C, error 1372, ERROR_SPECIAL_GROUP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1372"]},{"id":809,"title":"ERROR_SPECIAL_USER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1373","0x55D","error 1373","ERROR_SPECIAL_USER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","special","user","cannot","perform","this","operation","built"],"errorCode":"1373","eventId":"","severity":"Medium","summary":"Cannot perform this operation on this built-in special user.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1373; use the surrounding log entries to confirm it.","resolution":"1. Record where 1373 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SPECIAL_USER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1373 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot perform this operation on this built-in special user.\n\nLookup forms: 1373, 0x55D, error 1373, ERROR_SPECIAL_USER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1373"]},{"id":810,"title":"ERROR_MEMBERS_PRIMARY_GROUP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1374","0x55E","error 1374","ERROR_MEMBERS_PRIMARY_GROUP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","members","primary","group","the","user","cannot","removed","from","because","currently"],"errorCode":"1374","eventId":"","severity":"Medium","summary":"The user cannot be removed from a group because the group is currently the user's primary group.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1374; use the surrounding log entries to confirm it.","resolution":"1. Record where 1374 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MEMBERS_PRIMARY_GROUP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1374 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The user cannot be removed from a group because the group is currently the user's primary group.\n\nLookup forms: 1374, 0x55E, error 1374, ERROR_MEMBERS_PRIMARY_GROUP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1374"]},{"id":811,"title":"ERROR_TOKEN_ALREADY_IN_USE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1375","0x55F","error 1375","ERROR_TOKEN_ALREADY_IN_USE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","token","already","use","the","primary"],"errorCode":"1375","eventId":"","severity":"Low","summary":"The token is already in use as a primary token.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1375; use the surrounding log entries to confirm it.","resolution":"1. Record where 1375 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TOKEN_ALREADY_IN_USE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1375 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The token is already in use as a primary token.\n\nLookup forms: 1375, 0x55F, error 1375, ERROR_TOKEN_ALREADY_IN_USE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1375"]},{"id":812,"title":"ERROR_NO_SUCH_ALIAS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1376","0x560","error 1376","ERROR_NO_SUCH_ALIAS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","such","alias","the","specified","local","group","does","not","exist"],"errorCode":"1376","eventId":"","severity":"Low","summary":"The specified local group does not exist.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1376; use the surrounding log entries to confirm it.","resolution":"1. Record where 1376 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_SUCH_ALIAS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1376 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified local group does not exist.\n\nLookup forms: 1376, 0x560, error 1376, ERROR_NO_SUCH_ALIAS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1376"]},{"id":813,"title":"ERROR_MEMBER_NOT_IN_ALIAS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1377","0x561","error 1377","ERROR_MEMBER_NOT_IN_ALIAS","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","member","not","alias","the","specified","account","name","group"],"errorCode":"1377","eventId":"","severity":"Low","summary":"The specified account name is not a member of the group.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1377; use the surrounding log entries to confirm it.","resolution":"1. Record where 1377 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MEMBER_NOT_IN_ALIAS.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1377 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified account name is not a member of the group.\n\nLookup forms: 1377, 0x561, error 1377, ERROR_MEMBER_NOT_IN_ALIAS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The specified account name is not a member of the local group.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1377"]},{"id":814,"title":"ERROR_MEMBER_IN_ALIAS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1378","0x562","error 1378","ERROR_MEMBER_IN_ALIAS","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","member","alias","the","specified","account","name","already","group"],"errorCode":"1378","eventId":"","severity":"Low","summary":"The specified account name is already a member of the group.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1378; use the surrounding log entries to confirm it.","resolution":"1. Record where 1378 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MEMBER_IN_ALIAS.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1378 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified account name is already a member of the group.\n\nLookup forms: 1378, 0x562, error 1378, ERROR_MEMBER_IN_ALIAS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The specified account name is already a member of the local group.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1378"]},{"id":815,"title":"ERROR_ALIAS_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1379","0x563","error 1379","ERROR_ALIAS_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","alias","exists","the","specified","local","group","already"],"errorCode":"1379","eventId":"","severity":"Medium","summary":"The specified local group already exists.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1379; use the surrounding log entries to confirm it.","resolution":"1. Record where 1379 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ALIAS_EXISTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1379 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified local group already exists.\n\nLookup forms: 1379, 0x563, error 1379, ERROR_ALIAS_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1379"]},{"id":816,"title":"ERROR_LOGON_NOT_GRANTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1380","0x564","error 1380","ERROR_LOGON_NOT_GRANTED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","logon","not","granted","failure","the","user","has","been","requested","type","this","computer"],"errorCode":"1380","eventId":"","severity":"High","summary":"Logon failure: the user has not been granted the requested logon type at this computer.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1380; use the surrounding log entries to confirm it.","resolution":"1. Record where 1380 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOGON_NOT_GRANTED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1380 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Logon failure: the user has not been granted the requested logon type at this computer.\n\nLookup forms: 1380, 0x564, error 1380, ERROR_LOGON_NOT_GRANTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1380"]},{"id":817,"title":"ERROR_TOO_MANY_SECRETS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1381","0x565","error 1381","ERROR_TOO_MANY_SECRETS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","too","many","secrets","the","maximum","number","that","may","stored","single","system","has","been","exceeded"],"errorCode":"1381","eventId":"","severity":"Low","summary":"The maximum number of secrets that may be stored in a single system has been exceeded.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1381; use the surrounding log entries to confirm it.","resolution":"1. Record where 1381 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TOO_MANY_SECRETS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1381 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The maximum number of secrets that may be stored in a single system has been exceeded.\n\nLookup forms: 1381, 0x565, error 1381, ERROR_TOO_MANY_SECRETS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1381"]},{"id":818,"title":"ERROR_SECRET_TOO_LONG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1382","0x566","error 1382","ERROR_SECRET_TOO_LONG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","secret","too","long","the","length","exceeds","maximum","allowed"],"errorCode":"1382","eventId":"","severity":"Low","summary":"The length of a secret exceeds the maximum length allowed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1382; use the surrounding log entries to confirm it.","resolution":"1. Record where 1382 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SECRET_TOO_LONG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1382 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The length of a secret exceeds the maximum length allowed.\n\nLookup forms: 1382, 0x566, error 1382, ERROR_SECRET_TOO_LONG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1382"]},{"id":819,"title":"ERROR_INTERNAL_DB_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1383","0x567","error 1383","ERROR_INTERNAL_DB_ERROR","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","internal","the","local","security","authority","database","contains","inconsistency"],"errorCode":"1383","eventId":"","severity":"Low","summary":"The local security authority database contains an internal inconsistency.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1383; use the surrounding log entries to confirm it.","resolution":"1. Record where 1383 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INTERNAL_DB_ERROR.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1383 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The local security authority database contains an internal inconsistency.\n\nLookup forms: 1383, 0x567, error 1383, ERROR_INTERNAL_DB_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1383"]},{"id":820,"title":"ERROR_TOO_MANY_CONTEXT_IDS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1384","0x568","error 1384","ERROR_TOO_MANY_CONTEXT_IDS","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","too","many","context","ids","during","logon","attempt","the","user","security","accumulated"],"errorCode":"1384","eventId":"","severity":"High","summary":"During a logon attempt, the user's security context accumulated too many security IDs.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1384; use the surrounding log entries to confirm it.","resolution":"1. Record where 1384 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TOO_MANY_CONTEXT_IDS.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1384 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: During a logon attempt, the user's security context accumulated too many security IDs.\n\nLookup forms: 1384, 0x568, error 1384, ERROR_TOO_MANY_CONTEXT_IDS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1384"]},{"id":821,"title":"ERROR_LOGON_TYPE_NOT_GRANTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1385","0x569","error 1385","ERROR_LOGON_TYPE_NOT_GRANTED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","logon","type","not","granted","failure","the","user","has","been","requested","this","computer"],"errorCode":"1385","eventId":"","severity":"High","summary":"Logon failure: the user has not been granted the requested logon type at this computer.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1385; use the surrounding log entries to confirm it.","resolution":"1. Record where 1385 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOGON_TYPE_NOT_GRANTED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1385 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Logon failure: the user has not been granted the requested logon type at this computer.\n\nLookup forms: 1385, 0x569, error 1385, ERROR_LOGON_TYPE_NOT_GRANTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1385"]},{"id":822,"title":"ERROR_NT_CROSS_ENCRYPTION_REQUIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1386","0x56A","error 1386","ERROR_NT_CROSS_ENCRYPTION_REQUIRED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cross","encryption","required","encrypted","password","necessary","change","user"],"errorCode":"1386","eventId":"","severity":"Low","summary":"A cross-encrypted password is necessary to change a user password.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1386; use the surrounding log entries to confirm it.","resolution":"1. Record where 1386 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NT_CROSS_ENCRYPTION_REQUIRED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1386 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A cross-encrypted password is necessary to change a user password.\n\nLookup forms: 1386, 0x56A, error 1386, ERROR_NT_CROSS_ENCRYPTION_REQUIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1386"]},{"id":823,"title":"ERROR_NO_SUCH_MEMBER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1387","0x56B","error 1387","ERROR_NO_SUCH_MEMBER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","such","member","could","not","added","removed","from","the","local","group","because","does","exist"],"errorCode":"1387","eventId":"","severity":"Low","summary":"A member could not be added to or removed from the local group because the member does not exist.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1387; use the surrounding log entries to confirm it.","resolution":"1. Record where 1387 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_SUCH_MEMBER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1387 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A member could not be added to or removed from the local group because the member does not exist.\n\nLookup forms: 1387, 0x56B, error 1387, ERROR_NO_SUCH_MEMBER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): A new member could not be added to or removed from the local group because the member does not exist.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1387"]},{"id":824,"title":"ERROR_INVALID_MEMBER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1388","0x56C","error 1388","ERROR_INVALID_MEMBER","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","invalid","member","new","could","not","added","local","group","because","the","has","wrong","account","type"],"errorCode":"1388","eventId":"","severity":"Low","summary":"A new member could not be added to a local group because the member has the wrong account type.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1388; use the surrounding log entries to confirm it.","resolution":"1. Record where 1388 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_MEMBER.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1388 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A new member could not be added to a local group because the member has the wrong account type.\n\nLookup forms: 1388, 0x56C, error 1388, ERROR_INVALID_MEMBER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1388"]},{"id":825,"title":"ERROR_TOO_MANY_SIDS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1389","0x56D","error 1389","ERROR_TOO_MANY_SIDS","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","too","many","sids","security","ids","have","been","specified"],"errorCode":"1389","eventId":"","severity":"Low","summary":"Too many security IDs have been specified.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1389; use the surrounding log entries to confirm it.","resolution":"1. Record where 1389 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TOO_MANY_SIDS.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1389 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Too many security IDs have been specified.\n\nLookup forms: 1389, 0x56D, error 1389, ERROR_TOO_MANY_SIDS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1389"]},{"id":826,"title":"ERROR_LM_CROSS_ENCRYPTION_REQUIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1390","0x56E","error 1390","ERROR_LM_CROSS_ENCRYPTION_REQUIRED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cross","encryption","required","encrypted","password","necessary","change","this","user"],"errorCode":"1390","eventId":"","severity":"Low","summary":"A cross-encrypted password is necessary to change this user password.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1390; use the surrounding log entries to confirm it.","resolution":"1. Record where 1390 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LM_CROSS_ENCRYPTION_REQUIRED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1390 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A cross-encrypted password is necessary to change this user password.\n\nLookup forms: 1390, 0x56E, error 1390, ERROR_LM_CROSS_ENCRYPTION_REQUIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1390"]},{"id":827,"title":"ERROR_NO_INHERITANCE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1391","0x56F","error 1391","ERROR_NO_INHERITANCE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","inheritance","indicates","acl","contains","inheritable","components"],"errorCode":"1391","eventId":"","severity":"Low","summary":"Indicates an ACL contains no inheritable components.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1391; use the surrounding log entries to confirm it.","resolution":"1. Record where 1391 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_INHERITANCE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1391 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Indicates an ACL contains no inheritable components.\n\nLookup forms: 1391, 0x56F, error 1391, ERROR_NO_INHERITANCE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1391"]},{"id":828,"title":"ERROR_FILE_CORRUPT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1392","0x570","error 1392","ERROR_FILE_CORRUPT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","file","corrupt","the","directory","corrupted","and","unreadable"],"errorCode":"1392","eventId":"","severity":"Critical","summary":"The file or directory is corrupted and unreadable.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1392; use the surrounding log entries to confirm it.","resolution":"1. Record where 1392 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FILE_CORRUPT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1392 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file or directory is corrupted and unreadable.\n\nLookup forms: 1392, 0x570, error 1392, ERROR_FILE_CORRUPT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1392"]},{"id":829,"title":"ERROR_DISK_CORRUPT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1393","0x571","error 1393","ERROR_DISK_CORRUPT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","disk","corrupt","the","structure","corrupted","and","unreadable"],"errorCode":"1393","eventId":"","severity":"Critical","summary":"The disk structure is corrupted and unreadable.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1393; use the surrounding log entries to confirm it.","resolution":"1. Record where 1393 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DISK_CORRUPT.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1393 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The disk structure is corrupted and unreadable.\n\nLookup forms: 1393, 0x571, error 1393, ERROR_DISK_CORRUPT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1393"]},{"id":830,"title":"ERROR_NO_USER_SESSION_KEY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1394","0x572","error 1394","ERROR_NO_USER_SESSION_KEY","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","user","session","key","there","for","the","specified","logon"],"errorCode":"1394","eventId":"","severity":"High","summary":"There is no user session key for the specified logon session.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1394; use the surrounding log entries to confirm it.","resolution":"1. Record where 1394 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_USER_SESSION_KEY.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1394 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There is no user session key for the specified logon session.\n\nLookup forms: 1394, 0x572, error 1394, ERROR_NO_USER_SESSION_KEY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1394"]},{"id":831,"title":"ERROR_LICENSE_QUOTA_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1395","0x573","error 1395","ERROR_LICENSE_QUOTA_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","license","quota","exceeded","the","service","being","accessed","licensed","for","particular","number","connections","more","can","made","this","time","because","there","are","already","many","accept"],"errorCode":"1395","eventId":"","severity":"High","summary":"The service being accessed is licensed for a particular number of connections. No more connections can be made to the service at this time because there are already as many connections as the service can accept.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1395; use the surrounding log entries to confirm it.","resolution":"1. Record where 1395 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Verify the required service or agent is installed, running, and current; repair the component if needed.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LICENSE_QUOTA_EXCEEDED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1395 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The service being accessed is licensed for a particular number of connections. No more connections can be made to the service at this time because there are already as many connections as the service can accept.\n\nLookup forms: 1395, 0x573, error 1395, ERROR_LICENSE_QUOTA_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1395"]},{"id":832,"title":"ERROR_WRONG_TARGET_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1396","0x574","error 1396","ERROR_WRONG_TARGET_NAME","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","wrong","target","name","the","account","incorrect"],"errorCode":"1396","eventId":"","severity":"Low","summary":"The target account name is incorrect.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1396; use the surrounding log entries to confirm it.","resolution":"1. Record where 1396 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WRONG_TARGET_NAME.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1396 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The target account name is incorrect.\n\nLookup forms: 1396, 0x574, error 1396, ERROR_WRONG_TARGET_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Logon Failure: The target account name is incorrect.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1396"]},{"id":833,"title":"ERROR_MUTUAL_AUTH_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1397","0x575","error 1397","ERROR_MUTUAL_AUTH_FAILED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","mutual","auth","failed","authentication","the","server","password","out","date","domain","controller"],"errorCode":"1397","eventId":"","severity":"High","summary":"Mutual Authentication failed. The server's password is out of date at the domain controller.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1397; use the surrounding log entries to confirm it.","resolution":"1. Record where 1397 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MUTUAL_AUTH_FAILED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1397 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Mutual Authentication failed. The server's password is out of date at the domain controller.\n\nLookup forms: 1397, 0x575, error 1397, ERROR_MUTUAL_AUTH_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1397"]},{"id":834,"title":"ERROR_TIME_SKEW","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1398","0x576","error 1398","ERROR_TIME_SKEW","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","time","skew","there","and","date","difference","between","the","client","server"],"errorCode":"1398","eventId":"","severity":"Low","summary":"There is a time and/or date difference between the client and server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1398; use the surrounding log entries to confirm it.","resolution":"1. Record where 1398 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TIME_SKEW.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1398 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There is a time and/or date difference between the client and server.\n\nLookup forms: 1398, 0x576, error 1398, ERROR_TIME_SKEW. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1398"]},{"id":835,"title":"ERROR_CURRENT_DOMAIN_NOT_ALLOWED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1399","0x577","error 1399","ERROR_CURRENT_DOMAIN_NOT_ALLOWED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","current","domain","not","allowed","this","operation","cannot","performed","the"],"errorCode":"1399","eventId":"","severity":"Medium","summary":"This operation cannot be performed on the current domain.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1399; use the surrounding log entries to confirm it.","resolution":"1. Record where 1399 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CURRENT_DOMAIN_NOT_ALLOWED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1399 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation cannot be performed on the current domain.\n\nLookup forms: 1399, 0x577, error 1399, ERROR_CURRENT_DOMAIN_NOT_ALLOWED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1399"]},{"id":836,"title":"ERROR_INVALID_WINDOW_HANDLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1400","0x578","error 1400","ERROR_INVALID_WINDOW_HANDLE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","invalid","window","handle"],"errorCode":"1400","eventId":"","severity":"Medium","summary":"Invalid window handle.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1400; use the surrounding log entries to confirm it.","resolution":"1. Record where 1400 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_WINDOW_HANDLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1400 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid window handle.\n\nLookup forms: 1400, 0x578, error 1400, ERROR_INVALID_WINDOW_HANDLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1400"]},{"id":837,"title":"ERROR_INVALID_MENU_HANDLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1401","0x579","error 1401","ERROR_INVALID_MENU_HANDLE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","invalid","menu","handle"],"errorCode":"1401","eventId":"","severity":"Medium","summary":"Invalid menu handle.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1401; use the surrounding log entries to confirm it.","resolution":"1. Record where 1401 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_MENU_HANDLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1401 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid menu handle.\n\nLookup forms: 1401, 0x579, error 1401, ERROR_INVALID_MENU_HANDLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1401"]},{"id":838,"title":"ERROR_INVALID_CURSOR_HANDLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1402","0x57A","error 1402","ERROR_INVALID_CURSOR_HANDLE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","invalid","cursor","handle"],"errorCode":"1402","eventId":"","severity":"Medium","summary":"Invalid cursor handle.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1402; use the surrounding log entries to confirm it.","resolution":"1. Record where 1402 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_CURSOR_HANDLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1402 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid cursor handle.\n\nLookup forms: 1402, 0x57A, error 1402, ERROR_INVALID_CURSOR_HANDLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1402"]},{"id":839,"title":"ERROR_INVALID_ACCEL_HANDLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1403","0x57B","error 1403","ERROR_INVALID_ACCEL_HANDLE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","invalid","accel","handle","accelerator","table"],"errorCode":"1403","eventId":"","severity":"Medium","summary":"Invalid accelerator table handle.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1403; use the surrounding log entries to confirm it.","resolution":"1. Record where 1403 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_ACCEL_HANDLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1403 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid accelerator table handle.\n\nLookup forms: 1403, 0x57B, error 1403, ERROR_INVALID_ACCEL_HANDLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1403"]},{"id":840,"title":"ERROR_INVALID_HOOK_HANDLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1404","0x57C","error 1404","ERROR_INVALID_HOOK_HANDLE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","invalid","hook","handle"],"errorCode":"1404","eventId":"","severity":"Medium","summary":"Invalid hook handle.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1404; use the surrounding log entries to confirm it.","resolution":"1. Record where 1404 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_HOOK_HANDLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1404 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid hook handle.\n\nLookup forms: 1404, 0x57C, error 1404, ERROR_INVALID_HOOK_HANDLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1404"]},{"id":841,"title":"ERROR_INVALID_DWP_HANDLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1405","0x57D","error 1405","ERROR_INVALID_DWP_HANDLE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","invalid","dwp","handle","multiple","window","position","structure"],"errorCode":"1405","eventId":"","severity":"Medium","summary":"Invalid handle to a multiple-window position structure.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1405; use the surrounding log entries to confirm it.","resolution":"1. Record where 1405 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_DWP_HANDLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1405 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid handle to a multiple-window position structure.\n\nLookup forms: 1405, 0x57D, error 1405, ERROR_INVALID_DWP_HANDLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1405"]},{"id":842,"title":"ERROR_TLW_WITH_WSCHILD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1406","0x57E","error 1406","ERROR_TLW_WITH_WSCHILD","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","tlw","with","wschild","cannot","create","top","level","child","window"],"errorCode":"1406","eventId":"","severity":"Medium","summary":"Cannot create a top-level child window.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1406; use the surrounding log entries to confirm it.","resolution":"1. Record where 1406 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TLW_WITH_WSCHILD.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1406 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot create a top-level child window.\n\nLookup forms: 1406, 0x57E, error 1406, ERROR_TLW_WITH_WSCHILD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1406"]},{"id":843,"title":"ERROR_CANNOT_FIND_WND_CLASS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1407","0x57F","error 1407","ERROR_CANNOT_FIND_WND_CLASS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cannot","find","wnd","class","window"],"errorCode":"1407","eventId":"","severity":"Medium","summary":"Cannot find window class.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1407; use the surrounding log entries to confirm it.","resolution":"1. Record where 1407 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANNOT_FIND_WND_CLASS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1407 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot find window class.\n\nLookup forms: 1407, 0x57F, error 1407, ERROR_CANNOT_FIND_WND_CLASS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1407"]},{"id":844,"title":"ERROR_WINDOW_OF_OTHER_THREAD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1408","0x580","error 1408","ERROR_WINDOW_OF_OTHER_THREAD","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","window","other","thread","invalid","belongs"],"errorCode":"1408","eventId":"","severity":"Medium","summary":"Invalid window; it belongs to other thread.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1408; use the surrounding log entries to confirm it.","resolution":"1. Record where 1408 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WINDOW_OF_OTHER_THREAD.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1408 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid window; it belongs to other thread.\n\nLookup forms: 1408, 0x580, error 1408, ERROR_WINDOW_OF_OTHER_THREAD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1408"]},{"id":845,"title":"ERROR_HOTKEY_ALREADY_REGISTERED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1409","0x581","error 1409","ERROR_HOTKEY_ALREADY_REGISTERED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","hotkey","already","registered","hot","key"],"errorCode":"1409","eventId":"","severity":"Low","summary":"Hot key is already registered.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1409; use the surrounding log entries to confirm it.","resolution":"1. Record where 1409 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_HOTKEY_ALREADY_REGISTERED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1409 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Hot key is already registered.\n\nLookup forms: 1409, 0x581, error 1409, ERROR_HOTKEY_ALREADY_REGISTERED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1409"]},{"id":846,"title":"ERROR_CLASS_ALREADY_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1410","0x582","error 1410","ERROR_CLASS_ALREADY_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","class","already","exists"],"errorCode":"1410","eventId":"","severity":"Medium","summary":"Class already exists.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1410; use the surrounding log entries to confirm it.","resolution":"1. Record where 1410 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLASS_ALREADY_EXISTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1410 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Class already exists.\n\nLookup forms: 1410, 0x582, error 1410, ERROR_CLASS_ALREADY_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1410"]},{"id":847,"title":"ERROR_CLASS_DOES_NOT_EXIST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1411","0x583","error 1411","ERROR_CLASS_DOES_NOT_EXIST","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","class","does","not","exist"],"errorCode":"1411","eventId":"","severity":"Low","summary":"Class does not exist.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1411; use the surrounding log entries to confirm it.","resolution":"1. Record where 1411 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLASS_DOES_NOT_EXIST.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1411 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Class does not exist.\n\nLookup forms: 1411, 0x583, error 1411, ERROR_CLASS_DOES_NOT_EXIST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1411"]},{"id":848,"title":"ERROR_CLASS_HAS_WINDOWS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1412","0x584","error 1412","ERROR_CLASS_HAS_WINDOWS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","class","has","windows","still","open"],"errorCode":"1412","eventId":"","severity":"Low","summary":"Class still has open windows.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1412; use the surrounding log entries to confirm it.","resolution":"1. Record where 1412 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLASS_HAS_WINDOWS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1412 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Class still has open windows.\n\nLookup forms: 1412, 0x584, error 1412, ERROR_CLASS_HAS_WINDOWS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1412"]},{"id":849,"title":"ERROR_INVALID_INDEX","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1413","0x585","error 1413","ERROR_INVALID_INDEX","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","index"],"errorCode":"1413","eventId":"","severity":"Medium","summary":"Invalid index.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1413; use the surrounding log entries to confirm it.","resolution":"1. Record where 1413 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_INDEX.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1413 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid index.\n\nLookup forms: 1413, 0x585, error 1413, ERROR_INVALID_INDEX. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1413"]},{"id":850,"title":"ERROR_INVALID_ICON_HANDLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1414","0x586","error 1414","ERROR_INVALID_ICON_HANDLE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","invalid","icon","handle"],"errorCode":"1414","eventId":"","severity":"Medium","summary":"Invalid icon handle.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1414; use the surrounding log entries to confirm it.","resolution":"1. Record where 1414 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_ICON_HANDLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1414 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid icon handle.\n\nLookup forms: 1414, 0x586, error 1414, ERROR_INVALID_ICON_HANDLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1414"]},{"id":851,"title":"ERROR_PRIVATE_DIALOG_INDEX","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1415","0x587","error 1415","ERROR_PRIVATE_DIALOG_INDEX","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","private","dialog","index","using","window","words"],"errorCode":"1415","eventId":"","severity":"Low","summary":"Using private DIALOG window words.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1415; use the surrounding log entries to confirm it.","resolution":"1. Record where 1415 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PRIVATE_DIALOG_INDEX.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1415 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Using private DIALOG window words.\n\nLookup forms: 1415, 0x587, error 1415, ERROR_PRIVATE_DIALOG_INDEX. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1415"]},{"id":852,"title":"ERROR_LISTBOX_ID_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1416","0x588","error 1416","ERROR_LISTBOX_ID_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","listbox","not","found","the","list","box","identifier","was"],"errorCode":"1416","eventId":"","severity":"Medium","summary":"The list box identifier was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1416; use the surrounding log entries to confirm it.","resolution":"1. Record where 1416 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LISTBOX_ID_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1416 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The list box identifier was not found.\n\nLookup forms: 1416, 0x588, error 1416, ERROR_LISTBOX_ID_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1416"]},{"id":853,"title":"ERROR_NO_WILDCARD_CHARACTERS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1417","0x589","error 1417","ERROR_NO_WILDCARD_CHARACTERS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wildcard","characters","wildcards","were","found"],"errorCode":"1417","eventId":"","severity":"Low","summary":"No wildcards were found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1417; use the surrounding log entries to confirm it.","resolution":"1. Record where 1417 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_WILDCARD_CHARACTERS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1417 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No wildcards were found.\n\nLookup forms: 1417, 0x589, error 1417, ERROR_NO_WILDCARD_CHARACTERS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1417"]},{"id":854,"title":"ERROR_CLIPBOARD_NOT_OPEN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1418","0x58A","error 1418","ERROR_CLIPBOARD_NOT_OPEN","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","clipboard","not","open","thread","does","have"],"errorCode":"1418","eventId":"","severity":"Low","summary":"Thread does not have a clipboard open.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1418; use the surrounding log entries to confirm it.","resolution":"1. Record where 1418 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLIPBOARD_NOT_OPEN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1418 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Thread does not have a clipboard open.\n\nLookup forms: 1418, 0x58A, error 1418, ERROR_CLIPBOARD_NOT_OPEN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1418"]},{"id":855,"title":"ERROR_HOTKEY_NOT_REGISTERED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1419","0x58B","error 1419","ERROR_HOTKEY_NOT_REGISTERED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","hotkey","not","registered","hot","key"],"errorCode":"1419","eventId":"","severity":"Low","summary":"Hot key is not registered.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1419; use the surrounding log entries to confirm it.","resolution":"1. Record where 1419 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_HOTKEY_NOT_REGISTERED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1419 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Hot key is not registered.\n\nLookup forms: 1419, 0x58B, error 1419, ERROR_HOTKEY_NOT_REGISTERED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1419"]},{"id":856,"title":"ERROR_WINDOW_NOT_DIALOG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1420","0x58C","error 1420","ERROR_WINDOW_NOT_DIALOG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","window","not","dialog","the","valid"],"errorCode":"1420","eventId":"","severity":"Low","summary":"The window is not a valid dialog window.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1420; use the surrounding log entries to confirm it.","resolution":"1. Record where 1420 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WINDOW_NOT_DIALOG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1420 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The window is not a valid dialog window.\n\nLookup forms: 1420, 0x58C, error 1420, ERROR_WINDOW_NOT_DIALOG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1420"]},{"id":857,"title":"ERROR_CONTROL_ID_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1421","0x58D","error 1421","ERROR_CONTROL_ID_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","control","not","found"],"errorCode":"1421","eventId":"","severity":"Medium","summary":"Control ID not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1421; use the surrounding log entries to confirm it.","resolution":"1. Record where 1421 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CONTROL_ID_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1421 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Control ID not found.\n\nLookup forms: 1421, 0x58D, error 1421, ERROR_CONTROL_ID_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1421"]},{"id":858,"title":"ERROR_INVALID_COMBOBOX_MESSAGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1422","0x58E","error 1422","ERROR_INVALID_COMBOBOX_MESSAGE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","combobox","message","for","combo","box","because","does","not","have","edit","control"],"errorCode":"1422","eventId":"","severity":"Medium","summary":"Invalid message for a combo box because it does not have an edit control.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1422; use the surrounding log entries to confirm it.","resolution":"1. Record where 1422 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_COMBOBOX_MESSAGE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1422 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid message for a combo box because it does not have an edit control.\n\nLookup forms: 1422, 0x58E, error 1422, ERROR_INVALID_COMBOBOX_MESSAGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1422"]},{"id":859,"title":"ERROR_WINDOW_NOT_COMBOBOX","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1423","0x58F","error 1423","ERROR_WINDOW_NOT_COMBOBOX","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","window","not","combobox","the","combo","box"],"errorCode":"1423","eventId":"","severity":"Low","summary":"The window is not a combo box.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1423; use the surrounding log entries to confirm it.","resolution":"1. Record where 1423 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WINDOW_NOT_COMBOBOX.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1423 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The window is not a combo box.\n\nLookup forms: 1423, 0x58F, error 1423, ERROR_WINDOW_NOT_COMBOBOX. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1423"]},{"id":860,"title":"ERROR_INVALID_EDIT_HEIGHT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1424","0x590","error 1424","ERROR_INVALID_EDIT_HEIGHT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","edit","height","must","less","than","256"],"errorCode":"1424","eventId":"","severity":"Low","summary":"Height must be less than 256.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1424; use the surrounding log entries to confirm it.","resolution":"1. Record where 1424 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_EDIT_HEIGHT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1424 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Height must be less than 256.\n\nLookup forms: 1424, 0x590, error 1424, ERROR_INVALID_EDIT_HEIGHT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1424"]},{"id":861,"title":"ERROR_DC_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1425","0x591","error 1425","ERROR_DC_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","not","found","invalid","device","context","handle"],"errorCode":"1425","eventId":"","severity":"Medium","summary":"Invalid device context (DC) handle.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1425; use the surrounding log entries to confirm it.","resolution":"1. Record where 1425 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DC_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1425 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid device context (DC) handle.\n\nLookup forms: 1425, 0x591, error 1425, ERROR_DC_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1425"]},{"id":862,"title":"ERROR_INVALID_HOOK_FILTER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1426","0x592","error 1426","ERROR_INVALID_HOOK_FILTER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","hook","filter","procedure","type"],"errorCode":"1426","eventId":"","severity":"Medium","summary":"Invalid hook procedure type.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1426; use the surrounding log entries to confirm it.","resolution":"1. Record where 1426 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_HOOK_FILTER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1426 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid hook procedure type.\n\nLookup forms: 1426, 0x592, error 1426, ERROR_INVALID_HOOK_FILTER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1426"]},{"id":863,"title":"ERROR_INVALID_FILTER_PROC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1427","0x593","error 1427","ERROR_INVALID_FILTER_PROC","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","filter","proc","hook","procedure"],"errorCode":"1427","eventId":"","severity":"Medium","summary":"Invalid hook procedure.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1427; use the surrounding log entries to confirm it.","resolution":"1. Record where 1427 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_FILTER_PROC.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1427 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid hook procedure.\n\nLookup forms: 1427, 0x593, error 1427, ERROR_INVALID_FILTER_PROC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1427"]},{"id":864,"title":"ERROR_HOOK_NEEDS_HMOD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1428","0x594","error 1428","ERROR_HOOK_NEEDS_HMOD","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","hook","needs","hmod","cannot","set","nonlocal","without","module","handle"],"errorCode":"1428","eventId":"","severity":"Medium","summary":"Cannot set nonlocal hook without a module handle.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1428; use the surrounding log entries to confirm it.","resolution":"1. Record where 1428 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_HOOK_NEEDS_HMOD.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1428 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot set nonlocal hook without a module handle.\n\nLookup forms: 1428, 0x594, error 1428, ERROR_HOOK_NEEDS_HMOD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1428"]},{"id":865,"title":"ERROR_GLOBAL_ONLY_HOOK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1429","0x595","error 1429","ERROR_GLOBAL_ONLY_HOOK","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","global","only","hook","this","procedure","can","set","globally"],"errorCode":"1429","eventId":"","severity":"Low","summary":"This hook procedure can only be set globally.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1429; use the surrounding log entries to confirm it.","resolution":"1. Record where 1429 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_GLOBAL_ONLY_HOOK.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1429 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This hook procedure can only be set globally.\n\nLookup forms: 1429, 0x595, error 1429, ERROR_GLOBAL_ONLY_HOOK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1429"]},{"id":866,"title":"ERROR_JOURNAL_HOOK_SET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1430","0x596","error 1430","ERROR_JOURNAL_HOOK_SET","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","journal","hook","set","the","procedure","already","installed"],"errorCode":"1430","eventId":"","severity":"Low","summary":"The journal hook procedure is already installed.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 1430; use the surrounding log entries to confirm it.","resolution":"1. Record where 1430 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_JOURNAL_HOOK_SET.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1430 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The journal hook procedure is already installed.\n\nLookup forms: 1430, 0x596, error 1430, ERROR_JOURNAL_HOOK_SET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1430"]},{"id":867,"title":"ERROR_HOOK_NOT_INSTALLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1431","0x597","error 1431","ERROR_HOOK_NOT_INSTALLED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","hook","not","installed","the","procedure"],"errorCode":"1431","eventId":"","severity":"Low","summary":"The hook procedure is not installed.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 1431; use the surrounding log entries to confirm it.","resolution":"1. Record where 1431 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_HOOK_NOT_INSTALLED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1431 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The hook procedure is not installed.\n\nLookup forms: 1431, 0x597, error 1431, ERROR_HOOK_NOT_INSTALLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1431"]},{"id":868,"title":"ERROR_INVALID_LB_MESSAGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1432","0x598","error 1432","ERROR_INVALID_LB_MESSAGE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","message","for","single","selection","list","box"],"errorCode":"1432","eventId":"","severity":"Medium","summary":"Invalid message for single-selection list box.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1432; use the surrounding log entries to confirm it.","resolution":"1. Record where 1432 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_LB_MESSAGE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1432 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid message for single-selection list box.\n\nLookup forms: 1432, 0x598, error 1432, ERROR_INVALID_LB_MESSAGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1432"]},{"id":869,"title":"ERROR_SETCOUNT_ON_BAD_LB","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1433","0x599","error 1433","ERROR_SETCOUNT_ON_BAD_LB","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","setcount","bad","sent","non","lazy","list","box"],"errorCode":"1433","eventId":"","severity":"Low","summary":"LB_SETCOUNT sent to non-lazy list box.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1433; use the surrounding log entries to confirm it.","resolution":"1. Record where 1433 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SETCOUNT_ON_BAD_LB.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1433 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: LB_SETCOUNT sent to non-lazy list box.\n\nLookup forms: 1433, 0x599, error 1433, ERROR_SETCOUNT_ON_BAD_LB. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1433"]},{"id":870,"title":"ERROR_LB_WITHOUT_TABSTOPS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1434","0x59A","error 1434","ERROR_LB_WITHOUT_TABSTOPS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","without","tabstops","this","list","box","does","not","support","tab","stops"],"errorCode":"1434","eventId":"","severity":"Low","summary":"This list box does not support tab stops.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1434; use the surrounding log entries to confirm it.","resolution":"1. Record where 1434 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LB_WITHOUT_TABSTOPS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1434 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This list box does not support tab stops.\n\nLookup forms: 1434, 0x59A, error 1434, ERROR_LB_WITHOUT_TABSTOPS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1434"]},{"id":871,"title":"ERROR_DESTROY_OBJECT_OF_OTHER_THREAD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1435","0x59B","error 1435","ERROR_DESTROY_OBJECT_OF_OTHER_THREAD","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","destroy","object","other","thread","cannot","created","another"],"errorCode":"1435","eventId":"","severity":"Medium","summary":"Cannot destroy object created by another thread.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1435; use the surrounding log entries to confirm it.","resolution":"1. Record where 1435 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DESTROY_OBJECT_OF_OTHER_THREAD.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1435 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot destroy object created by another thread.\n\nLookup forms: 1435, 0x59B, error 1435, ERROR_DESTROY_OBJECT_OF_OTHER_THREAD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1435"]},{"id":872,"title":"ERROR_CHILD_WINDOW_MENU","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1436","0x59C","error 1436","ERROR_CHILD_WINDOW_MENU","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","child","window","menu","windows","cannot","have","menus"],"errorCode":"1436","eventId":"","severity":"Medium","summary":"Child windows cannot have menus.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1436; use the surrounding log entries to confirm it.","resolution":"1. Record where 1436 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CHILD_WINDOW_MENU.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1436 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Child windows cannot have menus.\n\nLookup forms: 1436, 0x59C, error 1436, ERROR_CHILD_WINDOW_MENU. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1436"]},{"id":873,"title":"ERROR_NO_SYSTEM_MENU","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1437","0x59D","error 1437","ERROR_NO_SYSTEM_MENU","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","system","menu","the","window","does","not","have"],"errorCode":"1437","eventId":"","severity":"Low","summary":"The window does not have a system menu.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1437; use the surrounding log entries to confirm it.","resolution":"1. Record where 1437 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_SYSTEM_MENU.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1437 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The window does not have a system menu.\n\nLookup forms: 1437, 0x59D, error 1437, ERROR_NO_SYSTEM_MENU. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1437"]},{"id":874,"title":"ERROR_INVALID_MSGBOX_STYLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1438","0x59E","error 1438","ERROR_INVALID_MSGBOX_STYLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","msgbox","style","message","box"],"errorCode":"1438","eventId":"","severity":"Medium","summary":"Invalid message box style.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1438; use the surrounding log entries to confirm it.","resolution":"1. Record where 1438 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_MSGBOX_STYLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1438 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid message box style.\n\nLookup forms: 1438, 0x59E, error 1438, ERROR_INVALID_MSGBOX_STYLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1438"]},{"id":875,"title":"ERROR_INVALID_SPI_VALUE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1439","0x59F","error 1439","ERROR_INVALID_SPI_VALUE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","spi","value","system","wide","parameter"],"errorCode":"1439","eventId":"","severity":"Medium","summary":"Invalid system-wide (SPI_*) parameter.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1439; use the surrounding log entries to confirm it.","resolution":"1. Record where 1439 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_SPI_VALUE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1439 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid system-wide (SPI_*) parameter.\n\nLookup forms: 1439, 0x59F, error 1439, ERROR_INVALID_SPI_VALUE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1439"]},{"id":876,"title":"ERROR_SCREEN_ALREADY_LOCKED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1440","0x5A0","error 1440","ERROR_SCREEN_ALREADY_LOCKED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","screen","already","locked"],"errorCode":"1440","eventId":"","severity":"High","summary":"Screen already locked.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1440; use the surrounding log entries to confirm it.","resolution":"1. Record where 1440 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SCREEN_ALREADY_LOCKED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1440 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Screen already locked.\n\nLookup forms: 1440, 0x5A0, error 1440, ERROR_SCREEN_ALREADY_LOCKED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1440"]},{"id":877,"title":"ERROR_HWNDS_HAVE_DIFF_PARENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1441","0x5A1","error 1441","ERROR_HWNDS_HAVE_DIFF_PARENT","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","hwnds","have","diff","parent","all","handles","windows","multiple","window","position","structure","must","the","same"],"errorCode":"1441","eventId":"","severity":"Low","summary":"All handles to windows in a multiple-window position structure must have the same parent.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1441; use the surrounding log entries to confirm it.","resolution":"1. Record where 1441 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_HWNDS_HAVE_DIFF_PARENT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1441 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: All handles to windows in a multiple-window position structure must have the same parent.\n\nLookup forms: 1441, 0x5A1, error 1441, ERROR_HWNDS_HAVE_DIFF_PARENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1441"]},{"id":878,"title":"ERROR_NOT_CHILD_WINDOW","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1442","0x5A2","error 1442","ERROR_NOT_CHILD_WINDOW","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","not","child","window","the"],"errorCode":"1442","eventId":"","severity":"Low","summary":"The window is not a child window.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1442; use the surrounding log entries to confirm it.","resolution":"1. Record where 1442 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_CHILD_WINDOW.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1442 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The window is not a child window.\n\nLookup forms: 1442, 0x5A2, error 1442, ERROR_NOT_CHILD_WINDOW. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1442"]},{"id":879,"title":"ERROR_INVALID_GW_COMMAND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1443","0x5A3","error 1443","ERROR_INVALID_GW_COMMAND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","command"],"errorCode":"1443","eventId":"","severity":"Medium","summary":"Invalid GW_* command.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1443; use the surrounding log entries to confirm it.","resolution":"1. Record where 1443 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_GW_COMMAND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1443 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid GW_* command.\n\nLookup forms: 1443, 0x5A3, error 1443, ERROR_INVALID_GW_COMMAND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1443"]},{"id":880,"title":"ERROR_INVALID_THREAD_ID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1444","0x5A4","error 1444","ERROR_INVALID_THREAD_ID","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","invalid","thread","identifier"],"errorCode":"1444","eventId":"","severity":"Medium","summary":"Invalid thread identifier.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1444; use the surrounding log entries to confirm it.","resolution":"1. Record where 1444 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_THREAD_ID.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1444 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid thread identifier.\n\nLookup forms: 1444, 0x5A4, error 1444, ERROR_INVALID_THREAD_ID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1444"]},{"id":881,"title":"ERROR_NON_MDICHILD_WINDOW","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1445","0x5A5","error 1445","ERROR_NON_MDICHILD_WINDOW","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","non","mdichild","window","cannot","process","message","from","that","not","multiple","document","interface","mdi"],"errorCode":"1445","eventId":"","severity":"Medium","summary":"Cannot process a message from a window that is not a multiple document interface (MDI) window.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1445; use the surrounding log entries to confirm it.","resolution":"1. Record where 1445 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NON_MDICHILD_WINDOW.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1445 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot process a message from a window that is not a multiple document interface (MDI) window.\n\nLookup forms: 1445, 0x5A5, error 1445, ERROR_NON_MDICHILD_WINDOW. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1445"]},{"id":882,"title":"ERROR_POPUP_ALREADY_ACTIVE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1446","0x5A6","error 1446","ERROR_POPUP_ALREADY_ACTIVE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","popup","already","active","menu"],"errorCode":"1446","eventId":"","severity":"Low","summary":"Popup menu already active.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1446; use the surrounding log entries to confirm it.","resolution":"1. Record where 1446 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_POPUP_ALREADY_ACTIVE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1446 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Popup menu already active.\n\nLookup forms: 1446, 0x5A6, error 1446, ERROR_POPUP_ALREADY_ACTIVE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1446"]},{"id":883,"title":"ERROR_NO_SCROLLBARS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1447","0x5A7","error 1447","ERROR_NO_SCROLLBARS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","scrollbars","the","window","does","not","have","scroll","bars"],"errorCode":"1447","eventId":"","severity":"Low","summary":"The window does not have scroll bars.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1447; use the surrounding log entries to confirm it.","resolution":"1. Record where 1447 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_SCROLLBARS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1447 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The window does not have scroll bars.\n\nLookup forms: 1447, 0x5A7, error 1447, ERROR_NO_SCROLLBARS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1447"]},{"id":884,"title":"ERROR_INVALID_SCROLLBAR_RANGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1448","0x5A8","error 1448","ERROR_INVALID_SCROLLBAR_RANGE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","scrollbar","range","scroll","bar","cannot","greater","than","maxlong"],"errorCode":"1448","eventId":"","severity":"Medium","summary":"Scroll bar range cannot be greater than MAXLONG.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1448; use the surrounding log entries to confirm it.","resolution":"1. Record where 1448 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_SCROLLBAR_RANGE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1448 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Scroll bar range cannot be greater than MAXLONG.\n\nLookup forms: 1448, 0x5A8, error 1448, ERROR_INVALID_SCROLLBAR_RANGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1448"]},{"id":885,"title":"ERROR_INVALID_SHOWWIN_COMMAND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1449","0x5A9","error 1449","ERROR_INVALID_SHOWWIN_COMMAND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","showwin","command","cannot","show","remove","the","window","way","specified"],"errorCode":"1449","eventId":"","severity":"Medium","summary":"Cannot show or remove the window in the way specified.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1449; use the surrounding log entries to confirm it.","resolution":"1. Record where 1449 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_SHOWWIN_COMMAND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1449 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot show or remove the window in the way specified.\n\nLookup forms: 1449, 0x5A9, error 1449, ERROR_INVALID_SHOWWIN_COMMAND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1449"]},{"id":886,"title":"ERROR_NO_SYSTEM_RESOURCES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1450","0x5AA","error 1450","ERROR_NO_SYSTEM_RESOURCES","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","system","resources","insufficient","exist","complete","the","requested","service"],"errorCode":"1450","eventId":"","severity":"Low","summary":"Insufficient system resources exist to complete the requested service.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1450; use the surrounding log entries to confirm it.","resolution":"1. Record where 1450 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_SYSTEM_RESOURCES.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1450 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Insufficient system resources exist to complete the requested service.\n\nLookup forms: 1450, 0x5AA, error 1450, ERROR_NO_SYSTEM_RESOURCES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1450"]},{"id":887,"title":"ERROR_NONPAGED_SYSTEM_RESOURCES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1451","0x5AB","error 1451","ERROR_NONPAGED_SYSTEM_RESOURCES","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","nonpaged","system","resources","insufficient","exist","complete","the","requested","service"],"errorCode":"1451","eventId":"","severity":"Low","summary":"Insufficient system resources exist to complete the requested service.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1451; use the surrounding log entries to confirm it.","resolution":"1. Record where 1451 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NONPAGED_SYSTEM_RESOURCES.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1451 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Insufficient system resources exist to complete the requested service.\n\nLookup forms: 1451, 0x5AB, error 1451, ERROR_NONPAGED_SYSTEM_RESOURCES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1451"]},{"id":888,"title":"ERROR_PAGED_SYSTEM_RESOURCES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1452","0x5AC","error 1452","ERROR_PAGED_SYSTEM_RESOURCES","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","paged","system","resources","insufficient","exist","complete","the","requested","service"],"errorCode":"1452","eventId":"","severity":"Low","summary":"Insufficient system resources exist to complete the requested service.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1452; use the surrounding log entries to confirm it.","resolution":"1. Record where 1452 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PAGED_SYSTEM_RESOURCES.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1452 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Insufficient system resources exist to complete the requested service.\n\nLookup forms: 1452, 0x5AC, error 1452, ERROR_PAGED_SYSTEM_RESOURCES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1452"]},{"id":889,"title":"ERROR_WORKING_SET_QUOTA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1453","0x5AD","error 1453","ERROR_WORKING_SET_QUOTA","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","working","set","quota","insufficient","complete","the","requested","service"],"errorCode":"1453","eventId":"","severity":"Low","summary":"Insufficient quota to complete the requested service.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1453; use the surrounding log entries to confirm it.","resolution":"1. Record where 1453 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WORKING_SET_QUOTA.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1453 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Insufficient quota to complete the requested service.\n\nLookup forms: 1453, 0x5AD, error 1453, ERROR_WORKING_SET_QUOTA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1453"]},{"id":890,"title":"ERROR_PAGEFILE_QUOTA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1454","0x5AE","error 1454","ERROR_PAGEFILE_QUOTA","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","pagefile","quota","insufficient","complete","the","requested","service"],"errorCode":"1454","eventId":"","severity":"Low","summary":"Insufficient quota to complete the requested service.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1454; use the surrounding log entries to confirm it.","resolution":"1. Record where 1454 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PAGEFILE_QUOTA.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1454 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Insufficient quota to complete the requested service.\n\nLookup forms: 1454, 0x5AE, error 1454, ERROR_PAGEFILE_QUOTA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1454"]},{"id":891,"title":"ERROR_COMMITMENT_LIMIT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1455","0x5AF","error 1455","ERROR_COMMITMENT_LIMIT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","commitment","limit","the","paging","file","too","small","for","this","operation","complete"],"errorCode":"1455","eventId":"","severity":"Low","summary":"The paging file is too small for this operation to complete.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1455; use the surrounding log entries to confirm it.","resolution":"1. Record where 1455 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_COMMITMENT_LIMIT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1455 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The paging file is too small for this operation to complete.\n\nLookup forms: 1455, 0x5AF, error 1455, ERROR_COMMITMENT_LIMIT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1455"]},{"id":892,"title":"ERROR_MENU_ITEM_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1456","0x5B0","error 1456","ERROR_MENU_ITEM_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","menu","item","not","found","was"],"errorCode":"1456","eventId":"","severity":"Medium","summary":"A menu item was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1456; use the surrounding log entries to confirm it.","resolution":"1. Record where 1456 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MENU_ITEM_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1456 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A menu item was not found.\n\nLookup forms: 1456, 0x5B0, error 1456, ERROR_MENU_ITEM_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1456"]},{"id":893,"title":"ERROR_INVALID_KEYBOARD_HANDLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1457","0x5B1","error 1457","ERROR_INVALID_KEYBOARD_HANDLE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","invalid","keyboard","handle","layout"],"errorCode":"1457","eventId":"","severity":"Medium","summary":"Invalid keyboard layout handle.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1457; use the surrounding log entries to confirm it.","resolution":"1. Record where 1457 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_KEYBOARD_HANDLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1457 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid keyboard layout handle.\n\nLookup forms: 1457, 0x5B1, error 1457, ERROR_INVALID_KEYBOARD_HANDLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1457"]},{"id":894,"title":"ERROR_HOOK_TYPE_NOT_ALLOWED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1458","0x5B2","error 1458","ERROR_HOOK_TYPE_NOT_ALLOWED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","hook","type","not","allowed"],"errorCode":"1458","eventId":"","severity":"Low","summary":"Hook type not allowed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1458; use the surrounding log entries to confirm it.","resolution":"1. Record where 1458 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_HOOK_TYPE_NOT_ALLOWED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1458 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Hook type not allowed.\n\nLookup forms: 1458, 0x5B2, error 1458, ERROR_HOOK_TYPE_NOT_ALLOWED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1458"]},{"id":895,"title":"ERROR_REQUIRES_INTERACTIVE_WINDOWSTATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1459","0x5B3","error 1459","ERROR_REQUIRES_INTERACTIVE_WINDOWSTATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","requires","interactive","windowstation","this","operation","window","station"],"errorCode":"1459","eventId":"","severity":"Low","summary":"This operation requires an interactive window station.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1459; use the surrounding log entries to confirm it.","resolution":"1. Record where 1459 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REQUIRES_INTERACTIVE_WINDOWSTATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1459 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation requires an interactive window station.\n\nLookup forms: 1459, 0x5B3, error 1459, ERROR_REQUIRES_INTERACTIVE_WINDOWSTATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1459"]},{"id":896,"title":"ERROR_TIMEOUT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1460","0x5B4","error 1460","ERROR_TIMEOUT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","timeout","this","operation","returned","because","the","period","expired"],"errorCode":"1460","eventId":"","severity":"Medium","summary":"This operation returned because the timeout period expired.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1460; use the surrounding log entries to confirm it.","resolution":"1. Record where 1460 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TIMEOUT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1460 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation returned because the timeout period expired.\n\nLookup forms: 1460, 0x5B4, error 1460, ERROR_TIMEOUT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1460"]},{"id":897,"title":"ERROR_INVALID_MONITOR_HANDLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1461","0x5B5","error 1461","ERROR_INVALID_MONITOR_HANDLE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","invalid","monitor","handle"],"errorCode":"1461","eventId":"","severity":"Medium","summary":"Invalid monitor handle.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1461; use the surrounding log entries to confirm it.","resolution":"1. Record where 1461 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_MONITOR_HANDLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1461 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid monitor handle.\n\nLookup forms: 1461, 0x5B5, error 1461, ERROR_INVALID_MONITOR_HANDLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1461"]},{"id":898,"title":"ERROR_INCORRECT_SIZE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1462","0x5B6","error 1462","ERROR_INCORRECT_SIZE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","incorrect","size","argument"],"errorCode":"1462","eventId":"","severity":"Low","summary":"Incorrect size argument.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1462; use the surrounding log entries to confirm it.","resolution":"1. Record where 1462 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INCORRECT_SIZE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1462 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Incorrect size argument.\n\nLookup forms: 1462, 0x5B6, error 1462, ERROR_INCORRECT_SIZE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1462"]},{"id":899,"title":"ERROR_SYMLINK_CLASS_DISABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1463","0x5B7","error 1463","ERROR_SYMLINK_CLASS_DISABLED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","symlink","class","disabled","the","symbolic","link","cannot","followed","because","its","type"],"errorCode":"1463","eventId":"","severity":"Medium","summary":"The symbolic link cannot be followed because its type is disabled.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1463; use the surrounding log entries to confirm it.","resolution":"1. Record where 1463 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SYMLINK_CLASS_DISABLED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1463 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The symbolic link cannot be followed because its type is disabled.\n\nLookup forms: 1463, 0x5B7, error 1463, ERROR_SYMLINK_CLASS_DISABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1463"]},{"id":900,"title":"ERROR_SYMLINK_NOT_SUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1464","0x5B8","error 1464","ERROR_SYMLINK_NOT_SUPPORTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","symlink","not","supported","this","application","does","support","the","current","operation","symbolic","links"],"errorCode":"1464","eventId":"","severity":"Low","summary":"This application does not support the current operation on symbolic links.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1464; use the surrounding log entries to confirm it.","resolution":"1. Record where 1464 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SYMLINK_NOT_SUPPORTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1464 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This application does not support the current operation on symbolic links.\n\nLookup forms: 1464, 0x5B8, error 1464, ERROR_SYMLINK_NOT_SUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1464"]},{"id":901,"title":"ERROR_XML_PARSE_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1465","0x5B9","error 1465","ERROR_XML_PARSE_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","xml","parse","windows","was","unable","the","requested","data"],"errorCode":"1465","eventId":"","severity":"Medium","summary":"Windows was unable to parse the requested XML data.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1465; use the surrounding log entries to confirm it.","resolution":"1. Record where 1465 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_XML_PARSE_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1465 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Windows was unable to parse the requested XML data.\n\nLookup forms: 1465, 0x5B9, error 1465, ERROR_XML_PARSE_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1465"]},{"id":902,"title":"ERROR_XMLDSIG_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1466","0x5BA","error 1466","ERROR_XMLDSIG_ERROR","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","xmldsig","was","encountered","while","processing","xml","digital","signature"],"errorCode":"1466","eventId":"","severity":"Low","summary":"An error was encountered while processing an XML digital signature.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1466; use the surrounding log entries to confirm it.","resolution":"1. Record where 1466 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_XMLDSIG_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1466 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An error was encountered while processing an XML digital signature.\n\nLookup forms: 1466, 0x5BA, error 1466, ERROR_XMLDSIG_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1466"]},{"id":903,"title":"ERROR_RESTART_APPLICATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1467","0x5BB","error 1467","ERROR_RESTART_APPLICATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","restart","application","this","must","restarted"],"errorCode":"1467","eventId":"","severity":"Low","summary":"This application must be restarted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1467; use the surrounding log entries to confirm it.","resolution":"1. Record where 1467 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESTART_APPLICATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1467 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This application must be restarted.\n\nLookup forms: 1467, 0x5BB, error 1467, ERROR_RESTART_APPLICATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1467"]},{"id":904,"title":"ERROR_WRONG_COMPARTMENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1468","0x5BC","error 1468","ERROR_WRONG_COMPARTMENT","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","wrong","compartment","the","caller","made","connection","request","routing"],"errorCode":"1468","eventId":"","severity":"High","summary":"The caller made the connection request in the wrong routing compartment.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1468; use the surrounding log entries to confirm it.","resolution":"1. Record where 1468 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WRONG_COMPARTMENT.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1468 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The caller made the connection request in the wrong routing compartment.\n\nLookup forms: 1468, 0x5BC, error 1468, ERROR_WRONG_COMPARTMENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1468"]},{"id":905,"title":"ERROR_AUTHIP_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1469","0x5BD","error 1469","ERROR_AUTHIP_FAILURE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","authip","failure","there","was","when","attempting","connect","the","remote","host"],"errorCode":"1469","eventId":"","severity":"High","summary":"There was an AuthIP failure when attempting to connect to the remote host.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1469; use the surrounding log entries to confirm it.","resolution":"1. Record where 1469 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_AUTHIP_FAILURE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1469 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There was an AuthIP failure when attempting to connect to the remote host.\n\nLookup forms: 1469, 0x5BD, error 1469, ERROR_AUTHIP_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1469"]},{"id":906,"title":"ERROR_NO_NVRAM_RESOURCES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1470","0x5BE","error 1470","ERROR_NO_NVRAM_RESOURCES","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","nvram","resources","insufficient","exist","complete","the","requested","service","reboot","might","required"],"errorCode":"1470","eventId":"","severity":"Low","summary":"Insufficient NVRAM resources exist to complete the requested service. A reboot might be required.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1470; use the surrounding log entries to confirm it.","resolution":"1. Record where 1470 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_NVRAM_RESOURCES.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1470 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Insufficient NVRAM resources exist to complete the requested service. A reboot might be required.\n\nLookup forms: 1470, 0x5BE, error 1470, ERROR_NO_NVRAM_RESOURCES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1470"]},{"id":907,"title":"ERROR_NOT_GUI_PROCESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1471","0x5BF","error 1471","ERROR_NOT_GUI_PROCESS","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","not","gui","process","unable","finish","the","requested","operation","because","specified"],"errorCode":"1471","eventId":"","severity":"Medium","summary":"Unable to finish the requested operation because the specified process is not a GUI process.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1471; use the surrounding log entries to confirm it.","resolution":"1. Record where 1471 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_GUI_PROCESS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1471 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to finish the requested operation because the specified process is not a GUI process.\n\nLookup forms: 1471, 0x5BF, error 1471, ERROR_NOT_GUI_PROCESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1471"]},{"id":908,"title":"ERROR_EVENTLOG_FILE_CORRUPT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1500","0x5DC","error 1500","ERROR_EVENTLOG_FILE_CORRUPT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","eventlog","file","corrupt","the","event","log","corrupted"],"errorCode":"1500","eventId":"","severity":"Critical","summary":"The event log file is corrupted.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1500; use the surrounding log entries to confirm it.","resolution":"1. Record where 1500 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVENTLOG_FILE_CORRUPT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1500 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The event log file is corrupted.\n\nLookup forms: 1500, 0x5DC, error 1500, ERROR_EVENTLOG_FILE_CORRUPT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1500"]},{"id":909,"title":"ERROR_EVENTLOG_CANT_START","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1501","0x5DD","error 1501","ERROR_EVENTLOG_CANT_START","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","eventlog","cant","start","event","log","file","could","opened","the","logging","service","did","not"],"errorCode":"1501","eventId":"","severity":"Low","summary":"No event log file could be opened, so the event logging service did not start.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1501; use the surrounding log entries to confirm it.","resolution":"1. Record where 1501 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVENTLOG_CANT_START.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1501 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No event log file could be opened, so the event logging service did not start.\n\nLookup forms: 1501, 0x5DD, error 1501, ERROR_EVENTLOG_CANT_START. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1501"]},{"id":910,"title":"ERROR_LOG_FILE_FULL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1502","0x5DE","error 1502","ERROR_LOG_FILE_FULL","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","log","file","full","the","event"],"errorCode":"1502","eventId":"","severity":"Low","summary":"The event log file is full.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1502; use the surrounding log entries to confirm it.","resolution":"1. Record where 1502 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_FILE_FULL.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1502 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The event log file is full.\n\nLookup forms: 1502, 0x5DE, error 1502, ERROR_LOG_FILE_FULL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1502"]},{"id":911,"title":"ERROR_EVENTLOG_FILE_CHANGED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1503","0x5DF","error 1503","ERROR_EVENTLOG_FILE_CHANGED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","eventlog","file","changed","the","event","log","has","between","read","operations"],"errorCode":"1503","eventId":"","severity":"Low","summary":"The event log file has changed between read operations.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1503; use the surrounding log entries to confirm it.","resolution":"1. Record where 1503 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVENTLOG_FILE_CHANGED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1503 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The event log file has changed between read operations.\n\nLookup forms: 1503, 0x5DF, error 1503, ERROR_EVENTLOG_FILE_CHANGED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1503"]},{"id":912,"title":"ERROR_INVALID_TASK_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1550","0x60E","error 1550","ERROR_INVALID_TASK_NAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","task","name","the","specified"],"errorCode":"1550","eventId":"","severity":"Medium","summary":"The specified task name is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1550; use the surrounding log entries to confirm it.","resolution":"1. Record where 1550 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_TASK_NAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1550 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified task name is invalid.\n\nLookup forms: 1550, 0x60E, error 1550, ERROR_INVALID_TASK_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1550"]},{"id":913,"title":"ERROR_INVALID_TASK_INDEX","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1551","0x60F","error 1551","ERROR_INVALID_TASK_INDEX","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","task","index","the","specified"],"errorCode":"1551","eventId":"","severity":"Medium","summary":"The specified task index is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1551; use the surrounding log entries to confirm it.","resolution":"1. Record where 1551 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_TASK_INDEX.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1551 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified task index is invalid.\n\nLookup forms: 1551, 0x60F, error 1551, ERROR_INVALID_TASK_INDEX. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1551"]},{"id":914,"title":"ERROR_THREAD_ALREADY_IN_TASK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1552","0x610","error 1552","ERROR_THREAD_ALREADY_IN_TASK","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","thread","already","task","the","specified","joining"],"errorCode":"1552","eventId":"","severity":"Low","summary":"The specified thread is already joining a task.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1552; use the surrounding log entries to confirm it.","resolution":"1. Record where 1552 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_THREAD_ALREADY_IN_TASK.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1552 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified thread is already joining a task.\n\nLookup forms: 1552, 0x610, error 1552, ERROR_THREAD_ALREADY_IN_TASK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1552"]},{"id":915,"title":"ERROR_INSTALL_SERVICE_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1601","0x641","error 1601","ERROR_INSTALL_SERVICE_FAILURE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","install","service","failure","the","windows","installer","could","not","accessed","this","can","occur","correctly","installed","contact","your","support","personnel","for","assistance"],"errorCode":"1601","eventId":"","severity":"Low","summary":"The Windows Installer Service could not be accessed. This can occur if the Windows Installer is not correctly installed. Contact your support personnel for assistance.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1601; use the surrounding log entries to confirm it.","resolution":"1. Record where 1601 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_SERVICE_FAILURE.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1601 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Windows Installer Service could not be accessed. This can occur if the Windows Installer is not correctly installed. Contact your support personnel for assistance.\n\nLookup forms: 1601, 0x641, error 1601, ERROR_INSTALL_SERVICE_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The Windows Installer service could not be accessed. This can occur if you are running Windows in safe mode, or if the Windows Installer is not correctly installed. Contact your support personnel for assistance.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1601"]},{"id":916,"title":"ERROR_INSTALL_USEREXIT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1602","0x642","error 1602","ERROR_INSTALL_USEREXIT","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","install","userexit","user","cancelled","installation"],"errorCode":"1602","eventId":"","severity":"Low","summary":"User cancelled installation.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 1602; use the surrounding log entries to confirm it.","resolution":"1. Record where 1602 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_USEREXIT.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1602 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: User cancelled installation.\n\nLookup forms: 1602, 0x642, error 1602, ERROR_INSTALL_USEREXIT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1602"]},{"id":917,"title":"ERROR_INSTALL_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1603","0x643","error 1603","ERROR_INSTALL_FAILURE","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","install","failure","fatal","during","installation"],"errorCode":"1603","eventId":"","severity":"Low","summary":"Fatal error during installation.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 1603; use the surrounding log entries to confirm it.","resolution":"1. Record where 1603 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_FAILURE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1603 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Fatal error during installation.\n\nLookup forms: 1603, 0x643, error 1603, ERROR_INSTALL_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1603"]},{"id":918,"title":"ERROR_INSTALL_SUSPEND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1604","0x644","error 1604","ERROR_INSTALL_SUSPEND","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","install","suspend","installation","suspended","incomplete"],"errorCode":"1604","eventId":"","severity":"Low","summary":"Installation suspended, incomplete.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 1604; use the surrounding log entries to confirm it.","resolution":"1. Record where 1604 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_SUSPEND.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1604 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Installation suspended, incomplete.\n\nLookup forms: 1604, 0x644, error 1604, ERROR_INSTALL_SUSPEND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1604"]},{"id":919,"title":"ERROR_UNKNOWN_PRODUCT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1605","0x645","error 1605","ERROR_UNKNOWN_PRODUCT","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","unknown","product","this","action","only","valid","for","products","that","are","currently","installed"],"errorCode":"1605","eventId":"","severity":"Low","summary":"This action is only valid for products that are currently installed.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 1605; use the surrounding log entries to confirm it.","resolution":"1. Record where 1605 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNKNOWN_PRODUCT.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1605 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This action is only valid for products that are currently installed.\n\nLookup forms: 1605, 0x645, error 1605, ERROR_UNKNOWN_PRODUCT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1605"]},{"id":920,"title":"ERROR_UNKNOWN_FEATURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1606","0x646","error 1606","ERROR_UNKNOWN_FEATURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","unknown","feature","not","registered"],"errorCode":"1606","eventId":"","severity":"Low","summary":"Feature ID not registered.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1606; use the surrounding log entries to confirm it.","resolution":"1. Record where 1606 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNKNOWN_FEATURE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1606 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Feature ID not registered.\n\nLookup forms: 1606, 0x646, error 1606, ERROR_UNKNOWN_FEATURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1606"]},{"id":921,"title":"ERROR_UNKNOWN_COMPONENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1607","0x647","error 1607","ERROR_UNKNOWN_COMPONENT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","unknown","component","not","registered"],"errorCode":"1607","eventId":"","severity":"Low","summary":"Component ID not registered.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1607; use the surrounding log entries to confirm it.","resolution":"1. Record where 1607 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNKNOWN_COMPONENT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1607 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Component ID not registered.\n\nLookup forms: 1607, 0x647, error 1607, ERROR_UNKNOWN_COMPONENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1607"]},{"id":922,"title":"ERROR_UNKNOWN_PROPERTY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1608","0x648","error 1608","ERROR_UNKNOWN_PROPERTY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","unknown","property"],"errorCode":"1608","eventId":"","severity":"Low","summary":"Unknown property.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1608; use the surrounding log entries to confirm it.","resolution":"1. Record where 1608 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNKNOWN_PROPERTY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1608 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unknown property.\n\nLookup forms: 1608, 0x648, error 1608, ERROR_UNKNOWN_PROPERTY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1608"]},{"id":923,"title":"ERROR_INVALID_HANDLE_STATE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1609","0x649","error 1609","ERROR_INVALID_HANDLE_STATE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","invalid","handle","state"],"errorCode":"1609","eventId":"","severity":"Medium","summary":"Handle is in an invalid state.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1609; use the surrounding log entries to confirm it.","resolution":"1. Record where 1609 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_HANDLE_STATE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1609 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Handle is in an invalid state.\n\nLookup forms: 1609, 0x649, error 1609, ERROR_INVALID_HANDLE_STATE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1609"]},{"id":924,"title":"ERROR_BAD_CONFIGURATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1610","0x64A","error 1610","ERROR_BAD_CONFIGURATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","bad","configuration","the","data","for","this","product","corrupt","contact","your","support","personnel"],"errorCode":"1610","eventId":"","severity":"Critical","summary":"The configuration data for this product is corrupt. Contact your support personnel.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1610; use the surrounding log entries to confirm it.","resolution":"1. Record where 1610 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_CONFIGURATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1610 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The configuration data for this product is corrupt. Contact your support personnel.\n\nLookup forms: 1610, 0x64A, error 1610, ERROR_BAD_CONFIGURATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1610"]},{"id":925,"title":"ERROR_INDEX_ABSENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1611","0x64B","error 1611","ERROR_INDEX_ABSENT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","index","absent","component","qualifier","not","present"],"errorCode":"1611","eventId":"","severity":"Low","summary":"Component qualifier not present.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1611; use the surrounding log entries to confirm it.","resolution":"1. Record where 1611 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INDEX_ABSENT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1611 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Component qualifier not present.\n\nLookup forms: 1611, 0x64B, error 1611, ERROR_INDEX_ABSENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1611"]},{"id":926,"title":"ERROR_INSTALL_SOURCE_ABSENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1612","0x64C","error 1612","ERROR_INSTALL_SOURCE_ABSENT","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","install","source","absent","the","installation","for","this","product","not","available","verify","that","exists","and","you","can","access"],"errorCode":"1612","eventId":"","severity":"Low","summary":"The installation source for this product is not available. Verify that the source exists and that you can access it.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1612; use the surrounding log entries to confirm it.","resolution":"1. Record where 1612 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_SOURCE_ABSENT.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1612 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The installation source for this product is not available. Verify that the source exists and that you can access it.\n\nLookup forms: 1612, 0x64C, error 1612, ERROR_INSTALL_SOURCE_ABSENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1612"]},{"id":927,"title":"ERROR_INSTALL_PACKAGE_VERSION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1613","0x64D","error 1613","ERROR_INSTALL_PACKAGE_VERSION","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","install","package","version","this","installation","cannot","installed","the","windows","installer","service","you","must","pack","that","contains","newer"],"errorCode":"1613","eventId":"","severity":"Medium","summary":"This installation package cannot be installed by the Windows Installer service. You must install a Windows service pack that contains a newer version of the Windows Installer service.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1613; use the surrounding log entries to confirm it.","resolution":"1. Record where 1613 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_PACKAGE_VERSION.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1613 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This installation package cannot be installed by the Windows Installer service. You must install a Windows service pack that contains a newer version of the Windows Installer service.\n\nLookup forms: 1613, 0x64D, error 1613, ERROR_INSTALL_PACKAGE_VERSION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1613"]},{"id":928,"title":"ERROR_PRODUCT_UNINSTALLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1614","0x64E","error 1614","ERROR_PRODUCT_UNINSTALLED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","product","uninstalled"],"errorCode":"1614","eventId":"","severity":"Low","summary":"Product is uninstalled.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 1614; use the surrounding log entries to confirm it.","resolution":"1. Record where 1614 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PRODUCT_UNINSTALLED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1614 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Product is uninstalled.\n\nLookup forms: 1614, 0x64E, error 1614, ERROR_PRODUCT_UNINSTALLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1614"]},{"id":929,"title":"ERROR_BAD_QUERY_SYNTAX","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1615","0x64F","error 1615","ERROR_BAD_QUERY_SYNTAX","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","bad","query","syntax","sql","invalid","unsupported"],"errorCode":"1615","eventId":"","severity":"Medium","summary":"SQL query syntax invalid or unsupported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1615; use the surrounding log entries to confirm it.","resolution":"1. Record where 1615 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_QUERY_SYNTAX.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1615 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: SQL query syntax invalid or unsupported.\n\nLookup forms: 1615, 0x64F, error 1615, ERROR_BAD_QUERY_SYNTAX. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1615"]},{"id":930,"title":"ERROR_INVALID_FIELD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1616","0x650","error 1616","ERROR_INVALID_FIELD","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","field","record","does","not","exist"],"errorCode":"1616","eventId":"","severity":"Low","summary":"Record field does not exist.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1616; use the surrounding log entries to confirm it.","resolution":"1. Record where 1616 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_FIELD.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1616 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Record field does not exist.\n\nLookup forms: 1616, 0x650, error 1616, ERROR_INVALID_FIELD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1616"]},{"id":931,"title":"ERROR_DEVICE_REMOVED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1617","0x651","error 1617","ERROR_DEVICE_REMOVED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","device","removed","the","has","been"],"errorCode":"1617","eventId":"","severity":"Low","summary":"The device has been removed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1617; use the surrounding log entries to confirm it.","resolution":"1. Record where 1617 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEVICE_REMOVED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1617 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The device has been removed.\n\nLookup forms: 1617, 0x651, error 1617, ERROR_DEVICE_REMOVED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1617"]},{"id":932,"title":"ERROR_INSTALL_ALREADY_RUNNING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1618","0x652","error 1618","ERROR_INSTALL_ALREADY_RUNNING","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","install","already","running","another","installation","progress","complete","that","before","proceeding","with","this"],"errorCode":"1618","eventId":"","severity":"Low","summary":"Another installation is already in progress. Complete that installation before proceeding with this install.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 1618; use the surrounding log entries to confirm it.","resolution":"1. Record where 1618 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_ALREADY_RUNNING.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1618 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Another installation is already in progress. Complete that installation before proceeding with this install.\n\nLookup forms: 1618, 0x652, error 1618, ERROR_INSTALL_ALREADY_RUNNING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1618"]},{"id":933,"title":"ERROR_INSTALL_PACKAGE_OPEN_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1619","0x653","error 1619","ERROR_INSTALL_PACKAGE_OPEN_FAILED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","install","package","open","failed","this","installation","could","not","opened","verify","that","the","exists","and","you","can","access","contact","application","vendor","valid","windows","installer"],"errorCode":"1619","eventId":"","severity":"Low","summary":"This installation package could not be opened. Verify that the package exists and that you can access it, or contact the application vendor to verify that this is a valid Windows Installer package.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1619; use the surrounding log entries to confirm it.","resolution":"1. Record where 1619 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_PACKAGE_OPEN_FAILED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1619 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This installation package could not be opened. Verify that the package exists and that you can access it, or contact the application vendor to verify that this is a valid Windows Installer package.\n\nLookup forms: 1619, 0x653, error 1619, ERROR_INSTALL_PACKAGE_OPEN_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1619"]},{"id":934,"title":"ERROR_INSTALL_PACKAGE_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1620","0x654","error 1620","ERROR_INSTALL_PACKAGE_INVALID","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","install","package","invalid","this","installation","could","not","opened","contact","the","application","vendor","verify","that","valid","windows","installer"],"errorCode":"1620","eventId":"","severity":"Low","summary":"This installation package could not be opened. Contact the application vendor to verify that this is a valid Windows Installer package.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 1620; use the surrounding log entries to confirm it.","resolution":"1. Record where 1620 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_PACKAGE_INVALID.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1620 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This installation package could not be opened. Contact the application vendor to verify that this is a valid Windows Installer package.\n\nLookup forms: 1620, 0x654, error 1620, ERROR_INSTALL_PACKAGE_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1620"]},{"id":935,"title":"ERROR_INSTALL_UI_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1621","0x655","error 1621","ERROR_INSTALL_UI_FAILURE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","install","failure","there","was","starting","the","windows","installer","service","user","interface","contact","your","support","personnel"],"errorCode":"1621","eventId":"","severity":"Low","summary":"There was an error starting the Windows Installer service user interface. Contact your support personnel.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1621; use the surrounding log entries to confirm it.","resolution":"1. Record where 1621 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_UI_FAILURE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1621 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There was an error starting the Windows Installer service user interface. Contact your support personnel.\n\nLookup forms: 1621, 0x655, error 1621, ERROR_INSTALL_UI_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1621"]},{"id":936,"title":"ERROR_INSTALL_LOG_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1622","0x656","error 1622","ERROR_INSTALL_LOG_FAILURE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","install","log","failure","opening","installation","file","verify","that","the","specified","location","exists","and","you","can","write"],"errorCode":"1622","eventId":"","severity":"Low","summary":"Error opening installation log file. Verify that the specified log file location exists and that you can write to it.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1622; use the surrounding log entries to confirm it.","resolution":"1. Record where 1622 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_LOG_FAILURE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1622 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Error opening installation log file. Verify that the specified log file location exists and that you can write to it.\n\nLookup forms: 1622, 0x656, error 1622, ERROR_INSTALL_LOG_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1622"]},{"id":937,"title":"ERROR_INSTALL_LANGUAGE_UNSUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1623","0x657","error 1623","ERROR_INSTALL_LANGUAGE_UNSUPPORTED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","install","language","unsupported","the","this","installation","package","not","supported","your","system"],"errorCode":"1623","eventId":"","severity":"Medium","summary":"The language of this installation package is not supported by your system.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 1623; use the surrounding log entries to confirm it.","resolution":"1. Record where 1623 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_LANGUAGE_UNSUPPORTED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1623 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The language of this installation package is not supported by your system.\n\nLookup forms: 1623, 0x657, error 1623, ERROR_INSTALL_LANGUAGE_UNSUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1623"]},{"id":938,"title":"ERROR_INSTALL_TRANSFORM_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1624","0x658","error 1624","ERROR_INSTALL_TRANSFORM_FAILURE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","install","transform","failure","applying","transforms","verify","that","the","specified","paths","are","valid"],"errorCode":"1624","eventId":"","severity":"Low","summary":"Error applying transforms. Verify that the specified transform paths are valid.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1624; use the surrounding log entries to confirm it.","resolution":"1. Record where 1624 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_TRANSFORM_FAILURE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1624 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Error applying transforms. Verify that the specified transform paths are valid.\n\nLookup forms: 1624, 0x658, error 1624, ERROR_INSTALL_TRANSFORM_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1624"]},{"id":939,"title":"ERROR_INSTALL_PACKAGE_REJECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1625","0x659","error 1625","ERROR_INSTALL_PACKAGE_REJECTED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","install","package","rejected","this","installation","forbidden","system","policy","contact","your","administrator"],"errorCode":"1625","eventId":"","severity":"Low","summary":"This installation is forbidden by system policy. Contact your system administrator.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 1625; use the surrounding log entries to confirm it.","resolution":"1. Record where 1625 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_PACKAGE_REJECTED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1625 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This installation is forbidden by system policy. Contact your system administrator.\n\nLookup forms: 1625, 0x659, error 1625, ERROR_INSTALL_PACKAGE_REJECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1625"]},{"id":940,"title":"ERROR_FUNCTION_NOT_CALLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1626","0x65A","error 1626","ERROR_FUNCTION_NOT_CALLED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","function","not","called","could","executed"],"errorCode":"1626","eventId":"","severity":"Low","summary":"Function could not be executed.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1626; use the surrounding log entries to confirm it.","resolution":"1. Record where 1626 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FUNCTION_NOT_CALLED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1626 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Function could not be executed.\n\nLookup forms: 1626, 0x65A, error 1626, ERROR_FUNCTION_NOT_CALLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1626"]},{"id":941,"title":"ERROR_FUNCTION_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1627","0x65B","error 1627","ERROR_FUNCTION_FAILED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","function","failed","during","execution"],"errorCode":"1627","eventId":"","severity":"High","summary":"Function failed during execution.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1627; use the surrounding log entries to confirm it.","resolution":"1. Record where 1627 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FUNCTION_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1627 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Function failed during execution.\n\nLookup forms: 1627, 0x65B, error 1627, ERROR_FUNCTION_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1627"]},{"id":942,"title":"ERROR_INVALID_TABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1628","0x65C","error 1628","ERROR_INVALID_TABLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","table","unknown","specified"],"errorCode":"1628","eventId":"","severity":"Medium","summary":"Invalid or unknown table specified.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1628; use the surrounding log entries to confirm it.","resolution":"1. Record where 1628 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_TABLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1628 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid or unknown table specified.\n\nLookup forms: 1628, 0x65C, error 1628, ERROR_INVALID_TABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1628"]},{"id":943,"title":"ERROR_DATATYPE_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1629","0x65D","error 1629","ERROR_DATATYPE_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","datatype","mismatch","data","supplied","wrong","type"],"errorCode":"1629","eventId":"","severity":"Low","summary":"Data supplied is of wrong type.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1629; use the surrounding log entries to confirm it.","resolution":"1. Record where 1629 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DATATYPE_MISMATCH.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1629 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Data supplied is of wrong type.\n\nLookup forms: 1629, 0x65D, error 1629, ERROR_DATATYPE_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1629"]},{"id":944,"title":"ERROR_UNSUPPORTED_TYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1630","0x65E","error 1630","ERROR_UNSUPPORTED_TYPE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","unsupported","type","data","this","not","supported"],"errorCode":"1630","eventId":"","severity":"Medium","summary":"Data of this type is not supported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1630; use the surrounding log entries to confirm it.","resolution":"1. Record where 1630 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNSUPPORTED_TYPE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1630 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Data of this type is not supported.\n\nLookup forms: 1630, 0x65E, error 1630, ERROR_UNSUPPORTED_TYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1630"]},{"id":945,"title":"ERROR_CREATE_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1631","0x65F","error 1631","ERROR_CREATE_FAILED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","create","failed","the","windows","installer","service","start","contact","your","support","personnel"],"errorCode":"1631","eventId":"","severity":"High","summary":"The Windows Installer service failed to start. Contact your support personnel.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1631; use the surrounding log entries to confirm it.","resolution":"1. Record where 1631 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CREATE_FAILED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1631 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Windows Installer service failed to start. Contact your support personnel.\n\nLookup forms: 1631, 0x65F, error 1631, ERROR_CREATE_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1631"]},{"id":946,"title":"ERROR_INSTALL_TEMP_UNWRITABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1632","0x660","error 1632","ERROR_INSTALL_TEMP_UNWRITABLE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","install","temp","unwritable","the","folder","drive","that","full","inaccessible","free","space","verify","you","have","write","permission"],"errorCode":"1632","eventId":"","severity":"Low","summary":"The Temp folder is on a drive that is full or is inaccessible. Free up space on the drive or verify that you have write permission on the Temp folder.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1632; use the surrounding log entries to confirm it.","resolution":"1. Record where 1632 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Confirm the user or service identity has the required permissions and is not locked or disabled.\n4. Check available memory, disk capacity, quotas, and system resource pressure.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_TEMP_UNWRITABLE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Confirm the user or service identity has the required permissions and is not locked or disabled.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1632 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Temp folder is on a drive that is full or is inaccessible. Free up space on the drive or verify that you have write permission on the Temp folder.\n\nLookup forms: 1632, 0x660, error 1632, ERROR_INSTALL_TEMP_UNWRITABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The Temp folder is on a drive that is full or inaccessible. Free up space on the drive or verify that you have write permission on the Temp folder.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1632"]},{"id":947,"title":"ERROR_INSTALL_PLATFORM_UNSUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1633","0x661","error 1633","ERROR_INSTALL_PLATFORM_UNSUPPORTED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","install","platform","unsupported","this","installation","package","not","supported","processor","type","contact","your","product","vendor"],"errorCode":"1633","eventId":"","severity":"Medium","summary":"This installation package is not supported by this processor type. Contact your product vendor.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1633; use the surrounding log entries to confirm it.","resolution":"1. Record where 1633 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_PLATFORM_UNSUPPORTED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1633 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This installation package is not supported by this processor type. Contact your product vendor.\n\nLookup forms: 1633, 0x661, error 1633, ERROR_INSTALL_PLATFORM_UNSUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1633"]},{"id":948,"title":"ERROR_INSTALL_NOTUSED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1634","0x662","error 1634","ERROR_INSTALL_NOTUSED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","install","notused","component","not","used","this","computer"],"errorCode":"1634","eventId":"","severity":"Low","summary":"Component not used on this computer.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1634; use the surrounding log entries to confirm it.","resolution":"1. Record where 1634 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_NOTUSED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1634 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Component not used on this computer.\n\nLookup forms: 1634, 0x662, error 1634, ERROR_INSTALL_NOTUSED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1634"]},{"id":949,"title":"ERROR_PATCH_PACKAGE_OPEN_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1635","0x663","error 1635","ERROR_PATCH_PACKAGE_OPEN_FAILED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","patch","package","open","failed","this","update","could","not","opened","verify","that","the","exists","and","you","can","access","contact","application","vendor","valid","windows","installer"],"errorCode":"1635","eventId":"","severity":"Low","summary":"This update package could not be opened. Verify that the update package exists and that you can access it, or contact the application vendor to verify that this is a valid Windows Installer update package.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1635; use the surrounding log entries to confirm it.","resolution":"1. Record where 1635 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PATCH_PACKAGE_OPEN_FAILED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1635 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This update package could not be opened. Verify that the update package exists and that you can access it, or contact the application vendor to verify that this is a valid Windows Installer update package.\n\nLookup forms: 1635, 0x663, error 1635, ERROR_PATCH_PACKAGE_OPEN_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): This patch package could not be opened. Verify that the patch package exists and that you can access it, or contact the application vendor to verify that this is a valid Windows Installer patch package.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1635"]},{"id":950,"title":"ERROR_PATCH_PACKAGE_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1636","0x664","error 1636","ERROR_PATCH_PACKAGE_INVALID","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","patch","package","invalid","this","update","could","not","opened","contact","the","application","vendor","verify","that","valid","windows","installer"],"errorCode":"1636","eventId":"","severity":"Low","summary":"This update package could not be opened. Contact the application vendor to verify that this is a valid Windows Installer update package.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 1636; use the surrounding log entries to confirm it.","resolution":"1. Record where 1636 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PATCH_PACKAGE_INVALID.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1636 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This update package could not be opened. Contact the application vendor to verify that this is a valid Windows Installer update package.\n\nLookup forms: 1636, 0x664, error 1636, ERROR_PATCH_PACKAGE_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): This patch package could not be opened. Contact the application vendor to verify that this is a valid Windows Installer patch package.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1636"]},{"id":951,"title":"ERROR_PATCH_PACKAGE_UNSUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1637","0x665","error 1637","ERROR_PATCH_PACKAGE_UNSUPPORTED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","patch","package","unsupported","this","update","cannot","processed","the","windows","installer","service","you","must","install","pack","that","contains","newer","version"],"errorCode":"1637","eventId":"","severity":"Medium","summary":"This update package cannot be processed by the Windows Installer service. You must install a Windows service pack that contains a newer version of the Windows Installer service.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1637; use the surrounding log entries to confirm it.","resolution":"1. Record where 1637 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PATCH_PACKAGE_UNSUPPORTED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1637 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This update package cannot be processed by the Windows Installer service. You must install a Windows service pack that contains a newer version of the Windows Installer service.\n\nLookup forms: 1637, 0x665, error 1637, ERROR_PATCH_PACKAGE_UNSUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): This patch package cannot be processed by the Windows Installer service. You must install a Windows service pack that contains a newer version of the Windows Installer service.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1637"]},{"id":952,"title":"ERROR_PRODUCT_VERSION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1638","0x666","error 1638","ERROR_PRODUCT_VERSION","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","product","version","another","this","already","installed","installation","cannot","continue","configure","remove","the","existing","use","add","programs","control","panel"],"errorCode":"1638","eventId":"","severity":"Medium","summary":"Another version of this product is already installed. Installation of this version cannot continue. To configure or remove the existing version of this product, use Add/Remove Programs on the Control Panel.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 1638; use the surrounding log entries to confirm it.","resolution":"1. Record where 1638 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PRODUCT_VERSION.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1638 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Another version of this product is already installed. Installation of this version cannot continue. To configure or remove the existing version of this product, use Add/Remove Programs on the Control Panel.\n\nLookup forms: 1638, 0x666, error 1638, ERROR_PRODUCT_VERSION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1638"]},{"id":953,"title":"ERROR_INVALID_COMMAND_LINE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1639","0x667","error 1639","ERROR_INVALID_COMMAND_LINE","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","invalid","command","line","argument","consult","the","windows","installer","sdk","for","detailed","help"],"errorCode":"1639","eventId":"","severity":"Medium","summary":"Invalid command line argument. Consult the Windows Installer SDK for detailed command line help.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 1639; use the surrounding log entries to confirm it.","resolution":"1. Record where 1639 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_COMMAND_LINE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1639 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid command line argument. Consult the Windows Installer SDK for detailed command line help.\n\nLookup forms: 1639, 0x667, error 1639, ERROR_INVALID_COMMAND_LINE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1639"]},{"id":954,"title":"ERROR_INSTALL_REMOTE_DISALLOWED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1640","0x668","error 1640","ERROR_INSTALL_REMOTE_DISALLOWED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","install","remote","disallowed","only","administrators","have","permission","add","remove","configure","server","software","during","terminal","services","session","you","want","the","contact","your","network","administrator"],"errorCode":"1640","eventId":"","severity":"High","summary":"Only administrators have permission to add, remove, or configure server software during a Terminal services remote session. If you want to install or configure software on the server, contact your network administrator.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1640; use the surrounding log entries to confirm it.","resolution":"1. Record where 1640 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Verify the required service or agent is installed, running, and current; repair the component if needed.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_REMOTE_DISALLOWED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1640 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Only administrators have permission to add, remove, or configure server software during a Terminal services remote session. If you want to install or configure software on the server, contact your network administrator.\n\nLookup forms: 1640, 0x668, error 1640, ERROR_INSTALL_REMOTE_DISALLOWED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Only administrators have permission to add, remove, or configure server software during a Terminal Services remote session. If you want to install or configure software on the server, contact your network administrator.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1640"]},{"id":955,"title":"ERROR_SUCCESS_REBOOT_INITIATED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1641","0x669","error 1641","ERROR_SUCCESS_REBOOT_INITIATED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","success","reboot","initiated","the","requested","operation","completed","successfully","system","will","restarted","changes","can","take","effect"],"errorCode":"1641","eventId":"","severity":"Low","summary":"The requested operation completed successfully. The system will be restarted so the changes can take effect.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1641; use the surrounding log entries to confirm it.","resolution":"1. Record where 1641 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SUCCESS_REBOOT_INITIATED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1641 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested operation completed successfully. The system will be restarted so the changes can take effect.\n\nLookup forms: 1641, 0x669, error 1641, ERROR_SUCCESS_REBOOT_INITIATED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1641"]},{"id":956,"title":"ERROR_PATCH_TARGET_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1642","0x66A","error 1642","ERROR_PATCH_TARGET_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","patch","target","not","found","the","upgrade","cannot","installed","windows","installer","service","because","program","upgraded","may","missing","update","different","version","verify","that","exists","your","computer"],"errorCode":"1642","eventId":"","severity":"Medium","summary":"The upgrade cannot be installed by the Windows Installer service because the program to be upgraded may be missing, or the upgrade may update a different version of the program. Verify that the program to be upgraded exists on your computer and that you have the correct upgrade.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1642; use the surrounding log entries to confirm it.","resolution":"1. Record where 1642 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PATCH_TARGET_NOT_FOUND.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1642 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The upgrade cannot be installed by the Windows Installer service because the program to be upgraded may be missing, or the upgrade may update a different version of the program. Verify that the program to be upgraded exists on your computer and that you have the correct upgrade.\n\nLookup forms: 1642, 0x66A, error 1642, ERROR_PATCH_TARGET_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The upgrade patch cannot be installed by the Windows Installer service because the program to be upgraded may be missing, or the upgrade patch may update a different version of the program. Verify that the program to be upgraded exists on your computer and that you have the correct upgrade patch.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1642"]},{"id":957,"title":"ERROR_PATCH_PACKAGE_REJECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1643","0x66B","error 1643","ERROR_PATCH_PACKAGE_REJECTED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","patch","package","rejected","the","update","not","permitted","software","restriction","policy"],"errorCode":"1643","eventId":"","severity":"Low","summary":"The update package is not permitted by software restriction policy.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 1643; use the surrounding log entries to confirm it.","resolution":"1. Record where 1643 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PATCH_PACKAGE_REJECTED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1643 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The update package is not permitted by software restriction policy.\n\nLookup forms: 1643, 0x66B, error 1643, ERROR_PATCH_PACKAGE_REJECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The patch package is not permitted by software restriction policy.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1643"]},{"id":958,"title":"ERROR_INSTALL_TRANSFORM_REJECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1644","0x66C","error 1644","ERROR_INSTALL_TRANSFORM_REJECTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","install","transform","rejected","one","more","customizations","are","not","permitted","software","restriction","policy"],"errorCode":"1644","eventId":"","severity":"Low","summary":"One or more customizations are not permitted by software restriction policy.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1644; use the surrounding log entries to confirm it.","resolution":"1. Record where 1644 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_TRANSFORM_REJECTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1644 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: One or more customizations are not permitted by software restriction policy.\n\nLookup forms: 1644, 0x66C, error 1644, ERROR_INSTALL_TRANSFORM_REJECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1644"]},{"id":959,"title":"ERROR_INSTALL_REMOTE_PROHIBITED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1645","0x66D","error 1645","ERROR_INSTALL_REMOTE_PROHIBITED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","install","remote","prohibited","the","windows","installer","does","not","permit","installation","from","desktop","connection"],"errorCode":"1645","eventId":"","severity":"High","summary":"The Windows Installer does not permit installation from a Remote Desktop Connection.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1645; use the surrounding log entries to confirm it.","resolution":"1. Record where 1645 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_REMOTE_PROHIBITED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1645 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Windows Installer does not permit installation from a Remote Desktop Connection.\n\nLookup forms: 1645, 0x66D, error 1645, ERROR_INSTALL_REMOTE_PROHIBITED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1645"]},{"id":960,"title":"ERROR_PATCH_REMOVAL_UNSUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1646","0x66E","error 1646","ERROR_PATCH_REMOVAL_UNSUPPORTED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","patch","removal","unsupported","uninstallation","the","update","package","not","supported"],"errorCode":"1646","eventId":"","severity":"Medium","summary":"Uninstallation of the update package is not supported.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 1646; use the surrounding log entries to confirm it.","resolution":"1. Record where 1646 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PATCH_REMOVAL_UNSUPPORTED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1646 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Uninstallation of the update package is not supported.\n\nLookup forms: 1646, 0x66E, error 1646, ERROR_PATCH_REMOVAL_UNSUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1646"]},{"id":961,"title":"ERROR_UNKNOWN_PATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1647","0x66F","error 1647","ERROR_UNKNOWN_PATCH","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","unknown","patch","the","update","not","applied","this","product"],"errorCode":"1647","eventId":"","severity":"Low","summary":"The update is not applied to this product.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 1647; use the surrounding log entries to confirm it.","resolution":"1. Record where 1647 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNKNOWN_PATCH.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1647 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The update is not applied to this product.\n\nLookup forms: 1647, 0x66F, error 1647, ERROR_UNKNOWN_PATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1647"]},{"id":962,"title":"ERROR_PATCH_NO_SEQUENCE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1648","0x670","error 1648","ERROR_PATCH_NO_SEQUENCE","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","patch","sequence","valid","could","found","for","the","set","updates"],"errorCode":"1648","eventId":"","severity":"Low","summary":"No valid sequence could be found for the set of updates.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 1648; use the surrounding log entries to confirm it.","resolution":"1. Record where 1648 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PATCH_NO_SEQUENCE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1648 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No valid sequence could be found for the set of updates.\n\nLookup forms: 1648, 0x670, error 1648, ERROR_PATCH_NO_SEQUENCE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1648"]},{"id":963,"title":"ERROR_PATCH_REMOVAL_DISALLOWED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1649","0x671","error 1649","ERROR_PATCH_REMOVAL_DISALLOWED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","patch","removal","disallowed","update","was","policy"],"errorCode":"1649","eventId":"","severity":"Low","summary":"Update removal was disallowed by policy.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 1649; use the surrounding log entries to confirm it.","resolution":"1. Record where 1649 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PATCH_REMOVAL_DISALLOWED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1649 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Update removal was disallowed by policy.\n\nLookup forms: 1649, 0x671, error 1649, ERROR_PATCH_REMOVAL_DISALLOWED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1649"]},{"id":964,"title":"ERROR_INVALID_PATCH_XML","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1650","0x672","error 1650","ERROR_INVALID_PATCH_XML","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","invalid","patch","xml","the","update","data"],"errorCode":"1650","eventId":"","severity":"Medium","summary":"The XML update data is invalid.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 1650; use the surrounding log entries to confirm it.","resolution":"1. Record where 1650 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_PATCH_XML.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1650 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The XML update data is invalid.\n\nLookup forms: 1650, 0x672, error 1650, ERROR_INVALID_PATCH_XML. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1650"]},{"id":965,"title":"ERROR_PATCH_MANAGED_ADVERTISED_PRODUCT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1651","0x673","error 1651","ERROR_PATCH_MANAGED_ADVERTISED_PRODUCT","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","patch","managed","advertised","product","windows","installer","does","not","permit","updating","products","least","one","feature","the","must","installed","before","applying","update"],"errorCode":"1651","eventId":"","severity":"Low","summary":"Windows Installer does not permit updating of managed advertised products. At least one feature of the product must be installed before applying the update.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 1651; use the surrounding log entries to confirm it.","resolution":"1. Record where 1651 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PATCH_MANAGED_ADVERTISED_PRODUCT.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1651 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Windows Installer does not permit updating of managed advertised products. At least one feature of the product must be installed before applying the update.\n\nLookup forms: 1651, 0x673, error 1651, ERROR_PATCH_MANAGED_ADVERTISED_PRODUCT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1651"]},{"id":966,"title":"ERROR_INSTALL_SERVICE_SAFEBOOT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1652","0x674","error 1652","ERROR_INSTALL_SERVICE_SAFEBOOT","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","install","service","safeboot","the","windows","installer","not","accessible","safe","mode","please","try","again","when","your","computer","you","can","use","system","restore","return","machine","previous"],"errorCode":"1652","eventId":"","severity":"Low","summary":"The Windows Installer service is not accessible in Safe Mode. Please try again when your computer is not in Safe Mode or you can use System Restore to return your machine to a previous good state.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1652; use the surrounding log entries to confirm it.","resolution":"1. Record where 1652 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_SERVICE_SAFEBOOT.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1652 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Windows Installer service is not accessible in Safe Mode. Please try again when your computer is not in Safe Mode or you can use System Restore to return your machine to a previous good state.\n\nLookup forms: 1652, 0x674, error 1652, ERROR_INSTALL_SERVICE_SAFEBOOT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1652"]},{"id":967,"title":"ERROR_FAIL_FAST_EXCEPTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1653","0x675","error 1653","ERROR_FAIL_FAST_EXCEPTION","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","fail","fast","exception","occurred","handlers","will","not","invoked","and","the","process","terminated","immediately"],"errorCode":"1653","eventId":"","severity":"Low","summary":"A fail fast exception occurred. Exception handlers will not be invoked and the process will be terminated immediately.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1653; use the surrounding log entries to confirm it.","resolution":"1. Record where 1653 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FAIL_FAST_EXCEPTION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1653 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A fail fast exception occurred. Exception handlers will not be invoked and the process will be terminated immediately.\n\nLookup forms: 1653, 0x675, error 1653, ERROR_FAIL_FAST_EXCEPTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1653"]},{"id":968,"title":"ERROR_INSTALL_REJECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1654","0x676","error 1654","ERROR_INSTALL_REJECTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","install","rejected","the","app","that","you","are","trying","run","not","supported","this","version","windows"],"errorCode":"1654","eventId":"","severity":"Medium","summary":"The app that you are trying to run is not supported on this version of Windows.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1654; use the surrounding log entries to confirm it.","resolution":"1. Record where 1654 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_REJECTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1654 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The app that you are trying to run is not supported on this version of Windows.\n\nLookup forms: 1654, 0x676, error 1654, ERROR_INSTALL_REJECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1654"]},{"id":969,"title":"RPC_S_INVALID_STRING_BINDING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1700","0x6A4","error 1700","RPC_S_INVALID_STRING_BINDING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","invalid","string","binding","the"],"errorCode":"1700","eventId":"","severity":"Medium","summary":"The string binding is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1700; use the surrounding log entries to confirm it.","resolution":"1. Record where 1700 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_INVALID_STRING_BINDING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1700 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The string binding is invalid.\n\nLookup forms: 1700, 0x6A4, error 1700, RPC_S_INVALID_STRING_BINDING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1700"]},{"id":970,"title":"RPC_S_WRONG_KIND_OF_BINDING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1701","0x6A5","error 1701","RPC_S_WRONG_KIND_OF_BINDING","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","rpc","wrong","kind","binding","the","handle","not","correct","type"],"errorCode":"1701","eventId":"","severity":"Low","summary":"The binding handle is not the correct type.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1701; use the surrounding log entries to confirm it.","resolution":"1. Record where 1701 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_WRONG_KIND_OF_BINDING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1701 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The binding handle is not the correct type.\n\nLookup forms: 1701, 0x6A5, error 1701, RPC_S_WRONG_KIND_OF_BINDING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1701"]},{"id":971,"title":"RPC_S_INVALID_BINDING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1702","0x6A6","error 1702","RPC_S_INVALID_BINDING","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","rpc","invalid","binding","the","handle"],"errorCode":"1702","eventId":"","severity":"Medium","summary":"The binding handle is invalid.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1702; use the surrounding log entries to confirm it.","resolution":"1. Record where 1702 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_INVALID_BINDING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1702 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The binding handle is invalid.\n\nLookup forms: 1702, 0x6A6, error 1702, RPC_S_INVALID_BINDING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1702"]},{"id":972,"title":"RPC_S_PROTSEQ_NOT_SUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1703","0x6A7","error 1703","RPC_S_PROTSEQ_NOT_SUPPORTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","protseq","not","supported","the","protocol","sequence"],"errorCode":"1703","eventId":"","severity":"Medium","summary":"The RPC protocol sequence is not supported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1703; use the surrounding log entries to confirm it.","resolution":"1. Record where 1703 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_PROTSEQ_NOT_SUPPORTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1703 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The RPC protocol sequence is not supported.\n\nLookup forms: 1703, 0x6A7, error 1703, RPC_S_PROTSEQ_NOT_SUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1703"]},{"id":973,"title":"RPC_S_INVALID_RPC_PROTSEQ","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1704","0x6A8","error 1704","RPC_S_INVALID_RPC_PROTSEQ","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","invalid","protseq","the","protocol","sequence"],"errorCode":"1704","eventId":"","severity":"Medium","summary":"The RPC protocol sequence is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1704; use the surrounding log entries to confirm it.","resolution":"1. Record where 1704 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_INVALID_RPC_PROTSEQ.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1704 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The RPC protocol sequence is invalid.\n\nLookup forms: 1704, 0x6A8, error 1704, RPC_S_INVALID_RPC_PROTSEQ. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1704"]},{"id":974,"title":"RPC_S_INVALID_STRING_UUID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1705","0x6A9","error 1705","RPC_S_INVALID_STRING_UUID","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","invalid","string","uuid","the","universal","unique","identifier"],"errorCode":"1705","eventId":"","severity":"Medium","summary":"The string universal unique identifier (UUID) is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1705; use the surrounding log entries to confirm it.","resolution":"1. Record where 1705 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_INVALID_STRING_UUID.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1705 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The string universal unique identifier (UUID) is invalid.\n\nLookup forms: 1705, 0x6A9, error 1705, RPC_S_INVALID_STRING_UUID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1705"]},{"id":975,"title":"RPC_S_INVALID_ENDPOINT_FORMAT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1706","0x6AA","error 1706","RPC_S_INVALID_ENDPOINT_FORMAT","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","rpc","invalid","endpoint","format","the"],"errorCode":"1706","eventId":"","severity":"Medium","summary":"The endpoint format is invalid.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1706; use the surrounding log entries to confirm it.","resolution":"1. Record where 1706 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_INVALID_ENDPOINT_FORMAT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1706 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The endpoint format is invalid.\n\nLookup forms: 1706, 0x6AA, error 1706, RPC_S_INVALID_ENDPOINT_FORMAT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1706"]},{"id":976,"title":"RPC_S_INVALID_NET_ADDR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1707","0x6AB","error 1707","RPC_S_INVALID_NET_ADDR","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","rpc","invalid","net","addr","the","network","address"],"errorCode":"1707","eventId":"","severity":"High","summary":"The network address is invalid.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1707; use the surrounding log entries to confirm it.","resolution":"1. Record where 1707 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_INVALID_NET_ADDR.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1707 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The network address is invalid.\n\nLookup forms: 1707, 0x6AB, error 1707, RPC_S_INVALID_NET_ADDR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1707"]},{"id":977,"title":"RPC_S_NO_ENDPOINT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1708","0x6AC","error 1708","RPC_S_NO_ENDPOINT_FOUND","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","rpc","endpoint","found","was"],"errorCode":"1708","eventId":"","severity":"Low","summary":"No endpoint was found.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1708; use the surrounding log entries to confirm it.","resolution":"1. Record where 1708 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_NO_ENDPOINT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1708 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No endpoint was found.\n\nLookup forms: 1708, 0x6AC, error 1708, RPC_S_NO_ENDPOINT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1708"]},{"id":978,"title":"RPC_S_INVALID_TIMEOUT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1709","0x6AD","error 1709","RPC_S_INVALID_TIMEOUT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","invalid","timeout","the","value"],"errorCode":"1709","eventId":"","severity":"Medium","summary":"The timeout value is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1709; use the surrounding log entries to confirm it.","resolution":"1. Record where 1709 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_INVALID_TIMEOUT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1709 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The timeout value is invalid.\n\nLookup forms: 1709, 0x6AD, error 1709, RPC_S_INVALID_TIMEOUT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1709"]},{"id":979,"title":"RPC_S_OBJECT_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1710","0x6AE","error 1710","RPC_S_OBJECT_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","object","not","found","the","universal","unique","identifier","uuid","was"],"errorCode":"1710","eventId":"","severity":"Medium","summary":"The object universal unique identifier (UUID) was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1710; use the surrounding log entries to confirm it.","resolution":"1. Record where 1710 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_OBJECT_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1710 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The object universal unique identifier (UUID) was not found.\n\nLookup forms: 1710, 0x6AE, error 1710, RPC_S_OBJECT_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1710"]},{"id":980,"title":"RPC_S_ALREADY_REGISTERED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1711","0x6AF","error 1711","RPC_S_ALREADY_REGISTERED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","already","registered","the","object","universal","unique","identifier","uuid","has","been"],"errorCode":"1711","eventId":"","severity":"Low","summary":"The object universal unique identifier (UUID) has already been registered.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1711; use the surrounding log entries to confirm it.","resolution":"1. Record where 1711 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_ALREADY_REGISTERED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1711 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The object universal unique identifier (UUID) has already been registered.\n\nLookup forms: 1711, 0x6AF, error 1711, RPC_S_ALREADY_REGISTERED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1711"]},{"id":981,"title":"RPC_S_TYPE_ALREADY_REGISTERED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1712","0x6B0","error 1712","RPC_S_TYPE_ALREADY_REGISTERED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","type","already","registered","the","universal","unique","identifier","uuid","has","been"],"errorCode":"1712","eventId":"","severity":"Low","summary":"The type universal unique identifier (UUID) has already been registered.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1712; use the surrounding log entries to confirm it.","resolution":"1. Record where 1712 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_TYPE_ALREADY_REGISTERED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1712 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The type universal unique identifier (UUID) has already been registered.\n\nLookup forms: 1712, 0x6B0, error 1712, RPC_S_TYPE_ALREADY_REGISTERED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1712"]},{"id":982,"title":"RPC_S_ALREADY_LISTENING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1713","0x6B1","error 1713","RPC_S_ALREADY_LISTENING","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","rpc","already","listening","the","server"],"errorCode":"1713","eventId":"","severity":"Low","summary":"The RPC server is already listening.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1713; use the surrounding log entries to confirm it.","resolution":"1. Record where 1713 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_ALREADY_LISTENING.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1713 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The RPC server is already listening.\n\nLookup forms: 1713, 0x6B1, error 1713, RPC_S_ALREADY_LISTENING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1713"]},{"id":983,"title":"RPC_S_NO_PROTSEQS_REGISTERED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1714","0x6B2","error 1714","RPC_S_NO_PROTSEQS_REGISTERED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","protseqs","registered","protocol","sequences","have","been"],"errorCode":"1714","eventId":"","severity":"Low","summary":"No protocol sequences have been registered.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1714; use the surrounding log entries to confirm it.","resolution":"1. Record where 1714 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_NO_PROTSEQS_REGISTERED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1714 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No protocol sequences have been registered.\n\nLookup forms: 1714, 0x6B2, error 1714, RPC_S_NO_PROTSEQS_REGISTERED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1714"]},{"id":984,"title":"RPC_S_NOT_LISTENING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1715","0x6B3","error 1715","RPC_S_NOT_LISTENING","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","rpc","not","listening","the","server"],"errorCode":"1715","eventId":"","severity":"Low","summary":"The RPC server is not listening.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1715; use the surrounding log entries to confirm it.","resolution":"1. Record where 1715 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_NOT_LISTENING.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1715 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The RPC server is not listening.\n\nLookup forms: 1715, 0x6B3, error 1715, RPC_S_NOT_LISTENING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1715"]},{"id":985,"title":"RPC_S_UNKNOWN_MGR_TYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1716","0x6B4","error 1716","RPC_S_UNKNOWN_MGR_TYPE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","unknown","mgr","type","the","manager"],"errorCode":"1716","eventId":"","severity":"Low","summary":"The manager type is unknown.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1716; use the surrounding log entries to confirm it.","resolution":"1. Record where 1716 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_UNKNOWN_MGR_TYPE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1716 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The manager type is unknown.\n\nLookup forms: 1716, 0x6B4, error 1716, RPC_S_UNKNOWN_MGR_TYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1716"]},{"id":986,"title":"RPC_S_UNKNOWN_IF","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1717","0x6B5","error 1717","RPC_S_UNKNOWN_IF","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","unknown","the","interface"],"errorCode":"1717","eventId":"","severity":"Low","summary":"The interface is unknown.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1717; use the surrounding log entries to confirm it.","resolution":"1. Record where 1717 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_UNKNOWN_IF.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1717 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The interface is unknown.\n\nLookup forms: 1717, 0x6B5, error 1717, RPC_S_UNKNOWN_IF. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1717"]},{"id":987,"title":"RPC_S_NO_BINDINGS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1718","0x6B6","error 1718","RPC_S_NO_BINDINGS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","bindings","there","are"],"errorCode":"1718","eventId":"","severity":"Low","summary":"There are no bindings.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1718; use the surrounding log entries to confirm it.","resolution":"1. Record where 1718 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_NO_BINDINGS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1718 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There are no bindings.\n\nLookup forms: 1718, 0x6B6, error 1718, RPC_S_NO_BINDINGS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1718"]},{"id":988,"title":"RPC_S_NO_PROTSEQS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1719","0x6B7","error 1719","RPC_S_NO_PROTSEQS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","protseqs","there","are","protocol","sequences"],"errorCode":"1719","eventId":"","severity":"Low","summary":"There are no protocol sequences.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1719; use the surrounding log entries to confirm it.","resolution":"1. Record where 1719 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_NO_PROTSEQS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1719 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There are no protocol sequences.\n\nLookup forms: 1719, 0x6B7, error 1719, RPC_S_NO_PROTSEQS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1719"]},{"id":989,"title":"RPC_S_CANT_CREATE_ENDPOINT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1720","0x6B8","error 1720","RPC_S_CANT_CREATE_ENDPOINT","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","rpc","cant","create","endpoint","the","cannot","created"],"errorCode":"1720","eventId":"","severity":"Medium","summary":"The endpoint cannot be created.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1720; use the surrounding log entries to confirm it.","resolution":"1. Record where 1720 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_CANT_CREATE_ENDPOINT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1720 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The endpoint cannot be created.\n\nLookup forms: 1720, 0x6B8, error 1720, RPC_S_CANT_CREATE_ENDPOINT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1720"]},{"id":990,"title":"RPC_S_OUT_OF_RESOURCES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1721","0x6B9","error 1721","RPC_S_OUT_OF_RESOURCES","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","out","resources","not","enough","are","available","complete","this","operation"],"errorCode":"1721","eventId":"","severity":"Low","summary":"Not enough resources are available to complete this operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1721; use the surrounding log entries to confirm it.","resolution":"1. Record where 1721 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_OUT_OF_RESOURCES.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1721 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Not enough resources are available to complete this operation.\n\nLookup forms: 1721, 0x6B9, error 1721, RPC_S_OUT_OF_RESOURCES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1721"]},{"id":991,"title":"RPC_S_SERVER_UNAVAILABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1722","0x6BA","error 1722","RPC_S_SERVER_UNAVAILABLE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","rpc","server","unavailable","the","dns","and","networking"],"errorCode":"1722","eventId":"","severity":"Low","summary":"The RPC server is unavailable.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1722; use the surrounding log entries to confirm it.","resolution":"1. Record where 1722 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_SERVER_UNAVAILABLE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1722 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The RPC server is unavailable.\n\nLookup forms: 1722, 0x6BA, error 1722, RPC_S_SERVER_UNAVAILABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (microsoft_windows_error_code_master_list.txt): Category: DNS AND NETWORKING\nDescription: The RPC server is unavailable.\n\nFixes:\n1. Verify the exact host, IP, port, route, gateway, and DNS response from the affected device.\n2. Review firewall, proxy, VPN, load balancer, TLS inspection, and remote service health.\n3. Capture a network trace if the failure source is unclear, correct it, and retest connectivity.\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf; microsoft_windows_error_code_master_list.txt","commands":[],"platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1722"]},{"id":992,"title":"RPC_S_SERVER_TOO_BUSY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1723","0x6BB","error 1723","RPC_S_SERVER_TOO_BUSY","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","rpc","server","too","busy","the","complete","this","operation"],"errorCode":"1723","eventId":"","severity":"Medium","summary":"The RPC server is too busy to complete this operation.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1723; use the surrounding log entries to confirm it.","resolution":"1. Record where 1723 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_SERVER_TOO_BUSY.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1723 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The RPC server is too busy to complete this operation.\n\nLookup forms: 1723, 0x6BB, error 1723, RPC_S_SERVER_TOO_BUSY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1723"]},{"id":993,"title":"RPC_S_INVALID_NETWORK_OPTIONS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1724","0x6BC","error 1724","RPC_S_INVALID_NETWORK_OPTIONS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","rpc","invalid","network","options","the","are"],"errorCode":"1724","eventId":"","severity":"High","summary":"The network options are invalid.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1724; use the surrounding log entries to confirm it.","resolution":"1. Record where 1724 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_INVALID_NETWORK_OPTIONS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1724 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The network options are invalid.\n\nLookup forms: 1724, 0x6BC, error 1724, RPC_S_INVALID_NETWORK_OPTIONS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1724"]},{"id":994,"title":"RPC_S_NO_CALL_ACTIVE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1725","0x6BD","error 1725","RPC_S_NO_CALL_ACTIVE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","rpc","call","active","there","are","remote","procedure","calls","this","thread"],"errorCode":"1725","eventId":"","severity":"Low","summary":"There are no remote procedure calls active on this thread.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1725; use the surrounding log entries to confirm it.","resolution":"1. Record where 1725 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_NO_CALL_ACTIVE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1725 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There are no remote procedure calls active on this thread.\n\nLookup forms: 1725, 0x6BD, error 1725, RPC_S_NO_CALL_ACTIVE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1725"]},{"id":995,"title":"RPC_S_CALL_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1726","0x6BE","error 1726","RPC_S_CALL_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","call","failed","the","remote","procedure"],"errorCode":"1726","eventId":"","severity":"High","summary":"The remote procedure call failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1726; use the surrounding log entries to confirm it.","resolution":"1. Record where 1726 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_CALL_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1726 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The remote procedure call failed.\n\nLookup forms: 1726, 0x6BE, error 1726, RPC_S_CALL_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1726"]},{"id":996,"title":"RPC_S_CALL_FAILED_DNE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1727","0x6BF","error 1727","RPC_S_CALL_FAILED_DNE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","call","failed","dne","the","remote","procedure","and","did","not","execute"],"errorCode":"1727","eventId":"","severity":"High","summary":"The remote procedure call failed and did not execute.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1727; use the surrounding log entries to confirm it.","resolution":"1. Record where 1727 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_CALL_FAILED_DNE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1727 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The remote procedure call failed and did not execute.\n\nLookup forms: 1727, 0x6BF, error 1727, RPC_S_CALL_FAILED_DNE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1727"]},{"id":997,"title":"RPC_S_PROTOCOL_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1728","0x6C0","error 1728","RPC_S_PROTOCOL_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","protocol","error","remote","procedure","call","occurred"],"errorCode":"1728","eventId":"","severity":"Low","summary":"A remote procedure call (RPC) protocol error occurred.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1728; use the surrounding log entries to confirm it.","resolution":"1. Record where 1728 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_PROTOCOL_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1728 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A remote procedure call (RPC) protocol error occurred.\n\nLookup forms: 1728, 0x6C0, error 1728, RPC_S_PROTOCOL_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1728"]},{"id":998,"title":"RPC_S_PROXY_ACCESS_DENIED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1729","0x6C1","error 1729","RPC_S_PROXY_ACCESS_DENIED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","rpc","proxy","access","denied","the","http"],"errorCode":"1729","eventId":"","severity":"Low","summary":"Access to the HTTP proxy is denied.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1729; use the surrounding log entries to confirm it.","resolution":"1. Record where 1729 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_PROXY_ACCESS_DENIED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1729 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Access to the HTTP proxy is denied.\n\nLookup forms: 1729, 0x6C1, error 1729, RPC_S_PROXY_ACCESS_DENIED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1729"]},{"id":999,"title":"RPC_S_UNSUPPORTED_TRANS_SYN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1730","0x6C2","error 1730","RPC_S_UNSUPPORTED_TRANS_SYN","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","rpc","unsupported","trans","syn","the","transfer","syntax","not","supported","server"],"errorCode":"1730","eventId":"","severity":"Medium","summary":"The transfer syntax is not supported by the RPC server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1730; use the surrounding log entries to confirm it.","resolution":"1. Record where 1730 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_UNSUPPORTED_TRANS_SYN.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1730 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The transfer syntax is not supported by the RPC server.\n\nLookup forms: 1730, 0x6C2, error 1730, RPC_S_UNSUPPORTED_TRANS_SYN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1730"]},{"id":1000,"title":"RPC_S_UNSUPPORTED_TYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1732","0x6C4","error 1732","RPC_S_UNSUPPORTED_TYPE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","unsupported","type","the","universal","unique","identifier","uuid","not","supported"],"errorCode":"1732","eventId":"","severity":"Medium","summary":"The universal unique identifier (UUID) type is not supported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1732; use the surrounding log entries to confirm it.","resolution":"1. Record where 1732 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_UNSUPPORTED_TYPE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1732 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The universal unique identifier (UUID) type is not supported.\n\nLookup forms: 1732, 0x6C4, error 1732, RPC_S_UNSUPPORTED_TYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1732"]},{"id":1001,"title":"RPC_S_INVALID_TAG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1733","0x6C5","error 1733","RPC_S_INVALID_TAG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","invalid","tag","the"],"errorCode":"1733","eventId":"","severity":"Medium","summary":"The tag is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1733; use the surrounding log entries to confirm it.","resolution":"1. Record where 1733 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_INVALID_TAG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1733 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The tag is invalid.\n\nLookup forms: 1733, 0x6C5, error 1733, RPC_S_INVALID_TAG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1733"]},{"id":1002,"title":"RPC_S_INVALID_BOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1734","0x6C6","error 1734","RPC_S_INVALID_BOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","invalid","bound","the","array","bounds","are"],"errorCode":"1734","eventId":"","severity":"Medium","summary":"The array bounds are invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1734; use the surrounding log entries to confirm it.","resolution":"1. Record where 1734 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_INVALID_BOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1734 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The array bounds are invalid.\n\nLookup forms: 1734, 0x6C6, error 1734, RPC_S_INVALID_BOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1734"]},{"id":1003,"title":"RPC_S_NO_ENTRY_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1735","0x6C7","error 1735","RPC_S_NO_ENTRY_NAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","entry","name","the","binding","does","not","contain"],"errorCode":"1735","eventId":"","severity":"Low","summary":"The binding does not contain an entry name.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1735; use the surrounding log entries to confirm it.","resolution":"1. Record where 1735 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_NO_ENTRY_NAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1735 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The binding does not contain an entry name.\n\nLookup forms: 1735, 0x6C7, error 1735, RPC_S_NO_ENTRY_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1735"]},{"id":1004,"title":"RPC_S_INVALID_NAME_SYNTAX","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1736","0x6C8","error 1736","RPC_S_INVALID_NAME_SYNTAX","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","invalid","name","syntax","the"],"errorCode":"1736","eventId":"","severity":"Medium","summary":"The name syntax is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1736; use the surrounding log entries to confirm it.","resolution":"1. Record where 1736 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_INVALID_NAME_SYNTAX.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1736 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The name syntax is invalid.\n\nLookup forms: 1736, 0x6C8, error 1736, RPC_S_INVALID_NAME_SYNTAX. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1736"]},{"id":1005,"title":"RPC_S_UNSUPPORTED_NAME_SYNTAX","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1737","0x6C9","error 1737","RPC_S_UNSUPPORTED_NAME_SYNTAX","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","unsupported","name","syntax","the","not","supported"],"errorCode":"1737","eventId":"","severity":"Medium","summary":"The name syntax is not supported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1737; use the surrounding log entries to confirm it.","resolution":"1. Record where 1737 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_UNSUPPORTED_NAME_SYNTAX.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1737 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The name syntax is not supported.\n\nLookup forms: 1737, 0x6C9, error 1737, RPC_S_UNSUPPORTED_NAME_SYNTAX. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1737"]},{"id":1006,"title":"RPC_S_UUID_NO_ADDRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1739","0x6CB","error 1739","RPC_S_UUID_NO_ADDRESS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","rpc","uuid","address","network","available","use","construct","universal","unique","identifier"],"errorCode":"1739","eventId":"","severity":"High","summary":"No network address is available to use to construct a universal unique identifier (UUID).","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1739; use the surrounding log entries to confirm it.","resolution":"1. Record where 1739 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_UUID_NO_ADDRESS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1739 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No network address is available to use to construct a universal unique identifier (UUID).\n\nLookup forms: 1739, 0x6CB, error 1739, RPC_S_UUID_NO_ADDRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1739"]},{"id":1007,"title":"RPC_S_DUPLICATE_ENDPOINT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1740","0x6CC","error 1740","RPC_S_DUPLICATE_ENDPOINT","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","rpc","duplicate","endpoint","the"],"errorCode":"1740","eventId":"","severity":"Low","summary":"The endpoint is a duplicate.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1740; use the surrounding log entries to confirm it.","resolution":"1. Record where 1740 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_DUPLICATE_ENDPOINT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1740 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The endpoint is a duplicate.\n\nLookup forms: 1740, 0x6CC, error 1740, RPC_S_DUPLICATE_ENDPOINT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1740"]},{"id":1008,"title":"RPC_S_UNKNOWN_AUTHN_TYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1741","0x6CD","error 1741","RPC_S_UNKNOWN_AUTHN_TYPE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","rpc","unknown","authn","type","the","authentication"],"errorCode":"1741","eventId":"","severity":"High","summary":"The authentication type is unknown.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1741; use the surrounding log entries to confirm it.","resolution":"1. Record where 1741 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_UNKNOWN_AUTHN_TYPE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1741 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The authentication type is unknown.\n\nLookup forms: 1741, 0x6CD, error 1741, RPC_S_UNKNOWN_AUTHN_TYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1741"]},{"id":1009,"title":"RPC_S_MAX_CALLS_TOO_SMALL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1742","0x6CE","error 1742","RPC_S_MAX_CALLS_TOO_SMALL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","max","calls","too","small","the","maximum","number"],"errorCode":"1742","eventId":"","severity":"Low","summary":"The maximum number of calls is too small.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1742; use the surrounding log entries to confirm it.","resolution":"1. Record where 1742 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_MAX_CALLS_TOO_SMALL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1742 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The maximum number of calls is too small.\n\nLookup forms: 1742, 0x6CE, error 1742, RPC_S_MAX_CALLS_TOO_SMALL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1742"]},{"id":1010,"title":"RPC_S_STRING_TOO_LONG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1743","0x6CF","error 1743","RPC_S_STRING_TOO_LONG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","string","too","long","the"],"errorCode":"1743","eventId":"","severity":"Low","summary":"The string is too long.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1743; use the surrounding log entries to confirm it.","resolution":"1. Record where 1743 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_STRING_TOO_LONG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1743 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The string is too long.\n\nLookup forms: 1743, 0x6CF, error 1743, RPC_S_STRING_TOO_LONG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1743"]},{"id":1011,"title":"RPC_S_PROTSEQ_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1744","0x6D0","error 1744","RPC_S_PROTSEQ_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","protseq","not","found","the","protocol","sequence","was"],"errorCode":"1744","eventId":"","severity":"Medium","summary":"The RPC protocol sequence was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1744; use the surrounding log entries to confirm it.","resolution":"1. Record where 1744 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_PROTSEQ_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1744 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The RPC protocol sequence was not found.\n\nLookup forms: 1744, 0x6D0, error 1744, RPC_S_PROTSEQ_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1744"]},{"id":1012,"title":"RPC_S_PROCNUM_OUT_OF_RANGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1745","0x6D1","error 1745","RPC_S_PROCNUM_OUT_OF_RANGE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","procnum","out","range","the","procedure","number"],"errorCode":"1745","eventId":"","severity":"Low","summary":"The procedure number is out of range.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1745; use the surrounding log entries to confirm it.","resolution":"1. Record where 1745 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_PROCNUM_OUT_OF_RANGE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1745 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The procedure number is out of range.\n\nLookup forms: 1745, 0x6D1, error 1745, RPC_S_PROCNUM_OUT_OF_RANGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1745"]},{"id":1013,"title":"RPC_S_BINDING_HAS_NO_AUTH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1746","0x6D2","error 1746","RPC_S_BINDING_HAS_NO_AUTH","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","rpc","binding","has","auth","the","does","not","contain","any","authentication","information"],"errorCode":"1746","eventId":"","severity":"High","summary":"The binding does not contain any authentication information.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1746; use the surrounding log entries to confirm it.","resolution":"1. Record where 1746 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_BINDING_HAS_NO_AUTH.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1746 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The binding does not contain any authentication information.\n\nLookup forms: 1746, 0x6D2, error 1746, RPC_S_BINDING_HAS_NO_AUTH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1746"]},{"id":1014,"title":"RPC_S_UNKNOWN_AUTHN_SERVICE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1747","0x6D3","error 1747","RPC_S_UNKNOWN_AUTHN_SERVICE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","rpc","unknown","authn","service","the","authentication"],"errorCode":"1747","eventId":"","severity":"High","summary":"The authentication service is unknown.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1747; use the surrounding log entries to confirm it.","resolution":"1. Record where 1747 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_UNKNOWN_AUTHN_SERVICE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1747 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The authentication service is unknown.\n\nLookup forms: 1747, 0x6D3, error 1747, RPC_S_UNKNOWN_AUTHN_SERVICE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1747"]},{"id":1015,"title":"RPC_S_UNKNOWN_AUTHN_LEVEL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1748","0x6D4","error 1748","RPC_S_UNKNOWN_AUTHN_LEVEL","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","rpc","unknown","authn","level","the","authentication"],"errorCode":"1748","eventId":"","severity":"High","summary":"The authentication level is unknown.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1748; use the surrounding log entries to confirm it.","resolution":"1. Record where 1748 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_UNKNOWN_AUTHN_LEVEL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1748 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The authentication level is unknown.\n\nLookup forms: 1748, 0x6D4, error 1748, RPC_S_UNKNOWN_AUTHN_LEVEL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1748"]},{"id":1016,"title":"RPC_S_INVALID_AUTH_IDENTITY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1749","0x6D5","error 1749","RPC_S_INVALID_AUTH_IDENTITY","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","rpc","invalid","auth","identity","the","security","context"],"errorCode":"1749","eventId":"","severity":"Medium","summary":"The security context is invalid.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1749; use the surrounding log entries to confirm it.","resolution":"1. Record where 1749 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_INVALID_AUTH_IDENTITY.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1749 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The security context is invalid.\n\nLookup forms: 1749, 0x6D5, error 1749, RPC_S_INVALID_AUTH_IDENTITY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1749"]},{"id":1017,"title":"RPC_S_UNKNOWN_AUTHZ_SERVICE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1750","0x6D6","error 1750","RPC_S_UNKNOWN_AUTHZ_SERVICE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","rpc","unknown","authz","service","the","authorization"],"errorCode":"1750","eventId":"","severity":"Low","summary":"The authorization service is unknown.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1750; use the surrounding log entries to confirm it.","resolution":"1. Record where 1750 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_UNKNOWN_AUTHZ_SERVICE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1750 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The authorization service is unknown.\n\nLookup forms: 1750, 0x6D6, error 1750, RPC_S_UNKNOWN_AUTHZ_SERVICE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1750"]},{"id":1018,"title":"EPT_S_INVALID_ENTRY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1751","0x6D7","error 1751","EPT_S_INVALID_ENTRY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","ept","invalid","entry","the"],"errorCode":"1751","eventId":"","severity":"Medium","summary":"The entry is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1751; use the surrounding log entries to confirm it.","resolution":"1. Record where 1751 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to EPT_S_INVALID_ENTRY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1751 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The entry is invalid.\n\nLookup forms: 1751, 0x6D7, error 1751, EPT_S_INVALID_ENTRY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1751"]},{"id":1019,"title":"EPT_S_CANT_PERFORM_OP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1752","0x6D8","error 1752","EPT_S_CANT_PERFORM_OP","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","ept","cant","perform","the","server","endpoint","cannot","operation"],"errorCode":"1752","eventId":"","severity":"Medium","summary":"The server endpoint cannot perform the operation.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1752; use the surrounding log entries to confirm it.","resolution":"1. Record where 1752 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to EPT_S_CANT_PERFORM_OP.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1752 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The server endpoint cannot perform the operation.\n\nLookup forms: 1752, 0x6D8, error 1752, EPT_S_CANT_PERFORM_OP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1752"]},{"id":1020,"title":"EPT_S_NOT_REGISTERED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1753","0x6D9","error 1753","EPT_S_NOT_REGISTERED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","ept","not","registered","there","are","more","endpoints","available","from","the","endpoint","mapper"],"errorCode":"1753","eventId":"","severity":"Low","summary":"There are no more endpoints available from the endpoint mapper.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1753; use the surrounding log entries to confirm it.","resolution":"1. Record where 1753 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to EPT_S_NOT_REGISTERED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1753 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There are no more endpoints available from the endpoint mapper.\n\nLookup forms: 1753, 0x6D9, error 1753, EPT_S_NOT_REGISTERED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1753"]},{"id":1021,"title":"RPC_S_NOTHING_TO_EXPORT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1754","0x6DA","error 1754","RPC_S_NOTHING_TO_EXPORT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","nothing","export","interfaces","have","been","exported"],"errorCode":"1754","eventId":"","severity":"Low","summary":"No interfaces have been exported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1754; use the surrounding log entries to confirm it.","resolution":"1. Record where 1754 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_NOTHING_TO_EXPORT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1754 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No interfaces have been exported.\n\nLookup forms: 1754, 0x6DA, error 1754, RPC_S_NOTHING_TO_EXPORT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1754"]},{"id":1022,"title":"RPC_S_INCOMPLETE_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1755","0x6DB","error 1755","RPC_S_INCOMPLETE_NAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","incomplete","name","the","entry"],"errorCode":"1755","eventId":"","severity":"Low","summary":"The entry name is incomplete.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1755; use the surrounding log entries to confirm it.","resolution":"1. Record where 1755 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_INCOMPLETE_NAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1755 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The entry name is incomplete.\n\nLookup forms: 1755, 0x6DB, error 1755, RPC_S_INCOMPLETE_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1755"]},{"id":1023,"title":"RPC_S_INVALID_VERS_OPTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1756","0x6DC","error 1756","RPC_S_INVALID_VERS_OPTION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","invalid","vers","option","the","version"],"errorCode":"1756","eventId":"","severity":"Medium","summary":"The version option is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1756; use the surrounding log entries to confirm it.","resolution":"1. Record where 1756 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_INVALID_VERS_OPTION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1756 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The version option is invalid.\n\nLookup forms: 1756, 0x6DC, error 1756, RPC_S_INVALID_VERS_OPTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1756"]},{"id":1024,"title":"RPC_S_NO_MORE_MEMBERS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1757","0x6DD","error 1757","RPC_S_NO_MORE_MEMBERS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","more","members","there","are"],"errorCode":"1757","eventId":"","severity":"Low","summary":"There are no more members.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1757; use the surrounding log entries to confirm it.","resolution":"1. Record where 1757 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_NO_MORE_MEMBERS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1757 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There are no more members.\n\nLookup forms: 1757, 0x6DD, error 1757, RPC_S_NO_MORE_MEMBERS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1757"]},{"id":1025,"title":"RPC_S_NOT_ALL_OBJS_UNEXPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1758","0x6DE","error 1758","RPC_S_NOT_ALL_OBJS_UNEXPORTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","not","all","objs","unexported","there","nothing","unexport"],"errorCode":"1758","eventId":"","severity":"Low","summary":"There is nothing to unexport.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1758; use the surrounding log entries to confirm it.","resolution":"1. Record where 1758 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_NOT_ALL_OBJS_UNEXPORTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1758 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There is nothing to unexport.\n\nLookup forms: 1758, 0x6DE, error 1758, RPC_S_NOT_ALL_OBJS_UNEXPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1758"]},{"id":1026,"title":"RPC_S_INTERFACE_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1759","0x6DF","error 1759","RPC_S_INTERFACE_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","interface","not","found","the","was"],"errorCode":"1759","eventId":"","severity":"Medium","summary":"The interface was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1759; use the surrounding log entries to confirm it.","resolution":"1. Record where 1759 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_INTERFACE_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1759 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The interface was not found.\n\nLookup forms: 1759, 0x6DF, error 1759, RPC_S_INTERFACE_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1759"]},{"id":1027,"title":"RPC_S_ENTRY_ALREADY_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1760","0x6E0","error 1760","RPC_S_ENTRY_ALREADY_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","entry","already","exists","the"],"errorCode":"1760","eventId":"","severity":"Medium","summary":"The entry already exists.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1760; use the surrounding log entries to confirm it.","resolution":"1. Record where 1760 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_ENTRY_ALREADY_EXISTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1760 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The entry already exists.\n\nLookup forms: 1760, 0x6E0, error 1760, RPC_S_ENTRY_ALREADY_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1760"]},{"id":1028,"title":"RPC_S_ENTRY_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1761","0x6E1","error 1761","RPC_S_ENTRY_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","entry","not","found","the"],"errorCode":"1761","eventId":"","severity":"Medium","summary":"The entry is not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1761; use the surrounding log entries to confirm it.","resolution":"1. Record where 1761 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_ENTRY_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1761 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The entry is not found.\n\nLookup forms: 1761, 0x6E1, error 1761, RPC_S_ENTRY_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1761"]},{"id":1029,"title":"RPC_S_NAME_SERVICE_UNAVAILABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1762","0x6E2","error 1762","RPC_S_NAME_SERVICE_UNAVAILABLE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","rpc","name","service","unavailable","the"],"errorCode":"1762","eventId":"","severity":"Low","summary":"The name service is unavailable.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1762; use the surrounding log entries to confirm it.","resolution":"1. Record where 1762 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_NAME_SERVICE_UNAVAILABLE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1762 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The name service is unavailable.\n\nLookup forms: 1762, 0x6E2, error 1762, RPC_S_NAME_SERVICE_UNAVAILABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1762"]},{"id":1030,"title":"RPC_S_INVALID_NAF_ID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1763","0x6E3","error 1763","RPC_S_INVALID_NAF_ID","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","rpc","invalid","naf","the","network","address","family"],"errorCode":"1763","eventId":"","severity":"High","summary":"The network address family is invalid.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1763; use the surrounding log entries to confirm it.","resolution":"1. Record where 1763 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_INVALID_NAF_ID.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1763 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The network address family is invalid.\n\nLookup forms: 1763, 0x6E3, error 1763, RPC_S_INVALID_NAF_ID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1763"]},{"id":1031,"title":"RPC_S_CANNOT_SUPPORT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1764","0x6E4","error 1764","RPC_S_CANNOT_SUPPORT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","cannot","support","the","requested","operation","not","supported"],"errorCode":"1764","eventId":"","severity":"Medium","summary":"The requested operation is not supported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1764; use the surrounding log entries to confirm it.","resolution":"1. Record where 1764 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_CANNOT_SUPPORT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1764 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested operation is not supported.\n\nLookup forms: 1764, 0x6E4, error 1764, RPC_S_CANNOT_SUPPORT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1764"]},{"id":1032,"title":"RPC_S_NO_CONTEXT_AVAILABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1765","0x6E5","error 1765","RPC_S_NO_CONTEXT_AVAILABLE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","rpc","context","available","security","allow","impersonation"],"errorCode":"1765","eventId":"","severity":"Low","summary":"No security context is available to allow impersonation.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1765; use the surrounding log entries to confirm it.","resolution":"1. Record where 1765 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_NO_CONTEXT_AVAILABLE.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1765 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No security context is available to allow impersonation.\n\nLookup forms: 1765, 0x6E5, error 1765, RPC_S_NO_CONTEXT_AVAILABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1765"]},{"id":1033,"title":"RPC_S_INTERNAL_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1766","0x6E6","error 1766","RPC_S_INTERNAL_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","internal","error","occurred","remote","procedure","call"],"errorCode":"1766","eventId":"","severity":"Low","summary":"An internal error occurred in a remote procedure call (RPC).","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1766; use the surrounding log entries to confirm it.","resolution":"1. Record where 1766 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_INTERNAL_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1766 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An internal error occurred in a remote procedure call (RPC).\n\nLookup forms: 1766, 0x6E6, error 1766, RPC_S_INTERNAL_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1766"]},{"id":1034,"title":"RPC_S_ZERO_DIVIDE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1767","0x6E7","error 1767","RPC_S_ZERO_DIVIDE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","rpc","zero","divide","the","server","attempted","integer","division"],"errorCode":"1767","eventId":"","severity":"Low","summary":"The RPC server attempted an integer division by zero.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1767; use the surrounding log entries to confirm it.","resolution":"1. Record where 1767 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_ZERO_DIVIDE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1767 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The RPC server attempted an integer division by zero.\n\nLookup forms: 1767, 0x6E7, error 1767, RPC_S_ZERO_DIVIDE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1767"]},{"id":1035,"title":"RPC_S_ADDRESS_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1768","0x6E8","error 1768","RPC_S_ADDRESS_ERROR","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","rpc","address","error","addressing","occurred","the","server"],"errorCode":"1768","eventId":"","severity":"Low","summary":"An addressing error occurred in the RPC server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1768; use the surrounding log entries to confirm it.","resolution":"1. Record where 1768 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_ADDRESS_ERROR.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1768 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An addressing error occurred in the RPC server.\n\nLookup forms: 1768, 0x6E8, error 1768, RPC_S_ADDRESS_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1768"]},{"id":1036,"title":"RPC_S_FP_DIV_ZERO","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1769","0x6E9","error 1769","RPC_S_FP_DIV_ZERO","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","rpc","div","zero","floating","point","operation","the","server","caused","division"],"errorCode":"1769","eventId":"","severity":"Low","summary":"A floating-point operation at the RPC server caused a division by zero.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1769; use the surrounding log entries to confirm it.","resolution":"1. Record where 1769 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_FP_DIV_ZERO.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1769 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A floating-point operation at the RPC server caused a division by zero.\n\nLookup forms: 1769, 0x6E9, error 1769, RPC_S_FP_DIV_ZERO. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1769"]},{"id":1037,"title":"RPC_S_FP_UNDERFLOW","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1770","0x6EA","error 1770","RPC_S_FP_UNDERFLOW","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","rpc","underflow","floating","point","occurred","the","server"],"errorCode":"1770","eventId":"","severity":"Low","summary":"A floating-point underflow occurred at the RPC server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1770; use the surrounding log entries to confirm it.","resolution":"1. Record where 1770 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_FP_UNDERFLOW.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1770 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A floating-point underflow occurred at the RPC server.\n\nLookup forms: 1770, 0x6EA, error 1770, RPC_S_FP_UNDERFLOW. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1770"]},{"id":1038,"title":"RPC_S_FP_OVERFLOW","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1771","0x6EB","error 1771","RPC_S_FP_OVERFLOW","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","rpc","overflow","floating","point","occurred","the","server"],"errorCode":"1771","eventId":"","severity":"Low","summary":"A floating-point overflow occurred at the RPC server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1771; use the surrounding log entries to confirm it.","resolution":"1. Record where 1771 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_FP_OVERFLOW.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1771 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A floating-point overflow occurred at the RPC server.\n\nLookup forms: 1771, 0x6EB, error 1771, RPC_S_FP_OVERFLOW. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1771"]},{"id":1039,"title":"RPC_X_NO_MORE_ENTRIES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1772","0x6EC","error 1772","RPC_X_NO_MORE_ENTRIES","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","rpc","more","entries","the","list","servers","available","for","binding","auto","handles","has","been","exhausted"],"errorCode":"1772","eventId":"","severity":"Low","summary":"The list of RPC servers available for the binding of auto handles has been exhausted.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1772; use the surrounding log entries to confirm it.","resolution":"1. Record where 1772 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_X_NO_MORE_ENTRIES.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1772 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The list of RPC servers available for the binding of auto handles has been exhausted.\n\nLookup forms: 1772, 0x6EC, error 1772, RPC_X_NO_MORE_ENTRIES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1772"]},{"id":1040,"title":"RPC_X_SS_CHAR_TRANS_OPEN_FAIL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1773","0x6ED","error 1773","RPC_X_SS_CHAR_TRANS_OPEN_FAIL","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","rpc","char","trans","open","fail","unable","the","character","translation","table","file"],"errorCode":"1773","eventId":"","severity":"Medium","summary":"Unable to open the character translation table file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1773; use the surrounding log entries to confirm it.","resolution":"1. Record where 1773 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_X_SS_CHAR_TRANS_OPEN_FAIL.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1773 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to open the character translation table file.\n\nLookup forms: 1773, 0x6ED, error 1773, RPC_X_SS_CHAR_TRANS_OPEN_FAIL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1773"]},{"id":1041,"title":"RPC_X_SS_CHAR_TRANS_SHORT_FILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1774","0x6EE","error 1774","RPC_X_SS_CHAR_TRANS_SHORT_FILE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","rpc","char","trans","short","file","the","containing","character","translation","table","has","fewer","than","512","bytes"],"errorCode":"1774","eventId":"","severity":"Low","summary":"The file containing the character translation table has fewer than 512 bytes.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1774; use the surrounding log entries to confirm it.","resolution":"1. Record where 1774 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_X_SS_CHAR_TRANS_SHORT_FILE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1774 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file containing the character translation table has fewer than 512 bytes.\n\nLookup forms: 1774, 0x6EE, error 1774, RPC_X_SS_CHAR_TRANS_SHORT_FILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1774"]},{"id":1042,"title":"RPC_X_SS_IN_NULL_CONTEXT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1775","0x6EF","error 1775","RPC_X_SS_IN_NULL_CONTEXT","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","rpc","null","context","handle","was","passed","from","the","client","host","during","remote","procedure","call"],"errorCode":"1775","eventId":"","severity":"Low","summary":"A null context handle was passed from the client to the host during a remote procedure call.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1775; use the surrounding log entries to confirm it.","resolution":"1. Record where 1775 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_X_SS_IN_NULL_CONTEXT.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1775 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A null context handle was passed from the client to the host during a remote procedure call.\n\nLookup forms: 1775, 0x6EF, error 1775, RPC_X_SS_IN_NULL_CONTEXT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1775"]},{"id":1043,"title":"RPC_X_SS_CONTEXT_DAMAGED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1777","0x6F1","error 1777","RPC_X_SS_CONTEXT_DAMAGED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","rpc","context","damaged","the","handle","changed","during","remote","procedure","call"],"errorCode":"1777","eventId":"","severity":"Low","summary":"The context handle changed during a remote procedure call.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1777; use the surrounding log entries to confirm it.","resolution":"1. Record where 1777 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_X_SS_CONTEXT_DAMAGED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1777 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The context handle changed during a remote procedure call.\n\nLookup forms: 1777, 0x6F1, error 1777, RPC_X_SS_CONTEXT_DAMAGED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1777"]},{"id":1044,"title":"RPC_X_SS_HANDLES_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1778","0x6F2","error 1778","RPC_X_SS_HANDLES_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","rpc","handles","mismatch","the","binding","passed","remote","procedure","call","not","match"],"errorCode":"1778","eventId":"","severity":"Low","summary":"The binding handles passed to a remote procedure call do not match.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1778; use the surrounding log entries to confirm it.","resolution":"1. Record where 1778 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_X_SS_HANDLES_MISMATCH.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1778 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The binding handles passed to a remote procedure call do not match.\n\nLookup forms: 1778, 0x6F2, error 1778, RPC_X_SS_HANDLES_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1778"]},{"id":1045,"title":"RPC_X_SS_CANNOT_GET_CALL_HANDLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1779","0x6F3","error 1779","RPC_X_SS_CANNOT_GET_CALL_HANDLE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","rpc","cannot","get","call","handle","the","stub","unable","remote","procedure"],"errorCode":"1779","eventId":"","severity":"Medium","summary":"The stub is unable to get the remote procedure call handle.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1779; use the surrounding log entries to confirm it.","resolution":"1. Record where 1779 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_X_SS_CANNOT_GET_CALL_HANDLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1779 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The stub is unable to get the remote procedure call handle.\n\nLookup forms: 1779, 0x6F3, error 1779, RPC_X_SS_CANNOT_GET_CALL_HANDLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1779"]},{"id":1046,"title":"RPC_X_NULL_REF_POINTER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1780","0x6F4","error 1780","RPC_X_NULL_REF_POINTER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","null","ref","pointer","reference","was","passed","the","stub"],"errorCode":"1780","eventId":"","severity":"Low","summary":"A null reference pointer was passed to the stub.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1780; use the surrounding log entries to confirm it.","resolution":"1. Record where 1780 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_X_NULL_REF_POINTER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1780 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A null reference pointer was passed to the stub.\n\nLookup forms: 1780, 0x6F4, error 1780, RPC_X_NULL_REF_POINTER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1780"]},{"id":1047,"title":"RPC_X_ENUM_VALUE_OUT_OF_RANGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1781","0x6F5","error 1781","RPC_X_ENUM_VALUE_OUT_OF_RANGE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","enum","value","out","range","the","enumeration"],"errorCode":"1781","eventId":"","severity":"Low","summary":"The enumeration value is out of range.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1781; use the surrounding log entries to confirm it.","resolution":"1. Record where 1781 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_X_ENUM_VALUE_OUT_OF_RANGE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1781 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The enumeration value is out of range.\n\nLookup forms: 1781, 0x6F5, error 1781, RPC_X_ENUM_VALUE_OUT_OF_RANGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1781"]},{"id":1048,"title":"RPC_X_BYTE_COUNT_TOO_SMALL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1782","0x6F6","error 1782","RPC_X_BYTE_COUNT_TOO_SMALL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","byte","count","too","small","the"],"errorCode":"1782","eventId":"","severity":"Low","summary":"The byte count is too small.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1782; use the surrounding log entries to confirm it.","resolution":"1. Record where 1782 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_X_BYTE_COUNT_TOO_SMALL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1782 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The byte count is too small.\n\nLookup forms: 1782, 0x6F6, error 1782, RPC_X_BYTE_COUNT_TOO_SMALL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1782"]},{"id":1049,"title":"RPC_X_BAD_STUB_DATA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1783","0x6F7","error 1783","RPC_X_BAD_STUB_DATA","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","bad","stub","data","the","received"],"errorCode":"1783","eventId":"","severity":"Low","summary":"The stub received bad data.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1783; use the surrounding log entries to confirm it.","resolution":"1. Record where 1783 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_X_BAD_STUB_DATA.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1783 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The stub received bad data.\n\nLookup forms: 1783, 0x6F7, error 1783, RPC_X_BAD_STUB_DATA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1783"]},{"id":1050,"title":"ERROR_INVALID_USER_BUFFER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1784","0x6F8","error 1784","ERROR_INVALID_USER_BUFFER","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","invalid","user","buffer","the","supplied","not","valid","for","requested","operation"],"errorCode":"1784","eventId":"","severity":"Low","summary":"The supplied user buffer is not valid for the requested operation.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1784; use the surrounding log entries to confirm it.","resolution":"1. Record where 1784 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_USER_BUFFER.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1784 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The supplied user buffer is not valid for the requested operation.\n\nLookup forms: 1784, 0x6F8, error 1784, ERROR_INVALID_USER_BUFFER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1784"]},{"id":1051,"title":"ERROR_UNRECOGNIZED_MEDIA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1785","0x6F9","error 1785","ERROR_UNRECOGNIZED_MEDIA","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","unrecognized","media","the","disk","not","recognized","may","formatted"],"errorCode":"1785","eventId":"","severity":"Low","summary":"The disk media is not recognized. It may not be formatted.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1785; use the surrounding log entries to confirm it.","resolution":"1. Record where 1785 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNRECOGNIZED_MEDIA.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1785 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The disk media is not recognized. It may not be formatted.\n\nLookup forms: 1785, 0x6F9, error 1785, ERROR_UNRECOGNIZED_MEDIA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1785"]},{"id":1052,"title":"ERROR_NO_TRUST_LSA_SECRET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1786","0x6FA","error 1786","ERROR_NO_TRUST_LSA_SECRET","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","trust","lsa","secret","the","workstation","does","not","have"],"errorCode":"1786","eventId":"","severity":"Low","summary":"The workstation does not have a trust secret.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1786; use the surrounding log entries to confirm it.","resolution":"1. Record where 1786 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_TRUST_LSA_SECRET.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1786 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The workstation does not have a trust secret.\n\nLookup forms: 1786, 0x6FA, error 1786, ERROR_NO_TRUST_LSA_SECRET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1786"]},{"id":1053,"title":"ERROR_NO_TRUST_SAM_ACCOUNT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1787","0x6FB","error 1787","ERROR_NO_TRUST_SAM_ACCOUNT","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","trust","sam","account","the","security","database","server","does","not","have","computer","for","this","workstation","relationship"],"errorCode":"1787","eventId":"","severity":"Low","summary":"The security database on the server does not have a computer account for this workstation trust relationship.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1787; use the surrounding log entries to confirm it.","resolution":"1. Record where 1787 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_TRUST_SAM_ACCOUNT.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1787 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The security database on the server does not have a computer account for this workstation trust relationship.\n\nLookup forms: 1787, 0x6FB, error 1787, ERROR_NO_TRUST_SAM_ACCOUNT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1787"]},{"id":1054,"title":"ERROR_TRUSTED_DOMAIN_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1788","0x6FC","error 1788","ERROR_TRUSTED_DOMAIN_FAILURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","trusted","domain","failure","the","trust","relationship","between","primary","and","failed"],"errorCode":"1788","eventId":"","severity":"High","summary":"The trust relationship between the primary domain and the trusted domain failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1788; use the surrounding log entries to confirm it.","resolution":"1. Record where 1788 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRUSTED_DOMAIN_FAILURE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1788 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The trust relationship between the primary domain and the trusted domain failed.\n\nLookup forms: 1788, 0x6FC, error 1788, ERROR_TRUSTED_DOMAIN_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1788"]},{"id":1055,"title":"ERROR_TRUSTED_RELATIONSHIP_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1789","0x6FD","error 1789","ERROR_TRUSTED_RELATIONSHIP_FAILURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","trusted","relationship","failure","the","trust","between","this","workstation","and","primary","domain","failed"],"errorCode":"1789","eventId":"","severity":"High","summary":"The trust relationship between this workstation and the primary domain failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1789; use the surrounding log entries to confirm it.","resolution":"1. Record where 1789 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRUSTED_RELATIONSHIP_FAILURE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1789 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The trust relationship between this workstation and the primary domain failed.\n\nLookup forms: 1789, 0x6FD, error 1789, ERROR_TRUSTED_RELATIONSHIP_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1789"]},{"id":1056,"title":"ERROR_TRUST_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1790","0x6FE","error 1790","ERROR_TRUST_FAILURE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","trust","failure","the","network","logon","failed"],"errorCode":"1790","eventId":"","severity":"High","summary":"The network logon failed.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1790; use the surrounding log entries to confirm it.","resolution":"1. Record where 1790 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRUST_FAILURE.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1790 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The network logon failed.\n\nLookup forms: 1790, 0x6FE, error 1790, ERROR_TRUST_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1790"]},{"id":1057,"title":"RPC_S_CALL_IN_PROGRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1791","0x6FF","error 1791","RPC_S_CALL_IN_PROGRESS","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","rpc","call","progress","remote","procedure","already","for","this","thread"],"errorCode":"1791","eventId":"","severity":"Low","summary":"A remote procedure call is already in progress for this thread.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1791; use the surrounding log entries to confirm it.","resolution":"1. Record where 1791 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_CALL_IN_PROGRESS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1791 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A remote procedure call is already in progress for this thread.\n\nLookup forms: 1791, 0x6FF, error 1791, RPC_S_CALL_IN_PROGRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1791"]},{"id":1058,"title":"ERROR_NETLOGON_NOT_STARTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1792","0x700","error 1792","ERROR_NETLOGON_NOT_STARTED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","netlogon","not","started","attempt","was","made","logon","but","the","network","service"],"errorCode":"1792","eventId":"","severity":"High","summary":"An attempt was made to logon, but the network logon service was not started.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1792; use the surrounding log entries to confirm it.","resolution":"1. Record where 1792 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Verify the required service or agent is installed, running, and current; repair the component if needed.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NETLOGON_NOT_STARTED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1792 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt was made to logon, but the network logon service was not started.\n\nLookup forms: 1792, 0x700, error 1792, ERROR_NETLOGON_NOT_STARTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1792"]},{"id":1059,"title":"ERROR_ACCOUNT_EXPIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1793","0x701","error 1793","ERROR_ACCOUNT_EXPIRED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","account","expired","the","user","has"],"errorCode":"1793","eventId":"","severity":"Low","summary":"The user's account has expired.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1793; use the surrounding log entries to confirm it.","resolution":"1. Record where 1793 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ACCOUNT_EXPIRED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1793 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The user's account has expired.\n\nLookup forms: 1793, 0x701, error 1793, ERROR_ACCOUNT_EXPIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1793"]},{"id":1060,"title":"ERROR_REDIRECTOR_HAS_OPEN_HANDLES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1794","0x702","error 1794","ERROR_REDIRECTOR_HAS_OPEN_HANDLES","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","redirector","has","open","handles","the","use","and","cannot","unloaded"],"errorCode":"1794","eventId":"","severity":"Medium","summary":"The redirector is in use and cannot be unloaded.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1794; use the surrounding log entries to confirm it.","resolution":"1. Record where 1794 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REDIRECTOR_HAS_OPEN_HANDLES.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1794 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The redirector is in use and cannot be unloaded.\n\nLookup forms: 1794, 0x702, error 1794, ERROR_REDIRECTOR_HAS_OPEN_HANDLES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1794"]},{"id":1061,"title":"ERROR_PRINTER_DRIVER_ALREADY_INSTALLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1795","0x703","error 1795","ERROR_PRINTER_DRIVER_ALREADY_INSTALLED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","printer","driver","already","installed","the","specified"],"errorCode":"1795","eventId":"","severity":"Low","summary":"The specified printer driver is already installed.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1795; use the surrounding log entries to confirm it.","resolution":"1. Record where 1795 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PRINTER_DRIVER_ALREADY_INSTALLED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1795 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified printer driver is already installed.\n\nLookup forms: 1795, 0x703, error 1795, ERROR_PRINTER_DRIVER_ALREADY_INSTALLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1795"]},{"id":1062,"title":"ERROR_UNKNOWN_PORT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1796","0x704","error 1796","ERROR_UNKNOWN_PORT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","unknown","port","the","specified"],"errorCode":"1796","eventId":"","severity":"Low","summary":"The specified port is unknown.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1796; use the surrounding log entries to confirm it.","resolution":"1. Record where 1796 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNKNOWN_PORT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1796 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified port is unknown.\n\nLookup forms: 1796, 0x704, error 1796, ERROR_UNKNOWN_PORT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1796"]},{"id":1063,"title":"ERROR_UNKNOWN_PRINTER_DRIVER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1797","0x705","error 1797","ERROR_UNKNOWN_PRINTER_DRIVER","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","unknown","printer","driver","the"],"errorCode":"1797","eventId":"","severity":"Low","summary":"The printer driver is unknown.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1797; use the surrounding log entries to confirm it.","resolution":"1. Record where 1797 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNKNOWN_PRINTER_DRIVER.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1797 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The printer driver is unknown.\n\nLookup forms: 1797, 0x705, error 1797, ERROR_UNKNOWN_PRINTER_DRIVER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1797"]},{"id":1064,"title":"ERROR_UNKNOWN_PRINTPROCESSOR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1798","0x706","error 1798","ERROR_UNKNOWN_PRINTPROCESSOR","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","unknown","printprocessor","the","print","processor"],"errorCode":"1798","eventId":"","severity":"Low","summary":"The print processor is unknown.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1798; use the surrounding log entries to confirm it.","resolution":"1. Record where 1798 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNKNOWN_PRINTPROCESSOR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1798 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The print processor is unknown.\n\nLookup forms: 1798, 0x706, error 1798, ERROR_UNKNOWN_PRINTPROCESSOR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1798"]},{"id":1065,"title":"ERROR_INVALID_SEPARATOR_FILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1799","0x707","error 1799","ERROR_INVALID_SEPARATOR_FILE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","invalid","separator","file","the","specified"],"errorCode":"1799","eventId":"","severity":"Medium","summary":"The specified separator file is invalid.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1799; use the surrounding log entries to confirm it.","resolution":"1. Record where 1799 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_SEPARATOR_FILE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1799 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified separator file is invalid.\n\nLookup forms: 1799, 0x707, error 1799, ERROR_INVALID_SEPARATOR_FILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1799"]},{"id":1066,"title":"ERROR_INVALID_PRIORITY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1800","0x708","error 1800","ERROR_INVALID_PRIORITY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","priority","the","specified"],"errorCode":"1800","eventId":"","severity":"Medium","summary":"The specified priority is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1800; use the surrounding log entries to confirm it.","resolution":"1. Record where 1800 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_PRIORITY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1800 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified priority is invalid.\n\nLookup forms: 1800, 0x708, error 1800, ERROR_INVALID_PRIORITY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1800"]},{"id":1067,"title":"ERROR_INVALID_PRINTER_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1801","0x709","error 1801","ERROR_INVALID_PRINTER_NAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","printer","name","the"],"errorCode":"1801","eventId":"","severity":"Medium","summary":"The printer name is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1801; use the surrounding log entries to confirm it.","resolution":"1. Record where 1801 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_PRINTER_NAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1801 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The printer name is invalid.\n\nLookup forms: 1801, 0x709, error 1801, ERROR_INVALID_PRINTER_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1801"]},{"id":1068,"title":"ERROR_PRINTER_ALREADY_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1802","0x70A","error 1802","ERROR_PRINTER_ALREADY_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","printer","already","exists","the"],"errorCode":"1802","eventId":"","severity":"Medium","summary":"The printer already exists.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1802; use the surrounding log entries to confirm it.","resolution":"1. Record where 1802 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PRINTER_ALREADY_EXISTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1802 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The printer already exists.\n\nLookup forms: 1802, 0x70A, error 1802, ERROR_PRINTER_ALREADY_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1802"]},{"id":1069,"title":"ERROR_INVALID_PRINTER_COMMAND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1803","0x70B","error 1803","ERROR_INVALID_PRINTER_COMMAND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","printer","command","the"],"errorCode":"1803","eventId":"","severity":"Medium","summary":"The printer command is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1803; use the surrounding log entries to confirm it.","resolution":"1. Record where 1803 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_PRINTER_COMMAND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1803 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The printer command is invalid.\n\nLookup forms: 1803, 0x70B, error 1803, ERROR_INVALID_PRINTER_COMMAND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1803"]},{"id":1070,"title":"ERROR_INVALID_DATATYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1804","0x70C","error 1804","ERROR_INVALID_DATATYPE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","datatype","the","specified"],"errorCode":"1804","eventId":"","severity":"Medium","summary":"The specified datatype is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1804; use the surrounding log entries to confirm it.","resolution":"1. Record where 1804 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_DATATYPE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1804 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified datatype is invalid.\n\nLookup forms: 1804, 0x70C, error 1804, ERROR_INVALID_DATATYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1804"]},{"id":1071,"title":"ERROR_INVALID_ENVIRONMENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1805","0x70D","error 1805","ERROR_INVALID_ENVIRONMENT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","environment","the","specified"],"errorCode":"1805","eventId":"","severity":"Medium","summary":"The environment specified is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1805; use the surrounding log entries to confirm it.","resolution":"1. Record where 1805 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_ENVIRONMENT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1805 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The environment specified is invalid.\n\nLookup forms: 1805, 0x70D, error 1805, ERROR_INVALID_ENVIRONMENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1805"]},{"id":1072,"title":"RPC_S_NO_MORE_BINDINGS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1806","0x70E","error 1806","RPC_S_NO_MORE_BINDINGS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","more","bindings","there","are"],"errorCode":"1806","eventId":"","severity":"Low","summary":"There are no more bindings.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1806; use the surrounding log entries to confirm it.","resolution":"1. Record where 1806 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_NO_MORE_BINDINGS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1806 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There are no more bindings.\n\nLookup forms: 1806, 0x70E, error 1806, RPC_S_NO_MORE_BINDINGS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1806"]},{"id":1073,"title":"ERROR_NOLOGON_INTERDOMAIN_TRUST_ACCOUNT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1807","0x70F","error 1807","ERROR_NOLOGON_INTERDOMAIN_TRUST_ACCOUNT","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","nologon","interdomain","trust","account","the","used","use","your","global","user","local","access","this","server"],"errorCode":"1807","eventId":"","severity":"Low","summary":"The account used is an interdomain trust account. Use your global user account or local user account to access this server.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1807; use the surrounding log entries to confirm it.","resolution":"1. Record where 1807 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOLOGON_INTERDOMAIN_TRUST_ACCOUNT.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1807 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The account used is an interdomain trust account. Use your global user account or local user account to access this server.\n\nLookup forms: 1807, 0x70F, error 1807, ERROR_NOLOGON_INTERDOMAIN_TRUST_ACCOUNT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1807"]},{"id":1074,"title":"ERROR_NOLOGON_WORKSTATION_TRUST_ACCOUNT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1808","0x710","error 1808","ERROR_NOLOGON_WORKSTATION_TRUST_ACCOUNT","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","nologon","workstation","trust","account","the","used","computer","use","your","global","user","local","access","this","server"],"errorCode":"1808","eventId":"","severity":"Low","summary":"The account used is a computer account. Use your global user account or local user account to access this server.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1808; use the surrounding log entries to confirm it.","resolution":"1. Record where 1808 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOLOGON_WORKSTATION_TRUST_ACCOUNT.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1808 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The account used is a computer account. Use your global user account or local user account to access this server.\n\nLookup forms: 1808, 0x710, error 1808, ERROR_NOLOGON_WORKSTATION_TRUST_ACCOUNT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1808"]},{"id":1075,"title":"ERROR_NOLOGON_SERVER_TRUST_ACCOUNT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1809","0x711","error 1809","ERROR_NOLOGON_SERVER_TRUST_ACCOUNT","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","nologon","server","trust","account","the","used","use","your","global","user","local","access","this"],"errorCode":"1809","eventId":"","severity":"Low","summary":"The account used is a server trust account. Use your global user account or local user account to access this server.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1809; use the surrounding log entries to confirm it.","resolution":"1. Record where 1809 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOLOGON_SERVER_TRUST_ACCOUNT.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1809 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The account used is a server trust account. Use your global user account or local user account to access this server.\n\nLookup forms: 1809, 0x711, error 1809, ERROR_NOLOGON_SERVER_TRUST_ACCOUNT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1809"]},{"id":1076,"title":"ERROR_DOMAIN_TRUST_INCONSISTENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1810","0x712","error 1810","ERROR_DOMAIN_TRUST_INCONSISTENT","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","domain","trust","inconsistent","the","name","security","sid","specified","with","information","for","that"],"errorCode":"1810","eventId":"","severity":"Low","summary":"The name or security ID (SID) of the domain specified is inconsistent with the trust information for that domain.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1810; use the surrounding log entries to confirm it.","resolution":"1. Record where 1810 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DOMAIN_TRUST_INCONSISTENT.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1810 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The name or security ID (SID) of the domain specified is inconsistent with the trust information for that domain.\n\nLookup forms: 1810, 0x712, error 1810, ERROR_DOMAIN_TRUST_INCONSISTENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1810"]},{"id":1077,"title":"ERROR_SERVER_HAS_OPEN_HANDLES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1811","0x713","error 1811","ERROR_SERVER_HAS_OPEN_HANDLES","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","server","has","open","handles","the","use","and","cannot","unloaded"],"errorCode":"1811","eventId":"","severity":"Medium","summary":"The server is in use and cannot be unloaded.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1811; use the surrounding log entries to confirm it.","resolution":"1. Record where 1811 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVER_HAS_OPEN_HANDLES.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1811 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The server is in use and cannot be unloaded.\n\nLookup forms: 1811, 0x713, error 1811, ERROR_SERVER_HAS_OPEN_HANDLES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1811"]},{"id":1078,"title":"ERROR_RESOURCE_DATA_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1812","0x714","error 1812","ERROR_RESOURCE_DATA_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","resource","data","not","found","the","specified","image","file","did","contain","section"],"errorCode":"1812","eventId":"","severity":"Low","summary":"The specified image file did not contain a resource section.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1812; use the surrounding log entries to confirm it.","resolution":"1. Record where 1812 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESOURCE_DATA_NOT_FOUND.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1812 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified image file did not contain a resource section.\n\nLookup forms: 1812, 0x714, error 1812, ERROR_RESOURCE_DATA_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1812"]},{"id":1079,"title":"ERROR_RESOURCE_TYPE_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1813","0x715","error 1813","ERROR_RESOURCE_TYPE_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","resource","type","not","found","the","specified","cannot","image","file"],"errorCode":"1813","eventId":"","severity":"Medium","summary":"The specified resource type cannot be found in the image file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1813; use the surrounding log entries to confirm it.","resolution":"1. Record where 1813 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESOURCE_TYPE_NOT_FOUND.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1813 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified resource type cannot be found in the image file.\n\nLookup forms: 1813, 0x715, error 1813, ERROR_RESOURCE_TYPE_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1813"]},{"id":1080,"title":"ERROR_RESOURCE_NAME_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1814","0x716","error 1814","ERROR_RESOURCE_NAME_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","resource","name","not","found","the","specified","cannot","image","file"],"errorCode":"1814","eventId":"","severity":"Medium","summary":"The specified resource name cannot be found in the image file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1814; use the surrounding log entries to confirm it.","resolution":"1. Record where 1814 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESOURCE_NAME_NOT_FOUND.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1814 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified resource name cannot be found in the image file.\n\nLookup forms: 1814, 0x716, error 1814, ERROR_RESOURCE_NAME_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1814"]},{"id":1081,"title":"ERROR_RESOURCE_LANG_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1815","0x717","error 1815","ERROR_RESOURCE_LANG_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","resource","lang","not","found","the","specified","language","cannot","image","file"],"errorCode":"1815","eventId":"","severity":"Medium","summary":"The specified resource language ID cannot be found in the image file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1815; use the surrounding log entries to confirm it.","resolution":"1. Record where 1815 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESOURCE_LANG_NOT_FOUND.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1815 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified resource language ID cannot be found in the image file.\n\nLookup forms: 1815, 0x717, error 1815, ERROR_RESOURCE_LANG_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1815"]},{"id":1082,"title":"ERROR_NOT_ENOUGH_QUOTA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1816","0x718","error 1816","ERROR_NOT_ENOUGH_QUOTA","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","not","enough","quota","available","process","this","command"],"errorCode":"1816","eventId":"","severity":"Low","summary":"Not enough quota is available to process this command.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1816; use the surrounding log entries to confirm it.","resolution":"1. Record where 1816 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_ENOUGH_QUOTA.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1816 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Not enough quota is available to process this command.\n\nLookup forms: 1816, 0x718, error 1816, ERROR_NOT_ENOUGH_QUOTA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1816"]},{"id":1083,"title":"RPC_S_NO_INTERFACES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1817","0x719","error 1817","RPC_S_NO_INTERFACES","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","interfaces","have","been","registered"],"errorCode":"1817","eventId":"","severity":"Low","summary":"No interfaces have been registered.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1817; use the surrounding log entries to confirm it.","resolution":"1. Record where 1817 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_NO_INTERFACES.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1817 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No interfaces have been registered.\n\nLookup forms: 1817, 0x719, error 1817, RPC_S_NO_INTERFACES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1817"]},{"id":1084,"title":"RPC_S_CALL_CANCELLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1818","0x71A","error 1818","RPC_S_CALL_CANCELLED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","call","cancelled","the","remote","procedure","was"],"errorCode":"1818","eventId":"","severity":"Low","summary":"The remote procedure call was cancelled.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1818; use the surrounding log entries to confirm it.","resolution":"1. Record where 1818 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_CALL_CANCELLED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1818 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The remote procedure call was cancelled.\n\nLookup forms: 1818, 0x71A, error 1818, RPC_S_CALL_CANCELLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1818"]},{"id":1085,"title":"RPC_S_BINDING_INCOMPLETE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1819","0x71B","error 1819","RPC_S_BINDING_INCOMPLETE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","rpc","binding","incomplete","the","handle","does","not","contain","all","required","information"],"errorCode":"1819","eventId":"","severity":"Low","summary":"The binding handle does not contain all required information.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1819; use the surrounding log entries to confirm it.","resolution":"1. Record where 1819 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_BINDING_INCOMPLETE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1819 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The binding handle does not contain all required information.\n\nLookup forms: 1819, 0x71B, error 1819, RPC_S_BINDING_INCOMPLETE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1819"]},{"id":1086,"title":"RPC_S_COMM_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1820","0x71C","error 1820","RPC_S_COMM_FAILURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","comm","failure","communications","occurred","during","remote","procedure","call"],"errorCode":"1820","eventId":"","severity":"High","summary":"A communications failure occurred during a remote procedure call.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1820; use the surrounding log entries to confirm it.","resolution":"1. Record where 1820 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_COMM_FAILURE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1820 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A communications failure occurred during a remote procedure call.\n\nLookup forms: 1820, 0x71C, error 1820, RPC_S_COMM_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1820"]},{"id":1087,"title":"RPC_S_UNSUPPORTED_AUTHN_LEVEL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1821","0x71D","error 1821","RPC_S_UNSUPPORTED_AUTHN_LEVEL","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","rpc","unsupported","authn","level","the","requested","authentication","not","supported"],"errorCode":"1821","eventId":"","severity":"High","summary":"The requested authentication level is not supported.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1821; use the surrounding log entries to confirm it.","resolution":"1. Record where 1821 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_UNSUPPORTED_AUTHN_LEVEL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1821 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested authentication level is not supported.\n\nLookup forms: 1821, 0x71D, error 1821, RPC_S_UNSUPPORTED_AUTHN_LEVEL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1821"]},{"id":1088,"title":"RPC_S_NO_PRINC_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1822","0x71E","error 1822","RPC_S_NO_PRINC_NAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","princ","name","principal","registered"],"errorCode":"1822","eventId":"","severity":"Low","summary":"No principal name registered.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1822; use the surrounding log entries to confirm it.","resolution":"1. Record where 1822 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_NO_PRINC_NAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1822 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No principal name registered.\n\nLookup forms: 1822, 0x71E, error 1822, RPC_S_NO_PRINC_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1822"]},{"id":1089,"title":"RPC_S_NOT_RPC_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1823","0x71F","error 1823","RPC_S_NOT_RPC_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","not","error","the","specified","valid","windows","code"],"errorCode":"1823","eventId":"","severity":"Low","summary":"The error specified is not a valid Windows RPC error code.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1823; use the surrounding log entries to confirm it.","resolution":"1. Record where 1823 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_NOT_RPC_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1823 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The error specified is not a valid Windows RPC error code.\n\nLookup forms: 1823, 0x71F, error 1823, RPC_S_NOT_RPC_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1823"]},{"id":1090,"title":"RPC_S_UUID_LOCAL_ONLY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1824","0x720","error 1824","RPC_S_UUID_LOCAL_ONLY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","uuid","local","only","that","valid","this","computer","has","been","allocated"],"errorCode":"1824","eventId":"","severity":"Low","summary":"A UUID that is valid only on this computer has been allocated.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1824; use the surrounding log entries to confirm it.","resolution":"1. Record where 1824 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_UUID_LOCAL_ONLY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1824 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A UUID that is valid only on this computer has been allocated.\n\nLookup forms: 1824, 0x720, error 1824, RPC_S_UUID_LOCAL_ONLY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1824"]},{"id":1091,"title":"RPC_S_SEC_PKG_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1825","0x721","error 1825","RPC_S_SEC_PKG_ERROR","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","rpc","sec","pkg","error","security","package","specific","occurred"],"errorCode":"1825","eventId":"","severity":"Low","summary":"A security package specific error occurred.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1825; use the surrounding log entries to confirm it.","resolution":"1. Record where 1825 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_SEC_PKG_ERROR.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1825 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A security package specific error occurred.\n\nLookup forms: 1825, 0x721, error 1825, RPC_S_SEC_PKG_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1825"]},{"id":1092,"title":"RPC_S_NOT_CANCELLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1826","0x722","error 1826","RPC_S_NOT_CANCELLED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","rpc","not","cancelled","thread","canceled"],"errorCode":"1826","eventId":"","severity":"Low","summary":"Thread is not canceled.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1826; use the surrounding log entries to confirm it.","resolution":"1. Record where 1826 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_NOT_CANCELLED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1826 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Thread is not canceled.\n\nLookup forms: 1826, 0x722, error 1826, RPC_S_NOT_CANCELLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1826"]},{"id":1093,"title":"RPC_X_INVALID_ES_ACTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1827","0x723","error 1827","RPC_X_INVALID_ES_ACTION","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","rpc","invalid","action","operation","the","encoding","decoding","handle"],"errorCode":"1827","eventId":"","severity":"Medium","summary":"Invalid operation on the encoding/decoding handle.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1827; use the surrounding log entries to confirm it.","resolution":"1. Record where 1827 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_X_INVALID_ES_ACTION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1827 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid operation on the encoding/decoding handle.\n\nLookup forms: 1827, 0x723, error 1827, RPC_X_INVALID_ES_ACTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1827"]},{"id":1094,"title":"RPC_X_WRONG_ES_VERSION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1828","0x724","error 1828","RPC_X_WRONG_ES_VERSION","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","rpc","wrong","version","incompatible","the","serializing","package"],"errorCode":"1828","eventId":"","severity":"Low","summary":"Incompatible version of the serializing package.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 1828; use the surrounding log entries to confirm it.","resolution":"1. Record where 1828 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_X_WRONG_ES_VERSION.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1828 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Incompatible version of the serializing package.\n\nLookup forms: 1828, 0x724, error 1828, RPC_X_WRONG_ES_VERSION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1828"]},{"id":1095,"title":"RPC_X_WRONG_STUB_VERSION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1829","0x725","error 1829","RPC_X_WRONG_STUB_VERSION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","wrong","stub","version","incompatible","the"],"errorCode":"1829","eventId":"","severity":"Low","summary":"Incompatible version of the RPC stub.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1829; use the surrounding log entries to confirm it.","resolution":"1. Record where 1829 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_X_WRONG_STUB_VERSION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1829 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Incompatible version of the RPC stub.\n\nLookup forms: 1829, 0x725, error 1829, RPC_X_WRONG_STUB_VERSION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1829"]},{"id":1096,"title":"RPC_X_INVALID_PIPE_OBJECT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1830","0x726","error 1830","RPC_X_INVALID_PIPE_OBJECT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","invalid","pipe","object","the","corrupted"],"errorCode":"1830","eventId":"","severity":"Critical","summary":"The RPC pipe object is invalid or corrupted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1830; use the surrounding log entries to confirm it.","resolution":"1. Record where 1830 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_X_INVALID_PIPE_OBJECT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1830 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The RPC pipe object is invalid or corrupted.\n\nLookup forms: 1830, 0x726, error 1830, RPC_X_INVALID_PIPE_OBJECT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1830"]},{"id":1097,"title":"RPC_X_WRONG_PIPE_ORDER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1831","0x727","error 1831","RPC_X_WRONG_PIPE_ORDER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","wrong","pipe","order","invalid","operation","was","attempted","object"],"errorCode":"1831","eventId":"","severity":"Medium","summary":"An invalid operation was attempted on an RPC pipe object.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1831; use the surrounding log entries to confirm it.","resolution":"1. Record where 1831 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_X_WRONG_PIPE_ORDER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1831 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An invalid operation was attempted on an RPC pipe object.\n\nLookup forms: 1831, 0x727, error 1831, RPC_X_WRONG_PIPE_ORDER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1831"]},{"id":1098,"title":"RPC_X_WRONG_PIPE_VERSION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1832","0x728","error 1832","RPC_X_WRONG_PIPE_VERSION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","wrong","pipe","version","unsupported"],"errorCode":"1832","eventId":"","severity":"Low","summary":"Unsupported RPC pipe version.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1832; use the surrounding log entries to confirm it.","resolution":"1. Record where 1832 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_X_WRONG_PIPE_VERSION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1832 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unsupported RPC pipe version.\n\nLookup forms: 1832, 0x728, error 1832, RPC_X_WRONG_PIPE_VERSION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1832"]},{"id":1099,"title":"RPC_S_COOKIE_AUTH_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1833","0x729","error 1833","RPC_S_COOKIE_AUTH_FAILED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","rpc","cookie","auth","failed","http","proxy","server","rejected","the","connection","because","authentication"],"errorCode":"1833","eventId":"","severity":"High","summary":"HTTP proxy server rejected the connection because the cookie authentication failed.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1833; use the surrounding log entries to confirm it.","resolution":"1. Record where 1833 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_COOKIE_AUTH_FAILED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1833 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: HTTP proxy server rejected the connection because the cookie authentication failed.\n\nLookup forms: 1833, 0x729, error 1833, RPC_S_COOKIE_AUTH_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1833"]},{"id":1100,"title":"RPC_S_GROUP_MEMBER_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1898","0x76A","error 1898","RPC_S_GROUP_MEMBER_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","group","member","not","found","the","was"],"errorCode":"1898","eventId":"","severity":"Medium","summary":"The group member was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1898; use the surrounding log entries to confirm it.","resolution":"1. Record where 1898 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_GROUP_MEMBER_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1898 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The group member was not found.\n\nLookup forms: 1898, 0x76A, error 1898, RPC_S_GROUP_MEMBER_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1898"]},{"id":1101,"title":"EPT_S_CANT_CREATE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1899","0x76B","error 1899","EPT_S_CANT_CREATE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","ept","cant","create","the","endpoint","mapper","database","entry","could","not","created"],"errorCode":"1899","eventId":"","severity":"Low","summary":"The endpoint mapper database entry could not be created.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1899; use the surrounding log entries to confirm it.","resolution":"1. Record where 1899 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to EPT_S_CANT_CREATE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1899 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The endpoint mapper database entry could not be created.\n\nLookup forms: 1899, 0x76B, error 1899, EPT_S_CANT_CREATE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1899"]},{"id":1102,"title":"RPC_S_INVALID_OBJECT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1900","0x76C","error 1900","RPC_S_INVALID_OBJECT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","invalid","object","the","universal","unique","identifier","uuid","nil"],"errorCode":"1900","eventId":"","severity":"Low","summary":"The object universal unique identifier (UUID) is the nil UUID.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1900; use the surrounding log entries to confirm it.","resolution":"1. Record where 1900 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_INVALID_OBJECT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1900 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The object universal unique identifier (UUID) is the nil UUID.\n\nLookup forms: 1900, 0x76C, error 1900, RPC_S_INVALID_OBJECT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1900"]},{"id":1103,"title":"ERROR_INVALID_TIME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1901","0x76D","error 1901","ERROR_INVALID_TIME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","time","the","specified"],"errorCode":"1901","eventId":"","severity":"Medium","summary":"The specified time is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1901; use the surrounding log entries to confirm it.","resolution":"1. Record where 1901 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_TIME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1901 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified time is invalid.\n\nLookup forms: 1901, 0x76D, error 1901, ERROR_INVALID_TIME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1901"]},{"id":1104,"title":"ERROR_INVALID_FORM_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1902","0x76E","error 1902","ERROR_INVALID_FORM_NAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","form","name","the","specified"],"errorCode":"1902","eventId":"","severity":"Medium","summary":"The specified form name is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1902; use the surrounding log entries to confirm it.","resolution":"1. Record where 1902 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_FORM_NAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1902 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified form name is invalid.\n\nLookup forms: 1902, 0x76E, error 1902, ERROR_INVALID_FORM_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1902"]},{"id":1105,"title":"ERROR_INVALID_FORM_SIZE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1903","0x76F","error 1903","ERROR_INVALID_FORM_SIZE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","form","size","the","specified"],"errorCode":"1903","eventId":"","severity":"Medium","summary":"The specified form size is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1903; use the surrounding log entries to confirm it.","resolution":"1. Record where 1903 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_FORM_SIZE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1903 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified form size is invalid.\n\nLookup forms: 1903, 0x76F, error 1903, ERROR_INVALID_FORM_SIZE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1903"]},{"id":1106,"title":"ERROR_ALREADY_WAITING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1904","0x770","error 1904","ERROR_ALREADY_WAITING","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","already","waiting","the","specified","printer","handle","being","waited"],"errorCode":"1904","eventId":"","severity":"Low","summary":"The specified printer handle is already being waited on.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1904; use the surrounding log entries to confirm it.","resolution":"1. Record where 1904 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ALREADY_WAITING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1904 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified printer handle is already being waited on.\n\nLookup forms: 1904, 0x770, error 1904, ERROR_ALREADY_WAITING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1904"]},{"id":1107,"title":"ERROR_PRINTER_DELETED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1905","0x771","error 1905","ERROR_PRINTER_DELETED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","printer","deleted","the","specified","has","been"],"errorCode":"1905","eventId":"","severity":"Low","summary":"The specified printer has been deleted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1905; use the surrounding log entries to confirm it.","resolution":"1. Record where 1905 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PRINTER_DELETED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1905 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified printer has been deleted.\n\nLookup forms: 1905, 0x771, error 1905, ERROR_PRINTER_DELETED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1905"]},{"id":1108,"title":"ERROR_INVALID_PRINTER_STATE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1906","0x772","error 1906","ERROR_INVALID_PRINTER_STATE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","printer","state","the"],"errorCode":"1906","eventId":"","severity":"Medium","summary":"The state of the printer is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1906; use the surrounding log entries to confirm it.","resolution":"1. Record where 1906 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_PRINTER_STATE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1906 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The state of the printer is invalid.\n\nLookup forms: 1906, 0x772, error 1906, ERROR_INVALID_PRINTER_STATE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1906"]},{"id":1109,"title":"ERROR_PASSWORD_MUST_CHANGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1907","0x773","error 1907","ERROR_PASSWORD_MUST_CHANGE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","password","must","change","the","user","changed","before","signing"],"errorCode":"1907","eventId":"","severity":"Low","summary":"The user's password must be changed before signing in.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1907; use the surrounding log entries to confirm it.","resolution":"1. Record where 1907 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PASSWORD_MUST_CHANGE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1907 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The user's password must be changed before signing in.\n\nLookup forms: 1907, 0x773, error 1907, ERROR_PASSWORD_MUST_CHANGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The user's password must be changed before logging on the first time.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1907"]},{"id":1110,"title":"ERROR_DOMAIN_CONTROLLER_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1908","0x774","error 1908","ERROR_DOMAIN_CONTROLLER_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","domain","controller","not","found","could","find","the","for","this"],"errorCode":"1908","eventId":"","severity":"Low","summary":"Could not find the domain controller for this domain.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1908; use the surrounding log entries to confirm it.","resolution":"1. Record where 1908 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DOMAIN_CONTROLLER_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1908 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Could not find the domain controller for this domain.\n\nLookup forms: 1908, 0x774, error 1908, ERROR_DOMAIN_CONTROLLER_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1908"]},{"id":1111,"title":"ERROR_ACCOUNT_LOCKED_OUT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1909","0x775","error 1909","ERROR_ACCOUNT_LOCKED_OUT","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","account","locked","out","the","referenced","currently","and","may","not","logged"],"errorCode":"1909","eventId":"","severity":"High","summary":"The referenced account is currently locked out and may not be logged on to.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1909; use the surrounding log entries to confirm it.","resolution":"1. Record where 1909 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ACCOUNT_LOCKED_OUT.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1909 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The referenced account is currently locked out and may not be logged on to.\n\nLookup forms: 1909, 0x775, error 1909, ERROR_ACCOUNT_LOCKED_OUT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1909"]},{"id":1112,"title":"OR_INVALID_OXID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1910","0x776","error 1910","OR_INVALID_OXID","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","invalid","oxid","the","object","exporter","specified","was","not","found"],"errorCode":"1910","eventId":"","severity":"Medium","summary":"The object exporter specified was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1910; use the surrounding log entries to confirm it.","resolution":"1. Record where 1910 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to OR_INVALID_OXID.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1910 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The object exporter specified was not found.\n\nLookup forms: 1910, 0x776, error 1910, OR_INVALID_OXID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1910"]},{"id":1113,"title":"OR_INVALID_OID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1911","0x777","error 1911","OR_INVALID_OID","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","invalid","oid","the","object","specified","was","not","found"],"errorCode":"1911","eventId":"","severity":"Medium","summary":"The object specified was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1911; use the surrounding log entries to confirm it.","resolution":"1. Record where 1911 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to OR_INVALID_OID.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1911 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The object specified was not found.\n\nLookup forms: 1911, 0x777, error 1911, OR_INVALID_OID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1911"]},{"id":1114,"title":"OR_INVALID_SET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1912","0x778","error 1912","OR_INVALID_SET","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","invalid","set","the","object","resolver","specified","was","not","found"],"errorCode":"1912","eventId":"","severity":"Medium","summary":"The object resolver set specified was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1912; use the surrounding log entries to confirm it.","resolution":"1. Record where 1912 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to OR_INVALID_SET.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1912 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The object resolver set specified was not found.\n\nLookup forms: 1912, 0x778, error 1912, OR_INVALID_SET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1912"]},{"id":1115,"title":"RPC_S_SEND_INCOMPLETE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1913","0x779","error 1913","RPC_S_SEND_INCOMPLETE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","rpc","send","incomplete","some","data","remains","sent","the","request","buffer"],"errorCode":"1913","eventId":"","severity":"Low","summary":"Some data remains to be sent in the request buffer.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1913; use the surrounding log entries to confirm it.","resolution":"1. Record where 1913 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_SEND_INCOMPLETE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1913 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Some data remains to be sent in the request buffer.\n\nLookup forms: 1913, 0x779, error 1913, RPC_S_SEND_INCOMPLETE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1913"]},{"id":1116,"title":"RPC_S_INVALID_ASYNC_HANDLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1914","0x77A","error 1914","RPC_S_INVALID_ASYNC_HANDLE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","rpc","invalid","async","handle","asynchronous","remote","procedure","call"],"errorCode":"1914","eventId":"","severity":"Medium","summary":"Invalid asynchronous remote procedure call handle.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1914; use the surrounding log entries to confirm it.","resolution":"1. Record where 1914 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_INVALID_ASYNC_HANDLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1914 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid asynchronous remote procedure call handle.\n\nLookup forms: 1914, 0x77A, error 1914, RPC_S_INVALID_ASYNC_HANDLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1914"]},{"id":1117,"title":"RPC_S_INVALID_ASYNC_CALL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1915","0x77B","error 1915","RPC_S_INVALID_ASYNC_CALL","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","rpc","invalid","async","call","asynchronous","handle","for","this","operation"],"errorCode":"1915","eventId":"","severity":"Medium","summary":"Invalid asynchronous RPC call handle for this operation.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1915; use the surrounding log entries to confirm it.","resolution":"1. Record where 1915 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_INVALID_ASYNC_CALL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1915 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid asynchronous RPC call handle for this operation.\n\nLookup forms: 1915, 0x77B, error 1915, RPC_S_INVALID_ASYNC_CALL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1915"]},{"id":1118,"title":"RPC_X_PIPE_CLOSED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1916","0x77C","error 1916","RPC_X_PIPE_CLOSED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","pipe","closed","the","object","has","already","been"],"errorCode":"1916","eventId":"","severity":"Low","summary":"The RPC pipe object has already been closed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1916; use the surrounding log entries to confirm it.","resolution":"1. Record where 1916 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_X_PIPE_CLOSED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1916 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The RPC pipe object has already been closed.\n\nLookup forms: 1916, 0x77C, error 1916, RPC_X_PIPE_CLOSED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1916"]},{"id":1119,"title":"RPC_X_PIPE_DISCIPLINE_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1917","0x77D","error 1917","RPC_X_PIPE_DISCIPLINE_ERROR","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","rpc","pipe","discipline","error","the","call","completed","before","all","pipes","were","processed"],"errorCode":"1917","eventId":"","severity":"Low","summary":"The RPC call completed before all pipes were processed.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 1917; use the surrounding log entries to confirm it.","resolution":"1. Record where 1917 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_X_PIPE_DISCIPLINE_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1917 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The RPC call completed before all pipes were processed.\n\nLookup forms: 1917, 0x77D, error 1917, RPC_X_PIPE_DISCIPLINE_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1917"]},{"id":1120,"title":"RPC_X_PIPE_EMPTY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1918","0x77E","error 1918","RPC_X_PIPE_EMPTY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","pipe","empty","more","data","available","from","the"],"errorCode":"1918","eventId":"","severity":"Low","summary":"No more data is available from the RPC pipe.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1918; use the surrounding log entries to confirm it.","resolution":"1. Record where 1918 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_X_PIPE_EMPTY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1918 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No more data is available from the RPC pipe.\n\nLookup forms: 1918, 0x77E, error 1918, RPC_X_PIPE_EMPTY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1918"]},{"id":1121,"title":"ERROR_NO_SITENAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1919","0x77F","error 1919","ERROR_NO_SITENAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sitename","site","name","available","for","this","machine"],"errorCode":"1919","eventId":"","severity":"Low","summary":"No site name is available for this machine.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1919; use the surrounding log entries to confirm it.","resolution":"1. Record where 1919 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_SITENAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1919 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No site name is available for this machine.\n\nLookup forms: 1919, 0x77F, error 1919, ERROR_NO_SITENAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1919"]},{"id":1122,"title":"ERROR_CANT_ACCESS_FILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1920","0x780","error 1920","ERROR_CANT_ACCESS_FILE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","cant","access","file","the","cannot","accessed","system"],"errorCode":"1920","eventId":"","severity":"Medium","summary":"The file cannot be accessed by the system.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1920; use the surrounding log entries to confirm it.","resolution":"1. Record where 1920 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Confirm the user or service identity has the required permissions and is not locked or disabled.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANT_ACCESS_FILE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Confirm the user or service identity has the required permissions and is not locked or disabled.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1920 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file cannot be accessed by the system.\n\nLookup forms: 1920, 0x780, error 1920, ERROR_CANT_ACCESS_FILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1920"]},{"id":1123,"title":"ERROR_CANT_RESOLVE_FILENAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1921","0x781","error 1921","ERROR_CANT_RESOLVE_FILENAME","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","cant","resolve","filename","the","name","file","cannot","resolved","system"],"errorCode":"1921","eventId":"","severity":"Medium","summary":"The name of the file cannot be resolved by the system.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1921; use the surrounding log entries to confirm it.","resolution":"1. Record where 1921 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANT_RESOLVE_FILENAME.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1921 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The name of the file cannot be resolved by the system.\n\nLookup forms: 1921, 0x781, error 1921, ERROR_CANT_RESOLVE_FILENAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1921"]},{"id":1124,"title":"RPC_S_ENTRY_TYPE_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1922","0x782","error 1922","RPC_S_ENTRY_TYPE_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","entry","type","mismatch","the","not","expected"],"errorCode":"1922","eventId":"","severity":"Low","summary":"The entry is not of the expected type.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1922; use the surrounding log entries to confirm it.","resolution":"1. Record where 1922 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_ENTRY_TYPE_MISMATCH.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1922 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The entry is not of the expected type.\n\nLookup forms: 1922, 0x782, error 1922, RPC_S_ENTRY_TYPE_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1922"]},{"id":1125,"title":"RPC_S_NOT_ALL_OBJS_EXPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1923","0x783","error 1923","RPC_S_NOT_ALL_OBJS_EXPORTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","not","all","objs","exported","object","uuids","could","the","specified","entry"],"errorCode":"1923","eventId":"","severity":"Low","summary":"Not all object UUIDs could be exported to the specified entry.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1923; use the surrounding log entries to confirm it.","resolution":"1. Record where 1923 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_NOT_ALL_OBJS_EXPORTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1923 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Not all object UUIDs could be exported to the specified entry.\n\nLookup forms: 1923, 0x783, error 1923, RPC_S_NOT_ALL_OBJS_EXPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1923"]},{"id":1126,"title":"RPC_S_INTERFACE_NOT_EXPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1924","0x784","error 1924","RPC_S_INTERFACE_NOT_EXPORTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","interface","not","exported","could","the","specified","entry"],"errorCode":"1924","eventId":"","severity":"Low","summary":"Interface could not be exported to the specified entry.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1924; use the surrounding log entries to confirm it.","resolution":"1. Record where 1924 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_INTERFACE_NOT_EXPORTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1924 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Interface could not be exported to the specified entry.\n\nLookup forms: 1924, 0x784, error 1924, RPC_S_INTERFACE_NOT_EXPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1924"]},{"id":1127,"title":"RPC_S_PROFILE_NOT_ADDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1925","0x785","error 1925","RPC_S_PROFILE_NOT_ADDED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","rpc","profile","not","added","the","specified","entry","could"],"errorCode":"1925","eventId":"","severity":"Low","summary":"The specified profile entry could not be added.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1925; use the surrounding log entries to confirm it.","resolution":"1. Record where 1925 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_PROFILE_NOT_ADDED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1925 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified profile entry could not be added.\n\nLookup forms: 1925, 0x785, error 1925, RPC_S_PROFILE_NOT_ADDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1925"]},{"id":1128,"title":"RPC_S_PRF_ELT_NOT_ADDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1926","0x786","error 1926","RPC_S_PRF_ELT_NOT_ADDED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","rpc","prf","elt","not","added","the","specified","profile","element","could"],"errorCode":"1926","eventId":"","severity":"Low","summary":"The specified profile element could not be added.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1926; use the surrounding log entries to confirm it.","resolution":"1. Record where 1926 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_PRF_ELT_NOT_ADDED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1926 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified profile element could not be added.\n\nLookup forms: 1926, 0x786, error 1926, RPC_S_PRF_ELT_NOT_ADDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1926"]},{"id":1129,"title":"RPC_S_PRF_ELT_NOT_REMOVED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1927","0x787","error 1927","RPC_S_PRF_ELT_NOT_REMOVED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","rpc","prf","elt","not","removed","the","specified","profile","element","could"],"errorCode":"1927","eventId":"","severity":"Low","summary":"The specified profile element could not be removed.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1927; use the surrounding log entries to confirm it.","resolution":"1. Record where 1927 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_PRF_ELT_NOT_REMOVED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1927 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified profile element could not be removed.\n\nLookup forms: 1927, 0x787, error 1927, RPC_S_PRF_ELT_NOT_REMOVED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1927"]},{"id":1130,"title":"RPC_S_GRP_ELT_NOT_ADDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1928","0x788","error 1928","RPC_S_GRP_ELT_NOT_ADDED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","grp","elt","not","added","the","group","element","could"],"errorCode":"1928","eventId":"","severity":"Low","summary":"The group element could not be added.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1928; use the surrounding log entries to confirm it.","resolution":"1. Record where 1928 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_GRP_ELT_NOT_ADDED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1928 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The group element could not be added.\n\nLookup forms: 1928, 0x788, error 1928, RPC_S_GRP_ELT_NOT_ADDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1928"]},{"id":1131,"title":"RPC_S_GRP_ELT_NOT_REMOVED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1929","0x789","error 1929","RPC_S_GRP_ELT_NOT_REMOVED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","rpc","grp","elt","not","removed","the","group","element","could"],"errorCode":"1929","eventId":"","severity":"Low","summary":"The group element could not be removed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1929; use the surrounding log entries to confirm it.","resolution":"1. Record where 1929 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to RPC_S_GRP_ELT_NOT_REMOVED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1929 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The group element could not be removed.\n\nLookup forms: 1929, 0x789, error 1929, RPC_S_GRP_ELT_NOT_REMOVED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1929"]},{"id":1132,"title":"ERROR_KM_DRIVER_BLOCKED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1930","0x78A","error 1930","ERROR_KM_DRIVER_BLOCKED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","driver","blocked","the","printer","not","compatible","with","policy","enabled","your","computer","that","blocks","drivers"],"errorCode":"1930","eventId":"","severity":"Low","summary":"The printer driver is not compatible with a policy enabled on your computer that blocks NT 4.0 drivers.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 1930; use the surrounding log entries to confirm it.","resolution":"1. Record where 1930 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_KM_DRIVER_BLOCKED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1930 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The printer driver is not compatible with a policy enabled on your computer that blocks NT 4.0 drivers.\n\nLookup forms: 1930, 0x78A, error 1930, ERROR_KM_DRIVER_BLOCKED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1930"]},{"id":1133,"title":"ERROR_CONTEXT_EXPIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1931","0x78B","error 1931","ERROR_CONTEXT_EXPIRED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","context","expired","the","has","and","can","longer","used"],"errorCode":"1931","eventId":"","severity":"Low","summary":"The context has expired and can no longer be used.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1931; use the surrounding log entries to confirm it.","resolution":"1. Record where 1931 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CONTEXT_EXPIRED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1931 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The context has expired and can no longer be used.\n\nLookup forms: 1931, 0x78B, error 1931, ERROR_CONTEXT_EXPIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1931"]},{"id":1134,"title":"ERROR_PER_USER_TRUST_QUOTA_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1932","0x78C","error 1932","ERROR_PER_USER_TRUST_QUOTA_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","per","user","trust","quota","exceeded","the","current","delegated","creation","has","been"],"errorCode":"1932","eventId":"","severity":"Low","summary":"The current user's delegated trust creation quota has been exceeded.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1932; use the surrounding log entries to confirm it.","resolution":"1. Record where 1932 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PER_USER_TRUST_QUOTA_EXCEEDED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1932 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The current user's delegated trust creation quota has been exceeded.\n\nLookup forms: 1932, 0x78C, error 1932, ERROR_PER_USER_TRUST_QUOTA_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1932"]},{"id":1135,"title":"ERROR_ALL_USER_TRUST_QUOTA_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1933","0x78D","error 1933","ERROR_ALL_USER_TRUST_QUOTA_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","all","user","trust","quota","exceeded","the","total","delegated","creation","has","been"],"errorCode":"1933","eventId":"","severity":"Low","summary":"The total delegated trust creation quota has been exceeded.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1933; use the surrounding log entries to confirm it.","resolution":"1. Record where 1933 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ALL_USER_TRUST_QUOTA_EXCEEDED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1933 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The total delegated trust creation quota has been exceeded.\n\nLookup forms: 1933, 0x78D, error 1933, ERROR_ALL_USER_TRUST_QUOTA_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1933"]},{"id":1136,"title":"ERROR_USER_DELETE_TRUST_QUOTA_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1934","0x78E","error 1934","ERROR_USER_DELETE_TRUST_QUOTA_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","user","delete","trust","quota","exceeded","the","current","delegated","deletion","has","been"],"errorCode":"1934","eventId":"","severity":"Low","summary":"The current user's delegated trust deletion quota has been exceeded.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 1934; use the surrounding log entries to confirm it.","resolution":"1. Record where 1934 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_USER_DELETE_TRUST_QUOTA_EXCEEDED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1934 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The current user's delegated trust deletion quota has been exceeded.\n\nLookup forms: 1934, 0x78E, error 1934, ERROR_USER_DELETE_TRUST_QUOTA_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1934"]},{"id":1137,"title":"ERROR_AUTHENTICATION_FIREWALL_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1935","0x78F","error 1935","ERROR_AUTHENTICATION_FIREWALL_FAILED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","authentication","firewall","failed","the","computer","you","are","signing","into","protected","specified","account","not","allowed","authenticate"],"errorCode":"1935","eventId":"","severity":"High","summary":"The computer you are signing into is protected by an authentication firewall. The specified account is not allowed to authenticate to the computer.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1935; use the surrounding log entries to confirm it.","resolution":"1. Record where 1935 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_AUTHENTICATION_FIREWALL_FAILED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1935 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The computer you are signing into is protected by an authentication firewall. The specified account is not allowed to authenticate to the computer.\n\nLookup forms: 1935, 0x78F, error 1935, ERROR_AUTHENTICATION_FIREWALL_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1935"]},{"id":1138,"title":"ERROR_REMOTE_PRINT_CONNECTIONS_BLOCKED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1936","0x790","error 1936","ERROR_REMOTE_PRINT_CONNECTIONS_BLOCKED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","remote","print","connections","blocked","the","spooler","are","policy","set","your","machine"],"errorCode":"1936","eventId":"","severity":"High","summary":"Remote connections to the Print Spooler are blocked by a policy set on your machine.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 1936; use the surrounding log entries to confirm it.","resolution":"1. Record where 1936 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REMOTE_PRINT_CONNECTIONS_BLOCKED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1936 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Remote connections to the Print Spooler are blocked by a policy set on your machine.\n\nLookup forms: 1936, 0x790, error 1936, ERROR_REMOTE_PRINT_CONNECTIONS_BLOCKED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1936"]},{"id":1139,"title":"ERROR_NTLM_BLOCKED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1937","0x791","error 1937","ERROR_NTLM_BLOCKED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ntlm","blocked","authentication","failed","because","has","been","disabled"],"errorCode":"1937","eventId":"","severity":"High","summary":"Authentication failed because NTLM authentication has been disabled.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1937; use the surrounding log entries to confirm it.","resolution":"1. Record where 1937 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NTLM_BLOCKED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1937 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Authentication failed because NTLM authentication has been disabled.\n\nLookup forms: 1937, 0x791, error 1937, ERROR_NTLM_BLOCKED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1937"]},{"id":1140,"title":"ERROR_PASSWORD_CHANGE_REQUIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["1938","0x792","error 1938","ERROR_PASSWORD_CHANGE_REQUIRED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","password","change","required","logon","failure","eas","policy","requires","that","the","user","their","before","this","operation","can","performed"],"errorCode":"1938","eventId":"","severity":"High","summary":"Logon Failure: EAS policy requires that the user change their password before this operation can be performed.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1938; use the surrounding log entries to confirm it.","resolution":"1. Record where 1938 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PASSWORD_CHANGE_REQUIRED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1938 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Logon Failure: EAS policy requires that the user change their password before this operation can be performed.\n\nLookup forms: 1938, 0x792, error 1938, ERROR_PASSWORD_CHANGE_REQUIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["1938"]},{"id":1141,"title":"ERROR_INVALID_PIXEL_FORMAT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2000","0x7D0","error 2000","ERROR_INVALID_PIXEL_FORMAT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","pixel","format","the"],"errorCode":"2000","eventId":"","severity":"Medium","summary":"The pixel format is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2000; use the surrounding log entries to confirm it.","resolution":"1. Record where 2000 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_PIXEL_FORMAT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2000 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The pixel format is invalid.\n\nLookup forms: 2000, 0x7D0, error 2000, ERROR_INVALID_PIXEL_FORMAT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2000"]},{"id":1142,"title":"ERROR_BAD_DRIVER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2001","0x7D1","error 2001","ERROR_BAD_DRIVER","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","bad","driver","the","specified","invalid"],"errorCode":"2001","eventId":"","severity":"Medium","summary":"The specified driver is invalid.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2001; use the surrounding log entries to confirm it.","resolution":"1. Record where 2001 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_DRIVER.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2001 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified driver is invalid.\n\nLookup forms: 2001, 0x7D1, error 2001, ERROR_BAD_DRIVER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2001"]},{"id":1143,"title":"ERROR_INVALID_WINDOW_STYLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2002","0x7D2","error 2002","ERROR_INVALID_WINDOW_STYLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","window","style","the","class","attribute","for","this","operation"],"errorCode":"2002","eventId":"","severity":"Medium","summary":"The window style or class attribute is invalid for this operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2002; use the surrounding log entries to confirm it.","resolution":"1. Record where 2002 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_WINDOW_STYLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2002 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The window style or class attribute is invalid for this operation.\n\nLookup forms: 2002, 0x7D2, error 2002, ERROR_INVALID_WINDOW_STYLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2002"]},{"id":1144,"title":"ERROR_METAFILE_NOT_SUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2003","0x7D3","error 2003","ERROR_METAFILE_NOT_SUPPORTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","metafile","not","supported","the","requested","operation"],"errorCode":"2003","eventId":"","severity":"Medium","summary":"The requested metafile operation is not supported.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2003; use the surrounding log entries to confirm it.","resolution":"1. Record where 2003 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_METAFILE_NOT_SUPPORTED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2003 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested metafile operation is not supported.\n\nLookup forms: 2003, 0x7D3, error 2003, ERROR_METAFILE_NOT_SUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2003"]},{"id":1145,"title":"ERROR_TRANSFORM_NOT_SUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2004","0x7D4","error 2004","ERROR_TRANSFORM_NOT_SUPPORTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","transform","not","supported","the","requested","transformation","operation"],"errorCode":"2004","eventId":"","severity":"Medium","summary":"The requested transformation operation is not supported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2004; use the surrounding log entries to confirm it.","resolution":"1. Record where 2004 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSFORM_NOT_SUPPORTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2004 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested transformation operation is not supported.\n\nLookup forms: 2004, 0x7D4, error 2004, ERROR_TRANSFORM_NOT_SUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2004"]},{"id":1146,"title":"ERROR_CLIPPING_NOT_SUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2005","0x7D5","error 2005","ERROR_CLIPPING_NOT_SUPPORTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","clipping","not","supported","the","requested","operation"],"errorCode":"2005","eventId":"","severity":"Medium","summary":"The requested clipping operation is not supported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2005; use the surrounding log entries to confirm it.","resolution":"1. Record where 2005 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLIPPING_NOT_SUPPORTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2005 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested clipping operation is not supported.\n\nLookup forms: 2005, 0x7D5, error 2005, ERROR_CLIPPING_NOT_SUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2005"]},{"id":1147,"title":"ERROR_INVALID_CMM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2010","0x7DA","error 2010","ERROR_INVALID_CMM","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","invalid","cmm","the","specified","color","management","module"],"errorCode":"2010","eventId":"","severity":"Medium","summary":"The specified color management module is invalid.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 2010; use the surrounding log entries to confirm it.","resolution":"1. Record where 2010 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_CMM.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2010 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified color management module is invalid.\n\nLookup forms: 2010, 0x7DA, error 2010, ERROR_INVALID_CMM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2010"]},{"id":1148,"title":"ERROR_INVALID_PROFILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2011","0x7DB","error 2011","ERROR_INVALID_PROFILE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","invalid","profile","the","specified","color"],"errorCode":"2011","eventId":"","severity":"Medium","summary":"The specified color profile is invalid.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2011; use the surrounding log entries to confirm it.","resolution":"1. Record where 2011 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_PROFILE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2011 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified color profile is invalid.\n\nLookup forms: 2011, 0x7DB, error 2011, ERROR_INVALID_PROFILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2011"]},{"id":1149,"title":"ERROR_TAG_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2012","0x7DC","error 2012","ERROR_TAG_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","tag","not","found","the","specified","was"],"errorCode":"2012","eventId":"","severity":"Medium","summary":"The specified tag was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2012; use the surrounding log entries to confirm it.","resolution":"1. Record where 2012 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TAG_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2012 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified tag was not found.\n\nLookup forms: 2012, 0x7DC, error 2012, ERROR_TAG_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2012"]},{"id":1150,"title":"ERROR_TAG_NOT_PRESENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2013","0x7DD","error 2013","ERROR_TAG_NOT_PRESENT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","tag","not","present","required"],"errorCode":"2013","eventId":"","severity":"Low","summary":"A required tag is not present.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2013; use the surrounding log entries to confirm it.","resolution":"1. Record where 2013 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TAG_NOT_PRESENT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2013 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A required tag is not present.\n\nLookup forms: 2013, 0x7DD, error 2013, ERROR_TAG_NOT_PRESENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2013"]},{"id":1151,"title":"ERROR_DUPLICATE_TAG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2014","0x7DE","error 2014","ERROR_DUPLICATE_TAG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","duplicate","tag","the","specified","already","present"],"errorCode":"2014","eventId":"","severity":"Low","summary":"The specified tag is already present.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2014; use the surrounding log entries to confirm it.","resolution":"1. Record where 2014 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DUPLICATE_TAG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2014 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified tag is already present.\n\nLookup forms: 2014, 0x7DE, error 2014, ERROR_DUPLICATE_TAG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2014"]},{"id":1152,"title":"ERROR_PROFILE_NOT_ASSOCIATED_WITH_DEVICE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2015","0x7DF","error 2015","ERROR_PROFILE_NOT_ASSOCIATED_WITH_DEVICE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","profile","not","associated","with","device","the","specified","color"],"errorCode":"2015","eventId":"","severity":"Low","summary":"The specified color profile is not associated with the specified device.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2015; use the surrounding log entries to confirm it.","resolution":"1. Record where 2015 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PROFILE_NOT_ASSOCIATED_WITH_DEVICE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2015 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified color profile is not associated with the specified device.\n\nLookup forms: 2015, 0x7DF, error 2015, ERROR_PROFILE_NOT_ASSOCIATED_WITH_DEVICE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The specified color profile is not associated with any device.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2015"]},{"id":1153,"title":"ERROR_PROFILE_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2016","0x7E0","error 2016","ERROR_PROFILE_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","profile","not","found","the","specified","color","was"],"errorCode":"2016","eventId":"","severity":"Medium","summary":"The specified color profile was not found.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2016; use the surrounding log entries to confirm it.","resolution":"1. Record where 2016 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PROFILE_NOT_FOUND.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2016 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified color profile was not found.\n\nLookup forms: 2016, 0x7E0, error 2016, ERROR_PROFILE_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2016"]},{"id":1154,"title":"ERROR_INVALID_COLORSPACE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2017","0x7E1","error 2017","ERROR_INVALID_COLORSPACE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","colorspace","the","specified","color","space"],"errorCode":"2017","eventId":"","severity":"Medium","summary":"The specified color space is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2017; use the surrounding log entries to confirm it.","resolution":"1. Record where 2017 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_COLORSPACE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2017 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified color space is invalid.\n\nLookup forms: 2017, 0x7E1, error 2017, ERROR_INVALID_COLORSPACE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2017"]},{"id":1155,"title":"ERROR_ICM_NOT_ENABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2018","0x7E2","error 2018","ERROR_ICM_NOT_ENABLED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","icm","not","enabled","image","color","management"],"errorCode":"2018","eventId":"","severity":"Low","summary":"Image Color Management is not enabled.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2018; use the surrounding log entries to confirm it.","resolution":"1. Record where 2018 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ICM_NOT_ENABLED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2018 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Image Color Management is not enabled.\n\nLookup forms: 2018, 0x7E2, error 2018, ERROR_ICM_NOT_ENABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2018"]},{"id":1156,"title":"ERROR_DELETING_ICM_XFORM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2019","0x7E3","error 2019","ERROR_DELETING_ICM_XFORM","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","deleting","icm","xform","there","was","while","the","color","transform"],"errorCode":"2019","eventId":"","severity":"Low","summary":"There was an error while deleting the color transform.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2019; use the surrounding log entries to confirm it.","resolution":"1. Record where 2019 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DELETING_ICM_XFORM.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2019 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There was an error while deleting the color transform.\n\nLookup forms: 2019, 0x7E3, error 2019, ERROR_DELETING_ICM_XFORM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2019"]},{"id":1157,"title":"ERROR_INVALID_TRANSFORM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2020","0x7E4","error 2020","ERROR_INVALID_TRANSFORM","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","transform","the","specified","color"],"errorCode":"2020","eventId":"","severity":"Medium","summary":"The specified color transform is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2020; use the surrounding log entries to confirm it.","resolution":"1. Record where 2020 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_TRANSFORM.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2020 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified color transform is invalid.\n\nLookup forms: 2020, 0x7E4, error 2020, ERROR_INVALID_TRANSFORM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2020"]},{"id":1158,"title":"ERROR_COLORSPACE_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2021","0x7E5","error 2021","ERROR_COLORSPACE_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","colorspace","mismatch","the","specified","transform","does","not","match","bitmap","color","space"],"errorCode":"2021","eventId":"","severity":"Low","summary":"The specified transform does not match the bitmap's color space.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2021; use the surrounding log entries to confirm it.","resolution":"1. Record where 2021 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_COLORSPACE_MISMATCH.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2021 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified transform does not match the bitmap's color space.\n\nLookup forms: 2021, 0x7E5, error 2021, ERROR_COLORSPACE_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2021"]},{"id":1159,"title":"ERROR_INVALID_COLORINDEX","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2022","0x7E6","error 2022","ERROR_INVALID_COLORINDEX","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","invalid","colorindex","the","specified","named","color","index","not","present","profile"],"errorCode":"2022","eventId":"","severity":"Low","summary":"The specified named color index is not present in the profile.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2022; use the surrounding log entries to confirm it.","resolution":"1. Record where 2022 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_COLORINDEX.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2022 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified named color index is not present in the profile.\n\nLookup forms: 2022, 0x7E6, error 2022, ERROR_INVALID_COLORINDEX. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2022"]},{"id":1160,"title":"ERROR_PROFILE_DOES_NOT_MATCH_DEVICE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2023","0x7E7","error 2023","ERROR_PROFILE_DOES_NOT_MATCH_DEVICE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","profile","does","not","match","device","the","specified","intended","for","different","type","than"],"errorCode":"2023","eventId":"","severity":"Low","summary":"The specified profile is intended for a device of a different type than the specified device.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2023; use the surrounding log entries to confirm it.","resolution":"1. Record where 2023 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PROFILE_DOES_NOT_MATCH_DEVICE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2023 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified profile is intended for a device of a different type than the specified device.\n\nLookup forms: 2023, 0x7E7, error 2023, ERROR_PROFILE_DOES_NOT_MATCH_DEVICE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2023"]},{"id":1161,"title":"ERROR_CONNECTED_OTHER_PASSWORD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2108","0x83C","error 2108","ERROR_CONNECTED_OTHER_PASSWORD","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","connected","other","password","the","network","connection","was","made","successfully","but","user","had","prompted","for","than","one","originally","specified"],"errorCode":"2108","eventId":"","severity":"High","summary":"The network connection was made successfully, but the user had to be prompted for a password other than the one originally specified.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2108; use the surrounding log entries to confirm it.","resolution":"1. Record where 2108 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CONNECTED_OTHER_PASSWORD.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2108 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The network connection was made successfully, but the user had to be prompted for a password other than the one originally specified.\n\nLookup forms: 2108, 0x83C, error 2108, ERROR_CONNECTED_OTHER_PASSWORD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2108"]},{"id":1162,"title":"ERROR_CONNECTED_OTHER_PASSWORD_DEFAULT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2109","0x83D","error 2109","ERROR_CONNECTED_OTHER_PASSWORD_DEFAULT","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","connected","other","password","default","the","network","connection","was","made","successfully","using","credentials"],"errorCode":"2109","eventId":"","severity":"High","summary":"The network connection was made successfully using default credentials.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2109; use the surrounding log entries to confirm it.","resolution":"1. Record where 2109 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CONNECTED_OTHER_PASSWORD_DEFAULT.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2109 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The network connection was made successfully using default credentials.\n\nLookup forms: 2109, 0x83D, error 2109, ERROR_CONNECTED_OTHER_PASSWORD_DEFAULT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2109"]},{"id":1163,"title":"ERROR_BAD_USERNAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2202","0x89A","error 2202","ERROR_BAD_USERNAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","bad","username","the","specified","invalid"],"errorCode":"2202","eventId":"","severity":"Medium","summary":"The specified username is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2202; use the surrounding log entries to confirm it.","resolution":"1. Record where 2202 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_USERNAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2202 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified username is invalid.\n\nLookup forms: 2202, 0x89A, error 2202, ERROR_BAD_USERNAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2202"]},{"id":1164,"title":"ERROR_NOT_CONNECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2250","0x8CA","error 2250","ERROR_NOT_CONNECTED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","not","connected","this","network","connection","does","exist"],"errorCode":"2250","eventId":"","severity":"High","summary":"This network connection does not exist.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2250; use the surrounding log entries to confirm it.","resolution":"1. Record where 2250 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_CONNECTED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2250 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This network connection does not exist.\n\nLookup forms: 2250, 0x8CA, error 2250, ERROR_NOT_CONNECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2250"]},{"id":1165,"title":"ERROR_OPEN_FILES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2401","0x961","error 2401","ERROR_OPEN_FILES","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","open","files","this","network","connection","has","requests","pending"],"errorCode":"2401","eventId":"","severity":"High","summary":"This network connection has files open or requests pending.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2401; use the surrounding log entries to confirm it.","resolution":"1. Record where 2401 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_OPEN_FILES.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2401 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This network connection has files open or requests pending.\n\nLookup forms: 2401, 0x961, error 2401, ERROR_OPEN_FILES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2401"]},{"id":1166,"title":"ERROR_ACTIVE_CONNECTIONS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2402","0x962","error 2402","ERROR_ACTIVE_CONNECTIONS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","active","connections","still","exist"],"errorCode":"2402","eventId":"","severity":"High","summary":"Active connections still exist.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2402; use the surrounding log entries to confirm it.","resolution":"1. Record where 2402 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ACTIVE_CONNECTIONS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2402 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Active connections still exist.\n\nLookup forms: 2402, 0x962, error 2402, ERROR_ACTIVE_CONNECTIONS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2402"]},{"id":1167,"title":"ERROR_DEVICE_IN_USE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2404","0x964","error 2404","ERROR_DEVICE_IN_USE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","device","use","the","active","process","and","cannot","disconnected"],"errorCode":"2404","eventId":"","severity":"Medium","summary":"The device is in use by an active process and cannot be disconnected.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2404; use the surrounding log entries to confirm it.","resolution":"1. Record where 2404 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEVICE_IN_USE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2404 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The device is in use by an active process and cannot be disconnected.\n\nLookup forms: 2404, 0x964, error 2404, ERROR_DEVICE_IN_USE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2404"]},{"id":1168,"title":"ERROR_UNKNOWN_PRINT_MONITOR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3000","0xBB8","error 3000","ERROR_UNKNOWN_PRINT_MONITOR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","unknown","print","monitor","the","specified"],"errorCode":"3000","eventId":"","severity":"Low","summary":"The specified print monitor is unknown.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 3000; use the surrounding log entries to confirm it.","resolution":"1. Record where 3000 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNKNOWN_PRINT_MONITOR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3000 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified print monitor is unknown.\n\nLookup forms: 3000, 0xBB8, error 3000, ERROR_UNKNOWN_PRINT_MONITOR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3000"]},{"id":1169,"title":"ERROR_PRINTER_DRIVER_IN_USE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3001","0xBB9","error 3001","ERROR_PRINTER_DRIVER_IN_USE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","printer","driver","use","the","specified","currently"],"errorCode":"3001","eventId":"","severity":"Low","summary":"The specified printer driver is currently in use.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 3001; use the surrounding log entries to confirm it.","resolution":"1. Record where 3001 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PRINTER_DRIVER_IN_USE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3001 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified printer driver is currently in use.\n\nLookup forms: 3001, 0xBB9, error 3001, ERROR_PRINTER_DRIVER_IN_USE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3001"]},{"id":1170,"title":"ERROR_SPOOL_FILE_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3002","0xBBA","error 3002","ERROR_SPOOL_FILE_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","spool","file","not","found","the","was"],"errorCode":"3002","eventId":"","severity":"Medium","summary":"The spool file was not found.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 3002; use the surrounding log entries to confirm it.","resolution":"1. Record where 3002 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SPOOL_FILE_NOT_FOUND.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3002 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The spool file was not found.\n\nLookup forms: 3002, 0xBBA, error 3002, ERROR_SPOOL_FILE_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3002"]},{"id":1171,"title":"ERROR_SPL_NO_STARTDOC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3003","0xBBB","error 3003","ERROR_SPL_NO_STARTDOC","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","spl","startdoc","startdocprinter","call","was","not","issued"],"errorCode":"3003","eventId":"","severity":"Low","summary":"A StartDocPrinter call was not issued.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 3003; use the surrounding log entries to confirm it.","resolution":"1. Record where 3003 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SPL_NO_STARTDOC.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3003 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A StartDocPrinter call was not issued.\n\nLookup forms: 3003, 0xBBB, error 3003, ERROR_SPL_NO_STARTDOC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3003"]},{"id":1172,"title":"ERROR_SPL_NO_ADDJOB","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3004","0xBBC","error 3004","ERROR_SPL_NO_ADDJOB","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","spl","addjob","call","was","not","issued"],"errorCode":"3004","eventId":"","severity":"Low","summary":"An AddJob call was not issued.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 3004; use the surrounding log entries to confirm it.","resolution":"1. Record where 3004 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SPL_NO_ADDJOB.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3004 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An AddJob call was not issued.\n\nLookup forms: 3004, 0xBBC, error 3004, ERROR_SPL_NO_ADDJOB. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3004"]},{"id":1173,"title":"ERROR_PRINT_PROCESSOR_ALREADY_INSTALLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3005","0xBBD","error 3005","ERROR_PRINT_PROCESSOR_ALREADY_INSTALLED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","print","processor","already","installed","the","specified","has","been"],"errorCode":"3005","eventId":"","severity":"Low","summary":"The specified print processor has already been installed.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 3005; use the surrounding log entries to confirm it.","resolution":"1. Record where 3005 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PRINT_PROCESSOR_ALREADY_INSTALLED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3005 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified print processor has already been installed.\n\nLookup forms: 3005, 0xBBD, error 3005, ERROR_PRINT_PROCESSOR_ALREADY_INSTALLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3005"]},{"id":1174,"title":"ERROR_PRINT_MONITOR_ALREADY_INSTALLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3006","0xBBE","error 3006","ERROR_PRINT_MONITOR_ALREADY_INSTALLED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","print","monitor","already","installed","the","specified","has","been"],"errorCode":"3006","eventId":"","severity":"Low","summary":"The specified print monitor has already been installed.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 3006; use the surrounding log entries to confirm it.","resolution":"1. Record where 3006 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PRINT_MONITOR_ALREADY_INSTALLED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3006 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified print monitor has already been installed.\n\nLookup forms: 3006, 0xBBE, error 3006, ERROR_PRINT_MONITOR_ALREADY_INSTALLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3006"]},{"id":1175,"title":"ERROR_INVALID_PRINT_MONITOR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3007","0xBBF","error 3007","ERROR_INVALID_PRINT_MONITOR","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","invalid","print","monitor","the","specified","does","not","have","required","functions"],"errorCode":"3007","eventId":"","severity":"Low","summary":"The specified print monitor does not have the required functions.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 3007; use the surrounding log entries to confirm it.","resolution":"1. Record where 3007 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_PRINT_MONITOR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3007 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified print monitor does not have the required functions.\n\nLookup forms: 3007, 0xBBF, error 3007, ERROR_INVALID_PRINT_MONITOR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3007"]},{"id":1176,"title":"ERROR_PRINT_MONITOR_IN_USE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3008","0xBC0","error 3008","ERROR_PRINT_MONITOR_IN_USE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","print","monitor","use","the","specified","currently"],"errorCode":"3008","eventId":"","severity":"Low","summary":"The specified print monitor is currently in use.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 3008; use the surrounding log entries to confirm it.","resolution":"1. Record where 3008 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PRINT_MONITOR_IN_USE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3008 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified print monitor is currently in use.\n\nLookup forms: 3008, 0xBC0, error 3008, ERROR_PRINT_MONITOR_IN_USE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3008"]},{"id":1177,"title":"ERROR_PRINTER_HAS_JOBS_QUEUED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3009","0xBC1","error 3009","ERROR_PRINTER_HAS_JOBS_QUEUED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","printer","has","jobs","queued","the","requested","operation","not","allowed","when","there","are"],"errorCode":"3009","eventId":"","severity":"Low","summary":"The requested operation is not allowed when there are jobs queued to the printer.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 3009; use the surrounding log entries to confirm it.","resolution":"1. Record where 3009 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PRINTER_HAS_JOBS_QUEUED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3009 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested operation is not allowed when there are jobs queued to the printer.\n\nLookup forms: 3009, 0xBC1, error 3009, ERROR_PRINTER_HAS_JOBS_QUEUED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3009"]},{"id":1178,"title":"ERROR_SUCCESS_REBOOT_REQUIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3010","0xBC2","error 3010","ERROR_SUCCESS_REBOOT_REQUIRED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","success","reboot","required","the","requested","operation","successful","changes","will","not","effective","until","system","rebooted"],"errorCode":"3010","eventId":"","severity":"Low","summary":"The requested operation is successful. Changes will not be effective until the system is rebooted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 3010; use the surrounding log entries to confirm it.","resolution":"1. Record where 3010 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SUCCESS_REBOOT_REQUIRED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3010 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested operation is successful. Changes will not be effective until the system is rebooted.\n\nLookup forms: 3010, 0xBC2, error 3010, ERROR_SUCCESS_REBOOT_REQUIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3010"]},{"id":1179,"title":"ERROR_SUCCESS_RESTART_REQUIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3011","0xBC3","error 3011","ERROR_SUCCESS_RESTART_REQUIRED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","success","restart","required","the","requested","operation","successful","changes","will","not","effective","until","service","restarted"],"errorCode":"3011","eventId":"","severity":"Low","summary":"The requested operation is successful. Changes will not be effective until the service is restarted.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 3011; use the surrounding log entries to confirm it.","resolution":"1. Record where 3011 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SUCCESS_RESTART_REQUIRED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3011 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested operation is successful. Changes will not be effective until the service is restarted.\n\nLookup forms: 3011, 0xBC3, error 3011, ERROR_SUCCESS_RESTART_REQUIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3011"]},{"id":1180,"title":"ERROR_PRINTER_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3012","0xBC4","error 3012","ERROR_PRINTER_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","printer","not","found","printers","were"],"errorCode":"3012","eventId":"","severity":"Low","summary":"No printers were found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 3012; use the surrounding log entries to confirm it.","resolution":"1. Record where 3012 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PRINTER_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3012 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No printers were found.\n\nLookup forms: 3012, 0xBC4, error 3012, ERROR_PRINTER_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3012"]},{"id":1181,"title":"ERROR_PRINTER_DRIVER_WARNED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3013","0xBC5","error 3013","ERROR_PRINTER_DRIVER_WARNED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","printer","driver","warned","the","known","unreliable"],"errorCode":"3013","eventId":"","severity":"Low","summary":"The printer driver is known to be unreliable.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 3013; use the surrounding log entries to confirm it.","resolution":"1. Record where 3013 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PRINTER_DRIVER_WARNED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3013 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The printer driver is known to be unreliable.\n\nLookup forms: 3013, 0xBC5, error 3013, ERROR_PRINTER_DRIVER_WARNED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3013"]},{"id":1182,"title":"ERROR_PRINTER_DRIVER_BLOCKED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3014","0xBC6","error 3014","ERROR_PRINTER_DRIVER_BLOCKED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","printer","driver","blocked","the","known","harm","system"],"errorCode":"3014","eventId":"","severity":"Low","summary":"The printer driver is known to harm the system.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 3014; use the surrounding log entries to confirm it.","resolution":"1. Record where 3014 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PRINTER_DRIVER_BLOCKED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3014 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The printer driver is known to harm the system.\n\nLookup forms: 3014, 0xBC6, error 3014, ERROR_PRINTER_DRIVER_BLOCKED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3014"]},{"id":1183,"title":"ERROR_PRINTER_DRIVER_PACKAGE_IN_USE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3015","0xBC7","error 3015","ERROR_PRINTER_DRIVER_PACKAGE_IN_USE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","printer","driver","package","use","the","specified","currently"],"errorCode":"3015","eventId":"","severity":"Low","summary":"The specified printer driver package is currently in use.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 3015; use the surrounding log entries to confirm it.","resolution":"1. Record where 3015 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PRINTER_DRIVER_PACKAGE_IN_USE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3015 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified printer driver package is currently in use.\n\nLookup forms: 3015, 0xBC7, error 3015, ERROR_PRINTER_DRIVER_PACKAGE_IN_USE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3015"]},{"id":1184,"title":"ERROR_CORE_DRIVER_PACKAGE_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3016","0xBC8","error 3016","ERROR_CORE_DRIVER_PACKAGE_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","core","driver","package","not","found","unable","find","that","required","the","printer"],"errorCode":"3016","eventId":"","severity":"Medium","summary":"Unable to find a core driver package that is required by the printer driver package.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 3016; use the surrounding log entries to confirm it.","resolution":"1. Record where 3016 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CORE_DRIVER_PACKAGE_NOT_FOUND.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3016 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to find a core driver package that is required by the printer driver package.\n\nLookup forms: 3016, 0xBC8, error 3016, ERROR_CORE_DRIVER_PACKAGE_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3016"]},{"id":1185,"title":"ERROR_FAIL_REBOOT_REQUIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3017","0xBC9","error 3017","ERROR_FAIL_REBOOT_REQUIRED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","fail","reboot","required","the","requested","operation","failed","system","roll","back","changes","made"],"errorCode":"3017","eventId":"","severity":"High","summary":"The requested operation failed. A system reboot is required to roll back changes made.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 3017; use the surrounding log entries to confirm it.","resolution":"1. Record where 3017 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FAIL_REBOOT_REQUIRED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3017 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested operation failed. A system reboot is required to roll back changes made.\n\nLookup forms: 3017, 0xBC9, error 3017, ERROR_FAIL_REBOOT_REQUIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3017"]},{"id":1186,"title":"ERROR_FAIL_REBOOT_INITIATED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3018","0xBCA","error 3018","ERROR_FAIL_REBOOT_INITIATED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","fail","reboot","initiated","the","requested","operation","failed","system","has","been","roll","back","changes","made"],"errorCode":"3018","eventId":"","severity":"High","summary":"The requested operation failed. A system reboot has been initiated to roll back changes made.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 3018; use the surrounding log entries to confirm it.","resolution":"1. Record where 3018 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FAIL_REBOOT_INITIATED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3018 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested operation failed. A system reboot has been initiated to roll back changes made.\n\nLookup forms: 3018, 0xBCA, error 3018, ERROR_FAIL_REBOOT_INITIATED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3018"]},{"id":1187,"title":"ERROR_PRINTER_DRIVER_DOWNLOAD_NEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3019","0xBCB","error 3019","ERROR_PRINTER_DRIVER_DOWNLOAD_NEEDED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","printer","driver","download","needed","the","specified","was","not","found","system","and","needs","downloaded"],"errorCode":"3019","eventId":"","severity":"Medium","summary":"The specified printer driver was not found on the system and needs to be downloaded.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 3019; use the surrounding log entries to confirm it.","resolution":"1. Record where 3019 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PRINTER_DRIVER_DOWNLOAD_NEEDED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3019 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified printer driver was not found on the system and needs to be downloaded.\n\nLookup forms: 3019, 0xBCB, error 3019, ERROR_PRINTER_DRIVER_DOWNLOAD_NEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3019"]},{"id":1188,"title":"ERROR_PRINT_JOB_RESTART_REQUIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3020","0xBCC","error 3020","ERROR_PRINT_JOB_RESTART_REQUIRED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","print","job","restart","required","the","requested","has","failed","system","update","requires","resubmitted"],"errorCode":"3020","eventId":"","severity":"High","summary":"The requested print job has failed to print. A print system update requires the job to be resubmitted.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 3020; use the surrounding log entries to confirm it.","resolution":"1. Record where 3020 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PRINT_JOB_RESTART_REQUIRED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3020 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested print job has failed to print. A print system update requires the job to be resubmitted.\n\nLookup forms: 3020, 0xBCC, error 3020, ERROR_PRINT_JOB_RESTART_REQUIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3020"]},{"id":1189,"title":"ERROR_INVALID_PRINTER_DRIVER_MANIFEST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3021","0xBCD","error 3021","ERROR_INVALID_PRINTER_DRIVER_MANIFEST","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","invalid","printer","driver","manifest","the","does","not","contain","valid","contains","too","many","manifests"],"errorCode":"3021","eventId":"","severity":"Low","summary":"The printer driver does not contain a valid manifest, or contains too many manifests.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 3021; use the surrounding log entries to confirm it.","resolution":"1. Record where 3021 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_PRINTER_DRIVER_MANIFEST.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3021 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The printer driver does not contain a valid manifest, or contains too many manifests.\n\nLookup forms: 3021, 0xBCD, error 3021, ERROR_INVALID_PRINTER_DRIVER_MANIFEST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3021"]},{"id":1190,"title":"ERROR_PRINTER_NOT_SHAREABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3022","0xBCE","error 3022","ERROR_PRINTER_NOT_SHAREABLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","printer","not","shareable","the","specified","cannot","shared"],"errorCode":"3022","eventId":"","severity":"Medium","summary":"The specified printer cannot be shared.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 3022; use the surrounding log entries to confirm it.","resolution":"1. Record where 3022 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PRINTER_NOT_SHAREABLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3022 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified printer cannot be shared.\n\nLookup forms: 3022, 0xBCE, error 3022, ERROR_PRINTER_NOT_SHAREABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3022"]},{"id":1191,"title":"ERROR_REQUEST_PAUSED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3050","0xBEA","error 3050","ERROR_REQUEST_PAUSED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","request","paused","the","operation","was"],"errorCode":"3050","eventId":"","severity":"Low","summary":"The operation was paused.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 3050; use the surrounding log entries to confirm it.","resolution":"1. Record where 3050 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REQUEST_PAUSED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3050 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation was paused.\n\nLookup forms: 3050, 0xBEA, error 3050, ERROR_REQUEST_PAUSED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3050"]},{"id":1192,"title":"ERROR_IO_REISSUE_AS_CACHED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["3950","0xF6E","error 3950","ERROR_IO_REISSUE_AS_CACHED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","reissue","cached","the","given","operation"],"errorCode":"3950","eventId":"","severity":"Low","summary":"Reissue the given operation as a cached IO operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 3950; use the surrounding log entries to confirm it.","resolution":"1. Record where 3950 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IO_REISSUE_AS_CACHED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 3950 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Reissue the given operation as a cached IO operation.\n\nLookup forms: 3950, 0xF6E, error 3950, ERROR_IO_REISSUE_AS_CACHED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["3950"]},{"id":1193,"title":"ERROR_WINS_INTERNAL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4000","0xFA0","error 4000","ERROR_WINS_INTERNAL","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","wins","internal","encountered","while","processing","the","command"],"errorCode":"4000","eventId":"","severity":"Low","summary":"WINS encountered an error while processing the command.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 4000; use the surrounding log entries to confirm it.","resolution":"1. Record where 4000 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WINS_INTERNAL.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4000 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: WINS encountered an error while processing the command.\n\nLookup forms: 4000, 0xFA0, error 4000, ERROR_WINS_INTERNAL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4000"]},{"id":1194,"title":"ERROR_CAN_NOT_DEL_LOCAL_WINS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4001","0xFA1","error 4001","ERROR_CAN_NOT_DEL_LOCAL_WINS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","can","not","del","local","wins","the","cannot","deleted"],"errorCode":"4001","eventId":"","severity":"Medium","summary":"The local WINS cannot be deleted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4001; use the surrounding log entries to confirm it.","resolution":"1. Record where 4001 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CAN_NOT_DEL_LOCAL_WINS.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4001 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The local WINS cannot be deleted.\n\nLookup forms: 4001, 0xFA1, error 4001, ERROR_CAN_NOT_DEL_LOCAL_WINS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4001"]},{"id":1195,"title":"ERROR_STATIC_INIT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4002","0xFA2","error 4002","ERROR_STATIC_INIT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","static","init","the","importation","from","file","failed"],"errorCode":"4002","eventId":"","severity":"High","summary":"The importation from the file failed.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 4002; use the surrounding log entries to confirm it.","resolution":"1. Record where 4002 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STATIC_INIT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4002 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The importation from the file failed.\n\nLookup forms: 4002, 0xFA2, error 4002, ERROR_STATIC_INIT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4002"]},{"id":1196,"title":"ERROR_INC_BACKUP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4003","0xFA3","error 4003","ERROR_INC_BACKUP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","inc","backup","the","failed","was","full","done","before"],"errorCode":"4003","eventId":"","severity":"High","summary":"The backup failed. Was a full backup done before?","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4003; use the surrounding log entries to confirm it.","resolution":"1. Record where 4003 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INC_BACKUP.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4003 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The backup failed. Was a full backup done before?\n\nLookup forms: 4003, 0xFA3, error 4003, ERROR_INC_BACKUP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4003"]},{"id":1197,"title":"ERROR_FULL_BACKUP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4004","0xFA4","error 4004","ERROR_FULL_BACKUP","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","full","backup","the","failed","check","directory","which","you","are","backing","database"],"errorCode":"4004","eventId":"","severity":"High","summary":"The backup failed. Check the directory to which you are backing the database.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 4004; use the surrounding log entries to confirm it.","resolution":"1. Record where 4004 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FULL_BACKUP.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4004 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The backup failed. Check the directory to which you are backing the database.\n\nLookup forms: 4004, 0xFA4, error 4004, ERROR_FULL_BACKUP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4004"]},{"id":1198,"title":"ERROR_REC_NON_EXISTENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4005","0xFA5","error 4005","ERROR_REC_NON_EXISTENT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","rec","non","existent","the","name","does","not","exist","wins","database"],"errorCode":"4005","eventId":"","severity":"Low","summary":"The name does not exist in the WINS database.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4005; use the surrounding log entries to confirm it.","resolution":"1. Record where 4005 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REC_NON_EXISTENT.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4005 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The name does not exist in the WINS database.\n\nLookup forms: 4005, 0xFA5, error 4005, ERROR_REC_NON_EXISTENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4005"]},{"id":1199,"title":"ERROR_RPL_NOT_ALLOWED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4006","0xFA6","error 4006","ERROR_RPL_NOT_ALLOWED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","rpl","not","allowed","replication","with","nonconfigured","partner"],"errorCode":"4006","eventId":"","severity":"Low","summary":"Replication with a nonconfigured partner is not allowed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4006; use the surrounding log entries to confirm it.","resolution":"1. Record where 4006 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RPL_NOT_ALLOWED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4006 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Replication with a nonconfigured partner is not allowed.\n\nLookup forms: 4006, 0xFA6, error 4006, ERROR_RPL_NOT_ALLOWED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4006"]},{"id":1200,"title":"PEERDIST_ERROR_CONTENTINFO_VERSION_UNSUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4050","0xFD2","error 4050","PEERDIST_ERROR_CONTENTINFO_VERSION_UNSUPPORTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","peerdist","error","contentinfo","version","unsupported","the","supplied","content","information","not","supported"],"errorCode":"4050","eventId":"","severity":"Medium","summary":"The version of the supplied content information is not supported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4050; use the surrounding log entries to confirm it.","resolution":"1. Record where 4050 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to PEERDIST_ERROR_CONTENTINFO_VERSION_UNSUPPORTED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4050 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The version of the supplied content information is not supported.\n\nLookup forms: 4050, 0xFD2, error 4050, PEERDIST_ERROR_CONTENTINFO_VERSION_UNSUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4050"]},{"id":1201,"title":"PEERDIST_ERROR_CANNOT_PARSE_CONTENTINFO","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4051","0xFD3","error 4051","PEERDIST_ERROR_CANNOT_PARSE_CONTENTINFO","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","peerdist","error","cannot","parse","contentinfo","the","supplied","content","information","malformed"],"errorCode":"4051","eventId":"","severity":"Low","summary":"The supplied content information is malformed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4051; use the surrounding log entries to confirm it.","resolution":"1. Record where 4051 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to PEERDIST_ERROR_CANNOT_PARSE_CONTENTINFO.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4051 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The supplied content information is malformed.\n\nLookup forms: 4051, 0xFD3, error 4051, PEERDIST_ERROR_CANNOT_PARSE_CONTENTINFO. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4051"]},{"id":1202,"title":"PEERDIST_ERROR_MISSING_DATA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4052","0xFD4","error 4052","PEERDIST_ERROR_MISSING_DATA","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","peerdist","error","missing","data","the","requested","cannot","found","local","peer","caches"],"errorCode":"4052","eventId":"","severity":"Medium","summary":"The requested data cannot be found in local or peer caches.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4052; use the surrounding log entries to confirm it.","resolution":"1. Record where 4052 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to PEERDIST_ERROR_MISSING_DATA.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4052 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested data cannot be found in local or peer caches.\n\nLookup forms: 4052, 0xFD4, error 4052, PEERDIST_ERROR_MISSING_DATA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4052"]},{"id":1203,"title":"PEERDIST_ERROR_NO_MORE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4053","0xFD5","error 4053","PEERDIST_ERROR_NO_MORE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","peerdist","error","more","data","available","required"],"errorCode":"4053","eventId":"","severity":"Low","summary":"No more data is available or required.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4053; use the surrounding log entries to confirm it.","resolution":"1. Record where 4053 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to PEERDIST_ERROR_NO_MORE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4053 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No more data is available or required.\n\nLookup forms: 4053, 0xFD5, error 4053, PEERDIST_ERROR_NO_MORE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4053"]},{"id":1204,"title":"PEERDIST_ERROR_NOT_INITIALIZED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4054","0xFD6","error 4054","PEERDIST_ERROR_NOT_INITIALIZED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","peerdist","error","not","initialized","the","supplied","object","has","been"],"errorCode":"4054","eventId":"","severity":"Low","summary":"The supplied object has not been initialized.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4054; use the surrounding log entries to confirm it.","resolution":"1. Record where 4054 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to PEERDIST_ERROR_NOT_INITIALIZED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4054 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The supplied object has not been initialized.\n\nLookup forms: 4054, 0xFD6, error 4054, PEERDIST_ERROR_NOT_INITIALIZED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4054"]},{"id":1205,"title":"PEERDIST_ERROR_ALREADY_INITIALIZED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4055","0xFD7","error 4055","PEERDIST_ERROR_ALREADY_INITIALIZED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","peerdist","error","already","initialized","the","supplied","object","has","been"],"errorCode":"4055","eventId":"","severity":"Low","summary":"The supplied object has already been initialized.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4055; use the surrounding log entries to confirm it.","resolution":"1. Record where 4055 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to PEERDIST_ERROR_ALREADY_INITIALIZED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4055 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The supplied object has already been initialized.\n\nLookup forms: 4055, 0xFD7, error 4055, PEERDIST_ERROR_ALREADY_INITIALIZED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4055"]},{"id":1206,"title":"PEERDIST_ERROR_SHUTDOWN_IN_PROGRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4056","0xFD8","error 4056","PEERDIST_ERROR_SHUTDOWN_IN_PROGRESS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","peerdist","error","shutdown","progress","operation","already"],"errorCode":"4056","eventId":"","severity":"Low","summary":"A shutdown operation is already in progress.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4056; use the surrounding log entries to confirm it.","resolution":"1. Record where 4056 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to PEERDIST_ERROR_SHUTDOWN_IN_PROGRESS.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4056 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A shutdown operation is already in progress.\n\nLookup forms: 4056, 0xFD8, error 4056, PEERDIST_ERROR_SHUTDOWN_IN_PROGRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4056"]},{"id":1207,"title":"PEERDIST_ERROR_INVALIDATED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4057","0xFD9","error 4057","PEERDIST_ERROR_INVALIDATED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","peerdist","error","invalidated","the","supplied","object","has","already","been"],"errorCode":"4057","eventId":"","severity":"Medium","summary":"The supplied object has already been invalidated.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4057; use the surrounding log entries to confirm it.","resolution":"1. Record where 4057 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to PEERDIST_ERROR_INVALIDATED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4057 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The supplied object has already been invalidated.\n\nLookup forms: 4057, 0xFD9, error 4057, PEERDIST_ERROR_INVALIDATED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4057"]},{"id":1208,"title":"PEERDIST_ERROR_ALREADY_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4058","0xFDA","error 4058","PEERDIST_ERROR_ALREADY_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","peerdist","error","already","exists","element","and","was","not","replaced"],"errorCode":"4058","eventId":"","severity":"Medium","summary":"An element already exists and was not replaced.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4058; use the surrounding log entries to confirm it.","resolution":"1. Record where 4058 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to PEERDIST_ERROR_ALREADY_EXISTS.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4058 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An element already exists and was not replaced.\n\nLookup forms: 4058, 0xFDA, error 4058, PEERDIST_ERROR_ALREADY_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4058"]},{"id":1209,"title":"PEERDIST_ERROR_OPERATION_NOTFOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4059","0xFDB","error 4059","PEERDIST_ERROR_OPERATION_NOTFOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","peerdist","error","operation","notfound","cannot","cancel","the","requested","has","already","been","completed"],"errorCode":"4059","eventId":"","severity":"Medium","summary":"Cannot cancel the requested operation as it has already been completed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4059; use the surrounding log entries to confirm it.","resolution":"1. Record where 4059 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to PEERDIST_ERROR_OPERATION_NOTFOUND.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4059 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot cancel the requested operation as it has already been completed.\n\nLookup forms: 4059, 0xFDB, error 4059, PEERDIST_ERROR_OPERATION_NOTFOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4059"]},{"id":1210,"title":"PEERDIST_ERROR_ALREADY_COMPLETED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4060","0xFDC","error 4060","PEERDIST_ERROR_ALREADY_COMPLETED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","peerdist","error","already","completed","can","not","perform","the","requested","operation","because","has","been","carried","out"],"errorCode":"4060","eventId":"","severity":"Low","summary":"Can not perform the requested operation because it has already been carried out.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4060; use the surrounding log entries to confirm it.","resolution":"1. Record where 4060 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to PEERDIST_ERROR_ALREADY_COMPLETED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4060 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Can not perform the requested operation because it has already been carried out.\n\nLookup forms: 4060, 0xFDC, error 4060, PEERDIST_ERROR_ALREADY_COMPLETED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4060"]},{"id":1211,"title":"PEERDIST_ERROR_OUT_OF_BOUNDS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4061","0xFDD","error 4061","PEERDIST_ERROR_OUT_OF_BOUNDS","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","peerdist","error","out","bounds","operation","accessed","data","beyond","the","valid"],"errorCode":"4061","eventId":"","severity":"Low","summary":"An operation accessed data beyond the bounds of valid data.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 4061; use the surrounding log entries to confirm it.","resolution":"1. Record where 4061 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to PEERDIST_ERROR_OUT_OF_BOUNDS.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4061 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An operation accessed data beyond the bounds of valid data.\n\nLookup forms: 4061, 0xFDD, error 4061, PEERDIST_ERROR_OUT_OF_BOUNDS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4061"]},{"id":1212,"title":"PEERDIST_ERROR_VERSION_UNSUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4062","0xFDE","error 4062","PEERDIST_ERROR_VERSION_UNSUPPORTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","peerdist","error","version","unsupported","the","requested","not","supported"],"errorCode":"4062","eventId":"","severity":"Medium","summary":"The requested version is not supported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4062; use the surrounding log entries to confirm it.","resolution":"1. Record where 4062 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to PEERDIST_ERROR_VERSION_UNSUPPORTED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4062 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested version is not supported.\n\nLookup forms: 4062, 0xFDE, error 4062, PEERDIST_ERROR_VERSION_UNSUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4062"]},{"id":1213,"title":"PEERDIST_ERROR_INVALID_CONFIGURATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4063","0xFDF","error 4063","PEERDIST_ERROR_INVALID_CONFIGURATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","peerdist","error","invalid","configuration","value"],"errorCode":"4063","eventId":"","severity":"Medium","summary":"A configuration value is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4063; use the surrounding log entries to confirm it.","resolution":"1. Record where 4063 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to PEERDIST_ERROR_INVALID_CONFIGURATION.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4063 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A configuration value is invalid.\n\nLookup forms: 4063, 0xFDF, error 4063, PEERDIST_ERROR_INVALID_CONFIGURATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4063"]},{"id":1214,"title":"PEERDIST_ERROR_NOT_LICENSED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4064","0xFE0","error 4064","PEERDIST_ERROR_NOT_LICENSED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","peerdist","error","not","licensed","the","sku"],"errorCode":"4064","eventId":"","severity":"Low","summary":"The SKU is not licensed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4064; use the surrounding log entries to confirm it.","resolution":"1. Record where 4064 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to PEERDIST_ERROR_NOT_LICENSED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4064 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The SKU is not licensed.\n\nLookup forms: 4064, 0xFE0, error 4064, PEERDIST_ERROR_NOT_LICENSED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4064"]},{"id":1215,"title":"PEERDIST_ERROR_SERVICE_UNAVAILABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4065","0xFE1","error 4065","PEERDIST_ERROR_SERVICE_UNAVAILABLE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","peerdist","error","service","unavailable","still","initializing","and","will","available","shortly"],"errorCode":"4065","eventId":"","severity":"Low","summary":"PeerDist Service is still initializing and will be available shortly.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 4065; use the surrounding log entries to confirm it.","resolution":"1. Record where 4065 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to PEERDIST_ERROR_SERVICE_UNAVAILABLE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4065 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: PeerDist Service is still initializing and will be available shortly.\n\nLookup forms: 4065, 0xFE1, error 4065, PEERDIST_ERROR_SERVICE_UNAVAILABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4065"]},{"id":1216,"title":"PEERDIST_ERROR_TRUST_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4066","0xFE2","error 4066","PEERDIST_ERROR_TRUST_FAILURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","peerdist","error","trust","failure","communication","with","one","more","computers","will","temporarily","blocked","due","recent","errors"],"errorCode":"4066","eventId":"","severity":"High","summary":"Communication with one or more computers will be temporarily blocked due to recent errors.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4066; use the surrounding log entries to confirm it.","resolution":"1. Record where 4066 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to PEERDIST_ERROR_TRUST_FAILURE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4066 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Communication with one or more computers will be temporarily blocked due to recent errors.\n\nLookup forms: 4066, 0xFE2, error 4066, PEERDIST_ERROR_TRUST_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4066"]},{"id":1217,"title":"ERROR_DHCP_ADDRESS_CONFLICT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4100","0x1004","error 4100","ERROR_DHCP_ADDRESS_CONFLICT","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","dhcp","address","conflict","the","client","has","obtained","that","already","use","network","local","interface","will","disabled","until","can","obtain","new"],"errorCode":"4100","eventId":"","severity":"High","summary":"The DHCP client has obtained an IP address that is already in use on the network. The local interface will be disabled until the DHCP client can obtain a new address.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 4100; use the surrounding log entries to confirm it.","resolution":"1. Record where 4100 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DHCP_ADDRESS_CONFLICT.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4100 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The DHCP client has obtained an IP address that is already in use on the network. The local interface will be disabled until the DHCP client can obtain a new address.\n\nLookup forms: 4100, 0x1004, error 4100, ERROR_DHCP_ADDRESS_CONFLICT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4100"]},{"id":1218,"title":"ERROR_WMI_GUID_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4200","0x1068","error 4200","ERROR_WMI_GUID_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wmi","guid","not","found","the","passed","was","recognized","valid","data","provider"],"errorCode":"4200","eventId":"","severity":"Low","summary":"The GUID passed was not recognized as valid by a WMI data provider.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4200; use the surrounding log entries to confirm it.","resolution":"1. Record where 4200 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WMI_GUID_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4200 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The GUID passed was not recognized as valid by a WMI data provider.\n\nLookup forms: 4200, 0x1068, error 4200, ERROR_WMI_GUID_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4200"]},{"id":1219,"title":"ERROR_WMI_INSTANCE_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4201","0x1069","error 4201","ERROR_WMI_INSTANCE_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wmi","instance","not","found","the","name","passed","was","recognized","valid","data","provider"],"errorCode":"4201","eventId":"","severity":"Low","summary":"The instance name passed was not recognized as valid by a WMI data provider.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4201; use the surrounding log entries to confirm it.","resolution":"1. Record where 4201 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WMI_INSTANCE_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4201 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The instance name passed was not recognized as valid by a WMI data provider.\n\nLookup forms: 4201, 0x1069, error 4201, ERROR_WMI_INSTANCE_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4201"]},{"id":1220,"title":"ERROR_WMI_ITEMID_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4202","0x106A","error 4202","ERROR_WMI_ITEMID_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wmi","itemid","not","found","the","data","item","passed","was","recognized","valid","provider"],"errorCode":"4202","eventId":"","severity":"Low","summary":"The data item ID passed was not recognized as valid by a WMI data provider.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4202; use the surrounding log entries to confirm it.","resolution":"1. Record where 4202 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WMI_ITEMID_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4202 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The data item ID passed was not recognized as valid by a WMI data provider.\n\nLookup forms: 4202, 0x106A, error 4202, ERROR_WMI_ITEMID_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4202"]},{"id":1221,"title":"ERROR_WMI_TRY_AGAIN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4203","0x106B","error 4203","ERROR_WMI_TRY_AGAIN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wmi","try","again","the","request","could","not","completed","and","should","retried"],"errorCode":"4203","eventId":"","severity":"Low","summary":"The WMI request could not be completed and should be retried.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4203; use the surrounding log entries to confirm it.","resolution":"1. Record where 4203 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WMI_TRY_AGAIN.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4203 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The WMI request could not be completed and should be retried.\n\nLookup forms: 4203, 0x106B, error 4203, ERROR_WMI_TRY_AGAIN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4203"]},{"id":1222,"title":"ERROR_WMI_DP_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4204","0x106C","error 4204","ERROR_WMI_DP_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wmi","not","found","the","data","provider","could","located"],"errorCode":"4204","eventId":"","severity":"Low","summary":"The WMI data provider could not be located.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4204; use the surrounding log entries to confirm it.","resolution":"1. Record where 4204 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WMI_DP_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4204 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The WMI data provider could not be located.\n\nLookup forms: 4204, 0x106C, error 4204, ERROR_WMI_DP_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4204"]},{"id":1223,"title":"ERROR_WMI_UNRESOLVED_INSTANCE_REF","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4205","0x106D","error 4205","ERROR_WMI_UNRESOLVED_INSTANCE_REF","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wmi","unresolved","instance","ref","the","data","provider","references","set","that","has","not","been","registered"],"errorCode":"4205","eventId":"","severity":"Low","summary":"The WMI data provider references an instance set that has not been registered.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4205; use the surrounding log entries to confirm it.","resolution":"1. Record where 4205 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WMI_UNRESOLVED_INSTANCE_REF.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4205 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The WMI data provider references an instance set that has not been registered.\n\nLookup forms: 4205, 0x106D, error 4205, ERROR_WMI_UNRESOLVED_INSTANCE_REF. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4205"]},{"id":1224,"title":"ERROR_WMI_ALREADY_ENABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4206","0x106E","error 4206","ERROR_WMI_ALREADY_ENABLED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wmi","already","enabled","the","data","block","event","notification","has","been"],"errorCode":"4206","eventId":"","severity":"Low","summary":"The WMI data block or event notification has already been enabled.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4206; use the surrounding log entries to confirm it.","resolution":"1. Record where 4206 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WMI_ALREADY_ENABLED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4206 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The WMI data block or event notification has already been enabled.\n\nLookup forms: 4206, 0x106E, error 4206, ERROR_WMI_ALREADY_ENABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4206"]},{"id":1225,"title":"ERROR_WMI_GUID_DISCONNECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4207","0x106F","error 4207","ERROR_WMI_GUID_DISCONNECTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wmi","guid","disconnected","the","data","block","longer","available"],"errorCode":"4207","eventId":"","severity":"Low","summary":"The WMI data block is no longer available.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4207; use the surrounding log entries to confirm it.","resolution":"1. Record where 4207 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WMI_GUID_DISCONNECTED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4207 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The WMI data block is no longer available.\n\nLookup forms: 4207, 0x106F, error 4207, ERROR_WMI_GUID_DISCONNECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4207"]},{"id":1226,"title":"ERROR_WMI_SERVER_UNAVAILABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4208","0x1070","error 4208","ERROR_WMI_SERVER_UNAVAILABLE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","wmi","server","unavailable","the","data","service","not","available"],"errorCode":"4208","eventId":"","severity":"Low","summary":"The WMI data service is not available.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 4208; use the surrounding log entries to confirm it.","resolution":"1. Record where 4208 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WMI_SERVER_UNAVAILABLE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4208 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The WMI data service is not available.\n\nLookup forms: 4208, 0x1070, error 4208, ERROR_WMI_SERVER_UNAVAILABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4208"]},{"id":1227,"title":"ERROR_WMI_DP_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4209","0x1071","error 4209","ERROR_WMI_DP_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wmi","failed","the","data","provider","carry","out","request"],"errorCode":"4209","eventId":"","severity":"High","summary":"The WMI data provider failed to carry out the request.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4209; use the surrounding log entries to confirm it.","resolution":"1. Record where 4209 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WMI_DP_FAILED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4209 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The WMI data provider failed to carry out the request.\n\nLookup forms: 4209, 0x1071, error 4209, ERROR_WMI_DP_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4209"]},{"id":1228,"title":"ERROR_WMI_INVALID_MOF","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4210","0x1072","error 4210","ERROR_WMI_INVALID_MOF","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wmi","invalid","mof","the","information","not","valid"],"errorCode":"4210","eventId":"","severity":"Low","summary":"The WMI MOF information is not valid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4210; use the surrounding log entries to confirm it.","resolution":"1. Record where 4210 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WMI_INVALID_MOF.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4210 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The WMI MOF information is not valid.\n\nLookup forms: 4210, 0x1072, error 4210, ERROR_WMI_INVALID_MOF. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4210"]},{"id":1229,"title":"ERROR_WMI_INVALID_REGINFO","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4211","0x1073","error 4211","ERROR_WMI_INVALID_REGINFO","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wmi","invalid","reginfo","the","registration","information","not","valid"],"errorCode":"4211","eventId":"","severity":"Low","summary":"The WMI registration information is not valid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4211; use the surrounding log entries to confirm it.","resolution":"1. Record where 4211 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WMI_INVALID_REGINFO.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4211 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The WMI registration information is not valid.\n\nLookup forms: 4211, 0x1073, error 4211, ERROR_WMI_INVALID_REGINFO. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4211"]},{"id":1230,"title":"ERROR_WMI_ALREADY_DISABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4212","0x1074","error 4212","ERROR_WMI_ALREADY_DISABLED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wmi","already","disabled","the","data","block","event","notification","has","been"],"errorCode":"4212","eventId":"","severity":"Low","summary":"The WMI data block or event notification has already been disabled.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4212; use the surrounding log entries to confirm it.","resolution":"1. Record where 4212 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WMI_ALREADY_DISABLED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4212 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The WMI data block or event notification has already been disabled.\n\nLookup forms: 4212, 0x1074, error 4212, ERROR_WMI_ALREADY_DISABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4212"]},{"id":1231,"title":"ERROR_WMI_READ_ONLY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4213","0x1075","error 4213","ERROR_WMI_READ_ONLY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wmi","read","only","the","data","item","block"],"errorCode":"4213","eventId":"","severity":"Low","summary":"The WMI data item or data block is read only.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4213; use the surrounding log entries to confirm it.","resolution":"1. Record where 4213 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WMI_READ_ONLY.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4213 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The WMI data item or data block is read only.\n\nLookup forms: 4213, 0x1075, error 4213, ERROR_WMI_READ_ONLY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4213"]},{"id":1232,"title":"ERROR_WMI_SET_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4214","0x1076","error 4214","ERROR_WMI_SET_FAILURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wmi","set","failure","the","data","item","block","could","not","changed"],"errorCode":"4214","eventId":"","severity":"Low","summary":"The WMI data item or data block could not be changed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4214; use the surrounding log entries to confirm it.","resolution":"1. Record where 4214 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WMI_SET_FAILURE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4214 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The WMI data item or data block could not be changed.\n\nLookup forms: 4214, 0x1076, error 4214, ERROR_WMI_SET_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4214"]},{"id":1233,"title":"ERROR_NOT_APPCONTAINER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4250","0x109A","error 4250","ERROR_NOT_APPCONTAINER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","not","appcontainer","this","operation","only","valid","the","context","app","container"],"errorCode":"4250","eventId":"","severity":"Low","summary":"This operation is only valid in the context of an app container.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4250; use the surrounding log entries to confirm it.","resolution":"1. Record where 4250 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_APPCONTAINER.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4250 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation is only valid in the context of an app container.\n\nLookup forms: 4250, 0x109A, error 4250, ERROR_NOT_APPCONTAINER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4250"]},{"id":1234,"title":"ERROR_APPCONTAINER_REQUIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4251","0x109B","error 4251","ERROR_APPCONTAINER_REQUIRED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","appcontainer","required","this","application","can","only","run","the","context","app","container"],"errorCode":"4251","eventId":"","severity":"Low","summary":"This application can only run in the context of an app container.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4251; use the surrounding log entries to confirm it.","resolution":"1. Record where 4251 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_APPCONTAINER_REQUIRED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4251 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This application can only run in the context of an app container.\n\nLookup forms: 4251, 0x109B, error 4251, ERROR_APPCONTAINER_REQUIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4251"]},{"id":1235,"title":"ERROR_NOT_SUPPORTED_IN_APPCONTAINER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4252","0x109C","error 4252","ERROR_NOT_SUPPORTED_IN_APPCONTAINER","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","not","supported","appcontainer","this","functionality","the","context","app","container"],"errorCode":"4252","eventId":"","severity":"Medium","summary":"This functionality is not supported in the context of an app container.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 4252; use the surrounding log entries to confirm it.","resolution":"1. Record where 4252 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_SUPPORTED_IN_APPCONTAINER.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4252 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This functionality is not supported in the context of an app container.\n\nLookup forms: 4252, 0x109C, error 4252, ERROR_NOT_SUPPORTED_IN_APPCONTAINER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4252"]},{"id":1236,"title":"ERROR_INVALID_PACKAGE_SID_LENGTH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4253","0x109D","error 4253","ERROR_INVALID_PACKAGE_SID_LENGTH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","package","sid","length","the","supplied","not","valid","for","app","container","sids"],"errorCode":"4253","eventId":"","severity":"Low","summary":"The length of the SID supplied is not a valid length for app container SIDs.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4253; use the surrounding log entries to confirm it.","resolution":"1. Record where 4253 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_PACKAGE_SID_LENGTH.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4253 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The length of the SID supplied is not a valid length for app container SIDs.\n\nLookup forms: 4253, 0x109D, error 4253, ERROR_INVALID_PACKAGE_SID_LENGTH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4253"]},{"id":1237,"title":"ERROR_INVALID_MEDIA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4300","0x10CC","error 4300","ERROR_INVALID_MEDIA","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","media","the","identifier","does","not","represent","valid","medium"],"errorCode":"4300","eventId":"","severity":"Low","summary":"The media identifier does not represent a valid medium.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4300; use the surrounding log entries to confirm it.","resolution":"1. Record where 4300 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_MEDIA.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4300 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The media identifier does not represent a valid medium.\n\nLookup forms: 4300, 0x10CC, error 4300, ERROR_INVALID_MEDIA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4300"]},{"id":1238,"title":"ERROR_INVALID_LIBRARY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4301","0x10CD","error 4301","ERROR_INVALID_LIBRARY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","library","the","identifier","does","not","represent","valid"],"errorCode":"4301","eventId":"","severity":"Low","summary":"The library identifier does not represent a valid library.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4301; use the surrounding log entries to confirm it.","resolution":"1. Record where 4301 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_LIBRARY.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4301 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The library identifier does not represent a valid library.\n\nLookup forms: 4301, 0x10CD, error 4301, ERROR_INVALID_LIBRARY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4301"]},{"id":1239,"title":"ERROR_INVALID_MEDIA_POOL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4302","0x10CE","error 4302","ERROR_INVALID_MEDIA_POOL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","media","pool","the","identifier","does","not","represent","valid"],"errorCode":"4302","eventId":"","severity":"Low","summary":"The media pool identifier does not represent a valid media pool.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4302; use the surrounding log entries to confirm it.","resolution":"1. Record where 4302 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_MEDIA_POOL.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4302 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The media pool identifier does not represent a valid media pool.\n\nLookup forms: 4302, 0x10CE, error 4302, ERROR_INVALID_MEDIA_POOL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4302"]},{"id":1240,"title":"ERROR_DRIVE_MEDIA_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4303","0x10CF","error 4303","ERROR_DRIVE_MEDIA_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","drive","media","mismatch","the","and","medium","are","not","compatible","exist","different","libraries"],"errorCode":"4303","eventId":"","severity":"Low","summary":"The drive and medium are not compatible or exist in different libraries.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 4303; use the surrounding log entries to confirm it.","resolution":"1. Record where 4303 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DRIVE_MEDIA_MISMATCH.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4303 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The drive and medium are not compatible or exist in different libraries.\n\nLookup forms: 4303, 0x10CF, error 4303, ERROR_DRIVE_MEDIA_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4303"]},{"id":1241,"title":"ERROR_MEDIA_OFFLINE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4304","0x10D0","error 4304","ERROR_MEDIA_OFFLINE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","media","offline","the","medium","currently","exists","library","and","must","online","perform","this","operation"],"errorCode":"4304","eventId":"","severity":"Low","summary":"The medium currently exists in an offline library and must be online to perform this operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4304; use the surrounding log entries to confirm it.","resolution":"1. Record where 4304 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MEDIA_OFFLINE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4304 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The medium currently exists in an offline library and must be online to perform this operation.\n\nLookup forms: 4304, 0x10D0, error 4304, ERROR_MEDIA_OFFLINE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4304"]},{"id":1242,"title":"ERROR_LIBRARY_OFFLINE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4305","0x10D1","error 4305","ERROR_LIBRARY_OFFLINE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","library","offline","the","operation","cannot","performed"],"errorCode":"4305","eventId":"","severity":"Medium","summary":"The operation cannot be performed on an offline library.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4305; use the surrounding log entries to confirm it.","resolution":"1. Record where 4305 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LIBRARY_OFFLINE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4305 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation cannot be performed on an offline library.\n\nLookup forms: 4305, 0x10D1, error 4305, ERROR_LIBRARY_OFFLINE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4305"]},{"id":1243,"title":"ERROR_EMPTY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4306","0x10D2","error 4306","ERROR_EMPTY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","empty","the","library","drive","media","pool"],"errorCode":"4306","eventId":"","severity":"Low","summary":"The library, drive, or media pool is empty.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 4306; use the surrounding log entries to confirm it.","resolution":"1. Record where 4306 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EMPTY.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4306 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The library, drive, or media pool is empty.\n\nLookup forms: 4306, 0x10D2, error 4306, ERROR_EMPTY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4306"]},{"id":1244,"title":"ERROR_NOT_EMPTY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4307","0x10D3","error 4307","ERROR_NOT_EMPTY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","not","empty","the","library","drive","media","pool","must","perform","this","operation"],"errorCode":"4307","eventId":"","severity":"Low","summary":"The library, drive, or media pool must be empty to perform this operation.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 4307; use the surrounding log entries to confirm it.","resolution":"1. Record where 4307 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_EMPTY.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4307 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The library, drive, or media pool must be empty to perform this operation.\n\nLookup forms: 4307, 0x10D3, error 4307, ERROR_NOT_EMPTY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4307"]},{"id":1245,"title":"ERROR_MEDIA_UNAVAILABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4308","0x10D4","error 4308","ERROR_MEDIA_UNAVAILABLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","media","unavailable","currently","available","this","pool","library"],"errorCode":"4308","eventId":"","severity":"Low","summary":"No media is currently available in this media pool or library.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4308; use the surrounding log entries to confirm it.","resolution":"1. Record where 4308 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MEDIA_UNAVAILABLE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4308 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No media is currently available in this media pool or library.\n\nLookup forms: 4308, 0x10D4, error 4308, ERROR_MEDIA_UNAVAILABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4308"]},{"id":1246,"title":"ERROR_RESOURCE_DISABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4309","0x10D5","error 4309","ERROR_RESOURCE_DISABLED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","resource","disabled","required","for","this","operation"],"errorCode":"4309","eventId":"","severity":"Low","summary":"A resource required for this operation is disabled.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4309; use the surrounding log entries to confirm it.","resolution":"1. Record where 4309 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESOURCE_DISABLED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4309 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A resource required for this operation is disabled.\n\nLookup forms: 4309, 0x10D5, error 4309, ERROR_RESOURCE_DISABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4309"]},{"id":1247,"title":"ERROR_INVALID_CLEANER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4310","0x10D6","error 4310","ERROR_INVALID_CLEANER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","cleaner","the","media","identifier","does","not","represent","valid"],"errorCode":"4310","eventId":"","severity":"Low","summary":"The media identifier does not represent a valid cleaner.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4310; use the surrounding log entries to confirm it.","resolution":"1. Record where 4310 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_CLEANER.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4310 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The media identifier does not represent a valid cleaner.\n\nLookup forms: 4310, 0x10D6, error 4310, ERROR_INVALID_CLEANER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4310"]},{"id":1248,"title":"ERROR_UNABLE_TO_CLEAN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4311","0x10D7","error 4311","ERROR_UNABLE_TO_CLEAN","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","unable","clean","the","drive","cannot","cleaned","does","not","support","cleaning"],"errorCode":"4311","eventId":"","severity":"Medium","summary":"The drive cannot be cleaned or does not support cleaning.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 4311; use the surrounding log entries to confirm it.","resolution":"1. Record where 4311 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNABLE_TO_CLEAN.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4311 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The drive cannot be cleaned or does not support cleaning.\n\nLookup forms: 4311, 0x10D7, error 4311, ERROR_UNABLE_TO_CLEAN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4311"]},{"id":1249,"title":"ERROR_OBJECT_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4312","0x10D8","error 4312","ERROR_OBJECT_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","object","not","found","the","identifier","does","represent","valid"],"errorCode":"4312","eventId":"","severity":"Low","summary":"The object identifier does not represent a valid object.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4312; use the surrounding log entries to confirm it.","resolution":"1. Record where 4312 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_OBJECT_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4312 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The object identifier does not represent a valid object.\n\nLookup forms: 4312, 0x10D8, error 4312, ERROR_OBJECT_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4312"]},{"id":1250,"title":"ERROR_DATABASE_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4313","0x10D9","error 4313","ERROR_DATABASE_FAILURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","database","failure","unable","read","from","write","the"],"errorCode":"4313","eventId":"","severity":"Medium","summary":"Unable to read from or write to the database.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4313; use the surrounding log entries to confirm it.","resolution":"1. Record where 4313 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DATABASE_FAILURE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4313 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to read from or write to the database.\n\nLookup forms: 4313, 0x10D9, error 4313, ERROR_DATABASE_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4313"]},{"id":1251,"title":"ERROR_DATABASE_FULL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4314","0x10DA","error 4314","ERROR_DATABASE_FULL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","database","full","the"],"errorCode":"4314","eventId":"","severity":"Low","summary":"The database is full.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4314; use the surrounding log entries to confirm it.","resolution":"1. Record where 4314 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DATABASE_FULL.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4314 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The database is full.\n\nLookup forms: 4314, 0x10DA, error 4314, ERROR_DATABASE_FULL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4314"]},{"id":1252,"title":"ERROR_MEDIA_INCOMPATIBLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4315","0x10DB","error 4315","ERROR_MEDIA_INCOMPATIBLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","media","incompatible","the","medium","not","compatible","with","device","pool"],"errorCode":"4315","eventId":"","severity":"Low","summary":"The medium is not compatible with the device or media pool.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4315; use the surrounding log entries to confirm it.","resolution":"1. Record where 4315 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MEDIA_INCOMPATIBLE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4315 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The medium is not compatible with the device or media pool.\n\nLookup forms: 4315, 0x10DB, error 4315, ERROR_MEDIA_INCOMPATIBLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4315"]},{"id":1253,"title":"ERROR_RESOURCE_NOT_PRESENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4316","0x10DC","error 4316","ERROR_RESOURCE_NOT_PRESENT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","resource","not","present","the","required","for","this","operation","does","exist"],"errorCode":"4316","eventId":"","severity":"Low","summary":"The resource required for this operation does not exist.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4316; use the surrounding log entries to confirm it.","resolution":"1. Record where 4316 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESOURCE_NOT_PRESENT.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4316 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The resource required for this operation does not exist.\n\nLookup forms: 4316, 0x10DC, error 4316, ERROR_RESOURCE_NOT_PRESENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4316"]},{"id":1254,"title":"ERROR_INVALID_OPERATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4317","0x10DD","error 4317","ERROR_INVALID_OPERATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","operation","the","identifier","not","valid"],"errorCode":"4317","eventId":"","severity":"Low","summary":"The operation identifier is not valid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4317; use the surrounding log entries to confirm it.","resolution":"1. Record where 4317 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_OPERATION.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4317 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation identifier is not valid.\n\nLookup forms: 4317, 0x10DD, error 4317, ERROR_INVALID_OPERATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4317"]},{"id":1255,"title":"ERROR_MEDIA_NOT_AVAILABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4318","0x10DE","error 4318","ERROR_MEDIA_NOT_AVAILABLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","media","not","available","the","mounted","ready","for","use"],"errorCode":"4318","eventId":"","severity":"Low","summary":"The media is not mounted or ready for use.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4318; use the surrounding log entries to confirm it.","resolution":"1. Record where 4318 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MEDIA_NOT_AVAILABLE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4318 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The media is not mounted or ready for use.\n\nLookup forms: 4318, 0x10DE, error 4318, ERROR_MEDIA_NOT_AVAILABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4318"]},{"id":1256,"title":"ERROR_DEVICE_NOT_AVAILABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4319","0x10DF","error 4319","ERROR_DEVICE_NOT_AVAILABLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","device","not","available","the","ready","for","use"],"errorCode":"4319","eventId":"","severity":"Low","summary":"The device is not ready for use.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4319; use the surrounding log entries to confirm it.","resolution":"1. Record where 4319 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEVICE_NOT_AVAILABLE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4319 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The device is not ready for use.\n\nLookup forms: 4319, 0x10DF, error 4319, ERROR_DEVICE_NOT_AVAILABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4319"]},{"id":1257,"title":"ERROR_REQUEST_REFUSED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4320","0x10E0","error 4320","ERROR_REQUEST_REFUSED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","request","refused","the","operator","administrator","has"],"errorCode":"4320","eventId":"","severity":"Low","summary":"The operator or administrator has refused the request.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4320; use the surrounding log entries to confirm it.","resolution":"1. Record where 4320 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REQUEST_REFUSED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4320 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operator or administrator has refused the request.\n\nLookup forms: 4320, 0x10E0, error 4320, ERROR_REQUEST_REFUSED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4320"]},{"id":1258,"title":"ERROR_INVALID_DRIVE_OBJECT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4321","0x10E1","error 4321","ERROR_INVALID_DRIVE_OBJECT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","invalid","drive","object","the","identifier","does","not","represent","valid"],"errorCode":"4321","eventId":"","severity":"Low","summary":"The drive identifier does not represent a valid drive.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 4321; use the surrounding log entries to confirm it.","resolution":"1. Record where 4321 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_DRIVE_OBJECT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4321 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The drive identifier does not represent a valid drive.\n\nLookup forms: 4321, 0x10E1, error 4321, ERROR_INVALID_DRIVE_OBJECT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4321"]},{"id":1259,"title":"ERROR_LIBRARY_FULL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4322","0x10E2","error 4322","ERROR_LIBRARY_FULL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","library","full","slot","available","for","use"],"errorCode":"4322","eventId":"","severity":"Low","summary":"Library is full. No slot is available for use.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4322; use the surrounding log entries to confirm it.","resolution":"1. Record where 4322 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LIBRARY_FULL.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4322 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Library is full. No slot is available for use.\n\nLookup forms: 4322, 0x10E2, error 4322, ERROR_LIBRARY_FULL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4322"]},{"id":1260,"title":"ERROR_MEDIUM_NOT_ACCESSIBLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4323","0x10E3","error 4323","ERROR_MEDIUM_NOT_ACCESSIBLE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","medium","not","accessible","the","transport","cannot","access"],"errorCode":"4323","eventId":"","severity":"Medium","summary":"The transport cannot access the medium.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 4323; use the surrounding log entries to confirm it.","resolution":"1. Record where 4323 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MEDIUM_NOT_ACCESSIBLE.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4323 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The transport cannot access the medium.\n\nLookup forms: 4323, 0x10E3, error 4323, ERROR_MEDIUM_NOT_ACCESSIBLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4323"]},{"id":1261,"title":"ERROR_UNABLE_TO_LOAD_MEDIUM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4324","0x10E4","error 4324","ERROR_UNABLE_TO_LOAD_MEDIUM","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","unable","load","medium","the","into","drive"],"errorCode":"4324","eventId":"","severity":"Medium","summary":"Unable to load the medium into the drive.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 4324; use the surrounding log entries to confirm it.","resolution":"1. Record where 4324 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNABLE_TO_LOAD_MEDIUM.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4324 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to load the medium into the drive.\n\nLookup forms: 4324, 0x10E4, error 4324, ERROR_UNABLE_TO_LOAD_MEDIUM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4324"]},{"id":1262,"title":"ERROR_UNABLE_TO_INVENTORY_DRIVE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4325","0x10E5","error 4325","ERROR_UNABLE_TO_INVENTORY_DRIVE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","unable","inventory","drive","retrieve","the","status"],"errorCode":"4325","eventId":"","severity":"Medium","summary":"Unable to retrieve the drive status.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 4325; use the surrounding log entries to confirm it.","resolution":"1. Record where 4325 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNABLE_TO_INVENTORY_DRIVE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4325 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to retrieve the drive status.\n\nLookup forms: 4325, 0x10E5, error 4325, ERROR_UNABLE_TO_INVENTORY_DRIVE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Unable to retrieve status about the drive.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4325"]},{"id":1263,"title":"ERROR_UNABLE_TO_INVENTORY_SLOT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4326","0x10E6","error 4326","ERROR_UNABLE_TO_INVENTORY_SLOT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","unable","inventory","slot","retrieve","the","status"],"errorCode":"4326","eventId":"","severity":"Medium","summary":"Unable to retrieve the slot status.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4326; use the surrounding log entries to confirm it.","resolution":"1. Record where 4326 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNABLE_TO_INVENTORY_SLOT.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4326 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to retrieve the slot status.\n\nLookup forms: 4326, 0x10E6, error 4326, ERROR_UNABLE_TO_INVENTORY_SLOT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Unable to retrieve status about the slot.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4326"]},{"id":1264,"title":"ERROR_UNABLE_TO_INVENTORY_TRANSPORT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4327","0x10E7","error 4327","ERROR_UNABLE_TO_INVENTORY_TRANSPORT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","unable","inventory","transport","retrieve","status","about","the"],"errorCode":"4327","eventId":"","severity":"Medium","summary":"Unable to retrieve status about the transport.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4327; use the surrounding log entries to confirm it.","resolution":"1. Record where 4327 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNABLE_TO_INVENTORY_TRANSPORT.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4327 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to retrieve status about the transport.\n\nLookup forms: 4327, 0x10E7, error 4327, ERROR_UNABLE_TO_INVENTORY_TRANSPORT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4327"]},{"id":1265,"title":"ERROR_TRANSPORT_FULL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4328","0x10E8","error 4328","ERROR_TRANSPORT_FULL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","transport","full","cannot","use","the","because","already"],"errorCode":"4328","eventId":"","severity":"Medium","summary":"Cannot use the transport because it is already in use.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4328; use the surrounding log entries to confirm it.","resolution":"1. Record where 4328 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSPORT_FULL.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4328 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot use the transport because it is already in use.\n\nLookup forms: 4328, 0x10E8, error 4328, ERROR_TRANSPORT_FULL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4328"]},{"id":1266,"title":"ERROR_CONTROLLING_IEPORT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4329","0x10E9","error 4329","ERROR_CONTROLLING_IEPORT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","controlling","ieport","unable","open","close","the","inject","eject","port"],"errorCode":"4329","eventId":"","severity":"Medium","summary":"Unable to open or close the inject/eject port.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4329; use the surrounding log entries to confirm it.","resolution":"1. Record where 4329 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CONTROLLING_IEPORT.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4329 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to open or close the inject/eject port.\n\nLookup forms: 4329, 0x10E9, error 4329, ERROR_CONTROLLING_IEPORT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4329"]},{"id":1267,"title":"ERROR_UNABLE_TO_EJECT_MOUNTED_MEDIA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4330","0x10EA","error 4330","ERROR_UNABLE_TO_EJECT_MOUNTED_MEDIA","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","unable","eject","mounted","media","the","medium","because","drive"],"errorCode":"4330","eventId":"","severity":"Medium","summary":"Unable to eject the medium because it is in a drive.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 4330; use the surrounding log entries to confirm it.","resolution":"1. Record where 4330 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNABLE_TO_EJECT_MOUNTED_MEDIA.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4330 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to eject the medium because it is in a drive.\n\nLookup forms: 4330, 0x10EA, error 4330, ERROR_UNABLE_TO_EJECT_MOUNTED_MEDIA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Unable to eject the media because it is in a drive.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4330"]},{"id":1268,"title":"ERROR_CLEANER_SLOT_SET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4331","0x10EB","error 4331","ERROR_CLEANER_SLOT_SET","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cleaner","slot","set","already","reserved"],"errorCode":"4331","eventId":"","severity":"Low","summary":"A cleaner slot is already reserved.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4331; use the surrounding log entries to confirm it.","resolution":"1. Record where 4331 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLEANER_SLOT_SET.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4331 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A cleaner slot is already reserved.\n\nLookup forms: 4331, 0x10EB, error 4331, ERROR_CLEANER_SLOT_SET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4331"]},{"id":1269,"title":"ERROR_CLEANER_SLOT_NOT_SET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4332","0x10EC","error 4332","ERROR_CLEANER_SLOT_NOT_SET","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cleaner","slot","not","set","reserved"],"errorCode":"4332","eventId":"","severity":"Low","summary":"A cleaner slot is not reserved.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4332; use the surrounding log entries to confirm it.","resolution":"1. Record where 4332 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLEANER_SLOT_NOT_SET.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4332 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A cleaner slot is not reserved.\n\nLookup forms: 4332, 0x10EC, error 4332, ERROR_CLEANER_SLOT_NOT_SET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4332"]},{"id":1270,"title":"ERROR_CLEANER_CARTRIDGE_SPENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4333","0x10ED","error 4333","ERROR_CLEANER_CARTRIDGE_SPENT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","cleaner","cartridge","spent","the","has","performed","maximum","number","drive","cleanings"],"errorCode":"4333","eventId":"","severity":"Low","summary":"The cleaner cartridge has performed the maximum number of drive cleanings.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 4333; use the surrounding log entries to confirm it.","resolution":"1. Record where 4333 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLEANER_CARTRIDGE_SPENT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4333 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cleaner cartridge has performed the maximum number of drive cleanings.\n\nLookup forms: 4333, 0x10ED, error 4333, ERROR_CLEANER_CARTRIDGE_SPENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4333"]},{"id":1271,"title":"ERROR_UNEXPECTED_OMID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4334","0x10EE","error 4334","ERROR_UNEXPECTED_OMID","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","unexpected","omid","medium","identifier"],"errorCode":"4334","eventId":"","severity":"Low","summary":"Unexpected on-medium identifier.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4334; use the surrounding log entries to confirm it.","resolution":"1. Record where 4334 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNEXPECTED_OMID.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4334 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unexpected on-medium identifier.\n\nLookup forms: 4334, 0x10EE, error 4334, ERROR_UNEXPECTED_OMID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4334"]},{"id":1272,"title":"ERROR_CANT_DELETE_LAST_ITEM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4335","0x10EF","error 4335","ERROR_CANT_DELETE_LAST_ITEM","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","delete","last","item","the","remaining","this","group","resource","cannot","deleted"],"errorCode":"4335","eventId":"","severity":"Medium","summary":"The last remaining item in this group or resource cannot be deleted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4335; use the surrounding log entries to confirm it.","resolution":"1. Record where 4335 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANT_DELETE_LAST_ITEM.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4335 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The last remaining item in this group or resource cannot be deleted.\n\nLookup forms: 4335, 0x10EF, error 4335, ERROR_CANT_DELETE_LAST_ITEM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4335"]},{"id":1273,"title":"ERROR_MESSAGE_EXCEEDS_MAX_SIZE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4336","0x10F0","error 4336","ERROR_MESSAGE_EXCEEDS_MAX_SIZE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","message","exceeds","max","size","the","provided","maximum","allowed","for","this","parameter"],"errorCode":"4336","eventId":"","severity":"Low","summary":"The message provided exceeds the maximum size allowed for this parameter.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4336; use the surrounding log entries to confirm it.","resolution":"1. Record where 4336 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MESSAGE_EXCEEDS_MAX_SIZE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4336 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The message provided exceeds the maximum size allowed for this parameter.\n\nLookup forms: 4336, 0x10F0, error 4336, ERROR_MESSAGE_EXCEEDS_MAX_SIZE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4336"]},{"id":1274,"title":"ERROR_VOLUME_CONTAINS_SYS_FILES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4337","0x10F1","error 4337","ERROR_VOLUME_CONTAINS_SYS_FILES","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","volume","contains","sys","files","the","system","paging"],"errorCode":"4337","eventId":"","severity":"Low","summary":"The volume contains system or paging files.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 4337; use the surrounding log entries to confirm it.","resolution":"1. Record where 4337 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_VOLUME_CONTAINS_SYS_FILES.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4337 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The volume contains system or paging files.\n\nLookup forms: 4337, 0x10F1, error 4337, ERROR_VOLUME_CONTAINS_SYS_FILES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4337"]},{"id":1275,"title":"ERROR_INDIGENOUS_TYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4338","0x10F2","error 4338","ERROR_INDIGENOUS_TYPE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","indigenous","type","the","media","cannot","removed","from","this","library","since","least","one","drive","reports","can","support"],"errorCode":"4338","eventId":"","severity":"Medium","summary":"The media type cannot be removed from this library since at least one drive in the library reports it can support this media type.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 4338; use the surrounding log entries to confirm it.","resolution":"1. Record where 4338 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INDIGENOUS_TYPE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4338 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The media type cannot be removed from this library since at least one drive in the library reports it can support this media type.\n\nLookup forms: 4338, 0x10F2, error 4338, ERROR_INDIGENOUS_TYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4338"]},{"id":1276,"title":"ERROR_NO_SUPPORTING_DRIVES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4339","0x10F3","error 4339","ERROR_NO_SUPPORTING_DRIVES","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","supporting","drives","this","offline","media","cannot","mounted","system","since","enabled","are","present","which","can","used"],"errorCode":"4339","eventId":"","severity":"Medium","summary":"This offline media cannot be mounted on this system since no enabled drives are present which can be used.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 4339; use the surrounding log entries to confirm it.","resolution":"1. Record where 4339 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_SUPPORTING_DRIVES.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4339 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This offline media cannot be mounted on this system since no enabled drives are present which can be used.\n\nLookup forms: 4339, 0x10F3, error 4339, ERROR_NO_SUPPORTING_DRIVES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4339"]},{"id":1277,"title":"ERROR_CLEANER_CARTRIDGE_INSTALLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4340","0x10F4","error 4340","ERROR_CLEANER_CARTRIDGE_INSTALLED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cleaner","cartridge","installed","present","the","tape","library"],"errorCode":"4340","eventId":"","severity":"Low","summary":"A cleaner cartridge is present in the tape library.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4340; use the surrounding log entries to confirm it.","resolution":"1. Record where 4340 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLEANER_CARTRIDGE_INSTALLED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4340 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A cleaner cartridge is present in the tape library.\n\nLookup forms: 4340, 0x10F4, error 4340, ERROR_CLEANER_CARTRIDGE_INSTALLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4340"]},{"id":1278,"title":"ERROR_IEPORT_FULL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4341","0x10F5","error 4341","ERROR_IEPORT_FULL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ieport","full","cannot","use","the","inject","eject","port","because","not","empty"],"errorCode":"4341","eventId":"","severity":"Medium","summary":"Cannot use the inject/eject port because it is not empty.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4341; use the surrounding log entries to confirm it.","resolution":"1. Record where 4341 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IEPORT_FULL.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4341 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot use the inject/eject port because it is not empty.\n\nLookup forms: 4341, 0x10F5, error 4341, ERROR_IEPORT_FULL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4341"]},{"id":1279,"title":"ERROR_FILE_OFFLINE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4350","0x10FE","error 4350","ERROR_FILE_OFFLINE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","file","offline","this","currently","not","available","for","use","computer"],"errorCode":"4350","eventId":"","severity":"Low","summary":"This file is currently not available for use on this computer.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 4350; use the surrounding log entries to confirm it.","resolution":"1. Record where 4350 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FILE_OFFLINE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4350 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This file is currently not available for use on this computer.\n\nLookup forms: 4350, 0x10FE, error 4350, ERROR_FILE_OFFLINE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The remote storage service was not able to recall the file.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4350"]},{"id":1280,"title":"ERROR_REMOTE_STORAGE_NOT_ACTIVE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4351","0x10FF","error 4351","ERROR_REMOTE_STORAGE_NOT_ACTIVE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","remote","storage","not","active","the","service","operational","this","time"],"errorCode":"4351","eventId":"","severity":"Low","summary":"The remote storage service is not operational at this time.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 4351; use the surrounding log entries to confirm it.","resolution":"1. Record where 4351 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review the response body, request permissions, rate limits, and service health before retrying.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REMOTE_STORAGE_NOT_ACTIVE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4351 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The remote storage service is not operational at this time.\n\nLookup forms: 4351, 0x10FF, error 4351, ERROR_REMOTE_STORAGE_NOT_ACTIVE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4351"]},{"id":1281,"title":"ERROR_REMOTE_STORAGE_MEDIA_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4352","0x1100","error 4352","ERROR_REMOTE_STORAGE_MEDIA_ERROR","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","remote","storage","media","the","service","encountered"],"errorCode":"4352","eventId":"","severity":"Low","summary":"The remote storage service encountered a media error.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 4352; use the surrounding log entries to confirm it.","resolution":"1. Record where 4352 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review the response body, request permissions, rate limits, and service health before retrying.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REMOTE_STORAGE_MEDIA_ERROR.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4352 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The remote storage service encountered a media error.\n\nLookup forms: 4352, 0x1100, error 4352, ERROR_REMOTE_STORAGE_MEDIA_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4352"]},{"id":1282,"title":"ERROR_NOT_A_REPARSE_POINT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4390","0x1126","error 4390","ERROR_NOT_A_REPARSE_POINT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","not","reparse","point","the","file","directory"],"errorCode":"4390","eventId":"","severity":"Low","summary":"The file or directory is not a reparse point.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 4390; use the surrounding log entries to confirm it.","resolution":"1. Record where 4390 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_A_REPARSE_POINT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4390 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file or directory is not a reparse point.\n\nLookup forms: 4390, 0x1126, error 4390, ERROR_NOT_A_REPARSE_POINT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4390"]},{"id":1283,"title":"ERROR_REPARSE_ATTRIBUTE_CONFLICT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4391","0x1127","error 4391","ERROR_REPARSE_ATTRIBUTE_CONFLICT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","reparse","attribute","conflict","the","point","cannot","set","because","conflicts","with","existing"],"errorCode":"4391","eventId":"","severity":"Medium","summary":"The reparse point attribute cannot be set because it conflicts with an existing attribute.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4391; use the surrounding log entries to confirm it.","resolution":"1. Record where 4391 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REPARSE_ATTRIBUTE_CONFLICT.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4391 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The reparse point attribute cannot be set because it conflicts with an existing attribute.\n\nLookup forms: 4391, 0x1127, error 4391, ERROR_REPARSE_ATTRIBUTE_CONFLICT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4391"]},{"id":1284,"title":"ERROR_INVALID_REPARSE_DATA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4392","0x1128","error 4392","ERROR_INVALID_REPARSE_DATA","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","invalid","reparse","data","the","present","point","buffer"],"errorCode":"4392","eventId":"","severity":"Medium","summary":"The data present in the reparse point buffer is invalid.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 4392; use the surrounding log entries to confirm it.","resolution":"1. Record where 4392 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_REPARSE_DATA.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4392 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The data present in the reparse point buffer is invalid.\n\nLookup forms: 4392, 0x1128, error 4392, ERROR_INVALID_REPARSE_DATA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4392"]},{"id":1285,"title":"ERROR_REPARSE_TAG_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4393","0x1129","error 4393","ERROR_REPARSE_TAG_INVALID","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","reparse","tag","invalid","the","present","point","buffer"],"errorCode":"4393","eventId":"","severity":"Medium","summary":"The tag present in the reparse point buffer is invalid.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 4393; use the surrounding log entries to confirm it.","resolution":"1. Record where 4393 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REPARSE_TAG_INVALID.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4393 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The tag present in the reparse point buffer is invalid.\n\nLookup forms: 4393, 0x1129, error 4393, ERROR_REPARSE_TAG_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4393"]},{"id":1286,"title":"ERROR_REPARSE_TAG_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4394","0x112A","error 4394","ERROR_REPARSE_TAG_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","reparse","tag","mismatch","there","between","the","specified","request","and","present","point"],"errorCode":"4394","eventId":"","severity":"Low","summary":"There is a mismatch between the tag specified in the request and the tag present in the reparse point.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4394; use the surrounding log entries to confirm it.","resolution":"1. Record where 4394 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REPARSE_TAG_MISMATCH.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4394 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There is a mismatch between the tag specified in the request and the tag present in the reparse point.\n\nLookup forms: 4394, 0x112A, error 4394, ERROR_REPARSE_TAG_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4394"]},{"id":1287,"title":"ERROR_APP_DATA_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4400","0x1130","error 4400","ERROR_APP_DATA_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","app","data","not","found","fast","cache"],"errorCode":"4400","eventId":"","severity":"Medium","summary":"Fast Cache data not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4400; use the surrounding log entries to confirm it.","resolution":"1. Record where 4400 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_APP_DATA_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4400 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Fast Cache data not found.\n\nLookup forms: 4400, 0x1130, error 4400, ERROR_APP_DATA_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4400"]},{"id":1288,"title":"ERROR_APP_DATA_EXPIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4401","0x1131","error 4401","ERROR_APP_DATA_EXPIRED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","app","data","expired","fast","cache"],"errorCode":"4401","eventId":"","severity":"Low","summary":"Fast Cache data expired.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4401; use the surrounding log entries to confirm it.","resolution":"1. Record where 4401 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_APP_DATA_EXPIRED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4401 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Fast Cache data expired.\n\nLookup forms: 4401, 0x1131, error 4401, ERROR_APP_DATA_EXPIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4401"]},{"id":1289,"title":"ERROR_APP_DATA_CORRUPT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4402","0x1132","error 4402","ERROR_APP_DATA_CORRUPT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","app","data","corrupt","fast","cache"],"errorCode":"4402","eventId":"","severity":"Critical","summary":"Fast Cache data corrupt.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4402; use the surrounding log entries to confirm it.","resolution":"1. Record where 4402 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_APP_DATA_CORRUPT.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4402 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Fast Cache data corrupt.\n\nLookup forms: 4402, 0x1132, error 4402, ERROR_APP_DATA_CORRUPT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4402"]},{"id":1290,"title":"ERROR_APP_DATA_LIMIT_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4403","0x1133","error 4403","ERROR_APP_DATA_LIMIT_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","app","data","limit","exceeded","fast","cache","has","its","max","size","and","cannot","updated"],"errorCode":"4403","eventId":"","severity":"Medium","summary":"Fast Cache data has exceeded its max size and cannot be updated.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 4403; use the surrounding log entries to confirm it.","resolution":"1. Record where 4403 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_APP_DATA_LIMIT_EXCEEDED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4403 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Fast Cache data has exceeded its max size and cannot be updated.\n\nLookup forms: 4403, 0x1133, error 4403, ERROR_APP_DATA_LIMIT_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4403"]},{"id":1291,"title":"ERROR_APP_DATA_REBOOT_REQUIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4404","0x1134","error 4404","ERROR_APP_DATA_REBOOT_REQUIRED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","app","data","reboot","required","fast","cache","has","been","rearmed","and","requires","until","can","updated"],"errorCode":"4404","eventId":"","severity":"Low","summary":"Fast Cache has been ReArmed and requires a reboot until it can be updated.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 4404; use the surrounding log entries to confirm it.","resolution":"1. Record where 4404 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_APP_DATA_REBOOT_REQUIRED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4404 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Fast Cache has been ReArmed and requires a reboot until it can be updated.\n\nLookup forms: 4404, 0x1134, error 4404, ERROR_APP_DATA_REBOOT_REQUIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4404"]},{"id":1292,"title":"ERROR_SECUREBOOT_ROLLBACK_DETECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4420","0x1144","error 4420","ERROR_SECUREBOOT_ROLLBACK_DETECTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","secureboot","rollback","detected","secure","boot","that","protected","data","has","been","attempted"],"errorCode":"4420","eventId":"","severity":"Low","summary":"Secure Boot detected that rollback of protected data has been attempted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4420; use the surrounding log entries to confirm it.","resolution":"1. Record where 4420 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SECUREBOOT_ROLLBACK_DETECTED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4420 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Secure Boot detected that rollback of protected data has been attempted.\n\nLookup forms: 4420, 0x1144, error 4420, ERROR_SECUREBOOT_ROLLBACK_DETECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4420"]},{"id":1293,"title":"ERROR_SECUREBOOT_POLICY_VIOLATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4421","0x1145","error 4421","ERROR_SECUREBOOT_POLICY_VIOLATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","secureboot","policy","violation","the","value","protected","secure","boot","and","cannot","modified","deleted"],"errorCode":"4421","eventId":"","severity":"Medium","summary":"The value is protected by Secure Boot policy and cannot be modified or deleted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4421; use the surrounding log entries to confirm it.","resolution":"1. Record where 4421 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SECUREBOOT_POLICY_VIOLATION.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4421 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The value is protected by Secure Boot policy and cannot be modified or deleted.\n\nLookup forms: 4421, 0x1145, error 4421, ERROR_SECUREBOOT_POLICY_VIOLATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4421"]},{"id":1294,"title":"ERROR_SECUREBOOT_INVALID_POLICY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4422","0x1146","error 4422","ERROR_SECUREBOOT_INVALID_POLICY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","secureboot","invalid","policy","the","secure","boot"],"errorCode":"4422","eventId":"","severity":"Medium","summary":"The Secure Boot policy is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4422; use the surrounding log entries to confirm it.","resolution":"1. Record where 4422 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SECUREBOOT_INVALID_POLICY.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4422 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Secure Boot policy is invalid.\n\nLookup forms: 4422, 0x1146, error 4422, ERROR_SECUREBOOT_INVALID_POLICY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4422"]},{"id":1295,"title":"ERROR_SECUREBOOT_POLICY_PUBLISHER_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4423","0x1147","error 4423","ERROR_SECUREBOOT_POLICY_PUBLISHER_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","secureboot","policy","publisher","not","found","new","secure","boot","did","contain","the","current","its","update","list"],"errorCode":"4423","eventId":"","severity":"Low","summary":"A new Secure Boot policy did not contain the current publisher on its update list.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 4423; use the surrounding log entries to confirm it.","resolution":"1. Record where 4423 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SECUREBOOT_POLICY_PUBLISHER_NOT_FOUND.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4423 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A new Secure Boot policy did not contain the current publisher on its update list.\n\nLookup forms: 4423, 0x1147, error 4423, ERROR_SECUREBOOT_POLICY_PUBLISHER_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4423"]},{"id":1296,"title":"ERROR_SECUREBOOT_POLICY_NOT_SIGNED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4424","0x1148","error 4424","ERROR_SECUREBOOT_POLICY_NOT_SIGNED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","secureboot","policy","not","signed","the","secure","boot","either","non","trusted","signer"],"errorCode":"4424","eventId":"","severity":"Low","summary":"The Secure Boot policy is either not signed or is signed by a non-trusted signer.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4424; use the surrounding log entries to confirm it.","resolution":"1. Record where 4424 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SECUREBOOT_POLICY_NOT_SIGNED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4424 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Secure Boot policy is either not signed or is signed by a non-trusted signer.\n\nLookup forms: 4424, 0x1148, error 4424, ERROR_SECUREBOOT_POLICY_NOT_SIGNED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4424"]},{"id":1297,"title":"ERROR_SECUREBOOT_NOT_ENABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4425","0x1149","error 4425","ERROR_SECUREBOOT_NOT_ENABLED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","secureboot","not","enabled","secure","boot","this","machine"],"errorCode":"4425","eventId":"","severity":"Low","summary":"Secure Boot is not enabled on this machine.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4425; use the surrounding log entries to confirm it.","resolution":"1. Record where 4425 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SECUREBOOT_NOT_ENABLED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4425 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Secure Boot is not enabled on this machine.\n\nLookup forms: 4425, 0x1149, error 4425, ERROR_SECUREBOOT_NOT_ENABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4425"]},{"id":1298,"title":"ERROR_SECUREBOOT_FILE_REPLACED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4426","0x114A","error 4426","ERROR_SECUREBOOT_FILE_REPLACED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","secureboot","file","replaced","secure","boot","requires","that","certain","files","and","drivers","are","not","other"],"errorCode":"4426","eventId":"","severity":"Low","summary":"Secure Boot requires that certain files and drivers are not replaced by other files or drivers.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 4426; use the surrounding log entries to confirm it.","resolution":"1. Record where 4426 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SECUREBOOT_FILE_REPLACED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4426 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Secure Boot requires that certain files and drivers are not replaced by other files or drivers.\n\nLookup forms: 4426, 0x114A, error 4426, ERROR_SECUREBOOT_FILE_REPLACED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4426"]},{"id":1299,"title":"ERROR_OFFLOAD_READ_FLT_NOT_SUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4440","0x1158","error 4440","ERROR_OFFLOAD_READ_FLT_NOT_SUPPORTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","offload","read","flt","not","supported","the","copy","operation","filter"],"errorCode":"4440","eventId":"","severity":"Medium","summary":"The copy offload read operation is not supported by a filter.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4440; use the surrounding log entries to confirm it.","resolution":"1. Record where 4440 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_OFFLOAD_READ_FLT_NOT_SUPPORTED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4440 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The copy offload read operation is not supported by a filter.\n\nLookup forms: 4440, 0x1158, error 4440, ERROR_OFFLOAD_READ_FLT_NOT_SUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4440"]},{"id":1300,"title":"ERROR_OFFLOAD_WRITE_FLT_NOT_SUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4441","0x1159","error 4441","ERROR_OFFLOAD_WRITE_FLT_NOT_SUPPORTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","offload","write","flt","not","supported","the","copy","operation","filter"],"errorCode":"4441","eventId":"","severity":"Medium","summary":"The copy offload write operation is not supported by a filter.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 4441; use the surrounding log entries to confirm it.","resolution":"1. Record where 4441 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_OFFLOAD_WRITE_FLT_NOT_SUPPORTED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4441 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The copy offload write operation is not supported by a filter.\n\nLookup forms: 4441, 0x1159, error 4441, ERROR_OFFLOAD_WRITE_FLT_NOT_SUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4441"]},{"id":1301,"title":"ERROR_OFFLOAD_READ_FILE_NOT_SUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4442","0x115A","error 4442","ERROR_OFFLOAD_READ_FILE_NOT_SUPPORTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","offload","read","file","not","supported","the","copy","operation","for"],"errorCode":"4442","eventId":"","severity":"Medium","summary":"The copy offload read operation is not supported for the file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 4442; use the surrounding log entries to confirm it.","resolution":"1. Record where 4442 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_OFFLOAD_READ_FILE_NOT_SUPPORTED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4442 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The copy offload read operation is not supported for the file.\n\nLookup forms: 4442, 0x115A, error 4442, ERROR_OFFLOAD_READ_FILE_NOT_SUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4442"]},{"id":1302,"title":"ERROR_OFFLOAD_WRITE_FILE_NOT_SUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4443","0x115B","error 4443","ERROR_OFFLOAD_WRITE_FILE_NOT_SUPPORTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","offload","write","file","not","supported","the","copy","operation","for"],"errorCode":"4443","eventId":"","severity":"Medium","summary":"The copy offload write operation is not supported for the file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 4443; use the surrounding log entries to confirm it.","resolution":"1. Record where 4443 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_OFFLOAD_WRITE_FILE_NOT_SUPPORTED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4443 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The copy offload write operation is not supported for the file.\n\nLookup forms: 4443, 0x115B, error 4443, ERROR_OFFLOAD_WRITE_FILE_NOT_SUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4443"]},{"id":1303,"title":"ERROR_VOLUME_NOT_SIS_ENABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["4500","0x1194","error 4500","ERROR_VOLUME_NOT_SIS_ENABLED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","volume","not","sis","enabled","single","instance","storage","available","this"],"errorCode":"4500","eventId":"","severity":"Low","summary":"Single Instance Storage is not available on this volume.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 4500; use the surrounding log entries to confirm it.","resolution":"1. Record where 4500 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_VOLUME_NOT_SIS_ENABLED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 4500 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Single Instance Storage is not available on this volume.\n\nLookup forms: 4500, 0x1194, error 4500, ERROR_VOLUME_NOT_SIS_ENABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["4500"]},{"id":1304,"title":"ERROR_DEPENDENT_RESOURCE_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5001","0x1389","error 5001","ERROR_DEPENDENT_RESOURCE_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dependent","resource","exists","the","operation","cannot","completed","because","other","resources","are","this"],"errorCode":"5001","eventId":"","severity":"Medium","summary":"The operation cannot be completed because other resources are dependent on this resource.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5001; use the surrounding log entries to confirm it.","resolution":"1. Record where 5001 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEPENDENT_RESOURCE_EXISTS.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5001 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation cannot be completed because other resources are dependent on this resource.\n\nLookup forms: 5001, 0x1389, error 5001, ERROR_DEPENDENT_RESOURCE_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The cluster resource cannot be moved to another group because other resources are dependent on it.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5001"]},{"id":1305,"title":"ERROR_DEPENDENCY_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5002","0x138A","error 5002","ERROR_DEPENDENCY_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dependency","not","found","the","cluster","resource","cannot"],"errorCode":"5002","eventId":"","severity":"Medium","summary":"The cluster resource dependency cannot be found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5002; use the surrounding log entries to confirm it.","resolution":"1. Record where 5002 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEPENDENCY_NOT_FOUND.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5002 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster resource dependency cannot be found.\n\nLookup forms: 5002, 0x138A, error 5002, ERROR_DEPENDENCY_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5002"]},{"id":1306,"title":"ERROR_DEPENDENCY_ALREADY_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5003","0x138B","error 5003","ERROR_DEPENDENCY_ALREADY_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dependency","already","exists","the","cluster","resource","cannot","made","dependent","specified","because"],"errorCode":"5003","eventId":"","severity":"Medium","summary":"The cluster resource cannot be made dependent on the specified resource because it is already dependent.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5003; use the surrounding log entries to confirm it.","resolution":"1. Record where 5003 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEPENDENCY_ALREADY_EXISTS.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5003 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster resource cannot be made dependent on the specified resource because it is already dependent.\n\nLookup forms: 5003, 0x138B, error 5003, ERROR_DEPENDENCY_ALREADY_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5003"]},{"id":1307,"title":"ERROR_RESOURCE_NOT_ONLINE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5004","0x138C","error 5004","ERROR_RESOURCE_NOT_ONLINE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","resource","not","online","the","cluster"],"errorCode":"5004","eventId":"","severity":"Low","summary":"The cluster resource is not online.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5004; use the surrounding log entries to confirm it.","resolution":"1. Record where 5004 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESOURCE_NOT_ONLINE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5004 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster resource is not online.\n\nLookup forms: 5004, 0x138C, error 5004, ERROR_RESOURCE_NOT_ONLINE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5004"]},{"id":1308,"title":"ERROR_HOST_NODE_NOT_AVAILABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5005","0x138D","error 5005","ERROR_HOST_NODE_NOT_AVAILABLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","host","node","not","available","cluster","for","this","operation"],"errorCode":"5005","eventId":"","severity":"Low","summary":"A cluster node is not available for this operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5005; use the surrounding log entries to confirm it.","resolution":"1. Record where 5005 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_HOST_NODE_NOT_AVAILABLE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5005 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A cluster node is not available for this operation.\n\nLookup forms: 5005, 0x138D, error 5005, ERROR_HOST_NODE_NOT_AVAILABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5005"]},{"id":1309,"title":"ERROR_RESOURCE_NOT_AVAILABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5006","0x138E","error 5006","ERROR_RESOURCE_NOT_AVAILABLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","resource","not","available","the","cluster"],"errorCode":"5006","eventId":"","severity":"Low","summary":"The cluster resource is not available.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5006; use the surrounding log entries to confirm it.","resolution":"1. Record where 5006 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESOURCE_NOT_AVAILABLE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5006 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster resource is not available.\n\nLookup forms: 5006, 0x138E, error 5006, ERROR_RESOURCE_NOT_AVAILABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5006"]},{"id":1310,"title":"ERROR_RESOURCE_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5007","0x138F","error 5007","ERROR_RESOURCE_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","resource","not","found","the","cluster","could"],"errorCode":"5007","eventId":"","severity":"Low","summary":"The cluster resource could not be found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5007; use the surrounding log entries to confirm it.","resolution":"1. Record where 5007 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESOURCE_NOT_FOUND.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5007 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster resource could not be found.\n\nLookup forms: 5007, 0x138F, error 5007, ERROR_RESOURCE_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5007"]},{"id":1311,"title":"ERROR_SHUTDOWN_CLUSTER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5008","0x1390","error 5008","ERROR_SHUTDOWN_CLUSTER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","shutdown","cluster","the","being","shut","down"],"errorCode":"5008","eventId":"","severity":"Low","summary":"The cluster is being shut down.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5008; use the surrounding log entries to confirm it.","resolution":"1. Record where 5008 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SHUTDOWN_CLUSTER.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5008 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster is being shut down.\n\nLookup forms: 5008, 0x1390, error 5008, ERROR_SHUTDOWN_CLUSTER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5008"]},{"id":1312,"title":"ERROR_CANT_EVICT_ACTIVE_NODE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5009","0x1391","error 5009","ERROR_CANT_EVICT_ACTIVE_NODE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","evict","active","node","cluster","cannot","evicted","from","the","unless","down","last"],"errorCode":"5009","eventId":"","severity":"Medium","summary":"A cluster node cannot be evicted from the cluster unless the node is down or it is the last node.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5009; use the surrounding log entries to confirm it.","resolution":"1. Record where 5009 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANT_EVICT_ACTIVE_NODE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5009 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A cluster node cannot be evicted from the cluster unless the node is down or it is the last node.\n\nLookup forms: 5009, 0x1391, error 5009, ERROR_CANT_EVICT_ACTIVE_NODE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): A cluster node cannot be evicted from the cluster unless the node is down.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5009"]},{"id":1313,"title":"ERROR_OBJECT_ALREADY_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5010","0x1392","error 5010","ERROR_OBJECT_ALREADY_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","object","already","exists","the"],"errorCode":"5010","eventId":"","severity":"Medium","summary":"The object already exists.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5010; use the surrounding log entries to confirm it.","resolution":"1. Record where 5010 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_OBJECT_ALREADY_EXISTS.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5010 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The object already exists.\n\nLookup forms: 5010, 0x1392, error 5010, ERROR_OBJECT_ALREADY_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5010"]},{"id":1314,"title":"ERROR_OBJECT_IN_LIST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5011","0x1393","error 5011","ERROR_OBJECT_IN_LIST","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","object","list","the","already"],"errorCode":"5011","eventId":"","severity":"Low","summary":"The object is already in the list.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5011; use the surrounding log entries to confirm it.","resolution":"1. Record where 5011 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_OBJECT_IN_LIST.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5011 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The object is already in the list.\n\nLookup forms: 5011, 0x1393, error 5011, ERROR_OBJECT_IN_LIST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5011"]},{"id":1315,"title":"ERROR_GROUP_NOT_AVAILABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5012","0x1394","error 5012","ERROR_GROUP_NOT_AVAILABLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","group","not","available","the","cluster","for","any","new","requests"],"errorCode":"5012","eventId":"","severity":"Low","summary":"The cluster group is not available for any new requests.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5012; use the surrounding log entries to confirm it.","resolution":"1. Record where 5012 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_GROUP_NOT_AVAILABLE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5012 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster group is not available for any new requests.\n\nLookup forms: 5012, 0x1394, error 5012, ERROR_GROUP_NOT_AVAILABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5012"]},{"id":1316,"title":"ERROR_GROUP_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5013","0x1395","error 5013","ERROR_GROUP_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","group","not","found","the","cluster","could"],"errorCode":"5013","eventId":"","severity":"Low","summary":"The cluster group could not be found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5013; use the surrounding log entries to confirm it.","resolution":"1. Record where 5013 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_GROUP_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5013 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster group could not be found.\n\nLookup forms: 5013, 0x1395, error 5013, ERROR_GROUP_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5013"]},{"id":1317,"title":"ERROR_GROUP_NOT_ONLINE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5014","0x1396","error 5014","ERROR_GROUP_NOT_ONLINE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","group","not","online","the","operation","could","completed","because","cluster"],"errorCode":"5014","eventId":"","severity":"Low","summary":"The operation could not be completed because the cluster group is not online.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5014; use the surrounding log entries to confirm it.","resolution":"1. Record where 5014 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_GROUP_NOT_ONLINE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5014 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation could not be completed because the cluster group is not online.\n\nLookup forms: 5014, 0x1396, error 5014, ERROR_GROUP_NOT_ONLINE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5014"]},{"id":1318,"title":"ERROR_HOST_NODE_NOT_RESOURCE_OWNER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5015","0x1397","error 5015","ERROR_HOST_NODE_NOT_RESOURCE_OWNER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","host","node","not","resource","owner","the","operation","failed","because","either","specified","cluster","possible"],"errorCode":"5015","eventId":"","severity":"High","summary":"The operation failed because either the specified cluster node is not the owner of the resource, or the node is not a possible owner of the resource.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5015; use the surrounding log entries to confirm it.","resolution":"1. Record where 5015 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_HOST_NODE_NOT_RESOURCE_OWNER.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5015 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation failed because either the specified cluster node is not the owner of the resource, or the node is not a possible owner of the resource.\n\nLookup forms: 5015, 0x1397, error 5015, ERROR_HOST_NODE_NOT_RESOURCE_OWNER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The cluster node is not the owner of the resource.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5015"]},{"id":1319,"title":"ERROR_HOST_NODE_NOT_GROUP_OWNER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5016","0x1398","error 5016","ERROR_HOST_NODE_NOT_GROUP_OWNER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","host","node","not","group","owner","the","operation","failed","because","either","specified","cluster","possible"],"errorCode":"5016","eventId":"","severity":"High","summary":"The operation failed because either the specified cluster node is not the owner of the group, or the node is not a possible owner of the group.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5016; use the surrounding log entries to confirm it.","resolution":"1. Record where 5016 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_HOST_NODE_NOT_GROUP_OWNER.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5016 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation failed because either the specified cluster node is not the owner of the group, or the node is not a possible owner of the group.\n\nLookup forms: 5016, 0x1398, error 5016, ERROR_HOST_NODE_NOT_GROUP_OWNER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The cluster node is not the owner of the group.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5016"]},{"id":1320,"title":"ERROR_RESMON_CREATE_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5017","0x1399","error 5017","ERROR_RESMON_CREATE_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","resmon","create","failed","the","cluster","resource","could","not","created","specified","monitor"],"errorCode":"5017","eventId":"","severity":"Low","summary":"The cluster resource could not be created in the specified resource monitor.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5017; use the surrounding log entries to confirm it.","resolution":"1. Record where 5017 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESMON_CREATE_FAILED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5017 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster resource could not be created in the specified resource monitor.\n\nLookup forms: 5017, 0x1399, error 5017, ERROR_RESMON_CREATE_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5017"]},{"id":1321,"title":"ERROR_RESMON_ONLINE_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5018","0x139A","error 5018","ERROR_RESMON_ONLINE_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","resmon","online","failed","the","cluster","resource","could","not","brought","monitor"],"errorCode":"5018","eventId":"","severity":"Low","summary":"The cluster resource could not be brought online by the resource monitor.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5018; use the surrounding log entries to confirm it.","resolution":"1. Record where 5018 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESMON_ONLINE_FAILED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5018 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster resource could not be brought online by the resource monitor.\n\nLookup forms: 5018, 0x139A, error 5018, ERROR_RESMON_ONLINE_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5018"]},{"id":1322,"title":"ERROR_RESOURCE_ONLINE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5019","0x139B","error 5019","ERROR_RESOURCE_ONLINE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","resource","online","the","operation","could","not","completed","because","cluster"],"errorCode":"5019","eventId":"","severity":"Low","summary":"The operation could not be completed because the cluster resource is online.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5019; use the surrounding log entries to confirm it.","resolution":"1. Record where 5019 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESOURCE_ONLINE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5019 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation could not be completed because the cluster resource is online.\n\nLookup forms: 5019, 0x139B, error 5019, ERROR_RESOURCE_ONLINE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5019"]},{"id":1323,"title":"ERROR_QUORUM_RESOURCE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5020","0x139C","error 5020","ERROR_QUORUM_RESOURCE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","quorum","resource","the","cluster","could","not","deleted","brought","offline","because"],"errorCode":"5020","eventId":"","severity":"Low","summary":"The cluster resource could not be deleted or brought offline because it is the quorum resource.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5020; use the surrounding log entries to confirm it.","resolution":"1. Record where 5020 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_QUORUM_RESOURCE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5020 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster resource could not be deleted or brought offline because it is the quorum resource.\n\nLookup forms: 5020, 0x139C, error 5020, ERROR_QUORUM_RESOURCE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5020"]},{"id":1324,"title":"ERROR_NOT_QUORUM_CAPABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5021","0x139D","error 5021","ERROR_NOT_QUORUM_CAPABLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","not","quorum","capable","the","cluster","could","make","specified","resource","because","being"],"errorCode":"5021","eventId":"","severity":"Low","summary":"The cluster could not make the specified resource a quorum resource because it is not capable of being a quorum resource.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5021; use the surrounding log entries to confirm it.","resolution":"1. Record where 5021 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_QUORUM_CAPABLE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5021 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster could not make the specified resource a quorum resource because it is not capable of being a quorum resource.\n\nLookup forms: 5021, 0x139D, error 5021, ERROR_NOT_QUORUM_CAPABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5021"]},{"id":1325,"title":"ERROR_CLUSTER_SHUTTING_DOWN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5022","0x139E","error 5022","ERROR_CLUSTER_SHUTTING_DOWN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","shutting","down","the","software"],"errorCode":"5022","eventId":"","severity":"Low","summary":"The cluster software is shutting down.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5022; use the surrounding log entries to confirm it.","resolution":"1. Record where 5022 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_SHUTTING_DOWN.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5022 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster software is shutting down.\n\nLookup forms: 5022, 0x139E, error 5022, ERROR_CLUSTER_SHUTTING_DOWN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5022"]},{"id":1326,"title":"ERROR_INVALID_STATE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5023","0x139F","error 5023","ERROR_INVALID_STATE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","state","the","group","resource","not","correct","perform","requested","operation"],"errorCode":"5023","eventId":"","severity":"Low","summary":"The group or resource is not in the correct state to perform the requested operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5023; use the surrounding log entries to confirm it.","resolution":"1. Record where 5023 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_STATE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5023 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The group or resource is not in the correct state to perform the requested operation.\n\nLookup forms: 5023, 0x139F, error 5023, ERROR_INVALID_STATE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5023"]},{"id":1327,"title":"ERROR_RESOURCE_PROPERTIES_STORED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5024","0x13A0","error 5024","ERROR_RESOURCE_PROPERTIES_STORED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","resource","properties","stored","the","were","but","not","all","changes","will","take","effect","until","next","time","brought","online"],"errorCode":"5024","eventId":"","severity":"Low","summary":"The properties were stored but not all changes will take effect until the next time the resource is brought online.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5024; use the surrounding log entries to confirm it.","resolution":"1. Record where 5024 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESOURCE_PROPERTIES_STORED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5024 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The properties were stored but not all changes will take effect until the next time the resource is brought online.\n\nLookup forms: 5024, 0x13A0, error 5024, ERROR_RESOURCE_PROPERTIES_STORED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5024"]},{"id":1328,"title":"ERROR_NOT_QUORUM_CLASS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5025","0x13A1","error 5025","ERROR_NOT_QUORUM_CLASS","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","not","quorum","class","the","cluster","could","make","specified","resource","because","does","belong","shared","storage"],"errorCode":"5025","eventId":"","severity":"Low","summary":"The cluster could not make the specified resource a quorum resource because it does not belong to a shared storage class.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 5025; use the surrounding log entries to confirm it.","resolution":"1. Record where 5025 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_QUORUM_CLASS.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5025 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster could not make the specified resource a quorum resource because it does not belong to a shared storage class.\n\nLookup forms: 5025, 0x13A1, error 5025, ERROR_NOT_QUORUM_CLASS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5025"]},{"id":1329,"title":"ERROR_CORE_RESOURCE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5026","0x13A2","error 5026","ERROR_CORE_RESOURCE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","core","resource","the","cluster","could","not","deleted","since"],"errorCode":"5026","eventId":"","severity":"Low","summary":"The cluster resource could not be deleted since it is a core resource.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5026; use the surrounding log entries to confirm it.","resolution":"1. Record where 5026 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CORE_RESOURCE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5026 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster resource could not be deleted since it is a core resource.\n\nLookup forms: 5026, 0x13A2, error 5026, ERROR_CORE_RESOURCE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5026"]},{"id":1330,"title":"ERROR_QUORUM_RESOURCE_ONLINE_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5027","0x13A3","error 5027","ERROR_QUORUM_RESOURCE_ONLINE_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","quorum","resource","online","failed","the","come"],"errorCode":"5027","eventId":"","severity":"High","summary":"The quorum resource failed to come online.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5027; use the surrounding log entries to confirm it.","resolution":"1. Record where 5027 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_QUORUM_RESOURCE_ONLINE_FAILED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5027 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The quorum resource failed to come online.\n\nLookup forms: 5027, 0x13A3, error 5027, ERROR_QUORUM_RESOURCE_ONLINE_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5027"]},{"id":1331,"title":"ERROR_QUORUMLOG_OPEN_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5028","0x13A4","error 5028","ERROR_QUORUMLOG_OPEN_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","quorumlog","open","failed","the","quorum","log","could","not","created","mounted","successfully"],"errorCode":"5028","eventId":"","severity":"Low","summary":"The quorum log could not be created or mounted successfully.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5028; use the surrounding log entries to confirm it.","resolution":"1. Record where 5028 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_QUORUMLOG_OPEN_FAILED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5028 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The quorum log could not be created or mounted successfully.\n\nLookup forms: 5028, 0x13A4, error 5028, ERROR_QUORUMLOG_OPEN_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5028"]},{"id":1332,"title":"ERROR_CLUSTERLOG_CORRUPT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5029","0x13A5","error 5029","ERROR_CLUSTERLOG_CORRUPT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","clusterlog","corrupt","the","cluster","log"],"errorCode":"5029","eventId":"","severity":"Critical","summary":"The cluster log is corrupt.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5029; use the surrounding log entries to confirm it.","resolution":"1. Record where 5029 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTERLOG_CORRUPT.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5029 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster log is corrupt.\n\nLookup forms: 5029, 0x13A5, error 5029, ERROR_CLUSTERLOG_CORRUPT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5029"]},{"id":1333,"title":"ERROR_CLUSTERLOG_RECORD_EXCEEDS_MAXSIZE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5030","0x13A6","error 5030","ERROR_CLUSTERLOG_RECORD_EXCEEDS_MAXSIZE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","clusterlog","record","exceeds","maxsize","the","could","not","written","cluster","log","since","maximum","size"],"errorCode":"5030","eventId":"","severity":"Low","summary":"The record could not be written to the cluster log since it exceeds the maximum size.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5030; use the surrounding log entries to confirm it.","resolution":"1. Record where 5030 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTERLOG_RECORD_EXCEEDS_MAXSIZE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5030 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The record could not be written to the cluster log since it exceeds the maximum size.\n\nLookup forms: 5030, 0x13A6, error 5030, ERROR_CLUSTERLOG_RECORD_EXCEEDS_MAXSIZE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5030"]},{"id":1334,"title":"ERROR_CLUSTERLOG_EXCEEDS_MAXSIZE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5031","0x13A7","error 5031","ERROR_CLUSTERLOG_EXCEEDS_MAXSIZE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","clusterlog","exceeds","maxsize","the","cluster","log","its","maximum","size"],"errorCode":"5031","eventId":"","severity":"Low","summary":"The cluster log exceeds its maximum size.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5031; use the surrounding log entries to confirm it.","resolution":"1. Record where 5031 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTERLOG_EXCEEDS_MAXSIZE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5031 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster log exceeds its maximum size.\n\nLookup forms: 5031, 0x13A7, error 5031, ERROR_CLUSTERLOG_EXCEEDS_MAXSIZE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5031"]},{"id":1335,"title":"ERROR_CLUSTERLOG_CHKPOINT_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5032","0x13A8","error 5032","ERROR_CLUSTERLOG_CHKPOINT_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","clusterlog","chkpoint","not","found","checkpoint","record","was","the","cluster","log"],"errorCode":"5032","eventId":"","severity":"Low","summary":"No checkpoint record was found in the cluster log.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5032; use the surrounding log entries to confirm it.","resolution":"1. Record where 5032 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTERLOG_CHKPOINT_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5032 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No checkpoint record was found in the cluster log.\n\nLookup forms: 5032, 0x13A8, error 5032, ERROR_CLUSTERLOG_CHKPOINT_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5032"]},{"id":1336,"title":"ERROR_CLUSTERLOG_NOT_ENOUGH_SPACE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5033","0x13A9","error 5033","ERROR_CLUSTERLOG_NOT_ENOUGH_SPACE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","clusterlog","not","enough","space","the","minimum","required","disk","needed","for","logging","available"],"errorCode":"5033","eventId":"","severity":"Low","summary":"The minimum required disk space needed for logging is not available.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 5033; use the surrounding log entries to confirm it.","resolution":"1. Record where 5033 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTERLOG_NOT_ENOUGH_SPACE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5033 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The minimum required disk space needed for logging is not available.\n\nLookup forms: 5033, 0x13A9, error 5033, ERROR_CLUSTERLOG_NOT_ENOUGH_SPACE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5033"]},{"id":1337,"title":"ERROR_QUORUM_OWNER_ALIVE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5034","0x13AA","error 5034","ERROR_QUORUM_OWNER_ALIVE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","quorum","owner","alive","the","cluster","node","failed","take","control","resource","because","owned","another","active"],"errorCode":"5034","eventId":"","severity":"High","summary":"The cluster node failed to take control of the quorum resource because the resource is owned by another active node.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5034; use the surrounding log entries to confirm it.","resolution":"1. Record where 5034 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_QUORUM_OWNER_ALIVE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5034 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster node failed to take control of the quorum resource because the resource is owned by another active node.\n\nLookup forms: 5034, 0x13AA, error 5034, ERROR_QUORUM_OWNER_ALIVE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5034"]},{"id":1338,"title":"ERROR_NETWORK_NOT_AVAILABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5035","0x13AB","error 5035","ERROR_NETWORK_NOT_AVAILABLE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","network","not","available","cluster","for","this","operation"],"errorCode":"5035","eventId":"","severity":"High","summary":"A cluster network is not available for this operation.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 5035; use the surrounding log entries to confirm it.","resolution":"1. Record where 5035 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NETWORK_NOT_AVAILABLE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5035 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A cluster network is not available for this operation.\n\nLookup forms: 5035, 0x13AB, error 5035, ERROR_NETWORK_NOT_AVAILABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5035"]},{"id":1339,"title":"ERROR_NODE_NOT_AVAILABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5036","0x13AC","error 5036","ERROR_NODE_NOT_AVAILABLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","node","not","available","cluster","for","this","operation"],"errorCode":"5036","eventId":"","severity":"Low","summary":"A cluster node is not available for this operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5036; use the surrounding log entries to confirm it.","resolution":"1. Record where 5036 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NODE_NOT_AVAILABLE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5036 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A cluster node is not available for this operation.\n\nLookup forms: 5036, 0x13AC, error 5036, ERROR_NODE_NOT_AVAILABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5036"]},{"id":1340,"title":"ERROR_ALL_NODES_NOT_AVAILABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5037","0x13AD","error 5037","ERROR_ALL_NODES_NOT_AVAILABLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","all","nodes","not","available","cluster","must","running","perform","this","operation"],"errorCode":"5037","eventId":"","severity":"Low","summary":"All cluster nodes must be running to perform this operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5037; use the surrounding log entries to confirm it.","resolution":"1. Record where 5037 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ALL_NODES_NOT_AVAILABLE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5037 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: All cluster nodes must be running to perform this operation.\n\nLookup forms: 5037, 0x13AD, error 5037, ERROR_ALL_NODES_NOT_AVAILABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5037"]},{"id":1341,"title":"ERROR_RESOURCE_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5038","0x13AE","error 5038","ERROR_RESOURCE_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","resource","failed","cluster"],"errorCode":"5038","eventId":"","severity":"High","summary":"A cluster resource failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5038; use the surrounding log entries to confirm it.","resolution":"1. Record where 5038 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESOURCE_FAILED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5038 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A cluster resource failed.\n\nLookup forms: 5038, 0x13AE, error 5038, ERROR_RESOURCE_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5038"]},{"id":1342,"title":"ERROR_CLUSTER_INVALID_NODE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5039","0x13AF","error 5039","ERROR_CLUSTER_INVALID_NODE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","invalid","node","the","not","valid"],"errorCode":"5039","eventId":"","severity":"Low","summary":"The cluster node is not valid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5039; use the surrounding log entries to confirm it.","resolution":"1. Record where 5039 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_INVALID_NODE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5039 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster node is not valid.\n\nLookup forms: 5039, 0x13AF, error 5039, ERROR_CLUSTER_INVALID_NODE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5039"]},{"id":1343,"title":"ERROR_CLUSTER_NODE_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5040","0x13B0","error 5040","ERROR_CLUSTER_NODE_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","node","exists","the","already"],"errorCode":"5040","eventId":"","severity":"Medium","summary":"The cluster node already exists.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5040; use the surrounding log entries to confirm it.","resolution":"1. Record where 5040 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NODE_EXISTS.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5040 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster node already exists.\n\nLookup forms: 5040, 0x13B0, error 5040, ERROR_CLUSTER_NODE_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5040"]},{"id":1344,"title":"ERROR_CLUSTER_JOIN_IN_PROGRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5041","0x13B1","error 5041","ERROR_CLUSTER_JOIN_IN_PROGRESS","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","cluster","join","progress","node","the","process","joining"],"errorCode":"5041","eventId":"","severity":"Low","summary":"A node is in the process of joining the cluster.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 5041; use the surrounding log entries to confirm it.","resolution":"1. Record where 5041 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_JOIN_IN_PROGRESS.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5041 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A node is in the process of joining the cluster.\n\nLookup forms: 5041, 0x13B1, error 5041, ERROR_CLUSTER_JOIN_IN_PROGRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5041"]},{"id":1345,"title":"ERROR_CLUSTER_NODE_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5042","0x13B2","error 5042","ERROR_CLUSTER_NODE_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","node","not","found","the","was"],"errorCode":"5042","eventId":"","severity":"Medium","summary":"The cluster node was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5042; use the surrounding log entries to confirm it.","resolution":"1. Record where 5042 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NODE_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5042 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster node was not found.\n\nLookup forms: 5042, 0x13B2, error 5042, ERROR_CLUSTER_NODE_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5042"]},{"id":1346,"title":"ERROR_CLUSTER_LOCAL_NODE_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5043","0x13B3","error 5043","ERROR_CLUSTER_LOCAL_NODE_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","local","node","not","found","the","information","was"],"errorCode":"5043","eventId":"","severity":"Medium","summary":"The cluster local node information was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5043; use the surrounding log entries to confirm it.","resolution":"1. Record where 5043 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_LOCAL_NODE_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5043 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster local node information was not found.\n\nLookup forms: 5043, 0x13B3, error 5043, ERROR_CLUSTER_LOCAL_NODE_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5043"]},{"id":1347,"title":"ERROR_CLUSTER_NETWORK_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5044","0x13B4","error 5044","ERROR_CLUSTER_NETWORK_EXISTS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","cluster","network","exists","the","already"],"errorCode":"5044","eventId":"","severity":"High","summary":"The cluster network already exists.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 5044; use the surrounding log entries to confirm it.","resolution":"1. Record where 5044 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NETWORK_EXISTS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5044 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster network already exists.\n\nLookup forms: 5044, 0x13B4, error 5044, ERROR_CLUSTER_NETWORK_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5044"]},{"id":1348,"title":"ERROR_CLUSTER_NETWORK_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5045","0x13B5","error 5045","ERROR_CLUSTER_NETWORK_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","cluster","network","not","found","the","was"],"errorCode":"5045","eventId":"","severity":"High","summary":"The cluster network was not found.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 5045; use the surrounding log entries to confirm it.","resolution":"1. Record where 5045 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NETWORK_NOT_FOUND.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5045 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster network was not found.\n\nLookup forms: 5045, 0x13B5, error 5045, ERROR_CLUSTER_NETWORK_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5045"]},{"id":1349,"title":"ERROR_CLUSTER_NETINTERFACE_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5046","0x13B6","error 5046","ERROR_CLUSTER_NETINTERFACE_EXISTS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","cluster","netinterface","exists","the","network","interface","already"],"errorCode":"5046","eventId":"","severity":"High","summary":"The cluster network interface already exists.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 5046; use the surrounding log entries to confirm it.","resolution":"1. Record where 5046 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NETINTERFACE_EXISTS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5046 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster network interface already exists.\n\nLookup forms: 5046, 0x13B6, error 5046, ERROR_CLUSTER_NETINTERFACE_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5046"]},{"id":1350,"title":"ERROR_CLUSTER_NETINTERFACE_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5047","0x13B7","error 5047","ERROR_CLUSTER_NETINTERFACE_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","cluster","netinterface","not","found","the","network","interface","was"],"errorCode":"5047","eventId":"","severity":"High","summary":"The cluster network interface was not found.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 5047; use the surrounding log entries to confirm it.","resolution":"1. Record where 5047 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NETINTERFACE_NOT_FOUND.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5047 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster network interface was not found.\n\nLookup forms: 5047, 0x13B7, error 5047, ERROR_CLUSTER_NETINTERFACE_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5047"]},{"id":1351,"title":"ERROR_CLUSTER_INVALID_REQUEST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5048","0x13B8","error 5048","ERROR_CLUSTER_INVALID_REQUEST","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","invalid","request","the","not","valid","for","this","object"],"errorCode":"5048","eventId":"","severity":"Low","summary":"The cluster request is not valid for this object.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5048; use the surrounding log entries to confirm it.","resolution":"1. Record where 5048 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_INVALID_REQUEST.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5048 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster request is not valid for this object.\n\nLookup forms: 5048, 0x13B8, error 5048, ERROR_CLUSTER_INVALID_REQUEST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5048"]},{"id":1352,"title":"ERROR_CLUSTER_INVALID_NETWORK_PROVIDER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5049","0x13B9","error 5049","ERROR_CLUSTER_INVALID_NETWORK_PROVIDER","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","cluster","invalid","network","provider","the","not","valid"],"errorCode":"5049","eventId":"","severity":"High","summary":"The cluster network provider is not valid.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 5049; use the surrounding log entries to confirm it.","resolution":"1. Record where 5049 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_INVALID_NETWORK_PROVIDER.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5049 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster network provider is not valid.\n\nLookup forms: 5049, 0x13B9, error 5049, ERROR_CLUSTER_INVALID_NETWORK_PROVIDER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5049"]},{"id":1353,"title":"ERROR_CLUSTER_NODE_DOWN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5050","0x13BA","error 5050","ERROR_CLUSTER_NODE_DOWN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","node","down","the"],"errorCode":"5050","eventId":"","severity":"Low","summary":"The cluster node is down.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5050; use the surrounding log entries to confirm it.","resolution":"1. Record where 5050 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NODE_DOWN.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5050 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster node is down.\n\nLookup forms: 5050, 0x13BA, error 5050, ERROR_CLUSTER_NODE_DOWN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5050"]},{"id":1354,"title":"ERROR_CLUSTER_NODE_UNREACHABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5051","0x13BB","error 5051","ERROR_CLUSTER_NODE_UNREACHABLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","node","unreachable","the","not","reachable"],"errorCode":"5051","eventId":"","severity":"Low","summary":"The cluster node is not reachable.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5051; use the surrounding log entries to confirm it.","resolution":"1. Record where 5051 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NODE_UNREACHABLE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5051 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster node is not reachable.\n\nLookup forms: 5051, 0x13BB, error 5051, ERROR_CLUSTER_NODE_UNREACHABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5051"]},{"id":1355,"title":"ERROR_CLUSTER_NODE_NOT_MEMBER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5052","0x13BC","error 5052","ERROR_CLUSTER_NODE_NOT_MEMBER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","node","not","member","the"],"errorCode":"5052","eventId":"","severity":"Low","summary":"The cluster node is not a member of the cluster.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5052; use the surrounding log entries to confirm it.","resolution":"1. Record where 5052 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NODE_NOT_MEMBER.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5052 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster node is not a member of the cluster.\n\nLookup forms: 5052, 0x13BC, error 5052, ERROR_CLUSTER_NODE_NOT_MEMBER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5052"]},{"id":1356,"title":"ERROR_CLUSTER_JOIN_NOT_IN_PROGRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5053","0x13BD","error 5053","ERROR_CLUSTER_JOIN_NOT_IN_PROGRESS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","join","not","progress","operation"],"errorCode":"5053","eventId":"","severity":"Low","summary":"A cluster join operation is not in progress.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5053; use the surrounding log entries to confirm it.","resolution":"1. Record where 5053 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_JOIN_NOT_IN_PROGRESS.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5053 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A cluster join operation is not in progress.\n\nLookup forms: 5053, 0x13BD, error 5053, ERROR_CLUSTER_JOIN_NOT_IN_PROGRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5053"]},{"id":1357,"title":"ERROR_CLUSTER_INVALID_NETWORK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5054","0x13BE","error 5054","ERROR_CLUSTER_INVALID_NETWORK","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","cluster","invalid","network","the","not","valid"],"errorCode":"5054","eventId":"","severity":"High","summary":"The cluster network is not valid.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 5054; use the surrounding log entries to confirm it.","resolution":"1. Record where 5054 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_INVALID_NETWORK.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5054 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster network is not valid.\n\nLookup forms: 5054, 0x13BE, error 5054, ERROR_CLUSTER_INVALID_NETWORK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5054"]},{"id":1358,"title":"ERROR_CLUSTER_NODE_UP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5056","0x13C0","error 5056","ERROR_CLUSTER_NODE_UP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","node","the"],"errorCode":"5056","eventId":"","severity":"Low","summary":"The cluster node is up.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5056; use the surrounding log entries to confirm it.","resolution":"1. Record where 5056 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NODE_UP.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5056 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster node is up.\n\nLookup forms: 5056, 0x13C0, error 5056, ERROR_CLUSTER_NODE_UP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5056"]},{"id":1359,"title":"ERROR_CLUSTER_IPADDR_IN_USE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5057","0x13C1","error 5057","ERROR_CLUSTER_IPADDR_IN_USE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","ipaddr","use","the","address","already"],"errorCode":"5057","eventId":"","severity":"Low","summary":"The cluster IP address is already in use.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5057; use the surrounding log entries to confirm it.","resolution":"1. Record where 5057 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_IPADDR_IN_USE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5057 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster IP address is already in use.\n\nLookup forms: 5057, 0x13C1, error 5057, ERROR_CLUSTER_IPADDR_IN_USE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5057"]},{"id":1360,"title":"ERROR_CLUSTER_NODE_NOT_PAUSED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5058","0x13C2","error 5058","ERROR_CLUSTER_NODE_NOT_PAUSED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","node","not","paused","the"],"errorCode":"5058","eventId":"","severity":"Low","summary":"The cluster node is not paused.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5058; use the surrounding log entries to confirm it.","resolution":"1. Record where 5058 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NODE_NOT_PAUSED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5058 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster node is not paused.\n\nLookup forms: 5058, 0x13C2, error 5058, ERROR_CLUSTER_NODE_NOT_PAUSED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5058"]},{"id":1361,"title":"ERROR_CLUSTER_NO_SECURITY_CONTEXT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5059","0x13C3","error 5059","ERROR_CLUSTER_NO_SECURITY_CONTEXT","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","cluster","security","context","available"],"errorCode":"5059","eventId":"","severity":"Low","summary":"No cluster security context is available.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 5059; use the surrounding log entries to confirm it.","resolution":"1. Record where 5059 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NO_SECURITY_CONTEXT.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5059 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No cluster security context is available.\n\nLookup forms: 5059, 0x13C3, error 5059, ERROR_CLUSTER_NO_SECURITY_CONTEXT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5059"]},{"id":1362,"title":"ERROR_CLUSTER_NETWORK_NOT_INTERNAL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5060","0x13C4","error 5060","ERROR_CLUSTER_NETWORK_NOT_INTERNAL","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","cluster","network","not","internal","the","configured","for","communication"],"errorCode":"5060","eventId":"","severity":"High","summary":"The cluster network is not configured for internal cluster communication.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 5060; use the surrounding log entries to confirm it.","resolution":"1. Record where 5060 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NETWORK_NOT_INTERNAL.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5060 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster network is not configured for internal cluster communication.\n\nLookup forms: 5060, 0x13C4, error 5060, ERROR_CLUSTER_NETWORK_NOT_INTERNAL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5060"]},{"id":1363,"title":"ERROR_CLUSTER_NODE_ALREADY_UP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5061","0x13C5","error 5061","ERROR_CLUSTER_NODE_ALREADY_UP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","node","already","the"],"errorCode":"5061","eventId":"","severity":"Low","summary":"The cluster node is already up.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5061; use the surrounding log entries to confirm it.","resolution":"1. Record where 5061 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NODE_ALREADY_UP.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5061 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster node is already up.\n\nLookup forms: 5061, 0x13C5, error 5061, ERROR_CLUSTER_NODE_ALREADY_UP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5061"]},{"id":1364,"title":"ERROR_CLUSTER_NODE_ALREADY_DOWN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5062","0x13C6","error 5062","ERROR_CLUSTER_NODE_ALREADY_DOWN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","node","already","down","the"],"errorCode":"5062","eventId":"","severity":"Low","summary":"The cluster node is already down.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5062; use the surrounding log entries to confirm it.","resolution":"1. Record where 5062 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NODE_ALREADY_DOWN.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5062 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster node is already down.\n\nLookup forms: 5062, 0x13C6, error 5062, ERROR_CLUSTER_NODE_ALREADY_DOWN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5062"]},{"id":1365,"title":"ERROR_CLUSTER_NETWORK_ALREADY_ONLINE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5063","0x13C7","error 5063","ERROR_CLUSTER_NETWORK_ALREADY_ONLINE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","cluster","network","already","online","the"],"errorCode":"5063","eventId":"","severity":"High","summary":"The cluster network is already online.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 5063; use the surrounding log entries to confirm it.","resolution":"1. Record where 5063 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NETWORK_ALREADY_ONLINE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5063 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster network is already online.\n\nLookup forms: 5063, 0x13C7, error 5063, ERROR_CLUSTER_NETWORK_ALREADY_ONLINE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5063"]},{"id":1366,"title":"ERROR_CLUSTER_NETWORK_ALREADY_OFFLINE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5064","0x13C8","error 5064","ERROR_CLUSTER_NETWORK_ALREADY_OFFLINE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","cluster","network","already","offline","the"],"errorCode":"5064","eventId":"","severity":"High","summary":"The cluster network is already offline.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 5064; use the surrounding log entries to confirm it.","resolution":"1. Record where 5064 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NETWORK_ALREADY_OFFLINE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5064 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster network is already offline.\n\nLookup forms: 5064, 0x13C8, error 5064, ERROR_CLUSTER_NETWORK_ALREADY_OFFLINE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5064"]},{"id":1367,"title":"ERROR_CLUSTER_NODE_ALREADY_MEMBER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5065","0x13C9","error 5065","ERROR_CLUSTER_NODE_ALREADY_MEMBER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","node","already","member","the"],"errorCode":"5065","eventId":"","severity":"Low","summary":"The cluster node is already a member of the cluster.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5065; use the surrounding log entries to confirm it.","resolution":"1. Record where 5065 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NODE_ALREADY_MEMBER.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5065 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster node is already a member of the cluster.\n\nLookup forms: 5065, 0x13C9, error 5065, ERROR_CLUSTER_NODE_ALREADY_MEMBER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5065"]},{"id":1368,"title":"ERROR_CLUSTER_LAST_INTERNAL_NETWORK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5066","0x13CA","error 5066","ERROR_CLUSTER_LAST_INTERNAL_NETWORK","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","cluster","last","internal","network","the","only","one","configured","for","communication","between","two","more","active","nodes","capability","cannot","removed","from"],"errorCode":"5066","eventId":"","severity":"High","summary":"The cluster network is the only one configured for internal cluster communication between two or more active cluster nodes. The internal communication capability cannot be removed from the network.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 5066; use the surrounding log entries to confirm it.","resolution":"1. Record where 5066 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_LAST_INTERNAL_NETWORK.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5066 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster network is the only one configured for internal cluster communication between two or more active cluster nodes. The internal communication capability cannot be removed from the network.\n\nLookup forms: 5066, 0x13CA, error 5066, ERROR_CLUSTER_LAST_INTERNAL_NETWORK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5066"]},{"id":1369,"title":"ERROR_CLUSTER_NETWORK_HAS_DEPENDENTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5067","0x13CB","error 5067","ERROR_CLUSTER_NETWORK_HAS_DEPENDENTS","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","cluster","network","has","dependents","one","more","resources","depend","the","provide","service","clients","client","access","capability","cannot","removed","from"],"errorCode":"5067","eventId":"","severity":"High","summary":"One or more cluster resources depend on the network to provide service to clients. The client access capability cannot be removed from the network.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 5067; use the surrounding log entries to confirm it.","resolution":"1. Record where 5067 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Check available memory, disk capacity, quotas, and system resource pressure.\n5. Verify the required service or agent is installed, running, and current; repair the component if needed.\n6. Review the response body, request permissions, rate limits, and service health before retrying.\n7. Review Event Viewer and the application or service log for the same timestamp and code.\n8. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NETWORK_HAS_DEPENDENTS.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5067 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: One or more cluster resources depend on the network to provide service to clients. The client access capability cannot be removed from the network.\n\nLookup forms: 5067, 0x13CB, error 5067, ERROR_CLUSTER_NETWORK_HAS_DEPENDENTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5067"]},{"id":1370,"title":"ERROR_INVALID_OPERATION_ON_QUORUM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5068","0x13CC","error 5068","ERROR_INVALID_OPERATION_ON_QUORUM","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","operation","quorum","this","cannot","performed","the","cluster","resource","you","may","not","bring","offline","modify","its","possible","owners","list"],"errorCode":"5068","eventId":"","severity":"Medium","summary":"This operation cannot be performed on the cluster resource as it the quorum resource. You may not bring the quorum resource offline or modify its possible owners list.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5068; use the surrounding log entries to confirm it.","resolution":"1. Record where 5068 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_OPERATION_ON_QUORUM.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5068 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation cannot be performed on the cluster resource as it the quorum resource. You may not bring the quorum resource offline or modify its possible owners list.\n\nLookup forms: 5068, 0x13CC, error 5068, ERROR_INVALID_OPERATION_ON_QUORUM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5068"]},{"id":1371,"title":"ERROR_DEPENDENCY_NOT_ALLOWED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5069","0x13CD","error 5069","ERROR_DEPENDENCY_NOT_ALLOWED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dependency","not","allowed","the","cluster","quorum","resource","have","any","dependencies"],"errorCode":"5069","eventId":"","severity":"Low","summary":"The cluster quorum resource is not allowed to have any dependencies.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5069; use the surrounding log entries to confirm it.","resolution":"1. Record where 5069 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEPENDENCY_NOT_ALLOWED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5069 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster quorum resource is not allowed to have any dependencies.\n\nLookup forms: 5069, 0x13CD, error 5069, ERROR_DEPENDENCY_NOT_ALLOWED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5069"]},{"id":1372,"title":"ERROR_CLUSTER_NODE_PAUSED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5070","0x13CE","error 5070","ERROR_CLUSTER_NODE_PAUSED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","node","paused","the"],"errorCode":"5070","eventId":"","severity":"Low","summary":"The cluster node is paused.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5070; use the surrounding log entries to confirm it.","resolution":"1. Record where 5070 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NODE_PAUSED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5070 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster node is paused.\n\nLookup forms: 5070, 0x13CE, error 5070, ERROR_CLUSTER_NODE_PAUSED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5070"]},{"id":1373,"title":"ERROR_NODE_CANT_HOST_RESOURCE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5071","0x13CF","error 5071","ERROR_NODE_CANT_HOST_RESOURCE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","node","cant","host","resource","the","cluster","cannot","brought","online","owner","run","this"],"errorCode":"5071","eventId":"","severity":"Medium","summary":"The cluster resource cannot be brought online. The owner node cannot run this resource.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5071; use the surrounding log entries to confirm it.","resolution":"1. Record where 5071 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NODE_CANT_HOST_RESOURCE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5071 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster resource cannot be brought online. The owner node cannot run this resource.\n\nLookup forms: 5071, 0x13CF, error 5071, ERROR_NODE_CANT_HOST_RESOURCE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5071"]},{"id":1374,"title":"ERROR_CLUSTER_NODE_NOT_READY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5072","0x13D0","error 5072","ERROR_CLUSTER_NODE_NOT_READY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","node","not","ready","the","perform","requested","operation"],"errorCode":"5072","eventId":"","severity":"Low","summary":"The cluster node is not ready to perform the requested operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5072; use the surrounding log entries to confirm it.","resolution":"1. Record where 5072 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NODE_NOT_READY.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5072 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster node is not ready to perform the requested operation.\n\nLookup forms: 5072, 0x13D0, error 5072, ERROR_CLUSTER_NODE_NOT_READY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5072"]},{"id":1375,"title":"ERROR_CLUSTER_NODE_SHUTTING_DOWN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5073","0x13D1","error 5073","ERROR_CLUSTER_NODE_SHUTTING_DOWN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","node","shutting","down","the"],"errorCode":"5073","eventId":"","severity":"Low","summary":"The cluster node is shutting down.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5073; use the surrounding log entries to confirm it.","resolution":"1. Record where 5073 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NODE_SHUTTING_DOWN.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5073 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster node is shutting down.\n\nLookup forms: 5073, 0x13D1, error 5073, ERROR_CLUSTER_NODE_SHUTTING_DOWN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5073"]},{"id":1376,"title":"ERROR_CLUSTER_JOIN_ABORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5074","0x13D2","error 5074","ERROR_CLUSTER_JOIN_ABORTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","join","aborted","the","operation","was"],"errorCode":"5074","eventId":"","severity":"Low","summary":"The cluster join operation was aborted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5074; use the surrounding log entries to confirm it.","resolution":"1. Record where 5074 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_JOIN_ABORTED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5074 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster join operation was aborted.\n\nLookup forms: 5074, 0x13D2, error 5074, ERROR_CLUSTER_JOIN_ABORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5074"]},{"id":1377,"title":"ERROR_CLUSTER_INCOMPATIBLE_VERSIONS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5075","0x13D3","error 5075","ERROR_CLUSTER_INCOMPATIBLE_VERSIONS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","incompatible","versions","the","join","operation","failed","due","software","between","joining","node","and","its","sponsor"],"errorCode":"5075","eventId":"","severity":"High","summary":"The cluster join operation failed due to incompatible software versions between the joining node and its sponsor.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5075; use the surrounding log entries to confirm it.","resolution":"1. Record where 5075 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_INCOMPATIBLE_VERSIONS.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5075 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster join operation failed due to incompatible software versions between the joining node and its sponsor.\n\nLookup forms: 5075, 0x13D3, error 5075, ERROR_CLUSTER_INCOMPATIBLE_VERSIONS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5075"]},{"id":1378,"title":"ERROR_CLUSTER_MAXNUM_OF_RESOURCES_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5076","0x13D4","error 5076","ERROR_CLUSTER_MAXNUM_OF_RESOURCES_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","maxnum","resources","exceeded","this","resource","cannot","created","because","the","has","reached","limit","number","can","monitor"],"errorCode":"5076","eventId":"","severity":"Medium","summary":"This resource cannot be created because the cluster has reached the limit on the number of resources it can monitor.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5076; use the surrounding log entries to confirm it.","resolution":"1. Record where 5076 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_MAXNUM_OF_RESOURCES_EXCEEDED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5076 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This resource cannot be created because the cluster has reached the limit on the number of resources it can monitor.\n\nLookup forms: 5076, 0x13D4, error 5076, ERROR_CLUSTER_MAXNUM_OF_RESOURCES_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5076"]},{"id":1379,"title":"ERROR_CLUSTER_SYSTEM_CONFIG_CHANGED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5077","0x13D5","error 5077","ERROR_CLUSTER_SYSTEM_CONFIG_CHANGED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","system","config","changed","the","configuration","during","join","form","operation","was","aborted"],"errorCode":"5077","eventId":"","severity":"Low","summary":"The system configuration changed during the cluster join or form operation. The join or form operation was aborted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5077; use the surrounding log entries to confirm it.","resolution":"1. Record where 5077 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_SYSTEM_CONFIG_CHANGED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5077 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system configuration changed during the cluster join or form operation. The join or form operation was aborted.\n\nLookup forms: 5077, 0x13D5, error 5077, ERROR_CLUSTER_SYSTEM_CONFIG_CHANGED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5077"]},{"id":1380,"title":"ERROR_CLUSTER_RESOURCE_TYPE_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5078","0x13D6","error 5078","ERROR_CLUSTER_RESOURCE_TYPE_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","resource","type","not","found","the","specified","was"],"errorCode":"5078","eventId":"","severity":"Medium","summary":"The specified resource type was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5078; use the surrounding log entries to confirm it.","resolution":"1. Record where 5078 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_RESOURCE_TYPE_NOT_FOUND.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5078 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified resource type was not found.\n\nLookup forms: 5078, 0x13D6, error 5078, ERROR_CLUSTER_RESOURCE_TYPE_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5078"]},{"id":1381,"title":"ERROR_CLUSTER_RESTYPE_NOT_SUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5079","0x13D7","error 5079","ERROR_CLUSTER_RESTYPE_NOT_SUPPORTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","restype","not","supported","the","specified","node","does","support","resource","this","type","may","due","version","inconsistencies","absence","dll"],"errorCode":"5079","eventId":"","severity":"Low","summary":"The specified node does not support a resource of this type. This may be due to version inconsistencies or due to the absence of the resource DLL on this node.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5079; use the surrounding log entries to confirm it.","resolution":"1. Record where 5079 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_RESTYPE_NOT_SUPPORTED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5079 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified node does not support a resource of this type. This may be due to version inconsistencies or due to the absence of the resource DLL on this node.\n\nLookup forms: 5079, 0x13D7, error 5079, ERROR_CLUSTER_RESTYPE_NOT_SUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5079"]},{"id":1382,"title":"ERROR_CLUSTER_RESNAME_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5080","0x13D8","error 5080","ERROR_CLUSTER_RESNAME_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","resname","not","found","the","specified","resource","name","supported","this","dll","may","due","bad","changed","supplied"],"errorCode":"5080","eventId":"","severity":"Medium","summary":"The specified resource name is not supported by this resource DLL. This may be due to a bad (or changed) name supplied to the resource DLL.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5080; use the surrounding log entries to confirm it.","resolution":"1. Record where 5080 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_RESNAME_NOT_FOUND.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5080 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified resource name is not supported by this resource DLL. This may be due to a bad (or changed) name supplied to the resource DLL.\n\nLookup forms: 5080, 0x13D8, error 5080, ERROR_CLUSTER_RESNAME_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The specified resource name is supported by this resource DLL. This may be due to a bad (or changed) name supplied to the resource DLL.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5080"]},{"id":1383,"title":"ERROR_CLUSTER_NO_RPC_PACKAGES_REGISTERED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5081","0x13D9","error 5081","ERROR_CLUSTER_NO_RPC_PACKAGES_REGISTERED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","cluster","rpc","packages","registered","authentication","package","could","with","the","server"],"errorCode":"5081","eventId":"","severity":"High","summary":"No authentication package could be registered with the RPC server.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 5081; use the surrounding log entries to confirm it.","resolution":"1. Record where 5081 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review the response body, request permissions, rate limits, and service health before retrying.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NO_RPC_PACKAGES_REGISTERED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5081 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No authentication package could be registered with the RPC server.\n\nLookup forms: 5081, 0x13D9, error 5081, ERROR_CLUSTER_NO_RPC_PACKAGES_REGISTERED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5081"]},{"id":1384,"title":"ERROR_CLUSTER_OWNER_NOT_IN_PREFLIST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5082","0x13DA","error 5082","ERROR_CLUSTER_OWNER_NOT_IN_PREFLIST","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","owner","not","preflist","you","cannot","bring","the","group","online","because","preferred","list","for","change","node","move"],"errorCode":"5082","eventId":"","severity":"Medium","summary":"You cannot bring the group online because the owner of the group is not in the preferred list for the group. To change the owner node for the group, move the group.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5082; use the surrounding log entries to confirm it.","resolution":"1. Record where 5082 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_OWNER_NOT_IN_PREFLIST.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5082 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: You cannot bring the group online because the owner of the group is not in the preferred list for the group. To change the owner node for the group, move the group.\n\nLookup forms: 5082, 0x13DA, error 5082, ERROR_CLUSTER_OWNER_NOT_IN_PREFLIST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5082"]},{"id":1385,"title":"ERROR_CLUSTER_DATABASE_SEQMISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5083","0x13DB","error 5083","ERROR_CLUSTER_DATABASE_SEQMISMATCH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","database","seqmismatch","the","join","operation","failed","because","sequence","number","has","changed","incompatible","with","locker","node","this","may","happen","during","was","changing"],"errorCode":"5083","eventId":"","severity":"High","summary":"The join operation failed because the cluster database sequence number has changed or is incompatible with the locker node. This may happen during a join operation if the cluster database was changing during the join.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5083; use the surrounding log entries to confirm it.","resolution":"1. Record where 5083 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_DATABASE_SEQMISMATCH.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5083 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The join operation failed because the cluster database sequence number has changed or is incompatible with the locker node. This may happen during a join operation if the cluster database was changing during the join.\n\nLookup forms: 5083, 0x13DB, error 5083, ERROR_CLUSTER_DATABASE_SEQMISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5083"]},{"id":1386,"title":"ERROR_RESMON_INVALID_STATE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5084","0x13DC","error 5084","ERROR_RESMON_INVALID_STATE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","resmon","invalid","state","the","resource","monitor","will","not","allow","fail","operation","performed","while","its","current","this","may","happen","pending"],"errorCode":"5084","eventId":"","severity":"Low","summary":"The resource monitor will not allow the fail operation to be performed while the resource is in its current state. This may happen if the resource is in a pending state.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5084; use the surrounding log entries to confirm it.","resolution":"1. Record where 5084 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESMON_INVALID_STATE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5084 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The resource monitor will not allow the fail operation to be performed while the resource is in its current state. This may happen if the resource is in a pending state.\n\nLookup forms: 5084, 0x13DC, error 5084, ERROR_RESMON_INVALID_STATE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5084"]},{"id":1387,"title":"ERROR_CLUSTER_GUM_NOT_LOCKER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5085","0x13DD","error 5085","ERROR_CLUSTER_GUM_NOT_LOCKER","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","cluster","gum","not","locker","non","code","got","request","reserve","the","lock","for","making","global","updates"],"errorCode":"5085","eventId":"","severity":"Low","summary":"A non locker code got a request to reserve the lock for making global updates.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 5085; use the surrounding log entries to confirm it.","resolution":"1. Record where 5085 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_GUM_NOT_LOCKER.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5085 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A non locker code got a request to reserve the lock for making global updates.\n\nLookup forms: 5085, 0x13DD, error 5085, ERROR_CLUSTER_GUM_NOT_LOCKER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5085"]},{"id":1388,"title":"ERROR_QUORUM_DISK_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5086","0x13DE","error 5086","ERROR_QUORUM_DISK_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","quorum","disk","not","found","the","could","located","cluster","service"],"errorCode":"5086","eventId":"","severity":"Low","summary":"The quorum disk could not be located by the cluster service.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 5086; use the surrounding log entries to confirm it.","resolution":"1. Record where 5086 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review the response body, request permissions, rate limits, and service health before retrying.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_QUORUM_DISK_NOT_FOUND.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5086 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The quorum disk could not be located by the cluster service.\n\nLookup forms: 5086, 0x13DE, error 5086, ERROR_QUORUM_DISK_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5086"]},{"id":1389,"title":"ERROR_DATABASE_BACKUP_CORRUPT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5087","0x13DF","error 5087","ERROR_DATABASE_BACKUP_CORRUPT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","database","backup","corrupt","the","backed","cluster","possibly"],"errorCode":"5087","eventId":"","severity":"Critical","summary":"The backed up cluster database is possibly corrupt.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5087; use the surrounding log entries to confirm it.","resolution":"1. Record where 5087 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DATABASE_BACKUP_CORRUPT.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5087 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The backed up cluster database is possibly corrupt.\n\nLookup forms: 5087, 0x13DF, error 5087, ERROR_DATABASE_BACKUP_CORRUPT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The backup up cluster database is possibly corrupt.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5087"]},{"id":1390,"title":"ERROR_CLUSTER_NODE_ALREADY_HAS_DFS_ROOT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5088","0x13E0","error 5088","ERROR_CLUSTER_NODE_ALREADY_HAS_DFS_ROOT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","node","already","has","dfs","root","exists","this"],"errorCode":"5088","eventId":"","severity":"Medium","summary":"A DFS root already exists in this cluster node.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5088; use the surrounding log entries to confirm it.","resolution":"1. Record where 5088 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NODE_ALREADY_HAS_DFS_ROOT.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5088 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A DFS root already exists in this cluster node.\n\nLookup forms: 5088, 0x13E0, error 5088, ERROR_CLUSTER_NODE_ALREADY_HAS_DFS_ROOT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5088"]},{"id":1391,"title":"ERROR_RESOURCE_PROPERTY_UNCHANGEABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5089","0x13E1","error 5089","ERROR_RESOURCE_PROPERTY_UNCHANGEABLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","resource","property","unchangeable","attempt","modify","failed","because","conflicts","with","another","existing"],"errorCode":"5089","eventId":"","severity":"High","summary":"An attempt to modify a resource property failed because it conflicts with another existing property.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5089; use the surrounding log entries to confirm it.","resolution":"1. Record where 5089 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESOURCE_PROPERTY_UNCHANGEABLE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5089 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt to modify a resource property failed because it conflicts with another existing property.\n\nLookup forms: 5089, 0x13E1, error 5089, ERROR_RESOURCE_PROPERTY_UNCHANGEABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5089"]},{"id":1392,"title":"ERROR_CLUSTER_MEMBERSHIP_INVALID_STATE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5890","0x1702","error 5890","ERROR_CLUSTER_MEMBERSHIP_INVALID_STATE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","membership","invalid","state","operation","was","attempted","that","incompatible","with","the","current","node"],"errorCode":"5890","eventId":"","severity":"Low","summary":"An operation was attempted that is incompatible with the current membership state of the node.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5890; use the surrounding log entries to confirm it.","resolution":"1. Record where 5890 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_MEMBERSHIP_INVALID_STATE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5890 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An operation was attempted that is incompatible with the current membership state of the node.\n\nLookup forms: 5890, 0x1702, error 5890, ERROR_CLUSTER_MEMBERSHIP_INVALID_STATE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5890"]},{"id":1393,"title":"ERROR_CLUSTER_QUORUMLOG_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5891","0x1703","error 5891","ERROR_CLUSTER_QUORUMLOG_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","quorumlog","not","found","the","quorum","resource","does","contain","log"],"errorCode":"5891","eventId":"","severity":"Low","summary":"The quorum resource does not contain the quorum log.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5891; use the surrounding log entries to confirm it.","resolution":"1. Record where 5891 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_QUORUMLOG_NOT_FOUND.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5891 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The quorum resource does not contain the quorum log.\n\nLookup forms: 5891, 0x1703, error 5891, ERROR_CLUSTER_QUORUMLOG_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5891"]},{"id":1394,"title":"ERROR_CLUSTER_MEMBERSHIP_HALT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5892","0x1704","error 5892","ERROR_CLUSTER_MEMBERSHIP_HALT","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","cluster","membership","halt","the","engine","requested","shutdown","service","this","node"],"errorCode":"5892","eventId":"","severity":"Low","summary":"The membership engine requested shutdown of the cluster service on this node.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 5892; use the surrounding log entries to confirm it.","resolution":"1. Record where 5892 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_MEMBERSHIP_HALT.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5892 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The membership engine requested shutdown of the cluster service on this node.\n\nLookup forms: 5892, 0x1704, error 5892, ERROR_CLUSTER_MEMBERSHIP_HALT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5892"]},{"id":1395,"title":"ERROR_CLUSTER_INSTANCE_ID_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5893","0x1705","error 5893","ERROR_CLUSTER_INSTANCE_ID_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","instance","mismatch","the","join","operation","failed","because","joining","node","does","not","match","sponsor"],"errorCode":"5893","eventId":"","severity":"High","summary":"The join operation failed because the cluster instance ID of the joining node does not match the cluster instance ID of the sponsor node.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5893; use the surrounding log entries to confirm it.","resolution":"1. Record where 5893 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_INSTANCE_ID_MISMATCH.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5893 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The join operation failed because the cluster instance ID of the joining node does not match the cluster instance ID of the sponsor node.\n\nLookup forms: 5893, 0x1705, error 5893, ERROR_CLUSTER_INSTANCE_ID_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5893"]},{"id":1396,"title":"ERROR_CLUSTER_NETWORK_NOT_FOUND_FOR_IP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5894","0x1706","error 5894","ERROR_CLUSTER_NETWORK_NOT_FOUND_FOR_IP","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","cluster","network","not","found","for","matching","the","specified","address","could"],"errorCode":"5894","eventId":"","severity":"High","summary":"A matching cluster network for the specified IP address could not be found.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 5894; use the surrounding log entries to confirm it.","resolution":"1. Record where 5894 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NETWORK_NOT_FOUND_FOR_IP.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5894 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A matching cluster network for the specified IP address could not be found.\n\nLookup forms: 5894, 0x1706, error 5894, ERROR_CLUSTER_NETWORK_NOT_FOUND_FOR_IP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): A matching network for the specified IP address could not be found. Please also specify a subnet mask and a cluster network.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5894"]},{"id":1397,"title":"ERROR_CLUSTER_PROPERTY_DATA_TYPE_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5895","0x1707","error 5895","ERROR_CLUSTER_PROPERTY_DATA_TYPE_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","property","data","type","mismatch","the","actual","did","not","match","expected"],"errorCode":"5895","eventId":"","severity":"Low","summary":"The actual data type of the property did not match the expected data type of the property.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5895; use the surrounding log entries to confirm it.","resolution":"1. Record where 5895 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_PROPERTY_DATA_TYPE_MISMATCH.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5895 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The actual data type of the property did not match the expected data type of the property.\n\nLookup forms: 5895, 0x1707, error 5895, ERROR_CLUSTER_PROPERTY_DATA_TYPE_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5895"]},{"id":1398,"title":"ERROR_CLUSTER_EVICT_WITHOUT_CLEANUP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5896","0x1708","error 5896","ERROR_CLUSTER_EVICT_WITHOUT_CLEANUP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","evict","without","cleanup","the","node","was","evicted","from","successfully","but","not","cleaned","determine","what","steps","failed","and","how","recover","see","failover","clustering","application"],"errorCode":"5896","eventId":"","severity":"High","summary":"The cluster node was evicted from the cluster successfully, but the node was not cleaned up. To determine what cleanup steps failed and how to recover, see the Failover Clustering application event log using Event Viewer.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5896; use the surrounding log entries to confirm it.","resolution":"1. Record where 5896 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_EVICT_WITHOUT_CLEANUP.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5896 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster node was evicted from the cluster successfully, but the node was not cleaned up. To determine what cleanup steps failed and how to recover, see the Failover Clustering application event log using Event Viewer.\n\nLookup forms: 5896, 0x1708, error 5896, ERROR_CLUSTER_EVICT_WITHOUT_CLEANUP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The cluster node was evicted from the cluster successfully, but the node was not cleaned up. Extended status information explaining why the node was not cleaned up is available.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5896"]},{"id":1399,"title":"ERROR_CLUSTER_PARAMETER_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5897","0x1709","error 5897","ERROR_CLUSTER_PARAMETER_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","parameter","mismatch","two","more","values","specified","for","resource","properties","are","conflict"],"errorCode":"5897","eventId":"","severity":"Low","summary":"Two or more parameter values specified for a resource's properties are in conflict.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5897; use the surrounding log entries to confirm it.","resolution":"1. Record where 5897 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_PARAMETER_MISMATCH.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5897 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Two or more parameter values specified for a resource's properties are in conflict.\n\nLookup forms: 5897, 0x1709, error 5897, ERROR_CLUSTER_PARAMETER_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5897"]},{"id":1400,"title":"ERROR_NODE_CANNOT_BE_CLUSTERED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5898","0x170A","error 5898","ERROR_NODE_CANNOT_BE_CLUSTERED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","node","cannot","clustered","this","computer","made","member","cluster"],"errorCode":"5898","eventId":"","severity":"Medium","summary":"This computer cannot be made a member of a cluster.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5898; use the surrounding log entries to confirm it.","resolution":"1. Record where 5898 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NODE_CANNOT_BE_CLUSTERED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5898 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This computer cannot be made a member of a cluster.\n\nLookup forms: 5898, 0x170A, error 5898, ERROR_NODE_CANNOT_BE_CLUSTERED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5898"]},{"id":1401,"title":"ERROR_CLUSTER_WRONG_OS_VERSION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5899","0x170B","error 5899","ERROR_CLUSTER_WRONG_OS_VERSION","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","cluster","wrong","version","this","computer","cannot","made","member","because","does","not","have","the","correct","windows","installed"],"errorCode":"5899","eventId":"","severity":"Medium","summary":"This computer cannot be made a member of a cluster because it does not have the correct version of Windows installed.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 5899; use the surrounding log entries to confirm it.","resolution":"1. Record where 5899 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_WRONG_OS_VERSION.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5899 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This computer cannot be made a member of a cluster because it does not have the correct version of Windows installed.\n\nLookup forms: 5899, 0x170B, error 5899, ERROR_CLUSTER_WRONG_OS_VERSION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5899"]},{"id":1402,"title":"ERROR_CLUSTER_CANT_CREATE_DUP_CLUSTER_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5900","0x170C","error 5900","ERROR_CLUSTER_CANT_CREATE_DUP_CLUSTER_NAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","cant","create","dup","name","cannot","created","with","the","specified","because","that","already","use","specify","different","for"],"errorCode":"5900","eventId":"","severity":"Medium","summary":"A cluster cannot be created with the specified cluster name because that cluster name is already in use. Specify a different name for the cluster.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5900; use the surrounding log entries to confirm it.","resolution":"1. Record where 5900 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_CANT_CREATE_DUP_CLUSTER_NAME.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5900 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A cluster cannot be created with the specified cluster name because that cluster name is already in use. Specify a different name for the cluster.\n\nLookup forms: 5900, 0x170C, error 5900, ERROR_CLUSTER_CANT_CREATE_DUP_CLUSTER_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5900"]},{"id":1403,"title":"ERROR_CLUSCFG_ALREADY_COMMITTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5901","0x170D","error 5901","ERROR_CLUSCFG_ALREADY_COMMITTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluscfg","already","committed","the","cluster","configuration","action","has","been"],"errorCode":"5901","eventId":"","severity":"Low","summary":"The cluster configuration action has already been committed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5901; use the surrounding log entries to confirm it.","resolution":"1. Record where 5901 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSCFG_ALREADY_COMMITTED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5901 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster configuration action has already been committed.\n\nLookup forms: 5901, 0x170D, error 5901, ERROR_CLUSCFG_ALREADY_COMMITTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5901"]},{"id":1404,"title":"ERROR_CLUSCFG_ROLLBACK_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5902","0x170E","error 5902","ERROR_CLUSCFG_ROLLBACK_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluscfg","rollback","failed","the","cluster","configuration","action","could","not","rolled","back"],"errorCode":"5902","eventId":"","severity":"Low","summary":"The cluster configuration action could not be rolled back.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5902; use the surrounding log entries to confirm it.","resolution":"1. Record where 5902 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSCFG_ROLLBACK_FAILED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5902 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster configuration action could not be rolled back.\n\nLookup forms: 5902, 0x170E, error 5902, ERROR_CLUSCFG_ROLLBACK_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5902"]},{"id":1405,"title":"ERROR_CLUSCFG_SYSTEM_DISK_DRIVE_LETTER_CONFLICT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5903","0x170F","error 5903","ERROR_CLUSCFG_SYSTEM_DISK_DRIVE_LETTER_CONFLICT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","cluscfg","system","disk","drive","letter","conflict","the","assigned","one","node","conflicted","with","another"],"errorCode":"5903","eventId":"","severity":"Low","summary":"The drive letter assigned to a system disk on one node conflicted with the drive letter assigned to a disk on another node.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 5903; use the surrounding log entries to confirm it.","resolution":"1. Record where 5903 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review the response body, request permissions, rate limits, and service health before retrying.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSCFG_SYSTEM_DISK_DRIVE_LETTER_CONFLICT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5903 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The drive letter assigned to a system disk on one node conflicted with the drive letter assigned to a disk on another node.\n\nLookup forms: 5903, 0x170F, error 5903, ERROR_CLUSCFG_SYSTEM_DISK_DRIVE_LETTER_CONFLICT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5903"]},{"id":1406,"title":"ERROR_CLUSTER_OLD_VERSION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5904","0x1710","error 5904","ERROR_CLUSTER_OLD_VERSION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","old","version","one","more","nodes","the","are","running","windows","that","does","not","support","this","operation"],"errorCode":"5904","eventId":"","severity":"Low","summary":"One or more nodes in the cluster are running a version of Windows that does not support this operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5904; use the surrounding log entries to confirm it.","resolution":"1. Record where 5904 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_OLD_VERSION.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5904 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: One or more nodes in the cluster are running a version of Windows that does not support this operation.\n\nLookup forms: 5904, 0x1710, error 5904, ERROR_CLUSTER_OLD_VERSION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5904"]},{"id":1407,"title":"ERROR_CLUSTER_MISMATCHED_COMPUTER_ACCT_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5905","0x1711","error 5905","ERROR_CLUSTER_MISMATCHED_COMPUTER_ACCT_NAME","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","cluster","mismatched","computer","acct","name","the","corresponding","account","doesn","match","network","for","this","resource"],"errorCode":"5905","eventId":"","severity":"High","summary":"The name of the corresponding computer account doesn't match the Network Name for this resource.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 5905; use the surrounding log entries to confirm it.","resolution":"1. Record where 5905 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Check available memory, disk capacity, quotas, and system resource pressure.\n5. Review the response body, request permissions, rate limits, and service health before retrying.\n6. Review Event Viewer and the application or service log for the same timestamp and code.\n7. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_MISMATCHED_COMPUTER_ACCT_NAME.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5905 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The name of the corresponding computer account doesn't match the Network Name for this resource.\n\nLookup forms: 5905, 0x1711, error 5905, ERROR_CLUSTER_MISMATCHED_COMPUTER_ACCT_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5905"]},{"id":1408,"title":"ERROR_CLUSTER_NO_NET_ADAPTERS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5906","0x1712","error 5906","ERROR_CLUSTER_NO_NET_ADAPTERS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","cluster","net","adapters","network","are","available"],"errorCode":"5906","eventId":"","severity":"High","summary":"No network adapters are available.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 5906; use the surrounding log entries to confirm it.","resolution":"1. Record where 5906 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NO_NET_ADAPTERS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5906 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No network adapters are available.\n\nLookup forms: 5906, 0x1712, error 5906, ERROR_CLUSTER_NO_NET_ADAPTERS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5906"]},{"id":1409,"title":"ERROR_CLUSTER_POISONED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5907","0x1713","error 5907","ERROR_CLUSTER_POISONED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","poisoned","the","node","has","been"],"errorCode":"5907","eventId":"","severity":"Low","summary":"The cluster node has been poisoned.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5907; use the surrounding log entries to confirm it.","resolution":"1. Record where 5907 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_POISONED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5907 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster node has been poisoned.\n\nLookup forms: 5907, 0x1713, error 5907, ERROR_CLUSTER_POISONED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5907"]},{"id":1410,"title":"ERROR_CLUSTER_GROUP_MOVING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5908","0x1714","error 5908","ERROR_CLUSTER_GROUP_MOVING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","group","moving","the","unable","accept","request","since","another","node"],"errorCode":"5908","eventId":"","severity":"Medium","summary":"The group is unable to accept the request since it is moving to another node.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5908; use the surrounding log entries to confirm it.","resolution":"1. Record where 5908 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_GROUP_MOVING.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5908 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The group is unable to accept the request since it is moving to another node.\n\nLookup forms: 5908, 0x1714, error 5908, ERROR_CLUSTER_GROUP_MOVING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5908"]},{"id":1411,"title":"ERROR_CLUSTER_RESOURCE_TYPE_BUSY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5909","0x1715","error 5909","ERROR_CLUSTER_RESOURCE_TYPE_BUSY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","resource","type","busy","the","cannot","accept","request","since","too","performing","another","operation"],"errorCode":"5909","eventId":"","severity":"Medium","summary":"The resource type cannot accept the request since is too busy performing another operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5909; use the surrounding log entries to confirm it.","resolution":"1. Record where 5909 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_RESOURCE_TYPE_BUSY.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5909 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The resource type cannot accept the request since is too busy performing another operation.\n\nLookup forms: 5909, 0x1715, error 5909, ERROR_CLUSTER_RESOURCE_TYPE_BUSY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5909"]},{"id":1412,"title":"ERROR_RESOURCE_CALL_TIMED_OUT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5910","0x1716","error 5910","ERROR_RESOURCE_CALL_TIMED_OUT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","resource","call","timed","out","the","cluster","dll"],"errorCode":"5910","eventId":"","severity":"Low","summary":"The call to the cluster resource DLL timed out.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5910; use the surrounding log entries to confirm it.","resolution":"1. Record where 5910 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESOURCE_CALL_TIMED_OUT.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5910 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The call to the cluster resource DLL timed out.\n\nLookup forms: 5910, 0x1716, error 5910, ERROR_RESOURCE_CALL_TIMED_OUT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5910"]},{"id":1413,"title":"ERROR_INVALID_CLUSTER_IPV6_ADDRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5911","0x1717","error 5911","ERROR_INVALID_CLUSTER_IPV6_ADDRESS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","invalid","cluster","ipv6","address","the","not","valid","for","resource","global","required","and","must","match","network","compatibility","addresses","are","permitted"],"errorCode":"5911","eventId":"","severity":"High","summary":"The address is not valid for an IPv6 Address resource. A global IPv6 address is required, and it must match a cluster network. Compatibility addresses are not permitted.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 5911; use the surrounding log entries to confirm it.","resolution":"1. Record where 5911 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review the response body, request permissions, rate limits, and service health before retrying.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_CLUSTER_IPV6_ADDRESS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5911 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The address is not valid for an IPv6 Address resource. A global IPv6 address is required, and it must match a cluster network. Compatibility addresses are not permitted.\n\nLookup forms: 5911, 0x1717, error 5911, ERROR_INVALID_CLUSTER_IPV6_ADDRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5911"]},{"id":1414,"title":"ERROR_CLUSTER_INTERNAL_INVALID_FUNCTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5912","0x1718","error 5912","ERROR_CLUSTER_INTERNAL_INVALID_FUNCTION","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","cluster","internal","invalid","function","occurred","call","was","attempted"],"errorCode":"5912","eventId":"","severity":"Medium","summary":"An internal cluster error occurred. A call to an invalid function was attempted.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 5912; use the surrounding log entries to confirm it.","resolution":"1. Record where 5912 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_INTERNAL_INVALID_FUNCTION.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5912 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An internal cluster error occurred. A call to an invalid function was attempted.\n\nLookup forms: 5912, 0x1718, error 5912, ERROR_CLUSTER_INTERNAL_INVALID_FUNCTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5912"]},{"id":1415,"title":"ERROR_CLUSTER_PARAMETER_OUT_OF_BOUNDS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5913","0x1719","error 5913","ERROR_CLUSTER_PARAMETER_OUT_OF_BOUNDS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","parameter","out","bounds","value","acceptable","range"],"errorCode":"5913","eventId":"","severity":"Low","summary":"A parameter value is out of acceptable range.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5913; use the surrounding log entries to confirm it.","resolution":"1. Record where 5913 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_PARAMETER_OUT_OF_BOUNDS.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5913 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A parameter value is out of acceptable range.\n\nLookup forms: 5913, 0x1719, error 5913, ERROR_CLUSTER_PARAMETER_OUT_OF_BOUNDS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5913"]},{"id":1416,"title":"ERROR_CLUSTER_PARTIAL_SEND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5914","0x171A","error 5914","ERROR_CLUSTER_PARTIAL_SEND","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","cluster","partial","send","network","occurred","while","sending","data","another","node","the","number","bytes","transmitted","was","less","than","required"],"errorCode":"5914","eventId":"","severity":"High","summary":"A network error occurred while sending data to another node in the cluster. The number of bytes transmitted was less than required.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 5914; use the surrounding log entries to confirm it.","resolution":"1. Record where 5914 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_PARTIAL_SEND.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5914 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A network error occurred while sending data to another node in the cluster. The number of bytes transmitted was less than required.\n\nLookup forms: 5914, 0x171A, error 5914, ERROR_CLUSTER_PARTIAL_SEND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5914"]},{"id":1417,"title":"ERROR_CLUSTER_REGISTRY_INVALID_FUNCTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5915","0x171B","error 5915","ERROR_CLUSTER_REGISTRY_INVALID_FUNCTION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","registry","invalid","function","operation","was","attempted"],"errorCode":"5915","eventId":"","severity":"Medium","summary":"An invalid cluster registry operation was attempted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5915; use the surrounding log entries to confirm it.","resolution":"1. Record where 5915 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_REGISTRY_INVALID_FUNCTION.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5915 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An invalid cluster registry operation was attempted.\n\nLookup forms: 5915, 0x171B, error 5915, ERROR_CLUSTER_REGISTRY_INVALID_FUNCTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5915"]},{"id":1418,"title":"ERROR_CLUSTER_INVALID_STRING_TERMINATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5916","0x171C","error 5916","ERROR_CLUSTER_INVALID_STRING_TERMINATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","invalid","string","termination","input","characters","not","properly","terminated"],"errorCode":"5916","eventId":"","severity":"Low","summary":"An input string of characters is not properly terminated.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5916; use the surrounding log entries to confirm it.","resolution":"1. Record where 5916 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_INVALID_STRING_TERMINATION.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5916 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An input string of characters is not properly terminated.\n\nLookup forms: 5916, 0x171C, error 5916, ERROR_CLUSTER_INVALID_STRING_TERMINATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5916"]},{"id":1419,"title":"ERROR_CLUSTER_INVALID_STRING_FORMAT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5917","0x171D","error 5917","ERROR_CLUSTER_INVALID_STRING_FORMAT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","invalid","string","format","input","characters","not","valid","for","the","data","represents"],"errorCode":"5917","eventId":"","severity":"Low","summary":"An input string of characters is not in a valid format for the data it represents.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5917; use the surrounding log entries to confirm it.","resolution":"1. Record where 5917 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_INVALID_STRING_FORMAT.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5917 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An input string of characters is not in a valid format for the data it represents.\n\nLookup forms: 5917, 0x171D, error 5917, ERROR_CLUSTER_INVALID_STRING_FORMAT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5917"]},{"id":1420,"title":"ERROR_CLUSTER_DATABASE_TRANSACTION_IN_PROGRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5918","0x171E","error 5918","ERROR_CLUSTER_DATABASE_TRANSACTION_IN_PROGRESS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","database","transaction","progress","internal","occurred","was","attempted","while","already"],"errorCode":"5918","eventId":"","severity":"Low","summary":"An internal cluster error occurred. A cluster database transaction was attempted while a transaction was already in progress.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5918; use the surrounding log entries to confirm it.","resolution":"1. Record where 5918 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_DATABASE_TRANSACTION_IN_PROGRESS.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5918 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An internal cluster error occurred. A cluster database transaction was attempted while a transaction was already in progress.\n\nLookup forms: 5918, 0x171E, error 5918, ERROR_CLUSTER_DATABASE_TRANSACTION_IN_PROGRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5918"]},{"id":1421,"title":"ERROR_CLUSTER_DATABASE_TRANSACTION_NOT_IN_PROGRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5919","0x171F","error 5919","ERROR_CLUSTER_DATABASE_TRANSACTION_NOT_IN_PROGRESS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","database","transaction","not","progress","internal","occurred","there","was","attempt","commit","while"],"errorCode":"5919","eventId":"","severity":"Low","summary":"An internal cluster error occurred. There was an attempt to commit a cluster database transaction while no transaction was in progress.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5919; use the surrounding log entries to confirm it.","resolution":"1. Record where 5919 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_DATABASE_TRANSACTION_NOT_IN_PROGRESS.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5919 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An internal cluster error occurred. There was an attempt to commit a cluster database transaction while no transaction was in progress.\n\nLookup forms: 5919, 0x171F, error 5919, ERROR_CLUSTER_DATABASE_TRANSACTION_NOT_IN_PROGRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5919"]},{"id":1422,"title":"ERROR_CLUSTER_NULL_DATA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5920","0x1720","error 5920","ERROR_CLUSTER_NULL_DATA","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","null","data","internal","occurred","was","not","properly","initialized"],"errorCode":"5920","eventId":"","severity":"Low","summary":"An internal cluster error occurred. Data was not properly initialized.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5920; use the surrounding log entries to confirm it.","resolution":"1. Record where 5920 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NULL_DATA.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5920 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An internal cluster error occurred. Data was not properly initialized.\n\nLookup forms: 5920, 0x1720, error 5920, ERROR_CLUSTER_NULL_DATA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5920"]},{"id":1423,"title":"ERROR_CLUSTER_PARTIAL_READ","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5921","0x1721","error 5921","ERROR_CLUSTER_PARTIAL_READ","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","partial","read","occurred","while","reading","from","stream","data","unexpected","number","bytes","was","returned"],"errorCode":"5921","eventId":"","severity":"Low","summary":"An error occurred while reading from a stream of data. An unexpected number of bytes was returned.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5921; use the surrounding log entries to confirm it.","resolution":"1. Record where 5921 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_PARTIAL_READ.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5921 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An error occurred while reading from a stream of data. An unexpected number of bytes was returned.\n\nLookup forms: 5921, 0x1721, error 5921, ERROR_CLUSTER_PARTIAL_READ. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5921"]},{"id":1424,"title":"ERROR_CLUSTER_PARTIAL_WRITE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5922","0x1722","error 5922","ERROR_CLUSTER_PARTIAL_WRITE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","partial","write","occurred","while","writing","stream","data","the","required","number","bytes","could","not","written"],"errorCode":"5922","eventId":"","severity":"Low","summary":"An error occurred while writing to a stream of data. The required number of bytes could not be written.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5922; use the surrounding log entries to confirm it.","resolution":"1. Record where 5922 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_PARTIAL_WRITE.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5922 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An error occurred while writing to a stream of data. The required number of bytes could not be written.\n\nLookup forms: 5922, 0x1722, error 5922, ERROR_CLUSTER_PARTIAL_WRITE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5922"]},{"id":1425,"title":"ERROR_CLUSTER_CANT_DESERIALIZE_DATA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5923","0x1723","error 5923","ERROR_CLUSTER_CANT_DESERIALIZE_DATA","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","cant","deserialize","data","occurred","while","deserializing","stream"],"errorCode":"5923","eventId":"","severity":"Low","summary":"An error occurred while deserializing a stream of cluster data.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5923; use the surrounding log entries to confirm it.","resolution":"1. Record where 5923 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_CANT_DESERIALIZE_DATA.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5923 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An error occurred while deserializing a stream of cluster data.\n\nLookup forms: 5923, 0x1723, error 5923, ERROR_CLUSTER_CANT_DESERIALIZE_DATA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5923"]},{"id":1426,"title":"ERROR_DEPENDENT_RESOURCE_PROPERTY_CONFLICT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5924","0x1724","error 5924","ERROR_DEPENDENT_RESOURCE_PROPERTY_CONFLICT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dependent","resource","property","conflict","one","more","values","for","this","are","with","associated","its"],"errorCode":"5924","eventId":"","severity":"Low","summary":"One or more property values for this resource are in conflict with one or more property values associated with its dependent resource(s).","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5924; use the surrounding log entries to confirm it.","resolution":"1. Record where 5924 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEPENDENT_RESOURCE_PROPERTY_CONFLICT.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5924 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: One or more property values for this resource are in conflict with one or more property values associated with its dependent resource(s).\n\nLookup forms: 5924, 0x1724, error 5924, ERROR_DEPENDENT_RESOURCE_PROPERTY_CONFLICT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5924"]},{"id":1427,"title":"ERROR_CLUSTER_NO_QUORUM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5925","0x1725","error 5925","ERROR_CLUSTER_NO_QUORUM","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","quorum","nodes","was","not","present","form"],"errorCode":"5925","eventId":"","severity":"Low","summary":"A quorum of cluster nodes was not present to form a cluster.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5925; use the surrounding log entries to confirm it.","resolution":"1. Record where 5925 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NO_QUORUM.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5925 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A quorum of cluster nodes was not present to form a cluster.\n\nLookup forms: 5925, 0x1725, error 5925, ERROR_CLUSTER_NO_QUORUM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5925"]},{"id":1428,"title":"ERROR_CLUSTER_INVALID_IPV6_NETWORK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5926","0x1726","error 5926","ERROR_CLUSTER_INVALID_IPV6_NETWORK","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","cluster","invalid","ipv6","network","the","not","valid","for","address","resource","does","match","configured"],"errorCode":"5926","eventId":"","severity":"High","summary":"The cluster network is not valid for an IPv6 Address resource, or it does not match the configured address.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 5926; use the surrounding log entries to confirm it.","resolution":"1. Record where 5926 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review the response body, request permissions, rate limits, and service health before retrying.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_INVALID_IPV6_NETWORK.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5926 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster network is not valid for an IPv6 Address resource, or it does not match the configured address.\n\nLookup forms: 5926, 0x1726, error 5926, ERROR_CLUSTER_INVALID_IPV6_NETWORK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5926"]},{"id":1429,"title":"ERROR_CLUSTER_INVALID_IPV6_TUNNEL_NETWORK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5927","0x1727","error 5927","ERROR_CLUSTER_INVALID_IPV6_TUNNEL_NETWORK","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","cluster","invalid","ipv6","tunnel","network","the","not","valid","for","resource","check","configuration","address","which","depends"],"errorCode":"5927","eventId":"","severity":"High","summary":"The cluster network is not valid for an IPv6 Tunnel resource. Check the configuration of the IP Address resource on which the IPv6 Tunnel resource depends.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 5927; use the surrounding log entries to confirm it.","resolution":"1. Record where 5927 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review the response body, request permissions, rate limits, and service health before retrying.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_INVALID_IPV6_TUNNEL_NETWORK.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5927 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster network is not valid for an IPv6 Tunnel resource. Check the configuration of the IP Address resource on which the IPv6 Tunnel resource depends.\n\nLookup forms: 5927, 0x1727, error 5927, ERROR_CLUSTER_INVALID_IPV6_TUNNEL_NETWORK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5927"]},{"id":1430,"title":"ERROR_QUORUM_NOT_ALLOWED_IN_THIS_GROUP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5928","0x1728","error 5928","ERROR_QUORUM_NOT_ALLOWED_IN_THIS_GROUP","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","quorum","not","allowed","this","group","resource","cannot","reside","the","available","storage"],"errorCode":"5928","eventId":"","severity":"Medium","summary":"Quorum resource cannot reside in the Available Storage group.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 5928; use the surrounding log entries to confirm it.","resolution":"1. Record where 5928 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_QUORUM_NOT_ALLOWED_IN_THIS_GROUP.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5928 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Quorum resource cannot reside in the Available Storage group.\n\nLookup forms: 5928, 0x1728, error 5928, ERROR_QUORUM_NOT_ALLOWED_IN_THIS_GROUP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5928"]},{"id":1431,"title":"ERROR_DEPENDENCY_TREE_TOO_COMPLEX","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5929","0x1729","error 5929","ERROR_DEPENDENCY_TREE_TOO_COMPLEX","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dependency","tree","too","complex","the","dependencies","for","this","resource","are","nested","deeply"],"errorCode":"5929","eventId":"","severity":"Low","summary":"The dependencies for this resource are nested too deeply.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5929; use the surrounding log entries to confirm it.","resolution":"1. Record where 5929 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEPENDENCY_TREE_TOO_COMPLEX.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5929 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The dependencies for this resource are nested too deeply.\n\nLookup forms: 5929, 0x1729, error 5929, ERROR_DEPENDENCY_TREE_TOO_COMPLEX. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5929"]},{"id":1432,"title":"ERROR_EXCEPTION_IN_RESOURCE_CALL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5930","0x172A","error 5930","ERROR_EXCEPTION_IN_RESOURCE_CALL","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","exception","resource","call","the","into","dll","raised","unhandled"],"errorCode":"5930","eventId":"","severity":"Low","summary":"The call into the resource DLL raised an unhandled exception.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 5930; use the surrounding log entries to confirm it.","resolution":"1. Record where 5930 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EXCEPTION_IN_RESOURCE_CALL.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5930 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The call into the resource DLL raised an unhandled exception.\n\nLookup forms: 5930, 0x172A, error 5930, ERROR_EXCEPTION_IN_RESOURCE_CALL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5930"]},{"id":1433,"title":"ERROR_CLUSTER_RHS_FAILED_INITIALIZATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5931","0x172B","error 5931","ERROR_CLUSTER_RHS_FAILED_INITIALIZATION","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","cluster","rhs","failed","initialization","the","process","initialize"],"errorCode":"5931","eventId":"","severity":"High","summary":"The RHS process failed to initialize.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 5931; use the surrounding log entries to confirm it.","resolution":"1. Record where 5931 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_RHS_FAILED_INITIALIZATION.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5931 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The RHS process failed to initialize.\n\nLookup forms: 5931, 0x172B, error 5931, ERROR_CLUSTER_RHS_FAILED_INITIALIZATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5931"]},{"id":1434,"title":"ERROR_CLUSTER_NOT_INSTALLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5932","0x172C","error 5932","ERROR_CLUSTER_NOT_INSTALLED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","cluster","not","installed","the","failover","clustering","feature","this","node"],"errorCode":"5932","eventId":"","severity":"Low","summary":"The Failover Clustering feature is not installed on this node.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 5932; use the surrounding log entries to confirm it.","resolution":"1. Record where 5932 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NOT_INSTALLED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5932 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Failover Clustering feature is not installed on this node.\n\nLookup forms: 5932, 0x172C, error 5932, ERROR_CLUSTER_NOT_INSTALLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5932"]},{"id":1435,"title":"ERROR_CLUSTER_RESOURCES_MUST_BE_ONLINE_ON_THE_SAME_NODE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5933","0x172D","error 5933","ERROR_CLUSTER_RESOURCES_MUST_BE_ONLINE_ON_THE_SAME_NODE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","resources","must","online","the","same","node","for","this","operation"],"errorCode":"5933","eventId":"","severity":"Low","summary":"The resources must be online on the same node for this operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5933; use the surrounding log entries to confirm it.","resolution":"1. Record where 5933 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_RESOURCES_MUST_BE_ONLINE_ON_THE_SAME_NODE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5933 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The resources must be online on the same node for this operation.\n\nLookup forms: 5933, 0x172D, error 5933, ERROR_CLUSTER_RESOURCES_MUST_BE_ONLINE_ON_THE_SAME_NODE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5933"]},{"id":1436,"title":"ERROR_CLUSTER_MAX_NODES_IN_CLUSTER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5934","0x172E","error 5934","ERROR_CLUSTER_MAX_NODES_IN_CLUSTER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","max","nodes","new","node","can","not","added","since","this","already","its","maximum","number"],"errorCode":"5934","eventId":"","severity":"Low","summary":"A new node can not be added since this cluster is already at its maximum number of nodes.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5934; use the surrounding log entries to confirm it.","resolution":"1. Record where 5934 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_MAX_NODES_IN_CLUSTER.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5934 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A new node can not be added since this cluster is already at its maximum number of nodes.\n\nLookup forms: 5934, 0x172E, error 5934, ERROR_CLUSTER_MAX_NODES_IN_CLUSTER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5934"]},{"id":1437,"title":"ERROR_CLUSTER_TOO_MANY_NODES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5935","0x172F","error 5935","ERROR_CLUSTER_TOO_MANY_NODES","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","too","many","nodes","this","can","not","created","since","the","specified","number","exceeds","maximum","allowed","limit"],"errorCode":"5935","eventId":"","severity":"Low","summary":"This cluster can not be created since the specified number of nodes exceeds the maximum allowed limit.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5935; use the surrounding log entries to confirm it.","resolution":"1. Record where 5935 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_TOO_MANY_NODES.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5935 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This cluster can not be created since the specified number of nodes exceeds the maximum allowed limit.\n\nLookup forms: 5935, 0x172F, error 5935, ERROR_CLUSTER_TOO_MANY_NODES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5935"]},{"id":1438,"title":"ERROR_CLUSTER_OBJECT_ALREADY_USED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5936","0x1730","error 5936","ERROR_CLUSTER_OBJECT_ALREADY_USED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","object","already","used","attempt","use","the","specified","name","failed","because","enabled","computer","with","given","exists","domain"],"errorCode":"5936","eventId":"","severity":"High","summary":"An attempt to use the specified cluster name failed because an enabled computer object with the given name already exists in the domain.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5936; use the surrounding log entries to confirm it.","resolution":"1. Record where 5936 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_OBJECT_ALREADY_USED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5936 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt to use the specified cluster name failed because an enabled computer object with the given name already exists in the domain.\n\nLookup forms: 5936, 0x1730, error 5936, ERROR_CLUSTER_OBJECT_ALREADY_USED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5936"]},{"id":1439,"title":"ERROR_NONCORE_GROUPS_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5937","0x1731","error 5937","ERROR_NONCORE_GROUPS_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","noncore","groups","found","this","cluster","cannot","destroyed","has","non","core","application","which","must","deleted","before","the","can"],"errorCode":"5937","eventId":"","severity":"Medium","summary":"This cluster cannot be destroyed. It has non-core application groups which must be deleted before the cluster can be destroyed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5937; use the surrounding log entries to confirm it.","resolution":"1. Record where 5937 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NONCORE_GROUPS_FOUND.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5937 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This cluster cannot be destroyed. It has non-core application groups which must be deleted before the cluster can be destroyed.\n\nLookup forms: 5937, 0x1731, error 5937, ERROR_NONCORE_GROUPS_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5937"]},{"id":1440,"title":"ERROR_FILE_SHARE_RESOURCE_CONFLICT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5938","0x1732","error 5938","ERROR_FILE_SHARE_RESOURCE_CONFLICT","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","file","share","resource","conflict","associated","with","witness","cannot","hosted","this","cluster","any","its","nodes"],"errorCode":"5938","eventId":"","severity":"Medium","summary":"File share associated with file share witness resource cannot be hosted by this cluster or any of its nodes.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 5938; use the surrounding log entries to confirm it.","resolution":"1. Record where 5938 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Check available memory, disk capacity, quotas, and system resource pressure.\n5. Review the response body, request permissions, rate limits, and service health before retrying.\n6. Review Event Viewer and the application or service log for the same timestamp and code.\n7. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FILE_SHARE_RESOURCE_CONFLICT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5938 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: File share associated with file share witness resource cannot be hosted by this cluster or any of its nodes.\n\nLookup forms: 5938, 0x1732, error 5938, ERROR_FILE_SHARE_RESOURCE_CONFLICT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5938"]},{"id":1441,"title":"ERROR_CLUSTER_EVICT_INVALID_REQUEST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5939","0x1733","error 5939","ERROR_CLUSTER_EVICT_INVALID_REQUEST","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","evict","invalid","request","eviction","this","node","time","due","quorum","requirements","will","result","shutdown","the","last","destroy","command","should","used"],"errorCode":"5939","eventId":"","severity":"Medium","summary":"Eviction of this node is invalid at this time. Due to quorum requirements node eviction will result in cluster shutdown. If it is the last node in the cluster, destroy cluster command should be used.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5939; use the surrounding log entries to confirm it.","resolution":"1. Record where 5939 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_EVICT_INVALID_REQUEST.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5939 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Eviction of this node is invalid at this time. Due to quorum requirements node eviction will result in cluster shutdown. If it is the last node in the cluster, destroy cluster command should be used.\n\nLookup forms: 5939, 0x1733, error 5939, ERROR_CLUSTER_EVICT_INVALID_REQUEST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5939"]},{"id":1442,"title":"ERROR_CLUSTER_SINGLETON_RESOURCE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5940","0x1734","error 5940","ERROR_CLUSTER_SINGLETON_RESOURCE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","singleton","resource","only","one","instance","this","type","allowed","the"],"errorCode":"5940","eventId":"","severity":"Low","summary":"Only one instance of this resource type is allowed in the cluster.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5940; use the surrounding log entries to confirm it.","resolution":"1. Record where 5940 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_SINGLETON_RESOURCE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5940 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Only one instance of this resource type is allowed in the cluster.\n\nLookup forms: 5940, 0x1734, error 5940, ERROR_CLUSTER_SINGLETON_RESOURCE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5940"]},{"id":1443,"title":"ERROR_CLUSTER_GROUP_SINGLETON_RESOURCE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5941","0x1735","error 5941","ERROR_CLUSTER_GROUP_SINGLETON_RESOURCE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","group","singleton","resource","only","one","instance","this","type","allowed","per"],"errorCode":"5941","eventId":"","severity":"Low","summary":"Only one instance of this resource type is allowed per resource group.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5941; use the surrounding log entries to confirm it.","resolution":"1. Record where 5941 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_GROUP_SINGLETON_RESOURCE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5941 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Only one instance of this resource type is allowed per resource group.\n\nLookup forms: 5941, 0x1735, error 5941, ERROR_CLUSTER_GROUP_SINGLETON_RESOURCE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5941"]},{"id":1444,"title":"ERROR_CLUSTER_RESOURCE_PROVIDER_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5942","0x1736","error 5942","ERROR_CLUSTER_RESOURCE_PROVIDER_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","resource","provider","failed","the","come","online","due","failure","one","more","resources"],"errorCode":"5942","eventId":"","severity":"High","summary":"The resource failed to come online due to the failure of one or more provider resources.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5942; use the surrounding log entries to confirm it.","resolution":"1. Record where 5942 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_RESOURCE_PROVIDER_FAILED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5942 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The resource failed to come online due to the failure of one or more provider resources.\n\nLookup forms: 5942, 0x1736, error 5942, ERROR_CLUSTER_RESOURCE_PROVIDER_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5942"]},{"id":1445,"title":"ERROR_CLUSTER_RESOURCE_CONFIGURATION_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5943","0x1737","error 5943","ERROR_CLUSTER_RESOURCE_CONFIGURATION_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","resource","configuration","the","has","indicated","that","cannot","come","online","any","node"],"errorCode":"5943","eventId":"","severity":"Medium","summary":"The resource has indicated that it cannot come online on any node.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5943; use the surrounding log entries to confirm it.","resolution":"1. Record where 5943 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_RESOURCE_CONFIGURATION_ERROR.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5943 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The resource has indicated that it cannot come online on any node.\n\nLookup forms: 5943, 0x1737, error 5943, ERROR_CLUSTER_RESOURCE_CONFIGURATION_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5943"]},{"id":1446,"title":"ERROR_CLUSTER_GROUP_BUSY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5944","0x1738","error 5944","ERROR_CLUSTER_GROUP_BUSY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","group","busy","the","current","operation","cannot","performed","this","time"],"errorCode":"5944","eventId":"","severity":"Medium","summary":"The current operation cannot be performed on this group at this time.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5944; use the surrounding log entries to confirm it.","resolution":"1. Record where 5944 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_GROUP_BUSY.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5944 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The current operation cannot be performed on this group at this time.\n\nLookup forms: 5944, 0x1738, error 5944, ERROR_CLUSTER_GROUP_BUSY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5944"]},{"id":1447,"title":"ERROR_CLUSTER_NOT_SHARED_VOLUME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5945","0x1739","error 5945","ERROR_CLUSTER_NOT_SHARED_VOLUME","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","cluster","not","shared","volume","the","directory","file","located"],"errorCode":"5945","eventId":"","severity":"Low","summary":"The directory or file is not located on a cluster shared volume.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 5945; use the surrounding log entries to confirm it.","resolution":"1. Record where 5945 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NOT_SHARED_VOLUME.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5945 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory or file is not located on a cluster shared volume.\n\nLookup forms: 5945, 0x1739, error 5945, ERROR_CLUSTER_NOT_SHARED_VOLUME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5945"]},{"id":1448,"title":"ERROR_CLUSTER_INVALID_SECURITY_DESCRIPTOR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5946","0x173A","error 5946","ERROR_CLUSTER_INVALID_SECURITY_DESCRIPTOR","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","cluster","invalid","security","descriptor","the","does","not","meet","requirements","for"],"errorCode":"5946","eventId":"","severity":"Low","summary":"The Security Descriptor does not meet the requirements for a cluster.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 5946; use the surrounding log entries to confirm it.","resolution":"1. Record where 5946 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_INVALID_SECURITY_DESCRIPTOR.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5946 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Security Descriptor does not meet the requirements for a cluster.\n\nLookup forms: 5946, 0x173A, error 5946, ERROR_CLUSTER_INVALID_SECURITY_DESCRIPTOR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5946"]},{"id":1449,"title":"ERROR_CLUSTER_SHARED_VOLUMES_IN_USE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5947","0x173B","error 5947","ERROR_CLUSTER_SHARED_VOLUMES_IN_USE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","cluster","shared","volumes","use","there","one","more","resources","configured","the","those","must","moved","available","storage","order","for","operation","succeed"],"errorCode":"5947","eventId":"","severity":"Low","summary":"There is one or more shared volumes resources configured in the cluster. Those resources must be moved to available storage in order for operation to succeed.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 5947; use the surrounding log entries to confirm it.","resolution":"1. Record where 5947 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_SHARED_VOLUMES_IN_USE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5947 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There is one or more shared volumes resources configured in the cluster. Those resources must be moved to available storage in order for operation to succeed.\n\nLookup forms: 5947, 0x173B, error 5947, ERROR_CLUSTER_SHARED_VOLUMES_IN_USE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5947"]},{"id":1450,"title":"ERROR_CLUSTER_USE_SHARED_VOLUMES_API","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5948","0x173C","error 5948","ERROR_CLUSTER_USE_SHARED_VOLUMES_API","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","cluster","use","shared","volumes","api","this","group","resource","cannot","directly","manipulated","volume","apis","perform","desired","operation"],"errorCode":"5948","eventId":"","severity":"Medium","summary":"This group or resource cannot be directly manipulated. Use shared volume APIs to perform desired operation.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 5948; use the surrounding log entries to confirm it.","resolution":"1. Record where 5948 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_USE_SHARED_VOLUMES_API.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5948 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This group or resource cannot be directly manipulated. Use shared volume APIs to perform desired operation.\n\nLookup forms: 5948, 0x173C, error 5948, ERROR_CLUSTER_USE_SHARED_VOLUMES_API. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5948"]},{"id":1451,"title":"ERROR_CLUSTER_BACKUP_IN_PROGRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5949","0x173D","error 5949","ERROR_CLUSTER_BACKUP_IN_PROGRESS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","backup","progress","back","please","wait","for","completion","before","trying","this","operation","again"],"errorCode":"5949","eventId":"","severity":"Low","summary":"Back up is in progress. Please wait for backup completion before trying this operation again.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5949; use the surrounding log entries to confirm it.","resolution":"1. Record where 5949 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_BACKUP_IN_PROGRESS.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5949 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Back up is in progress. Please wait for backup completion before trying this operation again.\n\nLookup forms: 5949, 0x173D, error 5949, ERROR_CLUSTER_BACKUP_IN_PROGRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5949"]},{"id":1452,"title":"ERROR_NON_CSV_PATH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5950","0x173E","error 5950","ERROR_NON_CSV_PATH","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","non","csv","path","the","does","not","belong","cluster","shared","volume"],"errorCode":"5950","eventId":"","severity":"Low","summary":"The path does not belong to a cluster shared volume.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 5950; use the surrounding log entries to confirm it.","resolution":"1. Record where 5950 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NON_CSV_PATH.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5950 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The path does not belong to a cluster shared volume.\n\nLookup forms: 5950, 0x173E, error 5950, ERROR_NON_CSV_PATH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5950"]},{"id":1453,"title":"ERROR_CSV_VOLUME_NOT_LOCAL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5951","0x173F","error 5951","ERROR_CSV_VOLUME_NOT_LOCAL","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","csv","volume","not","local","the","cluster","shared","locally","mounted","this","node"],"errorCode":"5951","eventId":"","severity":"Low","summary":"The cluster shared volume is not locally mounted on this node.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 5951; use the surrounding log entries to confirm it.","resolution":"1. Record where 5951 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CSV_VOLUME_NOT_LOCAL.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5951 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster shared volume is not locally mounted on this node.\n\nLookup forms: 5951, 0x173F, error 5951, ERROR_CSV_VOLUME_NOT_LOCAL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5951"]},{"id":1454,"title":"ERROR_CLUSTER_WATCHDOG_TERMINATING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5952","0x1740","error 5952","ERROR_CLUSTER_WATCHDOG_TERMINATING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","watchdog","terminating","the"],"errorCode":"5952","eventId":"","severity":"Low","summary":"The cluster watchdog is terminating.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5952; use the surrounding log entries to confirm it.","resolution":"1. Record where 5952 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_WATCHDOG_TERMINATING.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5952 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cluster watchdog is terminating.\n\nLookup forms: 5952, 0x1740, error 5952, ERROR_CLUSTER_WATCHDOG_TERMINATING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5952"]},{"id":1455,"title":"ERROR_CLUSTER_RESOURCE_VETOED_MOVE_INCOMPATIBLE_NODES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5953","0x1741","error 5953","ERROR_CLUSTER_RESOURCE_VETOED_MOVE_INCOMPATIBLE_NODES","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","resource","vetoed","move","incompatible","nodes","between","two","because","they","are"],"errorCode":"5953","eventId":"","severity":"Low","summary":"A resource vetoed a move between two nodes because they are incompatible.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5953; use the surrounding log entries to confirm it.","resolution":"1. Record where 5953 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_RESOURCE_VETOED_MOVE_INCOMPATIBLE_NODES.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5953 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A resource vetoed a move between two nodes because they are incompatible.\n\nLookup forms: 5953, 0x1741, error 5953, ERROR_CLUSTER_RESOURCE_VETOED_MOVE_INCOMPATIBLE_NODES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5953"]},{"id":1456,"title":"ERROR_CLUSTER_INVALID_NODE_WEIGHT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5954","0x1742","error 5954","ERROR_CLUSTER_INVALID_NODE_WEIGHT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","cluster","invalid","node","weight","the","request","either","because","cannot","changed","while","disk","only","quorum","mode","changing","would","violate","minimum","requirements"],"errorCode":"5954","eventId":"","severity":"Medium","summary":"The request is invalid either because node weight cannot be changed while the cluster is in disk-only quorum mode, or because changing the node weight would violate the minimum cluster quorum requirements.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 5954; use the surrounding log entries to confirm it.","resolution":"1. Record where 5954 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_INVALID_NODE_WEIGHT.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5954 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The request is invalid either because node weight cannot be changed while the cluster is in disk-only quorum mode, or because changing the node weight would violate the minimum cluster quorum requirements.\n\nLookup forms: 5954, 0x1742, error 5954, ERROR_CLUSTER_INVALID_NODE_WEIGHT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5954"]},{"id":1457,"title":"ERROR_CLUSTER_RESOURCE_VETOED_CALL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5955","0x1743","error 5955","ERROR_CLUSTER_RESOURCE_VETOED_CALL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","resource","vetoed","call","the"],"errorCode":"5955","eventId":"","severity":"Low","summary":"The resource vetoed the call.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5955; use the surrounding log entries to confirm it.","resolution":"1. Record where 5955 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_RESOURCE_VETOED_CALL.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5955 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The resource vetoed the call.\n\nLookup forms: 5955, 0x1743, error 5955, ERROR_CLUSTER_RESOURCE_VETOED_CALL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5955"]},{"id":1458,"title":"ERROR_RESMON_SYSTEM_RESOURCES_LACKING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5956","0x1744","error 5956","ERROR_RESMON_SYSTEM_RESOURCES_LACKING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","resmon","system","resources","lacking","resource","could","not","start","run","because","reserve","sufficient"],"errorCode":"5956","eventId":"","severity":"Low","summary":"Resource could not start or run because it could not reserve sufficient system resources.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5956; use the surrounding log entries to confirm it.","resolution":"1. Record where 5956 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESMON_SYSTEM_RESOURCES_LACKING.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5956 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Resource could not start or run because it could not reserve sufficient system resources.\n\nLookup forms: 5956, 0x1744, error 5956, ERROR_RESMON_SYSTEM_RESOURCES_LACKING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5956"]},{"id":1459,"title":"ERROR_CLUSTER_RESOURCE_VETOED_MOVE_NOT_ENOUGH_RESOURCES_ON_DESTINATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5957","0x1745","error 5957","ERROR_CLUSTER_RESOURCE_VETOED_MOVE_NOT_ENOUGH_RESOURCES_ON_DESTINATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","resource","vetoed","move","not","enough","resources","destination","between","two","nodes","because","the","currently","does","have","complete","operation"],"errorCode":"5957","eventId":"","severity":"Low","summary":"A resource vetoed a move between two nodes because the destination currently does not have enough resources to complete the operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5957; use the surrounding log entries to confirm it.","resolution":"1. Record where 5957 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_RESOURCE_VETOED_MOVE_NOT_ENOUGH_RESOURCES_ON_DESTINATION.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5957 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A resource vetoed a move between two nodes because the destination currently does not have enough resources to complete the operation.\n\nLookup forms: 5957, 0x1745, error 5957, ERROR_CLUSTER_RESOURCE_VETOED_MOVE_NOT_ENOUGH_RESOURCES_ON_DESTINATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5957"]},{"id":1460,"title":"ERROR_CLUSTER_RESOURCE_VETOED_MOVE_NOT_ENOUGH_RESOURCES_ON_SOURCE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5958","0x1746","error 5958","ERROR_CLUSTER_RESOURCE_VETOED_MOVE_NOT_ENOUGH_RESOURCES_ON_SOURCE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","resource","vetoed","move","not","enough","resources","source","between","two","nodes","because","the","currently","does","have","complete","operation"],"errorCode":"5958","eventId":"","severity":"Low","summary":"A resource vetoed a move between two nodes because the source currently does not have enough resources to complete the operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5958; use the surrounding log entries to confirm it.","resolution":"1. Record where 5958 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_RESOURCE_VETOED_MOVE_NOT_ENOUGH_RESOURCES_ON_SOURCE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5958 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A resource vetoed a move between two nodes because the source currently does not have enough resources to complete the operation.\n\nLookup forms: 5958, 0x1746, error 5958, ERROR_CLUSTER_RESOURCE_VETOED_MOVE_NOT_ENOUGH_RESOURCES_ON_SOURCE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5958"]},{"id":1461,"title":"ERROR_CLUSTER_GROUP_QUEUED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5959","0x1747","error 5959","ERROR_CLUSTER_GROUP_QUEUED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","group","queued","the","requested","operation","can","not","completed","because","for"],"errorCode":"5959","eventId":"","severity":"Low","summary":"The requested operation can not be completed because the group is queued for an operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5959; use the surrounding log entries to confirm it.","resolution":"1. Record where 5959 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_GROUP_QUEUED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5959 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested operation can not be completed because the group is queued for an operation.\n\nLookup forms: 5959, 0x1747, error 5959, ERROR_CLUSTER_GROUP_QUEUED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5959"]},{"id":1462,"title":"ERROR_CLUSTER_RESOURCE_LOCKED_STATUS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5960","0x1748","error 5960","ERROR_CLUSTER_RESOURCE_LOCKED_STATUS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","resource","locked","status","the","requested","operation","can","not","completed","because","has"],"errorCode":"5960","eventId":"","severity":"High","summary":"The requested operation can not be completed because a resource has locked status.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5960; use the surrounding log entries to confirm it.","resolution":"1. Record where 5960 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_RESOURCE_LOCKED_STATUS.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5960 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested operation can not be completed because a resource has locked status.\n\nLookup forms: 5960, 0x1748, error 5960, ERROR_CLUSTER_RESOURCE_LOCKED_STATUS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5960"]},{"id":1463,"title":"ERROR_CLUSTER_SHARED_VOLUME_FAILOVER_NOT_ALLOWED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5961","0x1749","error 5961","ERROR_CLUSTER_SHARED_VOLUME_FAILOVER_NOT_ALLOWED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","cluster","shared","volume","failover","not","allowed","the","resource","cannot","move","another","node","because","vetoed","operation"],"errorCode":"5961","eventId":"","severity":"Medium","summary":"The resource cannot move to another node because a cluster shared volume vetoed the operation.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 5961; use the surrounding log entries to confirm it.","resolution":"1. Record where 5961 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_SHARED_VOLUME_FAILOVER_NOT_ALLOWED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5961 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The resource cannot move to another node because a cluster shared volume vetoed the operation.\n\nLookup forms: 5961, 0x1749, error 5961, ERROR_CLUSTER_SHARED_VOLUME_FAILOVER_NOT_ALLOWED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5961"]},{"id":1464,"title":"ERROR_CLUSTER_NODE_DRAIN_IN_PROGRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5962","0x174A","error 5962","ERROR_CLUSTER_NODE_DRAIN_IN_PROGRESS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","node","drain","progress","already"],"errorCode":"5962","eventId":"","severity":"Low","summary":"A node drain is already in progress.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5962; use the surrounding log entries to confirm it.","resolution":"1. Record where 5962 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_NODE_DRAIN_IN_PROGRESS.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5962 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A node drain is already in progress.\n\nLookup forms: 5962, 0x174A, error 5962, ERROR_CLUSTER_NODE_DRAIN_IN_PROGRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5962"]},{"id":1465,"title":"ERROR_CLUSTER_DISK_NOT_CONNECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5963","0x174B","error 5963","ERROR_CLUSTER_DISK_NOT_CONNECTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","cluster","disk","not","connected","clustered","storage","the","node"],"errorCode":"5963","eventId":"","severity":"Low","summary":"Clustered storage is not connected to the node.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 5963; use the surrounding log entries to confirm it.","resolution":"1. Record where 5963 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_DISK_NOT_CONNECTED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5963 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Clustered storage is not connected to the node.\n\nLookup forms: 5963, 0x174B, error 5963, ERROR_CLUSTER_DISK_NOT_CONNECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5963"]},{"id":1466,"title":"ERROR_DISK_NOT_CSV_CAPABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5964","0x174C","error 5964","ERROR_DISK_NOT_CSV_CAPABLE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","disk","not","csv","capable","the","configured","way","used","with","disks","must","have","least","one","partition","that","formatted","ntfs"],"errorCode":"5964","eventId":"","severity":"Low","summary":"The disk is not configured in a way to be used with CSV. CSV disks must have at least one partition that is formatted with NTFS.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 5964; use the surrounding log entries to confirm it.","resolution":"1. Record where 5964 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DISK_NOT_CSV_CAPABLE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5964 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The disk is not configured in a way to be used with CSV. CSV disks must have at least one partition that is formatted with NTFS.\n\nLookup forms: 5964, 0x174C, error 5964, ERROR_DISK_NOT_CSV_CAPABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5964"]},{"id":1467,"title":"ERROR_RESOURCE_NOT_IN_AVAILABLE_STORAGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5965","0x174D","error 5965","ERROR_RESOURCE_NOT_IN_AVAILABLE_STORAGE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","resource","not","available","storage","the","must","part","group","complete","this","action"],"errorCode":"5965","eventId":"","severity":"Low","summary":"The resource must be part of the Available Storage group to complete this action.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 5965; use the surrounding log entries to confirm it.","resolution":"1. Record where 5965 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESOURCE_NOT_IN_AVAILABLE_STORAGE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5965 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The resource must be part of the Available Storage group to complete this action.\n\nLookup forms: 5965, 0x174D, error 5965, ERROR_RESOURCE_NOT_IN_AVAILABLE_STORAGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5965"]},{"id":1468,"title":"ERROR_CLUSTER_SHARED_VOLUME_REDIRECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5966","0x174E","error 5966","ERROR_CLUSTER_SHARED_VOLUME_REDIRECTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","cluster","shared","volume","redirected","csvfs","failed","operation","mode"],"errorCode":"5966","eventId":"","severity":"High","summary":"CSVFS failed operation as volume is in redirected mode.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 5966; use the surrounding log entries to confirm it.","resolution":"1. Record where 5966 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_SHARED_VOLUME_REDIRECTED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5966 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: CSVFS failed operation as volume is in redirected mode.\n\nLookup forms: 5966, 0x174E, error 5966, ERROR_CLUSTER_SHARED_VOLUME_REDIRECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5966"]},{"id":1469,"title":"ERROR_CLUSTER_SHARED_VOLUME_NOT_REDIRECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5967","0x174F","error 5967","ERROR_CLUSTER_SHARED_VOLUME_NOT_REDIRECTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","cluster","shared","volume","not","redirected","csvfs","failed","operation","mode"],"errorCode":"5967","eventId":"","severity":"High","summary":"CSVFS failed operation as volume is not in redirected mode.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 5967; use the surrounding log entries to confirm it.","resolution":"1. Record where 5967 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_SHARED_VOLUME_NOT_REDIRECTED.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5967 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: CSVFS failed operation as volume is not in redirected mode.\n\nLookup forms: 5967, 0x174F, error 5967, ERROR_CLUSTER_SHARED_VOLUME_NOT_REDIRECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5967"]},{"id":1470,"title":"ERROR_CLUSTER_CANNOT_RETURN_PROPERTIES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5968","0x1750","error 5968","ERROR_CLUSTER_CANNOT_RETURN_PROPERTIES","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","cannot","return","properties","returned","this","time"],"errorCode":"5968","eventId":"","severity":"Medium","summary":"Cluster properties cannot be returned at this time.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5968; use the surrounding log entries to confirm it.","resolution":"1. Record where 5968 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_CANNOT_RETURN_PROPERTIES.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5968 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cluster properties cannot be returned at this time.\n\nLookup forms: 5968, 0x1750, error 5968, ERROR_CLUSTER_CANNOT_RETURN_PROPERTIES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5968"]},{"id":1471,"title":"ERROR_CLUSTER_RESOURCE_CONTAINS_UNSUPPORTED_DIFF_AREA_FOR_SHARED_VOLUMES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5969","0x1751","error 5969","ERROR_CLUSTER_RESOURCE_CONTAINS_UNSUPPORTED_DIFF_AREA_FOR_SHARED_VOLUMES","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","cluster","resource","contains","unsupported","diff","area","for","shared","volumes","the","clustered","disk","software","snapshot","that","are","not","supported"],"errorCode":"5969","eventId":"","severity":"Medium","summary":"The clustered disk resource contains software snapshot diff area that are not supported for Cluster Shared Volumes.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 5969; use the surrounding log entries to confirm it.","resolution":"1. Record where 5969 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_RESOURCE_CONTAINS_UNSUPPORTED_DIFF_AREA_FOR_SHARED_VOLUMES.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5969 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The clustered disk resource contains software snapshot diff area that are not supported for Cluster Shared Volumes.\n\nLookup forms: 5969, 0x1751, error 5969, ERROR_CLUSTER_RESOURCE_CONTAINS_UNSUPPORTED_DIFF_AREA_FOR_SHARED_VOLUMES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5969"]},{"id":1472,"title":"ERROR_CLUSTER_RESOURCE_IS_IN_MAINTENANCE_MODE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5970","0x1752","error 5970","ERROR_CLUSTER_RESOURCE_IS_IN_MAINTENANCE_MODE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","resource","maintenance","mode","the","operation","cannot","completed","because"],"errorCode":"5970","eventId":"","severity":"Medium","summary":"The operation cannot be completed because the resource is in maintenance mode.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5970; use the surrounding log entries to confirm it.","resolution":"1. Record where 5970 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_RESOURCE_IS_IN_MAINTENANCE_MODE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5970 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation cannot be completed because the resource is in maintenance mode.\n\nLookup forms: 5970, 0x1752, error 5970, ERROR_CLUSTER_RESOURCE_IS_IN_MAINTENANCE_MODE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5970"]},{"id":1473,"title":"ERROR_CLUSTER_AFFINITY_CONFLICT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5971","0x1753","error 5971","ERROR_CLUSTER_AFFINITY_CONFLICT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","affinity","conflict","the","operation","cannot","completed","because","conflicts"],"errorCode":"5971","eventId":"","severity":"Medium","summary":"The operation cannot be completed because of cluster affinity conflicts.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5971; use the surrounding log entries to confirm it.","resolution":"1. Record where 5971 occurred and reproduce the operation if it is safe to do so.\n2. Review the response body, request permissions, rate limits, and service health before retrying.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_AFFINITY_CONFLICT.\n\nWe recommend performing the following corrective action: Review the response body, request permissions, rate limits, and service health before retrying. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5971 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation cannot be completed because of cluster affinity conflicts.\n\nLookup forms: 5971, 0x1753, error 5971, ERROR_CLUSTER_AFFINITY_CONFLICT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5971"]},{"id":1474,"title":"ERROR_CLUSTER_RESOURCE_IS_REPLICA_VIRTUAL_MACHINE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["5972","0x1754","error 5972","ERROR_CLUSTER_RESOURCE_IS_REPLICA_VIRTUAL_MACHINE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cluster","resource","replica","virtual","machine","the","operation","cannot","completed","because"],"errorCode":"5972","eventId":"","severity":"Medium","summary":"The operation cannot be completed because the resource is a replica virtual machine.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 5972; use the surrounding log entries to confirm it.","resolution":"1. Record where 5972 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CLUSTER_RESOURCE_IS_REPLICA_VIRTUAL_MACHINE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 5972 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation cannot be completed because the resource is a replica virtual machine.\n\nLookup forms: 5972, 0x1754, error 5972, ERROR_CLUSTER_RESOURCE_IS_REPLICA_VIRTUAL_MACHINE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["5972"]},{"id":1475,"title":"ERROR_ENCRYPTION_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6000","0x1770","error 6000","ERROR_ENCRYPTION_FAILED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","encryption","failed","the","specified","file","could","not","encrypted"],"errorCode":"6000","eventId":"","severity":"Low","summary":"The specified file could not be encrypted.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6000; use the surrounding log entries to confirm it.","resolution":"1. Record where 6000 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ENCRYPTION_FAILED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6000 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified file could not be encrypted.\n\nLookup forms: 6000, 0x1770, error 6000, ERROR_ENCRYPTION_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6000"]},{"id":1476,"title":"ERROR_DECRYPTION_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6001","0x1771","error 6001","ERROR_DECRYPTION_FAILED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","decryption","failed","the","specified","file","could","not","decrypted"],"errorCode":"6001","eventId":"","severity":"Low","summary":"The specified file could not be decrypted.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6001; use the surrounding log entries to confirm it.","resolution":"1. Record where 6001 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DECRYPTION_FAILED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6001 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified file could not be decrypted.\n\nLookup forms: 6001, 0x1771, error 6001, ERROR_DECRYPTION_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6001"]},{"id":1477,"title":"ERROR_FILE_ENCRYPTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6002","0x1772","error 6002","ERROR_FILE_ENCRYPTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","file","encrypted","the","specified","and","user","does","not","have","ability","decrypt"],"errorCode":"6002","eventId":"","severity":"Low","summary":"The specified file is encrypted and the user does not have the ability to decrypt it.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6002; use the surrounding log entries to confirm it.","resolution":"1. Record where 6002 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FILE_ENCRYPTED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6002 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified file is encrypted and the user does not have the ability to decrypt it.\n\nLookup forms: 6002, 0x1772, error 6002, ERROR_FILE_ENCRYPTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6002"]},{"id":1478,"title":"ERROR_NO_RECOVERY_POLICY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6003","0x1773","error 6003","ERROR_NO_RECOVERY_POLICY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","recovery","policy","there","valid","encryption","configured","for","this","system"],"errorCode":"6003","eventId":"","severity":"Low","summary":"There is no valid encryption recovery policy configured for this system.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6003; use the surrounding log entries to confirm it.","resolution":"1. Record where 6003 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_RECOVERY_POLICY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6003 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There is no valid encryption recovery policy configured for this system.\n\nLookup forms: 6003, 0x1773, error 6003, ERROR_NO_RECOVERY_POLICY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6003"]},{"id":1479,"title":"ERROR_NO_EFS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6004","0x1774","error 6004","ERROR_NO_EFS","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","efs","the","required","encryption","driver","not","loaded","for","this","system"],"errorCode":"6004","eventId":"","severity":"Low","summary":"The required encryption driver is not loaded for this system.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6004; use the surrounding log entries to confirm it.","resolution":"1. Record where 6004 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_EFS.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6004 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The required encryption driver is not loaded for this system.\n\nLookup forms: 6004, 0x1774, error 6004, ERROR_NO_EFS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6004"]},{"id":1480,"title":"ERROR_WRONG_EFS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6005","0x1775","error 6005","ERROR_WRONG_EFS","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","wrong","efs","the","file","was","encrypted","with","different","encryption","driver","than","currently","loaded"],"errorCode":"6005","eventId":"","severity":"Low","summary":"The file was encrypted with a different encryption driver than is currently loaded.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6005; use the surrounding log entries to confirm it.","resolution":"1. Record where 6005 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_WRONG_EFS.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6005 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file was encrypted with a different encryption driver than is currently loaded.\n\nLookup forms: 6005, 0x1775, error 6005, ERROR_WRONG_EFS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6005"]},{"id":1481,"title":"ERROR_NO_USER_KEYS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6006","0x1776","error 6006","ERROR_NO_USER_KEYS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","user","keys","there","are","efs","defined","for","the"],"errorCode":"6006","eventId":"","severity":"Low","summary":"There are no EFS keys defined for the user.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6006; use the surrounding log entries to confirm it.","resolution":"1. Record where 6006 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_USER_KEYS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6006 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There are no EFS keys defined for the user.\n\nLookup forms: 6006, 0x1776, error 6006, ERROR_NO_USER_KEYS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6006"]},{"id":1482,"title":"ERROR_FILE_NOT_ENCRYPTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6007","0x1777","error 6007","ERROR_FILE_NOT_ENCRYPTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","file","not","encrypted","the","specified"],"errorCode":"6007","eventId":"","severity":"Low","summary":"The specified file is not encrypted.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6007; use the surrounding log entries to confirm it.","resolution":"1. Record where 6007 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FILE_NOT_ENCRYPTED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6007 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified file is not encrypted.\n\nLookup forms: 6007, 0x1777, error 6007, ERROR_FILE_NOT_ENCRYPTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6007"]},{"id":1483,"title":"ERROR_NOT_EXPORT_FORMAT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6008","0x1778","error 6008","ERROR_NOT_EXPORT_FORMAT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","not","export","format","the","specified","file","defined","efs"],"errorCode":"6008","eventId":"","severity":"Low","summary":"The specified file is not in the defined EFS export format.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6008; use the surrounding log entries to confirm it.","resolution":"1. Record where 6008 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_EXPORT_FORMAT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6008 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified file is not in the defined EFS export format.\n\nLookup forms: 6008, 0x1778, error 6008, ERROR_NOT_EXPORT_FORMAT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6008"]},{"id":1484,"title":"ERROR_FILE_READ_ONLY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6009","0x1779","error 6009","ERROR_FILE_READ_ONLY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","file","read","only","the","specified"],"errorCode":"6009","eventId":"","severity":"Low","summary":"The specified file is read only.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6009; use the surrounding log entries to confirm it.","resolution":"1. Record where 6009 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FILE_READ_ONLY.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6009 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified file is read only.\n\nLookup forms: 6009, 0x1779, error 6009, ERROR_FILE_READ_ONLY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6009"]},{"id":1485,"title":"ERROR_DIR_EFS_DISALLOWED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6010","0x177A","error 6010","ERROR_DIR_EFS_DISALLOWED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","dir","efs","disallowed","the","directory","has","been","disabled","for","encryption"],"errorCode":"6010","eventId":"","severity":"Low","summary":"The directory has been disabled for encryption.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6010; use the surrounding log entries to confirm it.","resolution":"1. Record where 6010 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DIR_EFS_DISALLOWED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6010 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory has been disabled for encryption.\n\nLookup forms: 6010, 0x177A, error 6010, ERROR_DIR_EFS_DISALLOWED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6010"]},{"id":1486,"title":"ERROR_EFS_SERVER_NOT_TRUSTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6011","0x177B","error 6011","ERROR_EFS_SERVER_NOT_TRUSTED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","efs","server","not","trusted","the","for","remote","encryption","operation"],"errorCode":"6011","eventId":"","severity":"Low","summary":"The server is not trusted for remote encryption operation.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 6011; use the surrounding log entries to confirm it.","resolution":"1. Record where 6011 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EFS_SERVER_NOT_TRUSTED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6011 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The server is not trusted for remote encryption operation.\n\nLookup forms: 6011, 0x177B, error 6011, ERROR_EFS_SERVER_NOT_TRUSTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6011"]},{"id":1487,"title":"ERROR_BAD_RECOVERY_POLICY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6012","0x177C","error 6012","ERROR_BAD_RECOVERY_POLICY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","bad","recovery","policy","configured","for","this","system","contains","invalid","certificate"],"errorCode":"6012","eventId":"","severity":"Medium","summary":"Recovery policy configured for this system contains invalid recovery certificate.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6012; use the surrounding log entries to confirm it.","resolution":"1. Record where 6012 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_RECOVERY_POLICY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6012 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Recovery policy configured for this system contains invalid recovery certificate.\n\nLookup forms: 6012, 0x177C, error 6012, ERROR_BAD_RECOVERY_POLICY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6012"]},{"id":1488,"title":"ERROR_EFS_ALG_BLOB_TOO_BIG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6013","0x177D","error 6013","ERROR_EFS_ALG_BLOB_TOO_BIG","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","efs","alg","blob","too","big","the","encryption","algorithm","used","source","file","needs","bigger","key","buffer","than","one","destination"],"errorCode":"6013","eventId":"","severity":"Low","summary":"The encryption algorithm used on the source file needs a bigger key buffer than the one on the destination file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6013; use the surrounding log entries to confirm it.","resolution":"1. Record where 6013 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EFS_ALG_BLOB_TOO_BIG.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6013 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The encryption algorithm used on the source file needs a bigger key buffer than the one on the destination file.\n\nLookup forms: 6013, 0x177D, error 6013, ERROR_EFS_ALG_BLOB_TOO_BIG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6013"]},{"id":1489,"title":"ERROR_VOLUME_NOT_SUPPORT_EFS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6014","0x177E","error 6014","ERROR_VOLUME_NOT_SUPPORT_EFS","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","volume","not","support","efs","the","disk","partition","does","file","encryption"],"errorCode":"6014","eventId":"","severity":"Low","summary":"The disk partition does not support file encryption.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6014; use the surrounding log entries to confirm it.","resolution":"1. Record where 6014 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_VOLUME_NOT_SUPPORT_EFS.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6014 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The disk partition does not support file encryption.\n\nLookup forms: 6014, 0x177E, error 6014, ERROR_VOLUME_NOT_SUPPORT_EFS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6014"]},{"id":1490,"title":"ERROR_EFS_DISABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6015","0x177F","error 6015","ERROR_EFS_DISABLED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","efs","disabled","this","machine","for","file","encryption"],"errorCode":"6015","eventId":"","severity":"Low","summary":"This machine is disabled for file encryption.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6015; use the surrounding log entries to confirm it.","resolution":"1. Record where 6015 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EFS_DISABLED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6015 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This machine is disabled for file encryption.\n\nLookup forms: 6015, 0x177F, error 6015, ERROR_EFS_DISABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6015"]},{"id":1491,"title":"ERROR_EFS_VERSION_NOT_SUPPORT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6016","0x1780","error 6016","ERROR_EFS_VERSION_NOT_SUPPORT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","efs","version","not","support","newer","system","required","decrypt","this","encrypted","file"],"errorCode":"6016","eventId":"","severity":"Low","summary":"A newer system is required to decrypt this encrypted file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6016; use the surrounding log entries to confirm it.","resolution":"1. Record where 6016 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EFS_VERSION_NOT_SUPPORT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6016 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A newer system is required to decrypt this encrypted file.\n\nLookup forms: 6016, 0x1780, error 6016, ERROR_EFS_VERSION_NOT_SUPPORT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6016"]},{"id":1492,"title":"ERROR_CS_ENCRYPTION_INVALID_SERVER_RESPONSE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6017","0x1781","error 6017","ERROR_CS_ENCRYPTION_INVALID_SERVER_RESPONSE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","encryption","invalid","server","response","the","remote","sent","for","file","being","opened","with","client","side"],"errorCode":"6017","eventId":"","severity":"Medium","summary":"The remote server sent an invalid response for a file being opened with Client Side Encryption.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 6017; use the surrounding log entries to confirm it.","resolution":"1. Record where 6017 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CS_ENCRYPTION_INVALID_SERVER_RESPONSE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6017 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The remote server sent an invalid response for a file being opened with Client Side Encryption.\n\nLookup forms: 6017, 0x1781, error 6017, ERROR_CS_ENCRYPTION_INVALID_SERVER_RESPONSE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6017"]},{"id":1493,"title":"ERROR_CS_ENCRYPTION_UNSUPPORTED_SERVER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6018","0x1782","error 6018","ERROR_CS_ENCRYPTION_UNSUPPORTED_SERVER","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","encryption","unsupported","server","client","side","not","supported","the","remote","even","though","claims","support"],"errorCode":"6018","eventId":"","severity":"Medium","summary":"Client Side Encryption is not supported by the remote server even though it claims to support it.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 6018; use the surrounding log entries to confirm it.","resolution":"1. Record where 6018 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CS_ENCRYPTION_UNSUPPORTED_SERVER.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6018 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Client Side Encryption is not supported by the remote server even though it claims to support it.\n\nLookup forms: 6018, 0x1782, error 6018, ERROR_CS_ENCRYPTION_UNSUPPORTED_SERVER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6018"]},{"id":1494,"title":"ERROR_CS_ENCRYPTION_EXISTING_ENCRYPTED_FILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6019","0x1783","error 6019","ERROR_CS_ENCRYPTION_EXISTING_ENCRYPTED_FILE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","encryption","existing","encrypted","file","and","should","opened","client","side","mode"],"errorCode":"6019","eventId":"","severity":"Low","summary":"File is encrypted and should be opened in Client Side Encryption mode.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6019; use the surrounding log entries to confirm it.","resolution":"1. Record where 6019 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CS_ENCRYPTION_EXISTING_ENCRYPTED_FILE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6019 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: File is encrypted and should be opened in Client Side Encryption mode.\n\nLookup forms: 6019, 0x1783, error 6019, ERROR_CS_ENCRYPTION_EXISTING_ENCRYPTED_FILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6019"]},{"id":1495,"title":"ERROR_CS_ENCRYPTION_NEW_ENCRYPTED_FILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6020","0x1784","error 6020","ERROR_CS_ENCRYPTION_NEW_ENCRYPTED_FILE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","encryption","new","encrypted","file","being","created","and","efs","needs","provided"],"errorCode":"6020","eventId":"","severity":"Low","summary":"A new encrypted file is being created and a $EFS needs to be provided.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6020; use the surrounding log entries to confirm it.","resolution":"1. Record where 6020 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CS_ENCRYPTION_NEW_ENCRYPTED_FILE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6020 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A new encrypted file is being created and a $EFS needs to be provided.\n\nLookup forms: 6020, 0x1784, error 6020, ERROR_CS_ENCRYPTION_NEW_ENCRYPTED_FILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6020"]},{"id":1496,"title":"ERROR_CS_ENCRYPTION_FILE_NOT_CSE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6021","0x1785","error 6021","ERROR_CS_ENCRYPTION_FILE_NOT_CSE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","encryption","file","not","cse","the","smb","client","requested","fsctl","non"],"errorCode":"6021","eventId":"","severity":"Low","summary":"The SMB client requested a CSE FSCTL on a non-CSE file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6021; use the surrounding log entries to confirm it.","resolution":"1. Record where 6021 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CS_ENCRYPTION_FILE_NOT_CSE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6021 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The SMB client requested a CSE FSCTL on a non-CSE file.\n\nLookup forms: 6021, 0x1785, error 6021, ERROR_CS_ENCRYPTION_FILE_NOT_CSE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6021"]},{"id":1497,"title":"ERROR_ENCRYPTION_POLICY_DENIES_OPERATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6022","0x1786","error 6022","ERROR_ENCRYPTION_POLICY_DENIES_OPERATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","encryption","policy","denies","operation","the","requested","was","blocked","for","more","information","contact","your","system","administrator"],"errorCode":"6022","eventId":"","severity":"High","summary":"The requested operation was blocked by policy. For more information, contact your system administrator.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6022; use the surrounding log entries to confirm it.","resolution":"1. Record where 6022 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ENCRYPTION_POLICY_DENIES_OPERATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6022 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested operation was blocked by policy. For more information, contact your system administrator.\n\nLookup forms: 6022, 0x1786, error 6022, ERROR_ENCRYPTION_POLICY_DENIES_OPERATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6022"]},{"id":1498,"title":"ERROR_NO_BROWSER_SERVERS_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6118","0x17E6","error 6118","ERROR_NO_BROWSER_SERVERS_FOUND","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","browser","servers","found","the","list","for","this","workgroup","not","currently","available"],"errorCode":"6118","eventId":"","severity":"Low","summary":"The list of servers for this workgroup is not currently available.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 6118; use the surrounding log entries to confirm it.","resolution":"1. Record where 6118 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_BROWSER_SERVERS_FOUND.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6118 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The list of servers for this workgroup is not currently available.\n\nLookup forms: 6118, 0x17E6, error 6118, ERROR_NO_BROWSER_SERVERS_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6118"]},{"id":1499,"title":"SCHED_E_SERVICE_NOT_LOCALSYSTEM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6200","0x1838","error 6200","SCHED_E_SERVICE_NOT_LOCALSYSTEM","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","sched","service","not","localsystem","the","task","scheduler","must","configured","run","system","account","function","properly","individual","tasks","may","other","accounts"],"errorCode":"6200","eventId":"","severity":"Low","summary":"The Task Scheduler service must be configured to run in the System account to function properly. Individual tasks may be configured to run in other accounts.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 6200; use the surrounding log entries to confirm it.","resolution":"1. Record where 6200 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to SCHED_E_SERVICE_NOT_LOCALSYSTEM.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6200 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Task Scheduler service must be configured to run in the System account to function properly. Individual tasks may be configured to run in other accounts.\n\nLookup forms: 6200, 0x1838, error 6200, SCHED_E_SERVICE_NOT_LOCALSYSTEM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6200"]},{"id":1500,"title":"ERROR_LOG_SECTOR_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6600","0x19C8","error 6600","ERROR_LOG_SECTOR_INVALID","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","log","sector","invalid","service","encountered"],"errorCode":"6600","eventId":"","severity":"Medium","summary":"Log service encountered an invalid log sector.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6600; use the surrounding log entries to confirm it.","resolution":"1. Record where 6600 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_SECTOR_INVALID.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6600 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log service encountered an invalid log sector.\n\nLookup forms: 6600, 0x19C8, error 6600, ERROR_LOG_SECTOR_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6600"]},{"id":1501,"title":"ERROR_LOG_SECTOR_PARITY_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6601","0x19C9","error 6601","ERROR_LOG_SECTOR_PARITY_INVALID","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","log","sector","parity","invalid","service","encountered","with","block"],"errorCode":"6601","eventId":"","severity":"Medium","summary":"Log service encountered a log sector with invalid block parity.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6601; use the surrounding log entries to confirm it.","resolution":"1. Record where 6601 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_SECTOR_PARITY_INVALID.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6601 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log service encountered a log sector with invalid block parity.\n\nLookup forms: 6601, 0x19C9, error 6601, ERROR_LOG_SECTOR_PARITY_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6601"]},{"id":1502,"title":"ERROR_LOG_SECTOR_REMAPPED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6602","0x19CA","error 6602","ERROR_LOG_SECTOR_REMAPPED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","log","sector","remapped","service","encountered"],"errorCode":"6602","eventId":"","severity":"Low","summary":"Log service encountered a remapped log sector.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6602; use the surrounding log entries to confirm it.","resolution":"1. Record where 6602 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_SECTOR_REMAPPED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6602 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log service encountered a remapped log sector.\n\nLookup forms: 6602, 0x19CA, error 6602, ERROR_LOG_SECTOR_REMAPPED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6602"]},{"id":1503,"title":"ERROR_LOG_BLOCK_INCOMPLETE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6603","0x19CB","error 6603","ERROR_LOG_BLOCK_INCOMPLETE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","log","block","incomplete","service","encountered","partial"],"errorCode":"6603","eventId":"","severity":"Low","summary":"Log service encountered a partial or incomplete log block.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6603; use the surrounding log entries to confirm it.","resolution":"1. Record where 6603 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_BLOCK_INCOMPLETE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6603 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log service encountered a partial or incomplete log block.\n\nLookup forms: 6603, 0x19CB, error 6603, ERROR_LOG_BLOCK_INCOMPLETE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6603"]},{"id":1504,"title":"ERROR_LOG_INVALID_RANGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6604","0x19CC","error 6604","ERROR_LOG_INVALID_RANGE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","log","invalid","range","service","encountered","attempt","access","data","outside","the","active"],"errorCode":"6604","eventId":"","severity":"Low","summary":"Log service encountered an attempt access data outside the active log range.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 6604; use the surrounding log entries to confirm it.","resolution":"1. Record where 6604 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_INVALID_RANGE.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6604 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log service encountered an attempt access data outside the active log range.\n\nLookup forms: 6604, 0x19CC, error 6604, ERROR_LOG_INVALID_RANGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6604"]},{"id":1505,"title":"ERROR_LOG_BLOCKS_EXHAUSTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6605","0x19CD","error 6605","ERROR_LOG_BLOCKS_EXHAUSTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","log","blocks","exhausted","service","user","marshalling","buffers","are"],"errorCode":"6605","eventId":"","severity":"Low","summary":"Log service user marshalling buffers are exhausted.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6605; use the surrounding log entries to confirm it.","resolution":"1. Record where 6605 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_BLOCKS_EXHAUSTED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6605 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log service user marshalling buffers are exhausted.\n\nLookup forms: 6605, 0x19CD, error 6605, ERROR_LOG_BLOCKS_EXHAUSTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6605"]},{"id":1506,"title":"ERROR_LOG_READ_CONTEXT_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6606","0x19CE","error 6606","ERROR_LOG_READ_CONTEXT_INVALID","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","log","read","context","invalid","service","encountered","attempt","from","marshalling","area","with"],"errorCode":"6606","eventId":"","severity":"Medium","summary":"Log service encountered an attempt read from a marshalling area with an invalid read context.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6606; use the surrounding log entries to confirm it.","resolution":"1. Record where 6606 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_READ_CONTEXT_INVALID.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6606 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log service encountered an attempt read from a marshalling area with an invalid read context.\n\nLookup forms: 6606, 0x19CE, error 6606, ERROR_LOG_READ_CONTEXT_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6606"]},{"id":1507,"title":"ERROR_LOG_RESTART_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6607","0x19CF","error 6607","ERROR_LOG_RESTART_INVALID","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","log","restart","invalid","service","encountered","area"],"errorCode":"6607","eventId":"","severity":"Medium","summary":"Log service encountered an invalid log restart area.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6607; use the surrounding log entries to confirm it.","resolution":"1. Record where 6607 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_RESTART_INVALID.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6607 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log service encountered an invalid log restart area.\n\nLookup forms: 6607, 0x19CF, error 6607, ERROR_LOG_RESTART_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6607"]},{"id":1508,"title":"ERROR_LOG_BLOCK_VERSION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6608","0x19D0","error 6608","ERROR_LOG_BLOCK_VERSION","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","log","block","version","service","encountered","invalid"],"errorCode":"6608","eventId":"","severity":"Medium","summary":"Log service encountered an invalid log block version.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6608; use the surrounding log entries to confirm it.","resolution":"1. Record where 6608 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_BLOCK_VERSION.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6608 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log service encountered an invalid log block version.\n\nLookup forms: 6608, 0x19D0, error 6608, ERROR_LOG_BLOCK_VERSION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6608"]},{"id":1509,"title":"ERROR_LOG_BLOCK_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6609","0x19D1","error 6609","ERROR_LOG_BLOCK_INVALID","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","log","block","invalid","service","encountered"],"errorCode":"6609","eventId":"","severity":"Medium","summary":"Log service encountered an invalid log block.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6609; use the surrounding log entries to confirm it.","resolution":"1. Record where 6609 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_BLOCK_INVALID.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6609 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log service encountered an invalid log block.\n\nLookup forms: 6609, 0x19D1, error 6609, ERROR_LOG_BLOCK_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6609"]},{"id":1510,"title":"ERROR_LOG_READ_MODE_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6610","0x19D2","error 6610","ERROR_LOG_READ_MODE_INVALID","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","log","read","mode","invalid","service","encountered","attempt","the","with"],"errorCode":"6610","eventId":"","severity":"Medium","summary":"Log service encountered an attempt to read the log with an invalid read mode.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6610; use the surrounding log entries to confirm it.","resolution":"1. Record where 6610 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_READ_MODE_INVALID.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6610 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log service encountered an attempt to read the log with an invalid read mode.\n\nLookup forms: 6610, 0x19D2, error 6610, ERROR_LOG_READ_MODE_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6610"]},{"id":1511,"title":"ERROR_LOG_NO_RESTART","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6611","0x19D3","error 6611","ERROR_LOG_NO_RESTART","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","log","restart","service","encountered","stream","with","area"],"errorCode":"6611","eventId":"","severity":"Low","summary":"Log service encountered a log stream with no restart area.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6611; use the surrounding log entries to confirm it.","resolution":"1. Record where 6611 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_NO_RESTART.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6611 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log service encountered a log stream with no restart area.\n\nLookup forms: 6611, 0x19D3, error 6611, ERROR_LOG_NO_RESTART. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6611"]},{"id":1512,"title":"ERROR_LOG_METADATA_CORRUPT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6612","0x19D4","error 6612","ERROR_LOG_METADATA_CORRUPT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","log","metadata","corrupt","service","encountered","corrupted","file"],"errorCode":"6612","eventId":"","severity":"Critical","summary":"Log service encountered a corrupted metadata file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6612; use the surrounding log entries to confirm it.","resolution":"1. Record where 6612 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_METADATA_CORRUPT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6612 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log service encountered a corrupted metadata file.\n\nLookup forms: 6612, 0x19D4, error 6612, ERROR_LOG_METADATA_CORRUPT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6612"]},{"id":1513,"title":"ERROR_LOG_METADATA_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6613","0x19D5","error 6613","ERROR_LOG_METADATA_INVALID","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","log","metadata","invalid","service","encountered","file","that","could","not","created","the","system"],"errorCode":"6613","eventId":"","severity":"Low","summary":"Log service encountered a metadata file that could not be created by the log file system.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6613; use the surrounding log entries to confirm it.","resolution":"1. Record where 6613 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_METADATA_INVALID.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6613 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log service encountered a metadata file that could not be created by the log file system.\n\nLookup forms: 6613, 0x19D5, error 6613, ERROR_LOG_METADATA_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6613"]},{"id":1514,"title":"ERROR_LOG_METADATA_INCONSISTENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6614","0x19D6","error 6614","ERROR_LOG_METADATA_INCONSISTENT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","log","metadata","inconsistent","service","encountered","file","with","data"],"errorCode":"6614","eventId":"","severity":"Low","summary":"Log service encountered a metadata file with inconsistent data.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6614; use the surrounding log entries to confirm it.","resolution":"1. Record where 6614 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_METADATA_INCONSISTENT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6614 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log service encountered a metadata file with inconsistent data.\n\nLookup forms: 6614, 0x19D6, error 6614, ERROR_LOG_METADATA_INCONSISTENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6614"]},{"id":1515,"title":"ERROR_LOG_RESERVATION_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6615","0x19D7","error 6615","ERROR_LOG_RESERVATION_INVALID","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","log","reservation","invalid","service","encountered","attempt","erroneous","allocate","dispose","space"],"errorCode":"6615","eventId":"","severity":"Low","summary":"Log service encountered an attempt to erroneous allocate or dispose reservation space.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6615; use the surrounding log entries to confirm it.","resolution":"1. Record where 6615 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_RESERVATION_INVALID.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6615 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log service encountered an attempt to erroneous allocate or dispose reservation space.\n\nLookup forms: 6615, 0x19D7, error 6615, ERROR_LOG_RESERVATION_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6615"]},{"id":1516,"title":"ERROR_LOG_CANT_DELETE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6616","0x19D8","error 6616","ERROR_LOG_CANT_DELETE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","log","cant","delete","service","cannot","file","system","container"],"errorCode":"6616","eventId":"","severity":"Medium","summary":"Log service cannot delete log file or file system container.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6616; use the surrounding log entries to confirm it.","resolution":"1. Record where 6616 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_CANT_DELETE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6616 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log service cannot delete log file or file system container.\n\nLookup forms: 6616, 0x19D8, error 6616, ERROR_LOG_CANT_DELETE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6616"]},{"id":1517,"title":"ERROR_LOG_CONTAINER_LIMIT_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6617","0x19D9","error 6617","ERROR_LOG_CONTAINER_LIMIT_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","log","container","limit","exceeded","service","has","reached","the","maximum","allowable","containers","allocated","file"],"errorCode":"6617","eventId":"","severity":"Low","summary":"Log service has reached the maximum allowable containers allocated to a log file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6617; use the surrounding log entries to confirm it.","resolution":"1. Record where 6617 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_CONTAINER_LIMIT_EXCEEDED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6617 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log service has reached the maximum allowable containers allocated to a log file.\n\nLookup forms: 6617, 0x19D9, error 6617, ERROR_LOG_CONTAINER_LIMIT_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6617"]},{"id":1518,"title":"ERROR_LOG_START_OF_LOG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6618","0x19DA","error 6618","ERROR_LOG_START_OF_LOG","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","log","start","service","has","attempted","read","write","backward","past","the"],"errorCode":"6618","eventId":"","severity":"Low","summary":"Log service has attempted to read or write backward past the start of the log.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6618; use the surrounding log entries to confirm it.","resolution":"1. Record where 6618 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_START_OF_LOG.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6618 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log service has attempted to read or write backward past the start of the log.\n\nLookup forms: 6618, 0x19DA, error 6618, ERROR_LOG_START_OF_LOG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6618"]},{"id":1519,"title":"ERROR_LOG_POLICY_ALREADY_INSTALLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6619","0x19DB","error 6619","ERROR_LOG_POLICY_ALREADY_INSTALLED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","log","policy","already","installed","could","not","because","the","same","type","present"],"errorCode":"6619","eventId":"","severity":"Low","summary":"Log policy could not be installed because a policy of the same type is already present.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 6619; use the surrounding log entries to confirm it.","resolution":"1. Record where 6619 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_POLICY_ALREADY_INSTALLED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6619 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log policy could not be installed because a policy of the same type is already present.\n\nLookup forms: 6619, 0x19DB, error 6619, ERROR_LOG_POLICY_ALREADY_INSTALLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6619"]},{"id":1520,"title":"ERROR_LOG_POLICY_NOT_INSTALLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6620","0x19DC","error 6620","ERROR_LOG_POLICY_NOT_INSTALLED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","log","policy","not","installed","question","was","the","time","request"],"errorCode":"6620","eventId":"","severity":"Low","summary":"Log policy in question was not installed at the time of the request.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 6620; use the surrounding log entries to confirm it.","resolution":"1. Record where 6620 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_POLICY_NOT_INSTALLED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6620 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log policy in question was not installed at the time of the request.\n\nLookup forms: 6620, 0x19DC, error 6620, ERROR_LOG_POLICY_NOT_INSTALLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6620"]},{"id":1521,"title":"ERROR_LOG_POLICY_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6621","0x19DD","error 6621","ERROR_LOG_POLICY_INVALID","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","log","policy","invalid","the","installed","set","policies"],"errorCode":"6621","eventId":"","severity":"Medium","summary":"The installed set of policies on the log is invalid.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 6621; use the surrounding log entries to confirm it.","resolution":"1. Record where 6621 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_POLICY_INVALID.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6621 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The installed set of policies on the log is invalid.\n\nLookup forms: 6621, 0x19DD, error 6621, ERROR_LOG_POLICY_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6621"]},{"id":1522,"title":"ERROR_LOG_POLICY_CONFLICT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6622","0x19DE","error 6622","ERROR_LOG_POLICY_CONFLICT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","log","policy","conflict","the","question","prevented","operation","from","completing"],"errorCode":"6622","eventId":"","severity":"Low","summary":"A policy on the log in question prevented the operation from completing.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6622; use the surrounding log entries to confirm it.","resolution":"1. Record where 6622 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_POLICY_CONFLICT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6622 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A policy on the log in question prevented the operation from completing.\n\nLookup forms: 6622, 0x19DE, error 6622, ERROR_LOG_POLICY_CONFLICT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6622"]},{"id":1523,"title":"ERROR_LOG_PINNED_ARCHIVE_TAIL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6623","0x19DF","error 6623","ERROR_LOG_PINNED_ARCHIVE_TAIL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","log","pinned","archive","tail","space","cannot","reclaimed","because","the"],"errorCode":"6623","eventId":"","severity":"Medium","summary":"Log space cannot be reclaimed because the log is pinned by the archive tail.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6623; use the surrounding log entries to confirm it.","resolution":"1. Record where 6623 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_PINNED_ARCHIVE_TAIL.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6623 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log space cannot be reclaimed because the log is pinned by the archive tail.\n\nLookup forms: 6623, 0x19DF, error 6623, ERROR_LOG_PINNED_ARCHIVE_TAIL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6623"]},{"id":1524,"title":"ERROR_LOG_RECORD_NONEXISTENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6624","0x19E0","error 6624","ERROR_LOG_RECORD_NONEXISTENT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","log","record","nonexistent","not","the","file"],"errorCode":"6624","eventId":"","severity":"Low","summary":"Log record is not a record in the log file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6624; use the surrounding log entries to confirm it.","resolution":"1. Record where 6624 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_RECORD_NONEXISTENT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6624 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log record is not a record in the log file.\n\nLookup forms: 6624, 0x19E0, error 6624, ERROR_LOG_RECORD_NONEXISTENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6624"]},{"id":1525,"title":"ERROR_LOG_RECORDS_RESERVED_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6625","0x19E1","error 6625","ERROR_LOG_RECORDS_RESERVED_INVALID","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","log","records","reserved","invalid","number","the","adjustment"],"errorCode":"6625","eventId":"","severity":"Medium","summary":"Number of reserved log records or the adjustment of the number of reserved log records is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6625; use the surrounding log entries to confirm it.","resolution":"1. Record where 6625 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_RECORDS_RESERVED_INVALID.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6625 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Number of reserved log records or the adjustment of the number of reserved log records is invalid.\n\nLookup forms: 6625, 0x19E1, error 6625, ERROR_LOG_RECORDS_RESERVED_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6625"]},{"id":1526,"title":"ERROR_LOG_SPACE_RESERVED_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6626","0x19E2","error 6626","ERROR_LOG_SPACE_RESERVED_INVALID","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","log","space","reserved","invalid","the","adjustment"],"errorCode":"6626","eventId":"","severity":"Medium","summary":"Reserved log space or the adjustment of the log space is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6626; use the surrounding log entries to confirm it.","resolution":"1. Record where 6626 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_SPACE_RESERVED_INVALID.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6626 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Reserved log space or the adjustment of the log space is invalid.\n\nLookup forms: 6626, 0x19E2, error 6626, ERROR_LOG_SPACE_RESERVED_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6626"]},{"id":1527,"title":"ERROR_LOG_TAIL_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6627","0x19E3","error 6627","ERROR_LOG_TAIL_INVALID","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","log","tail","invalid","new","existing","archive","base","the","active"],"errorCode":"6627","eventId":"","severity":"Medium","summary":"An new or existing archive tail or base of the active log is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6627; use the surrounding log entries to confirm it.","resolution":"1. Record where 6627 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_TAIL_INVALID.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6627 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An new or existing archive tail or base of the active log is invalid.\n\nLookup forms: 6627, 0x19E3, error 6627, ERROR_LOG_TAIL_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6627"]},{"id":1528,"title":"ERROR_LOG_FULL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6628","0x19E4","error 6628","ERROR_LOG_FULL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","log","full","space","exhausted"],"errorCode":"6628","eventId":"","severity":"Low","summary":"Log space is exhausted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6628; use the surrounding log entries to confirm it.","resolution":"1. Record where 6628 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_FULL.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6628 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log space is exhausted.\n\nLookup forms: 6628, 0x19E4, error 6628, ERROR_LOG_FULL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6628"]},{"id":1529,"title":"ERROR_COULD_NOT_RESIZE_LOG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6629","0x19E5","error 6629","ERROR_COULD_NOT_RESIZE_LOG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","could","not","resize","log","the","set","requested","size"],"errorCode":"6629","eventId":"","severity":"Low","summary":"The log could not be set to the requested size.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6629; use the surrounding log entries to confirm it.","resolution":"1. Record where 6629 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_COULD_NOT_RESIZE_LOG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6629 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The log could not be set to the requested size.\n\nLookup forms: 6629, 0x19E5, error 6629, ERROR_COULD_NOT_RESIZE_LOG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6629"]},{"id":1530,"title":"ERROR_LOG_MULTIPLEXED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6630","0x19E6","error 6630","ERROR_LOG_MULTIPLEXED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","log","multiplexed","direct","writes","the","physical","allowed"],"errorCode":"6630","eventId":"","severity":"Low","summary":"Log is multiplexed, no direct writes to the physical log is allowed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6630; use the surrounding log entries to confirm it.","resolution":"1. Record where 6630 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_MULTIPLEXED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6630 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log is multiplexed, no direct writes to the physical log is allowed.\n\nLookup forms: 6630, 0x19E6, error 6630, ERROR_LOG_MULTIPLEXED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6630"]},{"id":1531,"title":"ERROR_LOG_DEDICATED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6631","0x19E7","error 6631","ERROR_LOG_DEDICATED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","log","dedicated","the","operation","failed","because"],"errorCode":"6631","eventId":"","severity":"High","summary":"The operation failed because the log is a dedicated log.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6631; use the surrounding log entries to confirm it.","resolution":"1. Record where 6631 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_DEDICATED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6631 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation failed because the log is a dedicated log.\n\nLookup forms: 6631, 0x19E7, error 6631, ERROR_LOG_DEDICATED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6631"]},{"id":1532,"title":"ERROR_LOG_ARCHIVE_NOT_IN_PROGRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6632","0x19E8","error 6632","ERROR_LOG_ARCHIVE_NOT_IN_PROGRESS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","log","archive","not","progress","the","operation","requires","context"],"errorCode":"6632","eventId":"","severity":"Low","summary":"The operation requires an archive context.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6632; use the surrounding log entries to confirm it.","resolution":"1. Record where 6632 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_ARCHIVE_NOT_IN_PROGRESS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6632 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation requires an archive context.\n\nLookup forms: 6632, 0x19E8, error 6632, ERROR_LOG_ARCHIVE_NOT_IN_PROGRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6632"]},{"id":1533,"title":"ERROR_LOG_ARCHIVE_IN_PROGRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6633","0x19E9","error 6633","ERROR_LOG_ARCHIVE_IN_PROGRESS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","log","archive","progress","archival"],"errorCode":"6633","eventId":"","severity":"Low","summary":"Log archival is in progress.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6633; use the surrounding log entries to confirm it.","resolution":"1. Record where 6633 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_ARCHIVE_IN_PROGRESS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6633 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log archival is in progress.\n\nLookup forms: 6633, 0x19E9, error 6633, ERROR_LOG_ARCHIVE_IN_PROGRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6633"]},{"id":1534,"title":"ERROR_LOG_EPHEMERAL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6634","0x19EA","error 6634","ERROR_LOG_EPHEMERAL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","log","ephemeral","the","operation","requires","non","but"],"errorCode":"6634","eventId":"","severity":"Low","summary":"The operation requires a non-ephemeral log, but the log is ephemeral.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6634; use the surrounding log entries to confirm it.","resolution":"1. Record where 6634 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_EPHEMERAL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6634 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation requires a non-ephemeral log, but the log is ephemeral.\n\nLookup forms: 6634, 0x19EA, error 6634, ERROR_LOG_EPHEMERAL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6634"]},{"id":1535,"title":"ERROR_LOG_NOT_ENOUGH_CONTAINERS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6635","0x19EB","error 6635","ERROR_LOG_NOT_ENOUGH_CONTAINERS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","log","not","enough","containers","the","must","have","least","two","before","can","read","from","written"],"errorCode":"6635","eventId":"","severity":"Low","summary":"The log must have at least two containers before it can be read from or written to.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6635; use the surrounding log entries to confirm it.","resolution":"1. Record where 6635 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_NOT_ENOUGH_CONTAINERS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6635 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The log must have at least two containers before it can be read from or written to.\n\nLookup forms: 6635, 0x19EB, error 6635, ERROR_LOG_NOT_ENOUGH_CONTAINERS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6635"]},{"id":1536,"title":"ERROR_LOG_CLIENT_ALREADY_REGISTERED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6636","0x19EC","error 6636","ERROR_LOG_CLIENT_ALREADY_REGISTERED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","log","client","already","registered","has","the","stream"],"errorCode":"6636","eventId":"","severity":"Low","summary":"A log client has already registered on the stream.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6636; use the surrounding log entries to confirm it.","resolution":"1. Record where 6636 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_CLIENT_ALREADY_REGISTERED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6636 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A log client has already registered on the stream.\n\nLookup forms: 6636, 0x19EC, error 6636, ERROR_LOG_CLIENT_ALREADY_REGISTERED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6636"]},{"id":1537,"title":"ERROR_LOG_CLIENT_NOT_REGISTERED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6637","0x19ED","error 6637","ERROR_LOG_CLIENT_NOT_REGISTERED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","log","client","not","registered","has","been","the","stream"],"errorCode":"6637","eventId":"","severity":"Low","summary":"A log client has not been registered on the stream.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6637; use the surrounding log entries to confirm it.","resolution":"1. Record where 6637 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_CLIENT_NOT_REGISTERED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6637 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A log client has not been registered on the stream.\n\nLookup forms: 6637, 0x19ED, error 6637, ERROR_LOG_CLIENT_NOT_REGISTERED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6637"]},{"id":1538,"title":"ERROR_LOG_FULL_HANDLER_IN_PROGRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6638","0x19EE","error 6638","ERROR_LOG_FULL_HANDLER_IN_PROGRESS","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","log","full","handler","progress","request","has","already","been","made","handle","the","condition"],"errorCode":"6638","eventId":"","severity":"Low","summary":"A request has already been made to handle the log full condition.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6638; use the surrounding log entries to confirm it.","resolution":"1. Record where 6638 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_FULL_HANDLER_IN_PROGRESS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6638 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A request has already been made to handle the log full condition.\n\nLookup forms: 6638, 0x19EE, error 6638, ERROR_LOG_FULL_HANDLER_IN_PROGRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6638"]},{"id":1539,"title":"ERROR_LOG_CONTAINER_READ_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6639","0x19EF","error 6639","ERROR_LOG_CONTAINER_READ_FAILED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","log","container","read","failed","service","encountered","when","attempting","from"],"errorCode":"6639","eventId":"","severity":"Low","summary":"Log service encountered an error when attempting to read from a log container.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6639; use the surrounding log entries to confirm it.","resolution":"1. Record where 6639 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_CONTAINER_READ_FAILED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6639 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log service encountered an error when attempting to read from a log container.\n\nLookup forms: 6639, 0x19EF, error 6639, ERROR_LOG_CONTAINER_READ_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6639"]},{"id":1540,"title":"ERROR_LOG_CONTAINER_WRITE_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6640","0x19F0","error 6640","ERROR_LOG_CONTAINER_WRITE_FAILED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","log","container","write","failed","service","encountered","when","attempting"],"errorCode":"6640","eventId":"","severity":"Low","summary":"Log service encountered an error when attempting to write to a log container.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6640; use the surrounding log entries to confirm it.","resolution":"1. Record where 6640 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_CONTAINER_WRITE_FAILED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6640 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log service encountered an error when attempting to write to a log container.\n\nLookup forms: 6640, 0x19F0, error 6640, ERROR_LOG_CONTAINER_WRITE_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6640"]},{"id":1541,"title":"ERROR_LOG_CONTAINER_OPEN_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6641","0x19F1","error 6641","ERROR_LOG_CONTAINER_OPEN_FAILED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","log","container","open","failed","service","encountered","when","attempting"],"errorCode":"6641","eventId":"","severity":"Low","summary":"Log service encountered an error when attempting open a log container.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6641; use the surrounding log entries to confirm it.","resolution":"1. Record where 6641 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_CONTAINER_OPEN_FAILED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6641 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log service encountered an error when attempting open a log container.\n\nLookup forms: 6641, 0x19F1, error 6641, ERROR_LOG_CONTAINER_OPEN_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6641"]},{"id":1542,"title":"ERROR_LOG_CONTAINER_STATE_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6642","0x19F2","error 6642","ERROR_LOG_CONTAINER_STATE_INVALID","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","log","container","state","invalid","service","encountered","when","attempting","requested","action"],"errorCode":"6642","eventId":"","severity":"Medium","summary":"Log service encountered an invalid container state when attempting a requested action.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6642; use the surrounding log entries to confirm it.","resolution":"1. Record where 6642 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_CONTAINER_STATE_INVALID.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6642 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log service encountered an invalid container state when attempting a requested action.\n\nLookup forms: 6642, 0x19F2, error 6642, ERROR_LOG_CONTAINER_STATE_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6642"]},{"id":1543,"title":"ERROR_LOG_STATE_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6643","0x19F3","error 6643","ERROR_LOG_STATE_INVALID","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","log","state","invalid","service","not","the","correct","perform","requested","action"],"errorCode":"6643","eventId":"","severity":"Low","summary":"Log service is not in the correct state to perform a requested action.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6643; use the surrounding log entries to confirm it.","resolution":"1. Record where 6643 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_STATE_INVALID.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6643 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log service is not in the correct state to perform a requested action.\n\nLookup forms: 6643, 0x19F3, error 6643, ERROR_LOG_STATE_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6643"]},{"id":1544,"title":"ERROR_LOG_PINNED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6644","0x19F4","error 6644","ERROR_LOG_PINNED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","log","pinned","space","cannot","reclaimed","because","the"],"errorCode":"6644","eventId":"","severity":"Medium","summary":"Log space cannot be reclaimed because the log is pinned.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6644; use the surrounding log entries to confirm it.","resolution":"1. Record where 6644 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_PINNED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6644 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log space cannot be reclaimed because the log is pinned.\n\nLookup forms: 6644, 0x19F4, error 6644, ERROR_LOG_PINNED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6644"]},{"id":1545,"title":"ERROR_LOG_METADATA_FLUSH_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6645","0x19F5","error 6645","ERROR_LOG_METADATA_FLUSH_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","log","metadata","flush","failed"],"errorCode":"6645","eventId":"","severity":"High","summary":"Log metadata flush failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6645; use the surrounding log entries to confirm it.","resolution":"1. Record where 6645 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_METADATA_FLUSH_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6645 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log metadata flush failed.\n\nLookup forms: 6645, 0x19F5, error 6645, ERROR_LOG_METADATA_FLUSH_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6645"]},{"id":1546,"title":"ERROR_LOG_INCONSISTENT_SECURITY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6646","0x19F6","error 6646","ERROR_LOG_INCONSISTENT_SECURITY","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","log","inconsistent","security","the","and","its","containers"],"errorCode":"6646","eventId":"","severity":"Low","summary":"Security on the log and its containers is inconsistent.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 6646; use the surrounding log entries to confirm it.","resolution":"1. Record where 6646 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_INCONSISTENT_SECURITY.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6646 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Security on the log and its containers is inconsistent.\n\nLookup forms: 6646, 0x19F6, error 6646, ERROR_LOG_INCONSISTENT_SECURITY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6646"]},{"id":1547,"title":"ERROR_LOG_APPENDED_FLUSH_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6647","0x19F7","error 6647","ERROR_LOG_APPENDED_FLUSH_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","log","appended","flush","failed","records","were","the","reservation","changes","made","but","could","not","flushed"],"errorCode":"6647","eventId":"","severity":"Low","summary":"Records were appended to the log or reservation changes were made, but the log could not be flushed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6647; use the surrounding log entries to confirm it.","resolution":"1. Record where 6647 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_APPENDED_FLUSH_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6647 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Records were appended to the log or reservation changes were made, but the log could not be flushed.\n\nLookup forms: 6647, 0x19F7, error 6647, ERROR_LOG_APPENDED_FLUSH_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6647"]},{"id":1548,"title":"ERROR_LOG_PINNED_RESERVATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6648","0x19F8","error 6648","ERROR_LOG_PINNED_RESERVATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","log","pinned","reservation","the","due","consuming","most","space","free","some","reserved","records","make","available"],"errorCode":"6648","eventId":"","severity":"Low","summary":"The log is pinned due to reservation consuming most of the log space. Free some reserved records to make space available.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6648; use the surrounding log entries to confirm it.","resolution":"1. Record where 6648 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_PINNED_RESERVATION.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6648 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The log is pinned due to reservation consuming most of the log space. Free some reserved records to make space available.\n\nLookup forms: 6648, 0x19F8, error 6648, ERROR_LOG_PINNED_RESERVATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6648"]},{"id":1549,"title":"ERROR_INVALID_TRANSACTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6700","0x1A2C","error 6700","ERROR_INVALID_TRANSACTION","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","invalid","transaction","the","handle","associated","with","this","operation","not","valid"],"errorCode":"6700","eventId":"","severity":"Low","summary":"The transaction handle associated with this operation is not valid.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6700; use the surrounding log entries to confirm it.","resolution":"1. Record where 6700 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_TRANSACTION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6700 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The transaction handle associated with this operation is not valid.\n\nLookup forms: 6700, 0x1A2C, error 6700, ERROR_INVALID_TRANSACTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6700"]},{"id":1550,"title":"ERROR_TRANSACTION_NOT_ACTIVE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6701","0x1A2D","error 6701","ERROR_TRANSACTION_NOT_ACTIVE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","transaction","not","active","the","requested","operation","was","made","context","that","longer"],"errorCode":"6701","eventId":"","severity":"Low","summary":"The requested operation was made in the context of a transaction that is no longer active.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6701; use the surrounding log entries to confirm it.","resolution":"1. Record where 6701 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTION_NOT_ACTIVE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6701 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested operation was made in the context of a transaction that is no longer active.\n\nLookup forms: 6701, 0x1A2D, error 6701, ERROR_TRANSACTION_NOT_ACTIVE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6701"]},{"id":1551,"title":"ERROR_TRANSACTION_REQUEST_NOT_VALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6702","0x1A2E","error 6702","ERROR_TRANSACTION_REQUEST_NOT_VALID","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","transaction","request","not","valid","the","requested","operation","object","its","current","state"],"errorCode":"6702","eventId":"","severity":"Low","summary":"The requested operation is not valid on the Transaction object in its current state.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6702; use the surrounding log entries to confirm it.","resolution":"1. Record where 6702 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTION_REQUEST_NOT_VALID.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6702 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested operation is not valid on the Transaction object in its current state.\n\nLookup forms: 6702, 0x1A2E, error 6702, ERROR_TRANSACTION_REQUEST_NOT_VALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6702"]},{"id":1552,"title":"ERROR_TRANSACTION_NOT_REQUESTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6703","0x1A2F","error 6703","ERROR_TRANSACTION_NOT_REQUESTED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","transaction","not","requested","the","caller","has","called","response","api","but","expected","because","did","issue","corresponding","request"],"errorCode":"6703","eventId":"","severity":"Low","summary":"The caller has called a response API, but the response is not expected because the TM did not issue the corresponding request to the caller.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6703; use the surrounding log entries to confirm it.","resolution":"1. Record where 6703 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTION_NOT_REQUESTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6703 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The caller has called a response API, but the response is not expected because the TM did not issue the corresponding request to the caller.\n\nLookup forms: 6703, 0x1A2F, error 6703, ERROR_TRANSACTION_NOT_REQUESTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6703"]},{"id":1553,"title":"ERROR_TRANSACTION_ALREADY_ABORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6704","0x1A30","error 6704","ERROR_TRANSACTION_ALREADY_ABORTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","transaction","already","aborted","too","late","perform","the","requested","operation","since","has","been"],"errorCode":"6704","eventId":"","severity":"Low","summary":"It is too late to perform the requested operation, since the Transaction has already been aborted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6704; use the surrounding log entries to confirm it.","resolution":"1. Record where 6704 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTION_ALREADY_ABORTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6704 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: It is too late to perform the requested operation, since the Transaction has already been aborted.\n\nLookup forms: 6704, 0x1A30, error 6704, ERROR_TRANSACTION_ALREADY_ABORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6704"]},{"id":1554,"title":"ERROR_TRANSACTION_ALREADY_COMMITTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6705","0x1A31","error 6705","ERROR_TRANSACTION_ALREADY_COMMITTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","transaction","already","committed","too","late","perform","the","requested","operation","since","has","been"],"errorCode":"6705","eventId":"","severity":"Low","summary":"It is too late to perform the requested operation, since the Transaction has already been committed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6705; use the surrounding log entries to confirm it.","resolution":"1. Record where 6705 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTION_ALREADY_COMMITTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6705 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: It is too late to perform the requested operation, since the Transaction has already been committed.\n\nLookup forms: 6705, 0x1A31, error 6705, ERROR_TRANSACTION_ALREADY_COMMITTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6705"]},{"id":1555,"title":"ERROR_TM_INITIALIZATION_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6706","0x1A32","error 6706","ERROR_TM_INITIALIZATION_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","initialization","failed","the","transaction","manager","was","unable","successfully","initialized","transacted","operations","are","not","supported"],"errorCode":"6706","eventId":"","severity":"Medium","summary":"The Transaction Manager was unable to be successfully initialized. Transacted operations are not supported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6706; use the surrounding log entries to confirm it.","resolution":"1. Record where 6706 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TM_INITIALIZATION_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6706 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Transaction Manager was unable to be successfully initialized. Transacted operations are not supported.\n\nLookup forms: 6706, 0x1A32, error 6706, ERROR_TM_INITIALIZATION_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6706"]},{"id":1556,"title":"ERROR_RESOURCEMANAGER_READ_ONLY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6707","0x1A33","error 6707","ERROR_RESOURCEMANAGER_READ_ONLY","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","resourcemanager","read","only","the","specified","made","changes","updates","resource","under","this","transaction"],"errorCode":"6707","eventId":"","severity":"Low","summary":"The specified ResourceManager made no changes or updates to the resource under this transaction.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 6707; use the surrounding log entries to confirm it.","resolution":"1. Record where 6707 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESOURCEMANAGER_READ_ONLY.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6707 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified ResourceManager made no changes or updates to the resource under this transaction.\n\nLookup forms: 6707, 0x1A33, error 6707, ERROR_RESOURCEMANAGER_READ_ONLY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6707"]},{"id":1557,"title":"ERROR_TRANSACTION_NOT_JOINED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6708","0x1A34","error 6708","ERROR_TRANSACTION_NOT_JOINED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","transaction","not","joined","the","resource","manager","has","attempted","prepare","that","successfully"],"errorCode":"6708","eventId":"","severity":"Low","summary":"The resource manager has attempted to prepare a transaction that it has not successfully joined.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6708; use the surrounding log entries to confirm it.","resolution":"1. Record where 6708 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTION_NOT_JOINED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6708 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The resource manager has attempted to prepare a transaction that it has not successfully joined.\n\nLookup forms: 6708, 0x1A34, error 6708, ERROR_TRANSACTION_NOT_JOINED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6708"]},{"id":1558,"title":"ERROR_TRANSACTION_SUPERIOR_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6709","0x1A35","error 6709","ERROR_TRANSACTION_SUPERIOR_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","transaction","superior","exists","the","object","already","has","enlistment","and","caller","attempted","operation","that","would","have","created","new","only","single","allow"],"errorCode":"6709","eventId":"","severity":"Low","summary":"The Transaction object already has a superior enlistment, and the caller attempted an operation that would have created a new superior. Only a single superior enlistment is allow.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6709; use the surrounding log entries to confirm it.","resolution":"1. Record where 6709 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTION_SUPERIOR_EXISTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6709 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Transaction object already has a superior enlistment, and the caller attempted an operation that would have created a new superior. Only a single superior enlistment is allow.\n\nLookup forms: 6709, 0x1A35, error 6709, ERROR_TRANSACTION_SUPERIOR_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6709"]},{"id":1559,"title":"ERROR_CRM_PROTOCOL_ALREADY_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6710","0x1A36","error 6710","ERROR_CRM_PROTOCOL_ALREADY_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","crm","protocol","already","exists","the","tried","register","that"],"errorCode":"6710","eventId":"","severity":"Medium","summary":"The RM tried to register a protocol that already exists.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6710; use the surrounding log entries to confirm it.","resolution":"1. Record where 6710 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CRM_PROTOCOL_ALREADY_EXISTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6710 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The RM tried to register a protocol that already exists.\n\nLookup forms: 6710, 0x1A36, error 6710, ERROR_CRM_PROTOCOL_ALREADY_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6710"]},{"id":1560,"title":"ERROR_TRANSACTION_PROPAGATION_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6711","0x1A37","error 6711","ERROR_TRANSACTION_PROPAGATION_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","transaction","propagation","failed","the","attempt","propagate"],"errorCode":"6711","eventId":"","severity":"High","summary":"The attempt to propagate the Transaction failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6711; use the surrounding log entries to confirm it.","resolution":"1. Record where 6711 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTION_PROPAGATION_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6711 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The attempt to propagate the Transaction failed.\n\nLookup forms: 6711, 0x1A37, error 6711, ERROR_TRANSACTION_PROPAGATION_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6711"]},{"id":1561,"title":"ERROR_CRM_PROTOCOL_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6712","0x1A38","error 6712","ERROR_CRM_PROTOCOL_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","crm","protocol","not","found","the","requested","propagation","was","registered"],"errorCode":"6712","eventId":"","severity":"Low","summary":"The requested propagation protocol was not registered as a CRM.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6712; use the surrounding log entries to confirm it.","resolution":"1. Record where 6712 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CRM_PROTOCOL_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6712 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested propagation protocol was not registered as a CRM.\n\nLookup forms: 6712, 0x1A38, error 6712, ERROR_CRM_PROTOCOL_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6712"]},{"id":1562,"title":"ERROR_TRANSACTION_INVALID_MARSHALL_BUFFER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6713","0x1A39","error 6713","ERROR_TRANSACTION_INVALID_MARSHALL_BUFFER","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","transaction","invalid","marshall","buffer","the","passed","pushtransaction","pulltransaction","not","valid","format"],"errorCode":"6713","eventId":"","severity":"Low","summary":"The buffer passed in to PushTransaction or PullTransaction is not in a valid format.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6713; use the surrounding log entries to confirm it.","resolution":"1. Record where 6713 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTION_INVALID_MARSHALL_BUFFER.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6713 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The buffer passed in to PushTransaction or PullTransaction is not in a valid format.\n\nLookup forms: 6713, 0x1A39, error 6713, ERROR_TRANSACTION_INVALID_MARSHALL_BUFFER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6713"]},{"id":1563,"title":"ERROR_CURRENT_TRANSACTION_NOT_VALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6714","0x1A3A","error 6714","ERROR_CURRENT_TRANSACTION_NOT_VALID","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","current","transaction","not","valid","the","context","associated","with","thread","handle","object"],"errorCode":"6714","eventId":"","severity":"Low","summary":"The current transaction context associated with the thread is not a valid handle to a transaction object.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6714; use the surrounding log entries to confirm it.","resolution":"1. Record where 6714 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CURRENT_TRANSACTION_NOT_VALID.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6714 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The current transaction context associated with the thread is not a valid handle to a transaction object.\n\nLookup forms: 6714, 0x1A3A, error 6714, ERROR_CURRENT_TRANSACTION_NOT_VALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6714"]},{"id":1564,"title":"ERROR_TRANSACTION_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6715","0x1A3B","error 6715","ERROR_TRANSACTION_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","transaction","not","found","the","specified","object","could","opened","because","was"],"errorCode":"6715","eventId":"","severity":"Medium","summary":"The specified Transaction object could not be opened, because it was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6715; use the surrounding log entries to confirm it.","resolution":"1. Record where 6715 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTION_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6715 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified Transaction object could not be opened, because it was not found.\n\nLookup forms: 6715, 0x1A3B, error 6715, ERROR_TRANSACTION_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6715"]},{"id":1565,"title":"ERROR_RESOURCEMANAGER_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6716","0x1A3C","error 6716","ERROR_RESOURCEMANAGER_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","resourcemanager","not","found","the","specified","object","could","opened","because","was"],"errorCode":"6716","eventId":"","severity":"Medium","summary":"The specified ResourceManager object could not be opened, because it was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6716; use the surrounding log entries to confirm it.","resolution":"1. Record where 6716 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESOURCEMANAGER_NOT_FOUND.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6716 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified ResourceManager object could not be opened, because it was not found.\n\nLookup forms: 6716, 0x1A3C, error 6716, ERROR_RESOURCEMANAGER_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6716"]},{"id":1566,"title":"ERROR_ENLISTMENT_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6717","0x1A3D","error 6717","ERROR_ENLISTMENT_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","enlistment","not","found","the","specified","object","could","opened","because","was"],"errorCode":"6717","eventId":"","severity":"Medium","summary":"The specified Enlistment object could not be opened, because it was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6717; use the surrounding log entries to confirm it.","resolution":"1. Record where 6717 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ENLISTMENT_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6717 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified Enlistment object could not be opened, because it was not found.\n\nLookup forms: 6717, 0x1A3D, error 6717, ERROR_ENLISTMENT_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6717"]},{"id":1567,"title":"ERROR_TRANSACTIONMANAGER_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6718","0x1A3E","error 6718","ERROR_TRANSACTIONMANAGER_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","transactionmanager","not","found","the","specified","object","could","opened","because","was"],"errorCode":"6718","eventId":"","severity":"Medium","summary":"The specified TransactionManager object could not be opened, because it was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6718; use the surrounding log entries to confirm it.","resolution":"1. Record where 6718 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTIONMANAGER_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6718 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified TransactionManager object could not be opened, because it was not found.\n\nLookup forms: 6718, 0x1A3E, error 6718, ERROR_TRANSACTIONMANAGER_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6718"]},{"id":1568,"title":"ERROR_TRANSACTIONMANAGER_NOT_ONLINE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6719","0x1A3F","error 6719","ERROR_TRANSACTIONMANAGER_NOT_ONLINE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","transactionmanager","not","online","the","object","specified","could","created","opened","because","its","associated","must","brought","fully","calling","recovertransactionmanager","recover","end","logfile","before","objects","transaction","resourcemanager"],"errorCode":"6719","eventId":"","severity":"Low","summary":"The object specified could not be created or opened, because its associated TransactionManager is not online. The TransactionManager must be brought fully Online by calling RecoverTransactionManager to recover to the end of its LogFile before objects in its Transaction or ResourceManager namespaces can be opened. In addition, errors in writing records to its LogFile can cause a TransactionManager to go offline.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6719; use the surrounding log entries to confirm it.","resolution":"1. Record where 6719 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTIONMANAGER_NOT_ONLINE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6719 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The object specified could not be created or opened, because its associated TransactionManager is not online. The TransactionManager must be brought fully Online by calling RecoverTransactionManager to recover to the end of its LogFile before objects in its Transaction or ResourceManager namespaces can be opened. In addition, errors in writing records to its LogFile can cause a TransactionManager to go offline.\n\nLookup forms: 6719, 0x1A3F, error 6719, ERROR_TRANSACTIONMANAGER_NOT_ONLINE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6719"]},{"id":1569,"title":"ERROR_TRANSACTIONMANAGER_RECOVERY_NAME_COLLISION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6720","0x1A40","error 6720","ERROR_TRANSACTIONMANAGER_RECOVERY_NAME_COLLISION","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","transactionmanager","recovery","name","collision","the","specified","was","unable","create","objects","contained","its","logfile","namespace","therefore","recover"],"errorCode":"6720","eventId":"","severity":"Medium","summary":"The specified TransactionManager was unable to create the objects contained in its logfile in the Ob namespace. Therefore, the TransactionManager was unable to recover.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6720; use the surrounding log entries to confirm it.","resolution":"1. Record where 6720 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTIONMANAGER_RECOVERY_NAME_COLLISION.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6720 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified TransactionManager was unable to create the objects contained in its logfile in the Ob namespace. Therefore, the TransactionManager was unable to recover.\n\nLookup forms: 6720, 0x1A40, error 6720, ERROR_TRANSACTIONMANAGER_RECOVERY_NAME_COLLISION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6720"]},{"id":1570,"title":"ERROR_TRANSACTION_NOT_ROOT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6721","0x1A41","error 6721","ERROR_TRANSACTION_NOT_ROOT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","transaction","not","root","the","call","create","superior","enlistment","this","object","could","completed","because","specified","for","subordinate","branch","only","can","enlisted"],"errorCode":"6721","eventId":"","severity":"Low","summary":"The call to create a superior Enlistment on this Transaction object could not be completed, because the Transaction object specified for the enlistment is a subordinate branch of the Transaction. Only the root of the Transaction can be enlisted on as a superior.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6721; use the surrounding log entries to confirm it.","resolution":"1. Record where 6721 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTION_NOT_ROOT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6721 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The call to create a superior Enlistment on this Transaction object could not be completed, because the Transaction object specified for the enlistment is a subordinate branch of the Transaction. Only the root of the Transaction can be enlisted on as a superior.\n\nLookup forms: 6721, 0x1A41, error 6721, ERROR_TRANSACTION_NOT_ROOT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6721"]},{"id":1571,"title":"ERROR_TRANSACTION_OBJECT_EXPIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6722","0x1A42","error 6722","ERROR_TRANSACTION_OBJECT_EXPIRED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","transaction","object","expired","because","the","associated","manager","resource","has","been","closed","handle","longer","valid"],"errorCode":"6722","eventId":"","severity":"Low","summary":"Because the associated transaction manager or resource manager has been closed, the handle is no longer valid.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6722; use the surrounding log entries to confirm it.","resolution":"1. Record where 6722 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTION_OBJECT_EXPIRED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6722 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Because the associated transaction manager or resource manager has been closed, the handle is no longer valid.\n\nLookup forms: 6722, 0x1A42, error 6722, ERROR_TRANSACTION_OBJECT_EXPIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6722"]},{"id":1572,"title":"ERROR_TRANSACTION_RESPONSE_NOT_ENLISTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6723","0x1A43","error 6723","ERROR_TRANSACTION_RESPONSE_NOT_ENLISTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","transaction","response","not","enlisted","the","specified","operation","could","performed","this","superior","enlistment","because","was","created","with","corresponding","completion","notificationmask"],"errorCode":"6723","eventId":"","severity":"Low","summary":"The specified operation could not be performed on this Superior enlistment, because the enlistment was not created with the corresponding completion response in the NotificationMask.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6723; use the surrounding log entries to confirm it.","resolution":"1. Record where 6723 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTION_RESPONSE_NOT_ENLISTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6723 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified operation could not be performed on this Superior enlistment, because the enlistment was not created with the corresponding completion response in the NotificationMask.\n\nLookup forms: 6723, 0x1A43, error 6723, ERROR_TRANSACTION_RESPONSE_NOT_ENLISTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6723"]},{"id":1573,"title":"ERROR_TRANSACTION_RECORD_TOO_LONG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6724","0x1A44","error 6724","ERROR_TRANSACTION_RECORD_TOO_LONG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","transaction","record","too","long","the","specified","operation","could","not","performed","because","that","would","logged","was","this","can","occur","two","conditions","either","there","are","many"],"errorCode":"6724","eventId":"","severity":"Low","summary":"The specified operation could not be performed, because the record that would be logged was too long. This can occur because of two conditions: either there are too many Enlistments on this Transaction, or the combined RecoveryInformation being logged on behalf of those Enlistments is too long.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6724; use the surrounding log entries to confirm it.","resolution":"1. Record where 6724 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTION_RECORD_TOO_LONG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6724 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified operation could not be performed, because the record that would be logged was too long. This can occur because of two conditions: either there are too many Enlistments on this Transaction, or the combined RecoveryInformation being logged on behalf of those Enlistments is too long.\n\nLookup forms: 6724, 0x1A44, error 6724, ERROR_TRANSACTION_RECORD_TOO_LONG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6724"]},{"id":1574,"title":"ERROR_IMPLICIT_TRANSACTION_NOT_SUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6725","0x1A45","error 6725","ERROR_IMPLICIT_TRANSACTION_NOT_SUPPORTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","implicit","transaction","not","supported","are"],"errorCode":"6725","eventId":"","severity":"Medium","summary":"Implicit transaction are not supported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6725; use the surrounding log entries to confirm it.","resolution":"1. Record where 6725 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IMPLICIT_TRANSACTION_NOT_SUPPORTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6725 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Implicit transaction are not supported.\n\nLookup forms: 6725, 0x1A45, error 6725, ERROR_IMPLICIT_TRANSACTION_NOT_SUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6725"]},{"id":1575,"title":"ERROR_TRANSACTION_INTEGRITY_VIOLATED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6726","0x1A46","error 6726","ERROR_TRANSACTION_INTEGRITY_VIOLATED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","transaction","integrity","violated","the","kernel","manager","had","abort","forget","because","blocked","forward","progress"],"errorCode":"6726","eventId":"","severity":"High","summary":"The kernel transaction manager had to abort or forget the transaction because it blocked forward progress.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6726; use the surrounding log entries to confirm it.","resolution":"1. Record where 6726 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTION_INTEGRITY_VIOLATED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6726 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The kernel transaction manager had to abort or forget the transaction because it blocked forward progress.\n\nLookup forms: 6726, 0x1A46, error 6726, ERROR_TRANSACTION_INTEGRITY_VIOLATED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6726"]},{"id":1576,"title":"ERROR_TRANSACTIONMANAGER_IDENTITY_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6727","0x1A47","error 6727","ERROR_TRANSACTIONMANAGER_IDENTITY_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","transactionmanager","identity","mismatch","the","that","was","supplied","did","not","match","one","recorded","log","file"],"errorCode":"6727","eventId":"","severity":"Low","summary":"The TransactionManager identity that was supplied did not match the one recorded in the TransactionManager's log file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6727; use the surrounding log entries to confirm it.","resolution":"1. Record where 6727 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTIONMANAGER_IDENTITY_MISMATCH.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6727 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The TransactionManager identity that was supplied did not match the one recorded in the TransactionManager's log file.\n\nLookup forms: 6727, 0x1A47, error 6727, ERROR_TRANSACTIONMANAGER_IDENTITY_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6727"]},{"id":1577,"title":"ERROR_RM_CANNOT_BE_FROZEN_FOR_SNAPSHOT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6728","0x1A48","error 6728","ERROR_RM_CANNOT_BE_FROZEN_FOR_SNAPSHOT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cannot","frozen","for","snapshot","this","operation","continue","because","transactional","resource","manager","its","current","state","please","try","again"],"errorCode":"6728","eventId":"","severity":"Medium","summary":"This snapshot operation cannot continue because a transactional resource manager cannot be frozen in its current state. Please try again.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6728; use the surrounding log entries to confirm it.","resolution":"1. Record where 6728 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RM_CANNOT_BE_FROZEN_FOR_SNAPSHOT.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6728 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This snapshot operation cannot continue because a transactional resource manager cannot be frozen in its current state. Please try again.\n\nLookup forms: 6728, 0x1A48, error 6728, ERROR_RM_CANNOT_BE_FROZEN_FOR_SNAPSHOT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6728"]},{"id":1578,"title":"ERROR_TRANSACTION_MUST_WRITETHROUGH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6729","0x1A49","error 6729","ERROR_TRANSACTION_MUST_WRITETHROUGH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","transaction","must","writethrough","the","cannot","enlisted","with","specified","enlistmentmask","because","has","already","completed","preprepare","phase","order","ensure","correctness","resourcemanager","switch","write","through","mode","and"],"errorCode":"6729","eventId":"","severity":"Medium","summary":"The transaction cannot be enlisted on with the specified EnlistmentMask, because the transaction has already completed the PrePrepare phase. In order to ensure correctness, the ResourceManager must switch to a write- through mode and cease caching data within this transaction. Enlisting for only subsequent transaction phases may still succeed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6729; use the surrounding log entries to confirm it.","resolution":"1. Record where 6729 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTION_MUST_WRITETHROUGH.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6729 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The transaction cannot be enlisted on with the specified EnlistmentMask, because the transaction has already completed the PrePrepare phase. In order to ensure correctness, the ResourceManager must switch to a write- through mode and cease caching data within this transaction. Enlisting for only subsequent transaction phases may still succeed.\n\nLookup forms: 6729, 0x1A49, error 6729, ERROR_TRANSACTION_MUST_WRITETHROUGH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6729"]},{"id":1579,"title":"ERROR_TRANSACTION_NO_SUPERIOR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6730","0x1A4A","error 6730","ERROR_TRANSACTION_NO_SUPERIOR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","transaction","superior","the","does","not","have","enlistment"],"errorCode":"6730","eventId":"","severity":"Low","summary":"The transaction does not have a superior enlistment.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6730; use the surrounding log entries to confirm it.","resolution":"1. Record where 6730 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTION_NO_SUPERIOR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6730 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The transaction does not have a superior enlistment.\n\nLookup forms: 6730, 0x1A4A, error 6730, ERROR_TRANSACTION_NO_SUPERIOR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6730"]},{"id":1580,"title":"ERROR_HEURISTIC_DAMAGE_POSSIBLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6731","0x1A4B","error 6731","ERROR_HEURISTIC_DAMAGE_POSSIBLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","heuristic","damage","possible","the","attempt","commit","transaction","completed","but","that","some","portion","tree","did","not","successfully","due","heuristics","therefore","data","modified","may","have","committed"],"errorCode":"6731","eventId":"","severity":"Low","summary":"The attempt to commit the Transaction completed, but it is possible that some portion of the transaction tree did not commit successfully due to heuristics. Therefore it is possible that some data modified in the transaction may not have committed, resulting in transactional inconsistency. If possible, check the consistency of the associated data.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6731; use the surrounding log entries to confirm it.","resolution":"1. Record where 6731 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_HEURISTIC_DAMAGE_POSSIBLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6731 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The attempt to commit the Transaction completed, but it is possible that some portion of the transaction tree did not commit successfully due to heuristics. Therefore it is possible that some data modified in the transaction may not have committed, resulting in transactional inconsistency. If possible, check the consistency of the associated data.\n\nLookup forms: 6731, 0x1A4B, error 6731, ERROR_HEURISTIC_DAMAGE_POSSIBLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6731"]},{"id":1581,"title":"ERROR_TRANSACTIONAL_CONFLICT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6800","0x1A90","error 6800","ERROR_TRANSACTIONAL_CONFLICT","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","transactional","conflict","the","function","attempted","use","name","that","reserved","for","another","transaction"],"errorCode":"6800","eventId":"","severity":"Low","summary":"The function attempted to use a name that is reserved for use by another transaction.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6800; use the surrounding log entries to confirm it.","resolution":"1. Record where 6800 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTIONAL_CONFLICT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6800 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The function attempted to use a name that is reserved for use by another transaction.\n\nLookup forms: 6800, 0x1A90, error 6800, ERROR_TRANSACTIONAL_CONFLICT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6800"]},{"id":1582,"title":"ERROR_RM_NOT_ACTIVE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6801","0x1A91","error 6801","ERROR_RM_NOT_ACTIVE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","not","active","transaction","support","within","the","specified","resource","manager","started","was","shut","down","due"],"errorCode":"6801","eventId":"","severity":"Low","summary":"Transaction support within the specified resource manager is not started or was shut down due to an error.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6801; use the surrounding log entries to confirm it.","resolution":"1. Record where 6801 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RM_NOT_ACTIVE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6801 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Transaction support within the specified resource manager is not started or was shut down due to an error.\n\nLookup forms: 6801, 0x1A91, error 6801, ERROR_RM_NOT_ACTIVE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6801"]},{"id":1583,"title":"ERROR_RM_METADATA_CORRUPT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6802","0x1A92","error 6802","ERROR_RM_METADATA_CORRUPT","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","metadata","corrupt","the","has","been","corrupted","will","not","function"],"errorCode":"6802","eventId":"","severity":"Critical","summary":"The metadata of the RM has been corrupted. The RM will not function.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6802; use the surrounding log entries to confirm it.","resolution":"1. Record where 6802 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RM_METADATA_CORRUPT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6802 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The metadata of the RM has been corrupted. The RM will not function.\n\nLookup forms: 6802, 0x1A92, error 6802, ERROR_RM_METADATA_CORRUPT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6802"]},{"id":1584,"title":"ERROR_DIRECTORY_NOT_RM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6803","0x1A93","error 6803","ERROR_DIRECTORY_NOT_RM","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","directory","not","the","specified","does","contain","resource","manager"],"errorCode":"6803","eventId":"","severity":"Low","summary":"The specified directory does not contain a resource manager.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6803; use the surrounding log entries to confirm it.","resolution":"1. Record where 6803 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DIRECTORY_NOT_RM.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6803 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified directory does not contain a resource manager.\n\nLookup forms: 6803, 0x1A93, error 6803, ERROR_DIRECTORY_NOT_RM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6803"]},{"id":1585,"title":"ERROR_TRANSACTIONS_UNSUPPORTED_REMOTE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6805","0x1A95","error 6805","ERROR_TRANSACTIONS_UNSUPPORTED_REMOTE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","transactions","unsupported","remote","the","server","share","does","not","support","transacted","file","operations"],"errorCode":"6805","eventId":"","severity":"Low","summary":"The remote server or share does not support transacted file operations.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 6805; use the surrounding log entries to confirm it.","resolution":"1. Record where 6805 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTIONS_UNSUPPORTED_REMOTE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6805 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The remote server or share does not support transacted file operations.\n\nLookup forms: 6805, 0x1A95, error 6805, ERROR_TRANSACTIONS_UNSUPPORTED_REMOTE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6805"]},{"id":1586,"title":"ERROR_LOG_RESIZE_INVALID_SIZE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6806","0x1A96","error 6806","ERROR_LOG_RESIZE_INVALID_SIZE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","log","resize","invalid","size","the","requested"],"errorCode":"6806","eventId":"","severity":"Medium","summary":"The requested log size is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6806; use the surrounding log entries to confirm it.","resolution":"1. Record where 6806 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_RESIZE_INVALID_SIZE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6806 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested log size is invalid.\n\nLookup forms: 6806, 0x1A96, error 6806, ERROR_LOG_RESIZE_INVALID_SIZE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6806"]},{"id":1587,"title":"ERROR_OBJECT_NO_LONGER_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6807","0x1A97","error 6807","ERROR_OBJECT_NO_LONGER_EXISTS","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","object","longer","exists","the","file","stream","link","corresponding","handle","has","been","deleted","transaction","savepoint","rollback"],"errorCode":"6807","eventId":"","severity":"Low","summary":"The object (file, stream, link) corresponding to the handle has been deleted by a Transaction Savepoint Rollback.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6807; use the surrounding log entries to confirm it.","resolution":"1. Record where 6807 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_OBJECT_NO_LONGER_EXISTS.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6807 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The object (file, stream, link) corresponding to the handle has been deleted by a Transaction Savepoint Rollback.\n\nLookup forms: 6807, 0x1A97, error 6807, ERROR_OBJECT_NO_LONGER_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6807"]},{"id":1588,"title":"ERROR_STREAM_MINIVERSION_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6808","0x1A98","error 6808","ERROR_STREAM_MINIVERSION_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","stream","miniversion","not","found","the","specified","file","was","for","this","transacted","open"],"errorCode":"6808","eventId":"","severity":"Medium","summary":"The specified file miniversion was not found for this transacted file open.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6808; use the surrounding log entries to confirm it.","resolution":"1. Record where 6808 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STREAM_MINIVERSION_NOT_FOUND.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6808 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified file miniversion was not found for this transacted file open.\n\nLookup forms: 6808, 0x1A98, error 6808, ERROR_STREAM_MINIVERSION_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6808"]},{"id":1589,"title":"ERROR_STREAM_MINIVERSION_NOT_VALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6809","0x1A99","error 6809","ERROR_STREAM_MINIVERSION_NOT_VALID","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","stream","miniversion","not","valid","the","specified","file","was","found","but","has","been","invalidated","most","likely","cause","transaction","savepoint","rollback"],"errorCode":"6809","eventId":"","severity":"Medium","summary":"The specified file miniversion was found but has been invalidated. Most likely cause is a transaction savepoint rollback.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6809; use the surrounding log entries to confirm it.","resolution":"1. Record where 6809 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STREAM_MINIVERSION_NOT_VALID.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6809 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified file miniversion was found but has been invalidated. Most likely cause is a transaction savepoint rollback.\n\nLookup forms: 6809, 0x1A99, error 6809, ERROR_STREAM_MINIVERSION_NOT_VALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6809"]},{"id":1590,"title":"ERROR_MINIVERSION_INACCESSIBLE_FROM_SPECIFIED_TRANSACTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6810","0x1A9A","error 6810","ERROR_MINIVERSION_INACCESSIBLE_FROM_SPECIFIED_TRANSACTION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","miniversion","inaccessible","from","specified","transaction","may","only","opened","the","context","that","created"],"errorCode":"6810","eventId":"","severity":"Low","summary":"A miniversion may only be opened in the context of the transaction that created it.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6810; use the surrounding log entries to confirm it.","resolution":"1. Record where 6810 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MINIVERSION_INACCESSIBLE_FROM_SPECIFIED_TRANSACTION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6810 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A miniversion may only be opened in the context of the transaction that created it.\n\nLookup forms: 6810, 0x1A9A, error 6810, ERROR_MINIVERSION_INACCESSIBLE_FROM_SPECIFIED_TRANSACTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6810"]},{"id":1591,"title":"ERROR_CANT_OPEN_MINIVERSION_WITH_MODIFY_INTENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6811","0x1A9B","error 6811","ERROR_CANT_OPEN_MINIVERSION_WITH_MODIFY_INTENT","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","cant","open","miniversion","with","modify","intent","not","possible","access"],"errorCode":"6811","eventId":"","severity":"Low","summary":"It is not possible to open a miniversion with modify access.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 6811; use the surrounding log entries to confirm it.","resolution":"1. Record where 6811 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANT_OPEN_MINIVERSION_WITH_MODIFY_INTENT.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6811 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: It is not possible to open a miniversion with modify access.\n\nLookup forms: 6811, 0x1A9B, error 6811, ERROR_CANT_OPEN_MINIVERSION_WITH_MODIFY_INTENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6811"]},{"id":1592,"title":"ERROR_CANT_CREATE_MORE_STREAM_MINIVERSIONS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6812","0x1A9C","error 6812","ERROR_CANT_CREATE_MORE_STREAM_MINIVERSIONS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","create","more","stream","miniversions","not","possible","any","for","this"],"errorCode":"6812","eventId":"","severity":"Low","summary":"It is not possible to create any more miniversions for this stream.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6812; use the surrounding log entries to confirm it.","resolution":"1. Record where 6812 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANT_CREATE_MORE_STREAM_MINIVERSIONS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6812 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: It is not possible to create any more miniversions for this stream.\n\nLookup forms: 6812, 0x1A9C, error 6812, ERROR_CANT_CREATE_MORE_STREAM_MINIVERSIONS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6812"]},{"id":1593,"title":"ERROR_REMOTE_FILE_VERSION_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6814","0x1A9E","error 6814","ERROR_REMOTE_FILE_VERSION_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","remote","file","version","mismatch","the","server","sent","mismatching","number","fid","for","opened","with","transactions"],"errorCode":"6814","eventId":"","severity":"Low","summary":"The remote server sent mismatching version number or Fid for a file opened with transactions.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 6814; use the surrounding log entries to confirm it.","resolution":"1. Record where 6814 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REMOTE_FILE_VERSION_MISMATCH.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6814 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The remote server sent mismatching version number or Fid for a file opened with transactions.\n\nLookup forms: 6814, 0x1A9E, error 6814, ERROR_REMOTE_FILE_VERSION_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6814"]},{"id":1594,"title":"ERROR_HANDLE_NO_LONGER_VALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6815","0x1A9F","error 6815","ERROR_HANDLE_NO_LONGER_VALID","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","handle","longer","valid","the","has","been","invalidated","transaction","most","likely","cause","presence","memory","mapping","file","open","when","ended","rolled","back","savepoint"],"errorCode":"6815","eventId":"","severity":"Medium","summary":"The handle has been invalidated by a transaction. The most likely cause is the presence of memory mapping on a file or an open handle when the transaction ended or rolled back to savepoint.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6815; use the surrounding log entries to confirm it.","resolution":"1. Record where 6815 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_HANDLE_NO_LONGER_VALID.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6815 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The handle has been invalidated by a transaction. The most likely cause is the presence of memory mapping on a file or an open handle when the transaction ended or rolled back to savepoint.\n\nLookup forms: 6815, 0x1A9F, error 6815, ERROR_HANDLE_NO_LONGER_VALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6815"]},{"id":1595,"title":"ERROR_NO_TXF_METADATA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6816","0x1AA0","error 6816","ERROR_NO_TXF_METADATA","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","txf","metadata","there","transaction","the","file"],"errorCode":"6816","eventId":"","severity":"Low","summary":"There is no transaction metadata on the file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6816; use the surrounding log entries to confirm it.","resolution":"1. Record where 6816 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_TXF_METADATA.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6816 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There is no transaction metadata on the file.\n\nLookup forms: 6816, 0x1AA0, error 6816, ERROR_NO_TXF_METADATA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6816"]},{"id":1596,"title":"ERROR_LOG_CORRUPTION_DETECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6817","0x1AA1","error 6817","ERROR_LOG_CORRUPTION_DETECTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","log","corruption","detected","the","data","corrupt"],"errorCode":"6817","eventId":"","severity":"Critical","summary":"The log data is corrupt.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6817; use the surrounding log entries to confirm it.","resolution":"1. Record where 6817 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_CORRUPTION_DETECTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6817 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The log data is corrupt.\n\nLookup forms: 6817, 0x1AA1, error 6817, ERROR_LOG_CORRUPTION_DETECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6817"]},{"id":1597,"title":"ERROR_CANT_RECOVER_WITH_HANDLE_OPEN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6818","0x1AA2","error 6818","ERROR_CANT_RECOVER_WITH_HANDLE_OPEN","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","cant","recover","with","handle","open","the","file","can","recovered","because","there","still"],"errorCode":"6818","eventId":"","severity":"Low","summary":"The file can't be recovered because there is a handle still open on it.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6818; use the surrounding log entries to confirm it.","resolution":"1. Record where 6818 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANT_RECOVER_WITH_HANDLE_OPEN.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6818 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file can't be recovered because there is a handle still open on it.\n\nLookup forms: 6818, 0x1AA2, error 6818, ERROR_CANT_RECOVER_WITH_HANDLE_OPEN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6818"]},{"id":1598,"title":"ERROR_RM_DISCONNECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6819","0x1AA3","error 6819","ERROR_RM_DISCONNECTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","disconnected","the","transaction","outcome","unavailable","because","resource","manager","responsible","for","has"],"errorCode":"6819","eventId":"","severity":"Low","summary":"The transaction outcome is unavailable because the resource manager responsible for it has disconnected.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6819; use the surrounding log entries to confirm it.","resolution":"1. Record where 6819 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RM_DISCONNECTED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6819 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The transaction outcome is unavailable because the resource manager responsible for it has disconnected.\n\nLookup forms: 6819, 0x1AA3, error 6819, ERROR_RM_DISCONNECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6819"]},{"id":1599,"title":"ERROR_ENLISTMENT_NOT_SUPERIOR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6820","0x1AA4","error 6820","ERROR_ENLISTMENT_NOT_SUPERIOR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","enlistment","not","superior","the","request","was","rejected","because","question"],"errorCode":"6820","eventId":"","severity":"Low","summary":"The request was rejected because the enlistment in question is not a superior enlistment.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6820; use the surrounding log entries to confirm it.","resolution":"1. Record where 6820 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ENLISTMENT_NOT_SUPERIOR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6820 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The request was rejected because the enlistment in question is not a superior enlistment.\n\nLookup forms: 6820, 0x1AA4, error 6820, ERROR_ENLISTMENT_NOT_SUPERIOR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6820"]},{"id":1600,"title":"ERROR_RECOVERY_NOT_NEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6821","0x1AA5","error 6821","ERROR_RECOVERY_NOT_NEEDED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","recovery","not","needed","the","transactional","resource","manager","already","consistent"],"errorCode":"6821","eventId":"","severity":"Low","summary":"The transactional resource manager is already consistent. Recovery is not needed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6821; use the surrounding log entries to confirm it.","resolution":"1. Record where 6821 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RECOVERY_NOT_NEEDED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6821 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The transactional resource manager is already consistent. Recovery is not needed.\n\nLookup forms: 6821, 0x1AA5, error 6821, ERROR_RECOVERY_NOT_NEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6821"]},{"id":1601,"title":"ERROR_RM_ALREADY_STARTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6822","0x1AA6","error 6822","ERROR_RM_ALREADY_STARTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","already","started","the","transactional","resource","manager","has","been"],"errorCode":"6822","eventId":"","severity":"Low","summary":"The transactional resource manager has already been started.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6822; use the surrounding log entries to confirm it.","resolution":"1. Record where 6822 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RM_ALREADY_STARTED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6822 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The transactional resource manager has already been started.\n\nLookup forms: 6822, 0x1AA6, error 6822, ERROR_RM_ALREADY_STARTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6822"]},{"id":1602,"title":"ERROR_FILE_IDENTITY_NOT_PERSISTENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6823","0x1AA7","error 6823","ERROR_FILE_IDENTITY_NOT_PERSISTENT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","file","identity","not","persistent","the","cannot","opened","transactionally","because","its","depends","outcome","unresolved","transaction"],"errorCode":"6823","eventId":"","severity":"Medium","summary":"The file cannot be opened transactionally, because its identity depends on the outcome of an unresolved transaction.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6823; use the surrounding log entries to confirm it.","resolution":"1. Record where 6823 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FILE_IDENTITY_NOT_PERSISTENT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6823 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file cannot be opened transactionally, because its identity depends on the outcome of an unresolved transaction.\n\nLookup forms: 6823, 0x1AA7, error 6823, ERROR_FILE_IDENTITY_NOT_PERSISTENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6823"]},{"id":1603,"title":"ERROR_CANT_BREAK_TRANSACTIONAL_DEPENDENCY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6824","0x1AA8","error 6824","ERROR_CANT_BREAK_TRANSACTIONAL_DEPENDENCY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","break","transactional","dependency","the","operation","cannot","performed","because","another","transaction","depending","fact","that","this","property","will","not","change"],"errorCode":"6824","eventId":"","severity":"Medium","summary":"The operation cannot be performed because another transaction is depending on the fact that this property will not change.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6824; use the surrounding log entries to confirm it.","resolution":"1. Record where 6824 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANT_BREAK_TRANSACTIONAL_DEPENDENCY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6824 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation cannot be performed because another transaction is depending on the fact that this property will not change.\n\nLookup forms: 6824, 0x1AA8, error 6824, ERROR_CANT_BREAK_TRANSACTIONAL_DEPENDENCY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6824"]},{"id":1604,"title":"ERROR_CANT_CROSS_RM_BOUNDARY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6825","0x1AA9","error 6825","ERROR_CANT_CROSS_RM_BOUNDARY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","cant","cross","boundary","the","operation","would","involve","single","file","with","two","transactional","resource","managers","and","therefore","not","allowed"],"errorCode":"6825","eventId":"","severity":"Low","summary":"The operation would involve a single file with two transactional resource managers and is therefore not allowed.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6825; use the surrounding log entries to confirm it.","resolution":"1. Record where 6825 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANT_CROSS_RM_BOUNDARY.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6825 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation would involve a single file with two transactional resource managers and is therefore not allowed.\n\nLookup forms: 6825, 0x1AA9, error 6825, ERROR_CANT_CROSS_RM_BOUNDARY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6825"]},{"id":1605,"title":"ERROR_TXF_DIR_NOT_EMPTY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6826","0x1AAA","error 6826","ERROR_TXF_DIR_NOT_EMPTY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","txf","dir","not","empty","the","directory","must","for","this","operation","succeed"],"errorCode":"6826","eventId":"","severity":"Low","summary":"The $Txf directory must be empty for this operation to succeed.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6826; use the surrounding log entries to confirm it.","resolution":"1. Record where 6826 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TXF_DIR_NOT_EMPTY.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6826 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The $Txf directory must be empty for this operation to succeed.\n\nLookup forms: 6826, 0x1AAA, error 6826, ERROR_TXF_DIR_NOT_EMPTY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6826"]},{"id":1606,"title":"ERROR_INDOUBT_TRANSACTIONS_EXIST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6827","0x1AAB","error 6827","ERROR_INDOUBT_TRANSACTIONS_EXIST","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","indoubt","transactions","exist","the","operation","would","leave","transactional","resource","manager","inconsistent","state","and","therefore","not","allowed"],"errorCode":"6827","eventId":"","severity":"Low","summary":"The operation would leave a transactional resource manager in an inconsistent state and is therefore not allowed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6827; use the surrounding log entries to confirm it.","resolution":"1. Record where 6827 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INDOUBT_TRANSACTIONS_EXIST.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6827 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation would leave a transactional resource manager in an inconsistent state and is therefore not allowed.\n\nLookup forms: 6827, 0x1AAB, error 6827, ERROR_INDOUBT_TRANSACTIONS_EXIST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6827"]},{"id":1607,"title":"ERROR_TM_VOLATILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6828","0x1AAC","error 6828","ERROR_TM_VOLATILE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","volatile","the","operation","could","not","completed","because","transaction","manager","does","have","log"],"errorCode":"6828","eventId":"","severity":"Low","summary":"The operation could not be completed because the transaction manager does not have a log.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6828; use the surrounding log entries to confirm it.","resolution":"1. Record where 6828 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TM_VOLATILE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6828 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation could not be completed because the transaction manager does not have a log.\n\nLookup forms: 6828, 0x1AAC, error 6828, ERROR_TM_VOLATILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6828"]},{"id":1608,"title":"ERROR_ROLLBACK_TIMER_EXPIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6829","0x1AAD","error 6829","ERROR_ROLLBACK_TIMER_EXPIRED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","rollback","timer","expired","could","not","scheduled","because","previously","has","already","executed","been","queued","for","execution"],"errorCode":"6829","eventId":"","severity":"Low","summary":"A rollback could not be scheduled because a previously scheduled rollback has already executed or been queued for execution.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6829; use the surrounding log entries to confirm it.","resolution":"1. Record where 6829 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ROLLBACK_TIMER_EXPIRED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6829 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A rollback could not be scheduled because a previously scheduled rollback has already executed or been queued for execution.\n\nLookup forms: 6829, 0x1AAD, error 6829, ERROR_ROLLBACK_TIMER_EXPIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6829"]},{"id":1609,"title":"ERROR_TXF_ATTRIBUTE_CORRUPT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6830","0x1AAE","error 6830","ERROR_TXF_ATTRIBUTE_CORRUPT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","txf","attribute","corrupt","the","transactional","metadata","file","directory","and","unreadable"],"errorCode":"6830","eventId":"","severity":"Critical","summary":"The transactional metadata attribute on the file or directory is corrupt and unreadable.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6830; use the surrounding log entries to confirm it.","resolution":"1. Record where 6830 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TXF_ATTRIBUTE_CORRUPT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6830 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The transactional metadata attribute on the file or directory is corrupt and unreadable.\n\nLookup forms: 6830, 0x1AAE, error 6830, ERROR_TXF_ATTRIBUTE_CORRUPT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6830"]},{"id":1610,"title":"ERROR_EFS_NOT_ALLOWED_IN_TRANSACTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6831","0x1AAF","error 6831","ERROR_EFS_NOT_ALLOWED_IN_TRANSACTION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","efs","not","allowed","transaction","the","encryption","operation","could","completed","because","active"],"errorCode":"6831","eventId":"","severity":"Low","summary":"The encryption operation could not be completed because a transaction is active.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6831; use the surrounding log entries to confirm it.","resolution":"1. Record where 6831 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EFS_NOT_ALLOWED_IN_TRANSACTION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6831 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The encryption operation could not be completed because a transaction is active.\n\nLookup forms: 6831, 0x1AAF, error 6831, ERROR_EFS_NOT_ALLOWED_IN_TRANSACTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6831"]},{"id":1611,"title":"ERROR_TRANSACTIONAL_OPEN_NOT_ALLOWED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6832","0x1AB0","error 6832","ERROR_TRANSACTIONAL_OPEN_NOT_ALLOWED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","transactional","open","not","allowed","this","object","opened","transaction"],"errorCode":"6832","eventId":"","severity":"Low","summary":"This object is not allowed to be opened in a transaction.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6832; use the surrounding log entries to confirm it.","resolution":"1. Record where 6832 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTIONAL_OPEN_NOT_ALLOWED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6832 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This object is not allowed to be opened in a transaction.\n\nLookup forms: 6832, 0x1AB0, error 6832, ERROR_TRANSACTIONAL_OPEN_NOT_ALLOWED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6832"]},{"id":1612,"title":"ERROR_LOG_GROWTH_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6833","0x1AB1","error 6833","ERROR_LOG_GROWTH_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","log","growth","failed","attempt","create","space","the","transactional","resource","manager","failure","status","has","been","recorded","event"],"errorCode":"6833","eventId":"","severity":"High","summary":"An attempt to create space in the transactional resource manager's log failed. The failure status has been recorded in the event log.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6833; use the surrounding log entries to confirm it.","resolution":"1. Record where 6833 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_LOG_GROWTH_FAILED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6833 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt to create space in the transactional resource manager's log failed. The failure status has been recorded in the event log.\n\nLookup forms: 6833, 0x1AB1, error 6833, ERROR_LOG_GROWTH_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6833"]},{"id":1613,"title":"ERROR_TRANSACTED_MAPPING_UNSUPPORTED_REMOTE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6834","0x1AB2","error 6834","ERROR_TRANSACTED_MAPPING_UNSUPPORTED_REMOTE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","transacted","mapping","unsupported","remote","memory","creating","mapped","section","file","under","transaction","not","supported"],"errorCode":"6834","eventId":"","severity":"Medium","summary":"Memory mapping (creating a mapped section) a remote file under a transaction is not supported.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6834; use the surrounding log entries to confirm it.","resolution":"1. Record where 6834 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTED_MAPPING_UNSUPPORTED_REMOTE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6834 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Memory mapping (creating a mapped section) a remote file under a transaction is not supported.\n\nLookup forms: 6834, 0x1AB2, error 6834, ERROR_TRANSACTED_MAPPING_UNSUPPORTED_REMOTE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6834"]},{"id":1614,"title":"ERROR_TXF_METADATA_ALREADY_PRESENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6835","0x1AB3","error 6835","ERROR_TXF_METADATA_ALREADY_PRESENT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","txf","metadata","already","present","transaction","this","file","and","cannot","superseded"],"errorCode":"6835","eventId":"","severity":"Medium","summary":"Transaction metadata is already present on this file and cannot be superseded.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6835; use the surrounding log entries to confirm it.","resolution":"1. Record where 6835 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TXF_METADATA_ALREADY_PRESENT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6835 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Transaction metadata is already present on this file and cannot be superseded.\n\nLookup forms: 6835, 0x1AB3, error 6835, ERROR_TXF_METADATA_ALREADY_PRESENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6835"]},{"id":1615,"title":"ERROR_TRANSACTION_SCOPE_CALLBACKS_NOT_SET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6836","0x1AB4","error 6836","ERROR_TRANSACTION_SCOPE_CALLBACKS_NOT_SET","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","transaction","scope","callbacks","not","set","could","entered","because","the","handler","has","been","initialized"],"errorCode":"6836","eventId":"","severity":"Low","summary":"A transaction scope could not be entered because the scope handler has not been initialized.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6836; use the surrounding log entries to confirm it.","resolution":"1. Record where 6836 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTION_SCOPE_CALLBACKS_NOT_SET.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6836 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A transaction scope could not be entered because the scope handler has not been initialized.\n\nLookup forms: 6836, 0x1AB4, error 6836, ERROR_TRANSACTION_SCOPE_CALLBACKS_NOT_SET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6836"]},{"id":1616,"title":"ERROR_TRANSACTION_REQUIRED_PROMOTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6837","0x1AB5","error 6837","ERROR_TRANSACTION_REQUIRED_PROMOTION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","transaction","required","promotion","was","order","allow","the","resource","manager","enlist","but","set","disallow"],"errorCode":"6837","eventId":"","severity":"Low","summary":"Promotion was required in order to allow the resource manager to enlist, but the transaction was set to disallow it.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6837; use the surrounding log entries to confirm it.","resolution":"1. Record where 6837 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTION_REQUIRED_PROMOTION.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6837 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Promotion was required in order to allow the resource manager to enlist, but the transaction was set to disallow it.\n\nLookup forms: 6837, 0x1AB5, error 6837, ERROR_TRANSACTION_REQUIRED_PROMOTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6837"]},{"id":1617,"title":"ERROR_CANNOT_EXECUTE_FILE_IN_TRANSACTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6838","0x1AB6","error 6838","ERROR_CANNOT_EXECUTE_FILE_IN_TRANSACTION","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","cannot","execute","file","transaction","this","open","for","modification","unresolved","and","may","opened","only","transacted","reader"],"errorCode":"6838","eventId":"","severity":"Low","summary":"This file is open for modification in an unresolved transaction and may be opened for execute only by a transacted reader.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6838; use the surrounding log entries to confirm it.","resolution":"1. Record where 6838 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANNOT_EXECUTE_FILE_IN_TRANSACTION.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6838 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This file is open for modification in an unresolved transaction and may be opened for execute only by a transacted reader.\n\nLookup forms: 6838, 0x1AB6, error 6838, ERROR_CANNOT_EXECUTE_FILE_IN_TRANSACTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6838"]},{"id":1618,"title":"ERROR_TRANSACTIONS_NOT_FROZEN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6839","0x1AB7","error 6839","ERROR_TRANSACTIONS_NOT_FROZEN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","transactions","not","frozen","the","request","thaw","was","ignored","because","had","previously","been"],"errorCode":"6839","eventId":"","severity":"Low","summary":"The request to thaw frozen transactions was ignored because transactions had not previously been frozen.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6839; use the surrounding log entries to confirm it.","resolution":"1. Record where 6839 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTIONS_NOT_FROZEN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6839 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The request to thaw frozen transactions was ignored because transactions had not previously been frozen.\n\nLookup forms: 6839, 0x1AB7, error 6839, ERROR_TRANSACTIONS_NOT_FROZEN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6839"]},{"id":1619,"title":"ERROR_TRANSACTION_FREEZE_IN_PROGRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6840","0x1AB8","error 6840","ERROR_TRANSACTION_FREEZE_IN_PROGRESS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","transaction","freeze","progress","transactions","cannot","frozen","because","already"],"errorCode":"6840","eventId":"","severity":"Medium","summary":"Transactions cannot be frozen because a freeze is already in progress.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6840; use the surrounding log entries to confirm it.","resolution":"1. Record where 6840 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTION_FREEZE_IN_PROGRESS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6840 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Transactions cannot be frozen because a freeze is already in progress.\n\nLookup forms: 6840, 0x1AB8, error 6840, ERROR_TRANSACTION_FREEZE_IN_PROGRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6840"]},{"id":1620,"title":"ERROR_NOT_SNAPSHOT_VOLUME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6841","0x1AB9","error 6841","ERROR_NOT_SNAPSHOT_VOLUME","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","not","snapshot","volume","the","target","this","operation","only","valid","mounted"],"errorCode":"6841","eventId":"","severity":"Low","summary":"The target volume is not a snapshot volume. This operation is only valid on a volume mounted as a snapshot.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6841; use the surrounding log entries to confirm it.","resolution":"1. Record where 6841 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_SNAPSHOT_VOLUME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6841 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The target volume is not a snapshot volume. This operation is only valid on a volume mounted as a snapshot.\n\nLookup forms: 6841, 0x1AB9, error 6841, ERROR_NOT_SNAPSHOT_VOLUME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6841"]},{"id":1621,"title":"ERROR_NO_SAVEPOINT_WITH_OPEN_FILES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6842","0x1ABA","error 6842","ERROR_NO_SAVEPOINT_WITH_OPEN_FILES","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","savepoint","with","open","files","the","operation","failed","because","are","transaction","this","not","permitted"],"errorCode":"6842","eventId":"","severity":"High","summary":"The savepoint operation failed because files are open on the transaction. This is not permitted.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6842; use the surrounding log entries to confirm it.","resolution":"1. Record where 6842 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_SAVEPOINT_WITH_OPEN_FILES.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6842 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The savepoint operation failed because files are open on the transaction. This is not permitted.\n\nLookup forms: 6842, 0x1ABA, error 6842, ERROR_NO_SAVEPOINT_WITH_OPEN_FILES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6842"]},{"id":1622,"title":"ERROR_DATA_LOST_REPAIR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6843","0x1ABB","error 6843","ERROR_DATA_LOST_REPAIR","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","data","lost","repair","windows","has","discovered","corruption","file","and","that","since","been","repaired","loss","may","have","occurred"],"errorCode":"6843","eventId":"","severity":"Critical","summary":"Windows has discovered corruption in a file, and that file has since been repaired. Data loss may have occurred.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6843; use the surrounding log entries to confirm it.","resolution":"1. Record where 6843 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DATA_LOST_REPAIR.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6843 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Windows has discovered corruption in a file, and that file has since been repaired. Data loss may have occurred.\n\nLookup forms: 6843, 0x1ABB, error 6843, ERROR_DATA_LOST_REPAIR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6843"]},{"id":1623,"title":"ERROR_SPARSE_NOT_ALLOWED_IN_TRANSACTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6844","0x1ABC","error 6844","ERROR_SPARSE_NOT_ALLOWED_IN_TRANSACTION","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","sparse","not","allowed","transaction","the","operation","could","completed","because","active","file"],"errorCode":"6844","eventId":"","severity":"Low","summary":"The sparse operation could not be completed because a transaction is active on the file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6844; use the surrounding log entries to confirm it.","resolution":"1. Record where 6844 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SPARSE_NOT_ALLOWED_IN_TRANSACTION.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6844 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The sparse operation could not be completed because a transaction is active on the file.\n\nLookup forms: 6844, 0x1ABC, error 6844, ERROR_SPARSE_NOT_ALLOWED_IN_TRANSACTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6844"]},{"id":1624,"title":"ERROR_TM_IDENTITY_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6845","0x1ABD","error 6845","ERROR_TM_IDENTITY_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","identity","mismatch","the","call","create","transactionmanager","object","failed","because","stored","logfile","does","not","match","that","was","passed","argument"],"errorCode":"6845","eventId":"","severity":"High","summary":"The call to create a TransactionManager object failed because the Tm Identity stored in the logfile does not match the Tm Identity that was passed in as an argument.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6845; use the surrounding log entries to confirm it.","resolution":"1. Record where 6845 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TM_IDENTITY_MISMATCH.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6845 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The call to create a TransactionManager object failed because the Tm Identity stored in the logfile does not match the Tm Identity that was passed in as an argument.\n\nLookup forms: 6845, 0x1ABD, error 6845, ERROR_TM_IDENTITY_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6845"]},{"id":1625,"title":"ERROR_FLOATED_SECTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6846","0x1ABE","error 6846","ERROR_FLOATED_SECTION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","floated","section","was","attempted","object","that","has","been","result","transaction","ending","there","valid","data"],"errorCode":"6846","eventId":"","severity":"Low","summary":"I/O was attempted on a section object that has been floated as a result of a transaction ending. There is no valid data.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6846; use the surrounding log entries to confirm it.","resolution":"1. Record where 6846 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_FLOATED_SECTION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6846 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: I/O was attempted on a section object that has been floated as a result of a transaction ending. There is no valid data.\n\nLookup forms: 6846, 0x1ABE, error 6846, ERROR_FLOATED_SECTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6846"]},{"id":1626,"title":"ERROR_CANNOT_ACCEPT_TRANSACTED_WORK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6847","0x1ABF","error 6847","ERROR_CANNOT_ACCEPT_TRANSACTED_WORK","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cannot","accept","transacted","work","the","transactional","resource","manager","currently","due","transient","condition","such","low","resources"],"errorCode":"6847","eventId":"","severity":"Medium","summary":"The transactional resource manager cannot currently accept transacted work due to a transient condition such as low resources.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6847; use the surrounding log entries to confirm it.","resolution":"1. Record where 6847 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANNOT_ACCEPT_TRANSACTED_WORK.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6847 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The transactional resource manager cannot currently accept transacted work due to a transient condition such as low resources.\n\nLookup forms: 6847, 0x1ABF, error 6847, ERROR_CANNOT_ACCEPT_TRANSACTED_WORK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6847"]},{"id":1627,"title":"ERROR_CANNOT_ABORT_TRANSACTIONS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6848","0x1AC0","error 6848","ERROR_CANNOT_ABORT_TRANSACTIONS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cannot","abort","transactions","the","transactional","resource","manager","had","too","many","outstanding","that","could","not","aborted","manger","has","been","shut","down"],"errorCode":"6848","eventId":"","severity":"Low","summary":"The transactional resource manager had too many transactions outstanding that could not be aborted. The transactional resource manger has been shut down.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6848; use the surrounding log entries to confirm it.","resolution":"1. Record where 6848 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANNOT_ABORT_TRANSACTIONS.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6848 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The transactional resource manager had too many transactions outstanding that could not be aborted. The transactional resource manger has been shut down.\n\nLookup forms: 6848, 0x1AC0, error 6848, ERROR_CANNOT_ABORT_TRANSACTIONS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6848"]},{"id":1628,"title":"ERROR_BAD_CLUSTERS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6849","0x1AC1","error 6849","ERROR_BAD_CLUSTERS","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","bad","clusters","the","operation","could","not","completed","due","disk"],"errorCode":"6849","eventId":"","severity":"Low","summary":"The operation could not be completed due to bad clusters on disk.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6849; use the surrounding log entries to confirm it.","resolution":"1. Record where 6849 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_BAD_CLUSTERS.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6849 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation could not be completed due to bad clusters on disk.\n\nLookup forms: 6849, 0x1AC1, error 6849, ERROR_BAD_CLUSTERS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6849"]},{"id":1629,"title":"ERROR_COMPRESSION_NOT_ALLOWED_IN_TRANSACTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6850","0x1AC2","error 6850","ERROR_COMPRESSION_NOT_ALLOWED_IN_TRANSACTION","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","compression","not","allowed","transaction","the","operation","could","completed","because","active","file"],"errorCode":"6850","eventId":"","severity":"Low","summary":"The compression operation could not be completed because a transaction is active on the file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6850; use the surrounding log entries to confirm it.","resolution":"1. Record where 6850 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_COMPRESSION_NOT_ALLOWED_IN_TRANSACTION.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6850 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The compression operation could not be completed because a transaction is active on the file.\n\nLookup forms: 6850, 0x1AC2, error 6850, ERROR_COMPRESSION_NOT_ALLOWED_IN_TRANSACTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6850"]},{"id":1630,"title":"ERROR_VOLUME_DIRTY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6851","0x1AC3","error 6851","ERROR_VOLUME_DIRTY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","volume","dirty","the","operation","could","not","completed","because","please","run","chkdsk","and","try","again"],"errorCode":"6851","eventId":"","severity":"Low","summary":"The operation could not be completed because the volume is dirty. Please run chkdsk and try again.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 6851; use the surrounding log entries to confirm it.","resolution":"1. Record where 6851 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_VOLUME_DIRTY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6851 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation could not be completed because the volume is dirty. Please run chkdsk and try again.\n\nLookup forms: 6851, 0x1AC3, error 6851, ERROR_VOLUME_DIRTY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6851"]},{"id":1631,"title":"ERROR_NO_LINK_TRACKING_IN_TRANSACTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6852","0x1AC4","error 6852","ERROR_NO_LINK_TRACKING_IN_TRANSACTION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","link","tracking","transaction","the","operation","could","not","completed","because","active"],"errorCode":"6852","eventId":"","severity":"Low","summary":"The link tracking operation could not be completed because a transaction is active.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6852; use the surrounding log entries to confirm it.","resolution":"1. Record where 6852 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_LINK_TRACKING_IN_TRANSACTION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6852 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The link tracking operation could not be completed because a transaction is active.\n\nLookup forms: 6852, 0x1AC4, error 6852, ERROR_NO_LINK_TRACKING_IN_TRANSACTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6852"]},{"id":1632,"title":"ERROR_OPERATION_NOT_SUPPORTED_IN_TRANSACTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6853","0x1AC5","error 6853","ERROR_OPERATION_NOT_SUPPORTED_IN_TRANSACTION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","operation","not","supported","transaction","this","cannot","performed"],"errorCode":"6853","eventId":"","severity":"Medium","summary":"This operation cannot be performed in a transaction.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6853; use the surrounding log entries to confirm it.","resolution":"1. Record where 6853 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_OPERATION_NOT_SUPPORTED_IN_TRANSACTION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6853 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation cannot be performed in a transaction.\n\nLookup forms: 6853, 0x1AC5, error 6853, ERROR_OPERATION_NOT_SUPPORTED_IN_TRANSACTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6853"]},{"id":1633,"title":"ERROR_EXPIRED_HANDLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6854","0x1AC6","error 6854","ERROR_EXPIRED_HANDLE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","expired","handle","the","longer","properly","associated","with","its","transaction","may","have","been","opened","transactional","resource","manager","that","was","subsequently","forced","restart","please","close","and"],"errorCode":"6854","eventId":"","severity":"Low","summary":"The handle is no longer properly associated with its transaction. It may have been opened in a transactional resource manager that was subsequently forced to restart. Please close the handle and open a new one.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 6854; use the surrounding log entries to confirm it.","resolution":"1. Record where 6854 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EXPIRED_HANDLE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6854 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The handle is no longer properly associated with its transaction. It may have been opened in a transactional resource manager that was subsequently forced to restart. Please close the handle and open a new one.\n\nLookup forms: 6854, 0x1AC6, error 6854, ERROR_EXPIRED_HANDLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6854"]},{"id":1634,"title":"ERROR_TRANSACTION_NOT_ENLISTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["6855","0x1AC7","error 6855","ERROR_TRANSACTION_NOT_ENLISTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","transaction","not","enlisted","the","specified","operation","could","performed","because","resource","manager"],"errorCode":"6855","eventId":"","severity":"Low","summary":"The specified operation could not be performed because the resource manager is not enlisted in the transaction.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 6855; use the surrounding log entries to confirm it.","resolution":"1. Record where 6855 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TRANSACTION_NOT_ENLISTED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 6855 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified operation could not be performed because the resource manager is not enlisted in the transaction.\n\nLookup forms: 6855, 0x1AC7, error 6855, ERROR_TRANSACTION_NOT_ENLISTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["6855"]},{"id":1635,"title":"ERROR_CTX_WINSTATION_NAME_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7001","0x1B59","error 7001","ERROR_CTX_WINSTATION_NAME_INVALID","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ctx","winstation","name","invalid","the","specified","session"],"errorCode":"7001","eventId":"","severity":"Medium","summary":"The specified session name is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 7001; use the surrounding log entries to confirm it.","resolution":"1. Record where 7001 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_WINSTATION_NAME_INVALID.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7001 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified session name is invalid.\n\nLookup forms: 7001, 0x1B59, error 7001, ERROR_CTX_WINSTATION_NAME_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7001"]},{"id":1636,"title":"ERROR_CTX_INVALID_PD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7002","0x1B5A","error 7002","ERROR_CTX_INVALID_PD","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","ctx","invalid","the","specified","protocol","driver"],"errorCode":"7002","eventId":"","severity":"Medium","summary":"The specified protocol driver is invalid.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 7002; use the surrounding log entries to confirm it.","resolution":"1. Record where 7002 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_INVALID_PD.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7002 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified protocol driver is invalid.\n\nLookup forms: 7002, 0x1B5A, error 7002, ERROR_CTX_INVALID_PD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7002"]},{"id":1637,"title":"ERROR_CTX_PD_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7003","0x1B5B","error 7003","ERROR_CTX_PD_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","ctx","not","found","the","specified","protocol","driver","was","system","path"],"errorCode":"7003","eventId":"","severity":"Medium","summary":"The specified protocol driver was not found in the system path.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 7003; use the surrounding log entries to confirm it.","resolution":"1. Record where 7003 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_PD_NOT_FOUND.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7003 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified protocol driver was not found in the system path.\n\nLookup forms: 7003, 0x1B5B, error 7003, ERROR_CTX_PD_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7003"]},{"id":1638,"title":"ERROR_CTX_WD_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7004","0x1B5C","error 7004","ERROR_CTX_WD_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","ctx","not","found","the","specified","terminal","connection","driver","was","system","path"],"errorCode":"7004","eventId":"","severity":"High","summary":"The specified terminal connection driver was not found in the system path.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 7004; use the surrounding log entries to confirm it.","resolution":"1. Record where 7004 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_WD_NOT_FOUND.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7004 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified terminal connection driver was not found in the system path.\n\nLookup forms: 7004, 0x1B5C, error 7004, ERROR_CTX_WD_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7004"]},{"id":1639,"title":"ERROR_CTX_CANNOT_MAKE_EVENTLOG_ENTRY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7005","0x1B5D","error 7005","ERROR_CTX_CANNOT_MAKE_EVENTLOG_ENTRY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ctx","cannot","make","eventlog","entry","registry","key","for","event","logging","could","not","created","this","session"],"errorCode":"7005","eventId":"","severity":"Low","summary":"A registry key for event logging could not be created for this session.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 7005; use the surrounding log entries to confirm it.","resolution":"1. Record where 7005 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_CANNOT_MAKE_EVENTLOG_ENTRY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7005 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A registry key for event logging could not be created for this session.\n\nLookup forms: 7005, 0x1B5D, error 7005, ERROR_CTX_CANNOT_MAKE_EVENTLOG_ENTRY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7005"]},{"id":1640,"title":"ERROR_CTX_SERVICE_NAME_COLLISION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7006","0x1B5E","error 7006","ERROR_CTX_SERVICE_NAME_COLLISION","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","ctx","service","name","collision","with","the","same","already","exists","system"],"errorCode":"7006","eventId":"","severity":"Medium","summary":"A service with the same name already exists on the system.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 7006; use the surrounding log entries to confirm it.","resolution":"1. Record where 7006 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_SERVICE_NAME_COLLISION.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7006 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A service with the same name already exists on the system.\n\nLookup forms: 7006, 0x1B5E, error 7006, ERROR_CTX_SERVICE_NAME_COLLISION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7006"]},{"id":1641,"title":"ERROR_CTX_CLOSE_PENDING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7007","0x1B5F","error 7007","ERROR_CTX_CLOSE_PENDING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ctx","close","pending","operation","the","session"],"errorCode":"7007","eventId":"","severity":"Low","summary":"A close operation is pending on the session.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 7007; use the surrounding log entries to confirm it.","resolution":"1. Record where 7007 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_CLOSE_PENDING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7007 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A close operation is pending on the session.\n\nLookup forms: 7007, 0x1B5F, error 7007, ERROR_CTX_CLOSE_PENDING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7007"]},{"id":1642,"title":"ERROR_CTX_NO_OUTBUF","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7008","0x1B60","error 7008","ERROR_CTX_NO_OUTBUF","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","ctx","outbuf","there","are","free","output","buffers","available"],"errorCode":"7008","eventId":"","severity":"Low","summary":"There are no free output buffers available.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 7008; use the surrounding log entries to confirm it.","resolution":"1. Record where 7008 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_NO_OUTBUF.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7008 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There are no free output buffers available.\n\nLookup forms: 7008, 0x1B60, error 7008, ERROR_CTX_NO_OUTBUF. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7008"]},{"id":1643,"title":"ERROR_CTX_MODEM_INF_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7009","0x1B61","error 7009","ERROR_CTX_MODEM_INF_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","ctx","modem","inf","not","found","the","file","was"],"errorCode":"7009","eventId":"","severity":"Medium","summary":"The MODEM.INF file was not found.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 7009; use the surrounding log entries to confirm it.","resolution":"1. Record where 7009 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_MODEM_INF_NOT_FOUND.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7009 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The MODEM.INF file was not found.\n\nLookup forms: 7009, 0x1B61, error 7009, ERROR_CTX_MODEM_INF_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7009"]},{"id":1644,"title":"ERROR_CTX_INVALID_MODEMNAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7010","0x1B62","error 7010","ERROR_CTX_INVALID_MODEMNAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ctx","invalid","modemname","the","modem","name","was","not","found","inf"],"errorCode":"7010","eventId":"","severity":"Medium","summary":"The modem name was not found in MODEM.INF.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 7010; use the surrounding log entries to confirm it.","resolution":"1. Record where 7010 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_INVALID_MODEMNAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7010 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The modem name was not found in MODEM.INF.\n\nLookup forms: 7010, 0x1B62, error 7010, ERROR_CTX_INVALID_MODEMNAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7010"]},{"id":1645,"title":"ERROR_CTX_MODEM_RESPONSE_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7011","0x1B63","error 7011","ERROR_CTX_MODEM_RESPONSE_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ctx","modem","response","the","did","not","accept","command","sent","verify","that","configured","name","matches","attached"],"errorCode":"7011","eventId":"","severity":"Low","summary":"The modem did not accept the command sent to it. Verify that the configured modem name matches the attached modem.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 7011; use the surrounding log entries to confirm it.","resolution":"1. Record where 7011 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_MODEM_RESPONSE_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7011 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The modem did not accept the command sent to it. Verify that the configured modem name matches the attached modem.\n\nLookup forms: 7011, 0x1B63, error 7011, ERROR_CTX_MODEM_RESPONSE_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7011"]},{"id":1646,"title":"ERROR_CTX_MODEM_RESPONSE_TIMEOUT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7012","0x1B64","error 7012","ERROR_CTX_MODEM_RESPONSE_TIMEOUT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ctx","modem","response","timeout","the","did","not","respond","command","sent","verify","that","properly","cabled","and","powered"],"errorCode":"7012","eventId":"","severity":"Low","summary":"The modem did not respond to the command sent to it. Verify that the modem is properly cabled and powered on.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 7012; use the surrounding log entries to confirm it.","resolution":"1. Record where 7012 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_MODEM_RESPONSE_TIMEOUT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7012 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The modem did not respond to the command sent to it. Verify that the modem is properly cabled and powered on.\n\nLookup forms: 7012, 0x1B64, error 7012, ERROR_CTX_MODEM_RESPONSE_TIMEOUT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7012"]},{"id":1647,"title":"ERROR_CTX_MODEM_RESPONSE_NO_CARRIER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7013","0x1B65","error 7013","ERROR_CTX_MODEM_RESPONSE_NO_CARRIER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ctx","modem","response","carrier","detect","has","failed","been","dropped","due","disconnect"],"errorCode":"7013","eventId":"","severity":"High","summary":"Carrier detect has failed or carrier has been dropped due to disconnect.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 7013; use the surrounding log entries to confirm it.","resolution":"1. Record where 7013 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_MODEM_RESPONSE_NO_CARRIER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7013 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Carrier detect has failed or carrier has been dropped due to disconnect.\n\nLookup forms: 7013, 0x1B65, error 7013, ERROR_CTX_MODEM_RESPONSE_NO_CARRIER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7013"]},{"id":1648,"title":"ERROR_CTX_MODEM_RESPONSE_NO_DIALTONE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7014","0x1B66","error 7014","ERROR_CTX_MODEM_RESPONSE_NO_DIALTONE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","ctx","modem","response","dialtone","dial","tone","not","detected","within","the","required","time","verify","that","phone","cable","properly","attached","and","functional"],"errorCode":"7014","eventId":"","severity":"Low","summary":"Dial tone not detected within the required time. Verify that the phone cable is properly attached and functional.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 7014; use the surrounding log entries to confirm it.","resolution":"1. Record where 7014 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_MODEM_RESPONSE_NO_DIALTONE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7014 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Dial tone not detected within the required time. Verify that the phone cable is properly attached and functional.\n\nLookup forms: 7014, 0x1B66, error 7014, ERROR_CTX_MODEM_RESPONSE_NO_DIALTONE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7014"]},{"id":1649,"title":"ERROR_CTX_MODEM_RESPONSE_BUSY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7015","0x1B67","error 7015","ERROR_CTX_MODEM_RESPONSE_BUSY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ctx","modem","response","busy","signal","detected","remote","site","callback"],"errorCode":"7015","eventId":"","severity":"Medium","summary":"Busy signal detected at remote site on callback.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 7015; use the surrounding log entries to confirm it.","resolution":"1. Record where 7015 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_MODEM_RESPONSE_BUSY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7015 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Busy signal detected at remote site on callback.\n\nLookup forms: 7015, 0x1B67, error 7015, ERROR_CTX_MODEM_RESPONSE_BUSY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7015"]},{"id":1650,"title":"ERROR_CTX_MODEM_RESPONSE_VOICE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7016","0x1B68","error 7016","ERROR_CTX_MODEM_RESPONSE_VOICE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ctx","modem","response","voice","detected","remote","site","callback"],"errorCode":"7016","eventId":"","severity":"Low","summary":"Voice detected at remote site on callback.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 7016; use the surrounding log entries to confirm it.","resolution":"1. Record where 7016 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_MODEM_RESPONSE_VOICE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7016 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Voice detected at remote site on callback.\n\nLookup forms: 7016, 0x1B68, error 7016, ERROR_CTX_MODEM_RESPONSE_VOICE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7016"]},{"id":1651,"title":"ERROR_CTX_TD_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7017","0x1B69","error 7017","ERROR_CTX_TD_ERROR","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","ctx","transport","driver"],"errorCode":"7017","eventId":"","severity":"Low","summary":"Transport driver error.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 7017; use the surrounding log entries to confirm it.","resolution":"1. Record where 7017 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_TD_ERROR.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7017 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Transport driver error.\n\nLookup forms: 7017, 0x1B69, error 7017, ERROR_CTX_TD_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7017"]},{"id":1652,"title":"ERROR_CTX_WINSTATION_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7022","0x1B6E","error 7022","ERROR_CTX_WINSTATION_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ctx","winstation","not","found","the","specified","session","cannot"],"errorCode":"7022","eventId":"","severity":"Medium","summary":"The specified session cannot be found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 7022; use the surrounding log entries to confirm it.","resolution":"1. Record where 7022 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_WINSTATION_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7022 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified session cannot be found.\n\nLookup forms: 7022, 0x1B6E, error 7022, ERROR_CTX_WINSTATION_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7022"]},{"id":1653,"title":"ERROR_CTX_WINSTATION_ALREADY_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7023","0x1B6F","error 7023","ERROR_CTX_WINSTATION_ALREADY_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ctx","winstation","already","exists","the","specified","session","name","use"],"errorCode":"7023","eventId":"","severity":"Low","summary":"The specified session name is already in use.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 7023; use the surrounding log entries to confirm it.","resolution":"1. Record where 7023 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_WINSTATION_ALREADY_EXISTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7023 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified session name is already in use.\n\nLookup forms: 7023, 0x1B6F, error 7023, ERROR_CTX_WINSTATION_ALREADY_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7023"]},{"id":1654,"title":"ERROR_CTX_WINSTATION_BUSY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7024","0x1B70","error 7024","ERROR_CTX_WINSTATION_BUSY","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","ctx","winstation","busy","the","task","you","are","trying","can","completed","because","remote","desktop","services","currently","please","try","again","few","minutes","other","users","should","still"],"errorCode":"7024","eventId":"","severity":"Medium","summary":"The task you are trying to do can't be completed because Remote Desktop Services is currently busy. Please try again in a few minutes. Other users should still be able to log on.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 7024; use the surrounding log entries to confirm it.","resolution":"1. Record where 7024 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_WINSTATION_BUSY.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7024 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The task you are trying to do can't be completed because Remote Desktop Services is currently busy. Please try again in a few minutes. Other users should still be able to log on.\n\nLookup forms: 7024, 0x1B70, error 7024, ERROR_CTX_WINSTATION_BUSY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The requested operation cannot be completed because the terminal connection is currently busy processing a connect, disconnect, reset, or delete operation.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7024"]},{"id":1655,"title":"ERROR_CTX_BAD_VIDEO_MODE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7025","0x1B71","error 7025","ERROR_CTX_BAD_VIDEO_MODE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ctx","bad","video","mode","attempt","has","been","made","connect","session","whose","not","supported","the","current","client"],"errorCode":"7025","eventId":"","severity":"Medium","summary":"An attempt has been made to connect to a session whose video mode is not supported by the current client.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 7025; use the surrounding log entries to confirm it.","resolution":"1. Record where 7025 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_BAD_VIDEO_MODE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7025 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt has been made to connect to a session whose video mode is not supported by the current client.\n\nLookup forms: 7025, 0x1B71, error 7025, ERROR_CTX_BAD_VIDEO_MODE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7025"]},{"id":1656,"title":"ERROR_CTX_GRAPHICS_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7035","0x1B7B","error 7035","ERROR_CTX_GRAPHICS_INVALID","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ctx","graphics","invalid","the","application","attempted","enable","dos","mode","not","supported"],"errorCode":"7035","eventId":"","severity":"Medium","summary":"The application attempted to enable DOS graphics mode. DOS graphics mode is not supported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 7035; use the surrounding log entries to confirm it.","resolution":"1. Record where 7035 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_GRAPHICS_INVALID.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7035 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The application attempted to enable DOS graphics mode. DOS graphics mode is not supported.\n\nLookup forms: 7035, 0x1B7B, error 7035, ERROR_CTX_GRAPHICS_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7035"]},{"id":1657,"title":"ERROR_CTX_LOGON_DISABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7037","0x1B7D","error 7037","ERROR_CTX_LOGON_DISABLED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ctx","logon","disabled","your","interactive","privilege","has","been","please","contact","administrator"],"errorCode":"7037","eventId":"","severity":"High","summary":"Your interactive logon privilege has been disabled. Please contact your administrator.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 7037; use the surrounding log entries to confirm it.","resolution":"1. Record where 7037 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_LOGON_DISABLED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7037 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Your interactive logon privilege has been disabled. Please contact your administrator.\n\nLookup forms: 7037, 0x1B7D, error 7037, ERROR_CTX_LOGON_DISABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7037"]},{"id":1658,"title":"ERROR_CTX_NOT_CONSOLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7038","0x1B7E","error 7038","ERROR_CTX_NOT_CONSOLE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ctx","not","console","the","requested","operation","can","performed","only","system","this","most","often","result","driver","dll","requiring","direct","access"],"errorCode":"7038","eventId":"","severity":"Low","summary":"The requested operation can be performed only on the system console. This is most often the result of a driver or system DLL requiring direct console access.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 7038; use the surrounding log entries to confirm it.","resolution":"1. Record where 7038 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Confirm the user or service identity has the required permissions and is not locked or disabled.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_NOT_CONSOLE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Confirm the user or service identity has the required permissions and is not locked or disabled.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7038 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested operation can be performed only on the system console. This is most often the result of a driver or system DLL requiring direct console access.\n\nLookup forms: 7038, 0x1B7E, error 7038, ERROR_CTX_NOT_CONSOLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7038"]},{"id":1659,"title":"ERROR_CTX_CLIENT_QUERY_TIMEOUT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7040","0x1B80","error 7040","ERROR_CTX_CLIENT_QUERY_TIMEOUT","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","ctx","client","query","timeout","the","failed","respond","server","connect","message"],"errorCode":"7040","eventId":"","severity":"High","summary":"The client failed to respond to the server connect message.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 7040; use the surrounding log entries to confirm it.","resolution":"1. Record where 7040 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_CLIENT_QUERY_TIMEOUT.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7040 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The client failed to respond to the server connect message.\n\nLookup forms: 7040, 0x1B80, error 7040, ERROR_CTX_CLIENT_QUERY_TIMEOUT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7040"]},{"id":1660,"title":"ERROR_CTX_CONSOLE_DISCONNECT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7041","0x1B81","error 7041","ERROR_CTX_CONSOLE_DISCONNECT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ctx","console","disconnect","disconnecting","the","session","not","supported"],"errorCode":"7041","eventId":"","severity":"Medium","summary":"Disconnecting the console session is not supported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 7041; use the surrounding log entries to confirm it.","resolution":"1. Record where 7041 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_CONSOLE_DISCONNECT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7041 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Disconnecting the console session is not supported.\n\nLookup forms: 7041, 0x1B81, error 7041, ERROR_CTX_CONSOLE_DISCONNECT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7041"]},{"id":1661,"title":"ERROR_CTX_CONSOLE_CONNECT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7042","0x1B82","error 7042","ERROR_CTX_CONSOLE_CONNECT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ctx","console","connect","reconnecting","disconnected","session","the","not","supported"],"errorCode":"7042","eventId":"","severity":"Medium","summary":"Reconnecting a disconnected session to the console is not supported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 7042; use the surrounding log entries to confirm it.","resolution":"1. Record where 7042 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_CONSOLE_CONNECT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7042 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Reconnecting a disconnected session to the console is not supported.\n\nLookup forms: 7042, 0x1B82, error 7042, ERROR_CTX_CONSOLE_CONNECT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7042"]},{"id":1662,"title":"ERROR_CTX_SHADOW_DENIED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7044","0x1B84","error 7044","ERROR_CTX_SHADOW_DENIED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ctx","shadow","denied","the","request","control","another","session","remotely","was"],"errorCode":"7044","eventId":"","severity":"Low","summary":"The request to control another session remotely was denied.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 7044; use the surrounding log entries to confirm it.","resolution":"1. Record where 7044 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_SHADOW_DENIED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7044 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The request to control another session remotely was denied.\n\nLookup forms: 7044, 0x1B84, error 7044, ERROR_CTX_SHADOW_DENIED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7044"]},{"id":1663,"title":"ERROR_CTX_WINSTATION_ACCESS_DENIED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7045","0x1B85","error 7045","ERROR_CTX_WINSTATION_ACCESS_DENIED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ctx","winstation","access","denied","the","requested","session"],"errorCode":"7045","eventId":"","severity":"Low","summary":"The requested session access is denied.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 7045; use the surrounding log entries to confirm it.","resolution":"1. Record where 7045 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_WINSTATION_ACCESS_DENIED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7045 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested session access is denied.\n\nLookup forms: 7045, 0x1B85, error 7045, ERROR_CTX_WINSTATION_ACCESS_DENIED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7045"]},{"id":1664,"title":"ERROR_CTX_INVALID_WD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7049","0x1B89","error 7049","ERROR_CTX_INVALID_WD","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","ctx","invalid","the","specified","terminal","connection","driver"],"errorCode":"7049","eventId":"","severity":"High","summary":"The specified terminal connection driver is invalid.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 7049; use the surrounding log entries to confirm it.","resolution":"1. Record where 7049 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_INVALID_WD.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7049 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified terminal connection driver is invalid.\n\nLookup forms: 7049, 0x1B89, error 7049, ERROR_CTX_INVALID_WD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7049"]},{"id":1665,"title":"ERROR_CTX_SHADOW_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7050","0x1B8A","error 7050","ERROR_CTX_SHADOW_INVALID","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ctx","shadow","invalid","the","requested","session","cannot","controlled","remotely","this","may","because","disconnected","does","not","currently","have","user","logged"],"errorCode":"7050","eventId":"","severity":"Medium","summary":"The requested session cannot be controlled remotely. This may be because the session is disconnected or does not currently have a user logged on.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 7050; use the surrounding log entries to confirm it.","resolution":"1. Record where 7050 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_SHADOW_INVALID.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7050 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested session cannot be controlled remotely. This may be because the session is disconnected or does not currently have a user logged on.\n\nLookup forms: 7050, 0x1B8A, error 7050, ERROR_CTX_SHADOW_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7050"]},{"id":1666,"title":"ERROR_CTX_SHADOW_DISABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7051","0x1B8B","error 7051","ERROR_CTX_SHADOW_DISABLED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ctx","shadow","disabled","the","requested","session","not","configured","allow","remote","control"],"errorCode":"7051","eventId":"","severity":"Low","summary":"The requested session is not configured to allow remote control.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 7051; use the surrounding log entries to confirm it.","resolution":"1. Record where 7051 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_SHADOW_DISABLED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7051 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested session is not configured to allow remote control.\n\nLookup forms: 7051, 0x1B8B, error 7051, ERROR_CTX_SHADOW_DISABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7051"]},{"id":1667,"title":"ERROR_CTX_CLIENT_LICENSE_IN_USE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7052","0x1B8C","error 7052","ERROR_CTX_CLIENT_LICENSE_IN_USE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","ctx","client","license","use","your","request","connect","this","terminal","server","has","been","rejected","number","currently","being","used","another","user","please","call","system","administrator","obtain"],"errorCode":"7052","eventId":"","severity":"Low","summary":"Your request to connect to this Terminal Server has been rejected. Your Terminal Server client license number is currently being used by another user. Please call your system administrator to obtain a unique license number.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 7052; use the surrounding log entries to confirm it.","resolution":"1. Record where 7052 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_CLIENT_LICENSE_IN_USE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7052 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Your request to connect to this Terminal Server has been rejected. Your Terminal Server client license number is currently being used by another user. Please call your system administrator to obtain a unique license number.\n\nLookup forms: 7052, 0x1B8C, error 7052, ERROR_CTX_CLIENT_LICENSE_IN_USE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7052"]},{"id":1668,"title":"ERROR_CTX_CLIENT_LICENSE_NOT_SET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7053","0x1B8D","error 7053","ERROR_CTX_CLIENT_LICENSE_NOT_SET","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","ctx","client","license","not","set","your","request","connect","this","terminal","server","has","been","rejected","number","entered","for","copy","the","please","contact","system","administrator"],"errorCode":"7053","eventId":"","severity":"Low","summary":"Your request to connect to this Terminal Server has been rejected. Your Terminal Server client license number has not been entered for this copy of the Terminal Server client. Please contact your system administrator.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 7053; use the surrounding log entries to confirm it.","resolution":"1. Record where 7053 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_CLIENT_LICENSE_NOT_SET.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7053 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Your request to connect to this Terminal Server has been rejected. Your Terminal Server client license number has not been entered for this copy of the Terminal Server client. Please contact your system administrator.\n\nLookup forms: 7053, 0x1B8D, error 7053, ERROR_CTX_CLIENT_LICENSE_NOT_SET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7053"]},{"id":1669,"title":"ERROR_CTX_LICENSE_NOT_AVAILABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7054","0x1B8E","error 7054","ERROR_CTX_LICENSE_NOT_AVAILABLE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","ctx","license","not","available","the","number","connections","this","computer","limited","and","all","are","use","right","now","try","connecting","later","contact","your","system","administrator"],"errorCode":"7054","eventId":"","severity":"High","summary":"The number of connections to this computer is limited and all connections are in use right now. Try connecting later or contact your system administrator.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 7054; use the surrounding log entries to confirm it.","resolution":"1. Record where 7054 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_LICENSE_NOT_AVAILABLE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7054 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The number of connections to this computer is limited and all connections are in use right now. Try connecting later or contact your system administrator.\n\nLookup forms: 7054, 0x1B8E, error 7054, ERROR_CTX_LICENSE_NOT_AVAILABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The system has reached its licensed logon limit. Please try again later.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7054"]},{"id":1670,"title":"ERROR_CTX_LICENSE_CLIENT_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7055","0x1B8F","error 7055","ERROR_CTX_LICENSE_CLIENT_INVALID","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ctx","license","client","invalid","the","you","are","using","not","licensed","use","this","system","your","logon","request","denied"],"errorCode":"7055","eventId":"","severity":"High","summary":"The client you are using is not licensed to use this system. Your logon request is denied.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 7055; use the surrounding log entries to confirm it.","resolution":"1. Record where 7055 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_LICENSE_CLIENT_INVALID.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7055 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The client you are using is not licensed to use this system. Your logon request is denied.\n\nLookup forms: 7055, 0x1B8F, error 7055, ERROR_CTX_LICENSE_CLIENT_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7055"]},{"id":1671,"title":"ERROR_CTX_LICENSE_EXPIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7056","0x1B90","error 7056","ERROR_CTX_LICENSE_EXPIRED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ctx","license","expired","the","system","has","your","logon","request","denied"],"errorCode":"7056","eventId":"","severity":"High","summary":"The system license has expired. Your logon request is denied.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 7056; use the surrounding log entries to confirm it.","resolution":"1. Record where 7056 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_LICENSE_EXPIRED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7056 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system license has expired. Your logon request is denied.\n\nLookup forms: 7056, 0x1B90, error 7056, ERROR_CTX_LICENSE_EXPIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7056"]},{"id":1672,"title":"ERROR_CTX_SHADOW_NOT_RUNNING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7057","0x1B91","error 7057","ERROR_CTX_SHADOW_NOT_RUNNING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ctx","shadow","not","running","remote","control","could","terminated","because","the","specified","session","currently","being","remotely","controlled"],"errorCode":"7057","eventId":"","severity":"Low","summary":"Remote control could not be terminated because the specified session is not currently being remotely controlled.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 7057; use the surrounding log entries to confirm it.","resolution":"1. Record where 7057 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_SHADOW_NOT_RUNNING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7057 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Remote control could not be terminated because the specified session is not currently being remotely controlled.\n\nLookup forms: 7057, 0x1B91, error 7057, ERROR_CTX_SHADOW_NOT_RUNNING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7057"]},{"id":1673,"title":"ERROR_CTX_SHADOW_ENDED_BY_MODE_CHANGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7058","0x1B92","error 7058","ERROR_CTX_SHADOW_ENDED_BY_MODE_CHANGE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ctx","shadow","ended","mode","change","the","remote","control","console","was","terminated","because","display","changed","changing","session","not","supported"],"errorCode":"7058","eventId":"","severity":"Medium","summary":"The remote control of the console was terminated because the display mode was changed. Changing the display mode in a remote control session is not supported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 7058; use the surrounding log entries to confirm it.","resolution":"1. Record where 7058 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_SHADOW_ENDED_BY_MODE_CHANGE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7058 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The remote control of the console was terminated because the display mode was changed. Changing the display mode in a remote control session is not supported.\n\nLookup forms: 7058, 0x1B92, error 7058, ERROR_CTX_SHADOW_ENDED_BY_MODE_CHANGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7058"]},{"id":1674,"title":"ERROR_ACTIVATION_COUNT_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7059","0x1B93","error 7059","ERROR_ACTIVATION_COUNT_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","activation","count","exceeded","has","already","been","reset","the","maximum","number","times","for","this","installation","your","timer","will","not","cleared"],"errorCode":"7059","eventId":"","severity":"Low","summary":"Activation has already been reset the maximum number of times for this installation. Your activation timer will not be cleared.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 7059; use the surrounding log entries to confirm it.","resolution":"1. Record where 7059 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ACTIVATION_COUNT_EXCEEDED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7059 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Activation has already been reset the maximum number of times for this installation. Your activation timer will not be cleared.\n\nLookup forms: 7059, 0x1B93, error 7059, ERROR_ACTIVATION_COUNT_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7059"]},{"id":1675,"title":"ERROR_CTX_WINSTATIONS_DISABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7060","0x1B94","error 7060","ERROR_CTX_WINSTATIONS_DISABLED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ctx","winstations","disabled","remote","logins","are","currently"],"errorCode":"7060","eventId":"","severity":"Low","summary":"Remote logins are currently disabled.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 7060; use the surrounding log entries to confirm it.","resolution":"1. Record where 7060 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_WINSTATIONS_DISABLED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7060 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Remote logins are currently disabled.\n\nLookup forms: 7060, 0x1B94, error 7060, ERROR_CTX_WINSTATIONS_DISABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7060"]},{"id":1676,"title":"ERROR_CTX_ENCRYPTION_LEVEL_REQUIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7061","0x1B95","error 7061","ERROR_CTX_ENCRYPTION_LEVEL_REQUIRED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ctx","encryption","level","required","you","not","have","the","proper","access","this","session"],"errorCode":"7061","eventId":"","severity":"Low","summary":"You do not have the proper encryption level to access this Session.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 7061; use the surrounding log entries to confirm it.","resolution":"1. Record where 7061 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_ENCRYPTION_LEVEL_REQUIRED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7061 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: You do not have the proper encryption level to access this Session.\n\nLookup forms: 7061, 0x1B95, error 7061, ERROR_CTX_ENCRYPTION_LEVEL_REQUIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7061"]},{"id":1677,"title":"ERROR_CTX_SESSION_IN_USE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7062","0x1B96","error 7062","ERROR_CTX_SESSION_IN_USE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ctx","session","use","the","user","currently","logged","this","computer","only","current","administrator","can","log"],"errorCode":"7062","eventId":"","severity":"Low","summary":"The user %s\\\\%s is currently logged on to this computer. Only the current user or an administrator can log on to this computer.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 7062; use the surrounding log entries to confirm it.","resolution":"1. Record where 7062 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_SESSION_IN_USE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7062 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The user %s\\\\%s is currently logged on to this computer. Only the current user or an administrator can log on to this computer.\n\nLookup forms: 7062, 0x1B96, error 7062, ERROR_CTX_SESSION_IN_USE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7062"]},{"id":1678,"title":"ERROR_CTX_NO_FORCE_LOGOFF","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7063","0x1B97","error 7063","ERROR_CTX_NO_FORCE_LOGOFF","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ctx","force","logoff","the","user","already","logged","console","this","computer","you","not","have","permission","log","time","resolve","issue","contact","and","them","off"],"errorCode":"7063","eventId":"","severity":"Low","summary":"The user %s\\\\%s is already logged on to the console of this computer. You do not have permission to log in at this time. To resolve this issue, contact %s\\\\%s and have them log off.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 7063; use the surrounding log entries to confirm it.","resolution":"1. Record where 7063 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_NO_FORCE_LOGOFF.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7063 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The user %s\\\\%s is already logged on to the console of this computer. You do not have permission to log in at this time. To resolve this issue, contact %s\\\\%s and have them log off.\n\nLookup forms: 7063, 0x1B97, error 7063, ERROR_CTX_NO_FORCE_LOGOFF. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7063"]},{"id":1679,"title":"ERROR_CTX_ACCOUNT_RESTRICTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7064","0x1B98","error 7064","ERROR_CTX_ACCOUNT_RESTRICTION","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ctx","account","restriction","unable","log","you","because"],"errorCode":"7064","eventId":"","severity":"Medium","summary":"Unable to log you on because of an account restriction.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 7064; use the surrounding log entries to confirm it.","resolution":"1. Record where 7064 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_ACCOUNT_RESTRICTION.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7064 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to log you on because of an account restriction.\n\nLookup forms: 7064, 0x1B98, error 7064, ERROR_CTX_ACCOUNT_RESTRICTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7064"]},{"id":1680,"title":"ERROR_RDP_PROTOCOL_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7065","0x1B99","error 7065","ERROR_RDP_PROTOCOL_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","rdp","protocol","the","component","detected","stream","and","has","disconnected","client"],"errorCode":"7065","eventId":"","severity":"Low","summary":"The RDP protocol component %2 detected an error in the protocol stream and has disconnected the client.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 7065; use the surrounding log entries to confirm it.","resolution":"1. Record where 7065 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RDP_PROTOCOL_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7065 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The RDP protocol component %2 detected an error in the protocol stream and has disconnected the client.\n\nLookup forms: 7065, 0x1B99, error 7065, ERROR_RDP_PROTOCOL_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7065"]},{"id":1681,"title":"ERROR_CTX_CDM_CONNECT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7066","0x1B9A","error 7066","ERROR_CTX_CDM_CONNECT","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","ctx","cdm","connect","the","client","drive","mapping","service","has","connected","terminal","connection"],"errorCode":"7066","eventId":"","severity":"High","summary":"The Client Drive Mapping Service Has Connected on Terminal Connection.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 7066; use the surrounding log entries to confirm it.","resolution":"1. Record where 7066 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Verify the required service or agent is installed, running, and current; repair the component if needed.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_CDM_CONNECT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7066 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Client Drive Mapping Service Has Connected on Terminal Connection.\n\nLookup forms: 7066, 0x1B9A, error 7066, ERROR_CTX_CDM_CONNECT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7066"]},{"id":1682,"title":"ERROR_CTX_CDM_DISCONNECT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7067","0x1B9B","error 7067","ERROR_CTX_CDM_DISCONNECT","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","ctx","cdm","disconnect","the","client","drive","mapping","service","has","disconnected","terminal","connection"],"errorCode":"7067","eventId":"","severity":"High","summary":"The Client Drive Mapping Service Has Disconnected on Terminal Connection.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 7067; use the surrounding log entries to confirm it.","resolution":"1. Record where 7067 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Verify the required service or agent is installed, running, and current; repair the component if needed.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_CDM_DISCONNECT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7067 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Client Drive Mapping Service Has Disconnected on Terminal Connection.\n\nLookup forms: 7067, 0x1B9B, error 7067, ERROR_CTX_CDM_DISCONNECT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7067"]},{"id":1683,"title":"ERROR_CTX_SECURITY_LAYER_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7068","0x1B9C","error 7068","ERROR_CTX_SECURITY_LAYER_ERROR","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ctx","security","layer","the","terminal","server","detected","protocol","stream","and","has","disconnected","client"],"errorCode":"7068","eventId":"","severity":"Low","summary":"The Terminal Server security layer detected an error in the protocol stream and has disconnected the client.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 7068; use the surrounding log entries to confirm it.","resolution":"1. Record where 7068 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CTX_SECURITY_LAYER_ERROR.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7068 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Terminal Server security layer detected an error in the protocol stream and has disconnected the client.\n\nLookup forms: 7068, 0x1B9C, error 7068, ERROR_CTX_SECURITY_LAYER_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7068"]},{"id":1684,"title":"ERROR_TS_INCOMPATIBLE_SESSIONS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7069","0x1B9D","error 7069","ERROR_TS_INCOMPATIBLE_SESSIONS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","incompatible","sessions","the","target","session","with","current"],"errorCode":"7069","eventId":"","severity":"Low","summary":"The target session is incompatible with the current session.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 7069; use the surrounding log entries to confirm it.","resolution":"1. Record where 7069 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TS_INCOMPATIBLE_SESSIONS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7069 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The target session is incompatible with the current session.\n\nLookup forms: 7069, 0x1B9D, error 7069, ERROR_TS_INCOMPATIBLE_SESSIONS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7069"]},{"id":1685,"title":"ERROR_TS_VIDEO_SUBSYSTEM_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["7070","0x1B9E","error 7070","ERROR_TS_VIDEO_SUBSYSTEM_ERROR","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","video","subsystem","windows","can","connect","your","session","because","problem","occurred","the","try","connecting","again","later","contact","server","administrator","for","assistance"],"errorCode":"7070","eventId":"","severity":"Low","summary":"Windows can't connect to your session because a problem occurred in the Windows video subsystem. Try connecting again later, or contact the server administrator for assistance.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 7070; use the surrounding log entries to confirm it.","resolution":"1. Record where 7070 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_TS_VIDEO_SUBSYSTEM_ERROR.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 7070 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Windows can't connect to your session because a problem occurred in the Windows video subsystem. Try connecting again later, or contact the server administrator for assistance.\n\nLookup forms: 7070, 0x1B9E, error 7070, ERROR_TS_VIDEO_SUBSYSTEM_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["7070"]},{"id":1686,"title":"FRS_ERR_INVALID_API_SEQUENCE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8001","0x1F41","error 8001","FRS_ERR_INVALID_API_SEQUENCE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","frs","err","invalid","api","sequence","the","file","replication","service","was","called","incorrectly"],"errorCode":"8001","eventId":"","severity":"Low","summary":"The file replication service API was called incorrectly.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8001; use the surrounding log entries to confirm it.","resolution":"1. Record where 8001 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to FRS_ERR_INVALID_API_SEQUENCE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8001 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file replication service API was called incorrectly.\n\nLookup forms: 8001, 0x1F41, error 8001, FRS_ERR_INVALID_API_SEQUENCE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8001"]},{"id":1687,"title":"FRS_ERR_STARTING_SERVICE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8002","0x1F42","error 8002","FRS_ERR_STARTING_SERVICE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","frs","err","starting","service","the","file","replication","cannot","started"],"errorCode":"8002","eventId":"","severity":"Medium","summary":"The file replication service cannot be started.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8002; use the surrounding log entries to confirm it.","resolution":"1. Record where 8002 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to FRS_ERR_STARTING_SERVICE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8002 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file replication service cannot be started.\n\nLookup forms: 8002, 0x1F42, error 8002, FRS_ERR_STARTING_SERVICE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8002"]},{"id":1688,"title":"FRS_ERR_STOPPING_SERVICE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8003","0x1F43","error 8003","FRS_ERR_STOPPING_SERVICE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","frs","err","stopping","service","the","file","replication","cannot","stopped"],"errorCode":"8003","eventId":"","severity":"Medium","summary":"The file replication service cannot be stopped.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8003; use the surrounding log entries to confirm it.","resolution":"1. Record where 8003 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to FRS_ERR_STOPPING_SERVICE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8003 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file replication service cannot be stopped.\n\nLookup forms: 8003, 0x1F43, error 8003, FRS_ERR_STOPPING_SERVICE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8003"]},{"id":1689,"title":"FRS_ERR_INTERNAL_API","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8004","0x1F44","error 8004","FRS_ERR_INTERNAL_API","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","frs","err","internal","api","the","file","replication","service","terminated","request","event","log","may","have","more","information"],"errorCode":"8004","eventId":"","severity":"Low","summary":"The file replication service API terminated the request. The event log may have more information.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8004; use the surrounding log entries to confirm it.","resolution":"1. Record where 8004 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to FRS_ERR_INTERNAL_API.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8004 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file replication service API terminated the request. The event log may have more information.\n\nLookup forms: 8004, 0x1F44, error 8004, FRS_ERR_INTERNAL_API. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8004"]},{"id":1690,"title":"FRS_ERR_INTERNAL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8005","0x1F45","error 8005","FRS_ERR_INTERNAL","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","frs","err","internal","the","file","replication","service","terminated","request","event","log","may","have","more","information"],"errorCode":"8005","eventId":"","severity":"Low","summary":"The file replication service terminated the request. The event log may have more information.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8005; use the surrounding log entries to confirm it.","resolution":"1. Record where 8005 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to FRS_ERR_INTERNAL.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8005 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file replication service terminated the request. The event log may have more information.\n\nLookup forms: 8005, 0x1F45, error 8005, FRS_ERR_INTERNAL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8005"]},{"id":1691,"title":"FRS_ERR_SERVICE_COMM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8006","0x1F46","error 8006","FRS_ERR_SERVICE_COMM","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","frs","err","service","comm","the","file","replication","cannot","contacted","event","log","may","have","more","information"],"errorCode":"8006","eventId":"","severity":"Medium","summary":"The file replication service cannot be contacted. The event log may have more information.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8006; use the surrounding log entries to confirm it.","resolution":"1. Record where 8006 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to FRS_ERR_SERVICE_COMM.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8006 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file replication service cannot be contacted. The event log may have more information.\n\nLookup forms: 8006, 0x1F46, error 8006, FRS_ERR_SERVICE_COMM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8006"]},{"id":1692,"title":"FRS_ERR_INSUFFICIENT_PRIV","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8007","0x1F47","error 8007","FRS_ERR_INSUFFICIENT_PRIV","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","frs","err","insufficient","priv","the","file","replication","service","cannot","satisfy","request","because","user","has","privileges","event","log","may","have","more","information"],"errorCode":"8007","eventId":"","severity":"Medium","summary":"The file replication service cannot satisfy the request because the user has insufficient privileges. The event log may have more information.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8007; use the surrounding log entries to confirm it.","resolution":"1. Record where 8007 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Confirm the user or service identity has the required permissions and is not locked or disabled.\n4. Verify the required service or agent is installed, running, and current; repair the component if needed.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to FRS_ERR_INSUFFICIENT_PRIV.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Confirm the user or service identity has the required permissions and is not locked or disabled.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8007 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file replication service cannot satisfy the request because the user has insufficient privileges. The event log may have more information.\n\nLookup forms: 8007, 0x1F47, error 8007, FRS_ERR_INSUFFICIENT_PRIV. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8007"]},{"id":1693,"title":"FRS_ERR_AUTHENTICATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8008","0x1F48","error 8008","FRS_ERR_AUTHENTICATION","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","frs","err","authentication","the","file","replication","service","cannot","satisfy","request","because","authenticated","rpc","not","available","event","log","may","have","more","information"],"errorCode":"8008","eventId":"","severity":"Medium","summary":"The file replication service cannot satisfy the request because authenticated RPC is not available. The event log may have more information.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8008; use the surrounding log entries to confirm it.","resolution":"1. Record where 8008 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to FRS_ERR_AUTHENTICATION.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8008 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file replication service cannot satisfy the request because authenticated RPC is not available. The event log may have more information.\n\nLookup forms: 8008, 0x1F48, error 8008, FRS_ERR_AUTHENTICATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8008"]},{"id":1694,"title":"FRS_ERR_PARENT_INSUFFICIENT_PRIV","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8009","0x1F49","error 8009","FRS_ERR_PARENT_INSUFFICIENT_PRIV","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","frs","err","parent","insufficient","priv","the","file","replication","service","cannot","satisfy","request","because","user","has","privileges","domain","controller","event","log","may","have","more","information"],"errorCode":"8009","eventId":"","severity":"Medium","summary":"The file replication service cannot satisfy the request because the user has insufficient privileges on the domain controller. The event log may have more information.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8009; use the surrounding log entries to confirm it.","resolution":"1. Record where 8009 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Confirm the user or service identity has the required permissions and is not locked or disabled.\n4. Verify the required service or agent is installed, running, and current; repair the component if needed.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to FRS_ERR_PARENT_INSUFFICIENT_PRIV.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Confirm the user or service identity has the required permissions and is not locked or disabled.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8009 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file replication service cannot satisfy the request because the user has insufficient privileges on the domain controller. The event log may have more information.\n\nLookup forms: 8009, 0x1F49, error 8009, FRS_ERR_PARENT_INSUFFICIENT_PRIV. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8009"]},{"id":1695,"title":"FRS_ERR_PARENT_AUTHENTICATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8010","0x1F4A","error 8010","FRS_ERR_PARENT_AUTHENTICATION","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","frs","err","parent","authentication","the","file","replication","service","cannot","satisfy","request","because","authenticated","rpc","not","available","domain","controller","event","log","may","have","more","information"],"errorCode":"8010","eventId":"","severity":"Medium","summary":"The file replication service cannot satisfy the request because authenticated RPC is not available on the domain controller. The event log may have more information.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8010; use the surrounding log entries to confirm it.","resolution":"1. Record where 8010 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to FRS_ERR_PARENT_AUTHENTICATION.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8010 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file replication service cannot satisfy the request because authenticated RPC is not available on the domain controller. The event log may have more information.\n\nLookup forms: 8010, 0x1F4A, error 8010, FRS_ERR_PARENT_AUTHENTICATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8010"]},{"id":1696,"title":"FRS_ERR_CHILD_TO_PARENT_COMM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8011","0x1F4B","error 8011","FRS_ERR_CHILD_TO_PARENT_COMM","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","frs","err","child","parent","comm","the","file","replication","service","cannot","communicate","with","domain","controller","event","log","may","have","more","information"],"errorCode":"8011","eventId":"","severity":"Medium","summary":"The file replication service cannot communicate with the file replication service on the domain controller. The event log may have more information.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8011; use the surrounding log entries to confirm it.","resolution":"1. Record where 8011 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to FRS_ERR_CHILD_TO_PARENT_COMM.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8011 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file replication service cannot communicate with the file replication service on the domain controller. The event log may have more information.\n\nLookup forms: 8011, 0x1F4B, error 8011, FRS_ERR_CHILD_TO_PARENT_COMM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8011"]},{"id":1697,"title":"FRS_ERR_PARENT_TO_CHILD_COMM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8012","0x1F4C","error 8012","FRS_ERR_PARENT_TO_CHILD_COMM","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","frs","err","parent","child","comm","the","file","replication","service","domain","controller","cannot","communicate","with","this","computer","event","log","may","have","more","information"],"errorCode":"8012","eventId":"","severity":"Medium","summary":"The file replication service on the domain controller cannot communicate with the file replication service on this computer. The event log may have more information.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8012; use the surrounding log entries to confirm it.","resolution":"1. Record where 8012 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to FRS_ERR_PARENT_TO_CHILD_COMM.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8012 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file replication service on the domain controller cannot communicate with the file replication service on this computer. The event log may have more information.\n\nLookup forms: 8012, 0x1F4C, error 8012, FRS_ERR_PARENT_TO_CHILD_COMM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8012"]},{"id":1698,"title":"FRS_ERR_SYSVOL_POPULATE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8013","0x1F4D","error 8013","FRS_ERR_SYSVOL_POPULATE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","frs","err","sysvol","populate","the","file","replication","service","cannot","system","volume","because","internal","error","event","log","may","have","more","information"],"errorCode":"8013","eventId":"","severity":"Medium","summary":"The file replication service cannot populate the system volume because of an internal error. The event log may have more information.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8013; use the surrounding log entries to confirm it.","resolution":"1. Record where 8013 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to FRS_ERR_SYSVOL_POPULATE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8013 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file replication service cannot populate the system volume because of an internal error. The event log may have more information.\n\nLookup forms: 8013, 0x1F4D, error 8013, FRS_ERR_SYSVOL_POPULATE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8013"]},{"id":1699,"title":"FRS_ERR_SYSVOL_POPULATE_TIMEOUT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8014","0x1F4E","error 8014","FRS_ERR_SYSVOL_POPULATE_TIMEOUT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","frs","err","sysvol","populate","timeout","the","file","replication","service","cannot","system","volume","because","internal","event","log","may","have","more","information"],"errorCode":"8014","eventId":"","severity":"Medium","summary":"The file replication service cannot populate the system volume because of an internal timeout. The event log may have more information.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8014; use the surrounding log entries to confirm it.","resolution":"1. Record where 8014 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to FRS_ERR_SYSVOL_POPULATE_TIMEOUT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8014 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file replication service cannot populate the system volume because of an internal timeout. The event log may have more information.\n\nLookup forms: 8014, 0x1F4E, error 8014, FRS_ERR_SYSVOL_POPULATE_TIMEOUT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8014"]},{"id":1700,"title":"FRS_ERR_SYSVOL_IS_BUSY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8015","0x1F4F","error 8015","FRS_ERR_SYSVOL_IS_BUSY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","frs","err","sysvol","busy","the","file","replication","service","cannot","process","request","system","volume","with","previous"],"errorCode":"8015","eventId":"","severity":"Medium","summary":"The file replication service cannot process the request. The system volume is busy with a previous request.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8015; use the surrounding log entries to confirm it.","resolution":"1. Record where 8015 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to FRS_ERR_SYSVOL_IS_BUSY.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8015 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file replication service cannot process the request. The system volume is busy with a previous request.\n\nLookup forms: 8015, 0x1F4F, error 8015, FRS_ERR_SYSVOL_IS_BUSY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8015"]},{"id":1701,"title":"FRS_ERR_SYSVOL_DEMOTE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8016","0x1F50","error 8016","FRS_ERR_SYSVOL_DEMOTE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","frs","err","sysvol","demote","the","file","replication","service","cannot","stop","replicating","system","volume","because","internal","error","event","log","may","have","more","information"],"errorCode":"8016","eventId":"","severity":"Medium","summary":"The file replication service cannot stop replicating the system volume because of an internal error. The event log may have more information.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8016; use the surrounding log entries to confirm it.","resolution":"1. Record where 8016 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to FRS_ERR_SYSVOL_DEMOTE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8016 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file replication service cannot stop replicating the system volume because of an internal error. The event log may have more information.\n\nLookup forms: 8016, 0x1F50, error 8016, FRS_ERR_SYSVOL_DEMOTE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8016"]},{"id":1702,"title":"FRS_ERR_INVALID_SERVICE_PARAMETER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8017","0x1F51","error 8017","FRS_ERR_INVALID_SERVICE_PARAMETER","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","frs","err","invalid","service","parameter","the","file","replication","detected"],"errorCode":"8017","eventId":"","severity":"Medium","summary":"The file replication service detected an invalid parameter.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8017; use the surrounding log entries to confirm it.","resolution":"1. Record where 8017 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to FRS_ERR_INVALID_SERVICE_PARAMETER.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8017 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file replication service detected an invalid parameter.\n\nLookup forms: 8017, 0x1F51, error 8017, FRS_ERR_INVALID_SERVICE_PARAMETER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8017"]},{"id":1703,"title":"ERROR_DS_NOT_INSTALLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8200","0x2008","error 8200","ERROR_DS_NOT_INSTALLED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","not","installed","occurred","while","installing","the","directory","service","for","more","information","see","event","log"],"errorCode":"8200","eventId":"","severity":"Low","summary":"An error occurred while installing the directory service. For more information, see the event log.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8200; use the surrounding log entries to confirm it.","resolution":"1. Record where 8200 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NOT_INSTALLED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8200 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An error occurred while installing the directory service. For more information, see the event log.\n\nLookup forms: 8200, 0x2008, error 8200, ERROR_DS_NOT_INSTALLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8200"]},{"id":1704,"title":"ERROR_DS_MEMBERSHIP_EVALUATED_LOCALLY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8201","0x2009","error 8201","ERROR_DS_MEMBERSHIP_EVALUATED_LOCALLY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","membership","evaluated","locally","the","directory","service","group","memberships"],"errorCode":"8201","eventId":"","severity":"Low","summary":"The directory service evaluated group memberships locally.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8201; use the surrounding log entries to confirm it.","resolution":"1. Record where 8201 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_MEMBERSHIP_EVALUATED_LOCALLY.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8201 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service evaluated group memberships locally.\n\nLookup forms: 8201, 0x2009, error 8201, ERROR_DS_MEMBERSHIP_EVALUATED_LOCALLY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8201"]},{"id":1705,"title":"ERROR_DS_NO_ATTRIBUTE_OR_VALUE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8202","0x200A","error 8202","ERROR_DS_NO_ATTRIBUTE_OR_VALUE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","attribute","value","the","specified","directory","service","does","not","exist"],"errorCode":"8202","eventId":"","severity":"Low","summary":"The specified directory service attribute or value does not exist.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8202; use the surrounding log entries to confirm it.","resolution":"1. Record where 8202 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NO_ATTRIBUTE_OR_VALUE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8202 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified directory service attribute or value does not exist.\n\nLookup forms: 8202, 0x200A, error 8202, ERROR_DS_NO_ATTRIBUTE_OR_VALUE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8202"]},{"id":1706,"title":"ERROR_DS_INVALID_ATTRIBUTE_SYNTAX","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8203","0x200B","error 8203","ERROR_DS_INVALID_ATTRIBUTE_SYNTAX","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","invalid","attribute","syntax","the","specified","directory","service"],"errorCode":"8203","eventId":"","severity":"Medium","summary":"The attribute syntax specified to the directory service is invalid.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8203; use the surrounding log entries to confirm it.","resolution":"1. Record where 8203 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_INVALID_ATTRIBUTE_SYNTAX.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8203 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The attribute syntax specified to the directory service is invalid.\n\nLookup forms: 8203, 0x200B, error 8203, ERROR_DS_INVALID_ATTRIBUTE_SYNTAX. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8203"]},{"id":1707,"title":"ERROR_DS_ATTRIBUTE_TYPE_UNDEFINED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8204","0x200C","error 8204","ERROR_DS_ATTRIBUTE_TYPE_UNDEFINED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","attribute","type","undefined","the","specified","directory","service","not","defined"],"errorCode":"8204","eventId":"","severity":"Low","summary":"The attribute type specified to the directory service is not defined.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8204; use the surrounding log entries to confirm it.","resolution":"1. Record where 8204 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_ATTRIBUTE_TYPE_UNDEFINED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8204 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The attribute type specified to the directory service is not defined.\n\nLookup forms: 8204, 0x200C, error 8204, ERROR_DS_ATTRIBUTE_TYPE_UNDEFINED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8204"]},{"id":1708,"title":"ERROR_DS_ATTRIBUTE_OR_VALUE_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8205","0x200D","error 8205","ERROR_DS_ATTRIBUTE_OR_VALUE_EXISTS","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","attribute","value","exists","the","specified","directory","service","already"],"errorCode":"8205","eventId":"","severity":"Medium","summary":"The specified directory service attribute or value already exists.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8205; use the surrounding log entries to confirm it.","resolution":"1. Record where 8205 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_ATTRIBUTE_OR_VALUE_EXISTS.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8205 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified directory service attribute or value already exists.\n\nLookup forms: 8205, 0x200D, error 8205, ERROR_DS_ATTRIBUTE_OR_VALUE_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8205"]},{"id":1709,"title":"ERROR_DS_BUSY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8206","0x200E","error 8206","ERROR_DS_BUSY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","busy","the","directory","service"],"errorCode":"8206","eventId":"","severity":"Medium","summary":"The directory service is busy.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8206; use the surrounding log entries to confirm it.","resolution":"1. Record where 8206 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_BUSY.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8206 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service is busy.\n\nLookup forms: 8206, 0x200E, error 8206, ERROR_DS_BUSY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8206"]},{"id":1710,"title":"ERROR_DS_UNAVAILABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8207","0x200F","error 8207","ERROR_DS_UNAVAILABLE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","unavailable","the","directory","service"],"errorCode":"8207","eventId":"","severity":"Low","summary":"The directory service is unavailable.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8207; use the surrounding log entries to confirm it.","resolution":"1. Record where 8207 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_UNAVAILABLE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8207 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service is unavailable.\n\nLookup forms: 8207, 0x200F, error 8207, ERROR_DS_UNAVAILABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8207"]},{"id":1711,"title":"ERROR_DS_NO_RIDS_ALLOCATED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8208","0x2010","error 8208","ERROR_DS_NO_RIDS_ALLOCATED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","rids","allocated","the","directory","service","was","unable","allocate","relative","identifier"],"errorCode":"8208","eventId":"","severity":"Medium","summary":"The directory service was unable to allocate a relative identifier.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8208; use the surrounding log entries to confirm it.","resolution":"1. Record where 8208 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NO_RIDS_ALLOCATED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8208 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service was unable to allocate a relative identifier.\n\nLookup forms: 8208, 0x2010, error 8208, ERROR_DS_NO_RIDS_ALLOCATED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8208"]},{"id":1712,"title":"ERROR_DS_NO_MORE_RIDS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8209","0x2011","error 8209","ERROR_DS_NO_MORE_RIDS","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","more","rids","the","directory","service","has","exhausted","pool","relative","identifiers"],"errorCode":"8209","eventId":"","severity":"Low","summary":"The directory service has exhausted the pool of relative identifiers.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8209; use the surrounding log entries to confirm it.","resolution":"1. Record where 8209 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NO_MORE_RIDS.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8209 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service has exhausted the pool of relative identifiers.\n\nLookup forms: 8209, 0x2011, error 8209, ERROR_DS_NO_MORE_RIDS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8209"]},{"id":1713,"title":"ERROR_DS_INCORRECT_ROLE_OWNER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8210","0x2012","error 8210","ERROR_DS_INCORRECT_ROLE_OWNER","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","incorrect","role","owner","the","requested","operation","could","not","performed","because","directory","service","master","for","that","type"],"errorCode":"8210","eventId":"","severity":"Low","summary":"The requested operation could not be performed because the directory service is not the master for that type of operation.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8210; use the surrounding log entries to confirm it.","resolution":"1. Record where 8210 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_INCORRECT_ROLE_OWNER.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8210 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested operation could not be performed because the directory service is not the master for that type of operation.\n\nLookup forms: 8210, 0x2012, error 8210, ERROR_DS_INCORRECT_ROLE_OWNER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8210"]},{"id":1714,"title":"ERROR_DS_RIDMGR_INIT_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8211","0x2013","error 8211","ERROR_DS_RIDMGR_INIT_ERROR","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","ridmgr","init","the","directory","service","was","unable","initialize","subsystem","that","allocates","relative","identifiers"],"errorCode":"8211","eventId":"","severity":"Medium","summary":"The directory service was unable to initialize the subsystem that allocates relative identifiers.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8211; use the surrounding log entries to confirm it.","resolution":"1. Record where 8211 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_RIDMGR_INIT_ERROR.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8211 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service was unable to initialize the subsystem that allocates relative identifiers.\n\nLookup forms: 8211, 0x2013, error 8211, ERROR_DS_RIDMGR_INIT_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8211"]},{"id":1715,"title":"ERROR_DS_OBJ_CLASS_VIOLATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8212","0x2014","error 8212","ERROR_DS_OBJ_CLASS_VIOLATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","obj","class","violation","the","requested","operation","did","not","satisfy","one","more","constraints","associated","with","object"],"errorCode":"8212","eventId":"","severity":"Low","summary":"The requested operation did not satisfy one or more constraints associated with the class of the object.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8212; use the surrounding log entries to confirm it.","resolution":"1. Record where 8212 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_OBJ_CLASS_VIOLATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8212 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested operation did not satisfy one or more constraints associated with the class of the object.\n\nLookup forms: 8212, 0x2014, error 8212, ERROR_DS_OBJ_CLASS_VIOLATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8212"]},{"id":1716,"title":"ERROR_DS_CANT_ON_NON_LEAF","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8213","0x2015","error 8213","ERROR_DS_CANT_ON_NON_LEAF","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","cant","non","leaf","the","directory","service","can","perform","requested","operation","only","object"],"errorCode":"8213","eventId":"","severity":"Low","summary":"The directory service can perform the requested operation only on a leaf object.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8213; use the surrounding log entries to confirm it.","resolution":"1. Record where 8213 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_ON_NON_LEAF.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8213 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service can perform the requested operation only on a leaf object.\n\nLookup forms: 8213, 0x2015, error 8213, ERROR_DS_CANT_ON_NON_LEAF. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8213"]},{"id":1717,"title":"ERROR_DS_CANT_ON_RDN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8214","0x2016","error 8214","ERROR_DS_CANT_ON_RDN","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","cant","rdn","the","directory","service","cannot","perform","requested","operation","attribute","object"],"errorCode":"8214","eventId":"","severity":"Medium","summary":"The directory service cannot perform the requested operation on the RDN attribute of an object.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8214; use the surrounding log entries to confirm it.","resolution":"1. Record where 8214 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_ON_RDN.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8214 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service cannot perform the requested operation on the RDN attribute of an object.\n\nLookup forms: 8214, 0x2016, error 8214, ERROR_DS_CANT_ON_RDN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8214"]},{"id":1718,"title":"ERROR_DS_CANT_MOD_OBJ_CLASS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8215","0x2017","error 8215","ERROR_DS_CANT_MOD_OBJ_CLASS","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","cant","mod","obj","class","the","directory","service","detected","attempt","modify","object"],"errorCode":"8215","eventId":"","severity":"Low","summary":"The directory service detected an attempt to modify the object class of an object.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8215; use the surrounding log entries to confirm it.","resolution":"1. Record where 8215 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_MOD_OBJ_CLASS.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8215 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service detected an attempt to modify the object class of an object.\n\nLookup forms: 8215, 0x2017, error 8215, ERROR_DS_CANT_MOD_OBJ_CLASS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8215"]},{"id":1719,"title":"ERROR_DS_CROSS_DOM_MOVE_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8216","0x2018","error 8216","ERROR_DS_CROSS_DOM_MOVE_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cross","dom","move","the","requested","domain","operation","could","not","performed"],"errorCode":"8216","eventId":"","severity":"Low","summary":"The requested cross-domain move operation could not be performed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8216; use the surrounding log entries to confirm it.","resolution":"1. Record where 8216 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CROSS_DOM_MOVE_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8216 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested cross-domain move operation could not be performed.\n\nLookup forms: 8216, 0x2018, error 8216, ERROR_DS_CROSS_DOM_MOVE_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8216"]},{"id":1720,"title":"ERROR_DS_GC_NOT_AVAILABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8217","0x2019","error 8217","ERROR_DS_GC_NOT_AVAILABLE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","not","available","unable","contact","the","global","catalog","server"],"errorCode":"8217","eventId":"","severity":"Medium","summary":"Unable to contact the global catalog server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8217; use the surrounding log entries to confirm it.","resolution":"1. Record where 8217 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_GC_NOT_AVAILABLE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8217 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to contact the global catalog server.\n\nLookup forms: 8217, 0x2019, error 8217, ERROR_DS_GC_NOT_AVAILABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8217"]},{"id":1721,"title":"ERROR_SHARED_POLICY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8218","0x201A","error 8218","ERROR_SHARED_POLICY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","shared","policy","the","object","and","can","only","modified","root"],"errorCode":"8218","eventId":"","severity":"Low","summary":"The policy object is shared and can only be modified at the root.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8218; use the surrounding log entries to confirm it.","resolution":"1. Record where 8218 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SHARED_POLICY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8218 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The policy object is shared and can only be modified at the root.\n\nLookup forms: 8218, 0x201A, error 8218, ERROR_SHARED_POLICY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8218"]},{"id":1722,"title":"ERROR_POLICY_OBJECT_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8219","0x201B","error 8219","ERROR_POLICY_OBJECT_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","policy","object","not","found","the","does","exist"],"errorCode":"8219","eventId":"","severity":"Low","summary":"The policy object does not exist.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8219; use the surrounding log entries to confirm it.","resolution":"1. Record where 8219 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_POLICY_OBJECT_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8219 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The policy object does not exist.\n\nLookup forms: 8219, 0x201B, error 8219, ERROR_POLICY_OBJECT_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8219"]},{"id":1723,"title":"ERROR_POLICY_ONLY_IN_DS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8220","0x201C","error 8220","ERROR_POLICY_ONLY_IN_DS","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","policy","only","the","requested","information","directory","service"],"errorCode":"8220","eventId":"","severity":"Low","summary":"The requested policy information is only in the directory service.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8220; use the surrounding log entries to confirm it.","resolution":"1. Record where 8220 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_POLICY_ONLY_IN_DS.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8220 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested policy information is only in the directory service.\n\nLookup forms: 8220, 0x201C, error 8220, ERROR_POLICY_ONLY_IN_DS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8220"]},{"id":1724,"title":"ERROR_PROMOTION_ACTIVE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8221","0x201D","error 8221","ERROR_PROMOTION_ACTIVE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","promotion","active","domain","controller","currently"],"errorCode":"8221","eventId":"","severity":"Low","summary":"A domain controller promotion is currently active.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8221; use the surrounding log entries to confirm it.","resolution":"1. Record where 8221 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PROMOTION_ACTIVE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8221 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A domain controller promotion is currently active.\n\nLookup forms: 8221, 0x201D, error 8221, ERROR_PROMOTION_ACTIVE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8221"]},{"id":1725,"title":"ERROR_NO_PROMOTION_ACTIVE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8222","0x201E","error 8222","ERROR_NO_PROMOTION_ACTIVE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","promotion","active","domain","controller","not","currently"],"errorCode":"8222","eventId":"","severity":"Low","summary":"A domain controller promotion is not currently active.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8222; use the surrounding log entries to confirm it.","resolution":"1. Record where 8222 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_PROMOTION_ACTIVE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8222 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A domain controller promotion is not currently active.\n\nLookup forms: 8222, 0x201E, error 8222, ERROR_NO_PROMOTION_ACTIVE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8222"]},{"id":1726,"title":"ERROR_DS_OPERATIONS_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8224","0x2020","error 8224","ERROR_DS_OPERATIONS_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","operations","occurred"],"errorCode":"8224","eventId":"","severity":"Low","summary":"An operations error occurred.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8224; use the surrounding log entries to confirm it.","resolution":"1. Record where 8224 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_OPERATIONS_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8224 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An operations error occurred.\n\nLookup forms: 8224, 0x2020, error 8224, ERROR_DS_OPERATIONS_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8224"]},{"id":1727,"title":"ERROR_DS_PROTOCOL_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8225","0x2021","error 8225","ERROR_DS_PROTOCOL_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","protocol","occurred"],"errorCode":"8225","eventId":"","severity":"Low","summary":"A protocol error occurred.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8225; use the surrounding log entries to confirm it.","resolution":"1. Record where 8225 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_PROTOCOL_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8225 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A protocol error occurred.\n\nLookup forms: 8225, 0x2021, error 8225, ERROR_DS_PROTOCOL_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8225"]},{"id":1728,"title":"ERROR_DS_TIMELIMIT_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8226","0x2022","error 8226","ERROR_DS_TIMELIMIT_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","timelimit","exceeded","the","time","limit","for","this","request","was"],"errorCode":"8226","eventId":"","severity":"Low","summary":"The time limit for this request was exceeded.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8226; use the surrounding log entries to confirm it.","resolution":"1. Record where 8226 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_TIMELIMIT_EXCEEDED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8226 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The time limit for this request was exceeded.\n\nLookup forms: 8226, 0x2022, error 8226, ERROR_DS_TIMELIMIT_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8226"]},{"id":1729,"title":"ERROR_DS_SIZELIMIT_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8227","0x2023","error 8227","ERROR_DS_SIZELIMIT_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sizelimit","exceeded","the","size","limit","for","this","request","was"],"errorCode":"8227","eventId":"","severity":"Low","summary":"The size limit for this request was exceeded.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8227; use the surrounding log entries to confirm it.","resolution":"1. Record where 8227 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SIZELIMIT_EXCEEDED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8227 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The size limit for this request was exceeded.\n\nLookup forms: 8227, 0x2023, error 8227, ERROR_DS_SIZELIMIT_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8227"]},{"id":1730,"title":"ERROR_DS_ADMIN_LIMIT_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8228","0x2024","error 8228","ERROR_DS_ADMIN_LIMIT_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","admin","limit","exceeded","the","administrative","for","this","request","was"],"errorCode":"8228","eventId":"","severity":"Low","summary":"The administrative limit for this request was exceeded.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8228; use the surrounding log entries to confirm it.","resolution":"1. Record where 8228 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_ADMIN_LIMIT_EXCEEDED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8228 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The administrative limit for this request was exceeded.\n\nLookup forms: 8228, 0x2024, error 8228, ERROR_DS_ADMIN_LIMIT_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8228"]},{"id":1731,"title":"ERROR_DS_COMPARE_FALSE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8229","0x2025","error 8229","ERROR_DS_COMPARE_FALSE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","compare","false","the","response","was"],"errorCode":"8229","eventId":"","severity":"Low","summary":"The compare response was false.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8229; use the surrounding log entries to confirm it.","resolution":"1. Record where 8229 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_COMPARE_FALSE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8229 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The compare response was false.\n\nLookup forms: 8229, 0x2025, error 8229, ERROR_DS_COMPARE_FALSE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8229"]},{"id":1732,"title":"ERROR_DS_COMPARE_TRUE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8230","0x2026","error 8230","ERROR_DS_COMPARE_TRUE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","compare","true","the","response","was"],"errorCode":"8230","eventId":"","severity":"Low","summary":"The compare response was true.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8230; use the surrounding log entries to confirm it.","resolution":"1. Record where 8230 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_COMPARE_TRUE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8230 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The compare response was true.\n\nLookup forms: 8230, 0x2026, error 8230, ERROR_DS_COMPARE_TRUE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8230"]},{"id":1733,"title":"ERROR_DS_AUTH_METHOD_NOT_SUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8231","0x2027","error 8231","ERROR_DS_AUTH_METHOD_NOT_SUPPORTED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","auth","method","not","supported","the","requested","authentication","server"],"errorCode":"8231","eventId":"","severity":"High","summary":"The requested authentication method is not supported by the server.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8231; use the surrounding log entries to confirm it.","resolution":"1. Record where 8231 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_AUTH_METHOD_NOT_SUPPORTED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8231 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested authentication method is not supported by the server.\n\nLookup forms: 8231, 0x2027, error 8231, ERROR_DS_AUTH_METHOD_NOT_SUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8231"]},{"id":1734,"title":"ERROR_DS_STRONG_AUTH_REQUIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8232","0x2028","error 8232","ERROR_DS_STRONG_AUTH_REQUIRED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","strong","auth","required","more","secure","authentication","method","for","this","server"],"errorCode":"8232","eventId":"","severity":"High","summary":"A more secure authentication method is required for this server.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8232; use the surrounding log entries to confirm it.","resolution":"1. Record where 8232 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_STRONG_AUTH_REQUIRED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8232 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A more secure authentication method is required for this server.\n\nLookup forms: 8232, 0x2028, error 8232, ERROR_DS_STRONG_AUTH_REQUIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8232"]},{"id":1735,"title":"ERROR_DS_INAPPROPRIATE_AUTH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8233","0x2029","error 8233","ERROR_DS_INAPPROPRIATE_AUTH","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","inappropriate","auth","authentication"],"errorCode":"8233","eventId":"","severity":"High","summary":"Inappropriate authentication.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8233; use the surrounding log entries to confirm it.","resolution":"1. Record where 8233 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_INAPPROPRIATE_AUTH.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8233 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Inappropriate authentication.\n\nLookup forms: 8233, 0x2029, error 8233, ERROR_DS_INAPPROPRIATE_AUTH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8233"]},{"id":1736,"title":"ERROR_DS_AUTH_UNKNOWN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8234","0x202A","error 8234","ERROR_DS_AUTH_UNKNOWN","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","auth","unknown","the","authentication","mechanism"],"errorCode":"8234","eventId":"","severity":"High","summary":"The authentication mechanism is unknown.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8234; use the surrounding log entries to confirm it.","resolution":"1. Record where 8234 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_AUTH_UNKNOWN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8234 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The authentication mechanism is unknown.\n\nLookup forms: 8234, 0x202A, error 8234, ERROR_DS_AUTH_UNKNOWN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8234"]},{"id":1737,"title":"ERROR_DS_REFERRAL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8235","0x202B","error 8235","ERROR_DS_REFERRAL","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","referral","was","returned","from","the","server"],"errorCode":"8235","eventId":"","severity":"Low","summary":"A referral was returned from the server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8235; use the surrounding log entries to confirm it.","resolution":"1. Record where 8235 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_REFERRAL.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8235 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A referral was returned from the server.\n\nLookup forms: 8235, 0x202B, error 8235, ERROR_DS_REFERRAL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8235"]},{"id":1738,"title":"ERROR_DS_UNAVAILABLE_CRIT_EXTENSION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8236","0x202C","error 8236","ERROR_DS_UNAVAILABLE_CRIT_EXTENSION","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","unavailable","crit","extension","the","server","does","not","support","requested","critical"],"errorCode":"8236","eventId":"","severity":"Low","summary":"The server does not support the requested critical extension.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8236; use the surrounding log entries to confirm it.","resolution":"1. Record where 8236 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_UNAVAILABLE_CRIT_EXTENSION.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8236 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The server does not support the requested critical extension.\n\nLookup forms: 8236, 0x202C, error 8236, ERROR_DS_UNAVAILABLE_CRIT_EXTENSION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8236"]},{"id":1739,"title":"ERROR_DS_CONFIDENTIALITY_REQUIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8237","0x202D","error 8237","ERROR_DS_CONFIDENTIALITY_REQUIRED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","confidentiality","required","this","request","requires","secure","connection"],"errorCode":"8237","eventId":"","severity":"High","summary":"This request requires a secure connection.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8237; use the surrounding log entries to confirm it.","resolution":"1. Record where 8237 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CONFIDENTIALITY_REQUIRED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8237 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This request requires a secure connection.\n\nLookup forms: 8237, 0x202D, error 8237, ERROR_DS_CONFIDENTIALITY_REQUIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8237"]},{"id":1740,"title":"ERROR_DS_INAPPROPRIATE_MATCHING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8238","0x202E","error 8238","ERROR_DS_INAPPROPRIATE_MATCHING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","inappropriate","matching"],"errorCode":"8238","eventId":"","severity":"Low","summary":"Inappropriate matching.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8238; use the surrounding log entries to confirm it.","resolution":"1. Record where 8238 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_INAPPROPRIATE_MATCHING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8238 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Inappropriate matching.\n\nLookup forms: 8238, 0x202E, error 8238, ERROR_DS_INAPPROPRIATE_MATCHING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8238"]},{"id":1741,"title":"ERROR_DS_CONSTRAINT_VIOLATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8239","0x202F","error 8239","ERROR_DS_CONSTRAINT_VIOLATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","constraint","violation","occurred"],"errorCode":"8239","eventId":"","severity":"Low","summary":"A constraint violation occurred.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8239; use the surrounding log entries to confirm it.","resolution":"1. Record where 8239 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CONSTRAINT_VIOLATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8239 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A constraint violation occurred.\n\nLookup forms: 8239, 0x202F, error 8239, ERROR_DS_CONSTRAINT_VIOLATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8239"]},{"id":1742,"title":"ERROR_DS_NO_SUCH_OBJECT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8240","0x2030","error 8240","ERROR_DS_NO_SUCH_OBJECT","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","such","object","there","the","server"],"errorCode":"8240","eventId":"","severity":"Low","summary":"There is no such object on the server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8240; use the surrounding log entries to confirm it.","resolution":"1. Record where 8240 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NO_SUCH_OBJECT.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8240 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There is no such object on the server.\n\nLookup forms: 8240, 0x2030, error 8240, ERROR_DS_NO_SUCH_OBJECT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8240"]},{"id":1743,"title":"ERROR_DS_ALIAS_PROBLEM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8241","0x2031","error 8241","ERROR_DS_ALIAS_PROBLEM","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","alias","problem","there"],"errorCode":"8241","eventId":"","severity":"Low","summary":"There is an alias problem.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8241; use the surrounding log entries to confirm it.","resolution":"1. Record where 8241 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_ALIAS_PROBLEM.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8241 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There is an alias problem.\n\nLookup forms: 8241, 0x2031, error 8241, ERROR_DS_ALIAS_PROBLEM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8241"]},{"id":1744,"title":"ERROR_DS_INVALID_DN_SYNTAX","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8242","0x2032","error 8242","ERROR_DS_INVALID_DN_SYNTAX","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","syntax","has","been","specified"],"errorCode":"8242","eventId":"","severity":"Medium","summary":"An invalid dn syntax has been specified.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8242; use the surrounding log entries to confirm it.","resolution":"1. Record where 8242 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_INVALID_DN_SYNTAX.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8242 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An invalid dn syntax has been specified.\n\nLookup forms: 8242, 0x2032, error 8242, ERROR_DS_INVALID_DN_SYNTAX. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8242"]},{"id":1745,"title":"ERROR_DS_IS_LEAF","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8243","0x2033","error 8243","ERROR_DS_IS_LEAF","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","leaf","the","object"],"errorCode":"8243","eventId":"","severity":"Low","summary":"The object is a leaf object.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8243; use the surrounding log entries to confirm it.","resolution":"1. Record where 8243 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_IS_LEAF.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8243 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The object is a leaf object.\n\nLookup forms: 8243, 0x2033, error 8243, ERROR_DS_IS_LEAF. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8243"]},{"id":1746,"title":"ERROR_DS_ALIAS_DEREF_PROBLEM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8244","0x2034","error 8244","ERROR_DS_ALIAS_DEREF_PROBLEM","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","alias","deref","problem","there","dereferencing"],"errorCode":"8244","eventId":"","severity":"Low","summary":"There is an alias dereferencing problem.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8244; use the surrounding log entries to confirm it.","resolution":"1. Record where 8244 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_ALIAS_DEREF_PROBLEM.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8244 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There is an alias dereferencing problem.\n\nLookup forms: 8244, 0x2034, error 8244, ERROR_DS_ALIAS_DEREF_PROBLEM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8244"]},{"id":1747,"title":"ERROR_DS_UNWILLING_TO_PERFORM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8245","0x2035","error 8245","ERROR_DS_UNWILLING_TO_PERFORM","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","unwilling","perform","the","server","process","request"],"errorCode":"8245","eventId":"","severity":"Low","summary":"The server is unwilling to process the request.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8245; use the surrounding log entries to confirm it.","resolution":"1. Record where 8245 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_UNWILLING_TO_PERFORM.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8245 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The server is unwilling to process the request.\n\nLookup forms: 8245, 0x2035, error 8245, ERROR_DS_UNWILLING_TO_PERFORM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8245"]},{"id":1748,"title":"ERROR_DS_LOOP_DETECT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8246","0x2036","error 8246","ERROR_DS_LOOP_DETECT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","loop","detect","has","been","detected"],"errorCode":"8246","eventId":"","severity":"Low","summary":"A loop has been detected.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8246; use the surrounding log entries to confirm it.","resolution":"1. Record where 8246 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_LOOP_DETECT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8246 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A loop has been detected.\n\nLookup forms: 8246, 0x2036, error 8246, ERROR_DS_LOOP_DETECT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8246"]},{"id":1749,"title":"ERROR_DS_NAMING_VIOLATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8247","0x2037","error 8247","ERROR_DS_NAMING_VIOLATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","naming","violation","there"],"errorCode":"8247","eventId":"","severity":"Low","summary":"There is a naming violation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8247; use the surrounding log entries to confirm it.","resolution":"1. Record where 8247 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NAMING_VIOLATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8247 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There is a naming violation.\n\nLookup forms: 8247, 0x2037, error 8247, ERROR_DS_NAMING_VIOLATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8247"]},{"id":1750,"title":"ERROR_DS_OBJECT_RESULTS_TOO_LARGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8248","0x2038","error 8248","ERROR_DS_OBJECT_RESULTS_TOO_LARGE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","object","results","too","large","the","result","set"],"errorCode":"8248","eventId":"","severity":"Low","summary":"The result set is too large.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8248; use the surrounding log entries to confirm it.","resolution":"1. Record where 8248 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_OBJECT_RESULTS_TOO_LARGE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8248 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The result set is too large.\n\nLookup forms: 8248, 0x2038, error 8248, ERROR_DS_OBJECT_RESULTS_TOO_LARGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8248"]},{"id":1751,"title":"ERROR_DS_AFFECTS_MULTIPLE_DSAS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8249","0x2039","error 8249","ERROR_DS_AFFECTS_MULTIPLE_DSAS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","affects","multiple","dsas","the","operation"],"errorCode":"8249","eventId":"","severity":"Low","summary":"The operation affects multiple DSAs.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8249; use the surrounding log entries to confirm it.","resolution":"1. Record where 8249 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_AFFECTS_MULTIPLE_DSAS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8249 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation affects multiple DSAs.\n\nLookup forms: 8249, 0x2039, error 8249, ERROR_DS_AFFECTS_MULTIPLE_DSAS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8249"]},{"id":1752,"title":"ERROR_DS_SERVER_DOWN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8250","0x203A","error 8250","ERROR_DS_SERVER_DOWN","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","server","down","the","not","operational"],"errorCode":"8250","eventId":"","severity":"Low","summary":"The server is not operational.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8250; use the surrounding log entries to confirm it.","resolution":"1. Record where 8250 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SERVER_DOWN.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8250 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The server is not operational.\n\nLookup forms: 8250, 0x203A, error 8250, ERROR_DS_SERVER_DOWN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8250"]},{"id":1753,"title":"ERROR_DS_LOCAL_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8251","0x203B","error 8251","ERROR_DS_LOCAL_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","local","has","occurred"],"errorCode":"8251","eventId":"","severity":"Low","summary":"A local error has occurred.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8251; use the surrounding log entries to confirm it.","resolution":"1. Record where 8251 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_LOCAL_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8251 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A local error has occurred.\n\nLookup forms: 8251, 0x203B, error 8251, ERROR_DS_LOCAL_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8251"]},{"id":1754,"title":"ERROR_DS_ENCODING_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8252","0x203C","error 8252","ERROR_DS_ENCODING_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","encoding","has","occurred"],"errorCode":"8252","eventId":"","severity":"Low","summary":"An encoding error has occurred.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8252; use the surrounding log entries to confirm it.","resolution":"1. Record where 8252 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_ENCODING_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8252 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An encoding error has occurred.\n\nLookup forms: 8252, 0x203C, error 8252, ERROR_DS_ENCODING_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8252"]},{"id":1755,"title":"ERROR_DS_DECODING_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8253","0x203D","error 8253","ERROR_DS_DECODING_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","decoding","has","occurred"],"errorCode":"8253","eventId":"","severity":"Low","summary":"A decoding error has occurred.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8253; use the surrounding log entries to confirm it.","resolution":"1. Record where 8253 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DECODING_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8253 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A decoding error has occurred.\n\nLookup forms: 8253, 0x203D, error 8253, ERROR_DS_DECODING_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8253"]},{"id":1756,"title":"ERROR_DS_FILTER_UNKNOWN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8254","0x203E","error 8254","ERROR_DS_FILTER_UNKNOWN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","filter","unknown","the","search","cannot","recognized"],"errorCode":"8254","eventId":"","severity":"Medium","summary":"The search filter cannot be recognized.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8254; use the surrounding log entries to confirm it.","resolution":"1. Record where 8254 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_FILTER_UNKNOWN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8254 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The search filter cannot be recognized.\n\nLookup forms: 8254, 0x203E, error 8254, ERROR_DS_FILTER_UNKNOWN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8254"]},{"id":1757,"title":"ERROR_DS_PARAM_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8255","0x203F","error 8255","ERROR_DS_PARAM_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","param","one","more","parameters","are","illegal"],"errorCode":"8255","eventId":"","severity":"Low","summary":"One or more parameters are illegal.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8255; use the surrounding log entries to confirm it.","resolution":"1. Record where 8255 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_PARAM_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8255 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: One or more parameters are illegal.\n\nLookup forms: 8255, 0x203F, error 8255, ERROR_DS_PARAM_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8255"]},{"id":1758,"title":"ERROR_DS_NOT_SUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8256","0x2040","error 8256","ERROR_DS_NOT_SUPPORTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","not","supported","the","specified","method"],"errorCode":"8256","eventId":"","severity":"Medium","summary":"The specified method is not supported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8256; use the surrounding log entries to confirm it.","resolution":"1. Record where 8256 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NOT_SUPPORTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8256 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified method is not supported.\n\nLookup forms: 8256, 0x2040, error 8256, ERROR_DS_NOT_SUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8256"]},{"id":1759,"title":"ERROR_DS_NO_RESULTS_RETURNED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8257","0x2041","error 8257","ERROR_DS_NO_RESULTS_RETURNED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","results","returned","were"],"errorCode":"8257","eventId":"","severity":"Low","summary":"No results were returned.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8257; use the surrounding log entries to confirm it.","resolution":"1. Record where 8257 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NO_RESULTS_RETURNED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8257 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No results were returned.\n\nLookup forms: 8257, 0x2041, error 8257, ERROR_DS_NO_RESULTS_RETURNED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8257"]},{"id":1760,"title":"ERROR_DS_CONTROL_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8258","0x2042","error 8258","ERROR_DS_CONTROL_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","control","not","found","the","specified","supported","server"],"errorCode":"8258","eventId":"","severity":"Medium","summary":"The specified control is not supported by the server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8258; use the surrounding log entries to confirm it.","resolution":"1. Record where 8258 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CONTROL_NOT_FOUND.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8258 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified control is not supported by the server.\n\nLookup forms: 8258, 0x2042, error 8258, ERROR_DS_CONTROL_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8258"]},{"id":1761,"title":"ERROR_DS_CLIENT_LOOP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8259","0x2043","error 8259","ERROR_DS_CLIENT_LOOP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","client","loop","referral","was","detected","the"],"errorCode":"8259","eventId":"","severity":"Low","summary":"A referral loop was detected by the client.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8259; use the surrounding log entries to confirm it.","resolution":"1. Record where 8259 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CLIENT_LOOP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8259 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A referral loop was detected by the client.\n\nLookup forms: 8259, 0x2043, error 8259, ERROR_DS_CLIENT_LOOP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8259"]},{"id":1762,"title":"ERROR_DS_REFERRAL_LIMIT_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8260","0x2044","error 8260","ERROR_DS_REFERRAL_LIMIT_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","referral","limit","exceeded","the","preset","was"],"errorCode":"8260","eventId":"","severity":"Low","summary":"The preset referral limit was exceeded.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8260; use the surrounding log entries to confirm it.","resolution":"1. Record where 8260 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_REFERRAL_LIMIT_EXCEEDED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8260 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The preset referral limit was exceeded.\n\nLookup forms: 8260, 0x2044, error 8260, ERROR_DS_REFERRAL_LIMIT_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8260"]},{"id":1763,"title":"ERROR_DS_SORT_CONTROL_MISSING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8261","0x2045","error 8261","ERROR_DS_SORT_CONTROL_MISSING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sort","control","missing","the","search","requires"],"errorCode":"8261","eventId":"","severity":"Low","summary":"The search requires a SORT control.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8261; use the surrounding log entries to confirm it.","resolution":"1. Record where 8261 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SORT_CONTROL_MISSING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8261 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The search requires a SORT control.\n\nLookup forms: 8261, 0x2045, error 8261, ERROR_DS_SORT_CONTROL_MISSING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8261"]},{"id":1764,"title":"ERROR_DS_OFFSET_RANGE_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8262","0x2046","error 8262","ERROR_DS_OFFSET_RANGE_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","offset","range","the","search","results","exceed","specified"],"errorCode":"8262","eventId":"","severity":"Low","summary":"The search results exceed the offset range specified.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8262; use the surrounding log entries to confirm it.","resolution":"1. Record where 8262 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_OFFSET_RANGE_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8262 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The search results exceed the offset range specified.\n\nLookup forms: 8262, 0x2046, error 8262, ERROR_DS_OFFSET_RANGE_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8262"]},{"id":1765,"title":"ERROR_DS_RIDMGR_DISABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8263","0x2047","error 8263","ERROR_DS_RIDMGR_DISABLED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ridmgr","disabled","the","directory","service","detected","subsystem","that","allocates","relative","identifiers","this","can","occur","protective","mechanism","when","system","determines","significant","portion","rids","have","been"],"errorCode":"8263","eventId":"","severity":"Low","summary":"The directory service detected the subsystem that allocates relative identifiers is disabled. This can occur as a protective mechanism when the system determines a significant portion of relative identifiers (RIDs) have been exhausted. Please see https://go.microsoft.com/fwlink/p/?linkid=228610 for recommended diagnostic steps and the procedure to re-enable account creation.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8263; use the surrounding log entries to confirm it.","resolution":"1. Record where 8263 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Confirm the user or service identity has the required permissions and is not locked or disabled.\n4. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n5. Verify the required service or agent is installed, running, and current; repair the component if needed.\n6. Review Event Viewer and the application or service log for the same timestamp and code.\n7. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_RIDMGR_DISABLED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Confirm the user or service identity has the required permissions and is not locked or disabled.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8263 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service detected the subsystem that allocates relative identifiers is disabled. This can occur as a protective mechanism when the system determines a significant portion of relative identifiers (RIDs) have been exhausted. Please see https://go.microsoft.com/fwlink/p/?linkid=228610 for recommended diagnostic steps and the procedure to re-enable account creation.\n\nLookup forms: 8263, 0x2047, error 8263, ERROR_DS_RIDMGR_DISABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8263"]},{"id":1766,"title":"ERROR_DS_ROOT_MUST_BE_NC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8301","0x206D","error 8301","ERROR_DS_ROOT_MUST_BE_NC","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","root","must","the","object","head","naming","context","cannot","have","instantiated","parent"],"errorCode":"8301","eventId":"","severity":"Medium","summary":"The root object must be the head of a naming context. The root object cannot have an instantiated parent.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8301; use the surrounding log entries to confirm it.","resolution":"1. Record where 8301 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_ROOT_MUST_BE_NC.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8301 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The root object must be the head of a naming context. The root object cannot have an instantiated parent.\n\nLookup forms: 8301, 0x206D, error 8301, ERROR_DS_ROOT_MUST_BE_NC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8301"]},{"id":1767,"title":"ERROR_DS_ADD_REPLICA_INHIBITED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8302","0x206E","error 8302","ERROR_DS_ADD_REPLICA_INHIBITED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","add","replica","inhibited","the","operation","cannot","performed","naming","context","must","writeable","order","create"],"errorCode":"8302","eventId":"","severity":"Medium","summary":"The add replica operation cannot be performed. The naming context must be writeable in order to create the replica.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8302; use the surrounding log entries to confirm it.","resolution":"1. Record where 8302 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_ADD_REPLICA_INHIBITED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8302 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The add replica operation cannot be performed. The naming context must be writeable in order to create the replica.\n\nLookup forms: 8302, 0x206E, error 8302, ERROR_DS_ADD_REPLICA_INHIBITED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The add replica operation cannot be performed. The naming context must be writable in order to create the replica.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8302"]},{"id":1768,"title":"ERROR_DS_ATT_NOT_DEF_IN_SCHEMA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8303","0x206F","error 8303","ERROR_DS_ATT_NOT_DEF_IN_SCHEMA","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","att","not","def","schema","reference","attribute","that","defined","the","occurred"],"errorCode":"8303","eventId":"","severity":"Low","summary":"A reference to an attribute that is not defined in the schema occurred.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8303; use the surrounding log entries to confirm it.","resolution":"1. Record where 8303 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_ATT_NOT_DEF_IN_SCHEMA.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8303 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A reference to an attribute that is not defined in the schema occurred.\n\nLookup forms: 8303, 0x206F, error 8303, ERROR_DS_ATT_NOT_DEF_IN_SCHEMA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8303"]},{"id":1769,"title":"ERROR_DS_MAX_OBJ_SIZE_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8304","0x2070","error 8304","ERROR_DS_MAX_OBJ_SIZE_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","max","obj","size","exceeded","the","maximum","object","has","been"],"errorCode":"8304","eventId":"","severity":"Low","summary":"The maximum size of an object has been exceeded.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8304; use the surrounding log entries to confirm it.","resolution":"1. Record where 8304 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_MAX_OBJ_SIZE_EXCEEDED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8304 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The maximum size of an object has been exceeded.\n\nLookup forms: 8304, 0x2070, error 8304, ERROR_DS_MAX_OBJ_SIZE_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8304"]},{"id":1770,"title":"ERROR_DS_OBJ_STRING_NAME_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8305","0x2071","error 8305","ERROR_DS_OBJ_STRING_NAME_EXISTS","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","obj","string","name","exists","attempt","was","made","add","object","the","directory","with","that","already","use"],"errorCode":"8305","eventId":"","severity":"Low","summary":"An attempt was made to add an object to the directory with a name that is already in use.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8305; use the surrounding log entries to confirm it.","resolution":"1. Record where 8305 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_OBJ_STRING_NAME_EXISTS.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8305 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt was made to add an object to the directory with a name that is already in use.\n\nLookup forms: 8305, 0x2071, error 8305, ERROR_DS_OBJ_STRING_NAME_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8305"]},{"id":1771,"title":"ERROR_DS_NO_RDN_DEFINED_IN_SCHEMA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8306","0x2072","error 8306","ERROR_DS_NO_RDN_DEFINED_IN_SCHEMA","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","rdn","defined","schema","attempt","was","made","add","object","class","that","does","not","have","the"],"errorCode":"8306","eventId":"","severity":"Low","summary":"An attempt was made to add an object of a class that does not have an RDN defined in the schema.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8306; use the surrounding log entries to confirm it.","resolution":"1. Record where 8306 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NO_RDN_DEFINED_IN_SCHEMA.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8306 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt was made to add an object of a class that does not have an RDN defined in the schema.\n\nLookup forms: 8306, 0x2072, error 8306, ERROR_DS_NO_RDN_DEFINED_IN_SCHEMA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8306"]},{"id":1772,"title":"ERROR_DS_RDN_DOESNT_MATCH_SCHEMA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8307","0x2073","error 8307","ERROR_DS_RDN_DOESNT_MATCH_SCHEMA","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","rdn","doesnt","match","schema","attempt","was","made","add","object","using","that","not","the","defined"],"errorCode":"8307","eventId":"","severity":"Low","summary":"An attempt was made to add an object using an RDN that is not the RDN defined in the schema.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8307; use the surrounding log entries to confirm it.","resolution":"1. Record where 8307 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_RDN_DOESNT_MATCH_SCHEMA.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8307 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt was made to add an object using an RDN that is not the RDN defined in the schema.\n\nLookup forms: 8307, 0x2073, error 8307, ERROR_DS_RDN_DOESNT_MATCH_SCHEMA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8307"]},{"id":1773,"title":"ERROR_DS_NO_REQUESTED_ATTS_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8308","0x2074","error 8308","ERROR_DS_NO_REQUESTED_ATTS_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","requested","atts","found","none","the","attributes","were","objects"],"errorCode":"8308","eventId":"","severity":"Low","summary":"None of the requested attributes were found on the objects.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8308; use the surrounding log entries to confirm it.","resolution":"1. Record where 8308 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NO_REQUESTED_ATTS_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8308 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: None of the requested attributes were found on the objects.\n\nLookup forms: 8308, 0x2074, error 8308, ERROR_DS_NO_REQUESTED_ATTS_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8308"]},{"id":1774,"title":"ERROR_DS_USER_BUFFER_TO_SMALL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8309","0x2075","error 8309","ERROR_DS_USER_BUFFER_TO_SMALL","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","user","buffer","small","the","too"],"errorCode":"8309","eventId":"","severity":"Low","summary":"The user buffer is too small.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8309; use the surrounding log entries to confirm it.","resolution":"1. Record where 8309 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_USER_BUFFER_TO_SMALL.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8309 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The user buffer is too small.\n\nLookup forms: 8309, 0x2075, error 8309, ERROR_DS_USER_BUFFER_TO_SMALL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8309"]},{"id":1775,"title":"ERROR_DS_ATT_IS_NOT_ON_OBJ","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8310","0x2076","error 8310","ERROR_DS_ATT_IS_NOT_ON_OBJ","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","att","not","obj","the","attribute","specified","operation","present","object"],"errorCode":"8310","eventId":"","severity":"Low","summary":"The attribute specified in the operation is not present on the object.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8310; use the surrounding log entries to confirm it.","resolution":"1. Record where 8310 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_ATT_IS_NOT_ON_OBJ.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8310 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The attribute specified in the operation is not present on the object.\n\nLookup forms: 8310, 0x2076, error 8310, ERROR_DS_ATT_IS_NOT_ON_OBJ. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8310"]},{"id":1776,"title":"ERROR_DS_ILLEGAL_MOD_OPERATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8311","0x2077","error 8311","ERROR_DS_ILLEGAL_MOD_OPERATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","illegal","mod","operation","modify","some","aspect","the","modification","not","permitted"],"errorCode":"8311","eventId":"","severity":"Low","summary":"Illegal modify operation. Some aspect of the modification is not permitted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8311; use the surrounding log entries to confirm it.","resolution":"1. Record where 8311 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_ILLEGAL_MOD_OPERATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8311 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Illegal modify operation. Some aspect of the modification is not permitted.\n\nLookup forms: 8311, 0x2077, error 8311, ERROR_DS_ILLEGAL_MOD_OPERATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8311"]},{"id":1777,"title":"ERROR_DS_OBJ_TOO_LARGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8312","0x2078","error 8312","ERROR_DS_OBJ_TOO_LARGE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","obj","too","large","the","specified","object"],"errorCode":"8312","eventId":"","severity":"Low","summary":"The specified object is too large.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8312; use the surrounding log entries to confirm it.","resolution":"1. Record where 8312 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_OBJ_TOO_LARGE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8312 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified object is too large.\n\nLookup forms: 8312, 0x2078, error 8312, ERROR_DS_OBJ_TOO_LARGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8312"]},{"id":1778,"title":"ERROR_DS_BAD_INSTANCE_TYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8313","0x2079","error 8313","ERROR_DS_BAD_INSTANCE_TYPE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","bad","instance","type","the","specified","not","valid"],"errorCode":"8313","eventId":"","severity":"Low","summary":"The specified instance type is not valid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8313; use the surrounding log entries to confirm it.","resolution":"1. Record where 8313 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_BAD_INSTANCE_TYPE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8313 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified instance type is not valid.\n\nLookup forms: 8313, 0x2079, error 8313, ERROR_DS_BAD_INSTANCE_TYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8313"]},{"id":1779,"title":"ERROR_DS_MASTERDSA_REQUIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8314","0x207A","error 8314","ERROR_DS_MASTERDSA_REQUIRED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","masterdsa","required","the","operation","must","performed","master","dsa"],"errorCode":"8314","eventId":"","severity":"Low","summary":"The operation must be performed at a master DSA.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8314; use the surrounding log entries to confirm it.","resolution":"1. Record where 8314 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_MASTERDSA_REQUIRED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8314 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation must be performed at a master DSA.\n\nLookup forms: 8314, 0x207A, error 8314, ERROR_DS_MASTERDSA_REQUIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8314"]},{"id":1780,"title":"ERROR_DS_OBJECT_CLASS_REQUIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8315","0x207B","error 8315","ERROR_DS_OBJECT_CLASS_REQUIRED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","object","class","required","the","attribute","must","specified"],"errorCode":"8315","eventId":"","severity":"Low","summary":"The object class attribute must be specified.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8315; use the surrounding log entries to confirm it.","resolution":"1. Record where 8315 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_OBJECT_CLASS_REQUIRED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8315 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The object class attribute must be specified.\n\nLookup forms: 8315, 0x207B, error 8315, ERROR_DS_OBJECT_CLASS_REQUIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8315"]},{"id":1781,"title":"ERROR_DS_MISSING_REQUIRED_ATT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8316","0x207C","error 8316","ERROR_DS_MISSING_REQUIRED_ATT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","missing","required","att","attribute"],"errorCode":"8316","eventId":"","severity":"Low","summary":"A required attribute is missing.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8316; use the surrounding log entries to confirm it.","resolution":"1. Record where 8316 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_MISSING_REQUIRED_ATT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8316 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A required attribute is missing.\n\nLookup forms: 8316, 0x207C, error 8316, ERROR_DS_MISSING_REQUIRED_ATT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8316"]},{"id":1782,"title":"ERROR_DS_ATT_NOT_DEF_FOR_CLASS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8317","0x207D","error 8317","ERROR_DS_ATT_NOT_DEF_FOR_CLASS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","att","not","def","for","class","attempt","was","made","modify","object","include","attribute","that","legal","its"],"errorCode":"8317","eventId":"","severity":"Low","summary":"An attempt was made to modify an object to include an attribute that is not legal for its class.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8317; use the surrounding log entries to confirm it.","resolution":"1. Record where 8317 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_ATT_NOT_DEF_FOR_CLASS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8317 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt was made to modify an object to include an attribute that is not legal for its class.\n\nLookup forms: 8317, 0x207D, error 8317, ERROR_DS_ATT_NOT_DEF_FOR_CLASS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8317"]},{"id":1783,"title":"ERROR_DS_ATT_ALREADY_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8318","0x207E","error 8318","ERROR_DS_ATT_ALREADY_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","att","already","exists","the","specified","attribute","present","object"],"errorCode":"8318","eventId":"","severity":"Low","summary":"The specified attribute is already present on the object.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8318; use the surrounding log entries to confirm it.","resolution":"1. Record where 8318 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_ATT_ALREADY_EXISTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8318 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified attribute is already present on the object.\n\nLookup forms: 8318, 0x207E, error 8318, ERROR_DS_ATT_ALREADY_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8318"]},{"id":1784,"title":"ERROR_DS_CANT_ADD_ATT_VALUES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8320","0x2080","error 8320","ERROR_DS_CANT_ADD_ATT_VALUES","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","add","att","values","the","specified","attribute","not","present","has"],"errorCode":"8320","eventId":"","severity":"Low","summary":"The specified attribute is not present, or has no values.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8320; use the surrounding log entries to confirm it.","resolution":"1. Record where 8320 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_ADD_ATT_VALUES.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8320 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified attribute is not present, or has no values.\n\nLookup forms: 8320, 0x2080, error 8320, ERROR_DS_CANT_ADD_ATT_VALUES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8320"]},{"id":1785,"title":"ERROR_DS_SINGLE_VALUE_CONSTRAINT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8321","0x2081","error 8321","ERROR_DS_SINGLE_VALUE_CONSTRAINT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","single","value","constraint","multiple","values","were","specified","for","attribute","that","can","have","only","one"],"errorCode":"8321","eventId":"","severity":"Low","summary":"Multiple values were specified for an attribute that can have only one value.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8321; use the surrounding log entries to confirm it.","resolution":"1. Record where 8321 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SINGLE_VALUE_CONSTRAINT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8321 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Multiple values were specified for an attribute that can have only one value.\n\nLookup forms: 8321, 0x2081, error 8321, ERROR_DS_SINGLE_VALUE_CONSTRAINT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8321"]},{"id":1786,"title":"ERROR_DS_RANGE_CONSTRAINT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8322","0x2082","error 8322","ERROR_DS_RANGE_CONSTRAINT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","range","constraint","value","for","the","attribute","was","not","acceptable","values"],"errorCode":"8322","eventId":"","severity":"Low","summary":"A value for the attribute was not in the acceptable range of values.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8322; use the surrounding log entries to confirm it.","resolution":"1. Record where 8322 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_RANGE_CONSTRAINT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8322 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A value for the attribute was not in the acceptable range of values.\n\nLookup forms: 8322, 0x2082, error 8322, ERROR_DS_RANGE_CONSTRAINT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8322"]},{"id":1787,"title":"ERROR_DS_ATT_VAL_ALREADY_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8323","0x2083","error 8323","ERROR_DS_ATT_VAL_ALREADY_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","att","val","already","exists","the","specified","value"],"errorCode":"8323","eventId":"","severity":"Medium","summary":"The specified value already exists.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8323; use the surrounding log entries to confirm it.","resolution":"1. Record where 8323 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_ATT_VAL_ALREADY_EXISTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8323 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified value already exists.\n\nLookup forms: 8323, 0x2083, error 8323, ERROR_DS_ATT_VAL_ALREADY_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8323"]},{"id":1788,"title":"ERROR_DS_CANT_REM_MISSING_ATT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8324","0x2084","error 8324","ERROR_DS_CANT_REM_MISSING_ATT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","rem","missing","att","the","attribute","cannot","removed","because","not","present","object"],"errorCode":"8324","eventId":"","severity":"Medium","summary":"The attribute cannot be removed because it is not present on the object.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8324; use the surrounding log entries to confirm it.","resolution":"1. Record where 8324 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_REM_MISSING_ATT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8324 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The attribute cannot be removed because it is not present on the object.\n\nLookup forms: 8324, 0x2084, error 8324, ERROR_DS_CANT_REM_MISSING_ATT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8324"]},{"id":1789,"title":"ERROR_DS_CANT_REM_MISSING_ATT_VAL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8325","0x2085","error 8325","ERROR_DS_CANT_REM_MISSING_ATT_VAL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","rem","missing","att","val","the","attribute","value","cannot","removed","because","not","present","object"],"errorCode":"8325","eventId":"","severity":"Medium","summary":"The attribute value cannot be removed because it is not present on the object.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8325; use the surrounding log entries to confirm it.","resolution":"1. Record where 8325 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_REM_MISSING_ATT_VAL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8325 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The attribute value cannot be removed because it is not present on the object.\n\nLookup forms: 8325, 0x2085, error 8325, ERROR_DS_CANT_REM_MISSING_ATT_VAL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8325"]},{"id":1790,"title":"ERROR_DS_ROOT_CANT_BE_SUBREF","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8326","0x2086","error 8326","ERROR_DS_ROOT_CANT_BE_SUBREF","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","root","cant","subref","the","specified","object","cannot"],"errorCode":"8326","eventId":"","severity":"Medium","summary":"The specified root object cannot be a subref.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8326; use the surrounding log entries to confirm it.","resolution":"1. Record where 8326 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_ROOT_CANT_BE_SUBREF.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8326 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified root object cannot be a subref.\n\nLookup forms: 8326, 0x2086, error 8326, ERROR_DS_ROOT_CANT_BE_SUBREF. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8326"]},{"id":1791,"title":"ERROR_DS_NO_CHAINING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8327","0x2087","error 8327","ERROR_DS_NO_CHAINING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","chaining","not","permitted"],"errorCode":"8327","eventId":"","severity":"Low","summary":"Chaining is not permitted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8327; use the surrounding log entries to confirm it.","resolution":"1. Record where 8327 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NO_CHAINING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8327 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Chaining is not permitted.\n\nLookup forms: 8327, 0x2087, error 8327, ERROR_DS_NO_CHAINING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8327"]},{"id":1792,"title":"ERROR_DS_NO_CHAINED_EVAL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8328","0x2088","error 8328","ERROR_DS_NO_CHAINED_EVAL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","chained","eval","evaluation","not","permitted"],"errorCode":"8328","eventId":"","severity":"Low","summary":"Chained evaluation is not permitted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8328; use the surrounding log entries to confirm it.","resolution":"1. Record where 8328 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NO_CHAINED_EVAL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8328 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Chained evaluation is not permitted.\n\nLookup forms: 8328, 0x2088, error 8328, ERROR_DS_NO_CHAINED_EVAL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8328"]},{"id":1793,"title":"ERROR_DS_NO_PARENT_OBJECT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8329","0x2089","error 8329","ERROR_DS_NO_PARENT_OBJECT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","parent","object","the","operation","could","not","performed","because","either","uninstantiated","deleted"],"errorCode":"8329","eventId":"","severity":"Low","summary":"The operation could not be performed because the object's parent is either uninstantiated or deleted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8329; use the surrounding log entries to confirm it.","resolution":"1. Record where 8329 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NO_PARENT_OBJECT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8329 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation could not be performed because the object's parent is either uninstantiated or deleted.\n\nLookup forms: 8329, 0x2089, error 8329, ERROR_DS_NO_PARENT_OBJECT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8329"]},{"id":1794,"title":"ERROR_DS_PARENT_IS_AN_ALIAS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8330","0x208A","error 8330","ERROR_DS_PARENT_IS_AN_ALIAS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","parent","alias","having","that","not","permitted","aliases","are","leaf","objects"],"errorCode":"8330","eventId":"","severity":"Low","summary":"Having a parent that is an alias is not permitted. Aliases are leaf objects.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8330; use the surrounding log entries to confirm it.","resolution":"1. Record where 8330 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_PARENT_IS_AN_ALIAS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8330 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Having a parent that is an alias is not permitted. Aliases are leaf objects.\n\nLookup forms: 8330, 0x208A, error 8330, ERROR_DS_PARENT_IS_AN_ALIAS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8330"]},{"id":1795,"title":"ERROR_DS_CANT_MIX_MASTER_AND_REPS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8331","0x208B","error 8331","ERROR_DS_CANT_MIX_MASTER_AND_REPS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","mix","master","and","reps","the","object","parent","must","same","type","either","both","masters","replicas"],"errorCode":"8331","eventId":"","severity":"Low","summary":"The object and parent must be of the same type, either both masters or both replicas.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8331; use the surrounding log entries to confirm it.","resolution":"1. Record where 8331 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_MIX_MASTER_AND_REPS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8331 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The object and parent must be of the same type, either both masters or both replicas.\n\nLookup forms: 8331, 0x208B, error 8331, ERROR_DS_CANT_MIX_MASTER_AND_REPS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8331"]},{"id":1796,"title":"ERROR_DS_CHILDREN_EXIST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8332","0x208C","error 8332","ERROR_DS_CHILDREN_EXIST","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","children","exist","the","operation","cannot","performed","because","child","objects","this","can","only","leaf","object"],"errorCode":"8332","eventId":"","severity":"Medium","summary":"The operation cannot be performed because child objects exist. This operation can only be performed on a leaf object.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8332; use the surrounding log entries to confirm it.","resolution":"1. Record where 8332 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CHILDREN_EXIST.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8332 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation cannot be performed because child objects exist. This operation can only be performed on a leaf object.\n\nLookup forms: 8332, 0x208C, error 8332, ERROR_DS_CHILDREN_EXIST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8332"]},{"id":1797,"title":"ERROR_DS_OBJ_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8333","0x208D","error 8333","ERROR_DS_OBJ_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","obj","not","found","directory","object"],"errorCode":"8333","eventId":"","severity":"Medium","summary":"Directory object not found.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8333; use the surrounding log entries to confirm it.","resolution":"1. Record where 8333 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_OBJ_NOT_FOUND.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8333 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Directory object not found.\n\nLookup forms: 8333, 0x208D, error 8333, ERROR_DS_OBJ_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8333"]},{"id":1798,"title":"ERROR_DS_ALIASED_OBJ_MISSING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8334","0x208E","error 8334","ERROR_DS_ALIASED_OBJ_MISSING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","aliased","obj","missing","the","object"],"errorCode":"8334","eventId":"","severity":"Low","summary":"The aliased object is missing.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8334; use the surrounding log entries to confirm it.","resolution":"1. Record where 8334 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_ALIASED_OBJ_MISSING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8334 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The aliased object is missing.\n\nLookup forms: 8334, 0x208E, error 8334, ERROR_DS_ALIASED_OBJ_MISSING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8334"]},{"id":1799,"title":"ERROR_DS_BAD_NAME_SYNTAX","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8335","0x208F","error 8335","ERROR_DS_BAD_NAME_SYNTAX","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","bad","name","syntax","the","object","has"],"errorCode":"8335","eventId":"","severity":"Low","summary":"The object name has bad syntax.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8335; use the surrounding log entries to confirm it.","resolution":"1. Record where 8335 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_BAD_NAME_SYNTAX.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8335 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The object name has bad syntax.\n\nLookup forms: 8335, 0x208F, error 8335, ERROR_DS_BAD_NAME_SYNTAX. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8335"]},{"id":1800,"title":"ERROR_DS_ALIAS_POINTS_TO_ALIAS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8336","0x2090","error 8336","ERROR_DS_ALIAS_POINTS_TO_ALIAS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","alias","points","not","permitted","for","refer","another"],"errorCode":"8336","eventId":"","severity":"Low","summary":"It is not permitted for an alias to refer to another alias.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8336; use the surrounding log entries to confirm it.","resolution":"1. Record where 8336 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_ALIAS_POINTS_TO_ALIAS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8336 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: It is not permitted for an alias to refer to another alias.\n\nLookup forms: 8336, 0x2090, error 8336, ERROR_DS_ALIAS_POINTS_TO_ALIAS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8336"]},{"id":1801,"title":"ERROR_DS_CANT_DEREF_ALIAS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8337","0x2091","error 8337","ERROR_DS_CANT_DEREF_ALIAS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","deref","alias","the","cannot","dereferenced"],"errorCode":"8337","eventId":"","severity":"Medium","summary":"The alias cannot be dereferenced.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8337; use the surrounding log entries to confirm it.","resolution":"1. Record where 8337 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_DEREF_ALIAS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8337 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The alias cannot be dereferenced.\n\nLookup forms: 8337, 0x2091, error 8337, ERROR_DS_CANT_DEREF_ALIAS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8337"]},{"id":1802,"title":"ERROR_DS_OUT_OF_SCOPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8338","0x2092","error 8338","ERROR_DS_OUT_OF_SCOPE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","out","scope","the","operation"],"errorCode":"8338","eventId":"","severity":"Low","summary":"The operation is out of scope.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8338; use the surrounding log entries to confirm it.","resolution":"1. Record where 8338 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_OUT_OF_SCOPE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8338 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation is out of scope.\n\nLookup forms: 8338, 0x2092, error 8338, ERROR_DS_OUT_OF_SCOPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8338"]},{"id":1803,"title":"ERROR_DS_OBJECT_BEING_REMOVED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8339","0x2093","error 8339","ERROR_DS_OBJECT_BEING_REMOVED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","object","being","removed","the","operation","cannot","continue","because","process"],"errorCode":"8339","eventId":"","severity":"Medium","summary":"The operation cannot continue because the object is in the process of being removed.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 8339; use the surrounding log entries to confirm it.","resolution":"1. Record where 8339 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_OBJECT_BEING_REMOVED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8339 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation cannot continue because the object is in the process of being removed.\n\nLookup forms: 8339, 0x2093, error 8339, ERROR_DS_OBJECT_BEING_REMOVED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8339"]},{"id":1804,"title":"ERROR_DS_CANT_DELETE_DSA_OBJ","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8340","0x2094","error 8340","ERROR_DS_CANT_DELETE_DSA_OBJ","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","delete","dsa","obj","the","object","cannot","deleted"],"errorCode":"8340","eventId":"","severity":"Medium","summary":"The DSA object cannot be deleted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8340; use the surrounding log entries to confirm it.","resolution":"1. Record where 8340 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_DELETE_DSA_OBJ.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8340 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The DSA object cannot be deleted.\n\nLookup forms: 8340, 0x2094, error 8340, ERROR_DS_CANT_DELETE_DSA_OBJ. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8340"]},{"id":1805,"title":"ERROR_DS_GENERIC_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8341","0x2095","error 8341","ERROR_DS_GENERIC_ERROR","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","generic","directory","service","has","occurred"],"errorCode":"8341","eventId":"","severity":"Low","summary":"A directory service error has occurred.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8341; use the surrounding log entries to confirm it.","resolution":"1. Record where 8341 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_GENERIC_ERROR.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8341 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A directory service error has occurred.\n\nLookup forms: 8341, 0x2095, error 8341, ERROR_DS_GENERIC_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8341"]},{"id":1806,"title":"ERROR_DS_DSA_MUST_BE_INT_MASTER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8342","0x2096","error 8342","ERROR_DS_DSA_MUST_BE_INT_MASTER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dsa","must","int","master","the","operation","can","only","performed","internal","object"],"errorCode":"8342","eventId":"","severity":"Low","summary":"The operation can only be performed on an internal master DSA object.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8342; use the surrounding log entries to confirm it.","resolution":"1. Record where 8342 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DSA_MUST_BE_INT_MASTER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8342 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation can only be performed on an internal master DSA object.\n\nLookup forms: 8342, 0x2096, error 8342, ERROR_DS_DSA_MUST_BE_INT_MASTER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8342"]},{"id":1807,"title":"ERROR_DS_CLASS_NOT_DSA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8343","0x2097","error 8343","ERROR_DS_CLASS_NOT_DSA","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","class","not","dsa","the","object","must"],"errorCode":"8343","eventId":"","severity":"Low","summary":"The object must be of class DSA.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8343; use the surrounding log entries to confirm it.","resolution":"1. Record where 8343 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CLASS_NOT_DSA.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8343 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The object must be of class DSA.\n\nLookup forms: 8343, 0x2097, error 8343, ERROR_DS_CLASS_NOT_DSA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8343"]},{"id":1808,"title":"ERROR_DS_INSUFF_ACCESS_RIGHTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8344","0x2098","error 8344","ERROR_DS_INSUFF_ACCESS_RIGHTS","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","insuff","access","rights","insufficient","perform","the","operation"],"errorCode":"8344","eventId":"","severity":"Low","summary":"Insufficient access rights to perform the operation.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8344; use the surrounding log entries to confirm it.","resolution":"1. Record where 8344 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_INSUFF_ACCESS_RIGHTS.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8344 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Insufficient access rights to perform the operation.\n\nLookup forms: 8344, 0x2098, error 8344, ERROR_DS_INSUFF_ACCESS_RIGHTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8344"]},{"id":1809,"title":"ERROR_DS_ILLEGAL_SUPERIOR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8345","0x2099","error 8345","ERROR_DS_ILLEGAL_SUPERIOR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","illegal","superior","the","object","cannot","added","because","parent","not","list","possible","superiors"],"errorCode":"8345","eventId":"","severity":"Medium","summary":"The object cannot be added because the parent is not on the list of possible superiors.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8345; use the surrounding log entries to confirm it.","resolution":"1. Record where 8345 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_ILLEGAL_SUPERIOR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8345 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The object cannot be added because the parent is not on the list of possible superiors.\n\nLookup forms: 8345, 0x2099, error 8345, ERROR_DS_ILLEGAL_SUPERIOR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8345"]},{"id":1810,"title":"ERROR_DS_ATTRIBUTE_OWNED_BY_SAM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8346","0x209A","error 8346","ERROR_DS_ATTRIBUTE_OWNED_BY_SAM","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","attribute","owned","sam","access","the","not","permitted","because","security","accounts","manager"],"errorCode":"8346","eventId":"","severity":"Low","summary":"Access to the attribute is not permitted because the attribute is owned by the Security Accounts Manager (SAM).","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8346; use the surrounding log entries to confirm it.","resolution":"1. Record where 8346 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_ATTRIBUTE_OWNED_BY_SAM.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8346 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Access to the attribute is not permitted because the attribute is owned by the Security Accounts Manager (SAM).\n\nLookup forms: 8346, 0x209A, error 8346, ERROR_DS_ATTRIBUTE_OWNED_BY_SAM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8346"]},{"id":1811,"title":"ERROR_DS_NAME_TOO_MANY_PARTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8347","0x209B","error 8347","ERROR_DS_NAME_TOO_MANY_PARTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","name","too","many","parts","the","has"],"errorCode":"8347","eventId":"","severity":"Low","summary":"The name has too many parts.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8347; use the surrounding log entries to confirm it.","resolution":"1. Record where 8347 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NAME_TOO_MANY_PARTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8347 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The name has too many parts.\n\nLookup forms: 8347, 0x209B, error 8347, ERROR_DS_NAME_TOO_MANY_PARTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8347"]},{"id":1812,"title":"ERROR_DS_NAME_TOO_LONG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8348","0x209C","error 8348","ERROR_DS_NAME_TOO_LONG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","name","too","long","the"],"errorCode":"8348","eventId":"","severity":"Low","summary":"The name is too long.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8348; use the surrounding log entries to confirm it.","resolution":"1. Record where 8348 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NAME_TOO_LONG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8348 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The name is too long.\n\nLookup forms: 8348, 0x209C, error 8348, ERROR_DS_NAME_TOO_LONG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8348"]},{"id":1813,"title":"ERROR_DS_NAME_VALUE_TOO_LONG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8349","0x209D","error 8349","ERROR_DS_NAME_VALUE_TOO_LONG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","name","value","too","long","the"],"errorCode":"8349","eventId":"","severity":"Low","summary":"The name value is too long.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8349; use the surrounding log entries to confirm it.","resolution":"1. Record where 8349 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NAME_VALUE_TOO_LONG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8349 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The name value is too long.\n\nLookup forms: 8349, 0x209D, error 8349, ERROR_DS_NAME_VALUE_TOO_LONG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8349"]},{"id":1814,"title":"ERROR_DS_NAME_UNPARSEABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8350","0x209E","error 8350","ERROR_DS_NAME_UNPARSEABLE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","name","unparseable","the","directory","service","encountered","parsing"],"errorCode":"8350","eventId":"","severity":"Low","summary":"The directory service encountered an error parsing a name.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8350; use the surrounding log entries to confirm it.","resolution":"1. Record where 8350 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NAME_UNPARSEABLE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8350 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service encountered an error parsing a name.\n\nLookup forms: 8350, 0x209E, error 8350, ERROR_DS_NAME_UNPARSEABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8350"]},{"id":1815,"title":"ERROR_DS_NAME_TYPE_UNKNOWN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8351","0x209F","error 8351","ERROR_DS_NAME_TYPE_UNKNOWN","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","name","type","unknown","the","directory","service","cannot","get","attribute","for"],"errorCode":"8351","eventId":"","severity":"Medium","summary":"The directory service cannot get the attribute type for a name.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8351; use the surrounding log entries to confirm it.","resolution":"1. Record where 8351 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NAME_TYPE_UNKNOWN.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8351 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service cannot get the attribute type for a name.\n\nLookup forms: 8351, 0x209F, error 8351, ERROR_DS_NAME_TYPE_UNKNOWN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8351"]},{"id":1816,"title":"ERROR_DS_NOT_AN_OBJECT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8352","0x20A0","error 8352","ERROR_DS_NOT_AN_OBJECT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","not","object","the","name","does","identify","identifies","phantom"],"errorCode":"8352","eventId":"","severity":"Low","summary":"The name does not identify an object; the name identifies a phantom.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8352; use the surrounding log entries to confirm it.","resolution":"1. Record where 8352 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NOT_AN_OBJECT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8352 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The name does not identify an object; the name identifies a phantom.\n\nLookup forms: 8352, 0x20A0, error 8352, ERROR_DS_NOT_AN_OBJECT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8352"]},{"id":1817,"title":"ERROR_DS_SEC_DESC_TOO_SHORT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8353","0x20A1","error 8353","ERROR_DS_SEC_DESC_TOO_SHORT","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","sec","desc","too","short","the","security","descriptor"],"errorCode":"8353","eventId":"","severity":"Low","summary":"The security descriptor is too short.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8353; use the surrounding log entries to confirm it.","resolution":"1. Record where 8353 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SEC_DESC_TOO_SHORT.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8353 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The security descriptor is too short.\n\nLookup forms: 8353, 0x20A1, error 8353, ERROR_DS_SEC_DESC_TOO_SHORT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8353"]},{"id":1818,"title":"ERROR_DS_SEC_DESC_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8354","0x20A2","error 8354","ERROR_DS_SEC_DESC_INVALID","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","sec","desc","invalid","the","security","descriptor"],"errorCode":"8354","eventId":"","severity":"Medium","summary":"The security descriptor is invalid.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8354; use the surrounding log entries to confirm it.","resolution":"1. Record where 8354 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SEC_DESC_INVALID.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8354 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The security descriptor is invalid.\n\nLookup forms: 8354, 0x20A2, error 8354, ERROR_DS_SEC_DESC_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8354"]},{"id":1819,"title":"ERROR_DS_NO_DELETED_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8355","0x20A3","error 8355","ERROR_DS_NO_DELETED_NAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","deleted","name","failed","create","for","object"],"errorCode":"8355","eventId":"","severity":"High","summary":"Failed to create name for deleted object.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8355; use the surrounding log entries to confirm it.","resolution":"1. Record where 8355 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NO_DELETED_NAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8355 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Failed to create name for deleted object.\n\nLookup forms: 8355, 0x20A3, error 8355, ERROR_DS_NO_DELETED_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8355"]},{"id":1820,"title":"ERROR_DS_SUBREF_MUST_HAVE_PARENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8356","0x20A4","error 8356","ERROR_DS_SUBREF_MUST_HAVE_PARENT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","subref","must","have","parent","the","new","exist"],"errorCode":"8356","eventId":"","severity":"Low","summary":"The parent of a new subref must exist.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8356; use the surrounding log entries to confirm it.","resolution":"1. Record where 8356 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SUBREF_MUST_HAVE_PARENT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8356 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The parent of a new subref must exist.\n\nLookup forms: 8356, 0x20A4, error 8356, ERROR_DS_SUBREF_MUST_HAVE_PARENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8356"]},{"id":1821,"title":"ERROR_DS_NCNAME_MUST_BE_NC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8357","0x20A5","error 8357","ERROR_DS_NCNAME_MUST_BE_NC","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ncname","must","the","object","naming","context"],"errorCode":"8357","eventId":"","severity":"Low","summary":"The object must be a naming context.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8357; use the surrounding log entries to confirm it.","resolution":"1. Record where 8357 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NCNAME_MUST_BE_NC.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8357 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The object must be a naming context.\n\nLookup forms: 8357, 0x20A5, error 8357, ERROR_DS_NCNAME_MUST_BE_NC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8357"]},{"id":1822,"title":"ERROR_DS_CANT_ADD_SYSTEM_ONLY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8358","0x20A6","error 8358","ERROR_DS_CANT_ADD_SYSTEM_ONLY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","add","system","only","not","permitted","attribute","which","owned","the"],"errorCode":"8358","eventId":"","severity":"Low","summary":"It is not permitted to add an attribute which is owned by the system.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8358; use the surrounding log entries to confirm it.","resolution":"1. Record where 8358 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_ADD_SYSTEM_ONLY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8358 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: It is not permitted to add an attribute which is owned by the system.\n\nLookup forms: 8358, 0x20A6, error 8358, ERROR_DS_CANT_ADD_SYSTEM_ONLY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8358"]},{"id":1823,"title":"ERROR_DS_CLASS_MUST_BE_CONCRETE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8359","0x20A7","error 8359","ERROR_DS_CLASS_MUST_BE_CONCRETE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","class","must","concrete","the","object","structural","you","cannot","instantiate","abstract"],"errorCode":"8359","eventId":"","severity":"Medium","summary":"The class of the object must be structural; you cannot instantiate an abstract class.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8359; use the surrounding log entries to confirm it.","resolution":"1. Record where 8359 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CLASS_MUST_BE_CONCRETE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8359 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The class of the object must be structural; you cannot instantiate an abstract class.\n\nLookup forms: 8359, 0x20A7, error 8359, ERROR_DS_CLASS_MUST_BE_CONCRETE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8359"]},{"id":1824,"title":"ERROR_DS_INVALID_DMD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8360","0x20A8","error 8360","ERROR_DS_INVALID_DMD","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","dmd","the","schema","object","could","not","found"],"errorCode":"8360","eventId":"","severity":"Low","summary":"The schema object could not be found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8360; use the surrounding log entries to confirm it.","resolution":"1. Record where 8360 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_INVALID_DMD.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8360 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The schema object could not be found.\n\nLookup forms: 8360, 0x20A8, error 8360, ERROR_DS_INVALID_DMD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8360"]},{"id":1825,"title":"ERROR_DS_OBJ_GUID_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8361","0x20A9","error 8361","ERROR_DS_OBJ_GUID_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","obj","guid","exists","local","object","with","this","dead","alive","already"],"errorCode":"8361","eventId":"","severity":"Medium","summary":"A local object with this GUID (dead or alive) already exists.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8361; use the surrounding log entries to confirm it.","resolution":"1. Record where 8361 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_OBJ_GUID_EXISTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8361 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A local object with this GUID (dead or alive) already exists.\n\nLookup forms: 8361, 0x20A9, error 8361, ERROR_DS_OBJ_GUID_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8361"]},{"id":1826,"title":"ERROR_DS_NOT_ON_BACKLINK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8362","0x20AA","error 8362","ERROR_DS_NOT_ON_BACKLINK","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","not","backlink","the","operation","cannot","performed","back","link"],"errorCode":"8362","eventId":"","severity":"Medium","summary":"The operation cannot be performed on a back link.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8362; use the surrounding log entries to confirm it.","resolution":"1. Record where 8362 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NOT_ON_BACKLINK.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8362 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation cannot be performed on a back link.\n\nLookup forms: 8362, 0x20AA, error 8362, ERROR_DS_NOT_ON_BACKLINK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8362"]},{"id":1827,"title":"ERROR_DS_NO_CROSSREF_FOR_NC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8363","0x20AB","error 8363","ERROR_DS_NO_CROSSREF_FOR_NC","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","crossref","for","the","cross","reference","specified","naming","context","could","not","found"],"errorCode":"8363","eventId":"","severity":"Low","summary":"The cross reference for the specified naming context could not be found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8363; use the surrounding log entries to confirm it.","resolution":"1. Record where 8363 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NO_CROSSREF_FOR_NC.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8363 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The cross reference for the specified naming context could not be found.\n\nLookup forms: 8363, 0x20AB, error 8363, ERROR_DS_NO_CROSSREF_FOR_NC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8363"]},{"id":1828,"title":"ERROR_DS_SHUTTING_DOWN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8364","0x20AC","error 8364","ERROR_DS_SHUTTING_DOWN","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","shutting","down","the","operation","could","not","performed","because","directory","service"],"errorCode":"8364","eventId":"","severity":"Low","summary":"The operation could not be performed because the directory service is shutting down.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8364; use the surrounding log entries to confirm it.","resolution":"1. Record where 8364 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SHUTTING_DOWN.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8364 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation could not be performed because the directory service is shutting down.\n\nLookup forms: 8364, 0x20AC, error 8364, ERROR_DS_SHUTTING_DOWN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8364"]},{"id":1829,"title":"ERROR_DS_UNKNOWN_OPERATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8365","0x20AD","error 8365","ERROR_DS_UNKNOWN_OPERATION","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","unknown","operation","the","directory","service","request","invalid"],"errorCode":"8365","eventId":"","severity":"Medium","summary":"The directory service request is invalid.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8365; use the surrounding log entries to confirm it.","resolution":"1. Record where 8365 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_UNKNOWN_OPERATION.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8365 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service request is invalid.\n\nLookup forms: 8365, 0x20AD, error 8365, ERROR_DS_UNKNOWN_OPERATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8365"]},{"id":1830,"title":"ERROR_DS_INVALID_ROLE_OWNER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8366","0x20AE","error 8366","ERROR_DS_INVALID_ROLE_OWNER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","role","owner","the","attribute","could","not","read"],"errorCode":"8366","eventId":"","severity":"Low","summary":"The role owner attribute could not be read.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8366; use the surrounding log entries to confirm it.","resolution":"1. Record where 8366 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_INVALID_ROLE_OWNER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8366 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The role owner attribute could not be read.\n\nLookup forms: 8366, 0x20AE, error 8366, ERROR_DS_INVALID_ROLE_OWNER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8366"]},{"id":1831,"title":"ERROR_DS_COULDNT_CONTACT_FSMO","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8367","0x20AF","error 8367","ERROR_DS_COULDNT_CONTACT_FSMO","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","couldnt","contact","fsmo","the","requested","operation","failed","current","holder","could","not","contacted"],"errorCode":"8367","eventId":"","severity":"High","summary":"The requested FSMO operation failed. The current FSMO holder could not be contacted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8367; use the surrounding log entries to confirm it.","resolution":"1. Record where 8367 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_COULDNT_CONTACT_FSMO.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8367 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested FSMO operation failed. The current FSMO holder could not be contacted.\n\nLookup forms: 8367, 0x20AF, error 8367, ERROR_DS_COULDNT_CONTACT_FSMO. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The requested FSMO operation failed. The current FSMO holder could not be reached.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8367"]},{"id":1832,"title":"ERROR_DS_CROSS_NC_DN_RENAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8368","0x20B0","error 8368","ERROR_DS_CROSS_NC_DN_RENAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cross","rename","modification","across","naming","context","not","permitted"],"errorCode":"8368","eventId":"","severity":"Low","summary":"Modification of a DN across a naming context is not permitted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8368; use the surrounding log entries to confirm it.","resolution":"1. Record where 8368 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CROSS_NC_DN_RENAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8368 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Modification of a DN across a naming context is not permitted.\n\nLookup forms: 8368, 0x20B0, error 8368, ERROR_DS_CROSS_NC_DN_RENAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8368"]},{"id":1833,"title":"ERROR_DS_CANT_MOD_SYSTEM_ONLY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8369","0x20B1","error 8369","ERROR_DS_CANT_MOD_SYSTEM_ONLY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","mod","system","only","the","attribute","cannot","modified","because","owned"],"errorCode":"8369","eventId":"","severity":"Medium","summary":"The attribute cannot be modified because it is owned by the system.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8369; use the surrounding log entries to confirm it.","resolution":"1. Record where 8369 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_MOD_SYSTEM_ONLY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8369 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The attribute cannot be modified because it is owned by the system.\n\nLookup forms: 8369, 0x20B1, error 8369, ERROR_DS_CANT_MOD_SYSTEM_ONLY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8369"]},{"id":1834,"title":"ERROR_DS_REPLICATOR_ONLY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8370","0x20B2","error 8370","ERROR_DS_REPLICATOR_ONLY","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","replicator","only","the","can","perform","this","function"],"errorCode":"8370","eventId":"","severity":"Low","summary":"Only the replicator can perform this function.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 8370; use the surrounding log entries to confirm it.","resolution":"1. Record where 8370 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_REPLICATOR_ONLY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8370 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Only the replicator can perform this function.\n\nLookup forms: 8370, 0x20B2, error 8370, ERROR_DS_REPLICATOR_ONLY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8370"]},{"id":1835,"title":"ERROR_DS_OBJ_CLASS_NOT_DEFINED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8371","0x20B3","error 8371","ERROR_DS_OBJ_CLASS_NOT_DEFINED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","obj","class","not","defined","the","specified"],"errorCode":"8371","eventId":"","severity":"Low","summary":"The specified class is not defined.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8371; use the surrounding log entries to confirm it.","resolution":"1. Record where 8371 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_OBJ_CLASS_NOT_DEFINED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8371 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified class is not defined.\n\nLookup forms: 8371, 0x20B3, error 8371, ERROR_DS_OBJ_CLASS_NOT_DEFINED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8371"]},{"id":1836,"title":"ERROR_DS_OBJ_CLASS_NOT_SUBCLASS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8372","0x20B4","error 8372","ERROR_DS_OBJ_CLASS_NOT_SUBCLASS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","obj","class","not","subclass","the","specified"],"errorCode":"8372","eventId":"","severity":"Low","summary":"The specified class is not a subclass.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8372; use the surrounding log entries to confirm it.","resolution":"1. Record where 8372 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_OBJ_CLASS_NOT_SUBCLASS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8372 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified class is not a subclass.\n\nLookup forms: 8372, 0x20B4, error 8372, ERROR_DS_OBJ_CLASS_NOT_SUBCLASS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8372"]},{"id":1837,"title":"ERROR_DS_NAME_REFERENCE_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8373","0x20B5","error 8373","ERROR_DS_NAME_REFERENCE_INVALID","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","name","reference","invalid","the"],"errorCode":"8373","eventId":"","severity":"Medium","summary":"The name reference is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8373; use the surrounding log entries to confirm it.","resolution":"1. Record where 8373 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NAME_REFERENCE_INVALID.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8373 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The name reference is invalid.\n\nLookup forms: 8373, 0x20B5, error 8373, ERROR_DS_NAME_REFERENCE_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8373"]},{"id":1838,"title":"ERROR_DS_CROSS_REF_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8374","0x20B6","error 8374","ERROR_DS_CROSS_REF_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cross","ref","exists","reference","already"],"errorCode":"8374","eventId":"","severity":"Medium","summary":"A cross reference already exists.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8374; use the surrounding log entries to confirm it.","resolution":"1. Record where 8374 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CROSS_REF_EXISTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8374 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A cross reference already exists.\n\nLookup forms: 8374, 0x20B6, error 8374, ERROR_DS_CROSS_REF_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8374"]},{"id":1839,"title":"ERROR_DS_CANT_DEL_MASTER_CROSSREF","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8375","0x20B7","error 8375","ERROR_DS_CANT_DEL_MASTER_CROSSREF","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","del","master","crossref","not","permitted","delete","cross","reference"],"errorCode":"8375","eventId":"","severity":"Low","summary":"It is not permitted to delete a master cross reference.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8375; use the surrounding log entries to confirm it.","resolution":"1. Record where 8375 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_DEL_MASTER_CROSSREF.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8375 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: It is not permitted to delete a master cross reference.\n\nLookup forms: 8375, 0x20B7, error 8375, ERROR_DS_CANT_DEL_MASTER_CROSSREF. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8375"]},{"id":1840,"title":"ERROR_DS_SUBTREE_NOTIFY_NOT_NC_HEAD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8376","0x20B8","error 8376","ERROR_DS_SUBTREE_NOTIFY_NOT_NC_HEAD","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","subtree","notify","not","head","notifications","are","only","supported","heads"],"errorCode":"8376","eventId":"","severity":"Low","summary":"Subtree notifications are only supported on NC heads.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8376; use the surrounding log entries to confirm it.","resolution":"1. Record where 8376 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SUBTREE_NOTIFY_NOT_NC_HEAD.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8376 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Subtree notifications are only supported on NC heads.\n\nLookup forms: 8376, 0x20B8, error 8376, ERROR_DS_SUBTREE_NOTIFY_NOT_NC_HEAD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8376"]},{"id":1841,"title":"ERROR_DS_NOTIFY_FILTER_TOO_COMPLEX","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8377","0x20B9","error 8377","ERROR_DS_NOTIFY_FILTER_TOO_COMPLEX","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","notify","filter","too","complex","notification"],"errorCode":"8377","eventId":"","severity":"Low","summary":"Notification filter is too complex.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8377; use the surrounding log entries to confirm it.","resolution":"1. Record where 8377 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NOTIFY_FILTER_TOO_COMPLEX.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8377 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Notification filter is too complex.\n\nLookup forms: 8377, 0x20B9, error 8377, ERROR_DS_NOTIFY_FILTER_TOO_COMPLEX. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8377"]},{"id":1842,"title":"ERROR_DS_DUP_RDN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8378","0x20BA","error 8378","ERROR_DS_DUP_RDN","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","dup","rdn","schema","update","failed","duplicate"],"errorCode":"8378","eventId":"","severity":"High","summary":"Schema update failed: duplicate RDN.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 8378; use the surrounding log entries to confirm it.","resolution":"1. Record where 8378 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DUP_RDN.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8378 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema update failed: duplicate RDN.\n\nLookup forms: 8378, 0x20BA, error 8378, ERROR_DS_DUP_RDN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8378"]},{"id":1843,"title":"ERROR_DS_DUP_OID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8379","0x20BB","error 8379","ERROR_DS_DUP_OID","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","dup","oid","schema","update","failed","duplicate"],"errorCode":"8379","eventId":"","severity":"High","summary":"Schema update failed: duplicate OID.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 8379; use the surrounding log entries to confirm it.","resolution":"1. Record where 8379 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DUP_OID.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8379 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema update failed: duplicate OID.\n\nLookup forms: 8379, 0x20BB, error 8379, ERROR_DS_DUP_OID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8379"]},{"id":1844,"title":"ERROR_DS_DUP_MAPI_ID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8380","0x20BC","error 8380","ERROR_DS_DUP_MAPI_ID","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","dup","mapi","schema","update","failed","duplicate","identifier"],"errorCode":"8380","eventId":"","severity":"High","summary":"Schema update failed: duplicate MAPI identifier.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 8380; use the surrounding log entries to confirm it.","resolution":"1. Record where 8380 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DUP_MAPI_ID.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8380 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema update failed: duplicate MAPI identifier.\n\nLookup forms: 8380, 0x20BC, error 8380, ERROR_DS_DUP_MAPI_ID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8380"]},{"id":1845,"title":"ERROR_DS_DUP_SCHEMA_ID_GUID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8381","0x20BD","error 8381","ERROR_DS_DUP_SCHEMA_ID_GUID","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","dup","schema","guid","update","failed","duplicate"],"errorCode":"8381","eventId":"","severity":"High","summary":"Schema update failed: duplicate schema-id GUID.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 8381; use the surrounding log entries to confirm it.","resolution":"1. Record where 8381 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DUP_SCHEMA_ID_GUID.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8381 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema update failed: duplicate schema-id GUID.\n\nLookup forms: 8381, 0x20BD, error 8381, ERROR_DS_DUP_SCHEMA_ID_GUID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8381"]},{"id":1846,"title":"ERROR_DS_DUP_LDAP_DISPLAY_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8382","0x20BE","error 8382","ERROR_DS_DUP_LDAP_DISPLAY_NAME","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","dup","ldap","display","name","schema","update","failed","duplicate"],"errorCode":"8382","eventId":"","severity":"High","summary":"Schema update failed: duplicate LDAP display name.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 8382; use the surrounding log entries to confirm it.","resolution":"1. Record where 8382 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DUP_LDAP_DISPLAY_NAME.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8382 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema update failed: duplicate LDAP display name.\n\nLookup forms: 8382, 0x20BE, error 8382, ERROR_DS_DUP_LDAP_DISPLAY_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8382"]},{"id":1847,"title":"ERROR_DS_SEMANTIC_ATT_TEST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8383","0x20BF","error 8383","ERROR_DS_SEMANTIC_ATT_TEST","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","semantic","att","test","schema","update","failed","range","lower","less","than","upper"],"errorCode":"8383","eventId":"","severity":"High","summary":"Schema update failed: range-lower less than range upper.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 8383; use the surrounding log entries to confirm it.","resolution":"1. Record where 8383 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SEMANTIC_ATT_TEST.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8383 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema update failed: range-lower less than range upper.\n\nLookup forms: 8383, 0x20BF, error 8383, ERROR_DS_SEMANTIC_ATT_TEST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8383"]},{"id":1848,"title":"ERROR_DS_SYNTAX_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8384","0x20C0","error 8384","ERROR_DS_SYNTAX_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","syntax","mismatch","schema","update","failed"],"errorCode":"8384","eventId":"","severity":"High","summary":"Schema update failed: syntax mismatch.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 8384; use the surrounding log entries to confirm it.","resolution":"1. Record where 8384 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SYNTAX_MISMATCH.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8384 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema update failed: syntax mismatch.\n\nLookup forms: 8384, 0x20C0, error 8384, ERROR_DS_SYNTAX_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8384"]},{"id":1849,"title":"ERROR_DS_EXISTS_IN_MUST_HAVE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8385","0x20C1","error 8385","ERROR_DS_EXISTS_IN_MUST_HAVE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","exists","must","have","schema","deletion","failed","attribute","used","contain"],"errorCode":"8385","eventId":"","severity":"High","summary":"Schema deletion failed: attribute is used in must-contain.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8385; use the surrounding log entries to confirm it.","resolution":"1. Record where 8385 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_EXISTS_IN_MUST_HAVE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8385 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema deletion failed: attribute is used in must-contain.\n\nLookup forms: 8385, 0x20C1, error 8385, ERROR_DS_EXISTS_IN_MUST_HAVE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8385"]},{"id":1850,"title":"ERROR_DS_EXISTS_IN_MAY_HAVE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8386","0x20C2","error 8386","ERROR_DS_EXISTS_IN_MAY_HAVE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","exists","may","have","schema","deletion","failed","attribute","used","contain"],"errorCode":"8386","eventId":"","severity":"High","summary":"Schema deletion failed: attribute is used in may-contain.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8386; use the surrounding log entries to confirm it.","resolution":"1. Record where 8386 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_EXISTS_IN_MAY_HAVE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8386 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema deletion failed: attribute is used in may-contain.\n\nLookup forms: 8386, 0x20C2, error 8386, ERROR_DS_EXISTS_IN_MAY_HAVE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8386"]},{"id":1851,"title":"ERROR_DS_NONEXISTENT_MAY_HAVE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8387","0x20C3","error 8387","ERROR_DS_NONEXISTENT_MAY_HAVE","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","nonexistent","may","have","schema","update","failed","attribute","contain","does","not","exist"],"errorCode":"8387","eventId":"","severity":"High","summary":"Schema update failed: attribute in may-contain does not exist.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 8387; use the surrounding log entries to confirm it.","resolution":"1. Record where 8387 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NONEXISTENT_MAY_HAVE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8387 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema update failed: attribute in may-contain does not exist.\n\nLookup forms: 8387, 0x20C3, error 8387, ERROR_DS_NONEXISTENT_MAY_HAVE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8387"]},{"id":1852,"title":"ERROR_DS_NONEXISTENT_MUST_HAVE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8388","0x20C4","error 8388","ERROR_DS_NONEXISTENT_MUST_HAVE","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","nonexistent","must","have","schema","update","failed","attribute","contain","does","not","exist"],"errorCode":"8388","eventId":"","severity":"High","summary":"Schema update failed: attribute in must-contain does not exist.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 8388; use the surrounding log entries to confirm it.","resolution":"1. Record where 8388 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NONEXISTENT_MUST_HAVE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8388 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema update failed: attribute in must-contain does not exist.\n\nLookup forms: 8388, 0x20C4, error 8388, ERROR_DS_NONEXISTENT_MUST_HAVE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8388"]},{"id":1853,"title":"ERROR_DS_AUX_CLS_TEST_FAIL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8389","0x20C5","error 8389","ERROR_DS_AUX_CLS_TEST_FAIL","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","aux","cls","test","fail","schema","update","failed","class","list","does","not","exist","auxiliary"],"errorCode":"8389","eventId":"","severity":"High","summary":"Schema update failed: class in aux-class list does not exist or is not an auxiliary class.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 8389; use the surrounding log entries to confirm it.","resolution":"1. Record where 8389 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_AUX_CLS_TEST_FAIL.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8389 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema update failed: class in aux-class list does not exist or is not an auxiliary class.\n\nLookup forms: 8389, 0x20C5, error 8389, ERROR_DS_AUX_CLS_TEST_FAIL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8389"]},{"id":1854,"title":"ERROR_DS_NONEXISTENT_POSS_SUP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8390","0x20C6","error 8390","ERROR_DS_NONEXISTENT_POSS_SUP","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","nonexistent","poss","sup","schema","update","failed","class","superiors","does","not","exist"],"errorCode":"8390","eventId":"","severity":"High","summary":"Schema update failed: class in poss-superiors does not exist.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 8390; use the surrounding log entries to confirm it.","resolution":"1. Record where 8390 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NONEXISTENT_POSS_SUP.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8390 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema update failed: class in poss-superiors does not exist.\n\nLookup forms: 8390, 0x20C6, error 8390, ERROR_DS_NONEXISTENT_POSS_SUP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8390"]},{"id":1855,"title":"ERROR_DS_SUB_CLS_TEST_FAIL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8391","0x20C7","error 8391","ERROR_DS_SUB_CLS_TEST_FAIL","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","sub","cls","test","fail","schema","update","failed","class","subclassof","list","does","not","exist","satisfy","hierarchy","rules"],"errorCode":"8391","eventId":"","severity":"High","summary":"Schema update failed: class in subclassof list does not exist or does not satisfy hierarchy rules.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 8391; use the surrounding log entries to confirm it.","resolution":"1. Record where 8391 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SUB_CLS_TEST_FAIL.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8391 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema update failed: class in subclassof list does not exist or does not satisfy hierarchy rules.\n\nLookup forms: 8391, 0x20C7, error 8391, ERROR_DS_SUB_CLS_TEST_FAIL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8391"]},{"id":1856,"title":"ERROR_DS_BAD_RDN_ATT_ID_SYNTAX","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8392","0x20C8","error 8392","ERROR_DS_BAD_RDN_ATT_ID_SYNTAX","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","bad","rdn","att","syntax","schema","update","failed","has","wrong"],"errorCode":"8392","eventId":"","severity":"High","summary":"Schema update failed: Rdn-Att-Id has wrong syntax.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 8392; use the surrounding log entries to confirm it.","resolution":"1. Record where 8392 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_BAD_RDN_ATT_ID_SYNTAX.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8392 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema update failed: Rdn-Att-Id has wrong syntax.\n\nLookup forms: 8392, 0x20C8, error 8392, ERROR_DS_BAD_RDN_ATT_ID_SYNTAX. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8392"]},{"id":1857,"title":"ERROR_DS_EXISTS_IN_AUX_CLS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8393","0x20C9","error 8393","ERROR_DS_EXISTS_IN_AUX_CLS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","exists","aux","cls","schema","deletion","failed","class","used","auxiliary"],"errorCode":"8393","eventId":"","severity":"High","summary":"Schema deletion failed: class is used as auxiliary class.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8393; use the surrounding log entries to confirm it.","resolution":"1. Record where 8393 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_EXISTS_IN_AUX_CLS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8393 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema deletion failed: class is used as auxiliary class.\n\nLookup forms: 8393, 0x20C9, error 8393, ERROR_DS_EXISTS_IN_AUX_CLS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8393"]},{"id":1858,"title":"ERROR_DS_EXISTS_IN_SUB_CLS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8394","0x20CA","error 8394","ERROR_DS_EXISTS_IN_SUB_CLS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","exists","sub","cls","schema","deletion","failed","class","used"],"errorCode":"8394","eventId":"","severity":"High","summary":"Schema deletion failed: class is used as sub class.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8394; use the surrounding log entries to confirm it.","resolution":"1. Record where 8394 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_EXISTS_IN_SUB_CLS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8394 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema deletion failed: class is used as sub class.\n\nLookup forms: 8394, 0x20CA, error 8394, ERROR_DS_EXISTS_IN_SUB_CLS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8394"]},{"id":1859,"title":"ERROR_DS_EXISTS_IN_POSS_SUP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8395","0x20CB","error 8395","ERROR_DS_EXISTS_IN_POSS_SUP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","exists","poss","sup","schema","deletion","failed","class","used","superior"],"errorCode":"8395","eventId":"","severity":"High","summary":"Schema deletion failed: class is used as poss superior.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8395; use the surrounding log entries to confirm it.","resolution":"1. Record where 8395 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_EXISTS_IN_POSS_SUP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8395 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema deletion failed: class is used as poss superior.\n\nLookup forms: 8395, 0x20CB, error 8395, ERROR_DS_EXISTS_IN_POSS_SUP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8395"]},{"id":1860,"title":"ERROR_DS_RECALCSCHEMA_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8396","0x20CC","error 8396","ERROR_DS_RECALCSCHEMA_FAILED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","recalcschema","failed","schema","update","recalculating","validation","cache"],"errorCode":"8396","eventId":"","severity":"High","summary":"Schema update failed in recalculating validation cache.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 8396; use the surrounding log entries to confirm it.","resolution":"1. Record where 8396 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_RECALCSCHEMA_FAILED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8396 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema update failed in recalculating validation cache.\n\nLookup forms: 8396, 0x20CC, error 8396, ERROR_DS_RECALCSCHEMA_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8396"]},{"id":1861,"title":"ERROR_DS_TREE_DELETE_NOT_FINISHED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8397","0x20CD","error 8397","ERROR_DS_TREE_DELETE_NOT_FINISHED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","tree","delete","not","finished","the","deletion","request","must","made","again","continue","deleting"],"errorCode":"8397","eventId":"","severity":"Low","summary":"The tree deletion is not finished. The request must be made again to continue deleting the tree.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8397; use the surrounding log entries to confirm it.","resolution":"1. Record where 8397 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_TREE_DELETE_NOT_FINISHED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8397 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The tree deletion is not finished. The request must be made again to continue deleting the tree.\n\nLookup forms: 8397, 0x20CD, error 8397, ERROR_DS_TREE_DELETE_NOT_FINISHED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8397"]},{"id":1862,"title":"ERROR_DS_CANT_DELETE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8398","0x20CE","error 8398","ERROR_DS_CANT_DELETE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","delete","the","requested","operation","could","not","performed"],"errorCode":"8398","eventId":"","severity":"Low","summary":"The requested delete operation could not be performed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8398; use the surrounding log entries to confirm it.","resolution":"1. Record where 8398 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_DELETE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8398 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested delete operation could not be performed.\n\nLookup forms: 8398, 0x20CE, error 8398, ERROR_DS_CANT_DELETE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8398"]},{"id":1863,"title":"ERROR_DS_ATT_SCHEMA_REQ_ID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8399","0x20CF","error 8399","ERROR_DS_ATT_SCHEMA_REQ_ID","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","att","schema","req","cannot","read","the","governs","class","identifier","for","record"],"errorCode":"8399","eventId":"","severity":"Medium","summary":"Cannot read the governs class identifier for the schema record.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8399; use the surrounding log entries to confirm it.","resolution":"1. Record where 8399 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_ATT_SCHEMA_REQ_ID.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8399 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot read the governs class identifier for the schema record.\n\nLookup forms: 8399, 0x20CF, error 8399, ERROR_DS_ATT_SCHEMA_REQ_ID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8399"]},{"id":1864,"title":"ERROR_DS_BAD_ATT_SCHEMA_SYNTAX","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8400","0x20D0","error 8400","ERROR_DS_BAD_ATT_SCHEMA_SYNTAX","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","bad","att","schema","syntax","the","attribute","has"],"errorCode":"8400","eventId":"","severity":"Low","summary":"The attribute schema has bad syntax.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8400; use the surrounding log entries to confirm it.","resolution":"1. Record where 8400 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_BAD_ATT_SCHEMA_SYNTAX.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8400 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The attribute schema has bad syntax.\n\nLookup forms: 8400, 0x20D0, error 8400, ERROR_DS_BAD_ATT_SCHEMA_SYNTAX. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8400"]},{"id":1865,"title":"ERROR_DS_CANT_CACHE_ATT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8401","0x20D1","error 8401","ERROR_DS_CANT_CACHE_ATT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","cache","att","the","attribute","could","not","cached"],"errorCode":"8401","eventId":"","severity":"Low","summary":"The attribute could not be cached.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8401; use the surrounding log entries to confirm it.","resolution":"1. Record where 8401 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_CACHE_ATT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8401 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The attribute could not be cached.\n\nLookup forms: 8401, 0x20D1, error 8401, ERROR_DS_CANT_CACHE_ATT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8401"]},{"id":1866,"title":"ERROR_DS_CANT_CACHE_CLASS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8402","0x20D2","error 8402","ERROR_DS_CANT_CACHE_CLASS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","cache","class","the","could","not","cached"],"errorCode":"8402","eventId":"","severity":"Low","summary":"The class could not be cached.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8402; use the surrounding log entries to confirm it.","resolution":"1. Record where 8402 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_CACHE_CLASS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8402 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The class could not be cached.\n\nLookup forms: 8402, 0x20D2, error 8402, ERROR_DS_CANT_CACHE_CLASS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8402"]},{"id":1867,"title":"ERROR_DS_CANT_REMOVE_ATT_CACHE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8403","0x20D3","error 8403","ERROR_DS_CANT_REMOVE_ATT_CACHE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","remove","att","cache","the","attribute","could","not","removed","from"],"errorCode":"8403","eventId":"","severity":"Low","summary":"The attribute could not be removed from the cache.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8403; use the surrounding log entries to confirm it.","resolution":"1. Record where 8403 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_REMOVE_ATT_CACHE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8403 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The attribute could not be removed from the cache.\n\nLookup forms: 8403, 0x20D3, error 8403, ERROR_DS_CANT_REMOVE_ATT_CACHE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8403"]},{"id":1868,"title":"ERROR_DS_CANT_REMOVE_CLASS_CACHE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8404","0x20D4","error 8404","ERROR_DS_CANT_REMOVE_CLASS_CACHE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","remove","class","cache","the","could","not","removed","from"],"errorCode":"8404","eventId":"","severity":"Low","summary":"The class could not be removed from the cache.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8404; use the surrounding log entries to confirm it.","resolution":"1. Record where 8404 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_REMOVE_CLASS_CACHE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8404 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The class could not be removed from the cache.\n\nLookup forms: 8404, 0x20D4, error 8404, ERROR_DS_CANT_REMOVE_CLASS_CACHE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8404"]},{"id":1869,"title":"ERROR_DS_CANT_RETRIEVE_DN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8405","0x20D5","error 8405","ERROR_DS_CANT_RETRIEVE_DN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","retrieve","the","distinguished","name","attribute","could","not","read"],"errorCode":"8405","eventId":"","severity":"Low","summary":"The distinguished name attribute could not be read.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8405; use the surrounding log entries to confirm it.","resolution":"1. Record where 8405 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_RETRIEVE_DN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8405 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The distinguished name attribute could not be read.\n\nLookup forms: 8405, 0x20D5, error 8405, ERROR_DS_CANT_RETRIEVE_DN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8405"]},{"id":1870,"title":"ERROR_DS_MISSING_SUPREF","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8406","0x20D6","error 8406","ERROR_DS_MISSING_SUPREF","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","missing","supref","superior","reference","has","been","configured","for","the","directory","service","therefore","unable","issue","referrals","objects","outside","this","forest"],"errorCode":"8406","eventId":"","severity":"Medium","summary":"No superior reference has been configured for the directory service. The directory service is therefore unable to issue referrals to objects outside this forest.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8406; use the surrounding log entries to confirm it.","resolution":"1. Record where 8406 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_MISSING_SUPREF.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8406 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No superior reference has been configured for the directory service. The directory service is therefore unable to issue referrals to objects outside this forest.\n\nLookup forms: 8406, 0x20D6, error 8406, ERROR_DS_MISSING_SUPREF. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): A required subref is missing.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8406"]},{"id":1871,"title":"ERROR_DS_CANT_RETRIEVE_INSTANCE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8407","0x20D7","error 8407","ERROR_DS_CANT_RETRIEVE_INSTANCE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","retrieve","instance","the","type","attribute","could","not","retrieved"],"errorCode":"8407","eventId":"","severity":"Low","summary":"The instance type attribute could not be retrieved.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8407; use the surrounding log entries to confirm it.","resolution":"1. Record where 8407 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_RETRIEVE_INSTANCE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8407 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The instance type attribute could not be retrieved.\n\nLookup forms: 8407, 0x20D7, error 8407, ERROR_DS_CANT_RETRIEVE_INSTANCE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8407"]},{"id":1872,"title":"ERROR_DS_CODE_INCONSISTENCY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8408","0x20D8","error 8408","ERROR_DS_CODE_INCONSISTENCY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","code","inconsistency","internal","has","occurred"],"errorCode":"8408","eventId":"","severity":"Low","summary":"An internal error has occurred.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8408; use the surrounding log entries to confirm it.","resolution":"1. Record where 8408 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CODE_INCONSISTENCY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8408 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An internal error has occurred.\n\nLookup forms: 8408, 0x20D8, error 8408, ERROR_DS_CODE_INCONSISTENCY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8408"]},{"id":1873,"title":"ERROR_DS_DATABASE_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8409","0x20D9","error 8409","ERROR_DS_DATABASE_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","database","has","occurred"],"errorCode":"8409","eventId":"","severity":"Low","summary":"A database error has occurred.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8409; use the surrounding log entries to confirm it.","resolution":"1. Record where 8409 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DATABASE_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8409 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A database error has occurred.\n\nLookup forms: 8409, 0x20D9, error 8409, ERROR_DS_DATABASE_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8409"]},{"id":1874,"title":"ERROR_DS_GOVERNSID_MISSING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8410","0x20DA","error 8410","ERROR_DS_GOVERNSID_MISSING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","governsid","missing","the","attribute"],"errorCode":"8410","eventId":"","severity":"Low","summary":"The attribute GOVERNSID is missing.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8410; use the surrounding log entries to confirm it.","resolution":"1. Record where 8410 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_GOVERNSID_MISSING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8410 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The attribute GOVERNSID is missing.\n\nLookup forms: 8410, 0x20DA, error 8410, ERROR_DS_GOVERNSID_MISSING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8410"]},{"id":1875,"title":"ERROR_DS_MISSING_EXPECTED_ATT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8411","0x20DB","error 8411","ERROR_DS_MISSING_EXPECTED_ATT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","missing","expected","att","attribute"],"errorCode":"8411","eventId":"","severity":"Low","summary":"An expected attribute is missing.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8411; use the surrounding log entries to confirm it.","resolution":"1. Record where 8411 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_MISSING_EXPECTED_ATT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8411 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An expected attribute is missing.\n\nLookup forms: 8411, 0x20DB, error 8411, ERROR_DS_MISSING_EXPECTED_ATT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8411"]},{"id":1876,"title":"ERROR_DS_NCNAME_MISSING_CR_REF","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8412","0x20DC","error 8412","ERROR_DS_NCNAME_MISSING_CR_REF","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ncname","missing","ref","the","specified","naming","context","cross","reference"],"errorCode":"8412","eventId":"","severity":"Low","summary":"The specified naming context is missing a cross reference.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8412; use the surrounding log entries to confirm it.","resolution":"1. Record where 8412 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NCNAME_MISSING_CR_REF.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8412 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified naming context is missing a cross reference.\n\nLookup forms: 8412, 0x20DC, error 8412, ERROR_DS_NCNAME_MISSING_CR_REF. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8412"]},{"id":1877,"title":"ERROR_DS_SECURITY_CHECKING_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8413","0x20DD","error 8413","ERROR_DS_SECURITY_CHECKING_ERROR","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","security","checking","has","occurred"],"errorCode":"8413","eventId":"","severity":"Low","summary":"A security checking error has occurred.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8413; use the surrounding log entries to confirm it.","resolution":"1. Record where 8413 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SECURITY_CHECKING_ERROR.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8413 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A security checking error has occurred.\n\nLookup forms: 8413, 0x20DD, error 8413, ERROR_DS_SECURITY_CHECKING_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8413"]},{"id":1878,"title":"ERROR_DS_SCHEMA_NOT_LOADED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8414","0x20DE","error 8414","ERROR_DS_SCHEMA_NOT_LOADED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","schema","not","loaded","the"],"errorCode":"8414","eventId":"","severity":"Low","summary":"The schema is not loaded.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8414; use the surrounding log entries to confirm it.","resolution":"1. Record where 8414 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SCHEMA_NOT_LOADED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8414 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The schema is not loaded.\n\nLookup forms: 8414, 0x20DE, error 8414, ERROR_DS_SCHEMA_NOT_LOADED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8414"]},{"id":1879,"title":"ERROR_DS_SCHEMA_ALLOC_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8415","0x20DF","error 8415","ERROR_DS_SCHEMA_ALLOC_FAILED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","schema","alloc","failed","allocation","please","check","the","machine","running","low","memory"],"errorCode":"8415","eventId":"","severity":"High","summary":"Schema allocation failed. Please check if the machine is running low on memory.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8415; use the surrounding log entries to confirm it.","resolution":"1. Record where 8415 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SCHEMA_ALLOC_FAILED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8415 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema allocation failed. Please check if the machine is running low on memory.\n\nLookup forms: 8415, 0x20DF, error 8415, ERROR_DS_SCHEMA_ALLOC_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8415"]},{"id":1880,"title":"ERROR_DS_ATT_SCHEMA_REQ_SYNTAX","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8416","0x20E0","error 8416","ERROR_DS_ATT_SCHEMA_REQ_SYNTAX","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","att","schema","req","syntax","failed","obtain","the","required","for","attribute"],"errorCode":"8416","eventId":"","severity":"High","summary":"Failed to obtain the required syntax for the attribute schema.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8416; use the surrounding log entries to confirm it.","resolution":"1. Record where 8416 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_ATT_SCHEMA_REQ_SYNTAX.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8416 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Failed to obtain the required syntax for the attribute schema.\n\nLookup forms: 8416, 0x20E0, error 8416, ERROR_DS_ATT_SCHEMA_REQ_SYNTAX. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8416"]},{"id":1881,"title":"ERROR_DS_GCVERIFY_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8417","0x20E1","error 8417","ERROR_DS_GCVERIFY_ERROR","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","gcverify","the","global","catalog","verification","failed","not","available","does","support","operation","some","part","directory","currently"],"errorCode":"8417","eventId":"","severity":"High","summary":"The global catalog verification failed. The global catalog is not available or does not support the operation. Some part of the directory is currently not available.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8417; use the surrounding log entries to confirm it.","resolution":"1. Record where 8417 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_GCVERIFY_ERROR.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8417 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The global catalog verification failed. The global catalog is not available or does not support the operation. Some part of the directory is currently not available.\n\nLookup forms: 8417, 0x20E1, error 8417, ERROR_DS_GCVERIFY_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8417"]},{"id":1882,"title":"ERROR_DS_DRA_SCHEMA_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8418","0x20E2","error 8418","ERROR_DS_DRA_SCHEMA_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","dra","schema","mismatch","the","replication","operation","failed","because","between","servers","involved"],"errorCode":"8418","eventId":"","severity":"High","summary":"The replication operation failed because of a schema mismatch between the servers involved.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8418; use the surrounding log entries to confirm it.","resolution":"1. Record where 8418 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_SCHEMA_MISMATCH.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8418 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replication operation failed because of a schema mismatch between the servers involved.\n\nLookup forms: 8418, 0x20E2, error 8418, ERROR_DS_DRA_SCHEMA_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8418"]},{"id":1883,"title":"ERROR_DS_CANT_FIND_DSA_OBJ","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8419","0x20E3","error 8419","ERROR_DS_CANT_FIND_DSA_OBJ","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","find","dsa","obj","the","object","could","not","found"],"errorCode":"8419","eventId":"","severity":"Low","summary":"The DSA object could not be found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8419; use the surrounding log entries to confirm it.","resolution":"1. Record where 8419 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_FIND_DSA_OBJ.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8419 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The DSA object could not be found.\n\nLookup forms: 8419, 0x20E3, error 8419, ERROR_DS_CANT_FIND_DSA_OBJ. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8419"]},{"id":1884,"title":"ERROR_DS_CANT_FIND_EXPECTED_NC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8420","0x20E4","error 8420","ERROR_DS_CANT_FIND_EXPECTED_NC","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","find","expected","the","naming","context","could","not","found"],"errorCode":"8420","eventId":"","severity":"Low","summary":"The naming context could not be found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8420; use the surrounding log entries to confirm it.","resolution":"1. Record where 8420 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_FIND_EXPECTED_NC.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8420 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The naming context could not be found.\n\nLookup forms: 8420, 0x20E4, error 8420, ERROR_DS_CANT_FIND_EXPECTED_NC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8420"]},{"id":1885,"title":"ERROR_DS_CANT_FIND_NC_IN_CACHE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8421","0x20E5","error 8421","ERROR_DS_CANT_FIND_NC_IN_CACHE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","find","cache","the","naming","context","could","not","found"],"errorCode":"8421","eventId":"","severity":"Low","summary":"The naming context could not be found in the cache.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8421; use the surrounding log entries to confirm it.","resolution":"1. Record where 8421 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_FIND_NC_IN_CACHE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8421 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The naming context could not be found in the cache.\n\nLookup forms: 8421, 0x20E5, error 8421, ERROR_DS_CANT_FIND_NC_IN_CACHE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8421"]},{"id":1886,"title":"ERROR_DS_CANT_RETRIEVE_CHILD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8422","0x20E6","error 8422","ERROR_DS_CANT_RETRIEVE_CHILD","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","retrieve","child","the","object","could","not","retrieved"],"errorCode":"8422","eventId":"","severity":"Low","summary":"The child object could not be retrieved.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8422; use the surrounding log entries to confirm it.","resolution":"1. Record where 8422 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_RETRIEVE_CHILD.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8422 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The child object could not be retrieved.\n\nLookup forms: 8422, 0x20E6, error 8422, ERROR_DS_CANT_RETRIEVE_CHILD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8422"]},{"id":1887,"title":"ERROR_DS_SECURITY_ILLEGAL_MODIFY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8423","0x20E7","error 8423","ERROR_DS_SECURITY_ILLEGAL_MODIFY","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","security","illegal","modify","the","modification","was","not","permitted","for","reasons"],"errorCode":"8423","eventId":"","severity":"Low","summary":"The modification was not permitted for security reasons.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8423; use the surrounding log entries to confirm it.","resolution":"1. Record where 8423 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SECURITY_ILLEGAL_MODIFY.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8423 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The modification was not permitted for security reasons.\n\nLookup forms: 8423, 0x20E7, error 8423, ERROR_DS_SECURITY_ILLEGAL_MODIFY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8423"]},{"id":1888,"title":"ERROR_DS_CANT_REPLACE_HIDDEN_REC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8424","0x20E8","error 8424","ERROR_DS_CANT_REPLACE_HIDDEN_REC","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","replace","hidden","rec","the","operation","cannot","record"],"errorCode":"8424","eventId":"","severity":"Medium","summary":"The operation cannot replace the hidden record.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8424; use the surrounding log entries to confirm it.","resolution":"1. Record where 8424 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_REPLACE_HIDDEN_REC.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8424 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation cannot replace the hidden record.\n\nLookup forms: 8424, 0x20E8, error 8424, ERROR_DS_CANT_REPLACE_HIDDEN_REC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8424"]},{"id":1889,"title":"ERROR_DS_BAD_HIERARCHY_FILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8425","0x20E9","error 8425","ERROR_DS_BAD_HIERARCHY_FILE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","bad","hierarchy","file","the","invalid"],"errorCode":"8425","eventId":"","severity":"Medium","summary":"The hierarchy file is invalid.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8425; use the surrounding log entries to confirm it.","resolution":"1. Record where 8425 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_BAD_HIERARCHY_FILE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8425 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The hierarchy file is invalid.\n\nLookup forms: 8425, 0x20E9, error 8425, ERROR_DS_BAD_HIERARCHY_FILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8425"]},{"id":1890,"title":"ERROR_DS_BUILD_HIERARCHY_TABLE_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8426","0x20EA","error 8426","ERROR_DS_BUILD_HIERARCHY_TABLE_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","build","hierarchy","table","failed","the","attempt"],"errorCode":"8426","eventId":"","severity":"High","summary":"The attempt to build the hierarchy table failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8426; use the surrounding log entries to confirm it.","resolution":"1. Record where 8426 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_BUILD_HIERARCHY_TABLE_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8426 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The attempt to build the hierarchy table failed.\n\nLookup forms: 8426, 0x20EA, error 8426, ERROR_DS_BUILD_HIERARCHY_TABLE_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8426"]},{"id":1891,"title":"ERROR_DS_CONFIG_PARAM_MISSING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8427","0x20EB","error 8427","ERROR_DS_CONFIG_PARAM_MISSING","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","config","param","missing","the","directory","configuration","parameter","from","registry"],"errorCode":"8427","eventId":"","severity":"Low","summary":"The directory configuration parameter is missing from the registry.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8427; use the surrounding log entries to confirm it.","resolution":"1. Record where 8427 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CONFIG_PARAM_MISSING.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8427 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory configuration parameter is missing from the registry.\n\nLookup forms: 8427, 0x20EB, error 8427, ERROR_DS_CONFIG_PARAM_MISSING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8427"]},{"id":1892,"title":"ERROR_DS_COUNTING_AB_INDICES_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8428","0x20EC","error 8428","ERROR_DS_COUNTING_AB_INDICES_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","counting","indices","failed","the","attempt","count","address","book"],"errorCode":"8428","eventId":"","severity":"High","summary":"The attempt to count the address book indices failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8428; use the surrounding log entries to confirm it.","resolution":"1. Record where 8428 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_COUNTING_AB_INDICES_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8428 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The attempt to count the address book indices failed.\n\nLookup forms: 8428, 0x20EC, error 8428, ERROR_DS_COUNTING_AB_INDICES_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8428"]},{"id":1893,"title":"ERROR_DS_HIERARCHY_TABLE_MALLOC_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8429","0x20ED","error 8429","ERROR_DS_HIERARCHY_TABLE_MALLOC_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","hierarchy","table","malloc","failed","the","allocation"],"errorCode":"8429","eventId":"","severity":"High","summary":"The allocation of the hierarchy table failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8429; use the surrounding log entries to confirm it.","resolution":"1. Record where 8429 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_HIERARCHY_TABLE_MALLOC_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8429 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The allocation of the hierarchy table failed.\n\nLookup forms: 8429, 0x20ED, error 8429, ERROR_DS_HIERARCHY_TABLE_MALLOC_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8429"]},{"id":1894,"title":"ERROR_DS_INTERNAL_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8430","0x20EE","error 8430","ERROR_DS_INTERNAL_FAILURE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","internal","failure","the","directory","service","encountered"],"errorCode":"8430","eventId":"","severity":"High","summary":"The directory service encountered an internal failure.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8430; use the surrounding log entries to confirm it.","resolution":"1. Record where 8430 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_INTERNAL_FAILURE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8430 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service encountered an internal failure.\n\nLookup forms: 8430, 0x20EE, error 8430, ERROR_DS_INTERNAL_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8430"]},{"id":1895,"title":"ERROR_DS_UNKNOWN_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8431","0x20EF","error 8431","ERROR_DS_UNKNOWN_ERROR","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","unknown","the","directory","service","encountered","failure"],"errorCode":"8431","eventId":"","severity":"High","summary":"The directory service encountered an unknown failure.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8431; use the surrounding log entries to confirm it.","resolution":"1. Record where 8431 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_UNKNOWN_ERROR.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8431 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service encountered an unknown failure.\n\nLookup forms: 8431, 0x20EF, error 8431, ERROR_DS_UNKNOWN_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8431"]},{"id":1896,"title":"ERROR_DS_ROOT_REQUIRES_CLASS_TOP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8432","0x20F0","error 8432","ERROR_DS_ROOT_REQUIRES_CLASS_TOP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","root","requires","class","top","object"],"errorCode":"8432","eventId":"","severity":"Low","summary":"A root object requires a class of 'top'.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8432; use the surrounding log entries to confirm it.","resolution":"1. Record where 8432 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_ROOT_REQUIRES_CLASS_TOP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8432 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A root object requires a class of 'top'.\n\nLookup forms: 8432, 0x20F0, error 8432, ERROR_DS_ROOT_REQUIRES_CLASS_TOP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8432"]},{"id":1897,"title":"ERROR_DS_REFUSING_FSMO_ROLES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8433","0x20F1","error 8433","ERROR_DS_REFUSING_FSMO_ROLES","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","refusing","fsmo","roles","this","directory","server","shutting","down","and","cannot","take","ownership","new","floating","single","master","operation"],"errorCode":"8433","eventId":"","severity":"Medium","summary":"This directory server is shutting down, and cannot take ownership of new floating single-master operation roles.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8433; use the surrounding log entries to confirm it.","resolution":"1. Record where 8433 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_REFUSING_FSMO_ROLES.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8433 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This directory server is shutting down, and cannot take ownership of new floating single-master operation roles.\n\nLookup forms: 8433, 0x20F1, error 8433, ERROR_DS_REFUSING_FSMO_ROLES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8433"]},{"id":1898,"title":"ERROR_DS_MISSING_FSMO_SETTINGS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8434","0x20F2","error 8434","ERROR_DS_MISSING_FSMO_SETTINGS","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","missing","fsmo","settings","the","directory","service","mandatory","configuration","information","and","unable","determine","ownership","floating","single","master","operation","roles"],"errorCode":"8434","eventId":"","severity":"Medium","summary":"The directory service is missing mandatory configuration information, and is unable to determine the ownership of floating single-master operation roles.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8434; use the surrounding log entries to confirm it.","resolution":"1. Record where 8434 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_MISSING_FSMO_SETTINGS.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8434 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service is missing mandatory configuration information, and is unable to determine the ownership of floating single-master operation roles.\n\nLookup forms: 8434, 0x20F2, error 8434, ERROR_DS_MISSING_FSMO_SETTINGS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8434"]},{"id":1899,"title":"ERROR_DS_UNABLE_TO_SURRENDER_ROLES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8435","0x20F3","error 8435","ERROR_DS_UNABLE_TO_SURRENDER_ROLES","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","unable","surrender","roles","the","directory","service","was","transfer","ownership","one","more","floating","single","master","operation","other","servers"],"errorCode":"8435","eventId":"","severity":"Medium","summary":"The directory service was unable to transfer ownership of one or more floating single-master operation roles to other servers.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8435; use the surrounding log entries to confirm it.","resolution":"1. Record where 8435 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Verify the required service or agent is installed, running, and current; repair the component if needed.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_UNABLE_TO_SURRENDER_ROLES.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8435 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service was unable to transfer ownership of one or more floating single-master operation roles to other servers.\n\nLookup forms: 8435, 0x20F3, error 8435, ERROR_DS_UNABLE_TO_SURRENDER_ROLES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8435"]},{"id":1900,"title":"ERROR_DS_DRA_GENERIC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8436","0x20F4","error 8436","ERROR_DS_DRA_GENERIC","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dra","generic","the","replication","operation","failed"],"errorCode":"8436","eventId":"","severity":"High","summary":"The replication operation failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8436; use the surrounding log entries to confirm it.","resolution":"1. Record where 8436 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_GENERIC.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8436 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replication operation failed.\n\nLookup forms: 8436, 0x20F4, error 8436, ERROR_DS_DRA_GENERIC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8436"]},{"id":1901,"title":"ERROR_DS_DRA_INVALID_PARAMETER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8437","0x20F5","error 8437","ERROR_DS_DRA_INVALID_PARAMETER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dra","invalid","parameter","was","specified","for","this","replication","operation"],"errorCode":"8437","eventId":"","severity":"Medium","summary":"An invalid parameter was specified for this replication operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8437; use the surrounding log entries to confirm it.","resolution":"1. Record where 8437 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_INVALID_PARAMETER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8437 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An invalid parameter was specified for this replication operation.\n\nLookup forms: 8437, 0x20F5, error 8437, ERROR_DS_DRA_INVALID_PARAMETER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8437"]},{"id":1902,"title":"ERROR_DS_DRA_BUSY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8438","0x20F6","error 8438","ERROR_DS_DRA_BUSY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","dra","busy","the","directory","service","too","complete","replication","operation","this","time"],"errorCode":"8438","eventId":"","severity":"Medium","summary":"The directory service is too busy to complete the replication operation at this time.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8438; use the surrounding log entries to confirm it.","resolution":"1. Record where 8438 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_BUSY.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8438 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service is too busy to complete the replication operation at this time.\n\nLookup forms: 8438, 0x20F6, error 8438, ERROR_DS_DRA_BUSY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8438"]},{"id":1903,"title":"ERROR_DS_DRA_BAD_DN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8439","0x20F7","error 8439","ERROR_DS_DRA_BAD_DN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dra","bad","the","distinguished","name","specified","for","this","replication","operation","invalid"],"errorCode":"8439","eventId":"","severity":"Medium","summary":"The distinguished name specified for this replication operation is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8439; use the surrounding log entries to confirm it.","resolution":"1. Record where 8439 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_BAD_DN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8439 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The distinguished name specified for this replication operation is invalid.\n\nLookup forms: 8439, 0x20F7, error 8439, ERROR_DS_DRA_BAD_DN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8439"]},{"id":1904,"title":"ERROR_DS_DRA_BAD_NC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8440","0x20F8","error 8440","ERROR_DS_DRA_BAD_NC","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dra","bad","the","naming","context","specified","for","this","replication","operation","invalid"],"errorCode":"8440","eventId":"","severity":"Medium","summary":"The naming context specified for this replication operation is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8440; use the surrounding log entries to confirm it.","resolution":"1. Record where 8440 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_BAD_NC.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8440 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The naming context specified for this replication operation is invalid.\n\nLookup forms: 8440, 0x20F8, error 8440, ERROR_DS_DRA_BAD_NC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8440"]},{"id":1905,"title":"ERROR_DS_DRA_DN_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8441","0x20F9","error 8441","ERROR_DS_DRA_DN_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dra","exists","the","distinguished","name","specified","for","this","replication","operation","already"],"errorCode":"8441","eventId":"","severity":"Medium","summary":"The distinguished name specified for this replication operation already exists.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8441; use the surrounding log entries to confirm it.","resolution":"1. Record where 8441 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_DN_EXISTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8441 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The distinguished name specified for this replication operation already exists.\n\nLookup forms: 8441, 0x20F9, error 8441, ERROR_DS_DRA_DN_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8441"]},{"id":1906,"title":"ERROR_DS_DRA_INTERNAL_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8442","0x20FA","error 8442","ERROR_DS_DRA_INTERNAL_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dra","internal","the","replication","system","encountered"],"errorCode":"8442","eventId":"","severity":"Low","summary":"The replication system encountered an internal error.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8442; use the surrounding log entries to confirm it.","resolution":"1. Record where 8442 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_INTERNAL_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8442 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replication system encountered an internal error.\n\nLookup forms: 8442, 0x20FA, error 8442, ERROR_DS_DRA_INTERNAL_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8442"]},{"id":1907,"title":"ERROR_DS_DRA_INCONSISTENT_DIT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8443","0x20FB","error 8443","ERROR_DS_DRA_INCONSISTENT_DIT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dra","inconsistent","dit","the","replication","operation","encountered","database","inconsistency"],"errorCode":"8443","eventId":"","severity":"Low","summary":"The replication operation encountered a database inconsistency.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8443; use the surrounding log entries to confirm it.","resolution":"1. Record where 8443 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_INCONSISTENT_DIT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8443 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replication operation encountered a database inconsistency.\n\nLookup forms: 8443, 0x20FB, error 8443, ERROR_DS_DRA_INCONSISTENT_DIT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8443"]},{"id":1908,"title":"ERROR_DS_DRA_CONNECTION_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8444","0x20FC","error 8444","ERROR_DS_DRA_CONNECTION_FAILED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","dra","connection","failed","the","server","specified","for","this","replication","operation","could","not","contacted"],"errorCode":"8444","eventId":"","severity":"Low","summary":"The server specified for this replication operation could not be contacted.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8444; use the surrounding log entries to confirm it.","resolution":"1. Record where 8444 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_CONNECTION_FAILED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8444 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The server specified for this replication operation could not be contacted.\n\nLookup forms: 8444, 0x20FC, error 8444, ERROR_DS_DRA_CONNECTION_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8444"]},{"id":1909,"title":"ERROR_DS_DRA_BAD_INSTANCE_TYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8445","0x20FD","error 8445","ERROR_DS_DRA_BAD_INSTANCE_TYPE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dra","bad","instance","type","the","replication","operation","encountered","object","with","invalid"],"errorCode":"8445","eventId":"","severity":"Medium","summary":"The replication operation encountered an object with an invalid instance type.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8445; use the surrounding log entries to confirm it.","resolution":"1. Record where 8445 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_BAD_INSTANCE_TYPE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8445 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replication operation encountered an object with an invalid instance type.\n\nLookup forms: 8445, 0x20FD, error 8445, ERROR_DS_DRA_BAD_INSTANCE_TYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8445"]},{"id":1910,"title":"ERROR_DS_DRA_OUT_OF_MEM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8446","0x20FE","error 8446","ERROR_DS_DRA_OUT_OF_MEM","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","dra","out","mem","the","replication","operation","failed","allocate","memory"],"errorCode":"8446","eventId":"","severity":"High","summary":"The replication operation failed to allocate memory.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8446; use the surrounding log entries to confirm it.","resolution":"1. Record where 8446 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_OUT_OF_MEM.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8446 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replication operation failed to allocate memory.\n\nLookup forms: 8446, 0x20FE, error 8446, ERROR_DS_DRA_OUT_OF_MEM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8446"]},{"id":1911,"title":"ERROR_DS_DRA_MAIL_PROBLEM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8447","0x20FF","error 8447","ERROR_DS_DRA_MAIL_PROBLEM","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dra","mail","problem","the","replication","operation","encountered","with","system"],"errorCode":"8447","eventId":"","severity":"Low","summary":"The replication operation encountered an error with the mail system.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8447; use the surrounding log entries to confirm it.","resolution":"1. Record where 8447 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_MAIL_PROBLEM.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8447 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replication operation encountered an error with the mail system.\n\nLookup forms: 8447, 0x20FF, error 8447, ERROR_DS_DRA_MAIL_PROBLEM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8447"]},{"id":1912,"title":"ERROR_DS_DRA_REF_ALREADY_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8448","0x2100","error 8448","ERROR_DS_DRA_REF_ALREADY_EXISTS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","dra","ref","already","exists","the","replication","reference","information","for","target","server"],"errorCode":"8448","eventId":"","severity":"Medium","summary":"The replication reference information for the target server already exists.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8448; use the surrounding log entries to confirm it.","resolution":"1. Record where 8448 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_REF_ALREADY_EXISTS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8448 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replication reference information for the target server already exists.\n\nLookup forms: 8448, 0x2100, error 8448, ERROR_DS_DRA_REF_ALREADY_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8448"]},{"id":1913,"title":"ERROR_DS_DRA_REF_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8449","0x2101","error 8449","ERROR_DS_DRA_REF_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","dra","ref","not","found","the","replication","reference","information","for","target","server","does","exist"],"errorCode":"8449","eventId":"","severity":"Low","summary":"The replication reference information for the target server does not exist.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8449; use the surrounding log entries to confirm it.","resolution":"1. Record where 8449 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_REF_NOT_FOUND.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8449 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replication reference information for the target server does not exist.\n\nLookup forms: 8449, 0x2101, error 8449, ERROR_DS_DRA_REF_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8449"]},{"id":1914,"title":"ERROR_DS_DRA_OBJ_IS_REP_SOURCE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8450","0x2102","error 8450","ERROR_DS_DRA_OBJ_IS_REP_SOURCE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","dra","obj","rep","source","the","naming","context","cannot","removed","because","replicated","another","server"],"errorCode":"8450","eventId":"","severity":"Medium","summary":"The naming context cannot be removed because it is replicated to another server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8450; use the surrounding log entries to confirm it.","resolution":"1. Record where 8450 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_OBJ_IS_REP_SOURCE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8450 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The naming context cannot be removed because it is replicated to another server.\n\nLookup forms: 8450, 0x2102, error 8450, ERROR_DS_DRA_OBJ_IS_REP_SOURCE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8450"]},{"id":1915,"title":"ERROR_DS_DRA_DB_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8451","0x2103","error 8451","ERROR_DS_DRA_DB_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dra","the","replication","operation","encountered","database"],"errorCode":"8451","eventId":"","severity":"Low","summary":"The replication operation encountered a database error.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8451; use the surrounding log entries to confirm it.","resolution":"1. Record where 8451 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_DB_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8451 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replication operation encountered a database error.\n\nLookup forms: 8451, 0x2103, error 8451, ERROR_DS_DRA_DB_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8451"]},{"id":1916,"title":"ERROR_DS_DRA_NO_REPLICA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8452","0x2104","error 8452","ERROR_DS_DRA_NO_REPLICA","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","dra","replica","the","naming","context","process","being","removed","not","replicated","from","specified","server"],"errorCode":"8452","eventId":"","severity":"Low","summary":"The naming context is in the process of being removed or is not replicated from the specified server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8452; use the surrounding log entries to confirm it.","resolution":"1. Record where 8452 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_NO_REPLICA.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8452 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The naming context is in the process of being removed or is not replicated from the specified server.\n\nLookup forms: 8452, 0x2104, error 8452, ERROR_DS_DRA_NO_REPLICA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8452"]},{"id":1917,"title":"ERROR_DS_DRA_ACCESS_DENIED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8453","0x2105","error 8453","ERROR_DS_DRA_ACCESS_DENIED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","dra","access","denied","replication","was"],"errorCode":"8453","eventId":"","severity":"Low","summary":"Replication access was denied.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8453; use the surrounding log entries to confirm it.","resolution":"1. Record where 8453 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_ACCESS_DENIED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8453 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Replication access was denied.\n\nLookup forms: 8453, 0x2105, error 8453, ERROR_DS_DRA_ACCESS_DENIED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8453"]},{"id":1918,"title":"ERROR_DS_DRA_NOT_SUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8454","0x2106","error 8454","ERROR_DS_DRA_NOT_SUPPORTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","dra","not","supported","the","requested","operation","this","version","directory","service"],"errorCode":"8454","eventId":"","severity":"Medium","summary":"The requested operation is not supported by this version of the directory service.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8454; use the surrounding log entries to confirm it.","resolution":"1. Record where 8454 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_NOT_SUPPORTED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8454 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested operation is not supported by this version of the directory service.\n\nLookup forms: 8454, 0x2106, error 8454, ERROR_DS_DRA_NOT_SUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8454"]},{"id":1919,"title":"ERROR_DS_DRA_RPC_CANCELLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8455","0x2107","error 8455","ERROR_DS_DRA_RPC_CANCELLED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dra","rpc","cancelled","the","replication","remote","procedure","call","was"],"errorCode":"8455","eventId":"","severity":"Low","summary":"The replication remote procedure call was cancelled.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8455; use the surrounding log entries to confirm it.","resolution":"1. Record where 8455 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_RPC_CANCELLED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8455 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replication remote procedure call was cancelled.\n\nLookup forms: 8455, 0x2107, error 8455, ERROR_DS_DRA_RPC_CANCELLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8455"]},{"id":1920,"title":"ERROR_DS_DRA_SOURCE_DISABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8456","0x2108","error 8456","ERROR_DS_DRA_SOURCE_DISABLED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","dra","source","disabled","the","server","currently","rejecting","replication","requests"],"errorCode":"8456","eventId":"","severity":"Low","summary":"The source server is currently rejecting replication requests.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8456; use the surrounding log entries to confirm it.","resolution":"1. Record where 8456 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_SOURCE_DISABLED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8456 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The source server is currently rejecting replication requests.\n\nLookup forms: 8456, 0x2108, error 8456, ERROR_DS_DRA_SOURCE_DISABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8456"]},{"id":1921,"title":"ERROR_DS_DRA_SINK_DISABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8457","0x2109","error 8457","ERROR_DS_DRA_SINK_DISABLED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","dra","sink","disabled","the","destination","server","currently","rejecting","replication","requests"],"errorCode":"8457","eventId":"","severity":"Low","summary":"The destination server is currently rejecting replication requests.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8457; use the surrounding log entries to confirm it.","resolution":"1. Record where 8457 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_SINK_DISABLED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8457 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The destination server is currently rejecting replication requests.\n\nLookup forms: 8457, 0x2109, error 8457, ERROR_DS_DRA_SINK_DISABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8457"]},{"id":1922,"title":"ERROR_DS_DRA_NAME_COLLISION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8458","0x210A","error 8458","ERROR_DS_DRA_NAME_COLLISION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dra","name","collision","the","replication","operation","failed","due","object","names"],"errorCode":"8458","eventId":"","severity":"High","summary":"The replication operation failed due to a collision of object names.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8458; use the surrounding log entries to confirm it.","resolution":"1. Record where 8458 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_NAME_COLLISION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8458 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replication operation failed due to a collision of object names.\n\nLookup forms: 8458, 0x210A, error 8458, ERROR_DS_DRA_NAME_COLLISION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8458"]},{"id":1923,"title":"ERROR_DS_DRA_SOURCE_REINSTALLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8459","0x210B","error 8459","ERROR_DS_DRA_SOURCE_REINSTALLED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","dra","source","reinstalled","the","replication","has","been"],"errorCode":"8459","eventId":"","severity":"Low","summary":"The replication source has been reinstalled.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 8459; use the surrounding log entries to confirm it.","resolution":"1. Record where 8459 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_SOURCE_REINSTALLED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8459 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replication source has been reinstalled.\n\nLookup forms: 8459, 0x210B, error 8459, ERROR_DS_DRA_SOURCE_REINSTALLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8459"]},{"id":1924,"title":"ERROR_DS_DRA_MISSING_PARENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8460","0x210C","error 8460","ERROR_DS_DRA_MISSING_PARENT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dra","missing","parent","the","replication","operation","failed","because","required","object"],"errorCode":"8460","eventId":"","severity":"High","summary":"The replication operation failed because a required parent object is missing.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8460; use the surrounding log entries to confirm it.","resolution":"1. Record where 8460 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_MISSING_PARENT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8460 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replication operation failed because a required parent object is missing.\n\nLookup forms: 8460, 0x210C, error 8460, ERROR_DS_DRA_MISSING_PARENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8460"]},{"id":1925,"title":"ERROR_DS_DRA_PREEMPTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8461","0x210D","error 8461","ERROR_DS_DRA_PREEMPTED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dra","preempted","the","replication","operation","was"],"errorCode":"8461","eventId":"","severity":"Low","summary":"The replication operation was preempted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8461; use the surrounding log entries to confirm it.","resolution":"1. Record where 8461 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_PREEMPTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8461 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replication operation was preempted.\n\nLookup forms: 8461, 0x210D, error 8461, ERROR_DS_DRA_PREEMPTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8461"]},{"id":1926,"title":"ERROR_DS_DRA_ABANDON_SYNC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8462","0x210E","error 8462","ERROR_DS_DRA_ABANDON_SYNC","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","dra","abandon","sync","the","replication","synchronization","attempt","was","abandoned","because","lack","updates"],"errorCode":"8462","eventId":"","severity":"Low","summary":"The replication synchronization attempt was abandoned because of a lack of updates.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 8462; use the surrounding log entries to confirm it.","resolution":"1. Record where 8462 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_ABANDON_SYNC.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8462 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replication synchronization attempt was abandoned because of a lack of updates.\n\nLookup forms: 8462, 0x210E, error 8462, ERROR_DS_DRA_ABANDON_SYNC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8462"]},{"id":1927,"title":"ERROR_DS_DRA_SHUTDOWN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8463","0x210F","error 8463","ERROR_DS_DRA_SHUTDOWN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dra","shutdown","the","replication","operation","was","terminated","because","system","shutting","down"],"errorCode":"8463","eventId":"","severity":"Low","summary":"The replication operation was terminated because the system is shutting down.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8463; use the surrounding log entries to confirm it.","resolution":"1. Record where 8463 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_SHUTDOWN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8463 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replication operation was terminated because the system is shutting down.\n\nLookup forms: 8463, 0x210F, error 8463, ERROR_DS_DRA_SHUTDOWN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8463"]},{"id":1928,"title":"ERROR_DS_DRA_INCOMPATIBLE_PARTIAL_SET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8464","0x2110","error 8464","ERROR_DS_DRA_INCOMPATIBLE_PARTIAL_SET","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dra","incompatible","partial","set","synchronization","attempt","failed","because","the","destination","currently","waiting","synchronize","new","attributes","from","source","this","condition","normal","recent","schema","change","modified"],"errorCode":"8464","eventId":"","severity":"High","summary":"Synchronization attempt failed because the destination DC is currently waiting to synchronize new partial attributes from source. This condition is normal if a recent schema change modified the partial attribute set. The destination partial attribute set is not a subset of source partial attribute set.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8464; use the surrounding log entries to confirm it.","resolution":"1. Record where 8464 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_INCOMPATIBLE_PARTIAL_SET.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8464 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Synchronization attempt failed because the destination DC is currently waiting to synchronize new partial attributes from source. This condition is normal if a recent schema change modified the partial attribute set. The destination partial attribute set is not a subset of source partial attribute set.\n\nLookup forms: 8464, 0x2110, error 8464, ERROR_DS_DRA_INCOMPATIBLE_PARTIAL_SET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The replication synchronization attempt failed as the destination partial attribute set is not a subset of source partial attribute set.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8464"]},{"id":1929,"title":"ERROR_DS_DRA_SOURCE_IS_PARTIAL_REPLICA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8465","0x2111","error 8465","ERROR_DS_DRA_SOURCE_IS_PARTIAL_REPLICA","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dra","source","partial","replica","the","replication","synchronization","attempt","failed","because","master","attempted","sync","from"],"errorCode":"8465","eventId":"","severity":"High","summary":"The replication synchronization attempt failed because a master replica attempted to sync from a partial replica.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8465; use the surrounding log entries to confirm it.","resolution":"1. Record where 8465 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_SOURCE_IS_PARTIAL_REPLICA.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8465 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replication synchronization attempt failed because a master replica attempted to sync from a partial replica.\n\nLookup forms: 8465, 0x2111, error 8465, ERROR_DS_DRA_SOURCE_IS_PARTIAL_REPLICA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8465"]},{"id":1930,"title":"ERROR_DS_DRA_EXTN_CONNECTION_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8466","0x2112","error 8466","ERROR_DS_DRA_EXTN_CONNECTION_FAILED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","dra","extn","connection","failed","the","server","specified","for","this","replication","operation","was","contacted","but","that","unable","contact","additional","needed","complete"],"errorCode":"8466","eventId":"","severity":"Medium","summary":"The server specified for this replication operation was contacted, but that server was unable to contact an additional server needed to complete the operation.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8466; use the surrounding log entries to confirm it.","resolution":"1. Record where 8466 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_EXTN_CONNECTION_FAILED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8466 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The server specified for this replication operation was contacted, but that server was unable to contact an additional server needed to complete the operation.\n\nLookup forms: 8466, 0x2112, error 8466, ERROR_DS_DRA_EXTN_CONNECTION_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8466"]},{"id":1931,"title":"ERROR_DS_INSTALL_SCHEMA_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8467","0x2113","error 8467","ERROR_DS_INSTALL_SCHEMA_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","install","schema","mismatch","the","version","directory","service","source","forest","not","compatible","with","this","computer"],"errorCode":"8467","eventId":"","severity":"Low","summary":"The version of the directory service schema of the source forest is not compatible with the version of directory service on this computer.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8467; use the surrounding log entries to confirm it.","resolution":"1. Record where 8467 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_INSTALL_SCHEMA_MISMATCH.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8467 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The version of the directory service schema of the source forest is not compatible with the version of directory service on this computer.\n\nLookup forms: 8467, 0x2113, error 8467, ERROR_DS_INSTALL_SCHEMA_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The version of the Active Directory schema of the source forest is not compatible with the version of Active Directory on this computer. You must upgrade the operating system on a domain controller in the source forest before this computer can be added as a domain controller to that forest.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8467"]},{"id":1932,"title":"ERROR_DS_DUP_LINK_ID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8468","0x2114","error 8468","ERROR_DS_DUP_LINK_ID","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","dup","link","schema","update","failed","attribute","with","the","same","identifier","already","exists"],"errorCode":"8468","eventId":"","severity":"High","summary":"Schema update failed: An attribute with the same link identifier already exists.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 8468; use the surrounding log entries to confirm it.","resolution":"1. Record where 8468 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DUP_LINK_ID.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8468 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema update failed: An attribute with the same link identifier already exists.\n\nLookup forms: 8468, 0x2114, error 8468, ERROR_DS_DUP_LINK_ID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8468"]},{"id":1933,"title":"ERROR_DS_NAME_ERROR_RESOLVING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8469","0x2115","error 8469","ERROR_DS_NAME_ERROR_RESOLVING","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","name","resolving","translation","generic","processing"],"errorCode":"8469","eventId":"","severity":"Low","summary":"Name translation: Generic processing error.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 8469; use the surrounding log entries to confirm it.","resolution":"1. Record where 8469 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NAME_ERROR_RESOLVING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8469 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Name translation: Generic processing error.\n\nLookup forms: 8469, 0x2115, error 8469, ERROR_DS_NAME_ERROR_RESOLVING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8469"]},{"id":1934,"title":"ERROR_DS_NAME_ERROR_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8470","0x2116","error 8470","ERROR_DS_NAME_ERROR_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","name","not","found","translation","could","find","the","insufficient","right","see"],"errorCode":"8470","eventId":"","severity":"Low","summary":"Name translation: Could not find the name or insufficient right to see name.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8470; use the surrounding log entries to confirm it.","resolution":"1. Record where 8470 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NAME_ERROR_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8470 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Name translation: Could not find the name or insufficient right to see name.\n\nLookup forms: 8470, 0x2116, error 8470, ERROR_DS_NAME_ERROR_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8470"]},{"id":1935,"title":"ERROR_DS_NAME_ERROR_NOT_UNIQUE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8471","0x2117","error 8471","ERROR_DS_NAME_ERROR_NOT_UNIQUE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","name","not","unique","translation","input","mapped","more","than","one","output"],"errorCode":"8471","eventId":"","severity":"Low","summary":"Name translation: Input name mapped to more than one output name.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8471; use the surrounding log entries to confirm it.","resolution":"1. Record where 8471 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NAME_ERROR_NOT_UNIQUE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8471 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Name translation: Input name mapped to more than one output name.\n\nLookup forms: 8471, 0x2117, error 8471, ERROR_DS_NAME_ERROR_NOT_UNIQUE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8471"]},{"id":1936,"title":"ERROR_DS_NAME_ERROR_NO_MAPPING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8472","0x2118","error 8472","ERROR_DS_NAME_ERROR_NO_MAPPING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","name","mapping","translation","input","found","but","not","the","associated","output","format"],"errorCode":"8472","eventId":"","severity":"Low","summary":"Name translation: Input name found, but not the associated output format.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8472; use the surrounding log entries to confirm it.","resolution":"1. Record where 8472 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NAME_ERROR_NO_MAPPING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8472 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Name translation: Input name found, but not the associated output format.\n\nLookup forms: 8472, 0x2118, error 8472, ERROR_DS_NAME_ERROR_NO_MAPPING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8472"]},{"id":1937,"title":"ERROR_DS_NAME_ERROR_DOMAIN_ONLY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8473","0x2119","error 8473","ERROR_DS_NAME_ERROR_DOMAIN_ONLY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","name","domain","only","translation","unable","resolve","completely","the","was","found"],"errorCode":"8473","eventId":"","severity":"Medium","summary":"Name translation: Unable to resolve completely, only the domain was found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8473; use the surrounding log entries to confirm it.","resolution":"1. Record where 8473 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NAME_ERROR_DOMAIN_ONLY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8473 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Name translation: Unable to resolve completely, only the domain was found.\n\nLookup forms: 8473, 0x2119, error 8473, ERROR_DS_NAME_ERROR_DOMAIN_ONLY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8473"]},{"id":1938,"title":"ERROR_DS_NAME_ERROR_NO_SYNTACTICAL_MAPPING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8474","0x211A","error 8474","ERROR_DS_NAME_ERROR_NO_SYNTACTICAL_MAPPING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","name","syntactical","mapping","translation","unable","perform","purely","the","client","without","going","out","wire"],"errorCode":"8474","eventId":"","severity":"Medium","summary":"Name translation: Unable to perform purely syntactical mapping at the client without going out to the wire.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8474; use the surrounding log entries to confirm it.","resolution":"1. Record where 8474 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NAME_ERROR_NO_SYNTACTICAL_MAPPING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8474 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Name translation: Unable to perform purely syntactical mapping at the client without going out to the wire.\n\nLookup forms: 8474, 0x211A, error 8474, ERROR_DS_NAME_ERROR_NO_SYNTACTICAL_MAPPING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8474"]},{"id":1939,"title":"ERROR_DS_CONSTRUCTED_ATT_MOD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8475","0x211B","error 8475","ERROR_DS_CONSTRUCTED_ATT_MOD","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","constructed","att","mod","modification","attribute","not","allowed"],"errorCode":"8475","eventId":"","severity":"Low","summary":"Modification of a constructed attribute is not allowed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8475; use the surrounding log entries to confirm it.","resolution":"1. Record where 8475 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CONSTRUCTED_ATT_MOD.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8475 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Modification of a constructed attribute is not allowed.\n\nLookup forms: 8475, 0x211B, error 8475, ERROR_DS_CONSTRUCTED_ATT_MOD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Modification of a constructed att is not allowed.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8475"]},{"id":1940,"title":"ERROR_DS_WRONG_OM_OBJ_CLASS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8476","0x211C","error 8476","ERROR_DS_WRONG_OM_OBJ_CLASS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wrong","obj","class","the","object","specified","incorrect","for","attribute","with","syntax"],"errorCode":"8476","eventId":"","severity":"Low","summary":"The OM-Object-Class specified is incorrect for an attribute with the specified syntax.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8476; use the surrounding log entries to confirm it.","resolution":"1. Record where 8476 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_WRONG_OM_OBJ_CLASS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8476 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The OM-Object-Class specified is incorrect for an attribute with the specified syntax.\n\nLookup forms: 8476, 0x211C, error 8476, ERROR_DS_WRONG_OM_OBJ_CLASS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8476"]},{"id":1941,"title":"ERROR_DS_DRA_REPL_PENDING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8477","0x211D","error 8477","ERROR_DS_DRA_REPL_PENDING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dra","repl","pending","the","replication","request","has","been","posted","waiting","for","reply"],"errorCode":"8477","eventId":"","severity":"Low","summary":"The replication request has been posted; waiting for reply.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8477; use the surrounding log entries to confirm it.","resolution":"1. Record where 8477 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_REPL_PENDING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8477 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replication request has been posted; waiting for reply.\n\nLookup forms: 8477, 0x211D, error 8477, ERROR_DS_DRA_REPL_PENDING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8477"]},{"id":1942,"title":"ERROR_DS_DS_REQUIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8478","0x211E","error 8478","ERROR_DS_DS_REQUIRED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","required","the","requested","operation","requires","directory","service","and","none","was","available"],"errorCode":"8478","eventId":"","severity":"Low","summary":"The requested operation requires a directory service, and none was available.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8478; use the surrounding log entries to confirm it.","resolution":"1. Record where 8478 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DS_REQUIRED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8478 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested operation requires a directory service, and none was available.\n\nLookup forms: 8478, 0x211E, error 8478, ERROR_DS_DS_REQUIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8478"]},{"id":1943,"title":"ERROR_DS_INVALID_LDAP_DISPLAY_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8479","0x211F","error 8479","ERROR_DS_INVALID_LDAP_DISPLAY_NAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","ldap","display","name","the","class","attribute","contains","non","ascii","characters"],"errorCode":"8479","eventId":"","severity":"Low","summary":"The LDAP display name of the class or attribute contains non-ASCII characters.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8479; use the surrounding log entries to confirm it.","resolution":"1. Record where 8479 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_INVALID_LDAP_DISPLAY_NAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8479 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The LDAP display name of the class or attribute contains non-ASCII characters.\n\nLookup forms: 8479, 0x211F, error 8479, ERROR_DS_INVALID_LDAP_DISPLAY_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8479"]},{"id":1944,"title":"ERROR_DS_NON_BASE_SEARCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8480","0x2120","error 8480","ERROR_DS_NON_BASE_SEARCH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","non","base","search","the","requested","operation","only","supported","for","searches"],"errorCode":"8480","eventId":"","severity":"Low","summary":"The requested search operation is only supported for base searches.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8480; use the surrounding log entries to confirm it.","resolution":"1. Record where 8480 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NON_BASE_SEARCH.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8480 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested search operation is only supported for base searches.\n\nLookup forms: 8480, 0x2120, error 8480, ERROR_DS_NON_BASE_SEARCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8480"]},{"id":1945,"title":"ERROR_DS_CANT_RETRIEVE_ATTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8481","0x2121","error 8481","ERROR_DS_CANT_RETRIEVE_ATTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","retrieve","atts","the","search","failed","attributes","from","database"],"errorCode":"8481","eventId":"","severity":"High","summary":"The search failed to retrieve attributes from the database.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8481; use the surrounding log entries to confirm it.","resolution":"1. Record where 8481 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_RETRIEVE_ATTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8481 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The search failed to retrieve attributes from the database.\n\nLookup forms: 8481, 0x2121, error 8481, ERROR_DS_CANT_RETRIEVE_ATTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8481"]},{"id":1946,"title":"ERROR_DS_BACKLINK_WITHOUT_LINK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8482","0x2122","error 8482","ERROR_DS_BACKLINK_WITHOUT_LINK","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","backlink","without","link","the","schema","update","operation","tried","add","backward","attribute","that","has","corresponding","forward"],"errorCode":"8482","eventId":"","severity":"Low","summary":"The schema update operation tried to add a backward link attribute that has no corresponding forward link.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 8482; use the surrounding log entries to confirm it.","resolution":"1. Record where 8482 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_BACKLINK_WITHOUT_LINK.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8482 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The schema update operation tried to add a backward link attribute that has no corresponding forward link.\n\nLookup forms: 8482, 0x2122, error 8482, ERROR_DS_BACKLINK_WITHOUT_LINK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8482"]},{"id":1947,"title":"ERROR_DS_EPOCH_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8483","0x2123","error 8483","ERROR_DS_EPOCH_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","epoch","mismatch","source","and","destination","cross","domain","move","not","agree","the","object","number","either","does","have","latest","version"],"errorCode":"8483","eventId":"","severity":"Low","summary":"Source and destination of a cross-domain move do not agree on the object's epoch number. Either source or destination does not have the latest version of the object.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8483; use the surrounding log entries to confirm it.","resolution":"1. Record where 8483 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_EPOCH_MISMATCH.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8483 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Source and destination of a cross-domain move do not agree on the object's epoch number. Either source or destination does not have the latest version of the object.\n\nLookup forms: 8483, 0x2123, error 8483, ERROR_DS_EPOCH_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Source and destination of a cross domain move do not agree on the object's epoch number. Either source or destination does not have the latest version of the object.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8483"]},{"id":1948,"title":"ERROR_DS_SRC_NAME_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8484","0x2124","error 8484","ERROR_DS_SRC_NAME_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","src","name","mismatch","source","and","destination","cross","domain","move","not","agree","the","object","current","either","does","have","latest","version"],"errorCode":"8484","eventId":"","severity":"Low","summary":"Source and destination of a cross-domain move do not agree on the object's current name. Either source or destination does not have the latest version of the object.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8484; use the surrounding log entries to confirm it.","resolution":"1. Record where 8484 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SRC_NAME_MISMATCH.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8484 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Source and destination of a cross-domain move do not agree on the object's current name. Either source or destination does not have the latest version of the object.\n\nLookup forms: 8484, 0x2124, error 8484, ERROR_DS_SRC_NAME_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Source and destination of a cross domain move do not agree on the object's current name. Either source or destination does not have the latest version of the object.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8484"]},{"id":1949,"title":"ERROR_DS_SRC_AND_DST_NC_IDENTICAL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8485","0x2125","error 8485","ERROR_DS_SRC_AND_DST_NC_IDENTICAL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","src","and","dst","identical","source","destination","for","the","cross","domain","move","operation","are","caller","should","use","local","instead"],"errorCode":"8485","eventId":"","severity":"Low","summary":"Source and destination for the cross-domain move operation are identical. Caller should use local move operation instead of cross-domain move operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8485; use the surrounding log entries to confirm it.","resolution":"1. Record where 8485 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SRC_AND_DST_NC_IDENTICAL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8485 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Source and destination for the cross-domain move operation are identical. Caller should use local move operation instead of cross-domain move operation.\n\nLookup forms: 8485, 0x2125, error 8485, ERROR_DS_SRC_AND_DST_NC_IDENTICAL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Source and destination of a cross domain move operation are identical. Caller should use local move operation instead of cross domain move operation.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8485"]},{"id":1950,"title":"ERROR_DS_DST_NC_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8486","0x2126","error 8486","ERROR_DS_DST_NC_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dst","mismatch","source","and","destination","for","cross","domain","move","are","not","agreement","the","naming","contexts","forest","either","does","have","latest","version","partitions","container"],"errorCode":"8486","eventId":"","severity":"Low","summary":"Source and destination for a cross-domain move are not in agreement on the naming contexts in the forest. Either source or destination does not have the latest version of the Partitions container.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8486; use the surrounding log entries to confirm it.","resolution":"1. Record where 8486 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DST_NC_MISMATCH.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8486 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Source and destination for a cross-domain move are not in agreement on the naming contexts in the forest. Either source or destination does not have the latest version of the Partitions container.\n\nLookup forms: 8486, 0x2126, error 8486, ERROR_DS_DST_NC_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Source and destination for a cross domain move are not in agreement on the naming contexts in the forest. Either source or destination does not have the latest version of the Partitions container.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8486"]},{"id":1951,"title":"ERROR_DS_NOT_AUTHORITIVE_FOR_DST_NC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8487","0x2127","error 8487","ERROR_DS_NOT_AUTHORITIVE_FOR_DST_NC","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","not","authoritive","for","dst","destination","cross","domain","move","authoritative","the","naming","context"],"errorCode":"8487","eventId":"","severity":"Low","summary":"Destination of a cross-domain move is not authoritative for the destination naming context.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8487; use the surrounding log entries to confirm it.","resolution":"1. Record where 8487 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NOT_AUTHORITIVE_FOR_DST_NC.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8487 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Destination of a cross-domain move is not authoritative for the destination naming context.\n\nLookup forms: 8487, 0x2127, error 8487, ERROR_DS_NOT_AUTHORITIVE_FOR_DST_NC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Destination of a cross domain move is not authoritative for the destination naming context.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8487"]},{"id":1952,"title":"ERROR_DS_SRC_GUID_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8488","0x2128","error 8488","ERROR_DS_SRC_GUID_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","src","guid","mismatch","source","and","destination","cross","domain","move","not","agree","the","identity","object","either","does","have","latest","version"],"errorCode":"8488","eventId":"","severity":"Low","summary":"Source and destination of a cross-domain move do not agree on the identity of the source object. Either source or destination does not have the latest version of the source object.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8488; use the surrounding log entries to confirm it.","resolution":"1. Record where 8488 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SRC_GUID_MISMATCH.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8488 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Source and destination of a cross-domain move do not agree on the identity of the source object. Either source or destination does not have the latest version of the source object.\n\nLookup forms: 8488, 0x2128, error 8488, ERROR_DS_SRC_GUID_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Source and destination of a cross domain move do not agree on the identity of the source object. Either source or destination does not have the latest version of the source object.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8488"]},{"id":1953,"title":"ERROR_DS_CANT_MOVE_DELETED_OBJECT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8489","0x2129","error 8489","ERROR_DS_CANT_MOVE_DELETED_OBJECT","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","cant","move","deleted","object","being","moved","across","domains","already","known","the","destination","server","source","does","not","have","latest","version"],"errorCode":"8489","eventId":"","severity":"Low","summary":"Object being moved across-domains is already known to be deleted by the destination server. The source server does not have the latest version of the source object.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8489; use the surrounding log entries to confirm it.","resolution":"1. Record where 8489 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_MOVE_DELETED_OBJECT.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8489 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Object being moved across-domains is already known to be deleted by the destination server. The source server does not have the latest version of the source object.\n\nLookup forms: 8489, 0x2129, error 8489, ERROR_DS_CANT_MOVE_DELETED_OBJECT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Object being moved across domains is already known to be deleted by the destination server. The source server does not have the latest version of the source object.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8489"]},{"id":1954,"title":"ERROR_DS_PDC_OPERATION_IN_PROGRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8490","0x212A","error 8490","ERROR_DS_PDC_OPERATION_IN_PROGRESS","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","pdc","operation","progress","another","which","requires","exclusive","access","the","fsmo","already"],"errorCode":"8490","eventId":"","severity":"Low","summary":"Another operation which requires exclusive access to the PDC FSMO is already in progress.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8490; use the surrounding log entries to confirm it.","resolution":"1. Record where 8490 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_PDC_OPERATION_IN_PROGRESS.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8490 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Another operation which requires exclusive access to the PDC FSMO is already in progress.\n\nLookup forms: 8490, 0x212A, error 8490, ERROR_DS_PDC_OPERATION_IN_PROGRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Another operation which requires exclusive access to the PDC PSMO is already in progress.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8490"]},{"id":1955,"title":"ERROR_DS_CROSS_DOMAIN_CLEANUP_REQD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8491","0x212B","error 8491","ERROR_DS_CROSS_DOMAIN_CLEANUP_REQD","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cross","domain","cleanup","reqd","move","operation","failed","such","that","two","versions","the","moved","object","exist","one","each","source","and","destination","domains","needs","removed","restore"],"errorCode":"8491","eventId":"","severity":"High","summary":"A cross-domain move operation failed such that two versions of the moved object exist - one each in the source and destination domains. The destination object needs to be removed to restore the system to a consistent state.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8491; use the surrounding log entries to confirm it.","resolution":"1. Record where 8491 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CROSS_DOMAIN_CLEANUP_REQD.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8491 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A cross-domain move operation failed such that two versions of the moved object exist - one each in the source and destination domains. The destination object needs to be removed to restore the system to a consistent state.\n\nLookup forms: 8491, 0x212B, error 8491, ERROR_DS_CROSS_DOMAIN_CLEANUP_REQD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): A cross domain move operation failed such that the two versions of the moved object exist - one each in the source and destination domains. The destination object needs to be removed to restore the system to a consistent state.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8491"]},{"id":1956,"title":"ERROR_DS_ILLEGAL_XDOM_MOVE_OPERATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8492","0x212C","error 8492","ERROR_DS_ILLEGAL_XDOM_MOVE_OPERATION","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","illegal","xdom","move","operation","this","object","may","not","moved","across","domain","boundaries","either","because","cross","moves","for","class","are","disallowed","the","has","some","special"],"errorCode":"8492","eventId":"","severity":"Low","summary":"This object may not be moved across domain boundaries either because cross-domain moves for this class are disallowed, or the object has some special characteristics, e.g.: trust account or restricted RID, which prevent its move.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8492; use the surrounding log entries to confirm it.","resolution":"1. Record where 8492 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_ILLEGAL_XDOM_MOVE_OPERATION.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8492 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This object may not be moved across domain boundaries either because cross-domain moves for this class are disallowed, or the object has some special characteristics, e.g.: trust account or restricted RID, which prevent its move.\n\nLookup forms: 8492, 0x212C, error 8492, ERROR_DS_ILLEGAL_XDOM_MOVE_OPERATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): This object may not be moved across domain boundaries either because cross domain moves for this class are disallowed, or the object has some special characteristics, eg: trust account or restricted RID, which prevent its move.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8492"]},{"id":1957,"title":"ERROR_DS_CANT_WITH_ACCT_GROUP_MEMBERSHPS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8493","0x212D","error 8493","ERROR_DS_CANT_WITH_ACCT_GROUP_MEMBERSHPS","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","cant","with","acct","group","membershps","can","move","objects","memberships","across","domain","boundaries","once","moved","this","would","violate","the","membership","conditions","account","remove","object","from"],"errorCode":"8493","eventId":"","severity":"Low","summary":"Can't move objects with memberships across domain boundaries as once moved, this would violate the membership conditions of the account group. Remove the object from any account group memberships and retry.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8493; use the surrounding log entries to confirm it.","resolution":"1. Record where 8493 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_WITH_ACCT_GROUP_MEMBERSHPS.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8493 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Can't move objects with memberships across domain boundaries as once moved, this would violate the membership conditions of the account group. Remove the object from any account group memberships and retry.\n\nLookup forms: 8493, 0x212D, error 8493, ERROR_DS_CANT_WITH_ACCT_GROUP_MEMBERSHPS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8493"]},{"id":1958,"title":"ERROR_DS_NC_MUST_HAVE_NC_PARENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8494","0x212E","error 8494","ERROR_DS_NC_MUST_HAVE_NC_PARENT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","must","have","parent","naming","context","head","the","immediate","child","another","not","interior","node"],"errorCode":"8494","eventId":"","severity":"Low","summary":"A naming context head must be the immediate child of another naming context head, not of an interior node.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8494; use the surrounding log entries to confirm it.","resolution":"1. Record where 8494 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NC_MUST_HAVE_NC_PARENT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8494 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A naming context head must be the immediate child of another naming context head, not of an interior node.\n\nLookup forms: 8494, 0x212E, error 8494, ERROR_DS_NC_MUST_HAVE_NC_PARENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8494"]},{"id":1959,"title":"ERROR_DS_CR_IMPOSSIBLE_TO_VALIDATE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8495","0x212F","error 8495","ERROR_DS_CR_IMPOSSIBLE_TO_VALIDATE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","impossible","validate","the","directory","cannot","proposed","naming","context","name","because","does","not","hold","replica","above","please","ensure","that","domain","master","role","held","server","configured"],"errorCode":"8495","eventId":"","severity":"Medium","summary":"The directory cannot validate the proposed naming context name because it does not hold a replica of the naming context above the proposed naming context. Please ensure that the domain naming master role is held by a server that is configured as a global catalog server, and that the server is up to date with its replication partners. (Applies only to Windows 2000 Domain Naming masters.)","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8495; use the surrounding log entries to confirm it.","resolution":"1. Record where 8495 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CR_IMPOSSIBLE_TO_VALIDATE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8495 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory cannot validate the proposed naming context name because it does not hold a replica of the naming context above the proposed naming context. Please ensure that the domain naming master role is held by a server that is configured as a global catalog server, and that the server is up to date with its replication partners. (Applies only to Windows 2000 Domain Naming masters.)\n\nLookup forms: 8495, 0x212F, error 8495, ERROR_DS_CR_IMPOSSIBLE_TO_VALIDATE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The directory cannot validate the proposed naming context name because it does not hold a replica of the naming context above the proposed naming context. Please ensure that the domain naming master role is held by a server that is configured as a global catalog server, and that the server is up to date with its replication partners. (Applies only to Windows 2000 Domain Naming masters)","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8495"]},{"id":1960,"title":"ERROR_DS_DST_DOMAIN_NOT_NATIVE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8496","0x2130","error 8496","ERROR_DS_DST_DOMAIN_NOT_NATIVE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dst","domain","not","native","destination","must","mode"],"errorCode":"8496","eventId":"","severity":"Low","summary":"Destination domain must be in native mode.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8496; use the surrounding log entries to confirm it.","resolution":"1. Record where 8496 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DST_DOMAIN_NOT_NATIVE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8496 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Destination domain must be in native mode.\n\nLookup forms: 8496, 0x2130, error 8496, ERROR_DS_DST_DOMAIN_NOT_NATIVE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8496"]},{"id":1961,"title":"ERROR_DS_MISSING_INFRASTRUCTURE_CONTAINER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8497","0x2131","error 8497","ERROR_DS_MISSING_INFRASTRUCTURE_CONTAINER","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","missing","infrastructure","container","the","operation","cannot","performed","because","server","does","not","have","domain","interest"],"errorCode":"8497","eventId":"","severity":"Medium","summary":"The operation cannot be performed because the server does not have an infrastructure container in the domain of interest.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8497; use the surrounding log entries to confirm it.","resolution":"1. Record where 8497 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_MISSING_INFRASTRUCTURE_CONTAINER.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8497 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation cannot be performed because the server does not have an infrastructure container in the domain of interest.\n\nLookup forms: 8497, 0x2131, error 8497, ERROR_DS_MISSING_INFRASTRUCTURE_CONTAINER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8497"]},{"id":1962,"title":"ERROR_DS_CANT_MOVE_ACCOUNT_GROUP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8498","0x2132","error 8498","ERROR_DS_CANT_MOVE_ACCOUNT_GROUP","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","cant","move","account","group","cross","domain","non","empty","groups","not","allowed"],"errorCode":"8498","eventId":"","severity":"Low","summary":"Cross-domain move of non-empty account groups is not allowed.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8498; use the surrounding log entries to confirm it.","resolution":"1. Record where 8498 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_MOVE_ACCOUNT_GROUP.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8498 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cross-domain move of non-empty account groups is not allowed.\n\nLookup forms: 8498, 0x2132, error 8498, ERROR_DS_CANT_MOVE_ACCOUNT_GROUP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8498"]},{"id":1963,"title":"ERROR_DS_CANT_MOVE_RESOURCE_GROUP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8499","0x2133","error 8499","ERROR_DS_CANT_MOVE_RESOURCE_GROUP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","move","resource","group","cross","domain","non","empty","groups","not","allowed"],"errorCode":"8499","eventId":"","severity":"Low","summary":"Cross-domain move of non-empty resource groups is not allowed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8499; use the surrounding log entries to confirm it.","resolution":"1. Record where 8499 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_MOVE_RESOURCE_GROUP.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8499 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cross-domain move of non-empty resource groups is not allowed.\n\nLookup forms: 8499, 0x2133, error 8499, ERROR_DS_CANT_MOVE_RESOURCE_GROUP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8499"]},{"id":1964,"title":"ERROR_DS_INVALID_SEARCH_FLAG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8500","0x2134","error 8500","ERROR_DS_INVALID_SEARCH_FLAG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","search","flag","the","flags","for","attribute","are","anr","bit","valid","only","attributes","unicode","teletex","strings"],"errorCode":"8500","eventId":"","severity":"Medium","summary":"The search flags for the attribute are invalid. The ANR bit is valid only on attributes of Unicode or Teletex strings.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8500; use the surrounding log entries to confirm it.","resolution":"1. Record where 8500 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_INVALID_SEARCH_FLAG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8500 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The search flags for the attribute are invalid. The ANR bit is valid only on attributes of Unicode or Teletex strings.\n\nLookup forms: 8500, 0x2134, error 8500, ERROR_DS_INVALID_SEARCH_FLAG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8500"]},{"id":1965,"title":"ERROR_DS_NO_TREE_DELETE_ABOVE_NC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8501","0x2135","error 8501","ERROR_DS_NO_TREE_DELETE_ABOVE_NC","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","tree","delete","above","deletions","starting","object","which","has","head","descendant","are","not","allowed"],"errorCode":"8501","eventId":"","severity":"Low","summary":"Tree deletions starting at an object which has an NC head as a descendant are not allowed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8501; use the surrounding log entries to confirm it.","resolution":"1. Record where 8501 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NO_TREE_DELETE_ABOVE_NC.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8501 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Tree deletions starting at an object which has an NC head as a descendant are not allowed.\n\nLookup forms: 8501, 0x2135, error 8501, ERROR_DS_NO_TREE_DELETE_ABOVE_NC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8501"]},{"id":1966,"title":"ERROR_DS_COULDNT_LOCK_TREE_FOR_DELETE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8502","0x2136","error 8502","ERROR_DS_COULDNT_LOCK_TREE_FOR_DELETE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","couldnt","lock","tree","for","delete","the","directory","service","failed","preparation","deletion","because","was","use"],"errorCode":"8502","eventId":"","severity":"High","summary":"The directory service failed to lock a tree in preparation for a tree deletion because the tree was in use.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8502; use the surrounding log entries to confirm it.","resolution":"1. Record where 8502 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_COULDNT_LOCK_TREE_FOR_DELETE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8502 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service failed to lock a tree in preparation for a tree deletion because the tree was in use.\n\nLookup forms: 8502, 0x2136, error 8502, ERROR_DS_COULDNT_LOCK_TREE_FOR_DELETE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8502"]},{"id":1967,"title":"ERROR_DS_COULDNT_IDENTIFY_OBJECTS_FOR_TREE_DELETE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8503","0x2137","error 8503","ERROR_DS_COULDNT_IDENTIFY_OBJECTS_FOR_TREE_DELETE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","couldnt","identify","objects","for","tree","delete","the","directory","service","failed","list","while","attempting","deletion"],"errorCode":"8503","eventId":"","severity":"High","summary":"The directory service failed to identify the list of objects to delete while attempting a tree deletion.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8503; use the surrounding log entries to confirm it.","resolution":"1. Record where 8503 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_COULDNT_IDENTIFY_OBJECTS_FOR_TREE_DELETE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8503 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service failed to identify the list of objects to delete while attempting a tree deletion.\n\nLookup forms: 8503, 0x2137, error 8503, ERROR_DS_COULDNT_IDENTIFY_OBJECTS_FOR_TREE_DELETE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8503"]},{"id":1968,"title":"ERROR_DS_SAM_INIT_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8504","0x2138","error 8504","ERROR_DS_SAM_INIT_FAILURE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","sam","init","failure","security","accounts","manager","initialization","failed","because","the","following","status","please","shutdown","this","system","and","reboot","into","directory","services","restore","mode","check"],"errorCode":"8504","eventId":"","severity":"High","summary":"Security Accounts Manager initialization failed because of the following error: %1. Error Status: 0x%2. Please shutdown this system and reboot into Directory Services Restore Mode, check the event log for more detailed information.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8504; use the surrounding log entries to confirm it.","resolution":"1. Record where 8504 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Confirm the user or service identity has the required permissions and is not locked or disabled.\n4. Verify the required service or agent is installed, running, and current; repair the component if needed.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SAM_INIT_FAILURE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Confirm the user or service identity has the required permissions and is not locked or disabled.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8504 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Security Accounts Manager initialization failed because of the following error: %1. Error Status: 0x%2. Please shutdown this system and reboot into Directory Services Restore Mode, check the event log for more detailed information.\n\nLookup forms: 8504, 0x2138, error 8504, ERROR_DS_SAM_INIT_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Security Accounts Manager initialization failed because of the following error: %1. Error Status: 0x%2. Click OK to shut down the system and reboot into Directory Services Restore Mode. Check the event log for detailed information.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8504"]},{"id":1969,"title":"ERROR_DS_SENSITIVE_GROUP_VIOLATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8505","0x2139","error 8505","ERROR_DS_SENSITIVE_GROUP_VIOLATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sensitive","group","violation","only","administrator","can","modify","the","membership","list","administrative"],"errorCode":"8505","eventId":"","severity":"Low","summary":"Only an administrator can modify the membership list of an administrative group.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8505; use the surrounding log entries to confirm it.","resolution":"1. Record where 8505 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SENSITIVE_GROUP_VIOLATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8505 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Only an administrator can modify the membership list of an administrative group.\n\nLookup forms: 8505, 0x2139, error 8505, ERROR_DS_SENSITIVE_GROUP_VIOLATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8505"]},{"id":1970,"title":"ERROR_DS_CANT_MOD_PRIMARYGROUPID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8506","0x213A","error 8506","ERROR_DS_CANT_MOD_PRIMARYGROUPID","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","cant","mod","primarygroupid","cannot","change","the","primary","group","domain","controller","account"],"errorCode":"8506","eventId":"","severity":"Medium","summary":"Cannot change the primary group ID of a domain controller account.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8506; use the surrounding log entries to confirm it.","resolution":"1. Record where 8506 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_MOD_PRIMARYGROUPID.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8506 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot change the primary group ID of a domain controller account.\n\nLookup forms: 8506, 0x213A, error 8506, ERROR_DS_CANT_MOD_PRIMARYGROUPID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8506"]},{"id":1971,"title":"ERROR_DS_ILLEGAL_BASE_SCHEMA_MOD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8507","0x213B","error 8507","ERROR_DS_ILLEGAL_BASE_SCHEMA_MOD","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","illegal","base","schema","mod","attempt","made","modify","the"],"errorCode":"8507","eventId":"","severity":"Low","summary":"An attempt is made to modify the base schema.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8507; use the surrounding log entries to confirm it.","resolution":"1. Record where 8507 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_ILLEGAL_BASE_SCHEMA_MOD.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8507 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt is made to modify the base schema.\n\nLookup forms: 8507, 0x213B, error 8507, ERROR_DS_ILLEGAL_BASE_SCHEMA_MOD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8507"]},{"id":1972,"title":"ERROR_DS_NONSAFE_SCHEMA_CHANGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8508","0x213C","error 8508","ERROR_DS_NONSAFE_SCHEMA_CHANGE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","nonsafe","schema","change","adding","new","mandatory","attribute","existing","class","deleting","from","optional","the","special","top","that","not","backlink","directly","through","inheritance","for","example","auxiliary"],"errorCode":"8508","eventId":"","severity":"Low","summary":"Adding a new mandatory attribute to an existing class, deleting a mandatory attribute from an existing class, or adding an optional attribute to the special class Top that is not a backlink attribute (directly or through inheritance, for example, by adding or deleting an auxiliary class) is not allowed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8508; use the surrounding log entries to confirm it.","resolution":"1. Record where 8508 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NONSAFE_SCHEMA_CHANGE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8508 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Adding a new mandatory attribute to an existing class, deleting a mandatory attribute from an existing class, or adding an optional attribute to the special class Top that is not a backlink attribute (directly or through inheritance, for example, by adding or deleting an auxiliary class) is not allowed.\n\nLookup forms: 8508, 0x213C, error 8508, ERROR_DS_NONSAFE_SCHEMA_CHANGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8508"]},{"id":1973,"title":"ERROR_DS_SCHEMA_UPDATE_DISALLOWED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8509","0x213D","error 8509","ERROR_DS_SCHEMA_UPDATE_DISALLOWED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","schema","update","disallowed","not","allowed","this","because","the","fsmo","role","owner"],"errorCode":"8509","eventId":"","severity":"Low","summary":"Schema update is not allowed on this DC because the DC is not the schema FSMO Role Owner.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 8509; use the surrounding log entries to confirm it.","resolution":"1. Record where 8509 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SCHEMA_UPDATE_DISALLOWED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8509 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema update is not allowed on this DC because the DC is not the schema FSMO Role Owner.\n\nLookup forms: 8509, 0x213D, error 8509, ERROR_DS_SCHEMA_UPDATE_DISALLOWED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8509"]},{"id":1974,"title":"ERROR_DS_CANT_CREATE_UNDER_SCHEMA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8510","0x213E","error 8510","ERROR_DS_CANT_CREATE_UNDER_SCHEMA","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","create","under","schema","object","this","class","cannot","created","the","container","you","can","only","attribute","and","objects"],"errorCode":"8510","eventId":"","severity":"Medium","summary":"An object of this class cannot be created under the schema container. You can only create attribute-schema and class-schema objects under the schema container.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8510; use the surrounding log entries to confirm it.","resolution":"1. Record where 8510 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_CREATE_UNDER_SCHEMA.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8510 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An object of this class cannot be created under the schema container. You can only create attribute-schema and class-schema objects under the schema container.\n\nLookup forms: 8510, 0x213E, error 8510, ERROR_DS_CANT_CREATE_UNDER_SCHEMA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): An object of this class cannot be created under the schema container. You can only create attributeschema and class-schema objects under the schema container.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8510"]},{"id":1975,"title":"ERROR_DS_INSTALL_NO_SRC_SCH_VERSION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8511","0x213F","error 8511","ERROR_DS_INSTALL_NO_SRC_SCH_VERSION","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","install","src","sch","version","the","replica","child","failed","get","objectversion","attribute","schema","container","source","either","missing","credentials","supplied","not","have","permission","read"],"errorCode":"8511","eventId":"","severity":"High","summary":"The replica/child install failed to get the objectVersion attribute on the schema container on the source DC. Either the attribute is missing on the schema container or the credentials supplied do not have permission to read it.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8511; use the surrounding log entries to confirm it.","resolution":"1. Record where 8511 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_INSTALL_NO_SRC_SCH_VERSION.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8511 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replica/child install failed to get the objectVersion attribute on the schema container on the source DC. Either the attribute is missing on the schema container or the credentials supplied do not have permission to read it.\n\nLookup forms: 8511, 0x213F, error 8511, ERROR_DS_INSTALL_NO_SRC_SCH_VERSION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8511"]},{"id":1976,"title":"ERROR_DS_INSTALL_NO_SCH_VERSION_IN_INIFILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8512","0x2140","error 8512","ERROR_DS_INSTALL_NO_SCH_VERSION_IN_INIFILE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","install","sch","version","inifile","the","replica","child","failed","read","objectversion","attribute","schema","section","file","ini","system32","directory"],"errorCode":"8512","eventId":"","severity":"High","summary":"The replica/child install failed to read the objectVersion attribute in the SCHEMA section of the file schema.ini in the system32 directory.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8512; use the surrounding log entries to confirm it.","resolution":"1. Record where 8512 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_INSTALL_NO_SCH_VERSION_IN_INIFILE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8512 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replica/child install failed to read the objectVersion attribute in the SCHEMA section of the file schema.ini in the system32 directory.\n\nLookup forms: 8512, 0x2140, error 8512, ERROR_DS_INSTALL_NO_SCH_VERSION_IN_INIFILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8512"]},{"id":1977,"title":"ERROR_DS_INVALID_GROUP_TYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8513","0x2141","error 8513","ERROR_DS_INVALID_GROUP_TYPE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","group","type","the","specified"],"errorCode":"8513","eventId":"","severity":"Medium","summary":"The specified group type is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8513; use the surrounding log entries to confirm it.","resolution":"1. Record where 8513 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_INVALID_GROUP_TYPE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8513 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified group type is invalid.\n\nLookup forms: 8513, 0x2141, error 8513, ERROR_DS_INVALID_GROUP_TYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8513"]},{"id":1978,"title":"ERROR_DS_NO_NEST_GLOBALGROUP_IN_MIXEDDOMAIN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8514","0x2142","error 8514","ERROR_DS_NO_NEST_GLOBALGROUP_IN_MIXEDDOMAIN","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","nest","globalgroup","mixeddomain","you","cannot","global","groups","mixed","domain","the","group","security","enabled"],"errorCode":"8514","eventId":"","severity":"Medium","summary":"You cannot nest global groups in a mixed domain if the group is security-enabled.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8514; use the surrounding log entries to confirm it.","resolution":"1. Record where 8514 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NO_NEST_GLOBALGROUP_IN_MIXEDDOMAIN.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8514 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: You cannot nest global groups in a mixed domain if the group is security-enabled.\n\nLookup forms: 8514, 0x2142, error 8514, ERROR_DS_NO_NEST_GLOBALGROUP_IN_MIXEDDOMAIN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Cannot nest global groups in a mixed domain if the group is security-enabled.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8514"]},{"id":1979,"title":"ERROR_DS_NO_NEST_LOCALGROUP_IN_MIXEDDOMAIN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8515","0x2143","error 8515","ERROR_DS_NO_NEST_LOCALGROUP_IN_MIXEDDOMAIN","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","nest","localgroup","mixeddomain","you","cannot","local","groups","mixed","domain","the","group","security","enabled"],"errorCode":"8515","eventId":"","severity":"Medium","summary":"You cannot nest local groups in a mixed domain if the group is security-enabled.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8515; use the surrounding log entries to confirm it.","resolution":"1. Record where 8515 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NO_NEST_LOCALGROUP_IN_MIXEDDOMAIN.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8515 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: You cannot nest local groups in a mixed domain if the group is security-enabled.\n\nLookup forms: 8515, 0x2143, error 8515, ERROR_DS_NO_NEST_LOCALGROUP_IN_MIXEDDOMAIN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Cannot nest local groups in a mixed domain if the group is security-enabled.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8515"]},{"id":1980,"title":"ERROR_DS_GLOBAL_CANT_HAVE_LOCAL_MEMBER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8516","0x2144","error 8516","ERROR_DS_GLOBAL_CANT_HAVE_LOCAL_MEMBER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","global","cant","have","local","member","group","cannot"],"errorCode":"8516","eventId":"","severity":"Medium","summary":"A global group cannot have a local group as a member.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8516; use the surrounding log entries to confirm it.","resolution":"1. Record where 8516 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_GLOBAL_CANT_HAVE_LOCAL_MEMBER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8516 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A global group cannot have a local group as a member.\n\nLookup forms: 8516, 0x2144, error 8516, ERROR_DS_GLOBAL_CANT_HAVE_LOCAL_MEMBER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8516"]},{"id":1981,"title":"ERROR_DS_GLOBAL_CANT_HAVE_UNIVERSAL_MEMBER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8517","0x2145","error 8517","ERROR_DS_GLOBAL_CANT_HAVE_UNIVERSAL_MEMBER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","global","cant","have","universal","member","group","cannot"],"errorCode":"8517","eventId":"","severity":"Medium","summary":"A global group cannot have a universal group as a member.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8517; use the surrounding log entries to confirm it.","resolution":"1. Record where 8517 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_GLOBAL_CANT_HAVE_UNIVERSAL_MEMBER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8517 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A global group cannot have a universal group as a member.\n\nLookup forms: 8517, 0x2145, error 8517, ERROR_DS_GLOBAL_CANT_HAVE_UNIVERSAL_MEMBER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8517"]},{"id":1982,"title":"ERROR_DS_UNIVERSAL_CANT_HAVE_LOCAL_MEMBER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8518","0x2146","error 8518","ERROR_DS_UNIVERSAL_CANT_HAVE_LOCAL_MEMBER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","universal","cant","have","local","member","group","cannot"],"errorCode":"8518","eventId":"","severity":"Medium","summary":"A universal group cannot have a local group as a member.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8518; use the surrounding log entries to confirm it.","resolution":"1. Record where 8518 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_UNIVERSAL_CANT_HAVE_LOCAL_MEMBER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8518 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A universal group cannot have a local group as a member.\n\nLookup forms: 8518, 0x2146, error 8518, ERROR_DS_UNIVERSAL_CANT_HAVE_LOCAL_MEMBER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8518"]},{"id":1983,"title":"ERROR_DS_GLOBAL_CANT_HAVE_CROSSDOMAIN_MEMBER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8519","0x2147","error 8519","ERROR_DS_GLOBAL_CANT_HAVE_CROSSDOMAIN_MEMBER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","global","cant","have","crossdomain","member","group","cannot","cross","domain"],"errorCode":"8519","eventId":"","severity":"Medium","summary":"A global group cannot have a cross-domain member.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8519; use the surrounding log entries to confirm it.","resolution":"1. Record where 8519 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_GLOBAL_CANT_HAVE_CROSSDOMAIN_MEMBER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8519 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A global group cannot have a cross-domain member.\n\nLookup forms: 8519, 0x2147, error 8519, ERROR_DS_GLOBAL_CANT_HAVE_CROSSDOMAIN_MEMBER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8519"]},{"id":1984,"title":"ERROR_DS_LOCAL_CANT_HAVE_CROSSDOMAIN_LOCAL_MEMBER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8520","0x2148","error 8520","ERROR_DS_LOCAL_CANT_HAVE_CROSSDOMAIN_LOCAL_MEMBER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","local","cant","have","crossdomain","member","group","cannot","another","cross","domain"],"errorCode":"8520","eventId":"","severity":"Medium","summary":"A local group cannot have another cross domain local group as a member.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8520; use the surrounding log entries to confirm it.","resolution":"1. Record where 8520 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_LOCAL_CANT_HAVE_CROSSDOMAIN_LOCAL_MEMBER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8520 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A local group cannot have another cross domain local group as a member.\n\nLookup forms: 8520, 0x2148, error 8520, ERROR_DS_LOCAL_CANT_HAVE_CROSSDOMAIN_LOCAL_MEMBER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): A local group cannot have another cross-domain local group as a member.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8520"]},{"id":1985,"title":"ERROR_DS_HAVE_PRIMARY_MEMBERS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8521","0x2149","error 8521","ERROR_DS_HAVE_PRIMARY_MEMBERS","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","have","primary","members","group","with","cannot","change","security","disabled"],"errorCode":"8521","eventId":"","severity":"Medium","summary":"A group with primary members cannot change to a security-disabled group.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8521; use the surrounding log entries to confirm it.","resolution":"1. Record where 8521 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_HAVE_PRIMARY_MEMBERS.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8521 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A group with primary members cannot change to a security-disabled group.\n\nLookup forms: 8521, 0x2149, error 8521, ERROR_DS_HAVE_PRIMARY_MEMBERS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8521"]},{"id":1986,"title":"ERROR_DS_STRING_SD_CONVERSION_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8522","0x214A","error 8522","ERROR_DS_STRING_SD_CONVERSION_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","string","conversion","failed","the","schema","cache","load","convert","default","class","object"],"errorCode":"8522","eventId":"","severity":"High","summary":"The schema cache load failed to convert the string default SD on a class-schema object.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8522; use the surrounding log entries to confirm it.","resolution":"1. Record where 8522 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_STRING_SD_CONVERSION_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8522 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The schema cache load failed to convert the string default SD on a class-schema object.\n\nLookup forms: 8522, 0x214A, error 8522, ERROR_DS_STRING_SD_CONVERSION_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8522"]},{"id":1987,"title":"ERROR_DS_NAMING_MASTER_GC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8523","0x214B","error 8523","ERROR_DS_NAMING_MASTER_GC","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","naming","master","only","dsas","configured","global","catalog","servers","should","allowed","hold","the","domain","fsmo","role","applies","windows","2000"],"errorCode":"8523","eventId":"","severity":"Low","summary":"Only DSAs configured to be Global Catalog servers should be allowed to hold the Domain Naming Master FSMO role. (Applies only to Windows 2000 servers.)","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8523; use the surrounding log entries to confirm it.","resolution":"1. Record where 8523 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NAMING_MASTER_GC.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8523 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Only DSAs configured to be Global Catalog servers should be allowed to hold the Domain Naming Master FSMO role. (Applies only to Windows 2000 servers.)\n\nLookup forms: 8523, 0x214B, error 8523, ERROR_DS_NAMING_MASTER_GC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Only DSAs configured to be Global Catalog servers should be allowed to hold the Domain Naming Master FSMO role. (Applies only to Windows 2000 servers)","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8523"]},{"id":1988,"title":"ERROR_DS_DNS_LOOKUP_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8524","0x214C","error 8524","ERROR_DS_DNS_LOOKUP_FAILURE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","dns","lookup","failure","the","dsa","operation","unable","proceed","because"],"errorCode":"8524","eventId":"","severity":"High","summary":"The DSA operation is unable to proceed because of a DNS lookup failure.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8524; use the surrounding log entries to confirm it.","resolution":"1. Record where 8524 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DNS_LOOKUP_FAILURE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8524 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The DSA operation is unable to proceed because of a DNS lookup failure.\n\nLookup forms: 8524, 0x214C, error 8524, ERROR_DS_DNS_LOOKUP_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8524"]},{"id":1989,"title":"ERROR_DS_COULDNT_UPDATE_SPNS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8525","0x214D","error 8525","ERROR_DS_COULDNT_UPDATE_SPNS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","couldnt","update","spns","while","processing","change","the","dns","host","name","for","object","service","principal","values","could","not","kept","sync"],"errorCode":"8525","eventId":"","severity":"Low","summary":"While processing a change to the DNS Host Name for an object, the Service Principal Name values could not be kept in sync.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8525; use the surrounding log entries to confirm it.","resolution":"1. Record where 8525 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_COULDNT_UPDATE_SPNS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8525 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: While processing a change to the DNS Host Name for an object, the Service Principal Name values could not be kept in sync.\n\nLookup forms: 8525, 0x214D, error 8525, ERROR_DS_COULDNT_UPDATE_SPNS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8525"]},{"id":1990,"title":"ERROR_DS_CANT_RETRIEVE_SD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8526","0x214E","error 8526","ERROR_DS_CANT_RETRIEVE_SD","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","cant","retrieve","the","security","descriptor","attribute","could","not","read"],"errorCode":"8526","eventId":"","severity":"Low","summary":"The Security Descriptor attribute could not be read.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8526; use the surrounding log entries to confirm it.","resolution":"1. Record where 8526 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_RETRIEVE_SD.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8526 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Security Descriptor attribute could not be read.\n\nLookup forms: 8526, 0x214E, error 8526, ERROR_DS_CANT_RETRIEVE_SD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8526"]},{"id":1991,"title":"ERROR_DS_KEY_NOT_UNIQUE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8527","0x214F","error 8527","ERROR_DS_KEY_NOT_UNIQUE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","key","not","unique","the","object","requested","was","found","but","with","that"],"errorCode":"8527","eventId":"","severity":"Medium","summary":"The object requested was not found, but an object with that key was found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8527; use the surrounding log entries to confirm it.","resolution":"1. Record where 8527 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_KEY_NOT_UNIQUE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8527 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The object requested was not found, but an object with that key was found.\n\nLookup forms: 8527, 0x214F, error 8527, ERROR_DS_KEY_NOT_UNIQUE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8527"]},{"id":1992,"title":"ERROR_DS_WRONG_LINKED_ATT_SYNTAX","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8528","0x2150","error 8528","ERROR_DS_WRONG_LINKED_ATT_SYNTAX","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wrong","linked","att","syntax","the","attribute","being","added","incorrect","forward","links","can","only","have","and","backlinks"],"errorCode":"8528","eventId":"","severity":"Low","summary":"The syntax of the linked attribute being added is incorrect. Forward links can only have syntax 2.5.5.1, 2.5.5.7, and 2.5.5.14, and backlinks can only have syntax 2.5.5.1.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8528; use the surrounding log entries to confirm it.","resolution":"1. Record where 8528 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_WRONG_LINKED_ATT_SYNTAX.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8528 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The syntax of the linked attribute being added is incorrect. Forward links can only have syntax 2.5.5.1, 2.5.5.7, and 2.5.5.14, and backlinks can only have syntax 2.5.5.1.\n\nLookup forms: 8528, 0x2150, error 8528, ERROR_DS_WRONG_LINKED_ATT_SYNTAX. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The syntax of the linked attributed being added is incorrect. Forward links can only have syntax 2.5.5.1, 2.5.5.7, and 2.5.5.14, and backlinks can only have syntax 2.5.5.1.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8528"]},{"id":1993,"title":"ERROR_DS_SAM_NEED_BOOTKEY_PASSWORD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8529","0x2151","error 8529","ERROR_DS_SAM_NEED_BOOTKEY_PASSWORD","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","sam","need","bootkey","password","security","account","manager","needs","get","the","boot"],"errorCode":"8529","eventId":"","severity":"Low","summary":"Security Account Manager needs to get the boot password.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8529; use the surrounding log entries to confirm it.","resolution":"1. Record where 8529 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SAM_NEED_BOOTKEY_PASSWORD.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8529 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Security Account Manager needs to get the boot password.\n\nLookup forms: 8529, 0x2151, error 8529, ERROR_DS_SAM_NEED_BOOTKEY_PASSWORD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8529"]},{"id":1994,"title":"ERROR_DS_SAM_NEED_BOOTKEY_FLOPPY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8530","0x2152","error 8530","ERROR_DS_SAM_NEED_BOOTKEY_FLOPPY","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","sam","need","bootkey","floppy","security","account","manager","needs","get","the","boot","key","from","disk"],"errorCode":"8530","eventId":"","severity":"Low","summary":"Security Account Manager needs to get the boot key from floppy disk.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8530; use the surrounding log entries to confirm it.","resolution":"1. Record where 8530 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SAM_NEED_BOOTKEY_FLOPPY.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8530 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Security Account Manager needs to get the boot key from floppy disk.\n\nLookup forms: 8530, 0x2152, error 8530, ERROR_DS_SAM_NEED_BOOTKEY_FLOPPY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8530"]},{"id":1995,"title":"ERROR_DS_CANT_START","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8531","0x2153","error 8531","ERROR_DS_CANT_START","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","cant","start","directory","service","cannot"],"errorCode":"8531","eventId":"","severity":"Medium","summary":"Directory Service cannot start.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8531; use the surrounding log entries to confirm it.","resolution":"1. Record where 8531 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_START.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8531 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Directory Service cannot start.\n\nLookup forms: 8531, 0x2153, error 8531, ERROR_DS_CANT_START. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8531"]},{"id":1996,"title":"ERROR_DS_INIT_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8532","0x2154","error 8532","ERROR_DS_INIT_FAILURE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","init","failure","directory","services","could","not","start"],"errorCode":"8532","eventId":"","severity":"Low","summary":"Directory Services could not start.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8532; use the surrounding log entries to confirm it.","resolution":"1. Record where 8532 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_INIT_FAILURE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8532 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Directory Services could not start.\n\nLookup forms: 8532, 0x2154, error 8532, ERROR_DS_INIT_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8532"]},{"id":1997,"title":"ERROR_DS_NO_PKT_PRIVACY_ON_CONNECTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8533","0x2155","error 8533","ERROR_DS_NO_PKT_PRIVACY_ON_CONNECTION","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","pkt","privacy","connection","the","between","client","and","server","requires","packet","better"],"errorCode":"8533","eventId":"","severity":"High","summary":"The connection between client and server requires packet privacy or better.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8533; use the surrounding log entries to confirm it.","resolution":"1. Record where 8533 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NO_PKT_PRIVACY_ON_CONNECTION.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8533 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The connection between client and server requires packet privacy or better.\n\nLookup forms: 8533, 0x2155, error 8533, ERROR_DS_NO_PKT_PRIVACY_ON_CONNECTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8533"]},{"id":1998,"title":"ERROR_DS_SOURCE_DOMAIN_IN_FOREST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8534","0x2156","error 8534","ERROR_DS_SOURCE_DOMAIN_IN_FOREST","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","source","domain","forest","the","may","not","same","destination"],"errorCode":"8534","eventId":"","severity":"Low","summary":"The source domain may not be in the same forest as destination.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8534; use the surrounding log entries to confirm it.","resolution":"1. Record where 8534 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SOURCE_DOMAIN_IN_FOREST.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8534 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The source domain may not be in the same forest as destination.\n\nLookup forms: 8534, 0x2156, error 8534, ERROR_DS_SOURCE_DOMAIN_IN_FOREST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8534"]},{"id":1999,"title":"ERROR_DS_DESTINATION_DOMAIN_NOT_IN_FOREST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8535","0x2157","error 8535","ERROR_DS_DESTINATION_DOMAIN_NOT_IN_FOREST","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","destination","domain","not","forest","the","must"],"errorCode":"8535","eventId":"","severity":"Low","summary":"The destination domain must be in the forest.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8535; use the surrounding log entries to confirm it.","resolution":"1. Record where 8535 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DESTINATION_DOMAIN_NOT_IN_FOREST.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8535 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The destination domain must be in the forest.\n\nLookup forms: 8535, 0x2157, error 8535, ERROR_DS_DESTINATION_DOMAIN_NOT_IN_FOREST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8535"]},{"id":2000,"title":"ERROR_DS_DESTINATION_AUDITING_NOT_ENABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8536","0x2158","error 8536","ERROR_DS_DESTINATION_AUDITING_NOT_ENABLED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","destination","auditing","not","enabled","the","operation","requires","that","domain"],"errorCode":"8536","eventId":"","severity":"Low","summary":"The operation requires that destination domain auditing be enabled.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8536; use the surrounding log entries to confirm it.","resolution":"1. Record where 8536 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DESTINATION_AUDITING_NOT_ENABLED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8536 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation requires that destination domain auditing be enabled.\n\nLookup forms: 8536, 0x2158, error 8536, ERROR_DS_DESTINATION_AUDITING_NOT_ENABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8536"]},{"id":2001,"title":"ERROR_DS_CANT_FIND_DC_FOR_SRC_DOMAIN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8537","0x2159","error 8537","ERROR_DS_CANT_FIND_DC_FOR_SRC_DOMAIN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","find","for","src","domain","the","operation","couldn","locate","source"],"errorCode":"8537","eventId":"","severity":"Low","summary":"The operation couldn't locate a DC for the source domain.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8537; use the surrounding log entries to confirm it.","resolution":"1. Record where 8537 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_FIND_DC_FOR_SRC_DOMAIN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8537 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation couldn't locate a DC for the source domain.\n\nLookup forms: 8537, 0x2159, error 8537, ERROR_DS_CANT_FIND_DC_FOR_SRC_DOMAIN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8537"]},{"id":2002,"title":"ERROR_DS_SRC_OBJ_NOT_GROUP_OR_USER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8538","0x215A","error 8538","ERROR_DS_SRC_OBJ_NOT_GROUP_OR_USER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","src","obj","not","group","user","the","source","object","must"],"errorCode":"8538","eventId":"","severity":"Low","summary":"The source object must be a group or user.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8538; use the surrounding log entries to confirm it.","resolution":"1. Record where 8538 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SRC_OBJ_NOT_GROUP_OR_USER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8538 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The source object must be a group or user.\n\nLookup forms: 8538, 0x215A, error 8538, ERROR_DS_SRC_OBJ_NOT_GROUP_OR_USER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8538"]},{"id":2003,"title":"ERROR_DS_SRC_SID_EXISTS_IN_FOREST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8539","0x215B","error 8539","ERROR_DS_SRC_SID_EXISTS_IN_FOREST","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","src","sid","exists","forest","the","source","object","already","destination"],"errorCode":"8539","eventId":"","severity":"Medium","summary":"The source object's SID already exists in destination forest.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8539; use the surrounding log entries to confirm it.","resolution":"1. Record where 8539 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SRC_SID_EXISTS_IN_FOREST.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8539 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The source object's SID already exists in destination forest.\n\nLookup forms: 8539, 0x215B, error 8539, ERROR_DS_SRC_SID_EXISTS_IN_FOREST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8539"]},{"id":2004,"title":"ERROR_DS_SRC_AND_DST_OBJECT_CLASS_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8540","0x215C","error 8540","ERROR_DS_SRC_AND_DST_OBJECT_CLASS_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","src","and","dst","object","class","mismatch","the","source","destination","must","same","type"],"errorCode":"8540","eventId":"","severity":"Low","summary":"The source and destination object must be of the same type.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8540; use the surrounding log entries to confirm it.","resolution":"1. Record where 8540 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SRC_AND_DST_OBJECT_CLASS_MISMATCH.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8540 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The source and destination object must be of the same type.\n\nLookup forms: 8540, 0x215C, error 8540, ERROR_DS_SRC_AND_DST_OBJECT_CLASS_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8540"]},{"id":2005,"title":"ERROR_SAM_INIT_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8541","0x215D","error 8541","ERROR_SAM_INIT_FAILURE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","sam","init","failure","security","accounts","manager","initialization","failed","because","the","following","status","click","shut","down","system","and","reboot","into","safe","mode","check","event","log"],"errorCode":"8541","eventId":"","severity":"High","summary":"Security Accounts Manager initialization failed because of the following error: %1. Error Status: 0x%2. Click OK to shut down the system and reboot into Safe Mode. Check the event log for detailed information.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8541; use the surrounding log entries to confirm it.","resolution":"1. Record where 8541 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SAM_INIT_FAILURE.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8541 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Security Accounts Manager initialization failed because of the following error: %1. Error Status: 0x%2. Click OK to shut down the system and reboot into Safe Mode. Check the event log for detailed information.\n\nLookup forms: 8541, 0x215D, error 8541, ERROR_SAM_INIT_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8541"]},{"id":2006,"title":"ERROR_DS_DRA_SCHEMA_INFO_SHIP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8542","0x215E","error 8542","ERROR_DS_DRA_SCHEMA_INFO_SHIP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dra","schema","info","ship","information","could","not","included","the","replication","request"],"errorCode":"8542","eventId":"","severity":"Low","summary":"Schema information could not be included in the replication request.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8542; use the surrounding log entries to confirm it.","resolution":"1. Record where 8542 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_SCHEMA_INFO_SHIP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8542 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema information could not be included in the replication request.\n\nLookup forms: 8542, 0x215E, error 8542, ERROR_DS_DRA_SCHEMA_INFO_SHIP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8542"]},{"id":2007,"title":"ERROR_DS_DRA_SCHEMA_CONFLICT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8543","0x215F","error 8543","ERROR_DS_DRA_SCHEMA_CONFLICT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dra","schema","conflict","the","replication","operation","could","not","completed","due","incompatibility"],"errorCode":"8543","eventId":"","severity":"Low","summary":"The replication operation could not be completed due to a schema incompatibility.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8543; use the surrounding log entries to confirm it.","resolution":"1. Record where 8543 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_SCHEMA_CONFLICT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8543 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replication operation could not be completed due to a schema incompatibility.\n\nLookup forms: 8543, 0x215F, error 8543, ERROR_DS_DRA_SCHEMA_CONFLICT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8543"]},{"id":2008,"title":"ERROR_DS_DRA_EARLIER_SCHEMA_CONFLICT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8544","0x2160","error 8544","ERROR_DS_DRA_EARLIER_SCHEMA_CONFLICT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dra","earlier","schema","conflict","the","replication","operation","could","not","completed","due","previous","incompatibility"],"errorCode":"8544","eventId":"","severity":"Low","summary":"The replication operation could not be completed due to a previous schema incompatibility.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8544; use the surrounding log entries to confirm it.","resolution":"1. Record where 8544 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_EARLIER_SCHEMA_CONFLICT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8544 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replication operation could not be completed due to a previous schema incompatibility.\n\nLookup forms: 8544, 0x2160, error 8544, ERROR_DS_DRA_EARLIER_SCHEMA_CONFLICT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8544"]},{"id":2009,"title":"ERROR_DS_DRA_OBJ_NC_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8545","0x2161","error 8545","ERROR_DS_DRA_OBJ_NC_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","dra","obj","mismatch","the","replication","update","could","not","applied","because","either","source","destination","has","yet","received","information","regarding","recent","cross","domain","move","operation"],"errorCode":"8545","eventId":"","severity":"Low","summary":"The replication update could not be applied because either the source or the destination has not yet received information regarding a recent cross-domain move operation.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 8545; use the surrounding log entries to confirm it.","resolution":"1. Record where 8545 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_OBJ_NC_MISMATCH.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8545 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replication update could not be applied because either the source or the destination has not yet received information regarding a recent cross-domain move operation.\n\nLookup forms: 8545, 0x2161, error 8545, ERROR_DS_DRA_OBJ_NC_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8545"]},{"id":2010,"title":"ERROR_DS_NC_STILL_HAS_DSAS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8546","0x2162","error 8546","ERROR_DS_NC_STILL_HAS_DSAS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","still","has","dsas","the","requested","domain","could","not","deleted","because","there","exist","controllers","that","host","this"],"errorCode":"8546","eventId":"","severity":"Low","summary":"The requested domain could not be deleted because there exist domain controllers that still host this domain.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8546; use the surrounding log entries to confirm it.","resolution":"1. Record where 8546 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NC_STILL_HAS_DSAS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8546 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested domain could not be deleted because there exist domain controllers that still host this domain.\n\nLookup forms: 8546, 0x2162, error 8546, ERROR_DS_NC_STILL_HAS_DSAS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8546"]},{"id":2011,"title":"ERROR_DS_GC_REQUIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8547","0x2163","error 8547","ERROR_DS_GC_REQUIRED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","required","the","requested","operation","can","performed","only","global","catalog","server"],"errorCode":"8547","eventId":"","severity":"Low","summary":"The requested operation can be performed only on a global catalog server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8547; use the surrounding log entries to confirm it.","resolution":"1. Record where 8547 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_GC_REQUIRED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8547 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested operation can be performed only on a global catalog server.\n\nLookup forms: 8547, 0x2163, error 8547, ERROR_DS_GC_REQUIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8547"]},{"id":2012,"title":"ERROR_DS_LOCAL_MEMBER_OF_LOCAL_ONLY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8548","0x2164","error 8548","ERROR_DS_LOCAL_MEMBER_OF_LOCAL_ONLY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","local","member","only","group","can","other","groups","the","same","domain"],"errorCode":"8548","eventId":"","severity":"Low","summary":"A local group can only be a member of other local groups in the same domain.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8548; use the surrounding log entries to confirm it.","resolution":"1. Record where 8548 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_LOCAL_MEMBER_OF_LOCAL_ONLY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8548 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A local group can only be a member of other local groups in the same domain.\n\nLookup forms: 8548, 0x2164, error 8548, ERROR_DS_LOCAL_MEMBER_OF_LOCAL_ONLY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8548"]},{"id":2013,"title":"ERROR_DS_NO_FPO_IN_UNIVERSAL_GROUPS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8549","0x2165","error 8549","ERROR_DS_NO_FPO_IN_UNIVERSAL_GROUPS","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","fpo","universal","groups","foreign","security","principals","cannot","members"],"errorCode":"8549","eventId":"","severity":"Medium","summary":"Foreign security principals cannot be members of universal groups.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8549; use the surrounding log entries to confirm it.","resolution":"1. Record where 8549 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NO_FPO_IN_UNIVERSAL_GROUPS.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8549 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Foreign security principals cannot be members of universal groups.\n\nLookup forms: 8549, 0x2165, error 8549, ERROR_DS_NO_FPO_IN_UNIVERSAL_GROUPS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8549"]},{"id":2014,"title":"ERROR_DS_CANT_ADD_TO_GC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8550","0x2166","error 8550","ERROR_DS_CANT_ADD_TO_GC","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","cant","add","the","attribute","not","allowed","replicated","because","security","reasons"],"errorCode":"8550","eventId":"","severity":"Low","summary":"The attribute is not allowed to be replicated to the GC because of security reasons.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8550; use the surrounding log entries to confirm it.","resolution":"1. Record where 8550 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_ADD_TO_GC.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8550 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The attribute is not allowed to be replicated to the GC because of security reasons.\n\nLookup forms: 8550, 0x2166, error 8550, ERROR_DS_CANT_ADD_TO_GC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8550"]},{"id":2015,"title":"ERROR_DS_NO_CHECKPOINT_WITH_PDC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8551","0x2167","error 8551","ERROR_DS_NO_CHECKPOINT_WITH_PDC","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","checkpoint","with","pdc","the","could","not","taken","because","there","too","many","modifications","being","processed","currently"],"errorCode":"8551","eventId":"","severity":"Low","summary":"The checkpoint with the PDC could not be taken because there too many modifications being processed currently.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 8551; use the surrounding log entries to confirm it.","resolution":"1. Record where 8551 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NO_CHECKPOINT_WITH_PDC.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8551 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The checkpoint with the PDC could not be taken because there too many modifications being processed currently.\n\nLookup forms: 8551, 0x2167, error 8551, ERROR_DS_NO_CHECKPOINT_WITH_PDC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The checkpoint with the PDC could not be taken because there are too many modifications being processed currently.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8551"]},{"id":2016,"title":"ERROR_DS_SOURCE_AUDITING_NOT_ENABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8552","0x2168","error 8552","ERROR_DS_SOURCE_AUDITING_NOT_ENABLED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","source","auditing","not","enabled","the","operation","requires","that","domain"],"errorCode":"8552","eventId":"","severity":"Low","summary":"The operation requires that source domain auditing be enabled.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8552; use the surrounding log entries to confirm it.","resolution":"1. Record where 8552 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SOURCE_AUDITING_NOT_ENABLED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8552 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation requires that source domain auditing be enabled.\n\nLookup forms: 8552, 0x2168, error 8552, ERROR_DS_SOURCE_AUDITING_NOT_ENABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8552"]},{"id":2017,"title":"ERROR_DS_CANT_CREATE_IN_NONDOMAIN_NC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8553","0x2169","error 8553","ERROR_DS_CANT_CREATE_IN_NONDOMAIN_NC","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","cant","create","nondomain","security","principal","objects","can","only","created","inside","domain","naming","contexts"],"errorCode":"8553","eventId":"","severity":"Low","summary":"Security principal objects can only be created inside domain naming contexts.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8553; use the surrounding log entries to confirm it.","resolution":"1. Record where 8553 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_CREATE_IN_NONDOMAIN_NC.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8553 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Security principal objects can only be created inside domain naming contexts.\n\nLookup forms: 8553, 0x2169, error 8553, ERROR_DS_CANT_CREATE_IN_NONDOMAIN_NC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8553"]},{"id":2018,"title":"ERROR_DS_INVALID_NAME_FOR_SPN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8554","0x216A","error 8554","ERROR_DS_INVALID_NAME_FOR_SPN","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","invalid","name","for","spn","service","principal","could","not","constructed","because","the","provided","hostname","necessary","format"],"errorCode":"8554","eventId":"","severity":"Low","summary":"A Service Principal Name (SPN) could not be constructed because the provided hostname is not in the necessary format.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8554; use the surrounding log entries to confirm it.","resolution":"1. Record where 8554 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_INVALID_NAME_FOR_SPN.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8554 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A Service Principal Name (SPN) could not be constructed because the provided hostname is not in the necessary format.\n\nLookup forms: 8554, 0x216A, error 8554, ERROR_DS_INVALID_NAME_FOR_SPN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8554"]},{"id":2019,"title":"ERROR_DS_FILTER_USES_CONTRUCTED_ATTRS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8555","0x216B","error 8555","ERROR_DS_FILTER_USES_CONTRUCTED_ATTRS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","filter","uses","contructed","attrs","was","passed","that","constructed","attributes"],"errorCode":"8555","eventId":"","severity":"Low","summary":"A Filter was passed that uses constructed attributes.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8555; use the surrounding log entries to confirm it.","resolution":"1. Record where 8555 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_FILTER_USES_CONTRUCTED_ATTRS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8555 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A Filter was passed that uses constructed attributes.\n\nLookup forms: 8555, 0x216B, error 8555, ERROR_DS_FILTER_USES_CONTRUCTED_ATTRS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8555"]},{"id":2020,"title":"ERROR_DS_UNICODEPWD_NOT_IN_QUOTES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8556","0x216C","error 8556","ERROR_DS_UNICODEPWD_NOT_IN_QUOTES","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","unicodepwd","not","quotes","the","attribute","value","must","enclosed","double"],"errorCode":"8556","eventId":"","severity":"Low","summary":"The unicodePwd attribute value must be enclosed in double quotes.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8556; use the surrounding log entries to confirm it.","resolution":"1. Record where 8556 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_UNICODEPWD_NOT_IN_QUOTES.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8556 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The unicodePwd attribute value must be enclosed in double quotes.\n\nLookup forms: 8556, 0x216C, error 8556, ERROR_DS_UNICODEPWD_NOT_IN_QUOTES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8556"]},{"id":2021,"title":"ERROR_DS_MACHINE_ACCOUNT_QUOTA_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8557","0x216D","error 8557","ERROR_DS_MACHINE_ACCOUNT_QUOTA_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","machine","account","quota","exceeded","your","computer","could","not","joined","the","domain","you","have","maximum","number","accounts","are","allowed","create","this","contact","system","administrator","limit"],"errorCode":"8557","eventId":"","severity":"Low","summary":"Your computer could not be joined to the domain. You have exceeded the maximum number of computer accounts you are allowed to create in this domain. Contact your system administrator to have this limit reset or increased.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8557; use the surrounding log entries to confirm it.","resolution":"1. Record where 8557 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_MACHINE_ACCOUNT_QUOTA_EXCEEDED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8557 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Your computer could not be joined to the domain. You have exceeded the maximum number of computer accounts you are allowed to create in this domain. Contact your system administrator to have this limit reset or increased.\n\nLookup forms: 8557, 0x216D, error 8557, ERROR_DS_MACHINE_ACCOUNT_QUOTA_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8557"]},{"id":2022,"title":"ERROR_DS_MUST_BE_RUN_ON_DST_DC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8558","0x216E","error 8558","ERROR_DS_MUST_BE_RUN_ON_DST_DC","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","must","run","dst","for","security","reasons","the","operation","destination"],"errorCode":"8558","eventId":"","severity":"Low","summary":"For security reasons, the operation must be run on the destination DC.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8558; use the surrounding log entries to confirm it.","resolution":"1. Record where 8558 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_MUST_BE_RUN_ON_DST_DC.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8558 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: For security reasons, the operation must be run on the destination DC.\n\nLookup forms: 8558, 0x216E, error 8558, ERROR_DS_MUST_BE_RUN_ON_DST_DC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8558"]},{"id":2023,"title":"ERROR_DS_SRC_DC_MUST_BE_SP4_OR_GREATER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8559","0x216F","error 8559","ERROR_DS_SRC_DC_MUST_BE_SP4_OR_GREATER","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","src","must","sp4","greater","for","security","reasons","the","source","nt4sp4"],"errorCode":"8559","eventId":"","severity":"Low","summary":"For security reasons, the source DC must be NT4SP4 or greater.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8559; use the surrounding log entries to confirm it.","resolution":"1. Record where 8559 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SRC_DC_MUST_BE_SP4_OR_GREATER.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8559 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: For security reasons, the source DC must be NT4SP4 or greater.\n\nLookup forms: 8559, 0x216F, error 8559, ERROR_DS_SRC_DC_MUST_BE_SP4_OR_GREATER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8559"]},{"id":2024,"title":"ERROR_DS_CANT_TREE_DELETE_CRITICAL_OBJ","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8560","0x2170","error 8560","ERROR_DS_CANT_TREE_DELETE_CRITICAL_OBJ","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","cant","tree","delete","critical","obj","directory","service","system","objects","cannot","deleted","during","operations","the","may","have","been","partially","performed"],"errorCode":"8560","eventId":"","severity":"Medium","summary":"Critical Directory Service System objects cannot be deleted during tree delete operations. The tree delete may have been partially performed.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8560; use the surrounding log entries to confirm it.","resolution":"1. Record where 8560 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_TREE_DELETE_CRITICAL_OBJ.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8560 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Critical Directory Service System objects cannot be deleted during tree delete operations. The tree delete may have been partially performed.\n\nLookup forms: 8560, 0x2170, error 8560, ERROR_DS_CANT_TREE_DELETE_CRITICAL_OBJ. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8560"]},{"id":2025,"title":"ERROR_DS_INIT_FAILURE_CONSOLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8561","0x2171","error 8561","ERROR_DS_INIT_FAILURE_CONSOLE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","init","failure","console","directory","services","could","not","start","because","the","following","status","please","click","shutdown","system","you","can","use","recovery","diagnose","further"],"errorCode":"8561","eventId":"","severity":"Low","summary":"Directory Services could not start because of the following error: %1. Error Status: 0x%2. Please click OK to shutdown the system. You can use the recovery console to diagnose the system further.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8561; use the surrounding log entries to confirm it.","resolution":"1. Record where 8561 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_INIT_FAILURE_CONSOLE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8561 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Directory Services could not start because of the following error: %1. Error Status: 0x%2. Please click OK to shutdown the system. You can use the recovery console to diagnose the system further.\n\nLookup forms: 8561, 0x2171, error 8561, ERROR_DS_INIT_FAILURE_CONSOLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8561"]},{"id":2026,"title":"ERROR_DS_SAM_INIT_FAILURE_CONSOLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8562","0x2172","error 8562","ERROR_DS_SAM_INIT_FAILURE_CONSOLE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","sam","init","failure","console","security","accounts","manager","initialization","failed","because","the","following","status","please","click","shutdown","system","you","can","use","recovery","diagnose","further"],"errorCode":"8562","eventId":"","severity":"High","summary":"Security Accounts Manager initialization failed because of the following error: %1. Error Status: 0x%2. Please click OK to shutdown the system. You can use the recovery console to diagnose the system further.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8562; use the surrounding log entries to confirm it.","resolution":"1. Record where 8562 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SAM_INIT_FAILURE_CONSOLE.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8562 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Security Accounts Manager initialization failed because of the following error: %1. Error Status: 0x%2. Please click OK to shutdown the system. You can use the recovery console to diagnose the system further.\n\nLookup forms: 8562, 0x2172, error 8562, ERROR_DS_SAM_INIT_FAILURE_CONSOLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8562"]},{"id":2027,"title":"ERROR_DS_FOREST_VERSION_TOO_HIGH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8563","0x2173","error 8563","ERROR_DS_FOREST_VERSION_TOO_HIGH","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","forest","version","too","high","the","operating","system","incompatible","with","current","functional","level","lds","configuration","set","you","must","upgrade","new","before","this","server","can","become"],"errorCode":"8563","eventId":"","severity":"Low","summary":"The version of the operating system is incompatible with the current AD DS forest functional level or AD LDS Configuration Set functional level. You must upgrade to a new version of the operating system before this server can become an AD DS Domain Controller or add an AD LDS Instance in this AD DS Forest or AD LDS Configuration Set.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8563; use the surrounding log entries to confirm it.","resolution":"1. Record where 8563 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_FOREST_VERSION_TOO_HIGH.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8563 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The version of the operating system is incompatible with the current AD DS forest functional level or AD LDS Configuration Set functional level. You must upgrade to a new version of the operating system before this server can become an AD DS Domain Controller or add an AD LDS Instance in this AD DS Forest or AD LDS Configuration Set.\n\nLookup forms: 8563, 0x2173, error 8563, ERROR_DS_FOREST_VERSION_TOO_HIGH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): This version of Windows is too old to support the current directory forest behavior. You must upgrade the operating system on this server before it can become a domain controller in this forest.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8563"]},{"id":2028,"title":"ERROR_DS_DOMAIN_VERSION_TOO_HIGH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8564","0x2174","error 8564","ERROR_DS_DOMAIN_VERSION_TOO_HIGH","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","domain","version","too","high","the","operating","system","installed","incompatible","with","current","functional","level","you","must","upgrade","new","before","this","server","can","become","controller"],"errorCode":"8564","eventId":"","severity":"Low","summary":"The version of the operating system installed is incompatible with the current domain functional level. You must upgrade to a new version of the operating system before this server can become a domain controller in this domain.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8564; use the surrounding log entries to confirm it.","resolution":"1. Record where 8564 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DOMAIN_VERSION_TOO_HIGH.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8564 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The version of the operating system installed is incompatible with the current domain functional level. You must upgrade to a new version of the operating system before this server can become a domain controller in this domain.\n\nLookup forms: 8564, 0x2174, error 8564, ERROR_DS_DOMAIN_VERSION_TOO_HIGH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): This version of Windows is too old to support the current domain behavior. You must upgrade the operating system on this server before it can become a domain controller in this domain.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8564"]},{"id":2029,"title":"ERROR_DS_FOREST_VERSION_TOO_LOW","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8565","0x2175","error 8565","ERROR_DS_FOREST_VERSION_TOO_LOW","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","forest","version","too","low","the","operating","system","installed","this","server","longer","supports","current","functional","level","lds","configuration","set","you","must","raise","before","can","become"],"errorCode":"8565","eventId":"","severity":"Low","summary":"The version of the operating system installed on this server no longer supports the current AD DS Forest functional level or AD LDS Configuration Set functional level. You must raise the AD DS Forest functional level or AD LDS Configuration Set functional level before this server can become an AD DS Domain Controller or an AD LDS Instance in this Forest or Configuration Set.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8565; use the surrounding log entries to confirm it.","resolution":"1. Record where 8565 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_FOREST_VERSION_TOO_LOW.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8565 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The version of the operating system installed on this server no longer supports the current AD DS Forest functional level or AD LDS Configuration Set functional level. You must raise the AD DS Forest functional level or AD LDS Configuration Set functional level before this server can become an AD DS Domain Controller or an AD LDS Instance in this Forest or Configuration Set.\n\nLookup forms: 8565, 0x2175, error 8565, ERROR_DS_FOREST_VERSION_TOO_LOW. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): This version of Windows no longer supports the behavior version in use in this directory forest. You must advance the forest behavior version before this server can become a domain controller in the forest.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8565"]},{"id":2030,"title":"ERROR_DS_DOMAIN_VERSION_TOO_LOW","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8566","0x2176","error 8566","ERROR_DS_DOMAIN_VERSION_TOO_LOW","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","domain","version","too","low","the","operating","system","installed","this","server","longer","supports","current","functional","level","you","must","raise","before","can","become","controller"],"errorCode":"8566","eventId":"","severity":"Low","summary":"The version of the operating system installed on this server no longer supports the current domain functional level. You must raise the domain functional level before this server can become a domain controller in this domain.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8566; use the surrounding log entries to confirm it.","resolution":"1. Record where 8566 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DOMAIN_VERSION_TOO_LOW.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8566 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The version of the operating system installed on this server no longer supports the current domain functional level. You must raise the domain functional level before this server can become a domain controller in this domain.\n\nLookup forms: 8566, 0x2176, error 8566, ERROR_DS_DOMAIN_VERSION_TOO_LOW. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): This version of Windows no longer supports the behavior version in use in this domain. You must advance the domain behavior version before this server can become a domain controller in the domain.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8566"]},{"id":2031,"title":"ERROR_DS_INCOMPATIBLE_VERSION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8567","0x2177","error 8567","ERROR_DS_INCOMPATIBLE_VERSION","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","incompatible","version","the","operating","system","installed","this","server","with","functional","level","domain","forest"],"errorCode":"8567","eventId":"","severity":"Low","summary":"The version of the operating system installed on this server is incompatible with the functional level of the domain or forest.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8567; use the surrounding log entries to confirm it.","resolution":"1. Record where 8567 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_INCOMPATIBLE_VERSION.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8567 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The version of the operating system installed on this server is incompatible with the functional level of the domain or forest.\n\nLookup forms: 8567, 0x2177, error 8567, ERROR_DS_INCOMPATIBLE_VERSION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The version of Windows is incompatible with the behavior version of the domain or forest.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8567"]},{"id":2032,"title":"ERROR_DS_LOW_DSA_VERSION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8568","0x2178","error 8568","ERROR_DS_LOW_DSA_VERSION","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","low","dsa","version","the","functional","level","domain","forest","cannot","raised","requested","value","because","there","exist","one","more","controllers","that","are","lower","incompatible"],"errorCode":"8568","eventId":"","severity":"Medium","summary":"The functional level of the domain (or forest) cannot be raised to the requested value, because there exist one or more domain controllers in the domain (or forest) that are at a lower incompatible functional level.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 8568; use the surrounding log entries to confirm it.","resolution":"1. Record where 8568 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_LOW_DSA_VERSION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8568 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The functional level of the domain (or forest) cannot be raised to the requested value, because there exist one or more domain controllers in the domain (or forest) that are at a lower incompatible functional level.\n\nLookup forms: 8568, 0x2178, error 8568, ERROR_DS_LOW_DSA_VERSION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The behavior version cannot be increased to the requested value because Domain Controllers still exist with versions lower than the requested value.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8568"]},{"id":2033,"title":"ERROR_DS_NO_BEHAVIOR_VERSION_IN_MIXEDDOMAIN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8569","0x2179","error 8569","ERROR_DS_NO_BEHAVIOR_VERSION_IN_MIXEDDOMAIN","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","behavior","version","mixeddomain","the","forest","functional","level","cannot","raised","requested","value","since","one","more","domains","are","still","mixed","domain","mode","all","must","native","for"],"errorCode":"8569","eventId":"","severity":"Medium","summary":"The forest functional level cannot be raised to the requested value since one or more domains are still in mixed domain mode. All domains in the forest must be in native mode, for you to raise the forest functional level.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 8569; use the surrounding log entries to confirm it.","resolution":"1. Record where 8569 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NO_BEHAVIOR_VERSION_IN_MIXEDDOMAIN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8569 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The forest functional level cannot be raised to the requested value since one or more domains are still in mixed domain mode. All domains in the forest must be in native mode, for you to raise the forest functional level.\n\nLookup forms: 8569, 0x2179, error 8569, ERROR_DS_NO_BEHAVIOR_VERSION_IN_MIXEDDOMAIN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The behavior version value cannot be increased while the domain is still in mixed domain mode. You must first change the domain to native mode before increasing the behavior version.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8569"]},{"id":2034,"title":"ERROR_DS_NOT_SUPPORTED_SORT_ORDER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8570","0x217A","error 8570","ERROR_DS_NOT_SUPPORTED_SORT_ORDER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","not","supported","sort","order","the","requested"],"errorCode":"8570","eventId":"","severity":"Medium","summary":"The sort order requested is not supported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8570; use the surrounding log entries to confirm it.","resolution":"1. Record where 8570 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NOT_SUPPORTED_SORT_ORDER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8570 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The sort order requested is not supported.\n\nLookup forms: 8570, 0x217A, error 8570, ERROR_DS_NOT_SUPPORTED_SORT_ORDER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8570"]},{"id":2035,"title":"ERROR_DS_NAME_NOT_UNIQUE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8571","0x217B","error 8571","ERROR_DS_NAME_NOT_UNIQUE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","name","not","unique","the","requested","already","exists","identifier"],"errorCode":"8571","eventId":"","severity":"Medium","summary":"The requested name already exists as a unique identifier.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8571; use the surrounding log entries to confirm it.","resolution":"1. Record where 8571 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NAME_NOT_UNIQUE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8571 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested name already exists as a unique identifier.\n\nLookup forms: 8571, 0x217B, error 8571, ERROR_DS_NAME_NOT_UNIQUE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Found an object with a non unique name.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8571"]},{"id":2036,"title":"ERROR_DS_MACHINE_ACCOUNT_CREATED_PRENT4","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8572","0x217C","error 8572","ERROR_DS_MACHINE_ACCOUNT_CREATED_PRENT4","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","machine","account","created","prent4","the","was","pre","nt4","needs","recreated"],"errorCode":"8572","eventId":"","severity":"Low","summary":"The machine account was created pre-NT4. The account needs to be recreated.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8572; use the surrounding log entries to confirm it.","resolution":"1. Record where 8572 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_MACHINE_ACCOUNT_CREATED_PRENT4.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8572 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The machine account was created pre-NT4. The account needs to be recreated.\n\nLookup forms: 8572, 0x217C, error 8572, ERROR_DS_MACHINE_ACCOUNT_CREATED_PRENT4. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8572"]},{"id":2037,"title":"ERROR_DS_OUT_OF_VERSION_STORE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8573","0x217D","error 8573","ERROR_DS_OUT_OF_VERSION_STORE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","out","version","store","the","database"],"errorCode":"8573","eventId":"","severity":"Low","summary":"The database is out of version store.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8573; use the surrounding log entries to confirm it.","resolution":"1. Record where 8573 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_OUT_OF_VERSION_STORE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8573 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The database is out of version store.\n\nLookup forms: 8573, 0x217D, error 8573, ERROR_DS_OUT_OF_VERSION_STORE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8573"]},{"id":2038,"title":"ERROR_DS_INCOMPATIBLE_CONTROLS_USED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8574","0x217E","error 8574","ERROR_DS_INCOMPATIBLE_CONTROLS_USED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","incompatible","controls","used","unable","continue","operation","because","multiple","conflicting","were"],"errorCode":"8574","eventId":"","severity":"Medium","summary":"Unable to continue operation because multiple conflicting controls were used.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8574; use the surrounding log entries to confirm it.","resolution":"1. Record where 8574 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_INCOMPATIBLE_CONTROLS_USED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8574 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to continue operation because multiple conflicting controls were used.\n\nLookup forms: 8574, 0x217E, error 8574, ERROR_DS_INCOMPATIBLE_CONTROLS_USED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8574"]},{"id":2039,"title":"ERROR_DS_NO_REF_DOMAIN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8575","0x217F","error 8575","ERROR_DS_NO_REF_DOMAIN","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ref","domain","unable","find","valid","security","descriptor","reference","for","this","partition"],"errorCode":"8575","eventId":"","severity":"Medium","summary":"Unable to find a valid security descriptor reference domain for this partition.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8575; use the surrounding log entries to confirm it.","resolution":"1. Record where 8575 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NO_REF_DOMAIN.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8575 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to find a valid security descriptor reference domain for this partition.\n\nLookup forms: 8575, 0x217F, error 8575, ERROR_DS_NO_REF_DOMAIN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8575"]},{"id":2040,"title":"ERROR_DS_RESERVED_LINK_ID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8576","0x2180","error 8576","ERROR_DS_RESERVED_LINK_ID","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","reserved","link","schema","update","failed","the","identifier"],"errorCode":"8576","eventId":"","severity":"High","summary":"Schema update failed: The link identifier is reserved.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 8576; use the surrounding log entries to confirm it.","resolution":"1. Record where 8576 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_RESERVED_LINK_ID.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8576 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema update failed: The link identifier is reserved.\n\nLookup forms: 8576, 0x2180, error 8576, ERROR_DS_RESERVED_LINK_ID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8576"]},{"id":2041,"title":"ERROR_DS_LINK_ID_NOT_AVAILABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8577","0x2181","error 8577","ERROR_DS_LINK_ID_NOT_AVAILABLE","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","link","not","available","schema","update","failed","there","are","identifiers"],"errorCode":"8577","eventId":"","severity":"High","summary":"Schema update failed: There are no link identifiers available.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 8577; use the surrounding log entries to confirm it.","resolution":"1. Record where 8577 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_LINK_ID_NOT_AVAILABLE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8577 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema update failed: There are no link identifiers available.\n\nLookup forms: 8577, 0x2181, error 8577, ERROR_DS_LINK_ID_NOT_AVAILABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8577"]},{"id":2042,"title":"ERROR_DS_AG_CANT_HAVE_UNIVERSAL_MEMBER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8578","0x2182","error 8578","ERROR_DS_AG_CANT_HAVE_UNIVERSAL_MEMBER","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","cant","have","universal","member","account","group","cannot"],"errorCode":"8578","eventId":"","severity":"Medium","summary":"An account group cannot have a universal group as a member.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8578; use the surrounding log entries to confirm it.","resolution":"1. Record where 8578 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_AG_CANT_HAVE_UNIVERSAL_MEMBER.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8578 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An account group cannot have a universal group as a member.\n\nLookup forms: 8578, 0x2182, error 8578, ERROR_DS_AG_CANT_HAVE_UNIVERSAL_MEMBER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8578"]},{"id":2043,"title":"ERROR_DS_MODIFYDN_DISALLOWED_BY_INSTANCE_TYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8579","0x2183","error 8579","ERROR_DS_MODIFYDN_DISALLOWED_BY_INSTANCE_TYPE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","modifydn","disallowed","instance","type","rename","move","operations","naming","context","heads","read","only","objects","are","not","allowed"],"errorCode":"8579","eventId":"","severity":"Low","summary":"Rename or move operations on naming context heads or read-only objects are not allowed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8579; use the surrounding log entries to confirm it.","resolution":"1. Record where 8579 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_MODIFYDN_DISALLOWED_BY_INSTANCE_TYPE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8579 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Rename or move operations on naming context heads or read-only objects are not allowed.\n\nLookup forms: 8579, 0x2183, error 8579, ERROR_DS_MODIFYDN_DISALLOWED_BY_INSTANCE_TYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8579"]},{"id":2044,"title":"ERROR_DS_NO_OBJECT_MOVE_IN_SCHEMA_NC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8580","0x2184","error 8580","ERROR_DS_NO_OBJECT_MOVE_IN_SCHEMA_NC","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","object","move","schema","operations","objects","the","naming","context","are","not","allowed"],"errorCode":"8580","eventId":"","severity":"Low","summary":"Move operations on objects in the schema naming context are not allowed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8580; use the surrounding log entries to confirm it.","resolution":"1. Record where 8580 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NO_OBJECT_MOVE_IN_SCHEMA_NC.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8580 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Move operations on objects in the schema naming context are not allowed.\n\nLookup forms: 8580, 0x2184, error 8580, ERROR_DS_NO_OBJECT_MOVE_IN_SCHEMA_NC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8580"]},{"id":2045,"title":"ERROR_DS_MODIFYDN_DISALLOWED_BY_FLAG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8581","0x2185","error 8581","ERROR_DS_MODIFYDN_DISALLOWED_BY_FLAG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","modifydn","disallowed","flag","system","has","been","set","the","object","and","does","not","allow","moved","renamed"],"errorCode":"8581","eventId":"","severity":"Low","summary":"A system flag has been set on the object and does not allow the object to be moved or renamed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8581; use the surrounding log entries to confirm it.","resolution":"1. Record where 8581 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_MODIFYDN_DISALLOWED_BY_FLAG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8581 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A system flag has been set on the object and does not allow the object to be moved or renamed.\n\nLookup forms: 8581, 0x2185, error 8581, ERROR_DS_MODIFYDN_DISALLOWED_BY_FLAG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8581"]},{"id":2046,"title":"ERROR_DS_MODIFYDN_WRONG_GRANDPARENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8582","0x2186","error 8582","ERROR_DS_MODIFYDN_WRONG_GRANDPARENT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","modifydn","wrong","grandparent","this","object","not","allowed","change","its","container","moves","are","forbidden","but","restricted","sibling","containers"],"errorCode":"8582","eventId":"","severity":"Low","summary":"This object is not allowed to change its grandparent container. Moves are not forbidden on this object, but are restricted to sibling containers.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8582; use the surrounding log entries to confirm it.","resolution":"1. Record where 8582 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_MODIFYDN_WRONG_GRANDPARENT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8582 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This object is not allowed to change its grandparent container. Moves are not forbidden on this object, but are restricted to sibling containers.\n\nLookup forms: 8582, 0x2186, error 8582, ERROR_DS_MODIFYDN_WRONG_GRANDPARENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8582"]},{"id":2047,"title":"ERROR_DS_NAME_ERROR_TRUST_REFERRAL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8583","0x2187","error 8583","ERROR_DS_NAME_ERROR_TRUST_REFERRAL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","name","trust","referral","unable","resolve","completely","another","forest","generated"],"errorCode":"8583","eventId":"","severity":"Medium","summary":"Unable to resolve completely, a referral to another forest is generated.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8583; use the surrounding log entries to confirm it.","resolution":"1. Record where 8583 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NAME_ERROR_TRUST_REFERRAL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8583 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to resolve completely, a referral to another forest is generated.\n\nLookup forms: 8583, 0x2187, error 8583, ERROR_DS_NAME_ERROR_TRUST_REFERRAL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8583"]},{"id":2048,"title":"ERROR_NOT_SUPPORTED_ON_STANDARD_SERVER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8584","0x2188","error 8584","ERROR_NOT_SUPPORTED_ON_STANDARD_SERVER","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","not","supported","standard","server","the","requested","action"],"errorCode":"8584","eventId":"","severity":"Medium","summary":"The requested action is not supported on standard server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8584; use the surrounding log entries to confirm it.","resolution":"1. Record where 8584 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NOT_SUPPORTED_ON_STANDARD_SERVER.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8584 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested action is not supported on standard server.\n\nLookup forms: 8584, 0x2188, error 8584, ERROR_NOT_SUPPORTED_ON_STANDARD_SERVER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8584"]},{"id":2049,"title":"ERROR_DS_CANT_ACCESS_REMOTE_PART_OF_AD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8585","0x2189","error 8585","ERROR_DS_CANT_ACCESS_REMOTE_PART_OF_AD","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","cant","access","remote","part","could","not","partition","the","directory","service","located","server","make","sure","least","one","running","for","question"],"errorCode":"8585","eventId":"","severity":"Low","summary":"Could not access a partition of the directory service located on a remote server. Make sure at least one server is running for the partition in question.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8585; use the surrounding log entries to confirm it.","resolution":"1. Record where 8585 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Confirm the user or service identity has the required permissions and is not locked or disabled.\n4. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n5. Verify the required service or agent is installed, running, and current; repair the component if needed.\n6. Review Event Viewer and the application or service log for the same timestamp and code.\n7. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_ACCESS_REMOTE_PART_OF_AD.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Confirm the user or service identity has the required permissions and is not locked or disabled.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8585 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Could not access a partition of the directory service located on a remote server. Make sure at least one server is running for the partition in question.\n\nLookup forms: 8585, 0x2189, error 8585, ERROR_DS_CANT_ACCESS_REMOTE_PART_OF_AD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Could not access a partition of the Active Directory located on a remote server. Make sure at least one server is running for the partition in question.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8585"]},{"id":2050,"title":"ERROR_DS_CR_IMPOSSIBLE_TO_VALIDATE_V2","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8586","0x218A","error 8586","ERROR_DS_CR_IMPOSSIBLE_TO_VALIDATE_V2","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","impossible","validate","the","directory","cannot","proposed","naming","context","partition","name","because","does","not","hold","replica","nor","can","contact","above","please","ensure","that","parent","properly"],"errorCode":"8586","eventId":"","severity":"Medium","summary":"The directory cannot validate the proposed naming context (or partition) name because it does not hold a replica nor can it contact a replica of the naming context above the proposed naming context. Please ensure that the parent naming context is properly registered in DNS, and at least one replica of this naming context is reachable by the Domain Naming master.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8586; use the surrounding log entries to confirm it.","resolution":"1. Record where 8586 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CR_IMPOSSIBLE_TO_VALIDATE_V2.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8586 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory cannot validate the proposed naming context (or partition) name because it does not hold a replica nor can it contact a replica of the naming context above the proposed naming context. Please ensure that the parent naming context is properly registered in DNS, and at least one replica of this naming context is reachable by the Domain Naming master.\n\nLookup forms: 8586, 0x218A, error 8586, ERROR_DS_CR_IMPOSSIBLE_TO_VALIDATE_V2. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8586"]},{"id":2051,"title":"ERROR_DS_THREAD_LIMIT_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8587","0x218B","error 8587","ERROR_DS_THREAD_LIMIT_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","thread","limit","exceeded","the","for","this","request","was"],"errorCode":"8587","eventId":"","severity":"Low","summary":"The thread limit for this request was exceeded.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 8587; use the surrounding log entries to confirm it.","resolution":"1. Record where 8587 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_THREAD_LIMIT_EXCEEDED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8587 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The thread limit for this request was exceeded.\n\nLookup forms: 8587, 0x218B, error 8587, ERROR_DS_THREAD_LIMIT_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8587"]},{"id":2052,"title":"ERROR_DS_NOT_CLOSEST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8588","0x218C","error 8588","ERROR_DS_NOT_CLOSEST","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","not","closest","the","global","catalog","server","site"],"errorCode":"8588","eventId":"","severity":"Low","summary":"The Global catalog server is not in the closest site.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8588; use the surrounding log entries to confirm it.","resolution":"1. Record where 8588 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NOT_CLOSEST.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8588 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Global catalog server is not in the closest site.\n\nLookup forms: 8588, 0x218C, error 8588, ERROR_DS_NOT_CLOSEST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The Global catalog server is not in the closet site.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8588"]},{"id":2053,"title":"ERROR_DS_CANT_DERIVE_SPN_WITHOUT_SERVER_REF","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8589","0x218D","error 8589","ERROR_DS_CANT_DERIVE_SPN_WITHOUT_SERVER_REF","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","cant","derive","spn","without","server","ref","the","cannot","service","principal","name","with","which","mutually","authenticate","target","because","corresponding","object","local","database","has","serverreference","attribute"],"errorCode":"8589","eventId":"","severity":"Medium","summary":"The DS cannot derive a service principal name (SPN) with which to mutually authenticate the target server because the corresponding server object in the local DS database has no serverReference attribute.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8589; use the surrounding log entries to confirm it.","resolution":"1. Record where 8589 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_DERIVE_SPN_WITHOUT_SERVER_REF.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8589 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The DS cannot derive a service principal name (SPN) with which to mutually authenticate the target server because the corresponding server object in the local DS database has no serverReference attribute.\n\nLookup forms: 8589, 0x218D, error 8589, ERROR_DS_CANT_DERIVE_SPN_WITHOUT_SERVER_REF. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8589"]},{"id":2054,"title":"ERROR_DS_SINGLE_USER_MODE_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8590","0x218E","error 8590","ERROR_DS_SINGLE_USER_MODE_FAILED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","single","user","mode","failed","the","directory","service","enter"],"errorCode":"8590","eventId":"","severity":"High","summary":"The Directory Service failed to enter single user mode.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8590; use the surrounding log entries to confirm it.","resolution":"1. Record where 8590 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SINGLE_USER_MODE_FAILED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8590 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Directory Service failed to enter single user mode.\n\nLookup forms: 8590, 0x218E, error 8590, ERROR_DS_SINGLE_USER_MODE_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8590"]},{"id":2055,"title":"ERROR_DS_NTDSCRIPT_SYNTAX_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8591","0x218F","error 8591","ERROR_DS_NTDSCRIPT_SYNTAX_ERROR","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","ntdscript","syntax","the","directory","service","cannot","parse","script","because"],"errorCode":"8591","eventId":"","severity":"Medium","summary":"The Directory Service cannot parse the script because of a syntax error.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8591; use the surrounding log entries to confirm it.","resolution":"1. Record where 8591 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NTDSCRIPT_SYNTAX_ERROR.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8591 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Directory Service cannot parse the script because of a syntax error.\n\nLookup forms: 8591, 0x218F, error 8591, ERROR_DS_NTDSCRIPT_SYNTAX_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8591"]},{"id":2056,"title":"ERROR_DS_NTDSCRIPT_PROCESS_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8592","0x2190","error 8592","ERROR_DS_NTDSCRIPT_PROCESS_ERROR","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","ntdscript","process","the","directory","service","cannot","script","because"],"errorCode":"8592","eventId":"","severity":"Medium","summary":"The Directory Service cannot process the script because of an error.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8592; use the surrounding log entries to confirm it.","resolution":"1. Record where 8592 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NTDSCRIPT_PROCESS_ERROR.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8592 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Directory Service cannot process the script because of an error.\n\nLookup forms: 8592, 0x2190, error 8592, ERROR_DS_NTDSCRIPT_PROCESS_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8592"]},{"id":2057,"title":"ERROR_DS_DIFFERENT_REPL_EPOCHS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8593","0x2191","error 8593","ERROR_DS_DIFFERENT_REPL_EPOCHS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","different","repl","epochs","the","directory","service","cannot","perform","requested","operation","because","servers","involved","are","replication","which","usually","related","domain","rename","that","progress"],"errorCode":"8593","eventId":"","severity":"Medium","summary":"The directory service cannot perform the requested operation because the servers involved are of different replication epochs (which is usually related to a domain rename that is in progress).","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8593; use the surrounding log entries to confirm it.","resolution":"1. Record where 8593 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Verify the required service or agent is installed, running, and current; repair the component if needed.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DIFFERENT_REPL_EPOCHS.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8593 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service cannot perform the requested operation because the servers involved are of different replication epochs (which is usually related to a domain rename that is in progress).\n\nLookup forms: 8593, 0x2191, error 8593, ERROR_DS_DIFFERENT_REPL_EPOCHS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8593"]},{"id":2058,"title":"ERROR_DS_DRS_EXTENSIONS_CHANGED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8594","0x2192","error 8594","ERROR_DS_DRS_EXTENSIONS_CHANGED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","drs","extensions","changed","the","directory","service","binding","must","renegotiated","due","change","server","information"],"errorCode":"8594","eventId":"","severity":"Low","summary":"The directory service binding must be renegotiated due to a change in the server extensions information.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8594; use the surrounding log entries to confirm it.","resolution":"1. Record where 8594 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Verify the required service or agent is installed, running, and current; repair the component if needed.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRS_EXTENSIONS_CHANGED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8594 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service binding must be renegotiated due to a change in the server extensions information.\n\nLookup forms: 8594, 0x2192, error 8594, ERROR_DS_DRS_EXTENSIONS_CHANGED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8594"]},{"id":2059,"title":"ERROR_DS_REPLICA_SET_CHANGE_NOT_ALLOWED_ON_DISABLED_CR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8595","0x2193","error 8595","ERROR_DS_REPLICA_SET_CHANGE_NOT_ALLOWED_ON_DISABLED_CR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","replica","set","change","not","allowed","disabled","operation","cross","ref"],"errorCode":"8595","eventId":"","severity":"Low","summary":"Operation not allowed on a disabled cross ref.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8595; use the surrounding log entries to confirm it.","resolution":"1. Record where 8595 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_REPLICA_SET_CHANGE_NOT_ALLOWED_ON_DISABLED_CR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8595 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Operation not allowed on a disabled cross ref.\n\nLookup forms: 8595, 0x2193, error 8595, ERROR_DS_REPLICA_SET_CHANGE_NOT_ALLOWED_ON_DISABLED_CR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8595"]},{"id":2060,"title":"ERROR_DS_NO_MSDS_INTID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8596","0x2194","error 8596","ERROR_DS_NO_MSDS_INTID","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","msds","intid","schema","update","failed","values","for","are","available"],"errorCode":"8596","eventId":"","severity":"High","summary":"Schema update failed: No values for msDS-IntId are available.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 8596; use the surrounding log entries to confirm it.","resolution":"1. Record where 8596 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NO_MSDS_INTID.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8596 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema update failed: No values for msDS-IntId are available.\n\nLookup forms: 8596, 0x2194, error 8596, ERROR_DS_NO_MSDS_INTID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8596"]},{"id":2061,"title":"ERROR_DS_DUP_MSDS_INTID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8597","0x2195","error 8597","ERROR_DS_DUP_MSDS_INTID","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","dup","msds","intid","schema","update","failed","duplicate","retry","the","operation"],"errorCode":"8597","eventId":"","severity":"High","summary":"Schema update failed: Duplicate msDS-INtId. Retry the operation.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 8597; use the surrounding log entries to confirm it.","resolution":"1. Record where 8597 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DUP_MSDS_INTID.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8597 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema update failed: Duplicate msDS-INtId. Retry the operation.\n\nLookup forms: 8597, 0x2195, error 8597, ERROR_DS_DUP_MSDS_INTID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8597"]},{"id":2062,"title":"ERROR_DS_EXISTS_IN_RDNATTID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8598","0x2196","error 8598","ERROR_DS_EXISTS_IN_RDNATTID","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","exists","rdnattid","schema","deletion","failed","attribute","used"],"errorCode":"8598","eventId":"","severity":"High","summary":"Schema deletion failed: attribute is used in rDNAttID.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8598; use the surrounding log entries to confirm it.","resolution":"1. Record where 8598 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_EXISTS_IN_RDNATTID.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8598 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema deletion failed: attribute is used in rDNAttID.\n\nLookup forms: 8598, 0x2196, error 8598, ERROR_DS_EXISTS_IN_RDNATTID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8598"]},{"id":2063,"title":"ERROR_DS_AUTHORIZATION_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8599","0x2197","error 8599","ERROR_DS_AUTHORIZATION_FAILED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","authorization","failed","the","directory","service","authorize","request"],"errorCode":"8599","eventId":"","severity":"High","summary":"The directory service failed to authorize the request.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8599; use the surrounding log entries to confirm it.","resolution":"1. Record where 8599 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_AUTHORIZATION_FAILED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8599 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service failed to authorize the request.\n\nLookup forms: 8599, 0x2197, error 8599, ERROR_DS_AUTHORIZATION_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8599"]},{"id":2064,"title":"ERROR_DS_INVALID_SCRIPT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8600","0x2198","error 8600","ERROR_DS_INVALID_SCRIPT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","invalid","script","the","directory","service","cannot","process","because"],"errorCode":"8600","eventId":"","severity":"Medium","summary":"The Directory Service cannot process the script because it is invalid.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8600; use the surrounding log entries to confirm it.","resolution":"1. Record where 8600 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_INVALID_SCRIPT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8600 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Directory Service cannot process the script because it is invalid.\n\nLookup forms: 8600, 0x2198, error 8600, ERROR_DS_INVALID_SCRIPT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8600"]},{"id":2065,"title":"ERROR_DS_REMOTE_CROSSREF_OP_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8601","0x2199","error 8601","ERROR_DS_REMOTE_CROSSREF_OP_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","remote","crossref","failed","the","create","cross","reference","operation","domain","naming","master","fsmo","extended","data"],"errorCode":"8601","eventId":"","severity":"High","summary":"The remote create cross reference operation failed on the Domain Naming Master FSMO. The operation's error is in the extended data.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8601; use the surrounding log entries to confirm it.","resolution":"1. Record where 8601 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_REMOTE_CROSSREF_OP_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8601 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The remote create cross reference operation failed on the Domain Naming Master FSMO. The operation's error is in the extended data.\n\nLookup forms: 8601, 0x2199, error 8601, ERROR_DS_REMOTE_CROSSREF_OP_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8601"]},{"id":2066,"title":"ERROR_DS_CROSS_REF_BUSY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8602","0x219A","error 8602","ERROR_DS_CROSS_REF_BUSY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cross","ref","busy","reference","use","locally","with","the","same","name"],"errorCode":"8602","eventId":"","severity":"Low","summary":"A cross reference is in use locally with the same name.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8602; use the surrounding log entries to confirm it.","resolution":"1. Record where 8602 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CROSS_REF_BUSY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8602 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A cross reference is in use locally with the same name.\n\nLookup forms: 8602, 0x219A, error 8602, ERROR_DS_CROSS_REF_BUSY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8602"]},{"id":2067,"title":"ERROR_DS_CANT_DERIVE_SPN_FOR_DELETED_DOMAIN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8603","0x219B","error 8603","ERROR_DS_CANT_DERIVE_SPN_FOR_DELETED_DOMAIN","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","cant","derive","spn","for","deleted","domain","the","cannot","service","principal","name","with","which","mutually","authenticate","target","server","because","has","been","from","forest"],"errorCode":"8603","eventId":"","severity":"Medium","summary":"The DS cannot derive a service principal name (SPN) with which to mutually authenticate the target server because the server's domain has been deleted from the forest.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8603; use the surrounding log entries to confirm it.","resolution":"1. Record where 8603 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_DERIVE_SPN_FOR_DELETED_DOMAIN.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8603 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The DS cannot derive a service principal name (SPN) with which to mutually authenticate the target server because the server's domain has been deleted from the forest.\n\nLookup forms: 8603, 0x219B, error 8603, ERROR_DS_CANT_DERIVE_SPN_FOR_DELETED_DOMAIN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8603"]},{"id":2068,"title":"ERROR_DS_CANT_DEMOTE_WITH_WRITEABLE_NC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8604","0x219C","error 8604","ERROR_DS_CANT_DEMOTE_WITH_WRITEABLE_NC","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","demote","with","writeable","ncs","prevent","this","from","demoting"],"errorCode":"8604","eventId":"","severity":"Low","summary":"Writeable NCs prevent this DC from demoting.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8604; use the surrounding log entries to confirm it.","resolution":"1. Record where 8604 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_DEMOTE_WITH_WRITEABLE_NC.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8604 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Writeable NCs prevent this DC from demoting.\n\nLookup forms: 8604, 0x219C, error 8604, ERROR_DS_CANT_DEMOTE_WITH_WRITEABLE_NC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8604"]},{"id":2069,"title":"ERROR_DS_DUPLICATE_ID_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8605","0x219D","error 8605","ERROR_DS_DUPLICATE_ID_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","duplicate","found","the","requested","object","has","non","unique","identifier","and","cannot","retrieved"],"errorCode":"8605","eventId":"","severity":"Medium","summary":"The requested object has a non-unique identifier and cannot be retrieved.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8605; use the surrounding log entries to confirm it.","resolution":"1. Record where 8605 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DUPLICATE_ID_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8605 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested object has a non-unique identifier and cannot be retrieved.\n\nLookup forms: 8605, 0x219D, error 8605, ERROR_DS_DUPLICATE_ID_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8605"]},{"id":2070,"title":"ERROR_DS_INSUFFICIENT_ATTR_TO_CREATE_OBJECT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8606","0x219E","error 8606","ERROR_DS_INSUFFICIENT_ATTR_TO_CREATE_OBJECT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","insufficient","attr","create","object","attributes","were","given","this","may","not","exist","because","have","been","deleted","and","already","garbage","collected"],"errorCode":"8606","eventId":"","severity":"Low","summary":"Insufficient attributes were given to create an object. This object may not exist because it may have been deleted and already garbage collected.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8606; use the surrounding log entries to confirm it.","resolution":"1. Record where 8606 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_INSUFFICIENT_ATTR_TO_CREATE_OBJECT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8606 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Insufficient attributes were given to create an object. This object may not exist because it may have been deleted and already garbage collected.\n\nLookup forms: 8606, 0x219E, error 8606, ERROR_DS_INSUFFICIENT_ATTR_TO_CREATE_OBJECT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8606"]},{"id":2071,"title":"ERROR_DS_GROUP_CONVERSION_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8607","0x219F","error 8607","ERROR_DS_GROUP_CONVERSION_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","group","conversion","the","cannot","converted","due","attribute","restrictions","requested","type"],"errorCode":"8607","eventId":"","severity":"Medium","summary":"The group cannot be converted due to attribute restrictions on the requested group type.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8607; use the surrounding log entries to confirm it.","resolution":"1. Record where 8607 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_GROUP_CONVERSION_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8607 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The group cannot be converted due to attribute restrictions on the requested group type.\n\nLookup forms: 8607, 0x219F, error 8607, ERROR_DS_GROUP_CONVERSION_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8607"]},{"id":2072,"title":"ERROR_DS_CANT_MOVE_APP_BASIC_GROUP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8608","0x21A0","error 8608","ERROR_DS_CANT_MOVE_APP_BASIC_GROUP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","move","app","basic","group","cross","domain","non","empty","application","groups","not","allowed"],"errorCode":"8608","eventId":"","severity":"Low","summary":"Cross-domain move of non-empty basic application groups is not allowed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8608; use the surrounding log entries to confirm it.","resolution":"1. Record where 8608 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_MOVE_APP_BASIC_GROUP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8608 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cross-domain move of non-empty basic application groups is not allowed.\n\nLookup forms: 8608, 0x21A0, error 8608, ERROR_DS_CANT_MOVE_APP_BASIC_GROUP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8608"]},{"id":2073,"title":"ERROR_DS_CANT_MOVE_APP_QUERY_GROUP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8609","0x21A1","error 8609","ERROR_DS_CANT_MOVE_APP_QUERY_GROUP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cant","move","app","query","group","cross","domain","non","empty","based","application","groups","not","allowed"],"errorCode":"8609","eventId":"","severity":"Low","summary":"Cross-domain move of non-empty query based application groups is not allowed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8609; use the surrounding log entries to confirm it.","resolution":"1. Record where 8609 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_CANT_MOVE_APP_QUERY_GROUP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8609 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cross-domain move of non-empty query based application groups is not allowed.\n\nLookup forms: 8609, 0x21A1, error 8609, ERROR_DS_CANT_MOVE_APP_QUERY_GROUP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8609"]},{"id":2074,"title":"ERROR_DS_ROLE_NOT_VERIFIED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8610","0x21A2","error 8610","ERROR_DS_ROLE_NOT_VERIFIED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","role","not","verified","the","fsmo","ownership","could","because","its","directory","partition","has","replicated","successfully","with","least","one","replication","partner"],"errorCode":"8610","eventId":"","severity":"Low","summary":"The FSMO role ownership could not be verified because its directory partition has not replicated successfully with at least one replication partner.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8610; use the surrounding log entries to confirm it.","resolution":"1. Record where 8610 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_ROLE_NOT_VERIFIED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8610 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The FSMO role ownership could not be verified because its directory partition has not replicated successfully with at least one replication partner.\n\nLookup forms: 8610, 0x21A2, error 8610, ERROR_DS_ROLE_NOT_VERIFIED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8610"]},{"id":2075,"title":"ERROR_DS_WKO_CONTAINER_CANNOT_BE_SPECIAL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8611","0x21A3","error 8611","ERROR_DS_WKO_CONTAINER_CANNOT_BE_SPECIAL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","wko","container","cannot","special","the","target","for","redirection","well","known","object","already"],"errorCode":"8611","eventId":"","severity":"Medium","summary":"The target container for a redirection of a well known object container cannot already be a special container.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8611; use the surrounding log entries to confirm it.","resolution":"1. Record where 8611 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_WKO_CONTAINER_CANNOT_BE_SPECIAL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8611 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The target container for a redirection of a well known object container cannot already be a special container.\n\nLookup forms: 8611, 0x21A3, error 8611, ERROR_DS_WKO_CONTAINER_CANNOT_BE_SPECIAL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8611"]},{"id":2076,"title":"ERROR_DS_DOMAIN_RENAME_IN_PROGRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8612","0x21A4","error 8612","ERROR_DS_DOMAIN_RENAME_IN_PROGRESS","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","domain","rename","progress","the","directory","service","cannot","perform","requested","operation","because"],"errorCode":"8612","eventId":"","severity":"Medium","summary":"The Directory Service cannot perform the requested operation because a domain rename operation is in progress.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8612; use the surrounding log entries to confirm it.","resolution":"1. Record where 8612 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DOMAIN_RENAME_IN_PROGRESS.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8612 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Directory Service cannot perform the requested operation because a domain rename operation is in progress.\n\nLookup forms: 8612, 0x21A4, error 8612, ERROR_DS_DOMAIN_RENAME_IN_PROGRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8612"]},{"id":2077,"title":"ERROR_DS_EXISTING_AD_CHILD_NC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8613","0x21A5","error 8613","ERROR_DS_EXISTING_AD_CHILD_NC","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","existing","child","the","directory","service","detected","partition","below","requested","name","hierarchy","must","created","top","down","method"],"errorCode":"8613","eventId":"","severity":"Low","summary":"The directory service detected a child partition below the requested partition name. The partition hierarchy must be created in a top down method.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 8613; use the surrounding log entries to confirm it.","resolution":"1. Record where 8613 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_EXISTING_AD_CHILD_NC.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8613 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service detected a child partition below the requested partition name. The partition hierarchy must be created in a top down method.\n\nLookup forms: 8613, 0x21A5, error 8613, ERROR_DS_EXISTING_AD_CHILD_NC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8613"]},{"id":2078,"title":"ERROR_DS_REPL_LIFETIME_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8614","0x21A6","error 8614","ERROR_DS_REPL_LIFETIME_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","repl","lifetime","exceeded","the","directory","service","cannot","replicate","with","this","server","because","time","since","last","replication","has","tombstone"],"errorCode":"8614","eventId":"","severity":"Medium","summary":"The directory service cannot replicate with this server because the time since the last replication with this server has exceeded the tombstone lifetime.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8614; use the surrounding log entries to confirm it.","resolution":"1. Record where 8614 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Verify the required service or agent is installed, running, and current; repair the component if needed.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_REPL_LIFETIME_EXCEEDED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8614 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service cannot replicate with this server because the time since the last replication with this server has exceeded the tombstone lifetime.\n\nLookup forms: 8614, 0x21A6, error 8614, ERROR_DS_REPL_LIFETIME_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8614"]},{"id":2079,"title":"ERROR_DS_DISALLOWED_IN_SYSTEM_CONTAINER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8615","0x21A7","error 8615","ERROR_DS_DISALLOWED_IN_SYSTEM_CONTAINER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","disallowed","system","container","the","requested","operation","not","allowed","object","under"],"errorCode":"8615","eventId":"","severity":"Low","summary":"The requested operation is not allowed on an object under the system container.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8615; use the surrounding log entries to confirm it.","resolution":"1. Record where 8615 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DISALLOWED_IN_SYSTEM_CONTAINER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8615 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested operation is not allowed on an object under the system container.\n\nLookup forms: 8615, 0x21A7, error 8615, ERROR_DS_DISALLOWED_IN_SYSTEM_CONTAINER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8615"]},{"id":2080,"title":"ERROR_DS_LDAP_SEND_QUEUE_FULL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8616","0x21A8","error 8616","ERROR_DS_LDAP_SEND_QUEUE_FULL","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","ldap","send","queue","full","the","servers","network","has","filled","because","client","not","processing","results","its","requests","fast","enough","more","will","processed","until","catches","does"],"errorCode":"8616","eventId":"","severity":"High","summary":"The LDAP servers network send queue has filled up because the client is not processing the results of its requests fast enough. No more requests will be processed until the client catches up. If the client does not catch up then it will be disconnected.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8616; use the surrounding log entries to confirm it.","resolution":"1. Record where 8616 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_LDAP_SEND_QUEUE_FULL.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8616 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The LDAP servers network send queue has filled up because the client is not processing the results of its requests fast enough. No more requests will be processed until the client catches up. If the client does not catch up then it will be disconnected.\n\nLookup forms: 8616, 0x21A8, error 8616, ERROR_DS_LDAP_SEND_QUEUE_FULL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8616"]},{"id":2081,"title":"ERROR_DS_DRA_OUT_SCHEDULE_WINDOW","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8617","0x21A9","error 8617","ERROR_DS_DRA_OUT_SCHEDULE_WINDOW","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dra","out","schedule","window","the","scheduled","replication","did","not","take","place","because","system","was","too","busy","execute","request","within","queue","overloaded","consider","reducing","number"],"errorCode":"8617","eventId":"","severity":"Medium","summary":"The scheduled replication did not take place because the system was too busy to execute the request within the schedule window. The replication queue is overloaded. Consider reducing the number of partners or decreasing the scheduled replication frequency.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8617; use the surrounding log entries to confirm it.","resolution":"1. Record where 8617 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_OUT_SCHEDULE_WINDOW.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8617 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The scheduled replication did not take place because the system was too busy to execute the request within the schedule window. The replication queue is overloaded. Consider reducing the number of partners or decreasing the scheduled replication frequency.\n\nLookup forms: 8617, 0x21A9, error 8617, ERROR_DS_DRA_OUT_SCHEDULE_WINDOW. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8617"]},{"id":2082,"title":"ERROR_DS_POLICY_NOT_KNOWN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8618","0x21AA","error 8618","ERROR_DS_POLICY_NOT_KNOWN","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","policy","not","known","this","time","cannot","determined","the","branch","replication","available","hub","domain","controller","please","retry","later","account","for","latencies"],"errorCode":"8618","eventId":"","severity":"Medium","summary":"At this time, it cannot be determined if the branch replication policy is available on the hub domain controller. Please retry at a later time to account for replication latencies.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8618; use the surrounding log entries to confirm it.","resolution":"1. Record where 8618 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_POLICY_NOT_KNOWN.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8618 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: At this time, it cannot be determined if the branch replication policy is available on the hub domain controller. Please retry at a later time to account for replication latencies.\n\nLookup forms: 8618, 0x21AA, error 8618, ERROR_DS_POLICY_NOT_KNOWN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8618"]},{"id":2083,"title":"ERROR_NO_SITE_SETTINGS_OBJECT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8619","0x21AB","error 8619","ERROR_NO_SITE_SETTINGS_OBJECT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","site","settings","object","the","for","specified","does","not","exist"],"errorCode":"8619","eventId":"","severity":"Low","summary":"The site settings object for the specified site does not exist.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8619; use the surrounding log entries to confirm it.","resolution":"1. Record where 8619 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_SITE_SETTINGS_OBJECT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8619 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The site settings object for the specified site does not exist.\n\nLookup forms: 8619, 0x21AB, error 8619, ERROR_NO_SITE_SETTINGS_OBJECT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8619"]},{"id":2084,"title":"ERROR_NO_SECRETS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8620","0x21AC","error 8620","ERROR_NO_SECRETS","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","secrets","the","local","account","store","does","not","contain","secret","material","for","specified"],"errorCode":"8620","eventId":"","severity":"Low","summary":"The local account store does not contain secret material for the specified account.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8620; use the surrounding log entries to confirm it.","resolution":"1. Record where 8620 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_SECRETS.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8620 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The local account store does not contain secret material for the specified account.\n\nLookup forms: 8620, 0x21AC, error 8620, ERROR_NO_SECRETS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8620"]},{"id":2085,"title":"ERROR_NO_WRITABLE_DC_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8621","0x21AD","error 8621","ERROR_NO_WRITABLE_DC_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","writable","found","could","not","find","domain","controller","the"],"errorCode":"8621","eventId":"","severity":"Low","summary":"Could not find a writable domain controller in the domain.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8621; use the surrounding log entries to confirm it.","resolution":"1. Record where 8621 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NO_WRITABLE_DC_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8621 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Could not find a writable domain controller in the domain.\n\nLookup forms: 8621, 0x21AD, error 8621, ERROR_NO_WRITABLE_DC_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8621"]},{"id":2086,"title":"ERROR_DS_NO_SERVER_OBJECT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8622","0x21AE","error 8622","ERROR_DS_NO_SERVER_OBJECT","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","server","object","the","for","domain","controller","does","not","exist"],"errorCode":"8622","eventId":"","severity":"Low","summary":"The server object for the domain controller does not exist.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8622; use the surrounding log entries to confirm it.","resolution":"1. Record where 8622 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NO_SERVER_OBJECT.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8622 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The server object for the domain controller does not exist.\n\nLookup forms: 8622, 0x21AE, error 8622, ERROR_DS_NO_SERVER_OBJECT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8622"]},{"id":2087,"title":"ERROR_DS_NO_NTDSA_OBJECT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8623","0x21AF","error 8623","ERROR_DS_NO_NTDSA_OBJECT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ntdsa","object","the","ntds","settings","for","domain","controller","does","not","exist"],"errorCode":"8623","eventId":"","severity":"Low","summary":"The NTDS Settings object for the domain controller does not exist.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8623; use the surrounding log entries to confirm it.","resolution":"1. Record where 8623 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NO_NTDSA_OBJECT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8623 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The NTDS Settings object for the domain controller does not exist.\n\nLookup forms: 8623, 0x21AF, error 8623, ERROR_DS_NO_NTDSA_OBJECT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8623"]},{"id":2088,"title":"ERROR_DS_NON_ASQ_SEARCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8624","0x21B0","error 8624","ERROR_DS_NON_ASQ_SEARCH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","non","asq","search","the","requested","operation","not","supported","for","searches"],"errorCode":"8624","eventId":"","severity":"Medium","summary":"The requested search operation is not supported for ASQ searches.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8624; use the surrounding log entries to confirm it.","resolution":"1. Record where 8624 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_NON_ASQ_SEARCH.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8624 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested search operation is not supported for ASQ searches.\n\nLookup forms: 8624, 0x21B0, error 8624, ERROR_DS_NON_ASQ_SEARCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8624"]},{"id":2089,"title":"ERROR_DS_AUDIT_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8625","0x21B1","error 8625","ERROR_DS_AUDIT_FAILURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","audit","failure","required","event","could","not","generated","for","the","operation"],"errorCode":"8625","eventId":"","severity":"Low","summary":"A required audit event could not be generated for the operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8625; use the surrounding log entries to confirm it.","resolution":"1. Record where 8625 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_AUDIT_FAILURE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8625 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A required audit event could not be generated for the operation.\n\nLookup forms: 8625, 0x21B1, error 8625, ERROR_DS_AUDIT_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8625"]},{"id":2090,"title":"ERROR_DS_INVALID_SEARCH_FLAG_SUBTREE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8626","0x21B2","error 8626","ERROR_DS_INVALID_SEARCH_FLAG_SUBTREE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","search","flag","subtree","the","flags","for","attribute","are","index","bit","valid","only","single","valued","attributes"],"errorCode":"8626","eventId":"","severity":"Medium","summary":"The search flags for the attribute are invalid. The subtree index bit is valid only on single valued attributes.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8626; use the surrounding log entries to confirm it.","resolution":"1. Record where 8626 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_INVALID_SEARCH_FLAG_SUBTREE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8626 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The search flags for the attribute are invalid. The subtree index bit is valid only on single valued attributes.\n\nLookup forms: 8626, 0x21B2, error 8626, ERROR_DS_INVALID_SEARCH_FLAG_SUBTREE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8626"]},{"id":2091,"title":"ERROR_DS_INVALID_SEARCH_FLAG_TUPLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8627","0x21B3","error 8627","ERROR_DS_INVALID_SEARCH_FLAG_TUPLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","search","flag","tuple","the","flags","for","attribute","are","index","bit","valid","only","attributes","unicode","strings"],"errorCode":"8627","eventId":"","severity":"Medium","summary":"The search flags for the attribute are invalid. The tuple index bit is valid only on attributes of Unicode strings.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8627; use the surrounding log entries to confirm it.","resolution":"1. Record where 8627 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_INVALID_SEARCH_FLAG_TUPLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8627 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The search flags for the attribute are invalid. The tuple index bit is valid only on attributes of Unicode strings.\n\nLookup forms: 8627, 0x21B3, error 8627, ERROR_DS_INVALID_SEARCH_FLAG_TUPLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8627"]},{"id":2092,"title":"ERROR_DS_HIERARCHY_TABLE_TOO_DEEP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8628","0x21B4","error 8628","ERROR_DS_HIERARCHY_TABLE_TOO_DEEP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","hierarchy","table","too","deep","the","address","books","are","nested","deeply","failed","build"],"errorCode":"8628","eventId":"","severity":"High","summary":"The address books are nested too deeply. Failed to build the hierarchy table.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8628; use the surrounding log entries to confirm it.","resolution":"1. Record where 8628 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_HIERARCHY_TABLE_TOO_DEEP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8628 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The address books are nested too deeply. Failed to build the hierarchy table.\n\nLookup forms: 8628, 0x21B4, error 8628, ERROR_DS_HIERARCHY_TABLE_TOO_DEEP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8628"]},{"id":2093,"title":"ERROR_DS_DRA_CORRUPT_UTD_VECTOR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8629","0x21B5","error 8629","ERROR_DS_DRA_CORRUPT_UTD_VECTOR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dra","corrupt","utd","vector","the","specified","date","ness"],"errorCode":"8629","eventId":"","severity":"Critical","summary":"The specified up-to-date-ness vector is corrupt.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8629; use the surrounding log entries to confirm it.","resolution":"1. Record where 8629 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_CORRUPT_UTD_VECTOR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8629 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified up-to-date-ness vector is corrupt.\n\nLookup forms: 8629, 0x21B5, error 8629, ERROR_DS_DRA_CORRUPT_UTD_VECTOR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8629"]},{"id":2094,"title":"ERROR_DS_DRA_SECRETS_DENIED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8630","0x21B6","error 8630","ERROR_DS_DRA_SECRETS_DENIED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","dra","secrets","denied","the","request","replicate"],"errorCode":"8630","eventId":"","severity":"Low","summary":"The request to replicate secrets is denied.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8630; use the surrounding log entries to confirm it.","resolution":"1. Record where 8630 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_SECRETS_DENIED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8630 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The request to replicate secrets is denied.\n\nLookup forms: 8630, 0x21B6, error 8630, ERROR_DS_DRA_SECRETS_DENIED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8630"]},{"id":2095,"title":"ERROR_DS_RESERVED_MAPI_ID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8631","0x21B7","error 8631","ERROR_DS_RESERVED_MAPI_ID","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","reserved","mapi","schema","update","failed","the","identifier"],"errorCode":"8631","eventId":"","severity":"High","summary":"Schema update failed: The MAPI identifier is reserved.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 8631; use the surrounding log entries to confirm it.","resolution":"1. Record where 8631 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_RESERVED_MAPI_ID.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8631 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema update failed: The MAPI identifier is reserved.\n\nLookup forms: 8631, 0x21B7, error 8631, ERROR_DS_RESERVED_MAPI_ID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8631"]},{"id":2096,"title":"ERROR_DS_MAPI_ID_NOT_AVAILABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8632","0x21B8","error 8632","ERROR_DS_MAPI_ID_NOT_AVAILABLE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","mapi","not","available","schema","update","failed","there","are","identifiers"],"errorCode":"8632","eventId":"","severity":"High","summary":"Schema update failed: There are no MAPI identifiers available.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 8632; use the surrounding log entries to confirm it.","resolution":"1. Record where 8632 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_MAPI_ID_NOT_AVAILABLE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8632 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Schema update failed: There are no MAPI identifiers available.\n\nLookup forms: 8632, 0x21B8, error 8632, ERROR_DS_MAPI_ID_NOT_AVAILABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8632"]},{"id":2097,"title":"ERROR_DS_DRA_MISSING_KRBTGT_SECRET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8633","0x21B9","error 8633","ERROR_DS_DRA_MISSING_KRBTGT_SECRET","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dra","missing","krbtgt","secret","the","replication","operation","failed","because","required","attributes","local","object","are"],"errorCode":"8633","eventId":"","severity":"High","summary":"The replication operation failed because the required attributes of the local krbtgt object are missing.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8633; use the surrounding log entries to confirm it.","resolution":"1. Record where 8633 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_MISSING_KRBTGT_SECRET.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8633 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replication operation failed because the required attributes of the local krbtgt object are missing.\n\nLookup forms: 8633, 0x21B9, error 8633, ERROR_DS_DRA_MISSING_KRBTGT_SECRET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8633"]},{"id":2098,"title":"ERROR_DS_DOMAIN_NAME_EXISTS_IN_FOREST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8634","0x21BA","error 8634","ERROR_DS_DOMAIN_NAME_EXISTS_IN_FOREST","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","domain","name","exists","forest","the","trusted","already"],"errorCode":"8634","eventId":"","severity":"Medium","summary":"The domain name of the trusted domain already exists in the forest.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8634; use the surrounding log entries to confirm it.","resolution":"1. Record where 8634 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DOMAIN_NAME_EXISTS_IN_FOREST.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8634 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The domain name of the trusted domain already exists in the forest.\n\nLookup forms: 8634, 0x21BA, error 8634, ERROR_DS_DOMAIN_NAME_EXISTS_IN_FOREST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8634"]},{"id":2099,"title":"ERROR_DS_FLAT_NAME_EXISTS_IN_FOREST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8635","0x21BB","error 8635","ERROR_DS_FLAT_NAME_EXISTS_IN_FOREST","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","flat","name","exists","forest","the","trusted","domain","already"],"errorCode":"8635","eventId":"","severity":"Medium","summary":"The flat name of the trusted domain already exists in the forest.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8635; use the surrounding log entries to confirm it.","resolution":"1. Record where 8635 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_FLAT_NAME_EXISTS_IN_FOREST.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8635 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The flat name of the trusted domain already exists in the forest.\n\nLookup forms: 8635, 0x21BB, error 8635, ERROR_DS_FLAT_NAME_EXISTS_IN_FOREST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8635"]},{"id":2100,"title":"ERROR_INVALID_USER_PRINCIPAL_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8636","0x21BC","error 8636","ERROR_INVALID_USER_PRINCIPAL_NAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","user","principal","name","the","upn"],"errorCode":"8636","eventId":"","severity":"Medium","summary":"The User Principal Name (UPN) is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8636; use the surrounding log entries to confirm it.","resolution":"1. Record where 8636 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_USER_PRINCIPAL_NAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8636 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The User Principal Name (UPN) is invalid.\n\nLookup forms: 8636, 0x21BC, error 8636, ERROR_INVALID_USER_PRINCIPAL_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8636"]},{"id":2101,"title":"ERROR_DS_OID_MAPPED_GROUP_CANT_HAVE_MEMBERS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8637","0x21BD","error 8637","ERROR_DS_OID_MAPPED_GROUP_CANT_HAVE_MEMBERS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","oid","mapped","group","cant","have","members","groups","cannot"],"errorCode":"8637","eventId":"","severity":"Medium","summary":"OID mapped groups cannot have members.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8637; use the surrounding log entries to confirm it.","resolution":"1. Record where 8637 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_OID_MAPPED_GROUP_CANT_HAVE_MEMBERS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8637 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: OID mapped groups cannot have members.\n\nLookup forms: 8637, 0x21BD, error 8637, ERROR_DS_OID_MAPPED_GROUP_CANT_HAVE_MEMBERS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8637"]},{"id":2102,"title":"ERROR_DS_OID_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8638","0x21BE","error 8638","ERROR_DS_OID_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","oid","not","found","the","specified","cannot"],"errorCode":"8638","eventId":"","severity":"Medium","summary":"The specified OID cannot be found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8638; use the surrounding log entries to confirm it.","resolution":"1. Record where 8638 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_OID_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8638 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified OID cannot be found.\n\nLookup forms: 8638, 0x21BE, error 8638, ERROR_DS_OID_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8638"]},{"id":2103,"title":"ERROR_DS_DRA_RECYCLED_TARGET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8639","0x21BF","error 8639","ERROR_DS_DRA_RECYCLED_TARGET","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","dra","recycled","target","the","replication","operation","failed","because","object","referred","link","value"],"errorCode":"8639","eventId":"","severity":"High","summary":"The replication operation failed because the target object referred by a link value is recycled.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8639; use the surrounding log entries to confirm it.","resolution":"1. Record where 8639 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DRA_RECYCLED_TARGET.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8639 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The replication operation failed because the target object referred by a link value is recycled.\n\nLookup forms: 8639, 0x21BF, error 8639, ERROR_DS_DRA_RECYCLED_TARGET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8639"]},{"id":2104,"title":"ERROR_DS_DISALLOWED_NC_REDIRECT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8640","0x21C0","error 8640","ERROR_DS_DISALLOWED_NC_REDIRECT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","disallowed","redirect","the","operation","failed","because","target","object","different","from","domain","current","controller"],"errorCode":"8640","eventId":"","severity":"High","summary":"The redirect operation failed because the target object is in a NC different from the domain NC of the current domain controller.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8640; use the surrounding log entries to confirm it.","resolution":"1. Record where 8640 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_DISALLOWED_NC_REDIRECT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8640 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The redirect operation failed because the target object is in a NC different from the domain NC of the current domain controller.\n\nLookup forms: 8640, 0x21C0, error 8640, ERROR_DS_DISALLOWED_NC_REDIRECT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8640"]},{"id":2105,"title":"ERROR_DS_HIGH_ADLDS_FFL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8641","0x21C1","error 8641","ERROR_DS_HIGH_ADLDS_FFL","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","high","adlds","ffl","the","functional","level","lds","configuration","set","cannot","lowered","requested","value"],"errorCode":"8641","eventId":"","severity":"Medium","summary":"The functional level of the AD LDS configuration set cannot be lowered to the requested value.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 8641; use the surrounding log entries to confirm it.","resolution":"1. Record where 8641 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_HIGH_ADLDS_FFL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8641 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The functional level of the AD LDS configuration set cannot be lowered to the requested value.\n\nLookup forms: 8641, 0x21C1, error 8641, ERROR_DS_HIGH_ADLDS_FFL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8641"]},{"id":2106,"title":"ERROR_DS_HIGH_DSA_VERSION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8642","0x21C2","error 8642","ERROR_DS_HIGH_DSA_VERSION","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","high","dsa","version","the","functional","level","domain","forest","cannot","lowered","requested","value"],"errorCode":"8642","eventId":"","severity":"Medium","summary":"The functional level of the domain (or forest) cannot be lowered to the requested value.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 8642; use the surrounding log entries to confirm it.","resolution":"1. Record where 8642 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_HIGH_DSA_VERSION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8642 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The functional level of the domain (or forest) cannot be lowered to the requested value.\n\nLookup forms: 8642, 0x21C2, error 8642, ERROR_DS_HIGH_DSA_VERSION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8642"]},{"id":2107,"title":"ERROR_DS_LOW_ADLDS_FFL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8643","0x21C3","error 8643","ERROR_DS_LOW_ADLDS_FFL","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","low","adlds","ffl","the","functional","level","lds","configuration","set","cannot","raised","requested","value","because","there","exist","one","more","instances","that","are","lower","incompatible"],"errorCode":"8643","eventId":"","severity":"Medium","summary":"The functional level of the AD LDS configuration set cannot be raised to the requested value, because there exist one or more ADLDS instances that are at a lower incompatible functional level.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 8643; use the surrounding log entries to confirm it.","resolution":"1. Record where 8643 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_LOW_ADLDS_FFL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8643 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The functional level of the AD LDS configuration set cannot be raised to the requested value, because there exist one or more ADLDS instances that are at a lower incompatible functional level.\n\nLookup forms: 8643, 0x21C3, error 8643, ERROR_DS_LOW_ADLDS_FFL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8643"]},{"id":2108,"title":"ERROR_DOMAIN_SID_SAME_AS_LOCAL_WORKSTATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8644","0x21C4","error 8644","ERROR_DOMAIN_SID_SAME_AS_LOCAL_WORKSTATION","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","domain","sid","same","local","workstation","the","join","cannot","completed","because","you","attempted","was","identical","this","machine","symptom","improperly","cloned","operating","system","install","should","run"],"errorCode":"8644","eventId":"","severity":"Medium","summary":"The domain join cannot be completed because the SID of the domain you attempted to join was identical to the SID of this machine. This is a symptom of an improperly cloned operating system install. You should run sysprep on this machine in order to generate a new machine SID. Please see https://go.microsoft.com/fwlink/p/?linkid=168895 for more information.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 8644; use the surrounding log entries to confirm it.","resolution":"1. Record where 8644 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DOMAIN_SID_SAME_AS_LOCAL_WORKSTATION.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8644 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The domain join cannot be completed because the SID of the domain you attempted to join was identical to the SID of this machine. This is a symptom of an improperly cloned operating system install. You should run sysprep on this machine in order to generate a new machine SID. Please see https://go.microsoft.com/fwlink/p/?linkid=168895 for more information.\n\nLookup forms: 8644, 0x21C4, error 8644, ERROR_DOMAIN_SID_SAME_AS_LOCAL_WORKSTATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8644"]},{"id":2109,"title":"ERROR_DS_UNDELETE_SAM_VALIDATION_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8645","0x21C5","error 8645","ERROR_DS_UNDELETE_SAM_VALIDATION_FAILED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","undelete","sam","validation","failed","the","operation","because","account","name","additional","object","being","undeleted","conflicts","with","existing","live"],"errorCode":"8645","eventId":"","severity":"High","summary":"The undelete operation failed because the Sam Account Name or Additional Sam Account Name of the object being undeleted conflicts with an existing live object.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8645; use the surrounding log entries to confirm it.","resolution":"1. Record where 8645 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_UNDELETE_SAM_VALIDATION_FAILED.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8645 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The undelete operation failed because the Sam Account Name or Additional Sam Account Name of the object being undeleted conflicts with an existing live object.\n\nLookup forms: 8645, 0x21C5, error 8645, ERROR_DS_UNDELETE_SAM_VALIDATION_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8645"]},{"id":2110,"title":"ERROR_INCORRECT_ACCOUNT_TYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8646","0x21C6","error 8646","ERROR_INCORRECT_ACCOUNT_TYPE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","incorrect","account","type","the","system","not","authoritative","for","specified","and","therefore","cannot","complete","operation","please","retry","using","provider","associated","with","this","online","use","site"],"errorCode":"8646","eventId":"","severity":"Medium","summary":"The system is not authoritative for the specified account and therefore cannot complete the operation. Please retry the operation using the provider associated with this account. If this is an online provider please use the provider's online site.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 8646; use the surrounding log entries to confirm it.","resolution":"1. Record where 8646 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INCORRECT_ACCOUNT_TYPE.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8646 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system is not authoritative for the specified account and therefore cannot complete the operation. Please retry the operation using the provider associated with this account. If this is an online provider please use the provider's online site.\n\nLookup forms: 8646, 0x21C6, error 8646, ERROR_INCORRECT_ACCOUNT_TYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8646"]},{"id":2111,"title":"DNS_ERROR_RCODE_FORMAT_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9001","0x2329","error 9001","DNS_ERROR_RCODE_FORMAT_ERROR","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","rcode","format","server","unable","interpret"],"errorCode":"9001","eventId":"","severity":"Medium","summary":"DNS server unable to interpret format.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9001; use the surrounding log entries to confirm it.","resolution":"1. Record where 9001 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_RCODE_FORMAT_ERROR.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9001 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS server unable to interpret format.\n\nLookup forms: 9001, 0x2329, error 9001, DNS_ERROR_RCODE_FORMAT_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9001"]},{"id":2112,"title":"DNS_ERROR_RCODE_SERVER_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9002","0x232A","error 9002","DNS_ERROR_RCODE_SERVER_FAILURE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","rcode","server","failure"],"errorCode":"9002","eventId":"","severity":"High","summary":"DNS server failure.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9002; use the surrounding log entries to confirm it.","resolution":"1. Record where 9002 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_RCODE_SERVER_FAILURE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9002 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS server failure.\n\nLookup forms: 9002, 0x232A, error 9002, DNS_ERROR_RCODE_SERVER_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9002"]},{"id":2113,"title":"DNS_ERROR_RCODE_NAME_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9003","0x232B","error 9003","DNS_ERROR_RCODE_NAME_ERROR","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","rcode","name","does","not","exist"],"errorCode":"9003","eventId":"","severity":"Low","summary":"DNS name does not exist.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9003; use the surrounding log entries to confirm it.","resolution":"1. Record where 9003 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_RCODE_NAME_ERROR.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9003 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS name does not exist.\n\nLookup forms: 9003, 0x232B, error 9003, DNS_ERROR_RCODE_NAME_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9003"]},{"id":2114,"title":"DNS_ERROR_RCODE_NOT_IMPLEMENTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9004","0x232C","error 9004","DNS_ERROR_RCODE_NOT_IMPLEMENTED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","rcode","not","implemented","request","supported","name","server"],"errorCode":"9004","eventId":"","severity":"Medium","summary":"DNS request not supported by name server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9004; use the surrounding log entries to confirm it.","resolution":"1. Record where 9004 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_RCODE_NOT_IMPLEMENTED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9004 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS request not supported by name server.\n\nLookup forms: 9004, 0x232C, error 9004, DNS_ERROR_RCODE_NOT_IMPLEMENTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9004"]},{"id":2115,"title":"DNS_ERROR_RCODE_REFUSED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9005","0x232D","error 9005","DNS_ERROR_RCODE_REFUSED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","rcode","refused","operation"],"errorCode":"9005","eventId":"","severity":"Low","summary":"DNS operation refused.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9005; use the surrounding log entries to confirm it.","resolution":"1. Record where 9005 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_RCODE_REFUSED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9005 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS operation refused.\n\nLookup forms: 9005, 0x232D, error 9005, DNS_ERROR_RCODE_REFUSED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9005"]},{"id":2116,"title":"DNS_ERROR_RCODE_YXDOMAIN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9006","0x232E","error 9006","DNS_ERROR_RCODE_YXDOMAIN","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","rcode","yxdomain","name","that","ought","not","exist","does"],"errorCode":"9006","eventId":"","severity":"Low","summary":"DNS name that ought not exist, does exist.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9006; use the surrounding log entries to confirm it.","resolution":"1. Record where 9006 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_RCODE_YXDOMAIN.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9006 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS name that ought not exist, does exist.\n\nLookup forms: 9006, 0x232E, error 9006, DNS_ERROR_RCODE_YXDOMAIN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9006"]},{"id":2117,"title":"DNS_ERROR_RCODE_YXRRSET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9007","0x232F","error 9007","DNS_ERROR_RCODE_YXRRSET","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","rcode","yxrrset","set","that","ought","not","exist","does"],"errorCode":"9007","eventId":"","severity":"Low","summary":"DNS RR set that ought not exist, does exist.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9007; use the surrounding log entries to confirm it.","resolution":"1. Record where 9007 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_RCODE_YXRRSET.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9007 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS RR set that ought not exist, does exist.\n\nLookup forms: 9007, 0x232F, error 9007, DNS_ERROR_RCODE_YXRRSET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9007"]},{"id":2118,"title":"DNS_ERROR_RCODE_NXRRSET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9008","0x2330","error 9008","DNS_ERROR_RCODE_NXRRSET","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","rcode","nxrrset","set","that","ought","exist","does","not"],"errorCode":"9008","eventId":"","severity":"Low","summary":"DNS RR set that ought to exist, does not exist.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9008; use the surrounding log entries to confirm it.","resolution":"1. Record where 9008 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_RCODE_NXRRSET.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9008 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS RR set that ought to exist, does not exist.\n\nLookup forms: 9008, 0x2330, error 9008, DNS_ERROR_RCODE_NXRRSET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9008"]},{"id":2119,"title":"DNS_ERROR_RCODE_NOTAUTH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9009","0x2331","error 9009","DNS_ERROR_RCODE_NOTAUTH","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","rcode","notauth","server","not","authoritative","for","zone"],"errorCode":"9009","eventId":"","severity":"Low","summary":"DNS server not authoritative for zone.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9009; use the surrounding log entries to confirm it.","resolution":"1. Record where 9009 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_RCODE_NOTAUTH.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9009 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS server not authoritative for zone.\n\nLookup forms: 9009, 0x2331, error 9009, DNS_ERROR_RCODE_NOTAUTH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9009"]},{"id":2120,"title":"DNS_ERROR_RCODE_NOTZONE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9010","0x2332","error 9010","DNS_ERROR_RCODE_NOTZONE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","rcode","notzone","name","update","prereq","not","zone"],"errorCode":"9010","eventId":"","severity":"Low","summary":"DNS name in update or prereq is not in zone.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9010; use the surrounding log entries to confirm it.","resolution":"1. Record where 9010 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_RCODE_NOTZONE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9010 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS name in update or prereq is not in zone.\n\nLookup forms: 9010, 0x2332, error 9010, DNS_ERROR_RCODE_NOTZONE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9010"]},{"id":2121,"title":"DNS_ERROR_RCODE_BADSIG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9016","0x2338","error 9016","DNS_ERROR_RCODE_BADSIG","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","rcode","badsig","signature","failed","verify"],"errorCode":"9016","eventId":"","severity":"High","summary":"DNS signature failed to verify.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9016; use the surrounding log entries to confirm it.","resolution":"1. Record where 9016 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_RCODE_BADSIG.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9016 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS signature failed to verify.\n\nLookup forms: 9016, 0x2338, error 9016, DNS_ERROR_RCODE_BADSIG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9016"]},{"id":2122,"title":"DNS_ERROR_RCODE_BADKEY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9017","0x2339","error 9017","DNS_ERROR_RCODE_BADKEY","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","rcode","badkey","bad","key"],"errorCode":"9017","eventId":"","severity":"Low","summary":"DNS bad key.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9017; use the surrounding log entries to confirm it.","resolution":"1. Record where 9017 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_RCODE_BADKEY.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9017 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS bad key.\n\nLookup forms: 9017, 0x2339, error 9017, DNS_ERROR_RCODE_BADKEY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9017"]},{"id":2123,"title":"DNS_ERROR_RCODE_BADTIME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9018","0x233A","error 9018","DNS_ERROR_RCODE_BADTIME","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","rcode","badtime","signature","validity","expired"],"errorCode":"9018","eventId":"","severity":"Low","summary":"DNS signature validity expired.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9018; use the surrounding log entries to confirm it.","resolution":"1. Record where 9018 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_RCODE_BADTIME.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9018 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS signature validity expired.\n\nLookup forms: 9018, 0x233A, error 9018, DNS_ERROR_RCODE_BADTIME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9018"]},{"id":2124,"title":"DNS_ERROR_KEYMASTER_REQUIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9101","0x238D","error 9101","DNS_ERROR_KEYMASTER_REQUIRED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","keymaster","required","only","the","server","acting","key","master","for","zone","may","perform","this","operation"],"errorCode":"9101","eventId":"","severity":"Low","summary":"Only the DNS server acting as the key master for the zone may perform this operation.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9101; use the surrounding log entries to confirm it.","resolution":"1. Record where 9101 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_KEYMASTER_REQUIRED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9101 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Only the DNS server acting as the key master for the zone may perform this operation.\n\nLookup forms: 9101, 0x238D, error 9101, DNS_ERROR_KEYMASTER_REQUIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9101"]},{"id":2125,"title":"DNS_ERROR_NOT_ALLOWED_ON_SIGNED_ZONE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9102","0x238E","error 9102","DNS_ERROR_NOT_ALLOWED_ON_SIGNED_ZONE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","not","allowed","signed","zone","this","operation","that","has","signing","keys"],"errorCode":"9102","eventId":"","severity":"Low","summary":"This operation is not allowed on a zone that is signed or has signing keys.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9102; use the surrounding log entries to confirm it.","resolution":"1. Record where 9102 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NOT_ALLOWED_ON_SIGNED_ZONE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9102 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation is not allowed on a zone that is signed or has signing keys.\n\nLookup forms: 9102, 0x238E, error 9102, DNS_ERROR_NOT_ALLOWED_ON_SIGNED_ZONE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9102"]},{"id":2126,"title":"DNS_ERROR_NSEC3_INCOMPATIBLE_WITH_RSA_SHA1","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9103","0x238F","error 9103","DNS_ERROR_NSEC3_INCOMPATIBLE_WITH_RSA_SHA1","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","nsec3","incompatible","with","rsa","sha1","not","compatible","the","sha","algorithm","choose","different","use","nsec"],"errorCode":"9103","eventId":"","severity":"Low","summary":"NSEC3 is not compatible with the RSA-SHA-1 algorithm. Choose a different algorithm or use NSEC.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9103; use the surrounding log entries to confirm it.","resolution":"1. Record where 9103 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NSEC3_INCOMPATIBLE_WITH_RSA_SHA1.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9103 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: NSEC3 is not compatible with the RSA-SHA-1 algorithm. Choose a different algorithm or use NSEC.\n\nLookup forms: 9103, 0x238F, error 9103, DNS_ERROR_NSEC3_INCOMPATIBLE_WITH_RSA_SHA1. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9103"]},{"id":2127,"title":"DNS_ERROR_NOT_ENOUGH_SIGNING_KEY_DESCRIPTORS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9104","0x2390","error 9104","DNS_ERROR_NOT_ENOUGH_SIGNING_KEY_DESCRIPTORS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","not","enough","signing","key","descriptors","the","zone","does","have","keys","there","must","least","one","ksk","and","zsk"],"errorCode":"9104","eventId":"","severity":"Low","summary":"The zone does not have enough signing keys. There must be at least one key signing key (KSK) and at least one zone signing key (ZSK).","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9104; use the surrounding log entries to confirm it.","resolution":"1. Record where 9104 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NOT_ENOUGH_SIGNING_KEY_DESCRIPTORS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9104 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The zone does not have enough signing keys. There must be at least one key signing key (KSK) and at least one zone signing key (ZSK).\n\nLookup forms: 9104, 0x2390, error 9104, DNS_ERROR_NOT_ENOUGH_SIGNING_KEY_DESCRIPTORS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9104"]},{"id":2128,"title":"DNS_ERROR_UNSUPPORTED_ALGORITHM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9105","0x2391","error 9105","DNS_ERROR_UNSUPPORTED_ALGORITHM","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","unsupported","algorithm","the","specified","not","supported"],"errorCode":"9105","eventId":"","severity":"Medium","summary":"The specified algorithm is not supported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9105; use the surrounding log entries to confirm it.","resolution":"1. Record where 9105 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_UNSUPPORTED_ALGORITHM.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9105 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified algorithm is not supported.\n\nLookup forms: 9105, 0x2391, error 9105, DNS_ERROR_UNSUPPORTED_ALGORITHM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9105"]},{"id":2129,"title":"DNS_ERROR_INVALID_KEY_SIZE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9106","0x2392","error 9106","DNS_ERROR_INVALID_KEY_SIZE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","invalid","key","size","the","specified","not","supported"],"errorCode":"9106","eventId":"","severity":"Medium","summary":"The specified key size is not supported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9106; use the surrounding log entries to confirm it.","resolution":"1. Record where 9106 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_INVALID_KEY_SIZE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9106 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified key size is not supported.\n\nLookup forms: 9106, 0x2392, error 9106, DNS_ERROR_INVALID_KEY_SIZE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9106"]},{"id":2130,"title":"DNS_ERROR_SIGNING_KEY_NOT_ACCESSIBLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9107","0x2393","error 9107","DNS_ERROR_SIGNING_KEY_NOT_ACCESSIBLE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","dns","error","signing","key","not","accessible","one","more","the","keys","for","zone","are","server","will","operational","until","this","resolved"],"errorCode":"9107","eventId":"","severity":"Low","summary":"One or more of the signing keys for a zone are not accessible to the DNS server. Zone signing will not be operational until this error is resolved.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 9107; use the surrounding log entries to confirm it.","resolution":"1. Record where 9107 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_SIGNING_KEY_NOT_ACCESSIBLE.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9107 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: One or more of the signing keys for a zone are not accessible to the DNS server. Zone signing will not be operational until this error is resolved.\n\nLookup forms: 9107, 0x2393, error 9107, DNS_ERROR_SIGNING_KEY_NOT_ACCESSIBLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9107"]},{"id":2131,"title":"DNS_ERROR_KSP_DOES_NOT_SUPPORT_PROTECTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9108","0x2394","error 9108","DNS_ERROR_KSP_DOES_NOT_SUPPORT_PROTECTION","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","dns","error","ksp","does","not","support","protection","the","specified","key","storage","provider","dpapi","data","zone","signing","will","operational","until","this","resolved"],"errorCode":"9108","eventId":"","severity":"Low","summary":"The specified key storage provider does not support DPAPI++ data protection. Zone signing will not be operational until this error is resolved.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 9108; use the surrounding log entries to confirm it.","resolution":"1. Record where 9108 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_KSP_DOES_NOT_SUPPORT_PROTECTION.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9108 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified key storage provider does not support DPAPI++ data protection. Zone signing will not be operational until this error is resolved.\n\nLookup forms: 9108, 0x2394, error 9108, DNS_ERROR_KSP_DOES_NOT_SUPPORT_PROTECTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9108"]},{"id":2132,"title":"DNS_ERROR_UNEXPECTED_DATA_PROTECTION_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9109","0x2395","error 9109","DNS_ERROR_UNEXPECTED_DATA_PROTECTION_ERROR","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","dns","error","unexpected","data","protection","dpapi","was","encountered","zone","signing","will","not","operational","until","this","resolved"],"errorCode":"9109","eventId":"","severity":"Low","summary":"An unexpected DPAPI++ error was encountered. Zone signing will not be operational until this error is resolved.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 9109; use the surrounding log entries to confirm it.","resolution":"1. Record where 9109 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_UNEXPECTED_DATA_PROTECTION_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9109 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An unexpected DPAPI++ error was encountered. Zone signing will not be operational until this error is resolved.\n\nLookup forms: 9109, 0x2395, error 9109, DNS_ERROR_UNEXPECTED_DATA_PROTECTION_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9109"]},{"id":2133,"title":"DNS_ERROR_UNEXPECTED_CNG_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9110","0x2396","error 9110","DNS_ERROR_UNEXPECTED_CNG_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","unexpected","cng","crypto","was","encountered","zone","signing","may","not","operational","until","this","resolved"],"errorCode":"9110","eventId":"","severity":"Low","summary":"An unexpected crypto error was encountered. Zone signing may not be operational until this error is resolved.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9110; use the surrounding log entries to confirm it.","resolution":"1. Record where 9110 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_UNEXPECTED_CNG_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9110 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An unexpected crypto error was encountered. Zone signing may not be operational until this error is resolved.\n\nLookup forms: 9110, 0x2396, error 9110, DNS_ERROR_UNEXPECTED_CNG_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9110"]},{"id":2134,"title":"DNS_ERROR_UNKNOWN_SIGNING_PARAMETER_VERSION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9111","0x2397","error 9111","DNS_ERROR_UNKNOWN_SIGNING_PARAMETER_VERSION","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","unknown","signing","parameter","version","the","server","encountered","key","with","zone","will","not","operational","until","this","resolved"],"errorCode":"9111","eventId":"","severity":"Low","summary":"The DNS server encountered a signing key with an unknown version. Zone signing will not be operational until this error is resolved.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9111; use the surrounding log entries to confirm it.","resolution":"1. Record where 9111 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_UNKNOWN_SIGNING_PARAMETER_VERSION.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9111 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The DNS server encountered a signing key with an unknown version. Zone signing will not be operational until this error is resolved.\n\nLookup forms: 9111, 0x2397, error 9111, DNS_ERROR_UNKNOWN_SIGNING_PARAMETER_VERSION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9111"]},{"id":2135,"title":"DNS_ERROR_KSP_NOT_ACCESSIBLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9112","0x2398","error 9112","DNS_ERROR_KSP_NOT_ACCESSIBLE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","ksp","not","accessible","the","specified","key","service","provider","cannot","opened","server"],"errorCode":"9112","eventId":"","severity":"Medium","summary":"The specified key service provider cannot be opened by the DNS server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9112; use the surrounding log entries to confirm it.","resolution":"1. Record where 9112 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_KSP_NOT_ACCESSIBLE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9112 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified key service provider cannot be opened by the DNS server.\n\nLookup forms: 9112, 0x2398, error 9112, DNS_ERROR_KSP_NOT_ACCESSIBLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9112"]},{"id":2136,"title":"DNS_ERROR_TOO_MANY_SKDS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9113","0x2399","error 9113","DNS_ERROR_TOO_MANY_SKDS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","too","many","skds","the","server","cannot","accept","any","more","signing","keys","with","specified","algorithm","and","ksk","flag","value","for","this","zone"],"errorCode":"9113","eventId":"","severity":"Medium","summary":"The DNS server cannot accept any more signing keys with the specified algorithm and KSK flag value for this zone.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9113; use the surrounding log entries to confirm it.","resolution":"1. Record where 9113 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_TOO_MANY_SKDS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9113 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The DNS server cannot accept any more signing keys with the specified algorithm and KSK flag value for this zone.\n\nLookup forms: 9113, 0x2399, error 9113, DNS_ERROR_TOO_MANY_SKDS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9113"]},{"id":2137,"title":"DNS_ERROR_INVALID_ROLLOVER_PERIOD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9114","0x239A","error 9114","DNS_ERROR_INVALID_ROLLOVER_PERIOD","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","invalid","rollover","period","the","specified"],"errorCode":"9114","eventId":"","severity":"Medium","summary":"The specified rollover period is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9114; use the surrounding log entries to confirm it.","resolution":"1. Record where 9114 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_INVALID_ROLLOVER_PERIOD.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9114 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified rollover period is invalid.\n\nLookup forms: 9114, 0x239A, error 9114, DNS_ERROR_INVALID_ROLLOVER_PERIOD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9114"]},{"id":2138,"title":"DNS_ERROR_INVALID_INITIAL_ROLLOVER_OFFSET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9115","0x239B","error 9115","DNS_ERROR_INVALID_INITIAL_ROLLOVER_OFFSET","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","invalid","initial","rollover","offset","the","specified"],"errorCode":"9115","eventId":"","severity":"Medium","summary":"The specified initial rollover offset is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9115; use the surrounding log entries to confirm it.","resolution":"1. Record where 9115 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_INVALID_INITIAL_ROLLOVER_OFFSET.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9115 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified initial rollover offset is invalid.\n\nLookup forms: 9115, 0x239B, error 9115, DNS_ERROR_INVALID_INITIAL_ROLLOVER_OFFSET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9115"]},{"id":2139,"title":"DNS_ERROR_ROLLOVER_IN_PROGRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9116","0x239C","error 9116","DNS_ERROR_ROLLOVER_IN_PROGRESS","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","dns","error","rollover","progress","the","specified","signing","key","already","process","rolling","over","keys"],"errorCode":"9116","eventId":"","severity":"Low","summary":"The specified signing key is already in process of rolling over keys.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 9116; use the surrounding log entries to confirm it.","resolution":"1. Record where 9116 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_ROLLOVER_IN_PROGRESS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9116 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified signing key is already in process of rolling over keys.\n\nLookup forms: 9116, 0x239C, error 9116, DNS_ERROR_ROLLOVER_IN_PROGRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9116"]},{"id":2140,"title":"DNS_ERROR_STANDBY_KEY_NOT_PRESENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9117","0x239D","error 9117","DNS_ERROR_STANDBY_KEY_NOT_PRESENT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","standby","key","not","present","the","specified","signing","does","have","revoke"],"errorCode":"9117","eventId":"","severity":"Low","summary":"The specified signing key does not have a standby key to revoke.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9117; use the surrounding log entries to confirm it.","resolution":"1. Record where 9117 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_STANDBY_KEY_NOT_PRESENT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9117 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified signing key does not have a standby key to revoke.\n\nLookup forms: 9117, 0x239D, error 9117, DNS_ERROR_STANDBY_KEY_NOT_PRESENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9117"]},{"id":2141,"title":"DNS_ERROR_NOT_ALLOWED_ON_ZSK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9118","0x239E","error 9118","DNS_ERROR_NOT_ALLOWED_ON_ZSK","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","not","allowed","zsk","this","operation","zone","signing","key"],"errorCode":"9118","eventId":"","severity":"Low","summary":"This operation is not allowed on a zone signing key (ZSK).","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9118; use the surrounding log entries to confirm it.","resolution":"1. Record where 9118 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NOT_ALLOWED_ON_ZSK.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9118 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation is not allowed on a zone signing key (ZSK).\n\nLookup forms: 9118, 0x239E, error 9118, DNS_ERROR_NOT_ALLOWED_ON_ZSK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9118"]},{"id":2142,"title":"DNS_ERROR_NOT_ALLOWED_ON_ACTIVE_SKD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9119","0x239F","error 9119","DNS_ERROR_NOT_ALLOWED_ON_ACTIVE_SKD","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","not","allowed","active","skd","this","operation","signing","key"],"errorCode":"9119","eventId":"","severity":"Low","summary":"This operation is not allowed on an active signing key.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9119; use the surrounding log entries to confirm it.","resolution":"1. Record where 9119 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NOT_ALLOWED_ON_ACTIVE_SKD.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9119 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation is not allowed on an active signing key.\n\nLookup forms: 9119, 0x239F, error 9119, DNS_ERROR_NOT_ALLOWED_ON_ACTIVE_SKD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9119"]},{"id":2143,"title":"DNS_ERROR_ROLLOVER_ALREADY_QUEUED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9120","0x23A0","error 9120","DNS_ERROR_ROLLOVER_ALREADY_QUEUED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","rollover","already","queued","the","specified","signing","key","for"],"errorCode":"9120","eventId":"","severity":"Low","summary":"The specified signing key is already queued for rollover.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9120; use the surrounding log entries to confirm it.","resolution":"1. Record where 9120 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_ROLLOVER_ALREADY_QUEUED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9120 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified signing key is already queued for rollover.\n\nLookup forms: 9120, 0x23A0, error 9120, DNS_ERROR_ROLLOVER_ALREADY_QUEUED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9120"]},{"id":2144,"title":"DNS_ERROR_NOT_ALLOWED_ON_UNSIGNED_ZONE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9121","0x23A1","error 9121","DNS_ERROR_NOT_ALLOWED_ON_UNSIGNED_ZONE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","not","allowed","unsigned","zone","this","operation"],"errorCode":"9121","eventId":"","severity":"Low","summary":"This operation is not allowed on an unsigned zone.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9121; use the surrounding log entries to confirm it.","resolution":"1. Record where 9121 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NOT_ALLOWED_ON_UNSIGNED_ZONE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9121 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation is not allowed on an unsigned zone.\n\nLookup forms: 9121, 0x23A1, error 9121, DNS_ERROR_NOT_ALLOWED_ON_UNSIGNED_ZONE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9121"]},{"id":2145,"title":"DNS_ERROR_BAD_KEYMASTER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9122","0x23A2","error 9122","DNS_ERROR_BAD_KEYMASTER","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","bad","keymaster","this","operation","could","not","completed","because","the","server","listed","current","key","master","for","zone","down","misconfigured","resolve","problem","use","another","seize"],"errorCode":"9122","eventId":"","severity":"Low","summary":"This operation could not be completed because the DNS server listed as the current key master for this zone is down or misconfigured. Resolve the problem on the current key master for this zone or use another DNS server to seize the key master role.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9122; use the surrounding log entries to confirm it.","resolution":"1. Record where 9122 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_BAD_KEYMASTER.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9122 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation could not be completed because the DNS server listed as the current key master for this zone is down or misconfigured. Resolve the problem on the current key master for this zone or use another DNS server to seize the key master role.\n\nLookup forms: 9122, 0x23A2, error 9122, DNS_ERROR_BAD_KEYMASTER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9122"]},{"id":2146,"title":"DNS_ERROR_INVALID_SIGNATURE_VALIDITY_PERIOD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9123","0x23A3","error 9123","DNS_ERROR_INVALID_SIGNATURE_VALIDITY_PERIOD","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","invalid","signature","validity","period","the","specified"],"errorCode":"9123","eventId":"","severity":"Medium","summary":"The specified signature validity period is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9123; use the surrounding log entries to confirm it.","resolution":"1. Record where 9123 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_INVALID_SIGNATURE_VALIDITY_PERIOD.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9123 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified signature validity period is invalid.\n\nLookup forms: 9123, 0x23A3, error 9123, DNS_ERROR_INVALID_SIGNATURE_VALIDITY_PERIOD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9123"]},{"id":2147,"title":"DNS_ERROR_INVALID_NSEC3_ITERATION_COUNT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9124","0x23A4","error 9124","DNS_ERROR_INVALID_NSEC3_ITERATION_COUNT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","invalid","nsec3","iteration","count","the","specified","higher","than","allowed","minimum","key","length","used","zone"],"errorCode":"9124","eventId":"","severity":"Low","summary":"The specified NSEC3 iteration count is higher than allowed by the minimum key length used in the zone.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9124; use the surrounding log entries to confirm it.","resolution":"1. Record where 9124 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_INVALID_NSEC3_ITERATION_COUNT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9124 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified NSEC3 iteration count is higher than allowed by the minimum key length used in the zone.\n\nLookup forms: 9124, 0x23A4, error 9124, DNS_ERROR_INVALID_NSEC3_ITERATION_COUNT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9124"]},{"id":2148,"title":"DNS_ERROR_DNSSEC_IS_DISABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9125","0x23A5","error 9125","DNS_ERROR_DNSSEC_IS_DISABLED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","dnssec","disabled","this","operation","could","not","completed","because","the","server","has","been","configured","with","features","enable"],"errorCode":"9125","eventId":"","severity":"Low","summary":"This operation could not be completed because the DNS server has been configured with DNSSEC features disabled. Enable DNSSEC on the DNS server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9125; use the surrounding log entries to confirm it.","resolution":"1. Record where 9125 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_DNSSEC_IS_DISABLED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9125 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation could not be completed because the DNS server has been configured with DNSSEC features disabled. Enable DNSSEC on the DNS server.\n\nLookup forms: 9125, 0x23A5, error 9125, DNS_ERROR_DNSSEC_IS_DISABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9125"]},{"id":2149,"title":"DNS_ERROR_INVALID_XML","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9126","0x23A6","error 9126","DNS_ERROR_INVALID_XML","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","invalid","xml","this","operation","could","not","completed","because","the","stream","received","empty","syntactically"],"errorCode":"9126","eventId":"","severity":"Medium","summary":"This operation could not be completed because the XML stream received is empty or syntactically invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9126; use the surrounding log entries to confirm it.","resolution":"1. Record where 9126 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_INVALID_XML.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9126 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation could not be completed because the XML stream received is empty or syntactically invalid.\n\nLookup forms: 9126, 0x23A6, error 9126, DNS_ERROR_INVALID_XML. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9126"]},{"id":2150,"title":"DNS_ERROR_NO_VALID_TRUST_ANCHORS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9127","0x23A7","error 9127","DNS_ERROR_NO_VALID_TRUST_ANCHORS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","valid","trust","anchors","this","operation","completed","but","were","added","because","all","the","received","either","invalid","unsupported","expired","would","not","become","less","than","days"],"errorCode":"9127","eventId":"","severity":"Medium","summary":"This operation completed, but no trust anchors were added because all of the trust anchors received were either invalid, unsupported, expired, or would not become valid in less than 30 days.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9127; use the surrounding log entries to confirm it.","resolution":"1. Record where 9127 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NO_VALID_TRUST_ANCHORS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9127 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation completed, but no trust anchors were added because all of the trust anchors received were either invalid, unsupported, expired, or would not become valid in less than 30 days.\n\nLookup forms: 9127, 0x23A7, error 9127, DNS_ERROR_NO_VALID_TRUST_ANCHORS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9127"]},{"id":2151,"title":"DNS_ERROR_ROLLOVER_NOT_POKEABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9128","0x23A8","error 9128","DNS_ERROR_ROLLOVER_NOT_POKEABLE","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","dns","error","rollover","not","pokeable","the","specified","signing","key","waiting","for","parental","update"],"errorCode":"9128","eventId":"","severity":"Low","summary":"The specified signing key is not waiting for parental DS update.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 9128; use the surrounding log entries to confirm it.","resolution":"1. Record where 9128 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_ROLLOVER_NOT_POKEABLE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9128 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified signing key is not waiting for parental DS update.\n\nLookup forms: 9128, 0x23A8, error 9128, DNS_ERROR_ROLLOVER_NOT_POKEABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9128"]},{"id":2152,"title":"DNS_ERROR_NSEC3_NAME_COLLISION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9129","0x23A9","error 9129","DNS_ERROR_NSEC3_NAME_COLLISION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","nsec3","name","collision","hash","detected","during","signing","specify","different","user","provided","salt","use","randomly","generated","and","attempt","sign","the","zone","again"],"errorCode":"9129","eventId":"","severity":"Low","summary":"Hash collision detected during NSEC3 signing. Specify a different user-provided salt, or use a randomly generated salt, and attempt to sign the zone again.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9129; use the surrounding log entries to confirm it.","resolution":"1. Record where 9129 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NSEC3_NAME_COLLISION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9129 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Hash collision detected during NSEC3 signing. Specify a different user-provided salt, or use a randomly generated salt, and attempt to sign the zone again.\n\nLookup forms: 9129, 0x23A9, error 9129, DNS_ERROR_NSEC3_NAME_COLLISION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9129"]},{"id":2153,"title":"DNS_ERROR_NSEC_INCOMPATIBLE_WITH_NSEC3_RSA_SHA1","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9130","0x23AA","error 9130","DNS_ERROR_NSEC_INCOMPATIBLE_WITH_NSEC3_RSA_SHA1","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","nsec","incompatible","with","nsec3","rsa","sha1","not","compatible","the","sha","algorithm","choose","different","use"],"errorCode":"9130","eventId":"","severity":"Low","summary":"NSEC is not compatible with the NSEC3-RSA-SHA-1 algorithm. Choose a different algorithm or use NSEC3.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9130; use the surrounding log entries to confirm it.","resolution":"1. Record where 9130 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NSEC_INCOMPATIBLE_WITH_NSEC3_RSA_SHA1.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9130 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: NSEC is not compatible with the NSEC3-RSA-SHA-1 algorithm. Choose a different algorithm or use NSEC3.\n\nLookup forms: 9130, 0x23AA, error 9130, DNS_ERROR_NSEC_INCOMPATIBLE_WITH_NSEC3_RSA_SHA1. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9130"]},{"id":2154,"title":"DNS_INFO_NO_RECORDS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9501","0x251D","error 9501","DNS_INFO_NO_RECORDS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","info","records","found","for","given","query"],"errorCode":"9501","eventId":"","severity":"Low","summary":"No records found for given DNS query.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9501; use the surrounding log entries to confirm it.","resolution":"1. Record where 9501 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_INFO_NO_RECORDS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9501 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No records found for given DNS query.\n\nLookup forms: 9501, 0x251D, error 9501, DNS_INFO_NO_RECORDS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9501"]},{"id":2155,"title":"DNS_ERROR_BAD_PACKET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9502","0x251E","error 9502","DNS_ERROR_BAD_PACKET","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","bad","packet"],"errorCode":"9502","eventId":"","severity":"Low","summary":"Bad DNS packet.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9502; use the surrounding log entries to confirm it.","resolution":"1. Record where 9502 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_BAD_PACKET.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9502 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Bad DNS packet.\n\nLookup forms: 9502, 0x251E, error 9502, DNS_ERROR_BAD_PACKET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9502"]},{"id":2156,"title":"DNS_ERROR_NO_PACKET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9503","0x251F","error 9503","DNS_ERROR_NO_PACKET","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","packet"],"errorCode":"9503","eventId":"","severity":"Low","summary":"No DNS packet.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9503; use the surrounding log entries to confirm it.","resolution":"1. Record where 9503 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NO_PACKET.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9503 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No DNS packet.\n\nLookup forms: 9503, 0x251F, error 9503, DNS_ERROR_NO_PACKET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9503"]},{"id":2157,"title":"DNS_ERROR_RCODE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9504","0x2520","error 9504","DNS_ERROR_RCODE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","rcode","check"],"errorCode":"9504","eventId":"","severity":"Low","summary":"DNS error, check rcode.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9504; use the surrounding log entries to confirm it.","resolution":"1. Record where 9504 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_RCODE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9504 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS error, check rcode.\n\nLookup forms: 9504, 0x2520, error 9504, DNS_ERROR_RCODE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9504"]},{"id":2158,"title":"DNS_ERROR_UNSECURE_PACKET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9505","0x2521","error 9505","DNS_ERROR_UNSECURE_PACKET","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","unsecure","packet","unsecured"],"errorCode":"9505","eventId":"","severity":"Low","summary":"Unsecured DNS packet.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9505; use the surrounding log entries to confirm it.","resolution":"1. Record where 9505 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_UNSECURE_PACKET.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9505 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unsecured DNS packet.\n\nLookup forms: 9505, 0x2521, error 9505, DNS_ERROR_UNSECURE_PACKET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9505"]},{"id":2159,"title":"DNS_REQUEST_PENDING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9506","0x2522","error 9506","DNS_REQUEST_PENDING","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","request","pending","query"],"errorCode":"9506","eventId":"","severity":"Low","summary":"DNS query request is pending.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9506; use the surrounding log entries to confirm it.","resolution":"1. Record where 9506 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_REQUEST_PENDING.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9506 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS query request is pending.\n\nLookup forms: 9506, 0x2522, error 9506, DNS_REQUEST_PENDING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9506"]},{"id":2160,"title":"DNS_ERROR_INVALID_TYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9551","0x254F","error 9551","DNS_ERROR_INVALID_TYPE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","invalid","type"],"errorCode":"9551","eventId":"","severity":"Medium","summary":"Invalid DNS type.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9551; use the surrounding log entries to confirm it.","resolution":"1. Record where 9551 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_INVALID_TYPE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9551 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid DNS type.\n\nLookup forms: 9551, 0x254F, error 9551, DNS_ERROR_INVALID_TYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9551"]},{"id":2161,"title":"DNS_ERROR_INVALID_IP_ADDRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9552","0x2550","error 9552","DNS_ERROR_INVALID_IP_ADDRESS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","invalid","address"],"errorCode":"9552","eventId":"","severity":"Medium","summary":"Invalid IP address.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9552; use the surrounding log entries to confirm it.","resolution":"1. Record where 9552 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_INVALID_IP_ADDRESS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9552 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid IP address.\n\nLookup forms: 9552, 0x2550, error 9552, DNS_ERROR_INVALID_IP_ADDRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9552"]},{"id":2162,"title":"DNS_ERROR_INVALID_PROPERTY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9553","0x2551","error 9553","DNS_ERROR_INVALID_PROPERTY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","invalid","property"],"errorCode":"9553","eventId":"","severity":"Medium","summary":"Invalid property.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9553; use the surrounding log entries to confirm it.","resolution":"1. Record where 9553 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_INVALID_PROPERTY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9553 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid property.\n\nLookup forms: 9553, 0x2551, error 9553, DNS_ERROR_INVALID_PROPERTY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9553"]},{"id":2163,"title":"DNS_ERROR_TRY_AGAIN_LATER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9554","0x2552","error 9554","DNS_ERROR_TRY_AGAIN_LATER","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","try","again","later","operation"],"errorCode":"9554","eventId":"","severity":"Low","summary":"Try DNS operation again later.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9554; use the surrounding log entries to confirm it.","resolution":"1. Record where 9554 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_TRY_AGAIN_LATER.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9554 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Try DNS operation again later.\n\nLookup forms: 9554, 0x2552, error 9554, DNS_ERROR_TRY_AGAIN_LATER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9554"]},{"id":2164,"title":"DNS_ERROR_NOT_UNIQUE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9555","0x2553","error 9555","DNS_ERROR_NOT_UNIQUE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","not","unique","record","for","given","name","and","type"],"errorCode":"9555","eventId":"","severity":"Low","summary":"Record for given name and type is not unique.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9555; use the surrounding log entries to confirm it.","resolution":"1. Record where 9555 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NOT_UNIQUE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9555 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Record for given name and type is not unique.\n\nLookup forms: 9555, 0x2553, error 9555, DNS_ERROR_NOT_UNIQUE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9555"]},{"id":2165,"title":"DNS_ERROR_NON_RFC_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9556","0x2554","error 9556","DNS_ERROR_NON_RFC_NAME","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","non","rfc","name","does","not","comply","with","specifications"],"errorCode":"9556","eventId":"","severity":"Low","summary":"DNS name does not comply with RFC specifications.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9556; use the surrounding log entries to confirm it.","resolution":"1. Record where 9556 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NON_RFC_NAME.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9556 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS name does not comply with RFC specifications.\n\nLookup forms: 9556, 0x2554, error 9556, DNS_ERROR_NON_RFC_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9556"]},{"id":2166,"title":"DNS_STATUS_FQDN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9557","0x2555","error 9557","DNS_STATUS_FQDN","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","status","fqdn","name","fully","qualified"],"errorCode":"9557","eventId":"","severity":"Low","summary":"DNS name is a fully-qualified DNS name.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9557; use the surrounding log entries to confirm it.","resolution":"1. Record where 9557 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_STATUS_FQDN.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9557 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS name is a fully-qualified DNS name.\n\nLookup forms: 9557, 0x2555, error 9557, DNS_STATUS_FQDN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9557"]},{"id":2167,"title":"DNS_STATUS_DOTTED_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9558","0x2556","error 9558","DNS_STATUS_DOTTED_NAME","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","status","dotted","name","multi","label"],"errorCode":"9558","eventId":"","severity":"Low","summary":"DNS name is dotted (multi-label).","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9558; use the surrounding log entries to confirm it.","resolution":"1. Record where 9558 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_STATUS_DOTTED_NAME.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9558 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS name is dotted (multi-label).\n\nLookup forms: 9558, 0x2556, error 9558, DNS_STATUS_DOTTED_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9558"]},{"id":2168,"title":"DNS_STATUS_SINGLE_PART_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9559","0x2557","error 9559","DNS_STATUS_SINGLE_PART_NAME","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","status","single","part","name"],"errorCode":"9559","eventId":"","severity":"Low","summary":"DNS name is a single-part name.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9559; use the surrounding log entries to confirm it.","resolution":"1. Record where 9559 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_STATUS_SINGLE_PART_NAME.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9559 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS name is a single-part name.\n\nLookup forms: 9559, 0x2557, error 9559, DNS_STATUS_SINGLE_PART_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9559"]},{"id":2169,"title":"DNS_ERROR_INVALID_NAME_CHAR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9560","0x2558","error 9560","DNS_ERROR_INVALID_NAME_CHAR","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","invalid","name","char","contains","character"],"errorCode":"9560","eventId":"","severity":"Medium","summary":"DNS name contains an invalid character.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9560; use the surrounding log entries to confirm it.","resolution":"1. Record where 9560 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_INVALID_NAME_CHAR.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9560 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS name contains an invalid character.\n\nLookup forms: 9560, 0x2558, error 9560, DNS_ERROR_INVALID_NAME_CHAR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): DSN name contains an invalid character.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9560"]},{"id":2170,"title":"DNS_ERROR_NUMERIC_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9561","0x2559","error 9561","DNS_ERROR_NUMERIC_NAME","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","numeric","name","entirely"],"errorCode":"9561","eventId":"","severity":"Low","summary":"DNS name is entirely numeric.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9561; use the surrounding log entries to confirm it.","resolution":"1. Record where 9561 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NUMERIC_NAME.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9561 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS name is entirely numeric.\n\nLookup forms: 9561, 0x2559, error 9561, DNS_ERROR_NUMERIC_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9561"]},{"id":2171,"title":"DNS_ERROR_NOT_ALLOWED_ON_ROOT_SERVER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9562","0x255A","error 9562","DNS_ERROR_NOT_ALLOWED_ON_ROOT_SERVER","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","not","allowed","root","server","the","operation","requested","permitted"],"errorCode":"9562","eventId":"","severity":"Low","summary":"The operation requested is not permitted on a DNS root server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9562; use the surrounding log entries to confirm it.","resolution":"1. Record where 9562 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NOT_ALLOWED_ON_ROOT_SERVER.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9562 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation requested is not permitted on a DNS root server.\n\nLookup forms: 9562, 0x255A, error 9562, DNS_ERROR_NOT_ALLOWED_ON_ROOT_SERVER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9562"]},{"id":2172,"title":"DNS_ERROR_NOT_ALLOWED_UNDER_DELEGATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9563","0x255B","error 9563","DNS_ERROR_NOT_ALLOWED_UNDER_DELEGATION","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","not","allowed","under","delegation","the","record","could","created","because","this","part","namespace","has","been","delegated","another","server"],"errorCode":"9563","eventId":"","severity":"Low","summary":"The record could not be created because this part of the DNS namespace has been delegated to another server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9563; use the surrounding log entries to confirm it.","resolution":"1. Record where 9563 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NOT_ALLOWED_UNDER_DELEGATION.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9563 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The record could not be created because this part of the DNS namespace has been delegated to another server.\n\nLookup forms: 9563, 0x255B, error 9563, DNS_ERROR_NOT_ALLOWED_UNDER_DELEGATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9563"]},{"id":2173,"title":"DNS_ERROR_CANNOT_FIND_ROOT_HINTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9564","0x255C","error 9564","DNS_ERROR_CANNOT_FIND_ROOT_HINTS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","cannot","find","root","hints","the","server","could","not","set"],"errorCode":"9564","eventId":"","severity":"Low","summary":"The DNS server could not find a set of root hints.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9564; use the surrounding log entries to confirm it.","resolution":"1. Record where 9564 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_CANNOT_FIND_ROOT_HINTS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9564 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The DNS server could not find a set of root hints.\n\nLookup forms: 9564, 0x255C, error 9564, DNS_ERROR_CANNOT_FIND_ROOT_HINTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9564"]},{"id":2174,"title":"DNS_ERROR_INCONSISTENT_ROOT_HINTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9565","0x255D","error 9565","DNS_ERROR_INCONSISTENT_ROOT_HINTS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","inconsistent","root","hints","the","server","found","but","they","were","not","consistent","across","all","adapters"],"errorCode":"9565","eventId":"","severity":"Low","summary":"The DNS server found root hints but they were not consistent across all adapters.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9565; use the surrounding log entries to confirm it.","resolution":"1. Record where 9565 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_INCONSISTENT_ROOT_HINTS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9565 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The DNS server found root hints but they were not consistent across all adapters.\n\nLookup forms: 9565, 0x255D, error 9565, DNS_ERROR_INCONSISTENT_ROOT_HINTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9565"]},{"id":2175,"title":"DNS_ERROR_DWORD_VALUE_TOO_SMALL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9566","0x255E","error 9566","DNS_ERROR_DWORD_VALUE_TOO_SMALL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","dword","value","too","small","the","specified","for","this","parameter"],"errorCode":"9566","eventId":"","severity":"Low","summary":"The specified value is too small for this parameter.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9566; use the surrounding log entries to confirm it.","resolution":"1. Record where 9566 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_DWORD_VALUE_TOO_SMALL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9566 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified value is too small for this parameter.\n\nLookup forms: 9566, 0x255E, error 9566, DNS_ERROR_DWORD_VALUE_TOO_SMALL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9566"]},{"id":2176,"title":"DNS_ERROR_DWORD_VALUE_TOO_LARGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9567","0x255F","error 9567","DNS_ERROR_DWORD_VALUE_TOO_LARGE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","dword","value","too","large","the","specified","for","this","parameter"],"errorCode":"9567","eventId":"","severity":"Low","summary":"The specified value is too large for this parameter.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9567; use the surrounding log entries to confirm it.","resolution":"1. Record where 9567 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_DWORD_VALUE_TOO_LARGE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9567 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified value is too large for this parameter.\n\nLookup forms: 9567, 0x255F, error 9567, DNS_ERROR_DWORD_VALUE_TOO_LARGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9567"]},{"id":2177,"title":"DNS_ERROR_BACKGROUND_LOADING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9568","0x2560","error 9568","DNS_ERROR_BACKGROUND_LOADING","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","background","loading","this","operation","not","allowed","while","the","server","zones","please","try","again","later"],"errorCode":"9568","eventId":"","severity":"Low","summary":"This operation is not allowed while the DNS server is loading zones in the background. Please try again later.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9568; use the surrounding log entries to confirm it.","resolution":"1. Record where 9568 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_BACKGROUND_LOADING.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9568 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation is not allowed while the DNS server is loading zones in the background. Please try again later.\n\nLookup forms: 9568, 0x2560, error 9568, DNS_ERROR_BACKGROUND_LOADING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9568"]},{"id":2178,"title":"DNS_ERROR_NOT_ALLOWED_ON_RODC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9569","0x2561","error 9569","DNS_ERROR_NOT_ALLOWED_ON_RODC","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","not","allowed","rodc","the","operation","requested","permitted","against","server","running","read","only"],"errorCode":"9569","eventId":"","severity":"Low","summary":"The operation requested is not permitted on against a DNS server running on a read-only DC.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9569; use the surrounding log entries to confirm it.","resolution":"1. Record where 9569 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NOT_ALLOWED_ON_RODC.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9569 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation requested is not permitted on against a DNS server running on a read-only DC.\n\nLookup forms: 9569, 0x2561, error 9569, DNS_ERROR_NOT_ALLOWED_ON_RODC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9569"]},{"id":2179,"title":"DNS_ERROR_NOT_ALLOWED_UNDER_DNAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9570","0x2562","error 9570","DNS_ERROR_NOT_ALLOWED_UNDER_DNAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","not","allowed","under","dname","data","exist","underneath","record"],"errorCode":"9570","eventId":"","severity":"Low","summary":"No data is allowed to exist underneath a DNAME record.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9570; use the surrounding log entries to confirm it.","resolution":"1. Record where 9570 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NOT_ALLOWED_UNDER_DNAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9570 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No data is allowed to exist underneath a DNAME record.\n\nLookup forms: 9570, 0x2562, error 9570, DNS_ERROR_NOT_ALLOWED_UNDER_DNAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9570"]},{"id":2180,"title":"DNS_ERROR_DELEGATION_REQUIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9571","0x2563","error 9571","DNS_ERROR_DELEGATION_REQUIRED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","delegation","required","this","operation","requires","credentials"],"errorCode":"9571","eventId":"","severity":"Low","summary":"This operation requires credentials delegation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9571; use the surrounding log entries to confirm it.","resolution":"1. Record where 9571 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_DELEGATION_REQUIRED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9571 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation requires credentials delegation.\n\nLookup forms: 9571, 0x2563, error 9571, DNS_ERROR_DELEGATION_REQUIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9571"]},{"id":2181,"title":"DNS_ERROR_INVALID_POLICY_TABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9572","0x2564","error 9572","DNS_ERROR_INVALID_POLICY_TABLE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","invalid","policy","table","name","resolution","has","been","corrupted","will","fail","until","fixed","contact","your","network","administrator"],"errorCode":"9572","eventId":"","severity":"Critical","summary":"Name resolution policy table has been corrupted. DNS resolution will fail until it is fixed. Contact your network administrator.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9572; use the surrounding log entries to confirm it.","resolution":"1. Record where 9572 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_INVALID_POLICY_TABLE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9572 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Name resolution policy table has been corrupted. DNS resolution will fail until it is fixed. Contact your network administrator.\n\nLookup forms: 9572, 0x2564, error 9572, DNS_ERROR_INVALID_POLICY_TABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9572"]},{"id":2182,"title":"DNS_ERROR_ZONE_DOES_NOT_EXIST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9601","0x2581","error 9601","DNS_ERROR_ZONE_DOES_NOT_EXIST","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","zone","does","not","exist"],"errorCode":"9601","eventId":"","severity":"Low","summary":"DNS zone does not exist.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9601; use the surrounding log entries to confirm it.","resolution":"1. Record where 9601 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_ZONE_DOES_NOT_EXIST.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9601 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS zone does not exist.\n\nLookup forms: 9601, 0x2581, error 9601, DNS_ERROR_ZONE_DOES_NOT_EXIST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9601"]},{"id":2183,"title":"DNS_ERROR_NO_ZONE_INFO","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9602","0x2582","error 9602","DNS_ERROR_NO_ZONE_INFO","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","zone","info","information","not","available"],"errorCode":"9602","eventId":"","severity":"Low","summary":"DNS zone information not available.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9602; use the surrounding log entries to confirm it.","resolution":"1. Record where 9602 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NO_ZONE_INFO.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9602 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS zone information not available.\n\nLookup forms: 9602, 0x2582, error 9602, DNS_ERROR_NO_ZONE_INFO. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9602"]},{"id":2184,"title":"DNS_ERROR_INVALID_ZONE_OPERATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9603","0x2583","error 9603","DNS_ERROR_INVALID_ZONE_OPERATION","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","invalid","zone","operation","for"],"errorCode":"9603","eventId":"","severity":"Medium","summary":"Invalid operation for DNS zone.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9603; use the surrounding log entries to confirm it.","resolution":"1. Record where 9603 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_INVALID_ZONE_OPERATION.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9603 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid operation for DNS zone.\n\nLookup forms: 9603, 0x2583, error 9603, DNS_ERROR_INVALID_ZONE_OPERATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9603"]},{"id":2185,"title":"DNS_ERROR_ZONE_CONFIGURATION_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9604","0x2584","error 9604","DNS_ERROR_ZONE_CONFIGURATION_ERROR","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","zone","configuration","invalid"],"errorCode":"9604","eventId":"","severity":"Medium","summary":"Invalid DNS zone configuration.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9604; use the surrounding log entries to confirm it.","resolution":"1. Record where 9604 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_ZONE_CONFIGURATION_ERROR.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9604 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid DNS zone configuration.\n\nLookup forms: 9604, 0x2584, error 9604, DNS_ERROR_ZONE_CONFIGURATION_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9604"]},{"id":2186,"title":"DNS_ERROR_ZONE_HAS_NO_SOA_RECORD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9605","0x2585","error 9605","DNS_ERROR_ZONE_HAS_NO_SOA_RECORD","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","zone","has","soa","record","start","authority"],"errorCode":"9605","eventId":"","severity":"Low","summary":"DNS zone has no start of authority (SOA) record.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9605; use the surrounding log entries to confirm it.","resolution":"1. Record where 9605 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_ZONE_HAS_NO_SOA_RECORD.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9605 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS zone has no start of authority (SOA) record.\n\nLookup forms: 9605, 0x2585, error 9605, DNS_ERROR_ZONE_HAS_NO_SOA_RECORD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9605"]},{"id":2187,"title":"DNS_ERROR_ZONE_HAS_NO_NS_RECORDS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9606","0x2586","error 9606","DNS_ERROR_ZONE_HAS_NO_NS_RECORDS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","zone","has","records","name","server","record"],"errorCode":"9606","eventId":"","severity":"Low","summary":"DNS zone has no Name Server (NS) record.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9606; use the surrounding log entries to confirm it.","resolution":"1. Record where 9606 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_ZONE_HAS_NO_NS_RECORDS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9606 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS zone has no Name Server (NS) record.\n\nLookup forms: 9606, 0x2586, error 9606, DNS_ERROR_ZONE_HAS_NO_NS_RECORDS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): DNS zone has no name server (NS) record.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9606"]},{"id":2188,"title":"DNS_ERROR_ZONE_LOCKED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9607","0x2587","error 9607","DNS_ERROR_ZONE_LOCKED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","zone","locked"],"errorCode":"9607","eventId":"","severity":"High","summary":"DNS zone is locked.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9607; use the surrounding log entries to confirm it.","resolution":"1. Record where 9607 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_ZONE_LOCKED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9607 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS zone is locked.\n\nLookup forms: 9607, 0x2587, error 9607, DNS_ERROR_ZONE_LOCKED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9607"]},{"id":2189,"title":"DNS_ERROR_ZONE_CREATION_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9608","0x2588","error 9608","DNS_ERROR_ZONE_CREATION_FAILED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","zone","creation","failed"],"errorCode":"9608","eventId":"","severity":"High","summary":"DNS zone creation failed.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9608; use the surrounding log entries to confirm it.","resolution":"1. Record where 9608 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_ZONE_CREATION_FAILED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9608 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS zone creation failed.\n\nLookup forms: 9608, 0x2588, error 9608, DNS_ERROR_ZONE_CREATION_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9608"]},{"id":2190,"title":"DNS_ERROR_ZONE_ALREADY_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9609","0x2589","error 9609","DNS_ERROR_ZONE_ALREADY_EXISTS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","zone","already","exists"],"errorCode":"9609","eventId":"","severity":"Medium","summary":"DNS zone already exists.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9609; use the surrounding log entries to confirm it.","resolution":"1. Record where 9609 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_ZONE_ALREADY_EXISTS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9609 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS zone already exists.\n\nLookup forms: 9609, 0x2589, error 9609, DNS_ERROR_ZONE_ALREADY_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9609"]},{"id":2191,"title":"DNS_ERROR_AUTOZONE_ALREADY_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9610","0x258A","error 9610","DNS_ERROR_AUTOZONE_ALREADY_EXISTS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","autozone","already","exists","automatic","zone"],"errorCode":"9610","eventId":"","severity":"Medium","summary":"DNS automatic zone already exists.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9610; use the surrounding log entries to confirm it.","resolution":"1. Record where 9610 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_AUTOZONE_ALREADY_EXISTS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9610 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS automatic zone already exists.\n\nLookup forms: 9610, 0x258A, error 9610, DNS_ERROR_AUTOZONE_ALREADY_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9610"]},{"id":2192,"title":"DNS_ERROR_INVALID_ZONE_TYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9611","0x258B","error 9611","DNS_ERROR_INVALID_ZONE_TYPE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","invalid","zone","type"],"errorCode":"9611","eventId":"","severity":"Medium","summary":"Invalid DNS zone type.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9611; use the surrounding log entries to confirm it.","resolution":"1. Record where 9611 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_INVALID_ZONE_TYPE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9611 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid DNS zone type.\n\nLookup forms: 9611, 0x258B, error 9611, DNS_ERROR_INVALID_ZONE_TYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9611"]},{"id":2193,"title":"DNS_ERROR_SECONDARY_REQUIRES_MASTER_IP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9612","0x258C","error 9612","DNS_ERROR_SECONDARY_REQUIRES_MASTER_IP","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","secondary","requires","master","zone","address"],"errorCode":"9612","eventId":"","severity":"Low","summary":"Secondary DNS zone requires master IP address.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9612; use the surrounding log entries to confirm it.","resolution":"1. Record where 9612 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_SECONDARY_REQUIRES_MASTER_IP.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9612 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Secondary DNS zone requires master IP address.\n\nLookup forms: 9612, 0x258C, error 9612, DNS_ERROR_SECONDARY_REQUIRES_MASTER_IP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9612"]},{"id":2194,"title":"DNS_ERROR_ZONE_NOT_SECONDARY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9613","0x258D","error 9613","DNS_ERROR_ZONE_NOT_SECONDARY","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","zone","not","secondary"],"errorCode":"9613","eventId":"","severity":"Low","summary":"DNS zone not secondary.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9613; use the surrounding log entries to confirm it.","resolution":"1. Record where 9613 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_ZONE_NOT_SECONDARY.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9613 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS zone not secondary.\n\nLookup forms: 9613, 0x258D, error 9613, DNS_ERROR_ZONE_NOT_SECONDARY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9613"]},{"id":2195,"title":"DNS_ERROR_NEED_SECONDARY_ADDRESSES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9614","0x258E","error 9614","DNS_ERROR_NEED_SECONDARY_ADDRESSES","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","need","secondary","addresses","address"],"errorCode":"9614","eventId":"","severity":"Low","summary":"Need secondary IP address.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9614; use the surrounding log entries to confirm it.","resolution":"1. Record where 9614 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NEED_SECONDARY_ADDRESSES.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9614 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Need secondary IP address.\n\nLookup forms: 9614, 0x258E, error 9614, DNS_ERROR_NEED_SECONDARY_ADDRESSES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9614"]},{"id":2196,"title":"DNS_ERROR_WINS_INIT_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9615","0x258F","error 9615","DNS_ERROR_WINS_INIT_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","wins","init","failed","initialization"],"errorCode":"9615","eventId":"","severity":"High","summary":"WINS initialization failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9615; use the surrounding log entries to confirm it.","resolution":"1. Record where 9615 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_WINS_INIT_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9615 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: WINS initialization failed.\n\nLookup forms: 9615, 0x258F, error 9615, DNS_ERROR_WINS_INIT_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9615"]},{"id":2197,"title":"DNS_ERROR_NEED_WINS_SERVERS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9616","0x2590","error 9616","DNS_ERROR_NEED_WINS_SERVERS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","need","wins","servers"],"errorCode":"9616","eventId":"","severity":"Low","summary":"Need WINS servers.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9616; use the surrounding log entries to confirm it.","resolution":"1. Record where 9616 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NEED_WINS_SERVERS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9616 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Need WINS servers.\n\nLookup forms: 9616, 0x2590, error 9616, DNS_ERROR_NEED_WINS_SERVERS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9616"]},{"id":2198,"title":"DNS_ERROR_NBSTAT_INIT_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9617","0x2591","error 9617","DNS_ERROR_NBSTAT_INIT_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","nbstat","init","failed","nbtstat","initialization","call"],"errorCode":"9617","eventId":"","severity":"High","summary":"NBTSTAT initialization call failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9617; use the surrounding log entries to confirm it.","resolution":"1. Record where 9617 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NBSTAT_INIT_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9617 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: NBTSTAT initialization call failed.\n\nLookup forms: 9617, 0x2591, error 9617, DNS_ERROR_NBSTAT_INIT_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9617"]},{"id":2199,"title":"DNS_ERROR_SOA_DELETE_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9618","0x2592","error 9618","DNS_ERROR_SOA_DELETE_INVALID","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","soa","delete","invalid","start","authority"],"errorCode":"9618","eventId":"","severity":"Medium","summary":"Invalid delete of start of authority (SOA).","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9618; use the surrounding log entries to confirm it.","resolution":"1. Record where 9618 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_SOA_DELETE_INVALID.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9618 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid delete of start of authority (SOA).\n\nLookup forms: 9618, 0x2592, error 9618, DNS_ERROR_SOA_DELETE_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9618"]},{"id":2200,"title":"DNS_ERROR_FORWARDER_ALREADY_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9619","0x2593","error 9619","DNS_ERROR_FORWARDER_ALREADY_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","forwarder","already","exists","conditional","forwarding","zone","for","that","name"],"errorCode":"9619","eventId":"","severity":"Medium","summary":"A conditional forwarding zone already exists for that name.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9619; use the surrounding log entries to confirm it.","resolution":"1. Record where 9619 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_FORWARDER_ALREADY_EXISTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9619 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A conditional forwarding zone already exists for that name.\n\nLookup forms: 9619, 0x2593, error 9619, DNS_ERROR_FORWARDER_ALREADY_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9619"]},{"id":2201,"title":"DNS_ERROR_ZONE_REQUIRES_MASTER_IP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9620","0x2594","error 9620","DNS_ERROR_ZONE_REQUIRES_MASTER_IP","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","zone","requires","master","this","must","configured","with","one","more","server","addresses"],"errorCode":"9620","eventId":"","severity":"Low","summary":"This zone must be configured with one or more master DNS server IP addresses.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9620; use the surrounding log entries to confirm it.","resolution":"1. Record where 9620 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_ZONE_REQUIRES_MASTER_IP.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9620 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This zone must be configured with one or more master DNS server IP addresses.\n\nLookup forms: 9620, 0x2594, error 9620, DNS_ERROR_ZONE_REQUIRES_MASTER_IP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9620"]},{"id":2202,"title":"DNS_ERROR_ZONE_IS_SHUTDOWN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9621","0x2595","error 9621","DNS_ERROR_ZONE_IS_SHUTDOWN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","zone","shutdown","the","operation","cannot","performed","because","this","shut","down"],"errorCode":"9621","eventId":"","severity":"Medium","summary":"The operation cannot be performed because this zone is shut down.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9621; use the surrounding log entries to confirm it.","resolution":"1. Record where 9621 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_ZONE_IS_SHUTDOWN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9621 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation cannot be performed because this zone is shut down.\n\nLookup forms: 9621, 0x2595, error 9621, DNS_ERROR_ZONE_IS_SHUTDOWN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The operation cannot be performed because this zone is shutdown.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9621"]},{"id":2203,"title":"DNS_ERROR_ZONE_LOCKED_FOR_SIGNING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9622","0x2596","error 9622","DNS_ERROR_ZONE_LOCKED_FOR_SIGNING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","zone","locked","for","signing","this","operation","cannot","performed","because","the","currently","being","signed","please","try","again","later"],"errorCode":"9622","eventId":"","severity":"Medium","summary":"This operation cannot be performed because the zone is currently being signed. Please try again later.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9622; use the surrounding log entries to confirm it.","resolution":"1. Record where 9622 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_ZONE_LOCKED_FOR_SIGNING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9622 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation cannot be performed because the zone is currently being signed. Please try again later.\n\nLookup forms: 9622, 0x2596, error 9622, DNS_ERROR_ZONE_LOCKED_FOR_SIGNING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9622"]},{"id":2204,"title":"DNS_ERROR_PRIMARY_REQUIRES_DATAFILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9651","0x25B3","error 9651","DNS_ERROR_PRIMARY_REQUIRES_DATAFILE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","primary","requires","datafile","zone"],"errorCode":"9651","eventId":"","severity":"Low","summary":"Primary DNS zone requires datafile.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9651; use the surrounding log entries to confirm it.","resolution":"1. Record where 9651 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_PRIMARY_REQUIRES_DATAFILE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9651 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Primary DNS zone requires datafile.\n\nLookup forms: 9651, 0x25B3, error 9651, DNS_ERROR_PRIMARY_REQUIRES_DATAFILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9651"]},{"id":2205,"title":"DNS_ERROR_INVALID_DATAFILE_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9652","0x25B4","error 9652","DNS_ERROR_INVALID_DATAFILE_NAME","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","invalid","datafile","name","for","zone"],"errorCode":"9652","eventId":"","severity":"Medium","summary":"Invalid datafile name for DNS zone.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9652; use the surrounding log entries to confirm it.","resolution":"1. Record where 9652 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_INVALID_DATAFILE_NAME.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9652 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid datafile name for DNS zone.\n\nLookup forms: 9652, 0x25B4, error 9652, DNS_ERROR_INVALID_DATAFILE_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9652"]},{"id":2206,"title":"DNS_ERROR_DATAFILE_OPEN_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9653","0x25B5","error 9653","DNS_ERROR_DATAFILE_OPEN_FAILURE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","datafile","open","failure","failed","for","zone"],"errorCode":"9653","eventId":"","severity":"High","summary":"Failed to open datafile for DNS zone.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9653; use the surrounding log entries to confirm it.","resolution":"1. Record where 9653 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_DATAFILE_OPEN_FAILURE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9653 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Failed to open datafile for DNS zone.\n\nLookup forms: 9653, 0x25B5, error 9653, DNS_ERROR_DATAFILE_OPEN_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9653"]},{"id":2207,"title":"DNS_ERROR_FILE_WRITEBACK_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9654","0x25B6","error 9654","DNS_ERROR_FILE_WRITEBACK_FAILED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","file","writeback","failed","write","datafile","for","zone"],"errorCode":"9654","eventId":"","severity":"High","summary":"Failed to write datafile for DNS zone.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9654; use the surrounding log entries to confirm it.","resolution":"1. Record where 9654 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_FILE_WRITEBACK_FAILED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9654 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Failed to write datafile for DNS zone.\n\nLookup forms: 9654, 0x25B6, error 9654, DNS_ERROR_FILE_WRITEBACK_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9654"]},{"id":2208,"title":"DNS_ERROR_DATAFILE_PARSING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9655","0x25B7","error 9655","DNS_ERROR_DATAFILE_PARSING","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","datafile","parsing","failure","while","reading","for","zone"],"errorCode":"9655","eventId":"","severity":"High","summary":"Failure while reading datafile for DNS zone.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9655; use the surrounding log entries to confirm it.","resolution":"1. Record where 9655 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_DATAFILE_PARSING.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9655 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Failure while reading datafile for DNS zone.\n\nLookup forms: 9655, 0x25B7, error 9655, DNS_ERROR_DATAFILE_PARSING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9655"]},{"id":2209,"title":"DNS_ERROR_RECORD_DOES_NOT_EXIST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9701","0x25E5","error 9701","DNS_ERROR_RECORD_DOES_NOT_EXIST","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","record","does","not","exist"],"errorCode":"9701","eventId":"","severity":"Low","summary":"DNS record does not exist.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9701; use the surrounding log entries to confirm it.","resolution":"1. Record where 9701 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_RECORD_DOES_NOT_EXIST.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9701 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS record does not exist.\n\nLookup forms: 9701, 0x25E5, error 9701, DNS_ERROR_RECORD_DOES_NOT_EXIST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9701"]},{"id":2210,"title":"DNS_ERROR_RECORD_FORMAT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9702","0x25E6","error 9702","DNS_ERROR_RECORD_FORMAT","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","record","format"],"errorCode":"9702","eventId":"","severity":"Low","summary":"DNS record format error.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9702; use the surrounding log entries to confirm it.","resolution":"1. Record where 9702 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_RECORD_FORMAT.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9702 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS record format error.\n\nLookup forms: 9702, 0x25E6, error 9702, DNS_ERROR_RECORD_FORMAT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9702"]},{"id":2211,"title":"DNS_ERROR_NODE_CREATION_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9703","0x25E7","error 9703","DNS_ERROR_NODE_CREATION_FAILED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","node","creation","failed","failure"],"errorCode":"9703","eventId":"","severity":"High","summary":"Node creation failure in DNS.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9703; use the surrounding log entries to confirm it.","resolution":"1. Record where 9703 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NODE_CREATION_FAILED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9703 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Node creation failure in DNS.\n\nLookup forms: 9703, 0x25E7, error 9703, DNS_ERROR_NODE_CREATION_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9703"]},{"id":2212,"title":"DNS_ERROR_UNKNOWN_RECORD_TYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9704","0x25E8","error 9704","DNS_ERROR_UNKNOWN_RECORD_TYPE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","unknown","record","type"],"errorCode":"9704","eventId":"","severity":"Low","summary":"Unknown DNS record type.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9704; use the surrounding log entries to confirm it.","resolution":"1. Record where 9704 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_UNKNOWN_RECORD_TYPE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9704 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unknown DNS record type.\n\nLookup forms: 9704, 0x25E8, error 9704, DNS_ERROR_UNKNOWN_RECORD_TYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9704"]},{"id":2213,"title":"DNS_ERROR_RECORD_TIMED_OUT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9705","0x25E9","error 9705","DNS_ERROR_RECORD_TIMED_OUT","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","record","timed","out"],"errorCode":"9705","eventId":"","severity":"Low","summary":"DNS record timed out.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9705; use the surrounding log entries to confirm it.","resolution":"1. Record where 9705 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_RECORD_TIMED_OUT.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9705 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS record timed out.\n\nLookup forms: 9705, 0x25E9, error 9705, DNS_ERROR_RECORD_TIMED_OUT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9705"]},{"id":2214,"title":"DNS_ERROR_NAME_NOT_IN_ZONE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9706","0x25EA","error 9706","DNS_ERROR_NAME_NOT_IN_ZONE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","name","not","zone"],"errorCode":"9706","eventId":"","severity":"Low","summary":"Name not in DNS zone.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9706; use the surrounding log entries to confirm it.","resolution":"1. Record where 9706 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NAME_NOT_IN_ZONE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9706 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Name not in DNS zone.\n\nLookup forms: 9706, 0x25EA, error 9706, DNS_ERROR_NAME_NOT_IN_ZONE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9706"]},{"id":2215,"title":"DNS_ERROR_CNAME_LOOP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9707","0x25EB","error 9707","DNS_ERROR_CNAME_LOOP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","cname","loop","detected"],"errorCode":"9707","eventId":"","severity":"Low","summary":"CNAME loop detected.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9707; use the surrounding log entries to confirm it.","resolution":"1. Record where 9707 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_CNAME_LOOP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9707 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: CNAME loop detected.\n\nLookup forms: 9707, 0x25EB, error 9707, DNS_ERROR_CNAME_LOOP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9707"]},{"id":2216,"title":"DNS_ERROR_NODE_IS_CNAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9708","0x25EC","error 9708","DNS_ERROR_NODE_IS_CNAME","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","node","cname","record"],"errorCode":"9708","eventId":"","severity":"Low","summary":"Node is a CNAME DNS record.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9708; use the surrounding log entries to confirm it.","resolution":"1. Record where 9708 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NODE_IS_CNAME.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9708 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Node is a CNAME DNS record.\n\nLookup forms: 9708, 0x25EC, error 9708, DNS_ERROR_NODE_IS_CNAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9708"]},{"id":2217,"title":"DNS_ERROR_CNAME_COLLISION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9709","0x25ED","error 9709","DNS_ERROR_CNAME_COLLISION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","cname","collision","record","already","exists","for","given","name"],"errorCode":"9709","eventId":"","severity":"Medium","summary":"A CNAME record already exists for given name.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9709; use the surrounding log entries to confirm it.","resolution":"1. Record where 9709 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_CNAME_COLLISION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9709 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A CNAME record already exists for given name.\n\nLookup forms: 9709, 0x25ED, error 9709, DNS_ERROR_CNAME_COLLISION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9709"]},{"id":2218,"title":"DNS_ERROR_RECORD_ONLY_AT_ZONE_ROOT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9710","0x25EE","error 9710","DNS_ERROR_RECORD_ONLY_AT_ZONE_ROOT","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","record","only","zone","root"],"errorCode":"9710","eventId":"","severity":"Low","summary":"Record only at DNS zone root.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9710; use the surrounding log entries to confirm it.","resolution":"1. Record where 9710 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_RECORD_ONLY_AT_ZONE_ROOT.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9710 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Record only at DNS zone root.\n\nLookup forms: 9710, 0x25EE, error 9710, DNS_ERROR_RECORD_ONLY_AT_ZONE_ROOT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9710"]},{"id":2219,"title":"DNS_ERROR_RECORD_ALREADY_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9711","0x25EF","error 9711","DNS_ERROR_RECORD_ALREADY_EXISTS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","record","already","exists"],"errorCode":"9711","eventId":"","severity":"Medium","summary":"DNS record already exists.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9711; use the surrounding log entries to confirm it.","resolution":"1. Record where 9711 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_RECORD_ALREADY_EXISTS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9711 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS record already exists.\n\nLookup forms: 9711, 0x25EF, error 9711, DNS_ERROR_RECORD_ALREADY_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9711"]},{"id":2220,"title":"DNS_ERROR_SECONDARY_DATA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9712","0x25F0","error 9712","DNS_ERROR_SECONDARY_DATA","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","secondary","data","zone"],"errorCode":"9712","eventId":"","severity":"Low","summary":"Secondary DNS zone data error.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9712; use the surrounding log entries to confirm it.","resolution":"1. Record where 9712 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_SECONDARY_DATA.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9712 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Secondary DNS zone data error.\n\nLookup forms: 9712, 0x25F0, error 9712, DNS_ERROR_SECONDARY_DATA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9712"]},{"id":2221,"title":"DNS_ERROR_NO_CREATE_CACHE_DATA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9713","0x25F1","error 9713","DNS_ERROR_NO_CREATE_CACHE_DATA","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","create","cache","data","could","not"],"errorCode":"9713","eventId":"","severity":"Low","summary":"Could not create DNS cache data.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9713; use the surrounding log entries to confirm it.","resolution":"1. Record where 9713 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NO_CREATE_CACHE_DATA.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9713 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Could not create DNS cache data.\n\nLookup forms: 9713, 0x25F1, error 9713, DNS_ERROR_NO_CREATE_CACHE_DATA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9713"]},{"id":2222,"title":"DNS_ERROR_NAME_DOES_NOT_EXIST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9714","0x25F2","error 9714","DNS_ERROR_NAME_DOES_NOT_EXIST","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","name","does","not","exist"],"errorCode":"9714","eventId":"","severity":"Low","summary":"DNS name does not exist.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9714; use the surrounding log entries to confirm it.","resolution":"1. Record where 9714 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NAME_DOES_NOT_EXIST.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9714 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS name does not exist.\n\nLookup forms: 9714, 0x25F2, error 9714, DNS_ERROR_NAME_DOES_NOT_EXIST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9714"]},{"id":2223,"title":"DNS_WARNING_PTR_CREATE_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9715","0x25F3","error 9715","DNS_WARNING_PTR_CREATE_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","warning","ptr","create","failed","could","not","pointer","record"],"errorCode":"9715","eventId":"","severity":"Low","summary":"Could not create pointer (PTR) record.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9715; use the surrounding log entries to confirm it.","resolution":"1. Record where 9715 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_WARNING_PTR_CREATE_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9715 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Could not create pointer (PTR) record.\n\nLookup forms: 9715, 0x25F3, error 9715, DNS_WARNING_PTR_CREATE_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9715"]},{"id":2224,"title":"DNS_WARNING_DOMAIN_UNDELETED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9716","0x25F4","error 9716","DNS_WARNING_DOMAIN_UNDELETED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","warning","domain","undeleted","was"],"errorCode":"9716","eventId":"","severity":"Low","summary":"DNS domain was undeleted.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9716; use the surrounding log entries to confirm it.","resolution":"1. Record where 9716 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_WARNING_DOMAIN_UNDELETED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9716 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS domain was undeleted.\n\nLookup forms: 9716, 0x25F4, error 9716, DNS_WARNING_DOMAIN_UNDELETED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9716"]},{"id":2225,"title":"DNS_ERROR_DS_UNAVAILABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9717","0x25F5","error 9717","DNS_ERROR_DS_UNAVAILABLE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","dns","error","unavailable","the","directory","service"],"errorCode":"9717","eventId":"","severity":"Low","summary":"The directory service is unavailable.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 9717; use the surrounding log entries to confirm it.","resolution":"1. Record where 9717 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_DS_UNAVAILABLE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9717 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory service is unavailable.\n\nLookup forms: 9717, 0x25F5, error 9717, DNS_ERROR_DS_UNAVAILABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9717"]},{"id":2226,"title":"DNS_ERROR_DS_ZONE_ALREADY_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9718","0x25F6","error 9718","DNS_ERROR_DS_ZONE_ALREADY_EXISTS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","zone","already","exists","the","directory","service"],"errorCode":"9718","eventId":"","severity":"Medium","summary":"DNS zone already exists in the directory service.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9718; use the surrounding log entries to confirm it.","resolution":"1. Record where 9718 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Verify the required service or agent is installed, running, and current; repair the component if needed.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_DS_ZONE_ALREADY_EXISTS.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9718 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS zone already exists in the directory service.\n\nLookup forms: 9718, 0x25F6, error 9718, DNS_ERROR_DS_ZONE_ALREADY_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9718"]},{"id":2227,"title":"DNS_ERROR_NO_BOOTFILE_IF_DS_ZONE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9719","0x25F7","error 9719","DNS_ERROR_NO_BOOTFILE_IF_DS_ZONE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","bootfile","zone","server","not","creating","reading","the","boot","file","for","directory","service","integrated"],"errorCode":"9719","eventId":"","severity":"Low","summary":"DNS server not creating or reading the boot file for the directory service integrated DNS zone.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9719; use the surrounding log entries to confirm it.","resolution":"1. Record where 9719 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Verify the required service or agent is installed, running, and current; repair the component if needed.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NO_BOOTFILE_IF_DS_ZONE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9719 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS server not creating or reading the boot file for the directory service integrated DNS zone.\n\nLookup forms: 9719, 0x25F7, error 9719, DNS_ERROR_NO_BOOTFILE_IF_DS_ZONE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9719"]},{"id":2228,"title":"DNS_ERROR_NODE_IS_DNAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9720","0x25F8","error 9720","DNS_ERROR_NODE_IS_DNAME","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","node","dname","record"],"errorCode":"9720","eventId":"","severity":"Low","summary":"Node is a DNAME DNS record.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9720; use the surrounding log entries to confirm it.","resolution":"1. Record where 9720 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NODE_IS_DNAME.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9720 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Node is a DNAME DNS record.\n\nLookup forms: 9720, 0x25F8, error 9720, DNS_ERROR_NODE_IS_DNAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9720"]},{"id":2229,"title":"DNS_ERROR_DNAME_COLLISION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9721","0x25F9","error 9721","DNS_ERROR_DNAME_COLLISION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","dname","collision","record","already","exists","for","given","name"],"errorCode":"9721","eventId":"","severity":"Medium","summary":"A DNAME record already exists for given name.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9721; use the surrounding log entries to confirm it.","resolution":"1. Record where 9721 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_DNAME_COLLISION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9721 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A DNAME record already exists for given name.\n\nLookup forms: 9721, 0x25F9, error 9721, DNS_ERROR_DNAME_COLLISION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9721"]},{"id":2230,"title":"DNS_ERROR_ALIAS_LOOP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9722","0x25FA","error 9722","DNS_ERROR_ALIAS_LOOP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","dns","error","alias","loop","has","been","detected","with","either","cname","dname","records"],"errorCode":"9722","eventId":"","severity":"Low","summary":"An alias loop has been detected with either CNAME or DNAME records.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 9722; use the surrounding log entries to confirm it.","resolution":"1. Record where 9722 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_ALIAS_LOOP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9722 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An alias loop has been detected with either CNAME or DNAME records.\n\nLookup forms: 9722, 0x25FA, error 9722, DNS_ERROR_ALIAS_LOOP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9722"]},{"id":2231,"title":"DNS_INFO_AXFR_COMPLETE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9751","0x2617","error 9751","DNS_INFO_AXFR_COMPLETE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","info","axfr","complete","zone","transfer"],"errorCode":"9751","eventId":"","severity":"Low","summary":"DNS AXFR (zone transfer) complete.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9751; use the surrounding log entries to confirm it.","resolution":"1. Record where 9751 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_INFO_AXFR_COMPLETE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9751 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS AXFR (zone transfer) complete.\n\nLookup forms: 9751, 0x2617, error 9751, DNS_INFO_AXFR_COMPLETE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9751"]},{"id":2232,"title":"DNS_ERROR_AXFR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9752","0x2618","error 9752","DNS_ERROR_AXFR","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","axfr","zone","transfer","failed"],"errorCode":"9752","eventId":"","severity":"High","summary":"DNS zone transfer failed.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9752; use the surrounding log entries to confirm it.","resolution":"1. Record where 9752 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_AXFR.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9752 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DNS zone transfer failed.\n\nLookup forms: 9752, 0x2618, error 9752, DNS_ERROR_AXFR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9752"]},{"id":2233,"title":"DNS_INFO_ADDED_LOCAL_WINS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9753","0x2619","error 9753","DNS_INFO_ADDED_LOCAL_WINS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","info","added","local","wins","server"],"errorCode":"9753","eventId":"","severity":"Low","summary":"Added local WINS server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9753; use the surrounding log entries to confirm it.","resolution":"1. Record where 9753 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_INFO_ADDED_LOCAL_WINS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9753 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Added local WINS server.\n\nLookup forms: 9753, 0x2619, error 9753, DNS_INFO_ADDED_LOCAL_WINS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9753"]},{"id":2234,"title":"DNS_STATUS_CONTINUE_NEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9801","0x2649","error 9801","DNS_STATUS_CONTINUE_NEEDED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","dns","status","continue","needed","secure","update","call","needs","request"],"errorCode":"9801","eventId":"","severity":"Low","summary":"Secure update call needs to continue update request.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 9801; use the surrounding log entries to confirm it.","resolution":"1. Record where 9801 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_STATUS_CONTINUE_NEEDED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9801 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Secure update call needs to continue update request.\n\nLookup forms: 9801, 0x2649, error 9801, DNS_STATUS_CONTINUE_NEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9801"]},{"id":2235,"title":"DNS_ERROR_NO_TCPIP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9851","0x267B","error 9851","DNS_ERROR_NO_TCPIP","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","tcpip","tcp","network","protocol","not","installed"],"errorCode":"9851","eventId":"","severity":"High","summary":"TCP/IP network protocol not installed.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9851; use the surrounding log entries to confirm it.","resolution":"1. Record where 9851 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NO_TCPIP.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9851 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: TCP/IP network protocol not installed.\n\nLookup forms: 9851, 0x267B, error 9851, DNS_ERROR_NO_TCPIP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9851"]},{"id":2236,"title":"DNS_ERROR_NO_DNS_SERVERS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9852","0x267C","error 9852","DNS_ERROR_NO_DNS_SERVERS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","servers","configured","for","local","system"],"errorCode":"9852","eventId":"","severity":"Low","summary":"No DNS servers configured for local system.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9852; use the surrounding log entries to confirm it.","resolution":"1. Record where 9852 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_NO_DNS_SERVERS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9852 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No DNS servers configured for local system.\n\nLookup forms: 9852, 0x267C, error 9852, DNS_ERROR_NO_DNS_SERVERS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9852"]},{"id":2237,"title":"DNS_ERROR_DP_DOES_NOT_EXIST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9901","0x26AD","error 9901","DNS_ERROR_DP_DOES_NOT_EXIST","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","dns","error","does","not","exist","the","specified","directory","partition"],"errorCode":"9901","eventId":"","severity":"Low","summary":"The specified directory partition does not exist.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 9901; use the surrounding log entries to confirm it.","resolution":"1. Record where 9901 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_DP_DOES_NOT_EXIST.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9901 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified directory partition does not exist.\n\nLookup forms: 9901, 0x26AD, error 9901, DNS_ERROR_DP_DOES_NOT_EXIST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9901"]},{"id":2238,"title":"DNS_ERROR_DP_ALREADY_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9902","0x26AE","error 9902","DNS_ERROR_DP_ALREADY_EXISTS","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","dns","error","already","exists","the","specified","directory","partition"],"errorCode":"9902","eventId":"","severity":"Medium","summary":"The specified directory partition already exists.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 9902; use the surrounding log entries to confirm it.","resolution":"1. Record where 9902 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_DP_ALREADY_EXISTS.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9902 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified directory partition already exists.\n\nLookup forms: 9902, 0x26AE, error 9902, DNS_ERROR_DP_ALREADY_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9902"]},{"id":2239,"title":"DNS_ERROR_DP_NOT_ENLISTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9903","0x26AF","error 9903","DNS_ERROR_DP_NOT_ENLISTED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","not","enlisted","this","server","the","specified","directory","partition"],"errorCode":"9903","eventId":"","severity":"Low","summary":"This DNS server is not enlisted in the specified directory partition.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9903; use the surrounding log entries to confirm it.","resolution":"1. Record where 9903 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_DP_NOT_ENLISTED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9903 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This DNS server is not enlisted in the specified directory partition.\n\nLookup forms: 9903, 0x26AF, error 9903, DNS_ERROR_DP_NOT_ENLISTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The DS is not enlisted in the specified directory partition.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9903"]},{"id":2240,"title":"DNS_ERROR_DP_ALREADY_ENLISTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9904","0x26B0","error 9904","DNS_ERROR_DP_ALREADY_ENLISTED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","already","enlisted","this","server","the","specified","directory","partition"],"errorCode":"9904","eventId":"","severity":"Low","summary":"This DNS server is already enlisted in the specified directory partition.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9904; use the surrounding log entries to confirm it.","resolution":"1. Record where 9904 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_DP_ALREADY_ENLISTED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9904 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This DNS server is already enlisted in the specified directory partition.\n\nLookup forms: 9904, 0x26B0, error 9904, DNS_ERROR_DP_ALREADY_ENLISTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The DS is already enlisted in the specified directory partition.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9904"]},{"id":2241,"title":"DNS_ERROR_DP_NOT_AVAILABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9905","0x26B1","error 9905","DNS_ERROR_DP_NOT_AVAILABLE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","dns","error","not","available","the","directory","partition","this","time","please","wait","few","minutes","and","try","again"],"errorCode":"9905","eventId":"","severity":"Low","summary":"The directory partition is not available at this time. Please wait a few minutes and try again.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 9905; use the surrounding log entries to confirm it.","resolution":"1. Record where 9905 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_DP_NOT_AVAILABLE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9905 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The directory partition is not available at this time. Please wait a few minutes and try again.\n\nLookup forms: 9905, 0x26B1, error 9905, DNS_ERROR_DP_NOT_AVAILABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9905"]},{"id":2242,"title":"DNS_ERROR_DP_FSMO_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["9906","0x26B2","error 9906","DNS_ERROR_DP_FSMO_ERROR","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","dns","error","fsmo","the","operation","failed","because","domain","naming","master","role","could","not","reached","controller","holding","down","unable","service","request","running","windows","server","2003","later"],"errorCode":"9906","eventId":"","severity":"High","summary":"The operation failed because the domain naming master FSMO role could not be reached. The domain controller holding the domain naming master FSMO role is down or unable to service the request or is not running Windows Server 2003 or later.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 9906; use the surrounding log entries to confirm it.","resolution":"1. Record where 9906 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to DNS_ERROR_DP_FSMO_ERROR.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 9906 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation failed because the domain naming master FSMO role could not be reached. The domain controller holding the domain naming master FSMO role is down or unable to service the request or is not running Windows Server 2003 or later.\n\nLookup forms: 9906, 0x26B2, error 9906, DNS_ERROR_DP_FSMO_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["9906"]},{"id":2243,"title":"WSAEINTR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10004","0x2714","error 10004","WSAEINTR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsaeintr","blocking","operation","was","interrupted","call","wsacancelblockingcall"],"errorCode":"10004","eventId":"","severity":"Low","summary":"A blocking operation was interrupted by a call to WSACancelBlockingCall.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 10004; use the surrounding log entries to confirm it.","resolution":"1. Record where 10004 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEINTR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10004 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A blocking operation was interrupted by a call to WSACancelBlockingCall.\n\nLookup forms: 10004, 0x2714, error 10004, WSAEINTR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10004"]},{"id":2244,"title":"WSAEBADF","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10009","0x2719","error 10009","WSAEBADF","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","wsaebadf","the","file","handle","supplied","not","valid"],"errorCode":"10009","eventId":"","severity":"Low","summary":"The file handle supplied is not valid.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 10009; use the surrounding log entries to confirm it.","resolution":"1. Record where 10009 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEBADF.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10009 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file handle supplied is not valid.\n\nLookup forms: 10009, 0x2719, error 10009, WSAEBADF. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10009"]},{"id":2245,"title":"WSAEACCES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10013","0x271D","error 10013","WSAEACCES","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","wsaeacces","attempt","was","made","access","socket","way","forbidden","its","permissions"],"errorCode":"10013","eventId":"","severity":"Low","summary":"An attempt was made to access a socket in a way forbidden by its access permissions.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 10013; use the surrounding log entries to confirm it.","resolution":"1. Record where 10013 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEACCES.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10013 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt was made to access a socket in a way forbidden by its access permissions.\n\nLookup forms: 10013, 0x271D, error 10013, WSAEACCES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10013"]},{"id":2246,"title":"WSAEFAULT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10014","0x271E","error 10014","WSAEFAULT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsaefault","the","system","detected","invalid","pointer","address","attempting","use","argument","call"],"errorCode":"10014","eventId":"","severity":"Medium","summary":"The system detected an invalid pointer address in attempting to use a pointer argument in a call.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 10014; use the surrounding log entries to confirm it.","resolution":"1. Record where 10014 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEFAULT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10014 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system detected an invalid pointer address in attempting to use a pointer argument in a call.\n\nLookup forms: 10014, 0x271E, error 10014, WSAEFAULT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10014"]},{"id":2247,"title":"WSAEINVAL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10022","0x2726","error 10022","WSAEINVAL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsaeinval","invalid","argument","was","supplied"],"errorCode":"10022","eventId":"","severity":"Medium","summary":"An invalid argument was supplied.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 10022; use the surrounding log entries to confirm it.","resolution":"1. Record where 10022 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEINVAL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10022 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An invalid argument was supplied.\n\nLookup forms: 10022, 0x2726, error 10022, WSAEINVAL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10022"]},{"id":2248,"title":"WSAEMFILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10024","0x2728","error 10024","WSAEMFILE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsaemfile","too","many","open","sockets"],"errorCode":"10024","eventId":"","severity":"Low","summary":"Too many open sockets.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 10024; use the surrounding log entries to confirm it.","resolution":"1. Record where 10024 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEMFILE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10024 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Too many open sockets.\n\nLookup forms: 10024, 0x2728, error 10024, WSAEMFILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10024"]},{"id":2249,"title":"WSAEWOULDBLOCK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10035","0x2733","error 10035","WSAEWOULDBLOCK","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsaewouldblock","non","blocking","socket","operation","could","not","completed","immediately"],"errorCode":"10035","eventId":"","severity":"Low","summary":"A non-blocking socket operation could not be completed immediately.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 10035; use the surrounding log entries to confirm it.","resolution":"1. Record where 10035 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEWOULDBLOCK.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10035 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A non-blocking socket operation could not be completed immediately.\n\nLookup forms: 10035, 0x2733, error 10035, WSAEWOULDBLOCK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10035"]},{"id":2250,"title":"WSAEINPROGRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10036","0x2734","error 10036","WSAEINPROGRESS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsaeinprogress","blocking","operation","currently","executing"],"errorCode":"10036","eventId":"","severity":"Low","summary":"A blocking operation is currently executing.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 10036; use the surrounding log entries to confirm it.","resolution":"1. Record where 10036 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEINPROGRESS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10036 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A blocking operation is currently executing.\n\nLookup forms: 10036, 0x2734, error 10036, WSAEINPROGRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10036"]},{"id":2251,"title":"WSAEALREADY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10037","0x2735","error 10037","WSAEALREADY","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsaealready","operation","was","attempted","non","blocking","socket","that","already","had","progress"],"errorCode":"10037","eventId":"","severity":"Low","summary":"An operation was attempted on a non-blocking socket that already had an operation in progress.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 10037; use the surrounding log entries to confirm it.","resolution":"1. Record where 10037 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEALREADY.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10037 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An operation was attempted on a non-blocking socket that already had an operation in progress.\n\nLookup forms: 10037, 0x2735, error 10037, WSAEALREADY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10037"]},{"id":2252,"title":"WSAENOTSOCK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10038","0x2736","error 10038","WSAENOTSOCK","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsaenotsock","operation","was","attempted","something","that","not","socket"],"errorCode":"10038","eventId":"","severity":"Low","summary":"An operation was attempted on something that is not a socket.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 10038; use the surrounding log entries to confirm it.","resolution":"1. Record where 10038 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAENOTSOCK.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10038 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An operation was attempted on something that is not a socket.\n\nLookup forms: 10038, 0x2736, error 10038, WSAENOTSOCK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10038"]},{"id":2253,"title":"WSAEDESTADDRREQ","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10039","0x2737","error 10039","WSAEDESTADDRREQ","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsaedestaddrreq","required","address","was","omitted","from","operation","socket"],"errorCode":"10039","eventId":"","severity":"Low","summary":"A required address was omitted from an operation on a socket.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 10039; use the surrounding log entries to confirm it.","resolution":"1. Record where 10039 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEDESTADDRREQ.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10039 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A required address was omitted from an operation on a socket.\n\nLookup forms: 10039, 0x2737, error 10039, WSAEDESTADDRREQ. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10039"]},{"id":2254,"title":"WSAEMSGSIZE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10040","0x2738","error 10040","WSAEMSGSIZE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsaemsgsize","message","sent","datagram","socket","was","larger","than","the","internal","buffer","some","other","network","limit","used","receive","into","smaller","itself"],"errorCode":"10040","eventId":"","severity":"High","summary":"A message sent on a datagram socket was larger than the internal message buffer or some other network limit, or the buffer used to receive a datagram into was smaller than the datagram itself.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 10040; use the surrounding log entries to confirm it.","resolution":"1. Record where 10040 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEMSGSIZE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10040 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A message sent on a datagram socket was larger than the internal message buffer or some other network limit, or the buffer used to receive a datagram into was smaller than the datagram itself.\n\nLookup forms: 10040, 0x2738, error 10040, WSAEMSGSIZE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10040"]},{"id":2255,"title":"WSAEPROTOTYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10041","0x2739","error 10041","WSAEPROTOTYPE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsaeprototype","protocol","was","specified","the","socket","function","call","that","does","not","support","semantics","type","requested"],"errorCode":"10041","eventId":"","severity":"Low","summary":"A protocol was specified in the socket function call that does not support the semantics of the socket type requested.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 10041; use the surrounding log entries to confirm it.","resolution":"1. Record where 10041 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEPROTOTYPE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10041 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A protocol was specified in the socket function call that does not support the semantics of the socket type requested.\n\nLookup forms: 10041, 0x2739, error 10041, WSAEPROTOTYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10041"]},{"id":2256,"title":"WSAENOPROTOOPT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10042","0x273A","error 10042","WSAENOPROTOOPT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsaenoprotoopt","unknown","invalid","unsupported","option","level","was","specified","getsockopt","setsockopt","call"],"errorCode":"10042","eventId":"","severity":"Medium","summary":"An unknown, invalid, or unsupported option or level was specified in a getsockopt or setsockopt call.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 10042; use the surrounding log entries to confirm it.","resolution":"1. Record where 10042 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAENOPROTOOPT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10042 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An unknown, invalid, or unsupported option or level was specified in a getsockopt or setsockopt call.\n\nLookup forms: 10042, 0x273A, error 10042, WSAENOPROTOOPT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10042"]},{"id":2257,"title":"WSAEPROTONOSUPPORT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10043","0x273B","error 10043","WSAEPROTONOSUPPORT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsaeprotonosupport","the","requested","protocol","has","not","been","configured","into","system","implementation","for","exists"],"errorCode":"10043","eventId":"","severity":"Low","summary":"The requested protocol has not been configured into the system, or no implementation for it exists.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 10043; use the surrounding log entries to confirm it.","resolution":"1. Record where 10043 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEPROTONOSUPPORT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10043 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested protocol has not been configured into the system, or no implementation for it exists.\n\nLookup forms: 10043, 0x273B, error 10043, WSAEPROTONOSUPPORT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10043"]},{"id":2258,"title":"WSAESOCKTNOSUPPORT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10044","0x273C","error 10044","WSAESOCKTNOSUPPORT","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsaesocktnosupport","the","support","for","specified","socket","type","does","not","exist","this","address","family"],"errorCode":"10044","eventId":"","severity":"Low","summary":"The support for the specified socket type does not exist in this address family.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 10044; use the surrounding log entries to confirm it.","resolution":"1. Record where 10044 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAESOCKTNOSUPPORT.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10044 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The support for the specified socket type does not exist in this address family.\n\nLookup forms: 10044, 0x273C, error 10044, WSAESOCKTNOSUPPORT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10044"]},{"id":2259,"title":"WSAEOPNOTSUPP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10045","0x273D","error 10045","WSAEOPNOTSUPP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsaeopnotsupp","the","attempted","operation","not","supported","for","type","object","referenced"],"errorCode":"10045","eventId":"","severity":"Medium","summary":"The attempted operation is not supported for the type of object referenced.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 10045; use the surrounding log entries to confirm it.","resolution":"1. Record where 10045 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEOPNOTSUPP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10045 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The attempted operation is not supported for the type of object referenced.\n\nLookup forms: 10045, 0x273D, error 10045, WSAEOPNOTSUPP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10045"]},{"id":2260,"title":"WSAEPFNOSUPPORT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10046","0x273E","error 10046","WSAEPFNOSUPPORT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsaepfnosupport","the","protocol","family","has","not","been","configured","into","system","implementation","for","exists"],"errorCode":"10046","eventId":"","severity":"Low","summary":"The protocol family has not been configured into the system or no implementation for it exists.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 10046; use the surrounding log entries to confirm it.","resolution":"1. Record where 10046 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEPFNOSUPPORT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10046 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The protocol family has not been configured into the system or no implementation for it exists.\n\nLookup forms: 10046, 0x273E, error 10046, WSAEPFNOSUPPORT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10046"]},{"id":2261,"title":"WSAEAFNOSUPPORT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10047","0x273F","error 10047","WSAEAFNOSUPPORT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsaeafnosupport","address","incompatible","with","the","requested","protocol","was","used"],"errorCode":"10047","eventId":"","severity":"Low","summary":"An address incompatible with the requested protocol was used.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 10047; use the surrounding log entries to confirm it.","resolution":"1. Record where 10047 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEAFNOSUPPORT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10047 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An address incompatible with the requested protocol was used.\n\nLookup forms: 10047, 0x273F, error 10047, WSAEAFNOSUPPORT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10047"]},{"id":2262,"title":"WSAEADDRINUSE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10048","0x2740","error 10048","WSAEADDRINUSE","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsaeaddrinuse","only","one","usage","each","socket","address","protocol","network","port","normally","permitted"],"errorCode":"10048","eventId":"","severity":"High","summary":"Only one usage of each socket address (protocol/network address/port) is normally permitted.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 10048; use the surrounding log entries to confirm it.","resolution":"1. Record where 10048 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEADDRINUSE.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10048 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Only one usage of each socket address (protocol/network address/port) is normally permitted.\n\nLookup forms: 10048, 0x2740, error 10048, WSAEADDRINUSE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10048"]},{"id":2263,"title":"WSAEADDRNOTAVAIL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10049","0x2741","error 10049","WSAEADDRNOTAVAIL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsaeaddrnotavail","the","requested","address","not","valid","its","context"],"errorCode":"10049","eventId":"","severity":"Low","summary":"The requested address is not valid in its context.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 10049; use the surrounding log entries to confirm it.","resolution":"1. Record where 10049 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEADDRNOTAVAIL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10049 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested address is not valid in its context.\n\nLookup forms: 10049, 0x2741, error 10049, WSAEADDRNOTAVAIL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10049"]},{"id":2264,"title":"WSAENETDOWN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10050","0x2742","error 10050","WSAENETDOWN","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsaenetdown","socket","operation","encountered","dead","network"],"errorCode":"10050","eventId":"","severity":"High","summary":"A socket operation encountered a dead network.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 10050; use the surrounding log entries to confirm it.","resolution":"1. Record where 10050 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAENETDOWN.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10050 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A socket operation encountered a dead network.\n\nLookup forms: 10050, 0x2742, error 10050, WSAENETDOWN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10050"]},{"id":2265,"title":"WSAENETUNREACH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10051","0x2743","error 10051","WSAENETUNREACH","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsaenetunreach","socket","operation","was","attempted","unreachable","network"],"errorCode":"10051","eventId":"","severity":"High","summary":"A socket operation was attempted to an unreachable network.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 10051; use the surrounding log entries to confirm it.","resolution":"1. Record where 10051 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAENETUNREACH.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10051 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A socket operation was attempted to an unreachable network.\n\nLookup forms: 10051, 0x2743, error 10051, WSAENETUNREACH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10051"]},{"id":2266,"title":"WSAENETRESET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10052","0x2744","error 10052","WSAENETRESET","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsaenetreset","the","connection","has","been","broken","due","keep","alive","activity","detecting","failure","while","operation","was","progress"],"errorCode":"10052","eventId":"","severity":"High","summary":"The connection has been broken due to keep-alive activity detecting a failure while the operation was in progress.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 10052; use the surrounding log entries to confirm it.","resolution":"1. Record where 10052 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAENETRESET.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10052 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The connection has been broken due to keep-alive activity detecting a failure while the operation was in progress.\n\nLookup forms: 10052, 0x2744, error 10052, WSAENETRESET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10052"]},{"id":2267,"title":"WSAECONNABORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10053","0x2745","error 10053","WSAECONNABORTED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsaeconnaborted","established","connection","was","aborted","the","software","your","host","machine"],"errorCode":"10053","eventId":"","severity":"High","summary":"An established connection was aborted by the software in your host machine.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 10053; use the surrounding log entries to confirm it.","resolution":"1. Record where 10053 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAECONNABORTED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10053 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An established connection was aborted by the software in your host machine.\n\nLookup forms: 10053, 0x2745, error 10053, WSAECONNABORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10053"]},{"id":2268,"title":"WSAECONNRESET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10054","0x2746","error 10054","WSAECONNRESET","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsaeconnreset","existing","connection","was","forcibly","closed","the","remote","host","dns","and","networking","reset","peer"],"errorCode":"10054","eventId":"","severity":"High","summary":"An existing connection was forcibly closed by the remote host.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 10054; use the surrounding log entries to confirm it.","resolution":"1. Record where 10054 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAECONNRESET.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10054 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An existing connection was forcibly closed by the remote host.\n\nLookup forms: 10054, 0x2746, error 10054, WSAECONNRESET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (microsoft_windows_error_code_master_list.txt): Category: DNS AND NETWORKING\nDescription: The connection was reset by the peer.\n\nFixes:\n1. Verify the exact host, IP, port, route, gateway, and DNS response from the affected device.\n2. Review firewall, proxy, VPN, load balancer, TLS inspection, and remote service health.\n3. Capture a network trace if the failure source is unclear, correct it, and retest connectivity.\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf; microsoft_windows_error_code_master_list.txt","commands":[],"platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10054"]},{"id":2269,"title":"WSAENOBUFS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10055","0x2747","error 10055","WSAENOBUFS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsaenobufs","operation","socket","could","not","performed","because","the","system","lacked","sufficient","buffer","space","queue","was","full"],"errorCode":"10055","eventId":"","severity":"Low","summary":"An operation on a socket could not be performed because the system lacked sufficient buffer space or because a queue was full.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 10055; use the surrounding log entries to confirm it.","resolution":"1. Record where 10055 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAENOBUFS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10055 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An operation on a socket could not be performed because the system lacked sufficient buffer space or because a queue was full.\n\nLookup forms: 10055, 0x2747, error 10055, WSAENOBUFS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10055"]},{"id":2270,"title":"WSAEISCONN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10056","0x2748","error 10056","WSAEISCONN","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsaeisconn","connect","request","was","made","already","connected","socket"],"errorCode":"10056","eventId":"","severity":"Low","summary":"A connect request was made on an already connected socket.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 10056; use the surrounding log entries to confirm it.","resolution":"1. Record where 10056 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEISCONN.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10056 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A connect request was made on an already connected socket.\n\nLookup forms: 10056, 0x2748, error 10056, WSAEISCONN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10056"]},{"id":2271,"title":"WSAENOTCONN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10057","0x2749","error 10057","WSAENOTCONN","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsaenotconn","request","send","receive","data","was","disallowed","because","the","socket","not","connected","and","when","sending","datagram","using","sendto","call","address","supplied"],"errorCode":"10057","eventId":"","severity":"Low","summary":"A request to send or receive data was disallowed because the socket is not connected and (when sending on a datagram socket using a sendto call) no address was supplied.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 10057; use the surrounding log entries to confirm it.","resolution":"1. Record where 10057 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAENOTCONN.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10057 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A request to send or receive data was disallowed because the socket is not connected and (when sending on a datagram socket using a sendto call) no address was supplied.\n\nLookup forms: 10057, 0x2749, error 10057, WSAENOTCONN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10057"]},{"id":2272,"title":"WSAESHUTDOWN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10058","0x274A","error 10058","WSAESHUTDOWN","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsaeshutdown","request","send","receive","data","was","disallowed","because","the","socket","had","already","been","shut","down","that","direction","with","previous","shutdown","call"],"errorCode":"10058","eventId":"","severity":"Low","summary":"A request to send or receive data was disallowed because the socket had already been shut down in that direction with a previous shutdown call.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 10058; use the surrounding log entries to confirm it.","resolution":"1. Record where 10058 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAESHUTDOWN.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10058 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A request to send or receive data was disallowed because the socket had already been shut down in that direction with a previous shutdown call.\n\nLookup forms: 10058, 0x274A, error 10058, WSAESHUTDOWN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10058"]},{"id":2273,"title":"WSAETOOMANYREFS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10059","0x274B","error 10059","WSAETOOMANYREFS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsaetoomanyrefs","too","many","references","some","kernel","object"],"errorCode":"10059","eventId":"","severity":"Low","summary":"Too many references to some kernel object.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 10059; use the surrounding log entries to confirm it.","resolution":"1. Record where 10059 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAETOOMANYREFS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10059 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Too many references to some kernel object.\n\nLookup forms: 10059, 0x274B, error 10059, WSAETOOMANYREFS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10059"]},{"id":2274,"title":"WSAETIMEDOUT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10060","0x274C","error 10060","WSAETIMEDOUT","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsaetimedout","connection","attempt","failed","because","the","connected","party","did","not","properly","respond","after","period","time","established","host","has","dns","and","networking","timed","out"],"errorCode":"10060","eventId":"","severity":"High","summary":"A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 10060; use the surrounding log entries to confirm it.","resolution":"1. Record where 10060 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAETIMEDOUT.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10060 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond.\n\nLookup forms: 10060, 0x274C, error 10060, WSAETIMEDOUT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (microsoft_windows_error_code_master_list.txt): Category: DNS AND NETWORKING\nDescription: The connection attempt timed out.\n\nFixes:\n1. Verify the exact host, IP, port, route, gateway, and DNS response from the affected device.\n2. Review firewall, proxy, VPN, load balancer, TLS inspection, and remote service health.\n3. Capture a network trace if the failure source is unclear, correct it, and retest connectivity.\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf; microsoft_windows_error_code_master_list.txt","commands":[],"platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10060"]},{"id":2275,"title":"WSAECONNREFUSED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10061","0x274D","error 10061","WSAECONNREFUSED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsaeconnrefused","connection","could","made","because","the","target","machine","actively","refused"],"errorCode":"10061","eventId":"","severity":"High","summary":"No connection could be made because the target machine actively refused it.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 10061; use the surrounding log entries to confirm it.","resolution":"1. Record where 10061 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAECONNREFUSED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10061 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No connection could be made because the target machine actively refused it.\n\nLookup forms: 10061, 0x274D, error 10061, WSAECONNREFUSED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10061"]},{"id":2276,"title":"WSAELOOP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10062","0x274E","error 10062","WSAELOOP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsaeloop","cannot","translate","name"],"errorCode":"10062","eventId":"","severity":"Medium","summary":"Cannot translate name.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 10062; use the surrounding log entries to confirm it.","resolution":"1. Record where 10062 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAELOOP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10062 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot translate name.\n\nLookup forms: 10062, 0x274E, error 10062, WSAELOOP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10062"]},{"id":2277,"title":"WSAENAMETOOLONG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10063","0x274F","error 10063","WSAENAMETOOLONG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsaenametoolong","name","component","was","too","long"],"errorCode":"10063","eventId":"","severity":"Low","summary":"Name component or name was too long.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 10063; use the surrounding log entries to confirm it.","resolution":"1. Record where 10063 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAENAMETOOLONG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10063 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Name component or name was too long.\n\nLookup forms: 10063, 0x274F, error 10063, WSAENAMETOOLONG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10063"]},{"id":2278,"title":"WSAEHOSTDOWN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10064","0x2750","error 10064","WSAEHOSTDOWN","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsaehostdown","socket","operation","failed","because","the","destination","host","was","down"],"errorCode":"10064","eventId":"","severity":"High","summary":"A socket operation failed because the destination host was down.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 10064; use the surrounding log entries to confirm it.","resolution":"1. Record where 10064 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEHOSTDOWN.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10064 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A socket operation failed because the destination host was down.\n\nLookup forms: 10064, 0x2750, error 10064, WSAEHOSTDOWN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10064"]},{"id":2279,"title":"WSAEHOSTUNREACH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10065","0x2751","error 10065","WSAEHOSTUNREACH","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsaehostunreach","socket","operation","was","attempted","unreachable","host","dns","and","networking","there","route","the"],"errorCode":"10065","eventId":"","severity":"Low","summary":"A socket operation was attempted to an unreachable host.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 10065; use the surrounding log entries to confirm it.","resolution":"1. Record where 10065 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEHOSTUNREACH.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10065 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A socket operation was attempted to an unreachable host.\n\nLookup forms: 10065, 0x2751, error 10065, WSAEHOSTUNREACH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (microsoft_windows_error_code_master_list.txt): Category: DNS AND NETWORKING\nDescription: There is no route to the host.\n\nFixes:\n1. Verify the exact host, IP, port, route, gateway, and DNS response from the affected device.\n2. Review firewall, proxy, VPN, load balancer, TLS inspection, and remote service health.\n3. Capture a network trace if the failure source is unclear, correct it, and retest connectivity.\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf; microsoft_windows_error_code_master_list.txt","commands":[],"platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10065"]},{"id":2280,"title":"WSAENOTEMPTY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10066","0x2752","error 10066","WSAENOTEMPTY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","wsaenotempty","cannot","remove","directory","that","not","empty"],"errorCode":"10066","eventId":"","severity":"Medium","summary":"Cannot remove a directory that is not empty.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 10066; use the surrounding log entries to confirm it.","resolution":"1. Record where 10066 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAENOTEMPTY.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10066 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot remove a directory that is not empty.\n\nLookup forms: 10066, 0x2752, error 10066, WSAENOTEMPTY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10066"]},{"id":2281,"title":"WSAEPROCLIM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10067","0x2753","error 10067","WSAEPROCLIM","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsaeproclim","windows","sockets","implementation","may","have","limit","the","number","applications","that","use","simultaneously"],"errorCode":"10067","eventId":"","severity":"Low","summary":"A Windows Sockets implementation may have a limit on the number of applications that may use it simultaneously.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 10067; use the surrounding log entries to confirm it.","resolution":"1. Record where 10067 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEPROCLIM.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10067 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A Windows Sockets implementation may have a limit on the number of applications that may use it simultaneously.\n\nLookup forms: 10067, 0x2753, error 10067, WSAEPROCLIM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10067"]},{"id":2282,"title":"WSAEUSERS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10068","0x2754","error 10068","WSAEUSERS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsaeusers","ran","out","quota"],"errorCode":"10068","eventId":"","severity":"Low","summary":"Ran out of quota.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 10068; use the surrounding log entries to confirm it.","resolution":"1. Record where 10068 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEUSERS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10068 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Ran out of quota.\n\nLookup forms: 10068, 0x2754, error 10068, WSAEUSERS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10068"]},{"id":2283,"title":"WSAEDQUOT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10069","0x2755","error 10069","WSAEDQUOT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","wsaedquot","ran","out","disk","quota"],"errorCode":"10069","eventId":"","severity":"Low","summary":"Ran out of disk quota.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 10069; use the surrounding log entries to confirm it.","resolution":"1. Record where 10069 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEDQUOT.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10069 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Ran out of disk quota.\n\nLookup forms: 10069, 0x2755, error 10069, WSAEDQUOT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10069"]},{"id":2284,"title":"WSAESTALE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10070","0x2756","error 10070","WSAESTALE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","wsaestale","file","handle","reference","longer","available"],"errorCode":"10070","eventId":"","severity":"Low","summary":"File handle reference is no longer available.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 10070; use the surrounding log entries to confirm it.","resolution":"1. Record where 10070 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAESTALE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10070 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: File handle reference is no longer available.\n\nLookup forms: 10070, 0x2756, error 10070, WSAESTALE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10070"]},{"id":2285,"title":"WSAEREMOTE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10071","0x2757","error 10071","WSAEREMOTE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsaeremote","item","not","available","locally"],"errorCode":"10071","eventId":"","severity":"Low","summary":"Item is not available locally.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 10071; use the surrounding log entries to confirm it.","resolution":"1. Record where 10071 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEREMOTE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10071 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Item is not available locally.\n\nLookup forms: 10071, 0x2757, error 10071, WSAEREMOTE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10071"]},{"id":2286,"title":"WSASYSNOTREADY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10091","0x276B","error 10091","WSASYSNOTREADY","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsasysnotready","wsastartup","cannot","function","this","time","because","the","underlying","system","uses","provide","network","services","currently","unavailable"],"errorCode":"10091","eventId":"","severity":"High","summary":"WSAStartup cannot function at this time because the underlying system it uses to provide network services is currently unavailable.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 10091; use the surrounding log entries to confirm it.","resolution":"1. Record where 10091 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSASYSNOTREADY.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10091 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: WSAStartup cannot function at this time because the underlying system it uses to provide network services is currently unavailable.\n\nLookup forms: 10091, 0x276B, error 10091, WSASYSNOTREADY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10091"]},{"id":2287,"title":"WSAVERNOTSUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10092","0x276C","error 10092","WSAVERNOTSUPPORTED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsavernotsupported","the","windows","sockets","version","requested","not","supported"],"errorCode":"10092","eventId":"","severity":"Medium","summary":"The Windows Sockets version requested is not supported.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 10092; use the surrounding log entries to confirm it.","resolution":"1. Record where 10092 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAVERNOTSUPPORTED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10092 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Windows Sockets version requested is not supported.\n\nLookup forms: 10092, 0x276C, error 10092, WSAVERNOTSUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10092"]},{"id":2288,"title":"WSANOTINITIALISED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10093","0x276D","error 10093","WSANOTINITIALISED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsanotinitialised","either","the","application","has","not","called","wsastartup","failed"],"errorCode":"10093","eventId":"","severity":"High","summary":"Either the application has not called WSAStartup, or WSAStartup failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 10093; use the surrounding log entries to confirm it.","resolution":"1. Record where 10093 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSANOTINITIALISED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10093 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Either the application has not called WSAStartup, or WSAStartup failed.\n\nLookup forms: 10093, 0x276D, error 10093, WSANOTINITIALISED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10093"]},{"id":2289,"title":"WSAEDISCON","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10101","0x2775","error 10101","WSAEDISCON","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsaediscon","returned","wsarecv","wsarecvfrom","indicate","the","remote","party","has","initiated","graceful","shutdown","sequence"],"errorCode":"10101","eventId":"","severity":"Low","summary":"Returned by WSARecv or WSARecvFrom to indicate the remote party has initiated a graceful shutdown sequence.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 10101; use the surrounding log entries to confirm it.","resolution":"1. Record where 10101 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEDISCON.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10101 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Returned by WSARecv or WSARecvFrom to indicate the remote party has initiated a graceful shutdown sequence.\n\nLookup forms: 10101, 0x2775, error 10101, WSAEDISCON. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10101"]},{"id":2290,"title":"WSAENOMORE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10102","0x2776","error 10102","WSAENOMORE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","wsaenomore","more","results","can","returned","wsalookupservicenext"],"errorCode":"10102","eventId":"","severity":"Low","summary":"No more results can be returned by WSALookupServiceNext.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 10102; use the surrounding log entries to confirm it.","resolution":"1. Record where 10102 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAENOMORE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10102 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No more results can be returned by WSALookupServiceNext.\n\nLookup forms: 10102, 0x2776, error 10102, WSAENOMORE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10102"]},{"id":2291,"title":"WSAECANCELLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10103","0x2777","error 10103","WSAECANCELLED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","wsaecancelled","call","wsalookupserviceend","was","made","while","this","still","processing","the","has","been","canceled"],"errorCode":"10103","eventId":"","severity":"Low","summary":"A call to WSALookupServiceEnd was made while this call was still processing. The call has been canceled.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 10103; use the surrounding log entries to confirm it.","resolution":"1. Record where 10103 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAECANCELLED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10103 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A call to WSALookupServiceEnd was made while this call was still processing. The call has been canceled.\n\nLookup forms: 10103, 0x2777, error 10103, WSAECANCELLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10103"]},{"id":2292,"title":"WSAEINVALIDPROCTABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10104","0x2778","error 10104","WSAEINVALIDPROCTABLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsaeinvalidproctable","the","procedure","call","table","invalid"],"errorCode":"10104","eventId":"","severity":"Medium","summary":"The procedure call table is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 10104; use the surrounding log entries to confirm it.","resolution":"1. Record where 10104 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEINVALIDPROCTABLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10104 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The procedure call table is invalid.\n\nLookup forms: 10104, 0x2778, error 10104, WSAEINVALIDPROCTABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10104"]},{"id":2293,"title":"WSAEINVALIDPROVIDER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10105","0x2779","error 10105","WSAEINVALIDPROVIDER","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","wsaeinvalidprovider","the","requested","service","provider","invalid"],"errorCode":"10105","eventId":"","severity":"Medium","summary":"The requested service provider is invalid.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 10105; use the surrounding log entries to confirm it.","resolution":"1. Record where 10105 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEINVALIDPROVIDER.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10105 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested service provider is invalid.\n\nLookup forms: 10105, 0x2779, error 10105, WSAEINVALIDPROVIDER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10105"]},{"id":2294,"title":"WSAEPROVIDERFAILEDINIT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10106","0x277A","error 10106","WSAEPROVIDERFAILEDINIT","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","wsaeproviderfailedinit","the","requested","service","provider","could","not","loaded","initialized"],"errorCode":"10106","eventId":"","severity":"Low","summary":"The requested service provider could not be loaded or initialized.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 10106; use the surrounding log entries to confirm it.","resolution":"1. Record where 10106 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEPROVIDERFAILEDINIT.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10106 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested service provider could not be loaded or initialized.\n\nLookup forms: 10106, 0x277A, error 10106, WSAEPROVIDERFAILEDINIT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10106"]},{"id":2295,"title":"WSASYSCALLFAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10107","0x277B","error 10107","WSASYSCALLFAILURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsasyscallfailure","system","call","has","failed"],"errorCode":"10107","eventId":"","severity":"High","summary":"A system call has failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 10107; use the surrounding log entries to confirm it.","resolution":"1. Record where 10107 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSASYSCALLFAILURE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10107 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A system call has failed.\n\nLookup forms: 10107, 0x277B, error 10107, WSASYSCALLFAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): A system call that should never fail has failed.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10107"]},{"id":2296,"title":"WSASERVICE_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10108","0x277C","error 10108","WSASERVICE_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","wsaservice","not","found","such","service","known","the","cannot","specified","name","space"],"errorCode":"10108","eventId":"","severity":"Medium","summary":"No such service is known. The service cannot be found in the specified name space.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 10108; use the surrounding log entries to confirm it.","resolution":"1. Record where 10108 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSASERVICE_NOT_FOUND.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10108 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No such service is known. The service cannot be found in the specified name space.\n\nLookup forms: 10108, 0x277C, error 10108, WSASERVICE_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10108"]},{"id":2297,"title":"WSATYPE_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10109","0x277D","error 10109","WSATYPE_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsatype","not","found","the","specified","class","was"],"errorCode":"10109","eventId":"","severity":"Medium","summary":"The specified class was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 10109; use the surrounding log entries to confirm it.","resolution":"1. Record where 10109 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSATYPE_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10109 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified class was not found.\n\nLookup forms: 10109, 0x277D, error 10109, WSATYPE_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10109"]},{"id":2298,"title":"WSA_E_NO_MORE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10110","0x277E","error 10110","WSA_E_NO_MORE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","wsa","more","results","can","returned","wsalookupservicenext"],"errorCode":"10110","eventId":"","severity":"Low","summary":"No more results can be returned by WSALookupServiceNext.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 10110; use the surrounding log entries to confirm it.","resolution":"1. Record where 10110 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_E_NO_MORE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10110 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No more results can be returned by WSALookupServiceNext.\n\nLookup forms: 10110, 0x277E, error 10110, WSA_E_NO_MORE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10110"]},{"id":2299,"title":"WSA_E_CANCELLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10111","0x277F","error 10111","WSA_E_CANCELLED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","wsa","cancelled","call","wsalookupserviceend","was","made","while","this","still","processing","the","has","been","canceled"],"errorCode":"10111","eventId":"","severity":"Low","summary":"A call to WSALookupServiceEnd was made while this call was still processing. The call has been canceled.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 10111; use the surrounding log entries to confirm it.","resolution":"1. Record where 10111 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_E_CANCELLED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10111 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A call to WSALookupServiceEnd was made while this call was still processing. The call has been canceled.\n\nLookup forms: 10111, 0x277F, error 10111, WSA_E_CANCELLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10111"]},{"id":2300,"title":"WSAEREFUSED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["10112","0x2780","error 10112","WSAEREFUSED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsaerefused","database","query","failed","because","was","actively","refused"],"errorCode":"10112","eventId":"","severity":"High","summary":"A database query failed because it was actively refused.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 10112; use the surrounding log entries to confirm it.","resolution":"1. Record where 10112 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAEREFUSED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 10112 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A database query failed because it was actively refused.\n\nLookup forms: 10112, 0x2780, error 10112, WSAEREFUSED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["10112"]},{"id":2301,"title":"WSAHOST_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11001","0x2AF9","error 11001","WSAHOST_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsahost","not","found","such","host","known"],"errorCode":"11001","eventId":"","severity":"Low","summary":"No such host is known.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 11001; use the surrounding log entries to confirm it.","resolution":"1. Record where 11001 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSAHOST_NOT_FOUND.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11001 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No such host is known.\n\nLookup forms: 11001, 0x2AF9, error 11001, WSAHOST_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11001"]},{"id":2302,"title":"WSATRY_AGAIN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11002","0x2AFA","error 11002","WSATRY_AGAIN","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsatry","again","this","usually","temporary","error","during","hostname","resolution","and","means","that","the","local","server","did","not","receive","response","from","authoritative"],"errorCode":"11002","eventId":"","severity":"Low","summary":"This is usually a temporary error during hostname resolution and means that the local server did not receive a response from an authoritative server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 11002; use the surrounding log entries to confirm it.","resolution":"1. Record where 11002 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSATRY_AGAIN.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11002 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This is usually a temporary error during hostname resolution and means that the local server did not receive a response from an authoritative server.\n\nLookup forms: 11002, 0x2AFA, error 11002, WSATRY_AGAIN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11002"]},{"id":2303,"title":"WSANO_RECOVERY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11003","0x2AFB","error 11003","WSANO_RECOVERY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsano","recovery","non","recoverable","error","occurred","during","database","lookup"],"errorCode":"11003","eventId":"","severity":"Low","summary":"A non-recoverable error occurred during a database lookup.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 11003; use the surrounding log entries to confirm it.","resolution":"1. Record where 11003 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSANO_RECOVERY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11003 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A non-recoverable error occurred during a database lookup.\n\nLookup forms: 11003, 0x2AFB, error 11003, WSANO_RECOVERY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11003"]},{"id":2304,"title":"WSANO_DATA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11004","0x2AFC","error 11004","WSANO_DATA","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsano","data","the","requested","name","valid","but","type","was","found"],"errorCode":"11004","eventId":"","severity":"Low","summary":"The requested name is valid, but no data of the requested type was found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 11004; use the surrounding log entries to confirm it.","resolution":"1. Record where 11004 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSANO_DATA.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11004 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested name is valid, but no data of the requested type was found.\n\nLookup forms: 11004, 0x2AFC, error 11004, WSANO_DATA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The requested name is valid and was found in the database, but it does not have the correct associated data being resolved for.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11004"]},{"id":2305,"title":"WSA_QOS_RECEIVERS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11005","0x2AFD","error 11005","WSA_QOS_RECEIVERS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsa","qos","receivers","least","one","reserve","has","arrived"],"errorCode":"11005","eventId":"","severity":"Low","summary":"At least one reserve has arrived.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 11005; use the surrounding log entries to confirm it.","resolution":"1. Record where 11005 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_RECEIVERS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11005 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: At least one reserve has arrived.\n\nLookup forms: 11005, 0x2AFD, error 11005, WSA_QOS_RECEIVERS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11005"]},{"id":2306,"title":"WSA_QOS_SENDERS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11006","0x2AFE","error 11006","WSA_QOS_SENDERS","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","wsa","qos","senders","least","one","path","has","arrived"],"errorCode":"11006","eventId":"","severity":"Low","summary":"At least one path has arrived.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 11006; use the surrounding log entries to confirm it.","resolution":"1. Record where 11006 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_SENDERS.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11006 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: At least one path has arrived.\n\nLookup forms: 11006, 0x2AFE, error 11006, WSA_QOS_SENDERS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11006"]},{"id":2307,"title":"WSA_QOS_NO_SENDERS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11007","0x2AFF","error 11007","WSA_QOS_NO_SENDERS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsa","qos","senders","there","are"],"errorCode":"11007","eventId":"","severity":"Low","summary":"There are no senders.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 11007; use the surrounding log entries to confirm it.","resolution":"1. Record where 11007 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_NO_SENDERS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11007 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There are no senders.\n\nLookup forms: 11007, 0x2AFF, error 11007, WSA_QOS_NO_SENDERS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11007"]},{"id":2308,"title":"WSA_QOS_NO_RECEIVERS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11008","0x2B00","error 11008","WSA_QOS_NO_RECEIVERS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsa","qos","receivers","there","are"],"errorCode":"11008","eventId":"","severity":"Low","summary":"There are no receivers.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 11008; use the surrounding log entries to confirm it.","resolution":"1. Record where 11008 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_NO_RECEIVERS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11008 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There are no receivers.\n\nLookup forms: 11008, 0x2B00, error 11008, WSA_QOS_NO_RECEIVERS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11008"]},{"id":2309,"title":"WSA_QOS_REQUEST_CONFIRMED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11009","0x2B01","error 11009","WSA_QOS_REQUEST_CONFIRMED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsa","qos","request","confirmed","reserve","has","been"],"errorCode":"11009","eventId":"","severity":"Low","summary":"Reserve has been confirmed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 11009; use the surrounding log entries to confirm it.","resolution":"1. Record where 11009 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_REQUEST_CONFIRMED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11009 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Reserve has been confirmed.\n\nLookup forms: 11009, 0x2B01, error 11009, WSA_QOS_REQUEST_CONFIRMED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11009"]},{"id":2310,"title":"WSA_QOS_ADMISSION_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11010","0x2B02","error 11010","WSA_QOS_ADMISSION_FAILURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsa","qos","admission","failure","error","due","lack","resources"],"errorCode":"11010","eventId":"","severity":"Low","summary":"Error due to lack of resources.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 11010; use the surrounding log entries to confirm it.","resolution":"1. Record where 11010 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_ADMISSION_FAILURE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11010 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Error due to lack of resources.\n\nLookup forms: 11010, 0x2B02, error 11010, WSA_QOS_ADMISSION_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11010"]},{"id":2311,"title":"WSA_QOS_POLICY_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11011","0x2B03","error 11011","WSA_QOS_POLICY_FAILURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsa","qos","policy","failure","rejected","for","administrative","reasons","bad","credentials"],"errorCode":"11011","eventId":"","severity":"Low","summary":"Rejected for administrative reasons - bad credentials.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 11011; use the surrounding log entries to confirm it.","resolution":"1. Record where 11011 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_POLICY_FAILURE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11011 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Rejected for administrative reasons - bad credentials.\n\nLookup forms: 11011, 0x2B03, error 11011, WSA_QOS_POLICY_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11011"]},{"id":2312,"title":"WSA_QOS_BAD_STYLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11012","0x2B04","error 11012","WSA_QOS_BAD_STYLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsa","qos","bad","style","unknown","conflicting"],"errorCode":"11012","eventId":"","severity":"Low","summary":"Unknown or conflicting style.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 11012; use the surrounding log entries to confirm it.","resolution":"1. Record where 11012 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_BAD_STYLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11012 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unknown or conflicting style.\n\nLookup forms: 11012, 0x2B04, error 11012, WSA_QOS_BAD_STYLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11012"]},{"id":2313,"title":"WSA_QOS_BAD_OBJECT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11013","0x2B05","error 11013","WSA_QOS_BAD_OBJECT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","wsa","qos","bad","object","problem","with","some","part","the","filterspec","providerspecific","buffer","general"],"errorCode":"11013","eventId":"","severity":"Low","summary":"Problem with some part of the filterspec or providerspecific buffer in general.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 11013; use the surrounding log entries to confirm it.","resolution":"1. Record where 11013 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_BAD_OBJECT.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11013 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Problem with some part of the filterspec or providerspecific buffer in general.\n\nLookup forms: 11013, 0x2B05, error 11013, WSA_QOS_BAD_OBJECT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11013"]},{"id":2314,"title":"WSA_QOS_TRAFFIC_CTRL_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11014","0x2B06","error 11014","WSA_QOS_TRAFFIC_CTRL_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsa","qos","traffic","ctrl","error","problem","with","some","part","the","flowspec"],"errorCode":"11014","eventId":"","severity":"Low","summary":"Problem with some part of the flowspec.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 11014; use the surrounding log entries to confirm it.","resolution":"1. Record where 11014 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_TRAFFIC_CTRL_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11014 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Problem with some part of the flowspec.\n\nLookup forms: 11014, 0x2B06, error 11014, WSA_QOS_TRAFFIC_CTRL_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11014"]},{"id":2315,"title":"WSA_QOS_GENERIC_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11015","0x2B07","error 11015","WSA_QOS_GENERIC_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsa","qos","generic","error","general"],"errorCode":"11015","eventId":"","severity":"Low","summary":"General QOS error.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 11015; use the surrounding log entries to confirm it.","resolution":"1. Record where 11015 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_GENERIC_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11015 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: General QOS error.\n\nLookup forms: 11015, 0x2B07, error 11015, WSA_QOS_GENERIC_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11015"]},{"id":2316,"title":"WSA_QOS_ESERVICETYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11016","0x2B08","error 11016","WSA_QOS_ESERVICETYPE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","wsa","qos","eservicetype","invalid","unrecognized","service","type","was","found","the","flowspec"],"errorCode":"11016","eventId":"","severity":"Medium","summary":"An invalid or unrecognized service type was found in the flowspec.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 11016; use the surrounding log entries to confirm it.","resolution":"1. Record where 11016 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_ESERVICETYPE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11016 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An invalid or unrecognized service type was found in the flowspec.\n\nLookup forms: 11016, 0x2B08, error 11016, WSA_QOS_ESERVICETYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11016"]},{"id":2317,"title":"WSA_QOS_EFLOWSPEC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11017","0x2B09","error 11017","WSA_QOS_EFLOWSPEC","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsa","qos","eflowspec","invalid","inconsistent","flowspec","was","found","the","structure"],"errorCode":"11017","eventId":"","severity":"Medium","summary":"An invalid or inconsistent flowspec was found in the QOS structure.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 11017; use the surrounding log entries to confirm it.","resolution":"1. Record where 11017 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_EFLOWSPEC.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11017 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An invalid or inconsistent flowspec was found in the QOS structure.\n\nLookup forms: 11017, 0x2B09, error 11017, WSA_QOS_EFLOWSPEC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11017"]},{"id":2318,"title":"WSA_QOS_EPROVSPECBUF","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11018","0x2B0A","error 11018","WSA_QOS_EPROVSPECBUF","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","wsa","qos","eprovspecbuf","invalid","provider","specific","buffer"],"errorCode":"11018","eventId":"","severity":"Medium","summary":"Invalid QOS provider-specific buffer.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 11018; use the surrounding log entries to confirm it.","resolution":"1. Record where 11018 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_EPROVSPECBUF.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11018 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid QOS provider-specific buffer.\n\nLookup forms: 11018, 0x2B0A, error 11018, WSA_QOS_EPROVSPECBUF. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11018"]},{"id":2319,"title":"WSA_QOS_EFILTERSTYLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11019","0x2B0B","error 11019","WSA_QOS_EFILTERSTYLE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsa","qos","efilterstyle","invalid","filter","style","was","used"],"errorCode":"11019","eventId":"","severity":"Medium","summary":"An invalid QOS filter style was used.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 11019; use the surrounding log entries to confirm it.","resolution":"1. Record where 11019 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_EFILTERSTYLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11019 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An invalid QOS filter style was used.\n\nLookup forms: 11019, 0x2B0B, error 11019, WSA_QOS_EFILTERSTYLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11019"]},{"id":2320,"title":"WSA_QOS_EFILTERTYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11020","0x2B0C","error 11020","WSA_QOS_EFILTERTYPE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsa","qos","efiltertype","invalid","filter","type","was","used"],"errorCode":"11020","eventId":"","severity":"Medium","summary":"An invalid QOS filter type was used.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 11020; use the surrounding log entries to confirm it.","resolution":"1. Record where 11020 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_EFILTERTYPE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11020 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An invalid QOS filter type was used.\n\nLookup forms: 11020, 0x2B0C, error 11020, WSA_QOS_EFILTERTYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11020"]},{"id":2321,"title":"WSA_QOS_EFILTERCOUNT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11021","0x2B0D","error 11021","WSA_QOS_EFILTERCOUNT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsa","qos","efiltercount","incorrect","number","filterspecs","were","specified","the","flowdescriptor"],"errorCode":"11021","eventId":"","severity":"Low","summary":"An incorrect number of QOS FILTERSPECs were specified in the FLOWDESCRIPTOR.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 11021; use the surrounding log entries to confirm it.","resolution":"1. Record where 11021 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_EFILTERCOUNT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11021 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An incorrect number of QOS FILTERSPECs were specified in the FLOWDESCRIPTOR.\n\nLookup forms: 11021, 0x2B0D, error 11021, WSA_QOS_EFILTERCOUNT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11021"]},{"id":2322,"title":"WSA_QOS_EOBJLENGTH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11022","0x2B0E","error 11022","WSA_QOS_EOBJLENGTH","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","wsa","qos","eobjlength","object","with","invalid","objectlength","field","was","specified","the","provider","specific","buffer"],"errorCode":"11022","eventId":"","severity":"Medium","summary":"An object with an invalid ObjectLength field was specified in the QOS provider-specific buffer.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 11022; use the surrounding log entries to confirm it.","resolution":"1. Record where 11022 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_EOBJLENGTH.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11022 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An object with an invalid ObjectLength field was specified in the QOS provider-specific buffer.\n\nLookup forms: 11022, 0x2B0E, error 11022, WSA_QOS_EOBJLENGTH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11022"]},{"id":2323,"title":"WSA_QOS_EFLOWCOUNT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11023","0x2B0F","error 11023","WSA_QOS_EFLOWCOUNT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsa","qos","eflowcount","incorrect","number","flow","descriptors","was","specified","the","structure"],"errorCode":"11023","eventId":"","severity":"Low","summary":"An incorrect number of flow descriptors was specified in the QOS structure.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 11023; use the surrounding log entries to confirm it.","resolution":"1. Record where 11023 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_EFLOWCOUNT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11023 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An incorrect number of flow descriptors was specified in the QOS structure.\n\nLookup forms: 11023, 0x2B0F, error 11023, WSA_QOS_EFLOWCOUNT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11023"]},{"id":2324,"title":"WSA_QOS_EUNKOWNPSOBJ","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11024","0x2B10","error 11024","WSA_QOS_EUNKOWNPSOBJ","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","wsa","qos","eunkownpsobj","unrecognized","object","was","found","the","provider","specific","buffer"],"errorCode":"11024","eventId":"","severity":"Low","summary":"An unrecognized object was found in the QOS provider-specific buffer.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 11024; use the surrounding log entries to confirm it.","resolution":"1. Record where 11024 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_EUNKOWNPSOBJ.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11024 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An unrecognized object was found in the QOS provider-specific buffer.\n\nLookup forms: 11024, 0x2B10, error 11024, WSA_QOS_EUNKOWNPSOBJ. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11024"]},{"id":2325,"title":"WSA_QOS_EPOLICYOBJ","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11025","0x2B11","error 11025","WSA_QOS_EPOLICYOBJ","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","wsa","qos","epolicyobj","invalid","policy","object","was","found","the","provider","specific","buffer"],"errorCode":"11025","eventId":"","severity":"Medium","summary":"An invalid policy object was found in the QOS provider-specific buffer.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 11025; use the surrounding log entries to confirm it.","resolution":"1. Record where 11025 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_EPOLICYOBJ.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11025 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An invalid policy object was found in the QOS provider-specific buffer.\n\nLookup forms: 11025, 0x2B11, error 11025, WSA_QOS_EPOLICYOBJ. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11025"]},{"id":2326,"title":"WSA_QOS_EFLOWDESC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11026","0x2B12","error 11026","WSA_QOS_EFLOWDESC","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsa","qos","eflowdesc","invalid","flow","descriptor","was","found","the","list"],"errorCode":"11026","eventId":"","severity":"Medium","summary":"An invalid QOS flow descriptor was found in the flow descriptor list.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 11026; use the surrounding log entries to confirm it.","resolution":"1. Record where 11026 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_EFLOWDESC.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11026 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An invalid QOS flow descriptor was found in the flow descriptor list.\n\nLookup forms: 11026, 0x2B12, error 11026, WSA_QOS_EFLOWDESC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11026"]},{"id":2327,"title":"WSA_QOS_EPSFLOWSPEC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11027","0x2B13","error 11027","WSA_QOS_EPSFLOWSPEC","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","wsa","qos","epsflowspec","invalid","inconsistent","flowspec","was","found","the","provider","specific","buffer"],"errorCode":"11027","eventId":"","severity":"Medium","summary":"An invalid or inconsistent flowspec was found in the QOS provider specific buffer.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 11027; use the surrounding log entries to confirm it.","resolution":"1. Record where 11027 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_EPSFLOWSPEC.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11027 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An invalid or inconsistent flowspec was found in the QOS provider specific buffer.\n\nLookup forms: 11027, 0x2B13, error 11027, WSA_QOS_EPSFLOWSPEC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): An invalid or inconsistent flowspec was found in the QOS provider-specific buffer.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11027"]},{"id":2328,"title":"WSA_QOS_EPSFILTERSPEC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11028","0x2B14","error 11028","WSA_QOS_EPSFILTERSPEC","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","wsa","qos","epsfilterspec","invalid","filterspec","was","found","the","provider","specific","buffer"],"errorCode":"11028","eventId":"","severity":"Medium","summary":"An invalid FILTERSPEC was found in the QOS provider-specific buffer.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 11028; use the surrounding log entries to confirm it.","resolution":"1. Record where 11028 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_EPSFILTERSPEC.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11028 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An invalid FILTERSPEC was found in the QOS provider-specific buffer.\n\nLookup forms: 11028, 0x2B14, error 11028, WSA_QOS_EPSFILTERSPEC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11028"]},{"id":2329,"title":"WSA_QOS_ESDMODEOBJ","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11029","0x2B15","error 11029","WSA_QOS_ESDMODEOBJ","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","wsa","qos","esdmodeobj","invalid","shape","discard","mode","object","was","found","the","provider","specific","buffer"],"errorCode":"11029","eventId":"","severity":"Medium","summary":"An invalid shape discard mode object was found in the QOS provider specific buffer.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 11029; use the surrounding log entries to confirm it.","resolution":"1. Record where 11029 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_ESDMODEOBJ.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11029 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An invalid shape discard mode object was found in the QOS provider specific buffer.\n\nLookup forms: 11029, 0x2B15, error 11029, WSA_QOS_ESDMODEOBJ. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): An invalid shape discard mode object was found in the QOS provider-specific buffer.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11029"]},{"id":2330,"title":"WSA_QOS_ESHAPERATEOBJ","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11030","0x2B16","error 11030","WSA_QOS_ESHAPERATEOBJ","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","wsa","qos","eshaperateobj","invalid","shaping","rate","object","was","found","the","provider","specific","buffer"],"errorCode":"11030","eventId":"","severity":"Medium","summary":"An invalid shaping rate object was found in the QOS provider-specific buffer.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 11030; use the surrounding log entries to confirm it.","resolution":"1. Record where 11030 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_ESHAPERATEOBJ.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11030 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An invalid shaping rate object was found in the QOS provider-specific buffer.\n\nLookup forms: 11030, 0x2B16, error 11030, WSA_QOS_ESHAPERATEOBJ. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11030"]},{"id":2331,"title":"WSA_QOS_RESERVED_PETYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11031","0x2B17","error 11031","WSA_QOS_RESERVED_PETYPE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","wsa","qos","reserved","petype","policy","element","was","found","the","provider","specific","buffer"],"errorCode":"11031","eventId":"","severity":"Low","summary":"A reserved policy element was found in the QOS provider-specific buffer.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 11031; use the surrounding log entries to confirm it.","resolution":"1. Record where 11031 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_QOS_RESERVED_PETYPE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11031 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A reserved policy element was found in the QOS provider-specific buffer.\n\nLookup forms: 11031, 0x2B17, error 11031, WSA_QOS_RESERVED_PETYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11031"]},{"id":2332,"title":"WSA_SECURE_HOST_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11032","0x2B18","error 11032","WSA_SECURE_HOST_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","wsa","secure","host","not","found","such","known","securely"],"errorCode":"11032","eventId":"","severity":"Low","summary":"No such host is known securely.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 11032; use the surrounding log entries to confirm it.","resolution":"1. Record where 11032 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_SECURE_HOST_NOT_FOUND.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11032 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No such host is known securely.\n\nLookup forms: 11032, 0x2B18, error 11032, WSA_SECURE_HOST_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11032"]},{"id":2333,"title":"WSA_IPSEC_NAME_POLICY_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["11033","0x2B19","error 11033","WSA_IPSEC_NAME_POLICY_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","wsa","ipsec","name","policy","error","based","could","not","added"],"errorCode":"11033","eventId":"","severity":"Low","summary":"Name based IPSEC policy could not be added.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 11033; use the surrounding log entries to confirm it.","resolution":"1. Record where 11033 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WSA_IPSEC_NAME_POLICY_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 11033 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Name based IPSEC policy could not be added.\n\nLookup forms: 11033, 0x2B19, error 11033, WSA_IPSEC_NAME_POLICY_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["11033"]},{"id":2334,"title":"ERROR_IPSEC_QM_POLICY_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13000","0x32C8","error 13000","ERROR_IPSEC_QM_POLICY_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","policy","exists","the","specified","quick","mode","already"],"errorCode":"13000","eventId":"","severity":"Medium","summary":"The specified quick mode policy already exists.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13000; use the surrounding log entries to confirm it.","resolution":"1. Record where 13000 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_QM_POLICY_EXISTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13000 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified quick mode policy already exists.\n\nLookup forms: 13000, 0x32C8, error 13000, ERROR_IPSEC_QM_POLICY_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13000"]},{"id":2335,"title":"ERROR_IPSEC_QM_POLICY_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13001","0x32C9","error 13001","ERROR_IPSEC_QM_POLICY_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","policy","not","found","the","specified","quick","mode","was"],"errorCode":"13001","eventId":"","severity":"Medium","summary":"The specified quick mode policy was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13001; use the surrounding log entries to confirm it.","resolution":"1. Record where 13001 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_QM_POLICY_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13001 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified quick mode policy was not found.\n\nLookup forms: 13001, 0x32C9, error 13001, ERROR_IPSEC_QM_POLICY_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13001"]},{"id":2336,"title":"ERROR_IPSEC_QM_POLICY_IN_USE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13002","0x32CA","error 13002","ERROR_IPSEC_QM_POLICY_IN_USE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","policy","use","the","specified","quick","mode","being","used"],"errorCode":"13002","eventId":"","severity":"Low","summary":"The specified quick mode policy is being used.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13002; use the surrounding log entries to confirm it.","resolution":"1. Record where 13002 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_QM_POLICY_IN_USE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13002 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified quick mode policy is being used.\n\nLookup forms: 13002, 0x32CA, error 13002, ERROR_IPSEC_QM_POLICY_IN_USE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13002"]},{"id":2337,"title":"ERROR_IPSEC_MM_POLICY_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13003","0x32CB","error 13003","ERROR_IPSEC_MM_POLICY_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","policy","exists","the","specified","main","mode","already"],"errorCode":"13003","eventId":"","severity":"Medium","summary":"The specified main mode policy already exists.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13003; use the surrounding log entries to confirm it.","resolution":"1. Record where 13003 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_MM_POLICY_EXISTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13003 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified main mode policy already exists.\n\nLookup forms: 13003, 0x32CB, error 13003, ERROR_IPSEC_MM_POLICY_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13003"]},{"id":2338,"title":"ERROR_IPSEC_MM_POLICY_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13004","0x32CC","error 13004","ERROR_IPSEC_MM_POLICY_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","policy","not","found","the","specified","main","mode","was"],"errorCode":"13004","eventId":"","severity":"Medium","summary":"The specified main mode policy was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13004; use the surrounding log entries to confirm it.","resolution":"1. Record where 13004 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_MM_POLICY_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13004 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified main mode policy was not found.\n\nLookup forms: 13004, 0x32CC, error 13004, ERROR_IPSEC_MM_POLICY_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13004"]},{"id":2339,"title":"ERROR_IPSEC_MM_POLICY_IN_USE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13005","0x32CD","error 13005","ERROR_IPSEC_MM_POLICY_IN_USE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","policy","use","the","specified","main","mode","being","used"],"errorCode":"13005","eventId":"","severity":"Low","summary":"The specified main mode policy is being used.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13005; use the surrounding log entries to confirm it.","resolution":"1. Record where 13005 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_MM_POLICY_IN_USE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13005 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified main mode policy is being used.\n\nLookup forms: 13005, 0x32CD, error 13005, ERROR_IPSEC_MM_POLICY_IN_USE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13005"]},{"id":2340,"title":"ERROR_IPSEC_MM_FILTER_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13006","0x32CE","error 13006","ERROR_IPSEC_MM_FILTER_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","filter","exists","the","specified","main","mode","already"],"errorCode":"13006","eventId":"","severity":"Medium","summary":"The specified main mode filter already exists.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13006; use the surrounding log entries to confirm it.","resolution":"1. Record where 13006 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_MM_FILTER_EXISTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13006 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified main mode filter already exists.\n\nLookup forms: 13006, 0x32CE, error 13006, ERROR_IPSEC_MM_FILTER_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13006"]},{"id":2341,"title":"ERROR_IPSEC_MM_FILTER_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13007","0x32CF","error 13007","ERROR_IPSEC_MM_FILTER_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","filter","not","found","the","specified","main","mode","was"],"errorCode":"13007","eventId":"","severity":"Medium","summary":"The specified main mode filter was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13007; use the surrounding log entries to confirm it.","resolution":"1. Record where 13007 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_MM_FILTER_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13007 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified main mode filter was not found.\n\nLookup forms: 13007, 0x32CF, error 13007, ERROR_IPSEC_MM_FILTER_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13007"]},{"id":2342,"title":"ERROR_IPSEC_TRANSPORT_FILTER_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13008","0x32D0","error 13008","ERROR_IPSEC_TRANSPORT_FILTER_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","transport","filter","exists","the","specified","mode","already"],"errorCode":"13008","eventId":"","severity":"Medium","summary":"The specified transport mode filter already exists.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13008; use the surrounding log entries to confirm it.","resolution":"1. Record where 13008 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_TRANSPORT_FILTER_EXISTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13008 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified transport mode filter already exists.\n\nLookup forms: 13008, 0x32D0, error 13008, ERROR_IPSEC_TRANSPORT_FILTER_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13008"]},{"id":2343,"title":"ERROR_IPSEC_TRANSPORT_FILTER_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13009","0x32D1","error 13009","ERROR_IPSEC_TRANSPORT_FILTER_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","transport","filter","not","found","the","specified","mode","does","exist"],"errorCode":"13009","eventId":"","severity":"Low","summary":"The specified transport mode filter does not exist.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13009; use the surrounding log entries to confirm it.","resolution":"1. Record where 13009 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_TRANSPORT_FILTER_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13009 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified transport mode filter does not exist.\n\nLookup forms: 13009, 0x32D1, error 13009, ERROR_IPSEC_TRANSPORT_FILTER_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13009"]},{"id":2344,"title":"ERROR_IPSEC_MM_AUTH_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13010","0x32D2","error 13010","ERROR_IPSEC_MM_AUTH_EXISTS","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ipsec","auth","exists","the","specified","main","mode","authentication","list"],"errorCode":"13010","eventId":"","severity":"High","summary":"The specified main mode authentication list exists.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 13010; use the surrounding log entries to confirm it.","resolution":"1. Record where 13010 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_MM_AUTH_EXISTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13010 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified main mode authentication list exists.\n\nLookup forms: 13010, 0x32D2, error 13010, ERROR_IPSEC_MM_AUTH_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13010"]},{"id":2345,"title":"ERROR_IPSEC_MM_AUTH_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13011","0x32D3","error 13011","ERROR_IPSEC_MM_AUTH_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ipsec","auth","not","found","the","specified","main","mode","authentication","list","was"],"errorCode":"13011","eventId":"","severity":"High","summary":"The specified main mode authentication list was not found.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 13011; use the surrounding log entries to confirm it.","resolution":"1. Record where 13011 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_MM_AUTH_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13011 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified main mode authentication list was not found.\n\nLookup forms: 13011, 0x32D3, error 13011, ERROR_IPSEC_MM_AUTH_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13011"]},{"id":2346,"title":"ERROR_IPSEC_MM_AUTH_IN_USE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13012","0x32D4","error 13012","ERROR_IPSEC_MM_AUTH_IN_USE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ipsec","auth","use","the","specified","main","mode","authentication","list","being","used"],"errorCode":"13012","eventId":"","severity":"High","summary":"The specified main mode authentication list is being used.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 13012; use the surrounding log entries to confirm it.","resolution":"1. Record where 13012 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_MM_AUTH_IN_USE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13012 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified main mode authentication list is being used.\n\nLookup forms: 13012, 0x32D4, error 13012, ERROR_IPSEC_MM_AUTH_IN_USE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The specified quick mode policy is being used.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13012"]},{"id":2347,"title":"ERROR_IPSEC_DEFAULT_MM_POLICY_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13013","0x32D5","error 13013","ERROR_IPSEC_DEFAULT_MM_POLICY_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","default","policy","not","found","the","specified","main","mode","was"],"errorCode":"13013","eventId":"","severity":"Medium","summary":"The specified default main mode policy was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13013; use the surrounding log entries to confirm it.","resolution":"1. Record where 13013 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_DEFAULT_MM_POLICY_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13013 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified default main mode policy was not found.\n\nLookup forms: 13013, 0x32D5, error 13013, ERROR_IPSEC_DEFAULT_MM_POLICY_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The specified main mode policy was not found.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13013"]},{"id":2348,"title":"ERROR_IPSEC_DEFAULT_MM_AUTH_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13014","0x32D6","error 13014","ERROR_IPSEC_DEFAULT_MM_AUTH_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ipsec","default","auth","not","found","the","specified","main","mode","authentication","list","was"],"errorCode":"13014","eventId":"","severity":"High","summary":"The specified default main mode authentication list was not found.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 13014; use the surrounding log entries to confirm it.","resolution":"1. Record where 13014 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_DEFAULT_MM_AUTH_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13014 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified default main mode authentication list was not found.\n\nLookup forms: 13014, 0x32D6, error 13014, ERROR_IPSEC_DEFAULT_MM_AUTH_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The specified quick mode policy was not found.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13014"]},{"id":2349,"title":"ERROR_IPSEC_DEFAULT_QM_POLICY_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13015","0x32D7","error 13015","ERROR_IPSEC_DEFAULT_QM_POLICY_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","default","policy","not","found","the","specified","quick","mode","was"],"errorCode":"13015","eventId":"","severity":"Medium","summary":"The specified default quick mode policy was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13015; use the surrounding log entries to confirm it.","resolution":"1. Record where 13015 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_DEFAULT_QM_POLICY_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13015 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified default quick mode policy was not found.\n\nLookup forms: 13015, 0x32D7, error 13015, ERROR_IPSEC_DEFAULT_QM_POLICY_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The manifest file contains one or more syntax errors.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13015"]},{"id":2350,"title":"ERROR_IPSEC_TUNNEL_FILTER_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13016","0x32D8","error 13016","ERROR_IPSEC_TUNNEL_FILTER_EXISTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","tunnel","filter","exists","the","specified","mode"],"errorCode":"13016","eventId":"","severity":"Low","summary":"The specified tunnel mode filter exists.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13016; use the surrounding log entries to confirm it.","resolution":"1. Record where 13016 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_TUNNEL_FILTER_EXISTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13016 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified tunnel mode filter exists.\n\nLookup forms: 13016, 0x32D8, error 13016, ERROR_IPSEC_TUNNEL_FILTER_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The application attempted to activate a disabled activation context.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13016"]},{"id":2351,"title":"ERROR_IPSEC_TUNNEL_FILTER_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13017","0x32D9","error 13017","ERROR_IPSEC_TUNNEL_FILTER_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","tunnel","filter","not","found","the","specified","mode","was"],"errorCode":"13017","eventId":"","severity":"Medium","summary":"The specified tunnel mode filter was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13017; use the surrounding log entries to confirm it.","resolution":"1. Record where 13017 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_TUNNEL_FILTER_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13017 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified tunnel mode filter was not found.\n\nLookup forms: 13017, 0x32D9, error 13017, ERROR_IPSEC_TUNNEL_FILTER_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The requested lookup key was not found in any active activation context.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13017"]},{"id":2352,"title":"ERROR_IPSEC_MM_FILTER_PENDING_DELETION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13018","0x32DA","error 13018","ERROR_IPSEC_MM_FILTER_PENDING_DELETION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","filter","pending","deletion","the","main","mode"],"errorCode":"13018","eventId":"","severity":"Low","summary":"The Main Mode filter is pending deletion.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13018; use the surrounding log entries to confirm it.","resolution":"1. Record where 13018 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_MM_FILTER_PENDING_DELETION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13018 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Main Mode filter is pending deletion.\n\nLookup forms: 13018, 0x32DA, error 13018, ERROR_IPSEC_MM_FILTER_PENDING_DELETION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13018"]},{"id":2353,"title":"ERROR_IPSEC_TRANSPORT_FILTER_PENDING_DELETION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13019","0x32DB","error 13019","ERROR_IPSEC_TRANSPORT_FILTER_PENDING_DELETION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","transport","filter","pending","deletion","the"],"errorCode":"13019","eventId":"","severity":"Low","summary":"The transport filter is pending deletion.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13019; use the surrounding log entries to confirm it.","resolution":"1. Record where 13019 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_TRANSPORT_FILTER_PENDING_DELETION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13019 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The transport filter is pending deletion.\n\nLookup forms: 13019, 0x32DB, error 13019, ERROR_IPSEC_TRANSPORT_FILTER_PENDING_DELETION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13019"]},{"id":2354,"title":"ERROR_IPSEC_TUNNEL_FILTER_PENDING_DELETION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13020","0x32DC","error 13020","ERROR_IPSEC_TUNNEL_FILTER_PENDING_DELETION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","tunnel","filter","pending","deletion","the"],"errorCode":"13020","eventId":"","severity":"Low","summary":"The tunnel filter is pending deletion.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13020; use the surrounding log entries to confirm it.","resolution":"1. Record where 13020 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_TUNNEL_FILTER_PENDING_DELETION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13020 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The tunnel filter is pending deletion.\n\nLookup forms: 13020, 0x32DC, error 13020, ERROR_IPSEC_TUNNEL_FILTER_PENDING_DELETION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13020"]},{"id":2355,"title":"ERROR_IPSEC_MM_POLICY_PENDING_DELETION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13021","0x32DD","error 13021","ERROR_IPSEC_MM_POLICY_PENDING_DELETION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","policy","pending","deletion","the","main","mode"],"errorCode":"13021","eventId":"","severity":"Low","summary":"The Main Mode policy is pending deletion.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13021; use the surrounding log entries to confirm it.","resolution":"1. Record where 13021 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_MM_POLICY_PENDING_DELETION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13021 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Main Mode policy is pending deletion.\n\nLookup forms: 13021, 0x32DD, error 13021, ERROR_IPSEC_MM_POLICY_PENDING_DELETION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13021"]},{"id":2356,"title":"ERROR_IPSEC_MM_AUTH_PENDING_DELETION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13022","0x32DE","error 13022","ERROR_IPSEC_MM_AUTH_PENDING_DELETION","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ipsec","auth","pending","deletion","the","main","mode","authentication","bundle"],"errorCode":"13022","eventId":"","severity":"High","summary":"The Main Mode authentication bundle is pending deletion.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 13022; use the surrounding log entries to confirm it.","resolution":"1. Record where 13022 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_MM_AUTH_PENDING_DELETION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13022 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Main Mode authentication bundle is pending deletion.\n\nLookup forms: 13022, 0x32DE, error 13022, ERROR_IPSEC_MM_AUTH_PENDING_DELETION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13022"]},{"id":2357,"title":"ERROR_IPSEC_QM_POLICY_PENDING_DELETION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13023","0x32DF","error 13023","ERROR_IPSEC_QM_POLICY_PENDING_DELETION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","policy","pending","deletion","the","quick","mode"],"errorCode":"13023","eventId":"","severity":"Low","summary":"The Quick Mode policy is pending deletion.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13023; use the surrounding log entries to confirm it.","resolution":"1. Record where 13023 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_QM_POLICY_PENDING_DELETION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13023 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Quick Mode policy is pending deletion.\n\nLookup forms: 13023, 0x32DF, error 13023, ERROR_IPSEC_QM_POLICY_PENDING_DELETION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13023"]},{"id":2358,"title":"WARNING_IPSEC_MM_POLICY_PRUNED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13024","0x32E0","error 13024","WARNING_IPSEC_MM_POLICY_PRUNED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","warning","ipsec","policy","pruned","the","main","mode","was","successfully","added","but","some","requested","offers","are","not","supported"],"errorCode":"13024","eventId":"","severity":"Medium","summary":"The Main Mode policy was successfully added, but some of the requested offers are not supported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13024; use the surrounding log entries to confirm it.","resolution":"1. Record where 13024 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WARNING_IPSEC_MM_POLICY_PRUNED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13024 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Main Mode policy was successfully added, but some of the requested offers are not supported.\n\nLookup forms: 13024, 0x32E0, error 13024, WARNING_IPSEC_MM_POLICY_PRUNED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13024"]},{"id":2359,"title":"WARNING_IPSEC_QM_POLICY_PRUNED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13025","0x32E1","error 13025","WARNING_IPSEC_QM_POLICY_PRUNED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","warning","ipsec","policy","pruned","the","quick","mode","was","successfully","added","but","some","requested","offers","are","not","supported"],"errorCode":"13025","eventId":"","severity":"Medium","summary":"The Quick Mode policy was successfully added, but some of the requested offers are not supported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13025; use the surrounding log entries to confirm it.","resolution":"1. Record where 13025 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to WARNING_IPSEC_QM_POLICY_PRUNED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13025 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Quick Mode policy was successfully added, but some of the requested offers are not supported.\n\nLookup forms: 13025, 0x32E1, error 13025, WARNING_IPSEC_QM_POLICY_PRUNED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13025"]},{"id":2360,"title":"ERROR_IPSEC_IKE_NEG_STATUS_BEGIN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13800","0x35E8","error 13800","ERROR_IPSEC_IKE_NEG_STATUS_BEGIN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","neg","status","begin"],"errorCode":"13800","eventId":"","severity":"Low","summary":"ERROR_IPSEC_IKE_NEG_STATUS_BEGIN","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13800; use the surrounding log entries to confirm it.","resolution":"1. Record where 13800 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_NEG_STATUS_BEGIN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13800 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: ERROR_IPSEC_IKE_NEG_STATUS_BEGIN\n\nLookup forms: 13800, 0x35E8, error 13800, ERROR_IPSEC_IKE_NEG_STATUS_BEGIN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13800"]},{"id":2361,"title":"ERROR_IPSEC_IKE_AUTH_FAIL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13801","0x35E9","error 13801","ERROR_IPSEC_IKE_AUTH_FAIL","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ipsec","ike","auth","fail","authentication","credentials","are","unacceptable"],"errorCode":"13801","eventId":"","severity":"High","summary":"IKE authentication credentials are unacceptable.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 13801; use the surrounding log entries to confirm it.","resolution":"1. Record where 13801 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_AUTH_FAIL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13801 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: IKE authentication credentials are unacceptable.\n\nLookup forms: 13801, 0x35E9, error 13801, ERROR_IPSEC_IKE_AUTH_FAIL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13801"]},{"id":2362,"title":"ERROR_IPSEC_IKE_ATTRIB_FAIL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13802","0x35EA","error 13802","ERROR_IPSEC_IKE_ATTRIB_FAIL","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ipsec","ike","attrib","fail","security","attributes","are","unacceptable"],"errorCode":"13802","eventId":"","severity":"Low","summary":"IKE security attributes are unacceptable.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 13802; use the surrounding log entries to confirm it.","resolution":"1. Record where 13802 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_ATTRIB_FAIL.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13802 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: IKE security attributes are unacceptable.\n\nLookup forms: 13802, 0x35EA, error 13802, ERROR_IPSEC_IKE_ATTRIB_FAIL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13802"]},{"id":2363,"title":"ERROR_IPSEC_IKE_NEGOTIATION_PENDING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13803","0x35EB","error 13803","ERROR_IPSEC_IKE_NEGOTIATION_PENDING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","negotiation","pending","progress"],"errorCode":"13803","eventId":"","severity":"Low","summary":"IKE Negotiation in progress.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13803; use the surrounding log entries to confirm it.","resolution":"1. Record where 13803 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_NEGOTIATION_PENDING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13803 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: IKE Negotiation in progress.\n\nLookup forms: 13803, 0x35EB, error 13803, ERROR_IPSEC_IKE_NEGOTIATION_PENDING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13803"]},{"id":2364,"title":"ERROR_IPSEC_IKE_GENERAL_PROCESSING_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13804","0x35EC","error 13804","ERROR_IPSEC_IKE_GENERAL_PROCESSING_ERROR","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","ipsec","ike","general","processing"],"errorCode":"13804","eventId":"","severity":"Low","summary":"General processing error.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 13804; use the surrounding log entries to confirm it.","resolution":"1. Record where 13804 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_GENERAL_PROCESSING_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13804 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: General processing error.\n\nLookup forms: 13804, 0x35EC, error 13804, ERROR_IPSEC_IKE_GENERAL_PROCESSING_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13804"]},{"id":2365,"title":"ERROR_IPSEC_IKE_TIMED_OUT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13805","0x35ED","error 13805","ERROR_IPSEC_IKE_TIMED_OUT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","timed","out","negotiation"],"errorCode":"13805","eventId":"","severity":"Low","summary":"Negotiation timed out.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13805; use the surrounding log entries to confirm it.","resolution":"1. Record where 13805 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_TIMED_OUT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13805 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Negotiation timed out.\n\nLookup forms: 13805, 0x35ED, error 13805, ERROR_IPSEC_IKE_TIMED_OUT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13805"]},{"id":2366,"title":"ERROR_IPSEC_IKE_NO_CERT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13806","0x35EE","error 13806","ERROR_IPSEC_IKE_NO_CERT","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ipsec","ike","cert","failed","find","valid","machine","certificate","contact","your","network","security","administrator","about","installing","the","appropriate","store"],"errorCode":"13806","eventId":"","severity":"High","summary":"IKE failed to find valid machine certificate. Contact your Network Security Administrator about installing a valid certificate in the appropriate Certificate Store.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 13806; use the surrounding log entries to confirm it.","resolution":"1. Record where 13806 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Verify the required service or agent is installed, running, and current; repair the component if needed.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_NO_CERT.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13806 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: IKE failed to find valid machine certificate. Contact your Network Security Administrator about installing a valid certificate in the appropriate Certificate Store.\n\nLookup forms: 13806, 0x35EE, error 13806, ERROR_IPSEC_IKE_NO_CERT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13806"]},{"id":2367,"title":"ERROR_IPSEC_IKE_SA_DELETED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13807","0x35EF","error 13807","ERROR_IPSEC_IKE_SA_DELETED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","deleted","peer","before","establishment","completed"],"errorCode":"13807","eventId":"","severity":"Low","summary":"IKE SA deleted by peer before establishment completed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13807; use the surrounding log entries to confirm it.","resolution":"1. Record where 13807 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_SA_DELETED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13807 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: IKE SA deleted by peer before establishment completed.\n\nLookup forms: 13807, 0x35EF, error 13807, ERROR_IPSEC_IKE_SA_DELETED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13807"]},{"id":2368,"title":"ERROR_IPSEC_IKE_SA_REAPED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13808","0x35F0","error 13808","ERROR_IPSEC_IKE_SA_REAPED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","reaped","deleted","before","establishment","completed"],"errorCode":"13808","eventId":"","severity":"Low","summary":"IKE SA deleted before establishment completed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13808; use the surrounding log entries to confirm it.","resolution":"1. Record where 13808 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_SA_REAPED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13808 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: IKE SA deleted before establishment completed.\n\nLookup forms: 13808, 0x35F0, error 13808, ERROR_IPSEC_IKE_SA_REAPED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13808"]},{"id":2369,"title":"ERROR_IPSEC_IKE_MM_ACQUIRE_DROP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13809","0x35F1","error 13809","ERROR_IPSEC_IKE_MM_ACQUIRE_DROP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","acquire","drop","negotiation","request","sat","queue","too","long"],"errorCode":"13809","eventId":"","severity":"Low","summary":"Negotiation request sat in Queue too long.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13809; use the surrounding log entries to confirm it.","resolution":"1. Record where 13809 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_MM_ACQUIRE_DROP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13809 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Negotiation request sat in Queue too long.\n\nLookup forms: 13809, 0x35F1, error 13809, ERROR_IPSEC_IKE_MM_ACQUIRE_DROP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13809"]},{"id":2370,"title":"ERROR_IPSEC_IKE_QM_ACQUIRE_DROP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13810","0x35F2","error 13810","ERROR_IPSEC_IKE_QM_ACQUIRE_DROP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","acquire","drop","negotiation","request","sat","queue","too","long"],"errorCode":"13810","eventId":"","severity":"Low","summary":"Negotiation request sat in Queue too long.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13810; use the surrounding log entries to confirm it.","resolution":"1. Record where 13810 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_QM_ACQUIRE_DROP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13810 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Negotiation request sat in Queue too long.\n\nLookup forms: 13810, 0x35F2, error 13810, ERROR_IPSEC_IKE_QM_ACQUIRE_DROP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13810"]},{"id":2371,"title":"ERROR_IPSEC_IKE_QUEUE_DROP_MM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13811","0x35F3","error 13811","ERROR_IPSEC_IKE_QUEUE_DROP_MM","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","queue","drop","negotiation","request","sat","too","long"],"errorCode":"13811","eventId":"","severity":"Low","summary":"Negotiation request sat in Queue too long.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13811; use the surrounding log entries to confirm it.","resolution":"1. Record where 13811 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_QUEUE_DROP_MM.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13811 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Negotiation request sat in Queue too long.\n\nLookup forms: 13811, 0x35F3, error 13811, ERROR_IPSEC_IKE_QUEUE_DROP_MM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13811"]},{"id":2372,"title":"ERROR_IPSEC_IKE_QUEUE_DROP_NO_MM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13812","0x35F4","error 13812","ERROR_IPSEC_IKE_QUEUE_DROP_NO_MM","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","queue","drop","negotiation","request","sat","too","long"],"errorCode":"13812","eventId":"","severity":"Low","summary":"Negotiation request sat in Queue too long.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13812; use the surrounding log entries to confirm it.","resolution":"1. Record where 13812 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_QUEUE_DROP_NO_MM.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13812 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Negotiation request sat in Queue too long.\n\nLookup forms: 13812, 0x35F4, error 13812, ERROR_IPSEC_IKE_QUEUE_DROP_NO_MM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13812"]},{"id":2373,"title":"ERROR_IPSEC_IKE_DROP_NO_RESPONSE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13813","0x35F5","error 13813","ERROR_IPSEC_IKE_DROP_NO_RESPONSE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","drop","response","from","peer"],"errorCode":"13813","eventId":"","severity":"Low","summary":"No response from peer.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13813; use the surrounding log entries to confirm it.","resolution":"1. Record where 13813 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_DROP_NO_RESPONSE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13813 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No response from peer.\n\nLookup forms: 13813, 0x35F5, error 13813, ERROR_IPSEC_IKE_DROP_NO_RESPONSE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13813"]},{"id":2374,"title":"ERROR_IPSEC_IKE_MM_DELAY_DROP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13814","0x35F6","error 13814","ERROR_IPSEC_IKE_MM_DELAY_DROP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","delay","drop","negotiation","took","too","long"],"errorCode":"13814","eventId":"","severity":"Low","summary":"Negotiation took too long.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13814; use the surrounding log entries to confirm it.","resolution":"1. Record where 13814 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_MM_DELAY_DROP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13814 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Negotiation took too long.\n\nLookup forms: 13814, 0x35F6, error 13814, ERROR_IPSEC_IKE_MM_DELAY_DROP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13814"]},{"id":2375,"title":"ERROR_IPSEC_IKE_QM_DELAY_DROP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13815","0x35F7","error 13815","ERROR_IPSEC_IKE_QM_DELAY_DROP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","delay","drop","negotiation","took","too","long"],"errorCode":"13815","eventId":"","severity":"Low","summary":"Negotiation took too long.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13815; use the surrounding log entries to confirm it.","resolution":"1. Record where 13815 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_QM_DELAY_DROP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13815 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Negotiation took too long.\n\nLookup forms: 13815, 0x35F7, error 13815, ERROR_IPSEC_IKE_QM_DELAY_DROP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13815"]},{"id":2376,"title":"ERROR_IPSEC_IKE_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13816","0x35F8","error 13816","ERROR_IPSEC_IKE_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","unknown","occurred"],"errorCode":"13816","eventId":"","severity":"Low","summary":"Unknown error occurred.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13816; use the surrounding log entries to confirm it.","resolution":"1. Record where 13816 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13816 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unknown error occurred.\n\nLookup forms: 13816, 0x35F8, error 13816, ERROR_IPSEC_IKE_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13816"]},{"id":2377,"title":"ERROR_IPSEC_IKE_CRL_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13817","0x35F9","error 13817","ERROR_IPSEC_IKE_CRL_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","crl","failed","certificate","revocation","check"],"errorCode":"13817","eventId":"","severity":"High","summary":"Certificate Revocation Check failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13817; use the surrounding log entries to confirm it.","resolution":"1. Record where 13817 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_CRL_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13817 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Certificate Revocation Check failed.\n\nLookup forms: 13817, 0x35F9, error 13817, ERROR_IPSEC_IKE_CRL_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13817"]},{"id":2378,"title":"ERROR_IPSEC_IKE_INVALID_KEY_USAGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13818","0x35FA","error 13818","ERROR_IPSEC_IKE_INVALID_KEY_USAGE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","invalid","key","usage","certificate"],"errorCode":"13818","eventId":"","severity":"Medium","summary":"Invalid certificate key usage.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13818; use the surrounding log entries to confirm it.","resolution":"1. Record where 13818 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_INVALID_KEY_USAGE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13818 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid certificate key usage.\n\nLookup forms: 13818, 0x35FA, error 13818, ERROR_IPSEC_IKE_INVALID_KEY_USAGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13818"]},{"id":2379,"title":"ERROR_IPSEC_IKE_INVALID_CERT_TYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13819","0x35FB","error 13819","ERROR_IPSEC_IKE_INVALID_CERT_TYPE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","invalid","cert","type","certificate"],"errorCode":"13819","eventId":"","severity":"Medium","summary":"Invalid certificate type.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13819; use the surrounding log entries to confirm it.","resolution":"1. Record where 13819 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_INVALID_CERT_TYPE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13819 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid certificate type.\n\nLookup forms: 13819, 0x35FB, error 13819, ERROR_IPSEC_IKE_INVALID_CERT_TYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13819"]},{"id":2380,"title":"ERROR_IPSEC_IKE_NO_PRIVATE_KEY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13820","0x35FC","error 13820","ERROR_IPSEC_IKE_NO_PRIVATE_KEY","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ipsec","ike","private","key","negotiation","failed","because","the","machine","certificate","used","does","not","have","certificates","require","contact","your","network","security","administrator","about","replacing","with"],"errorCode":"13820","eventId":"","severity":"High","summary":"IKE negotiation failed because the machine certificate used does not have a private key. IPsec certificates require a private key. Contact your Network Security administrator about replacing with a certificate that has a private key.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 13820; use the surrounding log entries to confirm it.","resolution":"1. Record where 13820 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_NO_PRIVATE_KEY.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13820 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: IKE negotiation failed because the machine certificate used does not have a private key. IPsec certificates require a private key. Contact your Network Security administrator about replacing with a certificate that has a private key.\n\nLookup forms: 13820, 0x35FC, error 13820, ERROR_IPSEC_IKE_NO_PRIVATE_KEY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): No private key associated with machine certificate.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13820"]},{"id":2381,"title":"ERROR_IPSEC_IKE_SIMULTANEOUS_REKEY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13821","0x35FD","error 13821","ERROR_IPSEC_IKE_SIMULTANEOUS_REKEY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","simultaneous","rekey","rekeys","were","detected"],"errorCode":"13821","eventId":"","severity":"Low","summary":"Simultaneous rekeys were detected.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13821; use the surrounding log entries to confirm it.","resolution":"1. Record where 13821 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_SIMULTANEOUS_REKEY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13821 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Simultaneous rekeys were detected.\n\nLookup forms: 13821, 0x35FD, error 13821, ERROR_IPSEC_IKE_SIMULTANEOUS_REKEY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13821"]},{"id":2382,"title":"ERROR_IPSEC_IKE_DH_FAIL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13822","0x35FE","error 13822","ERROR_IPSEC_IKE_DH_FAIL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","fail","failure","diffie","hellman","computation"],"errorCode":"13822","eventId":"","severity":"High","summary":"Failure in Diffie-Hellman computation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13822; use the surrounding log entries to confirm it.","resolution":"1. Record where 13822 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_DH_FAIL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13822 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Failure in Diffie-Hellman computation.\n\nLookup forms: 13822, 0x35FE, error 13822, ERROR_IPSEC_IKE_DH_FAIL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Failure in Diffie-Helman computation.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13822"]},{"id":2383,"title":"ERROR_IPSEC_IKE_CRITICAL_PAYLOAD_NOT_RECOGNIZED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13823","0x35FF","error 13823","ERROR_IPSEC_IKE_CRITICAL_PAYLOAD_NOT_RECOGNIZED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","ipsec","ike","critical","payload","not","recognized","don","know","how","process"],"errorCode":"13823","eventId":"","severity":"Low","summary":"Don't know how to process critical payload.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 13823; use the surrounding log entries to confirm it.","resolution":"1. Record where 13823 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_CRITICAL_PAYLOAD_NOT_RECOGNIZED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13823 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Don't know how to process critical payload.\n\nLookup forms: 13823, 0x35FF, error 13823, ERROR_IPSEC_IKE_CRITICAL_PAYLOAD_NOT_RECOGNIZED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13823"]},{"id":2384,"title":"ERROR_IPSEC_IKE_INVALID_HEADER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13824","0x3600","error 13824","ERROR_IPSEC_IKE_INVALID_HEADER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","invalid","header"],"errorCode":"13824","eventId":"","severity":"Medium","summary":"Invalid header.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13824; use the surrounding log entries to confirm it.","resolution":"1. Record where 13824 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_INVALID_HEADER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13824 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid header.\n\nLookup forms: 13824, 0x3600, error 13824, ERROR_IPSEC_IKE_INVALID_HEADER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13824"]},{"id":2385,"title":"ERROR_IPSEC_IKE_NO_POLICY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13825","0x3601","error 13825","ERROR_IPSEC_IKE_NO_POLICY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","policy","configured"],"errorCode":"13825","eventId":"","severity":"Low","summary":"No policy configured.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13825; use the surrounding log entries to confirm it.","resolution":"1. Record where 13825 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_NO_POLICY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13825 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No policy configured.\n\nLookup forms: 13825, 0x3601, error 13825, ERROR_IPSEC_IKE_NO_POLICY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13825"]},{"id":2386,"title":"ERROR_IPSEC_IKE_INVALID_SIGNATURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13826","0x3602","error 13826","ERROR_IPSEC_IKE_INVALID_SIGNATURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","invalid","signature","failed","verify"],"errorCode":"13826","eventId":"","severity":"High","summary":"Failed to verify signature.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13826; use the surrounding log entries to confirm it.","resolution":"1. Record where 13826 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_INVALID_SIGNATURE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13826 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Failed to verify signature.\n\nLookup forms: 13826, 0x3602, error 13826, ERROR_IPSEC_IKE_INVALID_SIGNATURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13826"]},{"id":2387,"title":"ERROR_IPSEC_IKE_KERBEROS_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13827","0x3603","error 13827","ERROR_IPSEC_IKE_KERBEROS_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","kerberos","failed","authenticate","using"],"errorCode":"13827","eventId":"","severity":"High","summary":"Failed to authenticate using Kerberos.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13827; use the surrounding log entries to confirm it.","resolution":"1. Record where 13827 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_KERBEROS_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13827 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Failed to authenticate using Kerberos.\n\nLookup forms: 13827, 0x3603, error 13827, ERROR_IPSEC_IKE_KERBEROS_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13827"]},{"id":2388,"title":"ERROR_IPSEC_IKE_NO_PUBLIC_KEY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13828","0x3604","error 13828","ERROR_IPSEC_IKE_NO_PUBLIC_KEY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","public","key","peer","certificate","did","not","have"],"errorCode":"13828","eventId":"","severity":"Low","summary":"Peer's certificate did not have a public key.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13828; use the surrounding log entries to confirm it.","resolution":"1. Record where 13828 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_NO_PUBLIC_KEY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13828 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Peer's certificate did not have a public key.\n\nLookup forms: 13828, 0x3604, error 13828, ERROR_IPSEC_IKE_NO_PUBLIC_KEY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13828"]},{"id":2389,"title":"ERROR_IPSEC_IKE_PROCESS_ERR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13829","0x3605","error 13829","ERROR_IPSEC_IKE_PROCESS_ERR","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","ipsec","ike","process","err","processing","payload"],"errorCode":"13829","eventId":"","severity":"Low","summary":"Error processing error payload.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 13829; use the surrounding log entries to confirm it.","resolution":"1. Record where 13829 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_PROCESS_ERR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13829 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Error processing error payload.\n\nLookup forms: 13829, 0x3605, error 13829, ERROR_IPSEC_IKE_PROCESS_ERR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13829"]},{"id":2390,"title":"ERROR_IPSEC_IKE_PROCESS_ERR_SA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13830","0x3606","error 13830","ERROR_IPSEC_IKE_PROCESS_ERR_SA","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","ipsec","ike","process","err","processing","payload"],"errorCode":"13830","eventId":"","severity":"Low","summary":"Error processing SA payload.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 13830; use the surrounding log entries to confirm it.","resolution":"1. Record where 13830 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_PROCESS_ERR_SA.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13830 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Error processing SA payload.\n\nLookup forms: 13830, 0x3606, error 13830, ERROR_IPSEC_IKE_PROCESS_ERR_SA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13830"]},{"id":2391,"title":"ERROR_IPSEC_IKE_PROCESS_ERR_PROP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13831","0x3607","error 13831","ERROR_IPSEC_IKE_PROCESS_ERR_PROP","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","ipsec","ike","process","err","prop","processing","proposal","payload"],"errorCode":"13831","eventId":"","severity":"Low","summary":"Error processing Proposal payload.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 13831; use the surrounding log entries to confirm it.","resolution":"1. Record where 13831 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_PROCESS_ERR_PROP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13831 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Error processing Proposal payload.\n\nLookup forms: 13831, 0x3607, error 13831, ERROR_IPSEC_IKE_PROCESS_ERR_PROP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13831"]},{"id":2392,"title":"ERROR_IPSEC_IKE_PROCESS_ERR_TRANS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13832","0x3608","error 13832","ERROR_IPSEC_IKE_PROCESS_ERR_TRANS","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","ipsec","ike","process","err","trans","processing","transform","payload"],"errorCode":"13832","eventId":"","severity":"Low","summary":"Error processing Transform payload.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 13832; use the surrounding log entries to confirm it.","resolution":"1. Record where 13832 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_PROCESS_ERR_TRANS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13832 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Error processing Transform payload.\n\nLookup forms: 13832, 0x3608, error 13832, ERROR_IPSEC_IKE_PROCESS_ERR_TRANS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13832"]},{"id":2393,"title":"ERROR_IPSEC_IKE_PROCESS_ERR_KE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13833","0x3609","error 13833","ERROR_IPSEC_IKE_PROCESS_ERR_KE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","ipsec","ike","process","err","processing","payload"],"errorCode":"13833","eventId":"","severity":"Low","summary":"Error processing KE payload.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 13833; use the surrounding log entries to confirm it.","resolution":"1. Record where 13833 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_PROCESS_ERR_KE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13833 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Error processing KE payload.\n\nLookup forms: 13833, 0x3609, error 13833, ERROR_IPSEC_IKE_PROCESS_ERR_KE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13833"]},{"id":2394,"title":"ERROR_IPSEC_IKE_PROCESS_ERR_ID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13834","0x360A","error 13834","ERROR_IPSEC_IKE_PROCESS_ERR_ID","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","ipsec","ike","process","err","processing","payload"],"errorCode":"13834","eventId":"","severity":"Low","summary":"Error processing ID payload.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 13834; use the surrounding log entries to confirm it.","resolution":"1. Record where 13834 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_PROCESS_ERR_ID.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13834 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Error processing ID payload.\n\nLookup forms: 13834, 0x360A, error 13834, ERROR_IPSEC_IKE_PROCESS_ERR_ID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13834"]},{"id":2395,"title":"ERROR_IPSEC_IKE_PROCESS_ERR_CERT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13835","0x360B","error 13835","ERROR_IPSEC_IKE_PROCESS_ERR_CERT","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","ipsec","ike","process","err","cert","processing","payload"],"errorCode":"13835","eventId":"","severity":"Low","summary":"Error processing Cert payload.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 13835; use the surrounding log entries to confirm it.","resolution":"1. Record where 13835 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_PROCESS_ERR_CERT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13835 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Error processing Cert payload.\n\nLookup forms: 13835, 0x360B, error 13835, ERROR_IPSEC_IKE_PROCESS_ERR_CERT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13835"]},{"id":2396,"title":"ERROR_IPSEC_IKE_PROCESS_ERR_CERT_REQ","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13836","0x360C","error 13836","ERROR_IPSEC_IKE_PROCESS_ERR_CERT_REQ","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","ipsec","ike","process","err","cert","req","processing","certificate","request","payload"],"errorCode":"13836","eventId":"","severity":"Low","summary":"Error processing Certificate Request payload.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 13836; use the surrounding log entries to confirm it.","resolution":"1. Record where 13836 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_PROCESS_ERR_CERT_REQ.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13836 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Error processing Certificate Request payload.\n\nLookup forms: 13836, 0x360C, error 13836, ERROR_IPSEC_IKE_PROCESS_ERR_CERT_REQ. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13836"]},{"id":2397,"title":"ERROR_IPSEC_IKE_PROCESS_ERR_HASH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13837","0x360D","error 13837","ERROR_IPSEC_IKE_PROCESS_ERR_HASH","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","ipsec","ike","process","err","hash","processing","payload"],"errorCode":"13837","eventId":"","severity":"Low","summary":"Error processing Hash payload.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 13837; use the surrounding log entries to confirm it.","resolution":"1. Record where 13837 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_PROCESS_ERR_HASH.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13837 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Error processing Hash payload.\n\nLookup forms: 13837, 0x360D, error 13837, ERROR_IPSEC_IKE_PROCESS_ERR_HASH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13837"]},{"id":2398,"title":"ERROR_IPSEC_IKE_PROCESS_ERR_SIG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13838","0x360E","error 13838","ERROR_IPSEC_IKE_PROCESS_ERR_SIG","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","ipsec","ike","process","err","sig","processing","signature","payload"],"errorCode":"13838","eventId":"","severity":"Low","summary":"Error processing Signature payload.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 13838; use the surrounding log entries to confirm it.","resolution":"1. Record where 13838 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_PROCESS_ERR_SIG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13838 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Error processing Signature payload.\n\nLookup forms: 13838, 0x360E, error 13838, ERROR_IPSEC_IKE_PROCESS_ERR_SIG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13838"]},{"id":2399,"title":"ERROR_IPSEC_IKE_PROCESS_ERR_NONCE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13839","0x360F","error 13839","ERROR_IPSEC_IKE_PROCESS_ERR_NONCE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","ipsec","ike","process","err","nonce","processing","payload"],"errorCode":"13839","eventId":"","severity":"Low","summary":"Error processing Nonce payload.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 13839; use the surrounding log entries to confirm it.","resolution":"1. Record where 13839 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_PROCESS_ERR_NONCE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13839 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Error processing Nonce payload.\n\nLookup forms: 13839, 0x360F, error 13839, ERROR_IPSEC_IKE_PROCESS_ERR_NONCE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13839"]},{"id":2400,"title":"ERROR_IPSEC_IKE_PROCESS_ERR_NOTIFY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13840","0x3610","error 13840","ERROR_IPSEC_IKE_PROCESS_ERR_NOTIFY","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","ipsec","ike","process","err","notify","processing","payload"],"errorCode":"13840","eventId":"","severity":"Low","summary":"Error processing Notify payload.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 13840; use the surrounding log entries to confirm it.","resolution":"1. Record where 13840 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_PROCESS_ERR_NOTIFY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13840 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Error processing Notify payload.\n\nLookup forms: 13840, 0x3610, error 13840, ERROR_IPSEC_IKE_PROCESS_ERR_NOTIFY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13840"]},{"id":2401,"title":"ERROR_IPSEC_IKE_PROCESS_ERR_DELETE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13841","0x3611","error 13841","ERROR_IPSEC_IKE_PROCESS_ERR_DELETE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","ipsec","ike","process","err","delete","processing","payload"],"errorCode":"13841","eventId":"","severity":"Low","summary":"Error processing Delete Payload.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 13841; use the surrounding log entries to confirm it.","resolution":"1. Record where 13841 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_PROCESS_ERR_DELETE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13841 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Error processing Delete Payload.\n\nLookup forms: 13841, 0x3611, error 13841, ERROR_IPSEC_IKE_PROCESS_ERR_DELETE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13841"]},{"id":2402,"title":"ERROR_IPSEC_IKE_PROCESS_ERR_VENDOR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13842","0x3612","error 13842","ERROR_IPSEC_IKE_PROCESS_ERR_VENDOR","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","ipsec","ike","process","err","vendor","processing","vendorid","payload"],"errorCode":"13842","eventId":"","severity":"Low","summary":"Error processing VendorId payload.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 13842; use the surrounding log entries to confirm it.","resolution":"1. Record where 13842 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_PROCESS_ERR_VENDOR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13842 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Error processing VendorId payload.\n\nLookup forms: 13842, 0x3612, error 13842, ERROR_IPSEC_IKE_PROCESS_ERR_VENDOR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13842"]},{"id":2403,"title":"ERROR_IPSEC_IKE_INVALID_PAYLOAD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13843","0x3613","error 13843","ERROR_IPSEC_IKE_INVALID_PAYLOAD","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","invalid","payload","received"],"errorCode":"13843","eventId":"","severity":"Medium","summary":"Invalid payload received.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13843; use the surrounding log entries to confirm it.","resolution":"1. Record where 13843 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_INVALID_PAYLOAD.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13843 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid payload received.\n\nLookup forms: 13843, 0x3613, error 13843, ERROR_IPSEC_IKE_INVALID_PAYLOAD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13843"]},{"id":2404,"title":"ERROR_IPSEC_IKE_LOAD_SOFT_SA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13844","0x3614","error 13844","ERROR_IPSEC_IKE_LOAD_SOFT_SA","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","load","soft","loaded"],"errorCode":"13844","eventId":"","severity":"Low","summary":"Soft SA loaded.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13844; use the surrounding log entries to confirm it.","resolution":"1. Record where 13844 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_LOAD_SOFT_SA.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13844 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Soft SA loaded.\n\nLookup forms: 13844, 0x3614, error 13844, ERROR_IPSEC_IKE_LOAD_SOFT_SA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13844"]},{"id":2405,"title":"ERROR_IPSEC_IKE_SOFT_SA_TORN_DOWN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13845","0x3615","error 13845","ERROR_IPSEC_IKE_SOFT_SA_TORN_DOWN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","soft","torn","down"],"errorCode":"13845","eventId":"","severity":"Low","summary":"Soft SA torn down.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13845; use the surrounding log entries to confirm it.","resolution":"1. Record where 13845 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_SOFT_SA_TORN_DOWN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13845 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Soft SA torn down.\n\nLookup forms: 13845, 0x3615, error 13845, ERROR_IPSEC_IKE_SOFT_SA_TORN_DOWN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13845"]},{"id":2406,"title":"ERROR_IPSEC_IKE_INVALID_COOKIE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13846","0x3616","error 13846","ERROR_IPSEC_IKE_INVALID_COOKIE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","invalid","cookie","received"],"errorCode":"13846","eventId":"","severity":"Medium","summary":"Invalid cookie received.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13846; use the surrounding log entries to confirm it.","resolution":"1. Record where 13846 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_INVALID_COOKIE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13846 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid cookie received.\n\nLookup forms: 13846, 0x3616, error 13846, ERROR_IPSEC_IKE_INVALID_COOKIE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Invalid cookie received..","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13846"]},{"id":2407,"title":"ERROR_IPSEC_IKE_NO_PEER_CERT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13847","0x3617","error 13847","ERROR_IPSEC_IKE_NO_PEER_CERT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","peer","cert","failed","send","valid","machine","certificate"],"errorCode":"13847","eventId":"","severity":"High","summary":"Peer failed to send valid machine certificate.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13847; use the surrounding log entries to confirm it.","resolution":"1. Record where 13847 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_NO_PEER_CERT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13847 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Peer failed to send valid machine certificate.\n\nLookup forms: 13847, 0x3617, error 13847, ERROR_IPSEC_IKE_NO_PEER_CERT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13847"]},{"id":2408,"title":"ERROR_IPSEC_IKE_PEER_CRL_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13848","0x3618","error 13848","ERROR_IPSEC_IKE_PEER_CRL_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","peer","crl","failed","certification","revocation","check","certificate"],"errorCode":"13848","eventId":"","severity":"High","summary":"Certification Revocation check of peer's certificate failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13848; use the surrounding log entries to confirm it.","resolution":"1. Record where 13848 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_PEER_CRL_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13848 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Certification Revocation check of peer's certificate failed.\n\nLookup forms: 13848, 0x3618, error 13848, ERROR_IPSEC_IKE_PEER_CRL_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13848"]},{"id":2409,"title":"ERROR_IPSEC_IKE_POLICY_CHANGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13849","0x3619","error 13849","ERROR_IPSEC_IKE_POLICY_CHANGE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","policy","change","new","invalidated","sas","formed","with","old"],"errorCode":"13849","eventId":"","severity":"Medium","summary":"New policy invalidated SAs formed with old policy.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13849; use the surrounding log entries to confirm it.","resolution":"1. Record where 13849 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_POLICY_CHANGE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13849 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: New policy invalidated SAs formed with old policy.\n\nLookup forms: 13849, 0x3619, error 13849, ERROR_IPSEC_IKE_POLICY_CHANGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13849"]},{"id":2410,"title":"ERROR_IPSEC_IKE_NO_MM_POLICY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13850","0x361A","error 13850","ERROR_IPSEC_IKE_NO_MM_POLICY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","policy","there","available","main","mode"],"errorCode":"13850","eventId":"","severity":"Low","summary":"There is no available Main Mode IKE policy.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13850; use the surrounding log entries to confirm it.","resolution":"1. Record where 13850 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_NO_MM_POLICY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13850 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There is no available Main Mode IKE policy.\n\nLookup forms: 13850, 0x361A, error 13850, ERROR_IPSEC_IKE_NO_MM_POLICY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13850"]},{"id":2411,"title":"ERROR_IPSEC_IKE_NOTCBPRIV","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13851","0x361B","error 13851","ERROR_IPSEC_IKE_NOTCBPRIV","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ipsec","ike","notcbpriv","failed","enabled","tcb","privilege"],"errorCode":"13851","eventId":"","severity":"High","summary":"Failed to enabled TCB privilege.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 13851; use the surrounding log entries to confirm it.","resolution":"1. Record where 13851 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_NOTCBPRIV.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13851 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Failed to enabled TCB privilege.\n\nLookup forms: 13851, 0x361B, error 13851, ERROR_IPSEC_IKE_NOTCBPRIV. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13851"]},{"id":2412,"title":"ERROR_IPSEC_IKE_SECLOADFAIL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13852","0x361C","error 13852","ERROR_IPSEC_IKE_SECLOADFAIL","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ipsec","ike","secloadfail","failed","load","security","dll"],"errorCode":"13852","eventId":"","severity":"High","summary":"Failed to load SECURITY.DLL.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 13852; use the surrounding log entries to confirm it.","resolution":"1. Record where 13852 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_SECLOADFAIL.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13852 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Failed to load SECURITY.DLL.\n\nLookup forms: 13852, 0x361C, error 13852, ERROR_IPSEC_IKE_SECLOADFAIL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13852"]},{"id":2413,"title":"ERROR_IPSEC_IKE_FAILSSPINIT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13853","0x361D","error 13853","ERROR_IPSEC_IKE_FAILSSPINIT","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ipsec","ike","failsspinit","failed","obtain","security","function","table","dispatch","address","from","sspi"],"errorCode":"13853","eventId":"","severity":"High","summary":"Failed to obtain security function table dispatch address from SSPI.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 13853; use the surrounding log entries to confirm it.","resolution":"1. Record where 13853 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_FAILSSPINIT.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13853 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Failed to obtain security function table dispatch address from SSPI.\n\nLookup forms: 13853, 0x361D, error 13853, ERROR_IPSEC_IKE_FAILSSPINIT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13853"]},{"id":2414,"title":"ERROR_IPSEC_IKE_FAILQUERYSSP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13854","0x361E","error 13854","ERROR_IPSEC_IKE_FAILQUERYSSP","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","ipsec","ike","failqueryssp","failed","query","kerberos","package","obtain","max","token","size"],"errorCode":"13854","eventId":"","severity":"High","summary":"Failed to query Kerberos package to obtain max token size.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 13854; use the surrounding log entries to confirm it.","resolution":"1. Record where 13854 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_FAILQUERYSSP.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13854 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Failed to query Kerberos package to obtain max token size.\n\nLookup forms: 13854, 0x361E, error 13854, ERROR_IPSEC_IKE_FAILQUERYSSP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13854"]},{"id":2415,"title":"ERROR_IPSEC_IKE_SRVACQFAIL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13855","0x361F","error 13855","ERROR_IPSEC_IKE_SRVACQFAIL","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ipsec","ike","srvacqfail","failed","obtain","kerberos","server","credentials","for","isakmp","service","authentication","will","not","function","the","most","likely","reason","this","lack","domain","membership","normal"],"errorCode":"13855","eventId":"","severity":"High","summary":"Failed to obtain Kerberos server credentials for ISAKMP/ERROR_IPSEC_IKE service. Kerberos authentication will not function. The most likely reason for this is lack of domain membership. This is normal if your computer is a member of a workgroup.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 13855; use the surrounding log entries to confirm it.","resolution":"1. Record where 13855 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_SRVACQFAIL.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13855 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Failed to obtain Kerberos server credentials for ISAKMP/ERROR_IPSEC_IKE service. Kerberos authentication will not function. The most likely reason for this is lack of domain membership. This is normal if your computer is a member of a workgroup.\n\nLookup forms: 13855, 0x361F, error 13855, ERROR_IPSEC_IKE_SRVACQFAIL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13855"]},{"id":2416,"title":"ERROR_IPSEC_IKE_SRVQUERYCRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13856","0x3620","error 13856","ERROR_IPSEC_IKE_SRVQUERYCRED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","ipsec","ike","srvquerycred","failed","determine","sspi","principal","name","for","isakmp","service","querycredentialsattributes"],"errorCode":"13856","eventId":"","severity":"High","summary":"Failed to determine SSPI principal name for ISAKMP/ERROR_IPSEC_IKE service (QueryCredentialsAttributes).","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 13856; use the surrounding log entries to confirm it.","resolution":"1. Record where 13856 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_SRVQUERYCRED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13856 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Failed to determine SSPI principal name for ISAKMP/ERROR_IPSEC_IKE service (QueryCredentialsAttributes).\n\nLookup forms: 13856, 0x3620, error 13856, ERROR_IPSEC_IKE_SRVQUERYCRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13856"]},{"id":2417,"title":"ERROR_IPSEC_IKE_GETSPIFAIL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13857","0x3621","error 13857","ERROR_IPSEC_IKE_GETSPIFAIL","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","ipsec","ike","getspifail","failed","obtain","new","spi","for","the","inbound","from","driver","most","common","cause","this","that","does","not","have","correct","filter","check","your"],"errorCode":"13857","eventId":"","severity":"High","summary":"Failed to obtain new SPI for the inbound SA from IPsec driver. The most common cause for this is that the driver does not have the correct filter. Check your policy to verify the filters.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 13857; use the surrounding log entries to confirm it.","resolution":"1. Record where 13857 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_GETSPIFAIL.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13857 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Failed to obtain new SPI for the inbound SA from IPsec driver. The most common cause for this is that the driver does not have the correct filter. Check your policy to verify the filters.\n\nLookup forms: 13857, 0x3621, error 13857, ERROR_IPSEC_IKE_GETSPIFAIL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Failed to obtain new SPI for the inbound SA from Ipsec driver. The most common cause for this is that the driver does not have the correct filter. Check your policy to verify the filters.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13857"]},{"id":2418,"title":"ERROR_IPSEC_IKE_INVALID_FILTER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13858","0x3622","error 13858","ERROR_IPSEC_IKE_INVALID_FILTER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","invalid","filter","given"],"errorCode":"13858","eventId":"","severity":"Medium","summary":"Given filter is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13858; use the surrounding log entries to confirm it.","resolution":"1. Record where 13858 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_INVALID_FILTER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13858 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Given filter is invalid.\n\nLookup forms: 13858, 0x3622, error 13858, ERROR_IPSEC_IKE_INVALID_FILTER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13858"]},{"id":2419,"title":"ERROR_IPSEC_IKE_OUT_OF_MEMORY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13859","0x3623","error 13859","ERROR_IPSEC_IKE_OUT_OF_MEMORY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","ipsec","ike","out","memory","allocation","failed"],"errorCode":"13859","eventId":"","severity":"High","summary":"Memory allocation failed.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 13859; use the surrounding log entries to confirm it.","resolution":"1. Record where 13859 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_OUT_OF_MEMORY.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13859 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Memory allocation failed.\n\nLookup forms: 13859, 0x3623, error 13859, ERROR_IPSEC_IKE_OUT_OF_MEMORY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13859"]},{"id":2420,"title":"ERROR_IPSEC_IKE_ADD_UPDATE_KEY_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13860","0x3624","error 13860","ERROR_IPSEC_IKE_ADD_UPDATE_KEY_FAILED","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ipsec","ike","add","update","key","failed","security","association","driver","the","most","common","cause","for","this","negotiation","took","too","long","complete","problem","persists","reduce","load"],"errorCode":"13860","eventId":"","severity":"High","summary":"Failed to add Security Association to IPsec Driver. The most common cause for this is if the IKE negotiation took too long to complete. If the problem persists, reduce the load on the faulting machine.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 13860; use the surrounding log entries to confirm it.","resolution":"1. Record where 13860 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Confirm the user or service identity has the required permissions and is not locked or disabled.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_ADD_UPDATE_KEY_FAILED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Confirm the user or service identity has the required permissions and is not locked or disabled.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13860 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Failed to add Security Association to IPsec Driver. The most common cause for this is if the IKE negotiation took too long to complete. If the problem persists, reduce the load on the faulting machine.\n\nLookup forms: 13860, 0x3624, error 13860, ERROR_IPSEC_IKE_ADD_UPDATE_KEY_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Failed to add Security Association to IPSec Driver. The most common cause for this is if the IKE negotiation took too long to complete. If the problem persists, reduce the load on the faulting machine.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13860"]},{"id":2421,"title":"ERROR_IPSEC_IKE_INVALID_POLICY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13861","0x3625","error 13861","ERROR_IPSEC_IKE_INVALID_POLICY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","invalid","policy"],"errorCode":"13861","eventId":"","severity":"Medium","summary":"Invalid policy.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13861; use the surrounding log entries to confirm it.","resolution":"1. Record where 13861 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_INVALID_POLICY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13861 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid policy.\n\nLookup forms: 13861, 0x3625, error 13861, ERROR_IPSEC_IKE_INVALID_POLICY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13861"]},{"id":2422,"title":"ERROR_IPSEC_IKE_UNKNOWN_DOI","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13862","0x3626","error 13862","ERROR_IPSEC_IKE_UNKNOWN_DOI","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","unknown","doi","invalid"],"errorCode":"13862","eventId":"","severity":"Medium","summary":"Invalid DOI.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13862; use the surrounding log entries to confirm it.","resolution":"1. Record where 13862 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_UNKNOWN_DOI.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13862 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid DOI.\n\nLookup forms: 13862, 0x3626, error 13862, ERROR_IPSEC_IKE_UNKNOWN_DOI. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13862"]},{"id":2423,"title":"ERROR_IPSEC_IKE_INVALID_SITUATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13863","0x3627","error 13863","ERROR_IPSEC_IKE_INVALID_SITUATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","invalid","situation"],"errorCode":"13863","eventId":"","severity":"Medium","summary":"Invalid situation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13863; use the surrounding log entries to confirm it.","resolution":"1. Record where 13863 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_INVALID_SITUATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13863 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid situation.\n\nLookup forms: 13863, 0x3627, error 13863, ERROR_IPSEC_IKE_INVALID_SITUATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13863"]},{"id":2424,"title":"ERROR_IPSEC_IKE_DH_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13864","0x3628","error 13864","ERROR_IPSEC_IKE_DH_FAILURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","failure","diffie","hellman"],"errorCode":"13864","eventId":"","severity":"High","summary":"Diffie-Hellman failure.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13864; use the surrounding log entries to confirm it.","resolution":"1. Record where 13864 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_DH_FAILURE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13864 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Diffie-Hellman failure.\n\nLookup forms: 13864, 0x3628, error 13864, ERROR_IPSEC_IKE_DH_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13864"]},{"id":2425,"title":"ERROR_IPSEC_IKE_INVALID_GROUP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13865","0x3629","error 13865","ERROR_IPSEC_IKE_INVALID_GROUP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","invalid","group","diffie","hellman"],"errorCode":"13865","eventId":"","severity":"Medium","summary":"Invalid Diffie-Hellman group.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13865; use the surrounding log entries to confirm it.","resolution":"1. Record where 13865 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_INVALID_GROUP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13865 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid Diffie-Hellman group.\n\nLookup forms: 13865, 0x3629, error 13865, ERROR_IPSEC_IKE_INVALID_GROUP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13865"]},{"id":2426,"title":"ERROR_IPSEC_IKE_ENCRYPT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13866","0x362A","error 13866","ERROR_IPSEC_IKE_ENCRYPT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","encrypt","encrypting","payload"],"errorCode":"13866","eventId":"","severity":"Low","summary":"Error encrypting payload.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13866; use the surrounding log entries to confirm it.","resolution":"1. Record where 13866 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_ENCRYPT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13866 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Error encrypting payload.\n\nLookup forms: 13866, 0x362A, error 13866, ERROR_IPSEC_IKE_ENCRYPT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13866"]},{"id":2427,"title":"ERROR_IPSEC_IKE_DECRYPT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13867","0x362B","error 13867","ERROR_IPSEC_IKE_DECRYPT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","decrypt","decrypting","payload"],"errorCode":"13867","eventId":"","severity":"Low","summary":"Error decrypting payload.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13867; use the surrounding log entries to confirm it.","resolution":"1. Record where 13867 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_DECRYPT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13867 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Error decrypting payload.\n\nLookup forms: 13867, 0x362B, error 13867, ERROR_IPSEC_IKE_DECRYPT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13867"]},{"id":2428,"title":"ERROR_IPSEC_IKE_POLICY_MATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13868","0x362C","error 13868","ERROR_IPSEC_IKE_POLICY_MATCH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","policy","match"],"errorCode":"13868","eventId":"","severity":"Low","summary":"Policy match error.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13868; use the surrounding log entries to confirm it.","resolution":"1. Record where 13868 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_POLICY_MATCH.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13868 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Policy match error.\n\nLookup forms: 13868, 0x362C, error 13868, ERROR_IPSEC_IKE_POLICY_MATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13868"]},{"id":2429,"title":"ERROR_IPSEC_IKE_UNSUPPORTED_ID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13869","0x362D","error 13869","ERROR_IPSEC_IKE_UNSUPPORTED_ID","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","unsupported"],"errorCode":"13869","eventId":"","severity":"Low","summary":"Unsupported ID.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13869; use the surrounding log entries to confirm it.","resolution":"1. Record where 13869 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_UNSUPPORTED_ID.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13869 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unsupported ID.\n\nLookup forms: 13869, 0x362D, error 13869, ERROR_IPSEC_IKE_UNSUPPORTED_ID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13869"]},{"id":2430,"title":"ERROR_IPSEC_IKE_INVALID_HASH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13870","0x362E","error 13870","ERROR_IPSEC_IKE_INVALID_HASH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","invalid","hash","verification","failed"],"errorCode":"13870","eventId":"","severity":"High","summary":"Hash verification failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13870; use the surrounding log entries to confirm it.","resolution":"1. Record where 13870 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_INVALID_HASH.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13870 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Hash verification failed.\n\nLookup forms: 13870, 0x362E, error 13870, ERROR_IPSEC_IKE_INVALID_HASH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13870"]},{"id":2431,"title":"ERROR_IPSEC_IKE_INVALID_HASH_ALG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13871","0x362F","error 13871","ERROR_IPSEC_IKE_INVALID_HASH_ALG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","invalid","hash","alg","algorithm"],"errorCode":"13871","eventId":"","severity":"Medium","summary":"Invalid hash algorithm.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13871; use the surrounding log entries to confirm it.","resolution":"1. Record where 13871 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_INVALID_HASH_ALG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13871 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid hash algorithm.\n\nLookup forms: 13871, 0x362F, error 13871, ERROR_IPSEC_IKE_INVALID_HASH_ALG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13871"]},{"id":2432,"title":"ERROR_IPSEC_IKE_INVALID_HASH_SIZE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13872","0x3630","error 13872","ERROR_IPSEC_IKE_INVALID_HASH_SIZE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","invalid","hash","size"],"errorCode":"13872","eventId":"","severity":"Medium","summary":"Invalid hash size.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13872; use the surrounding log entries to confirm it.","resolution":"1. Record where 13872 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_INVALID_HASH_SIZE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13872 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid hash size.\n\nLookup forms: 13872, 0x3630, error 13872, ERROR_IPSEC_IKE_INVALID_HASH_SIZE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13872"]},{"id":2433,"title":"ERROR_IPSEC_IKE_INVALID_ENCRYPT_ALG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13873","0x3631","error 13873","ERROR_IPSEC_IKE_INVALID_ENCRYPT_ALG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","invalid","encrypt","alg","encryption","algorithm"],"errorCode":"13873","eventId":"","severity":"Medium","summary":"Invalid encryption algorithm.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13873; use the surrounding log entries to confirm it.","resolution":"1. Record where 13873 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_INVALID_ENCRYPT_ALG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13873 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid encryption algorithm.\n\nLookup forms: 13873, 0x3631, error 13873, ERROR_IPSEC_IKE_INVALID_ENCRYPT_ALG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13873"]},{"id":2434,"title":"ERROR_IPSEC_IKE_INVALID_AUTH_ALG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13874","0x3632","error 13874","ERROR_IPSEC_IKE_INVALID_AUTH_ALG","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ipsec","ike","invalid","auth","alg","authentication","algorithm"],"errorCode":"13874","eventId":"","severity":"High","summary":"Invalid authentication algorithm.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 13874; use the surrounding log entries to confirm it.","resolution":"1. Record where 13874 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_INVALID_AUTH_ALG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13874 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid authentication algorithm.\n\nLookup forms: 13874, 0x3632, error 13874, ERROR_IPSEC_IKE_INVALID_AUTH_ALG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13874"]},{"id":2435,"title":"ERROR_IPSEC_IKE_INVALID_SIG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13875","0x3633","error 13875","ERROR_IPSEC_IKE_INVALID_SIG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","invalid","sig","certificate","signature"],"errorCode":"13875","eventId":"","severity":"Medium","summary":"Invalid certificate signature.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13875; use the surrounding log entries to confirm it.","resolution":"1. Record where 13875 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_INVALID_SIG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13875 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid certificate signature.\n\nLookup forms: 13875, 0x3633, error 13875, ERROR_IPSEC_IKE_INVALID_SIG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13875"]},{"id":2436,"title":"ERROR_IPSEC_IKE_LOAD_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13876","0x3634","error 13876","ERROR_IPSEC_IKE_LOAD_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","load","failed"],"errorCode":"13876","eventId":"","severity":"High","summary":"Load failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13876; use the surrounding log entries to confirm it.","resolution":"1. Record where 13876 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_LOAD_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13876 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Load failed.\n\nLookup forms: 13876, 0x3634, error 13876, ERROR_IPSEC_IKE_LOAD_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13876"]},{"id":2437,"title":"ERROR_IPSEC_IKE_RPC_DELETE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13877","0x3635","error 13877","ERROR_IPSEC_IKE_RPC_DELETE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","rpc","delete","deleted","via","call"],"errorCode":"13877","eventId":"","severity":"Low","summary":"Deleted via RPC call.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13877; use the surrounding log entries to confirm it.","resolution":"1. Record where 13877 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_RPC_DELETE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13877 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Deleted via RPC call.\n\nLookup forms: 13877, 0x3635, error 13877, ERROR_IPSEC_IKE_RPC_DELETE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13877"]},{"id":2438,"title":"ERROR_IPSEC_IKE_BENIGN_REINIT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13878","0x3636","error 13878","ERROR_IPSEC_IKE_BENIGN_REINIT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","benign","reinit","temporary","state","created","perform","reinitialization","this","not","real","failure"],"errorCode":"13878","eventId":"","severity":"High","summary":"Temporary state created to perform reinitialization. This is not a real failure.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13878; use the surrounding log entries to confirm it.","resolution":"1. Record where 13878 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_BENIGN_REINIT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13878 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Temporary state created to perform reinitialization. This is not a real failure.\n\nLookup forms: 13878, 0x3636, error 13878, ERROR_IPSEC_IKE_BENIGN_REINIT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Temporary state created to perform reinit. This is not a real failure.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13878"]},{"id":2439,"title":"ERROR_IPSEC_IKE_INVALID_RESPONDER_LIFETIME_NOTIFY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13879","0x3637","error 13879","ERROR_IPSEC_IKE_INVALID_RESPONDER_LIFETIME_NOTIFY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","invalid","responder","lifetime","notify","the","value","received","below","windows","2000","configured","minimum","please","fix","policy","peer","machine"],"errorCode":"13879","eventId":"","severity":"Low","summary":"The lifetime value received in the Responder Lifetime Notify is below the Windows 2000 configured minimum value. Please fix the policy on the peer machine.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13879; use the surrounding log entries to confirm it.","resolution":"1. Record where 13879 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_INVALID_RESPONDER_LIFETIME_NOTIFY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13879 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The lifetime value received in the Responder Lifetime Notify is below the Windows 2000 configured minimum value. Please fix the policy on the peer machine.\n\nLookup forms: 13879, 0x3637, error 13879, ERROR_IPSEC_IKE_INVALID_RESPONDER_LIFETIME_NOTIFY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13879"]},{"id":2440,"title":"ERROR_IPSEC_IKE_INVALID_MAJOR_VERSION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13880","0x3638","error 13880","ERROR_IPSEC_IKE_INVALID_MAJOR_VERSION","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","ipsec","ike","invalid","major","version","the","recipient","cannot","handle","specified","header"],"errorCode":"13880","eventId":"","severity":"Medium","summary":"The recipient cannot handle version of IKE specified in the header.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 13880; use the surrounding log entries to confirm it.","resolution":"1. Record where 13880 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_INVALID_MAJOR_VERSION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13880 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The recipient cannot handle version of IKE specified in the header.\n\nLookup forms: 13880, 0x3638, error 13880, ERROR_IPSEC_IKE_INVALID_MAJOR_VERSION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13880"]},{"id":2441,"title":"ERROR_IPSEC_IKE_INVALID_CERT_KEYLEN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13881","0x3639","error 13881","ERROR_IPSEC_IKE_INVALID_CERT_KEYLEN","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ipsec","ike","invalid","cert","keylen","key","length","certificate","too","small","for","configured","security","requirements"],"errorCode":"13881","eventId":"","severity":"Low","summary":"Key length in certificate is too small for configured security requirements.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 13881; use the surrounding log entries to confirm it.","resolution":"1. Record where 13881 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_INVALID_CERT_KEYLEN.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13881 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Key length in certificate is too small for configured security requirements.\n\nLookup forms: 13881, 0x3639, error 13881, ERROR_IPSEC_IKE_INVALID_CERT_KEYLEN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13881"]},{"id":2442,"title":"ERROR_IPSEC_IKE_MM_LIMIT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13882","0x363A","error 13882","ERROR_IPSEC_IKE_MM_LIMIT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","limit","max","number","established","sas","peer","exceeded"],"errorCode":"13882","eventId":"","severity":"Low","summary":"Max number of established MM SAs to peer exceeded.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13882; use the surrounding log entries to confirm it.","resolution":"1. Record where 13882 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_MM_LIMIT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13882 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Max number of established MM SAs to peer exceeded.\n\nLookup forms: 13882, 0x363A, error 13882, ERROR_IPSEC_IKE_MM_LIMIT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13882"]},{"id":2443,"title":"ERROR_IPSEC_IKE_NEGOTIATION_DISABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13883","0x363B","error 13883","ERROR_IPSEC_IKE_NEGOTIATION_DISABLED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","negotiation","disabled","received","policy","that","disables"],"errorCode":"13883","eventId":"","severity":"Low","summary":"IKE received a policy that disables negotiation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13883; use the surrounding log entries to confirm it.","resolution":"1. Record where 13883 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_NEGOTIATION_DISABLED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13883 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: IKE received a policy that disables negotiation.\n\nLookup forms: 13883, 0x363B, error 13883, ERROR_IPSEC_IKE_NEGOTIATION_DISABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13883"]},{"id":2444,"title":"ERROR_IPSEC_IKE_QM_LIMIT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13884","0x363C","error 13884","ERROR_IPSEC_IKE_QM_LIMIT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","limit","reached","maximum","quick","mode","for","the","main","new","will","started"],"errorCode":"13884","eventId":"","severity":"Low","summary":"Reached maximum quick mode limit for the main mode. New main mode will be started.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13884; use the surrounding log entries to confirm it.","resolution":"1. Record where 13884 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_QM_LIMIT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13884 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Reached maximum quick mode limit for the main mode. New main mode will be started.\n\nLookup forms: 13884, 0x363C, error 13884, ERROR_IPSEC_IKE_QM_LIMIT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): ERROR_IPSEC_IKE_NEG_STATUS_END","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13884"]},{"id":2445,"title":"ERROR_IPSEC_IKE_MM_EXPIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13885","0x363D","error 13885","ERROR_IPSEC_IKE_MM_EXPIRED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","expired","main","mode","lifetime","peer","sent","delete"],"errorCode":"13885","eventId":"","severity":"Low","summary":"Main mode SA lifetime expired or peer sent a main mode delete.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13885; use the surrounding log entries to confirm it.","resolution":"1. Record where 13885 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_MM_EXPIRED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13885 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Main mode SA lifetime expired or peer sent a main mode delete.\n\nLookup forms: 13885, 0x363D, error 13885, ERROR_IPSEC_IKE_MM_EXPIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13885"]},{"id":2446,"title":"ERROR_IPSEC_IKE_PEER_MM_ASSUMED_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13886","0x363E","error 13886","ERROR_IPSEC_IKE_PEER_MM_ASSUMED_INVALID","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","peer","assumed","invalid","main","mode","because","stopped","responding"],"errorCode":"13886","eventId":"","severity":"Medium","summary":"Main mode SA assumed to be invalid because peer stopped responding.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13886; use the surrounding log entries to confirm it.","resolution":"1. Record where 13886 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_PEER_MM_ASSUMED_INVALID.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13886 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Main mode SA assumed to be invalid because peer stopped responding.\n\nLookup forms: 13886, 0x363E, error 13886, ERROR_IPSEC_IKE_PEER_MM_ASSUMED_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13886"]},{"id":2447,"title":"ERROR_IPSEC_IKE_CERT_CHAIN_POLICY_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13887","0x363F","error 13887","ERROR_IPSEC_IKE_CERT_CHAIN_POLICY_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","cert","chain","policy","mismatch","certificate","doesn","trusted","root"],"errorCode":"13887","eventId":"","severity":"Low","summary":"Certificate doesn't chain to a trusted root in IPsec policy.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13887; use the surrounding log entries to confirm it.","resolution":"1. Record where 13887 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_CERT_CHAIN_POLICY_MISMATCH.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13887 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Certificate doesn't chain to a trusted root in IPsec policy.\n\nLookup forms: 13887, 0x363F, error 13887, ERROR_IPSEC_IKE_CERT_CHAIN_POLICY_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13887"]},{"id":2448,"title":"ERROR_IPSEC_IKE_UNEXPECTED_MESSAGE_ID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13888","0x3640","error 13888","ERROR_IPSEC_IKE_UNEXPECTED_MESSAGE_ID","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","unexpected","message","received"],"errorCode":"13888","eventId":"","severity":"Low","summary":"Received unexpected message ID.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13888; use the surrounding log entries to confirm it.","resolution":"1. Record where 13888 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_UNEXPECTED_MESSAGE_ID.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13888 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Received unexpected message ID.\n\nLookup forms: 13888, 0x3640, error 13888, ERROR_IPSEC_IKE_UNEXPECTED_MESSAGE_ID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13888"]},{"id":2449,"title":"ERROR_IPSEC_IKE_INVALID_AUTH_PAYLOAD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13889","0x3641","error 13889","ERROR_IPSEC_IKE_INVALID_AUTH_PAYLOAD","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ipsec","ike","invalid","auth","payload","received","authentication","offers"],"errorCode":"13889","eventId":"","severity":"High","summary":"Received invalid authentication offers.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 13889; use the surrounding log entries to confirm it.","resolution":"1. Record where 13889 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_INVALID_AUTH_PAYLOAD.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13889 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Received invalid authentication offers.\n\nLookup forms: 13889, 0x3641, error 13889, ERROR_IPSEC_IKE_INVALID_AUTH_PAYLOAD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13889"]},{"id":2450,"title":"ERROR_IPSEC_IKE_DOS_COOKIE_SENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13890","0x3642","error 13890","ERROR_IPSEC_IKE_DOS_COOKIE_SENT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","dos","cookie","sent","notify","initiator"],"errorCode":"13890","eventId":"","severity":"Low","summary":"Sent DoS cookie notify to initiator.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13890; use the surrounding log entries to confirm it.","resolution":"1. Record where 13890 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_DOS_COOKIE_SENT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13890 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Sent DoS cookie notify to initiator.\n\nLookup forms: 13890, 0x3642, error 13890, ERROR_IPSEC_IKE_DOS_COOKIE_SENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13890"]},{"id":2451,"title":"ERROR_IPSEC_IKE_SHUTTING_DOWN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13891","0x3643","error 13891","ERROR_IPSEC_IKE_SHUTTING_DOWN","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","ipsec","ike","shutting","down","service"],"errorCode":"13891","eventId":"","severity":"Low","summary":"IKE service is shutting down.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 13891; use the surrounding log entries to confirm it.","resolution":"1. Record where 13891 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_SHUTTING_DOWN.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13891 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: IKE service is shutting down.\n\nLookup forms: 13891, 0x3643, error 13891, ERROR_IPSEC_IKE_SHUTTING_DOWN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13891"]},{"id":2452,"title":"ERROR_IPSEC_IKE_CGA_AUTH_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13892","0x3644","error 13892","ERROR_IPSEC_IKE_CGA_AUTH_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","cga","auth","failed","could","not","verify","binding","between","address","and","certificate"],"errorCode":"13892","eventId":"","severity":"Low","summary":"Could not verify binding between CGA address and certificate.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13892; use the surrounding log entries to confirm it.","resolution":"1. Record where 13892 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_CGA_AUTH_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13892 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Could not verify binding between CGA address and certificate.\n\nLookup forms: 13892, 0x3644, error 13892, ERROR_IPSEC_IKE_CGA_AUTH_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13892"]},{"id":2453,"title":"ERROR_IPSEC_IKE_PROCESS_ERR_NATOA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13893","0x3645","error 13893","ERROR_IPSEC_IKE_PROCESS_ERR_NATOA","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","ipsec","ike","process","err","natoa","processing","payload"],"errorCode":"13893","eventId":"","severity":"Low","summary":"Error processing NatOA payload.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 13893; use the surrounding log entries to confirm it.","resolution":"1. Record where 13893 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_PROCESS_ERR_NATOA.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13893 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Error processing NatOA payload.\n\nLookup forms: 13893, 0x3645, error 13893, ERROR_IPSEC_IKE_PROCESS_ERR_NATOA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13893"]},{"id":2454,"title":"ERROR_IPSEC_IKE_INVALID_MM_FOR_QM","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13894","0x3646","error 13894","ERROR_IPSEC_IKE_INVALID_MM_FOR_QM","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","invalid","for","parameters","the","main","mode","are","this","quick"],"errorCode":"13894","eventId":"","severity":"Medium","summary":"Parameters of the main mode are invalid for this quick mode.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13894; use the surrounding log entries to confirm it.","resolution":"1. Record where 13894 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_INVALID_MM_FOR_QM.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13894 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Parameters of the main mode are invalid for this quick mode.\n\nLookup forms: 13894, 0x3646, error 13894, ERROR_IPSEC_IKE_INVALID_MM_FOR_QM. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13894"]},{"id":2455,"title":"ERROR_IPSEC_IKE_QM_EXPIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13895","0x3647","error 13895","ERROR_IPSEC_IKE_QM_EXPIRED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","ipsec","ike","expired","quick","mode","was","driver"],"errorCode":"13895","eventId":"","severity":"Low","summary":"Quick mode SA was expired by IPsec driver.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 13895; use the surrounding log entries to confirm it.","resolution":"1. Record where 13895 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_QM_EXPIRED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13895 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Quick mode SA was expired by IPsec driver.\n\nLookup forms: 13895, 0x3647, error 13895, ERROR_IPSEC_IKE_QM_EXPIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13895"]},{"id":2456,"title":"ERROR_IPSEC_IKE_TOO_MANY_FILTERS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13896","0x3648","error 13896","ERROR_IPSEC_IKE_TOO_MANY_FILTERS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","too","many","filters","dynamically","added","ikeext","were","detected"],"errorCode":"13896","eventId":"","severity":"Low","summary":"Too many dynamically added IKEEXT filters were detected.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13896; use the surrounding log entries to confirm it.","resolution":"1. Record where 13896 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_TOO_MANY_FILTERS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13896 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Too many dynamically added IKEEXT filters were detected.\n\nLookup forms: 13896, 0x3648, error 13896, ERROR_IPSEC_IKE_TOO_MANY_FILTERS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13896"]},{"id":2457,"title":"ERROR_IPSEC_IKE_NEG_STATUS_END","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13897","0x3649","error 13897","ERROR_IPSEC_IKE_NEG_STATUS_END","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","neg","status","end"],"errorCode":"13897","eventId":"","severity":"Low","summary":"ERROR_IPSEC_IKE_NEG_STATUS_END","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13897; use the surrounding log entries to confirm it.","resolution":"1. Record where 13897 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_NEG_STATUS_END.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13897 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: ERROR_IPSEC_IKE_NEG_STATUS_END\n\nLookup forms: 13897, 0x3649, error 13897, ERROR_IPSEC_IKE_NEG_STATUS_END. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13897"]},{"id":2458,"title":"ERROR_IPSEC_IKE_KILL_DUMMY_NAP_TUNNEL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13898","0x364A","error 13898","ERROR_IPSEC_IKE_KILL_DUMMY_NAP_TUNNEL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","kill","dummy","nap","tunnel","reauth","succeeded","and","must","delete","the","ikev2"],"errorCode":"13898","eventId":"","severity":"Low","summary":"NAP reauth succeeded and must delete the dummy NAP IKEv2 tunnel.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13898; use the surrounding log entries to confirm it.","resolution":"1. Record where 13898 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_KILL_DUMMY_NAP_TUNNEL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13898 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: NAP reauth succeeded and must delete the dummy NAP IKEv2 tunnel.\n\nLookup forms: 13898, 0x364A, error 13898, ERROR_IPSEC_IKE_KILL_DUMMY_NAP_TUNNEL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13898"]},{"id":2459,"title":"ERROR_IPSEC_IKE_INNER_IP_ASSIGNMENT_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13899","0x364B","error 13899","ERROR_IPSEC_IKE_INNER_IP_ASSIGNMENT_FAILURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","inner","assignment","failure","assigning","address","initiator","tunnel","mode"],"errorCode":"13899","eventId":"","severity":"Low","summary":"Error in assigning inner IP address to initiator in tunnel mode.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13899; use the surrounding log entries to confirm it.","resolution":"1. Record where 13899 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_INNER_IP_ASSIGNMENT_FAILURE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13899 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Error in assigning inner IP address to initiator in tunnel mode.\n\nLookup forms: 13899, 0x364B, error 13899, ERROR_IPSEC_IKE_INNER_IP_ASSIGNMENT_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13899"]},{"id":2460,"title":"ERROR_IPSEC_IKE_REQUIRE_CP_PAYLOAD_MISSING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13900","0x364C","error 13900","ERROR_IPSEC_IKE_REQUIRE_CP_PAYLOAD_MISSING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","require","payload","missing","configuration"],"errorCode":"13900","eventId":"","severity":"Low","summary":"Require configuration payload missing.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13900; use the surrounding log entries to confirm it.","resolution":"1. Record where 13900 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_REQUIRE_CP_PAYLOAD_MISSING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13900 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Require configuration payload missing.\n\nLookup forms: 13900, 0x364C, error 13900, ERROR_IPSEC_IKE_REQUIRE_CP_PAYLOAD_MISSING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13900"]},{"id":2461,"title":"ERROR_IPSEC_KEY_MODULE_IMPERSONATION_NEGOTIATION_PENDING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13901","0x364D","error 13901","ERROR_IPSEC_KEY_MODULE_IMPERSONATION_NEGOTIATION_PENDING","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ipsec","key","module","impersonation","negotiation","pending","running","the","security","principle","who","issued","connection","progress"],"errorCode":"13901","eventId":"","severity":"High","summary":"A negotiation running as the security principle who issued the connection is in progress.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 13901; use the surrounding log entries to confirm it.","resolution":"1. Record where 13901 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_KEY_MODULE_IMPERSONATION_NEGOTIATION_PENDING.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13901 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A negotiation running as the security principle who issued the connection is in progress.\n\nLookup forms: 13901, 0x364D, error 13901, ERROR_IPSEC_KEY_MODULE_IMPERSONATION_NEGOTIATION_PENDING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13901"]},{"id":2462,"title":"ERROR_IPSEC_IKE_COEXISTENCE_SUPPRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13902","0x364E","error 13902","ERROR_IPSEC_IKE_COEXISTENCE_SUPPRESS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","coexistence","suppress","was","deleted","due","ikev1","authip","existence","check"],"errorCode":"13902","eventId":"","severity":"Low","summary":"SA was deleted due to IKEv1/AuthIP co-existence suppress check.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13902; use the surrounding log entries to confirm it.","resolution":"1. Record where 13902 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_COEXISTENCE_SUPPRESS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13902 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: SA was deleted due to IKEv1/AuthIP co-existence suppress check.\n\nLookup forms: 13902, 0x364E, error 13902, ERROR_IPSEC_IKE_COEXISTENCE_SUPPRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13902"]},{"id":2463,"title":"ERROR_IPSEC_IKE_RATELIMIT_DROP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13903","0x364F","error 13903","ERROR_IPSEC_IKE_RATELIMIT_DROP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","ratelimit","drop","incoming","request","was","dropped","due","peer","address","rate","limiting"],"errorCode":"13903","eventId":"","severity":"Low","summary":"Incoming SA request was dropped due to peer IP address rate limiting.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13903; use the surrounding log entries to confirm it.","resolution":"1. Record where 13903 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_RATELIMIT_DROP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13903 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Incoming SA request was dropped due to peer IP address rate limiting.\n\nLookup forms: 13903, 0x364F, error 13903, ERROR_IPSEC_IKE_RATELIMIT_DROP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13903"]},{"id":2464,"title":"ERROR_IPSEC_IKE_PEER_DOESNT_SUPPORT_MOBIKE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13904","0x3650","error 13904","ERROR_IPSEC_IKE_PEER_DOESNT_SUPPORT_MOBIKE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","peer","doesnt","support","mobike","does","not"],"errorCode":"13904","eventId":"","severity":"Low","summary":"Peer does not support MOBIKE.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13904; use the surrounding log entries to confirm it.","resolution":"1. Record where 13904 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_PEER_DOESNT_SUPPORT_MOBIKE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13904 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Peer does not support MOBIKE.\n\nLookup forms: 13904, 0x3650, error 13904, ERROR_IPSEC_IKE_PEER_DOESNT_SUPPORT_MOBIKE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13904"]},{"id":2465,"title":"ERROR_IPSEC_IKE_AUTHORIZATION_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13905","0x3651","error 13905","ERROR_IPSEC_IKE_AUTHORIZATION_FAILURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","authorization","failure","establishment","not","authorized"],"errorCode":"13905","eventId":"","severity":"Low","summary":"SA establishment is not authorized.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13905; use the surrounding log entries to confirm it.","resolution":"1. Record where 13905 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_AUTHORIZATION_FAILURE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13905 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: SA establishment is not authorized.\n\nLookup forms: 13905, 0x3651, error 13905, ERROR_IPSEC_IKE_AUTHORIZATION_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13905"]},{"id":2466,"title":"ERROR_IPSEC_IKE_STRONG_CRED_AUTHORIZATION_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13906","0x3652","error 13906","ERROR_IPSEC_IKE_STRONG_CRED_AUTHORIZATION_FAILURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","strong","cred","authorization","failure","establishment","not","authorized","because","there","sufficiently","pkinit","based","credential"],"errorCode":"13906","eventId":"","severity":"Low","summary":"SA establishment is not authorized because there is not a sufficiently strong PKINIT-based credential.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13906; use the surrounding log entries to confirm it.","resolution":"1. Record where 13906 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_STRONG_CRED_AUTHORIZATION_FAILURE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13906 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: SA establishment is not authorized because there is not a sufficiently strong PKINIT-based credential.\n\nLookup forms: 13906, 0x3652, error 13906, ERROR_IPSEC_IKE_STRONG_CRED_AUTHORIZATION_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13906"]},{"id":2467,"title":"ERROR_IPSEC_IKE_AUTHORIZATION_FAILURE_WITH_OPTIONAL_RETRY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13907","0x3653","error 13907","ERROR_IPSEC_IKE_AUTHORIZATION_FAILURE_WITH_OPTIONAL_RETRY","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","ipsec","ike","authorization","failure","with","optional","retry","establishment","not","authorized","you","may","need","enter","updated","different","credentials","such","smartcard"],"errorCode":"13907","eventId":"","severity":"Low","summary":"SA establishment is not authorized. You may need to enter updated or different credentials such as a smartcard.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 13907; use the surrounding log entries to confirm it.","resolution":"1. Record where 13907 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_AUTHORIZATION_FAILURE_WITH_OPTIONAL_RETRY.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13907 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: SA establishment is not authorized. You may need to enter updated or different credentials such as a smartcard.\n\nLookup forms: 13907, 0x3653, error 13907, ERROR_IPSEC_IKE_AUTHORIZATION_FAILURE_WITH_OPTIONAL_RETRY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13907"]},{"id":2468,"title":"ERROR_IPSEC_IKE_STRONG_CRED_AUTHORIZATION_AND_CERTMAP_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13908","0x3654","error 13908","ERROR_IPSEC_IKE_STRONG_CRED_AUTHORIZATION_AND_CERTMAP_FAILURE","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","ipsec","ike","strong","cred","authorization","and","certmap","failure","establishment","not","authorized","because","there","sufficiently","pkinit","based","credential","this","might","related","certificate","account","mapping","for"],"errorCode":"13908","eventId":"","severity":"High","summary":"SA establishment is not authorized because there is not a sufficiently strong PKINIT-based credential. This might be related to certificate-to-account mapping failure for the SA.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 13908; use the surrounding log entries to confirm it.","resolution":"1. Record where 13908 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_STRONG_CRED_AUTHORIZATION_AND_CERTMAP_FAILURE.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13908 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: SA establishment is not authorized because there is not a sufficiently strong PKINIT-based credential. This might be related to certificate-to-account mapping failure for the SA.\n\nLookup forms: 13908, 0x3654, error 13908, ERROR_IPSEC_IKE_STRONG_CRED_AUTHORIZATION_AND_CERTMAP_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13908"]},{"id":2469,"title":"ERROR_IPSEC_IKE_NEG_STATUS_EXTENDED_END","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13909","0x3655","error 13909","ERROR_IPSEC_IKE_NEG_STATUS_EXTENDED_END","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","ike","neg","status","extended","end"],"errorCode":"13909","eventId":"","severity":"Low","summary":"ERROR_IPSEC_IKE_NEG_STATUS_EXTENDED_END","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13909; use the surrounding log entries to confirm it.","resolution":"1. Record where 13909 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_IKE_NEG_STATUS_EXTENDED_END.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13909 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: ERROR_IPSEC_IKE_NEG_STATUS_EXTENDED_END\n\nLookup forms: 13909, 0x3655, error 13909, ERROR_IPSEC_IKE_NEG_STATUS_EXTENDED_END. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13909"]},{"id":2470,"title":"ERROR_IPSEC_BAD_SPI","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13910","0x3656","error 13910","ERROR_IPSEC_BAD_SPI","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","bad","spi","the","packet","does","not","match","valid"],"errorCode":"13910","eventId":"","severity":"Low","summary":"The SPI in the packet does not match a valid IPsec SA.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13910; use the surrounding log entries to confirm it.","resolution":"1. Record where 13910 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_BAD_SPI.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13910 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The SPI in the packet does not match a valid IPsec SA.\n\nLookup forms: 13910, 0x3656, error 13910, ERROR_IPSEC_BAD_SPI. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13910"]},{"id":2471,"title":"ERROR_IPSEC_SA_LIFETIME_EXPIRED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13911","0x3657","error 13911","ERROR_IPSEC_SA_LIFETIME_EXPIRED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","lifetime","expired","packet","was","received","whose","has"],"errorCode":"13911","eventId":"","severity":"Low","summary":"Packet was received on an IPsec SA whose lifetime has expired.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13911; use the surrounding log entries to confirm it.","resolution":"1. Record where 13911 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_SA_LIFETIME_EXPIRED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13911 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Packet was received on an IPsec SA whose lifetime has expired.\n\nLookup forms: 13911, 0x3657, error 13911, ERROR_IPSEC_SA_LIFETIME_EXPIRED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13911"]},{"id":2472,"title":"ERROR_IPSEC_WRONG_SA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13912","0x3658","error 13912","ERROR_IPSEC_WRONG_SA","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","wrong","packet","was","received","that","does","not","match","the","characteristics"],"errorCode":"13912","eventId":"","severity":"Low","summary":"Packet was received on an IPsec SA that does not match the packet characteristics.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13912; use the surrounding log entries to confirm it.","resolution":"1. Record where 13912 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_WRONG_SA.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13912 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Packet was received on an IPsec SA that does not match the packet characteristics.\n\nLookup forms: 13912, 0x3658, error 13912, ERROR_IPSEC_WRONG_SA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13912"]},{"id":2473,"title":"ERROR_IPSEC_REPLAY_CHECK_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13913","0x3659","error 13913","ERROR_IPSEC_REPLAY_CHECK_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","replay","check","failed","packet","sequence","number"],"errorCode":"13913","eventId":"","severity":"High","summary":"Packet sequence number replay check failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13913; use the surrounding log entries to confirm it.","resolution":"1. Record where 13913 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_REPLAY_CHECK_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13913 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Packet sequence number replay check failed.\n\nLookup forms: 13913, 0x3659, error 13913, ERROR_IPSEC_REPLAY_CHECK_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13913"]},{"id":2474,"title":"ERROR_IPSEC_INVALID_PACKET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13914","0x365A","error 13914","ERROR_IPSEC_INVALID_PACKET","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","invalid","packet","header","and","trailer","the"],"errorCode":"13914","eventId":"","severity":"Medium","summary":"IPsec header and/or trailer in the packet is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13914; use the surrounding log entries to confirm it.","resolution":"1. Record where 13914 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_INVALID_PACKET.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13914 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: IPsec header and/or trailer in the packet is invalid.\n\nLookup forms: 13914, 0x365A, error 13914, ERROR_IPSEC_INVALID_PACKET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13914"]},{"id":2475,"title":"ERROR_IPSEC_INTEGRITY_CHECK_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13915","0x365B","error 13915","ERROR_IPSEC_INTEGRITY_CHECK_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","integrity","check","failed"],"errorCode":"13915","eventId":"","severity":"High","summary":"IPsec integrity check failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13915; use the surrounding log entries to confirm it.","resolution":"1. Record where 13915 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_INTEGRITY_CHECK_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13915 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: IPsec integrity check failed.\n\nLookup forms: 13915, 0x365B, error 13915, ERROR_IPSEC_INTEGRITY_CHECK_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13915"]},{"id":2476,"title":"ERROR_IPSEC_CLEAR_TEXT_DROP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13916","0x365C","error 13916","ERROR_IPSEC_CLEAR_TEXT_DROP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","clear","text","drop","dropped","packet"],"errorCode":"13916","eventId":"","severity":"Low","summary":"IPsec dropped a clear text packet.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13916; use the surrounding log entries to confirm it.","resolution":"1. Record where 13916 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_CLEAR_TEXT_DROP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13916 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: IPsec dropped a clear text packet.\n\nLookup forms: 13916, 0x365C, error 13916, ERROR_IPSEC_CLEAR_TEXT_DROP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13916"]},{"id":2477,"title":"ERROR_IPSEC_AUTH_FIREWALL_DROP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13917","0x365D","error 13917","ERROR_IPSEC_AUTH_FIREWALL_DROP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","auth","firewall","drop","dropped","incoming","esp","packet","authenticated","mode","this","benign"],"errorCode":"13917","eventId":"","severity":"Low","summary":"IPsec dropped an incoming ESP packet in authenticated firewall mode. This drop is benign.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13917; use the surrounding log entries to confirm it.","resolution":"1. Record where 13917 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_AUTH_FIREWALL_DROP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13917 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: IPsec dropped an incoming ESP packet in authenticated firewall mode. This drop is benign.\n\nLookup forms: 13917, 0x365D, error 13917, ERROR_IPSEC_AUTH_FIREWALL_DROP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13917"]},{"id":2478,"title":"ERROR_IPSEC_THROTTLE_DROP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13918","0x365E","error 13918","ERROR_IPSEC_THROTTLE_DROP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","throttle","drop","dropped","packet","due","dos","throttling"],"errorCode":"13918","eventId":"","severity":"Low","summary":"IPsec dropped a packet due to DoS throttling.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13918; use the surrounding log entries to confirm it.","resolution":"1. Record where 13918 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_THROTTLE_DROP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13918 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: IPsec dropped a packet due to DoS throttling.\n\nLookup forms: 13918, 0x365E, error 13918, ERROR_IPSEC_THROTTLE_DROP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13918"]},{"id":2479,"title":"ERROR_IPSEC_DOSP_BLOCK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13925","0x3665","error 13925","ERROR_IPSEC_DOSP_BLOCK","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","dosp","block","dos","protection","matched","explicit","rule"],"errorCode":"13925","eventId":"","severity":"Low","summary":"IPsec DoS Protection matched an explicit block rule.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13925; use the surrounding log entries to confirm it.","resolution":"1. Record where 13925 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_DOSP_BLOCK.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13925 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: IPsec DoS Protection matched an explicit block rule.\n\nLookup forms: 13925, 0x3665, error 13925, ERROR_IPSEC_DOSP_BLOCK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13925"]},{"id":2480,"title":"ERROR_IPSEC_DOSP_RECEIVED_MULTICAST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13926","0x3666","error 13926","ERROR_IPSEC_DOSP_RECEIVED_MULTICAST","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","dosp","received","multicast","dos","protection","specific","packet","which","not","allowed"],"errorCode":"13926","eventId":"","severity":"Low","summary":"IPsec DoS Protection received an IPsec specific multicast packet which is not allowed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13926; use the surrounding log entries to confirm it.","resolution":"1. Record where 13926 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_DOSP_RECEIVED_MULTICAST.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13926 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: IPsec DoS Protection received an IPsec specific multicast packet which is not allowed.\n\nLookup forms: 13926, 0x3666, error 13926, ERROR_IPSEC_DOSP_RECEIVED_MULTICAST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13926"]},{"id":2481,"title":"ERROR_IPSEC_DOSP_INVALID_PACKET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13927","0x3667","error 13927","ERROR_IPSEC_DOSP_INVALID_PACKET","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","dosp","invalid","packet","dos","protection","received","incorrectly","formatted"],"errorCode":"13927","eventId":"","severity":"Low","summary":"IPsec DoS Protection received an incorrectly formatted packet.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13927; use the surrounding log entries to confirm it.","resolution":"1. Record where 13927 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_DOSP_INVALID_PACKET.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13927 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: IPsec DoS Protection received an incorrectly formatted packet.\n\nLookup forms: 13927, 0x3667, error 13927, ERROR_IPSEC_DOSP_INVALID_PACKET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13927"]},{"id":2482,"title":"ERROR_IPSEC_DOSP_STATE_LOOKUP_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13928","0x3668","error 13928","ERROR_IPSEC_DOSP_STATE_LOOKUP_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","dosp","state","lookup","failed","dos","protection","look"],"errorCode":"13928","eventId":"","severity":"High","summary":"IPsec DoS Protection failed to look up state.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13928; use the surrounding log entries to confirm it.","resolution":"1. Record where 13928 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_DOSP_STATE_LOOKUP_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13928 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: IPsec DoS Protection failed to look up state.\n\nLookup forms: 13928, 0x3668, error 13928, ERROR_IPSEC_DOSP_STATE_LOOKUP_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13928"]},{"id":2483,"title":"ERROR_IPSEC_DOSP_MAX_ENTRIES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13929","0x3669","error 13929","ERROR_IPSEC_DOSP_MAX_ENTRIES","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","dosp","max","entries","dos","protection","failed","create","state","because","the","maximum","number","allowed","policy","has","been","reached"],"errorCode":"13929","eventId":"","severity":"High","summary":"IPsec DoS Protection failed to create state because the maximum number of entries allowed by policy has been reached.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13929; use the surrounding log entries to confirm it.","resolution":"1. Record where 13929 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_DOSP_MAX_ENTRIES.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13929 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: IPsec DoS Protection failed to create state because the maximum number of entries allowed by policy has been reached.\n\nLookup forms: 13929, 0x3669, error 13929, ERROR_IPSEC_DOSP_MAX_ENTRIES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13929"]},{"id":2484,"title":"ERROR_IPSEC_DOSP_KEYMOD_NOT_ALLOWED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13930","0x366A","error 13930","ERROR_IPSEC_DOSP_KEYMOD_NOT_ALLOWED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","ipsec","dosp","keymod","not","allowed","dos","protection","received","negotiation","packet","for","keying","module","which","policy"],"errorCode":"13930","eventId":"","severity":"Low","summary":"IPsec DoS Protection received an IPsec negotiation packet for a keying module which is not allowed by policy.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 13930; use the surrounding log entries to confirm it.","resolution":"1. Record where 13930 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_DOSP_KEYMOD_NOT_ALLOWED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13930 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: IPsec DoS Protection received an IPsec negotiation packet for a keying module which is not allowed by policy.\n\nLookup forms: 13930, 0x366A, error 13930, ERROR_IPSEC_DOSP_KEYMOD_NOT_ALLOWED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13930"]},{"id":2485,"title":"ERROR_IPSEC_DOSP_NOT_INSTALLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13931","0x366B","error 13931","ERROR_IPSEC_DOSP_NOT_INSTALLED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","dosp","not","installed","dos","protection","has","been","enabled"],"errorCode":"13931","eventId":"","severity":"Low","summary":"IPsec DoS Protection has not been enabled.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13931; use the surrounding log entries to confirm it.","resolution":"1. Record where 13931 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_DOSP_NOT_INSTALLED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13931 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: IPsec DoS Protection has not been enabled.\n\nLookup forms: 13931, 0x366B, error 13931, ERROR_IPSEC_DOSP_NOT_INSTALLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13931"]},{"id":2486,"title":"ERROR_IPSEC_DOSP_MAX_PER_IP_RATELIMIT_QUEUES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["13932","0x366C","error 13932","ERROR_IPSEC_DOSP_MAX_PER_IP_RATELIMIT_QUEUES","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ipsec","dosp","max","per","ratelimit","queues","dos","protection","failed","create","internal","rate","limit","queue","because","the","maximum","number","allowed","policy","has","been","reached"],"errorCode":"13932","eventId":"","severity":"High","summary":"IPsec DoS Protection failed to create a per internal IP rate limit queue because the maximum number of queues allowed by policy has been reached.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 13932; use the surrounding log entries to confirm it.","resolution":"1. Record where 13932 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_IPSEC_DOSP_MAX_PER_IP_RATELIMIT_QUEUES.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 13932 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: IPsec DoS Protection failed to create a per internal IP rate limit queue because the maximum number of queues allowed by policy has been reached.\n\nLookup forms: 13932, 0x366C, error 13932, ERROR_IPSEC_DOSP_MAX_PER_IP_RATELIMIT_QUEUES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["13932"]},{"id":2487,"title":"ERROR_SXS_SECTION_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14000","0x36B0","error 14000","ERROR_SXS_SECTION_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","section","not","found","the","requested","was","present","activation","context"],"errorCode":"14000","eventId":"","severity":"Low","summary":"The requested section was not present in the activation context.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14000; use the surrounding log entries to confirm it.","resolution":"1. Record where 14000 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_SECTION_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14000 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested section was not present in the activation context.\n\nLookup forms: 14000, 0x36B0, error 14000, ERROR_SXS_SECTION_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14000"]},{"id":2488,"title":"ERROR_SXS_CANT_GEN_ACTCTX","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14001","0x36B1","error 14001","ERROR_SXS_CANT_GEN_ACTCTX","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","cant","gen","actctx","the","application","has","failed","start","because","its","side","configuration","incorrect","please","see","event","log","use","command","line","sxstrace","exe","tool"],"errorCode":"14001","eventId":"","severity":"High","summary":"The application has failed to start because its side-by-side configuration is incorrect. Please see the application event log or use the command-line sxstrace.exe tool for more detail.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14001; use the surrounding log entries to confirm it.","resolution":"1. Record where 14001 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_CANT_GEN_ACTCTX.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14001 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The application has failed to start because its side-by-side configuration is incorrect. Please see the application event log or use the command-line sxstrace.exe tool for more detail.\n\nLookup forms: 14001, 0x36B1, error 14001, ERROR_SXS_CANT_GEN_ACTCTX. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): This application has failed to start because the application configuration is incorrect. Reinstalling the application may fix this problem.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14001"]},{"id":2489,"title":"ERROR_SXS_INVALID_ACTCTXDATA_FORMAT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14002","0x36B2","error 14002","ERROR_SXS_INVALID_ACTCTXDATA_FORMAT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","invalid","actctxdata","format","the","application","binding","data"],"errorCode":"14002","eventId":"","severity":"Medium","summary":"The application binding data format is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14002; use the surrounding log entries to confirm it.","resolution":"1. Record where 14002 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_INVALID_ACTCTXDATA_FORMAT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14002 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The application binding data format is invalid.\n\nLookup forms: 14002, 0x36B2, error 14002, ERROR_SXS_INVALID_ACTCTXDATA_FORMAT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14002"]},{"id":2490,"title":"ERROR_SXS_ASSEMBLY_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14003","0x36B3","error 14003","ERROR_SXS_ASSEMBLY_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","sxs","assembly","not","found","the","referenced","installed","your","system"],"errorCode":"14003","eventId":"","severity":"Low","summary":"The referenced assembly is not installed on your system.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 14003; use the surrounding log entries to confirm it.","resolution":"1. Record where 14003 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_ASSEMBLY_NOT_FOUND.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14003 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The referenced assembly is not installed on your system.\n\nLookup forms: 14003, 0x36B3, error 14003, ERROR_SXS_ASSEMBLY_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14003"]},{"id":2491,"title":"ERROR_SXS_MANIFEST_FORMAT_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14004","0x36B4","error 14004","ERROR_SXS_MANIFEST_FORMAT_ERROR","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","sxs","manifest","format","the","file","does","not","begin","with","required","tag","and","information"],"errorCode":"14004","eventId":"","severity":"Low","summary":"The manifest file does not begin with the required tag and format information.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 14004; use the surrounding log entries to confirm it.","resolution":"1. Record where 14004 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_MANIFEST_FORMAT_ERROR.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14004 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The manifest file does not begin with the required tag and format information.\n\nLookup forms: 14004, 0x36B4, error 14004, ERROR_SXS_MANIFEST_FORMAT_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14004"]},{"id":2492,"title":"ERROR_SXS_MANIFEST_PARSE_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14005","0x36B5","error 14005","ERROR_SXS_MANIFEST_PARSE_ERROR","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","sxs","manifest","parse","the","file","contains","one","more","syntax","errors"],"errorCode":"14005","eventId":"","severity":"Low","summary":"The manifest file contains one or more syntax errors.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 14005; use the surrounding log entries to confirm it.","resolution":"1. Record where 14005 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_MANIFEST_PARSE_ERROR.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14005 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The manifest file contains one or more syntax errors.\n\nLookup forms: 14005, 0x36B5, error 14005, ERROR_SXS_MANIFEST_PARSE_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14005"]},{"id":2493,"title":"ERROR_SXS_ACTIVATION_CONTEXT_DISABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14006","0x36B6","error 14006","ERROR_SXS_ACTIVATION_CONTEXT_DISABLED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","activation","context","disabled","the","application","attempted","activate"],"errorCode":"14006","eventId":"","severity":"Low","summary":"The application attempted to activate a disabled activation context.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14006; use the surrounding log entries to confirm it.","resolution":"1. Record where 14006 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_ACTIVATION_CONTEXT_DISABLED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14006 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The application attempted to activate a disabled activation context.\n\nLookup forms: 14006, 0x36B6, error 14006, ERROR_SXS_ACTIVATION_CONTEXT_DISABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14006"]},{"id":2494,"title":"ERROR_SXS_KEY_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14007","0x36B7","error 14007","ERROR_SXS_KEY_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","key","not","found","the","requested","lookup","was","any","active","activation","context"],"errorCode":"14007","eventId":"","severity":"Medium","summary":"The requested lookup key was not found in any active activation context.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14007; use the surrounding log entries to confirm it.","resolution":"1. Record where 14007 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_KEY_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14007 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested lookup key was not found in any active activation context.\n\nLookup forms: 14007, 0x36B7, error 14007, ERROR_SXS_KEY_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14007"]},{"id":2495,"title":"ERROR_SXS_VERSION_CONFLICT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14008","0x36B8","error 14008","ERROR_SXS_VERSION_CONFLICT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","version","conflict","component","required","the","application","conflicts","with","another","already","active"],"errorCode":"14008","eventId":"","severity":"Low","summary":"A component version required by the application conflicts with another component version already active.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14008; use the surrounding log entries to confirm it.","resolution":"1. Record where 14008 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_VERSION_CONFLICT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14008 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A component version required by the application conflicts with another component version already active.\n\nLookup forms: 14008, 0x36B8, error 14008, ERROR_SXS_VERSION_CONFLICT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14008"]},{"id":2496,"title":"ERROR_SXS_WRONG_SECTION_TYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14009","0x36B9","error 14009","ERROR_SXS_WRONG_SECTION_TYPE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","sxs","wrong","section","type","the","requested","activation","context","does","not","match","query","api","used"],"errorCode":"14009","eventId":"","severity":"Low","summary":"The type requested activation context section does not match the query API used.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 14009; use the surrounding log entries to confirm it.","resolution":"1. Record where 14009 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_WRONG_SECTION_TYPE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14009 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The type requested activation context section does not match the query API used.\n\nLookup forms: 14009, 0x36B9, error 14009, ERROR_SXS_WRONG_SECTION_TYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14009"]},{"id":2497,"title":"ERROR_SXS_THREAD_QUERIES_DISABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14010","0x36BA","error 14010","ERROR_SXS_THREAD_QUERIES_DISABLED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","sxs","thread","queries","disabled","lack","system","resources","has","required","isolated","activation","for","the","current","execution"],"errorCode":"14010","eventId":"","severity":"Low","summary":"Lack of system resources has required isolated activation to be disabled for the current thread of execution.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 14010; use the surrounding log entries to confirm it.","resolution":"1. Record where 14010 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_THREAD_QUERIES_DISABLED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14010 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Lack of system resources has required isolated activation to be disabled for the current thread of execution.\n\nLookup forms: 14010, 0x36BA, error 14010, ERROR_SXS_THREAD_QUERIES_DISABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14010"]},{"id":2498,"title":"ERROR_SXS_PROCESS_DEFAULT_ALREADY_SET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14011","0x36BB","error 14011","ERROR_SXS_PROCESS_DEFAULT_ALREADY_SET","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","sxs","process","default","already","set","attempt","the","activation","context","failed","because","was"],"errorCode":"14011","eventId":"","severity":"High","summary":"An attempt to set the process default activation context failed because the process default activation context was already set.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 14011; use the surrounding log entries to confirm it.","resolution":"1. Record where 14011 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_PROCESS_DEFAULT_ALREADY_SET.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14011 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An attempt to set the process default activation context failed because the process default activation context was already set.\n\nLookup forms: 14011, 0x36BB, error 14011, ERROR_SXS_PROCESS_DEFAULT_ALREADY_SET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14011"]},{"id":2499,"title":"ERROR_SXS_UNKNOWN_ENCODING_GROUP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14012","0x36BC","error 14012","ERROR_SXS_UNKNOWN_ENCODING_GROUP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","unknown","encoding","group","the","identifier","specified","not","recognized"],"errorCode":"14012","eventId":"","severity":"Low","summary":"The encoding group identifier specified is not recognized.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14012; use the surrounding log entries to confirm it.","resolution":"1. Record where 14012 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_UNKNOWN_ENCODING_GROUP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14012 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The encoding group identifier specified is not recognized.\n\nLookup forms: 14012, 0x36BC, error 14012, ERROR_SXS_UNKNOWN_ENCODING_GROUP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14012"]},{"id":2500,"title":"ERROR_SXS_UNKNOWN_ENCODING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14013","0x36BD","error 14013","ERROR_SXS_UNKNOWN_ENCODING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","unknown","encoding","the","requested","not","recognized"],"errorCode":"14013","eventId":"","severity":"Low","summary":"The encoding requested is not recognized.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14013; use the surrounding log entries to confirm it.","resolution":"1. Record where 14013 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_UNKNOWN_ENCODING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14013 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The encoding requested is not recognized.\n\nLookup forms: 14013, 0x36BD, error 14013, ERROR_SXS_UNKNOWN_ENCODING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14013"]},{"id":2501,"title":"ERROR_SXS_INVALID_XML_NAMESPACE_URI","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14014","0x36BE","error 14014","ERROR_SXS_INVALID_XML_NAMESPACE_URI","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","invalid","xml","namespace","uri","the","manifest","contains","reference"],"errorCode":"14014","eventId":"","severity":"Medium","summary":"The manifest contains a reference to an invalid URI.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14014; use the surrounding log entries to confirm it.","resolution":"1. Record where 14014 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_INVALID_XML_NAMESPACE_URI.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14014 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The manifest contains a reference to an invalid URI.\n\nLookup forms: 14014, 0x36BE, error 14014, ERROR_SXS_INVALID_XML_NAMESPACE_URI. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14014"]},{"id":2502,"title":"ERROR_SXS_ROOT_MANIFEST_DEPENDENCY_NOT_INSTALLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14015","0x36BF","error 14015","ERROR_SXS_ROOT_MANIFEST_DEPENDENCY_NOT_INSTALLED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","sxs","root","manifest","dependency","not","installed","the","application","contains","reference","dependent","assembly","which"],"errorCode":"14015","eventId":"","severity":"Low","summary":"The application manifest contains a reference to a dependent assembly which is not installed.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 14015; use the surrounding log entries to confirm it.","resolution":"1. Record where 14015 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_ROOT_MANIFEST_DEPENDENCY_NOT_INSTALLED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14015 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The application manifest contains a reference to a dependent assembly which is not installed.\n\nLookup forms: 14015, 0x36BF, error 14015, ERROR_SXS_ROOT_MANIFEST_DEPENDENCY_NOT_INSTALLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14015"]},{"id":2503,"title":"ERROR_SXS_LEAF_MANIFEST_DEPENDENCY_NOT_INSTALLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14016","0x36C0","error 14016","ERROR_SXS_LEAF_MANIFEST_DEPENDENCY_NOT_INSTALLED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","sxs","leaf","manifest","dependency","not","installed","the","for","assembly","used","application","has","reference","dependent","which"],"errorCode":"14016","eventId":"","severity":"Low","summary":"The manifest for an assembly used by the application has a reference to a dependent assembly which is not installed.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 14016; use the surrounding log entries to confirm it.","resolution":"1. Record where 14016 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_LEAF_MANIFEST_DEPENDENCY_NOT_INSTALLED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14016 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The manifest for an assembly used by the application has a reference to a dependent assembly which is not installed.\n\nLookup forms: 14016, 0x36C0, error 14016, ERROR_SXS_LEAF_MANIFEST_DEPENDENCY_NOT_INSTALLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14016"]},{"id":2504,"title":"ERROR_SXS_INVALID_ASSEMBLY_IDENTITY_ATTRIBUTE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14017","0x36C1","error 14017","ERROR_SXS_INVALID_ASSEMBLY_IDENTITY_ATTRIBUTE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","invalid","assembly","identity","attribute","the","manifest","contains","for","which","not","valid"],"errorCode":"14017","eventId":"","severity":"Low","summary":"The manifest contains an attribute for the assembly identity which is not valid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14017; use the surrounding log entries to confirm it.","resolution":"1. Record where 14017 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_INVALID_ASSEMBLY_IDENTITY_ATTRIBUTE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14017 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The manifest contains an attribute for the assembly identity which is not valid.\n\nLookup forms: 14017, 0x36C1, error 14017, ERROR_SXS_INVALID_ASSEMBLY_IDENTITY_ATTRIBUTE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14017"]},{"id":2505,"title":"ERROR_SXS_MANIFEST_MISSING_REQUIRED_DEFAULT_NAMESPACE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14018","0x36C2","error 14018","ERROR_SXS_MANIFEST_MISSING_REQUIRED_DEFAULT_NAMESPACE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","manifest","missing","required","default","namespace","the","specification","assembly","element"],"errorCode":"14018","eventId":"","severity":"Low","summary":"The manifest is missing the required default namespace specification on the assembly element.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14018; use the surrounding log entries to confirm it.","resolution":"1. Record where 14018 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_MANIFEST_MISSING_REQUIRED_DEFAULT_NAMESPACE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14018 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The manifest is missing the required default namespace specification on the assembly element.\n\nLookup forms: 14018, 0x36C2, error 14018, ERROR_SXS_MANIFEST_MISSING_REQUIRED_DEFAULT_NAMESPACE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14018"]},{"id":2506,"title":"ERROR_SXS_MANIFEST_INVALID_REQUIRED_DEFAULT_NAMESPACE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14019","0x36C3","error 14019","ERROR_SXS_MANIFEST_INVALID_REQUIRED_DEFAULT_NAMESPACE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","manifest","invalid","required","default","namespace","the","has","specified","assembly","element","but","its","value","not","urn","schemas","microsoft","com","asm"],"errorCode":"14019","eventId":"","severity":"Low","summary":"The manifest has a default namespace specified on the assembly element but its value is not \"urn:schemas-microsoft-com:asm.v1\".","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14019; use the surrounding log entries to confirm it.","resolution":"1. Record where 14019 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_MANIFEST_INVALID_REQUIRED_DEFAULT_NAMESPACE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14019 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The manifest has a default namespace specified on the assembly element but its value is not \"urn:schemas-microsoft-com:asm.v1\".\n\nLookup forms: 14019, 0x36C3, error 14019, ERROR_SXS_MANIFEST_INVALID_REQUIRED_DEFAULT_NAMESPACE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14019"]},{"id":2507,"title":"ERROR_SXS_PRIVATE_MANIFEST_CROSS_PATH_WITH_REPARSE_POINT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14020","0x36C4","error 14020","ERROR_SXS_PRIVATE_MANIFEST_CROSS_PATH_WITH_REPARSE_POINT","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","sxs","private","manifest","cross","path","with","reparse","point","the","probed","has","crossed","unsupported"],"errorCode":"14020","eventId":"","severity":"Low","summary":"The private manifest probed has crossed a path with an unsupported reparse point.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 14020; use the surrounding log entries to confirm it.","resolution":"1. Record where 14020 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_PRIVATE_MANIFEST_CROSS_PATH_WITH_REPARSE_POINT.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14020 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The private manifest probed has crossed a path with an unsupported reparse point.\n\nLookup forms: 14020, 0x36C4, error 14020, ERROR_SXS_PRIVATE_MANIFEST_CROSS_PATH_WITH_REPARSE_POINT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): The private manifest probe has crossed the reparse-point-associated path.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14020"]},{"id":2508,"title":"ERROR_SXS_DUPLICATE_DLL_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14021","0x36C5","error 14021","ERROR_SXS_DUPLICATE_DLL_NAME","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","sxs","duplicate","dll","name","two","more","components","referenced","directly","indirectly","the","application","manifest","have","files","same"],"errorCode":"14021","eventId":"","severity":"Low","summary":"Two or more components referenced directly or indirectly by the application manifest have files by the same name.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 14021; use the surrounding log entries to confirm it.","resolution":"1. Record where 14021 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_DUPLICATE_DLL_NAME.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14021 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Two or more components referenced directly or indirectly by the application manifest have files by the same name.\n\nLookup forms: 14021, 0x36C5, error 14021, ERROR_SXS_DUPLICATE_DLL_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14021"]},{"id":2509,"title":"ERROR_SXS_DUPLICATE_WINDOWCLASS_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14022","0x36C6","error 14022","ERROR_SXS_DUPLICATE_WINDOWCLASS_NAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","duplicate","windowclass","name","two","more","components","referenced","directly","indirectly","the","application","manifest","have","window","classes","with","same"],"errorCode":"14022","eventId":"","severity":"Low","summary":"Two or more components referenced directly or indirectly by the application manifest have window classes with the same name.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14022; use the surrounding log entries to confirm it.","resolution":"1. Record where 14022 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_DUPLICATE_WINDOWCLASS_NAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14022 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Two or more components referenced directly or indirectly by the application manifest have window classes with the same name.\n\nLookup forms: 14022, 0x36C6, error 14022, ERROR_SXS_DUPLICATE_WINDOWCLASS_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14022"]},{"id":2510,"title":"ERROR_SXS_DUPLICATE_CLSID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14023","0x36C7","error 14023","ERROR_SXS_DUPLICATE_CLSID","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","sxs","duplicate","clsid","two","more","components","referenced","directly","indirectly","the","application","manifest","have","same","com","server","clsids"],"errorCode":"14023","eventId":"","severity":"Low","summary":"Two or more components referenced directly or indirectly by the application manifest have the same COM server CLSIDs.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 14023; use the surrounding log entries to confirm it.","resolution":"1. Record where 14023 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_DUPLICATE_CLSID.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14023 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Two or more components referenced directly or indirectly by the application manifest have the same COM server CLSIDs.\n\nLookup forms: 14023, 0x36C7, error 14023, ERROR_SXS_DUPLICATE_CLSID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14023"]},{"id":2511,"title":"ERROR_SXS_DUPLICATE_IID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14024","0x36C8","error 14024","ERROR_SXS_DUPLICATE_IID","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","duplicate","iid","two","more","components","referenced","directly","indirectly","the","application","manifest","have","proxies","for","same","com","interface","iids"],"errorCode":"14024","eventId":"","severity":"Low","summary":"Two or more components referenced directly or indirectly by the application manifest have proxies for the same COM interface IIDs.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14024; use the surrounding log entries to confirm it.","resolution":"1. Record where 14024 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_DUPLICATE_IID.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14024 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Two or more components referenced directly or indirectly by the application manifest have proxies for the same COM interface IIDs.\n\nLookup forms: 14024, 0x36C8, error 14024, ERROR_SXS_DUPLICATE_IID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14024"]},{"id":2512,"title":"ERROR_SXS_DUPLICATE_TLBID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14025","0x36C9","error 14025","ERROR_SXS_DUPLICATE_TLBID","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","duplicate","tlbid","two","more","components","referenced","directly","indirectly","the","application","manifest","have","same","com","type","library","tlbids"],"errorCode":"14025","eventId":"","severity":"Low","summary":"Two or more components referenced directly or indirectly by the application manifest have the same COM type library TLBIDs.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14025; use the surrounding log entries to confirm it.","resolution":"1. Record where 14025 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_DUPLICATE_TLBID.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14025 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Two or more components referenced directly or indirectly by the application manifest have the same COM type library TLBIDs.\n\nLookup forms: 14025, 0x36C9, error 14025, ERROR_SXS_DUPLICATE_TLBID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14025"]},{"id":2513,"title":"ERROR_SXS_DUPLICATE_PROGID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14026","0x36CA","error 14026","ERROR_SXS_DUPLICATE_PROGID","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","duplicate","progid","two","more","components","referenced","directly","indirectly","the","application","manifest","have","same","com","progids"],"errorCode":"14026","eventId":"","severity":"Low","summary":"Two or more components referenced directly or indirectly by the application manifest have the same COM ProgIDs.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14026; use the surrounding log entries to confirm it.","resolution":"1. Record where 14026 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_DUPLICATE_PROGID.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14026 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Two or more components referenced directly or indirectly by the application manifest have the same COM ProgIDs.\n\nLookup forms: 14026, 0x36CA, error 14026, ERROR_SXS_DUPLICATE_PROGID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14026"]},{"id":2514,"title":"ERROR_SXS_DUPLICATE_ASSEMBLY_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14027","0x36CB","error 14027","ERROR_SXS_DUPLICATE_ASSEMBLY_NAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","duplicate","assembly","name","two","more","components","referenced","directly","indirectly","the","application","manifest","are","different","versions","same","component","which","not","permitted"],"errorCode":"14027","eventId":"","severity":"Low","summary":"Two or more components referenced directly or indirectly by the application manifest are different versions of the same component which is not permitted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14027; use the surrounding log entries to confirm it.","resolution":"1. Record where 14027 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_DUPLICATE_ASSEMBLY_NAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14027 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Two or more components referenced directly or indirectly by the application manifest are different versions of the same component which is not permitted.\n\nLookup forms: 14027, 0x36CB, error 14027, ERROR_SXS_DUPLICATE_ASSEMBLY_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14027"]},{"id":2515,"title":"ERROR_SXS_FILE_HASH_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14028","0x36CC","error 14028","ERROR_SXS_FILE_HASH_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","sxs","file","hash","mismatch","component","does","not","match","the","verification","information","present","manifest"],"errorCode":"14028","eventId":"","severity":"Low","summary":"A component's file does not match the verification information present in the component manifest.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 14028; use the surrounding log entries to confirm it.","resolution":"1. Record where 14028 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_FILE_HASH_MISMATCH.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14028 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A component's file does not match the verification information present in the component manifest.\n\nLookup forms: 14028, 0x36CC, error 14028, ERROR_SXS_FILE_HASH_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14028"]},{"id":2516,"title":"ERROR_SXS_POLICY_PARSE_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14029","0x36CD","error 14029","ERROR_SXS_POLICY_PARSE_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","policy","parse","the","manifest","contains","one","more","syntax","errors"],"errorCode":"14029","eventId":"","severity":"Low","summary":"The policy manifest contains one or more syntax errors.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14029; use the surrounding log entries to confirm it.","resolution":"1. Record where 14029 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_POLICY_PARSE_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14029 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The policy manifest contains one or more syntax errors.\n\nLookup forms: 14029, 0x36CD, error 14029, ERROR_SXS_POLICY_PARSE_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14029"]},{"id":2517,"title":"ERROR_SXS_XML_E_MISSINGQUOTE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14030","0x36CE","error 14030","ERROR_SXS_XML_E_MISSINGQUOTE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","missingquote","manifest","parse","string","literal","was","expected","but","opening","quote","character","found"],"errorCode":"14030","eventId":"","severity":"Low","summary":"Manifest Parse Error : A string literal was expected, but no opening quote character was found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14030; use the surrounding log entries to confirm it.","resolution":"1. Record where 14030 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_MISSINGQUOTE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14030 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : A string literal was expected, but no opening quote character was found.\n\nLookup forms: 14030, 0x36CE, error 14030, ERROR_SXS_XML_E_MISSINGQUOTE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14030"]},{"id":2518,"title":"ERROR_SXS_XML_E_COMMENTSYNTAX","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14031","0x36CF","error 14031","ERROR_SXS_XML_E_COMMENTSYNTAX","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","commentsyntax","manifest","parse","incorrect","syntax","was","used","comment"],"errorCode":"14031","eventId":"","severity":"Low","summary":"Manifest Parse Error : Incorrect syntax was used in a comment.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14031; use the surrounding log entries to confirm it.","resolution":"1. Record where 14031 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_COMMENTSYNTAX.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14031 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : Incorrect syntax was used in a comment.\n\nLookup forms: 14031, 0x36CF, error 14031, ERROR_SXS_XML_E_COMMENTSYNTAX. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14031"]},{"id":2519,"title":"ERROR_SXS_XML_E_BADSTARTNAMECHAR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14032","0x36D0","error 14032","ERROR_SXS_XML_E_BADSTARTNAMECHAR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","badstartnamechar","manifest","parse","name","was","started","with","invalid","character"],"errorCode":"14032","eventId":"","severity":"Medium","summary":"Manifest Parse Error : A name was started with an invalid character.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14032; use the surrounding log entries to confirm it.","resolution":"1. Record where 14032 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_BADSTARTNAMECHAR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14032 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : A name was started with an invalid character.\n\nLookup forms: 14032, 0x36D0, error 14032, ERROR_SXS_XML_E_BADSTARTNAMECHAR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14032"]},{"id":2520,"title":"ERROR_SXS_XML_E_BADNAMECHAR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14033","0x36D1","error 14033","ERROR_SXS_XML_E_BADNAMECHAR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","badnamechar","manifest","parse","name","contained","invalid","character"],"errorCode":"14033","eventId":"","severity":"Medium","summary":"Manifest Parse Error : A name contained an invalid character.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14033; use the surrounding log entries to confirm it.","resolution":"1. Record where 14033 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_BADNAMECHAR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14033 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : A name contained an invalid character.\n\nLookup forms: 14033, 0x36D1, error 14033, ERROR_SXS_XML_E_BADNAMECHAR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14033"]},{"id":2521,"title":"ERROR_SXS_XML_E_BADCHARINSTRING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14034","0x36D2","error 14034","ERROR_SXS_XML_E_BADCHARINSTRING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","badcharinstring","manifest","parse","string","literal","contained","invalid","character"],"errorCode":"14034","eventId":"","severity":"Medium","summary":"Manifest Parse Error : A string literal contained an invalid character.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14034; use the surrounding log entries to confirm it.","resolution":"1. Record where 14034 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_BADCHARINSTRING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14034 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : A string literal contained an invalid character.\n\nLookup forms: 14034, 0x36D2, error 14034, ERROR_SXS_XML_E_BADCHARINSTRING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14034"]},{"id":2522,"title":"ERROR_SXS_XML_E_XMLDECLSYNTAX","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14035","0x36D3","error 14035","ERROR_SXS_XML_E_XMLDECLSYNTAX","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","xmldeclsyntax","manifest","parse","invalid","syntax","for","declaration"],"errorCode":"14035","eventId":"","severity":"Medium","summary":"Manifest Parse Error : Invalid syntax for an xml declaration.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14035; use the surrounding log entries to confirm it.","resolution":"1. Record where 14035 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_XMLDECLSYNTAX.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14035 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : Invalid syntax for an xml declaration.\n\nLookup forms: 14035, 0x36D3, error 14035, ERROR_SXS_XML_E_XMLDECLSYNTAX. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Manifest Parse Error : Invalid syntax for an XML declaration.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14035"]},{"id":2523,"title":"ERROR_SXS_XML_E_BADCHARDATA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14036","0x36D4","error 14036","ERROR_SXS_XML_E_BADCHARDATA","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","badchardata","manifest","parse","invalid","character","was","found","text","content"],"errorCode":"14036","eventId":"","severity":"Medium","summary":"Manifest Parse Error : An Invalid character was found in text content.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14036; use the surrounding log entries to confirm it.","resolution":"1. Record where 14036 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_BADCHARDATA.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14036 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : An Invalid character was found in text content.\n\nLookup forms: 14036, 0x36D4, error 14036, ERROR_SXS_XML_E_BADCHARDATA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Manifest Parse Error : An invalid character was found in text content.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14036"]},{"id":2524,"title":"ERROR_SXS_XML_E_MISSINGWHITESPACE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14037","0x36D5","error 14037","ERROR_SXS_XML_E_MISSINGWHITESPACE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","missingwhitespace","manifest","parse","required","white","space","was","missing"],"errorCode":"14037","eventId":"","severity":"Low","summary":"Manifest Parse Error : Required white space was missing.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14037; use the surrounding log entries to confirm it.","resolution":"1. Record where 14037 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_MISSINGWHITESPACE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14037 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : Required white space was missing.\n\nLookup forms: 14037, 0x36D5, error 14037, ERROR_SXS_XML_E_MISSINGWHITESPACE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14037"]},{"id":2525,"title":"ERROR_SXS_XML_E_EXPECTINGTAGEND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14038","0x36D6","error 14038","ERROR_SXS_XML_E_EXPECTINGTAGEND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","expectingtagend","manifest","parse","the","character","was","expected"],"errorCode":"14038","eventId":"","severity":"Low","summary":"Manifest Parse Error : The character '>' was expected.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14038; use the surrounding log entries to confirm it.","resolution":"1. Record where 14038 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_EXPECTINGTAGEND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14038 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : The character '>' was expected.\n\nLookup forms: 14038, 0x36D6, error 14038, ERROR_SXS_XML_E_EXPECTINGTAGEND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14038"]},{"id":2526,"title":"ERROR_SXS_XML_E_MISSINGSEMICOLON","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14039","0x36D7","error 14039","ERROR_SXS_XML_E_MISSINGSEMICOLON","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","missingsemicolon","manifest","parse","semi","colon","character","was","expected"],"errorCode":"14039","eventId":"","severity":"Low","summary":"Manifest Parse Error : A semi colon character was expected.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14039; use the surrounding log entries to confirm it.","resolution":"1. Record where 14039 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_MISSINGSEMICOLON.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14039 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : A semi colon character was expected.\n\nLookup forms: 14039, 0x36D7, error 14039, ERROR_SXS_XML_E_MISSINGSEMICOLON. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14039"]},{"id":2527,"title":"ERROR_SXS_XML_E_UNBALANCEDPAREN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14040","0x36D8","error 14040","ERROR_SXS_XML_E_UNBALANCEDPAREN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","unbalancedparen","manifest","parse","unbalanced","parentheses"],"errorCode":"14040","eventId":"","severity":"Low","summary":"Manifest Parse Error : Unbalanced parentheses.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14040; use the surrounding log entries to confirm it.","resolution":"1. Record where 14040 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_UNBALANCEDPAREN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14040 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : Unbalanced parentheses.\n\nLookup forms: 14040, 0x36D8, error 14040, ERROR_SXS_XML_E_UNBALANCEDPAREN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14040"]},{"id":2528,"title":"ERROR_SXS_XML_E_INTERNALERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14041","0x36D9","error 14041","ERROR_SXS_XML_E_INTERNALERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","internalerror","manifest","parse","internal"],"errorCode":"14041","eventId":"","severity":"Low","summary":"Manifest Parse Error : Internal error.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14041; use the surrounding log entries to confirm it.","resolution":"1. Record where 14041 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_INTERNALERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14041 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : Internal error.\n\nLookup forms: 14041, 0x36D9, error 14041, ERROR_SXS_XML_E_INTERNALERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14041"]},{"id":2529,"title":"ERROR_SXS_XML_E_UNEXPECTED_WHITESPACE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14042","0x36DA","error 14042","ERROR_SXS_XML_E_UNEXPECTED_WHITESPACE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","unexpected","whitespace","manifest","parse","not","allowed","this","location"],"errorCode":"14042","eventId":"","severity":"Low","summary":"Manifest Parse Error : Whitespace is not allowed at this location.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14042; use the surrounding log entries to confirm it.","resolution":"1. Record where 14042 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_UNEXPECTED_WHITESPACE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14042 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : Whitespace is not allowed at this location.\n\nLookup forms: 14042, 0x36DA, error 14042, ERROR_SXS_XML_E_UNEXPECTED_WHITESPACE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Manifest Parse Error : White space is not allowed at this location.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14042"]},{"id":2530,"title":"ERROR_SXS_XML_E_INCOMPLETE_ENCODING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14043","0x36DB","error 14043","ERROR_SXS_XML_E_INCOMPLETE_ENCODING","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","sxs","xml","incomplete","encoding","manifest","parse","end","file","reached","invalid","state","for","current"],"errorCode":"14043","eventId":"","severity":"Medium","summary":"Manifest Parse Error : End of file reached in invalid state for current encoding.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 14043; use the surrounding log entries to confirm it.","resolution":"1. Record where 14043 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_INCOMPLETE_ENCODING.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14043 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : End of file reached in invalid state for current encoding.\n\nLookup forms: 14043, 0x36DB, error 14043, ERROR_SXS_XML_E_INCOMPLETE_ENCODING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14043"]},{"id":2531,"title":"ERROR_SXS_XML_E_MISSING_PAREN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14044","0x36DC","error 14044","ERROR_SXS_XML_E_MISSING_PAREN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","missing","paren","manifest","parse","parenthesis"],"errorCode":"14044","eventId":"","severity":"Low","summary":"Manifest Parse Error : Missing parenthesis.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14044; use the surrounding log entries to confirm it.","resolution":"1. Record where 14044 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_MISSING_PAREN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14044 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : Missing parenthesis.\n\nLookup forms: 14044, 0x36DC, error 14044, ERROR_SXS_XML_E_MISSING_PAREN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14044"]},{"id":2532,"title":"ERROR_SXS_XML_E_EXPECTINGCLOSEQUOTE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14045","0x36DD","error 14045","ERROR_SXS_XML_E_EXPECTINGCLOSEQUOTE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","expectingclosequote","manifest","parse","single","double","closing","quote","character","missing"],"errorCode":"14045","eventId":"","severity":"Low","summary":"Manifest Parse Error : A single or double closing quote character (\\' or \\\") is missing.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14045; use the surrounding log entries to confirm it.","resolution":"1. Record where 14045 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_EXPECTINGCLOSEQUOTE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14045 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : A single or double closing quote character (\\' or \\\") is missing.\n\nLookup forms: 14045, 0x36DD, error 14045, ERROR_SXS_XML_E_EXPECTINGCLOSEQUOTE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14045"]},{"id":2533,"title":"ERROR_SXS_XML_E_MULTIPLE_COLONS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14046","0x36DE","error 14046","ERROR_SXS_XML_E_MULTIPLE_COLONS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","multiple","colons","manifest","parse","are","not","allowed","name"],"errorCode":"14046","eventId":"","severity":"Low","summary":"Manifest Parse Error : Multiple colons are not allowed in a name.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14046; use the surrounding log entries to confirm it.","resolution":"1. Record where 14046 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_MULTIPLE_COLONS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14046 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : Multiple colons are not allowed in a name.\n\nLookup forms: 14046, 0x36DE, error 14046, ERROR_SXS_XML_E_MULTIPLE_COLONS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14046"]},{"id":2534,"title":"ERROR_SXS_XML_E_INVALID_DECIMAL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14047","0x36DF","error 14047","ERROR_SXS_XML_E_INVALID_DECIMAL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","invalid","decimal","manifest","parse","character","for","digit"],"errorCode":"14047","eventId":"","severity":"Medium","summary":"Manifest Parse Error : Invalid character for decimal digit.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14047; use the surrounding log entries to confirm it.","resolution":"1. Record where 14047 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_INVALID_DECIMAL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14047 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : Invalid character for decimal digit.\n\nLookup forms: 14047, 0x36DF, error 14047, ERROR_SXS_XML_E_INVALID_DECIMAL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14047"]},{"id":2535,"title":"ERROR_SXS_XML_E_INVALID_HEXIDECIMAL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14048","0x36E0","error 14048","ERROR_SXS_XML_E_INVALID_HEXIDECIMAL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","invalid","hexidecimal","manifest","parse","character","for","hexadecimal","digit"],"errorCode":"14048","eventId":"","severity":"Medium","summary":"Manifest Parse Error : Invalid character for hexadecimal digit.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14048; use the surrounding log entries to confirm it.","resolution":"1. Record where 14048 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_INVALID_HEXIDECIMAL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14048 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : Invalid character for hexadecimal digit.\n\nLookup forms: 14048, 0x36E0, error 14048, ERROR_SXS_XML_E_INVALID_HEXIDECIMAL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14048"]},{"id":2536,"title":"ERROR_SXS_XML_E_INVALID_UNICODE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14049","0x36E1","error 14049","ERROR_SXS_XML_E_INVALID_UNICODE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","invalid","unicode","manifest","parse","character","value","for","this","platform"],"errorCode":"14049","eventId":"","severity":"Medium","summary":"Manifest Parse Error : Invalid unicode character value for this platform.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14049; use the surrounding log entries to confirm it.","resolution":"1. Record where 14049 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_INVALID_UNICODE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14049 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : Invalid unicode character value for this platform.\n\nLookup forms: 14049, 0x36E1, error 14049, ERROR_SXS_XML_E_INVALID_UNICODE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Manifest Parse Error : Invalid Unicode character value for this platform.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14049"]},{"id":2537,"title":"ERROR_SXS_XML_E_WHITESPACEORQUESTIONMARK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14050","0x36E2","error 14050","ERROR_SXS_XML_E_WHITESPACEORQUESTIONMARK","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","whitespaceorquestionmark","manifest","parse","expecting","whitespace"],"errorCode":"14050","eventId":"","severity":"Low","summary":"Manifest Parse Error : Expecting whitespace or '?'.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14050; use the surrounding log entries to confirm it.","resolution":"1. Record where 14050 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_WHITESPACEORQUESTIONMARK.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14050 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : Expecting whitespace or '?'.\n\nLookup forms: 14050, 0x36E2, error 14050, ERROR_SXS_XML_E_WHITESPACEORQUESTIONMARK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Manifest Parse Error : Expecting white space or '?'.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14050"]},{"id":2538,"title":"ERROR_SXS_XML_E_UNEXPECTEDENDTAG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14051","0x36E3","error 14051","ERROR_SXS_XML_E_UNEXPECTEDENDTAG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","unexpectedendtag","manifest","parse","end","tag","was","not","expected","this","location"],"errorCode":"14051","eventId":"","severity":"Low","summary":"Manifest Parse Error : End tag was not expected at this location.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14051; use the surrounding log entries to confirm it.","resolution":"1. Record where 14051 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_UNEXPECTEDENDTAG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14051 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : End tag was not expected at this location.\n\nLookup forms: 14051, 0x36E3, error 14051, ERROR_SXS_XML_E_UNEXPECTEDENDTAG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14051"]},{"id":2539,"title":"ERROR_SXS_XML_E_UNCLOSEDTAG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14052","0x36E4","error 14052","ERROR_SXS_XML_E_UNCLOSEDTAG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","unclosedtag","manifest","parse","the","following","tags","were","not","closed"],"errorCode":"14052","eventId":"","severity":"Low","summary":"Manifest Parse Error : The following tags were not closed: %1.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14052; use the surrounding log entries to confirm it.","resolution":"1. Record where 14052 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_UNCLOSEDTAG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14052 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : The following tags were not closed: %1.\n\nLookup forms: 14052, 0x36E4, error 14052, ERROR_SXS_XML_E_UNCLOSEDTAG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14052"]},{"id":2540,"title":"ERROR_SXS_XML_E_DUPLICATEATTRIBUTE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14053","0x36E5","error 14053","ERROR_SXS_XML_E_DUPLICATEATTRIBUTE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","duplicateattribute","manifest","parse","duplicate","attribute"],"errorCode":"14053","eventId":"","severity":"Low","summary":"Manifest Parse Error : Duplicate attribute.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14053; use the surrounding log entries to confirm it.","resolution":"1. Record where 14053 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_DUPLICATEATTRIBUTE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14053 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : Duplicate attribute.\n\nLookup forms: 14053, 0x36E5, error 14053, ERROR_SXS_XML_E_DUPLICATEATTRIBUTE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14053"]},{"id":2541,"title":"ERROR_SXS_XML_E_MULTIPLEROOTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14054","0x36E6","error 14054","ERROR_SXS_XML_E_MULTIPLEROOTS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","multipleroots","manifest","parse","only","one","top","level","element","allowed","document"],"errorCode":"14054","eventId":"","severity":"Low","summary":"Manifest Parse Error : Only one top level element is allowed in an XML document.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14054; use the surrounding log entries to confirm it.","resolution":"1. Record where 14054 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_MULTIPLEROOTS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14054 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : Only one top level element is allowed in an XML document.\n\nLookup forms: 14054, 0x36E6, error 14054, ERROR_SXS_XML_E_MULTIPLEROOTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14054"]},{"id":2542,"title":"ERROR_SXS_XML_E_INVALIDATROOTLEVEL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14055","0x36E7","error 14055","ERROR_SXS_XML_E_INVALIDATROOTLEVEL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","invalidatrootlevel","manifest","parse","invalid","the","top","level","document"],"errorCode":"14055","eventId":"","severity":"Medium","summary":"Manifest Parse Error : Invalid at the top level of the document.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14055; use the surrounding log entries to confirm it.","resolution":"1. Record where 14055 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_INVALIDATROOTLEVEL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14055 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : Invalid at the top level of the document.\n\nLookup forms: 14055, 0x36E7, error 14055, ERROR_SXS_XML_E_INVALIDATROOTLEVEL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14055"]},{"id":2543,"title":"ERROR_SXS_XML_E_BADXMLDECL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14056","0x36E8","error 14056","ERROR_SXS_XML_E_BADXMLDECL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","badxmldecl","manifest","parse","invalid","declaration"],"errorCode":"14056","eventId":"","severity":"Medium","summary":"Manifest Parse Error : Invalid xml declaration.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14056; use the surrounding log entries to confirm it.","resolution":"1. Record where 14056 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_BADXMLDECL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14056 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : Invalid xml declaration.\n\nLookup forms: 14056, 0x36E8, error 14056, ERROR_SXS_XML_E_BADXMLDECL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Manifest Parse Error : Invalid XML declaration.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14056"]},{"id":2544,"title":"ERROR_SXS_XML_E_MISSINGROOT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14057","0x36E9","error 14057","ERROR_SXS_XML_E_MISSINGROOT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","missingroot","manifest","parse","document","must","have","top","level","element"],"errorCode":"14057","eventId":"","severity":"Low","summary":"Manifest Parse Error : XML document must have a top level element.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14057; use the surrounding log entries to confirm it.","resolution":"1. Record where 14057 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_MISSINGROOT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14057 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : XML document must have a top level element.\n\nLookup forms: 14057, 0x36E9, error 14057, ERROR_SXS_XML_E_MISSINGROOT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14057"]},{"id":2545,"title":"ERROR_SXS_XML_E_UNEXPECTEDEOF","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14058","0x36EA","error 14058","ERROR_SXS_XML_E_UNEXPECTEDEOF","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","sxs","xml","unexpectedeof","manifest","parse","unexpected","end","file"],"errorCode":"14058","eventId":"","severity":"Low","summary":"Manifest Parse Error : Unexpected end of file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 14058; use the surrounding log entries to confirm it.","resolution":"1. Record where 14058 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_UNEXPECTEDEOF.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14058 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : Unexpected end of file.\n\nLookup forms: 14058, 0x36EA, error 14058, ERROR_SXS_XML_E_UNEXPECTEDEOF. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14058"]},{"id":2546,"title":"ERROR_SXS_XML_E_BADPEREFINSUBSET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14059","0x36EB","error 14059","ERROR_SXS_XML_E_BADPEREFINSUBSET","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","badperefinsubset","manifest","parse","parameter","entities","cannot","used","inside","markup","declarations","internal","subset"],"errorCode":"14059","eventId":"","severity":"Medium","summary":"Manifest Parse Error : Parameter entities cannot be used inside markup declarations in an internal subset.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14059; use the surrounding log entries to confirm it.","resolution":"1. Record where 14059 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_BADPEREFINSUBSET.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14059 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : Parameter entities cannot be used inside markup declarations in an internal subset.\n\nLookup forms: 14059, 0x36EB, error 14059, ERROR_SXS_XML_E_BADPEREFINSUBSET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14059"]},{"id":2547,"title":"ERROR_SXS_XML_E_UNCLOSEDSTARTTAG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14060","0x36EC","error 14060","ERROR_SXS_XML_E_UNCLOSEDSTARTTAG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","unclosedstarttag","manifest","parse","element","was","not","closed"],"errorCode":"14060","eventId":"","severity":"Low","summary":"Manifest Parse Error : Element was not closed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14060; use the surrounding log entries to confirm it.","resolution":"1. Record where 14060 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_UNCLOSEDSTARTTAG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14060 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : Element was not closed.\n\nLookup forms: 14060, 0x36EC, error 14060, ERROR_SXS_XML_E_UNCLOSEDSTARTTAG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14060"]},{"id":2548,"title":"ERROR_SXS_XML_E_UNCLOSEDENDTAG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14061","0x36ED","error 14061","ERROR_SXS_XML_E_UNCLOSEDENDTAG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","unclosedendtag","manifest","parse","end","element","was","missing","the","character"],"errorCode":"14061","eventId":"","severity":"Low","summary":"Manifest Parse Error : End element was missing the character '>'.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14061; use the surrounding log entries to confirm it.","resolution":"1. Record where 14061 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_UNCLOSEDENDTAG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14061 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : End element was missing the character '>'.\n\nLookup forms: 14061, 0x36ED, error 14061, ERROR_SXS_XML_E_UNCLOSEDENDTAG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14061"]},{"id":2549,"title":"ERROR_SXS_XML_E_UNCLOSEDSTRING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14062","0x36EE","error 14062","ERROR_SXS_XML_E_UNCLOSEDSTRING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","unclosedstring","manifest","parse","string","literal","was","not","closed"],"errorCode":"14062","eventId":"","severity":"Low","summary":"Manifest Parse Error : A string literal was not closed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14062; use the surrounding log entries to confirm it.","resolution":"1. Record where 14062 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_UNCLOSEDSTRING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14062 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : A string literal was not closed.\n\nLookup forms: 14062, 0x36EE, error 14062, ERROR_SXS_XML_E_UNCLOSEDSTRING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14062"]},{"id":2550,"title":"ERROR_SXS_XML_E_UNCLOSEDCOMMENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14063","0x36EF","error 14063","ERROR_SXS_XML_E_UNCLOSEDCOMMENT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","unclosedcomment","manifest","parse","comment","was","not","closed"],"errorCode":"14063","eventId":"","severity":"Low","summary":"Manifest Parse Error : A comment was not closed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14063; use the surrounding log entries to confirm it.","resolution":"1. Record where 14063 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_UNCLOSEDCOMMENT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14063 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : A comment was not closed.\n\nLookup forms: 14063, 0x36EF, error 14063, ERROR_SXS_XML_E_UNCLOSEDCOMMENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14063"]},{"id":2551,"title":"ERROR_SXS_XML_E_UNCLOSEDDECL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14064","0x36F0","error 14064","ERROR_SXS_XML_E_UNCLOSEDDECL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","uncloseddecl","manifest","parse","declaration","was","not","closed"],"errorCode":"14064","eventId":"","severity":"Low","summary":"Manifest Parse Error : A declaration was not closed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14064; use the surrounding log entries to confirm it.","resolution":"1. Record where 14064 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_UNCLOSEDDECL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14064 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : A declaration was not closed.\n\nLookup forms: 14064, 0x36F0, error 14064, ERROR_SXS_XML_E_UNCLOSEDDECL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14064"]},{"id":2552,"title":"ERROR_SXS_XML_E_UNCLOSEDCDATA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14065","0x36F1","error 14065","ERROR_SXS_XML_E_UNCLOSEDCDATA","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","unclosedcdata","manifest","parse","cdata","section","was","not","closed"],"errorCode":"14065","eventId":"","severity":"Low","summary":"Manifest Parse Error : A CDATA section was not closed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14065; use the surrounding log entries to confirm it.","resolution":"1. Record where 14065 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_UNCLOSEDCDATA.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14065 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : A CDATA section was not closed.\n\nLookup forms: 14065, 0x36F1, error 14065, ERROR_SXS_XML_E_UNCLOSEDCDATA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14065"]},{"id":2553,"title":"ERROR_SXS_XML_E_RESERVEDNAMESPACE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14066","0x36F2","error 14066","ERROR_SXS_XML_E_RESERVEDNAMESPACE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","reservednamespace","manifest","parse","the","namespace","prefix","not","allowed","start","with","reserved","string"],"errorCode":"14066","eventId":"","severity":"Low","summary":"Manifest Parse Error : The namespace prefix is not allowed to start with the reserved string \"xml\".","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14066; use the surrounding log entries to confirm it.","resolution":"1. Record where 14066 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_RESERVEDNAMESPACE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14066 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : The namespace prefix is not allowed to start with the reserved string \"xml\".\n\nLookup forms: 14066, 0x36F2, error 14066, ERROR_SXS_XML_E_RESERVEDNAMESPACE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14066"]},{"id":2554,"title":"ERROR_SXS_XML_E_INVALIDENCODING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14067","0x36F3","error 14067","ERROR_SXS_XML_E_INVALIDENCODING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","invalidencoding","manifest","parse","system","does","not","support","the","specified","encoding"],"errorCode":"14067","eventId":"","severity":"Low","summary":"Manifest Parse Error : System does not support the specified encoding.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14067; use the surrounding log entries to confirm it.","resolution":"1. Record where 14067 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_INVALIDENCODING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14067 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : System does not support the specified encoding.\n\nLookup forms: 14067, 0x36F3, error 14067, ERROR_SXS_XML_E_INVALIDENCODING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14067"]},{"id":2555,"title":"ERROR_SXS_XML_E_INVALIDSWITCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14068","0x36F4","error 14068","ERROR_SXS_XML_E_INVALIDSWITCH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","invalidswitch","manifest","parse","switch","from","current","encoding","specified","not","supported"],"errorCode":"14068","eventId":"","severity":"Medium","summary":"Manifest Parse Error : Switch from current encoding to specified encoding not supported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14068; use the surrounding log entries to confirm it.","resolution":"1. Record where 14068 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_INVALIDSWITCH.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14068 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : Switch from current encoding to specified encoding not supported.\n\nLookup forms: 14068, 0x36F4, error 14068, ERROR_SXS_XML_E_INVALIDSWITCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14068"]},{"id":2556,"title":"ERROR_SXS_XML_E_BADXMLCASE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14069","0x36F5","error 14069","ERROR_SXS_XML_E_BADXMLCASE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","badxmlcase","manifest","parse","the","name","reserved","and","must","lower","case"],"errorCode":"14069","eventId":"","severity":"Low","summary":"Manifest Parse Error : The name 'xml' is reserved and must be lower case.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14069; use the surrounding log entries to confirm it.","resolution":"1. Record where 14069 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_BADXMLCASE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14069 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : The name 'xml' is reserved and must be lower case.\n\nLookup forms: 14069, 0x36F5, error 14069, ERROR_SXS_XML_E_BADXMLCASE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14069"]},{"id":2557,"title":"ERROR_SXS_XML_E_INVALID_STANDALONE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14070","0x36F6","error 14070","ERROR_SXS_XML_E_INVALID_STANDALONE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","invalid","standalone","manifest","parse","the","attribute","must","have","value","yes"],"errorCode":"14070","eventId":"","severity":"Low","summary":"Manifest Parse Error : The standalone attribute must have the value 'yes' or 'no'.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14070; use the surrounding log entries to confirm it.","resolution":"1. Record where 14070 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_INVALID_STANDALONE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14070 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : The standalone attribute must have the value 'yes' or 'no'.\n\nLookup forms: 14070, 0x36F6, error 14070, ERROR_SXS_XML_E_INVALID_STANDALONE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14070"]},{"id":2558,"title":"ERROR_SXS_XML_E_UNEXPECTED_STANDALONE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14071","0x36F7","error 14071","ERROR_SXS_XML_E_UNEXPECTED_STANDALONE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","unexpected","standalone","manifest","parse","the","attribute","cannot","used","external","entities"],"errorCode":"14071","eventId":"","severity":"Medium","summary":"Manifest Parse Error : The standalone attribute cannot be used in external entities.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14071; use the surrounding log entries to confirm it.","resolution":"1. Record where 14071 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_UNEXPECTED_STANDALONE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14071 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : The standalone attribute cannot be used in external entities.\n\nLookup forms: 14071, 0x36F7, error 14071, ERROR_SXS_XML_E_UNEXPECTED_STANDALONE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14071"]},{"id":2559,"title":"ERROR_SXS_XML_E_INVALID_VERSION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14072","0x36F8","error 14072","ERROR_SXS_XML_E_INVALID_VERSION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","invalid","version","manifest","parse","number"],"errorCode":"14072","eventId":"","severity":"Medium","summary":"Manifest Parse Error : Invalid version number.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14072; use the surrounding log entries to confirm it.","resolution":"1. Record where 14072 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_INVALID_VERSION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14072 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : Invalid version number.\n\nLookup forms: 14072, 0x36F8, error 14072, ERROR_SXS_XML_E_INVALID_VERSION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14072"]},{"id":2560,"title":"ERROR_SXS_XML_E_MISSINGEQUALS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14073","0x36F9","error 14073","ERROR_SXS_XML_E_MISSINGEQUALS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","xml","missingequals","manifest","parse","missing","equals","sign","between","attribute","and","value"],"errorCode":"14073","eventId":"","severity":"Low","summary":"Manifest Parse Error : Missing equals sign between attribute and attribute value.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14073; use the surrounding log entries to confirm it.","resolution":"1. Record where 14073 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_XML_E_MISSINGEQUALS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14073 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Manifest Parse Error : Missing equals sign between attribute and attribute value.\n\nLookup forms: 14073, 0x36F9, error 14073, ERROR_SXS_XML_E_MISSINGEQUALS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14073"]},{"id":2561,"title":"ERROR_SXS_PROTECTION_RECOVERY_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14074","0x36FA","error 14074","ERROR_SXS_PROTECTION_RECOVERY_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","protection","recovery","failed","assembly","unable","recover","the","specified"],"errorCode":"14074","eventId":"","severity":"Medium","summary":"Assembly Protection Error : Unable to recover the specified assembly.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14074; use the surrounding log entries to confirm it.","resolution":"1. Record where 14074 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_PROTECTION_RECOVERY_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14074 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Assembly Protection Error : Unable to recover the specified assembly.\n\nLookup forms: 14074, 0x36FA, error 14074, ERROR_SXS_PROTECTION_RECOVERY_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Assembly Protection Error: Unable to recover the specified assembly.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14074"]},{"id":2562,"title":"ERROR_SXS_PROTECTION_PUBLIC_KEY_TOO_SHORT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14075","0x36FB","error 14075","ERROR_SXS_PROTECTION_PUBLIC_KEY_TOO_SHORT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","protection","public","key","too","short","assembly","the","for","was","allowed"],"errorCode":"14075","eventId":"","severity":"Low","summary":"Assembly Protection Error : The public key for an assembly was too short to be allowed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14075; use the surrounding log entries to confirm it.","resolution":"1. Record where 14075 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_PROTECTION_PUBLIC_KEY_TOO_SHORT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14075 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Assembly Protection Error : The public key for an assembly was too short to be allowed.\n\nLookup forms: 14075, 0x36FB, error 14075, ERROR_SXS_PROTECTION_PUBLIC_KEY_TOO_SHORT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Assembly Protection Error: The public key for an assembly was too short to be allowed.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14075"]},{"id":2563,"title":"ERROR_SXS_PROTECTION_CATALOG_NOT_VALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14076","0x36FC","error 14076","ERROR_SXS_PROTECTION_CATALOG_NOT_VALID","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","protection","catalog","not","valid","assembly","the","for","does","match","manifest"],"errorCode":"14076","eventId":"","severity":"Low","summary":"Assembly Protection Error : The catalog for an assembly is not valid, or does not match the assembly's manifest.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14076; use the surrounding log entries to confirm it.","resolution":"1. Record where 14076 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_PROTECTION_CATALOG_NOT_VALID.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14076 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Assembly Protection Error : The catalog for an assembly is not valid, or does not match the assembly's manifest.\n\nLookup forms: 14076, 0x36FC, error 14076, ERROR_SXS_PROTECTION_CATALOG_NOT_VALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Assembly Protection Error: The catalog for an assembly is not valid, or does not match the assembly's manifest.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14076"]},{"id":2564,"title":"ERROR_SXS_UNTRANSLATABLE_HRESULT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14077","0x36FD","error 14077","ERROR_SXS_UNTRANSLATABLE_HRESULT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","untranslatable","hresult","could","not","translated","corresponding","win32","code"],"errorCode":"14077","eventId":"","severity":"Low","summary":"An HRESULT could not be translated to a corresponding Win32 error code.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14077; use the surrounding log entries to confirm it.","resolution":"1. Record where 14077 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_UNTRANSLATABLE_HRESULT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14077 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An HRESULT could not be translated to a corresponding Win32 error code.\n\nLookup forms: 14077, 0x36FD, error 14077, ERROR_SXS_UNTRANSLATABLE_HRESULT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14077"]},{"id":2565,"title":"ERROR_SXS_PROTECTION_CATALOG_FILE_MISSING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14078","0x36FE","error 14078","ERROR_SXS_PROTECTION_CATALOG_FILE_MISSING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","protection","catalog","file","missing","assembly","the","for"],"errorCode":"14078","eventId":"","severity":"Low","summary":"Assembly Protection Error : The catalog for an assembly is missing.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14078; use the surrounding log entries to confirm it.","resolution":"1. Record where 14078 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_PROTECTION_CATALOG_FILE_MISSING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14078 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Assembly Protection Error : The catalog for an assembly is missing.\n\nLookup forms: 14078, 0x36FE, error 14078, ERROR_SXS_PROTECTION_CATALOG_FILE_MISSING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (ivanti_error_codes.pdf): Assembly Protection Error: The catalog for an assembly is missing.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14078"]},{"id":2566,"title":"ERROR_SXS_MISSING_ASSEMBLY_IDENTITY_ATTRIBUTE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14079","0x36FF","error 14079","ERROR_SXS_MISSING_ASSEMBLY_IDENTITY_ATTRIBUTE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","missing","assembly","identity","attribute","the","supplied","one","more","attributes","which","must","present","this","context"],"errorCode":"14079","eventId":"","severity":"Low","summary":"The supplied assembly identity is missing one or more attributes which must be present in this context.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14079; use the surrounding log entries to confirm it.","resolution":"1. Record where 14079 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_MISSING_ASSEMBLY_IDENTITY_ATTRIBUTE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14079 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The supplied assembly identity is missing one or more attributes which must be present in this context.\n\nLookup forms: 14079, 0x36FF, error 14079, ERROR_SXS_MISSING_ASSEMBLY_IDENTITY_ATTRIBUTE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14079"]},{"id":2567,"title":"ERROR_SXS_INVALID_ASSEMBLY_IDENTITY_ATTRIBUTE_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14080","0x3700","error 14080","ERROR_SXS_INVALID_ASSEMBLY_IDENTITY_ATTRIBUTE_NAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","invalid","assembly","identity","attribute","name","the","supplied","has","one","more","names","that","contain","characters","not","permitted","xml"],"errorCode":"14080","eventId":"","severity":"Low","summary":"The supplied assembly identity has one or more attribute names that contain characters not permitted in XML names.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14080; use the surrounding log entries to confirm it.","resolution":"1. Record where 14080 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_INVALID_ASSEMBLY_IDENTITY_ATTRIBUTE_NAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14080 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The supplied assembly identity has one or more attribute names that contain characters not permitted in XML names.\n\nLookup forms: 14080, 0x3700, error 14080, ERROR_SXS_INVALID_ASSEMBLY_IDENTITY_ATTRIBUTE_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14080"]},{"id":2568,"title":"ERROR_SXS_ASSEMBLY_MISSING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14081","0x3701","error 14081","ERROR_SXS_ASSEMBLY_MISSING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","assembly","missing","the","referenced","could","not","found"],"errorCode":"14081","eventId":"","severity":"Low","summary":"The referenced assembly could not be found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14081; use the surrounding log entries to confirm it.","resolution":"1. Record where 14081 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_ASSEMBLY_MISSING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14081 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The referenced assembly could not be found.\n\nLookup forms: 14081, 0x3701, error 14081, ERROR_SXS_ASSEMBLY_MISSING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14081"]},{"id":2569,"title":"ERROR_SXS_CORRUPT_ACTIVATION_STACK","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14082","0x3702","error 14082","ERROR_SXS_CORRUPT_ACTIVATION_STACK","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","sxs","corrupt","activation","stack","the","context","for","running","thread","execution"],"errorCode":"14082","eventId":"","severity":"Critical","summary":"The activation context activation stack for the running thread of execution is corrupt.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 14082; use the surrounding log entries to confirm it.","resolution":"1. Record where 14082 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_CORRUPT_ACTIVATION_STACK.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14082 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The activation context activation stack for the running thread of execution is corrupt.\n\nLookup forms: 14082, 0x3702, error 14082, ERROR_SXS_CORRUPT_ACTIVATION_STACK. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14082"]},{"id":2570,"title":"ERROR_SXS_CORRUPTION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14083","0x3703","error 14083","ERROR_SXS_CORRUPTION","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","sxs","corruption","the","application","isolation","metadata","for","this","process","thread","has","become","corrupt"],"errorCode":"14083","eventId":"","severity":"Critical","summary":"The application isolation metadata for this process or thread has become corrupt.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 14083; use the surrounding log entries to confirm it.","resolution":"1. Record where 14083 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_CORRUPTION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14083 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The application isolation metadata for this process or thread has become corrupt.\n\nLookup forms: 14083, 0x3703, error 14083, ERROR_SXS_CORRUPTION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14083"]},{"id":2571,"title":"ERROR_SXS_EARLY_DEACTIVATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14084","0x3704","error 14084","ERROR_SXS_EARLY_DEACTIVATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","early","deactivation","the","activation","context","being","deactivated","not","most","recently","activated","one"],"errorCode":"14084","eventId":"","severity":"Low","summary":"The activation context being deactivated is not the most recently activated one.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14084; use the surrounding log entries to confirm it.","resolution":"1. Record where 14084 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_EARLY_DEACTIVATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14084 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The activation context being deactivated is not the most recently activated one.\n\nLookup forms: 14084, 0x3704, error 14084, ERROR_SXS_EARLY_DEACTIVATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14084"]},{"id":2572,"title":"ERROR_SXS_INVALID_DEACTIVATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14085","0x3705","error 14085","ERROR_SXS_INVALID_DEACTIVATION","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","sxs","invalid","deactivation","the","activation","context","being","deactivated","not","active","for","current","thread","execution"],"errorCode":"14085","eventId":"","severity":"Low","summary":"The activation context being deactivated is not active for the current thread of execution.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 14085; use the surrounding log entries to confirm it.","resolution":"1. Record where 14085 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_INVALID_DEACTIVATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14085 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The activation context being deactivated is not active for the current thread of execution.\n\nLookup forms: 14085, 0x3705, error 14085, ERROR_SXS_INVALID_DEACTIVATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14085"]},{"id":2573,"title":"ERROR_SXS_MULTIPLE_DEACTIVATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14086","0x3706","error 14086","ERROR_SXS_MULTIPLE_DEACTIVATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","multiple","deactivation","the","activation","context","being","deactivated","has","already","been"],"errorCode":"14086","eventId":"","severity":"Low","summary":"The activation context being deactivated has already been deactivated.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14086; use the surrounding log entries to confirm it.","resolution":"1. Record where 14086 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_MULTIPLE_DEACTIVATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14086 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The activation context being deactivated has already been deactivated.\n\nLookup forms: 14086, 0x3706, error 14086, ERROR_SXS_MULTIPLE_DEACTIVATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14086"]},{"id":2574,"title":"ERROR_SXS_PROCESS_TERMINATION_REQUESTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14087","0x3707","error 14087","ERROR_SXS_PROCESS_TERMINATION_REQUESTED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","sxs","process","termination","requested","component","used","the","isolation","facility","has","terminate"],"errorCode":"14087","eventId":"","severity":"Low","summary":"A component used by the isolation facility has requested to terminate the process.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 14087; use the surrounding log entries to confirm it.","resolution":"1. Record where 14087 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_PROCESS_TERMINATION_REQUESTED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14087 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A component used by the isolation facility has requested to terminate the process.\n\nLookup forms: 14087, 0x3707, error 14087, ERROR_SXS_PROCESS_TERMINATION_REQUESTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14087"]},{"id":2575,"title":"ERROR_SXS_RELEASE_ACTIVATION_CONTEXT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14088","0x3708","error 14088","ERROR_SXS_RELEASE_ACTIVATION_CONTEXT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","release","activation","context","kernel","mode","component","releasing","reference"],"errorCode":"14088","eventId":"","severity":"Low","summary":"A kernel mode component is releasing a reference on an activation context.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14088; use the surrounding log entries to confirm it.","resolution":"1. Record where 14088 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_RELEASE_ACTIVATION_CONTEXT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14088 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A kernel mode component is releasing a reference on an activation context.\n\nLookup forms: 14088, 0x3708, error 14088, ERROR_SXS_RELEASE_ACTIVATION_CONTEXT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14088"]},{"id":2576,"title":"ERROR_SXS_SYSTEM_DEFAULT_ACTIVATION_CONTEXT_EMPTY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14089","0x3709","error 14089","ERROR_SXS_SYSTEM_DEFAULT_ACTIVATION_CONTEXT_EMPTY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","system","default","activation","context","empty","the","assembly","could","not","generated"],"errorCode":"14089","eventId":"","severity":"Low","summary":"The activation context of system default assembly could not be generated.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14089; use the surrounding log entries to confirm it.","resolution":"1. Record where 14089 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_SYSTEM_DEFAULT_ACTIVATION_CONTEXT_EMPTY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14089 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The activation context of system default assembly could not be generated.\n\nLookup forms: 14089, 0x3709, error 14089, ERROR_SXS_SYSTEM_DEFAULT_ACTIVATION_CONTEXT_EMPTY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14089"]},{"id":2577,"title":"ERROR_SXS_INVALID_IDENTITY_ATTRIBUTE_VALUE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14090","0x370A","error 14090","ERROR_SXS_INVALID_IDENTITY_ATTRIBUTE_VALUE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","invalid","identity","attribute","value","the","not","within","legal","range"],"errorCode":"14090","eventId":"","severity":"Low","summary":"The value of an attribute in an identity is not within the legal range.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14090; use the surrounding log entries to confirm it.","resolution":"1. Record where 14090 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_INVALID_IDENTITY_ATTRIBUTE_VALUE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14090 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The value of an attribute in an identity is not within the legal range.\n\nLookup forms: 14090, 0x370A, error 14090, ERROR_SXS_INVALID_IDENTITY_ATTRIBUTE_VALUE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14090"]},{"id":2578,"title":"ERROR_SXS_INVALID_IDENTITY_ATTRIBUTE_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14091","0x370B","error 14091","ERROR_SXS_INVALID_IDENTITY_ATTRIBUTE_NAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","invalid","identity","attribute","name","the","not","within","legal","range"],"errorCode":"14091","eventId":"","severity":"Low","summary":"The name of an attribute in an identity is not within the legal range.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14091; use the surrounding log entries to confirm it.","resolution":"1. Record where 14091 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_INVALID_IDENTITY_ATTRIBUTE_NAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14091 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The name of an attribute in an identity is not within the legal range.\n\nLookup forms: 14091, 0x370B, error 14091, ERROR_SXS_INVALID_IDENTITY_ATTRIBUTE_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14091"]},{"id":2579,"title":"ERROR_SXS_IDENTITY_DUPLICATE_ATTRIBUTE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14092","0x370C","error 14092","ERROR_SXS_IDENTITY_DUPLICATE_ATTRIBUTE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","identity","duplicate","attribute","contains","two","definitions","for","the","same"],"errorCode":"14092","eventId":"","severity":"Low","summary":"An identity contains two definitions for the same attribute.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14092; use the surrounding log entries to confirm it.","resolution":"1. Record where 14092 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_IDENTITY_DUPLICATE_ATTRIBUTE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14092 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An identity contains two definitions for the same attribute.\n\nLookup forms: 14092, 0x370C, error 14092, ERROR_SXS_IDENTITY_DUPLICATE_ATTRIBUTE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14092"]},{"id":2580,"title":"ERROR_SXS_IDENTITY_PARSE_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14093","0x370D","error 14093","ERROR_SXS_IDENTITY_PARSE_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","identity","parse","the","string","malformed","this","may","due","trailing","comma","more","than","two","unnamed","attributes","missing","attribute","name","value"],"errorCode":"14093","eventId":"","severity":"Low","summary":"The identity string is malformed. This may be due to a trailing comma, more than two unnamed attributes, missing attribute name or missing attribute value.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14093; use the surrounding log entries to confirm it.","resolution":"1. Record where 14093 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_IDENTITY_PARSE_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14093 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The identity string is malformed. This may be due to a trailing comma, more than two unnamed attributes, missing attribute name or missing attribute value.\n\nLookup forms: 14093, 0x370D, error 14093, ERROR_SXS_IDENTITY_PARSE_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14093"]},{"id":2581,"title":"ERROR_MALFORMED_SUBSTITUTION_STRING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14094","0x370E","error 14094","ERROR_MALFORMED_SUBSTITUTION_STRING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","malformed","substitution","string","containing","localized","substitutable","content","was","either","dollar","sign","followed","something","other","than","left","parenthesis","another","right","not","found"],"errorCode":"14094","eventId":"","severity":"Medium","summary":"A string containing localized substitutable content was malformed. Either a dollar sign ($) was followed by something other than a left parenthesis or another dollar sign or an substitution's right parenthesis was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14094; use the surrounding log entries to confirm it.","resolution":"1. Record where 14094 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MALFORMED_SUBSTITUTION_STRING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14094 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A string containing localized substitutable content was malformed. Either a dollar sign ($) was followed by something other than a left parenthesis or another dollar sign or an substitution's right parenthesis was not found.\n\nLookup forms: 14094, 0x370E, error 14094, ERROR_MALFORMED_SUBSTITUTION_STRING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14094"]},{"id":2582,"title":"ERROR_SXS_INCORRECT_PUBLIC_KEY_TOKEN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14095","0x370F","error 14095","ERROR_SXS_INCORRECT_PUBLIC_KEY_TOKEN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","incorrect","public","key","token","the","does","not","correspond","specified"],"errorCode":"14095","eventId":"","severity":"Low","summary":"The public key token does not correspond to the public key specified.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14095; use the surrounding log entries to confirm it.","resolution":"1. Record where 14095 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_INCORRECT_PUBLIC_KEY_TOKEN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14095 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The public key token does not correspond to the public key specified.\n\nLookup forms: 14095, 0x370F, error 14095, ERROR_SXS_INCORRECT_PUBLIC_KEY_TOKEN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14095"]},{"id":2583,"title":"ERROR_UNMAPPED_SUBSTITUTION_STRING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14096","0x3710","error 14096","ERROR_UNMAPPED_SUBSTITUTION_STRING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","unmapped","substitution","string","had","mapping"],"errorCode":"14096","eventId":"","severity":"Low","summary":"A substitution string had no mapping.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14096; use the surrounding log entries to confirm it.","resolution":"1. Record where 14096 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_UNMAPPED_SUBSTITUTION_STRING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14096 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A substitution string had no mapping.\n\nLookup forms: 14096, 0x3710, error 14096, ERROR_UNMAPPED_SUBSTITUTION_STRING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14096"]},{"id":2584,"title":"ERROR_SXS_ASSEMBLY_NOT_LOCKED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14097","0x3711","error 14097","ERROR_SXS_ASSEMBLY_NOT_LOCKED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","assembly","not","locked","the","component","must","before","making","request"],"errorCode":"14097","eventId":"","severity":"High","summary":"The component must be locked before making the request.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14097; use the surrounding log entries to confirm it.","resolution":"1. Record where 14097 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_ASSEMBLY_NOT_LOCKED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14097 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The component must be locked before making the request.\n\nLookup forms: 14097, 0x3711, error 14097, ERROR_SXS_ASSEMBLY_NOT_LOCKED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14097"]},{"id":2585,"title":"ERROR_SXS_COMPONENT_STORE_CORRUPT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14098","0x3712","error 14098","ERROR_SXS_COMPONENT_STORE_CORRUPT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","component","store","corrupt","the","has","been","corrupted"],"errorCode":"14098","eventId":"","severity":"Critical","summary":"The component store has been corrupted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14098; use the surrounding log entries to confirm it.","resolution":"1. Record where 14098 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_COMPONENT_STORE_CORRUPT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14098 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The component store has been corrupted.\n\nLookup forms: 14098, 0x3712, error 14098, ERROR_SXS_COMPONENT_STORE_CORRUPT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14098"]},{"id":2586,"title":"ERROR_ADVANCED_INSTALLER_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14099","0x3713","error 14099","ERROR_ADVANCED_INSTALLER_FAILED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","advanced","installer","failed","during","setup","servicing"],"errorCode":"14099","eventId":"","severity":"High","summary":"An advanced installer failed during setup or servicing.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 14099; use the surrounding log entries to confirm it.","resolution":"1. Record where 14099 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ADVANCED_INSTALLER_FAILED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14099 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An advanced installer failed during setup or servicing.\n\nLookup forms: 14099, 0x3713, error 14099, ERROR_ADVANCED_INSTALLER_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14099"]},{"id":2587,"title":"ERROR_XML_ENCODING_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14100","0x3714","error 14100","ERROR_XML_ENCODING_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","xml","encoding","mismatch","the","character","declaration","did","not","match","used","document"],"errorCode":"14100","eventId":"","severity":"Low","summary":"The character encoding in the XML declaration did not match the encoding used in the document.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14100; use the surrounding log entries to confirm it.","resolution":"1. Record where 14100 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_XML_ENCODING_MISMATCH.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14100 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The character encoding in the XML declaration did not match the encoding used in the document.\n\nLookup forms: 14100, 0x3714, error 14100, ERROR_XML_ENCODING_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14100"]},{"id":2588,"title":"ERROR_SXS_MANIFEST_IDENTITY_SAME_BUT_CONTENTS_DIFFERENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14101","0x3715","error 14101","ERROR_SXS_MANIFEST_IDENTITY_SAME_BUT_CONTENTS_DIFFERENT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","manifest","identity","same","but","contents","different","the","identities","manifests","are","identical","their"],"errorCode":"14101","eventId":"","severity":"Low","summary":"The identities of the manifests are identical but their contents are different.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14101; use the surrounding log entries to confirm it.","resolution":"1. Record where 14101 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_MANIFEST_IDENTITY_SAME_BUT_CONTENTS_DIFFERENT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14101 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The identities of the manifests are identical but their contents are different.\n\nLookup forms: 14101, 0x3715, error 14101, ERROR_SXS_MANIFEST_IDENTITY_SAME_BUT_CONTENTS_DIFFERENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14101"]},{"id":2589,"title":"ERROR_SXS_IDENTITIES_DIFFERENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14102","0x3716","error 14102","ERROR_SXS_IDENTITIES_DIFFERENT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","identities","different","the","component","are"],"errorCode":"14102","eventId":"","severity":"Low","summary":"The component identities are different.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14102; use the surrounding log entries to confirm it.","resolution":"1. Record where 14102 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_IDENTITIES_DIFFERENT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14102 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The component identities are different.\n\nLookup forms: 14102, 0x3716, error 14102, ERROR_SXS_IDENTITIES_DIFFERENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14102"]},{"id":2590,"title":"ERROR_SXS_ASSEMBLY_IS_NOT_A_DEPLOYMENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14103","0x3717","error 14103","ERROR_SXS_ASSEMBLY_IS_NOT_A_DEPLOYMENT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","assembly","not","deployment","the"],"errorCode":"14103","eventId":"","severity":"Low","summary":"The assembly is not a deployment.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14103; use the surrounding log entries to confirm it.","resolution":"1. Record where 14103 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_ASSEMBLY_IS_NOT_A_DEPLOYMENT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14103 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The assembly is not a deployment.\n\nLookup forms: 14103, 0x3717, error 14103, ERROR_SXS_ASSEMBLY_IS_NOT_A_DEPLOYMENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14103"]},{"id":2591,"title":"ERROR_SXS_FILE_NOT_PART_OF_ASSEMBLY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14104","0x3718","error 14104","ERROR_SXS_FILE_NOT_PART_OF_ASSEMBLY","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","sxs","file","not","part","assembly","the"],"errorCode":"14104","eventId":"","severity":"Low","summary":"The file is not a part of the assembly.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 14104; use the surrounding log entries to confirm it.","resolution":"1. Record where 14104 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_FILE_NOT_PART_OF_ASSEMBLY.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14104 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file is not a part of the assembly.\n\nLookup forms: 14104, 0x3718, error 14104, ERROR_SXS_FILE_NOT_PART_OF_ASSEMBLY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14104"]},{"id":2592,"title":"ERROR_SXS_MANIFEST_TOO_BIG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14105","0x3719","error 14105","ERROR_SXS_MANIFEST_TOO_BIG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","manifest","too","big","the","size","exceeds","maximum","allowed"],"errorCode":"14105","eventId":"","severity":"Low","summary":"The size of the manifest exceeds the maximum allowed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14105; use the surrounding log entries to confirm it.","resolution":"1. Record where 14105 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_MANIFEST_TOO_BIG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14105 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The size of the manifest exceeds the maximum allowed.\n\nLookup forms: 14105, 0x3719, error 14105, ERROR_SXS_MANIFEST_TOO_BIG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14105"]},{"id":2593,"title":"ERROR_SXS_SETTING_NOT_REGISTERED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14106","0x371A","error 14106","ERROR_SXS_SETTING_NOT_REGISTERED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","setting","not","registered","the"],"errorCode":"14106","eventId":"","severity":"Low","summary":"The setting is not registered.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14106; use the surrounding log entries to confirm it.","resolution":"1. Record where 14106 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_SETTING_NOT_REGISTERED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14106 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The setting is not registered.\n\nLookup forms: 14106, 0x371A, error 14106, ERROR_SXS_SETTING_NOT_REGISTERED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14106"]},{"id":2594,"title":"ERROR_SXS_TRANSACTION_CLOSURE_INCOMPLETE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14107","0x371B","error 14107","ERROR_SXS_TRANSACTION_CLOSURE_INCOMPLETE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","sxs","transaction","closure","incomplete","one","more","required","members","the","are","not","present"],"errorCode":"14107","eventId":"","severity":"Low","summary":"One or more required members of the transaction are not present.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14107; use the surrounding log entries to confirm it.","resolution":"1. Record where 14107 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_TRANSACTION_CLOSURE_INCOMPLETE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14107 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: One or more required members of the transaction are not present.\n\nLookup forms: 14107, 0x371B, error 14107, ERROR_SXS_TRANSACTION_CLOSURE_INCOMPLETE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14107"]},{"id":2595,"title":"ERROR_SMI_PRIMITIVE_INSTALLER_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14108","0x371C","error 14108","ERROR_SMI_PRIMITIVE_INSTALLER_FAILED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","smi","primitive","installer","failed","the","during","setup","servicing"],"errorCode":"14108","eventId":"","severity":"High","summary":"The SMI primitive installer failed during setup or servicing.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 14108; use the surrounding log entries to confirm it.","resolution":"1. Record where 14108 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SMI_PRIMITIVE_INSTALLER_FAILED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14108 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The SMI primitive installer failed during setup or servicing.\n\nLookup forms: 14108, 0x371C, error 14108, ERROR_SMI_PRIMITIVE_INSTALLER_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14108"]},{"id":2596,"title":"ERROR_GENERIC_COMMAND_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14109","0x371D","error 14109","ERROR_GENERIC_COMMAND_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","generic","command","failed","executable","returned","result","that","indicates","failure"],"errorCode":"14109","eventId":"","severity":"High","summary":"A generic command executable returned a result that indicates failure.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 14109; use the surrounding log entries to confirm it.","resolution":"1. Record where 14109 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_GENERIC_COMMAND_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14109 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A generic command executable returned a result that indicates failure.\n\nLookup forms: 14109, 0x371D, error 14109, ERROR_GENERIC_COMMAND_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14109"]},{"id":2597,"title":"ERROR_SXS_FILE_HASH_MISSING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["14110","0x371E","error 14110","ERROR_SXS_FILE_HASH_MISSING","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","sxs","file","hash","missing","component","verification","information","its","manifest"],"errorCode":"14110","eventId":"","severity":"Low","summary":"A component is missing file verification information in its manifest.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 14110; use the surrounding log entries to confirm it.","resolution":"1. Record where 14110 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SXS_FILE_HASH_MISSING.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 14110 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A component is missing file verification information in its manifest.\n\nLookup forms: 14110, 0x371E, error 14110, ERROR_SXS_FILE_HASH_MISSING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["14110"]},{"id":2598,"title":"ERROR_EVT_INVALID_CHANNEL_PATH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15000","0x3A98","error 15000","ERROR_EVT_INVALID_CHANNEL_PATH","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","evt","invalid","channel","path","the","specified"],"errorCode":"15000","eventId":"","severity":"Medium","summary":"The specified channel path is invalid.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 15000; use the surrounding log entries to confirm it.","resolution":"1. Record where 15000 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_INVALID_CHANNEL_PATH.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15000 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified channel path is invalid.\n\nLookup forms: 15000, 0x3A98, error 15000, ERROR_EVT_INVALID_CHANNEL_PATH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15000"]},{"id":2599,"title":"ERROR_EVT_INVALID_QUERY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15001","0x3A99","error 15001","ERROR_EVT_INVALID_QUERY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","invalid","query","the","specified"],"errorCode":"15001","eventId":"","severity":"Medium","summary":"The specified query is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15001; use the surrounding log entries to confirm it.","resolution":"1. Record where 15001 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_INVALID_QUERY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15001 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified query is invalid.\n\nLookup forms: 15001, 0x3A99, error 15001, ERROR_EVT_INVALID_QUERY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15001"]},{"id":2600,"title":"ERROR_EVT_PUBLISHER_METADATA_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15002","0x3A9A","error 15002","ERROR_EVT_PUBLISHER_METADATA_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","publisher","metadata","not","found","the","cannot","resource"],"errorCode":"15002","eventId":"","severity":"Medium","summary":"The publisher metadata cannot be found in the resource.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15002; use the surrounding log entries to confirm it.","resolution":"1. Record where 15002 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_PUBLISHER_METADATA_NOT_FOUND.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15002 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The publisher metadata cannot be found in the resource.\n\nLookup forms: 15002, 0x3A9A, error 15002, ERROR_EVT_PUBLISHER_METADATA_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15002"]},{"id":2601,"title":"ERROR_EVT_EVENT_TEMPLATE_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15003","0x3A9B","error 15003","ERROR_EVT_EVENT_TEMPLATE_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","event","template","not","found","the","for","definition","cannot","resource"],"errorCode":"15003","eventId":"","severity":"Medium","summary":"The template for an event definition cannot be found in the resource (error = %1).","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15003; use the surrounding log entries to confirm it.","resolution":"1. Record where 15003 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_EVENT_TEMPLATE_NOT_FOUND.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15003 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The template for an event definition cannot be found in the resource (error = %1).\n\nLookup forms: 15003, 0x3A9B, error 15003, ERROR_EVT_EVENT_TEMPLATE_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15003"]},{"id":2602,"title":"ERROR_EVT_INVALID_PUBLISHER_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15004","0x3A9C","error 15004","ERROR_EVT_INVALID_PUBLISHER_NAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","invalid","publisher","name","the","specified"],"errorCode":"15004","eventId":"","severity":"Medium","summary":"The specified publisher name is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15004; use the surrounding log entries to confirm it.","resolution":"1. Record where 15004 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_INVALID_PUBLISHER_NAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15004 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified publisher name is invalid.\n\nLookup forms: 15004, 0x3A9C, error 15004, ERROR_EVT_INVALID_PUBLISHER_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15004"]},{"id":2603,"title":"ERROR_EVT_INVALID_EVENT_DATA","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15005","0x3A9D","error 15005","ERROR_EVT_INVALID_EVENT_DATA","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","invalid","event","data","the","raised","publisher","not","compatible","with","template","definition","manifest"],"errorCode":"15005","eventId":"","severity":"Low","summary":"The event data raised by the publisher is not compatible with the event template definition in the publisher's manifest.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15005; use the surrounding log entries to confirm it.","resolution":"1. Record where 15005 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_INVALID_EVENT_DATA.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15005 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The event data raised by the publisher is not compatible with the event template definition in the publisher's manifest.\n\nLookup forms: 15005, 0x3A9D, error 15005, ERROR_EVT_INVALID_EVENT_DATA. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15005"]},{"id":2604,"title":"ERROR_EVT_CHANNEL_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15007","0x3A9F","error 15007","ERROR_EVT_CHANNEL_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","channel","not","found","the","specified","could","check","configuration"],"errorCode":"15007","eventId":"","severity":"Low","summary":"The specified channel could not be found. Check channel configuration.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15007; use the surrounding log entries to confirm it.","resolution":"1. Record where 15007 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_CHANNEL_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15007 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified channel could not be found. Check channel configuration.\n\nLookup forms: 15007, 0x3A9F, error 15007, ERROR_EVT_CHANNEL_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15007"]},{"id":2605,"title":"ERROR_EVT_MALFORMED_XML_TEXT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15008","0x3AA0","error 15008","ERROR_EVT_MALFORMED_XML_TEXT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","malformed","xml","text","the","specified","was","not","well","formed","see","extended","for","more","details"],"errorCode":"15008","eventId":"","severity":"Low","summary":"The specified xml text was not well-formed. See Extended Error for more details.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15008; use the surrounding log entries to confirm it.","resolution":"1. Record where 15008 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_MALFORMED_XML_TEXT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15008 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified xml text was not well-formed. See Extended Error for more details.\n\nLookup forms: 15008, 0x3AA0, error 15008, ERROR_EVT_MALFORMED_XML_TEXT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15008"]},{"id":2606,"title":"ERROR_EVT_SUBSCRIPTION_TO_DIRECT_CHANNEL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15009","0x3AA1","error 15009","ERROR_EVT_SUBSCRIPTION_TO_DIRECT_CHANNEL","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","evt","subscription","direct","channel","the","caller","trying","subscribe","which","not","allowed","events","for","directly","logfile","and","cannot","subscribed"],"errorCode":"15009","eventId":"","severity":"Medium","summary":"The caller is trying to subscribe to a direct channel which is not allowed. The events for a direct channel go directly to a logfile and cannot be subscribed to.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 15009; use the surrounding log entries to confirm it.","resolution":"1. Record where 15009 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_SUBSCRIPTION_TO_DIRECT_CHANNEL.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15009 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The caller is trying to subscribe to a direct channel which is not allowed. The events for a direct channel go directly to a logfile and cannot be subscribed to.\n\nLookup forms: 15009, 0x3AA1, error 15009, ERROR_EVT_SUBSCRIPTION_TO_DIRECT_CHANNEL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15009"]},{"id":2607,"title":"ERROR_EVT_CONFIGURATION_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15010","0x3AA2","error 15010","ERROR_EVT_CONFIGURATION_ERROR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","configuration"],"errorCode":"15010","eventId":"","severity":"Low","summary":"Configuration error.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15010; use the surrounding log entries to confirm it.","resolution":"1. Record where 15010 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_CONFIGURATION_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15010 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Configuration error.\n\nLookup forms: 15010, 0x3AA2, error 15010, ERROR_EVT_CONFIGURATION_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15010"]},{"id":2608,"title":"ERROR_EVT_QUERY_RESULT_STALE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15011","0x3AA3","error 15011","ERROR_EVT_QUERY_RESULT_STALE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","evt","query","result","stale","the","invalid","this","may","due","log","being","cleared","rolling","over","after","was","created","users","should","handle","code","releasing","object","and"],"errorCode":"15011","eventId":"","severity":"Medium","summary":"The query result is stale / invalid. This may be due to the log being cleared or rolling over after the query result was created. Users should handle this code by releasing the query result object and reissuing the query.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 15011; use the surrounding log entries to confirm it.","resolution":"1. Record where 15011 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_QUERY_RESULT_STALE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15011 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The query result is stale / invalid. This may be due to the log being cleared or rolling over after the query result was created. Users should handle this code by releasing the query result object and reissuing the query.\n\nLookup forms: 15011, 0x3AA3, error 15011, ERROR_EVT_QUERY_RESULT_STALE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15011"]},{"id":2609,"title":"ERROR_EVT_QUERY_RESULT_INVALID_POSITION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15012","0x3AA4","error 15012","ERROR_EVT_QUERY_RESULT_INVALID_POSITION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","query","result","invalid","position","currently"],"errorCode":"15012","eventId":"","severity":"Medium","summary":"Query result is currently at an invalid position.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15012; use the surrounding log entries to confirm it.","resolution":"1. Record where 15012 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_QUERY_RESULT_INVALID_POSITION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15012 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Query result is currently at an invalid position.\n\nLookup forms: 15012, 0x3AA4, error 15012, ERROR_EVT_QUERY_RESULT_INVALID_POSITION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15012"]},{"id":2610,"title":"ERROR_EVT_NON_VALIDATING_MSXML","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15013","0x3AA5","error 15013","ERROR_EVT_NON_VALIDATING_MSXML","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","non","validating","msxml","registered","doesn","support","validation"],"errorCode":"15013","eventId":"","severity":"Low","summary":"Registered MSXML doesn't support validation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15013; use the surrounding log entries to confirm it.","resolution":"1. Record where 15013 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_NON_VALIDATING_MSXML.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15013 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Registered MSXML doesn't support validation.\n\nLookup forms: 15013, 0x3AA5, error 15013, ERROR_EVT_NON_VALIDATING_MSXML. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15013"]},{"id":2611,"title":"ERROR_EVT_FILTER_ALREADYSCOPED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15014","0x3AA6","error 15014","ERROR_EVT_FILTER_ALREADYSCOPED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","filter","alreadyscoped","expression","can","only","followed","change","scope","operation","itself","evaluates","node","set","and","not","already","part","some","other"],"errorCode":"15014","eventId":"","severity":"Low","summary":"An expression can only be followed by a change of scope operation if it itself evaluates to a node set and is not already part of some other change of scope operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15014; use the surrounding log entries to confirm it.","resolution":"1. Record where 15014 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_FILTER_ALREADYSCOPED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15014 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An expression can only be followed by a change of scope operation if it itself evaluates to a node set and is not already part of some other change of scope operation.\n\nLookup forms: 15014, 0x3AA6, error 15014, ERROR_EVT_FILTER_ALREADYSCOPED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15014"]},{"id":2612,"title":"ERROR_EVT_FILTER_NOTELTSET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15015","0x3AA7","error 15015","ERROR_EVT_FILTER_NOTELTSET","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","filter","noteltset","can","perform","step","operation","from","term","that","does","not","represent","element","set"],"errorCode":"15015","eventId":"","severity":"Low","summary":"Can't perform a step operation from a term that does not represent an element set.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15015; use the surrounding log entries to confirm it.","resolution":"1. Record where 15015 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_FILTER_NOTELTSET.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15015 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Can't perform a step operation from a term that does not represent an element set.\n\nLookup forms: 15015, 0x3AA7, error 15015, ERROR_EVT_FILTER_NOTELTSET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15015"]},{"id":2613,"title":"ERROR_EVT_FILTER_INVARG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15016","0x3AA8","error 15016","ERROR_EVT_FILTER_INVARG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","filter","invarg","left","hand","side","arguments","binary","operators","must","either","attributes","nodes","variables","and","right","constants"],"errorCode":"15016","eventId":"","severity":"Low","summary":"Left hand side arguments to binary operators must be either attributes, nodes or variables and right hand side arguments must be constants.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15016; use the surrounding log entries to confirm it.","resolution":"1. Record where 15016 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_FILTER_INVARG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15016 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Left hand side arguments to binary operators must be either attributes, nodes or variables and right hand side arguments must be constants.\n\nLookup forms: 15016, 0x3AA8, error 15016, ERROR_EVT_FILTER_INVARG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15016"]},{"id":2614,"title":"ERROR_EVT_FILTER_INVTEST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15017","0x3AA9","error 15017","ERROR_EVT_FILTER_INVTEST","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","filter","invtest","step","operation","must","involve","either","node","test","the","case","predicate","algebraic","expression","against","which","each","set","identified","preceding","can","evaluated"],"errorCode":"15017","eventId":"","severity":"Low","summary":"A step operation must involve either a node test or, in the case of a predicate, an algebraic expression against which to test each node in the node set identified by the preceding node set can be evaluated.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15017; use the surrounding log entries to confirm it.","resolution":"1. Record where 15017 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_FILTER_INVTEST.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15017 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A step operation must involve either a node test or, in the case of a predicate, an algebraic expression against which to test each node in the node set identified by the preceding node set can be evaluated.\n\nLookup forms: 15017, 0x3AA9, error 15017, ERROR_EVT_FILTER_INVTEST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15017"]},{"id":2615,"title":"ERROR_EVT_FILTER_INVTYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15018","0x3AAA","error 15018","ERROR_EVT_FILTER_INVTYPE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","filter","invtype","this","data","type","currently","unsupported"],"errorCode":"15018","eventId":"","severity":"Low","summary":"This data type is currently unsupported.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15018; use the surrounding log entries to confirm it.","resolution":"1. Record where 15018 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_FILTER_INVTYPE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15018 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This data type is currently unsupported.\n\nLookup forms: 15018, 0x3AAA, error 15018, ERROR_EVT_FILTER_INVTYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15018"]},{"id":2616,"title":"ERROR_EVT_FILTER_PARSEERR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15019","0x3AAB","error 15019","ERROR_EVT_FILTER_PARSEERR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","filter","parseerr","syntax","occurred","position"],"errorCode":"15019","eventId":"","severity":"Low","summary":"A syntax error occurred at position %1!d!.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15019; use the surrounding log entries to confirm it.","resolution":"1. Record where 15019 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_FILTER_PARSEERR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15019 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A syntax error occurred at position %1!d!.\n\nLookup forms: 15019, 0x3AAB, error 15019, ERROR_EVT_FILTER_PARSEERR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15019"]},{"id":2617,"title":"ERROR_EVT_FILTER_UNSUPPORTEDOP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15020","0x3AAC","error 15020","ERROR_EVT_FILTER_UNSUPPORTEDOP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","filter","unsupportedop","this","operator","unsupported","implementation","the"],"errorCode":"15020","eventId":"","severity":"Low","summary":"This operator is unsupported by this implementation of the filter.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15020; use the surrounding log entries to confirm it.","resolution":"1. Record where 15020 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_FILTER_UNSUPPORTEDOP.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15020 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operator is unsupported by this implementation of the filter.\n\nLookup forms: 15020, 0x3AAC, error 15020, ERROR_EVT_FILTER_UNSUPPORTEDOP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15020"]},{"id":2618,"title":"ERROR_EVT_FILTER_UNEXPECTEDTOKEN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15021","0x3AAD","error 15021","ERROR_EVT_FILTER_UNEXPECTEDTOKEN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","filter","unexpectedtoken","the","token","encountered","was","unexpected"],"errorCode":"15021","eventId":"","severity":"Low","summary":"The token encountered was unexpected.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15021; use the surrounding log entries to confirm it.","resolution":"1. Record where 15021 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_FILTER_UNEXPECTEDTOKEN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15021 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The token encountered was unexpected.\n\nLookup forms: 15021, 0x3AAD, error 15021, ERROR_EVT_FILTER_UNEXPECTEDTOKEN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15021"]},{"id":2619,"title":"ERROR_EVT_INVALID_OPERATION_OVER_ENABLED_DIRECT_CHANNEL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15022","0x3AAE","error 15022","ERROR_EVT_INVALID_OPERATION_OVER_ENABLED_DIRECT_CHANNEL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","invalid","operation","over","enabled","direct","channel","the","requested","cannot","performed","must","first","disabled","before","performing"],"errorCode":"15022","eventId":"","severity":"Medium","summary":"The requested operation cannot be performed over an enabled direct channel. The channel must first be disabled before performing the requested operation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15022; use the surrounding log entries to confirm it.","resolution":"1. Record where 15022 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_INVALID_OPERATION_OVER_ENABLED_DIRECT_CHANNEL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15022 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested operation cannot be performed over an enabled direct channel. The channel must first be disabled before performing the requested operation.\n\nLookup forms: 15022, 0x3AAE, error 15022, ERROR_EVT_INVALID_OPERATION_OVER_ENABLED_DIRECT_CHANNEL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15022"]},{"id":2620,"title":"ERROR_EVT_INVALID_CHANNEL_PROPERTY_VALUE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15023","0x3AAF","error 15023","ERROR_EVT_INVALID_CHANNEL_PROPERTY_VALUE","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","evt","invalid","channel","property","value","contains","the","has","type","outside","valid","range","can","updated","not","supported","this"],"errorCode":"15023","eventId":"","severity":"Medium","summary":"Channel property %1!s! contains invalid value. The value has invalid type, is outside of valid range, can't be updated or is not supported by this type of channel.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 15023; use the surrounding log entries to confirm it.","resolution":"1. Record where 15023 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_INVALID_CHANNEL_PROPERTY_VALUE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15023 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Channel property %1!s! contains invalid value. The value has invalid type, is outside of valid range, can't be updated or is not supported by this type of channel.\n\nLookup forms: 15023, 0x3AAF, error 15023, ERROR_EVT_INVALID_CHANNEL_PROPERTY_VALUE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15023"]},{"id":2621,"title":"ERROR_EVT_INVALID_PUBLISHER_PROPERTY_VALUE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15024","0x3AB0","error 15024","ERROR_EVT_INVALID_PUBLISHER_PROPERTY_VALUE","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","evt","invalid","publisher","property","value","contains","the","has","type","outside","valid","range","can","updated","not","supported","this"],"errorCode":"15024","eventId":"","severity":"Medium","summary":"Publisher property %1!s! contains invalid value. The value has invalid type, is outside of valid range, can't be updated or is not supported by this type of publisher.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 15024; use the surrounding log entries to confirm it.","resolution":"1. Record where 15024 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_INVALID_PUBLISHER_PROPERTY_VALUE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15024 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Publisher property %1!s! contains invalid value. The value has invalid type, is outside of valid range, can't be updated or is not supported by this type of publisher.\n\nLookup forms: 15024, 0x3AB0, error 15024, ERROR_EVT_INVALID_PUBLISHER_PROPERTY_VALUE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15024"]},{"id":2622,"title":"ERROR_EVT_CHANNEL_CANNOT_ACTIVATE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15025","0x3AB1","error 15025","ERROR_EVT_CHANNEL_CANNOT_ACTIVATE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","channel","cannot","activate","the","fails"],"errorCode":"15025","eventId":"","severity":"Low","summary":"The channel fails to activate.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15025; use the surrounding log entries to confirm it.","resolution":"1. Record where 15025 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_CHANNEL_CANNOT_ACTIVATE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15025 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The channel fails to activate.\n\nLookup forms: 15025, 0x3AB1, error 15025, ERROR_EVT_CHANNEL_CANNOT_ACTIVATE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15025"]},{"id":2623,"title":"ERROR_EVT_FILTER_TOO_COMPLEX","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15026","0x3AB2","error 15026","ERROR_EVT_FILTER_TOO_COMPLEX","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","evt","filter","too","complex","the","xpath","expression","exceeded","supported","complexity","please","simplify","split","into","two","more","simple","expressions"],"errorCode":"15026","eventId":"","severity":"Low","summary":"The xpath expression exceeded supported complexity. Please simplify it or split it into two or more simple expressions.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 15026; use the surrounding log entries to confirm it.","resolution":"1. Record where 15026 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_FILTER_TOO_COMPLEX.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15026 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The xpath expression exceeded supported complexity. Please simplify it or split it into two or more simple expressions.\n\nLookup forms: 15026, 0x3AB2, error 15026, ERROR_EVT_FILTER_TOO_COMPLEX. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15026"]},{"id":2624,"title":"ERROR_EVT_MESSAGE_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15027","0x3AB3","error 15027","ERROR_EVT_MESSAGE_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","message","not","found","the","resource","present","but","string","table"],"errorCode":"15027","eventId":"","severity":"Medium","summary":"the message resource is present but the message is not found in the string/message table.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15027; use the surrounding log entries to confirm it.","resolution":"1. Record where 15027 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_MESSAGE_NOT_FOUND.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15027 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: the message resource is present but the message is not found in the string/message table.\n\nLookup forms: 15027, 0x3AB3, error 15027, ERROR_EVT_MESSAGE_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15027"]},{"id":2625,"title":"ERROR_EVT_MESSAGE_ID_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15028","0x3AB4","error 15028","ERROR_EVT_MESSAGE_ID_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","message","not","found","the","for","desired","could"],"errorCode":"15028","eventId":"","severity":"Low","summary":"The message id for the desired message could not be found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15028; use the surrounding log entries to confirm it.","resolution":"1. Record where 15028 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_MESSAGE_ID_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15028 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The message id for the desired message could not be found.\n\nLookup forms: 15028, 0x3AB4, error 15028, ERROR_EVT_MESSAGE_ID_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15028"]},{"id":2626,"title":"ERROR_EVT_UNRESOLVED_VALUE_INSERT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15029","0x3AB5","error 15029","ERROR_EVT_UNRESOLVED_VALUE_INSERT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","unresolved","value","insert","the","substitution","string","for","index","could","not","found"],"errorCode":"15029","eventId":"","severity":"Low","summary":"The substitution string for insert index (%1) could not be found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15029; use the surrounding log entries to confirm it.","resolution":"1. Record where 15029 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_UNRESOLVED_VALUE_INSERT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15029 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The substitution string for insert index (%1) could not be found.\n\nLookup forms: 15029, 0x3AB5, error 15029, ERROR_EVT_UNRESOLVED_VALUE_INSERT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15029"]},{"id":2627,"title":"ERROR_EVT_UNRESOLVED_PARAMETER_INSERT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15030","0x3AB6","error 15030","ERROR_EVT_UNRESOLVED_PARAMETER_INSERT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","unresolved","parameter","insert","the","description","string","for","reference","could","not","found"],"errorCode":"15030","eventId":"","severity":"Low","summary":"The description string for parameter reference (%1) could not be found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15030; use the surrounding log entries to confirm it.","resolution":"1. Record where 15030 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_UNRESOLVED_PARAMETER_INSERT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15030 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The description string for parameter reference (%1) could not be found.\n\nLookup forms: 15030, 0x3AB6, error 15030, ERROR_EVT_UNRESOLVED_PARAMETER_INSERT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15030"]},{"id":2628,"title":"ERROR_EVT_MAX_INSERTS_REACHED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15031","0x3AB7","error 15031","ERROR_EVT_MAX_INSERTS_REACHED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","max","inserts","reached","the","maximum","number","replacements","has","been"],"errorCode":"15031","eventId":"","severity":"Low","summary":"The maximum number of replacements has been reached.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15031; use the surrounding log entries to confirm it.","resolution":"1. Record where 15031 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_MAX_INSERTS_REACHED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15031 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The maximum number of replacements has been reached.\n\nLookup forms: 15031, 0x3AB7, error 15031, ERROR_EVT_MAX_INSERTS_REACHED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15031"]},{"id":2629,"title":"ERROR_EVT_EVENT_DEFINITION_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15032","0x3AB8","error 15032","ERROR_EVT_EVENT_DEFINITION_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","event","definition","not","found","the","could","for"],"errorCode":"15032","eventId":"","severity":"Low","summary":"The event definition could not be found for event id (%1).","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15032; use the surrounding log entries to confirm it.","resolution":"1. Record where 15032 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_EVENT_DEFINITION_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15032 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The event definition could not be found for event id (%1).\n\nLookup forms: 15032, 0x3AB8, error 15032, ERROR_EVT_EVENT_DEFINITION_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15032"]},{"id":2630,"title":"ERROR_EVT_MESSAGE_LOCALE_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15033","0x3AB9","error 15033","ERROR_EVT_MESSAGE_LOCALE_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","message","locale","not","found","the","specific","resource","for","desired","present"],"errorCode":"15033","eventId":"","severity":"Low","summary":"The locale specific resource for the desired message is not present.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15033; use the surrounding log entries to confirm it.","resolution":"1. Record where 15033 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_MESSAGE_LOCALE_NOT_FOUND.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15033 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The locale specific resource for the desired message is not present.\n\nLookup forms: 15033, 0x3AB9, error 15033, ERROR_EVT_MESSAGE_LOCALE_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15033"]},{"id":2631,"title":"ERROR_EVT_VERSION_TOO_OLD","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15034","0x3ABA","error 15034","ERROR_EVT_VERSION_TOO_OLD","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","version","too","old","the","resource","compatible"],"errorCode":"15034","eventId":"","severity":"Low","summary":"The resource is too old to be compatible.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15034; use the surrounding log entries to confirm it.","resolution":"1. Record where 15034 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_VERSION_TOO_OLD.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15034 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The resource is too old to be compatible.\n\nLookup forms: 15034, 0x3ABA, error 15034, ERROR_EVT_VERSION_TOO_OLD. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15034"]},{"id":2632,"title":"ERROR_EVT_VERSION_TOO_NEW","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15035","0x3ABB","error 15035","ERROR_EVT_VERSION_TOO_NEW","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","version","too","new","the","resource","compatible"],"errorCode":"15035","eventId":"","severity":"Low","summary":"The resource is too new to be compatible.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15035; use the surrounding log entries to confirm it.","resolution":"1. Record where 15035 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_VERSION_TOO_NEW.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15035 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The resource is too new to be compatible.\n\nLookup forms: 15035, 0x3ABB, error 15035, ERROR_EVT_VERSION_TOO_NEW. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15035"]},{"id":2633,"title":"ERROR_EVT_CANNOT_OPEN_CHANNEL_OF_QUERY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15036","0x3ABC","error 15036","ERROR_EVT_CANNOT_OPEN_CHANNEL_OF_QUERY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","cannot","open","channel","query","the","index","can","opened"],"errorCode":"15036","eventId":"","severity":"Low","summary":"The channel at index %1!d! of the query can't be opened.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15036; use the surrounding log entries to confirm it.","resolution":"1. Record where 15036 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_CANNOT_OPEN_CHANNEL_OF_QUERY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15036 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The channel at index %1!d! of the query can't be opened.\n\nLookup forms: 15036, 0x3ABC, error 15036, ERROR_EVT_CANNOT_OPEN_CHANNEL_OF_QUERY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15036"]},{"id":2634,"title":"ERROR_EVT_PUBLISHER_DISABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15037","0x3ABD","error 15037","ERROR_EVT_PUBLISHER_DISABLED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","evt","publisher","disabled","the","has","been","and","its","resource","not","available","this","usually","occurs","when","process","being","uninstalled","upgraded"],"errorCode":"15037","eventId":"","severity":"Low","summary":"The publisher has been disabled and its resource is not available. This usually occurs when the publisher is in the process of being uninstalled or upgraded.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 15037; use the surrounding log entries to confirm it.","resolution":"1. Record where 15037 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_PUBLISHER_DISABLED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15037 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The publisher has been disabled and its resource is not available. This usually occurs when the publisher is in the process of being uninstalled or upgraded.\n\nLookup forms: 15037, 0x3ABD, error 15037, ERROR_EVT_PUBLISHER_DISABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15037"]},{"id":2635,"title":"ERROR_EVT_FILTER_OUT_OF_RANGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15038","0x3ABE","error 15038","ERROR_EVT_FILTER_OUT_OF_RANGE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","evt","filter","out","range","attempted","create","numeric","type","that","outside","its","valid"],"errorCode":"15038","eventId":"","severity":"Low","summary":"Attempted to create a numeric type that is outside of its valid range.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15038; use the surrounding log entries to confirm it.","resolution":"1. Record where 15038 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EVT_FILTER_OUT_OF_RANGE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15038 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Attempted to create a numeric type that is outside of its valid range.\n\nLookup forms: 15038, 0x3ABE, error 15038, ERROR_EVT_FILTER_OUT_OF_RANGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15038"]},{"id":2636,"title":"ERROR_EC_SUBSCRIPTION_CANNOT_ACTIVATE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15080","0x3AE8","error 15080","ERROR_EC_SUBSCRIPTION_CANNOT_ACTIVATE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","subscription","cannot","activate","the","fails"],"errorCode":"15080","eventId":"","severity":"Low","summary":"The subscription fails to activate.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15080; use the surrounding log entries to confirm it.","resolution":"1. Record where 15080 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EC_SUBSCRIPTION_CANNOT_ACTIVATE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15080 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The subscription fails to activate.\n\nLookup forms: 15080, 0x3AE8, error 15080, ERROR_EC_SUBSCRIPTION_CANNOT_ACTIVATE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15080"]},{"id":2637,"title":"ERROR_EC_LOG_DISABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15081","0x3AE9","error 15081","ERROR_EC_LOG_DISABLED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","log","disabled","the","subscription","state","and","cannot","used","forward","events","must","first","enabled","before","can","activated"],"errorCode":"15081","eventId":"","severity":"Medium","summary":"The log of the subscription is in disabled state, and cannot be used to forward events to. The log must first be enabled before the subscription can be activated.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15081; use the surrounding log entries to confirm it.","resolution":"1. Record where 15081 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EC_LOG_DISABLED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15081 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The log of the subscription is in disabled state, and cannot be used to forward events to. The log must first be enabled before the subscription can be activated.\n\nLookup forms: 15081, 0x3AE9, error 15081, ERROR_EC_LOG_DISABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15081"]},{"id":2638,"title":"ERROR_EC_CIRCULAR_FORWARDING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15082","0x3AEA","error 15082","ERROR_EC_CIRCULAR_FORWARDING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","circular","forwarding","when","events","from","local","machine","itself","the","query","subscription","can","contain","target","log"],"errorCode":"15082","eventId":"","severity":"Low","summary":"When forwarding events from local machine to itself, the query of the subscription can't contain target log of the subscription.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15082; use the surrounding log entries to confirm it.","resolution":"1. Record where 15082 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EC_CIRCULAR_FORWARDING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15082 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: When forwarding events from local machine to itself, the query of the subscription can't contain target log of the subscription.\n\nLookup forms: 15082, 0x3AEA, error 15082, ERROR_EC_CIRCULAR_FORWARDING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15082"]},{"id":2639,"title":"ERROR_EC_CREDSTORE_FULL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15083","0x3AEB","error 15083","ERROR_EC_CREDSTORE_FULL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","credstore","full","the","credential","store","that","used","save","credentials"],"errorCode":"15083","eventId":"","severity":"Low","summary":"The credential store that is used to save credentials is full.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15083; use the surrounding log entries to confirm it.","resolution":"1. Record where 15083 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EC_CREDSTORE_FULL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15083 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The credential store that is used to save credentials is full.\n\nLookup forms: 15083, 0x3AEB, error 15083, ERROR_EC_CREDSTORE_FULL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15083"]},{"id":2640,"title":"ERROR_EC_CRED_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15084","0x3AEC","error 15084","ERROR_EC_CRED_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cred","not","found","the","credential","used","this","subscription","can","store"],"errorCode":"15084","eventId":"","severity":"Low","summary":"The credential used by this subscription can't be found in credential store.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15084; use the surrounding log entries to confirm it.","resolution":"1. Record where 15084 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EC_CRED_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15084 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The credential used by this subscription can't be found in credential store.\n\nLookup forms: 15084, 0x3AEC, error 15084, ERROR_EC_CRED_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15084"]},{"id":2641,"title":"ERROR_EC_NO_ACTIVE_CHANNEL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15085","0x3AED","error 15085","ERROR_EC_NO_ACTIVE_CHANNEL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","active","channel","found","for","the","query"],"errorCode":"15085","eventId":"","severity":"Low","summary":"No active channel is found for the query.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15085; use the surrounding log entries to confirm it.","resolution":"1. Record where 15085 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_EC_NO_ACTIVE_CHANNEL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15085 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No active channel is found for the query.\n\nLookup forms: 15085, 0x3AED, error 15085, ERROR_EC_NO_ACTIVE_CHANNEL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15085"]},{"id":2642,"title":"ERROR_MUI_FILE_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15100","0x3AFC","error 15100","ERROR_MUI_FILE_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","mui","file","not","found","the","resource","loader","failed","find"],"errorCode":"15100","eventId":"","severity":"High","summary":"The resource loader failed to find MUI file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 15100; use the surrounding log entries to confirm it.","resolution":"1. Record where 15100 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MUI_FILE_NOT_FOUND.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15100 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The resource loader failed to find MUI file.\n\nLookup forms: 15100, 0x3AFC, error 15100, ERROR_MUI_FILE_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15100"]},{"id":2643,"title":"ERROR_MUI_INVALID_FILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15101","0x3AFD","error 15101","ERROR_MUI_INVALID_FILE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","mui","invalid","file","the","resource","loader","failed","load","because","fail","pass","validation"],"errorCode":"15101","eventId":"","severity":"High","summary":"The resource loader failed to load MUI file because the file fail to pass validation.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 15101; use the surrounding log entries to confirm it.","resolution":"1. Record where 15101 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MUI_INVALID_FILE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15101 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The resource loader failed to load MUI file because the file fail to pass validation.\n\nLookup forms: 15101, 0x3AFD, error 15101, ERROR_MUI_INVALID_FILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15101"]},{"id":2644,"title":"ERROR_MUI_INVALID_RC_CONFIG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15102","0x3AFE","error 15102","ERROR_MUI_INVALID_RC_CONFIG","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","mui","invalid","config","the","manifest","corrupted","with","garbage","data","unsupported","version","missing","required","item"],"errorCode":"15102","eventId":"","severity":"Critical","summary":"The RC Manifest is corrupted with garbage data or unsupported version or missing required item.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15102; use the surrounding log entries to confirm it.","resolution":"1. Record where 15102 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MUI_INVALID_RC_CONFIG.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15102 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The RC Manifest is corrupted with garbage data or unsupported version or missing required item.\n\nLookup forms: 15102, 0x3AFE, error 15102, ERROR_MUI_INVALID_RC_CONFIG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15102"]},{"id":2645,"title":"ERROR_MUI_INVALID_LOCALE_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15103","0x3AFF","error 15103","ERROR_MUI_INVALID_LOCALE_NAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","mui","invalid","locale","name","the","manifest","has","culture"],"errorCode":"15103","eventId":"","severity":"Medium","summary":"The RC Manifest has invalid culture name.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15103; use the surrounding log entries to confirm it.","resolution":"1. Record where 15103 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MUI_INVALID_LOCALE_NAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15103 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The RC Manifest has invalid culture name.\n\nLookup forms: 15103, 0x3AFF, error 15103, ERROR_MUI_INVALID_LOCALE_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15103"]},{"id":2646,"title":"ERROR_MUI_INVALID_ULTIMATEFALLBACK_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15104","0x3B00","error 15104","ERROR_MUI_INVALID_ULTIMATEFALLBACK_NAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","mui","invalid","ultimatefallback","name","the","manifest","has"],"errorCode":"15104","eventId":"","severity":"Medium","summary":"The RC Manifest has invalid ultimatefallback name.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15104; use the surrounding log entries to confirm it.","resolution":"1. Record where 15104 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MUI_INVALID_ULTIMATEFALLBACK_NAME.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15104 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The RC Manifest has invalid ultimatefallback name.\n\nLookup forms: 15104, 0x3B00, error 15104, ERROR_MUI_INVALID_ULTIMATEFALLBACK_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15104"]},{"id":2647,"title":"ERROR_MUI_FILE_NOT_LOADED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15105","0x3B01","error 15105","ERROR_MUI_FILE_NOT_LOADED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","mui","file","not","loaded","the","resource","loader","cache","doesn","have","entry"],"errorCode":"15105","eventId":"","severity":"Low","summary":"The resource loader cache doesn't have loaded MUI entry.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15105; use the surrounding log entries to confirm it.","resolution":"1. Record where 15105 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MUI_FILE_NOT_LOADED.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15105 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The resource loader cache doesn't have loaded MUI entry.\n\nLookup forms: 15105, 0x3B01, error 15105, ERROR_MUI_FILE_NOT_LOADED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15105"]},{"id":2648,"title":"ERROR_RESOURCE_ENUM_USER_STOP","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15106","0x3B02","error 15106","ERROR_RESOURCE_ENUM_USER_STOP","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","resource","enum","user","stop","stopped","enumeration"],"errorCode":"15106","eventId":"","severity":"Low","summary":"User stopped resource enumeration.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15106; use the surrounding log entries to confirm it.","resolution":"1. Record where 15106 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESOURCE_ENUM_USER_STOP.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15106 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: User stopped resource enumeration.\n\nLookup forms: 15106, 0x3B02, error 15106, ERROR_RESOURCE_ENUM_USER_STOP. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15106"]},{"id":2649,"title":"ERROR_MUI_INTLSETTINGS_UILANG_NOT_INSTALLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15107","0x3B03","error 15107","ERROR_MUI_INTLSETTINGS_UILANG_NOT_INSTALLED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","mui","intlsettings","uilang","not","installed","language","installation","failed"],"errorCode":"15107","eventId":"","severity":"High","summary":"UI language installation failed.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 15107; use the surrounding log entries to confirm it.","resolution":"1. Record where 15107 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MUI_INTLSETTINGS_UILANG_NOT_INSTALLED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15107 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: UI language installation failed.\n\nLookup forms: 15107, 0x3B03, error 15107, ERROR_MUI_INTLSETTINGS_UILANG_NOT_INSTALLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15107"]},{"id":2650,"title":"ERROR_MUI_INTLSETTINGS_INVALID_LOCALE_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15108","0x3B04","error 15108","ERROR_MUI_INTLSETTINGS_INVALID_LOCALE_NAME","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","mui","intlsettings","invalid","locale","name","installation","failed"],"errorCode":"15108","eventId":"","severity":"High","summary":"Locale installation failed.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 15108; use the surrounding log entries to confirm it.","resolution":"1. Record where 15108 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MUI_INTLSETTINGS_INVALID_LOCALE_NAME.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15108 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Locale installation failed.\n\nLookup forms: 15108, 0x3B04, error 15108, ERROR_MUI_INTLSETTINGS_INVALID_LOCALE_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15108"]},{"id":2651,"title":"ERROR_MRM_RUNTIME_NO_DEFAULT_OR_NEUTRAL_RESOURCE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15110","0x3B06","error 15110","ERROR_MRM_RUNTIME_NO_DEFAULT_OR_NEUTRAL_RESOURCE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","mrm","runtime","default","neutral","resource","does","not","have","value"],"errorCode":"15110","eventId":"","severity":"Low","summary":"A resource does not have default or neutral value.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15110; use the surrounding log entries to confirm it.","resolution":"1. Record where 15110 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MRM_RUNTIME_NO_DEFAULT_OR_NEUTRAL_RESOURCE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15110 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A resource does not have default or neutral value.\n\nLookup forms: 15110, 0x3B06, error 15110, ERROR_MRM_RUNTIME_NO_DEFAULT_OR_NEUTRAL_RESOURCE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15110"]},{"id":2652,"title":"ERROR_MRM_INVALID_PRICONFIG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15111","0x3B07","error 15111","ERROR_MRM_INVALID_PRICONFIG","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","mrm","invalid","priconfig","pri","config","file"],"errorCode":"15111","eventId":"","severity":"Medium","summary":"Invalid PRI config file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 15111; use the surrounding log entries to confirm it.","resolution":"1. Record where 15111 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MRM_INVALID_PRICONFIG.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15111 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid PRI config file.\n\nLookup forms: 15111, 0x3B07, error 15111, ERROR_MRM_INVALID_PRICONFIG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15111"]},{"id":2653,"title":"ERROR_MRM_INVALID_FILE_TYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15112","0x3B08","error 15112","ERROR_MRM_INVALID_FILE_TYPE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","mrm","invalid","file","type"],"errorCode":"15112","eventId":"","severity":"Medium","summary":"Invalid file type.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 15112; use the surrounding log entries to confirm it.","resolution":"1. Record where 15112 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MRM_INVALID_FILE_TYPE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15112 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid file type.\n\nLookup forms: 15112, 0x3B08, error 15112, ERROR_MRM_INVALID_FILE_TYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15112"]},{"id":2654,"title":"ERROR_MRM_UNKNOWN_QUALIFIER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15113","0x3B09","error 15113","ERROR_MRM_UNKNOWN_QUALIFIER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","mrm","unknown","qualifier"],"errorCode":"15113","eventId":"","severity":"Low","summary":"Unknown qualifier.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15113; use the surrounding log entries to confirm it.","resolution":"1. Record where 15113 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MRM_UNKNOWN_QUALIFIER.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15113 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unknown qualifier.\n\nLookup forms: 15113, 0x3B09, error 15113, ERROR_MRM_UNKNOWN_QUALIFIER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15113"]},{"id":2655,"title":"ERROR_MRM_INVALID_QUALIFIER_VALUE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15114","0x3B0A","error 15114","ERROR_MRM_INVALID_QUALIFIER_VALUE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","mrm","invalid","qualifier","value"],"errorCode":"15114","eventId":"","severity":"Medium","summary":"Invalid qualifier value.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15114; use the surrounding log entries to confirm it.","resolution":"1. Record where 15114 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MRM_INVALID_QUALIFIER_VALUE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15114 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid qualifier value.\n\nLookup forms: 15114, 0x3B0A, error 15114, ERROR_MRM_INVALID_QUALIFIER_VALUE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15114"]},{"id":2656,"title":"ERROR_MRM_NO_CANDIDATE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15115","0x3B0B","error 15115","ERROR_MRM_NO_CANDIDATE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","mrm","candidate","found"],"errorCode":"15115","eventId":"","severity":"Low","summary":"No Candidate found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15115; use the surrounding log entries to confirm it.","resolution":"1. Record where 15115 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MRM_NO_CANDIDATE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15115 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No Candidate found.\n\nLookup forms: 15115, 0x3B0B, error 15115, ERROR_MRM_NO_CANDIDATE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15115"]},{"id":2657,"title":"ERROR_MRM_NO_MATCH_OR_DEFAULT_CANDIDATE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15116","0x3B0C","error 15116","ERROR_MRM_NO_MATCH_OR_DEFAULT_CANDIDATE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","mrm","match","default","candidate","the","resourcemap","namedresource","has","item","that","does","not","have","neutral","resource"],"errorCode":"15116","eventId":"","severity":"Low","summary":"The ResourceMap or NamedResource has an item that does not have default or neutral resource..","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15116; use the surrounding log entries to confirm it.","resolution":"1. Record where 15116 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MRM_NO_MATCH_OR_DEFAULT_CANDIDATE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15116 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The ResourceMap or NamedResource has an item that does not have default or neutral resource..\n\nLookup forms: 15116, 0x3B0C, error 15116, ERROR_MRM_NO_MATCH_OR_DEFAULT_CANDIDATE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15116"]},{"id":2658,"title":"ERROR_MRM_RESOURCE_TYPE_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15117","0x3B0D","error 15117","ERROR_MRM_RESOURCE_TYPE_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","mrm","resource","type","mismatch","invalid","resourcecandidate"],"errorCode":"15117","eventId":"","severity":"Medium","summary":"Invalid ResourceCandidate type.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15117; use the surrounding log entries to confirm it.","resolution":"1. Record where 15117 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MRM_RESOURCE_TYPE_MISMATCH.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15117 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid ResourceCandidate type.\n\nLookup forms: 15117, 0x3B0D, error 15117, ERROR_MRM_RESOURCE_TYPE_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15117"]},{"id":2659,"title":"ERROR_MRM_DUPLICATE_MAP_NAME","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15118","0x3B0E","error 15118","ERROR_MRM_DUPLICATE_MAP_NAME","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","mrm","duplicate","map","name","resource"],"errorCode":"15118","eventId":"","severity":"Low","summary":"Duplicate Resource Map.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15118; use the surrounding log entries to confirm it.","resolution":"1. Record where 15118 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MRM_DUPLICATE_MAP_NAME.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15118 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Duplicate Resource Map.\n\nLookup forms: 15118, 0x3B0E, error 15118, ERROR_MRM_DUPLICATE_MAP_NAME. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15118"]},{"id":2660,"title":"ERROR_MRM_DUPLICATE_ENTRY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15119","0x3B0F","error 15119","ERROR_MRM_DUPLICATE_ENTRY","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","mrm","duplicate","entry"],"errorCode":"15119","eventId":"","severity":"Low","summary":"Duplicate Entry.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15119; use the surrounding log entries to confirm it.","resolution":"1. Record where 15119 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MRM_DUPLICATE_ENTRY.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15119 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Duplicate Entry.\n\nLookup forms: 15119, 0x3B0F, error 15119, ERROR_MRM_DUPLICATE_ENTRY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15119"]},{"id":2661,"title":"ERROR_MRM_INVALID_RESOURCE_IDENTIFIER","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15120","0x3B10","error 15120","ERROR_MRM_INVALID_RESOURCE_IDENTIFIER","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","mrm","invalid","resource","identifier"],"errorCode":"15120","eventId":"","severity":"Medium","summary":"Invalid Resource Identifier.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15120; use the surrounding log entries to confirm it.","resolution":"1. Record where 15120 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MRM_INVALID_RESOURCE_IDENTIFIER.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15120 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid Resource Identifier.\n\nLookup forms: 15120, 0x3B10, error 15120, ERROR_MRM_INVALID_RESOURCE_IDENTIFIER. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15120"]},{"id":2662,"title":"ERROR_MRM_FILEPATH_TOO_LONG","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15121","0x3B11","error 15121","ERROR_MRM_FILEPATH_TOO_LONG","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","mrm","filepath","too","long"],"errorCode":"15121","eventId":"","severity":"Low","summary":"Filepath too long.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 15121; use the surrounding log entries to confirm it.","resolution":"1. Record where 15121 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MRM_FILEPATH_TOO_LONG.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15121 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Filepath too long.\n\nLookup forms: 15121, 0x3B11, error 15121, ERROR_MRM_FILEPATH_TOO_LONG. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15121"]},{"id":2663,"title":"ERROR_MRM_UNSUPPORTED_DIRECTORY_TYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15122","0x3B12","error 15122","ERROR_MRM_UNSUPPORTED_DIRECTORY_TYPE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","mrm","unsupported","directory","type"],"errorCode":"15122","eventId":"","severity":"Low","summary":"Unsupported directory type.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 15122; use the surrounding log entries to confirm it.","resolution":"1. Record where 15122 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MRM_UNSUPPORTED_DIRECTORY_TYPE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15122 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unsupported directory type.\n\nLookup forms: 15122, 0x3B12, error 15122, ERROR_MRM_UNSUPPORTED_DIRECTORY_TYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15122"]},{"id":2664,"title":"ERROR_MRM_INVALID_PRI_FILE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15126","0x3B16","error 15126","ERROR_MRM_INVALID_PRI_FILE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","mrm","invalid","pri","file"],"errorCode":"15126","eventId":"","severity":"Medium","summary":"Invalid PRI File.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 15126; use the surrounding log entries to confirm it.","resolution":"1. Record where 15126 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MRM_INVALID_PRI_FILE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15126 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid PRI File.\n\nLookup forms: 15126, 0x3B16, error 15126, ERROR_MRM_INVALID_PRI_FILE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15126"]},{"id":2665,"title":"ERROR_MRM_NAMED_RESOURCE_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15127","0x3B17","error 15127","ERROR_MRM_NAMED_RESOURCE_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","mrm","named","resource","not","found","namedresource"],"errorCode":"15127","eventId":"","severity":"Medium","summary":"NamedResource Not Found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15127; use the surrounding log entries to confirm it.","resolution":"1. Record where 15127 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MRM_NAMED_RESOURCE_NOT_FOUND.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15127 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: NamedResource Not Found.\n\nLookup forms: 15127, 0x3B17, error 15127, ERROR_MRM_NAMED_RESOURCE_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15127"]},{"id":2666,"title":"ERROR_MRM_MAP_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15135","0x3B1F","error 15135","ERROR_MRM_MAP_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","mrm","map","not","found","resourcemap"],"errorCode":"15135","eventId":"","severity":"Medium","summary":"ResourceMap Not Found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15135; use the surrounding log entries to confirm it.","resolution":"1. Record where 15135 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MRM_MAP_NOT_FOUND.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15135 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: ResourceMap Not Found.\n\nLookup forms: 15135, 0x3B1F, error 15135, ERROR_MRM_MAP_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15135"]},{"id":2667,"title":"ERROR_MRM_UNSUPPORTED_PROFILE_TYPE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15136","0x3B20","error 15136","ERROR_MRM_UNSUPPORTED_PROFILE_TYPE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","mrm","unsupported","profile","type","mrt"],"errorCode":"15136","eventId":"","severity":"Low","summary":"Unsupported MRT profile type.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 15136; use the surrounding log entries to confirm it.","resolution":"1. Record where 15136 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MRM_UNSUPPORTED_PROFILE_TYPE.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15136 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unsupported MRT profile type.\n\nLookup forms: 15136, 0x3B20, error 15136, ERROR_MRM_UNSUPPORTED_PROFILE_TYPE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15136"]},{"id":2668,"title":"ERROR_MRM_INVALID_QUALIFIER_OPERATOR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15137","0x3B21","error 15137","ERROR_MRM_INVALID_QUALIFIER_OPERATOR","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","mrm","invalid","qualifier","operator"],"errorCode":"15137","eventId":"","severity":"Medium","summary":"Invalid qualifier operator.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15137; use the surrounding log entries to confirm it.","resolution":"1. Record where 15137 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MRM_INVALID_QUALIFIER_OPERATOR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15137 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Invalid qualifier operator.\n\nLookup forms: 15137, 0x3B21, error 15137, ERROR_MRM_INVALID_QUALIFIER_OPERATOR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15137"]},{"id":2669,"title":"ERROR_MRM_INDETERMINATE_QUALIFIER_VALUE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15138","0x3B22","error 15138","ERROR_MRM_INDETERMINATE_QUALIFIER_VALUE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","mrm","indeterminate","qualifier","value","unable","determine","has","not","been","set"],"errorCode":"15138","eventId":"","severity":"Medium","summary":"Unable to determine qualifier value or qualifier value has not been set.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15138; use the surrounding log entries to confirm it.","resolution":"1. Record where 15138 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MRM_INDETERMINATE_QUALIFIER_VALUE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15138 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to determine qualifier value or qualifier value has not been set.\n\nLookup forms: 15138, 0x3B22, error 15138, ERROR_MRM_INDETERMINATE_QUALIFIER_VALUE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15138"]},{"id":2670,"title":"ERROR_MRM_AUTOMERGE_ENABLED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15139","0x3B23","error 15139","ERROR_MRM_AUTOMERGE_ENABLED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","mrm","automerge","enabled","the","pri","file"],"errorCode":"15139","eventId":"","severity":"Low","summary":"Automerge is enabled in the PRI file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 15139; use the surrounding log entries to confirm it.","resolution":"1. Record where 15139 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MRM_AUTOMERGE_ENABLED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15139 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Automerge is enabled in the PRI file.\n\nLookup forms: 15139, 0x3B23, error 15139, ERROR_MRM_AUTOMERGE_ENABLED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15139"]},{"id":2671,"title":"ERROR_MRM_TOO_MANY_RESOURCES","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15140","0x3B24","error 15140","ERROR_MRM_TOO_MANY_RESOURCES","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","mrm","too","many","resources","defined","for","package"],"errorCode":"15140","eventId":"","severity":"Low","summary":"Too many resources defined for package.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 15140; use the surrounding log entries to confirm it.","resolution":"1. Record where 15140 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MRM_TOO_MANY_RESOURCES.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15140 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Too many resources defined for package.\n\nLookup forms: 15140, 0x3B24, error 15140, ERROR_MRM_TOO_MANY_RESOURCES. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15140"]},{"id":2672,"title":"ERROR_MCA_INVALID_CAPABILITIES_STRING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15200","0x3B60","error 15200","ERROR_MCA_INVALID_CAPABILITIES_STRING","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","error","mca","invalid","capabilities","string","the","monitor","returned","ddc","that","did","not","comply","with","access","bus","mccs","revision","specification"],"errorCode":"15200","eventId":"","severity":"Low","summary":"The monitor returned a DDC/CI capabilities string that did not comply with the ACCESS.bus 3.0, DDC/CI 1.1 or MCCS 2 Revision 1 specification.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 15200; use the surrounding log entries to confirm it.","resolution":"1. Record where 15200 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MCA_INVALID_CAPABILITIES_STRING.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15200 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The monitor returned a DDC/CI capabilities string that did not comply with the ACCESS.bus 3.0, DDC/CI 1.1 or MCCS 2 Revision 1 specification.\n\nLookup forms: 15200, 0x3B60, error 15200, ERROR_MCA_INVALID_CAPABILITIES_STRING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15200"]},{"id":2673,"title":"ERROR_MCA_INVALID_VCP_VERSION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15201","0x3B61","error 15201","ERROR_MCA_INVALID_VCP_VERSION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","mca","invalid","vcp","version","the","monitor","0xdf","code","returned","value"],"errorCode":"15201","eventId":"","severity":"Medium","summary":"The monitor's VCP Version (0xDF) VCP code returned an invalid version value.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15201; use the surrounding log entries to confirm it.","resolution":"1. Record where 15201 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MCA_INVALID_VCP_VERSION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15201 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The monitor's VCP Version (0xDF) VCP code returned an invalid version value.\n\nLookup forms: 15201, 0x3B61, error 15201, ERROR_MCA_INVALID_VCP_VERSION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15201"]},{"id":2674,"title":"ERROR_MCA_MONITOR_VIOLATES_MCCS_SPECIFICATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15202","0x3B62","error 15202","ERROR_MCA_MONITOR_VIOLATES_MCCS_SPECIFICATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","mca","monitor","violates","mccs","specification","the","does","not","comply","with","claims","support"],"errorCode":"15202","eventId":"","severity":"Low","summary":"The monitor does not comply with the MCCS specification it claims to support.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15202; use the surrounding log entries to confirm it.","resolution":"1. Record where 15202 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MCA_MONITOR_VIOLATES_MCCS_SPECIFICATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15202 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The monitor does not comply with the MCCS specification it claims to support.\n\nLookup forms: 15202, 0x3B62, error 15202, ERROR_MCA_MONITOR_VIOLATES_MCCS_SPECIFICATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15202"]},{"id":2675,"title":"ERROR_MCA_MCCS_VERSION_MISMATCH","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15203","0x3B63","error 15203","ERROR_MCA_MCCS_VERSION_MISMATCH","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","mca","mccs","version","mismatch","the","monitor","ver","capability","does","not","match","reports","when","vcp","0xdf","code","used"],"errorCode":"15203","eventId":"","severity":"Low","summary":"The MCCS version in a monitor's mccs_ver capability does not match the MCCS version the monitor reports when the VCP Version (0xDF) VCP code is used.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15203; use the surrounding log entries to confirm it.","resolution":"1. Record where 15203 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MCA_MCCS_VERSION_MISMATCH.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15203 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The MCCS version in a monitor's mccs_ver capability does not match the MCCS version the monitor reports when the VCP Version (0xDF) VCP code is used.\n\nLookup forms: 15203, 0x3B63, error 15203, ERROR_MCA_MCCS_VERSION_MISMATCH. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15203"]},{"id":2676,"title":"ERROR_MCA_UNSUPPORTED_MCCS_VERSION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15204","0x3B64","error 15204","ERROR_MCA_UNSUPPORTED_MCCS_VERSION","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","mca","unsupported","mccs","version","the","monitor","configuration","api","only","works","with","monitors","that","support","specification","revision"],"errorCode":"15204","eventId":"","severity":"Low","summary":"The Monitor Configuration API only works with monitors that support the MCCS 1.0 specification, MCCS 2.0 specification or the MCCS 2.0 Revision 1 specification.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 15204; use the surrounding log entries to confirm it.","resolution":"1. Record where 15204 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MCA_UNSUPPORTED_MCCS_VERSION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15204 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Monitor Configuration API only works with monitors that support the MCCS 1.0 specification, MCCS 2.0 specification or the MCCS 2.0 Revision 1 specification.\n\nLookup forms: 15204, 0x3B64, error 15204, ERROR_MCA_UNSUPPORTED_MCCS_VERSION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15204"]},{"id":2677,"title":"ERROR_MCA_INTERNAL_ERROR","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15205","0x3B65","error 15205","ERROR_MCA_INTERNAL_ERROR","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","mca","internal","monitor","configuration","api","occurred"],"errorCode":"15205","eventId":"","severity":"Low","summary":"An internal Monitor Configuration API error occurred.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 15205; use the surrounding log entries to confirm it.","resolution":"1. Record where 15205 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MCA_INTERNAL_ERROR.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15205 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An internal Monitor Configuration API error occurred.\n\nLookup forms: 15205, 0x3B65, error 15205, ERROR_MCA_INTERNAL_ERROR. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15205"]},{"id":2678,"title":"ERROR_MCA_INVALID_TECHNOLOGY_TYPE_RETURNED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15206","0x3B66","error 15206","ERROR_MCA_INVALID_TECHNOLOGY_TYPE_RETURNED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","mca","invalid","technology","type","returned","the","monitor","crt","plasma","and","lcd","tft","are","examples","types","this","implies","that","violated","mccs","revision","specification"],"errorCode":"15206","eventId":"","severity":"Medium","summary":"The monitor returned an invalid monitor technology type. CRT, Plasma and LCD (TFT) are examples of monitor technology types. This error implies that the monitor violated the MCCS 2.0 or MCCS 2.0 Revision 1 specification.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15206; use the surrounding log entries to confirm it.","resolution":"1. Record where 15206 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MCA_INVALID_TECHNOLOGY_TYPE_RETURNED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15206 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The monitor returned an invalid monitor technology type. CRT, Plasma and LCD (TFT) are examples of monitor technology types. This error implies that the monitor violated the MCCS 2.0 or MCCS 2.0 Revision 1 specification.\n\nLookup forms: 15206, 0x3B66, error 15206, ERROR_MCA_INVALID_TECHNOLOGY_TYPE_RETURNED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15206"]},{"id":2679,"title":"ERROR_MCA_UNSUPPORTED_COLOR_TEMPERATURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15207","0x3B67","error 15207","ERROR_MCA_UNSUPPORTED_COLOR_TEMPERATURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","mca","unsupported","color","temperature","the","caller","setmonitorcolortemperature","specified","that","current","monitor","did","not","support","this","implies","violated","mccs","revision","specification"],"errorCode":"15207","eventId":"","severity":"Low","summary":"The caller of SetMonitorColorTemperature specified a color temperature that the current monitor did not support. This error implies that the monitor violated the MCCS 2.0 or MCCS 2.0 Revision 1 specification.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15207; use the surrounding log entries to confirm it.","resolution":"1. Record where 15207 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_MCA_UNSUPPORTED_COLOR_TEMPERATURE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15207 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The caller of SetMonitorColorTemperature specified a color temperature that the current monitor did not support. This error implies that the monitor violated the MCCS 2.0 or MCCS 2.0 Revision 1 specification.\n\nLookup forms: 15207, 0x3B67, error 15207, ERROR_MCA_UNSUPPORTED_COLOR_TEMPERATURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15207"]},{"id":2680,"title":"ERROR_AMBIGUOUS_SYSTEM_DEVICE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15250","0x3B92","error 15250","ERROR_AMBIGUOUS_SYSTEM_DEVICE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","ambiguous","system","device","the","requested","cannot","identified","due","multiple","indistinguishable","devices","potentially","matching","identification","criteria"],"errorCode":"15250","eventId":"","severity":"Medium","summary":"The requested system device cannot be identified due to multiple indistinguishable devices potentially matching the identification criteria.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15250; use the surrounding log entries to confirm it.","resolution":"1. Record where 15250 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_AMBIGUOUS_SYSTEM_DEVICE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15250 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested system device cannot be identified due to multiple indistinguishable devices potentially matching the identification criteria.\n\nLookup forms: 15250, 0x3B92, error 15250, ERROR_AMBIGUOUS_SYSTEM_DEVICE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15250"]},{"id":2681,"title":"ERROR_SYSTEM_DEVICE_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15299","0x3BC3","error 15299","ERROR_SYSTEM_DEVICE_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","system","device","not","found","the","requested","cannot"],"errorCode":"15299","eventId":"","severity":"Medium","summary":"The requested system device cannot be found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15299; use the surrounding log entries to confirm it.","resolution":"1. Record where 15299 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SYSTEM_DEVICE_NOT_FOUND.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15299 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested system device cannot be found.\n\nLookup forms: 15299, 0x3BC3, error 15299, ERROR_SYSTEM_DEVICE_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15299"]},{"id":2682,"title":"ERROR_HASH_NOT_SUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15300","0x3BC4","error 15300","ERROR_HASH_NOT_SUPPORTED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","hash","not","supported","generation","for","the","specified","version","and","type","enabled","server"],"errorCode":"15300","eventId":"","severity":"Low","summary":"Hash generation for the specified hash version and hash type is not enabled on the server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 15300; use the surrounding log entries to confirm it.","resolution":"1. Record where 15300 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_HASH_NOT_SUPPORTED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15300 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Hash generation for the specified hash version and hash type is not enabled on the server.\n\nLookup forms: 15300, 0x3BC4, error 15300, ERROR_HASH_NOT_SUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15300"]},{"id":2683,"title":"ERROR_HASH_NOT_PRESENT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15301","0x3BC5","error 15301","ERROR_HASH_NOT_PRESENT","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","hash","not","present","the","requested","from","server","available","longer","valid"],"errorCode":"15301","eventId":"","severity":"Low","summary":"The hash requested from the server is not available or no longer valid.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 15301; use the surrounding log entries to confirm it.","resolution":"1. Record where 15301 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_HASH_NOT_PRESENT.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15301 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The hash requested from the server is not available or no longer valid.\n\nLookup forms: 15301, 0x3BC5, error 15301, ERROR_HASH_NOT_PRESENT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15301"]},{"id":2684,"title":"ERROR_SECONDARY_IC_PROVIDER_NOT_REGISTERED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15321","0x3BD9","error 15321","ERROR_SECONDARY_IC_PROVIDER_NOT_REGISTERED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","secondary","provider","not","registered","the","interrupt","controller","instance","that","manages","specified"],"errorCode":"15321","eventId":"","severity":"Low","summary":"The secondary interrupt controller instance that manages the specified interrupt is not registered.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15321; use the surrounding log entries to confirm it.","resolution":"1. Record where 15321 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SECONDARY_IC_PROVIDER_NOT_REGISTERED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15321 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The secondary interrupt controller instance that manages the specified interrupt is not registered.\n\nLookup forms: 15321, 0x3BD9, error 15321, ERROR_SECONDARY_IC_PROVIDER_NOT_REGISTERED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15321"]},{"id":2685,"title":"ERROR_GPIO_CLIENT_INFORMATION_INVALID","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15322","0x3BDA","error 15322","ERROR_GPIO_CLIENT_INFORMATION_INVALID","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","gpio","client","information","invalid","the","supplied","driver"],"errorCode":"15322","eventId":"","severity":"Medium","summary":"The information supplied by the GPIO client driver is invalid.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 15322; use the surrounding log entries to confirm it.","resolution":"1. Record where 15322 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_GPIO_CLIENT_INFORMATION_INVALID.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15322 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The information supplied by the GPIO client driver is invalid.\n\nLookup forms: 15322, 0x3BDA, error 15322, ERROR_GPIO_CLIENT_INFORMATION_INVALID. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15322"]},{"id":2686,"title":"ERROR_GPIO_VERSION_NOT_SUPPORTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15323","0x3BDB","error 15323","ERROR_GPIO_VERSION_NOT_SUPPORTED","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","gpio","version","not","supported","the","specified","client","driver"],"errorCode":"15323","eventId":"","severity":"Medium","summary":"The version specified by the GPIO client driver is not supported.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 15323; use the surrounding log entries to confirm it.","resolution":"1. Record where 15323 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_GPIO_VERSION_NOT_SUPPORTED.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15323 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The version specified by the GPIO client driver is not supported.\n\nLookup forms: 15323, 0x3BDB, error 15323, ERROR_GPIO_VERSION_NOT_SUPPORTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15323"]},{"id":2687,"title":"ERROR_GPIO_INVALID_REGISTRATION_PACKET","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15324","0x3BDC","error 15324","ERROR_GPIO_INVALID_REGISTRATION_PACKET","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","gpio","invalid","registration","packet","the","supplied","client","driver","not","valid"],"errorCode":"15324","eventId":"","severity":"Low","summary":"The registration packet supplied by the GPIO client driver is not valid.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 15324; use the surrounding log entries to confirm it.","resolution":"1. Record where 15324 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_GPIO_INVALID_REGISTRATION_PACKET.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15324 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The registration packet supplied by the GPIO client driver is not valid.\n\nLookup forms: 15324, 0x3BDC, error 15324, ERROR_GPIO_INVALID_REGISTRATION_PACKET. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15324"]},{"id":2688,"title":"ERROR_GPIO_OPERATION_DENIED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15325","0x3BDD","error 15325","ERROR_GPIO_OPERATION_DENIED","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","gpio","operation","denied","the","requested","not","supported","for","specified","handle"],"errorCode":"15325","eventId":"","severity":"Medium","summary":"The requested operation is not supported for the specified handle.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 15325; use the surrounding log entries to confirm it.","resolution":"1. Record where 15325 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_GPIO_OPERATION_DENIED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15325 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested operation is not supported for the specified handle.\n\nLookup forms: 15325, 0x3BDD, error 15325, ERROR_GPIO_OPERATION_DENIED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15325"]},{"id":2689,"title":"ERROR_GPIO_INCOMPATIBLE_CONNECT_MODE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15326","0x3BDE","error 15326","ERROR_GPIO_INCOMPATIBLE_CONNECT_MODE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","gpio","incompatible","connect","mode","the","requested","conflicts","with","existing","one","more","specified","pins"],"errorCode":"15326","eventId":"","severity":"Low","summary":"The requested connect mode conflicts with an existing mode on one or more of the specified pins.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15326; use the surrounding log entries to confirm it.","resolution":"1. Record where 15326 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_GPIO_INCOMPATIBLE_CONNECT_MODE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15326 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested connect mode conflicts with an existing mode on one or more of the specified pins.\n\nLookup forms: 15326, 0x3BDE, error 15326, ERROR_GPIO_INCOMPATIBLE_CONNECT_MODE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15326"]},{"id":2690,"title":"ERROR_GPIO_INTERRUPT_ALREADY_UNMASKED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15327","0x3BDF","error 15327","ERROR_GPIO_INTERRUPT_ALREADY_UNMASKED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","gpio","interrupt","already","unmasked","the","requested","not","masked"],"errorCode":"15327","eventId":"","severity":"Low","summary":"The interrupt requested to be unmasked is not masked.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15327; use the surrounding log entries to confirm it.","resolution":"1. Record where 15327 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_GPIO_INTERRUPT_ALREADY_UNMASKED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15327 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The interrupt requested to be unmasked is not masked.\n\nLookup forms: 15327, 0x3BDF, error 15327, ERROR_GPIO_INTERRUPT_ALREADY_UNMASKED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15327"]},{"id":2691,"title":"ERROR_CANNOT_SWITCH_RUNLEVEL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15400","0x3C28","error 15400","ERROR_CANNOT_SWITCH_RUNLEVEL","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","cannot","switch","runlevel","the","requested","run","level","completed","successfully"],"errorCode":"15400","eventId":"","severity":"Medium","summary":"The requested run level switch cannot be completed successfully.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15400; use the surrounding log entries to confirm it.","resolution":"1. Record where 15400 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_CANNOT_SWITCH_RUNLEVEL.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15400 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested run level switch cannot be completed successfully.\n\nLookup forms: 15400, 0x3C28, error 15400, ERROR_CANNOT_SWITCH_RUNLEVEL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15400"]},{"id":2692,"title":"ERROR_INVALID_RUNLEVEL_SETTING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15401","0x3C29","error 15401","ERROR_INVALID_RUNLEVEL_SETTING","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","invalid","runlevel","setting","the","service","has","run","level","for","must","not","higher","than","its","dependent","services"],"errorCode":"15401","eventId":"","severity":"Medium","summary":"The service has an invalid run level setting. The run level for a service must not be higher than the run level of its dependent services.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 15401; use the surrounding log entries to confirm it.","resolution":"1. Record where 15401 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_RUNLEVEL_SETTING.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15401 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The service has an invalid run level setting. The run level for a service must not be higher than the run level of its dependent services.\n\nLookup forms: 15401, 0x3C29, error 15401, ERROR_INVALID_RUNLEVEL_SETTING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15401"]},{"id":2693,"title":"ERROR_RUNLEVEL_SWITCH_TIMEOUT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15402","0x3C2A","error 15402","ERROR_RUNLEVEL_SWITCH_TIMEOUT","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","runlevel","switch","timeout","the","requested","run","level","cannot","completed","successfully","since","one","more","services","will","not","stop","restart","within","specified"],"errorCode":"15402","eventId":"","severity":"Medium","summary":"The requested run level switch cannot be completed successfully since one or more services will not stop or restart within the specified timeout.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 15402; use the surrounding log entries to confirm it.","resolution":"1. Record where 15402 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RUNLEVEL_SWITCH_TIMEOUT.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15402 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested run level switch cannot be completed successfully since one or more services will not stop or restart within the specified timeout.\n\nLookup forms: 15402, 0x3C2A, error 15402, ERROR_RUNLEVEL_SWITCH_TIMEOUT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15402"]},{"id":2694,"title":"ERROR_RUNLEVEL_SWITCH_AGENT_TIMEOUT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15403","0x3C2B","error 15403","ERROR_RUNLEVEL_SWITCH_AGENT_TIMEOUT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","runlevel","switch","agent","timeout","run","level","did","not","respond","within","the","specified"],"errorCode":"15403","eventId":"","severity":"Medium","summary":"A run level switch agent did not respond within the specified timeout.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15403; use the surrounding log entries to confirm it.","resolution":"1. Record where 15403 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RUNLEVEL_SWITCH_AGENT_TIMEOUT.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15403 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A run level switch agent did not respond within the specified timeout.\n\nLookup forms: 15403, 0x3C2B, error 15403, ERROR_RUNLEVEL_SWITCH_AGENT_TIMEOUT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15403"]},{"id":2695,"title":"ERROR_RUNLEVEL_SWITCH_IN_PROGRESS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15404","0x3C2C","error 15404","ERROR_RUNLEVEL_SWITCH_IN_PROGRESS","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","runlevel","switch","progress","run","level","currently"],"errorCode":"15404","eventId":"","severity":"Low","summary":"A run level switch is currently in progress.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15404; use the surrounding log entries to confirm it.","resolution":"1. Record where 15404 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RUNLEVEL_SWITCH_IN_PROGRESS.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15404 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A run level switch is currently in progress.\n\nLookup forms: 15404, 0x3C2C, error 15404, ERROR_RUNLEVEL_SWITCH_IN_PROGRESS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15404"]},{"id":2696,"title":"ERROR_SERVICES_FAILED_AUTOSTART","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15405","0x3C2D","error 15405","ERROR_SERVICES_FAILED_AUTOSTART","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","services","failed","autostart","one","more","start","during","the","service","startup","phase","run","level","switch"],"errorCode":"15405","eventId":"","severity":"High","summary":"One or more services failed to start during the service startup phase of a run level switch.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 15405; use the surrounding log entries to confirm it.","resolution":"1. Record where 15405 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SERVICES_FAILED_AUTOSTART.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15405 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: One or more services failed to start during the service startup phase of a run level switch.\n\nLookup forms: 15405, 0x3C2D, error 15405, ERROR_SERVICES_FAILED_AUTOSTART. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15405"]},{"id":2697,"title":"ERROR_COM_TASK_STOP_PENDING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15501","0x3C8D","error 15501","ERROR_COM_TASK_STOP_PENDING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","com","task","stop","pending","the","request","cannot","completed","immediately","since","needs","more","time","shutdown"],"errorCode":"15501","eventId":"","severity":"Medium","summary":"The task stop request cannot be completed immediately since task needs more time to shutdown.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15501; use the surrounding log entries to confirm it.","resolution":"1. Record where 15501 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_COM_TASK_STOP_PENDING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15501 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The task stop request cannot be completed immediately since task needs more time to shutdown.\n\nLookup forms: 15501, 0x3C8D, error 15501, ERROR_COM_TASK_STOP_PENDING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15501"]},{"id":2698,"title":"ERROR_INSTALL_OPEN_PACKAGE_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15600","0x3CF0","error 15600","ERROR_INSTALL_OPEN_PACKAGE_FAILED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","install","open","package","failed","could","not","opened"],"errorCode":"15600","eventId":"","severity":"Low","summary":"Package could not be opened.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 15600; use the surrounding log entries to confirm it.","resolution":"1. Record where 15600 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_OPEN_PACKAGE_FAILED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15600 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Package could not be opened.\n\nLookup forms: 15600, 0x3CF0, error 15600, ERROR_INSTALL_OPEN_PACKAGE_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15600"]},{"id":2699,"title":"ERROR_INSTALL_PACKAGE_NOT_FOUND","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15601","0x3CF1","error 15601","ERROR_INSTALL_PACKAGE_NOT_FOUND","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","install","package","not","found","was"],"errorCode":"15601","eventId":"","severity":"Medium","summary":"Package was not found.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 15601; use the surrounding log entries to confirm it.","resolution":"1. Record where 15601 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_PACKAGE_NOT_FOUND.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15601 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Package was not found.\n\nLookup forms: 15601, 0x3CF1, error 15601, ERROR_INSTALL_PACKAGE_NOT_FOUND. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15601"]},{"id":2700,"title":"ERROR_INSTALL_INVALID_PACKAGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15602","0x3CF2","error 15602","ERROR_INSTALL_INVALID_PACKAGE","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","install","invalid","package","data"],"errorCode":"15602","eventId":"","severity":"Medium","summary":"Package data is invalid.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 15602; use the surrounding log entries to confirm it.","resolution":"1. Record where 15602 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_INVALID_PACKAGE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15602 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Package data is invalid.\n\nLookup forms: 15602, 0x3CF2, error 15602, ERROR_INSTALL_INVALID_PACKAGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15602"]},{"id":2701,"title":"ERROR_INSTALL_RESOLVE_DEPENDENCY_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15603","0x3CF3","error 15603","ERROR_INSTALL_RESOLVE_DEPENDENCY_FAILED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","install","resolve","dependency","failed","package","updates","conflict","validation"],"errorCode":"15603","eventId":"","severity":"High","summary":"Package failed updates, dependency or conflict validation.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 15603; use the surrounding log entries to confirm it.","resolution":"1. Record where 15603 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_RESOLVE_DEPENDENCY_FAILED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15603 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Package failed updates, dependency or conflict validation.\n\nLookup forms: 15603, 0x3CF3, error 15603, ERROR_INSTALL_RESOLVE_DEPENDENCY_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15603"]},{"id":2702,"title":"ERROR_INSTALL_OUT_OF_DISK_SPACE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15604","0x3CF4","error 15604","ERROR_INSTALL_OUT_OF_DISK_SPACE","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","error","install","out","disk","space","there","not","enough","your","computer","please","free","some","and","try","again"],"errorCode":"15604","eventId":"","severity":"Low","summary":"There is not enough disk space on your computer. Please free up some space and try again.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 15604; use the surrounding log entries to confirm it.","resolution":"1. Record where 15604 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_OUT_OF_DISK_SPACE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15604 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There is not enough disk space on your computer. Please free up some space and try again.\n\nLookup forms: 15604, 0x3CF4, error 15604, ERROR_INSTALL_OUT_OF_DISK_SPACE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15604"]},{"id":2703,"title":"ERROR_INSTALL_NETWORK_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15605","0x3CF5","error 15605","ERROR_INSTALL_NETWORK_FAILURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","install","network","failure","there","was","problem","downloading","your","product"],"errorCode":"15605","eventId":"","severity":"Low","summary":"There was a problem downloading your product.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15605; use the surrounding log entries to confirm it.","resolution":"1. Record where 15605 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_NETWORK_FAILURE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15605 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There was a problem downloading your product.\n\nLookup forms: 15605, 0x3CF5, error 15605, ERROR_INSTALL_NETWORK_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15605"]},{"id":2704,"title":"ERROR_INSTALL_REGISTRATION_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15606","0x3CF6","error 15606","ERROR_INSTALL_REGISTRATION_FAILURE","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","install","registration","failure","package","could","not","registered"],"errorCode":"15606","eventId":"","severity":"Low","summary":"Package could not be registered.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 15606; use the surrounding log entries to confirm it.","resolution":"1. Record where 15606 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_REGISTRATION_FAILURE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15606 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Package could not be registered.\n\nLookup forms: 15606, 0x3CF6, error 15606, ERROR_INSTALL_REGISTRATION_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15606"]},{"id":2705,"title":"ERROR_INSTALL_DEREGISTRATION_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15607","0x3CF7","error 15607","ERROR_INSTALL_DEREGISTRATION_FAILURE","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","install","deregistration","failure","package","could","not","unregistered"],"errorCode":"15607","eventId":"","severity":"Low","summary":"Package could not be unregistered.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 15607; use the surrounding log entries to confirm it.","resolution":"1. Record where 15607 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_DEREGISTRATION_FAILURE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15607 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Package could not be unregistered.\n\nLookup forms: 15607, 0x3CF7, error 15607, ERROR_INSTALL_DEREGISTRATION_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15607"]},{"id":2706,"title":"ERROR_INSTALL_CANCEL","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15608","0x3CF8","error 15608","ERROR_INSTALL_CANCEL","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","install","cancel","user","cancelled","the","request"],"errorCode":"15608","eventId":"","severity":"Low","summary":"User cancelled the install request.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 15608; use the surrounding log entries to confirm it.","resolution":"1. Record where 15608 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_CANCEL.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15608 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: User cancelled the install request.\n\nLookup forms: 15608, 0x3CF8, error 15608, ERROR_INSTALL_CANCEL. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15608"]},{"id":2707,"title":"ERROR_INSTALL_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15609","0x3CF9","error 15609","ERROR_INSTALL_FAILED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","install","failed","please","contact","your","software","vendor"],"errorCode":"15609","eventId":"","severity":"High","summary":"Install failed. Please contact your software vendor.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 15609; use the surrounding log entries to confirm it.","resolution":"1. Record where 15609 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_FAILED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15609 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Install failed. Please contact your software vendor.\n\nLookup forms: 15609, 0x3CF9, error 15609, ERROR_INSTALL_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15609"]},{"id":2708,"title":"ERROR_REMOVE_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15610","0x3CFA","error 15610","ERROR_REMOVE_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","remove","failed","removal","please","contact","your","software","vendor"],"errorCode":"15610","eventId":"","severity":"High","summary":"Removal failed. Please contact your software vendor.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15610; use the surrounding log entries to confirm it.","resolution":"1. Record where 15610 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_REMOVE_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15610 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Removal failed. Please contact your software vendor.\n\nLookup forms: 15610, 0x3CFA, error 15610, ERROR_REMOVE_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15610"]},{"id":2709,"title":"ERROR_PACKAGE_ALREADY_EXISTS","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15611","0x3CFB","error 15611","ERROR_PACKAGE_ALREADY_EXISTS","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","error","package","already","exists","the","provided","installed","and","reinstallation","was","blocked","check","appxdeployment","server","event","log","for","details"],"errorCode":"15611","eventId":"","severity":"High","summary":"The provided package is already installed, and reinstallation of the package was blocked. Check the AppXDeployment-Server event log for details.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 15611; use the surrounding log entries to confirm it.","resolution":"1. Record where 15611 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PACKAGE_ALREADY_EXISTS.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15611 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The provided package is already installed, and reinstallation of the package was blocked. Check the AppXDeployment-Server event log for details.\n\nLookup forms: 15611, 0x3CFB, error 15611, ERROR_PACKAGE_ALREADY_EXISTS. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15611"]},{"id":2710,"title":"ERROR_NEEDS_REMEDIATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15612","0x3CFC","error 15612","ERROR_NEEDS_REMEDIATION","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","needs","remediation","the","application","cannot","started","try","reinstalling","fix","problem"],"errorCode":"15612","eventId":"","severity":"Medium","summary":"The application cannot be started. Try reinstalling the application to fix the problem.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 15612; use the surrounding log entries to confirm it.","resolution":"1. Record where 15612 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_NEEDS_REMEDIATION.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15612 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The application cannot be started. Try reinstalling the application to fix the problem.\n\nLookup forms: 15612, 0x3CFC, error 15612, ERROR_NEEDS_REMEDIATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15612"]},{"id":2711,"title":"ERROR_INSTALL_PREREQUISITE_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15613","0x3CFD","error 15613","ERROR_INSTALL_PREREQUISITE_FAILED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","install","prerequisite","failed","for","could","not","satisfied"],"errorCode":"15613","eventId":"","severity":"Low","summary":"A Prerequisite for an install could not be satisfied.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 15613; use the surrounding log entries to confirm it.","resolution":"1. Record where 15613 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_PREREQUISITE_FAILED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15613 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A Prerequisite for an install could not be satisfied.\n\nLookup forms: 15613, 0x3CFD, error 15613, ERROR_INSTALL_PREREQUISITE_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15613"]},{"id":2712,"title":"ERROR_PACKAGE_REPOSITORY_CORRUPTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15614","0x3CFE","error 15614","ERROR_PACKAGE_REPOSITORY_CORRUPTED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","package","repository","corrupted","the"],"errorCode":"15614","eventId":"","severity":"Critical","summary":"The package repository is corrupted.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 15614; use the surrounding log entries to confirm it.","resolution":"1. Record where 15614 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PACKAGE_REPOSITORY_CORRUPTED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15614 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The package repository is corrupted.\n\nLookup forms: 15614, 0x3CFE, error 15614, ERROR_PACKAGE_REPOSITORY_CORRUPTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15614"]},{"id":2713,"title":"ERROR_INSTALL_POLICY_FAILURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15615","0x3CFF","error 15615","ERROR_INSTALL_POLICY_FAILURE","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","install","policy","failure","this","application","you","need","either","windows","developer","license","sideloading","enabled","system"],"errorCode":"15615","eventId":"","severity":"Low","summary":"To install this application you need either a Windows developer license or a sideloading-enabled system.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 15615; use the surrounding log entries to confirm it.","resolution":"1. Record where 15615 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_POLICY_FAILURE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15615 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: To install this application you need either a Windows developer license or a sideloading-enabled system.\n\nLookup forms: 15615, 0x3CFF, error 15615, ERROR_INSTALL_POLICY_FAILURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15615"]},{"id":2714,"title":"ERROR_PACKAGE_UPDATING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15616","0x3D00","error 15616","ERROR_PACKAGE_UPDATING","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","package","updating","the","application","cannot","started","because","currently"],"errorCode":"15616","eventId":"","severity":"Medium","summary":"The application cannot be started because it is currently updating.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15616; use the surrounding log entries to confirm it.","resolution":"1. Record where 15616 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PACKAGE_UPDATING.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15616 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The application cannot be started because it is currently updating.\n\nLookup forms: 15616, 0x3D00, error 15616, ERROR_PACKAGE_UPDATING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15616"]},{"id":2715,"title":"ERROR_DEPLOYMENT_BLOCKED_BY_POLICY","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15617","0x3D01","error 15617","ERROR_DEPLOYMENT_BLOCKED_BY_POLICY","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","deployment","blocked","policy","the","package","operation","please","contact","your","system","administrator"],"errorCode":"15617","eventId":"","severity":"High","summary":"The package deployment operation is blocked by policy. Please contact your system administrator.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 15617; use the surrounding log entries to confirm it.","resolution":"1. Record where 15617 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DEPLOYMENT_BLOCKED_BY_POLICY.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15617 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The package deployment operation is blocked by policy. Please contact your system administrator.\n\nLookup forms: 15617, 0x3D01, error 15617, ERROR_DEPLOYMENT_BLOCKED_BY_POLICY. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15617"]},{"id":2716,"title":"ERROR_PACKAGES_IN_USE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15618","0x3D02","error 15618","ERROR_PACKAGES_IN_USE","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","packages","use","the","package","could","not","installed","because","resources","modifies","are","currently"],"errorCode":"15618","eventId":"","severity":"Low","summary":"The package could not be installed because resources it modifies are currently in use.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 15618; use the surrounding log entries to confirm it.","resolution":"1. Record where 15618 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_PACKAGES_IN_USE.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15618 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The package could not be installed because resources it modifies are currently in use.\n\nLookup forms: 15618, 0x3D02, error 15618, ERROR_PACKAGES_IN_USE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15618"]},{"id":2717,"title":"ERROR_RECOVERY_FILE_CORRUPT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15619","0x3D03","error 15619","ERROR_RECOVERY_FILE_CORRUPT","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","recovery","file","corrupt","the","package","could","not","recovered","because","necessary","data","for","have","been","corrupted"],"errorCode":"15619","eventId":"","severity":"Critical","summary":"The package could not be recovered because necessary data for recovery have been corrupted.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 15619; use the surrounding log entries to confirm it.","resolution":"1. Record where 15619 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RECOVERY_FILE_CORRUPT.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15619 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The package could not be recovered because necessary data for recovery have been corrupted.\n\nLookup forms: 15619, 0x3D03, error 15619, ERROR_RECOVERY_FILE_CORRUPT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15619"]},{"id":2718,"title":"ERROR_INVALID_STAGED_SIGNATURE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15620","0x3D04","error 15620","ERROR_INVALID_STAGED_SIGNATURE","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","invalid","staged","signature","the","register","developer","mode","appxsignature","p7x","and","appxblockmap","xml","must","valid","should","not","present"],"errorCode":"15620","eventId":"","severity":"Medium","summary":"The signature is invalid. To register in developer mode, AppxSignature.p7x and AppxBlockMap.xml must be valid or should not be present.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15620; use the surrounding log entries to confirm it.","resolution":"1. Record where 15620 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INVALID_STAGED_SIGNATURE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15620 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The signature is invalid. To register in developer mode, AppxSignature.p7x and AppxBlockMap.xml must be valid or should not be present.\n\nLookup forms: 15620, 0x3D04, error 15620, ERROR_INVALID_STAGED_SIGNATURE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15620"]},{"id":2719,"title":"ERROR_DELETING_EXISTING_APPLICATIONDATA_STORE_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15621","0x3D05","error 15621","ERROR_DELETING_EXISTING_APPLICATIONDATA_STORE_FAILED","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","deleting","existing","applicationdata","store","failed","occurred","while","the","package","previously","application","data"],"errorCode":"15621","eventId":"","severity":"Low","summary":"An error occurred while deleting the package's previously existing application data.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 15621; use the surrounding log entries to confirm it.","resolution":"1. Record where 15621 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DELETING_EXISTING_APPLICATIONDATA_STORE_FAILED.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15621 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An error occurred while deleting the package's previously existing application data.\n\nLookup forms: 15621, 0x3D05, error 15621, ERROR_DELETING_EXISTING_APPLICATIONDATA_STORE_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15621"]},{"id":2720,"title":"ERROR_INSTALL_PACKAGE_DOWNGRADE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15622","0x3D06","error 15622","ERROR_INSTALL_PACKAGE_DOWNGRADE","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","error","install","package","downgrade","the","could","not","installed","because","higher","version","this","already"],"errorCode":"15622","eventId":"","severity":"Low","summary":"The package could not be installed because a higher version of this package is already installed.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 15622; use the surrounding log entries to confirm it.","resolution":"1. Record where 15622 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_PACKAGE_DOWNGRADE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15622 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The package could not be installed because a higher version of this package is already installed.\n\nLookup forms: 15622, 0x3D06, error 15622, ERROR_INSTALL_PACKAGE_DOWNGRADE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15622"]},{"id":2721,"title":"ERROR_SYSTEM_NEEDS_REMEDIATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15623","0x3D07","error 15623","ERROR_SYSTEM_NEEDS_REMEDIATION","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","system","needs","remediation","binary","was","detected","try","refreshing","the","fix","problem"],"errorCode":"15623","eventId":"","severity":"Low","summary":"An error in a system binary was detected. Try refreshing the PC to fix the problem.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15623; use the surrounding log entries to confirm it.","resolution":"1. Record where 15623 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_SYSTEM_NEEDS_REMEDIATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15623 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An error in a system binary was detected. Try refreshing the PC to fix the problem.\n\nLookup forms: 15623, 0x3D07, error 15623, ERROR_SYSTEM_NEEDS_REMEDIATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15623"]},{"id":2722,"title":"ERROR_APPX_INTEGRITY_FAILURE_CLR_NGEN","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15624","0x3D08","error 15624","ERROR_APPX_INTEGRITY_FAILURE_CLR_NGEN","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","appx","integrity","failure","clr","ngen","corrupted","binary","was","detected","the","system"],"errorCode":"15624","eventId":"","severity":"Critical","summary":"A corrupted CLR NGEN binary was detected on the system.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15624; use the surrounding log entries to confirm it.","resolution":"1. Record where 15624 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_APPX_INTEGRITY_FAILURE_CLR_NGEN.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15624 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A corrupted CLR NGEN binary was detected on the system.\n\nLookup forms: 15624, 0x3D08, error 15624, ERROR_APPX_INTEGRITY_FAILURE_CLR_NGEN. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15624"]},{"id":2723,"title":"ERROR_RESILIENCY_FILE_CORRUPT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15625","0x3D09","error 15625","ERROR_RESILIENCY_FILE_CORRUPT","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","resiliency","file","corrupt","the","operation","could","not","resumed","because","necessary","data","for","recovery","have","been","corrupted"],"errorCode":"15625","eventId":"","severity":"Critical","summary":"The operation could not be resumed because necessary data for recovery have been corrupted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15625; use the surrounding log entries to confirm it.","resolution":"1. Record where 15625 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_RESILIENCY_FILE_CORRUPT.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15625 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation could not be resumed because necessary data for recovery have been corrupted.\n\nLookup forms: 15625, 0x3D09, error 15625, ERROR_RESILIENCY_FILE_CORRUPT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15625"]},{"id":2724,"title":"ERROR_INSTALL_FIREWALL_SERVICE_NOT_RUNNING","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15626","0x3D0A","error 15626","ERROR_INSTALL_FIREWALL_SERVICE_NOT_RUNNING","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","install","firewall","service","not","running","the","package","could","installed","because","windows","enable","and","try","again"],"errorCode":"15626","eventId":"","severity":"Low","summary":"The package could not be installed because the Windows Firewall service is not running. Enable the Windows Firewall service and try again.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 15626; use the surrounding log entries to confirm it.","resolution":"1. Record where 15626 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_INSTALL_FIREWALL_SERVICE_NOT_RUNNING.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15626 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The package could not be installed because the Windows Firewall service is not running. Enable the Windows Firewall service and try again.\n\nLookup forms: 15626, 0x3D0A, error 15626, ERROR_INSTALL_FIREWALL_SERVICE_NOT_RUNNING. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15626"]},{"id":2725,"title":"APPMODEL_ERROR_NO_PACKAGE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15700","0x3D54","error 15700","APPMODEL_ERROR_NO_PACKAGE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","appmodel","error","package","the","process","has","identity"],"errorCode":"15700","eventId":"","severity":"Low","summary":"The process has no package identity.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 15700; use the surrounding log entries to confirm it.","resolution":"1. Record where 15700 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to APPMODEL_ERROR_NO_PACKAGE.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15700 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The process has no package identity.\n\nLookup forms: 15700, 0x3D54, error 15700, APPMODEL_ERROR_NO_PACKAGE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15700"]},{"id":2726,"title":"APPMODEL_ERROR_PACKAGE_RUNTIME_CORRUPT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15701","0x3D55","error 15701","APPMODEL_ERROR_PACKAGE_RUNTIME_CORRUPT","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","appmodel","error","package","runtime","corrupt","the","information","corrupted"],"errorCode":"15701","eventId":"","severity":"Critical","summary":"The package runtime information is corrupted.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 15701; use the surrounding log entries to confirm it.","resolution":"1. Record where 15701 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to APPMODEL_ERROR_PACKAGE_RUNTIME_CORRUPT.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15701 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The package runtime information is corrupted.\n\nLookup forms: 15701, 0x3D55, error 15701, APPMODEL_ERROR_PACKAGE_RUNTIME_CORRUPT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15701"]},{"id":2727,"title":"APPMODEL_ERROR_PACKAGE_IDENTITY_CORRUPT","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15702","0x3D56","error 15702","APPMODEL_ERROR_PACKAGE_IDENTITY_CORRUPT","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","appmodel","error","package","identity","corrupt","the","corrupted"],"errorCode":"15702","eventId":"","severity":"Critical","summary":"The package identity is corrupted.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 15702; use the surrounding log entries to confirm it.","resolution":"1. Record where 15702 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to APPMODEL_ERROR_PACKAGE_IDENTITY_CORRUPT.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15702 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The package identity is corrupted.\n\nLookup forms: 15702, 0x3D56, error 15702, APPMODEL_ERROR_PACKAGE_IDENTITY_CORRUPT. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15702"]},{"id":2728,"title":"APPMODEL_ERROR_NO_APPLICATION","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15703","0x3D57","error 15703","APPMODEL_ERROR_NO_APPLICATION","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","appmodel","error","application","the","process","has","identity"],"errorCode":"15703","eventId":"","severity":"Low","summary":"The process has no application identity.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 15703; use the surrounding log entries to confirm it.","resolution":"1. Record where 15703 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to APPMODEL_ERROR_NO_APPLICATION.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15703 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The process has no application identity.\n\nLookup forms: 15703, 0x3D57, error 15703, APPMODEL_ERROR_NO_APPLICATION. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15703"]},{"id":2729,"title":"ERROR_STATE_LOAD_STORE_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15800","0x3DB8","error 15800","ERROR_STATE_LOAD_STORE_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","state","load","store","failed","loading","the"],"errorCode":"15800","eventId":"","severity":"High","summary":"Loading the state store failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15800; use the surrounding log entries to confirm it.","resolution":"1. Record where 15800 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STATE_LOAD_STORE_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15800 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Loading the state store failed.\n\nLookup forms: 15800, 0x3DB8, error 15800, ERROR_STATE_LOAD_STORE_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15800"]},{"id":2730,"title":"ERROR_STATE_GET_VERSION_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15801","0x3DB9","error 15801","ERROR_STATE_GET_VERSION_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","state","get","version","failed","retrieving","the","for","application"],"errorCode":"15801","eventId":"","severity":"High","summary":"Retrieving the state version for the application failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15801; use the surrounding log entries to confirm it.","resolution":"1. Record where 15801 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STATE_GET_VERSION_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15801 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Retrieving the state version for the application failed.\n\nLookup forms: 15801, 0x3DB9, error 15801, ERROR_STATE_GET_VERSION_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15801"]},{"id":2731,"title":"ERROR_STATE_SET_VERSION_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15802","0x3DBA","error 15802","ERROR_STATE_SET_VERSION_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","state","set","version","failed","setting","the","for","application"],"errorCode":"15802","eventId":"","severity":"High","summary":"Setting the state version for the application failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15802; use the surrounding log entries to confirm it.","resolution":"1. Record where 15802 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STATE_SET_VERSION_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15802 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Setting the state version for the application failed.\n\nLookup forms: 15802, 0x3DBA, error 15802, ERROR_STATE_SET_VERSION_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15802"]},{"id":2732,"title":"ERROR_STATE_STRUCTURED_RESET_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15803","0x3DBB","error 15803","ERROR_STATE_STRUCTURED_RESET_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","state","structured","reset","failed","resetting","the","application"],"errorCode":"15803","eventId":"","severity":"High","summary":"Resetting the structured state of the application failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15803; use the surrounding log entries to confirm it.","resolution":"1. Record where 15803 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STATE_STRUCTURED_RESET_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15803 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Resetting the structured state of the application failed.\n\nLookup forms: 15803, 0x3DBB, error 15803, ERROR_STATE_STRUCTURED_RESET_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15803"]},{"id":2733,"title":"ERROR_STATE_OPEN_CONTAINER_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15804","0x3DBC","error 15804","ERROR_STATE_OPEN_CONTAINER_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","state","open","container","failed","manager","the"],"errorCode":"15804","eventId":"","severity":"High","summary":"State Manager failed to open the container.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15804; use the surrounding log entries to confirm it.","resolution":"1. Record where 15804 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STATE_OPEN_CONTAINER_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15804 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: State Manager failed to open the container.\n\nLookup forms: 15804, 0x3DBC, error 15804, ERROR_STATE_OPEN_CONTAINER_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15804"]},{"id":2734,"title":"ERROR_STATE_CREATE_CONTAINER_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15805","0x3DBD","error 15805","ERROR_STATE_CREATE_CONTAINER_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","state","create","container","failed","manager","the"],"errorCode":"15805","eventId":"","severity":"High","summary":"State Manager failed to create the container.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15805; use the surrounding log entries to confirm it.","resolution":"1. Record where 15805 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STATE_CREATE_CONTAINER_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15805 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: State Manager failed to create the container.\n\nLookup forms: 15805, 0x3DBD, error 15805, ERROR_STATE_CREATE_CONTAINER_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15805"]},{"id":2735,"title":"ERROR_STATE_DELETE_CONTAINER_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15806","0x3DBE","error 15806","ERROR_STATE_DELETE_CONTAINER_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","state","delete","container","failed","manager","the"],"errorCode":"15806","eventId":"","severity":"High","summary":"State Manager failed to delete the container.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15806; use the surrounding log entries to confirm it.","resolution":"1. Record where 15806 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STATE_DELETE_CONTAINER_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15806 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: State Manager failed to delete the container.\n\nLookup forms: 15806, 0x3DBE, error 15806, ERROR_STATE_DELETE_CONTAINER_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15806"]},{"id":2736,"title":"ERROR_STATE_READ_SETTING_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15807","0x3DBF","error 15807","ERROR_STATE_READ_SETTING_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","state","read","setting","failed","manager","the"],"errorCode":"15807","eventId":"","severity":"High","summary":"State Manager failed to read the setting.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15807; use the surrounding log entries to confirm it.","resolution":"1. Record where 15807 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STATE_READ_SETTING_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15807 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: State Manager failed to read the setting.\n\nLookup forms: 15807, 0x3DBF, error 15807, ERROR_STATE_READ_SETTING_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15807"]},{"id":2737,"title":"ERROR_STATE_WRITE_SETTING_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15808","0x3DC0","error 15808","ERROR_STATE_WRITE_SETTING_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","state","write","setting","failed","manager","the"],"errorCode":"15808","eventId":"","severity":"High","summary":"State Manager failed to write the setting.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15808; use the surrounding log entries to confirm it.","resolution":"1. Record where 15808 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STATE_WRITE_SETTING_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15808 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: State Manager failed to write the setting.\n\nLookup forms: 15808, 0x3DC0, error 15808, ERROR_STATE_WRITE_SETTING_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15808"]},{"id":2738,"title":"ERROR_STATE_DELETE_SETTING_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15809","0x3DC1","error 15809","ERROR_STATE_DELETE_SETTING_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","state","delete","setting","failed","manager","the"],"errorCode":"15809","eventId":"","severity":"High","summary":"State Manager failed to delete the setting.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15809; use the surrounding log entries to confirm it.","resolution":"1. Record where 15809 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STATE_DELETE_SETTING_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15809 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: State Manager failed to delete the setting.\n\nLookup forms: 15809, 0x3DC1, error 15809, ERROR_STATE_DELETE_SETTING_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15809"]},{"id":2739,"title":"ERROR_STATE_QUERY_SETTING_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15810","0x3DC2","error 15810","ERROR_STATE_QUERY_SETTING_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","state","query","setting","failed","manager","the"],"errorCode":"15810","eventId":"","severity":"High","summary":"State Manager failed to query the setting.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15810; use the surrounding log entries to confirm it.","resolution":"1. Record where 15810 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STATE_QUERY_SETTING_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15810 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: State Manager failed to query the setting.\n\nLookup forms: 15810, 0x3DC2, error 15810, ERROR_STATE_QUERY_SETTING_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15810"]},{"id":2740,"title":"ERROR_STATE_READ_COMPOSITE_SETTING_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15811","0x3DC3","error 15811","ERROR_STATE_READ_COMPOSITE_SETTING_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","state","read","composite","setting","failed","manager","the"],"errorCode":"15811","eventId":"","severity":"High","summary":"State Manager failed to read the composite setting.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15811; use the surrounding log entries to confirm it.","resolution":"1. Record where 15811 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STATE_READ_COMPOSITE_SETTING_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15811 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: State Manager failed to read the composite setting.\n\nLookup forms: 15811, 0x3DC3, error 15811, ERROR_STATE_READ_COMPOSITE_SETTING_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15811"]},{"id":2741,"title":"ERROR_STATE_WRITE_COMPOSITE_SETTING_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15812","0x3DC4","error 15812","ERROR_STATE_WRITE_COMPOSITE_SETTING_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","state","write","composite","setting","failed","manager","the"],"errorCode":"15812","eventId":"","severity":"High","summary":"State Manager failed to write the composite setting.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15812; use the surrounding log entries to confirm it.","resolution":"1. Record where 15812 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STATE_WRITE_COMPOSITE_SETTING_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15812 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: State Manager failed to write the composite setting.\n\nLookup forms: 15812, 0x3DC4, error 15812, ERROR_STATE_WRITE_COMPOSITE_SETTING_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15812"]},{"id":2742,"title":"ERROR_STATE_ENUMERATE_CONTAINER_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15813","0x3DC5","error 15813","ERROR_STATE_ENUMERATE_CONTAINER_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","state","enumerate","container","failed","manager","the","containers"],"errorCode":"15813","eventId":"","severity":"High","summary":"State Manager failed to enumerate the containers.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15813; use the surrounding log entries to confirm it.","resolution":"1. Record where 15813 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STATE_ENUMERATE_CONTAINER_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15813 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: State Manager failed to enumerate the containers.\n\nLookup forms: 15813, 0x3DC5, error 15813, ERROR_STATE_ENUMERATE_CONTAINER_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15813"]},{"id":2743,"title":"ERROR_STATE_ENUMERATE_SETTINGS_FAILED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15814","0x3DC6","error 15814","ERROR_STATE_ENUMERATE_SETTINGS_FAILED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","state","enumerate","settings","failed","manager","the"],"errorCode":"15814","eventId":"","severity":"High","summary":"State Manager failed to enumerate the settings.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15814; use the surrounding log entries to confirm it.","resolution":"1. Record where 15814 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STATE_ENUMERATE_SETTINGS_FAILED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15814 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: State Manager failed to enumerate the settings.\n\nLookup forms: 15814, 0x3DC6, error 15814, ERROR_STATE_ENUMERATE_SETTINGS_FAILED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15814"]},{"id":2744,"title":"ERROR_STATE_COMPOSITE_SETTING_VALUE_SIZE_LIMIT_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15815","0x3DC7","error 15815","ERROR_STATE_COMPOSITE_SETTING_VALUE_SIZE_LIMIT_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","state","composite","setting","value","size","limit","exceeded","the","manager","has"],"errorCode":"15815","eventId":"","severity":"Low","summary":"The size of the state manager composite setting value has exceeded the limit.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15815; use the surrounding log entries to confirm it.","resolution":"1. Record where 15815 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STATE_COMPOSITE_SETTING_VALUE_SIZE_LIMIT_EXCEEDED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15815 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The size of the state manager composite setting value has exceeded the limit.\n\nLookup forms: 15815, 0x3DC7, error 15815, ERROR_STATE_COMPOSITE_SETTING_VALUE_SIZE_LIMIT_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15815"]},{"id":2745,"title":"ERROR_STATE_SETTING_VALUE_SIZE_LIMIT_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15816","0x3DC8","error 15816","ERROR_STATE_SETTING_VALUE_SIZE_LIMIT_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","state","setting","value","size","limit","exceeded","the","manager","has"],"errorCode":"15816","eventId":"","severity":"Low","summary":"The size of the state manager setting value has exceeded the limit.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15816; use the surrounding log entries to confirm it.","resolution":"1. Record where 15816 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STATE_SETTING_VALUE_SIZE_LIMIT_EXCEEDED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15816 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The size of the state manager setting value has exceeded the limit.\n\nLookup forms: 15816, 0x3DC8, error 15816, ERROR_STATE_SETTING_VALUE_SIZE_LIMIT_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15816"]},{"id":2746,"title":"ERROR_STATE_SETTING_NAME_SIZE_LIMIT_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15817","0x3DC9","error 15817","ERROR_STATE_SETTING_NAME_SIZE_LIMIT_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","state","setting","name","size","limit","exceeded","the","length","manager","has"],"errorCode":"15817","eventId":"","severity":"Low","summary":"The length of the state manager setting name has exceeded the limit.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15817; use the surrounding log entries to confirm it.","resolution":"1. Record where 15817 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STATE_SETTING_NAME_SIZE_LIMIT_EXCEEDED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15817 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The length of the state manager setting name has exceeded the limit.\n\nLookup forms: 15817, 0x3DC9, error 15817, ERROR_STATE_SETTING_NAME_SIZE_LIMIT_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15817"]},{"id":2747,"title":"ERROR_STATE_CONTAINER_NAME_SIZE_LIMIT_EXCEEDED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15818","0x3DCA","error 15818","ERROR_STATE_CONTAINER_NAME_SIZE_LIMIT_EXCEEDED","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","state","container","name","size","limit","exceeded","the","length","manager","has"],"errorCode":"15818","eventId":"","severity":"Low","summary":"The length of the state manager container name has exceeded the limit.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 15818; use the surrounding log entries to confirm it.","resolution":"1. Record where 15818 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_STATE_CONTAINER_NAME_SIZE_LIMIT_EXCEEDED.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15818 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The length of the state manager container name has exceeded the limit.\n\nLookup forms: 15818, 0x3DCA, error 15818, ERROR_STATE_CONTAINER_NAME_SIZE_LIMIT_EXCEEDED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15818"]},{"id":2748,"title":"ERROR_API_UNAVAILABLE","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["15841","0x3DE1","error 15841","ERROR_API_UNAVAILABLE","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","error","api","unavailable","this","cannot","used","the","context","caller","application","type"],"errorCode":"15841","eventId":"","severity":"Medium","summary":"This API cannot be used in the context of the caller's application type.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 15841; use the surrounding log entries to confirm it.","resolution":"1. Record where 15841 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_API_UNAVAILABLE.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 15841 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This API cannot be used in the context of the caller's application type.\n\nLookup forms: 15841, 0x3DE1, error 15841, ERROR_API_UNAVAILABLE. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["15841"]},{"id":2749,"title":"ERROR_ITERATED_DATA_EXCEEDS_64k","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["194","0xC2","0x000000C2","error 194","ERROR_ITERATED_DATA_EXCEEDS_64k","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","iterated","data","exceeds","64k","the","operating","system","cannot","run"],"errorCode":"194","eventId":"","severity":"Medium","summary":"The operating system cannot run %1.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 194; use the surrounding log entries to confirm it.","resolution":"1. Record where 194 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_ITERATED_DATA_EXCEEDS_64k.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 194 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operating system cannot run %1.\n\nLookup forms: 194, 0xC2, 0x000000C2, error 194, ERROR_ITERATED_DATA_EXCEEDS_64k. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["194"]},{"id":2750,"title":"ERROR_AUTODATASEG_EXCEEDS_64k","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["199","0xC7","0x000000C7","error 199","ERROR_AUTODATASEG_EXCEEDS_64k","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","autodataseg","exceeds","64k","the","operating","system","cannot","run","this","application","program"],"errorCode":"199","eventId":"","severity":"Medium","summary":"The operating system cannot run this application program.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 199; use the surrounding log entries to confirm it.","resolution":"1. Record where 199 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_AUTODATASEG_EXCEEDS_64k.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 199 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operating system cannot run this application program.\n\nLookup forms: 199, 0xC7, 0x000000C7, error 199, ERROR_AUTODATASEG_EXCEEDS_64k. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes; ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["199"]},{"id":2751,"title":"NERR_NetNotStarted","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2102","0x836","0x00000836","error 2102","NERR_NetNotStarted","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","netnotstarted","the","workstation","driver","not","installed"],"errorCode":"2102","eventId":"","severity":"Low","summary":"The workstation driver is not installed.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2102; use the surrounding log entries to confirm it.","resolution":"1. Record where 2102 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NetNotStarted.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2102 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The workstation driver is not installed.\n\nLookup forms: 2102, 0x836, 0x00000836, error 2102, NERR_NetNotStarted. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2102"]},{"id":2752,"title":"NERR_UnknownServer","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2103","0x837","0x00000837","error 2103","NERR_UnknownServer","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","unknownserver","the","server","could","not","located"],"errorCode":"2103","eventId":"","severity":"Low","summary":"The server could not be located.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2103; use the surrounding log entries to confirm it.","resolution":"1. Record where 2103 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_UnknownServer.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2103 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The server could not be located.\n\nLookup forms: 2103, 0x837, 0x00000837, error 2103, NERR_UnknownServer. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2103"]},{"id":2753,"title":"NERR_ShareMem","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2104","0x838","0x00000838","error 2104","NERR_ShareMem","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","sharemem","internal","error","occurred","the","network","cannot","access","shared","memory","segment"],"errorCode":"2104","eventId":"","severity":"High","summary":"An internal error occurred. The network cannot access a shared memory segment.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2104; use the surrounding log entries to confirm it.","resolution":"1. Record where 2104 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Check available memory, disk capacity, quotas, and system resource pressure.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ShareMem.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2104 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An internal error occurred. The network cannot access a shared memory segment.\n\nLookup forms: 2104, 0x838, 0x00000838, error 2104, NERR_ShareMem. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2104"]},{"id":2754,"title":"NERR_NoNetworkResource","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2105","0x839","0x00000839","error 2105","NERR_NoNetworkResource","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","nonetworkresource","network","resource","shortage","occurred"],"errorCode":"2105","eventId":"","severity":"High","summary":"A network resource shortage occurred.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2105; use the surrounding log entries to confirm it.","resolution":"1. Record where 2105 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NoNetworkResource.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2105 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A network resource shortage occurred.\n\nLookup forms: 2105, 0x839, 0x00000839, error 2105, NERR_NoNetworkResource. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2105"]},{"id":2755,"title":"NERR_RemoteOnly","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2106","0x83A","0x0000083A","error 2106","NERR_RemoteOnly","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","remoteonly","this","operation","not","supported","workstations"],"errorCode":"2106","eventId":"","severity":"Medium","summary":"This operation is not supported on workstations.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2106; use the surrounding log entries to confirm it.","resolution":"1. Record where 2106 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RemoteOnly.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2106 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation is not supported on workstations.\n\nLookup forms: 2106, 0x83A, 0x0000083A, error 2106, NERR_RemoteOnly. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2106"]},{"id":2756,"title":"NERR_DevNotRedirected","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2107","0x83B","0x0000083B","error 2107","NERR_DevNotRedirected","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","devnotredirected","the","device","not","connected"],"errorCode":"2107","eventId":"","severity":"Low","summary":"The device is not connected.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2107; use the surrounding log entries to confirm it.","resolution":"1. Record where 2107 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DevNotRedirected.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2107 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The device is not connected.\n\nLookup forms: 2107, 0x83B, 0x0000083B, error 2107, NERR_DevNotRedirected. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2107"]},{"id":2757,"title":"NERR_ServerNotStarted","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2114","0x842","0x00000842","error 2114","NERR_ServerNotStarted","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","servernotstarted","the","server","service","not","started"],"errorCode":"2114","eventId":"","severity":"Low","summary":"The Server service is not started.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2114; use the surrounding log entries to confirm it.","resolution":"1. Record where 2114 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ServerNotStarted.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2114 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Server service is not started.\n\nLookup forms: 2114, 0x842, 0x00000842, error 2114, NERR_ServerNotStarted. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2114"]},{"id":2758,"title":"NERR_ItemNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2115","0x843","0x00000843","error 2115","NERR_ItemNotFound","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","itemnotfound","the","queue","empty"],"errorCode":"2115","eventId":"","severity":"Low","summary":"The queue is empty.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2115; use the surrounding log entries to confirm it.","resolution":"1. Record where 2115 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ItemNotFound.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2115 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The queue is empty.\n\nLookup forms: 2115, 0x843, 0x00000843, error 2115, NERR_ItemNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2115"]},{"id":2759,"title":"NERR_UnknownDevDir","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2116","0x844","0x00000844","error 2116","NERR_UnknownDevDir","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","unknowndevdir","the","device","directory","does","not","exist"],"errorCode":"2116","eventId":"","severity":"Low","summary":"The device or directory does not exist.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2116; use the surrounding log entries to confirm it.","resolution":"1. Record where 2116 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_UnknownDevDir.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2116 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The device or directory does not exist.\n\nLookup forms: 2116, 0x844, 0x00000844, error 2116, NERR_UnknownDevDir. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2116"]},{"id":2760,"title":"NERR_RedirectedPath","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2117","0x845","0x00000845","error 2117","NERR_RedirectedPath","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","redirectedpath","the","operation","invalid","redirected","resource"],"errorCode":"2117","eventId":"","severity":"Medium","summary":"The operation is invalid on a redirected resource.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2117; use the surrounding log entries to confirm it.","resolution":"1. Record where 2117 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RedirectedPath.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2117 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation is invalid on a redirected resource.\n\nLookup forms: 2117, 0x845, 0x00000845, error 2117, NERR_RedirectedPath. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2117"]},{"id":2761,"title":"NERR_DuplicateShare","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2118","0x846","0x00000846","error 2118","NERR_DuplicateShare","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","duplicateshare","the","name","has","already","been","shared"],"errorCode":"2118","eventId":"","severity":"Low","summary":"The name has already been shared.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2118; use the surrounding log entries to confirm it.","resolution":"1. Record where 2118 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DuplicateShare.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2118 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The name has already been shared.\n\nLookup forms: 2118, 0x846, 0x00000846, error 2118, NERR_DuplicateShare. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2118"]},{"id":2762,"title":"NERR_NoRoom","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2119","0x847","0x00000847","error 2119","NERR_NoRoom","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","noroom","the","server","currently","out","requested","resource"],"errorCode":"2119","eventId":"","severity":"Low","summary":"The server is currently out of the requested resource.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2119; use the surrounding log entries to confirm it.","resolution":"1. Record where 2119 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NoRoom.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2119 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The server is currently out of the requested resource.\n\nLookup forms: 2119, 0x847, 0x00000847, error 2119, NERR_NoRoom. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2119"]},{"id":2763,"title":"NERR_TooManyItems","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2121","0x849","0x00000849","error 2121","NERR_TooManyItems","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","toomanyitems","requested","addition","items","exceeds","the","maximum","allowed"],"errorCode":"2121","eventId":"","severity":"Low","summary":"Requested addition of items exceeds the maximum allowed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2121; use the surrounding log entries to confirm it.","resolution":"1. Record where 2121 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_TooManyItems.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2121 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Requested addition of items exceeds the maximum allowed.\n\nLookup forms: 2121, 0x849, 0x00000849, error 2121, NERR_TooManyItems. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2121"]},{"id":2764,"title":"NERR_InvalidMaxUsers","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2122","0x84A","0x0000084A","error 2122","NERR_InvalidMaxUsers","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","invalidmaxusers","the","peer","service","supports","only","two","simultaneous","users"],"errorCode":"2122","eventId":"","severity":"Low","summary":"The Peer service supports only two simultaneous users.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2122; use the surrounding log entries to confirm it.","resolution":"1. Record where 2122 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_InvalidMaxUsers.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2122 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Peer service supports only two simultaneous users.\n\nLookup forms: 2122, 0x84A, 0x0000084A, error 2122, NERR_InvalidMaxUsers. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2122"]},{"id":2765,"title":"NERR_BufTooSmall","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2123","0x84B","0x0000084B","error 2123","NERR_BufTooSmall","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","buftoosmall","the","api","return","buffer","too","small"],"errorCode":"2123","eventId":"","severity":"Low","summary":"The API return buffer is too small.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2123; use the surrounding log entries to confirm it.","resolution":"1. Record where 2123 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_BufTooSmall.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2123 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The API return buffer is too small.\n\nLookup forms: 2123, 0x84B, 0x0000084B, error 2123, NERR_BufTooSmall. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2123"]},{"id":2766,"title":"NERR_RemoteErr","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2127","0x84F","0x0000084F","error 2127","NERR_RemoteErr","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","remoteerr","remote","api","error","occurred"],"errorCode":"2127","eventId":"","severity":"Low","summary":"A remote API error occurred.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2127; use the surrounding log entries to confirm it.","resolution":"1. Record where 2127 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RemoteErr.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2127 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A remote API error occurred.\n\nLookup forms: 2127, 0x84F, 0x0000084F, error 2127, NERR_RemoteErr. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2127"]},{"id":2767,"title":"NERR_LanmanIniError","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2131","0x853","0x00000853","error 2131","NERR_LanmanIniError","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","lanmaninierror","error","occurred","when","opening","reading","the","configuration","file"],"errorCode":"2131","eventId":"","severity":"Low","summary":"An error occurred when opening or reading the configuration file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2131; use the surrounding log entries to confirm it.","resolution":"1. Record where 2131 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_LanmanIniError.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2131 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An error occurred when opening or reading the configuration file.\n\nLookup forms: 2131, 0x853, 0x00000853, error 2131, NERR_LanmanIniError. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2131"]},{"id":2768,"title":"NERR_NetworkError","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2136","0x858","0x00000858","error 2136","NERR_NetworkError","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","networkerror","general","network","error","occurred"],"errorCode":"2136","eventId":"","severity":"High","summary":"A general network error occurred.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2136; use the surrounding log entries to confirm it.","resolution":"1. Record where 2136 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NetworkError.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2136 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A general network error occurred.\n\nLookup forms: 2136, 0x858, 0x00000858, error 2136, NERR_NetworkError. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2136"]},{"id":2769,"title":"NERR_WkstaInconsistentState","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2137","0x859","0x00000859","error 2137","NERR_WkstaInconsistentState","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","wkstainconsistentstate","the","workstation","service","inconsistent","state","restart","computer","before","restarting"],"errorCode":"2137","eventId":"","severity":"Low","summary":"The Workstation service is in an inconsistent state. Restart the computer before restarting the Workstation service.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2137; use the surrounding log entries to confirm it.","resolution":"1. Record where 2137 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_WkstaInconsistentState.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2137 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Workstation service is in an inconsistent state. Restart the computer before restarting the Workstation service.\n\nLookup forms: 2137, 0x859, 0x00000859, error 2137, NERR_WkstaInconsistentState. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2137"]},{"id":2770,"title":"NERR_WkstaNotStarted","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2138","0x85A","0x0000085A","error 2138","NERR_WkstaNotStarted","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","wkstanotstarted","the","workstation","service","has","not","been","started"],"errorCode":"2138","eventId":"","severity":"Low","summary":"The Workstation service has not been started.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2138; use the surrounding log entries to confirm it.","resolution":"1. Record where 2138 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_WkstaNotStarted.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2138 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Workstation service has not been started.\n\nLookup forms: 2138, 0x85A, 0x0000085A, error 2138, NERR_WkstaNotStarted. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2138"]},{"id":2771,"title":"NERR_BrowserNotStarted","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2139","0x85B","0x0000085B","error 2139","NERR_BrowserNotStarted","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","browsernotstarted","the","requested","information","not","available"],"errorCode":"2139","eventId":"","severity":"Low","summary":"The requested information is not available.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2139; use the surrounding log entries to confirm it.","resolution":"1. Record where 2139 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_BrowserNotStarted.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2139 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested information is not available.\n\nLookup forms: 2139, 0x85B, 0x0000085B, error 2139, NERR_BrowserNotStarted. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2139"]},{"id":2772,"title":"NERR_InternalError","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2140","0x85C","0x0000085C","error 2140","NERR_InternalError","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","internalerror","internal","error","occurred"],"errorCode":"2140","eventId":"","severity":"Low","summary":"An internal error occurred.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2140; use the surrounding log entries to confirm it.","resolution":"1. Record where 2140 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_InternalError.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2140 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An internal error occurred.\n\nLookup forms: 2140, 0x85C, 0x0000085C, error 2140, NERR_InternalError. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2140"]},{"id":2773,"title":"NERR_BadTransactConfig","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2141","0x85D","0x0000085D","error 2141","NERR_BadTransactConfig","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","badtransactconfig","the","server","not","configured","for","transactions"],"errorCode":"2141","eventId":"","severity":"Low","summary":"The server is not configured for transactions.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2141; use the surrounding log entries to confirm it.","resolution":"1. Record where 2141 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_BadTransactConfig.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2141 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The server is not configured for transactions.\n\nLookup forms: 2141, 0x85D, 0x0000085D, error 2141, NERR_BadTransactConfig. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2141"]},{"id":2774,"title":"NERR_InvalidAPI","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2142","0x85E","0x0000085E","error 2142","NERR_InvalidAPI","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","invalidapi","the","requested","api","not","supported","remote","server"],"errorCode":"2142","eventId":"","severity":"Medium","summary":"The requested API is not supported on the remote server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2142; use the surrounding log entries to confirm it.","resolution":"1. Record where 2142 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_InvalidAPI.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2142 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested API is not supported on the remote server.\n\nLookup forms: 2142, 0x85E, 0x0000085E, error 2142, NERR_InvalidAPI. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2142"]},{"id":2775,"title":"NERR_BadEventName","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2143","0x85F","0x0000085F","error 2143","NERR_BadEventName","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","badeventname","the","event","name","invalid"],"errorCode":"2143","eventId":"","severity":"Medium","summary":"The event name is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2143; use the surrounding log entries to confirm it.","resolution":"1. Record where 2143 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_BadEventName.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2143 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The event name is invalid.\n\nLookup forms: 2143, 0x85F, 0x0000085F, error 2143, NERR_BadEventName. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2143"]},{"id":2776,"title":"NERR_DupNameReboot","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2144","0x860","0x00000860","error 2144","NERR_DupNameReboot","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","dupnamereboot","the","computer","name","already","exists","network","change","and","reboot"],"errorCode":"2144","eventId":"","severity":"High","summary":"The computer name already exists on the network. Change it and reboot the computer.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2144; use the surrounding log entries to confirm it.","resolution":"1. Record where 2144 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DupNameReboot.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2144 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The computer name already exists on the network. Change it and reboot the computer.\n\nLookup forms: 2144, 0x860, 0x00000860, error 2144, NERR_DupNameReboot. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2144"]},{"id":2777,"title":"NERR_CfgCompNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2146","0x862","0x00000862","error 2146","NERR_CfgCompNotFound","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","cfgcompnotfound","the","specified","component","could","not","found","configuration","information"],"errorCode":"2146","eventId":"","severity":"Low","summary":"The specified component could not be found in the configuration information.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2146; use the surrounding log entries to confirm it.","resolution":"1. Record where 2146 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_CfgCompNotFound.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2146 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified component could not be found in the configuration information.\n\nLookup forms: 2146, 0x862, 0x00000862, error 2146, NERR_CfgCompNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2146"]},{"id":2778,"title":"NERR_CfgParamNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2147","0x863","0x00000863","error 2147","NERR_CfgParamNotFound","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","cfgparamnotfound","the","specified","parameter","could","not","found","configuration","information"],"errorCode":"2147","eventId":"","severity":"Low","summary":"The specified parameter could not be found in the configuration information.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2147; use the surrounding log entries to confirm it.","resolution":"1. Record where 2147 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_CfgParamNotFound.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2147 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified parameter could not be found in the configuration information.\n\nLookup forms: 2147, 0x863, 0x00000863, error 2147, NERR_CfgParamNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2147"]},{"id":2779,"title":"NERR_LineTooLong","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2149","0x865","0x00000865","error 2149","NERR_LineTooLong","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","linetoolong","line","the","configuration","file","too","long"],"errorCode":"2149","eventId":"","severity":"Low","summary":"A line in the configuration file is too long.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2149; use the surrounding log entries to confirm it.","resolution":"1. Record where 2149 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_LineTooLong.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2149 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A line in the configuration file is too long.\n\nLookup forms: 2149, 0x865, 0x00000865, error 2149, NERR_LineTooLong. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2149"]},{"id":2780,"title":"NERR_QNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2150","0x866","0x00000866","error 2150","NERR_QNotFound","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","qnotfound","the","printer","does","not","exist"],"errorCode":"2150","eventId":"","severity":"Low","summary":"The printer does not exist.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2150; use the surrounding log entries to confirm it.","resolution":"1. Record where 2150 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_QNotFound.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2150 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The printer does not exist.\n\nLookup forms: 2150, 0x866, 0x00000866, error 2150, NERR_QNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2150"]},{"id":2781,"title":"NERR_JobNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2151","0x867","0x00000867","error 2151","NERR_JobNotFound","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","jobnotfound","the","print","job","does","not","exist"],"errorCode":"2151","eventId":"","severity":"Low","summary":"The print job does not exist.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2151; use the surrounding log entries to confirm it.","resolution":"1. Record where 2151 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_JobNotFound.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2151 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The print job does not exist.\n\nLookup forms: 2151, 0x867, 0x00000867, error 2151, NERR_JobNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2151"]},{"id":2782,"title":"NERR_DestNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2152","0x868","0x00000868","error 2152","NERR_DestNotFound","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","destnotfound","the","printer","destination","cannot","found"],"errorCode":"2152","eventId":"","severity":"Medium","summary":"The printer destination cannot be found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2152; use the surrounding log entries to confirm it.","resolution":"1. Record where 2152 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DestNotFound.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2152 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The printer destination cannot be found.\n\nLookup forms: 2152, 0x868, 0x00000868, error 2152, NERR_DestNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2152"]},{"id":2783,"title":"NERR_DestExists","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2153","0x869","0x00000869","error 2153","NERR_DestExists","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","destexists","the","printer","destination","already","exists"],"errorCode":"2153","eventId":"","severity":"Medium","summary":"The printer destination already exists.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2153; use the surrounding log entries to confirm it.","resolution":"1. Record where 2153 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DestExists.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2153 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The printer destination already exists.\n\nLookup forms: 2153, 0x869, 0x00000869, error 2153, NERR_DestExists. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2153"]},{"id":2784,"title":"NERR_QExists","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2154","0x86A","0x0000086A","error 2154","NERR_QExists","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","qexists","the","print","queue","already","exists"],"errorCode":"2154","eventId":"","severity":"Medium","summary":"The print queue already exists.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2154; use the surrounding log entries to confirm it.","resolution":"1. Record where 2154 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_QExists.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2154 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The print queue already exists.\n\nLookup forms: 2154, 0x86A, 0x0000086A, error 2154, NERR_QExists. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2154"]},{"id":2785,"title":"NERR_QNoRoom","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2155","0x86B","0x0000086B","error 2155","NERR_QNoRoom","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","qnoroom","more","printers","can","added"],"errorCode":"2155","eventId":"","severity":"Low","summary":"No more printers can be added.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2155; use the surrounding log entries to confirm it.","resolution":"1. Record where 2155 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_QNoRoom.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2155 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No more printers can be added.\n\nLookup forms: 2155, 0x86B, 0x0000086B, error 2155, NERR_QNoRoom. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2155"]},{"id":2786,"title":"NERR_JobNoRoom","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2156","0x86C","0x0000086C","error 2156","NERR_JobNoRoom","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","jobnoroom","more","print","jobs","can","added"],"errorCode":"2156","eventId":"","severity":"Low","summary":"No more print jobs can be added.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2156; use the surrounding log entries to confirm it.","resolution":"1. Record where 2156 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_JobNoRoom.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2156 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No more print jobs can be added.\n\nLookup forms: 2156, 0x86C, 0x0000086C, error 2156, NERR_JobNoRoom. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2156"]},{"id":2787,"title":"NERR_DestNoRoom","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2157","0x86D","0x0000086D","error 2157","NERR_DestNoRoom","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","destnoroom","more","printer","destinations","can","added"],"errorCode":"2157","eventId":"","severity":"Low","summary":"No more printer destinations can be added.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2157; use the surrounding log entries to confirm it.","resolution":"1. Record where 2157 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DestNoRoom.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2157 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No more printer destinations can be added.\n\nLookup forms: 2157, 0x86D, 0x0000086D, error 2157, NERR_DestNoRoom. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2157"]},{"id":2788,"title":"NERR_DestIdle","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2158","0x86E","0x0000086E","error 2158","NERR_DestIdle","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","destidle","this","printer","destination","idle","and","cannot","accept","control","operations"],"errorCode":"2158","eventId":"","severity":"Medium","summary":"This printer destination is idle and cannot accept control operations.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2158; use the surrounding log entries to confirm it.","resolution":"1. Record where 2158 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DestIdle.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2158 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This printer destination is idle and cannot accept control operations.\n\nLookup forms: 2158, 0x86E, 0x0000086E, error 2158, NERR_DestIdle. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2158"]},{"id":2789,"title":"NERR_DestInvalidOp","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2159","0x86F","0x0000086F","error 2159","NERR_DestInvalidOp","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","destinvalidop","this","printer","destination","request","contains","invalid","control","function"],"errorCode":"2159","eventId":"","severity":"Medium","summary":"This printer destination request contains an invalid control function.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2159; use the surrounding log entries to confirm it.","resolution":"1. Record where 2159 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DestInvalidOp.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2159 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This printer destination request contains an invalid control function.\n\nLookup forms: 2159, 0x86F, 0x0000086F, error 2159, NERR_DestInvalidOp. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2159"]},{"id":2790,"title":"NERR_ProcNoRespond","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2160","0x870","0x00000870","error 2160","NERR_ProcNoRespond","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","procnorespond","the","print","processor","not","responding"],"errorCode":"2160","eventId":"","severity":"Low","summary":"The print processor is not responding.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2160; use the surrounding log entries to confirm it.","resolution":"1. Record where 2160 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ProcNoRespond.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2160 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The print processor is not responding.\n\nLookup forms: 2160, 0x870, 0x00000870, error 2160, NERR_ProcNoRespond. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2160"]},{"id":2791,"title":"NERR_SpoolerNotLoaded","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2161","0x871","0x00000871","error 2161","NERR_SpoolerNotLoaded","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","spoolernotloaded","the","spooler","not","running"],"errorCode":"2161","eventId":"","severity":"Low","summary":"The spooler is not running.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2161; use the surrounding log entries to confirm it.","resolution":"1. Record where 2161 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_SpoolerNotLoaded.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2161 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The spooler is not running.\n\nLookup forms: 2161, 0x871, 0x00000871, error 2161, NERR_SpoolerNotLoaded. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2161"]},{"id":2792,"title":"NERR_DestInvalidState","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2162","0x872","0x00000872","error 2162","NERR_DestInvalidState","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","destinvalidstate","this","operation","cannot","performed","the","print","destination","its","current","state"],"errorCode":"2162","eventId":"","severity":"Medium","summary":"This operation cannot be performed on the print destination in its current state.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2162; use the surrounding log entries to confirm it.","resolution":"1. Record where 2162 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DestInvalidState.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2162 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation cannot be performed on the print destination in its current state.\n\nLookup forms: 2162, 0x872, 0x00000872, error 2162, NERR_DestInvalidState. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2162"]},{"id":2793,"title":"NERR_QinvalidState","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2163","0x873","0x00000873","error 2163","NERR_QinvalidState","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","qinvalidstate","this","operation","cannot","performed","the","print","queue","its","current","state"],"errorCode":"2163","eventId":"","severity":"Medium","summary":"This operation cannot be performed on the print queue in its current state.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2163; use the surrounding log entries to confirm it.","resolution":"1. Record where 2163 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_QinvalidState.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2163 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation cannot be performed on the print queue in its current state.\n\nLookup forms: 2163, 0x873, 0x00000873, error 2163, NERR_QinvalidState. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2163"]},{"id":2794,"title":"NERR_JobInvalidState","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2164","0x874","0x00000874","error 2164","NERR_JobInvalidState","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","jobinvalidstate","this","operation","cannot","performed","the","print","job","its","current","state"],"errorCode":"2164","eventId":"","severity":"Medium","summary":"This operation cannot be performed on the print job in its current state.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2164; use the surrounding log entries to confirm it.","resolution":"1. Record where 2164 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_JobInvalidState.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2164 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation cannot be performed on the print job in its current state.\n\nLookup forms: 2164, 0x874, 0x00000874, error 2164, NERR_JobInvalidState. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2164"]},{"id":2795,"title":"NERR_SpoolNoMemory","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2165","0x875","0x00000875","error 2165","NERR_SpoolNoMemory","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","spoolnomemory","spooler","memory","allocation","failure","occurred"],"errorCode":"2165","eventId":"","severity":"High","summary":"A spooler memory allocation failure occurred.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2165; use the surrounding log entries to confirm it.","resolution":"1. Record where 2165 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_SpoolNoMemory.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2165 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A spooler memory allocation failure occurred.\n\nLookup forms: 2165, 0x875, 0x00000875, error 2165, NERR_SpoolNoMemory. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2165"]},{"id":2796,"title":"NERR_DriverNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2166","0x876","0x00000876","error 2166","NERR_DriverNotFound","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","drivernotfound","the","device","driver","does","not","exist"],"errorCode":"2166","eventId":"","severity":"Low","summary":"The device driver does not exist.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2166; use the surrounding log entries to confirm it.","resolution":"1. Record where 2166 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DriverNotFound.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2166 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The device driver does not exist.\n\nLookup forms: 2166, 0x876, 0x00000876, error 2166, NERR_DriverNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2166"]},{"id":2797,"title":"NERR_DataTypeInvalid","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2167","0x877","0x00000877","error 2167","NERR_DataTypeInvalid","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","datatypeinvalid","the","data","type","not","supported","print","processor"],"errorCode":"2167","eventId":"","severity":"Medium","summary":"The data type is not supported by the print processor.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2167; use the surrounding log entries to confirm it.","resolution":"1. Record where 2167 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DataTypeInvalid.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2167 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The data type is not supported by the print processor.\n\nLookup forms: 2167, 0x877, 0x00000877, error 2167, NERR_DataTypeInvalid. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2167"]},{"id":2798,"title":"NERR_ProcNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2168","0x878","0x00000878","error 2168","NERR_ProcNotFound","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","procnotfound","the","print","processor","not","installed"],"errorCode":"2168","eventId":"","severity":"Low","summary":"The print processor is not installed.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2168; use the surrounding log entries to confirm it.","resolution":"1. Record where 2168 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ProcNotFound.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2168 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The print processor is not installed.\n\nLookup forms: 2168, 0x878, 0x00000878, error 2168, NERR_ProcNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2168"]},{"id":2799,"title":"NERR_ServiceTableLocked","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2180","0x884","0x00000884","error 2180","NERR_ServiceTableLocked","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","servicetablelocked","the","service","database","locked"],"errorCode":"2180","eventId":"","severity":"High","summary":"The service database is locked.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2180; use the surrounding log entries to confirm it.","resolution":"1. Record where 2180 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ServiceTableLocked.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2180 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The service database is locked.\n\nLookup forms: 2180, 0x884, 0x00000884, error 2180, NERR_ServiceTableLocked. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2180"]},{"id":2800,"title":"NERR_ServiceTableFull","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2181","0x885","0x00000885","error 2181","NERR_ServiceTableFull","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","servicetablefull","the","service","table","full"],"errorCode":"2181","eventId":"","severity":"Low","summary":"The service table is full.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2181; use the surrounding log entries to confirm it.","resolution":"1. Record where 2181 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ServiceTableFull.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2181 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The service table is full.\n\nLookup forms: 2181, 0x885, 0x00000885, error 2181, NERR_ServiceTableFull. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2181"]},{"id":2801,"title":"NERR_ServiceInstalled","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2182","0x886","0x00000886","error 2182","NERR_ServiceInstalled","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","serviceinstalled","the","requested","service","has","already","been","started"],"errorCode":"2182","eventId":"","severity":"Low","summary":"The requested service has already been started.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2182; use the surrounding log entries to confirm it.","resolution":"1. Record where 2182 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ServiceInstalled.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2182 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested service has already been started.\n\nLookup forms: 2182, 0x886, 0x00000886, error 2182, NERR_ServiceInstalled. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2182"]},{"id":2802,"title":"NERR_ServiceEntryLocked","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2183","0x887","0x00000887","error 2183","NERR_ServiceEntryLocked","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","serviceentrylocked","the","service","does","not","respond","control","actions"],"errorCode":"2183","eventId":"","severity":"Low","summary":"The service does not respond to control actions.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2183; use the surrounding log entries to confirm it.","resolution":"1. Record where 2183 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ServiceEntryLocked.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2183 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The service does not respond to control actions.\n\nLookup forms: 2183, 0x887, 0x00000887, error 2183, NERR_ServiceEntryLocked. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2183"]},{"id":2803,"title":"NERR_ServiceNotInstalled","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2184","0x888","0x00000888","error 2184","NERR_ServiceNotInstalled","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","servicenotinstalled","the","service","has","not","been","started"],"errorCode":"2184","eventId":"","severity":"Low","summary":"The service has not been started.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2184; use the surrounding log entries to confirm it.","resolution":"1. Record where 2184 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ServiceNotInstalled.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2184 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The service has not been started.\n\nLookup forms: 2184, 0x888, 0x00000888, error 2184, NERR_ServiceNotInstalled. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2184"]},{"id":2804,"title":"NERR_BadServiceName","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2185","0x889","0x00000889","error 2185","NERR_BadServiceName","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","badservicename","the","service","name","invalid"],"errorCode":"2185","eventId":"","severity":"Medium","summary":"The service name is invalid.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2185; use the surrounding log entries to confirm it.","resolution":"1. Record where 2185 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_BadServiceName.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2185 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The service name is invalid.\n\nLookup forms: 2185, 0x889, 0x00000889, error 2185, NERR_BadServiceName. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2185"]},{"id":2805,"title":"NERR_ServiceCtlTimeout","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2186","0x88A","0x0000088A","error 2186","NERR_ServiceCtlTimeout","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","servicectltimeout","the","service","not","responding","control","function"],"errorCode":"2186","eventId":"","severity":"Low","summary":"The service is not responding to the control function.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2186; use the surrounding log entries to confirm it.","resolution":"1. Record where 2186 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ServiceCtlTimeout.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2186 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The service is not responding to the control function.\n\nLookup forms: 2186, 0x88A, 0x0000088A, error 2186, NERR_ServiceCtlTimeout. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2186"]},{"id":2806,"title":"NERR_ServiceCtlBusy","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2187","0x88B","0x0000088B","error 2187","NERR_ServiceCtlBusy","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","servicectlbusy","the","service","control","busy"],"errorCode":"2187","eventId":"","severity":"Medium","summary":"The service control is busy.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2187; use the surrounding log entries to confirm it.","resolution":"1. Record where 2187 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ServiceCtlBusy.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2187 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The service control is busy.\n\nLookup forms: 2187, 0x88B, 0x0000088B, error 2187, NERR_ServiceCtlBusy. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2187"]},{"id":2807,"title":"NERR_BadServiceProgName","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2188","0x88C","0x0000088C","error 2188","NERR_BadServiceProgName","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","badserviceprogname","the","configuration","file","contains","invalid","service","program","name"],"errorCode":"2188","eventId":"","severity":"Medium","summary":"The configuration file contains an invalid service program name.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2188; use the surrounding log entries to confirm it.","resolution":"1. Record where 2188 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_BadServiceProgName.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2188 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The configuration file contains an invalid service program name.\n\nLookup forms: 2188, 0x88C, 0x0000088C, error 2188, NERR_BadServiceProgName. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2188"]},{"id":2808,"title":"NERR_ServiceNotCtrl","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2189","0x88D","0x0000088D","error 2189","NERR_ServiceNotCtrl","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","servicenotctrl","the","service","could","not","controlled","its","present","state"],"errorCode":"2189","eventId":"","severity":"Low","summary":"The service could not be controlled in its present state.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2189; use the surrounding log entries to confirm it.","resolution":"1. Record where 2189 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ServiceNotCtrl.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2189 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The service could not be controlled in its present state.\n\nLookup forms: 2189, 0x88D, 0x0000088D, error 2189, NERR_ServiceNotCtrl. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2189"]},{"id":2809,"title":"NERR_ServiceKillProc","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2190","0x88E","0x0000088E","error 2190","NERR_ServiceKillProc","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","servicekillproc","the","service","ended","abnormally"],"errorCode":"2190","eventId":"","severity":"Low","summary":"The service ended abnormally.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2190; use the surrounding log entries to confirm it.","resolution":"1. Record where 2190 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ServiceKillProc.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2190 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The service ended abnormally.\n\nLookup forms: 2190, 0x88E, 0x0000088E, error 2190, NERR_ServiceKillProc. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2190"]},{"id":2810,"title":"NERR_ServiceCtlNotValid","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2191","0x88F","0x0000088F","error 2191","NERR_ServiceCtlNotValid","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","servicectlnotvalid","the","requested","pause","stop","not","valid","for","this","service"],"errorCode":"2191","eventId":"","severity":"Low","summary":"The requested pause or stop is not valid for this service.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2191; use the surrounding log entries to confirm it.","resolution":"1. Record where 2191 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ServiceCtlNotValid.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2191 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested pause or stop is not valid for this service.\n\nLookup forms: 2191, 0x88F, 0x0000088F, error 2191, NERR_ServiceCtlNotValid. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2191"]},{"id":2811,"title":"NERR_NotInDispatchTbl","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2192","0x890","0x00000890","error 2192","NERR_NotInDispatchTbl","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","notindispatchtbl","the","service","control","dispatcher","could","not","find","name","dispatch","table"],"errorCode":"2192","eventId":"","severity":"Low","summary":"The service control dispatcher could not find the service name in the dispatch table.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2192; use the surrounding log entries to confirm it.","resolution":"1. Record where 2192 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NotInDispatchTbl.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2192 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The service control dispatcher could not find the service name in the dispatch table.\n\nLookup forms: 2192, 0x890, 0x00000890, error 2192, NERR_NotInDispatchTbl. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2192"]},{"id":2812,"title":"NERR_BadControlRecv","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2193","0x891","0x00000891","error 2193","NERR_BadControlRecv","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","badcontrolrecv","the","service","control","dispatcher","pipe","read","failed"],"errorCode":"2193","eventId":"","severity":"High","summary":"The service control dispatcher pipe read failed.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2193; use the surrounding log entries to confirm it.","resolution":"1. Record where 2193 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_BadControlRecv.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2193 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The service control dispatcher pipe read failed.\n\nLookup forms: 2193, 0x891, 0x00000891, error 2193, NERR_BadControlRecv. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2193"]},{"id":2813,"title":"NERR_ServiceNotStarting","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2194","0x892","0x00000892","error 2194","NERR_ServiceNotStarting","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","servicenotstarting","thread","for","the","new","service","could","not","created"],"errorCode":"2194","eventId":"","severity":"Low","summary":"A thread for the new service could not be created.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2194; use the surrounding log entries to confirm it.","resolution":"1. Record where 2194 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ServiceNotStarting.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2194 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A thread for the new service could not be created.\n\nLookup forms: 2194, 0x892, 0x00000892, error 2194, NERR_ServiceNotStarting. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2194"]},{"id":2814,"title":"NERR_AlreadyLoggedOn","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2200","0x898","0x00000898","error 2200","NERR_AlreadyLoggedOn","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","alreadyloggedon","this","workstation","already","logged","the","lan"],"errorCode":"2200","eventId":"","severity":"Low","summary":"This workstation is already logged on to the LAN.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2200; use the surrounding log entries to confirm it.","resolution":"1. Record where 2200 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_AlreadyLoggedOn.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2200 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This workstation is already logged on to the LAN.\n\nLookup forms: 2200, 0x898, 0x00000898, error 2200, NERR_AlreadyLoggedOn. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2200"]},{"id":2815,"title":"NERR_NotLoggedOn","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2201","0x899","0x00000899","error 2201","NERR_NotLoggedOn","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","notloggedon","the","workstation","not","logged","lan"],"errorCode":"2201","eventId":"","severity":"Low","summary":"The workstation is not logged on to the LAN.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2201; use the surrounding log entries to confirm it.","resolution":"1. Record where 2201 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NotLoggedOn.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2201 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The workstation is not logged on to the LAN.\n\nLookup forms: 2201, 0x899, 0x00000899, error 2201, NERR_NotLoggedOn. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2201"]},{"id":2816,"title":"NERR_BadPassword","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2203","0x89B","0x0000089B","error 2203","NERR_BadPassword","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","badpassword","the","password","parameter","invalid"],"errorCode":"2203","eventId":"","severity":"Medium","summary":"The password parameter is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2203; use the surrounding log entries to confirm it.","resolution":"1. Record where 2203 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_BadPassword.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2203 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The password parameter is invalid.\n\nLookup forms: 2203, 0x89B, 0x0000089B, error 2203, NERR_BadPassword. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2203"]},{"id":2817,"title":"NERR_UnableToAddName_W","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2204","0x89C","0x0000089C","error 2204","NERR_UnableToAddName_W","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","unabletoaddname","the","logon","processor","did","not","add","message","alias"],"errorCode":"2204","eventId":"","severity":"High","summary":"The logon processor did not add the message alias.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2204; use the surrounding log entries to confirm it.","resolution":"1. Record where 2204 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_UnableToAddName_W.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2204 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The logon processor did not add the message alias.\n\nLookup forms: 2204, 0x89C, 0x0000089C, error 2204, NERR_UnableToAddName_W. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2204"]},{"id":2818,"title":"NERR_UnableToAddName_F","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2205","0x89D","0x0000089D","error 2205","NERR_UnableToAddName_F","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","unabletoaddname","the","logon","processor","did","not","add","message","alias"],"errorCode":"2205","eventId":"","severity":"High","summary":"The logon processor did not add the message alias.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2205; use the surrounding log entries to confirm it.","resolution":"1. Record where 2205 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_UnableToAddName_F.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2205 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The logon processor did not add the message alias.\n\nLookup forms: 2205, 0x89D, 0x0000089D, error 2205, NERR_UnableToAddName_F. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2205"]},{"id":2819,"title":"NERR_UnableToDelName_W","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2206","0x89E","0x0000089E","error 2206","NERR_UnableToDelName_W","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","unabletodelname","the","logoff","processor","did","not","delete","message","alias"],"errorCode":"2206","eventId":"","severity":"Low","summary":"The logoff processor did not delete the message alias.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2206; use the surrounding log entries to confirm it.","resolution":"1. Record where 2206 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_UnableToDelName_W.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2206 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The logoff processor did not delete the message alias.\n\nLookup forms: 2206, 0x89E, 0x0000089E, error 2206, NERR_UnableToDelName_W. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2206"]},{"id":2820,"title":"NERR_UnableToDelName_F","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2207","0x89F","0x0000089F","error 2207","NERR_UnableToDelName_F","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","unabletodelname","the","logoff","processor","did","not","delete","message","alias"],"errorCode":"2207","eventId":"","severity":"Low","summary":"The logoff processor did not delete the message alias.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2207; use the surrounding log entries to confirm it.","resolution":"1. Record where 2207 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_UnableToDelName_F.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2207 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The logoff processor did not delete the message alias.\n\nLookup forms: 2207, 0x89F, 0x0000089F, error 2207, NERR_UnableToDelName_F. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2207"]},{"id":2821,"title":"NERR_LogonsPaused","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2209","0x8A1","0x000008A1","error 2209","NERR_LogonsPaused","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","logonspaused","network","logons","are","paused"],"errorCode":"2209","eventId":"","severity":"High","summary":"Network logons are paused.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2209; use the surrounding log entries to confirm it.","resolution":"1. Record where 2209 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_LogonsPaused.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2209 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Network logons are paused.\n\nLookup forms: 2209, 0x8A1, 0x000008A1, error 2209, NERR_LogonsPaused. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2209"]},{"id":2822,"title":"NERR_LogonServerConflict","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2210","0x8A2","0x000008A2","error 2210","NERR_LogonServerConflict","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","logonserverconflict","centralized","logon","server","conflict","occurred"],"errorCode":"2210","eventId":"","severity":"High","summary":"A centralized logon server conflict occurred.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2210; use the surrounding log entries to confirm it.","resolution":"1. Record where 2210 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_LogonServerConflict.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2210 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A centralized logon server conflict occurred.\n\nLookup forms: 2210, 0x8A2, 0x000008A2, error 2210, NERR_LogonServerConflict. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2210"]},{"id":2823,"title":"NERR_LogonNoUserPath","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2211","0x8A3","0x000008A3","error 2211","NERR_LogonNoUserPath","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","logonnouserpath","the","server","configured","without","valid","user","path"],"errorCode":"2211","eventId":"","severity":"Low","summary":"The server is configured without a valid user path.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2211; use the surrounding log entries to confirm it.","resolution":"1. Record where 2211 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_LogonNoUserPath.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2211 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The server is configured without a valid user path.\n\nLookup forms: 2211, 0x8A3, 0x000008A3, error 2211, NERR_LogonNoUserPath. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2211"]},{"id":2824,"title":"NERR_LogonScriptError","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2212","0x8A4","0x000008A4","error 2212","NERR_LogonScriptError","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","logonscripterror","error","occurred","while","loading","running","the","logon","script"],"errorCode":"2212","eventId":"","severity":"High","summary":"An error occurred while loading or running the logon script.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2212; use the surrounding log entries to confirm it.","resolution":"1. Record where 2212 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_LogonScriptError.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2212 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An error occurred while loading or running the logon script.\n\nLookup forms: 2212, 0x8A4, 0x000008A4, error 2212, NERR_LogonScriptError. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2212"]},{"id":2825,"title":"NERR_StandaloneLogon","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2214","0x8A6","0x000008A6","error 2214","NERR_StandaloneLogon","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","standalonelogon","the","logon","server","was","not","specified","computer","will","logged","standalone"],"errorCode":"2214","eventId":"","severity":"High","summary":"The logon server was not specified. The computer will be logged on as STANDALONE.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2214; use the surrounding log entries to confirm it.","resolution":"1. Record where 2214 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_StandaloneLogon.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2214 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The logon server was not specified. The computer will be logged on as STANDALONE.\n\nLookup forms: 2214, 0x8A6, 0x000008A6, error 2214, NERR_StandaloneLogon. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2214"]},{"id":2826,"title":"NERR_LogonServerNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2215","0x8A7","0x000008A7","error 2215","NERR_LogonServerNotFound","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","logonservernotfound","the","logon","server","could","not","found"],"errorCode":"2215","eventId":"","severity":"High","summary":"The logon server could not be found.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2215; use the surrounding log entries to confirm it.","resolution":"1. Record where 2215 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_LogonServerNotFound.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2215 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The logon server could not be found.\n\nLookup forms: 2215, 0x8A7, 0x000008A7, error 2215, NERR_LogonServerNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2215"]},{"id":2827,"title":"NERR_LogonDomainExists","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2216","0x8A8","0x000008A8","error 2216","NERR_LogonDomainExists","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","logondomainexists","there","already","logon","domain","for","this","computer"],"errorCode":"2216","eventId":"","severity":"High","summary":"There is already a logon domain for this computer.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2216; use the surrounding log entries to confirm it.","resolution":"1. Record where 2216 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_LogonDomainExists.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2216 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There is already a logon domain for this computer.\n\nLookup forms: 2216, 0x8A8, 0x000008A8, error 2216, NERR_LogonDomainExists. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2216"]},{"id":2828,"title":"NERR_NonValidatedLogon","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2217","0x8A9","0x000008A9","error 2217","NERR_NonValidatedLogon","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","nonvalidatedlogon","the","logon","server","could","not","validate"],"errorCode":"2217","eventId":"","severity":"High","summary":"The logon server could not validate the logon.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2217; use the surrounding log entries to confirm it.","resolution":"1. Record where 2217 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NonValidatedLogon.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2217 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The logon server could not validate the logon.\n\nLookup forms: 2217, 0x8A9, 0x000008A9, error 2217, NERR_NonValidatedLogon. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2217"]},{"id":2829,"title":"NERR_ACFNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2219","0x8AB","0x000008AB","error 2219","NERR_ACFNotFound","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","acfnotfound","the","security","database","could","not","found"],"errorCode":"2219","eventId":"","severity":"Low","summary":"The security database could not be found.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2219; use the surrounding log entries to confirm it.","resolution":"1. Record where 2219 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ACFNotFound.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2219 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The security database could not be found.\n\nLookup forms: 2219, 0x8AB, 0x000008AB, error 2219, NERR_ACFNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2219"]},{"id":2830,"title":"NERR_GroupNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2220","0x8AC","0x000008AC","error 2220","NERR_GroupNotFound","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","groupnotfound","the","group","name","could","not","found"],"errorCode":"2220","eventId":"","severity":"Low","summary":"The group name could not be found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2220; use the surrounding log entries to confirm it.","resolution":"1. Record where 2220 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_GroupNotFound.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2220 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The group name could not be found.\n\nLookup forms: 2220, 0x8AC, 0x000008AC, error 2220, NERR_GroupNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2220"]},{"id":2831,"title":"NERR_UserNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2221","0x8AD","0x000008AD","error 2221","NERR_UserNotFound","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","usernotfound","the","user","name","could","not","found"],"errorCode":"2221","eventId":"","severity":"Low","summary":"The user name could not be found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2221; use the surrounding log entries to confirm it.","resolution":"1. Record where 2221 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_UserNotFound.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2221 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The user name could not be found.\n\nLookup forms: 2221, 0x8AD, 0x000008AD, error 2221, NERR_UserNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2221"]},{"id":2832,"title":"NERR_ResourceNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2222","0x8AE","0x000008AE","error 2222","NERR_ResourceNotFound","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","resourcenotfound","the","resource","name","could","not","found"],"errorCode":"2222","eventId":"","severity":"Low","summary":"The resource name could not be found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2222; use the surrounding log entries to confirm it.","resolution":"1. Record where 2222 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ResourceNotFound.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2222 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The resource name could not be found.\n\nLookup forms: 2222, 0x8AE, 0x000008AE, error 2222, NERR_ResourceNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2222"]},{"id":2833,"title":"NERR_GroupExists","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2223","0x8AF","0x000008AF","error 2223","NERR_GroupExists","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","groupexists","the","group","already","exists"],"errorCode":"2223","eventId":"","severity":"Medium","summary":"The group already exists.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2223; use the surrounding log entries to confirm it.","resolution":"1. Record where 2223 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_GroupExists.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2223 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The group already exists.\n\nLookup forms: 2223, 0x8AF, 0x000008AF, error 2223, NERR_GroupExists. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2223"]},{"id":2834,"title":"NERR_UserExists","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2224","0x8B0","0x000008B0","error 2224","NERR_UserExists","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","userexists","the","user","account","already","exists"],"errorCode":"2224","eventId":"","severity":"Medium","summary":"The user account already exists.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2224; use the surrounding log entries to confirm it.","resolution":"1. Record where 2224 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_UserExists.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2224 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The user account already exists.\n\nLookup forms: 2224, 0x8B0, 0x000008B0, error 2224, NERR_UserExists. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2224"]},{"id":2835,"title":"NERR_ResourceExists","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2225","0x8B1","0x000008B1","error 2225","NERR_ResourceExists","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","resourceexists","the","resource","permission","list","already","exists"],"errorCode":"2225","eventId":"","severity":"Medium","summary":"The resource permission list already exists.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2225; use the surrounding log entries to confirm it.","resolution":"1. Record where 2225 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ResourceExists.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2225 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The resource permission list already exists.\n\nLookup forms: 2225, 0x8B1, 0x000008B1, error 2225, NERR_ResourceExists. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2225"]},{"id":2836,"title":"NERR_NotPrimary","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2226","0x8B2","0x000008B2","error 2226","NERR_NotPrimary","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","notprimary","this","operation","allowed","only","the","pdc","domain"],"errorCode":"2226","eventId":"","severity":"Low","summary":"This operation is allowed only on the PDC of the domain.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2226; use the surrounding log entries to confirm it.","resolution":"1. Record where 2226 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NotPrimary.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2226 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation is allowed only on the PDC of the domain.\n\nLookup forms: 2226, 0x8B2, 0x000008B2, error 2226, NERR_NotPrimary. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2226"]},{"id":2837,"title":"NERR_ACFNotLoaded","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2227","0x8B3","0x000008B3","error 2227","NERR_ACFNotLoaded","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","acfnotloaded","the","security","database","has","not","been","started"],"errorCode":"2227","eventId":"","severity":"Low","summary":"The security database has not been started.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2227; use the surrounding log entries to confirm it.","resolution":"1. Record where 2227 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ACFNotLoaded.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2227 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The security database has not been started.\n\nLookup forms: 2227, 0x8B3, 0x000008B3, error 2227, NERR_ACFNotLoaded. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2227"]},{"id":2838,"title":"NERR_ACFNoRoom","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2228","0x8B4","0x000008B4","error 2228","NERR_ACFNoRoom","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","acfnoroom","there","are","too","many","names","the","user","accounts","database"],"errorCode":"2228","eventId":"","severity":"Low","summary":"There are too many names in the user accounts database.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2228; use the surrounding log entries to confirm it.","resolution":"1. Record where 2228 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ACFNoRoom.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2228 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There are too many names in the user accounts database.\n\nLookup forms: 2228, 0x8B4, 0x000008B4, error 2228, NERR_ACFNoRoom. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2228"]},{"id":2839,"title":"NERR_ACFFileIOFail","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2229","0x8B5","0x000008B5","error 2229","NERR_ACFFileIOFail","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","acffileiofail","disk","failure","occurred"],"errorCode":"2229","eventId":"","severity":"High","summary":"A disk I/O failure occurred.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2229; use the surrounding log entries to confirm it.","resolution":"1. Record where 2229 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ACFFileIOFail.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2229 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A disk I/O failure occurred.\n\nLookup forms: 2229, 0x8B5, 0x000008B5, error 2229, NERR_ACFFileIOFail. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2229"]},{"id":2840,"title":"NERR_ACFTooManyLists","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2230","0x8B6","0x000008B6","error 2230","NERR_ACFTooManyLists","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","acftoomanylists","the","limit","entries","per","resource","was","exceeded"],"errorCode":"2230","eventId":"","severity":"Low","summary":"The limit of 64 entries per resource was exceeded.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2230; use the surrounding log entries to confirm it.","resolution":"1. Record where 2230 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ACFTooManyLists.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2230 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The limit of 64 entries per resource was exceeded.\n\nLookup forms: 2230, 0x8B6, 0x000008B6, error 2230, NERR_ACFTooManyLists. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2230"]},{"id":2841,"title":"NERR_UserLogon","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2231","0x8B7","0x000008B7","error 2231","NERR_UserLogon","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","userlogon","deleting","user","with","session","not","allowed"],"errorCode":"2231","eventId":"","severity":"Low","summary":"Deleting a user with a session is not allowed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2231; use the surrounding log entries to confirm it.","resolution":"1. Record where 2231 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_UserLogon.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2231 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Deleting a user with a session is not allowed.\n\nLookup forms: 2231, 0x8B7, 0x000008B7, error 2231, NERR_UserLogon. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2231"]},{"id":2842,"title":"NERR_ACFNoParent","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2232","0x8B8","0x000008B8","error 2232","NERR_ACFNoParent","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","acfnoparent","the","parent","directory","could","not","located"],"errorCode":"2232","eventId":"","severity":"Low","summary":"The parent directory could not be located.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2232; use the surrounding log entries to confirm it.","resolution":"1. Record where 2232 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ACFNoParent.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2232 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The parent directory could not be located.\n\nLookup forms: 2232, 0x8B8, 0x000008B8, error 2232, NERR_ACFNoParent. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2232"]},{"id":2843,"title":"NERR_CanNotGrowSegment","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2233","0x8B9","0x000008B9","error 2233","NERR_CanNotGrowSegment","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","cannotgrowsegment","unable","add","the","security","database","session","cache","segment"],"errorCode":"2233","eventId":"","severity":"Medium","summary":"Unable to add to the security database session cache segment.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2233; use the surrounding log entries to confirm it.","resolution":"1. Record where 2233 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_CanNotGrowSegment.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2233 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to add to the security database session cache segment.\n\nLookup forms: 2233, 0x8B9, 0x000008B9, error 2233, NERR_CanNotGrowSegment. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2233"]},{"id":2844,"title":"NERR_SpeGroupOp","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2234","0x8BA","0x000008BA","error 2234","NERR_SpeGroupOp","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","spegroupop","this","operation","not","allowed","special","group"],"errorCode":"2234","eventId":"","severity":"Low","summary":"This operation is not allowed on this special group.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2234; use the surrounding log entries to confirm it.","resolution":"1. Record where 2234 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_SpeGroupOp.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2234 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation is not allowed on this special group.\n\nLookup forms: 2234, 0x8BA, 0x000008BA, error 2234, NERR_SpeGroupOp. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2234"]},{"id":2845,"title":"NERR_NotInCache","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2235","0x8BB","0x000008BB","error 2235","NERR_NotInCache","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","notincache","this","user","not","cached","the","accounts","database","session","cache"],"errorCode":"2235","eventId":"","severity":"Low","summary":"This user is not cached in the user accounts database session cache.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2235; use the surrounding log entries to confirm it.","resolution":"1. Record where 2235 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NotInCache.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2235 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This user is not cached in the user accounts database session cache.\n\nLookup forms: 2235, 0x8BB, 0x000008BB, error 2235, NERR_NotInCache. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2235"]},{"id":2846,"title":"NERR_UserInGroup","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2236","0x8BC","0x000008BC","error 2236","NERR_UserInGroup","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","useringroup","the","user","already","belongs","this","group"],"errorCode":"2236","eventId":"","severity":"Low","summary":"The user already belongs to this group.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2236; use the surrounding log entries to confirm it.","resolution":"1. Record where 2236 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_UserInGroup.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2236 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The user already belongs to this group.\n\nLookup forms: 2236, 0x8BC, 0x000008BC, error 2236, NERR_UserInGroup. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2236"]},{"id":2847,"title":"NERR_UserNotInGroup","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2237","0x8BD","0x000008BD","error 2237","NERR_UserNotInGroup","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","usernotingroup","the","user","does","not","belong","this","group"],"errorCode":"2237","eventId":"","severity":"Low","summary":"The user does not belong to this group.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2237; use the surrounding log entries to confirm it.","resolution":"1. Record where 2237 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_UserNotInGroup.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2237 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The user does not belong to this group.\n\nLookup forms: 2237, 0x8BD, 0x000008BD, error 2237, NERR_UserNotInGroup. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2237"]},{"id":2848,"title":"NERR_AccountUndefined","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2238","0x8BE","0x000008BE","error 2238","NERR_AccountUndefined","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","accountundefined","this","user","account","undefined"],"errorCode":"2238","eventId":"","severity":"Low","summary":"This user account is undefined.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2238; use the surrounding log entries to confirm it.","resolution":"1. Record where 2238 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_AccountUndefined.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2238 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This user account is undefined.\n\nLookup forms: 2238, 0x8BE, 0x000008BE, error 2238, NERR_AccountUndefined. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2238"]},{"id":2849,"title":"NERR_AccountExpired","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2239","0x8BF","0x000008BF","error 2239","NERR_AccountExpired","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","accountexpired","this","user","account","has","expired"],"errorCode":"2239","eventId":"","severity":"Low","summary":"This user account has expired.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2239; use the surrounding log entries to confirm it.","resolution":"1. Record where 2239 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_AccountExpired.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2239 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This user account has expired.\n\nLookup forms: 2239, 0x8BF, 0x000008BF, error 2239, NERR_AccountExpired. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2239"]},{"id":2850,"title":"NERR_InvalidWorkstation","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2240","0x8C0","0x000008C0","error 2240","NERR_InvalidWorkstation","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","invalidworkstation","the","user","not","allowed","log","from","this","workstation"],"errorCode":"2240","eventId":"","severity":"Low","summary":"The user is not allowed to log on from this workstation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2240; use the surrounding log entries to confirm it.","resolution":"1. Record where 2240 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_InvalidWorkstation.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2240 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The user is not allowed to log on from this workstation.\n\nLookup forms: 2240, 0x8C0, 0x000008C0, error 2240, NERR_InvalidWorkstation. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2240"]},{"id":2851,"title":"NERR_InvalidLogonHours","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2241","0x8C1","0x000008C1","error 2241","NERR_InvalidLogonHours","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","invalidlogonhours","the","user","not","allowed","log","this","time"],"errorCode":"2241","eventId":"","severity":"Low","summary":"The user is not allowed to log on at this time.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2241; use the surrounding log entries to confirm it.","resolution":"1. Record where 2241 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_InvalidLogonHours.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2241 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The user is not allowed to log on at this time.\n\nLookup forms: 2241, 0x8C1, 0x000008C1, error 2241, NERR_InvalidLogonHours. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2241"]},{"id":2852,"title":"NERR_PasswordExpired","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2242","0x8C2","0x000008C2","error 2242","NERR_PasswordExpired","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","passwordexpired","the","password","this","user","has","expired"],"errorCode":"2242","eventId":"","severity":"Low","summary":"The password of this user has expired.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2242; use the surrounding log entries to confirm it.","resolution":"1. Record where 2242 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_PasswordExpired.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2242 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The password of this user has expired.\n\nLookup forms: 2242, 0x8C2, 0x000008C2, error 2242, NERR_PasswordExpired. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2242"]},{"id":2853,"title":"NERR_PasswordCantChange","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2243","0x8C3","0x000008C3","error 2243","NERR_PasswordCantChange","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","passwordcantchange","the","password","this","user","cannot","change"],"errorCode":"2243","eventId":"","severity":"Medium","summary":"The password of this user cannot change.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2243; use the surrounding log entries to confirm it.","resolution":"1. Record where 2243 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_PasswordCantChange.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2243 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The password of this user cannot change.\n\nLookup forms: 2243, 0x8C3, 0x000008C3, error 2243, NERR_PasswordCantChange. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2243"]},{"id":2854,"title":"NERR_PasswordHistConflict","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2244","0x8C4","0x000008C4","error 2244","NERR_PasswordHistConflict","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","passwordhistconflict","this","password","cannot","used","now"],"errorCode":"2244","eventId":"","severity":"Medium","summary":"This password cannot be used now.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2244; use the surrounding log entries to confirm it.","resolution":"1. Record where 2244 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_PasswordHistConflict.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2244 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This password cannot be used now.\n\nLookup forms: 2244, 0x8C4, 0x000008C4, error 2244, NERR_PasswordHistConflict. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2244"]},{"id":2855,"title":"NERR_PasswordTooShort","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2245","0x8C5","0x000008C5","error 2245","NERR_PasswordTooShort","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","passwordtooshort","the","password","does","not","meet","policy","requirements","check","minimum","length","complexity","and","history"],"errorCode":"2245","eventId":"","severity":"Low","summary":"The password does not meet the password policy requirements. Check the minimum password length, password complexity, and password history requirements.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2245; use the surrounding log entries to confirm it.","resolution":"1. Record where 2245 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_PasswordTooShort.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2245 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The password does not meet the password policy requirements. Check the minimum password length, password complexity, and password history requirements.\n\nLookup forms: 2245, 0x8C5, 0x000008C5, error 2245, NERR_PasswordTooShort. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2245"]},{"id":2856,"title":"NERR_PasswordTooRecent","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2246","0x8C6","0x000008C6","error 2246","NERR_PasswordTooRecent","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","passwordtoorecent","the","password","this","user","too","recent","change"],"errorCode":"2246","eventId":"","severity":"Low","summary":"The password of this user is too recent to change.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2246; use the surrounding log entries to confirm it.","resolution":"1. Record where 2246 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_PasswordTooRecent.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2246 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The password of this user is too recent to change.\n\nLookup forms: 2246, 0x8C6, 0x000008C6, error 2246, NERR_PasswordTooRecent. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2246"]},{"id":2857,"title":"NERR_InvalidDatabase","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2247","0x8C7","0x000008C7","error 2247","NERR_InvalidDatabase","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","invaliddatabase","the","security","database","corrupted"],"errorCode":"2247","eventId":"","severity":"Critical","summary":"The security database is corrupted.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2247; use the surrounding log entries to confirm it.","resolution":"1. Record where 2247 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_InvalidDatabase.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2247 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The security database is corrupted.\n\nLookup forms: 2247, 0x8C7, 0x000008C7, error 2247, NERR_InvalidDatabase. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2247"]},{"id":2858,"title":"NERR_DatabaseUpToDate","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2248","0x8C8","0x000008C8","error 2248","NERR_DatabaseUpToDate","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","databaseuptodate","updates","are","necessary","this","replicant","network","local","security","database"],"errorCode":"2248","eventId":"","severity":"High","summary":"No updates are necessary to this replicant network or local security database.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2248; use the surrounding log entries to confirm it.","resolution":"1. Record where 2248 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Verify the required service or agent is installed, running, and current; repair the component if needed.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DatabaseUpToDate.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2248 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No updates are necessary to this replicant network or local security database.\n\nLookup forms: 2248, 0x8C8, 0x000008C8, error 2248, NERR_DatabaseUpToDate. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2248"]},{"id":2859,"title":"NERR_SyncRequired","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2249","0x8C9","0x000008C9","error 2249","NERR_SyncRequired","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","syncrequired","this","replicant","database","outdated","synchronization","required"],"errorCode":"2249","eventId":"","severity":"Low","summary":"This replicant database is outdated; synchronization is required.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2249; use the surrounding log entries to confirm it.","resolution":"1. Record where 2249 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_SyncRequired.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2249 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This replicant database is outdated; synchronization is required.\n\nLookup forms: 2249, 0x8C9, 0x000008C9, error 2249, NERR_SyncRequired. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2249"]},{"id":2860,"title":"NERR_BadAsgType","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2251","0x8CB","0x000008CB","error 2251","NERR_BadAsgType","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","badasgtype","this","asg","type","invalid"],"errorCode":"2251","eventId":"","severity":"Medium","summary":"This asg_type is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2251; use the surrounding log entries to confirm it.","resolution":"1. Record where 2251 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_BadAsgType.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2251 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This asg_type is invalid.\n\nLookup forms: 2251, 0x8CB, 0x000008CB, error 2251, NERR_BadAsgType. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2251"]},{"id":2861,"title":"NERR_DeviceIsShared","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2252","0x8CC","0x000008CC","error 2252","NERR_DeviceIsShared","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","deviceisshared","this","device","currently","being","shared"],"errorCode":"2252","eventId":"","severity":"Low","summary":"This device is currently being shared.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2252; use the surrounding log entries to confirm it.","resolution":"1. Record where 2252 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DeviceIsShared.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2252 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This device is currently being shared.\n\nLookup forms: 2252, 0x8CC, 0x000008CC, error 2252, NERR_DeviceIsShared. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2252"]},{"id":2862,"title":"NERR_NoComputerName","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2270","0x8DE","0x000008DE","error 2270","NERR_NoComputerName","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","nocomputername","the","computer","name","could","not","added","message","alias","might","already","exist","network"],"errorCode":"2270","eventId":"","severity":"High","summary":"The computer name could not be added as a message alias. The name might already exist on the network.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2270; use the surrounding log entries to confirm it.","resolution":"1. Record where 2270 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NoComputerName.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2270 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The computer name could not be added as a message alias. The name might already exist on the network.\n\nLookup forms: 2270, 0x8DE, 0x000008DE, error 2270, NERR_NoComputerName. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2270"]},{"id":2863,"title":"NERR_MsgAlreadyStarted","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2271","0x8DF","0x000008DF","error 2271","NERR_MsgAlreadyStarted","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","msgalreadystarted","the","messenger","service","already","started"],"errorCode":"2271","eventId":"","severity":"Low","summary":"The Messenger service is already started.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2271; use the surrounding log entries to confirm it.","resolution":"1. Record where 2271 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_MsgAlreadyStarted.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2271 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Messenger service is already started.\n\nLookup forms: 2271, 0x8DF, 0x000008DF, error 2271, NERR_MsgAlreadyStarted. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2271"]},{"id":2864,"title":"NERR_MsgInitFailed","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2272","0x8E0","0x000008E0","error 2272","NERR_MsgInitFailed","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","msginitfailed","the","messenger","service","failed","start"],"errorCode":"2272","eventId":"","severity":"High","summary":"The Messenger service failed to start.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2272; use the surrounding log entries to confirm it.","resolution":"1. Record where 2272 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_MsgInitFailed.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2272 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Messenger service failed to start.\n\nLookup forms: 2272, 0x8E0, 0x000008E0, error 2272, NERR_MsgInitFailed. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2272"]},{"id":2865,"title":"NERR_NameNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2273","0x8E1","0x000008E1","error 2273","NERR_NameNotFound","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","namenotfound","the","message","alias","could","not","found","network"],"errorCode":"2273","eventId":"","severity":"High","summary":"The message alias could not be found on the network.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2273; use the surrounding log entries to confirm it.","resolution":"1. Record where 2273 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NameNotFound.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2273 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The message alias could not be found on the network.\n\nLookup forms: 2273, 0x8E1, 0x000008E1, error 2273, NERR_NameNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2273"]},{"id":2866,"title":"NERR_AlreadyForwarded","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2274","0x8E2","0x000008E2","error 2274","NERR_AlreadyForwarded","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","alreadyforwarded","this","message","alias","has","already","been","forwarded"],"errorCode":"2274","eventId":"","severity":"Low","summary":"This message alias has already been forwarded.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2274; use the surrounding log entries to confirm it.","resolution":"1. Record where 2274 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_AlreadyForwarded.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2274 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This message alias has already been forwarded.\n\nLookup forms: 2274, 0x8E2, 0x000008E2, error 2274, NERR_AlreadyForwarded. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2274"]},{"id":2867,"title":"NERR_AddForwarded","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2275","0x8E3","0x000008E3","error 2275","NERR_AddForwarded","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","addforwarded","this","message","alias","has","been","added","but","still","forwarded"],"errorCode":"2275","eventId":"","severity":"Low","summary":"This message alias has been added but is still forwarded.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2275; use the surrounding log entries to confirm it.","resolution":"1. Record where 2275 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_AddForwarded.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2275 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This message alias has been added but is still forwarded.\n\nLookup forms: 2275, 0x8E3, 0x000008E3, error 2275, NERR_AddForwarded. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2275"]},{"id":2868,"title":"NERR_AlreadyExists","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2276","0x8E4","0x000008E4","error 2276","NERR_AlreadyExists","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","alreadyexists","this","message","alias","already","exists","locally"],"errorCode":"2276","eventId":"","severity":"Medium","summary":"This message alias already exists locally.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2276; use the surrounding log entries to confirm it.","resolution":"1. Record where 2276 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_AlreadyExists.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2276 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This message alias already exists locally.\n\nLookup forms: 2276, 0x8E4, 0x000008E4, error 2276, NERR_AlreadyExists. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2276"]},{"id":2869,"title":"NERR_TooManyNames","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2277","0x8E5","0x000008E5","error 2277","NERR_TooManyNames","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","toomanynames","the","maximum","number","added","message","aliases","has","been","exceeded"],"errorCode":"2277","eventId":"","severity":"Low","summary":"The maximum number of added message aliases has been exceeded.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2277; use the surrounding log entries to confirm it.","resolution":"1. Record where 2277 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_TooManyNames.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2277 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The maximum number of added message aliases has been exceeded.\n\nLookup forms: 2277, 0x8E5, 0x000008E5, error 2277, NERR_TooManyNames. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2277"]},{"id":2870,"title":"NERR_DelComputerName","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2278","0x8E6","0x000008E6","error 2278","NERR_DelComputerName","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","delcomputername","the","computer","name","could","not","deleted"],"errorCode":"2278","eventId":"","severity":"Low","summary":"The computer name could not be deleted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2278; use the surrounding log entries to confirm it.","resolution":"1. Record where 2278 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DelComputerName.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2278 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The computer name could not be deleted.\n\nLookup forms: 2278, 0x8E6, 0x000008E6, error 2278, NERR_DelComputerName. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2278"]},{"id":2871,"title":"NERR_LocalForward","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2279","0x8E7","0x000008E7","error 2279","NERR_LocalForward","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","localforward","messages","cannot","forwarded","back","the","same","workstation"],"errorCode":"2279","eventId":"","severity":"Medium","summary":"Messages cannot be forwarded back to the same workstation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2279; use the surrounding log entries to confirm it.","resolution":"1. Record where 2279 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_LocalForward.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2279 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Messages cannot be forwarded back to the same workstation.\n\nLookup forms: 2279, 0x8E7, 0x000008E7, error 2279, NERR_LocalForward. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2279"]},{"id":2872,"title":"NERR_GrpMsgProcessor","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2280","0x8E8","0x000008E8","error 2280","NERR_GrpMsgProcessor","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","grpmsgprocessor","error","occurred","the","domain","message","processor"],"errorCode":"2280","eventId":"","severity":"Low","summary":"An error occurred in the domain message processor.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2280; use the surrounding log entries to confirm it.","resolution":"1. Record where 2280 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_GrpMsgProcessor.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2280 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An error occurred in the domain message processor.\n\nLookup forms: 2280, 0x8E8, 0x000008E8, error 2280, NERR_GrpMsgProcessor. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2280"]},{"id":2873,"title":"NERR_PausedRemote","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2281","0x8E9","0x000008E9","error 2281","NERR_PausedRemote","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","pausedremote","the","message","was","sent","but","recipient","has","paused","messenger","service"],"errorCode":"2281","eventId":"","severity":"Low","summary":"The message was sent, but the recipient has paused the Messenger service.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2281; use the surrounding log entries to confirm it.","resolution":"1. Record where 2281 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_PausedRemote.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2281 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The message was sent, but the recipient has paused the Messenger service.\n\nLookup forms: 2281, 0x8E9, 0x000008E9, error 2281, NERR_PausedRemote. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2281"]},{"id":2874,"title":"NERR_BadReceive","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2282","0x8EA","0x000008EA","error 2282","NERR_BadReceive","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","badreceive","the","message","was","sent","but","not","received"],"errorCode":"2282","eventId":"","severity":"Low","summary":"The message was sent but not received.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2282; use the surrounding log entries to confirm it.","resolution":"1. Record where 2282 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_BadReceive.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2282 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The message was sent but not received.\n\nLookup forms: 2282, 0x8EA, 0x000008EA, error 2282, NERR_BadReceive. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2282"]},{"id":2875,"title":"NERR_NameInUse","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2283","0x8EB","0x000008EB","error 2283","NERR_NameInUse","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","nameinuse","the","message","alias","currently","use","try","again","later"],"errorCode":"2283","eventId":"","severity":"Low","summary":"The message alias is currently in use. Try again later.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2283; use the surrounding log entries to confirm it.","resolution":"1. Record where 2283 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NameInUse.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2283 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The message alias is currently in use. Try again later.\n\nLookup forms: 2283, 0x8EB, 0x000008EB, error 2283, NERR_NameInUse. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2283"]},{"id":2876,"title":"NERR_MsgNotStarted","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2284","0x8EC","0x000008EC","error 2284","NERR_MsgNotStarted","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","msgnotstarted","the","messenger","service","has","not","been","started"],"errorCode":"2284","eventId":"","severity":"Low","summary":"The Messenger service has not been started.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2284; use the surrounding log entries to confirm it.","resolution":"1. Record where 2284 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_MsgNotStarted.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2284 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Messenger service has not been started.\n\nLookup forms: 2284, 0x8EC, 0x000008EC, error 2284, NERR_MsgNotStarted. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2284"]},{"id":2877,"title":"NERR_NotLocalName","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2285","0x8ED","0x000008ED","error 2285","NERR_NotLocalName","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","notlocalname","the","name","not","local","computer"],"errorCode":"2285","eventId":"","severity":"Low","summary":"The name is not on the local computer.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2285; use the surrounding log entries to confirm it.","resolution":"1. Record where 2285 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NotLocalName.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2285 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The name is not on the local computer.\n\nLookup forms: 2285, 0x8ED, 0x000008ED, error 2285, NERR_NotLocalName. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2285"]},{"id":2878,"title":"NERR_NoForwardName","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2286","0x8EE","0x000008EE","error 2286","NERR_NoForwardName","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","noforwardname","the","forwarded","message","alias","could","not","found","network"],"errorCode":"2286","eventId":"","severity":"High","summary":"The forwarded message alias could not be found on the network.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2286; use the surrounding log entries to confirm it.","resolution":"1. Record where 2286 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NoForwardName.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2286 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The forwarded message alias could not be found on the network.\n\nLookup forms: 2286, 0x8EE, 0x000008EE, error 2286, NERR_NoForwardName. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2286"]},{"id":2879,"title":"NERR_RemoteFull","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2287","0x8EF","0x000008EF","error 2287","NERR_RemoteFull","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","remotefull","the","message","alias","table","remote","station","full"],"errorCode":"2287","eventId":"","severity":"Low","summary":"The message alias table on the remote station is full.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2287; use the surrounding log entries to confirm it.","resolution":"1. Record where 2287 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RemoteFull.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2287 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The message alias table on the remote station is full.\n\nLookup forms: 2287, 0x8EF, 0x000008EF, error 2287, NERR_RemoteFull. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2287"]},{"id":2880,"title":"NERR_NameNotForwarded","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2288","0x8F0","0x000008F0","error 2288","NERR_NameNotForwarded","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","namenotforwarded","messages","for","this","alias","are","not","currently","being","forwarded"],"errorCode":"2288","eventId":"","severity":"Low","summary":"Messages for this alias are not currently being forwarded.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2288; use the surrounding log entries to confirm it.","resolution":"1. Record where 2288 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NameNotForwarded.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2288 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Messages for this alias are not currently being forwarded.\n\nLookup forms: 2288, 0x8F0, 0x000008F0, error 2288, NERR_NameNotForwarded. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2288"]},{"id":2881,"title":"NERR_TruncatedBroadcast","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2289","0x8F1","0x000008F1","error 2289","NERR_TruncatedBroadcast","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","truncatedbroadcast","the","broadcast","message","was","truncated"],"errorCode":"2289","eventId":"","severity":"Low","summary":"The broadcast message was truncated.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2289; use the surrounding log entries to confirm it.","resolution":"1. Record where 2289 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_TruncatedBroadcast.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2289 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The broadcast message was truncated.\n\nLookup forms: 2289, 0x8F1, 0x000008F1, error 2289, NERR_TruncatedBroadcast. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2289"]},{"id":2882,"title":"NERR_InvalidDevice","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2294","0x8F6","0x000008F6","error 2294","NERR_InvalidDevice","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","invaliddevice","this","invalid","device","name"],"errorCode":"2294","eventId":"","severity":"Medium","summary":"This is an invalid device name.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2294; use the surrounding log entries to confirm it.","resolution":"1. Record where 2294 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_InvalidDevice.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2294 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This is an invalid device name.\n\nLookup forms: 2294, 0x8F6, 0x000008F6, error 2294, NERR_InvalidDevice. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2294"]},{"id":2883,"title":"NERR_WriteFault","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2295","0x8F7","0x000008F7","error 2295","NERR_WriteFault","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","writefault","write","fault","occurred"],"errorCode":"2295","eventId":"","severity":"Low","summary":"A write fault occurred.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2295; use the surrounding log entries to confirm it.","resolution":"1. Record where 2295 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_WriteFault.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2295 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A write fault occurred.\n\nLookup forms: 2295, 0x8F7, 0x000008F7, error 2295, NERR_WriteFault. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2295"]},{"id":2884,"title":"NERR_DuplicateName","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2297","0x8F9","0x000008F9","error 2297","NERR_DuplicateName","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","duplicatename","duplicate","message","alias","exists","the","network"],"errorCode":"2297","eventId":"","severity":"High","summary":"A duplicate message alias exists on the network.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2297; use the surrounding log entries to confirm it.","resolution":"1. Record where 2297 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DuplicateName.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2297 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A duplicate message alias exists on the network.\n\nLookup forms: 2297, 0x8F9, 0x000008F9, error 2297, NERR_DuplicateName. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2297"]},{"id":2885,"title":"NERR_DeleteLater","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2298","0x8FA","0x000008FA","error 2298","NERR_DeleteLater","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","deletelater","this","message","alias","will","deleted","later"],"errorCode":"2298","eventId":"","severity":"Low","summary":"This message alias will be deleted later.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2298; use the surrounding log entries to confirm it.","resolution":"1. Record where 2298 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DeleteLater.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2298 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This message alias will be deleted later.\n\nLookup forms: 2298, 0x8FA, 0x000008FA, error 2298, NERR_DeleteLater. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2298"]},{"id":2886,"title":"NERR_IncompleteDel","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2299","0x8FB","0x000008FB","error 2299","NERR_IncompleteDel","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","incompletedel","the","message","alias","was","not","successfully","deleted","from","all","networks"],"errorCode":"2299","eventId":"","severity":"High","summary":"The message alias was not successfully deleted from all networks.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2299; use the surrounding log entries to confirm it.","resolution":"1. Record where 2299 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_IncompleteDel.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2299 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The message alias was not successfully deleted from all networks.\n\nLookup forms: 2299, 0x8FB, 0x000008FB, error 2299, NERR_IncompleteDel. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2299"]},{"id":2887,"title":"NERR_MultipleNets","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2300","0x8FC","0x000008FC","error 2300","NERR_MultipleNets","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","multiplenets","this","operation","not","supported","computers","with","multiple","networks"],"errorCode":"2300","eventId":"","severity":"High","summary":"This operation is not supported on computers with multiple networks.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2300; use the surrounding log entries to confirm it.","resolution":"1. Record where 2300 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_MultipleNets.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2300 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation is not supported on computers with multiple networks.\n\nLookup forms: 2300, 0x8FC, 0x000008FC, error 2300, NERR_MultipleNets. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2300"]},{"id":2888,"title":"NERR_NetNameNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2310","0x906","0x00000906","error 2310","NERR_NetNameNotFound","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","netnamenotfound","this","shared","resource","does","not","exist"],"errorCode":"2310","eventId":"","severity":"Low","summary":"This shared resource does not exist.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2310; use the surrounding log entries to confirm it.","resolution":"1. Record where 2310 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NetNameNotFound.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2310 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This shared resource does not exist.\n\nLookup forms: 2310, 0x906, 0x00000906, error 2310, NERR_NetNameNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2310"]},{"id":2889,"title":"NERR_DeviceNotShared","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2311","0x907","0x00000907","error 2311","NERR_DeviceNotShared","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","devicenotshared","this","device","not","shared"],"errorCode":"2311","eventId":"","severity":"Low","summary":"This device is not shared.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2311; use the surrounding log entries to confirm it.","resolution":"1. Record where 2311 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DeviceNotShared.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2311 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This device is not shared.\n\nLookup forms: 2311, 0x907, 0x00000907, error 2311, NERR_DeviceNotShared. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2311"]},{"id":2890,"title":"NERR_ClientNameNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2312","0x908","0x00000908","error 2312","NERR_ClientNameNotFound","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","clientnamenotfound","session","does","not","exist","with","that","computer","name"],"errorCode":"2312","eventId":"","severity":"Low","summary":"A session does not exist with that computer name.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2312; use the surrounding log entries to confirm it.","resolution":"1. Record where 2312 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ClientNameNotFound.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2312 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A session does not exist with that computer name.\n\nLookup forms: 2312, 0x908, 0x00000908, error 2312, NERR_ClientNameNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2312"]},{"id":2891,"title":"NERR_FileIdNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2314","0x90A","0x0000090A","error 2314","NERR_FileIdNotFound","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","fileidnotfound","there","not","open","file","with","that","identification","number"],"errorCode":"2314","eventId":"","severity":"Low","summary":"There is not an open file with that identification number.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2314; use the surrounding log entries to confirm it.","resolution":"1. Record where 2314 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_FileIdNotFound.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2314 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There is not an open file with that identification number.\n\nLookup forms: 2314, 0x90A, 0x0000090A, error 2314, NERR_FileIdNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2314"]},{"id":2892,"title":"NERR_ExecFailure","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2315","0x90B","0x0000090B","error 2315","NERR_ExecFailure","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","execfailure","failure","occurred","when","executing","remote","administration","command"],"errorCode":"2315","eventId":"","severity":"High","summary":"A failure occurred when executing a remote administration command.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2315; use the surrounding log entries to confirm it.","resolution":"1. Record where 2315 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ExecFailure.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2315 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A failure occurred when executing a remote administration command.\n\nLookup forms: 2315, 0x90B, 0x0000090B, error 2315, NERR_ExecFailure. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2315"]},{"id":2893,"title":"NERR_TmpFile","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2316","0x90C","0x0000090C","error 2316","NERR_TmpFile","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","tmpfile","failure","occurred","when","opening","remote","temporary","file"],"errorCode":"2316","eventId":"","severity":"High","summary":"A failure occurred when opening a remote temporary file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2316; use the surrounding log entries to confirm it.","resolution":"1. Record where 2316 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_TmpFile.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2316 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A failure occurred when opening a remote temporary file.\n\nLookup forms: 2316, 0x90C, 0x0000090C, error 2316, NERR_TmpFile. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2316"]},{"id":2894,"title":"NERR_TooMuchData","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2317","0x90D","0x0000090D","error 2317","NERR_TooMuchData","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","toomuchdata","the","data","returned","from","remote","administration","command","has","been","truncated"],"errorCode":"2317","eventId":"","severity":"Low","summary":"The data returned from a remote administration command has been truncated to 64 KB.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2317; use the surrounding log entries to confirm it.","resolution":"1. Record where 2317 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_TooMuchData.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2317 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The data returned from a remote administration command has been truncated to 64 KB.\n\nLookup forms: 2317, 0x90D, 0x0000090D, error 2317, NERR_TooMuchData. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2317"]},{"id":2895,"title":"NERR_DeviceShareConflict","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2318","0x90E","0x0000090E","error 2318","NERR_DeviceShareConflict","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","deviceshareconflict","this","device","cannot","shared","both","spooled","and","nonspooled","resource"],"errorCode":"2318","eventId":"","severity":"Medium","summary":"This device cannot be shared as both a spooled and a nonspooled resource.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2318; use the surrounding log entries to confirm it.","resolution":"1. Record where 2318 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DeviceShareConflict.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2318 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This device cannot be shared as both a spooled and a nonspooled resource.\n\nLookup forms: 2318, 0x90E, 0x0000090E, error 2318, NERR_DeviceShareConflict. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2318"]},{"id":2896,"title":"NERR_BrowserTableIncomplete","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2319","0x90F","0x0000090F","error 2319","NERR_BrowserTableIncomplete","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","browsertableincomplete","the","information","list","servers","might","incorrect"],"errorCode":"2319","eventId":"","severity":"Low","summary":"The information in the list of servers might be incorrect.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2319; use the surrounding log entries to confirm it.","resolution":"1. Record where 2319 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_BrowserTableIncomplete.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2319 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The information in the list of servers might be incorrect.\n\nLookup forms: 2319, 0x90F, 0x0000090F, error 2319, NERR_BrowserTableIncomplete. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2319"]},{"id":2897,"title":"NERR_NotLocalDomain","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2320","0x910","0x00000910","error 2320","NERR_NotLocalDomain","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","notlocaldomain","the","computer","not","active","this","domain"],"errorCode":"2320","eventId":"","severity":"Low","summary":"The computer is not active in this domain.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2320; use the surrounding log entries to confirm it.","resolution":"1. Record where 2320 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NotLocalDomain.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2320 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The computer is not active in this domain.\n\nLookup forms: 2320, 0x910, 0x00000910, error 2320, NERR_NotLocalDomain. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2320"]},{"id":2898,"title":"NERR_IsDfsShare","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2321","0x911","0x00000911","error 2321","NERR_IsDfsShare","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","isdfsshare","the","share","must","removed","from","distributed","file","system","dfs","before","can","deleted"],"errorCode":"2321","eventId":"","severity":"Low","summary":"The share must be removed from the Distributed File System (DFS) before it can be deleted.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2321; use the surrounding log entries to confirm it.","resolution":"1. Record where 2321 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_IsDfsShare.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2321 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The share must be removed from the Distributed File System (DFS) before it can be deleted.\n\nLookup forms: 2321, 0x911, 0x00000911, error 2321, NERR_IsDfsShare. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2321"]},{"id":2899,"title":"NERR_DevInvalidOpCode","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2331","0x91B","0x0000091B","error 2331","NERR_DevInvalidOpCode","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","devinvalidopcode","the","operation","invalid","for","this","device"],"errorCode":"2331","eventId":"","severity":"Medium","summary":"The operation is invalid for this device.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2331; use the surrounding log entries to confirm it.","resolution":"1. Record where 2331 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DevInvalidOpCode.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2331 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation is invalid for this device.\n\nLookup forms: 2331, 0x91B, 0x0000091B, error 2331, NERR_DevInvalidOpCode. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2331"]},{"id":2900,"title":"NERR_DevNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2332","0x91C","0x0000091C","error 2332","NERR_DevNotFound","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","devnotfound","this","device","cannot","shared"],"errorCode":"2332","eventId":"","severity":"Medium","summary":"This device cannot be shared.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2332; use the surrounding log entries to confirm it.","resolution":"1. Record where 2332 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DevNotFound.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2332 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This device cannot be shared.\n\nLookup forms: 2332, 0x91C, 0x0000091C, error 2332, NERR_DevNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2332"]},{"id":2901,"title":"NERR_DevNotOpen","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2333","0x91D","0x0000091D","error 2333","NERR_DevNotOpen","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","devnotopen","this","device","was","not","open"],"errorCode":"2333","eventId":"","severity":"Low","summary":"This device was not open.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2333; use the surrounding log entries to confirm it.","resolution":"1. Record where 2333 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DevNotOpen.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2333 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This device was not open.\n\nLookup forms: 2333, 0x91D, 0x0000091D, error 2333, NERR_DevNotOpen. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2333"]},{"id":2902,"title":"NERR_BadQueueDevString","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2334","0x91E","0x0000091E","error 2334","NERR_BadQueueDevString","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","badqueuedevstring","this","device","name","list","invalid"],"errorCode":"2334","eventId":"","severity":"Medium","summary":"This device name list is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2334; use the surrounding log entries to confirm it.","resolution":"1. Record where 2334 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_BadQueueDevString.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2334 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This device name list is invalid.\n\nLookup forms: 2334, 0x91E, 0x0000091E, error 2334, NERR_BadQueueDevString. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2334"]},{"id":2903,"title":"NERR_BadQueuePriority","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2335","0x91F","0x0000091F","error 2335","NERR_BadQueuePriority","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","badqueuepriority","the","queue","priority","invalid"],"errorCode":"2335","eventId":"","severity":"Medium","summary":"The queue priority is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2335; use the surrounding log entries to confirm it.","resolution":"1. Record where 2335 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_BadQueuePriority.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2335 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The queue priority is invalid.\n\nLookup forms: 2335, 0x91F, 0x0000091F, error 2335, NERR_BadQueuePriority. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2335"]},{"id":2904,"title":"NERR_NoCommDevs","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2337","0x921","0x00000921","error 2337","NERR_NoCommDevs","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","nocommdevs","there","are","shared","communication","devices"],"errorCode":"2337","eventId":"","severity":"Low","summary":"There are no shared communication devices.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2337; use the surrounding log entries to confirm it.","resolution":"1. Record where 2337 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NoCommDevs.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2337 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There are no shared communication devices.\n\nLookup forms: 2337, 0x921, 0x00000921, error 2337, NERR_NoCommDevs. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2337"]},{"id":2905,"title":"NERR_QueueNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2338","0x922","0x00000922","error 2338","NERR_QueueNotFound","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","queuenotfound","the","queue","you","specified","does","not","exist"],"errorCode":"2338","eventId":"","severity":"Low","summary":"The queue you specified does not exist.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2338; use the surrounding log entries to confirm it.","resolution":"1. Record where 2338 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_QueueNotFound.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2338 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The queue you specified does not exist.\n\nLookup forms: 2338, 0x922, 0x00000922, error 2338, NERR_QueueNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2338"]},{"id":2906,"title":"NERR_BadDevString","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2340","0x924","0x00000924","error 2340","NERR_BadDevString","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","baddevstring","this","list","devices","invalid"],"errorCode":"2340","eventId":"","severity":"Medium","summary":"This list of devices is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2340; use the surrounding log entries to confirm it.","resolution":"1. Record where 2340 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_BadDevString.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2340 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This list of devices is invalid.\n\nLookup forms: 2340, 0x924, 0x00000924, error 2340, NERR_BadDevString. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2340"]},{"id":2907,"title":"NERR_BadDev","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2341","0x925","0x00000925","error 2341","NERR_BadDev","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","baddev","the","requested","device","invalid"],"errorCode":"2341","eventId":"","severity":"Medium","summary":"The requested device is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2341; use the surrounding log entries to confirm it.","resolution":"1. Record where 2341 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_BadDev.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2341 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested device is invalid.\n\nLookup forms: 2341, 0x925, 0x00000925, error 2341, NERR_BadDev. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2341"]},{"id":2908,"title":"NERR_InUseBySpooler","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2342","0x926","0x00000926","error 2342","NERR_InUseBySpooler","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","inusebyspooler","this","device","already","use","the","spooler"],"errorCode":"2342","eventId":"","severity":"Low","summary":"This device is already in use by the spooler.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2342; use the surrounding log entries to confirm it.","resolution":"1. Record where 2342 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_InUseBySpooler.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2342 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This device is already in use by the spooler.\n\nLookup forms: 2342, 0x926, 0x00000926, error 2342, NERR_InUseBySpooler. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2342"]},{"id":2909,"title":"NERR_CommDevInUse","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2343","0x927","0x00000927","error 2343","NERR_CommDevInUse","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","commdevinuse","this","device","already","use","communication"],"errorCode":"2343","eventId":"","severity":"Low","summary":"This device is already in use as a communication device.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2343; use the surrounding log entries to confirm it.","resolution":"1. Record where 2343 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_CommDevInUse.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2343 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This device is already in use as a communication device.\n\nLookup forms: 2343, 0x927, 0x00000927, error 2343, NERR_CommDevInUse. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2343"]},{"id":2910,"title":"NERR_InvalidComputer","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2351","0x92F","0x0000092F","error 2351","NERR_InvalidComputer","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","invalidcomputer","this","computer","name","invalid"],"errorCode":"2351","eventId":"","severity":"Medium","summary":"This computer name is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2351; use the surrounding log entries to confirm it.","resolution":"1. Record where 2351 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_InvalidComputer.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2351 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This computer name is invalid.\n\nLookup forms: 2351, 0x92F, 0x0000092F, error 2351, NERR_InvalidComputer. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2351"]},{"id":2911,"title":"NERR_MaxLenExceeded","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2354","0x932","0x00000932","error 2354","NERR_MaxLenExceeded","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","maxlenexceeded","the","string","and","prefix","specified","are","too","long"],"errorCode":"2354","eventId":"","severity":"Low","summary":"The string and prefix specified are too long.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2354; use the surrounding log entries to confirm it.","resolution":"1. Record where 2354 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_MaxLenExceeded.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2354 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The string and prefix specified are too long.\n\nLookup forms: 2354, 0x932, 0x00000932, error 2354, NERR_MaxLenExceeded. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2354"]},{"id":2912,"title":"NERR_BadComponent","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2356","0x934","0x00000934","error 2356","NERR_BadComponent","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","badcomponent","this","path","component","invalid"],"errorCode":"2356","eventId":"","severity":"Medium","summary":"This path component is invalid.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2356; use the surrounding log entries to confirm it.","resolution":"1. Record where 2356 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_BadComponent.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2356 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This path component is invalid.\n\nLookup forms: 2356, 0x934, 0x00000934, error 2356, NERR_BadComponent. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2356"]},{"id":2913,"title":"NERR_CantType","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2357","0x935","0x00000935","error 2357","NERR_CantType","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","canttype","could","not","determine","the","type","input"],"errorCode":"2357","eventId":"","severity":"Low","summary":"Could not determine the type of input.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2357; use the surrounding log entries to confirm it.","resolution":"1. Record where 2357 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_CantType.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2357 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Could not determine the type of input.\n\nLookup forms: 2357, 0x935, 0x00000935, error 2357, NERR_CantType. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2357"]},{"id":2914,"title":"NERR_TooManyEntries","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2362","0x93A","0x0000093A","error 2362","NERR_TooManyEntries","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","toomanyentries","the","buffer","for","types","not","big","enough"],"errorCode":"2362","eventId":"","severity":"Low","summary":"The buffer for types is not big enough.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2362; use the surrounding log entries to confirm it.","resolution":"1. Record where 2362 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_TooManyEntries.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2362 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The buffer for types is not big enough.\n\nLookup forms: 2362, 0x93A, 0x0000093A, error 2362, NERR_TooManyEntries. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2362"]},{"id":2915,"title":"NERR_ProfileFileTooBig","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2370","0x942","0x00000942","error 2370","NERR_ProfileFileTooBig","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","profilefiletoobig","profile","files","cannot","exceed"],"errorCode":"2370","eventId":"","severity":"Medium","summary":"Profile files cannot exceed 64 KB.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2370; use the surrounding log entries to confirm it.","resolution":"1. Record where 2370 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ProfileFileTooBig.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2370 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Profile files cannot exceed 64 KB.\n\nLookup forms: 2370, 0x942, 0x00000942, error 2370, NERR_ProfileFileTooBig. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2370"]},{"id":2916,"title":"NERR_ProfileOffset","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2371","0x943","0x00000943","error 2371","NERR_ProfileOffset","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","profileoffset","the","start","offset","out","range"],"errorCode":"2371","eventId":"","severity":"Low","summary":"The start offset is out of range.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2371; use the surrounding log entries to confirm it.","resolution":"1. Record where 2371 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ProfileOffset.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2371 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The start offset is out of range.\n\nLookup forms: 2371, 0x943, 0x00000943, error 2371, NERR_ProfileOffset. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2371"]},{"id":2917,"title":"NERR_ProfileCleanup","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2372","0x944","0x00000944","error 2372","NERR_ProfileCleanup","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","profilecleanup","the","system","cannot","delete","current","connections","network","resources"],"errorCode":"2372","eventId":"","severity":"High","summary":"The system cannot delete current connections to network resources.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2372; use the surrounding log entries to confirm it.","resolution":"1. Record where 2372 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ProfileCleanup.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2372 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system cannot delete current connections to network resources.\n\nLookup forms: 2372, 0x944, 0x00000944, error 2372, NERR_ProfileCleanup. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2372"]},{"id":2918,"title":"NERR_ProfileUnknownCmd","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2373","0x945","0x00000945","error 2373","NERR_ProfileUnknownCmd","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","profileunknowncmd","the","system","was","unable","parse","command","line","this","file"],"errorCode":"2373","eventId":"","severity":"Medium","summary":"The system was unable to parse the command line in this file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2373; use the surrounding log entries to confirm it.","resolution":"1. Record where 2373 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ProfileUnknownCmd.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2373 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system was unable to parse the command line in this file.\n\nLookup forms: 2373, 0x945, 0x00000945, error 2373, NERR_ProfileUnknownCmd. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2373"]},{"id":2919,"title":"NERR_ProfileLoadErr","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2374","0x946","0x00000946","error 2374","NERR_ProfileLoadErr","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","profileloaderr","error","occurred","while","loading","the","profile","file"],"errorCode":"2374","eventId":"","severity":"Low","summary":"An error occurred while loading the profile file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2374; use the surrounding log entries to confirm it.","resolution":"1. Record where 2374 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ProfileLoadErr.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2374 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An error occurred while loading the profile file.\n\nLookup forms: 2374, 0x946, 0x00000946, error 2374, NERR_ProfileLoadErr. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2374"]},{"id":2920,"title":"NERR_ProfileSaveErr","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2375","0x947","0x00000947","error 2375","NERR_ProfileSaveErr","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","profilesaveerr","errors","occurred","while","saving","the","profile","file","was","partially","saved"],"errorCode":"2375","eventId":"","severity":"Low","summary":"Errors occurred while saving the profile file. The profile was partially saved.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2375; use the surrounding log entries to confirm it.","resolution":"1. Record where 2375 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ProfileSaveErr.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2375 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Errors occurred while saving the profile file. The profile was partially saved.\n\nLookup forms: 2375, 0x947, 0x00000947, error 2375, NERR_ProfileSaveErr. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2375"]},{"id":2921,"title":"NERR_LogOverflow","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2377","0x949","0x00000949","error 2377","NERR_LogOverflow","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","logoverflow","log","file","full"],"errorCode":"2377","eventId":"","severity":"Low","summary":"Log file %1 is full.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2377; use the surrounding log entries to confirm it.","resolution":"1. Record where 2377 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_LogOverflow.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2377 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log file %1 is full.\n\nLookup forms: 2377, 0x949, 0x00000949, error 2377, NERR_LogOverflow. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2377"]},{"id":2922,"title":"NERR_LogFileChanged","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2378","0x94A","0x0000094A","error 2378","NERR_LogFileChanged","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","logfilechanged","this","log","file","has","changed","between","reads"],"errorCode":"2378","eventId":"","severity":"Low","summary":"This log file has changed between reads.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2378; use the surrounding log entries to confirm it.","resolution":"1. Record where 2378 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_LogFileChanged.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2378 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This log file has changed between reads.\n\nLookup forms: 2378, 0x94A, 0x0000094A, error 2378, NERR_LogFileChanged. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2378"]},{"id":2923,"title":"NERR_LogFileCorrupt","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2379","0x94B","0x0000094B","error 2379","NERR_LogFileCorrupt","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","logfilecorrupt","log","file","corrupt"],"errorCode":"2379","eventId":"","severity":"Critical","summary":"Log file %1 is corrupt.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2379; use the surrounding log entries to confirm it.","resolution":"1. Record where 2379 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_LogFileCorrupt.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2379 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Log file %1 is corrupt.\n\nLookup forms: 2379, 0x94B, 0x0000094B, error 2379, NERR_LogFileCorrupt. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2379"]},{"id":2924,"title":"NERR_SourceIsDir","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2380","0x94C","0x0000094C","error 2380","NERR_SourceIsDir","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","sourceisdir","the","source","path","cannot","directory"],"errorCode":"2380","eventId":"","severity":"Medium","summary":"The source path cannot be a directory.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2380; use the surrounding log entries to confirm it.","resolution":"1. Record where 2380 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_SourceIsDir.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2380 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The source path cannot be a directory.\n\nLookup forms: 2380, 0x94C, 0x0000094C, error 2380, NERR_SourceIsDir. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2380"]},{"id":2925,"title":"NERR_BadSource","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2381","0x94D","0x0000094D","error 2381","NERR_BadSource","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","badsource","the","source","path","illegal"],"errorCode":"2381","eventId":"","severity":"Low","summary":"The source path is illegal.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2381; use the surrounding log entries to confirm it.","resolution":"1. Record where 2381 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_BadSource.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2381 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The source path is illegal.\n\nLookup forms: 2381, 0x94D, 0x0000094D, error 2381, NERR_BadSource. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2381"]},{"id":2926,"title":"NERR_BadDest","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2382","0x94E","0x0000094E","error 2382","NERR_BadDest","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","baddest","the","destination","path","illegal"],"errorCode":"2382","eventId":"","severity":"Low","summary":"The destination path is illegal.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2382; use the surrounding log entries to confirm it.","resolution":"1. Record where 2382 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_BadDest.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2382 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The destination path is illegal.\n\nLookup forms: 2382, 0x94E, 0x0000094E, error 2382, NERR_BadDest. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2382"]},{"id":2927,"title":"NERR_DifferentServers","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2383","0x94F","0x0000094F","error 2383","NERR_DifferentServers","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","differentservers","the","source","and","destination","paths","are","different","servers"],"errorCode":"2383","eventId":"","severity":"Low","summary":"The source and destination paths are on different servers.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2383; use the surrounding log entries to confirm it.","resolution":"1. Record where 2383 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DifferentServers.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2383 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The source and destination paths are on different servers.\n\nLookup forms: 2383, 0x94F, 0x0000094F, error 2383, NERR_DifferentServers. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2383"]},{"id":2928,"title":"NERR_RunSrvPaused","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2385","0x951","0x00000951","error 2385","NERR_RunSrvPaused","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","runsrvpaused","the","run","server","you","requested","paused"],"errorCode":"2385","eventId":"","severity":"Low","summary":"The Run server you requested is paused.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2385; use the surrounding log entries to confirm it.","resolution":"1. Record where 2385 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RunSrvPaused.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2385 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Run server you requested is paused.\n\nLookup forms: 2385, 0x951, 0x00000951, error 2385, NERR_RunSrvPaused. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2385"]},{"id":2929,"title":"NERR_ErrCommRunSrv","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2389","0x955","0x00000955","error 2389","NERR_ErrCommRunSrv","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","errcommrunsrv","error","occurred","when","communicating","with","run","server"],"errorCode":"2389","eventId":"","severity":"Low","summary":"An error occurred when communicating with a Run server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2389; use the surrounding log entries to confirm it.","resolution":"1. Record where 2389 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ErrCommRunSrv.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2389 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An error occurred when communicating with a Run server.\n\nLookup forms: 2389, 0x955, 0x00000955, error 2389, NERR_ErrCommRunSrv. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2389"]},{"id":2930,"title":"NERR_ErrorExecingGhost","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2391","0x957","0x00000957","error 2391","NERR_ErrorExecingGhost","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","errorexecingghost","error","occurred","when","starting","background","process"],"errorCode":"2391","eventId":"","severity":"Low","summary":"An error occurred when starting a background process.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2391; use the surrounding log entries to confirm it.","resolution":"1. Record where 2391 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ErrorExecingGhost.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2391 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An error occurred when starting a background process.\n\nLookup forms: 2391, 0x957, 0x00000957, error 2391, NERR_ErrorExecingGhost. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2391"]},{"id":2931,"title":"NERR_ShareNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2392","0x958","0x00000958","error 2392","NERR_ShareNotFound","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","sharenotfound","the","shared","resource","you","are","connected","could","not","found"],"errorCode":"2392","eventId":"","severity":"Low","summary":"The shared resource you are connected to could not be found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2392; use the surrounding log entries to confirm it.","resolution":"1. Record where 2392 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ShareNotFound.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2392 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The shared resource you are connected to could not be found.\n\nLookup forms: 2392, 0x958, 0x00000958, error 2392, NERR_ShareNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2392"]},{"id":2932,"title":"NERR_InvalidLana","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2400","0x960","0x00000960","error 2400","NERR_InvalidLana","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","invalidlana","the","lan","adapter","number","invalid"],"errorCode":"2400","eventId":"","severity":"Medium","summary":"The LAN adapter number is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2400; use the surrounding log entries to confirm it.","resolution":"1. Record where 2400 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_InvalidLana.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2400 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The LAN adapter number is invalid.\n\nLookup forms: 2400, 0x960, 0x00000960, error 2400, NERR_InvalidLana. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2400"]},{"id":2933,"title":"NERR_BadPasswordCore","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2403","0x963","0x00000963","error 2403","NERR_BadPasswordCore","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","badpasswordcore","this","share","name","password","invalid"],"errorCode":"2403","eventId":"","severity":"Medium","summary":"This share name or password is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2403; use the surrounding log entries to confirm it.","resolution":"1. Record where 2403 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_BadPasswordCore.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2403 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This share name or password is invalid.\n\nLookup forms: 2403, 0x963, 0x00000963, error 2403, NERR_BadPasswordCore. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2403"]},{"id":2934,"title":"NERR_LocalDrive","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2405","0x965","0x00000965","error 2405","NERR_LocalDrive","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","localdrive","the","drive","letter","use","locally"],"errorCode":"2405","eventId":"","severity":"Low","summary":"The drive letter is in use locally.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2405; use the surrounding log entries to confirm it.","resolution":"1. Record where 2405 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_LocalDrive.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2405 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The drive letter is in use locally.\n\nLookup forms: 2405, 0x965, 0x00000965, error 2405, NERR_LocalDrive. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2405"]},{"id":2935,"title":"NERR_AlertExists","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2430","0x97E","0x0000097E","error 2430","NERR_AlertExists","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","alertexists","the","specified","client","already","registered","for","event"],"errorCode":"2430","eventId":"","severity":"Low","summary":"The specified client is already registered for the specified event.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2430; use the surrounding log entries to confirm it.","resolution":"1. Record where 2430 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_AlertExists.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2430 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified client is already registered for the specified event.\n\nLookup forms: 2430, 0x97E, 0x0000097E, error 2430, NERR_AlertExists. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2430"]},{"id":2936,"title":"NERR_TooManyAlerts","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2431","0x97F","0x0000097F","error 2431","NERR_TooManyAlerts","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","toomanyalerts","the","alert","table","full"],"errorCode":"2431","eventId":"","severity":"Low","summary":"The alert table is full.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2431; use the surrounding log entries to confirm it.","resolution":"1. Record where 2431 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_TooManyAlerts.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2431 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The alert table is full.\n\nLookup forms: 2431, 0x97F, 0x0000097F, error 2431, NERR_TooManyAlerts. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2431"]},{"id":2937,"title":"NERR_NoSuchAlert","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2432","0x980","0x00000980","error 2432","NERR_NoSuchAlert","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","nosuchalert","invalid","nonexistent","alert","name","was","raised"],"errorCode":"2432","eventId":"","severity":"Medium","summary":"An invalid or nonexistent alert name was raised.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2432; use the surrounding log entries to confirm it.","resolution":"1. Record where 2432 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NoSuchAlert.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2432 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An invalid or nonexistent alert name was raised.\n\nLookup forms: 2432, 0x980, 0x00000980, error 2432, NERR_NoSuchAlert. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2432"]},{"id":2938,"title":"NERR_BadRecipient","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2433","0x981","0x00000981","error 2433","NERR_BadRecipient","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","badrecipient","the","alert","recipient","invalid"],"errorCode":"2433","eventId":"","severity":"Medium","summary":"The alert recipient is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2433; use the surrounding log entries to confirm it.","resolution":"1. Record where 2433 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_BadRecipient.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2433 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The alert recipient is invalid.\n\nLookup forms: 2433, 0x981, 0x00000981, error 2433, NERR_BadRecipient. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2433"]},{"id":2939,"title":"NERR_AcctLimitExceeded","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2434","0x982","0x00000982","error 2434","NERR_AcctLimitExceeded","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","acctlimitexceeded","user","session","with","this","server","has","been","deleted"],"errorCode":"2434","eventId":"","severity":"Low","summary":"A user's session with this server has been deleted.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2434; use the surrounding log entries to confirm it.","resolution":"1. Record where 2434 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_AcctLimitExceeded.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2434 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A user's session with this server has been deleted.\n\nLookup forms: 2434, 0x982, 0x00000982, error 2434, NERR_AcctLimitExceeded. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2434"]},{"id":2940,"title":"NERR_InvalidLogSeek","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2440","0x988","0x00000988","error 2440","NERR_InvalidLogSeek","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","invalidlogseek","the","log","file","does","not","contain","requested","record","number"],"errorCode":"2440","eventId":"","severity":"Low","summary":"The log file does not contain the requested record number.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2440; use the surrounding log entries to confirm it.","resolution":"1. Record where 2440 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_InvalidLogSeek.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2440 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The log file does not contain the requested record number.\n\nLookup forms: 2440, 0x988, 0x00000988, error 2440, NERR_InvalidLogSeek. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2440"]},{"id":2941,"title":"NERR_BadUasConfig","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2450","0x992","0x00000992","error 2450","NERR_BadUasConfig","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","baduasconfig","the","user","accounts","database","not","configured","correctly"],"errorCode":"2450","eventId":"","severity":"Low","summary":"The user accounts database is not configured correctly.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2450; use the surrounding log entries to confirm it.","resolution":"1. Record where 2450 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_BadUasConfig.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2450 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The user accounts database is not configured correctly.\n\nLookup forms: 2450, 0x992, 0x00000992, error 2450, NERR_BadUasConfig. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2450"]},{"id":2942,"title":"NERR_InvalidUASOp","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2451","0x993","0x00000993","error 2451","NERR_InvalidUASOp","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","invaliduasop","this","operation","not","permitted","when","the","net","logon","service","running"],"errorCode":"2451","eventId":"","severity":"High","summary":"This operation is not permitted when the Net Logon service is running.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2451; use the surrounding log entries to confirm it.","resolution":"1. Record where 2451 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_InvalidUASOp.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2451 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation is not permitted when the Net Logon service is running.\n\nLookup forms: 2451, 0x993, 0x00000993, error 2451, NERR_InvalidUASOp. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2451"]},{"id":2943,"title":"NERR_LastAdmin","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2452","0x994","0x00000994","error 2452","NERR_LastAdmin","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","lastadmin","this","operation","not","allowed","the","last","administrative","account"],"errorCode":"2452","eventId":"","severity":"Low","summary":"This operation is not allowed on the last administrative account.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2452; use the surrounding log entries to confirm it.","resolution":"1. Record where 2452 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_LastAdmin.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2452 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This operation is not allowed on the last administrative account.\n\nLookup forms: 2452, 0x994, 0x00000994, error 2452, NERR_LastAdmin. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2452"]},{"id":2944,"title":"NERR_DCNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2453","0x995","0x00000995","error 2453","NERR_DCNotFound","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","dcnotfound","could","not","find","the","domain","controller","for","this"],"errorCode":"2453","eventId":"","severity":"Low","summary":"Could not find the domain controller for this domain.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2453; use the surrounding log entries to confirm it.","resolution":"1. Record where 2453 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DCNotFound.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2453 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Could not find the domain controller for this domain.\n\nLookup forms: 2453, 0x995, 0x00000995, error 2453, NERR_DCNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2453"]},{"id":2945,"title":"NERR_LogonTrackingError","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2454","0x996","0x00000996","error 2454","NERR_LogonTrackingError","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","logontrackingerror","could","not","set","logon","information","for","this","user"],"errorCode":"2454","eventId":"","severity":"High","summary":"Could not set logon information for this user.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2454; use the surrounding log entries to confirm it.","resolution":"1. Record where 2454 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_LogonTrackingError.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2454 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Could not set logon information for this user.\n\nLookup forms: 2454, 0x996, 0x00000996, error 2454, NERR_LogonTrackingError. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2454"]},{"id":2946,"title":"NERR_NetlogonNotStarted","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2455","0x997","0x00000997","error 2455","NERR_NetlogonNotStarted","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","netlogonnotstarted","the","net","logon","service","has","not","been","started"],"errorCode":"2455","eventId":"","severity":"High","summary":"The Net Logon service has not been started.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2455; use the surrounding log entries to confirm it.","resolution":"1. Record where 2455 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NetlogonNotStarted.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2455 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The Net Logon service has not been started.\n\nLookup forms: 2455, 0x997, 0x00000997, error 2455, NERR_NetlogonNotStarted. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2455"]},{"id":2947,"title":"NERR_CanNotGrowUASFile","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2456","0x998","0x00000998","error 2456","NERR_CanNotGrowUASFile","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","cannotgrowuasfile","unable","add","the","user","accounts","database"],"errorCode":"2456","eventId":"","severity":"Medium","summary":"Unable to add to the user accounts database.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2456; use the surrounding log entries to confirm it.","resolution":"1. Record where 2456 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_CanNotGrowUASFile.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2456 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to add to the user accounts database.\n\nLookup forms: 2456, 0x998, 0x00000998, error 2456, NERR_CanNotGrowUASFile. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2456"]},{"id":2948,"title":"NERR_TimeDiffAtDC","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2457","0x999","0x00000999","error 2457","NERR_TimeDiffAtDC","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","timediffatdc","this","server","clock","not","synchronized","with","the","pdc"],"errorCode":"2457","eventId":"","severity":"Low","summary":"This server's clock is not synchronized with the PDC's clock.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2457; use the surrounding log entries to confirm it.","resolution":"1. Record where 2457 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_TimeDiffAtDC.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2457 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This server's clock is not synchronized with the PDC's clock.\n\nLookup forms: 2457, 0x999, 0x00000999, error 2457, NERR_TimeDiffAtDC. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2457"]},{"id":2949,"title":"NERR_PasswordMismatch","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2458","0x99A","0x0000099A","error 2458","NERR_PasswordMismatch","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","passwordmismatch","password","mismatch","has","been","detected"],"errorCode":"2458","eventId":"","severity":"Low","summary":"A password mismatch has been detected.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2458; use the surrounding log entries to confirm it.","resolution":"1. Record where 2458 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_PasswordMismatch.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2458 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A password mismatch has been detected.\n\nLookup forms: 2458, 0x99A, 0x0000099A, error 2458, NERR_PasswordMismatch. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2458"]},{"id":2950,"title":"NERR_NoSuchServer","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2460","0x99C","0x0000099C","error 2460","NERR_NoSuchServer","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","nosuchserver","the","server","identification","does","not","specify","valid"],"errorCode":"2460","eventId":"","severity":"Low","summary":"The server identification does not specify a valid server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2460; use the surrounding log entries to confirm it.","resolution":"1. Record where 2460 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NoSuchServer.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2460 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The server identification does not specify a valid server.\n\nLookup forms: 2460, 0x99C, 0x0000099C, error 2460, NERR_NoSuchServer. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2460"]},{"id":2951,"title":"NERR_NoSuchSession","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2461","0x99D","0x0000099D","error 2461","NERR_NoSuchSession","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","nosuchsession","the","session","identification","does","not","specify","valid"],"errorCode":"2461","eventId":"","severity":"Low","summary":"The session identification does not specify a valid session.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2461; use the surrounding log entries to confirm it.","resolution":"1. Record where 2461 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NoSuchSession.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2461 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The session identification does not specify a valid session.\n\nLookup forms: 2461, 0x99D, 0x0000099D, error 2461, NERR_NoSuchSession. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2461"]},{"id":2952,"title":"NERR_NoSuchConnection","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2462","0x99E","0x0000099E","error 2462","NERR_NoSuchConnection","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","nosuchconnection","the","connection","identification","does","not","specify","valid"],"errorCode":"2462","eventId":"","severity":"High","summary":"The connection identification does not specify a valid connection.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2462; use the surrounding log entries to confirm it.","resolution":"1. Record where 2462 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NoSuchConnection.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2462 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The connection identification does not specify a valid connection.\n\nLookup forms: 2462, 0x99E, 0x0000099E, error 2462, NERR_NoSuchConnection. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2462"]},{"id":2953,"title":"NERR_TooManyServers","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2463","0x99F","0x0000099F","error 2463","NERR_TooManyServers","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","toomanyservers","there","space","for","another","entry","the","table","available","servers"],"errorCode":"2463","eventId":"","severity":"Low","summary":"There is no space for another entry in the table of available servers.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2463; use the surrounding log entries to confirm it.","resolution":"1. Record where 2463 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_TooManyServers.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2463 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There is no space for another entry in the table of available servers.\n\nLookup forms: 2463, 0x99F, 0x0000099F, error 2463, NERR_TooManyServers. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2463"]},{"id":2954,"title":"NERR_TooManySessions","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2464","0x9A0","0x000009A0","error 2464","NERR_TooManySessions","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","toomanysessions","the","server","has","reached","maximum","number","sessions","supports"],"errorCode":"2464","eventId":"","severity":"Low","summary":"The server has reached the maximum number of sessions it supports.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2464; use the surrounding log entries to confirm it.","resolution":"1. Record where 2464 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_TooManySessions.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2464 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The server has reached the maximum number of sessions it supports.\n\nLookup forms: 2464, 0x9A0, 0x000009A0, error 2464, NERR_TooManySessions. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2464"]},{"id":2955,"title":"NERR_TooManyConnections","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2465","0x9A1","0x000009A1","error 2465","NERR_TooManyConnections","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","toomanyconnections","the","server","has","reached","maximum","number","connections","supports"],"errorCode":"2465","eventId":"","severity":"High","summary":"The server has reached the maximum number of connections it supports.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2465; use the surrounding log entries to confirm it.","resolution":"1. Record where 2465 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_TooManyConnections.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2465 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The server has reached the maximum number of connections it supports.\n\nLookup forms: 2465, 0x9A1, 0x000009A1, error 2465, NERR_TooManyConnections. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2465"]},{"id":2956,"title":"NERR_TooManyFiles","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2466","0x9A2","0x000009A2","error 2466","NERR_TooManyFiles","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","toomanyfiles","the","server","cannot","open","more","files","because","has","reached","its","maximum","number"],"errorCode":"2466","eventId":"","severity":"Medium","summary":"The server cannot open more files because it has reached its maximum number.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2466; use the surrounding log entries to confirm it.","resolution":"1. Record where 2466 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_TooManyFiles.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2466 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The server cannot open more files because it has reached its maximum number.\n\nLookup forms: 2466, 0x9A2, 0x000009A2, error 2466, NERR_TooManyFiles. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2466"]},{"id":2957,"title":"NERR_NoAlternateServers","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2467","0x9A3","0x000009A3","error 2467","NERR_NoAlternateServers","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","noalternateservers","there","are","alternate","servers","registered","this","server"],"errorCode":"2467","eventId":"","severity":"Low","summary":"There are no alternate servers registered on this server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2467; use the surrounding log entries to confirm it.","resolution":"1. Record where 2467 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NoAlternateServers.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2467 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There are no alternate servers registered on this server.\n\nLookup forms: 2467, 0x9A3, 0x000009A3, error 2467, NERR_NoAlternateServers. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2467"]},{"id":2958,"title":"NERR_TryDownLevel","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2470","0x9A6","0x000009A6","error 2470","NERR_TryDownLevel","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","trydownlevel","try","the","down","level","remote","admin","protocol","version","api","instead"],"errorCode":"2470","eventId":"","severity":"Low","summary":"Try the down-level (remote admin protocol) version of API instead.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2470; use the surrounding log entries to confirm it.","resolution":"1. Record where 2470 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_TryDownLevel.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2470 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Try the down-level (remote admin protocol) version of API instead.\n\nLookup forms: 2470, 0x9A6, 0x000009A6, error 2470, NERR_TryDownLevel. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2470"]},{"id":2959,"title":"NERR_UPSDriverNotStarted","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2480","0x9B0","0x000009B0","error 2480","NERR_UPSDriverNotStarted","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","upsdrivernotstarted","the","uninterruptible","power","supply","ups","driver","could","not","accessed","service"],"errorCode":"2480","eventId":"","severity":"Low","summary":"The uninterruptible power supply (UPS) driver could not be accessed by the UPS service.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2480; use the surrounding log entries to confirm it.","resolution":"1. Record where 2480 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Confirm the user or service identity has the required permissions and is not locked or disabled.\n4. Verify the required service or agent is installed, running, and current; repair the component if needed.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_UPSDriverNotStarted.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Confirm the user or service identity has the required permissions and is not locked or disabled.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2480 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The uninterruptible power supply (UPS) driver could not be accessed by the UPS service.\n\nLookup forms: 2480, 0x9B0, 0x000009B0, error 2480, NERR_UPSDriverNotStarted. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2480"]},{"id":2960,"title":"NERR_UPSInvalidConfig","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2481","0x9B1","0x000009B1","error 2481","NERR_UPSInvalidConfig","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","upsinvalidconfig","the","ups","service","not","configured","correctly"],"errorCode":"2481","eventId":"","severity":"Low","summary":"The UPS service is not configured correctly.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2481; use the surrounding log entries to confirm it.","resolution":"1. Record where 2481 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_UPSInvalidConfig.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2481 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The UPS service is not configured correctly.\n\nLookup forms: 2481, 0x9B1, 0x000009B1, error 2481, NERR_UPSInvalidConfig. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2481"]},{"id":2961,"title":"NERR_UPSInvalidCommPort","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2482","0x9B2","0x000009B2","error 2482","NERR_UPSInvalidCommPort","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","upsinvalidcommport","the","ups","service","could","not","access","specified","comm","port"],"errorCode":"2482","eventId":"","severity":"Low","summary":"The UPS service could not access the specified Comm Port.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2482; use the surrounding log entries to confirm it.","resolution":"1. Record where 2482 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_UPSInvalidCommPort.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2482 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The UPS service could not access the specified Comm Port.\n\nLookup forms: 2482, 0x9B2, 0x000009B2, error 2482, NERR_UPSInvalidCommPort. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2482"]},{"id":2962,"title":"NERR_UPSSignalAsserted","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2483","0x9B3","0x000009B3","error 2483","NERR_UPSSignalAsserted","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","upssignalasserted","the","ups","indicated","line","fail","low","battery","situation","service","not","started"],"errorCode":"2483","eventId":"","severity":"Low","summary":"The UPS indicated a line fail or low battery situation. Service not started.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2483; use the surrounding log entries to confirm it.","resolution":"1. Record where 2483 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_UPSSignalAsserted.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2483 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The UPS indicated a line fail or low battery situation. Service not started.\n\nLookup forms: 2483, 0x9B3, 0x000009B3, error 2483, NERR_UPSSignalAsserted. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2483"]},{"id":2963,"title":"NERR_UPSShutdownFailed","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2484","0x9B4","0x000009B4","error 2484","NERR_UPSShutdownFailed","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","upsshutdownfailed","the","ups","service","failed","perform","system","shut","down"],"errorCode":"2484","eventId":"","severity":"High","summary":"The UPS service failed to perform a system shut down.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2484; use the surrounding log entries to confirm it.","resolution":"1. Record where 2484 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_UPSShutdownFailed.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2484 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The UPS service failed to perform a system shut down.\n\nLookup forms: 2484, 0x9B4, 0x000009B4, error 2484, NERR_UPSShutdownFailed. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2484"]},{"id":2964,"title":"NERR_BadDosRetCode","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2500","0x9C4","0x000009C4","error 2500","NERR_BadDosRetCode","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","baddosretcode","the","program","below","returned","dos","error","code"],"errorCode":"2500","eventId":"","severity":"Low","summary":"The program below returned an MS-DOS error code.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2500; use the surrounding log entries to confirm it.","resolution":"1. Record where 2500 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_BadDosRetCode.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2500 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The program below returned an MS-DOS error code.\n\nLookup forms: 2500, 0x9C4, 0x000009C4, error 2500, NERR_BadDosRetCode. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2500"]},{"id":2965,"title":"NERR_ProgNeedsExtraMem","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2501","0x9C5","0x000009C5","error 2501","NERR_ProgNeedsExtraMem","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","progneedsextramem","the","program","below","needs","more","memory"],"errorCode":"2501","eventId":"","severity":"Low","summary":"The program below needs more memory.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2501; use the surrounding log entries to confirm it.","resolution":"1. Record where 2501 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ProgNeedsExtraMem.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2501 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The program below needs more memory.\n\nLookup forms: 2501, 0x9C5, 0x000009C5, error 2501, NERR_ProgNeedsExtraMem. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2501"]},{"id":2966,"title":"NERR_BadDosFunction","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2502","0x9C6","0x000009C6","error 2502","NERR_BadDosFunction","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","baddosfunction","the","program","below","called","unsupported","dos","function"],"errorCode":"2502","eventId":"","severity":"Low","summary":"The program below called an unsupported MS-DOS function.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2502; use the surrounding log entries to confirm it.","resolution":"1. Record where 2502 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_BadDosFunction.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2502 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The program below called an unsupported MS-DOS function.\n\nLookup forms: 2502, 0x9C6, 0x000009C6, error 2502, NERR_BadDosFunction. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2502"]},{"id":2967,"title":"NERR_RemoteBootFailed","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2503","0x9C7","0x000009C7","error 2503","NERR_RemoteBootFailed","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","remotebootfailed","the","workstation","failed","boot"],"errorCode":"2503","eventId":"","severity":"High","summary":"The workstation failed to boot.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2503; use the surrounding log entries to confirm it.","resolution":"1. Record where 2503 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RemoteBootFailed.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2503 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The workstation failed to boot.\n\nLookup forms: 2503, 0x9C7, 0x000009C7, error 2503, NERR_RemoteBootFailed. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2503"]},{"id":2968,"title":"NERR_BadFileCheckSum","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2504","0x9C8","0x000009C8","error 2504","NERR_BadFileCheckSum","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","badfilechecksum","the","file","below","corrupt"],"errorCode":"2504","eventId":"","severity":"Critical","summary":"The file below is corrupt.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2504; use the surrounding log entries to confirm it.","resolution":"1. Record where 2504 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_BadFileCheckSum.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2504 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The file below is corrupt.\n\nLookup forms: 2504, 0x9C8, 0x000009C8, error 2504, NERR_BadFileCheckSum. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2504"]},{"id":2969,"title":"NERR_NoRplBootSystem","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2505","0x9C9","0x000009C9","error 2505","NERR_NoRplBootSystem","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","norplbootsystem","loader","specified","the","boot","block","definition","file"],"errorCode":"2505","eventId":"","severity":"Low","summary":"No loader is specified in the boot-block definition file.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2505; use the surrounding log entries to confirm it.","resolution":"1. Record where 2505 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NoRplBootSystem.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2505 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: No loader is specified in the boot-block definition file.\n\nLookup forms: 2505, 0x9C9, 0x000009C9, error 2505, NERR_NoRplBootSystem. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2505"]},{"id":2970,"title":"NERR_RplLoadrNetBiosErr","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2506","0x9CA","0x000009CA","error 2506","NERR_RplLoadrNetBiosErr","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","rplloadrnetbioserr","netbios","returned","error","the","network","control","blocks","ncbs","and","server","message","block","smb","are","dumped","above"],"errorCode":"2506","eventId":"","severity":"High","summary":"NetBIOS returned an error: The network control blocks (NCBs) and Server Message Block (SMB) are dumped above.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2506; use the surrounding log entries to confirm it.","resolution":"1. Record where 2506 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplLoadrNetBiosErr.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2506 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: NetBIOS returned an error: The network control blocks (NCBs) and Server Message Block (SMB) are dumped above.\n\nLookup forms: 2506, 0x9CA, 0x000009CA, error 2506, NERR_RplLoadrNetBiosErr. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2506"]},{"id":2971,"title":"NERR_RplLoadrDiskErr","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2507","0x9CB","0x000009CB","error 2507","NERR_RplLoadrDiskErr","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","rplloadrdiskerr","disk","error","occurred"],"errorCode":"2507","eventId":"","severity":"Low","summary":"A disk I/O error occurred.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2507; use the surrounding log entries to confirm it.","resolution":"1. Record where 2507 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplLoadrDiskErr.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2507 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A disk I/O error occurred.\n\nLookup forms: 2507, 0x9CB, 0x000009CB, error 2507, NERR_RplLoadrDiskErr. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2507"]},{"id":2972,"title":"NERR_ImageParamErr","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2508","0x9CC","0x000009CC","error 2508","NERR_ImageParamErr","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","imageparamerr","image","parameter","substitution","failed"],"errorCode":"2508","eventId":"","severity":"High","summary":"Image parameter substitution failed.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2508; use the surrounding log entries to confirm it.","resolution":"1. Record where 2508 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ImageParamErr.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2508 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Image parameter substitution failed.\n\nLookup forms: 2508, 0x9CC, 0x000009CC, error 2508, NERR_ImageParamErr. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2508"]},{"id":2973,"title":"NERR_TooManyImageParams","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2509","0x9CD","0x000009CD","error 2509","NERR_TooManyImageParams","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","toomanyimageparams","too","many","image","parameters","cross","disk","sector","boundaries"],"errorCode":"2509","eventId":"","severity":"Low","summary":"Too many image parameters cross disk sector boundaries.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2509; use the surrounding log entries to confirm it.","resolution":"1. Record where 2509 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_TooManyImageParams.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2509 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Too many image parameters cross disk sector boundaries.\n\nLookup forms: 2509, 0x9CD, 0x000009CD, error 2509, NERR_TooManyImageParams. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2509"]},{"id":2974,"title":"NERR_NonDosFloppyUsed","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2510","0x9CE","0x000009CE","error 2510","NERR_NonDosFloppyUsed","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","nondosfloppyused","the","image","was","not","generated","from","dos","disk","formatted","with"],"errorCode":"2510","eventId":"","severity":"Low","summary":"The image was not generated from an MS-DOS disk formatted with /S.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2510; use the surrounding log entries to confirm it.","resolution":"1. Record where 2510 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NonDosFloppyUsed.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2510 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The image was not generated from an MS-DOS disk formatted with /S.\n\nLookup forms: 2510, 0x9CE, 0x000009CE, error 2510, NERR_NonDosFloppyUsed. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2510"]},{"id":2975,"title":"NERR_RplBootRestart","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2511","0x9CF","0x000009CF","error 2511","NERR_RplBootRestart","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","rplbootrestart","remote","boot","will","restarted","later"],"errorCode":"2511","eventId":"","severity":"Low","summary":"Remote boot will be restarted later.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2511; use the surrounding log entries to confirm it.","resolution":"1. Record where 2511 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplBootRestart.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2511 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Remote boot will be restarted later.\n\nLookup forms: 2511, 0x9CF, 0x000009CF, error 2511, NERR_RplBootRestart. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2511"]},{"id":2976,"title":"NERR_RplSrvrCallFailed","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2512","0x9D0","0x000009D0","error 2512","NERR_RplSrvrCallFailed","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","rplsrvrcallfailed","the","call","remoteboot","server","failed"],"errorCode":"2512","eventId":"","severity":"High","summary":"The call to the Remoteboot server failed.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2512; use the surrounding log entries to confirm it.","resolution":"1. Record where 2512 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplSrvrCallFailed.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2512 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The call to the Remoteboot server failed.\n\nLookup forms: 2512, 0x9D0, 0x000009D0, error 2512, NERR_RplSrvrCallFailed. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2512"]},{"id":2977,"title":"NERR_CantConnectRplSrvr","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2513","0x9D1","0x000009D1","error 2513","NERR_CantConnectRplSrvr","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","cantconnectrplsrvr","cannot","connect","the","remoteboot","server"],"errorCode":"2513","eventId":"","severity":"Medium","summary":"Cannot connect to the Remoteboot server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2513; use the surrounding log entries to confirm it.","resolution":"1. Record where 2513 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_CantConnectRplSrvr.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2513 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot connect to the Remoteboot server.\n\nLookup forms: 2513, 0x9D1, 0x000009D1, error 2513, NERR_CantConnectRplSrvr. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2513"]},{"id":2978,"title":"NERR_CantOpenImageFile","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2514","0x9D2","0x000009D2","error 2514","NERR_CantOpenImageFile","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","cantopenimagefile","cannot","open","image","file","the","remoteboot","server"],"errorCode":"2514","eventId":"","severity":"Medium","summary":"Cannot open image file on the Remoteboot server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2514; use the surrounding log entries to confirm it.","resolution":"1. Record where 2514 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_CantOpenImageFile.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2514 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot open image file on the Remoteboot server.\n\nLookup forms: 2514, 0x9D2, 0x000009D2, error 2514, NERR_CantOpenImageFile. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2514"]},{"id":2979,"title":"NERR_CallingRplSrvr","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2515","0x9D3","0x000009D3","error 2515","NERR_CallingRplSrvr","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","callingrplsrvr","connecting","the","remoteboot","server"],"errorCode":"2515","eventId":"","severity":"Low","summary":"Connecting to the Remoteboot server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2515; use the surrounding log entries to confirm it.","resolution":"1. Record where 2515 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_CallingRplSrvr.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2515 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Connecting to the Remoteboot server.\n\nLookup forms: 2515, 0x9D3, 0x000009D3, error 2515, NERR_CallingRplSrvr. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2515"]},{"id":2980,"title":"NERR_StartingRplBoot","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2516","0x9D4","0x000009D4","error 2516","NERR_StartingRplBoot","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","startingrplboot","connecting","the","remoteboot","server"],"errorCode":"2516","eventId":"","severity":"Low","summary":"Connecting to the Remoteboot server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2516; use the surrounding log entries to confirm it.","resolution":"1. Record where 2516 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_StartingRplBoot.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2516 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Connecting to the Remoteboot server.\n\nLookup forms: 2516, 0x9D4, 0x000009D4, error 2516, NERR_StartingRplBoot. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2516"]},{"id":2981,"title":"NERR_RplBootServiceTerm","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2517","0x9D5","0x000009D5","error 2517","NERR_RplBootServiceTerm","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","rplbootserviceterm","remote","boot","service","was","stopped","check","the","error","log","for","cause","problem"],"errorCode":"2517","eventId":"","severity":"Low","summary":"Remote boot service was stopped, check the error log for the cause of the problem.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2517; use the surrounding log entries to confirm it.","resolution":"1. Record where 2517 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplBootServiceTerm.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2517 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Remote boot service was stopped, check the error log for the cause of the problem.\n\nLookup forms: 2517, 0x9D5, 0x000009D5, error 2517, NERR_RplBootServiceTerm. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2517"]},{"id":2982,"title":"NERR_RplBootStartFailed","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2518","0x9D6","0x000009D6","error 2518","NERR_RplBootStartFailed","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","rplbootstartfailed","remote","boot","startup","failed","check","the","error","log","for","cause","problem"],"errorCode":"2518","eventId":"","severity":"High","summary":"Remote boot startup failed; check the error log for the cause of the problem.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2518; use the surrounding log entries to confirm it.","resolution":"1. Record where 2518 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplBootStartFailed.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2518 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Remote boot startup failed; check the error log for the cause of the problem.\n\nLookup forms: 2518, 0x9D6, 0x000009D6, error 2518, NERR_RplBootStartFailed. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2518"]},{"id":2983,"title":"NERR_RPL_CONNECTED","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2519","0x9D7","0x000009D7","error 2519","NERR_RPL_CONNECTED","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","rpl","connected","second","connection","remoteboot","resource","not","allowed"],"errorCode":"2519","eventId":"","severity":"High","summary":"A second connection to a Remoteboot resource is not allowed.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2519; use the surrounding log entries to confirm it.","resolution":"1. Record where 2519 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RPL_CONNECTED.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2519 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A second connection to a Remoteboot resource is not allowed.\n\nLookup forms: 2519, 0x9D7, 0x000009D7, error 2519, NERR_RPL_CONNECTED. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2519"]},{"id":2984,"title":"NERR_BrowserConfiguredToNotRun","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2550","0x9F6","0x000009F6","error 2550","NERR_BrowserConfiguredToNotRun","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","browserconfiguredtonotrun","the","browser","service","was","configured","with","maintainserverlist"],"errorCode":"2550","eventId":"","severity":"Low","summary":"The browser service was configured with MaintainServerList=No.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2550; use the surrounding log entries to confirm it.","resolution":"1. Record where 2550 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_BrowserConfiguredToNotRun.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2550 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The browser service was configured with MaintainServerList=No.\n\nLookup forms: 2550, 0x9F6, 0x000009F6, error 2550, NERR_BrowserConfiguredToNotRun. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2550"]},{"id":2985,"title":"NERR_RplNoAdaptersStarted","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2610","0xA32","0x00000A32","error 2610","NERR_RplNoAdaptersStarted","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","rplnoadaptersstarted","service","failed","start","because","none","the","network","adapters","started","with","this"],"errorCode":"2610","eventId":"","severity":"High","summary":"Service failed to start because none of the network adapters started with this service.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2610; use the surrounding log entries to confirm it.","resolution":"1. Record where 2610 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplNoAdaptersStarted.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2610 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Service failed to start because none of the network adapters started with this service.\n\nLookup forms: 2610, 0xA32, 0x00000A32, error 2610, NERR_RplNoAdaptersStarted. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2610"]},{"id":2986,"title":"NERR_RplBadRegistry","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2611","0xA33","0x00000A33","error 2611","NERR_RplBadRegistry","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","rplbadregistry","service","failed","start","due","bad","startup","information","the","registry"],"errorCode":"2611","eventId":"","severity":"High","summary":"Service failed to start due to bad startup information in the registry.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2611; use the surrounding log entries to confirm it.","resolution":"1. Record where 2611 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplBadRegistry.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2611 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Service failed to start due to bad startup information in the registry.\n\nLookup forms: 2611, 0xA33, 0x00000A33, error 2611, NERR_RplBadRegistry. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2611"]},{"id":2987,"title":"NERR_RplBadDatabase","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2612","0xA34","0x00000A34","error 2612","NERR_RplBadDatabase","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","rplbaddatabase","service","failed","start","because","its","database","absent","corrupt"],"errorCode":"2612","eventId":"","severity":"Critical","summary":"Service failed to start because its database is absent or corrupt.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2612; use the surrounding log entries to confirm it.","resolution":"1. Record where 2612 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplBadDatabase.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2612 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Service failed to start because its database is absent or corrupt.\n\nLookup forms: 2612, 0xA34, 0x00000A34, error 2612, NERR_RplBadDatabase. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2612"]},{"id":2988,"title":"NERR_RplRplfilesShare","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2613","0xA35","0x00000A35","error 2613","NERR_RplRplfilesShare","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","rplrplfilesshare","service","failed","start","because","the","rplfiles","share","absent"],"errorCode":"2613","eventId":"","severity":"High","summary":"Service failed to start because the RPLFILES share is absent.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2613; use the surrounding log entries to confirm it.","resolution":"1. Record where 2613 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplRplfilesShare.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2613 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Service failed to start because the RPLFILES share is absent.\n\nLookup forms: 2613, 0xA35, 0x00000A35, error 2613, NERR_RplRplfilesShare. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2613"]},{"id":2989,"title":"NERR_RplNotRplServer","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2614","0xA36","0x00000A36","error 2614","NERR_RplNotRplServer","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","rplnotrplserver","service","failed","start","because","the","rpluser","group","absent"],"errorCode":"2614","eventId":"","severity":"High","summary":"Service failed to start because the RPLUSER group is absent.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2614; use the surrounding log entries to confirm it.","resolution":"1. Record where 2614 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplNotRplServer.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2614 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Service failed to start because the RPLUSER group is absent.\n\nLookup forms: 2614, 0xA36, 0x00000A36, error 2614, NERR_RplNotRplServer. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2614"]},{"id":2990,"title":"NERR_RplCannotEnum","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2615","0xA37","0x00000A37","error 2615","NERR_RplCannotEnum","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","rplcannotenum","cannot","enumerate","service","records"],"errorCode":"2615","eventId":"","severity":"Medium","summary":"Cannot enumerate service records.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2615; use the surrounding log entries to confirm it.","resolution":"1. Record where 2615 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplCannotEnum.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2615 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot enumerate service records.\n\nLookup forms: 2615, 0xA37, 0x00000A37, error 2615, NERR_RplCannotEnum. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2615"]},{"id":2991,"title":"NERR_RplWkstaInfoCorrupted","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2616","0xA38","0x00000A38","error 2616","NERR_RplWkstaInfoCorrupted","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","rplwkstainfocorrupted","workstation","record","information","has","been","corrupted"],"errorCode":"2616","eventId":"","severity":"Critical","summary":"Workstation record information has been corrupted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2616; use the surrounding log entries to confirm it.","resolution":"1. Record where 2616 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplWkstaInfoCorrupted.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2616 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Workstation record information has been corrupted.\n\nLookup forms: 2616, 0xA38, 0x00000A38, error 2616, NERR_RplWkstaInfoCorrupted. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2616"]},{"id":2992,"title":"NERR_RplWkstaNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2617","0xA39","0x00000A39","error 2617","NERR_RplWkstaNotFound","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","rplwkstanotfound","workstation","record","was","not","found"],"errorCode":"2617","eventId":"","severity":"Medium","summary":"Workstation record was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2617; use the surrounding log entries to confirm it.","resolution":"1. Record where 2617 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplWkstaNotFound.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2617 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Workstation record was not found.\n\nLookup forms: 2617, 0xA39, 0x00000A39, error 2617, NERR_RplWkstaNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2617"]},{"id":2993,"title":"NERR_RplWkstaNameUnavailable","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2618","0xA3A","0x00000A3A","error 2618","NERR_RplWkstaNameUnavailable","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","rplwkstanameunavailable","workstation","name","use","some","other"],"errorCode":"2618","eventId":"","severity":"Low","summary":"Workstation name is in use by some other workstation.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2618; use the surrounding log entries to confirm it.","resolution":"1. Record where 2618 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplWkstaNameUnavailable.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2618 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Workstation name is in use by some other workstation.\n\nLookup forms: 2618, 0xA3A, 0x00000A3A, error 2618, NERR_RplWkstaNameUnavailable. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2618"]},{"id":2994,"title":"NERR_RplProfileInfoCorrupted","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2619","0xA3B","0x00000A3B","error 2619","NERR_RplProfileInfoCorrupted","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","rplprofileinfocorrupted","profile","record","information","has","been","corrupted"],"errorCode":"2619","eventId":"","severity":"Critical","summary":"Profile record information has been corrupted.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2619; use the surrounding log entries to confirm it.","resolution":"1. Record where 2619 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplProfileInfoCorrupted.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2619 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Profile record information has been corrupted.\n\nLookup forms: 2619, 0xA3B, 0x00000A3B, error 2619, NERR_RplProfileInfoCorrupted. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2619"]},{"id":2995,"title":"NERR_RplProfileNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2620","0xA3C","0x00000A3C","error 2620","NERR_RplProfileNotFound","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","rplprofilenotfound","profile","record","was","not","found"],"errorCode":"2620","eventId":"","severity":"Medium","summary":"Profile record was not found.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2620; use the surrounding log entries to confirm it.","resolution":"1. Record where 2620 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplProfileNotFound.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2620 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Profile record was not found.\n\nLookup forms: 2620, 0xA3C, 0x00000A3C, error 2620, NERR_RplProfileNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2620"]},{"id":2996,"title":"NERR_RplProfileNameUnavailable","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2621","0xA3D","0x00000A3D","error 2621","NERR_RplProfileNameUnavailable","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","rplprofilenameunavailable","profile","name","use","some","other"],"errorCode":"2621","eventId":"","severity":"Low","summary":"Profile name is in use by some other profile.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2621; use the surrounding log entries to confirm it.","resolution":"1. Record where 2621 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplProfileNameUnavailable.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2621 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Profile name is in use by some other profile.\n\nLookup forms: 2621, 0xA3D, 0x00000A3D, error 2621, NERR_RplProfileNameUnavailable. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2621"]},{"id":2997,"title":"NERR_RplProfileNotEmpty","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2622","0xA3E","0x00000A3E","error 2622","NERR_RplProfileNotEmpty","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","rplprofilenotempty","there","are","workstations","using","this","profile"],"errorCode":"2622","eventId":"","severity":"Low","summary":"There are workstations using this profile.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2622; use the surrounding log entries to confirm it.","resolution":"1. Record where 2622 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplProfileNotEmpty.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2622 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There are workstations using this profile.\n\nLookup forms: 2622, 0xA3E, 0x00000A3E, error 2622, NERR_RplProfileNotEmpty. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2622"]},{"id":2998,"title":"NERR_RplConfigInfoCorrupted","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2623","0xA3F","0x00000A3F","error 2623","NERR_RplConfigInfoCorrupted","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","rplconfiginfocorrupted","configuration","record","information","has","been","corrupted"],"errorCode":"2623","eventId":"","severity":"Critical","summary":"Configuration record information has been corrupted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2623; use the surrounding log entries to confirm it.","resolution":"1. Record where 2623 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplConfigInfoCorrupted.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2623 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Configuration record information has been corrupted.\n\nLookup forms: 2623, 0xA3F, 0x00000A3F, error 2623, NERR_RplConfigInfoCorrupted. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2623"]},{"id":2999,"title":"NERR_RplConfigNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2624","0xA40","0x00000A40","error 2624","NERR_RplConfigNotFound","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","rplconfignotfound","configuration","record","was","not","found"],"errorCode":"2624","eventId":"","severity":"Medium","summary":"Configuration record was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2624; use the surrounding log entries to confirm it.","resolution":"1. Record where 2624 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplConfigNotFound.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2624 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Configuration record was not found.\n\nLookup forms: 2624, 0xA40, 0x00000A40, error 2624, NERR_RplConfigNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2624"]},{"id":3000,"title":"NERR_RplAdapterInfoCorrupted","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2625","0xA41","0x00000A41","error 2625","NERR_RplAdapterInfoCorrupted","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","rpladapterinfocorrupted","adapter","record","information","has","been","corrupted"],"errorCode":"2625","eventId":"","severity":"Critical","summary":"Adapter ID record information has been corrupted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2625; use the surrounding log entries to confirm it.","resolution":"1. Record where 2625 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplAdapterInfoCorrupted.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2625 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Adapter ID record information has been corrupted.\n\nLookup forms: 2625, 0xA41, 0x00000A41, error 2625, NERR_RplAdapterInfoCorrupted. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2625"]},{"id":3001,"title":"NERR_RplInternal","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2626","0xA42","0x00000A42","error 2626","NERR_RplInternal","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","rplinternal","internal","service","error","has","occurred"],"errorCode":"2626","eventId":"","severity":"Low","summary":"An internal service error has occurred.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2626; use the surrounding log entries to confirm it.","resolution":"1. Record where 2626 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplInternal.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2626 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An internal service error has occurred.\n\nLookup forms: 2626, 0xA42, 0x00000A42, error 2626, NERR_RplInternal. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2626"]},{"id":3002,"title":"NERR_RplVendorInfoCorrupted","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2627","0xA43","0x00000A43","error 2627","NERR_RplVendorInfoCorrupted","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","rplvendorinfocorrupted","vendor","record","information","has","been","corrupted"],"errorCode":"2627","eventId":"","severity":"Critical","summary":"Vendor ID record information has been corrupted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2627; use the surrounding log entries to confirm it.","resolution":"1. Record where 2627 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplVendorInfoCorrupted.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2627 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Vendor ID record information has been corrupted.\n\nLookup forms: 2627, 0xA43, 0x00000A43, error 2627, NERR_RplVendorInfoCorrupted. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2627"]},{"id":3003,"title":"NERR_RplBootInfoCorrupted","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2628","0xA44","0x00000A44","error 2628","NERR_RplBootInfoCorrupted","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","rplbootinfocorrupted","boot","block","record","information","has","been","corrupted"],"errorCode":"2628","eventId":"","severity":"Critical","summary":"Boot block record information has been corrupted.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2628; use the surrounding log entries to confirm it.","resolution":"1. Record where 2628 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplBootInfoCorrupted.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2628 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Boot block record information has been corrupted.\n\nLookup forms: 2628, 0xA44, 0x00000A44, error 2628, NERR_RplBootInfoCorrupted. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2628"]},{"id":3004,"title":"NERR_RplWkstaNeedsUserAcct","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2629","0xA45","0x00000A45","error 2629","NERR_RplWkstaNeedsUserAcct","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","rplwkstaneedsuseracct","the","user","account","for","this","workstation","record","missing"],"errorCode":"2629","eventId":"","severity":"Low","summary":"The user account for this workstation record is missing.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2629; use the surrounding log entries to confirm it.","resolution":"1. Record where 2629 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplWkstaNeedsUserAcct.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2629 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The user account for this workstation record is missing.\n\nLookup forms: 2629, 0xA45, 0x00000A45, error 2629, NERR_RplWkstaNeedsUserAcct. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2629"]},{"id":3005,"title":"NERR_RplNeedsRPLUSERAcct","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2630","0xA46","0x00000A46","error 2630","NERR_RplNeedsRPLUSERAcct","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","rplneedsrpluseracct","the","rpluser","local","group","could","not","found"],"errorCode":"2630","eventId":"","severity":"Low","summary":"The RPLUSER local group could not be found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2630; use the surrounding log entries to confirm it.","resolution":"1. Record where 2630 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplNeedsRPLUSERAcct.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2630 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The RPLUSER local group could not be found.\n\nLookup forms: 2630, 0xA46, 0x00000A46, error 2630, NERR_RplNeedsRPLUSERAcct. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2630"]},{"id":3006,"title":"NERR_RplBootNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2631","0xA47","0x00000A47","error 2631","NERR_RplBootNotFound","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","rplbootnotfound","boot","block","record","was","not","found"],"errorCode":"2631","eventId":"","severity":"Medium","summary":"Boot block record was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2631; use the surrounding log entries to confirm it.","resolution":"1. Record where 2631 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplBootNotFound.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2631 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Boot block record was not found.\n\nLookup forms: 2631, 0xA47, 0x00000A47, error 2631, NERR_RplBootNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2631"]},{"id":3007,"title":"NERR_RplIncompatibleProfile","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2632","0xA48","0x00000A48","error 2632","NERR_RplIncompatibleProfile","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","rplincompatibleprofile","chosen","profile","incompatible","with","this","workstation"],"errorCode":"2632","eventId":"","severity":"Low","summary":"Chosen profile is incompatible with this workstation.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2632; use the surrounding log entries to confirm it.","resolution":"1. Record where 2632 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplIncompatibleProfile.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2632 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Chosen profile is incompatible with this workstation.\n\nLookup forms: 2632, 0xA48, 0x00000A48, error 2632, NERR_RplIncompatibleProfile. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2632"]},{"id":3008,"title":"NERR_RplAdapterNameUnavailable","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2633","0xA49","0x00000A49","error 2633","NERR_RplAdapterNameUnavailable","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","rpladapternameunavailable","chosen","network","adapter","use","some","other","workstation"],"errorCode":"2633","eventId":"","severity":"High","summary":"Chosen network adapter ID is in use by some other workstation.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2633; use the surrounding log entries to confirm it.","resolution":"1. Record where 2633 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplAdapterNameUnavailable.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2633 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Chosen network adapter ID is in use by some other workstation.\n\nLookup forms: 2633, 0xA49, 0x00000A49, error 2633, NERR_RplAdapterNameUnavailable. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2633"]},{"id":3009,"title":"NERR_RplConfigNotEmpty","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2634","0xA4A","0x00000A4A","error 2634","NERR_RplConfigNotEmpty","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","rplconfignotempty","there","are","profiles","using","this","configuration"],"errorCode":"2634","eventId":"","severity":"Low","summary":"There are profiles using this configuration.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2634; use the surrounding log entries to confirm it.","resolution":"1. Record where 2634 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplConfigNotEmpty.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2634 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There are profiles using this configuration.\n\nLookup forms: 2634, 0xA4A, 0x00000A4A, error 2634, NERR_RplConfigNotEmpty. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2634"]},{"id":3010,"title":"NERR_RplBootInUse","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2635","0xA4B","0x00000A4B","error 2635","NERR_RplBootInUse","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","rplbootinuse","there","are","workstations","profiles","configurations","using","this","boot","block"],"errorCode":"2635","eventId":"","severity":"Low","summary":"There are workstations, profiles, or configurations using this boot block.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2635; use the surrounding log entries to confirm it.","resolution":"1. Record where 2635 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplBootInUse.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2635 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There are workstations, profiles, or configurations using this boot block.\n\nLookup forms: 2635, 0xA4B, 0x00000A4B, error 2635, NERR_RplBootInUse. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2635"]},{"id":3011,"title":"NERR_RplBackupDatabase","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2636","0xA4C","0x00000A4C","error 2636","NERR_RplBackupDatabase","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","rplbackupdatabase","service","failed","back","the","remoteboot","database"],"errorCode":"2636","eventId":"","severity":"High","summary":"Service failed to back up the Remoteboot database.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2636; use the surrounding log entries to confirm it.","resolution":"1. Record where 2636 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplBackupDatabase.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2636 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Service failed to back up the Remoteboot database.\n\nLookup forms: 2636, 0xA4C, 0x00000A4C, error 2636, NERR_RplBackupDatabase. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2636"]},{"id":3012,"title":"NERR_RplAdapterNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2637","0xA4D","0x00000A4D","error 2637","NERR_RplAdapterNotFound","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","rpladapternotfound","adapter","record","was","not","found"],"errorCode":"2637","eventId":"","severity":"Medium","summary":"Adapter record was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2637; use the surrounding log entries to confirm it.","resolution":"1. Record where 2637 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplAdapterNotFound.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2637 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Adapter record was not found.\n\nLookup forms: 2637, 0xA4D, 0x00000A4D, error 2637, NERR_RplAdapterNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2637"]},{"id":3013,"title":"NERR_RplVendorNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2638","0xA4E","0x00000A4E","error 2638","NERR_RplVendorNotFound","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","rplvendornotfound","vendor","record","was","not","found"],"errorCode":"2638","eventId":"","severity":"Medium","summary":"Vendor record was not found.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2638; use the surrounding log entries to confirm it.","resolution":"1. Record where 2638 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplVendorNotFound.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2638 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Vendor record was not found.\n\nLookup forms: 2638, 0xA4E, 0x00000A4E, error 2638, NERR_RplVendorNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2638"]},{"id":3014,"title":"NERR_RplVendorNameUnavailable","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2639","0xA4F","0x00000A4F","error 2639","NERR_RplVendorNameUnavailable","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","rplvendornameunavailable","vendor","name","use","some","other","record"],"errorCode":"2639","eventId":"","severity":"Low","summary":"Vendor name is in use by some other vendor record.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2639; use the surrounding log entries to confirm it.","resolution":"1. Record where 2639 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplVendorNameUnavailable.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2639 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Vendor name is in use by some other vendor record.\n\nLookup forms: 2639, 0xA4F, 0x00000A4F, error 2639, NERR_RplVendorNameUnavailable. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2639"]},{"id":3015,"title":"NERR_RplBootNameUnavailable","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2640","0xA50","0x00000A50","error 2640","NERR_RplBootNameUnavailable","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","rplbootnameunavailable","the","boot","name","vendor","use","some","other","block","record"],"errorCode":"2640","eventId":"","severity":"Low","summary":"The boot name or vendor ID is in use by some other boot block record.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2640; use the surrounding log entries to confirm it.","resolution":"1. Record where 2640 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplBootNameUnavailable.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2640 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The boot name or vendor ID is in use by some other boot block record.\n\nLookup forms: 2640, 0xA50, 0x00000A50, error 2640, NERR_RplBootNameUnavailable. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2640"]},{"id":3016,"title":"NERR_RplConfigNameUnavailable","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2641","0xA51","0x00000A51","error 2641","NERR_RplConfigNameUnavailable","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","rplconfignameunavailable","the","configuration","name","use","some","other"],"errorCode":"2641","eventId":"","severity":"Low","summary":"The configuration name is in use by some other configuration.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2641; use the surrounding log entries to confirm it.","resolution":"1. Record where 2641 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_RplConfigNameUnavailable.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2641 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The configuration name is in use by some other configuration.\n\nLookup forms: 2641, 0xA51, 0x00000A51, error 2641, NERR_RplConfigNameUnavailable. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2641"]},{"id":3017,"title":"NERR_DfsInternalCorruption","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2660","0xA64","0x00000A64","error 2660","NERR_DfsInternalCorruption","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","dfsinternalcorruption","the","internal","database","maintained","dfs","service","corrupt"],"errorCode":"2660","eventId":"","severity":"Critical","summary":"The internal database maintained by the DFS service is corrupt.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2660; use the surrounding log entries to confirm it.","resolution":"1. Record where 2660 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DfsInternalCorruption.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2660 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The internal database maintained by the DFS service is corrupt.\n\nLookup forms: 2660, 0xA64, 0x00000A64, error 2660, NERR_DfsInternalCorruption. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2660"]},{"id":3018,"title":"NERR_DfsVolumeDataCorrupt","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2661","0xA65","0x00000A65","error 2661","NERR_DfsVolumeDataCorrupt","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","dfsvolumedatacorrupt","one","the","records","internal","dfs","database","corrupt"],"errorCode":"2661","eventId":"","severity":"Critical","summary":"One of the records in the internal DFS database is corrupt.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2661; use the surrounding log entries to confirm it.","resolution":"1. Record where 2661 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DfsVolumeDataCorrupt.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2661 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: One of the records in the internal DFS database is corrupt.\n\nLookup forms: 2661, 0xA65, 0x00000A65, error 2661, NERR_DfsVolumeDataCorrupt. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2661"]},{"id":3019,"title":"NERR_DfsNoSuchVolume","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2662","0xA66","0x00000A66","error 2662","NERR_DfsNoSuchVolume","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","dfsnosuchvolume","there","dfs","name","whose","entry","path","matches","the","input"],"errorCode":"2662","eventId":"","severity":"Low","summary":"There is no DFS name whose entry path matches the input entry path.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2662; use the surrounding log entries to confirm it.","resolution":"1. Record where 2662 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DfsNoSuchVolume.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2662 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: There is no DFS name whose entry path matches the input entry path.\n\nLookup forms: 2662, 0xA66, 0x00000A66, error 2662, NERR_DfsNoSuchVolume. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2662"]},{"id":3020,"title":"NERR_DfsVolumeAlreadyExists","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2663","0xA67","0x00000A67","error 2663","NERR_DfsVolumeAlreadyExists","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","dfsvolumealreadyexists","root","link","with","the","given","name","already","exists"],"errorCode":"2663","eventId":"","severity":"Medium","summary":"A root or link with the given name already exists.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2663; use the surrounding log entries to confirm it.","resolution":"1. Record where 2663 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DfsVolumeAlreadyExists.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2663 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A root or link with the given name already exists.\n\nLookup forms: 2663, 0xA67, 0x00000A67, error 2663, NERR_DfsVolumeAlreadyExists. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2663"]},{"id":3021,"title":"NERR_DfsAlreadyShared","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2664","0xA68","0x00000A68","error 2664","NERR_DfsAlreadyShared","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","dfsalreadyshared","the","server","share","specified","already","shared","dfs"],"errorCode":"2664","eventId":"","severity":"Low","summary":"The server share specified is already shared in the DFS.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2664; use the surrounding log entries to confirm it.","resolution":"1. Record where 2664 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DfsAlreadyShared.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2664 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The server share specified is already shared in the DFS.\n\nLookup forms: 2664, 0xA68, 0x00000A68, error 2664, NERR_DfsAlreadyShared. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2664"]},{"id":3022,"title":"NERR_DfsNoSuchShare","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2665","0xA69","0x00000A69","error 2665","NERR_DfsNoSuchShare","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","dfsnosuchshare","the","indicated","server","share","does","not","support","dfs","namespace"],"errorCode":"2665","eventId":"","severity":"Low","summary":"The indicated server share does not support the indicated DFS namespace.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2665; use the surrounding log entries to confirm it.","resolution":"1. Record where 2665 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DfsNoSuchShare.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2665 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The indicated server share does not support the indicated DFS namespace.\n\nLookup forms: 2665, 0xA69, 0x00000A69, error 2665, NERR_DfsNoSuchShare. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2665"]},{"id":3023,"title":"NERR_DfsNotALeafVolume","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2666","0xA6A","0x00000A6A","error 2666","NERR_DfsNotALeafVolume","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","dfsnotaleafvolume","the","operation","not","valid","this","portion","namespace"],"errorCode":"2666","eventId":"","severity":"Low","summary":"The operation is not valid in this portion of the namespace.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2666; use the surrounding log entries to confirm it.","resolution":"1. Record where 2666 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DfsNotALeafVolume.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2666 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation is not valid in this portion of the namespace.\n\nLookup forms: 2666, 0xA6A, 0x00000A6A, error 2666, NERR_DfsNotALeafVolume. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2666"]},{"id":3024,"title":"NERR_DfsLeafVolume","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2667","0xA6B","0x00000A6B","error 2667","NERR_DfsLeafVolume","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","dfsleafvolume","the","operation","not","valid","this","portion","namespace"],"errorCode":"2667","eventId":"","severity":"Low","summary":"The operation is not valid in this portion of the namespace.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2667; use the surrounding log entries to confirm it.","resolution":"1. Record where 2667 occurred and reproduce the operation if it is safe to do so.\n2. Check available memory, disk capacity, quotas, and system resource pressure.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DfsLeafVolume.\n\nWe recommend performing the following corrective action: Check available memory, disk capacity, quotas, and system resource pressure. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2667 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation is not valid in this portion of the namespace.\n\nLookup forms: 2667, 0xA6B, 0x00000A6B, error 2667, NERR_DfsLeafVolume. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2667"]},{"id":3025,"title":"NERR_DfsVolumeHasMultipleServers","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2668","0xA6C","0x00000A6C","error 2668","NERR_DfsVolumeHasMultipleServers","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","dfsvolumehasmultipleservers","the","operation","ambiguous","because","link","has","multiple","servers"],"errorCode":"2668","eventId":"","severity":"Low","summary":"The operation is ambiguous because the link has multiple servers.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2668; use the surrounding log entries to confirm it.","resolution":"1. Record where 2668 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DfsVolumeHasMultipleServers.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2668 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation is ambiguous because the link has multiple servers.\n\nLookup forms: 2668, 0xA6C, 0x00000A6C, error 2668, NERR_DfsVolumeHasMultipleServers. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2668"]},{"id":3026,"title":"NERR_DfsCantCreateJunctionPoint","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2669","0xA6D","0x00000A6D","error 2669","NERR_DfsCantCreateJunctionPoint","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","dfscantcreatejunctionpoint","unable","create","link"],"errorCode":"2669","eventId":"","severity":"Medium","summary":"Unable to create a link.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2669; use the surrounding log entries to confirm it.","resolution":"1. Record where 2669 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DfsCantCreateJunctionPoint.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2669 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Unable to create a link.\n\nLookup forms: 2669, 0xA6D, 0x00000A6D, error 2669, NERR_DfsCantCreateJunctionPoint. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2669"]},{"id":3027,"title":"NERR_DfsServerNotDfsAware","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2670","0xA6E","0x00000A6E","error 2670","NERR_DfsServerNotDfsAware","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","dfsservernotdfsaware","the","server","not","dfs","aware"],"errorCode":"2670","eventId":"","severity":"Low","summary":"The server is not DFS-aware.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2670; use the surrounding log entries to confirm it.","resolution":"1. Record where 2670 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DfsServerNotDfsAware.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2670 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The server is not DFS-aware.\n\nLookup forms: 2670, 0xA6E, 0x00000A6E, error 2670, NERR_DfsServerNotDfsAware. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2670"]},{"id":3028,"title":"NERR_DfsBadRenamePath","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2671","0xA6F","0x00000A6F","error 2671","NERR_DfsBadRenamePath","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","dfsbadrenamepath","the","specified","rename","target","path","invalid"],"errorCode":"2671","eventId":"","severity":"Medium","summary":"The specified rename target path is invalid.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2671; use the surrounding log entries to confirm it.","resolution":"1. Record where 2671 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DfsBadRenamePath.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2671 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified rename target path is invalid.\n\nLookup forms: 2671, 0xA6F, 0x00000A6F, error 2671, NERR_DfsBadRenamePath. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2671"]},{"id":3029,"title":"NERR_DfsVolumeIsOffline","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2672","0xA70","0x00000A70","error 2672","NERR_DfsVolumeIsOffline","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","dfsvolumeisoffline","the","specified","dfs","link","offline"],"errorCode":"2672","eventId":"","severity":"Low","summary":"The specified DFS link is offline.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2672; use the surrounding log entries to confirm it.","resolution":"1. Record where 2672 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DfsVolumeIsOffline.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2672 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified DFS link is offline.\n\nLookup forms: 2672, 0xA70, 0x00000A70, error 2672, NERR_DfsVolumeIsOffline. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2672"]},{"id":3030,"title":"NERR_DfsNoSuchServer","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2673","0xA71","0x00000A71","error 2673","NERR_DfsNoSuchServer","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","dfsnosuchserver","the","specified","server","not","for","this","link"],"errorCode":"2673","eventId":"","severity":"Low","summary":"The specified server is not a server for this link.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2673; use the surrounding log entries to confirm it.","resolution":"1. Record where 2673 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DfsNoSuchServer.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2673 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified server is not a server for this link.\n\nLookup forms: 2673, 0xA71, 0x00000A71, error 2673, NERR_DfsNoSuchServer. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2673"]},{"id":3031,"title":"NERR_DfsCyclicalName","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2674","0xA72","0x00000A72","error 2674","NERR_DfsCyclicalName","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","dfscyclicalname","cycle","the","dfs","name","was","detected"],"errorCode":"2674","eventId":"","severity":"Low","summary":"A cycle in the DFS name was detected.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2674; use the surrounding log entries to confirm it.","resolution":"1. Record where 2674 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DfsCyclicalName.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2674 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A cycle in the DFS name was detected.\n\nLookup forms: 2674, 0xA72, 0x00000A72, error 2674, NERR_DfsCyclicalName. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2674"]},{"id":3032,"title":"NERR_DfsNotSupportedInServerDfs","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2675","0xA73","0x00000A73","error 2675","NERR_DfsNotSupportedInServerDfs","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","dfsnotsupportedinserverdfs","the","operation","not","supported","server","based","dfs"],"errorCode":"2675","eventId":"","severity":"Medium","summary":"The operation is not supported on a server-based DFS.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2675; use the surrounding log entries to confirm it.","resolution":"1. Record where 2675 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DfsNotSupportedInServerDfs.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2675 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation is not supported on a server-based DFS.\n\nLookup forms: 2675, 0xA73, 0x00000A73, error 2675, NERR_DfsNotSupportedInServerDfs. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2675"]},{"id":3033,"title":"NERR_DfsDuplicateService","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2676","0xA74","0x00000A74","error 2676","NERR_DfsDuplicateService","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","dfsduplicateservice","this","link","already","supported","the","specified","server","share"],"errorCode":"2676","eventId":"","severity":"Low","summary":"This link is already supported by the specified server share.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2676; use the surrounding log entries to confirm it.","resolution":"1. Record where 2676 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DfsDuplicateService.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2676 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This link is already supported by the specified server share.\n\nLookup forms: 2676, 0xA74, 0x00000A74, error 2676, NERR_DfsDuplicateService. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2676"]},{"id":3034,"title":"NERR_DfsCantRemoveLastServerShare","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2677","0xA75","0x00000A75","error 2677","NERR_DfsCantRemoveLastServerShare","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","dfscantremovelastservershare","cannot","remove","the","last","server","share","supporting","this","root","link"],"errorCode":"2677","eventId":"","severity":"Medium","summary":"Cannot remove the last server share supporting this root or link.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2677; use the surrounding log entries to confirm it.","resolution":"1. Record where 2677 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DfsCantRemoveLastServerShare.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2677 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Cannot remove the last server share supporting this root or link.\n\nLookup forms: 2677, 0xA75, 0x00000A75, error 2677, NERR_DfsCantRemoveLastServerShare. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2677"]},{"id":3035,"title":"NERR_DfsVolumeIsInterDfs","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2678","0xA76","0x00000A76","error 2678","NERR_DfsVolumeIsInterDfs","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","dfsvolumeisinterdfs","the","operation","not","supported","for","inter","dfs","link"],"errorCode":"2678","eventId":"","severity":"Medium","summary":"The operation is not supported for an inter-DFS link.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2678; use the surrounding log entries to confirm it.","resolution":"1. Record where 2678 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DfsVolumeIsInterDfs.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2678 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation is not supported for an inter-DFS link.\n\nLookup forms: 2678, 0xA76, 0x00000A76, error 2678, NERR_DfsVolumeIsInterDfs. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2678"]},{"id":3036,"title":"NERR_DfsInconsistent","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2679","0xA77","0x00000A77","error 2679","NERR_DfsInconsistent","Win32 System Code","Windows","Windows / Win32 API","the calling process or Windows service","microsoft error","windows troubleshooting","nerr","dfsinconsistent","the","internal","state","dfs","service","has","become","inconsistent"],"errorCode":"2679","eventId":"","severity":"Low","summary":"The internal state of the DFS Service has become inconsistent.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 2679; use the surrounding log entries to confirm it.","resolution":"1. Record where 2679 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DfsInconsistent.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2679 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The internal state of the DFS Service has become inconsistent.\n\nLookup forms: 2679, 0xA77, 0x00000A77, error 2679, NERR_DfsInconsistent. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2679"]},{"id":3037,"title":"NERR_DfsServerUpgraded","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2680","0xA78","0x00000A78","error 2680","NERR_DfsServerUpgraded","Win32 System Code","Windows","Windows / Win32 API","network connectivity","microsoft error","windows troubleshooting","nerr","dfsserverupgraded","the","dfs","service","has","been","installed","specified","server"],"errorCode":"2680","eventId":"","severity":"Low","summary":"The DFS Service has been installed on the specified server.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 2680; use the surrounding log entries to confirm it.","resolution":"1. Record where 2680 occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DfsServerUpgraded.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2680 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The DFS Service has been installed on the specified server.\n\nLookup forms: 2680, 0xA78, 0x00000A78, error 2680, NERR_DfsServerUpgraded. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2680"]},{"id":3038,"title":"NERR_DfsDataIsIdentical","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2681","0xA79","0x00000A79","error 2681","NERR_DfsDataIsIdentical","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","dfsdataisidentical","the","dfs","data","being","reconciled","identical"],"errorCode":"2681","eventId":"","severity":"Low","summary":"The DFS data being reconciled is identical.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2681; use the surrounding log entries to confirm it.","resolution":"1. Record where 2681 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DfsDataIsIdentical.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2681 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The DFS data being reconciled is identical.\n\nLookup forms: 2681, 0xA79, 0x00000A79, error 2681, NERR_DfsDataIsIdentical. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2681"]},{"id":3039,"title":"NERR_DfsCantRemoveDfsRoot","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2682","0xA7A","0x00000A7A","error 2682","NERR_DfsCantRemoveDfsRoot","Win32 System Code","Windows","Windows / Win32 API","installation or update components","microsoft error","windows troubleshooting","nerr","dfscantremovedfsroot","the","dfs","root","cannot","deleted","uninstall","required"],"errorCode":"2682","eventId":"","severity":"Medium","summary":"The DFS root cannot be deleted. Uninstall DFS if required.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 2682; use the surrounding log entries to confirm it.","resolution":"1. Record where 2682 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DfsCantRemoveDfsRoot.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2682 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The DFS root cannot be deleted. Uninstall DFS if required.\n\nLookup forms: 2682, 0xA7A, 0x00000A7A, error 2682, NERR_DfsCantRemoveDfsRoot. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2682"]},{"id":3040,"title":"NERR_DfsChildOrParentInDfs","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2683","0xA7B","0x00000A7B","error 2683","NERR_DfsChildOrParentInDfs","Win32 System Code","Windows","Windows / Win32 API","files, storage, or memory","microsoft error","windows troubleshooting","nerr","dfschildorparentindfs","child","parent","directory","the","share","already","dfs"],"errorCode":"2683","eventId":"","severity":"Low","summary":"A child or parent directory of the share is already in a DFS.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 2683; use the surrounding log entries to confirm it.","resolution":"1. Record where 2683 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DfsChildOrParentInDfs.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2683 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A child or parent directory of the share is already in a DFS.\n\nLookup forms: 2683, 0xA7B, 0x00000A7B, error 2683, NERR_DfsChildOrParentInDfs. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2683"]},{"id":3041,"title":"NERR_DfsInternalError","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2690","0xA82","0x00000A82","error 2690","NERR_DfsInternalError","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","dfsinternalerror","dfs","internal","error"],"errorCode":"2690","eventId":"","severity":"Low","summary":"DFS internal error.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2690; use the surrounding log entries to confirm it.","resolution":"1. Record where 2690 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DfsInternalError.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2690 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: DFS internal error.\n\nLookup forms: 2690, 0xA82, 0x00000A82, error 2690, NERR_DfsInternalError. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2690"]},{"id":3042,"title":"NERR_SetupAlreadyJoined","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2691","0xA83","0x00000A83","error 2691","NERR_SetupAlreadyJoined","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","setupalreadyjoined","this","machine","already","joined","domain"],"errorCode":"2691","eventId":"","severity":"Low","summary":"This machine is already joined to a domain.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2691; use the surrounding log entries to confirm it.","resolution":"1. Record where 2691 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_SetupAlreadyJoined.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2691 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This machine is already joined to a domain.\n\nLookup forms: 2691, 0xA83, 0x00000A83, error 2691, NERR_SetupAlreadyJoined. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2691"]},{"id":3043,"title":"NERR_SetupNotJoined","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2692","0xA84","0x00000A84","error 2692","NERR_SetupNotJoined","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","setupnotjoined","this","machine","not","currently","joined","domain"],"errorCode":"2692","eventId":"","severity":"Low","summary":"This machine is not currently joined to a domain.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2692; use the surrounding log entries to confirm it.","resolution":"1. Record where 2692 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_SetupNotJoined.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2692 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This machine is not currently joined to a domain.\n\nLookup forms: 2692, 0xA84, 0x00000A84, error 2692, NERR_SetupNotJoined. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2692"]},{"id":3044,"title":"NERR_SetupDomainController","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2693","0xA85","0x00000A85","error 2693","NERR_SetupDomainController","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","setupdomaincontroller","this","machine","domain","controller","and","cannot","unjoined","from"],"errorCode":"2693","eventId":"","severity":"Medium","summary":"This machine is a domain controller and cannot be unjoined from a domain.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2693; use the surrounding log entries to confirm it.","resolution":"1. Record where 2693 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_SetupDomainController.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2693 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This machine is a domain controller and cannot be unjoined from a domain.\n\nLookup forms: 2693, 0xA85, 0x00000A85, error 2693, NERR_SetupDomainController. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2693"]},{"id":3045,"title":"NERR_DefaultJoinRequired","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2694","0xA86","0x00000A86","error 2694","NERR_DefaultJoinRequired","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","defaultjoinrequired","the","destination","domain","controller","does","not","support","creating","machine","accounts","organizational","units","ous"],"errorCode":"2694","eventId":"","severity":"Low","summary":"The destination domain controller does not support creating machine accounts in organizational units (OUs).","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2694; use the surrounding log entries to confirm it.","resolution":"1. Record where 2694 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_DefaultJoinRequired.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2694 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The destination domain controller does not support creating machine accounts in organizational units (OUs).\n\nLookup forms: 2694, 0xA86, 0x00000A86, error 2694, NERR_DefaultJoinRequired. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2694"]},{"id":3046,"title":"NERR_InvalidWorkgroupName","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2695","0xA87","0x00000A87","error 2695","NERR_InvalidWorkgroupName","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","invalidworkgroupname","the","specified","workgroup","name","invalid"],"errorCode":"2695","eventId":"","severity":"Medium","summary":"The specified workgroup name is invalid.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2695; use the surrounding log entries to confirm it.","resolution":"1. Record where 2695 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_InvalidWorkgroupName.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2695 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified workgroup name is invalid.\n\nLookup forms: 2695, 0xA87, 0x00000A87, error 2695, NERR_InvalidWorkgroupName. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2695"]},{"id":3047,"title":"NERR_NameUsesIncompatibleCodePage","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2696","0xA88","0x00000A88","error 2696","NERR_NameUsesIncompatibleCodePage","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","nameusesincompatiblecodepage","the","specified","computer","name","incompatible","with","default","language","used","domain","controller"],"errorCode":"2696","eventId":"","severity":"Low","summary":"The specified computer name is incompatible with the default language used on the domain controller.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2696; use the surrounding log entries to confirm it.","resolution":"1. Record where 2696 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_NameUsesIncompatibleCodePage.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2696 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified computer name is incompatible with the default language used on the domain controller.\n\nLookup forms: 2696, 0xA88, 0x00000A88, error 2696, NERR_NameUsesIncompatibleCodePage. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2696"]},{"id":3048,"title":"NERR_ComputerAccountNotFound","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2697","0xA89","0x00000A89","error 2697","NERR_ComputerAccountNotFound","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","computeraccountnotfound","the","specified","computer","account","could","not","found"],"errorCode":"2697","eventId":"","severity":"Low","summary":"The specified computer account could not be found.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2697; use the surrounding log entries to confirm it.","resolution":"1. Record where 2697 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_ComputerAccountNotFound.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2697 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The specified computer account could not be found.\n\nLookup forms: 2697, 0xA89, 0x00000A89, error 2697, NERR_ComputerAccountNotFound. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2697"]},{"id":3049,"title":"NERR_PersonalSku","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2698","0xA8A","0x00000A8A","error 2698","NERR_PersonalSku","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","personalsku","this","version","windows","cannot","joined","domain"],"errorCode":"2698","eventId":"","severity":"Medium","summary":"This version of Windows cannot be joined to a domain.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2698; use the surrounding log entries to confirm it.","resolution":"1. Record where 2698 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_PersonalSku.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2698 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: This version of Windows cannot be joined to a domain.\n\nLookup forms: 2698, 0xA8A, 0x00000A8A, error 2698, NERR_PersonalSku. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2698"]},{"id":3050,"title":"NERR_PasswordMustChange","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2701","0xA8D","0x00000A8D","error 2701","NERR_PasswordMustChange","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","passwordmustchange","the","password","must","change","next","logon"],"errorCode":"2701","eventId":"","severity":"High","summary":"The password must change at the next logon.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2701; use the surrounding log entries to confirm it.","resolution":"1. Record where 2701 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_PasswordMustChange.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2701 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The password must change at the next logon.\n\nLookup forms: 2701, 0xA8D, 0x00000A8D, error 2701, NERR_PasswordMustChange. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2701"]},{"id":3051,"title":"NERR_AccountLockedOut","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2702","0xA8E","0x00000A8E","error 2702","NERR_AccountLockedOut","Win32 System Code","Windows","Windows / Win32 API","permissions and identity","microsoft error","windows troubleshooting","nerr","accountlockedout","the","account","locked","out"],"errorCode":"2702","eventId":"","severity":"High","summary":"The account is locked out.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 2702; use the surrounding log entries to confirm it.","resolution":"1. Record where 2702 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_AccountLockedOut.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2702 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The account is locked out.\n\nLookup forms: 2702, 0xA8E, 0x00000A8E, error 2702, NERR_AccountLockedOut. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2702"]},{"id":3052,"title":"NERR_PasswordTooLong","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2703","0xA8F","0x00000A8F","error 2703","NERR_PasswordTooLong","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","passwordtoolong","the","password","too","long"],"errorCode":"2703","eventId":"","severity":"Low","summary":"The password is too long.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2703; use the surrounding log entries to confirm it.","resolution":"1. Record where 2703 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_PasswordTooLong.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2703 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The password is too long.\n\nLookup forms: 2703, 0xA8F, 0x00000A8F, error 2703, NERR_PasswordTooLong. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2703"]},{"id":3053,"title":"NERR_PasswordNotComplexEnough","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2704","0xA90","0x00000A90","error 2704","NERR_PasswordNotComplexEnough","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","passwordnotcomplexenough","the","password","does","not","meet","complexity","policy"],"errorCode":"2704","eventId":"","severity":"Low","summary":"The password does not meet the complexity policy.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2704; use the surrounding log entries to confirm it.","resolution":"1. Record where 2704 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_PasswordNotComplexEnough.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2704 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The password does not meet the complexity policy.\n\nLookup forms: 2704, 0xA90, 0x00000A90, error 2704, NERR_PasswordNotComplexEnough. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2704"]},{"id":3054,"title":"NERR_PasswordFilterError","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["2705","0xA91","0x00000A91","error 2705","NERR_PasswordFilterError","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","nerr","passwordfiltererror","the","password","does","not","meet","requirements","filter","dlls"],"errorCode":"2705","eventId":"","severity":"Low","summary":"The password does not meet the requirements of the password filter DLLs.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 2705; use the surrounding log entries to confirm it.","resolution":"1. Record where 2705 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to NERR_PasswordFilterError.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 2705 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The password does not meet the requirements of the password filter DLLs.\n\nLookup forms: 2705, 0xA91, 0x00000A91, error 2705, NERR_PasswordFilterError. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["2705"]},{"id":3055,"title":"ERROR_DS_SPN_VALUE_NOT_UNIQUE_IN_FOREST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8647","0x21C7","0x000021C7","error 8647","ERROR_DS_SPN_VALUE_NOT_UNIQUE_IN_FOREST","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","spn","value","not","unique","forest","the","operation","failed","because","provided","for","addition","modification","wide"],"errorCode":"8647","eventId":"","severity":"High","summary":"The operation failed because the SPN value provided for addition/modification is not unique forest-wide.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8647; use the surrounding log entries to confirm it.","resolution":"1. Record where 8647 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_SPN_VALUE_NOT_UNIQUE_IN_FOREST.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8647 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation failed because the SPN value provided for addition/modification is not unique forest-wide.\n\nLookup forms: 8647, 0x21C7, 0x000021C7, error 8647, ERROR_DS_SPN_VALUE_NOT_UNIQUE_IN_FOREST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8647"]},{"id":3056,"title":"ERROR_DS_UPN_VALUE_NOT_UNIQUE_IN_FOREST","category":"Windows","product":"Windows / Win32 API","tags":["Win32 System Code","Windows","Windows / Win32 API"],"keywords":["8648","0x21C8","0x000021C8","error 8648","ERROR_DS_UPN_VALUE_NOT_UNIQUE_IN_FOREST","Win32 System Code","Windows","Windows / Win32 API","the operation's inputs or current system state","microsoft error","windows troubleshooting","error","upn","value","not","unique","forest","the","operation","failed","because","provided","for","addition","modification","wide"],"errorCode":"8648","eventId":"","severity":"High","summary":"The operation failed because the UPN value provided for addition/modification is not unique forest-wide.","rootCause":"This response is commonly caused by an issue with the operation's inputs or current system state. The exact cause depends on the application, API call, and operation that returned 8648; use the surrounding log entries to confirm it.","resolution":"1. Record where 8648 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to ERROR_DS_UPN_VALUE_NOT_UNIQUE_IN_FOREST.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 8648 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation failed because the UPN value provided for addition/modification is not unique forest-wide.\n\nLookup forms: 8648, 0x21C8, 0x000021C8, error 8648, ERROR_DS_UPN_VALUE_NOT_UNIQUE_IN_FOREST. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"Microsoft MS-ERREF 2.2 Win32 Error Codes","platforms":["windows"],"vendors":["Windows"],"technologies":["Win32 System Code","Windows","Windows / Win32 API"],"aliases":["8648"]},{"id":3057,"title":"CheckRemoteDebuggerPresent()","category":"PowerShell","product":"Windows Debugging API","tags":["Debugging Function","Windows API","Developer Reference"],"keywords":["CheckRemoteDebuggerPresent","CheckRemoteDebuggerPresent()","windows debugging","debugger","debug api","win32","developer troubleshooting","checks","the","specified","process","currently","being","debugged"],"errorCode":"","eventId":"","severity":"Low","summary":"Checks if the specified process is currently being debugged.","rootCause":"This is a Windows debugging reference function, not an error condition. It is used when inspecting, controlling, or communicating with a process under debugging.","resolution":"1. Confirm that CheckRemoteDebuggerPresent is appropriate for the debugging scenario.\n2. Review the process architecture, debugger permissions, and return status.\n3. Capture GetLastError details when the function reports failure.\n4. Validate behavior in a controlled test environment before production use.","emailScript":"Hello,\n\nWe are using the Windows debugging capability CheckRemoteDebuggerPresent() to gather more information about the application issue. This diagnostic step helps identify where the process is failing and does not normally require action from you.\n\nPlease let us know if the issue changes while testing is in progress.\n\nThank you,\n\nIT Support","faqSteps":"1. Leave the affected application open unless IT Support asks you to close it.\n2. Save your work before diagnostic testing begins.\n3. Tell IT Support if the application closes or behaves differently during testing.\n4. No additional action is required unless instructions are provided.","notes":"Function purpose from source: Checks if the specified process is currently being debugged.\n\nUse this as a debugging reference. No parameters or signatures are included because they were not present in the source document. Confirm current platform documentation before implementation.\n\nAdditional source detail (windows-win32-debug.pdf): CheckRemoteDebuggerPresent function\n(debugapi.h)\nArticle02/22/2024\nDetermines whether the specified process is being debugged.\nC++\n[in] hProcess\nA handle to the process.\n[in, out] pbDebuggerPresent\nA pointer to a variable that the function sets to TRUE if the specified process is being\ndebugged, or FALSE otherwise.\nIf the function succeeds, the return value is nonzero.\nIf the function fails, the return value is zero. To get extended error information, call\nGetLastError.\nThe \"remote\" in CheckRemoteDebuggerPresent does not imply that the debugger necessarily\nresides on a different computer; instead, it indicates that the debugger resides in a separate\nand parallel process. Use the IsDebuggerPresent function to detect whether the calling process\nis running under the debugger.\nSyntax\nBOOL CheckRemoteDebuggerPresent(\n [in] HANDLE hProcess,\n [in, out] PBOOL pbDebuggerPresent\n);\nParameters\nReturn value\nRemarks\nTo compile an application that uses this function, define the _WIN32_WINNT macro as 0x0501\nor later. For more information, see Using the Windows Headers.\nRequirement Value\nMinimum supported client Windows Vista, Windows XP with SP1 [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader debugapi.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nDebugging Functions\nIsDebuggerPresent\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows_debug_and_codes.txt; windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Debugging Function","Windows API","Developer Reference"],"aliases":[]},{"id":3058,"title":"ContinueDebugEvent()","category":"PowerShell","product":"Windows Debugging API","tags":["Debugging Function","Windows API","Developer Reference"],"keywords":["ContinueDebugEvent","ContinueDebugEvent()","windows debugging","debugger","debug api","win32","developer troubleshooting","allows","resume","thread","that","has","reported","debugging","event"],"errorCode":"","eventId":"","severity":"Low","summary":"Allows a debugger to resume a thread that has reported a debugging event.","rootCause":"This is a Windows debugging reference function, not an error condition. It is used when inspecting, controlling, or communicating with a process under debugging.","resolution":"1. Confirm that ContinueDebugEvent is appropriate for the debugging scenario.\n2. Review the process architecture, debugger permissions, and return status.\n3. Capture GetLastError details when the function reports failure.\n4. Validate behavior in a controlled test environment before production use.","emailScript":"Hello,\n\nWe are using the Windows debugging capability ContinueDebugEvent() to gather more information about the application issue. This diagnostic step helps identify where the process is failing and does not normally require action from you.\n\nPlease let us know if the issue changes while testing is in progress.\n\nThank you,\n\nIT Support","faqSteps":"1. Leave the affected application open unless IT Support asks you to close it.\n2. Save your work before diagnostic testing begins.\n3. Tell IT Support if the application closes or behaves differently during testing.\n4. No additional action is required unless instructions are provided.","notes":"Function purpose from source: Allows a debugger to resume a thread that has reported a debugging event.\n\nUse this as a debugging reference. No parameters or signatures are included because they were not present in the source document. Confirm current platform documentation before implementation.\n\nAdditional source detail (windows-win32-debug.pdf): ContinueDebugEvent function (debugapi.h)\nArticle10/13/2021\nEnables a debugger to continue a thread that previously reported a debugging event.\nC++\n[in] dwProcessId\nThe process identifier of the process to continue.\n[in] dwThreadId\nThe thread identifier of the thread to continue. The combination of process identifier and\nthread identifier must identify a thread that has previously reported a debugging event.\n[in] dwContinueStatus\nThe options to continue the thread that reported the debugging event.\nValue Meaning\nDBG_CONTINUE\n0x00010002L\nIf the thread specified by the dwThreadId parameter\npreviously reported an EXCEPTION_DEBUG_EVENT debugging\nevent, the function stops all exception processing and\ncontinues the thread and the exception is marked as handled.\nFor any other debugging event, this flag simply continues the\nthread.\nDBG_EXCEPTION_NOT_HANDLED\n0x80010001L\nIf the thread specified by dwThreadId previously reported an\nEXCEPTION_DEBUG_EVENT debugging event, the function\ncontinues exception processing. If this is a first-chance\nexception event, the search and dispatch logic of the\nSyntax\nBOOL ContinueDebugEvent(\n [in] DWORD dwProcessId,\n [in] DWORD dwThreadId,\n [in] DWORD dwContinueStatus\n);\nParameters\nﾉ Expand table\nstructured exception handler is used; otherwise, the process is\nterminated. For any other debugging event, this flag simply\ncontinues the thread.\nDBG_REPLY_LATER\n0x40010001L\nSupported in Windows 10, version 1507 or above, this flag\ncauses dwThreadId to replay the existing breaking event after\nthe target continues. By calling the SuspendThread API\nagainst dwThreadId, a debugger can resume other threads in\nthe process and later return to the breaking.\nIf the function succeeds, the return value is nonzero.\nIf the function fails, the return value is zero. To get extended error information, call\nGetLastError.\nOnly the thread that created dwProcessId with the CreateProcess function can call\nContinueDebugEvent.\nAfter the ContinueDebugEvent function succeeds, the specified thread continues. Depending\non the debugging event previously reported by the thread, different actions occur. If the\ncontinued thread previously reported an EXIT_THREAD_DEBUG_EVENT debugging event,\nContinueDebugEvent closes the handle the debugger has to the thread. If the continued\nthread previously reported an EXIT_PROCESS_DEBUG_EVENT debugging event,\nContinueDebugEvent closes the handles the debugger has to the process and to the thread.\nFor an example, see Writing the Debugger's Main Loop.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nReturn value\nRemarks\nExamples\nRequirements\nﾉ Expand table\nRequirement Value\nTarget Platform Windows\nHeader debugapi.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nCreateProcess\nDebugging Events\nDebugging Functions\nSee also","sourceDocument":"windows_debug_and_codes.txt; windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Debugging Function","Windows API","Developer Reference"],"aliases":[]},{"id":3059,"title":"DebugActiveProcess()","category":"PowerShell","product":"Windows Debugging API","tags":["Debugging Function","Windows API","Developer Reference"],"keywords":["DebugActiveProcess","DebugActiveProcess()","windows debugging","debugger","debug api","win32","developer troubleshooting","lets","attach","and","debug","active","process"],"errorCode":"","eventId":"","severity":"Low","summary":"Lets a debugger attach to and debug an active process.","rootCause":"This is a Windows debugging reference function, not an error condition. It is used when inspecting, controlling, or communicating with a process under debugging.","resolution":"1. Confirm that DebugActiveProcess is appropriate for the debugging scenario.\n2. Review the process architecture, debugger permissions, and return status.\n3. Capture GetLastError details when the function reports failure.\n4. Validate behavior in a controlled test environment before production use.","emailScript":"Hello,\n\nWe are using the Windows debugging capability DebugActiveProcess() to gather more information about the application issue. This diagnostic step helps identify where the process is failing and does not normally require action from you.\n\nPlease let us know if the issue changes while testing is in progress.\n\nThank you,\n\nIT Support","faqSteps":"1. Leave the affected application open unless IT Support asks you to close it.\n2. Save your work before diagnostic testing begins.\n3. Tell IT Support if the application closes or behaves differently during testing.\n4. No additional action is required unless instructions are provided.","notes":"Function purpose from source: Lets a debugger attach to and debug an active process.\n\nUse this as a debugging reference. No parameters or signatures are included because they were not present in the source document. Confirm current platform documentation before implementation.\n\nAdditional source detail (windows-win32-debug.pdf): DebugActiveProcess function (debugapi.h)\nArticle10/13/2021\nEnables a debugger to attach to an active process and debug it.\nC++\n[in] dwProcessId\nThe identifier for the process to be debugged. The debugger is granted debugging access to\nthe process as if it created the process with the DEBUG_ONLY_THIS_PROCESS flag. For more\ninformation, see the Remarks section of this topic.\nIf the function succeeds, the return value is nonzero.\nIf the function fails, the return value is 0 (zero). To get extended error information, call\nGetLastError.\nTo stop debugging the process, you must exit the process or call the DebugActiveProcessStop\nfunction. Exiting the debugger also exits the process unless you use the\nDebugSetProcessKillOnExit function.\nThe debugger must have appropriate access to the target process, and it must be able to open\nthe process for PROCESS_ALL_ACCESS. DebugActiveProcess can fail if the target process is\ncreated with a security descriptor that grants the debugger anything less than full access. If the\ndebugging process has the SE_DEBUG_NAME privilege granted and enabled, it can debug any\nprocess.\nSyntax\nBOOL DebugActiveProcess(\n [in] DWORD dwProcessId\n);\nParameters\nReturn value\nRemarks\nAfter the system checks the process identifier and determines that a valid debugging\nattachment is being made, the function returns TRUE. Then the debugger is expected to wait\nfor debugging events by using the WaitForDebugEvent function. The system suspends all\nthreads in the process, and sends the debugger events that represents the current state of the\nprocess.\nThe system sends the debugger a single CREATE_PROCESS_DEBUG_EVENT debugging event\nthat represents the process specified by the dwProcessId parameter. The lpStartAddress\nmember of the CREATE_PROCESS_DEBUG_INFO structure is NULL.\nFor each thread that is currently part of the process, the system sends a\nCREATE_THREAD_DEBUG_EVENT debugging event. The lpStartAddress member of the\nCREATE_THREAD_DEBUG_INFO structure is NULL.\nFor each dynamic-link library (DLL) that is currently loaded into the address space of the target\nprocess, the system sends a LOAD_DLL_DEBUG_EVENT debugging event. The system arranges\nfor the first thread in the process to execute a breakpoint instruction after it resumes.\nContinuing this thread causes it to return to doing the same thing as before the debugger is\nattached.\nAfter all of this is done, the system resumes all threads in the process. When the first thread in\nthe process resumes, it executes a breakpoint instruction that causes an\nEXCEPTION_DEBUG_EVENT debugging event to be sent to the debugger. All future debugging\nevents are sent to the debugger by using the normal mechanism and rules.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader debugapi.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nRequirements\nﾉ Expand table\nSee also\nCREATE_PROCESS_DEBUG_INFO\nCREATE_THREAD_DEBUG_INFO\nCreateProcess\nDebugActiveProcessStop\nDebugging Functions\nDebugging a Running Process\nWaitForDebugEvent","sourceDocument":"windows_debug_and_codes.txt; windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Debugging Function","Windows API","Developer Reference"],"aliases":[]},{"id":3060,"title":"DebugActiveProcessStop()","category":"PowerShell","product":"Windows Debugging API","tags":["Debugging Function","Windows API","Developer Reference"],"keywords":["DebugActiveProcessStop","DebugActiveProcessStop()","windows debugging","debugger","debug api","win32","developer troubleshooting","stops","the","from","debugging","given","process"],"errorCode":"","eventId":"","severity":"Low","summary":"Stops the debugger from debugging the given process.","rootCause":"This is a Windows debugging reference function, not an error condition. It is used when inspecting, controlling, or communicating with a process under debugging.","resolution":"1. Confirm that DebugActiveProcessStop is appropriate for the debugging scenario.\n2. Review the process architecture, debugger permissions, and return status.\n3. Capture GetLastError details when the function reports failure.\n4. Validate behavior in a controlled test environment before production use.","emailScript":"Hello,\n\nWe are using the Windows debugging capability DebugActiveProcessStop() to gather more information about the application issue. This diagnostic step helps identify where the process is failing and does not normally require action from you.\n\nPlease let us know if the issue changes while testing is in progress.\n\nThank you,\n\nIT Support","faqSteps":"1. Leave the affected application open unless IT Support asks you to close it.\n2. Save your work before diagnostic testing begins.\n3. Tell IT Support if the application closes or behaves differently during testing.\n4. No additional action is required unless instructions are provided.","notes":"Function purpose from source: Stops the debugger from debugging the given process.\n\nUse this as a debugging reference. No parameters or signatures are included because they were not present in the source document. Confirm current platform documentation before implementation.\n\nAdditional source detail (windows-win32-debug.pdf): DebugActiveProcessStop function\n(debugapi.h)\nArticle02/22/2024\nStops the debugger from debugging the specified process.\nC++\n[in] dwProcessId\nThe identifier of the process to stop debugging.\nIf the function succeeds, the return value is nonzero.\nIf the function fails, the return value is zero. To get extended error information, call\nGetLastError.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader debugapi.h (include Windows.h)\nSyntax\nBOOL DebugActiveProcessStop(\n [in] DWORD dwProcessId\n);\nParameters\nReturn value\nRequirements\nﾉ Expand table\nRequirement Value\nLibrary Kernel32.lib\nDLL Kernel32.dll\nDebugActiveProcess\nDebugging Functions\nDebugging a Running Process\nProcess Functions for Debugging\nSee also","sourceDocument":"windows_debug_and_codes.txt; windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Debugging Function","Windows API","Developer Reference"],"aliases":[]},{"id":3061,"title":"DebugBreak()","category":"PowerShell","product":"Windows Debugging API","tags":["Debugging Function","Windows API","Developer Reference"],"keywords":["DebugBreak","DebugBreak()","windows debugging","debugger","debug api","win32","developer troubleshooting","triggers","breakpoint","exception","the","current","process"],"errorCode":"","eventId":"","severity":"Low","summary":"Triggers a breakpoint exception in the current process.","rootCause":"This is a Windows debugging reference function, not an error condition. It is used when inspecting, controlling, or communicating with a process under debugging.","resolution":"1. Confirm that DebugBreak is appropriate for the debugging scenario.\n2. Review the process architecture, debugger permissions, and return status.\n3. Capture GetLastError details when the function reports failure.\n4. Validate behavior in a controlled test environment before production use.","emailScript":"Hello,\n\nWe are using the Windows debugging capability DebugBreak() to gather more information about the application issue. This diagnostic step helps identify where the process is failing and does not normally require action from you.\n\nPlease let us know if the issue changes while testing is in progress.\n\nThank you,\n\nIT Support","faqSteps":"1. Leave the affected application open unless IT Support asks you to close it.\n2. Save your work before diagnostic testing begins.\n3. Tell IT Support if the application closes or behaves differently during testing.\n4. No additional action is required unless instructions are provided.","notes":"Function purpose from source: Triggers a breakpoint exception in the current process.\n\nUse this as a debugging reference. No parameters or signatures are included because they were not present in the source document. Confirm current platform documentation before implementation.\n\nAdditional source detail (windows-win32-debug.pdf): DebugBreak function (debugapi.h)\n02/22/2024\nCauses a breakpoint exception to occur in the current process. This allows the calling thread to\nsignal the debugger to handle the exception.\nTo cause a breakpoint exception in another process, use the DebugBreakProcess function.\nC++\nNone\nIf the process is not being debugged, the function uses the search logic of a standard\nexception handler. In most cases, this causes the calling process to terminate because of an\nunhandled breakpoint exception.\nFor an example, see Using an Exception Handler.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nSyntax\nVOID DebugBreak();\nReturn value\nRemarks\nExamples\nRequirements\nﾉ Expand table\nRequirement Value\nHeader debugapi.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nCommunicating with the Debugger\nDebugActiveProcess\nDebugBreakProcess\nDebugging Functions\nSee also","sourceDocument":"windows_debug_and_codes.txt; windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Debugging Function","Windows API","Developer Reference"],"aliases":[]},{"id":3062,"title":"DebugBreakProcess()","category":"PowerShell","product":"Windows Debugging API","tags":["Debugging Function","Windows API","Developer Reference"],"keywords":["DebugBreakProcess","DebugBreakProcess()","windows debugging","debugger","debug api","win32","developer troubleshooting","triggers","breakpoint","exception","the","specified","process"],"errorCode":"","eventId":"","severity":"Low","summary":"Triggers a breakpoint exception in the specified process.","rootCause":"This is a Windows debugging reference function, not an error condition. It is used when inspecting, controlling, or communicating with a process under debugging.","resolution":"1. Confirm that DebugBreakProcess is appropriate for the debugging scenario.\n2. Review the process architecture, debugger permissions, and return status.\n3. Capture GetLastError details when the function reports failure.\n4. Validate behavior in a controlled test environment before production use.","emailScript":"Hello,\n\nWe are using the Windows debugging capability DebugBreakProcess() to gather more information about the application issue. This diagnostic step helps identify where the process is failing and does not normally require action from you.\n\nPlease let us know if the issue changes while testing is in progress.\n\nThank you,\n\nIT Support","faqSteps":"1. Leave the affected application open unless IT Support asks you to close it.\n2. Save your work before diagnostic testing begins.\n3. Tell IT Support if the application closes or behaves differently during testing.\n4. No additional action is required unless instructions are provided.","notes":"Function purpose from source: Triggers a breakpoint exception in the specified process.\n\nUse this as a debugging reference. No parameters or signatures are included because they were not present in the source document. Confirm current platform documentation before implementation.\n\nAdditional source detail (windows-win32-debug.pdf): DebugBreakProcess function (winbase.h)\nArticle02/22/2024\nCauses a breakpoint exception to occur in the specified process. This allows the calling thread\nto signal the debugger to handle the exception.\nC++\n[in] Process\nA handle to the process.\nIf the function succeeds, the return value is nonzero.\nIf the function fails, the return value is zero. To get extended error information, call\nGetLastError.\nIf the process is not being debugged, the function uses the search logic of a standard\nexception handler. In most cases, this causes the process to terminate because of an\nunhandled breakpoint exception.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nSyntax\nBOOL DebugBreakProcess(\n [in] HANDLE Process\n);\nParameters\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nRequirement Value\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader winbase.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nCommunicating with the Debugger\nDebugBreak\nDebugging Functions\nSee also","sourceDocument":"windows_debug_and_codes.txt; windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Debugging Function","Windows API","Developer Reference"],"aliases":[]},{"id":3063,"title":"DebugSetProcessKillOnExit()","category":"PowerShell","product":"Windows Debugging API","tags":["Debugging Function","Windows API","Developer Reference"],"keywords":["DebugSetProcessKillOnExit","DebugSetProcessKillOnExit()","windows debugging","debugger","debug api","win32","developer troubleshooting","defines","the","action","taken","when","calling","thread","exits"],"errorCode":"","eventId":"","severity":"Low","summary":"Defines the action taken when the calling thread exits.","rootCause":"This is a Windows debugging reference function, not an error condition. It is used when inspecting, controlling, or communicating with a process under debugging.","resolution":"1. Confirm that DebugSetProcessKillOnExit is appropriate for the debugging scenario.\n2. Review the process architecture, debugger permissions, and return status.\n3. Capture GetLastError details when the function reports failure.\n4. Validate behavior in a controlled test environment before production use.","emailScript":"Hello,\n\nWe are using the Windows debugging capability DebugSetProcessKillOnExit() to gather more information about the application issue. This diagnostic step helps identify where the process is failing and does not normally require action from you.\n\nPlease let us know if the issue changes while testing is in progress.\n\nThank you,\n\nIT Support","faqSteps":"1. Leave the affected application open unless IT Support asks you to close it.\n2. Save your work before diagnostic testing begins.\n3. Tell IT Support if the application closes or behaves differently during testing.\n4. No additional action is required unless instructions are provided.","notes":"Function purpose from source: Defines the action taken when the calling thread exits.\n\nUse this as a debugging reference. No parameters or signatures are included because they were not present in the source document. Confirm current platform documentation before implementation.\n\nAdditional source detail (windows-win32-debug.pdf): DebugSetProcessKillOnExit function\n(winbase.h)\nArticle02/22/2024\nSets the action to be performed when the calling thread exits.\nC++\n[in] KillOnExit\nIf this parameter is TRUE, the thread terminates all attached processes on exit (note that this is\nthe default). Otherwise, the thread detaches from all processes being debugged on exit.\nIf the function succeeds, the return value is nonzero.\nIf the function fails, the return value is zero. To get extended error information, call\nGetLastError.\nThe calling thread must have established at least one debugging connection using the\nCreateProcess or DebugActiveProcess function before calling this function.\nDebugSetProcessKillOnExit affects all current and future debuggees connected to the calling\nthread. A thread can call this function multiple times to change the action as needed.\nSyntax\nBOOL DebugSetProcessKillOnExit(\n [in] BOOL KillOnExit\n);\nParameters\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader winbase.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nDebugActiveProcessStop\nDebugging Functions\nSee also","sourceDocument":"windows_debug_and_codes.txt; windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Debugging Function","Windows API","Developer Reference"],"aliases":[]},{"id":3064,"title":"FatalExit()","category":"PowerShell","product":"Windows Debugging API","tags":["Debugging Function","Windows API","Developer Reference"],"keywords":["FatalExit","FatalExit()","windows debugging","debugger","debug api","win32","developer troubleshooting","transfers","control","the"],"errorCode":"","eventId":"","severity":"Low","summary":"Transfers control to the debugger.","rootCause":"This is a Windows debugging reference function, not an error condition. It is used when inspecting, controlling, or communicating with a process under debugging.","resolution":"1. Confirm that FatalExit is appropriate for the debugging scenario.\n2. Review the process architecture, debugger permissions, and return status.\n3. Capture GetLastError details when the function reports failure.\n4. Validate behavior in a controlled test environment before production use.","emailScript":"Hello,\n\nWe are using the Windows debugging capability FatalExit() to gather more information about the application issue. This diagnostic step helps identify where the process is failing and does not normally require action from you.\n\nPlease let us know if the issue changes while testing is in progress.\n\nThank you,\n\nIT Support","faqSteps":"1. Leave the affected application open unless IT Support asks you to close it.\n2. Save your work before diagnostic testing begins.\n3. Tell IT Support if the application closes or behaves differently during testing.\n4. No additional action is required unless instructions are provided.","notes":"Function purpose from source: Transfers control to the debugger.\n\nUse this as a debugging reference. No parameters or signatures are included because they were not present in the source document. Confirm current platform documentation before implementation.\n\nAdditional source detail (windows-win32-debug.pdf): FatalExit function (winbase.h)\nArticle02/22/2024\nTransfers execution control to the debugger. The behavior of the debugger thereafter is\nspecific to the type of debugger used.\nC++\n[in] ExitCode\nThe error code associated with the exit.\nThis function does not return a value.\nAn application should only use FatalExit for debugging purposes. It should not call the function\nin a retail version of the application because doing so will terminate the application.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nSyntax\n__analysis_noreturn VOID FatalExit(\n [in] int ExitCode\n);\nParameters\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nRequirement Value\nHeader winbase.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nCommunicating with the Debugger\nDebugging Functions\nFatalAppExit\nSee also","sourceDocument":"windows_debug_and_codes.txt; windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Debugging Function","Windows API","Developer Reference"],"aliases":[]},{"id":3065,"title":"FlushInstructionCache()","category":"PowerShell","product":"Windows Debugging API","tags":["Debugging Function","Windows API","Developer Reference"],"keywords":["FlushInstructionCache","FlushInstructionCache()","windows debugging","debugger","debug api","win32","developer troubleshooting","clears","the","instruction","cache","for","specified","process"],"errorCode":"","eventId":"","severity":"Low","summary":"Clears the instruction cache for the specified process.","rootCause":"This is a Windows debugging reference function, not an error condition. It is used when inspecting, controlling, or communicating with a process under debugging.","resolution":"1. Confirm that FlushInstructionCache is appropriate for the debugging scenario.\n2. Review the process architecture, debugger permissions, and return status.\n3. Capture GetLastError details when the function reports failure.\n4. Validate behavior in a controlled test environment before production use.","emailScript":"Hello,\n\nWe are using the Windows debugging capability FlushInstructionCache() to gather more information about the application issue. This diagnostic step helps identify where the process is failing and does not normally require action from you.\n\nPlease let us know if the issue changes while testing is in progress.\n\nThank you,\n\nIT Support","faqSteps":"1. Leave the affected application open unless IT Support asks you to close it.\n2. Save your work before diagnostic testing begins.\n3. Tell IT Support if the application closes or behaves differently during testing.\n4. No additional action is required unless instructions are provided.","notes":"Function purpose from source: Clears the instruction cache for the specified process.\n\nUse this as a debugging reference. No parameters or signatures are included because they were not present in the source document. Confirm current platform documentation before implementation.\n\nAdditional source detail (windows-win32-debug.pdf): FlushInstructionCache function\n(processthreadsapi.h)\n02/22/2024\nFlushes the instruction cache for the specified process.\nC++\n[in] hProcess\nA handle to a process whose instruction cache is to be flushed.\n[in] lpBaseAddress\nA pointer to the base of the region to be flushed. This parameter can be NULL.\n[in] dwSize\nThe size of the region to be flushed if the lpBaseAddress parameter is not NULL, in bytes.\nIf the function succeeds, the return value is nonzero.\nIf the function fails, the return value is zero. To get extended error information, call\nGetLastError.\nSyntax\nBOOL FlushInstructionCache(\n [in] HANDLE hProcess,\n [in] LPCVOID lpBaseAddress,\n [in] SIZE_T dwSize\n);\nParameters\nReturn value\nRemarks\nApplications should call FlushInstructionCache if they generate or modify code in memory. The\nCPU cannot detect the change, and may execute the old code it cached.\nRequirement Value\nMinimum supported client Windows XP [desktop apps | UWP apps]\nMinimum supported server Windows Server 2003 [desktop apps | UWP apps]\nTarget Platform Windows\nHeader processthreadsapi.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nDebugging Functions\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows_debug_and_codes.txt; windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Debugging Function","Windows API","Developer Reference"],"aliases":[]},{"id":3066,"title":"GetThreadContext()","category":"PowerShell","product":"Windows Debugging API","tags":["Debugging Function","Windows API","Developer Reference"],"keywords":["GetThreadContext","GetThreadContext()","windows debugging","debugger","debug api","win32","developer troubleshooting","obtains","the","context","specified","thread"],"errorCode":"","eventId":"","severity":"Low","summary":"Obtains the context of the specified thread.","rootCause":"This is a Windows debugging reference function, not an error condition. It is used when inspecting, controlling, or communicating with a process under debugging.","resolution":"1. Confirm that GetThreadContext is appropriate for the debugging scenario.\n2. Review the process architecture, debugger permissions, and return status.\n3. Capture GetLastError details when the function reports failure.\n4. Validate behavior in a controlled test environment before production use.","emailScript":"Hello,\n\nWe are using the Windows debugging capability GetThreadContext() to gather more information about the application issue. This diagnostic step helps identify where the process is failing and does not normally require action from you.\n\nPlease let us know if the issue changes while testing is in progress.\n\nThank you,\n\nIT Support","faqSteps":"1. Leave the affected application open unless IT Support asks you to close it.\n2. Save your work before diagnostic testing begins.\n3. Tell IT Support if the application closes or behaves differently during testing.\n4. No additional action is required unless instructions are provided.","notes":"Function purpose from source: Obtains the context of the specified thread.\n\nUse this as a debugging reference. No parameters or signatures are included because they were not present in the source document. Confirm current platform documentation before implementation.\n\nAdditional source detail (windows-win32-debug.pdf): GetThreadContext function\n(processthreadsapi.h)\n06/17/2025\nRetrieves the context of the specified thread.\nC++\n[in] hThread\nA handle to the thread whose context is to be retrieved. The handle must have\nTHREAD_GET_CONTEXT access to the thread. For more information, see Thread Security and\nAccess Rights.\nWindows XP or Windows Server 2003: The handle must also have\nTHREAD_QUERY_INFORMATION access.\n[in, out] lpContext\nA pointer to a CONTEXT structure (such as ARM64_NT_CONTEXT) that receives the appropriate\ncontext of the specified thread. The value of the ContextFlags member of this structure\nspecifies which portions of a thread's context are retrieved. The CONTEXT structure is highly\nprocessor specific. Refer to the WinNT.h header file for processor-specific definitions of this\nstructures and any alignment requirements.\n７ Note\nA 64-bit application can retrieve the context of a WOW64 thread using the\nWow64GetThreadContext function.\nSyntax\nBOOL GetThreadContext(\n [in] HANDLE hThread,\n [in, out] LPCONTEXT lpContext\n);\nParameters\nIf the function succeeds, the return value is nonzero.\nIf the function fails, the return value is zero. To get extended error information, call\nGetLastError.\nThis function is used to retrieve the thread context of the specified thread. The function\nretrieves a selective context based on the value of the ContextFlags member of the context\nstructure. The thread identified by the hThread parameter is typically being debugged, but the\nfunction can also operate when the thread is not being debugged.\nYou cannot get a valid context for a running thread. Use the SuspendThread function to\nsuspend the thread before calling GetThreadContext.\nIf you call GetThreadContext for the current thread, the function returns successfully; however,\nthe context returned is not valid.\nRequirement Value\nMinimum supported client Windows XP [desktop apps | UWP apps]\nMinimum supported server Windows Server 2003 [desktop apps | UWP apps]\nTarget Platform Windows\nHeader processthreadsapi.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nCONTEXT\nARM64_NT_CONTEXT\nDebugging Functions\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nSee also\nGetXStateFeaturesMask\nSetThreadContext\nSuspendThread\nWow64GetThreadContext","sourceDocument":"windows_debug_and_codes.txt; windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Debugging Function","Windows API","Developer Reference"],"aliases":[]},{"id":3067,"title":"GetThreadSelectorEntry()","category":"PowerShell","product":"Windows Debugging API","tags":["Debugging Function","Windows API","Developer Reference"],"keywords":["GetThreadSelectorEntry","GetThreadSelectorEntry()","windows debugging","debugger","debug api","win32","developer troubleshooting","retrieves","descriptor","table","entry","for","given","selector","and","thread"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves a descriptor table entry for a given selector and thread.","rootCause":"This is a Windows debugging reference function, not an error condition. It is used when inspecting, controlling, or communicating with a process under debugging.","resolution":"1. Confirm that GetThreadSelectorEntry is appropriate for the debugging scenario.\n2. Review the process architecture, debugger permissions, and return status.\n3. Capture GetLastError details when the function reports failure.\n4. Validate behavior in a controlled test environment before production use.","emailScript":"Hello,\n\nWe are using the Windows debugging capability GetThreadSelectorEntry() to gather more information about the application issue. This diagnostic step helps identify where the process is failing and does not normally require action from you.\n\nPlease let us know if the issue changes while testing is in progress.\n\nThank you,\n\nIT Support","faqSteps":"1. Leave the affected application open unless IT Support asks you to close it.\n2. Save your work before diagnostic testing begins.\n3. Tell IT Support if the application closes or behaves differently during testing.\n4. No additional action is required unless instructions are provided.","notes":"Function purpose from source: Retrieves a descriptor table entry for a given selector and thread.\n\nUse this as a debugging reference. No parameters or signatures are included because they were not present in the source document. Confirm current platform documentation before implementation.\n\nAdditional source detail (windows-win32-debug.pdf): GetThreadSelectorEntry function\n(winbase.h)\n02/22/2024\nRetrieves a descriptor table entry for the specified selector and thread.\nC++\n[in] hThread\nA handle to the thread containing the specified selector. The handle must have\nTHREAD_QUERY_INFORMATION access. For more information, see Thread Security and Access\nRights.\n[in] dwSelector\nThe global or local selector value to look up in the thread's descriptor tables.\n[out] lpSelectorEntry\nA pointer to an LDT_ENTRY structure that receives a copy of the descriptor table entry if the\nspecified selector has an entry in the specified thread's descriptor table. This information can\nbe used to convert a segment-relative address to a linear virtual address.\nIf the function succeeds, the return value is nonzero. In that case, the structure pointed to by\nthe lpSelectorEntry parameter receives a copy of the specified descriptor table entry.\nIf the function fails, the return value is zero. To get extended error information, call\nGetLastError.\nSyntax\nBOOL GetThreadSelectorEntry(\n [in] HANDLE hThread,\n [in] DWORD dwSelector,\n [out] LPLDT_ENTRY lpSelectorEntry\n);\nParameters\nReturn value\nGetThreadSelectorEntry is only functional on x86-based systems. For systems that are not x86based, the function returns FALSE.\nDebuggers use this function to convert segment-relative addresses to linear virtual addresses.\nThe ReadProcessMemory and WriteProcessMemory functions use linear virtual addresses.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader winbase.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nDebugging Functions\nLDT_ENTRY\nReadProcessMemory\nWriteProcessMemory\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows_debug_and_codes.txt; windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Debugging Function","Windows API","Developer Reference"],"aliases":[]},{"id":3068,"title":"IsDebuggerPresent()","category":"PowerShell","product":"Windows Debugging API","tags":["Debugging Function","Windows API","Developer Reference"],"keywords":["IsDebuggerPresent","IsDebuggerPresent()","windows debugging","debugger","debug api","win32","developer troubleshooting","checks","the","calling","process","being","debugged","user","mode"],"errorCode":"","eventId":"","severity":"Low","summary":"Checks if the calling process is being debugged by a user-mode debugger.","rootCause":"This is a Windows debugging reference function, not an error condition. It is used when inspecting, controlling, or communicating with a process under debugging.","resolution":"1. Confirm that IsDebuggerPresent is appropriate for the debugging scenario.\n2. Review the process architecture, debugger permissions, and return status.\n3. Capture GetLastError details when the function reports failure.\n4. Validate behavior in a controlled test environment before production use.","emailScript":"Hello,\n\nWe are using the Windows debugging capability IsDebuggerPresent() to gather more information about the application issue. This diagnostic step helps identify where the process is failing and does not normally require action from you.\n\nPlease let us know if the issue changes while testing is in progress.\n\nThank you,\n\nIT Support","faqSteps":"1. Leave the affected application open unless IT Support asks you to close it.\n2. Save your work before diagnostic testing begins.\n3. Tell IT Support if the application closes or behaves differently during testing.\n4. No additional action is required unless instructions are provided.","notes":"Function purpose from source: Checks if the calling process is being debugged by a user-mode debugger.\n\nUse this as a debugging reference. No parameters or signatures are included because they were not present in the source document. Confirm current platform documentation before implementation.\n\nAdditional source detail (windows-win32-debug.pdf): IsDebuggerPresent function (debugapi.h)\nArticle02/12/2025\nDetermines whether the calling process is being debugged by a user-mode debugger.\nC++\nIf the current process is running in the context of a debugger, the return value is nonzero.\nIf the current process is not running in the context of a debugger, the return value is zero.\nThis function allows an application to determine whether or not it is being debugged, so that it\ncan modify its behavior. For example, an application could provide additional information\nusing the OutputDebugString function if it is being debugged.\nTo determine whether a remote process is being debugged, use the\nCheckRemoteDebuggerPresent function.\nRequirement Value\nMinimum supported client Windows NT Workstation 4.0 [desktop apps | UWP apps]\nMinimum supported server Windows NT Server 4.0 [desktop apps | UWP apps]\nTarget Platform Windows\nHeader debugapi.h (include Windows.h)\nLibrary Kernel32.lib\nSyntax\nBOOL IsDebuggerPresent();\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nRequirement Value\nDLL Kernel32.dll\nCheckRemoteDebuggerPresent\nDebugging Functions\nOutputDebugString\nSee also","sourceDocument":"windows_debug_and_codes.txt; windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Debugging Function","Windows API","Developer Reference"],"aliases":[]},{"id":3069,"title":"OutputDebugString()","category":"PowerShell","product":"Windows Debugging API","tags":["Debugging Function","Windows API","Developer Reference"],"keywords":["OutputDebugString","OutputDebugString()","windows debugging","debugger","debug api","win32","developer troubleshooting","sends","string","the","for","display","purposes"],"errorCode":"","eventId":"","severity":"Low","summary":"Sends a string to the debugger for display purposes.","rootCause":"This is a Windows debugging reference function, not an error condition. It is used when inspecting, controlling, or communicating with a process under debugging.","resolution":"1. Confirm that OutputDebugString is appropriate for the debugging scenario.\n2. Review the process architecture, debugger permissions, and return status.\n3. Capture GetLastError details when the function reports failure.\n4. Validate behavior in a controlled test environment before production use.","emailScript":"Hello,\n\nWe are using the Windows debugging capability OutputDebugString() to gather more information about the application issue. This diagnostic step helps identify where the process is failing and does not normally require action from you.\n\nPlease let us know if the issue changes while testing is in progress.\n\nThank you,\n\nIT Support","faqSteps":"1. Leave the affected application open unless IT Support asks you to close it.\n2. Save your work before diagnostic testing begins.\n3. Tell IT Support if the application closes or behaves differently during testing.\n4. No additional action is required unless instructions are provided.","notes":"Function purpose from source: Sends a string to the debugger for display purposes.\n\nUse this as a debugging reference. No parameters or signatures are included because they were not present in the source document. Confirm current platform documentation before implementation.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Debugging Function","Windows API","Developer Reference"],"aliases":[]},{"id":3070,"title":"ReadProcessMemory()","category":"PowerShell","product":"Windows Debugging API","tags":["Debugging Function","Windows API","Developer Reference"],"keywords":["ReadProcessMemory","ReadProcessMemory()","windows debugging","debugger","debug api","win32","developer troubleshooting","reads","data","from","memory","area","specified","process"],"errorCode":"","eventId":"","severity":"Low","summary":"Reads data from a memory area in a specified process.","rootCause":"This is a Windows debugging reference function, not an error condition. It is used when inspecting, controlling, or communicating with a process under debugging.","resolution":"1. Confirm that ReadProcessMemory is appropriate for the debugging scenario.\n2. Review the process architecture, debugger permissions, and return status.\n3. Capture GetLastError details when the function reports failure.\n4. Validate behavior in a controlled test environment before production use.","emailScript":"Hello,\n\nWe are using the Windows debugging capability ReadProcessMemory() to gather more information about the application issue. This diagnostic step helps identify where the process is failing and does not normally require action from you.\n\nPlease let us know if the issue changes while testing is in progress.\n\nThank you,\n\nIT Support","faqSteps":"1. Leave the affected application open unless IT Support asks you to close it.\n2. Save your work before diagnostic testing begins.\n3. Tell IT Support if the application closes or behaves differently during testing.\n4. No additional action is required unless instructions are provided.","notes":"Function purpose from source: Reads data from a memory area in a specified process.\n\nUse this as a debugging reference. No parameters or signatures are included because they were not present in the source document. Confirm current platform documentation before implementation.\n\nAdditional source detail (windows-win32-debug.pdf): ReadProcessMemory function\n(memoryapi.h)\n05/14/2022\nC++\n[in] hProcess\nA handle to the process with memory that is being read. The handle must have\nPROCESS_VM_READ access to the process.\n[in] lpBaseAddress\nA pointer to the base address in the specified process from which to read. Before any data\ntransfer occurs, the system verifies that all data in the base address and memory of the\nspecified size is accessible for read access, and if it is not accessible the function fails.\n[out] lpBuffer\nA pointer to a buffer that receives the contents from the address space of the specified\nprocess.\n[in] nSize\nThe number of bytes to be read from the specified process.\n[out] lpNumberOfBytesRead\nA pointer to a variable that receives the number of bytes transferred into the specified buffer. If\nlpNumberOfBytesRead is NULL, the parameter is ignored.\nSyntax\nBOOL ReadProcessMemory(\n [in] HANDLE hProcess,\n [in] LPCVOID lpBaseAddress,\n [out] LPVOID lpBuffer,\n [in] SIZE_T nSize,\n [out] SIZE_T *lpNumberOfBytesRead\n);\nParameters\nIf the function succeeds, the return value is nonzero.\nIf the function fails, the return value is 0 (zero). To get extended error information, call\nGetLastError.\nThe function fails if the requested read operation crosses into an area of the process that is\ninaccessible.\nReadProcessMemory copies the data in the specified address range from the address space of\nthe specified process into the specified buffer of the current process. Any process that has a\nhandle with PROCESS_VM_READ access can call the function.\nThe entire area to be read must be accessible, and if it is not accessible, the function fails.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader memoryapi.h (include Windows.h)\nLibrary onecore.lib\nDLL Kernel32.dll\nDebugging Functions, OpenProcess, Process Functions for Debugging, VirtualAllocEx,\nWriteProcessMemory\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows_debug_and_codes.txt; windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Debugging Function","Windows API","Developer Reference"],"aliases":[]},{"id":3071,"title":"SetThreadContext()","category":"PowerShell","product":"Windows Debugging API","tags":["Debugging Function","Windows API","Developer Reference"],"keywords":["SetThreadContext","SetThreadContext()","windows debugging","debugger","debug api","win32","developer troubleshooting","sets","the","context","for","specified","thread"],"errorCode":"","eventId":"","severity":"Low","summary":"Sets the context for a specified thread.","rootCause":"This is a Windows debugging reference function, not an error condition. It is used when inspecting, controlling, or communicating with a process under debugging.","resolution":"1. Confirm that SetThreadContext is appropriate for the debugging scenario.\n2. Review the process architecture, debugger permissions, and return status.\n3. Capture GetLastError details when the function reports failure.\n4. Validate behavior in a controlled test environment before production use.","emailScript":"Hello,\n\nWe are using the Windows debugging capability SetThreadContext() to gather more information about the application issue. This diagnostic step helps identify where the process is failing and does not normally require action from you.\n\nPlease let us know if the issue changes while testing is in progress.\n\nThank you,\n\nIT Support","faqSteps":"1. Leave the affected application open unless IT Support asks you to close it.\n2. Save your work before diagnostic testing begins.\n3. Tell IT Support if the application closes or behaves differently during testing.\n4. No additional action is required unless instructions are provided.","notes":"Function purpose from source: Sets the context for a specified thread.\n\nUse this as a debugging reference. No parameters or signatures are included because they were not present in the source document. Confirm current platform documentation before implementation.\n\nAdditional source detail (windows-win32-debug.pdf): SetThreadContext function\n(processthreadsapi.h)\n06/17/2025\nSets the context for the specified thread.\nC++\n[in] hThread\nA handle to the thread whose context is to be set. The handle must have the\nTHREAD_SET_CONTEXT access right to the thread. For more information, see Thread Security\nand Access Rights.\n[in] lpContext\nA pointer to a CONTEXT structure that contains the context to be set in the specified thread.\nThe value of the ContextFlags member of this structure specifies which portions of a thread's\ncontext to set. Some values in the CONTEXT structure that cannot be specified are silently set\nto the correct value. This includes bits in the CPU status register that specify the privileged\nprocessor mode, global enabling bits in the debugging register, and other states that must be\ncontrolled by the operating system.\n７ Note\nA 64-bit application can set the context of a WOW64 thread using the\nWow64SetThreadContext function.\nSyntax\nBOOL SetThreadContext(\n [in] HANDLE hThread,\n [in] const CONTEXT *lpContext\n);\nParameters\nReturn value\nIf the context was set, the return value is nonzero.\nIf the function fails, the return value is zero. To get extended error information, call\nGetLastError.\nThe function sets the thread context based on the value of the ContextFlags member of the\ncontext structure. The thread identified by the hThread parameter is typically being debugged,\nbut the function can also operate even when the thread is not being debugged.\nDo not try to set the context for a running thread; the results are unpredictable. Use the\nSuspendThread function to suspend the thread before calling SetThreadContext.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader processthreadsapi.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nCONTEXT\nDebugging Functions\nGetThreadContext\nGetXStateFeaturesMask\nSetXStateFeaturesMask\nSuspendThread\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows_debug_and_codes.txt; windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Debugging Function","Windows API","Developer Reference"],"aliases":[]},{"id":3072,"title":"WaitForDebugEvent()","category":"PowerShell","product":"Windows Debugging API","tags":["Debugging Function","Windows API","Developer Reference"],"keywords":["WaitForDebugEvent","WaitForDebugEvent()","windows debugging","debugger","debug api","win32","developer troubleshooting","waits","for","debugging","event","occur","debugged","process"],"errorCode":"","eventId":"","severity":"Low","summary":"Waits for a debugging event to occur in a debugged process.","rootCause":"This is a Windows debugging reference function, not an error condition. It is used when inspecting, controlling, or communicating with a process under debugging.","resolution":"1. Confirm that WaitForDebugEvent is appropriate for the debugging scenario.\n2. Review the process architecture, debugger permissions, and return status.\n3. Capture GetLastError details when the function reports failure.\n4. Validate behavior in a controlled test environment before production use.","emailScript":"Hello,\n\nWe are using the Windows debugging capability WaitForDebugEvent() to gather more information about the application issue. This diagnostic step helps identify where the process is failing and does not normally require action from you.\n\nPlease let us know if the issue changes while testing is in progress.\n\nThank you,\n\nIT Support","faqSteps":"1. Leave the affected application open unless IT Support asks you to close it.\n2. Save your work before diagnostic testing begins.\n3. Tell IT Support if the application closes or behaves differently during testing.\n4. No additional action is required unless instructions are provided.","notes":"Function purpose from source: Waits for a debugging event to occur in a debugged process.\n\nUse this as a debugging reference. No parameters or signatures are included because they were not present in the source document. Confirm current platform documentation before implementation.\n\nAdditional source detail (windows-win32-debug.pdf): WaitForDebugEvent function (debugapi.h)\nArticle07/27/2022\nWaits for a debugging event to occur in a process being debugged.\n \nC++\n[out] lpDebugEvent\nA pointer to a DEBUG_EVENT structure that receives information about the debugging event.\n[in] dwMilliseconds\nThe number of milliseconds to wait for a debugging event. If this parameter is zero, the\nfunction tests for a debugging event and returns immediately. If the parameter is INFINITE, the\nfunction does not return until a debugging event has occurred.\nIf the function succeeds, the return value is nonzero.\nIf the function fails, the return value is zero. To get extended error information, call\nGetLastError.\nImportant In the past, the operating system did not output Unicode strings via\nOutputDebugStringW and instead only output ASCII strings. To force\nOutputDebugStringW to correctly output Unicode strings, debuggers are required to call\nWaitForDebugEventEx to opt into the new behavior. On calling WaitForDebugEventEx,\nthe operating system will know that the debugger supports Unicode and is specifically\nopting into receiving Unicode strings.\nSyntax\nBOOL WaitForDebugEvent(\n [out] LPDEBUG_EVENT lpDebugEvent,\n [in] DWORD dwMilliseconds\n);\nParameters\nReturn value\nOnly the thread that created the process being debugged can call WaitForDebugEvent.\nWhen a CREATE_PROCESS_DEBUG_EVENT occurs, the debugger application receives a handle\nto the image file of the process being debugged, a handle to the process being debugged, and\na handle to the initial thread of the process being debugged in the DEBUG_EVENT structure.\nThe members these handles are returned in are u.CreateProcessInfo.hFile (image file),\nu.CreateProcessInfo.hProcess (process), and u.CreateProcessInfo.hThread (initial thread). If the\nsystem previously reported an EXIT_PROCESS_DEBUG_EVENT debugging event, the system\ncloses the handles to the process and thread when the debugger calls the\nContinueDebugEvent function. The debugger should close the handle to the image file by\ncalling the CloseHandle function.\nSimilarly, when a CREATE_THREAD_DEBUG_EVENT occurs, the debugger application receives a\nhandle to the thread whose creation caused the debugging event in the\nu.CreateThread.hThread member of the DEBUG_EVENT structure. If the system previously\nreported an EXIT_THREAD_DEBUG_EVENT debugging event, the system closes the handles to\nthe thread when the debugger calls the ContinueDebugEvent function.\nWhen a LOAD_DLL_DEBUG_EVENT occurs, the debugger application receives a handle to the\nloaded DLL in the u.LoadDll.hFile member of the DEBUG_EVENT structure. This handle should\nbe closed by the debugger application by calling the CloseHandle function.\n \nFor an example, see Writing the Debugger's Main Loop.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nRemarks\nWarning Do not queue an asynchronous procedure call (APC) to a thread that calls\nWaitForDebugEvent.\nExamples\nRequirements\nﾉ Expand table\nRequirement Value\nTarget Platform Windows\nHeader debugapi.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nContinueDebugEvent\nDEBUG_EVENT\nDebugActiveProcess\nDebugBreak\nDebugging Events\nDebugging Functions\nOutputDebugString\nSee also","sourceDocument":"windows_debug_and_codes.txt; windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Debugging Function","Windows API","Developer Reference"],"aliases":[]},{"id":3073,"title":"WaitForDebugEventEx()","category":"PowerShell","product":"Windows Debugging API","tags":["Debugging Function","Windows API","Developer Reference"],"keywords":["WaitForDebugEventEx","WaitForDebugEventEx()","windows debugging","debugger","debug api","win32","developer troubleshooting","waits","for","debugging","event","debugged","process","and","supports","unicode","strings","from","outputdebugstringw"],"errorCode":"","eventId":"","severity":"Low","summary":"Waits for a debugging event in a debugged process and supports Unicode strings from OutputDebugStringW.","rootCause":"This is a Windows debugging reference function, not an error condition. It is used when inspecting, controlling, or communicating with a process under debugging.","resolution":"1. Confirm that WaitForDebugEventEx is appropriate for the debugging scenario.\n2. Review the process architecture, debugger permissions, and return status.\n3. Capture GetLastError details when the function reports failure.\n4. Validate behavior in a controlled test environment before production use.","emailScript":"Hello,\n\nWe are using the Windows debugging capability WaitForDebugEventEx() to gather more information about the application issue. This diagnostic step helps identify where the process is failing and does not normally require action from you.\n\nPlease let us know if the issue changes while testing is in progress.\n\nThank you,\n\nIT Support","faqSteps":"1. Leave the affected application open unless IT Support asks you to close it.\n2. Save your work before diagnostic testing begins.\n3. Tell IT Support if the application closes or behaves differently during testing.\n4. No additional action is required unless instructions are provided.","notes":"Function purpose from source: Waits for a debugging event in a debugged process and supports Unicode strings from OutputDebugStringW.\n\nUse this as a debugging reference. No parameters or signatures are included because they were not present in the source document. Confirm current platform documentation before implementation.\n\nAdditional source detail (windows-win32-debug.pdf): WaitForDebugEventEx function\n(debugapi.h)\nArticle07/27/2022\nWaits for a debugging event to occur in a process being debugged.\n \nC++\n[out] lpDebugEvent\nA pointer to a DEBUG_EVENT structure that receives information about the debugging event.\n[in] dwMilliseconds\nThe number of milliseconds to wait for a debugging event. If this parameter is zero, the\nfunction tests for a debugging event and returns immediately. If the parameter is INFINITE, the\nfunction does not return until a debugging event has occurred.\nIf the function succeeds, the return value is nonzero.\nImportant In the past, the operating system did not output Unicode strings via\nOutputDebugStringW and instead only output ASCII strings. To force\nOutputDebugStringW to correctly output Unicode strings, debuggers are required to call\nWaitForDebugEventEx to opt into the new behavior. On calling WaitForDebugEventEx,\nthe operating system will know that the debugger supports Unicode and is specifically\nopting into receiving Unicode strings.\nSyntax\nBOOL WaitForDebugEventEx(\n [out] LPDEBUG_EVENT lpDebugEvent,\n [in] DWORD dwMilliseconds\n);\nParameters\nReturn value\nIf the function fails, the return value is zero. To get extended error information, call\nGetLastError.\nOnly the thread that created the process being debugged can call WaitForDebugEventEx.\nWhen a CREATE_PROCESS_DEBUG_EVENT occurs, the debugger application receives a handle\nto the image file of the process being debugged, a handle to the process being debugged, and\na handle to the initial thread of the process being debugged in the DEBUG_EVENT structure.\nThe members these handles are returned in are u.CreateProcessInfo.hFile (image file),\nu.CreateProcessInfo.hProcess (process), and u.CreateProcessInfo.hThread (initial thread). If the\nsystem previously reported an EXIT_PROCESS_DEBUG_EVENT debugging event, the system\ncloses the handles to the process and thread when the debugger calls the\nContinueDebugEvent function. The debugger should close the handle to the image file by\ncalling the CloseHandle function.\nSimilarly, when a CREATE_THREAD_DEBUG_EVENT occurs, the debugger application receives a\nhandle to the thread whose creation caused the debugging event in the\nu.CreateThread.hThread member of the DEBUG_EVENT structure. If the system previously\nreported an EXIT_THREAD_DEBUG_EVENT debugging event, the system closes the handles to\nthe thread when the debugger calls the ContinueDebugEvent function.\nWhen a LOAD_DLL_DEBUG_EVENT occurs, the debugger application receives a handle to the\nloaded DLL in the u.LoadDll.hFile member of the DEBUG_EVENT structure. This handle should\nbe closed by the debugger application by calling the CloseHandle function.\n \nFor an example, see Writing the Debugger's Main Loop.\nRemarks\nWarning Do not queue an asynchronous procedure call (APC) to a thread that calls\nWaitForDebugEventEx.\nExamples\nRequirements\nﾉ Expand table\nRequirement Value\nMinimum supported client Windows 10 [desktop apps only]\nMinimum supported server Windows Server 2016 [desktop apps only]\nTarget Platform Windows\nHeader debugapi.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nContinueDebugEvent\nDEBUG_EVENT\nDebugActiveProcess\nDebugBreak\nDebugging Events\nDebugging Functions\nOutputDebugString\nSee also","sourceDocument":"windows_debug_and_codes.txt; windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Debugging Function","Windows API","Developer Reference"],"aliases":[]},{"id":3074,"title":"Wow64GetThreadContext()","category":"PowerShell","product":"Windows Debugging API","tags":["Debugging Function","Windows API","Developer Reference"],"keywords":["Wow64GetThreadContext","Wow64GetThreadContext()","windows debugging","debugger","debug api","win32","developer troubleshooting","retrieves","the","context","specified","wow64","thread"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the context of a specified WOW64 thread.","rootCause":"This is a Windows debugging reference function, not an error condition. It is used when inspecting, controlling, or communicating with a process under debugging.","resolution":"1. Confirm that Wow64GetThreadContext is appropriate for the debugging scenario.\n2. Review the process architecture, debugger permissions, and return status.\n3. Capture GetLastError details when the function reports failure.\n4. Validate behavior in a controlled test environment before production use.","emailScript":"Hello,\n\nWe are using the Windows debugging capability Wow64GetThreadContext() to gather more information about the application issue. This diagnostic step helps identify where the process is failing and does not normally require action from you.\n\nPlease let us know if the issue changes while testing is in progress.\n\nThank you,\n\nIT Support","faqSteps":"1. Leave the affected application open unless IT Support asks you to close it.\n2. Save your work before diagnostic testing begins.\n3. Tell IT Support if the application closes or behaves differently during testing.\n4. No additional action is required unless instructions are provided.","notes":"Function purpose from source: Retrieves the context of a specified WOW64 thread.\n\nUse this as a debugging reference. No parameters or signatures are included because they were not present in the source document. Confirm current platform documentation before implementation.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Debugging Function","Windows API","Developer Reference"],"aliases":[]},{"id":3075,"title":"Wow64GetThreadSelectorEntry()","category":"PowerShell","product":"Windows Debugging API","tags":["Debugging Function","Windows API","Developer Reference"],"keywords":["Wow64GetThreadSelectorEntry","Wow64GetThreadSelectorEntry()","windows debugging","debugger","debug api","win32","developer troubleshooting","retrieves","descriptor","table","entry","for","selector","and","wow64","thread"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves a descriptor table entry for a selector and WOW64 thread.","rootCause":"This is a Windows debugging reference function, not an error condition. It is used when inspecting, controlling, or communicating with a process under debugging.","resolution":"1. Confirm that Wow64GetThreadSelectorEntry is appropriate for the debugging scenario.\n2. Review the process architecture, debugger permissions, and return status.\n3. Capture GetLastError details when the function reports failure.\n4. Validate behavior in a controlled test environment before production use.","emailScript":"Hello,\n\nWe are using the Windows debugging capability Wow64GetThreadSelectorEntry() to gather more information about the application issue. This diagnostic step helps identify where the process is failing and does not normally require action from you.\n\nPlease let us know if the issue changes while testing is in progress.\n\nThank you,\n\nIT Support","faqSteps":"1. Leave the affected application open unless IT Support asks you to close it.\n2. Save your work before diagnostic testing begins.\n3. Tell IT Support if the application closes or behaves differently during testing.\n4. No additional action is required unless instructions are provided.","notes":"Function purpose from source: Retrieves a descriptor table entry for a selector and WOW64 thread.\n\nUse this as a debugging reference. No parameters or signatures are included because they were not present in the source document. Confirm current platform documentation before implementation.\n\nAdditional source detail (windows-win32-debug.pdf): Wow64GetThreadSelectorEntry function\n(winbase.h)\nArticle02/22/2024\nRetrieves a descriptor table entry for the specified selector and WOW64 thread.\nC++\n[in] hThread\nA handle to the thread containing the specified selector. The handle must have been created\nwith THREAD_QUERY_INFORMATION access to the thread. For more information, see Thread\nSecurity and Access Rights.\n[in] dwSelector\nThe global or local selector value to look up in the thread's descriptor tables.\n[out] lpSelectorEntry\nA pointer to a WOW64_LDT_ENTRY structure that receives a copy of the descriptor table entry\nif the specified selector has an entry in the specified thread's descriptor table. This information\ncan be used to convert a segment-relative address to a linear virtual address.\nIf the function succeeds, the return value is nonzero. In that case, the structure pointed to by\nthe lpSelectorEntry parameter receives a copy of the specified descriptor table entry.\nIf the function fails, the return value is zero. To get extended error information, call\nGetLastError.\nSyntax\nBOOL Wow64GetThreadSelectorEntry(\n [in] HANDLE hThread,\n [in] DWORD dwSelector,\n [out] PWOW64_LDT_ENTRY lpSelectorEntry\n);\nParameters\nReturn value\nThe Wow64GetThreadSelectorEntry function is functional only on 64-bit systems and can be\ncalled only by 64-bit processes. If this function is called by a 32-bit process, the function fails\nwith ERROR_NOT_SUPPORTED. A 32-bit process should use the GetThreadSelectorEntry\nfunction instead.\nDebuggers use this function to convert segment-relative addresses to linear virtual addresses.\nThe ReadProcessMemory and WriteProcessMemory functions use linear virtual addresses.\nRequirement Value\nMinimum supported client Windows 7 [desktop apps only]\nMinimum supported server Windows Server 2008 R2 [desktop apps only]\nTarget Platform Windows\nHeader winbase.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nRemarks\nRequirements\nﾉ Expand table","sourceDocument":"windows_debug_and_codes.txt; windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Debugging Function","Windows API","Developer Reference"],"aliases":[]},{"id":3076,"title":"Wow64SetThreadContext()","category":"PowerShell","product":"Windows Debugging API","tags":["Debugging Function","Windows API","Developer Reference"],"keywords":["Wow64SetThreadContext","Wow64SetThreadContext()","windows debugging","debugger","debug api","win32","developer troubleshooting","sets","the","context","specified","wow64","thread"],"errorCode":"","eventId":"","severity":"Low","summary":"Sets the context of a specified WOW64 thread.","rootCause":"This is a Windows debugging reference function, not an error condition. It is used when inspecting, controlling, or communicating with a process under debugging.","resolution":"1. Confirm that Wow64SetThreadContext is appropriate for the debugging scenario.\n2. Review the process architecture, debugger permissions, and return status.\n3. Capture GetLastError details when the function reports failure.\n4. Validate behavior in a controlled test environment before production use.","emailScript":"Hello,\n\nWe are using the Windows debugging capability Wow64SetThreadContext() to gather more information about the application issue. This diagnostic step helps identify where the process is failing and does not normally require action from you.\n\nPlease let us know if the issue changes while testing is in progress.\n\nThank you,\n\nIT Support","faqSteps":"1. Leave the affected application open unless IT Support asks you to close it.\n2. Save your work before diagnostic testing begins.\n3. Tell IT Support if the application closes or behaves differently during testing.\n4. No additional action is required unless instructions are provided.","notes":"Function purpose from source: Sets the context of a specified WOW64 thread.\n\nUse this as a debugging reference. No parameters or signatures are included because they were not present in the source document. Confirm current platform documentation before implementation.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Debugging Function","Windows API","Developer Reference"],"aliases":[]},{"id":3077,"title":"WriteProcessMemory()","category":"PowerShell","product":"Windows Debugging API","tags":["Debugging Function","Windows API","Developer Reference"],"keywords":["WriteProcessMemory","WriteProcessMemory()","windows debugging","debugger","debug api","win32","developer troubleshooting","writes","data","memory","area","specified","process"],"errorCode":"","eventId":"","severity":"Low","summary":"Writes data to a memory area in a specified process.","rootCause":"This is a Windows debugging reference function, not an error condition. It is used when inspecting, controlling, or communicating with a process under debugging.","resolution":"1. Confirm that WriteProcessMemory is appropriate for the debugging scenario.\n2. Review the process architecture, debugger permissions, and return status.\n3. Capture GetLastError details when the function reports failure.\n4. Validate behavior in a controlled test environment before production use.","emailScript":"Hello,\n\nWe are using the Windows debugging capability WriteProcessMemory() to gather more information about the application issue. This diagnostic step helps identify where the process is failing and does not normally require action from you.\n\nPlease let us know if the issue changes while testing is in progress.\n\nThank you,\n\nIT Support","faqSteps":"1. Leave the affected application open unless IT Support asks you to close it.\n2. Save your work before diagnostic testing begins.\n3. Tell IT Support if the application closes or behaves differently during testing.\n4. No additional action is required unless instructions are provided.","notes":"Function purpose from source: Writes data to a memory area in a specified process.\n\nUse this as a debugging reference. No parameters or signatures are included because they were not present in the source document. Confirm current platform documentation before implementation.\n\nAdditional source detail (windows-win32-debug.pdf): WriteProcessMemory function\n(memoryapi.h)\n05/14/2022\nWrites data to an area of memory in a specified process. The entire area to be written to must\nbe accessible or the operation fails.\nC++\n[in] hProcess\nA handle to the process memory to be modified. The handle must have PROCESS_VM_WRITE\nand PROCESS_VM_OPERATION access to the process.\n[in] lpBaseAddress\nA pointer to the base address in the specified process to which data is written. Before data\ntransfer occurs, the system verifies that all data in the base address and memory of the\nspecified size is accessible for write access, and if it is not accessible, the function fails.\n[in] lpBuffer\nA pointer to the buffer that contains data to be written in the address space of the specified\nprocess.\n[in] nSize\nThe number of bytes to be written to the specified process.\n[out] lpNumberOfBytesWritten\nSyntax\nBOOL WriteProcessMemory(\n [in] HANDLE hProcess,\n [in] LPVOID lpBaseAddress,\n [in] LPCVOID lpBuffer,\n [in] SIZE_T nSize,\n [out] SIZE_T *lpNumberOfBytesWritten\n);\nParameters\nA pointer to a variable that receives the number of bytes transferred into the specified process.\nThis parameter is optional. If lpNumberOfBytesWritten is NULL, the parameter is ignored.\nIf the function succeeds, the return value is nonzero.\nIf the function fails, the return value is 0 (zero). To get extended error information, call\nGetLastError. The function fails if the requested write operation crosses into an area of the\nprocess that is inaccessible.\nWriteProcessMemory copies the data from the specified buffer in the current process to the\naddress range of the specified process. Any process that has a handle with\nPROCESS_VM_WRITE and PROCESS_VM_OPERATION access to the process to be written to can\ncall the function. Typically but not always, the process with address space that is being written\nto is being debugged.\nThe entire area to be written to must be accessible, and if it is not accessible, the function fails.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader memoryapi.h (include Windows.h)\nLibrary onecore.lib\nDLL Kernel32.dll\nDebugging Functions\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nSee also\nProcess Functions for Debugging\nReadProcessMemory\nVirtualAllocEx\nDebugging Structures\nThe following structures are used with debugging:\nCONTEXT\nCREATE_PROCESS_DEBUG_INFO\nCREATE_THREAD_DEBUG_INFO\nDEBUG_EVENT\nEXCEPTION_DEBUG_INFO\nEXIT_PROCESS_DEBUG_INFO\nEXIT_THREAD_DEBUG_INFO\nLDT_ENTRY\nLOAD_DLL_DEBUG_INFO\nOUTPUT_DEBUG_STRING_INFO\nRIP_INFO\nUNLOAD_DLL_DEBUG_INFO\nWOW64_CONTEXT\nWOW64_FLOATING_SAVE_AREA\nWOW64_LDT_ENTRY\n \n \nLast updated on 07/14/2025","sourceDocument":"windows_debug_and_codes.txt; windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Debugging Function","Windows API","Developer Reference"],"aliases":[]},{"id":3078,"title":"0x80070002 - File Not Found","category":"Windows","product":"Windows / Windows Update","tags":["Microsoft Service Code","Windows","Windows / Windows Update"],"keywords":["0x80070002","0x80070002 - File Not Found","Microsoft Service Code","Windows","Windows / Windows Update","files, storage, or memory","microsoft error","windows troubleshooting","file","not","found","the","system","cannot","find","required","this","commonly","points","missing","corrupted","files","needed","windows","update","another","application","general","specified"],"errorCode":"0x80070002","eventId":"","severity":"Critical","summary":"The system cannot find a required file. This commonly points to missing or corrupted files needed by Windows Update or another application.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 0x80070002; use the surrounding log entries to confirm it.","resolution":"1. Record where 0x80070002 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to 0x80070002 - File Not Found.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 0x80070002 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The system cannot find a required file. This commonly points to missing or corrupted files needed by Windows Update or another application.\n\nLookup forms: 0x80070002, 0x80070002. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (microsoft_windows_error_code_master_list.txt): Category: WINDOWS GENERAL\nDescription: The system cannot find the file specified.\n\nFixes:\n1. Capture the full message, operation, and matching Event Viewer entry.\n2. Verify permissions, paths, services, dependencies, network access, and pending restart state.\n3. Repair the affected component; for Windows corruption run DISM /Online /Cleanup-Image /RestoreHealth, then sfc /scannow.\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","sourceDocument":"windows_debug_and_codes.txt; microsoft_windows_error_code_master_list.txt","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"platforms":["windows"],"vendors":["Windows"],"technologies":["Microsoft Service Code","Windows","Windows / Windows Update"],"aliases":["0x80070002"]},{"id":3079,"title":"0x80070005 - Access Denied","category":"Windows","product":"Windows / Microsoft Services","tags":["Microsoft Service Code","Windows","Windows / Microsoft Services"],"keywords":["0x80070005","0x80070005 - Access Denied","Microsoft Service Code","Windows","Windows / Microsoft Services","permissions and identity","microsoft error","windows troubleshooting","access","denied","the","operation","was","because","user","service","does","not","have","required","rights","file","registry","key","update","office","activation","resource","windows","general"],"errorCode":"0x80070005","eventId":"","severity":"Low","summary":"The operation was denied because the user or service does not have the required rights to access a file, registry key, service, update, or Office activation resource.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 0x80070005; use the surrounding log entries to confirm it.","resolution":"1. Record where 0x80070005 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Confirm the user or service identity has the required permissions and is not locked or disabled.\n4. Check available memory, disk capacity, quotas, and system resource pressure.\n5. Verify the required service or agent is installed, running, and current; repair the component if needed.\n6. Review Event Viewer and the application or service log for the same timestamp and code.\n7. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to 0x80070005 - Access Denied.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Confirm the user or service identity has the required permissions and is not locked or disabled.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 0x80070005 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The operation was denied because the user or service does not have the required rights to access a file, registry key, service, update, or Office activation resource.\n\nLookup forms: 0x80070005, 0x80070005. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (microsoft_windows_error_code_master_list.txt): Category: WINDOWS GENERAL\nDescription: Access is denied.\n\nFixes:\n1. Capture the full message, operation, and matching Event Viewer entry.\n2. Verify permissions, paths, services, dependencies, network access, and pending restart state.\n3. Repair the affected component; for Windows corruption run DISM /Online /Cleanup-Image /RestoreHealth, then sfc /scannow.\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","sourceDocument":"windows_debug_and_codes.txt; microsoft_windows_error_code_master_list.txt","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"platforms":["windows"],"vendors":["Windows"],"technologies":["Microsoft Service Code","Windows","Windows / Microsoft Services"],"aliases":["0x80070005"]},{"id":3080,"title":"0x80072EFD - Server Connection Failed","category":"Networking","product":"Windows Update / Microsoft Store","tags":["Microsoft Service Code","Networking","Windows Update / Microsoft Store"],"keywords":["0x80072EFD","0x80072efd","0x80072EFD - Server Connection Failed","Microsoft Service Code","Networking","Windows Update / Microsoft Store","network connectivity","microsoft error","windows troubleshooting","server","connection","failed","the","microsoft","service","could","not","established","usually","because","network","proxy","firewall","dns","availability","problems","windows","general","with"],"errorCode":"0x80072EFD","eventId":"","severity":"High","summary":"A connection to the Microsoft service could not be established, usually because of network, proxy, firewall, DNS, or service availability problems.","rootCause":"This response is commonly caused by an issue with network connectivity. The exact cause depends on the application, API call, and operation that returned 0x80072EFD; use the surrounding log entries to confirm it.","resolution":"1. Record where 0x80072EFD occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to 0x80072EFD - Server Connection Failed.\n\nWe recommend performing the following corrective action: Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 0x80072EFD appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A connection to the Microsoft service could not be established, usually because of network, proxy, firewall, DNS, or service availability problems.\n\nLookup forms: 0x80072EFD, 0x80072efd. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (microsoft_windows_error_code_master_list.txt): Category: WINDOWS GENERAL\nDescription: A connection with the server could not be established.\n\nFixes:\n1. Capture the full message, operation, and matching Event Viewer entry.\n2. Verify permissions, paths, services, dependencies, network access, and pending restart state.\n3. Repair the affected component; for Windows corruption run DISM /Online /Cleanup-Image /RestoreHealth, then sfc /scannow.\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","sourceDocument":"windows_debug_and_codes.txt; microsoft_windows_error_code_master_list.txt","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"platforms":["windows"],"vendors":["Windows Update"],"technologies":["Microsoft Service Code","Networking","Windows Update / Microsoft Store"],"aliases":["0x80072EFD"]},{"id":3081,"title":"429 Too Many Requests","category":"Networking","product":"HTTP / Microsoft APIs","tags":["HTTP / API Code","Networking","HTTP / Microsoft APIs"],"keywords":["429","429 Too Many Requests","HTTP / API Code","Networking","HTTP / Microsoft APIs","the calling process or Windows service","microsoft error","windows troubleshooting","too","many","requests","the","client","application","sent","more","than","service","permits","within","current","time","window"],"errorCode":"429","eventId":"","severity":"Low","summary":"The client or application sent more requests than the service permits within the current time window.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 429; use the surrounding log entries to confirm it.","resolution":"1. Record where 429 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to 429 Too Many Requests.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 429 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The client or application sent more requests than the service permits within the current time window.\n\nLookup forms: 429, 429. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["HTTP"],"technologies":["HTTP / API Code","Networking","HTTP / Microsoft APIs"],"aliases":["429"]},{"id":3082,"title":"503 Service Unavailable","category":"Networking","product":"HTTP / Microsoft Services","tags":["HTTP / API Code","Networking","HTTP / Microsoft Services"],"keywords":["503","503 Service Unavailable","HTTP / API Code","Networking","HTTP / Microsoft Services","the calling process or Windows service","microsoft error","windows troubleshooting","service","unavailable","the","requested","microsoft","web","temporarily","cannot","currently","handle","request"],"errorCode":"503","eventId":"","severity":"Medium","summary":"The requested Microsoft or web service is temporarily unavailable or cannot currently handle the request.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 503; use the surrounding log entries to confirm it.","resolution":"1. Record where 503 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review the response body, request permissions, rate limits, and service health before retrying.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to 503 Service Unavailable.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review the response body, request permissions, rate limits, and service health before retrying.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 503 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The requested Microsoft or web service is temporarily unavailable or cannot currently handle the request.\n\nLookup forms: 503, 503. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["HTTP"],"technologies":["HTTP / API Code","Networking","HTTP / Microsoft Services"],"aliases":["503"]},{"id":3083,"title":"403 Forbidden - Microsoft Graph API","category":"Entra ID","product":"Microsoft Graph API","tags":["HTTP / API Code","Entra ID","Microsoft Graph API"],"keywords":["403","403 Forbidden - Microsoft Graph API","HTTP / API Code","Entra ID","Microsoft Graph API","permissions and identity","microsoft error","windows troubleshooting","forbidden","microsoft","graph","api","the","application","was","authenticated","but","does","not","have","permission","access","requested","resource"],"errorCode":"403","eventId":"","severity":"Low","summary":"The application was authenticated but does not have permission to access the requested Microsoft Graph resource.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 403; use the surrounding log entries to confirm it.","resolution":"1. Record where 403 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Check available memory, disk capacity, quotas, and system resource pressure.\n4. Review the response body, request permissions, rate limits, and service health before retrying.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to 403 Forbidden - Microsoft Graph API.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Check available memory, disk capacity, quotas, and system resource pressure.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 403 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The application was authenticated but does not have permission to access the requested Microsoft Graph resource.\n\nLookup forms: 403, 403. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Microsoft Graph API"],"technologies":["HTTP / API Code","Entra ID","Microsoft Graph API"],"aliases":["403"]},{"id":3084,"title":"0x8007000D - Invalid Data","category":"Patch Management","product":"Windows Update / Windows 11","tags":["Microsoft Service Code","Patch Management","Windows Update / Windows 11"],"keywords":["0x8007000D","0x8007000d","0x8007000D - Invalid Data","Microsoft Service Code","Patch Management","Windows Update / Windows 11","files, storage, or memory","microsoft error","windows troubleshooting","invalid","data","windows","update","upgrade","encountered","often","because","system","files","are","corrupt","the","downloaded","package","incomplete","corrupted"],"errorCode":"0x8007000D","eventId":"","severity":"Critical","summary":"Windows Update or upgrade encountered invalid data, often because system files are corrupt or the downloaded update package is incomplete.","rootCause":"This response is commonly caused by an issue with files, storage, or memory. The exact cause depends on the application, API call, and operation that returned 0x8007000D; use the surrounding log entries to confirm it.","resolution":"1. Record where 0x8007000D occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to 0x8007000D - Invalid Data.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 0x8007000D appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Windows Update or upgrade encountered invalid data, often because system files are corrupt or the downloaded update package is incomplete.\n\nLookup forms: 0x8007000D, 0x8007000d. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (microsoft_windows_error_code_master_list.txt): Category: WINDOWS UPDATE\nDescription: Invalid or corrupted update data.\n\nFixes:\n1. Review WindowsUpdate.log and CBS.log for the failing package or phase.\n2. Run the Windows Update troubleshooter, confirm update services, disk space, DNS, proxy, and endpoint access.\n3. Repair servicing with DISM and SFC; reset update components only if logs indicate cache or datastore damage.\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","sourceDocument":"windows_debug_and_codes.txt; microsoft_windows_error_code_master_list.txt","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"platforms":["windows"],"vendors":["Windows Update"],"technologies":["Microsoft Service Code","Patch Management","Windows Update / Windows 11"],"aliases":["0x8007000D"]},{"id":3085,"title":"0x80246017 - Update Installation Blocked","category":"Patch Management","product":"Windows Update / Windows 11","tags":["Microsoft Service Code","Patch Management","Windows Update / Windows 11"],"keywords":["0x80246017","0x80246017 - Update Installation Blocked","Microsoft Service Code","Patch Management","Windows Update / Windows 11","the calling process or Windows service","microsoft error","windows troubleshooting","update","installation","blocked","was","downloaded","but","cannot","installed","commonly","because","required","service","such","background","intelligent","transfer","not","running"],"errorCode":"0x80246017","eventId":"","severity":"Medium","summary":"An update was downloaded but cannot be installed, commonly because a required update service such as Background Intelligent Transfer Service is not running.","rootCause":"This response is commonly caused by an issue with the calling process or Windows service. The exact cause depends on the application, API call, and operation that returned 0x80246017; use the surrounding log entries to confirm it.","resolution":"1. Record where 0x80246017 occurred and reproduce the operation if it is safe to do so.\n2. Verify the required service or agent is installed, running, and current; repair the component if needed.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to 0x80246017 - Update Installation Blocked.\n\nWe recommend performing the following corrective action: Verify the required service or agent is installed, running, and current; repair the component if needed. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 0x80246017 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An update was downloaded but cannot be installed, commonly because a required update service such as Background Intelligent Transfer Service is not running.\n\nLookup forms: 0x80246017, 0x80246017. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Windows Update"],"technologies":["Microsoft Service Code","Patch Management","Windows Update / Windows 11"],"aliases":["0x80246017"]},{"id":3086,"title":"VMAccessNotSupported - VM Access Not Supported","category":"Azure","product":"Azure Virtual Machines","tags":["Microsoft Service Code","Azure","Azure Virtual Machines"],"keywords":["VMAccessNotSupported","vmaccessnotsupported","VMAccessNotSupported - VM Access Not Supported","Microsoft Service Code","Azure","Azure Virtual Machines","permissions and identity","microsoft error","windows troubleshooting","access","not","supported","azure","cannot","reset","the","password","configure","extension","because","virtual","machine","agent","unresponsive","installed"],"errorCode":"VMAccessNotSupported","eventId":"","severity":"Medium","summary":"Azure cannot reset the password or configure a VM access extension because the virtual machine agent is unresponsive or not installed.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned VMAccessNotSupported; use the surrounding log entries to confirm it.","resolution":"1. Record where VMAccessNotSupported occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to VMAccessNotSupported - VM Access Not Supported.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when VMAccessNotSupported appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: Azure cannot reset the password or configure a VM access extension because the virtual machine agent is unresponsive or not installed.\n\nLookup forms: VMAccessNotSupported, vmaccessnotsupported. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"windows_debug_and_codes.txt","platforms":["windows"],"vendors":["Azure Virtual Machines"],"technologies":["Microsoft Service Code","Azure","Azure Virtual Machines"],"aliases":["VMAccessNotSupported"]},{"id":3087,"title":"AADSTS50034 - User Account Locked","category":"Entra ID","product":"Microsoft Entra ID","tags":["Microsoft Service Code","Entra ID","Microsoft Entra ID"],"keywords":["AADSTS50034","aadsts50034","AADSTS50034 - User Account Locked","Microsoft Service Code","Entra ID","Microsoft Entra ID","permissions and identity","microsoft error","windows troubleshooting","user","account","locked","the","after","too","many","failed","sign","attempts","and","requires","administrator","review","unlock","microsoft","entra","was","not","found","directory"],"errorCode":"AADSTS50034","eventId":"","severity":"High","summary":"The user account is locked after too many failed sign-in attempts and requires an administrator to review or unlock it.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned AADSTS50034; use the surrounding log entries to confirm it.","resolution":"1. Record where AADSTS50034 occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to AADSTS50034 - User Account Locked.\n\nWe recommend performing the following corrective action: Confirm the user or service identity has the required permissions and is not locked or disabled. Review Event Viewer and the application or service log for the same timestamp and code.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when AADSTS50034 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The user account is locked after too many failed sign-in attempts and requires an administrator to review or unlock it.\n\nLookup forms: AADSTS50034, aadsts50034. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (microsoft_windows_error_code_master_list.txt): Category: MICROSOFT ENTRA ID\nDescription: User account was not found in the directory.\n\nFixes:\n1. Open the failed Entra sign-in event and record error, correlation ID, timestamp, tenant, application, and Conditional Access result.\n2. Verify the user, tenant, app assignment, consent, MFA, device, and policy state indicated by the event.\n3. Correct the identified identity or policy condition, allow replication, and test again.\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","sourceDocument":"windows_debug_and_codes.txt; microsoft_windows_error_code_master_list.txt","commands":[],"platforms":["windows"],"vendors":["Microsoft Entra ID"],"technologies":["Microsoft Service Code","Entra ID","Microsoft Entra ID"],"aliases":["AADSTS50034"]},{"id":3088,"title":"0x8007007E - Module Not Found","category":"Microsoft 365","product":"Microsoft 365 / Office","tags":["Microsoft Service Code","Microsoft 365","Microsoft 365 / Office"],"keywords":["0x8007007E","0x8007007e","0x8007007E - Module Not Found","Microsoft Service Code","Microsoft 365","Microsoft 365 / Office","installation or update components","microsoft error","windows troubleshooting","module","not","found","required","could","this","can","prevent","office","applications","from","opening","and","often","indicates","corrupted","incomplete","installation","windows","general","the","specified"],"errorCode":"0x8007007E","eventId":"","severity":"Critical","summary":"A required module could not be found. This can prevent Office applications from opening and often indicates a corrupted or incomplete installation.","rootCause":"This response is commonly caused by an issue with installation or update components. The exact cause depends on the application, API call, and operation that returned 0x8007007E; use the surrounding log entries to confirm it.","resolution":"1. Record where 0x8007007E occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Verify the required service or agent is installed, running, and current; repair the component if needed.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to 0x8007007E - Module Not Found.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Verify the required service or agent is installed, running, and current; repair the component if needed.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 0x8007007E appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: A required module could not be found. This can prevent Office applications from opening and often indicates a corrupted or incomplete installation.\n\nLookup forms: 0x8007007E, 0x8007007e. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (microsoft_windows_error_code_master_list.txt): Category: WINDOWS GENERAL\nDescription: The specified module could not be found.\n\nFixes:\n1. Capture the full message, operation, and matching Event Viewer entry.\n2. Verify permissions, paths, services, dependencies, network access, and pending restart state.\n3. Repair the affected component; for Windows corruption run DISM /Online /Cleanup-Image /RestoreHealth, then sfc /scannow.\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","sourceDocument":"windows_debug_and_codes.txt; microsoft_windows_error_code_master_list.txt","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"platforms":["windows"],"vendors":["Microsoft 365"],"technologies":["Microsoft Service Code","Microsoft 365","Microsoft 365 / Office"],"aliases":["0x8007007E"]},{"id":3089,"title":"0x8004de40 - OneDrive Cannot Connect","category":"Microsoft 365","product":"Microsoft OneDrive","tags":["Microsoft Service Code","Microsoft 365","Microsoft OneDrive"],"keywords":["0x8004de40","0x8004de40 - OneDrive Cannot Connect","Microsoft Service Code","Microsoft 365","Microsoft OneDrive","permissions and identity","microsoft error","windows troubleshooting","onedrive","cannot","connect","the","cloud","because","network","service","proxy","tls","authentication","problem","microsoft","services"],"errorCode":"0x8004de40","eventId":"","severity":"High","summary":"OneDrive cannot connect to the cloud because of a network, service, proxy, TLS, or authentication problem.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 0x8004de40; use the surrounding log entries to confirm it.","resolution":"1. Record where 0x8004de40 occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Verify the required service or agent is installed, running, and current; repair the component if needed.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to 0x8004de40 - OneDrive Cannot Connect.\n\nWe recommend performing the following corrective action: Verify the referenced path, file, drive, or component exists and is accessible. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 0x8004de40 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: OneDrive cannot connect to the cloud because of a network, service, proxy, TLS, or authentication problem.\n\nLookup forms: 0x8004de40, 0x8004de40. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.\n\nAdditional source detail (microsoft_windows_error_code_master_list.txt): Category: ONEDRIVE\nDescription: OneDrive cannot connect to Microsoft services.\n\nFixes:\n1. Check Microsoft 365 service health, account status, network, proxy, TLS, and required endpoints.\n2. Restart and update OneDrive; verify Files On-Demand and file permissions.\n3. Reset OneDrive if the sync provider remains unhealthy, then confirm sync returns to Up to date.\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","sourceDocument":"windows_debug_and_codes.txt; microsoft_windows_error_code_master_list.txt","commands":[],"platforms":["windows"],"vendors":["Microsoft OneDrive"],"technologies":["Microsoft Service Code","Microsoft 365","Microsoft OneDrive"],"aliases":["0x8004de40"]},{"id":3090,"title":"1266 - The smartcard certificate used for authentication has been revoked","category":"Ivanti","product":"Ivanti / Windows","tags":["Ivanti Windows Code","Ivanti","Ivanti / Windows"],"keywords":["1266","error 1266","4F2","1266 - The smartcard certificate used for authentication has been revoked","Ivanti Windows Code","Ivanti","Ivanti / Windows","permissions and identity","microsoft error","windows troubleshooting","the","smartcard","certificate","used","for","authentication","has","been","revoked","please","contact","your","system","administrator","there","may","additional","information","event","log"],"errorCode":"1266","eventId":"","severity":"High","summary":"The smartcard certificate used for authentication has been revoked. Please contact your system administrator. There may be additional information in the event log.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1266; use the surrounding log entries to confirm it.","resolution":"1. Record where 1266 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to 1266 - The smartcard certificate used for authentication has been revoked.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1266 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The smartcard certificate used for authentication has been revoked. Please contact your system administrator. There may be additional information in the event log.\n\nLookup forms: 1266, error 1266, 4F2. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Ivanti"],"technologies":["Ivanti Windows Code","Ivanti","Ivanti / Windows"],"aliases":["1266"]},{"id":3091,"title":"1267 - An untrusted certificate authority was detected while processing the smartcard c","category":"Ivanti","product":"Ivanti / Windows","tags":["Ivanti Windows Code","Ivanti","Ivanti / Windows"],"keywords":["1267","error 1267","4F3","1267 - An untrusted certificate authority was detected while processing the smartcard c","Ivanti Windows Code","Ivanti","Ivanti / Windows","permissions and identity","microsoft error","windows troubleshooting","untrusted","certificate","authority","was","detected","while","processing","the","smartcard","used","for","authentication","please","contact","your","system","administrator"],"errorCode":"1267","eventId":"","severity":"High","summary":"An untrusted certificate authority was detected while processing the smartcard certificate used for authentication. Please contact your system administrator.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1267; use the surrounding log entries to confirm it.","resolution":"1. Record where 1267 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to 1267 - An untrusted certificate authority was detected while processing the smartcard c.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1267 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: An untrusted certificate authority was detected while processing the smartcard certificate used for authentication. Please contact your system administrator.\n\nLookup forms: 1267, error 1267, 4F3. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Ivanti"],"technologies":["Ivanti Windows Code","Ivanti","Ivanti / Windows"],"aliases":["1267"]},{"id":3092,"title":"1268 - The revocation status of the smartcard certificate used for authentication could","category":"Ivanti","product":"Ivanti / Windows","tags":["Ivanti Windows Code","Ivanti","Ivanti / Windows"],"keywords":["1268","error 1268","4F4","1268 - The revocation status of the smartcard certificate used for authentication could","Ivanti Windows Code","Ivanti","Ivanti / Windows","permissions and identity","microsoft error","windows troubleshooting","the","revocation","status","smartcard","certificate","used","for","authentication","could","not","determined","please","contact","your","system","administrator"],"errorCode":"1268","eventId":"","severity":"High","summary":"The revocation status of the smartcard certificate used for authentication could not be determined. Please contact your system administrator.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1268; use the surrounding log entries to confirm it.","resolution":"1. Record where 1268 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to 1268 - The revocation status of the smartcard certificate used for authentication could.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1268 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The revocation status of the smartcard certificate used for authentication could not be determined. Please contact your system administrator.\n\nLookup forms: 1268, error 1268, 4F4. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Ivanti"],"technologies":["Ivanti Windows Code","Ivanti","Ivanti / Windows"],"aliases":["1268"]},{"id":3093,"title":"1269 - The smartcard certificate used for authentication was not trusted","category":"Ivanti","product":"Ivanti / Windows","tags":["Ivanti Windows Code","Ivanti","Ivanti / Windows"],"keywords":["1269","error 1269","4F5","1269 - The smartcard certificate used for authentication was not trusted","Ivanti Windows Code","Ivanti","Ivanti / Windows","permissions and identity","microsoft error","windows troubleshooting","the","smartcard","certificate","used","for","authentication","was","not","trusted","please","contact","your","system","administrator"],"errorCode":"1269","eventId":"","severity":"High","summary":"The smartcard certificate used for authentication was not trusted. Please contact your system administrator.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1269; use the surrounding log entries to confirm it.","resolution":"1. Record where 1269 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to 1269 - The smartcard certificate used for authentication was not trusted.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1269 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The smartcard certificate used for authentication was not trusted. Please contact your system administrator.\n\nLookup forms: 1269, error 1269, 4F5. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Ivanti"],"technologies":["Ivanti Windows Code","Ivanti","Ivanti / Windows"],"aliases":["1269"]},{"id":3094,"title":"1270 - The smartcard certificate used for authentication has expired","category":"Ivanti","product":"Ivanti / Windows","tags":["Ivanti Windows Code","Ivanti","Ivanti / Windows"],"keywords":["1270","error 1270","4F6","1270 - The smartcard certificate used for authentication has expired","Ivanti Windows Code","Ivanti","Ivanti / Windows","permissions and identity","microsoft error","windows troubleshooting","the","smartcard","certificate","used","for","authentication","has","expired","please","contact","your","system","administrator"],"errorCode":"1270","eventId":"","severity":"High","summary":"The smartcard certificate used for authentication has expired. Please contact your system administrator.","rootCause":"This response is commonly caused by an issue with permissions and identity. The exact cause depends on the application, API call, and operation that returned 1270; use the surrounding log entries to confirm it.","resolution":"1. Record where 1270 occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue and determined it is related to 1270 - The smartcard certificate used for authentication has expired.\n\nWe recommend performing the following corrective action: Review Event Viewer and the application or service log for the same timestamp and code. Correct the confirmed cause, retry once, and validate normal operation.\n\nPlease let us know if the issue continues after completing these steps.\n\nThank you,\n\nIT Support","faqSteps":"1. Close and reopen the affected application, then try the action once more.\n2. Confirm the computer is connected to the company network or internet as required.\n3. Note what you were doing when 1270 appeared.\n4. Send IT Support the full message and a screenshot if the issue continues.","notes":"Source description: The smartcard certificate used for authentication has expired. Please contact your system administrator.\n\nLookup forms: 1270, error 1270, 4F6. Capture GetLastError or API response context before changing the system. For Win32 codes, use FormatMessage with FORMAT_MESSAGE_FROM_SYSTEM or a Windows Error Lookup tool to validate the message on the affected OS.","sourceDocument":"ivanti_error_codes.pdf","platforms":["windows"],"vendors":["Ivanti"],"technologies":["Ivanti Windows Code","Ivanti","Ivanti / Windows"],"aliases":["1270"]},{"id":3095,"title":"Server Or VM Offline","category":"Hyper-V","product":"Windows Server / Hyper-V","tags":["Hyper-V","Troubleshooting","Windows Server"],"keywords":["server","offline","technician","reference","for","diagnosing","and","resolving","hyper","host","power","outage","internet","site","connectivity","failure","powered","off","vmms","required","service","stopped","storage","unavailable","monitoring","agent","disconnected"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for diagnosing and resolving server or vm offline.","rootCause":"- Hyper-V host is offline\n- Power outage\n- Internet or site connectivity failure\n- VM is powered off\n- VMMS or required Hyper-V service is stopped\n- Host storage is unavailable\n- Monitoring agent is stopped or disconnected","resolution":"1. Determine whether only one VM, all VMs, or the entire host is offline.\n2. Ping the host management address and verify switch/firewall connectivity.\n3. Connect through iDRAC, iLO, LOM, or the hypervisor console.\n4. Check the physical host for power, hardware, RAID, and boot errors.\n5. Verify the Hyper-V Virtual Machine Management service:\n Get-Service vmms\n6. List VM states:\n Get-VM\n7. Start the affected VM only after confirming its storage is available:\n Start-VM -Name \"VM-NAME\"\n8. If every VM is offline, troubleshoot the host before troubleshooting individual guests.\n9. Verify that the monitoring agent returns after the server is restored.","emailScript":"Hello,\n\nWe reviewed the issue related to Server Or VM Offline.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- Hyper-V host is offline\n- Power outage\n- Internet or site connectivity failure\n- VM is powered off\n- VMMS or required Hyper-V service is stopped\n- Host storage is unavailable\n- Monitoring agent is stopped or disconnected\n\nValidation:\n- Host responds to management tools\n- VM state shows Running\n- Guest OS responds to ping or RMM\n- Required applications and services respond\n- Monitoring alert clears\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Hyper-V","Troubleshooting","Windows Server"],"aliases":[]},{"id":3096,"title":"VM Fails To Start","category":"Hyper-V","product":"Windows Server / Hyper-V","tags":["Hyper-V","Troubleshooting","Windows Server"],"keywords":["fails","start","technician","reference","for","diagnosing","and","resolving","insufficient","host","memory","vhdx","configuration","path","unavailable","incorrect","ntfs","permissions","checkpoint","avhdx","chain","problem","virtual","switch","longer","exists","corruption","another","process","has","locked","the","disk","storage","full","vmms","wmi","failure"],"errorCode":"","eventId":"","severity":"Critical","summary":"Technician reference for diagnosing and resolving vm fails to start.","rootCause":"- Insufficient host memory\n- VHDX or configuration path is unavailable\n- Incorrect NTFS permissions\n- Checkpoint or AVHDX chain problem\n- Virtual switch no longer exists\n- VM configuration corruption\n- Another process has locked the virtual disk\n- Host storage is full\n- VMMS or WMI failure","resolution":"1. Record the complete Hyper-V error and VM ID.\n2. Check free RAM, disk space, and storage availability.\n3. Confirm the VM configuration and VHDX paths:\n Get-VM -Name \"VM-NAME\" | Format-List *\n Get-VMHardDiskDrive -VMName \"VM-NAME\"\n4. Confirm that the configured virtual switch exists:\n Get-VMSwitch\n5. Review:\n Event Viewer\n Applications and Services Logs\n Microsoft\n Windows\n Hyper-V-VMMS\n Admin\n6. Verify permissions on the VM configuration and disk folders.\n7. Check for active checkpoints:\n Get-VMSnapshot -VMName \"VM-NAME\"\n8. Check for AVHDX files and validate the disk chain before making changes.\n9. Restart VMMS only after evaluating the impact:\n Restart-Service vmms\n10. Retry starting the VM.","emailScript":"Hello,\n\nWe reviewed the issue related to VM Fails To Start.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- Insufficient host memory\n- VHDX or configuration path is unavailable\n- Incorrect NTFS permissions\n- Checkpoint or AVHDX chain problem\n- Virtual switch no longer exists\n- VM configuration corruption\n- Another process has locked the virtual disk\n- Host storage is full\n- VMMS or WMI failure\n\nValidation:\n- VM reaches Running state\n- Guest OS completes boot\n- Event Viewer does not generate a new start failure\n- Application services inside the VM are functional\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Hyper-V","Troubleshooting","Windows Server"],"aliases":[]},{"id":3097,"title":"Insufficient Memory","category":"Windows Server","product":"Windows Server","tags":["Windows Server","Troubleshooting","Windows Server"],"keywords":["insufficient","memory","technician","reference","for","diagnosing","and","resolving","not","enough","available","host","startup","configured","too","high","many","vms","running","dynamic","settings","are","inappropriate","process","backup","software","consuming"],"errorCode":"","eventId":"","severity":"Low","summary":"Technician reference for diagnosing and resolving insufficient memory.","rootCause":"- Not enough available host memory\n- VM startup memory configured too high\n- Too many VMs running\n- Dynamic Memory settings are inappropriate\n- Host process or backup software consuming memory","resolution":"1. Check host memory in Task Manager, Resource Monitor, or PowerShell.\n2. Review VM memory configuration:\n Get-VMMemory -VMName \"VM-NAME\"\n3. Stop unused VMs if operationally approved.\n4. Reduce Startup RAM only if supported by the guest workload.\n5. Review Minimum RAM and Maximum RAM when Dynamic Memory is enabled.\n6. Identify host processes consuming abnormal memory.\n7. Retry the VM start after sufficient memory is available.","emailScript":"Hello,\n\nWe reviewed the issue related to Insufficient Memory.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- Not enough available host memory\n- VM startup memory configured too high\n- Too many VMs running\n- Dynamic Memory settings are inappropriate\n- Host process or backup software consuming memory\n\nValidation:\n- VM starts normally\n- Host retains adequate available memory\n- No memory pressure or paging alert follows the repair\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Windows Server","Troubleshooting","Windows Server"],"aliases":[]},{"id":3098,"title":"VM Stuck Starting, Stopping, Saved, Or Paused","category":"Hyper-V","product":"Windows Server / Hyper-V","tags":["Hyper-V","Troubleshooting","Windows Server"],"keywords":["stuck","starting","stopping","saved","paused","technician","reference","for","diagnosing","and","resolving","storage","problem","worker","process","hung","cluster","resource","failure","backup","checkpoint","operation","vmms","deadlock","host","exhaustion","csv","network","interruption"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for diagnosing and resolving vm stuck starting, stopping, saved, or paused.","rootCause":"- Storage I/O problem\n- VM worker process is hung\n- Cluster resource failure\n- Backup or checkpoint operation is stuck\n- VMMS deadlock\n- Host resource exhaustion\n- CSV or network interruption","resolution":"1. Identify whether one VM or multiple VMs are affected.\n2. Review Hyper-V-VMMS, Hyper-V-Worker, System, and cluster logs.\n3. Check host CPU, RAM, disk latency, and free space.\n4. Check whether a backup or checkpoint merge is active.\n5. For a clustered VM, inspect the role in Failover Cluster Manager.\n6. Attempt a normal shutdown before using a forced power-off.\n7. If required and approved:\n Stop-VM -Name \"VM-NAME\" -TurnOff\n8. Restart VMMS only if storage is healthy and the effect on other VMs is understood.\n9. Reboot the host only as a controlled final step with VM impact documented.","emailScript":"Hello,\n\nWe reviewed the issue related to VM Stuck Starting, Stopping, Saved, Or Paused.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- Storage I/O problem\n- VM worker process is hung\n- Cluster resource failure\n- Backup or checkpoint operation is stuck\n- VMMS deadlock\n- Host resource exhaustion\n- CSV or network interruption\n\nValidation:\n- VM returns to a stable Off or Running state\n- Disk merge activity completes\n- No CSV, storage, or cluster alarms remain\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Hyper-V","Troubleshooting","Windows Server"],"aliases":[]},{"id":3099,"title":"Stale Or Orphaned AVHDX Files","category":"Hyper-V","product":"Windows Server / Hyper-V","tags":["Hyper-V","Troubleshooting","Windows Server"],"keywords":["stale","orphaned","avhdx","files","technician","reference","for","diagnosing","and","resolving","failed","checkpoint","deletion","incomplete","backup","cleanup","insufficient","host","disk","space","during","merge","interruption","processing","from","decommissioned"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for diagnosing and resolving stale or orphaned avhdx files.","rootCause":"- Failed checkpoint deletion\n- Incomplete backup cleanup\n- Insufficient host disk space during merge\n- VM or host interruption during checkpoint processing\n- Orphaned files from a decommissioned VM","resolution":"1. Do not delete the AVHDX files manually.\n2. Check Hyper-V Manager for checkpoints.\n3. List checkpoints:\n Get-VMSnapshot -VMName \"VM-NAME\"\n4. List the configured disk path:\n Get-VMHardDiskDrive -VMName \"VM-NAME\"\n5. Inspect each disk with Inspect Disk or:\n Get-VHD -Path \"D:\\Path\\Disk.avhdx\"\n6. Map the complete ParentPath chain to the base VHDX.\n7. Check whether a backup is running or the VM is marked as being in backup.\n8. If the checkpoint appears in Hyper-V, remove it normally and monitor the merge.\n9. If it is orphaned, use Edit Disk > Inspect/Merge only after validating the chain and backup.\n10. Confirm adequate free disk space before merging.\n11. Remove only files proven to be unattached and no longer part of any active chain.","emailScript":"Hello,\n\nWe reviewed the issue related to Stale Or Orphaned AVHDX Files.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- Failed checkpoint deletion\n- Incomplete backup cleanup\n- Insufficient host disk space during merge\n- VM or host interruption during checkpoint processing\n- Orphaned files from a decommissioned VM\n\nValidation:\n- Active VM points to the correct disk\n- Checkpoint merge completes\n- No unexpected AVHDX growth continues\n- VM boots and data is current\n- Backup succeeds\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Hyper-V","Troubleshooting","Windows Server"],"aliases":[]},{"id":3100,"title":"Checkpoint Cannot Be Removed","category":"Hyper-V","product":"Windows Server / Hyper-V","tags":["Hyper-V","Troubleshooting","Windows Server"],"keywords":["checkpoint","cannot","removed","failed","remove","delete","catastrophic","failure","0x8000ffff","virtual","machine","generate","vhd","tree","broken","differencing","disk","chain","missing","parent","storage","unavailable","insufficient","space","backup","software","holding","the","incorrect","permissions","file","system","corruption","0x8000FFFF"],"errorCode":"0x8000FFFF","eventId":"","severity":"Critical","summary":"Failed to remove checkpoint\nCannot delete checkpoint\nCatastrophic failure 0x8000FFFF\nVirtual machine failed to generate VHD tree","rootCause":"- Broken differencing-disk chain\n- Missing parent disk\n- Storage unavailable\n- Insufficient disk space\n- Backup software holding the checkpoint\n- Incorrect permissions\n- File system corruption","resolution":"1. Stop creating additional checkpoints.\n2. Confirm storage health and available capacity.\n3. Record the current VM disk path and checkpoint hierarchy.\n4. Inspect the VHDX/AVHDX parent chain.\n5. Check for active backup jobs and VSS operations.\n6. Correct missing path or permission issues.\n7. Attempt normal checkpoint removal.\n8. If normal removal fails, perform a controlled disk merge only after backup and chain validation.\n9. Start the VM and confirm that the current data state is preserved.","emailScript":"Hello,\n\nWe reviewed the issue related to Checkpoint Cannot Be Removed.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- Broken differencing-disk chain\n- Missing parent disk\n- Storage unavailable\n- Insufficient disk space\n- Backup software holding the checkpoint\n- Incorrect permissions\n- File system corruption\n\nValidation:\n- No checkpoint remains unexpectedly\n- AVHDX merge completes\n- VM uses the expected VHDX\n- Backup job completes successfully\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Hyper-V","Troubleshooting","Windows Server"],"aliases":["0x8000FFFF"]},{"id":3101,"title":"Hyper-V Replication Failure","category":"Hyper-V","product":"Windows Server / Hyper-V","tags":["Hyper-V","Troubleshooting","Windows Server"],"keywords":["hyper","replication","failure","failed","could","not","replicate","changes","suspended","address","resolved","after","repeated","attempts","replica","host","unavailable","dns","resolution","firewall","port","blockage","authentication","certificate","service","issue","insufficient","storage","broken","relationship","large","backlog","outage"],"errorCode":"","eventId":"","severity":"Critical","summary":"- VM replication failed\n- VM could not replicate changes\n- Replication suspended\n- Address could not be resolved\n- Replication failed after repeated attempts","rootCause":"- Replica host unavailable\n- DNS resolution failure\n- Firewall or port blockage\n- Authentication or certificate failure\n- Replication service issue\n- Insufficient storage on replica host\n- Broken replication relationship\n- Large backlog after an outage","resolution":"1. Verify source and replica hosts are online.\n2. Test DNS resolution in both directions.\n3. Verify the configured replication port and firewall access.\n4. Check replication health:\n Get-VMReplication\n5. Review Hyper-V-VMMS replication events on both hosts.\n6. Verify certificate validity if certificate authentication is used.\n7. Confirm sufficient storage on the replica destination.\n8. Resume replication when suspended:\n Resume-VMReplication -VMName \"VM-NAME\"\n9. If the relationship is irrecoverable, remove and recreate replication using a planned initial replication method.","emailScript":"Hello,\n\nWe reviewed the issue related to Hyper-V Replication Failure.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- Replica host unavailable\n- DNS resolution failure\n- Firewall or port blockage\n- Authentication or certificate failure\n- Replication service issue\n- Insufficient storage on replica host\n- Broken replication relationship\n- Large backlog after an outage\n\nValidation:\n- Replication state is Replicating\n- Replication health is Normal\n- Backlog decreases\n- Test failover completes when operationally approved\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Hyper-V","Troubleshooting","Windows Server"],"aliases":[]},{"id":3102,"title":"Hyper-V Manager Cannot Connect","category":"Hyper-V","product":"Windows Server / Hyper-V","tags":["Hyper-V","Troubleshooting","Windows Server"],"keywords":["hyper","manager","cannot","connect","winrm","client","process","the","request","access","denied","authority","could","contacted","for","authentication","error","0x80090311","0x8009030d","loading","virtual","machines","indefinitely","dns","domain","controller","communication","problem","configuration","firewall","blockage","incorrect","permissions","kerberos","spn","time","synchronization","failure","vmms","wmi","0x80090311"],"errorCode":"0x80090311","eventId":"","severity":"High","summary":"- Hyper-V Manager cannot connect\n- WinRM client cannot process the request\n- Access denied\n- No authority could be contacted for authentication\n- Error 0x80090311\n- Error 0x8009030D\n- Loading virtual machines indefinitely","rootCause":"- DNS or domain controller communication problem\n- WinRM configuration problem\n- Firewall blockage\n- Incorrect permissions\n- Kerberos or SPN problem\n- Time synchronization failure\n- VMMS or WMI failure","resolution":"1. Verify hostname and DNS resolution.\n2. Confirm client, host, and domain time are synchronized.\n3. Test network and management firewall access.\n4. Check services:\n WinRM\n VMMS\n WMI\n5. Verify the administrator is authorized on the Hyper-V host.\n6. Review WinRM, Kerberos, System, WMI, and Hyper-V logs.\n7. Test local Hyper-V Manager on the host.\n8. Repair WMI or WinRM only after confirming the affected component.","emailScript":"Hello,\n\nWe reviewed the issue related to Hyper-V Manager Cannot Connect.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- DNS or domain controller communication problem\n- WinRM configuration problem\n- Firewall blockage\n- Incorrect permissions\n- Kerberos or SPN problem\n- Time synchronization failure\n- VMMS or WMI failure\n\nValidation:\n- Hyper-V Manager displays VMs\n- Remote start and stop operations work\n- No Kerberos, WinRM, or WMI errors return\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Hyper-V","Troubleshooting","Windows Server"],"aliases":["0x80090311"]},{"id":3103,"title":"VM Has No Network Connection","category":"Hyper-V","product":"Windows Server / Hyper-V","tags":["Hyper-V","Troubleshooting","Windows Server"],"keywords":["has","network","connection","technician","reference","for","diagnosing","and","resolving","connected","the","wrong","virtual","switch","was","deleted","recreated","incorrect","vlan","physical","nic","team","failure","duplicate","address","guest","disabled","dns","gateway","configuration","problem","host","extension","security","filter","interference"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for diagnosing and resolving vm has no network connection.","rootCause":"- VM connected to the wrong virtual switch\n- Virtual switch was deleted or recreated\n- Incorrect VLAN ID\n- Physical NIC or NIC team failure\n- Duplicate IP address\n- Guest NIC disabled\n- DNS or gateway configuration problem\n- Host switch extension or security filter interference","resolution":"1. Check VM network adapter configuration:\n Get-VMNetworkAdapter -VMName \"VM-NAME\"\n2. Check host virtual switches:\n Get-VMSwitch\n3. Confirm the correct switch and VLAN:\n Get-VMNetworkAdapterVlan -VMName \"VM-NAME\"\n4. Verify physical NIC or SET/NIC team state.\n5. Inside the guest, check:\n ipconfig /all\n route print\n Get-NetAdapter\n6. Test local gateway, DNS server, and another network endpoint.\n7. Correct duplicate IP, DNS, VLAN, or switch assignment.\n8. Review firewall and security-agent filtering.","emailScript":"Hello,\n\nWe reviewed the issue related to VM Has No Network Connection.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- VM connected to the wrong virtual switch\n- Virtual switch was deleted or recreated\n- Incorrect VLAN ID\n- Physical NIC or NIC team failure\n- Duplicate IP address\n- Guest NIC disabled\n- DNS or gateway configuration problem\n- Host switch extension or security filter interference\n\nValidation:\n- Guest reaches gateway and DNS\n- DNS names resolve\n- Required application ports connect\n- Network remains stable after reboot\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Hyper-V","Troubleshooting","Windows Server"],"aliases":[]},{"id":3104,"title":"Live Migration Failure","category":"Hyper-V","product":"Windows Server / Hyper-V","tags":["Hyper-V","Troubleshooting","Windows Server"],"keywords":["live","migration","failure","hardware","destination","not","compatible","credentials","supplied","were","recognized","fails","times","out","becomes","inaccessible","after","cpu","generation","mismatch","authentication","configuration","network","dns","issue","storage","path","unavailable","delegation","permission","problem","device","incompatible","with","lacks","memory","capacity"],"errorCode":"","eventId":"","severity":"High","summary":"- Hardware on destination is not compatible\n- Credentials supplied were not recognized\n- Live migration fails or times out\n- VM becomes inaccessible after migration","rootCause":"- CPU generation mismatch\n- Authentication configuration mismatch\n- Network or DNS issue\n- Storage path unavailable\n- Delegation or permission problem\n- VM device incompatible with migration\n- Destination lacks memory or capacity","resolution":"1. Confirm both hosts support the VM configuration.\n2. Compare CPU capabilities and enable processor compatibility only when appropriate.\n3. Verify live migration authentication settings on both hosts.\n4. Validate DNS, network throughput, firewall rules, and migration networks.\n5. Confirm destination memory and storage capacity.\n6. Check whether TPM, GPU, USB, or passthrough devices prevent migration.\n7. Review Hyper-V-VMMS and Failover Clustering events.\n8. Retry after correcting the specific compatibility or authentication failure.","emailScript":"Hello,\n\nWe reviewed the issue related to Live Migration Failure.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- CPU generation mismatch\n- Authentication configuration mismatch\n- Network or DNS issue\n- Storage path unavailable\n- Delegation or permission problem\n- VM device incompatible with migration\n- Destination lacks memory or capacity\n\nValidation:\n- Migration completes\n- VM remains reachable\n- Storage and network adapters remain connected\n- Application services remain healthy\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Hyper-V","Troubleshooting","Windows Server"],"aliases":[]},{"id":3105,"title":"VM Trust Relationship Failed","category":"Hyper-V","product":"Windows Server / Hyper-V","tags":["Hyper-V","Troubleshooting","Windows Server"],"keywords":["trust","relationship","failed","the","between","this","workstation","and","primary","domain","computer","account","password","mismatch","reverted","old","checkpoint","broken","secure","channel","duplicate","dns","time","synchronization","issue","isolated","from","controller"],"errorCode":"","eventId":"","severity":"High","summary":"The trust relationship between this workstation and the primary domain failed","rootCause":"- Computer account password mismatch\n- VM reverted to an old checkpoint\n- Broken secure channel\n- Duplicate computer account\n- DNS or time synchronization issue\n- VM isolated from a domain controller","resolution":"1. Verify the VM uses internal domain DNS.\n2. Verify time synchronization with the domain.\n3. Test domain controller connectivity.\n4. Test the secure channel:\n Test-ComputerSecureChannel -Verbose\n5. Repair it with authorized domain credentials:\n Test-ComputerSecureChannel -Repair -Credential DOMAIN\\AdminUser\n6. Restart the server.\n7. If repair fails, reset the computer account or perform a controlled domain rejoin.\n8. Avoid reverting domain-joined systems, especially DCs, to old checkpoints.","emailScript":"Hello,\n\nWe reviewed the issue related to VM Trust Relationship Failed.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- Computer account password mismatch\n- VM reverted to an old checkpoint\n- Broken secure channel\n- Duplicate computer account\n- DNS or time synchronization issue\n- VM isolated from a domain controller\n\nValidation:\n- Secure-channel test returns True\n- Domain sign-in succeeds\n- Group Policy applies:\n gpupdate /force\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Hyper-V","Troubleshooting","Windows Server"],"aliases":[]},{"id":3106,"title":"Domain Is Not Available","category":"Active Directory","product":"Windows Server / Active Directory","tags":["Active Directory","Troubleshooting","Windows Server"],"keywords":["domain","not","available","the","specified","either","does","exist","could","contacted","isn","client","server","using","public","dns","controller","offline","network","vpn","unavailable","records","missing","time","difference","required","ports","blocked","netlogon","service","problem"],"errorCode":"","eventId":"","severity":"High","summary":"The specified domain either does not exist or could not be contacted\nThe domain isn't available","rootCause":"- Client or server is using public DNS\n- Domain controller offline\n- Network or VPN unavailable\n- DNS records missing\n- Time difference\n- Required ports blocked\n- Netlogon or DNS service problem","resolution":"1. Verify the network connection.\n2. Confirm DNS points only to authorized AD DNS servers.\n3. Ping the DC by IP and hostname.\n4. Test DNS:\n nslookup domain.local\n nslookup -type=SRV _ldap._tcp.dc._msdcs.domain.local\n5. Verify time:\n w32tm /query /status\n6. Check DNS Server, Netlogon, and Active Directory Domain Services.\n7. Restart Netlogon only if appropriate:\n Restart-Service Netlogon\n8. Re-register DNS records if required:\n ipconfig /registerdns\n9. Review firewall rules and AD-required ports.","emailScript":"Hello,\n\nWe reviewed the issue related to Domain Is Not Available.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- Client or server is using public DNS\n- Domain controller offline\n- Network or VPN unavailable\n- DNS records missing\n- Time difference\n- Required ports blocked\n- Netlogon or DNS service problem\n\nValidation:\n- DC locator succeeds:\n nltest /dsgetdc:domain.local\n- Domain authentication functions\n- Group Policy applies\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Active Directory","Troubleshooting","Windows Server"],"aliases":[]},{"id":3107,"title":"Active Directory Replication Failure","category":"Active Directory","product":"Windows Server / Active Directory","tags":["Active Directory","Troubleshooting","Windows Server"],"keywords":["active","directory","replication","failure","technician","reference","for","diagnosing","and","resolving","local","has","not","recently","received","access","denied","target","principal","name","incorrect","rpc","server","unavailable","naming","context","being","removed","partner","unreachable"],"errorCode":"","eventId":"","severity":"Critical","summary":"Technician reference for diagnosing and resolving active directory replication failure.","rootCause":"- Local DC has not recently received replication\n- Replication access denied\n- Target principal name is incorrect\n- RPC server unavailable\n- Naming context is being removed\n- Replication partner unreachable","resolution":"1. Run:\n repadmin /replsummary\n repadmin /showrepl\n dcdiag /e /v\n2. Verify DNS settings on every domain controller.\n3. Confirm time synchronization.\n4. Test RPC, LDAP, Kerberos, SMB, and DNS connectivity.\n5. Review Directory Service, DFS Replication, DNS Server, and System logs.\n6. Correct stale DNS records, broken secure channels, or network blocks.\n7. Force replication only after addressing the underlying cause:\n repadmin /syncall /AdeP\n8. Do not remove replication metadata without confirming that the DC is permanently decommissioned.","emailScript":"Hello,\n\nWe reviewed the issue related to Active Directory Replication Failure.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- Local DC has not recently received replication\n- Replication access denied\n- Target principal name is incorrect\n- RPC server unavailable\n- Naming context is being removed\n- Replication partner unreachable\n\nValidation:\n- Replication summary shows no failures\n- SYSVOL and NETLOGON shares exist\n- Authentication works through multiple DCs\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Active Directory","Troubleshooting","Windows Server"],"aliases":[]},{"id":3108,"title":"Active Directory Global Catalog Not Found","category":"Active Directory","product":"Windows Server / Active Directory","tags":["Active Directory","Troubleshooting","Windows Server"],"keywords":["active","directory","global","catalog","not","found","web","services","was","unable","determine","server","dns","issue","reachable","marked","time","synchronization","error","firewall","port","database","replication","problem"],"errorCode":"","eventId":"","severity":"Medium","summary":"Active Directory Web Services was unable to determine a global catalog server","rootCause":"- DNS issue\n- No reachable Global Catalog\n- DC not marked as a Global Catalog\n- Time synchronization error\n- Firewall or port issue\n- AD database or replication problem","resolution":"1. Verify DNS and domain controller discovery.\n2. Confirm at least one appropriate DC is configured as a Global Catalog.\n3. Check AD Sites and Services placement and connectivity.\n4. Run:\n nltest /dsgetdc:domain.local /GC\n repadmin /replsummary\n dcdiag /test:dns\n5. Verify time synchronization.\n6. Review AD Web Services, Directory Service, DNS, and System logs.\n7. Repair replication or connectivity issues before changing GC placement.","emailScript":"Hello,\n\nWe reviewed the issue related to Active Directory Global Catalog Not Found.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- DNS issue\n- No reachable Global Catalog\n- DC not marked as a Global Catalog\n- Time synchronization error\n- Firewall or port issue\n- AD database or replication problem\n\nValidation:\n- GC discovery succeeds\n- AD administrative tools connect\n- User authentication and directory searches work\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Active Directory","Troubleshooting","Windows Server"],"aliases":[]},{"id":3109,"title":"DFSR SYSVOL Offline Too Long","category":"Active Directory","product":"Windows Server / Active Directory","tags":["Active Directory","Troubleshooting","Windows Server"],"keywords":["dfsr","sysvol","offline","too","long","9061","the","replicated","folder","has","been","for","disconnected","longer","than","maxofflinetimeindays","stale","data","term","replication","failure","healthy","authoritative","partner","dns","network","isolation"],"errorCode":"","eventId":"","severity":"Critical","summary":"9061 - The replicated folder has been offline for too long","rootCause":"- DC disconnected longer than MaxOfflineTimeInDays\n- Stale SYSVOL data\n- Long-term replication failure\n- No healthy authoritative partner\n- DNS or network isolation","resolution":"1. Treat this as an Active Directory recovery issue, not a normal service restart.\n2. Identify a healthy DC with current SYSVOL.\n3. Run AD replication and DNS diagnostics.\n4. Back up the affected DC or VM.\n5. Determine whether a non-authoritative SYSVOL synchronization is appropriate.\n6. Follow the supported DFSR SYSVOL recovery procedure.\n7. If the DC is no longer trustworthy, demote/rebuild it rather than forcing stale data into replication.\n8. Do not simply increase MaxOfflineTimeInDays to bypass the protection.","emailScript":"Hello,\n\nWe reviewed the issue related to DFSR SYSVOL Offline Too Long.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- DC disconnected longer than MaxOfflineTimeInDays\n- Stale SYSVOL data\n- Long-term replication failure\n- No healthy authoritative partner\n- DNS or network isolation\n\nValidation:\n- DFSR Event Log confirms successful initialization\n- SYSVOL and NETLOGON are shared\n- repadmin and dcdiag complete without related failures\n- Group Policy replicates correctly\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Active Directory","Troubleshooting","Windows Server"],"aliases":[]},{"id":3110,"title":"VSS Writers Failed","category":"Backups","product":"Windows Server / VSS","tags":["Backups","Troubleshooting","Windows Server"],"keywords":["vss","writers","failed","one","more","volume","shadow","copy","service","are","state","writer","specific","stopped","hung","backup","job","interrupted","insufficient","disk","space","provider","conflict","server","pending","reboot","application","database","issue"],"errorCode":"","eventId":"","severity":"High","summary":"One or more Volume Shadow Copy Service writers are in a failed state","rootCause":"- Writer-specific service stopped or hung\n- Backup job interrupted\n- Insufficient disk space\n- VSS provider conflict\n- Server pending reboot\n- Application or database issue","resolution":"1. Check writer status:\n vssadmin list writers\n2. Record the failed writer and its error.\n3. Check free space on protected and shadow-storage volumes.\n4. Review VSS, VolSnap, application, SQL, NTDS, DFSR, or IIS logs as applicable.\n5. Restart the service associated with the failed writer when operationally safe.\n6. A basic VSS restart may be attempted when appropriate:\n net stop vss\n net start vss\n7. Recheck:\n vssadmin list writers\n8. Install approved Windows and backup-software updates.\n9. Reboot the server during an approved window if writers remain failed.\n10. Retry and verify the backup.","emailScript":"Hello,\n\nWe reviewed the issue related to VSS Writers Failed.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- Writer-specific service stopped or hung\n- Backup job interrupted\n- Insufficient disk space\n- VSS provider conflict\n- Server pending reboot\n- Application or database issue\n\nValidation:\n- Writers show Stable and No error\n- Backup completes\n- No new VSS or VolSnap event is generated\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Backups","Troubleshooting","Windows Server"],"aliases":[]},{"id":3111,"title":"NTFS File System Corruption","category":"Windows Server","product":"Windows Server","tags":["Windows Server","Troubleshooting","Windows Server"],"keywords":["ntfs","file","system","corruption","detected","volume","corrupt","unavailable","failed","failing","physical","disk","bad","sectors","controller","raid","issue","unexpected","power","loss","storage","disconnect","metadata","damage"],"errorCode":"","eventId":"","severity":"Critical","summary":"NTFS file system corruption detected\nVolume is corrupt or unavailable","rootCause":"- Failed or failing physical disk\n- Bad sectors\n- Controller or RAID issue\n- Unexpected power loss\n- Storage disconnect\n- File system metadata damage","resolution":"1. Avoid unnecessary writes to the affected volume.\n2. Verify backups immediately.\n3. Check RAID, controller, iDRAC/iLO, SMART, and storage alerts.\n4. Review System log for Disk, Ntfs, StorPort, and controller events.\n5. Run an online scan when appropriate:\n chkdsk X: /scan\n6. Schedule offline repair only after backup and outage planning:\n chkdsk X: /f\n7. Use /r only when bad-sector analysis is required and adequate downtime is available:\n chkdsk X: /r\n8. Replace failing physical hardware before trusting the repaired filesystem.\n9. For a VHDX, check both guest NTFS and host storage health.","emailScript":"Hello,\n\nWe reviewed the issue related to NTFS File System Corruption.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- Failed or failing physical disk\n- Bad sectors\n- Controller or RAID issue\n- Unexpected power loss\n- Storage disconnect\n- File system metadata damage\n\nValidation:\n- CHKDSK completes without unresolved errors\n- RAID and SMART status are healthy\n- No recurring Disk or NTFS events\n- Application data is accessible\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Windows Server","Troubleshooting","Windows Server"],"aliases":[]},{"id":3112,"title":"Predictive Disk Failure","category":"Windows Server","product":"Windows Server","tags":["Windows Server","Troubleshooting","Windows Server"],"keywords":["predictive","disk","failure","smart","alert","reported","for"],"errorCode":"","eventId":"","severity":"Critical","summary":"SMART alert or predictive failure reported for a disk","rootCause":"The condition can result from configuration, resource, storage, service, or connectivity problems affecting Windows Server.","resolution":"1. Identify the exact physical disk, controller, enclosure, and slot.\n2. Confirm the array type and redundancy state.\n3. Verify that a current backup exists.\n4. If the disk is part of a healthy redundant array, follow the hardware vendor's offline, replace, and rebuild procedure.\n5. If the disk is non-redundant, back up data before removing anything.\n6. If it is a hot spare, follow the vendor procedure to unassign and replace it.\n7. Monitor the rebuild until complete.\n8. Check for additional predictive failures before closing the incident.","emailScript":"Hello,\n\nWe reviewed the issue related to Predictive Disk Failure.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\nThe condition can result from configuration, resource, storage, service, or connectivity problems affecting Windows Server.\n\nValidation:\n- Array shows Optimal or Healthy\n- Rebuild completes\n- No predictive failure remains\n- Host and VMs remain stable\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Windows Server","Troubleshooting","Windows Server"],"aliases":[]},{"id":3113,"title":"Critically Low Disk Space","category":"Windows Server","product":"Windows Server","tags":["Windows Server","Troubleshooting","Windows Server"],"keywords":["critically","low","disk","space","technician","reference","for","diagnosing","and","resolving","growing","logs","windows","update","cache","old","profiles","application","dumps","backup","files","unmerged","avhdx","vss","shadow","copies","database","growth","recycle","bin","temporary"],"errorCode":"","eventId":"","severity":"Low","summary":"Technician reference for diagnosing and resolving critically low disk space.","rootCause":"- Growing logs\n- Windows Update cache\n- Old profiles\n- Application dumps\n- Backup files\n- Unmerged AVHDX files\n- VSS shadow copies\n- Database growth\n- Recycle Bin or temporary files","resolution":"1. Determine which volume is affected.\n2. Identify the largest folders and recent growth.\n3. Check for AVHDX or checkpoint growth before deleting ordinary files.\n4. Review VSS usage:\n vssadmin list shadowstorage\n5. Clear approved temporary files and obsolete logs.\n6. Move or archive application data according to retention requirements.\n7. Expand the VHDX and guest partition when cleanup is insufficient.\n8. Set monitoring thresholds and investigate recurring growth.","emailScript":"Hello,\n\nWe reviewed the issue related to Critically Low Disk Space.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- Growing logs\n- Windows Update cache\n- Old profiles\n- Application dumps\n- Backup files\n- Unmerged AVHDX files\n- VSS shadow copies\n- Database growth\n- Recycle Bin or temporary files\n\nValidation:\n- Adequate free-space percentage restored\n- Application services remain functional\n- Checkpoint and backup chains are healthy\n- Alert clears\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Windows Server","Troubleshooting","Windows Server"],"aliases":[]},{"id":3114,"title":"High CPU Utilization","category":"Windows Server","product":"Windows Server","tags":["Windows Server","Troubleshooting","Windows Server"],"keywords":["high","cpu","utilization","average","processor","queue","length","elevated","resource","intensive","application","too","many","simultaneous","processes","backup","scan","update","scheduled","task","faulty","unoptimized","service","malware","insufficient","allocation","host","contention"],"errorCode":"","eventId":"","severity":"Low","summary":"Average processor utilization is high\nProcessor queue length is elevated","rootCause":"- Resource-intensive application\n- Too many simultaneous processes\n- Backup, scan, update, or scheduled task\n- Faulty or unoptimized service\n- Malware\n- Insufficient CPU allocation\n- Host contention","resolution":"1. Identify the highest CPU processes.\n2. Determine whether the condition is sustained or temporary.\n3. Review recently installed updates and application changes.\n4. Check scheduled backups, scans, and maintenance tasks.\n5. Run an approved security scan.\n6. Restart only the affected noncritical service when safe.\n7. Move intensive tasks outside business hours.\n8. For a VM, check CPU pressure on both guest and host.\n9. Increase vCPU only after confirming host capacity and application need.","emailScript":"Hello,\n\nWe reviewed the issue related to High CPU Utilization.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- Resource-intensive application\n- Too many simultaneous processes\n- Backup, scan, update, or scheduled task\n- Faulty or unoptimized service\n- Malware\n- Insufficient CPU allocation\n- Host contention\n\nValidation:\n- CPU usage and queue length return to normal\n- Application response improves\n- No underlying service or malware alert remains\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Windows Server","Troubleshooting","Windows Server"],"aliases":[]},{"id":3115,"title":"High Memory Utilization","category":"Windows Server","product":"Windows Server","tags":["Windows Server","Troubleshooting","Windows Server"],"keywords":["high","memory","utilization","technician","reference","for","diagnosing","and","resolving","leak","database","cache","growth","too","many","user","sessions","backup","security","process","insufficient","assigned","ram","host","pressure","incorrect","dynamic","configuration"],"errorCode":"","eventId":"","severity":"Low","summary":"Technician reference for diagnosing and resolving high memory utilization.","rootCause":"- Memory leak\n- Database cache growth\n- Too many user sessions\n- Backup or security process\n- Insufficient assigned RAM\n- Host memory pressure\n- Incorrect Dynamic Memory configuration","resolution":"1. Identify top memory-consuming processes.\n2. Compare current usage with the server's normal baseline.\n3. Check application logs for leaks or failures.\n4. Log off stale RDS sessions when approved.\n5. Restart only the affected service when operationally safe.\n6. Confirm pagefile configuration and available disk space.\n7. For VMs, review Startup, Minimum, Maximum, and assigned memory.\n8. Add memory only after confirming the host has sufficient capacity.","emailScript":"Hello,\n\nWe reviewed the issue related to High Memory Utilization.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- Memory leak\n- Database cache growth\n- Too many user sessions\n- Backup or security process\n- Insufficient assigned RAM\n- Host memory pressure\n- Incorrect Dynamic Memory configuration\n\nValidation:\n- Memory utilization remains stable\n- No excessive paging\n- Application performance returns to normal\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Windows Server","Troubleshooting","Windows Server"],"aliases":[]},{"id":3116,"title":"Windows Service Will Not Start","category":"Windows Server","product":"Windows Server","tags":["Windows Server","Troubleshooting","Windows Server"],"keywords":["windows","service","will","not","start","error","1053","did","respond","timely","fashion","access","denied","dependency","failed","logon","failure","account","password","changed","stopped","corrupt","application","files","port","already","use","insufficient","permissions","timeout","during","startup","pending","reboot"],"errorCode":"","eventId":"","severity":"Critical","summary":"- Error 1053\n- Service did not respond in a timely fashion\n- Access denied\n- Dependency service failed\n- Logon failure","rootCause":"- Service account password changed\n- Dependency stopped\n- Corrupt application files\n- Port already in use\n- Insufficient permissions\n- Timeout during startup\n- Pending reboot","resolution":"1. Record the exact service name and error.\n2. Check dependencies:\n sc.exe qc SERVICE-NAME\n3. Check service account status and Log On credentials.\n4. Review System and Application logs.\n5. Check whether the executable path exists.\n6. Check for port or file locks.\n7. Start the dependency services.\n8. Repair or reinstall the associated application if files are damaged.\n9. Increase ServicesPipeTimeout only when vendor guidance confirms slow initialization.","emailScript":"Hello,\n\nWe reviewed the issue related to Windows Service Will Not Start.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- Service account password changed\n- Dependency stopped\n- Corrupt application files\n- Port already in use\n- Insufficient permissions\n- Timeout during startup\n- Pending reboot\n\nValidation:\n- Service reaches Running\n- It remains running after reboot\n- Dependent application functions normally\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Windows Server","Troubleshooting","Windows Server"],"aliases":[]},{"id":3117,"title":"Service Stuck Starting Or Stopping","category":"Windows Server","product":"Windows Server","tags":["Windows Server","Troubleshooting","Windows Server"],"keywords":["service","stuck","starting","stopping","technician","reference","for","diagnosing","and","resolving"],"errorCode":"","eventId":"","severity":"Low","summary":"Technician reference for diagnosing and resolving service stuck starting or stopping.","rootCause":"The condition can result from configuration, resource, storage, service, or connectivity problems affecting Windows Server.","resolution":"1. Query the service:\n sc.exe queryex SERVICE-NAME\n2. Record the PID.\n3. Validate that the PID belongs to the intended service.\n4. Attempt a normal stop:\n Stop-Service -Name \"SERVICE-NAME\"\n5. If it remains hung and impact is understood:\n taskkill /PID 1234 /F\n6. Start the service again.\n7. Review logs to identify why it hung.\n8. Reboot the server during a maintenance window if the service cannot be safely terminated.","emailScript":"Hello,\n\nWe reviewed the issue related to Service Stuck Starting Or Stopping.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\nThe condition can result from configuration, resource, storage, service, or connectivity problems affecting Windows Server.\n\nValidation:\n- Service changes state normally\n- Application operates\n- Hang does not recur\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Windows Server","Troubleshooting","Windows Server"],"aliases":[]},{"id":3118,"title":"Multiple Monitored Services Down","category":"Windows Server","product":"Windows Server","tags":["Windows Server","Troubleshooting","Windows Server"],"keywords":["multiple","monitored","services","down","technician","reference","for","diagnosing","and","resolving","server","recently","rebooted","delayed","start","have","not","initialized","dependency","failure","service","account","problem","corruption","network","domain","unavailable","monitoring","agent","has","stale","status"],"errorCode":"","eventId":"","severity":"Critical","summary":"Technician reference for diagnosing and resolving multiple monitored services down.","rootCause":"- Server recently rebooted\n- Delayed-start services have not initialized\n- Dependency failure\n- Service account problem\n- OS corruption\n- Network or domain dependency unavailable\n- Monitoring agent has stale status","resolution":"1. Confirm server uptime and whether a reboot just occurred.\n2. Review each service's startup type and current state:\n Get-Service | Where-Object Status -ne \"Running\"\n3. Check dependencies and service accounts.\n4. Review System and Application events around the first failure.\n5. Start services individually in dependency order.\n6. Confirm that delayed-start services initialize.\n7. Repair the shared dependency instead of repeatedly restarting every service.\n8. Refresh or restart the monitoring agent if services are healthy but alerts remain stale.","emailScript":"Hello,\n\nWe reviewed the issue related to Multiple Monitored Services Down.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- Server recently rebooted\n- Delayed-start services have not initialized\n- Dependency failure\n- Service account problem\n- OS corruption\n- Network or domain dependency unavailable\n- Monitoring agent has stale status\n\nValidation:\n- Required services remain Running\n- Applications pass functional tests\n- Monitoring status refreshes\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Windows Server","Troubleshooting","Windows Server"],"aliases":[]},{"id":3119,"title":"Windows Update Or Patch Assessment Failure","category":"Patch Management","product":"Windows Server / Windows Update","tags":["Patch Management","Troubleshooting","Windows Server"],"keywords":["windows","update","patch","assessment","failure","failed","extract","installed","missing","patches","error","executing","search","server","execution","timed","out","service","stopped","unhealthy","bits","cache","corruption","proxy","firewall","blockage","wsus","unreachable","wmi","problem","pending","reboot","rmm","patching","agent","issue"],"errorCode":"","eventId":"","severity":"Critical","summary":"- Failed to extract installed or missing patches\n- Error executing search\n- Server execution failed\n- Assessment timed out","rootCause":"- Windows Update service stopped or unhealthy\n- BITS stopped\n- Update cache corruption\n- Proxy or firewall blockage\n- WSUS unreachable\n- WMI problem\n- Pending reboot\n- RMM patching agent issue","resolution":"1. Check pending reboot status.\n2. Check services:\n Windows Update\n BITS\n Cryptographic Services\n3. Confirm Microsoft Update or WSUS connectivity.\n4. Check proxy and firewall rules.\n5. Review WindowsUpdateClient and CBS logs.\n6. Run:\n DISM /Online /Cleanup-Image /RestoreHealth\n sfc /scannow\n7. Reset Windows Update components when corruption is confirmed.\n8. Restart the RMM or patch-assessment service.\n9. Run a new patch scan.","emailScript":"Hello,\n\nWe reviewed the issue related to Windows Update Or Patch Assessment Failure.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- Windows Update service stopped or unhealthy\n- BITS stopped\n- Update cache corruption\n- Proxy or firewall blockage\n- WSUS unreachable\n- WMI problem\n- Pending reboot\n- RMM patching agent issue\n\nValidation:\n- Patch scan completes\n- Available or installed updates are reported correctly\n- Required updates install\n- Server reboots if required\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Patch Management","Troubleshooting","Windows Server"],"aliases":[]},{"id":3120,"title":"Server Reboot Pending After Patching","category":"Patch Management","product":"Windows Server / Windows Update","tags":["Patch Management","Troubleshooting","Windows Server"],"keywords":["server","reboot","pending","after","patching","technician","reference","for","diagnosing","and","resolving"],"errorCode":"","eventId":"","severity":"Low","summary":"Technician reference for diagnosing and resolving server reboot pending after patching.","rootCause":"The condition can result from configuration, resource, storage, service, or connectivity problems affecting Windows Server / Windows Update.","resolution":"1. Confirm the reboot requirement and installed patches.\n2. Check whether the server hosts critical roles or VMs.\n3. Notify affected users and schedule an approved reboot.\n4. For a Hyper-V host, shut down or migrate guests as required.\n5. Reboot the server gracefully.\n6. Confirm all automatic services and applications return.\n7. Run another update assessment.","emailScript":"Hello,\n\nWe reviewed the issue related to Server Reboot Pending After Patching.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\nThe condition can result from configuration, resource, storage, service, or connectivity problems affecting Windows Server / Windows Update.\n\nValidation:\n- No pending-reboot alert\n- Server and application services are healthy\n- Patch assessment succeeds\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Patch Management","Troubleshooting","Windows Server"],"aliases":[]},{"id":3121,"title":"Unexpected Server Restart","category":"Windows Server","product":"Windows Server","tags":["Windows Server","Troubleshooting","Windows Server"],"keywords":["unexpected","server","restart","without","memory","dump","event","kernel","power","6008","shutdown","loss","hard","reset","hypervisor","host","reboot","hardware","failure","bugcheck","with","disabled","unwritable","thermal","issue","ups","storage","motherboard","fault","41"],"errorCode":"","eventId":"41","severity":"High","summary":"- Unexpected restart without memory dump\n- Event ID 41 Kernel-Power\n- Event ID 6008 unexpected shutdown","rootCause":"- Power loss\n- Hard reset\n- Hypervisor or host reboot\n- Hardware failure\n- Bugcheck with dump disabled or unwritable\n- Thermal issue\n- UPS failure\n- Storage or motherboard fault","resolution":"1. Correlate guest, host, UPS, iDRAC/iLO, and facility power logs.\n2. Review:\n System log\n Reliability Monitor\n WHEA events\n BugCheck events\n Kernel-Power events\n3. Check whether the Hyper-V host restarted at the same time.\n4. Verify memory-dump and pagefile configuration.\n5. Check hardware health, temperatures, RAID, firmware, and power supplies.\n6. Review recent patches, drivers, and configuration changes.\n7. Confirm UPS communication and runtime.\n8. Monitor for recurrence.","emailScript":"Hello,\n\nWe reviewed the issue related to Unexpected Server Restart.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- Power loss\n- Hard reset\n- Hypervisor or host reboot\n- Hardware failure\n- Bugcheck with dump disabled or unwritable\n- Thermal issue\n- UPS failure\n- Storage or motherboard fault\n\nValidation:\n- Root cause is documented\n- No continuing hardware alarm\n- Dump collection is configured\n- Server remains stable\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Windows Server","Troubleshooting","Windows Server"],"aliases":["41"]},{"id":3122,"title":"BSOD Or Restart With Memory Dump","category":"Windows Server","product":"Windows Server","tags":["Windows Server","Troubleshooting","Windows Server"],"keywords":["bsod","restart","with","memory","dump","technician","reference","for","diagnosing","and","resolving"],"errorCode":"","eventId":"","severity":"Low","summary":"Technician reference for diagnosing and resolving bsod or restart with memory dump.","rootCause":"The condition can result from configuration, resource, storage, service, or connectivity problems affecting Windows Server.","resolution":"1. Record the bugcheck code and parameters.\n2. Preserve files from:\n C:\\Windows\\Minidump\n C:\\Windows\\MEMORY.DMP\n3. Review the System log and Reliability Monitor.\n4. Confirm the dump file was written successfully.\n5. Check recently changed drivers, firmware, antivirus, storage agents, and backup tools.\n6. Update or roll back the confirmed faulty component.\n7. Run hardware diagnostics when WHEA or memory errors appear.\n8. Avoid declaring a driver as the cause based only on the visible module name without dump analysis.","emailScript":"Hello,\n\nWe reviewed the issue related to BSOD Or Restart With Memory Dump.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\nThe condition can result from configuration, resource, storage, service, or connectivity problems affecting Windows Server.\n\nValidation:\n- No repeat bugcheck\n- Driver and firmware versions are documented\n- Hardware diagnostics pass\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Windows Server","Troubleshooting","Windows Server"],"aliases":[]},{"id":3123,"title":"WMI Repository Inconsistent","category":"Windows Server","product":"Windows Server","tags":["Windows Server","Troubleshooting","Windows Server"],"keywords":["wmi","repository","inconsistent","not","consistent","queries","fail","hyper","manager","management","tools","cannot","enumerate","data"],"errorCode":"","eventId":"","severity":"Low","summary":"WMI repository is not consistent\nWMI queries fail\nHyper-V Manager or management tools cannot enumerate data","rootCause":"The condition can result from configuration, resource, storage, service, or connectivity problems affecting Windows Server.","resolution":"1. Confirm the issue with:\n winmgmt /verifyrepository\n2. Restart the WMI service only if operationally safe.\n3. Attempt a salvage:\n winmgmt /salvagerepository\n4. Re-run:\n winmgmt /verifyrepository\n5. Use repository reset only as a controlled last resort because it can affect management agents and providers.\n6. Reinstall or repair affected WMI providers if only one product is failing.\n7. Restart and test RMM, Hyper-V, backup, and monitoring tools.","emailScript":"Hello,\n\nWe reviewed the issue related to WMI Repository Inconsistent.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\nThe condition can result from configuration, resource, storage, service, or connectivity problems affecting Windows Server.\n\nValidation:\n- Repository reports consistent\n- WMI queries work\n- Hyper-V and RMM inventory returns\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Windows Server","Troubleshooting","Windows Server"],"aliases":[]},{"id":3124,"title":"VHDX Corrupted Or Unreadable","category":"Hyper-V","product":"Windows Server / Hyper-V","tags":["Hyper-V","Troubleshooting","Windows Server"],"keywords":["vhdx","corrupted","unreadable","0x80070570","the","file","directory","and","virtual","disk","cannot","opened","windows","general"],"errorCode":"0x80070570","eventId":"","severity":"Critical","summary":"0x80070570\nThe file or directory is corrupted and unreadable\nVirtual disk cannot be opened","rootCause":"The condition can result from configuration, resource, storage, service, or connectivity problems affecting Windows Server / Hyper-V.","resolution":"1. Stop write activity to the affected storage.\n2. Confirm the host volume and RAID are healthy.\n3. Preserve a copy of the damaged VHDX when possible.\n4. Check the host filesystem before modifying the VHDX.\n5. Inspect the disk:\n Get-VHD -Path \"D:\\Path\\Disk.vhdx\"\n6. Check whether the disk belongs to an AVHDX chain.\n7. Restore from a known-good backup if integrity cannot be established.\n8. Do not use repair or merge operations on the only copy.","emailScript":"Hello,\n\nWe reviewed the issue related to VHDX Corrupted Or Unreadable.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\nThe condition can result from configuration, resource, storage, service, or connectivity problems affecting Windows Server / Hyper-V.\n\nValidation:\n- Disk mounts or VM boots\n- Guest filesystem passes validation\n- Backup succeeds\n- No host storage errors remain\n\n===================================================\n\nAdditional source detail (microsoft_windows_error_code_master_list.txt): Category: WINDOWS GENERAL\nDescription: The file or directory is corrupted and unreadable.\n\nFixes:\n1. Capture the full message, operation, and matching Event Viewer entry.\n2. Verify permissions, paths, services, dependencies, network access, and pending restart state.\n3. Repair the affected component; for Windows corruption run DISM /Online /Cleanup-Image /RestoreHealth, then sfc /scannow.\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt; microsoft_windows_error_code_master_list.txt","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"platforms":["windows"],"vendors":["Windows Server"],"technologies":["Hyper-V","Troubleshooting","Windows Server"],"aliases":["0x80070570"]},{"id":3125,"title":"Backup Snapshot Timeout Or Failure","category":"Backups","product":"Windows Server / VSS","tags":["Backups","Troubleshooting","Windows Server"],"keywords":["backup","snapshot","timeout","failure","technician","reference","for","diagnosing","and","resolving","vss","writer","checkpoint","creation","exceeds","insufficient","disk","space","storage","latency","avhdx","merge","backlog","agent","provider","conflict","integration","service","issue"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for diagnosing and resolving backup snapshot timeout or failure.","rootCause":"- VSS writer failure\n- Checkpoint creation exceeds timeout\n- Insufficient disk space\n- Storage latency\n- AVHDX merge backlog\n- Backup agent or provider conflict\n- VM integration service issue","resolution":"1. Check VSS writers in the guest.\n2. Check Hyper-V checkpoint status on the host.\n3. Confirm free space on both host and guest volumes.\n4. Review backup, VSS, Hyper-V-VMMS, and Hyper-V-Worker logs.\n5. Check for old checkpoints or AVHDX files.\n6. Confirm Hyper-V integration services are current.\n7. Repair the failing writer or application service.\n8. Retry the backup and monitor checkpoint creation and removal.","emailScript":"Hello,\n\nWe reviewed the issue related to Backup Snapshot Timeout Or Failure.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- VSS writer failure\n- Checkpoint creation exceeds timeout\n- Insufficient disk space\n- Storage latency\n- AVHDX merge backlog\n- Backup agent or provider conflict\n- VM integration service issue\n\nValidation:\n- Backup completes\n- Temporary checkpoint is removed\n- AVHDX merge completes\n- Restore point is usable\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Backups","Troubleshooting","Windows Server"],"aliases":[]},{"id":3126,"title":"Time Synchronization Error","category":"Windows Server","product":"Windows Server","tags":["Windows Server","Troubleshooting","Windows Server"],"keywords":["time","synchronization","error","technician","reference","for","diagnosing","and","resolving","kerberos","authentication","failure","domain","logon","expired","not","yet","valid","tokens","replication","problems","certificate","errors","oauth","failures"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for diagnosing and resolving time synchronization error.","rootCause":"- Kerberos authentication failure\n- Domain logon failure\n- Expired or not-yet-valid tokens\n- Replication problems\n- Certificate errors\n- OAuth failures","resolution":"1. Identify the authoritative time design.\n2. On domain members, verify:\n w32tm /query /source\n w32tm /query /status\n3. Confirm the PDC Emulator uses an approved external NTP source.\n4. Confirm other DCs and members follow the domain hierarchy.\n5. For VMs, ensure hypervisor time synchronization does not conflict with domain time.\n6. Correct host time and NTP configuration.\n7. Resynchronize:\n w32tm /resync\n8. Review Time-Service logs.","emailScript":"Hello,\n\nWe reviewed the issue related to Time Synchronization Error.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\n- Kerberos authentication failure\n- Domain logon failure\n- Expired or not-yet-valid tokens\n- Replication problems\n- Certificate errors\n- OAuth failures\n\nValidation:\n- Time source is correct\n- Offset is acceptable\n- Kerberos, replication, and token operations succeed\n\n===================================================","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Windows Server","Troubleshooting","Windows Server"],"aliases":[]},{"id":3127,"title":"General Server Health Commands","category":"Windows Server","product":"Windows Server","tags":["Windows Server","Troubleshooting","Windows Server"],"keywords":["general","server","health","commands","technician","reference","for","diagnosing","and","resolving"],"errorCode":"","eventId":"","severity":"Low","summary":"Technician reference for diagnosing and resolving general server health commands.","rootCause":"The condition can result from configuration, resource, storage, service, or connectivity problems affecting Windows Server.","resolution":"1. Record the exact error and affected system.\n2. Review the relevant Windows and application event logs.\n3. Validate services, storage, networking, and recent changes.\n4. Correct the confirmed cause and verify service health.","emailScript":"Hello,\n\nWe reviewed the issue related to General Server Health Commands.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We will validate the server and confirm when normal service is restored.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work in any affected application.\n2. Do not restart the server or virtual machine unless IT Support directs you to do so.\n3. Note the time and action that produced the issue.\n4. Contact IT Support if service remains unavailable after the recovery notice.","notes":"Common causes:\nThe condition can result from configuration, resource, storage, service, or connectivity problems affecting Windows Server.\n\nValidation:\nConfirm the alert clears and affected services operate normally.","sourceDocument":"WINDOWS SERVER AND HYPER-V VM ERROR.txt","platforms":["windows"],"vendors":["Windows Server"],"technologies":["Windows Server","Troubleshooting","Windows Server"],"aliases":[]},{"id":3128,"title":"Windows 365 Business Cloud PC Setup Failed","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["windows","365","business","cloud","setup","failed","troubleshoot","issues","this","article","provides","troubleshooting","steps","for","the","error","issue","where","takes","longer","than","minutes","after","you","assign","user","license","ensure","that","mobile","device","management","mdm","authority","configuration","set","correctly","depending","whether","plan"],"errorCode":"","eventId":"","severity":"High","summary":"Troubleshoot Windows 365 Business Cloud\nPC setup issues\nThis article provides troubleshooting steps for the \"Setup failed\" error or the issue where the\nsetup takes longer than 90 minutes after you assign the user a license. Ensure that the mobile device management (MDM) authority configuration is set up correctly.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. Ensure that the mobile device management (MDM) authority configuration is set up correctly.\n2. Use Microsoft Intune to manage your Cloud PCs.\n3. make sure that your Mobility (MDM and MAM) settings in Microsoft Entra ID are correctly\n4. Make sure the MDM authority configuration is set\n5. users might see their Cloud PCs fail to complete their setup on the Windows 365 home page.\n6. Check the Intune settings you might have previously set on\n7. user can reset the Cloud PC.\n8. Confirm that the MDM discovery URL is the default for Intune.","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 Business Cloud PC Setup Failed.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Troubleshoot Windows 365 Business Cloud\nPC setup issues\nThis article provides troubleshooting steps for the \"Setup failed\" error or the issue where the\nsetup takes longer than 90 minutes after you assign the user a license.\nEnsure that the mobile device management (MDM) authority configuration is set up correctly.\nDepending on whether you plan to use Microsoft Intune to manage the Cloud PCs, follow the\nappropriate path:\nIf you use or plan to use Microsoft Intune for your Cloud PCs, follow the steps in Path A:\nUse Microsoft Intune to manage your Cloud PCs.\nIf you don't plan to use Microsoft Intune to manage your Cloud PCs, follow the steps in\nPath B: Turn off automatic MDM enrollment and Intune enrollment in Organization\nSettings.\nIf you already use Microsoft Intune, or plan to use it to manage your Windows 365 Cloud PCs,\nmake sure that your Mobility (MDM and MAM) settings in Microsoft Entra ID are correctly\nconfigured.\n1. In the Azure portal, go to the Microsoft Entra Overview page.\n2. In the left navigation pane, under Manage, select Mobility (MDM and MAM), and then\nselect Microsoft Intune.\n） Important\nYou must be a Global Administrator to do most tasks described in this article. If other\nadmin roles can be used for a specific procedure, they're noted before the procedure. If\nyou don't have permission to sign in to or access parts of the Azure portal, contact your IT\nadministrator. For more information about Azure rules, see Microsoft Entra built-in roles.\nTo learn more about the Azure portal, see Azure portal overview.\nMake sure the MDM authority configuration is set\nup correctly\nPath A: Use Microsoft Intune to manage your Cloud PCs\n3. On the Configure page, next to MDM user scope, select Some or All, and then select\nSave.\n4. In the left navigation pane, under Manage, select Mobility (MDM and MAM) > Microsoft\nIntune Enrollment, and then repeat step 3.\nIf the automatic enrollment of new Cloud PCs into the Microsoft Intune setting is turned on,\nusers might see their Cloud PCs fail to complete their setup on the Windows 365 home page.\nConsult the following table for how to troubleshoot these issues:\nError Troubleshooting steps\nTo complete the setup, ask your\nadministrator to update policy settings\nin Microsoft Intune to enroll this device.\nCheck the Intune settings you might have previously set on\nyour tenant. For more information, see Troubleshoot policies\nand profiles. Once the issue is fixed, either you or the user can\nreset the Cloud PC.\nTo complete the setup, ask your\nadministrator to remove restrictions\npreventing Intune from allowing\nWindows enrollment.\nYou might have set up enrollment restrictions on your Intune\ntenant. For more information, see Enrollment restrictions\noverview. Once the restrictions are removed, either you or the\nuser can reset the Cloud PC.\nTo complete the setup, ask your\nadministrator to correct the\nconfiguration of the Mobile Device\nManagement discovery URL in Intune.\nConfirm that the MDM discovery URL is the default for Intune.\nFollow steps 1-4 to set it in Configure automatic MDM\nenrollment. Once the MDM discovery URL is set to the default,\neither you or the user can reset the Cloud PC.\nUsers who are assigned a Cloud PC must have an Intune license assigned to them to receive\nuser policies. The CloudPCBPRT system account doesn't need to be assigned an Intune license.\n1. In the Microsoft Intune admin center, select Users > All Users.\n2. In the All users list, select a user.\n3. On the user Profile page, select Licenses.\n4. On the Licenses page, select Assignments.\n5. Find Intune, select the checkbox, and then select Save. The user account now has the\npermissions to use the service and enroll devices.\nﾉ Expand table\n） Important\nTo assign licenses, you must be a Global or Licensing administrator, or you must have a\nrole with licensing permissions.\n6. Go to Reset your Cloud PCs.\nIf you don't plan to use Microsoft Intune for your Cloud PC management, turn off automatic\nMDM enrollment and clear the Enroll new Cloud PCs in Microsoft Intune checkbox in\nOrganization Settings.\n1. In the Azure portal, go to the Microsoft Entra Overview page.\n2. In the left navigation pane, under Manage, select Mobility (MDM and MAM), and then\nselect Microsoft Intune.\n3. On the Configure page, you see one of two things. If you have a Microsoft Entra ID P1 or\nP2 subscription, select None next to MDM user scope, and then select Save. If you don't\nhave a Microsoft Entra ID P1 or P2 subscription, select Disable.\n4. In the left navigation pane, under Manage, select Mobility (MDM and MAM), and select\nMicrosoft Intune Enrollment.\n5. Go to Reset your Cloud PCs.\n1. On the Windows 365 home page, go to Your organization's Cloud PCs, and then select\nUpdate organization settings.\n2. On the right-hand side, scroll down to Microsoft Intune and clear the Enroll new Cloud\nPCs in Microsoft Intune checkbox.\n3. Select Save at the bottom.\nPath B: Turn off automatic MDM enrollment and Intune\nenrollment in Organization Settings\n） ","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3129,"title":"Windows 365 Business Known Issues","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["windows","365","business","known","issues","the","following","items","are","for","user","tries","use","microsoft","standard","license","their","cloud","they","might","see","error","account","issue","products","found","your","cannot","used","activate","office","shared","computer","scenarios","should","uninstall","version","installed","and","install"],"errorCode":"","eventId":"","severity":"Medium","summary":"Known issues: Windows 365 Business\nThe following items are known issues for Windows 365 Business. If a user tries to use a Microsoft 365 Business Standard license on their Cloud PC, they might\nsee the following error:\nAccount Issue: The products we found in your account cannot be used to activate Office in\nshared computer scenarios.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. Users can manually change their language/locale in the URL for most websites.\n2. Users can manually set their internet search engine's location. For example, on Bing.com users\n3. Sign in to your Cloud PC.\n4. confirm which services work with Windows 365 Business. If you need more information, consult\n5. Make sure that you have the latest version of the Remote Desktop client, which can be found\n6. Remove the syncwindowsetting registry key under the path:\n7. Add the syncwindowsetting registry key with the value 1 under the path:","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 Business Known Issues.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Known issues: Windows 365 Business\nThe following items are known issues for Windows 365 Business.\nIf a user tries to use a Microsoft 365 Business Standard license on their Cloud PC, they might\nsee the following error:\nAccount Issue: The products we found in your account cannot be used to activate Office in\nshared computer scenarios.\nThe user should uninstall the version of Office installed on their Cloud PC and install a new\ncopy from Office.com.\nSome websites that are accessed from a Cloud PC use its IP address to determine how content\nis displayed. Therefore, users might see content based on where the Cloud PC was created,\ninstead of content based on where the user is located.\nThere are two workarounds for this issue:\nUsers can manually change their language/locale in the URL for most websites.\nFor example, in the following URL, change the language/locale from en-us to fr-fr to get the\nFrench version:\nBefore: https://learn.microsoft.com/en-us/microsoft-365/admin/setup/get-started-windows365-business\nMicrosoft 365 Business Standard not activating on\nCloud PCs\nSolution\nSome websites might display the wrong language\nWorkaround\nWorkaround 1: Change the language/locale in URLs\nAfter: https://learn.microsoft.com/fr-fr/microsoft-365/admin/setup/get-started-windows365-business\nUsers can manually set their internet search engine's location. For example, on Bing.com users\ncan visit the Settings menu (in the top-right corner of the site) to manually set the language,\ncountry/region, and location.\nWhen users sign in to their Cloud PCs from Windows 365, the Microsoft Narrator screen\nreader isn't turned on.\nTo turn on Narrator when accessing your Cloud PC from the web interface:\n1. Go to Windows 365.\n2. Sign in to your Cloud PC.\n3. On your keyboard, press Alt+F3+Ctrl, and then press Enter.\nSending outbound email messages directly on port 25 from a Windows 365 Business Cloud PC\nisn't supported. Communication over port TCP/25 is blocked at the Windows 365 Business\nnetwork layer for security reasons.\nIf your email service uses Simple Mail Transfer Protocol (SMTP) for your email client application,\nyou can use its web interface, if available.\nOr you can ask your email service provider to help configure their email client app to use\nsecure SMTP over Transport Layer Security (TLS), which uses a different port.\nWorkaround 2: Set the search engine location\nMicrosoft Narrator screen reader not turned on\nSolution\nSending outbound email messages using port 25\nisn't supported\nSolution\nVirtual Private Network support\nBecause there are many Virtual Private Network (VPN) solutions available, Microsoft can't\nconfirm which services work with Windows 365 Business. If you need more information, consult\nyour VPN provider. For organizations that have advanced networking needs, Windows 365\nEnterprise is recommended. For more information, see Network requirements.\nWhen non-local admin users sign in to a Cloud PC by using an iPad and the Microsoft Remote\nDesktop app, the Start menu and taskbar might be missing from the Windows 11 user\ninterface.\nMake sure that you have the latest version of the Remote Desktop client, which can be found\nfrom Remote Desktop clients for Remote Desktop Services and remote PCs.\nIn addition, you can sign in to the Cloud PC by using Windows 365.\nMany devices registered with Active Directory might have a machine account password that is\nautomatically updated. By default, these passwords are updated every 30 days. This\nautomation applies to hybrid joined PCs but not Microsoft Entra Native PCs.\nThe machine account password is maintained on the Cloud PC. If the Cloud PC is restored to a\npoint that has a previous password stored, the Cloud PC won't be able to sign in to the\ndomain.\nFor more information, see Machine Account Password Process.\nIn a remote desktop session, when you select one position in a text file, the cursor in the Cloud\nPC has some offset with the actual position.\nMissing Start menu and taskbar when using iPad\nand the Remote Desktop app to access a Cloud PC\nSolution\nRestore and automatic rolling credentials\nCursor's visible location is offset from the actual\nposition\nPossible cause\nIn high DPI mode, both the server and Cloud PC browser scale the cursor. This conflict results\nin an offset between the visible cursor position and the actual cursor focus.\nTurn off high DPI mode.\nOutlook only downloads one month of previous mail, which can't be changed in Outlook\nsettings.\n1. Open Registry Editor.\n2. Remove the syncwindowsetting registry key under the path:\n\\HKEY_CURRENT_USER\\SOFTWARE\\Policies\\Microsoft\\Office\\16.0\\Outlook\\Cached Mode\n3. Add the syncwindowsetting registry key with the value 1 under the path:\n\\HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Cached Mode\nAfter you complete these steps, the default will be one month. However, the download period\ncan be changed in Outlook settings.\nTroubleshoot Windows 365 Business Cloud PC setup issues\nLast updated on 02/12/2026\nSolution\nOutlook only dow","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3130,"title":"Remove Windows 365 Business Cloud PCs From Grace Period","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["remove","windows","365","business","cloud","pcs","from","grace","period","using","graph","explorer","and","microsoft","api","when","license","removed","user","enter","seven","day","before","permanent","removal","this","article","explains","how","manually","reassign","licenses","avoid","provisioning","issues","provides","step","instructions","for","the"],"errorCode":"","eventId":"","severity":"Medium","summary":"Remove Windows 365 Business Cloud PCs\nfrom grace period using Graph Explorer and\nMicrosoft Graph API\nWhen a license is removed from a user, Windows 365 Business Cloud PCs enter a seven-day\ngrace period before permanent removal. This article explains how to manually remove Cloud PCs\nfrom grace to reassign licenses and avoid provisioning issues.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. Remove Windows 365 Business Cloud PCs\n2. Select Sign in to Graph Explorer (top right corner).\n3. Review the results to locate the Cloud PCs you want to remove. Note the id value for each","emailScript":"Hello,\n\nWe reviewed the issue related to Remove Windows 365 Business Cloud PCs From Grace Period.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Remove Windows 365 Business Cloud PCs\nfrom grace period using Graph Explorer and\nMicrosoft Graph API\nWhen a license is removed from a user, Windows 365 Business Cloud PCs enter a seven-day\ngrace period before permanent removal. This article explains how to manually remove Cloud PCs\nfrom grace to reassign licenses and avoid provisioning issues.\nThis article provides step-by-step instructions for using Microsoft Graph Explorer and the\nMicrosoft Graph API to perform this deprovision.\nAdministrator access to your Microsoft 365 tenant\nPermissions to use Microsoft Graph API (Cloud PC administrator or equivalent)\nAccess to Microsoft Graph Explorer\nCloud PCs in inGracePeriod status in your Windows 365 environment\n1. Go to Graph Explorer.\n2. Select Sign in to Graph Explorer (top right corner).\n3. Authenticate by using your administrator credentials and set the tenant.\nSummary\n７ Note\nFor most scenarios, administrators can now end the grace period and deprovision Windows\n365 Business Cloud PCs directly from the Microsoft 365 admin center or Intune by using the\nDeprovision now option. This article describes how to perform the same action by using\nMicrosoft Graph and is intended for automation or advanced troubleshooting scenarios.\nPrerequisites\nStep 1: Sign in to Graph Explorer\n1. In the query box, set the following GET request:\nHTML\n2. In Graph Explorer, select Modify Permissions.\n3. Consent to the following permissions for your session:\nCloudPC.Read.All\nCloudPC.ReadWrite.All\n4. If not already granted, select Consent to add these permissions.\n5. Select Run Query.\n6. Review the results to locate the Cloud PCs you want to remove. Note the id value for each\nrelevant Cloud PC.\n1. For each Cloud PC, send a POST request to remove it from grace. In the query box, select\nPOST and use the following request:\nHTML\n2. Replace {cloudPCId} by using the actual ID of the Cloud PC. For example:\nHTML\n3. Leave the request body empty.\n4. Select Run Query.\nStep 2: Identify Cloud PCs in grace period\nhttps://graph.microsoft.com/beta/deviceManagement/virtualEndpoint/cloudPCs?\n$filter=status eq 'inGracePeriod'\nStep 3: Remove a Cloud PC from grace\nhttps://graph.microsoft.com/beta/deviceManagement/virtualEndpoint/cloudPCs/{cloud\nPCId}/endGracePeriod\nhttps://graph.microsoft.com/beta/deviceManagement/virtualEndpoint/cloudPCs/4b18de\n4b-ab05-4059-8c61-0323a7df4ced/endGracePeriod\n5. If successful, you receive a No Content - 204 response.\n1. To confirm removal from grace, repeat the GET request from Step 3.\n2. The Cloud PC shouldn't appear with status eq 'inGracePeriod'.\nIf you receive a permissions error, verify that you have the correct roles and all necessary\npermissions are consented.\nChanges made through the Graph API might take a few minutes to reflect in the Windows\n365 portal.\nRemoving a Cloud PC from grace permanently deletes the Cloud PC and any associated\nuser data.\nMicrosoft Graph Cloud PC Documentation\nList cloudPCs\ncloudPC: endGracePeriod\nLast updated on 06/29/2026\nStep 4: Verify removal\nTroubleshooting and notes\nMore information","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3131,"title":"Resize a Windows 365 Business Cloud PC","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["resize","windows","365","business","cloud","you","can","use","this","remote","action","modify","the","following","ways","upgrade","ram","cpu","and","storage","size","downgrade","applies","supported","versions","preserves","user","disk","data","single","consider","resizing","when","needs","changes","components","more","vcpu","cores","run"],"errorCode":"","eventId":"","severity":"Medium","summary":"You can use this remote action to modify\na Cloud PC in the following ways:\nUpgrade the RAM, CPU, and storage size of a Cloud PC. Downgrade the RAM and CPU of a Cloud PC.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. additional Cloud PCs, don't try to manually assign licenses.\n2. Sign in to the User Details Panel - Microsoft 365 admin center, and then select the user\n3. Select one of the available options. The list of options is based on your inventory's available\n4. Review the results of the Resize action.","emailScript":"Hello,\n\nWe reviewed the issue related to Resize a Windows 365 Business Cloud PC.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Resize a Windows 365 Business Cloud PC\nApplies to: Supported versions of Windows 365\nThe Resize remote action preserves user and disk data. You can use this remote action to modify\na Cloud PC in the following ways:\nUpgrade the RAM, CPU, and storage size of a Cloud PC.\nDowngrade the RAM and CPU of a Cloud PC.\nResize a single Cloud PC.\nConsider resizing a Cloud PC when a user needs changes in the following components:\nMore RAM and vCPU cores to run CPU-intensive applications.\nMore disk space for storing files.\nLess RAM and fewer vCPU cores to run their current workload applications.\nThe following Business Cloud PC licenses support the Resizing remote action:\nDirect licenses.\nPaid, preview, and trial licenses.\nSingle device operations.\nDuring the resizing process, the Windows 365 service automatically unassigns the original license\nand assigns the new license on behalf of the administrator. To avoid accidentally creating\n） Important\nYou can't use the Resize remote action to downsize disk space.\nYou can't use the Resize remote action on Cloud PCs that use Graphical Processing\nUnits (GPU Cloud PCs). Although GPU Cloud PCs might show up in the resize flow,\ntrying to resize a GPU Cloud PC results in an error.\n７ Note\nThese operations don't require you to reprovision the Cloud PC.\nResizing and licenses\nadditional Cloud PCs, don't try to manually assign licenses.\nTo resize a Cloud PC that uses a direct-assigned license, you have to belong to the Windows\n365 Administrator role. Alternatively, you can use a custom role that includes the\npermissions of this built-in role.\nBefore you use the Resize remote action, make sure that your license inventory includes\navailable licenses for the resized Cloud PC configuration. To request more licenses, contact\nyour procurement admin. You can also purchase licenses from one of the available channels,\nsuch EA, CSP, MCA, and Web Direct.\nThe resizing action disconnects the user from their session. This process might cause the\nloss of any unsaved work. To avoid such disruptions, before you begin any resizing action,\ncoordinate with the end users. Contact them and instruct them to save their work and sign\nout, and that their Cloud PCs might be offline for 15 to 20 minutes. After they've signed out,\nbegin the resizing action.\n1. Sign in to the User Details Panel - Microsoft 365 admin center, and then select the user\nwhose Cloud PC that you want to resize.\n2. In the user's Properties, select Devices > Resize.\nPrerequisites\nHow to resize a Windows 365 Business Cloud PC\n3. Select one of the available options. The list of options is based on your inventory's available\nlicenses.\n4. Select Resize.\nResizing can take from 15 to 20 minutes. You can monitor the status in the Windows 365\nprovisioning blade.\n5. Review the results of the Resize action.\nIf some listed devices are marked as \"Resize not supported,\" those devices aren't resized.\nDuring a bulk resize operation, if some devices can't be resized, the operation continues for\nthe other devices. To identify issues, review any status messages and details After you\nresolve the issue, you can try to resize the affected devices again.\nLast updated on 02/12/2026","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3132,"title":"AI-Enabled Cloud PC Known Issues","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["enabled","cloud","known","issues","your","account","and","device","meet","those","requirements","review","the","following","topics","learn","whether","issue","documented","after","you","enable","background","processes","might","run","for","hours","before","supported","features","are","ready","use","applies","versions","windows","365","isn","working"],"errorCode":"","eventId":"","severity":"Medium","summary":"If your account and your device meet those\nrequirements, review the following topics to learn whether your issue is documented. After you AI-enable your Cloud PC, background processes might run for 24-48 hours before\nthe supported AI features are ready to use.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. Make sure that the following features aren't selected. If any of them are selected, clear\n2. configured to display icons instead of thumbnails.\n3. Select Start and Open Settings.\n4. Go to System > Performance.\n5. Additional help for AI-enabled Cloud PC issues","emailScript":"Hello,\n\nWe reviewed the issue related to AI-Enabled Cloud PC Known Issues.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"AI-enabled Cloud PC known issues\nApplies to: ✅ Supported versions of Windows 365\nIf your Cloud PC isn't working correctly, first make sure that you've satisfied all the minimum\nrequirements for artificial intelligence (AI) features. If your account and your device meet those\nrequirements, review the following topics to learn whether your issue is documented.\nAfter you AI-enable your Cloud PC, background processes might run for 24-48 hours before\nthe supported AI features are ready to use.\nIf AI-enabled features aren't available after this time, restart your Cloud PC and check for\nWindows updates.\nAfter you install a Windows update, the sparkles might disappear from the magnifying glass\nicon.\nTo restore the icon, select the Windows search box. If the sparkles are still missing, restart your\nCloud PC.\nAfter you install a Windows update, AI features might not be available.\nTo restore all AI-enabled features, restart your Cloud PC.\nSearch results might take time to load in the All tab of the Windows search box.\nAI-enabled status activation time\nSparkles missing from Windows search box after\nyou install a Windows update\nAI features missing after you install a Windows\nupdate\nSemantic Search results don't appear in the\nWindows search \"All\" tab\nIf search results don't appear on your first search attempt, repeat the search. You might have to\nrepeat the search multiple times to see the full results.\nIf Semantic File Search isn't working, make sure that the Cloud PC doesn't use nested\nvirtualization.\nTo check this setting, and disable it if it's necessary, follow these steps:\n1. Press Windows logo key+R, and then enter control panel.\n2. In the Control Panel search bar, enter Turn Windows features on or off.\n3. Make sure that the following features aren't selected. If any of them are selected, clear\ntheir checkboxes.\nVirtual Machine Platform\nWindows Hypervisor Platform\nHyper-V\nHyper-V Management Tools\nHyper-V GUI Management Tools\nHyper-V Module for Windows PowerShell\nHyper-V Platform\nHyper-V Hypervisor\nHyper-V Services\n4. To apply the changes, select OK, and then restart your Cloud PC.\nIn some environments, the Click-to-Do keyboard shortcut may not launch the Click-to-Do\nexperience as expected.\nThis can occur when:\nUsing a Cloud PC in Windowed mode\nAccessing a Cloud PC from the Mac Client\nSemantic File Search doesn't work on a Cloud PC\nthat uses nested virtualization\nClick-to-Do keyboard shortcut may not work in\ncertain scenarios\nYou can still use Click-to-Do by manually launching it from the Start menu. Select Start, search\nfor Click-to-Do, and open the app from search results.\nIn some cases, thumbnail previews may not appear for files returned in AI-enabled search\nexperiences on Cloud PCs. This issue may occur when system performance settings are\nconfigured to display icons instead of thumbnails.\nWorkaround: To restore thumbnail previews:\n1. Select Start and Open Settings.\n2. Go to System > Performance.\n3. Select Visual Effects.\n4. Turn on Show thumbnails instead of icons.\n5. Restart your Cloud PC.\nIf you're experiencing issues that aren't covered in this article, you can contact Microsoft\nSupport by submitting a support request through the Microsoft 365 admin center. Get support\n– Microsoft 365 admin\nLast updated on 03/27/2026\nThumbnail previews may not appear in search\nresult\nAdditional help for AI-enabled Cloud PC issues","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3133,"title":"Azure Network Connection Health Checks","category":"Networking","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["azure","network","connection","health","checks","the","are","periodically","run","make","sure","that","cloud","provisioning","successful","end","user","experiences","optimal","unique","feature","windows","365","anc","tab","every","created","displays","status","this","helps","you","determine","whether","new","pcs","can","expected","provision","successfully"],"errorCode":"","eventId":"","severity":"Medium","summary":"The\nhealth checks are periodically run to make sure that:\nCloud PC provisioning is successful. End-user Cloud PC experiences are optimal.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. Checks successful: All health checks passed. The ANC is ready for use.\n2. Checks successful with warnings: All critical health checks passed. However at least one\n3. use ANCs with this status.\n4. Checks failed: One or more required checks failed. An ANC can't be used if it's in a failed","emailScript":"Hello,\n\nWe reviewed the issue related to Azure Network Connection Health Checks.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Azure network connection health checks\nA unique feature of Windows 365 is the Azure network connection (ANC) health checks. The\nhealth checks are periodically run to make sure that:\nCloud PC provisioning is successful.\nEnd-user Cloud PC experiences are optimal.\nIn the Azure network connection tab, every ANC created displays a status. This status helps\nyou determine whether new Cloud PCs can be expected to provision successfully, and whether\nexisting end-users are having an optimal Cloud PC experience.\nStatuses include:\nRunning checks: The health checks are currently running. The ANC list view automatically\nrefreshes every five minutes. Wait for the checks to complete before attempting to assign\nit to a provisioning policy.\nChecks successful: All health checks passed. The ANC is ready for use.\nChecks successful with warnings: All critical health checks passed. However at least one\nnoncritical check might have issues. An example of a check that might trigger this state is\nthe Microsoft Entra hybrid join sync check. Microsoft Entra hybrid join sync can take up to\n90 minutes. Therefore, we checked much of the Microsoft Entra hybrid join sync service\nbut couldn't confirm that the device sync succeeded until later. Provisioning policies can\nuse ANCs with this status.\nChecks failed: One or more required checks failed. An ANC can't be used if it's in a failed\nstate. Resolve the underlying issue and retry the health checks.\nInactive: The ANC is inactive and health checks are paused. Reactivate the ANC to restart\nthe health checks. After the health checks are passed, the ANC is ready for use.\nEvery failed ANC or success with a warning error state includes the technical details behind the\nfailure. Select the View details link for each failed check to view more information on the\nfailure. After you fix the underlying issue, retry the health check to rerun the tests. To retry the\nhealth check, you must have the Intune Administrator or Windows 365 Administrator role.\nAzure network connection status\nStatus error details\nDNS can resolve Active Directory domain: Ensure that the Service Location (SRV) locator\nresource records for a domain controller can be located via DNS. For more information,\nsee Verify that SRV Domain Name System (DNS) records have been created.\nActive directory domain join: Confirm that the domain join action using the credentials,\ndomain, and Organizational Unit (OU) provided on the ANC configuration is successful.\nFailures in this check can occur if the password has been changed.\nEndpoint connectivity: Connectivity to the required URL/endpoints.\nMicrosoft Entra device sync (warning): Device ID sync is enabled on the Microsoft Entra\ntenant, and the computer object is being synced within 90 minutes.\nAzure subnet IP address usage: Sufficient IP addresses are available in the provided\nAzure subnet.\nAzure tenant readiness: The defined Azure subscription is enabled and ready for use. No\nAzure policy restrictions are blocking the creation of Windows 365 resources\nAzure virtual network readiness: The defined virtual network is in a Windows 365supported region.\nFirst party app permissions exist on Azure subscription: Sufficient permissions exist on\nthe Azure subscription.\nFirst party app permissions exist on Azure resource group: Sufficient permissions exist\non the Azure resource group.\nFirst party app permissions exist on Azure virtual network: Sufficient permissions exist\non the Azure virtual network.\nEnvironment and configuration are ready: The underlying infrastructure is ready for\nprovisioning to succeed.\nIntune enrollment restrictions allow Windows enrollment: Verify that Intune enrollment\nrestrictions are configured to allow Windows enrollment.\nLocalization language package readiness: Verify that the operating system and Microsoft\n365 language packages are reachable. Also, verify that the localization package download\nlink is reachable.\nSupported checks\nUDP connection check: Network configuration allows the use of User Datagram Protocol\n(UDP) direct connection (STUN) or relayed connection (TURN).\nSingle sign-on configuration: Determine if the network is properly configured for single\nsign-on to Microsoft Entra hybrid joined Cloud PCs by ensuring a Kerberos Server object\nexists.\nLearn more about Azure network connections.\nLast updated on 02/12/2026\nNext steps","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3134,"title":"Trouhoot Azure Network Connections","category":"Networking","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["trouhoot","azure","network","connections","troubleshoot","the","connection","anc","periodically","checks","your","environment","make","sure","that","all","requirements","are","met","and","healthy","state","any","check","fails","you","can","see","error","messages","microsoft","intune","admin","center","this","guide","contains","some","further","instructions"],"errorCode":"","eventId":"","severity":"Medium","summary":"Troubleshoot Azure network connections\nThe Azure network connection (ANC) periodically checks your environment to make sure that\nall requirements are met and that it's in a healthy state. If any check fails, you can see error\nmessages in the Microsoft Intune admin center.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. Ensure that you can successfully resolve and reach these endpoints through the Azure vNet\n2. used and ensure that any firewall, proxy, or other Network services employed within the\n3. Make sure that your Microsoft Entra computer objects appear in Microsoft Entra ID quickly. We\n4. Make sure that sufficient IP address allocation is available for the number of Cloud PCs you\n5. Check the subnet in the Azure virtual network. It should have enough address space\n6. Make sure there are enough addresses to handle three provisioning retries, each of which\n7. Remove any unused virtual network interface cards (vNICs). It's best to use a dedicated\n8. Sign in to the Azure portal and make sure that the Azure subscription is enabled, valid, and","emailScript":"Hello,\n\nWe reviewed the issue related to Trouhoot Azure Network Connections.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Troubleshoot Azure network connections\nThe Azure network connection (ANC) periodically checks your environment to make sure that\nall requirements are met and that it's in a healthy state. If any check fails, you can see error\nmessages in the Microsoft Intune admin center. This guide contains some further instructions\nfor troubleshooting issues that might cause checks to fail.\nWhen a Cloud PC is provisioned, it's automatically joined to the provided domain. To test the\ndomain join process, a domain computer object is created in the defined organizational unit\n(OU) with a name similar to \"CPC-Hth\" every time Windows 365 health checks are run. These\ncomputer objects are disabled when the health check is complete. Active Directory domain join\nfailure can occur for many reasons. If the domain join fails, make sure that:\nThe domain join user has sufficient permissions to join the domain provided.\nThe domain join user can write to the OU provided.\nThe domain join user isn't restricted in how many computers they can join. For example,\nthe default maximum number of joins per user is 10, and this maximum can affect Cloud\nPC provisioning.\nThe subnet being used can reach a domain controller.\nYou test Add-Computer using the domain join credentials on a virtual machine (VM)\nconnected to the Cloud PC vNet/subnet.\nYou troubleshoot domain join failures like any physical computer in your organization.\nIf you have a domain name that can be resolved on the internet (like contoso.com), make\nsure that your Domain Name System (DNS) servers are configured as internal. Also, make\nsure that they can resolve Active Directory domain DNS records, not your public domain\nname.\nIf you encounter the following errors in your ANC health checks, consider the suggestions in\nthe following two sections to ensure your Azure and on-premises configurations can\nsuccessfully reach the required Windows 365 endpoints:\nInternal Server Error\nInternalServerErrorUnableToRunDscScript\nActive Directory domain join\nSuccessful communication with a domain controller within your organization is essential for\nconfiguring an ANC to allow hybrid domain-joined Cloud PCs. Ensure that the Azure vNet used\nfor your ANC connection has a network route to a domain controller and ensure that your DNS\nsetup can successfully resolve it.\nWinRM is required to complete an ANC setup.\nTo ensure successful provisioning, verify that WinRM isn't restricted to specific IP addresses,\nwhether through a Group Policy Object (GPO) or Microsoft Intune configuration service\nprovider (CSP), for the groups used in your provisioning policies. WinRM should be configured\nto allow network requests from any IP address.\nFor more information, see GPO configurations or Intune CSP.\nDuring ANC configuration, the service needs to download configuration data from various\nMicrosoft endpoints as listed in Network requirements. Failure to reach these endpoints due to\nmisconfigured network settings can lead to a failure. To ensure successful access, Transport\nLayer Security (TLS) inspection should be avoided on any vNET used for ANC connections.\nEnsure that you can successfully resolve and reach these endpoints through the Azure vNet\nused and ensure that any firewall, proxy, or other Network services employed within the\nnetwork allow access to them.\nBefore mobile device management (MDM) enrollment can take place during provisioning, a\nMicrosoft Entra ID object must be present for the Cloud PC. This check is intended to make\nsure that your organizations computer accounts are syncing to Microsoft Entra ID in a timely\nmanner.\nDomain controller line of sight\n７ Note\nThis section only applies to hybrid environments.\nWindows Remote Management (WinRM) requirements for\nANC\nANC Endpoint Access\nMicrosoft Entra device sync\nMake sure that your Microsoft Entra computer objects appear in Microsoft Entra ID quickly. We\nrecommend that they appear within 30 minutes, and no longer than 60 minutes. If the\ncomputer object doesn't arrive in Microsoft Entra ID within 90 minutes, provisioning fails.\nIf provisioning fails, make sure that:\nThe sync period configuration on Microsoft Entra ID is set appropriately. Speak with your\nidentity team to make sure that your directory is syncing fast enough.\nYour Microsoft Entra ID is active and healthy.\nMicrosoft Entra Connect is running correctly, and there are no issues with the sync server.\nYou manually perform an Add-Computer into the OU provided for Cloud PCs. Time how\nlong it takes for that computer object to appear in Microsoft Entra ID.\nAs part of the ANC setup, you're required to provide a subnet to which the Cloud PC connects.\nFor each Cloud PC, provisioning creates a virtual NIC and consumes an IP address from this\nsubnet.\nMake sure that sufficient IP address allocation is available for the number of Cloud PCs you\nexpect to provision. Also, plan enough address space for provisioning failures and potential\ndisaster recovery.\nIf this check fails, make sure that you:\nCheck the subnet in ","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3135,"title":"Windows 365 Link OOBE - An Error Has Occurred","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["windows","365","link","oobe","error","has","occurred","fails","load","with","this","article","helps","resolve","the","during","out","box","experience","when","you","first","turn","loaded","guide","through","process","joining","device","your","microsoft","entra","tenant","and","enrolling","into","intune","management","failure","occurs"],"errorCode":"","eventId":"","severity":"Medium","summary":"Windows 365 Link fails to load OOBE with\nerror \"An error has occurred\"\nThis article helps resolve the error \"An error has occurred\" during the Windows Out of Box\nExperience (OOBE). When you first turn on Windows 365 Link, OOBE is loaded to guide you through the process of\njoining the device to your Microsoft Entra tenant and enrolling the device into Intune\nmanagement.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. When you first turn on Windows 365 Link, OOBE is loaded to guide you through the process of\njoining the device to your Microsoft Entra tenant and enrolling the device into Intune\nmanagement.\n2. If a failure occurs, you might encounter the following error message:\nLet's add your Microsoft account\nAn error has occurred.\n3. This error commonly occurs due to the following reasons:\nJoin permissions\nJoin limits\nEnrollment restrictions\nTo complete OOBE, ensure the following items:\nYou're allowed to join Windows devices to Microsoft Entra.\n4. For configuration details, see\nAllow joining Windows 365 Link to Microsoft Entra.\n5. You don't exceed the maximum number of devices allowed to join Microsoft Entra ID.","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 Link OOBE - An Error Has Occurred.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Windows 365 Link fails to load OOBE with\nerror \"An error has occurred\"\nThis article helps resolve the error \"An error has occurred\" during the Windows Out of Box\nExperience (OOBE).\nWhen you first turn on Windows 365 Link, OOBE is loaded to guide you through the process of\njoining the device to your Microsoft Entra tenant and enrolling the device into Intune\nmanagement. If a failure occurs, you might encounter the following error message:\nLet's add your Microsoft account\nAn error has occurred. Please try again.\nThis error commonly occurs due to the following reasons:\nJoin permissions\nJoin limits\nEnrollment restrictions\nTo complete OOBE, ensure the following items:\nYou're allowed to join Windows devices to Microsoft Entra. For configuration details, see\nAllow joining Windows 365 Link to Microsoft Entra.\nYou don't exceed the maximum number of devices allowed to join Microsoft Entra ID. For\nconfiguration details, see Allow joining Windows 365 Link to Microsoft Entra.\nYou aren't blocked by platform restrictions that prevent you from enrolling Windows\ndevices in Intune management. For configuration details, see Configure enrollment\nrestrictions for Windows 365 Link devices.\nLast updated on 02/12/2026","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3136,"title":"Windows 365 Link OOBE - Something Went Wrong","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["windows","365","link","oobe","something","went","wrong","fails","load","with","error","this","article","helps","resolve","the","during","out","box","experience","when","you","first","turn","loaded","guide","through","process","joining","device","your","microsoft","entra","tenant","and","enrolling","into","intune","management","failure"],"errorCode":"","eventId":"","severity":"Medium","summary":"Windows 365 Link fails to load OOBE with\nerror \"Something went wrong\"\nThis article helps resolve the error \"Something went wrong\" during the Windows Out of Box\nExperience (OOBE). When you first turn on Windows 365 Link, OOBE is loaded to guide you through the process of\njoining the device to your Microsoft Entra tenant and enrolling the device into Intune\nmanagement.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. When you first turn on Windows 365 Link, OOBE is loaded to guide you through the process of\njoining the device to your Microsoft Entra tenant and enrolling the device into Intune\nmanagement.\n2. If a failure occurs, you might encounter the following error message:\nSomething went wrong.\n3. Looks like we can't connect to the URL for your organization's MDM terms of use.\n4. Try\nagain, or contact your system administrator with the problem information from this page.\n5. This error commonly occurs because you aren't configured for automatic enrollment in mobile\ndevice management (MDM) with Intune.","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 Link OOBE - Something Went Wrong.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Windows 365 Link fails to load OOBE with\nerror \"Something went wrong\"\nThis article helps resolve the error \"Something went wrong\" during the Windows Out of Box\nExperience (OOBE).\nWhen you first turn on Windows 365 Link, OOBE is loaded to guide you through the process of\njoining the device to your Microsoft Entra tenant and enrolling the device into Intune\nmanagement. If a failure occurs, you might encounter the following error message:\nSomething went wrong.\nLooks like we can't connect to the URL for your organization's MDM terms of use. Try\nagain, or contact your system administrator with the problem information from this page.\nThis error commonly occurs because you aren't configured for automatic enrollment in mobile\ndevice management (MDM) with Intune. For configuration details, see Automatically enroll\nWindows 365 Link in Intune.\nLast updated on 02/12/2026","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3137,"title":"Windows 365 Flex User Experience Sync Issues","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["windows","365","flex","user","experience","sync","issues","troubleshoot","for","shared","mode","this","article","provides","troubleshooting","steps","the","most","common","that","are","related","environments","when","signs","might","notify","them","they","signed","using","temporary","profile","instead","regular","also","displays","another","notification","states"],"errorCode":"","eventId":"","severity":"Medium","summary":"Troubleshoot User Experience Sync for\nWindows 365 Flex in shared mode\nThis article provides troubleshooting steps for the most common issues that are related to User\nExperience Sync in Windows 365 Flex shared mode environments. When a user signs in, Windows might notify them that they signed in by using a temporary\nprofile instead of the user's regular profile.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. User Experience Sync doesn't support policies that affect write access to fixed or removable\n2. Users receive a warning about a temporary\n3. User Experience Sync provides a limited amount pooled user storage based on a storage\n4. sign in successfully and create their individual user storage. This process results in an exceeded\n5. Used size becomes greater than the Total size\n6. User impact: Existing users who have individual storage can continue to sign in and access\n7. Review contents of the Downloads folder and delete files and folders that aren't needed\n8. Sign in to the Microsoft Intune admin center.","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 Flex User Experience Sync Issues.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Troubleshoot User Experience Sync for\nWindows 365 Flex in shared mode\nThis article provides troubleshooting steps for the most common issues that are related to User\nExperience Sync in Windows 365 Flex shared mode environments.\nWhen a user signs in, Windows might notify them that they signed in by using a temporary\nprofile instead of the user's regular profile. Windows also displays another notification that states,\n\"We can't sign into your account.\" As a result, the user has a temporary user experience.\nTo start troubleshooting this issue, check the status of the user's individual user storage as\ndescribed in the following sections.\nUser Experience Sync doesn't support policies that affect write access to fixed or removable\ndrives. When policies prevent or change access permissions to individual user storage, the drive\nattaches. However, when the user signs in, Windows creates a temporary profile (temporary user\nexperience).\nWindows 365 uses Microsoft managed keys (MMK) to encrypt individual user storage instead of\nusing BitLocker or other products. Review your organization policies that target the Windows 365\nFlex Cloud PCs in shared mode to verify that the following settings aren't enabled.\nUsers receive a warning about a temporary\nuser experience\n７ Note\nA temporary profile is a non-persistent Windows user profile that Windows creates when the\nsystem can't load or create the user's regular profile. The temporary profile provides basic\nfunctionality, but any changes that are made during the session (such as changes to settings,\nchanges to files, or customizations) are discarded when the user signs out. Users see a\nnotification that they signed in by using a temporary profile, and their desktop and Start\nmenu use default Windows settings instead of their personalized configuration.\nPolicies prevent access to individual user storage\nPolicy Setting\nWindows Component\\BitLocker Drive Encryption\\Fixed\nData Drives\nDeny write access to fixed data drives not\nprotected by BitLocker\nWindows Component\\BitLocker Drive\nEncryption\\Removable Data Drives\nDeny write access to removable drives not\nprotected by BitLocker\nDuring the Windows sign-in process, users follow one of two flows:\nCreate and attach new individual user storage\nAttach their existing individual user storage\nBoth processes require the service to attach a disk to the Cloud PC while the user is signing in.\nAttachment failures are uncommon but might occur when the pooled user storage exceeds the\nstorage limit.\nUser Experience Sync provides a limited amount pooled user storage based on a storage\ncalculation.\nEach provisioning policy defines a pooled user storage limit calculated using the following\nformula:\nTotal pooled storage = OS disk size × Number of provisioned Cloud PCs\nﾉ Expand table\nIndividual user storage failed to attach to their session\nPooled user storage has exceeded the storage limit\nUnderstanding pooled storage limits\nFigure 1: Storage calculation of pooled user storage based on Cloud PC size and count\nUnder normal conditions, the pooled user storage is consumed as users create individual user\nstorages. When the storage reaches capacity:\nTotal size and Used size are equal\nAvailable size shows 0 GB\nThe User Storage tab displays these metrics in the provisioning policy\nFigure 2: Pooled user storage that is at the policy limit\nNormal storage consumption\nWhen pooled user storage is near capacity and multiple users sign in simultaneously, all users\nsign in successfully and create their individual user storage. This process results in an exceeded\ncondition that has the following characteristics:\nUsed size becomes greater than the Total size\nAvailable size remains 0 GB\nA new Exceeded property appears, showing the amount that exceeds the policy limit\nFigure 3: Pooled user storage that has exceeded the policy limit\nWhen pooled user storage exceeds its limit, the provisioning policy enters a tolerance period to\nprevent further storage growth. During this period:\nDuration: The tolerance period lasts for 7 days from when the exceeded condition first\noccurs.\nUser impact: Existing users who have individual storage can continue to sign in and access\ntheir personalized user experience.\nNew user restrictions: New users that attempt to sign in receive a temporary user\nexperience until storage is freed up.\nAdministrator actions: Manually delete individual user storage or increase the Cloud PC\ncount for the assignment.\nExceeded storage conditions\nExceeded tolerance period\nAutomatic resolution: If storage usage drops below the limit during the tolerance period,\nnormal operations resume immediately.\nAfter the seven-day tolerance period expires:\nService protection: The service begins deleting individual user storage starting at the oldest\n(based on the last attach timestamp). The quantity of individual user storage that's deleted\nis determined by the amount of space that's required for the policy to be under the policy\nlimit.\nWhen individual user storage becomes low o","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3138,"title":"Windows 365 App Issues","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["windows","365","app","issues","troubleshoot","with","the","this","article","helps","you","identify","and","solve","when","select","connect","button","your","cloud","might","receive","can","error","fix","issue","settings","device","apps","default","find","avd","host","update","for","files","run","following","command","clear"],"errorCode":"","eventId":"","severity":"Medium","summary":"Troubleshoot issues with the Windows\n365 app\nThis article helps you identify and solve issues with the Windows 365 app. When you select the Connect button to connect to your Cloud PC, you might receive a \"Can't\nconnect to Cloud PC\" error.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. When you select the Connect button to connect to your Cloud PC, you might receive a \"Can't\nconnect to Cloud PC\" error.\n2. In the Settings app on your Windows device, select Apps > Default apps.\n3. Find the AVD host app and update the default app for .avd files.\n4. Run the following command to clear the old Remote Desktop client cache:\nreg delete \"HKEY_CLASSES_ROOT\\progF3672D4C2FFE4422A53C78C345774E2D\" /f\nWhen a Remote Desktop client is installed, you might see a file type association message after\ntrying to connect to your Cloud PC.\n5. Make sure to select the Azure Virtual Desktop (HostApp)\noption to launch the Cloud PC session.","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 App Issues.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Troubleshoot issues with the Windows\n365 app\nThis article helps you identify and solve issues with the Windows 365 app.\nWhen you select the Connect button to connect to your Cloud PC, you might receive a \"Can't\nconnect to Cloud PC\" error.\nTo fix this issue:\n1. In the Settings app on your Windows device, select Apps > Default apps.\n2. Find the AVD host app and update the default app for .avd files.\n3. Run the following command to clear the old Remote Desktop client cache:\nreg delete \"HKEY_CLASSES_ROOT\\progF3672D4C2FFE4422A53C78C345774E2D\" /f\nWhen a Remote Desktop client is installed, you might see a file type association message after\ntrying to connect to your Cloud PC. Make sure to select the Azure Virtual Desktop (HostApp)\noption to launch the Cloud PC session.\nLimitations\n７ Note\nThe Windows 365 app currently doesn't support:\nWindows 11 IoT\nConfiguring Remote Desktop Protocol (RDP) properties\n\"Can't connect to Cloud PC\" error\nThe Windows 365 app asks to select a new default app\nThe Windows 365 app supports window mode to work more efficiently side-by-side with your\nlocal PC. To activate window mode, select the Window mode button on the connection bar.\nIf the Windows 365 app doesn't show any Cloud PCs, you might sign in with the wrong user\naccount. Ensure you sign in with an account enrolled with the Microsoft Entra account that has\nCloud PCs provisioned.\nFor more information about Windows 365 app, see What is Windows App?.\nLast updated on 07/21/2026\nChange Cloud PC session from full screen to\nwindow mode\nNo Cloud PCs are displayed in the Windows 365 app\nNext steps","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3139,"title":"Rename, Restart, Restore, or Reset Cloud PCs","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["rename","restart","restore","reset","cloud","pcs","and","with","windows","365","you","can","perform","variety","actions","your","just","like","would","physical","this","article","describes","the","direct","available","help","manage","including","inspecting","connections","viewing","details","renaming","restarting","restoring","resetting","when","inspect","connection"],"errorCode":"","eventId":"","severity":"Medium","summary":"Rename, Restart, Restore and Reset Cloud\nPCs with Windows 365\nYou can perform a variety of actions on your Windows 365 Cloud PC, just like you would on a\nphysical PC. This article describes the direct actions available to help you manage your Cloud PCs,\nincluding inspecting connections, viewing details, renaming, restarting, restoring, and resetting.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. Check the box next to Yes, I want to inspect the connection for this Cloud PC, and then\n2. select Inspect connection.\n3. use our help resources to further troubleshoot your issue.\n4. Select View details. A pop-up appears with your Cloud PC details.\n5. Restarting your Cloud PC works just like restarting a physical PC. Any unsaved changes might be\n6. Select Restart again to confirm you want to restart the selected Cloud PC.\n7. Restarted [Name’s] Cloud PC highlighted in green - your restart attempt was\n8. restart attempt was unsuccessful. Try restarting again by using the preceding steps.","emailScript":"Hello,\n\nWe reviewed the issue related to Rename, Restart, Restore, or Reset Cloud PCs.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Rename, Restart, Restore and Reset Cloud\nPCs with Windows 365\nYou can perform a variety of actions on your Windows 365 Cloud PC, just like you would on a\nphysical PC. This article describes the direct actions available to help you manage your Cloud PCs,\nincluding inspecting connections, viewing details, renaming, restarting, restoring, and resetting.\nWhen you inspect the connection, the process checks if your Cloud PC is ready to connect, if\nWindows 365 is working properly, and it tries to resolve any detected problems. Your Cloud PC is\nunavailable while it's checking the connection.\n1. Under Your Cloud PCs, select Inspect connection at the upper right of the Cloud PC you\nwant to inspect. A pop-up appears.\n2. Check the box next to Yes, I want to inspect the connection for this Cloud PC, and then\nselect Inspect connection.\n3. After your Cloud PC inspects your connection, you see one of the following results:\nFixed connection issues for [Name's] Cloud PC highlighted in green - your Cloud PC\ndisplays Ready to connect at the upper left.\nNo connection issues found for [Name's] Cloud PC highlighted in green - your Cloud\nPC displays Ready to connect at the upper left.\nCouldn't fix connection issues found for [Name's] Cloud PC highlighted in red. Please\nuse our help resources to further troubleshoot your issue.\nYou can view your Cloud PC details, such as OS, OS version, device name, Cloud PC name, license,\nand last sign-in.\n1. Under Your Cloud PCs, select the three dots (More) at the upper right of the Cloud PC\nwhose details you want to view.\n2. Select View details. A pop-up appears with your Cloud PC details.\nInspect the connection\nView Cloud PC details\nRename your Cloud PC\nRenaming your Cloud PC works just like renaming a physical PC. It changes your Cloud PC name\nto whatever name you choose.\nTo rename your Cloud PC:\n1. Under Your Cloud PCs, select Edit next to [Name’s] Cloud PC.\n2. Enter the new name you want for this Cloud PC.\n3. After you rename your Cloud PC, you see one of the following results:\nIf successful: Renamed [Name’s] Cloud PC highlighted in green.\nIf unsuccessful, one or more of the following error messages appear in red:\n[Name’s] Cloud PC wasn't renamed. Names can't include the characters /:*?”<>|.\n[Name’s] Cloud PC wasn't renamed. Names can't start with: .\n[Name’s] Cloud PC wasn't renamed. Names must be at least 1 character long.\n[Name’s] Cloud PC wasn't renamed. Names must be less than 16 characters long.\nRestarting your Cloud PC works just like restarting a physical PC. Any unsaved changes might be\nlost. Your Cloud PC is unavailable until it finishes restarting.\n1. Under Your Cloud PCs, select Restart at the top right of the Cloud PC you want to restart.\n2. Select Restart again to confirm you want to restart the selected Cloud PC.\n3. After your Cloud PC restarts, you see one of the following results:\nRestarted [Name’s] Cloud PC highlighted in green - your restart attempt was\nsuccessful.\n[Name’s] Cloud PC wasn't restarted. Try restarting again highlighted in red - your\nrestart attempt was unsuccessful. Try restarting again by using the preceding steps.\nRestoring your Cloud PC works like restoring a physical PC. It returns your Cloud PC to a previous\npoint in time. Restoring a Cloud PC permanently deletes data saved to the Cloud PC and any\napps installed between the restore point and now. Your Cloud PC is unavailable until it finishes\nrestoring.\nRestart your Cloud PC\nRestore your Cloud PC\n２ Warning\n1. Under Your Cloud PCs, select the three dots ... at the top right of the Cloud PC you want to\nrestore, and then select Restore.\n2. Check the box next to Yes, I want to restore this Cloud PC, choose a restart point from the\ndrop-down menu, and then select Restore.\n3. When your Cloud PC finishes restoring, you see one of the following results:\nRestored [Name’s] Cloud PC highlighted in green - your restore attempt was\nsuccessful.\n[Name’s] Cloud PC wasn’t restored. Try restoring again highlighted in red - your\nrestore attempt was unsuccessful. Try restoring again by using the preceding steps.\nResetting your Cloud PC works like resetting a physical PC. It deletes all data and resets any\nchanges you made on your Cloud PC. Resetting a Cloud PC reinstalls Windows 11, removes\npersonal files and apps, resets any changes to settings, and removes any saved restore points. To\navoid losing everything on this Cloud PC, use restore to return it to a previous point in time. Your\nCloud PC is unavailable until it finishes resetting.\n1. Under Your Cloud PCs, select the three dots ... at the top right of the Cloud PC you’d like to\nrestore, and then select Reset.\n2. Check the box next to Yes, I want to restore this Cloud PC.\n3. Check that you're sure you want to fully reset this Cloud PC, and then select Reset.\n4. When your Cloud PC finishes resetting, you see one of the following results:\nReset [Name’s] Cloud PC highlighted in green - your restore attempt was successful.\n[Name’s] Cloud PC wasn’t reset. Try resetting agai","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3140,"title":"Windows 365 Enterprise and Flex Known Issues","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["windows","365","enterprise","and","flex","known","issues","the","following","items","are","for","when","you","use","conditional","access","user","who","signs","cloud","first","time","might","trigger","impossible","travel","location","alert","follow","these","steps","investigate","risk","verify","that","activity","matches","expected","behavior"],"errorCode":"","eventId":"","severity":"Medium","summary":"Windows 365 Enterprise and Windows 365\nFlex known issues\nThe following items are known issues for Windows 365 Enterprise and Windows 365 Flex. When you use Conditional Access, a user who signs in to a Cloud PC for the first time might\ntrigger an impossible travel location alert.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. Check the GPO or the Intune Settings Catalog for the Intune Configuration profile that you used\n2. Make sure that you have the latest version of the Remote Desktop client, which can be found\n3. Remove the syncwindowsetting registry key under the path:\n4. Add the syncwindowsetting registry key with the value 1 under the path:\n5. Ensure that the execution policy and App Control for Business policies allow required scripts\n6. Review any applied GPOs that set the PowerShell execution policy to AllSigned.\n7. Remove the GPO or change the policy to RemoteSigned.\n8. Retry the ANC health check. If the check succeeds, retry provisioning.","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 Enterprise and Flex Known Issues.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Windows 365 Enterprise and Windows 365\nFlex known issues\nThe following items are known issues for Windows 365 Enterprise and Windows 365 Flex.\nWhen you use Conditional Access, a user who signs in to a Cloud PC for the first time might\ntrigger an impossible travel location alert.\nFollow these steps to investigate risk and verify that the activity matches the expected behavior\nof the user, based on their physical location and the location of the Cloud PC.\nWatermarking support is configured on session hosts and enforced by the Remote Desktop\nclient. You can configure Watermarking support by configuring a Group Policy Object (GPO) or\nthe Intune Settings Catalog. The default for the QR code embedded content setting doesn't allow\nadministrators to look up device information from leaked images for Cloud PCs.\nCheck the GPO or the Intune Settings Catalog for the Intune Configuration profile that you used\nto configure Watermarking support. Make sure that the QR code embedded content setting is\nconfigured to Device ID.\nFor more information, see Administrative template for Azure Virtual Desktop.\nWhen non-local admin users sign in to a Cloud PC by using an iPad and the Microsoft Remote\nDesktop app, the Start menu and taskbar might be missing from the Windows 11 user interface.\nFirst-time Cloud PC sign-in triggers an impossible travel\nlocation alert\nSolution\nWatermarking support in Windows 365\nSolution\nMissing Start menu and taskbar when using iPad and\nthe Remote Desktop app to access a Cloud PC\nMake sure that you have the latest version of the Remote Desktop client, which can be found\nfrom Remote Desktop clients for Remote Desktop Services and remote PCs.\nIn addition, you can sign in to the Cloud PC by using Windows 365.\nMany devices registered with Active Directory might have a machine account password that is\nautomatically updated. By default, these passwords are updated every 30 days. This automation\napplies to hybrid joined PCs but not Microsoft Entra Native PCs.\nThe machine account password is maintained on the Cloud PC. If the Cloud PC is restored to a\npoint that has a previous password stored, the Cloud PC won't be able to sign in to the domain.\nFor more information, see Machine Account Password Process.\nIn a remote desktop session, when you select one position in a text file, the cursor in the Cloud\nPC has some offset with the actual position.\nIn high DPI mode, both the server and Cloud PC browser scale the cursor. This conflict results in\nan offset between the visible cursor position and the actual cursor focus.\nTurn off high DPI mode.\nOutlook only downloads one month of previous mail, which can't be changed in Outlook\nsettings.\n1. Open Registry Editor.\nSolution\nRestore and automatic rolling credentials\nCursor's visible location is offset from the\nactual position\nPossible cause\nSolution\nOutlook only downloads one month of mail\nSolution\n2. Remove the syncwindowsetting registry key under the path:\n\\HKEY_CURRENT_USER\\SOFTWARE\\Policies\\Microsoft\\Office\\16.0\\Outlook\\Cached Mode\n3. Add the syncwindowsetting registry key with the value 1 under the path:\n\\HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Cached Mode\nAfter you complete these steps, the default will be one month. However, the download period\ncan be changed in Outlook settings.\nUpgrading an existing Cloud PC between release versions of Windows 10 to Windows 11 might\ncause the computer name to change to a name that has a prefix of \"pps.\" The Intune device\nname remains unchanged.\nFind and manage the Cloud PC in Microsoft Intune by using the unchanged Intune device name,\neither through the Devices > All devices list or the Devices > Windows 365 > All Cloud PCs list.\nWindows 365 provisioning might fail if the Desired State Configuration (DSC) extension is used\nand the PowerShell execution policy is set to AllSigned through Group Policy.\nWindows 365 sets the PowerShell execution policy to RemoteSigned at the LocalMachine scope\nduring provisioning. This policy allows locally created scripts and scripts run through the Custom\nScript Extension (CSE), while requiring downloaded scripts to be digitally signed. If a customerconfigured GPO sets the execution policy to AllSigned at the MachinePolicy scope, it overrides\nthe default configuration and blocks unsigned scripts.\nYou might see either of the following errors:\nCustom Script Extension authorization manager validation failed. Script execution was\nblocked by an authorization manager validation failure in the Custom Script Extension.\n\"An internal error occurred. The virtual machine deployment timed out.\"\nIn-place Windows upgrade might change the\ncomputer name\nSolution\nWindows 365 provisioning fails\nSolution\n1. Ensure that the execution policy and App Control for Business policies allow required scripts\nto run.\n2. Review any applied GPOs that set the PowerShell execution policy to AllSigned.\n3. Remove the GPO or change the policy to RemoteSigned.\n4. Retry the ANC health check. If the check succeeds, retry pr","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3141,"title":"Windows 365 Partner Connector Issues","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["windows","365","partner","connector","issues","troubleshoot","connectors","this","article","provides","some","troubleshooting","steps","and","possible","solutions","for","the","related","when","you","enable","citrix","hdx","plus","omnissa","horizon","anyware","user","agent","automatically","installed","that","cloud","pcs","enables","corresponding","third","party","protocol"],"errorCode":"","eventId":"","severity":"Medium","summary":"Troubleshoot partner connectors in\nWindows 365\nThis article provides some troubleshooting steps and possible solutions for the issues related\nto partner connectors in Windows 365. When you enable a partner connector (Citrix HDX Plus, Omnissa Horizon, or HP Anyware) for a\nuser, the partner agent is automatically installed on that user's Cloud PCs.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. user, the partner agent is automatically installed on that user's Cloud PCs. The agent enables\n2. Check Apps & Features to see if the partner agent is installed on the Cloud PC.\n3. Check Windows Event Viewer (eventvwr.msc) logs to make sure that the agent\n4. Check installation logs for any failures:\n5. Check the Cloud PC registration status in the partner configuration console.\n6. add the license back to trigger the reinstallation of the partner agent.\n7. enablement. Reprovisioning deletes the Cloud PC and creates a new one. All data on the\n8. Adding the user to the Direct Access Users group on the Cloud PC.","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 Partner Connector Issues.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Troubleshoot partner connectors in\nWindows 365\nThis article provides some troubleshooting steps and possible solutions for the issues related\nto partner connectors in Windows 365.\nWhen you enable a partner connector (Citrix HDX Plus, Omnissa Horizon, or HP Anyware) for a\nuser, the partner agent is automatically installed on that user's Cloud PCs. The agent enables\nthe corresponding third-party protocol.\nIf the installation encounters an issue, an error message appears in the All Cloud PC list,\nproviding advice on how to troubleshoot the error.\nEven though the installation fails, the user can still connect to their Cloud PC using Remote\nDesktop.\nWhile troubleshooting the error, make sure that the following steps are successful:\nThe user's license state is synchronized from the partner service to Microsoft Intune,\nincluding the user's Microsoft Entra user ID.\nThe prerequisites are met.\nThe partner connector is enabled and healthy in Microsoft Intune.\nThe correct permissions are set for the partner third-party apps in Microsoft Entra ID.\nThe Microsoft Entra user is added and discoverable in the Partner Cloud console.\nThe partner agent is downloaded on the Cloud PC.\nThe Cloud PC can access partner download URLs.\nNo security policy blocks PowerShell or any app/agent installation as System.\nThe partner agent is installed.\nCheck Apps & Features to see if the partner agent is installed on the Cloud PC.\nCheck Windows Event Viewer (eventvwr.msc) logs to make sure that the agent\ninstallation is executed.\nCheck installation logs for any failures:\nCitrix: %TEMPsystemdrive%\\Windows\\Temp\\Citrix\\XenDesktop Installer\nTroubleshoot partner agent installation issues\nTroubleshooting steps\nOmnissa Horizon:\nFor installation issues:\nC:\\Windows\\Temp\\Omnissa_Horizon_Agents_Installer_**.log.\nRun this script for collecting the logs for post-installation issues: C:\\Program\nFiles\\Omnissa\\Horizon Agents\\Horizon Agent\\DCT\\support.bat.\nHP Anyware:\nC:\\Teradici\\provisioning.log.\nOr, select Generate support bundle on the client side.\nThe Cloud PC is registered to the partner cloud tenant.\nCheck the Cloud PC registration status in the partner configuration console.\nIf the Cloud PC is unregistered, check the Application sign-in events in Windows Event\nViewer (eventvwr.msc) for partner service errors and warnings.\nAfter you find the root cause, remove the assigned license from the partner console and then\nadd the license back to trigger the reinstallation of the partner agent.\nIf you have connectivity issues with your partner-provisioned Cloud PC, test the default RDPbased connectivity to determine if the issue is with the Cloud PC or the partner connectivity.\nWhen the partner protocol is enabled, the Windows 365 remote protocol remains enabled but\ninactive. This inactivity means that users trying to connect to the Windows 365-supported\nRemote Desktop clients (including the HTML5 browser) are blocked by default. Users can only\nconnect using the partner protocol. Users trying to connect to non-partner clients receive a\ngeneric error message.\nYou can enable the RDP protocol so users can sign in with RDP to test the Cloud PC\nconnectivity. You can enable the RDP protocol by:\n７ Note\nIf no other solution works, you can reprovision the Cloud PC to reattempt the\nenablement. Reprovisioning deletes the Cloud PC and creates a new one. All data on the\noriginal Cloud PC will be lost. Therefore, reprovisioning should be the last resort to resolve\nthe issue.\nTroubleshoot connection issues\nTurn on the Remote Desktop Protocol (RDP) protocol\nMaking a user a local administrator on the Cloud PC.\nAdding the user to the Direct Access Users group on the Cloud PC.\nAfter taking either of these steps, you might need to restart the Cloud PC for the group\nmembership updates to take effect. The user can then connect using either RDP or the partner\nprotocol.\nYou can now test the connectivity using RDP and raise a support case with the relevant support\nteam if problems persist.\nFor more information about Citrix HDX Plus for Windows 365, see Set up Citrix HDX Plus\nfor Windows 365 Enterprise.\nFor more information about HP Anyware for Windows 365, see Set up HP Anyware for\nWindows 365 Enterprise.\nFor more information about Omnissa Horizon for Windows 365, see Set up Omnissa\nHorizon for Windows 365 Enterprise.\nLast updated on 02/12/2026\nNext steps","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3142,"title":"Windows 365 GPU Driver Issue","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["windows","365","gpu","driver","issue","troubleshoot","drivers","this","article","provides","solution","known","with","graphic","card","enabled","cloud","pcs","when","you","use","might","encounter","error","the","nvidia","outdated","can","occur","due","mismatch","underlying","graphics","version","message","resembles","following","screenshot","see","dialog"],"errorCode":"","eventId":"","severity":"Medium","summary":"Troubleshoot Windows 365 GPU drivers\nThis article provides a solution to a known issue with graphic card drivers on Windows 365\nGPU-enabled Cloud PCs. When you use Windows 365 GPU-enabled Cloud PCs, you might encounter a driver error if the\nNVIDIA driver is outdated.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. Verify if you're using the NVIDIA GPU:\n2. Download and install the latest driver:\n3. Verify that the update is successful:\n4. download the latest drivers.","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 GPU Driver Issue.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Troubleshoot Windows 365 GPU drivers\nThis article provides a solution to a known issue with graphic card drivers on Windows 365\nGPU-enabled Cloud PCs.\nWhen you use Windows 365 GPU-enabled Cloud PCs, you might encounter a driver error if the\nNVIDIA driver is outdated. This issue can occur due to a mismatch in the underlying graphics\ncard driver version.\nThe error message resembles the following screenshot. You can see an error dialog on the\nNVIDIA *** driver in Device Manager.\nNVIDIA GPU driver version\n７ Note\nThe actual dialog error number version might be different.\nResolution\nTo fix this issue, you need to download a new NVIDIA driver. Follow these troubleshooting\nsteps:\n1. Verify if you're using the NVIDIA GPU:\na. Open Device Manager on your Cloud PC.\nb. Expand Display Adapters.\nc. If NVIDIA *** appears, continue with the next steps. If not, no update is needed for this\nCloud PC.\n2. Download and install the latest driver:\na. Go to the Microsoft-approved NVIDIA GRID/vGPU driver download page.\nb. Download the latest driver for your Windows operating system.\nc. Extract the files and run the installer (no need to uninstall your current driver).\nd. Restart your Cloud PC once the installation is complete.\n3. Verify that the update is successful:\na. After restarting, open Device Manager again.\nb. Expand Display Adapters and confirm that the error has disappeared.\nIf you're using any of the NVIDIA driver series, such as NV, NVv3, and NVads A10V5 series or\nNCas_T4_V3 VM series, go to Install NVIDIA GPU drivers on N-series VMs running Windows to\ndownload the latest drivers.\nGPU Cloud PCs in Windows 365\nThird-party information disclaimer\nThe third-party products that this article discusses are manufactured by companies that are\nindependent of Microsoft. Microsoft makes no warranty, implied or otherwise, about the\nperformance or reliability of these products.\nLast updated on 02/12/2026\nReference","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3143,"title":"Windows 365 Provisioning Errors","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["windows","365","provisioning","errors","troubleshoot","the","following","can","occur","during","cloud","service","connection","point","scp","used","your","pcs","discover","microsoft","entra","tenant","information","you","must","configure","scps","using","connect","for","each","forest","plan","join","configuration","doesn","exist","discovered","virtual","network"],"errorCode":"","eventId":"","severity":"High","summary":"Troubleshoot provisioning errors\nThe following errors can occur during Cloud PC provisioning. The service connection point (SCP) is used by your Cloud PCs to discover your Microsoft Entra\ntenant information.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. Make sure that the AD domain, organizational unit (OU), and credentials in the associated\n2. Make sure that the domain join user has sufficient permissions to perform the domain\n3. Make sure that the virtual network and subnet can reach a domain controller correctly.\n4. configured to sync the AD computer objects every 30 minutes, and no more than 60 minutes.\n5. address space is too narrow.\n6. user ends their Cloud PC connection by selecting the shutdown icon, they might need to\n7. restart the Cloud PC from the Cloud PC portal before connecting again.\n8. Make sure that there are no Intune policies that might override Windows 365's default of","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 Provisioning Errors.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Troubleshoot provisioning errors\nThe following errors can occur during Cloud PC provisioning.\nThe service connection point (SCP) is used by your Cloud PCs to discover your Microsoft Entra\ntenant information. You must configure your SCPs by using Microsoft Entra Connect for each\nforest you plan to join Cloud PCs to.\nIf the SCP configuration doesn't exist or can't be discovered by using the virtual network\ndeclared, provisioning fails.\nTo understand more about the SCP and learn how to configure it, see the Microsoft Entra\ndocumentation.\nSuggested solution: Confirm with your identity team that the SCP exists for all target forests.\nCloud PC provisioning is blocked if the associated Azure network connection (ANC) isn't\nhealthy.\nThe ANC refreshes every six hours. Provisioning fails if the ANC refresh fails while provisioning\nis underway.\nSuggested solution: Make sure that the ANC is healthy and retry the provisioning.\nWindows 365 provisioned the Cloud PC but didn't allocate the full OS storage according to\nwhat the user should have received based on their assigned Windows 365 license. As a result,\nthe user can't see or use the full storage that they were assigned.\nSuggested solution: Retry provisioning.\nMicrosoft Entra ID service connection point\nmisconfigured\nAzure network connection isn't healthy\nDisk allocation error\nDomain join failed\nWindows 365 failed to join the Cloud PC to your on-premises Active Directory (AD) domain.\nMany factors can cause this failure.\nMake sure that the AD domain, organizational unit (OU), and credentials in the associated\nANC are correct.\nMake sure that the domain join user has sufficient permissions to perform the domain\njoin.\nMake sure that the virtual network and subnet can reach a domain controller correctly.\nJsonADDomainExtension is the Azure function used to perform this domain join. Make sure that\neverything required for this domain join to succeed is in place.\nSuggested solution: Attach an Azure virtual machine (VM) to the configured virtual network\nand perform a domain join using the credentials provided.\nWindows 365 doesn't perform any Microsoft Entra hybrid join function for the customer.\nMicrosoft Entra hybrid join must be configured and healthy as a prerequisite for Cloud PC.\nIf provisioning fails because of Microsoft Entra hybrid join, it's likely because of an insufficient\nsync period configured in your AD Sync service. Make sure that Microsoft Entra Connect is\nconfigured to sync the AD computer objects every 30 minutes, and no more than 60 minutes.\nThis step times out if the Microsoft Entra object doesn't appear within 90 minutes.\nAnother factor to consider is your on-premises AD replication time. Make sure that the domain\ncontroller being used for Windows 365 is replicated fast enough to make it into Microsoft Entra\nID within this five-hour time-out window.\nIf your organization uses Active Directory Federation Services (ADFS), this registration process\nis optimized and might result in Cloud PC provisioning being completed faster than a\nMicrosoft Entra Connect sync might be.\nSuggested solution: Check to see if the AD object:\nAppears in the correct OU.\nIs successfully synced to Microsoft Entra ID before provisioning times out.\nMicrosoft Entra hybrid join failed\nIntune enrollment failed\nWindows 365 performs a device-based mobile device management (MDM) enrollment into\nIntune.\nIf Intune enrollment fails, make sure that:\nAll of the required Intune endpoints are available on the virtual network of your Cloud\nPCs.\nThere are no MDM enrollment restrictions on the tenant. Windows corporate device\nenrollment is allowed in custom and default policies.\nThe Intune tenant is active and healthy.\nIf co-managing Cloud PCs with Intune and Configuration Manager, ensure that the Cloud\nPC OU isn't targeted for client push installation. Instead deploy the Configuration\nManager agent from Intune. For more information, see Client installation methods in\nConfiguration Manager.\nSuggested solution: Attempt an Intune enrollment using a test device or VM.\nWhile provisioning is in progress, someone removed the user's Windows 365 license.\nSuggested solution: Make sure that the user has a valid license associated with it.\nWindows 365 provisioned the Cloud PC but didn't grant the user local administrator\npermissions as defined by a User Settings policy. As a result, the user won't be an administrator\non their Cloud PC. So, they can't make system-level changes or install apps on the system-level\ncontext.\nSuggested solution: Retry provisioning or create a new User Settings policy.\nWindows 365 provisioned the Cloud PC. However, it didn't configure the Cloud PC to use\nMicrosoft Teams in the mode optimized for running on a remote VM. This optimization doesn't\ninstall Microsoft Teams and all of its components. It only sets the configuration that takes effect\nif you install Microsoft Teams on the Cloud PC. If this optimization isn't set and Microsoft\nTeams is installed on this device, Microsoft Teams doesn","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3144,"title":"Windows 365 Enterprise Cloud PC Grace Period","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["windows","365","enterprise","cloud","grace","period","troubleshoot","issues","pcs","provide","seamless","and","scalable","solution","for","virtual","desktops","however","administrators","might","encounter","situations","where","enters","this","guide","explains","how","when","license","removed","from","user","account","their","during","time","the","remains","accessible"],"errorCode":"","eventId":"","severity":"Medium","summary":"Troubleshoot Windows 365 Enterprise\nCloud PC grace period issues\nWindows 365 Cloud PCs provide a seamless and scalable solution for virtual desktops. However, administrators might encounter situations where a Cloud PC enters a grace period.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. removed from a user or the connection between the user and the provisioning policy is broken.\n2. Ensure the user is a member of any group assigned to a provisioning policy and that the\n3. Sign in to the Microsoft 365 admin center as at least a License Administrator.\n4. Go to the Billing > Licenses page.\n5. select its name from the Suggested groups list.\n6. add it to the list. You can add up to 20 users at a time.\n7. Sign in to the Microsoft Intune admin center, and then select Groups > All groups.\n8. Select Members > Add members.","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 Enterprise Cloud PC Grace Period.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Troubleshoot Windows 365 Enterprise\nCloud PC grace period issues\nWindows 365 Cloud PCs provide a seamless and scalable solution for virtual desktops.\nHowever, administrators might encounter situations where a Cloud PC enters a grace period.\nThis guide explains how to troubleshoot Cloud PC grace period issues.\nWhen a Windows 365 license is removed from a user account, their Enterprise Cloud PC enters\na grace period. During this time, the Cloud PC remains accessible before it's deprovisioned. It's\nimportant to act promptly to avoid service disruption.\nA Windows 365 Cloud PC can enter a grace period when a valid Windows 365 license is\nremoved from a user or the connection between the user and the provisioning policy is broken.\nThis can happen in one of the following scenarios:\nThe user account is removed from the group where the license is inherited.\nThe direct license assignment is removed from the user.\nThe user is removed from the group that is assigned to the provisioning policy used to\ncreate the Cloud PC.\nIn any of these scenarios, the Cloud PC remains operational for seven days, allowing time to\nresolve the issue before the Cloud PC is deprovisioned.\nTo return Cloud PCs to a provisioned state, check the following two key areas:\n1. The original license assignments are in place.\n2. The connection to the relevant provisioning policy is in place.\nThe following sections provide the necessary actions to address the grace period. The sections\ninclude the following steps:\n1. Reassign Windows 365 Enterprise licenses to users via group-based licensing or direct\nassignment.\nUnderstand the grace period\nActions to address the grace period\n2. Ensure the user is a member of any group assigned to a provisioning policy and that the\nassignments are in place.\nThere are two primary methods to reassign Windows 365 licenses to users: group-based\nlicensing and direct assignment.\nGroup-based licensing allows administrators to assign licenses to users through Microsoft\nEntra ID groups. This method simplifies management by automating license assignments based\non group membership. Follow these steps to manage group-based licensing:\n1. Sign in to the Microsoft 365 admin center as at least a License Administrator.\n2. Go to the Billing > Licenses page.\n3. On the Subscriptions tab, select the Windows 365 license that you want to assign.\n4. On the License details page, select the Groups tab, and then select Assign licenses.\n5. In the details panel, search for the group that you want to assign licenses to, and then\nselect its name from the Suggested groups list.\n6. To assign or remove access to specific items, select Turn apps and services on or off.\n7. When finished, select Assign, and then close the right pane.\nDirect assignment involves manually assigning licenses to individual users. Follow these steps\nto manage the direct assignment of licenses:\n1. Sign in to the Microsoft 365 admin center as at least a License Administrator.\n2. Go to the Billing > Licenses page.\n3. On the Subscriptions tab, select the Windows 365 license that you want to assign.\n4. On the License details page, select the Users tab, and then select Assign licenses.\n5. In the Assign licenses to users pane, type a name, and then choose it from the results to\nadd it to the list. You can add up to 20 users at a time.\n6. To assign or remove access to specific items, select Turn apps and services on or off.\n7. When finished, select Assign, and then close the right pane.\nMissing Windows 365 licenses\nGroup-based licensing\nDirect assignment\nDisconnection from provisioning policies\nIf a user is disconnected from a provisioning policy, either by being removed from the assigned\ngroup or if the group they belong to is unassigned, any Cloud PCs created from that\nassociation enter a grace period. To resolve this issue, ensure that the correct assignments and\ngroup memberships are in place.\nProvisioning policies in Windows 365 require users to be part of specific Microsoft Entra ID\ngroups to receive their Cloud PCs. Ensuring that users are members of these groups is crucial\nfor proper provisioning.\nTo do so, follow these steps:\n1. Sign in to the Microsoft Intune admin center, and then select Groups > All groups.\n2. Choose the relevant group associated with the provisioning policy.\n3. Select Members > Add members.\n4. Add the users who require Cloud PCs to this group and select Select.\nIf a group is removed from a provisioning policy, all Cloud PCs associated with its members\nenter a seven-day grace period. To resolve this issue, you need to reassign the group.\nTo do so, follow these steps:\n1. Sign in to the Microsoft Intune admin center, and then select Devices > Windows 365.\n2. Navigate to Provisioning policies and open the provisioning policy the Cloud PCs in the\ngrace period were created from.\n3. Under Assignments, select Edit.\n4. On the Assignments page, select Add groups, choose the groups you want this policy\nassigned to, and then select Select.\n5. Select Next and Update.\nVa","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3145,"title":"Cloud PC Connection Errors","category":"Networking","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["cloud","connection","errors","either","the","user","physical","device","denied","pku2u","protocol","requests","only","triggered","following","cases","microsoft","entra","joined","troubleshoot","can","occur","when","connecting","from","windows","desktop","client","registered","hybrid","same","organization","turn","both","and","create","filter","for","all","pcs"],"errorCode":"","eventId":"","severity":"Medium","summary":"Either the Cloud PC or the user's physical device denied PKU2U protocol requests. The PKU2U\nprotocol is only triggered in the following cases:\nThe Cloud PC is Microsoft Entra joined.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. user's physical device, you (or the user) can manage this setting through the Allow PKU2U\n2. Remove per-user multifactor authentication for all users connecting to Cloud PCs. Then, set a\n3. Sign in to Windows 365, select the cog icon next to the Cloud PC, and then select Restart.\n4. Review the settings and confirm that they aren't interfering with connections.\n5. Make sure that IP address 168.63.129.16 is reachable through any security software installed on\n6. Make sure that SSL inspection/Termination is disabled for networks used by your Cloud\n7. Review other troubleshooting steps","emailScript":"Hello,\n\nWe reviewed the issue related to Cloud PC Connection Errors.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Troubleshoot Cloud PC connection errors\nThe following errors can occur when connecting to a Cloud PC.\nEither the Cloud PC or the user's physical device denied PKU2U protocol requests. The PKU2U\nprotocol is only triggered in the following cases:\nThe Cloud PC is Microsoft Entra joined.\nThe user is connecting from the Windows desktop client.\nThe user's physical device is Microsoft Entra registered, Microsoft Entra joined, or\nMicrosoft Entra hybrid joined to the same organization as the Cloud PC.\nTurn on PKU2U protocol requests on both the Cloud PC and the user's physical device:\n1. Create a filter for all Cloud PCs.\n2. Create a device configuration policy using the settings catalog.\n3. On the Configuration settings page, search for and select Network Security Allow\nPKU2U Authentication Requests > Allow.\nErrors when connecting to a Microsoft Entra joined\nCloud PC\nThe logon attempt failed\nPotential cause 1\nPossible solution\n4. On the Assignments page, select Add all devices > Edit filter > Include filtered devices\nin assignment, and then select the filter you created for all Cloud PCs.\n5. On the Assignments page, also select a Microsoft Entra group containing the user or the\nuser's physical device.\n6. Complete the creation of the device configuration policy.\nIf you only manage the user's physical device through Group Policy or you don't manage the\nuser's physical device, you (or the user) can manage this setting through the Allow PKU2U\nauthentication requests to this computer to use online identities policy.\nPer-user multifactor authentication is turned on for the user account. Because it blocks sign-in,\nper-user multifactor authentication isn't supported for users connecting to Microsoft Entra\njoined Cloud PCs.\nRemove per-user multifactor authentication for all users connecting to Cloud PCs. Then, set a\nMicrosoft Entra Conditional Access policy and assign it to the appropriate users.\nPotential cause 2\nPossible solution\nThere might be a resource issue on your Cloud PC.\nSign in to Windows 365, select the cog icon next to the Cloud PC, and then select Restart.\nThis error can be caused by network configuration settings, like:\nCustom DNS settings\nNetwork Virtual Appliance blocking\nNetwork security group configuration\nResource locks\nBlocks on required endpoints\nReview the settings and confirm that they aren't interfering with connections.\nThis error can occur when the Cloud PC's processor is over-utilized.\nSpecific connection errors\nWe couldn't connect because there are currently no available\nresources\nPotential cause\nPossible solution\nWe couldn't connect to the gateway because of an error. If\nthis keeps happening, ask your admin or tech support for\nhelp.\nPotential cause\nPossible solution\nThe remote PC ended your session. If this keeps happening,\ncontact your network administrator for assistance. Error code:\n0x3\nPotential cause\nPossible solution\nIf the issue persists, sign in to Windows 365, select the cog icon next to the Cloud PC, and\nthen select Restart.\nIf you encounter these errors, make sure that you don't have a configured Cloud Service\nProvider (CSP) or Group Policy Object (GPO) that blocks remote desktop connections.\nIntune CSP policy:\nSettings catalog: Administrative Templates\\Windows Components\\Remote Desktop\nServices\\Remote Desktop Session Host\\Connections\nAllow users to connect remotely by using Remote Desktop Services\nGPO configuration path:\nComputer Configuration\\Windows Components\\Remote Desktop Services\\Remote Desktop\nSession Host\\Connections\nAllow users to connect remotely by using Remote Desktop Services\nIf you continue to experience issues, run the Inspect Connection option within the Windows\nApp or the Troubleshoot option under Manage my Cloud PC located under the three dots.\nSome other possible causes for Cloud PC connection failures include:\nUpdate VPN clients to the most up-to-date versions.\nConnection Attempt timed out, Please try again, or An error\noccurred while accessing this resource\nOther connection error causes\nOut-of-date third-party VPN client versions\nPossible solution\nSigning in to the Cloud PC with Microsoft Entra ID-only user\naccounts\nPossible solution\nWindows 365 is currently a Microsoft Entra hybrid join device, requiring users to sign in with\ntheir on-premises Active Directory account.\nRemote Credential Guard requires connectivity to the on-premises Active Directory Domain\nController on the client PC used to access the Cloud PC. This connection is only possible using\na VPN solution. Using a KDC proxy isn't currently available for Windows 365.\nWindows 365 Cloud PCs require access to Azure communication channels.\nMake sure that IP address 168.63.129.16 is reachable through any security software installed on\nthe Cloud PC or gateway devices used in the virtual network connected to your Azure network\nconnection (ANC).\nFor more information, see What is IP Address 168.63.129.16.\nConnection problems might be caused by settings delivered by group policies. To test this\npossible cause, y","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3146,"title":"Windows 365 Link - Interactive Window Could Not Be Shown","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["windows","365","link","interactive","window","could","not","shown","connection","fails","with","error","this","article","helps","resolve","the","after","you","authenticate","sign","screen","might","encounter","following","message","when","connecting","your","cloud","something","went","wrong","authentication","issue","occurred","where","please","try","again"],"errorCode":"","eventId":"","severity":"Medium","summary":"Windows 365 Link connection fails with\nerror \"an interactive window could not be\nshown\"\nThis article helps resolve the connection error \"an interactive window could not be shown.\"\nAfter you authenticate on the sign-in screen, you might encounter the following error message\nwhen connecting to your Cloud PC:\nSomething went wrong. An authentication issue occurred where an interactive window could not be shown.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. users should no longer encounter this error message for the reasons stated below. If such\n2. used for the sign-in stage matches (or is stronger than) the setting on the Resources policy\n3. used for the connection stage.\n4. User actions policies. Some Grant controls, such as device compliance or custom controls,\n5. Sign in to the Microsoft Entra admin center > Protection > Conditional Access > Signin logs.\n6. Select the User sign-ins (interactive) tab and use filters to find entries for the sign-in. For\n7. Username: <enter the UPN of the user>\n8. Select an entry to review if the details are:","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 Link - Interactive Window Could Not Be Shown.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Windows 365 Link connection fails with\nerror \"an interactive window could not be\nshown\"\nThis article helps resolve the connection error \"an interactive window could not be shown.\"\nAfter you authenticate on the sign-in screen, you might encounter the following error message\nwhen connecting to your Cloud PC:\nSomething went wrong.\nAn authentication issue occurred where an interactive window could not be shown. Please\ntry again later.\nThe connection attempts via Windows 365 Link use non-interactive single sign-on and can't\nprompt for user authentication. If you see this error, Windows 365 resources might be\nprotected by a Conditional Access policy that requires interactive authentication. For more\ninformation, see Set Conditional Access policies for Windows 365.\nThe common causes of this error are:\nMissing user action policy\nConditional Access policy not assigned\nMismatched access controls\nUnsupported access controls\nFor configuration details, see Conditional Access policies for Windows 365 Link.\n７ Note\nWith the release of Windows 365 Link December Quality Update version 26100.7462,\nusers should no longer encounter this error message for the reasons stated below. If such\nan error is encountered first check that Windows 365 Link is on version 26100.7462 or\ngreater. For more information on updating the device, see Windows 365 Link update\nbehavior and control.\nMissing user action policy\nInteractive authentication should occur during the sign-in stage. This commonly requires a new\nConditional Access policy because the sign-in only triggers User actions policies to Register or\njoin devices, whereas the connection triggers Resources policies.\nIf the User actions policy exists, confirm if you're in the scope of the assignments of users.\nThe sign-in stage generates a security token that is used in the connection stage. If the\nConditional Access policies in either stage have the access controls configured differently, an\nauthentication issue might occur. Ensure the access control setting on the User actions policy\nused for the sign-in stage matches (or is stronger than) the setting on the Resources policy\nused for the connection stage.\nA Conditional Access policy applied to resources might use controls that are unavailable for\nUser actions policies. Some Grant controls, such as device compliance or custom controls,\ncan't be used with User actions policies. Some Session controls, such as Sign-in frequency,\ncan't be used with User actions policies. If a User actions policy applied during the connection\nstage requires any of these unsupported controls, modifications are required to accommodate\nthe use of Windows 365 Link devices.\nConditional Access sign-in logs can be used to verify how Conditional Access policies are (or\naren't) being applied to the sign-in and connection attempts.\n1. Sign in to the Microsoft Entra admin center > Protection > Conditional Access > Signin logs.\n2. Select the User sign-ins (interactive) tab and use filters to find entries for the sign-in. For\nexample, try using:\nResource: Device Registration Service\nUsername: <enter the UPN of the user>\nDate: <select a relevant interval>\nConditional Access policy not assigned\nMismatched access controls\nUnsupported access controls\nConfirm the problem\n3. Select an entry to review if the details are:\nBasic info / Authentication requirement: Single-factor\nBasic info / Status: Success\nConditional Access / Result: Not Applied\n4. Select the User sign-ins (non-interactive) tab and use filters to find entries for the\nconnection. For example, try using:\nApplication: Windows 365 Client\nUsername: <enter the UPN of the user>\nDate: <select a relevant interval>\n5. Expand the results and select an entry to review if the details are:\nBasic info / Authentication requirement: Multifactor\nBasic info / Status: Interrupted\nConditional Access / Result: <any failures occurred>\nIf you encounter entries similar to the preceding ones, then a combination of those Conditional\nAccess policies likely causes the error.\nFor configuration details, see Conditional Access policies for Windows 365 Link.\nLast updated on 02/12/2026","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3147,"title":"Windows 365 Link - Cloud PC Does Not Support Entra ID SSO","category":"Entra ID","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["windows","365","link","cloud","does","not","support","entra","sso","connection","fails","with","single","sign","after","user","authenticates","the","page","when","tries","connect","might","encounter","following","message","something","went","wrong","your","this","error","commonly","occurs","isn","enabled","requires","that","connects","confirm"],"errorCode":"","eventId":"","severity":"Medium","summary":"Windows 365 Link connection fails with\n\"Cloud PC does not support Entra ID single\nsign-on\"\nAfter a user authenticates on the sign-in page, when the user tries to connect to the Cloud PC,\nthe user might encounter the following message:\nSomething went wrong. Your Cloud PC does not support Entra ID single sign-on.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. Sign in to the Microsoft Intune admin center.\n2. Select Columns > Using single sign-on.","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 Link - Cloud PC Does Not Support Entra ID SSO.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Windows 365 Link connection fails with\n\"Cloud PC does not support Entra ID single\nsign-on\"\nAfter a user authenticates on the sign-in page, when the user tries to connect to the Cloud PC,\nthe user might encounter the following message:\nSomething went wrong.\nYour Cloud PC does not support Entra ID single sign-on.\nThis error commonly occurs when single sign-on (SSO) isn't enabled.\nWindows 365 Link requires that SSO is enabled on the Cloud PC it connects to.\nTo confirm the status of SSO on the Cloud PC, follow these steps:\n1. Sign in to the Microsoft Intune admin center.\n2. Navigate to Devices > Device onboarding > Windows 365 > All Cloud PCs.\n3. Select Columns > Using single sign-on.\n4. Search the list for the Cloud PC in question by device name or the user's User Principal\nName (UPN).\n5. If Using single sign-on shows No, Windows 365 Link can't connect to it.\nFor details on how to enable SSO on Cloud PCs, see Configure single sign-on for Windows 365\nusing Microsoft Entra authentication.\nLast updated on 02/12/2026\nCause\nResolution\nReference","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3148,"title":"Windows 365 Link - Connection to Remote PC Was Lost","category":"Networking","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["windows","365","link","connection","remote","was","lost","fails","with","the","after","user","authenticates","sign","page","when","tries","connect","cloud","might","encounter","following","message","this","because","network","problem","keeps","happening","ask","your","admin","tech","support","for","help","error","commonly","occurs","filtering"],"errorCode":"","eventId":"","severity":"High","summary":"Windows 365 Link connection fails with\n\"connection to the remote PC was lost\"\nAfter a user authenticates on the sign-in page, when the user tries to connect to the Cloud PC,\nthe user might encounter the following message:\nLost connection\nThe connection to the remote PC was lost. This might be because of a network connection\nproblem.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. This might be because of a network connection\nproblem.\n2. If this keeps happening, ask your admin or tech support for help.\n3. This error commonly occurs because of network filtering.\n4. Connecting to a Cloud PC from a Windows 365 Link device has the same network requirements\nas other clients.\n5. The network connection being used might be blocking or filtering the\nendpoints that are required to use the service.","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 Link - Connection to Remote PC Was Lost.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Windows 365 Link connection fails with\n\"connection to the remote PC was lost\"\nAfter a user authenticates on the sign-in page, when the user tries to connect to the Cloud PC,\nthe user might encounter the following message:\nLost connection\nThe connection to the remote PC was lost. This might be because of a network connection\nproblem. If this keeps happening, ask your admin or tech support for help.\nThis error commonly occurs because of network filtering.\nConnecting to a Cloud PC from a Windows 365 Link device has the same network requirements\nas other clients. The network connection being used might be blocking or filtering the\nendpoints that are required to use the service.\nTo resolve this issue, fix the networking problem. For more information, see End user devices.\nLast updated on 02/12/2026\nCause\nResolution","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3149,"title":"Windows 365 Link - Failed to Open Entra ID Credential Prompt","category":"Entra ID","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["windows","365","link","failed","open","entra","credential","prompt","connection","fails","with","microsoft","after","user","authenticates","the","sign","page","when","tries","connect","cloud","might","encounter","following","message","denied","this","can","happen","sso","enabled","pcs","first","time","you","are","connecting","connected","days"],"errorCode":"","eventId":"","severity":"High","summary":"Windows 365 Link connection fails with\n\"Failed to open a Microsoft Entra ID\ncredential prompt\"\nAfter a user authenticates on the sign-in page, when the user tries to connect to the Cloud PC,\nthe user might encounter the following message:\nConnection Denied. Failed to open a Microsoft Entra ID credential prompt.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. users should no longer encounter this error message for the reasons stated below. If such","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 Link - Failed to Open Entra ID Credential Prompt.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Windows 365 Link connection fails with\n\"Failed to open a Microsoft Entra ID\ncredential prompt\"\nAfter a user authenticates on the sign-in page, when the user tries to connect to the Cloud PC,\nthe user might encounter the following message:\nConnection Denied.\nFailed to open a Microsoft Entra ID credential prompt. This can happen in SSO-enabled\nCloud PCs if this is the first time you are connecting to it, or if you first connected 30 days\nago. Connect to your Cloud PC on another device and then try again.\nThis error commonly occurs when single sign-on (SSO) consent is required.\nWhen a user connects to a Cloud PC that has SSO enabled, the user might be prompted for\nconsent to use the authentication token. This issue can happen under several conditions:\nThe Cloud PC is newly provisioned.\nThe Cloud PC is reprovisioned.\nThe Cloud PC just has SSO enabled.\nIt's been 30 days since the last time consent was given.\nIf any of these conditions are true, the next time the user attempts to sign in, consent is\nrequired via an interactive prompt. However, the prompt can't be shown on Windows 365 Link\n７ Note\nWith the release of Windows 365 Link December Quality Update version 26100.7462,\nusers should no longer encounter this error message for the reasons stated below. If such\nan error is encountered first check that Windows 365 Link is on version 26100.7462 or\ngreater. For more information on updating the device, see Windows 365 Link update\nbehavior and control.\nCause\nbecause Windows 365 Link uses a non-interactive SSO connection, resulting in the error\nmessage.\nAs a workaround, the user can connect to this Cloud PC from a different device or the Web\nClient where the prompt can be acknowledged. However, the prompt returns every 30 days.\nFor configuration details on how to prevent this issue, see Suppress single sign-on consent\nprompts for Windows 365 Link.\nLast updated on 02/12/2026\nWorkaround","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3150,"title":"Windows 365 Boot Troubleshooting","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["windows","365","boot","troubleshooting","troubleshoot","applies","supported","versions","this","article","provides","steps","for","issues","that","occur","when","you","set","manage","devices","the","user","can","access","cloud","from","physical","device","follow","these","check","whether","sign","either","other","available","locations","app","another"],"errorCode":"","eventId":"","severity":"Medium","summary":"Troubleshoot Windows 365 Boot\nApplies to: ✅ Supported versions of Windows 365\nThis article provides troubleshooting steps for issues that occur when you set up or manage\nWindows 365 Boot devices. If the user can't access the Cloud PC from the Windows 365 Boot physical device, follow these\nsteps:\n1.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. Check whether the user can sign in to the Cloud PC from either of the other available\n2. select Connect while signed into device.\n3. check the Windows 365 Boot physical device for issues. In this case, verify that the physical\n4. User can't access the Cloud PC from the Windows\n5. Check the following registry entries to verify that the physical device is configured correctly to\n6. Remove and add Windows 365 Boot to the physical\n7. Remove Windows 365 Boot from the physical device\n8. Sign in to the Microsoft Intune admin center, and then select Groups > All groups.","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 Boot Troubleshooting.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Troubleshoot Windows 365 Boot\nApplies to: ✅ Supported versions of Windows 365\nThis article provides troubleshooting steps for issues that occur when you set up or manage\nWindows 365 Boot devices.\nIf the user can't access the Cloud PC from the Windows 365 Boot physical device, follow these\nsteps:\n1. Check whether the user can sign in to the Cloud PC from either of the other available\nlocations:\nWindows 365.\nThe Windows App on another (non-Windows 365 Boot) device.\n2. If a user has more than one Cloud PC, make sure that they select a default Cloud PC to use\neach time that they sign in. To set this default, follow these steps:\na. Go to Windows 365.\nb. On the card for the Cloud PC that you that want to set as default, select the More\noptions ellipsis (...), and then select Settings.\nc. On the Integrated experiences tab, locate the Boot to this Cloud PC section, and then\nselect Connect while signed into device.\nd. Select Save.\n3. If the user can sign in to the Cloud PC from the app or web, and a default Cloud PC is set,\ncheck the Windows 365 Boot physical device for issues. In this case, verify that the physical\ndevice is configured correctly and has the required software versions. For more\ninformation, see Windows 365 Boot physical device requirements.\n4. To deliver policies more quickly to the device, administrators can try to manually select\nDevice sync. After this change, the user can try to restart the device.\nUser can't access the Cloud PC from the Windows\n365 Boot physical device\nPhysical device registry key configuration\nCheck the following registry entries to verify that the physical device is configured correctly to\nrun Windows 365 Boot. If it's necessary, create or update the registry entries.\nRegistry key name Registry value nameRegistry\nvalue\nHKLM\\Software\\Microsoft\\PolicyManager\\current\\device\\CloudDesktopBootToCloudMode 1\nHKLM\\Software\\Microsoft\\PolicyManager\\current\\device\\WindowsLogonOverrideShellProgram1\nHKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\SharedPC\\NodeValues 18 1\nHKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\SharedPC\\NodeValues 01 1\nWindows 365 Boot requires that the physical device runs specific versions of both Windows 365\nand Azure Virtual Desktop (HostApp) apps. To check the installed versions, run the following\nPowerShell cmdlet as an administrator:\nAzure PowerShell\nThis cmdlet shows all the Microsoft-maintained apps (such as QuickAssist and Microsoft Family)\non the physical device. To make sure that Windows 365 Boot works correctly, verify that the app\nversions meet the following requirements:\nWindows App version 2.0.285 or a later version\nAzure Virtual Desktop (HostApp) app version 1.2.4159 or a later version\nThe latest version of Windows 11\nIf you can't identify the source of the issue, remove Windows 365 Boot from the device, and\nthen add it again.\nﾉ Expand table\nPhysical device versions of Windows 365, Azure\nVirtual Desktop Apps, and Windows\nGet-AppxPackage -AllUsers -name *MicrosoftCorporationII*\nRemove and add Windows 365 Boot to the physical\ndevice again\nRemove Windows 365 Boot from the physical device\n1. Sign in to the Microsoft Intune admin center, and then select Groups > All groups.\n2. Select the group for your Windows 365 Boot device, and then select Members.\n3. Select the physical device, and then select Remove > Yes.\n4. Select Devices > All devices, select the physical device, and then select Overview > Sync.\nIt takes up to eight hours for Intune to remove the policies. After the removal, the physical\ndevice is no longer set up for Windows 365 Boot.\n1. Sign in to the Microsoft Intune admin center, and then select Groups > All groups.\n2. Select the group for your Windows 365 Boot device, and then select Members.\n3. Select Add members, and then select the physical device.\n4. Wait about 10 minutes.\n5. Select Devices > All devices, select the physical device, and then select Overview > Sync.\nThe physical device is now set up for Windows 365 Boot. Retest it to verify that it works.\nThis issue indicates that the device didn't fully authenticate on the network.\nTo fix the issue, disconnect the device from the Wi-Fi network that requires a captive portal signin, and then reconnect and complete the sign-in steps again.\nAfter the user signs in by using the captive portal, the network state might not propagate\ncorrectly.\nCancel the connection to return to the connection lounge. To reconnect, select Connect for the\nCloud PC that you want to connect to.\nAdd Windows 365 Boot back to the physical device\nIssues connecting to a captive portal\nNetwork connection doesn't update after the device connects\nto the captive portal\nUser can't reconnect to their Cloud PC after signing in to a\ncaptive portal\nContact Microsoft Support\nIf the issue persists, collect the following log and ID information, and then contact Microsoft\nSupport.\nCollect Windows 365 and Microsoft Entra ID log information from the following locations:\nC:\\Users\\*username*\\AppData\\Local\\Temp\\DiagOutputDir\\Windows365\\Lo","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3151,"title":"Windows 365 Boot Known Issues","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["windows","365","boot","known","issues","only","supports","vpn","clients","that","don","require","application","installation","appbased","users","sign","aren","supported","because","can","interact","with","the","client","from","device","this","article","provides","solutions","recent","user","isn","completely","signed","out","after","closing","laptop"],"errorCode":"","eventId":"","severity":"Medium","summary":"Windows 365 Boot only supports VPN clients that don't require application installation. Appbased VPN clients that require users to sign in aren't supported because users can't interact\nwith the VPN client from a Windows 365 Boot device.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. Check to see if you have the policy setting configured in Microsoft Intune. For more\n2. Configure the Windows 365 Boot physical device's Wi-Fi profile through Microsoft Intune. For\n3. Select Ctrl+Alt+Del and select the Sign out option.\n4. Make sure Microsoft Teams optimizations are used as explained in Microsoft Teams on Cloud\n5. Users can't launch the web browser to sign in to a\n6. Users see a black screen after using the\n7. use your Windows 365 Boot configured device's camera in Microsoft Teams.\n8. Remove Windows 365 Boot from the physical device.","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 Boot Known Issues.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Windows 365 Boot known issues\nThis article provides solutions to the recent known issues with Windows 365 Boot.\nWindows 365 Boot only supports VPN clients that don't require application installation. Appbased VPN clients that require users to sign in aren't supported because users can't interact\nwith the VPN client from a Windows 365 Boot device.\nThe user isn't completely signed out after closing the laptop lid. When they open the laptop,\nthey see a black screen or the app trying to disconnect. Eventually, it signs the user out of the\nsession.\nDuplicate dialogs might be displayed for the physical device and the Cloud PC. This issue can\noccur for:\nSome shortcut keys, like Win+G or sticky keys.\nEnabling accessibility key settings, like High contrast, Num keys, or Toggle keys.\nWindows 365 Boot isn't currently supported in Kiosk mode on Windows.\nWindows 365 Boot doesn't completely restrict the user from accessing the physical device. For\nmore information, see Restrict user access to Windows 365 Boot physical device.\nVPN support\nExiting the session on sleep or closing the device\nDuplicate dialogs for some shortcut and sticky keys\nWindows 365 Boot isn't supported in Kiosk mode\nRestricted access to the physical device\nOther sign-in options besides username/password\nare displayed on the sign-in screen\nWindows 365 Boot is used with the Shared PC configuration service provider (CSP). The\nprimary supported sign-in method is username/password.\nIf you have Windows Hello for Business enabled for the Windows 365 Boot device, you can use\nMicrosoft Intune to disable it. For more information, see Enable security keys for Windows\nsign-in.\nIf the Windows 365 Boot physical device lets users sign in using a convenience PIN, you can\nturn it off. For more information, see AllowPINLogon.\nWhen the Use security keys for sign-in policy setting is enabled, it can be configured to be the\ndefault credential provider. This policy might result in the user seeing a sign-in for the physical\ndevice.\nCheck to see if you have the policy setting configured in Microsoft Intune. For more\ninformation on how to check, see Enable security keys for Windows sign-in.\nIf it's set, exclude your Windows 365 Boot devices from the policy.\nWindows 365 Boot uses \"clean\" Windows 11 devices that don't have preconfigured\napplications or policies assigned to the device.\nReset the device to a \"clean\" state. For more information, see Windows 365 Boot physical\ndevice requirements.\nSolution\nDefault credential provider is set to Security Key on\nthe sign-in screen\nSolution\nLocal device has background apps and previous\npolicy configurations that impact the user's\nWindows 365 Boot experience\nSolution\nWhen using single sign-on, users are prompted to authenticate to Microsoft Entra ID and allow\nthe Remote Desktop connection when launching a connection to a new Cloud PC. Microsoft\nEntra remembers up to 15 devices for 30 days before prompting again.\nIf you see this dialog, select Yes to connect.\nWindows 365 Boot is designed for Ethernet connections or Wi-Fi connections managed\nthrough the WiFi CSP.\nConfigure the Windows 365 Boot physical device's Wi-Fi profile through Microsoft Intune. For\nmore information, see Add Wi-Fi settings for Windows 10/11 devices in Microsoft Intune.\nThis known issue is under investigation.\nSelect Ctrl+Alt+Del and select the Sign out option.\nMake sure Microsoft Teams optimizations are used as explained in Microsoft Teams on Cloud\nPC.\nSingle sign-on users see a dialog to allow remote\ndesktop connection during the connection attempt\nSolution\nUsers can't launch the web browser to sign in to a\nWi-Fi network\nSolution\nUsers see a black screen after using the\nDisconnect/Sign-out/Lock command from the\nCloud PC\nSolution\nMicrosoft Teams calls have poor performance\nSolution\nCamera permissions must be granted to the Azure Virtual Desktop (HostApp) application to\nuse your Windows 365 Boot configured device's camera in Microsoft Teams.\n1. Remove Windows 365 Boot from the physical device.\n2. On the physical device, open Settings > Privacy & Security > Camera > Let apps access\nyour camera.\n3. Set Azure Virtual Desktop (HostApp) to On.\n4. Add Windows 365 Boot back onto the physical device.\nUsers are currently blocked from accessing most features on their Windows 365 Boot physical\ndevices. However, to assist with troubleshooting, some features aren't blocked.\nTo learn how to restrict user access to the physical device, see Restrict user access to Windows\n365 Boot physical device.\nWindows 365 Boot physical devices might sign out users because of screen idle policies\napplied to the physical device or Cloud PC.\nTo use an Intune device configuration profile, change or configure the DeviceLock CSP policy\n(MaxInactivityTimeDeviceLock). Make these changes for both the physical device and the Cloud\nPC.\nCamera access is denied in the Cloud PC\nSolution\nUsers can still interact with physical device features\nlike Settings, Task Manager, and Notifications\nSolution\nUsers are discon","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3152,"title":"Windows 365 Switch Known Issues","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["windows","365","switch","known","issues","currently","only","supports","one","enabled","cloud","the","user","automatically","signed","first","available","supported","from","list","assigned","pcs","this","article","provides","troubleshooting","steps","for","recent","with","sign","different","users","can","select","ellipses","choose","and","then","add"],"errorCode":"","eventId":"","severity":"Medium","summary":"Currently, Windows 365 Switch only supports one Switch-enabled Cloud PC. The user is\nautomatically signed in to the first available Switch-supported Cloud PC from the list of\nassigned Cloud PCs.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. Select the Windows App Add to Task view button on the Cloud PC you want to add.\n2. Remove or replace a stale Cloud PC from the Task\n3. Users must switch back to their physical device and change the settings in the Settings app.\n4. Select the Task view button for the Cloud PC again. The connection continues in the","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 Switch Known Issues.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Windows 365 Switch known issues\nThis article provides troubleshooting steps for the recent known issues with Windows 365\nSwitch.\nCurrently, Windows 365 Switch only supports one Switch-enabled Cloud PC. The user is\nautomatically signed in to the first available Switch-supported Cloud PC from the list of\nassigned Cloud PCs. To sign in to a different Cloud PC, users can select the ellipses (...), choose\nthe Cloud PC, and then select Add to Task view. Only one Cloud PC can be added to the Task\nview at a time. If you try to pin multiple Cloud PCs to the Task view, they're added in a stack\nfashion. For example, if you remove the first Cloud PC you added, the second one takes its\nplace. Because only the first Cloud PC added is displayed in the Task view, we don't\nrecommend pinning more than one Cloud PC to the Task view.\nIf your Task view has a Cloud PC that you no longer have access to, you can remove and\nreplace it.\n1. Uninstall the Windows App.\n2. Reinstall the Windows App.\n3. Select the Windows App Add to Task view button on the Cloud PC you want to add.\nSome gestures, such as three-finger gestures to change apps or four-finger gestures to bring\nup the Task view and show the desktop, aren't supported in the Cloud PC. These gestures are\ntriggered on the physical device instead. All other usual Windows 11 gestures are supported.\nSupport for only one Cloud PC\nRemove or replace a stale Cloud PC from the Task\nview\nSolution\nLimited gestures\nBluetooth and hardware settings can't be managed\nfrom the Cloud PC\nCloud PCs lack hardware components like Bluetooth adapters. Users can't change the settings\nfrom the Cloud PC Settings app or quick settings.\nUsers must switch back to their physical device and change the settings in the Settings app.\nIf the Reconnect option in the disconnect message dialog is used, reconnecting might not\nwork as expected or result in an unusable Cloud PC session.\nLet the disconnect complete, and then launch a new connection using Task view.\nCloud PCs that are connected via Windows Task view quietly disconnect to avoid disrupting\nthe local PC session. The disconnected Cloud PC session shows a black screen with a message\nbox.\nWhen the re-connectable error message is displayed, you can reconnect through the message\nbox that reassemble the following screenshot:\nSolution\nReconnect button not working\nSolution\nCloud PC disconnects while focused on local PC\nSolution\nAfter you select a Cloud PC from the Task view, users might be prompted to sign in using their\naccount credentials. In some builds of Windows, after providing the credentials, users might\nnot be returned to the Cloud PC connection.\nSelect the Task view button for the Cloud PC again. The connection continues in the\nbackground. The user should be connected to their Cloud PC within a few minutes.\nIf the local PC is missing from the Cloud PC's Task view bar, the Azure Virtual Desktop\n(HostApp) might be outdated.\nUninstall and reinstall the Azure Virtual Desktop (HostApp) app from the Microsoft Store .\nTroubleshooting Windows 365 issues\nLast updated on 02/12/2026\nNavigation between sign-in prompts and your\nCloud PC\nSolution\nLocal PC missing from Cloud PC Task view bar\nSolution\nNext steps","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3153,"title":"Windows 365 BCDR Known Issues","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["windows","365","bcdr","known","issues","after","you","restore","cloud","from","snapshot","during","disaster","recovery","failover","upon","failing","back","the","primary","region","users","might","encounter","error","message","when","they","start","classic","outlook","this","issue","occurs","because","offline","cache","becomes","corrupted","client"],"errorCode":"","eventId":"","severity":"Medium","summary":"After you restore a Cloud PC from a snapshot during a disaster recovery failover, or upon\nfailing back to the primary region after the disaster, users might encounter an error message\nwhen they start classic Outlook. This issue occurs because the Outlook offline cache becomes corrupted because the client and\nthe server become out of sync during a failover.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. Use the new Outlook app. The new Outlook app uses a different caching mechanism that","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 BCDR Known Issues.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Windows 365 BCDR known issues\nThis article addresses a known issue that's related to Windows 365 Business Continuity and\nDisaster Recovery (BCDR) scenarios.\nAfter you restore a Cloud PC from a snapshot during a disaster recovery failover, or upon\nfailing back to the primary region after the disaster, users might encounter an error message\nwhen they start classic Outlook.\nThis issue occurs because the Outlook offline cache becomes corrupted because the client and\nthe server become out of sync during a failover. The client on the snapshot reflects a past state\nrelative to the server's current status. The process of resynchronizing the Offline Storage Table\n(OST) file can take time.\nThis process doesn't cause any data loss.\nAfter you complete a failover or failback operation, delete the Cloud PC's OST file.\nThis action forces Outlook to rebuild the search index and the offline cache of the mailbox. This\nprocess doesn't cause any data loss.\nUse the new Outlook app. The new Outlook app uses a different caching mechanism that\neliminates this synchronization issue.\nLast updated on 02/12/2026\nClassic Outlook is corrupted after disaster recovery\nfailover or failback\nWorkaround\nResolution","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3154,"title":"Windows 365 for Agents Provisioning Errors","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Troubleshooting"],"keywords":["windows","365","for","agents","provisioning","errors","troubleshoot","when","you","provision","cloud","pcs","can","cause","pool","status","show","failed","available","with","warning","this","article","describes","the","most","common","issues","and","how","resolve","them","selected","billing","plan","policy","invalid","until","has","valid"],"errorCode":"","eventId":"","severity":"High","summary":"Troubleshoot Windows 365 for Agents\nprovisioning errors\nWhen you provision Cloud PCs in Windows 365 for Agents, provisioning errors can cause a Cloud\nPC pool status to show as Failed or Available with warning. This article describes the most\ncommon provisioning issues and how to resolve them.","rootCause":"This Windows 365 condition is commonly caused by a problem with licensing, policy assignment, Microsoft Entra ID, Intune enrollment, network configuration, client state, or Cloud PC provisioning. Review the detailed source notes and service health to identify the specific cause.","resolution":"1. Review the pool configuration, and edit it as necessary. Then, try to reprovision the Cloud PC.","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 for Agents Provisioning Errors.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. Please retry after we confirm the Cloud PC configuration is healthy.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you are signed in with your company account.\n2. Check that your internet connection is stable.\n3. Restart the Windows 365 application or browser session.\n4. Record the full error message and contact IT Support if access is still unavailable.","notes":"Troubleshoot Windows 365 for Agents\nprovisioning errors\nWhen you provision Cloud PCs in Windows 365 for Agents, provisioning errors can cause a Cloud\nPC pool status to show as Failed or Available with warning. This article describes the most\ncommon provisioning issues and how to resolve them.\nThe selected billing plan for the provisioning policy (agents) is invalid. Until the provisioning\npolicy has a valid billing plan, you can't provision Cloud PCs, and all pool updates fail.\nTo resolve this issue, update the billing plan, and then try again to provision the Cloud PCs.\nReview the pool configuration, and edit it as necessary. Then, try to reprovision the Cloud PC.\nIf an update doesn't install, try again to install the update.\nLast updated on 06/02/2026\nSummary\nInvalid billing plan\nCan't reprovision Cloud PC\nOther failures or warnings","sourceDocument":"troubleshoot-windows-365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Troubleshooting"],"aliases":[]},{"id":3155,"title":"Windows 365 Troubleshooting and Support Portal","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Support Reference"],"keywords":["windows","365","troubleshooting","and","support","portal","use","the","microsoft","endpoint","manager","workflow","inspect","user","assigned","licenses","group","membership","managed","devices","enrollment","failures","cloud","state","before","escalating"],"errorCode":"","eventId":"","severity":"Medium","summary":"Use the Microsoft Endpoint Manager Troubleshooting + support workflow to inspect a user, assigned licenses, group membership, managed devices, enrollment failures, and Cloud PC state before escalating.","rootCause":"Windows 365 depends on coordinated licensing, Microsoft Entra ID, Intune, networking, and provisioning-policy configuration. A missing or unhealthy dependency can prevent provisioning or user access.","resolution":"1. Record where Windows 365 Troubleshooting and Support Portal occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 Troubleshooting and Support Portal.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are correcting the account or Cloud PC configuration and will validate access.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Sign in with your assigned company account.\n2. Confirm your device has a working internet connection.\n3. Record the complete message shown on screen.\n4. Contact IT Support so your license, policy, and Cloud PC state can be checked.","notes":"Use the Microsoft Endpoint Manager Troubleshooting + support workflow to inspect a user, assigned licenses, group membership, managed devices, enrollment failures, and Cloud PC state before escalating.","sourceDocument":"troubleshooting_365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Support Reference"],"aliases":[]},{"id":3156,"title":"Windows 365 Hybrid Entra ID Join Failed","category":"Entra ID","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Support Reference"],"keywords":["windows","365","hybrid","entra","join","failed","cloud","provisioning","can","fail","when","the","computer","object","does","not","synchronize","from","active","directory","microsoft","service","connection","point","missing","connect","synchronization","unhealthy"],"errorCode":"","eventId":"","severity":"Medium","summary":"Cloud PC provisioning can fail when the computer object does not synchronize from Active Directory to Microsoft Entra ID, the service connection point is missing, or Entra Connect synchronization is unhealthy.","rootCause":"Windows 365 depends on coordinated licensing, Microsoft Entra ID, Intune, networking, and provisioning-policy configuration. A missing or unhealthy dependency can prevent provisioning or user access.","resolution":"1. Record where Windows 365 Hybrid Entra ID Join Failed occurred and reproduce the operation if it is safe to do so.\n2. Verify the referenced path, file, drive, or component exists and is accessible.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Verify the required service or agent is installed, running, and current; repair the component if needed.\n5. Review Event Viewer and the application or service log for the same timestamp and code.\n6. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 Hybrid Entra ID Join Failed.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are correcting the account or Cloud PC configuration and will validate access.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Sign in with your assigned company account.\n2. Confirm your device has a working internet connection.\n3. Record the complete message shown on screen.\n4. Contact IT Support so your license, policy, and Cloud PC state can be checked.","notes":"Cloud PC provisioning can fail when the computer object does not synchronize from Active Directory to Microsoft Entra ID, the service connection point is missing, or Entra Connect synchronization is unhealthy.","sourceDocument":"troubleshooting_365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Support Reference"],"aliases":[]},{"id":3157,"title":"Windows 365 Intune Enrollment Failed","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Support Reference"],"keywords":["windows","365","intune","enrollment","failed","provisioning","can","fail","when","device","based","mdm","into","blocked","licensing","restrictions","scope","tenant","health"],"errorCode":"","eventId":"","severity":"Medium","summary":"Windows 365 provisioning can fail when device-based MDM enrollment into Intune is blocked by licensing, enrollment restrictions, MDM scope, or tenant health.","rootCause":"Windows 365 depends on coordinated licensing, Microsoft Entra ID, Intune, networking, and provisioning-policy configuration. A missing or unhealthy dependency can prevent provisioning or user access.","resolution":"1. Record where Windows 365 Intune Enrollment Failed occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 Intune Enrollment Failed.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are correcting the account or Cloud PC configuration and will validate access.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Sign in with your assigned company account.\n2. Confirm your device has a working internet connection.\n3. Record the complete message shown on screen.\n4. Contact IT Support so your license, policy, and Cloud PC state can be checked.","notes":"Windows 365 provisioning can fail when device-based MDM enrollment into Intune is blocked by licensing, enrollment restrictions, MDM scope, or tenant health.","sourceDocument":"troubleshooting_365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Support Reference"],"aliases":[]},{"id":3158,"title":"Windows 365 Provisioning Policy Not Found","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Support Reference"],"keywords":["windows","365","provisioning","policy","not","found","the","assigned","user","cloud","cannot","locate","valid","because","group","assignment","deletion","synchronization","issues"],"errorCode":"","eventId":"","severity":"Medium","summary":"The assigned user or Cloud PC cannot locate a valid Windows 365 provisioning policy because of group assignment, policy deletion, or synchronization issues.","rootCause":"Windows 365 depends on coordinated licensing, Microsoft Entra ID, Intune, networking, and provisioning-policy configuration. A missing or unhealthy dependency can prevent provisioning or user access.","resolution":"1. Record where Windows 365 Provisioning Policy Not Found occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 Provisioning Policy Not Found.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are correcting the account or Cloud PC configuration and will validate access.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Sign in with your assigned company account.\n2. Confirm your device has a working internet connection.\n3. Record the complete message shown on screen.\n4. Contact IT Support so your license, policy, and Cloud PC state can be checked.","notes":"The assigned user or Cloud PC cannot locate a valid Windows 365 provisioning policy because of group assignment, policy deletion, or synchronization issues.","sourceDocument":"troubleshooting_365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Support Reference"],"aliases":[]},{"id":3159,"title":"Windows 365 User Not Found","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Support Reference"],"keywords":["windows","365","user","not","found","provisioning","cannot","continue","when","the","assigned","resolved","does","have","required","and","intune","licensing","group","membership"],"errorCode":"","eventId":"","severity":"Medium","summary":"Provisioning cannot continue when the assigned user cannot be resolved or does not have the required Windows 365 and Intune licensing and group membership.","rootCause":"Windows 365 depends on coordinated licensing, Microsoft Entra ID, Intune, networking, and provisioning-policy configuration. A missing or unhealthy dependency can prevent provisioning or user access.","resolution":"1. Record where Windows 365 User Not Found occurred and reproduce the operation if it is safe to do so.\n2. Review Event Viewer and the application or service log for the same timestamp and code.\n3. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 User Not Found.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are correcting the account or Cloud PC configuration and will validate access.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Sign in with your assigned company account.\n2. Confirm your device has a working internet connection.\n3. Record the complete message shown on screen.\n4. Contact IT Support so your license, policy, and Cloud PC state can be checked.","notes":"Provisioning cannot continue when the assigned user cannot be resolved or does not have the required Windows 365 and Intune licensing and group membership.","sourceDocument":"troubleshooting_365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Support Reference"],"aliases":[]},{"id":3160,"title":"Windows 365 Cloud PC Device-Based Filtering","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Support Reference"],"keywords":["windows","365","cloud","device","based","filtering","dynamic","groups","should","use","supported","properties","policies","and","applications","target","the","intended","pcs"],"errorCode":"","eventId":"","severity":"Medium","summary":"Cloud PC dynamic device groups should use supported Windows 365 device properties so policies and applications target the intended Cloud PCs.","rootCause":"Windows 365 depends on coordinated licensing, Microsoft Entra ID, Intune, networking, and provisioning-policy configuration. A missing or unhealthy dependency can prevent provisioning or user access.","resolution":"1. Record where Windows 365 Cloud PC Device-Based Filtering occurred and reproduce the operation if it is safe to do so.\n2. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n3. Review Event Viewer and the application or service log for the same timestamp and code.\n4. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 Cloud PC Device-Based Filtering.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are correcting the account or Cloud PC configuration and will validate access.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Sign in with your assigned company account.\n2. Confirm your device has a working internet connection.\n3. Record the complete message shown on screen.\n4. Contact IT Support so your license, policy, and Cloud PC state can be checked.","notes":"Cloud PC dynamic device groups should use supported Windows 365 device properties so policies and applications target the intended Cloud PCs.","sourceDocument":"troubleshooting_365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Support Reference"],"aliases":[]},{"id":3161,"title":"Windows 365 Cloud PC Access Ending","category":"Microsoft 365","product":"Windows 365 Cloud PC","tags":["Windows 365","Cloud PC","Support Reference"],"keywords":["windows","365","cloud","access","ending","user","may","see","that","when","licensing","provisioning","policy","group","membership","removed","and","the","enters","its","grace","period"],"errorCode":"","eventId":"","severity":"Medium","summary":"A user may see that Cloud PC access is ending when licensing or provisioning-policy group membership is removed and the Cloud PC enters its grace period.","rootCause":"Windows 365 depends on coordinated licensing, Microsoft Entra ID, Intune, networking, and provisioning-policy configuration. A missing or unhealthy dependency can prevent provisioning or user access.","resolution":"1. Record where Windows 365 Cloud PC Access Ending occurred and reproduce the operation if it is safe to do so.\n2. Confirm the user or service identity has the required permissions and is not locked or disabled.\n3. Test DNS, routing, proxy, firewall, TLS, and service availability from the affected system.\n4. Review Event Viewer and the application or service log for the same timestamp and code.\n5. Correct the confirmed cause, retry once, and validate normal operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Windows 365 Cloud PC Access Ending.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are correcting the account or Cloud PC configuration and will validate access.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Sign in with your assigned company account.\n2. Confirm your device has a working internet connection.\n3. Record the complete message shown on screen.\n4. Contact IT Support so your license, policy, and Cloud PC state can be checked.","notes":"A user may see that Cloud PC access is ending when licensing or provisioning-policy group membership is removed and the Cloud PC enters its grace period.","sourceDocument":"troubleshooting_365.pdf","platforms":["windows"],"vendors":["Windows 365 Cloud PC"],"technologies":["Windows 365","Cloud PC","Support Reference"],"aliases":[]},{"id":3162,"title":"Error Handling (Error Handling)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["error","handling","well","written","applications","include","code","that","allows","them","recover","gracefully","from","unexpected","errors","2025","when","occurs","the","application","may","need","request","user","intervention","able","its","own","extreme","cases","log","off","shut","down","system","about","using","reference","for","information"],"errorCode":"","eventId":"","severity":"Low","summary":"Well-written applications include error-handling code that allows them to recover gracefully\nfrom unexpected errors.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to Error Handling (Error Handling).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"Error Handling (Error Handling)\n07/14/2025\nWell-written applications include error-handling code that allows them to recover gracefully\nfrom unexpected errors. When an error occurs, the application may need to request user\nintervention, or it may be able to recover on its own. In extreme cases, the application may log\nthe user off or shut down the system.\nAbout Error Handling\nUsing Error Handling\nError Handling Reference\nFor information about exception handling, see Structured Exception Handling.\nAbout Error Handling\nThe error handling functions enable you to receive and display error information for your\napplication. For more information, see the following topics:\nError Mode\nLast Error Code\nNotifying the User\nMessage Tables\nFatal Application Exit\nFor information on writing error messages, see Error Message Guidelines.\n \n \nLast updated on 07/14/2025\nError Mode\nThe error mode indicates to the system how the application is going to respond to serious\nerrors. Serious errors include disk failure, drive-not-ready errors, data misalignment, and\nunhandled exceptions. This error mode can be managed by either a per-thread or per-process\nbasis. An application can let the system display a message box informing the user that an error\nhas occurred, or it can handle the errors.\nTo handle these errors without user intervention, use SetErrorMode or the thread-specific\nSetThreadErrorMode. After calling one of these functions and specifying appropriate flags, the\nsystem will not display the corresponding error message boxes.\nA process can retrieve its error mode using GetErrorMode or GetThreadErrorMode.\nBest practice is that all applications call the process-wide SetErrorMode function with a\nparameter of SEM_FAILCRITICALERRORS at startup. This is to prevent error mode dialogs from\nhanging the application.\nOther than that, callers should favor the thread-specific versions of these functions since they\nare less disruptive to the normal behavior of the system.\n \n \nLast updated on 07/14/2025\nLast-Error Code\nWhen an error occurs, most system functions return an error code, usually 0, NULL, or –1. Many\nsystem functions also set an additional error code called the last-error code. This error code is\nmaintained separately for each running thread; an error in one thread does not overwrite the\nlast-error code in another thread. Any function can call the SetLastError or SetLastErrorEx\nfunction to set the last-error code for the current thread. These functions are intended\nprimarily for dynamic-link libraries (DLL), so they can provide information to the calling\napplication. Note that some functions call SetLastError or SetLastErrorEx with 0 when they\nsucceed, wiping out the error code set by the most recently failed function, while others do\nnot.\nAn application can retrieve the last-error code by using the GetLastError function; the error\ncode may tell more about what actually occurred to make the function fail. The documentation\nfor system functions will indicate the conditions under which the function sets the last-error\ncode.\nThe system defines a set of error codes that can be set as last-error codes or be returned by\nthese functions. Error codes are 32-bit values (bit 31 is the most significant bit). Bit 29 is\nreserved for application-defined error codes; no system error code has this bit set. If you define\nerror codes for your application, set this bit to indicate that the error code has been defined by\nan application and to ensure that the error codes do not conflict with any system-defined error\ncodes. For more information, see WinError.h and System Error Codes.\n \n \nLast updated on 07/14/2025\nNotifying the User\nTo notify the user that some kind of error has occurred, many applications simply produce a\nsound by using the MessageBeep function or flash the window by using either the\nFlashWindow or FlashWindowEx function. An application can also use these functions to call\nattention to an error and then display a message box or an error message containing details\nabout the error.\n \n \nLast updated on 07/14/2025\nMessage Tables\nMessage tables are special string resources used when displaying error messages. They are\ndeclared in a resource file using the MESSAGETABLE resource-definition statement. To access\nthe message strings, use the FormatMessage function.\nThe system provides a message table for the system error codes. To retrieve the string that\ncorresponds to the error code, call FormatMessage with the\nFORMAT_MESSAGE_FROM_SYSTEM flag.\nTo provide a message table for your application, follow the instructions in Message Text Files.\nTo retrieve strings from your message table, call FormatMessage with the\nFORMAT_MESSAGE_FROM_HMODULE flag.\n \n \nLast updated on 07/14/2025\nFatal Application Exit\nThe FatalAppExit function displays a message box and terminates the application when the\nuser closes the message box. This function should only be used as a last resort, because it may\nnot free the memory or files owned by the application.\n \n \nLast updated on 07/14/2025\nError Message Guidelines\nAn error message is text that is displayed to describe a problem that has occurred that is\npreventing the user or the system from completing a task. The problem could result in data\ncorruption or loss. Other message types include confirmations, warnings, and notifications. The\nguidelines in this topic are intended to help you write clear error messages that are easy to\nlocalize and useful for customers.\nPoorly written error messages can be a source of frustration for users and can increase\ntechnical support costs. A well-written error message provides the following information to the\nuser:\nWhat happened and why?\nWhat is the end result for the user?\nWhat can the user do to prevent it from happening again?\nThe length of the text is not an issue as long as the developer handles buffer sizes correctly. It\nis important that the user have all the information necessary to solve the problem. If a message\nhas multiple audiences, you may need to pro","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3163,"title":"Beep function (utilapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["beep","function","utilapiset","generates","simple","tones","the","speaker","article02","2025","synchronous","performs","alertable","wait","and","does","not","return","control","its","caller","until","sound","finishes","dwfreq","frequency","hertz","this","parameter","must","range","through","767","0x25","0x7fff","dwduration","duration","milliseconds","succeeds","value"],"errorCode":"","eventId":"","severity":"Low","summary":"Generates simple tones on the speaker.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to Beep function (utilapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"Beep function (utilapiset.h)\nArticle02/05/2025\nGenerates simple tones on the speaker. The function is synchronous; it performs an alertable\nwait and does not return control to its caller until the sound finishes.\nC++\n[in] dwFreq\nThe frequency of the sound, in hertz. This parameter must be in the range 37 through 32,767\n(0x25 through 0x7FFF).\n[in] dwDuration\nThe duration of the sound, in milliseconds.\nIf the function succeeds, the return value is nonzero.\nIf the function fails, the return value is zero. To get extended error information, call\nGetLastError.\nA long time ago, all PC computers shared a common 8254 programmable interval timer chip\nfor the generation of primitive sounds. The Beep function was written specifically to emit a\nbeep on that piece of hardware.\nOn these older systems, muting and volume controls have no effect on Beep; you would still\nhear the tone. To silence the tone, you used the following commands:\nSyntax\nBOOL Beep(\n [in] DWORD dwFreq,\n [in] DWORD dwDuration\n);\nParameters\nReturn value\nRemarks\nnet stop beep\nsc config beep start= disabled\nSince then, sound cards have become standard equipment on almost all PC computers. As\nsound cards became more common, manufacturers began to remove the old timer chip from\ncomputers. The chips were also excluded from the design of server computers. The result is\nthat Beep did not work on all computers without the chip. This was okay because most\ndevelopers had moved on to calling the MessageBeep function that uses whatever is the\ndefault sound device instead of the 8254 chip.\nEventually because of the lack of hardware to communicate with, support for playing sound\nfrom the motherboard speaker was dropped in Windows Vista and Windows XP 64-Bit Edition.\nIn Windows 7, Beep was rewritten to pass the beep to the default sound device for the session.\nThis is normally the sound card, except when run under Terminal Services, in which case the\nbeep is rendered on the client.\nThe following example demonstrates the use of this function.\nC++\nRequirement Value\nMinimum supported client Windows XP [desktop apps | UWP apps]\nMinimum supported server Windows Server 2003 [desktop apps | UWP apps]\nTarget Platform Windows\nHeader utilapiset.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nExamples\nBeep( 750, 300 );\nRequirements\nﾉ Expand table\nError Handling Functions\nMessageBeep\nNotifying the User\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3164,"title":"FlashWindow function (winuser.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["flashwindow","function","winuser","flashes","the","specified","window","one","time","2021","does","not","change","active","state","flash","number","times","use","flashwindowex","hwnd","handle","flashed","can","either","open","minimized","binvert","this","parameter","true","from","other","false","returned","its","original","inactive","when","application"],"errorCode":"","eventId":"","severity":"Low","summary":"Flashes the specified window one time.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to FlashWindow function (winuser.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"FlashWindow function (winuser.h)\n10/13/2021\nFlashes the specified window one time. It does not change the active state of the window.\nTo flash the window a specified number of times, use the FlashWindowEx function.\nC++\n[in] hWnd\nA handle to the window to be flashed. The window can be either open or minimized.\n[in] bInvert\nIf this parameter is TRUE, the window is flashed from one state to the other. If it is FALSE, the\nwindow is returned to its original state (either active or inactive).\nWhen an application is minimized and this parameter is TRUE, the taskbar window button\nflashes active/inactive. If it is FALSE, the taskbar window button flashes inactive, meaning that it\ndoes not change colors. It flashes, as if it were being redrawn, but it does not provide the visual\ninvert clue to the user.\nThe return value specifies the window's state before the call to the FlashWindow function. If\nthe window caption was drawn as active before the call, the return value is nonzero. Otherwise,\nthe return value is zero.\nSyntax\nBOOL FlashWindow(\n [in] HWND hWnd,\n [in] BOOL bInvert\n);\nParameters\nReturn value\nRemarks\nFlashing a window means changing the appearance of its caption bar as if the window were\nchanging from inactive to active status, or vice versa. (An inactive caption bar changes to an\nactive caption bar; an active caption bar changes to an inactive caption bar.)\nTypically, a window is flashed to inform the user that the window requires attention but that it\ndoes not currently have the keyboard focus.\nThe FlashWindow function flashes the window only once; for repeated flashing, the application\nshould create a system timer.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader winuser.h (include Windows.h)\nLibrary User32.lib\nDLL User32.dll\nError Handling Functions\nNotifying the User\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3165,"title":"FlashWindowEx function (winuser.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["flashwindowex","function","winuser","does","not","change","the","active","state","window","2024","flashes","specified","pfwi","pointer","flashwinfo","structure","return","value","specifies","before","call","caption","was","drawn","nonzero","otherwise","zero","typically","you","flash","inform","user","that","requires","attention","but","currently","have","keyboard"],"errorCode":"","eventId":"","severity":"Low","summary":"It does not change the active state of the window.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to FlashWindowEx function (winuser.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"FlashWindowEx function (winuser.h)\n02/22/2024\nFlashes the specified window. It does not change the active state of the window.\nC++\n[in] pfwi\nA pointer to a FLASHWINFO structure.\nThe return value specifies the window's state before the call to the FlashWindowEx function. If\nthe window caption was drawn as active before the call, the return value is nonzero. Otherwise,\nthe return value is zero.\nTypically, you flash a window to inform the user that the window requires attention but does\nnot currently have the keyboard focus. When a window flashes, it appears to change from\ninactive to active status. An inactive caption bar changes to an active caption bar; an active\ncaption bar changes to an inactive caption bar.\nRequirement Value\nMinimum supported clientWindows XP [desktop apps only]\nSyntax\nBOOL FlashWindowEx(\n [in] PFLASHWINFO pfwi\n);\nParameters\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nRequirement Value\nMinimum supported\nserver\nWindows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader winuser.h (include Windows.h)\nLibrary User32.lib\nDLL User32.dll\nAPI set ext-ms-win-ntuser-misc-l1-5-0 (introduced in Windows 10, version\n10.0.10240)\nError Handling Functions\nFLASHWINFO\nNotifying the User\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3166,"title":"FormatMessage function (winbase.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["formatmessage","function","winbase","the","requires","message","definition","input","article09","2022","formats","string","can","come","from","buffer","passed","into","table","resource","already","loaded","module","caller","ask","search","system","for","finds","based","identifier","and","language","copies","formatted","text","output","processing","any","embedded"],"errorCode":"","eventId":"","severity":"Low","summary":"The function requires a message definition as input.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to FormatMessage function (winbase.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"FormatMessage function (winbase.h)\nArticle09/22/2022\nFormats a message string. The function requires a message definition as input. The message\ndefinition can come from a buffer passed into the function. It can come from a message table\nresource in an already-loaded module. Or the caller can ask the function to search the system's\nmessage table resource(s) for the message definition. The function finds the message definition\nin a message table resource based on a message identifier and a language identifier. The\nfunction copies the formatted message text to an output buffer, processing any embedded\ninsert sequences if requested.\nC++\n[in] dwFlags\nThe formatting options, and how to interpret the lpSource parameter. The low-order byte of\ndwFlags specifies how the function handles line breaks in the output buffer. The low-order byte\ncan also specify the maximum width of a formatted output line.\nThis parameter can be one or more of the following values.\nValue Meaning\nFORMAT_MESSAGE_ALLOCATE_BUFFER\n0x00000100\nThe function allocates a buffer large enough to hold the\nformatted message, and places a pointer to the allocated\nbuffer at the address specified by lpBuffer. The lpBuffer\nparameter is a pointer to an LPTSTR; you must cast the\npointer to an LPTSTR (for example, (LPTSTR)&lpBuffer). The\nSyntax\nDWORD FormatMessage(\n [in] DWORD dwFlags,\n [in, optional] LPCVOID lpSource,\n [in] DWORD dwMessageId,\n [in] DWORD dwLanguageId,\n [out] LPTSTR lpBuffer,\n [in] DWORD nSize,\n [in, optional] va_list *Arguments\n);\nParameters\nﾉ Expand table\nnSize parameter specifies the minimum number of TCHARs to\nallocate for an output message buffer. The caller should use\nthe LocalFree function to free the buffer when it is no longer\nneeded.\nIf the length of the formatted message exceeds 128K bytes,\nthen FormatMessage will fail and a subsequent call to\nGetLastError will return ERROR_MORE_DATA.\nIn previous versions of Windows, this value was not available\nfor use when compiling Windows Store apps. As of\nWindows 10 this value can be used.\nWindows Server 2003 and Windows XP: \nIf the length of the formatted message exceeds 128K bytes,\nthen FormatMessage will not automatically fail with an error\nof ERROR_MORE_DATA.\nFORMAT_MESSAGE_ARGUMENT_ARRAY\n0x00002000\nThe Arguments parameter is not a va_list structure, but is a\npointer to an array of values that represent the arguments.\nThis flag cannot be used with 64-bit integer values. If you are\nusing a 64-bit integer, you must use the va_list structure.\nFORMAT_MESSAGE_FROM_HMODULE\n0x00000800\nThe lpSource parameter is a module handle containing the\nmessage-table resource(s) to search. If this lpSource handle is\nNULL, the current process's application image file will be\nsearched. This flag cannot be used with\nFORMAT_MESSAGE_FROM_STRING.\nIf the module has no message table resource, the function\nfails with ERROR_RESOURCE_TYPE_NOT_FOUND.\nFORMAT_MESSAGE_FROM_STRING\n0x00000400\nThe lpSource parameter is a pointer to a null-terminated\nstring that contains a message definition. The message\ndefinition may contain insert sequences, just as the message\ntext in a message table resource may. This flag cannot be\nused with FORMAT_MESSAGE_FROM_HMODULE or\nFORMAT_MESSAGE_FROM_SYSTEM.\nFORMAT_MESSAGE_FROM_SYSTEM\n0x00001000\nThe function should search the system message-table\nresource(s) for the requested message. If this flag is specified\nwith FORMAT_MESSAGE_FROM_HMODULE, the function\nsearches the system message table if the message is not\nfound in the module specified by lpSource. This flag cannot be\nused with FORMAT_MESSAGE_FROM_STRING.\nIf this flag is specified, an application can pass the result of\nthe GetLastError function to retrieve the message text for a\nsystem-defined error.\nFORMAT_MESSAGE_IGNORE_INSERTS\n0x00000200\nInsert sequences in the message definition such as %1 are to\nbe ignored and passed through to the output buffer\nunchanged. This flag is useful for fetching a message for later\nformatting. If this flag is set, the Arguments parameter is\nignored.\n \nThe low-order byte of dwFlags can specify the maximum width of a formatted output line. The\nfollowing are possible values of the low-order byte.\nValue Meaning\n0 There are no output line width restrictions. The function\nstores line breaks that are in the message definition text into\nthe output buffer.\nFORMAT_MESSAGE_MAX_WIDTH_MASK\n0x000000FF\nThe function ignores regular line breaks in the message\ndefinition text. The function stores hard-coded line breaks in\nthe message definition text into the output buffer. The\nfunction generates no new line breaks.\n \nIf the low-order byte is a nonzero value other than FORMAT_MESSAGE_MAX_WIDTH_MASK, it\nspecifies the maximum number of characters in an output line. The function ignores regular\nline breaks in the message definition text. The function never splits a string delimited by white\nspace across a line break. The function stores hard-coded line breaks in the message definition\ntext into the output buffer. Hard-coded line breaks are coded with the %n escape sequence.\n[in, optional] lpSource\nThe location of the message definition. The type of this parameter depends upon the settings\nin the dwFlags parameter.\ndwFlags Setting Meaning\nFORMAT_MESSAGE_FROM_HMODULE\n0x00000800\nA handle to the module that contains the message table to\nsearch.\nFORMAT_MESSAGE_FROM_STRING\n0x00000400\nPointer to a string that consists of unformatted message text.\nIt will be scanned for inserts and formatted accordingly.\n \nﾉ Expand table\nﾉ Expand table\nIf neither of these flags is set in dwFlags, then lpSource is ignored.\n[in] dwMessageId\nThe message identifier for the requested message. This parameter is ignored if dwFlags\nincludes FORMAT_MESSAGE_FROM_STRING.\n[in] dwLanguageId\nThe language identifier for the requested message. This parameter is ignored if dwFlags\nincludes FORMAT_MESSAGE_FROM_STRING.\nIf you pass a specific LANGID in this parameter, FormatMessage will return a message for that\nLANGID only. If the function cannot find a mess","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3167,"title":"GetErrorMode function (errhandlingapi.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["geterrormode","function","errhandlingapi","retrieves","the","error","mode","for","current","process","article02","2025","this","returns","one","following","values","return","code","value","description","uses","system","default","which","displays","all","dialog","boxes","sem","failcriticalerrors","0x0001","does","not","display","critical","handler","message","box","instead"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the error mode for the current process.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to GetErrorMode function (errhandlingapi.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"GetErrorMode function (errhandlingapi.h)\nArticle02/12/2025\nRetrieves the error mode for the current process.\nC++\nThe process error mode. This function returns one of the following values.\nReturn code/value Description\n0 Uses the system default, which displays all error dialog boxes.\nSEM_FAILCRITICALERRORS\n0x0001\nThe system does not display the critical-error-handler\nmessage box. Instead, the system sends the error to the\ncalling process.\nSEM_NOALIGNMENTFAULTEXCEPT\n0x0004\nThe system automatically fixes memory alignment faults and\nmakes them invisible to the application. It does this for the\ncalling process and any descendant processes. This feature is\nonly supported by certain processor architectures. For more\ninformation, see SetErrorMode.\nSEM_NOGPFAULTERRORBOX\n0x0002\nThe system does not display the Windows Error Reporting\ndialog.\nSEM_NOOPENFILEERRORBOX\n0x8000\nThe system does not display a message box when it fails to\nfind a file. Instead, the error is returned to the calling process.\nEach process has an associated error mode that indicates to the system how the application is\ngoing to respond to serious errors. A child process inherits the error mode of its parent\nprocess.\nSyntax\nUINT GetErrorMode();\nReturn value\nﾉ Expand table\nRemarks\nTo change the error mode for the process, use the SetErrorMode function.\nWindows 7: Callers should favor SetThreadErrorMode over SetErrorMode since it is less\ndisruptive to the normal behavior of the system. GetThreadErrorMode is the call function that\ncorresponds to GetErrorMode.\nRequirement Value\nMinimum supported client Windows Vista [desktop apps only]\nMinimum supported server Windows Server 2008 [desktop apps only]\nTarget Platform Windows\nHeader errhandlingapi.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nError Handling Functions\nError Mode\nGetThreadErrorMode\nSetErrorMode\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3168,"title":"GetLastError function (errhandlingapi.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["getlasterror","function","errhandlingapi","retrieves","the","calling","thread","last","error","code","value","article02","2024","maintained","perthread","basis","multiple","threads","not","overwrite","each","other","visual","basic","applications","should","call","err","lastdllerror","instead","return","section","documentation","for","that","sets","notes","conditions","under","which"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the calling thread's last-error code value.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to GetLastError function (errhandlingapi.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"GetLastError function (errhandlingapi.h)\nArticle02/06/2024\nRetrieves the calling thread's last-error code value. The last-error code is maintained on a perthread basis. Multiple threads do not overwrite each other's last-error code.\nVisual Basic: Applications should call err.LastDllError instead of GetLastError.\nC++\nThe return value is the calling thread's last-error code.\nThe Return Value section of the documentation for each function that sets the last-error code\nnotes the conditions under which the function sets the last-error code. Most functions that set\nthe thread's last-error code set it when they fail. However, some functions also set the lasterror code when they succeed. If the function is not documented to set the last-error code, the\nvalue returned by this function is simply the most recent last-error code to have been set;\nsome functions set the last-error code to 0 on success and others do not.\nFunctions executed by the calling thread set this value by calling the SetLastError function. You\nshould call the GetLastError function immediately when a function's return value indicates that\nsuch a call will return useful data. That is because some functions call SetLastError with a zero\nwhen they succeed, wiping out the error code set by the most recently failed function.\nTo obtain an error string for system error codes, use the FormatMessage function. For a\ncomplete list of error codes provided by the operating system, see System Error Codes.\nThe error codes returned by a function are not part of the Windows API specification and can\nvary by operating system or device driver. For this reason, we cannot provide the complete list\nof error codes that can be returned by each function. There are also many functions whose\ndocumentation does not include even a partial list of error codes that can be returned.\nSyntax\n_Post_equals_last_error_ DWORD GetLastError();\nReturn value\nRemarks\nError codes are 32-bit values (bit 31 is the most significant bit). Bit 29 is reserved for\napplication-defined error codes; no system error code has this bit set. If you are defining an\nerror code for your application, set this bit to one. That indicates that the error code has been\ndefined by an application, and ensures that your error code does not conflict with any error\ncodes defined by the system.\nTo convert a system error into an HRESULT value, use the HRESULT_FROM_WIN32 macro.\nFor an example, see Retrieving the Last-Error Code.\nRequirement Value\nMinimum supported client Windows XP [desktop apps | UWP apps]\nMinimum supported server Windows Server 2003 [desktop apps | UWP apps]\nTarget Platform Windows\nHeader errhandlingapi.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nError Handling Functions\nFormatMessage\nHRESULT_FROM_WIN32\nLast-Error Code\nSetLastError\nSetLastErrorEx\nVertdll APIs available in VBS enclaves\nExamples\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3169,"title":"GetThreadErrorMode function (errhandlingapi.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["getthreaderrormode","function","errhandlingapi","retrieves","the","error","mode","for","calling","thread","article02","2025","process","this","returns","one","following","values","return","code","value","description","uses","system","default","which","display","all","dialog","boxes","sem","failcriticalerrors","0x0001","does","not","critical","handler","message","box","instead"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the error mode for the calling thread.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to GetThreadErrorMode function (errhandlingapi.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"GetThreadErrorMode function\n(errhandlingapi.h)\nArticle02/12/2025\nRetrieves the error mode for the calling thread.\nC++\nThe process error mode. This function returns one of the following values.\nReturn code/value Description\n0 Uses the system default, which is to display all error dialog\nboxes.\nSEM_FAILCRITICALERRORS\n0x0001\nThe system does not display the critical-error-handler\nmessage box. Instead, the system sends the error to the\ncalling thread.\nSEM_NOGPFAULTERRORBOX\n0x0002\nThe system does not display the Windows Error Reporting\ndialog.\nSEM_NOOPENFILEERRORBOX\n0x8000\nThe system does not display a message box when it fails to\nfind a file. Instead, the error is returned to the calling thread.\nA thread inherits the error mode of the process in which it is running. To change the error\nmode for the thread, use the SetThreadErrorMode function.\nSyntax\nDWORD GetThreadErrorMode();\nReturn value\nﾉ Expand table\nRemarks\nRequirements\nRequirement Value\nMinimum supported client Windows 7 [desktop apps | UWP apps]\nMinimum supported server Windows Server 2008 R2 [desktop apps | UWP apps]\nTarget Platform Windows\nHeader errhandlingapi.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nGetErrorMode\nSetThreadErrorMode\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3170,"title":"MessageBeep function (winuser.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["messagebeep","function","winuser","the","waveform","sound","for","each","type","identified","entry","registry","2025","plays","utype","played","sounds","are","set","user","through","control","panel","application","and","then","stored","this","parameter","can","one","following","values","value","meaning","0xffffffff","simple","beep","card","not"],"errorCode":"","eventId":"","severity":"Low","summary":"The waveform sound for each sound type is identified by an entry in\nthe registry.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MessageBeep function (winuser.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MessageBeep function (winuser.h)\n02/05/2025\nPlays a waveform sound. The waveform sound for each sound type is identified by an entry in\nthe registry.\n \nC++\n[in] uType\nThe sound to be played. The sounds are set by the user through the Sound control panel\napplication, and then stored in the registry.\nThis parameter can be one of the following values.\nValue Meaning\n0xFFFFFFFF A simple beep. If the sound card is not available, the sound is generated\nusing the speaker.\nMB_ICONASTERISK\n0x00000040L\nSee MB_ICONINFORMATION.\nMB_ICONEXCLAMATION\n0x00000030L\nSee MB_ICONWARNING.\nMB_ICONERROR The sound specified as the Windows Critical Stop sound.\nNote On Windows Server 2022, the\nMicrosoft\\Windows\\Multimedia\\SystemSoundsService task in Task Scheduler is disabled.\nThis task will need to be enabled for MessageBeep to function.\nSyntax\nBOOL MessageBeep(\n [in] UINT uType\n);\nParameters\nﾉ Expand table\n0x00000010L\nMB_ICONHAND\n0x00000010L\nSee MB_ICONERROR.\nMB_ICONINFORMATION\n0x00000040L\nThe sound specified as the Windows Asterisk sound.\nMB_ICONQUESTION\n0x00000020L\nThe sound specified as the Windows Question sound.\nMB_ICONSTOP\n0x00000010L\nSee MB_ICONERROR.\nMB_ICONWARNING\n0x00000030L\nThe sound specified as the Windows Exclamation sound.\nMB_OK\n0x00000000L\nThe sound specified as the Windows Default Beep sound.\nIf the function succeeds, the return value is nonzero.\nIf the function fails, the return value is zero. To get extended error information, call\nGetLastError.\nAfter queuing the sound, the MessageBeep function returns control to the calling function and\nplays the sound asynchronously.\nIf it cannot play the specified alert sound, MessageBeep attempts to play the system default\nsound. If it cannot play the system default sound, the function produces a standard beep\nsound using the Beep function. Starting in Windows 7, this plays a simple tone on the default\nsound device. See the documentation for the Beep function for further details.\nThe user can disable the warning beep by using the Sound control panel application.\nNote To send a beep to a remote client, use the Beep function. The Beep function is redirected\nto the client, whereas MessageBeep is not.\nReturn value\nRemarks\nRequirements\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader winuser.h (include Windows.h)\nLibrary User32.lib\nDLL User32.dll\nAPI set ext-ms-win-ntuser-misc-l1-1-0 (introduced in Windows 8)\nBeep\nError Handling Functions\nFlashWindow\nNotifying the User\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3171,"title":"RtlLookupFunctionEntry function (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["rtllookupfunctionentry","function","winnt","searches","the","active","tables","for","entry","that","corresponds","specified","value","2024","controlpc","virtual","address","instruction","bundle","within","out","imagebase","base","module","which","belongs","historytable","global","pointer","this","parameter","has","different","declaration","x64","and","arm","systems","more","information"],"errorCode":"","eventId":"","severity":"Low","summary":"Searches the active function tables for an entry that corresponds to the specified PC value.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to RtlLookupFunctionEntry function (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"RtlLookupFunctionEntry function (winnt.h)\n02/22/2024\nSearches the active function tables for an entry that corresponds to the specified PC value.\nC++\n[in] ControlPc\nThe virtual address of an instruction bundle within the function.\n[out] ImageBase\nThe base address of module to which the function belongs.\n[out] HistoryTable\nThe global pointer value of the module.\nThis parameter has a different declaration on x64 and ARM systems. For more information, see\nx64 Definition and ARM Definition.\nIf there is no entry in the function table for the specified PC, the function returns NULL.\nOtherwise, the function returns the address of the function table entry that corresponds to the\nspecified PC.\nSyntax\nNTSYSAPI PRUNTIME_FUNCTION RtlLookupFunctionEntry(\n [in] DWORD64 ControlPc,\n [out] PDWORD64 ImageBase,\n [out] PUNWIND_HISTORY_TABLE HistoryTable\n);\nParameters\nReturn value\nRequirements\nRequirement Value\nTarget Platform Windows\nHeader winnt.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nRtlUnwindEx\nRtlVirtualUnwind\nVertdll APIs available in VBS enclaves\nﾉ Expand table\nSee also\nRtlSetImageMitigationPolicy\nSets the specified mitigation policy for the specified image.\nC++\nThe name of the image on which mitigation policy is set. If ImagePathName is NULL, the\nsystem mitigation policy is being set.\nThe mitigation policy that is to be set. This parameter supports the following enumeration\nvalues:\nField name Value Description\nImageUserShadowStackPolicy 15 The policy regarding user-mode, hardware-enforced, stack\nprotection for the process. The SetProcessMitigationPolicy\nfunction sets the policy flags for user-mode, hardware-enforced,\nstack protection when a\nPROCESS_MITIGATION_USER_SHADOW_STACK_POLICY structure\nis provided.\nFlags that control the behavior of the set operation. Supported flags for this parameter include:\nNTSYSAPI NTSTATUS NTAPI RtlSetImageMitigationPolicy(\n _In_opt_ PCWSTR ImagePathName,\n _In_ IMAGE_MITIGATION_POLICY MitigationPolicy,\n _In_ ULONG Flags,\n _In_reads_bytes_opt_(BufferSize) PVOID Buffer,\n _In_ ULONG BufferSize\n )\nParameters\nImagePathName\nMitigationPolicy\nﾉ Expand table\nFlags\nﾉ Expand table\nFlag Value Description\nMITIGATION_POLICY_FLAG_RESET_VALUE 0x0 Resets the policy value to the default for the\nsystem\nMITIGATION_POLICY_FLAG_USE_AUDIT_POLICY0x8 Used to get/set the audit policy for the given\nmitigation\nA pointer to the buffer that holds the policy data.\nThe length in bytes of the buffer provided in Buffer.\nReturns an NTSTATUS success or error code.\nThis API is not defined in a Windows SDK header file and must be manually declared. The API is\nexported from ntdll.dll.\nRequirement Value\nMinimum supported client Windows 10, version 1709\nDLL Ntdll.dll\nLast updated on 07/14/2025\nBuffer\nBufferSize\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3172,"title":"RtlNtStatusToDosError function (winternl.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["rtlntstatustodoserror","function","winternl","converts","the","specified","ntstatus","code","its","equivalent","system","error","article11","2024","status","converted","returns","corresponding","there","that","provides","inverse","functionality","which","would","convert","mid","not","found","returned","when","does","have","requirement","value","minimum","supported","client","windows","desktop"],"errorCode":"","eventId":"","severity":"Low","summary":"Converts the specified NTSTATUS code to its equivalent system error code.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to RtlNtStatusToDosError function (winternl.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"RtlNtStatusToDosError function (winternl.h)\nArticle11/20/2024\nConverts the specified NTSTATUS code to its equivalent system error code.\nC++\n[in] Status\nThe NTSTATUS code to be converted.\nThe function returns the corresponding system error code.\nThere is no function that provides the inverse functionality of RtlNtStatusToDosError, which\nwould convert a system error code to its corresponding NTSTATUS code.\nERROR_MR_MID_NOT_FOUND is returned when the specified NTSTATUS code does not have a\ncorresponding system error code.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nSyntax\nULONG RtlNtStatusToDosError(\n [in] NTSTATUS Status\n);\nParameters\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nRequirement Value\nTarget Platform Windows\nHeader winternl.h\nLibrary ntdll.lib\nDLL ntdll.dll\nError Handling Functions\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3173,"title":"RtlPcToFileHeader function (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["rtlpctofileheader","function","winnt","retrieves","the","base","address","image","that","contains","specified","value","2024","pcvalue","searches","all","modules","mapped","into","space","calling","process","for","module","this","out","baseofimage","containing","must","added","any","relative","addresses","headers","locate","found","returns","null","requirement","target"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the base address of the image that contains the specified PC value.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to RtlPcToFileHeader function (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"RtlPcToFileHeader function (winnt.h)\n02/22/2024\nRetrieves the base address of the image that contains the specified PC value.\nC++\n[in] PcValue\nThe PC value. The function searches all modules mapped into the address space of the calling\nprocess for a module that contains this value.\n[out] BaseOfImage\nThe base address of the image containing the PC value. This value must be added to any\nrelative addresses in the headers to locate the image.\nIf the PC value is found, the function returns the base address of the image that contains the\nPC value.\nIf no image contains the PC value, the function returns NULL.\nRequirement Value\nTarget Platform Windows\nSyntax\nNTSYSAPI PVOID RtlPcToFileHeader(\n [in] PVOID PcValue,\n [out] PVOID *BaseOfImage\n);\nParameters\nReturn value\nRequirements\nﾉ Expand table\nRequirement Value\nHeader winnt.h\nLibrary Kernel32.lib\nDLL Kernel32.dll\nRtlLookupFunctionEntry\nVertdll APIs available in VBS enclaves\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3174,"title":"RtlUnwind function (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["rtlunwind","function","winnt","initiates","unwind","procedure","call","frames","2024","optional","targetframe","pointer","the","frame","that","target","this","parameter","null","performs","exit","targetip","continuation","address","ignored","exceptionrecord","exception","record","structure","returnvalue","value","placed","integer","return","register","before","continuing","execution","does","not"],"errorCode":"","eventId":"","severity":"Low","summary":"Initiates an unwind of procedure call frames.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to RtlUnwind function (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"RtlUnwind function (winnt.h)\n02/22/2024\nInitiates an unwind of procedure call frames.\nC++\n[in, optional] TargetFrame\nA pointer to the call frame that is the target of the unwind. If this parameter is NULL, the\nfunction performs an exit unwind.\n[in, optional] TargetIp\nThe continuation address of the unwind. This parameter is ignored if TargetFrame is NULL.\n[in, optional] ExceptionRecord\nA pointer to an EXCEPTION_RECORD structure.\n[in] ReturnValue\nA value to be placed in the integer function return register before continuing execution.\nThis function does not return a value.\nSyntax\nNTSYSAPI VOID RtlUnwind(\n [in, optional] PVOID TargetFrame,\n [in, optional] PVOID TargetIp,\n [in, optional] PEXCEPTION_RECORD ExceptionRecord,\n [in] PVOID ReturnValue\n);\nParameters\nReturn value\nRequirements\nRequirement Value\nMinimum supported client Windows XP [desktop apps | UWP apps]\nMinimum supported server Windows Server 2003 [desktop apps | UWP apps]\nTarget Platform Windows\nHeader winnt.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nEXCEPTION_RECORD\nVertdll APIs available in VBS enclaves\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3175,"title":"RtlUnwind2 function (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["rtlunwind2","function","winnt","initiates","unwind","procedure","call","frames","article02","2024","optional","targetframe","pointer","the","frame","that","target","this","parameter","null","performs","exit","targetip","continuation","address","ignored","exceptionrecord","exception","record","structure","returnvalue","value","placed","integer","return","register","before","continuing","execution","contextrecord"],"errorCode":"","eventId":"","severity":"Low","summary":"Initiates an unwind of procedure call frames.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to RtlUnwind2 function (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"RtlUnwind2 function (winnt.h)\nArticle02/22/2024\nInitiates an unwind of procedure call frames.\nC++\n[in, optional] TargetFrame\nA pointer to the call frame that is the target of the unwind. If this parameter is NULL, the\nfunction performs an exit unwind.\n[in, optional] TargetIp\nThe continuation address of the unwind. This parameter is ignored if TargetFrame is NULL.\n[in, optional] ExceptionRecord\nA pointer to an EXCEPTION_RECORD structure.\n[in] ReturnValue\nA value to be placed in the integer function return register before continuing execution.\n[in] ContextRecord\nA pointer to a CONTEXT structure that stores context during the unwind operation.\nThis function does not return a value.\nSyntax\nNTSYSAPI VOID RtlUnwind2(\n [in, optional] FRAME_POINTERS TargetFrame,\n [in, optional] PVOID TargetIp,\n [in, optional] PEXCEPTION_RECORD ExceptionRecord,\n [in] PVOID ReturnValue,\n [in] PCONTEXT ContextRecord\n);\nParameters\nReturn value\nThe FRAME_POINTERS structure is defined as follows:\nC++\nRequirement Value\nTarget Platform Windows\nHeader winnt.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nCONTEXT\nEXCEPTION_RECORD\nRemarks\ntypedef struct _FRAME_POINTERS {\n ULONGLONG MemoryStackFp;\n ULONGLONG BackingStoreFp;\n} FRAME_POINTERS, *PFRAME_POINTERS;\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3176,"title":"RtlUnwindEx function (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["rtlunwindex","function","winnt","initiates","unwind","procedure","call","frames","2024","optional","targetframe","pointer","the","frame","that","target","this","parameter","null","performs","exit","targetip","continuation","address","ignored","exceptionrecord","exception","record","structure","returnvalue","value","placed","integer","return","register","before","continuing","execution","contextrecord","context"],"errorCode":"","eventId":"","severity":"Low","summary":"Initiates an unwind of procedure call frames.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to RtlUnwindEx function (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"RtlUnwindEx function (winnt.h)\n02/22/2024\nInitiates an unwind of procedure call frames.\nC++\n[in, optional] TargetFrame\nA pointer to the call frame that is the target of the unwind. If this parameter is NULL, the\nfunction performs an exit unwind.\n[in, optional] TargetIp\nThe continuation address of the unwind. This parameter is ignored if TargetFrame is NULL.\n[in, optional] ExceptionRecord\nA pointer to an EXCEPTION_RECORD structure.\n[in] ReturnValue\nA value to be placed in the integer function return register before continuing execution.\n[in] ContextRecord\nA pointer to a CONTEXT structure that stores context during the unwind operation.\n[in, optional] HistoryTable\nSyntax\nNTSYSAPI VOID RtlUnwindEx(\n [in, optional] PVOID TargetFrame,\n [in, optional] PVOID TargetIp,\n [in, optional] PEXCEPTION_RECORD ExceptionRecord,\n [in] PVOID ReturnValue,\n [in] PCONTEXT ContextRecord,\n [in, optional] PUNWIND_HISTORY_TABLE HistoryTable\n);\nParameters\nA pointer to the unwind history table. This structure is processor specific. For definitions of this\nstructure, see Winternl.h.\nThis function does not return a value.\nThe FRAME_POINTERS structure is defined as follows:\nC++\nRequirement Value\nTarget Platform Windows\nHeader winnt.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nCONTEXT\nEXCEPTION_RECORD\nVertdll APIs available in VBS enclaves\nReturn value\nRemarks\ntypedef struct _FRAME_POINTERS {\n ULONGLONG MemoryStackFp;\n ULONGLONG BackingStoreFp;\n} FRAME_POINTERS, *PFRAME_POINTERS;\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3177,"title":"RtlVirtualUnwind function (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["rtlvirtualunwind","function","winnt","retrieves","the","invocation","context","that","precedes","specified","2024","handlertype","handler","type","this","parameter","can","one","following","values","only","present","x64","value","meaning","unw","flag","nhandler","0x0","has","ehandler","0x1","exception","should","called","note","not","implemented","all","processor"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the invocation context of the function that precedes the specified function context.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to RtlVirtualUnwind function (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"RtlVirtualUnwind function (winnt.h)\n02/22/2024\nRetrieves the invocation context of the function that precedes the specified function context.\nC++\n[in] HandlerType\nThe handler type. This parameter can be one of the following values.\nThis parameter is only present on x64.\nValue Meaning\nUNW_FLAG_NHANDLER\n0x0\nThe function has no handler.\nUNW_FLAG_EHANDLER\n0x1\nThe function has an exception handler that should be called.\n７ Note\n This function is not implemented on all processor platforms and the implementation is\ndifferent on each platform that supports it. The following prototype lists all the potential\nparameters and their application. Read further for processor-specific function prototypes.\nSyntax\nNTSYSAPI PEXCEPTION_ROUTINE RtlVirtualUnwind(\n [in] DWORD HandlerType,\n [in] DWORD64 ImageBase,\n [in] DWORD64 ControlPc,\n [in] PRUNTIME_FUNCTION FunctionEntry,\n [in, out] PCONTEXT ContextRecord,\n [out] PVOID *HandlerData,\n [out] PDWORD64 EstablisherFrame,\n [in, out, optional] PKNONVOLATILE_CONTEXT_POINTERS ContextPointers\n);\nParameters\nﾉ Expand table\nUNW_FLAG_UHANDLER\n0x2\nThe function has a termination handler that should be called\nwhen unwinding an exception.\nUNW_FLAG_CHAININFO\n0x4\nThe FunctionEntry member is the contents of a previous\nfunction table entry.\n[in] ImageBase\nThe base address of the module to which the function belongs.\n[in] ControlPc\nThe virtual address where control left the specified function.\n[in] FunctionEntry\nThe address of the function table entry for the specified function. To obtain the function table\nentry, call the RtlLookupFunctionEntry function.\n[in, out] ContextRecord\nA pointer to a CONTEXT structure that represents the context of the previous frame.\n[out] HandlerData\nThe location of the PC. If this parameter is 0, the PC is in the prologue, epilogue, or a null frame\nregion of the function. If this parameter is 1, the PC is in the body of the function.\nThis parameter is not present on x64.\n[out] EstablisherFrame\nA pointer to a FRAME_POINTERS structure that receives the establisher frame pointer value.\nThe real frame pointer is defined only if InFunction is 1.\nThis parameter is of type PULONG64 on x64.\n[in, out, optional] ContextPointers\nAn optional pointer to a context pointers structure.\nThis function returns a pointer to an EXCEPTION_ROUTINE callback function.\nReturn value\nThe complete list of epilogue markers for x64 is as follows:\nret\nret n\nrep ret\njmp imm8 | imm32 where the target is outside the function being unwound\njmp qword ptr imm32\nrex.w jmp reg\nRequirement Value\nTarget Platform Windows\nHeader winnt.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nCONTEXT\nEXCEPTION_RECORD\nRtlLookupFunctionEntry\nVertdll APIs available in VBS enclaves\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3178,"title":"SetErrorMode function (errhandlingapi.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["seterrormode","function","errhandlingapi","controls","whether","the","system","process","handles","specified","serious","error","types","article06","2024","umode","mode","this","parameter","can","one","more","following","values","value","meaning","use","default","which","displays","all","dialog","boxes","sem","failcriticalerrors","0x0001","does","not","display","critical"],"errorCode":"","eventId":"","severity":"Low","summary":"Controls whether the system or the process handles the specified serious error types.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SetErrorMode function (errhandlingapi.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SetErrorMode function (errhandlingapi.h)\nArticle06/26/2024\nControls whether the system or the process handles the specified serious error types.\nC++\n[in] uMode\nThe process error mode. This parameter can be one or more of the following values.\nValue Meaning\n0 Use the system default, which displays all error dialog boxes.\nSEM_FAILCRITICALERRORS\n0x0001\nThe system does not display the critical-error-handler\nmessage box. Instead, the system sends the error to the\ncalling process.\nBest practice is that all applications call the process-wide\nSetErrorMode function with a parameter of\nSEM_FAILCRITICALERRORS at startup. This is to prevent error\nmode dialogs from hanging the application.\nSEM_NOALIGNMENTFAULTEXCEPT\n0x0004\nThe system automatically fixes memory alignment faults and\nmakes them invisible to the application. It does this for the\ncalling process and any descendant processes. This feature is\nonly supported by certain processor architectures. For more\ninformation, see the Remarks section.\nAfter this value is set for a process, subsequent attempts to\nclear the value are ignored.\nSEM_NOGPFAULTERRORBOX\n0x0002\nThe system does not invoke Windows Error Reporting. To\ndisable Windows Error Reporting UI, call WerSetFlags with the\nWER_FAULT_REPORTING_NO_UI flag.\nSyntax\nUINT SetErrorMode(\n [in] UINT uMode\n);\nParameters\nﾉ Expand table\nSEM_NOOPENFILEERRORBOX\n0x8000\nThe OpenFile function does not display a message box when it\nfails to find a file. Instead, the error is returned to the caller.\nThis error mode overrides the OF_PROMPT flag.\nThe return value is the previous state of the error-mode bit flags.\nEach process has an associated error mode that indicates to the system how the application is\ngoing to respond to serious errors. A child process inherits the error mode of its parent\nprocess. To retrieve the process error mode, use the GetErrorMode function.\nBecause the error mode is set for the entire process, you must ensure that multi-threaded\napplications do not set different error-mode flags. Doing so can lead to inconsistent error\nhandling.\nThe system does not make alignment faults visible to an application on all processor\narchitectures. Therefore, specifying SEM_NOALIGNMENTFAULTEXCEPT is not an error on such\narchitectures, but the system is free to silently ignore the request. This means that code\nsequences such as the following are not always valid on x86 computers:\nC++\nSetErrorMode(SEM_NOALIGNMENTFAULTEXCEPT); \nfuOldErrorMode = SetErrorMode(0); \nASSERT(fuOldErrorMode == SEM_NOALIGNMENTFAULTEXCEPT);\nItanium: An application must explicitly call SetErrorMode with\nSEM_NOALIGNMENTFAULTEXCEPT to have the system automatically fix alignment faults. The\ndefault setting is for the system to make alignment faults visible to an application.\nVisual Studio 2005: When declaring a pointer to a structure that may not have aligned data,\nyou can use the __unaligned keyword to indicate that the type must be read one byte at a\ntime. For more information, see Windows Data Alignment.\nWindows 7: Callers should favor SetThreadErrorMode over SetErrorMode since it is less\ndisruptive to the normal behavior of the system.\nReturn value\nRemarks\nﾉ Expand table\nRequirement Value\nMinimum supported client Windows XP [desktop apps | UWP apps]\nMinimum supported server Windows Server 2003 [desktop apps | UWP apps]\nTarget Platform Windows\nHeader errhandlingapi.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nError Handling Functions\nError Mode\nGetErrorMode\nSetThreadErrorMode\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3179,"title":"SetLastError function (errhandlingapi.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["setlasterror","function","errhandlingapi","sets","the","last","error","code","for","calling","thread","2024","dwerrcode","none","kept","local","storage","that","multiple","threads","not","overwrite","each","other","values","most","functions","call","setlasterrorex","only","when","they","fail","however","some","system","under","conditions","success","those"],"errorCode":"","eventId":"","severity":"Low","summary":"Sets the last-error code for the calling thread.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SetLastError function (errhandlingapi.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SetLastError function (errhandlingapi.h)\n02/22/2024\nSets the last-error code for the calling thread.\nC++\n[in] dwErrCode\nThe last-error code for the thread.\nNone\nThe last-error code is kept in thread local storage so that multiple threads do not overwrite\neach other's values.\nMost functions call SetLastError or SetLastErrorEx only when they fail. However, some system\nfunctions call SetLastError or SetLastErrorEx under conditions of success; those cases are\nnoted in each function's documentation.\nApplications can optionally retrieve the value set by this function by using the GetLastError\nfunction immediately after a function fails.\nError codes are 32-bit values (bit 31 is the most significant bit). Bit 29 is reserved for\napplication-defined error codes; no system error code has this bit set. If you are defining an\nerror code for your application, set this bit to indicate that the error code has been defined by\nyour application and to ensure that your error code does not conflict with any system-defined\nerror codes.\nSyntax\nVOID SetLastError(\n [in] DWORD dwErrCode\n);\nParameters\nReturn value\nRemarks\nRequirement Value\nMinimum supported client Windows XP [desktop apps | UWP apps]\nMinimum supported server Windows Server 2003 [desktop apps | UWP apps]\nTarget Platform Windows\nHeader errhandlingapi.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nError Handling Functions\nGetLastError\nLast-Error Code\nSetLastErrorEx\nVertdll APIs available in VBS enclaves\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3180,"title":"SetLastErrorEx function (winuser.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["setlasterrorex","function","winuser","currently","this","identical","the","setlasterror","2021","sets","last","error","code","second","parameter","ignored","dwerrcode","for","thread","dwtype","none","kept","local","storage","that","multiple","threads","not","overwrite","each","other","values","most","functions","call","only","when","they","fail","however"],"errorCode":"","eventId":"","severity":"Low","summary":"Currently, this function is identical to the SetLastError function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SetLastErrorEx function (winuser.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SetLastErrorEx function (winuser.h)\n10/13/2021\nSets the last-error code.\nCurrently, this function is identical to the SetLastError function. The second parameter is\nignored.\nC++\n[in] dwErrCode\nThe last-error code for the thread.\n[in] dwType\nThis parameter is ignored.\nNone\nThe last-error code is kept in thread local storage so that multiple threads do not overwrite\neach other's values.\nMost functions call SetLastError or SetLastErrorEx only when they fail. However, some system\nfunctions call SetLastError or SetLastErrorEx under conditions of success; those cases are\nnoted in each function's documentation.\nSyntax\nVOID SetLastErrorEx(\n [in] DWORD dwErrCode,\n [in] DWORD dwType\n);\nParameters\nReturn value\nRemarks\nApplications can optionally retrieve the value set by this function by using the GetLastError\nfunction immediately after a function fails.\nError codes are 32-bit values (bit 31 is the most significant bit). Bit 29 is reserved for\napplication-defined error codes; no system error code has this bit set. If you are defining an\nerror code for your application, set this bit to indicate that the error code has been defined by\nthe application and to ensure that your error code does not conflict with any system-defined\nerror codes.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader winuser.h (include Windows.h)\nLibrary User32.lib\nDLL User32.dll\nError Handling Functions\nGetLastError\nLast-Error Code\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3181,"title":"SetThreadErrorMode function (errhandlingapi.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["setthreaderrormode","function","errhandlingapi","controls","whether","the","system","will","handle","specified","types","serious","errors","calling","thread","them","article10","2021","dwnewmode","error","mode","this","parameter","can","one","more","following","values","value","meaning","use","default","which","display","all","dialog","boxes","sem","failcriticalerrors","0x0001"],"errorCode":"","eventId":"","severity":"Low","summary":"Controls whether the system will handle the specified types of serious errors or whether the\ncalling thread will handle them.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SetThreadErrorMode function (errhandlingapi.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SetThreadErrorMode function\n(errhandlingapi.h)\nArticle10/13/2021\nControls whether the system will handle the specified types of serious errors or whether the\ncalling thread will handle them.\nC++\n[in] dwNewMode\nThe thread error mode. This parameter can be one or more of the following values.\nValue Meaning\n0 Use the system default, which is to display all error dialog\nboxes.\nSEM_FAILCRITICALERRORS\n0x0001\nThe system does not display the critical-error-handler\nmessage box. Instead, the system sends the error to the\ncalling thread.\nBest practice is that all applications call the process-wide\nSetErrorMode function with a parameter of\nSEM_FAILCRITICALERRORS at startup. This is to prevent error\nmode dialogs from hanging the application.\nSEM_NOGPFAULTERRORBOX\n0x0002\nThe system does not display the Windows Error Reporting\ndialog.\nSEM_NOOPENFILEERRORBOX\n0x8000\nThe OpenFile function does not display a message box when it\nfails to find a file. Instead, the error is returned to the caller.\nThis error mode overrides the OF_PROMPT flag.\nSyntax\nBOOL SetThreadErrorMode(\n [in] DWORD dwNewMode,\n [out] LPDWORD lpOldMode\n);\nParameters\nﾉ Expand table\n[out] lpOldMode\nIf the function succeeds, this parameter is set to the thread's previous error mode. This\nparameter can be NULL.\nIf the function succeeds, the return value is nonzero.\nIf the function fails, the return value is zero. To get extended error information, call\nGetLastError.\nEach process has an associated error mode that indicates to the system how the application is\ngoing to respond to serious errors. A thread inherits the error mode of the process in which it\nis running. To retrieve the process error mode, use the GetErrorMode function. To retrieve the\nerror mode of the calling thread, use the GetThreadErrorMode function.\nRequirement Value\nMinimum supported client Windows 7 [desktop apps | UWP apps]\nMinimum supported server Windows Server 2008 R2 [desktop apps | UWP apps]\nTarget Platform Windows\nHeader errhandlingapi.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nGetThreadErrorMode\nSetErrorMode\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nSee also\nError Handling Macros\nThe following macro is used with error handling:\nC_ASSERT\n \n \nLast updated on 07/14/2025","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3182,"title":"C_ASSERT macro (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["assert","macro","winnt","checks","assertions","compile","time","2024","expression","that","can","determined","none","the","defined","follows","following","examples","demonstrate","common","types","syntax","void","parameters","return","value","remarks","define","typedef","char","buffer","cch","size","max","path","arraysize","array1","array2","field","offset"],"errorCode":"","eventId":"","severity":"Low","summary":"Checks assertions at compile time.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to C_ASSERT macro (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"C_ASSERT macro (winnt.h)\n02/22/2024\nChecks assertions at compile time.\nC++\ne\nAn expression that can be determined at compile time.\nNone\nThe C_ASSERT macro is defined as follows.\nC++\nThe following examples demonstrate common types of compile-time assertions.\nC++\nSyntax\nvoid C_ASSERT(\n e\n);\nParameters\nReturn value\nRemarks\n#define C_ASSERT(e) typedef char __C_ASSERT__[(e)?1:-1]\nC_ASSERT (BUFFER_CCH_SIZE <= MAX_PATH);\nC_ASSERT (ARRAYSIZE(array1) == ARRAYSIZE(array2));\nC_ASSERT (FIELD_OFFSET(STRUCT_DEF, MemberName) == 0x1d4);\nRequirement Value\nTarget Platform Windows\nHeader winnt.h (include Windows.h)\nC_ASSERT (sizeof(BOOLEAN) == sizeof(UCHAR));\nRequirements\nﾉ Expand table\nError Handling Structures\nThe following structure is used with error handling:\nFLASHWINFO\n \n \nLast updated on 07/14/2025","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3183,"title":"FLASHWINFO structure (winuser.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["flashwinfo","structure","winuser","contains","the","flash","status","for","window","and","number","times","system","should","article05","2024","cbsize","size","bytes","hwnd","handle","flashed","can","either","opened","minimized","dwflags","this","parameter","one","more","following","values","value","meaning","flashw","all","0x00000003","both","caption"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains the flash status for a window and the number of times the system should flash the\nwindow.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to FLASHWINFO structure (winuser.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"FLASHWINFO structure (winuser.h)\nArticle05/15/2024\nContains the flash status for a window and the number of times the system should flash the\nwindow.\nC++\ncbSize\nThe size of the structure, in bytes.\nhwnd\nA handle to the window to be flashed. The window can be either opened or minimized.\ndwFlags\nThe flash status. This parameter can be one or more of the following values.\nValue Meaning\nFLASHW_ALL\n0x00000003\nFlash both the window caption and taskbar button. This is\nequivalent to setting the FLASHW_CAPTION | FLASHW_TRAY\nflags.\nFLASHW_CAPTION\n0x00000001\nFlash the window caption.\nFLASHW_STOP\n0\nStop flashing. The system restores the window to its original\nstate.\nSyntax\ntypedef struct {\n UINT cbSize;\n HWND hwnd;\n DWORD dwFlags;\n UINT uCount;\n DWORD dwTimeout;\n} FLASHWINFO, *PFLASHWINFO;\nMembers\nﾉ Expand table\nFLASHW_TIMER\n0x00000004\nFlash continuously, until the FLASHW_STOP flag is set.\nFLASHW_TIMERNOFG\n0x0000000C\nFlash continuously until the window comes to the foreground.\nFLASHW_TRAY\n0x00000002\nFlash the taskbar button.\nuCount\nThe number of times to flash the window.\ndwTimeout\nThe rate at which the window is to be flashed, in milliseconds. If dwTimeout is zero, the\nfunction uses the default caret blink rate.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nHeader winuser.h (include Windows.h)\nFlashWindowEx\nRequirements\nﾉ Expand table\nSee also\nDebug system error codes\nSystem error codes can occur across many locations in the system and require investigation\nand analysis to debug (due to their scope, descriptions for system error codes cannot be very\nspecific), starting with the programmatic and runtime context in which the errors occurred.\nSystem error codes are defined in WinError.h and can be returned by non-system software or\nby a function deep in the stack and far removed from code that is handling the error.\nWe've listed the system error codes in this section, organized by number. If you need more\nhelp tracking down a specific error, here are some more recommendations:\nUse the Microsoft Error Lookup Tool.\nInstall the Debugging Tools for Windows, load a memory dump file, and then run the !err\n<code> command.\nSearch the Microsoft Protocols site for the raw text or error code. For more information,\nsee [MS-ERREF]: Windows Error Codes.\nIf you're searching for other errors, here are some links that might help:\nWindows Update errors - For help resolving issues with Windows Update.\nWindows activation errors - For help verifying your copy of Windows.\nTroubleshooting blue screen errors - For help discovering what caused a stop error.\nMicrosoft Support - For support with a Microsoft product.\nOther error codes may be generated by third party services or apps (for example, Error Code:\n-118 may be displayed by the Steam game service), in which case you need to contact the\nthird party.\nThe following topics provide lists of system error codes defined in the WinError.h header file.\nSystem Error Codes (0-499) (0x0-0x1f3)\nSystem Error Codes (500-999) (0x1f4-0x3e7)\nSystem Error Codes (1000-1299) (0x3e8-0x513)\nSystem Error Codes (1300-1699) (0x514-0x6a3)\nMore ways to find an error code\nThird party error codes\nSystem error codes\nSystem Error Codes (1700-3999) (0x6a4-0xf9f)\nSystem Error Codes (4000-5999) (0xfa0-0x176f)\nSystem Error Codes (6000-8199) (0x1770-0x2007)\nSystem Error Codes (8200-8999) (0x2008-0x2327)\nSystem Error Codes (9000-11999) (0x2328-0x2edf)\nSystem Error Codes (12000-15999) (0x2ee0-0x3e7f)\nLast updated on 07/14/2025\nThe Microsoft Error Lookup Tool\nThe Microsoft Error Lookup Tool displays the message text that is associated with a\nhexadecimal status code (or other code). This text is defined in various Microsoft source-code\nheader files, such as Winerror.h, Setupapi.h, and so on.\nThe tool is digitally signed by Microsoft. The following is the SHA256 information for the file\ndownload:\nAlgorithm Hash\nSHA256 88739EC82BA16A0B4A3C83C1DD2FCA6336AD8E2A1E5F1238C085B1E86AB8834A\n1. Download the tool by selecting this link.\n2. If you didn't specify a location in step 1, go to your download folder, and copy or move\nthe downloaded file (Err_6.4.5.exe) to folder in which you will store the tool. You do not\nhave to expand or install the file.\nﾉ Expand table\n７ Note\nBusiness environments may restrict which files can run and from where. Before you\ndownload and run this tool, check the following details:\nDo you have to have permission or a security exception in order to download or run\nthe tool?\nCan you store and run this tool on your computer (for example, in your Documents\nfolder)? Or do you have to store and run the tool on a specialized computer, such as\na central file server?\nUsage\n７ Note\nIf you copy or move the file to a folder that is listed in your operating system's Path\nenvironment variable, it will work at any command prompt.\n3. Open a Command Prompt window. If necessary, change the directory to the location of\nthe Error Lookup Tool.\n4. Run the following command:\nWindows Command Prompt\nWindows Command Prompt\nWindows Command Prompt\nErr_6.4.5.exe <error code>\n７ Note\nIn this command, <error code> represents the hexadecimal code that you want to\nlook up.\nExamples\nC:\\Tools>Err_6.4.5.exe c000021a\n# for hex 0xc000021a / decimal -1073741286\n STATUS_SYSTEM_PROCESS_TERMINATED ntstatus.h \n# {Fatal System Error} \n# The %hs system process terminated unexpectedly with a \n# status of 0x%08x (0x%08x 0x%08x). \n# The system has been shut down. \n# as an HRESULT: Severity: FAILURE (1), FACILITY_NULL (0x0), Code 0x21a \n# for hex 0x21a / decimal 538 \n ERROR_ABIOS_ERROR winerror.h \n# An error occurred in the ABIOS subsystem. \n# 2 matches found for \"c000021a\"\nC:\\Tools>Err_6.4.5.exe 7b\n# for hex 0x7b / decimal 123\n INACCESSIBLE_BOOT_DEVICE bugcodes.h \n NMERR_SECURITY_BREACH_CAPTURE_DELETED netmon.h \n ERROR_INVALID_NAME winerror.h \n# The filename, directory name, or volume label syntax is \n# incorrect. \n# as an HRESULT: Severity: SUCCESS (0)","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3184,"title":"OutputDebugStringW function (debugapi.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["outputdebugstringw","function","debugapi","sends","string","the","debugger","for","display","2024","optional","lpoutputstring","null","terminated","displayed","none","past","operating","system","did","not","return","unicode","strings","through","ascii","were","returned","instead","force","debuggers","are","required","call","waitfordebugeventex","opt","into","new","behavior","this"],"errorCode":"","eventId":"","severity":"Low","summary":"Sends a string to the debugger for display.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to OutputDebugStringW function (debugapi.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"OutputDebugStringW function\n(debugapi.h)\n02/22/2024\nSends a string to the debugger for display.\nC++\n[in, optional] lpOutputString\nThe null-terminated string to be displayed.\nNone\nIn the past, the operating system did not return Unicode strings through\nOutputDebugStringW (ASCII strings were returned instead). To force OutputDebugStringW to\nreturn Unicode strings, debuggers are required to call the WaitForDebugEventEx function to\nopt into the new behavior. In this way, the operating system knows that the debugger supports\nUnicode and is specifically opting into receiving Unicode strings.\nSyntax\nVOID OutputDebugStringW(\n [in, optional] LPCWSTR lpOutputString\n);\nParameters\nReturn value\nRemarks\n） Important\nTo use this function, you must include the Windows.h header in your application (not\ndebugapi.h).\nIf the application does not have a debugger, and the filter mask allows it, the system debugger\ndisplays the string. To display the string, this function calls the DbgPrint function. Prior to\nWindows Vista, content was not filtered by the system debugger.\nIf the application does not have a debugger and the system debugger is not active,\nOutputDebugString does nothing.\nOutputDebugStringW converts the specified string based on the current system locale\ninformation and passes it to OutputDebugStringA to be displayed. As a result, some Unicode\ncharacters may not be displayed correctly.\nApplications should send very minimal debug output and provide a way for the user to enable\nor disable its use. See Event Tracing to learn more about tracing details.\nVisual Studio has changed how it handles the display of these strings throughout its revision\nhistory. Refer to the Visual Studio documentation for details of how your version deals with\nthis.\nThe debugapi.h header defines OutputDebugString as an alias that automatically selects the\nANSI or Unicode version of this function based on the definition of the UNICODE preprocessor\nconstant. Mixing usage of the encoding-neutral alias with code that is not encoding-neutral\ncan lead to mismatches and compilation or runtime errors. For more information, see\nConventions for Function Prototypes.\nRequirement Value\nMinimum supported client Windows XP [desktop apps | UWP apps]\nMinimum supported server Windows Server 2003 [desktop apps | UWP apps]\nTarget Platform Windows\nHeader debugapi.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nRequirements\nﾉ Expand table\nSee also\nCommunicating with the Debugger\nDebugging Functions\nVertdll APIs available in VBS enclaves","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3185,"title":"ARM64_NT_CONTEXT structure (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["arm64","context","structure","winnt","contains","processor","specific","register","data","article03","2025","the","system","uses","structures","perform","various","internal","operations","definition","varies","for","different","architectures","this","page","applies","architecture","following","table","links","other","api","reference","x86","bit","arm32","expand","syntax","typedef"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains processor-specific register data.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to ARM64_NT_CONTEXT structure (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"ARM64_NT_CONTEXT structure\n(winnt.h)\nArticle03/28/2025\nContains processor-specific register data. The system uses CONTEXT structures to\nperform various internal operations. The structure definition varies for different\nprocessor architectures. This page applies to the Arm64 architecture. The following table\nlinks to the structures for other architectures.\nArchitecture API reference page\nx86 64-bit CONTEXT structure (x86 64-bit)\nx86 32-bit CONTEXT structure (x86 32-bit)\nArm32 CONTEXT structure (Arm32)\nC++\nﾉ Expand table\nSyntax\ntypedef struct _ARM64_NT_CONTEXT {\n DWORD ContextFlags;\n DWORD Cpsr;\n union {\n struct {\n DWORD64 X0;\n DWORD64 X1;\n DWORD64 X2;\n DWORD64 X3;\n DWORD64 X4;\n DWORD64 X5;\n DWORD64 X6;\n DWORD64 X7;\n DWORD64 X8;\n DWORD64 X9;\n DWORD64 X10;\n DWORD64 X11;\n DWORD64 X12;\n DWORD64 X13;\n DWORD64 X14;\n DWORD64 X15;\n DWORD64 X16;\n DWORD64 X17;\nContextFlags\nCpsr\nDUMMYUNIONNAME\nDUMMYUNIONNAME.DUMMYSTRUCTNAME\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X0\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X1\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X2\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X3\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X4\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X5\n DWORD64 X18;\n DWORD64 X19;\n DWORD64 X20;\n DWORD64 X21;\n DWORD64 X22;\n DWORD64 X23;\n DWORD64 X24;\n DWORD64 X25;\n DWORD64 X26;\n DWORD64 X27;\n DWORD64 X28;\n DWORD64 Fp;\n DWORD64 Lr;\n } DUMMYSTRUCTNAME;\n DWORD64 X[31];\n } DUMMYUNIONNAME;\n DWORD64 Sp;\n DWORD64 Pc;\n ARM64_NT_NEON128 V[32];\n DWORD Fpcr;\n DWORD Fpsr;\n DWORD Bcr[ARM64_MAX_BREAKPOINTS];\n DWORD64 Bvr[ARM64_MAX_BREAKPOINTS];\n DWORD Wcr[ARM64_MAX_WATCHPOINTS];\n DWORD64 Wvr[ARM64_MAX_WATCHPOINTS];\n} ARM64_NT_CONTEXT, *PARM64_NT_CONTEXT;\nMembers\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X6\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X7\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X8\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X9\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X10\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X11\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X12\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X13\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X14\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X15\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X16\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X17\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X18\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X19\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X20\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X21\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X22\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X23\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X24\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X25\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X26\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X27\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.X28\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.Fp\nDUMMYUNIONNAME.DUMMYSTRUCTNAME.Lr\nDUMMYUNIONNAME.X[31]\nSp\nPc\nV[32]\nFpcr\nFpsr\nBcr[ARM64_MAX_BREAKPOINTS]\nBvr[ARM64_MAX_BREAKPOINTS]\nWcr[ARM64_MAX_WATCHPOINTS]\nWvr[ARM64_MAX_WATCHPOINTS]\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nHeader winnt.h (include Windows.h)\nDebugging Structures\nGetThreadContext\nGetXStateFeaturesMask\nSetThreadContext\nWOW64_CONTEXT\nRequirements\nﾉ Expand table\nSee also\nFeedback\nWas this page helpful?\nProvide product feedback | Get help at Microsoft Q&A\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3186,"title":"CREATE_PROCESS_DEBUG_INFO structure (minwinbase.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["create","process","debug","info","structure","minwinbase","contains","creation","information","that","can","used","debugger","article04","2021","hfile","handle","the","image","file","this","member","null","not","valid","otherwise","use","read","from","and","write","when","finished","with","should","close","using","closehandle","function","hprocess"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains process creation information that can be used by a debugger.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to CREATE_PROCESS_DEBUG_INFO structure (minwinbase.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"CREATE_PROCESS_DEBUG_INFO structure\n(minwinbase.h)\nArticle04/02/2021\nContains process creation information that can be used by a debugger.\nC++\nhFile\nA handle to the process's image file. If this member is NULL, the handle is not valid. Otherwise,\nthe debugger can use the member to read from and write to the image file.\nWhen the debugger is finished with this file, it should close the handle using the CloseHandle\nfunction.\nhProcess\nA handle to the process. If this member is NULL, the handle is not valid. Otherwise, the\ndebugger can use the member to read from and write to the process's memory.\nhThread\nA handle to the initial thread of the process identified by the hProcess member. If hThread\nparam is NULL, the handle is not valid. Otherwise, the debugger has THREAD_GET_CONTEXT,\nTHREAD_SET_CONTEXT, and THREAD_SUSPEND_RESUME access to the thread, allowing the\nSyntax\ntypedef struct _CREATE_PROCESS_DEBUG_INFO {\n HANDLE hFile;\n HANDLE hProcess;\n HANDLE hThread;\n LPVOID lpBaseOfImage;\n DWORD dwDebugInfoFileOffset;\n DWORD nDebugInfoSize;\n LPVOID lpThreadLocalBase;\n LPTHREAD_START_ROUTINE lpStartAddress;\n LPVOID lpImageName;\n WORD fUnicode;\n} CREATE_PROCESS_DEBUG_INFO, *LPCREATE_PROCESS_DEBUG_INFO;\nMembers\ndebugger to read from and write to the registers of the thread and to control execution of the\nthread.\nlpBaseOfImage\nThe base address of the executable image that the process is running.\ndwDebugInfoFileOffset\nThe offset to the debugging information in the file identified by the hFile member.\nnDebugInfoSize\nThe size of the debugging information in the file, in bytes. If this value is zero, there is no\ndebugging information.\nlpThreadLocalBase\nA pointer to a block of data. At offset 0x2C into this block is another pointer, called\nThreadLocalStoragePointer, that points to an array of per-module thread local storage blocks.\nThis gives a debugger access to per-thread data in the threads of the process being debugged\nusing the same algorithms that a compiler would use.\nlpStartAddress\nA pointer to the starting address of the thread. This value may only be an approximation of the\nthread's starting address, because any application with appropriate access to the thread can\nchange the thread's context by using the SetThreadContext function.\nlpImageName\nA pointer to the file name associated with the hFile member. This parameter may be NULL, or\nit may contain the address of a string pointer in the address space of the process being\ndebugged. That address may, in turn, either be NULL or point to the actual filename. If\nfUnicode is a nonzero value, the name string is Unicode; otherwise, it is ANSI.\nThis member is strictly optional. Debuggers must be prepared to handle the case where\nlpImageName is NULL or *lpImageName (in the address space of the process being\ndebugged) is NULL. Specifically, the system does not provide an image name for a create\nprocess event, and will not likely pass an image name for the first DLL event. The system also\ndoes not provide this information in the case of debug events that originate from a call to the\nDebugActiveProcess function.\nfUnicode\nA value that indicates whether a file name specified by the lpImageName member is Unicode\nor ANSI. A nonzero value indicates Unicode; zero indicates ANSI.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nHeader minwinbase.h (include Windows.h)\nCREATE_THREAD_DEBUG_INFO\nDEBUG_EVENT\nDebugActiveProcess\nLOAD_DLL_DEBUG_INFO\nSetThreadContext\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3187,"title":"CREATE_THREAD_DEBUG_INFO structure (minwinbase.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["create","thread","debug","info","structure","minwinbase","contains","creation","information","that","can","used","debugger","article02","2024","hthread","handle","the","whose","caused","debugging","event","this","member","null","not","valid","otherwise","has","get","context","set","and","suspend","resume","access","allowing","read","from","write"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains thread-creation information that can be used by a debugger.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to CREATE_THREAD_DEBUG_INFO structure (minwinbase.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"CREATE_THREAD_DEBUG_INFO structure\n(minwinbase.h)\nArticle02/22/2024\nContains thread-creation information that can be used by a debugger.\nC++\nhThread\nA handle to the thread whose creation caused the debugging event. If this member is NULL,\nthe handle is not valid. Otherwise, the debugger has THREAD_GET_CONTEXT,\nTHREAD_SET_CONTEXT, and THREAD_SUSPEND_RESUME access to the thread, allowing the\ndebugger to read from and write to the registers of the thread and control execution of the\nthread.\nlpThreadLocalBase\nA pointer to a block of data. At offset 0x2C into this block is another pointer, called\nThreadLocalStoragePointer, that points to an array of per-module thread local storage blocks.\nThis gives a debugger access to per-thread data in the threads of the process being debugged\nusing the same algorithms that a compiler would use.\nlpStartAddress\nA pointer to the starting address of the thread. This value may only be an approximation of the\nthread's starting address, because any application with appropriate access to the thread can\nchange the thread's context by using the SetThreadContext function.\nSyntax\ntypedef struct _CREATE_THREAD_DEBUG_INFO {\n HANDLE hThread;\n LPVOID lpThreadLocalBase;\n LPTHREAD_START_ROUTINE lpStartAddress;\n} CREATE_THREAD_DEBUG_INFO, *LPCREATE_THREAD_DEBUG_INFO;\nMembers\nRequirements\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nHeader minwinbase.h (include Windows.h)\nCREATE_PROCESS_DEBUG_INFO\nDEBUG_EVENT\nDebugging Structures\nLOAD_DLL_DEBUG_INFO\nSetThreadContext\nﾉ Expand table\nSee also\nDEBUG_EVENT structure (minwinbase.h)\nDescribes a debugging event.\nC++\ndwDebugEventCode\nType: DWORD\nThe code that identifies the type of debugging event. This member can be one of the following\nvalues.\nValue Meaning\nCREATE_PROCESS_DEBUG_EVENT\n3\nReports a create-process debugging event (includes both a\nprocess and its main thread). The value of\nu.CreateProcessInfo specifies a\nCREATE_PROCESS_DEBUG_INFO structure.\nCREATE_THREAD_DEBUG_EVENT\n2\nReports a create-thread debugging event (does not include\nthe main thread of a process, see\n`CREATE_PROCESS_DEBUG_EVENT`). The value of\nSyntax\ntypedef struct _DEBUG_EVENT {\n DWORD dwDebugEventCode;\n DWORD dwProcessId;\n DWORD dwThreadId;\n union {\n EXCEPTION_DEBUG_INFO Exception;\n CREATE_THREAD_DEBUG_INFO CreateThread;\n CREATE_PROCESS_DEBUG_INFO CreateProcessInfo;\n EXIT_THREAD_DEBUG_INFO ExitThread;\n EXIT_PROCESS_DEBUG_INFO ExitProcess;\n LOAD_DLL_DEBUG_INFO LoadDll;\n UNLOAD_DLL_DEBUG_INFO UnloadDll;\n OUTPUT_DEBUG_STRING_INFO DebugString;\n RIP_INFO RipInfo;\n } u;\n} DEBUG_EVENT, *LPDEBUG_EVENT;\nMembers\nﾉ Expand table\nu.CreateThread specifies a CREATE_THREAD_DEBUG_INFO\nstructure.\nEXCEPTION_DEBUG_EVENT\n1\nReports an exception debugging event. The value of\nu.Exception specifies an EXCEPTION_DEBUG_INFO structure.\nEXIT_PROCESS_DEBUG_EVENT\n5\nReports an exit-process debugging event. The value of\nu.ExitProcess specifies an EXIT_PROCESS_DEBUG_INFO\nstructure.\nEXIT_THREAD_DEBUG_EVENT\n4\nReports an exit-thread debugging event. The value of\nu.ExitThread specifies an EXIT_THREAD_DEBUG_INFO\nstructure.\nLOAD_DLL_DEBUG_EVENT\n6\nReports a load-dynamic-link-library (DLL) debugging event.\nThe value of u.LoadDll specifies a LOAD_DLL_DEBUG_INFO\nstructure.\nOUTPUT_DEBUG_STRING_EVENT\n8\nReports an output-debugging-string debugging event. The\nvalue of u.DebugString specifies an\nOUTPUT_DEBUG_STRING_INFO structure.\nRIP_EVENT\n9\nReports a RIP-debugging event (system debugging error). The\nvalue of u.RipInfo specifies a RIP_INFO structure.\nUNLOAD_DLL_DEBUG_EVENT\n7\nReports an unload-DLL debugging event. The value of\nu.UnloadDll specifies an UNLOAD_DLL_DEBUG_INFO\nstructure.\ndwProcessId\nType: DWORD\nThe identifier of the process in which the debugging event occurred. A debugger uses this\nvalue to locate the debugger's per-process structure. These values are not necessarily small\nintegers that can be used as table indices.\ndwThreadId\nType: DWORD\nThe identifier of the thread in which the debugging event occurred. A debugger uses this value\nto locate the debugger's per-thread structure. These values are not necessarily small integers\nthat can be used as table indices.\nu\nAny additional information relating to the debugging event. This union takes on the type and\nvalue appropriate to the type of debugging event, as described in the dwDebugEventCode\nmember.\nu.Exception\nType: EXCEPTION_DEBUG_INFO\nIf the dwDebugEventCode is EXCEPTION_DEBUG_EVENT (1), u.Exception specifies an\nEXCEPTION_DEBUG_INFO structure.\nu.CreateThread\nType: CREATE_THREAD_DEBUG_INFO\nIf the dwDebugEventCode is CREATE_THREAD_DEBUG_EVENT (2), u.CreateThread specifies an\nCREATE_THREAD_DEBUG_INFO structure.\nu.CreateProcessInfo\nType: CREATE_PROCESS_DEBUG_INFO\nIf the dwDebugEventCode is CREATE_PROCESS_DEBUG_EVENT (3), u.CreateProcessInfo\nspecifies an CREATE_PROCESS_DEBUG_INFO structure.\nu.ExitThread\nType: EXIT_THREAD_DEBUG_INFO\nIf the dwDebugEventCode is EXIT_THREAD_DEBUG_EVENT (4), u.ExitThread specifies an\nEXIT_THREAD_DEBUG_INFO structure.\nu.ExitProcess\nType: EXIT_PROCESS_DEBUG_INFO\nIf the dwDebugEventCode is EXIT_PROCESS_DEBUG_EVENT (5), u.ExitProcess specifies an\nEXIT_PROCESS_DEBUG_INFO structure.\nu.LoadDll\nType: LOAD_DLL_DEBUG_INFO\nIf the dwDebugEventCode is LOAD_DLL_DEBUG_EVENT (6), u.LoadDll specifies an\nLOAD_DLL_DEBUG_INFO structure.\nu.UnloadDll\nType: UNLOAD_DLL_DEBUG_INFO\nIf the dwDebugEventCode is UNLOAD_DLL_DEBUG_EVENT (7), u.UnloadDll specifies an\nUNLOAD_DLL_DEBUG_INFO structure.\nu.DebugString\nType: OUTPUT_DEBUG_STRING_INFO\nIf the dwDebugEventCode is OUTPUT_DEBUG_STRING_EVENT (8), u.DebugString specifies an\nOUTPUT_DEBUG_STRING_INFO structure.\nu.RipInfo\nType: RIP_INFO\nIf the dwDebugEventCode is RIP_EVENT (9), u.RipInfo specifies an RIP_INFO structure.\nIf the WaitForDebugEvent function succeeds, it fills in the members of a DEBUG_EVENT\nstructure.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server ","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3188,"title":"EXCEPTION_DEBUG_INFO structure (minwinbase.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["exception","debug","info","structure","minwinbase","contains","information","that","can","used","debugger","article02","2024","exceptionrecord","record","with","specific","the","this","includes","code","flags","address","pointer","related","extra","parameters","and","dwfirstchance","value","indicates","whether","has","previously","encountered","specified","member","nonzero","first","time"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains exception information that can be used by a debugger.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to EXCEPTION_DEBUG_INFO structure (minwinbase.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"EXCEPTION_DEBUG_INFO structure\n(minwinbase.h)\nArticle02/22/2024\nContains exception information that can be used by a debugger.\nC++\nExceptionRecord\nAn EXCEPTION_RECORD structure with information specific to the exception. This includes the\nexception code, flags, address, a pointer to a related exception, extra parameters, and so on.\ndwFirstChance\nA value that indicates whether the debugger has previously encountered the exception\nspecified by the ExceptionRecord member. If the dwFirstChance member is nonzero, this is the\nfirst time the debugger has encountered the exception. Debuggers typically handle breakpoint\nand single-step exceptions when they are first encountered. If this member is zero, the\ndebugger has previously encountered the exception. This occurs only if, during the search for\nstructured exception handlers, either no handler was found or the exception was continued.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nSyntax\ntypedef struct _EXCEPTION_DEBUG_INFO {\n EXCEPTION_RECORD ExceptionRecord;\n DWORD dwFirstChance;\n} EXCEPTION_DEBUG_INFO, *LPEXCEPTION_DEBUG_INFO;\nMembers\nRequirements\nﾉ Expand table\nRequirement Value\nHeader minwinbase.h (include Windows.h)\nDEBUG_EVENT\nEXCEPTION_RECORD\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3189,"title":"EXIT_PROCESS_DEBUG_INFO structure (minwinbase.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["exit","process","debug","info","structure","minwinbase","contains","the","code","for","terminating","article02","2024","dwexitcode","requirement","value","minimum","supported","client","windows","desktop","apps","only","server","2003","header","include","event","syntax","typedef","struct","dword","lpexit","members","requirements","expand","table","see","also"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains the exit code for a terminating process.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to EXIT_PROCESS_DEBUG_INFO structure (minwinbase.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"EXIT_PROCESS_DEBUG_INFO structure\n(minwinbase.h)\nArticle02/22/2024\nContains the exit code for a terminating process.\nC++\ndwExitCode\nThe exit code for the process.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nHeader minwinbase.h (include Windows.h)\nDEBUG_EVENT\nSyntax\ntypedef struct _EXIT_PROCESS_DEBUG_INFO {\n DWORD dwExitCode;\n} EXIT_PROCESS_DEBUG_INFO, *LPEXIT_PROCESS_DEBUG_INFO;\nMembers\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3190,"title":"EXIT_THREAD_DEBUG_INFO structure (minwinbase.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["exit","thread","debug","info","structure","minwinbase","contains","the","code","for","terminating","article02","2024","dwexitcode","requirement","value","minimum","supported","client","windows","desktop","apps","only","server","2003","header","include","event","syntax","typedef","struct","dword","lpexit","members","requirements","expand","table","see","also"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains the exit code for a terminating thread.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to EXIT_THREAD_DEBUG_INFO structure (minwinbase.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"EXIT_THREAD_DEBUG_INFO structure\n(minwinbase.h)\nArticle02/22/2024\nContains the exit code for a terminating thread.\nC++\ndwExitCode\nThe exit code for the thread.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nHeader minwinbase.h (include Windows.h)\nDEBUG_EVENT\nSyntax\ntypedef struct _EXIT_THREAD_DEBUG_INFO {\n DWORD dwExitCode;\n} EXIT_THREAD_DEBUG_INFO, *LPEXIT_THREAD_DEBUG_INFO;\nMembers\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3191,"title":"LDT_ENTRY structure (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["ldt","entry","structure","winnt","describes","the","descriptor","table","article02","2024","this","valid","only","x86","based","systems","limitlow","low","order","part","address","last","byte","segment","baselow","base","highword","syntax","typedef","struct","word","union","basemid","flags1","flags2","basehi","bytes","dword","type","dpl"],"errorCode":"","eventId":"","severity":"Low","summary":"Describes an entry in the descriptor table.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to LDT_ENTRY structure (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"LDT_ENTRY structure (winnt.h)\nArticle02/22/2024\nDescribes an entry in the descriptor table. This structure is valid only on x86-based\nsystems.\nC++\nLimitLow\nThe low-order part of the address of the last byte in the segment.\nBaseLow\nThe low-order part of the base address of the segment.\nHighWord\nSyntax\ntypedef struct _LDT_ENTRY {\n WORD LimitLow;\n WORD BaseLow;\n union {\n struct {\n BYTE BaseMid;\n BYTE Flags1;\n BYTE Flags2;\n BYTE BaseHi;\n } Bytes;\n struct {\n DWORD BaseMid : 8;\n DWORD Type : 5;\n DWORD Dpl : 2;\n DWORD Pres : 1;\n DWORD LimitHi : 4;\n DWORD Sys : 1;\n DWORD Reserved_0 : 1;\n DWORD Default_Big : 1;\n DWORD Granularity : 1;\n DWORD BaseHi : 8;\n } Bits;\n } HighWord;\n} LDT_ENTRY, *PLDT_ENTRY;\nMembers\nThe high-order portion of the descriptor. This member may be interpreted as bytes or\ncollections of bits, depending on the level of detail required.\nHighWord.Bytes\nHighWord.Bytes.BaseMid\nMiddle bits (16–23) of the base address of the segment.\nHighWord.Bytes.Flags1\nValues of the Type, Dpl, and Pres members in the Bits structure.\nHighWord.Bytes.Flags2\nValues of the LimitHi, Sys, Reserved_0, Default_Big, and Granularity members in the\nBits structure.\nHighWord.Bytes.BaseHi\nHigh bits (24–31) of the base address of the segment.\nHighWord.Bits\nHighWord.Bits.BaseMid\nThe middle bits (16–23) of the base address of the segment.\nHighWord.Bits.Type\nThe type of segment. This member can be one of the following values:\nHighWord.Bits.Dpl\nThe privilege level of the descriptor. This member is an integer value in the range 0\n(most privileged) through 3 (least privileged).\nHighWord.Bits.Pres\nThe present flag. This member is 1 if the segment is present in physical memory or 0 if it\nis not.\nHighWord.Bits.LimitHi\nThe high bits (16–19) of the address of the last byte in the segment.\nHighWord.Bits.Sys\nThe space that is available to system programmers. This member might be used for\nmarking segments in some system-specific way.\nHighWord.Bits.Reserved_0\nReserved.\nHighWord.Bits.Default_Big\nThe size of segment. If the segment is a data segment, this member contains 1 if the\nsegment is larger than 64 kilobytes (K) or 0 if the segment is smaller than or equal to\n64K.\nIf the segment is a code segment, this member contains 1 if the segment is a code\nsegment and runs with the default (native mode) instruction set. This member contains\n0 if the code segment is an 80286 code segment and runs with 16-bit offsets and the\n80286-compatible instruction set.\nHighWord.Bits.Granularity\nThe granularity. This member contains 0 if the segment is byte granular, 1 if the\nsegment is page granular.\nHighWord.Bits.BaseHi\nThe high bits (24–31) of the base address of the segment.\nThe GetThreadSelectorEntry function fills this structure with information from an entry in\nthe descriptor table. You can use this information to convert a segment-relative address\nto a linear virtual address.\nThe base address of a segment is the address of offset 0 in the segment. To calculate\nthis value, combine the BaseLow, BaseMid, and BaseHi members.\nThe limit of a segment is the address of the last byte that can be addressed in the\nsegment. To calculate this value, combine the LimitLow and LimitHi members.\nRemarks\nRequirements\nﾉ Expand table\nFeedback\nWas this page helpful?\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nHeader winnt.h (include Windows.h)\nDebugging Structures\nGetThreadSelectorEntry\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3192,"title":"LOAD_DLL_DEBUG_INFO structure (minwinbase.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["load","dll","debug","info","structure","minwinbase","contains","information","about","dynamic","link","library","that","has","just","been","loaded","article04","2021","hfile","handle","the","this","member","null","not","valid","otherwise","opened","for","reading","and","read","sharing","context","debugger","when","finished","with","file"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains information about a dynamic-link library (DLL) that has just been loaded.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to LOAD_DLL_DEBUG_INFO structure (minwinbase.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"LOAD_DLL_DEBUG_INFO structure\n(minwinbase.h)\nArticle04/02/2021\nContains information about a dynamic-link library (DLL) that has just been loaded.\nC++\nhFile\nA handle to the loaded DLL. If this member is NULL, the handle is not valid. Otherwise, the\nmember is opened for reading and read-sharing in the context of the debugger.\nWhen the debugger is finished with this file, it should close the handle using the CloseHandle\nfunction.\nlpBaseOfDll\nA pointer to the base address of the DLL in the address space of the process loading the DLL.\ndwDebugInfoFileOffset\nThe offset to the debugging information in the file identified by the hFile member, in bytes.\nThe system expects the debugging information to be in CodeView 4.0 format. This format is\ncurrently a derivative of Common Object File Format (COFF).\nnDebugInfoSize\nThe size of the debugging information in the file, in bytes. If this member is zero, there is no\ndebugging information.\nSyntax\ntypedef struct _LOAD_DLL_DEBUG_INFO {\n HANDLE hFile;\n LPVOID lpBaseOfDll;\n DWORD dwDebugInfoFileOffset;\n DWORD nDebugInfoSize;\n LPVOID lpImageName;\n WORD fUnicode;\n} LOAD_DLL_DEBUG_INFO, *LPLOAD_DLL_DEBUG_INFO;\nMembers\nlpImageName\nA pointer to the file name associated with hFile. This member may be NULL, or it may contain\nthe address of a string pointer in the address space of the process being debugged. That\naddress may, in turn, either be NULL or point to the actual filename. If fUnicode is a nonzero\nvalue, the name string is Unicode; otherwise, it is ANSI.\nThis member is strictly optional. Debuggers must be prepared to handle the case where\nlpImageName is NULL or *lpImageName (in the address space of the process being\ndebugged) is NULL. Specifically, the system will never provide an image name for a create\nprocess event, and it will not likely pass an image name for the first DLL event. The system will\nalso never provide this information in the case of debugging events that originate from a call\nto the DebugActiveProcess function.\nfUnicode\nA value that indicates whether a filename specified by lpImageName is Unicode or ANSI. A\nnonzero value for this member indicates Unicode; zero indicates ANSI.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nHeader minwinbase.h (include Windows.h)\nCREATE_PROCESS_DEBUG_INFO\nCREATE_THREAD_DEBUG_INFO\nDEBUG_EVENT\nDebugActiveProcess\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3193,"title":"OUTPUT_DEBUG_STRING_INFO structure (minwinbase.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["output","debug","string","info","structure","minwinbase","contains","the","address","format","and","length","bytes","debugging","article02","2024","lpdebugstringdata","calling","process","space","debugger","can","use","readprocessmemory","function","retrieve","value","funicode","this","member","zero","ansi","nonzero","unicode","ndebugstringlength","lower","bits","type","word","does"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains the address, format, and length, in bytes, of a debugging string.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to OUTPUT_DEBUG_STRING_INFO structure (minwinbase.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"OUTPUT_DEBUG_STRING_INFO structure\n(minwinbase.h)\nArticle02/22/2024\nContains the address, format, and length, in bytes, of a debugging string.\nC++\nlpDebugStringData\nThe debugging string in the calling process's address space. The debugger can use the\nReadProcessMemory function to retrieve the value of the string.\nfUnicode\nThe format of the debugging string. If this member is zero, the debugging string is ANSI; if it is\nnonzero, the string is Unicode.\nnDebugStringLength\nThe lower 16 bits of the length of the string in bytes. As nDebugStringLength is of type WORD,\nthis does not always contain the full length of the string in bytes.\nFor example, if the original output string is longer than 65536 bytes, this field will contain a\nvalue that is less than the actual string length in bytes.\nSyntax\ntypedef struct _OUTPUT_DEBUG_STRING_INFO {\n LPSTR lpDebugStringData;\n WORD fUnicode;\n WORD nDebugStringLength;\n} OUTPUT_DEBUG_STRING_INFO, *LPOUTPUT_DEBUG_STRING_INFO;\nMembers\nRequirements\nﾉ Expand table\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nHeader minwinbase.h (include Windows.h)\nDEBUG_EVENT\nReadProcessMemory\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3194,"title":"RIP_INFO structure (minwinbase.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["rip","info","structure","minwinbase","contains","the","error","that","caused","debug","event","article02","2024","dwerror","for","more","information","see","handling","dwtype","any","additional","about","type","this","member","can","one","following","values","value","meaning","sle","0x00000001","indicates","invalid","data","was","passed","function"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains the error that caused the RIP debug event.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to RIP_INFO structure (minwinbase.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"RIP_INFO structure (minwinbase.h)\nArticle02/22/2024\nContains the error that caused the RIP debug event.\nC++\ndwError\nThe error that caused the RIP debug event. For more information, see Error Handling.\ndwType\nAny additional information about the type of error that caused the RIP debug event. This\nmember can be one of the following values.\nValue Meaning\nSLE_ERROR\n0x00000001\nIndicates that invalid data was passed to the function that\nfailed. This caused the application to fail.\nSLE_MINORERROR\n0x00000002\nIndicates that invalid data was passed to the function, but the\nerror probably will not cause the application to fail.\nSLE_WARNING\n0x00000003\nIndicates that potentially invalid data was passed to the\nfunction, but the function completed processing.\n0 Indicates that only dwError was set.\nSyntax\ntypedef struct _RIP_INFO {\n DWORD dwError;\n DWORD dwType;\n} RIP_INFO, *LPRIP_INFO;\nMembers\nﾉ Expand table\nRequirements\nﾉ Expand table\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nHeader minwinbase.h (include Minwinbase.h, Windows.h)\nDEBUG_EVENT\nSee also\nThread Environment Block (Debugging\nNotes)\nThe Thread Environment Block (TEB structure) holds context information for a thread.\nIn the following versions of Windows, the offset of the 32-bit TEB address within the 64-bit TEB\nis 0. This can be used to directly access the 32-bit TEB of a WOW64 thread. This might change\nin later versions of Windows\nPlatform Version\nWindows Vista Windows Server 2008\nWindows 7 Windows Server 2008 R2\nWindows 8 Windows Server 2012\nWindows 8.1 Windows Server 2012 R2\n \nDebugging Structures\nWOW64_CONTEXT\n \n \nLast updated on 07/14/2025\nﾉ Expand table\nRelated topics","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3195,"title":"UNLOAD_DLL_DEBUG_INFO structure (minwinbase.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["unload","dll","debug","info","structure","minwinbase","contains","information","about","dynamic","link","library","that","has","just","been","unloaded","article02","2024","lpbaseofdll","pointer","the","base","address","space","process","unloading","requirement","value","minimum","supported","client","windows","desktop","apps","only","server","2003","header","include"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains information about a dynamic-link library (DLL) that has just been unloaded.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to UNLOAD_DLL_DEBUG_INFO structure (minwinbase.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"UNLOAD_DLL_DEBUG_INFO structure\n(minwinbase.h)\nArticle02/22/2024\nContains information about a dynamic-link library (DLL) that has just been unloaded.\nC++\nlpBaseOfDll\nA pointer to the base address of the DLL in the address space of the process unloading the\nDLL.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nHeader minwinbase.h (include Windows.h)\nDEBUG_EVENT\nSyntax\ntypedef struct _UNLOAD_DLL_DEBUG_INFO {\n LPVOID lpBaseOfDll;\n} UNLOAD_DLL_DEBUG_INFO, *LPUNLOAD_DLL_DEBUG_INFO;\nMembers\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3196,"title":"WOW64_CONTEXT structure (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["wow64","context","structure","winnt","represents","frame","article02","2024","refer","the","header","file","for","definition","this","contextflags","dr0","dr1","syntax","typedef","struct","dword","dr2","dr3","dr6","dr7","floating","save","area","floatsave","seggs","segfs","seges","segds","edi","esi","ebx","edx","ecx","eax"],"errorCode":"","eventId":"","severity":"Low","summary":"Represents a context frame on WOW64.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to WOW64_CONTEXT structure (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"WOW64_CONTEXT structure (winnt.h)\nArticle02/22/2024\nRepresents a context frame on WOW64. Refer to the header file WinNT.h for the\ndefinition of this structure.\nC++\nContextFlags\nDr0\nDr1\nSyntax\ntypedef struct _WOW64_CONTEXT {\n DWORD ContextFlags;\n DWORD Dr0;\n DWORD Dr1;\n DWORD Dr2;\n DWORD Dr3;\n DWORD Dr6;\n DWORD Dr7;\n WOW64_FLOATING_SAVE_AREA FloatSave;\n DWORD SegGs;\n DWORD SegFs;\n DWORD SegEs;\n DWORD SegDs;\n DWORD Edi;\n DWORD Esi;\n DWORD Ebx;\n DWORD Edx;\n DWORD Ecx;\n DWORD Eax;\n DWORD Ebp;\n DWORD Eip;\n DWORD SegCs;\n DWORD EFlags;\n DWORD Esp;\n DWORD SegSs;\n BYTE \nExtendedRegisters[WOW64_MAXIMUM_SUPPORTED_EXTENSION];\n} WOW64_CONTEXT;\nMembers\nDr2\nDr3\nDr6\nDr7\nFloatSave\nSegGs\nSegFs\nSegEs\nSegDs\nEdi\nEsi\nEbx\nEdx\nEcx\nEax\nEbp\nEip\nSegCs\nEFlags\nEsp\nSegSs\nExtendedRegisters[WOW64_MAXIMUM_SUPPORTED_EXTENSION]\nRemarks\nFeedback\nWas this page helpful?\nIn the following versions of Windows, Slot 1 of Thread Local Storage (TLS) holds a\npointer to a structure that contains a WOW64_CONTEXT structure starting at offset 4.\nThis might change in later versions of Windows.\nWindows Vista Windows Server 2008\nWindows 7 Windows Server 2008 R2\nWindows 8 Windows Server 2012\nWindows 8.1 Windows Server 2012 R2\nRequirement Value\nMinimum supported client Windows Vista [desktop apps only]\nMinimum supported server Windows Server 2008 [desktop apps only]\nHeader winnt.h (include Windows.h)\nThread Environment Block (Debugging Notes)\nWOW64_FLOATING_SAVE_AREA\nWow64GetThreadContext\nWow64SetThreadContext\nﾉ Expand table\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3197,"title":"WOW64_FLOATING_SAVE_AREA structure (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["wow64","floating","save","area","structure","winnt","represents","the","80387","article02","2024","refer","header","file","for","definition","this","controlword","statusword","tagword","erroroffset","errorselector","dataoffset","dataselector","registerarea","size","registers","cr0npxstate","syntax","typedef","struct","dword","byte","members","feedback","was","page","helpful","requirement","value"],"errorCode":"","eventId":"","severity":"Low","summary":"Represents the 80387 save area on WOW64.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to WOW64_FLOATING_SAVE_AREA structure (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"WOW64_FLOATING_SAVE_AREA\nstructure (winnt.h)\nArticle02/22/2024\nRepresents the 80387 save area on WOW64. Refer to the header file WinNT.h for the\ndefinition of this structure.\nC++\nControlWord\nStatusWord\nTagWord\nErrorOffset\nErrorSelector\nDataOffset\nDataSelector\nRegisterArea[WOW64_SIZE_OF_80387_REGISTERS]\nCr0NpxState\nSyntax\ntypedef struct _WOW64_FLOATING_SAVE_AREA {\n DWORD ControlWord;\n DWORD StatusWord;\n DWORD TagWord;\n DWORD ErrorOffset;\n DWORD ErrorSelector;\n DWORD DataOffset;\n DWORD DataSelector;\n BYTE RegisterArea[WOW64_SIZE_OF_80387_REGISTERS];\n DWORD Cr0NpxState;\n} WOW64_FLOATING_SAVE_AREA;\nMembers\nFeedback\nWas this page helpful?\nRequirement Value\nMinimum supported client Windows Vista [desktop apps only]\nMinimum supported server Windows Server 2008 [desktop apps only]\nHeader winnt.h (include Windows.h)\nWOW64_CONTEXT\nWow64GetThreadContext\nWow64SetThreadContext\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3198,"title":"WOW64_LDT_ENTRY structure (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["wow64","ldt","entry","structure","winnt","describes","the","descriptor","table","for","bit","thread","system","article05","2021","this","valid","only","systems","limitlow","low","order","part","address","last","byte","segment","baselow","base","highword","syntax","typedef","struct","word","union","basemid","flags1","flags2","basehi","bytes"],"errorCode":"","eventId":"","severity":"Low","summary":"Describes an entry in the descriptor table for a 32-bit thread on a 64-bit system.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to WOW64_LDT_ENTRY structure (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"WOW64_LDT_ENTRY structure (winnt.h)\nArticle05/07/2021\nDescribes an entry in the descriptor table for a 32-bit thread on a 64-bit system. This\nstructure is valid only on 64-bit systems.\nC++\nLimitLow\nThe low-order part of the address of the last byte in the segment.\nBaseLow\nThe low-order part of the base address of the segment.\nHighWord\nSyntax\ntypedef struct _WOW64_LDT_ENTRY {\n WORD LimitLow;\n WORD BaseLow;\n union {\n struct {\n BYTE BaseMid;\n BYTE Flags1;\n BYTE Flags2;\n BYTE BaseHi;\n } Bytes;\n struct {\n DWORD BaseMid : 8;\n DWORD Type : 5;\n DWORD Dpl : 2;\n DWORD Pres : 1;\n DWORD LimitHi : 4;\n DWORD Sys : 1;\n DWORD Reserved_0 : 1;\n DWORD Default_Big : 1;\n DWORD Granularity : 1;\n DWORD BaseHi : 8;\n } Bits;\n } HighWord;\n} WOW64_LDT_ENTRY, *PWOW64_LDT_ENTRY;\nMembers\nThe high-order portion of the descriptor. This member may be interpreted as bytes or\ncollections of bits, depending on the level of detail required.\nHighWord.Bytes\nHighWord.Bytes.BaseMid\nMiddle bits (16–23) of the base address of the segment.\nHighWord.Bytes.Flags1\nValues of the Type, Dpl, and Pres members in the Bits structure.\nHighWord.Bytes.Flags2\nValues of the LimitHi, Sys, Reserved_0, Default_Big, and Granularity members in the\nBits structure.\nHighWord.Bytes.BaseHi\nHigh bits (24–31) of the base address of the segment.\nHighWord.Bits\nHighWord.Bits.BaseMid\nThe middle bits (16–23) of the base address of the segment.\nHighWord.Bits.Type\nThe type of segment. This member can be one of the following values:\nHighWord.Bits.Dpl\nThe privilege level of the descriptor. This member is an integer value in the range 0\n(most privileged) through 3 (least privileged).\nHighWord.Bits.Pres\nThe present flag. This member is 1 if the segment is present in physical memory or 0 if it\nis not.\nHighWord.Bits.LimitHi\nThe high bits (16–19) of the address of the last byte in the segment.\nHighWord.Bits.Sys\nThe space that is available to system programmers. This member might be used for\nmarking segments in some system-specific way.\nHighWord.Bits.Reserved_0\nReserved.\nHighWord.Bits.Default_Big\nThe size of segment. If the segment is a data segment, this member contains 1 if the\nsegment is larger than 64 kilobytes (KB) or 0 if the segment is smaller than or equal to\n64 KB.\nIf the segment is a code segment, this member contains 1. The segment runs with the\ndefault (native mode) instruction set.\nHighWord.Bits.Granularity\nThe granularity. This member contains 0 if the segment is byte granular, 1 if the\nsegment is page granular.\nHighWord.Bits.BaseHi\nThe high bits (24–31) of the base address of the segment.\nThe Wow64GetThreadSelectorEntry function fills this structure with information from an\nentry in the descriptor table. You can use this information to convert a segment-relative\naddress to a linear virtual address.\nThe base address of a segment is the address of offset 0 in the segment. To calculate\nthis value, combine the BaseLow, BaseMid, and BaseHi members.\nThe limit of a segment is the address of the last byte that can be addressed in the\nsegment. To calculate this value, combine the LimitLow and LimitHi members.\nThe WOW64_LDT_ENTRY structure has the same layout for a 64-bit process as the\nLDT_ENTRY structure has for a 32-bit process.\nRemarks\nRequirements\nﾉ Expand table\nFeedback\nWas this page helpful?\nRequirement Value\nMinimum supported client Windows 7 [desktop apps only]\nMinimum supported server Windows Server 2008 R2 [desktop apps only]\nHeader winnt.h (include Windows.h)\nDebugging Structures\nWow64GetThreadSelectorEntry\nSee also\nYes No\nDebug Help Library\nThis overview describes the function set provided by the debug help library, DbgHelp. It\ncontains a set of debugging support routines that allow you to work with executable images in\nthe portable executable (PE) format.\nThe DbgHelp documentation is as follows:\nAbout DbgHelp\nUsing DbgHelp\nDbgHelp Reference\nTo obtain the latest version of DbgHelp.dll, go to\nhttps://developer.microsoft.com/windows/downloads/windows-10-sdk and download\nDebugging Tools for Windows.\nFor a description of the PE format, download the specification from the following location:\nMicrosoft Portable Executable and Common Object File Format Specification - 1999\n(pecoff).doc.\nFor information on how to browse information found in .pdb files, see the Debug Interface\nAccess SDK.\nLast updated on 07/14/2025\nAbout DbgHelp\nThe following topics describe symbol files and the functionality provided by the DbgHelp\nfunctions.\nDbgHelp Versions\nSymbol Files\nSymbol Handling\nSymbol Servers and Symbol Stores\nMinidump Files\nSource Server\nUpdated Platform Support\nNote that all DbgHelp functions are single threaded. Therefore, calls from more than one\nthread to this function will likely result in unexpected behavior or memory corruption. To avoid\nthis, you must synchronize all concurrent calls from more than one thread to this function.\n \n \nLast updated on 07/14/2025\nDbgHelp Versions\nThe DbgHelp library is implemented by DbgHelp.dll. Although this DLL is included in all\nsupported versions of Windows, it is rarely the most current version of DbgHelp available.\nFurthermore, the version of DbgHelp that ships in Windows has reduced functionality from the\nother releases-- specifically, it lacks support for Symbol Server and Source Server.\nThe most current versions of DbgHelp.dll, SymSrv.dll, and SrcSrv.dll are available as a part of\nthe Debugging Tools For Windows package. The redistribution policies make it possible for\npeople to include the Debugging Tools For Windows installer in their own packages and\nreleases.\nTo obtain the latest version of DbgHelp.dll, go to\nhttps://developer.microsoft.com/windows/downloads/windows-10-sdk and download\nDebugging Tools for Windows. Refer to Calling the DbgHelp Library for information on proper\ninstallation.\nMany versions of DbgHelp include additional functionality. To ensure that the correct version of\nDbgHelp is available for your application, review the Requirements information in the specific\nAPI reference documentation.\nLast upda","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3199,"title":"IMAGEHLP_SYMBOL_TYPE_INFO enumeration (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["imagehlp","symbol","type","info","enumeration","dbghelp","identifies","the","information","retrieved","article01","2025","syntax","typedef","enum","get","symtag","symname","length","typeid","basetype","arrayindextypeid","findchildren","datakind","addressoffset","offset","value","count","childrencount","bitposition","virtualbaseclass","virtualtableshapeid","virtualbasepointeroffset","classparentid","nested","symindex","lexicalparent","address","thisadjust","udtkind"],"errorCode":"","eventId":"","severity":"Low","summary":"Identifies the type of symbol information to be retrieved.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to IMAGEHLP_SYMBOL_TYPE_INFO enumeration (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"IMAGEHLP_SYMBOL_TYPE_INFO\nenumeration (dbghelp.h)\nArticle01/24/2025\nIdentifies the type of symbol information to be retrieved.\nC++\nSyntax\ntypedef enum _IMAGEHLP_SYMBOL_TYPE_INFO {\n TI_GET_SYMTAG,\n TI_GET_SYMNAME,\n TI_GET_LENGTH,\n TI_GET_TYPE,\n TI_GET_TYPEID,\n TI_GET_BASETYPE,\n TI_GET_ARRAYINDEXTYPEID,\n TI_FINDCHILDREN,\n TI_GET_DATAKIND,\n TI_GET_ADDRESSOFFSET,\n TI_GET_OFFSET,\n TI_GET_VALUE,\n TI_GET_COUNT,\n TI_GET_CHILDRENCOUNT,\n TI_GET_BITPOSITION,\n TI_GET_VIRTUALBASECLASS,\n TI_GET_VIRTUALTABLESHAPEID,\n TI_GET_VIRTUALBASEPOINTEROFFSET,\n TI_GET_CLASSPARENTID,\n TI_GET_NESTED,\n TI_GET_SYMINDEX,\n TI_GET_LEXICALPARENT,\n TI_GET_ADDRESS,\n TI_GET_THISADJUST,\n TI_GET_UDTKIND,\n TI_IS_EQUIV_TO,\n TI_GET_CALLING_CONVENTION,\n TI_IS_CLOSE_EQUIV_TO,\n TI_GTIEX_REQS_VALID,\n TI_GET_VIRTUALBASEOFFSET,\n TI_GET_VIRTUALBASEDISPINDEX,\n TI_GET_IS_REFERENCE,\n TI_GET_INDIRECTVIRTUALBASECLASS,\n TI_GET_VIRTUALBASETABLETYPE,\n TI_GET_OBJECTPOINTERTYPE,\n TI_GET_DISCRIMINATEDUNION_TAG_TYPEID,\n TI_GET_DISCRIMINATEDUNION_TAG_OFFSET,\n TI_GET_DISCRIMINATEDUNION_TAG_RANGESCOUNT,\nTI_GET_SYMTAG\nThe symbol tag.\nThe data type is DWORD*.\nTI_GET_SYMNAME\nThe symbol name.\nThe data type is WCHAR**. The caller must free the buffer.\nTI_GET_LENGTH\nThe length of the type.\nThe data type is ULONG64*.\nTI_GET_TYPE\nThe type.\nThe data type is DWORD*.\nTI_GET_TYPEID\nThe type index.\nThe data type is DWORD*.\nTI_GET_BASETYPE\nThe base type for the type index.\nThe data type is DWORD*.\nTI_GET_ARRAYINDEXTYPEID\nThe type index for index of an array type.\nThe data type is DWORD*.\nTI_FINDCHILDREN\nThe type index of all children.\n TI_GET_DISCRIMINATEDUNION_TAG_RANGES,\n IMAGEHLP_SYMBOL_TYPE_INFO_MAX\n} IMAGEHLP_SYMBOL_TYPE_INFO;\nConstants\nﾉ Expand table\nThe data type is a pointer to a\nTI_FINDCHILDREN_PARAMS structure.\n- The Count member should be initialized with the number of children.\n- The Start member should also be initialized. In most cases, to zero.\nTI_GET_DATAKIND\nThe data kind.\nThe data type is DWORD*.\nTI_GET_ADDRESSOFFSET\nThe address offset.\nThe data type is DWORD*.\nTI_GET_OFFSET\nThe offset of the type in the parent. Members can use this to get their offset in a structure.\nThe data type is DWORD*.\nTI_GET_VALUE\nThe value of a constant or enumeration value.\nThe data type is VARIANT*.\nTI_GET_COUNT\nThe count of array elements.\nThe data type is DWORD*.\nTI_GET_CHILDRENCOUNT\nThe number of children.\nThe data type is DWORD*.\nTI_GET_BITPOSITION\nThe bit position of a bitfield.\nThe data type is DWORD*.\nTI_GET_VIRTUALBASECLASS\nA value that indicates whether the base class is virtually inherited.\nThe data type is BOOL.\nTI_GET_VIRTUALTABLESHAPEID\nThe symbol interface of the type of virtual table, for a user-defined type.\nTI_GET_VIRTUALBASEPOINTEROFFSET\nThe offset of the virtual base pointer.\nThe data type is DWORD*.\nTI_GET_CLASSPARENTID\nThe type index of the class parent.\nThe data type is DWORD*.\nTI_GET_NESTED\nA value that indicates whether the type index is nested.\nThe data type is DWORD*.\nTI_GET_SYMINDEX\nThe symbol index for a type.\nThe data type is DWORD*.\nTI_GET_LEXICALPARENT\nThe lexical parent of the type.\nThe data type is DWORD*.\nTI_GET_ADDRESS\nThe index address.\nThe data type is ULONG64*.\nTI_GET_THISADJUST\nThe offset from the this pointer to its actual value.\nThe data type is DWORD*.\nTI_GET_UDTKIND\nThe UDT kind.\nThe data type is DWORD*.\nTI_IS_EQUIV_TO\nThe equivalency of two types.\nThe data type is DWORD*. The value is S_OK is the two types are equivalent, and S_FALSE\notherwise.\nTI_GET_CALLING_CONVENTION\nThe calling convention.\nThe data type is DWORD. The following are the valid values:\nTI_IS_CLOSE_EQUIV_TO\nThe equivalency of two symbols. This is not guaranteed to be accurate.\nThe data type is DWORD*. The value is S_OK is the two types are equivalent, and S_FALSE\notherwise.\nTI_GTIEX_REQS_VALID\nThe element where the valid request bitfield should be stored.\nThe data type is ULONG64*.\nThis value is only used with the SymGetTypeInfoEx function.\nTI_GET_VIRTUALBASEOFFSET\nThe offset in the virtual function table of a virtual function.\nThe data type is DWORD.\nTI_GET_VIRTUALBASEDISPINDEX\nThe index into the virtual base displacement table.\nThe data type is DWORD.\nTI_GET_IS_REFERENCE\nIndicates whether a pointer type is a reference.\nThe data type is Boolean.\nTI_GET_INDIRECTVIRTUALBASECLASS\nIndicates whether the user-defined data type is an indirect virtual base.\nThe data type is BOOL.\nDbgHelp 6.6 and earlier: This value is not supported.\nTI_GET_VIRTUALBASETABLETYPE\nIMAGEHLP_SYMBOL_TYPE_INFO_MAX\nRequirements\nﾉ Expand table\nFeedback\nWas this page helpful?\nProvide product feedback | Get help at Microsoft Q&A\nRequirement Value\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nSymGetTypeInfo\nSymGetTypeInfoEx\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3200,"title":"MINIDUMP_CALLBACK_TYPE enumeration (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","callback","type","enumeration","minidumpapiset","identifies","the","information","returned","minidumpcallback","function","article06","2021","not","all","memory","failures","will","cause","for","example","failure","within","stack","then","considered","unrecoverable","and","fail","modulecallback","returns","module","syntax","typedef","enum","threadcallback","threadexcallback","includethreadcallback","includemodulecallback","memorycallback"],"errorCode":"","eventId":"","severity":"Low","summary":"Identifies the type of information returned by the MiniDumpCallback function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_CALLBACK_TYPE enumeration (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_CALLBACK_TYPE\nenumeration (minidumpapiset.h)\nArticle06/02/2021\nIdentifies the type of information returned by the MiniDumpCallback function. Not all\nmemory failures will cause a callback; for example if the failure is within a stack then the\nfailure is considered to be unrecoverable and the minidump will fail.\nC++\n \nModuleCallback\nThe callback function returns module information.\nSyntax\ntypedef enum _MINIDUMP_CALLBACK_TYPE {\n ModuleCallback,\n ThreadCallback,\n ThreadExCallback,\n IncludeThreadCallback,\n IncludeModuleCallback,\n MemoryCallback,\n CancelCallback,\n WriteKernelMinidumpCallback,\n KernelMinidumpStatusCallback,\n RemoveMemoryCallback,\n IncludeVmRegionCallback,\n IoStartCallback,\n IoWriteAllCallback,\n IoFinishCallback,\n ReadMemoryFailureCallback,\n SecondaryFlagsCallback,\n IsProcessSnapshotCallback,\n VmStartCallback,\n VmQueryCallback,\n VmPreReadCallback,\n VmPostReadCallback\n} MINIDUMP_CALLBACK_TYPE;\nConstants\nﾉ Expand table\nThreadCallback\nThe callback function returns thread information.\nThreadExCallback\nThe callback function returns extended thread information.\nIncludeThreadCallback\nThe callback function indicates which threads are to be included. It is called as the minidump\nlibrary is\nenumerating the threads in a process, rather than after the information gathered, as it is with\nThreadCallback or ThreadExCallback. It is called for\neach thread. If the callback function returns FALSE, the current thread is excluded.\nThis allows the caller to obtain information for a subset of the threads in a process, without\nsuspending\nthreads that are not of interest. Alternately, you can modify the ThreadWriteFlags\nmember of the MINIDUMP_CALLBACK_OUTPUT\nstructure and return TRUE to avoid gathering unnecessary information for the\nthread.\nIncludeModuleCallback\nThe callback function indicates which modules are to be included. The callback function is called\nas the\nminidump library is enumerating the modules in a process, rather than after the information is\ngathered, as it\nis with ModuleCallback. It is called for each module. If the callback function\nreturns FALSE, the current module is excluded. Alternatively, you can modify the\nModuleWriteFlags member of the\nMINIDUMP_CALLBACK_OUTPUT structure and\nreturn TRUE to avoid gathering unnecessary information for the module.\nMemoryCallback\nThe callback function returns a region of memory to be included in the dump. The callback is\ncalled only\nfor dumps generated without the MiniDumpWithFullMemory flag. If the callback function returns\nFALSE or a region of size 0, the callback will not be called again.\nDbgHelp 6.1 and earlier: This value is not supported.\nCancelCallback\nThe callback function returns cancellation information.\nDbgHelp 6.1 and earlier: This value is not supported.\nWriteKernelMinidumpCallback\nThe user-mode minidump has been successfully completed. To initiate a kernel-mode minidump,\nthe callback\nshould return TRUE and set the Handle member of the\nMINIDUMP_CALLBACK_OUTPUT structure.\nDbgHelp 6.1 and earlier: This value is not supported.\nKernelMinidumpStatusCallback\nThe callback function returns status information for the kernel minidump.\nDbgHelp 6.1 and earlier: This value is not supported.\nRemoveMemoryCallback\nThe callback function returns a region of memory to be excluded from the dump. The callback is\ncalled only\nfor dumps generated without the MiniDumpWithFullMemory flag. If the callback\nfunction returns FALSE or a region of size 0, the callback will not be called again.\nDbgHelp 6.3 and earlier: This value is not supported.\nIncludeVmRegionCallback\nThe callback function returns information about the virtual memory region. It is called twice for\neach\nregion during the full-memory writing pass. The VmRegion member of the\nMINIDUMP_CALLBACK_OUTPUT structure\ncontains the current memory region. You can modify the base address and size of the region, as\nlong as the new\nregion remains a subset of the original region; changes to other members are ignored. If the\ncallback returns\nTRUE and sets the Continue member of\nMINIDUMP_CALLBACK_OUTPUT to\nTRUE, the minidump library will use the region specified by\nVmRegion as the region to be written. If the callback returns\nFALSE or if Continue is FALSE,\nthe callback will not be called for additional memory regions.\nDbgHelp 6.4 and earlier: This value is not supported.\nIoStartCallback\nThe callback function indicates that the caller will be providing an alternate I/O routine. If the\ncallback\nreturns TRUE and sets the Status member of\nMINIDUMP_CALLBACK_OUTPUT to\nS_FALSE, the minidump library will send all I/O through callbacks. The caller will\nreceive an IoWriteAllCallback callback for each piece of data.\nDbgHelp 6.4 and earlier: This value is not supported.\nIoWriteAllCallback\nThe callback must write all requested bytes or fail. The Io member of the\nMINIDUMP_CALLBACK_INPUT structure contains\nthe request. If the write operation fails, the callback should return FALSE. If the\nwrite operation succeeds, the callback should return TRUE and set the\nStatus member of\nMINIDUMP_CALLBACK_OUTPUT to\nS_OK. The caller will receive an IoFinishCallback callback\nwhen the I/O has completed.\nDbgHelp 6.4 and earlier: This value is not supported.\nIoFinishCallback\nThe callback returns I/O completion information. If the callback returns FALSE or\ndoes not set the Status member of\nMINIDUMP_CALLBACK_OUTPUT to\nS_OK, the minidump library assumes the minidump write operation has failed.\nDbgHelp 6.4 and earlier: This value is not supported.\nReadMemoryFailureCallback\nThere has been a failure to read memory. If the callback returns TRUE and sets\nthe Status member of\nMINIDUMP_CALLBACK_OUTPUT to\nS_OK, the memory failure is ignored and the block is omitted from the minidump. Otherwise, this\nfailure results in a failure to write to the minidump.\nDbgHelp 6.4 and earlier: This value is not supported.\nSecondaryFlagsCallback\nThe callback returns secondary information.\nDbgHelp 6.5 and earlier: This value is not supported.\nIsProcessSnapshotCallback\nTh","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3201,"title":"MINIDUMP_HANDLE_OBJECT_INFORMA TION_TYPE enumeration (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","handle","object","informa","tion","type","enumeration","minidumpapiset","identifies","the","specific","information","article02","2024","minihandleobjectinformationnone","there","for","this","minithreadinformation1","thread","objects","minimutantinformation1","mutant","minimutantinformation2","syntax","typedef","enum","miniprocessinformation1","miniprocessinformation2","minieventinformation1","minisectioninformation1","minisemaphoreinformation1","minihandleobjectinformationtypemax","constants","expand","table","feedback","was","page","helpful"],"errorCode":"","eventId":"","severity":"Low","summary":"Identifies the type of object-specific information.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_HANDLE_OBJECT_INFORMA TION_TYPE enumeration (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_HANDLE_OBJECT_INFORMA\nTION_TYPE enumeration\n(minidumpapiset.h)\nArticle02/22/2024\nIdentifies the type of object-specific information.\nC++\n \nMiniHandleObjectInformationNone\nThere is no object-specific information for this handle type.\nMiniThreadInformation1\nThe information is specific to thread objects.\nMiniMutantInformation1\nThe information is specific to mutant objects.\nMiniMutantInformation2\nThe information is specific to mutant objects.\nSyntax\ntypedef enum _MINIDUMP_HANDLE_OBJECT_INFORMATION_TYPE {\n MiniHandleObjectInformationNone,\n MiniThreadInformation1,\n MiniMutantInformation1,\n MiniMutantInformation2,\n MiniProcessInformation1,\n MiniProcessInformation2,\n MiniEventInformation1,\n MiniSectionInformation1,\n MiniSemaphoreInformation1,\n MiniHandleObjectInformationTypeMax\n} MINIDUMP_HANDLE_OBJECT_INFORMATION_TYPE;\nConstants\nﾉ Expand table\nFeedback\nWas this page helpful?\n \nMiniProcessInformation1\nThe information is specific to process objects.\nMiniProcessInformation2\nThe information is specific to process objects.\nMiniEventInformation1\nMiniSectionInformation1\nMiniSemaphoreInformation1\nMiniHandleObjectInformationTypeMax\nThe information represented by each of these values can vary by operating system and\nprocesor architecture. Per-handle object-specific information is automatically gathered\nwhen minidump type is MiniDumpWithHandleData. For more information, see\nMINIDUMP_TYPE.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 6.5 or later\nMINIDUMP_HANDLE_OBJECT_INFORMATION\nRemarks\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3202,"title":"MINIDUMP_SECONDARY_FLAGS enumeration (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","secondary","flags","enumeration","minidumpapiset","specifies","the","for","article02","2024","minisecondarywithoutpowerinfo","value","0x00000001","information","does","not","retrieve","processor","power","contained","misc","info","structure","minisecondaryvalidflags","requirement","header","include","dbghelp","redistributable","dll","later","syntax","typedef","enum","constants","expand","table","requirements","feedback","was"],"errorCode":"","eventId":"","severity":"Low","summary":"Specifies the secondary flags for the minidump.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_SECONDARY_FLAGS enumeration (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_SECONDARY_FLAGS\nenumeration (minidumpapiset.h)\nArticle02/22/2024\nSpecifies the secondary flags for the minidump.\nC++\n \nMiniSecondaryWithoutPowerInfo\nValue: 0x00000001\nThe minidump information does not retrieve the processor power information contained in the\nMINIDUMP_MISC_INFO_2 structure.\nMiniSecondaryValidFlags\nValue: 0x00000001\nRequirement Value\nHeader minidumpapiset.h (include Dbghelp.h)\nRedistributable DbgHelp.dll 6.6 or later\nSyntax\ntypedef enum _MINIDUMP_SECONDARY_FLAGS {\n MiniSecondaryWithoutPowerInfo = 0x00000001,\n MiniSecondaryValidFlags = 0x00000001\n} MINIDUMP_SECONDARY_FLAGS;\nConstants\nﾉ Expand table\nRequirements\nﾉ Expand table\nFeedback\nWas this page helpful?\nMINIDUMP_MISC_INFO_2\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3203,"title":"MINIDUMP_STREAM_TYPE enumeration (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","stream","type","enumeration","minidumpapiset","represents","the","data","article05","2022","syntax","typedef","enum","unusedstream","reservedstream0","reservedstream1","threadliststream","moduleliststream","memoryliststream","exceptionstream","systeminfostream","threadexliststream","memory64liststream","commentstreama","commentstreamw","handledatastream","functiontablestream","unloadedmoduleliststream","miscinfostream","memoryinfoliststream","threadinfoliststream","handleoperationliststream","tokenstream","javascriptdatastream","systemmemoryinfostream","processvmcountersstream","ipttracestream","threadnamesstream","cestreamnull","0x8000"],"errorCode":"","eventId":"","severity":"Low","summary":"Represents the type of a minidump data stream.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_STREAM_TYPE enumeration (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_STREAM_TYPE enumeration\n(minidumpapiset.h)\nArticle05/24/2022\nRepresents the type of a minidump data stream.\nC++\nSyntax\ntypedef enum _MINIDUMP_STREAM_TYPE {\n UnusedStream = 0,\n ReservedStream0 = 1,\n ReservedStream1 = 2,\n ThreadListStream = 3,\n ModuleListStream = 4,\n MemoryListStream = 5,\n ExceptionStream = 6,\n SystemInfoStream = 7,\n ThreadExListStream = 8,\n Memory64ListStream = 9,\n CommentStreamA = 10,\n CommentStreamW = 11,\n HandleDataStream = 12,\n FunctionTableStream = 13,\n UnloadedModuleListStream = 14,\n MiscInfoStream = 15,\n MemoryInfoListStream = 16,\n ThreadInfoListStream = 17,\n HandleOperationListStream = 18,\n TokenStream = 19,\n JavaScriptDataStream = 20,\n SystemMemoryInfoStream = 21,\n ProcessVmCountersStream = 22,\n IptTraceStream = 23,\n ThreadNamesStream = 24,\n ceStreamNull = 0x8000,\n ceStreamSystemInfo = 0x8001,\n ceStreamException = 0x8002,\n ceStreamModuleList = 0x8003,\n ceStreamProcessList = 0x8004,\n ceStreamThreadList = 0x8005,\n ceStreamThreadContextList = 0x8006,\n ceStreamThreadCallStackList = 0x8007,\n ceStreamMemoryVirtualList = 0x8008,\n ceStreamMemoryPhysicalList = 0x8009,\n ceStreamBucketParameters = 0x800A,\n ceStreamProcessModuleMap = 0x800B,\n ceStreamDiagnosisList = 0x800C,\nUnusedStream\nValue: 0\nReserved. Do not use this enumeration value.\nReservedStream0\nValue: 1\nReserved. Do not use this enumeration value.\nReservedStream1\nValue: 2\nReserved. Do not use this enumeration value.\nThreadListStream\nValue: 3\nThe stream contains thread information. For more information, see\nMINIDUMP_THREAD_LIST.\nModuleListStream\nValue: 4\nThe stream contains module information. For more information, see\nMINIDUMP_MODULE_LIST.\nMemoryListStream\nValue: 5\nThe stream contains memory allocation information. For more information, see\nMINIDUMP_MEMORY_LIST.\nExceptionStream\nValue: 6\nThe stream contains exception information. For more information, see\nMINIDUMP_EXCEPTION_STREAM.\nSystemInfoStream\nValue: 7\nThe stream contains general system information. For more information, see\nMINIDUMP_SYSTEM_INFO.\nThreadExListStream\nValue: 8\n LastReservedStream = 0xffff\n} MINIDUMP_STREAM_TYPE;\nConstants\nﾉ Expand table\nThe stream contains extended thread information. For more information, see\nMINIDUMP_THREAD_EX_LIST.\nMemory64ListStream\nValue: 9\nThe stream contains memory allocation information. For more information, see\nMINIDUMP_MEMORY64_LIST.\nCommentStreamA\nValue: 10\nThe stream contains an ANSI string used for documentation purposes.\nCommentStreamW\nValue: 11\nThe stream contains a Unicode string used for documentation purposes.\nHandleDataStream\nValue: 12\nThe stream contains high-level information about the active operating system handles. For more\ninformation, see\nMINIDUMP_HANDLE_DATA_STREAM.\nFunctionTableStream\nValue: 13\nThe stream contains function table information. For more information, see\nMINIDUMP_FUNCTION_TABLE_STREAM.\nUnloadedModuleListStream\nValue: 14\nThe stream contains module information for the unloaded modules. For more information, see\nMINIDUMP_UNLOADED_MODULE_LIST.\nDbgHelp 5.1: This value is not supported.\nMiscInfoStream\nValue: 15\nThe stream contains miscellaneous information. For more information, see\nMINIDUMP_MISC_INFO or MINIDUMP_MISC_INFO_2.\nDbgHelp 5.1: This value is not supported.\nMemoryInfoListStream\nValue: 16\nThe stream contains memory region description information. It corresponds to the information\nthat would be returned for the process from the VirtualQuery function. For more information, see\nMINIDUMP_MEMORY_INFO_LIST.\nDbgHelp 6.1 and earlier: This value is not supported.\nThreadInfoListStream\nValue: 17\nThe stream contains thread state information. For more information, see\nMINIDUMP_THREAD_INFO_LIST.\nDbgHelp 6.1 and earlier: This value is not supported.\nHandleOperationListStream\nValue: 18\nThis stream contains operation list information. For more information, see\nMINIDUMP_HANDLE_OPERATION_LIST.\nDbgHelp 6.4 and earlier: This value is not supported.\nTokenStream\nValue: 19\nJavaScriptDataStream\nValue: 20\nSystemMemoryInfoStream\nValue: 21\nProcessVmCountersStream\nValue: 22\nIptTraceStream\nValue: 23\nThreadNamesStream\nValue: 24\nceStreamNull\nValue: 0x8000\nceStreamSystemInfo\nValue: 0x8001\nceStreamException\nValue: 0x8002\nceStreamModuleList\nValue: 0x8003\nceStreamProcessList\nValue: 0x8004\nceStreamThreadList\nValue: 0x8005\nceStreamThreadContextList\nValue: 0x8006\nceStreamThreadCallStackList\nValue: 0x8007\nceStreamMemoryVirtualList\nValue: 0x8008\nceStreamMemoryPhysicalList\nValue: 0x8009\nceStreamBucketParameters\nValue: 0x800A\nceStreamProcessModuleMap\nValue: 0x800B\nceStreamDiagnosisList\nValue: 0x800C\nLastReservedStream\nValue: 0xffff\nAny value greater than this value will not be used by the system and can be used to represent\napplication-defined data streams. For more information, see\nMINIDUMP_USER_STREAM.\nIn this context, a data stream is a set of data in a minidump file.\nThe StreamType member of the MINIDUMP_DIRECTORY structure can be one of these\ntypes. Additional types may be added in the future, so if a program reading the\nminidump header encounters a stream type it does not recognize, it should ignore the\nstream altogether.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRemarks\nRequirements\nﾉ Expand table\nFeedback\nWas this page helpful?\nRequirement Value\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_DIRECTORY\nMINIDUMP_EXCEPTION_STREAM\nMINIDUMP_FUNCTION_TABLE_STREAM\nMINIDUMP_HANDLE_DATA_STREAM\nMINIDUMP_HANDLE_OPERATION_LIST\nMINIDUMP_MEMORY_INFO_LIST\nMINIDUMP_MEMORY_LIST\nMINIDUMP_MISC_INFO\nMINIDUMP_MODULE_LIST\nMINIDUMP_SYSTEM_INFO\nMINIDUMP_THREAD_EX_LIST\nMINIDUMP_THREAD_INFO_LIST\nMINIDUMP_THREAD_LIST\nMINIDUMP_UNLOADED_MODULE_LIST\nMINIDUMP_USER_STREAM\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3204,"title":"MINIDUMP_TYPE enumeration (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","type","enumeration","minidumpapiset","identifies","the","information","that","will","written","file","minidumpwritedump","function","article01","2022","important","code","has","evolved","greatly","over","years","since","its","inception","many","constants","listed","this","page","were","added","later","and","are","not","available","all","versions","dbghelp"],"errorCode":"","eventId":"","severity":"Low","summary":"Identifies the type of information that will be written to the minidump file by the\nMiniDumpWriteDump function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_TYPE enumeration (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_TYPE enumeration\n(minidumpapiset.h)\nArticle01/31/2022\nIdentifies the type of information that will be written to the minidump file by the\nMiniDumpWriteDump function.\n \nC++\nImportant \nThe minidump code has evolved greatly over the years since its inception. Many of\nthe constants listed on this page were added later and are not available in all\nversions of DbgHelp.dll. Those that did not exist in the original code are labeled\naccordingly along with the version of DbgHelp.dll that they first were implemented\nin. The listed version numbers corresponds to the Debugging Tools For Windows\nreleases and do not apply to copies of DbgHelp.dll that are integrated into\nWindows. See DbgHelp Versions for more details.\nSyntax\ntypedef enum _MINIDUMP_TYPE {\n MiniDumpNormal = 0x00000000,\n MiniDumpWithDataSegs = 0x00000001,\n MiniDumpWithFullMemory = 0x00000002,\n MiniDumpWithHandleData = 0x00000004,\n MiniDumpFilterMemory = 0x00000008,\n MiniDumpScanMemory = 0x00000010,\n MiniDumpWithUnloadedModules = 0x00000020,\n MiniDumpWithIndirectlyReferencedMemory = 0x00000040,\n MiniDumpFilterModulePaths = 0x00000080,\n MiniDumpWithProcessThreadData = 0x00000100,\n MiniDumpWithPrivateReadWriteMemory = 0x00000200,\n MiniDumpWithoutOptionalData = 0x00000400,\n MiniDumpWithFullMemoryInfo = 0x00000800,\n MiniDumpWithThreadInfo = 0x00001000,\n MiniDumpWithCodeSegs = 0x00002000,\n MiniDumpWithoutAuxiliaryState = 0x00004000,\n MiniDumpWithFullAuxiliaryState = 0x00008000,\n MiniDumpWithPrivateWriteCopyMemory = 0x00010000,\n MiniDumpIgnoreInaccessibleMemory = 0x00020000,\n MiniDumpWithTokenInformation = 0x00040000,\n MiniDumpWithModuleHeaders = 0x00080000,\nMiniDumpNormal\nValue: 0x00000000\n0x00000000. Include just the information necessary to capture stack traces for all existing threads\nin a process.\nMiniDumpWithDataSegs\nValue: 0x00000001\n0x00000001. Include the data sections from all loaded modules. This results in the inclusion of\nglobal variables, which\ncan make the minidump file significantly larger. For per-module control, use the\nModuleWriteDataSeg enumeration value from\nMODULE_WRITE_FLAGS.\nMiniDumpWithFullMemory\nValue: 0x00000002\n0x00000002. Include all accessible memory in the process. The raw memory data is included at the\nend, so that the\ninitial structures can be mapped directly without the raw memory information. This option can\nresult in a very\nlarge file.\nMiniDumpWithHandleData\nValue: 0x00000004\n0x00000004. Include high-level information about the operating system handles that are active\nwhen the minidump is\nmade.\nMiniDumpFilterMemory\nValue: 0x00000008\n0x00000008. Stack and backing store memory written to the minidump file should be filtered to\nremove all but the\npointer values necessary to reconstruct a stack trace.\n MiniDumpFilterTriage = 0x00100000,\n MiniDumpWithAvxXStateContext = 0x00200000,\n MiniDumpWithIptTrace = 0x00400000,\n MiniDumpScanInaccessiblePartialPages = 0x00800000,\n MiniDumpFilterWriteCombinedMemory,\n MiniDumpValidTypeFlags = 0x01ffffff\n} MINIDUMP_TYPE;\nConstants\nﾉ Expand table\nMiniDumpScanMemory\nValue: 0x00000010\n0x00000010. Stack and backing store memory should be scanned for pointer references to\nmodules in the module list. If a\nmodule is referenced by stack or backing store memory, the ModuleWriteFlags member of\nthe MINIDUMP_CALLBACK_OUTPUT structure is\nset to ModuleReferencedByMemory.\nMiniDumpWithUnloadedModules\nValue: 0x00000020\n0x00000020. Include information from the list of modules that were recently unloaded, if this\ninformation is maintained\nby the operating system.\nWindows Server 2003 and Windows XP: The operating system does not maintain information\nfor unloaded modules until\nWindows Server 2003 with SP1 and Windows XP with SP2.\nDbgHelp 5.1: This value is not supported.\nMiniDumpWithIndirectlyReferencedMemory\nValue: 0x00000040\n0x00000040. Include pages with data referenced by locals or other stack memory. This option can\nincrease the size of\nthe minidump file significantly.\nDbgHelp 5.1: This value is not supported.\nMiniDumpFilterModulePaths\nValue: 0x00000080\n0x00000080. Filter module paths for information such as user names or important directories. This\noption may prevent\nthe system from locating the image file and should be used only in special situations.\nDbgHelp 5.1: This value is not supported.\nMiniDumpWithProcessThreadData\nValue: 0x00000100\n0x00000100. Include complete per-process and per-thread information from the operating system.\nDbgHelp 5.1: This value is not supported.\nMiniDumpWithPrivateReadWriteMemory\nValue: 0x00000200\n0x00000200. Scan the virtual address space for PAGE_READWRITE memory to be included.\nDbgHelp 5.1: This value is not supported.\nMiniDumpWithoutOptionalData\nValue: 0x00000400\n0x00000400. Reduce the data that is dumped by eliminating memory regions that are not essential\nto meet criteria\nspecified for the dump. This can avoid dumping memory that may contain data that is private to\nthe user.\nHowever, it is not a guarantee that no private information will be present.\nDbgHelp 6.1 and earlier: This value is not supported.\nMiniDumpWithFullMemoryInfo\nValue: 0x00000800\n0x00000800. Include memory region information. For more information, see\nMINIDUMP_MEMORY_INFO_LIST.\nDbgHelp 6.1 and earlier: This value is not supported.\nMiniDumpWithThreadInfo\nValue: 0x00001000\n0x00001000. Include thread state information. For more information, see\nMINIDUMP_THREAD_INFO_LIST.\nDbgHelp 6.1 and earlier: This value is not supported.\nMiniDumpWithCodeSegs\nValue: 0x00002000\n0x00002000. Include all code and code-related sections from loaded modules to capture\nexecutable content. For\nper-module control, use the ModuleWriteCodeSegs enumeration value from\nMODULE_WRITE_FLAGS.\nDbgHelp 6.1 and earlier: This value is not supported.\nMiniDumpWithoutAuxiliaryState\nValue: 0x00004000\n0x00004000. Turns off secondary auxiliary-supported memory gathering.\nMiniDumpWithFullAuxiliaryState\nValue: 0x00008000\n0x00008000. Requests that auxiliary data providers include their state in the dump image; the state\ndata that is\n","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3205,"title":"MODULE_WRITE_FLAGS enumeration (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["module","write","flags","enumeration","minidumpapiset","identifies","the","type","information","that","will","written","minidump","file","minidumpwritedump","function","article02","2024","modulewritemodule","value","0x0001","only","modulewritedataseg","0x0002","and","data","segment","this","set","minidumpwithdatasegs","from","modulewritemiscrecord","0x0004","miscellaneous","record","modulewritecvrecord","0x0008","syntax","typedef","enum"],"errorCode":"","eventId":"","severity":"Low","summary":"Identifies the type of module information that will be written to the minidump file by the\nMiniDumpWriteDump function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MODULE_WRITE_FLAGS enumeration (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MODULE_WRITE_FLAGS enumeration\n(minidumpapiset.h)\nArticle02/22/2024\nIdentifies the type of module information that will be written to the minidump file by the\nMiniDumpWriteDump function.\nC++\n \nModuleWriteModule\nValue: 0x0001\nOnly module information will be written to the minidump file.\nModuleWriteDataSeg\nValue: 0x0002\nModule and data segment information will be written to the minidump file. This value will only be\nset if the MiniDumpWithDataSegs enumeration value from MINIDUMP_TYPE is set.\nModuleWriteMiscRecord\nValue: 0x0004\nModule, data segment, and miscellaneous record information will be written to the minidump file.\nModuleWriteCvRecord\nValue: 0x0008\nSyntax\ntypedef enum _MODULE_WRITE_FLAGS {\n ModuleWriteModule = 0x0001,\n ModuleWriteDataSeg = 0x0002,\n ModuleWriteMiscRecord = 0x0004,\n ModuleWriteCvRecord = 0x0008,\n ModuleReferencedByMemory = 0x0010,\n ModuleWriteTlsData = 0x0020,\n ModuleWriteCodeSegs = 0x0040\n} MODULE_WRITE_FLAGS;\nConstants\nﾉ Expand table\nFeedback\n \nCodeView information will be written to the minidump file. Some debuggers need the CodeView\ninformation to properly locate symbols.\nModuleReferencedByMemory\nValue: 0x0010\nIndicates that a module was referenced by a pointer on the stack or backing store of a thread in\nthe minidump. This value is valid only if the DumpType parameter of the\nMiniDumpWriteDump function includes MiniDumpScanMemory.\nModuleWriteTlsData\nValue: 0x0020\nPer-module automatic TLS data is written to the minidump file. (Note that automatic TLS data is\ncreated using __declspec(thread) while TlsAlloc creates dynamic TLS data). This value is valid only\nif the DumpType parameter of the\nMiniDumpWriteDump function includes MiniDumpWithProcessThreadData.\nDbgHelp 6.1 and earlier: This value is not supported.\nModuleWriteCodeSegs\nValue: 0x0040\nCode segment information will be written to the minidump file. This value will only be set if the\nMiniDumpWithCodeSegs enumeration value from MINIDUMP_TYPE is set.\nDbgHelp 6.1 and earlier: This value is not supported.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_CALLBACK_OUTPUT\nMiniDumpWriteDump\nRequirements\nﾉ Expand table\nSee also\nWas this page helpful? Yes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3206,"title":"THREAD_WRITE_FLAGS enumeration (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["thread","write","flags","enumeration","minidumpapiset","identifies","the","type","information","that","will","written","minidump","file","minidumpwritedump","function","article01","2022","threadwritethread","value","0x0001","only","basic","threadwritestack","0x0002","and","stack","threadwritecontext","0x0004","entire","context","threadwritebackingstore","0x0008","intel","itanium","backing","store","memory","every","syntax"],"errorCode":"","eventId":"","severity":"Low","summary":"Identifies the type of thread information that will be written to the minidump file by the\nMiniDumpWriteDump function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to THREAD_WRITE_FLAGS enumeration (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"THREAD_WRITE_FLAGS enumeration\n(minidumpapiset.h)\nArticle01/31/2022\nIdentifies the type of thread information that will be written to the minidump file by the\nMiniDumpWriteDump function.\nC++\n \nThreadWriteThread\nValue: 0x0001\nOnly basic thread information will be written to the minidump file.\nThreadWriteStack\nValue: 0x0002\nBasic thread and thread stack information will be written to the minidump file.\nThreadWriteContext\nValue: 0x0004\nThe entire thread context will be written to the minidump file.\nThreadWriteBackingStore\nValue: 0x0008\nIntel Itanium: The backing store memory of every thread will be written to the minidump file.\nSyntax\ntypedef enum _THREAD_WRITE_FLAGS {\n ThreadWriteThread = 0x0001,\n ThreadWriteStack = 0x0002,\n ThreadWriteContext = 0x0004,\n ThreadWriteBackingStore = 0x0008,\n ThreadWriteInstructionWindow = 0x0010,\n ThreadWriteThreadData = 0x0020,\n ThreadWriteThreadInfo = 0x0040\n} THREAD_WRITE_FLAGS;\nConstants\nﾉ Expand table\nFeedback\nWas this page helpful?\n \nThreadWriteInstructionWindow\nValue: 0x0010\nA small amount of memory surrounding each thread's instruction pointer will be written to the\nminidump file. This allows instructions near a thread's instruction pointer to be disassembled even\nif an executable image matching the module cannot be found.\nThreadWriteThreadData\nValue: 0x0020\nWhen the minidump type includes MiniDumpWithProcessThreadData, this flag is set. The\ncallback function can clear this flag to control which threads provide complete thread data in the\nminidump file.\nDbgHelp 5.1: This value is not supported.\nThreadWriteThreadInfo\nValue: 0x0040\nWhen the minidump type includes MiniDumpWithThreadInfo, this flag is set. The callback\nfunction can clear this flag to control which threads provide thread state information in the\nminidump file. For more information, see MINIDUMP_THREAD_INFO.\nDbgHelp 6.1 and earlier: This value is not supported.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_CALLBACK_OUTPUT\nMiniDumpWriteDump\nRequirements\nﾉ Expand table\nSee also\nYes No\nDbgHelp Functions\nThe following are the DbgHelp functions.\nThe following are general helper functions:\nEnumDirTree\nImagehlpApiVersion\nImagehlpApiVersionEx\nMakeSureDirectoryPathExists\nSearchTreeForFile\nThe debugging service functions are the functions most suited for use by a debugger or the\ndebugging code in an application. These functions can be used in concert with the symbol\nhandler functions for easier use.\nEnumerateLoadedModules64\nEnumerateLoadedModulesEx\nFindDebugInfoFile\nFindDebugInfoFileEx\nFindExecutableImage\nFindExecutableImageEx\nStackWalk64\nSymSetParentWindow\nUnDecorateSymbolName\nThe image access functions access the data in an executable image. The functions provide\nhigh-level access to the base of images and very specific access to the most common parts of\nan image's data.\nGetTimestampForLoadedLibrary\nImageDirectoryEntryToData\nImageDirectoryEntryToDataEx\nImageNtHeader\nGeneral\nDebugger\nImage Access\nImageRvaToSection\nImageRvaToVa\nThe symbol handler functions give applications easy and portable access to the symbolic\ndebugging information of an image. These functions should be used exclusively to ensure\naccess to symbolic information. This is necessary because these functions isolate the\napplication from the symbol format.\nSymAddSourceStream\nSymAddSymbol\nSymCleanup\nSymDeleteSymbol\nSymEnumerateModules64\nSymEnumLines\nSymEnumProcesses\nSymEnumSourceFiles\nSymEnumSourceLines\nSymEnumSymbols\nSymEnumSymbolsForAddr\nSymEnumTypes\nSymEnumTypesByName\nSymFindDebugInfoFile\nSymFindExecutableImage\nSymFindFileInPath\nSymFromAddr\nSymFromIndex\nSymFromName\nSymFromToken\nSymFunctionTableAccess64\nSymGetFileLineOffsets64\nSymGetHomeDirectory\nSymGetLineFromAddr64\nSymGetLineFromName64\nSymGetLineNext64\nSymGetLinePrev64\nSymGetModuleBase64\nSymGetModuleInfo64\nSymGetOmaps\nSymGetOptions\nSymbol Handler\nSymGetScope\nSymGetSearchPath\nSymGetSymbolFile\nSymGetTypeFromName\nSymGetTypeInfo\nSymGetTypeInfoEx\nSymInitialize\nSymLoadModule64\nSymLoadModuleEx\nSymMatchFileName\nSymMatchString\nSymNext\nSymPrev\nSymRefreshModuleList\nSymRegisterCallback64\nSymRegisterFunctionEntryCallback64\nSymSearch\nSymSetContext\nSymSetHomeDirectory\nSymSetOptions\nSymSetScopeFromAddr\nSymSetScopeFromIndex\nSymSetSearchPath\nSymUnDName64\nSymUnloadModule64\nThe symbol server enables debuggers to automatically retrieve the correct symbol files without\nproduct names, releases, or build numbers. The following functions are used with the symbol\nserver.\nSymSrvDeltaName\nSymSrvGetFileIndexes\nSymSrvGetFileIndexInfo\nSymSrvGetFileIndexString\nSymSrvGetSupplement\nSymSrvIsStore\nSymSrvStoreFile\nSymSrvStoreSupplement\nSymbol Server\nThe minidump functions provide a way for applications to produce crashdump files that\ncontain a useful subset of the entire process context; this is known as a minidump file. The\nfollowing functions are used with minidump files.\nMiniDumpCallback\nMiniDumpReadDumpStream\nMiniDumpWriteDump\nSource server enables a client to retrieve the exact version of the source files that were used to\nbuild an application. The following functions are used with source server.\nSymGetSourceFile\nSymEnumSourceFileTokens\nSymEnumSourceFileTokensProc\nSymGetSourceFileFromToken\nSymGetSourceFileToken\nSymGetSourceVarFromToken\nMapDebugInformation\nSymEnumerateSymbols64\nSymGetSymFromAddr64\nSymGetSymFromName64\nSymGetSymNext64\nSymGetSymPrev64\nUnMapDebugInformation\n \n \nLast updated on 07/14/2025\nUser-mode Minidump Files\nSource Server\nObsolete Functions","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3207,"title":"EnumDirTree function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["enumdirtree","function","dbghelp","enumerates","all","occurrences","the","specified","file","directory","tree","article08","2022","optional","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","rootpath","path","where","should","begin","searching","for","inputpathname","name","found","you","can","specify","partial","out","outputpathbuffer"],"errorCode":"","eventId":"","severity":"Low","summary":"Enumerates all occurrences of the specified file in the specified directory tree.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to EnumDirTree function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"EnumDirTree function (dbghelp.h)\nArticle08/09/2022\nEnumerates all occurrences of the specified file in the specified directory tree.\nC++\n[in, optional] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] RootPath\nThe path where the function should begin searching for the file.\n[in] InputPathName\nThe name of the file to be found. You can specify a partial path.\n[out, optional] OutputPathBuffer\nA pointer to a buffer that receives the full path of the file. If the function fails or does not find a\nmatching file, this buffer will still contain the last full path that was found.\nThis parameter is optional and can be NULL.\n[in, optional] cb\nAn application-defined callback function, or NULL. For more information, see EnumDirTreeProc.\n[in, optional] data\nSyntax\nBOOL IMAGEAPI EnumDirTree(\n [in, optional] HANDLE hProcess,\n [in] PCSTR RootPath,\n [in] PCSTR InputPathName,\n [out, optional] PSTR OutputPathBuffer,\n [in, optional] PENUMDIRTREE_CALLBACK cb,\n [in, optional] PVOID data\n);\nParameters\nThe user-defined data or NULL. This value is passed to the callback function.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe search can be canceled if you register a SymRegisterCallbackProc64 callback function. For\nevery file operation, EnumDirTree calls this callback function with\nCBA_DEFERRED_SYMBOL_LOAD_CANCEL. If the callback function returns TRUE, EnumDirTree\ncancels the search.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.0 or later\nDbgHelp Functions\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nSee also\nEnumDirTreeProc","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3208,"title":"PENUMDIRTREE_CALLBACK callback function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["penumdirtree","callback","function","dbghelp","application","defined","used","with","the","enumdirtree","article02","2024","called","every","time","match","found","and","callbackw","types","define","pointer","this","enumdirtreeproc","placeholder","for","name","filepath","buffer","that","receives","full","path","file","optional","callerdata","user","value","specified","null"],"errorCode":"","eventId":"","severity":"Low","summary":"An application-defined callback function used with the EnumDirTree function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to PENUMDIRTREE_CALLBACK callback function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"PENUMDIRTREE_CALLBACK callback\nfunction (dbghelp.h)\nArticle02/22/2024\nAn application-defined callback function used with the EnumDirTree function. It is called every\ntime a match is found.\nThe PENUMDIRTREE_CALLBACK and PENUMDIRTREE_CALLBACKW types define a pointer to\nthis callback function. EnumDirTreeProc is a placeholder for the application-defined function\nname.\nC++\n[in] FilePath\nA pointer to a buffer that receives the full path of the file that is found.\n[in, optional] CallerData\nA user-defined value specified in EnumDirTree, or NULL. Typically, this parameter is used by an\napplication to pass a pointer to a data structure that enables the callback function to establish\nsome context.\nTo continue enumeration, the callback function must return FALSE.\nTo stop enumeration, the callback function must return TRUE.\nSyntax\nPENUMDIRTREE_CALLBACK PenumdirtreeCallback;\nBOOL PenumdirtreeCallback(\n [in] PCSTR FilePath,\n [in, optional] PVOID CallerData\n)\n{...}\nParameters\nReturn value\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nRedistributable DbgHelp.dll 6.0 or later\nDbgHelp Functions\nEnumDirTree\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3209,"title":"EnumerateLoadedModules function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["enumerateloadedmodules","function","dbghelp","enumerates","the","loaded","modules","for","specified","process","article02","2024","hprocess","handle","whose","will","enumerated","enumloadedmodulescallback","application","defined","callback","more","information","see","enumerateloadedmodulesproc64","optional","usercontext","user","data","this","value","passed","succeeds","return","true","fails","false","retrieve","extended","error"],"errorCode":"","eventId":"","severity":"Low","summary":"Enumerates the loaded modules for the specified process.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to EnumerateLoadedModules function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"EnumerateLoadedModules function\n(dbghelp.h)\nArticle02/22/2024\nEnumerates the loaded modules for the specified process.\nC++\n[in] hProcess\nA handle to the process whose modules will be enumerated.\n[in] EnumLoadedModulesCallback\nAn application-defined callback function. For more information, see\nEnumerateLoadedModulesProc64.\n[in, optional] UserContext\nOptional user-defined data. This value is passed to the callback function.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nSyntax\nBOOL IMAGEAPI EnumerateLoadedModules(\n [in] HANDLE hProcess,\n [in] PENUMLOADED_MODULES_CALLBACK EnumLoadedModulesCallback,\n [in, optional] PVOID UserContext\n);\nParameters\nReturn value\nRemarks\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, EnumerateLoadedModulesW64, define\nDBGHELP_TRANSLATE_TCHAR. EnumerateLoadedModulesW64 is defined as follows in\nDbgHelp.h.\nC++\nThis function supersedes the EnumerateLoadedModules function. For more information, see\nUpdated Platform Support. EnumerateLoadedModules is defined as follows in DbgHelp.h.\nC++\nBOOL\nIMAGEAPI\nEnumerateLoadedModulesW64(\n __in HANDLE hProcess,\n __in PENUMLOADED_MODULES_CALLBACKW64 EnumLoadedModulesCallback,\n __in PVOID UserContext\n );\n#ifdef DBGHELP_TRANSLATE_TCHAR\n #define EnumerateLoadedModules64 EnumerateLoadedModulesW64\n#endif\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define EnumerateLoadedModules EnumerateLoadedModules64\n#else\nBOOL\nIMAGEAPI\nEnumerateLoadedModules(\n __in HANDLE hProcess,\n __in PENUMLOADED_MODULES_CALLBACK EnumLoadedModulesCallback,\n __in_opt PVOID UserContext\n );\n#endif\nRequirements\nﾉ Expand table\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nEnumerateLoadedModulesProc64\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3210,"title":"EnumerateLoadedModulesEx function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["enumerateloadedmodulesex","function","dbghelp","enumerates","the","loaded","modules","for","specified","process","article02","2024","hprocess","handle","whose","will","enumerated","enumloadedmodulescallback","application","defined","callback","more","information","see","enumerateloadedmodulesproc64","optional","usercontext","user","data","this","value","passed","succeeds","return","true","fails","false","retrieve","extended","error"],"errorCode":"","eventId":"","severity":"Low","summary":"Enumerates the loaded modules for the specified process.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to EnumerateLoadedModulesEx function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"EnumerateLoadedModulesEx function\n(dbghelp.h)\nArticle02/22/2024\nEnumerates the loaded modules for the specified process.\nC++\n[in] hProcess\nA handle to the process whose modules will be enumerated.\n[in] EnumLoadedModulesCallback\nAn application-defined callback function. For more information, see\nEnumerateLoadedModulesProc64.\n[in, optional] UserContext\nOptional user-defined data. This value is passed to the callback function.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nSyntax\nBOOL IMAGEAPI EnumerateLoadedModulesEx(\n [in] HANDLE hProcess,\n [in] PENUMLOADED_MODULES_CALLBACK64 EnumLoadedModulesCallback,\n [in, optional] PVOID UserContext\n);\nParameters\nReturn value\nRemarks\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.8 or later\nDbgHelp Functions\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3211,"title":"PENUMLOADED_MODULES_CALLBACK callback function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["penumloaded","modules","callback","function","dbghelp","application","defined","used","with","the","enumerateloadedmodules64","article02","2024","callback64","and","callbackw64","types","define","pointer","this","enumerateloadedmodulesproc64","placeholder","for","name","modulename","enumerated","module","modulebase","base","address","note","that","possible","become","invalid","example","may","unloaded","use","exception"],"errorCode":"","eventId":"","severity":"Low","summary":"An application-defined callback function used with the EnumerateLoadedModules64 function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to PENUMLOADED_MODULES_CALLBACK callback function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"PENUMLOADED_MODULES_CALLBACK\ncallback function (dbghelp.h)\nArticle02/22/2024\nAn application-defined callback function used with the EnumerateLoadedModules64 function.\nThe PENUMLOADED_MODULES_CALLBACK64 and\nPENUMLOADED_MODULES_CALLBACKW64 types define a pointer to this callback function.\nEnumerateLoadedModulesProc64 is a placeholder for the application-defined function name.\nC++\n[in] ModuleName\nThe name of the enumerated module.\n[in] ModuleBase\nThe base address of the module. Note that it is possible for this address to become invalid (for\nexample, the module may be unloaded). Use exception handling when accessing the address\nor passing the address to another function to prevent an access violation from occurring.\n[in] ModuleSize\nThe size of the module, in bytes.\n[in, optional] UserContext\nOptional user-defined data. This value is passed from EnumerateLoadedModules64.\nSyntax\nPENUMLOADED_MODULES_CALLBACK PenumloadedModulesCallback;\nBOOL PenumloadedModulesCallback(\n [in] PCSTR ModuleName,\n [in] ULONG ModuleBase,\n [in] ULONG ModuleSize,\n [in, optional] PVOID UserContext\n)\n{...}\nParameters\nTo continue enumeration, the callback function must return TRUE.\nTo stop enumeration, the callback function must return FALSE.\nThis callback function supersedes the PENUMLOADED_MODULES_CALLBACK callback function.\nPENUMLOADED_MODULES_CALLBACK is defined as follows in DbgHelp.h.\nC++\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nEnumerateLoadedModules64\nReturn value\nRemarks\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define PENUMLOADED_MODULES_CALLBACK PENUMLOADED_MODULES_CALLBACK64\n#else\ntypedef BOOL (CALLBACK *PENUMLOADED_MODULES_CALLBACK)(\n __in PCSTR ModuleName,\n __in ULONG ModuleBase,\n __in ULONG ModuleSize,\n __in_opt PVOID UserContext\n );\n#endif\nRequirements\nﾉ Expand table\nSee also\nFindDebugInfoFile function (dbghelp.h)\nLocates a debug (.dbg) file.\nTo provide a callback function to verify the symbol file located, use the FindDebugInfoFileEx\nfunction.\nC++\n[in] FileName\nThe name of the .dbg file that is desired. You can use a partial path.\n[in] SymbolPath\nThe path where symbol files are located. This can be multiple paths separated by semicolons. To\nretrieve the symbol path, use the SymGetSearchPath function.\n[out] DebugFilePath\nA pointer to a buffer that receives the full path of the .dbg file. This buffer must be at least\nMAX_PATH+1 characters.\nIf the function succeeds, the return value is an open handle to the .dbg file.\nIf the function fails, the return value is NULL. To retrieve extended error information, call\nGetLastError.\nSyntax\nHANDLE IMAGEAPI FindDebugInfoFile(\n [in] PCSTR FileName,\n [in] PCSTR SymbolPath,\n [out] PSTR DebugFilePath\n);\nParameters\nReturn value\nRemarks\nThe FindDebugInfoFile function is used to locate a .dbg file. This function is provided so the\nsearch can be conducted in several different directories through a single function call. The\nSymbolPath parameter can contain multiple paths, with each separated by a semicolon (;). When\nmultiple paths are specified, the function searches each directory for the file. Subdirectories are\nnot searched. When the file is located, the search stops. Thus, be sure to specify SymbolPath with\nthe paths in the correct order.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than one\nthread to this function will likely result in unexpected behavior or memory corruption. To avoid\nthis, you must synchronize all concurrent calls from more than one thread to this function.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nFindDebugInfoFileEx\nSymGetSearchPath\nLast updated on 02/22/2024\nRequirements\nﾉ Expand table\nSee also\nFindDebugInfoFileEx function (dbghelp.h)\nLocates the specified debug (.dbg) file.\nC++\n[in] FileName\nThe name of the .dbg file to locate. You can use a partial path.\n[in] SymbolPath\nThe path where symbol files are located. This can be multiple paths separated by semicolons. To\nretrieve the symbol path, use the SymGetSearchPath function.\n[out] DebugFilePath\nA pointer to a buffer that receives the full path of the .dbg file. This buffer must be at least\nMAX_PATH+1 characters.\n[in, optional] Callback\nAn application-defined callback function that verifies whether the correct file was found or the\nfunction should continue its search. For more information, see FindDebugInfoFileProc.\nThis parameter may be NULL.\n[in, optional] CallerData\nOptional user-defined data to pass to the callback function.\nSyntax\nHANDLE IMAGEAPI FindDebugInfoFileEx(\n [in] PCSTR FileName,\n [in] PCSTR SymbolPath,\n [out] PSTR DebugFilePath,\n [in, optional] PFIND_DEBUG_FILE_CALLBACK Callback,\n [in, optional] PVOID CallerData\n);\nParameters\nIf the function succeeds, the return value is an open handle to the .dbg file.\nIf the function fails, the return value is NULL. To retrieve extended error information, call\nGetLastError.\nThe FindDebugInfoFileEx function is used to locate a .dbg file. This function is provided so the\nsearch can be conducted in several different directories through a single function call. The\nSymbolPath parameter can contain multiple paths, with each separated by a semicolon (;). When\nmultiple paths are specified, the function searches each specified directory for the file. When the\nfile is located, the search stops. Thus, be sure to specify SymbolPath with the paths in the correct\norder.\nIf the file name specified does not include a .dbg extension, FindDebugInfoFileEx searches for\nthe file in the following sequence:\n1. SymbolPath\\Symbols\\ext\\filename.dbg\n2. SymbolPath\\ext\\filename.dbg\n3. SymbolPath\\filename.dbg\n4. FileNamePath\\filename.dbg\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than one\nthread to this function will likely result in unexpected behavior or memory corruption. To avoid\nthis, y","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3212,"title":"PFIND_DEBUG_FILE_CALLBACK callback function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["pfind","debug","file","callback","function","dbghelp","application","defined","used","with","the","finddebuginfofileex","article02","2024","verifies","whether","symbol","located","correct","and","callbackw","types","define","pointer","this","finddebuginfofileproc","placeholder","for","applicationdefined","name","filehandle","handle","filename","callerdata","optional","user","data","parameter","can","null"],"errorCode":"","eventId":"","severity":"Low","summary":"An application-defined callback function used with the FindDebugInfoFileEx function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to PFIND_DEBUG_FILE_CALLBACK callback function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"PFIND_DEBUG_FILE_CALLBACK callback\nfunction (dbghelp.h)\nArticle02/22/2024\nAn application-defined callback function used with the FindDebugInfoFileEx function. It verifies\nwhether the symbol file located by FindDebugInfoFileEx is the correct symbol file.\nThe PFIND_DEBUG_FILE_CALLBACK and PFIND_DEBUG_FILE_CALLBACKW types define a\npointer to this callback function. FindDebugInfoFileProc is a placeholder for the applicationdefined function name.\nC++\n[in] FileHandle\nA handle to the symbol file.\n[in] FileName\nThe name of the symbol file.\n[in] CallerData\nOptional user-defined data. This parameter can be NULL.\nIf the symbol file is valid, return TRUE. Otherwise, return FALSE.\nSyntax\nPFIND_DEBUG_FILE_CALLBACK PfindDebugFileCallback;\nBOOL PfindDebugFileCallback(\n [in] HANDLE FileHandle,\n [in] PCSTR FileName,\n [in] PVOID CallerData\n)\n{...}\nParameters\nReturn value\nOne way to verify the symbol file is to compare its timestamp to the timestamp in the image.\nTo retrieve the timestamp of the image, use the GetTimestampForLoadedLibrary function. To\nretrieve the timestamp of the symbol file, use the SymGetModuleInfo64 function.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nFindDebugInfoFileEx\nGetTimestampForLoadedLibrary\nSymGetModuleInfo64\nRemarks\nRequirements\nﾉ Expand table\nSee also\nFindExecutableImage function (dbghelp.h)\nLocates an executable file.\nTo specify a callback function, use the FindExecutableImageEx function.\nC++\n[in] FileName\nThe name of the symbol file to be located. This parameter can be a partial path.\n[in] SymbolPath\nThe path where symbol files are located. This can be multiple paths separated by semicolons. To\nretrieve the symbol path, use the SymGetSearchPath function.\n[out] ImageFilePath\nA pointer to a buffer that receives the full path of the executable file. This buffer must be at least\nMAX_PATH+1 characters.\nIf the function succeeds, the return value is an open handle to the executable file.\nIf the function fails, the return value is NULL. To retrieve extended error information, call\nGetLastError.\nSyntax\nHANDLE IMAGEAPI FindExecutableImage(\n [in] PCSTR FileName,\n [in] PCSTR SymbolPath,\n [out] PSTR ImageFilePath\n);\nParameters\nReturn value\nRemarks\nThe FindExecutableImage function is provided so executable files can be located in several\ndifferent directories through a single function call. The SymbolPath parameter can contain\nmultiple paths, with each separated by a semicolon (;). When multiple paths are specified, the\nfunction searches each directory tree for the executable file. When the file is located, the search\nstops. Thus, be sure to specify SymbolPath with the paths in the correct order.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than one\nthread to this function will likely result in unexpected behavior or memory corruption. To avoid\nthis, you must synchronize all concurrent calls from more than one thread to this function.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nFindExecutableImageEx\nSymGetSearchPath\nLast updated on 05/15/2026\nRequirements\nﾉ Expand table\nSee also\nFindExecutableImageEx function\n(dbghelp.h)\nLocates the specified executable file.\nC++\n[in] FileName\nThe name of the symbol file to be located. This parameter can be a partial path.\n[in] SymbolPath\nThe path where symbol files are located. This string can contain multiple paths separated by\nsemicolons. To retrieve the symbol path, use the SymGetSearchPath function.\n[out] ImageFilePath\nA pointer to a buffer that receives the full path of the executable file. This buffer must be at least\nMAX_PATH+1 characters.\n[in, optional] Callback\nAn application-defined callback function that verifies whether the correct executable file was\nfound, or whether the function should continue its search. For more information, see\nFindExecutableImageProc.\nThis parameter can be NULL.\nSyntax\nHANDLE IMAGEAPI FindExecutableImageEx(\n [in] PCSTR FileName,\n [in] PCSTR SymbolPath,\n [out] PSTR ImageFilePath,\n [in, optional] PFIND_EXE_FILE_CALLBACK Callback,\n [in, optional] PVOID CallerData\n);\nParameters\n[in, optional] CallerData\nOptional user-defined data for the callback function. This parameter can be NULL.\nIf the function succeeds, the return value is an open handle to the executable file.\nIf the function fails, the return value is NULL. To retrieve extended error information, call\nGetLastError.\nThe FindExecutableImageEx function is provided so executable files can be found in several\ndifferent directories by using a single function call. If the SymbolPath parameter contains multiple\npaths, the function searches each specified directory tree for the executable file. When the file is\nfound, the search stops. Thus, be sure to specify SymbolPath with the paths in the correct order.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than one\nthread to this function will likely result in unexpected behavior or memory corruption. To avoid\nthis, you must synchronize all concurrent calls from more than one thread to this function.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nSee also\nFindExecutableImageProc\nSymGetSearchPath\nLast updated on 05/15/2026","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3213,"title":"PFIND_EXE_FILE_CALLBACK callback function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["pfind","exe","file","callback","function","dbghelp","application","defined","used","with","the","findexecutableimageex","article08","2022","verifies","whether","executable","found","correct","and","callbackw","types","define","pointer","this","findexecutableimageproc","placeholder","for","name","filehandle","handle","filename","callerdata","optional","user","data","parameter","can","null","valid"],"errorCode":"","eventId":"","severity":"Low","summary":"An application-defined callback function used with the FindExecutableImageEx function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to PFIND_EXE_FILE_CALLBACK callback function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"PFIND_EXE_FILE_CALLBACK callback\nfunction (dbghelp.h)\nArticle08/09/2022\nAn application-defined callback function used with the FindExecutableImageEx function. It\nverifies whether the executable file found by FindExecutableImageEx is the correct executable\nfile.\nThe PFIND_EXE_FILE_CALLBACK and PFIND_EXE_FILE_CALLBACKW types define a pointer to\nthis callback function. FindExecutableImageProc is a placeholder for the application-defined\nfunction name.\nC++\n[in] FileHandle\nA handle to the executable file.\n[in] FileName\nThe name of the executable file.\n[in] CallerData\nOptional user-defined data. This parameter can be NULL.\nIf the executable file is valid, return TRUE. Otherwise, return FALSE.\nSyntax\nPFIND_EXE_FILE_CALLBACK PfindExeFileCallback;\nBOOL PfindExeFileCallback(\n [in] HANDLE FileHandle,\n [in] PCSTR FileName,\n [in] PVOID CallerData\n)\n{...}\nParameters\nReturn value\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nFindExecutableImageEx\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3214,"title":"PFUNCTION_TABLE_ACCESS_ROUTINE callback function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["pfunction","table","access","routine","callback","function","dbghelp","application","defined","used","with","the","stackwalk64","article02","2024","provides","run","time","for","process","routine64","type","defines","pointer","this","functiontableaccessproc64","placeholder","name","hprocess","handle","which","stack","trace","generated","addrbase","address","instruction","located","returns","x86"],"errorCode":"","eventId":"","severity":"Low","summary":"An application-defined callback function used with the StackWalk64 function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to PFUNCTION_TABLE_ACCESS_ROUTINE callback function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"PFUNCTION_TABLE_ACCESS_ROUTINE\ncallback function (dbghelp.h)\nArticle02/22/2024\nAn application-defined callback function used with the StackWalk64 function. It provides access\nto the run-time function table for the process.\nThe PFUNCTION_TABLE_ACCESS_ROUTINE64 type defines a pointer to this callback function.\nFunctionTableAccessProc64 is a placeholder for the application-defined function name.\nC++\n[in] hProcess\nA handle to the process for which the stack trace is generated.\n[in] AddrBase\nThe address of the instruction to be located.\nThe function returns a pointer to the run-time function table. On an x86 computer, this is a\npointer to an FPO_DATA structure. On an Alpha computer, this is a pointer to an\nIMAGE_FUNCTION_ENTRY structure.\nSyntax\nPFUNCTION_TABLE_ACCESS_ROUTINE PfunctionTableAccessRoutine;\nPVOID PfunctionTableAccessRoutine(\n [in] HANDLE hProcess,\n [in] DWORD AddrBase\n)\n{...}\nParameters\nReturn value\nRemarks\nThis callback function supersedes the PFUNCTION_TABLE_ACCESS_ROUTINE callback function.\nPFUNCTION_TABLE_ACCESS_ROUTINE is defined as follows in DbgHelp.h.\nC++\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nFPO_DATA\nIMAGE_FUNCTION_ENTRY\nStackWalk64\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define PFUNCTION_TABLE_ACCESS_ROUTINE PFUNCTION_TABLE_ACCESS_ROUTINE64\n#else\ntypedef\nPVOID\n(__stdcall *PFUNCTION_TABLE_ACCESS_ROUTINE)(\n __in HANDLE hProcess,\n __in DWORD AddrBase\n );\n#endif\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3215,"title":"PGET_MODULE_BASE_ROUTINE callback function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["pget","module","base","routine","callback","function","dbghelp","application","defined","used","with","the","stackwalk64","article08","2022","called","when","needs","address","for","given","virtual","routine64","type","defines","pointer","this","getmodulebaseproc64","placeholder","name","hprocess","handle","process","which","stack","trace","generated","within","image","located"],"errorCode":"","eventId":"","severity":"Low","summary":"An application-defined callback function used with the StackWalk64 function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to PGET_MODULE_BASE_ROUTINE callback function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"PGET_MODULE_BASE_ROUTINE callback\nfunction (dbghelp.h)\nArticle08/09/2022\nAn application-defined callback function used with the StackWalk64 function. It is called when\nStackWalk64 needs a module base address for a given virtual address.\nThe PGET_MODULE_BASE_ROUTINE64 type defines a pointer to this callback function.\nGetModuleBaseProc64 is a placeholder for the application-defined function name.\nC++\n[in] hProcess\nA handle to the process for which the stack trace is generated.\n[in] Address\nAn address within the module image to be located.\nThe function returns the base address of the module.\nThis callback function supersedes the PGET_MODULE_BASE_ROUTINE callback function.\nPGET_MODULE_BASE_ROUTINE is defined as follows in DbgHelp.h.\nSyntax\nPGET_MODULE_BASE_ROUTINE PgetModuleBaseRoutine;\nDWORD PgetModuleBaseRoutine(\n [in] HANDLE hProcess,\n [in] DWORD Address\n)\n{...}\nParameters\nReturn value\nRemarks\nC++\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nStackWalk64\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define PGET_MODULE_BASE_ROUTINE PGET_MODULE_BASE_ROUTINE64\n#else\ntypedef\nDWORD\n(__stdcall *PGET_MODULE_BASE_ROUTINE)(\n __in HANDLE hProcess,\n __in DWORD Address\n );\n#endif\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3216,"title":"GetSymLoadError function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["getsymloaderror","function","dbghelp","gets","the","last","symbol","load","error","article02","2024","requirement","value","target","platform","windows","header","library","lib","dll","redistributable","later","syntax","dword","imageapi","return","requirements","expand","table"],"errorCode":"","eventId":"","severity":"Low","summary":"Gets the last symbol load error.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to GetSymLoadError function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"GetSymLoadError function (dbghelp.h)\nArticle02/22/2024\nGets the last symbol load error.\nC++\nThe last symbol load error.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary DbgHelp.lib\nDLL DbgHelp.dll\nRedistributable DbgHelp.dll 6.2 or later\nSyntax\nDWORD IMAGEAPI GetSymLoadError();\nReturn value\nRequirements\nﾉ Expand table","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3217,"title":"GetTimestampForLoadedLibrary function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["gettimestampforloadedlibrary","function","dbghelp","retrieves","the","time","stamp","loaded","image","article02","2024","module","base","address","that","mapped","into","memory","call","mapviewoffile","succeeds","return","value","from","fails","zero","retrieve","extended","error","information","getlasterror","for","initially","set","linker","but","can","modified","operations","such"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the time stamp of a loaded image.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to GetTimestampForLoadedLibrary function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"GetTimestampForLoadedLibrary function\n(dbghelp.h)\nArticle02/22/2024\nRetrieves the time stamp of a loaded image.\nC++\n[in] Module\nThe base address of an image that is mapped into memory by a call to the MapViewOfFile\nfunction.\nIf the function succeeds, the return value is the time stamp from the image.\nIf the function fails, the return value is zero. To retrieve extended error information, call\nGetLastError.\nThe time stamp for an image is initially set by the linker, but it can be modified by operations\nsuch as rebasing. The value is represented in the number of seconds elapsed since midnight\n(00:00:00), January 1, 1970, Universal Coordinated Time, according to the system clock. The\ntime stamp can be printed using the C run-time (CRT) function ctime.\nAll DbgHelp Functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nSyntax\nDWORD IMAGEAPI GetTimestampForLoadedLibrary(\n [in] HMODULE Module\n);\nParameters\nReturn value\nRemarks\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nMapViewOfFile\nReBaseImage\nReBaseImage64\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3218,"title":"ImageDirectoryEntryToData function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["imagedirectoryentrytodata","function","dbghelp","obtains","access","image","specific","data","article10","2021","this","has","been","superseded","the","imagedirectoryentrytodataex","use","retrieve","section","header","base","address","mappedasimage","parameter","true","file","mapped","system","flag","false","mapviewoffile","directoryentry","index","number","desired","directory","entry","can","one","following"],"errorCode":"","eventId":"","severity":"Low","summary":"Obtains access to image-specific data.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to ImageDirectoryEntryToData function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"ImageDirectoryEntryToData function\n(dbghelp.h)\nArticle10/13/2021\nObtains access to image-specific data.\nThis function has been superseded by the ImageDirectoryEntryToDataEx function. Use\nImageDirectoryEntryToDataEx to retrieve the section header.\nC++\n[in] Base\nThe base address of the image.\n[in] MappedAsImage\nIf this parameter is TRUE, the file is mapped by the system as an image. If the flag is FALSE, the\nfile is mapped as a data file by the MapViewOfFile function.\n[in] DirectoryEntry\nThe index number of the desired directory entry. This parameter can be one of the following\nvalues.\nValue Meaning\nIMAGE_DIRECTORY_ENTRY_ARCHITECTURE\n7\nArchitecture-specific data\nSyntax\nPVOID IMAGEAPI ImageDirectoryEntryToData(\n [in] PVOID Base,\n [in] BOOLEAN MappedAsImage,\n [in] USHORT DirectoryEntry,\n [out] PULONG Size\n);\nParameters\nﾉ Expand table\nIMAGE_DIRECTORY_ENTRY_BASERELOC\n5\nBase relocation table\nIMAGE_DIRECTORY_ENTRY_BOUND_IMPORT\n11\nBound import directory\nIMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR\n14\nCOM descriptor table\nIMAGE_DIRECTORY_ENTRY_DEBUG\n6\nDebug directory\nIMAGE_DIRECTORY_ENTRY_DELAY_IMPORT\n13\nDelay import table\nIMAGE_DIRECTORY_ENTRY_EXCEPTION\n3\nException directory\nIMAGE_DIRECTORY_ENTRY_EXPORT\n0\nExport directory\nIMAGE_DIRECTORY_ENTRY_GLOBALPTR\n8\nThe relative virtual address of global pointer\nIMAGE_DIRECTORY_ENTRY_IAT\n12\nImport address table\nIMAGE_DIRECTORY_ENTRY_IMPORT\n1\nImport directory\nIMAGE_DIRECTORY_ENTRY_LOAD_CONFIG\n10\nLoad configuration directory\nIMAGE_DIRECTORY_ENTRY_RESOURCE\n2\nResource directory\nIMAGE_DIRECTORY_ENTRY_SECURITY\n4\nSecurity directory\nIMAGE_DIRECTORY_ENTRY_TLS\n9\nThread local storage directory\n[out] Size\nA pointer to a variable that receives the size of the data for the directory entry, in bytes.\nIf the function succeeds, the return value is a pointer to the directory entry's data.\nReturn value\nIf the function fails, the return value is NULL. To retrieve extended error information, call\nGetLastError.\nThe ImageDirectoryEntryToData function is used to obtain access to image-specific data.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nImageDirectoryEntryToDataEx\nMapViewOfFile\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3219,"title":"ImageDirectoryEntryToDataEx function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["imagedirectoryentrytodataex","function","dbghelp","locates","directory","entry","within","the","image","header","and","returns","address","data","for","article10","2021","this","section","located","one","exists","base","file","mappedasimage","flag","true","mapped","system","false","mapviewoffile","directoryentry","value","must","following","values","meaning","architecture","specific","basereloc"],"errorCode":"","eventId":"","severity":"Low","summary":"Locates a directory entry within the image header and returns the address of the data for the\ndirectory entry.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to ImageDirectoryEntryToDataEx function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"ImageDirectoryEntryToDataEx function\n(dbghelp.h)\nArticle10/13/2021\nLocates a directory entry within the image header and returns the address of the data for the\ndirectory entry. This function returns the section header for the data located, if one exists.\nC++\n[in] Base\nThe base address of the image or data file.\n[in] MappedAsImage\nIf the flag is TRUE, the file is mapped by the system as an image. If this flag is FALSE, the file is\nmapped as a data file by the MapViewOfFile function.\n[in] DirectoryEntry\nThe directory entry to be located. The value must be one of the following values.\nValue Meaning\nIMAGE_DIRECTORY_ENTRY_ARCHITECTURE\n7\nArchitecture-specific data\nIMAGE_DIRECTORY_ENTRY_BASERELOC\n5\nBase relocation table\nSyntax\nPVOID IMAGEAPI ImageDirectoryEntryToDataEx(\n [in] PVOID Base,\n [in] BOOLEAN MappedAsImage,\n [in] USHORT DirectoryEntry,\n [out] PULONG Size,\n [out, optional] PIMAGE_SECTION_HEADER *FoundHeader\n);\nParameters\nﾉ Expand table\nIMAGE_DIRECTORY_ENTRY_BOUND_IMPORT\n11\nBound import directory\nIMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR\n14\nCOM descriptor table\nIMAGE_DIRECTORY_ENTRY_DEBUG\n6\nDebug directory\nIMAGE_DIRECTORY_ENTRY_DELAY_IMPORT\n13\nDelay import table\nIMAGE_DIRECTORY_ENTRY_EXCEPTION\n3\nException directory\nIMAGE_DIRECTORY_ENTRY_EXPORT\n0\nExport directory\nIMAGE_DIRECTORY_ENTRY_GLOBALPTR\n8\nThe relative virtual address of global pointer\nIMAGE_DIRECTORY_ENTRY_IAT\n12\nImport address table\nIMAGE_DIRECTORY_ENTRY_IMPORT\n1\nImport directory\nIMAGE_DIRECTORY_ENTRY_LOAD_CONFIG\n10\nLoad configuration directory\nIMAGE_DIRECTORY_ENTRY_RESOURCE\n2\nResource directory\nIMAGE_DIRECTORY_ENTRY_SECURITY\n4\nSecurity directory\nIMAGE_DIRECTORY_ENTRY_TLS\n9\nThread local storage directory\n[out] Size\nA pointer to a variable that receives the size of the data for the directory entry that is located.\n[out, optional] FoundHeader\nA pointer to an IMAGE_SECTION_HEADER structure that receives the data. If the section header\ndoes not exist, this parameter is NULL.\nReturn value\nIf the function succeeds, the return value is a pointer to the data for the directory entry.\nIf the function fails, the return value is NULL. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nIMAGE_SECTION_HEADER\nMapViewOfFile\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3220,"title":"ImagehlpApiVersion function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["imagehlpapiversion","function","dbghelp","retrieves","the","version","information","library","installed","system","article02","2024","indicate","with","which","application","was","built","use","imagehlpapiversionex","return","value","pointer","api","structure","determine","whether","compatible","used","although","functions","are","backward","introduced","one","obviously","not","available","earlier","versions"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the version information of the DbgHelp library installed on the system.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to ImagehlpApiVersion function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"ImagehlpApiVersion function (dbghelp.h)\nArticle02/22/2024\nRetrieves the version information of the DbgHelp library installed on the system.\nTo indicate the version of the library with which the application was built, use the\nImagehlpApiVersionEx function.\nC++\nThe return value is a pointer to an API_VERSION structure.\nUse the information in the API_VERSION structure to determine whether the version of the\nlibrary installed on the system is compatible with the version of the library used by the\napplication. Although the library functions are backward compatible, functions introduced in\none version are obviously not available in earlier versions.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nSyntax\nLPAPI_VERSION IMAGEAPI ImagehlpApiVersion();\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nRequirement Value\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nAPI_VERSION\nDbgHelp Functions\nImagehlpApiVersionEx\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3221,"title":"ImagehlpApiVersionEx function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["imagehlpapiversionex","function","dbghelp","modifies","the","version","information","library","used","application","article02","2024","appversion","pointer","api","structure","that","contains","valid","for","your","return","value","use","indicate","with","which","was","built","uses","this","ensure","compatibility","example","consider","walking","through","kernel","mode","callback"],"errorCode":"","eventId":"","severity":"Low","summary":"Modifies the version information of the library used by the application.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to ImagehlpApiVersionEx function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"ImagehlpApiVersionEx function (dbghelp.h)\nArticle02/22/2024\nModifies the version information of the library used by the application.\nC++\n[in] AppVersion\nA pointer to an API_VERSION structure that contains valid version information for your\napplication.\nThe return value is a pointer to an API_VERSION structure.\nUse the ImagehlpApiVersionEx function to indicate the version of the library with which the\napplication was built. The library uses this information to ensure compatibility. For example,\nconsider walking through kernel-mode callback stack frames (User and GDI exist in kernel\nmode). If you call ImagehlpApiVersionEx to set the Revision member to version 4 or later, the\nStackWalk64 function will continue through a callback stack frame. Otherwise, if you set\nRevision to a version earlier than 4, StackWalk64 will stop at the kernel transition.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nSyntax\nLPAPI_VERSION IMAGEAPI ImagehlpApiVersionEx(\n [in] LPAPI_VERSION AppVersion\n);\nParameters\nReturn value\nRemarks\nRequirements\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nAPI_VERSION\nDbgHelp Functions\nImagehlpApiVersion\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3222,"title":"ImageNtHeader function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["imagentheader","function","dbghelp","locates","the","image","headers","structure","and","returns","pointer","data","article02","2024","base","address","that","mapped","into","memory","call","mapviewoffile","succeeds","return","value","fails","null","retrieve","extended","error","information","getlasterror","all","functions","such","this","one","are","single","threaded"],"errorCode":"","eventId":"","severity":"Low","summary":"Locates the IMAGE_NT_HEADERS structure in a PE image and returns a pointer to the data.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to ImageNtHeader function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"ImageNtHeader function (dbghelp.h)\nArticle02/22/2024\nLocates the IMAGE_NT_HEADERS structure in a PE image and returns a pointer to the data.\nC++\n[in] Base\nThe base address of an image that is mapped into memory by a call to the MapViewOfFile\nfunction.\nIf the function succeeds, the return value is a pointer to an IMAGE_NT_HEADERS structure.\nIf the function fails, the return value is NULL. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nSyntax\nPIMAGE_NT_HEADERS IMAGEAPI ImageNtHeader(\n [in] PVOID Base\n);\nParameters\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nIMAGE_NT_HEADERS\nMapViewOfFile\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3223,"title":"ImageRvaToSection function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["imagervatosection","function","dbghelp","locates","relative","virtual","address","rva","within","the","image","header","file","that","mapped","and","returns","pointer","section","table","entry","for","article10","2021","ntheaders","headers","structure","this","can","obtained","calling","imagentheader","base","parameter","reserved","located","succeeds","return","value","fails"],"errorCode":"","eventId":"","severity":"Low","summary":"Locates a relative virtual address (RVA) within the image header of a file that is mapped as a file\nand returns a pointer to the section table entry for that RVA.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to ImageRvaToSection function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"ImageRvaToSection function (dbghelp.h)\nArticle10/13/2021\nLocates a relative virtual address (RVA) within the image header of a file that is mapped as a file\nand returns a pointer to the section table entry for that RVA.\nC++\n[in] NtHeaders\nA pointer to an IMAGE_NT_HEADERS structure. This structure can be obtained by calling the\nImageNtHeader function.\n[in] Base\nThis parameter is reserved.\n[in] Rva\nThe relative virtual address to be located.\nIf the function succeeds, the return value is a pointer to an IMAGE_SECTION_HEADER structure.\nIf the function fails, the return value is NULL. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\nSyntax\nPIMAGE_SECTION_HEADER IMAGEAPI ImageRvaToSection(\n [in] PIMAGE_NT_HEADERS NtHeaders,\n [in] PVOID Base,\n [in] ULONG Rva\n);\nParameters\nReturn value\nRemarks\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nIMAGE_NT_HEADERS\nIMAGE_SECTION_HEADER\nImageNtHeader\nMapViewOfFile\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3224,"title":"ImageRvaToVa function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["imagervatova","function","dbghelp","locates","relative","virtual","address","rva","within","the","image","header","file","that","mapped","and","returns","corresponding","byte","article02","2024","ntheaders","pointer","headers","structure","this","can","obtained","calling","imagentheader","base","into","memory","through","call","mapviewoffile","located","optional","lastrvasection","section"],"errorCode":"","eventId":"","severity":"Low","summary":"Locates a relative virtual address (RVA) within the image header of a file that is mapped as a file\nand returns the virtual address of the corresponding byte in the file.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to ImageRvaToVa function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"ImageRvaToVa function (dbghelp.h)\nArticle02/22/2024\nLocates a relative virtual address (RVA) within the image header of a file that is mapped as a file\nand returns the virtual address of the corresponding byte in the file.\nC++\n[in] NtHeaders\nA pointer to an IMAGE_NT_HEADERS structure. This structure can be obtained by calling the\nImageNtHeader function.\n[in] Base\nThe base address of an image that is mapped into memory through a call to the\nMapViewOfFile function.\n[in] Rva\nThe relative virtual address to be located.\n[in, optional] LastRvaSection\nA pointer to an IMAGE_SECTION_HEADER structure that specifies the last RVA section. This is\nan optional parameter. When specified, it points to a variable that contains the last section\nvalue used for the specified image to translate an RVA to a VA.\nIf the function succeeds, the return value is the virtual address in the mapped file.\nSyntax\nPVOID IMAGEAPI ImageRvaToVa(\n [in] PIMAGE_NT_HEADERS NtHeaders,\n [in] PVOID Base,\n [in] ULONG Rva,\n [in, optional] PIMAGE_SECTION_HEADER *LastRvaSection\n);\nParameters\nReturn value\nIf the function fails, the return value is NULL. To retrieve extended error information, call\nGetLastError.\nThe ImageRvaToVa function locates an RVA within the image header of a file that is mapped as\na file and returns the virtual address of the corresponding byte in the file.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nIMAGE_NT_HEADERS\nIMAGE_SECTION_HEADER\nImageNtHeader\nMapViewOfFile\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3225,"title":"MakeSureDirectoryPathExists function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["makesuredirectorypathexists","function","dbghelp","creates","all","the","directories","specified","path","beginning","with","root","article02","2024","dirpath","valid","name","final","component","directory","not","file","string","must","end","backslash","character","succeeds","return","value","true","fails","false","retrieve","extended","error","information","call","getlasterror","each"],"errorCode":"","eventId":"","severity":"Low","summary":"Creates all the directories in the specified path, beginning with the root.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MakeSureDirectoryPathExists function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MakeSureDirectoryPathExists function\n(dbghelp.h)\nArticle02/22/2024\nCreates all the directories in the specified path, beginning with the root.\nC++\n[in] DirPath\nA valid path name. If the final component of the path is a directory, not a file name, the string\nmust end with a backslash (\\) character.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nEach directory specified is created, if it does not already exist. If only some of the directories\nare created, the function will return FALSE.\nThis function does not support Unicode strings. To specify a Unicode path, use the\nSHCreateDirectoryEx function.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nSyntax\nBOOL IMAGEAPI MakeSureDirectoryPathExists(\n [in] PCSTR DirPath\n);\nParameters\nReturn value\nRemarks\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3226,"title":"MapDebugInformation function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["mapdebuginformation","function","dbghelp","obtains","access","the","debugging","information","for","image","article10","2021","optional","filehandle","handle","open","executable","null","filename","name","file","symbolpath","path","where","symbol","files","are","located","can","multiple","paths","separated","semicolons","retrieve","use","symgetsearchpath","imagebase","base","address","zero"],"errorCode":"","eventId":"","severity":"Low","summary":"Obtains access to the debugging information for an image.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MapDebugInformation function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MapDebugInformation function\n(dbghelp.h)\nArticle10/13/2021\nObtains access to the debugging information for an image.\n \nC++\n[in, optional] FileHandle\nA handle to an open executable image or NULL.\n[in] FileName\nThe name of an executable image file or NULL.\n[in, optional] SymbolPath\nThe path where symbol files are located. The path can be multiple paths separated by\nsemicolons. To retrieve the symbol path, use the SymGetSearchPath function.\n[in] ImageBase\nThe base address for the image or zero.\nNote This function is provided only for backward compatibility. It does not return reliable\ninformation. New applications should use the SymGetModuleInfo64 and\nSymLoadModule64 functions.\nSyntax\nPIMAGE_DEBUG_INFORMATION IMAGEAPI MapDebugInformation(\n [in, optional] HANDLE FileHandle,\n [in] PCSTR FileName,\n [in, optional] PCSTR SymbolPath,\n [in] ULONG ImageBase\n);\nParameters\nIf the function succeeds, the return value is a pointer to an IMAGE_DEBUG_INFORMATION\nstructure.\nIf the function fails, the return value is NULL. To retrieve extended error information, call\nGetLastError.\nThe MapDebugInformation function is used to obtain access to an image's debugging\ninformation. The debugging information is extracted from the image or the symbol file and\nplaced into the IMAGE_DEBUG_INFORMATION structure. This structure is allocated by the\nlibrary and must be deallocated by using the UnmapDebugInformation function. The memory\nfor the structure is not in the process's default heap, so attempts to free it with a memory\ndeallocation routine will fail.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nIMAGE_DEBUG_INFORMATION\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nSee also\nSymGetSearchPath\nUnmapDebugInformation","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3227,"title":"MINIDUMP_CALLBACK_ROUTINE callback function (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","callback","routine","function","minidumpapiset","application","defined","used","with","minidumpwritedump","article02","2024","receives","extended","information","the","type","defines","pointer","this","minidumpcallback","placeholder","for","name","callbackparam","parameter","value","callbackinput","input","structure","that","specifies","out","callbackoutput","output","from","succeeds","return","true","otherwise"],"errorCode":"","eventId":"","severity":"Low","summary":"An application-defined callback function used with MiniDumpWriteDump.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_CALLBACK_ROUTINE callback function (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_CALLBACK_ROUTINE callback\nfunction (minidumpapiset.h)\nArticle02/22/2024\nAn application-defined callback function used with MiniDumpWriteDump. It receives extended\nminidump information.\nThe MINIDUMP_CALLBACK_ROUTINE type defines a pointer to this callback function.\nMiniDumpCallback is a placeholder for the application-defined function name.\nC++\n[in] CallbackParam\nAn application-defined parameter value.\n[in] CallbackInput\nA pointer to a MINIDUMP_CALLBACK_INPUT structure that specifies extended minidump\ninformation.\n[in, out] CallbackOutput\nA pointer to a MINIDUMP_CALLBACK_OUTPUT structure that receives application-defined\ninformation from the callback function.\nIf the function succeeds, return TRUE; otherwise, return FALSE.\nSyntax\nMINIDUMP_CALLBACK_ROUTINE MinidumpCallbackRoutine;\nBOOL MinidumpCallbackRoutine(\n [in] PVOID CallbackParam,\n [in] PMINIDUMP_CALLBACK_INPUT CallbackInput,\n [in, out] PMINIDUMP_CALLBACK_OUTPUT CallbackOutput\n)\n{...}\nParameters\nReturn value\nRequirement Value\nTarget Platform Windows\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nMINIDUMP_CALLBACK_INFORMATION\nMiniDumpWriteDump\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3228,"title":"MiniDumpReadDumpStream function (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidumpreaddumpstream","function","minidumpapiset","reads","stream","from","user","mode","minidump","file","article02","2024","baseofdump","pointer","the","base","mapped","should","have","been","into","memory","using","mapviewoffile","streamnumber","type","data","read","this","member","can","one","values","enumeration","out","dir","directory","structure","streampointer","beginning"],"errorCode":"","eventId":"","severity":"Low","summary":"Reads a stream from a user-mode minidump file.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MiniDumpReadDumpStream function (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MiniDumpReadDumpStream function\n(minidumpapiset.h)\nArticle02/22/2024\nReads a stream from a user-mode minidump file.\nC++\n[in] BaseOfDump\nA pointer to the base of the mapped minidump file. The file should have been mapped into\nmemory using the MapViewOfFile function.\n[in] StreamNumber\nThe type of data to be read from the minidump file. This member can be one of the values in\nthe MINIDUMP_STREAM_TYPE enumeration.\n[out] Dir\nA pointer to a MINIDUMP_DIRECTORY structure.\n[out] StreamPointer\nA pointer to the beginning of the minidump stream. The format of this stream depends on the\nvalue of StreamNumber. For more information, see MINIDUMP_STREAM_TYPE.\n[out] StreamSize\nThe size of the stream pointed to by StreamPointer, in bytes.\nSyntax\nBOOL MiniDumpReadDumpStream(\n [in] PVOID BaseOfDump,\n [in] ULONG StreamNumber,\n [out] PMINIDUMP_DIRECTORY *Dir,\n [out] PVOID *StreamPointer,\n [out] ULONG *StreamSize\n);\nParameters\nIf the function succeeds, the return value is TRUE; otherwise, the return value is FALSE.\nIn this context, a data stream is a block of data written to a minidump file.\nRequirement Value\nTarget Platform Windows\nHeader minidumpapiset.h (include Dbghelp.h)\nLibrary Dbghelp.lib\nDLL Dbghelp.dll; Dbgcore.dll\nRedistributable DbgHelp.dll and Dbgcore.dll\nDbgHelp Functions\nMINIDUMP_DIRECTORY\nMINIDUMP_STREAM_TYPE\nMiniDumpWriteDump\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3229,"title":"MiniDumpWriteDump function (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidumpwritedump","function","minidumpapiset","writes","user","mode","minidump","information","the","specified","file","article02","2024","hprocess","handle","process","for","which","generated","this","must","have","query","and","read","access","collected","then","dup","also","required","more","see","security","rights","caller","able","get","thread","all"],"errorCode":"","eventId":"","severity":"Low","summary":"Writes user-mode minidump information to the specified file.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MiniDumpWriteDump function (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MiniDumpWriteDump function\n(minidumpapiset.h)\nArticle02/21/2024\nWrites user-mode minidump information to the specified file.\nC++\n[in] hProcess\nA handle to the process for which the information is to be generated.\nThis handle must have PROCESS_QUERY_INFORMATION and PROCESS_VM_READ access to\nthe process. If handle information is to be collected then PROCESS_DUP_HANDLE access is\nalso required. For more information, see Process Security and Access Rights. The caller must\nalso be able to get THREAD_ALL_ACCESS access to the threads in the process. For more\ninformation, see Thread Security and Access Rights.\n[in] ProcessId\nThe identifier of the process for which the information is to be generated.\n[in] hFile\nA handle to the file in which the information is to be written.\n[in] DumpType\nSyntax\nBOOL MiniDumpWriteDump(\n [in] HANDLE hProcess,\n [in] DWORD ProcessId,\n [in] HANDLE hFile,\n [in] MINIDUMP_TYPE DumpType,\n [in] PMINIDUMP_EXCEPTION_INFORMATION ExceptionParam,\n [in] PMINIDUMP_USER_STREAM_INFORMATION UserStreamParam,\n [in] PMINIDUMP_CALLBACK_INFORMATION CallbackParam\n);\nParameters\nThe type of information to be generated. This parameter can be one or more of the values\nfrom the MINIDUMP_TYPE enumeration.\n[in] ExceptionParam\nA pointer to a MINIDUMP_EXCEPTION_INFORMATION structure describing the client exception\nthat caused the minidump to be generated. If the value of this parameter is NULL, no\nexception information is included in the minidump file.\n[in] UserStreamParam\nA pointer to a MINIDUMP_USER_STREAM_INFORMATION structure. If the value of this\nparameter is NULL, no user-defined information is included in the minidump file.\n[in] CallbackParam\nA pointer to a MINIDUMP_CALLBACK_INFORMATION structure that specifies a callback routine\nwhich is to receive extended minidump information. If the value of this parameter is NULL, no\ncallbacks are performed.\nIf the function succeeds, the return value is TRUE; otherwise, the return value is FALSE. To\nretrieve extended error information, call GetLastError. Note that the last error will be an\nHRESULT value.\nIf the operation is canceled, the last error code is HRESULT_FROM_WIN32(ERROR_CANCELLED).\nThe MiniDumpCallback function receives extended minidump information from\nMiniDumpWriteDump. It also provides a way for the caller to determine the granularity of\ninformation written to the minidump file, as the callback function can filter the default\ninformation.\nMiniDumpWriteDump should be called from a separate process if at all possible, rather than\nfrom within the target process being dumped. This is especially true when the target process is\nalready not stable. For example, if it just crashed. A loader deadlock is one of many potential\nside effects of calling MiniDumpWriteDump from within the target process. If calling\nMiniDumpWriteDump from a separate process is not possible, then it is advisable to have a\ndedicated thread whose sole purpose is to call MiniDumpWriteDump. This can help ensure\nthat the stack is not already exhausted before the call to MiniDumpWriteDump.\nReturn value\nRemarks\nMiniDumpWriteDump may not produce a valid stack trace for the calling thread. To work\naround this problem, you must capture the state of the calling thread before calling\nMiniDumpWriteDump and use it as the ExceptionParam parameter. One way to do this is to\nforce an exception inside a __try/__except block and use the EXCEPTION_POINTERS\ninformation provided by GetExceptionInformation. Alternatively, you can call the function from\na new worker thread and filter this worker thread from the dump.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nTarget Platform Windows\nHeader minidumpapiset.h (include Dbghelp.h)\nLibrary Dbghelp.lib\nDLL Dbghelp.dll; Dbgcore.dll\nRedistributable DbgHelp.dll and Dbgcore.dll\nDbgHelp Functions\nMINIDUMP_CALLBACK_INFORMATION\nMINIDUMP_EXCEPTION_INFORMATION\nMINIDUMP_USER_STREAM_INFORMATION\nMiniDumpCallback\nMiniDumpReadDumpStream\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3230,"title":"PREAD_PROCESS_MEMORY_ROUTINE callback function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["pread","process","memory","routine","callback","function","dbghelp","application","defined","used","with","the","stackwalk64","article02","2024","called","when","needs","read","from","address","space","routine64","type","defines","pointer","this","readprocessmemoryproc64","placeholder","for","name","hprocess","handle","which","stack","trace","generated","lpbaseaddress","base","out"],"errorCode":"","eventId":"","severity":"Low","summary":"An application-defined callback function used with the StackWalk64 function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to PREAD_PROCESS_MEMORY_ROUTINE callback function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"PREAD_PROCESS_MEMORY_ROUTINE\ncallback function (dbghelp.h)\nArticle02/22/2024\nAn application-defined callback function used with the StackWalk64 function. It is called when\nStackWalk64 needs to read memory from the address space of the process.\nThe PREAD_PROCESS_MEMORY_ROUTINE64 type defines a pointer to this callback function.\nReadProcessMemoryProc64 is a placeholder for the application-defined function name.\nC++\n[in] hProcess\nA handle to the process for which the stack trace is generated.\n[in] lpBaseAddress\nThe base address of the memory to be read.\n[out] lpBuffer\nA pointer to a buffer that receives the memory to be read.\n[in] nSize\nThe size of the memory to be read, in bytes.\n[out] lpNumberOfBytesRead\nSyntax\nPREAD_PROCESS_MEMORY_ROUTINE PreadProcessMemoryRoutine;\nBOOL PreadProcessMemoryRoutine(\n [in] HANDLE hProcess,\n [in] DWORD lpBaseAddress,\n [out] PVOID lpBuffer,\n [in] DWORD nSize,\n [out] PDWORD lpNumberOfBytesRead\n)\n{...}\nParameters\nA pointer to a variable that receives the number of bytes actually read.\nIf the function succeeds, the return value should be TRUE. If the function fails, the return value\nshould be FALSE.\nIn many cases, this function can best service the callback with a corresponding call to\nReadProcessMemory.\nThis function should read as much of the requested memory as possible. The StackWalk64\nfunction handles the case where only part of the requested memory is read.\nThis callback function supersedes the PREAD_PROCESS_MEMORY_ROUTINE callback function.\nPREAD_PROCESS_MEMORY_ROUTINE is defined as follows in Dbghelp.h.\nC++\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nReturn value\nRemarks\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define PREAD_PROCESS_MEMORY_ROUTINE PREAD_PROCESS_MEMORY_ROUTINE64\n#else\ntypedef\nBOOL\n(__stdcall *PREAD_PROCESS_MEMORY_ROUTINE)(\n __in HANDLE hProcess,\n __in DWORD lpBaseAddress,\n __out_bcount(nSize) PVOID lpBuffer,\n __in DWORD nSize,\n __out PDWORD lpNumberOfBytesRead\n );\n#endif\nRequirements\nﾉ Expand table\nDbgHelp Functions\nReadProcessMemory\nStackWalk64\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3231,"title":"SearchTreeForFile function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["searchtreeforfile","function","dbghelp","searches","directory","tree","for","specified","file","article02","2024","rootpath","the","path","where","should","begin","searching","inputpathname","which","will","search","you","can","use","partial","out","outputpathbuffer","pointer","buffer","that","receives","full","found","this","string","not","modified","return","value"],"errorCode":"","eventId":"","severity":"Low","summary":"Searches a directory tree for a specified file.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SearchTreeForFile function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SearchTreeForFile function (dbghelp.h)\nArticle02/22/2024\nSearches a directory tree for a specified file.\nC++\n[in] RootPath\nThe path where the function should begin searching for the file.\n[in] InputPathName\nThe file for which the function will search. You can use a partial path.\n[out] OutputPathBuffer\nA pointer to a buffer that receives the full path to the file that is found. This string is not\nmodified if the return value is FALSE.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe function searches for the file specified by the InputPathName parameter beginning at the\npath specified in the RootPath parameter. The maximum path depth that is allowed in the\nRootPath is 32 directories. When the function finds the file in the directory tree, it places the full\nSyntax\nBOOL IMAGEAPI SearchTreeForFile(\n [in] PCSTR RootPath,\n [in] PCSTR InputPathName,\n [out] PSTR OutputPathBuffer\n);\nParameters\nReturn value\nRemarks\npath to the file in the buffer specified by the OutputPathBuffer parameter. The underlying file\nsystem specifies the order of the subdirectory search.\nThe search can be canceled if you register a SymRegisterCallbackProc64 callback function. For\nevery directory searched, SearchTreeForFile calls this callback function with\nCBA_DEFERRED_SYMBOL_LOAD_CANCEL. If the callback function returns TRUE,\nSearchTreeForFile cancels the search.\nThis function triggers one CBA_DEFERRED_SYMBOL_LOAD_CANCEL event per directory\nsearched. This allows the caller to cancel the search.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3232,"title":"SetSymLoadError function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["setsymloaderror","function","dbghelp","error","symbol","load","article02","2024","sets","this","does","not","return","value","requirement","target","platform","windows","header","library","lib","dll","redistributable","later","syntax","void","imageapi","dword","parameters","requirements","expand","table"],"errorCode":"","eventId":"","severity":"Low","summary":"C++\n[in] error\nA symbol load error.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SetSymLoadError function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SetSymLoadError function (dbghelp.h)\nArticle02/22/2024\nSets a symbol load error.\nC++\n[in] error\nA symbol load error.\nThis function does not return a value.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary DbgHelp.lib\nDLL DbgHelp.dll\nRedistributable DbgHelp.dll 6.2 or later\nSyntax\nvoid IMAGEAPI SetSymLoadError(\n [in] DWORD error\n);\nParameters\nReturn value\nRequirements\nﾉ Expand table","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3233,"title":"StackWalk function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["stackwalk","function","dbghelp","machinetype","the","architecture","type","computer","for","which","stack","trace","generated","article07","2022","obtains","this","parameter","can","one","following","values","value","meaning","image","file","machine","i386","0x014c","intel","x86","ia64","0x0200","itanium","amd64","0x8664","x64","em64t","hprocess","handle"],"errorCode":"","eventId":"","severity":"Low","summary":"C++\n[in] MachineType\nThe architecture type of the computer for which the stack trace is generated.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to StackWalk function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"StackWalk function (dbghelp.h)\nArticle07/27/2022\nObtains a stack trace.\nC++\n[in] MachineType\nThe architecture type of the computer for which the stack trace is generated. This parameter\ncan be one of the following values.\nValue Meaning\nIMAGE_FILE_MACHINE_I386\n0x014c\nIntel x86\nIMAGE_FILE_MACHINE_IA64\n0x0200\nIntel Itanium\nIMAGE_FILE_MACHINE_AMD64\n0x8664\nx64 (AMD64 or EM64T)\n[in] hProcess\nA handle to the process for which the stack trace is generated. If the caller supplies a valid\ncallback pointer for the ReadMemoryRoutine parameter, then this value does not have to be a\nSyntax\nBOOL IMAGEAPI StackWalk(\n [in] DWORD MachineType,\n [in] HANDLE hProcess,\n [in] HANDLE hThread,\n [in, out] LPSTACKFRAME StackFrame,\n [in, out] PVOID ContextRecord,\n [in, optional] PREAD_PROCESS_MEMORY_ROUTINE ReadMemoryRoutine,\n [in, optional] PFUNCTION_TABLE_ACCESS_ROUTINE FunctionTableAccessRoutine,\n [in, optional] PGET_MODULE_BASE_ROUTINE GetModuleBaseRoutine,\n [in, optional] PTRANSLATE_ADDRESS_ROUTINE TranslateAddress\n);\nParameters\nﾉ Expand table\nvalid process handle. It can be a token that is unique and consistently the same for all calls to\nthe StackWalk64 function. If the symbol handler is used with StackWalk64, use the same\nprocess handles for the calls to each function.\n[in] hThread\nA handle to the thread for which the stack trace is generated. If the caller supplies a valid\ncallback pointer for the ReadMemoryRoutine parameter, then this value does not have to be a\nvalid thread handle. It can be a token that is unique and consistently the same for all calls to\nthe StackWalk64 function.\n[in, out] StackFrame\nA pointer to a STACKFRAME64 structure. This structure receives information for the next frame,\nif the function call succeeds.\n[in, out] ContextRecord\nA pointer to a CONTEXT structure. This parameter is required only when the MachineType\nparameter is not IMAGE_FILE_MACHINE_I386. However, it is recommended that this parameter\ncontain a valid context record. This allows StackWalk64 to handle a greater variety of\nsituations.\nThis context may be modified, so do not pass a context record that should not be modified.\n[in, optional] ReadMemoryRoutine\nA callback routine that provides memory read services. When the StackWalk64 function needs\nto read memory from the process's address space, the ReadProcessMemoryProc64 callback is\nused.\nIf this parameter is NULL, then the function uses a default routine. In this case, the hProcess\nparameter must be a valid process handle.\nIf this parameter is not NULL, the application should implement and register a symbol handler\ncallback function that handles CBA_READ_MEMORY.\n[in, optional] FunctionTableAccessRoutine\nA callback routine that provides access to the run-time function table for the process. This\nparameter is required because the StackWalk64 function does not have access to the process's\nrun-time function table. For more information, see FunctionTableAccessProc64.\nThe symbol handler provides functions that load and access the run-time table. If these\nfunctions are used, then SymFunctionTableAccess64 can be passed as a valid parameter.\n[in, optional] GetModuleBaseRoutine\nA callback routine that provides a module base for any given virtual address. This parameter is\nrequired. For more information, see GetModuleBaseProc64.\nThe symbol handler provides functions that load and maintain module information. If these\nfunctions are used, then SymGetModuleBase64 can be passed as a valid parameter.\n[in, optional] TranslateAddress\nA callback routine that provides address translation for 16-bit addresses. For more information,\nsee TranslateAddressProc64.\nMost callers of StackWalk64 can safely pass NULL for this parameter.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. Note that StackWalk64 generally does not set\nthe last error code.\nThe StackWalk64 function provides a portable method for obtaining a stack trace. Using the\nStackWalk64 function is recommended over writing your own function because of all the\ncomplexities associated with stack walking on platforms. In addition, there are compiler\noptions that cause the stack to appear differently, depending on how the module is compiled.\nBy using this function, your application has a portable stack trace that continues to work as the\ncompiler and operating system change.\nThe first call to this function will fail if the AddrPC, AddrFrame, and AddrStack members of the\nSTACKFRAME64 structure passed in the StackFrame parameter are not initialized.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nThis function supersedes the StackWalk function. For more information, see Updated Platform\nSupport. StackWalk is defined as follows in DbgHelp.h.\nC++\nReturn value\nRemarks\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary DbgHelp.lib\nDLL DbgHelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nCONTEXT\nDbgHelp Functions\nFunctionTableAccessProc64\nGetModuleBaseProc64\nReadProcessMemoryProc64\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define StackWalk StackWalk64\n#else\nBOOL\nIMAGEAPI\nStackWalk(\n DWORD MachineType,\n __in HANDLE hProcess,\n __in HANDLE hThread,\n __inout LPSTACKFRAME StackFrame,\n __inout PVOID ContextRecord,\n __in_opt PREAD_PROCESS_MEMORY_ROUTINE ReadMemoryRoutine,\n __in_opt PFUNCTION_TABLE_ACCESS_ROUTINE FunctionTableAccessRoutine,\n __in_opt PGET_MODULE_BASE_ROUTINE GetModuleBaseRoutine,\n __in_opt PTRANSLATE_ADDRESS_ROUTINE TranslateAddress\n );\n#endif\nRequirements\nﾉ Expand table\nSee also\nSTACKFRAME64\nTranslateAddressProc64","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3234,"title":"StackWalkEx function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["stackwalkex","function","dbghelp","machinetype","the","architecture","type","computer","for","which","stack","trace","generated","article07","2022","obtains","this","parameter","can","one","following","values","value","meaning","image","file","machine","i386","0x014c","intel","x86","ia64","0x0200","itanium","amd64","0x8664","x64","em64t","hprocess","syntax"],"errorCode":"","eventId":"","severity":"Low","summary":"C++\n[in] MachineType\nThe architecture type of the computer for which the stack trace is generated.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to StackWalkEx function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"StackWalkEx function (dbghelp.h)\nArticle07/27/2022\nObtains a stack trace.\nC++\n[in] MachineType\nThe architecture type of the computer for which the stack trace is generated. This parameter\ncan be one of the following values.\nValue Meaning\nIMAGE_FILE_MACHINE_I386\n0x014c\nIntel x86\nIMAGE_FILE_MACHINE_IA64\n0x0200\nIntel Itanium\nIMAGE_FILE_MACHINE_AMD64\n0x8664\nx64 (AMD64 or EM64T)\n[in] hProcess\nSyntax\nBOOL IMAGEAPI StackWalkEx(\n [in] DWORD MachineType,\n [in] HANDLE hProcess,\n [in] HANDLE hThread,\n [in, out] LPSTACKFRAME_EX StackFrame,\n [in, out] PVOID ContextRecord,\n [in, optional] PREAD_PROCESS_MEMORY_ROUTINE64 ReadMemoryRoutine,\n [in, optional] PFUNCTION_TABLE_ACCESS_ROUTINE64 FunctionTableAccessRoutine,\n [in, optional] PGET_MODULE_BASE_ROUTINE64 GetModuleBaseRoutine,\n [in, optional] PTRANSLATE_ADDRESS_ROUTINE64 TranslateAddress,\n [in] DWORD Flags\n);\nParameters\nﾉ Expand table\nA handle to the process for which the stack trace is generated. If the caller supplies a valid\ncallback pointer for the ReadMemoryRoutine parameter, then this value does not have to be a\nvalid process handle. It can be a token that is unique and consistently the same for all calls to\nthe StackWalkEx function. If the symbol handler is used with StackWalkEx, use the same\nprocess handles for the calls to each function.\n[in] hThread\nA handle to the thread for which the stack trace is generated. If the caller supplies a valid\ncallback pointer for the ReadMemoryRoutine parameter, then this value does not have to be a\nvalid thread handle. It can be a token that is unique and consistently the same for all calls to\nthe StackWalkEx function.\n[in, out] StackFrame\nA pointer to a STACKFRAME_EX structure. This structure receives information for the next\nframe, if the function call succeeds.\n[in, out] ContextRecord\nA pointer to a CONTEXT structure. This parameter is required only when the MachineType\nparameter is not IMAGE_FILE_MACHINE_I386. However, it is recommended that this parameter\ncontain a valid context record. This allows StackWalkEx to handle a greater variety of\nsituations.\nThis context may be modified, so do not pass a context record that should not be modified.\n[in, optional] ReadMemoryRoutine\nA callback routine that provides memory read services. When the StackWalkEx function needs\nto read memory from the process's address space, the ReadProcessMemoryProc64 callback is\nused.\nIf this parameter is NULL, then the function uses a default routine. In this case, the hProcess\nparameter must be a valid process handle.\nIf this parameter is not NULL, the application should implement and register a symbol handler\ncallback function that handles CBA_READ_MEMORY.\n[in, optional] FunctionTableAccessRoutine\nA callback routine that provides access to the run-time function table for the process. This\nparameter is required because the StackWalkEx function does not have access to the process's\nrun-time function table. For more information, see FunctionTableAccessProc64.\nThe symbol handler provides functions that load and access the run-time table. If these\nfunctions are used, then SymFunctionTableAccess64 can be passed as a valid parameter.\n[in, optional] GetModuleBaseRoutine\nA callback routine that provides a module base for any given virtual address. This parameter is\nrequired. For more information, see GetModuleBaseProc64.\nThe symbol handler provides functions that load and maintain module information. If these\nfunctions are used, then SymGetModuleBase64 can be passed as a valid parameter.\n[in, optional] TranslateAddress\nA callback routine that provides address translation for 16-bit addresses. For more information,\nsee TranslateAddressProc64.\nMost callers of StackWalkEx can safely pass NULL for this parameter.\n[in] Flags\nA combination of zero or more flags.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. Note that StackWalkEx generally does not set the\nlast error code.\nThe StackWalkEx function provides a portable method for obtaining a stack trace. Using the\nStackWalkEx function is recommended over writing your own function because of all the\ncomplexities associated with stack walking on platforms. In addition, there are compiler\noptions that cause the stack to appear differently, depending on how the module is compiled.\nBy using this function, your application has a portable stack trace that continues to work as the\ncompiler and operating system change.\nSYM_STKWALK_DEFAULT (0)\nSYM_STKWALK_FORCE_FRAMEPTR (1)\nReturn value\nRemarks\nThe first call to this function will fail if the AddrPC,\nAddrFrame, and AddrStack members of the STACKFRAME64 structure passed in the\nStackFrame parameter are not initialized.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary DbgHelp.lib\nDLL DbgHelp.dll\nRedistributable DbgHelp.dll 6.2 or later\nCONTEXT\nDbgHelp Functions\nFunctionTableAccessProc64\nReadProcessMemoryProc64\nSTACKFRAME_EX\nSymFunctionTableAccess64\nSymGetModuleBase64\nTranslateAddressProc64\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3235,"title":"SymAddrIncludeInlineTrace function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symaddrincludeinlinetrace","function","dbghelp","indicates","whether","the","specified","address","within","inline","frame","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","returns","zero","not","requirement","value","target","platform","windows","header","library","lib","syntax","dword","imageapi","dword64","parameters","return"],"errorCode":"","eventId":"","severity":"Low","summary":"Indicates whether the specified address is within an inline frame.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymAddrIncludeInlineTrace function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymAddrIncludeInlineTrace function\n(dbghelp.h)\nArticle02/22/2024\nIndicates whether the specified address is within an inline frame.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] Address\nThe address.\nReturns zero if the address is not within an inline frame.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary DbgHelp.lib\nSyntax\nDWORD IMAGEAPI SymAddrIncludeInlineTrace(\n [in] HANDLE hProcess,\n [in] DWORD64 Address\n);\nParameters\nReturn value\nRequirements\nﾉ Expand table\nRequirement Value\nDLL DbgHelp.dll\nRedistributable DbgHelp.dll 6.2 or later","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3236,"title":"SymAddSourceStream function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symaddsourcestream","function","dbghelp","adds","the","stream","specified","module","for","use","source","server","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","base","address","optional","streamfile","null","terminated","string","that","contains","absolute","relative","path","file","indexing","can","buffer"],"errorCode":"","eventId":"","severity":"Low","summary":"Adds the stream to the specified module for use by the Source Server.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymAddSourceStream function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymAddSourceStream function (dbghelp.h)\nArticle02/22/2024\nAdds the stream to the specified module for use by the Source Server.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] Base\nThe base address of the module.\n[in, optional] StreamFile\nA null-terminated string that contains the absolute or relative path to a file that contains the\nsource indexing stream. Can be NULL if Buffer is not NULL.\n[in, optional] Buffer\nA buffer that contains the source indexing stream. Can be NULL if StreamFile is not NULL.\n[in] Size\nSize, in bytes, of the Buffer buffer.\nIf the function succeeds, the return value is TRUE.\nSyntax\nBOOL IMAGEAPI SymAddSourceStream(\n [in] HANDLE hProcess,\n [in] ULONG64 Base,\n [in, optional] PCSTR StreamFile,\n [in, optional] PBYTE Buffer,\n [in] size_t Size\n);\nParameters\nReturn value\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nSymAddSourceStream adds a stream of data formatted for use by the source Server to a\ndesignated module. The caller can pass the stream either as a buffer in the Buffer parameter or\na file in the StreamFile parameter. If both parameters are filled, then the function uses the\nBuffer parameter. If both parameters are NULL, then the function returns FALSE and the lasterror code is set to ERROR_INVALID_PARAMETER.\nIt is important to note that SymAddSourceStream does not add the stream to any\ncorresponding PDB in order to persist the data. This function is used by those\nprogrammatically implementing their own debuggers in scenarios in which a PDB is not\navailable.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.8 or later\nRemarks\nRequirements\nﾉ Expand table","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3237,"title":"SymAddSymbol function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symaddsymbol","function","dbghelp","adds","virtual","symbol","the","specified","module","article08","2022","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","baseofdll","base","address","name","maximum","size","max","sym","characters","within","range","bytes","parameter","optional","flags","unused","syntax","bool","imageapi"],"errorCode":"","eventId":"","severity":"Low","summary":"Adds a virtual symbol to the specified module.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymAddSymbol function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymAddSymbol function (dbghelp.h)\nArticle08/09/2022\nAdds a virtual symbol to the specified module.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] BaseOfDll\nThe base address of the module.\n[in] Name\nThe name of the symbol. The maximum size of a symbol name is MAX_SYM_NAME characters.\n[in] Address\nThe address of the symbol. This address must be within the address range of the specified\nmodule.\n[in] Size\nThe size of the symbol, in bytes. This parameter is optional.\n[in] Flags\nThis parameter is unused.\nSyntax\nBOOL IMAGEAPI SymAddSymbol(\n [in] HANDLE hProcess,\n [in] ULONG64 BaseOfDll,\n [in] PCSTR Name,\n [in] DWORD64 Address,\n [in] DWORD Size,\n [in] DWORD Flags\n);\nParameters\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.0 or later\nDbgHelp Functions\nSymDeleteSymbol\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3238,"title":"SymCleanup function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symcleanup","function","dbghelp","deallocates","all","resources","associated","with","the","process","handle","article10","2021","hprocess","that","was","originally","passed","syminitialize","succeeds","return","value","true","fails","false","retrieve","extended","error","information","call","getlasterror","this","frees","failure","causes","memory","and","resource","leaks","calling"],"errorCode":"","eventId":"","severity":"Low","summary":"Deallocates all resources associated with the process handle.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymCleanup function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymCleanup function (dbghelp.h)\nArticle10/13/2021\nDeallocates all resources associated with the process handle.\nC++\n[in] hProcess\nA handle to the process that was originally passed to the SymInitialize function.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThis function frees all resources associated with the process handle. Failure to call this function\ncauses memory and resource leaks in the calling application.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, call SymInitialize only when your process starts and SymCleanup only when your\nprocess ends. It is not necessary for each thread in the process to call these functions.\nFor an example, see Terminating the Symbol Handler.\nSyntax\nBOOL IMAGEAPI SymCleanup(\n [in] HANDLE hProcess\n);\nParameters\nReturn value\nRemarks\nExamples\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nSymInitialize\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3239,"title":"SymCompareInlineTrace function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symcompareinlinetrace","function","dbghelp","hprocess","handle","process","article10","2021","compares","two","inline","traces","this","must","have","been","previously","passed","the","syminitialize","address1","first","address","compared","inlinecontext1","context","for","trace","retaddress1","return","address2","second","retaddress2","syntax","dword","imageapi","dword64","parameters","indicates","result"],"errorCode":"","eventId":"","severity":"Low","summary":"C++\n[in] hProcess\nA handle to a process.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymCompareInlineTrace function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymCompareInlineTrace function\n(dbghelp.h)\nArticle10/13/2021\nCompares two inline traces.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] Address1\nThe first address to be compared.\n[in] InlineContext1\nThe inline context for the first trace to be compared.\n[in] RetAddress1\nThe return address of the first trace to be compared.\n[in] Address2\nThe second address to be compared.\n[in] RetAddress2\nSyntax\nDWORD IMAGEAPI SymCompareInlineTrace(\n [in] HANDLE hProcess,\n [in] DWORD64 Address1,\n [in] DWORD InlineContext1,\n [in] DWORD64 RetAddress1,\n [in] DWORD64 Address2,\n [in] DWORD64 RetAddress2\n);\nParameters\nThe return address of the second trace to be compared.\nIndicates the result of the comparison.\nReturn code/value Description\nSYM_INLINE_COMP_ERROR\n0\nAn error occurred.\nSYM_INLINE_COMP_IDENTICAL\n1\nThe inline contexts are identical.\nSYM_INLINE_COMP_STEPIN\n2\nThe inline trace is a step-in of an inline function.\nSYM_INLINE_COMP_STEPOUT\n3\nThe inline trace is a step-out of an inline function.\nSYM_INLINE_COMP_STEPOVER\n4\nThe inline trace is a step-over of an inline function.\nSYM_INLINE_COMP_DIFFERENT\n5\nThe inline contexts are different.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary DbgHelp.lib\nDLL DbgHelp.dll\nRedistributable DbgHelp.dll 6.2 or later\nReturn value\nﾉ Expand table\nRequirements\nﾉ Expand table","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3240,"title":"SymDeleteSymbol function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symdeletesymbol","function","dbghelp","deletes","virtual","symbol","from","the","specified","module","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","baseofdll","base","address","optional","name","within","range","flags","parameter","unused","succeeds","return","value","true","syntax","bool","imageapi","ulong64"],"errorCode":"","eventId":"","severity":"Low","summary":"Deletes a virtual symbol from the specified module.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymDeleteSymbol function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymDeleteSymbol function (dbghelp.h)\nArticle02/22/2024\nDeletes a virtual symbol from the specified module.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] BaseOfDll\nThe base address of the module.\n[in, optional] Name\nThe name of the symbol.\n[in] Address\nThe address of the symbol. This address must be within the address range of the specified\nmodule.\n[in] Flags\nThis parameter is unused.\nIf the function succeeds, the return value is TRUE.\nSyntax\nBOOL IMAGEAPI SymDeleteSymbol(\n [in] HANDLE hProcess,\n [in] ULONG64 BaseOfDll,\n [in, optional] PCSTR Name,\n [in] DWORD64 Address,\n [in] DWORD Flags\n);\nParameters\nReturn value\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.0 or later\nDbgHelp Functions\nSymAddSymbol\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3241,"title":"SymEnumerateModules function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symenumeratemodules","function","dbghelp","enumerates","all","modules","that","have","been","loaded","for","the","process","symloadmodule64","symloadmoduleex","article07","2022","hprocess","handle","was","originally","passed","syminitialize","enummodulescallback","enumeration","callback","this","called","once","per","module","more","information","see","symenumeratemodulesproc64","optional","usercontext","user","defined","value"],"errorCode":"","eventId":"","severity":"Low","summary":"Enumerates all modules that have been loaded for the process by the SymLoadModule64 or\nSymLoadModuleEx function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymEnumerateModules function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymEnumerateModules function\n(dbghelp.h)\nArticle07/27/2022\nEnumerates all modules that have been loaded for the process by the SymLoadModule64 or\nSymLoadModuleEx function.\nC++\n[in] hProcess\nA handle to the process that was originally passed to the SymInitialize function.\n[in] EnumModulesCallback\nThe enumeration callback function. This function is called once per module. For more\ninformation, see SymEnumerateModulesProc64.\n[in, optional] UserContext\nA user-defined value or NULL. This value is simply passed to the callback function. Normally,\nthis parameter is used by an application to pass a pointer to a data structure that lets the\ncallback function establish some type of context.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nSyntax\nBOOL IMAGEAPI SymEnumerateModules(\n [in] HANDLE hProcess,\n [in] PSYM_ENUMMODULES_CALLBACK EnumModulesCallback,\n [in, optional] PVOID UserContext\n);\nParameters\nReturn value\nThe SymEnumerateModules64 function enumerates all modules that have been loaded for the\nprocess by SymLoadModule64, even if the symbol loading is deferred. The enumeration\ncallback function is called once for each module and is passed the module information.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nSymEnumerateModulesW64 is defined as follows in Dbghelp.h.\nC++\nThis function supersedes the SymEnumerateModules function. For more information, see\nUpdated Platform Support. SymEnumerateModules is defined as follows in Dbghelp.h.\nC++\nRemarks\nBOOL\nIMAGEAPI\nSymEnumerateModulesW64(\n __in HANDLE hProcess,\n __in PSYM_ENUMMODULES_CALLBACKW64 EnumModulesCallback,\n __in_opt PVOID UserContext\n );\n#ifdef DBGHELP_TRANSLATE_TCHAR\n#define SymEnumerateModules64 SymEnumerateModulesW64\n#endif\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define SymEnumerateModules SymEnumerateModules64\n#else\nBOOL\nIMAGEAPI\nSymEnumerateModules(\n __in HANDLE hProcess,\n __in PSYM_ENUMMODULES_CALLBACK EnumModulesCallback,\n __in_opt PVOID UserContext\n );\n#endif\nExamples\nFor an example, see Enumerating Symbol Modules.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nSymEnumerateModulesProc64\nSymInitialize\nSymLoadModule64\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3242,"title":"PSYM_ENUMMODULES_CALLBACK callback function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["psym","enummodules","callback","function","dbghelp","application","defined","used","with","the","symenumeratemodules64","article02","2024","called","once","for","each","enumerated","module","and","receives","information","callback64","callbackw64","types","define","pointer","this","symenumeratemodulesproc64","placeholder","name","modulename","baseofdll","base","address","where","loaded","into","memory","optional"],"errorCode":"","eventId":"","severity":"Low","summary":"An application-defined callback function used with the SymEnumerateModules64 function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to PSYM_ENUMMODULES_CALLBACK callback function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"PSYM_ENUMMODULES_CALLBACK callback\nfunction (dbghelp.h)\nArticle02/22/2024\nAn application-defined callback function used with the SymEnumerateModules64 function. It is\ncalled once for each enumerated module, and receives the module information.\nThe PSYM_ENUMMODULES_CALLBACK64 and PSYM_ENUMMODULES_CALLBACKW64 types\ndefine a pointer to this callback function. SymEnumerateModulesProc64 is a placeholder for\nthe application-defined function name.\nC++\n[in] ModuleName\nThe name of the module.\n[in] BaseOfDll\nThe base address where the module is loaded into memory.\n[in, optional] UserContext\nThe user-defined value specified in SymEnumerateModules64, or NULL. Typically, this\nparameter is used by an application to pass a pointer to a data structure that lets the callback\nfunction establish some type of context.\nSyntax\nPSYM_ENUMMODULES_CALLBACK PsymEnummodulesCallback;\nBOOL PsymEnummodulesCallback(\n [in] PCSTR ModuleName,\n [in] ULONG BaseOfDll,\n [in, optional] PVOID UserContext\n)\n{...}\nParameters\nReturn value\nIf the return value is TRUE, the enumeration will continue.\nIf the return value is FALSE, the enumeration will stop.\nThe calling application is called once per module until all modules are enumerated, or until the\nenumeration callback function returns FALSE.\nThis callback function supersedes the PSYM_ENUMMODULES_CALLBACK callback function.\nPSYM_ENUMMODULES_CALLBACK is defined as follows in DbgHelp.h.\nC++\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nSymEnumerateModules64\nRemarks\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define PSYM_ENUMMODULES_CALLBACK PSYM_ENUMMODULES_CALLBACK64\n#else\ntypedef BOOL\n(CALLBACK *PSYM_ENUMMODULES_CALLBACK)(\n __in PCSTR ModuleName,\n __in ULONG BaseOfDll,\n __in_opt PVOID UserContext\n );\n#endif\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3243,"title":"SymEnumerateSymbols function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symenumeratesymbols","function","dbghelp","enumerates","all","the","symbols","for","specified","module","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","baseofdll","base","address","which","are","enumerated","enumsymbolscallback","callback","that","receives","symbol","information","more","see","symenumeratesymbolsproc64","optional","usercontext","user"],"errorCode":"","eventId":"","severity":"Low","summary":"Enumerates all the symbols for a specified module.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymEnumerateSymbols function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymEnumerateSymbols function\n(dbghelp.h)\nArticle02/22/2024\nEnumerates all the symbols for a specified module.\n \nC++\n[in] hProcess\nA handle to the process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] BaseOfDll\nThe base address of the module for which symbols are to be enumerated.\n[in] EnumSymbolsCallback\nThe callback function that receives the symbol information. For more information, see\nSymEnumerateSymbolsProc64.\n[in, optional] UserContext\nA user-defined value or NULL. This value is passed to the callback function. Typically, this\nparameter is used by an application to pass a pointer to a data structure that enables the\nNote This function is provided only for compatibility. Applications should use\nSymEnumSymbols, which is faster and more powerful.\nSyntax\nDBHLP_DEPRECIATED BOOL IMAGEAPI SymEnumerateSymbols(\n [in] HANDLE hProcess,\n [in] ULONG BaseOfDll,\n [in] PSYM_ENUMSYMBOLS_CALLBACK EnumSymbolsCallback,\n [in, optional] PVOID UserContext\n);\nParameters\ncallback function establish some type of context.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe SymEnumerateSymbols64 function enumerates all the symbols for the specified module.\nThe module information is located by the BaseOfDll parameter. The callback function is called\nonce per symbol and is passed the information for each symbol.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nThe Unicode version of this function, SymEnumerateSymbolsW64 is defined as follows in\nDbghelp.h.\nC++\nThis function supersedes the SymEnumerateSymbols function. For more information, see\nUpdated Platform Support. SymEnumerateSymbols is defined as follows in Dbghelp.h.\nC++\nReturn value\nRemarks\nBOOL\nIMAGEAPI\nSymEnumerateSymbolsW64(\n __in HANDLE hProcess,\n __in ULONG64 BaseOfDll,\n __in PSYM_ENUMSYMBOLS_CALLBACK64W EnumSymbolsCallback,\n __in_opt PVOID UserContext\n );\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define SymEnumerateSymbols SymEnumerateSymbols64\n#define SymEnumerateSymbolsW SymEnumerateSymbolsW64\n#else\nBOOL\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nSymEnumSymbols\nSymEnumerateSymbolsProc64\nSymInitialize\nIMAGEAPI\nSymEnumerateSymbols(\n __in HANDLE hProcess,\n __in ULONG BaseOfDll,\n __in PSYM_ENUMSYMBOLS_CALLBACK EnumSymbolsCallback,\n __in_opt PVOID UserContext\n );\nBOOL\nIMAGEAPI\nSymEnumerateSymbolsW(\n __in HANDLE hProcess,\n __in ULONG BaseOfDll,\n __in PSYM_ENUMSYMBOLS_CALLBACKW EnumSymbolsCallback,\n __in_opt PVOID UserContext\n );\n#endif\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3244,"title":"PSYM_ENUMSYMBOLS_CALLBACK callback function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["psym","enumsymbols","callback","function","dbghelp","application","defined","used","with","the","symenumeratesymbols64","article02","2024","called","once","for","each","enumerated","symbol","and","receives","information","callback64","callback64w","types","define","pointer","this","symenumeratesymbolsproc64","placeholder","name","symbolname","can","undecorated","symopt","undname","option","symsetoptions","symboladdress","virtual"],"errorCode":"","eventId":"","severity":"Low","summary":"An application-defined callback function used with the SymEnumerateSymbols64 function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to PSYM_ENUMSYMBOLS_CALLBACK callback function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"PSYM_ENUMSYMBOLS_CALLBACK callback\nfunction (dbghelp.h)\nArticle02/22/2024\nAn application-defined callback function used with the SymEnumerateSymbols64 function. It is\ncalled once for each enumerated symbol, and receives the symbol information.\nThe PSYM_ENUMSYMBOLS_CALLBACK64 and PSYM_ENUMSYMBOLS_CALLBACK64W types\ndefine a pointer to this callback function. SymEnumerateSymbolsProc64 is a placeholder for\nthe application-defined function name.\n \nC++\n[in] SymbolName\nThe name of the symbol. The name can be undecorated if the SYMOPT_UNDNAME option is\nused with the SymSetOptions function.\n[in] SymbolAddress\nThe virtual address for the beginning of the symbol.\n[in] SymbolSize\nNote This function is provided only for compatibility. Applications should use\nSymEnumSymbols.\nSyntax\nPSYM_ENUMSYMBOLS_CALLBACK PsymEnumsymbolsCallback;\nBOOL PsymEnumsymbolsCallback(\n [in] PCSTR SymbolName,\n [in] ULONG SymbolAddress,\n [in] ULONG SymbolSize,\n [in, optional] PVOID UserContext\n)\n{...}\nParameters\nThe size of the symbol, in bytes. The size is calculated and is actually a best-guess value. In\nsome cases, the value can be zero.\n[in, optional] UserContext\nThe user-defined value specified in SymEnumerateSymbols64, or NULL. Typically, this\nparameter is used by an application to pass a pointer to a data structure that lets the callback\nfunction establish some type of context.\nIf the function returns TRUE, the enumeration will continue.\nIf the function returns FALSE, the enumeration will stop.\nThe calling application is called once per symbol until all the symbols are enumerated or until\nthe enumeration callback function returns FALSE.\nThis callback function supersedes the PSYM_ENUMSYMBOLS_CALLBACK callback function.\nPSYM_ENUMSYMBOLS_CALLBACK is defined as follows in Dbghelp.h.\nC++\nReturn value\nRemarks\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define PSYM_ENUMSYMBOLS_CALLBACK PSYM_ENUMSYMBOLS_CALLBACK64\n#define PSYM_ENUMSYMBOLS_CALLBACKW PSYM_ENUMSYMBOLS_CALLBACK64W\n#else\ntypedef BOOL\n(CALLBACK *PSYM_ENUMSYMBOLS_CALLBACK)(\n __in PCSTR SymbolName,\n __in ULONG SymbolAddress,\n __in ULONG SymbolSize,\n __in_opt PVOID UserContext\n );\ntypedef BOOL\n(CALLBACK *PSYM_ENUMSYMBOLS_CALLBACKW)(\n __in PCWSTR SymbolName,\n __in ULONG SymbolAddress,\n __in ULONG SymbolSize,\n __in_opt PVOID UserContext\n );\n#endif\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nSymEnumSymbols\nSymEnumerateSymbols64\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3245,"title":"SymEnumLines function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symenumlines","function","dbghelp","enumerates","all","lines","the","specified","module","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","base","address","optional","obj","name","file","within","scope","enumeration","limited","parameter","null","empty","string","files","are","searched","wildcard","expression"],"errorCode":"","eventId":"","severity":"Low","summary":"Enumerates all lines in the specified module.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymEnumLines function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymEnumLines function (dbghelp.h)\nArticle02/22/2024\nEnumerates all lines in the specified module.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] Base\nThe base address of the module.\n[in, optional] Obj\nThe name of an .obj file within the module. The scope of the enumeration is limited to this file.\nIf this parameter is NULL or an empty string, all .obj files are searched.\n[in, optional] File\nA wildcard expression that indicates the names of the source files to be searched. If this\nparameter is NULL or an empty string, all files are searched.\n[in] EnumLinesCallback\nA SymEnumLinesProc callback function that receives the line information.\n[in, optional] UserContext\nSyntax\nBOOL IMAGEAPI SymEnumLines(\n [in] HANDLE hProcess,\n [in] ULONG64 Base,\n [in, optional] PCSTR Obj,\n [in, optional] PCSTR File,\n [in] PSYM_ENUMLINES_CALLBACK EnumLinesCallback,\n [in, optional] PVOID UserContext\n);\nParameters\nA user-defined value that is passed to the callback function, or NULL. This parameter is\ntypically used by an application to pass a pointer to a data structure that provides context for\nthe callback function.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThis function is supported for PDB information only. If you have COFF information, try using\none of the SymGetLineXXX functions.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.1 or later\nDbgHelp Functions\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nSee also\nSymEnumLinesProc","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3246,"title":"PSYM_ENUMLINES_CALLBACK callback function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["psym","enumlines","callback","function","dbghelp","application","defined","used","with","the","symenumlines","and","symenumsourcelines","functions","article02","2024","callbackw","types","define","pointer","this","symenumlinesproc","placeholder","for","applicationdefined","name","lineinfo","srccodeinfo","structure","that","provides","information","about","line","usercontext","user","value","passed","from","null"],"errorCode":"","eventId":"","severity":"Low","summary":"An application-defined callback function used with the SymEnumLines and\nSymEnumSourceLines functions.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to PSYM_ENUMLINES_CALLBACK callback function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"PSYM_ENUMLINES_CALLBACK callback\nfunction (dbghelp.h)\nArticle02/22/2024\nAn application-defined callback function used with the SymEnumLines and\nSymEnumSourceLines functions.\nThe PSYM_ENUMLINES_CALLBACK and PSYM_ENUMLINES_CALLBACKW types define a\npointer to this callback function. SymEnumLinesProc is a placeholder for the applicationdefined function name.\nC++\n[in] LineInfo\nA pointer to a SRCCODEINFO structure that provides information about the line.\n[in] UserContext\nThe user-defined value passed from the SymEnumLines function, or NULL. This parameter is\ntypically used by an application to pass a pointer to a data structure that provides context\ninformation for the callback function.\nIf the function returns TRUE, the enumeration will continue.\nIf the function returns FALSE, the enumeration will stop.\nSyntax\nPSYM_ENUMLINES_CALLBACK PsymEnumlinesCallback;\nBOOL PsymEnumlinesCallback(\n [in] PSRCCODEINFO LineInfo,\n [in] PVOID UserContext\n)\n{...}\nParameters\nReturn value\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nRedistributable DbgHelp.dll 6.1 or later\nDbgHelp Functions\nSymEnumLines\nSymEnumSourceLines\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3247,"title":"SymEnumProcesses function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symenumprocesses","function","dbghelp","enumerates","each","process","that","has","called","the","syminitialize","article02","2024","enumprocessescallback","symenumprocessesproc","callback","receives","information","usercontext","user","defined","value","passed","null","this","parameter","typically","used","application","pass","pointer","data","structure","provides","context","for","succeeds","return","true","fails"],"errorCode":"","eventId":"","severity":"Low","summary":"Enumerates each process that has called the SymInitialize function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymEnumProcesses function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymEnumProcesses function (dbghelp.h)\nArticle02/22/2024\nEnumerates each process that has called the SymInitialize function.\nC++\n[in] EnumProcessesCallback\nA SymEnumProcessesProc callback function that receives the process information.\n[in] UserContext\nA user-defined value that is passed to the callback function, or NULL. This parameter is\ntypically used by an application to pass a pointer to a data structure that provides context for\nthe callback function.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nSyntax\nBOOL IMAGEAPI SymEnumProcesses(\n [in] PSYM_ENUMPROCESSES_CALLBACK EnumProcessesCallback,\n [in] PVOID UserContext\n);\nParameters\nReturn value\nRemarks\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.3 or later\nDbgHelp Functions\nSymEnumProcessesProc\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3248,"title":"PSYM_ENUMPROCESSES_CALLBACK callback function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["psym","enumprocesses","callback","function","dbghelp","application","defined","used","with","the","symenumprocesses","article02","2024","type","defines","pointer","this","symenumprocessesproc","placeholder","for","name","hprocess","handle","process","usercontext","user","value","passed","from","null","parameter","typically","pass","data","structure","that","provides","context","information","returns"],"errorCode":"","eventId":"","severity":"Low","summary":"An application-defined function used with the SymEnumProcesses function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to PSYM_ENUMPROCESSES_CALLBACK callback function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"PSYM_ENUMPROCESSES_CALLBACK\ncallback function (dbghelp.h)\nArticle02/22/2024\nAn application-defined function used with the SymEnumProcesses function.\nThe PSYM_ENUMPROCESSES_CALLBACK type defines a pointer to this callback function.\nSymEnumProcessesProc is a placeholder for the application-defined function name.\nC++\n[in] hProcess\nA handle to the process.\n[in] UserContext\nThe user-defined value passed from the SymEnumProcesses function, or NULL. This parameter\nis typically used by an application to pass a pointer to a data structure that provides context\ninformation for the callback function.\nIf the function returns TRUE, the enumeration will continue.\nIf the function returns FALSE, the enumeration will stop.\nSyntax\nPSYM_ENUMPROCESSES_CALLBACK PsymEnumprocessesCallback;\nBOOL PsymEnumprocessesCallback(\n [in] HANDLE hProcess,\n [in] PVOID UserContext\n)\n{...}\nParameters\nReturn value\nRequirements\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nRedistributable DbgHelp.dll 6.3 or later\nSymEnumProcesses\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3249,"title":"SymEnumSourceFiles function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symenumsourcefiles","function","dbghelp","enumerates","all","source","files","process","article02","2024","hprocess","handle","this","must","have","been","previously","passed","the","syminitialize","modbase","base","address","module","value","zero","and","mask","contains","exclamation","point","looks","across","modules","does","not","contain","uses","scope","established"],"errorCode":"","eventId":"","severity":"Low","summary":"Enumerates all source files in a process.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymEnumSourceFiles function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymEnumSourceFiles function (dbghelp.h)\nArticle02/22/2024\nEnumerates all source files in a process.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] ModBase\nThe base address of the module. If this value is zero and Mask contains an exclamation point\n(!), the function looks across modules. If this value is zero and Mask does not contain an\nexclamation point, the function uses the scope established by the SymSetContext function.\n[in, optional] Mask\nA wildcard expression that indicates the names of the source files to be enumerated. To specify\na module name, use the !mod syntax.\nIf this parameter is NULL, the function will enumerate all files.\n[in] cbSrcFiles\nPointer to a SymEnumSourceFilesProc callback function that receives the source file\ninformation.\n[in, optional] UserContext\nSyntax\nBOOL IMAGEAPI SymEnumSourceFiles(\n [in] HANDLE hProcess,\n [in] ULONG64 ModBase,\n [in, optional] PCSTR Mask,\n [in] PSYM_ENUMSOURCEFILES_CALLBACK cbSrcFiles,\n [in, optional] PVOID UserContext\n);\nParameters\nUser-defined value that is passed to the callback function, or NULL. This parameter is typically\nused by an application to pass a pointer to a data structure that provides context for the\ncallback function.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.2 or later\nDbgHelp Functions\nSymEnumSourceFilesProc\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3250,"title":"PSYM_ENUMSOURCEFILES_CALLBACK callback function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["psym","enumsourcefiles","callback","function","dbghelp","application","defined","used","with","the","symenumsourcefiles","article02","2024","and","callbackw","types","define","pointer","this","symenumsourcefilesproc","placeholder","for","name","psourcefile","sourcefile","structure","that","provides","information","about","source","file","optional","usercontext","user","value","passed","from","null","parameter"],"errorCode":"","eventId":"","severity":"Low","summary":"An application-defined callback function used with the SymEnumSourceFiles function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to PSYM_ENUMSOURCEFILES_CALLBACK callback function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"PSYM_ENUMSOURCEFILES_CALLBACK\ncallback function (dbghelp.h)\nArticle02/22/2024\nAn application-defined callback function used with the SymEnumSourceFiles function.\nThe PSYM_ENUMSOURCEFILES_CALLBACK and PSYM_ENUMSOURCEFILES_CALLBACKW\ntypes define a pointer to this callback function. SymEnumSourceFilesProc is a placeholder for\nthe application-defined function name.\nC++\n[in] pSourceFile\nA pointer to a SOURCEFILE structure that provides information about the source file.\n[in, optional] UserContext\nThe user-defined value passed from the SymEnumSourceFiles function, or NULL. This\nparameter is typically used by an application to pass a pointer to a data structure that provides\ncontext information for the callback function.\nIf the function returns TRUE, the enumeration will continue.\nIf the function returns FALSE, the enumeration will stop.\nSyntax\nPSYM_ENUMSOURCEFILES_CALLBACK PsymEnumsourcefilesCallback;\nBOOL PsymEnumsourcefilesCallback(\n [in] PSOURCEFILE pSourceFile,\n [in, optional] PVOID UserContext\n)\n{...}\nParameters\nReturn value\nRequirements\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nRedistributable DbgHelp.dll 6.2 or later\nDbgHelp Functions\nSOURCEFILE\nSymEnumSourceFiles\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3251,"title":"SymEnumSourceFileTokens function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symenumsourcefiletokens","function","dbghelp","enumerates","all","individual","entries","module","source","server","data","available","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","the","syminitialize","base","address","callback","symenumsourcefiletokensproc","that","receives","symbol","information","succeeds","return","value","true","fails","false","retrieve"],"errorCode":"","eventId":"","severity":"Low","summary":"Enumerates all individual entries in a module's source server data, if available.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymEnumSourceFileTokens function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymEnumSourceFileTokens function\n(dbghelp.h)\nArticle02/22/2024\nEnumerates all individual entries in a module's source server data, if available.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] Base\nThe base address of the module.\n[in] Callback\nA SymEnumSourceFileTokensProc callback function that receives the symbol information.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nSyntax\nBOOL IMAGEAPI SymEnumSourceFileTokens(\n [in] HANDLE hProcess,\n [in] ULONG64 Base,\n [in] PENUMSOURCEFILETOKENSCALLBACK Callback\n);\nParameters\nReturn value\nRemarks\nSome modules have PDB files with source server information detailing the version control\ninformation for each of the source files used to create each individual module. An application\ncan use this function to enumerate the data for every source file that was \"source indexed\".\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.8 or later\nDbgHelp Functions\nSource Server\nSymEnumSourceFileTokensProc\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3252,"title":"PENUMSOURCEFILETOKENSCALLBACK callback function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["penumsourcefiletokenscallback","callback","function","dbghelp","application","defined","used","with","the","symenumsourcefiletokens","which","enumerates","source","server","version","control","information","stored","pdb","for","module","article02","2024","type","defines","pointer","this","symenumsourcefiletokensproc","placeholder","name","token","opaque","data","structure","that","contains","corresponding","particular","individual","file"],"errorCode":"","eventId":"","severity":"Low","summary":"An application-defined callback function used with the SymEnumSourceFileTokens function\nwhich enumerates the source server version control information stored in the PDB for a\nmodule.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to PENUMSOURCEFILETOKENSCALLBACK callback function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"PENUMSOURCEFILETOKENSCALLBACK\ncallback function (dbghelp.h)\nArticle02/22/2024\nAn application-defined callback function used with the SymEnumSourceFileTokens function\nwhich enumerates the source server version control information stored in the PDB for a\nmodule.\nThe PENUMSOURCEFILETOKENSCALLBACK type defines a pointer to this callback function.\nSymEnumSourceFileTokensProc is a placeholder for the application-defined function name.\nC++\n[in] token\nA pointer to an opaque data structure that contains the version control information\ncorresponding to a particular individual source file. The usage of this token is detailed below.\n[in] size\nThe size of the data in the token parameter.\nIf the function returns TRUE, the enumeration will continue.\nIf the function returns FALSE, the enumeration will stop.\nSyntax\nPENUMSOURCEFILETOKENSCALLBACK Penumsourcefiletokenscallback;\nBOOL Penumsourcefiletokenscallback(\n [in] PVOID token,\n [in] size_t size\n)\n{...}\nParameters\nReturn value\nRemarks\nAn application can use this token to extract a source file from version control by calling\nSymGetSourceFileFromToken.\nTo get individual variables from the token, call SymGetSourceVarFromToken. The names of the\nvariables differ based on the scripts used to create the tokens. See Source Server for details.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nRedistributable DbgHelp.dll 6.8 or later\nDbgHelp Functions\nSource Server\nSymEnumSourceFileTokens\nSymGetSourceFile\nSymGetSourceFileFromToken\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3253,"title":"SymEnumSourceLines function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symenumsourcelines","function","dbghelp","enumerates","all","source","lines","module","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","the","syminitialize","base","address","optional","obj","name","file","within","scope","enumeration","limited","parameter","null","empty","string","files","are","searched","wildcard","expression"],"errorCode":"","eventId":"","severity":"Low","summary":"Enumerates all source lines in a module.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymEnumSourceLines function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymEnumSourceLines function (dbghelp.h)\nArticle02/22/2024\nEnumerates all source lines in a module.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] Base\nThe base address of the module.\n[in, optional] Obj\nThe name of an .obj file within the module. The scope of the enumeration is limited to this file.\nIf this parameter is NULL or an empty string, all .obj files are searched.\n[in, optional] File\nA wildcard expression that indicates the names of the source files to be searched. If this\nparameter is NULL or an empty string, all files are searched.\n[in, optional] Line\nThe line number of a line within the module. The scope of the enumeration is limited to this\nline. If this parameter is 0, all lines are searched.\nSyntax\nBOOL IMAGEAPI SymEnumSourceLines(\n [in] HANDLE hProcess,\n [in] ULONG64 Base,\n [in, optional] PCSTR Obj,\n [in, optional] PCSTR File,\n [in, optional] DWORD Line,\n [in] DWORD Flags,\n [in] PSYM_ENUMLINES_CALLBACK EnumLinesCallback,\n [in, optional] PVOID UserContext\n);\nParameters\n[in] Flags\nIf this parameter is ESLFLAG_FULLPATH, the function matches the full path in the File\nparameter.\n[in] EnumLinesCallback\nA SymEnumLinesProc callback function that receives the line information.\n[in, optional] UserContext\nA user-defined value that is passed to the callback function, or NULL. This parameter is\ntypically used by an application to pass a pointer to a data structure that provides context for\nthe callback function.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.4 or later\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nDbgHelp Functions\nSymEnumLinesProc\nSymInitialize\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3254,"title":"SymEnumSymbols function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symenumsymbols","function","dbghelp","enumerates","all","symbols","process","article08","2022","hprocess","handle","this","must","have","been","previously","passed","the","syminitialize","baseofdll","base","address","module","value","zero","and","mask","contains","exclamation","point","looks","across","modules","does","not","contain","uses","scope","established","symsetcontext"],"errorCode":"","eventId":"","severity":"Low","summary":"Enumerates all symbols in a process.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymEnumSymbols function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymEnumSymbols function (dbghelp.h)\nArticle08/09/2022\nEnumerates all symbols in a process.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] BaseOfDll\nThe base address of the module. If this value is zero and Mask contains an exclamation point\n(!), the function looks across modules. If this value is zero and Mask does not contain an\nexclamation point, the function uses the scope established by the SymSetContext function.\n[in, optional] Mask\nA wildcard string that indicates the names of the symbols to be enumerated. The text can\noptionally contain the wildcards, \"*\" and \"?\".\nTo specify a specific module or set of modules, begin the text with a wildcard string specifying\nthe module, followed by an exclamation point. When specifying a module, BaseOfDll is\nignored.\nValue Meaning\nSyntax\nBOOL IMAGEAPI SymEnumSymbols(\n [in] HANDLE hProcess,\n [in] ULONG64 BaseOfDll,\n [in, optional] PCSTR Mask,\n [in] PSYM_ENUMERATESYMBOLS_CALLBACK EnumSymbolsCallback,\n [in, optional] PVOID UserContext\n);\nParameters\nﾉ Expand table\nfoo If BaseOfDll is not zero, then SymEnumSymbols will look for a\nglobal symbol named \"foo\".\nIf BaseOfDll is zero, then SymEnumSymbols will look for a\nlocal symbol named \"foo\" within the scope established by the\nmost recent call to the SymSetContext function.\nfoo? If BaseOfDll is not zero, then SymEnumSymbols will look for a\nglobal symbol that starts with \"foo\" and contains one extra\ncharacter afterwards, such as \"fool\" and \"foot\".\nIf BaseOfDll is zero, then SymEnumSymbols will look for a\nsymbol that starts with \"foo\" and contains one extra character\nafterwards, such as \"fool\" and \"foot\". The search would be\nwithin the scope established by the most recent call to the\nSymSetContext function.\nfoo*!bar SymEnumSymbols will look in every loaded module that starts\nwith the text \"foo\" for a symbol called \"bar\". It could find\nmatches such as these, \"foot!bar\", \"footlocker!bar\", and\n\"fool!bar\".\n*!* SymEnumSymbols will enumerate every symbol in every\nloaded module.\n[in] EnumSymbolsCallback\nA SymEnumSymbolsProc callback function that receives the symbol information.\n[in, optional] UserContext\nA user-defined value that is passed to the callback function, or NULL. This parameter is\ntypically used by an application to pass a pointer to a data structure that provides context for\nthe callback function.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\nReturn value\nRemarks\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nFor an example, see Enumerating Symbols.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nSymEnumSymbolsProc\nExamples\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3255,"title":"SymEnumSymbolsEx function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symenumsymbolsex","function","dbghelp","enumerates","all","symbols","process","article08","2022","hprocess","handle","this","must","have","been","previously","passed","the","syminitialize","baseofdll","base","address","module","value","zero","and","mask","contains","exclamation","point","looks","across","modules","does","not","contain","uses","scope","established","symsetcontext"],"errorCode":"","eventId":"","severity":"Low","summary":"Enumerates all symbols in a process.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymEnumSymbolsEx function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymEnumSymbolsEx function (dbghelp.h)\nArticle08/09/2022\nEnumerates all symbols in a process.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] BaseOfDll\nThe base address of the module. If this value is zero and Mask contains an exclamation point\n(!), the function looks across modules. If this value is zero and Mask does not contain an\nexclamation point, the function uses the scope established by the SymSetContext function.\n[in, optional] Mask\nA wildcard string that indicates the names of the symbols to be enumerated. The text can\noptionally contain the wildcards, \"*\" and \"?\".\nTo specify a specific module or set of modules, begin the text with a wildcard string specifying\nthe module, followed by an exclamation point. When specifying a module, BaseOfDll is\nignored.\nValue Meaning\nSyntax\nBOOL IMAGEAPI SymEnumSymbolsEx(\n [in] HANDLE hProcess,\n [in] ULONG64 BaseOfDll,\n [in, optional] PCSTR Mask,\n [in] PSYM_ENUMERATESYMBOLS_CALLBACK EnumSymbolsCallback,\n [in, optional] PVOID UserContext,\n [in] DWORD Options\n);\nParameters\nﾉ Expand table\nfoo If BaseOfDll is not zero, then SymEnumSymbols will look for a\nglobal symbol named \"foo\".\nIf BaseOfDll is zero, then SymEnumSymbols will look for a local\nsymbol named \"foo\" within the scope established by the most\nrecent call to the SymSetContext function.\nfoo? If BaseOfDll is not zero, then SymEnumSymbols will look for a\nglobal symbol that starts with \"foo\" and contains one extra\ncharacter afterwards, such as \"fool\" and \"foot\".\nIf BaseOfDll is zero, then SymEnumSymbols will look for a\nsymbol that starts with \"foo\" and contains one extra character\nafterwards, such as \"fool\" and \"foot\". The search would be\nwithin the scope established by the most recent call to the\nSymSetContext function.\nfoo*!bar SymEnumSymbols will look in every loaded module that starts\nwith the text \"foo\" for a symbol called \"bar\". It could find\nmatches such as these, \"foot!bar\", \"footlocker!bar\", and\n\"fool!bar\".\n*!* SymEnumSymbols will enumerate every symbol in every\nloaded module.\n[in] EnumSymbolsCallback\nA SymEnumSymbolsProc callback function that receives the symbol information.\n[in, optional] UserContext\nA user-defined value that is passed to the callback function, or NULL. This parameter is\ntypically used by an application to pass a pointer to a data structure that provides context for\nthe callback function.\n[in] Options\nIndicates possible options.\nValue Meaning\nSYMENUM_OPTIONS_DEFAULT\n1\nUse the default options.\nSYMENUM_OPTIONS_INLINE\n2\nEnumerate inline symbols.\nﾉ Expand table\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary DbgHelp.lib\nDLL DbgHelp.dll\nRedistributable DbgHelp.dll 6.2 or later\nReturn value\nRequirements\nﾉ Expand table","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3256,"title":"SymEnumSymbolsForAddr function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symenumsymbolsforaddr","function","dbghelp","enumerates","the","symbols","for","specified","address","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","which","are","located","does","not","symbol","boundary","comes","after","beginning","and","before","end","plus","size","will","find","enumsymbolscallback","application"],"errorCode":"","eventId":"","severity":"Low","summary":"Enumerates the symbols for the specified address.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymEnumSymbolsForAddr function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymEnumSymbolsForAddr function\n(dbghelp.h)\nArticle02/22/2024\nEnumerates the symbols for the specified address.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] Address\nThe address for which symbols are to be located. The address does not have to be on a symbol\nboundary. If the address comes after the beginning of a symbol and before the end of the\nsymbol (the beginning of the symbol plus the symbol size), the function will find the symbol.\n[in] EnumSymbolsCallback\nAn application-defined callback function. This function is called for every symbol found at\nAddress. For more information, see SymEnumSymbolsProc.\n[in, optional] UserContext\nOptional user-defined data. This value is passed to the callback function.\nIf the function succeeds, the return value is TRUE.\nSyntax\nBOOL IMAGEAPI SymEnumSymbolsForAddr(\n [in] HANDLE hProcess,\n [in] DWORD64 Address,\n [in] PSYM_ENUMERATESYMBOLS_CALLBACK EnumSymbolsCallback,\n [in, optional] PVOID UserContext\n);\nParameters\nReturn value\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.0 or later\nDbgHelp Functions\nSymEnumSymbolsProc\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3257,"title":"PSYM_ENUMERATESYMBOLS_CALLBACK callback function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["psym","enumeratesymbols","callback","function","dbghelp","application","defined","used","with","the","symenumsymbols","symenumtypes","and","symenumtypesbyname","functions","article02","2024","callbackw","types","define","pointer","this","symenumsymbolsproc","placeholder","for","name","psyminfo","symbol","info","structure","that","provides","information","about","symbolsize","size","bytes","calculated","actually","guess"],"errorCode":"","eventId":"","severity":"Low","summary":"An application-defined callback function used with the SymEnumSymbols, SymEnumTypes, and\nSymEnumTypesByName functions.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to PSYM_ENUMERATESYMBOLS_CALLBACK callback function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"PSYM_ENUMERATESYMBOLS_CALLBACK\ncallback function (dbghelp.h)\nArticle02/22/2024\nAn application-defined callback function used with the SymEnumSymbols, SymEnumTypes, and\nSymEnumTypesByName functions.\nThe PSYM_ENUMERATESYMBOLS_CALLBACK and PSYM_ENUMERATESYMBOLS_CALLBACKW\ntypes define a pointer to this callback function. SymEnumSymbolsProc is a placeholder for the\napplication-defined function name.\nC++\n[in] pSymInfo\nA pointer to a SYMBOL_INFO structure that provides information about the symbol.\n[in] SymbolSize\nThe size of the symbol, in bytes. The size is calculated and is actually a guess. In some cases,\nthis value can be zero.\n[in, optional] UserContext\nThe user-defined value passed from the SymEnumSymbols or SymEnumTypes function, or\nNULL. This parameter is typically used by an application to pass a pointer to a data structure\nthat provides context information for the callback function.\nSyntax\nPSYM_ENUMERATESYMBOLS_CALLBACK PsymEnumeratesymbolsCallback;\nBOOL PsymEnumeratesymbolsCallback(\n [in] PSYMBOL_INFO pSymInfo,\n [in] ULONG SymbolSize,\n [in, optional] PVOID UserContext\n)\n{...}\nParameters\nReturn value\nIf the function returns TRUE, the enumeration will continue.\nIf the function returns FALSE, the enumeration will stop.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nSYMBOL_INFO\nSymEnumSymbols\nSymEnumTypes\nSymEnumTypesByName\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3258,"title":"SymEnumTypes function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symenumtypes","function","dbghelp","enumerates","all","user","defined","types","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","the","syminitialize","baseofdll","base","address","module","enumsymbolscallback","pointer","symenumsymbolsproc","callback","that","receives","symbol","information","optional","usercontext","value","null","parameter","typically","used"],"errorCode":"","eventId":"","severity":"Low","summary":"Enumerates all user-defined types.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymEnumTypes function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymEnumTypes function (dbghelp.h)\nArticle02/22/2024\nEnumerates all user-defined types.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] BaseOfDll\nThe base address of the module.\n[in] EnumSymbolsCallback\nA pointer to an SymEnumSymbolsProc callback function that receives the symbol information.\n[in, optional] UserContext\nA user-defined value to be passed to the callback function, or NULL. This parameter is typically\nused by an application to pass a pointer to a data structure that provides context information\nfor the callback function.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nSyntax\nBOOL IMAGEAPI SymEnumTypes(\n [in] HANDLE hProcess,\n [in] ULONG64 BaseOfDll,\n [in] PSYM_ENUMERATESYMBOLS_CALLBACK EnumSymbolsCallback,\n [in, optional] PVOID UserContext\n);\nParameters\nReturn value\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nSymEnumSymbolsProc\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3259,"title":"SymEnumTypesByName function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symenumtypesbyname","function","dbghelp","enumerates","all","user","defined","types","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","the","syminitialize","baseofdll","base","address","module","optional","mask","wildcard","expression","that","indicates","names","symbols","enumerated","specify","name","use","mod","syntax","enumsymbolscallback"],"errorCode":"","eventId":"","severity":"Low","summary":"Enumerates all user-defined types.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymEnumTypesByName function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymEnumTypesByName function\n(dbghelp.h)\nArticle02/22/2024\nEnumerates all user-defined types.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] BaseOfDll\nThe base address of the module.\n[in, optional] mask\nA wildcard expression that indicates the names of the symbols to be enumerated. To specify a\nmodule name, use the !mod syntax.\n[in] EnumSymbolsCallback\nA pointer to an SymEnumSymbolsProc callback function that receives the symbol information.\n[in] UserContext\nA user-defined value to be passed to the callback function, or NULL. This parameter is typically\nused by an application to pass a pointer to a data structure that provides context information\nfor the callback function.\nSyntax\nBOOL IMAGEAPI SymEnumTypesByName(\n [in] HANDLE hProcess,\n [in] ULONG64 BaseOfDll,\n [in, optional] PCSTR mask,\n [in] PSYM_ENUMERATESYMBOLS_CALLBACK EnumSymbolsCallback,\n [in] PVOID UserContext\n);\nParameters\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.8 or later\nDbgHelp Functions\nSymEnumSymbolsProc\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nSee also\nSymFindDebugInfoFile function (dbghelp.h)\nLocates a .dbg file in the process search path.\nC++\n[in] hProcess\nA handle to the process that was originally passed to the SymInitialize function.\n[in] FileName\nThe name of the .dbg file. You can use a partial path.\n[out] DebugFilePath\nThe fully qualified path of the .dbg file. This buffer must be at least MAX_PATH+1 characters.\n[in, optional] Callback\nAn application-defined callback function that verifies whether the correct file was found or the\nfunction should continue its search. For more information, see FindDebugInfoFileProc.\nThis parameter can be NULL.\n[in, optional] CallerData\nA user-defined value or NULL. This value is simply passed to the callback function. This parameter\nis typically used by an application to pass a pointer to a data structure that provides some\ncontext for the callback function.\nSyntax\nHANDLE IMAGEAPI SymFindDebugInfoFile(\n [in] HANDLE hProcess,\n [in] PCSTR FileName,\n [out] PSTR DebugFilePath,\n [in, optional] PFIND_DEBUG_FILE_CALLBACK Callback,\n [in, optional] PVOID CallerData\n);\nParameters\nIf the function succeeds, the return value is an open handle to the .dbg file.\nIf the function fails, the return value is NULL. To retrieve extended error information, call\nGetLastError.\nThis function uses the search path set using the SymInitialize or SymSetSearchPath function.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than one\nthread to this function will likely result in unexpected behavior or memory corruption. To avoid\nthis, you must synchronize all concurrent calls from more than one thread to this function.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.6 or later\nDbgHelp Functions\nFindDebugInfoFileProc\nLast updated on 02/22/2024\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nSee also\nSymFindExecutableImage function\n(dbghelp.h)\nLocates an executable file in the process search path.\nC++\n[in] hProcess\nA handle to the process that was originally passed to the SymInitialize function.\n[in] FileName\nThe name of the executable file. You can use a partial path.\n[out] ImageFilePath\nThe fully qualified path of the executable file. This buffer must be at least MAX_PATH+1\ncharacters.\n[in] Callback\nAn application-defined callback function that verifies whether the correct executable file was\nfound, or whether the function should continue its search. For more information, see\nFindExecutableImageProc.\nThis parameter can be NULL.\n[in] CallerData\nSyntax\nHANDLE IMAGEAPI SymFindExecutableImage(\n [in] HANDLE hProcess,\n [in] PCSTR FileName,\n [out] PSTR ImageFilePath,\n [in] PFIND_EXE_FILE_CALLBACK Callback,\n [in] PVOID CallerData\n);\nParameters\nA user-defined value or NULL. This value is simply passed to the callback function. This parameter\nis typically used by an application to pass a pointer to a data structure that provides some\ncontext for the callback function.\nIf the function succeeds, the return value is an open handle to the executable file.\nIf the function fails, the return value is NULL. To retrieve extended error information, call\nGetLastError.\nThis function uses the search path set using the SymInitialize or SymSetSearchPath function.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than one\nthread to this function will likely result in unexpected behavior or memory corruption. To avoid\nthis, you must synchronize all concurrent calls from more than one thread to this function.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.6 or later\nDbgHelp Functions\nFindExecutableImageProc\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nSee also\nLast updated on 02/22/2024\nSymFindFileInPath function (dbghelp.h)\nLocates a symbol file or executable image.\nC++\n[in] hprocess\nA handle to the process that was originally passed to the SymInitialize function.\n[in, optional] SearchPath\nThe search path. This can be multiple paths separated by semicolons. It can include bot","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3260,"title":"PFINDFILEINPATHCALLBACK callback function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["pfindfileinpathcallback","callback","function","dbghelp","application","defined","used","with","the","symfindfileinpath","article08","2022","and","pfindfileinpathcallbackw","types","define","pointer","this","symfindfileinpathproc","placeholder","for","name","filename","file","located","context","user","value","specified","null","parameter","typically","pass","data","structure","that","provides","some","return","true"],"errorCode":"","eventId":"","severity":"Low","summary":"An application-defined callback function used with the SymFindFileInPath function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to PFINDFILEINPATHCALLBACK callback function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"PFINDFILEINPATHCALLBACK callback\nfunction (dbghelp.h)\nArticle08/09/2022\nAn application-defined callback function used with the SymFindFileInPath function.\nThe PFINDFILEINPATHCALLBACK and PFINDFILEINPATHCALLBACKW types define a pointer to\nthis callback function. SymFindFileInPathProc is a placeholder for the application-defined\nfunction name.\nC++\n[in] filename\nThe name of the file located by SymFindFileInPath.\n[in] context\nThe user-defined value specified in SymFindFileInPath, or NULL. This parameter is typically\nused by an application to pass a pointer to a data structure that provides some context for the\ncallback function.\nReturn TRUE to continue searching.\nReturn FALSE to end the search.\nSyntax\nPFINDFILEINPATHCALLBACK Pfindfileinpathcallback;\nBOOL Pfindfileinpathcallback(\n [in] PCSTR filename,\n [in] PVOID context\n)\n{...}\nParameters\nReturn value\nRequirements\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nSymFindFileInPath\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3261,"title":"SymFromAddr function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symfromaddr","function","dbghelp","retrieves","symbol","information","for","the","specified","address","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","which","should","located","does","not","boundary","comes","after","beginning","and","before","end","found","out","optional","displacement","from","zero"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves symbol information for the specified address.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymFromAddr function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymFromAddr function (dbghelp.h)\nArticle02/22/2024\nRetrieves symbol information for the specified address.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] Address\nThe address for which a symbol should be located. The address does not have to be on a\nsymbol boundary. If the address comes after the beginning of a symbol and before the end of\nthe symbol, the symbol is found.\n[out, optional] Displacement\nThe displacement from the beginning of the symbol, or zero.\n[in, out] Symbol\nA pointer to a SYMBOL_INFO structure that provides information about the symbol. The\nsymbol name is variable in length; therefore this buffer must be large enough to hold the name\nstored at the end of the SYMBOL_INFO structure. Be sure to set the MaxNameLen member to\nthe number of bytes reserved for the name.\nIf the function succeeds, the return value is TRUE.\nSyntax\nBOOL IMAGEAPI SymFromAddr(\n [in] HANDLE hProcess,\n [in] DWORD64 Address,\n [out, optional] PDWORD64 Displacement,\n [in, out] PSYMBOL_INFO Symbol\n);\nParameters\nReturn value\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nFor an example, see Retrieving Symbol Information by Address.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nSYMBOL_INFO\nRemarks\nExamples\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3262,"title":"SymFromIndex function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symfromindex","function","dbghelp","retrieves","symbol","information","for","the","specified","index","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","baseofdll","base","address","module","unique","value","out","pointer","info","structure","that","provides","about","succeeds","return","true","fails","false"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves symbol information for the specified index.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymFromIndex function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymFromIndex function (dbghelp.h)\nArticle02/22/2024\nRetrieves symbol information for the specified index.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] BaseOfDll\nThe base address of the module.\n[in] Index\nA unique value for the symbol.\n[in, out] Symbol\nA pointer to a SYMBOL_INFO structure that provides information about the symbol.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nSyntax\nBOOL IMAGEAPI SymFromIndex(\n [in] HANDLE hProcess,\n [in] ULONG64 BaseOfDll,\n [in] DWORD Index,\n [in, out] PSYMBOL_INFO Symbol\n);\nParameters\nReturn value\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.2 or later\nDbgHelp Functions\nSYMBOL_INFO\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3263,"title":"SymFromInlineContext function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symfrominlinecontext","function","dbghelp","retrieves","symbol","information","for","the","specified","address","and","inline","context","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","which","should","located","does","not","boundary","comes","after","beginning","before","end","found","inlinecontext","out","optional"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves symbol information for the specified address and inline context.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymFromInlineContext function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymFromInlineContext function\n(dbghelp.h)\nArticle02/22/2024\nRetrieves symbol information for the specified address and inline context.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] Address\nThe address for which a symbol should be located. The address does not have to be on a\nsymbol boundary. If the address comes after the beginning of a symbol and before the end of\nthe symbol, the symbol is found.\n[in] InlineContext\nThe inline context for which a symbol should be located.\n[out, optional] Displacement\nThe displacement from the beginning of the symbol, or zero.\n[in, out] Symbol\nA pointer to a SYMBOL_INFO structure that provides information about the symbol. The\nsymbol name is variable in length; therefore this buffer must be large enough to hold the name\nSyntax\nBOOL IMAGEAPI SymFromInlineContext(\n [in] HANDLE hProcess,\n [in] DWORD64 Address,\n [in] ULONG InlineContext,\n [out, optional] PDWORD64 Displacement,\n [in, out] PSYMBOL_INFO Symbol\n);\nParameters\nstored at the end of the SYMBOL_INFO structure. Be sure to set the MaxNameLen member to\nthe number of bytes reserved for the name.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary DbgHelp.lib\nDLL DbgHelp.dll\nRedistributable DbgHelp.dll 6.2 or later\nReturn value\nRequirements\nﾉ Expand table","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3264,"title":"SymFromName function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symfromname","function","dbghelp","retrieves","symbol","information","for","the","specified","name","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","located","out","pointer","info","structure","that","provides","about","succeeds","return","value","true","fails","false","retrieve","extended","error","call"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves symbol information for the specified name.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymFromName function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymFromName function (dbghelp.h)\nArticle02/22/2024\nRetrieves symbol information for the specified name.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] Name\nThe name of the symbol to be located.\n[in, out] Symbol\nA pointer to a SYMBOL_INFO structure that provides information about the symbol.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\nSyntax\nBOOL IMAGEAPI SymFromName(\n [in] HANDLE hProcess,\n [in] PCSTR Name,\n [in, out] PSYMBOL_INFO Symbol\n);\nParameters\nReturn value\nRemarks\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nFor an example, see Retrieving Symbol Information by Name.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nSYMBOL_INFO\nExamples\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3265,"title":"SymFromToken function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symfromtoken","function","dbghelp","retrieves","symbol","information","for","the","specified","managed","code","token","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","base","address","module","out","pointer","info","structure","that","provides","about","succeeds","return","value","true","fails","false"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves symbol information for the specified managed code token.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymFromToken function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymFromToken function (dbghelp.h)\nArticle02/22/2024\nRetrieves symbol information for the specified managed code token.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] Base\nThe base address of the managed code module.\n[in] Token\nThe managed code token.\n[in, out] Symbol\nA pointer to a SYMBOL_INFO structure that provides information about the symbol.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nSyntax\nBOOL IMAGEAPI SymFromToken(\n [in] HANDLE hProcess,\n [in] DWORD64 Base,\n [in] DWORD Token,\n [in, out] PSYMBOL_INFO Symbol\n);\nParameters\nReturn value\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.1 or later\nDbgHelp Functions\nSYMBOL_INFO\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3266,"title":"SymFunctionTableAccess function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symfunctiontableaccess","function","dbghelp","retrieves","the","table","entry","for","specified","address","article02","2024","hprocess","handle","process","that","was","originally","passed","syminitialize","addrbase","base","which","information","required","succeeds","return","value","pointer","fails","null","retrieve","extended","error","call","getlasterror","type","returned","specific","image"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the function table entry for the specified address.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymFunctionTableAccess function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymFunctionTableAccess function\n(dbghelp.h)\nArticle02/22/2024\nRetrieves the function table entry for the specified address.\nC++\n[in] hProcess\nA handle to the process that was originally passed to the SymInitialize function.\n[in] AddrBase\nThe base address for which function table information is required.\nIf the function succeeds, the return value is a pointer to the function table entry.\nIf the function fails, the return value is NULL. To retrieve extended error information, call\nGetLastError.\nThe type of pointer returned is specific to the image from which symbols are loaded.\nx86: If the image is for an x86 system, this is a pointer to an FPO_DATA structure.\nx64: If the image is for an x64 system, this is a pointer to an\n_IMAGE_RUNTIME_FUNCTION_ENTRY structure.\nSyntax\nPVOID IMAGEAPI SymFunctionTableAccess(\n [in] HANDLE hProcess,\n [in] DWORD AddrBase\n);\nParameters\nReturn value\nRemarks\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nThis function supersedes the SymFunctionTableAccess function. For more information, see\nUpdated Platform Support. SymFunctionTableAccess is defined as follows in Dbghelp.h.\nC++\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nFPO_DATA\nIMAGE_FUNCTION_ENTRY\nSymInitialize\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define SymFunctionTableAccess SymFunctionTableAccess64\n#else\nPVOID\nIMAGEAPI\nSymFunctionTableAccess(\n __in HANDLE hProcess,\n __in DWORD AddrBase\n );\n#endif\nRequirements\nﾉ Expand table\nSee also\n_IMAGE_RUNTIME_FUNCTION_ENTRY","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3267,"title":"SymFunctionTableAccess64AccessRoutines function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symfunctiontableaccess64accessroutines","function","dbghelp","finds","table","entry","frame","pointer","omission","fpo","record","for","address","article02","2024","use","symfunctiontableaccess64","instead","hprocess","handle","the","process","that","was","originally","passed","syminitialize","addrbase","base","which","information","required","optional","readmemoryroutine","read","memory","callback","getmodulebaseroutine","get","module"],"errorCode":"","eventId":"","severity":"Low","summary":"Finds a function table entry or frame pointer omission (FPO) record for an address.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymFunctionTableAccess64AccessRoutines function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymFunctionTableAccess64AccessRoutines\nfunction (dbghelp.h)\nArticle02/22/2024\nFinds a function table entry or frame pointer omission (FPO) record for an address.\nUse SymFunctionTableAccess64 instead.\nC++\n[in] hProcess\nA handle to the process that was originally passed to the SymInitialize function.\n[in] AddrBase\nThe base address for which function table information is required.\n[in, optional] ReadMemoryRoutine\nPointer to a read memory callback function.\n[in, optional] GetModuleBaseRoutine\nPointer to a get module base callback function.\nNone\nSyntax\nPVOID IMAGEAPI SymFunctionTableAccess64AccessRoutines(\n [in] HANDLE hProcess,\n [in] DWORD64 AddrBase,\n [in, optional] PREAD_PROCESS_MEMORY_ROUTINE64 ReadMemoryRoutine,\n [in, optional] PGET_MODULE_BASE_ROUTINE64 GetModuleBaseRoutine\n);\nParameters\nReturn value\nRequirements\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary DbgHelp.lib\nDLL DbgHelp.dll\nRedistributable DbgHelp.dll 6.2 or later\nSymInitialize\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3268,"title":"SymGetExtendedOption function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgetextendedoption","function","dbghelp","gets","whether","the","specified","extended","symbol","option","off","article02","2024","check","following","are","valid","values","value","meaning","symopt","disableaccesstimeupdate","turns","explicit","updates","last","access","time","that","loaded","default","file","consumed","cache","can","maintained","using","least","recently","used"],"errorCode":"","eventId":"","severity":"Low","summary":"Gets whether the specified extended symbol option on or off.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetExtendedOption function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetExtendedOption function\n(dbghelp.h)\nArticle02/22/2024\nGets whether the specified extended symbol option on or off.\nC++\n[in] option\nThe extended symbol option to check. The following are valid values.\nValue Meaning\nSYMOPT_EX_DISABLEACCESSTIMEUPDATE\n0\nTurns off explicit updates to the last access time of a\nsymbol that is loaded. By default, DbgHelp updates the last\naccess time of a symbol file that is consumed so that a\nsymbol cache can be maintained by using a least recently\nused mechanism.\nThe value of the specified symbol option.\nSyntax\nBOOL IMAGEAPI SymGetExtendedOption(\n [in] IMAGEHLP_EXTENDED_OPTIONS option\n);\nParameters\nﾉ Expand table\nReturn value\nRequirements\nﾉ Expand table\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary DbgHelp.lib\nDLL DbgHelp.dll\nRedistributable DbgHelp.dll 10.0.16232.1000 or later\nIMAGEHLP_EXTENDED_OPTIONS\nSymSetExtendedOption\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3269,"title":"SymGetFileLineOffsets64 function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgetfilelineoffsets64","function","dbghelp","locates","line","information","for","the","specified","module","and","file","name","article02","2024","hprocess","handle","process","that","was","originally","passed","syminitialize","optional","modulename","which","lines","are","located","this","parameter","null","searches","all","modules","filename","out","buffer","array","offsets"],"errorCode":"","eventId":"","severity":"Low","summary":"Locates line information for the specified module and file name.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetFileLineOffsets64 function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetFileLineOffsets64 function\n(dbghelp.h)\nArticle02/22/2024\nLocates line information for the specified module and file name.\nC++\n[in] hProcess\nA handle to the process that was originally passed to the SymInitialize function.\n[in, optional] ModuleName\nThe name of the module in which lines are to be located. If this parameter is NULL, the\nfunction searches all modules.\n[in] FileName\nThe name of the file in which lines are to be located.\n[out] Buffer\nAn array of offsets for each line. The offset for the line n is stored in element n-1. Array\nelements for lines that do not have line information are left unchanged.\n[in] BufferLines\nThe size of the Buffer array, in elements.\nSyntax\nULONG IMAGEAPI SymGetFileLineOffsets64(\n [in] HANDLE hProcess,\n [in, optional] PCSTR ModuleName,\n [in] PCSTR FileName,\n [out] PDWORD64 Buffer,\n [in] ULONG BufferLines\n);\nParameters\nReturn value\nIf the function succeeds, the return value is the highest line number found. This value is zero if\nno line information was found.\nIf the function fails, the return value is LINE_ERROR. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3270,"title":"SymGetHomeDirectory function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgethomedirectory","function","dbghelp","retrieves","the","home","directory","used","article02","2024","type","retrieved","this","parameter","can","one","following","values","value","meaning","hdbase","hdsrc","source","hdsym","symbol","out","dir","pointer","string","that","receives","size","output","buffer","characters","syntax","pchar","imageapi","dword","pstr"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the home directory used by Dbghelp.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetHomeDirectory function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetHomeDirectory function\n(dbghelp.h)\nArticle02/22/2024\nRetrieves the home directory used by Dbghelp.\nC++\n[in] type\nThe directory to be retrieved. This parameter can be one of the following values.\nValue Meaning\nhdBase\n0\nThe home directory.\nhdSrc\n2\nThe source directory.\nhdSym\n1\nThe symbol directory.\n[out] dir\nA pointer to a string that receives the directory.\n[in] size\nThe size of the output buffer, in characters.\nSyntax\nPCHAR IMAGEAPI SymGetHomeDirectory(\n [in] DWORD type,\n [out] PSTR dir,\n [in] size_t size\n);\nParameters\nﾉ Expand table\nIf the function succeeds, the return value is a pointer to the dir parameter.\nIf the function fails, the return value is NULL. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.1 or later\nDbgHelp Functions\nSymSetHomeDirectory\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3271,"title":"SymGetLineFromAddr function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgetlinefromaddr","function","dbghelp","locates","the","source","line","for","specified","address","article07","2022","hprocess","handle","process","that","was","originally","passed","syminitialize","dwaddr","which","should","located","not","necessary","boundary","appears","after","beginning","and","before","end","found","out","pdwdisplacement","displacement","bytes","from","zero"],"errorCode":"","eventId":"","severity":"Low","summary":"Locates the source line for the specified address.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetLineFromAddr function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetLineFromAddr function (dbghelp.h)\nArticle07/27/2022\nLocates the source line for the specified address.\nC++\n[in] hProcess\nA handle to the process that was originally passed to the SymInitialize function.\n[in] dwAddr\nThe address for which a line should be located. It is not necessary for the address to be on a\nline boundary. If the address appears after the beginning of a line and before the end of the\nline, the line is found.\n[out] pdwDisplacement\nThe displacement in bytes from the beginning of the line, or zero.\n[out] Line\nA pointer to an IMAGEHLP_LINE64 structure.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nSyntax\nBOOL IMAGEAPI SymGetLineFromAddr(\n [in] HANDLE hProcess,\n [in] DWORD dwAddr,\n [out] PDWORD pdwDisplacement,\n [out] PIMAGEHLP_LINE Line\n);\nParameters\nReturn value\nThe caller must allocate the Line buffer properly and fill in the required members of the\nIMAGEHLP_LINE64 structure before calling SymGetLineFromAddr64.\nThis function returns a pointer to a buffer that may be reused by another function. Therefore,\nbe sure to copy the data returned to another buffer immediately.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nSymGetLineFromAddrW64 is defined as follows in Dbghelp.h.\nC++\nThis function supersedes the SymGetLineFromAddr function. For more information, see\nUpdated Platform Support. SymGetLineFromAddr is defined as follows in Dbghelp.h.\nC++\nRemarks\nBOOL\nIMAGEAPI\nSymGetLineFromAddrW64(\n _In_ HANDLE hProcess,\n _In_ DWORD64 dwAddr,\n _Out_ PDWORD pdwDisplacement,\n _Out_ PIMAGEHLP_LINEW64 Line\n );\n#ifdef DBGHELP_TRANSLATE_TCHAR\n #define SymGetLineFromAddr64 SymGetLineFromAddrW64\n#endif\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define SymGetLineFromAddr SymGetLineFromAddr64\n#define SymGetLineFromAddrW SymGetLineFromAddrW64\n#else\nBOOL\nIMAGEAPI\nSymGetLineFromAddr(\n _In_ HANDLE hProcess,\n _In_ DWORD dwAddr,\n _Out_ PDWORD pdwDisplacement,\n _Out_ PIMAGEHLP_LINE Line\n );\nFor an example, see Retrieving Symbol Information by Address.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nIMAGEHLP_LINE64\nSymGetLineFromName64\nSymInitialize\nBOOL\nIMAGEAPI\nSymGetLineFromAddrW(\n _In_ HANDLE hProcess,\n _In_ DWORD dwAddr,\n _Out_ PDWORD pdwDisplacement,\n _Out_ PIMAGEHLP_LINEW Line\n );\n#endif\nExamples\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3272,"title":"SymGetLineFromInlineContext function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgetlinefrominlinecontext","function","dbghelp","locates","the","source","line","for","specified","inline","context","article02","2024","hprocess","handle","process","that","was","originally","passed","syminitialize","qwaddr","address","which","should","located","not","necessary","boundary","appears","after","beginning","and","before","end","found","inlinecontext","optional","qwmodulebaseaddress","base"],"errorCode":"","eventId":"","severity":"Low","summary":"Locates the source line for the specified inline context.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetLineFromInlineContext function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetLineFromInlineContext function\n(dbghelp.h)\nArticle02/22/2024\nLocates the source line for the specified inline context.\nC++\n[in] hProcess\nA handle to the process that was originally passed to the SymInitialize function.\n[in] qwAddr\nThe address for which a line should be located. It is not necessary for the address to be on a\nline boundary. If the address appears after the beginning of a line and before the end of the\nline, the line is found.\n[in] InlineContext\nThe inline context.\n[in, optional] qwModuleBaseAddress\nThe base address of the module.\n[out] pdwDisplacement\nThe displacement in bytes from the beginning of the line, or zero.\n[out] Line64\nSyntax\nBOOL IMAGEAPI SymGetLineFromInlineContext(\n [in] HANDLE hProcess,\n [in] DWORD64 qwAddr,\n [in] ULONG InlineContext,\n [in, optional] DWORD64 qwModuleBaseAddress,\n [out] PDWORD pdwDisplacement,\n [out] PIMAGEHLP_LINE64 Line64\n);\nParameters\nA pointer to an IMAGEHLP_LINE64 structure.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe caller must allocate the Line buffer properly and fill in the required members of the\nIMAGEHLP_LINE64 structure before calling SymGetLineFromInlineContext.\nThis function returns a pointer to a buffer that may be reused by another function. Therefore,\nbe sure to copy the data returned to another buffer immediately.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nSymGetLineFromInlineContext is defined as follows in Dbghelp.h.\nsyntax\nReturn value\nRemarks\nBOOL\nIMAGEAPI\nSymGetLineFromInlineContextW(\n _In_ HANDLE hProcess,\n _In_ DWORD64 dwAddr,\n _In_ ULONG InlineContext,\n _In_opt_ DWORD64 qwModuleBaseAddress,\n _Out_ PDWORD pdwDisplacement,\n _Out_ PIMAGEHLP_LINEW64 Line\n );\n#ifdef DBGHELP_TRANSLATE_TCHAR\n #define SymGetLineFromInlineContext SymGetLineFromInlineContextW\n#endif\nRequirements\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary DbgHelp.lib\nDLL DbgHelp.dll\nRedistributable DbgHelp.dll 6.2 or later\nﾉ Expand table","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3273,"title":"SymGetLineFromName function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgetlinefromname","function","dbghelp","locates","source","line","for","the","specified","module","file","name","and","number","article02","2024","hprocess","handle","process","that","was","originally","passed","syminitialize","optional","modulename","which","located","filename","application","has","more","than","one","with","this","sure","specify","full","path"],"errorCode":"","eventId":"","severity":"Low","summary":"Locates a source line for the specified module, file name, and line number.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetLineFromName function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetLineFromName function\n(dbghelp.h)\nArticle02/22/2024\nLocates a source line for the specified module, file name, and line number.\nC++\n[in] hProcess\nA handle to the process that was originally passed to the SymInitialize function.\n[in, optional] ModuleName\nThe name of the module in which a line is to be located.\n[in, optional] FileName\nThe name of the file in which a line is to be located. If the application has more than one\nsource file with this name, be sure to specify a full path.\n[in] dwLineNumber\nThe line number to be located.\n[out] plDisplacement\nThe displacement in bytes from the beginning of the line, or zero.\n[in, out] Line\nSyntax\nBOOL IMAGEAPI SymGetLineFromName(\n [in] HANDLE hProcess,\n [in, optional] PCSTR ModuleName,\n [in, optional] PCSTR FileName,\n [in] DWORD dwLineNumber,\n [out] PLONG plDisplacement,\n [in, out] PIMAGEHLP_LINE Line\n);\nParameters\nA pointer to an IMAGEHLP_LINE64 structure.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe caller must allocate the Line buffer properly and fill in the required members of the\nIMAGEHLP_LINE64 structure before calling SymGetLineFromName64.\nBefore calling this function, ensure that the symbols are initialized correctly by first calling\nSymInitialize, SymSetOptions, and SymLoadModule64.\nThis function returns a pointer to a buffer that may be reused by another function. Therefore,\nbe sure to copy the data returned to another buffer immediately.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nSymGetLineFromNameW64 is defined as follows in Dbghelp.h.\nC++\nReturn value\nRemarks\nBOOL\nIMAGEAPI\nSymGetLineFromNameW64(\n __in HANDLE hProcess,\n __in_opt PCWSTR ModuleName,\n __in_opt PCWSTR FileName,\n __in DWORD dwLineNumber,\n __out PLONG plDisplacement,\n __inout PIMAGEHLP_LINEW64 Line\n );\n#ifdef DBGHELP_TRANSLATE_TCHAR\n#define SymGetLineFromName64 SymGetLineFromNameW64\n#endif\nThis function supersedes the SymGetLineFromName function. For more information, see\nUpdated Platform Support. SymGetLineFromName is defined as follows in Dbghelp.h.\nC++\nFor an example, see Retrieving Symbol Information by Name.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nIMAGEHLP_LINE64\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define SymGetLineFromName SymGetLineFromName64\n#else\nBOOL\nIMAGEAPI\nSymGetLineFromName(\n __in HANDLE hProcess,\n __in_opt PCSTR ModuleName,\n __in_opt PCSTR FileName,\n __in DWORD dwLineNumber,\n __out PLONG plDisplacement,\n __inout PIMAGEHLP_LINE Line\n );\n#endif\nExamples\nRequirements\nﾉ Expand table\nSee also\nSymGetLineFromAddr64\nSymInitialize","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3274,"title":"SymGetLineNext function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgetlinenext","function","dbghelp","retrieves","the","line","information","for","next","source","article07","2022","hprocess","handle","process","that","was","originally","passed","syminitialize","out","pointer","imagehlp","line64","structure","contains","succeeds","return","value","true","fails","false","retrieve","extended","error","call","getlasterror","symgetlinenext64","requires","have"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the line information for the next source line.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetLineNext function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetLineNext function (dbghelp.h)\nArticle07/27/2022\nRetrieves the line information for the next source line.\nC++\n[in] hProcess\nA handle to the process that was originally passed to the SymInitialize function.\n[in, out] Line\nA pointer to an IMAGEHLP_LINE64 structure that contains the line information.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe SymGetLineNext64 function requires that the IMAGEHLP_LINE64 structure have valid data,\npresumably obtained from a call to the SymGetLineFromAddr64 or SymGetLineFromName64\nfunction. This structure receives the line information for the next line in sequence.\nThis function returns a pointer to a buffer that may be reused by another function. Therefore,\nbe sure to copy the data returned to another buffer immediately.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\nSyntax\nBOOL IMAGEAPI SymGetLineNext(\n [in] HANDLE hProcess,\n [in, out] PIMAGEHLP_LINE Line\n);\nParameters\nReturn value\nRemarks\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nSymGetLineNextW64 is defined as follows in Dbghelp.h.\nC++\nThis function supersedes the SymGetLineNext function. For more information, see Updated\nPlatform Support. SymGetLineNext is defined as follows in Dbghelp.h.\nC++\nBOOL\nIMAGEAPI\nSymGetLineNextW64(\n __in HANDLE hProcess,\n __inout PIMAGEHLP_LINEW64 Line\n#ifdef DBGHELP_TRANSLATE_TCHAR\n#define SymGetLineNext64 SymGetLineNextW64\n#endif\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define SymGetLineNext SymGetLineNext64\n#else\nBOOL\nIMAGEAPI\nSymGetLineNext(\n __in HANDLE hProcess,\n __inout PIMAGEHLP_LINE Line\n );\nBOOL\nIMAGEAPI\nSymGetLineNextW(\n __in HANDLE hProcess,\n __inout PIMAGEHLP_LINEW Line\n );\n#endif\nRequirements\nﾉ Expand table\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nIMAGEHLP_LINE64\nSymGetLineFromAddr64\nSymGetLineFromName64\nSymGetLinePrev64\nSymInitialize\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3275,"title":"SymGetLinePrev function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgetlineprev","function","dbghelp","retrieves","the","line","information","for","previous","source","article07","2022","hprocess","handle","process","that","was","originally","passed","syminitialize","out","pointer","imagehlp","line64","structure","succeeds","return","value","true","fails","false","retrieve","extended","error","call","getlasterror","symgetlineprev64","requires","have","valid"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the line information for the previous source line.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetLinePrev function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetLinePrev function (dbghelp.h)\nArticle07/27/2022\nRetrieves the line information for the previous source line.\nC++\n[in] hProcess\nA handle to the process that was originally passed to the SymInitialize function.\n[in, out] Line\nA pointer to an IMAGEHLP_LINE64 structure.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe SymGetLinePrev64 function requires that the IMAGEHLP_LINE64 structure have valid data,\npresumably obtained from a call to the SymGetLineFromAddr64 or SymGetLineFromName64\nfunction. This structure is filled with the line information for the previous line in sequence.\nThis function returns a pointer to a buffer that may be reused by another function. Therefore,\nbe sure to copy the data returned to another buffer immediately.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\nSyntax\nBOOL IMAGEAPI SymGetLinePrev(\n [in] HANDLE hProcess,\n [in, out] PIMAGEHLP_LINE Line\n);\nParameters\nReturn value\nRemarks\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nSymGetLinePrevW64 is defined as follows in DbgHelp.h.\nC++\nThis function supersedes the SymGetLinePrev function. For more information, see Updated\nPlatform Support. SymGetLinePrev is defined as follows in DbgHelp.h.\nC++\nBOOL\nIMAGEAPI\nSymGetLinePrevW64(\n __in HANDLE hProcess,\n __inout PIMAGEHLP_LINEW64 Line\n );\n#ifdef DBGHELP_TRANSLATE_TCHAR\n#define SymGetLinePrev64 SymGetLinePrevW64\n#endif\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define SymGetLinePrev SymGetLinePrev64\n#else\nBOOL\nIMAGEAPI\nSymGetLinePrev(\n __in HANDLE hProcess,\n __inout PIMAGEHLP_LINE Line\n );\nBOOL\nIMAGEAPI\nSymGetLinePrevW(\n __in HANDLE hProcess,\n __inout PIMAGEHLP_LINEW Line\n );\n#endif\nRequirements\nﾉ Expand table\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nIMAGEHLP_LINE64\nSymGetLineFromAddr64\nSymGetLineFromName64\nSymGetLineNext64\nSymInitialize\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3276,"title":"SymGetModuleBase function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgetmodulebase","function","dbghelp","retrieves","the","base","address","module","that","contains","specified","article02","2024","hprocess","handle","process","was","originally","passed","syminitialize","dwaddr","virtual","contained","one","modules","loaded","symloadmodule64","succeeds","return","value","nonzero","containing","parameter","fails","zero","retrieve","extended","error","information","call"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the base address of the module that contains the specified address.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetModuleBase function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetModuleBase function (dbghelp.h)\nArticle02/22/2024\nRetrieves the base address of the module that contains the specified address.\nC++\n[in] hProcess\nA handle to the process that was originally passed to the SymInitialize function.\n[in] dwAddr\nThe virtual address that is contained in one of the modules loaded by the SymLoadModule64\nfunction.\nIf the function succeeds, the return value is a nonzero virtual address. The value is the base\naddress of the module containing the address specified by the dwAddr parameter.\nIf the function fails, the return value is zero. To retrieve extended error information, call\nGetLastError.\nThe module table is searched for a module that contains dwAddr. The module is located based\non the load address and size of each module.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\nSyntax\nDWORD IMAGEAPI SymGetModuleBase(\n [in] HANDLE hProcess,\n [in] DWORD dwAddr\n);\nParameters\nReturn value\nRemarks\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nThis function supersedes the SymGetModuleBase function. For more information, see Updated\nPlatform Support. SymGetModuleBase is defined as follows in DbgHelp.h.\nC++\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nSymInitialize\nSymLoadModule64\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define SymGetModuleBase SymGetModuleBase64\n#else\nDWORD\nIMAGEAPI\nSymGetModuleBase(\n __in HANDLE hProcess,\n __in DWORD dwAddr\n );\n#endif\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3277,"title":"SymGetModuleInfo function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgetmoduleinfo","function","dbghelp","retrieves","the","module","information","specified","article08","2022","hprocess","handle","process","that","was","originally","passed","syminitialize","dwaddr","virtual","address","contained","one","modules","loaded","symloadmodule64","out","moduleinfo","pointer","imagehlp","module64","structure","sizeofstruct","member","must","set","size","invalid","value","will"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the module information of the specified module.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetModuleInfo function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetModuleInfo function (dbghelp.h)\nArticle08/09/2022\nRetrieves the module information of the specified module.\nC++\n[in] hProcess\nA handle to the process that was originally passed to the SymInitialize function.\n[in] dwAddr\nThe virtual address that is contained in one of the modules loaded by the SymLoadModule64\nfunction\n[out] ModuleInfo\nA pointer to an IMAGEHLP_MODULE64 structure. The SizeOfStruct member must be set to the\nsize of the IMAGEHLP_MODULE64 structure. An invalid value will result in an error.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe module table is searched for a module that contains the dwAddr. The module is located\nbased on the load address and size of each module. If a valid module is found, the ModuleInfo\nSyntax\nBOOL IMAGEAPI SymGetModuleInfo(\n [in] HANDLE hProcess,\n [in] DWORD dwAddr,\n [out] PIMAGEHLP_MODULE ModuleInfo\n);\nParameters\nReturn value\nRemarks\nparameter is filled with the information about the module.\nThe size of the IMAGEHLP_MODULE64 structure used by this function has changed over the\nyears. If a version of DbgHelp.dll is called that is older than the DbgHelp.h used to compile the\ncalling code, then this function may fail with an error code of ERROR_INVALID_PARAMETER.\nThis most commonly occurs when the system version (%WinDir%\\System32\\DbgHelp.dll) is\ncalled. Code that calls the system version of DbgHelp.dll must be compiled using the\nappropriate SDK for that Windows release or the SDK for a previous release.\nThe recommended model is to redistribute the required version of DbgHelp.dll along with the\ncalling software. This allows the caller to use the most robust versions of DbgHelp.dll as well as\na simplifying upgrades. The most recent version of DbgHelp.dll can always be found in the\nDebugging Tools for Windows package. As a general rule, code that is compiled to work with\nolder versions will always work with newer versions.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nSymGetModuleInfoW64 is defined as follows in DbgHelp.h.\nC++\nThis function supersedes the SymGetModuleInfo function. For more information, see Updated\nPlatform Support. SymGetModuleInfo is defined as follows in DbgHelp.h.\nC++\nBOOL\nIMAGEAPI\nSymGetModuleInfoW64(\n __in HANDLE hProcess,\n __in DWORD64 qwAddr,\n __out PIMAGEHLP_MODULEW64 ModuleInfo\n );\n#ifdef DBGHELP_TRANSLATE_TCHAR\n#define SymGetModuleInfo64 SymGetModuleInfoW64\n#endif\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define SymGetModuleInfo SymGetModuleInfo64\n#define SymGetModuleInfoW SymGetModuleInfoW64\n#else\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nIMAGEHLP_MODULE64\nSymInitialize\nSymLoadModule64\nBOOL\nIMAGEAPI\nSymGetModuleInfo(\n __in HANDLE hProcess,\n __in DWORD dwAddr,\n __out PIMAGEHLP_MODULE ModuleInfo\n );\nBOOL\nIMAGEAPI\nSymGetModuleInfoW(\n __in HANDLE hProcess,\n __in DWORD dwAddr,\n __out PIMAGEHLP_MODULEW ModuleInfo\n );\n#endif\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3278,"title":"SymGetOmaps function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgetomaps","function","dbghelp","retrieves","the","omap","tables","within","loaded","module","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","baseofdll","base","address","out","omapto","array","map","entries","new","image","layout","taken","from","original","for","details","see","structure"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the omap tables within a loaded module.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetOmaps function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetOmaps function (dbghelp.h)\nArticle02/22/2024\nRetrieves the omap tables within a loaded module.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] BaseOfDll\nThe base address of the module.\n[out] OmapTo\nAn array of address map entries to the new image layout taken from the original layout. For\ndetails on the map entries, see the OMAP structure.\n[out] cOmapTo\nThe number of entries in the OmapTo array.\n[out] OmapFrom\nAn array of address map entries from the new image layout to the original layout (as described\nby the debug symbols). For details on the map entries, see the OMAP structure.\n[out] cOmapFrom\nSyntax\nBOOL IMAGEAPI SymGetOmaps(\n [in] HANDLE hProcess,\n [in] DWORD64 BaseOfDll,\n [out] POMAP *OmapTo,\n [out] PDWORD64 cOmapTo,\n [out] POMAP *OmapFrom,\n [out] PDWORD64 cOmapFrom\n);\nParameters\nThe number of entries in the OmapFrom array.\nIf the function succeeds, the return value is TRUE.\nIf the function fails (the omap is not found), the return value is FALSE. To retrieve extended\nerror information, call GetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.8 or later\nOMAP\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3279,"title":"SymGetOptions function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgetoptions","function","dbghelp","retrieves","the","current","option","mask","article02","2024","returns","options","that","have","been","set","zero","valid","value","and","indicates","all","are","turned","off","these","can","changed","several","times","while","library","use","application","any","change","affects","future","calls","symbol"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the current option mask.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetOptions function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetOptions function (dbghelp.h)\nArticle02/22/2024\nRetrieves the current option mask.\nC++\nThe function returns the current options that have been set. Zero is a valid value and indicates\nthat all options are turned off.\nThese options can be changed several times while the library is in use by an application. Any\noption change affects all future calls to the symbol handler.\nThe return value is the combination of the following values that have been set using the\nSymSetOptions function.\nSYMOPT_ALLOW_ABSOLUTE_SYMBOLS\nSYMOPT_ALLOW_ZERO_ADDRESS\nSYMOPT_AUTO_PUBLICS\nSYMOPT_CASE_INSENSITIVE\nSYMOPT_DEBUG\nSYMOPT_DEFERRED_LOADS\nSYMOPT_EXACT_SYMBOLS\nSYMOPT_FAIL_CRITICAL_ERRORS\nSYMOPT_FAVOR_COMPRESSED\nSYMOPT_FLAT_DIRECTORY\nSYMOPT_IGNORE_CVREC\nSYMOPT_IGNORE_IMAGEDIR\nSYMOPT_IGNORE_NT_SYMPATH\nSYMOPT_INCLUDE_32BIT_MODULES\nSYMOPT_LOAD_ANYTHING\nSYMOPT_LOAD_LINES\nSyntax\nDWORD IMAGEAPI SymGetOptions();\nReturn value\nRemarks\nSYMOPT_NO_CPP\nSYMOPT_NO_IMAGE_SEARCH\nSYMOPT_NO_PROMPTS\nSYMOPT_NO_PUBLICS\nSYMOPT_NO_UNQUALIFIED_LOADS\nSYMOPT_OVERWRITE\nSYMOPT_PUBLICS_ONLY\nSYMOPT_SECURE\nSYMOPT_UNDNAME\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3280,"title":"SymGetScope function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgetscope","function","dbghelp","retrieves","the","scope","for","specified","index","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","baseofdll","base","address","module","unique","value","symbol","out","pointer","info","structure","member","contains","succeeds","return","true","fails","false","retrieve"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the scope for the specified index.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetScope function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetScope function (dbghelp.h)\nArticle02/22/2024\nRetrieves the scope for the specified index.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] BaseOfDll\nThe base address of the module.\n[in] Index\nA unique value for the symbol.\n[in, out] Symbol\nA pointer to a SYMBOL_INFO structure. The Scope member contains the scope.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nSyntax\nBOOL IMAGEAPI SymGetScope(\n [in] HANDLE hProcess,\n [in] ULONG64 BaseOfDll,\n [in] DWORD Index,\n [in, out] PSYMBOL_INFO Symbol\n);\nParameters\nReturn value\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.2 or later\nDbgHelp Functions\nSYMBOL_INFO\nSymSetScopeFromAddr\nSymSetScopeFromIndex\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3281,"title":"SymGetSearchPath function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgetsearchpath","function","dbghelp","retrieves","the","symbol","search","path","for","specified","process","article08","2022","hprocess","handle","that","was","originally","passed","syminitialize","out","searchpath","pointer","buffer","receives","searchpathlength","size","characters","succeeds","return","value","true","fails","false","retrieve","extended","error","information","call","getlasterror"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the symbol search path for the specified process.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetSearchPath function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetSearchPath function (dbghelp.h)\nArticle08/09/2022\nRetrieves the symbol search path for the specified process.\nC++\n[in] hProcess\nA handle to the process that was originally passed to the SymInitialize function.\n[out] SearchPath\nA pointer to the buffer that receives the symbol search path.\n[in] SearchPathLength\nThe size of the SearchPath buffer, in characters.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe SymGetSearchPath function copies the symbol search path for the specified process into\nthe SearchPath buffer. If the function fails, the contents of the buffer are undefined.\nTo specify a symbol search path for the process, use the SymSetSearchPath function.\nSyntax\nBOOL IMAGEAPI SymGetSearchPath(\n [in] HANDLE hProcess,\n [out] PSTR SearchPath,\n [in] DWORD SearchPathLength\n);\nParameters\nReturn value\nRemarks\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nSymInitialize\nSymSetSearchPath\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3282,"title":"SymGetSourceFile function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgetsourcefile","function","dbghelp","retrieves","the","specified","source","file","from","server","article08","2022","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","base","address","module","optional","params","parameter","unused","filespec","name","out","filepath","pointer","buffer","that","receives","fully","qualified","path"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the specified source file from the source server.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetSourceFile function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetSourceFile function (dbghelp.h)\nArticle08/09/2022\nRetrieves the specified source file from the source server.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] Base\nThe base address of the module.\n[in, optional] Params\nThis parameter is unused.\n[in] FileSpec\nThe name of the source file.\n[out] FilePath\nA pointer to a buffer that receives the fully qualified path of the source file.\n[in] Size\nThe size of the FilePath buffer, in characters.\nSyntax\nBOOL IMAGEAPI SymGetSourceFile(\n [in] HANDLE hProcess,\n [in] ULONG64 Base,\n [in, optional] PCSTR Params,\n [in] PCSTR FileSpec,\n [out] PSTR FilePath,\n [in] DWORD Size\n);\nParameters\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nTo control which directory receives the source files, use the SymSetHomeDirectory function.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.2 or later\nDbgHelp Functions\nSource Server\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3283,"title":"SymGetSourceFileChecksum function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgetsourcefilechecksum","function","dbghelp","retrieves","the","specified","source","file","checksum","from","server","article08","2022","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","base","address","module","filespec","name","out","pchecksumtype","success","points","type","pchecksum","pointer","buffer","that","receives","null","then"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the specified source file checksum from the source server.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetSourceFileChecksum function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetSourceFileChecksum function\n(dbghelp.h)\nArticle08/09/2022\nRetrieves the specified source file checksum from the source server.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] Base\nThe base address of the module.\n[in] FileSpec\nThe name of the source file.\n[out] pCheckSumType\nOn success, points to the checksum type.\n[out] pChecksum\npointer to a buffer that receives the checksum. If NULL, then when the call returns\npActualBytesWritten returns the number of bytes required.\nSyntax\nBOOL IMAGEAPI SymGetSourceFileChecksum(\n [in] HANDLE hProcess,\n [in] ULONG64 Base,\n [in] PCSTR FileSpec,\n [out] DWORD *pCheckSumType,\n [out] BYTE *pChecksum,\n [in] DWORD checksumSize,\n [out] DWORD *pActualBytesWritten\n);\nParameters\n[in] checksumSize\nThe size of the pChecksum buffer, in bytes.\n[out] pActualBytesWritten\nPointer to the actual bytes written in the buffer.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 10.0.15063 or later\nReturn value\nRequirements\nﾉ Expand table","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3284,"title":"SymGetSourceFileFromToken function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgetsourcefilefromtoken","function","dbghelp","retrieves","the","source","file","associated","with","specified","token","from","server","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","pointer","optional","params","parameter","unused","out","filepath","buffer","that","receives","fully","qualified","path","size","characters"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the source file associated with the specified token from the source server.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetSourceFileFromToken function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetSourceFileFromToken function\n(dbghelp.h)\nArticle02/22/2024\nRetrieves the source file associated with the specified token from the source server.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] Token\nA pointer to the token.\n[in, optional] Params\nThis parameter is unused.\n[out] FilePath\nA pointer to a buffer that receives the fully qualified path of the source file.\n[in] Size\nThe size of the FilePath buffer, in characters.\nSyntax\nBOOL IMAGEAPI SymGetSourceFileFromToken(\n [in] HANDLE hProcess,\n [in] PVOID Token,\n [in, optional] PCSTR Params,\n [out] PSTR FilePath,\n [in] DWORD Size\n);\nParameters\nReturn value\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.2 or later\nDbgHelp Functions\nSource Server\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3285,"title":"SymGetSourceFileToken function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgetsourcefiletoken","function","dbghelp","retrieves","token","for","the","specified","source","file","from","server","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","base","address","module","filespec","name","out","pointer","buffer","that","receives","size","bytes","syntax","bool","imageapi","ulong64"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves token for the specified source file from the source server.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetSourceFileToken function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetSourceFileToken function\n(dbghelp.h)\nArticle02/22/2024\nRetrieves token for the specified source file from the source server.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] Base\nThe base address of the module.\n[in] FileSpec\nThe name of the source file.\n[out] Token\nA pointer to a buffer that receives the token.\n[out] Size\nThe size of the Token buffer, in bytes.\nSyntax\nBOOL IMAGEAPI SymGetSourceFileToken(\n [in] HANDLE hProcess,\n [in] ULONG64 Base,\n [in] PCSTR FileSpec,\n [out] PVOID *Token,\n [out] DWORD *Size\n);\nParameters\nReturn value\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.2 or later\nDbgHelp Functions\nSource Server\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3286,"title":"SymGetSourceVarFromToken function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgetsourcevarfromtoken","function","dbghelp","retrieves","the","value","associated","with","specified","variable","name","from","source","server","token","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","pointer","optional","params","parameter","unused","varname","whose","you","want","retrieve","out","buffer","that"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the value associated with the specified variable name from the Source Server token.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetSourceVarFromToken function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetSourceVarFromToken function\n(dbghelp.h)\nArticle02/22/2024\nRetrieves the value associated with the specified variable name from the Source Server token.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] Token\nA pointer to the token.\n[in, optional] Params\nThis parameter is unused.\n[in] VarName\nThe name of the variable token whose value you want to retrieve.\n[out] Value\nA pointer to a buffer that receives the value associated with the variable token specified in the\nVarName parameter.\n[in] Size\nSyntax\nBOOL IMAGEAPI SymGetSourceVarFromToken(\n [in] HANDLE hProcess,\n [in] PVOID Token,\n [in, optional] PCSTR Params,\n [in] PCSTR VarName,\n [out] PSTR Value,\n [in] DWORD Size\n);\nParameters\nThe size of the Value buffer, in characters.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.8 or later\nReturn value\nRemarks\nRequirements\nﾉ Expand table","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3287,"title":"SymGetSymbolFile function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgetsymbolfile","function","dbghelp","locates","symbol","file","the","specified","path","article08","2022","optional","hprocess","handle","process","that","was","originally","passed","syminitialize","this","sympath","cannot","null","use","option","load","without","calling","symcleanup","parameter","empty","string","uses","set","using","symsetsearchpath","imagefile","name","image"],"errorCode":"","eventId":"","severity":"Low","summary":"Locates a symbol file in the specified symbol path.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetSymbolFile function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetSymbolFile function (dbghelp.h)\nArticle08/09/2022\nLocates a symbol file in the specified symbol path.\nC++\n[in, optional] hProcess\nA handle to the process that was originally passed to the SymInitialize function.\nIf this handle is 0, SymPath cannot be NULL. Use this option to load a symbol file without\ncalling SymInitialize or SymCleanup.\n[in, optional] SymPath\nThe symbol path. If this parameter is NULL or an empty string, the function uses the symbol\npath set using the SymInitialize or SymSetSearchPath function.\n[in] ImageFile\nThe name of the image file.\n[in] Type\nThe type of symbol file. This parameter can be one of the following values.\nSyntax\nBOOL IMAGEAPI SymGetSymbolFile(\n [in, optional] HANDLE hProcess,\n [in, optional] PCSTR SymPath,\n [in] PCSTR ImageFile,\n [in] DWORD Type,\n [out] PSTR SymbolFile,\n [in] size_t cSymbolFile,\n [out] PSTR DbgFile,\n [in] size_t cDbgFile\n);\nParameters\nﾉ Expand table\nValue Meaning\nsfImage\n0\nA .exe or .dll file.\nsfDbg\n1\nA .dbg file.\nsfPdb\n2\nA .pdb file.\nsfMpd\n3\nReserved.\n[out] SymbolFile\nA pointer to a null-terminated string that receives the name of the symbol file.\n[in] cSymbolFile\nThe size of the SymbolFile buffer, in characters.\n[out] DbgFile\nA pointer to a buffer that receives the fully qualified path to the symbol file. This buffer must\nbe at least MAX_PATH characters.\n[in] cDbgFile\nThe size of the DbgFile buffer, in characters.\nIf the server locates a valid symbol file, it returns TRUE; otherwise, it returns FALSE and\nGetLastError returns a value that indicates why the symbol file was not returned.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nReturn value\nRemarks\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.3 or later\nDbgHelp Functions\nSymInitialize\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3288,"title":"SymGetSymFromAddr function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgetsymfromaddr","function","dbghelp","locates","the","symbol","for","specified","address","article02","2024","hprocess","handle","process","that","was","originally","passed","syminitialize","dwaddr","which","located","does","not","have","boundary","comes","after","beginning","and","before","end","plus","size","found","out","optional","pdwdisplacement","displacement","from"],"errorCode":"","eventId":"","severity":"Low","summary":"Locates the symbol for the specified address.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetSymFromAddr function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetSymFromAddr function (dbghelp.h)\nArticle02/22/2024\nLocates the symbol for the specified address.\n \nC++\n[in] hProcess\nA handle to the process that was originally passed to the SymInitialize function.\n[in] dwAddr\nThe address for which a symbol is to be located. The address does not have to be on a symbol\nboundary. If the address comes after the beginning of a symbol and before the end of the\nsymbol (the beginning of the symbol plus the symbol size), the symbol is found.\n[out, optional] pdwDisplacement\nThe displacement from the beginning of the symbol, or zero.\n[in, out] Symbol\nA pointer to an IMAGEHLP_SYMBOL64 structure.\nNote This function is provided only for compatibility. Applications should use\nSymFromAddr.\nSyntax\nBOOL IMAGEAPI SymGetSymFromAddr(\n [in] HANDLE hProcess,\n [in] DWORD dwAddr,\n [out, optional] PDWORD pdwDisplacement,\n [in, out] PIMAGEHLP_SYMBOL Symbol\n);\nParameters\nReturn value\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe SymGetSymFromAddr64 function locates the symbol for a specified address. The modules\nare searched for the one the address belongs to. When the module is found, its symbol table is\nsearched for a match. When the symbol is found, the symbol information is copied into the\nSymbol buffer provided by the caller. The caller must allocate the Symbol buffer properly and\nfill in the required parameters in the IMAGEHLP_SYMBOL64 structure before calling\nSymGetSymFromAddr64.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nThis function supersedes the SymGetSymFromAddr function. For more information, see\nUpdated Platform Support. SymGetSymFromAddr is defined as follows in Dbghelp.h.\nC++\nRequirement Value\nTarget Platform Windows\nRemarks\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define SymGetSymFromAddr SymGetSymFromAddr64\n#else\nBOOL\nIMAGEAPI\nSymGetSymFromAddr(\n __in HANDLE hProcess,\n __in DWORD dwAddr,\n __out_opt PDWORD pdwDisplacement,\n __inout PIMAGEHLP_SYMBOL Symbol\n );\n#endif\nRequirements\nﾉ Expand table\nRequirement Value\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nIMAGEHLP_SYMBOL64\nSymFromAddr\nSymInitialize\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3289,"title":"SymGetSymFromName function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgetsymfromname","function","dbghelp","locates","symbol","for","the","specified","name","article07","2022","hprocess","handle","process","that","was","originally","passed","syminitialize","which","located","out","pointer","imagehlp","symbol64","structure","succeeds","return","value","true","fails","false","retrieve","extended","error","information","call","getlasterror","note","this"],"errorCode":"","eventId":"","severity":"Low","summary":"Locates a symbol for the specified name.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetSymFromName function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetSymFromName function\n(dbghelp.h)\nArticle07/27/2022\nLocates a symbol for the specified name.\n \nC++\n[in] hProcess\nA handle to the process that was originally passed to the SymInitialize function.\n[in] Name\nThe symbol name for which a symbol is to be located.\n[in, out] Symbol\nA pointer to an IMAGEHLP_SYMBOL64 structure.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nNote This function is provided only for compatibility. Applications should use\nSymFromName.\nSyntax\nBOOL IMAGEAPI SymGetSymFromName(\n [in] HANDLE hProcess,\n [in] PCSTR Name,\n [in, out] PIMAGEHLP_SYMBOL Symbol\n);\nParameters\nReturn value\nThe SymGetSymFromName64 function is used to locate a symbol for a specified name. The\nname can contain a module prefix that isolates the symbol search to a single module's symbol\ntable.\nThe module prefix is in the form of \"module!\". The \"!\" character is the delimiter between the\nmodule name and the symbol name. If there is no module prefix, then the search is performed\non each module's symbol table in a linear manner, beginning with the first module that is\nloaded.\nUsing the module prefix is preferable for two reasons. First, the symbol search occurs much\nfaster. Second, when deferred symbol loading is turned on, the search causes symbols to be\nloaded for each module that is searched. When the symbol is found, the symbol information is\ncopied into the Symbol buffer provided by the caller. The caller must allocate the Symbol buffer\nproperly and fill in the required parameters in the IMAGEHLP_SYMBOL64 structure before\ncalling SymGetSymFromName64.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nThis function supersedes the SymGetSymFromName function. For more information, see\nUpdated Platform Support. SymGetSymFromName is defined as follows in Dbghelp.h.\nC++\nRemarks\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define SymGetSymFromName SymGetSymFromName64\n#else\nBOOL\nIMAGEAPI\nSymGetSymFromName(\n __in HANDLE hProcess,\n __in PCSTR Name,\n __inout PIMAGEHLP_SYMBOL Symbol\n );\n#endif\nRequirements\nﾉ Expand table\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nIMAGEHLP_SYMBOL64\nSymFromName\nSymInitialize\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3290,"title":"SymGetSymNext function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgetsymnext","function","dbghelp","retrieves","the","symbol","information","for","next","article02","2024","hprocess","handle","process","that","was","originally","passed","syminitialize","out","pointer","imagehlp","symbol64","structure","succeeds","return","value","true","fails","false","retrieve","extended","error","call","getlasterror","symgetsymnext64","requires","have","valid","data"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the symbol information for the next symbol.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetSymNext function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetSymNext function (dbghelp.h)\nArticle02/22/2024\nRetrieves the symbol information for the next symbol.\n \nC++\n[in] hProcess\nA handle to the process that was originally passed to the SymInitialize function.\n[in, out] Symbol\nA pointer to an IMAGEHLP_SYMBOL64 structure.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe SymGetSymNext64 function requires that the IMAGEHLP_SYMBOL64 structure have valid\ndata, presumably obtained from a call to the SymGetSymFromAddr64 or\nSymGetSymFromName64 function. This structure is filled with the symbol information for the\nnext symbol in sequence by virtual address.\nNote This function is provided only for compatibility. Applications should use SymNext.\nSyntax\nBOOL IMAGEAPI SymGetSymNext(\n [in] HANDLE hProcess,\n [in, out] PIMAGEHLP_SYMBOL Symbol\n);\nParameters\nReturn value\nRemarks\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nSymGetSymNextW64 is defined as follows in DbgHelp.h.\nC++\nThis function supersedes the SymGetSymNext function. For more information, see Updated\nPlatform Support. SymGetSymNext is defined as follows in DbgHelp.h.\nC++\nBOOL\nIMAGEAPI\nSymGetSymNextW64(\n __in HANDLE hProcess,\n __inout PIMAGEHLP_SYMBOLW64 Symbol\n );\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define SymGetSymNext SymGetSymNext64\n#define SymGetSymNextW SymGetSymNextW64\n#else\nBOOL\nIMAGEAPI\nSymGetSymNext(\n __in HANDLE hProcess,\n __inout PIMAGEHLP_SYMBOL Symbol\n );\nBOOL\nIMAGEAPI\nSymGetSymNextW(\n __in HANDLE hProcess,\n __inout PIMAGEHLP_SYMBOLW Symbol\n );\n#endif\nRequirements\nﾉ Expand table\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nIMAGEHLP_SYMBOL64\nSymGetSymFromAddr64\nSymGetSymFromName64\nSymGetSymPrev64\nSymInitialize\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3291,"title":"SymGetSymPrev function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgetsymprev","function","dbghelp","retrieves","the","symbol","information","for","previous","article02","2024","hprocess","handle","process","that","was","originally","passed","syminitialize","out","pointer","imagehlp","symbol64","structure","succeeds","return","value","true","fails","false","retrieve","extended","error","call","getlasterror","symgetsymprev64","requires","have","valid","data"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the symbol information for the previous symbol.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetSymPrev function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetSymPrev function (dbghelp.h)\nArticle02/22/2024\nRetrieves the symbol information for the previous symbol.\n \nC++\n[in] hProcess\nA handle to the process that was originally passed to the SymInitialize function.\n[in, out] Symbol\nA pointer to an IMAGEHLP_SYMBOL64 structure.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe SymGetSymPrev64 function requires the IMAGEHLP_SYMBOL64 structure to have valid\ndata, presumably obtained from a call to the SymGetSymFromAddr64 or\nSymGetSymFromName64 function. This structure is filled in with the symbol information for the\nprevious symbol in sequence by virtual address.\nNote This function is provided only for compatibility. Applications should use SymPrev.\nSyntax\nBOOL IMAGEAPI SymGetSymPrev(\n [in] HANDLE hProcess,\n [in, out] PIMAGEHLP_SYMBOL Symbol\n);\nParameters\nReturn value\nRemarks\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nSymGetSymPrevW64 is defined as follows in DbgHelp.h.\nC++\nThis function supersedes the SymGetSymPrev function. For more information, see Updated\nPlatform Support. SymGetSymPrev is defined as follows in Dbghelp.h.\nC++\nBOOL\nIMAGEAPI\nSymGetSymPrevW64(\n __in HANDLE hProcess,\n __inout PIMAGEHLP_SYMBOLW64 Symbol\n );\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define SymGetSymPrev SymGetSymPrev64\n#define SymGetSymPrevW SymGetSymPrevW64\n#else\nBOOL\nIMAGEAPI\nSymGetSymPrev(\n __in HANDLE hProcess,\n __inout PIMAGEHLP_SYMBOL Symbol\n );\nBOOL\nIMAGEAPI\nSymGetSymPrevW(\n __in HANDLE hProcess,\n __inout PIMAGEHLP_SYMBOLW Symbol\n );\n#endif\nRequirements\nﾉ Expand table\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nIMAGEHLP_SYMBOL64\nSymGetSymFromAddr64\nSymGetSymFromName64\nSymGetSymNext64\nSymInitialize\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3292,"title":"SymGetTypeFromName function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgettypefromname","function","dbghelp","retrieves","type","index","for","the","specified","name","article08","2022","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","baseofdll","base","address","module","out","symbol","pointer","info","structure","typeindex","member","contains","succeeds","return","value","true","fails","false"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves a type index for the specified type name.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetTypeFromName function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetTypeFromName function\n(dbghelp.h)\nArticle08/09/2022\nRetrieves a type index for the specified type name.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] BaseOfDll\nThe base address of the module.\n[in] Name\nThe name of the type.\n[in, out] Symbol\nA pointer to a SYMBOL_INFO structure. The TypeIndex member contains the type index.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nSyntax\nBOOL IMAGEAPI SymGetTypeFromName(\n [in] HANDLE hProcess,\n [in] ULONG64 BaseOfDll,\n [in] PCSTR Name,\n [in, out] PSYMBOL_INFO Symbol\n);\nParameters\nReturn value\nTo retrieve information about the type, pass the type index to the SymGetTypeInfo function.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nSYMBOL_INFO\nSymGetTypeInfo\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3293,"title":"SymGetTypeInfo function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgettypeinfo","function","dbghelp","retrieves","type","information","for","the","specified","index","article10","2021","larger","queries","use","symgettypeinfoex","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","modbase","base","address","module","typeid","number","functions","return","typeindex","member","symbol","info","structure","gettype"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves type information for the specified type index.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetTypeInfo function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetTypeInfo function (dbghelp.h)\nArticle10/13/2021\nRetrieves type information for the specified type index. For larger queries, use the\nSymGetTypeInfoEx function.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] ModBase\nThe base address of the module.\n[in] TypeId\nThe type index. (A number of functions return a type index in the TypeIndex member of the\nSYMBOL_INFO structure.)\n[in] GetType\nThe information type. This parameter can be one of more of the values from the\nIMAGEHLP_SYMBOL_TYPE_INFO enumeration type.\n[out] pInfo\nThe data. The format of the data depends on the value of the GetType parameter.\nSyntax\nBOOL IMAGEAPI SymGetTypeInfo(\n [in] HANDLE hProcess,\n [in] DWORD64 ModBase,\n [in] ULONG TypeId,\n [in] IMAGEHLP_SYMBOL_TYPE_INFO GetType,\n [out] PVOID pInfo\n);\nParameters\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nFor more details on the type information, see the documentation for the PDB format.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nIMAGEHLP_SYMBOL_TYPE_INFO\nSymGetTypeFromName\nSymGetTypeInfoEx\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3294,"title":"SymGetTypeInfoEx function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symgettypeinfoex","function","dbghelp","retrieves","multiple","pieces","type","information","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","the","syminitialize","modbase","base","address","module","out","params","pointer","imagehlp","get","info","structure","that","specifies","input","and","output","for","query","succeeds"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves multiple pieces of type information.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymGetTypeInfoEx function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymGetTypeInfoEx function (dbghelp.h)\nArticle02/22/2024\nRetrieves multiple pieces of type information.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] ModBase\nThe base address of the module.\n[in, out] Params\nA pointer to an IMAGEHLP_GET_TYPE_INFO_PARAMS structure that specifies input and output\ninformation for the query.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\nSyntax\nBOOL IMAGEAPI SymGetTypeInfoEx(\n [in] HANDLE hProcess,\n [in] DWORD64 ModBase,\n [in, out] PIMAGEHLP_GET_TYPE_INFO_PARAMS Params\n);\nParameters\nReturn value\nRemarks\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.3 or later\nDbgHelp Functions\nIMAGEHLP_GET_TYPE_INFO_PARAMS\nSymGetTypeFromName\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3295,"title":"SymInitialize function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["syminitialize","function","dbghelp","initializes","the","symbol","handler","for","process","article02","2023","hprocess","handle","that","identifies","caller","this","value","should","unique","and","nonzero","but","need","not","however","you","use","sure","correct","application","debugger","being","debugged","returned","getcurrentprocess","used","must","avoid","sharing"],"errorCode":"","eventId":"","severity":"Low","summary":"Initializes the symbol handler for a process.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymInitialize function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymInitialize function (dbghelp.h)\nArticle02/02/2023\nInitializes the symbol handler for a process.\nC++\n[in] hProcess\nA handle that identifies the caller. This value should be unique and nonzero, but need not be a\nprocess handle. However, if you do use a process handle, be sure to use the correct handle. If\nthe application is a debugger, use the process handle for the process being debugged. Do not\nuse the handle returned by GetCurrentProcess. The handle used must be unique to avoid\nsharing a session with another component, and using GetCurrentProcess can have unexpected\nresults when multiple components are attempting to use dbghelp to inspect the current\nprocess. Using GetCurrentProcess when debugging another process will also cause functions\nlike SymLoadModuleEx to have unexpected results.\nThis parameter cannot be NULL.\n[in, optional] UserSearchPath\nThe path, or series of paths separated by a semicolon (;), that is used to search for symbol files.\nIf this parameter is NULL, the library attempts to form a symbol path from the following\nsources:\nThe current working directory of the application\nThe _NT_SYMBOL_PATH environment variable\nThe _NT_ALTERNATE_SYMBOL_PATH environment variable\nNote that the search path can also be set using the SymSetSearchPath function.\n[in] fInvadeProcess\nSyntax\nBOOL IMAGEAPI SymInitialize(\n [in] HANDLE hProcess,\n [in, optional] PCSTR UserSearchPath,\n [in] BOOL fInvadeProcess\n);\nParameters\nIf this value is TRUE, enumerates the loaded modules for the process and effectively calls the\nSymLoadModule64 function for each module.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe SymInitialize function is used to initialize the symbol handler for a process. In the context\nof the symbol handler, a process is a convenient object to use when collecting symbol\ninformation. Usually, symbol handlers are used by debuggers and other tools that need to load\nsymbols for a process being debugged.\nThe handle passed to SymInitialize must be the same value passed to all other symbol handler\nfunctions called by the process. It is the handle that the functions use to identify the caller and\nlocate the correct symbol information. When you have finished using the symbol information,\ncall the SymCleanup function to deallocate all resources associated with the process for which\nsymbols are loaded.\nThe search for symbols files is performed recursively for all paths specified in the\nUserSearchPath parameter. Therefore, if you specify the root directory in a search, the whole\ndrive is searched, which can take significant time. Note that the directory that contains the\nexecutable file for the process is not automatically part of the search path. To include this\ndirectory in the search path, call the GetModuleFileNameEx function, then add the path\nreturned to UserSearchPath.\nA process that calls SymInitialize should not call it again unless it calls SymCleanup first. If the\ncall to SymInitialize set fInvadeProcess to TRUE and you simply need to reload the module list,\nuse the SymRefreshModuleList function.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, call SymInitialize only when your process starts and SymCleanup only when your\nprocess ends. It is not necessary for each thread in the process to call these functions.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nReturn value\nRemarks\nExamples\nFor an example, see Initializing the Symbol Handler.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nGetModuleFileNameEx\nSymCleanup\nSymEnumProcesses\nSymLoadModule64\nSymRefreshModuleList\nSymSetSearchPath\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3296,"title":"SymLoadModule function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symloadmodule","function","dbghelp","this","has","been","superseded","the","symloadmoduleex","article07","2022","loads","symbol","table","hprocess","handle","process","must","have","previously","passed","syminitialize","optional","hfile","file","for","executable","image","argument","used","mostly","debuggers","where","debugger","passes","obtained","from","debugging","event","value"],"errorCode":"","eventId":"","severity":"Low","summary":"This function has been superseded by the SymLoadModuleEx function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymLoadModule function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymLoadModule function (dbghelp.h)\nArticle07/27/2022\nLoads the symbol table.\nThis function has been superseded by the SymLoadModuleEx function.\nC++\n[in] hProcess\nA handle to the process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in, optional] hFile\nA handle to the file for the executable image. This argument is used mostly by debuggers,\nwhere the debugger passes the file handle obtained from a debugging event. A value of NULL\nindicates that hFile is not used.\n[in, optional] ImageName\nThe name of the executable image. This name can contain a partial path, a full path, or no path\nat all. If the file cannot be located by the name provided, the symbol search path is used.\n[in, optional] ModuleName\nA shortcut name for the module. If the pointer value is NULL, the library creates a name using\nthe base name of the symbol file.\n[in] BaseOfDll\nSyntax\nDWORD IMAGEAPI SymLoadModule(\n [in] HANDLE hProcess,\n [in, optional] HANDLE hFile,\n [in, optional] PCSTR ImageName,\n [in, optional] PCSTR ModuleName,\n [in] DWORD BaseOfDll,\n [in] DWORD SizeOfDll\n);\nParameters\nThe load address of the module. If the value is zero, the library obtains the load address from\nthe symbol file. The load address contained in the symbol file is not necessarily the actual load\naddress. Debuggers and other applications having an actual load address should use the real\nload address when calling this function.\nIf the image is a .pdb file, this parameter cannot be zero.\n[in] SizeOfDll\nThe size of the module, in bytes. If the value is zero, the library obtains the size from the\nsymbol file. The size contained in the symbol file is not necessarily the actual size. Debuggers\nand other applications having an actual size should use the real size when calling this function.\nIf the image is a .pdb file, this parameter cannot be zero.\nIf the function succeeds, the return value is the base address of the loaded module.\nIf the function fails, the return value is zero. To retrieve extended error information, call\nGetLastError.\nIf the module is already loaded, the return value is zero and GetLastError returns\nERROR_SUCCESS.\nThe symbol handler creates an entry for the module and if the deferred symbol loading option\nis turned off, an attempt is made to load the symbols. If deferred symbol loading is enabled,\nthe module is marked as deferred and the symbols are not loaded until a reference is made to\na symbol in the module.\nTo unload the symbol table, use the SymUnloadModule64 function.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nThis function supersedes the SymLoadModule function. For more information, see Updated\nPlatform Support. SymLoadModule is defined as follows in DbgHelp.h.\nC++\nReturn value\nRemarks\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nSymInitialize\nSymUnloadModule64\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define SymLoadModule SymLoadModule64\n#else\nDWORD\nIMAGEAPI\nSymLoadModule(\n __in HANDLE hProcess,\n __in_opt HANDLE hFile,\n __in_opt PCSTR ImageName,\n __in_opt PCSTR ModuleName,\n __in DWORD BaseOfDll,\n __in DWORD SizeOfDll\n );\n#endif\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3297,"title":"SymLoadModuleEx function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symloadmoduleex","function","dbghelp","loads","the","symbol","table","for","specified","module","article08","2022","hprocess","handle","process","that","was","originally","passed","syminitialize","hfile","file","executable","image","this","argument","used","mostly","debuggers","where","debugger","passes","obtained","from","debugging","event","value","null","indicates","not"],"errorCode":"","eventId":"","severity":"Low","summary":"Loads the symbol table for the specified module.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymLoadModuleEx function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymLoadModuleEx function (dbghelp.h)\nArticle08/09/2022\nLoads the symbol table for the specified module.\nC++\n[in] hProcess\nA handle to the process that was originally passed to the SymInitialize function.\n[in] hFile\nA handle to the file for the executable image. This argument is used mostly by debuggers,\nwhere the debugger passes the file handle obtained from a debugging event. A value of NULL\nindicates that hFile is not used.\n[in] ImageName\nThe name of the executable image. This name can contain a partial path, a full path, or no path\nat all. If the file cannot be located by the name provided, the symbol search path is used.\n[in] ModuleName\nA shortcut name for the module. If the pointer value is NULL, the library creates a name using\nthe base name of the symbol file.\n[in] BaseOfDll\nSyntax\nDWORD64 IMAGEAPI SymLoadModuleEx(\n [in] HANDLE hProcess,\n [in] HANDLE hFile,\n [in] PCSTR ImageName,\n [in] PCSTR ModuleName,\n [in] DWORD64 BaseOfDll,\n [in] DWORD DllSize,\n [in] PMODLOAD_DATA Data,\n [in] DWORD Flags\n);\nParameters\nThe load address of the module. If the value is zero, the library obtains the load address from\nthe symbol file. The load address contained in the symbol file is not necessarily the actual load\naddress. Debuggers and other applications having an actual load address should use the real\nload address when calling this function.\nIf the image is a .pdb file, this parameter cannot be zero.\n[in] DllSize\nThe size of the module, in bytes. If the value is zero, the library obtains the size from the\nsymbol file. The size contained in the symbol file is not necessarily the actual size. Debuggers\nand other applications having an actual size should use the real size when calling this function.\nIf the image is a .pdb file, this parameter cannot be zero.\n[in] Data\nA pointer to a MODLOAD_DATA structure that represents headers other than the standard PE\nheader. This parameter is optional and can be NULL.\n[in] Flags\nThis parameter can be zero or one or more of the following values. If this parameter is zero, the\nfunction loads the modules and the symbols for the module.\nValue Meaning\nSLMFLAG_NO_SYMBOLS\n0x4\nLoads the module but not the symbols for the module.\nSLMFLAG_VIRTUAL\n0x1\nCreates a virtual module named ModuleName at the address\nspecified in BaseOfDll. To add symbols to this module, call the\nSymAddSymbol function.\nIf the function succeeds, the return value is the base address of the loaded module.\nIf the function fails, the return value is zero. To retrieve extended error information, call\nGetLastError.\nIf the module is already loaded, the return value is zero and GetLastError returns\nERROR_SUCCESS.\nﾉ Expand table\nReturn value\nThe symbol handler creates an entry for the module and if the deferred symbol loading option\nis turned off, an attempt is made to load the symbols. If deferred symbol loading is enabled,\nthe module is marked as deferred and the symbols are not loaded until a reference is made to\na symbol in the module. Therefore, you should always call the SymGetModuleInfo64 function\nafter calling SymLoadModuleEx.\nTo unload the symbol table, use the SymUnloadModule64 function.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nFor an example, see Loading a Symbol Module.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.0 or later\nDbgHelp Functions\nMODLOAD_DATA\nSymAddSymbol\nRemarks\nExamples\nRequirements\nﾉ Expand table\nSee also\nSymUnloadModule64","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3298,"title":"SymMatchFileName function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symmatchfilename","function","dbghelp","compares","string","file","name","and","path","article11","2022","filename","the","compared","match","parameter","out","optional","filenamestop","pointer","buffer","that","receives","location","where","matching","stopped","for","complete","this","value","can","one","character","before","also","null","matchstop","may","succeeds"],"errorCode":"","eventId":"","severity":"Low","summary":"Compares a string to a file name and path.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymMatchFileName function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymMatchFileName function (dbghelp.h)\nArticle11/22/2022\nCompares a string to a file name and path.\nC++\n[in] FileName\nThe file name to be compared to the Match parameter.\n[in] Match\nThe string to be compared to the FileName parameter.\n[out, optional] FileNameStop\nA pointer to a string buffer that receives a pointer to the location in FileName where matching\nstopped. For a complete match, this value can be one character before FileName. This value\ncan also be NULL.\n[out, optional] MatchStop\nA pointer to a string buffer that receives a pointer to the location in Match where matching\nstopped. For a complete match, this value may be one character before Match. This value may\nbe NULL.\nIf the function succeeds, the return value is TRUE.\nSyntax\nBOOL IMAGEAPI SymMatchFileName(\n [in] PCSTR FileName,\n [in] PCSTR Match,\n [out, optional] PSTR *FileNameStop,\n [out, optional] PSTR *MatchStop\n);\nParameters\nReturn value\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nBecause the match string can be a suffix of the complete file name, this function can be used to\nmatch a plain file name to a fully qualified file name.\nMatching begins from the end of both strings and proceeds backward. Matching is caseinsensitive and equates a backslash (\\) with a forward slash (/).\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3299,"title":"SymMatchString function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symmatchstring","function","dbghelp","compares","the","specified","string","wildcard","expression","article02","2024","such","symbol","name","compared","parameter","compare","supports","inclusion","and","characters","matches","any","single","character","fcase","variable","that","indicates","whether","not","comparison","case","sensitive","succeeds","return","value","true","fails","false"],"errorCode":"","eventId":"","severity":"Low","summary":"Compares the specified string to the specified wildcard expression.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymMatchString function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymMatchString function (dbghelp.h)\nArticle02/22/2024\nCompares the specified string to the specified wildcard expression.\nC++\n[in] string\nThe string, such as a symbol name, to be compared to the expression parameter.\n[in] expression\nThe wildcard expression to compare to the string parameter. The wildcard expression supports\nthe inclusion of the * and ? characters. * matches any string and ? matches any single character.\n[in] fCase\nA variable that indicates whether or not the comparison is to be case sensitive.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\nSyntax\nBOOL IMAGEAPI SymMatchString(\n [in] PCSTR string,\n [in] PCSTR expression,\n [in] BOOL fCase\n);\nParameters\nReturn value\nRemarks\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.2 or later\nDbgHelp Functions\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3300,"title":"SymNext function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symnext","function","dbghelp","retrieves","symbol","information","for","the","next","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","out","pointer","info","structure","that","provides","about","current","upon","return","contains","succeeds","value","true","fails","false","retrieve","extended","error"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves symbol information for the next symbol.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymNext function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymNext function (dbghelp.h)\nArticle02/22/2024\nRetrieves symbol information for the next symbol.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in, out] si\nA pointer to a SYMBOL_INFO structure that provides information about the current symbol.\nUpon return, the structure contains information about the next symbol.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThis function requires that the SYMBOL_INFO structure have valid data for the current symbol.\nThe next symbol is the symbol with the virtual address that is next in the sequence.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\nSyntax\nBOOL IMAGEAPI SymNext(\n [in] HANDLE hProcess,\n [in, out] PSYMBOL_INFO si\n);\nParameters\nReturn value\nRemarks\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.2 or later\nDbgHelp Functions\nSYMBOL_INFO\nSymPrev\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3301,"title":"SymPrev function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symprev","function","dbghelp","retrieves","symbol","information","for","the","previous","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","out","pointer","info","structure","that","provides","about","current","upon","return","contains","succeeds","value","true","fails","false","retrieve","extended","error"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves symbol information for the previous symbol.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymPrev function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymPrev function (dbghelp.h)\nArticle02/22/2024\nRetrieves symbol information for the previous symbol.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in, out] si\nA pointer to a SYMBOL_INFO structure that provides information about the current symbol.\nUpon return, the structure contains information about the previous symbol.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThis function requires that the SYMBOL_INFO structure have valid data for the current symbol.\nThe previous symbol is the symbol with a virtual address that immediately precedes this\nsymbol.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\nSyntax\nBOOL IMAGEAPI SymPrev(\n [in] HANDLE hProcess,\n [in, out] PSYMBOL_INFO si\n);\nParameters\nReturn value\nRemarks\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.2 or later\nDbgHelp Functions\nSYMBOL_INFO\nSymNext\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3302,"title":"SymQueryInlineTrace function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symqueryinlinetrace","function","dbghelp","hprocess","handle","process","article02","2024","queries","inline","trace","this","must","have","been","previously","passed","the","syminitialize","startaddress","start","address","startcontext","contains","context","block","startretaddress","return","current","curaddress","out","curcontext","dword","that","receives","syntax","bool","imageapi","dword64","lpdword"],"errorCode":"","eventId":"","severity":"Low","summary":"C++\n[in] hProcess\nA handle to a process.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymQueryInlineTrace function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymQueryInlineTrace function (dbghelp.h)\nArticle02/22/2024\nQueries an inline trace.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] StartAddress\nThe start address.\n[in] StartContext\nContains the context of the start of block.\n[in] StartRetAddress\nContains the return address of the start of the current block/\n[in] CurAddress\nContains the current address.\n[out] CurContext\nAddress of a DWORD that receives the current context.\nSyntax\nBOOL IMAGEAPI SymQueryInlineTrace(\n [in] HANDLE hProcess,\n [in] DWORD64 StartAddress,\n [in] DWORD StartContext,\n [in] DWORD64 StartRetAddress,\n [in] DWORD64 CurAddress,\n [out] LPDWORD CurContext,\n [out] LPDWORD CurFrameIndex\n);\nParameters\n[out] CurFrameIndex\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nNone\nEither the StartAddress or StartRetAddress parameters must be within the same function scope\nas the CurAddress parameter. The former indicates a step-over within the same function and\nthe latter indicates a step-over from StartAddress.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary DbgHelp.lib\nDLL DbgHelp.dll\nRedistributable DbgHelp.dll 6.2 or later\nReturn value\nRemarks\nRequirements\nﾉ Expand table","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3303,"title":"SymRefreshModuleList function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symrefreshmodulelist","function","dbghelp","refreshes","the","module","list","for","process","article02","2024","hprocess","handle","this","must","have","been","previously","passed","syminitialize","succeeds","return","value","true","fails","false","retrieve","extended","error","information","call","getlasterror","enumerates","loaded","modules","and","effectively","calls","symloadmodule64","each"],"errorCode":"","eventId":"","severity":"Low","summary":"Refreshes the module list for the process.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymRefreshModuleList function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymRefreshModuleList function\n(dbghelp.h)\nArticle02/22/2024\nRefreshes the module list for the process.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThis function enumerates the loaded modules for the process and effectively calls the\nSymLoadModule64 function for each module. This same process is performed by SymInitialize\nif fInvadeProcess is TRUE.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nSyntax\nBOOL IMAGEAPI SymRefreshModuleList(\n [in] HANDLE hProcess\n);\nParameters\nReturn value\nRemarks\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.5 or later\nDbgHelp Functions\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3304,"title":"SymRegisterCallback function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symregistercallback","function","dbghelp","registers","callback","for","use","the","symbol","handler","article07","2022","hprocess","handle","process","that","was","originally","passed","syminitialize","callbackfunction","symregistercallbackproc64","usercontext","user","defined","value","null","this","simply","normally","parameter","used","application","pass","pointer","data","structure","lets","establish","some"],"errorCode":"","eventId":"","severity":"Low","summary":"Registers a callback function for use by the symbol handler.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymRegisterCallback function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymRegisterCallback function (dbghelp.h)\nArticle07/27/2022\nRegisters a callback function for use by the symbol handler.\nC++\n[in] hProcess\nA handle to the process that was originally passed to the SymInitialize function.\n[in] CallbackFunction\nA SymRegisterCallbackProc64 callback function.\n[in] UserContext\nA user-defined value or NULL. This value is simply passed to the callback function. Normally,\nthis parameter is used by an application to pass a pointer to a data structure that lets the\ncallback function establish some context.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe SymRegisterCallback64 function lets an application register a callback function for use by\nthe symbol handler. The symbol handler calls the registered callback function when there is\nSyntax\nBOOL IMAGEAPI SymRegisterCallback(\n [in] HANDLE hProcess,\n [in] PSYMBOL_REGISTERED_CALLBACK CallbackFunction,\n [in] PVOID UserContext\n);\nParameters\nReturn value\nRemarks\nstatus or progress information for the application.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nSymRegisterCallbackW64 is defined as follows in Dbghelp.h.\nC++\nThis function supersedes the SymRegisterCallback function. For more information, see\nUpdated Platform Support. SymRegisterCallback is defined as follows in Dbghelp.h.\nC++\nFor a more extensive example, read Getting Notifications.\nBOOL\nIMAGEAPI\nSymRegisterCallbackW64(\n __in HANDLE hProcess,\n __in PSYMBOL_REGISTERED_CALLBACK64 CallbackFunction,\n __in ULONG64 UserContext\n );\n#ifdef DBGHELP_TRANSLATE_TCHAR\n#define SymRegisterCallback64 SymRegisterCallbackW64\n#endif\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define SymRegisterCallback SymRegisterCallback64\n#else\nBOOL\nIMAGEAPI\nSymRegisterCallback(\n __in HANDLE hProcess,\n __in PSYMBOL_REGISTERED_CALLBACK CallbackFunction,\n __in_opt PVOID UserContext\n );\n#endif\nRequirements\nﾉ Expand table\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nGetting Notifications\nSymInitialize\nSymRegisterCallbackProc64\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["unknown"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3305,"title":"PSYMBOL_REGISTERED_CALLBACK callback function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["psymbol","registered","callback","function","dbghelp","application","defined","used","with","the","symregistercallback64","article08","2022","called","symbol","handler","callback64","type","defines","pointer","this","symregistercallbackproc64","placeholder","for","name","hprocess","handle","process","that","was","originally","passed","syminitialize","actioncode","code","parameter","can","one","following","values"],"errorCode":"","eventId":"","severity":"Low","summary":"An application-defined callback function used with the SymRegisterCallback64 function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to PSYMBOL_REGISTERED_CALLBACK callback function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"PSYMBOL_REGISTERED_CALLBACK callback\nfunction (dbghelp.h)\nArticle08/09/2022\nAn application-defined callback function used with the SymRegisterCallback64 function. It is\ncalled by the symbol handler.\nThe PSYMBOL_REGISTERED_CALLBACK64 type defines a pointer to this callback function.\nSymRegisterCallbackProc64 is a placeholder for the application-defined function name.\nC++\n[in] hProcess\nA handle to the process that was originally passed to the SymInitialize function.\n[in] ActionCode\nThe callback code. This parameter can be one of the following values.\nValue Meaning\nCBA_DEBUG_INFO\n0x10000000\nDisplay verbose information.\nThe CallbackData parameter is a pointer to a string.\nCBA_DEFERRED_SYMBOL_LOAD_CANCEL\n0x00000007\nDeferred symbol loading has started. To cancel the symbol\nload, return TRUE.\nSyntax\nPSYMBOL_REGISTERED_CALLBACK PsymbolRegisteredCallback;\nBOOL PsymbolRegisteredCallback(\n [in] HANDLE hProcess,\n [in] ULONG ActionCode,\n [in, optional] PVOID CallbackData,\n [in, optional] PVOID UserContext\n)\n{...}\nParameters\nﾉ Expand table\nThe CallbackData parameter is a pointer to a\nIMAGEHLP_DEFERRED_SYMBOL_LOAD64 structure.\nCBA_DEFERRED_SYMBOL_LOAD_COMPLETE\n0x00000002\nDeferred symbol load has completed.\nThe CallbackData parameter is a pointer to a\nIMAGEHLP_DEFERRED_SYMBOL_LOAD64 structure.\nCBA_DEFERRED_SYMBOL_LOAD_FAILURE\n0x00000003\nDeferred symbol load has failed.\nThe CallbackData parameter is a pointer to a\nIMAGEHLP_DEFERRED_SYMBOL_LOAD64 structure. The\nsymbol handler will attempt to load the symbols again if\nthe callback function sets the FileName member of this\nstructure.\nCBA_DEFERRED_SYMBOL_LOAD_PARTIAL\n0x00000020\nDeferred symbol load has partially completed. The symbol\nloader is unable to read the image header from either the\nimage file or the specified module.\nThe CallbackData parameter is a pointer to a\nIMAGEHLP_DEFERRED_SYMBOL_LOAD64 structure. The\nsymbol handler will attempt to load the symbols again if\nthe callback function sets the FileName member of this\nstructure.\nDbgHelp 5.1: This value is not supported.\nCBA_DEFERRED_SYMBOL_LOAD_START\n0x00000001\nDeferred symbol load has started.\nThe CallbackData parameter is a pointer to a\nIMAGEHLP_DEFERRED_SYMBOL_LOAD64 structure.\nCBA_DUPLICATE_SYMBOL\n0x00000005\nDuplicate symbols were found. This reason is used only in\nCOFF or CodeView format.\nThe CallbackData parameter is a pointer to a\nIMAGEHLP_DUPLICATE_SYMBOL64 structure. To specify\nwhich symbol to use, set the SelectedSymbol member of\nthis structure.\nCBA_EVENT\n0x00000010\nDisplay verbose information. If you do not handle this\nevent, the information is resent through the\nCBA_DEBUG_INFO event.\nThe CallbackData parameter is a pointer to a\nIMAGEHLP_CBA_EVENT structure.\nCBA_READ_MEMORY\n0x00000006\nThe loaded image has been read.\nThe CallbackData parameter is a pointer to a\nIMAGEHLP_CBA_READ_MEMORY structure. The callback\nfunction should read the number of bytes specified by the\nbytes member into the buffer specified by the buf\nmember, and update the bytesread member accordingly.\nCBA_SET_OPTIONS\n0x00000008\nSymbol options have been updated. To retrieve the\ncurrent options, call the SymGetOptions function.\nThe CallbackData parameter should be ignored.\nCBA_SRCSRV_EVENT\n0x40000000\nDisplay verbose information for source server. If you do\nnot handle this event, the information is resent through\nthe CBA_DEBUG_INFO event.\nThe CallbackData parameter is a pointer to a\nIMAGEHLP_CBA_EVENT structure.\nDbgHelp 6.6 and earlier: This value is not supported.\nCBA_SRCSRV_INFO\n0x20000000\nDisplay verbose information for source server.\nThe CallbackData parameter is a pointer to a string.\nDbgHelp 6.6 and earlier: This value is not supported.\nCBA_SYMBOLS_UNLOADED\n0x00000004\nSymbols have been unloaded.\nThe CallbackData parameter should be ignored.\n[in, optional] CallbackData\nData for the operation. The format of this data depends on the value of the ActionCode\nparameter.\nIf the callback function was registered with SymRegisterCallbackW64, the data is a Unicode\nstring or data structure. Otherwise, the data uses ANSI format.\n[in, optional] UserContext\nUser-defined value specified in SymRegisterCallback64, or NULL. Typically, this parameter is\nused by an application to pass a pointer to a data structure that lets the callback function\nestablish some context.\nTo indicate success handling the code, return TRUE.\nTo indicate failure handling the code, return FALSE. If your code does not handle a particular\ncode, you should also return FALSE. (Returning TRUE in this case may have unintended\nconsequences.)\nThe calling application gets called through the registered callback function as a result of\nanother call to one of the symbol handler functions. The calling application must be prepared\nfor the possible side effects that this can cause. If the application has only one callback function\nReturn value\nRemarks\nthat is being used by multiple threads, then care may be necessary to synchronize some types\nof data access while in the context of the callback function.\nThis callback function supersedes the PSYMBOL_REGISTERED_CALLBACK callback function.\nPSYMBOL_REGISTERED_CALLBACK is defined as follows in Dbghelp.h.\nC++\nFor a more extensive example, read Getting Notifications.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nGetting Notifications\nIMAGEHLP_CBA_EVENT\nIMAGEHLP_CBA_READ_MEMORY\nIMAGEHLP_DEFERRED_SYMBOL_LOAD64\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define PSYMBOL_REGISTERED_CALLBACK PSYMBOL_REGISTERED_CALLBACK64\n#else\ntypedef BOOL\n(CALLBACK *PSYMBOL_REGISTERED_CALLBACK)(\n __in HANDLE hProcess,\n __in ULONG ActionCode,\n __in_opt PVOID CallbackData,\n __in_opt PVOID UserContext\n );\n#endif\nRequirements\nﾉ Expand table\nSee also\nIMAGEHLP_DUPLICATE_SYMBOL64\nSymRegisterCallback64","sourceDocument":"windows-win32-debug.pdf","platforms":["platform-neutral"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3306,"title":"SymRegisterFunctionEntryCallback function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symregisterfunctionentrycallback","function","dbghelp","registers","callback","for","use","the","stack","walking","procedure","alpha","computers","article07","2022","hprocess","handle","process","that","was","originally","passed","stackwalk64","callbackfunction","symregisterfunctionentrycallbackproc64","usercontext","user","defined","value","null","this","simply","normally","parameter","used","application","pass","pointer","data","structure"],"errorCode":"","eventId":"","severity":"Low","summary":"Registers a callback function for use by the stack walking procedure on Alpha computers.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymRegisterFunctionEntryCallback function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymRegisterFunctionEntryCallback function\n(dbghelp.h)\nArticle07/27/2022\nRegisters a callback function for use by the stack walking procedure on Alpha computers.\nC++\n[in] hProcess\nA handle to the process that was originally passed to the StackWalk64 function.\n[in] CallbackFunction\nA SymRegisterFunctionEntryCallbackProc64 callback function.\n[in] UserContext\nA user-defined value or NULL. This value is simply passed to the callback function. Normally,\nthis parameter is used by an application to pass a pointer to a data structure that lets the\ncallback function establish some context.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nSyntax\nBOOL IMAGEAPI SymRegisterFunctionEntryCallback(\n [in] HANDLE hProcess,\n [in] PSYMBOL_FUNCENTRY_CALLBACK CallbackFunction,\n [in] PVOID UserContext\n);\nParameters\nReturn value\nRemarks\nThe SymRegisterFunctionEntryCallback64 function lets an application register a callback\nfunction for use by the stack walking procedure. The stack walking procedure calls the\nregistered callback function when it is unable to locate a function table entry for an address. In\nmost cases, the stack walking procedure locates the function table entries in the function table\nof the image containing the address. However, in situations where the function table entries\nare not in the image, this callback allows the debugger to provide the function table entry from\nanother source. For example, run-time generated code on Alpha computers can define\ndynamic function tables to support exception handling and stack tracing.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nThis function supersedes the SymRegisterFunctionEntryCallback function. For more\ninformation, see Updated Platform Support. SymRegisterFunctionEntryCallback is defined as\nfollows in Dbghelp.h.\nC++\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define SymRegisterFunctionEntryCallback SymRegisterFunctionEntryCallback64\n#else\nBOOL\nIMAGEAPI\nSymRegisterFunctionEntryCallback(\n __in HANDLE hProcess,\n __in PSYMBOL_FUNCENTRY_CALLBACK CallbackFunction,\n __in_opt PVOID UserContext\n );\n#endif\nRequirements\nﾉ Expand table\nRequirement Value\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nStackWalk64\nSymRegisterFunctionEntryCallbackProc64\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["platform-neutral"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3307,"title":"PSYMBOL_FUNCENTRY_CALLBACK callback function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["psymbol","funcentry","callback","function","dbghelp","application","defined","used","with","the","symregisterfunctionentrycallback64","article08","2022","called","stack","walking","procedure","callback64","type","defines","pointer","this","symregisterfunctionentrycallbackproc64","placeholder","for","name","hprocess","handle","process","that","was","originally","passed","stackwalk64","addrbase","address","instruction","which","should","return"],"errorCode":"","eventId":"","severity":"Low","summary":"An application-defined callback function used with the SymRegisterFunctionEntryCallback64\nfunction.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to PSYMBOL_FUNCENTRY_CALLBACK callback function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"PSYMBOL_FUNCENTRY_CALLBACK callback\nfunction (dbghelp.h)\nArticle08/09/2022\nAn application-defined callback function used with the SymRegisterFunctionEntryCallback64\nfunction. It is called by the stack walking procedure.\nThe PSYMBOL_FUNCENTRY_CALLBACK64 type defines a pointer to this callback function.\nSymRegisterFunctionEntryCallbackProc64 is a placeholder for the application-defined\nfunction name.\nC++\n[in] hProcess\nA handle to the process that was originally passed to the StackWalk64 function.\n[in] AddrBase\nThe address of an instruction for which the callback function should return a function table\nentry.\n[in, optional] UserContext\nThe user-defined value specified in SymRegisterFunctionEntryCallback64, or NULL. Typically,\nthis parameter is used by an application to pass a pointer to a data structure that lets the\ncallback function establish some context.\nSyntax\nPSYMBOL_FUNCENTRY_CALLBACK PsymbolFuncentryCallback;\nPVOID PsymbolFuncentryCallback(\n [in] HANDLE hProcess,\n [in] DWORD AddrBase,\n [in, optional] PVOID UserContext\n)\n{...}\nParameters\nReturn value\nReturn the value NULL if no function table entry is available.\nOn success, return a pointer to an IMAGE_RUNTIME_FUNCTION_ENTRY structure. Refer to the\nheader file WinNT.h for the definition of this function.\nThe structure must be returned in exactly the form it exists in the process being debugged.\nSome members may be pointers to other locations in the process address space. The\nReadProcessMemoryProc64 callback function may be called to retrieve the information at\nthese locations.\nThe calling application gets called through the registered callback function as a result of a call\nto the StackWalk64 function. The calling application must be prepared for the possible side\neffects that this can cause. If the application has only one callback function that is being used\nby multiple threads, then it may be necessary to synchronize some types of data access while\nin the context of the callback function.\nThis function is similar to the FunctionTableAccessProc64 callback function. The difference is\nthat FunctionTableAccessProc64 returns an IMAGE_FUNCTION_ENTRY structure, while this\nfunction returns an IMAGE_RUNTIME_FUNCTION_ENTRY structure.\nThis callback function supersedes the PSYMBOL_FUNCENTRY_CALLBACK callback function.\nPSYMBOL_FUNCENTRY_CALLBACK is defined as follows in Dbghelp.h.\nC++\nRemarks\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define PSYMBOL_FUNCENTRY_CALLBACK PSYMBOL_FUNCENTRY_CALLBACK64\n#endif\ntypedef\nPVOID\n(CALLBACK *PSYMBOL_FUNCENTRY_CALLBACK)(\n __in HANDLE hProcess,\n __in DWORD AddrBase,\n __in_opt PVOID UserContext\n );\nRequirements\nﾉ Expand table\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nSymRegisterFunctionEntryCallback64\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3308,"title":"SymSearch function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symsearch","function","dbghelp","searches","for","pdb","symbols","that","meet","the","specified","criteria","article08","2022","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","baseofdll","base","address","module","value","zero","and","mask","contains","exclamation","point","looks","across","modules","does","not"],"errorCode":"","eventId":"","severity":"Low","summary":"Searches for PDB symbols that meet the specified criteria.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymSearch function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymSearch function (dbghelp.h)\nArticle08/09/2022\nSearches for PDB symbols that meet the specified criteria.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] BaseOfDll\nThe base address of the module. If this value is zero and Mask contains an exclamation point\n(!), the function looks across modules. If this value is zero and Mask does not contain an\nexclamation point, the function uses the scope established by the SymSetContext function.\n[in, optional] Index\nA unique value for the symbol.\n[in, optional] SymTag\nThe PDB classification. These values are defined in Dbghelp.h in the SymTagEnum enumeration\ntype. For descriptions, see the PDB documentation.\n[in, optional] Mask\nSyntax\nBOOL IMAGEAPI SymSearch(\n [in] HANDLE hProcess,\n [in] ULONG64 BaseOfDll,\n [in, optional] DWORD Index,\n [in, optional] DWORD SymTag,\n [in, optional] PCSTR Mask,\n [in, optional] DWORD64 Address,\n [in] PSYM_ENUMERATESYMBOLS_CALLBACK EnumSymbolsCallback,\n [in, optional] PVOID UserContext,\n [in] DWORD Options\n);\nParameters\nA wildcard expression that indicates the names of the symbols to be enumerated. To specify a\nmodule name, use the !mod syntax.\n[in, optional] Address\nThe address of the symbol.\n[in] EnumSymbolsCallback\nA SymEnumSymbolsProc callback function that receives the symbol information.\n[in, optional] UserContext\nA user-defined value that is passed to the callback function, or NULL. This parameter is\ntypically used by an application to pass a pointer to a data structure that provides context for\nthe callback function.\n[in] Options\nThe options that control the behavior of this function.\nValue Meaning\nSYMSEARCH_ALLITEMS\n0x08\nInclude all symbols and other data in the .pdb files.\nDbgHelp 6.6 and earlier: This value is not supported.\nSYMSEARCH_GLOBALSONLY\n0x04\nSearch only for global symbols.\nSYMSEARCH_MASKOBJS\n0x01\nFor internal use only.\nSYMSEARCH_RECURSE\n0x02\nRecurse from the top to find all symbols.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nﾉ Expand table\nReturn value\nRemarks\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.2 or later\nDbgHelp Functions\nSymEnumSymbolsProc\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3309,"title":"SymSetContext function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symsetcontext","function","dbghelp","sets","context","information","used","the","symenumsymbols","article02","2024","this","only","works","with","pdb","symbols","hprocess","handle","process","must","have","been","previously","passed","syminitialize","stackframe","pointer","imagehlp","stack","frame","structure","that","contains","optional","parameter","ignored","succeeds","return","value"],"errorCode":"","eventId":"","severity":"Low","summary":"Sets context information used by the SymEnumSymbols function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymSetContext function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymSetContext function (dbghelp.h)\nArticle02/22/2024\nSets context information used by the SymEnumSymbols function. This function only works with\nPDB symbols.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] StackFrame\nA pointer to an IMAGEHLP_STACK_FRAME structure that contains frame information.\n[in, optional] Context\nThis parameter is ignored.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nIf you call SymSetContext to set the context to its current value, the function fails but\nGetLastError returns ERROR_SUCCESS.\nSyntax\nBOOL IMAGEAPI SymSetContext(\n [in] HANDLE hProcess,\n [in] PIMAGEHLP_STACK_FRAME StackFrame,\n [in, optional] PIMAGEHLP_CONTEXT Context\n);\nParameters\nReturn value\nRemarks\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nIMAGEHLP_STACK_FRAME\nSymEnumSymbols\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3310,"title":"SymSetExtendedOption function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symsetextendedoption","function","dbghelp","turns","the","specified","extended","symbol","option","off","article10","2021","turn","following","are","valid","values","value","meaning","symopt","disableaccesstimeupdate","when","set","true","explicitly","updating","last","access","time","that","loaded","default","updates","file","consumed","cache","can","maintained","using","least"],"errorCode":"","eventId":"","severity":"Low","summary":"Turns the specified extended symbol option on or off.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymSetExtendedOption function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymSetExtendedOption function\n(dbghelp.h)\nArticle10/13/2021\nTurns the specified extended symbol option on or off.\nC++\n[in] option\nThe extended symbol option to turn on or off. The following are valid values.\nValue Meaning\nSYMOPT_EX_DISABLEACCESSTIMEUPDATE\n0\nWhen set to TRUE, turns off explicitly updating the last\naccess time of a symbol that is loaded. By default, DbgHelp\nupdates the last access time of a symbol file that is\nconsumed so that a symbol cache can be maintained by\nusing a least recently used mechanism.\n[in] value\nThe value to set for the specified option, either TRUE or FALSE.\nThe previous value of the specified extended option.\nSyntax\nBOOL IMAGEAPI SymSetExtendedOption(\n [in] IMAGEHLP_EXTENDED_OPTIONS option,\n [in] BOOL value\n);\nParameters\nﾉ Expand table\nReturn value\nRequirements\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary DbgHelp.lib\nDLL DbgHelp.dll\nRedistributable DbgHelp.dll 10.0.16232.1000 or later\nIMAGEHLP_EXTENDED_OPTIONS\nSymGetExtendedOption\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3311,"title":"SymSetHomeDirectory function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symsethomedirectory","function","dbghelp","sets","the","home","directory","used","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","optional","dir","writable","otherwise","common","application","specified","with","csidl","appdata","parameter","null","uses","default","succeeds","return","value","pointer","fails","retrieve"],"errorCode":"","eventId":"","severity":"Low","summary":"Sets the home directory used by Dbghelp.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymSetHomeDirectory function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymSetHomeDirectory function\n(dbghelp.h)\nArticle02/22/2024\nSets the home directory used by Dbghelp.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in, optional] dir\nThe home directory. This directory must be writable, otherwise the home directory is the\ncommon application directory specified with CSIDL_COMMON_APPDATA. If this parameter is\nNULL, the function uses the default directory.\nIf the function succeeds, the return value is a pointer to the dir parameter.\nIf the function fails, the return value is NULL. To retrieve extended error information, call\nGetLastError.\nThe default home directory is the directory in which Dbghelp.dll resides. Dbghelp uses this\ndirectory as a basis for other directories, such as the default downstream store directory (the\nsym subdirectory of the home directory).\nSyntax\nPCHAR IMAGEAPI SymSetHomeDirectory(\n [in] HANDLE hProcess,\n [in, optional] PCSTR dir\n);\nParameters\nReturn value\nRemarks\nThe home directory used for the default symbol store and the source server cache location is\nstored in the DBGHELP_HOMEDIR environment variable.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.1 or later\nDbgHelp Functions\nSymGetHomeDirectory\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3312,"title":"SymSetOptions function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symsetoptions","function","dbghelp","symoptions","the","symbol","options","article10","2021","sets","mask","zero","valid","value","and","indicates","that","all","are","turned","off","values","combined","using","operator","form","following","meaning","symopt","allow","absolute","symbols","0x00000800","enables","use","stored","with","addresses","most","rvas"],"errorCode":"","eventId":"","severity":"Low","summary":"C++\n[in] SymOptions\nThe symbol options.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymSetOptions function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymSetOptions function (dbghelp.h)\nArticle10/13/2021\nSets the options mask.\nC++\n[in] SymOptions\nThe symbol options. Zero is a valid value and indicates that all options are turned off. The\noptions values are combined using the OR operator to form a valid options value. The\nfollowing are valid values.\nValue Meaning\nSYMOPT_ALLOW_ABSOLUTE_SYMBOLS\n0x00000800\nEnables the use of symbols that are stored with absolute\naddresses. Most symbols are stored as RVAs from the base\nof the module. DbgHelp translates them to absolute\naddresses. There are symbols that are stored as an absolute\naddress. These have very specialized purposes and are\ntypically not used.\nDbgHelp 5.1 and earlier: This value is not supported.\nSYMOPT_ALLOW_ZERO_ADDRESS\n0x01000000\nEnables the use of symbols that do not have an address. By\ndefault, DbgHelp filters out symbols that do not have an\naddress.\nSYMOPT_AUTO_PUBLICS\n0x00010000\nDo not search the public symbols when searching for\nsymbols by address, or when enumerating symbols, unless\nthey were not found in the global symbols or within the\ncurrent scope. This option has no effect with\nSYMOPT_PUBLICS_ONLY.\nDbgHelp 5.1 and earlier: This value is not supported.\nSyntax\nDWORD IMAGEAPI SymSetOptions(\n [in] DWORD SymOptions\n);\nParameters\nﾉ Expand table\nSYMOPT_CASE_INSENSITIVE\n0x00000001\nAll symbol searches are insensitive to case.\nSYMOPT_DEBUG\n0x80000000\nPass debug output through OutputDebugString or the\nSymRegisterCallbackProc64 callback function.\nSYMOPT_DEFERRED_LOADS\n0x00000004\nSymbols are not loaded until a reference is made requiring\nthe symbols be loaded. This is the fastest, most efficient way\nto use the symbol handler.\nSYMOPT_DISABLE_SYMSRV_AUTODETECT\n0x02000000\nDisables the auto-detection of symbol server stores in the\nsymbol path, even without the \"SRV*\" designation,\nmaintaining compatibility with previous behavior.\nDbgHelp 6.6 and earlier: This value is not supported.\nSYMOPT_EXACT_SYMBOLS\n0x00000400\nDo not load an unmatched .pdb file. Do not load export\nsymbols if all else fails.\nSYMOPT_FAIL_CRITICAL_ERRORS\n0x00000200\nDo not display system dialog boxes when there is a media\nfailure such as no media in a drive. Instead, the failure\nhappens silently.\nSYMOPT_FAVOR_COMPRESSED\n0x00800000\nIf there is both an uncompressed and a compressed file\navailable, favor the compressed file. This option is good for\nslow connections.\nSYMOPT_FLAT_DIRECTORY\n0x00400000\nSymbols are stored in the root directory of the default\ndownstream store.\nDbgHelp 6.1 and earlier: This value is not supported.\nSYMOPT_IGNORE_CVREC\n0x00000080\nIgnore path information in the CodeView record of the\nimage header when loading a .pdb file.\nSYMOPT_IGNORE_IMAGEDIR\n0x00200000\nIgnore the image directory.\nDbgHelp 6.1 and earlier: This value is not supported.\nSYMOPT_IGNORE_NT_SYMPATH\n0x00001000\nDo not use the path specified by _NT_SYMBOL_PATH if the\nuser calls SymSetSearchPath without a valid path.\nDbgHelp 5.1: This value is not supported.\nSYMOPT_INCLUDE_32BIT_MODULES\n0x00002000\nWhen debugging on 64-bit Windows, include any 32-bit\nmodules.\nSYMOPT_LOAD_ANYTHING\n0x00000040\nDisable checks to ensure a file (.exe, .dbg., or .pdb) is the\ncorrect file. Instead, load the first file located.\nSYMOPT_LOAD_LINES\n0x00000010\nLoads line number information.\nSYMOPT_NO_CPP\n0x00000008\nAll C++ decorated symbols containing the symbol separator\n\"::\" are replaced by \"__\". This option exists for debuggers\nthat cannot handle parsing real C++ symbol names.\nSYMOPT_NO_IMAGE_SEARCH\n0x00020000\nDo not search the image for the symbol path when loading\nthe symbols for a module if the module header cannot be\nread.\nDbgHelp 5.1: This value is not supported.\nSYMOPT_NO_PROMPTS\n0x00080000\nPrevents prompting for validation from the symbol server.\nSYMOPT_NO_PUBLICS\n0x00008000\nDo not search the publics table for symbols. This option\nshould have little effect because there are copies of the\npublic symbols in the globals table.\nDbgHelp 5.1: This value is not supported.\nSYMOPT_NO_UNQUALIFIED_LOADS\n0x00000100\nPrevents symbols from being loaded when the caller\nexamines symbols across multiple modules. Examine only\nthe module whose symbols have already been loaded.\nSYMOPT_OVERWRITE\n0x00100000\nOverwrite the downlevel store from the symbol store.\nDbgHelp 6.1 and earlier: This value is not supported.\nSYMOPT_PUBLICS_ONLY\n0x00004000\nDo not use private symbols. The version of DbgHelp that\nshipped with earlier Windows release supported only public\nsymbols; this option provides compatibility with this\nlimitation.\nDbgHelp 5.1: This value is not supported.\nSYMOPT_SECURE\n0x00040000\nDbgHelp will not load any symbol server other than SymSrv.\nSymSrv will not use the downstream store specified in\n_NT_SYMBOL_PATH. After this flag has been set, it cannot\nbe cleared.\nDbgHelp 6.0 and 6.1: This flag can be cleared.\nDbgHelp 5.1: This value is not supported.\nSYMOPT_UNDNAME\n0x00000002\nAll symbols are presented in undecorated form.\nThis option has no effect on global or local symbols\nbecause they are stored undecorated. This option applies\nonly to public symbols.\nThe function returns the current options mask.\nReturn value\nRemarks\nThe options value can be changed any number of times while the library is in use by an\napplication. The option change affects all future calls to the symbol handler.\nTo get the current options mask, call the SymGetOptions function.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nFor an example, see Initializing the Symbol Handler.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nSymGetOptions\nExamples\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3313,"title":"SymSetParentWindow function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symsetparentwindow","function","dbghelp","sets","the","window","that","caller","will","use","display","user","interface","article02","2024","hwnd","handle","succeeds","return","value","true","fails","false","retrieve","extended","error","information","call","getlasterror","all","functions","such","this","one","are","single","threaded","therefore","calls","from"],"errorCode":"","eventId":"","severity":"Low","summary":"Sets the window that the caller will use to display a user interface.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymSetParentWindow function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymSetParentWindow function (dbghelp.h)\nArticle02/22/2024\nSets the window that the caller will use to display a user interface.\nC++\n[in] hwnd\nA handle to the window.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nTarget Platform Windows\nSyntax\nBOOL IMAGEAPI SymSetParentWindow(\n [in] HWND hwnd\n);\nParameters\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nRequirement Value\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.0 or later\nDbgHelp Functions\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3314,"title":"SymSetScopeFromAddr function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symsetscopefromaddr","function","dbghelp","sets","the","local","scope","symbol","that","matches","specified","address","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","succeeds","return","value","true","fails","false","retrieve","extended","error","information","call","getlasterror","all","functions","such","one"],"errorCode":"","eventId":"","severity":"Low","summary":"Sets the local scope to the symbol that matches the specified address.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymSetScopeFromAddr function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymSetScopeFromAddr function\n(dbghelp.h)\nArticle02/22/2024\nSets the local scope to the symbol that matches the specified address.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] Address\nThe address.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nSyntax\nBOOL IMAGEAPI SymSetScopeFromAddr(\n [in] HANDLE hProcess,\n [in] ULONG64 Address\n);\nParameters\nReturn value\nRemarks\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.8 or later\nSymGetScope\nSymSetScopeFromIndex\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3315,"title":"SymSetScopeFromIndex function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symsetscopefromindex","function","dbghelp","sets","the","local","scope","symbol","that","matches","specified","index","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","baseofdll","base","address","module","unique","value","for","succeeds","return","true","fails","false","retrieve","extended","error","information"],"errorCode":"","eventId":"","severity":"Low","summary":"Sets the local scope to the symbol that matches the specified index.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymSetScopeFromIndex function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymSetScopeFromIndex function\n(dbghelp.h)\nArticle02/22/2024\nSets the local scope to the symbol that matches the specified index.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] BaseOfDll\nThe base address of the module.\n[in] Index\nThe unique value for the symbol.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nSyntax\nBOOL IMAGEAPI SymSetScopeFromIndex(\n [in] HANDLE hProcess,\n [in] ULONG64 BaseOfDll,\n [in] DWORD Index\n);\nParameters\nReturn value\nRemarks\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.8 or later\nSymGetScope\nSymSetScopeFromAddr\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3316,"title":"SymSetScopeFromInlineContext function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symsetscopefrominlinecontext","function","dbghelp","sets","the","local","scope","symbol","that","matches","specified","address","and","inline","context","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","inlinecontext","succeeds","return","value","true","fails","false","retrieve","extended","error","information","call","getlasterror"],"errorCode":"","eventId":"","severity":"Low","summary":"Sets the local scope to the symbol that matches the specified address and inline context.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymSetScopeFromInlineContext function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymSetScopeFromInlineContext function\n(dbghelp.h)\nArticle02/22/2024\nSets the local scope to the symbol that matches the specified address and inline context.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in] Address\nThe address.\n[in] InlineContext\nThe inline context.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nSyntax\nBOOL IMAGEAPI SymSetScopeFromInlineContext(\n [in] HANDLE hProcess,\n [in] ULONG64 Address,\n [in] ULONG InlineContext\n);\nParameters\nReturn value\nRequirements\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary DbgHelp.lib\nDLL DbgHelp.dll\nRedistributable DbgHelp.dll 6.2 or later\nﾉ Expand table","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3317,"title":"SymSetSearchPath function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symsetsearchpath","function","dbghelp","sets","the","search","path","for","specified","process","article02","2024","hprocess","handle","that","was","originally","passed","syminitialize","optional","searchpath","symbol","string","can","contain","multiple","paths","separated","semicolons","succeeds","return","value","true","fails","false","retrieve","extended","error","information","call"],"errorCode":"","eventId":"","severity":"Low","summary":"Sets the search path for the specified process.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymSetSearchPath function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymSetSearchPath function (dbghelp.h)\nArticle02/22/2024\nSets the search path for the specified process.\nC++\n[in] hProcess\nA handle to the process that was originally passed to the SymInitialize function.\n[in, optional] SearchPath\nThe symbol search path. The string can contain multiple paths separated by semicolons.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe symbol search path can be changed any number of times while the library is in use by an\napplication. The change affects all future calls to the symbol handler.\nTo get the current search path, call the SymGetSearchPath function.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nSyntax\nBOOL IMAGEAPI SymSetSearchPath(\n [in] HANDLE hProcess,\n [in, optional] PCSTR SearchPath\n);\nParameters\nReturn value\nRemarks\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nSymGetSearchPath\nSymInitialize\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3318,"title":"SymSrvDeltaName function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symsrvdeltaname","function","dbghelp","generates","the","name","for","file","that","describes","relationship","between","two","different","versions","same","symbol","image","article08","2022","using","this","feature","prevents","applications","from","having","regenerate","such","information","every","time","they","analyze","files","hprocess","handle","process","must","have"],"errorCode":"","eventId":"","severity":"Low","summary":"Generates the name for a file that describes the relationship between two different versions of\nthe same symbol or image file.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymSrvDeltaName function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymSrvDeltaName function (dbghelp.h)\nArticle08/09/2022\nGenerates the name for a file that describes the relationship between two different versions of\nthe same symbol or image file. Using this feature prevents applications from having to\nregenerate such information every time they analyze two files.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in, optional] SymPath\nThe symbol path. The function uses only the symbol stores described in standard syntax for\nsymbol stores. All other paths are ignored. If this parameter is NULL, the function uses the\nsymbol path set using the SymInitialize or SymSetSearchPath function.\n[in] Type\nThe extension for the generated file name.\n[in] File1\nThe path of the first version of the symbol or image file.\n[in] File2\nThe path of the second version of the symbol or image file.\nSyntax\nPCSTR IMAGEAPI SymSrvDeltaName(\n [in] HANDLE hProcess,\n [in, optional] PCSTR SymPath,\n [in] PCSTR Type,\n [in] PCSTR File1,\n [in] PCSTR File2\n);\nParameters\nIf the function succeeds, the return value is the resulting file name.\nIf the function fails, the return value is NULL. To retrieve extended error information, call\nGetLastError.\nThis function opens the two specified files, reads the indexing information from the header,\nand passes this information to the symbol server so it can create the file name. If you specify\nthe Type parameter as \"xml\", the name is the index of File1, followed by a dash, followed by the\nindex of File2, followed by an .xml extension. For example:\n3F3D5C755000-3F3D647621000.xml\nThis function returns a pointer to a buffer that may be reused by another function. Therefore,\nbe sure to copy the data returned to another buffer immediately.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.3 or later\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nSee also\nDbgHelp Functions","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3319,"title":"SymSrvGetFileIndexes function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symsrvgetfileindexes","function","dbghelp","retrieves","the","indexes","for","specified","pdb","dbg","image","file","that","would","used","store","article02","2024","combination","these","values","uniquely","identifies","symbol","server","they","can","when","calling","symfindfileinpath","search","name","out","first","three","identifying","parameters","val1","second","optional"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the indexes for the specified .pdb, .dbg, or image file that would be used to store the\nfile.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymSrvGetFileIndexes function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymSrvGetFileIndexes function (dbghelp.h)\nArticle02/22/2024\nRetrieves the indexes for the specified .pdb, .dbg, or image file that would be used to store the\nfile. The combination of these values uniquely identifies the file in the symbol server. They can\nbe used when calling the SymFindFileInPath function to search for a file in a symbol store.\nC++\n[in] File\nThe name of the file.\n[out] Id\nThe first of three identifying parameters.\n[out] Val1\nThe second of three identifying parameters.\n[out, optional] Val2\nThe third of three identifying parameters.\n[in] Flags\nThis parameter is reserved for future use.\nIf the function succeeds, the return value is nonzero.\nSyntax\nBOOL IMAGEAPI SymSrvGetFileIndexes(\n [in] PCSTR File,\n [out] GUID *Id,\n [out] PDWORD Val1,\n [out, optional] PDWORD Val2,\n [in] DWORD Flags\n);\nParameters\nReturn value\nIf the function fails, the return value is zero. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.3 or later\nDbgHelp Functions\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3320,"title":"SymSrvGetFileIndexInfo function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symsrvgetfileindexinfo","function","dbghelp","retrieves","the","index","information","for","specified","pdb","dbg","image","file","article02","2024","name","out","info","symsrv","structure","that","receives","flags","this","parameter","reserved","future","use","succeeds","return","value","true","fails","false","retrieve","extended","error","call","getlasterror","not"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the index information for the specified .pdb, .dbg, or image file.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymSrvGetFileIndexInfo function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymSrvGetFileIndexInfo function\n(dbghelp.h)\nArticle02/22/2024\nRetrieves the index information for the specified .pdb, .dbg, or image file.\nC++\n[in] File\nThe name of the file.\n[out] Info\nA SYMSRV_INDEX_INFO structure that receives the index information.\n[in] Flags\nThis parameter is reserved for future use.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThis function is not for general use. Those writing utilities for the management of files in\nsymbol server stores may use to this function to predict the relative path the symbol server will\nSyntax\nBOOL IMAGEAPI SymSrvGetFileIndexInfo(\n [in] PCSTR File,\n [out] PSYMSRV_INDEX_INFO Info,\n [in] DWORD Flags\n);\nParameters\nReturn value\nRemarks\nlook for a file. It is used by srctool.exe to actually populate symbol server stores. It may also be\nof use to those looking to find the parameters to feed the SymFindFileInPath function.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.6 or later\nDbgHelp Functions\nSYMSRV_INDEX_INFO\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3321,"title":"SymSrvGetFileIndexString function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symsrvgetfileindexstring","function","dbghelp","retrieves","the","index","string","for","specified","pdb","dbg","image","file","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","optional","srvpath","path","symbol","server","name","out","pointer","buffer","that","receives","size","characters","flags","syntax"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the index string for the specified .pdb, .dbg, or image file.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymSrvGetFileIndexString function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymSrvGetFileIndexString function\n(dbghelp.h)\nArticle02/22/2024\nRetrieves the index string for the specified .pdb, .dbg, or image file.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in, optional] SrvPath\nThe path to the symbol server.\n[in] File\nThe name of the file.\n[out] Index\nA pointer to a buffer that receives the index string.\n[in] Size\nThe size of the Index buffer, in characters.\n[in] Flags\nSyntax\nBOOL IMAGEAPI SymSrvGetFileIndexString(\n [in] HANDLE hProcess,\n [in, optional] PCSTR SrvPath,\n [in] PCSTR File,\n [out] PSTR Index,\n [in] size_t Size,\n [in] DWORD Flags\n);\nParameters\nThis parameter is reserved for future use.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThis function is not for general use. Those writing utilities for the management of files in\nsymbol server stores may use to this function to predict the relative path the symbol server will\nlook for a file. It is used by srctool.exe to actually populate symbol server stores.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary DbgHelp.lib\nDLL DbgHelp.dll\nRedistributable DbgHelp.dll 6.3 or later\nDbgHelp Functions\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3322,"title":"SymSrvGetSupplement function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symsrvgetsupplement","function","dbghelp","retrieves","the","specified","file","from","supplement","for","symbol","store","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","optional","sympath","path","uses","only","stores","described","standard","syntax","all","other","paths","are","ignored","parameter","null"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the specified file from the supplement for a symbol store.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymSrvGetSupplement function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymSrvGetSupplement function\n(dbghelp.h)\nArticle02/22/2024\nRetrieves the specified file from the supplement for a symbol store.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in, optional] SymPath\nThe symbol path. The function uses only the symbol stores described in standard syntax for\nsymbol stores. All other paths are ignored. If this parameter is NULL, the function uses the\nsymbol path set using the SymInitialize or SymSetSearchPath function.\n[in] Node\nThe symbol file associated with the supplemental file.\n[in] File\nThe name of the file.\nIf the function succeeds, the return value is the fully qualified path for the supplemental file.\nSyntax\nPCSTR IMAGEAPI SymSrvGetSupplement(\n [in] HANDLE hProcess,\n [in, optional] PCSTR SymPath,\n [in] PCSTR Node,\n [in] PCSTR File\n);\nParameters\nReturn value\nIf the function fails, the return value is NULL. To retrieve extended error information, call\nGetLastError.\nFor more information on supplemental files, see SymSrvStoreSupplement.\nThis function returns a pointer to a buffer that may be reused by another function. Therefore,\nbe sure to copy the data returned to another buffer immediately.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.3 or later\nDbgHelp Functions\nSymSrvStoreSupplement\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3323,"title":"SymSrvIsStore function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symsrvisstore","function","dbghelp","determines","whether","the","specified","path","points","symbol","store","article02","2024","optional","hprocess","handle","process","that","you","previously","passed","syminitialize","this","parameter","set","null","only","exists","otherwise","and","contains","entry","for","can","specify","default","example","srv","point","http"],"errorCode":"","eventId":"","severity":"Low","summary":"Determines whether the specified path points to a symbol store.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymSrvIsStore function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymSrvIsStore function (dbghelp.h)\nArticle02/22/2024\nDetermines whether the specified path points to a symbol store.\nC++\n[in, optional] hProcess\nThe handle of a process that you previously passed to the SymInitialize function. If this\nparameter is set to NULL, the function determines only whether the store exists; otherwise, the\nfunction determines whether the store exists and contains a process entry for the specified\nprocess handle.\n[in] path\nThe path to a symbol store. The path can specify the default symbol store (for example, SRV*),\npoint to an HTTP or HTTPS symbol server, or specify a UNC, absolute, or relative path to the\nstore.\nIf the path specifies a symbol store, the function returns TRUE. Otherwise, it returns FALSE. To\nget extended error information, call the GetLastError function.\nIf the path points to the default symbol store (for example, SRV*) or to an HTTP or HTTPS\nsymbol server, the function assumes the store exists.\nIf there is a proxy computer between the client computer and the server, the version of the\nSymSrv.dll on the proxy cannot be less than the version that is on the client.\nSyntax\nBOOL IMAGEAPI SymSrvIsStore(\n [in, optional] HANDLE hProcess,\n [in] PCSTR path\n);\nParameters\nReturn value\nRemarks\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.3 or later\nDbgHelp Functions\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3324,"title":"SymSrvStoreFile function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symsrvstorefile","function","dbghelp","stores","file","the","specified","symbol","store","article02","2024","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","optional","srvpath","name","flags","that","control","parameter","can","one","following","values","value","meaning","symstoreopt","compress","0x01","overwrite","0x02","exists"],"errorCode":"","eventId":"","severity":"Low","summary":"Stores a file in the specified symbol store.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymSrvStoreFile function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymSrvStoreFile function (dbghelp.h)\nArticle02/22/2024\nStores a file in the specified symbol store.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in, optional] SrvPath\nThe symbol store.\n[in] File\nThe name of the file.\n[in] Flags\nThe flags that control the function. This parameter can be one of the following values.\nValue Meaning\nSYMSTOREOPT_COMPRESS\n0x01\nCompress the file.\nSYMSTOREOPT_OVERWRITE\n0x02\nOverwrite the file if it exists.\nSyntax\nPCSTR IMAGEAPI SymSrvStoreFile(\n [in] HANDLE hProcess,\n [in, optional] PCSTR SrvPath,\n [in] PCSTR File,\n [in] DWORD Flags\n);\nParameters\nﾉ Expand table\nSYMSTOREOPT_PASS_IF_EXISTS\n0x40\nDo not report an error if the file already exists in the symbol\nstore.\nSYMSTOREOPT_POINTER\n0x08\nStore in File.ptr.\nSYMSTOREOPT_RETURNINDEX\n0x04\nReturn the index only.\nIf the function succeeds, the return value is a pointer to a null-terminated string that specifies\nthe full-qualified path to the stored file.\nIf the function fails, the return value is NULL. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nThis function returns a pointer to a buffer that may be reused by another function. Therefore,\nbe sure to copy the data returned to another buffer immediately.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 6.3 or later\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nDbgHelp Functions\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3325,"title":"SymSrvStoreSupplement function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symsrvstoresupplement","function","dbghelp","stores","file","the","specified","supplement","symbol","store","article02","2024","typically","associated","with","server","hprocess","handle","process","this","must","have","been","previously","passed","syminitialize","optional","srvpath","path","node","supplemental","name","flags","parameter","symstoreopt","compress","compressed","currently","there","are"],"errorCode":"","eventId":"","severity":"Low","summary":"Stores a file in the specified supplement to a symbol store.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymSrvStoreSupplement function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymSrvStoreSupplement function\n(dbghelp.h)\nArticle02/22/2024\nStores a file in the specified supplement to a symbol store. The file is typically associated with a\nfile in the symbol server.\nC++\n[in] hProcess\nA handle to a process. This handle must have been previously passed to the SymInitialize\nfunction.\n[in, optional] SrvPath\nThe path to the symbol store.\n[in] Node\nThe symbol file associated with the supplemental file.\n[in] File\nThe name of the file.\n[in] Flags\nIf this parameter is SYMSTOREOPT_COMPRESS, the file is compressed in the symbol store.\nCurrently, there are no other supported values.\nSyntax\nPCSTR IMAGEAPI SymSrvStoreSupplement(\n [in] HANDLE hProcess,\n [in, optional] PCSTR SrvPath,\n [in] PCSTR Node,\n [in] PCSTR File,\n [in] DWORD Flags\n);\nParameters\nIf the function succeeds, the return value is the fully qualified path for the supplemental file.\nIf the function fails, the return value is NULL. To retrieve extended error information, call\nGetLastError.\nAn important use for this function is to store delta files. For more information, see\nSymSrvDeltaName.\nThis function returns a pointer to a buffer that may be reused by another function. Therefore,\nbe sure to copy the data returned to another buffer immediately.\nThe symbol server stores supplemental files with the same extension in a common directory.\nFor example, Sup1.xml would be stored in the following directory:\nSymPath\\supplement\\Node\\xml.\nThe administrator of a store can prevent users from writing supplemental files by creating a\nread-only file in the root of the store named Supplement. Alternatively, the administrator can\ncreate the supplement directory and use ACLs to control access.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nRequirement Value\nRedistributable DbgHelp.dll 6.3 or later\nDbgHelp Functions\nSymSrvGetSupplement\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3326,"title":"SymUnDName function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symundname","function","dbghelp","undecorates","decorated","symbol","name","article07","2022","applications","can","also","use","the","undecoratesymbolname","sym","pointer","imagehlp","symbol64","structure","that","specifies","undecorated","out","undecname","buffer","receives","undecnamelength","size","characters","succeeds","return","value","true","fails","false","retrieve","extended","error","information"],"errorCode":"","eventId":"","severity":"Low","summary":"Undecorates a decorated C++ symbol name.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymUnDName function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymUnDName function (dbghelp.h)\nArticle07/27/2022\nUndecorates a decorated C++ symbol name.\nApplications can also use the UnDecorateSymbolName function.\nC++\n[in] sym\nA pointer to an IMAGEHLP_SYMBOL64 structure that specifies the symbol to be undecorated.\n[out] UnDecName\nA pointer to a buffer that receives the undecorated name.\n[in] UnDecNameLength\nThe size of the UnDecName buffer, in characters.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\nSyntax\nBOOL IMAGEAPI SymUnDName(\n [in] PIMAGEHLP_SYMBOL sym,\n [out] PSTR UnDecName,\n [in] DWORD UnDecNameLength\n);\nParameters\nReturn value\nRemarks\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nThis function supersedes the SymUnDName function. For more information, see Updated\nPlatform Support. SymUnDName is defined as follows in Dbghelp.h.\nC++\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nUnDecorateSymbolName\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define SymUnDName SymUnDName64\n#else\nBOOL\nIMAGEAPI\nSymUnDName(\n __in PIMAGEHLP_SYMBOL sym, \n __out_ecount(UnDecNameLength) PSTR UnDecName, \n __in DWORD UnDecNameLength \n );\n#endif\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3327,"title":"SymUnloadModule function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symunloadmodule","function","dbghelp","hprocess","handle","the","process","that","was","originally","passed","syminitialize","article02","2025","unloads","symbol","table","baseofdll","base","address","module","unloaded","succeeds","return","value","true","fails","false","retrieve","extended","error","information","call","getlasterror","all","functions","such","this","one","are"],"errorCode":"","eventId":"","severity":"Low","summary":"C++\n[in] hProcess\nA handle to the process that was originally passed to the SymInitialize function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SymUnloadModule function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SymUnloadModule function (dbghelp.h)\nArticle02/12/2025\nUnloads the symbol table.\nC++\n[in] hProcess\nA handle to the process that was originally passed to the SymInitialize function.\n[in] BaseOfDll\nThe base address of the module that is to be unloaded.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nThe SymUnloadModule64 function supersedes this function. For more information, see\nUpdated Platform Support. SymUnloadedModule is defined as follows in Dbghelp.h.\nC++\nSyntax\nBOOL IMAGEAPI SymUnloadModule(\n [in] HANDLE hProcess,\n [in] DWORD BaseOfDll\n);\nParameters\nReturn value\nRemarks\nFor an example, see Unloading a Symbol Module.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nSymInitialize\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define SymUnloadModule SymUnloadModule64\n#else\nBOOL\nIMAGEAPI\nSymUnloadModule(\n __in HANDLE hProcess,\n __in DWORD BaseOfDll\n );\n#endif\nExamples\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3328,"title":"PTRANSLATE_ADDRESS_ROUTINE callback function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["ptranslate","address","routine","callback","function","dbghelp","application","defined","used","with","the","stackwalk64","article02","2024","provides","translation","for","bit","addresses","routine64","type","defines","pointer","this","translateaddressproc64","placeholder","name","hprocess","handle","process","which","stack","trace","generated","hthread","thread","lpaddr","translated","returns","syntax"],"errorCode":"","eventId":"","severity":"Low","summary":"An application-defined callback function used with the StackWalk64 function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to PTRANSLATE_ADDRESS_ROUTINE callback function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"PTRANSLATE_ADDRESS_ROUTINE callback\nfunction (dbghelp.h)\nArticle02/22/2024\nAn application-defined callback function used with the StackWalk64 function. It provides\naddress translation for 16-bit addresses.\nThe PTRANSLATE_ADDRESS_ROUTINE64 type defines a pointer to this callback function.\nTranslateAddressProc64 is a placeholder for the application-defined function name.\nC++\n[in] hProcess\nA handle to the process for which the stack trace is generated.\n[in] hThread\nA handle to the thread for which the stack trace is generated.\n[in] lpaddr\nAn address to be translated.\nThe function returns the translated address.\nSyntax\nPTRANSLATE_ADDRESS_ROUTINE PtranslateAddressRoutine;\nDWORD PtranslateAddressRoutine(\n [in] HANDLE hProcess,\n [in] HANDLE hThread,\n [in] LPADDRESS lpaddr\n)\n{...}\nParameters\nReturn value\nThis callback function supersedes the PTRANSLATE_ADDRESS_ROUTINE callback function.\nPTRANSLATE_ADDRESS_ROUTINE is defined as follows in Dbghelp.h.\nC++\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nStackWalk64\nRemarks\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define PTRANSLATE_ADDRESS_ROUTINE PTRANSLATE_ADDRESS_ROUTINE64\n#else\ntypedef\nDWORD\n(__stdcall *PTRANSLATE_ADDRESS_ROUTINE)(\n __in HANDLE hProcess,\n __in HANDLE hThread,\n __out LPADDRESS lpaddr\n );\n#endif\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3329,"title":"UnDecorateSymbolName function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["undecoratesymbolname","function","dbghelp","undecorates","the","specified","decorated","symbol","name","article08","2022","this","can","identified","first","character","which","always","question","mark","out","outputstring","pointer","string","buffer","that","receives","undecorated","maxstringlength","size","undecoratedname","characters","flags","options","for","how","parameter","zero","more","following"],"errorCode":"","eventId":"","severity":"Low","summary":"Undecorates the specified decorated C++ symbol name.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to UnDecorateSymbolName function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"UnDecorateSymbolName function\n(dbghelp.h)\nArticle08/09/2022\nUndecorates the specified decorated C++ symbol name.\nC++\n[in] name\nThe decorated C++ symbol name. This name can be identified by the first character of the\nname, which is always a question mark (?).\n[out] outputString\nA pointer to a string buffer that receives the undecorated name.\n[in] maxStringLength\nThe size of the UnDecoratedName buffer, in characters.\n[in] flags\nThe options for how the decorated name is undecorated. This parameter can be zero or more\nof the following values.\nValue Meaning\nUNDNAME_32_BIT_DECODE\n0x0800\nUndecorate 32-bit decorated names.\nSyntax\nDWORD IMAGEAPI UnDecorateSymbolName(\n [in] PCSTR name,\n [out] PSTR outputString,\n [in] DWORD maxStringLength,\n [in] DWORD flags\n);\nParameters\nﾉ Expand table\nUNDNAME_COMPLETE\n0x0000\nEnable full undecoration.\nUNDNAME_NAME_ONLY\n0x1000\nUndecorate only the name for primary declaration. Returns\n[scope::]name. Does expand template parameters.\nUNDNAME_NO_ACCESS_SPECIFIERS\n0x0080\nDisable expansion of access specifiers for members.\nUNDNAME_NO_ALLOCATION_LANGUAGE\n0x0010\nDisable expansion of the declaration language specifier.\nUNDNAME_NO_ALLOCATION_MODEL\n0x0008\nDisable expansion of the declaration model.\nUNDNAME_NO_ARGUMENTS\n0x2000\nDo not undecorate function arguments.\nUNDNAME_NO_CV_THISTYPE\n0x0040\nDisable expansion of CodeView modifiers on the this type\nfor primary declaration.\nUNDNAME_NO_FUNCTION_RETURNS\n0x0004\nDisable expansion of return types for primary declarations.\nUNDNAME_NO_LEADING_UNDERSCORES\n0x0001\nRemove leading underscores from Microsoft keywords.\nUNDNAME_NO_MEMBER_TYPE\n0x0200\nDisable expansion of the static or virtual attribute of\nmembers.\nUNDNAME_NO_MS_KEYWORDS\n0x0002\nDisable expansion of Microsoft keywords.\nUNDNAME_NO_MS_THISTYPE\n0x0020\nDisable expansion of Microsoft keywords on the this type\nfor primary declaration.\nUNDNAME_NO_RETURN_UDT_MODEL\n0x0400\nDisable expansion of the Microsoft model for user-defined\ntype returns.\nUNDNAME_NO_SPECIAL_SYMS\n0x4000\nDo not undecorate special names, such as vtable, vcall,\nvector, metatype, and so on.\nUNDNAME_NO_THISTYPE\n0x0060\nDisable all modifiers on the this type.\nUNDNAME_NO_THROW_SIGNATURES\n0x0100\nDisable expansion of throw-signatures for functions and\npointers to functions.\nReturn value\nIf the function succeeds, the return value is the number of characters in the UnDecoratedName\nbuffer, not including the NULL terminator.\nIf the function fails, the return value is zero. To retrieve extended error information, call\nGetLastError.\nIf the function fails and returns zero, the content of the UnDecoratedName buffer is\nundetermined.\nTo use undecorated symbols, call the SymSetOptions function with the SYMOPT_UNDNAME\noption.\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nTo call the Unicode version of this function, define DBGHELP_TRANSLATE_TCHAR.\nFor an example, see Retrieving Undecorated Symbol Names.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nRemarks\nExamples\nRequirements\nﾉ Expand table\nSee also\nDbgHelp Functions\nSymSetOptions","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3330,"title":"UnmapDebugInformation function (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["unmapdebuginformation","function","dbghelp","deallocates","the","memory","and","resources","allocated","call","mapdebuginformation","article10","2021","debuginfo","pointer","image","debug","information","structure","that","returned","from","succeeds","return","value","true","fails","false","retrieve","extended","error","getlasterror","counterpart","must","used","deallocate","note","this","provided","only"],"errorCode":"","eventId":"","severity":"Low","summary":"Deallocates the memory and resources allocated by a call to the MapDebugInformation\nfunction.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to UnmapDebugInformation function (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"UnmapDebugInformation function\n(dbghelp.h)\nArticle10/13/2021\nDeallocates the memory and resources allocated by a call to the MapDebugInformation\nfunction.\n \nC++\n[in] DebugInfo\nA pointer to an IMAGE_DEBUG_INFORMATION structure that is returned from a call to\nMapDebugInformation.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe UnmapDebugInformation function is the counterpart to the MapDebugInformation\nfunction and must be used to deallocate the memory and resources allocated by a call to the\nMapDebugInformation function.\nNote This function is provided only for backward compatibility. New applications should\nuse the SymUnloadModule64 function.\nSyntax\nBOOL IMAGEAPI UnmapDebugInformation(\n [in] PIMAGE_DEBUG_INFORMATION DebugInfo\n);\nParameters\nReturn value\nRemarks\nAll DbgHelp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nTarget Platform Windows\nHeader dbghelp.h\nLibrary Dbghelp.lib\nDLL Dbghelp.dll\nRedistributable DbgHelp.dll 5.1 or later\nDbgHelp Functions\nIMAGE_DEBUG_INFORMATION\nMapDebugInformation\nRequirements\nﾉ Expand table\nSee also\nDbgHelp Structures\nThe following are the DbgHelp structures:\nTopic Description\n_IMAGE_RUNTIME_FUNCTION_ENTRY Represents an entry in the function table on 64-bit\nWindows.\nADDRESS64 Represents an address. It is used in the\nSTACKFRAME64 structure.\nAPI_VERSION Contains the library version.\nFPO_DATA Represents the stack frame layout for a function on\nan x86 computer when frame pointer omission (FPO)\noptimization is used. The structure is used to locate\nthe base of the call frame.\nIMAGE_DEBUG_INFORMATION Contains debugging information.\nIMAGEHLP_CBA_EVENT Contains information about a debugging event.\nIMAGEHLP_CBA_READ_MEMORY Contains information about a memory read\noperation.\nIMAGEHLP_DEFERRED_SYMBOL_LOAD64 Contains information about a deferred symbol load.\nIMAGEHLP_DUPLICATE_SYMBOL64 Contains duplicate symbol information.\nIMAGEHLP_GET_TYPE_INFO_PARAMS Contains type information for a module.\nIMAGEHLP_LINE64 Represents a source file line.\nIMAGEHLP_MODULE64 Contains module information.\nIMAGEHLP_STACK_FRAME Contains the stack frame information.\nIMAGEHLP_SYMBOL64 Contains symbol information.\nKDHELP64 Information that is used by kernel debuggers to\ntrace through user-mode callbacks in a thread's\nkernel stack.\nLOADED_IMAGE Contains information about the loaded image.\nIn this section\nﾉ Expand table\nTopic Description\nMINIDUMP_CALLBACK_INFORMATION Contains a pointer to an optional callback function\nthat can be used by the MiniDumpWriteDump\nfunction.\nMINIDUMP_CALLBACK_INPUT Contains information used by the\nMiniDumpCallback function.\nMINIDUMP_CALLBACK_OUTPUT Contains information returned by the\nMiniDumpCallback function.\nMINIDUMP_DIRECTORY Contains the information needed to access a specific\ndata stream in a minidump file.\nMINIDUMP_EXCEPTION Contains exception information.\nMINIDUMP_EXCEPTION_INFORMATION Contains the exception information written to the\nminidump file by the MiniDumpWriteDump\nfunction.\nMINIDUMP_EXCEPTION_STREAM Represents an exception information stream.\nMINIDUMP_FUNCTION_TABLE_DESCRIPTOR Represents a function table stream.\nMINIDUMP_FUNCTION_TABLE_STREAM Represents the header for the function table stream.\nMINIDUMP_HANDLE_DATA_STREAM Represents the header for a handle data stream.\nMINIDUMP_HANDLE_DESCRIPTOR Contains the state of an individual system handle at\nthe time the minidump was written.\nMINIDUMP_HANDLE_DESCRIPTOR_2 Describes the state of an individual system handle at\nthe time the minidump was written.\nMINIDUMP_HANDLE_OBJECT_INFORMATION Contains object-specific information for a handle.\nMINIDUMP_HANDLE_OPERATION_LIST Contains a list of handle operations.\nMINIDUMP_HEADER Contains header information for the minidump file.\nMINIDUMP_INCLUDE_MODULE_CALLBACK Contains information for the MiniDumpCallback\nfunction when the callback type is\nIncludeModuleCallback.\nMINIDUMP_INCLUDE_THREAD_CALLBACK Contains information for the MiniDumpCallback\nfunction when the callback type is\nIncludeThreadCallback.\nMINIDUMP_IO_CALLBACK Contains I/O callback information.\nMINIDUMP_LOCATION_DESCRIPTOR Contains information describing the location of a\nTopic Description\ndata stream within a minidump file.\nMINIDUMP_MEMORY_DESCRIPTOR Describes a range of memory.\nMINIDUMP_MEMORY_INFO Describes a region of memory.\nMINIDUMP_MEMORY_INFO_LIST Contains a list of memory regions.\nMINIDUMP_MEMORY_LIST Contains a list of memory ranges.\nMINIDUMP_MISC_INFO Contains a variety of information.\nMINIDUMP_MISC_INFO_2 Represents information in the miscellaneous\ninformation stream.\nMINIDUMP_MODULE Contains information for a specific module.\nMINIDUMP_MODULE_CALLBACK Contains module information for the\nMiniDumpCallback function when the callback type\nis ModuleCallback.\nMINIDUMP_MODULE_LIST Contains a list of modules.\nMINIDUMP_READ_MEMORY_FAILURE_CALLBACK Contains information about a failed memory read\noperation.\nMINIDUMP_STRING Describes a string.\nMINIDUMP_SYSTEM_INFO Contains processor and operating system\ninformation.\nMINIDUMP_THREAD Contains information for a specific thread.\nMINIDUMP_THREAD_CALLBACK Contains thread information for the\nMiniDumpCallback function when the callback type\nis ThreadCallback.\nMINIDUMP_THREAD_EX Contains extended information for a specific thread.\nMINIDUMP_THREAD_EX_CALLBACK Contains extended thread information for the\nMiniDumpCallback function when the callback type\nis ThreadExCallback.\nMINIDUMP_THREAD_EX_LIST Contains a list of threads.\nMINIDUMP_THREAD_INFO Contains thread state information.\nMINIDUMP_THREAD_INFO_LIST Contains a list of threads.\nMINIDUMP_THREAD_LIST Contains a list of threads.\nTopic Description\nMINIDUMP_UNLOADE","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3331,"title":"RUNTIME_FUNCTION structure (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["runtime","function","structure","winnt","represents","entry","the","table","bit","windows","article02","2024","beginaddress","address","start","endaddress","end","dummyunionname","unwindinfoaddress","unwind","information","for","unwinddata","syntax","typedef","struct","image","dword","union","pruntime","pimage","members","requirements","expand","feedback","was","this","page","helpful","requirement"],"errorCode":"","eventId":"","severity":"Low","summary":"Represents an entry in the function table on 64-bit Windows.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to RUNTIME_FUNCTION structure (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"RUNTIME_FUNCTION structure\n(winnt.h)\nArticle02/22/2024\nRepresents an entry in the function table on 64-bit Windows.\nC++\nBeginAddress\nThe address of the start of the function.\nEndAddress\nThe address of the end of the function.\nDUMMYUNIONNAME\nDUMMYUNIONNAME.UnwindInfoAddress\nThe address of the unwind information for the function.\nDUMMYUNIONNAME.UnwindData\nSyntax\ntypedef struct _IMAGE_RUNTIME_FUNCTION_ENTRY {\n DWORD BeginAddress;\n DWORD EndAddress;\n union {\n DWORD UnwindInfoAddress;\n DWORD UnwindData;\n } DUMMYUNIONNAME;\n} RUNTIME_FUNCTION, *PRUNTIME_FUNCTION, _IMAGE_RUNTIME_FUNCTION_ENTRY, \n*_PIMAGE_RUNTIME_FUNCTION_ENTRY;\nMembers\nRequirements\nﾉ Expand table\nFeedback\nWas this page helpful?\nRequirement Value\nHeader winnt.h (include Windows.h)\nRedistributable DbgHelp.dll 5.1 or later\nSymFunctionTableAccess64\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3332,"title":"ADDRESS structure (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["address","structure","dbghelp","used","the","stackframe64","article07","2022","represents","offset","into","segment","bit","virtual","interpretation","this","value","depends","contained","mode","member","number","only","for","addressing","can","one","following","values","meaning","addrmode1616","support","you","must","supply","translateaddressproc64","callback","function","addrmode1632","addrmodereal"],"errorCode":"","eventId":"","severity":"Low","summary":"It is used in the STACKFRAME64 structure.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to ADDRESS structure (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"ADDRESS structure (dbghelp.h)\nArticle07/27/2022\nRepresents an address. It is used in the STACKFRAME64 structure.\nC++\nOffset\nThe offset into the segment, or a 32-bit virtual address. The interpretation of this value\ndepends on the value contained in the Mode member.\nSegment\nThe segment number. This value is used only for 16-bit addressing.\nMode\nThe addressing mode. This member can be one of the following values.\nValue Meaning\nAddrMode1616\n0\n16:16 addressing. To support this addressing mode, you must\nsupply a TranslateAddressProc64 callback function.\nAddrMode1632\n1\n16:32 addressing. To support this addressing mode, you must\nsupply a TranslateAddressProc64 callback function.\nAddrModeReal\n2\nReal-mode addressing. To support this addressing mode, you\nmust supply a TranslateAddressProc64 callback function.\nAddrModeFlat\n3\nFlat addressing. This is the only addressing mode supported\nby the library.\nSyntax\ntypedef struct _tagADDRESS {\n DWORD Offset;\n WORD Segment;\n ADDRESS_MODE Mode;\n} ADDRESS, *LPADDRESS;\nMembers\nﾉ Expand table\nThis structure supersedes the ADDRESS structure. For more information, see Updated Platform\nSupport. ADDRESS is defined as follows in DbgHelp.h.\nC++\nRequirement Value\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nSTACKFRAME64\nRemarks\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define ADDRESS ADDRESS64\n#define LPADDRESS LPADDRESS64\n#else\ntypedef struct _tagADDRESS {\n DWORD Offset;\n WORD Segment;\n ADDRESS_MODE Mode;\n} ADDRESS, *LPADDRESS;\n#endif\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3333,"title":"API_VERSION structure (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["api","version","structure","dbghelp","majorversion","the","major","number","article02","2024","contains","library","minorversion","minor","revision","reserved","this","member","for","use","operating","system","requirement","value","header","redistributable","dll","later","syntax","typedef","struct","ushort","lpapi","members","requirements","expand","table","imagehlpapiversion","imagehlpapiversionex","see"],"errorCode":"","eventId":"","severity":"Low","summary":"C++\nMajorVersion\nThe major version number.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to API_VERSION structure (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"API_VERSION structure (dbghelp.h)\nArticle02/22/2024\nContains the library version.\nC++\nMajorVersion\nThe major version number.\nMinorVersion\nThe minor version number.\nRevision\nThe revision number.\nReserved\nThis member is reserved for use by the operating system.\nRequirement Value\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nSyntax\ntypedef struct API_VERSION {\n USHORT MajorVersion;\n USHORT MinorVersion;\n USHORT Revision;\n USHORT Reserved;\n} API_VERSION, *LPAPI_VERSION;\nMembers\nRequirements\nﾉ Expand table\nImagehlpApiVersion\nImagehlpApiVersionEx\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3334,"title":"FPO_DATA structure (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["fpo","data","structure","winnt","represents","the","stack","frame","layout","for","function","x86","computer","when","pointer","omission","optimization","used","article02","2024","locate","base","call","uloffstart","offset","first","byte","code","cbprocsize","number","bytes","cdwlocals","local","variables","cdwparams","size","parameters","dwords","cbprolog","syntax"],"errorCode":"","eventId":"","severity":"Low","summary":"Represents the stack frame layout for a function on an x86 computer when frame\npointer omission (FPO) optimization is used.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to FPO_DATA structure (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"FPO_DATA structure (winnt.h)\nArticle02/22/2024\nRepresents the stack frame layout for a function on an x86 computer when frame\npointer omission (FPO) optimization is used. The structure is used to locate the base of\nthe call frame.\nC++\nulOffStart\nThe offset of the first byte of the function code.\ncbProcSize\nThe number of bytes in the function.\ncdwLocals\nThe number of local variables.\ncdwParams\nThe size of the parameters, in DWORDs.\ncbProlog\nSyntax\ntypedef struct _FPO_DATA {\n DWORD ulOffStart;\n DWORD cbProcSize;\n DWORD cdwLocals;\n WORD cdwParams;\n WORD cbProlog : 8;\n WORD cbRegs : 3;\n WORD fHasSEH : 1;\n WORD fUseBP : 1;\n WORD reserved : 1;\n WORD cbFrame : 2;\n} FPO_DATA, *PFPO_DATA;\nMembers\nThe number of bytes in the function prolog code.\ncbRegs\nThe number of registers saved.\nfHasSEH\nA variable that indicates whether the function uses structured exception handling.\nfUseBP\nA variable that indicates whether the EBP register has been allocated.\nreserved\nReserved for future use.\ncbFrame\nA variable that indicates the frame type.\nType Meaning\nFRAME_FPO\n0\nFPO frame\nFRAME_NONFPO\n3\nNon-FPO frame\nFRAME_TRAP\n1\nTrap frame\nFRAME_TSS\n2\nTSS frame\nRequirement Value\nHeader winnt.h (include Windows.h)\nRedistributable DbgHelp.dll 5.1 or later\nﾉ Expand table\nRequirements\nﾉ Expand table\nFeedback\nWas this page helpful?\nFunctionTableAccessProc64\nSTACKFRAME64\nSymFunctionTableAccess64\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3335,"title":"IMAGE_DEBUG_INFORMATION structure (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["image","debug","information","structure","dbghelp","contains","debugging","article09","2022","note","this","used","the","mapdebuginformation","and","unmapdebuginformation","functions","which","are","provided","only","for","backward","compatibility","syntax","typedef","struct","list","entry","dword","reservedsize","pvoid","reservedmappedbase","ushort","reservedmachine","reservedcharacteristics","reservedchecksum","imagebase","sizeofimage","reservednumberofsections"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains debugging information.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to IMAGE_DEBUG_INFORMATION structure (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"IMAGE_DEBUG_INFORMATION structure\n(dbghelp.h)\nArticle09/01/2022\nContains debugging information.\n \nC++\nNote This structure is used by the MapDebugInformation and\nUnmapDebugInformation functions, which are provided only for backward\ncompatibility.\nSyntax\ntypedef struct _IMAGE_DEBUG_INFORMATION {\n LIST_ENTRY List;\n DWORD ReservedSize;\n PVOID ReservedMappedBase;\n USHORT ReservedMachine;\n USHORT ReservedCharacteristics;\n DWORD ReservedCheckSum;\n DWORD ImageBase;\n DWORD SizeOfImage;\n DWORD ReservedNumberOfSections;\n PIMAGE_SECTION_HEADER ReservedSections;\n DWORD ReservedExportedNamesSize;\n PSTR ReservedExportedNames;\n DWORD ReservedNumberOfFunctionTableEntries;\n PIMAGE_FUNCTION_ENTRY ReservedFunctionTableEntries;\n DWORD ReservedLowestFunctionStartingAddress;\n DWORD ReservedHighestFunctionEndingAddress;\n DWORD ReservedNumberOfFpoTableEntries;\n PFPO_DATA ReservedFpoTableEntries;\n DWORD SizeOfCoffSymbols;\n PIMAGE_COFF_SYMBOLS_HEADER CoffSymbols;\n DWORD ReservedSizeOfCodeViewSymbols;\n PVOID ReservedCodeViewSymbols;\n PSTR ImageFilePath;\n PSTR ImageFileName;\n PSTR ReservedDebugFilePath;\n DWORD ReservedTimeDateStamp;\n BOOL ReservedRomImage;\n PIMAGE_DEBUG_DIRECTORY ReservedDebugDirectory;\n DWORD ReservedNumberOfDebugDirectories;\n DWORD ReservedOriginalFunctionTableBaseAddress;\nList\nA linked list of LIST_ENTRY structures.\nReservedSize\nThe size of the memory allocated for the IMAGE_DEBUG_INFORMATION structure and\nall debugging information, in bytes.\nReservedMappedBase\nThe base address of the image.\nReservedMachine\nThe computer type. This member can be one of the following values.\nValue Meaning\nIMAGE_FILE_MACHINE_I386\n0x014c\nIntel (32-bit)\nIMAGE_FILE_MACHINE_IA64\n0x0200\nIntel Itanium\nIMAGE_FILE_MACHINE_AMD64\n0x8664\nx64 (AMD64 or EM64T)\nReservedCharacteristics\nThe characteristics of the image. This member can be one of the following values.\nValue Meaning\nIMAGE_FILE_RELOCS_STRIPPED\n0x0001\nRelocation information is stripped from the file.\n DWORD Reserved[2];\n} IMAGE_DEBUG_INFORMATION, *PIMAGE_DEBUG_INFORMATION;\nMembers\nﾉ Expand table\nﾉ Expand table\nIMAGE_FILE_EXECUTABLE_IMAGE\n0x0002\nThe file is executable (there are no unresolved\nexternal references).\nIMAGE_FILE_LINE_NUMS_STRIPPED\n0x0004\nLine numbers are stripped from the file.\nIMAGE_FILE_LOCAL_SYMS_STRIPPED\n0x0008\nLocal symbols are stripped from file.\nIMAGE_FILE_AGGRESIVE_WS_TRIM\n0x0010\nAggressively trim the working set.\nIMAGE_FILE_LARGE_ADDRESS_AWARE\n0x0020\nThe application can handle addresses larger than\n2 GB.\nIMAGE_FILE_BYTES_REVERSED_LO\n0x0080\nBytes of the word are reversed.\nIMAGE_FILE_32BIT_MACHINE\n0x0100\nComputer supports 32-bit words.\nIMAGE_FILE_DEBUG_STRIPPED\n0x0200\nDebugging information is stored separately in a\n.dbg file.\nIMAGE_FILE_REMOVABLE_RUN_FROM_SWAP\n0x0400\nIf the image is on removable media, copy and\nrun from the swap file.\nIMAGE_FILE_NET_RUN_FROM_SWAP\n0x0800\nIf the image is on the network, copy and run\nfrom the swap file.\nIMAGE_FILE_SYSTEM\n0x1000\nSystem file.\nIMAGE_FILE_DLL\n0x2000\nDLL file.\nIMAGE_FILE_UP_SYSTEM_ONLY\n0x4000\nFile should be run only on a uniprocessor\ncomputer.\nIMAGE_FILE_BYTES_REVERSED_HI\n0x8000\nBytes of the word are reversed.\nReservedCheckSum\nThe checksum of the image.\nImageBase\nThe requested base address of the image.\nSizeOfImage\nThe size of the image, in bytes.\nReservedNumberOfSections\nThe number of COFF section headers.\nReservedSections\nA pointer to the first COFF section header. For more information, see\nIMAGE_SECTION_HEADER.\nReservedExportedNamesSize\nThe size of the ExportedNames member, in bytes.\nReservedExportedNames\nA pointer to a series of null-terminated strings that name all the functions exported\nfrom the image.\nReservedNumberOfFunctionTableEntries\nThe number of entries contained in the FunctionTableEntries member.\nReservedFunctionTableEntries\nA pointer to the first function table entry. For more information, see\nIMAGE_FUNCTION_ENTRY.\nReservedLowestFunctionStartingAddress\nThe lowest function table starting address.\nReservedHighestFunctionEndingAddress\nThe highest function table ending address.\nReservedNumberOfFpoTableEntries\nThe number of entries contained in the FpoTableEntries member.\nReservedFpoTableEntries\nA pointer to the first FPO entry. For more information, see FPO_DATA.\nSizeOfCoffSymbols\nThe size of the COFF symbol table, in bytes.\nCoffSymbols\nA pointer to the COFF symbol table.\nReservedSizeOfCodeViewSymbols\nThe size of the CodeView symbol table, in bytes.\nReservedCodeViewSymbols\nA pointer to the beginning of the CodeView symbol table.\nImageFilePath\nThe relative path to the image file name.\nImageFileName\nThe image file name.\nReservedDebugFilePath\nThe full path to the symbol file.\nReservedTimeDateStamp\nThe timestamp of the image. This represents the date and time the image was created\nby the linker.\nReservedRomImage\nThis value is TRUE if the image is a ROM image.\nReservedDebugDirectory\nA pointer to the first debug directory. For more information, see\nIMAGE_DEBUG_DIRECTORY.\nReservedNumberOfDebugDirectories\nThe number of entries contained in the DebugDirectory member.\nReservedOriginalFunctionTableBaseAddress\nThe original function table base address.\nReserved[2]\nFeedback\nThis member is reserved for use by the operating system.\nThe LIST_ENTRY structure is defined as follows:\nC++\nRequirement Value\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nFPO_DATA\nIMAGE_COFF_SYMBOLS_HEADER\nIMAGE_DEBUG_DIRECTORY\nIMAGE_FUNCTION_ENTRY\nIMAGE_SECTION_HEADER\nMapDebugInformation\nUnmapDebugInformation\nRemarks\ntypedef struct _LIST_ENTRY {\n struct _LIST_ENTRY *Flink;\n struct _LIST_ENTRY *Blink;\n} LIST_ENTRY, *PLIST_ENTRY, *RESTRICTED_POINTER PRLIST_ENTRY;\nRequirements\nﾉ Expand table\nSee also\nWas this page helpful? Yes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3336,"title":"IMAGEHLP_CBA_EVENT structure (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["imagehlp","cba","event","structure","dbghelp","contains","information","about","debugging","article02","2024","severity","the","this","parameter","can","one","following","values","value","meaning","sevinfo","informational","sevproblem","reserved","for","future","use","sevattn","sevfatal","code","member","syntax","typedef","struct","dword","pchar","desc","pvoid","object"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains information about a debugging event.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to IMAGEHLP_CBA_EVENT structure (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"IMAGEHLP_CBA_EVENT structure\n(dbghelp.h)\nArticle02/22/2024\nContains information about a debugging event.\nC++\nseverity\nThe event severity. This parameter can be one of the following values.\nValue Meaning\nsevInfo\n0\nInformational event.\nsevProblem\n1\nReserved for future use.\nsevAttn\n2\nReserved for future use.\nsevFatal\n3\nReserved for future use.\ncode\nThis member is reserved for future use.\nSyntax\ntypedef struct _IMAGEHLP_CBA_EVENT {\n DWORD severity;\n DWORD code;\n PCHAR desc;\n PVOID object;\n} IMAGEHLP_CBA_EVENT, *PIMAGEHLP_CBA_EVENT;\nMembers\nﾉ Expand table\nFeedback\nWas this page helpful?\ndesc\nA text description of the error.\nobject\nThis member is reserved for future use.\nRequirement Value\nHeader dbghelp.h\nRedistributable DbgHelp.dll 6.1 or later\nSymRegisterCallbackProc64\nSymbolServerCallback\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3337,"title":"IMAGEHLP_CBA_READ_MEMORY structure (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["imagehlp","cba","read","memory","structure","dbghelp","contains","information","about","operation","article02","2024","addr","the","address","buf","pointer","buffer","that","receives","bytes","number","bytesread","variable","syntax","typedef","struct","dword64","pvoid","dword","pimagehlp","members","requirements","expand","table","feedback","was","this","page","helpful"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains information about a memory read operation.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to IMAGEHLP_CBA_READ_MEMORY structure (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"IMAGEHLP_CBA_READ_MEMORY\nstructure (dbghelp.h)\nArticle02/22/2024\nContains information about a memory read operation.\nC++\naddr\nThe address to be read.\nbuf\nA pointer to a buffer that receives the memory read.\nbytes\nThe number of bytes to read.\nbytesread\nA pointer to a variable that receives the number of bytes read.\nSyntax\ntypedef struct _IMAGEHLP_CBA_READ_MEMORY {\n DWORD64 addr;\n PVOID buf;\n DWORD bytes;\n DWORD *bytesread;\n} IMAGEHLP_CBA_READ_MEMORY, *PIMAGEHLP_CBA_READ_MEMORY;\nMembers\nRequirements\nﾉ Expand table\nFeedback\nWas this page helpful?\nRequirement Value\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nSymRegisterCallbackProc64\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3338,"title":"IMAGEHLP_DEFERRED_SYMBOL_LOAD structure (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["imagehlp","deferred","symbol","load","structure","dbghelp","contains","information","about","article02","2024","sizeofstruct","the","size","bytes","caller","must","set","this","member","sizeof","load64","baseofimage","base","virtual","address","where","image","loaded","checksum","computed","value","can","zero","timedatestamp","date","and","timestamp","represented","number"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains information about a deferred symbol load.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to IMAGEHLP_DEFERRED_SYMBOL_LOAD structure (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"IMAGEHLP_DEFERRED_SYMBOL_LOAD\nstructure (dbghelp.h)\nArticle02/22/2024\nContains information about a deferred symbol load.\nC++\nSizeOfStruct\nThe size of the structure, in bytes. The caller must set this member to\nsizeof(IMAGEHLP_DEFERRED_SYMBOL_LOAD64).\nBaseOfImage\nThe base virtual address where the image is loaded.\nCheckSum\nThe computed checksum of the image. This value can be zero.\nTimeDateStamp\nThe date and timestamp value. The value is represented in the number of seconds\nelapsed since midnight (00:00:00), January 1, 1970, Universal Coordinated Time,\naccording to the system clock. The timestamp can be printed using the C run-time (CRT)\nfunction ctime.\nSyntax\ntypedef struct _IMAGEHLP_DEFERRED_SYMBOL_LOAD {\n DWORD SizeOfStruct;\n DWORD BaseOfImage;\n DWORD CheckSum;\n DWORD TimeDateStamp;\n CHAR FileName[MAX_PATH];\n BOOLEAN Reparse;\n HANDLE hFile;\n} IMAGEHLP_DEFERRED_SYMBOL_LOAD, *PIMAGEHLP_DEFERRED_SYMBOL_LOAD;\nMembers\nFileName[MAX_PATH]\nThe image name. The name may or may not contain a full path.\nReparse\nIf this member is TRUE, the operation should be performed again. Otherwise, it should\nnot.\nhFile\nA handle to a file. This member is used with CBA_DEFERRED_SYMBOL_LOAD_PARTIAL\nand IMAGEHLP_DEFERRED_SYMBOL_LOAD_FAILURE callbacks.\nThis structure supersedes the IMAGEHLP_DEFERRED_SYMBOL_LOAD structure. For\nmore information, see Updated Platform Support.\nIMAGEHLP_DEFERRED_SYMBOL_LOAD is defined as follows in DbgHelp.h.\nC++\nRequirement Value\nHeader dbghelp.h\nRemarks\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define IMAGEHLP_DEFERRED_SYMBOL_LOAD IMAGEHLP_DEFERRED_SYMBOL_LOAD64\n#define PIMAGEHLP_DEFERRED_SYMBOL_LOAD PIMAGEHLP_DEFERRED_SYMBOL_LOAD64\n#else\ntypedef struct _IMAGEHLP_DEFERRED_SYMBOL_LOAD {\n DWORD SizeOfStruct; \n DWORD BaseOfImage; \n DWORD CheckSum; \n DWORD TimeDateStamp; \n CHAR FileName[MAX_PATH]; \n BOOLEAN Reparse; \n HANDLE hFile; \n} IMAGEHLP_DEFERRED_SYMBOL_LOAD, *PIMAGEHLP_DEFERRED_SYMBOL_LOAD;\n#endif\nRequirements\nﾉ Expand table\nFeedback\nWas this page helpful?\nRequirement Value\nRedistributable DbgHelp.dll 5.1 or later\nSymRegisterCallbackProc64\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3339,"title":"IMAGEHLP_DUPLICATE_SYMBOL structure (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["imagehlp","duplicate","symbol","structure","dbghelp","contains","information","article02","2024","sizeofstruct","the","size","bytes","caller","must","set","this","member","sizeof","symbol64","numberofdups","number","symbols","pointer","array","structures","entries","specified","selectedsymbol","index","into","for","selected","supersedes","more","see","updated","platform","support","defined"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains duplicate symbol information.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to IMAGEHLP_DUPLICATE_SYMBOL structure (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"IMAGEHLP_DUPLICATE_SYMBOL\nstructure (dbghelp.h)\nArticle02/22/2024\nContains duplicate symbol information.\nC++\nSizeOfStruct\nThe size of the structure, in bytes. The caller must set this member to\nsizeof(IMAGEHLP_DUPLICATE_SYMBOL64).\nNumberOfDups\nThe number of duplicate symbols.\nSymbol\nA pointer to an array of symbols ( IMAGEHLP_SYMBOL64 structures). The number of\nentries in the array is specified by the NumberOfDups member.\nSelectedSymbol\nThe index into the symbol array for the selected symbol.\nThis structure supersedes the IMAGEHLP_DUPLICATE_SYMBOL structure. For more\ninformation, see Updated Platform Support. IMAGEHLP_DUPLICATE_SYMBOL is defined\nSyntax\ntypedef struct _IMAGEHLP_DUPLICATE_SYMBOL {\n DWORD SizeOfStruct;\n DWORD NumberOfDups;\n PIMAGEHLP_SYMBOL Symbol;\n DWORD SelectedSymbol;\n} IMAGEHLP_DUPLICATE_SYMBOL, *PIMAGEHLP_DUPLICATE_SYMBOL;\nMembers\nRemarks\nFeedback\nWas this page helpful?\nas follows in DbgHelp.h.\nC++\nRequirement Value\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nIMAGEHLP_SYMBOL64\nSymRegisterCallbackProc64\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define IMAGEHLP_DUPLICATE_SYMBOL IMAGEHLP_DUPLICATE_SYMBOL64\n#define PIMAGEHLP_DUPLICATE_SYMBOL PIMAGEHLP_DUPLICATE_SYMBOL64\n#else\ntypedef struct _IMAGEHLP_DUPLICATE_SYMBOL {\n DWORD SizeOfStruct;\n DWORD NumberOfDups; \n PIMAGEHLP_SYMBOL Symbol; \n DWORD SelectedSymbol; \n} IMAGEHLP_DUPLICATE_SYMBOL, *PIMAGEHLP_DUPLICATE_SYMBOL;\n#endif\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3340,"title":"IMAGEHLP_GET_TYPE_INFO_PARAMS structure (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["imagehlp","get","type","info","params","structure","dbghelp","contains","information","for","module","article04","2021","sizeofstruct","the","size","this","bytes","flags","member","can","one","following","values","value","meaning","syntax","typedef","struct","ulong","numids","pulong","typeids","ulong64","tagfilter","numreqs","symbol","reqkinds","ptr","reqoffsets"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains type information for a module.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to IMAGEHLP_GET_TYPE_INFO_PARAMS structure (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"IMAGEHLP_GET_TYPE_INFO_PARAMS\nstructure (dbghelp.h)\nArticle04/02/2021\nContains type information for a module.\nC++\nSizeOfStruct\nThe size of this structure, in bytes.\nFlags\nThis member can be one of the following values.\nValue Meaning\nSyntax\ntypedef struct _IMAGEHLP_GET_TYPE_INFO_PARAMS {\n ULONG SizeOfStruct;\n ULONG Flags;\n ULONG NumIds;\n PULONG TypeIds;\n ULONG64 TagFilter;\n ULONG NumReqs;\n IMAGEHLP_SYMBOL_TYPE_INFO *ReqKinds;\n PULONG_PTR ReqOffsets;\n PULONG ReqSizes;\n ULONG_PTR ReqStride;\n ULONG_PTR BufferSize;\n PVOID Buffer;\n ULONG EntriesMatched;\n ULONG EntriesFilled;\n ULONG64 TagsFound;\n ULONG64 AllReqsValid;\n ULONG NumReqsValid;\n PULONG64 ReqsValid;\n} IMAGEHLP_GET_TYPE_INFO_PARAMS, *PIMAGEHLP_GET_TYPE_INFO_PARAMS;\nMembers\nﾉ Expand table\nIMAGEHLP_GET_TYPE_INFO_CHILDREN\n0x00000002\nRetrieve information about the children of the\nspecified types, not the types themselves.\nIMAGEHLP_GET_TYPE_INFO_UNCACHED\n0x00000001\nDo not cache the data for later retrievals. It is good to\nuse this flag if you will not be requesting the\ninformation again.\nNumIds\nThe number of elements specified in the TypeIds array.\nTypeIds\nAn array of type indexes.\nTagFilter\nThe filter for return values. For example, set this member to 1 << SymTagData to return\nonly results with a symbol tag of SymTagData. For a list of tags, see the SymTagEnum\ntype defined in Dbghelp.h\nNumReqs\nThe number of elements specified in the arrays specified in the ReqKinds, ReqOffsets,\nand ReqSizes members. These arrays must be the same size.\nReqKinds\nAn array of information types to be requested. Each element is one of the enumeration\nvalues in the IMAGEHLP_SYMBOL_TYPE_INFO enumeration type.\nReqOffsets\nAn array of offsets that specify where to store the data for each request within each\nelement of Buffer array.\nReqSizes\nThe size of each data request, in bytes. The required sizes are described in\nIMAGEHLP_SYMBOL_TYPE_INFO.\nReqStride\nThe number of bytes for each element in the Buffer array.\nBufferSize\nThe size of the Buffer array, in bytes.\nBuffer\nAn array of records used for storing query results. Each record is separated by ReqStride\nbytes. Each type for which data is to be retrieved requires one record in the array. Within\neach record, there are NumReqs pieces of data stored as the result of individual queries.\nThe data is stored within the record according to the offsets specified in ReqOffsets. The\nformat of the data depends on the value of the ReqKinds member in use.\nEntriesMatched\nThe number of type entries that match the filter.\nEntriesFilled\nThe number of elements in the Buffer array that received results.\nTagsFound\nA bitmask indicating all tag bits encountered during the search operation.\nAllReqsValid\nA bitmask indicate the bit-wise AND of all ReqsValid fields.\nNumReqsValid\nThe size of ReqsValid, in elements.\nReqsValid\nA bitmask indexed by Buffer element index that indicates which request data is valid.\nThis member can be NULL.\nRequirement Value\nHeader dbghelp.h\nRedistributable DbgHelp.dll 6.3 or later\nRequirements\nﾉ Expand table\nFeedback\nWas this page helpful?\nIMAGEHLP_SYMBOL_TYPE_INFO\nSymGetTypeInfoEx\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3341,"title":"IMAGEHLP_LINE structure (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["imagehlp","line","structure","dbghelp","sizeofstruct","the","size","bytes","article02","2024","represents","source","file","caller","must","set","this","member","sizeof","line64","key","reserved","for","use","operating","system","linenumber","number","filename","name","including","full","path","address","first","instruction","syntax","typedef","struct","dword"],"errorCode":"","eventId":"","severity":"Low","summary":"C++\nSizeOfStruct\nThe size of the structure, in bytes.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to IMAGEHLP_LINE structure (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"IMAGEHLP_LINE structure (dbghelp.h)\nArticle02/22/2024\nRepresents a source file line.\nC++\nSizeOfStruct\nThe size of the structure, in bytes. The caller must set this member to\nsizeof(IMAGEHLP_LINE64).\nKey\nThis member is reserved for use by the operating system.\nLineNumber\nThe line number in the file.\nFileName\nThe name of the file, including the full path.\nAddress\nThe address of the first instruction in the line.\nSyntax\ntypedef struct _IMAGEHLP_LINE {\n DWORD SizeOfStruct;\n PVOID Key;\n DWORD LineNumber;\n PCHAR FileName;\n DWORD Address;\n} IMAGEHLP_LINE, *PIMAGEHLP_LINE;\nMembers\nRemarks\nThis structure supersedes the IMAGEHLP_LINE structure. For more information, see\nUpdated Platform Support. IMAGEHLP_LINE is defined as follows in DbgHelp.h.\nC++\nRequirement Value\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nSymGetLineFromAddr64\nSymGetLineFromName64\nSymGetLineNext64\nSymGetLinePrev64\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define IMAGEHLP_LINE IMAGEHLP_LINE64\n#define PIMAGEHLP_LINE PIMAGEHLP_LINE64\n#else\ntypedef struct _IMAGEHLP_LINE {\n DWORD SizeOfStruct; \n PVOID Key; \n DWORD LineNumber; \n PCHAR FileName; \n DWORD Address; \n} IMAGEHLP_LINE, *PIMAGEHLP_LINE;\ntypedef struct _IMAGEHLP_LINEW {\n DWORD SizeOfStruct; \n PVOID Key; \n DWORD LineNumber; \n PCHAR FileName; \n DWORD64 Address; \n} IMAGEHLP_LINEW, *PIMAGEHLP_LINEW;\n#endif\nRequirements\nﾉ Expand table\nSee also\nFeedback\nWas this page helpful? Yes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3342,"title":"IMAGEHLP_MODULE structure (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["imagehlp","module","structure","dbghelp","sizeofstruct","the","size","bytes","article02","2024","contains","information","caller","must","set","this","member","sizeof","module64","baseofimage","base","virtual","address","where","image","loaded","imagesize","timedatestamp","date","and","timestamp","value","represented","number","seconds","elapsed","since","midnight","january","1970"],"errorCode":"","eventId":"","severity":"Low","summary":"C++\nSizeOfStruct\nThe size of the structure, in bytes.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to IMAGEHLP_MODULE structure (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"IMAGEHLP_MODULE structure\n(dbghelp.h)\nArticle02/22/2024\nContains module information.\nC++\nSizeOfStruct\nThe size of the structure, in bytes. The caller must set this member to\nsizeof(IMAGEHLP_MODULE64).\nBaseOfImage\nThe base virtual address where the image is loaded.\nImageSize\nThe size of the image, in bytes.\nTimeDateStamp\nThe date and timestamp value. The value is represented in the number of seconds\nelapsed since midnight (00:00:00), January 1, 1970, Universal Coordinated Time,\nSyntax\ntypedef struct _IMAGEHLP_MODULE {\n DWORD SizeOfStruct;\n DWORD BaseOfImage;\n DWORD ImageSize;\n DWORD TimeDateStamp;\n DWORD CheckSum;\n DWORD NumSyms;\n SYM_TYPE SymType;\n CHAR ModuleName[32];\n CHAR ImageName[256];\n CHAR LoadedImageName[256];\n} IMAGEHLP_MODULE, *PIMAGEHLP_MODULE;\nMembers\naccording to the system clock. The timestamp can be printed using the C run-time (CRT)\nfunction ctime.\nCheckSum\nThe checksum of the image. This value can be zero.\nNumSyms\nThe number of symbols in the symbol table. The value of this parameter is not\nmeaningful when SymPdb is specified as the value of the SymType parameter.\nSymType\nThe type of symbols that are loaded. This member can be one of the following values.\nValue Meaning\nSymCoff COFF symbols.\nSymCv CodeView symbols.\nSymDeferred Symbol loading deferred.\nSymDia DIA symbols.\nSymExport Symbols generated from a DLL export table.\nSymNone No symbols are loaded.\nSymPdb PDB symbols.\nSymSym .sym file.\nSymVirtual The virtual module created by SymLoadModuleEx with\nSLMFLAG_VIRTUAL.\nModuleName[32]\nThe module name.\nImageName[256]\nThe image name. The name may or may not contain a full path.\nLoadedImageName[256]\nﾉ Expand table\nThe full path and file name of the file from which symbols were loaded.\nThis structure supersedes the IMAGEHLP_MODULE structure. For more information, see\nUpdated Platform Support. IMAGEHLP_MODULE is defined as follows in DbgHelp.h.\nC++\nRemarks\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define IMAGEHLP_MODULE IMAGEHLP_MODULE64\n#define PIMAGEHLP_MODULE PIMAGEHLP_MODULE64\n#define IMAGEHLP_MODULEW IMAGEHLP_MODULEW64\n#define PIMAGEHLP_MODULEW PIMAGEHLP_MODULEW64\n#else\ntypedef struct _IMAGEHLP_MODULE {\n DWORD SizeOfStruct;\n DWORD BaseOfImage; \n DWORD ImageSize; \n DWORD TimeDateStamp; \n DWORD CheckSum; \n DWORD NumSyms; \n SYM_TYPE SymType; \n CHAR ModuleName[32]; \n CHAR ImageName[256]; \n CHAR LoadedImageName[256]; \n} IMAGEHLP_MODULE, *PIMAGEHLP_MODULE;\ntypedef struct _IMAGEHLP_MODULEW {\n DWORD SizeOfStruct; \n DWORD BaseOfImage; \n DWORD ImageSize; \n DWORD TimeDateStamp; \n DWORD CheckSum; \n DWORD NumSyms; \n SYM_TYPE SymType; \n WCHAR ModuleName[32]; \n WCHAR ImageName[256]; \n WCHAR LoadedImageName[256]; \n} IMAGEHLP_MODULEW, *PIMAGEHLP_MODULEW;\n#endif\nRequirements\nﾉ Expand table\nFeedback\nWas this page helpful?\nRequirement Value\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nSymGetModuleInfo64\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3343,"title":"IMAGEHLP_STACK_FRAME structure (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["imagehlp","stack","frame","structure","dbghelp","contains","the","information","article02","2024","this","used","with","symsetcontext","function","instructionoffset","program","counter","x86","eip","intel","itanium","combination","bundle","address","and","slot","indicator","for","within","x64","rip","returnoffset","return","frameoffset","syntax","typedef","struct","ulong64","stackoffset"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains the stack frame information.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to IMAGEHLP_STACK_FRAME structure (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"IMAGEHLP_STACK_FRAME structure\n(dbghelp.h)\nArticle02/22/2024\nContains the stack frame information. This structure is used with the SymSetContext\nfunction.\nC++\nInstructionOffset\nThe program counter.\nx86: The program counter is EIP.\nIntel Itanium: The program counter is a combination of the bundle address and a slot\nindicator of 0, 4, or 8 for the slot within the bundle.\nx64: The program counter is RIP.\nReturnOffset\nThe return address.\nFrameOffset\nSyntax\ntypedef struct _IMAGEHLP_STACK_FRAME {\n ULONG64 InstructionOffset;\n ULONG64 ReturnOffset;\n ULONG64 FrameOffset;\n ULONG64 StackOffset;\n ULONG64 BackingStoreOffset;\n ULONG64 FuncTableEntry;\n ULONG64 Params[4];\n ULONG64 Reserved[5];\n BOOL Virtual;\n ULONG Reserved2;\n} IMAGEHLP_STACK_FRAME, *PIMAGEHLP_STACK_FRAME;\nMembers\nThe frame pointer.\nx86: The frame pointer is EBP.\nIntel Itanium: There is no frame pointer, but AddrBStore is used.\nx64: The frame pointer is RBP. AMD-64 does not always use this value.\nStackOffset\nThe stack pointer.\nx86: The stack pointer is ESP.\nIntel Itanium: The stack pointer is SP.\nx64: The stack pointer is RSP.\nBackingStoreOffset\nIntel Itanium: The backing store address.\nFuncTableEntry\nx86: An FPO_DATA structure. If there is no function table entry, this member is NULL.\nParams[4]\nThe possible arguments to the function.\nReserved[5]\nThis member is reserved for system use.\nVirtual\nIf this is a virtual frame, this member is TRUE. Otherwise, this member is FALSE.\nReserved2\nThis member is reserved for system use.\nRequirements\nﾉ Expand table\nFeedback\nWas this page helpful?\nRequirement Value\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nSymSetContext\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3344,"title":"IMAGEHLP_SYMBOL structure (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["imagehlp","symbol","structure","dbghelp","sizeofstruct","the","size","bytes","article02","2024","contains","information","caller","must","set","this","member","sizeof","symbol64","address","virtual","for","value","best","guess","and","can","zero","flags","reserved","use","operating","system","maxnamelength","maximum","length","string","that","name","contain"],"errorCode":"","eventId":"","severity":"Low","summary":"C++\nSizeOfStruct\nThe size of the structure, in bytes.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to IMAGEHLP_SYMBOL structure (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"IMAGEHLP_SYMBOL structure\n(dbghelp.h)\nArticle02/22/2024\nContains symbol information.\nC++\nSizeOfStruct\nThe size of the structure, in bytes. The caller must set this member to\nsizeof(IMAGEHLP_SYMBOL64).\nAddress\nThe virtual address for the symbol.\nSize\nThe size of the symbol, in bytes. This value is a best guess and can be zero.\nFlags\nThis member is reserved for use by the operating system.\nMaxNameLength\nThe maximum length of the string that the Name member can contain, in characters,\nnot including the null-terminating character. Because symbol names can vary in length,\nSyntax\ntypedef struct _IMAGEHLP_SYMBOL {\n DWORD SizeOfStruct;\n DWORD Address;\n DWORD Size;\n DWORD Flags;\n DWORD MaxNameLength;\n CHAR Name[1];\n} IMAGEHLP_SYMBOL, *PIMAGEHLP_SYMBOL;\nMembers\nthis data structure is allocated by the caller. This member is used so the library knows\nhow much memory is available for use by the symbol name.\nName[1]\nThe decorated or undecorated symbol name. If the buffer is not large enough for the\ncomplete name, it is truncated to MaxNameLength characters, including the nullterminating character.\nThis structure supersedes the IMAGEHLP_SYMBOL structure. For more information, see\nUpdated Platform Support. IMAGEHLP_SYMBOL is defined as follows in DbgHelp.h.\nC++\nRequirement Value\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nSymGetSymFromAddr64\nRemarks\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n #define IMAGEHLP_SYMBOL IMAGEHLP_SYMBOL64\n #define PIMAGEHLP_SYMBOL PIMAGEHLP_SYMBOL64\n#else\n typedef struct _IMAGEHLP_SYMBOL {\n DWORD SizeOfStruct; \n DWORD Address; \n DWORD Size; \n DWORD Flags; \n DWORD MaxNameLength; \n CHAR Name[1]; \n } IMAGEHLP_SYMBOL, *PIMAGEHLP_SYMBOL;\n#endif\nRequirements\nﾉ Expand table\nSee also\nFeedback\nWas this page helpful?\nSymGetSymFromName64\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3345,"title":"KDHELP structure (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["kdhelp","structure","dbghelp","information","that","used","kernel","debuggers","trace","through","user","mode","callbacks","thread","stack","article02","2024","the","address","object","provided","wait","state","change","packet","thcallbackstack","offset","pointer","current","callback","frame","nextcallback","next","framepointer","saved","applicable","syntax","typedef","struct","dword"],"errorCode":"","eventId":"","severity":"Low","summary":"Information that is used by kernel debuggers to trace through user-mode callbacks in a\nthread's kernel stack.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to KDHELP structure (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"KDHELP structure (dbghelp.h)\nArticle02/22/2024\nInformation that is used by kernel debuggers to trace through user-mode callbacks in a\nthread's kernel stack.\nC++\nThread\nThe address of the kernel thread object, as provided in the WAIT_STATE_CHANGE\npacket.\nThCallbackStack\nThe offset in the thread object to the pointer to the current callback frame in the kernel\nstack.\nNextCallback\nThe address of the next callback frame.\nFramePointer\nThe address of the saved frame pointer, if applicable.\nSyntax\ntypedef struct _KDHELP {\n DWORD Thread;\n DWORD ThCallbackStack;\n DWORD NextCallback;\n DWORD FramePointer;\n DWORD KiCallUserMode;\n DWORD KeUserCallbackDispatcher;\n DWORD SystemRangeStart;\n DWORD ThCallbackBStore;\n DWORD KiUserExceptionDispatcher;\n DWORD StackBase;\n DWORD StackLimit;\n DWORD Reserved[5];\n} KDHELP, *PKDHELP;\nMembers\nKiCallUserMode\nThe address of the kernel function that calls out to user mode.\nKeUserCallbackDispatcher\nThe address of the user-mode dispatcher function.\nSystemRangeStart\nThe lowest kernel-mode address.\nThCallbackBStore\nIntel Itanium: The offset in the thread object to a pointer to the current callback\nbacking store frame in the kernel stack.\nKiUserExceptionDispatcher\nThe address of the user-mode exception dispatcher function.\nDbgHelp 6.1 and earlier: This member is not supported.\nStackBase\nThe address of the stack base.\nStackLimit\nThe stack limit.\nReserved[5]\nThis member is reserved for use by the operating system.\nThis structure supersedes the KDHELP structure. For more information, see Updated\nPlatform Support. KDHELP is defined as follows in Dbghelp.h.\nC++\nRemarks\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define KDHELP KDHELP64\n#define PKDHELP PKDHELP64\n#else\ntypedef struct _KDHELP {\n DWORD Thread;\nFeedback\nWas this page helpful?\nRequirement Value\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nSTACKFRAME64\n DWORD ThCallbackStack;\n DWORD NextCallback;\n DWORD FramePointer;\n DWORD KiCallUserMode;\n DWORD KeUserCallbackDispatcher;\n DWORD SystemRangeStart;\n DWORD ThCallbackBStore;\n DWORD KiUserExceptionDispatcher;\n DWORD StackBase;\n DWORD StackLimit;\n DWORD Reserved[5];\n} KDHELP, *PKDHELP;\n#endif\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3346,"title":"LOADED_IMAGE structure (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["loaded","image","structure","dbghelp","contains","information","about","the","article04","2021","modulename","file","name","mapped","hfile","handle","mappedaddress","base","address","fileheader","syntax","typedef","struct","pstr","puchar","pimage","headers64","else","headers32","endif","section","header","lastrvasection","ulong","numberofsections","sections","characteristics","boolean","fsystemimage","fdosimage"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains information about the loaded image.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to LOADED_IMAGE structure (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"LOADED_IMAGE structure (dbghelp.h)\nArticle04/02/2021\nContains information about the loaded image.\nC++\nModuleName\nThe file name of the mapped file.\nhFile\nA handle to the mapped file.\nMappedAddress\nThe base address of the mapped file.\nFileHeader\nSyntax\ntypedef struct _LOADED_IMAGE {\n PSTR ModuleName;\n HANDLE hFile;\n PUCHAR MappedAddress;\n#if ...\n PIMAGE_NT_HEADERS64 FileHeader;\n#else\n PIMAGE_NT_HEADERS32 FileHeader;\n#endif\n PIMAGE_SECTION_HEADER LastRvaSection;\n ULONG NumberOfSections;\n PIMAGE_SECTION_HEADER Sections;\n ULONG Characteristics;\n BOOLEAN fSystemImage;\n BOOLEAN fDOSImage;\n BOOLEAN fReadOnly;\n UCHAR Version;\n LIST_ENTRY Links;\n ULONG SizeOfImage;\n} LOADED_IMAGE, *PLOADED_IMAGE;\nMembers\nA pointer to an IMAGE_NT_HEADERS structure.\nLastRvaSection\nA pointer to an IMAGE_SECTION_HEADER structure.\nNumberOfSections\nThe number of COFF section headers.\nSections\nA pointer to an IMAGE_SECTION_HEADER structure.\nCharacteristics\nThe image characteristics value. This member can be one of the following values.\nValue Meaning\nIMAGE_FILE_RELOCS_STRIPPED\n0x0001\nRelocation information is stripped from the file.\nIMAGE_FILE_EXECUTABLE_IMAGE\n0x0002\nThe file is executable (there are no unresolved\nexternal references).\nIMAGE_FILE_LINE_NUMS_STRIPPED\n0x0004\nLine numbers are stripped from the file.\nIMAGE_FILE_LOCAL_SYMS_STRIPPED\n0x0008\nLocal symbols are stripped from file.\nIMAGE_FILE_AGGRESIVE_WS_TRIM\n0x0010\nAggressively trim the working set.\nIMAGE_FILE_LARGE_ADDRESS_AWARE\n0x0020\nThe application can handle addresses larger than\n2 GB.\nIMAGE_FILE_BYTES_REVERSED_LO\n0x0080\nBytes of word are reversed.\nIMAGE_FILE_32BIT_MACHINE\n0x0100\nComputer supports 32-bit words.\nIMAGE_FILE_DEBUG_STRIPPED\n0x0200\nDebugging information is stored separately in a\n.dbg file.\nﾉ Expand table\nIMAGE_FILE_REMOVABLE_RUN_FROM_SWAP\n0x0400\nIf the image is on removable media, copy and\nrun from the swap file.\nIMAGE_FILE_NET_RUN_FROM_SWAP\n0x0800\nIf the image is on the network, copy and run\nfrom the swap file.\nIMAGE_FILE_SYSTEM\n0x1000\nSystem file.\nIMAGE_FILE_DLL\n0x2000\nDLL file.\nIMAGE_FILE_UP_SYSTEM_ONLY\n0x4000\nFile should be run only on a uniprocessor\ncomputer.\nIMAGE_FILE_BYTES_REVERSED_HI\n0x8000\nBytes of the word are reversed.\nfSystemImage\nIf the image is a kernel mode executable image, this value is TRUE.\nfDOSImage\nIf the image is a 16-bit executable image, this value is TRUE.\nfReadOnly\nIf the image is read-only, this value is TRUE.\nPrior to Windows Vista: This member is not included in the structure.\nVersion\nThe version string.\nPrior to Windows Vista: This member is not included in the structure.\nLinks\nThe list of loaded images.\nSizeOfImage\nThe size of the image, in bytes.\nRemarks\nFeedback\nWas this page helpful?\nThe LIST_ENTRY structure is defined as follows:\nC++\nRequirement Value\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nIMAGE_NT_HEADERS\nIMAGE_SECTION_HEADER\nImageLoad\nMapAndLoad\ntypedef struct _LIST_ENTRY {\n struct _LIST_ENTRY *Flink;\n struct _LIST_ENTRY *Blink;\n} LIST_ENTRY, *PLIST_ENTRY, *RESTRICTED_POINTER PRLIST_ENTRY;\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3347,"title":"MINIDUMP_CALLBACK_INFORMATION structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","callback","information","structure","minidumpapiset","contains","pointer","optional","function","that","can","used","the","minidumpwritedump","article02","2024","callbackroutine","minidumpcallback","callbackparam","application","defined","data","for","requirement","value","header","include","dbghelp","redistributable","dll","later","syntax","typedef","struct","routine","pvoid","pminidump","members","requirements","expand"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains a pointer to an optional callback function that can be used by the\nMiniDumpWriteDump function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_CALLBACK_INFORMATION structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_CALLBACK_INFORMATION\nstructure (minidumpapiset.h)\nArticle02/22/2024\nContains a pointer to an optional callback function that can be used by the\nMiniDumpWriteDump function.\nC++\nCallbackRoutine\nA pointer to the MiniDumpCallback callback function.\nCallbackParam\nThe application-defined data for CallbackRoutine.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nMiniDumpCallback\nSyntax\ntypedef struct _MINIDUMP_CALLBACK_INFORMATION {\n MINIDUMP_CALLBACK_ROUTINE CallbackRoutine;\n PVOID CallbackParam;\n} MINIDUMP_CALLBACK_INFORMATION, *PMINIDUMP_CALLBACK_INFORMATION;\nMembers\nRequirements\nﾉ Expand table\nSee also\nFeedback\nWas this page helpful?\nMiniDumpWriteDump\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3348,"title":"MINIDUMP_CALLBACK_INPUT structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","callback","input","structure","minidumpapiset","contains","information","used","the","minidumpcallback","function","article02","2024","processid","identifier","process","that","this","member","not","callbacktype","iostartcallback","processhandle","handle","syntax","typedef","struct","ulong","union","hresult","status","thread","threadex","module","include","includethread","includemodule","read","memory","failure"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains information used by the MiniDumpCallback function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_CALLBACK_INPUT structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_CALLBACK_INPUT structure\n(minidumpapiset.h)\nArticle02/22/2024\nContains information used by the MiniDumpCallback function.\nC++\nProcessId\nThe identifier of the process that contains callback function.\nThis member is not used if CallbackType is IoStartCallback.\nProcessHandle\nA handle to the process that contains the callback function.\nThis member is not used if CallbackType is IoStartCallback.\nSyntax\ntypedef struct _MINIDUMP_CALLBACK_INPUT {\n ULONG ProcessId;\n HANDLE ProcessHandle;\n ULONG CallbackType;\n union {\n HRESULT Status;\n MINIDUMP_THREAD_CALLBACK Thread;\n MINIDUMP_THREAD_EX_CALLBACK ThreadEx;\n MINIDUMP_MODULE_CALLBACK Module;\n MINIDUMP_INCLUDE_THREAD_CALLBACK IncludeThread;\n MINIDUMP_INCLUDE_MODULE_CALLBACK IncludeModule;\n MINIDUMP_IO_CALLBACK Io;\n MINIDUMP_READ_MEMORY_FAILURE_CALLBACK ReadMemoryFailure;\n ULONG SecondaryFlags;\n MINIDUMP_VM_QUERY_CALLBACK VmQuery;\n MINIDUMP_VM_PRE_READ_CALLBACK VmPreRead;\n MINIDUMP_VM_POST_READ_CALLBACK VmPostRead;\n };\n} MINIDUMP_CALLBACK_INPUT, *PMINIDUMP_CALLBACK_INPUT;\nMembers\nCallbackType\nThe type of callback function. This member can be one of the values in the\nMINIDUMP_CALLBACK_TYPE enumeration.\nStatus\nIf CallbackType is KernelMinidumpStatusCallback, the union is an HRESULT value that\nindicates the status of the kernel minidump write attempt.\nThread\nIf CallbackType is ThreadCallback, the union is a MINIDUMP_THREAD_CALLBACK\nstructure.\nThreadEx\nIf CallbackType is ThreadExCallback, the union is a MINIDUMP_THREAD_EX_CALLBACK\nstructure.\nModule\nIf CallbackType is ModuleCallback, the union is a MINIDUMP_MODULE_CALLBACK\nstructure.\nIncludeThread\nIf CallbackType is IncludeThreadCallback, the union is a\nMINIDUMP_INCLUDE_THREAD_CALLBACK structure.\nDbgHelp 6.2 and earlier: This member is not available.\nIncludeModule\nIf CallbackType is IncludeModuleCallback, the union is a\nMINIDUMP_INCLUDE_MODULE_CALLBACK structure.\nDbgHelp 6.2 and earlier: This member is not available.\nIo\nIf CallbackType is IoStartCallback, IoWriteAllCallback, or IoFinishCallback, the union is\na MINIDUMP_IO_CALLBACK structure.\nDbgHelp 6.4 and earlier: This member is not available.\nReadMemoryFailure\nIf CallbackType is ReadMemoryFailureCallback, the union is a\nMINIDUMP_READ_MEMORY_FAILURE_CALLBACK structure.\nDbgHelp 6.4 and earlier: This member is not available.\nSecondaryFlags\nContains a value from the MINIDUMP_SECONDARY_FLAGS enumeration type.\nDbgHelp 6.5 and earlier: This member is not available.\nVmQuery\nVmPreRead\nVmPostRead\nIf CallbackType is CancelCallback or MemoryCallback, the ProcessId, ProcessHandle,\nand CallbackType members are valid but no other input is specified.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_CALLBACK_TYPE\nMINIDUMP_INCLUDE_MODULE_CALLBACK\nMINIDUMP_INCLUDE_THREAD_CALLBACK\nMINIDUMP_IO_CALLBACK\nMINIDUMP_MODULE_CALLBACK\nRemarks\nRequirements\nﾉ Expand table\nSee also\nFeedback\nWas this page helpful?\nMINIDUMP_READ_MEMORY_FAILURE_CALLBACK\nMINIDUMP_THREAD_CALLBACK\nMINIDUMP_THREAD_EX_CALLBACK\nMiniDumpCallback\nYes No\nMINIDUMP_CALLBACK_OUTPUT structure\n(minidumpapiset.h)\nContains information returned by the MiniDumpCallback function.\nC++\nModuleWriteFlags\nSyntax\ntypedef struct _MINIDUMP_CALLBACK_OUTPUT {\n union {\n ULONG ModuleWriteFlags;\n ULONG ThreadWriteFlags;\n ULONG SecondaryFlags;\n struct {\n ULONG64 MemoryBase;\n ULONG MemorySize;\n };\n struct {\n BOOL CheckCancel;\n BOOL Cancel;\n };\n HANDLE Handle;\n struct {\n MINIDUMP_MEMORY_INFO VmRegion;\n BOOL Continue;\n };\n struct {\n HRESULT VmQueryStatus;\n MINIDUMP_MEMORY_INFO VmQueryResult;\n };\n struct {\n HRESULT VmReadStatus;\n ULONG VmReadBytesCompleted;\n };\n MINIDUMP_COMPRESSED_MEMORY_STREAM_START_CALLBACK CompressedMemoryStreamStart;\n HRESULT Status;\n };\n} MINIDUMP_CALLBACK_OUTPUT, *PMINIDUMP_CALLBACK_OUTPUT;\nMembers\nThe module write operation flags. This member can be one or more of the values in the\nMODULE_WRITE_FLAGS enumeration. The flags are set to their default values on entry to the\ncallback.\nThis member is ignored unless the callback type is IncludeModuleCallback or ModuleCallback.\nThreadWriteFlags\nThe thread write operation flags. This member can be one or more of the values in the\nTHREAD_WRITE_FLAGS enumeration. The flags are set to their default values on entry to the\ncallback.\nThis member is ignored unless the callback type is IncludeThreadCallback, ThreadCallback, or\nThreadExCallback.\nSecondaryFlags\nContains a value from the MINIDUMP_SECONDARY_FLAGS enumeration type.\nDbgHelp 6.5 and earlier: This member is not available.\nMemoryBase\nThe base address of the memory region to be included in the dump.\nThis member is ignored unless the callback type is MemoryCallback or RemoveMemoryCallback.\nMemorySize\nThe size of the memory region to be included in the dump, in bytes.\nThis member is ignored unless the callback type is MemoryCallback or RemoveMemoryCallback.\nCheckCancel\nControls whether the callback function should receive cancel callbacks. If this member is TRUE,\nthe cancel callbacks will continue. Otherwise, they will not.\nThis member is ignored unless the callback type is CancelCallback.\nCancel\nControls whether the dump should be canceled. If the callback function returns TRUE and Cancel\nis TRUE, the dump will be canceled. In this case, the MiniDumpWriteDump function fails and the\ndump is not valid.\nThis member is ignored unless the callback type is CancelCallback.\nHandle\nA handle to the file to which a kernel minidump will be written.\nThis member is ignored unless the callback type is WriteKernelMinidumpCallback.\nVmRegion\nA MINIDUMP_MEMORY_INFO structure that describes the virtual memory region. The region\nbase and size must be aligned on a page boundary. The region size can be set to 0 to filter out\nthe region.\nThis member is ignored unless the callback type is IncludeVmRegionCallback.\nContinue\nControls whether the dump should be continued. If the callback function returns TRUE and\nContinue is TRUE, the dump will be continued. Otherwise, the MiniDumpW","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3349,"title":"MINIDUMP_DIRECTORY structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","directory","structure","minidumpapiset","contains","the","information","needed","access","specific","data","stream","file","article02","2024","streamtype","type","this","member","can","one","values","enumeration","location","descriptor","that","specifies","context","block","within","requirement","value","header","include","dbghelp","syntax","typedef","struct","ulong32","pminidump"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains the information needed to access a specific data stream in a minidump file.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_DIRECTORY structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_DIRECTORY structure\n(minidumpapiset.h)\nArticle02/22/2024\nContains the information needed to access a specific data stream in a minidump file.\nC++\nStreamType\nThe type of data stream. This member can be one of the values in the\nMINIDUMP_STREAM_TYPE enumeration.\nLocation\nA MINIDUMP_LOCATION_DESCRIPTOR structure that specifies the location of the data\nstream.\nIn this context, a data stream is a block of data within a minidump file.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nSyntax\ntypedef struct _MINIDUMP_DIRECTORY {\n ULONG32 StreamType;\n MINIDUMP_LOCATION_DESCRIPTOR Location;\n} MINIDUMP_DIRECTORY, *PMINIDUMP_DIRECTORY;\nMembers\nRemarks\nRequirements\nﾉ Expand table\nFeedback\nWas this page helpful?\nRequirement Value\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_LOCATION_DESCRIPTOR\nMINIDUMP_STREAM_TYPE\nMiniDumpReadDumpStream\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3350,"title":"MINIDUMP_EXCEPTION structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","exception","structure","minidumpapiset","contains","information","article09","2022","exceptioncode","the","reason","occurred","this","code","generated","hardware","specified","raiseexception","function","for","software","following","are","codes","likely","occur","due","common","programming","errors","value","meaning","access","violation","thread","tried","read","from","write","virtual"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains exception information.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_EXCEPTION structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_EXCEPTION structure\n(minidumpapiset.h)\nArticle09/01/2022\nContains exception information.\nC++\nExceptionCode\nThe reason the exception occurred. This is the code generated by a hardware exception,\nor the code specified in the RaiseException function for a software-generated exception.\nFollowing are the exception codes likely to occur due to common programming errors.\nValue Meaning\nEXCEPTION_ACCESS_VIOLATION The thread tried to read from or write to a virtual\naddress for which it does not have the\nappropriate access.\nEXCEPTION_ARRAY_BOUNDS_EXCEEDED The thread tried to access an array element that\nis out of bounds and the underlying hardware\nsupports bounds checking.\nEXCEPTION_BREAKPOINT A breakpoint was encountered.\nSyntax\ntypedef struct _MINIDUMP_EXCEPTION {\n ULONG32 ExceptionCode;\n ULONG32 ExceptionFlags;\n ULONG64 ExceptionRecord;\n ULONG64 ExceptionAddress;\n ULONG32 NumberParameters;\n ULONG32 __unusedAlignment;\n ULONG64 ExceptionInformation[EXCEPTION_MAXIMUM_PARAMETERS];\n} MINIDUMP_EXCEPTION, *PMINIDUMP_EXCEPTION;\nMembers\nﾉ Expand table\nEXCEPTION_DATATYPE_MISALIGNMENTThe thread tried to read or write data that is\nmisaligned on hardware that does not provide\nalignment. For example, 16-bit values must be\naligned on 2-byte boundaries; 32-bit values on 4byte boundaries, and so on.\nEXCEPTION_FLT_DENORMAL_OPERANDOne of the operands in a floating-point\noperation is denormal. A denormal value is one\nthat is too small to represent as a standard\nfloating-point value.\nEXCEPTION_FLT_DIVIDE_BY_ZERO The thread tried to divide a floating-point value\nby a floating-point divisor of zero.\nEXCEPTION_FLT_INEXACT_RESULT The result of a floating-point operation cannot\nbe represented exactly as a decimal fraction.\nEXCEPTION_FLT_INVALID_OPERATION This exception represents any floating-point\nexception not included in this list.\nEXCEPTION_FLT_OVERFLOW The exponent of a floating-point operation is\ngreater than the magnitude allowed by the\ncorresponding type.\nEXCEPTION_FLT_STACK_CHECK The stack overflowed or underflowed as the\nresult of a floating-point operation.\nEXCEPTION_FLT_UNDERFLOW The exponent of a floating-point operation is less\nthan the magnitude allowed by the\ncorresponding type.\nEXCEPTION_ILLEGAL_INSTRUCTION The thread tried to execute an invalid instruction.\nEXCEPTION_IN_PAGE_ERROR The thread tried to access a page that was not\npresent, and the system was unable to load the\npage. For example, this exception might occur if\na network connection is lost while running a\nprogram over the network.\nEXCEPTION_INT_DIVIDE_BY_ZERO The thread tried to divide an integer value by an\ninteger divisor of zero.\nEXCEPTION_INT_OVERFLOW The result of an integer operation caused a carry\nout of the most significant bit of the result.\nEXCEPTION_INVALID_DISPOSITION An exception handler returned an invalid\ndisposition to the exception dispatcher.\nProgrammers using a high-level language such\nas C should never encounter this exception.\nEXCEPTION_NONCONTINUABLE_EXCEPTIONThe thread tried to continue execution after a\nnoncontinuable exception occurred.\nEXCEPTION_PRIV_INSTRUCTION The thread tried to execute an instruction whose\noperation is not allowed in the current machine\nmode.\nEXCEPTION_SINGLE_STEP A trace trap or other single-instruction\nmechanism signaled that one instruction has\nbeen executed.\nEXCEPTION_STACK_OVERFLOW The thread used up its stack.\n \nAnother exception code is likely to occur when debugging console processes. It does\nnot arise because of a programming error. The DBG_CONTROL_C exception code occurs\nwhen CTRL+C is input to a console process that handles CTRL+C signals and is being\ndebugged. This exception code is not meant to be handled by applications. It is raised\nonly for the benefit of the debugger, and is raised only when a debugger is attached to\nthe console process.\nExceptionFlags\nThis member can be either zero, indicating a continuable exception, or\nEXCEPTION_NONCONTINUABLE, indicating a noncontinuable exception. Any attempt to\ncontinue execution after a noncontinuable exception causes the\nEXCEPTION_NONCONTINUABLE_EXCEPTION exception.\nExceptionRecord\nA pointer to an associated MINIDUMP_EXCEPTION structure. Exception records can be\nchained together to provide additional information when nested exceptions occur.\nExceptionAddress\nThe address where the exception occurred.\nNumberParameters\nThe number of parameters associated with the exception. This is the number of defined\nelements in the ExceptionInformation array.\n__unusedAlignment\nReserved for cross-platform structure member alignment. Do not set.\nExceptionInformation[EXCEPTION_MAXIMUM_PARAMETERS]\nFeedback\nWas this page helpful?\nAn array of additional arguments that describe the exception. The RaiseException\nfunction can specify this array of arguments. For most exception codes, the array\nelements are undefined. For the following exception code, the array elements are\ndefined as follows.\nException code Meaning\nEXCEPTION_ACCESS_VIOLATION The first element of the array contains a read/write flag\nthat indicates the type of operation that caused the\naccess violation. If this value is zero, the thread attempted\nto read the inaccessible data. If this value is 1, the thread\nattempted to write to an inaccessible address.\nThe second array element specifies the virtual address of\nthe inaccessible data.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_EXCEPTION_STREAM\nRaiseException\nﾉ Expand table\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3351,"title":"MINIDUMP_EXCEPTION_INFORMATION structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","exception","information","structure","minidumpapiset","contains","the","written","file","minidumpwritedump","function","article02","2024","threadid","identifier","thread","throwing","exceptionpointers","pointer","pointers","specifying","computer","independent","description","and","processor","context","time","clientpointers","determines","where","get","memory","regions","pointed","member","set","true","resides","process"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains the exception information written to the minidump file by the\nMiniDumpWriteDump function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_EXCEPTION_INFORMATION structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_EXCEPTION_INFORMATION\nstructure (minidumpapiset.h)\nArticle02/22/2024\nContains the exception information written to the minidump file by the\nMiniDumpWriteDump function.\nC++\nThreadId\nThe identifier of the thread throwing the exception.\nExceptionPointers\nA pointer to an EXCEPTION_POINTERS structure specifying a computer-independent\ndescription of the exception and the processor context at the time of the exception.\nClientPointers\nDetermines where to get the memory regions pointed to by the ExceptionPointers\nmember. Set to TRUE if the memory resides in the process being debugged (the target\nprocess of the debugger). Otherwise, set to FALSE if the memory resides in the address\nspace of the calling program (the debugger process). If you are accessing local memory\n(in the calling process) you should not set this member to TRUE.\nSyntax\ntypedef struct _MINIDUMP_EXCEPTION_INFORMATION {\n DWORD ThreadId;\n PEXCEPTION_POINTERS ExceptionPointers;\n BOOL ClientPointers;\n} MINIDUMP_EXCEPTION_INFORMATION, *PMINIDUMP_EXCEPTION_INFORMATION;\nMembers\nRequirements\nﾉ Expand table\nFeedback\nWas this page helpful?\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nEXCEPTION_POINTERS\nMiniDumpWriteDump\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3352,"title":"MINIDUMP_EXCEPTION_STREAM structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","exception","stream","structure","minidumpapiset","represents","information","article02","2024","threadid","the","identifier","thread","that","caused","alignment","variable","for","exceptionrecord","threadcontext","location","descriptor","this","context","data","set","file","syntax","typedef","struct","ulong32","pminidump","members","remarks","requirements","requirement","value","header","include","dbghelp"],"errorCode":"","eventId":"","severity":"Low","summary":"Represents an exception information stream.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_EXCEPTION_STREAM structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_EXCEPTION_STREAM structure\n(minidumpapiset.h)\nArticle02/22/2024\nRepresents an exception information stream.\nC++\nThreadId\nThe identifier of the thread that caused the exception.\n__alignment\nA variable for alignment.\nExceptionRecord\nA MINIDUMP_EXCEPTION structure.\nThreadContext\nA MINIDUMP_LOCATION_DESCRIPTOR structure.\nIn this context, a data stream is a set of data in a minidump file.\nSyntax\ntypedef struct MINIDUMP_EXCEPTION_STREAM {\n ULONG32 ThreadId;\n ULONG32 __alignment;\n MINIDUMP_EXCEPTION ExceptionRecord;\n MINIDUMP_LOCATION_DESCRIPTOR ThreadContext;\n} MINIDUMP_EXCEPTION_STREAM, *PMINIDUMP_EXCEPTION_STREAM;\nMembers\nRemarks\nRequirements\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_EXCEPTION\nMINIDUMP_LOCATION_DESCRIPTOR\nMINIDUMP_STREAM_TYPE\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3353,"title":"MINIDUMP_FUNCTION_TABLE_DESCRIP TOR structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","function","table","descrip","tor","structure","minidumpapiset","represents","stream","article02","2024","minimumaddress","the","minimum","address","functions","described","maximumaddress","maximum","baseaddress","base","use","when","computing","full","virtual","addresses","from","relative","entries","entrycount","number","sizeofalignpad","size","alignment","padding","that","follows","entry","data"],"errorCode":"","eventId":"","severity":"Low","summary":"Represents a function table stream.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_FUNCTION_TABLE_DESCRIP TOR structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_FUNCTION_TABLE_DESCRIP\nTOR structure (minidumpapiset.h)\nArticle02/22/2024\nRepresents a function table stream.\nC++\nMinimumAddress\nThe minimum address of functions described by the table.\nMaximumAddress\nThe maximum address of functions described by the table.\nBaseAddress\nThe base address to use when computing full virtual addresses from relative virtual\naddresses in function entries.\nEntryCount\nThe number of entries in the function table.\nSizeOfAlignPad\nThe size of alignment padding that follows the function entry data, in bytes. The\nfunction entry data in the stream is guaranteed to be aligned appropriately for access to\nSyntax\ntypedef struct _MINIDUMP_FUNCTION_TABLE_DESCRIPTOR {\n ULONG64 MinimumAddress;\n ULONG64 MaximumAddress;\n ULONG64 BaseAddress;\n ULONG32 EntryCount;\n ULONG32 SizeOfAlignPad;\n} MINIDUMP_FUNCTION_TABLE_DESCRIPTOR, *PMINIDUMP_FUNCTION_TABLE_DESCRIPTOR;\nMembers\nFeedback\nWas this page helpful?\nthe data members. If a minidump is directly mapped in memory, it is always possible to\ndirectly reference structure members in the stream.\nThe first descriptor in the function table stream follows the header,\nMINIDUMP_FUNCTION_TABLE_STREAM. The generic descriptor is followed by a native\nsystem descriptor, then by EntryCount native system function entry structures.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_FUNCTION_TABLE_STREAM\nRemarks\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3354,"title":"MINIDUMP_FUNCTION_TABLE_STREAM structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","function","table","stream","structure","minidumpapiset","represents","the","header","for","article02","2024","sizeofheader","size","information","bytes","this","value","sizeof","sizeofdescriptor","descriptor","sizeofnativedescriptor","raw","system","depends","particular","platform","and","version","which","was","generated","sizeoffunctionentry","entry","numberofdescriptors","syntax","typedef","struct","ulong32","sizeofalignpad"],"errorCode":"","eventId":"","severity":"Low","summary":"Represents the header for the function table stream.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_FUNCTION_TABLE_STREAM structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_FUNCTION_TABLE_STREAM\nstructure (minidumpapiset.h)\nArticle02/22/2024\nRepresents the header for the function table stream.\nC++\nSizeOfHeader\nThe size of header information for the stream, in bytes. This value is\nsizeof(MINIDUMP_FUNCTION_TABLE_STREAM).\nSizeOfDescriptor\nThe size of a descriptor in the stream, in bytes. This value is\nsizeof(MINIDUMP_FUNCTION_TABLE_DESCRIPTOR).\nSizeOfNativeDescriptor\nThe size of a raw system descriptor in the stream, in bytes. This value depends on the\nparticular platform and system version on which the minidump was generated.\nSizeOfFunctionEntry\nThe size of a raw system function table entry, in bytes. This value depends on the\nparticular platform and system version on which the minidump was generated.\nNumberOfDescriptors\nSyntax\ntypedef struct _MINIDUMP_FUNCTION_TABLE_STREAM {\n ULONG32 SizeOfHeader;\n ULONG32 SizeOfDescriptor;\n ULONG32 SizeOfNativeDescriptor;\n ULONG32 SizeOfFunctionEntry;\n ULONG32 NumberOfDescriptors;\n ULONG32 SizeOfAlignPad;\n} MINIDUMP_FUNCTION_TABLE_STREAM, *PMINIDUMP_FUNCTION_TABLE_STREAM;\nMembers\nFeedback\nWas this page helpful?\nThe number of descriptors in the stream.\nSizeOfAlignPad\nThe size of alignment padding that follows the header, in bytes.\nIn this context, a data stream is a set of data in a minidump file. This header structure is\nfollowed by NumberOfDescriptors function tables. For each function table there is a\nMINIDUMP_FUNCTION_TABLE_DESCRIPTOR structure, then the raw system descriptor\nfor the table, then the raw system function entry data. If necessary, alignment padding is\nplaced between tables to properly align the initial structures.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_FUNCTION_TABLE_DESCRIPTOR\nMINIDUMP_STREAM_TYPE\nRemarks\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3355,"title":"MINIDUMP_HANDLE_DATA_STREAM structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","handle","data","stream","structure","minidumpapiset","represents","the","header","for","article02","2024","sizeofheader","size","information","bytes","this","value","sizeof","sizeofdescriptor","descriptor","numberofdescriptors","number","descriptors","reserved","future","use","must","zero","context","set","file","followed","syntax","typedef","struct","ulong32","pminidump","members","remarks"],"errorCode":"","eventId":"","severity":"Low","summary":"Represents the header for a handle data stream.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_HANDLE_DATA_STREAM structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_HANDLE_DATA_STREAM\nstructure (minidumpapiset.h)\nArticle02/22/2024\nRepresents the header for a handle data stream.\nC++\nSizeOfHeader\nThe size of the header information for the stream, in bytes. This value is\nsizeof(MINIDUMP_HANDLE_DATA_STREAM).\nSizeOfDescriptor\nThe size of a descriptor in the stream, in bytes. This value is\nsizeof(MINIDUMP_HANDLE_DESCRIPTOR) or sizeof(MINIDUMP_HANDLE_DESCRIPTOR_2).\nNumberOfDescriptors\nThe number of descriptors in the stream.\nReserved\nReserved for future use; must be zero.\nIn this context, a data stream is a set of data in a minidump file. This header structure is\nfollowed by NumberOfDescriptors MINIDUMP_HANDLE_DESCRIPTOR or\nSyntax\ntypedef struct _MINIDUMP_HANDLE_DATA_STREAM {\n ULONG32 SizeOfHeader;\n ULONG32 SizeOfDescriptor;\n ULONG32 NumberOfDescriptors;\n ULONG32 Reserved;\n} MINIDUMP_HANDLE_DATA_STREAM, *PMINIDUMP_HANDLE_DATA_STREAM;\nMembers\nRemarks\nFeedback\nWas this page helpful?\nMINIDUMP_HANDLE_DESCRIPTOR_2 structures.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_HANDLE_DESCRIPTOR\nMINIDUMP_HANDLE_DESCRIPTOR_2\nMINIDUMP_STREAM_TYPE\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3356,"title":"MINIDUMP_HANDLE_DESCRIPTOR structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","handle","descriptor","structure","minidumpapiset","contains","the","state","individual","system","time","was","written","article02","2024","operating","value","typenamerva","rva","string","that","specifies","object","type","this","member","can","zero","objectnamerva","name","attributes","meaning","depends","and","grantedaccess","syntax","typedef","struct","ulong64","ulong32"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains the state of an individual system handle at the time the minidump was written.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_HANDLE_DESCRIPTOR structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_HANDLE_DESCRIPTOR\nstructure (minidumpapiset.h)\nArticle02/22/2024\nContains the state of an individual system handle at the time the minidump was written.\nC++\nHandle\nThe operating system handle value.\nTypeNameRva\nAn RVA to a MINIDUMP_STRING structure that specifies the object type of the handle.\nThis member can be zero.\nObjectNameRva\nAn RVA to a MINIDUMP_STRING structure that specifies the object name of the handle.\nThis member can be zero.\nAttributes\nThe meaning of this member depends on the handle type and the operating system.\nGrantedAccess\nThe meaning of this member depends on the handle type and the operating system.\nSyntax\ntypedef struct _MINIDUMP_HANDLE_DESCRIPTOR {\n ULONG64 Handle;\n RVA TypeNameRva;\n RVA ObjectNameRva;\n ULONG32 Attributes;\n ULONG32 GrantedAccess;\n ULONG32 HandleCount;\n ULONG32 PointerCount;\n} MINIDUMP_HANDLE_DESCRIPTOR, *PMINIDUMP_HANDLE_DESCRIPTOR;\nMembers\nFeedback\nWas this page helpful?\nHandleCount\nThe meaning of this member depends on the handle type and the operating system.\nPointerCount\nThe meaning of this member depends on the handle type and the operating system.\nThe first descriptor in the handle data stream follows the header,\nMINIDUMP_HANDLE_DATA_STREAM.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_HANDLE_DATA_STREAM\nMINIDUMP_STRING\nRemarks\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3357,"title":"MINIDUMP_HANDLE_DESCRIPTOR_2 structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","handle","descriptor","structure","minidumpapiset","describes","the","state","individual","system","time","was","written","article02","2024","operating","value","typenamerva","rva","string","that","specifies","object","type","this","member","can","zero","objectnamerva","name","attributes","meaning","depends","and","syntax","typedef","struct","ulong64","ulong32","grantedaccess"],"errorCode":"","eventId":"","severity":"Low","summary":"Describes the state of an individual system handle at the time the minidump was\nwritten.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_HANDLE_DESCRIPTOR_2 structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_HANDLE_DESCRIPTOR_2\nstructure (minidumpapiset.h)\nArticle02/22/2024\nDescribes the state of an individual system handle at the time the minidump was\nwritten.\nC++\nHandle\nThe operating system handle value.\nTypeNameRva\nAn RVA to a MINIDUMP_STRING structure that specifies the object type of the handle.\nThis member can be zero.\nObjectNameRva\nAn RVA to a MINIDUMP_STRING structure that specifies the object name of the handle.\nThis member can be 0.\nAttributes\nThe meaning of this member depends on the handle type and the operating system.\nSyntax\ntypedef struct _MINIDUMP_HANDLE_DESCRIPTOR_2 {\n ULONG64 Handle;\n RVA TypeNameRva;\n RVA ObjectNameRva;\n ULONG32 Attributes;\n ULONG32 GrantedAccess;\n ULONG32 HandleCount;\n ULONG32 PointerCount;\n RVA ObjectInfoRva;\n ULONG32 Reserved0;\n} MINIDUMP_HANDLE_DESCRIPTOR_2, *PMINIDUMP_HANDLE_DESCRIPTOR_2;\nMembers\nGrantedAccess\nThe meaning of this member depends on the handle type and the operating system.\nHandleCount\nThe meaning of this member depends on the handle type and the operating system.\nPointerCount\nThe meaning of this member depends on the handle type and the operating system.\nObjectInfoRva\nAn RVA to a MINIDUMP_HANDLE_OBJECT_INFORMATION structure that specifies\nobject-specific information. This member can be 0 if there is no extra information.\nReserved0\nReserved for future use; must be zero.\nThe first descriptor in the handle data stream follows the header,\nMINIDUMP_HANDLE_DATA_STREAM.\nRequirement Value\nHeader minidumpapiset.h (include Dbghelp.h)\nRedistributable DbgHelp.dll 6.5 or later\nMINIDUMP_HANDLE_DATA_STREAM\nMINIDUMP_HANDLE_OBJECT_INFORMATION\nMINIDUMP_STRING\nRemarks\nRequirements\nﾉ Expand table\nSee also\nFeedback\nWas this page helpful? Yes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3358,"title":"MINIDUMP_HANDLE_OBJECT_INFORMA TION structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","handle","object","informa","tion","structure","minidumpapiset","contains","specific","information","for","article02","2024","nextinforva","rva","that","specifies","additional","this","member","there","are","more","elements","the","list","infotype","type","one","values","from","enumeration","sizeofinfo","size","follows","bytes","requirement","value","header","include"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains object-specific information for a handle.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_HANDLE_OBJECT_INFORMA TION structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_HANDLE_OBJECT_INFORMA\nTION structure (minidumpapiset.h)\nArticle02/22/2024\nContains object-specific information for a handle.\nC++\nNextInfoRva\nAn RVA to a MINIDUMP_HANDLE_OBJECT_INFORMATION structure that specifies\nadditional object-specific information. This member is 0 if there are no more elements in\nthe list.\nInfoType\nThe object information type. This member is one of the values from the\nMINIDUMP_HANDLE_OBJECT_INFORMATION_TYPE enumeration.\nSizeOfInfo\nThe size of the information that follows this member, in bytes.\nRequirement Value\nHeader minidumpapiset.h (include Dbghelp.h)\nSyntax\ntypedef struct _MINIDUMP_HANDLE_OBJECT_INFORMATION {\n RVA NextInfoRva;\n ULONG32 InfoType;\n ULONG32 SizeOfInfo;\n} MINIDUMP_HANDLE_OBJECT_INFORMATION;\nMembers\nRequirements\nﾉ Expand table\nFeedback\nWas this page helpful?\nRequirement Value\nRedistributable DbgHelp.dll 6.5 or later\nMINIDUMP_HANDLE_DESCRIPTOR_2\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3359,"title":"MINIDUMP_HANDLE_OPERATION_LIST structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","handle","operation","list","structure","minidumpapiset","contains","operations","article02","2024","sizeofheader","the","size","header","data","for","stream","bytes","this","generally","sizeof","sizeofentry","each","entry","following","avrf","numberofentries","number","entries","these","are","structures","follow","reserved","member","future","use","syntax","typedef","struct"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains a list of handle operations.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_HANDLE_OPERATION_LIST structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_HANDLE_OPERATION_LIST\nstructure (minidumpapiset.h)\nArticle02/22/2024\nContains a list of handle operations.\nC++\nSizeOfHeader\nThe size of the header data for the stream, in bytes. This is generally\nsizeof(MINIDUMP_HANDLE_OPERATION_LIST).\nSizeOfEntry\nThe size of each entry following the header, in bytes. This is generally\nsizeof(AVRF_HANDLE_OPERATION).\nNumberOfEntries\nThe number of entries in the stream. These are generally AVRF_HANDLE_OPERATION\nstructures. The entries follow the header.\nReserved\nThis member is reserved for future use.\nSyntax\ntypedef struct _MINIDUMP_HANDLE_OPERATION_LIST {\n ULONG32 SizeOfHeader;\n ULONG32 SizeOfEntry;\n ULONG32 NumberOfEntries;\n ULONG32 Reserved;\n} MINIDUMP_HANDLE_OPERATION_LIST, *PMINIDUMP_HANDLE_OPERATION_LIST;\nMembers\nRemarks\nFeedback\nWas this page helpful?\nFor a definition of the AVRF_HANDLE_OPERATION structure, see the Avrfsdk.h header\nfile.\nRequirement Value\nHeader minidumpapiset.h (include Dbghelp.h)\nRedistributable DbgHelp.dll 6.5 or later\nMINIDUMP_STREAM_TYPE\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3360,"title":"MINIDUMP_HEADER structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","header","structure","minidumpapiset","contains","information","for","the","file","article02","2024","signature","set","this","member","version","format","low","order","word","high","internal","value","that","implementation","specific","numberofstreams","number","streams","directory","streamdirectoryrva","base","rva","array","structures","syntax","typedef","struct","ulong32","checksum"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains header information for the minidump file.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_HEADER structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_HEADER structure\n(minidumpapiset.h)\nArticle02/22/2024\nContains header information for the minidump file.\nC++\nSignature\nThe signature. Set this member to MINIDUMP_SIGNATURE.\nVersion\nThe version of the minidump format. The low-order word is MINIDUMP_VERSION. The\nhigh-order word is an internal value that is implementation specific.\nNumberOfStreams\nThe number of streams in the minidump directory.\nStreamDirectoryRva\nThe base RVA of the minidump directory. The directory is an array of\nMINIDUMP_DIRECTORY structures.\nSyntax\ntypedef struct _MINIDUMP_HEADER {\n ULONG32 Signature;\n ULONG32 Version;\n ULONG32 NumberOfStreams;\n RVA StreamDirectoryRva;\n ULONG32 CheckSum;\n union {\n ULONG32 Reserved;\n ULONG32 TimeDateStamp;\n };\n ULONG64 Flags;\n} MINIDUMP_HEADER, *PMINIDUMP_HEADER;\nMembers\nFeedback\nWas this page helpful?\nCheckSum\nThe checksum for the minidump file. This member can be zero.\nReserved\nThis member is reserved.\nTimeDateStamp\nTime and date, in time_t format.\nFlags\nOne or more values from the MINIDUMP_TYPE enumeration type.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_DIRECTORY\nMINIDUMP_TYPE\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3361,"title":"MINIDUMP_INCLUDE_MODULE_CALLBA CK structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","include","module","callba","structure","minidumpapiset","contains","information","for","the","minidumpcallback","function","when","callback","type","includemodulecallback","article02","2024","baseofimage","base","address","executable","image","memory","requirement","value","header","dbghelp","redistributable","dll","later","input","syntax","typedef","struct","ulong64","pminidump","members","requirements","expand"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains information for the MiniDumpCallback function when the callback type is\nIncludeModuleCallback.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_INCLUDE_MODULE_CALLBA CK structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_INCLUDE_MODULE_CALLBA\nCK structure (minidumpapiset.h)\nArticle02/22/2024\nContains information for the MiniDumpCallback function when the callback type is\nIncludeModuleCallback.\nC++\nBaseOfImage\nThe base address of the executable image in memory.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_CALLBACK_INPUT\nMINIDUMP_CALLBACK_TYPE\nMiniDumpCallback\nSyntax\ntypedef struct _MINIDUMP_INCLUDE_MODULE_CALLBACK {\n ULONG64 BaseOfImage;\n} MINIDUMP_INCLUDE_MODULE_CALLBACK, *PMINIDUMP_INCLUDE_MODULE_CALLBACK;\nMembers\nRequirements\nﾉ Expand table\nSee also\nFeedback\nWas this page helpful? Yes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3362,"title":"MINIDUMP_INCLUDE_THREAD_CALLBA CK structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","include","thread","callba","structure","minidumpapiset","contains","information","for","the","minidumpcallback","function","when","callback","type","includethreadcallback","article02","2024","threadid","identifier","requirement","value","header","dbghelp","redistributable","dll","later","input","syntax","typedef","struct","ulong","pminidump","members","requirements","expand","table","see","also","feedback"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains information for the MiniDumpCallback function when the callback type is\nIncludeThreadCallback.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_INCLUDE_THREAD_CALLBA CK structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_INCLUDE_THREAD_CALLBA\nCK structure (minidumpapiset.h)\nArticle02/22/2024\nContains information for the MiniDumpCallback function when the callback type is\nIncludeThreadCallback.\nC++\nThreadId\nThe identifier of the thread.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_CALLBACK_INPUT\nMINIDUMP_CALLBACK_TYPE\nMiniDumpCallback\nSyntax\ntypedef struct _MINIDUMP_INCLUDE_THREAD_CALLBACK {\n ULONG ThreadId;\n} MINIDUMP_INCLUDE_THREAD_CALLBACK, *PMINIDUMP_INCLUDE_THREAD_CALLBACK;\nMembers\nRequirements\nﾉ Expand table\nSee also\nFeedback\nWas this page helpful? Yes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3363,"title":"MINIDUMP_IO_CALLBACK structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","callback","structure","minidumpapiset","contains","information","article02","2024","this","used","the","minidumpcallback","function","when","type","iostartcallback","iowriteallcallback","iofinishcallback","handle","file","passed","minidumpwritedump","offset","for","write","operation","from","start","data","member","only","with","buffer","pointer","that","written","bufferbytes","size","bytes","syntax"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains I/O callback information.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_IO_CALLBACK structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_IO_CALLBACK structure\n(minidumpapiset.h)\nArticle02/22/2024\nContains I/O callback information. This structure is used by the MiniDumpCallback\nfunction when the callback type is IoStartCallback, IoWriteAllCallback, or\nIoFinishCallback.\nC++\nHandle\nThe file handle passed to the MiniDumpWriteDump function.\nOffset\nThe offset for the write operation from the start of the minidump data. This member is\nused only with IoWriteAllCallback.\nBuffer\nA pointer to a buffer that contains the data to be written. This member is used only with\nIoWriteAllCallback.\nBufferBytes\nThe size of the data buffer, in bytes. This member is used only with IoWriteAllCallback.\nSyntax\ntypedef struct _MINIDUMP_IO_CALLBACK {\n HANDLE Handle;\n ULONG64 Offset;\n PVOID Buffer;\n ULONG BufferBytes;\n} MINIDUMP_IO_CALLBACK, *PMINIDUMP_IO_CALLBACK;\nMembers\nRequirements\nFeedback\nWas this page helpful?\nRequirement Value\nHeader minidumpapiset.h (include Dbghelp.h)\nRedistributable DbgHelp.dll 6.5 or later\nMINIDUMP_CALLBACK_INPUT\nMiniDumpCallback\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3364,"title":"MINIDUMP_LOCATION_DESCRIPTOR structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","location","descriptor","structure","minidumpapiset","contains","information","describing","the","data","stream","within","file","article02","2024","datasize","size","bytes","rva","relative","virtual","address","this","byte","offset","from","beginning","context","refers","block","uses","bit","locations","for","rvas","first","4gb","and","are","used"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains information describing the location of a data stream within a minidump file.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_LOCATION_DESCRIPTOR structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_LOCATION_DESCRIPTOR\nstructure (minidumpapiset.h)\nArticle02/22/2024\nContains information describing the location of a data stream within a minidump file.\nC++\nDataSize\nThe size of the data stream, in bytes.\nRva\nThe relative virtual address (RVA) of the data. This is the byte offset of the data stream\nfrom the beginning of the minidump file.\nIn this context, a data stream refers to a block of data within a minidump file.\nThis structure uses 32-bit locations for RVAs in the first 4GB and 64-bit locations are\nused for larger RVAs. The MINIDUMP_LOCATION_DESCRIPTOR64 structure is defined\nas follows.\nC++\nSyntax\ntypedef struct _MINIDUMP_LOCATION_DESCRIPTOR {\n ULONG32 DataSize;\n RVA Rva;\n} MINIDUMP_LOCATION_DESCRIPTOR;\nMembers\nRemarks\ntypedef struct _MINIDUMP_LOCATION_DESCRIPTOR64 {\n ULONG64 DataSize;\n RVA64 Rva;\n} MINIDUMP_LOCATION_DESCRIPTOR64;\nFeedback\nWas this page helpful?\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h, Minidumpapiset.h)\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_DIRECTORY\nMINIDUMP_EXCEPTION_STREAM\nMINIDUMP_MEMORY_DESCRIPTOR\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3365,"title":"MINIDUMP_MEMORY_DESCRIPTOR structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","memory","descriptor","structure","minidumpapiset","startofmemoryrange","the","starting","address","range","article02","2024","describes","location","descriptor64","used","for","full","minidumps","where","all","raw","sequential","end","there","need","individual","relative","virtual","addresses","rvas","because","rva","base","plus","sum","preceding","data","blocks","defined"],"errorCode":"","eventId":"","severity":"Low","summary":"C++\nStartOfMemoryRange\nThe starting address of the memory range.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_MEMORY_DESCRIPTOR structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_MEMORY_DESCRIPTOR\nstructure (minidumpapiset.h)\nArticle02/22/2024\nDescribes a range of memory.\nC++\nStartOfMemoryRange\nThe starting address of the memory range.\nMemory\nA MINIDUMP_LOCATION_DESCRIPTOR structure.\nMINIDUMP_MEMORY_DESCRIPTOR64 is used for full-memory minidumps where all of\nthe raw memory is sequential at the end of the minidump. There is no need for\nindividual relative virtual addresses (RVAs), because the RVA is the base RVA plus the\nsum of the preceding data blocks. The MINIDUMP_MEMORY_DESCRIPTOR64 structure\nis defined as follows.\nC++\nSyntax\ntypedef struct _MINIDUMP_MEMORY_DESCRIPTOR {\n ULONG64 StartOfMemoryRange;\n MINIDUMP_LOCATION_DESCRIPTOR Memory;\n} MINIDUMP_MEMORY_DESCRIPTOR, *PMINIDUMP_MEMORY_DESCRIPTOR;\nMembers\nRemarks\ntypedef struct _MINIDUMP_MEMORY_DESCRIPTOR64 {\n ULONG64 StartOfMemoryRange;\n ULONG64 DataSize;\n} MINIDUMP_MEMORY_DESCRIPTOR64, *PMINIDUMP_MEMORY_DESCRIPTOR64;\nFeedback\nWas this page helpful?\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h, Minidumpapiset.h)\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_LOCATION_DESCRIPTOR\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3366,"title":"MINIDUMP_MEMORY_INFO structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","memory","info","structure","minidumpapiset","baseaddress","the","base","address","region","pages","article04","2021","describes","allocationbase","range","this","page","contained","within","allocationprotect","protection","when","was","initially","allocated","member","can","one","options","along","with","guard","nocache","needed","alignment1","variable","for","alignment","syntax"],"errorCode":"","eventId":"","severity":"Low","summary":"C++\nBaseAddress\nThe base address of the region of pages.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_MEMORY_INFO structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_MEMORY_INFO structure\n(minidumpapiset.h)\nArticle04/02/2021\nDescribes a region of memory.\nC++\nBaseAddress\nThe base address of the region of pages.\nAllocationBase\nThe base address of a range of pages in this region. The page is contained within this\nmemory region.\nAllocationProtect\nThe memory protection when the region was initially allocated. This member can be one\nof the memory protection options, along with PAGE_GUARD or PAGE_NOCACHE, as\nneeded.\n__alignment1\nA variable for alignment.\nSyntax\ntypedef struct _MINIDUMP_MEMORY_INFO {\n ULONG64 BaseAddress;\n ULONG64 AllocationBase;\n ULONG32 AllocationProtect;\n ULONG32 __alignment1;\n ULONG64 RegionSize;\n ULONG32 State;\n ULONG32 Protect;\n ULONG32 Type;\n ULONG32 __alignment2;\n} MINIDUMP_MEMORY_INFO, *PMINIDUMP_MEMORY_INFO;\nMembers\nRegionSize\nThe size of the region beginning at the base address in which all pages have identical\nattributes, in bytes.\nState\nThe state of the pages in the region. This member can be one of the following values.\nState Meaning\nMEM_COMMIT\n0x1000\nIndicates committed pages for which physical storage has\nbeen allocated, either in memory or in the paging file on\ndisk.\nMEM_FREE\n0x10000\nIndicates free pages not accessible to the calling process\nand available to be allocated. For free pages, the\ninformation in the AllocationBase, AllocationProtect,\nProtect, and Type members is undefined.\nMEM_RESERVE\n0x2000\nIndicates reserved pages where a range of the process's\nvirtual address space is reserved without any physical\nstorage being allocated. For reserved pages, the\ninformation in the Protect member is undefined.\nProtect\nThe access protection of the pages in the region. This member is one of the values listed\nfor the AllocationProtect member.\nType\nThe type of pages in the region. The following types are defined.\nType Meaning\nMEM_IMAGE\n0x1000000\nIndicates that the memory pages within the region are\nmapped into the view of an image section.\nMEM_MAPPED\n0x40000\nIndicates that the memory pages within the region are\nmapped into the view of a section.\nMEM_PRIVATE\n0x20000\nIndicates that the memory pages within the region are\nprivate (that is, not shared by other processes).\nﾉ Expand table\nﾉ Expand table\nFeedback\nWas this page helpful?\n__alignment2\nA variable for alignment.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 6.3 or later\nMINIDUMP_MEMORY_INFO_LIST\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3367,"title":"MINIDUMP_MEMORY_INFO_LIST structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","memory","info","list","structure","minidumpapiset","contains","regions","article02","2024","sizeofheader","the","size","header","data","for","stream","bytes","this","generally","sizeof","sizeofentry","each","entry","following","numberofentries","number","entries","these","are","structures","follow","requirement","value","include","dbghelp","syntax","typedef","struct","ulong"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains a list of memory regions.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_MEMORY_INFO_LIST structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_MEMORY_INFO_LIST\nstructure (minidumpapiset.h)\nArticle02/22/2024\nContains a list of memory regions.\nC++\nSizeOfHeader\nThe size of the header data for the stream, in bytes. This is generally\nsizeof(MINIDUMP_MEMORY_INFO_LIST).\nSizeOfEntry\nThe size of each entry following the header, in bytes. This is generally\nsizeof(MINIDUMP_MEMORY_INFO).\nNumberOfEntries\nThe number of entries in the stream. These are generally MINIDUMP_MEMORY_INFO\nstructures. The entries follow the header.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nSyntax\ntypedef struct _MINIDUMP_MEMORY_INFO_LIST {\n ULONG SizeOfHeader;\n ULONG SizeOfEntry;\n ULONG64 NumberOfEntries;\n} MINIDUMP_MEMORY_INFO_LIST, *PMINIDUMP_MEMORY_INFO_LIST;\nMembers\nRequirements\nﾉ Expand table\nFeedback\nWas this page helpful?\nRequirement Value\nRedistributable DbgHelp.dll 6.3 or later\nMINIDUMP_MEMORY_INFO\nMINIDUMP_STREAM_TYPE\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3368,"title":"MINIDUMP_MEMORY64_LIST structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","memory64","list","structure","minidumpapiset","contains","memory","ranges","article02","2024","numberofmemoryranges","the","number","structures","memoryranges","array","baserva","descriptor","defined","follows","used","for","fullmemory","minidumps","syntax","typedef","struct","ulong64","rva64","descriptor64","pminidump","members","remarks","feedback","was","this","page","helpful","note","that"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains a list of memory ranges.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_MEMORY64_LIST structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_MEMORY64_LIST structure\n(minidumpapiset.h)\nArticle02/22/2024\nContains a list of memory ranges.\nC++\nNumberOfMemoryRanges\nThe number of structures in the MemoryRanges array.\nBaseRva\nMemoryRanges[0]\nAn array of MINIDUMP_MEMORY_DESCRIPTOR structures.\nThe MINIDUMP_MEMORY64_LIST structure is defined as follows. It is used for fullmemory minidumps.\nC++\nSyntax\ntypedef struct _MINIDUMP_MEMORY64_LIST {\n ULONG64 NumberOfMemoryRanges;\n RVA64 BaseRva;\n MINIDUMP_MEMORY_DESCRIPTOR64 MemoryRanges[0];\n} MINIDUMP_MEMORY64_LIST, *PMINIDUMP_MEMORY64_LIST;\nMembers\nRemarks\ntypedef struct _MINIDUMP_MEMORY64_LIST {\n ULONG64 NumberOfMemoryRanges;\n RVA64 BaseRva;\n MINIDUMP_MEMORY_DESCRIPTOR64 MemoryRanges [0];\n} MINIDUMP_MEMORY64_LIST, *PMINIDUMP_MEMORY64_LIST;\nFeedback\nWas this page helpful?\nNote that BaseRva is the overall base RVA for the memory list. To locate the data for a\nparticular descriptor, start at BaseRva and increment by the size of a descriptor until you\nreach the descriptor.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h, Minidumpapiset.h)\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_MEMORY_DESCRIPTOR\nMINIDUMP_STREAM_TYPE\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3369,"title":"MINIDUMP_MISC_INFO structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","misc","info","structure","minidumpapiset","contains","variety","information","article02","2024","sizeofinfo","the","size","bytes","flags1","flags","that","indicate","valid","members","this","member","can","one","more","following","values","value","meaning","misc1","process","0x00000001","processid","used","times","0x00000002","processcreatetime","processkerneltime","and","processusertime"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains a variety of information.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_MISC_INFO structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_MISC_INFO structure\n(minidumpapiset.h)\nArticle02/22/2024\nContains a variety of information.\nC++\nSizeOfInfo\nThe size of the structure, in bytes.\nFlags1\nThe flags that indicate the valid members of this structure. This member can be one or\nmore of the following values.\nValue Meaning\nMINIDUMP_MISC1_PROCESS_ID\n0x00000001\nProcessId is used.\nMINIDUMP_MISC1_PROCESS_TIMES\n0x00000002\nProcessCreateTime, ProcessKernelTime, and\nProcessUserTime are used.\nProcessId\nSyntax\ntypedef struct _MINIDUMP_MISC_INFO {\n ULONG32 SizeOfInfo;\n ULONG32 Flags1;\n ULONG32 ProcessId;\n ULONG32 ProcessCreateTime;\n ULONG32 ProcessUserTime;\n ULONG32 ProcessKernelTime;\n} MINIDUMP_MISC_INFO, *PMINIDUMP_MISC_INFO;\nMembers\nﾉ Expand table\nFeedback\nWas this page helpful?\nThe identifier of the process. If Flags1 does not specify MINIDUMP_MISC1_PROCESS_ID,\nthis member is unused.\nProcessCreateTime\nThe creation time of the process, in time_t format. If Flags1 does not specify\nMINIDUMP_MISC1_PROCESS_TIMES, this member is unused.\nProcessUserTime\nThe time the process has executed in user mode, in seconds. The time that each of the\nthreads of the process has executed in user mode is determined, then all these times are\nsummed to obtain this value. If Flags1 does not specify\nMINIDUMP_MISC1_PROCESS_TIMES, this member is unused.\nProcessKernelTime\nThe time the process has executed in kernel mode, in seconds. The time that each of the\nthreads of the process has executed in kernel mode is determined, then all these times\nare summed to obtain this value. If Flags1 does not specify\nMINIDUMP_MISC1_PROCESS_TIMES, this member is unused.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 6.0 or later\nMINIDUMP_STREAM_TYPE\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3370,"title":"MINIDUMP_MISC_INFO_2 structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","misc","info","structure","minidumpapiset","represents","information","the","miscellaneous","stream","article04","2021","sizeofinfo","size","bytes","flags1","flags","that","indicate","valid","members","this","member","can","one","more","following","values","value","meaning","misc1","process","0x00000001","processid","used","times","processcreatetime","processkerneltime","and","syntax"],"errorCode":"","eventId":"","severity":"Low","summary":"Represents information in the miscellaneous information stream.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_MISC_INFO_2 structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_MISC_INFO_2 structure\n(minidumpapiset.h)\nArticle04/02/2021\nRepresents information in the miscellaneous information stream.\nC++\nSizeOfInfo\nThe size of the structure, in bytes.\nFlags1\nThe flags that indicate the valid members of this structure. This member can be one or\nmore of the following values.\nValue Meaning\nMINIDUMP_MISC1_PROCESS_ID\n0x00000001\nProcessId is used.\nMINIDUMP_MISC1_PROCESS_TIMES ProcessCreateTime, ProcessKernelTime, and\nSyntax\ntypedef struct _MINIDUMP_MISC_INFO_2 {\n ULONG32 SizeOfInfo;\n ULONG32 Flags1;\n ULONG32 ProcessId;\n ULONG32 ProcessCreateTime;\n ULONG32 ProcessUserTime;\n ULONG32 ProcessKernelTime;\n ULONG32 ProcessorMaxMhz;\n ULONG32 ProcessorCurrentMhz;\n ULONG32 ProcessorMhzLimit;\n ULONG32 ProcessorMaxIdleState;\n ULONG32 ProcessorCurrentIdleState;\n} MINIDUMP_MISC_INFO_2, *PMINIDUMP_MISC_INFO_2;\nMembers\nﾉ Expand table\n0x00000002 ProcessUserTime are used.\nMINIDUMP_MISC1_PROCESSOR_POWER_INFO\n0x00000004\nProcessorMaxMhz, ProcessorCurrentMhz,\nProcessorMhzLimit, ProcessorMaxIdleState,\nand ProcessorCurrentIdleState are used.\nProcessId\nThe identifier of the process. If Flags1 does not specify MINIDUMP_MISC1_PROCESS_ID,\nthis member is unused.\nProcessCreateTime\nThe creation time of the process, in time_t format. If Flags1 does not specify\nMINIDUMP_MISC1_PROCESS_TIMES, this member is unused.\nProcessUserTime\nThe time the process has executed in user mode, in seconds. The time that each of the\nthreads of the process has executed in user mode is determined, then all these times are\nsummed to obtain this value. If Flags1 does not specify\nMINIDUMP_MISC1_PROCESS_TIMES, this member is unused.\nProcessKernelTime\nThe time the process has executed in kernel mode, in seconds. The time that each of the\nthreads of the process has executed in kernel mode is determined, then all these times\nare summed to obtain this value. If Flags1 does not specify\nMINIDUMP_MISC1_PROCESS_TIMES, this member is unused.\nProcessorMaxMhz\nThe maximum specified clock frequency of the system processor, in MHz. If Flags1 does\nnot specify MINIDUMP_MISC1_PROCESSOR_POWER_INFO, this member is unused.\nProcessorCurrentMhz\nThe processor clock frequency, in MHz. This number is the maximum specified processor\nclock frequency multiplied by the current processor throttle. If Flags1 does not specify\nMINIDUMP_MISC1_PROCESSOR_POWER_INFO, this member is unused.\nProcessorMhzLimit\nThe limit on the processor clock frequency, in MHz. This number is the maximum\nspecified processor clock frequency multiplied by the current processor thermal throttle\nFeedback\nWas this page helpful?\nlimit. If Flags1 does not specify MINIDUMP_MISC1_PROCESSOR_POWER_INFO, this\nmember is unused.\nProcessorMaxIdleState\nThe maximum idle state of the processor. If Flags1 does not specify\nMINIDUMP_MISC1_PROCESSOR_POWER_INFO, this member is unused.\nProcessorCurrentIdleState\nThe current idle state of the processor. If Flags1 does not specify\nMINIDUMP_MISC1_PROCESSOR_POWER_INFO, this member is unused.\nRequirement Value\nHeader minidumpapiset.h (include Dbghelp.h)\nRedistributable DbgHelp.dll 6.5 or later\nMINIDUMP_STREAM_TYPE\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3371,"title":"MINIDUMP_MODULE structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","module","structure","minidumpapiset","contains","information","for","specific","article02","2024","baseofimage","the","base","address","executable","image","memory","sizeofimage","size","bytes","checksum","value","timedatestamp","timestamp","time","format","modulenamerva","rva","string","that","specifies","name","syntax","typedef","struct","ulong64","ulong32","fixedfileinfo","versioninfo","location"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains information for a specific module.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_MODULE structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_MODULE structure\n(minidumpapiset.h)\nArticle02/22/2024\nContains information for a specific module.\nC++\nBaseOfImage\nThe base address of the module executable image in memory.\nSizeOfImage\nThe size of the module executable image in memory, in bytes.\nCheckSum\nThe checksum value of the module executable image.\nTimeDateStamp\nThe timestamp value of the module executable image, in time_t format.\nModuleNameRva\nAn RVA to a MINIDUMP_STRING structure that specifies the name of the module.\nSyntax\ntypedef struct _MINIDUMP_MODULE {\n ULONG64 BaseOfImage;\n ULONG32 SizeOfImage;\n ULONG32 CheckSum;\n ULONG32 TimeDateStamp;\n RVA ModuleNameRva;\n VS_FIXEDFILEINFO VersionInfo;\n MINIDUMP_LOCATION_DESCRIPTOR CvRecord;\n MINIDUMP_LOCATION_DESCRIPTOR MiscRecord;\n ULONG64 Reserved0;\n ULONG64 Reserved1;\n} MINIDUMP_MODULE, *PMINIDUMP_MODULE;\nMembers\nFeedback\nVersionInfo\nA VS_FIXEDFILEINFO structure that specifies the version of the module.\nCvRecord\nA MINIDUMP_LOCATION_DESCRIPTOR structure that specifies the CodeView record of\nthe module.\nMiscRecord\nA MINIDUMP_LOCATION_DESCRIPTOR structure that specifies the miscellaneous record\nof the module.\nReserved0\nReserved for future use.\nReserved1\nReserved for future use.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_MODULE_LIST\nMINIDUMP_STRING\nVS_FIXEDFILEINFO\nRequirements\nﾉ Expand table\nSee also\nWas this page helpful? Yes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3372,"title":"MINIDUMP_MODULE_CALLBACK structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","module","callback","structure","minidumpapiset","contains","information","for","the","minidumpcallback","function","when","type","modulecallback","article02","2024","fullpath","fully","qualified","path","executable","baseofimage","base","address","image","memory","sizeofimage","size","bytes","checksum","value","timedatestamp","syntax","typedef","struct","pwchar","ulong64","ulong","fixedfileinfo","versioninfo"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains module information for the MiniDumpCallback function when the callback\ntype is ModuleCallback.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_MODULE_CALLBACK structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_MODULE_CALLBACK\nstructure (minidumpapiset.h)\nArticle02/22/2024\nContains module information for the MiniDumpCallback function when the callback\ntype is ModuleCallback.\nC++\nFullPath\nThe fully qualified path of the module executable.\nBaseOfImage\nThe base address of the module executable image in memory.\nSizeOfImage\nThe size of the module executable image in memory, in bytes.\nCheckSum\nThe checksum value of the module executable image.\nTimeDateStamp\nSyntax\ntypedef struct _MINIDUMP_MODULE_CALLBACK {\n PWCHAR FullPath;\n ULONG64 BaseOfImage;\n ULONG SizeOfImage;\n ULONG CheckSum;\n ULONG TimeDateStamp;\n VS_FIXEDFILEINFO VersionInfo;\n PVOID CvRecord;\n ULONG SizeOfCvRecord;\n PVOID MiscRecord;\n ULONG SizeOfMiscRecord;\n} MINIDUMP_MODULE_CALLBACK, *PMINIDUMP_MODULE_CALLBACK;\nMembers\nFeedback\nWas this page helpful?\nThe timestamp value of the module executable image, in time_t format.\nVersionInfo\nA VS_FIXEDFILEINFO structure that specifies the version of the module.\nCvRecord\nA pointer to a string containing the CodeView record of the module.\nSizeOfCvRecord\nThe size of the Codeview record of the module in the CvRecord member, in bytes.\nMiscRecord\nA pointer to a string that specifies the miscellaneous record of the module.\nSizeOfMiscRecord\nThe size of the miscellaneous record of the module in the MiscRecord member, in bytes.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_CALLBACK_INPUT\nMiniDumpCallback\nVS_FIXEDFILEINFO\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3373,"title":"MINIDUMP_MODULE_LIST structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","module","list","structure","minidumpapiset","numberofmodules","the","number","structures","modules","array","article02","2024","contains","requirement","value","header","include","dbghelp","redistributable","dll","later","stream","type","syntax","typedef","struct","ulong32","pminidump","members","requirements","expand","table","see","also","feedback","was","this","page","helpful"],"errorCode":"","eventId":"","severity":"Low","summary":"C++\nNumberOfModules\nThe number of structures in the Modules array.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_MODULE_LIST structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_MODULE_LIST structure\n(minidumpapiset.h)\nArticle02/22/2024\nContains a list of modules.\nC++\nNumberOfModules\nThe number of structures in the Modules array.\nModules[0]\nAn array of MINIDUMP_MODULE structures.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_MODULE\nMINIDUMP_STREAM_TYPE\nSyntax\ntypedef struct _MINIDUMP_MODULE_LIST {\n ULONG32 NumberOfModules;\n MINIDUMP_MODULE Modules[0];\n} MINIDUMP_MODULE_LIST, *PMINIDUMP_MODULE_LIST;\nMembers\nRequirements\nﾉ Expand table\nSee also\nFeedback\nWas this page helpful? Yes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3374,"title":"MINIDUMP_READ_MEMORY_FAILURE_C ALLBACK structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","read","memory","failure","allback","structure","minidumpapiset","contains","information","about","failed","operation","article02","2024","this","used","the","minidumpcallback","function","when","callback","type","readmemoryfailurecallback","offset","address","for","bytes","size","failurestatus","resulting","error","code","from","requirement","value","header","include","dbghelp","redistributable","dll"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains information about a failed memory read operation.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_READ_MEMORY_FAILURE_C ALLBACK structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_READ_MEMORY_FAILURE_C\nALLBACK structure (minidumpapiset.h)\nArticle02/22/2024\nContains information about a failed memory read operation. This structure is used by\nthe MiniDumpCallback function when the callback type is ReadMemoryFailureCallback.\nC++\nOffset\nThe offset of the address for the failed memory read operation.\nBytes\nThe size of the failed memory read operation, in bytes.\nFailureStatus\nThe resulting error code from the failed memory read operation.\nRequirement Value\nHeader minidumpapiset.h (include Dbghelp.h)\nRedistributable DbgHelp.dll 6.5 or later\nSyntax\ntypedef struct _MINIDUMP_READ_MEMORY_FAILURE_CALLBACK {\n ULONG64 Offset;\n ULONG Bytes;\n HRESULT FailureStatus;\n} MINIDUMP_READ_MEMORY_FAILURE_CALLBACK, \n*PMINIDUMP_READ_MEMORY_FAILURE_CALLBACK;\nMembers\nRequirements\nﾉ Expand table\nFeedback\nWas this page helpful?\nMINIDUMP_CALLBACK_INPUT\nMiniDumpCallback\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3375,"title":"MINIDUMP_STRING structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","string","structure","minidumpapiset","length","the","size","buffer","member","bytes","article02","2024","describes","this","does","not","include","nullterminating","character","null","terminated","requirement","value","header","dbghelp","redistributable","dll","later","handle","descriptor","syntax","typedef","struct","ulong32","wchar","pminidump","members","requirements","expand","table"],"errorCode":"","eventId":"","severity":"Low","summary":"C++\nLength\nThe size of the string in the Buffer member, in bytes.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_STRING structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_STRING structure\n(minidumpapiset.h)\nArticle02/22/2024\nDescribes a string.\nC++\nLength\nThe size of the string in the Buffer member, in bytes. This size does not include the nullterminating character.\nBuffer[0]\nThe null-terminated string.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_HANDLE_DESCRIPTOR\nSyntax\ntypedef struct _MINIDUMP_STRING {\n ULONG32 Length;\n WCHAR Buffer[0];\n} MINIDUMP_STRING, *PMINIDUMP_STRING;\nMembers\nRequirements\nﾉ Expand table\nSee also\nFeedback\nWas this page helpful?\nMINIDUMP_MODULE\nMINIDUMP_UNLOADED_MODULE\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3376,"title":"MINIDUMP_SYSTEM_INFO structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","system","info","structure","minidumpapiset","contains","processor","and","operating","information","article04","2021","processorarchitecture","the","architecture","this","member","can","one","following","values","value","meaning","syntax","typedef","struct","ushort","processorlevel","processorrevision","union","reserved0","uchar","numberofprocessors","producttype","ulong32","majorversion","minorversion","buildnumber","platformid","rva"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains processor and operating system information.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_SYSTEM_INFO structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_SYSTEM_INFO structure\n(minidumpapiset.h)\nArticle04/02/2021\nContains processor and operating system information.\nC++\nProcessorArchitecture\nThe system's processor architecture. This member can be one of the following values.\nValue Meaning\nSyntax\ntypedef struct _MINIDUMP_SYSTEM_INFO {\n USHORT ProcessorArchitecture;\n USHORT ProcessorLevel;\n USHORT ProcessorRevision;\n union {\n USHORT Reserved0;\n struct {\n UCHAR NumberOfProcessors;\n UCHAR ProductType;\n };\n };\n ULONG32 MajorVersion;\n ULONG32 MinorVersion;\n ULONG32 BuildNumber;\n ULONG32 PlatformId;\n RVA CSDVersionRva;\n union {\n ULONG32 Reserved1;\n struct {\n USHORT SuiteMask;\n USHORT Reserved2;\n };\n };\n CPU_INFORMATION Cpu;\n} MINIDUMP_SYSTEM_INFO, *PMINIDUMP_SYSTEM_INFO;\nMembers\nﾉ Expand table\nPROCESSOR_ARCHITECTURE_AMD64\n9\nx64 (AMD or Intel)\nPROCESSOR_ARCHITECTURE_ARM\n5\nARM\nPROCESSOR_ARCHITECTURE_IA64\n6\nIntel Itanium\nPROCESSOR_ARCHITECTURE_INTEL\n0\nx86\nPROCESSOR_ARCHITECTURE_UNKNOWN\n0xffff\nUnknown processor.\nProcessorLevel\nThe system's architecture-dependent processor level.\nIf ProcessorArchitecture is PROCESSOR_ARCHITECTURE_INTEL, ProcessorLevel can be\none of the following values.\nValue Meaning\n3 Intel 80386\n4 Intel 80486\n5 Intel Pentium\n6 Intel Pentium Pro or Pentium II\n \nIf ProcessorArchitecture is PROCESSOR_ARCHITECTURE_IA64, ProcessorLevel is set to\n1.\nProcessorRevision\nThe architecture-dependent processor revision.\nProcessor Value\nIntel 80386 or 80486A value of the form xxyz.\nﾉ Expand table\nﾉ Expand table\nIf xx is equal to 0xFF, y - 0xA is the model number, and z is the stepping\nidentifier. For example, an Intel 80486-D0 system returns 0xFFD0.\nIf xx is not equal to 0xFF, xx + 'A' is the stepping letter and yz is the\nminor stepping.\nIntel Pentium, Cyrix, or\nNextGen 586\nA value of the form xxyy, where xx is the model number and yy is the\nstepping. Display this value of 0x0201 as follows:\nModel xx, Stepping yy\nReserved0\nThis member is reserved for future use and must be zero.\nNumberOfProcessors\nThe number of processors in the system.\nProductType\nAny additional information about the system. This member can be one of the following\nvalues.\nValue Meaning\nVER_NT_DOMAIN_CONTROLLER\n0x0000002\nThe system is a domain controller.\nVER_NT_SERVER\n0x0000003\nThe system is a server.\nVER_NT_WORKSTATION\n0x0000001\nThe system is running Windows XP, Windows Vista,\nWindows 7, or Windows 8.\nMajorVersion\nThe major version number of the operating system. This member can be 4, 5, or 6.\nMinorVersion\nThe minor version number of the operating system.\nBuildNumber\nThe build number of the operating system.\nﾉ Expand table\nPlatformId\nThe operating system platform. This member can be one of the following values.\nValue Meaning\nVER_PLATFORM_WIN32s\n0\nNot supported\nVER_PLATFORM_WIN32_WINDOWS\n1\nNot supported.\nVER_PLATFORM_WIN32_NT\n2\nThe operating system platform is Windows.\nCSDVersionRva\nAn RVA (from the beginning of the dump) to a MINIDUMP_STRING that describes the\nlatest Service Pack installed on the system. If no Service Pack has been installed, the\nstring is empty.\nReserved1\nThis member is reserved for future use.\nSuiteMask\nThe bit flags that identify the product suites available on the system. This member can\nbe a combination of the following values.\nValue Meaning\nVER_SUITE_BACKOFFICE\n0x00000004\nMicrosoft BackOffice components are installed.\nVER_SUITE_BLADE\n0x00000400\nWindows Server 2003, Web Edition is installed.\nVER_SUITE_COMPUTE_SERVER\n0x00004000\nWindows Server 2003, Compute Cluster Edition is\ninstalled.\nVER_SUITE_DATACENTER\n0x00000080\nWindows Server 2008 R2 Datacenter, Windows\nServer 2008 Datacenter, or Windows Server 2003,\nDatacenter Edition is installed.\nﾉ Expand table\nﾉ Expand table\nVER_SUITE_ENTERPRISE\n0x00000002\nWindows Server 2008 R2 Enterprise, Windows\nServer 2008 Enterprise, or Windows Server 2003,\nEnterprise Edition is installed.\nVER_SUITE_EMBEDDEDNT\n0x00000040\nWindows Embedded is installed.\nVER_SUITE_PERSONAL\n0x00000200\nWindows XP Home Edition is installed.\nVER_SUITE_SINGLEUSERTS\n0x00000100\nRemote Desktop is supported, but only one\ninteractive session is supported. This value is set\nunless the system is running in application server\nmode.\nVER_SUITE_SMALLBUSINESS\n0x00000001\nMicrosoft Small Business Server was once installed\non the system, but may have been upgraded to\nanother version of Windows.\nVER_SUITE_SMALLBUSINESS_RESTRICTED\n0x00000020\nMicrosoft Small Business Server is installed with the\nrestrictive client license in force.\nVER_SUITE_STORAGE_SERVER\n0x00002000\nWindows Storage Server is installed.\nVER_SUITE_TERMINAL\n0x00000010\nTerminal Services is installed. This value is always set.\nIf VER_SUITE_TERMINAL is set but\nVER_SUITE_SINGLEUSERTS is not set, the system is\nrunning in application server mode.\nReserved2\nThis member is reserved for future use.\nCpu\nThe CPU information obtained from the CPUID instruction. This structure is supported\nonly for x86 computers.\nCPUID subfunction 0. The array elements are as follows:\nX86CpuInfo\nVendorId\nVersionInformation\nFeedback\nWas this page helpful?\nCPUID subfunction 1. Value of EAX.\nCPUID subfunction 1. Value of EDX.\nCPUID subfunction 80000001. Value of EBX. This member is supported only if the vendor\nis \"AuthenticAMD\".\nOther CPU information. This structure is supported only for non-x86 computers.\nFor a list of possible values, see the IsProcessorFeaturePresent function.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nIsProcessorFeaturePresent\nMINIDUMP_STREAM_TYPE\nFeatureInformation\nAMDExtendedCpuFeatures\nOtherCpuInfo\nProcessorFeatures\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3377,"title":"MINIDUMP_THREAD structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","thread","structure","minidumpapiset","contains","information","for","specific","article02","2024","threadid","the","identifier","suspendcount","suspend","count","greater","than","zero","suspended","otherwise","not","maximum","value","priorityclass","priority","class","see","scheduling","priorities","level","teb","environment","block","syntax","typedef","struct","ulong32","ulong64","memory"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains information for a specific thread.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_THREAD structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_THREAD structure\n(minidumpapiset.h)\nArticle02/22/2024\nContains information for a specific thread.\nC++\nThreadId\nThe identifier of the thread.\nSuspendCount\nThe suspend count for the thread. If the suspend count is greater than zero, the thread\nis suspended; otherwise, the thread is not suspended. The maximum value is\nMAXIMUM_SUSPEND_COUNT.\nPriorityClass\nThe priority class of the thread. See Scheduling Priorities.\nPriority\nThe priority level of the thread.\nTeb\nThe thread environment block.\nSyntax\ntypedef struct _MINIDUMP_THREAD {\n ULONG32 ThreadId;\n ULONG32 SuspendCount;\n ULONG32 PriorityClass;\n ULONG32 Priority;\n ULONG64 Teb;\n MINIDUMP_MEMORY_DESCRIPTOR Stack;\n MINIDUMP_LOCATION_DESCRIPTOR ThreadContext;\n} MINIDUMP_THREAD, *PMINIDUMP_THREAD;\nMembers\nFeedback\nWas this page helpful?\nStack\nA MINIDUMP_MEMORY_DESCRIPTOR structure.\nThreadContext\nA MINIDUMP_LOCATION_DESCRIPTOR structure.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_LOCATION_DESCRIPTOR\nMINIDUMP_MEMORY_DESCRIPTOR\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3378,"title":"MINIDUMP_THREAD_CALLBACK structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","thread","callback","structure","minidumpapiset","contains","information","for","the","minidumpcallback","function","when","type","threadcallback","article02","2024","threadid","identifier","threadhandle","handle","pad","context","that","processor","specific","data","sizeofcontext","size","returned","member","bytes","stackbase","syntax","typedef","struct","ulong","ulong64","stackend","pminidump","members"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains thread information for the MiniDumpCallback function when the callback type\nis ThreadCallback.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_THREAD_CALLBACK structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_THREAD_CALLBACK\nstructure (minidumpapiset.h)\nArticle02/22/2024\nContains thread information for the MiniDumpCallback function when the callback type\nis ThreadCallback.\nC++\nThreadId\nThe identifier of the thread.\nThreadHandle\nA handle to the thread\nPad\nContext\nA CONTEXT structure that contains the processor-specific data.\nSizeOfContext\nThe size of the returned processor-specific data in the Context member, in bytes.\nStackBase\nSyntax\ntypedef struct _MINIDUMP_THREAD_CALLBACK {\n ULONG ThreadId;\n HANDLE ThreadHandle;\n ULONG Pad;\n CONTEXT Context;\n ULONG SizeOfContext;\n ULONG64 StackBase;\n ULONG64 StackEnd;\n} MINIDUMP_THREAD_CALLBACK, *PMINIDUMP_THREAD_CALLBACK;\nMembers\nFeedback\nWas this page helpful?\nThe base address of the thread stack.\nStackEnd\nThe ending address of the thread stack.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nCONTEXT\nMINIDUMP_CALLBACK_INPUT\nMiniDumpCallback\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3379,"title":"MINIDUMP_THREAD_EX structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","thread","structure","minidumpapiset","contains","extended","information","for","specific","article02","2024","threadid","the","identifier","suspendcount","suspend","count","greater","than","zero","suspended","otherwise","not","maximum","value","priorityclass","priority","class","see","scheduling","priorities","level","teb","syntax","typedef","struct","ulong32","ulong64","memory","descriptor"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains extended information for a specific thread.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_THREAD_EX structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_THREAD_EX structure\n(minidumpapiset.h)\nArticle02/22/2024\nContains extended information for a specific thread.\nC++\nThreadId\nThe identifier of the thread.\nSuspendCount\nThe suspend count for the thread. If the suspend count is greater than zero, the thread\nis suspended; otherwise, the thread is not suspended. The maximum value is\nMAXIMUM_SUSPEND_COUNT.\nPriorityClass\nThe priority class of the thread. See Scheduling Priorities.\nPriority\nThe priority level of the thread.\nTeb\nSyntax\ntypedef struct _MINIDUMP_THREAD_EX {\n ULONG32 ThreadId;\n ULONG32 SuspendCount;\n ULONG32 PriorityClass;\n ULONG32 Priority;\n ULONG64 Teb;\n MINIDUMP_MEMORY_DESCRIPTOR Stack;\n MINIDUMP_LOCATION_DESCRIPTOR ThreadContext;\n MINIDUMP_MEMORY_DESCRIPTOR BackingStore;\n} MINIDUMP_THREAD_EX, *PMINIDUMP_THREAD_EX;\nMembers\nFeedback\nWas this page helpful?\nThe thread environment block.\nStack\nA MINIDUMP_MEMORY_DESCRIPTOR structure.\nThreadContext\nA MINIDUMP_LOCATION_DESCRIPTOR structure.\nBackingStore\nIntel Itanium: The backing store for the thread.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_LOCATION_DESCRIPTOR\nMINIDUMP_MEMORY_DESCRIPTOR\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3380,"title":"MINIDUMP_THREAD_EX_CALLBACK structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","thread","callback","structure","minidumpapiset","contains","extended","information","for","the","minidumpcallback","function","when","type","threadexcallback","article02","2024","threadid","identifier","threadhandle","handle","pad","context","that","processor","specific","data","sizeofcontext","size","returned","member","bytes","syntax","typedef","struct","ulong","ulong64","stackbase","stackend","backingstorebase"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains extended thread information for the MiniDumpCallback function when the\ncallback type is ThreadExCallback.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_THREAD_EX_CALLBACK structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_THREAD_EX_CALLBACK\nstructure (minidumpapiset.h)\nArticle02/22/2024\nContains extended thread information for the MiniDumpCallback function when the\ncallback type is ThreadExCallback.\nC++\nThreadId\nThe identifier of the thread.\nThreadHandle\nA handle to the thread\nPad\nContext\nA CONTEXT structure that contains the processor-specific data.\nSizeOfContext\nThe size of the returned processor-specific data in the Context member, in bytes.\nSyntax\ntypedef struct _MINIDUMP_THREAD_EX_CALLBACK {\n ULONG ThreadId;\n HANDLE ThreadHandle;\n ULONG Pad;\n CONTEXT Context;\n ULONG SizeOfContext;\n ULONG64 StackBase;\n ULONG64 StackEnd;\n ULONG64 BackingStoreBase;\n ULONG64 BackingStoreEnd;\n} MINIDUMP_THREAD_EX_CALLBACK, *PMINIDUMP_THREAD_EX_CALLBACK;\nMembers\nFeedback\nWas this page helpful?\nStackBase\nThe base address of the thread stack.\nStackEnd\nThe ending address of the thread stack.\nBackingStoreBase\nIntel Itanium: The base address of the thread backing store.\nBackingStoreEnd\nIntel Itanium: The ending address of the thread backing store.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nCONTEXT\nMINIDUMP_CALLBACK_INPUT\nMiniDumpCallback\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3381,"title":"MINIDUMP_THREAD_EX_LIST structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","thread","list","structure","minidumpapiset","numberofthreads","the","number","structures","threads","array","article02","2024","contains","requirement","value","header","include","dbghelp","redistributable","dll","later","stream","type","syntax","typedef","struct","ulong32","pminidump","members","requirements","expand","table","see","also","feedback","was","this","page","helpful"],"errorCode":"","eventId":"","severity":"Low","summary":"C++\nNumberOfThreads\nThe number of structures in the Threads array.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_THREAD_EX_LIST structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_THREAD_EX_LIST structure\n(minidumpapiset.h)\nArticle02/22/2024\nContains a list of threads.\nC++\nNumberOfThreads\nThe number of structures in the Threads array.\nThreads[0]\nAn array of MINIDUMP_THREAD_EX structures.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_STREAM_TYPE\nMINIDUMP_THREAD_EX\nSyntax\ntypedef struct _MINIDUMP_THREAD_EX_LIST {\n ULONG32 NumberOfThreads;\n MINIDUMP_THREAD_EX Threads[0];\n} MINIDUMP_THREAD_EX_LIST, *PMINIDUMP_THREAD_EX_LIST;\nMembers\nRequirements\nﾉ Expand table\nSee also\nFeedback\nWas this page helpful? Yes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3382,"title":"MINIDUMP_THREAD_INFO structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","thread","info","structure","minidumpapiset","contains","state","information","article02","2024","threadid","the","identifier","dumpflags","flags","that","indicate","this","member","can","one","following","values","value","meaning","error","0x00000001","placeholder","due","accessing","exists","beyond","syntax","typedef","struct","ulong32","dumperror","exitstatus","ulong64","createtime"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains thread state information.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_THREAD_INFO structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_THREAD_INFO structure\n(minidumpapiset.h)\nArticle02/22/2024\nContains thread state information.\nC++\nThreadId\nThe identifier of the thread.\nDumpFlags\nThe flags that indicate the thread state. This member can be 0 or one of the following\nvalues.\nValue Meaning\nMINIDUMP_THREAD_INFO_ERROR_THREAD\n0x00000001\nA placeholder thread due to an error accessing\nthe thread. No thread information exists\nbeyond the thread identifier.\nSyntax\ntypedef struct _MINIDUMP_THREAD_INFO {\n ULONG32 ThreadId;\n ULONG32 DumpFlags;\n ULONG32 DumpError;\n ULONG32 ExitStatus;\n ULONG64 CreateTime;\n ULONG64 ExitTime;\n ULONG64 KernelTime;\n ULONG64 UserTime;\n ULONG64 StartAddress;\n ULONG64 Affinity;\n} MINIDUMP_THREAD_INFO, *PMINIDUMP_THREAD_INFO;\nMembers\nﾉ Expand table\nMINIDUMP_THREAD_INFO_EXITED_THREAD\n0x00000004\nThe thread has exited (not running any code)\nat the time of the dump.\nMINIDUMP_THREAD_INFO_INVALID_CONTEXT\n0x00000010\nThread context could not be retrieved.\nMINIDUMP_THREAD_INFO_INVALID_INFO\n0x00000008\nThread information could not be retrieved.\nMINIDUMP_THREAD_INFO_INVALID_TEB\n0x00000020\nTEB information could not be retrieved.\nMINIDUMP_THREAD_INFO_WRITING_THREAD\n0x00000002\nThis is the thread that called\nMiniDumpWriteDump.\nDumpError\nAn HRESULT value that indicates the dump status.\nExitStatus\nThe thread termination status code.\nCreateTime\nThe time when the thread was created, in 100-nanosecond intervals since January 1,\n1601 (UTC).\nExitTime\nThe time when the thread exited, in 100-nanosecond intervals since January 1, 1601\n(UTC).\nKernelTime\nThe time executed in kernel mode, in 100-nanosecond intervals.\nUserTime\nThe time executed in user mode, in 100-nanosecond intervals.\nStartAddress\nThe starting address of the thread.\nAffinity\nThe processor affinity mask.\nFeedback\nWas this page helpful?\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 6.3 or later\nMINIDUMP_THREAD_INFO_LIST\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3383,"title":"MINIDUMP_THREAD_INFO_LIST structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","thread","info","list","structure","minidumpapiset","sizeofheader","the","size","header","data","for","stream","bytes","article02","2024","contains","threads","this","generally","sizeof","sizeofentry","each","entry","following","numberofentries","number","entries","these","are","structures","follow","requirement","value","include","dbghelp","syntax","typedef","struct","ulong"],"errorCode":"","eventId":"","severity":"Low","summary":"C++\nSizeOfHeader\nThe size of the header data for the stream, in bytes.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_THREAD_INFO_LIST structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_THREAD_INFO_LIST\nstructure (minidumpapiset.h)\nArticle02/22/2024\nContains a list of threads.\nC++\nSizeOfHeader\nThe size of the header data for the stream, in bytes. This is generally\nsizeof(MINIDUMP_THREAD_INFO_LIST).\nSizeOfEntry\nThe size of each entry following the header, in bytes. This is generally\nsizeof(MINIDUMP_THREAD_INFO).\nNumberOfEntries\nThe number of entries in the stream. These are generally MINIDUMP_THREAD_INFO\nstructures. The entries follow the header.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nSyntax\ntypedef struct _MINIDUMP_THREAD_INFO_LIST {\n ULONG SizeOfHeader;\n ULONG SizeOfEntry;\n ULONG NumberOfEntries;\n} MINIDUMP_THREAD_INFO_LIST, *PMINIDUMP_THREAD_INFO_LIST;\nMembers\nRequirements\nﾉ Expand table\nFeedback\nWas this page helpful?\nRequirement Value\nRedistributable DbgHelp.dll 6.3 or later\nMINIDUMP_STREAM_TYPE\nMINIDUMP_THREAD_INFO\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3384,"title":"MINIDUMP_THREAD_LIST structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","thread","list","structure","minidumpapiset","numberofthreads","the","number","structures","threads","array","article02","2024","contains","requirement","value","header","include","dbghelp","redistributable","dll","later","stream","type","syntax","typedef","struct","ulong32","pminidump","members","requirements","expand","table","see","also","feedback","was","this","page","helpful"],"errorCode":"","eventId":"","severity":"Low","summary":"C++\nNumberOfThreads\nThe number of structures in the Threads array.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_THREAD_LIST structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_THREAD_LIST structure\n(minidumpapiset.h)\nArticle02/22/2024\nContains a list of threads.\nC++\nNumberOfThreads\nThe number of structures in the Threads array.\nThreads[0]\nAn array of MINIDUMP_THREAD structures.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_STREAM_TYPE\nMINIDUMP_THREAD\nSyntax\ntypedef struct _MINIDUMP_THREAD_LIST {\n ULONG32 NumberOfThreads;\n MINIDUMP_THREAD Threads[0];\n} MINIDUMP_THREAD_LIST, *PMINIDUMP_THREAD_LIST;\nMembers\nRequirements\nﾉ Expand table\nSee also\nFeedback\nWas this page helpful? Yes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3385,"title":"MINIDUMP_UNLOADED_MODULE structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","unloaded","module","structure","minidumpapiset","contains","information","about","that","has","been","article02","2024","this","can","help","diagnose","problems","calling","code","longer","loaded","baseofimage","the","base","address","executable","image","memory","sizeofimage","size","bytes","checksum","value","timedatestamp","timestamp","time","format","modulenamerva","rva"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains information about a module that has been unloaded.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_UNLOADED_MODULE structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_UNLOADED_MODULE\nstructure (minidumpapiset.h)\nArticle02/22/2024\nContains information about a module that has been unloaded. This information can help\ndiagnose problems calling code that is no longer loaded.\nC++\nBaseOfImage\nThe base address of the module executable image in memory.\nSizeOfImage\nThe size of the module executable image in memory, in bytes.\nCheckSum\nThe checksum value of the module executable image.\nTimeDateStamp\nThe timestamp value of the module executable image, in time_t format.\nModuleNameRva\nAn RVA to a MINIDUMP_STRING structure that specifies the name of the module.\nSyntax\ntypedef struct _MINIDUMP_UNLOADED_MODULE {\n ULONG64 BaseOfImage;\n ULONG32 SizeOfImage;\n ULONG32 CheckSum;\n ULONG32 TimeDateStamp;\n RVA ModuleNameRva;\n} MINIDUMP_UNLOADED_MODULE, *PMINIDUMP_UNLOADED_MODULE;\nMembers\nRequirements\nFeedback\nWas this page helpful?\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 6.0 or later\nMINIDUMP_UNLOADED_MODULE_LIST\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3386,"title":"MINIDUMP_UNLOADED_MODULE_LIST structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","unloaded","module","list","structure","minidumpapiset","contains","modules","article02","2024","sizeofheader","the","size","header","data","for","stream","bytes","this","generally","sizeof","sizeofentry","each","entry","following","numberofentries","number","entries","these","are","structures","follow","requirement","value","include","dbghelp","syntax","typedef","struct","ulong32"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains a list of unloaded modules.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_UNLOADED_MODULE_LIST structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_UNLOADED_MODULE_LIST\nstructure (minidumpapiset.h)\nArticle02/22/2024\nContains a list of unloaded modules.\nC++\nSizeOfHeader\nThe size of the header data for the stream, in bytes. This is generally\nsizeof(MINIDUMP_UNLOADED_MODULE_LIST).\nSizeOfEntry\nThe size of each entry following the header, in bytes. This is generally\nsizeof(MINIDUMP_UNLOADED_MODULE).\nNumberOfEntries\nThe number of entries in the stream. These are generally\nMINIDUMP_UNLOADED_MODULE structures. The entries follow the header.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nSyntax\ntypedef struct _MINIDUMP_UNLOADED_MODULE_LIST {\n ULONG32 SizeOfHeader;\n ULONG32 SizeOfEntry;\n ULONG32 NumberOfEntries;\n} MINIDUMP_UNLOADED_MODULE_LIST, *PMINIDUMP_UNLOADED_MODULE_LIST;\nMembers\nRequirements\nﾉ Expand table\nFeedback\nWas this page helpful?\nRequirement Value\nRedistributable DbgHelp.dll 6.0 or later\nMINIDUMP_STREAM_TYPE\nMINIDUMP_UNLOADED_MODULE\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3387,"title":"MINIDUMP_USER_STREAM structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","user","stream","structure","minidumpapiset","contains","defined","information","stored","data","article02","2024","type","the","for","more","see","buffersize","size","buffer","bytes","pointer","that","this","context","refers","block","within","file","syntax","typedef","struct","ulong32","ulong","pvoid","pminidump","members","remarks","requirements","expand"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains user-defined information stored in a data stream.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_USER_STREAM structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_USER_STREAM structure\n(minidumpapiset.h)\nArticle02/22/2024\nContains user-defined information stored in a data stream.\nC++\nType\nThe type of data stream. For more information, see MINIDUMP_STREAM_TYPE.\nBufferSize\nThe size of the user-defined data stream buffer, in bytes.\nBuffer\nA pointer to a buffer that contains the user-defined data stream.\nIn this context, a data stream refers to a block of data within a minidump file.\nSyntax\ntypedef struct _MINIDUMP_USER_STREAM {\n ULONG32 Type;\n ULONG BufferSize;\n PVOID Buffer;\n} MINIDUMP_USER_STREAM, *PMINIDUMP_USER_STREAM;\nMembers\nRemarks\nRequirements\nﾉ Expand table\nFeedback\nWas this page helpful?\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nMINIDUMP_STREAM_TYPE\nMINIDUMP_USER_STREAM_INFORMATION\nMiniDumpCallback\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3388,"title":"MINIDUMP_USER_STREAM_INFORMATI ON structure (minidumpapiset.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["minidump","user","stream","informati","structure","minidumpapiset","contains","list","data","streams","used","the","minidumpwritedump","function","article02","2024","userstreamcount","number","userstreamarray","array","structures","this","context","refers","block","within","file","requirement","value","header","include","dbghelp","redistributable","dll","later","syntax","typedef","struct","information","ulong"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains a list of user data streams used by the MiniDumpWriteDump function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MINIDUMP_USER_STREAM_INFORMATI ON structure (minidumpapiset.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MINIDUMP_USER_STREAM_INFORMATI\nON structure (minidumpapiset.h)\nArticle02/22/2024\nContains a list of user data streams used by the MiniDumpWriteDump function.\nC++\nUserStreamCount\nThe number of user streams.\nUserStreamArray\nAn array of MINIDUMP_USER_STREAM structures.\nIn this context, a data stream refers to a block of data within a minidump file.\nRequirement Value\nHeader minidumpapiset.h (include DbgHelp.h)\nRedistributable DbgHelp.dll 5.1 or later\nSyntax\ntypedef struct _MINIDUMP_USER_STREAM_INFORMATION {\n ULONG UserStreamCount;\n PMINIDUMP_USER_STREAM UserStreamArray;\n} MINIDUMP_USER_STREAM_INFORMATION, *PMINIDUMP_USER_STREAM_INFORMATION;\nMembers\nRemarks\nRequirements\nﾉ Expand table\nFeedback\nWas this page helpful?\nMINIDUMP_USER_STREAM\nMiniDumpWriteDump\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3389,"title":"MODLOAD_CVMISC structure (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["modload","cvmisc","structure","dbghelp","contains","codeview","and","misc","records","article02","2024","ocv","the","offset","record","ccv","size","omisc","cmisc","dtimage","date","time","stamp","image","cimage","syntax","typedef","struct","dword","pmodload","members","feedback","was","this","page","helpful","requirement","value","header","redistributable"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains CodeView and Misc records.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MODLOAD_CVMISC structure (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MODLOAD_CVMISC structure\n(dbghelp.h)\nArticle02/22/2024\nContains CodeView and Misc records.\nC++\noCV\nThe offset of the CodeView record.\ncCV\nThe size of the CodeView record.\noMisc\nThe offset of the Misc record.\ncMisc\nThe size of the Misc record.\ndtImage\nThe date/time stamp of the image.\ncImage\nSyntax\ntypedef struct _MODLOAD_CVMISC {\n DWORD oCV;\n size_t cCV;\n DWORD oMisc;\n size_t cMisc;\n DWORD dtImage;\n DWORD cImage;\n} MODLOAD_CVMISC, *PMODLOAD_CVMISC;\nMembers\nFeedback\nWas this page helpful?\nThe size of the image.\nRequirement Value\nHeader dbghelp.h\nRedistributable DbgHelp.dll 6.8 or later\nMODLOAD_DATA\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3390,"title":"MODLOAD_DATA structure (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["modload","data","structure","dbghelp","ssize","the","size","this","bytes","article02","2024","contains","module","ssig","type","member","can","one","following","values","value","meaning","dbhheader","debugdirs","0x1","buffer","that","array","image","debug","directory","structures","cvmisc","0x2","format","depends","syntax","typedef","struct","dword"],"errorCode":"","eventId":"","severity":"Low","summary":"C++\nssize\nThe size of this structure, in bytes.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MODLOAD_DATA structure (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MODLOAD_DATA structure (dbghelp.h)\nArticle02/22/2024\nContains module data.\nC++\nssize\nThe size of this structure, in bytes.\nssig\nThe type of data. This member can be one of the following values.\nValue Meaning\nDBHHEADER_DEBUGDIRS\n0x1\nThe data member is a buffer that contains an array of\nIMAGE_DEBUG_DIRECTORY structures.\nDBHHEADER_CVMISC\n0x2\nThe data member is a buffer that contains an array of\nMODLOAD_CVMISC structures.\ndata\nThe data. The format of this data depends on the value of the ssig member.\nsize\nThe size of the data buffer, in bytes.\nSyntax\ntypedef struct _MODLOAD_DATA {\n DWORD ssize;\n DWORD ssig;\n PVOID data;\n DWORD size;\n DWORD flags;\n} MODLOAD_DATA, *PMODLOAD_DATA;\nMembers\nﾉ Expand table\nFeedback\nWas this page helpful?\nflags\nThis member is unused.\nRequirement Value\nHeader dbghelp.h\nRedistributable DbgHelp.dll 6.0 or later\nIMAGE_DEBUG_DIRECTORY\nMODLOAD_CVMISC\nSymLoadModuleEx\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3391,"title":"OMAP structure (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["omap","structure","dbghelp","describes","entry","address","map","article02","2024","rva","relative","virtual","image","rvato","the","that","mapped","provides","translation","from","one","layout","another","array","structures","sorted","defines","translate","addra","addrb","perform","following","steps","search","for","with","largest","less","than","equal"],"errorCode":"","eventId":"","severity":"Low","summary":"Describes an entry in an address map.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to OMAP structure (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"OMAP structure (dbghelp.h)\nArticle02/22/2024\nDescribes an entry in an address map.\nC++\nrva\nA relative virtual address (RVA) in image A.\nrvaTo\nThe relative virtual address that rva is mapped to in image B.\nAn address map provides a translation from one image layout (A) to another (B). An\narray of OMAP structures, sorted by rva, defines an address map.\nTo translate an address, addrA, in image A to an address, addrB, in image B, perform the\nfollowing steps:\n1. Search the map for the entry, e, with the largest rva less than or equal to addrA.\n2. Set delta = addrA – e.rva.\n3. Set addrB = e.rvaTo + delta.\nSyntax\ntypedef struct _OMAP {\n ULONG rva;\n ULONG rvaTo;\n} OMAP, *POMAP;\nMembers\nRemarks\nRequirements\nﾉ Expand table\nFeedback\nWas this page helpful?\nRequirement Value\nHeader dbghelp.h\nRedistributable DbgHelp.dll 6.8 or later\nSymGetOmaps\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3392,"title":"Feedback SOURCEFILE structure (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["feedback","sourcefile","structure","dbghelp","contains","source","file","information","article02","2024","modbase","the","base","address","module","filename","fully","qualified","name","requirement","value","header","redistributable","dll","later","symenumsourcefiles","syntax","typedef","struct","dword64","pchar","psourcefile","members","requirements","expand","table","see","also","was","this"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains source file information.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to Feedback SOURCEFILE structure (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"Feedback\nSOURCEFILE structure (dbghelp.h)\nArticle02/22/2024\nContains source file information.\nC++\nModBase\nThe base address of the module.\nFileName\nThe fully qualified source file name.\nRequirement Value\nHeader dbghelp.h\nRedistributable DbgHelp.dll 6.3 or later\nSymEnumSourceFiles\nSyntax\ntypedef struct _SOURCEFILE {\n DWORD64 ModBase;\n PCHAR FileName;\n} SOURCEFILE, *PSOURCEFILE;\nMembers\nRequirements\nﾉ Expand table\nSee also\nWas this page helpful? Yes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3393,"title":"SRCCODEINFO structure (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["srccodeinfo","structure","dbghelp","sizeofstruct","the","size","bytes","article02","2024","contains","line","information","key","this","member","not","used","modbase","base","address","module","that","obj","max","path","name","object","file","within","filename","fully","qualified","source","linenumber","number","syntax","typedef","struct","dword","pvoid"],"errorCode":"","eventId":"","severity":"Low","summary":"C++\nSizeOfStruct\nThe size of the structure, in bytes.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SRCCODEINFO structure (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SRCCODEINFO structure (dbghelp.h)\nArticle02/22/2024\nContains line information.\nC++\nSizeOfStruct\nThe size of the structure, in bytes.\nKey\nThis member is not used.\nModBase\nThe base address of the module that contains the line.\nObj[MAX_PATH + 1]\nThe name of the object file within the module that contains the line.\nFileName[MAX_PATH + 1]\nThe fully qualified source file name.\nLineNumber\nThe line number within the source file.\nSyntax\ntypedef struct _SRCCODEINFO {\n DWORD SizeOfStruct;\n PVOID Key;\n DWORD64 ModBase;\n CHAR Obj[MAX_PATH + 1];\n CHAR FileName[MAX_PATH + 1];\n DWORD LineNumber;\n DWORD64 Address;\n} SRCCODEINFO, *PSRCCODEINFO;\nMembers\nFeedback\nWas this page helpful?\nAddress\nThe virtual address of the first instruction of the line.\nRequirement Value\nHeader dbghelp.h\nRedistributable DbgHelp.dll 6.1 or later\nSymEnumLinesProc\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3394,"title":"STACKFRAME structure (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["stackframe","structure","dbghelp","addrpc","address","that","specifies","the","program","counter","article05","2024","represents","stack","frame","x86","eip","intel","itanium","stiip","x64","rip","addrreturn","return","addrframe","pointer","ebp","there","but","addrbstore","used","syntax","typedef","struct","tagstackframe","addrstack","pvoid","functableentry","dword","params"],"errorCode":"","eventId":"","severity":"Low","summary":"C++\nAddrPC\nAn ADDRESS structure that specifies the program counter.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to STACKFRAME structure (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"STACKFRAME structure (dbghelp.h)\nArticle05/29/2024\nRepresents a stack frame.\nC++\nAddrPC\nAn ADDRESS structure that specifies the program counter.\nx86: The program counter is EIP.\nIntel Itanium: The program counter is StIIP.\nx64: The program counter is RIP.\nAddrReturn\nAn ADDRESS structure that specifies the return address.\nAddrFrame\nAn ADDRESS structure that specifies the frame pointer.\nx86: The frame pointer is EBP.\nIntel Itanium: There is no frame pointer, but AddrBStore is used.\nSyntax\ntypedef struct _tagSTACKFRAME {\n ADDRESS AddrPC;\n ADDRESS AddrReturn;\n ADDRESS AddrFrame;\n ADDRESS AddrStack;\n PVOID FuncTableEntry;\n DWORD Params[4];\n BOOL Far;\n BOOL Virtual;\n DWORD Reserved[3];\n KDHELP KdHelp;\n ADDRESS AddrBStore;\n} STACKFRAME, *LPSTACKFRAME;\nMembers\nx64: The frame pointer is RBP or RDI. This value is not always used.\nAddrStack\nAn ADDRESS structure that specifies the stack pointer.\nx86: The stack pointer is ESP.\nIntel Itanium: The stack pointer is SP.\nx64: The stack pointer is RSP.\nFuncTableEntry\nOn x86 computers, this member is an FPO_DATA structure. If there is no function table entry,\nthis member is NULL.\nParams[4]\nThe possible arguments to the function.\nFar\nThis member is TRUE if this is a WOW far call.\nVirtual\nThis member is TRUE if this is a virtual frame.\nReserved[3]\nThis member is used internally by the StackWalk function.\nKdHelp\nA KDHELP structure that specifies helper data for walking kernel callback frames.\nAddrBStore\nIntel Itanium: An ADDRESS structure that specifies the backing store (RsBSP).\nThis structure supersedes the STACKFRAME structure. For more information, see Updated\nPlatform Support. STACKFRAME is defined as follows in Dbghelp.h.\nC++\nRemarks\nRequirement Value\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nADDRESS\nFPO_DATA\nIMAGE_FUNCTION_ENTRY\nKDHELP\nStackWalk\n#if !defined(_IMAGEHLP_SOURCE_) && defined(_IMAGEHLP64)\n#define STACKFRAME STACKFRAME64\n#define LPSTACKFRAME LPSTACKFRAME64\n#else\ntypedef struct _tagSTACKFRAME {\n ADDRESS AddrPC; // program counter\n ADDRESS AddrReturn; // return address\n ADDRESS AddrFrame; // frame pointer\n ADDRESS AddrStack; // stack pointer\n PVOID FuncTableEntry; // pointer to pdata/fpo or NULL\n DWORD Params[4]; // possible arguments to the function\n BOOL Far; // WOW far call\n BOOL Virtual; // is this a virtual frame?\n DWORD Reserved[3];\n KDHELP KdHelp;\n ADDRESS AddrBStore; // backing store pointer\n} STACKFRAME, *LPSTACKFRAME;\n#endif\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3395,"title":"STACKFRAME_EX structure (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["stackframe","structure","dbghelp","represents","extended","stack","frame","article05","2024","addrpc","address64","that","specifies","the","program","counter","x86","eip","intel","itanium","stiip","x64","rip","addrreturn","return","address","addrframe","pointer","ebp","syntax","typedef","struct","tagstackframe","addrstack","addrbstore","pvoid","functableentry","dword64","params","bool"],"errorCode":"","eventId":"","severity":"Low","summary":"Represents an extended stack frame.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to STACKFRAME_EX structure (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"STACKFRAME_EX structure (dbghelp.h)\nArticle05/29/2024\nRepresents an extended stack frame.\nC++\nAddrPC\nAn ADDRESS64 structure that specifies the program counter.\nx86: The program counter is EIP.\nIntel Itanium: The program counter is StIIP.\nx64: The program counter is RIP.\nAddrReturn\nAn ADDRESS64 structure that specifies the return address.\nAddrFrame\nAn ADDRESS64 structure that specifies the frame pointer.\nx86: The frame pointer is EBP.\nSyntax\ntypedef struct _tagSTACKFRAME_EX {\n ADDRESS64 AddrPC;\n ADDRESS64 AddrReturn;\n ADDRESS64 AddrFrame;\n ADDRESS64 AddrStack;\n ADDRESS64 AddrBStore;\n PVOID FuncTableEntry;\n DWORD64 Params[4];\n BOOL Far;\n BOOL Virtual;\n DWORD64 Reserved[3];\n KDHELP64 KdHelp;\n DWORD StackFrameSize;\n DWORD InlineFrameContext;\n} STACKFRAME_EX, *LPSTACKFRAME_EX;\nMembers\nIntel Itanium: There is no frame pointer, but AddrBStore is used.\nx64: The frame pointer is RBP or RDI. This value is not always used.\nAddrStack\nAn ADDRESS64 structure that specifies the stack pointer.\nx86: The stack pointer is ESP.\nIntel Itanium: The stack pointer is SP.\nx64: The stack pointer is RSP.\nAddrBStore\nIntel Itanium: An ADDRESS64 structure that specifies the backing store (RsBSP).\nFuncTableEntry\nOn x86 computers, this member is an FPO_DATA structure. If there is no function table entry,\nthis member is NULL.\nParams[4]\nThe possible arguments to the function.\nFar\nThis member is TRUE if this is a WOW far call.\nVirtual\nThis member is TRUE if this is a virtual frame.\nReserved[3]\nThis member is used internally by the StackWalk64 function.\nKdHelp\nA KDHELP64 structure that specifies helper data for walking kernel callback frames.\nStackFrameSize\nSet to sizeof(STACKFRAME_EX).\nInlineFrameContext\nSpecifies the type of the inline frame context.\nValue Meaning\nINLINE_FRAME_CONTEXT_INIT\n0\nUnknown.\nINLINE_FRAME_CONTEXT_IGNORE\n0xffffffff\nUnknown.\nThis structure supersedes the STACKFRAME64 structure. For more information, see Updated\nPlatform Support.\nRequirement Value\nHeader dbghelp.h\nRedistributable DbgHelp.dll 6.2 or later\nﾉ Expand table\nRemarks\nRequirements\nﾉ Expand table","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3396,"title":"SYMBOL_INFO structure (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symbol","info","structure","dbghelp","sizeofstruct","the","size","bytes","article02","2023","contains","information","this","member","must","set","sizeof","note","that","total","data","maxnamelen","tchar","reason","subtract","one","first","character","name","accounted","for","typeindex","unique","value","identifies","type","describes","does","not","persist"],"errorCode":"","eventId":"","severity":"Low","summary":"C++\nSizeOfStruct\nThe size of the structure, in bytes.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SYMBOL_INFO structure (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SYMBOL_INFO structure (dbghelp.h)\nArticle02/02/2023\nContains symbol information.\nC++\nSizeOfStruct\nThe size of the structure, in bytes. This member must be set to sizeof(SYMBOL_INFO).\nNote that the total size of the data is the SizeOfStruct + (MaxNameLen - 1) *\nsizeof(TCHAR). The reason to subtract one is that the first character in the name is\naccounted for in the size of the structure.\nTypeIndex\nA unique value that identifies the type data that describes the symbol. This value does\nnot persist between sessions.\nReserved[2]\nThis member is reserved for system use.\nSyntax\ntypedef struct _SYMBOL_INFO {\n ULONG SizeOfStruct;\n ULONG TypeIndex;\n ULONG64 Reserved[2];\n ULONG Index;\n ULONG Size;\n ULONG64 ModBase;\n ULONG Flags;\n ULONG64 Value;\n ULONG64 Address;\n ULONG Register;\n ULONG Scope;\n ULONG Tag;\n ULONG NameLen;\n ULONG MaxNameLen;\n CHAR Name[1];\n} SYMBOL_INFO, *PSYMBOL_INFO;\nMembers\nIndex\nThe unique value for the symbol. The value associated with a symbol is not guaranteed\nto be the same each time you run the process.\nFor PDB symbols, the index value for a symbol is not generated until the symbol is\nenumerated or retrieved through a search by name or address. The index values for all\nCodeView and COFF symbols are generated when the symbols are loaded.\nSize\nThe symbol size, in bytes (or bits, if the symbol is a bitfield member).\nThis value is meaningful only if the module symbols are from a pdb file; otherwise, this\nvalue is typically zero and should be ignored.\nModBase\nThe base address of the module that contains the symbol.\nFlags\nThis member can be one or more of the following values.\nValue Meaning\nSYMFLAG_CLR_TOKEN\n0x00040000\nThe symbol is a CLR token.\nSYMFLAG_CONSTANT\n0x00000100\nThe symbol is a constant.\nSYMFLAG_EXPORT\n0x00000200\nThe symbol is from the export table.\nSYMFLAG_FORWARDER\n0x00000400\nThe symbol is a forwarder.\nSYMFLAG_FRAMEREL\n0x00000020\nOffsets are frame relative.\nSYMFLAG_FUNCTION\n0x00000800\nThe symbol is a known function.\nSYMFLAG_ILREL\n0x00010000\nThe symbol address is an offset relative to the beginning\nof the intermediate language block. This applies to\nmanaged code only.\nﾉ Expand table\nSYMFLAG_LOCAL\n0x00000080\nThe symbol is a local variable.\nSYMFLAG_METADATA\n0x00020000\nThe symbol is managed metadata.\nSYMFLAG_PARAMETER\n0x00000040\nThe symbol is a parameter.\nSYMFLAG_REGISTER\n0x00000008\nThe symbol is a register. The Register member is used.\nSYMFLAG_REGREL\n0x00000010\nOffsets are register relative.\nSYMFLAG_SLOT\n0x00008000\nThe symbol is a managed code slot.\nSYMFLAG_THUNK\n0x00002000\nThe symbol is a thunk.\nSYMFLAG_TLSREL\n0x00004000\nThe symbol is an offset into the TLS data area.\nSYMFLAG_VALUEPRESENT\n0x00000001\nThe Value member is used.\nSYMFLAG_VIRTUAL\n0x00001000\nThe symbol is a virtual symbol created by the\nSymAddSymbol function.\nValue\nThe value of a constant.\nAddress\nThe virtual address of the start of the symbol.\nRegister\nThe register.\nScope\nThe DIA scope. For more information, see the Debug Interface Access SDK in the Visual\nStudio documentation. (This resource may not be available in some languages\nand countries.)\nTag\nFeedback\nWas this page helpful?\nThe PDB classification. These values are defined in Dbghelp.h in the SymTagEnum\nenumeration type.\nNameLen\nThe length of the name, in characters, not including the null-terminating character.\nMaxNameLen\nThe size of the Name buffer, in characters. If this member is 0, the Name member is not\nused.\nName[1]\nThe name of the symbol. The name can be undecorated if the SYMOPT_UNDNAME\noption is used with the SymSetOptions function.\nRequirement Value\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nSymEnumSymbolsProc\nSymFromAddr\nSymFromName\nSymGetTypeFromName\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3397,"title":"SYMSRV_INDEX_INFO structure (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["symsrv","index","info","structure","dbghelp","contains","symbol","server","information","article03","2023","sizeofstruct","the","size","bytes","this","member","must","set","sizeof","infow","file","max","path","name","pdb","dbg","image","stripped","value","that","indicates","whether","timestamp","from","header","used","only","for","files"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains symbol server index information.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SYMSRV_INDEX_INFO structure (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SYMSRV_INDEX_INFO structure\n(dbghelp.h)\nArticle03/13/2023\nContains symbol server index information.\nC++\nsizeofstruct\nThe size of the structure, in bytes. This member must be set to sizeof(SYMSRV_INDEX_INFO) or\nsizeof(SYMSRV_INDEX_INFOW).\nfile[MAX_PATH + 1]\nThe name of the .pdb, .dbg, or image file.\nstripped\nA value that indicates whether the image file is stripped.\ntimestamp\nThe timestamp from the PE header. This member is used only for image files.\nsize\nSyntax\ntypedef struct {\n DWORD sizeofstruct;\n char file[MAX_PATH + 1];\n BOOL stripped;\n DWORD timestamp;\n DWORD size;\n char dbgfile[MAX_PATH + 1];\n char pdbfile[MAX_PATH + 1];\n GUID guid;\n DWORD sig;\n DWORD age;\n} SYMSRV_INDEX_INFO, *PSYMSRV_INDEX_INFO;\nMembers\nThe file size from the PE header. This member is used only for image files.\ndbgfile[MAX_PATH + 1]\nIf the image file is stripped and there is a .dbg file, this member is the path to the .dbg file from\nthe CV record.\npdbfile[MAX_PATH + 1]\nThe .pdb file from the CV record. This member is used only for image and .dbg files.\nguid\nThe GUID of the .pdb file. If there is no GUID available, the signature of the .pdb file is copied\ninto first DWORD of the GUID.\nsig\nThe signature of the .pdb file (for use with old-style .pdb files). This value can be 0 if it is a newstyle .pdb file that uses a GUID-length signature.\nage\nThe age of the .pdb file.\nRequirement Value\nHeader dbghelp.h\nRedistributable DbgHelp.dll 6.6 or later\nSymSrvGetFileIndexInfo\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3398,"title":"TI_FINDCHILDREN_PARAMS structure (dbghelp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["findchildren","params","structure","dbghelp","contains","type","index","information","article02","2024","used","the","symgettypeinfo","function","count","number","children","start","zero","based","child","from","which","indexes","are","retrieved","for","example","array","with","five","elements","two","this","indicates","third","element","most","cases","member"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains type index information.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to TI_FINDCHILDREN_PARAMS structure (dbghelp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"TI_FINDCHILDREN_PARAMS structure\n(dbghelp.h)\nArticle02/22/2024\nContains type index information. It is used by the SymGetTypeInfo function.\nC++\nCount\nThe number of children.\nStart\nThe zero-based index of the child from which the child indexes are to be retrieved. For\nexample, in an array with five elements, if Start is two, this indicates the third array\nelement. In most cases, this member is zero.\nChildId[1]\nAn array of type indexes. There is one index per child.\nRequirement Value\nHeader dbghelp.h\nRedistributable DbgHelp.dll 5.1 or later\nSyntax\ntypedef struct _TI_FINDCHILDREN_PARAMS {\n ULONG Count;\n ULONG Start;\n ULONG ChildId[1];\n} TI_FINDCHILDREN_PARAMS;\nMembers\nRequirements\nﾉ Expand table\nFeedback\nWas this page helpful?\nSymGetTypeInfo\nSee also\nYes No\nImage Help Library\nThis overview describes the function set provided by the ImageHlp DLL. These functions allow\nyou to work with a portable executable (PE) image.\nAbout ImageHlp\nImageHlp Reference\nYou cannot redistribute the ImageHlp DLL that is included with the operating system. A subset\nof the functions are included in the Debug Help Library, which is restributable.\n \n \nLast updated on 07/14/2025\nAbout ImageHlp\nThe ImageHlp functions are used mostly by programming tools, application setup utilities, and\nother programs that need access to the data contained in a PE image. All ImageHlp functions\nare single threaded. Therefore, calls from more than one thread to this function will likely result\nin unexpected behavior or memory corruption. To avoid this, you must synchronize all\nconcurrent calls from more than one thread to this function.\nThe following topics describe PE images and the functionality provided by the ImageHlp\nfunctions.\nPE Format\nImage Access Functions\nImage Integrity Functions\nImage Modification Functions\n \n \nLast updated on 07/14/2025\nPE Format\nThis specification describes the structure of executable (image) files and object files under the\nWindows family of operating systems. These files are referred to as Portable Executable (PE)\nand Common Object File Format (COFF) files, respectively.\nThis revision of the Microsoft Portable Executable and Common Object File Format\nSpecification replaces all previous revisions of this specification.\nThis document specifies the structure of executable (image) files and object files under the\nMicrosoft Windows family of operating systems. These files are referred to as Portable\nExecutable (PE) and Common Object File Format (COFF) files, respectively. The name \"Portable\nExecutable\" refers to the fact that the format is not architecture specific.\nCertain concepts that appear throughout this specification are described in the following table:\nName Description\nattribute\ncertificate\nA certificate that is used to associate verifiable statements with an image. A number of\ndifferent verifiable statements can be associated with a file; one of the most useful ones is a\nstatement by a software manufacturer that indicates what the message digest of the image\nis expected to be. A message digest is similar to a checksum except that it is extremely\ndifficult to forge. Therefore, it is very difficult to modify a file to have the same message\ndigest as the original file. The statement can be verified as being made by the manufacturer\nby using public or private key cryptography schemes. This document describes details\nabout attribute certificates other than to allow for their insertion into image files.\ndate/time\nstamp\nA stamp that is used for different purposes in several places in a PE or COFF file. In most\ncases, the format of each stamp is the same as that used by the time functions in the C runtime library. For exceptions, see the descripton of IMAGE_DEBUG_TYPE_REPRO in Debug\nType. If the stamp value is 0 or 0xFFFFFFFF, it does not represent a real or meaningful\ndate/time stamp.\n７ Note\nThis document is provided to aid in the development of tools and applications for\nWindows but is not guaranteed to be a complete specification in all respects. Microsoft\nreserves the right to alter this document without notice.\nGeneral Concepts\nﾉ Expand table\nName Description\nfile pointerThe location of an item within the file itself, before being processed by the linker (in the\ncase of object files) or the loader (in the case of image files). In other words, this is a\nposition within the file as stored on disk.\nlinker A reference to the linker that is provided with Microsoft Visual Studio.\nobject file A file that is given as input to the linker. The linker produces an image file, which in turn is\nused as input by the loader. The term \"object file\" does not necessarily imply any\nconnection to object-oriented programming.\nreserved,\nmust be 0\nA description of a field that indicates that the value of the field must be zero for generators\nand consumers must ignore the field.\nRelative\nvirtual\naddress\n(RVA)\nIn an image file, this is the address of an item after it is loaded into memory, with the base\naddress of the image file subtracted from it. The RVA of an item almost always differs from\nits position within the file on disk (file pointer).\nIn an object file, an RVA is less meaningful because memory locations are not assigned. In\nthis case, an RVA would be an address within a section (described later in this table), to\nwhich a relocation is later applied during linking. For simplicity, a compiler should just set\nthe first RVA in each section to zero.\nsection The basic unit of code or data within a PE or COFF file. For example, all code in an object file\ncan be combined within a single section or (depending on compiler behavior) each function\ncan occupy its own section. With more sections, there is more file overhead, but the linker is\nable to link in code more selectively. A section is similar to a segment in Intel 8086\narchitecture. All the raw data in a section must be loaded contiguously. In addition, an\nimage file can contain a number of sections, such as .tls or .reloc , which have special\npurposes.\nVirtual\nAddress\n(","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3399,"title":"BindImage function (imagehlp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["bindimage","function","imagehlp","computes","the","virtual","address","each","imported","article10","2021","this","has","been","superseded","bindimageex","use","provide","status","routine","flags","control","image","binding","imagename","name","file","bound","value","can","partial","path","full","dllpath","root","search","specified","parameter","cannot","opened"],"errorCode":"","eventId":"","severity":"Low","summary":"Computes the virtual address of each imported function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to BindImage function (imagehlp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"BindImage function (imagehlp.h)\nArticle10/13/2021\nComputes the virtual address of each imported function.\nThis function has been superseded by the BindImageEx function. Use BindImageEx to provide\na status routine or flags to control the image binding.\nC++\n[in] ImageName\nThe name of the file to be bound. This value can be a file name, a partial path, or a full path.\n[in] DllPath\nThe root of the search path to use if the file specified by the ImageName parameter cannot be\nopened.\n[in] SymbolPath\nThe root of the path to search for the file's corresponding symbol file.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nSyntax\nBOOL IMAGEAPI BindImage(\n [in] PCSTR ImageName,\n [in] PCSTR DllPath,\n [in] PCSTR SymbolPath\n);\nParameters\nReturn value\nRemarks\nA call to BindImage is equivalent to the following call: BindImageEx( 0, ImageName, DllPath,\nSymbolPath, NULL );\nAll ImageHlp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader imagehlp.h\nLibrary Imagehlp.lib\nDLL Imagehlp.dll\nBindImageEx\nImageHlp Functions\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3400,"title":"BindImageEx function (imagehlp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["bindimageex","function","imagehlp","computes","the","virtual","address","each","that","imported","article10","2021","flags","bind","options","this","parameter","can","combination","following","values","value","meaning","all","images","0x00000004","call","tree","for","file","cache","import","dlls","0x00000008","not","discard","dll","information","between","calls"],"errorCode":"","eventId":"","severity":"Low","summary":"Computes the virtual address of each function that is imported.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to BindImageEx function (imagehlp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"BindImageEx function (imagehlp.h)\nArticle10/13/2021\nComputes the virtual address of each function that is imported.\nC++\n[in] Flags\nThe bind options. This parameter can be a combination of the following values.\nValue Meaning\nBIND_ALL_IMAGES\n0x00000004\nBind all images in the call tree for this file.\nBIND_CACHE_IMPORT_DLLS\n0x00000008\nDo not discard DLL information in the cache between calls.\nThis improves performance when binding a large number of\nimages.\nBIND_NO_BOUND_IMPORTS\n0x00000001\nDo not generate a new import address table.\nBIND_NO_UPDATE\n0x00000002\nDo not make changes to the file.\n[in] ImageName\nThe name of the file to be bound. This value can be a file name, a partial path, or a full path.\n[in] DllPath\nSyntax\nBOOL IMAGEAPI BindImageEx(\n [in] DWORD Flags,\n [in] PCSTR ImageName,\n [in] PCSTR DllPath,\n [in] PCSTR SymbolPath,\n [in] PIMAGEHLP_STATUS_ROUTINE StatusRoutine\n);\nParameters\nﾉ Expand table\nThe root of the search path to use if the file specified by the ImageName parameter cannot be\nopened.\n[in] SymbolPath\nThe root of the path to search for the file's corresponding symbol file.\n[in] StatusRoutine\nA pointer to a status routine. The status routine is called during the progress of the image\nbinding. For more information, see StatusRoutine.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe process of binding an image consists of computing the virtual address of each imported\nfunction. The computed virtual address is then saved in the importing image's Import Address\nTable (IAT). As a result, the image is loaded much faster, particularly if it uses many DLLs,\nbecause the system loader does not have to compute the address of each imported function.\nIf a corresponding symbol file can be located, its time stamp and checksum are updated.\nAll ImageHlp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nRequirement Value\nTarget Platform Windows\nHeader imagehlp.h\nLibrary Imagehlp.lib\nDLL Imagehlp.dll\nImageHlp Functions\nStatusRoutine\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3401,"title":"CheckSumMappedFile function (imagehlp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["checksummappedfile","function","imagehlp","computes","the","checksum","specified","image","file","article10","2021","baseaddress","base","address","mapped","this","value","obtained","calling","mapviewoffile","filelength","size","bytes","out","headersum","pointer","variable","that","receives","original","from","zero","there","error","computed","succeeds","return","headers","structure","contained"],"errorCode":"","eventId":"","severity":"Low","summary":"Computes the checksum of the specified image file.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to CheckSumMappedFile function (imagehlp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"CheckSumMappedFile function\n(imagehlp.h)\nArticle10/13/2021\nComputes the checksum of the specified image file.\nC++\n[in] BaseAddress\nThe base address of the mapped file. This value is obtained by calling the MapViewOfFile\nfunction.\n[in] FileLength\nThe size of the file, in bytes.\n[out] HeaderSum\nA pointer to a variable that receives the original checksum from the image file, or zero if there\nis an error.\n[out] CheckSum\nA pointer to the variable that receives the computed checksum.\nIf the function succeeds, the return value is a pointer to the IMAGE_NT_HEADERS structure\ncontained in the mapped image.\nSyntax\nPIMAGE_NT_HEADERS IMAGEAPI CheckSumMappedFile(\n [in] PVOID BaseAddress,\n [in] DWORD FileLength,\n [out] PDWORD HeaderSum,\n [out] PDWORD CheckSum\n);\nParameters\nReturn value\nIf the function fails, the return value is NULL. To retrieve extended error information, call\nGetLastError.\nThe CheckSumMappedFile function computes a new checksum for the file and returns it in the\nCheckSum parameter. This function is used by any application that creates or modifies an\nexecutable image. Checksums are required for kernel-mode drivers and some system DLLs. The\nlinker computes the original checksum at link time, if you use the appropriate linker switch. For\nmore details, see your linker documentation.\nIt is recommended that all images have valid checksums. It is the caller's responsibility to place\nthe newly computed checksum into the mapped image and update the on-disk image of the\nfile.\nAll ImageHlp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader imagehlp.h\nLibrary Imagehlp.lib\nDLL Imagehlp.dll\nIMAGE_NT_HEADERS\nImageHlp Functions\nRemarks\nRequirements\nﾉ Expand table\nSee also\nMapFileAndCheckSum\nMapViewOfFile","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3402,"title":"DIGEST_FUNCTION callback function (imagehlp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["digest","function","callback","imagehlp","application","defined","used","the","imagegetdigeststream","process","data","article02","2024","type","defines","pointer","this","digestfunction","placeholder","for","name","refdata","user","supplied","handle","value","passed","parameter","pdata","stream","dwlength","size","bytes","succeeds","return","should","true","fails","false","syntax"],"errorCode":"","eventId":"","severity":"Low","summary":"An application-defined callback function used by the ImageGetDigestStream function to\nprocess data.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to DIGEST_FUNCTION callback function (imagehlp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"DIGEST_FUNCTION callback function\n(imagehlp.h)\nArticle02/22/2024\nAn application-defined callback function used by the ImageGetDigestStream function to\nprocess data.\nThe DIGEST_FUNCTION type defines a pointer to this callback function. DigestFunction is a\nplaceholder for the application-defined function name.\nC++\n[in] refdata\nA user-supplied handle to the digest. This value is passed as a parameter to the\nImageGetDigestStream function.\n[in] pData\nThe data stream.\n[in] dwLength\nThe size of the data stream, in bytes.\nIf the function succeeds, the return value should be TRUE. If the function fails, the return value\nshould be FALSE.\nSyntax\nDIGEST_FUNCTION DigestFunction;\nBOOL DigestFunction(\n [in] DIGEST_HANDLE refdata,\n [in] PBYTE pData,\n [in] DWORD dwLength\n)\n{...}\nParameters\nReturn value\nAll ImageHlp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader imagehlp.h\nImageGetDigestStream\nImageHlp Functions\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3403,"title":"GetImageConfigInformation function (imagehlp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["getimageconfiginformation","function","imagehlp","locates","and","returns","the","load","configuration","data","image","article02","2024","loadedimage","pointer","loaded","structure","that","returned","from","call","mapandload","imageload","out","imageconfiginformation","config","directory","receives","information","win64","defined","then","directory64","however","not","directory32","succeeds","return","value","true"],"errorCode":"","eventId":"","severity":"Low","summary":"Locates and returns the load configuration data of an image.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to GetImageConfigInformation function (imagehlp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"GetImageConfigInformation function\n(imagehlp.h)\nArticle02/22/2024\nLocates and returns the load configuration data of an image.\nC++\n[in] LoadedImage\nA pointer to a LOADED_IMAGE structure that is returned from a call to MapAndLoad or\nImageLoad.\n[out] ImageConfigInformation\nA pointer to an IMAGE_LOAD_CONFIG_DIRECTORY structure that receives the configuration\ninformation.\nIf _WIN64 is defined, then IMAGE_LOAD_CONFIG_DIRECTORY is defined as\nIMAGE_LOAD_CONFIG_DIRECTORY64. However, if _WIN64 is not defined, then\nIMAGE_LOAD_CONFIG_DIRECTORY is defined as IMAGE_LOAD_CONFIG_DIRECTORY32.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nSyntax\nBOOL IMAGEAPI GetImageConfigInformation(\n [in] PLOADED_IMAGE LoadedImage,\n [out] PIMAGE_LOAD_CONFIG_DIRECTORY ImageConfigInformation\n);\nParameters\nReturn value\nRemarks\nThe SetImageConfigInformation function locates and changes the load configuration data of\nan image.\nAll ImageHlp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader imagehlp.h\nLibrary Imagehlp.lib\nDLL Imagehlp.dll\nImageHlp Functions LOADED_IMAGE SetImageConfigInformation\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3404,"title":"GetImageUnusedHeaderBytes function (imagehlp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["getimageunusedheaderbytes","function","imagehlp","retrieves","the","offset","and","size","part","header","that","currently","unused","article02","2024","loadedimage","pointer","loaded","image","structure","returned","from","call","mapandload","imageload","out","sizeunusedheaderbytes","variable","receive","bytes","which","succeeds","return","value","base","address","first","byte","fails","zero"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the offset and size of the part of the PE header that is currently unused.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to GetImageUnusedHeaderBytes function (imagehlp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"GetImageUnusedHeaderBytes function\n(imagehlp.h)\nArticle02/22/2024\nRetrieves the offset and size of the part of the PE header that is currently unused.\nC++\n[in] LoadedImage\nA pointer to a LOADED_IMAGE structure that is returned from a call to MapAndLoad or\nImageLoad.\n[out] SizeUnusedHeaderBytes\nA pointer to a variable to receive the size, in bytes, of the part of the image's header which is\nunused.\nIf the function succeeds, the return value is the offset from the base address of the first unused\nheader byte.\nIf the function fails, the return value is zero. To retrieve extended error information, call\nGetLastError.\nAll ImageHlp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\nSyntax\nDWORD IMAGEAPI GetImageUnusedHeaderBytes(\n [in] PLOADED_IMAGE LoadedImage,\n [out] PDWORD SizeUnusedHeaderBytes\n);\nParameters\nReturn value\nRemarks\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader imagehlp.h\nLibrary Imagehlp.lib\nDLL Imagehlp.dll\nImageHlp Functions\nLOADED_IMAGE\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3405,"title":"ImageAddCertificate function (imagehlp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["imageaddcertificate","function","imagehlp","adds","certificate","the","specified","file","article02","2024","filehandle","handle","image","modified","this","must","opened","for","read","data","and","write","access","pointer","win","header","all","associated","sections","length","member","will","used","determine","buffer","out","index","variable","that","receives"],"errorCode":"","eventId":"","severity":"Low","summary":"Adds a certificate to the specified file.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to ImageAddCertificate function (imagehlp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"ImageAddCertificate function (imagehlp.h)\nArticle02/22/2024\nAdds a certificate to the specified file.\nC++\n[in] FileHandle\nA handle to the image file to be modified. This handle must be opened for FILE_READ_DATA\nand FILE_WRITE_DATA access.\n[in] Certificate\nA pointer to a WIN_CERTIFICATE header and all associated sections. The Length member in\nthe certificate header will be used to determine the length of this buffer.\n[out] Index\nA pointer to a variable that receives the index of the newly added certificate.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe certificate is added at the end of the existing list of certificates and is assigned an index.\nSyntax\nBOOL IMAGEAPI ImageAddCertificate(\n [in] HANDLE FileHandle,\n [in] LPWIN_CERTIFICATE Certificate,\n [out] PDWORD Index\n);\nParameters\nReturn value\nRemarks\nAll ImageHlp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader imagehlp.h\nLibrary Imagehlp.lib\nDLL Imagehlp.dll\nImageHlp Functions\nImageRemoveCertificate\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3406,"title":"ImageEnumerateCertificates function (imagehlp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["imageenumeratecertificates","function","imagehlp","retrieves","information","about","the","certificates","currently","contained","image","file","article10","2021","filehandle","handle","examined","this","must","opened","for","read","data","access","typefilter","certificate","section","type","used","filter","when","returning","cert","any","should","passed","all","types","present","out"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves information about the certificates currently contained in an image file.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to ImageEnumerateCertificates function (imagehlp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"ImageEnumerateCertificates function\n(imagehlp.h)\nArticle10/13/2021\nRetrieves information about the certificates currently contained in an image file.\nC++\n[in] FileHandle\nA handle to the image file to be examined. This handle must be opened for FILE_READ_DATA\naccess.\n[in] TypeFilter\nThe certificate section type to be used as a filter when returning certificate information.\nCERT_SECTION_TYPE_ANY should be passed for information on all section types present in the\nimage.\n[out] CertificateCount\nA pointer to a variable that receives the number of certificates in the image containing sections\nof the type specified by the TypeFilter parameter. If none are found, this parameter is zero.\n[in, out] Indices\nOptionally provides a buffer to use to return an array of indices to the certificates containing\nsections of the specified type. No ordering should be assumed for the index values, nor are\nthey guaranteed to be contiguous when CERT_SECTION_TYPE_ANY is queried.\n[in, optional] IndexCount\nSyntax\nBOOL IMAGEAPI ImageEnumerateCertificates(\n [in] HANDLE FileHandle,\n [in] WORD TypeFilter,\n [out] PDWORD CertificateCount,\n [in, out] PDWORD Indices,\n [in, optional] DWORD IndexCount\n);\nParameters\nThe size of the Indices buffer, in DWORDs. This parameter will be examined whenever Indices is\npresent. If CertificateCount is greater than IndexCount, Indices will be filled in with the first\nIndexCount sections found in the image; any others will not be returned.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe ImageEnumerateCertificates function returns information about the certificates currently\ncontained in an image file. It has filtering capabilities which allow certificates containing\nsections of any single type (or of any type) to be returned.\nAfter the indices of interesting certificates are discovered, they can be passed to the\nImageGetCertificateData function to obtain the actual bodies of the certificates.\nAll ImageHlp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader imagehlp.h\nLibrary Imagehlp.lib\nDLL Imagehlp.dll\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nImageGetCertificateData\nImageHlp Functions\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3407,"title":"ImageGetCertificateData function (imagehlp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["imagegetcertificatedata","function","imagehlp","retrieves","complete","certificate","from","file","article02","2024","filehandle","handle","the","image","this","must","opened","for","read","data","access","certificateindex","index","returned","out","pointer","win","structure","that","receives","buffer","not","large","enough","contain","fails","and","last","error","code"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves a complete certificate from a file.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to ImageGetCertificateData function (imagehlp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"ImageGetCertificateData function\n(imagehlp.h)\nArticle02/22/2024\nRetrieves a complete certificate from a file.\nC++\n[in] FileHandle\nA handle to the image file. This handle must be opened for FILE_READ_DATA access.\n[in] CertificateIndex\nThe index of the certificate to be returned.\n[out] Certificate\nA pointer to a WIN_CERTIFICATE structure that receives the certificate data. If the buffer is not\nlarge enough to contain the structure, the function fails and the last error code is set to\nERROR_INSUFFICIENT_BUFFER.\n[in, out] RequiredLength\nOn input, this parameter specifies the length of the Certificate buffer in bytes. On success, it\nreceives the length of the certificate.\nIf the function succeeds, the return value is TRUE.\nSyntax\nBOOL IMAGEAPI ImageGetCertificateData(\n [in] HANDLE FileHandle,\n [in] DWORD CertificateIndex,\n [out] LPWIN_CERTIFICATE Certificate,\n [in, out] PDWORD RequiredLength\n);\nParameters\nReturn value\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe WIN_CERTIFICATE structure is defined as follows:\nC++\nAll ImageHlp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader imagehlp.h\nLibrary Imagehlp.lib\nDLL Imagehlp.dll\nImageHlp Functions\nRemarks\ntypedef struct _WIN_CERTIFICATE {\n DWORD dwLength;\n WORD wRevision;\n WORD wCertificateType; // WIN_CERT_TYPE_xxx\n BYTE bCertificate[ANYSIZE_ARRAY];\n} WIN_CERTIFICATE, *LPWIN_CERTIFICATE;\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3408,"title":"ImageGetCertificateHeader function (imagehlp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["imagegetcertificateheader","function","imagehlp","retrieves","the","header","specified","certificate","but","not","including","section","offset","array","article02","2024","filehandle","handle","image","file","this","must","opened","for","read","data","access","certificateindex","index","whose","returned","out","certificateheader","pointer","win","structure","that","receives","succeeds","return"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the header of the specified certificate, up to, but not including, the section offset\narray.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to ImageGetCertificateHeader function (imagehlp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"ImageGetCertificateHeader function\n(imagehlp.h)\nArticle02/22/2024\nRetrieves the header of the specified certificate, up to, but not including, the section offset\narray.\nC++\n[in] FileHandle\nA handle to the image file. This handle must be opened for FILE_READ_DATA access.\n[in] CertificateIndex\nThe index of the certificate whose header is to be returned.\n[in, out] Certificateheader\nA pointer to the WIN_CERTIFICATE structure that receives the certificate header.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nSyntax\nBOOL IMAGEAPI ImageGetCertificateHeader(\n [in] HANDLE FileHandle,\n [in] DWORD CertificateIndex,\n [in, out] LPWIN_CERTIFICATE Certificateheader\n);\nParameters\nReturn value\nRemarks\nAll ImageHlp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader imagehlp.h\nLibrary Imagehlp.lib\nDLL Imagehlp.dll\nImageHlp Functions\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3409,"title":"ImageGetDigestStream function (imagehlp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["imagegetdigeststream","function","imagehlp","retrieves","the","requested","data","from","specified","image","file","article10","2021","filehandle","handle","this","must","opened","for","read","access","digestlevel","aspects","that","are","included","returned","stream","parameter","can","one","more","following","values","value","meaning","cert","digest","all","import"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the requested data from the specified image file.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to ImageGetDigestStream function (imagehlp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"ImageGetDigestStream function\n(imagehlp.h)\nArticle10/13/2021\nRetrieves the requested data from the specified image file.\nC++\n[in] FileHandle\nA handle to the image file. This handle must be opened for FILE_READ_DATA access.\n[in] DigestLevel\nThe aspects of the image that are to be included in the returned data stream. This parameter\ncan be one or more of the following values.\nValue Meaning\nCERT_PE_IMAGE_DIGEST_ALL_IMPORT_INFO\n0x04\nInclude all import information.\nCERT_PE_IMAGE_DIGEST_DEBUG_INFO\n0x01\nInclude symbolic debugging information.\nCERT_PE_IMAGE_DIGEST_RESOURCES\n0x02\nInclude resource information.\n[in] DigestFunction\nA pointer to a callback routine to process the data. For more information, see DigestFunction.\nSyntax\nBOOL IMAGEAPI ImageGetDigestStream(\n [in] HANDLE FileHandle,\n [in] DWORD DigestLevel,\n [in] DIGEST_FUNCTION DigestFunction,\n [in] DIGEST_HANDLE DigestHandle\n);\nParameters\nﾉ Expand table\n[in] DigestHandle\nA user-supplied handle to the digest. This parameter is passed to DigestFunction as the first\nargument.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe ImageGetDigestStream function returns the data to be digested from a specified image\nfile, subject to the passed DigestLevel parameter. The order of the bytes will be consistent for\ndifferent calls, which is required to ensure that the same message digest is always produced\nfrom the retrieved byte stream.\nTo ensure cross-platform compatibility, all implementations of this function must behave in a\nconsistent manner with respect to the order in which the various parts of the image file are\nreturned.\nData should be returned in the following order:\n1. Image (executable and static data) information.\n2. Resource data.\n3. Debugging information.\nIf any of these are not specified, the remaining parts must be returned in the same order.\nAll ImageHlp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader imagehlp.h\nLibrary Imagehlp.lib\nDLL Imagehlp.dll\nImageHlp Functions\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3410,"title":"ImageLoad function (imagehlp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["imageload","function","imagehlp","maintains","list","loaded","dlls","article02","2024","dllname","the","name","image","dllpath","path","used","locate","provided","cannot","found","null","then","search","rules","set","forth","searchpath","apply","succeeds","return","value","pointer","structure","fails","retrieve","extended","error","information","call","getlasterror"],"errorCode":"","eventId":"","severity":"Low","summary":"Maintains a list of loaded DLLs.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to ImageLoad function (imagehlp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"ImageLoad function (imagehlp.h)\nArticle02/22/2024\nMaintains a list of loaded DLLs.\nC++\n[in] DllName\nThe name of the image.\n[in] DllPath\nThe path used to locate the image if the name provided cannot be found. If NULL is used, then\nthe search path rules set forth in the SearchPath function apply.\nIf the function succeeds, the return value is a pointer to a LOADED_IMAGE structure.\nIf the function fails, the return value is NULL. To retrieve extended error information, call\nGetLastError.\nThe ImageLoad function is used to maintain a list of loaded DLLs. If the image has already\nbeen loaded, the prior LOADED_IMAGE is returned. Otherwise, the new image is added to the\nlist.\nThe LOADED_IMAGE structure must be deallocated by the ImageUnload function.\nAll ImageHlp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\nSyntax\nPLOADED_IMAGE IMAGEAPI ImageLoad(\n [in] PCSTR DllName,\n [in] PCSTR DllPath\n);\nParameters\nReturn value\nRemarks\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader imagehlp.h\nLibrary Imagehlp.lib\nDLL Imagehlp.dll\nImageHlp Functions\nImageUnload\nLOADED_IMAGE\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3411,"title":"ImageRemoveCertificate function (imagehlp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["imageremovecertificate","function","imagehlp","removes","the","specified","certificate","from","given","file","article02","2024","filehandle","handle","image","modified","this","must","opened","for","read","data","and","write","access","index","removed","succeeds","return","value","true","fails","false","retrieve","extended","error","information","call","getlasterror","all"],"errorCode":"","eventId":"","severity":"Low","summary":"Removes the specified certificate from the given file.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to ImageRemoveCertificate function (imagehlp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"ImageRemoveCertificate function\n(imagehlp.h)\nArticle02/22/2024\nRemoves the specified certificate from the given file.\nC++\n[in] FileHandle\nA handle to the image file to be modified. This handle must be opened for FILE_READ_DATA\nand FILE_WRITE_DATA access.\n[in] Index\nThe index of the certificate to be removed.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nAll ImageHlp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nSyntax\nBOOL IMAGEAPI ImageRemoveCertificate(\n [in] HANDLE FileHandle,\n [in] DWORD Index\n);\nParameters\nReturn value\nRemarks\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader imagehlp.h\nLibrary Imagehlp.lib\nDLL Imagehlp.dll\nImageAddCertificate\nImageHlp Functions\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3412,"title":"ImageUnload function (imagehlp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["imageunload","function","imagehlp","deallocates","resources","from","previous","call","the","imageload","article02","2024","loadedimage","pointer","loaded","image","structure","that","returned","succeeds","return","value","true","fails","false","retrieve","extended","error","information","getlasterror","and","share","internal","data","can","corrupted","multiple","consecutive","calls","are"],"errorCode":"","eventId":"","severity":"Low","summary":"Deallocates resources from a previous call to the ImageLoad function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to ImageUnload function (imagehlp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"ImageUnload function (imagehlp.h)\nArticle02/22/2024\nDeallocates resources from a previous call to the ImageLoad function.\nC++\n[in] LoadedImage\nA pointer to a LOADED_IMAGE structure that is returned from a call to the ImageLoad function.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nImageLoad and ImageUnload share internal data that can be corrupted if multiple consecutive\ncalls to ImageLoad are performed. Therefore, make sure that you have called ImageLoad only\nonce before calling ImageUnload.\nAll ImageHlp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nSyntax\nBOOL IMAGEAPI ImageUnload(\n [in] PLOADED_IMAGE LoadedImage\n);\nParameters\nReturn value\nRemarks\nRequirements\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader imagehlp.h\nLibrary Imagehlp.lib\nDLL Imagehlp.dll\nImageHlp Functions\nImageLoad\nLOADED_IMAGE\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3413,"title":"MapAndLoad function (imagehlp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["mapandload","function","imagehlp","maps","image","and","preloads","data","from","the","mapped","file","article10","2021","imagename","name","executable","dll","that","loaded","dllpath","path","used","locate","provided","cannot","found","this","parameter","null","then","search","rules","set","using","searchpath","apply","out","loadedimage","pointer"],"errorCode":"","eventId":"","severity":"Low","summary":"Maps an image and preloads data from the mapped file.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MapAndLoad function (imagehlp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MapAndLoad function (imagehlp.h)\nArticle10/13/2021\nMaps an image and preloads data from the mapped file.\nC++\n[in] ImageName\nThe file name of the image (executable file or DLL) that is loaded.\n[in] DllPath\nThe path used to locate the image if the name provided cannot be found. If this parameter is\nNULL, then the search path rules set using the SearchPath function apply.\n[out] LoadedImage\nA pointer to a LOADED_IMAGE structure that receives information about the image after it is\nloaded.\n[in] DotDll\nThe default extension to be used if the image name does not contain a file name extension. If\nthe value is TRUE, a .DLL extension is used. If the value is FALSE, then an .EXE extension is used.\n[in] ReadOnly\nThe access mode. If this value is TRUE, the file is mapped for read-access only. If the value is\nFALSE, the file is mapped for read and write access.\nSyntax\nBOOL IMAGEAPI MapAndLoad(\n [in] PCSTR ImageName,\n [in] PCSTR DllPath,\n [out] PLOADED_IMAGE LoadedImage,\n [in] BOOL DotDll,\n [in] BOOL ReadOnly\n);\nParameters\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe MapAndLoad function maps an image and preloads data from the mapped file. The\ncorresponding function, UnMapAndLoad, must be used to deallocate all resources that are\nallocated by the MapAndLoad function.\nAll ImageHlp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader imagehlp.h\nLibrary Imagehlp.lib\nDLL Imagehlp.dll\nImageHlp Functions\nLOADED_IMAGE\nUnMapAndLoad\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3414,"title":"MapFileAndCheckSumA function (imagehlp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["mapfileandchecksuma","function","imagehlp","computes","the","checksum","specified","file","article02","2023","filename","name","for","which","computed","out","headersum","pointer","variable","that","receives","original","from","image","zero","there","error","succeeds","return","value","success","fails","one","following","code","description","map","failure","could","not"],"errorCode":"","eventId":"","severity":"Low","summary":"Computes the checksum of the specified file.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to MapFileAndCheckSumA function (imagehlp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"MapFileAndCheckSumA function\n(imagehlp.h)\nArticle02/09/2023\nComputes the checksum of the specified file.\nC++\n[in] Filename\nThe file name of the file for which the checksum is to be computed.\n[out] HeaderSum\nA pointer to a variable that receives the original checksum from the image file, or zero if there\nis an error.\n[out] CheckSum\nA pointer to a variable that receives the computed checksum.\nIf the function succeeds, the return value is CHECKSUM_SUCCESS (0).\nIf the function fails, the return value is one of the following.\nReturn code/value Description\nCHECKSUM_MAP_FAILURE Could not map the file.\nSyntax\nDWORD IMAGEAPI MapFileAndCheckSumA(\n [in] PCSTR Filename,\n [out] PDWORD HeaderSum,\n [out] PDWORD CheckSum\n);\nParameters\nReturn value\nﾉ Expand table\n2\nCHECKSUM_MAPVIEW_FAILURE\n3\nCould not map a view of the file.\nCHECKSUM_OPEN_FAILURE\n1\nCould not open the file.\nCHECKSUM_UNICODE_FAILURE\n4\nCould not convert the file name to Unicode.\nThe MapFileAndCheckSum function computes a new checksum for the file and returns it in the\nCheckSum parameter. This function is used by any application that creates or modifies an\nexecutable image. Checksums are required for kernel-mode drivers and some system DLLs. The\nlinker computes the original checksum at link time, if you use the appropriate linker switch. For\nmore details, see your linker documentation.\nIt is recommended that all images have valid checksums. It is the caller's responsibility to place\nthe newly computed checksum into the mapped image and update the on-disk image of the\nfile.\nPassing a Filename parameter that does not point to a valid executable image will produce\nunpredictable results. Any user of this function is encouraged to make sure that a valid\nexecutable image is being passed.\nAll ImageHlp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\n \nRemarks\nNote The Unicode implementation of this function calls the ASCII implementation and as\na result, the function can fail if the codepage does not support the characters in the path.\nFor example, if you pass a non-English Unicode file path, and the default codepage is\nEnglish, the unrecognized non-English wide chars are converted to \"??\" and the file cannot\nbe opened (the function returns CHECKSUM_OPEN_FAILURE).\n７ Note\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader imagehlp.h\nLibrary Imagehlp.lib\nDLL Imagehlp.dll\nCheckSumMappedFile\nImageHlp Functions\nThe imagehlp.h header defines MapFileAndCheckSum as an alias that automatically\nselects the ANSI or Unicode version of this function based on the definition of the\nUNICODE preprocessor constant. Mixing usage of the encoding-neutral alias with code\nthat is not encoding-neutral can lead to mismatches that result in compilation or runtime\nerrors. For more information, see Conventions for Function Prototypes.\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3415,"title":"ReBaseImage function (imagehlp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["rebaseimage","function","imagehlp","changes","the","load","address","for","specified","image","which","reduces","required","time","dll","article07","2022","alternatively","you","can","use","rebase","tool","this","available","visual","studio","and","windows","sdk","note","that","implemented","call","rebaseimage64","currentimagename","name","file","rebased","must"],"errorCode":"","eventId":"","severity":"Low","summary":"Changes the load address for the specified image, which reduces the required load time for a\nDLL.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to ReBaseImage function (imagehlp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"ReBaseImage function (imagehlp.h)\nArticle07/27/2022\nChanges the load address for the specified image, which reduces the required load time for a\nDLL.\nAlternatively, you can use the Rebase tool. This tool is available in Visual Studio and the\nWindows SDK.\nNote that this function is implemented as a call to the ReBaseImage64 function.\nC++\n[in] CurrentImageName\nThe name of the file to be rebased. You must specify the full path to the file unless the module\nis in the current working directory of the calling process.\n[in] SymbolPath\nThe path used to find the corresponding symbol file. Specify this path for executable images\nthat have symbolic information because when image addresses change, the corresponding\nsymbol database file (PDB) may also need to be changed. Note that even if the symbol path is\nnot valid, the function will succeed if it is able to rebases your image.\n[in] fReBase\nSyntax\nBOOL IMAGEAPI ReBaseImage(\n [in] PCSTR CurrentImageName,\n [in] PCSTR SymbolPath,\n [in] BOOL fReBase,\n [in] BOOL fRebaseSysfileOk,\n [in] BOOL fGoingDown,\n [in] ULONG CheckImageSize,\n [out] ULONG *OldImageSize,\n [out] ULONG_PTR *OldImageBase,\n [out] ULONG *NewImageSize,\n [in, out] ULONG_PTR *NewImageBase,\n [in] ULONG TimeStamp\n);\nParameters\nIf this value is TRUE, the image is rebased. Otherwise, the image is not rebased.\n[in] fRebaseSysfileOk\nIf this value is TRUE, the system image is rebased. Otherwise, the system image is not rebased.\n[in] fGoingDown\nIf this value is TRUE, the image can be rebased below the given base; otherwise, it cannot.\n[in] CheckImageSize\nThe maximum size that the image can grow to, in bytes, or zero if there is no limit.\n[out] OldImageSize\nA pointer to a variable that receives the original image size, in bytes.\n[out] OldImageBase\nA pointer to a variable that receives the original image base.\n[out] NewImageSize\nA pointer to a variable that receives the new image size after the rebase operation, in bytes.\n[in, out] NewImageBase\nThe base address to use for rebasing the image. If the address is not available and the\nfGoingDown parameter is set to TRUE, the function finds a new base address and sets this\nparameter to the new base address. If fGoingDown is FALSE, the function finds a new base\naddress but does not set this parameter to the new base address.\n[in] TimeStamp\nThe new time date stamp for the image file header. The value must be represented in the\nnumber of seconds elapsed since midnight (00:00:00), January 1, 1970, Universal Coordinated\nTime, according to the system clock.\nIf this parameter is 0, the current file header time date stamp is incremented by 1 second.\nIf the function succeeds, the return value is TRUE.\nReturn value\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe ReBaseImage function changes the desired load address for the specified image. This\noperation involves reading the entire image and updating all fixups, debugging information,\nand checksum. You can rebase an image to reduce the required load time for its DLLs. If an\napplication can rely on a DLL being loaded at the desired load address, then the system loader\ndoes not have to relocate the image. The image is simply loaded into the application's virtual\naddress space and the DllMain function is called, if one is present.\nAll ImageHlp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nYou cannot rebase DLLs that link with /DYNAMICBASE or that reside in protected directories,\nsuch as the System32 folder.\nAs an alternative to using this function, see the /BASE linker option.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader imagehlp.h\nLibrary Imagehlp.lib\nDLL Imagehlp.dll\nDllMain\nRemarks\nRequirements\nﾉ Expand table\nSee also\nImageHlp Functions","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3416,"title":"ReBaseImage64 function (imagehlp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["rebaseimage64","function","imagehlp","changes","the","load","address","for","specified","image","which","reduces","required","time","dll","article07","2022","alternatively","you","can","use","rebase","tool","this","available","visual","studio","and","windows","sdk","currentimagename","name","file","rebased","must","specify","full","path","unless","module"],"errorCode":"","eventId":"","severity":"Low","summary":"Changes the load address for the specified image, which reduces the required load time for a\nDLL.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to ReBaseImage64 function (imagehlp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"ReBaseImage64 function (imagehlp.h)\nArticle07/27/2022\nChanges the load address for the specified image, which reduces the required load time for a\nDLL.\nAlternatively, you can use the Rebase tool. This tool is available in Visual Studio and the\nWindows SDK.\nC++\n[in] CurrentImageName\nThe name of the file to be rebased. You must specify the full path to the file unless the module\nis in the current working directory of the calling process.\n[in] SymbolPath\nThe path used to find the corresponding symbol file. Specify this path for executable images\nthat have symbolic information because when image addresses change, the corresponding\nsymbol database file (PDB) may also need to be changed. Note that even if the symbol path is\nnot valid, the function will succeed if it is able to rebases your image.\n[in] fReBase\nIf this value is TRUE, the image is rebased. Otherwise, the image is not rebased.\nSyntax\nBOOL IMAGEAPI ReBaseImage64(\n [in] PCSTR CurrentImageName,\n [in] PCSTR SymbolPath,\n [in] BOOL fReBase,\n [in] BOOL fRebaseSysfileOk,\n [in] BOOL fGoingDown,\n [in] ULONG CheckImageSize,\n [out] ULONG *OldImageSize,\n [out] ULONG64 *OldImageBase,\n [out] ULONG *NewImageSize,\n [in, out] ULONG64 *NewImageBase,\n [in] ULONG TimeStamp\n);\nParameters\n[in] fRebaseSysfileOk\nIf this value is TRUE, the system image is rebased. Otherwise, the system image is not rebased.\n[in] fGoingDown\nIf this value is TRUE, the image can be rebased below the given base; otherwise, it cannot.\n[in] CheckImageSize\nThe maximum size that the image can grow to, in bytes, or zero if there is no limit.\n[out] OldImageSize\nA pointer to a variable that receives the original image size, in bytes.\n[out] OldImageBase\nA pointer to a variable that receives the original image base.\n[out] NewImageSize\nA pointer to a variable that receives the new image size after the rebase operation, in bytes.\n[in, out] NewImageBase\nThe base address to use for rebasing the image. If the address is not available and the\nfGoingDown parameter is set to TRUE, the function finds a new base address and sets this\nparameter to the new base address. If fGoingDown is FALSE, the function finds a new base\naddress but does not set this parameter to the new base address.\n[in] TimeStamp\nThe new time date stamp for the image file header. The value must be represented in the\nnumber of seconds elapsed since midnight (00:00:00), January 1, 1970, Universal Coordinated\nTime, according to the system clock.\nIf this parameter is 0, the current file header time date stamp is incremented by 1 second.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nReturn value\nThe ReBaseImage64 function changes the desired load address for the specified image. This\noperation involves reading the entire image and updating all fixups, debugging information,\nand checksum. You can rebase an image to reduce the required load time for its DLLs. If an\napplication can rely on a DLL being loaded at the desired load address, then the system loader\ndoes not have to relocate the image. The image is simply loaded into the application's virtual\naddress space and the DllMain function is called, if one is present.\nAll ImageHlp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nYou cannot rebase DLLs that link with /DYNAMICBASE or that reside in protected directories,\nsuch as the System32 folder.\nAs an alternative to using this function, see the /BASE linker option.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader imagehlp.h\nLibrary Imagehlp.lib\nDLL Imagehlp.dll\nDllMain\nImageHlp Functions\nReBaseImage\nRemarks\nRequirements\nﾉ Expand table\nSee also\nSetImageConfigInformation function\n(imagehlp.h)\nLocates and changes the load configuration data of an image.\nC++\n[in] LoadedImage\nA pointer to a LOADED_IMAGE structure that is returned from a call to MapAndLoad or\nImageLoad.\n[in] ImageConfigInformation\nA pointer to an IMAGE_LOAD_CONFIG_DIRECTORY64 structure.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe SetImageConfigInformation function locates and returns the load configuration data of an\nimage.\nAll ImageHlp functions, such as this one, are single threaded. Therefore, calls from more than one\nthread to this function will likely result in unexpected behavior or memory corruption. To avoid\nSyntax\nBOOL IMAGEAPI SetImageConfigInformation(\n [in] PLOADED_IMAGE LoadedImage,\n [in] PIMAGE_LOAD_CONFIG_DIRECTORY ImageConfigInformation\n);\nParameters\nReturn value\nRemarks\nthis, you must synchronize all concurrent calls from more than one thread to this function.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader imagehlp.h\nLibrary Imagehlp.lib\nDLL Imagehlp.dll\nGetImageConfigInformation\nIMAGE_LOAD_CONFIG_DIRECTORY64\nImageHlp Functions\nLOADED_IMAGE\nLast updated on 02/22/2024\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3417,"title":"SplitSymbols function (imagehlp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["splitsymbols","function","imagehlp","strips","symbols","from","the","specified","image","article02","2024","imagename","name","which","split","symbolspath","subdirectory","for","storing","this","parameter","optional","out","symbolfilepath","generated","symbol","file","typically","has","dbg","extension","flags","information","can","zero","combination","following","values","value","meaning"],"errorCode":"","eventId":"","severity":"Low","summary":"Strips symbols from the specified image.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SplitSymbols function (imagehlp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SplitSymbols function (imagehlp.h)\nArticle02/22/2024\nStrips symbols from the specified image.\nC++\n[in] ImageName\nThe name of the image from which to split symbols.\n[in] SymbolsPath\nThe subdirectory for storing symbols. This parameter is optional.\n[out] SymbolFilePath\nThe name of the generated symbol file. This file typically has a .dbg extension.\n[in] Flags\nThe information to be split from the image. This parameter can be zero or a combination of the\nfollowing values.\nValue Meaning\nSPLITSYM_EXTRACT_ALL\n0x00000002\nUsually, an image with the symbols split off will still contain a\nMISC debug directory with the name of the symbol file.\nTherefore, the debugger can still find the symbols. Using this\nflag removes this link. The end result is similar to using the -\ndebug:none switch on the Microsoft linker.\nSyntax\nBOOL IMAGEAPI SplitSymbols(\n [in] PSTR ImageName,\n [in] PCSTR SymbolsPath,\n [out] PSTR SymbolFilePath,\n [in] ULONG Flags\n);\nParameters\nﾉ Expand table\nSPLITSYM_REMOVE_PRIVATE\n0x00000001\nThis strips off the private CodeView symbolic information\nwhen generating the symbol file.\nSPLITSYM_SYMBOLPATH_IS_SRC\n0x00000004\nThe symbol file path contains an alternate path to locate the\n.pdb file.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe SplitSymbols function should be used when stripping symbols from an image. It will create\na symbol file that all compatible debuggers understand. The format is defined in WinNT.h and\nconsists of an image header, followed by the array of section headers, the FPO information,\nand all debugging symbolic information from the image.\nIf the SymbolsPath parameter is NULL, the symbol file is stored in the directory where the\nimage exists. Otherwise, it is stored in the subdirectory below SymbolsPath that matches the\nextension of the image. Using this method reduces the chances of symbol file collision. For\nexample, the symbols for myapp.exe will be in the SymbolsPath\\exe directory and the symbols\nfor myapp.dll will be in the SymbolsPath\\dll directory.\nAll ImageHlp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nRequirement Value\nHeader imagehlp.h\nLibrary Imagehlp.lib\nDLL Imagehlp.dll\nImageHlp Functions\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3418,"title":"PIMAGEHLP_STATUS_ROUTINE callback function (imagehlp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["pimagehlp","status","routine","callback","function","imagehlp","application","defined","used","with","the","bindimageex","article02","2024","called","during","process","image","binding","type","defines","pointer","this","statusroutine","placeholder","for","name","reason","current","bind","operation","parameter","can","one","following","values","value","meaning","bindoutofmemory","out"],"errorCode":"","eventId":"","severity":"Low","summary":"An application-defined callback function used with the BindImageEx function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to PIMAGEHLP_STATUS_ROUTINE callback function (imagehlp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"PIMAGEHLP_STATUS_ROUTINE callback\nfunction (imagehlp.h)\nArticle02/22/2024\nAn application-defined callback function used with the BindImageEx function. The status\nroutine is called during the process of the image binding.\nThe PIMAGEHLP_STATUS_ROUTINE type defines a pointer to this callback function.\nStatusRoutine is a placeholder for the application-defined function name.\nC++\n[in] Reason\nThe current status of the bind operation. This parameter can be one of the following values.\nValue Meaning\nBindOutOfMemory\n0\nOut of memory. The Parameter value is the number of bytes in\nthe allocation attempt.\nBindRvaToVaFailed\n1\nThe relative virtual address is invalid for the image. The\nParameter value is not used.\nBindNoRoomInImage\n2\nNo room in the image for new format import table. The\nParameter value is not used.\nSyntax\nPIMAGEHLP_STATUS_ROUTINE PimagehlpStatusRoutine;\nBOOL PimagehlpStatusRoutine(\n [in] IMAGEHLP_STATUS_REASON Reason,\n [in] PCSTR ImageName,\n [in] PCSTR DllName,\n [in] ULONG_PTR Va,\n [in] ULONG_PTR Parameter\n)\n{...}\nParameters\nﾉ Expand table\nBindImportModuleFailed\n3\nModule import failed. The Parameter value is not used.\nBindImportProcedureFailed\n4\nProcedure import failed. The Parameter value is the name of\nthe function.\nBindImportModule\n5\nModule import is starting. The Parameter value is not used.\nBindImportProcedure\n6\nProcedure import is starting. The Parameter value is the name\nof the function.\nBindForwarder\n7\nThe Parameter value is the name of the function forwarded.\nBindForwarderNOT\n8\nThe Parameter value is the name of the function not\nforwarded.\nBindImageModified\n9\nImage modified. The Parameter value is not used.\nBindExpandFileHeaders\n10\nFile headers expanded. The Parameter value is the number of\nbytes\nBindImageComplete\n11\nBinding is complete. For more information on the Parameter\nvalue, see the following Remarks section.\nBindMismatchedSymbols\n12\nChecksum did not match. The Parameter value is the name of\nthe symbol file.\nBindSymbolsNotUpdated\n13\nSymbol file was not updated. The Parameter value is the name\nof the symbol file not updated.\n[in] ImageName\nThe name of the file to be bound. This value can be a file name, a partial path, or a full path.\n[in] DllName\nThe name of the DLL.\n[in] Va\nThe computed virtual address.\n[in] Parameter\nAny additional status information. This value depends on the value of the Reason parameter.\nFor more information, see the code fragment in the following Remarks section.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nAll ImageHlp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nThe following code fragment describes how to use the Va value when the status is\nBindImageComplete.\nC++\nReturn value\nRemarks\ncase BindImageComplete:\n if (fVerbose) {\n fprintf(stderr, \"BIND: Details of binding %s\\n\", ImageName );\n NewImports = (PIMAGE_BOUND_IMPORT_DESCRIPTOR)Va;\n NewImport = NewImports;\n while (NewImport->OffsetModuleName) {\n fprintf( stderr, \" Import from %s [%x]\",\n (LPSTR)NewImports + NewImport->OffsetModuleName,\n NewImport->TimeDateStamp\n );\n if (NewImport->NumberOfModuleForwarderRefs != 0) {\n fprintf( stderr, \" with %u forwarders\", NewImport-> \n NumberOfModuleForwarderRefs );\n }\n fprintf( stderr, \"\\n\" );\n NewForwarder = (PIMAGE_BOUND_FORWARDER_REF)(NewImport+1);\n for (i=0; i<NewImport->NumberOfModuleForwarderRefs; i++) \n {\n fprintf( stderr, \" Forward to %s [%x]\\n\",\n (LPSTR)NewImports + NewForwarder->OffsetModuleName,\n NewForwarder->TimeDateStamp);\n NewForwarder += 1;\n }\n NewImport = (PIMAGE_BOUND_IMPORT_DESCRIPTOR)NewForwarder;\n }\n }\n break;\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader imagehlp.h\nBindImageEx\nImageHlp Functions\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3419,"title":"TouchFileTimes function (imagehlp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["touchfiletimes","function","imagehlp","updates","the","date","and","time","which","specified","file","was","last","modified","article10","2021","filehandle","handle","interest","psystemtime","pointer","systemtime","structure","this","parameter","null","current","system","used","succeeds","return","value","true","fails","false","retrieve","extended","error","information","call"],"errorCode":"","eventId":"","severity":"Low","summary":"Updates the date and time at which the specified file was last modified.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to TouchFileTimes function (imagehlp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"TouchFileTimes function (imagehlp.h)\nArticle10/13/2021\nUpdates the date and time at which the specified file was last modified.\nC++\n[in] FileHandle\nA handle to the file of interest.\n[in] pSystemTime\nA pointer to a SYSTEMTIME structure. If this parameter is NULL, the current system date and\ntime is used.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nAll ImageHlp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nSyntax\nBOOL IMAGEAPI TouchFileTimes(\n [in] HANDLE FileHandle,\n [in] PSYSTEMTIME pSystemTime\n);\nParameters\nReturn value\nRemarks\nRequirements\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader imagehlp.h\nLibrary Imagehlp.lib\nDLL Imagehlp.dll\nImage Help Library Overview\nImageHlp Functions\nSYSTEMTIME\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3420,"title":"UnMapAndLoad function (imagehlp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["unmapandload","function","imagehlp","deallocate","all","resources","that","are","allocated","previous","call","the","mapandload","article02","2024","loadedimage","pointer","loaded","image","structure","this","obtained","through","succeeds","return","value","true","fails","false","retrieve","extended","error","information","getlasterror","must","used","also","writes","new","checksum"],"errorCode":"","eventId":"","severity":"Low","summary":"Deallocate all resources that are allocated by a previous call to the MapAndLoad function.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to UnMapAndLoad function (imagehlp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"UnMapAndLoad function (imagehlp.h)\nArticle02/22/2024\nDeallocate all resources that are allocated by a previous call to the MapAndLoad function.\nC++\n[in] LoadedImage\nA pointer to a LOADED_IMAGE structure. This structure is obtained through a call to the\nMapAndLoad function.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe UnMapAndLoad function must be used to deallocate all resources that are allocated by a\nprevious call to MapAndLoad. This function also writes a new checksum value into the image\nbefore the file is closed. This ensures that if a file is changed, it can be successfully loaded by\nthe system loader.\nAll ImageHlp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nSyntax\nBOOL IMAGEAPI UnMapAndLoad(\n [in] PLOADED_IMAGE LoadedImage\n);\nParameters\nReturn value\nRemarks\nRequirements\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader imagehlp.h\nLibrary Imagehlp.lib\nDLL Imagehlp.dll\nImageHlp Functions\nLOADED_IMAGE\nMapAndLoad\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3421,"title":"UpdateDebugInfoFile function (imagehlp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["updatedebuginfofile","function","imagehlp","uses","the","specified","information","update","corresponding","fields","symbol","file","article10","2021","this","has","been","superseded","updatedebuginfofileex","use","verify","checksum","value","imagefilename","name","image","that","now","out","date","with","respect","its","symbolpath","path","which","look","for","debugfilepath","pointer"],"errorCode":"","eventId":"","severity":"Low","summary":"Uses the specified information to update the corresponding fields in the symbol file.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to UpdateDebugInfoFile function (imagehlp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"UpdateDebugInfoFile function (imagehlp.h)\nArticle10/13/2021\nUses the specified information to update the corresponding fields in the symbol file.\n \nThis function has been superseded by the UpdateDebugInfoFileEx function. Use\nUpdateDebugInfoFileEx to verify the checksum value.\nC++\n[in] ImageFileName\nThe name of the image that is now out of date with respect to its symbol file.\n[in] SymbolPath\nThe path in which to look for the symbol file.\n[out] DebugFilePath\nA pointer to a buffer that receives the name of the symbol file that was updated.\n[in] NtHeaders\nA pointer to an IMAGE_NT_HEADERS structure that specifies the new header information.\nIf the function succeeds, the return value is TRUE.\nNote This function works with .dbg files, not .pdb files.\nSyntax\nBOOL IMAGEAPI UpdateDebugInfoFile(\n [in] PCSTR ImageFileName,\n [in] PCSTR SymbolPath,\n [out] PSTR DebugFilePath,\n [in] PIMAGE_NT_HEADERS32 NtHeaders\n);\nParameters\nReturn value\nIf the function fails, the return value is FALSE. To retrieve extended error information, call\nGetLastError.\nThe UpdateDebugInfoFile function takes the information stored in the IMAGE_NT_HEADERS\nstructure and updates the corresponding fields in the symbol file. Any time an image file is\nmodified, this function should be called to keep the numbers in sync. Specifically, whenever an\nimage checksum changes, the symbol file should be updated to match.\nAll ImageHlp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader imagehlp.h\nLibrary Imagehlp.lib\nDLL Imagehlp.dll\nIMAGE_NT_HEADERS\nImageHlp Functions\nUpdateDebugInfoFileEx\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3422,"title":"UpdateDebugInfoFileEx function (imagehlp.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["updatedebuginfofileex","function","imagehlp","uses","the","specified","extended","information","update","corresponding","fields","symbol","file","article10","2021","imagefilename","name","image","that","now","out","date","with","respect","its","symbolpath","path","which","look","for","debugfilepath","pointer","buffer","receives","was","updated","ntheaders","headers","structure","specifies"],"errorCode":"","eventId":"","severity":"Low","summary":"Uses the specified extended information to update the corresponding fields in the symbol file.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to UpdateDebugInfoFileEx function (imagehlp.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"UpdateDebugInfoFileEx function\n(imagehlp.h)\nArticle10/13/2021\nUses the specified extended information to update the corresponding fields in the symbol file.\n \nC++\n[in] ImageFileName\nThe name of the image that is now out of date with respect to its symbol file.\n[in] SymbolPath\nThe path in which to look for the symbol file.\n[out] DebugFilePath\nA pointer to a buffer that receives the name of the symbol file that was updated.\n[in] NtHeaders\nA pointer to an IMAGE_NT_HEADERS structure that specifies the new header information.\n[in] OldCheckSum\nNote This function works with .dbg files, not .pdb files.\nSyntax\nBOOL IMAGEAPI UpdateDebugInfoFileEx(\n [in] PCSTR ImageFileName,\n [in] PCSTR SymbolPath,\n [out] PSTR DebugFilePath,\n [in] PIMAGE_NT_HEADERS32 NtHeaders,\n [in] DWORD OldCheckSum\n);\nParameters\nThe original checksum value. If this value does not match the checksum that is present in the\nmapped image, the flags in the symbol file contain IMAGE_SEPARATE_DEBUG_MISMATCH and\nthe last error value is set to ERROR_INVALID_DATA.\nIf the function succeeds, the return value is TRUE.\nIf the function fails, the return value is FALSE.\nThe UpdateDebugInfoFileEx function takes the information stored in the IMAGE_NT_HEADERS\nstructure and updates the corresponding fields in the symbol file. Any time an image file is\nmodified, this function should be called to keep the numbers in sync. Specifically, whenever an\nimage checksum changes, the symbol file should be updated to match.\nAll ImageHlp functions, such as this one, are single threaded. Therefore, calls from more than\none thread to this function will likely result in unexpected behavior or memory corruption. To\navoid this, you must synchronize all concurrent calls from more than one thread to this\nfunction.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader imagehlp.h\nLibrary Imagehlp.lib\nDLL Imagehlp.dll\nIMAGE_NT_HEADERS\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nSee also\nImageHlp Functions\nImageHlp Structures\nThe following are the ImageHlp data structures:\nIMAGE_COFF_SYMBOLS_HEADER\nIMAGE_DATA_DIRECTORY\nIMAGE_DEBUG_DIRECTORY\nIMAGE_FILE_HEADER\nIMAGE_FUNCTION_ENTRY\nIMAGE_LOAD_CONFIG_DIRECTORY64\nIMAGE_NT_HEADERS\nIMAGE_OPTIONAL_HEADER\nIMAGE_SECTION_HEADER\n \n \nLast updated on 07/14/2025","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3423,"title":"IMAGE_COFF_SYMBOLS_HEADER structure (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["image","coff","symbols","header","structure","winnt","represents","the","article02","2024","numberofsymbols","number","lvatofirstsymbol","virtual","address","first","symbol","numberoflinenumbers","line","entries","lvatofirstlinenumber","entry","rvatofirstbyteofcode","relative","byte","code","syntax","typedef","struct","dword","rvatolastbyteofcode","rvatofirstbyteofdata","rvatolastbyteofdata","pimage","members","feedback","was","this","page","helpful"],"errorCode":"","eventId":"","severity":"Low","summary":"Represents the COFF symbols header.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to IMAGE_COFF_SYMBOLS_HEADER structure (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"IMAGE_COFF_SYMBOLS_HEADER\nstructure (winnt.h)\nArticle02/22/2024\nRepresents the COFF symbols header.\nC++\nNumberOfSymbols\nThe number of symbols.\nLvaToFirstSymbol\nThe virtual address of the first symbol.\nNumberOfLinenumbers\nThe number of line-number entries.\nLvaToFirstLinenumber\nThe virtual address of the first line-number entry.\nRvaToFirstByteOfCode\nThe relative virtual address of the first byte of code.\nSyntax\ntypedef struct _IMAGE_COFF_SYMBOLS_HEADER {\n DWORD NumberOfSymbols;\n DWORD LvaToFirstSymbol;\n DWORD NumberOfLinenumbers;\n DWORD LvaToFirstLinenumber;\n DWORD RvaToFirstByteOfCode;\n DWORD RvaToLastByteOfCode;\n DWORD RvaToFirstByteOfData;\n DWORD RvaToLastByteOfData;\n} IMAGE_COFF_SYMBOLS_HEADER, *PIMAGE_COFF_SYMBOLS_HEADER;\nMembers\nFeedback\nWas this page helpful?\nRvaToLastByteOfCode\nThe relative virtual address of the last byte of code.\nRvaToFirstByteOfData\nThe relative virtual address of the first byte of data.\nRvaToLastByteOfData\nThe relative virtual address of the last byte of data.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nHeader winnt.h (include Windows.h)\nImageHlp Structures\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3424,"title":"IMAGE_DATA_DIRECTORY structure (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["image","data","directory","structure","winnt","virtualaddress","the","relative","virtual","address","table","article02","2024","represents","size","bytes","following","list","directories","offsets","are","beginning","optional","header","offset","pe32","description","112","export","and","104","120","import","128","resource","136","exception","syntax","typedef","struct"],"errorCode":"","eventId":"","severity":"Low","summary":"C++\nVirtualAddress\nThe relative virtual address of the table.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to IMAGE_DATA_DIRECTORY structure (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"IMAGE_DATA_DIRECTORY structure\n(winnt.h)\nArticle02/22/2024\nRepresents the data directory.\nC++\nVirtualAddress\nThe relative virtual address of the table.\nSize\nThe size of the table, in bytes.\nThe following is a list of the data directories. Offsets are relative to the beginning of the\noptional header.\nOffset (PE/PE32+) Description\n96/112 Export table address and size\n104/120 Import table address and size\n112/128 Resource table address and size\n120/136 Exception table address and size\nSyntax\ntypedef struct _IMAGE_DATA_DIRECTORY {\n DWORD VirtualAddress;\n DWORD Size;\n} IMAGE_DATA_DIRECTORY, *PIMAGE_DATA_DIRECTORY;\nMembers\nRemarks\nﾉ Expand table\nFeedback\nWas this page helpful?\n128/144 Certificate table address and size\n136/152 Base relocation table address and size\n144/160 Debugging information starting address and size\n152/168 Architecture-specific data address and size\n160/176 Global pointer register relative virtual address\n168/184 Thread local storage (TLS) table address and size\n176/192 Load configuration table address and size\n184/200 Bound import table address and size\n192/208 Import address table address and size\n200/216 Delay import descriptor address and size\n208/224 The CLR header address and size\n216/232 Reserved\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nHeader winnt.h (include Windows.h)\nIMAGE_OPTIONAL_HEADER\nImageHlp Structures\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3425,"title":"IMAGE_DEBUG_DIRECTORY structure (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["image","debug","directory","structure","winnt","represents","the","format","article11","2024","characteristics","reserved","timedatestamp","time","and","date","debugging","information","was","created","majorversion","major","version","number","minorversion","minor","type","this","field","enables","support","multiple","debuggers","for","more","see","specification","syntax","typedef","struct"],"errorCode":"","eventId":"","severity":"Low","summary":"Represents the debug directory format.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to IMAGE_DEBUG_DIRECTORY structure (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"IMAGE_DEBUG_DIRECTORY structure\n(winnt.h)\nArticle11/20/2024\nRepresents the debug directory format.\nC++\nCharacteristics\nReserved.\nTimeDateStamp\nThe time and date the debugging information was created.\nMajorVersion\nThe major version number of the debugging information format.\nMinorVersion\nThe minor version number of the debugging information format.\nType\nThe format of debugging information. This field enables support of multiple debuggers.\nFor more information, see Debug Type in PE Format specification.\nSyntax\ntypedef struct _IMAGE_DEBUG_DIRECTORY {\n DWORD Characteristics;\n DWORD TimeDateStamp;\n WORD MajorVersion;\n WORD MinorVersion;\n DWORD Type;\n DWORD SizeOfData;\n DWORD AddressOfRawData;\n DWORD PointerToRawData;\n} IMAGE_DEBUG_DIRECTORY, *PIMAGE_DEBUG_DIRECTORY;\nMembers\nFeedback\nWas this page helpful?\nProvide product feedback | Get help at Microsoft Q&A\nSizeOfData\nThe size of the debugging information, in bytes. This value does not include the debug\ndirectory itself.\nAddressOfRawData\nThe address of the debugging information when the image is loaded, relative to the\nimage base.\nPointerToRawData\nA file pointer to the debugging information.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nHeader winnt.h (include Windows.h)\nImageHlp Structures\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3426,"title":"IMAGE_FILE_HEADER structure (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["image","file","header","structure","winnt","represents","the","coff","format","article02","2025","machine","architecture","type","computer","can","only","run","specified","system","that","emulates","this","member","one","following","values","for","complete","list","valid","types","and","supported","architectures","see","documentation","numberofsections","number","sections"],"errorCode":"","eventId":"","severity":"Low","summary":"Represents the COFF header format.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to IMAGE_FILE_HEADER structure (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"IMAGE_FILE_HEADER structure (winnt.h)\nArticle02/12/2025\nRepresents the COFF header format.\nC++\nMachine\nThe architecture type of the computer. An image file can only be run on the specified\ncomputer or a system that emulates the specified computer. This member can be one of\nthe following values.\nFor a complete list of valid Machine types and supported architectures, see the PE\nFormat documentation.\nNumberOfSections\nThe number of sections. This indicates the size of the section table, which immediately\nfollows the headers. Note that the Windows loader limits the number of sections to 96.\nTimeDateStamp\nThe low 32 bits of the time stamp of the image. This represents the date and time the\nimage was created by the linker. The value is represented in the number of seconds\nelapsed since midnight (00:00:00), January 1, 1970, Universal Coordinated Time,\naccording to the system clock.\nPointerToSymbolTable\nSyntax\ntypedef struct _IMAGE_FILE_HEADER {\n WORD Machine;\n WORD NumberOfSections;\n DWORD TimeDateStamp;\n DWORD PointerToSymbolTable;\n DWORD NumberOfSymbols;\n WORD SizeOfOptionalHeader;\n WORD Characteristics;\n} IMAGE_FILE_HEADER, *PIMAGE_FILE_HEADER;\nMembers\nThe offset of the symbol table, in bytes, or zero if no COFF symbol table exists.\nNumberOfSymbols\nThe number of symbols in the symbol table.\nSizeOfOptionalHeader\nThe size of the optional header, in bytes. This value should be 0 for object files.\nCharacteristics\nThe characteristics of the image. This member can be one or more of the following\nvalues.\nValue Meaning\nIMAGE_FILE_RELOCS_STRIPPED\n0x0001\nRelocation information was stripped from the file.\nThe file must be loaded at its preferred base\naddress. If the base address is not available, the\nloader reports an error.\nIMAGE_FILE_EXECUTABLE_IMAGE\n0x0002\nThe file is executable (there are no unresolved\nexternal references).\nIMAGE_FILE_LINE_NUMS_STRIPPED\n0x0004\nCOFF line numbers were stripped from the file.\nIMAGE_FILE_LOCAL_SYMS_STRIPPED\n0x0008\nCOFF symbol table entries were stripped from\nfile.\nIMAGE_FILE_AGGRESIVE_WS_TRIM\n0x0010\nAggressively trim the working set. This value is\nobsolete.\nIMAGE_FILE_LARGE_ADDRESS_AWARE\n0x0020\nThe application can handle addresses larger than\n2 GB.\nIMAGE_FILE_BYTES_REVERSED_LO\n0x0080\nThe bytes of the word are reversed. This flag is\nobsolete.\nIMAGE_FILE_32BIT_MACHINE\n0x0100\nThe computer supports 32-bit words.\nIMAGE_FILE_DEBUG_STRIPPED\n0x0200\nDebugging information was removed and stored\nseparately in another file.\nIMAGE_FILE_REMOVABLE_RUN_FROM_SWAP\n0x0400\nIf the image is on removable media, copy it to\nand run it from the swap file.\nﾉ Expand table\nFeedback\nWas this page helpful?\nProvide product feedback | Get help at Microsoft Q&A\nIMAGE_FILE_NET_RUN_FROM_SWAP\n0x0800\nIf the image is on the network, copy it to and run\nit from the swap file.\nIMAGE_FILE_SYSTEM\n0x1000\nThe image is a system file.\nIMAGE_FILE_DLL\n0x2000\nThe image is a DLL file. While it is an executable\nfile, it cannot be run directly.\nIMAGE_FILE_UP_SYSTEM_ONLY\n0x4000\nThe file should be run only on a uniprocessor\ncomputer.\nIMAGE_FILE_BYTES_REVERSED_HI\n0x8000\nThe bytes of the word are reversed. This flag is\nobsolete.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nHeader winnt.h (include Windows.h)\nIMAGE_NT_HEADERS\nImageHlp Structures\nRequirements\nﾉ Expand table\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3427,"title":"IMAGE_FUNCTION_ENTRY structure (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["image","function","entry","structure","winnt","represents","the","table","article02","2024","startingaddress","address","start","endingaddress","end","endofprologue","prologue","code","following","definition","exists","for","bit","support","syntax","typedef","struct","dword","pimage","members","remarks","entry64","ulonglong","union","unwindinfoaddress","feedback","was","this","page","helpful"],"errorCode":"","eventId":"","severity":"Low","summary":"Represents an entry in the function table.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to IMAGE_FUNCTION_ENTRY structure (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"IMAGE_FUNCTION_ENTRY structure\n(winnt.h)\nArticle02/22/2024\nRepresents an entry in the function table.\nC++\nStartingAddress\nThe image address of the start of the function.\nEndingAddress\nThe image address of the end of the function.\nEndOfPrologue\nThe image address of the end of the prologue code.\nThe following definition exists for 64-bit support.\nC++\nSyntax\ntypedef struct _IMAGE_FUNCTION_ENTRY {\n DWORD StartingAddress;\n DWORD EndingAddress;\n DWORD EndOfPrologue;\n} IMAGE_FUNCTION_ENTRY, *PIMAGE_FUNCTION_ENTRY;\nMembers\nRemarks\ntypedef struct _IMAGE_FUNCTION_ENTRY64 {\n ULONGLONG StartingAddress;\n ULONGLONG EndingAddress;\n union {\n ULONGLONG EndOfPrologue;\n ULONGLONG UnwindInfoAddress;\nFeedback\nWas this page helpful?\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nHeader winnt.h (include Windows.h)\nImageHlp Structures\nSTACKFRAME64\n };\n} IMAGE_FUNCTION_ENTRY64, *PIMAGE_FUNCTION_ENTRY64;\nRequirements\nﾉ Expand table\nSee also\nYes No\nIMAGE_LOAD_CONFIG_DIRECTORY32\nstructure (winnt.h)\nContains the load configuration data of an image.\nC++\nSyntax\ntypedef struct _IMAGE_LOAD_CONFIG_DIRECTORY32 {\n DWORD Size;\n DWORD TimeDateStamp;\n WORD MajorVersion;\n WORD MinorVersion;\n DWORD GlobalFlagsClear;\n DWORD GlobalFlagsSet;\n DWORD CriticalSectionDefaultTimeout;\n DWORD DeCommitFreeBlockThreshold;\n DWORD DeCommitTotalFreeThreshold;\n DWORD LockPrefixTable;\n DWORD MaximumAllocationSize;\n DWORD VirtualMemoryThreshold;\n DWORD ProcessHeapFlags;\n DWORD ProcessAffinityMask;\n WORD CSDVersion;\n WORD DependentLoadFlags;\n DWORD EditList;\n DWORD SecurityCookie;\n DWORD SEHandlerTable;\n DWORD SEHandlerCount;\n DWORD GuardCFCheckFunctionPointer;\n DWORD GuardCFDispatchFunctionPointer;\n DWORD GuardCFFunctionTable;\n DWORD GuardCFFunctionCount;\n DWORD GuardFlags;\n IMAGE_LOAD_CONFIG_CODE_INTEGRITY CodeIntegrity;\n DWORD GuardAddressTakenIatEntryTable;\n DWORD GuardAddressTakenIatEntryCount;\n DWORD GuardLongJumpTargetTable;\n DWORD GuardLongJumpTargetCount;\n DWORD DynamicValueRelocTable;\n DWORD CHPEMetadataPointer;\n DWORD GuardRFFailureRoutine;\n DWORD GuardRFFailureRoutineFunctionPointer;\n DWORD DynamicValueRelocTableOffset;\n WORD DynamicValueRelocTableSection;\n WORD Reserved2;\n DWORD GuardRFVerifyStackPointerFunctionPointer;\n DWORD HotPatchTableOffset;\n DWORD Reserved3;\nSize\nThe size of the structure. For Windows XP, the size must be specified as 64 for x86 images.\nTimeDateStamp\nThe date and time stamp value. The value is represented in the number of seconds elapsed\nsince midnight (00:00:00), January 1, 1970, Universal Coordinated Time, according to the\nsystem clock. The time stamp can be printed using the C run-time (CRT) function ctime.\nMajorVersion\nThe major version number.\nMinorVersion\nThe minor version number.\nGlobalFlagsClear\nThe global flags that control system behavior. For more information, see Gflags.exe.\nGlobalFlagsSet\nThe global flags that control system behavior. For more information, see Gflags.exe.\nCriticalSectionDefaultTimeout\nThe critical section default time-out value.\nDeCommitFreeBlockThreshold\nThe size of the minimum block that must be freed before it is freed (de-committed), in bytes.\nThis value is advisory.\n DWORD EnclaveConfigurationPointer;\n DWORD VolatileMetadataPointer;\n DWORD GuardEHContinuationTable;\n DWORD GuardEHContinuationCount;\n DWORD GuardXFGCheckFunctionPointer;\n DWORD GuardXFGDispatchFunctionPointer;\n DWORD GuardXFGTableDispatchFunctionPointer;\n DWORD CastGuardOsDeterminedFailureMode;\n DWORD GuardMemcpyFunctionPointer;\n DWORD UmaFunctionPointers;\n} IMAGE_LOAD_CONFIG_DIRECTORY32, *PIMAGE_LOAD_CONFIG_DIRECTORY32;\nMembers\nDeCommitTotalFreeThreshold\nThe size of the minimum total memory that must be freed in the process heap before it is freed\n(de-committed), in bytes. This value is advisory.\nLockPrefixTable\nThe VA of a list of addresses where the LOCK prefix is used. These will be replaced by NOP on\nsingle-processor systems. This member is available only for x86.\nMaximumAllocationSize\nThe maximum allocation size, in bytes. This member is obsolete and is used only for debugging\npurposes.\nVirtualMemoryThreshold\nThe maximum block size that can be allocated from heap segments, in bytes.\nProcessHeapFlags\nThe process heap flags. For more information, see HeapCreate.\nProcessAffinityMask\nThe process affinity mask. For more information, see GetProcessAffinityMask. This member is\navailable only for .exe files.\nCSDVersion\nThe service pack version.\nDependentLoadFlags\nEditList\nReserved for use by the system.\nSecurityCookie\nA pointer to a cookie that is used by Visual C++ or GS implementation.\nSEHandlerTable\nThe VA of the sorted table of RVAs of each valid, unique handler in the image. This member is\navailable only for x86.\nSEHandlerCount\nThe count of unique handlers in the table. This member is available only for x86.\nGuardCFCheckFunctionPointer\nGuardCFDispatchFunctionPointer\nGuardCFFunctionTable\nGuardCFFunctionCount\nGuardFlags\nCodeIntegrity\nGuardAddressTakenIatEntryTable\nGuardAddressTakenIatEntryCount\nGuardLongJumpTargetTable\nGuardLongJumpTargetCount\nDynamicValueRelocTable\nCHPEMetadataPointer\nGuardRFFailureRoutine\nGuardRFFailureRoutineFunctionPointer\nDynamicValueRelocTableOffset\nDynamicValueRelocTableSection\nReserved2\nGuardRFVerifyStackPointerFunctionPointer\nHotPatchTableOffset\nReserved3\nEnclaveConfigurationPointer\nVolatileMetadataPointer\nGuardEHContinuationTable\nGuardEHContinuationCount\nGuardXFGCheckFunctionPointer\nGuardXFGDispatchFunctionPointer\nGuardXFGTableDispatchFunctionPointer\nCastGuardOsDeterminedFailureMode\nGuardMemcpyFunctionPointer\nUmaFunctionPointers\nIf _WIN64 is defined, then IMAGE_LOAD_CONFIG_DIRECTORY is defined as\nIMAGE_LOAD_CONFIG_DIRECTORY64. However, if _WIN64 is not defined, then\nIMAGE_LOAD_CONFIG_DIRECTORY is defined as IMAGE_LOAD_CONFIG_DIRECTORY32.\nC++\nRemarks\ntypedef struct {\n DWORD Size;\n DWORD TimeDateStamp;\n WORD MajorVersion;\n WORD MinorVersion;\n DWORD GlobalFlagsClear;\n DWORD GlobalFlagsSet;\n DWORD","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3428,"title":"IMAGE_NT_HEADERS32 structure (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["image","headers32","structure","winnt","represents","the","header","format","article02","2024","signature","byte","identifying","file","bytes","are","fileheader","that","specifies","optionalheader","optional","actual","named","and","headers","defined","however","win64","then","headers64","syntax","typedef","struct","dword","header32","pimage","members","remarks","header64","requirement"],"errorCode":"","eventId":"","severity":"Low","summary":"Represents the PE header format.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to IMAGE_NT_HEADERS32 structure (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"IMAGE_NT_HEADERS32 structure (winnt.h)\nArticle02/22/2024\nRepresents the PE header format.\nC++\nSignature\nA 4-byte signature identifying the file as a PE image. The bytes are \"PE\\0\\0\".\nFileHeader\nAn IMAGE_FILE_HEADER structure that specifies the file header.\nOptionalHeader\nAn IMAGE_OPTIONAL_HEADER structure that specifies the optional file header.\nThe actual structure in WinNT.h is named IMAGE_NT_HEADERS32 and IMAGE_NT_HEADERS is\ndefined as IMAGE_NT_HEADERS32. However, if _WIN64 is defined, then IMAGE_NT_HEADERS\nis defined as IMAGE_NT_HEADERS64.\nC++\nSyntax\ntypedef struct _IMAGE_NT_HEADERS {\n DWORD Signature;\n IMAGE_FILE_HEADER FileHeader;\n IMAGE_OPTIONAL_HEADER32 OptionalHeader;\n} IMAGE_NT_HEADERS32, *PIMAGE_NT_HEADERS32;\nMembers\nRemarks\ntypedef struct _IMAGE_NT_HEADERS64 {\n DWORD Signature;\n IMAGE_FILE_HEADER FileHeader;\n IMAGE_OPTIONAL_HEADER64 OptionalHeader;\n} IMAGE_NT_HEADERS64, *PIMAGE_NT_HEADERS64;\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nHeader winnt.h (include Windows.h)\nCheckSumMappedFile\nIMAGE_FILE_HEADER\nIMAGE_OPTIONAL_HEADER\nImageHlp Structures\nImageNtHeader\nImageRvaToSection\nImageRvaToVa\nLOADED_IMAGE\nUpdateDebugInfoFile\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3429,"title":"IMAGE_OPTIONAL_HEADER32 structure (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["image","optional","header32","structure","winnt","represents","the","header","format","article09","2022","magic","syntax","typedef","struct","word","byte","majorlinkerversion","minorlinkerversion","dword","sizeofcode","sizeofinitializeddata","sizeofuninitializeddata","addressofentrypoint","baseofcode","baseofdata","imagebase","sectionalignment","filealignment","majoroperatingsystemversion","minoroperatingsystemversion","majorimageversion","minorimageversion","majorsubsystemversion","minorsubsystemversion","win32versionvalue","sizeofimage","sizeofheaders","checksum","subsystem"],"errorCode":"","eventId":"","severity":"Low","summary":"Represents the optional header format.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to IMAGE_OPTIONAL_HEADER32 structure (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"IMAGE_OPTIONAL_HEADER32 structure\n(winnt.h)\nArticle09/01/2022\nRepresents the optional header format.\nC++\nMagic\nSyntax\ntypedef struct _IMAGE_OPTIONAL_HEADER {\n WORD Magic;\n BYTE MajorLinkerVersion;\n BYTE MinorLinkerVersion;\n DWORD SizeOfCode;\n DWORD SizeOfInitializedData;\n DWORD SizeOfUninitializedData;\n DWORD AddressOfEntryPoint;\n DWORD BaseOfCode;\n DWORD BaseOfData;\n DWORD ImageBase;\n DWORD SectionAlignment;\n DWORD FileAlignment;\n WORD MajorOperatingSystemVersion;\n WORD MinorOperatingSystemVersion;\n WORD MajorImageVersion;\n WORD MinorImageVersion;\n WORD MajorSubsystemVersion;\n WORD MinorSubsystemVersion;\n DWORD Win32VersionValue;\n DWORD SizeOfImage;\n DWORD SizeOfHeaders;\n DWORD CheckSum;\n WORD Subsystem;\n WORD DllCharacteristics;\n DWORD SizeOfStackReserve;\n DWORD SizeOfStackCommit;\n DWORD SizeOfHeapReserve;\n DWORD SizeOfHeapCommit;\n DWORD LoaderFlags;\n DWORD NumberOfRvaAndSizes;\n IMAGE_DATA_DIRECTORY DataDirectory[IMAGE_NUMBEROF_DIRECTORY_ENTRIES];\n} IMAGE_OPTIONAL_HEADER32, *PIMAGE_OPTIONAL_HEADER32;\nMembers\nThe state of the image file. This member can be one of the following values.\nValue Meaning\nIMAGE_NT_OPTIONAL_HDR_MAGIC The file is an executable image. This value is defined as\nIMAGE_NT_OPTIONAL_HDR32_MAGIC in a 32-bit application\nand as IMAGE_NT_OPTIONAL_HDR64_MAGIC in a 64-bit\napplication.\nIMAGE_NT_OPTIONAL_HDR32_MAGIC\n0x10b\nThe file is an executable image.\nIMAGE_NT_OPTIONAL_HDR64_MAGIC\n0x20b\nThe file is an executable image.\nIMAGE_ROM_OPTIONAL_HDR_MAGIC\n0x107\nThe file is a ROM image.\nMajorLinkerVersion\nThe major version number of the linker.\nMinorLinkerVersion\nThe minor version number of the linker.\nSizeOfCode\nThe size of the code section, in bytes, or the sum of all such sections if there are multiple code\nsections.\nSizeOfInitializedData\nThe size of the initialized data section, in bytes, or the sum of all such sections if there are\nmultiple initialized data sections.\nSizeOfUninitializedData\nThe size of the uninitialized data section, in bytes, or the sum of all such sections if there are\nmultiple uninitialized data sections.\nAddressOfEntryPoint\nA pointer to the entry point function, relative to the image base address. For executable files,\nthis is the starting address. For device drivers, this is the address of the initialization function.\nﾉ Expand table\nThe entry point function is optional for DLLs. When no entry point is present, this member is\nzero.\nBaseOfCode\nA pointer to the beginning of the code section, relative to the image base.\nBaseOfData\nA pointer to the beginning of the data section, relative to the image base.\nImageBase\nThe preferred address of the first byte of the image when it is loaded in memory. This value is a\nmultiple of 64K bytes. The default value for DLLs is 0x10000000. The default value for\napplications is 0x00400000, except on Windows CE where it is 0x00010000.\nSectionAlignment\nThe alignment of sections loaded in memory, in bytes. This value must be greater than or equal\nto the FileAlignment member. The default value is the page size for the system.\nFileAlignment\nThe alignment of the raw data of sections in the image file, in bytes. The value should be a\npower of 2 between 512 and 64K (inclusive). The default is 512. If the SectionAlignment\nmember is less than the system page size, this member must be the same as\nSectionAlignment.\nMajorOperatingSystemVersion\nThe major version number of the required operating system.\nMinorOperatingSystemVersion\nThe minor version number of the required operating system.\nMajorImageVersion\nThe major version number of the image.\nMinorImageVersion\nThe minor version number of the image.\nMajorSubsystemVersion\nThe major version number of the subsystem.\nMinorSubsystemVersion\nThe minor version number of the subsystem.\nWin32VersionValue\nThis member is reserved and must be 0.\nSizeOfImage\nThe size of the image, in bytes, including all headers. Must be a multiple of SectionAlignment.\nSizeOfHeaders\nThe combined size of the following items, rounded to a multiple of the value specified in the\nFileAlignment member.\ne_lfanew member of IMAGE_DOS_HEADER\n4 byte signature\nsize of IMAGE_FILE_HEADER\nsize of optional header\nsize of all section headers\nCheckSum\nThe image file checksum. The following files are validated at load time: all drivers, any DLL\nloaded at boot time, and any DLL loaded into a critical system process.\nSubsystem\nThe subsystem required to run this image. The following values are defined.\nValue Meaning\nIMAGE_SUBSYSTEM_UNKNOWN\n0\nUnknown subsystem.\nIMAGE_SUBSYSTEM_NATIVE\n1\nNo subsystem required (device drivers and\nnative system processes).\nIMAGE_SUBSYSTEM_WINDOWS_GUI\n2\nWindows graphical user interface (GUI)\nsubsystem.\nﾉ Expand table\nIMAGE_SUBSYSTEM_WINDOWS_CUI\n3\nWindows character-mode user interface (CUI)\nsubsystem.\nIMAGE_SUBSYSTEM_OS2_CUI\n5\nOS/2 CUI subsystem.\nIMAGE_SUBSYSTEM_POSIX_CUI\n7\nPOSIX CUI subsystem.\nIMAGE_SUBSYSTEM_WINDOWS_CE_GUI\n9\nWindows CE system.\nIMAGE_SUBSYSTEM_EFI_APPLICATION\n10\nExtensible Firmware Interface (EFI) application.\nIMAGE_SUBSYSTEM_EFI_BOOT_SERVICE_DRIVER\n11\nEFI driver with boot services.\nIMAGE_SUBSYSTEM_EFI_RUNTIME_DRIVER\n12\nEFI driver with run-time services.\nIMAGE_SUBSYSTEM_EFI_ROM\n13\nEFI ROM image.\nIMAGE_SUBSYSTEM_XBOX\n14\nXbox system.\nIMAGE_SUBSYSTEM_WINDOWS_BOOT_APPLICATION\n16\nBoot application.\nDllCharacteristics\nThe DLL characteristics of the image. The following values are defined.\nValue Meaning\n0x0001 Reserved.\n0x0002 Reserved.\n0x0004 Reserved.\n0x0008 Reserved.\nIMAGE_DLL_CHARACTERISTICS_HIGH_ENTROPY_VA\n0x0020\nASLR with 64 bit address space.\nIMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE\n0x0040\nThe DLL can be relocated at load time.\nﾉ Expand table\nIMAGE_DLLCHARACTERISTICS_FORCE_INTEGRITY\n0x0080\nCode integrity checks are forced. If you set\nthis flag and a section contains only\nuninitialized data, set the\nPointerToRawData member of\nIMAGE_SECTION_HEADER for that section\nto zero; otherwise, the image will fail to\nload because the digital signature cannot\nbe verified.\nIMAGE_DLLCHARACTERISTICS_NX_COMPAT\n0x0100\nT","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3430,"title":"IMAGE_SECTION_HEADER structure (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["image","section","header","structure","winnt","represents","the","format","article09","2022","name","sizeof","short","byte","null","padded","utf","string","there","terminating","character","exactly","eight","characters","long","for","longer","names","this","member","contains","forward","slash","followed","ascii","representation","decimal","number","that","offset"],"errorCode":"","eventId":"","severity":"Low","summary":"Represents the image section header format.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to IMAGE_SECTION_HEADER structure (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"IMAGE_SECTION_HEADER structure\n(winnt.h)\nArticle09/01/2022\nRepresents the image section header format.\nC++\nName[IMAGE_SIZEOF_SHORT_NAME]\nAn 8-byte, null-padded UTF-8 string. There is no terminating null character if the string\nis exactly eight characters long. For longer names, this member contains a forward slash\n(/) followed by an ASCII representation of a decimal number that is an offset into the\nstring table. Executable images do not use a string table and do not support section\nnames longer than eight characters.\nMisc\nMisc.PhysicalAddress\nThe file address.\nMisc.VirtualSize\nSyntax\ntypedef struct _IMAGE_SECTION_HEADER {\n BYTE Name[IMAGE_SIZEOF_SHORT_NAME];\n union {\n DWORD PhysicalAddress;\n DWORD VirtualSize;\n } Misc;\n DWORD VirtualAddress;\n DWORD SizeOfRawData;\n DWORD PointerToRawData;\n DWORD PointerToRelocations;\n DWORD PointerToLinenumbers;\n WORD NumberOfRelocations;\n WORD NumberOfLinenumbers;\n DWORD Characteristics;\n} IMAGE_SECTION_HEADER, *PIMAGE_SECTION_HEADER;\nMembers\nThe total size of the section when loaded into memory, in bytes. If this value is greater\nthan the SizeOfRawData member, the section is filled with zeroes. This field is valid only\nfor executable images and should be set to 0 for object files.\nVirtualAddress\nThe address of the first byte of the section when loaded into memory, relative to the\nimage base. For object files, this is the address of the first byte before relocation is\napplied.\nSizeOfRawData\nThe size of the initialized data on disk, in bytes. This value must be a multiple of the\nFileAlignment member of the IMAGE_OPTIONAL_HEADER structure. If this value is less\nthan the VirtualSize member, the remainder of the section is filled with zeroes. If the\nsection contains only uninitialized data, the member is zero.\nPointerToRawData\nA file pointer to the first page within the COFF file. This value must be a multiple of the\nFileAlignment member of the IMAGE_OPTIONAL_HEADER structure. If a section\ncontains only uninitialized data, set this member is zero.\nPointerToRelocations\nA file pointer to the beginning of the relocation entries for the section. If there are no\nrelocations, this value is zero.\nPointerToLinenumbers\nA file pointer to the beginning of the line-number entries for the section. If there are no\nCOFF line numbers, this value is zero.\nNumberOfRelocations\nThe number of relocation entries for the section. This value is zero for executable\nimages.\nNumberOfLinenumbers\nThe number of line-number entries for the section.\nCharacteristics\nThe characteristics of the image. The following values are defined.\nFlag Meaning\n0x00000000 Reserved.\n0x00000001 Reserved.\n0x00000002 Reserved.\n0x00000004 Reserved.\nIMAGE_SCN_TYPE_NO_PAD\n0x00000008\nThe section should not be padded to the next\nboundary. This flag is obsolete and is replaced by\nIMAGE_SCN_ALIGN_1BYTES.\n0x00000010 Reserved.\nIMAGE_SCN_CNT_CODE\n0x00000020\nThe section contains executable code.\nIMAGE_SCN_CNT_INITIALIZED_DATA\n0x00000040\nThe section contains initialized data.\nIMAGE_SCN_CNT_UNINITIALIZED_DATA\n0x00000080\nThe section contains uninitialized data.\nIMAGE_SCN_LNK_OTHER\n0x00000100\nReserved.\nIMAGE_SCN_LNK_INFO\n0x00000200\nThe section contains comments or other information.\nThis is valid only for object files.\n0x00000400 Reserved.\nIMAGE_SCN_LNK_REMOVE\n0x00000800\nThe section will not become part of the image. This is\nvalid only for object files.\nIMAGE_SCN_LNK_COMDAT\n0x00001000\nThe section contains COMDAT data. This is valid only\nfor object files.\n0x00002000 Reserved.\nIMAGE_SCN_NO_DEFER_SPEC_EXC\n0x00004000\nReset speculative exceptions handling bits in the TLB\nentries for this section.\nIMAGE_SCN_GPREL\n0x00008000\nThe section contains data referenced through the\nglobal pointer.\n0x00010000 Reserved.\nIMAGE_SCN_MEM_PURGEABLE Reserved.\nﾉ Expand table\n0x00020000\nIMAGE_SCN_MEM_LOCKED\n0x00040000\nReserved.\nIMAGE_SCN_MEM_PRELOAD\n0x00080000\nReserved.\nIMAGE_SCN_ALIGN_1BYTES\n0x00100000\nAlign data on a 1-byte boundary. This is valid only for\nobject files.\nIMAGE_SCN_ALIGN_2BYTES\n0x00200000\nAlign data on a 2-byte boundary. This is valid only for\nobject files.\nIMAGE_SCN_ALIGN_4BYTES\n0x00300000\nAlign data on a 4-byte boundary. This is valid only for\nobject files.\nIMAGE_SCN_ALIGN_8BYTES\n0x00400000\nAlign data on a 8-byte boundary. This is valid only for\nobject files.\nIMAGE_SCN_ALIGN_16BYTES\n0x00500000\nAlign data on a 16-byte boundary. This is valid only for\nobject files.\nIMAGE_SCN_ALIGN_32BYTES\n0x00600000\nAlign data on a 32-byte boundary. This is valid only for\nobject files.\nIMAGE_SCN_ALIGN_64BYTES\n0x00700000\nAlign data on a 64-byte boundary. This is valid only for\nobject files.\nIMAGE_SCN_ALIGN_128BYTES\n0x00800000\nAlign data on a 128-byte boundary. This is valid only\nfor object files.\nIMAGE_SCN_ALIGN_256BYTES\n0x00900000\nAlign data on a 256-byte boundary. This is valid only\nfor object files.\nIMAGE_SCN_ALIGN_512BYTES\n0x00A00000\nAlign data on a 512-byte boundary. This is valid only\nfor object files.\nIMAGE_SCN_ALIGN_1024BYTES\n0x00B00000\nAlign data on a 1024-byte boundary. This is valid only\nfor object files.\nIMAGE_SCN_ALIGN_2048BYTES\n0x00C00000\nAlign data on a 2048-byte boundary. This is valid only\nfor object files.\nIMAGE_SCN_ALIGN_4096BYTES\n0x00D00000\nAlign data on a 4096-byte boundary. This is valid only\nfor object files.\nIMAGE_SCN_ALIGN_8192BYTES\n0x00E00000\nAlign data on a 8192-byte boundary. This is valid only\nfor object files.\nIMAGE_SCN_LNK_NRELOC_OVFL\n0x01000000\nThe section contains extended relocations. The count\nof relocations for the section exceeds the 16 bits that\nis reserved for it in the section header. If the\nNumberOfRelocations field in the section header is\n0xffff, the actual relocation count is stored in the\nVirtualAddress field of the first relocation. It is an\nerror if IMAGE_SCN_LNK_NRELOC_OVFL is set and\nthere are fewer than 0xffff relocations in the section.\nIMAGE_SCN_MEM_DISCARDABLE\n0x02000000\nThe section can be discarded as needed.\nIMAGE_SCN_MEM_NOT_CACHED\n0x04000000\nThe section cannot be cached.\nIMAGE_SCN_MEM_NOT_PAGED","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3431,"title":"AddVectoredContinueHandler function (errhandlingapi.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["addvectoredcontinuehandler","function","errhandlingapi","registers","vectored","continue","handler","article02","2024","first","the","order","which","should","called","parameter","nonzero","zero","last","pointer","for","more","information","see","vectoredhandler","succeeds","return","value","exception","fails","null","until","subsequent","call","used","specify","different","points","dll","and"],"errorCode":"","eventId":"","severity":"Low","summary":"Registers a vectored continue handler.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to AddVectoredContinueHandler function (errhandlingapi.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"AddVectoredContinueHandler function\n(errhandlingapi.h)\nArticle02/22/2024\nRegisters a vectored continue handler.\nC++\nFirst\nThe order in which the handler should be called. If the parameter is nonzero, the handler is the\nfirst handler to be called. If the parameter is zero, the handler is the last handler to be called.\nHandler\nA pointer to the handler to be called. For more information, see VectoredHandler.\nIf the function succeeds, the return value is a pointer to the exception handler.\nIf the function fails, the return value is NULL.\nIf the First parameter is nonzero, the handler is the first handler to be called until a subsequent\ncall to AddVectoredContinueHandler is used to specify a different handler as the first handler.\nIf the VectoredHandler parameter points to a function in a DLL and that DLL is unloaded, the\nhandler is still registered. This can lead to application errors.\nTo unregister the handler, use the RemoveVectoredContinueHandler function.\nSyntax\nPVOID AddVectoredContinueHandler(\n ULONG First,\n PVECTORED_EXCEPTION_HANDLER Handler\n);\nParameters\nReturn value\nRemarks\nTo compile an application that uses this function, define the _WIN32_WINNT macro as 0x0500\nor later. For more information, see Using the Windows Headers.\nRequirement Value\nMinimum supported client Windows Vista, Windows XP Professional x64 Edition [desktop apps only]\nMinimum supported server Windows Server 2008, Windows Server 2003 with SP1 [desktop apps only]\nTarget Platform Windows\nHeader errhandlingapi.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nAddVectoredExceptionHandler function, RemoveVectoredExceptionHandler function, Vectored\nException Handling, VectoredHandler\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3432,"title":"AddVectoredExceptionHandler function (errhandlingapi.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["addvectoredexceptionhandler","function","errhandlingapi","registers","vectored","exception","handler","article04","2021","first","the","order","which","should","called","parameter","nonzero","zero","last","pointer","for","more","information","see","vectoredhandler","succeeds","return","value","handle","fails","null","until","subsequent","call","used","specify","different","points","dll","and"],"errorCode":"","eventId":"","severity":"Low","summary":"Registers a vectored exception handler.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to AddVectoredExceptionHandler function (errhandlingapi.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"AddVectoredExceptionHandler function\n(errhandlingapi.h)\nArticle04/02/2021\nRegisters a vectored exception handler.\nC++\nFirst\nThe order in which the handler should be called. If the parameter is nonzero, the handler is the\nfirst handler to be called. If the parameter is zero, the handler is the last handler to be called.\nHandler\nA pointer to the handler to be called. For more information, see VectoredHandler.\nIf the function succeeds, the return value is a handle to the exception handler.\nIf the function fails, the return value is NULL.\nIf the First parameter is nonzero, the handler is the first handler to be called until a subsequent\ncall to AddVectoredExceptionHandler is used to specify a different handler as the first handler.\nIf the VectoredHandler parameter points to a function in a DLL and that DLL is unloaded, the\nhandler is still registered. This can lead to application errors.\nTo unregister the handler, use the RemoveVectoredExceptionHandler function function.\nSyntax\nPVOID AddVectoredExceptionHandler(\n ULONG First,\n PVECTORED_EXCEPTION_HANDLER Handler\n);\nParameters\nReturn value\nRemarks\nTo compile an application that uses this function, define the _WIN32_WINNT macro as 0x0500\nor later. For more information, see Using the Windows Headers.\nFor an example, see Using a Vectored Exception Handler.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader errhandlingapi.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nAddVectoredContinueHandler function, RemoveVectoredExceptionHandler function, Vectored\nException Handling, VectoredHandler\nExamples\nRequirements\nﾉ Expand table\nSee also\nGetExceptionCode macro\nRetrieves a code that identifies the type of exception that occurs. The function can be called\nonly from within the filter expression or exception-handler block of an exception handler.\n \nC++\nThis macro has no parameters.\nThe return value identifies the type of exception. The following table identifies the exception\ncodes that can occur due to common programming errors. These values are defined in\nWinBase.h and WinNT.h.\nReturn code Description\nEXCEPTION_ACCESS_VIOLATION The thread attempts to read from or write to a virtual\naddress for which it does not have access.\nThis value is defined as STATUS_ACCESS_VIOLATION.\nEXCEPTION_ARRAY_BOUNDS_EXCEEDED The thread attempts to access an array element that is\nout of bounds, and the underlying hardware supports\nbounds checking.\nThis value is defined as\nSTATUS_ARRAY_BOUNDS_EXCEEDED.\n７ Note\nThe Microsoft C/C++ Optimizing Compiler interprets this function as a keyword, and its\nuse outside the appropriate exception-handling syntax generates a compiler error.\nSyntax\nDWORD GetExceptionCode(void);\nParameters\nReturn value\nﾉ Expand table\nReturn code Description\nEXCEPTION_BREAKPOINT A breakpoint is encountered.\nThis value is defined as STATUS_BREAKPOINT.\nEXCEPTION_DATATYPE_MISALIGNMENTThe thread attempts to read or write data that is\nmisaligned on hardware that does not provide\nalignment. For example, 16-bit values must be aligned on\n2-byte boundaries, 32-bit values on 4-byte boundaries,\nand so on.\nThis value is defined as\nSTATUS_DATATYPE_MISALIGNMENT.\nEXCEPTION_FLT_DENORMAL_OPERANDOne of the operands in a floating point operation is\ndenormal. A denormal value is one that is too small to\nrepresent as a standard floating point value.\nThis value is defined as\nSTATUS_FLOAT_DENORMAL_OPERAND.\nEXCEPTION_FLT_DIVIDE_BY_ZERO The thread attempts to divide a floating point value by a\nfloating point divisor of 0 (zero).\nThis value is defined as STATUS_FLOAT_DIVIDE_BY_ZERO.\nEXCEPTION_FLT_INEXACT_RESULT The result of a floating point operation cannot be\nrepresented exactly as a decimal fraction.\nThis value is defined as STATUS_FLOAT_INEXACT_RESULT.\nEXCEPTION_FLT_INVALID_OPERATION A floating point exception that is not included in this list.\nThis value is defined as\nSTATUS_FLOAT_INVALID_OPERATION.\nEXCEPTION_FLT_OVERFLOW The exponent of a floating point operation is greater\nthan the magnitude allowed by the corresponding type.\nThis value is defined as STATUS_FLOAT_OVERFLOW.\nEXCEPTION_FLT_STACK_CHECK The stack has overflowed or underflowed, because of a\nfloating point operation.\nThis value is defined as STATUS_FLOAT_STACK_CHECK.\nEXCEPTION_FLT_UNDERFLOW The exponent of a floating point operation is less than\nthe magnitude allowed by the corresponding type.\nThis value is defined as STATUS_FLOAT_UNDERFLOW.\nEXCEPTION_GUARD_PAGE The thread accessed memory allocated with the\nPAGE_GUARD modifier.\nThis value is defined as\nSTATUS_GUARD_PAGE_VIOLATION.\nEXCEPTION_ILLEGAL_INSTRUCTION The thread tries to execute an invalid instruction.\nThis value is defined as STATUS_ILLEGAL_INSTRUCTION.\nReturn code Description\nEXCEPTION_IN_PAGE_ERROR The thread tries to access a page that is not present, and\nthe system is unable to load the page. For example, this\nexception might occur if a network connection is lost\nwhile running a program over a network.\nThis value is defined as STATUS_IN_PAGE_ERROR.\nEXCEPTION_INT_DIVIDE_BY_ZERO The thread attempts to divide an integer value by an\ninteger divisor of 0 (zero).\nThis value is defined as\nSTATUS_INTEGER_DIVIDE_BY_ZERO.\nEXCEPTION_INT_OVERFLOW The result of an integer operation creates a value that is\ntoo large to be held by the destination register. In some\ncases, this will result in a carry out of the most significant\nbit of the result. Some operations do not set the carry\nflag.\nThis value is defined as STATUS_INTEGER_OVERFLOW.\nEXCEPTION_INVALID_DISPOSITION An exception handler returns an invalid disposition to the\nexception dispatcher. Programmers using a high-level\nlanguage such as C should never encounter this\nexception.\nThis value is defined as STATUS_INVALID_DISPOSITION.\nEXCEPTION_INVALID_HANDLE The thread used a handle to a kernel object that was\ninvalid (probably because it had been closed.)\nThis value is defined as STATUS_IN","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3433,"title":"RaiseException function (errhandlingapi.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["raiseexception","function","errhandlingapi","raises","exception","the","calling","thread","2024","dwexceptioncode","application","defined","code","being","raised","filter","expression","and","handler","block","can","use","getexceptioncode","retrieve","this","value","note","that","system","will","clear","bit","before","displaying","message","reserved","used","for","its","own"],"errorCode":"","eventId":"","severity":"Low","summary":"Raises an exception in the calling thread.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to RaiseException function (errhandlingapi.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"RaiseException function (errhandlingapi.h)\n02/02/2024\nRaises an exception in the calling thread.\nC++\n[in] dwExceptionCode\nAn application-defined exception code of the exception being raised. The filter expression and\nexception-handler block of an exception handler can use the GetExceptionCode function to\nretrieve this value.\nNote that the system will clear bit 28 of dwExceptionCode before displaying a message This bit\nis a reserved exception bit, used by the system for its own purposes.\n[in] dwExceptionFlags\nThe exception flags. This can be either zero to indicate a continuable exception, or\nEXCEPTION_NONCONTINUABLE to indicate a noncontinuable exception. Any attempt to\ncontinue execution after a noncontinuable exception causes the\nEXCEPTION_NONCONTINUABLE_EXCEPTION exception.\n[in] nNumberOfArguments\nThe number of arguments in the lpArguments array. This value must not exceed\nEXCEPTION_MAXIMUM_PARAMETERS. This parameter is ignored if lpArguments is NULL.\n[in] lpArguments\nAn array of arguments. This parameter can be NULL. These arguments can contain any\napplication-defined data that needs to be passed to the filter expression of the exception\nSyntax\nVOID RaiseException(\n [in] DWORD dwExceptionCode,\n [in] DWORD dwExceptionFlags,\n [in] DWORD nNumberOfArguments,\n [in] const ULONG_PTR *lpArguments\n);\nParameters\nhandler.\nThis function does not return a value.\nThe RaiseException function enables a process to use structured exception handling to handle\nprivate, software-generated, application-defined exceptions.\nRaising an exception causes the exception dispatcher to go through the following search for an\nexception handler:\n1. The system first attempts to notify the process's debugger, if any.\n2. If the process is not being debugged, or if the associated debugger does not handle the\nexception, the system attempts to locate a frame-based exception handler by searching\nthe stack frames of the thread in which the exception occurred. The system searches the\ncurrent stack frame first, then proceeds backward through preceding stack frames.\n3. If no frame-based handler can be found, or no frame-based handler handles the\nexception, the system makes a second attempt to notify the process's debugger.\n4. If the process is not being debugged, or if the associated debugger does not handle the\nexception, the system provides default handling based on the exception type. For most\nexceptions, the default action is to call the ExitProcess function.\nThe values specified in the dwExceptionCode, dwExceptionFlags, nNumberOfArguments, and\nlpArguments parameters can be retrieved in the filter expression of a frame-based exception\nhandler by calling the GetExceptionInformation function. A debugger can retrieve these values\nby calling the WaitForDebugEvent function.\nFor an example, see Using an Exception Handler.\nRequirement Value\nMinimum supported client Windows XP [desktop apps | UWP apps]\nReturn value\nRemarks\nExamples\nRequirements\nﾉ Expand table\nRequirement Value\nMinimum supported server Windows Server 2003 [desktop apps | UWP apps]\nTarget Platform Windows\nHeader errhandlingapi.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nExitProcess\nGetExceptionCode\nGetExceptionInformation\nStructured Exception Handling Functions\nStructured Exception Handling Overview\nWaitForDebugEvent\nVertdll APIs available in VBS enclaves\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3434,"title":"RaiseFailFastException Function","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["raisefailfastexception","function","this","documentation","preliminary","and","subject","change","raises","exception","that","bypasses","all","handlers","frame","vector","based","article05","2009","raising","terminates","the","application","invokes","windows","error","reporting","running","syntax","parameters","pexceptionrecord","optional","pointer","record","structure","contains","information","you","must","specify"],"errorCode":"","eventId":"","severity":"Low","summary":"[This documentation is preliminary and is subject to change.]\nRaises an exception that bypasses all exception handlers (frame or vector based).","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to RaiseFailFastException Function.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"RaiseFailFastException Function\nArticle05/08/2009\n[This documentation is preliminary and is subject to change.]\nRaises an exception that bypasses all exception handlers (frame or vector based). Raising this\nexception terminates the application and invokes Windows Error Reporting (if Windows Error\nReporting is running).\nSyntax\nc++\nParameters\npExceptionRecord [in, optional]\nA pointer to an EXCEPTION_RECORD structure that contains the exception information.\nYou must specify the ExceptionAddress and ExceptionCode members.\nIf this parameter is NULL, the function creates an exception record and sets the\nExceptionCode member to STATUS_FAIL_FAST_EXCEPTION. The function will also set the\nExceptionAddress member if the dwFlags parameter contains the\nFAIL_FAST_GENERATE_EXCEPTION_ADDRESS flag.\npContextRecord [in, optional]\nA pointer to a CONTEXT structure that contains the context information. If NULL, this\nfunction generates the context (however, the context will not match the context of the\ncaller).\ndwFlags [in]\nYou can specify zero or one or more of the following flags that control this function's\nbehavior:\nVOID WINAPI RaiseFailFastException(\n __in_opt PEXCEPTION_RECORD pExceptionRecord,\n __in_opt PCONTEXT pContextRecord,\n __in DWORD dwFlags\n);\nﾉ Expand table\nValue Meaning\nFAIL_FAST_GENERATE_EXCEPTION_ADDRESS\n0x1\nCauses RaiseFailFastException to set the\nExceptionAddress of EXCEPTION_RECORD to the\nreturn address of this function (the next instruction\nin the caller after the call to RaiseFailFastException).\nThis function will set the exception address only if\nExceptionAddress is NULL.\nFAIL_FAST_NO_HARD_ERROR_DLG 0x2 If the Windows Error Report service is not running\nwhen an unhandled exception occurs, a message\nbox is diplayed to the user that identifies the\naddress where the exception occurred. To prevent\nthe message box from being displayed to the user,\nand to fail silently, set this flag.\n \nReturn Value\nThis function does not return a value.\nRemarks\nTypically, you call this function if your application is in a bad state and you want to terminate\nimmediately and have a Windows Error Report created.\nIf the WER service is not running or there is no debugger attached to the process, the process\nwill be terminated.\nThis function raises a second chance exception. If JIT debugging is enabled, a debugger will\nattach to the process.\nRequirements\nMinimum supported client Windows 7\nMinimum supported server Windows Server 2008 R2\nHeader Winbase.h (include Windows.h)\nLibrary Kernel32.lib\nﾉ Expand table\nDLL Kernel32.dll\nSee Also\nEnvironment.FailFast\nSend comments about this topic to Microsoft\nBuild date: 5/7/2009","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3435,"title":"RemoveVectoredContinueHandler function (errhandlingapi.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["removevectoredcontinuehandler","function","errhandlingapi","unregisters","vectored","continue","handler","2025","handle","pointer","exception","previously","registered","using","the","addvectoredcontinuehandler","succeeds","return","value","nonzero","fails","zero","compile","application","that","uses","this","define","win32","winnt","macro","0x0500","later","for","more","information","see","windows","headers","syntax"],"errorCode":"","eventId":"","severity":"Low","summary":"Unregisters a vectored continue handler.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to RemoveVectoredContinueHandler function (errhandlingapi.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"RemoveVectoredContinueHandler function\n(errhandlingapi.h)\n10/07/2025\nUnregisters a vectored continue handler.\nC++\nHandle\nA pointer to a vectored exception handler previously registered using the\nAddVectoredContinueHandler function.\nIf the function succeeds, the return value is nonzero.\nIf the function fails, the return value is zero.\nTo compile an application that uses this function, define the _WIN32_WINNT macro as 0x0500\nor later. For more information, see Using the Windows Headers.\nSyntax\nULONG RemoveVectoredContinueHandler(\n PVOID Handle\n);\nParameters\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nRequirement Value\nMinimum supported client Windows Vista, Windows XP Professional x64 Edition [desktop apps only]\nMinimum supported server Windows Server 2008, Windows Server 2003 with SP1 [desktop apps only]\nTarget Platform Windows\nHeader errhandlingapi.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nAddVectoredContinueHandler function, Vectored Exception Handling\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3436,"title":"RemoveVectoredExceptionHandler function (errhandlingapi.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["removevectoredexceptionhandler","function","errhandlingapi","unregisters","vectored","exception","handler","article02","2024","handle","the","previously","registered","using","addvectoredexceptionhandler","succeeds","return","value","nonzero","fails","zero","compile","application","that","uses","this","define","win32","winnt","macro","0x0500","later","for","more","information","see","windows","headers","example","syntax"],"errorCode":"","eventId":"","severity":"Low","summary":"Unregisters a vectored exception handler.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to RemoveVectoredExceptionHandler function (errhandlingapi.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"RemoveVectoredExceptionHandler function\n(errhandlingapi.h)\nArticle02/22/2024\nUnregisters a vectored exception handler.\nC++\nHandle\nA handle to the vectored exception handler previously registered using the\nAddVectoredExceptionHandler function.\nIf the function succeeds, the return value is nonzero.\nIf the function fails, the return value is zero.\nTo compile an application that uses this function, define the _WIN32_WINNT macro as 0x0500\nor later. For more information, see Using the Windows Headers.\nFor an example, see Using a Vectored Exception Handler.\nSyntax\nULONG RemoveVectoredExceptionHandler(\n PVOID Handle\n);\nParameters\nReturn value\nRemarks\nExamples\nRequirements\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader errhandlingapi.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nAddVectoredExceptionHandler function, Vectored Exception Handling\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3437,"title":"RtlAddFunctionTable function (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["rtladdfunctiontable","function","winnt","adds","dynamic","table","the","list","2024","functiontable","pointer","array","entries","for","definition","pruntime","type","see","more","information","runtime","calling","convention","documentation","processor","entrycount","number","baseaddress","base","address","use","when","computing","full","virtual","addresses","from","relative","succeeds","return"],"errorCode":"","eventId":"","severity":"Low","summary":"Adds a dynamic function table to the dynamic function table list.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to RtlAddFunctionTable function (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"RtlAddFunctionTable function (winnt.h)\n02/22/2024\nAdds a dynamic function table to the dynamic function table list.\nC++\n[in] FunctionTable\nA pointer to an array of function entries. For a definition of the PRUNTIME_FUNCTION type,\nsee WinNT.h. For more information on runtime function entries, see the calling convention\ndocumentation for the processor.\n[in] EntryCount\nThe number of entries in the FunctionTable array.\n[in] BaseAddress\nThe base address to use when computing full virtual addresses from relative virtual addresses\nof function table entries.\nIf the function succeeds, the return value is TRUE. Otherwise, the return value is FALSE.\nFunction tables are used on 64-bit Windows to determine how to unwind or walk the stack.\nThese tables are usually generated by the compiler and stored as part of the image. However,\nSyntax\nNTSYSAPI BOOLEAN RtlAddFunctionTable(\n [in] PRUNTIME_FUNCTION FunctionTable,\n [in] DWORD EntryCount,\n [in] DWORD64 BaseAddress\n);\nParameters\nReturn value\nRemarks\napplications must provide the function table for dynamically generated code. For more\ninformation about function tables, see the architecture guide for your system.\nThis function is useful for code that is generated from a template or generated only once\nduring the life of the process. For more dynamically generated code, use the\nRtlInstallFunctionTableCallback function.\nRequirement Value\nTarget Platform Windows\nHeader winnt.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nRtlDeleteFunctionTable\nRtlInstallFunctionTableCallback\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3438,"title":"RtlAddGrowableFunctionTable function (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["rtladdgrowablefunctiontable","function","winnt","informs","the","system","dynamic","table","representing","region","memory","containing","code","2024","out","dynamictable","pointer","variable","that","receives","opaque","reference","newly","added","success","functiontable","partially","filled","array","runtime","entries","which","provides","unwind","information","for","this","must","remain","sorted"],"errorCode":"","eventId":"","severity":"Low","summary":"Informs the system of a dynamic function table representing a region of memory containing\ncode.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to RtlAddGrowableFunctionTable function (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"RtlAddGrowableFunctionTable function\n(winnt.h)\n02/22/2024\nInforms the system of a dynamic function table representing a region of memory containing\ncode.\nC++\n[out] DynamicTable\nA pointer to a variable that receives an opaque reference to the newly-added table on success.\nFunctionTable\nA pointer to a partially-filled array of RUNTIME_FUNCTION entries which provides unwind\ninformation for the region of code. The entries in this array must remain sorted in ascending\norder of the BeginAddress members.\n[in] EntryCount\nThe number of entries currently populated in the function table. This value may be zero.\n[in] MaximumEntryCount\nThe capacity of the function table.\n[in] RangeBase\nThe beginning of the memory range described by the function table.\nSyntax\nNTSYSAPI DWORD RtlAddGrowableFunctionTable(\n [out] PVOID *DynamicTable,\n PRUNTIME_FUNCTION FunctionTable,\n [in] DWORD EntryCount,\n [in] DWORD MaximumEntryCount,\n [in] ULONG_PTR RangeBase,\n [in] ULONG_PTR RangeEnd\n);\nParameters\n[in] RangeEnd\nThe end of the memory range described by the function table.\nThis function returns zero on success. (More detail).\nSee http://msdn.microsoft.com/en-us/library/cc704588(PROT.10).aspx for a list of NTSTATUS\nvalues.\nThe function table can grow as code is added to the memory region. The entries in the table\nmust be sorted. This table is used for dispatching exceptions through runtime-generated code\nand for collecting stack backtraces.\nRequirement Value\nMinimum supported client Windows 8 [desktop apps only]\nMinimum supported server Windows Server 2012 [desktop apps only]\nTarget Platform Windows\nHeader winnt.h (include Windows.h)\nLibrary Ntdll.lib\nDLL Ntdll.dll\nReturn value\nRemarks\nRequirements\nﾉ Expand table","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3439,"title":"RtlCaptureContext function (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["rtlcapturecontext","function","winnt","retrieves","context","record","the","caller","2024","out","contextrecord","pointer","structure","this","does","not","return","value","requirement","minimum","supported","client","windows","desktop","apps","only","server","2003","target","platform","header","include","library","kernel32","lib","dll","syntax","ntsysapi","void","pcontext"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves a context record in the context of the caller.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to RtlCaptureContext function (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"RtlCaptureContext function (winnt.h)\n02/22/2024\nRetrieves a context record in the context of the caller.\nC++\n[out] ContextRecord\nA pointer to a CONTEXT structure.\nThis function does not return a value.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader winnt.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nSyntax\nNTSYSAPI VOID RtlCaptureContext(\n [out] PCONTEXT ContextRecord\n);\nParameters\nReturn value\nRequirements\nﾉ Expand table\nCONTEXT\nRtlRestoreContext\nVertdll APIs available in VBS enclaves\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3440,"title":"RtlDeleteFunctionTable function (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["rtldeletefunctiontable","function","winnt","removes","dynamic","table","from","the","list","2024","functiontable","pointer","array","entries","that","were","previously","passed","rtladdfunctiontable","identifier","rtlinstallfunctiontablecallback","for","definition","pruntime","type","see","succeeds","return","value","true","otherwise","false","tables","are","used","bit","windows","determine","how","unwind"],"errorCode":"","eventId":"","severity":"Low","summary":"Removes a dynamic function table from the dynamic function table list.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to RtlDeleteFunctionTable function (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"RtlDeleteFunctionTable function (winnt.h)\n02/22/2024\nRemoves a dynamic function table from the dynamic function table list.\nC++\n[in] FunctionTable\nA pointer to an array of function entries that were previously passed to RtlAddFunctionTable or\nan identifier previously passed to RtlInstallFunctionTableCallback. For a definition of the\nPRUNTIME_FUNCTION type, see WinNT.h.\nIf the function succeeds, the return value is TRUE. Otherwise, the return value is FALSE.\nFunction tables are used on 64-bit Windows to determine how to unwind or walk the stack.\nThese tables are usually generated by the compiler and stored as part of the image. However,\napplications must provide the function table for dynamically generated code. For more\ninformation about function tables, see the architecture guide for your system.\nRequirement Value\nTarget Platform Windows\nSyntax\nNTSYSAPI BOOLEAN RtlDeleteFunctionTable(\n [in] PRUNTIME_FUNCTION FunctionTable\n);\nParameters\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nRequirement Value\nHeader winnt.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nRtlAddFunctionTable\nRtlInstallFunctionTableCallback\nSee also\nRtlDeleteGrowableFunctionTable function\n(winnt.h)\nInforms the system that a previously reported dynamic function table is no longer in use.\nC++\n[in] DynamicTable\nAn opaque reference returned by RtlAddGrowableFunctionTable.\nThis function does not return a value.\nRequirement Value\nMinimum supported client Windows 8 [desktop apps only]\nMinimum supported server Windows Server 2012 [desktop apps only]\nTarget Platform Windows\nHeader winnt.h (include Windows.h)\nLibrary Ntdll.lib\nDLL Ntdll.dll\nSyntax\nNTSYSAPI VOID RtlDeleteGrowableFunctionTable(\n [in] PVOID DynamicTable\n);\nParameters\nReturn value\nRequirements\nﾉ Expand table\nLast updated on 02/22/2024\nRtlGrowFunctionTable function (winnt.h)\nReports that a dynamic function table has increased in size.\nC++\nDynamicTable\nAn opaque reference returned by RtlAddGrowableFunctionTable.\n[in] NewEntryCount\nThe new number of entries in the RUNTIME_FUNCTION array. This must be greater than the\npreviously reported size of the array.\nThis function does not return a value.\nRtlGrowFunctionTable should be called after populating the corresponding entries in the\nRUNTIME_FUNCTION array specified in RtlAddGrowableFunctionTable.\nRequirement Value\nMinimum supported client Windows 8 [desktop apps only]\nSyntax\nNTSYSAPI VOID RtlGrowFunctionTable(\n PVOID DynamicTable,\n [in] DWORD NewEntryCount\n);\nParameters\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nRequirement Value\nMinimum supported server Windows Server 2012 [desktop apps only]\nTarget Platform Windows\nHeader winnt.h (include Windows.h)\nLibrary Ntdll.lib\nDLL Ntdll.dll\nLast updated on 08/23/2022","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3441,"title":"RtlInstallFunctionTableCallback function (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["rtlinstallfunctiontablecallback","function","winnt","adds","dynamic","table","the","list","2022","tableidentifier","identifier","for","callback","two","low","order","bits","must","set","example","baseaddress","0x3","base","address","region","memory","managed","length","size","bytes","pointer","that","called","retrieve","entries","functions","specified","definition","pget","runtime"],"errorCode":"","eventId":"","severity":"Low","summary":"Adds a dynamic function table to the dynamic function table list.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to RtlInstallFunctionTableCallback function (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"RtlInstallFunctionTableCallback function\n(winnt.h)\n07/27/2022\nAdds a dynamic function table to the dynamic function table list.\nC++\n[in] TableIdentifier\nThe identifier for the dynamic function table callback. The two low-order bits must be set. For\nexample, BaseAddress|0x3.\n[in] BaseAddress\nThe base address of the region of memory managed by the callback function.\n[in] Length\nThe size of the region of memory managed by the callback function, in bytes.\n[in] Callback\nA pointer to the callback function that is called to retrieve the function table entries for the\nfunctions in the specified region of memory. For a definition of the\nPGET_RUNTIME_FUNCTION_CALLBACK type, see WinNT.h.\n[in] Context\nA pointer to the user-defined data to be passed to the callback function.\nSyntax\nNTSYSAPI BOOLEAN RtlInstallFunctionTableCallback(\n [in] DWORD64 TableIdentifier,\n [in] DWORD64 BaseAddress,\n [in] DWORD Length,\n [in] PGET_RUNTIME_FUNCTION_CALLBACK Callback,\n [in] PVOID Context,\n [in] PCWSTR OutOfProcessCallbackDll\n);\nParameters\n[in] OutOfProcessCallbackDll\nAn optional pointer to a string that specifies the path of a DLL that provides function table\nentries that are outside the process.\nWhen a debugger unwinds to a function in the range of addresses managed by the callback\nfunction, it loads this DLL and calls the\nOUT_OF_PROCESS_FUNCTION_TABLE_CALLBACK_EXPORT_NAME function, whose type is\nPOUT_OF_PROCESS_FUNCTION_TABLE_CALLBACK. For more information, see the definitions\nof these items in WinNT.h.\nIf the function succeeds, the return value is TRUE. If the function fails, the return value is FALSE.\nFunction tables are used on 64-bit Windows to determine how to unwind or walk the stack.\nThese tables are usually generated by the compiler and stored as part of the image. However,\napplications must provide the function table for dynamically generated code. For more\ninformation about function tables, see the architecture guide for your system.\nThis function is useful for very dynamic code. The application specifies the memory range for\nthe generated code, but does not need to generate a table until it is needed by an unwind\nrequest. At that time, the system calls the callback function with the Context and the control\naddress. The callback function must return the runtime function entry for the specified address.\nBe sure to avoid creating a deadlock between the callback function and the code generator.\nFor code that is generated from a template or generated only once during the life of the\nprocess, use the RtlAddFunctionTable function.\nRequirement Value\nTarget Platform Windows\nHeader winnt.h (include Windows.h)\nLibrary Kernel32.lib\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nRequirement Value\nDLL Kernel32.dll\nRtlAddFunctionTable\nRtlDeleteFunctionTable\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3442,"title":"RtlRestoreContext function (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["rtlrestorecontext","function","winnt","restores","the","context","caller","specified","record","2024","contextrecord","pointer","structure","exceptionrecord","exception","this","parameter","optional","and","should","typically","null","used","primarily","with","long","jump","catch","throw","support","exceptioncode","member","status","longjump","exceptioninformation","contains","buffer","will","copy","non"],"errorCode":"","eventId":"","severity":"Low","summary":"Restores the context of the caller to the specified context record.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to RtlRestoreContext function (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"RtlRestoreContext function (winnt.h)\n02/22/2024\nRestores the context of the caller to the specified context record.\nC++\n[in] ContextRecord\nA pointer to a CONTEXT structure.\n[in] ExceptionRecord\nA pointer to an EXCEPTION_RECORD structure. This parameter is optional and should typically\nbe NULL.\nAn exception record is used primarily with long jump and C++ catch-throw support. If the\nExceptionCode member is STATUS_LONGJUMP, the ExceptionInformation member contains a\npointer to a jump buffer. RtlRestoreContext will copy the non-volatile state from the jump\nbuffer in to the context record before the context record is restored.\nIf the ExceptionCode member is STATUS_UNWIND_CONSOLIDATE, the ExceptionInformation\nmember contains a pointer to a callback function, such as a catch handler. RtlRestoreContext\nconsolidates the call frames between its frame and the frame specified in the context record\nbefore calling the callback function. This hides frames from any exception handling that might\noccur in the callback function. The difference between this and a typical unwind is that the data\non the stack is still present, so frame data such as a throw object is still available. The callback\nfunction returns a new program counter to update in the context record, which is then used in\na normal restore context.\nSyntax\nNTSYSAPI VOID __cdecl RtlRestoreContext(\n PCONTEXT ContextRecord,\n _EXCEPTION_RECORD *ExceptionRecord\n);\nParameters\nReturn value\nThis function does not return a value.\nRequirement Value\nTarget Platform Windows\nHeader winnt.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nCONTEXT\nRtlCaptureContext\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3443,"title":"SetUnhandledExceptionFilter function (errhandlingapi.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["setunhandledexceptionfilter","function","errhandlingapi","enables","application","supersede","the","top","level","exception","handler","each","thread","process","article02","2024","after","calling","this","occurs","that","not","being","debugged","and","makes","unhandled","filter","will","call","specified","lptoplevelexceptionfilter","parameter","pointer","called","whenever","unhandledexceptionfilter","gets","control","value"],"errorCode":"","eventId":"","severity":"Low","summary":"Enables an application to supersede the top-level exception handler of each thread of a\nprocess.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SetUnhandledExceptionFilter function (errhandlingapi.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SetUnhandledExceptionFilter function\n(errhandlingapi.h)\nArticle02/06/2024\nEnables an application to supersede the top-level exception handler of each thread of a\nprocess.\nAfter calling this function, if an exception occurs in a process that is not being debugged, and\nthe exception makes it to the unhandled exception filter, that filter will call the exception filter\nfunction specified by the lpTopLevelExceptionFilter parameter.\nC++\n[in] lpTopLevelExceptionFilter\nA pointer to a top-level exception filter function that will be called whenever the\nUnhandledExceptionFilter function gets control, and the process is not being debugged. A\nvalue of NULL for this parameter specifies default handling within UnhandledExceptionFilter.\nThe filter function has syntax similar to that of UnhandledExceptionFilter: It takes a single\nparameter of type LPEXCEPTION_POINTERS, has a WINAPI calling convention, and returns a\nvalue of type LONG. The filter function should return one of the following values.\nValue Meaning\nEXCEPTION_EXECUTE_HANDLER\n0x1\nReturn from UnhandledExceptionFilter and execute the\nassociated exception handler. This usually results in process\ntermination.\nEXCEPTION_CONTINUE_EXECUTION\n0xffffffff\nReturn from UnhandledExceptionFilter and continue execution\nfrom the point of the exception. Note that the filter function is\nfree to modify the continuation state by modifying the\nSyntax\nLPTOP_LEVEL_EXCEPTION_FILTER SetUnhandledExceptionFilter(\n [in] LPTOP_LEVEL_EXCEPTION_FILTER lpTopLevelExceptionFilter\n);\nParameters\nﾉ Expand table\nexception information supplied through its\nLPEXCEPTION_POINTERS parameter.\nEXCEPTION_CONTINUE_SEARCH\n0x0\nProceed with normal execution of UnhandledExceptionFilter.\nThat means obeying the SetErrorMode flags, or invoking the\nApplication Error pop-up message box.\nThe SetUnhandledExceptionFilter function returns the address of the previous exception filter\nestablished with the function. A NULL return value means that there is no current top-level\nexception handler.\nIssuing SetUnhandledExceptionFilter replaces the existing top-level exception filter for all\nexisting and all future threads in the calling process.\nThe exception handler specified by lpTopLevelExceptionFilter is executed in the context of the\nthread that caused the fault. This can affect the exception handler's ability to recover from\ncertain exceptions, such as an invalid stack.\nRequirement Value\nMinimum supported client Windows XP [desktop apps | UWP apps]\nMinimum supported server Windows Server 2003 [desktop apps | UWP apps]\nTarget Platform Windows\nHeader errhandlingapi.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nStructured Exception Handling Functions\nReturn value\nRemarks\nRequirements\nﾉ Expand table\nSee also\nStructured Exception Handling Overview\nUnhandledExceptionFilter\nVertdll APIs available in VBS enclaves","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3444,"title":"UnhandledExceptionFilter function (errhandlingapi.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["unhandledexceptionfilter","function","errhandlingapi","application","defined","that","passes","unhandled","exceptions","the","debugger","process","being","debugged","article10","2021","otherwise","optionally","displays","error","message","box","and","causes","exception","handler","executed","this","can","called","only","from","within","filter","expression","exceptioninfo","pointer","pointers","structure","specifies"],"errorCode":"","eventId":"","severity":"Low","summary":"An application-defined function that passes unhandled exceptions to the debugger, if the\nprocess is being debugged.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to UnhandledExceptionFilter function (errhandlingapi.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"UnhandledExceptionFilter function\n(errhandlingapi.h)\nArticle10/13/2021\nAn application-defined function that passes unhandled exceptions to the debugger, if the\nprocess is being debugged. Otherwise, it optionally displays an Application Error message box\nand causes the exception handler to be executed. This function can be called only from within\nthe filter expression of an exception handler.\nC++\n[in] ExceptionInfo\nA pointer to an EXCEPTION_POINTERS structure that specifies a description of the exception\nand the processor context at the time of the exception. This pointer is the return value of a call\nto the GetExceptionInformation function.\nThe function returns one of the following values.\nReturn code/value Description\nEXCEPTION_CONTINUE_SEARCH\n0x0\nThe process is being debugged, so the exception should be\npassed (as second chance) to the application's debugger.\nEXCEPTION_EXECUTE_HANDLER\n0x1\nIf the SEM_NOGPFAULTERRORBOX flag was specified in a\nprevious call to SetErrorMode, no Application Error message\nbox is displayed. The function returns control to the exception\nhandler, which is free to take any appropriate action.\nSyntax\nLONG UnhandledExceptionFilter(\n [in] _EXCEPTION_POINTERS *ExceptionInfo\n);\nParameters\nReturn value\nﾉ Expand table\nIf the process is not being debugged, the function displays an Application Error message box,\ndepending on the current error mode. The default behavior is to display the dialog box, but\nthis can be disabled by specifying SEM_NOGPFAULTERRORBOX in a call to the SetErrorMode\nfunction.\nThe system uses UnhandledExceptionFilter internally to handle exceptions that occur during\nprocess and thread creation.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader errhandlingapi.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nEXCEPTION_POINTERS\nGetExceptionInformation\nSetErrorMode\nSetUnhandledExceptionFilter\nStructured Exception Handling Functions\nStructured Exception Handling Overview\nRemarks\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3445,"title":"PVECTORED_EXCEPTION_HANDLER callback function (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["pvectored","exception","handler","callback","function","winnt","application","defined","that","serves","vectored","article02","2024","specify","this","address","when","calling","the","addvectoredexceptionhandler","type","defines","pointer","vectoredhandler","placeholder","for","name","exceptioninfo","pointers","structure","receives","record","return","control","point","which","occurred","continue","execution","0xffffffff"],"errorCode":"","eventId":"","severity":"Low","summary":"An application-defined function that serves as a vectored exception handler.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to PVECTORED_EXCEPTION_HANDLER callback function (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"PVECTORED_EXCEPTION_HANDLER\ncallback function (winnt.h)\nArticle02/22/2024\nAn application-defined function that serves as a vectored exception handler. Specify this\naddress when calling the AddVectoredExceptionHandler function. The\nPVECTORED_EXCEPTION_HANDLER type defines a pointer to this callback function.\nVectoredHandler is a placeholder for the application-defined name.\nC++\n[in] ExceptionInfo\nA pointer to an EXCEPTION_POINTERS structure that receives the exception record.\nTo return control to the point at which the exception occurred, return\nEXCEPTION_CONTINUE_EXECUTION (0xffffffff). To continue the handler search, return\nEXCEPTION_CONTINUE_SEARCH (0x0).\nThe handler should not call functions that acquire synchronization objects or allocate memory,\nbecause this can cause problems. Typically, the handler will simply access the exception record\nand return.\nSyntax\nPVECTORED_EXCEPTION_HANDLER PvectoredExceptionHandler;\nLONG PvectoredExceptionHandler(\n [in] _EXCEPTION_POINTERS *ExceptionInfo\n)\n{...}\nParameters\nReturn value\nRemarks\nRequirements\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nTarget Platform Windows\nHeader winnt.h (include Windows.h)\nEXCEPTION_POINTERS\nVectored Exception Handling\nﾉ Expand table\nSee also\nStructured Exception Handling Structures\nThe following structures are used with structured exception handling:\nEXCEPTION_POINTERS\nEXCEPTION_RECORD\n \n \nLast updated on 07/14/2025","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3446,"title":"EXCEPTION_POINTERS structure (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["exception","pointers","structure","winnt","contains","record","with","machine","independent","description","and","context","dependent","the","processor","time","article02","2024","exceptionrecord","pointer","that","contextrecord","specific","state","requirement","value","minimum","supported","client","windows","desktop","apps","only","server","2003","header","include","syntax","typedef","struct"],"errorCode":"","eventId":"","severity":"Low","summary":"Contains an exception record with a machine-independent description of an exception and a\ncontext record with a machine-dependent description of the processor context at the time of\nthe exception.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to EXCEPTION_POINTERS structure (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"EXCEPTION_POINTERS structure (winnt.h)\nArticle02/22/2024\nContains an exception record with a machine-independent description of an exception and a\ncontext record with a machine-dependent description of the processor context at the time of\nthe exception.\nC++\nExceptionRecord\nA pointer to an EXCEPTION_RECORD structure that contains a machine-independent\ndescription of the exception.\nContextRecord\nA pointer to a CONTEXT structure that contains a processor-specific description of the state of\nthe processor at the time of the exception.\nRequirement Value\nMinimum supported client Windows XP [desktop apps only]\nMinimum supported server Windows Server 2003 [desktop apps only]\nHeader winnt.h (include Windows.h)\nSyntax\ntypedef struct _EXCEPTION_POINTERS {\n PEXCEPTION_RECORD ExceptionRecord;\n PCONTEXT ContextRecord;\n} EXCEPTION_POINTERS, *PEXCEPTION_POINTERS;\nMembers\nRequirements\nﾉ Expand table\nSee also\nCONTEXT\nEXCEPTION_RECORD\nGetExceptionInformation","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3447,"title":"EXCEPTION_RECORD structure (winnt.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["exception","record","structure","winnt","exceptioncode","the","reason","occurred","article09","2022","describes","this","code","generated","hardware","specified","raiseexception","function","for","software","following","tables","codes","that","are","likely","occur","due","common","programming","errors","value","meaning","access","violation","thread","tried","read","from","write"],"errorCode":"","eventId":"","severity":"Low","summary":"C++\nExceptionCode\nThe reason the exception occurred.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to EXCEPTION_RECORD structure (winnt.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"EXCEPTION_RECORD structure (winnt.h)\nArticle09/01/2022\nDescribes an exception.\nC++\nExceptionCode\nThe reason the exception occurred. This is the code generated by a hardware exception, or the\ncode specified in the RaiseException function for a software-generated exception. The\nfollowing tables describes the exception codes that are likely to occur due to common\nprogramming errors.\nValue Meaning\nEXCEPTION_ACCESS_VIOLATION The thread tried to read from or write to a virtual address\nfor which it does not have the appropriate access.\nEXCEPTION_ARRAY_BOUNDS_EXCEEDED The thread tried to access an array element that is out of\nbounds and the underlying hardware supports bounds\nchecking.\nEXCEPTION_BREAKPOINT A breakpoint was encountered.\nEXCEPTION_DATATYPE_MISALIGNMENTThe thread tried to read or write data that is misaligned\non hardware that does not provide alignment. For\nexample, 16-bit values must be aligned on 2-byte\nboundaries; 32-bit values on 4-byte boundaries, and so\non.\nSyntax\ntypedef struct _EXCEPTION_RECORD {\n DWORD ExceptionCode;\n DWORD ExceptionFlags;\n struct _EXCEPTION_RECORD *ExceptionRecord;\n PVOID ExceptionAddress;\n DWORD NumberParameters;\n ULONG_PTR ExceptionInformation[EXCEPTION_MAXIMUM_PARAMETERS];\n} EXCEPTION_RECORD;\nMembers\nﾉ Expand table\nEXCEPTION_FLT_DENORMAL_OPERANDOne of the operands in a floating-point operation is\ndenormal. A denormal value is one that is too small to\nrepresent as a standard floating-point value.\nEXCEPTION_FLT_DIVIDE_BY_ZERO The thread tried to divide a floating-point value by a\nfloating-point divisor of zero.\nEXCEPTION_FLT_INEXACT_RESULT The result of a floating-point operation cannot be\nrepresented exactly as a decimal fraction.\nEXCEPTION_FLT_INVALID_OPERATION This exception represents any floating-point exception\nnot included in this list.\nEXCEPTION_FLT_OVERFLOW The exponent of a floating-point operation is greater\nthan the magnitude allowed by the corresponding type.\nEXCEPTION_FLT_STACK_CHECK The stack overflowed or underflowed as the result of a\nfloating-point operation.\nEXCEPTION_FLT_UNDERFLOW The exponent of a floating-point operation is less than\nthe magnitude allowed by the corresponding type.\nEXCEPTION_ILLEGAL_INSTRUCTION The thread tried to execute an invalid instruction.\nEXCEPTION_IN_PAGE_ERROR The thread tried to access a page that was not present,\nand the system was unable to load the page. For\nexample, this exception might occur if a network\nconnection is lost while running a program over the\nnetwork.\nEXCEPTION_INT_DIVIDE_BY_ZERO The thread tried to divide an integer value by an integer\ndivisor of zero.\nEXCEPTION_INT_OVERFLOW The result of an integer operation caused a carry out of\nthe most significant bit of the result.\nEXCEPTION_INVALID_DISPOSITION An exception handler returned an invalid disposition to\nthe exception dispatcher. Programmers using a highlevel language such as C should never encounter this\nexception.\nEXCEPTION_NONCONTINUABLE_EXCEPTIONThe thread tried to continue execution after a\nnoncontinuable exception occurred.\nEXCEPTION_PRIV_INSTRUCTION The thread tried to execute an instruction whose\noperation is not allowed in the current machine mode.\nEXCEPTION_SINGLE_STEP A trace trap or other single-instruction mechanism\nsignaled that one instruction has been executed.\nEXCEPTION_STACK_OVERFLOW The thread used up its stack.\nAnother exception code is likely to occur when debugging console processes. It does not arise\nbecause of a programming error. The DBG_CONTROL_C exception code occurs when CTRL+C\nis input to a console process that handles CTRL+C signals and is being debugged. This\nexception code is not meant to be handled by applications. It is raised only for the benefit of\nthe debugger, and is raised only when a debugger is attached to the console process.\nExceptionFlags\nThis member contains zero or more exception flags. The following table describes some of the\ncommonly seen exception flags. Exception flags not present in the following table should be\ntreated as reserved for system use.\nException flag Meaning\nEXCEPTION_NONCONTINUABLE The presence of this flag indicates that the exception is a\nnoncontinuable exception, whereas the absence of this flag\nindicates that the exception is a continuable exception. Any\nattempt to continue execution after a noncontinuable\nexception causes the\nEXCEPTION_NONCONTINUABLE_EXCEPTION exception.\nEXCEPTION_SOFTWARE_ORIGINATE This flag is reserved for system use.\nExceptionRecord\nA pointer to an associated EXCEPTION_RECORD structure. Exception records can be chained\ntogether to provide additional information when nested exceptions occur.\nExceptionAddress\nThe address where the exception occurred.\nNumberParameters\nThe number of parameters associated with the exception. This is the number of defined\nelements in the ExceptionInformation array.\nExceptionInformation[EXCEPTION_MAXIMUM_PARAMETERS]\nAn array of additional arguments that describe the exception. The RaiseException function can\nspecify this array of arguments. For most exception codes, the array elements are undefined.\nThe following table describes the exception codes whose array elements are defined.\nﾉ Expand table\nException code Meaning\nEXCEPTION_ACCESS_VIOLATION The first element of the array contains a read-write flag that\nindicates the type of operation that caused the access\nviolation. If this value is zero, the thread attempted to read the\ninaccessible data. If this value is 1, the thread attempted to\nwrite to an inaccessible address.\nIf this value is 8, the thread caused a user-mode data\nexecution prevention (DEP) violation.\nThe second array element specifies the virtual address of the\ninaccessible data.\nEXCEPTION_IN_PAGE_ERROR The first element of the array contains a read-write flag that\nindicates the type of operation that caused the access\nviolation. If this value is zero, the thread attempted to read the\ninaccessible data. If this value is 1, the thread attempted to\nwrite to an inaccessible address.\nIf this value is 8, the thread","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3448,"title":"CloseThreadWaitChainSession function (wct.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["closethreadwaitchainsession","function","wct","closes","the","specified","session","and","cancels","any","outstanding","asynchronous","operations","2024","wcthandle","handle","created","openthreadwaitchainsession","none","was","opened","mode","with","async","open","flag","after","their","callback","functions","have","been","called","returned","then","returns","for","example","see","using"],"errorCode":"","eventId":"","severity":"Low","summary":"Closes the specified WCT session and cancels any outstanding asynchronous operations.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to CloseThreadWaitChainSession function (wct.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"CloseThreadWaitChainSession function\n(wct.h)\n02/22/2024\nCloses the specified WCT session and cancels any outstanding asynchronous operations.\nC++\n[in] WctHandle\nA handle to the WCT session created by the OpenThreadWaitChainSession function.\nNone\nIf the WCT session was opened in asynchronous mode (with WCT_ASYNC_OPEN_FLAG), the\nfunction cancels any outstanding operations after their callback functions have been called and\nreturned, and then it returns.\nFor an example, see Using WCT.\nSyntax\nVOID CloseThreadWaitChainSession(\n [in] HWCT WctHandle\n);\nParameters\nReturn value\nRemarks\nExamples\nRequirements\nﾉ Expand table\nRequirement Value\nMinimum supported client Windows Vista [desktop apps only]\nMinimum supported server Windows Server 2008 [desktop apps only]\nTarget Platform Windows\nHeader wct.h\nLibrary Advapi32.lib\nDLL Advapi32.dll\nOpenThreadWaitChainSession\nWait Chain Traversal\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3449,"title":"GetThreadWaitChain function (wct.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["getthreadwaitchain","function","wct","retrieves","the","wait","chain","for","specified","thread","article10","2021","wcthandle","handle","session","created","openthreadwaitchainsession","optional","context","pointer","application","defined","structure","passed","callback","asynchronous","flags","retrieval","options","this","parameter","can","one","more","following","values","value","meaning","out","proc"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves the wait chain for the specified thread.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to GetThreadWaitChain function (wct.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"GetThreadWaitChain function (wct.h)\nArticle10/13/2021\nRetrieves the wait chain for the specified thread.\nC++\n[in] WctHandle\nA handle to the WCT session created by the OpenThreadWaitChainSession function.\n[in, optional] Context\nA pointer to an application-defined context structure to be passed to the callback function for\nan asynchronous session.\n[in] Flags\nThe wait chain retrieval options. This parameter can be one of more of the following values.\nValue Meaning\nWCT_OUT_OF_PROC_COM_FLAG Enumerates all threads of an out-of-proc MTA COM server to\nfind the correct thread identifier.\nWCT_OUT_OF_PROC_CS_FLAG Retrieves critical-section information from other processes.\nWCT_OUT_OF_PROC_FLAG Follows the wait chain into other processes. Otherwise, the\nfunction reports the first thread in a different process but does\nSyntax\nBOOL GetThreadWaitChain(\n [in] HWCT WctHandle,\n [in, optional] DWORD_PTR Context,\n [in] DWORD Flags,\n [in] DWORD ThreadId,\n [in, out] LPDWORD NodeCount,\n [out] PWAITCHAIN_NODE_INFO NodeInfoArray,\n [out] LPBOOL IsCycle\n);\nParameters\nﾉ Expand table\nnot retrieve additional information.\n[in] ThreadId\nThe identifier of the thread.\n[in, out] NodeCount\nOn input, a number from 1 to WCT_MAX_NODE_COUNT that specifies the number of nodes in\nthe wait chain. On return, the number of nodes retrieved. If the array cannot contain all the\nnodes of the wait chain, the function fails, GetLastError returns ERROR_MORE_DATA, and this\nparameter receives the number of array elements required to contain all the nodes.\nFor asynchronous sessions, check the value that is passed to the callback function. Do not free\nthe variable until the callback function has returned.\n[out] NodeInfoArray\nAn array of WAITCHAIN_NODE_INFO structures that receives the wait chain.\nFor asynchronous sessions, check the value that is passed to the callback function. Do not free\nthe array until the callback function has returned.\n[out] IsCycle\nIf the function detects a deadlock, this variable is set to TRUE; otherwise, it is set to FALSE.\nFor asynchronous sessions, check the value that is passed to the callback function. Do not free\nthe variable until the callback function has returned.\nIf the function succeeds, the return value is nonzero.\nIf the function fails, the return value is zero. To retrieve extended error information, call\nGetLastError.\nReturn code Description\nERROR_ACCESS_DENIED The caller did not have sufficient privilege to open a target\nthread.\nERROR_INVALID_PARAMETER One of the input parameters is invalid.\nReturn value\nﾉ Expand table\nERROR_IO_PENDING The WCT session was opened in asynchronous mode. The\nresults will be returned through the WaitChainCallback\ncallback function.\nERROR_MORE_DATA The NodeInfoArray buffer is not large enough to contain all\nthe nodes in the wait chain. The NodeCount parameter\ncontains the number of nodes in the chain. The wait chain\nreturned is still valid.\nERROR_NOT_SUPPORTED The operating system is not providing this service.\nERROR_OBJECT_NOT_FOUND The specified thread could not be located.\nERROR_TOO_MANY_THREADS The number of nodes exceeds WCT_MAX_NODE_COUNT. The\nwait chain returned is still valid.\nIf the session is asynchronous, the function returns FALSE and GetLastError returns\nERROR_IO_PENDING. To obtain the results, see the WaitChainCallback callback function.\nIf the specified thread is not blocked or is blocked on an unsupported synchronization element,\nthe function returns a single item in NodeInfoArray.\nThe caller must have the SE_DEBUG_NAME privilege. If the caller has insufficient privileges, the\nfunction fails if the first thread cannot be accessed. Otherwise, the last node in the array will\nhave its ObjectStatus member set to WctStatusNoAcces.\nIf any subset of nodes in the array forms a cycle, the function sets the IsCycle parameter to\nTRUE.\nWait chain information is dynamic; it was correct when the function was called but may be outof-date by the time it is reviewed by the caller.\nFor an example, see Using WCT.\nRemarks\nExamples\nRequirements\nﾉ Expand table\nRequirement Value\nMinimum supported client Windows Vista [desktop apps only]\nMinimum supported server Windows Server 2008 [desktop apps only]\nTarget Platform Windows\nHeader wct.h\nLibrary Advapi32.lib\nDLL Advapi32.dll\nOpenThreadWaitChainSession\nWAITCHAIN_NODE_INFO\nWait Chain Traversal\nWaitChainCallback\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3450,"title":"OpenThreadWaitChainSession function (wct.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["openthreadwaitchainsession","function","wct","flags","the","session","type","article02","2024","creates","new","this","parameter","can","one","following","values","value","meaning","synchronous","async","open","flag","asynchronous","optional","callback","pointer","waitchaincallback","succeeds","return","handle","newly","created","fails","null","get","extended","error","information","call"],"errorCode":"","eventId":"","severity":"Low","summary":"C++\n[in] Flags\nThe session type.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to OpenThreadWaitChainSession function (wct.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"OpenThreadWaitChainSession function\n(wct.h)\nArticle02/22/2024\nCreates a new WCT session.\nC++\n[in] Flags\nThe session type. This parameter can be one of the following values.\nValue Meaning\n0 A synchronous session.\nWCT_ASYNC_OPEN_FLAG An asynchronous session.\n[in, optional] callback\nIf the session is asynchronous, this parameter can be a pointer to a WaitChainCallback callback\nfunction.\nIf the function succeeds, the return value is a handle to the newly created session.\nIf the function fails, the return value is NULL. To get extended error information, call\nGetLastError.\nSyntax\nHWCT OpenThreadWaitChainSession(\n [in] DWORD Flags,\n [in, optional] PWAITCHAINCALLBACK callback\n);\nParameters\nﾉ Expand table\nReturn value\nWhen you have finished using the session, call the CloseThreadWaitChainSession function.\nFor an example, see Using WCT.\nRequirement Value\nMinimum supported client Windows Vista [desktop apps only]\nMinimum supported server Windows Server 2008 [desktop apps only]\nTarget Platform Windows\nHeader wct.h\nLibrary Advapi32.lib\nDLL Advapi32.dll\nCloseThreadWaitChainSession\nGetThreadWaitChain\nWait Chain Traversal\nWaitChainCallback\nRemarks\nExamples\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3451,"title":"RegisterWaitChainCOMCallback function (wct.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["registerwaitchaincomcallback","function","wct","register","com","callback","functions","for","2024","callstatecallback","the","address","cogetcallstate","activationstatecallback","cogetactivationstate","none","thread","blocked","call","can","retrieve","ownership","information","using","these","this","multiple","times","only","last","addresses","retrieved","are","used","example","see","syntax","void","pcogetcallstate","pcogetactivationstate"],"errorCode":"","eventId":"","severity":"Low","summary":"Register COM callback functions for WCT.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to RegisterWaitChainCOMCallback function (wct.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"RegisterWaitChainCOMCallback function\n(wct.h)\n02/22/2024\nRegister COM callback functions for WCT.\nC++\n[in] CallStateCallback\nThe address of the CoGetCallState function.\n[in] ActivationStateCallback\nThe address of the CoGetActivationState function.\nNone\nIf a thread is blocked on a COM call, WCT can retrieve COM ownership information using these\ncallback functions. If this function is callback multiple times, only the last addresses retrieved\nare used.\nFor an example, see Using WCT.\nSyntax\nVOID RegisterWaitChainCOMCallback(\n [in] PCOGETCALLSTATE CallStateCallback,\n [in] PCOGETACTIVATIONSTATE ActivationStateCallback\n);\nParameters\nReturn value\nRemarks\nExamples\nRequirement Value\nMinimum supported client Windows Vista [desktop apps only]\nMinimum supported server Windows Server 2008 [desktop apps only]\nTarget Platform Windows\nHeader wct.h\nLibrary Advapi32.lib\nDLL Advapi32.dll\nWait Chain Traversal\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3452,"title":"WAITCHAIN_NODE_INFO structure (wct.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["waitchain","node","info","structure","wct","represents","wait","chain","article09","2022","objecttype","the","object","type","this","member","one","following","values","from","enumeration","syntax","typedef","struct","status","objectstatus","union","wchar","objectname","objname","length","large","integer","timeout","bool","alertable","lockobject","dword","processid","threadid"],"errorCode":"","eventId":"","severity":"Low","summary":"Represents a node in a wait chain.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to WAITCHAIN_NODE_INFO structure (wct.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"WAITCHAIN_NODE_INFO structure\n(wct.h)\nArticle09/01/2022\nRepresents a node in a wait chain.\nC++\nObjectType\nThe object type. This member is one of the following values from the\nWCT_OBJECT_TYPE enumeration type.\nSyntax\ntypedef struct _WAITCHAIN_NODE_INFO {\n WCT_OBJECT_TYPE ObjectType;\n WCT_OBJECT_STATUS ObjectStatus;\n union {\n struct {\n WCHAR ObjectName[WCT_OBJNAME_LENGTH];\n LARGE_INTEGER Timeout;\n BOOL Alertable;\n } LockObject;\n struct {\n DWORD ProcessId;\n DWORD ThreadId;\n DWORD WaitTime;\n DWORD ContextSwitches;\n } ThreadObject;\n };\n} WAITCHAIN_NODE_INFO, *PWAITCHAIN_NODE_INFO;\nMembers\nWctCriticalSectionType\nWctSendMessageType\nWctMutexType\nObjectStatus\nThe object status. This member is one of the following values from the\nWCT_OBJECT_STATUS enumeration type.\nWctAlpcType\nWctComType\nWctThreadWaitType\nWctProcessWaitType\nWctThreadType\nWctComActivationType\nWctUnknownType\nWctStatusNoAccess\nWctStatusRunning\nWctStatusBlocked\nWctStatusPidOnly\nWctStatusPidOnlyRpcss\nWctStatusOwned\nWctStatusNotOwned\nWctStatusAbandoned\nLockObject\nLockObject.ObjectName[WCT_OBJNAME_LENGTH]\nThe name of the object. Object names are only available for certain object, such as\nmutexes. If the object does not have a name, this member is an empty string.\nLockObject.Timeout\nThis member is reserved for future use.\nLockObject.Alertable\nThis member is reserved for future use.\nThreadObject\nThreadObject.ProcessId\nThe process identifier.\nThreadObject.ThreadId\nThe thread identifier. For COM and ALPC, this member can be 0.\nThreadObject.WaitTime\nThe wait time.\nThreadObject.ContextSwitches\nThe number of context switches.\nRequirement Value\nMinimum supported client Windows Vista [desktop apps only]\nMinimum supported server Windows Server 2008 [desktop apps only]\nWctStatusUnknown\nWctStatusError\nRequirements\nﾉ Expand table\nFeedback\nWas this page helpful?\nRequirement Value\nHeader wct.h\nGetThreadWaitChain\nWaitChainCallback\nSee also\nYes No","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3453,"title":"PWAITCHAINCALLBACK callback function (wct.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["pwaitchaincallback","callback","function","wct","application","defined","that","receives","wait","chain","2021","specify","this","address","when","calling","the","openthreadwaitchainsession","type","defines","pointer","waitchaincallback","placeholder","for","name","wcthandle","handle","session","created","context","optional","structure","specified","getthreadwaitchain","callbackstatus","status","parameter","can","one","following"],"errorCode":"","eventId":"","severity":"Low","summary":"An application-defined callback function that receives a wait chain.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to PWAITCHAINCALLBACK callback function (wct.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"PWAITCHAINCALLBACK callback function\n(wct.h)\n10/05/2021\nAn application-defined callback function that receives a wait chain. Specify this address when\ncalling the OpenThreadWaitChainSession function.\nThe PWAITCHAINCALLBACK type defines a pointer to this callback function.\nWaitChainCallback is a placeholder for the application-defined function name.\nC++\nWctHandle\nA handle to the WCT session created by the OpenThreadWaitChainSession function.\nContext\nA optional pointer to an application-defined context structure specified by the\nGetThreadWaitChain function.\nCallbackStatus\nThe callback status. This parameter can be one of the following values, or one of the other\nsystem error codes.\nSyntax\nPWAITCHAINCALLBACK Pwaitchaincallback;\nVOID Pwaitchaincallback(\n HWCT WctHandle,\n DWORD_PTR Context,\n DWORD CallbackStatus,\n LPDWORD NodeCount,\n PWAITCHAIN_NODE_INFO NodeInfoArray,\n LPBOOL IsCycle\n)\n{...}\nParameters\nValue Meaning\nERROR_ACCESS_DENIED The caller did not have sufficient privilege to open a target\nthread.\nERROR_CANCELLED The asynchronous session was canceled by a call to the\nCloseThreadWaitChainSession function.\nERROR_MORE_DATA The NodeInfoArray buffer is not large enough to contain all\nthe nodes in the wait chain. The NodeCount parameter\ncontains the number of nodes in the chain. The wait chain\nreturned is still valid.\nERROR_OBJECT_NOT_FOUND The specified thread could not be located.\nERROR_SUCCESS The operation completed successfully.\nERROR_TOO_MANY_THREADS The number of nodes exceeds WCT_MAX_NODE_COUNT. The\nwait chain returned is still valid.\nNodeCount\nThe number of nodes retrieved, up to WCT_MAX_NODE_COUNT. If the array cannot contain all\nthe nodes of the wait chain, the function fails, CallbackStatus is ERROR_MORE_DATA, and this\nparameter receives the number of array elements required to contain all the nodes.\nNodeInfoArray\nAn array of WAITCHAIN_NODE_INFO structures that receives the wait chain.\nIsCycle\nIf the function detects a deadlock, this variable is set to TRUE; otherwise, it is set to FALSE.\nNone\nﾉ Expand table\nReturn value\nRequirements\nﾉ Expand table\nRequirement Value\nMinimum supported client Windows Vista [desktop apps only]\nMinimum supported server Windows Server 2008 [desktop apps only]\nTarget Platform Windows\nHeader wct.h\nGetThreadWaitChain\nOpenThreadWaitChainSession\nWAITCHAIN_NODE_INFO\nSee also\nIntel AVX\nIntel Advanced Vector Extensions (AVX) is a 256-bit SIMD floating point vector extension of\nIntel architecture. It includes extensions to both instruction and register sets.\nMicrosoft has developed some API enhancements, such as XState functions, that enable\napplications to access and manipulate extended processor feature information and state,\nincluding Intel AVX.\nTopic Description\nWorking with\nXState Context\nThis document contains an example that demonstrates how to use the XState\ncontext functions to retrieve and set extended features on a thread.\nAVX Functions Intel AVX functions\nIntel AVX is designed for use by applications that are strongly floating point compute intensive\nand can be vectorized. Example applications include audio processing and audio codecs, image\nand video editing applications, financial services analysis and modeling software, and\nmanufacturing and engineering software.\nLast updated on 07/14/2025\nPurpose\nIn this section\nﾉ Expand table\nDeveloper audience\nWorking with XState Context\nThis document contains an example that demonstrates how to use the XState context functions\nto retrieve and set extended features on a thread. The following examples manipulate\nIntel Advanced Vector Extensions (AVX) state which is defined by FeatureId 2 (Feature Mask 4).\nIntel AVX is defined in the \"Intel Advanced Vector Extensions Programming Reference\"\navailable from https://go.microsoft.com/fwlink/p/?linkid=212716.\nWindows 7 with SP1: The AVX API is first implemented on Windows 7 with SP1. Since there is\nno SDK for Windows 7 with SP1, that means there are no available headers and library files to\nwork with. In this situation, a caller must declare the needed functions from this documentation\nand get pointers to them using GetModuleHandle on \"Kernel32.dll\", followed by calls to\nGetProcAddress.\nC++\n#include <stdlib.h>\n#include <stdio.h>\n#include <tchar.h>\n#include <windows.h>\n#include <winerror.h>\n// Windows 7 SP1 is the first version of Windows to support the AVX API.\n// The value for CONTEXT_XSTATE has changed between Windows 7 and\n// Windows 7 SP1 and greater.\n// While the value will be correct for future SDK headers, we need to set \n// this value manually when building with a Windows 7 SDK for running on \n// Windows 7 SPI OS bits.\n#undef CONTEXT_XSTATE\n#if defined(_M_X64)\n#define CONTEXT_XSTATE (0x00100040)\n#else\n#define CONTEXT_XSTATE (0x00010040)\n#endif\n// Since the AVX API is not declared in the Windows 7 SDK headers and \n// since we don't have the proper libs to work with, we will declare \n// the API as function pointers and get them with GetProcAddress calls \n// from kernel32.dll. We also need to set some #defines.\n#define XSTATE_AVX (XSTATE_GSSE)\n#define XSTATE_MASK_AVX (XSTATE_MASK_GSSE)\ntypedef DWORD64 (WINAPI *PGETENABLEDXSTATEFEATURES)();\nPGETENABLEDXSTATEFEATURES pfnGetEnabledXStateFeatures = NULL;\ntypedef BOOL (WINAPI *PINITIALIZECONTEXT)(PVOID Buffer, DWORD ContextFlags,\nPCONTEXT* Context, PDWORD ContextLength);\nPINITIALIZECONTEXT pfnInitializeContext = NULL;\n \ntypedef BOOL (WINAPI *PGETXSTATEFEATURESMASK)(PCONTEXT Context, PDWORD64 \nFeatureMask);\nPGETXSTATEFEATURESMASK pfnGetXStateFeaturesMask = NULL;\ntypedef PVOID (WINAPI *LOCATEXSTATEFEATURE)(PCONTEXT Context, DWORD FeatureId, \nPDWORD Length);\nLOCATEXSTATEFEATURE pfnLocateXStateFeature = NULL;\n \ntypedef BOOL (WINAPI *SETXSTATEFEATURESMASK)(PCONTEXT Context, DWORD64 FeatureMask);\nSETXSTATEFEATURESMASK pfnSetXStateFeaturesMask = NULL;\n \nVOID\nPrintThreadAvxState (\n __in HANDLE hThread\n )\n{\n PVOID Buffer;\n PCONTEXT Context;\n DWORD ContextSize;\n DWORD64 FeatureMask;\n DWORD FeatureLength;\n ULONG Index;\n BOOL S","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3454,"title":"CopyContext function (winbase.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["copycontext","function","winbase","copies","source","context","structure","including","any","xstate","onto","initialized","destination","2024","out","pointer","that","receives","the","copied","from","should","calling","initializecontext","before","this","contextflags","flags","specifying","pieces","will","into","must","subset","specified","when","which","copy","processor","data"],"errorCode":"","eventId":"","severity":"Low","summary":"Copies a source context structure (including any XState) onto an initialized destination context\nstructure.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to CopyContext function (winbase.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"CopyContext function (winbase.h)\n02/22/2024\nCopies a source context structure (including any XState) onto an initialized destination context\nstructure.\nC++\n[in, out] Destination\nA pointer to a CONTEXT structure that receives the context copied from the Source. The\nCONTEXT structure should be initialized by calling InitializeContext before calling this function.\n[in] ContextFlags\nFlags specifying the pieces of the Source CONTEXT structure that will be copied into the\ndestination. This must be a subset of the ContextFlags specified when calling InitializeContext\non the Destination CONTEXT.\n[in] Source\nA pointer to a CONTEXT structure from which to copy processor context data.\nThis function returns TRUE if the context was copied successfully, otherwise FALSE. To get\nextended error information, call GetLastError.\nSyntax\nBOOL CopyContext(\n [in, out] PCONTEXT Destination,\n [in] DWORD ContextFlags,\n [in] PCONTEXT Source\n);\nParameters\nReturn value\nRemarks\nThe function copies data from the Source CONTEXT over the corresponding data in the\nDestination CONTEXT, including extended context if any is present. The Destination CONTEXT\nmust have been initialized with InitializeContext to ensure proper alignment and initialization. If\nany data is present in the Destination CONTEXT and the corresponding flag is not set in the\nSource CONTEXT or in the ContextFlags parameter, the data remains valid in the Destination.\nWindows 7 with SP1 and Windows Server 2008 R2 with SP1: The AVX API is first implemented\non Windows 7 with SP1 and Windows Server 2008 R2 with SP1 . Since there is no SDK for SP1,\nthat means there are no available headers and library files to work with. In this situation, a\ncaller must declare the needed functions from this documentation and get pointers to them\nusing GetModuleHandle on \"Kernel32.dll\", followed by calls to GetProcAddress. See Working\nwith XState Context for details.\nRequirement Value\nMinimum supported client Windows 7 with SP1 [desktop apps only]\nMinimum supported server Windows Server 2008 R2 with SP1 [desktop apps only]\nTarget Platform Windows\nHeader winbase.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nCONTEXT\nInitializeContext\nIntel AVX\nWorking with XState Context\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3455,"title":"GetEnabledXStateFeatures function (winbase.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["getenabledxstatefeatures","function","winbase","gets","mask","enabled","xstate","features","x86","x64","processors","2021","the","definition","feature","bits","are","processor","vendor","specific","please","refer","relevant","reference","manuals","for","additional","information","particular","this","returns","bitmask","which","each","bit","represents","that","system","application","should"],"errorCode":"","eventId":"","severity":"Low","summary":"Gets a mask of enabled XState features on x86 or x64 processors.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to GetEnabledXStateFeatures function (winbase.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"GetEnabledXStateFeatures function\n(winbase.h)\n06/29/2021\nGets a mask of enabled XState features on x86 or x64 processors.\nThe definition of XState feature bits are processor vendor specific. Please refer to the relevant\nprocessor reference manuals for additional information on a particular feature.\nC++\nThis function returns a bitmask in which each bit represents an XState feature that is enabled\non the system.\nAn application should call this function to determine what features are present and enabled on\nthe system before using an XState processor feature or attempting to manipulate XState\ncontexts. Bits 0 and 1 refer to the X87 FPU and the presence of SSE registers, respectively. The\nmeanings of specific feature bits beyond 0 and 1 are defined in the Programmer Reference\nManuals released by the processor vendors.\n \nWindows 7 with SP1 and Windows Server 2008 R2 with SP1: The AVX API is first implemented\non Windows 7 with SP1 and Windows Server 2008 R2 with SP1 . Since there is no SDK for SP1,\nthat means there are no available headers and library files to work with. In this situation, a\ncaller must declare the needed functions from this documentation and get pointers to them\nSyntax\nDWORD64 GetEnabledXStateFeatures();\nReturn value\nRemarks\nNote Not all features supported by a processor may be enabled on the system. Using a\nfeature which is not enabled may result in exceptions or undefined behavior.\nusing GetModuleHandle on \"Kernel32.dll\", followed by calls to GetProcAddress. See Working\nwith XState Context for details.\nRequirement Value\nMinimum supported client Windows 7 with SP1 [desktop apps | UWP apps]\nMinimum supported server Windows Server 2008 R2 with SP1 [desktop apps | UWP apps]\nTarget Platform Windows\nHeader winbase.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nIntel AVX\nWorking with XState Context\nRequirements\nﾉ Expand table\nSee also\nGetXStateFeaturesMask function (winbase.h)\nReturns the mask of XState features set within a CONTEXT structure.\nC++\n[in] Context\nA pointer to a CONTEXT structure that has been initialized with InitializeContext.\n[out] FeatureMask\nA pointer to a variable that receives the mask of XState features which are present in the specified\nCONTEXT structure.\nThis function returns TRUE if successful, otherwise FALSE.\nThe GetXStateFeaturesMask function returns the mask of valid features in the specified context.\nIf a CONTEXT is to be passed to GetThreadContext or Wow64GetThreadContext, the application\nmust call SetXStateFeaturesMask to set which features are to be retrieved.\nGetXStateFeaturesMask should then be called on the CONTEXT returned by GetThreadContext\nor Wow64GetThreadContext to determine which feature areas contain valid data. If a particular\nfeature bit is not set, the corresponding state is in a processor-specific INITIALIZED state and the\ncontents of the feature area retrieved by LocateXStateFeature are undefined.\nSyntax\nBOOL GetXStateFeaturesMask(\n [in] PCONTEXT Context,\n [out] PDWORD64 FeatureMask\n);\nParameters\nReturn value\nRemarks\nThe definition of XState features are processor vendor specific. Please refer to the relevant\nprocessor reference manuals for additional information on a particular feature.\n \nWindows 7 with SP1 and Windows Server 2008 R2 with SP1: The AVX API is first implemented\non Windows 7 with SP1 and Windows Server 2008 R2 with SP1 . Since there is no SDK for SP1,\nthat means there are no available headers and library files to work with. In this situation, a caller\nmust declare the needed functions from this documentation and get pointers to them using\nGetModuleHandle on \"Kernel32.dll\", followed by calls to GetProcAddress. See Working with\nXState Context for details.\nRequirement Value\nMinimum supported client Windows 7 with SP1 [desktop apps | UWP apps]\nMinimum supported server Windows Server 2008 R2 with SP1 [desktop apps | UWP apps]\nTarget Platform Windows\nHeader winbase.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nCONTEXT\nGetThreadContext\nIntel AVX\nSetXStateFeaturesMask\nNote The value returned by GetXStateFeaturesMask on a CONTEXT after a context\noperation will always be a subset of the mask specified in a call to SetXStateFeaturesMask\nprior to the context operation.\nRequirements\nﾉ Expand table\nSee also\nWorking with XState Context\nWow64GetThreadContext\nLast updated on 08/23/2022","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3456,"title":"InitializeContext function (winbase.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["initializecontext","function","winbase","initializes","context","structure","inside","buffer","with","the","necessary","size","and","alignment","2021","out","optional","pointer","within","which","initialize","this","parameter","can","null","determine","required","hold","record","specified","contextflags","value","indicating","portions","should","initialized","influences","variable","receives","address"],"errorCode":"","eventId":"","severity":"Low","summary":"Initializes a CONTEXT structure inside a buffer with the necessary size and alignment.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to InitializeContext function (winbase.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"InitializeContext function (winbase.h)\n10/13/2021\nInitializes a CONTEXT structure inside a buffer with the necessary size and alignment.\nC++\n[out, optional] Buffer\nA pointer to a buffer within which to initialize a CONTEXT structure. This parameter can be\nNULL to determine the buffer size required to hold a context record with the specified\nContextFlags.\n[in] ContextFlags\nA value indicating which portions of the Context structure should be initialized. This parameter\ninfluences the size of the initialized Context structure.\n \n[out, optional] Context\nA pointer to a variable which receives the address of the initialized CONTEXT structure within\nthe Buffer.\nSyntax\nBOOL InitializeContext(\n [out, optional] PVOID Buffer,\n [in] DWORD ContextFlags,\n [out, optional] PCONTEXT *Context,\n [in, out] PDWORD ContextLength\n);\nParameters\nNote CONTEXT_XSTATE is not part of CONTEXT_FULL or CONTEXT_ALL. It must be\nspecified separately if an XState context is desired.\nNote Due to alignment requirements of CONTEXT structures, the value returned in\nContext may not be at the beginning of the supplied buffer.\n[in, out] ContextLength\nOn input, specifies the length of the buffer pointed to by Buffer, in bytes. If the buffer is not\nlarge enough to contain the specified portions of the CONTEXT, the function fails, GetLastError\nreturns ERROR_INSUFFICIENT_BUFFER, and ContextLength is set to the required size of the\nbuffer. If the function fails with an error other than ERROR_INSUFFICIENT_BUFFER, the\ncontents of ContextLength are undefined.\nThis function returns TRUE if successful, otherwise FALSE. To get extended error information,\ncall GetLastError.\nInitializeContext can be used to initialize a CONTEXT structure within a buffer with the required\nsize and alignment characteristics. This routine is required if the CONTEXT_XSTATE ContextFlag\nis specified since the required context size and alignment may change depending on which\nprocessor features are enabled on the system.\nFirst, call this function with the ContextFlags parameter set to the maximum number of features\nyou will be using and the Buffer parameter to NULL. The function returns the required buffer\nsize in bytes in the ContextLength parameter. Allocate enough space for the data in the Buffer\nand call the function again to initialize the Context. Upon successful completion of this routine,\nthe ContextFlags member of the Context structure is initialized, but the remaining contents of\nthe structure are undefined. Some bits specified in the ContextFlags parameter may not be set\nin Context->ContextFlags if they are not supported by the system. Applications may\nsubsequently remove, but must never add, bits from the ContextFlags member of CONTEXT.\nWindows 7 with SP1 and Windows Server 2008 R2 with SP1: The AVX API is first implemented\non Windows 7 with SP1 and Windows Server 2008 R2 with SP1 . Since there is no SDK for SP1,\nthat means there are no available headers and library files to work with. In this situation, a\ncaller must declare the needed functions from this documentation and get pointers to them\nusing GetModuleHandle on \"Kernel32.dll\", followed by calls to GetProcAddress. See Working\nwith XState Context for details.\nReturn value\nRemarks\nRequirements\nRequirement Value\nMinimum supported client Windows 7 with SP1 [desktop apps | UWP apps]\nMinimum supported server Windows Server 2008 R2 with SP1 [desktop apps | UWP apps]\nTarget Platform Windows\nHeader winbase.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nCONTEXT\nCopyContext\nIntel AVX\nWorking with XState Context\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3457,"title":"LocateXStateFeature function (winbase.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["locatexstatefeature","function","winbase","retrieves","pointer","the","processor","state","for","xstate","feature","within","context","structure","2023","definition","bits","are","vendor","specific","please","refer","relevant","reference","manuals","additional","information","particular","containing","retrieve","set","this","should","have","been","initialized","with","initializecontext","flag","contextflags"],"errorCode":"","eventId":"","severity":"Low","summary":"Retrieves a pointer to the processor state for an XState feature within a CONTEXT structure.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to LocateXStateFeature function (winbase.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"LocateXStateFeature function (winbase.h)\n03/03/2023\nRetrieves a pointer to the processor state for an XState feature within a CONTEXT structure.\nThe definition of XState feature bits are processor vendor specific. Please refer to the relevant\nprocessor reference manuals for additional information on a particular feature.\nC++\n[in] Context\nA pointer to a CONTEXT structure containing the state to retrieve or set. This CONTEXT should\nhave been initialized with InitializeContext with the CONTEXT_XSTATE flag set in the\nContextFlags parameter.\n[in] FeatureId\nThe number of the feature to locate within the CONTEXT structure.\n[out, optional] Length\nA pointer to a variable which receives the length of the feature area in bytes. The contents of\nthis variable are undefined if this function returns NULL.\nIf the specified feature is supported by the system and the specified CONTEXT structure has\nbeen initialized with the CONTEXT_XSTATE flag, this function returns a pointer to the feature\narea for the specified feature. The contents and layout of this area is processor-specific.\nSyntax\nPVOID LocateXStateFeature(\n [in] PCONTEXT Context,\n [in] DWORD FeatureId,\n [out, optional] PDWORD Length\n);\nParameters\nReturn value\nIf the CONTEXT_XSTATE flag is not set in the CONTEXT structure or the FeatureID is not\nsupported by the system, the return value is NULL. No additional error information is available.\nThe LocateXStateFeature function must be used to find an individual XState feature within an\nextensible CONTEXT structure. Features are not necessarily contiguous in memory and\napplications should not assume the offset between two consecutive features will remain\nconstant in the future.\nThe FeatureID parameter of the function corresponds to a bit within the feature mask. For\nexample, FeatureId 2 corresponds to a FeatureMask of 4 in SetXStateFeaturesMask. FeatureID\nvalues of 0 and 1 correspond to X87 FPU state and SSE state, respectively.\nIf you are setting XState on a thread via the SetThreadContext or Wow64SetThreadContext\nAPIs, you must also call SetXStateFeaturesMask on the CONTEXT structure with the mask value\nof the filled-in feature to mark the feature as active.\nWindows 7 with SP1 and Windows Server 2008 R2 with SP1: The AVX API is first implemented\non Windows 7 with SP1 and Windows Server 2008 R2 with SP1 . Since there is no SDK for SP1,\nthat means there are no available headers and library files to work with. In this situation, a\ncaller must declare the needed functions from this documentation and get pointers to them\nusing GetModuleHandle on \"Kernel32.dll\", followed by calls to GetProcAddress. See Working\nwith XState Context for details.\nRequirement Value\nMinimum supported client Windows 7 with SP1 [desktop apps | UWP apps]\nMinimum supported server Windows Server 2008 R2 with SP1 [desktop apps | UWP apps]\nTarget Platform Windows\nHeader winbase.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nRemarks\nRequirements\nﾉ Expand table\nCONTEXT\nIntel AVX\nSetThreadContext\nSetXStateFeaturesMask\nWorking with XState Context\nWow64SetThreadContext\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3458,"title":"SetXStateFeaturesMask function (winbase.h)","category":"PowerShell","product":"Windows Debugging API","tags":["Windows Debugging","Win32 API","Developer Reference"],"keywords":["setxstatefeaturesmask","function","winbase","sets","the","mask","xstate","features","set","within","context","structure","2024","out","pointer","that","has","been","initialized","with","initializecontext","featuremask","specified","this","returns","true","successful","otherwise","false","valid","before","calling","getthreadcontext","wow64getthreadcontext","setthreadcontext","wow64setthreadcontext","application","must","call","specify"],"errorCode":"","eventId":"","severity":"Low","summary":"Sets the mask of XState features set within a CONTEXT structure.","rootCause":"This is a Windows debugging and error-handling reference, not a standalone error condition. Use it to understand or instrument application behavior during diagnosis.","resolution":"1. Confirm the reference applies to the target Windows version and process architecture.\n2. Review documented prerequisites, return values, and error handling.\n3. Capture the last-error code immediately when an API call fails.\n4. Reproduce and validate the behavior in a controlled environment.","emailScript":"Hello,\n\nWe reviewed the issue related to SetXStateFeaturesMask function (winbase.h).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. This diagnostic reference helps us identify the application failure and normally requires no action from you.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work before diagnostic testing.\n2. Leave the affected application available unless IT Support asks you to close it.\n3. Tell IT Support what action triggers the problem.\n4. No additional action is required unless instructions are provided.","notes":"SetXStateFeaturesMask function\n(winbase.h)\n02/22/2024\nSets the mask of XState features set within a CONTEXT structure.\nC++\n[in, out] Context\nA pointer to a CONTEXT structure that has been initialized with InitializeContext.\n[in] FeatureMask\nA mask of XState features to set in the specified CONTEXT structure.\nThis function returns TRUE if successful, otherwise FALSE.\nThe SetXStateFeaturesMask function sets the mask of valid features in the specified context.\nBefore calling GetThreadContext, Wow64GetThreadContext, SetThreadContext, or\nWow64SetThreadContext the application must call SetXStateFeaturesMask to specify which\nset of features to retrieve or set. The system silently ignores any feature specified in the\nFeatureMask which is not enabled on the processor.\nWindows 7 with SP1 and Windows Server 2008 R2 with SP1: The AVX API is first implemented\non Windows 7 with SP1 and Windows Server 2008 R2 with SP1 . Since there is no SDK for SP1,\nthat means there are no available headers and library files to work with. In this situation, a\nSyntax\nBOOL SetXStateFeaturesMask(\n [in, out] PCONTEXT Context,\n [in] DWORD64 FeatureMask\n);\nParameters\nReturn value\nRemarks\ncaller must declare the needed functions from this documentation and get pointers to them\nusing GetModuleHandle on \"Kernel32.dll\", followed by calls to GetProcAddress. See Working\nwith XState Context for details.\nRequirement Value\nMinimum supported client Windows 7 with SP1 [desktop apps only]\nMinimum supported server Windows Server 2008 R2 with SP1 [desktop apps only]\nTarget Platform Windows\nHeader winbase.h (include Windows.h)\nLibrary Kernel32.lib\nDLL Kernel32.dll\nCONTEXT\nGetThreadContext\nIntel AVX\nSetThreadContext\nWorking with XState Context\nWow64GetThreadContext\nWow64SetThreadContext\nRequirements\nﾉ Expand table\nSee also","sourceDocument":"windows-win32-debug.pdf","platforms":["windows"],"vendors":["Windows Debugging API"],"technologies":["Windows Debugging","Win32 API","Developer Reference"],"aliases":[]},{"id":3459,"title":"Common Tasks","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["common","tasks","rundll32","exe","advapi32","dll","processidletasks","dism","online","cleanup","image","scanhealth","restorehealth","sfc","scannow","defrag","chkdsk"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for common tasks. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Common Tasks.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"Rundll32.exe advapi32.dll,ProcessIdleTasks\nDISM.exe /Online /Cleanup-image /Scanhealth\nDISM.exe /Online /Cleanup-image /Restorehealth\nsfc/scannow\ndefrag c: -b\nchkdsk /f /r c:","commands":["Rundll32.exe advapi32.dll,ProcessIdleTasks","DISM.exe /Online /Cleanup-image /Scanhealth","DISM.exe /Online /Cleanup-image /Restorehealth","sfc /scannow","defrag c: -b","chkdsk /f /r c:"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3460,"title":"Advanced Startup Options","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["advanced","startup","options","shut","down","your","computer","type","shutdown","restart","log","off"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for advanced startup options. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Advanced Startup Options.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"To shut down your computer, type shutdown /s\nTo restart your computer, type shutdown /r\nTo log off your computer type shutdown /l","commands":[],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3461,"title":"enable or disable the Built-in Admin Account","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["enable","disable","the","built","admin","account","net","user","administrator","active","yes"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for enable or disable the built-in admin account. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to enable or disable the Built-in Admin Account.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"net user administrator /active:yes\nnet user administrator active:no","commands":["net user administrator /active:yes","net user administrator /active:no"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3462,"title":"Find SID of Current User using \"WhoAmI\" command","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["find","sid","current","user","using","whoami","command","all","users","wmic","useraccount","open","cmd","exe","administrator","enter","get","domain","name"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for find sid of current user using \"whoami\" command. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Find SID of Current User using \"WhoAmI\" command.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"whoami /user\nTo Find SID of All Users using \"wmic useraccount\" command, open cmd.exe as Administrator & enter:\nwmic useraccount get domain,name,sid","commands":["whoami /user","wmic useraccount get domain,name,sid"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3463,"title":"Add localservice and networkservice to your Administrator group","category":"Networking","product":"Microsoft Windows","tags":["Networking","Command Reference","Technician Fix"],"keywords":["add","localservice","and","networkservice","your","administrator","group","net","localgroup","administrators"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for add localservice and networkservice to your administrator group. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Add localservice and networkservice to your Administrator group.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"net localgroup administrators localservice /add\nnet localgroup administrators networkservice /add","commands":["net localgroup administrators localservice /add","net localgroup administrators networkservice /add"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Networking","Command Reference","Technician Fix"],"aliases":[]},{"id":3464,"title":"Powercfg command-line options","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["powercfg","command","line","options","hibernate","list","displays","help","information","about","parameters","energy","analyzes","the","system","for","common","efficiency","battery","life","problems","delete","desired","power","plan","example","e9a42b02","d5df","448d","aa00","03f14749eb61","restore","default","scheme","restoredefaultschemes","guid","381b4222","f694","41f0","9685"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for powercfg command-line options. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Powercfg command-line options.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"powercfg /hibernate on\npowercfg List\npowercfg /? = Displays help-information about command-line parameters.\npowercfg /energy = Analyzes the system for common energy-efficiency & battery life problems.\nTo delete a desired power plan (example):\npowercfg -delete e9a42b02-d5df-448d-aa00-03f14749eb61\nTo restore Default Power Scheme:\npowercfg -restoredefaultschemes\nPower Scheme GUID: 381b4222-f694-41f0-9685-ff5bb260df2e (Balanced)\nPower Scheme GUID: 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c (High Performance)\nPower Scheme GUID: a1841308-3541-4fab-bc81-f71556f20b4a (Energy Saving)","commands":["powercfg /hibernate on","powercfg List","powercfg /? = Displays help-information about command-line parameters.","powercfg /energy = Analyzes the system for common energy-efficiency & battery life problems.","powercfg -delete e9a42b02-d5df-448d-aa00-03f14749eb61","powercfg -restoredefaultschemes"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3465,"title":"Disable Hibernation","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["disable","hibernation","powercfg","exe","hibernate","off"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for disable hibernation. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Disable Hibernation.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"powercfg.exe /hibernate off","commands":["powercfg.exe /hibernate off"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3466,"title":"Force pending idle tasks to be executed immediately","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["force","pending","idle","tasks","executed","immediately","rundll32","exe","advapi32","dll","processidletasks"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for force pending idle tasks to be executed immediately. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Force pending idle tasks to be executed immediately.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"Rundll32.exe advapi32.dll,ProcessIdleTasks","commands":["Rundll32.exe advapi32.dll,ProcessIdleTasks"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3467,"title":"Disable Superfetch on Windows 10","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["disable","superfetch","windows","type","and","then","click","services","the","start","menu","select","sysmain","list","stop","service","this","will","deactivate","afterwards","you","can","evaluate","your","system","works","any","better"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for disable superfetch on windows 10. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Disable Superfetch on Windows 10.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"Type, and then click on \"Services\" in the Start menu.\nSelect \"SysMain\" in the services list and click on \"Stop the service\".\nThis will deactivate Superfetch. Afterwards you can evaluate if your system works any better.","commands":[],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3468,"title":"How to Disable Prefetch, open Registry Editor and go to the following location","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["how","disable","prefetch","open","registry","editor","and","the","following","location","hkey","local","machine","system","currentcontrolset","control","session","manager","memory","management","prefetchparameters","double","click","enableprefetcher","this","key","value","data","put","turn","off","here","are","other","available","settings","from","application","launch","prefetching"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for how to disable prefetch, open registry editor and go to the following location. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to How to Disable Prefetch, open Registry Editor and go to the following location.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"\"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Session Manager\\Memory Management\\PrefetchParameters\"\nDouble-click on \"EnablePrefetcher\" to open this key and in \"Value data\" put \"0\" to turn Prefetch off.\nHere are the other available settings from 1-3:\n1 = Application launch prefetching enabled\n2 = Boot prefetching enabled\n3 = Applaunch and Boot enabled (Optimal and Default)\nBoth EnablePrefetcher and EnableSuperfetch keys default value = 3.","commands":[],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3469,"title":"re-create Prefetch (layout.ini)","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["create","prefetch","layout","ini","start","wait","rundll32","exe","advapi32","dll","processidletasks","this","command","recreates","windows","and","then","defrags","well","puts","them","meg","pieces","every","file","listed","inside","readyboot","uses","cache","files","for","booting","faster"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for re-create prefetch (layout.ini). Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to re-create Prefetch (layout.ini).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"start /wait rundll32.exe advapi32.dll,ProcessIdleTasks\nThis command recreates c:\\windows\\prefetch\\layout.ini, and then defrags (well puts them in 64 meg pieces) every file listed inside. Readyboot uses it to cache files for booting faster.","commands":["start /wait rundll32.exe advapi32.dll,ProcessIdleTasks"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3470,"title":"Set SuperFetch to cache Systems Files only, or other options","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["set","superfetch","cache","systems","files","only","other","options","open","regedit","exe","through","the","start","menu","search","run","box","and","browse","down","following","key","hkey","local","machine","system","currentcontrolset","control","session","manager","memory","management","prefetchparameters","find","enableprefetcher","right","hand","pane","change"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for set superfetch to cache systems files only, or other options. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Set SuperFetch to cache Systems Files only, or other options.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"Open regedit.exe through the start menu search or run box and browse down to the following key:\n\"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\ Session Manager\\Memory Management\\PrefetchParameters\"\nFind the EnablePrefetcher key on the right-hand pane, and change the value to one of these options:\nDisable Caching: 0\nCache Applications Only: 1\nCache Boot Files Only: 2\nCache Everything (default): 3\nYou'll have to restart your computer before this takes any effect.\nYou could consider clearing out the \\Windows\\Prefetch folder after making this change to start with a fresh cache, but keep in mind that the next boot will probably be slower since Windows will have to cache everything again.","commands":[],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3471,"title":"Disable virtual memory","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["disable","virtual","memory","windows","working","enabled","default","used","when","the","primary","ram","already","completely","occupied","nonetheless","your","doesn","have","ssd","use","adversely","influences","performance","for","this","situation","recommended","extra","speed","process","hard","drive","type","view","advanced","system","settings","search","bar"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for disable virtual memory. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Disable virtual memory.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"In Windows 10, virtual working memory is enabled by default. It is used when the primary memory (RAM) is already completely occupied. Nonetheless, if your Windows PC doesn't have an SSD, the use of virtual memory adversely influences performance. For this situation, it is recommended to disable this extra memory to speed up the process of the hard drive.\nType \"View advanced system settings\" in the search bar and open it.\nA \"System Properties\" dialog will open, with the selected tab \"Advanced Options\".\nIn the \"Advanced Options\" click the button \"Settings\", in the \"Performance\" section.\nThe \"Performance Options\" window will then open. Click again on the \"Advanced\" tab and then on the \"Change\" button, in the \"Virtual Memory\" section.\nFirst, uncheck the \"Automatically manage paging file size for all drives\" option. At that point select the option:\n\"No paging file.\"\nTo accept the settings and deactivate virtual memory, confirm the selection by pressing the \"Apply/OK\" button.","commands":[],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3472,"title":"In Windows 10 to restore Components","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["windows","restore","components","dism","exe","online","cleanup","image","scanhealth","checkhealth","restorehealth","prompts","for","sources","file","mount","insert","installation","media","locate","install","wim","esd","folder","substitute","its","path","the","following","command","source","full","example","you","have","temp","was","created","extract","convert"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for in windows 10 to restore components. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to In Windows 10 to restore Components.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"DiSM.exe /Online /Cleanup-image /Scanhealth\nDISM.exe /Online /Cleanup-image /Checkhealth\nDISM.exe /Online /Cleanup-image /Restorehealth\nIf it prompts for Sources file, mount or insert Windows 10 installation media, locate install.wim or .esd file in Sources folder, substitute its path in the following command:\nDism /Online /Cleanup-Image /RestoreHealth /Source:wim:Full Path to install.wim file:1\n(for example: Dism /Online /Cleanup-Image /RestoreHealth /Source:wim:H:\\Sources\\Install.wim:1)\nOr if you have an .esd file:\nDism /Online /Cleanup-Image /RestoreHealth /Source:esd:Full Path to install.esd file:1\nDism /Online /Cleanup-Image /RestoreHealth /Source:esd:\\sources\\install.esd\nOr if you have an .wim file (Temp was created to extract .wim as a convert of .esd & is just another example:\nDism /Online /Cleanup-Image /RestoreHealth /Source:wim:E:\\Win10_ISO\\sources\\install.wim","commands":["DiSM.exe /Online /Cleanup-image /Scanhealth","DISM.exe /Online /Cleanup-image /Checkhealth","DISM.exe /Online /Cleanup-image /Restorehealth","Dism /Online /Cleanup-Image /RestoreHealth /Source:wim:Full Path to install.wim file:1","Dism /Online /Cleanup-Image /RestoreHealth /Source:esd:Full Path to install.esd file:1","Dism /Online /Cleanup-Image /RestoreHealth /Source:esd:\\sources\\install.esd","Dism /Online /Cleanup-Image /RestoreHealth /Source:wim:E:\\Win10_ISO\\sources\\install.wim"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3473,"title":"Clean Up Component Store (WinSxS folder) in Windows 10","category":"Patch Management","product":"Microsoft Windows","tags":["Patch Management","Command Reference","Technician Fix"],"keywords":["clean","component","store","winsxs","folder","windows","schtasks","exe","run","microsoft","servicing","startcomponentcleanup","using","the","parameter","dism","running","version","gives","you","similar","results","task","scheduler","except","previous","versions","updated","components","will","immediately","deleted","without","day","grace","period","and","not","have","hour"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for clean up component store (winsxs folder) in windows 10. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Clean Up Component Store (WinSxS folder) in Windows 10.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"schtasks.exe /Run /TN \"\\Microsoft\\Windows\\Servicing\\StartComponentCleanup\"\nUsing the /StartComponentCleanup parameter of Dism.exe on a running version of Windows 10 gives you similar results to running the StartComponentCleanup task in Task Scheduler, except previous versions of updated components will be immediately deleted (without a 30 day grace period) and you will not have a 1-hour timeout limitation.\nDism.exe /online /Cleanup-Image /StartComponentCleanup\nClean Up Component Store using /StartComponentCleanup and /ResetBase with Dism Command.\nUse /ResetBase switch with /StartComponentCleanup parameter of DISM.exe on a running version of Windows 10 removes all superseded versions of every component in the component store.\nWarning! All existing service packs and updates cannot be uninstalled after this command is completed.\nThis will not block the uninstallation of future service packs or updates.\nDism.exe /online /Cleanup-Image /StartComponentCleanup /ResetBase\nClean Up Component Store (WinSxS folder) using /SPSuperseded with Dism Command.\nTo reduce the amount of space used by a Service Pack, use the /SPSuperseded parameter of Dism.exe on a running version of Windows 10 to remove any backup components needed for uninstallation of the service pack. A service pack is a collection of cumulative updates for a particular release of Windows.\nWarning! The service pack cannot be uninstalled after this command is completed.\nDism.exe /online /Cleanup-Image /SPSuperseded","commands":["schtasks.exe /Run /TN \"\\Microsoft\\Windows\\Servicing\\StartComponentCleanup\"","Dism.exe /online /Cleanup-Image /StartComponentCleanup","Dism.exe /online /Cleanup-Image /StartComponentCleanup /ResetBase","Dism.exe /online /Cleanup-Image /SPSuperseded"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Patch Management","Command Reference","Technician Fix"],"aliases":[]},{"id":3474,"title":"Check System Integrity Files (SFC)","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["check","system","integrity","files","sfc","full","fix","windows","management","moved","missing","how","view","the","details","scan","type","following","command","and","press","enter","findstr","windir","logs","cbs","log","userprofile","desktop","sfclogs","txt","repair","offline","open","settings","app","click","update","security","recovery"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for check system integrity files (sfc). Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Check System Integrity Files (SFC).\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"Full Fix: Windows management files moved or missing\nHow to view the details of an SFC scan:\nType the following command and press Enter:\nfindstr /c:\"[SR]\" %windir%\\Logs\\CBS\\CBS.log >\"%userprofile%\\Desktop\\sfclogs.txt\"\nHow to scan and repair system files on Windows 10 offline:\n1 - Open the Settings app. Click Update & security.\n2- Click Recovery. Under Advanced startup, click Restart now.\n3- Click Troubleshoot. Click Advanced options.\n4- Click Command Prompt to boot your computer only with Command Prompt.\nOn reboot, you'll be prompted to enter your username and password to continue.\nIf you need to run SCF outside of Windows, you need to tell the utility exactly where the Windows installation files are. On Command Prompt, type the following command to understand the location of the Windows and System Reserved partitions:\nwmic logicaldisk get deviceid, volumename, description\nType the following command, and press Enter:\nsfc /scannow /offbootdir=C:\\ /offwindir=D:\\Windows\nHow to repair system files manually on Windows 10:\nIf the System File Checker couldn't fix one or more files, you will need to repair them manually.\nOpen the sfclogs.txt file to determine which are the corrupted files, find where they belong by doing a simple file search or use your preferred Internet search engine to get more details. Then follow the instructions below to replace the corrupted file. Quick Tip: You can find known good system file copies on another computer running the same version of the operating system like the one running on your PC.\nOpen Command Prompt as Admin. Take ownership of the corrupted system file. In the Command Prompt type the following command, and press Enter:\ntakeown /f C:\\Path-and-File-Name\nNote: Replace C:\\Path-and-File-Name with the path and name of the corrupted file. For example:\nC:\\Windows\\System32\\appraiser.dll.\nAllow full admin access to the corrupted file using the following command and press Enter:\nicacls C:\\Path-and-File-Name /Grant Administrators:F\nReplace the file in question with a good copy using the following command and press Enter:\ncopy C:\\Path-SOURCE-and-File-Name C:\\Path-DESTINATION-and-File-Name\nNote: You need to replace C:\\Path-SOURCE-and-File-Name with the source path and file name of the known good file, and you also need to replace C:\\Path-DESTINATION-and-File-Name with the destination path and name of the damaged file. Example: copy D:\\Files\\appraiser.dll C:\\Windows\\System32\\appraiser.dll.\nType Yes and press Enter to confirm the overwrite.","commands":["findstr /c:\"[SR]\" %windir%\\Logs\\CBS\\CBS.log >\"%userprofile%\\Desktop\\sfclogs.txt\"","wmic logicaldisk get deviceid, volumename, description","sfc /scannow /offbootdir=C:\\ /offwindir=D:\\Windows","takeown /f C:\\Path-and-File-Name","icacls C:\\Path-and-File-Name /Grant Administrators:F","copy C:\\Path-SOURCE-and-File-Name C:\\Path-DESTINATION-and-File-Name"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3475,"title":"Remove Windows.old directory on C:\\","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["remove","windows","old","directory","takeown","icacls","grant","administrators","rmdir","open","cmd","exe","administrator","enter","getcurrent","sysreset"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for remove windows.old directory on c:\\. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Remove Windows.old directory on C:\\.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"takeown /F C:\\Windows.old\\* /R /A\nicacls C:\\Windows.old\\*.* /T /grant administrators:F\nrmdir /S /Q C:\\Windows.old\\\nRemove $Windows.~BT directory on C:\\, open cmd.exe as Administrator & enter:\ntakeown /F C:\\$Windows.~BT\\* /R /A\nicacls C:\\$Windows.~BT\\*.* /T /grant administrators:F\nrmdir /S /Q C:\\$Windows.~BT\\\nRemove $Windows.~WS directory on C:\\, open cmd.exe as Administrator & enter:\ntakeown /F C:\\$Windows.~WS\\* /R /A\nicacls C:\\$Windows.~WS\\*.* /T /grant administrators:F\nrmdir /S /Q C:\\$Windows.~WS\\\nRemove $GetCurrent directory on C:\\, open cmd.exe as Administrator & enter:\ntakeown /F C:\\$GetCurrent\\* /R /A\nicacls C:\\$GetCurrent\\*.* /T /grant administrators:F\nrmdir /S /Q C:\\$GetCurrent\\\nRemove $SysReset directory on C:\\, open cmd.exe as Administrator & enter:\ntakeown /F C:\\$SysReset\\* /R /A\nicacls C:\\$SysReset\\*.* /T /grant administrators:F\nrmdir /S /Q C:\\$SysReset\\","commands":["takeown /F C:\\Windows.old\\* /R /A","icacls C:\\Windows.old\\*.* /T /grant administrators:F","rmdir /S /Q C:\\Windows.old\\","takeown /F C:\\$Windows.~BT\\* /R /A","icacls C:\\$Windows.~BT\\*.* /T /grant administrators:F","rmdir /S /Q C:\\$Windows.~BT\\","takeown /F C:\\$Windows.~WS\\* /R /A","icacls C:\\$Windows.~WS\\*.* /T /grant administrators:F","rmdir /S /Q C:\\$Windows.~WS\\","takeown /F C:\\$GetCurrent\\* /R /A","icacls C:\\$GetCurrent\\*.* /T /grant administrators:F","rmdir /S /Q C:\\$GetCurrent\\","takeown /F C:\\$SysReset\\* /R /A","icacls C:\\$SysReset\\*.* /T /grant administrators:F","rmdir /S /Q C:\\$SysReset\\"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3476,"title":"Taking ownership of folder: E:\\*","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["taking","ownership","folder","icacls","reset","changing","files","attributes","attrib","set","system","owner","add","authority"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for taking ownership of folder: e:\\*. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Taking ownership of folder: E:\\*.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"icacls E:\\* /T /L /Q /C /RESET\nChanging files attributes in folder: E:\\*\nattrib /s -h -s E:\\*\nTo set System as Owner add NT AUTHORITY\\SYSTEM","commands":["icacls E:\\* /T /L /Q /C /RESET","attrib /s -h -s E:\\*"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3477,"title":"Re-Register dll","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["register","dll","this","command","line","tool","registers","files","components","the","registry","syntax","regsvr32","cmdline","dllname","parameters","unregisters","server","specifies","run","silently","and","not","display","any","message","boxes","call","dllregisterserver","you","must","use","option","with","calls","dllinstall","passing","optional","when","used"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for re-register dll. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Re-Register dll.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"This command-line tool registers .dll files as command components in the registry.\nSyntax\nregsvr32 [/u] [/s] [/n] [/i[:cmdline]] dllname\nParameters\n/u : Unregisters server.\n/s : Specifies regsvr32 to run silently and to not display any message boxes.\n/n : Specifies not to call DllRegisterServer. You must use this option with /i.\n/i :cmdline : Calls DllInstall passing it an optional [cmdline]. When used with /u, it calls dll uninstall.\ndllname : Specifies the name of the dll file that will be registered.\n/? : Displays help at the command prompt.\nExamples. To register the .dll for the Active Directory Schema, type:regsvr32 esentprf.dll\nNote, Windows 64-bits versions have two versions of the file Regsv32.exe:\nThe 64-bits version is: %systemroot%\\System32\\regsvr32.exe.\nThe 32-bits version is: %systemroot%\\SysWoW64\\regsvr32.exe.","commands":["regsvr32 [/u] [/s] [/n] [/i[:cmdline]] dllname"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3478,"title":"re-register Windows Media Player DLL files","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["register","windows","media","player","dll","files","regsvr32","vbscript","jscript","wmp","press","enter","after","each","command","and","once","done","restart","the","system"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for re-register windows media player dll files. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to re-register Windows Media Player DLL files.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"regsvr32 vbscript.dll\nregsvr32 jscript.dll\nregsvr32 wmp.dll\nPress Enter after each command, and once done, restart the system.","commands":["regsvr32 vbscript.dll","regsvr32 jscript.dll","regsvr32 wmp.dll"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3479,"title":"Repair or fully rebuild Windows WMI Repository","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["repair","fully","rebuild","windows","wmi","repository","winmgmt","verifyrepository","the","result","shown","inconsistent","step","salvagerepositorywinmgmt","check","again","had","been","repaired","successfully","additional","steps","can","found","below","url","https","blogs","technet","microsoft","com","mofcomp","full"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for repair or fully rebuild windows wmi repository. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Repair or fully rebuild Windows WMI Repository.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"winmgmt /verifyrepository\nIf the result is shown as inconsistent, go to step 2:\nwinmgmt /salvagerepositorywinmgmt /verifyrepository\nTo check again WMI Repository had been repaired successfully.\nAdditional WMI Repository rebuild steps can be found at below URL:\nhttps://blogs.technet.microsoft.com/...mofcomp-s/Full","commands":["winmgmt /verifyrepository"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3480,"title":"Rebuild Performance Counters registry strings","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["rebuild","performance","counters","registry","strings","lodctr","how","manually","counter","library","values","https","support","microsoft","com","help","300956"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for rebuild performance counters registry strings. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Rebuild Performance Counters registry strings.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"lodctr /R\nHow to manually rebuild Performance Counter Library values:\nhttps://support.microsoft.com/en-us/help/300956/how-to-manually-rebuild-performance-counter-library-values","commands":["lodctr /R"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3481,"title":"Trace Performance","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["trace","performance","xperf","help","start"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for trace performance. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Trace Performance.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"xperf -help start","commands":["xperf -help start"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3482,"title":"expand Volume Shadow Copy Storage Space","category":"Backups","product":"Microsoft Windows","tags":["Backups","Command Reference","Technician Fix"],"keywords":["expand","volume","shadow","copy","storage","space","vssadmin","resize","shadowstorage","for","maxsize","erase","orphaned","open","cmd","exe","administrator","enter","delete","shadows","all","check","errors","list","writers","register","vss","and","com","components","windir","system32","net","stop","swprv","regsvr32","ole32","dll","vssvc","registerregsvr32"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for expand volume shadow copy storage space. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to expand Volume Shadow Copy Storage Space.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"vssadmin resize shadowstorage /on=c: /for=c: /maxsize=20%'\nTo erase Orphaned Shadow Copy's, open cmd.exe as Administrator & enter:\nvssadmin delete shadows /all\nTo check for errors:\nvssadmin list writers\nRe-register all VSS and COM+ components, open cmd.exe as Administrator & enter:\ncd /d %windir%\\system32\nNet stop vss\nNet stop swprv\nregsvr32 ole32.dll\nregsvr32 vss_ps.dll\nVssvc /Registerregsvr32 /i swprv.dll\nregsvr32 /i eventcls.dllregsvr32 es.dll\nregsvr32 stdprov.dllregsvr32 vssui.dll\nregsvr32 msxml.dllregsvr32 msxml3.dll\nregsvr32 msxml4.dllregsvr32 Vssapi.dll\nregsvr32 Vssui.dll\nnet start vssnet\nstart swprv\nNet stop vss\nNet stop swprv\nregsvr32.exe /i %windir%\\system32\\eventcls.dll\nregsvr32.exe /i %windir%\\system32\\swprv.dll\nregsvr32.exe %windir%\\system32\\vssui.dll\negsvr32.exe %windir%\\SysWOW64\\vss_ps.dll\negsvr32.exe %windir%\\SysWOW64\\msxml.dll\nregsvr32.exe %windir%\\SysWOW64\\msxml2.dll\nregsvr32.exe %windir%\\SysWOW64\\msxml3.dll\nregsvr32.exe %windir%\\SysWOW64\\msxml4.dll\nregsvr32.exe %windir%\\SysWOW64\\ole32.dll\nregsvr32.exe %windir%\\SysWOW64\\oleaut32.dll\nregsvr32.exe %windir%\\SysWOW64\\es.dll\nregsvr32.exe %windir%\\SysWOW64\\comsvcs.dll\nvssvc /register\nnet start swprv\nnet start vss\nnet stop winmgmtregsvr32 wmiutils.dll\nnet start winmgmt\nIf the VSS error code 0x800423f3 is reported, the reason is a corrupt state of WMI (wmiutils.dll). This may happen if a registry cleaner was used or a third-party application was uninstalled incorrectly. What you need to do is re-register wmiutils.dll and then restart the WMI service. In the command prompt, execute the following three lines (note that stopping the WMI service does NOT stop VMs, it only stops the management service):\nnet stop winmgmtregsvr32 wmiutils.dll net start winmgmt","commands":["vssadmin resize shadowstorage /on=C: /for=C: /maxsize=20%","vssadmin delete shadows /all","vssadmin list writers","cd /d %windir%\\system32","Net stop vss","Net stop swprv","regsvr32 ole32.dll","regsvr32 vss_ps.dll","regsvr32 Vssui.dll","net start vssnet","start swprv","regsvr32.exe /i %windir%\\system32\\eventcls.dll","regsvr32.exe /i %windir%\\system32\\swprv.dll","regsvr32.exe %windir%\\system32\\vssui.dll","regsvr32.exe %windir%\\SysWOW64\\msxml2.dll","regsvr32.exe %windir%\\SysWOW64\\msxml3.dll","regsvr32.exe %windir%\\SysWOW64\\msxml4.dll","regsvr32.exe %windir%\\SysWOW64\\ole32.dll","regsvr32.exe %windir%\\SysWOW64\\oleaut32.dll","regsvr32.exe %windir%\\SysWOW64\\es.dll","regsvr32.exe %windir%\\SysWOW64\\comsvcs.dll","vssvc /register","net start swprv","net start vss","net start winmgmt"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Backups","Command Reference","Technician Fix"],"aliases":[]},{"id":3483,"title":"Open Troubleshooting Windows in Control Panel","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["open","troubleshooting","windows","control","panel","systemroot","system32","exe","name","microsoft","troubleshootingdesktop","experience","the","aero","troubleshooter","msdt","aerodiagnosticsound","playing","audio","audioplaybackdiagnostic","recording","audiorecordingdiagnosticdevice","hardware","and","devices","devicediagnosticnetwork","internet","connections","networkdiagnosticsweb","shared","folders","networkdiagnosticsfileshare","homegroup","homegroupdiagnostic","network","adapter","networkdiagnosticsnetworkadapter","incoming","networkdiagnosticsinboundweb","browser"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for open troubleshooting windows in control panel. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Open Troubleshooting Windows in Control Panel.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"%systemroot%\\system32\\control.exe /name Microsoft.TroubleshootingDesktop Experience.\nTo open the Aero troubleshooter:\n%systemroot%\\system32\\msdt.exe -id AeroDiagnosticSound.\nTo open the Playing Audio troubleshooter:\n%systemroot%\\system32\\msdt.exe -id AudioPlaybackDiagnostic\nTo open the Recording Audio troubleshooter in Control Panel:\n%systemroot%\\system32\\msdt.exe -id AudioRecordingDiagnosticDevice.\nTo open the Hardware and Devices troubleshooter in Control Panel:\n%systemroot%\\system32\\msdt.exe -id DeviceDiagnosticNetwork.\nTo open the Internet Connections troubleshooter:\n%systemroot%\\system32\\msdt.exe -id NetworkDiagnosticsWeb\nTo open the Shared Folders troubleshooter:\n%systemroot%\\system32\\msdt.exe -id NetworkDiagnosticsFileShare\nTo open the HomeGroup troubleshooter:\n%systemroot%\\system32\\msdt.exe -id HomeGroupDiagnostic\nTo open the Network Adapter troubleshooter:\n%systemroot%\\system32\\msdt.exe -id NetworkDiagnosticsNetworkAdapter\nTo open the Incoming Connections troubleshooter:\n%systemroot%\\system32\\msdt.exe -id NetworkDiagnosticsInboundWeb Browser.\nTo open the Internet Explorer Performance troubleshooter:\n%systemroot%\\system32\\msdt.exe -id IEBrowseWebDiagnostic\nTo open the Internet Explorer Safety troubleshooter:\n%systemroot%\\system32\\msdt.exe -id IESecurityDiagnosticSystem.\nTo open the System Maintenance troubleshooter:\n%systemroot%\\system32\\msdt.exe -id MaintenanceDiagnosticPrograms.\nTo open the Program Compatibility troubleshooter:\n%systemroot%\\system32\\msdt.exe -id PCWDiagPerformance.\nTo open the Performance troubleshooter:\n%systemroot%\\system32\\msdt.exe -id PerformanceDiagnosticPower.\nTo open the Power troubleshooter:\n%systemroot%\\system32\\msdt.exe -id PowerDiagnosticPrinting.\nTo open the Printer troubleshooter.:\n%systemroot%\\system32\\msdt.exe -id PrinterDiagnosticMedia Player.\nTo open the Windows Media Player Settings troubleshooter:\n%systemroot%\\system32\\msdt.exe -id WindowsMediaPlayerConfigurationDiagnostic\nTo open the Windows Media Player Library troubleshooter:\n%systemroot%\\system32\\msdt.exe -id WindowsMediaPlayerLibraryDiagnostic\nTo open the Windows Media Player DVD troubleshooter:\n%systemroot%\\system32\\msdt.exe -id WindowsMediaPlayerDVDDiagnostic","commands":[],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3484,"title":"Godmode","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["godmode","make","new","folder","and","rename","copy","paste","with","the","following","ed7ba470","8e54","465e","825c","99712043e01c","this","creates","shortcut","advanced","control","panel"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for godmode. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Godmode.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"Make a new Folder on C: and rename (copy and paste) it with the following:\nGodMode.{ED7BA470-8E54-465E-825C-99712043E01C}\nThis creates a shortcut to an advanced Control Panel.","commands":[],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3485,"title":"restore the computer's default libraries, follow these steps","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["restore","the","computer","default","libraries","follow","these","steps","note","deleting","and","creating","does","not","affect","data","open","windows","explorer","left","pane","click","you","don","see","listed","tap","view","top","screen","navigation","drop","down","menu","make","sure","that","show","selected","right"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for restore the computer's default libraries, follow these steps. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to restore the computer's default libraries, follow these steps.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"Note Deleting and re-creating the libraries does not affect the data in the libraries. Open Windows Explorer, in the left pane, click Libraries. Note If you don't see \"Libraries\" listed, tap or click View at the top of the screen. On the Navigation pane drop-down menu, make sure that Show libraries is selected. Right-click each library (Documents, Pictures, Music, and Videos) and then tap or click Delete. In the left pane, right-click Libraries & then select Restore default libraries. This action re-creates libraries. All the data in the library folders should again be accessible through Windows Explorer.","commands":[],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3486,"title":"copy large files","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["copy","large","files","robocopy"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for copy large files. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to copy large files.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"ROBOCOPY /?","commands":["ROBOCOPY /?"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3487,"title":"Install all the standard applications on your system","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["install","all","the","standard","applications","your","system","launch","powershell","set","executionpolicy","unrestricted","get","appxpackage","allusers","foreach","add","disabledevelopmentmode","register","installlocation","appxmanifest","xml"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for install all the standard applications on your system. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Install all the standard applications on your system.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"1) launch powershell\n2) Set-ExecutionPolicy Unrestricted\n3) Get-AppXPackage -AllUsers | Foreach {Add-AppxPackage -DisableDevelopmentMode -Register \"$($_.InstallLocation)\\AppXManifest.xml\"}","commands":[],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3488,"title":"Re-register missing apps using PowerShell, Run as administrator","category":"PowerShell","product":"Microsoft Windows","tags":["PowerShell","Command Reference","Technician Fix"],"keywords":["register","missing","apps","using","powershell","run","administrator","get","appxpackage","foreach","add","disabledevelopmentmode","installlocation","appxmanifest","xml"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for re-register missing apps using powershell, run as administrator. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Re-register missing apps using PowerShell, Run as administrator.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"Get-AppXPackage | Foreach {Add-AppxPackage -DisableDevelopmentMode -Register \"$($_.InstallLocation)\\AppXManifest.xml\"}","commands":["Get-AppXPackage | Foreach {Add-AppxPackage -DisableDevelopmentMode -Register \"$($_.InstallLocation)\\AppXManifest.xml\"}"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["PowerShell","Command Reference","Technician Fix"],"aliases":[]},{"id":3489,"title":"get Full access to WindowsApps in C:\\Program Files\\WindowsApps","category":"PowerShell","product":"Microsoft Windows","tags":["PowerShell","Command Reference","Technician Fix"],"keywords":["get","full","access","windowsapps","program","files","takeown","programfiles","icacls","inheritance","grant","administrators"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for get full access to windowsapps in c:\\program files\\windowsapps. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to get Full access to WindowsApps in C:\\Program Files\\WindowsApps.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"takeown /f \"%ProgramFiles%\\WindowsApps\" /a /r /d y\nicacls \"%ProgramFiles%\\WindowsApps\" /inheritance:r /grant:r Administrators:(OI)(CI)F /t /c","commands":["takeown /f \"%ProgramFiles%\\WindowsApps\" /a /r /d y","icacls \"%ProgramFiles%\\WindowsApps\" /inheritance:r /grant:r Administrators:(OI)(CI)F /t /c"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["PowerShell","Command Reference","Technician Fix"],"aliases":[]},{"id":3490,"title":"Remove Windows Apps","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["remove","windows","apps","uninstall","builder","get","appxpackage","3dbuilder","alarms","and","clock","windowsalarms","calculator","windowscalculator","calendar","mail","windowscommunicationsapps","camera","windowscamera","office","officehub","skype","skypeapp","started","getstarted","groove","music","zunemusic","maps","windowsmaps","microsoft","solitaire","collection","solitairecollection","money","bingfinance","movies","zunevideo","news","bingnews"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for remove windows apps. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Remove Windows Apps.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"Uninstall 3D Builder:\nGet-AppxPackage *3dbuilder* | Remove-AppxPackage\nUninstall Alarms and Clock:\nGet-AppxPackage *windowsalarms* | Remove-AppxPackage\nUninstall Calculator:\nGet-AppxPackage *windowscalculator* | Remove-AppxPackage\nUninstall Calendar and Mail:\nGet-AppxPackage *windowscommunicationsapps* | Remove-AppxPackage\nUninstall Camera:\nGet-AppxPackage *windowscamera* | Remove-AppxPackage\nUninstall Get Office:\nGet-AppxPackage *officehub* | Remove-AppxPackage\nUninstall Get Skype:\nGet-AppxPackage *skypeapp* | Remove-AppxPackage\nUninstall Get Started:\nGet-AppxPackage *getstarted* | Remove-AppxPackage\nUninstall Groove Music:\nGet-AppxPackage *zunemusic* | Remove-AppxPackage\nUninstall Maps:\nGet-AppxPackage *windowsmaps* | Remove-AppxPackage\nUninstall Microsoft Solitaire Collection:\nGet-AppxPackage *solitairecollection* | Remove-AppxPackage\nUninstall Money:\nGet-AppxPackage *bingfinance* | Remove-AppxPackage\nUninstall Movies & TV:\nGet-AppxPackage *zunevideo* | Remove-AppxPackage\nUninstall News:\nGet-AppxPackage *bingnews* | Remove-AppxPackage\nUninstall OneNote:\nGet-AppxPackage *onenote* | Remove-AppxPackage\nUninstall People:\nGet-AppxPackage *people* | Remove-AppxPackage\nUninstall Phone Companion:\nGet-AppxPackage *windowsphone* | Remove-AppxPackage\nUninstall Photos:\nGet-AppxPackage *photos* | Remove-AppxPackage\nUninstall Store:\nGet-AppxPackage *windowsstore* | Remove-AppxPackage\nUninstall Sports:\nGet-AppxPackage *bingsports* | Remove-AppxPackage\nUninstall Voice Recorder:\nGet-AppxPackage *soundrecorder* | Remove-AppxPackage\nUninstall Weather:\nGet-AppxPackage *bingweather* | Remove-AppxPackage\nUninstall Xbox:\nGet-AppxPackage *xboxapp* | Remove-AppxPackage","commands":["Get-AppxPackage *3dbuilder* | Remove-AppxPackage","Get-AppxPackage *windowsalarms* | Remove-AppxPackage","Get-AppxPackage *windowscalculator* | Remove-AppxPackage","Get-AppxPackage *windowscommunicationsapps* | Remove-AppxPackage","Get-AppxPackage *windowscamera* | Remove-AppxPackage","Get-AppxPackage *officehub* | Remove-AppxPackage","Get-AppxPackage *skypeapp* | Remove-AppxPackage","Get-AppxPackage *getstarted* | Remove-AppxPackage","Get-AppxPackage *zunemusic* | Remove-AppxPackage","Get-AppxPackage *windowsmaps* | Remove-AppxPackage","Get-AppxPackage *solitairecollection* | Remove-AppxPackage","Get-AppxPackage *bingfinance* | Remove-AppxPackage","Get-AppxPackage *zunevideo* | Remove-AppxPackage","Get-AppxPackage *bingnews* | Remove-AppxPackage","Get-AppxPackage *onenote* | Remove-AppxPackage","Get-AppxPackage *people* | Remove-AppxPackage","Get-AppxPackage *windowsphone* | Remove-AppxPackage","Get-AppxPackage *photos* | Remove-AppxPackage","Get-AppxPackage *windowsstore* | Remove-AppxPackage","Get-AppxPackage *bingsports* | Remove-AppxPackage","Get-AppxPackage *soundrecorder* | Remove-AppxPackage","Get-AppxPackage *bingweather* | Remove-AppxPackage","Get-AppxPackage *xboxapp* | Remove-AppxPackage"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3491,"title":"Disable Microsoft Compatibility Telemetry","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["disable","microsoft","compatibility","telemetry","delete","diagtracksc","dmwappushserviceecho","programdata","diagnosis","etllogs","autologger","diagtrack","listener","etlreg","add","hklm","software","policies","windows","datacollection","allowtelemetry","reg","dword"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for disable microsoft compatibility telemetry. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Disable Microsoft Compatibility Telemetry.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"sc delete DiagTracksc delete dmwappushserviceecho \"\" > C:\\\\ProgramData\\\\Microsoft\\\\Diagnosis\\\\ETLLogs\\\\AutoLogger\\\\AutoLogger-Diagtrack-Listener.etlreg add \"HKLM\\\\SOFTWARE\\\\Policies\\\\Microsoft\\\\Windows\\\\DataCollection\" /v AllowTelemetry /t REG_DWORD /d 0 /f","commands":["sc delete DiagTracksc delete dmwappushserviceecho \"\" > C:\\\\ProgramData\\\\Microsoft\\\\Diagnosis\\\\ETLLogs\\\\AutoLogger\\\\AutoLogger-Diagtrack-Listener.etlreg add \"HKLM\\\\SOFTWARE\\\\Policies\\\\Microsoft\\\\Windows\\\\DataCollection\" /v AllowTelemetry /t REG_DWORD /d 0 /f"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3492,"title":"Reset Windows Time Service","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["reset","windows","time","service","net","stop","w32timew32tm","unregisterw32tm","registernet","start","resyncor","try","this","triggerinfo","w32time","networkon","networkoff"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for reset windows time service. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Reset Windows Time Service.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"net stop w32timew32tm /unregisterw32tm /registernet start w32timew32tm /resyncOr try this:sc triggerinfo w32time start/networkon stop/networkoff","commands":["net stop w32timew32tm /unregisterw32tm /registernet start w32timew32tm /resyncOr try this:sc triggerinfo w32time start/networkon stop/networkoff"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3493,"title":"Remove XboxGamingOverlay","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["remove","xboxgamingoverlay","get","appxpackage","allusers","microsoft"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for remove xboxgamingoverlay. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Remove XboxGamingOverlay.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"Get-AppxPackage -AllUsers Microsoft.XboxGamingOverlay | Remove-AppxPackage","commands":["Get-AppxPackage -AllUsers Microsoft.XboxGamingOverlay | Remove-AppxPackage"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3494,"title":"Remove Gaming Services","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["remove","gaming","services","get","appxpackage","microsoft","gamingservices","allusers"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for remove gaming services. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Remove Gaming Services.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"get-appxpackage Microsoft.GamingServices | remove-AppxPackage -allusers","commands":["get-appxpackage Microsoft.GamingServices | remove-AppxPackage -allusers"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3495,"title":"Delete Windows Service","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["delete","windows","service","exe","stop","adobearm","servicesc"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for delete windows service. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Delete Windows Service.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"sc.exe stop AdobeARM servicesc.exe delete AdobeARM service","commands":["sc.exe stop AdobeARM servicesc.exe delete AdobeARM service"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3496,"title":"Disable Windows Search Indexing Service","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["disable","windows","search","indexing","service","stop","wsearch","config","start","disabled"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for disable windows search indexing service. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Disable Windows Search Indexing Service.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"sc stop \"WSearch\"sc config \"WSearch\" start= disabled","commands":["sc stop \"WSearch\"sc config \"WSearch\" start= disabled"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3497,"title":"Repair Volume Shadow Copy Service Errors: Unitrends SNMP service components online from Microsoft servers","category":"Backups","product":"Microsoft Windows","tags":["Backups","Command Reference","Technician Fix"],"keywords":["repair","volume","shadow","copy","service","errors","unitrends","snmp","components","online","from","microsoft","servers","this","open","the","elevated","powershell","console","and","run","command","add","windowscapability","name","client","you","can","also","use","dism","install","capability","capabilityname","after","that","verify","installed","get","disable"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for repair volume shadow copy service errors: unitrends snmp service components online from microsoft servers. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Repair Volume Shadow Copy Service Errors: Unitrends SNMP service components online from Microsoft servers.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"To do this, open the elevated PowerShell console and run the command:\nAdd-WindowsCapability -Online -Name \"SNMP.Client~~~~0.0.1.0\"\nYou can also use DISM to install the SNMP service:\nDISM /online /add-capability /capabilityname:SNMP.Client~~~~0.0.1.0\nAfter that, you can verify if the SNMP service is installed:\nGet-WindowsCapability -Online -Name \"SNMP*\"\nTo disable the SNMP service, use the PowerShell command:\nRemove-WindowsCapability -Online -Name \"SNMP.Client~~~~0.0.1.0\"\nStop the Cryptographic Services \"CryptSvc\" service manually before shutdown:\nnet stop cryptsvcshutdown /s /t 0\nHow to Install and Configure SNMP (Simple Network Management Protocol) Service on Windows 10/11?\nHow to Install and Configure SNMP Service on Windows 10/11? – TheITBros","commands":["Add-WindowsCapability -Online -Name \"SNMP.Client~~~~0.0.1.0\"","DISM /online /add-capability /capabilityname:SNMP.Client~~~~0.0.1.0","Get-WindowsCapability -Online -Name \"SNMP*\"","Remove-WindowsCapability -Online -Name \"SNMP.Client~~~~0.0.1.0\"","net stop cryptsvcshutdown /s /t 0"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Backups","Command Reference","Technician Fix"],"aliases":[]},{"id":3498,"title":"Delete HP Assistant, Support Tool Servicese","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["delete","assistant","support","tool","servicese","exe","hpapphelpercap","service","hpqcaslwmiex","hpdiagscap","hpnetworkcap","hpsysinfocap"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for delete hp assistant, support tool servicese. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Delete HP Assistant, Support Tool Servicese.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"sc.exe delete HPAppHelperCap service\nsc.exe delete hpqcaslwmiex service\nsc.exe delete HPDiagsCap service\nsc.exe delete HPNetworkCap service\nsc.exe delete HPSysInfoCap service","commands":["sc.exe delete HPAppHelperCap service","sc.exe delete hpqcaslwmiex service","sc.exe delete HPDiagsCap service","sc.exe delete HPNetworkCap service","sc.exe delete HPSysInfoCap service"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3499,"title":"Uninstall Intel(R) Rapid Storage Technology RST driver & Components","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["uninstall","intel","rapid","storage","technology","rst","driver","components","device","manager","double","click","ide","ata","atapi","controllers","your","sata","ahci","controller","navigate","the","tab","properties","window","select","restart","system","after","complete","restarts","and","you","booted","back","into","windows","ensure","that","under"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for uninstall intel(r) rapid storage technology rst driver & components. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Uninstall Intel(R) Rapid Storage Technology RST driver & Components.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"Go to Device Manager. Double-click IDE ATA/ATAPI controllers. Double-click your Intel(R) _____SATA AHCI Controller.\nNavigate to the Driver tab of the controller properties window. Select Uninstall. Restart the system after the uninstall is complete. After the system restarts and you've booted back into Windows, navigate back to Device Manager and ensure that under IDE ATA/ATAPI controllers, it is now Standard SATA AHCI Controller.\nIf the above is true, you're all set! The only thing left to do is ensure that anything regarding Intel(R) Rapid Storage Technology driver-wise is not loaded. There are multiple ways to do this, but the most user-friendly is by using DriverView:\nDriverView: Loaded Windows Drivers List\nOnce you've downloaded and installed DriverView, sort it by Driver Name (although it should be set that way by default). Ensure none of the following drivers are listed - iaStor.sys, iaStorA.sys, iaStorF.sys, iaStorS.sys, iastorv.sys.\nIf none are listed, you're officially finished and can stop reading the rest of the steps.\nIf however one of them is listed, head back to Device Manager and select View, and then check Show hidden devices.\nAfter showing hidden devices, double-click Non-plug and play Drivers. Right-click on your respected Intel(R) Rapid Storage Technology driver, and then select Properties. Navigate to the Driver tab and then under Startup, change it to Disabled.Restart the system. Now you should be all done, good job!\nRemove Intel(R) Rapid Storage Technology RST Services.\nDelete Intel(R) Storage Middleware Service:\nsc.exe stop RstMw Service\nsc.exe delete RstMwServiceDelete Intel(R) RST HFC Disable Service:\nsc.exe stop HfcDisableService\nsc.exe delete HfcDisableService\nDelete Intel(R) Optane(TM) Memory Service:\nsc.exe stop iaStorAfsService\nsc.exe delete iaStorAfsService","commands":["sc.exe stop RstMw Service","sc.exe delete RstMwServiceDelete Intel(R) RST HFC Disable Service:","sc.exe stop HfcDisableService","sc.exe delete HfcDisableService","sc.exe stop iaStorAfsService","sc.exe delete iaStorAfsService"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3500,"title":"Go to Settings --> Privacy --> Background Apps & Disable as many as you can","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["settings","privacy","background","apps","disable","many","you","can","default","ntfs","will","automatically","update","timestamps","whenever","directory","traversed","this","isn","necessary","feature","and","slows","down","large","volumes","pointing","regedit","hkey","local","machine","system","currentcontrolset","control","filesystem","set","ntfsdisablelastaccessupdate","uses","disparate","master"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for go to settings --> privacy --> background apps & disable as many as you can. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Go to Settings --> Privacy --> Background Apps & Disable as many as you can.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"By default NTFS will automatically update timestamps whenever a directory is traversed.\nThis isn't a necessary feature, and it slows down large volumes. Disable it by pointing regedit to:\nHKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\FileSystem\nSet 'NtfsDisableLastAccessUpdate' to 1.\nNTFS uses disparate master file control tables to store filesystem information about your drives. Over time these core MFT files grow and become fragmented, slowing down all accesses to the drive. By setting aside a little space, MFT's can grow without becoming fragmented. In the same key where you disabled the last access feature create a new DWORD value called 'NtfsMftZoneReservation' and set it to 2.","commands":[],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3501,"title":"Defrag Boot sector","category":"Windows Server","product":"Microsoft Windows","tags":["Windows Server","Command Reference","Technician Fix"],"keywords":["defrag","boot","sector"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for defrag boot sector. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Defrag Boot sector.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"defrag c: -b","commands":["defrag c: -b"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows Server","Command Reference","Technician Fix"],"aliases":[]},{"id":3502,"title":"Defrag.exe, from an elevated command prompt as Administrator","category":"Windows Server","product":"Microsoft Windows","tags":["Windows Server","Command Reference","Technician Fix"],"keywords":["defrag","exe","from","elevated","command","prompt","administrator","has","the","following","syntax","which","different","than","used","for","windows","vista","volume","volumes","options","are","drive","letter","mount","point","defragment","all","local","computer","except","those","specified","display","fragmentation","analysis","report","without","defragmenting","perform"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for defrag.exe, from an elevated command prompt as administrator. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Defrag.exe, from an elevated command prompt as Administrator.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"Defrag.exe has the following syntax (which is different than the syntax used for defrag in Windows Vista):\nDefrag <volume> | /C | /E <volumes> [/A | /X | /T] [/H] [/M] [/U] [/V]\nThe options for Defrag.exe are:\n<volume> The drive letter or mount point of the volume to defragment.\n/C Defragment all local volumes on the computer.\n/E Defragment all local volumes on the computer except those specified.\n/A Display a fragmentation analysis report for the specified volume without defragmenting it.\n/X Perform free-space consolidation. Free-space consolidation is useful if you need to shrink a volume, and it can reduce fragmentation of future files.\n/T Track an operation already in progress on the specified volume.\n/H Run operation at normal priority instead of default low priority. Specify this option if a computer is not otherwise in use.\n/M Defragment multiple volumes simultaneously, in parallel. This is primarily useful for computers that can access multiple disks simultaneously, such as those using SCSI- or SATA-based disks rather than disks with an IDE interface.\n/U Print the progress of the operation on the screen.\n/V Verbose mode.\nProvides additional detail and statistics. For example:\ndefrag c: /a /v\nDefrag all of your devices in verbose mode to see more info, and you also want the defrag to run at top priority.\nTo do this, we'll enter:\ndefrag /C /H /V","commands":["Defrag.exe has the following syntax (which is different than the syntax used for defrag in Windows Vista):","Defrag <volume> | /C | /E <volumes> [/A | /X | /T] [/H] [/M] [/U] [/V]","defrag c: /a /v","Defrag all of your devices in verbose mode to see more info, and you also want the defrag to run at top priority.","defrag /C /H /V"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows Server","Command Reference","Technician Fix"],"aliases":[]},{"id":3503,"title":"Chkdsk","category":"Windows Server","product":"Microsoft Windows","tags":["Windows Server","Command Reference","Technician Fix"],"keywords":["chkdsk","https","docs","microsoft","com","previous","versions","windows","pro","server","2012","and","cc730714","open","cmd","exe","administrator","use","command","line","check","disk","typing","without","the","hitting","enter","will","give","you","its","parameters","switches","get","report","for","say","drive","can","also"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for chkdsk. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Chkdsk.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":":https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc730714(v=ws.11)\nOpen cmd.exe as Administrator to use Command Line Check Disk:\nTyping \"chkdsk /?\" (without the \" \") and hitting Enter will give you its parameters or switches.\nTo get a report for, say, drive C, use \"chkdsk c:\"\nYou can also use the following parameters at the end of the command to specialize its operations.\nThe following are valid on FAT32 / NTFS volumes.\n/B Re-evaluates bad sectors\n/f Fixes errors detected.\n/r Identifies Bad Sectors and attempts recovery of information.\n/v Displays list of every file in every directory, on FAT32.\nDriverView: Loaded Windows Drivers List\nFor example:chkdsk /f /r c\nThe following are valid on NTFS volumes only.\n/B Re-evaluates bad clusters on the volume (NTFS only; implies /R).\n/c Skips the checking of cycles within the folder structure.\n/I Performs a simpler check of index entries.\n/x Forces the volume to dismount. Also invalidates all open file handles. This should be avoided in Desktop Editions of Windows, because of possibility of data loss/corruption.\n/l [:size] It changes the size of the file that logs NTFS transactions. This option too, like the above one, is intended for server administrators ONLY. Do note that, when you boot to the Windows Recovery Environment, only two switches may be available:\n/p It performs an exhaustive check of the current disk.\n/r It repairs possible damage on the current disk. For example: chkdsk /p /r c:\nThe following switches work in Windows 10, Windows 8 on NTFS volumes only:\n/scan Run online scan\n/forceofflinefix Bypass online repair and queue defects for offline repair. Needs to be used along with /scan.\n/perf Perform the scan as fast as possible.\n/spotfix Perform spot repair in offline mode.\n/offlinescanandfix Run offline scan and perform fixes.\n/sdcclean Garbage collection.\nThese switches are supported by Windows 10 on FAT/FAT32/exFAT volumes only:\n/freeorphanedchains Free up any orphaned cluster chains.\n/markclean Mark the volume clean if no corruption is detected.\nChkntfs Commands:\nApplies To: Windows Vista, Windows Server 2008, Windows Server 2012, Windows 8 and later versions.\nDisplays or modifies automatic disk checking when the computer is started. If used without options, chkntfs displays the file system of the specified volume. If automatic file checking is scheduled to run, chkntfs displays whether the specified volume is dirty or is scheduled to be checked the next time the computer is started. To run chkntfs, you must be a member of the Administrators group.\nSyntax examples:\nchkntfs <Volume> [...]\nchkntfs [/d]\nchkntfs [/t[:<Time>]]\nchkntfs [/x <Volume> [...]]\nchkntfs [/c <Volume> [...]]Parameters:<Volume> [...]\nSpecifies one or more volumes to check when the computer starts. Valid volumes include drive letters (followed by a colon), mount points, or volume names.\n/d Restores all chkntfs default settings, except the countdown time for automatic file checking.\nBy default, all volumes are checked when the computer is started, and chkdsk runs on those that are dirty.\n/t [:<Time>] Changes the Autochk.exe initiation countdown time to the amount of time specified in seconds. If you do not enter a time, /t displays the current countdown time.\n/x <Volume> [...]\nSpecifies one or more volumes to exclude from checking when the computer is started, even if the volume is marked as requiring chkdsk.\n/c <Volume> [...]\nSchedules one or more volumes to be checked when the computer is started, and runs chkdsk on those that are dirty/? Displays help at the command prompt. Examples: To display the type of file system for drive C, type:\nchkntfs c:\nTo exclude a volume from being checked:\nchkntfs /x c:\nTo exclude multiple volumes from being checked:\nchkntfs /x d: e:\nTo restores all chkntfs default settings:\nchkntfs /d c:\nTo display the Autochk.exe initiation countdown time, type:\nchkntfs /t\nTo change it to 30 seconds:\nchkntfs /t:30\nThe /c command-line option is accumulative. If you type /c more than once, each entry remains. To ensure that only a particular volume is checked, reset the defaults to clear all previous commands, exclude all volumes from being checked, and then schedule automatic file checking on the desired volume. For example, to schedule automatic file checking on the D volume but not the C or E volumes, type the following commands in order:\nchkntfs /d\nchkntfs /x c: d: e:\nchkntfs /c d:\nTo disable chkdsk chkntfs at every boot navigate to this key in Regedit:\nHKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Session Manager\nIn the right hand pane, double click BootExecute. The default value of the key is:\nautocheck autochk\n*If you want disable checking for your D & E partitions enter:\nautocheck autochk /k:D /k:E *","commands":[],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows Server","Command Reference","Technician Fix"],"aliases":[]},{"id":3504,"title":"Delete System Volume Information","category":"Windows Server","product":"Microsoft Windows","tags":["Windows Server","Command Reference","Technician Fix"],"keywords":["delete","system","volume","information","take","ownership","for","the","directory","and","all","files","below","right","click","properties","advanced","change","owner","replace","sub","containers","objects","remove","hidden","attributes","attrib","with","rmdir"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for delete system volume information. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Delete System Volume Information.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"Take Ownership for the directory and all files below:\nRight click Properties, go to Advanced, Change Owner, 'Replace Owner on sub containers and objects'\nRemove the hidden and system attributes:\nATTRIB -H -S \"C:\\System Volume Information\"\nRemove it all with:\nRMDIR /s \"C:\\System Volume Information\"","commands":["ATTRIB -H -S \"C:\\System Volume Information\"","RMDIR /s \"C:\\System Volume Information\""],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows Server","Command Reference","Technician Fix"],"aliases":[]},{"id":3505,"title":"find out your BIOS version","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["find","out","your","bios","version","systeminfo","findstr","wmic","get","manufacturer","smbiosbiosversion","note","that","the","capital","not","lower","case"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for find out your bios version. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to find out your BIOS version.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"1. systeminfo | findstr /I /c:bios\n2. wmic bios get manufacturer, smbiosbiosversion\nNote that the I in /I is a capital i, not a lower case L.","commands":[],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3506,"title":"eject media, hardware or remove the USB device","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["eject","media","hardware","remove","the","usb","device","rundll32","exe","shell32","dll","control","rundll","hotplug"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for eject media, hardware or remove the usb device. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to eject media, hardware or remove the USB device.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"RunDll32.exe shell32.dll,Control_RunDLL hotplug.dll","commands":["RunDll32.exe shell32.dll,Control_RunDLL hotplug.dll"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3507,"title":"Windows PnP (Plug & Play) Utility for managing the Driver Store, and list all of the driver packages stored there","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["windows","pnp","plug","play","utility","for","managing","the","driver","store","and","list","all","packages","stored","there","pnputil"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for windows pnp (plug & play) utility for managing the driver store, and list all of the driver packages stored there. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Windows PnP (Plug & Play) Utility for managing the Driver Store, and list all of the driver packages stored there.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"pnputil -e","commands":["pnputil -e"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3508,"title":"Show Hidden Devices","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["show","hidden","devices","device","manager","displays","only","non","plug","and","play","drivers","printers","when","you","click","the","view","menu","that","install","are","not","connected","computer","such","universal","serial","bus","usb","ghosted","displayed","even","command","prompt","enter","set","devmgr","nonpresent"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for show hidden devices. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Show Hidden Devices.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"Device Manager displays only non-Plug and Play devices, drivers, and printers when you click Show hidden devices on the View menu. Devices that you install that are not connected to the computer (such as a Universal Serial Bus [USB] device or \"ghosted\" devices) are not displayed in Device Manager, even when you click Show hidden devices. Click Command Prompt and enter:\nset devmgr_show_nonpresent_devices=1","commands":[],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3509,"title":"Generate a List of Drivers","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["generate","list","drivers","pnputil","enum","txt"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for generate a list of drivers. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Generate a List of Drivers.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"pnputil /enum-drivers > c:\\drivers.txt","commands":["pnputil /enum-drivers > c:\\drivers.txt"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3510,"title":"Driver Verifier Manager & Device Manager","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["driver","verifier","manager","device","troubleshoot","problems","windows","your","freezes","frequently","encountering","frequent","stop","errors","bsod","then","advisable","check","the","problem","being","caused","faulty","while","most","cases","its","usually","unsigned","drivers","which","create","one","cannot","rule","out","signed","too","nevertheless","you"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for driver verifier manager & device manager. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Driver Verifier Manager & Device Manager.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"Troubleshoot Driver Problems in Windows: If your Windows freezes frequently or is encountering frequent Stop Errors or BSOD's then, it is advisable to check if the problem is being caused by a faulty Driver. While in most cases, its usually the unsigned drivers which create problems, one cannot rule out the signed drivers too! Nevertheless, you can troubleshoot, identify & resolve common device driver problems with the help of the built-in Driver Verifier Manager & Device Manager.\nWindows has, what is called as, Driver Verifier Manager. It's a very useful tool to identify problematic drivers.\nTo open it type \"verifier\" in start menu search box and hit enter. The Driver Verifier Manager tests each specified driver at startup. If it detects a problem, it identifies it and then stops it from running.\nTo use the Driver Verifier Manager, first, select Create Standard Settings > Click Next > Automatically select unsigned drivers > Next. You will see a dialog box 'Loading driver information' at the end of which you will be presented with a list of unsigned drivers.There are other options, too, to select at every step. Choose what you think would be most appropriate in your case. I have only mentioned unsigned drivers as they are usually suspect. This way Standard Settings will first be created. This helps you in identifying what might be a buggy driver.In the last stage of the wizard, you have two options: to click Cancel or to click Finish. It's best to click Cancel. This way no changes are made to your system configuration.\nFrom the list which is presented, you can manually try to Roll back, Update, Disable or Uninstall the Driver. But if you click Finish, then on re-start of the PC, you may be presented with an error message. This will include the name of the buggy driver along with an error code. Note down the driver's name and the error code.Next reboot, but this time in Safe Mode. Now you can choose to Roll back, Update, Disable or Uninstall the particular Driver. Finally, to disable the Driver Verifier Manager, type the following in Windows Start Menu Search and hit Enter:\nverifier /reset","commands":["verifier /reset"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3511,"title":"How to use Diskpart","category":"Windows Server","product":"Microsoft Windows","tags":["Windows Server","Command Reference","Technician Fix"],"keywords":["how","use","diskpart","separate","suite","commands","that","runs","the","command","window","its","own","shell","opened","first","entering","without","quotes","and","then","one","various","sub","are","listed","section","below","return","regular","line","enter","exit","for","windows","vista","must","with","administrator","privileges"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for how to use diskpart. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to How to use Diskpart.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"Diskpart is a separate suite of commands that runs in the command window in its own shell. It is opened by first entering the command \"diskpart\" (without quotes) and then entering one of the various sub-commands that are listed in the section below. To return to the regular command line, enter \"exit\".\nFor Windows Vista and Windows 7 the command line must be opened with administrator privileges. These more recent versions of Windows contain features not available in Windows XP, as indicated in the list below. Also note that Windows XP does not allow operations on removable media whereas in Windows Vista/7, media such as USB keys can be the object of Diskpart operations.\nBefore carrying out an operation on a particular disk, partition, or volume it must first be selected with the \"list disk\", \"list partition\", or \"list volume\" sub-commands followed by a \"select\" command. For example, the necessary sequence of commands can be represented in this schematic way for a disk operation:\nOpen command line->open Diskpart shell->list disk->select disk->do disk operation\nA similar sequence would hold for a operation involving a partition or volume. Diskpart exists as a separate executable file diskpart.exe and can also be accessed through the Run line or the Vista/7 search boxes. Diskpart is a very powerful command and can easily wipe out the contents of a disk or volume so it must be used with great care. Always be sure which volume or disk you are operating on.\nDiskpart command list are shown below. Some commands are not available in Windows XP and they are indicates with an asterisk (*).\nACTIVE - Mark the selected partition as active.\nADD - Add a mirror to a simple volume.\nASSIGN - Assign a drive letter or mount point to the selected volume.\nATTRIBUTES - Manipulate volume or disk attributes.*\nATTACH - Attaches a virtual disk file.*\nAUTOMOUNT - Enable and disable automatic mounting of basic volumes.*\nBREAK - Break a mirror set.\nCLEAN - Clear the configuration information, or all information, off the disk.\nCOMPACT - Attempts to reduce the physical size of the file.*\nCONVERT - Convert between different disk formats.\nCREATE - Create a volume, partition or virtual disk. (No virtual disk management in Windows XP.)\nDELETE - Delete an object.\nDETAIL - Provide details about an object.\nDETACH - Detaches a virtual disk file.*\nEXIT - Exit DiskPart.\nEXTEND - Extend a volume.\nEXPAND - Expands the maximum size available on a virtual disk.*\nFILESYSTEMS - Display current and supported file systems on the volume.*\nFORMAT - Format the volume or partition.*\nGPT - Assign attributes to the selected GPT partition.*\nHELP - Display a list of commands.\nIMPORT - Import a disk group.\nINACTIVE - Mark the selected partition as inactive.\nLIST - Display a list of objects.\nMERGE - Merges a child disk with its parents.*\nONLINE - Online an object that is currently marked as offline.\nOFFLINE - Offline an object that is currently marked as online.\nRECOVER - Refreshes the state of all disks in the selected pack. Attempts recovery on disks in the invalid pack, and resynchronizes mirrored volumes and RAID5 volumes that have stale plex or parity data.*\nREM - Does nothing. This is used to comment scripts.\nREMOVE - Remove a drive letter or mount point assignment.\nREPAIR - Repair a RAID-5 volume with a failed member.\nRESCAN - Rescan the computer looking for disks and volumes.\nRETAIN - Place a retained partition under a simple volume.\nSAN - Display or set the SAN policy for the currently booted OS.*\nSELECT - Shift the focus to an object.\nSETID - Change the partition type.*\nSHRINK - Reduce the size of the selected volume.*\nUNIQUEID - Displays or sets the GUID partition table (GPT) identifier or master boot record (MBR) signature of a disk.*\n(* indicates a command missing from Windows XP.)\nMake a USB key bootable:\nThis example applies to Windows Vista and Windows 7. Windows XP does not support using Diskpart on flash drives.\nOpen a command prompt with administrator rights and enter the following sequence of commands:\ndiskpart\nlist disk\nselect disk {number}\nclean\ncreate partition primary\nselect partition 1\nactiveformat fs=fat32 quick\nassign\nexit\nIn the \"select disk\" command, replace {number} with the drive number of your USB drive. Take care to choose the correct number since this procedure erases everything on the drive you select. The format command given above will create a FAT32 file system. This creates a bootable USB key that can be used for many purposes, once appropriate files are added. For example, it can be used to install Windows 7 (if the flash drive is large enough). If you wish to use the USB key to actually run Windows 7 or otherwise need NTFS formatting, you will need to replace \"format fs=fat32\" with \"format fs=ntfs\" and also modify the boot sector.\nGain access to a hidden partition:\nMost Windows PCs sold today come with a hidden partition containing a restore function. This partition will often have no drive letter assigned and will not be visible in Windows Explorer. It may be possible to make the partition accessible by using Diskpart to assign a drive letter to the partition. However, there are limitations and according to Microsoft not all hidden partitions can be assigned this way. Here is the procedure. Enter the following sequence of commands:\ndiskpart\nlist disk\nselect disk 0 (0 is the normal numbering for the restore partition but be sure to check if this is correct by looking at the sizes)\nlist partition\nselect partition 1 (or the smaller partition with no drive letter if the numbering is different)\nassign X (X is whatever drive letter you want to use)\nexit\nhttps://docs.microsoft.com/en-us/pre...ectedfrom=MSDN","commands":["Diskpart is a separate suite of commands that runs in the command window in its own shell. It is opened by first entering the command \"diskpart\" (without quotes) and then entering one of the various sub-commands that are listed in the section below. To return to the regular command line, enter \"exit\".","Diskpart command list are shown below. Some commands are not available in Windows XP and they are indicates with an asterisk (*).","ACTIVE - Mark the selected partition as active.","ASSIGN - Assign a drive letter or mount point to the selected volume.","CLEAN - Clear the configuration information, or all information, off the disk.","EXIT - Exit DiskPart.","FORMAT - Format the volume or partition.*","diskpart","list disk","select disk {number}","clean","create partition primary","select partition 1","assign","exit","select disk 0 (0 is the normal numbering for the restore partition but be sure to check if this is correct by looking at the sizes)","list partition","select partition 1 (or the smaller partition with no drive letter if the numbering is different)","assign X (X is whatever drive letter you want to use)"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows Server","Command Reference","Technician Fix"],"aliases":[]},{"id":3512,"title":"FSUTIL.exe","category":"Windows Server","product":"Microsoft Windows","tags":["Windows Server","Command Reference","Technician Fix"],"keywords":["fsutil","exe","file","system","utilities","windows","cmd","ss64","com","ckeck","for","bad","sectors","disk","partition","open","administrator","enter","dirty","query","set","self","healing","management","repair","volume","dismount","pathname","diskfree","querycluster","cluster","and","specific","commands","hardlink","quota","usn","sparse","object","reparse"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for fsutil.exe. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to FSUTIL.exe.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"Fsutil - File system utilities - Windows CMD - SS64.com\nTo ckeck for Bad Sectors on a disk or partition open cmd.exe as Administrator & enter:\nfsutil dirty query C:\nfsutil dirty set C:\nSelf healing management:\nFSUTIL repair query C:\nVolume management:\nFSUTIL volume dismount Volume_pathname\nFSUTIL volume diskfree Volume_pathname\nFSUTIL volume querycluster Volume_pathname cluster [cluster...]\nFile and Volume specific commands, Hardlink management, Quota management, USN, Sparse file, Object ID and Reparse point management, 8dot3name FIlename management options (for the Local System):\nShow the current setting for shortname behaviour:\nFSUTIL 8dot3name query Scan for affected registry entries:\nFSUTIL 8dot3name scan [/s] [/l log_file] [/v] DirectoryPath /s Recurse to subdirectories./l Log to file./v Verbose, output log to the console.\nChange the setting for shortname behaviour:\nFSUTIL 8dot3name set [0 through 3] [volume_Path] 1 | 0] When a volume is not specified, this updates the registry:\n0 - Enable 8dot3 creation on all volumes\n1 - Disable 8dot3 creation on all volumes\n2 - Set 8dot3 creation on a per volume basis\n3 - Disable 8dot3 creation on all volumes other than the system volume.\nWhen a volume is specified, this updates individual volume's on disk flag. This operation is only meaningful if the registry value is set to 2.\n0 - Enable 8dot3 creation on this volume\n1 - Disable 8dot3 creation on this volume\nRemove the shortnames for all files within a directory:\nFSUTIL 8dot3name strip [/t] [/s] [/f] [/l log_file] [/v] DirectoryPath\nThis command will permanently remove 8dot3 filenames from a volume.It will list the registry keys pointing to the stripped file names but will not modify the affected registry keys. Stripping will not be performed on any files with full path names longer than the maximum path length of 260 chars.\n**WARNING** If there are affected registry keys and you use the override switch /fit is recommended that you backup your volume as it may lead to unexpected application failures including the inability to uninstall.\n/t - Test mode, perform all operations except the actual stripping of filenames.\n/s - Recurse all subdirectories\n/f - Force, Strip the directory 8.3 filenames even if there are registry conflicts.\n/v - Verbose mode, output log to the console.\n/l - Specify output log file, if not specified this will default to \"%temp%\\8dot3_removal_log@(GMT YYYY-MM-DD HH-MM-SS)\"\nEXAMPLE: fsutil 8dot3name strip /l SS64.log /s D:\\datafiles\nFile system Behavior options:\nFSUTIL behavior query option\nFSUTIL behavior set option\nWhere option is one of:\nAllowExtChar {0|1} Allow extended characters in filenames\nBugcheckOnCorrupt {0|1} Enable bugcheck #\nDisableCompression {0|1} Disable compression #\nDisableEncryption {0|1} Disable encryption #\nDisableDeleteNotify {0|1} SSD TRIM Delete notifications for all volumes #\nDisableLastaccess {0|1} Don't generate last-access times\nDisable8dot3 [volumePath] sfnNumsfnNum is between 0 and 3:\n0 = Create short file names (default).\n1 = don't create short file names.\n2 = Set 8.3 names on a per volume basis.\n3 = Disable 8.3 names on all volumes except the system volume.\nEncryptPagingfile {0|1}QuotaNotify NumSeconds Log quota violations, default=3600 seconds\nMemory usage {1|2} Paged-pool memory cache, 1=default #\nMftZone {1|2|3|4}\nSet MFT Zone, multiple of 200MB\nSymlinkEvaluation L2L:{0|1} Local to local symbolic links #\nSymlinkEvaluation L2R:{0|1} Local to remote symbolic links #\nSymlinkEvaluation R2R:{0|1} Remote to local symbolic links #\nSymlinkEvaluation R2L:{0|1} Remote to remote symbolic links #\n1 = enable option\n0 = Disable option # = Windows7/2008+\nEg: FSUTIL behavior set disablelastaccess 1\nFSUTIL dirty query volume [pathname]\nFSUTIL dirty set volume [pathname]\nMarking a disk as dirty will prompt a Chkdsk at next boot:\nEg: FSUTIL dirty query C:\nCreate a new file of a specific size:\nFSUTIL file createnew filename length\nEg: fsutil file createnew C:\\testfile.txt 1000\nFind a file by user name (if Disk Quotas are enabled):\nFSUTIL file findbysid user directory\nEg : fsutil file findbysid scottb C:\\users\nQuery the allocated ranges for a file:\nFSUTIL file queryallocranges offset=val length=val filename\nOffset : File Offset, the start of the range to querylength : Size, in bytes, of the range.\nEg: fsutil file queryallocranges offset=1024 length=64 C:\\Temp\\sample.txt\nQuery the file ID of a file:\nFSUTIL file queryFileid filename\nDisplay a random link name for the file ID (in most cases the file ID will only have one link name):\nFSUTIL file queryFileNamebyid volume fileID\nSet the short NTFS filename for a file:\nFSUTIL file setshortname filename ShortName\nEg: fsutil file setshortname C:\\testfile.txt tes1.txt\nSet the valid data length for a file:\nFSUTIL file setvaliddata filename datalength.\nEg : fsutil file setvaliddata C:\\testfile.txt 4096\nSet the zero data for a file:\nFSUTIL file setzerodata offset=val length=val filename\nOffset : File offset, the start of the range to set to zeroes\nlength : Byte length of the zeroed range\nEg : fsutil file setzerodata offset=100 length=150 C:\\Temp\\sample.txt\nList all drives (including mapped and Subst drives):\nFSUTIL fsinfo drives\nQuery drive type for a drive:\nFSUTIL fsinfo drivetype volume pathname\nEg : fsutil fsinfo drivetype C:\nScript to list all drives on the local computer:\n@Echo off::\nStore all the drive letters currently in use in a variable:\nFor /f \"tokens=*\" %%L in ('FSUTIL fsinfo drives') do (set _drives=%%L)::\nRemove the first 8 characters - the 'Drives:' prefix :: this may need to adjusted for other languages/localesSet _drives=%_drives:~8%::\nFind and Display the drive type of each drive:\nFor %%D in (%_drives%) do (FSUTIL fsinfo drivetype %%D)\nQuery volume information:\nFSUTIL fsinfo volumeinfo volume pathname\nEg: fsutil fsinfo volumeinfo C:\\\nQuery NTFS specific volume information:\nFSUTIL fsinfo ntfsinfo volume pathname\nEg: fsutil fsinfo ntfsinfo C:\nQuery file system statistics:\nFSUTIL fsinfo statistics volume pathname\nEg: fsutil fsinfo statistics C:\nCreate a hardlink:\nFSUTIL hardlink create New_filename Existing_filename\nEg: fsutil hardlink create c:\\foo.txt c:\\bar.txt\nList hardlink(s) for a file:\nFSUTIL hardlink list filename\nEdit an object identifier:\nFSUTIL objectid {query | set | delete | create}\nQUOTA Management:\nFSUTIL quota {query|disable|track|enforce } C:\nFSUTIL quota violations:\nFSUTIL quota modify volume_pathname threshold limit user\nEg : fsutil quota modify c: 3000 5000 domain\\user\nSelf healing management:\nFSUTIL repair query volume pathname\nFSUTIL repair set volume pathname flags\nFlags: 0x01 - enable general repair\nFlags: 0x08 - warn about potential data loss\nFlags: 0x10 - Disable general repair and bugcheck once on first corruption.\nFSUTIL repair wait volume pathname [wait_type]\nWait types: 0 - Wait for all repairs (default)\nWait types: 1 - Wait for the current repair\nFSUTIL repair initiate volume pathname file_ref#\nfile_ref#: File reference including segment number of the file.\nQuery a reparse point:\nFSUTIL reparsepoint query filename\nEg : fsutil reparsepoint query C:\\Server\nDelete a reparse point:\nFSUTIL reparsepoint delete filename\nEg : fsutil reparsepoint delete C:\\Server\nTransactional Resource Manager management:\nFSUTIL resource create RM_root_pathanmeFSUTIL resource info RM_root_pathname\nClean transactional metadata on next mount:\nFSUTIL resource setautoreset {true|false} RM_root_pathanme\nPrefer consistency over availability:\nFSUTIL resource setconsistent RM_root_pathanme\nPrefer availability over consistency:\nFSUTIL resource setavailable RM_root_pathanme","commands":["Fsutil - File system utilities - Windows CMD - SS64.com","fsutil dirty query C:","fsutil dirty set C:","FSUTIL repair query C:","FSUTIL volume dismount Volume_pathname","FSUTIL volume diskfree Volume_pathname","FSUTIL volume querycluster Volume_pathname cluster [cluster...]","FSUTIL 8dot3name query Scan for affected registry entries:","FSUTIL 8dot3name scan [/s] [/l log_file] [/v] DirectoryPath /s Recurse to subdirectories./l Log to file./v Verbose, output log to the console.","FSUTIL 8dot3name set [0 through 3] [volume_Path] 1 | 0] When a volume is not specified, this updates the registry:","FSUTIL 8dot3name strip [/t] [/s] [/f] [/l log_file] [/v] DirectoryPath","fsutil 8dot3name strip /l SS64.log /s D:\\datafiles","FSUTIL behavior query option","FSUTIL behavior set option","FSUTIL behavior set disablelastaccess 1","FSUTIL dirty query volume [pathname]","FSUTIL dirty set volume [pathname]","FSUTIL file createnew filename length","fsutil file createnew C:\\testfile.txt 1000","FSUTIL file findbysid user directory","FSUTIL file queryallocranges offset=val length=val filename","fsutil file queryallocranges offset=1024 length=64 C:\\Temp\\sample.txt","FSUTIL file queryFileid filename","FSUTIL file queryFileNamebyid volume fileID","FSUTIL file setshortname filename ShortName","fsutil file setshortname C:\\testfile.txt tes1.txt","FSUTIL file setvaliddata filename datalength.","FSUTIL file setzerodata offset=val length=val filename","FSUTIL fsinfo drives","FSUTIL fsinfo drivetype volume pathname","@Echo off::","For /f \"tokens=*\" %%L in ('FSUTIL fsinfo drives') do (set _drives=%%L)::","FSUTIL fsinfo volumeinfo volume pathname","fsutil fsinfo volumeinfo C:\\","FSUTIL fsinfo ntfsinfo volume pathname","fsutil fsinfo ntfsinfo C:","FSUTIL fsinfo statistics volume pathname","fsutil fsinfo statistics C:","FSUTIL hardlink create New_filename Existing_filename","fsutil hardlink create c:\\foo.txt c:\\bar.txt","FSUTIL hardlink list filename","FSUTIL objectid {query | set | delete | create}","FSUTIL quota {query|disable|track|enforce } C:","FSUTIL quota violations:","FSUTIL quota modify volume_pathname threshold limit user","FSUTIL repair query volume pathname","FSUTIL repair set volume pathname flags","FSUTIL repair wait volume pathname [wait_type]","FSUTIL repair initiate volume pathname file_ref#","FSUTIL reparsepoint query filename","FSUTIL reparsepoint delete filename","FSUTIL resource create RM_root_pathanmeFSUTIL resource info RM_root_pathname","FSUTIL resource setautoreset {true|false} RM_root_pathanme","FSUTIL resource setconsistent RM_root_pathanme","FSUTIL resource setavailable RM_root_pathanme"],"sourceDocument":"common_tasks_fixes.txt","platforms":["windows"],"vendors":["Microsoft Windows"],"technologies":["Windows Server","Command Reference","Technician Fix"],"aliases":[]},{"id":3513,"title":"Rebuild the BCD in Windows","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["rebuild","the","bcd","windows","boot","configuration","data","fix","some","startup","issue","store","missing","becomes","corrupted","isn","properly","configured","won","able","start","and","you","see","bootmgr","similar","error","message","pretty","early","process","easiest","solution","simply","which","can","automatically","with","bootrec","command"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for rebuild the bcd in windows. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Rebuild the BCD in Windows.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"Rebuild the Boot Configuration Data to fix some Windows startup issue.\nIf the Windows boot configuration data (BCD) store is missing, becomes corrupted, or isn't properly configured, Windows won't be able to start, and you'll see BOOTMGR is Missing or a similar error message pretty early on in the boot process.\nThe easiest solution to a BCD issue is to simply rebuild it, which you can do automatically with the bootrec command.\nSelect Command Prompt, type the \"bootrec\" command as shown below, and then press Enter:\nbootrec /rebuildbcd\nbcdedit /export c:\\\nbcdbackup attrib c:\\boot\\\nbcd -h -r -s-\nTo rename the BCD store, execute the ren command as shown:\nren c:\\boot\\bcd bcd.old\nTry rebuilding the BCD again by executing the following, followed by Enter:\nbootrec /scanosbootrec /rebuildbcd\nThis command will delete all duplicate entries:\nbcdboot /bcdclean\nTo clean up all invalid entries, run CMD in Recovery Environment (SHIFT+Restart) and use:\nbcdboot /bcdclean full","commands":["bootrec /rebuildbcd","bcdedit /export c:\\","ren c:\\boot\\bcd bcd.old","bcdboot /bcdclean","bcdboot /bcdclean full"],"sourceDocument":"common_tasks_fixes.txt","platforms":["unknown"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3514,"title":"How to use Windows Recovery Environment (WinRE) to troubleshoot common startup issues","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["how","use","windows","recovery","environment","winre","troubleshoot","common","startup","issues","when","operating","system","fails","start","restarts","unexpectedly","the","can","used","run","commands","that","may","resolve","unable","because","disk","corruption","corrupted","missing","files","pending","actions","from","installation","update","media","for","installed"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for how to use windows recovery environment (winre) to troubleshoot common startup issues. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to How to use Windows Recovery Environment (WinRE) to troubleshoot common startup issues.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"When a Windows operating system fails to start or restarts unexpectedly, the Windows Recovery Environment (WinRE) can be used to run commands that may resolve the issues. The system may be unable to start because of disk corruption, corrupted or missing system files, or pending actions from the installation of an update.\nStart the system to the installation media for the installed version of Windows.\n1: On the Install Windows screen, select Next > Repair your computer.\n2: On the System Recovery Options screen, select Next > Command Prompt.\n3: At the command prompt, run the following command by using BCDEdit command-line options to identify the drive letter of the system volume:\nBCDEdit\nIn the Windows Boot Loader section, the drive letter of the system volume is displayed next to \"osdevice.\" (For example, C:)5: At the command prompt, run the following command to complete a check disk for the system volume:\nCHKDSK /f C:\nAt the command prompt, run the following command to complete a System File Check (SFC) for the system volume:\nSFC /scannow /offbootdir=C:\\ /offwindir=C:\\windows\nAt the command prompt, run the following command to complete an image cleanup and health restoration by using the DISM tool:\nDISM /image:C:\\ /cleanup-image /restorehealth\nAt the command prompt, run the following command to revert any pending actions by using the DISM tool.\ndism.exe /image:C:\\ /cleanup-image /revertpendingactions\nNote If the pending actions can't be reverted, you may have to investigate these further.\nClose the Command Prompt window, and then select Reboot.\nEnable/disable Windows Recovery Environment:\nbcdedit /set {default} recoveryenabled Yes\nbcdedit /set {default} recoveryenabled No\nRepair Windows Recovery Environment:\nOpen cmd.exe as Administrator & enter each command separately:\nreagentc /disable\nreagentc /enable\nreagentc /info\nWindows Recovery Environment (Windows RE) and system reset configuration Information:\nWindows RE status:\nEnabled\nWindows RE location:\n\\\\?\\GLOBALROOT\\device\\harddisk0\\partition1\\Recovery\\WindowsRE Boot\nRecovery image location:\nRecovery image index: 0\nCustom image location:\nCustom image index: 0REAGENTC.EXE\nFix Winre.wim corrupted or missing:\nIn order to locate the Winre.wim file, you can search the file on your computer. From an elevated Command Prompt, type the following command to search for the Winre.wim file on C:\ndrive:dir /a /s c:\\winre.wim\nIn a rare case, the Winre.wim file may be stored on another drive. Then you need to change the switch C: to the corresponding drive letter. For example, to search D: drive for the file, type: \"dir /a /s d:\\winre.wim\" (without quotes). When you find the Winre.wim file and it is vaild, you can type command \"reagentc /setreimage /path [path of Winre.wim]\".\nFor example, \"Reagentc /setreimage /path C:\\Recovery\\WindowsRE\"\nIf the Winre.wim file is corrupted, then you can copy the Winre.wim file on another computer that runs the same version of Windows to this computer. If you have the Install.esd file, you can extract that file and then you will get the Winre.wim file.When you get the Winre.wim file on your computer, do not forget to run the \"reagentc /setreimage /path [path]\" command to specify the Windows recovery environment location. Run following command to disable recovery screen due to shutdown failures (which includes yanking the power cord):\nbcdedit /set {default} bootstatuspolicy IgnoreAllFailures\nTo enable the Legacy Boot Policy. Type the following command and hit Enter:\nbcdedit /set {default} bootmenupolicy legacy\nMore BCDEdit /settings:\nhttps://docs.microsoft.com/en-us/windows-hardware/drivers/devtest/bcdedit--set\nNetwork & Internet:","commands":["Start the system to the installation media for the installed version of Windows.","BCDEdit","CHKDSK /f C:","SFC /scannow /offbootdir=C:\\ /offwindir=C:\\windows","DISM /image:C:\\ /cleanup-image /restorehealth","dism.exe /image:C:\\ /cleanup-image /revertpendingactions","bcdedit /set {default} recoveryenabled Yes","bcdedit /set {default} recoveryenabled No","reagentc /disable","reagentc /enable","reagentc /info","bcdedit /set {default} bootstatuspolicy IgnoreAllFailures","bcdedit /set {default} bootmenupolicy legacy"],"sourceDocument":"common_tasks_fixes.txt","platforms":["unknown"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3515,"title":"Check Firewall Status","category":"Networking","product":"Microsoft Windows","tags":["Networking","Command Reference","Technician Fix"],"keywords":["check","firewall","status","netsh","advfirewall","show","currentprofilereset","set","currentprofile","firewallpolicy","blockinbound","allowoutbound"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for check firewall status. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Check Firewall Status.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"netsh advfirewall show currentprofileReset Firewall:netsh advfirewall set currentprofile firewallpolicy blockinbound,allowoutbound","commands":["netsh advfirewall show currentprofileReset Firewall:netsh advfirewall set currentprofile firewallpolicy blockinbound,allowoutbound"],"sourceDocument":"common_tasks_fixes.txt","platforms":["unknown"],"vendors":["Microsoft Windows"],"technologies":["Networking","Command Reference","Technician Fix"],"aliases":[]},{"id":3516,"title":"Show Teredo status","category":"Networking","product":"Microsoft Windows","tags":["Networking","Command Reference","Technician Fix"],"keywords":["show","teredo","status","netsh","interface","state","enable","set","type","default","disable"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for show teredo status. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Show Teredo status.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"netsh interface Teredo show state\nEnable Teredo:\nnetsh interface Teredo set state type=default\nDisable Teredo:\nnetsh interface Teredo set state disable","commands":["netsh interface Teredo show state","netsh interface Teredo set state type=default","netsh interface Teredo set state disable"],"sourceDocument":"common_tasks_fixes.txt","platforms":["unknown"],"vendors":["Microsoft Windows"],"technologies":["Networking","Command Reference","Technician Fix"],"aliases":[]},{"id":3517,"title":"Repair Internet connections","category":"Networking","product":"Microsoft Windows","tags":["Networking","Command Reference","Technician Fix"],"keywords":["repair","internet","connections","ipconfig","release","renew","flushdns","netsh","winsock","reset","net","localgroup","administrators","localservice","add","fsutil","resource","setautoreset","true","int","resetlog","txt","all"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for repair internet connections. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Repair Internet connections.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"ipconfig /release\nipconfig /renew\nipconfig /flushdns\nNetsh winsock reset\nnet localgroup administrators localservice /add\nfsutil resource setautoreset true C:\\\nnetsh int ip reset resetlog.txt\nnetsh winsock reset all","commands":["ipconfig /release","ipconfig /renew","ipconfig /flushdns","Netsh winsock reset","net localgroup administrators localservice /add","fsutil resource setautoreset true C:\\","netsh int ip reset resetlog.txt","netsh winsock reset all"],"sourceDocument":"common_tasks_fixes.txt","platforms":["unknown"],"vendors":["Microsoft Windows"],"technologies":["Networking","Command Reference","Technician Fix"],"aliases":[]},{"id":3518,"title":"Delete a mapped network drive","category":"Networking","product":"Microsoft Windows","tags":["Networking","Command Reference","Technician Fix"],"keywords":["delete","mapped","network","drive","net","use","you","prefer","command","line","environments","can","the","drives","from","prompt","powershell","open","one","like","best","and","run","this","letter","then","press","enter","for","example","have","mapping","which","assigned","type","are","informed","that","was","deleted"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for delete a mapped network drive. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Delete a mapped network drive.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"net use /delete\nIf you prefer command-line environments, you can use the net use command to delete mapped network drives from Command Prompt or PowerShell. Open the one you like best and run this command: net use [Mapped Drive Letter] /delete. Then, press Enter. For example, we have a drive mapping to which we assigned the letter Z, so we have to type: net use Z: /delete. You are informed that the mapped drive was deleted successfully, and the network drive disappears immediately from File Explorer.\nNOTE: The net use /delete command only works for drive mappings that have a letter assigned. It doesn't work for network location mappings such as FTP servers or web servers.\nRun \"net use * /delete\" in Command Prompt or PowerShell to delete all the mapped network drives.\nIf you have more than one mapped network drive configured and you want to delete them all at once, you can use the same net use command to disconnect them all at once. Open Command Prompt and run the following command:\nnet use * /delete.","commands":["net use /delete","net use * /delete."],"sourceDocument":"common_tasks_fixes.txt","platforms":["unknown"],"vendors":["Microsoft Windows"],"technologies":["Networking","Command Reference","Technician Fix"],"aliases":[]},{"id":3519,"title":"netstat (network statistics) is a command line tool that displays network connections (both incoming and outgoing). It can be used on Windows, Macinto","category":"Networking","product":"Microsoft Windows","tags":["Networking","Command Reference","Technician Fix"],"keywords":["netstat","network","statistics","command","line","tool","that","displays","connections","both","incoming","and","outgoing","can","used","windows","macinto","all","active","including","tcp","udp","ports","address","numbers","instead","names","executable","involved","creating","each","connection","listening","port","example","the","output","this","itself","long"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for netstat (network statistics) is a command line tool that displays network connections (both incoming and outgoing). it can be used on windows, macinto. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to netstat (network statistics) is a command line tool that displays network connections (both incoming and outgoing). It can be used on Windows, Macinto.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"-a = displays all active connections including TCP and UDP ports\n-n = displays address as numbers instead of names\n-b = displays executable involved in creating each connection or listening port\nCommand example: netstat -na\nThe output of this command used by itself is long and time-consuming to scroll through to find what you are looking for.\nTo make this search easier, combine the netstat command with the find or grep command using pipe (|).To type the pipe (|) character, use Shift + \\ (backslash key).\nThe find command is for Windows-based systems only and can be used to search the results of the netstat command to find specific items. To find items listening on port 80, type: netstat -na | find \"80\"\nThe results of this command may find more information than needed. For example:10.80.0.1127.0.0.1:8080\nNeither of these is the desired information, so we can add additional text to narrow the search, such as: netstat -na | find \":80 \"This search is specific enough to show only port :80 items. It is important to include the space after the 0. Without it, the response will still show :8080 items.\nThe same information applies to using the grep command: netstat -na | grep \":80 \"If nothing is returned after entering this command, that means nothing is listening on that port for that machine. Keep in mind there may be software in which ports can be in use but not listening; netstat will show only ports that are listening.\nWindows Examples:\nnetstat -na | find \":80 \"netstat -na | find \":5432\"netstat -na | find \":443\"","commands":["netstat -na","netstat -na | find \":80 \"netstat -na | find \":5432\"netstat -na | find \":443\""],"sourceDocument":"common_tasks_fixes.txt","platforms":["unknown"],"vendors":["Microsoft Windows"],"technologies":["Networking","Command Reference","Technician Fix"],"aliases":[]},{"id":3520,"title":"create the wireless network report","category":"Networking","product":"Microsoft Windows","tags":["Networking","Command Reference","Technician Fix"],"keywords":["create","the","wireless","network","report","netsh","wlan","show","wlanreport"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for create the wireless network report. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to create the wireless network report.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"netsh wlan show wlanreport","commands":["netsh wlan show wlanreport"],"sourceDocument":"common_tasks_fixes.txt","platforms":["unknown"],"vendors":["Microsoft Windows"],"technologies":["Networking","Command Reference","Technician Fix"],"aliases":[]},{"id":3521,"title":"Renew an IP address:","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["renew","address","ipconfig","release","flush","dns","flushdns","reset","winsock","netsh","generate","log","file","the","changes","winsocklog","txt"],"errorCode":"","eventId":"","severity":"High","summary":"Technician reference for renew an ip address:. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Renew an IP address:.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"ipconfig /release\nFlush DNS:\nIpconfig /flushdns\nReset Winsock:\nNetsh winsock reset\nGenerate a log file of the changes:\nnetsh winsock reset c:\\winsocklog.txt","commands":["ipconfig /release","Ipconfig /flushdns","Netsh winsock reset","netsh winsock reset c:\\winsocklog.txt"],"sourceDocument":"common_tasks_fixes.txt","platforms":["unknown"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3522,"title":"Google incognito","category":"Windows","product":"Microsoft Windows","tags":["Windows","Command Reference","Technician Fix"],"keywords":["google","incognito","program","files","x86","chrome","application","exe"],"errorCode":"","eventId":"","severity":"Medium","summary":"Technician reference for google incognito. Review the complete procedure, prerequisites, and command impact before making changes.","rootCause":"This is a technician workflow rather than a single error condition. Use the surrounding symptoms, logs, system role, and recent changes to confirm that the procedure applies before running any command.","resolution":"1. Confirm the affected system, symptom, backups, and maintenance approval.\n2. Open the Commands tab and review each command and placeholder carefully.\n3. Run only the commands applicable to the diagnosed condition, one at a time.\n4. Capture output and stop if results differ from expectations.\n5. Restart only when required, then validate the original symptom and service health.","emailScript":"Hello,\n\nWe reviewed the issue related to Google incognito.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are applying the appropriate Windows maintenance steps and will verify normal operation afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Save your work and close affected applications if IT Support requests it.\n2. Keep the computer connected to power and the company network.\n3. Do not run administrative commands unless directed by IT Support.\n4. Report any new message or restart prompt that appears.","notes":"\"C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe\" -incognito","commands":["\"C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe\" -incognito"],"sourceDocument":"common_tasks_fixes.txt","platforms":["unknown"],"vendors":["Microsoft Windows"],"technologies":["Windows","Command Reference","Technician Fix"],"aliases":[]},{"id":3523,"title":"0x80004005 - Unspecified error","category":"Windows","product":"Microsoft Windows","tags":["Windows","WINDOWS GENERAL","Error Code"],"keywords":["0x80004005","0x80004005","windows","general","unspecified","error","capture","the","full","message","operation","and","matching","event","viewer","entry","verify","permissions","paths","services","dependencies","network","access","pending","restart","state","repair","affected","component","for","corruption","run","dism","online","cleanup","image","restorehealth","then","sfc","scannow"],"errorCode":"0x80004005","eventId":"","severity":"Critical","summary":"Unspecified error.","rootCause":"The code is contextual and can result from permissions, missing or damaged components, service state, configuration, connectivity, or a pending restart. Confirm the failing operation and matching logs before selecting a repair.","resolution":"1. Capture the full message, operation, and matching Event Viewer entry.\n2. Verify permissions, paths, services, dependencies, network access, and pending restart state.\n3. Repair the affected component; for Windows corruption run DISM /Online /Cleanup-Image /RestoreHealth, then sfc /scannow.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80004005, which is related to unspecified error.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80004005 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS GENERAL\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Windows"],"technologies":["Windows","WINDOWS GENERAL","Error Code"],"aliases":["0x80004005"]},{"id":3524,"title":"0x80070003 - The system cannot find the path specified","category":"Windows","product":"Microsoft Windows","tags":["Windows","WINDOWS GENERAL","Error Code"],"keywords":["0x80070003","0x80070003","windows","general","the","system","cannot","find","path","specified","capture","full","message","operation","and","matching","event","viewer","entry","verify","permissions","paths","services","dependencies","network","access","pending","restart","state","repair","affected","component","for","corruption","run","dism","online","cleanup","image","restorehealth","then"],"errorCode":"0x80070003","eventId":"","severity":"Critical","summary":"The system cannot find the path specified.","rootCause":"The code is contextual and can result from permissions, missing or damaged components, service state, configuration, connectivity, or a pending restart. Confirm the failing operation and matching logs before selecting a repair.","resolution":"1. Capture the full message, operation, and matching Event Viewer entry.\n2. Verify permissions, paths, services, dependencies, network access, and pending restart state.\n3. Repair the affected component; for Windows corruption run DISM /Online /Cleanup-Image /RestoreHealth, then sfc /scannow.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80070003, which is related to the system cannot find the path specified.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80070003 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS GENERAL\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Windows"],"technologies":["Windows","WINDOWS GENERAL","Error Code"],"aliases":["0x80070003"]},{"id":3525,"title":"0x80070035 - The network path was not found","category":"Windows","product":"Microsoft Windows","tags":["Windows","WINDOWS GENERAL","Error Code"],"keywords":["0x80070035","0x80070035","windows","general","the","network","path","was","not","found","capture","full","message","operation","and","matching","event","viewer","entry","verify","permissions","paths","services","dependencies","access","pending","restart","state","repair","affected","component","for","corruption","run","dism","online","cleanup","image","restorehealth","then","sfc"],"errorCode":"0x80070035","eventId":"","severity":"Critical","summary":"The network path was not found.","rootCause":"The code is contextual and can result from permissions, missing or damaged components, service state, configuration, connectivity, or a pending restart. Confirm the failing operation and matching logs before selecting a repair.","resolution":"1. Capture the full message, operation, and matching Event Viewer entry.\n2. Verify permissions, paths, services, dependencies, network access, and pending restart state.\n3. Repair the affected component; for Windows corruption run DISM /Online /Cleanup-Image /RestoreHealth, then sfc /scannow.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80070035, which is related to the network path was not found.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80070035 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS GENERAL\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Windows"],"technologies":["Windows","WINDOWS GENERAL","Error Code"],"aliases":["0x80070035"]},{"id":3526,"title":"0x80070057 - The parameter is incorrect","category":"Windows","product":"Microsoft Windows","tags":["Windows","WINDOWS GENERAL","Error Code"],"keywords":["0x80070057","0x80070057","windows","general","the","parameter","incorrect","capture","full","message","operation","and","matching","event","viewer","entry","verify","permissions","paths","services","dependencies","network","access","pending","restart","state","repair","affected","component","for","corruption","run","dism","online","cleanup","image","restorehealth","then","sfc","scannow"],"errorCode":"0x80070057","eventId":"","severity":"Critical","summary":"The parameter is incorrect.","rootCause":"The code is contextual and can result from permissions, missing or damaged components, service state, configuration, connectivity, or a pending restart. Confirm the failing operation and matching logs before selecting a repair.","resolution":"1. Capture the full message, operation, and matching Event Viewer entry.\n2. Verify permissions, paths, services, dependencies, network access, and pending restart state.\n3. Repair the affected component; for Windows corruption run DISM /Online /Cleanup-Image /RestoreHealth, then sfc /scannow.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80070057, which is related to the parameter is incorrect.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80070057 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS GENERAL\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Windows"],"technologies":["Windows","WINDOWS GENERAL","Error Code"],"aliases":["0x80070057"]},{"id":3527,"title":"0x80070103 - A same or newer driver is already installed","category":"Windows","product":"Microsoft Windows","tags":["Windows","WINDOWS GENERAL","Error Code"],"keywords":["0x80070103","0x80070103","windows","general","same","newer","driver","already","installed","capture","the","full","message","operation","and","matching","event","viewer","entry","verify","permissions","paths","services","dependencies","network","access","pending","restart","state","repair","affected","component","for","corruption","run","dism","online","cleanup","image","restorehealth","then"],"errorCode":"0x80070103","eventId":"","severity":"Critical","summary":"A same or newer driver is already installed.","rootCause":"The code is contextual and can result from permissions, missing or damaged components, service state, configuration, connectivity, or a pending restart. Confirm the failing operation and matching logs before selecting a repair.","resolution":"1. Capture the full message, operation, and matching Event Viewer entry.\n2. Verify permissions, paths, services, dependencies, network access, and pending restart state.\n3. Repair the affected component; for Windows corruption run DISM /Online /Cleanup-Image /RestoreHealth, then sfc /scannow.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80070103, which is related to a same or newer driver is already installed.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80070103 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS GENERAL\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Windows"],"technologies":["Windows","WINDOWS GENERAL","Error Code"],"aliases":["0x80070103"]},{"id":3528,"title":"0x80070422 - A required service is disabled","category":"Windows","product":"Microsoft Windows","tags":["Windows","WINDOWS GENERAL","Error Code"],"keywords":["0x80070422","0x80070422","windows","general","required","service","disabled","capture","the","full","message","operation","and","matching","event","viewer","entry","verify","permissions","paths","services","dependencies","network","access","pending","restart","state","repair","affected","component","for","corruption","run","dism","online","cleanup","image","restorehealth","then","sfc","scannow"],"errorCode":"0x80070422","eventId":"","severity":"Critical","summary":"A required service is disabled.","rootCause":"The code is contextual and can result from permissions, missing or damaged components, service state, configuration, connectivity, or a pending restart. Confirm the failing operation and matching logs before selecting a repair.","resolution":"1. Capture the full message, operation, and matching Event Viewer entry.\n2. Verify permissions, paths, services, dependencies, network access, and pending restart state.\n3. Repair the affected component; for Windows corruption run DISM /Online /Cleanup-Image /RestoreHealth, then sfc /scannow.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80070422, which is related to a required service is disabled.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80070422 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS GENERAL\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Windows"],"technologies":["Windows","WINDOWS GENERAL","Error Code"],"aliases":["0x80070422"]},{"id":3529,"title":"0x80070424 - The specified service is not installed","category":"Windows","product":"Microsoft Windows","tags":["Windows","WINDOWS GENERAL","Error Code"],"keywords":["0x80070424","0x80070424","windows","general","the","specified","service","not","installed","capture","full","message","operation","and","matching","event","viewer","entry","verify","permissions","paths","services","dependencies","network","access","pending","restart","state","repair","affected","component","for","corruption","run","dism","online","cleanup","image","restorehealth","then","sfc"],"errorCode":"0x80070424","eventId":"","severity":"Critical","summary":"The specified service is not installed.","rootCause":"The code is contextual and can result from permissions, missing or damaged components, service state, configuration, connectivity, or a pending restart. Confirm the failing operation and matching logs before selecting a repair.","resolution":"1. Capture the full message, operation, and matching Event Viewer entry.\n2. Verify permissions, paths, services, dependencies, network access, and pending restart state.\n3. Repair the affected component; for Windows corruption run DISM /Online /Cleanup-Image /RestoreHealth, then sfc /scannow.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80070424, which is related to the specified service is not installed.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80070424 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS GENERAL\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Windows"],"technologies":["Windows","WINDOWS GENERAL","Error Code"],"aliases":["0x80070424"]},{"id":3530,"title":"0x80070490 - Element not found","category":"Windows","product":"Microsoft Windows","tags":["Windows","WINDOWS GENERAL","Error Code"],"keywords":["0x80070490","0x80070490","windows","general","element","not","found","capture","the","full","message","operation","and","matching","event","viewer","entry","verify","permissions","paths","services","dependencies","network","access","pending","restart","state","repair","affected","component","for","corruption","run","dism","online","cleanup","image","restorehealth","then","sfc","scannow"],"errorCode":"0x80070490","eventId":"","severity":"Critical","summary":"Element not found.","rootCause":"The code is contextual and can result from permissions, missing or damaged components, service state, configuration, connectivity, or a pending restart. Confirm the failing operation and matching logs before selecting a repair.","resolution":"1. Capture the full message, operation, and matching Event Viewer entry.\n2. Verify permissions, paths, services, dependencies, network access, and pending restart state.\n3. Repair the affected component; for Windows corruption run DISM /Online /Cleanup-Image /RestoreHealth, then sfc /scannow.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80070490, which is related to element not found.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80070490 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS GENERAL\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Windows"],"technologies":["Windows","WINDOWS GENERAL","Error Code"],"aliases":["0x80070490"]},{"id":3531,"title":"0x800705B4 - The operation timed out","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Windows","WINDOWS GENERAL","Error Code","Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0x800705B4","0x800705b4","windows","general","the","operation","timed","out","capture","full","message","and","matching","event","viewer","entry","verify","permissions","paths","services","dependencies","network","access","pending","restart","state","repair","affected","component","for","corruption","run","dism","online","cleanup","image","restorehealth","then","sfc","scannow","800705B4","Enrollment or Autopilot Operation Timed Out","The workflow timed out waiting for network, TPM, policy, application, or service activity.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0x800705B4","eventId":"","severity":"Critical","summary":"The operation timed out.","rootCause":"The workflow timed out waiting for network, TPM, policy, application, or service activity.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Correlate the phase with Autopilot and MDM logs; validate DNS, proxy, firewall, TLS, time, TPM, and endpoints.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x800705B4 - Enrollment or Autopilot Operation Timed Out.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","lastUpdated":"2026-08-10","vendors":["Microsoft Intune"],"technologies":["Windows","WINDOWS GENERAL","Error Code","Microsoft Intune","MDM","Windows Enrollment"],"aliases":["0x800705B4"]},{"id":3532,"title":"0x80070643 - Fatal error during installation","category":"Windows","product":"Microsoft Windows","tags":["Windows","WINDOWS GENERAL","Error Code"],"keywords":["0x80070643","0x80070643","windows","general","fatal","error","during","installation","capture","the","full","message","operation","and","matching","event","viewer","entry","verify","permissions","paths","services","dependencies","network","access","pending","restart","state","repair","affected","component","for","corruption","run","dism","online","cleanup","image","restorehealth","then","sfc"],"errorCode":"0x80070643","eventId":"","severity":"Critical","summary":"Fatal error during installation.","rootCause":"The code is contextual and can result from permissions, missing or damaged components, service state, configuration, connectivity, or a pending restart. Confirm the failing operation and matching logs before selecting a repair.","resolution":"1. Capture the full message, operation, and matching Event Viewer entry.\n2. Verify permissions, paths, services, dependencies, network access, and pending restart state.\n3. Repair the affected component; for Windows corruption run DISM /Online /Cleanup-Image /RestoreHealth, then sfc /scannow.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80070643, which is related to fatal error during installation.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80070643 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS GENERAL\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Windows"],"technologies":["Windows","WINDOWS GENERAL","Error Code"],"aliases":["0x80070643"]},{"id":3533,"title":"0x800706BA - The RPC server is unavailable","category":"Windows","product":"Microsoft Windows","tags":["Windows","WINDOWS GENERAL","Error Code"],"keywords":["0x800706BA","0x800706ba","windows","general","the","rpc","server","unavailable","capture","full","message","operation","and","matching","event","viewer","entry","verify","permissions","paths","services","dependencies","network","access","pending","restart","state","repair","affected","component","for","corruption","run","dism","online","cleanup","image","restorehealth","then","sfc","scannow"],"errorCode":"0x800706BA","eventId":"","severity":"Critical","summary":"The RPC server is unavailable.","rootCause":"The code is contextual and can result from permissions, missing or damaged components, service state, configuration, connectivity, or a pending restart. Confirm the failing operation and matching logs before selecting a repair.","resolution":"1. Capture the full message, operation, and matching Event Viewer entry.\n2. Verify permissions, paths, services, dependencies, network access, and pending restart state.\n3. Repair the affected component; for Windows corruption run DISM /Online /Cleanup-Image /RestoreHealth, then sfc /scannow.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x800706BA, which is related to the rpc server is unavailable.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x800706BA and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS GENERAL\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Windows"],"technologies":["Windows","WINDOWS GENERAL","Error Code"],"aliases":["0x800706BA"]},{"id":3534,"title":"0x800706BE - The remote procedure call failed","category":"Windows","product":"Microsoft Windows","tags":["Windows","WINDOWS GENERAL","Error Code"],"keywords":["0x800706BE","0x800706be","windows","general","the","remote","procedure","call","failed","capture","full","message","operation","and","matching","event","viewer","entry","verify","permissions","paths","services","dependencies","network","access","pending","restart","state","repair","affected","component","for","corruption","run","dism","online","cleanup","image","restorehealth","then","sfc"],"errorCode":"0x800706BE","eventId":"","severity":"Critical","summary":"The remote procedure call failed.","rootCause":"The code is contextual and can result from permissions, missing or damaged components, service state, configuration, connectivity, or a pending restart. Confirm the failing operation and matching logs before selecting a repair.","resolution":"1. Capture the full message, operation, and matching Event Viewer entry.\n2. Verify permissions, paths, services, dependencies, network access, and pending restart state.\n3. Repair the affected component; for Windows corruption run DISM /Online /Cleanup-Image /RestoreHealth, then sfc /scannow.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x800706BE, which is related to the remote procedure call failed.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x800706BE and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS GENERAL\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Windows"],"technologies":["Windows","WINDOWS GENERAL","Error Code"],"aliases":["0x800706BE"]},{"id":3535,"title":"0x80072EE7 - The server name could not be resolved","category":"Windows","product":"Microsoft Windows","tags":["Windows","WINDOWS GENERAL","Error Code"],"keywords":["0x80072EE7","0x80072ee7","windows","general","the","server","name","could","not","resolved","capture","full","message","operation","and","matching","event","viewer","entry","verify","permissions","paths","services","dependencies","network","access","pending","restart","state","repair","affected","component","for","corruption","run","dism","online","cleanup","image","restorehealth","then"],"errorCode":"0x80072EE7","eventId":"","severity":"Critical","summary":"The server name could not be resolved.","rootCause":"The code is contextual and can result from permissions, missing or damaged components, service state, configuration, connectivity, or a pending restart. Confirm the failing operation and matching logs before selecting a repair.","resolution":"1. Capture the full message, operation, and matching Event Viewer entry.\n2. Verify permissions, paths, services, dependencies, network access, and pending restart state.\n3. Repair the affected component; for Windows corruption run DISM /Online /Cleanup-Image /RestoreHealth, then sfc /scannow.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80072EE7, which is related to the server name could not be resolved.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80072EE7 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS GENERAL\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Windows"],"technologies":["Windows","WINDOWS GENERAL","Error Code"],"aliases":["0x80072EE7"]},{"id":3536,"title":"0x80072F8F - Secure connection or certificate validation failed","category":"Windows","product":"Microsoft Windows","tags":["Windows","WINDOWS GENERAL","Error Code"],"keywords":["0x80072F8F","0x80072f8f","windows","general","secure","connection","certificate","validation","failed","capture","the","full","message","operation","and","matching","event","viewer","entry","verify","permissions","paths","services","dependencies","network","access","pending","restart","state","repair","affected","component","for","corruption","run","dism","online","cleanup","image","restorehealth","then"],"errorCode":"0x80072F8F","eventId":"","severity":"Critical","summary":"Secure connection or certificate validation failed.","rootCause":"The code is contextual and can result from permissions, missing or damaged components, service state, configuration, connectivity, or a pending restart. Confirm the failing operation and matching logs before selecting a repair.","resolution":"1. Capture the full message, operation, and matching Event Viewer entry.\n2. Verify permissions, paths, services, dependencies, network access, and pending restart state.\n3. Repair the affected component; for Windows corruption run DISM /Online /Cleanup-Image /RestoreHealth, then sfc /scannow.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80072F8F, which is related to secure connection or certificate validation failed.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80072F8F and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS GENERAL\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Windows"],"technologies":["Windows","WINDOWS GENERAL","Error Code"],"aliases":["0x80072F8F"]},{"id":3537,"title":"0x8024402C - Windows Update proxy or DNS configuration is invalid","category":"Patch Management","product":"Windows Update","tags":["Patch Management","WINDOWS UPDATE","Error Code"],"keywords":["0x8024402C","0x8024402c","windows","update","proxy","dns","configuration","invalid","review","windowsupdate","log","and","cbs","for","the","failing","package","phase","run","troubleshooter","confirm","services","disk","space","endpoint","access","repair","servicing","with","dism","sfc","reset","components","only","logs","indicate","cache","datastore","damage"],"errorCode":"0x8024402C","eventId":"","severity":"Medium","summary":"Windows Update proxy or DNS configuration is invalid.","rootCause":"Windows servicing, update metadata, component-store corruption, policy, connectivity, or a pending restart can produce this code. Confirm the exact update and servicing-log context before resetting components.","resolution":"1. Review WindowsUpdate.log and CBS.log for the failing package or phase.\n2. Run the Windows Update troubleshooter, confirm update services, disk space, DNS, proxy, and endpoint access.\n3. Repair servicing with DISM and SFC; reset update components only if logs indicate cache or datastore damage.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x8024402C, which is related to windows update proxy or dns configuration is invalid.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x8024402C and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS UPDATE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["Patch Management","WINDOWS UPDATE","Error Code"],"aliases":["0x8024402C"]},{"id":3538,"title":"0x80244022 - The update service returned HTTP 503 Service Unavailable","category":"Patch Management","product":"Windows Update","tags":["Patch Management","WINDOWS UPDATE","Error Code"],"keywords":["0x80244022","0x80244022","windows","update","the","service","returned","http","503","unavailable","review","windowsupdate","log","and","cbs","for","failing","package","phase","run","troubleshooter","confirm","services","disk","space","dns","proxy","endpoint","access","repair","servicing","with","dism","sfc","reset","components","only","logs","indicate","cache","datastore"],"errorCode":"0x80244022","eventId":"","severity":"High","summary":"The update service returned HTTP 503 Service Unavailable.","rootCause":"Windows servicing, update metadata, component-store corruption, policy, connectivity, or a pending restart can produce this code. Confirm the exact update and servicing-log context before resetting components.","resolution":"1. Review WindowsUpdate.log and CBS.log for the failing package or phase.\n2. Run the Windows Update troubleshooter, confirm update services, disk space, DNS, proxy, and endpoint access.\n3. Repair servicing with DISM and SFC; reset update components only if logs indicate cache or datastore damage.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80244022, which is related to the update service returned http 503 service unavailable.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80244022 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS UPDATE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["Patch Management","WINDOWS UPDATE","Error Code"],"aliases":["0x80244022"]},{"id":3539,"title":"0x800F081F - The repair source files could not be found","category":"Patch Management","product":"Windows Update","tags":["Patch Management","WINDOWS UPDATE","Error Code"],"keywords":["0x800F081F","0x800f081f","windows","update","the","repair","source","files","could","not","found","review","windowsupdate","log","and","cbs","for","failing","package","phase","run","troubleshooter","confirm","services","disk","space","dns","proxy","endpoint","access","servicing","with","dism","sfc","reset","components","only","logs","indicate","cache","datastore"],"errorCode":"0x800F081F","eventId":"","severity":"Low","summary":"The repair source files could not be found.","rootCause":"Windows servicing, update metadata, component-store corruption, policy, connectivity, or a pending restart can produce this code. Confirm the exact update and servicing-log context before resetting components.","resolution":"1. Review WindowsUpdate.log and CBS.log for the failing package or phase.\n2. Run the Windows Update troubleshooter, confirm update services, disk space, DNS, proxy, and endpoint access.\n3. Repair servicing with DISM and SFC; reset update components only if logs indicate cache or datastore damage.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x800F081F, which is related to the repair source files could not be found.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x800F081F and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS UPDATE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["Patch Management","WINDOWS UPDATE","Error Code"],"aliases":["0x800F081F"]},{"id":3540,"title":"0x800F0906 - Windows could not download required source files","category":"Patch Management","product":"Windows Update","tags":["Patch Management","WINDOWS UPDATE","Error Code"],"keywords":["0x800F0906","0x800f0906","windows","update","could","not","download","required","source","files","review","windowsupdate","log","and","cbs","for","the","failing","package","phase","run","troubleshooter","confirm","services","disk","space","dns","proxy","endpoint","access","repair","servicing","with","dism","sfc","reset","components","only","logs","indicate","cache"],"errorCode":"0x800F0906","eventId":"","severity":"Low","summary":"Windows could not download required source files.","rootCause":"Windows servicing, update metadata, component-store corruption, policy, connectivity, or a pending restart can produce this code. Confirm the exact update and servicing-log context before resetting components.","resolution":"1. Review WindowsUpdate.log and CBS.log for the failing package or phase.\n2. Run the Windows Update troubleshooter, confirm update services, disk space, DNS, proxy, and endpoint access.\n3. Repair servicing with DISM and SFC; reset update components only if logs indicate cache or datastore damage.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x800F0906, which is related to windows could not download required source files.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x800F0906 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS UPDATE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["Patch Management","WINDOWS UPDATE","Error Code"],"aliases":["0x800F0906"]},{"id":3541,"title":"0x800F0922 - Windows servicing could not complete the update","category":"Patch Management","product":"Windows Update","tags":["Patch Management","WINDOWS UPDATE","Error Code"],"keywords":["0x800F0922","0x800f0922","windows","update","servicing","could","not","complete","the","review","windowsupdate","log","and","cbs","for","failing","package","phase","run","troubleshooter","confirm","services","disk","space","dns","proxy","endpoint","access","repair","with","dism","sfc","reset","components","only","logs","indicate","cache","datastore","damage"],"errorCode":"0x800F0922","eventId":"","severity":"Low","summary":"Windows servicing could not complete the update.","rootCause":"Windows servicing, update metadata, component-store corruption, policy, connectivity, or a pending restart can produce this code. Confirm the exact update and servicing-log context before resetting components.","resolution":"1. Review WindowsUpdate.log and CBS.log for the failing package or phase.\n2. Run the Windows Update troubleshooter, confirm update services, disk space, DNS, proxy, and endpoint access.\n3. Repair servicing with DISM and SFC; reset update components only if logs indicate cache or datastore damage.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x800F0922, which is related to windows servicing could not complete the update.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x800F0922 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS UPDATE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["Patch Management","WINDOWS UPDATE","Error Code"],"aliases":["0x800F0922"]},{"id":3542,"title":"0x80073712 - The Windows component store is corrupted","category":"Patch Management","product":"Windows Update","tags":["Patch Management","WINDOWS UPDATE","Error Code"],"keywords":["0x80073712","0x80073712","windows","update","the","component","store","corrupted","review","windowsupdate","log","and","cbs","for","failing","package","phase","run","troubleshooter","confirm","services","disk","space","dns","proxy","endpoint","access","repair","servicing","with","dism","sfc","reset","components","only","logs","indicate","cache","datastore","damage"],"errorCode":"0x80073712","eventId":"","severity":"Critical","summary":"The Windows component store is corrupted.","rootCause":"Windows servicing, update metadata, component-store corruption, policy, connectivity, or a pending restart can produce this code. Confirm the exact update and servicing-log context before resetting components.","resolution":"1. Review WindowsUpdate.log and CBS.log for the failing package or phase.\n2. Run the Windows Update troubleshooter, confirm update services, disk space, DNS, proxy, and endpoint access.\n3. Repair servicing with DISM and SFC; reset update components only if logs indicate cache or datastore damage.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80073712, which is related to the windows component store is corrupted.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80073712 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS UPDATE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["Patch Management","WINDOWS UPDATE","Error Code"],"aliases":["0x80073712"]},{"id":3543,"title":"0x8024200D - The update requires another download","category":"Patch Management","product":"Windows Update","tags":["Patch Management","WINDOWS UPDATE","Error Code"],"keywords":["0x8024200D","0x8024200d","windows","update","the","requires","another","download","review","windowsupdate","log","and","cbs","for","failing","package","phase","run","troubleshooter","confirm","services","disk","space","dns","proxy","endpoint","access","repair","servicing","with","dism","sfc","reset","components","only","logs","indicate","cache","datastore","damage"],"errorCode":"0x8024200D","eventId":"","severity":"Low","summary":"The update requires another download.","rootCause":"Windows servicing, update metadata, component-store corruption, policy, connectivity, or a pending restart can produce this code. Confirm the exact update and servicing-log context before resetting components.","resolution":"1. Review WindowsUpdate.log and CBS.log for the failing package or phase.\n2. Run the Windows Update troubleshooter, confirm update services, disk space, DNS, proxy, and endpoint access.\n3. Repair servicing with DISM and SFC; reset update components only if logs indicate cache or datastore damage.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x8024200D, which is related to the update requires another download.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x8024200D and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS UPDATE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["Patch Management","WINDOWS UPDATE","Error Code"],"aliases":["0x8024200D"]},{"id":3544,"title":"0x80246007 - The update was not downloaded","category":"Patch Management","product":"Windows Update","tags":["Patch Management","WINDOWS UPDATE","Error Code"],"keywords":["0x80246007","0x80246007","windows","update","the","was","not","downloaded","review","windowsupdate","log","and","cbs","for","failing","package","phase","run","troubleshooter","confirm","services","disk","space","dns","proxy","endpoint","access","repair","servicing","with","dism","sfc","reset","components","only","logs","indicate","cache","datastore","damage"],"errorCode":"0x80246007","eventId":"","severity":"Low","summary":"The update was not downloaded.","rootCause":"Windows servicing, update metadata, component-store corruption, policy, connectivity, or a pending restart can produce this code. Confirm the exact update and servicing-log context before resetting components.","resolution":"1. Review WindowsUpdate.log and CBS.log for the failing package or phase.\n2. Run the Windows Update troubleshooter, confirm update services, disk space, DNS, proxy, and endpoint access.\n3. Repair servicing with DISM and SFC; reset update components only if logs indicate cache or datastore damage.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80246007, which is related to the update was not downloaded.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80246007 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS UPDATE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["Patch Management","WINDOWS UPDATE","Error Code"],"aliases":["0x80246007"]},{"id":3545,"title":"0x80240034 - The update failed to download","category":"Patch Management","product":"Windows Update","tags":["Patch Management","WINDOWS UPDATE","Error Code"],"keywords":["0x80240034","0x80240034","windows","update","the","failed","download","review","windowsupdate","log","and","cbs","for","failing","package","phase","run","troubleshooter","confirm","services","disk","space","dns","proxy","endpoint","access","repair","servicing","with","dism","sfc","reset","components","only","logs","indicate","cache","datastore","damage"],"errorCode":"0x80240034","eventId":"","severity":"High","summary":"The update failed to download.","rootCause":"Windows servicing, update metadata, component-store corruption, policy, connectivity, or a pending restart can produce this code. Confirm the exact update and servicing-log context before resetting components.","resolution":"1. Review WindowsUpdate.log and CBS.log for the failing package or phase.\n2. Run the Windows Update troubleshooter, confirm update services, disk space, DNS, proxy, and endpoint access.\n3. Repair servicing with DISM and SFC; reset update components only if logs indicate cache or datastore damage.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80240034, which is related to the update failed to download.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80240034 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS UPDATE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["Patch Management","WINDOWS UPDATE","Error Code"],"aliases":["0x80240034"]},{"id":3546,"title":"0x80248014 - Windows Update data store or service registration problem","category":"Patch Management","product":"Windows Update","tags":["Patch Management","WINDOWS UPDATE","Error Code"],"keywords":["0x80248014","0x80248014","windows","update","data","store","service","registration","problem","review","windowsupdate","log","and","cbs","for","the","failing","package","phase","run","troubleshooter","confirm","services","disk","space","dns","proxy","endpoint","access","repair","servicing","with","dism","sfc","reset","components","only","logs","indicate","cache","datastore"],"errorCode":"0x80248014","eventId":"","severity":"Low","summary":"Windows Update data store or service registration problem.","rootCause":"Windows servicing, update metadata, component-store corruption, policy, connectivity, or a pending restart can produce this code. Confirm the exact update and servicing-log context before resetting components.","resolution":"1. Review WindowsUpdate.log and CBS.log for the failing package or phase.\n2. Run the Windows Update troubleshooter, confirm update services, disk space, DNS, proxy, and endpoint access.\n3. Repair servicing with DISM and SFC; reset update components only if logs indicate cache or datastore damage.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80248014, which is related to windows update data store or service registration problem.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80248014 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS UPDATE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["Patch Management","WINDOWS UPDATE","Error Code"],"aliases":["0x80248014"]},{"id":3547,"title":"0x80242006 - The update contains invalid metadata","category":"Patch Management","product":"Windows Update","tags":["Patch Management","WINDOWS UPDATE","Error Code"],"keywords":["0x80242006","0x80242006","windows","update","the","contains","invalid","metadata","review","windowsupdate","log","and","cbs","for","failing","package","phase","run","troubleshooter","confirm","services","disk","space","dns","proxy","endpoint","access","repair","servicing","with","dism","sfc","reset","components","only","logs","indicate","cache","datastore","damage"],"errorCode":"0x80242006","eventId":"","severity":"Medium","summary":"The update contains invalid metadata.","rootCause":"Windows servicing, update metadata, component-store corruption, policy, connectivity, or a pending restart can produce this code. Confirm the exact update and servicing-log context before resetting components.","resolution":"1. Review WindowsUpdate.log and CBS.log for the failing package or phase.\n2. Run the Windows Update troubleshooter, confirm update services, disk space, DNS, proxy, and endpoint access.\n3. Repair servicing with DISM and SFC; reset update components only if logs indicate cache or datastore damage.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80242006, which is related to the update contains invalid metadata.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80242006 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS UPDATE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["Patch Management","WINDOWS UPDATE","Error Code"],"aliases":["0x80242006"]},{"id":3548,"title":"0x80070BC9 - A restart is required","category":"Patch Management","product":"Windows Update","tags":["Patch Management","WINDOWS UPDATE","Error Code"],"keywords":["0x80070BC9","0x80070bc9","windows","update","restart","required","review","windowsupdate","log","and","cbs","for","the","failing","package","phase","run","troubleshooter","confirm","services","disk","space","dns","proxy","endpoint","access","repair","servicing","with","dism","sfc","reset","components","only","logs","indicate","cache","datastore","damage"],"errorCode":"0x80070BC9","eventId":"","severity":"Low","summary":"A restart is required.","rootCause":"Windows servicing, update metadata, component-store corruption, policy, connectivity, or a pending restart can produce this code. Confirm the exact update and servicing-log context before resetting components.","resolution":"1. Review WindowsUpdate.log and CBS.log for the failing package or phase.\n2. Run the Windows Update troubleshooter, confirm update services, disk space, DNS, proxy, and endpoint access.\n3. Repair servicing with DISM and SFC; reset update components only if logs indicate cache or datastore damage.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80070BC9, which is related to a restart is required.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80070BC9 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS UPDATE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["Patch Management","WINDOWS UPDATE","Error Code"],"aliases":["0x80070BC9"]},{"id":3549,"title":"0x8024A10A - The Windows Update service is shutting down","category":"Patch Management","product":"Windows Update","tags":["Patch Management","WINDOWS UPDATE","Error Code"],"keywords":["0x8024A10A","0x8024a10a","windows","update","the","service","shutting","down","review","windowsupdate","log","and","cbs","for","failing","package","phase","run","troubleshooter","confirm","services","disk","space","dns","proxy","endpoint","access","repair","servicing","with","dism","sfc","reset","components","only","logs","indicate","cache","datastore","damage"],"errorCode":"0x8024A10A","eventId":"","severity":"Low","summary":"The Windows Update service is shutting down.","rootCause":"Windows servicing, update metadata, component-store corruption, policy, connectivity, or a pending restart can produce this code. Confirm the exact update and servicing-log context before resetting components.","resolution":"1. Review WindowsUpdate.log and CBS.log for the failing package or phase.\n2. Run the Windows Update troubleshooter, confirm update services, disk space, DNS, proxy, and endpoint access.\n3. Repair servicing with DISM and SFC; reset update components only if logs indicate cache or datastore damage.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x8024A10A, which is related to the windows update service is shutting down.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x8024A10A and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS UPDATE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["Patch Management","WINDOWS UPDATE","Error Code"],"aliases":["0x8024A10A"]},{"id":3550,"title":"0xC1900101 - Windows upgrade rolled back, commonly because of a driver issue","category":"Patch Management","product":"Windows Update","tags":["Patch Management","WINDOWS UPDATE","Error Code"],"keywords":["0xC1900101","0xc1900101","windows","update","upgrade","rolled","back","commonly","because","driver","issue","review","windowsupdate","log","and","cbs","for","the","failing","package","phase","run","troubleshooter","confirm","services","disk","space","dns","proxy","endpoint","access","repair","servicing","with","dism","sfc","reset","components","only","logs","indicate","win","setup","generic","rollback","associated","compatibility"],"errorCode":"0xC1900101","eventId":"","severity":"Low","summary":"Windows upgrade rolled back, commonly because of a driver issue.","rootCause":"Windows servicing, update metadata, component-store corruption, policy, connectivity, or a pending restart can produce this code. Confirm the exact update and servicing-log context before resetting components.","resolution":"1. Review WindowsUpdate.log and CBS.log for the failing package or phase.\n2. Run the Windows Update troubleshooter, confirm update services, disk space, DNS, proxy, and endpoint access.\n3. Repair servicing with DISM and SFC; reset update components only if logs indicate cache or datastore damage.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0xC1900101, which is related to windows upgrade rolled back, commonly because of a driver issue.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0xC1900101 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS UPDATE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.\n\nAdditional source detail (windows_error_code_expansion.txt): Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt; windows_error_code_expansion.txt","identifier":"0xC1900101","identifiers":["0xC1900101"],"identifierType":"Windows Setup Result","namespace":"WIN-SETUP","platform":"Windows","component":"Windows Setup","eventSource":"Windows Setup","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC1900101\nNamespace: WIN-SETUP\nType: Windows Setup Result\nPlatform: Windows\nProduct: Windows Setup / Feature Upgrade\nComponent: Windows Setup\nReview status: Verified\n\nMeaning: A generic Windows Setup rollback, commonly associated with driver\ncompatibility.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["Patch Management","WINDOWS UPDATE","Error Code"],"aliases":["0xC1900101"]},{"id":3551,"title":"0xC1900200 - The device does not meet upgrade requirements","category":"Patch Management","product":"Windows Update","tags":["Patch Management","WINDOWS UPDATE","Error Code"],"keywords":["0xC1900200","0xc1900200","windows","update","the","device","does","not","meet","upgrade","requirements","review","windowsupdate","log","and","cbs","for","failing","package","phase","run","troubleshooter","confirm","services","disk","space","dns","proxy","endpoint","access","repair","servicing","with","dism","sfc","reset","components","only","logs","indicate","cache","win","setup","computer","operating","system"],"errorCode":"0xC1900200","eventId":"","severity":"Low","summary":"The device does not meet upgrade requirements.","rootCause":"Windows servicing, update metadata, component-store corruption, policy, connectivity, or a pending restart can produce this code. Confirm the exact update and servicing-log context before resetting components.","resolution":"1. Review WindowsUpdate.log and CBS.log for the failing package or phase.\n2. Run the Windows Update troubleshooter, confirm update services, disk space, DNS, proxy, and endpoint access.\n3. Repair servicing with DISM and SFC; reset update components only if logs indicate cache or datastore damage.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0xC1900200, which is related to the device does not meet upgrade requirements.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0xC1900200 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS UPDATE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.\n\nAdditional source detail (windows_error_code_expansion.txt): Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt; windows_error_code_expansion.txt","identifier":"0xC1900200","identifiers":["0xC1900200"],"identifierType":"Windows Setup Result","namespace":"WIN-SETUP","platform":"Windows","component":"Windows Setup","eventSource":"Windows Setup","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC1900200\nNamespace: WIN-SETUP\nType: Windows Setup Result\nPlatform: Windows\nProduct: Windows Setup / Feature Upgrade\nComponent: Windows Setup\nReview status: Verified\n\nMeaning: The computer does not meet the operating-system requirements.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["Patch Management","WINDOWS UPDATE","Error Code"],"aliases":["0xC1900200"]},{"id":3552,"title":"0xC1900208 - An incompatible application blocks the upgrade","category":"Patch Management","product":"Windows Update","tags":["Patch Management","WINDOWS UPDATE","Error Code"],"keywords":["0xC1900208","0xc1900208","windows","update","incompatible","application","blocks","the","upgrade","review","windowsupdate","log","and","cbs","for","failing","package","phase","run","troubleshooter","confirm","services","disk","space","dns","proxy","endpoint","access","repair","servicing","with","dism","sfc","reset","components","only","logs","indicate","cache","datastore","damage","win","setup","driver"],"errorCode":"0xC1900208","eventId":"","severity":"Low","summary":"An incompatible application blocks the upgrade.","rootCause":"Windows servicing, update metadata, component-store corruption, policy, connectivity, or a pending restart can produce this code. Confirm the exact update and servicing-log context before resetting components.","resolution":"1. Review WindowsUpdate.log and CBS.log for the failing package or phase.\n2. Run the Windows Update troubleshooter, confirm update services, disk space, DNS, proxy, and endpoint access.\n3. Repair servicing with DISM and SFC; reset update components only if logs indicate cache or datastore damage.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0xC1900208, which is related to an incompatible application blocks the upgrade.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0xC1900208 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS UPDATE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.\n\nAdditional source detail (windows_error_code_expansion.txt): Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt; windows_error_code_expansion.txt","identifier":"0xC1900208","identifiers":["0xC1900208"],"identifierType":"Windows Setup Result","namespace":"WIN-SETUP","platform":"Windows","component":"Windows Setup","eventSource":"Windows Setup","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC1900208\nNamespace: WIN-SETUP\nType: Windows Setup Result\nPlatform: Windows\nProduct: Windows Setup / Feature Upgrade\nComponent: Windows Setup\nReview status: Verified\n\nMeaning: An incompatible application or driver blocks the upgrade.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["Patch Management","WINDOWS UPDATE","Error Code"],"aliases":["0xC1900208"]},{"id":3553,"title":"0xC190020E - Insufficient free disk space for the upgrade","category":"Patch Management","product":"Windows Update","tags":["Patch Management","WINDOWS UPDATE","Error Code"],"keywords":["0xC190020E","0xc190020e","windows","update","insufficient","free","disk","space","for","the","upgrade","review","windowsupdate","log","and","cbs","failing","package","phase","run","troubleshooter","confirm","services","dns","proxy","endpoint","access","repair","servicing","with","dism","sfc","reset","components","only","logs","indicate","cache","datastore","damage","win","setup","computer","does","not","have","enough"],"errorCode":"0xC190020E","eventId":"","severity":"Low","summary":"Insufficient free disk space for the upgrade.","rootCause":"Windows servicing, update metadata, component-store corruption, policy, connectivity, or a pending restart can produce this code. Confirm the exact update and servicing-log context before resetting components.","resolution":"1. Review WindowsUpdate.log and CBS.log for the failing package or phase.\n2. Run the Windows Update troubleshooter, confirm update services, disk space, DNS, proxy, and endpoint access.\n3. Repair servicing with DISM and SFC; reset update components only if logs indicate cache or datastore damage.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0xC190020E, which is related to insufficient free disk space for the upgrade.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0xC190020E and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS UPDATE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.\n\nAdditional source detail (windows_error_code_expansion.txt): Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","commands":["DISM /Online /Cleanup-Image /RestoreHealth","sfc /scannow"],"sourceDocument":"microsoft_windows_error_code_master_list.txt; windows_error_code_expansion.txt","identifier":"0xC190020E","identifiers":["0xC190020E"],"identifierType":"Windows Setup Result","namespace":"WIN-SETUP","platform":"Windows","component":"Windows Setup","eventSource":"Windows Setup","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC190020E\nNamespace: WIN-SETUP\nType: Windows Setup Result\nPlatform: Windows\nProduct: Windows Setup / Feature Upgrade\nComponent: Windows Setup\nReview status: Verified\n\nMeaning: The computer does not have enough free disk space.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["Patch Management","WINDOWS UPDATE","Error Code"],"aliases":["0xC190020E"]},{"id":3554,"title":"AADSTS50011 - Reply URL mismatch","category":"Entra ID","product":"Microsoft Entra ID","tags":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"keywords":["AADSTS50011","aadsts50011","microsoft","entra","reply","url","mismatch","open","the","failed","sign","event","and","record","error","correlation","timestamp","tenant","application","conditional","access","result","verify","user","app","assignment","consent","mfa","device","policy","state","indicated","correct","identified","identity","condition","allow","replication","test","again"],"errorCode":"AADSTS50011","eventId":"","severity":"High","summary":"Reply URL mismatch.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Open the failed Entra sign-in event and record error, correlation ID, timestamp, tenant, application, and Conditional Access result.\n2. Verify the user, tenant, app assignment, consent, MFA, device, and policy state indicated by the event.\n3. Correct the identified identity or policy condition, allow replication, and test again.","emailScript":"Hello,\n\nWe reviewed the issue and identified error AADSTS50011, which is related to reply url mismatch.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error AADSTS50011 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT ENTRA ID\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Entra ID"],"technologies":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"aliases":["AADSTS50011"]},{"id":3555,"title":"AADSTS50020 - The account does not exist in the target tenant","category":"Entra ID","product":"Microsoft Entra ID","tags":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"keywords":["AADSTS50020","aadsts50020","microsoft","entra","the","account","does","not","exist","target","tenant","open","failed","sign","event","and","record","error","correlation","timestamp","application","conditional","access","result","verify","user","app","assignment","consent","mfa","device","policy","state","indicated","correct","identified","identity","condition","allow","replication","test"],"errorCode":"AADSTS50020","eventId":"","severity":"High","summary":"The account does not exist in the target tenant.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Open the failed Entra sign-in event and record error, correlation ID, timestamp, tenant, application, and Conditional Access result.\n2. Verify the user, tenant, app assignment, consent, MFA, device, and policy state indicated by the event.\n3. Correct the identified identity or policy condition, allow replication, and test again.","emailScript":"Hello,\n\nWe reviewed the issue and identified error AADSTS50020, which is related to the account does not exist in the target tenant.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error AADSTS50020 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT ENTRA ID\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Entra ID"],"technologies":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"aliases":["AADSTS50020"]},{"id":3556,"title":"AADSTS50057 - The user account is disabled","category":"Entra ID","product":"Microsoft Entra ID","tags":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"keywords":["AADSTS50057","aadsts50057","microsoft","entra","the","user","account","disabled","open","failed","sign","event","and","record","error","correlation","timestamp","tenant","application","conditional","access","result","verify","app","assignment","consent","mfa","device","policy","state","indicated","correct","identified","identity","condition","allow","replication","test","again"],"errorCode":"AADSTS50057","eventId":"","severity":"High","summary":"The user account is disabled.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Open the failed Entra sign-in event and record error, correlation ID, timestamp, tenant, application, and Conditional Access result.\n2. Verify the user, tenant, app assignment, consent, MFA, device, and policy state indicated by the event.\n3. Correct the identified identity or policy condition, allow replication, and test again.","emailScript":"Hello,\n\nWe reviewed the issue and identified error AADSTS50057, which is related to the user account is disabled.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error AADSTS50057 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT ENTRA ID\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Entra ID"],"technologies":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"aliases":["AADSTS50057"]},{"id":3557,"title":"AADSTS50058 - Silent sign-in failed because no user session exists","category":"Entra ID","product":"Microsoft Entra ID","tags":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"keywords":["AADSTS50058","aadsts50058","microsoft","entra","silent","sign","failed","because","user","session","exists","open","the","event","and","record","error","correlation","timestamp","tenant","application","conditional","access","result","verify","app","assignment","consent","mfa","device","policy","state","indicated","correct","identified","identity","condition","allow","replication","test","again"],"errorCode":"AADSTS50058","eventId":"","severity":"High","summary":"Silent sign-in failed because no user session exists.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Open the failed Entra sign-in event and record error, correlation ID, timestamp, tenant, application, and Conditional Access result.\n2. Verify the user, tenant, app assignment, consent, MFA, device, and policy state indicated by the event.\n3. Correct the identified identity or policy condition, allow replication, and test again.","emailScript":"Hello,\n\nWe reviewed the issue and identified error AADSTS50058, which is related to silent sign-in failed because no user session exists.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error AADSTS50058 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT ENTRA ID\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Entra ID"],"technologies":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"aliases":["AADSTS50058"]},{"id":3558,"title":"AADSTS50076 - Multi-factor authentication is required","category":"Entra ID","product":"Microsoft Entra ID","tags":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"keywords":["AADSTS50076","aadsts50076","microsoft","entra","multi","factor","authentication","required","open","the","failed","sign","event","and","record","error","correlation","timestamp","tenant","application","conditional","access","result","verify","user","app","assignment","consent","mfa","device","policy","state","indicated","correct","identified","identity","condition","allow","replication","test","again"],"errorCode":"AADSTS50076","eventId":"","severity":"High","summary":"Multi-factor authentication is required.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Open the failed Entra sign-in event and record error, correlation ID, timestamp, tenant, application, and Conditional Access result.\n2. Verify the user, tenant, app assignment, consent, MFA, device, and policy state indicated by the event.\n3. Correct the identified identity or policy condition, allow replication, and test again.","emailScript":"Hello,\n\nWe reviewed the issue and identified error AADSTS50076, which is related to multi-factor authentication is required.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error AADSTS50076 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT ENTRA ID\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Entra ID"],"technologies":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"aliases":["AADSTS50076"]},{"id":3559,"title":"AADSTS50079 - The user must register for multi-factor authentication","category":"Entra ID","product":"Microsoft Entra ID","tags":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"keywords":["AADSTS50079","aadsts50079","microsoft","entra","the","user","must","register","for","multi","factor","authentication","open","failed","sign","event","and","record","error","correlation","timestamp","tenant","application","conditional","access","result","verify","app","assignment","consent","mfa","device","policy","state","indicated","correct","identified","identity","condition","allow","replication"],"errorCode":"AADSTS50079","eventId":"","severity":"High","summary":"The user must register for multi-factor authentication.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Open the failed Entra sign-in event and record error, correlation ID, timestamp, tenant, application, and Conditional Access result.\n2. Verify the user, tenant, app assignment, consent, MFA, device, and policy state indicated by the event.\n3. Correct the identified identity or policy condition, allow replication, and test again.","emailScript":"Hello,\n\nWe reviewed the issue and identified error AADSTS50079, which is related to the user must register for multi-factor authentication.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error AADSTS50079 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT ENTRA ID\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Entra ID"],"technologies":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"aliases":["AADSTS50079"]},{"id":3560,"title":"AADSTS50105 - The user is not assigned to the application","category":"Entra ID","product":"Microsoft Entra ID","tags":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"keywords":["AADSTS50105","aadsts50105","microsoft","entra","the","user","not","assigned","application","open","failed","sign","event","and","record","error","correlation","timestamp","tenant","conditional","access","result","verify","app","assignment","consent","mfa","device","policy","state","indicated","correct","identified","identity","condition","allow","replication","test","again"],"errorCode":"AADSTS50105","eventId":"","severity":"High","summary":"The user is not assigned to the application.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Open the failed Entra sign-in event and record error, correlation ID, timestamp, tenant, application, and Conditional Access result.\n2. Verify the user, tenant, app assignment, consent, MFA, device, and policy state indicated by the event.\n3. Correct the identified identity or policy condition, allow replication, and test again.","emailScript":"Hello,\n\nWe reviewed the issue and identified error AADSTS50105, which is related to the user is not assigned to the application.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error AADSTS50105 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT ENTRA ID\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Entra ID"],"technologies":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"aliases":["AADSTS50105"]},{"id":3561,"title":"AADSTS53003 - Access is blocked by Conditional Access","category":"Entra ID","product":"Microsoft Entra ID","tags":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"keywords":["AADSTS53003","aadsts53003","microsoft","entra","access","blocked","conditional","open","the","failed","sign","event","and","record","error","correlation","timestamp","tenant","application","result","verify","user","app","assignment","consent","mfa","device","policy","state","indicated","correct","identified","identity","condition","allow","replication","test","again"],"errorCode":"AADSTS53003","eventId":"","severity":"High","summary":"Access is blocked by Conditional Access.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Open the failed Entra sign-in event and record error, correlation ID, timestamp, tenant, application, and Conditional Access result.\n2. Verify the user, tenant, app assignment, consent, MFA, device, and policy state indicated by the event.\n3. Correct the identified identity or policy condition, allow replication, and test again.","emailScript":"Hello,\n\nWe reviewed the issue and identified error AADSTS53003, which is related to access is blocked by conditional access.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error AADSTS53003 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT ENTRA ID\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Entra ID"],"technologies":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"aliases":["AADSTS53003"]},{"id":3562,"title":"AADSTS65001 - User or administrator consent is required","category":"Entra ID","product":"Microsoft Entra ID","tags":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"keywords":["AADSTS65001","aadsts65001","microsoft","entra","user","administrator","consent","required","open","the","failed","sign","event","and","record","error","correlation","timestamp","tenant","application","conditional","access","result","verify","app","assignment","mfa","device","policy","state","indicated","correct","identified","identity","condition","allow","replication","test","again"],"errorCode":"AADSTS65001","eventId":"","severity":"High","summary":"User or administrator consent is required.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Open the failed Entra sign-in event and record error, correlation ID, timestamp, tenant, application, and Conditional Access result.\n2. Verify the user, tenant, app assignment, consent, MFA, device, and policy state indicated by the event.\n3. Correct the identified identity or policy condition, allow replication, and test again.","emailScript":"Hello,\n\nWe reviewed the issue and identified error AADSTS65001, which is related to user or administrator consent is required.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error AADSTS65001 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT ENTRA ID\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Entra ID"],"technologies":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"aliases":["AADSTS65001"]},{"id":3563,"title":"AADSTS65004 - The user declined consent","category":"Entra ID","product":"Microsoft Entra ID","tags":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"keywords":["AADSTS65004","aadsts65004","microsoft","entra","the","user","declined","consent","open","failed","sign","event","and","record","error","correlation","timestamp","tenant","application","conditional","access","result","verify","app","assignment","mfa","device","policy","state","indicated","correct","identified","identity","condition","allow","replication","test","again"],"errorCode":"AADSTS65004","eventId":"","severity":"High","summary":"The user declined consent.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Open the failed Entra sign-in event and record error, correlation ID, timestamp, tenant, application, and Conditional Access result.\n2. Verify the user, tenant, app assignment, consent, MFA, device, and policy state indicated by the event.\n3. Correct the identified identity or policy condition, allow replication, and test again.","emailScript":"Hello,\n\nWe reviewed the issue and identified error AADSTS65004, which is related to the user declined consent.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error AADSTS65004 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT ENTRA ID\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Entra ID"],"technologies":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"aliases":["AADSTS65004"]},{"id":3564,"title":"AADSTS700016 - The application was not found in the directory","category":"Entra ID","product":"Microsoft Entra ID","tags":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"keywords":["AADSTS700016","aadsts700016","microsoft","entra","the","application","was","not","found","directory","open","failed","sign","event","and","record","error","correlation","timestamp","tenant","conditional","access","result","verify","user","app","assignment","consent","mfa","device","policy","state","indicated","correct","identified","identity","condition","allow","replication","test","again"],"errorCode":"AADSTS700016","eventId":"","severity":"High","summary":"The application was not found in the directory.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Open the failed Entra sign-in event and record error, correlation ID, timestamp, tenant, application, and Conditional Access result.\n2. Verify the user, tenant, app assignment, consent, MFA, device, and policy state indicated by the event.\n3. Correct the identified identity or policy condition, allow replication, and test again.","emailScript":"Hello,\n\nWe reviewed the issue and identified error AADSTS700016, which is related to the application was not found in the directory.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error AADSTS700016 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT ENTRA ID\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Entra ID"],"technologies":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"aliases":["AADSTS700016"]},{"id":3565,"title":"AADSTS700082 - The refresh token expired because of inactivity","category":"Entra ID","product":"Microsoft Entra ID","tags":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"keywords":["AADSTS700082","aadsts700082","microsoft","entra","the","refresh","token","expired","because","inactivity","open","failed","sign","event","and","record","error","correlation","timestamp","tenant","application","conditional","access","result","verify","user","app","assignment","consent","mfa","device","policy","state","indicated","correct","identified","identity","condition","allow","replication","test"],"errorCode":"AADSTS700082","eventId":"","severity":"High","summary":"The refresh token expired because of inactivity.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Open the failed Entra sign-in event and record error, correlation ID, timestamp, tenant, application, and Conditional Access result.\n2. Verify the user, tenant, app assignment, consent, MFA, device, and policy state indicated by the event.\n3. Correct the identified identity or policy condition, allow replication, and test again.","emailScript":"Hello,\n\nWe reviewed the issue and identified error AADSTS700082, which is related to the refresh token expired because of inactivity.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error AADSTS700082 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT ENTRA ID\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Entra ID"],"technologies":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"aliases":["AADSTS700082"]},{"id":3566,"title":"AADSTS90002 - Tenant not found","category":"Entra ID","product":"Microsoft Entra ID","tags":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"keywords":["AADSTS90002","aadsts90002","microsoft","entra","tenant","not","found","open","the","failed","sign","event","and","record","error","correlation","timestamp","application","conditional","access","result","verify","user","app","assignment","consent","mfa","device","policy","state","indicated","correct","identified","identity","condition","allow","replication","test","again"],"errorCode":"AADSTS90002","eventId":"","severity":"High","summary":"Tenant not found.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Open the failed Entra sign-in event and record error, correlation ID, timestamp, tenant, application, and Conditional Access result.\n2. Verify the user, tenant, app assignment, consent, MFA, device, and policy state indicated by the event.\n3. Correct the identified identity or policy condition, allow replication, and test again.","emailScript":"Hello,\n\nWe reviewed the issue and identified error AADSTS90002, which is related to tenant not found.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error AADSTS90002 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT ENTRA ID\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Entra ID"],"technologies":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"aliases":["AADSTS90002"]},{"id":3567,"title":"AADSTS900561 - The authentication endpoint received an unsupported request method","category":"Entra ID","product":"Microsoft Entra ID","tags":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"keywords":["AADSTS900561","aadsts900561","microsoft","entra","the","authentication","endpoint","received","unsupported","request","method","open","failed","sign","event","and","record","error","correlation","timestamp","tenant","application","conditional","access","result","verify","user","app","assignment","consent","mfa","device","policy","state","indicated","correct","identified","identity","condition","allow","replication"],"errorCode":"AADSTS900561","eventId":"","severity":"High","summary":"The authentication endpoint received an unsupported request method.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Open the failed Entra sign-in event and record error, correlation ID, timestamp, tenant, application, and Conditional Access result.\n2. Verify the user, tenant, app assignment, consent, MFA, device, and policy state indicated by the event.\n3. Correct the identified identity or policy condition, allow replication, and test again.","emailScript":"Hello,\n\nWe reviewed the issue and identified error AADSTS900561, which is related to the authentication endpoint received an unsupported request method.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error AADSTS900561 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT ENTRA ID\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Entra ID"],"technologies":["Entra ID","MICROSOFT ENTRA ID","Error Code"],"aliases":["AADSTS900561"]},{"id":3568,"title":"0x80180014 - MDM enrollment is not permitted for this user or device","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft 365","INTUNE AND MDM","Error Code","Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0x80180014","intune","and","mdm","enrollment","not","permitted","for","this","user","device","review","app","reports","plus","devicemanagement","enterprise","diagnostics","provider","intunemanagementextension","logs","verify","licensing","scope","restrictions","targeting","requirements","install","command","return","codes","detection","logic","correct","the","specific","policy","condition","sync","retest","80180014","Windows MDM Enrollment Not Allowed","Windows version, platform restriction, user permission, ownership, device limit, or policy does not permit enrollment.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0x80180014","eventId":"","severity":"Low","summary":"MDM enrollment is not permitted for this user or device.","rootCause":"Windows version, platform restriction, user permission, ownership, device limit, or policy does not permit enrollment.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Verify supported edition/build, enrollment restrictions, device limit, MDM scope, and user authorization; correct the specific policy.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x80180014 - Windows MDM Enrollment Not Allowed.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","lastUpdated":"2026-08-10","vendors":["Microsoft Intune"],"technologies":["Microsoft 365","INTUNE AND MDM","Error Code","Microsoft Intune","MDM","Windows Enrollment"],"aliases":["0x80180014"]},{"id":3569,"title":"0x80180018 - MDM enrollment failed","category":"Microsoft 365","product":"Microsoft Intune","tags":["Microsoft 365","INTUNE AND MDM","Error Code"],"keywords":["0x80180018","0x80180018","intune","and","mdm","enrollment","failed","review","device","app","reports","plus","devicemanagement","enterprise","diagnostics","provider","intunemanagementextension","logs","verify","licensing","scope","restrictions","targeting","requirements","install","command","return","codes","detection","logic","correct","the","specific","policy","condition","sync","retest"],"errorCode":"0x80180018","eventId":"","severity":"High","summary":"MDM enrollment failed.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Review Intune device/app reports plus DeviceManagement-Enterprise-Diagnostics-Provider and IntuneManagementExtension logs.\n2. Verify licensing, MDM scope, enrollment restrictions, targeting, requirements, install command, return codes, and detection logic.\n3. Correct the specific enrollment, policy, or app condition, sync the device, and retest.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80180018, which is related to mdm enrollment failed.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80180018 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: INTUNE AND MDM\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Intune"],"technologies":["Microsoft 365","INTUNE AND MDM","Error Code"],"aliases":["0x80180018"]},{"id":3570,"title":"0x80180026 - Enrollment is blocked by another MDM or management policy","category":"Microsoft 365","product":"Microsoft Intune","tags":["Microsoft 365","INTUNE AND MDM","Error Code"],"keywords":["0x80180026","0x80180026","intune","and","mdm","enrollment","blocked","another","management","policy","review","device","app","reports","plus","devicemanagement","enterprise","diagnostics","provider","intunemanagementextension","logs","verify","licensing","scope","restrictions","targeting","requirements","install","command","return","codes","detection","logic","correct","the","specific","condition","sync","retest"],"errorCode":"0x80180026","eventId":"","severity":"High","summary":"Enrollment is blocked by another MDM or management policy.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Review Intune device/app reports plus DeviceManagement-Enterprise-Diagnostics-Provider and IntuneManagementExtension logs.\n2. Verify licensing, MDM scope, enrollment restrictions, targeting, requirements, install command, return codes, and detection logic.\n3. Correct the specific enrollment, policy, or app condition, sync the device, and retest.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80180026, which is related to enrollment is blocked by another mdm or management policy.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80180026 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: INTUNE AND MDM\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Intune"],"technologies":["Microsoft 365","INTUNE AND MDM","Error Code"],"aliases":["0x80180026"]},{"id":3571,"title":"0x87D1041C - The application was not detected after installation","category":"Microsoft 365","product":"Microsoft Intune","tags":["Microsoft 365","INTUNE AND MDM","Error Code"],"keywords":["0x87D1041C","0x87d1041c","intune","and","mdm","the","application","was","not","detected","after","installation","review","device","app","reports","plus","devicemanagement","enterprise","diagnostics","provider","intunemanagementextension","logs","verify","licensing","scope","enrollment","restrictions","targeting","requirements","install","command","return","codes","detection","logic","correct","specific","policy","condition","sync"],"errorCode":"0x87D1041C","eventId":"","severity":"Low","summary":"The application was not detected after installation.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Review Intune device/app reports plus DeviceManagement-Enterprise-Diagnostics-Provider and IntuneManagementExtension logs.\n2. Verify licensing, MDM scope, enrollment restrictions, targeting, requirements, install command, return codes, and detection logic.\n3. Correct the specific enrollment, policy, or app condition, sync the device, and retest.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x87D1041C, which is related to the application was not detected after installation.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x87D1041C and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: INTUNE AND MDM\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Intune"],"technologies":["Microsoft 365","INTUNE AND MDM","Error Code"],"aliases":["0x87D1041C"]},{"id":3572,"title":"0x87D30065 - The Win32 application installation failed","category":"Microsoft 365","product":"Microsoft Intune","tags":["Microsoft 365","INTUNE AND MDM","Error Code"],"keywords":["0x87D30065","0x87d30065","intune","and","mdm","the","win32","application","installation","failed","review","device","app","reports","plus","devicemanagement","enterprise","diagnostics","provider","intunemanagementextension","logs","verify","licensing","scope","enrollment","restrictions","targeting","requirements","install","command","return","codes","detection","logic","correct","specific","policy","condition","sync","retest"],"errorCode":"0x87D30065","eventId":"","severity":"High","summary":"The Win32 application installation failed.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Review Intune device/app reports plus DeviceManagement-Enterprise-Diagnostics-Provider and IntuneManagementExtension logs.\n2. Verify licensing, MDM scope, enrollment restrictions, targeting, requirements, install command, return codes, and detection logic.\n3. Correct the specific enrollment, policy, or app condition, sync the device, and retest.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x87D30065, which is related to the win32 application installation failed.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x87D30065 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: INTUNE AND MDM\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Intune"],"technologies":["Microsoft 365","INTUNE AND MDM","Error Code"],"aliases":["0x87D30065"]},{"id":3573,"title":"0x87D1FDE8 - The MDM policy could not be remediated","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft 365","INTUNE AND MDM","Error Code","Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0x87D1FDE8","0x87d1fde8","intune","and","mdm","the","policy","could","not","remediated","review","device","app","reports","plus","devicemanagement","enterprise","diagnostics","provider","intunemanagementextension","logs","verify","licensing","scope","enrollment","restrictions","targeting","requirements","install","command","return","codes","detection","logic","correct","specific","condition","sync","retest","87D1FDE8","Policy Remediation Failed","Intune detected noncompliance but could not apply the correction.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0x87D1FDE8","eventId":"","severity":"Low","summary":"The MDM policy could not be remediated.","rootCause":"Intune detected noncompliance but could not apply the correction.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Find the failing CSP and event; check prerequisites, conflicts, permissions and value support, then verify a successful sync.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x87D1FDE8 - Policy Remediation Failed.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","lastUpdated":"2026-08-10","vendors":["Microsoft Intune"],"technologies":["Microsoft 365","INTUNE AND MDM","Error Code","Microsoft Intune","MDM","Windows Enrollment"],"aliases":["0x87D1FDE8"]},{"id":3574,"title":"0x87D101F4 - The application requirement was not met","category":"Microsoft 365","product":"Microsoft Intune","tags":["Microsoft 365","INTUNE AND MDM","Error Code"],"keywords":["0x87D101F4","0x87d101f4","intune","and","mdm","the","application","requirement","was","not","met","review","device","app","reports","plus","devicemanagement","enterprise","diagnostics","provider","intunemanagementextension","logs","verify","licensing","scope","enrollment","restrictions","targeting","requirements","install","command","return","codes","detection","logic","correct","specific","policy","condition","sync","retest"],"errorCode":"0x87D101F4","eventId":"","severity":"Low","summary":"The application requirement was not met.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Review Intune device/app reports plus DeviceManagement-Enterprise-Diagnostics-Provider and IntuneManagementExtension logs.\n2. Verify licensing, MDM scope, enrollment restrictions, targeting, requirements, install command, return codes, and detection logic.\n3. Correct the specific enrollment, policy, or app condition, sync the device, and retest.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x87D101F4, which is related to the application requirement was not met.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x87D101F4 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: INTUNE AND MDM\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Intune"],"technologies":["Microsoft 365","INTUNE AND MDM","Error Code"],"aliases":["0x87D101F4"]},{"id":3575,"title":"700003 - The device object was deleted or is no longer recognized","category":"Microsoft 365","product":"Microsoft Intune","tags":["Microsoft 365","INTUNE AND MDM","Error Code"],"keywords":["700003","700003","intune","and","mdm","the","device","object","was","deleted","longer","recognized","review","app","reports","plus","devicemanagement","enterprise","diagnostics","provider","intunemanagementextension","logs","verify","licensing","scope","enrollment","restrictions","targeting","requirements","install","command","return","codes","detection","logic","correct","specific","policy","condition","sync","retest"],"errorCode":"700003","eventId":"","severity":"Low","summary":"The device object was deleted or is no longer recognized.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Review Intune device/app reports plus DeviceManagement-Enterprise-Diagnostics-Provider and IntuneManagementExtension logs.\n2. Verify licensing, MDM scope, enrollment restrictions, targeting, requirements, install command, return codes, and detection logic.\n3. Correct the specific enrollment, policy, or app condition, sync the device, and retest.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 700003, which is related to the device object was deleted or is no longer recognized.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 700003 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: INTUNE AND MDM\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Intune"],"technologies":["Microsoft 365","INTUNE AND MDM","Error Code"],"aliases":["700003"]},{"id":3576,"title":"80190190 - The MDM service returned HTTP 400 Bad Request","category":"Microsoft 365","product":"Microsoft Intune","tags":["Microsoft 365","INTUNE AND MDM","Error Code"],"keywords":["80190190","80190190","intune","and","mdm","the","service","returned","http","400","bad","request","review","device","app","reports","plus","devicemanagement","enterprise","diagnostics","provider","intunemanagementextension","logs","verify","licensing","scope","enrollment","restrictions","targeting","requirements","install","command","return","codes","detection","logic","correct","specific","policy","condition","sync"],"errorCode":"80190190","eventId":"","severity":"Low","summary":"The MDM service returned HTTP 400 Bad Request.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Review Intune device/app reports plus DeviceManagement-Enterprise-Diagnostics-Provider and IntuneManagementExtension logs.\n2. Verify licensing, MDM scope, enrollment restrictions, targeting, requirements, install command, return codes, and detection logic.\n3. Correct the specific enrollment, policy, or app condition, sync the device, and retest.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 80190190, which is related to the mdm service returned http 400 bad request.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 80190190 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: INTUNE AND MDM\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Intune"],"technologies":["Microsoft 365","INTUNE AND MDM","Error Code"],"aliases":["80190190"]},{"id":3577,"title":"0x801C03EA - Device registration did not complete","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Windows","WINDOWS AUTOPILOT","Error Code","Microsoft Intune","MDM","Windows Enrollment","TPM","Autopilot"],"keywords":["0x801C03EA","0x801c03ea","windows","autopilot","device","registration","did","not","complete","review","deployment","esp","entra","sign","and","mdm","diagnostic","records","verify","dns","time","tpm","identity","enrollment","restrictions","access","required","intune","store","update","endpoints","correct","the","failed","app","policy","network","dependency","perform","clean","reset","801C03EA","TPM Attestation or Device Registration Failure","TPM attestation, firmware, device identity, or registration validation failed.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd","TPM"],"errorCode":"0x801C03EA","eventId":"","severity":"High","summary":"Device registration did not complete.","rootCause":"TPM attestation, firmware, device identity, or registration validation failed.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Check TPM readiness, firmware, updates, time, attestation endpoints and Autopilot identity. Never clear TPM without recovery-key and impact review.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x801C03EA - TPM Attestation or Device Registration Failure.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","lastUpdated":"2026-08-10","vendors":["Microsoft Intune"],"technologies":["Windows","WINDOWS AUTOPILOT","Error Code","Microsoft Intune","MDM","Windows Enrollment","TPM","Autopilot"],"aliases":["0x801C03EA"]},{"id":3578,"title":"0x81036502 - Enrollment Status Page did not complete successfully","category":"Windows","product":"Windows Autopilot","tags":["Windows","WINDOWS AUTOPILOT","Error Code"],"keywords":["0x81036502","0x81036502","windows","autopilot","enrollment","status","page","did","not","complete","successfully","review","deployment","esp","entra","sign","device","and","mdm","diagnostic","records","verify","dns","time","tpm","identity","restrictions","access","required","intune","store","update","endpoints","correct","the","failed","app","policy","network","dependency","perform"],"errorCode":"0x81036502","eventId":"","severity":"High","summary":"Enrollment Status Page did not complete successfully.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Review Autopilot deployment, ESP, Entra sign-in/device, and MDM diagnostic records.\n2. Verify DNS, time, TPM, device identity, enrollment restrictions, and access to required Autopilot, Entra, Intune, Store, and update endpoints.\n3. Correct the failed app, policy, identity, or network dependency and perform a clean reset before retesting when required.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x81036502, which is related to enrollment status page did not complete successfully.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x81036502 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS AUTOPILOT\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Windows Autopilot"],"technologies":["Windows","WINDOWS AUTOPILOT","Error Code"],"aliases":["0x81036502"]},{"id":3579,"title":"0x80072EE2 - A required service request timed out","category":"Windows","product":"Windows Autopilot","tags":["Windows","WINDOWS AUTOPILOT","Error Code"],"keywords":["0x80072EE2","0x80072ee2","windows","autopilot","required","service","request","timed","out","review","deployment","esp","entra","sign","device","and","mdm","diagnostic","records","verify","dns","time","tpm","identity","enrollment","restrictions","access","intune","store","update","endpoints","correct","the","failed","app","policy","network","dependency","perform","clean","reset"],"errorCode":"0x80072EE2","eventId":"","severity":"High","summary":"A required service request timed out.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Review Autopilot deployment, ESP, Entra sign-in/device, and MDM diagnostic records.\n2. Verify DNS, time, TPM, device identity, enrollment restrictions, and access to required Autopilot, Entra, Intune, Store, and update endpoints.\n3. Correct the failed app, policy, identity, or network dependency and perform a clean reset before retesting when required.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80072EE2, which is related to a required service request timed out.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80072EE2 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS AUTOPILOT\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Windows Autopilot"],"technologies":["Windows","WINDOWS AUTOPILOT","Error Code"],"aliases":["0x80072EE2"]},{"id":3580,"title":"30015-11 - Microsoft 365 Apps installation failed","category":"Microsoft 365","product":"Microsoft 365 Apps","tags":["Microsoft 365","MICROSOFT 365 APPS","Error Code"],"keywords":["30015-11","30015","microsoft","365","apps","installation","failed","review","click","run","activation","wam","sign","logs","for","the","exact","failure","verify","licensing","edition","account","time","network","proxy","office","cdn","access","and","conflicting","installations","repair","remove","damaged","components","with","support","tools","then","reinstall","reactivate"],"errorCode":"30015-11","eventId":"","severity":"High","summary":"Microsoft 365 Apps installation failed.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Review Click-to-Run, activation, or WAM sign-in logs for the exact failure.\n2. Verify licensing, edition, account, time, network, proxy, Office CDN access, and conflicting Office installations.\n3. Repair or remove damaged Office components with Microsoft support tools, then reinstall or reactivate from the approved source.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 30015-11, which is related to microsoft 365 apps installation failed.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 30015-11 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT 365 APPS\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft 365 Apps"],"technologies":["Microsoft 365","MICROSOFT 365 APPS","Error Code"],"aliases":["30015-11"]},{"id":3581,"title":"30182-1 - Microsoft 365 Apps installation or update failed","category":"Microsoft 365","product":"Microsoft 365 Apps","tags":["Microsoft 365","MICROSOFT 365 APPS","Error Code"],"keywords":["30182-1","30182","microsoft","365","apps","installation","update","failed","review","click","run","activation","wam","sign","logs","for","the","exact","failure","verify","licensing","edition","account","time","network","proxy","office","cdn","access","and","conflicting","installations","repair","remove","damaged","components","with","support","tools","then","reinstall"],"errorCode":"30182-1","eventId":"","severity":"High","summary":"Microsoft 365 Apps installation or update failed.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Review Click-to-Run, activation, or WAM sign-in logs for the exact failure.\n2. Verify licensing, edition, account, time, network, proxy, Office CDN access, and conflicting Office installations.\n3. Repair or remove damaged Office components with Microsoft support tools, then reinstall or reactivate from the approved source.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 30182-1, which is related to microsoft 365 apps installation or update failed.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 30182-1 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT 365 APPS\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft 365 Apps"],"technologies":["Microsoft 365","MICROSOFT 365 APPS","Error Code"],"aliases":["30182-1"]},{"id":3582,"title":"0xC004F074 - The licensing service could not contact a KMS host","category":"Microsoft 365","product":"Microsoft 365 Apps","tags":["Microsoft 365","MICROSOFT 365 APPS","Error Code"],"keywords":["0xC004F074","0xc004f074","microsoft","365","apps","the","licensing","service","could","not","contact","kms","host","review","click","run","activation","wam","sign","logs","for","exact","failure","verify","edition","account","time","network","proxy","office","cdn","access","and","conflicting","installations","repair","remove","damaged","components","with","support"],"errorCode":"0xC004F074","eventId":"","severity":"High","summary":"The licensing service could not contact a KMS host.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Review Click-to-Run, activation, or WAM sign-in logs for the exact failure.\n2. Verify licensing, edition, account, time, network, proxy, Office CDN access, and conflicting Office installations.\n3. Repair or remove damaged Office components with Microsoft support tools, then reinstall or reactivate from the approved source.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0xC004F074, which is related to the licensing service could not contact a kms host.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0xC004F074 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT 365 APPS\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft 365 Apps"],"technologies":["Microsoft 365","MICROSOFT 365 APPS","Error Code"],"aliases":["0xC004F074"]},{"id":3583,"title":"0xC004C003 - The activation server rejected the product key","category":"Microsoft 365","product":"Microsoft 365 Apps","tags":["Microsoft 365","MICROSOFT 365 APPS","Error Code"],"keywords":["0xC004C003","0xc004c003","microsoft","365","apps","the","activation","server","rejected","product","key","review","click","run","wam","sign","logs","for","exact","failure","verify","licensing","edition","account","time","network","proxy","office","cdn","access","and","conflicting","installations","repair","remove","damaged","components","with","support","tools","then"],"errorCode":"0xC004C003","eventId":"","severity":"High","summary":"The activation server rejected the product key.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Review Click-to-Run, activation, or WAM sign-in logs for the exact failure.\n2. Verify licensing, edition, account, time, network, proxy, Office CDN access, and conflicting Office installations.\n3. Repair or remove damaged Office components with Microsoft support tools, then reinstall or reactivate from the approved source.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0xC004C003, which is related to the activation server rejected the product key.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0xC004C003 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT 365 APPS\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft 365 Apps"],"technologies":["Microsoft 365","MICROSOFT 365 APPS","Error Code"],"aliases":["0xC004C003"]},{"id":3584,"title":"0xC004F050 - The product key is invalid for the installed edition","category":"Microsoft 365","product":"Microsoft 365 Apps","tags":["Microsoft 365","MICROSOFT 365 APPS","Error Code"],"keywords":["0xC004F050","0xc004f050","microsoft","365","apps","the","product","key","invalid","for","installed","edition","review","click","run","activation","wam","sign","logs","exact","failure","verify","licensing","account","time","network","proxy","office","cdn","access","and","conflicting","installations","repair","remove","damaged","components","with","support","tools","then"],"errorCode":"0xC004F050","eventId":"","severity":"High","summary":"The product key is invalid for the installed edition.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Review Click-to-Run, activation, or WAM sign-in logs for the exact failure.\n2. Verify licensing, edition, account, time, network, proxy, Office CDN access, and conflicting Office installations.\n3. Repair or remove damaged Office components with Microsoft support tools, then reinstall or reactivate from the approved source.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0xC004F050, which is related to the product key is invalid for the installed edition.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0xC004F050 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT 365 APPS\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft 365 Apps"],"technologies":["Microsoft 365","MICROSOFT 365 APPS","Error Code"],"aliases":["0xC004F050"]},{"id":3585,"title":"0x8004010F - Outlook cannot access its data file or address book service","category":"Outlook","product":"Microsoft Outlook","tags":["Outlook","OUTLOOK","Error Code"],"keywords":["0x8004010F","0x8004010f","outlook","cannot","access","its","data","file","address","book","service","test","the","web","separate","mailbox","issues","from","local","client","verify","health","network","dns","autodiscover","credentials","quota","profile","and","state","create","new","repair","affected","pst","only","after","server","side","confirmed","healthy"],"errorCode":"0x8004010F","eventId":"","severity":"High","summary":"Outlook cannot access its data file or address book service.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Test Outlook on the web to separate mailbox issues from local client issues.\n2. Verify service health, network, DNS, Autodiscover, credentials, quota, profile, and data-file state.\n3. Create a new Outlook profile or repair the affected PST only after server-side data is confirmed healthy.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x8004010F, which is related to outlook cannot access its data file or address book service.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x8004010F and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: OUTLOOK\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Outlook"],"technologies":["Outlook","OUTLOOK","Error Code"],"aliases":["0x8004010F"]},{"id":3586,"title":"0x80040115 - Outlook cannot connect to the server","category":"Outlook","product":"Microsoft Outlook","tags":["Outlook","OUTLOOK","Error Code"],"keywords":["0x80040115","0x80040115","outlook","cannot","connect","the","server","test","web","separate","mailbox","issues","from","local","client","verify","service","health","network","dns","autodiscover","credentials","quota","profile","and","data","file","state","create","new","repair","affected","pst","only","after","side","confirmed","healthy"],"errorCode":"0x80040115","eventId":"","severity":"High","summary":"Outlook cannot connect to the server.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Test Outlook on the web to separate mailbox issues from local client issues.\n2. Verify service health, network, DNS, Autodiscover, credentials, quota, profile, and data-file state.\n3. Create a new Outlook profile or repair the affected PST only after server-side data is confirmed healthy.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80040115, which is related to outlook cannot connect to the server.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80040115 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: OUTLOOK\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Outlook"],"technologies":["Outlook","OUTLOOK","Error Code"],"aliases":["0x80040115"]},{"id":3587,"title":"0x80040600 - The Outlook data file contains errors","category":"Outlook","product":"Microsoft Outlook","tags":["Outlook","OUTLOOK","Error Code"],"keywords":["0x80040600","0x80040600","outlook","the","data","file","contains","errors","test","web","separate","mailbox","issues","from","local","client","verify","service","health","network","dns","autodiscover","credentials","quota","profile","and","state","create","new","repair","affected","pst","only","after","server","side","confirmed","healthy"],"errorCode":"0x80040600","eventId":"","severity":"High","summary":"The Outlook data file contains errors.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Test Outlook on the web to separate mailbox issues from local client issues.\n2. Verify service health, network, DNS, Autodiscover, credentials, quota, profile, and data-file state.\n3. Create a new Outlook profile or repair the affected PST only after server-side data is confirmed healthy.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80040600, which is related to the outlook data file contains errors.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80040600 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: OUTLOOK\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Outlook"],"technologies":["Outlook","OUTLOOK","Error Code"],"aliases":["0x80040600"]},{"id":3588,"title":"0x8004060C - The message store has reached a size or quota limit","category":"Outlook","product":"Microsoft Outlook","tags":["Outlook","OUTLOOK","Error Code"],"keywords":["0x8004060C","0x8004060c","outlook","the","message","store","has","reached","size","quota","limit","test","web","separate","mailbox","issues","from","local","client","verify","service","health","network","dns","autodiscover","credentials","profile","and","data","file","state","create","new","repair","affected","pst","only","after","server","side","confirmed"],"errorCode":"0x8004060C","eventId":"","severity":"High","summary":"The message store has reached a size or quota limit.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Test Outlook on the web to separate mailbox issues from local client issues.\n2. Verify service health, network, DNS, Autodiscover, credentials, quota, profile, and data-file state.\n3. Create a new Outlook profile or repair the affected PST only after server-side data is confirmed healthy.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x8004060C, which is related to the message store has reached a size or quota limit.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x8004060C and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: OUTLOOK\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Outlook"],"technologies":["Outlook","OUTLOOK","Error Code"],"aliases":["0x8004060C"]},{"id":3589,"title":"0x8004210A - The operation timed out waiting for the receiving server","category":"Outlook","product":"Microsoft Outlook","tags":["Outlook","OUTLOOK","Error Code"],"keywords":["0x8004210A","0x8004210a","outlook","the","operation","timed","out","waiting","for","receiving","server","test","web","separate","mailbox","issues","from","local","client","verify","service","health","network","dns","autodiscover","credentials","quota","profile","and","data","file","state","create","new","repair","affected","pst","only","after","side","confirmed"],"errorCode":"0x8004210A","eventId":"","severity":"High","summary":"The operation timed out waiting for the receiving server.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Test Outlook on the web to separate mailbox issues from local client issues.\n2. Verify service health, network, DNS, Autodiscover, credentials, quota, profile, and data-file state.\n3. Create a new Outlook profile or repair the affected PST only after server-side data is confirmed healthy.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x8004210A, which is related to the operation timed out waiting for the receiving server.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x8004210A and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: OUTLOOK\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Outlook"],"technologies":["Outlook","OUTLOOK","Error Code"],"aliases":["0x8004210A"]},{"id":3590,"title":"0x8004210B - The operation timed out waiting for the sending server","category":"Outlook","product":"Microsoft Outlook","tags":["Outlook","OUTLOOK","Error Code"],"keywords":["0x8004210B","0x8004210b","outlook","the","operation","timed","out","waiting","for","sending","server","test","web","separate","mailbox","issues","from","local","client","verify","service","health","network","dns","autodiscover","credentials","quota","profile","and","data","file","state","create","new","repair","affected","pst","only","after","side","confirmed"],"errorCode":"0x8004210B","eventId":"","severity":"High","summary":"The operation timed out waiting for the sending server.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Test Outlook on the web to separate mailbox issues from local client issues.\n2. Verify service health, network, DNS, Autodiscover, credentials, quota, profile, and data-file state.\n3. Create a new Outlook profile or repair the affected PST only after server-side data is confirmed healthy.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x8004210B, which is related to the operation timed out waiting for the sending server.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x8004210B and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: OUTLOOK\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Outlook"],"technologies":["Outlook","OUTLOOK","Error Code"],"aliases":["0x8004210B"]},{"id":3591,"title":"0x800CCC0E - Outlook cannot connect to the mail server","category":"Outlook","product":"Microsoft Outlook","tags":["Outlook","OUTLOOK","Error Code"],"keywords":["0x800CCC0E","0x800ccc0e","outlook","cannot","connect","the","mail","server","test","web","separate","mailbox","issues","from","local","client","verify","service","health","network","dns","autodiscover","credentials","quota","profile","and","data","file","state","create","new","repair","affected","pst","only","after","side","confirmed","healthy"],"errorCode":"0x800CCC0E","eventId":"","severity":"High","summary":"Outlook cannot connect to the mail server.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Test Outlook on the web to separate mailbox issues from local client issues.\n2. Verify service health, network, DNS, Autodiscover, credentials, quota, profile, and data-file state.\n3. Create a new Outlook profile or repair the affected PST only after server-side data is confirmed healthy.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x800CCC0E, which is related to outlook cannot connect to the mail server.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x800CCC0E and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: OUTLOOK\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Outlook"],"technologies":["Outlook","OUTLOOK","Error Code"],"aliases":["0x800CCC0E"]},{"id":3592,"title":"0x800CCC0F - The mail server connection was interrupted","category":"Outlook","product":"Microsoft Outlook","tags":["Outlook","OUTLOOK","Error Code"],"keywords":["0x800CCC0F","0x800ccc0f","outlook","the","mail","server","connection","was","interrupted","test","web","separate","mailbox","issues","from","local","client","verify","service","health","network","dns","autodiscover","credentials","quota","profile","and","data","file","state","create","new","repair","affected","pst","only","after","side","confirmed","healthy"],"errorCode":"0x800CCC0F","eventId":"","severity":"High","summary":"The mail server connection was interrupted.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Test Outlook on the web to separate mailbox issues from local client issues.\n2. Verify service health, network, DNS, Autodiscover, credentials, quota, profile, and data-file state.\n3. Create a new Outlook profile or repair the affected PST only after server-side data is confirmed healthy.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x800CCC0F, which is related to the mail server connection was interrupted.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x800CCC0F and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: OUTLOOK\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Outlook"],"technologies":["Outlook","OUTLOOK","Error Code"],"aliases":["0x800CCC0F"]},{"id":3593,"title":"0x800CCC92 - The mail server rejected the username or password","category":"Outlook","product":"Microsoft Outlook","tags":["Outlook","OUTLOOK","Error Code"],"keywords":["0x800CCC92","0x800ccc92","outlook","the","mail","server","rejected","username","password","test","web","separate","mailbox","issues","from","local","client","verify","service","health","network","dns","autodiscover","credentials","quota","profile","and","data","file","state","create","new","repair","affected","pst","only","after","side","confirmed","healthy"],"errorCode":"0x800CCC92","eventId":"","severity":"High","summary":"The mail server rejected the username or password.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Test Outlook on the web to separate mailbox issues from local client issues.\n2. Verify service health, network, DNS, Autodiscover, credentials, quota, profile, and data-file state.\n3. Create a new Outlook profile or repair the affected PST only after server-side data is confirmed healthy.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x800CCC92, which is related to the mail server rejected the username or password.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x800CCC92 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: OUTLOOK\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Outlook"],"technologies":["Outlook","OUTLOOK","Error Code"],"aliases":["0x800CCC92"]},{"id":3594,"title":"550 5.1.1 - The recipient address or mailbox does not exist","category":"Exchange","product":"Exchange Online","tags":["Exchange","EXCHANGE ONLINE","Error Code"],"keywords":["550 5.1.1","550","exchange","online","the","recipient","address","mailbox","does","not","exist","read","complete","ndr","and","run","message","trace","identify","rejecting","server","policy","connector","route","limit","verify","objects","accepted","domains","connectors","transport","rules","permissions","anti","spam","size","limits","relevant","correct","specific","mail"],"errorCode":"550 5.1.1","eventId":"","severity":"Low","summary":"The recipient address or mailbox does not exist.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Read the complete NDR and run Message Trace to identify the rejecting server, policy, connector, route, recipient, or limit.\n2. Verify recipient objects, accepted domains, connectors, transport rules, permissions, anti-spam policy, and size limits as relevant.\n3. Correct the specific mail-flow condition and retest with a new message.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 550 5.1.1, which is related to the recipient address or mailbox does not exist.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 550 5.1.1 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: EXCHANGE ONLINE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Exchange Online"],"technologies":["Exchange","EXCHANGE ONLINE","Error Code"],"aliases":["550 5.1.1"]},{"id":3595,"title":"4.4.7 - The message expired in the delivery queue","category":"Exchange","product":"Exchange Online","tags":["Exchange","EXCHANGE ONLINE","Error Code"],"keywords":["4.4.7","exchange","online","the","message","expired","delivery","queue","read","complete","ndr","and","run","trace","identify","rejecting","server","policy","connector","route","recipient","limit","verify","objects","accepted","domains","connectors","transport","rules","permissions","anti","spam","size","limits","relevant","correct","specific","mail","flow","condition","retest"],"errorCode":"4.4.7","eventId":"","severity":"Low","summary":"The message expired in the delivery queue.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Read the complete NDR and run Message Trace to identify the rejecting server, policy, connector, route, recipient, or limit.\n2. Verify recipient objects, accepted domains, connectors, transport rules, permissions, anti-spam policy, and size limits as relevant.\n3. Correct the specific mail-flow condition and retest with a new message.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 4.4.7, which is related to the message expired in the delivery queue.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 4.4.7 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: EXCHANGE ONLINE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Exchange Online"],"technologies":["Exchange","EXCHANGE ONLINE","Error Code"],"aliases":["4.4.7"]},{"id":3596,"title":"5.4.14 - A mail loop or routing problem occurred in Exchange Online","category":"Exchange","product":"Exchange Online","tags":["Exchange","EXCHANGE ONLINE","Error Code"],"keywords":["5.4.14","exchange","online","mail","loop","routing","problem","occurred","read","the","complete","ndr","and","run","message","trace","identify","rejecting","server","policy","connector","route","recipient","limit","verify","objects","accepted","domains","connectors","transport","rules","permissions","anti","spam","size","limits","relevant","correct","specific","flow","condition"],"errorCode":"5.4.14","eventId":"","severity":"Low","summary":"A mail loop or routing problem occurred in Exchange Online.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Read the complete NDR and run Message Trace to identify the rejecting server, policy, connector, route, recipient, or limit.\n2. Verify recipient objects, accepted domains, connectors, transport rules, permissions, anti-spam policy, and size limits as relevant.\n3. Correct the specific mail-flow condition and retest with a new message.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 5.4.14, which is related to a mail loop or routing problem occurred in exchange online.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 5.4.14 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: EXCHANGE ONLINE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Exchange Online"],"technologies":["Exchange","EXCHANGE ONLINE","Error Code"],"aliases":["5.4.14"]},{"id":3597,"title":"550 5.7.1 - Delivery was blocked by a security, permission, or routing rule","category":"Exchange","product":"Exchange Online","tags":["Exchange","EXCHANGE ONLINE","Error Code"],"keywords":["550 5.7.1","550","exchange","online","delivery","was","blocked","security","permission","routing","rule","read","the","complete","ndr","and","run","message","trace","identify","rejecting","server","policy","connector","route","recipient","limit","verify","objects","accepted","domains","connectors","transport","rules","permissions","anti","spam","size","limits","relevant","correct"],"errorCode":"550 5.7.1","eventId":"","severity":"High","summary":"Delivery was blocked by a security, permission, or routing rule.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Read the complete NDR and run Message Trace to identify the rejecting server, policy, connector, route, recipient, or limit.\n2. Verify recipient objects, accepted domains, connectors, transport rules, permissions, anti-spam policy, and size limits as relevant.\n3. Correct the specific mail-flow condition and retest with a new message.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 550 5.7.1, which is related to delivery was blocked by a security, permission, or routing rule.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 550 5.7.1 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: EXCHANGE ONLINE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Exchange Online"],"technologies":["Exchange","EXCHANGE ONLINE","Error Code"],"aliases":["550 5.7.1"]},{"id":3598,"title":"550 5.7.520 - Automatic external forwarding is blocked","category":"Exchange","product":"Exchange Online","tags":["Exchange","EXCHANGE ONLINE","Error Code"],"keywords":["550 5.7.520","550","520","exchange","online","automatic","external","forwarding","blocked","read","the","complete","ndr","and","run","message","trace","identify","rejecting","server","policy","connector","route","recipient","limit","verify","objects","accepted","domains","connectors","transport","rules","permissions","anti","spam","size","limits","relevant","correct","specific","mail"],"errorCode":"550 5.7.520","eventId":"","severity":"High","summary":"Automatic external forwarding is blocked.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Read the complete NDR and run Message Trace to identify the rejecting server, policy, connector, route, recipient, or limit.\n2. Verify recipient objects, accepted domains, connectors, transport rules, permissions, anti-spam policy, and size limits as relevant.\n3. Correct the specific mail-flow condition and retest with a new message.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 550 5.7.520, which is related to automatic external forwarding is blocked.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 550 5.7.520 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: EXCHANGE ONLINE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Exchange Online"],"technologies":["Exchange","EXCHANGE ONLINE","Error Code"],"aliases":["550 5.7.520"]},{"id":3599,"title":"552 5.2.3 - The message is too large","category":"Exchange","product":"Exchange Online","tags":["Exchange","EXCHANGE ONLINE","Error Code"],"keywords":["552 5.2.3","552","exchange","online","the","message","too","large","read","complete","ndr","and","run","trace","identify","rejecting","server","policy","connector","route","recipient","limit","verify","objects","accepted","domains","connectors","transport","rules","permissions","anti","spam","size","limits","relevant","correct","specific","mail","flow","condition","retest"],"errorCode":"552 5.2.3","eventId":"","severity":"Low","summary":"The message is too large.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Read the complete NDR and run Message Trace to identify the rejecting server, policy, connector, route, recipient, or limit.\n2. Verify recipient objects, accepted domains, connectors, transport rules, permissions, anti-spam policy, and size limits as relevant.\n3. Correct the specific mail-flow condition and retest with a new message.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 552 5.2.3, which is related to the message is too large.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 552 5.2.3 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: EXCHANGE ONLINE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Exchange Online"],"technologies":["Exchange","EXCHANGE ONLINE","Error Code"],"aliases":["552 5.2.3"]},{"id":3600,"title":"432 4.3.2 - The recipient thread limit was exceeded","category":"Exchange","product":"Exchange Online","tags":["Exchange","EXCHANGE ONLINE","Error Code"],"keywords":["432 4.3.2","432","exchange","online","the","recipient","thread","limit","was","exceeded","read","complete","ndr","and","run","message","trace","identify","rejecting","server","policy","connector","route","verify","objects","accepted","domains","connectors","transport","rules","permissions","anti","spam","size","limits","relevant","correct","specific","mail","flow","condition"],"errorCode":"432 4.3.2","eventId":"","severity":"Low","summary":"The recipient thread limit was exceeded.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Read the complete NDR and run Message Trace to identify the rejecting server, policy, connector, route, recipient, or limit.\n2. Verify recipient objects, accepted domains, connectors, transport rules, permissions, anti-spam policy, and size limits as relevant.\n3. Correct the specific mail-flow condition and retest with a new message.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 432 4.3.2, which is related to the recipient thread limit was exceeded.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 432 4.3.2 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: EXCHANGE ONLINE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Exchange Online"],"technologies":["Exchange","EXCHANGE ONLINE","Error Code"],"aliases":["432 4.3.2"]},{"id":3601,"title":"0xCAA20003 - An authorization problem occurred","category":"Teams","product":"Microsoft Teams","tags":["Teams","MICROSOFT TEAMS","Error Code"],"keywords":["0xCAA20003","0xcaa20003","microsoft","teams","authorization","problem","occurred","record","the","status","code","and","inspect","matching","entra","sign","event","verify","time","credentials","consent","conditional","access","dns","proxy","firewall","vpn","365","service","health","correct","identified","authentication","connectivity","issue","clear","stale","state","needed","retry"],"errorCode":"0xCAA20003","eventId":"","severity":"High","summary":"An authorization problem occurred.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Record the status code and inspect the matching Entra sign-in event.\n2. Verify time, credentials, consent, Conditional Access, DNS, proxy, firewall, VPN, and Microsoft 365 service health.\n3. Correct the identified authentication or connectivity issue, clear stale sign-in state if needed, and retry.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0xCAA20003, which is related to an authorization problem occurred.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0xCAA20003 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT TEAMS\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Teams"],"technologies":["Teams","MICROSOFT TEAMS","Error Code"],"aliases":["0xCAA20003"]},{"id":3602,"title":"0xCAA20004 - The request requires approval","category":"Teams","product":"Microsoft Teams","tags":["Teams","MICROSOFT TEAMS","Error Code"],"keywords":["0xCAA20004","0xcaa20004","microsoft","teams","the","request","requires","approval","record","status","code","and","inspect","matching","entra","sign","event","verify","time","credentials","consent","conditional","access","dns","proxy","firewall","vpn","365","service","health","correct","identified","authentication","connectivity","issue","clear","stale","state","needed","retry"],"errorCode":"0xCAA20004","eventId":"","severity":"High","summary":"The request requires approval.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Record the status code and inspect the matching Entra sign-in event.\n2. Verify time, credentials, consent, Conditional Access, DNS, proxy, firewall, VPN, and Microsoft 365 service health.\n3. Correct the identified authentication or connectivity issue, clear stale sign-in state if needed, and retry.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0xCAA20004, which is related to the request requires approval.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0xCAA20004 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT TEAMS\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Teams"],"technologies":["Teams","MICROSOFT TEAMS","Error Code"],"aliases":["0xCAA20004"]},{"id":3603,"title":"0xCAA70004 - The server or proxy could not be found","category":"Teams","product":"Microsoft Teams","tags":["Teams","MICROSOFT TEAMS","Error Code"],"keywords":["0xCAA70004","0xcaa70004","microsoft","teams","the","server","proxy","could","not","found","record","status","code","and","inspect","matching","entra","sign","event","verify","time","credentials","consent","conditional","access","dns","firewall","vpn","365","service","health","correct","identified","authentication","connectivity","issue","clear","stale","state","needed","retry"],"errorCode":"0xCAA70004","eventId":"","severity":"High","summary":"The server or proxy could not be found.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Record the status code and inspect the matching Entra sign-in event.\n2. Verify time, credentials, consent, Conditional Access, DNS, proxy, firewall, VPN, and Microsoft 365 service health.\n3. Correct the identified authentication or connectivity issue, clear stale sign-in state if needed, and retry.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0xCAA70004, which is related to the server or proxy could not be found.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0xCAA70004 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT TEAMS\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Teams"],"technologies":["Teams","MICROSOFT TEAMS","Error Code"],"aliases":["0xCAA70004"]},{"id":3604,"title":"0xCAA70007 - The download failed because the connection was interrupted","category":"Teams","product":"Microsoft Teams","tags":["Teams","MICROSOFT TEAMS","Error Code"],"keywords":["0xCAA70007","0xcaa70007","microsoft","teams","the","download","failed","because","connection","was","interrupted","record","status","code","and","inspect","matching","entra","sign","event","verify","time","credentials","consent","conditional","access","dns","proxy","firewall","vpn","365","service","health","correct","identified","authentication","connectivity","issue","clear","stale","state"],"errorCode":"0xCAA70007","eventId":"","severity":"High","summary":"The download failed because the connection was interrupted.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Record the status code and inspect the matching Entra sign-in event.\n2. Verify time, credentials, consent, Conditional Access, DNS, proxy, firewall, VPN, and Microsoft 365 service health.\n3. Correct the identified authentication or connectivity issue, clear stale sign-in state if needed, and retry.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0xCAA70007, which is related to the download failed because the connection was interrupted.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0xCAA70007 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT TEAMS\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Teams"],"technologies":["Teams","MICROSOFT TEAMS","Error Code"],"aliases":["0xCAA70007"]},{"id":3605,"title":"0xCAA82EE2 - The request timed out","category":"Teams","product":"Microsoft Teams","tags":["Teams","MICROSOFT TEAMS","Error Code"],"keywords":["0xCAA82EE2","0xcaa82ee2","microsoft","teams","the","request","timed","out","record","status","code","and","inspect","matching","entra","sign","event","verify","time","credentials","consent","conditional","access","dns","proxy","firewall","vpn","365","service","health","correct","identified","authentication","connectivity","issue","clear","stale","state","needed","retry"],"errorCode":"0xCAA82EE2","eventId":"","severity":"High","summary":"The request timed out.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Record the status code and inspect the matching Entra sign-in event.\n2. Verify time, credentials, consent, Conditional Access, DNS, proxy, firewall, VPN, and Microsoft 365 service health.\n3. Correct the identified authentication or connectivity issue, clear stale sign-in state if needed, and retry.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0xCAA82EE2, which is related to the request timed out.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0xCAA82EE2 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT TEAMS\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Teams"],"technologies":["Teams","MICROSOFT TEAMS","Error Code"],"aliases":["0xCAA82EE2"]},{"id":3606,"title":"0xCAA82EE7 - The server name could not be resolved","category":"Teams","product":"Microsoft Teams","tags":["Teams","MICROSOFT TEAMS","Error Code"],"keywords":["0xCAA82EE7","0xcaa82ee7","microsoft","teams","the","server","name","could","not","resolved","record","status","code","and","inspect","matching","entra","sign","event","verify","time","credentials","consent","conditional","access","dns","proxy","firewall","vpn","365","service","health","correct","identified","authentication","connectivity","issue","clear","stale","state","needed"],"errorCode":"0xCAA82EE7","eventId":"","severity":"High","summary":"The server name could not be resolved.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Record the status code and inspect the matching Entra sign-in event.\n2. Verify time, credentials, consent, Conditional Access, DNS, proxy, firewall, VPN, and Microsoft 365 service health.\n3. Correct the identified authentication or connectivity issue, clear stale sign-in state if needed, and retry.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0xCAA82EE7, which is related to the server name could not be resolved.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0xCAA82EE7 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT TEAMS\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Teams"],"technologies":["Teams","MICROSOFT TEAMS","Error Code"],"aliases":["0xCAA82EE7"]},{"id":3607,"title":"0xCAA90018 - The wrong credentials were used","category":"Teams","product":"Microsoft Teams","tags":["Teams","MICROSOFT TEAMS","Error Code"],"keywords":["0xCAA90018","0xcaa90018","microsoft","teams","the","wrong","credentials","were","used","record","status","code","and","inspect","matching","entra","sign","event","verify","time","consent","conditional","access","dns","proxy","firewall","vpn","365","service","health","correct","identified","authentication","connectivity","issue","clear","stale","state","needed","retry"],"errorCode":"0xCAA90018","eventId":"","severity":"High","summary":"The wrong credentials were used.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Record the status code and inspect the matching Entra sign-in event.\n2. Verify time, credentials, consent, Conditional Access, DNS, proxy, firewall, VPN, and Microsoft 365 service health.\n3. Correct the identified authentication or connectivity issue, clear stale sign-in state if needed, and retry.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0xCAA90018, which is related to the wrong credentials were used.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0xCAA90018 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT TEAMS\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Teams"],"technologies":["Teams","MICROSOFT TEAMS","Error Code"],"aliases":["0xCAA90018"]},{"id":3608,"title":"0x8007016A - The cloud file provider is not running","category":"Microsoft 365","product":"Microsoft OneDrive","tags":["Microsoft 365","ONEDRIVE","Error Code"],"keywords":["0x8007016A","0x8007016a","onedrive","the","cloud","file","provider","not","running","check","microsoft","365","service","health","account","status","network","proxy","tls","and","required","endpoints","restart","update","verify","files","demand","permissions","reset","sync","remains","unhealthy","then","confirm","returns","date"],"errorCode":"0x8007016A","eventId":"","severity":"High","summary":"The cloud file provider is not running.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Check Microsoft 365 service health, account status, network, proxy, TLS, and required endpoints.\n2. Restart and update OneDrive; verify Files On-Demand and file permissions.\n3. Reset OneDrive if the sync provider remains unhealthy, then confirm sync returns to Up to date.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x8007016A, which is related to the cloud file provider is not running.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x8007016A and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: ONEDRIVE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft OneDrive"],"technologies":["Microsoft 365","ONEDRIVE","Error Code"],"aliases":["0x8007016A"]},{"id":3609,"title":"0x8007017C - The cloud operation is invalid in the current sync state","category":"Microsoft 365","product":"Microsoft OneDrive","tags":["Microsoft 365","ONEDRIVE","Error Code"],"keywords":["0x8007017C","0x8007017c","onedrive","the","cloud","operation","invalid","current","sync","state","check","microsoft","365","service","health","account","status","network","proxy","tls","and","required","endpoints","restart","update","verify","files","demand","file","permissions","reset","provider","remains","unhealthy","then","confirm","returns","date"],"errorCode":"0x8007017C","eventId":"","severity":"High","summary":"The cloud operation is invalid in the current sync state.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Check Microsoft 365 service health, account status, network, proxy, TLS, and required endpoints.\n2. Restart and update OneDrive; verify Files On-Demand and file permissions.\n3. Reset OneDrive if the sync provider remains unhealthy, then confirm sync returns to Up to date.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x8007017C, which is related to the cloud operation is invalid in the current sync state.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x8007017C and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: ONEDRIVE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft OneDrive"],"technologies":["Microsoft 365","ONEDRIVE","Error Code"],"aliases":["0x8007017C"]},{"id":3610,"title":"0x80070194 - The cloud file provider exited unexpectedly","category":"Microsoft 365","product":"Microsoft OneDrive","tags":["Microsoft 365","ONEDRIVE","Error Code"],"keywords":["0x80070194","0x80070194","onedrive","the","cloud","file","provider","exited","unexpectedly","check","microsoft","365","service","health","account","status","network","proxy","tls","and","required","endpoints","restart","update","verify","files","demand","permissions","reset","sync","remains","unhealthy","then","confirm","returns","date"],"errorCode":"0x80070194","eventId":"","severity":"High","summary":"The cloud file provider exited unexpectedly.","rootCause":"Client state, authentication, licensing, service health, connectivity, cache, or tenant configuration can produce this Microsoft 365 error. Correlate the code with client and service logs.","resolution":"1. Check Microsoft 365 service health, account status, network, proxy, TLS, and required endpoints.\n2. Restart and update OneDrive; verify Files On-Demand and file permissions.\n3. Reset OneDrive if the sync provider remains unhealthy, then confirm sync returns to Up to date.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80070194, which is related to the cloud file provider exited unexpectedly.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80070194 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: ONEDRIVE\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft OneDrive"],"technologies":["Microsoft 365","ONEDRIVE","Error Code"],"aliases":["0x80070194"]},{"id":3611,"title":"0x800106BA - Microsoft Defender Antivirus service is disabled or stopped","category":"Security","product":"Microsoft Defender","tags":["Security","MICROSOFT DEFENDER","Error Code"],"keywords":["0x800106BA","0x800106ba","microsoft","defender","antivirus","service","disabled","stopped","check","windows","security","provider","status","services","policy","and","any","third","party","ownership","verify","update","endpoint","access","plus","proxy","firewall","behavior","restore","the","approved","configuration","run","platform","intelligence"],"errorCode":"0x800106BA","eventId":"","severity":"Low","summary":"Microsoft Defender Antivirus service is disabled or stopped.","rootCause":"Security policy, key or certificate state, permissions, trust, device health, or service configuration can cause this condition. Preserve recovery material and logs before changing security settings.","resolution":"1. Check Windows Security provider status, Defender services, policy, and any third-party antivirus ownership.\n2. Verify Microsoft Update and Defender endpoint access plus proxy and firewall behavior.\n3. Restore the approved security configuration and run a platform and security-intelligence update.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x800106BA, which is related to microsoft defender antivirus service is disabled or stopped.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x800106BA and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT DEFENDER\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Defender"],"technologies":["Security","MICROSOFT DEFENDER","Error Code"],"aliases":["0x800106BA"]},{"id":3612,"title":"0x80240438 - Microsoft Defender could not obtain updates","category":"Security","product":"Microsoft Defender","tags":["Security","MICROSOFT DEFENDER","Error Code"],"keywords":["0x80240438","0x80240438","microsoft","defender","could","not","obtain","updates","check","windows","security","provider","status","services","policy","and","any","third","party","antivirus","ownership","verify","update","endpoint","access","plus","proxy","firewall","behavior","restore","the","approved","configuration","run","platform","intelligence"],"errorCode":"0x80240438","eventId":"","severity":"Low","summary":"Microsoft Defender could not obtain updates.","rootCause":"Security policy, key or certificate state, permissions, trust, device health, or service configuration can cause this condition. Preserve recovery material and logs before changing security settings.","resolution":"1. Check Windows Security provider status, Defender services, policy, and any third-party antivirus ownership.\n2. Verify Microsoft Update and Defender endpoint access plus proxy and firewall behavior.\n3. Restore the approved security configuration and run a platform and security-intelligence update.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80240438, which is related to microsoft defender could not obtain updates.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80240438 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT DEFENDER\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Defender"],"technologies":["Security","MICROSOFT DEFENDER","Error Code"],"aliases":["0x80240438"]},{"id":3613,"title":"0x80310000 - A BitLocker operation failed","category":"Security","product":"Microsoft BitLocker","tags":["Security","BITLOCKER","Error Code"],"keywords":["0x80310000","0x80310000","bitlocker","operation","failed","protect","and","verify","recovery","information","before","changing","tpm","firmware","partitions","boot","files","protectors","review","api","logs","plus","secure","pcr","protector","policy","state","recover","with","the","matching","key","when","required","restore","healthy","confirm","escrow"],"errorCode":"0x80310000","eventId":"","severity":"High","summary":"A BitLocker operation failed.","rootCause":"Security policy, key or certificate state, permissions, trust, device health, or service configuration can cause this condition. Preserve recovery material and logs before changing security settings.","resolution":"1. Protect and verify recovery information before changing TPM, firmware, partitions, boot files, or protectors.\n2. Review BitLocker-API and TPM logs plus Secure Boot, PCR, protector, and policy state.\n3. Recover with the matching key when required, restore healthy protectors, and confirm escrow.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80310000, which is related to a bitlocker operation failed.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80310000 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: BITLOCKER\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft BitLocker"],"technologies":["Security","BITLOCKER","Error Code"],"aliases":["0x80310000"]},{"id":3614,"title":"0x80310024 - TPM or platform validation prevented the BitLocker operation","category":"Security","product":"Microsoft BitLocker","tags":["Security","BITLOCKER","Error Code"],"keywords":["0x80310024","0x80310024","bitlocker","tpm","platform","validation","prevented","the","operation","protect","and","verify","recovery","information","before","changing","firmware","partitions","boot","files","protectors","review","api","logs","plus","secure","pcr","protector","policy","state","recover","with","matching","key","when","required","restore","healthy","confirm","escrow"],"errorCode":"0x80310024","eventId":"","severity":"Low","summary":"TPM or platform validation prevented the BitLocker operation.","rootCause":"Security policy, key or certificate state, permissions, trust, device health, or service configuration can cause this condition. Preserve recovery material and logs before changing security settings.","resolution":"1. Protect and verify recovery information before changing TPM, firmware, partitions, boot files, or protectors.\n2. Review BitLocker-API and TPM logs plus Secure Boot, PCR, protector, and policy state.\n3. Recover with the matching key when required, restore healthy protectors, and confirm escrow.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80310024, which is related to tpm or platform validation prevented the bitlocker operation.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80310024 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: BITLOCKER\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft BitLocker"],"technologies":["Security","BITLOCKER","Error Code"],"aliases":["0x80310024"]},{"id":3615,"title":"0x8031004A - BitLocker requires recovery or cannot use the expected protector","category":"Security","product":"Microsoft BitLocker","tags":["Security","BITLOCKER","Error Code"],"keywords":["0x8031004A","0x8031004a","bitlocker","requires","recovery","cannot","use","the","expected","protector","protect","and","verify","information","before","changing","tpm","firmware","partitions","boot","files","protectors","review","api","logs","plus","secure","pcr","policy","state","recover","with","matching","key","when","required","restore","healthy","confirm","escrow"],"errorCode":"0x8031004A","eventId":"","severity":"Medium","summary":"BitLocker requires recovery or cannot use the expected protector.","rootCause":"Security policy, key or certificate state, permissions, trust, device health, or service configuration can cause this condition. Preserve recovery material and logs before changing security settings.","resolution":"1. Protect and verify recovery information before changing TPM, firmware, partitions, boot files, or protectors.\n2. Review BitLocker-API and TPM logs plus Secure Boot, PCR, protector, and policy state.\n3. Recover with the matching key when required, restore healthy protectors, and confirm escrow.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x8031004A, which is related to bitlocker requires recovery or cannot use the expected protector.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x8031004A and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: BITLOCKER\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft BitLocker"],"technologies":["Security","BITLOCKER","Error Code"],"aliases":["0x8031004A"]},{"id":3616,"title":"1030 - Group Policy could not retrieve policy information","category":"Active Directory","product":"Windows Group Policy","tags":["Active Directory","GROUP POLICY","Error Code"],"keywords":["1030","1030","group","policy","could","not","retrieve","information","review","the","grouppolicy","operational","and","system","logs","note","adjacent","events","verify","domain","dns","time","secure","channel","controller","discovery","sysvol","access","dfsr","permissions","correct","directory","replication","network","issue","run","gpupdate","force"],"errorCode":"1030","eventId":"","severity":"High","summary":"Group Policy could not retrieve policy information.","rootCause":"The code is contextual and can result from permissions, missing or damaged components, service state, configuration, connectivity, or a pending restart. Confirm the failing operation and matching logs before selecting a repair.","resolution":"1. Review the GroupPolicy operational and System logs and note adjacent events.\n2. Verify domain DNS, time, secure channel, domain-controller discovery, SYSVOL access, DFSR, and permissions.\n3. Correct the directory, replication, or network issue and run gpupdate /force.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 1030, which is related to group policy could not retrieve policy information.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 1030 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: GROUP POLICY\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":["gpupdate /force"],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Windows Group Policy"],"technologies":["Active Directory","GROUP POLICY","Error Code"],"aliases":["1030"]},{"id":3617,"title":"0x800B0109 - The certificate chain terminates in an untrusted root","category":"Security","product":"Windows PKI / Certificates","tags":["Security","CERTIFICATES AND PKI","Error Code"],"keywords":["0x800B0109","0x800b0109","certificates","and","pki","the","certificate","chain","terminates","untrusted","root","inspect","full","validity","dates","bindings","crl","ocsp","locations","correct","system","time","restore","trust","revocation","endpoint","access","renew","replace","redeploy","approved","retest","validation"],"errorCode":"0x800B0109","eventId":"","severity":"Low","summary":"The certificate chain terminates in an untrusted root.","rootCause":"Security policy, key or certificate state, permissions, trust, device health, or service configuration can cause this condition. Preserve recovery material and logs before changing security settings.","resolution":"1. Inspect the full certificate chain, validity dates, bindings, CRL, and OCSP locations.\n2. Correct system time and restore trust or revocation endpoint access.\n3. Renew, replace, or redeploy the approved certificate chain and retest validation.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x800B0109, which is related to the certificate chain terminates in an untrusted root.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x800B0109 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: CERTIFICATES AND PKI\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Windows PKI"],"technologies":["Security","CERTIFICATES AND PKI","Error Code"],"aliases":["0x800B0109"]},{"id":3618,"title":"0x800B0101 - A required certificate is expired or not yet valid","category":"Security","product":"Windows PKI / Certificates","tags":["Security","CERTIFICATES AND PKI","Error Code"],"keywords":["0x800B0101","0x800b0101","certificates","and","pki","required","certificate","expired","not","yet","valid","inspect","the","full","chain","validity","dates","bindings","crl","ocsp","locations","correct","system","time","restore","trust","revocation","endpoint","access","renew","replace","redeploy","approved","retest","validation"],"errorCode":"0x800B0101","eventId":"","severity":"Low","summary":"A required certificate is expired or not yet valid.","rootCause":"Security policy, key or certificate state, permissions, trust, device health, or service configuration can cause this condition. Preserve recovery material and logs before changing security settings.","resolution":"1. Inspect the full certificate chain, validity dates, bindings, CRL, and OCSP locations.\n2. Correct system time and restore trust or revocation endpoint access.\n3. Renew, replace, or redeploy the approved certificate chain and retest validation.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x800B0101, which is related to a required certificate is expired or not yet valid.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x800B0101 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: CERTIFICATES AND PKI\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Windows PKI"],"technologies":["Security","CERTIFICATES AND PKI","Error Code"],"aliases":["0x800B0101"]},{"id":3619,"title":"0x80092013 - The certificate revocation server is offline","category":"Security","product":"Windows PKI / Certificates","tags":["Security","CERTIFICATES AND PKI","Error Code"],"keywords":["0x80092013","0x80092013","certificates","and","pki","the","certificate","revocation","server","offline","inspect","full","chain","validity","dates","bindings","crl","ocsp","locations","correct","system","time","restore","trust","endpoint","access","renew","replace","redeploy","approved","retest","validation"],"errorCode":"0x80092013","eventId":"","severity":"Low","summary":"The certificate revocation server is offline.","rootCause":"Security policy, key or certificate state, permissions, trust, device health, or service configuration can cause this condition. Preserve recovery material and logs before changing security settings.","resolution":"1. Inspect the full certificate chain, validity dates, bindings, CRL, and OCSP locations.\n2. Correct system time and restore trust or revocation endpoint access.\n3. Renew, replace, or redeploy the approved certificate chain and retest validation.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80092013, which is related to the certificate revocation server is offline.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80092013 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: CERTIFICATES AND PKI\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Windows PKI"],"technologies":["Security","CERTIFICATES AND PKI","Error Code"],"aliases":["0x80092013"]},{"id":3620,"title":"0x80096010 - The digital signature is invalid","category":"Security","product":"Windows PKI / Certificates","tags":["Security","CERTIFICATES AND PKI","Error Code"],"keywords":["0x80096010","0x80096010","certificates","and","pki","the","digital","signature","invalid","inspect","full","certificate","chain","validity","dates","bindings","crl","ocsp","locations","correct","system","time","restore","trust","revocation","endpoint","access","renew","replace","redeploy","approved","retest","validation"],"errorCode":"0x80096010","eventId":"","severity":"Medium","summary":"The digital signature is invalid.","rootCause":"Security policy, key or certificate state, permissions, trust, device health, or service configuration can cause this condition. Preserve recovery material and logs before changing security settings.","resolution":"1. Inspect the full certificate chain, validity dates, bindings, CRL, and OCSP locations.\n2. Correct system time and restore trust or revocation endpoint access.\n3. Renew, replace, or redeploy the approved certificate chain and retest validation.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80096010, which is related to the digital signature is invalid.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80096010 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: CERTIFICATES AND PKI\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Windows PKI"],"technologies":["Security","CERTIFICATES AND PKI","Error Code"],"aliases":["0x80096010"]},{"id":3621,"title":"0x104 - Remote Desktop Cannot Reach Target Computer","category":"Windows Server","product":"Remote Desktop Services","tags":["Windows Server","REMOTE DESKTOP","Error Code"],"keywords":["0x104","0x104","remote","desktop","could","not","connect","the","verify","host","online","enabled","and","user","authorized","test","dns","routing","gateway","tcp","3389","configured","path","firewall","nla","time","certificates","update","both","endpoints","correct","specific","network","authentication","failure","before","retrying"],"errorCode":"0x104","eventId":"","severity":"High","summary":"Remote Desktop error 0x104 means the client could not reach the target computer. The failure occurs before a usable RDP session is established.","rootCause":"The target may be powered off, suspended, disconnected, or resolving to the wrong address. Remote Desktop may be disabled or blocked by Group Policy, the RDP-TCP listener or Remote Desktop Services may be unhealthy, TCP 3389 or a custom RDP port may be blocked, or an RD Gateway, VPN, route, firewall profile, or local-network permission may prevent reachability.","resolution":"1. Confirm the target computer is powered on and use an approved console such as Hyper-V, iLO, iDRAC, or the cloud console when available.\n2. Verify the hostname resolves to the expected IP address and test basic routing from the affected client.\n3. Test TCP 3389, or the configured RDP port, from the client. If an RD Gateway or VPN is required, verify that path separately.\n4. On the target, confirm Remote Desktop is enabled, the user is authorized, and policy is not disabling RDP.\n5. Confirm Remote Desktop Services is running and an RDP-TCP listener is present.\n6. Check Windows Defender Firewall and approved network firewalls for the active profile and configured RDP port. Do not disable the firewall as a test.\n7. Review TerminalServices-LocalSessionManager, TerminalServices-RemoteConnectionManager, System, and firewall logs at the failure time.\n8. Correct the confirmed power, DNS, route, gateway, listener, service, policy, or firewall issue and reconnect.\n9. Verify the session opens and the relevant logs show no new connection failure.","emailScript":"Hello,\n\nWe reviewed Remote Desktop error 0x104. The client is currently unable to reach the target computer, so we are checking the computer's availability, network path, Remote Desktop service, and firewall access.\n\nPlease keep the affected computer powered on and connected to its normal company network while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm the remote computer is powered on and connected to its normal network.\n2. Connect to the company VPN first if your organization requires it.\n3. Verify the computer name you were given and retry once.\n4. Do not disable antivirus or firewall protection.\n5. Send IT Support the full error, target name, approximate time, and whether the connection previously worked.","notes":"Error namespace: Microsoft Remote Desktop client. Do not confuse 0x104 with Win32 error 260 or an HTTP/transport value. Microsoft Windows Server guidance identifies machine state, RDP-TCP listener health, and network configuration as primary investigation areas. Registry changes are not a first-line action; back up the registry and preserve console access before any approved change.","commands":[{"shell":"PowerShell","command":"Resolve-DnsName <REMOTE-HOST>","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Test-NetConnection <REMOTE-HOST> -Port 3389 -InformationLevel Detailed","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-Service TermService","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"CMD","command":"qwinsta","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"troubleshoot-windows-server.pdf; microsoft_windows_error_code_master_list.txt","sourceAuthority":"Microsoft","namespace":"RDP-CLIENT","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Remote Desktop Services","Remote Desktop client","Windows Server"],"technologies":["RDP","TCP 3389","RDP-TCP Listener","Windows Defender Firewall"],"articleCategories":["Windows Server","Remote Desktop","Networking","Connectivity"],"aliases":["0x104","RDP 0x104","Remote Desktop error 0x104","cannot connect to remote PC"],"lastUpdated":"2026-08-10"},{"id":3622,"title":"0x112F - Remote Desktop authentication or CredSSP negotiation failed","category":"Windows Server","product":"Remote Desktop Services","tags":["Windows Server","REMOTE DESKTOP","Error Code"],"keywords":["0x112F","0x112f","remote","desktop","authentication","credssp","negotiation","failed","verify","the","host","online","enabled","and","user","authorized","test","dns","routing","gateway","tcp","3389","configured","path","firewall","nla","time","certificates","update","both","endpoints","correct","specific","network","failure","before","retrying"],"errorCode":"0x112F","eventId":"","severity":"High","summary":"Remote Desktop authentication or CredSSP negotiation failed.","rootCause":"The code is contextual and can result from permissions, missing or damaged components, service state, configuration, connectivity, or a pending restart. Confirm the failing operation and matching logs before selecting a repair.","resolution":"1. Verify the remote host is online, Remote Desktop is enabled, and the user is authorized.\n2. Test DNS, routing, gateway, TCP 3389 or the configured path, firewall, NLA, time, and certificates.\n3. Update both endpoints and correct the specific network or authentication failure before retrying.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x112F, which is related to remote desktop authentication or credssp negotiation failed.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x112F and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: REMOTE DESKTOP\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Remote Desktop Services"],"technologies":["Windows Server","REMOTE DESKTOP","Error Code"],"aliases":["0x112F"]},{"id":3623,"title":"0x803F7001 - No valid digital license or product key was found","category":"Windows","product":"Windows Activation","tags":["Windows","WINDOWS ACTIVATION","Error Code"],"keywords":["0x803F7001","0x803f7001","windows","activation","valid","digital","license","product","key","was","found","confirm","the","installed","edition","channel","type","account","entitlement","and","system","time","check","service","health","dns","proxy","tls","kms","reachability","when","applicable","run","troubleshooter","install","correct","approved","then","verify","status"],"errorCode":"0x803F7001","eventId":"","severity":"Low","summary":"No valid digital license or product key was found.","rootCause":"The code is contextual and can result from permissions, missing or damaged components, service state, configuration, connectivity, or a pending restart. Confirm the failing operation and matching logs before selecting a repair.","resolution":"1. Confirm the installed edition, license channel, key type, account entitlement, and system time.\n2. Check activation service health, DNS, proxy, TLS, and KMS reachability when applicable.\n3. Run Activation Troubleshooter or install the correct approved license/key, then verify activation status.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x803F7001, which is related to no valid digital license or product key was found.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x803F7001 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS ACTIVATION\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Windows Activation"],"technologies":["Windows","WINDOWS ACTIVATION","Error Code"],"aliases":["0x803F7001"]},{"id":3624,"title":"0x87E10BC6 - The activation or licensing operation could not complete","category":"Windows","product":"Windows Activation","tags":["Windows","WINDOWS ACTIVATION","Error Code"],"keywords":["0x87E10BC6","0x87e10bc6","windows","activation","the","licensing","operation","could","not","complete","confirm","installed","edition","license","channel","key","type","account","entitlement","and","system","time","check","service","health","dns","proxy","tls","kms","reachability","when","applicable","run","troubleshooter","install","correct","approved","then","verify","status"],"errorCode":"0x87E10BC6","eventId":"","severity":"Low","summary":"The activation or licensing operation could not complete.","rootCause":"The code is contextual and can result from permissions, missing or damaged components, service state, configuration, connectivity, or a pending restart. Confirm the failing operation and matching logs before selecting a repair.","resolution":"1. Confirm the installed edition, license channel, key type, account entitlement, and system time.\n2. Check activation service health, DNS, proxy, TLS, and KMS reachability when applicable.\n3. Run Activation Troubleshooter or install the correct approved license/key, then verify activation status.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x87E10BC6, which is related to the activation or licensing operation could not complete.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x87E10BC6 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS ACTIVATION\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Windows Activation"],"technologies":["Windows","WINDOWS ACTIVATION","Error Code"],"aliases":["0x87E10BC6"]},{"id":3625,"title":"0x8004FE33 - Activation failed through an authenticated proxy","category":"Windows","product":"Windows Activation","tags":["Windows","WINDOWS ACTIVATION","Error Code"],"keywords":["0x8004FE33","0x8004fe33","windows","activation","failed","through","authenticated","proxy","confirm","the","installed","edition","license","channel","key","type","account","entitlement","and","system","time","check","service","health","dns","tls","kms","reachability","when","applicable","run","troubleshooter","install","correct","approved","then","verify","status"],"errorCode":"0x8004FE33","eventId":"","severity":"High","summary":"Activation failed through an authenticated proxy.","rootCause":"The code is contextual and can result from permissions, missing or damaged components, service state, configuration, connectivity, or a pending restart. Confirm the failing operation and matching logs before selecting a repair.","resolution":"1. Confirm the installed edition, license channel, key type, account entitlement, and system time.\n2. Check activation service health, DNS, proxy, TLS, and KMS reachability when applicable.\n3. Run Activation Troubleshooter or install the correct approved license/key, then verify activation status.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x8004FE33, which is related to activation failed through an authenticated proxy.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x8004FE33 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS ACTIVATION\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Windows Activation"],"technologies":["Windows","WINDOWS ACTIVATION","Error Code"],"aliases":["0x8004FE33"]},{"id":3626,"title":"0x80073CF9 - Application package installation failed","category":"Windows","product":"Microsoft Store / AppX","tags":["Windows","MICROSOFT STORE AND APPX","Error Code"],"keywords":["0x80073CF9","0x80073cf9","microsoft","store","and","appx","application","package","installation","failed","review","appxdeploymentserver","event","logs","for","the","named","dependency","conflict","close","running","apps","check","free","space","windows","update","services","requirements","permissions","repair","reset","app","install","missing","frameworks","remove","conflicting","before","retrying"],"errorCode":"0x80073CF9","eventId":"","severity":"High","summary":"Application package installation failed.","rootCause":"The code is contextual and can result from permissions, missing or damaged components, service state, configuration, connectivity, or a pending restart. Confirm the failing operation and matching logs before selecting a repair.","resolution":"1. Review AppXDeploymentServer and Store event logs for the named package, dependency, or conflict.\n2. Close running apps, check free space, Windows Update, Store services, package requirements, and permissions.\n3. Repair or reset Store/app, install missing frameworks, or remove the conflicting package before retrying.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80073CF9, which is related to application package installation failed.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80073CF9 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT STORE AND APPX\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Store"],"technologies":["Windows","MICROSOFT STORE AND APPX","Error Code"],"aliases":["0x80073CF9"]},{"id":3627,"title":"0x80073D02 - The app package is in use","category":"Windows","product":"Microsoft Store / AppX","tags":["Windows","MICROSOFT STORE AND APPX","Error Code"],"keywords":["0x80073D02","0x80073d02","microsoft","store","and","appx","the","app","package","use","review","appxdeploymentserver","event","logs","for","named","dependency","conflict","close","running","apps","check","free","space","windows","update","services","requirements","permissions","repair","reset","install","missing","frameworks","remove","conflicting","before","retrying"],"errorCode":"0x80073D02","eventId":"","severity":"Low","summary":"The app package is in use.","rootCause":"The code is contextual and can result from permissions, missing or damaged components, service state, configuration, connectivity, or a pending restart. Confirm the failing operation and matching logs before selecting a repair.","resolution":"1. Review AppXDeploymentServer and Store event logs for the named package, dependency, or conflict.\n2. Close running apps, check free space, Windows Update, Store services, package requirements, and permissions.\n3. Repair or reset Store/app, install missing frameworks, or remove the conflicting package before retrying.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80073D02, which is related to the app package is in use.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80073D02 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT STORE AND APPX\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Store"],"technologies":["Windows","MICROSOFT STORE AND APPX","Error Code"],"aliases":["0x80073D02"]},{"id":3628,"title":"0x80073D05 - Existing application data could not be removed or updated","category":"Windows","product":"Microsoft Store / AppX","tags":["Windows","MICROSOFT STORE AND APPX","Error Code"],"keywords":["0x80073D05","0x80073d05","microsoft","store","and","appx","existing","application","data","could","not","removed","updated","review","appxdeploymentserver","event","logs","for","the","named","package","dependency","conflict","close","running","apps","check","free","space","windows","update","services","requirements","permissions","repair","reset","app","install","missing","frameworks","remove"],"errorCode":"0x80073D05","eventId":"","severity":"Low","summary":"Existing application data could not be removed or updated.","rootCause":"The code is contextual and can result from permissions, missing or damaged components, service state, configuration, connectivity, or a pending restart. Confirm the failing operation and matching logs before selecting a repair.","resolution":"1. Review AppXDeploymentServer and Store event logs for the named package, dependency, or conflict.\n2. Close running apps, check free space, Windows Update, Store services, package requirements, and permissions.\n3. Repair or reset Store/app, install missing frameworks, or remove the conflicting package before retrying.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80073D05, which is related to existing application data could not be removed or updated.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80073D05 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT STORE AND APPX\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Store"],"technologies":["Windows","MICROSOFT STORE AND APPX","Error Code"],"aliases":["0x80073D05"]},{"id":3629,"title":"0x80073CF3 - A package dependency, conflict, or requirement failed","category":"Windows","product":"Microsoft Store / AppX","tags":["Windows","MICROSOFT STORE AND APPX","Error Code"],"keywords":["0x80073CF3","0x80073cf3","microsoft","store","and","appx","package","dependency","conflict","requirement","failed","review","appxdeploymentserver","event","logs","for","the","named","close","running","apps","check","free","space","windows","update","services","requirements","permissions","repair","reset","app","install","missing","frameworks","remove","conflicting","before","retrying"],"errorCode":"0x80073CF3","eventId":"","severity":"High","summary":"A package dependency, conflict, or requirement failed.","rootCause":"The code is contextual and can result from permissions, missing or damaged components, service state, configuration, connectivity, or a pending restart. Confirm the failing operation and matching logs before selecting a repair.","resolution":"1. Review AppXDeploymentServer and Store event logs for the named package, dependency, or conflict.\n2. Close running apps, check free space, Windows Update, Store services, package requirements, and permissions.\n3. Repair or reset Store/app, install missing frameworks, or remove the conflicting package before retrying.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x80073CF3, which is related to a package dependency, conflict, or requirement failed.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x80073CF3 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT STORE AND APPX\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Store"],"technologies":["Windows","MICROSOFT STORE AND APPX","Error Code"],"aliases":["0x80073CF3"]},{"id":3630,"title":"0x803F8001 - Microsoft Store cannot verify the application license","category":"Windows","product":"Microsoft Store / AppX","tags":["Windows","MICROSOFT STORE AND APPX","Error Code"],"keywords":["0x803F8001","0x803f8001","microsoft","store","and","appx","cannot","verify","the","application","license","review","appxdeploymentserver","event","logs","for","named","package","dependency","conflict","close","running","apps","check","free","space","windows","update","services","requirements","permissions","repair","reset","app","install","missing","frameworks","remove","conflicting","before","retrying"],"errorCode":"0x803F8001","eventId":"","severity":"Medium","summary":"Microsoft Store cannot verify the application license.","rootCause":"The code is contextual and can result from permissions, missing or damaged components, service state, configuration, connectivity, or a pending restart. Confirm the failing operation and matching logs before selecting a repair.","resolution":"1. Review AppXDeploymentServer and Store event logs for the named package, dependency, or conflict.\n2. Close running apps, check free space, Windows Update, Store services, package requirements, and permissions.\n3. Repair or reset Store/app, install missing frameworks, or remove the conflicting package before retrying.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0x803F8001, which is related to microsoft store cannot verify the application license.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0x803F8001 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: MICROSOFT STORE AND APPX\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Microsoft Store"],"technologies":["Windows","MICROSOFT STORE AND APPX","Error Code"],"aliases":["0x803F8001"]},{"id":3631,"title":"DNS_PROBE_FINISHED_NXDOMAIN - The DNS name does not exist","category":"Networking","product":"Windows Networking","tags":["Networking","DNS AND NETWORKING","Error Code"],"keywords":["DNS_PROBE_FINISHED_NXDOMAIN","dns","probe","finished","nxdomain","and","networking","the","name","does","not","exist","verify","exact","host","port","route","gateway","response","from","affected","device","review","firewall","proxy","vpn","load","balancer","tls","inspection","remote","service","health","capture","network","trace","failure","source","unclear","correct","retest"],"errorCode":"DNS_PROBE_FINISHED_NXDOMAIN","eventId":"","severity":"High","summary":"The DNS name does not exist.","rootCause":"DNS resolution, routing, proxy, firewall, VPN, TLS inspection, or remote service availability can cause this response. Validate each network layer from the affected endpoint.","resolution":"1. Verify the exact host, IP, port, route, gateway, and DNS response from the affected device.\n2. Review firewall, proxy, VPN, load balancer, TLS inspection, and remote service health.\n3. Capture a network trace if the failure source is unclear, correct it, and retest connectivity.","emailScript":"Hello,\n\nWe reviewed the issue and identified error DNS_PROBE_FINISHED_NXDOMAIN, which is related to the dns name does not exist.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error DNS_PROBE_FINISHED_NXDOMAIN and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: DNS AND NETWORKING\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.","commands":[],"sourceDocument":"microsoft_windows_error_code_master_list.txt","platforms":["unknown"],"vendors":["Windows Networking"],"technologies":["Networking","DNS AND NETWORKING","Error Code"],"aliases":["DNS_PROBE_FINISHED_NXDOMAIN"]},{"id":3632,"title":"0xC000006D - The logon failed; the substatus identifies the cause","category":"Active Directory","product":"Windows Authentication","tags":["Active Directory","WINDOWS AUTHENTICATION","Error Code"],"keywords":["0xC000006D","0xc000006d","windows","authentication","the","logon","failed","substatus","identifies","cause","review","security","event","4625","and","record","status","type","account","process","workstation","source","address","identify","stale","credentials","services","scheduled","tasks","mapped","drives","applications","rmm","agents","user","sessions","correct","name","password","disabled","state","win","ntstatus","kerberos","general","failure","specific"],"errorCode":"0xC000006D","eventId":"","severity":"High","summary":"The logon failed; the substatus identifies the cause.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Review Security event 4625 and record status, substatus, logon type, account, process, workstation, and source address.\n2. Identify stale credentials in services, scheduled tasks, mapped drives, applications, RMM agents, or user sessions.\n3. Correct the account name, password, disabled state, trust, or stored credential and confirm failed-logon events stop.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0xC000006D, which is related to the logon failed; the substatus identifies the cause.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0xC000006D and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS AUTHENTICATION\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.\n\nAdditional source detail (windows_error_code_expansion.txt): Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","commands":[{"command":"nltest /dsgetdc:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"nltest /sc_verify:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"Test-ComputerSecureChannel -Verbose","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /status","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /source","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"microsoft_windows_error_code_master_list.txt; windows_error_code_expansion.txt","identifier":"0xC000006D","identifiers":["0xC000006D"],"identifierType":"Windows Authentication Status","namespace":"WIN-NTSTATUS","platform":"Windows","component":"Security / Kerberos","eventSource":"Security / Kerberos","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC000006D\nNamespace: WIN-NTSTATUS\nType: Windows Authentication Status\nPlatform: Windows\nProduct: Windows Authentication / Kerberos\nComponent: Security / Kerberos\nReview status: Verified\n\nMeaning: General logon failure. The substatus identifies the specific cause.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Authentication"],"technologies":["Active Directory","WINDOWS AUTHENTICATION","Error Code"],"aliases":["0xC000006D"]},{"id":3633,"title":"0xC0000064 - The user name does not exist","category":"Active Directory","product":"Windows Authentication","tags":["Active Directory","WINDOWS AUTHENTICATION","Error Code"],"keywords":["0xC0000064","0xc0000064","windows","authentication","the","user","name","does","not","exist","review","security","event","4625","and","record","status","substatus","logon","type","account","process","workstation","source","address","identify","stale","credentials","services","scheduled","tasks","mapped","drives","applications","rmm","agents","sessions","correct","password","disabled","state","win","ntstatus","kerberos","referenced","username"],"errorCode":"0xC0000064","eventId":"","severity":"High","summary":"The user name does not exist.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Review Security event 4625 and record status, substatus, logon type, account, process, workstation, and source address.\n2. Identify stale credentials in services, scheduled tasks, mapped drives, applications, RMM agents, or user sessions.\n3. Correct the account name, password, disabled state, trust, or stored credential and confirm failed-logon events stop.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0xC0000064, which is related to the user name does not exist.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0xC0000064 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS AUTHENTICATION\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.\n\nAdditional source detail (windows_error_code_expansion.txt): Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","commands":[{"command":"nltest /dsgetdc:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"nltest /sc_verify:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"Test-ComputerSecureChannel -Verbose","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /status","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /source","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"microsoft_windows_error_code_master_list.txt; windows_error_code_expansion.txt","identifier":"0xC0000064","identifiers":["0xC0000064"],"identifierType":"Windows Authentication Status","namespace":"WIN-NTSTATUS","platform":"Windows","component":"Security / Kerberos","eventSource":"Security / Kerberos","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC0000064\nNamespace: WIN-NTSTATUS\nType: Windows Authentication Status\nPlatform: Windows\nProduct: Windows Authentication / Kerberos\nComponent: Security / Kerberos\nReview status: Verified\n\nMeaning: The referenced username does not exist.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Authentication"],"technologies":["Active Directory","WINDOWS AUTHENTICATION","Error Code"],"aliases":["0xC0000064"]},{"id":3634,"title":"0xC000006A - The password is incorrect","category":"Active Directory","product":"Windows Authentication","tags":["Active Directory","WINDOWS AUTHENTICATION","Error Code"],"keywords":["0xC000006A","0xc000006a","windows","authentication","the","password","incorrect","review","security","event","4625","and","record","status","substatus","logon","type","account","process","workstation","source","address","identify","stale","credentials","services","scheduled","tasks","mapped","drives","applications","rmm","agents","user","sessions","correct","name","disabled","state","trust","stored","win","ntstatus","kerberos"],"errorCode":"0xC000006A","eventId":"","severity":"High","summary":"The password is incorrect.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Review Security event 4625 and record status, substatus, logon type, account, process, workstation, and source address.\n2. Identify stale credentials in services, scheduled tasks, mapped drives, applications, RMM agents, or user sessions.\n3. Correct the account name, password, disabled state, trust, or stored credential and confirm failed-logon events stop.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0xC000006A, which is related to the password is incorrect.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0xC000006A and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS AUTHENTICATION\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.\n\nAdditional source detail (windows_error_code_expansion.txt): Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","commands":[{"command":"nltest /dsgetdc:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"nltest /sc_verify:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"Test-ComputerSecureChannel -Verbose","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /status","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /source","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"microsoft_windows_error_code_master_list.txt; windows_error_code_expansion.txt","identifier":"0xC000006A","identifiers":["0xC000006A"],"identifierType":"Windows Authentication Status","namespace":"WIN-NTSTATUS","platform":"Windows","component":"Security / Kerberos","eventSource":"Security / Kerberos","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC000006A\nNamespace: WIN-NTSTATUS\nType: Windows Authentication Status\nPlatform: Windows\nProduct: Windows Authentication / Kerberos\nComponent: Security / Kerberos\nReview status: Verified\n\nMeaning: The password is incorrect.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Authentication"],"technologies":["Active Directory","WINDOWS AUTHENTICATION","Error Code"],"aliases":["0xC000006A"]},{"id":3635,"title":"0xC0000072 - The account is disabled","category":"Active Directory","product":"Windows Authentication","tags":["Active Directory","WINDOWS AUTHENTICATION","Error Code"],"keywords":["0xC0000072","0xc0000072","windows","authentication","the","account","disabled","review","security","event","4625","and","record","status","substatus","logon","type","process","workstation","source","address","identify","stale","credentials","services","scheduled","tasks","mapped","drives","applications","rmm","agents","user","sessions","correct","name","password","state","trust","stored","credential","win","ntstatus","kerberos"],"errorCode":"0xC0000072","eventId":"","severity":"High","summary":"The account is disabled.","rootCause":"Identity, licensing, device registration, policy assignment, credentials, conditional access, or directory synchronization can produce this response. Use sign-in and device logs to confirm the failing dependency.","resolution":"1. Review Security event 4625 and record status, substatus, logon type, account, process, workstation, and source address.\n2. Identify stale credentials in services, scheduled tasks, mapped drives, applications, RMM agents, or user sessions.\n3. Correct the account name, password, disabled state, trust, or stored credential and confirm failed-logon events stop.","emailScript":"Hello,\n\nWe reviewed the issue and identified error 0xC0000072, which is related to the account is disabled.\n\nWe are applying the appropriate corrective steps and will verify the affected service or application afterward.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete error 0xC0000072 and what you were doing when it appeared.\n2. Save your work and retry the action once.\n3. Confirm the device has a stable company-network or internet connection when required.\n4. Send IT Support the full message and a screenshot if the problem continues.","notes":"Source category: WINDOWS AUTHENTICATION\n\nVerification:\n1. Retry or reproduce the original operation.\n2. Confirm the error no longer appears in the relevant client, service, report, or event log.\n3. Document the root cause, change made, and validation result in the ticket.\n\nAdditional source detail (windows_error_code_expansion.txt): Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","commands":[{"command":"nltest /dsgetdc:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"nltest /sc_verify:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"Test-ComputerSecureChannel -Verbose","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /status","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /source","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"microsoft_windows_error_code_master_list.txt; windows_error_code_expansion.txt","identifier":"0xC0000072","identifiers":["0xC0000072"],"identifierType":"Windows Authentication Status","namespace":"WIN-NTSTATUS","platform":"Windows","component":"Security / Kerberos","eventSource":"Security / Kerberos","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC0000072\nNamespace: WIN-NTSTATUS\nType: Windows Authentication Status\nPlatform: Windows\nProduct: Windows Authentication / Kerberos\nComponent: Security / Kerberos\nReview status: Verified\n\nMeaning: The account is disabled.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Authentication"],"technologies":["Active Directory","WINDOWS AUTHENTICATION","Error Code"],"aliases":["0xC0000072"]},{"id":54000,"title":"Device Manager Code 1 - Device Is Not Configured Correctly","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 1"],"keywords":["Device Manager Code 1","Code 1","Device Is Not Configured Correctly","The device has no driver installed or its driver is configured incorrectly.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 1","eventId":"","severity":"Medium","summary":"Device Manager reports Code 1: Device Is Not Configured Correctly. The device has no driver installed or its driver is configured incorrectly.","rootCause":"The device has no driver installed or its driver is configured incorrectly.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Update the driver. If Windows cannot supply it, obtain the supported driver from the hardware manufacturer.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 1 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 1: Device Is Not Configured Correctly.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 1, HTTP 1, DOS error 1, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 1","Device status Code 1","Device Is Not Configured Correctly"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54001,"title":"Device Manager Code 3 - Driver Corrupted or System Resources Low","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 3"],"keywords":["Device Manager Code 3","Code 3","Driver Corrupted or System Resources Low","The driver may be corrupted, or Windows is low on memory or other resources.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 3","eventId":"","severity":"High","summary":"Device Manager reports Code 3: Driver Corrupted or System Resources Low. The driver may be corrupted, or Windows is low on memory or other resources.","rootCause":"The driver may be corrupted, or Windows is low on memory or other resources.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Close unnecessary applications and review memory resources. If the condition remains, uninstall and reinstall the supported driver; add memory only when resource evidence supports it.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 3 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 3: Driver Corrupted or System Resources Low.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 3, HTTP 3, DOS error 3, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 3","Device status Code 3","Driver Corrupted or System Resources Low"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54002,"title":"Device Manager Code 9 - Windows Cannot Identify the Hardware","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 9"],"keywords":["Device Manager Code 9","Code 9","Windows Cannot Identify the Hardware","Windows detected an invalid hardware identification number.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 9","eventId":"","severity":"Medium","summary":"Device Manager reports Code 9: Windows Cannot Identify the Hardware. Windows detected an invalid hardware identification number.","rootCause":"Windows detected an invalid hardware identification number.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Confirm the hardware identity and contact the manufacturer because the hardware or driver may be defective.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 9 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 9: Windows Cannot Identify the Hardware.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 9, HTTP 9, DOS error 9, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 9","Device status Code 9","Windows Cannot Identify the Hardware"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54003,"title":"Device Manager Code 10 - This Device Cannot Start","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 10"],"keywords":["Device Manager Code 10","Code 10","This Device Cannot Start","The device or its driver failed to start; a manufacturer-specific failure reason may be available.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 10","eventId":"","severity":"High","summary":"Device Manager reports Code 10: This Device Cannot Start. The device or its driver failed to start; a manufacturer-specific failure reason may be available.","rootCause":"The device or its driver failed to start; a manufacturer-specific failure reason may be available.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Review the full Device status message and update the device with the supported manufacturer driver.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 10 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 10: This Device Cannot Start.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 10, HTTP 10, DOS error 10, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 10","Device status Code 10","This Device Cannot Start"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54004,"title":"Device Manager Code 12 - Not Enough Free Resources","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 12"],"keywords":["Device Manager Code 12","Code 12","Not Enough Free Resources","The device has a conflicting or insufficient I/O, IRQ, DMA, or firmware-assigned resource.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 12","eventId":"","severity":"Medium","summary":"Device Manager reports Code 12: Not Enough Free Resources. The device has a conflicting or insufficient I/O, IRQ, DMA, or firmware-assigned resource.","rootCause":"The device has a conflicting or insufficient I/O, IRQ, DMA, or firmware-assigned resource.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Use Device Manager to identify the conflict and review firmware resource allocation. Change firmware or hardware resource settings only with vendor guidance and a recovery plan.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 12 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 12: Not Enough Free Resources.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 12, HTTP 12, DOS error 12, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. Firmware changes can prevent startup; confirm vendor support, power protection, recovery steps, and a maintenance window first.","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 12","Device status Code 12","Not Enough Free Resources"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54005,"title":"Device Manager Code 14 - Restart Required","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 14"],"keywords":["Device Manager Code 14","Code 14","Restart Required","The device cannot work correctly until Windows restarts.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 14","eventId":"","severity":"Medium","summary":"Device Manager reports Code 14: Restart Required. The device cannot work correctly until Windows restarts.","rootCause":"The device cannot work correctly until Windows restarts.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Save work and restart the computer, then verify the device state.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 14 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 14: Restart Required.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. A restart may be required, so please save your work.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 14, HTTP 14, DOS error 14, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 14","Device status Code 14","Restart Required"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54006,"title":"Device Manager Code 16 - Device Resources Partly Configured","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 16"],"keywords":["Device Manager Code 16","Code 16","Device Resources Partly Configured","Windows cannot identify every resource the device requires.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 16","eventId":"","severity":"Medium","summary":"Device Manager reports Code 16: Device Resources Partly Configured. Windows cannot identify every resource the device requires.","rootCause":"Windows cannot identify every resource the device requires.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. For supported Plug and Play hardware, inspect the Resources tab and correct only documented resource assignments; otherwise follow manufacturer guidance.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 16 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 16: Device Resources Partly Configured.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 16, HTTP 16, DOS error 16, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 16","Device status Code 16","Device Resources Partly Configured"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54007,"title":"Device Manager Code 18 - Reinstall the Device Driver","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 18"],"keywords":["Device Manager Code 18","Code 18","Reinstall the Device Driver","Windows recommends reinstalling the driver for this device.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 18","eventId":"","severity":"Medium","summary":"Device Manager reports Code 18: Reinstall the Device Driver. Windows recommends reinstalling the driver for this device.","rootCause":"Windows recommends reinstalling the driver for this device.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Uninstall the device from Device Manager, scan for hardware changes, and install the supported driver.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 18 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 18: Reinstall the Device Driver.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 18, HTTP 18, DOS error 18, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 18","Device status Code 18","Reinstall the Device Driver"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54008,"title":"Device Manager Code 19 - Device Registry Configuration Damaged","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 19"],"keywords":["Device Manager Code 19","Code 19","Device Registry Configuration Damaged","The device configuration in the registry is incomplete or damaged, possibly because of an invalid service definition or driver name.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 19","eventId":"","severity":"High","summary":"Device Manager reports Code 19: Device Registry Configuration Damaged. The device configuration in the registry is incomplete or damaged, possibly because of an invalid service definition or driver name.","rootCause":"The device configuration in the registry is incomplete or damaged, possibly because of an invalid service definition or driver name.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Uninstall and reinstall the supported driver. Use a known-good recovery point only after backup and impact review; do not manually delete registry keys as a generic fix.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 19 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 19: Device Registry Configuration Damaged.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 19, HTTP 19, DOS error 19, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 19","Device status Code 19","Device Registry Configuration Damaged"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54009,"title":"Device Manager Code 21 - Windows Is Removing the Device","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 21"],"keywords":["Device Manager Code 21","Code 21","Windows Is Removing the Device","Windows is still processing device removal.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 21","eventId":"","severity":"Medium","summary":"Device Manager reports Code 21: Windows Is Removing the Device. Windows is still processing device removal.","rootCause":"Windows is still processing device removal.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Wait, refresh Device Manager, and restart Windows if removal does not complete.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 21 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 21: Windows Is Removing the Device.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. A restart may be required, so please save your work.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 21, HTTP 21, DOS error 21, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 21","Device status Code 21","Windows Is Removing the Device"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54010,"title":"Device Manager Code 22 - Device Is Disabled","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 22"],"keywords":["Device Manager Code 22","Code 22","Device Is Disabled","The device was disabled in Device Manager.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 22","eventId":"","severity":"Medium","summary":"Device Manager reports Code 22: Device Is Disabled. The device was disabled in Device Manager.","rootCause":"The device was disabled in Device Manager.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Confirm the device should be active, then enable it in Device Manager and test it.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 22 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 22: Device Is Disabled.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 22, HTTP 22, DOS error 22, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 22","Device status Code 22","Device Is Disabled"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54011,"title":"Device Manager Code 24 - Device Missing or Not Working Properly","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 24"],"keywords":["Device Manager Code 24","Code 24","Device Missing or Not Working Properly","The device is absent, installed incorrectly, failing, or missing required drivers.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 24","eventId":"","severity":"Medium","summary":"Device Manager reports Code 24: Device Missing or Not Working Properly. The device is absent, installed incorrectly, failing, or missing required drivers.","rootCause":"The device is absent, installed incorrectly, failing, or missing required drivers.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Check the physical or virtual connection, remove the stale device entry where appropriate, reconnect it, and install the supported driver.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 24 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 24: Device Missing or Not Working Properly.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 24, HTTP 24, DOS error 24, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 24","Device status Code 24","Device Missing or Not Working Properly"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54012,"title":"Device Manager Code 28 - Device Drivers Are Not Installed","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 28"],"keywords":["Device Manager Code 28","Code 28","Device Drivers Are Not Installed","Windows does not have the required drivers installed.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 28","eventId":"","severity":"Medium","summary":"Device Manager reports Code 28: Device Drivers Are Not Installed. Windows does not have the required drivers installed.","rootCause":"Windows does not have the required drivers installed.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Install the current supported driver, or uninstall the incomplete device and scan for hardware changes before installing it.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 28 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 28: Device Drivers Are Not Installed.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 28, HTTP 28, DOS error 28, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 28","Device status Code 28","Device Drivers Are Not Installed"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54013,"title":"Device Manager Code 29 - Device Disabled by Firmware","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 29"],"keywords":["Device Manager Code 29","Code 29","Device Disabled by Firmware","System firmware did not provide the resources required by the device.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 29","eventId":"","severity":"Medium","summary":"Device Manager reports Code 29: Device Disabled by Firmware. System firmware did not provide the resources required by the device.","rootCause":"System firmware did not provide the resources required by the device.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Review firmware settings and manufacturer documentation; enable or correctly allocate the device in firmware only under an approved change plan.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 29 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 29: Device Disabled by Firmware.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 29, HTTP 29, DOS error 29, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. Firmware changes can prevent startup; confirm vendor support, power protection, recovery steps, and a maintenance window first.","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 29","Device status Code 29","Device Disabled by Firmware"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54014,"title":"Device Manager Code 31 - Windows Cannot Load Required Drivers","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 31"],"keywords":["Device Manager Code 31","Code 31","Windows Cannot Load Required Drivers","The device is not working because Windows cannot load its required driver.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 31","eventId":"","severity":"High","summary":"Device Manager reports Code 31: Windows Cannot Load Required Drivers. The device is not working because Windows cannot load its required driver.","rootCause":"The device is not working because Windows cannot load its required driver.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Update or reinstall the supported driver and review related DeviceSetupManager, Kernel-PnP, and System events.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 31 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 31: Windows Cannot Load Required Drivers.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 31, HTTP 31, DOS error 31, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 31","Device status Code 31","Windows Cannot Load Required Drivers"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54015,"title":"Device Manager Code 32 - Device Driver Service Is Disabled","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 32"],"keywords":["Device Manager Code 32","Code 32","Device Driver Service Is Disabled","The driver's service start type is disabled and another driver may be providing the function.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 32","eventId":"","severity":"Medium","summary":"Device Manager reports Code 32: Device Driver Service Is Disabled. The driver's service start type is disabled and another driver may be providing the function.","rootCause":"The driver's service start type is disabled and another driver may be providing the function.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Reinstall the supported driver and confirm the intended driver service configuration; avoid editing the registry start type without vendor guidance.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 32 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 32: Device Driver Service Is Disabled.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 32, HTTP 32, DOS error 32, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 32","Device status Code 32","Device Driver Service Is Disabled"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54016,"title":"Device Manager Code 33 - Resource Translator Failed","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 33"],"keywords":["Device Manager Code 33","Code 33","Resource Translator Failed","Windows cannot determine which resources the device requires.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 33","eventId":"","severity":"High","summary":"Device Manager reports Code 33: Resource Translator Failed. Windows cannot determine which resources the device requires.","rootCause":"Windows cannot determine which resources the device requires.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Review firmware and hardware configuration, apply an approved firmware update when supported, or have the vendor repair or replace the hardware.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 33 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 33: Resource Translator Failed.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 33, HTTP 33, DOS error 33, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. Firmware changes can prevent startup; confirm vendor support, power protection, recovery steps, and a maintenance window first.","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 33","Device status Code 33","Resource Translator Failed"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54017,"title":"Device Manager Code 34 - Manual Device Configuration Required","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 34"],"keywords":["Device Manager Code 34","Code 34","Manual Device Configuration Required","Windows cannot automatically determine the device settings.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 34","eventId":"","severity":"Medium","summary":"Device Manager reports Code 34: Manual Device Configuration Required. Windows cannot automatically determine the device settings.","rootCause":"Windows cannot automatically determine the device settings.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Follow the hardware manufacturer's documented configuration, then set only the required resources in Device Manager.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 34 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 34: Manual Device Configuration Required.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 34, HTTP 34, DOS error 34, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 34","Device status Code 34","Manual Device Configuration Required"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54018,"title":"Device Manager Code 35 - System Firmware Lacks Required Information","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 35"],"keywords":["Device Manager Code 35","Code 35","System Firmware Lacks Required Information","Firmware tables do not contain enough information to configure the device.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 35","eventId":"","severity":"Medium","summary":"Device Manager reports Code 35: System Firmware Lacks Required Information. Firmware tables do not contain enough information to configure the device.","rootCause":"Firmware tables do not contain enough information to configure the device.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Obtain an approved BIOS or firmware update from the computer manufacturer.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 35 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 35: System Firmware Lacks Required Information.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 35, HTTP 35, DOS error 35, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. Firmware changes can prevent startup; confirm vendor support, power protection, recovery steps, and a maintenance window first.","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 35","Device status Code 35","System Firmware Lacks Required Information"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54019,"title":"Device Manager Code 36 - PCI and ISA Interrupt Mismatch","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 36"],"keywords":["Device Manager Code 36","Code 36","PCI and ISA Interrupt Mismatch","The device is requesting one interrupt type while configured for another.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 36","eventId":"","severity":"Medium","summary":"Device Manager reports Code 36: PCI and ISA Interrupt Mismatch. The device is requesting one interrupt type while configured for another.","rootCause":"The device is requesting one interrupt type while configured for another.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Review IRQ reservations in system firmware and correct them only according to the manufacturer documentation.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 36 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 36: PCI and ISA Interrupt Mismatch.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 36, HTTP 36, DOS error 36, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. Firmware changes can prevent startup; confirm vendor support, power protection, recovery steps, and a maintenance window first.","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 36","Device status Code 36","PCI and ISA Interrupt Mismatch"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54020,"title":"Device Manager Code 37 - Driver Initialization Failed","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 37"],"keywords":["Device Manager Code 37","Code 37","Driver Initialization Failed","The driver returned a failure while running its DriverEntry routine.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 37","eventId":"","severity":"High","summary":"Device Manager reports Code 37: Driver Initialization Failed. The driver returned a failure while running its DriverEntry routine.","rootCause":"The driver returned a failure while running its DriverEntry routine.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Uninstall and reinstall the supported driver, then review driver and System events if initialization still fails.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 37 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 37: Driver Initialization Failed.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 37, HTTP 37, DOS error 37, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 37","Device status Code 37","Driver Initialization Failed"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54021,"title":"Device Manager Code 38 - Previous Driver Instance Still in Memory","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 38"],"keywords":["Device Manager Code 38","Code 38","Previous Driver Instance Still in Memory","Windows cannot load the driver because an earlier instance remains loaded.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 38","eventId":"","severity":"High","summary":"Device Manager reports Code 38: Previous Driver Instance Still in Memory. Windows cannot load the driver because an earlier instance remains loaded.","rootCause":"Windows cannot load the driver because an earlier instance remains loaded.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Save work and restart Windows, then confirm the driver loads normally.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 38 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 38: Previous Driver Instance Still in Memory.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. A restart may be required, so please save your work.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 38, HTTP 38, DOS error 38, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 38","Device status Code 38","Previous Driver Instance Still in Memory"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54022,"title":"Device Manager Code 39 - Driver Missing or Corrupted","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 39"],"keywords":["Device Manager Code 39","Code 39","Driver Missing or Corrupted","Windows cannot load the required driver because it may be missing or damaged.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 39","eventId":"","severity":"High","summary":"Device Manager reports Code 39: Driver Missing or Corrupted. Windows cannot load the required driver because it may be missing or damaged.","rootCause":"Windows cannot load the required driver because it may be missing or damaged.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Uninstall and reinstall the supported manufacturer driver.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 39 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 39: Driver Missing or Corrupted.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 39, HTTP 39, DOS error 39, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 39","Device status Code 39","Driver Missing or Corrupted"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54023,"title":"Device Manager Code 40 - Driver Service Registry Information Invalid","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 40"],"keywords":["Device Manager Code 40","Code 40","Driver Service Registry Information Invalid","The driver's service-key information is missing or recorded incorrectly.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 40","eventId":"","severity":"Medium","summary":"Device Manager reports Code 40: Driver Service Registry Information Invalid. The driver's service-key information is missing or recorded incorrectly.","rootCause":"The driver's service-key information is missing or recorded incorrectly.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Uninstall and reinstall the supported driver; do not manually reconstruct service registry keys without vendor documentation.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 40 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 40: Driver Service Registry Information Invalid.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 40, HTTP 40, DOS error 40, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 40","Device status Code 40","Driver Service Registry Information Invalid"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54024,"title":"Device Manager Code 41 - Driver Loaded but Hardware Not Found","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 41"],"keywords":["Device Manager Code 41","Code 41","Driver Loaded but Hardware Not Found","Windows loaded the driver but cannot find the device, often with non-Plug and Play hardware.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 41","eventId":"","severity":"Medium","summary":"Device Manager reports Code 41: Driver Loaded but Hardware Not Found. Windows loaded the driver but cannot find the device, often with non-Plug and Play hardware.","rootCause":"Windows loaded the driver but cannot find the device, often with non-Plug and Play hardware.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Confirm the device is physically or virtually present, then reinstall the supported driver.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 41 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 41: Driver Loaded but Hardware Not Found.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 41, HTTP 41, DOS error 41, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 41","Device status Code 41","Driver Loaded but Hardware Not Found"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54025,"title":"Device Manager Code 42 - Duplicate Device Instance","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 42"],"keywords":["Device Manager Code 42","Code 42","Duplicate Device Instance","Windows detected a duplicate device, possibly because of a bus-driver error or a device discovered in a new location.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 42","eventId":"","severity":"Medium","summary":"Device Manager reports Code 42: Duplicate Device Instance. Windows detected a duplicate device, possibly because of a bus-driver error or a device discovered in a new location.","rootCause":"Windows detected a duplicate device, possibly because of a bus-driver error or a device discovered in a new location.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Save work and restart Windows. If the duplicate returns, review bus, docking, virtualization, and manufacturer driver behavior.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 42 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 42: Duplicate Device Instance.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. A restart may be required, so please save your work.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 42, HTTP 42, DOS error 42, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 42","Device status Code 42","Duplicate Device Instance"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54026,"title":"Device Manager Code 43 - Device Reported a Failure","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 43"],"keywords":["Device Manager Code 43","Code 43","Device Reported a Failure","A driver controlling the device told Windows that the device failed.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 43","eventId":"","severity":"High","summary":"Device Manager reports Code 43: Device Reported a Failure. A driver controlling the device told Windows that the device failed.","rootCause":"A driver controlling the device told Windows that the device failed.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Review the device and System logs, power and cabling, firmware, and manufacturer diagnostics; reinstall the supported driver and contact the vendor if the hardware continues to report failure.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 43 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 43: Device Reported a Failure.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 43, HTTP 43, DOS error 43, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. Firmware changes can prevent startup; confirm vendor support, power protection, recovery steps, and a maintenance window first.","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 43","Device status Code 43","Device Reported a Failure"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54027,"title":"Device Manager Code 44 - Application or Service Stopped the Device","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 44"],"keywords":["Device Manager Code 44","Code 44","Application or Service Stopped the Device","An application or service shut down the hardware device.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 44","eventId":"","severity":"Medium","summary":"Device Manager reports Code 44: Application or Service Stopped the Device. An application or service shut down the hardware device.","rootCause":"An application or service shut down the hardware device.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Save work and restart Windows, then identify the application or service if the condition recurs.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 44 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 44: Application or Service Stopped the Device.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. A restart may be required, so please save your work.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 44, HTTP 44, DOS error 44, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 44","Device status Code 44","Application or Service Stopped the Device"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54028,"title":"Device Manager Code 45 - Device Is Not Connected","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 45"],"keywords":["Device Manager Code 45","Code 45","Device Is Not Connected","A previously installed device is currently disconnected.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 45","eventId":"","severity":"Medium","summary":"Device Manager reports Code 45: Device Is Not Connected. A previously installed device is currently disconnected.","rootCause":"A previously installed device is currently disconnected.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Reconnect the device if it is still required. No repair is necessary for an intentionally disconnected device.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 45 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 45: Device Is Not Connected.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 45, HTTP 45, DOS error 45, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 45","Device status Code 45","Device Is Not Connected"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54029,"title":"Device Manager Code 46 - Windows Is Shutting Down","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 46"],"keywords":["Device Manager Code 46","Code 46","Windows Is Shutting Down","The operating system is shutting down, so the hardware is unavailable.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 46","eventId":"","severity":"Medium","summary":"Device Manager reports Code 46: Windows Is Shutting Down. The operating system is shutting down, so the hardware is unavailable.","rootCause":"The operating system is shutting down, so the hardware is unavailable.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. No repair is normally required; verify the device after the next startup.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 46 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 46: Windows Is Shutting Down.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 46, HTTP 46, DOS error 46, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 46","Device status Code 46","Windows Is Shutting Down"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54030,"title":"Device Manager Code 47 - Device Prepared for Safe Removal","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 47"],"keywords":["Device Manager Code 47","Code 47","Device Prepared for Safe Removal","The device was prepared for removal but remains attached.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 47","eventId":"","severity":"Medium","summary":"Device Manager reports Code 47: Device Prepared for Safe Removal. The device was prepared for removal but remains attached.","rootCause":"The device was prepared for removal but remains attached.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Disconnect and reconnect the device safely; restart Windows if it remains unavailable.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 47 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 47: Device Prepared for Safe Removal.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. A restart may be required, so please save your work.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 47, HTTP 47, DOS error 47, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 47","Device status Code 47","Device Prepared for Safe Removal"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54031,"title":"Device Manager Code 48 - Driver Blocked for Compatibility","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 48"],"keywords":["Device Manager Code 48","Code 48","Driver Blocked for Compatibility","Windows blocked a driver known to have compatibility problems.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 48","eventId":"","severity":"High","summary":"Device Manager reports Code 48: Driver Blocked for Compatibility. Windows blocked a driver known to have compatibility problems.","rootCause":"Windows blocked a driver known to have compatibility problems.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Obtain and install a supported updated driver from the hardware manufacturer.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 48 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 48: Driver Blocked for Compatibility.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 48, HTTP 48, DOS error 48, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 48","Device status Code 48","Driver Blocked for Compatibility"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54032,"title":"Device Manager Code 49 - System Hive Too Large for New Devices","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 49"],"keywords":["Device Manager Code 49","Code 49","System Hive Too Large for New Devices","The system registry hive is too large, often because many unused device instances remain recorded.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 49","eventId":"","severity":"Medium","summary":"Device Manager reports Code 49: System Hive Too Large for New Devices. The system registry hive is too large, often because many unused device instances remain recorded.","rootCause":"The system registry hive is too large, often because many unused device instances remain recorded.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Show non-present devices, document them, and uninstall only obsolete hardware entries before restarting. Preserve a recovery plan and do not bulk-delete devices.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 49 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 49: System Hive Too Large for New Devices.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. A restart may be required, so please save your work.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 49, HTTP 49, DOS error 49, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 49","Device status Code 49","System Hive Too Large for New Devices"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54033,"title":"Device Manager Code 50 - Device Properties Could Not Be Applied","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 50"],"keywords":["Device Manager Code 50","Code 50","Device Properties Could Not Be Applied","Windows could not apply all device properties, possibly because of a driver limitation or failure.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 50","eventId":"","severity":"High","summary":"Device Manager reports Code 50: Device Properties Could Not Be Applied. Windows could not apply all device properties, possibly because of a driver limitation or failure.","rootCause":"Windows could not apply all device properties, possibly because of a driver limitation or failure.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Reinstall the supported driver and contact the hardware manufacturer for an updated driver if the problem remains.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 50 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 50: Device Properties Could Not Be Applied.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 50, HTTP 50, DOS error 50, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 50","Device status Code 50","Device Properties Could Not Be Applied"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54034,"title":"Device Manager Code 51 - Waiting for Another Device to Start","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 51"],"keywords":["Device Manager Code 51","Code 51","Waiting for Another Device to Start","This device depends on another device or device set that has not started.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 51","eventId":"","severity":"Medium","summary":"Device Manager reports Code 51: Waiting for Another Device to Start. This device depends on another device or device set that has not started.","rootCause":"This device depends on another device or device set that has not started.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Inspect related failed devices in the Device Manager tree and resolve the upstream dependency first.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 51 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 51: Waiting for Another Device to Start.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 51, HTTP 51, DOS error 51, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 51","Device status Code 51","Waiting for Another Device to Start"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54035,"title":"Device Manager Code 52 - Driver Digital Signature Cannot Be Verified","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 52"],"keywords":["Device Manager Code 52","Code 52","Driver Digital Signature Cannot Be Verified","The required driver may be unsigned, corrupted, or from an untrusted source.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 52","eventId":"","severity":"High","summary":"Device Manager reports Code 52: Driver Digital Signature Cannot Be Verified. The required driver may be unsigned, corrupted, or from an untrusted source.","rootCause":"The required driver may be unsigned, corrupted, or from an untrusted source.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Obtain the current signed driver from the hardware manufacturer. Do not disable signature enforcement as a routine fix.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 52 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 52: Driver Digital Signature Cannot Be Verified.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. \n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 52, HTTP 52, DOS error 52, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 52","Device status Code 52","Driver Digital Signature Cannot Be Verified"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54036,"title":"Device Manager Code 53 - Reserved for Windows Kernel Debugger","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 53"],"keywords":["Device Manager Code 53","Code 53","Reserved for Windows Kernel Debugger","The device is reserved for kernel-debugger use during the current boot session.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 53","eventId":"","severity":"Medium","summary":"Device Manager reports Code 53: Reserved for Windows Kernel Debugger. The device is reserved for kernel-debugger use during the current boot session.","rootCause":"The device is reserved for kernel-debugger use during the current boot session.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. If debugging is no longer required, disable Windows kernel debugging through the approved boot configuration and restart.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 53 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 53: Reserved for Windows Kernel Debugger.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. A restart may be required, so please save your work.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 53, HTTP 53, DOS error 53, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. ","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 53","Device status Code 53","Reserved for Windows Kernel Debugger"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54037,"title":"Device Manager Code 54 - Device Failed and Is Resetting","category":"Windows","product":"Windows Device Manager","tags":["Device Manager","Hardware","Driver","Code 54"],"keywords":["Device Manager Code 54","Code 54","Device Failed and Is Resetting","Windows assigned this intermittent code while an ACPI device reset is in progress.","driver error","hardware error","device status","devmgmt.msc"],"errorCode":"Device Manager Code 54","eventId":"","severity":"High","summary":"Device Manager reports Code 54: Device Failed and Is Resetting. Windows assigned this intermittent code while an ACPI device reset is in progress.","rootCause":"Windows assigned this intermittent code while an ACPI device reset is in progress.","resolution":"1. Open Device Manager, locate the affected device, and record its full Device status, hardware IDs, driver provider, driver version, and recent change history.\n2. Review System, Kernel-PnP, DeviceSetupManager, and Code Integrity events at the same time.\n3. Wait for the reset to complete. If the device remains stuck, save work and restart Windows, then investigate firmware, power, driver, and ACPI events.\n4. Re-scan hardware or restart only when required.\n5. Confirm Device Manager no longer reports Code 54 and test the device's actual function.","emailScript":"Hello,\n\nWe reviewed the hardware issue and identified Device Manager Code 54: Device Failed and Is Resetting.\n\nWe are checking the device, its supported driver, and the related Windows configuration before applying the corrective action. A restart may be required, so please save your work.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the device connected unless IT asks you to disconnect it.\n2. Do not download drivers from third-party driver websites.\n3. Send IT Support a screenshot of the device's Properties > General and Driver tabs.\n4. Save your work if a restart is requested.","notes":"Namespace: Windows Device Manager problem code. This is not Win32 system error 54, HTTP 54, DOS error 54, or another numeric-code family.\nMicrosoft's public support list is not exhaustive. Use the complete Device status text and hardware ID when escalating. Firmware changes can prevent startup; confirm vendor support, power protection, recovery steps, and a maintenance window first.","commands":[{"shell":"CMD","command":"pnputil /enum-devices /problem","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-PnpDevice -PresentOnly | Where-Object Status -ne 'OK' | Format-Table Status,Class,FriendlyName,InstanceId","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Support - Error codes in Device Manager in Windows","sourceAuthority":"Microsoft","namespace":"DEVICE-MANAGER","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Windows 11","Windows 10","Device Manager"],"technologies":["Plug and Play","Device Drivers","Hardware"],"articleCategories":["Windows","Hardware","Drivers","Device Manager"],"aliases":["Code 54","Device status Code 54","Device Failed and Is Resetting"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":54038,"title":"0xCAAD0009 - Device Registration Authentication Failed","category":"Entra ID","product":"Microsoft 365 Authentication / Device Registration","tags":["657ry","Device Registration","Work or School Account","Microsoft Authentication"],"keywords":["3400335369","0xCAAD0009","657ry","caad0009","device registration","work or school account","Microsoft Entra ID","Azure AD","AzureAdJoined","DomainJoined","WorkplaceJoined","DeviceAuthStatus","AzureAdPrt","TenantId","WamDefaultSet","OneDrive authentication","File Explorer","hybrid join","WAM","correlation ID"],"errorCode":"3400335369 / 0xCAAD0009","eventId":"","severity":"High","summary":"A Microsoft desktop application could not complete authentication using the device's work or school identity. The error may appear while OneDrive or File Explorer is loading, but Microsoft does not list it as a standard OneDrive synchronization error.","rootCause":"The Windows work or school account registration may be damaged or inconsistent. The Microsoft Entra device object may be disabled, deleted, duplicated, or stale. A registration failure, unavailable domain controller on a hybrid-joined device, or local Microsoft authentication component failure can also prevent the application from obtaining a valid device identity.","resolution":"1. Confirm the user can access OneDrive in a browser.\n2. Restart Windows and install current Windows and OneDrive updates.\n3. Run dsregcmd /status.\n4. Review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n5. Confirm the device exists and is enabled in Microsoft Entra ID and Intune.\n6. Verify the correct account under Settings > Accounts > Access work or school.\n7. If device identity is healthy, reset OneDrive or unlink and relink the account.\n8. If the failure continues, use the correlation ID and timestamp to review Entra sign-in logs or open a Microsoft support case.","emailScript":"Hello,\n\nWe reviewed the Microsoft 365 sign-in issue and found that the application could not complete authentication using this device's work or school identity.\n\nWe are validating the device registration and account connection, then we will confirm that OneDrive and File Explorer can access files normally.\n\nPlease let us know if another sign-in message appears during testing.\n\nThank you,\n\nIT Support","faqSteps":"1. Confirm that you can sign in to OneDrive in a web browser.\n2. Restart your computer and install any available Windows or OneDrive updates.\n3. Open Settings > Accounts > Access work or school and confirm that your company account is listed.\n4. Do not disconnect the account unless IT Support directs you to do so.\n5. Send IT Support a screenshot, correlation ID, and the time of any new sign-in error.","notes":"Verification:\n1. Confirm the account signs in successfully within OneDrive.\n2. Confirm OneDrive reports Up to date.\n3. Confirm files open normally through File Explorer.\n4. Confirm AzureAdPrt and DeviceAuthStatus show the expected healthy state.\n5. Confirm no new authentication failure appears at the test timestamp.\n\nThis code is associated with Microsoft desktop authentication and device registration context; do not classify it as a standard OneDrive sync error without supporting evidence.","commands":["dsregcmd /status"],"sourceDocument":"Manually submitted CopyCat fix","platforms":["unknown"],"vendors":["Microsoft 365 Authentication"],"technologies":["657ry","Device Registration","Work or School Account","Microsoft Authentication"],"aliases":["3400335369 / 0xCAAD0009"]},{"id":54039,"title":"0 - The installation completed successfully","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["win","msi","windows","installer","the","installation","completed","successfully","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity","damaged"],"errorCode":"0","eventId":"","severity":"Low","summary":"The installation completed successfully.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"No corrective action is required.","emailScript":"Hello,\n\nWe reviewed the issue related to 0 - The installation completed successfully.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The installation completed successfully.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0","identifiers":["0"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"No corrective action is required.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"Confirm the application is installed, detected, and functional.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: The installation completed successfully.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: Confirm the application is installed, detected, and functional.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["0"]},{"id":54040,"title":"3010 - The installation completed successfully, but a restart is required","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["3010","win","msi","windows","installer","the","installation","completed","successfully","but","restart","required","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions"],"errorCode":"3010","eventId":"","severity":"Low","summary":"The installation completed successfully, but a restart is required.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"Schedule or perform a restart according to organizational policy.","emailScript":"Hello,\n\nWe reviewed the issue related to 3010 - The installation completed successfully, but a restart is required.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The installation completed successfully, but a restart is required.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"3010","identifiers":["3010"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Yes","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"Schedule or perform a restart according to organizational policy.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"Restart the device and confirm the application is installed and detected.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 3010\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: The installation completed successfully, but a restart is required.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: Restart the device and confirm the application is installed and detected.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["3010"]},{"id":54041,"title":"1641 - The installation completed successfully and initiated a restart","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1641","win","msi","windows","installer","the","installation","completed","successfully","and","initiated","restart","operation","fails","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers"],"errorCode":"1641","eventId":"","severity":"Low","summary":"The installation completed successfully and initiated a restart.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"Allow Windows to complete the restart.","emailScript":"Hello,\n\nWe reviewed the issue related to 1641 - The installation completed successfully and initiated a restart.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The installation completed successfully and initiated a restart.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1641","identifiers":["1641"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Yes","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"Allow Windows to complete the restart.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"Confirm the application is installed and the device returned to a healthy\nmanagement state.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1641\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: The installation completed successfully and initiated a restart.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: Confirm the application is installed and the device returned to a healthy\nmanagement state.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1641"]},{"id":54042,"title":"1601 - The Windows Installer service could not be accessed","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1601","win","msi","windows","installer","the","service","could","not","accessed","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","unavailable","registration","problem","corruption","installation","attempted","under","unsupported","context"],"errorCode":"1601","eventId":"","severity":"Critical","summary":"The Windows Installer service could not be accessed.","rootCause":"- Windows Installer service unavailable\n- Service registration problem\n- Windows Installer corruption\n- Installation attempted under an unsupported context","resolution":"1. Check the Windows Installer service.\n2. Review the Application log and installer log.\n3. Restart the service or device if appropriate.\n4. Repair Windows Installer registration only when logs indicate damage.\n5. Retest with verbose MSI logging enabled.","emailScript":"Hello,\n\nWe reviewed the issue related to 1601 - The Windows Installer service could not be accessed.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The Windows Installer service could not be accessed.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1601","identifiers":["1601"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Check the Windows Installer service.\n2. Review the Application log and installer log.\n3. Restart the service or device if appropriate.\n4. Repair Windows Installer registration only when logs indicate damage.\n5. Retest with verbose MSI logging enabled.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1601\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: The Windows Installer service could not be accessed.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1601"]},{"id":54043,"title":"1602 - The installation was canceled by the user or installation process","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1602","win","msi","windows","installer","the","installation","was","canceled","user","process","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","selected","cancel","terminated","timeout","closed"],"errorCode":"1602","eventId":"","severity":"Medium","summary":"The installation was canceled by the user or installation process.","rootCause":"- User selected Cancel\n- Installer was terminated\n- Deployment timeout\n- Application closed the setup process","resolution":"1. Confirm whether the user or automation canceled the installation.\n2. Review the deployment timeout.\n3. Check installer logs.\n4. Retry after correcting the cancellation source.","emailScript":"Hello,\n\nWe reviewed the issue related to 1602 - The installation was canceled by the user or installation process.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The installation was canceled by the user or installation process.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1602","identifiers":["1602"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Confirm whether the user or automation canceled the installation.\n2. Review the deployment timeout.\n3. Check installer logs.\n4. Retry after correcting the cancellation source.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1602\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: The installation was canceled by the user or installation process.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1602"]},{"id":54044,"title":"1603 - A fatal error occurred during installation","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1603","win","msi","windows","installer","fatal","error","occurred","during","installation","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","already","installed","target","folder","encrypted","drive","accessed","substitute","lacks","required","permissions","locked","files"],"errorCode":"1603","eventId":"","severity":"High","summary":"A fatal error occurred during installation.","rootCause":"- Application is already installed\n- Target folder is encrypted\n- Target drive is accessed as a substitute drive\n- SYSTEM lacks required permissions\n- Locked files\n- Custom action failure\n- Pending restart\n- Incorrect installer context\n- Application-specific prerequisite failure","resolution":"1. Generate a verbose MSI log.\n2. Search backward from \"Return value 3\".\n3. Check whether the application is already installed.\n4. Check target-folder permissions for SYSTEM.\n5. Confirm the target folder is not encrypted.\n6. Check for locked files and pending restarts.\n7. Resolve the specific failure found before \"Return value 3\".\n8. Retry the installation.","emailScript":"Hello,\n\nWe reviewed the issue related to 1603 - A fatal error occurred during installation.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A fatal error occurred during installation.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"msiexec /i \"package.msi\" /L*v \"%TEMP%\\PackageInstall.log\"","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1603","identifiers":["1603"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Error 1603 is a generic final result. The actual failure is normally recorded\nearlier in the MSI log.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Generate a verbose MSI log.\n2. Search backward from \"Return value 3\".\n3. Check whether the application is already installed.\n4. Check target-folder permissions for SYSTEM.\n5. Confirm the target folder is not encrypted.\n6. Check for locked files and pending restarts.\n7. Resolve the specific failure found before \"Return value 3\".\n8. Retry the installation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1603\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: A fatal error occurred during installation.\n\nContext: Error 1603 is a generic final result. The actual failure is normally recorded\nearlier in the MSI log.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1603"]},{"id":54045,"title":"1604 - The installation was suspended or left incomplete","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1604","win","msi","windows","installer","the","installation","was","suspended","left","incomplete","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers"],"errorCode":"1604","eventId":"","severity":"Low","summary":"The installation was suspended or left incomplete.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Check for a suspended Windows Installer transaction.\n2. Restart the device if a reboot is pending.\n3. Review MSI logs.\n4. Retry or repair the affected installation.","emailScript":"Hello,\n\nWe reviewed the issue related to 1604 - The installation was suspended or left incomplete.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The installation was suspended or left incomplete.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1604","identifiers":["1604"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Check for a suspended Windows Installer transaction.\n2. Restart the device if a reboot is pending.\n3. Review MSI logs.\n4. Retry or repair the affected installation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1604\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: The installation was suspended or left incomplete.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1604"]},{"id":54046,"title":"1605 - The requested action applies only to a product that is currently installed","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1605","win","msi","windows","installer","the","requested","action","applies","only","product","that","currently","installed","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration"],"errorCode":"1605","eventId":"","severity":"Low","summary":"The requested action applies only to a product that is currently installed.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Confirm the MSI product code.\n2. Check installed applications.\n3. Verify whether the application was removed manually.\n4. Correct the uninstall or repair detection logic.","emailScript":"Hello,\n\nWe reviewed the issue related to 1605 - The requested action applies only to a product that is currently installed.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The requested action applies only to a product that is currently installed.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1605","identifiers":["1605"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Confirm the MSI product code.\n2. Check installed applications.\n3. Verify whether the application was removed manually.\n4. Correct the uninstall or repair detection logic.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1605\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: The requested action applies only to a product that is currently installed.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1605"]},{"id":54047,"title":"1606 - The Windows Installer feature identifier is not registered","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1606","win","msi","windows","installer","the","feature","identifier","not","registered","operation","fails","and","may","produce","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity"],"errorCode":"1606","eventId":"","severity":"Low","summary":"The Windows Installer feature identifier is not registered.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Confirm the package and feature identifiers.\n2. Repair or reinstall the product.\n3. Review package authoring or deployment parameters.","emailScript":"Hello,\n\nWe reviewed the issue related to 1606 - The Windows Installer feature identifier is not registered.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The Windows Installer feature identifier is not registered.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1606","identifiers":["1606"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Confirm the package and feature identifiers.\n2. Repair or reinstall the product.\n3. Review package authoring or deployment parameters.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1606\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: The Windows Installer feature identifier is not registered.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1606"]},{"id":54048,"title":"1607 - The Windows Installer component identifier is not registered","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1607","win","msi","windows","installer","the","component","identifier","not","registered","operation","fails","and","may","produce","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity","damaged"],"errorCode":"1607","eventId":"","severity":"Low","summary":"The Windows Installer component identifier is not registered.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Review MSI logs.\n2. Validate the component identifier.\n3. Repair or reinstall the affected product.","emailScript":"Hello,\n\nWe reviewed the issue related to 1607 - The Windows Installer component identifier is not registered.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The Windows Installer component identifier is not registered.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1607","identifiers":["1607"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Review MSI logs.\n2. Validate the component identifier.\n3. Repair or reinstall the affected product.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1607\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: The Windows Installer component identifier is not registered.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1607"]},{"id":54049,"title":"1608 - An unknown Windows Installer property was referenced","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1608","win","msi","windows","installer","unknown","property","was","referenced","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services"],"errorCode":"1608","eventId":"","severity":"Low","summary":"An unknown Windows Installer property was referenced.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Review command-line properties.\n2. Confirm transform and property names.\n3. Correct deployment parameters.\n4. Retest with verbose logging.","emailScript":"Hello,\n\nWe reviewed the issue related to 1608 - An unknown Windows Installer property was referenced.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: An unknown Windows Installer property was referenced.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1608","identifiers":["1608"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Review command-line properties.\n2. Confirm transform and property names.\n3. Correct deployment parameters.\n4. Retest with verbose logging.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1608\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: An unknown Windows Installer property was referenced.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1608"]},{"id":54050,"title":"1609 - The Windows Installer handle is in an invalid state","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1609","win","msi","windows","installer","the","handle","invalid","state","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity"],"errorCode":"1609","eventId":"","severity":"Medium","summary":"The Windows Installer handle is in an invalid state.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Close conflicting installer processes.\n2. Restart Windows Installer or the device.\n3. Review custom actions and installer logs.\n4. Retry installation.","emailScript":"Hello,\n\nWe reviewed the issue related to 1609 - The Windows Installer handle is in an invalid state.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The Windows Installer handle is in an invalid state.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1609","identifiers":["1609"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Close conflicting installer processes.\n2. Restart Windows Installer or the device.\n3. Review custom actions and installer logs.\n4. Retry installation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1609\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: The Windows Installer handle is in an invalid state.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1609"]},{"id":54051,"title":"1610 - The product configuration data is corrupted","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1610","win","msi","windows","installer","the","product","configuration","data","corrupted","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","dependencies","permissions","drivers","services","connectivity"],"errorCode":"1610","eventId":"","severity":"Critical","summary":"The product configuration data is corrupted.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Attempt an application repair.\n2. Retrieve the original installation source.\n3. Remove the damaged product using an approved cleanup method.\n4. Reinstall the application.","emailScript":"Hello,\n\nWe reviewed the issue related to 1610 - The product configuration data is corrupted.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The product configuration data is corrupted.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1610","identifiers":["1610"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Attempt an application repair.\n2. Retrieve the original installation source.\n3. Remove the damaged product using an approved cleanup method.\n4. Reinstall the application.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1610\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: The product configuration data is corrupted.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1610"]},{"id":54052,"title":"1612 - The installation source is unavailable","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1612","win","msi","windows","installer","the","installation","source","unavailable","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","original","path","network","share","offline","cache","missing","removed","changed"],"errorCode":"1612","eventId":"","severity":"High","summary":"The installation source is unavailable.","rootCause":"- Original MSI path unavailable\n- Network share offline\n- Installer cache missing\n- Application source removed\n- Deployment path changed","resolution":"1. Restore access to the original installation source.\n2. Confirm share and NTFS permissions.\n3. Verify the deployment path.\n4. Repair or reinstall using the correct package.","emailScript":"Hello,\n\nWe reviewed the issue related to 1612 - The installation source is unavailable.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The installation source is unavailable.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1612","identifiers":["1612"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Restore access to the original installation source.\n2. Confirm share and NTFS permissions.\n3. Verify the deployment path.\n4. Repair or reinstall using the correct package.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1612\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: The installation source is unavailable.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1612"]},{"id":54053,"title":"1614 - The product is already uninstalled","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1614","win","msi","windows","installer","the","product","already","uninstalled","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity"],"errorCode":"1614","eventId":"","severity":"Low","summary":"The product is already uninstalled.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"Refresh application inventory and correct stale detection or uninstall logic.","emailScript":"Hello,\n\nWe reviewed the issue related to 1614 - The product is already uninstalled.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The product is already uninstalled.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1614","identifiers":["1614"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"Refresh application inventory and correct stale detection or uninstall logic.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1614\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: The product is already uninstalled.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1614"]},{"id":54054,"title":"1618 - Another Windows Installer transaction is already in progress","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1618","win","msi","windows","installer","another","transaction","already","progress","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services"],"errorCode":"1618","eventId":"","severity":"Low","summary":"Another Windows Installer transaction is already in progress.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Check for active msiexec.exe processes.\n2. Allow the existing installation to finish.\n3. Check for pending Windows Update activity.\n4. Restart the device if the transaction is stuck.\n5. Retry the deployment.","emailScript":"Hello,\n\nWe reviewed the issue related to 1618 - Another Windows Installer transaction is already in progress.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Another Windows Installer transaction is already in progress.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1618","identifiers":["1618"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Check for active msiexec.exe processes.\n2. Allow the existing installation to finish.\n3. Check for pending Windows Update activity.\n4. Restart the device if the transaction is stuck.\n5. Retry the deployment.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1618\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: Another Windows Installer transaction is already in progress.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1618"]},{"id":54055,"title":"1619 - The installation package could not be opened","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1619","win","msi","windows","installer","the","installation","package","could","not","opened","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers"],"errorCode":"1619","eventId":"","severity":"Low","summary":"The installation package could not be opened.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Confirm the package exists.\n2. Verify permissions.\n3. Confirm the download is complete.\n4. Test the package from a local path.\n5. Replace a damaged package.","emailScript":"Hello,\n\nWe reviewed the issue related to 1619 - The installation package could not be opened.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The installation package could not be opened.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1619","identifiers":["1619"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Confirm the package exists.\n2. Verify permissions.\n3. Confirm the download is complete.\n4. Test the package from a local path.\n5. Replace a damaged package.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1619\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: The installation package could not be opened.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1619"]},{"id":54056,"title":"1620 - The installation package is invalid or could not be opened","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1620","win","msi","windows","installer","the","installation","package","invalid","could","not","opened","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions"],"errorCode":"1620","eventId":"","severity":"Medium","summary":"The installation package is invalid or could not be opened.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Verify the MSI file is valid.\n2. Confirm the package came from an approved source.\n3. Compare the file hash.\n4. Download or rebuild the package.","emailScript":"Hello,\n\nWe reviewed the issue related to 1620 - The installation package is invalid or could not be opened.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The installation package is invalid or could not be opened.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1620","identifiers":["1620"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Verify the MSI file is valid.\n2. Confirm the package came from an approved source.\n3. Compare the file hash.\n4. Download or rebuild the package.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1620\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: The installation package is invalid or could not be opened.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1620"]},{"id":54057,"title":"1622 - The Windows Installer log file could not be opened","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1622","win","msi","windows","installer","the","log","file","could","not","opened","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services"],"errorCode":"1622","eventId":"","severity":"Low","summary":"The Windows Installer log file could not be opened.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Verify the log path exists.\n2. Verify write permissions.\n3. Use a local writable directory.\n4. Retry verbose logging.","emailScript":"Hello,\n\nWe reviewed the issue related to 1622 - The Windows Installer log file could not be opened.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The Windows Installer log file could not be opened.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1622","identifiers":["1622"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Verify the log path exists.\n2. Verify write permissions.\n3. Use a local writable directory.\n4. Retry verbose logging.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1622\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: The Windows Installer log file could not be opened.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1622"]},{"id":54058,"title":"1624 - The transform could not be applied","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1624","win","msi","windows","installer","the","transform","could","not","applied","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services"],"errorCode":"1624","eventId":"","severity":"Low","summary":"The transform could not be applied.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Confirm the MST file exists.\n2. Verify the transform matches the MSI version.\n3. Check the TRANSFORMS property.\n4. Rebuild or replace the transform.","emailScript":"Hello,\n\nWe reviewed the issue related to 1624 - The transform could not be applied.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The transform could not be applied.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1624","identifiers":["1624"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Confirm the MST file exists.\n2. Verify the transform matches the MSI version.\n3. Check the TRANSFORMS property.\n4. Rebuild or replace the transform.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1624\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: The transform could not be applied.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1624"]},{"id":54059,"title":"1625 - Installation is forbidden by system policy","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1625","win","msi","windows","installer","installation","forbidden","system","policy","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity"],"errorCode":"1625","eventId":"","severity":"Low","summary":"Installation is forbidden by system policy.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Review AppLocker, Windows Defender Application Control, MDM, Group Policy,\nand endpoint application-control policies.\n2. Verify whether the installer is approved.\n3. Add an authorized policy exception if appropriate.\n4. Do not bypass organizational security controls.","emailScript":"Hello,\n\nWe reviewed the issue related to 1625 - Installation is forbidden by system policy.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Installation is forbidden by system policy.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1625","identifiers":["1625"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Review AppLocker, Windows Defender Application Control, MDM, Group Policy,\nand endpoint application-control policies.\n2. Verify whether the installer is approved.\n3. Add an authorized policy exception if appropriate.\n4. Do not bypass organizational security controls.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1625\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: Installation is forbidden by system policy.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1625"]},{"id":54060,"title":"1628 - The installer contains an invalid or unknown table","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1628","win","msi","windows","installer","the","contains","invalid","unknown","table","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services"],"errorCode":"1628","eventId":"","severity":"Medium","summary":"The installer contains an invalid or unknown table.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Validate the package.\n2. Confirm the MSI is not corrupted.\n3. Obtain a current installer from the vendor.\n4. Escalate to the package developer if package authoring is invalid.","emailScript":"Hello,\n\nWe reviewed the issue related to 1628 - The installer contains an invalid or unknown table.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The installer contains an invalid or unknown table.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1628","identifiers":["1628"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Validate the package.\n2. Confirm the MSI is not corrupted.\n3. Obtain a current installer from the vendor.\n4. Escalate to the package developer if package authoring is invalid.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1628\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: The installer contains an invalid or unknown table.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1628"]},{"id":54061,"title":"1633 - The installation package is not supported on this platform","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1633","win","msi","windows","installer","the","installation","package","not","supported","this","platform","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions"],"errorCode":"1633","eventId":"","severity":"Medium","summary":"The installation package is not supported on this platform.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Confirm OS architecture.\n2. Confirm Windows version and edition.\n3. Check ARM64, x64, and x86 compatibility.\n4. Obtain the correct installer.","emailScript":"Hello,\n\nWe reviewed the issue related to 1633 - The installation package is not supported on this platform.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The installation package is not supported on this platform.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1633","identifiers":["1633"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Confirm OS architecture.\n2. Confirm Windows version and edition.\n3. Check ARM64, x64, and x86 compatibility.\n4. Obtain the correct installer.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1633\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: The installation package is not supported on this platform.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1633"]},{"id":54062,"title":"1635 - The patch package could not be opened","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1635","win","msi","windows","installer","the","patch","package","could","not","opened","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers"],"errorCode":"1635","eventId":"","severity":"Low","summary":"The patch package could not be opened.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Confirm the MSP patch exists.\n2. Verify file integrity and permissions.\n3. Confirm the patch applies to the installed product.\n4. Download a current copy.","emailScript":"Hello,\n\nWe reviewed the issue related to 1635 - The patch package could not be opened.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The patch package could not be opened.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1635","identifiers":["1635"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Confirm the MSP patch exists.\n2. Verify file integrity and permissions.\n3. Confirm the patch applies to the installed product.\n4. Download a current copy.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1635\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: The patch package could not be opened.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1635"]},{"id":54063,"title":"1638 - Another version of the product is already installed","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1638","win","msi","windows","installer","another","version","the","product","already","installed","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers"],"errorCode":"1638","eventId":"","severity":"Low","summary":"Another version of the product is already installed.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Identify the installed version and product code.\n2. Determine whether the new package supports upgrades.\n3. Uninstall the existing version if required and approved.\n4. Correct Intune, RMM, or deployment detection logic.","emailScript":"Hello,\n\nWe reviewed the issue related to 1638 - Another version of the product is already installed.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Another version of the product is already installed.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1638","identifiers":["1638"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Identify the installed version and product code.\n2. Determine whether the new package supports upgrades.\n3. Uninstall the existing version if required and approved.\n4. Correct Intune, RMM, or deployment detection logic.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1638\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: Another version of the product is already installed.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1638"]},{"id":54064,"title":"1642 - The patch does not apply to the installed product","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1642","win","msi","windows","installer","the","patch","does","not","apply","installed","product","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions"],"errorCode":"1642","eventId":"","severity":"Low","summary":"The patch does not apply to the installed product.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Confirm the installed product version.\n2. Confirm product code and patch prerequisites.\n3. Install prerequisite updates.\n4. Use the correct patch.","emailScript":"Hello,\n\nWe reviewed the issue related to 1642 - The patch does not apply to the installed product.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The patch does not apply to the installed product.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1642","identifiers":["1642"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Confirm the installed product version.\n2. Confirm product code and patch prerequisites.\n3. Install prerequisite updates.\n4. Use the correct patch.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1642\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: The patch does not apply to the installed product.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1642"]},{"id":54065,"title":"1643 - The patch is blocked by system policy","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1643","win","msi","windows","installer","the","patch","blocked","system","policy","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity"],"errorCode":"1643","eventId":"","severity":"High","summary":"The patch is blocked by system policy.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Review Windows Installer and security policies.\n2. Verify the patch is approved.\n3. Correct policy through the authorized change process.","emailScript":"Hello,\n\nWe reviewed the issue related to 1643 - The patch is blocked by system policy.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The patch is blocked by system policy.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1643","identifiers":["1643"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Review Windows Installer and security policies.\n2. Verify the patch is approved.\n3. Correct policy through the authorized change process.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1643\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: The patch is blocked by system policy.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1643"]},{"id":54066,"title":"1644 - One or more installer customizations are blocked by policy","category":"Windows","product":"Windows Installer","tags":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"keywords":["1644","win","msi","windows","installer","one","more","customizations","are","blocked","policy","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions"],"errorCode":"1644","eventId":"","severity":"High","summary":"One or more installer customizations are blocked by policy.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Identify the blocked transform or customization.\n2. Review installer policy.\n3. Approve or replace the customization through change control.","emailScript":"Hello,\n\nWe reviewed the issue related to 1644 - One or more installer customizations are blocked by policy.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: One or more installer customizations are blocked by policy.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"1644","identifiers":["1644"],"identifierType":"Windows Installer Return Code","namespace":"WIN-MSI","platform":"Windows","component":"Windows Installer","eventSource":"Windows Installer","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on installer context","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Identify the blocked transform or customization.\n2. Review installer policy.\n3. Approve or replace the customization through change control.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Verbose MSI log; Event Viewer > Application; deployment-platform logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 1644\nNamespace: WIN-MSI\nType: Windows Installer Return Code\nPlatform: Windows\nProduct: Windows Installer\nComponent: Windows Installer\nReview status: Verified\n\nMeaning: One or more installer customizations are blocked by policy.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Verbose MSI log; Event Viewer > Application; deployment-platform logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Installer"],"technologies":["WIN-MSI","Windows Installer Return Code","Windows Installer","Verified"],"aliases":["1644"]},{"id":54067,"title":"0x0000000A - IRQL_NOT_LESS_OR_EQUAL","category":"Windows","product":"Windows Kernel / Bug Check","tags":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"keywords":["0x0000000a","irql","not","less","equal","win","bsod","windows","kernel","mode","driver","accessed","invalid","pageable","memory","elevated","interrupt","request","level","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","defective","incompatible","access","using"],"errorCode":"0x0000000A","eventId":"","severity":"High","summary":"Windows or a kernel-mode driver accessed invalid or pageable memory at an\nelevated interrupt request level.","rootCause":"- Defective or incompatible driver\n- Invalid kernel memory access\n- Driver using pageable memory at the wrong IRQL\n- Memory corruption","resolution":"1. Record all bug-check parameters.\n2. Check recently installed drivers and hardware.\n3. Update Windows, firmware, and approved drivers.\n4. Run memory diagnostics.\n5. Analyze the dump with WinDbg.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x0000000A - IRQL_NOT_LESS_OR_EQUAL.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Windows or a kernel-mode driver accessed invalid or pageable memory at an\nelevated interrupt request level.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x0000000A","identifiers":["0x0000000A","IRQL_NOT_LESS_OR_EQUAL"],"identifierType":"Windows Bug Check","namespace":"WIN-BSOD","platform":"Windows","component":"Windows Kernel","eventSource":"Windows Kernel","symbolicName":"IRQL_NOT_LESS_OR_EQUAL","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Record all bug-check parameters.\n2. Check recently installed drivers and hardware.\n3. Update Windows, firmware, and approved drivers.\n4. Run memory diagnostics.\n5. Analyze the dump with WinDbg.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace hardware or blame a named module from one crash without dump analysis and repeatable evidence.","logsToCheck":"C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x0000000A\nNamespace: WIN-BSOD\nType: Windows Bug Check\nPlatform: Windows\nProduct: Windows Kernel / Bug Check\nComponent: Windows Kernel\nReview status: Verified\n\nMeaning: Windows or a kernel-mode driver accessed invalid or pageable memory at an\nelevated interrupt request level.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Kernel"],"technologies":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"aliases":["0x0000000A","IRQL_NOT_LESS_OR_EQUAL"]},{"id":54068,"title":"0x00000018 - REFERENCE_BY_POINTER","category":"Windows","product":"Windows Kernel / Bug Check","tags":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"keywords":["0x00000018","reference","pointer","win","bsod","windows","kernel","object","count","became","inconsistent","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","defective","driver","lifecycle","issue","memory","corruption"],"errorCode":"0x00000018","eventId":"","severity":"High","summary":"A kernel object reference count became inconsistent.","rootCause":"- Defective driver\n- Kernel object lifecycle issue\n- Memory corruption","resolution":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x00000018 - REFERENCE_BY_POINTER.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A kernel object reference count became inconsistent.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x00000018","identifiers":["0x00000018","REFERENCE_BY_POINTER"],"identifierType":"Windows Bug Check","namespace":"WIN-BSOD","platform":"Windows","component":"Windows Kernel","eventSource":"Windows Kernel","symbolicName":"REFERENCE_BY_POINTER","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace hardware or blame a named module from one crash without dump analysis and repeatable evidence.","logsToCheck":"C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x00000018\nNamespace: WIN-BSOD\nType: Windows Bug Check\nPlatform: Windows\nProduct: Windows Kernel / Bug Check\nComponent: Windows Kernel\nReview status: Verified\n\nMeaning: A kernel object reference count became inconsistent.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Kernel"],"technologies":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"aliases":["0x00000018","REFERENCE_BY_POINTER"]},{"id":54069,"title":"0x0000001A - MEMORY_MANAGEMENT","category":"Windows","product":"Windows Kernel / Bug Check","tags":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"keywords":["0x0000001a","memory","management","win","bsod","windows","kernel","detected","serious","error","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","defective","ram","driver","corruption","storage","paging","file","unstable","firmware","overclocking"],"errorCode":"0x0000001A","eventId":"","severity":"High","summary":"Windows detected a serious memory-management error.","rootCause":"- Defective RAM\n- Driver corruption\n- Storage or paging-file corruption\n- Unstable firmware or overclocking","resolution":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x0000001A - MEMORY_MANAGEMENT.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Windows detected a serious memory-management error.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x0000001A","identifiers":["0x0000001A","MEMORY_MANAGEMENT"],"identifierType":"Windows Bug Check","namespace":"WIN-BSOD","platform":"Windows","component":"Windows Kernel","eventSource":"Windows Kernel","symbolicName":"MEMORY_MANAGEMENT","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace hardware or blame a named module from one crash without dump analysis and repeatable evidence.","logsToCheck":"C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x0000001A\nNamespace: WIN-BSOD\nType: Windows Bug Check\nPlatform: Windows\nProduct: Windows Kernel / Bug Check\nComponent: Windows Kernel\nReview status: Verified\n\nMeaning: Windows detected a serious memory-management error.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Kernel"],"technologies":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"aliases":["0x0000001A","MEMORY_MANAGEMENT"]},{"id":54070,"title":"0x0000001E - KMODE_EXCEPTION_NOT_HANDLED","category":"Windows","product":"Windows Kernel / Bug Check","tags":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"keywords":["0x0000001e","kmode","exception","not","handled","win","bsod","windows","kernel","mode","was","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","incompatible","driver","memory","corruption","firmware","issue","faulting","component"],"errorCode":"0x0000001E","eventId":"","severity":"High","summary":"A kernel-mode exception was not handled.","rootCause":"- Incompatible driver\n- Memory corruption\n- Firmware issue\n- Faulting kernel component","resolution":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x0000001E - KMODE_EXCEPTION_NOT_HANDLED.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A kernel-mode exception was not handled.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x0000001E","identifiers":["0x0000001E","KMODE_EXCEPTION_NOT_HANDLED"],"identifierType":"Windows Bug Check","namespace":"WIN-BSOD","platform":"Windows","component":"Windows Kernel","eventSource":"Windows Kernel","symbolicName":"KMODE_EXCEPTION_NOT_HANDLED","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace hardware or blame a named module from one crash without dump analysis and repeatable evidence.","logsToCheck":"C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x0000001E\nNamespace: WIN-BSOD\nType: Windows Bug Check\nPlatform: Windows\nProduct: Windows Kernel / Bug Check\nComponent: Windows Kernel\nReview status: Verified\n\nMeaning: A kernel-mode exception was not handled.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Kernel"],"technologies":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"aliases":["0x0000001E","KMODE_EXCEPTION_NOT_HANDLED"]},{"id":54071,"title":"0x00000024 - NTFS_FILE_SYSTEM","category":"Windows","product":"Windows Kernel / Bug Check","tags":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"keywords":["0x00000024","ntfs","file","system","win","bsod","windows","kernel","failure","occurred","the","driver","its","supporting","storage","path","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","crash","corruption","filter","backup","antivirus","cabling","controller","issue"],"errorCode":"0x00000024","eventId":"","severity":"High","summary":"A failure occurred in the NTFS file-system driver or its supporting storage\npath.","rootCause":"- File-system corruption\n- Storage failure\n- Filter driver\n- Backup or antivirus driver\n- Cabling or controller issue","resolution":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x00000024 - NTFS_FILE_SYSTEM.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A failure occurred in the NTFS file-system driver or its supporting storage\npath.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x00000024","identifiers":["0x00000024","NTFS_FILE_SYSTEM"],"identifierType":"Windows Bug Check","namespace":"WIN-BSOD","platform":"Windows","component":"Windows Kernel","eventSource":"Windows Kernel","symbolicName":"NTFS_FILE_SYSTEM","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace hardware or blame a named module from one crash without dump analysis and repeatable evidence.","logsToCheck":"C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x00000024\nNamespace: WIN-BSOD\nType: Windows Bug Check\nPlatform: Windows\nProduct: Windows Kernel / Bug Check\nComponent: Windows Kernel\nReview status: Verified\n\nMeaning: A failure occurred in the NTFS file-system driver or its supporting storage\npath.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Kernel"],"technologies":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"aliases":["0x00000024","NTFS_FILE_SYSTEM"]},{"id":54072,"title":"0x0000003B - SYSTEM_SERVICE_EXCEPTION","category":"Windows","product":"Windows Kernel / Bug Check","tags":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"keywords":["0x0000003b","system","service","exception","win","bsod","windows","kernel","occurred","while","was","transitioning","from","non","privileged","code","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","crash","driver","defect","memory","corruption","access","violation","security","graphics"],"errorCode":"0x0000003B","eventId":"","severity":"High","summary":"An exception occurred while Windows was transitioning from non-privileged\ncode to privileged system code.","rootCause":"- Driver defect\n- Memory corruption\n- Access violation\n- Security or graphics driver","resolution":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x0000003B - SYSTEM_SERVICE_EXCEPTION.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: An exception occurred while Windows was transitioning from non-privileged\ncode to privileged system code.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x0000003B","identifiers":["0x0000003B","SYSTEM_SERVICE_EXCEPTION"],"identifierType":"Windows Bug Check","namespace":"WIN-BSOD","platform":"Windows","component":"Windows Kernel","eventSource":"Windows Kernel","symbolicName":"SYSTEM_SERVICE_EXCEPTION","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace hardware or blame a named module from one crash without dump analysis and repeatable evidence.","logsToCheck":"C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x0000003B\nNamespace: WIN-BSOD\nType: Windows Bug Check\nPlatform: Windows\nProduct: Windows Kernel / Bug Check\nComponent: Windows Kernel\nReview status: Verified\n\nMeaning: An exception occurred while Windows was transitioning from non-privileged\ncode to privileged system code.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Kernel"],"technologies":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"aliases":["0x0000003B","SYSTEM_SERVICE_EXCEPTION"]},{"id":54073,"title":"0x00000050 - PAGE_FAULT_IN_NONPAGED_AREA","category":"Windows","product":"Windows Kernel / Bug Check","tags":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"keywords":["0x00000050","page","fault","nonpaged","area","win","bsod","windows","kernel","attempted","access","invalid","memory","that","should","have","remained","available","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","defective","ram","driver","defect","antivirus"],"errorCode":"0x00000050","eventId":"","severity":"High","summary":"Windows attempted to access invalid memory that should have remained\navailable.","rootCause":"- Defective RAM\n- Driver defect\n- Antivirus filter driver\n- File-system corruption\n- Storage failure","resolution":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x00000050 - PAGE_FAULT_IN_NONPAGED_AREA.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Windows attempted to access invalid memory that should have remained\navailable.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x00000050","identifiers":["0x00000050","PAGE_FAULT_IN_NONPAGED_AREA"],"identifierType":"Windows Bug Check","namespace":"WIN-BSOD","platform":"Windows","component":"Windows Kernel","eventSource":"Windows Kernel","symbolicName":"PAGE_FAULT_IN_NONPAGED_AREA","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace hardware or blame a named module from one crash without dump analysis and repeatable evidence.","logsToCheck":"C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x00000050\nNamespace: WIN-BSOD\nType: Windows Bug Check\nPlatform: Windows\nProduct: Windows Kernel / Bug Check\nComponent: Windows Kernel\nReview status: Verified\n\nMeaning: Windows attempted to access invalid memory that should have remained\navailable.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Kernel"],"technologies":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"aliases":["0x00000050","PAGE_FAULT_IN_NONPAGED_AREA"]},{"id":54074,"title":"0x0000007A - KERNEL_DATA_INPAGE_ERROR","category":"Windows","product":"Windows Kernel / Bug Check","tags":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"keywords":["0x0000007a","kernel","data","inpage","error","win","bsod","windows","could","not","read","required","from","the","paging","file","storage","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","failing","controller","issue","cabling","corruption","insufficient","connectivity"],"errorCode":"0x0000007A","eventId":"","severity":"High","summary":"Windows could not read required kernel data from the paging file or storage.","rootCause":"- Failing storage\n- Storage-controller issue\n- Cabling\n- File-system corruption\n- Insufficient storage connectivity\n- Memory issue","resolution":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x0000007A - KERNEL_DATA_INPAGE_ERROR.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Windows could not read required kernel data from the paging file or storage.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x0000007A","identifiers":["0x0000007A","KERNEL_DATA_INPAGE_ERROR"],"identifierType":"Windows Bug Check","namespace":"WIN-BSOD","platform":"Windows","component":"Windows Kernel","eventSource":"Windows Kernel","symbolicName":"KERNEL_DATA_INPAGE_ERROR","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace hardware or blame a named module from one crash without dump analysis and repeatable evidence.","logsToCheck":"C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x0000007A\nNamespace: WIN-BSOD\nType: Windows Bug Check\nPlatform: Windows\nProduct: Windows Kernel / Bug Check\nComponent: Windows Kernel\nReview status: Verified\n\nMeaning: Windows could not read required kernel data from the paging file or storage.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Kernel"],"technologies":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"aliases":["0x0000007A","KERNEL_DATA_INPAGE_ERROR"]},{"id":54075,"title":"0x0000007B - INACCESSIBLE_BOOT_DEVICE","category":"Windows","product":"Windows Kernel / Bug Check","tags":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"keywords":["0x0000007b","inaccessible","boot","device","win","bsod","windows","kernel","lost","access","the","system","storage","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","crash","controller","mode","changed","missing","driver","volume","corruption","failed","disk","broken","configuration"],"errorCode":"0x0000007B","eventId":"","severity":"High","summary":"Windows lost access to the system or boot storage device.","rootCause":"- Storage controller mode changed\n- Missing storage driver\n- Boot-volume corruption\n- Failed disk\n- Broken boot configuration","resolution":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x0000007B - INACCESSIBLE_BOOT_DEVICE.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Windows lost access to the system or boot storage device.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x0000007B","identifiers":["0x0000007B","INACCESSIBLE_BOOT_DEVICE"],"identifierType":"Windows Bug Check","namespace":"WIN-BSOD","platform":"Windows","component":"Windows Kernel","eventSource":"Windows Kernel","symbolicName":"INACCESSIBLE_BOOT_DEVICE","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace hardware or blame a named module from one crash without dump analysis and repeatable evidence.","logsToCheck":"C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x0000007B\nNamespace: WIN-BSOD\nType: Windows Bug Check\nPlatform: Windows\nProduct: Windows Kernel / Bug Check\nComponent: Windows Kernel\nReview status: Verified\n\nMeaning: Windows lost access to the system or boot storage device.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Kernel"],"technologies":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"aliases":["0x0000007B","INACCESSIBLE_BOOT_DEVICE"]},{"id":54076,"title":"0x0000007E - SYSTEM_THREAD_EXCEPTION_NOT_HANDLED","category":"Windows","product":"Windows Kernel / Bug Check","tags":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"keywords":["0x0000007e","system","thread","exception","not","handled","win","bsod","windows","kernel","generated","that","did","handle","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","crash","driver","issue","firmware","memory","corruption"],"errorCode":"0x0000007E","eventId":"","severity":"High","summary":"A system thread generated an exception that Windows did not handle.","rootCause":"- Driver issue\n- Firmware issue\n- Memory corruption","resolution":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x0000007E - SYSTEM_THREAD_EXCEPTION_NOT_HANDLED.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A system thread generated an exception that Windows did not handle.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x0000007E","identifiers":["0x0000007E","SYSTEM_THREAD_EXCEPTION_NOT_HANDLED"],"identifierType":"Windows Bug Check","namespace":"WIN-BSOD","platform":"Windows","component":"Windows Kernel","eventSource":"Windows Kernel","symbolicName":"SYSTEM_THREAD_EXCEPTION_NOT_HANDLED","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace hardware or blame a named module from one crash without dump analysis and repeatable evidence.","logsToCheck":"C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x0000007E\nNamespace: WIN-BSOD\nType: Windows Bug Check\nPlatform: Windows\nProduct: Windows Kernel / Bug Check\nComponent: Windows Kernel\nReview status: Verified\n\nMeaning: A system thread generated an exception that Windows did not handle.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Kernel"],"technologies":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"aliases":["0x0000007E","SYSTEM_THREAD_EXCEPTION_NOT_HANDLED"]},{"id":54077,"title":"0x0000009C - MACHINE_CHECK_EXCEPTION","category":"Windows","product":"Windows Kernel / Bug Check","tags":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"keywords":["0x0000009c","machine","check","exception","win","bsod","windows","kernel","the","processor","reported","hardware","level","failure","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","cpu","motherboard","power","cooling","firmware","memory"],"errorCode":"0x0000009C","eventId":"","severity":"High","summary":"The processor reported a hardware-level machine-check failure.","rootCause":"- CPU\n- Motherboard\n- Power\n- Cooling\n- Firmware\n- Memory","resolution":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x0000009C - MACHINE_CHECK_EXCEPTION.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The processor reported a hardware-level machine-check failure.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x0000009C","identifiers":["0x0000009C","MACHINE_CHECK_EXCEPTION"],"identifierType":"Windows Bug Check","namespace":"WIN-BSOD","platform":"Windows","component":"Windows Kernel","eventSource":"Windows Kernel","symbolicName":"MACHINE_CHECK_EXCEPTION","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace hardware or blame a named module from one crash without dump analysis and repeatable evidence.","logsToCheck":"C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x0000009C\nNamespace: WIN-BSOD\nType: Windows Bug Check\nPlatform: Windows\nProduct: Windows Kernel / Bug Check\nComponent: Windows Kernel\nReview status: Verified\n\nMeaning: The processor reported a hardware-level machine-check failure.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Kernel"],"technologies":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"aliases":["0x0000009C","MACHINE_CHECK_EXCEPTION"]},{"id":54078,"title":"0x0000009F - DRIVER_POWER_STATE_FAILURE","category":"Windows","product":"Windows Kernel / Bug Check","tags":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"keywords":["0x0000009f","driver","power","state","failure","win","bsod","windows","kernel","failed","complete","transition","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","sleep","wake","usb","device","network","adapter","storage","docking","station","firmware"],"errorCode":"0x0000009F","eventId":"","severity":"High","summary":"A driver failed to complete a power-state transition.","rootCause":"- Sleep or wake driver\n- USB device\n- Network adapter\n- Storage driver\n- Docking station\n- Firmware","resolution":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x0000009F - DRIVER_POWER_STATE_FAILURE.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A driver failed to complete a power-state transition.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x0000009F","identifiers":["0x0000009F","DRIVER_POWER_STATE_FAILURE"],"identifierType":"Windows Bug Check","namespace":"WIN-BSOD","platform":"Windows","component":"Windows Kernel","eventSource":"Windows Kernel","symbolicName":"DRIVER_POWER_STATE_FAILURE","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace hardware or blame a named module from one crash without dump analysis and repeatable evidence.","logsToCheck":"C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x0000009F\nNamespace: WIN-BSOD\nType: Windows Bug Check\nPlatform: Windows\nProduct: Windows Kernel / Bug Check\nComponent: Windows Kernel\nReview status: Verified\n\nMeaning: A driver failed to complete a power-state transition.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Kernel"],"technologies":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"aliases":["0x0000009F","DRIVER_POWER_STATE_FAILURE"]},{"id":54079,"title":"0x000000D1 - DRIVER_IRQL_NOT_LESS_OR_EQUAL","category":"Windows","product":"Windows Kernel / Bug Check","tags":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"keywords":["0x000000d1","driver","irql","not","less","equal","win","bsod","windows","kernel","accessed","invalid","pageable","memory","elevated","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","defective","network","storage","security"],"errorCode":"0x000000D1","eventId":"","severity":"High","summary":"A driver accessed invalid or pageable memory at an elevated IRQL.","rootCause":"- Defective driver\n- Network driver\n- Storage driver\n- Security driver","resolution":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x000000D1 - DRIVER_IRQL_NOT_LESS_OR_EQUAL.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A driver accessed invalid or pageable memory at an elevated IRQL.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x000000D1","identifiers":["0x000000D1","DRIVER_IRQL_NOT_LESS_OR_EQUAL"],"identifierType":"Windows Bug Check","namespace":"WIN-BSOD","platform":"Windows","component":"Windows Kernel","eventSource":"Windows Kernel","symbolicName":"DRIVER_IRQL_NOT_LESS_OR_EQUAL","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace hardware or blame a named module from one crash without dump analysis and repeatable evidence.","logsToCheck":"C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x000000D1\nNamespace: WIN-BSOD\nType: Windows Bug Check\nPlatform: Windows\nProduct: Windows Kernel / Bug Check\nComponent: Windows Kernel\nReview status: Verified\n\nMeaning: A driver accessed invalid or pageable memory at an elevated IRQL.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Kernel"],"technologies":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"aliases":["0x000000D1","DRIVER_IRQL_NOT_LESS_OR_EQUAL"]},{"id":54080,"title":"0x000000EF - CRITICAL_PROCESS_DIED","category":"Windows","product":"Windows Kernel / Bug Check","tags":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"keywords":["0x000000ef","critical","process","died","win","bsod","windows","kernel","terminated","unexpectedly","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","file","corruption","storage","failure","update","security","software","memory"],"errorCode":"0x000000EF","eventId":"","severity":"High","summary":"A critical Windows process terminated unexpectedly.","rootCause":"- System-file corruption\n- Storage failure\n- Update failure\n- Security software\n- Memory corruption","resolution":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x000000EF - CRITICAL_PROCESS_DIED.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A critical Windows process terminated unexpectedly.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x000000EF","identifiers":["0x000000EF","CRITICAL_PROCESS_DIED"],"identifierType":"Windows Bug Check","namespace":"WIN-BSOD","platform":"Windows","component":"Windows Kernel","eventSource":"Windows Kernel","symbolicName":"CRITICAL_PROCESS_DIED","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace hardware or blame a named module from one crash without dump analysis and repeatable evidence.","logsToCheck":"C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x000000EF\nNamespace: WIN-BSOD\nType: Windows Bug Check\nPlatform: Windows\nProduct: Windows Kernel / Bug Check\nComponent: Windows Kernel\nReview status: Verified\n\nMeaning: A critical Windows process terminated unexpectedly.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Kernel"],"technologies":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"aliases":["0x000000EF","CRITICAL_PROCESS_DIED"]},{"id":54081,"title":"0x00000101 - CLOCK_WATCHDOG_TIMEOUT","category":"Windows","product":"Windows Kernel / Bug Check","tags":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"keywords":["0x00000101","clock","watchdog","timeout","win","bsod","windows","kernel","processor","core","did","not","receive","expected","interrupt","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","cpu","instability","firmware","cooling","power","overclocking","motherboard"],"errorCode":"0x00000101","eventId":"","severity":"High","summary":"A processor core did not receive an expected clock interrupt.","rootCause":"- CPU instability\n- Firmware\n- Cooling\n- Power\n- Overclocking\n- Motherboard","resolution":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x00000101 - CLOCK_WATCHDOG_TIMEOUT.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A processor core did not receive an expected clock interrupt.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x00000101","identifiers":["0x00000101","CLOCK_WATCHDOG_TIMEOUT"],"identifierType":"Windows Bug Check","namespace":"WIN-BSOD","platform":"Windows","component":"Windows Kernel","eventSource":"Windows Kernel","symbolicName":"CLOCK_WATCHDOG_TIMEOUT","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace hardware or blame a named module from one crash without dump analysis and repeatable evidence.","logsToCheck":"C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x00000101\nNamespace: WIN-BSOD\nType: Windows Bug Check\nPlatform: Windows\nProduct: Windows Kernel / Bug Check\nComponent: Windows Kernel\nReview status: Verified\n\nMeaning: A processor core did not receive an expected clock interrupt.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Kernel"],"technologies":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"aliases":["0x00000101","CLOCK_WATCHDOG_TIMEOUT"]},{"id":54082,"title":"0x00000109 - CRITICAL_STRUCTURE_CORRUPTION","category":"Windows","product":"Windows Kernel / Bug Check","tags":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"keywords":["0x00000109","critical","structure","corruption","win","bsod","windows","kernel","detected","code","data","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","driver","defect","memory","security","software","hardware","instability"],"errorCode":"0x00000109","eventId":"","severity":"High","summary":"Windows detected corruption of critical kernel code or data.","rootCause":"- Driver defect\n- Memory corruption\n- Security software\n- Hardware instability","resolution":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x00000109 - CRITICAL_STRUCTURE_CORRUPTION.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Windows detected corruption of critical kernel code or data.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x00000109","identifiers":["0x00000109","CRITICAL_STRUCTURE_CORRUPTION"],"identifierType":"Windows Bug Check","namespace":"WIN-BSOD","platform":"Windows","component":"Windows Kernel","eventSource":"Windows Kernel","symbolicName":"CRITICAL_STRUCTURE_CORRUPTION","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace hardware or blame a named module from one crash without dump analysis and repeatable evidence.","logsToCheck":"C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x00000109\nNamespace: WIN-BSOD\nType: Windows Bug Check\nPlatform: Windows\nProduct: Windows Kernel / Bug Check\nComponent: Windows Kernel\nReview status: Verified\n\nMeaning: Windows detected corruption of critical kernel code or data.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Kernel"],"technologies":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"aliases":["0x00000109","CRITICAL_STRUCTURE_CORRUPTION"]},{"id":54083,"title":"0x00000116 - VIDEO_TDR_FAILURE","category":"Windows","product":"Windows Kernel / Bug Check","tags":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"keywords":["0x00000116","video","tdr","failure","win","bsod","windows","kernel","the","graphics","driver","gpu","failed","recover","within","allowed","timeout","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","thermal","issue","power","firmware","hardware","acceleration"],"errorCode":"0x00000116","eventId":"","severity":"High","summary":"The graphics driver or GPU failed to recover within the allowed timeout.","rootCause":"- Graphics driver\n- GPU\n- Thermal issue\n- Power issue\n- Firmware\n- Hardware acceleration","resolution":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x00000116 - VIDEO_TDR_FAILURE.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The graphics driver or GPU failed to recover within the allowed timeout.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x00000116","identifiers":["0x00000116","VIDEO_TDR_FAILURE"],"identifierType":"Windows Bug Check","namespace":"WIN-BSOD","platform":"Windows","component":"Windows Kernel","eventSource":"Windows Kernel","symbolicName":"VIDEO_TDR_FAILURE","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace hardware or blame a named module from one crash without dump analysis and repeatable evidence.","logsToCheck":"C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x00000116\nNamespace: WIN-BSOD\nType: Windows Bug Check\nPlatform: Windows\nProduct: Windows Kernel / Bug Check\nComponent: Windows Kernel\nReview status: Verified\n\nMeaning: The graphics driver or GPU failed to recover within the allowed timeout.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Kernel"],"technologies":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"aliases":["0x00000116","VIDEO_TDR_FAILURE"]},{"id":54084,"title":"0x00000124 - WHEA_UNCORRECTABLE_ERROR","category":"Windows","product":"Windows Kernel / Bug Check","tags":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"keywords":["0x00000124","whea","uncorrectable","error","win","bsod","windows","kernel","hardware","architecture","reported","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","cpu","ram","pcie","device","storage","motherboard","power","cooling","firmware"],"errorCode":"0x00000124","eventId":"","severity":"High","summary":"Windows Hardware Error Architecture reported an uncorrectable hardware error.","rootCause":"- CPU\n- RAM\n- PCIe device\n- Storage\n- Motherboard\n- Power\n- Cooling\n- Firmware","resolution":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x00000124 - WHEA_UNCORRECTABLE_ERROR.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Windows Hardware Error Architecture reported an uncorrectable hardware error.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x00000124","identifiers":["0x00000124","WHEA_UNCORRECTABLE_ERROR"],"identifierType":"Windows Bug Check","namespace":"WIN-BSOD","platform":"Windows","component":"Windows Kernel","eventSource":"Windows Kernel","symbolicName":"WHEA_UNCORRECTABLE_ERROR","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace hardware or blame a named module from one crash without dump analysis and repeatable evidence.","logsToCheck":"C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x00000124\nNamespace: WIN-BSOD\nType: Windows Bug Check\nPlatform: Windows\nProduct: Windows Kernel / Bug Check\nComponent: Windows Kernel\nReview status: Verified\n\nMeaning: Windows Hardware Error Architecture reported an uncorrectable hardware error.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Kernel"],"technologies":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"aliases":["0x00000124","WHEA_UNCORRECTABLE_ERROR"]},{"id":54085,"title":"0x00000133 - DPC_WATCHDOG_VIOLATION","category":"Windows","product":"Windows Kernel / Bug Check","tags":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"keywords":["0x00000133","dpc","watchdog","violation","win","bsod","windows","kernel","deferred","procedure","call","interrupt","routine","exceeded","the","allowed","time","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","storage","driver","firmware","device","controller","issue"],"errorCode":"0x00000133","eventId":"","severity":"High","summary":"A deferred procedure call or interrupt routine exceeded the allowed time.","rootCause":"- Storage driver\n- Firmware\n- Device driver\n- Controller issue","resolution":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x00000133 - DPC_WATCHDOG_VIOLATION.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A deferred procedure call or interrupt routine exceeded the allowed time.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x00000133","identifiers":["0x00000133","DPC_WATCHDOG_VIOLATION"],"identifierType":"Windows Bug Check","namespace":"WIN-BSOD","platform":"Windows","component":"Windows Kernel","eventSource":"Windows Kernel","symbolicName":"DPC_WATCHDOG_VIOLATION","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace hardware or blame a named module from one crash without dump analysis and repeatable evidence.","logsToCheck":"C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x00000133\nNamespace: WIN-BSOD\nType: Windows Bug Check\nPlatform: Windows\nProduct: Windows Kernel / Bug Check\nComponent: Windows Kernel\nReview status: Verified\n\nMeaning: A deferred procedure call or interrupt routine exceeded the allowed time.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Kernel"],"technologies":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"aliases":["0x00000133","DPC_WATCHDOG_VIOLATION"]},{"id":54086,"title":"0x00000139 - KERNEL_SECURITY_CHECK_FAILURE","category":"Windows","product":"Windows Kernel / Bug Check","tags":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"keywords":["0x00000139","kernel","security","check","failure","win","bsod","windows","detected","corruption","critical","data","structure","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","driver","defect","memory","stack","software"],"errorCode":"0x00000139","eventId":"","severity":"High","summary":"Windows detected corruption of a critical kernel data structure.","rootCause":"- Driver defect\n- Memory corruption\n- Stack corruption\n- Security software","resolution":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x00000139 - KERNEL_SECURITY_CHECK_FAILURE.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Windows detected corruption of a critical kernel data structure.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x00000139","identifiers":["0x00000139","KERNEL_SECURITY_CHECK_FAILURE"],"identifierType":"Windows Bug Check","namespace":"WIN-BSOD","platform":"Windows","component":"Windows Kernel","eventSource":"Windows Kernel","symbolicName":"KERNEL_SECURITY_CHECK_FAILURE","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace hardware or blame a named module from one crash without dump analysis and repeatable evidence.","logsToCheck":"C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x00000139\nNamespace: WIN-BSOD\nType: Windows Bug Check\nPlatform: Windows\nProduct: Windows Kernel / Bug Check\nComponent: Windows Kernel\nReview status: Verified\n\nMeaning: Windows detected corruption of a critical kernel data structure.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Kernel"],"technologies":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"aliases":["0x00000139","KERNEL_SECURITY_CHECK_FAILURE"]},{"id":54087,"title":"0x00000154 - UNEXPECTED_STORE_EXCEPTION","category":"Windows","product":"Windows Kernel / Bug Check","tags":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"keywords":["0x00000154","unexpected","store","exception","win","bsod","windows","kernel","the","memory","encountered","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","storage","failure","driver","file","corruption","issue"],"errorCode":"0x00000154","eventId":"","severity":"High","summary":"The Windows memory store encountered an unexpected exception.","rootCause":"- Storage failure\n- Storage driver\n- File-system corruption\n- Memory issue","resolution":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x00000154 - UNEXPECTED_STORE_EXCEPTION.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The Windows memory store encountered an unexpected exception.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x00000154","identifiers":["0x00000154","UNEXPECTED_STORE_EXCEPTION"],"identifierType":"Windows Bug Check","namespace":"WIN-BSOD","platform":"Windows","component":"Windows Kernel","eventSource":"Windows Kernel","symbolicName":"UNEXPECTED_STORE_EXCEPTION","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Record the stop code, all parameters, and recent changes.\n2. Collect the dump and Event ID 1001.\n3. Update approved drivers and firmware only after evidence review.\n4. Run appropriate hardware diagnostics.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace hardware or blame a named module from one crash without dump analysis and repeatable evidence.","logsToCheck":"C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x00000154\nNamespace: WIN-BSOD\nType: Windows Bug Check\nPlatform: Windows\nProduct: Windows Kernel / Bug Check\nComponent: Windows Kernel\nReview status: Verified\n\nMeaning: The Windows memory store encountered an unexpected exception.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: C:\\Windows\\Minidump; C:\\Windows\\MEMORY.DMP; System Event ID 1001; Reliability Monitor\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Kernel"],"technologies":["WIN-BSOD","Windows Bug Check","Windows Kernel","Verified"],"aliases":["0x00000154","UNEXPECTED_STORE_EXCEPTION"]},{"id":54088,"title":"0xC0000001 - A required device, driver, or system component failed during startup","category":"Windows","product":"Windows Boot / Recovery","tags":["WIN-BOOT","Windows Boot Error","Windows Boot","Verified"],"keywords":["0xc0000001","win","boot","windows","required","device","driver","system","component","failed","during","startup","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","crash","exact","cause","depends","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers"],"errorCode":"0xC0000001","eventId":"","severity":"High","summary":"A required device, driver, or system component failed during startup.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC0000001 - A required device, driver, or system component failed during startup.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A required device, driver, or system component failed during startup.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC0000001","identifiers":["0xC0000001"],"identifierType":"Windows Boot Error","namespace":"WIN-BOOT","platform":"Windows","component":"Windows Boot","eventSource":"Windows Boot","symbolicName":"","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not rewrite boot configuration or disk structures before collecting recovery information and confirming the correct Windows volume.","logsToCheck":"BCD configuration; SrtTrail.txt; setup and servicing logs; System log","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC0000001\nNamespace: WIN-BOOT\nType: Windows Boot Error\nPlatform: Windows\nProduct: Windows Boot / Recovery\nComponent: Windows Boot\nReview status: Verified\n\nMeaning: A required device, driver, or system component failed during startup.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: BCD configuration; SrtTrail.txt; setup and servicing logs; System log\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Boot"],"technologies":["WIN-BOOT","Windows Boot Error","Windows Boot","Verified"],"aliases":["0xC0000001"]},{"id":54089,"title":"0xC000000E - A required boot device is inaccessible, disconnected, or incorrectly\nreferenced","category":"Windows","product":"Windows Boot / Recovery","tags":["WIN-BOOT","Windows Boot Error","Windows Boot","Verified"],"keywords":["0xc000000e","win","boot","windows","required","device","inaccessible","disconnected","incorrectly","referenced","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers"],"errorCode":"0xC000000E","eventId":"","severity":"High","summary":"A required boot device is inaccessible, disconnected, or incorrectly\nreferenced.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC000000E - A required boot device is inaccessible, disconnected, or incorrectly\nreferenced.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A required boot device is inaccessible, disconnected, or incorrectly\nreferenced.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC000000E","identifiers":["0xC000000E"],"identifierType":"Windows Boot Error","namespace":"WIN-BOOT","platform":"Windows","component":"Windows Boot","eventSource":"Windows Boot","symbolicName":"","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not rewrite boot configuration or disk structures before collecting recovery information and confirming the correct Windows volume.","logsToCheck":"BCD configuration; SrtTrail.txt; setup and servicing logs; System log","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC000000E\nNamespace: WIN-BOOT\nType: Windows Boot Error\nPlatform: Windows\nProduct: Windows Boot / Recovery\nComponent: Windows Boot\nReview status: Verified\n\nMeaning: A required boot device is inaccessible, disconnected, or incorrectly\nreferenced.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: BCD configuration; SrtTrail.txt; setup and servicing logs; System log\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Boot"],"technologies":["WIN-BOOT","Windows Boot Error","Windows Boot","Verified"],"aliases":["0xC000000E"]},{"id":54090,"title":"0xC0000098 - Boot Configuration Data does not contain valid operating-system information","category":"Windows","product":"Windows Boot / Recovery","tags":["WIN-BOOT","Windows Boot Error","Windows Boot","Verified"],"keywords":["0xc0000098","win","boot","windows","configuration","data","does","not","contain","valid","operating","system","information","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","dependencies","permissions"],"errorCode":"0xC0000098","eventId":"","severity":"High","summary":"Boot Configuration Data does not contain valid operating-system information.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC0000098 - Boot Configuration Data does not contain valid operating-system information.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Boot Configuration Data does not contain valid operating-system information.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC0000098","identifiers":["0xC0000098"],"identifierType":"Windows Boot Error","namespace":"WIN-BOOT","platform":"Windows","component":"Windows Boot","eventSource":"Windows Boot","symbolicName":"","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not rewrite boot configuration or disk structures before collecting recovery information and confirming the correct Windows volume.","logsToCheck":"BCD configuration; SrtTrail.txt; setup and servicing logs; System log","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC0000098\nNamespace: WIN-BOOT\nType: Windows Boot Error\nPlatform: Windows\nProduct: Windows Boot / Recovery\nComponent: Windows Boot\nReview status: Verified\n\nMeaning: Boot Configuration Data does not contain valid operating-system information.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: BCD configuration; SrtTrail.txt; setup and servicing logs; System log\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Boot"],"technologies":["WIN-BOOT","Windows Boot Error","Windows Boot","Verified"],"aliases":["0xC0000098"]},{"id":54091,"title":"0xC000014C - Boot Configuration Data is missing or corrupted","category":"Windows","product":"Windows Boot / Recovery","tags":["WIN-BOOT","Windows Boot Error","Windows Boot","Verified"],"keywords":["0xc000014c","win","boot","windows","configuration","data","missing","corrupted","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","dependencies","permissions","drivers","services","connectivity","damaged"],"errorCode":"0xC000014C","eventId":"","severity":"High","summary":"Boot Configuration Data is missing or corrupted.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC000014C - Boot Configuration Data is missing or corrupted.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Boot Configuration Data is missing or corrupted.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC000014C","identifiers":["0xC000014C"],"identifierType":"Windows Boot Error","namespace":"WIN-BOOT","platform":"Windows","component":"Windows Boot","eventSource":"Windows Boot","symbolicName":"","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not rewrite boot configuration or disk structures before collecting recovery information and confirming the correct Windows volume.","logsToCheck":"BCD configuration; SrtTrail.txt; setup and servicing logs; System log","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC000014C\nNamespace: WIN-BOOT\nType: Windows Boot Error\nPlatform: Windows\nProduct: Windows Boot / Recovery\nComponent: Windows Boot\nReview status: Verified\n\nMeaning: Boot Configuration Data is missing or corrupted.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: BCD configuration; SrtTrail.txt; setup and servicing logs; System log\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Boot"],"technologies":["WIN-BOOT","Windows Boot Error","Windows Boot","Verified"],"aliases":["0xC000014C"]},{"id":54092,"title":"0xC000021A - A critical Windows system process terminated","category":"Windows","product":"Windows Boot / Recovery","tags":["WIN-BOOT","Windows Boot Error","Windows Boot","Verified"],"keywords":["0xc000021a","win","boot","windows","critical","system","process","terminated","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity","damaged"],"errorCode":"0xC000021A","eventId":"","severity":"High","summary":"A critical Windows system process terminated.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC000021A - A critical Windows system process terminated.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A critical Windows system process terminated.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC000021A","identifiers":["0xC000021A"],"identifierType":"Windows Boot Error","namespace":"WIN-BOOT","platform":"Windows","component":"Windows Boot","eventSource":"Windows Boot","symbolicName":"","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not rewrite boot configuration or disk structures before collecting recovery information and confirming the correct Windows volume.","logsToCheck":"BCD configuration; SrtTrail.txt; setup and servicing logs; System log","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC000021A\nNamespace: WIN-BOOT\nType: Windows Boot Error\nPlatform: Windows\nProduct: Windows Boot / Recovery\nComponent: Windows Boot\nReview status: Verified\n\nMeaning: A critical Windows system process terminated.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: BCD configuration; SrtTrail.txt; setup and servicing logs; System log\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Boot"],"technologies":["WIN-BOOT","Windows Boot Error","Windows Boot","Verified"],"aliases":["0xC000021A"]},{"id":54093,"title":"0xC0000221 - A driver or system DLL failed integrity validation or could not be loaded","category":"Windows","product":"Windows Boot / Recovery","tags":["WIN-BOOT","Windows Boot Error","Windows Boot","Verified"],"keywords":["0xc0000221","win","boot","windows","driver","system","dll","failed","integrity","validation","could","not","loaded","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies"],"errorCode":"0xC0000221","eventId":"","severity":"High","summary":"A driver or system DLL failed integrity validation or could not be loaded.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC0000221 - A driver or system DLL failed integrity validation or could not be loaded.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A driver or system DLL failed integrity validation or could not be loaded.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC0000221","identifiers":["0xC0000221"],"identifierType":"Windows Boot Error","namespace":"WIN-BOOT","platform":"Windows","component":"Windows Boot","eventSource":"Windows Boot","symbolicName":"","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not rewrite boot configuration or disk structures before collecting recovery information and confirming the correct Windows volume.","logsToCheck":"BCD configuration; SrtTrail.txt; setup and servicing logs; System log","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC0000221\nNamespace: WIN-BOOT\nType: Windows Boot Error\nPlatform: Windows\nProduct: Windows Boot / Recovery\nComponent: Windows Boot\nReview status: Verified\n\nMeaning: A driver or system DLL failed integrity validation or could not be loaded.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: BCD configuration; SrtTrail.txt; setup and servicing logs; System log\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Boot"],"technologies":["WIN-BOOT","Windows Boot Error","Windows Boot","Verified"],"aliases":["0xC0000221"]},{"id":54094,"title":"0xC0000225 - A required device is not connected or cannot be accessed","category":"Windows","product":"Windows Boot / Recovery","tags":["WIN-BOOT","Windows Boot Error","Windows Boot","Verified"],"keywords":["0xc0000225","win","boot","windows","required","device","not","connected","cannot","accessed","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers"],"errorCode":"0xC0000225","eventId":"","severity":"High","summary":"A required device is not connected or cannot be accessed.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC0000225 - A required device is not connected or cannot be accessed.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A required device is not connected or cannot be accessed.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC0000225","identifiers":["0xC0000225"],"identifierType":"Windows Boot Error","namespace":"WIN-BOOT","platform":"Windows","component":"Windows Boot","eventSource":"Windows Boot","symbolicName":"","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not rewrite boot configuration or disk structures before collecting recovery information and confirming the correct Windows volume.","logsToCheck":"BCD configuration; SrtTrail.txt; setup and servicing logs; System log","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC0000225\nNamespace: WIN-BOOT\nType: Windows Boot Error\nPlatform: Windows\nProduct: Windows Boot / Recovery\nComponent: Windows Boot\nReview status: Verified\n\nMeaning: A required device is not connected or cannot be accessed.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: BCD configuration; SrtTrail.txt; setup and servicing logs; System log\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Boot"],"technologies":["WIN-BOOT","Windows Boot Error","Windows Boot","Verified"],"aliases":["0xC0000225"]},{"id":54095,"title":"0xC0000428 - Windows could not verify the digital signature of a required file","category":"Windows","product":"Windows Boot / Recovery","tags":["WIN-BOOT","Windows Boot Error","Windows Boot","Verified"],"keywords":["0xc0000428","win","boot","windows","could","not","verify","the","digital","signature","required","file","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions"],"errorCode":"0xC0000428","eventId":"","severity":"High","summary":"Windows could not verify the digital signature of a required file.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC0000428 - Windows could not verify the digital signature of a required file.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Windows could not verify the digital signature of a required file.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC0000428","identifiers":["0xC0000428"],"identifierType":"Windows Boot Error","namespace":"WIN-BOOT","platform":"Windows","component":"Windows Boot","eventSource":"Windows Boot","symbolicName":"","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not rewrite boot configuration or disk structures before collecting recovery information and confirming the correct Windows volume.","logsToCheck":"BCD configuration; SrtTrail.txt; setup and servicing logs; System log","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC0000428\nNamespace: WIN-BOOT\nType: Windows Boot Error\nPlatform: Windows\nProduct: Windows Boot / Recovery\nComponent: Windows Boot\nReview status: Verified\n\nMeaning: Windows could not verify the digital signature of a required file.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: BCD configuration; SrtTrail.txt; setup and servicing logs; System log\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Boot"],"technologies":["WIN-BOOT","Windows Boot Error","Windows Boot","Verified"],"aliases":["0xC0000428"]},{"id":54096,"title":"0xC000000F - The boot selection failed because a required device is inaccessible","category":"Windows","product":"Windows Boot / Recovery","tags":["WIN-BOOT","Windows Boot Error","Windows Boot","Verified"],"keywords":["0xc000000f","win","boot","windows","the","selection","failed","because","required","device","inaccessible","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers"],"errorCode":"0xC000000F","eventId":"","severity":"High","summary":"The boot selection failed because a required device is inaccessible.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC000000F - The boot selection failed because a required device is inaccessible.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The boot selection failed because a required device is inaccessible.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC000000F","identifiers":["0xC000000F"],"identifierType":"Windows Boot Error","namespace":"WIN-BOOT","platform":"Windows","component":"Windows Boot","eventSource":"Windows Boot","symbolicName":"","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not rewrite boot configuration or disk structures before collecting recovery information and confirming the correct Windows volume.","logsToCheck":"BCD configuration; SrtTrail.txt; setup and servicing logs; System log","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC000000F\nNamespace: WIN-BOOT\nType: Windows Boot Error\nPlatform: Windows\nProduct: Windows Boot / Recovery\nComponent: Windows Boot\nReview status: Verified\n\nMeaning: The boot selection failed because a required device is inaccessible.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: BCD configuration; SrtTrail.txt; setup and servicing logs; System log\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Boot"],"technologies":["WIN-BOOT","Windows Boot Error","Windows Boot","Verified"],"aliases":["0xC000000F"]},{"id":54097,"title":"BOOTMGR IS MISSING - Windows Boot Manager could not be located","category":"Windows","product":"Windows Boot / Recovery","tags":["WIN-BOOT","Plain-text Boot Error","Windows Boot","Verified"],"keywords":["bootmgr","missing","win","boot","windows","manager","could","not","located","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services"],"errorCode":"BOOTMGR IS MISSING","eventId":"","severity":"High","summary":"Windows Boot Manager could not be located.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to BOOTMGR IS MISSING - Windows Boot Manager could not be located.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Windows Boot Manager could not be located.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"BOOTMGR IS MISSING","identifiers":["BOOTMGR IS MISSING"],"identifierType":"Plain-text Boot Error","namespace":"WIN-BOOT","platform":"Windows","component":"Windows Boot","eventSource":"Windows Boot","symbolicName":"","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not rewrite boot configuration or disk structures before collecting recovery information and confirming the correct Windows volume.","logsToCheck":"BCD configuration; SrtTrail.txt; setup and servicing logs; System log","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: BOOTMGR IS MISSING\nNamespace: WIN-BOOT\nType: Plain-text Boot Error\nPlatform: Windows\nProduct: Windows Boot / Recovery\nComponent: Windows Boot\nReview status: Verified\n\nMeaning: Windows Boot Manager could not be located.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: BCD configuration; SrtTrail.txt; setup and servicing logs; System log\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Boot"],"technologies":["WIN-BOOT","Plain-text Boot Error","Windows Boot","Verified"],"aliases":["BOOTMGR IS MISSING"]},{"id":54098,"title":"NO BOOTABLE DEVICE - The system firmware could not locate a bootable operating-system device","category":"Windows","product":"Windows Boot / Recovery","tags":["WIN-BOOT","Plain-text Boot Error","Windows Boot","Verified"],"keywords":["bootable","device","win","boot","windows","the","system","firmware","could","not","locate","operating","troubleshooting","requirements","before","modifying","files","determine","uefi","legacy","bios","disk","gpt","mbr","bitlocker","enabled","recovery","key","available","secure","does","detect","efi","partition","present","readable","correct","volume","assigned","drive"],"errorCode":"NO BOOTABLE DEVICE","eventId":"","severity":"High","summary":"The system firmware could not locate a bootable operating-system device.\nBOOT TROUBLESHOOTING REQUIREMENTS:\nBefore modifying boot files, determine:\n- Is the system UEFI or legacy BIOS?\n- Is the disk GPT or MBR?\n- Is BitLocker enabled?\n- Is the recovery key available?\n- Is Secure Boot enabled?\n- Does firmware detect the disk?\n- Is the EFI System Partition present?\n- Is the Windows partition readable?\n- Is the correct Windows volume assigned a drive letter in recovery?\n- Is user data backed up?\n- Is there evidence of storage failure?\nDIAGNOSTIC COMMANDS:\ndiskpart\nlist disk\nlist volume\nexit\nmanage-bde -status\nmanage-bde -protectors C: -get\nbcdedit /enum all\nreagentc /info\nIMPORTANT:\nDo not automatically run bootrec, bcdboot, chkdsk, diskpart clean, format,\nor partition-conversion commands.\nPresent repair commands only after the disk layout, encryption state, recovery\nkey availability, Windows volume, and EFI or system partition have been\nidentified.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to NO BOOTABLE DEVICE - The system firmware could not locate a bootable operating-system device.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The system firmware could not locate a bootable operating-system device.\nBOOT TROUBLESHOOTING REQUIREMENTS:\nBefore modifying boot files, determine:\n- Is the system UEFI or legacy BIOS?\n- Is the disk GPT or MBR?\n- Is BitLocker enabled?\n- Is the recovery key available?\n- Is Secure Boot enabled?\n- Does firmware detect the disk?\n- Is the EFI System Partition present?\n- Is the Windows partition readable?\n- Is the correct Windows volume assigned a drive letter in recovery?\n- Is user data backed up?\n- Is there evidence of storage failure?\nDIAGNOSTIC COMMANDS:\ndiskpart\nlist disk\nlist volume\nexit\nmanage-bde -status\nmanage-bde -protectors C: -get\nbcdedit /enum all\nreagentc /info\nIMPORTANT:\nDo not automatically run bootrec, bcdboot, chkdsk, diskpart clean, format,\nor partition-conversion commands.\nPresent repair commands only after the disk layout, encryption state, recovery\nkey availability, Windows volume, and EFI or system partition have been\nidentified.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"diskpart","admin":true,"restart":true,"risk":"High"},{"command":"exit","admin":true,"restart":true,"risk":"Standard"},{"command":"bcdedit /enum all","admin":true,"restart":true,"risk":"High"},{"command":"reagentc /info","admin":true,"restart":true,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"NO BOOTABLE DEVICE","identifiers":["NO BOOTABLE DEVICE"],"identifierType":"Plain-text Boot Error","namespace":"WIN-BOOT","platform":"Windows","component":"Windows Boot","eventSource":"Windows Boot","symbolicName":"","restartRequired":"Yes","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not rewrite boot configuration or disk structures before collecting recovery information and confirming the correct Windows volume.","logsToCheck":"BCD configuration; SrtTrail.txt; setup and servicing logs; System log","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: NO BOOTABLE DEVICE\nNamespace: WIN-BOOT\nType: Plain-text Boot Error\nPlatform: Windows\nProduct: Windows Boot / Recovery\nComponent: Windows Boot\nReview status: Verified\n\nMeaning: The system firmware could not locate a bootable operating-system device.\nBOOT TROUBLESHOOTING REQUIREMENTS:\nBefore modifying boot files, determine:\n- Is the system UEFI or legacy BIOS?\n- Is the disk GPT or MBR?\n- Is BitLocker enabled?\n- Is the recovery key available?\n- Is Secure Boot enabled?\n- Does firmware detect the disk?\n- Is the EFI System Partition present?\n- Is the Windows partition readable?\n- Is the correct Windows volume assigned a drive letter in recovery?\n- Is user data backed up?\n- Is there evidence of storage failure?\nDIAGNOSTIC COMMANDS:\ndiskpart\nlist disk\nlist volume\nexit\nmanage-bde -status\nmanage-bde -protectors C: -get\nbcdedit /enum all\nreagentc /info\nIMPORTANT:\nDo not automatically run bootrec, bcdboot, chkdsk, diskpart clean, format,\nor partition-conversion commands.\nPresent repair commands only after the disk layout, encryption state, recovery\nkey availability, Windows volume, and EFI or system partition have been\nidentified.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: BCD configuration; SrtTrail.txt; setup and servicing logs; System log\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Boot"],"technologies":["WIN-BOOT","Plain-text Boot Error","Windows Boot","Verified"],"aliases":["NO BOOTABLE DEVICE"]},{"id":54099,"title":"0x800F0831 - Component-store corruption or a missing servicing manifest dependency","category":"Patch Management","product":"Windows Update / Servicing","tags":["WIN-WU","Windows Update Error","Windows Update","Verified"],"keywords":["0x800f0831","win","windows","update","component","store","corruption","missing","servicing","manifest","dependency","first","action","review","cbs","log","and","run","dism","diagnostics","the","operation","fails","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","system","crash","exact","cause","depends","surrounding","evidence"],"errorCode":"0x800F0831","eventId":"","severity":"Critical","summary":"Component-store corruption or a missing servicing manifest dependency.\nFIRST ACTION:\nReview CBS.log and run DISM component-store diagnostics.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x800F0831 - Component-store corruption or a missing servicing manifest dependency.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Component-store corruption or a missing servicing manifest dependency.\nFIRST ACTION:\nReview CBS.log and run DISM component-store diagnostics.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x800F0831","identifiers":["0x800F0831"],"identifierType":"Windows Update Error","namespace":"WIN-WU","platform":"Windows","component":"Windows Update","eventSource":"Windows Update","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x800F0831\nNamespace: WIN-WU\nType: Windows Update Error\nPlatform: Windows\nProduct: Windows Update / Servicing\nComponent: Windows Update\nReview status: Verified\n\nMeaning: Component-store corruption or a missing servicing manifest dependency.\nFIRST ACTION:\nReview CBS.log and run DISM component-store diagnostics.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["WIN-WU","Windows Update Error","Windows Update","Verified"],"aliases":["0x800F0831"]},{"id":54100,"title":"0x80073701 - A required side-by-side assembly is missing","category":"Patch Management","product":"Windows Update / Servicing","tags":["WIN-WU","Windows Update Error","Windows Update","Verified"],"keywords":["0x80073701","win","windows","update","required","side","assembly","missing","first","action","review","cbs","log","and","repair","the","component","store","operation","fails","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","system","crash","exact","cause","depends","surrounding","evidence","common","factors","include"],"errorCode":"0x80073701","eventId":"","severity":"Low","summary":"A required side-by-side assembly is missing.\nFIRST ACTION:\nReview CBS.log and repair the component store.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x80073701 - A required side-by-side assembly is missing.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A required side-by-side assembly is missing.\nFIRST ACTION:\nReview CBS.log and repair the component store.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x80073701","identifiers":["0x80073701"],"identifierType":"Windows Update Error","namespace":"WIN-WU","platform":"Windows","component":"Windows Update","eventSource":"Windows Update","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x80073701\nNamespace: WIN-WU\nType: Windows Update Error\nPlatform: Windows\nProduct: Windows Update / Servicing\nComponent: Windows Update\nReview status: Verified\n\nMeaning: A required side-by-side assembly is missing.\nFIRST ACTION:\nReview CBS.log and repair the component store.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["WIN-WU","Windows Update Error","Windows Update","Verified"],"aliases":["0x80073701"]},{"id":54101,"title":"0x800705B9 - Windows servicing encountered malformed XML or servicing-stack data","category":"Patch Management","product":"Windows Update / Servicing","tags":["WIN-WU","Windows Update Error","Windows Update","Verified"],"keywords":["0x800705b9","win","windows","update","servicing","encountered","malformed","xml","stack","data","first","action","review","cbs","log","and","health","the","operation","fails","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors"],"errorCode":"0x800705B9","eventId":"","severity":"Low","summary":"Windows servicing encountered malformed XML or servicing-stack data.\nFIRST ACTION:\nReview CBS.log and servicing-stack health.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x800705B9 - Windows servicing encountered malformed XML or servicing-stack data.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Windows servicing encountered malformed XML or servicing-stack data.\nFIRST ACTION:\nReview CBS.log and servicing-stack health.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x800705B9","identifiers":["0x800705B9"],"identifierType":"Windows Update Error","namespace":"WIN-WU","platform":"Windows","component":"Windows Update","eventSource":"Windows Update","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x800705B9\nNamespace: WIN-WU\nType: Windows Update Error\nPlatform: Windows\nProduct: Windows Update / Servicing\nComponent: Windows Update\nReview status: Verified\n\nMeaning: Windows servicing encountered malformed XML or servicing-stack data.\nFIRST ACTION:\nReview CBS.log and servicing-stack health.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["WIN-WU","Windows Update Error","Windows Update","Verified"],"aliases":["0x800705B9"]},{"id":54102,"title":"0x80240439 - The Windows Update setup handler failed","category":"Patch Management","product":"Windows Update / Servicing","tags":["WIN-WU","Windows Update Error","Windows Update","Verified"],"keywords":["0x80240439","win","windows","update","the","setup","handler","failed","first","action","review","windowsupdate","log","and","component","state","operation","fails","may","produce","identifier","application","deployment","report","event","viewer","entry","system","crash","exact","cause","depends","surrounding","evidence","common","factors","include","configuration","dependencies","permissions"],"errorCode":"0x80240439","eventId":"","severity":"High","summary":"The Windows Update setup handler failed.\nFIRST ACTION:\nReview WindowsUpdate.log and update-component state.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x80240439 - The Windows Update setup handler failed.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The Windows Update setup handler failed.\nFIRST ACTION:\nReview WindowsUpdate.log and update-component state.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x80240439","identifiers":["0x80240439"],"identifierType":"Windows Update Error","namespace":"WIN-WU","platform":"Windows","component":"Windows Update","eventSource":"Windows Update","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x80240439\nNamespace: WIN-WU\nType: Windows Update Error\nPlatform: Windows\nProduct: Windows Update / Servicing\nComponent: Windows Update\nReview status: Verified\n\nMeaning: The Windows Update setup handler failed.\nFIRST ACTION:\nReview WindowsUpdate.log and update-component state.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["WIN-WU","Windows Update Error","Windows Update","Verified"],"aliases":["0x80240439"]},{"id":54103,"title":"0x800F0984 - A matching binary required for the delta update is missing","category":"Patch Management","product":"Windows Update / Servicing","tags":["WIN-WU","Windows Update Error","Windows Update","Verified"],"keywords":["0x800f0984","win","windows","update","matching","binary","required","for","the","delta","missing","first","action","repair","component","store","and","evaluate","place","corruption","cannot","resolved","operation","fails","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends"],"errorCode":"0x800F0984","eventId":"","severity":"Critical","summary":"A matching binary required for the delta update is missing.\nFIRST ACTION:\nRepair the component store and evaluate an in-place repair if corruption\ncannot be resolved.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x800F0984 - A matching binary required for the delta update is missing.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A matching binary required for the delta update is missing.\nFIRST ACTION:\nRepair the component store and evaluate an in-place repair if corruption\ncannot be resolved.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x800F0984","identifiers":["0x800F0984"],"identifierType":"Windows Update Error","namespace":"WIN-WU","platform":"Windows","component":"Windows Update","eventSource":"Windows Update","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x800F0984\nNamespace: WIN-WU\nType: Windows Update Error\nPlatform: Windows\nProduct: Windows Update / Servicing\nComponent: Windows Update\nReview status: Verified\n\nMeaning: A matching binary required for the delta update is missing.\nFIRST ACTION:\nRepair the component store and evaluate an in-place repair if corruption\ncannot be resolved.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["WIN-WU","Windows Update Error","Windows Update","Verified"],"aliases":["0x800F0984"]},{"id":54104,"title":"0x800F0986 - Windows could not apply the forward delta update","category":"Patch Management","product":"Windows Update / Servicing","tags":["WIN-WU","Windows Update Error","Windows Update","Verified"],"keywords":["0x800f0986","win","windows","update","could","not","apply","the","forward","delta","first","action","review","servicing","logs","and","evaluate","component","store","repair","operation","fails","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","surrounding","evidence"],"errorCode":"0x800F0986","eventId":"","severity":"Low","summary":"Windows could not apply the forward delta update.\nFIRST ACTION:\nReview servicing logs and evaluate component-store repair.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x800F0986 - Windows could not apply the forward delta update.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Windows could not apply the forward delta update.\nFIRST ACTION:\nReview servicing logs and evaluate component-store repair.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x800F0986","identifiers":["0x800F0986"],"identifierType":"Windows Update Error","namespace":"WIN-WU","platform":"Windows","component":"Windows Update","eventSource":"Windows Update","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x800F0986\nNamespace: WIN-WU\nType: Windows Update Error\nPlatform: Windows\nProduct: Windows Update / Servicing\nComponent: Windows Update\nReview status: Verified\n\nMeaning: Windows could not apply the forward delta update.\nFIRST ACTION:\nReview servicing logs and evaluate component-store repair.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["WIN-WU","Windows Update Error","Windows Update","Verified"],"aliases":["0x800F0986"]},{"id":54105,"title":"0x800F0830 - The Windows image is not serviceable","category":"Patch Management","product":"Windows Update / Servicing","tags":["WIN-WU","Windows Update Error","Windows Update","Verified"],"keywords":["0x800f0830","win","windows","update","the","image","not","serviceable","first","action","review","dism","health","and","consider","place","repair","after","backup","operation","fails","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence"],"errorCode":"0x800F0830","eventId":"","severity":"Low","summary":"The Windows image is not serviceable.\nFIRST ACTION:\nReview DISM health and consider an in-place repair after backup.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x800F0830 - The Windows image is not serviceable.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The Windows image is not serviceable.\nFIRST ACTION:\nReview DISM health and consider an in-place repair after backup.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x800F0830","identifiers":["0x800F0830"],"identifierType":"Windows Update Error","namespace":"WIN-WU","platform":"Windows","component":"Windows Update","eventSource":"Windows Update","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x800F0830\nNamespace: WIN-WU\nType: Windows Update Error\nPlatform: Windows\nProduct: Windows Update / Servicing\nComponent: Windows Update\nReview status: Verified\n\nMeaning: The Windows image is not serviceable.\nFIRST ACTION:\nReview DISM health and consider an in-place repair after backup.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["WIN-WU","Windows Update Error","Windows Update","Verified"],"aliases":["0x800F0830"]},{"id":54106,"title":"0x80242016 - Windows Update entered an unexpected state after restart","category":"Patch Management","product":"Windows Update / Servicing","tags":["WIN-WU","Windows Update Error","Windows Update","Verified"],"keywords":["0x80242016","win","windows","update","entered","unexpected","state","after","restart","first","action","review","post","servicing","and","logs","the","operation","fails","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors"],"errorCode":"0x80242016","eventId":"","severity":"Low","summary":"Windows Update entered an unexpected state after restart.\nFIRST ACTION:\nReview post-restart servicing and update logs.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x80242016 - Windows Update entered an unexpected state after restart.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Windows Update entered an unexpected state after restart.\nFIRST ACTION:\nReview post-restart servicing and update logs.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x80242016","identifiers":["0x80242016"],"identifierType":"Windows Update Error","namespace":"WIN-WU","platform":"Windows","component":"Windows Update","eventSource":"Windows Update","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x80242016\nNamespace: WIN-WU\nType: Windows Update Error\nPlatform: Windows\nProduct: Windows Update / Servicing\nComponent: Windows Update\nReview status: Verified\n\nMeaning: Windows Update entered an unexpected state after restart.\nFIRST ACTION:\nReview post-restart servicing and update logs.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["WIN-WU","Windows Update Error","Windows Update","Verified"],"aliases":["0x80242016"]},{"id":54107,"title":"0x80071AB1 - The transaction log could not grow","category":"Patch Management","product":"Windows Update / Servicing","tags":["WIN-WU","Windows Update Error","Windows Update","Verified"],"keywords":["0x80071ab1","win","windows","update","the","transaction","log","could","not","grow","first","action","check","free","disk","space","and","servicing","state","operation","fails","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","system","crash","exact","cause","depends","component","surrounding","evidence","common"],"errorCode":"0x80071AB1","eventId":"","severity":"Low","summary":"The transaction log could not grow.\nFIRST ACTION:\nCheck free disk space and servicing transaction state.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x80071AB1 - The transaction log could not grow.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The transaction log could not grow.\nFIRST ACTION:\nCheck free disk space and servicing transaction state.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x80071AB1","identifiers":["0x80071AB1"],"identifierType":"Windows Update Error","namespace":"WIN-WU","platform":"Windows","component":"Windows Update","eventSource":"Windows Update","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x80071AB1\nNamespace: WIN-WU\nType: Windows Update Error\nPlatform: Windows\nProduct: Windows Update / Servicing\nComponent: Windows Update\nReview status: Verified\n\nMeaning: The transaction log could not grow.\nFIRST ACTION:\nCheck free disk space and servicing transaction state.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["WIN-WU","Windows Update Error","Windows Update","Verified"],"aliases":["0x80071AB1"]},{"id":54108,"title":"0xC01A001D - A Windows transaction log is full","category":"Patch Management","product":"Windows Update / Servicing","tags":["WIN-WU","Windows Update Error","Windows Update","Verified"],"keywords":["0xc01a001d","win","windows","update","transaction","log","full","first","action","check","disk","capacity","and","state","the","operation","fails","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies"],"errorCode":"0xC01A001D","eventId":"","severity":"Low","summary":"A Windows transaction log is full.\nFIRST ACTION:\nCheck disk capacity and transaction-log state.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC01A001D - A Windows transaction log is full.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A Windows transaction log is full.\nFIRST ACTION:\nCheck disk capacity and transaction-log state.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC01A001D","identifiers":["0xC01A001D"],"identifierType":"Windows Update Error","namespace":"WIN-WU","platform":"Windows","component":"Windows Update","eventSource":"Windows Update","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC01A001D\nNamespace: WIN-WU\nType: Windows Update Error\nPlatform: Windows\nProduct: Windows Update / Servicing\nComponent: Windows Update\nReview status: Verified\n\nMeaning: A Windows transaction log is full.\nFIRST ACTION:\nCheck disk capacity and transaction-log state.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["WIN-WU","Windows Update Error","Windows Update","Verified"],"aliases":["0xC01A001D"]},{"id":54109,"title":"0x80070070 - Insufficient disk space","category":"Patch Management","product":"Windows Update / Servicing","tags":["WIN-WU","Windows Update Error","Windows Update","Verified"],"keywords":["0x80070070","win","windows","update","insufficient","disk","space","first","action","free","approved","temporary","and","application","data","the","operation","fails","may","produce","identifier","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration"],"errorCode":"0x80070070","eventId":"","severity":"Low","summary":"Insufficient disk space.\nFIRST ACTION:\nFree approved temporary, update, and application data.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x80070070 - Insufficient disk space.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Insufficient disk space.\nFIRST ACTION:\nFree approved temporary, update, and application data.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x80070070","identifiers":["0x80070070"],"identifierType":"Windows Update Error","namespace":"WIN-WU","platform":"Windows","component":"Windows Update","eventSource":"Windows Update","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x80070070\nNamespace: WIN-WU\nType: Windows Update Error\nPlatform: Windows\nProduct: Windows Update / Servicing\nComponent: Windows Update\nReview status: Verified\n\nMeaning: Insufficient disk space.\nFIRST ACTION:\nFree approved temporary, update, and application data.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["WIN-WU","Windows Update Error","Windows Update","Verified"],"aliases":["0x80070070"]},{"id":54110,"title":"0x80240016 - Another installation or servicing operation is in progress","category":"Patch Management","product":"Windows Update / Servicing","tags":["WIN-WU","Windows Update Error","Windows Update","Verified"],"keywords":["0x80240016","win","windows","update","another","installation","servicing","operation","progress","first","action","allow","the","current","finish","restart","stuck","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors"],"errorCode":"0x80240016","eventId":"","severity":"Low","summary":"Another installation or servicing operation is in progress.\nFIRST ACTION:\nAllow the current operation to finish or restart if the operation is stuck.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x80240016 - Another installation or servicing operation is in progress.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Another installation or servicing operation is in progress.\nFIRST ACTION:\nAllow the current operation to finish or restart if the operation is stuck.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x80240016","identifiers":["0x80240016"],"identifierType":"Windows Update Error","namespace":"WIN-WU","platform":"Windows","component":"Windows Update","eventSource":"Windows Update","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x80240016\nNamespace: WIN-WU\nType: Windows Update Error\nPlatform: Windows\nProduct: Windows Update / Servicing\nComponent: Windows Update\nReview status: Verified\n\nMeaning: Another installation or servicing operation is in progress.\nFIRST ACTION:\nAllow the current operation to finish or restart if the operation is stuck.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["WIN-WU","Windows Update Error","Windows Update","Verified"],"aliases":["0x80240016"]},{"id":54111,"title":"0x8024001E - The Windows Update service is shutting down","category":"Patch Management","product":"Windows Update / Servicing","tags":["WIN-WU","Windows Update Error","Windows Update","Verified"],"keywords":["0x8024001e","win","windows","update","the","service","shutting","down","first","action","restart","device","and","retry","operation","fails","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies"],"errorCode":"0x8024001E","eventId":"","severity":"Low","summary":"The Windows Update service is shutting down.\nFIRST ACTION:\nRestart the update service or device and retry.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x8024001E - The Windows Update service is shutting down.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The Windows Update service is shutting down.\nFIRST ACTION:\nRestart the update service or device and retry.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x8024001E","identifiers":["0x8024001E"],"identifierType":"Windows Update Error","namespace":"WIN-WU","platform":"Windows","component":"Windows Update","eventSource":"Windows Update","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x8024001E\nNamespace: WIN-WU\nType: Windows Update Error\nPlatform: Windows\nProduct: Windows Update / Servicing\nComponent: Windows Update\nReview status: Verified\n\nMeaning: The Windows Update service is shutting down.\nFIRST ACTION:\nRestart the update service or device and retry.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["WIN-WU","Windows Update Error","Windows Update","Verified"],"aliases":["0x8024001E"]},{"id":54112,"title":"0x8024001F - Windows Update encountered an invalid file or registry path","category":"Patch Management","product":"Windows Update / Servicing","tags":["WIN-WU","Windows Update Error","Windows Update","Verified"],"keywords":["0x8024001f","win","windows","update","encountered","invalid","file","registry","path","first","action","review","policy","and","logs","the","operation","fails","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include"],"errorCode":"0x8024001F","eventId":"","severity":"Medium","summary":"Windows Update encountered an invalid file or registry path.\nFIRST ACTION:\nReview policy, registry, and Windows Update logs.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x8024001F - Windows Update encountered an invalid file or registry path.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Windows Update encountered an invalid file or registry path.\nFIRST ACTION:\nReview policy, registry, and Windows Update logs.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x8024001F","identifiers":["0x8024001F"],"identifierType":"Windows Update Error","namespace":"WIN-WU","platform":"Windows","component":"Windows Update","eventSource":"Windows Update","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x8024001F\nNamespace: WIN-WU\nType: Windows Update Error\nPlatform: Windows\nProduct: Windows Update / Servicing\nComponent: Windows Update\nReview status: Verified\n\nMeaning: Windows Update encountered an invalid file or registry path.\nFIRST ACTION:\nReview policy, registry, and Windows Update logs.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["WIN-WU","Windows Update Error","Windows Update","Verified"],"aliases":["0x8024001F"]},{"id":54113,"title":"0x80240020 - No interactive user was available to complete the operation","category":"Patch Management","product":"Windows Update / Servicing","tags":["WIN-WU","Windows Update Error","Windows Update","Verified"],"keywords":["0x80240020","win","windows","update","interactive","user","was","available","complete","the","operation","first","action","review","deployment","context","and","whether","interaction","required","fails","may","produce","identifier","application","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common"],"errorCode":"0x80240020","eventId":"","severity":"Low","summary":"No interactive user was available to complete the operation.\nFIRST ACTION:\nReview deployment context and whether user interaction is required.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x80240020 - No interactive user was available to complete the operation.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: No interactive user was available to complete the operation.\nFIRST ACTION:\nReview deployment context and whether user interaction is required.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x80240020","identifiers":["0x80240020"],"identifierType":"Windows Update Error","namespace":"WIN-WU","platform":"Windows","component":"Windows Update","eventSource":"Windows Update","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x80240020\nNamespace: WIN-WU\nType: Windows Update Error\nPlatform: Windows\nProduct: Windows Update / Servicing\nComponent: Windows Update\nReview status: Verified\n\nMeaning: No interactive user was available to complete the operation.\nFIRST ACTION:\nReview deployment context and whether user interaction is required.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["WIN-WU","Windows Update Error","Windows Update","Verified"],"aliases":["0x80240020"]},{"id":54114,"title":"0x8024401C - The Windows Update request timed out","category":"Patch Management","product":"Windows Update / Servicing","tags":["WIN-WU","Windows Update Error","Windows Update","Verified"],"keywords":["0x8024401c","win","windows","update","the","request","timed","out","first","action","check","microsoft","wsus","access","dns","proxy","firewall","and","service","availability","operation","fails","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding"],"errorCode":"0x8024401C","eventId":"","severity":"Low","summary":"The Windows Update request timed out.\nFIRST ACTION:\nCheck Microsoft Update or WSUS access, DNS, proxy, firewall, and service\navailability.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x8024401C - The Windows Update request timed out.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The Windows Update request timed out.\nFIRST ACTION:\nCheck Microsoft Update or WSUS access, DNS, proxy, firewall, and service\navailability.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x8024401C","identifiers":["0x8024401C"],"identifierType":"Windows Update Error","namespace":"WIN-WU","platform":"Windows","component":"Windows Update","eventSource":"Windows Update","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x8024401C\nNamespace: WIN-WU\nType: Windows Update Error\nPlatform: Windows\nProduct: Windows Update / Servicing\nComponent: Windows Update\nReview status: Verified\n\nMeaning: The Windows Update request timed out.\nFIRST ACTION:\nCheck Microsoft Update or WSUS access, DNS, proxy, firewall, and service\navailability.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["WIN-WU","Windows Update Error","Windows Update","Verified"],"aliases":["0x8024401C"]},{"id":54115,"title":"0x8024402F - Update processing completed with one or more errors","category":"Patch Management","product":"Windows Update / Servicing","tags":["WIN-WU","Windows Update Error","Windows Update","Verified"],"keywords":["0x8024402f","win","windows","update","processing","completed","with","one","more","errors","first","action","review","windowsupdate","log","for","the","specific","subordinate","failure","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","system","crash","exact","cause","depends","component","surrounding"],"errorCode":"0x8024402F","eventId":"","severity":"High","summary":"Update processing completed with one or more errors.\nFIRST ACTION:\nReview WindowsUpdate.log for the specific subordinate failure.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x8024402F - Update processing completed with one or more errors.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Update processing completed with one or more errors.\nFIRST ACTION:\nReview WindowsUpdate.log for the specific subordinate failure.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x8024402F","identifiers":["0x8024402F"],"identifierType":"Windows Update Error","namespace":"WIN-WU","platform":"Windows","component":"Windows Update","eventSource":"Windows Update","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x8024402F\nNamespace: WIN-WU\nType: Windows Update Error\nPlatform: Windows\nProduct: Windows Update / Servicing\nComponent: Windows Update\nReview status: Verified\n\nMeaning: Update processing completed with one or more errors.\nFIRST ACTION:\nReview WindowsUpdate.log for the specific subordinate failure.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["WIN-WU","Windows Update Error","Windows Update","Verified"],"aliases":["0x8024402F"]},{"id":54116,"title":"0x80246008 - The Background Intelligent Transfer Service encountered a problem","category":"Patch Management","product":"Windows Update / Servicing","tags":["WIN-WU","Windows Update Error","Windows Update","Verified"],"keywords":["0x80246008","win","windows","update","the","background","intelligent","transfer","service","encountered","problem","first","action","check","bits","jobs","proxy","and","permissions","operation","fails","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence"],"errorCode":"0x80246008","eventId":"","severity":"Low","summary":"The Background Intelligent Transfer Service encountered a problem.\nFIRST ACTION:\nCheck BITS service, jobs, proxy, and permissions.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x80246008 - The Background Intelligent Transfer Service encountered a problem.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The Background Intelligent Transfer Service encountered a problem.\nFIRST ACTION:\nCheck BITS service, jobs, proxy, and permissions.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x80246008","identifiers":["0x80246008"],"identifierType":"Windows Update Error","namespace":"WIN-WU","platform":"Windows","component":"Windows Update","eventSource":"Windows Update","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x80246008\nNamespace: WIN-WU\nType: Windows Update Error\nPlatform: Windows\nProduct: Windows Update / Servicing\nComponent: Windows Update\nReview status: Verified\n\nMeaning: The Background Intelligent Transfer Service encountered a problem.\nFIRST ACTION:\nCheck BITS service, jobs, proxy, and permissions.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["WIN-WU","Windows Update Error","Windows Update","Verified"],"aliases":["0x80246008"]},{"id":54117,"title":"0x8024A000 - Automatic Updates could not service the request","category":"Patch Management","product":"Windows Update / Servicing","tags":["WIN-WU","Windows Update Error","Windows Update","Verified"],"keywords":["0x8024a000","win","windows","update","automatic","updates","could","not","service","the","request","first","action","check","services","and","component","health","logs","cbs","log","dism","windowsupdate","event","viewer","applications","microsoft","windowsupdateclient","servicing","common","commands","online","cleanup","image","checkhealth","scanhealth","restorehealth","sfc","scannow","important"],"errorCode":"0x8024A000","eventId":"","severity":"Low","summary":"Automatic Updates could not service the request.\nFIRST ACTION:\nCheck Windows Update services and component health.\nWINDOWS UPDATE LOGS:\nC:\\Windows\\Logs\\CBS\\CBS.log\nC:\\Windows\\Logs\\DISM\\dism.log\nWindowsUpdate.log\nEvent Viewer > Applications and Services Logs\nMicrosoft > Windows > WindowsUpdateClient\nMicrosoft > Windows > Servicing\nCOMMON COMMANDS:\nDISM /Online /Cleanup-Image /CheckHealth\nDISM /Online /Cleanup-Image /ScanHealth\nDISM /Online /Cleanup-Image /RestoreHealth\nsfc /scannow\nIMPORTANT:\nDo not reset Windows Update components as the automatic first step for every\nupdate error.\nReview logs first and perform a targeted reset only when the update cache,\nservice registration, or datastore is damaged.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x8024A000 - Automatic Updates could not service the request.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Automatic Updates could not service the request.\nFIRST ACTION:\nCheck Windows Update services and component health.\nWINDOWS UPDATE LOGS:\nC:\\Windows\\Logs\\CBS\\CBS.log\nC:\\Windows\\Logs\\DISM\\dism.log\nWindowsUpdate.log\nEvent Viewer > Applications and Services Logs\nMicrosoft > Windows > WindowsUpdateClient\nMicrosoft > Windows > Servicing\nCOMMON COMMANDS:\nDISM /Online /Cleanup-Image /CheckHealth\nDISM /Online /Cleanup-Image /ScanHealth\nDISM /Online /Cleanup-Image /RestoreHealth\nsfc /scannow\nIMPORTANT:\nDo not reset Windows Update components as the automatic first step for every\nupdate error.\nReview logs first and perform a targeted reset only when the update cache,\nservice registration, or datastore is damaged.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"DISM /Online /Cleanup-Image /CheckHealth","admin":true,"restart":false,"risk":"Standard"},{"command":"DISM /Online /Cleanup-Image /ScanHealth","admin":true,"restart":false,"risk":"Standard"},{"command":"DISM /Online /Cleanup-Image /RestoreHealth","admin":true,"restart":false,"risk":"Standard"},{"command":"sfc /scannow","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x8024A000","identifiers":["0x8024A000"],"identifierType":"Windows Update Error","namespace":"WIN-WU","platform":"Windows","component":"Windows Update","eventSource":"Windows Update","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x8024A000\nNamespace: WIN-WU\nType: Windows Update Error\nPlatform: Windows\nProduct: Windows Update / Servicing\nComponent: Windows Update\nReview status: Verified\n\nMeaning: Automatic Updates could not service the request.\nFIRST ACTION:\nCheck Windows Update services and component health.\nWINDOWS UPDATE LOGS:\nC:\\Windows\\Logs\\CBS\\CBS.log\nC:\\Windows\\Logs\\DISM\\dism.log\nWindowsUpdate.log\nEvent Viewer > Applications and Services Logs\nMicrosoft > Windows > WindowsUpdateClient\nMicrosoft > Windows > Servicing\nCOMMON COMMANDS:\nDISM /Online /Cleanup-Image /CheckHealth\nDISM /Online /Cleanup-Image /ScanHealth\nDISM /Online /Cleanup-Image /RestoreHealth\nsfc /scannow\nIMPORTANT:\nDo not reset Windows Update components as the automatic first step for every\nupdate error.\nReview logs first and perform a targeted reset only when the update cache,\nservice registration, or datastore is damaged.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: CBS.log; DISM.log; WindowsUpdate.log; Setup and System logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Update"],"technologies":["WIN-WU","Windows Update Error","Windows Update","Verified"],"aliases":["0x8024A000"]},{"id":54118,"title":"0xC1900107 - Cleanup from a previous installation is still pending","category":"Windows","product":"Windows Setup / Feature Upgrade","tags":["WIN-SETUP","Windows Setup Result","Windows Setup","Verified"],"keywords":["0xc1900107","win","setup","windows","cleanup","from","previous","installation","still","pending","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services"],"errorCode":"0xC1900107","eventId":"","severity":"Low","summary":"Cleanup from a previous installation is still pending.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC1900107 - Cleanup from a previous installation is still pending.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Cleanup from a previous installation is still pending.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC1900107","identifiers":["0xC1900107"],"identifierType":"Windows Setup Result","namespace":"WIN-SETUP","platform":"Windows","component":"Windows Setup","eventSource":"Windows Setup","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC1900107\nNamespace: WIN-SETUP\nType: Windows Setup Result\nPlatform: Windows\nProduct: Windows Setup / Feature Upgrade\nComponent: Windows Setup\nReview status: Verified\n\nMeaning: Cleanup from a previous installation is still pending.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Setup"],"technologies":["WIN-SETUP","Windows Setup Result","Windows Setup","Verified"],"aliases":["0xC1900107"]},{"id":54119,"title":"0xC1900204 - The selected migration path is unavailable","category":"Windows","product":"Windows Setup / Feature Upgrade","tags":["WIN-SETUP","Windows Setup Result","Windows Setup","Verified"],"keywords":["0xc1900204","win","setup","windows","the","selected","migration","path","unavailable","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity","damaged"],"errorCode":"0xC1900204","eventId":"","severity":"Low","summary":"The selected migration path is unavailable.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC1900204 - The selected migration path is unavailable.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The selected migration path is unavailable.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC1900204","identifiers":["0xC1900204"],"identifierType":"Windows Setup Result","namespace":"WIN-SETUP","platform":"Windows","component":"Windows Setup","eventSource":"Windows Setup","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC1900204\nNamespace: WIN-SETUP\nType: Windows Setup Result\nPlatform: Windows\nProduct: Windows Setup / Feature Upgrade\nComponent: Windows Setup\nReview status: Verified\n\nMeaning: The selected migration path is unavailable.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Setup"],"technologies":["WIN-SETUP","Windows Setup Result","Windows Setup","Verified"],"aliases":["0xC1900204"]},{"id":54120,"title":"0xC1900210 - The compatibility scan did not find an actionable compatibility issue","category":"Windows","product":"Windows Setup / Feature Upgrade","tags":["WIN-SETUP","Windows Setup Result","Windows Setup","Verified"],"keywords":["0xc1900210","win","setup","windows","the","compatibility","scan","did","not","find","actionable","issue","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers"],"errorCode":"0xC1900210","eventId":"","severity":"Low","summary":"The compatibility scan did not find an actionable compatibility issue.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC1900210 - The compatibility scan did not find an actionable compatibility issue.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The compatibility scan did not find an actionable compatibility issue.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC1900210","identifiers":["0xC1900210"],"identifierType":"Windows Setup Result","namespace":"WIN-SETUP","platform":"Windows","component":"Windows Setup","eventSource":"Windows Setup","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC1900210\nNamespace: WIN-SETUP\nType: Windows Setup Result\nPlatform: Windows\nProduct: Windows Setup / Feature Upgrade\nComponent: Windows Setup\nReview status: Verified\n\nMeaning: The compatibility scan did not find an actionable compatibility issue.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Setup"],"technologies":["WIN-SETUP","Windows Setup Result","Windows Setup","Verified"],"aliases":["0xC1900210"]},{"id":54121,"title":"0x80070070 - Insufficient disk space for Windows Setup","category":"Windows","product":"Windows Setup / Feature Upgrade","tags":["WIN-SETUP","Windows Setup Result","Windows Setup","Verified"],"keywords":["0x80070070","win","setup","windows","insufficient","disk","space","for","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity","damaged"],"errorCode":"0x80070070","eventId":"","severity":"Low","summary":"Insufficient disk space for Windows Setup.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x80070070 - Insufficient disk space for Windows Setup.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Insufficient disk space for Windows Setup.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x80070070","identifiers":["0x80070070"],"identifierType":"Windows Setup Result","namespace":"WIN-SETUP","platform":"Windows","component":"Windows Setup","eventSource":"Windows Setup","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x80070070\nNamespace: WIN-SETUP\nType: Windows Setup Result\nPlatform: Windows\nProduct: Windows Setup / Feature Upgrade\nComponent: Windows Setup\nReview status: Verified\n\nMeaning: Insufficient disk space for Windows Setup.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Setup"],"technologies":["WIN-SETUP","Windows Setup Result","Windows Setup","Verified"],"aliases":["0x80070070"]},{"id":54122,"title":"0x8007001F - A connected device is not functioning","category":"Windows","product":"Windows Setup / Feature Upgrade","tags":["WIN-SETUP","Windows Setup Result","Windows Setup","Verified"],"keywords":["0x8007001f","win","setup","windows","connected","device","not","functioning","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity","damaged"],"errorCode":"0x8007001F","eventId":"","severity":"Low","summary":"A connected device is not functioning.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x8007001F - A connected device is not functioning.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A connected device is not functioning.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x8007001F","identifiers":["0x8007001F"],"identifierType":"Windows Setup Result","namespace":"WIN-SETUP","platform":"Windows","component":"Windows Setup","eventSource":"Windows Setup","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x8007001F\nNamespace: WIN-SETUP\nType: Windows Setup Result\nPlatform: Windows\nProduct: Windows Setup / Feature Upgrade\nComponent: Windows Setup\nReview status: Verified\n\nMeaning: A connected device is not functioning.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Setup"],"technologies":["WIN-SETUP","Windows Setup Result","Windows Setup","Verified"],"aliases":["0x8007001F"]},{"id":54123,"title":"0x8007042B - A required setup process terminated unexpectedly","category":"Windows","product":"Windows Setup / Feature Upgrade","tags":["WIN-SETUP","Windows Setup Result","Windows Setup","Verified"],"keywords":["0x8007042b","win","setup","windows","required","process","terminated","unexpectedly","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity","damaged"],"errorCode":"0x8007042B","eventId":"","severity":"Low","summary":"A required setup process terminated unexpectedly.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x8007042B - A required setup process terminated unexpectedly.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A required setup process terminated unexpectedly.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x8007042B","identifiers":["0x8007042B"],"identifierType":"Windows Setup Result","namespace":"WIN-SETUP","platform":"Windows","component":"Windows Setup","eventSource":"Windows Setup","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x8007042B\nNamespace: WIN-SETUP\nType: Windows Setup Result\nPlatform: Windows\nProduct: Windows Setup / Feature Upgrade\nComponent: Windows Setup\nReview status: Verified\n\nMeaning: A required setup process terminated unexpectedly.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Setup"],"technologies":["WIN-SETUP","Windows Setup Result","Windows Setup","Verified"],"aliases":["0x8007042B"]},{"id":54124,"title":"0x800F0923 - A driver or application is incompatible with the upgrade","category":"Windows","product":"Windows Setup / Feature Upgrade","tags":["WIN-SETUP","Windows Setup Result","Windows Setup","Verified"],"keywords":["0x800f0923","win","setup","windows","driver","application","incompatible","with","the","upgrade","operation","fails","and","may","produce","identifier","deployment","report","event","viewer","entry","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity","damaged"],"errorCode":"0x800F0923","eventId":"","severity":"Low","summary":"A driver or application is incompatible with the upgrade.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x800F0923 - A driver or application is incompatible with the upgrade.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A driver or application is incompatible with the upgrade.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x800F0923","identifiers":["0x800F0923"],"identifierType":"Windows Setup Result","namespace":"WIN-SETUP","platform":"Windows","component":"Windows Setup","eventSource":"Windows Setup","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x800F0923\nNamespace: WIN-SETUP\nType: Windows Setup Result\nPlatform: Windows\nProduct: Windows Setup / Feature Upgrade\nComponent: Windows Setup\nReview status: Verified\n\nMeaning: A driver or application is incompatible with the upgrade.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Setup"],"technologies":["WIN-SETUP","Windows Setup Result","Windows Setup","Verified"],"aliases":["0x800F0923"]},{"id":54125,"title":"0xC1900101 - 0x20017 - The upgrade rolled back during SafeOS or boot processing","category":"Windows","product":"Windows Setup / Feature Upgrade","tags":["WIN-SETUP","Windows Setup Result","Windows Setup","Verified"],"keywords":["0xc1900101","0x20017","win","setup","windows","the","upgrade","rolled","back","during","safeos","boot","processing","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions"],"errorCode":"0xC1900101 - 0x20017","eventId":"","severity":"Low","summary":"The upgrade rolled back during SafeOS or boot processing.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC1900101 - 0x20017 - The upgrade rolled back during SafeOS or boot processing.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The upgrade rolled back during SafeOS or boot processing.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC1900101 - 0x20017","identifiers":["0xC1900101 - 0x20017"],"identifierType":"Windows Setup Result","namespace":"WIN-SETUP","platform":"Windows","component":"Windows Setup","eventSource":"Windows Setup","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC1900101 - 0x20017\nNamespace: WIN-SETUP\nType: Windows Setup Result\nPlatform: Windows\nProduct: Windows Setup / Feature Upgrade\nComponent: Windows Setup\nReview status: Verified\n\nMeaning: The upgrade rolled back during SafeOS or boot processing.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Setup"],"technologies":["WIN-SETUP","Windows Setup Result","Windows Setup","Verified"],"aliases":["0xC1900101 - 0x20017"]},{"id":54126,"title":"0xC1900101 - 0x30018 - The upgrade rolled back during first boot","category":"Windows","product":"Windows Setup / Feature Upgrade","tags":["WIN-SETUP","Windows Setup Result","Windows Setup","Verified"],"keywords":["0xc1900101","0x30018","win","setup","windows","the","upgrade","rolled","back","during","first","boot","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers"],"errorCode":"0xC1900101 - 0x30018","eventId":"","severity":"Low","summary":"The upgrade rolled back during first boot.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC1900101 - 0x30018 - The upgrade rolled back during first boot.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The upgrade rolled back during first boot.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC1900101 - 0x30018","identifiers":["0xC1900101 - 0x30018"],"identifierType":"Windows Setup Result","namespace":"WIN-SETUP","platform":"Windows","component":"Windows Setup","eventSource":"Windows Setup","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC1900101 - 0x30018\nNamespace: WIN-SETUP\nType: Windows Setup Result\nPlatform: Windows\nProduct: Windows Setup / Feature Upgrade\nComponent: Windows Setup\nReview status: Verified\n\nMeaning: The upgrade rolled back during first boot.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Setup"],"technologies":["WIN-SETUP","Windows Setup Result","Windows Setup","Verified"],"aliases":["0xC1900101 - 0x30018"]},{"id":54127,"title":"0xC1900101 - 0x4000D - The upgrade rolled back during second boot or data migration","category":"Windows","product":"Windows Setup / Feature Upgrade","tags":["WIN-SETUP","Windows Setup Result","Windows Setup","Verified"],"keywords":["0xc1900101","0x4000d","win","setup","windows","the","upgrade","rolled","back","during","second","boot","data","migration","troubleshooting","requirements","run","review","setupdiag","before","manually","applying","generic","fixes","capture","complete","result","code","and","extended","identify","phase","downlevel","safeos","first","oobe","rollback","sources","panther","setupact"],"errorCode":"0xC1900101 - 0x4000D","eventId":"","severity":"High","summary":"The upgrade rolled back during second boot or data migration.\nWINDOWS SETUP TROUBLESHOOTING REQUIREMENTS:\n1. Run or review SetupDiag before manually applying generic fixes.\n2. Capture the complete result code and extended code.\n3. Identify the setup phase:\n- Downlevel\n- SafeOS\n- First boot\n- Second boot\n- OOBE\n- Rollback\n4. Review:\nC:\\$Windows.~BT\\Sources\\Panther\\setupact.log\nC:\\$Windows.~BT\\Sources\\Panther\\setuperr.log\nC:\\$Windows.~BT\\Sources\\Rollback\\setupact.log\nC:\\Windows\\Panther\\setupact.log\nC:\\Windows\\Logs\\MoSetup\\BlueBox.log\nsetupapi.dev.log\nSetupDiagResults.log\n5. Check:\n- Free disk space\n- BIOS or firmware\n- Storage controller\n- BitLocker\n- Third-party encryption\n- Drivers\n- Security software\n- USB peripherals\n- Language packs\n- User-profile migration\n- Unsupported processor or hardware\n- Pending reboot\n- Previous installation remnants\n6. Do not label every 0xC1900101 failure as a driver issue without reviewing\nthe extended code and logs.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC1900101 - 0x4000D - The upgrade rolled back during second boot or data migration.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The upgrade rolled back during second boot or data migration.\nWINDOWS SETUP TROUBLESHOOTING REQUIREMENTS:\n1. Run or review SetupDiag before manually applying generic fixes.\n2. Capture the complete result code and extended code.\n3. Identify the setup phase:\n- Downlevel\n- SafeOS\n- First boot\n- Second boot\n- OOBE\n- Rollback\n4. Review:\nC:\\$Windows.~BT\\Sources\\Panther\\setupact.log\nC:\\$Windows.~BT\\Sources\\Panther\\setuperr.log\nC:\\$Windows.~BT\\Sources\\Rollback\\setupact.log\nC:\\Windows\\Panther\\setupact.log\nC:\\Windows\\Logs\\MoSetup\\BlueBox.log\nsetupapi.dev.log\nSetupDiagResults.log\n5. Check:\n- Free disk space\n- BIOS or firmware\n- Storage controller\n- BitLocker\n- Third-party encryption\n- Drivers\n- Security software\n- USB peripherals\n- Language packs\n- User-profile migration\n- Unsupported processor or hardware\n- Pending reboot\n- Previous installation remnants\n6. Do not label every 0xC1900101 failure as a driver issue without reviewing\nthe extended code and logs.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC1900101 - 0x4000D","identifiers":["0xC1900101 - 0x4000D"],"identifierType":"Windows Setup Result","namespace":"WIN-SETUP","platform":"Windows","component":"Windows Setup","eventSource":"Windows Setup","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC1900101 - 0x4000D\nNamespace: WIN-SETUP\nType: Windows Setup Result\nPlatform: Windows\nProduct: Windows Setup / Feature Upgrade\nComponent: Windows Setup\nReview status: Verified\n\nMeaning: The upgrade rolled back during second boot or data migration.\nWINDOWS SETUP TROUBLESHOOTING REQUIREMENTS:\n1. Run or review SetupDiag before manually applying generic fixes.\n2. Capture the complete result code and extended code.\n3. Identify the setup phase:\n- Downlevel\n- SafeOS\n- First boot\n- Second boot\n- OOBE\n- Rollback\n4. Review:\nC:\\$Windows.~BT\\Sources\\Panther\\setupact.log\nC:\\$Windows.~BT\\Sources\\Panther\\setuperr.log\nC:\\$Windows.~BT\\Sources\\Rollback\\setupact.log\nC:\\Windows\\Panther\\setupact.log\nC:\\Windows\\Logs\\MoSetup\\BlueBox.log\nsetupapi.dev.log\nSetupDiagResults.log\n5. Check:\n- Free disk space\n- BIOS or firmware\n- Storage controller\n- BitLocker\n- Third-party encryption\n- Drivers\n- Security software\n- USB peripherals\n- Language packs\n- User-profile migration\n- Unsupported processor or hardware\n- Pending reboot\n- Previous installation remnants\n6. Do not label every 0xC1900101 failure as a driver issue without reviewing\nthe extended code and logs.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: setupact.log; setuperr.log; Panther and Rollback folders; compatibility reports\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Setup"],"technologies":["WIN-SETUP","Windows Setup Result","Windows Setup","Verified"],"aliases":["0xC1900101 - 0x4000D"]},{"id":54128,"title":"Event ID 7000 - A Windows service failed to start","category":"Windows Server","product":"Windows Service Control Manager","tags":["WIN-EVENT","Windows Event ID","Service Control Manager","Verified"],"keywords":["event","7000","win","service","control","manager","windows","failed","start","the","operation","fails","and","may","produce","identifier","application","deployment","report","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity"],"errorCode":"","eventId":"7000","severity":"High","summary":"A Windows service failed to start.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 7000 - A Windows service failed to start.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A Windows service failed to start.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"sc queryex \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"sc qc \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Service -Name \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-CimInstance Win32_Service -Filter \"Name='ServiceName'\"","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 7000","identifiers":["Event ID 7000"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"Service Control Manager","eventSource":"Service Control Manager","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 7000\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Service Control Manager\nComponent: Service Control Manager\nReview status: Verified\n\nMeaning: A Windows service failed to start.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Service Control Manager"],"technologies":["WIN-EVENT","Windows Event ID","Service Control Manager","Verified"],"aliases":["7000"]},{"id":54129,"title":"Event ID 7001 - A service dependency failed","category":"Windows Server","product":"Windows Service Control Manager","tags":["WIN-EVENT","Windows Event ID","Service Control Manager","Verified"],"keywords":["event","7001","win","service","control","manager","dependency","failed","the","operation","fails","and","may","produce","identifier","application","deployment","report","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity","damaged"],"errorCode":"","eventId":"7001","severity":"High","summary":"A service dependency failed.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 7001 - A service dependency failed.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A service dependency failed.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"sc queryex \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"sc qc \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Service -Name \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-CimInstance Win32_Service -Filter \"Name='ServiceName'\"","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 7001","identifiers":["Event ID 7001"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"Service Control Manager","eventSource":"Service Control Manager","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 7001\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Service Control Manager\nComponent: Service Control Manager\nReview status: Verified\n\nMeaning: A service dependency failed.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Service Control Manager"],"technologies":["WIN-EVENT","Windows Event ID","Service Control Manager","Verified"],"aliases":["7001"]},{"id":54130,"title":"Event ID 7009 - Windows timed out while waiting for a service connection","category":"Windows Server","product":"Windows Service Control Manager","tags":["WIN-EVENT","Windows Event ID","Service Control Manager","Verified"],"keywords":["event","7009","win","service","control","manager","windows","timed","out","while","waiting","for","connection","the","operation","fails","and","may","produce","identifier","application","deployment","report","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies"],"errorCode":"","eventId":"7009","severity":"High","summary":"Windows timed out while waiting for a service connection.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 7009 - Windows timed out while waiting for a service connection.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Windows timed out while waiting for a service connection.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"sc queryex \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"sc qc \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Service -Name \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-CimInstance Win32_Service -Filter \"Name='ServiceName'\"","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 7009","identifiers":["Event ID 7009"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"Service Control Manager","eventSource":"Service Control Manager","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 7009\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Service Control Manager\nComponent: Service Control Manager\nReview status: Verified\n\nMeaning: Windows timed out while waiting for a service connection.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Service Control Manager"],"technologies":["WIN-EVENT","Windows Event ID","Service Control Manager","Verified"],"aliases":["7009"]},{"id":54131,"title":"Event ID 7011 - Windows timed out while waiting for a service transaction response","category":"Windows Server","product":"Windows Service Control Manager","tags":["WIN-EVENT","Windows Event ID","Service Control Manager","Verified"],"keywords":["event","7011","win","service","control","manager","windows","timed","out","while","waiting","for","transaction","response","the","operation","fails","and","may","produce","identifier","application","deployment","report","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration"],"errorCode":"","eventId":"7011","severity":"Low","summary":"Windows timed out while waiting for a service transaction response.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 7011 - Windows timed out while waiting for a service transaction response.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Windows timed out while waiting for a service transaction response.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"sc queryex \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"sc qc \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Service -Name \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-CimInstance Win32_Service -Filter \"Name='ServiceName'\"","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 7011","identifiers":["Event ID 7011"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"Service Control Manager","eventSource":"Service Control Manager","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 7011\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Service Control Manager\nComponent: Service Control Manager\nReview status: Verified\n\nMeaning: Windows timed out while waiting for a service transaction response.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Service Control Manager"],"technologies":["WIN-EVENT","Windows Event ID","Service Control Manager","Verified"],"aliases":["7011"]},{"id":54132,"title":"Event ID 7023 - A service terminated with an error","category":"Windows Server","product":"Windows Service Control Manager","tags":["WIN-EVENT","Windows Event ID","Service Control Manager","Verified"],"keywords":["event","7023","win","service","control","manager","terminated","with","error","the","operation","fails","and","may","produce","identifier","application","deployment","report","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity"],"errorCode":"","eventId":"7023","severity":"Low","summary":"A service terminated with an error.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 7023 - A service terminated with an error.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A service terminated with an error.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"sc queryex \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"sc qc \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Service -Name \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-CimInstance Win32_Service -Filter \"Name='ServiceName'\"","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 7023","identifiers":["Event ID 7023"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"Service Control Manager","eventSource":"Service Control Manager","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 7023\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Service Control Manager\nComponent: Service Control Manager\nReview status: Verified\n\nMeaning: A service terminated with an error.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Service Control Manager"],"technologies":["WIN-EVENT","Windows Event ID","Service Control Manager","Verified"],"aliases":["7023"]},{"id":54133,"title":"Event ID 7024 - A service terminated with a service-specific error","category":"Windows Server","product":"Windows Service Control Manager","tags":["WIN-EVENT","Windows Event ID","Service Control Manager","Verified"],"keywords":["event","7024","win","service","control","manager","terminated","with","specific","error","the","operation","fails","and","may","produce","identifier","application","deployment","report","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services"],"errorCode":"","eventId":"7024","severity":"Low","summary":"A service terminated with a service-specific error.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 7024 - A service terminated with a service-specific error.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A service terminated with a service-specific error.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"sc queryex \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"sc qc \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Service -Name \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-CimInstance Win32_Service -Filter \"Name='ServiceName'\"","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 7024","identifiers":["Event ID 7024"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"Service Control Manager","eventSource":"Service Control Manager","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 7024\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Service Control Manager\nComponent: Service Control Manager\nReview status: Verified\n\nMeaning: A service terminated with a service-specific error.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Service Control Manager"],"technologies":["WIN-EVENT","Windows Event ID","Service Control Manager","Verified"],"aliases":["7024"]},{"id":54134,"title":"Event ID 7031 - A service terminated unexpectedly and recovery action may be required","category":"Windows Server","product":"Windows Service Control Manager","tags":["WIN-EVENT","Windows Event ID","Service Control Manager","Verified"],"keywords":["event","7031","win","service","control","manager","terminated","unexpectedly","and","recovery","action","may","required","the","operation","fails","produce","identifier","application","deployment","report","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers"],"errorCode":"","eventId":"7031","severity":"Low","summary":"A service terminated unexpectedly and recovery action may be required.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 7031 - A service terminated unexpectedly and recovery action may be required.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A service terminated unexpectedly and recovery action may be required.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"sc queryex \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"sc qc \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Service -Name \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-CimInstance Win32_Service -Filter \"Name='ServiceName'\"","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 7031","identifiers":["Event ID 7031"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"Service Control Manager","eventSource":"Service Control Manager","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 7031\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Service Control Manager\nComponent: Service Control Manager\nReview status: Verified\n\nMeaning: A service terminated unexpectedly and recovery action may be required.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Service Control Manager"],"technologies":["WIN-EVENT","Windows Event ID","Service Control Manager","Verified"],"aliases":["7031"]},{"id":54135,"title":"Event ID 7034 - A service terminated unexpectedly","category":"Windows Server","product":"Windows Service Control Manager","tags":["WIN-EVENT","Windows Event ID","Service Control Manager","Verified"],"keywords":["event","7034","win","service","control","manager","terminated","unexpectedly","the","operation","fails","and","may","produce","identifier","application","deployment","report","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity","damaged"],"errorCode":"","eventId":"7034","severity":"Low","summary":"A service terminated unexpectedly.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 7034 - A service terminated unexpectedly.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A service terminated unexpectedly.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"sc queryex \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"sc qc \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Service -Name \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-CimInstance Win32_Service -Filter \"Name='ServiceName'\"","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 7034","identifiers":["Event ID 7034"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"Service Control Manager","eventSource":"Service Control Manager","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 7034\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Service Control Manager\nComponent: Service Control Manager\nReview status: Verified\n\nMeaning: A service terminated unexpectedly.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Service Control Manager"],"technologies":["WIN-EVENT","Windows Event ID","Service Control Manager","Verified"],"aliases":["7034"]},{"id":54136,"title":"Error 1053 - The service did not respond to the start or control request within the allowed\ntime","category":"Windows Server","product":"Windows Service Control Manager","tags":["WIN-SERVICE","Windows Service Error","Service Control Manager","Verified"],"keywords":["error","1053","win","service","control","manager","the","did","not","respond","start","request","within","allowed","time","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include"],"errorCode":"Error 1053","eventId":"","severity":"Low","summary":"The service did not respond to the start or control request within the allowed\ntime.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Error 1053 - The service did not respond to the start or control request within the allowed\ntime.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The service did not respond to the start or control request within the allowed\ntime.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"sc queryex \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"sc qc \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Service -Name \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-CimInstance Win32_Service -Filter \"Name='ServiceName'\"","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Error 1053","identifiers":["Error 1053"],"identifierType":"Windows Service Error","namespace":"WIN-SERVICE","platform":"Windows","component":"Service Control Manager","eventSource":"Service Control Manager","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"System log, Source: Service Control Manager; service-specific application logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Error 1053\nNamespace: WIN-SERVICE\nType: Windows Service Error\nPlatform: Windows\nProduct: Windows Service Control Manager\nComponent: Service Control Manager\nReview status: Verified\n\nMeaning: The service did not respond to the start or control request within the allowed\ntime.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: System log, Source: Service Control Manager; service-specific application logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Service Control Manager"],"technologies":["WIN-SERVICE","Windows Service Error","Service Control Manager","Verified"],"aliases":["Error 1053"]},{"id":54137,"title":"Error 1060 - The specified service does not exist","category":"Windows Server","product":"Windows Service Control Manager","tags":["WIN-SERVICE","Windows Service Error","Service Control Manager","Verified"],"keywords":["error","1060","win","service","control","manager","the","specified","does","not","exist","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers"],"errorCode":"Error 1060","eventId":"","severity":"Low","summary":"The specified service does not exist.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Error 1060 - The specified service does not exist.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The specified service does not exist.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"sc queryex \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"sc qc \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Service -Name \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-CimInstance Win32_Service -Filter \"Name='ServiceName'\"","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Error 1060","identifiers":["Error 1060"],"identifierType":"Windows Service Error","namespace":"WIN-SERVICE","platform":"Windows","component":"Service Control Manager","eventSource":"Service Control Manager","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"System log, Source: Service Control Manager; service-specific application logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Error 1060\nNamespace: WIN-SERVICE\nType: Windows Service Error\nPlatform: Windows\nProduct: Windows Service Control Manager\nComponent: Service Control Manager\nReview status: Verified\n\nMeaning: The specified service does not exist.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: System log, Source: Service Control Manager; service-specific application logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Service Control Manager"],"technologies":["WIN-SERVICE","Windows Service Error","Service Control Manager","Verified"],"aliases":["Error 1060"]},{"id":54138,"title":"Error 1067 - The service process terminated unexpectedly","category":"Windows Server","product":"Windows Service Control Manager","tags":["WIN-SERVICE","Windows Service Error","Service Control Manager","Verified"],"keywords":["error","1067","win","service","control","manager","the","process","terminated","unexpectedly","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services"],"errorCode":"Error 1067","eventId":"","severity":"Low","summary":"The service process terminated unexpectedly.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Error 1067 - The service process terminated unexpectedly.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The service process terminated unexpectedly.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"sc queryex \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"sc qc \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Service -Name \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-CimInstance Win32_Service -Filter \"Name='ServiceName'\"","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Error 1067","identifiers":["Error 1067"],"identifierType":"Windows Service Error","namespace":"WIN-SERVICE","platform":"Windows","component":"Service Control Manager","eventSource":"Service Control Manager","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"System log, Source: Service Control Manager; service-specific application logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Error 1067\nNamespace: WIN-SERVICE\nType: Windows Service Error\nPlatform: Windows\nProduct: Windows Service Control Manager\nComponent: Service Control Manager\nReview status: Verified\n\nMeaning: The service process terminated unexpectedly.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: System log, Source: Service Control Manager; service-specific application logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Service Control Manager"],"technologies":["WIN-SERVICE","Windows Service Error","Service Control Manager","Verified"],"aliases":["Error 1067"]},{"id":54139,"title":"Error 1068 - A dependency service or dependency group failed to start","category":"Windows Server","product":"Windows Service Control Manager","tags":["WIN-SERVICE","Windows Service Error","Service Control Manager","Verified"],"keywords":["error","1068","win","service","control","manager","dependency","group","failed","start","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers"],"errorCode":"Error 1068","eventId":"","severity":"High","summary":"A dependency service or dependency group failed to start.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Error 1068 - A dependency service or dependency group failed to start.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A dependency service or dependency group failed to start.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"sc queryex \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"sc qc \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Service -Name \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-CimInstance Win32_Service -Filter \"Name='ServiceName'\"","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Error 1068","identifiers":["Error 1068"],"identifierType":"Windows Service Error","namespace":"WIN-SERVICE","platform":"Windows","component":"Service Control Manager","eventSource":"Service Control Manager","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"System log, Source: Service Control Manager; service-specific application logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Error 1068\nNamespace: WIN-SERVICE\nType: Windows Service Error\nPlatform: Windows\nProduct: Windows Service Control Manager\nComponent: Service Control Manager\nReview status: Verified\n\nMeaning: A dependency service or dependency group failed to start.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: System log, Source: Service Control Manager; service-specific application logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Service Control Manager"],"technologies":["WIN-SERVICE","Windows Service Error","Service Control Manager","Verified"],"aliases":["Error 1068"]},{"id":54140,"title":"Error 1079 - The service account differs from other services running in the same process","category":"Windows Server","product":"Windows Service Control Manager","tags":["WIN-SERVICE","Windows Service Error","Service Control Manager","Verified"],"keywords":["error","1079","win","service","control","manager","the","account","differs","from","other","services","running","same","process","troubleshooting","requirements","collect","queryex","servicename","get","name","ciminstance","win32","filter","check","event","viewer","windows","logs","system","source","not","terminate","without","identifying","pid","sharing","dependencies","production"],"errorCode":"Error 1079","eventId":"","severity":"Low","summary":"The service account differs from other services running in the same process.\nSERVICE TROUBLESHOOTING REQUIREMENTS:\nCollect:\nsc queryex \"ServiceName\"\nsc qc \"ServiceName\"\nGet-Service -Name \"ServiceName\"\nGet-CimInstance Win32_Service -Filter \"Name='ServiceName'\"\nCheck:\nEvent Viewer > Windows Logs > System\nSource: Service Control Manager\nDo not terminate a service process without identifying:\n- The service PID\n- Other services sharing the process\n- The service dependencies\n- Production impact\n- Recovery behavior\n- Whether a restart is safer","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Error 1079 - The service account differs from other services running in the same process.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The service account differs from other services running in the same process.\nSERVICE TROUBLESHOOTING REQUIREMENTS:\nCollect:\nsc queryex \"ServiceName\"\nsc qc \"ServiceName\"\nGet-Service -Name \"ServiceName\"\nGet-CimInstance Win32_Service -Filter \"Name='ServiceName'\"\nCheck:\nEvent Viewer > Windows Logs > System\nSource: Service Control Manager\nDo not terminate a service process without identifying:\n- The service PID\n- Other services sharing the process\n- The service dependencies\n- Production impact\n- Recovery behavior\n- Whether a restart is safer\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"sc queryex \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"sc qc \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Service -Name \"ServiceName\"","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-CimInstance Win32_Service -Filter \"Name='ServiceName'\"","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Error 1079","identifiers":["Error 1079"],"identifierType":"Windows Service Error","namespace":"WIN-SERVICE","platform":"Windows","component":"Service Control Manager","eventSource":"Service Control Manager","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"System log, Source: Service Control Manager; service-specific application logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Error 1079\nNamespace: WIN-SERVICE\nType: Windows Service Error\nPlatform: Windows\nProduct: Windows Service Control Manager\nComponent: Service Control Manager\nReview status: Verified\n\nMeaning: The service account differs from other services running in the same process.\nSERVICE TROUBLESHOOTING REQUIREMENTS:\nCollect:\nsc queryex \"ServiceName\"\nsc qc \"ServiceName\"\nGet-Service -Name \"ServiceName\"\nGet-CimInstance Win32_Service -Filter \"Name='ServiceName'\"\nCheck:\nEvent Viewer > Windows Logs > System\nSource: Service Control Manager\nDo not terminate a service process without identifying:\n- The service PID\n- Other services sharing the process\n- The service dependencies\n- Production impact\n- Recovery behavior\n- Whether a restart is safer\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: System log, Source: Service Control Manager; service-specific application logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Service Control Manager"],"technologies":["WIN-SERVICE","Windows Service Error","Service Control Manager","Verified"],"aliases":["Error 1079"]},{"id":54141,"title":"0x80042301 - Volume Shadow Copy Service is in an invalid state","category":"Backups","product":"Volume Shadow Copy Service","tags":["WIN-VSS","VSS Error","VSS","Verified"],"keywords":["0x80042301","win","vss","volume","shadow","copy","service","invalid","state","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services"],"errorCode":"0x80042301","eventId":"","severity":"High","summary":"Volume Shadow Copy Service is in an invalid state.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Identify the failed writer and owning workload.\n2. Check VSS and application logs.\n3. Confirm backup status, free space, and provider health.\n4. Correct the specific writer or provider issue and run a test backup.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x80042301 - Volume Shadow Copy Service is in an invalid state.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Volume Shadow Copy Service is in an invalid state.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"vssadmin list writers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list providers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadows","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadowstorage","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x80042301","identifiers":["0x80042301"],"identifierType":"VSS Error","namespace":"WIN-VSS","platform":"Windows","component":"VSS","eventSource":"VSS","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Identify the failed writer and owning workload.\n2. Check VSS and application logs.\n3. Confirm backup status, free space, and provider health.\n4. Correct the specific writer or provider issue and run a test backup.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not delete snapshots, resize shadow storage, or restart every service before confirming backup and restore requirements.","logsToCheck":"Application and System logs; VSS and VolSnap events; backup-application logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x80042301\nNamespace: WIN-VSS\nType: VSS Error\nPlatform: Windows\nProduct: Volume Shadow Copy Service\nComponent: VSS\nReview status: Verified\n\nMeaning: Volume Shadow Copy Service is in an invalid state.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Application and System logs; VSS and VolSnap events; backup-application logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Volume Shadow Copy Service"],"technologies":["WIN-VSS","VSS Error","VSS","Verified"],"aliases":["0x80042301"]},{"id":54142,"title":"0x80042302 - Volume Shadow Copy Service is unavailable","category":"Backups","product":"Volume Shadow Copy Service","tags":["WIN-VSS","VSS Error","VSS","Verified"],"keywords":["0x80042302","win","vss","volume","shadow","copy","service","unavailable","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity"],"errorCode":"0x80042302","eventId":"","severity":"High","summary":"Volume Shadow Copy Service is unavailable.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Identify the failed writer and owning workload.\n2. Check VSS and application logs.\n3. Confirm backup status, free space, and provider health.\n4. Correct the specific writer or provider issue and run a test backup.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x80042302 - Volume Shadow Copy Service is unavailable.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Volume Shadow Copy Service is unavailable.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"vssadmin list writers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list providers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadows","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadowstorage","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x80042302","identifiers":["0x80042302"],"identifierType":"VSS Error","namespace":"WIN-VSS","platform":"Windows","component":"VSS","eventSource":"VSS","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Identify the failed writer and owning workload.\n2. Check VSS and application logs.\n3. Confirm backup status, free space, and provider health.\n4. Correct the specific writer or provider issue and run a test backup.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not delete snapshots, resize shadow storage, or restart every service before confirming backup and restore requirements.","logsToCheck":"Application and System logs; VSS and VolSnap events; backup-application logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x80042302\nNamespace: WIN-VSS\nType: VSS Error\nPlatform: Windows\nProduct: Volume Shadow Copy Service\nComponent: VSS\nReview status: Verified\n\nMeaning: Volume Shadow Copy Service is unavailable.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Application and System logs; VSS and VolSnap events; backup-application logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Volume Shadow Copy Service"],"technologies":["WIN-VSS","VSS Error","VSS","Verified"],"aliases":["0x80042302"]},{"id":54143,"title":"0x80042306 - A shadow-copy provider encountered an error","category":"Backups","product":"Volume Shadow Copy Service","tags":["WIN-VSS","VSS Error","VSS","Verified"],"keywords":["0x80042306","win","vss","shadow","copy","provider","encountered","error","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity"],"errorCode":"0x80042306","eventId":"","severity":"High","summary":"A shadow-copy provider encountered an error.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Identify the failed writer and owning workload.\n2. Check VSS and application logs.\n3. Confirm backup status, free space, and provider health.\n4. Correct the specific writer or provider issue and run a test backup.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x80042306 - A shadow-copy provider encountered an error.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A shadow-copy provider encountered an error.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"vssadmin list writers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list providers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadows","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadowstorage","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x80042306","identifiers":["0x80042306"],"identifierType":"VSS Error","namespace":"WIN-VSS","platform":"Windows","component":"VSS","eventSource":"VSS","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Identify the failed writer and owning workload.\n2. Check VSS and application logs.\n3. Confirm backup status, free space, and provider health.\n4. Correct the specific writer or provider issue and run a test backup.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not delete snapshots, resize shadow storage, or restart every service before confirming backup and restore requirements.","logsToCheck":"Application and System logs; VSS and VolSnap events; backup-application logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x80042306\nNamespace: WIN-VSS\nType: VSS Error\nPlatform: Windows\nProduct: Volume Shadow Copy Service\nComponent: VSS\nReview status: Verified\n\nMeaning: A shadow-copy provider encountered an error.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Application and System logs; VSS and VolSnap events; backup-application logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Volume Shadow Copy Service"],"technologies":["WIN-VSS","VSS Error","VSS","Verified"],"aliases":["0x80042306"]},{"id":54144,"title":"0x80042308 - The requested VSS object was not found","category":"Backups","product":"Volume Shadow Copy Service","tags":["WIN-VSS","VSS Error","VSS","Verified"],"keywords":["0x80042308","win","vss","the","requested","object","was","not","found","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity"],"errorCode":"0x80042308","eventId":"","severity":"High","summary":"The requested VSS object was not found.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Identify the failed writer and owning workload.\n2. Check VSS and application logs.\n3. Confirm backup status, free space, and provider health.\n4. Correct the specific writer or provider issue and run a test backup.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x80042308 - The requested VSS object was not found.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The requested VSS object was not found.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"vssadmin list writers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list providers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadows","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadowstorage","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x80042308","identifiers":["0x80042308"],"identifierType":"VSS Error","namespace":"WIN-VSS","platform":"Windows","component":"VSS","eventSource":"VSS","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Identify the failed writer and owning workload.\n2. Check VSS and application logs.\n3. Confirm backup status, free space, and provider health.\n4. Correct the specific writer or provider issue and run a test backup.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not delete snapshots, resize shadow storage, or restart every service before confirming backup and restore requirements.","logsToCheck":"Application and System logs; VSS and VolSnap events; backup-application logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x80042308\nNamespace: WIN-VSS\nType: VSS Error\nPlatform: Windows\nProduct: Volume Shadow Copy Service\nComponent: VSS\nReview status: Verified\n\nMeaning: The requested VSS object was not found.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Application and System logs; VSS and VolSnap events; backup-application logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Volume Shadow Copy Service"],"technologies":["WIN-VSS","VSS Error","VSS","Verified"],"aliases":["0x80042308"]},{"id":54145,"title":"0x8004230F - An unexpected shadow-copy provider error occurred","category":"Backups","product":"Volume Shadow Copy Service","tags":["WIN-VSS","VSS Error","VSS","Verified"],"keywords":["0x8004230f","win","vss","unexpected","shadow","copy","provider","error","occurred","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services"],"errorCode":"0x8004230F","eventId":"","severity":"High","summary":"An unexpected shadow-copy provider error occurred.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Identify the failed writer and owning workload.\n2. Check VSS and application logs.\n3. Confirm backup status, free space, and provider health.\n4. Correct the specific writer or provider issue and run a test backup.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x8004230F - An unexpected shadow-copy provider error occurred.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: An unexpected shadow-copy provider error occurred.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"vssadmin list writers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list providers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadows","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadowstorage","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x8004230F","identifiers":["0x8004230F"],"identifierType":"VSS Error","namespace":"WIN-VSS","platform":"Windows","component":"VSS","eventSource":"VSS","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Identify the failed writer and owning workload.\n2. Check VSS and application logs.\n3. Confirm backup status, free space, and provider health.\n4. Correct the specific writer or provider issue and run a test backup.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not delete snapshots, resize shadow storage, or restart every service before confirming backup and restore requirements.","logsToCheck":"Application and System logs; VSS and VolSnap events; backup-application logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x8004230F\nNamespace: WIN-VSS\nType: VSS Error\nPlatform: Windows\nProduct: Volume Shadow Copy Service\nComponent: VSS\nReview status: Verified\n\nMeaning: An unexpected shadow-copy provider error occurred.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Application and System logs; VSS and VolSnap events; backup-application logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Volume Shadow Copy Service"],"technologies":["WIN-VSS","VSS Error","VSS","Verified"],"aliases":["0x8004230F"]},{"id":54146,"title":"0x80042312 - The maximum number of snapshots was reached","category":"Backups","product":"Volume Shadow Copy Service","tags":["WIN-VSS","VSS Error","VSS","Verified"],"keywords":["0x80042312","win","vss","the","maximum","number","snapshots","was","reached","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity"],"errorCode":"0x80042312","eventId":"","severity":"High","summary":"The maximum number of snapshots was reached.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Identify the failed writer and owning workload.\n2. Check VSS and application logs.\n3. Confirm backup status, free space, and provider health.\n4. Correct the specific writer or provider issue and run a test backup.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x80042312 - The maximum number of snapshots was reached.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The maximum number of snapshots was reached.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"vssadmin list writers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list providers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadows","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadowstorage","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x80042312","identifiers":["0x80042312"],"identifierType":"VSS Error","namespace":"WIN-VSS","platform":"Windows","component":"VSS","eventSource":"VSS","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Identify the failed writer and owning workload.\n2. Check VSS and application logs.\n3. Confirm backup status, free space, and provider health.\n4. Correct the specific writer or provider issue and run a test backup.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not delete snapshots, resize shadow storage, or restart every service before confirming backup and restore requirements.","logsToCheck":"Application and System logs; VSS and VolSnap events; backup-application logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x80042312\nNamespace: WIN-VSS\nType: VSS Error\nPlatform: Windows\nProduct: Volume Shadow Copy Service\nComponent: VSS\nReview status: Verified\n\nMeaning: The maximum number of snapshots was reached.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Application and System logs; VSS and VolSnap events; backup-application logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Volume Shadow Copy Service"],"technologies":["WIN-VSS","VSS Error","VSS","Verified"],"aliases":["0x80042312"]},{"id":54147,"title":"0x80042316 - Another shadow-copy operation is already in progress","category":"Backups","product":"Volume Shadow Copy Service","tags":["WIN-VSS","VSS Error","VSS","Verified"],"keywords":["0x80042316","win","vss","another","shadow","copy","operation","already","progress","the","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity"],"errorCode":"0x80042316","eventId":"","severity":"High","summary":"Another shadow-copy operation is already in progress.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Identify the failed writer and owning workload.\n2. Check VSS and application logs.\n3. Confirm backup status, free space, and provider health.\n4. Correct the specific writer or provider issue and run a test backup.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x80042316 - Another shadow-copy operation is already in progress.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Another shadow-copy operation is already in progress.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"vssadmin list writers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list providers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadows","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadowstorage","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x80042316","identifiers":["0x80042316"],"identifierType":"VSS Error","namespace":"WIN-VSS","platform":"Windows","component":"VSS","eventSource":"VSS","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Identify the failed writer and owning workload.\n2. Check VSS and application logs.\n3. Confirm backup status, free space, and provider health.\n4. Correct the specific writer or provider issue and run a test backup.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not delete snapshots, resize shadow storage, or restart every service before confirming backup and restore requirements.","logsToCheck":"Application and System logs; VSS and VolSnap events; backup-application logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x80042316\nNamespace: WIN-VSS\nType: VSS Error\nPlatform: Windows\nProduct: Volume Shadow Copy Service\nComponent: VSS\nReview status: Verified\n\nMeaning: Another shadow-copy operation is already in progress.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Application and System logs; VSS and VolSnap events; backup-application logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Volume Shadow Copy Service"],"technologies":["WIN-VSS","VSS Error","VSS","Verified"],"aliases":["0x80042316"]},{"id":54148,"title":"0x80042318 - A required VSS writer was not found","category":"Backups","product":"Volume Shadow Copy Service","tags":["WIN-VSS","VSS Error","VSS","Verified"],"keywords":["0x80042318","win","vss","required","writer","was","not","found","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity"],"errorCode":"0x80042318","eventId":"","severity":"High","summary":"A required VSS writer was not found.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Identify the failed writer and owning workload.\n2. Check VSS and application logs.\n3. Confirm backup status, free space, and provider health.\n4. Correct the specific writer or provider issue and run a test backup.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x80042318 - A required VSS writer was not found.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A required VSS writer was not found.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"vssadmin list writers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list providers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadows","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadowstorage","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x80042318","identifiers":["0x80042318"],"identifierType":"VSS Error","namespace":"WIN-VSS","platform":"Windows","component":"VSS","eventSource":"VSS","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Identify the failed writer and owning workload.\n2. Check VSS and application logs.\n3. Confirm backup status, free space, and provider health.\n4. Correct the specific writer or provider issue and run a test backup.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not delete snapshots, resize shadow storage, or restart every service before confirming backup and restore requirements.","logsToCheck":"Application and System logs; VSS and VolSnap events; backup-application logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x80042318\nNamespace: WIN-VSS\nType: VSS Error\nPlatform: Windows\nProduct: Volume Shadow Copy Service\nComponent: VSS\nReview status: Verified\n\nMeaning: A required VSS writer was not found.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Application and System logs; VSS and VolSnap events; backup-application logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Volume Shadow Copy Service"],"technologies":["WIN-VSS","VSS Error","VSS","Verified"],"aliases":["0x80042318"]},{"id":54149,"title":"0x800423F0 - The shadow-copy set contains only a subset of required volumes","category":"Backups","product":"Volume Shadow Copy Service","tags":["WIN-VSS","VSS Error","VSS","Verified"],"keywords":["0x800423f0","win","vss","the","shadow","copy","set","contains","only","subset","required","volumes","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions"],"errorCode":"0x800423F0","eventId":"","severity":"High","summary":"The shadow-copy set contains only a subset of required volumes.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Identify the failed writer and owning workload.\n2. Check VSS and application logs.\n3. Confirm backup status, free space, and provider health.\n4. Correct the specific writer or provider issue and run a test backup.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x800423F0 - The shadow-copy set contains only a subset of required volumes.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The shadow-copy set contains only a subset of required volumes.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"vssadmin list writers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list providers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadows","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadowstorage","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x800423F0","identifiers":["0x800423F0"],"identifierType":"VSS Error","namespace":"WIN-VSS","platform":"Windows","component":"VSS","eventSource":"VSS","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Identify the failed writer and owning workload.\n2. Check VSS and application logs.\n3. Confirm backup status, free space, and provider health.\n4. Correct the specific writer or provider issue and run a test backup.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not delete snapshots, resize shadow storage, or restart every service before confirming backup and restore requirements.","logsToCheck":"Application and System logs; VSS and VolSnap events; backup-application logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x800423F0\nNamespace: WIN-VSS\nType: VSS Error\nPlatform: Windows\nProduct: Volume Shadow Copy Service\nComponent: VSS\nReview status: Verified\n\nMeaning: The shadow-copy set contains only a subset of required volumes.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Application and System logs; VSS and VolSnap events; backup-application logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Volume Shadow Copy Service"],"technologies":["WIN-VSS","VSS Error","VSS","Verified"],"aliases":["0x800423F0"]},{"id":54150,"title":"0x800423F2 - A VSS writer timed out","category":"Backups","product":"Volume Shadow Copy Service","tags":["WIN-VSS","VSS Error","VSS","Verified"],"keywords":["0x800423f2","win","vss","writer","timed","out","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity","damaged","state"],"errorCode":"0x800423F2","eventId":"","severity":"High","summary":"A VSS writer timed out.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Identify the failed writer and owning workload.\n2. Check VSS and application logs.\n3. Confirm backup status, free space, and provider health.\n4. Correct the specific writer or provider issue and run a test backup.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x800423F2 - A VSS writer timed out.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A VSS writer timed out.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"vssadmin list writers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list providers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadows","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadowstorage","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x800423F2","identifiers":["0x800423F2"],"identifierType":"VSS Error","namespace":"WIN-VSS","platform":"Windows","component":"VSS","eventSource":"VSS","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Identify the failed writer and owning workload.\n2. Check VSS and application logs.\n3. Confirm backup status, free space, and provider health.\n4. Correct the specific writer or provider issue and run a test backup.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not delete snapshots, resize shadow storage, or restart every service before confirming backup and restore requirements.","logsToCheck":"Application and System logs; VSS and VolSnap events; backup-application logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x800423F2\nNamespace: WIN-VSS\nType: VSS Error\nPlatform: Windows\nProduct: Volume Shadow Copy Service\nComponent: VSS\nReview status: Verified\n\nMeaning: A VSS writer timed out.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Application and System logs; VSS and VolSnap events; backup-application logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Volume Shadow Copy Service"],"technologies":["WIN-VSS","VSS Error","VSS","Verified"],"aliases":["0x800423F2"]},{"id":54151,"title":"0x800423F3 - A VSS writer experienced a transient error","category":"Backups","product":"Volume Shadow Copy Service","tags":["WIN-VSS","VSS Error","VSS","Verified"],"keywords":["0x800423f3","win","vss","writer","experienced","transient","error","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity","damaged"],"errorCode":"0x800423F3","eventId":"","severity":"High","summary":"A VSS writer experienced a transient error.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Identify the failed writer and owning workload.\n2. Check VSS and application logs.\n3. Confirm backup status, free space, and provider health.\n4. Correct the specific writer or provider issue and run a test backup.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x800423F3 - A VSS writer experienced a transient error.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A VSS writer experienced a transient error.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"vssadmin list writers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list providers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadows","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadowstorage","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x800423F3","identifiers":["0x800423F3"],"identifierType":"VSS Error","namespace":"WIN-VSS","platform":"Windows","component":"VSS","eventSource":"VSS","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Identify the failed writer and owning workload.\n2. Check VSS and application logs.\n3. Confirm backup status, free space, and provider health.\n4. Correct the specific writer or provider issue and run a test backup.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not delete snapshots, resize shadow storage, or restart every service before confirming backup and restore requirements.","logsToCheck":"Application and System logs; VSS and VolSnap events; backup-application logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x800423F3\nNamespace: WIN-VSS\nType: VSS Error\nPlatform: Windows\nProduct: Volume Shadow Copy Service\nComponent: VSS\nReview status: Verified\n\nMeaning: A VSS writer experienced a transient error.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Application and System logs; VSS and VolSnap events; backup-application logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Volume Shadow Copy Service"],"technologies":["WIN-VSS","VSS Error","VSS","Verified"],"aliases":["0x800423F3"]},{"id":54152,"title":"0x800423F4 - A VSS writer experienced a non-transient error","category":"Backups","product":"Volume Shadow Copy Service","tags":["WIN-VSS","VSS Error","VSS","Verified"],"keywords":["0x800423f4","win","vss","writer","experienced","non","transient","error","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity"],"errorCode":"0x800423F4","eventId":"","severity":"High","summary":"A VSS writer experienced a non-transient error.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Identify the failed writer and owning workload.\n2. Check VSS and application logs.\n3. Confirm backup status, free space, and provider health.\n4. Correct the specific writer or provider issue and run a test backup.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x800423F4 - A VSS writer experienced a non-transient error.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A VSS writer experienced a non-transient error.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"vssadmin list writers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list providers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadows","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadowstorage","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x800423F4","identifiers":["0x800423F4"],"identifierType":"VSS Error","namespace":"WIN-VSS","platform":"Windows","component":"VSS","eventSource":"VSS","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Identify the failed writer and owning workload.\n2. Check VSS and application logs.\n3. Confirm backup status, free space, and provider health.\n4. Correct the specific writer or provider issue and run a test backup.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not delete snapshots, resize shadow storage, or restart every service before confirming backup and restore requirements.","logsToCheck":"Application and System logs; VSS and VolSnap events; backup-application logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x800423F4\nNamespace: WIN-VSS\nType: VSS Error\nPlatform: Windows\nProduct: Volume Shadow Copy Service\nComponent: VSS\nReview status: Verified\n\nMeaning: A VSS writer experienced a non-transient error.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Application and System logs; VSS and VolSnap events; backup-application logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Volume Shadow Copy Service"],"technologies":["WIN-VSS","VSS Error","VSS","Verified"],"aliases":["0x800423F4"]},{"id":54153,"title":"Event ID 8193 - VSS encountered an unexpected error","category":"Backups","product":"Volume Shadow Copy Service","tags":["WIN-EVENT","Windows Event ID","VSS","Verified"],"keywords":["event","8193","win","vss","encountered","unexpected","error","the","operation","fails","and","may","produce","identifier","application","deployment","report","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity","damaged","state"],"errorCode":"","eventId":"8193","severity":"High","summary":"VSS encountered an unexpected error.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 8193 - VSS encountered an unexpected error.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: VSS encountered an unexpected error.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"vssadmin list writers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list providers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadows","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadowstorage","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 8193","identifiers":["Event ID 8193"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"VSS","eventSource":"VSS","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 8193\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Volume Shadow Copy Service\nComponent: VSS\nReview status: Verified\n\nMeaning: VSS encountered an unexpected error.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Volume Shadow Copy Service"],"technologies":["WIN-EVENT","Windows Event ID","VSS","Verified"],"aliases":["8193"]},{"id":54154,"title":"Event ID 12289 - A Volume Shadow Copy Service operation failed","category":"Backups","product":"Volume Shadow Copy Service","tags":["WIN-EVENT","Windows Event ID","VSS","Verified"],"keywords":["event","12289","win","vss","volume","shadow","copy","service","operation","failed","the","fails","and","may","produce","identifier","application","deployment","report","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity"],"errorCode":"","eventId":"12289","severity":"High","summary":"A Volume Shadow Copy Service operation failed.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 12289 - A Volume Shadow Copy Service operation failed.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A Volume Shadow Copy Service operation failed.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"vssadmin list writers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list providers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadows","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadowstorage","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 12289","identifiers":["Event ID 12289"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"VSS","eventSource":"VSS","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 12289\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Volume Shadow Copy Service\nComponent: VSS\nReview status: Verified\n\nMeaning: A Volume Shadow Copy Service operation failed.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Volume Shadow Copy Service"],"technologies":["WIN-EVENT","Windows Event ID","VSS","Verified"],"aliases":["12289"]},{"id":54155,"title":"Event ID 513 - A System Writer, Cryptographic Services, or backup-related operation failed","category":"Backups","product":"Volume Shadow Copy Service","tags":["WIN-EVENT","Windows Event ID","VSS","Verified"],"keywords":["event","513","win","vss","system","writer","cryptographic","services","backup","related","operation","failed","troubleshooting","requirements","collect","vssadmin","list","writers","providers","shadows","shadowstorage","identify","the","exact","registry","wmi","ntds","dfs","replication","sql","server","iis","metabase","exchange","hyper","not","restart","every","service","indiscriminately"],"errorCode":"","eventId":"513","severity":"High","summary":"A System Writer, Cryptographic Services, or backup-related operation failed.\nVSS TROUBLESHOOTING REQUIREMENTS:\nCollect:\nvssadmin list writers\nvssadmin list providers\nvssadmin list shadows\nvssadmin list shadowstorage\nIdentify the exact failed writer:\n- System Writer\n- Registry Writer\n- WMI Writer\n- NTDS Writer\n- DFS Replication Writer\n- SQL Server Writer\n- IIS Metabase Writer\n- Exchange Writer\n- Hyper-V VSS Writer\nDo not restart every service indiscriminately.\nMap the failed writer to its owning service and workload.\nBefore deleting snapshots or resizing shadow storage:\n- Confirm backup status\n- Confirm server role\n- Confirm restore requirements\n- Confirm available disk space\n- Obtain approval when required","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 513 - A System Writer, Cryptographic Services, or backup-related operation failed.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A System Writer, Cryptographic Services, or backup-related operation failed.\nVSS TROUBLESHOOTING REQUIREMENTS:\nCollect:\nvssadmin list writers\nvssadmin list providers\nvssadmin list shadows\nvssadmin list shadowstorage\nIdentify the exact failed writer:\n- System Writer\n- Registry Writer\n- WMI Writer\n- NTDS Writer\n- DFS Replication Writer\n- SQL Server Writer\n- IIS Metabase Writer\n- Exchange Writer\n- Hyper-V VSS Writer\nDo not restart every service indiscriminately.\nMap the failed writer to its owning service and workload.\nBefore deleting snapshots or resizing shadow storage:\n- Confirm backup status\n- Confirm server role\n- Confirm restore requirements\n- Confirm available disk space\n- Obtain approval when required\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"vssadmin list writers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list providers","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadows","admin":true,"restart":false,"risk":"Standard"},{"command":"vssadmin list shadowstorage","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 513","identifiers":["Event ID 513"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"VSS","eventSource":"VSS","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Run vssadmin list writers.\n2. Confirm relevant writers report Stable and No error.\n3. Run a test backup.\n4. Confirm the backup and application-consistency check complete successfully.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 513\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Volume Shadow Copy Service\nComponent: VSS\nReview status: Verified\n\nMeaning: A System Writer, Cryptographic Services, or backup-related operation failed.\nVSS TROUBLESHOOTING REQUIREMENTS:\nCollect:\nvssadmin list writers\nvssadmin list providers\nvssadmin list shadows\nvssadmin list shadowstorage\nIdentify the exact failed writer:\n- System Writer\n- Registry Writer\n- WMI Writer\n- NTDS Writer\n- DFS Replication Writer\n- SQL Server Writer\n- IIS Metabase Writer\n- Exchange Writer\n- Hyper-V VSS Writer\nDo not restart every service indiscriminately.\nMap the failed writer to its owning service and workload.\nBefore deleting snapshots or resizing shadow storage:\n- Confirm backup status\n- Confirm server role\n- Confirm restore requirements\n- Confirm available disk space\n- Obtain approval when required\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Run vssadmin list writers.\n2. Confirm relevant writers report Stable and No error.\n3. Run a test backup.\n4. Confirm the backup and application-consistency check complete successfully.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Volume Shadow Copy Service"],"technologies":["WIN-EVENT","Windows Event ID","VSS","Verified"],"aliases":["513"]},{"id":54156,"title":"0xC000006F - The user attempted to sign in outside permitted logon hours","category":"Active Directory","product":"Windows Authentication / Kerberos","tags":["WIN-NTSTATUS","Windows Authentication Status","Security / Kerberos","Verified"],"keywords":["0xc000006f","win","ntstatus","security","kerberos","the","user","attempted","sign","outside","permitted","logon","hours","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies"],"errorCode":"0xC000006F","eventId":"","severity":"High","summary":"The user attempted to sign in outside permitted logon hours.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC000006F - The user attempted to sign in outside permitted logon hours.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The user attempted to sign in outside permitted logon hours.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"nltest /dsgetdc:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"nltest /sc_verify:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"Test-ComputerSecureChannel -Verbose","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /status","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /source","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC000006F","identifiers":["0xC000006F"],"identifierType":"Windows Authentication Status","namespace":"WIN-NTSTATUS","platform":"Windows","component":"Security / Kerberos","eventSource":"Security / Kerberos","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC000006F\nNamespace: WIN-NTSTATUS\nType: Windows Authentication Status\nPlatform: Windows\nProduct: Windows Authentication / Kerberos\nComponent: Security / Kerberos\nReview status: Verified\n\nMeaning: The user attempted to sign in outside permitted logon hours.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Authentication"],"technologies":["WIN-NTSTATUS","Windows Authentication Status","Security / Kerberos","Verified"],"aliases":["0xC000006F"]},{"id":54157,"title":"0xC0000070 - The user is not authorized to sign in from the requested workstation","category":"Active Directory","product":"Windows Authentication / Kerberos","tags":["WIN-NTSTATUS","Windows Authentication Status","Security / Kerberos","Verified"],"keywords":["0xc0000070","win","ntstatus","security","kerberos","the","user","not","authorized","sign","from","requested","workstation","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies"],"errorCode":"0xC0000070","eventId":"","severity":"Low","summary":"The user is not authorized to sign in from the requested workstation.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC0000070 - The user is not authorized to sign in from the requested workstation.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The user is not authorized to sign in from the requested workstation.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"nltest /dsgetdc:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"nltest /sc_verify:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"Test-ComputerSecureChannel -Verbose","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /status","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /source","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC0000070","identifiers":["0xC0000070"],"identifierType":"Windows Authentication Status","namespace":"WIN-NTSTATUS","platform":"Windows","component":"Security / Kerberos","eventSource":"Security / Kerberos","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC0000070\nNamespace: WIN-NTSTATUS\nType: Windows Authentication Status\nPlatform: Windows\nProduct: Windows Authentication / Kerberos\nComponent: Security / Kerberos\nReview status: Verified\n\nMeaning: The user is not authorized to sign in from the requested workstation.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Authentication"],"technologies":["WIN-NTSTATUS","Windows Authentication Status","Security / Kerberos","Verified"],"aliases":["0xC0000070"]},{"id":54158,"title":"0xC0000071 - The password has expired","category":"Active Directory","product":"Windows Authentication / Kerberos","tags":["WIN-NTSTATUS","Windows Authentication Status","Security / Kerberos","Verified"],"keywords":["0xc0000071","win","ntstatus","security","kerberos","the","password","has","expired","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity"],"errorCode":"0xC0000071","eventId":"","severity":"Low","summary":"The password has expired.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC0000071 - The password has expired.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The password has expired.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"nltest /dsgetdc:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"nltest /sc_verify:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"Test-ComputerSecureChannel -Verbose","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /status","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /source","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC0000071","identifiers":["0xC0000071"],"identifierType":"Windows Authentication Status","namespace":"WIN-NTSTATUS","platform":"Windows","component":"Security / Kerberos","eventSource":"Security / Kerberos","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC0000071\nNamespace: WIN-NTSTATUS\nType: Windows Authentication Status\nPlatform: Windows\nProduct: Windows Authentication / Kerberos\nComponent: Security / Kerberos\nReview status: Verified\n\nMeaning: The password has expired.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Authentication"],"technologies":["WIN-NTSTATUS","Windows Authentication Status","Security / Kerberos","Verified"],"aliases":["0xC0000071"]},{"id":54159,"title":"0xC0000193 - The account has expired","category":"Active Directory","product":"Windows Authentication / Kerberos","tags":["WIN-NTSTATUS","Windows Authentication Status","Security / Kerberos","Verified"],"keywords":["0xc0000193","win","ntstatus","security","kerberos","the","account","has","expired","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity"],"errorCode":"0xC0000193","eventId":"","severity":"Low","summary":"The account has expired.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC0000193 - The account has expired.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The account has expired.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"nltest /dsgetdc:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"nltest /sc_verify:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"Test-ComputerSecureChannel -Verbose","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /status","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /source","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC0000193","identifiers":["0xC0000193"],"identifierType":"Windows Authentication Status","namespace":"WIN-NTSTATUS","platform":"Windows","component":"Security / Kerberos","eventSource":"Security / Kerberos","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC0000193\nNamespace: WIN-NTSTATUS\nType: Windows Authentication Status\nPlatform: Windows\nProduct: Windows Authentication / Kerberos\nComponent: Security / Kerberos\nReview status: Verified\n\nMeaning: The account has expired.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Authentication"],"technologies":["WIN-NTSTATUS","Windows Authentication Status","Security / Kerberos","Verified"],"aliases":["0xC0000193"]},{"id":54160,"title":"0xC0000234 - The account is locked out","category":"Active Directory","product":"Windows Authentication / Kerberos","tags":["WIN-NTSTATUS","Windows Authentication Status","Security / Kerberos","Verified"],"keywords":["0xc0000234","win","ntstatus","security","kerberos","the","account","locked","out","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity"],"errorCode":"0xC0000234","eventId":"","severity":"High","summary":"The account is locked out.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC0000234 - The account is locked out.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The account is locked out.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"nltest /dsgetdc:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"nltest /sc_verify:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"Test-ComputerSecureChannel -Verbose","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /status","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /source","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC0000234","identifiers":["0xC0000234"],"identifierType":"Windows Authentication Status","namespace":"WIN-NTSTATUS","platform":"Windows","component":"Security / Kerberos","eventSource":"Security / Kerberos","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC0000234\nNamespace: WIN-NTSTATUS\nType: Windows Authentication Status\nPlatform: Windows\nProduct: Windows Authentication / Kerberos\nComponent: Security / Kerberos\nReview status: Verified\n\nMeaning: The account is locked out.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Authentication"],"technologies":["WIN-NTSTATUS","Windows Authentication Status","Security / Kerberos","Verified"],"aliases":["0xC0000234"]},{"id":54161,"title":"0xC000015B - The user has not been granted the requested logon type","category":"Active Directory","product":"Windows Authentication / Kerberos","tags":["WIN-NTSTATUS","Windows Authentication Status","Security / Kerberos","Verified"],"keywords":["0xc000015b","win","ntstatus","security","kerberos","the","user","has","not","been","granted","requested","logon","type","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration"],"errorCode":"0xC000015B","eventId":"","severity":"High","summary":"The user has not been granted the requested logon type.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC000015B - The user has not been granted the requested logon type.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The user has not been granted the requested logon type.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"nltest /dsgetdc:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"nltest /sc_verify:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"Test-ComputerSecureChannel -Verbose","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /status","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /source","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC000015B","identifiers":["0xC000015B"],"identifierType":"Windows Authentication Status","namespace":"WIN-NTSTATUS","platform":"Windows","component":"Security / Kerberos","eventSource":"Security / Kerberos","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC000015B\nNamespace: WIN-NTSTATUS\nType: Windows Authentication Status\nPlatform: Windows\nProduct: Windows Authentication / Kerberos\nComponent: Security / Kerberos\nReview status: Verified\n\nMeaning: The user has not been granted the requested logon type.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Authentication"],"technologies":["WIN-NTSTATUS","Windows Authentication Status","Security / Kerberos","Verified"],"aliases":["0xC000015B"]},{"id":54162,"title":"KRB_AP_ERR_SKEW - The client and server clocks differ beyond the Kerberos tolerance","category":"Active Directory","product":"Windows Authentication / Kerberos","tags":["WIN-KERBEROS","Kerberos Protocol Error","Security / Kerberos","Verified"],"keywords":["krb","err","skew","win","kerberos","security","the","client","and","server","clocks","differ","beyond","tolerance","operation","fails","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies"],"errorCode":"KRB_AP_ERR_SKEW","eventId":"","severity":"Low","summary":"The client and server clocks differ beyond the Kerberos tolerance.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to KRB_AP_ERR_SKEW - The client and server clocks differ beyond the Kerberos tolerance.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The client and server clocks differ beyond the Kerberos tolerance.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"nltest /dsgetdc:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"nltest /sc_verify:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"Test-ComputerSecureChannel -Verbose","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /status","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /source","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"KRB_AP_ERR_SKEW","identifiers":["KRB_AP_ERR_SKEW"],"identifierType":"Kerberos Protocol Error","namespace":"WIN-KERBEROS","platform":"Windows","component":"Security / Kerberos","eventSource":"Security / Kerberos","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: KRB_AP_ERR_SKEW\nNamespace: WIN-KERBEROS\nType: Kerberos Protocol Error\nPlatform: Windows\nProduct: Windows Authentication / Kerberos\nComponent: Security / Kerberos\nReview status: Verified\n\nMeaning: The client and server clocks differ beyond the Kerberos tolerance.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Authentication"],"technologies":["WIN-KERBEROS","Kerberos Protocol Error","Security / Kerberos","Verified"],"aliases":["KRB_AP_ERR_SKEW"]},{"id":54163,"title":"KRB_AP_ERR_MODIFIED - The service ticket could not be decrypted by the target service","category":"Active Directory","product":"Windows Authentication / Kerberos","tags":["WIN-KERBEROS","Kerberos Protocol Error","Security / Kerberos","Verified"],"keywords":["krb","err","modified","win","kerberos","security","the","service","ticket","could","not","decrypted","target","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","duplicate","principal","name","incorrect","account","machine","password","mismatch","dns","resolving","wrong"],"errorCode":"KRB_AP_ERR_MODIFIED","eventId":"","severity":"Low","summary":"The service ticket could not be decrypted by the target service.","rootCause":"- Duplicate service principal name\n- Incorrect service account\n- Machine account password mismatch\n- DNS resolving to the wrong server\n- Stale computer object\n- Restored or cloned server identity\nCreate Event ID entries for:","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to KRB_AP_ERR_MODIFIED - The service ticket could not be decrypted by the target service.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The service ticket could not be decrypted by the target service.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"nltest /dsgetdc:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"nltest /sc_verify:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"Test-ComputerSecureChannel -Verbose","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /status","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /source","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"KRB_AP_ERR_MODIFIED","identifiers":["KRB_AP_ERR_MODIFIED"],"identifierType":"Kerberos Protocol Error","namespace":"WIN-KERBEROS","platform":"Windows","component":"Security / Kerberos","eventSource":"Security / Kerberos","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: KRB_AP_ERR_MODIFIED\nNamespace: WIN-KERBEROS\nType: Kerberos Protocol Error\nPlatform: Windows\nProduct: Windows Authentication / Kerberos\nComponent: Security / Kerberos\nReview status: Verified\n\nMeaning: The service ticket could not be decrypted by the target service.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Authentication"],"technologies":["WIN-KERBEROS","Kerberos Protocol Error","Security / Kerberos","Verified"],"aliases":["KRB_AP_ERR_MODIFIED"]},{"id":54164,"title":"Event ID 5719 - No domain controller was available","category":"Active Directory","product":"Windows Authentication / Kerberos","tags":["WIN-EVENT","Windows Event ID","Security / Kerberos","Verified"],"keywords":["event","5719","win","security","kerberos","domain","controller","was","available","the","operation","fails","and","may","produce","identifier","application","deployment","report","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity"],"errorCode":"","eventId":"5719","severity":"Low","summary":"No domain controller was available.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 5719 - No domain controller was available.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: No domain controller was available.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"nltest /dsgetdc:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"nltest /sc_verify:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"Test-ComputerSecureChannel -Verbose","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /status","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /source","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 5719","identifiers":["Event ID 5719"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"Security / Kerberos","eventSource":"Security / Kerberos","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 5719\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Authentication / Kerberos\nComponent: Security / Kerberos\nReview status: Verified\n\nMeaning: No domain controller was available.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Authentication"],"technologies":["WIN-EVENT","Windows Event ID","Security / Kerberos","Verified"],"aliases":["5719"]},{"id":54165,"title":"Event ID 5805 - A computer account authentication attempt failed","category":"Active Directory","product":"Windows Authentication / Kerberos","tags":["WIN-EVENT","Windows Event ID","Security / Kerberos","Verified"],"keywords":["event","5805","win","security","kerberos","computer","account","authentication","attempt","failed","the","operation","fails","and","may","produce","identifier","application","deployment","report","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services"],"errorCode":"","eventId":"5805","severity":"High","summary":"A computer account authentication attempt failed.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 5805 - A computer account authentication attempt failed.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A computer account authentication attempt failed.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"nltest /dsgetdc:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"nltest /sc_verify:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"Test-ComputerSecureChannel -Verbose","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /status","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /source","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 5805","identifiers":["Event ID 5805"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"Security / Kerberos","eventSource":"Security / Kerberos","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 5805\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Authentication / Kerberos\nComponent: Security / Kerberos\nReview status: Verified\n\nMeaning: A computer account authentication attempt failed.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Authentication"],"technologies":["WIN-EVENT","Windows Event ID","Security / Kerberos","Verified"],"aliases":["5805"]},{"id":54166,"title":"Event ID 3210 - The computer could not authenticate with the domain","category":"Active Directory","product":"Windows Authentication / Kerberos","tags":["WIN-EVENT","Windows Event ID","Security / Kerberos","Verified"],"keywords":["event","3210","win","security","kerberos","the","computer","could","not","authenticate","with","domain","operation","fails","and","may","produce","identifier","application","deployment","report","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers"],"errorCode":"","eventId":"3210","severity":"Low","summary":"The computer could not authenticate with the domain.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 3210 - The computer could not authenticate with the domain.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The computer could not authenticate with the domain.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"nltest /dsgetdc:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"nltest /sc_verify:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"Test-ComputerSecureChannel -Verbose","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /status","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /source","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 3210","identifiers":["Event ID 3210"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"Security / Kerberos","eventSource":"Security / Kerberos","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 3210\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Authentication / Kerberos\nComponent: Security / Kerberos\nReview status: Verified\n\nMeaning: The computer could not authenticate with the domain.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Authentication"],"technologies":["WIN-EVENT","Windows Event ID","Security / Kerberos","Verified"],"aliases":["3210"]},{"id":54167,"title":"Event ID 4625 - An account failed to log on","category":"Active Directory","product":"Windows Authentication / Kerberos","tags":["WIN-EVENT","Windows Event ID","Security / Kerberos","Verified"],"keywords":["event","4625","win","security","kerberos","account","failed","log","the","operation","fails","and","may","produce","identifier","application","deployment","report","viewer","entry","setup","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity","damaged","state"],"errorCode":"","eventId":"4625","severity":"High","summary":"An account failed to log on.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 4625 - An account failed to log on.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: An account failed to log on.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"nltest /dsgetdc:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"nltest /sc_verify:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"Test-ComputerSecureChannel -Verbose","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /status","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /source","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 4625","identifiers":["Event ID 4625"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"Security / Kerberos","eventSource":"Security / Kerberos","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 4625\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Authentication / Kerberos\nComponent: Security / Kerberos\nReview status: Verified\n\nMeaning: An account failed to log on.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Authentication"],"technologies":["WIN-EVENT","Windows Event ID","Security / Kerberos","Verified"],"aliases":["4625"]},{"id":54168,"title":"Event ID 4771 - Kerberos pre-authentication failed","category":"Active Directory","product":"Windows Authentication / Kerberos","tags":["WIN-EVENT","Windows Event ID","Security / Kerberos","Verified"],"keywords":["event","4771","win","security","kerberos","pre","authentication","failed","the","operation","fails","and","may","produce","identifier","application","deployment","report","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity","damaged"],"errorCode":"","eventId":"4771","severity":"High","summary":"Kerberos pre-authentication failed.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 4771 - Kerberos pre-authentication failed.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Kerberos pre-authentication failed.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"nltest /dsgetdc:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"nltest /sc_verify:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"Test-ComputerSecureChannel -Verbose","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /status","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /source","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 4771","identifiers":["Event ID 4771"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"Security / Kerberos","eventSource":"Security / Kerberos","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 4771\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Authentication / Kerberos\nComponent: Security / Kerberos\nReview status: Verified\n\nMeaning: Kerberos pre-authentication failed.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Authentication"],"technologies":["WIN-EVENT","Windows Event ID","Security / Kerberos","Verified"],"aliases":["4771"]},{"id":54169,"title":"Event ID 4740 - A user account was locked out","category":"Active Directory","product":"Windows Authentication / Kerberos","tags":["WIN-EVENT","Windows Event ID","Security / Kerberos","Verified"],"keywords":["event","4740","win","security","kerberos","user","account","was","locked","out","authentication","troubleshooting","requirements","for","4625","capture","name","domain","logon","type","failure","reason","status","substatus","caller","process","workstation","source","network","address","package","timestamp","check","stale","credentials","windows","services","scheduled","tasks","mapped"],"errorCode":"","eventId":"4740","severity":"High","summary":"A user account was locked out.\nAUTHENTICATION TROUBLESHOOTING REQUIREMENTS:\nFor Event ID 4625 capture:\n- Account name\n- Account domain\n- Logon type\n- Failure reason\n- Status\n- Substatus\n- Caller process\n- Workstation name\n- Source network address\n- Authentication package\n- Timestamp\nCheck for stale credentials in:\n- Windows services\n- Scheduled tasks\n- Mapped drives\n- Credential Manager\n- RMM agents\n- Backup software\n- Printers and scanners\n- Applications\n- Mobile devices\n- VPN clients\n- Wi-Fi profiles\n- Old workstations\nUseful commands:\nnltest /dsgetdc:domain.local\nnltest /sc_verify:domain.local\nTest-ComputerSecureChannel -Verbose\nw32tm /query /status\nw32tm /query /source\nsetspn -Q HTTP/servername\nsetspn -X\nIMPORTANT:\nDo not reset a computer account or remove and rejoin a device to the domain\nbefore verifying DNS, time, domain-controller connectivity, secure-channel\nstate, BitLocker recovery availability, local administrative access, and\nbusiness impact.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 4740 - A user account was locked out.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A user account was locked out.\nAUTHENTICATION TROUBLESHOOTING REQUIREMENTS:\nFor Event ID 4625 capture:\n- Account name\n- Account domain\n- Logon type\n- Failure reason\n- Status\n- Substatus\n- Caller process\n- Workstation name\n- Source network address\n- Authentication package\n- Timestamp\nCheck for stale credentials in:\n- Windows services\n- Scheduled tasks\n- Mapped drives\n- Credential Manager\n- RMM agents\n- Backup software\n- Printers and scanners\n- Applications\n- Mobile devices\n- VPN clients\n- Wi-Fi profiles\n- Old workstations\nUseful commands:\nnltest /dsgetdc:domain.local\nnltest /sc_verify:domain.local\nTest-ComputerSecureChannel -Verbose\nw32tm /query /status\nw32tm /query /source\nsetspn -Q HTTP/servername\nsetspn -X\nIMPORTANT:\nDo not reset a computer account or remove and rejoin a device to the domain\nbefore verifying DNS, time, domain-controller connectivity, secure-channel\nstate, BitLocker recovery availability, local administrative access, and\nbusiness impact.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"nltest /dsgetdc:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"nltest /sc_verify:domain.local","admin":true,"restart":false,"risk":"Standard"},{"command":"Test-ComputerSecureChannel -Verbose","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /status","admin":true,"restart":false,"risk":"Standard"},{"command":"w32tm /query /source","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 4740","identifiers":["Event ID 4740"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"Security / Kerberos","eventSource":"Security / Kerberos","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Potential","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 4740\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Authentication / Kerberos\nComponent: Security / Kerberos\nReview status: Verified\n\nMeaning: A user account was locked out.\nAUTHENTICATION TROUBLESHOOTING REQUIREMENTS:\nFor Event ID 4625 capture:\n- Account name\n- Account domain\n- Logon type\n- Failure reason\n- Status\n- Substatus\n- Caller process\n- Workstation name\n- Source network address\n- Authentication package\n- Timestamp\nCheck for stale credentials in:\n- Windows services\n- Scheduled tasks\n- Mapped drives\n- Credential Manager\n- RMM agents\n- Backup software\n- Printers and scanners\n- Applications\n- Mobile devices\n- VPN clients\n- Wi-Fi profiles\n- Old workstations\nUseful commands:\nnltest /dsgetdc:domain.local\nnltest /sc_verify:domain.local\nTest-ComputerSecureChannel -Verbose\nw32tm /query /status\nw32tm /query /source\nsetspn -Q HTTP/servername\nsetspn -X\nIMPORTANT:\nDo not reset a computer account or remove and rejoin a device to the domain\nbefore verifying DNS, time, domain-controller connectivity, secure-channel\nstate, BitLocker recovery availability, local administrative access, and\nbusiness impact.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Authentication"],"technologies":["WIN-EVENT","Windows Event ID","Security / Kerberos","Verified"],"aliases":["4740"]},{"id":54170,"title":"Event ID 1000 - An application crashed","category":"Windows","product":"Windows Applications / .NET","tags":["WIN-EVENT","Windows Event ID","Application Error","Verified"],"keywords":["event","1000","win","application","error","crashed","the","operation","fails","and","may","produce","identifier","deployment","report","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity","damaged","state"],"errorCode":"","eventId":"1000","severity":"Low","summary":"An application crashed.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 1000 - An application crashed.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: An application crashed.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 1000","identifiers":["Event ID 1000"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"Application Error","eventSource":"Application Error","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 1000\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Applications / .NET\nComponent: Application Error\nReview status: Verified\n\nMeaning: An application crashed.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Applications"],"technologies":["WIN-EVENT","Windows Event ID","Application Error","Verified"],"aliases":["1000"]},{"id":54171,"title":"Event ID 1001 - Windows Error Reporting recorded an application failure or system bug check","category":"Windows","product":"Windows Applications / .NET","tags":["WIN-EVENT","Windows Event ID","Application Error","Verified"],"keywords":["event","1001","win","application","error","windows","reporting","recorded","failure","system","bug","check","the","operation","fails","and","may","produce","identifier","deployment","report","viewer","entry","setup","log","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services"],"errorCode":"","eventId":"1001","severity":"High","summary":"Windows Error Reporting recorded an application failure or system bug check.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 1001 - Windows Error Reporting recorded an application failure or system bug check.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Windows Error Reporting recorded an application failure or system bug check.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 1001","identifiers":["Event ID 1001"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"Application Error","eventSource":"Application Error","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 1001\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Applications / .NET\nComponent: Application Error\nReview status: Verified\n\nMeaning: Windows Error Reporting recorded an application failure or system bug check.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Applications"],"technologies":["WIN-EVENT","Windows Event ID","Application Error","Verified"],"aliases":["1001"]},{"id":54172,"title":"Event ID 1026 - A ","category":"Windows","product":"Windows Applications / .NET","tags":["WIN-EVENT","Windows Event ID","Application Error","Verified"],"keywords":["event","1026","win","application","error","net","runtime","terminated","because","unhandled","exception","the","operation","fails","and","may","produce","identifier","deployment","report","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services"],"errorCode":"","eventId":"1026","severity":"Low","summary":"A .NET Runtime application terminated because of an unhandled exception.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 1026 - A .\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A .NET Runtime application terminated because of an unhandled exception.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 1026","identifiers":["Event ID 1026"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"Application Error","eventSource":"Application Error","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 1026\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Applications / .NET\nComponent: Application Error\nReview status: Verified\n\nMeaning: A .NET Runtime application terminated because of an unhandled exception.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Applications"],"technologies":["WIN-EVENT","Windows Event ID","Application Error","Verified"],"aliases":["1026"]},{"id":54173,"title":"0xC0000005 - An application attempted an invalid memory access","category":"Windows","product":"Windows Applications / .NET","tags":["WIN-NTSTATUS","NTSTATUS / Application Exception","Application Error","Verified"],"keywords":["0xc0000005","win","ntstatus","application","error","attempted","invalid","memory","access","the","operation","fails","and","may","produce","identifier","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity"],"errorCode":"0xC0000005","eventId":"","severity":"Medium","summary":"An application attempted an invalid memory access.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC0000005 - An application attempted an invalid memory access.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: An application attempted an invalid memory access.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC0000005","identifiers":["0xC0000005"],"identifierType":"NTSTATUS / Application Exception","namespace":"WIN-NTSTATUS","platform":"Windows","component":"Application Error","eventSource":"Application Error","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC0000005\nNamespace: WIN-NTSTATUS\nType: NTSTATUS / Application Exception\nPlatform: Windows\nProduct: Windows Applications / .NET\nComponent: Application Error\nReview status: Verified\n\nMeaning: An application attempted an invalid memory access.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Applications"],"technologies":["WIN-NTSTATUS","NTSTATUS / Application Exception","Application Error","Verified"],"aliases":["0xC0000005"]},{"id":54174,"title":"0xC0000135 - A required DLL or runtime component could not be found","category":"Windows","product":"Windows Applications / .NET","tags":["WIN-NTSTATUS","NTSTATUS / Application Exception","Application Error","Verified"],"keywords":["0xc0000135","win","ntstatus","application","error","required","dll","runtime","component","could","not","found","the","operation","fails","and","may","produce","identifier","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers"],"errorCode":"0xC0000135","eventId":"","severity":"Low","summary":"A required DLL or runtime component could not be found.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC0000135 - A required DLL or runtime component could not be found.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A required DLL or runtime component could not be found.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC0000135","identifiers":["0xC0000135"],"identifierType":"NTSTATUS / Application Exception","namespace":"WIN-NTSTATUS","platform":"Windows","component":"Application Error","eventSource":"Application Error","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC0000135\nNamespace: WIN-NTSTATUS\nType: NTSTATUS / Application Exception\nPlatform: Windows\nProduct: Windows Applications / .NET\nComponent: Application Error\nReview status: Verified\n\nMeaning: A required DLL or runtime component could not be found.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Applications"],"technologies":["WIN-NTSTATUS","NTSTATUS / Application Exception","Application Error","Verified"],"aliases":["0xC0000135"]},{"id":54175,"title":"0xC0000142 - A DLL failed to initialize","category":"Windows","product":"Windows Applications / .NET","tags":["WIN-NTSTATUS","NTSTATUS / Application Exception","Application Error","Verified"],"keywords":["0xc0000142","win","ntstatus","application","error","dll","failed","initialize","the","operation","fails","and","may","produce","identifier","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity","damaged"],"errorCode":"0xC0000142","eventId":"","severity":"High","summary":"A DLL failed to initialize.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC0000142 - A DLL failed to initialize.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A DLL failed to initialize.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC0000142","identifiers":["0xC0000142"],"identifierType":"NTSTATUS / Application Exception","namespace":"WIN-NTSTATUS","platform":"Windows","component":"Application Error","eventSource":"Application Error","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC0000142\nNamespace: WIN-NTSTATUS\nType: NTSTATUS / Application Exception\nPlatform: Windows\nProduct: Windows Applications / .NET\nComponent: Application Error\nReview status: Verified\n\nMeaning: A DLL failed to initialize.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Applications"],"technologies":["WIN-NTSTATUS","NTSTATUS / Application Exception","Application Error","Verified"],"aliases":["0xC0000142"]},{"id":54176,"title":"0xC0000374 - Windows detected heap corruption","category":"Windows","product":"Windows Applications / .NET","tags":["WIN-NTSTATUS","NTSTATUS / Application Exception","Application Error","Verified"],"keywords":["0xc0000374","win","ntstatus","application","error","windows","detected","heap","corruption","the","operation","fails","and","may","produce","identifier","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity"],"errorCode":"0xC0000374","eventId":"","severity":"Critical","summary":"Windows detected heap corruption.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC0000374 - Windows detected heap corruption.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Windows detected heap corruption.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC0000374","identifiers":["0xC0000374"],"identifierType":"NTSTATUS / Application Exception","namespace":"WIN-NTSTATUS","platform":"Windows","component":"Application Error","eventSource":"Application Error","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC0000374\nNamespace: WIN-NTSTATUS\nType: NTSTATUS / Application Exception\nPlatform: Windows\nProduct: Windows Applications / .NET\nComponent: Application Error\nReview status: Verified\n\nMeaning: Windows detected heap corruption.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Security Event ID 4625; Kerberos, Netlogon, and domain-controller logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Applications"],"technologies":["WIN-NTSTATUS","NTSTATUS / Application Exception","Application Error","Verified"],"aliases":["0xC0000374"]},{"id":54177,"title":"0xE0434352 - A ","category":"Windows","product":"Windows Applications / .NET","tags":["WIN-DOTNET","Windows Application Exception","Application Error","Verified"],"keywords":["0xe0434352","win","dotnet","application","error","net","generated","unhandled","common","language","runtime","exception","the","operation","fails","and","may","produce","identifier","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","factors","include","configuration","dependencies","permissions","drivers"],"errorCode":"0xE0434352","eventId":"","severity":"Low","summary":"A .NET application generated an unhandled Common Language Runtime exception.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xE0434352 - A .\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A .NET application generated an unhandled Common Language Runtime exception.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xE0434352","identifiers":["0xE0434352"],"identifierType":"Windows Application Exception","namespace":"WIN-DOTNET","platform":"Windows","component":"Application Error","eventSource":"Application Error","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Application Events 1000, 1001, and 1026; WER files; application logs; crash dump","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xE0434352\nNamespace: WIN-DOTNET\nType: Windows Application Exception\nPlatform: Windows\nProduct: Windows Applications / .NET\nComponent: Application Error\nReview status: Verified\n\nMeaning: A .NET application generated an unhandled Common Language Runtime exception.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Application Events 1000, 1001, and 1026; WER files; application logs; crash dump\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Applications"],"technologies":["WIN-DOTNET","Windows Application Exception","Application Error","Verified"],"aliases":["0xE0434352"]},{"id":54178,"title":"0xC06D007E - A Microsoft C++ exception indicates a required module could not be found","category":"Windows","product":"Windows Applications / .NET","tags":["WIN-DOTNET","Windows Application Exception","Application Error","Verified"],"keywords":["0xc06d007e","win","dotnet","application","error","microsoft","exception","indicates","required","module","could","not","found","the","operation","fails","and","may","produce","identifier","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies"],"errorCode":"0xC06D007E","eventId":"","severity":"Low","summary":"A Microsoft C++ exception indicates a required module could not be found.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC06D007E - A Microsoft C++ exception indicates a required module could not be found.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A Microsoft C++ exception indicates a required module could not be found.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC06D007E","identifiers":["0xC06D007E"],"identifierType":"Windows Application Exception","namespace":"WIN-DOTNET","platform":"Windows","component":"Application Error","eventSource":"Application Error","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Application Events 1000, 1001, and 1026; WER files; application logs; crash dump","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC06D007E\nNamespace: WIN-DOTNET\nType: Windows Application Exception\nPlatform: Windows\nProduct: Windows Applications / .NET\nComponent: Application Error\nReview status: Verified\n\nMeaning: A Microsoft C++ exception indicates a required module could not be found.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Application Events 1000, 1001, and 1026; WER files; application logs; crash dump\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Applications"],"technologies":["WIN-DOTNET","Windows Application Exception","Application Error","Verified"],"aliases":["0xC06D007E"]},{"id":54179,"title":"0xC06D007F - A Microsoft C++ exception indicates a required procedure could not be found","category":"Windows","product":"Windows Applications / .NET","tags":["WIN-DOTNET","Windows Application Exception","Application Error","Verified"],"keywords":["0xc06d007f","win","dotnet","application","error","microsoft","exception","indicates","required","procedure","could","not","found","crash","troubleshooting","requirements","capture","from","event","1000","faulting","name","version","module","code","fault","offset","process","path","report","timestamp","check","adjacent","1001","1026","windows","reporting","files","specific","logs"],"errorCode":"0xC06D007F","eventId":"","severity":"Low","summary":"A Microsoft C++ exception indicates a required procedure could not be found.\nAPPLICATION CRASH TROUBLESHOOTING REQUIREMENTS:\nCapture from Event ID 1000:\n- Faulting application name\n- Application version\n- Faulting module name\n- Module version\n- Exception code\n- Fault offset\n- Process ID\n- Application path\n- Module path\n- Report ID\n- Timestamp\nCheck adjacent:\n- Event ID 1001\n- Event ID 1026\n- Windows Error Reporting files\n- Application-specific logs\n- Reliability Monitor\nPossible fixes:\n1. Repair or reinstall the application.\n2. Install or repair the required .NET or Visual C++ runtime.\n3. Update Windows and the application.\n4. Check security software blocks.\n5. Test with a clean user profile.\n6. Capture a crash dump if the problem repeats.\n7. Escalate with logs and dump evidence.\nDo not assume KERNELBASE.dll is the root cause merely because it appears as\nthe faulting module.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC06D007F - A Microsoft C++ exception indicates a required procedure could not be found.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A Microsoft C++ exception indicates a required procedure could not be found.\nAPPLICATION CRASH TROUBLESHOOTING REQUIREMENTS:\nCapture from Event ID 1000:\n- Faulting application name\n- Application version\n- Faulting module name\n- Module version\n- Exception code\n- Fault offset\n- Process ID\n- Application path\n- Module path\n- Report ID\n- Timestamp\nCheck adjacent:\n- Event ID 1001\n- Event ID 1026\n- Windows Error Reporting files\n- Application-specific logs\n- Reliability Monitor\nPossible fixes:\n1. Repair or reinstall the application.\n2. Install or repair the required .NET or Visual C++ runtime.\n3. Update Windows and the application.\n4. Check security software blocks.\n5. Test with a clean user profile.\n6. Capture a crash dump if the problem repeats.\n7. Escalate with logs and dump evidence.\nDo not assume KERNELBASE.dll is the root cause merely because it appears as\nthe faulting module.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC06D007F","identifiers":["0xC06D007F"],"identifierType":"Windows Application Exception","namespace":"WIN-DOTNET","platform":"Windows","component":"Application Error","eventSource":"Application Error","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Application Events 1000, 1001, and 1026; WER files; application logs; crash dump","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC06D007F\nNamespace: WIN-DOTNET\nType: Windows Application Exception\nPlatform: Windows\nProduct: Windows Applications / .NET\nComponent: Application Error\nReview status: Verified\n\nMeaning: A Microsoft C++ exception indicates a required procedure could not be found.\nAPPLICATION CRASH TROUBLESHOOTING REQUIREMENTS:\nCapture from Event ID 1000:\n- Faulting application name\n- Application version\n- Faulting module name\n- Module version\n- Exception code\n- Fault offset\n- Process ID\n- Application path\n- Module path\n- Report ID\n- Timestamp\nCheck adjacent:\n- Event ID 1001\n- Event ID 1026\n- Windows Error Reporting files\n- Application-specific logs\n- Reliability Monitor\nPossible fixes:\n1. Repair or reinstall the application.\n2. Install or repair the required .NET or Visual C++ runtime.\n3. Update Windows and the application.\n4. Check security software blocks.\n5. Test with a clean user profile.\n6. Capture a crash dump if the problem repeats.\n7. Escalate with logs and dump evidence.\nDo not assume KERNELBASE.dll is the root cause merely because it appears as\nthe faulting module.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Application Events 1000, 1001, and 1026; WER files; application logs; crash dump\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Applications"],"technologies":["WIN-DOTNET","Windows Application Exception","Application Error","Verified"],"aliases":["0xC06D007F"]},{"id":54180,"title":"Event ID 7 - The storage device reported a bad block","category":"Windows Server","product":"Windows Storage / File System","tags":["WIN-EVENT","Windows Event ID","Disk / Ntfs / StorPort","Verified"],"keywords":["event","win","disk","ntfs","storport","the","storage","device","reported","bad","block","operation","fails","and","may","produce","identifier","application","deployment","report","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services"],"errorCode":"","eventId":"7","severity":"High","summary":"The storage device reported a bad block.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 7 - The storage device reported a bad block.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The storage device reported a bad block.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"Get-PhysicalDisk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Disk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Volume","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-StorageReliabilityCounter","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-WinEvent for Disk, Ntfs, StorPort, stornvme, and storage-controller events","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 7","identifiers":["Event ID 7"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"Disk / Ntfs / StorPort","eventSource":"Disk / Ntfs / StorPort","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 7\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Storage / File System\nComponent: Disk / Ntfs / StorPort\nReview status: Verified\n\nMeaning: The storage device reported a bad block.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Storage"],"technologies":["WIN-EVENT","Windows Event ID","Disk / Ntfs / StorPort","Verified"],"aliases":["7"]},{"id":54181,"title":"Event ID 11 - A controller error occurred","category":"Windows Server","product":"Windows Storage / File System","tags":["WIN-EVENT","Windows Event ID","Disk / Ntfs / StorPort","Verified"],"keywords":["event","win","disk","ntfs","storport","controller","error","occurred","the","operation","fails","and","may","produce","identifier","application","deployment","report","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity","damaged"],"errorCode":"","eventId":"11","severity":"High","summary":"A controller error occurred.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 11 - A controller error occurred.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A controller error occurred.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"Get-PhysicalDisk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Disk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Volume","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-StorageReliabilityCounter","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-WinEvent for Disk, Ntfs, StorPort, stornvme, and storage-controller events","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 11","identifiers":["Event ID 11"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"Disk / Ntfs / StorPort","eventSource":"Disk / Ntfs / StorPort","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 11\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Storage / File System\nComponent: Disk / Ntfs / StorPort\nReview status: Verified\n\nMeaning: A controller error occurred.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Storage"],"technologies":["WIN-EVENT","Windows Event ID","Disk / Ntfs / StorPort","Verified"],"aliases":["11"]},{"id":54182,"title":"Event ID 51 - An error occurred during a paging operation","category":"Windows Server","product":"Windows Storage / File System","tags":["WIN-EVENT","Windows Event ID","Disk / Ntfs / StorPort","Verified"],"keywords":["event","win","disk","ntfs","storport","error","occurred","during","paging","operation","the","fails","and","may","produce","identifier","application","deployment","report","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity"],"errorCode":"","eventId":"51","severity":"High","summary":"An error occurred during a paging operation.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 51 - An error occurred during a paging operation.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: An error occurred during a paging operation.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"Get-PhysicalDisk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Disk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Volume","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-StorageReliabilityCounter","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-WinEvent for Disk, Ntfs, StorPort, stornvme, and storage-controller events","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 51","identifiers":["Event ID 51"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"Disk / Ntfs / StorPort","eventSource":"Disk / Ntfs / StorPort","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 51\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Storage / File System\nComponent: Disk / Ntfs / StorPort\nReview status: Verified\n\nMeaning: An error occurred during a paging operation.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Storage"],"technologies":["WIN-EVENT","Windows Event ID","Disk / Ntfs / StorPort","Verified"],"aliases":["51"]},{"id":54183,"title":"Event ID 55 - Windows detected file-system corruption","category":"Windows Server","product":"Windows Storage / File System","tags":["WIN-EVENT","Windows Event ID","Disk / Ntfs / StorPort","Verified"],"keywords":["event","win","disk","ntfs","storport","windows","detected","file","system","corruption","the","operation","fails","and","may","produce","identifier","application","deployment","report","viewer","entry","setup","log","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity"],"errorCode":"","eventId":"55","severity":"High","summary":"Windows detected file-system corruption.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 55 - Windows detected file-system corruption.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Windows detected file-system corruption.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"Get-PhysicalDisk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Disk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Volume","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-StorageReliabilityCounter","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-WinEvent for Disk, Ntfs, StorPort, stornvme, and storage-controller events","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 55","identifiers":["Event ID 55"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"Disk / Ntfs / StorPort","eventSource":"Disk / Ntfs / StorPort","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 55\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Storage / File System\nComponent: Disk / Ntfs / StorPort\nReview status: Verified\n\nMeaning: Windows detected file-system corruption.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Storage"],"technologies":["WIN-EVENT","Windows Event ID","Disk / Ntfs / StorPort","Verified"],"aliases":["55"]},{"id":54184,"title":"Event ID 129 - Windows reset a storage device or controller after a timeout","category":"Windows Server","product":"Windows Storage / File System","tags":["WIN-EVENT","Windows Event ID","Disk / Ntfs / StorPort","Verified"],"keywords":["event","129","win","disk","ntfs","storport","windows","reset","storage","device","controller","after","timeout","the","operation","fails","and","may","produce","identifier","application","deployment","report","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies"],"errorCode":"","eventId":"129","severity":"High","summary":"Windows reset a storage device or controller after a timeout.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 129 - Windows reset a storage device or controller after a timeout.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Windows reset a storage device or controller after a timeout.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"Get-PhysicalDisk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Disk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Volume","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-StorageReliabilityCounter","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-WinEvent for Disk, Ntfs, StorPort, stornvme, and storage-controller events","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 129","identifiers":["Event ID 129"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"Disk / Ntfs / StorPort","eventSource":"Disk / Ntfs / StorPort","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 129\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Storage / File System\nComponent: Disk / Ntfs / StorPort\nReview status: Verified\n\nMeaning: Windows reset a storage device or controller after a timeout.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Storage"],"technologies":["WIN-EVENT","Windows Event ID","Disk / Ntfs / StorPort","Verified"],"aliases":["129"]},{"id":54185,"title":"Event ID 153 - An I/O operation was retried","category":"Windows Server","product":"Windows Storage / File System","tags":["WIN-EVENT","Windows Event ID","Disk / Ntfs / StorPort","Verified"],"keywords":["event","153","win","disk","ntfs","storport","operation","was","retried","the","fails","and","may","produce","identifier","application","deployment","report","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity","damaged"],"errorCode":"","eventId":"153","severity":"High","summary":"An I/O operation was retried.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 153 - An I/O operation was retried.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: An I/O operation was retried.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"Get-PhysicalDisk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Disk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Volume","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-StorageReliabilityCounter","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-WinEvent for Disk, Ntfs, StorPort, stornvme, and storage-controller events","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 153","identifiers":["Event ID 153"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"Disk / Ntfs / StorPort","eventSource":"Disk / Ntfs / StorPort","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 153\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Storage / File System\nComponent: Disk / Ntfs / StorPort\nReview status: Verified\n\nMeaning: An I/O operation was retried.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Storage"],"technologies":["WIN-EVENT","Windows Event ID","Disk / Ntfs / StorPort","Verified"],"aliases":["153"]},{"id":54186,"title":"Event ID 157 - A disk was unexpectedly removed","category":"Windows Server","product":"Windows Storage / File System","tags":["WIN-EVENT","Windows Event ID","Disk / Ntfs / StorPort","Verified"],"keywords":["event","157","win","disk","ntfs","storport","was","unexpectedly","removed","the","operation","fails","and","may","produce","identifier","application","deployment","report","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity"],"errorCode":"","eventId":"157","severity":"High","summary":"A disk was unexpectedly removed.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 157 - A disk was unexpectedly removed.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A disk was unexpectedly removed.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"Get-PhysicalDisk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Disk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Volume","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-StorageReliabilityCounter","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-WinEvent for Disk, Ntfs, StorPort, stornvme, and storage-controller events","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 157","identifiers":["Event ID 157"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"Disk / Ntfs / StorPort","eventSource":"Disk / Ntfs / StorPort","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 157\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Storage / File System\nComponent: Disk / Ntfs / StorPort\nReview status: Verified\n\nMeaning: A disk was unexpectedly removed.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Storage"],"technologies":["WIN-EVENT","Windows Event ID","Disk / Ntfs / StorPort","Verified"],"aliases":["157"]},{"id":54187,"title":"0x80070017 - A cyclic redundancy check failed","category":"Windows Server","product":"Windows Storage / File System","tags":["WIN-STORAGE","Windows Storage Error","Disk / Ntfs / StorPort","Verified"],"keywords":["0x80070017","win","storage","disk","ntfs","storport","cyclic","redundancy","check","failed","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers"],"errorCode":"0x80070017","eventId":"","severity":"High","summary":"A cyclic redundancy check failed.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x80070017 - A cyclic redundancy check failed.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A cyclic redundancy check failed.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"Get-PhysicalDisk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Disk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Volume","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-StorageReliabilityCounter","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-WinEvent for Disk, Ntfs, StorPort, stornvme, and storage-controller events","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x80070017","identifiers":["0x80070017"],"identifierType":"Windows Storage Error","namespace":"WIN-STORAGE","platform":"Windows","component":"Disk / Ntfs / StorPort","eventSource":"Disk / Ntfs / StorPort","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not run destructive disk repair or initialize/format media before backups, hardware evidence, and recovery planning are complete.","logsToCheck":"System log: Disk, Ntfs, StorPort, stornvme, and controller events; hardware diagnostics","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x80070017\nNamespace: WIN-STORAGE\nType: Windows Storage Error\nPlatform: Windows\nProduct: Windows Storage / File System\nComponent: Disk / Ntfs / StorPort\nReview status: Verified\n\nMeaning: A cyclic redundancy check failed.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: System log: Disk, Ntfs, StorPort, stornvme, and controller events; hardware diagnostics\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Storage"],"technologies":["WIN-STORAGE","Windows Storage Error","Disk / Ntfs / StorPort","Verified"],"aliases":["0x80070017"]},{"id":54188,"title":"0x800701B1 - A nonexistent device was specified","category":"Windows Server","product":"Windows Storage / File System","tags":["WIN-STORAGE","Windows Storage Error","Disk / Ntfs / StorPort","Verified"],"keywords":["0x800701b1","win","storage","disk","ntfs","storport","nonexistent","device","was","specified","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers"],"errorCode":"0x800701B1","eventId":"","severity":"High","summary":"A nonexistent device was specified.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x800701B1 - A nonexistent device was specified.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A nonexistent device was specified.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"Get-PhysicalDisk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Disk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Volume","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-StorageReliabilityCounter","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-WinEvent for Disk, Ntfs, StorPort, stornvme, and storage-controller events","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x800701B1","identifiers":["0x800701B1"],"identifierType":"Windows Storage Error","namespace":"WIN-STORAGE","platform":"Windows","component":"Disk / Ntfs / StorPort","eventSource":"Disk / Ntfs / StorPort","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not run destructive disk repair or initialize/format media before backups, hardware evidence, and recovery planning are complete.","logsToCheck":"System log: Disk, Ntfs, StorPort, stornvme, and controller events; hardware diagnostics","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x800701B1\nNamespace: WIN-STORAGE\nType: Windows Storage Error\nPlatform: Windows\nProduct: Windows Storage / File System\nComponent: Disk / Ntfs / StorPort\nReview status: Verified\n\nMeaning: A nonexistent device was specified.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: System log: Disk, Ntfs, StorPort, stornvme, and controller events; hardware diagnostics\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Storage"],"technologies":["WIN-STORAGE","Windows Storage Error","Disk / Ntfs / StorPort","Verified"],"aliases":["0x800701B1"]},{"id":54189,"title":"0x800701E3 - The storage device reported a fatal hardware error","category":"Windows Server","product":"Windows Storage / File System","tags":["WIN-STORAGE","Windows Storage Error","Disk / Ntfs / StorPort","Verified"],"keywords":["0x800701e3","win","storage","disk","ntfs","storport","the","device","reported","fatal","hardware","error","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions"],"errorCode":"0x800701E3","eventId":"","severity":"High","summary":"The storage device reported a fatal hardware error.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x800701E3 - The storage device reported a fatal hardware error.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The storage device reported a fatal hardware error.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"Get-PhysicalDisk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Disk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Volume","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-StorageReliabilityCounter","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-WinEvent for Disk, Ntfs, StorPort, stornvme, and storage-controller events","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x800701E3","identifiers":["0x800701E3"],"identifierType":"Windows Storage Error","namespace":"WIN-STORAGE","platform":"Windows","component":"Disk / Ntfs / StorPort","eventSource":"Disk / Ntfs / StorPort","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not run destructive disk repair or initialize/format media before backups, hardware evidence, and recovery planning are complete.","logsToCheck":"System log: Disk, Ntfs, StorPort, stornvme, and controller events; hardware diagnostics","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x800701E3\nNamespace: WIN-STORAGE\nType: Windows Storage Error\nPlatform: Windows\nProduct: Windows Storage / File System\nComponent: Disk / Ntfs / StorPort\nReview status: Verified\n\nMeaning: The storage device reported a fatal hardware error.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: System log: Disk, Ntfs, StorPort, stornvme, and controller events; hardware diagnostics\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Storage"],"technologies":["WIN-STORAGE","Windows Storage Error","Disk / Ntfs / StorPort","Verified"],"aliases":["0x800701E3"]},{"id":54190,"title":"0x800703EE - The file volume was externally altered during an operation","category":"Windows Server","product":"Windows Storage / File System","tags":["WIN-STORAGE","Windows Storage Error","Disk / Ntfs / StorPort","Verified"],"keywords":["0x800703ee","win","storage","disk","ntfs","storport","the","file","volume","was","externally","altered","during","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies"],"errorCode":"0x800703EE","eventId":"","severity":"High","summary":"The file volume was externally altered during an operation.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x800703EE - The file volume was externally altered during an operation.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The file volume was externally altered during an operation.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"Get-PhysicalDisk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Disk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Volume","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-StorageReliabilityCounter","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-WinEvent for Disk, Ntfs, StorPort, stornvme, and storage-controller events","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x800703EE","identifiers":["0x800703EE"],"identifierType":"Windows Storage Error","namespace":"WIN-STORAGE","platform":"Windows","component":"Disk / Ntfs / StorPort","eventSource":"Disk / Ntfs / StorPort","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not run destructive disk repair or initialize/format media before backups, hardware evidence, and recovery planning are complete.","logsToCheck":"System log: Disk, Ntfs, StorPort, stornvme, and controller events; hardware diagnostics","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x800703EE\nNamespace: WIN-STORAGE\nType: Windows Storage Error\nPlatform: Windows\nProduct: Windows Storage / File System\nComponent: Disk / Ntfs / StorPort\nReview status: Verified\n\nMeaning: The file volume was externally altered during an operation.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: System log: Disk, Ntfs, StorPort, stornvme, and controller events; hardware diagnostics\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Storage"],"technologies":["WIN-STORAGE","Windows Storage Error","Disk / Ntfs / StorPort","Verified"],"aliases":["0x800703EE"]},{"id":54191,"title":"0x80070570 - A file or directory is corrupted and unreadable","category":"Windows Server","product":"Windows Storage / File System","tags":["WIN-STORAGE","Windows Storage Error","Disk / Ntfs / StorPort","Verified"],"keywords":["0x80070570","win","storage","disk","ntfs","storport","file","directory","corrupted","and","unreadable","the","operation","fails","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers"],"errorCode":"0x80070570","eventId":"","severity":"High","summary":"A file or directory is corrupted and unreadable.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x80070570 - A file or directory is corrupted and unreadable.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A file or directory is corrupted and unreadable.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"Get-PhysicalDisk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Disk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Volume","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-StorageReliabilityCounter","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-WinEvent for Disk, Ntfs, StorPort, stornvme, and storage-controller events","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x80070570","identifiers":["0x80070570"],"identifierType":"Windows Storage Error","namespace":"WIN-STORAGE","platform":"Windows","component":"Disk / Ntfs / StorPort","eventSource":"Disk / Ntfs / StorPort","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not run destructive disk repair or initialize/format media before backups, hardware evidence, and recovery planning are complete.","logsToCheck":"System log: Disk, Ntfs, StorPort, stornvme, and controller events; hardware diagnostics","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x80070570\nNamespace: WIN-STORAGE\nType: Windows Storage Error\nPlatform: Windows\nProduct: Windows Storage / File System\nComponent: Disk / Ntfs / StorPort\nReview status: Verified\n\nMeaning: A file or directory is corrupted and unreadable.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: System log: Disk, Ntfs, StorPort, stornvme, and controller events; hardware diagnostics\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Storage"],"technologies":["WIN-STORAGE","Windows Storage Error","Disk / Ntfs / StorPort","Verified"],"aliases":["0x80070570"]},{"id":54192,"title":"0xC0000185 - An I/O communication or storage-path failure occurred","category":"Windows Server","product":"Windows Storage / File System","tags":["WIN-STORAGE","Windows Storage Error","Disk / Ntfs / StorPort","Verified"],"keywords":["0xc0000185","win","storage","disk","ntfs","storport","communication","path","failure","occurred","troubleshooting","requirements","collect","get","physicaldisk","volume","storagereliabilitycounter","winevent","for","stornvme","and","controller","events","check","smart","vendor","health","logs","firmware","cabling","backplane","power","raid","status","latency","file","system","state","recent","event"],"errorCode":"0xC0000185","eventId":"","severity":"High","summary":"An I/O communication or storage-path failure occurred.\nSTORAGE TROUBLESHOOTING REQUIREMENTS:\nCollect:\nGet-PhysicalDisk\nGet-Disk\nGet-Volume\nGet-StorageReliabilityCounter\nGet-WinEvent for Disk, Ntfs, StorPort, stornvme, and storage-controller events\nCheck:\n- SMART or vendor health\n- Controller logs\n- Storage firmware\n- Cabling\n- Backplane\n- Power\n- RAID status\n- Disk latency\n- File-system state\n- Recent Event IDs 7, 11, 51, 55, 129, 153, and 157\nIMPORTANT:\nDo not run chkdsk /f or chkdsk /r automatically when hardware failure is\nsuspected.\nFirst:\n1. Confirm backups.\n2. Confirm storage health.\n3. Assess data-loss risk.\n4. Capture logs.\n5. Determine whether copying data or replacing the disk is safer.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0xC0000185 - An I/O communication or storage-path failure occurred.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: An I/O communication or storage-path failure occurred.\nSTORAGE TROUBLESHOOTING REQUIREMENTS:\nCollect:\nGet-PhysicalDisk\nGet-Disk\nGet-Volume\nGet-StorageReliabilityCounter\nGet-WinEvent for Disk, Ntfs, StorPort, stornvme, and storage-controller events\nCheck:\n- SMART or vendor health\n- Controller logs\n- Storage firmware\n- Cabling\n- Backplane\n- Power\n- RAID status\n- Disk latency\n- File-system state\n- Recent Event IDs 7, 11, 51, 55, 129, 153, and 157\nIMPORTANT:\nDo not run chkdsk /f or chkdsk /r automatically when hardware failure is\nsuspected.\nFirst:\n1. Confirm backups.\n2. Confirm storage health.\n3. Assess data-loss risk.\n4. Capture logs.\n5. Determine whether copying data or replacing the disk is safer.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[{"command":"Get-PhysicalDisk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Disk","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-Volume","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-StorageReliabilityCounter","admin":true,"restart":false,"risk":"Standard"},{"command":"Get-WinEvent for Disk, Ntfs, StorPort, stornvme, and storage-controller events","admin":true,"restart":false,"risk":"Standard"}],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0xC0000185","identifiers":["0xC0000185"],"identifierType":"Windows Storage Error","namespace":"WIN-STORAGE","platform":"Windows","component":"Disk / Ntfs / StorPort","eventSource":"Disk / Ntfs / StorPort","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Potential","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not run destructive disk repair or initialize/format media before backups, hardware evidence, and recovery planning are complete.","logsToCheck":"System log: Disk, Ntfs, StorPort, stornvme, and controller events; hardware diagnostics","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0xC0000185\nNamespace: WIN-STORAGE\nType: Windows Storage Error\nPlatform: Windows\nProduct: Windows Storage / File System\nComponent: Disk / Ntfs / StorPort\nReview status: Verified\n\nMeaning: An I/O communication or storage-path failure occurred.\nSTORAGE TROUBLESHOOTING REQUIREMENTS:\nCollect:\nGet-PhysicalDisk\nGet-Disk\nGet-Volume\nGet-StorageReliabilityCounter\nGet-WinEvent for Disk, Ntfs, StorPort, stornvme, and storage-controller events\nCheck:\n- SMART or vendor health\n- Controller logs\n- Storage firmware\n- Cabling\n- Backplane\n- Power\n- RAID status\n- Disk latency\n- File-system state\n- Recent Event IDs 7, 11, 51, 55, 129, 153, and 157\nIMPORTANT:\nDo not run chkdsk /f or chkdsk /r automatically when hardware failure is\nsuspected.\nFirst:\n1. Confirm backups.\n2. Confirm storage health.\n3. Assess data-loss risk.\n4. Capture logs.\n5. Determine whether copying data or replacing the disk is safer.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: System log: Disk, Ntfs, StorPort, stornvme, and controller events; hardware diagnostics\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate immediately for repeated crashes, hardware warnings, corruption, encryption or recovery uncertainty, failed backups, production impact, or any condition with potential data loss.","platforms":["unknown"],"vendors":["Windows Storage"],"technologies":["WIN-STORAGE","Windows Storage Error","Disk / Ntfs / StorPort","Verified"],"aliases":["0xC0000185"]},{"id":54193,"title":"0x0000011B - Windows could not connect to the shared printer following printer security or\nRPC changes","category":"Printers","product":"Windows Printing","tags":["WIN-PRINT","Windows Printing Error","PrintService","Verified"],"keywords":["0x0000011b","win","print","printservice","windows","could","not","connect","the","shared","printer","following","security","rpc","changes","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include"],"errorCode":"0x0000011B","eventId":"","severity":"Low","summary":"Windows could not connect to the shared printer following printer security or\nRPC changes.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x0000011B - Windows could not connect to the shared printer following printer security or\nRPC changes.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Windows could not connect to the shared printer following printer security or\nRPC changes.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x0000011B","identifiers":["0x0000011B"],"identifierType":"Windows Printing Error","namespace":"WIN-PRINT","platform":"Windows","component":"PrintService","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace a production driver without recording the current configuration, testing one device, and preparing rollback.","logsToCheck":"PrintService Operational/Admin logs; System log; spooler and application logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x0000011B\nNamespace: WIN-PRINT\nType: Windows Printing Error\nPlatform: Windows\nProduct: Windows Printing\nComponent: PrintService\nReview status: Verified\n\nMeaning: Windows could not connect to the shared printer following printer security or\nRPC changes.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: PrintService Operational/Admin logs; System log; spooler and application logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-PRINT","Windows Printing Error","PrintService","Verified"],"aliases":["0x0000011B"]},{"id":54194,"title":"0x00000709 - Windows could not set the default printer or complete a printer-connection\noperation","category":"Printers","product":"Windows Printing","tags":["WIN-PRINT","Windows Printing Error","PrintService","Verified"],"keywords":["0x00000709","win","print","printservice","windows","could","not","set","the","default","printer","complete","connection","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies"],"errorCode":"0x00000709","eventId":"","severity":"High","summary":"Windows could not set the default printer or complete a printer-connection\noperation.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x00000709 - Windows could not set the default printer or complete a printer-connection\noperation.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Windows could not set the default printer or complete a printer-connection\noperation.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x00000709","identifiers":["0x00000709"],"identifierType":"Windows Printing Error","namespace":"WIN-PRINT","platform":"Windows","component":"PrintService","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace a production driver without recording the current configuration, testing one device, and preparing rollback.","logsToCheck":"PrintService Operational/Admin logs; System log; spooler and application logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x00000709\nNamespace: WIN-PRINT\nType: Windows Printing Error\nPlatform: Windows\nProduct: Windows Printing\nComponent: PrintService\nReview status: Verified\n\nMeaning: Windows could not set the default printer or complete a printer-connection\noperation.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: PrintService Operational/Admin logs; System log; spooler and application logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-PRINT","Windows Printing Error","PrintService","Verified"],"aliases":["0x00000709"]},{"id":54195,"title":"0x0000007E - A required print-driver module could not be found","category":"Printers","product":"Windows Printing","tags":["WIN-PRINT","Windows Printing Error","PrintService","Verified"],"keywords":["0x0000007e","win","print","printservice","required","driver","module","could","not","found","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers"],"errorCode":"0x0000007E","eventId":"","severity":"Low","summary":"A required print-driver module could not be found.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x0000007E - A required print-driver module could not be found.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A required print-driver module could not be found.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x0000007E","identifiers":["0x0000007E"],"identifierType":"Windows Printing Error","namespace":"WIN-PRINT","platform":"Windows","component":"PrintService","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace a production driver without recording the current configuration, testing one device, and preparing rollback.","logsToCheck":"PrintService Operational/Admin logs; System log; spooler and application logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x0000007E\nNamespace: WIN-PRINT\nType: Windows Printing Error\nPlatform: Windows\nProduct: Windows Printing\nComponent: PrintService\nReview status: Verified\n\nMeaning: A required print-driver module could not be found.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: PrintService Operational/Admin logs; System log; spooler and application logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-PRINT","Windows Printing Error","PrintService","Verified"],"aliases":["0x0000007E"]},{"id":54196,"title":"0x00000057 - An invalid printer parameter was supplied","category":"Printers","product":"Windows Printing","tags":["WIN-PRINT","Windows Printing Error","PrintService","Verified"],"keywords":["0x00000057","win","print","printservice","invalid","printer","parameter","was","supplied","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services"],"errorCode":"0x00000057","eventId":"","severity":"Medium","summary":"An invalid printer parameter was supplied.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x00000057 - An invalid printer parameter was supplied.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: An invalid printer parameter was supplied.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x00000057","identifiers":["0x00000057"],"identifierType":"Windows Printing Error","namespace":"WIN-PRINT","platform":"Windows","component":"PrintService","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace a production driver without recording the current configuration, testing one device, and preparing rollback.","logsToCheck":"PrintService Operational/Admin logs; System log; spooler and application logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x00000057\nNamespace: WIN-PRINT\nType: Windows Printing Error\nPlatform: Windows\nProduct: Windows Printing\nComponent: PrintService\nReview status: Verified\n\nMeaning: An invalid printer parameter was supplied.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: PrintService Operational/Admin logs; System log; spooler and application logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-PRINT","Windows Printing Error","PrintService","Verified"],"aliases":["0x00000057"]},{"id":54197,"title":"0x000006BA - The RPC server required by printing is unavailable","category":"Printers","product":"Windows Printing","tags":["WIN-PRINT","Windows Printing Error","PrintService","Verified"],"keywords":["0x000006ba","win","print","printservice","the","rpc","server","required","printing","unavailable","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services"],"errorCode":"0x000006BA","eventId":"","severity":"Low","summary":"The RPC server required by printing is unavailable.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x000006BA - The RPC server required by printing is unavailable.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: The RPC server required by printing is unavailable.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x000006BA","identifiers":["0x000006BA"],"identifierType":"Windows Printing Error","namespace":"WIN-PRINT","platform":"Windows","component":"PrintService","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace a production driver without recording the current configuration, testing one device, and preparing rollback.","logsToCheck":"PrintService Operational/Admin logs; System log; spooler and application logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x000006BA\nNamespace: WIN-PRINT\nType: Windows Printing Error\nPlatform: Windows\nProduct: Windows Printing\nComponent: PrintService\nReview status: Verified\n\nMeaning: The RPC server required by printing is unavailable.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: PrintService Operational/Admin logs; System log; spooler and application logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-PRINT","Windows Printing Error","PrintService","Verified"],"aliases":["0x000006BA"]},{"id":54198,"title":"0x000006B9 - Insufficient resources are available to complete the printer operation","category":"Printers","product":"Windows Printing","tags":["WIN-PRINT","Windows Printing Error","PrintService","Verified"],"keywords":["0x000006b9","win","print","printservice","insufficient","resources","are","available","complete","the","printer","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers"],"errorCode":"0x000006B9","eventId":"","severity":"Low","summary":"Insufficient resources are available to complete the printer operation.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x000006B9 - Insufficient resources are available to complete the printer operation.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: Insufficient resources are available to complete the printer operation.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x000006B9","identifiers":["0x000006B9"],"identifierType":"Windows Printing Error","namespace":"WIN-PRINT","platform":"Windows","component":"PrintService","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace a production driver without recording the current configuration, testing one device, and preparing rollback.","logsToCheck":"PrintService Operational/Admin logs; System log; spooler and application logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x000006B9\nNamespace: WIN-PRINT\nType: Windows Printing Error\nPlatform: Windows\nProduct: Windows Printing\nComponent: PrintService\nReview status: Verified\n\nMeaning: Insufficient resources are available to complete the printer operation.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: PrintService Operational/Admin logs; System log; spooler and application logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-PRINT","Windows Printing Error","PrintService","Verified"],"aliases":["0x000006B9"]},{"id":54199,"title":"0x00000BC4 - No printers were found","category":"Printers","product":"Windows Printing","tags":["WIN-PRINT","Windows Printing Error","PrintService","Verified"],"keywords":["0x00000bc4","win","print","printservice","printers","were","found","the","operation","fails","and","may","produce","identifier","application","deployment","report","event","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity","damaged"],"errorCode":"0x00000BC4","eventId":"","severity":"Low","summary":"No printers were found.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","emailScript":"Hello,\n\nWe reviewed the issue related to 0x00000BC4 - No printers were found.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: No printers were found.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"0x00000BC4","identifiers":["0x00000BC4"],"identifierType":"Windows Printing Error","namespace":"WIN-PRINT","platform":"Windows","component":"PrintService","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the complete message and matching logs.\n2. Confirm the affected component, context, and recent changes.\n3. Apply the least disruptive evidence-based correction.\n4. Retry the original operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not replace a production driver without recording the current configuration, testing one device, and preparing rollback.","logsToCheck":"PrintService Operational/Admin logs; System log; spooler and application logs","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: 0x00000BC4\nNamespace: WIN-PRINT\nType: Windows Printing Error\nPlatform: Windows\nProduct: Windows Printing\nComponent: PrintService\nReview status: Verified\n\nMeaning: No printers were found.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: PrintService Operational/Admin logs; System log; spooler and application logs\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-PRINT","Windows Printing Error","PrintService","Verified"],"aliases":["0x00000BC4"]},{"id":54200,"title":"Event ID 372 - A print job failed","category":"Printers","product":"Windows Printing","tags":["WIN-EVENT","Windows Event ID","PrintService","Verified"],"keywords":["event","372","win","printservice","print","job","failed","the","operation","fails","and","may","produce","identifier","application","deployment","report","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity","damaged","state"],"errorCode":"","eventId":"372","severity":"High","summary":"A print job failed.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 372 - A print job failed.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A print job failed.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 372","identifiers":["Event ID 372"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"PrintService","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 372\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Printing\nComponent: PrintService\nReview status: Verified\n\nMeaning: A print job failed.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-EVENT","Windows Event ID","PrintService","Verified"],"aliases":["372"]},{"id":54201,"title":"Event ID 808 - A print processor, driver, or rendering operation failed","category":"Printers","product":"Windows Printing","tags":["WIN-EVENT","Windows Event ID","PrintService","Verified"],"keywords":["event","808","win","printservice","print","processor","driver","rendering","operation","failed","the","fails","and","may","produce","identifier","application","deployment","report","viewer","entry","setup","log","system","crash","exact","cause","depends","component","surrounding","evidence","common","factors","include","configuration","dependencies","permissions","drivers","services","connectivity"],"errorCode":"","eventId":"808","severity":"High","summary":"A print processor, driver, or rendering operation failed.","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 808 - A print processor, driver, or rendering operation failed.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A print processor, driver, or rendering operation failed.\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 808","identifiers":["Event ID 808"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"PrintService","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 808\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Printing\nComponent: PrintService\nReview status: Verified\n\nMeaning: A print processor, driver, or rendering operation failed.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-EVENT","Windows Event ID","PrintService","Verified"],"aliases":["808"]},{"id":54202,"title":"Event ID 215 - A printer driver installation failed","category":"Printers","product":"Windows Printing","tags":["WIN-EVENT","Windows Event ID","PrintService","Verified"],"keywords":["event","215","win","printservice","printer","driver","installation","failed","printing","symptom","entries","create","searchable","articles","for","prints","gibberish","blank","pages","only","part","the","job","duplicate","print","jobs","stuck","queue","spooler","repeatedly","crashes","shared","disappeared","goes","offline","wrong","label","size","uses","microsoft"],"errorCode":"","eventId":"215","severity":"High","summary":"A printer driver installation failed.\nPRINTING SYMPTOM ENTRIES:\nCreate searchable symptom articles for:\n- Printer prints gibberish\n- Printer prints blank pages\n- Printer prints only part of the job\n- Duplicate print jobs\n- Print job stuck in queue\n- Print Spooler repeatedly crashes\n- Shared printer disappeared\n- Printer repeatedly goes offline\n- Wrong label size\n- Printer uses Microsoft IPP Class Driver instead of vendor driver\n- Printer works from Windows but not from an application\n- Local print connector is not listening\n- Local print connector crashes on request\n- Cash drawer does not open\n- RAW versus EMF rendering mismatch\n- PCL versus PostScript driver mismatch\n- Client and print-server driver versions differ\n- Windows replaces an approved vendor driver\nPRINTING TROUBLESHOOTING REQUIREMENTS:\nCheck:\n- Printer IP address\n- DNS\n- Standard TCP/IP versus WSD or IPP port\n- RAW port 9100\n- SNMP status\n- Driver name\n- Driver version\n- PCL, PCL6, PostScript, or class driver\n- Print processor\n- Data type\n- Client-side rendering\n- Advanced printing features\n- Print-server driver\n- Application-specific behavior\n- Spooler and PrintService logs\n- Device web interface\n- Firmware\n- Queue permissions\nDo not recommend changing a production printer driver without:\n- Confirming the printer model\n- Confirming supported page-description language\n- Recording the existing driver\n- Testing on one device\n- Having a rollback plan","rootCause":"The exact cause depends on the component and surrounding evidence; common factors include configuration, dependencies, permissions, drivers, services, connectivity, or damaged state.","resolution":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","emailScript":"Hello,\n\nWe reviewed the issue related to Event ID 215 - A printer driver installation failed.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: A printer driver installation failed.\nPRINTING SYMPTOM ENTRIES:\nCreate searchable symptom articles for:\n- Printer prints gibberish\n- Printer prints blank pages\n- Printer prints only part of the job\n- Duplicate print jobs\n- Print job stuck in queue\n- Print Spooler repeatedly crashes\n- Shared printer disappeared\n- Printer repeatedly goes offline\n- Wrong label size\n- Printer uses Microsoft IPP Class Driver instead of vendor driver\n- Printer works from Windows but not from an application\n- Local print connector is not listening\n- Local print connector crashes on request\n- Cash drawer does not open\n- RAW versus EMF rendering mismatch\n- PCL versus PostScript driver mismatch\n- Client and print-server driver versions differ\n- Windows replaces an approved vendor driver\nPRINTING TROUBLESHOOTING REQUIREMENTS:\nCheck:\n- Printer IP address\n- DNS\n- Standard TCP/IP versus WSD or IPP port\n- RAW port 9100\n- SNMP status\n- Driver name\n- Driver version\n- PCL, PCL6, PostScript, or class driver\n- Print processor\n- Data type\n- Client-side rendering\n- Advanced printing features\n- Print-server driver\n- Application-specific behavior\n- Spooler and PrintService logs\n- Device web interface\n- Firmware\n- Queue permissions\nDo not recommend changing a production printer driver without:\n- Confirming the printer model\n- Confirming supported page-description language\n- Recording the existing driver\n- Testing on one device\n- Having a rollback plan\n\nAdvanced fixes: Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Event ID 215","identifiers":["Event ID 215"],"identifierType":"Windows Event ID","namespace":"WIN-EVENT","platform":"Windows","component":"PrintService","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Yes","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"The operation fails and may produce the identifier in an application, deployment report, Event Viewer entry, setup log, or system crash.","firstLineFixes":"1. Capture the full event, source, timestamp, and surrounding events.\n2. Identify the affected component and recent changes.\n3. Correct the evidence-backed cause and reproduce the operation.","advancedFixes":"Use component-specific logs and vendor documentation to select advanced repair. Obtain approval, backups, recovery material, and a maintenance window when impact requires them.","doNotDo":"Do not apply destructive or security-reducing changes without evidence, approval, and a rollback plan.","logsToCheck":"Relevant Windows, application, and management logs for the exact timestamp","verification":"1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.","escalationCriteria":"Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Event ID 215\nNamespace: WIN-EVENT\nType: Windows Event ID\nPlatform: Windows\nProduct: Windows Printing\nComponent: PrintService\nReview status: Verified\n\nMeaning: A printer driver installation failed.\nPRINTING SYMPTOM ENTRIES:\nCreate searchable symptom articles for:\n- Printer prints gibberish\n- Printer prints blank pages\n- Printer prints only part of the job\n- Duplicate print jobs\n- Print job stuck in queue\n- Print Spooler repeatedly crashes\n- Shared printer disappeared\n- Printer repeatedly goes offline\n- Wrong label size\n- Printer uses Microsoft IPP Class Driver instead of vendor driver\n- Printer works from Windows but not from an application\n- Local print connector is not listening\n- Local print connector crashes on request\n- Cash drawer does not open\n- RAW versus EMF rendering mismatch\n- PCL versus PostScript driver mismatch\n- Client and print-server driver versions differ\n- Windows replaces an approved vendor driver\nPRINTING TROUBLESHOOTING REQUIREMENTS:\nCheck:\n- Printer IP address\n- DNS\n- Standard TCP/IP versus WSD or IPP port\n- RAW port 9100\n- SNMP status\n- Driver name\n- Driver version\n- PCL, PCL6, PostScript, or class driver\n- Print processor\n- Data type\n- Client-side rendering\n- Advanced printing features\n- Print-server driver\n- Application-specific behavior\n- Spooler and PrintService logs\n- Device web interface\n- Firmware\n- Queue permissions\nDo not recommend changing a production printer driver without:\n- Confirming the printer model\n- Confirming supported page-description language\n- Recording the existing driver\n- Testing on one device\n- Having a rollback plan\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: Relevant Windows, application, and management logs for the exact timestamp\n\nVerification: 1. Reproduce the original operation.\n2. Confirm the identifier and symptom do not recur.\n3. Validate the affected service, application, or device state.\n4. Document the evidence, change, and result.\n\nEscalation: Escalate when the issue affects a production server, repeats after evidence-based repair, risks data or security, requires vendor analysis, or cannot be validated safely.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-EVENT","Windows Event ID","PrintService","Verified"],"aliases":["215"]},{"id":54203,"title":"Printer prints gibberish","category":"Printers","product":"Windows Printing","tags":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"keywords":["printer","prints","gibberish","win","print","symptom","spooler","driver","queue","searchable","reference","for","possible","causes","include","the","port","configuration","dns","connectivity","language","version","processor","data","type","client","side","rendering","state","firmware","permissions","application","specific","behavior"],"errorCode":"Printer prints gibberish","eventId":"","severity":"Low","summary":"A searchable symptom reference for: Printer prints gibberish.","rootCause":"Possible causes include the printer or port configuration, DNS or connectivity, driver language/version, print processor, data type, client-side rendering, spooler state, firmware, permissions, or application-specific behavior.","resolution":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","emailScript":"Hello,\n\nWe reviewed the issue related to Printer prints gibberish.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nAdvanced fixes: Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Printer prints gibberish","identifiers":["Printer prints gibberish"],"identifierType":"Plain-text Error Message / Symptom","namespace":"WIN-PRINT-SYMPTOM","platform":"Windows","component":"Print Spooler / Driver / Queue","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on remediation","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"Printer prints gibberish","firstLineFixes":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","advancedFixes":"Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","doNotDo":"Do not replace a production driver or purge queues without recording configuration, assessing impact, and preparing rollback.","logsToCheck":"PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface","verification":"Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.","escalationCriteria":"Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Printer prints gibberish\nNamespace: WIN-PRINT-SYMPTOM\nType: Plain-text Error Message / Symptom\nPlatform: Windows\nProduct: Windows Printing\nComponent: Print Spooler / Driver / Queue\nReview status: Needs Review\n\nMeaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface\n\nVerification: Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.\n\nEscalation: Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"aliases":["Printer prints gibberish"]},{"id":54204,"title":"Printer prints blank pages","category":"Printers","product":"Windows Printing","tags":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"keywords":["printer","prints","blank","pages","win","print","symptom","spooler","driver","queue","searchable","reference","for","possible","causes","include","the","port","configuration","dns","connectivity","language","version","processor","data","type","client","side","rendering","state","firmware","permissions","application","specific","behavior"],"errorCode":"Printer prints blank pages","eventId":"","severity":"Low","summary":"A searchable symptom reference for: Printer prints blank pages.","rootCause":"Possible causes include the printer or port configuration, DNS or connectivity, driver language/version, print processor, data type, client-side rendering, spooler state, firmware, permissions, or application-specific behavior.","resolution":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","emailScript":"Hello,\n\nWe reviewed the issue related to Printer prints blank pages.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nAdvanced fixes: Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Printer prints blank pages","identifiers":["Printer prints blank pages"],"identifierType":"Plain-text Error Message / Symptom","namespace":"WIN-PRINT-SYMPTOM","platform":"Windows","component":"Print Spooler / Driver / Queue","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on remediation","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"Printer prints blank pages","firstLineFixes":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","advancedFixes":"Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","doNotDo":"Do not replace a production driver or purge queues without recording configuration, assessing impact, and preparing rollback.","logsToCheck":"PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface","verification":"Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.","escalationCriteria":"Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Printer prints blank pages\nNamespace: WIN-PRINT-SYMPTOM\nType: Plain-text Error Message / Symptom\nPlatform: Windows\nProduct: Windows Printing\nComponent: Print Spooler / Driver / Queue\nReview status: Needs Review\n\nMeaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface\n\nVerification: Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.\n\nEscalation: Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"aliases":["Printer prints blank pages"]},{"id":54205,"title":"Printer prints only part of the job","category":"Printers","product":"Windows Printing","tags":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"keywords":["printer","prints","only","part","the","job","win","print","symptom","spooler","driver","queue","searchable","reference","for","possible","causes","include","port","configuration","dns","connectivity","language","version","processor","data","type","client","side","rendering","state","firmware","permissions","application","specific","behavior"],"errorCode":"Printer prints only part of the job","eventId":"","severity":"Low","summary":"A searchable symptom reference for: Printer prints only part of the job.","rootCause":"Possible causes include the printer or port configuration, DNS or connectivity, driver language/version, print processor, data type, client-side rendering, spooler state, firmware, permissions, or application-specific behavior.","resolution":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","emailScript":"Hello,\n\nWe reviewed the issue related to Printer prints only part of the job.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nAdvanced fixes: Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Printer prints only part of the job","identifiers":["Printer prints only part of the job"],"identifierType":"Plain-text Error Message / Symptom","namespace":"WIN-PRINT-SYMPTOM","platform":"Windows","component":"Print Spooler / Driver / Queue","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on remediation","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"Printer prints only part of the job","firstLineFixes":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","advancedFixes":"Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","doNotDo":"Do not replace a production driver or purge queues without recording configuration, assessing impact, and preparing rollback.","logsToCheck":"PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface","verification":"Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.","escalationCriteria":"Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Printer prints only part of the job\nNamespace: WIN-PRINT-SYMPTOM\nType: Plain-text Error Message / Symptom\nPlatform: Windows\nProduct: Windows Printing\nComponent: Print Spooler / Driver / Queue\nReview status: Needs Review\n\nMeaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface\n\nVerification: Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.\n\nEscalation: Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"aliases":["Printer prints only part of the job"]},{"id":54206,"title":"Duplicate print jobs","category":"Printers","product":"Windows Printing","tags":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"keywords":["duplicate","print","jobs","win","symptom","spooler","driver","queue","searchable","reference","for","possible","causes","include","the","printer","port","configuration","dns","connectivity","language","version","processor","data","type","client","side","rendering","state","firmware","permissions","application","specific","behavior"],"errorCode":"Duplicate print jobs","eventId":"","severity":"Low","summary":"A searchable symptom reference for: Duplicate print jobs.","rootCause":"Possible causes include the printer or port configuration, DNS or connectivity, driver language/version, print processor, data type, client-side rendering, spooler state, firmware, permissions, or application-specific behavior.","resolution":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","emailScript":"Hello,\n\nWe reviewed the issue related to Duplicate print jobs.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nAdvanced fixes: Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Duplicate print jobs","identifiers":["Duplicate print jobs"],"identifierType":"Plain-text Error Message / Symptom","namespace":"WIN-PRINT-SYMPTOM","platform":"Windows","component":"Print Spooler / Driver / Queue","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on remediation","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"Duplicate print jobs","firstLineFixes":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","advancedFixes":"Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","doNotDo":"Do not replace a production driver or purge queues without recording configuration, assessing impact, and preparing rollback.","logsToCheck":"PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface","verification":"Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.","escalationCriteria":"Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Duplicate print jobs\nNamespace: WIN-PRINT-SYMPTOM\nType: Plain-text Error Message / Symptom\nPlatform: Windows\nProduct: Windows Printing\nComponent: Print Spooler / Driver / Queue\nReview status: Needs Review\n\nMeaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface\n\nVerification: Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.\n\nEscalation: Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"aliases":["Duplicate print jobs"]},{"id":54207,"title":"Print job stuck in queue","category":"Printers","product":"Windows Printing","tags":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"keywords":["print","job","stuck","queue","win","symptom","spooler","driver","searchable","reference","for","possible","causes","include","the","printer","port","configuration","dns","connectivity","language","version","processor","data","type","client","side","rendering","state","firmware","permissions","application","specific","behavior"],"errorCode":"Print job stuck in queue","eventId":"","severity":"Low","summary":"A searchable symptom reference for: Print job stuck in queue.","rootCause":"Possible causes include the printer or port configuration, DNS or connectivity, driver language/version, print processor, data type, client-side rendering, spooler state, firmware, permissions, or application-specific behavior.","resolution":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","emailScript":"Hello,\n\nWe reviewed the issue related to Print job stuck in queue.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nAdvanced fixes: Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Print job stuck in queue","identifiers":["Print job stuck in queue"],"identifierType":"Plain-text Error Message / Symptom","namespace":"WIN-PRINT-SYMPTOM","platform":"Windows","component":"Print Spooler / Driver / Queue","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on remediation","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"Print job stuck in queue","firstLineFixes":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","advancedFixes":"Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","doNotDo":"Do not replace a production driver or purge queues without recording configuration, assessing impact, and preparing rollback.","logsToCheck":"PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface","verification":"Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.","escalationCriteria":"Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Print job stuck in queue\nNamespace: WIN-PRINT-SYMPTOM\nType: Plain-text Error Message / Symptom\nPlatform: Windows\nProduct: Windows Printing\nComponent: Print Spooler / Driver / Queue\nReview status: Needs Review\n\nMeaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface\n\nVerification: Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.\n\nEscalation: Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"aliases":["Print job stuck in queue"]},{"id":54208,"title":"Print Spooler repeatedly crashes","category":"Printers","product":"Windows Printing","tags":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"keywords":["print","spooler","repeatedly","crashes","win","symptom","driver","queue","searchable","reference","for","possible","causes","include","the","printer","port","configuration","dns","connectivity","language","version","processor","data","type","client","side","rendering","state","firmware","permissions","application","specific","behavior"],"errorCode":"Print Spooler repeatedly crashes","eventId":"","severity":"Low","summary":"A searchable symptom reference for: Print Spooler repeatedly crashes.","rootCause":"Possible causes include the printer or port configuration, DNS or connectivity, driver language/version, print processor, data type, client-side rendering, spooler state, firmware, permissions, or application-specific behavior.","resolution":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","emailScript":"Hello,\n\nWe reviewed the issue related to Print Spooler repeatedly crashes.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nAdvanced fixes: Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Print Spooler repeatedly crashes","identifiers":["Print Spooler repeatedly crashes"],"identifierType":"Plain-text Error Message / Symptom","namespace":"WIN-PRINT-SYMPTOM","platform":"Windows","component":"Print Spooler / Driver / Queue","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on remediation","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"Print Spooler repeatedly crashes","firstLineFixes":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","advancedFixes":"Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","doNotDo":"Do not replace a production driver or purge queues without recording configuration, assessing impact, and preparing rollback.","logsToCheck":"PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface","verification":"Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.","escalationCriteria":"Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Print Spooler repeatedly crashes\nNamespace: WIN-PRINT-SYMPTOM\nType: Plain-text Error Message / Symptom\nPlatform: Windows\nProduct: Windows Printing\nComponent: Print Spooler / Driver / Queue\nReview status: Needs Review\n\nMeaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface\n\nVerification: Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.\n\nEscalation: Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"aliases":["Print Spooler repeatedly crashes"]},{"id":54209,"title":"Shared printer disappeared","category":"Printers","product":"Windows Printing","tags":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"keywords":["shared","printer","disappeared","win","print","symptom","spooler","driver","queue","searchable","reference","for","possible","causes","include","the","port","configuration","dns","connectivity","language","version","processor","data","type","client","side","rendering","state","firmware","permissions","application","specific","behavior"],"errorCode":"Shared printer disappeared","eventId":"","severity":"Low","summary":"A searchable symptom reference for: Shared printer disappeared.","rootCause":"Possible causes include the printer or port configuration, DNS or connectivity, driver language/version, print processor, data type, client-side rendering, spooler state, firmware, permissions, or application-specific behavior.","resolution":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","emailScript":"Hello,\n\nWe reviewed the issue related to Shared printer disappeared.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nAdvanced fixes: Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Shared printer disappeared","identifiers":["Shared printer disappeared"],"identifierType":"Plain-text Error Message / Symptom","namespace":"WIN-PRINT-SYMPTOM","platform":"Windows","component":"Print Spooler / Driver / Queue","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on remediation","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"Shared printer disappeared","firstLineFixes":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","advancedFixes":"Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","doNotDo":"Do not replace a production driver or purge queues without recording configuration, assessing impact, and preparing rollback.","logsToCheck":"PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface","verification":"Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.","escalationCriteria":"Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Shared printer disappeared\nNamespace: WIN-PRINT-SYMPTOM\nType: Plain-text Error Message / Symptom\nPlatform: Windows\nProduct: Windows Printing\nComponent: Print Spooler / Driver / Queue\nReview status: Needs Review\n\nMeaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface\n\nVerification: Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.\n\nEscalation: Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"aliases":["Shared printer disappeared"]},{"id":54210,"title":"Printer repeatedly goes offline","category":"Printers","product":"Windows Printing","tags":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"keywords":["printer","repeatedly","goes","offline","win","print","symptom","spooler","driver","queue","searchable","reference","for","possible","causes","include","the","port","configuration","dns","connectivity","language","version","processor","data","type","client","side","rendering","state","firmware","permissions","application","specific","behavior"],"errorCode":"Printer repeatedly goes offline","eventId":"","severity":"Low","summary":"A searchable symptom reference for: Printer repeatedly goes offline.","rootCause":"Possible causes include the printer or port configuration, DNS or connectivity, driver language/version, print processor, data type, client-side rendering, spooler state, firmware, permissions, or application-specific behavior.","resolution":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","emailScript":"Hello,\n\nWe reviewed the issue related to Printer repeatedly goes offline.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nAdvanced fixes: Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Printer repeatedly goes offline","identifiers":["Printer repeatedly goes offline"],"identifierType":"Plain-text Error Message / Symptom","namespace":"WIN-PRINT-SYMPTOM","platform":"Windows","component":"Print Spooler / Driver / Queue","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on remediation","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"Printer repeatedly goes offline","firstLineFixes":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","advancedFixes":"Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","doNotDo":"Do not replace a production driver or purge queues without recording configuration, assessing impact, and preparing rollback.","logsToCheck":"PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface","verification":"Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.","escalationCriteria":"Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Printer repeatedly goes offline\nNamespace: WIN-PRINT-SYMPTOM\nType: Plain-text Error Message / Symptom\nPlatform: Windows\nProduct: Windows Printing\nComponent: Print Spooler / Driver / Queue\nReview status: Needs Review\n\nMeaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface\n\nVerification: Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.\n\nEscalation: Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"aliases":["Printer repeatedly goes offline"]},{"id":54211,"title":"Wrong label size","category":"Printers","product":"Windows Printing","tags":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"keywords":["wrong","label","size","win","print","symptom","spooler","driver","queue","searchable","reference","for","possible","causes","include","the","printer","port","configuration","dns","connectivity","language","version","processor","data","type","client","side","rendering","state","firmware","permissions","application","specific","behavior"],"errorCode":"Wrong label size","eventId":"","severity":"Low","summary":"A searchable symptom reference for: Wrong label size.","rootCause":"Possible causes include the printer or port configuration, DNS or connectivity, driver language/version, print processor, data type, client-side rendering, spooler state, firmware, permissions, or application-specific behavior.","resolution":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","emailScript":"Hello,\n\nWe reviewed the issue related to Wrong label size.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nAdvanced fixes: Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Wrong label size","identifiers":["Wrong label size"],"identifierType":"Plain-text Error Message / Symptom","namespace":"WIN-PRINT-SYMPTOM","platform":"Windows","component":"Print Spooler / Driver / Queue","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on remediation","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"Wrong label size","firstLineFixes":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","advancedFixes":"Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","doNotDo":"Do not replace a production driver or purge queues without recording configuration, assessing impact, and preparing rollback.","logsToCheck":"PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface","verification":"Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.","escalationCriteria":"Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Wrong label size\nNamespace: WIN-PRINT-SYMPTOM\nType: Plain-text Error Message / Symptom\nPlatform: Windows\nProduct: Windows Printing\nComponent: Print Spooler / Driver / Queue\nReview status: Needs Review\n\nMeaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface\n\nVerification: Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.\n\nEscalation: Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"aliases":["Wrong label size"]},{"id":54212,"title":"Printer uses Microsoft IPP Class Driver instead of vendor driver","category":"Printers","product":"Windows Printing","tags":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"keywords":["printer","uses","microsoft","ipp","class","driver","instead","vendor","win","print","symptom","spooler","queue","searchable","reference","for","possible","causes","include","the","port","configuration","dns","connectivity","language","version","processor","data","type","client","side","rendering","state","firmware","permissions","application","specific","behavior"],"errorCode":"Printer uses Microsoft IPP Class Driver instead of vendor driver","eventId":"","severity":"Low","summary":"A searchable symptom reference for: Printer uses Microsoft IPP Class Driver instead of vendor driver.","rootCause":"Possible causes include the printer or port configuration, DNS or connectivity, driver language/version, print processor, data type, client-side rendering, spooler state, firmware, permissions, or application-specific behavior.","resolution":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","emailScript":"Hello,\n\nWe reviewed the issue related to Printer uses Microsoft IPP Class Driver instead of vendor driver.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nAdvanced fixes: Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Printer uses Microsoft IPP Class Driver instead of vendor driver","identifiers":["Printer uses Microsoft IPP Class Driver instead of vendor driver"],"identifierType":"Plain-text Error Message / Symptom","namespace":"WIN-PRINT-SYMPTOM","platform":"Windows","component":"Print Spooler / Driver / Queue","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on remediation","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"Printer uses Microsoft IPP Class Driver instead of vendor driver","firstLineFixes":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","advancedFixes":"Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","doNotDo":"Do not replace a production driver or purge queues without recording configuration, assessing impact, and preparing rollback.","logsToCheck":"PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface","verification":"Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.","escalationCriteria":"Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Printer uses Microsoft IPP Class Driver instead of vendor driver\nNamespace: WIN-PRINT-SYMPTOM\nType: Plain-text Error Message / Symptom\nPlatform: Windows\nProduct: Windows Printing\nComponent: Print Spooler / Driver / Queue\nReview status: Needs Review\n\nMeaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface\n\nVerification: Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.\n\nEscalation: Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"aliases":["Printer uses Microsoft IPP Class Driver instead of vendor driver"]},{"id":54213,"title":"Printer works from Windows but not from an application","category":"Printers","product":"Windows Printing","tags":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"keywords":["printer","works","from","windows","but","not","application","win","print","symptom","spooler","driver","queue","searchable","reference","for","possible","causes","include","the","port","configuration","dns","connectivity","language","version","processor","data","type","client","side","rendering","state","firmware","permissions","specific","behavior"],"errorCode":"Printer works from Windows but not from an application","eventId":"","severity":"Low","summary":"A searchable symptom reference for: Printer works from Windows but not from an application.","rootCause":"Possible causes include the printer or port configuration, DNS or connectivity, driver language/version, print processor, data type, client-side rendering, spooler state, firmware, permissions, or application-specific behavior.","resolution":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","emailScript":"Hello,\n\nWe reviewed the issue related to Printer works from Windows but not from an application.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nAdvanced fixes: Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Printer works from Windows but not from an application","identifiers":["Printer works from Windows but not from an application"],"identifierType":"Plain-text Error Message / Symptom","namespace":"WIN-PRINT-SYMPTOM","platform":"Windows","component":"Print Spooler / Driver / Queue","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on remediation","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"Printer works from Windows but not from an application","firstLineFixes":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","advancedFixes":"Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","doNotDo":"Do not replace a production driver or purge queues without recording configuration, assessing impact, and preparing rollback.","logsToCheck":"PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface","verification":"Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.","escalationCriteria":"Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Printer works from Windows but not from an application\nNamespace: WIN-PRINT-SYMPTOM\nType: Plain-text Error Message / Symptom\nPlatform: Windows\nProduct: Windows Printing\nComponent: Print Spooler / Driver / Queue\nReview status: Needs Review\n\nMeaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface\n\nVerification: Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.\n\nEscalation: Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"aliases":["Printer works from Windows but not from an application"]},{"id":54214,"title":"Local print connector is not listening","category":"Printers","product":"Windows Printing","tags":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"keywords":["local","print","connector","not","listening","win","symptom","spooler","driver","queue","searchable","reference","for","possible","causes","include","the","printer","port","configuration","dns","connectivity","language","version","processor","data","type","client","side","rendering","state","firmware","permissions","application","specific","behavior"],"errorCode":"Local print connector is not listening","eventId":"","severity":"Low","summary":"A searchable symptom reference for: Local print connector is not listening.","rootCause":"Possible causes include the printer or port configuration, DNS or connectivity, driver language/version, print processor, data type, client-side rendering, spooler state, firmware, permissions, or application-specific behavior.","resolution":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","emailScript":"Hello,\n\nWe reviewed the issue related to Local print connector is not listening.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nAdvanced fixes: Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Local print connector is not listening","identifiers":["Local print connector is not listening"],"identifierType":"Plain-text Error Message / Symptom","namespace":"WIN-PRINT-SYMPTOM","platform":"Windows","component":"Print Spooler / Driver / Queue","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on remediation","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"Local print connector is not listening","firstLineFixes":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","advancedFixes":"Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","doNotDo":"Do not replace a production driver or purge queues without recording configuration, assessing impact, and preparing rollback.","logsToCheck":"PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface","verification":"Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.","escalationCriteria":"Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Local print connector is not listening\nNamespace: WIN-PRINT-SYMPTOM\nType: Plain-text Error Message / Symptom\nPlatform: Windows\nProduct: Windows Printing\nComponent: Print Spooler / Driver / Queue\nReview status: Needs Review\n\nMeaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface\n\nVerification: Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.\n\nEscalation: Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"aliases":["Local print connector is not listening"]},{"id":54215,"title":"Local print connector crashes on request","category":"Printers","product":"Windows Printing","tags":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"keywords":["local","print","connector","crashes","request","win","symptom","spooler","driver","queue","searchable","reference","for","possible","causes","include","the","printer","port","configuration","dns","connectivity","language","version","processor","data","type","client","side","rendering","state","firmware","permissions","application","specific","behavior"],"errorCode":"Local print connector crashes on request","eventId":"","severity":"Low","summary":"A searchable symptom reference for: Local print connector crashes on request.","rootCause":"Possible causes include the printer or port configuration, DNS or connectivity, driver language/version, print processor, data type, client-side rendering, spooler state, firmware, permissions, or application-specific behavior.","resolution":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","emailScript":"Hello,\n\nWe reviewed the issue related to Local print connector crashes on request.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nAdvanced fixes: Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Local print connector crashes on request","identifiers":["Local print connector crashes on request"],"identifierType":"Plain-text Error Message / Symptom","namespace":"WIN-PRINT-SYMPTOM","platform":"Windows","component":"Print Spooler / Driver / Queue","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on remediation","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"Local print connector crashes on request","firstLineFixes":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","advancedFixes":"Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","doNotDo":"Do not replace a production driver or purge queues without recording configuration, assessing impact, and preparing rollback.","logsToCheck":"PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface","verification":"Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.","escalationCriteria":"Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Local print connector crashes on request\nNamespace: WIN-PRINT-SYMPTOM\nType: Plain-text Error Message / Symptom\nPlatform: Windows\nProduct: Windows Printing\nComponent: Print Spooler / Driver / Queue\nReview status: Needs Review\n\nMeaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface\n\nVerification: Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.\n\nEscalation: Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"aliases":["Local print connector crashes on request"]},{"id":54216,"title":"Cash drawer does not open","category":"Printers","product":"Windows Printing","tags":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"keywords":["cash","drawer","does","not","open","win","print","symptom","spooler","driver","queue","searchable","reference","for","possible","causes","include","the","printer","port","configuration","dns","connectivity","language","version","processor","data","type","client","side","rendering","state","firmware","permissions","application","specific","behavior"],"errorCode":"Cash drawer does not open","eventId":"","severity":"Low","summary":"A searchable symptom reference for: Cash drawer does not open.","rootCause":"Possible causes include the printer or port configuration, DNS or connectivity, driver language/version, print processor, data type, client-side rendering, spooler state, firmware, permissions, or application-specific behavior.","resolution":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","emailScript":"Hello,\n\nWe reviewed the issue related to Cash drawer does not open.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nAdvanced fixes: Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Cash drawer does not open","identifiers":["Cash drawer does not open"],"identifierType":"Plain-text Error Message / Symptom","namespace":"WIN-PRINT-SYMPTOM","platform":"Windows","component":"Print Spooler / Driver / Queue","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on remediation","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"Cash drawer does not open","firstLineFixes":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","advancedFixes":"Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","doNotDo":"Do not replace a production driver or purge queues without recording configuration, assessing impact, and preparing rollback.","logsToCheck":"PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface","verification":"Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.","escalationCriteria":"Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Cash drawer does not open\nNamespace: WIN-PRINT-SYMPTOM\nType: Plain-text Error Message / Symptom\nPlatform: Windows\nProduct: Windows Printing\nComponent: Print Spooler / Driver / Queue\nReview status: Needs Review\n\nMeaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface\n\nVerification: Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.\n\nEscalation: Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"aliases":["Cash drawer does not open"]},{"id":54217,"title":"RAW versus EMF rendering mismatch","category":"Printers","product":"Windows Printing","tags":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"keywords":["raw","versus","emf","rendering","mismatch","win","print","symptom","spooler","driver","queue","searchable","reference","for","possible","causes","include","the","printer","port","configuration","dns","connectivity","language","version","processor","data","type","client","side","state","firmware","permissions","application","specific","behavior"],"errorCode":"RAW versus EMF rendering mismatch","eventId":"","severity":"Low","summary":"A searchable symptom reference for: RAW versus EMF rendering mismatch.","rootCause":"Possible causes include the printer or port configuration, DNS or connectivity, driver language/version, print processor, data type, client-side rendering, spooler state, firmware, permissions, or application-specific behavior.","resolution":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","emailScript":"Hello,\n\nWe reviewed the issue related to RAW versus EMF rendering mismatch.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nAdvanced fixes: Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"RAW versus EMF rendering mismatch","identifiers":["RAW versus EMF rendering mismatch"],"identifierType":"Plain-text Error Message / Symptom","namespace":"WIN-PRINT-SYMPTOM","platform":"Windows","component":"Print Spooler / Driver / Queue","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on remediation","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"RAW versus EMF rendering mismatch","firstLineFixes":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","advancedFixes":"Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","doNotDo":"Do not replace a production driver or purge queues without recording configuration, assessing impact, and preparing rollback.","logsToCheck":"PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface","verification":"Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.","escalationCriteria":"Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: RAW versus EMF rendering mismatch\nNamespace: WIN-PRINT-SYMPTOM\nType: Plain-text Error Message / Symptom\nPlatform: Windows\nProduct: Windows Printing\nComponent: Print Spooler / Driver / Queue\nReview status: Needs Review\n\nMeaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface\n\nVerification: Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.\n\nEscalation: Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"aliases":["RAW versus EMF rendering mismatch"]},{"id":54218,"title":"PCL versus PostScript driver mismatch","category":"Printers","product":"Windows Printing","tags":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"keywords":["pcl","versus","postscript","driver","mismatch","win","print","symptom","spooler","queue","searchable","reference","for","possible","causes","include","the","printer","port","configuration","dns","connectivity","language","version","processor","data","type","client","side","rendering","state","firmware","permissions","application","specific","behavior"],"errorCode":"PCL versus PostScript driver mismatch","eventId":"","severity":"Low","summary":"A searchable symptom reference for: PCL versus PostScript driver mismatch.","rootCause":"Possible causes include the printer or port configuration, DNS or connectivity, driver language/version, print processor, data type, client-side rendering, spooler state, firmware, permissions, or application-specific behavior.","resolution":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","emailScript":"Hello,\n\nWe reviewed the issue related to PCL versus PostScript driver mismatch.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nAdvanced fixes: Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"PCL versus PostScript driver mismatch","identifiers":["PCL versus PostScript driver mismatch"],"identifierType":"Plain-text Error Message / Symptom","namespace":"WIN-PRINT-SYMPTOM","platform":"Windows","component":"Print Spooler / Driver / Queue","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on remediation","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"PCL versus PostScript driver mismatch","firstLineFixes":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","advancedFixes":"Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","doNotDo":"Do not replace a production driver or purge queues without recording configuration, assessing impact, and preparing rollback.","logsToCheck":"PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface","verification":"Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.","escalationCriteria":"Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: PCL versus PostScript driver mismatch\nNamespace: WIN-PRINT-SYMPTOM\nType: Plain-text Error Message / Symptom\nPlatform: Windows\nProduct: Windows Printing\nComponent: Print Spooler / Driver / Queue\nReview status: Needs Review\n\nMeaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface\n\nVerification: Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.\n\nEscalation: Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"aliases":["PCL versus PostScript driver mismatch"]},{"id":54219,"title":"Client and print-server driver versions differ","category":"Printers","product":"Windows Printing","tags":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"keywords":["client","and","print","server","driver","versions","differ","win","symptom","spooler","queue","searchable","reference","for","possible","causes","include","the","printer","port","configuration","dns","connectivity","language","version","processor","data","type","side","rendering","state","firmware","permissions","application","specific","behavior"],"errorCode":"Client and print-server driver versions differ","eventId":"","severity":"Low","summary":"A searchable symptom reference for: Client and print-server driver versions differ.","rootCause":"Possible causes include the printer or port configuration, DNS or connectivity, driver language/version, print processor, data type, client-side rendering, spooler state, firmware, permissions, or application-specific behavior.","resolution":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","emailScript":"Hello,\n\nWe reviewed the issue related to Client and print-server driver versions differ.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nAdvanced fixes: Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Client and print-server driver versions differ","identifiers":["Client and print-server driver versions differ"],"identifierType":"Plain-text Error Message / Symptom","namespace":"WIN-PRINT-SYMPTOM","platform":"Windows","component":"Print Spooler / Driver / Queue","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on remediation","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"Client and print-server driver versions differ","firstLineFixes":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","advancedFixes":"Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","doNotDo":"Do not replace a production driver or purge queues without recording configuration, assessing impact, and preparing rollback.","logsToCheck":"PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface","verification":"Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.","escalationCriteria":"Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Client and print-server driver versions differ\nNamespace: WIN-PRINT-SYMPTOM\nType: Plain-text Error Message / Symptom\nPlatform: Windows\nProduct: Windows Printing\nComponent: Print Spooler / Driver / Queue\nReview status: Needs Review\n\nMeaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface\n\nVerification: Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.\n\nEscalation: Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"aliases":["Client and print-server driver versions differ"]},{"id":54220,"title":"Windows replaces an approved vendor driver","category":"Printers","product":"Windows Printing","tags":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"keywords":["windows","replaces","approved","vendor","driver","win","print","symptom","spooler","queue","searchable","reference","for","possible","causes","include","the","printer","port","configuration","dns","connectivity","language","version","processor","data","type","client","side","rendering","state","firmware","permissions","application","specific","behavior"],"errorCode":"Windows replaces an approved vendor driver","eventId":"","severity":"Low","summary":"A searchable symptom reference for: Windows replaces an approved vendor driver.","rootCause":"Possible causes include the printer or port configuration, DNS or connectivity, driver language/version, print processor, data type, client-side rendering, spooler state, firmware, permissions, or application-specific behavior.","resolution":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","emailScript":"Hello,\n\nWe reviewed the issue related to Windows replaces an approved vendor driver.\n\nOur team is validating the affected configuration and applying the appropriate corrective steps. We are collecting the relevant Windows evidence and will apply the least disruptive verified correction.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Record the complete message and what you were doing.\n2. Save your work and avoid repeated retries if the device is crashing or storage is failing.\n3. Send IT Support the timestamp and a screenshot.\n4. Follow only the steps provided for this specific issue.","notes":"Technical meaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nAdvanced fixes: Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","commands":[],"sourceDocument":"windows_error_code_expansion.txt","identifier":"Windows replaces an approved vendor driver","identifiers":["Windows replaces an approved vendor driver"],"identifierType":"Plain-text Error Message / Symptom","namespace":"WIN-PRINT-SYMPTOM","platform":"Windows","component":"Print Spooler / Driver / Queue","eventSource":"PrintService","symbolicName":"","restartRequired":"Depends on remediation","adminRightsRequired":"Depends on remediation","dataLossRisk":"Low","securityImpact":"Low","contextWarning":"Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.","symptoms":"Windows replaces an approved vendor driver","firstLineFixes":"1. Record the printer model, IP, port type, driver, version, print processor, and failing application.\n2. Test the device web interface and a Windows test page.\n3. Compare behavior from another application and workstation.\n4. Review PrintService and spooler logs before changing the driver.","advancedFixes":"Test one approved driver or rendering change on one device with a rollback plan. Validate server/client driver compatibility and page-description language.","doNotDo":"Do not replace a production driver or purge queues without recording configuration, assessing impact, and preparing rollback.","logsToCheck":"PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface","verification":"Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.","escalationCriteria":"Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","relatedEventIds":[],"relatedErrorCodes":[],"relatedArticles":[],"lastVerified":"2026-08-06","technicianNotes":"Identifier: Windows replaces an approved vendor driver\nNamespace: WIN-PRINT-SYMPTOM\nType: Plain-text Error Message / Symptom\nPlatform: Windows\nProduct: Windows Printing\nComponent: Print Spooler / Driver / Queue\nReview status: Needs Review\n\nMeaning: This symptom does not identify a single root cause. Printer, port, driver, rendering, spooler, firmware, application, and network evidence must be correlated.\n\nContext: Windows identifiers are contextual. Capture the complete message, application, Event Source, Event ID, timestamp, operation, hexadecimal and decimal forms, and surrounding logs before selecting a fix. A generic code may describe only the final failure; review earlier entries for the original cause.\n\nEvidence / logs: PrintService Operational/Admin logs; System log; spooler logs; application logs; printer web interface\n\nVerification: Print a Windows test page and a representative job from the affected application; confirm correct output and no new PrintService errors.\n\nEscalation: Escalate for repeated spooler crashes, production-wide impact, firmware faults, unsupported drivers, or connector/application failures requiring vendor analysis.","platforms":["unknown"],"vendors":["Windows Printing"],"technologies":["WIN-PRINT-SYMPTOM","Plain-text Error Message / Symptom","Print Spooler / Driver / Queue","Needs Review"],"aliases":["Windows replaces an approved vendor driver"]},{"id":365001,"title":"Microsoft 365 User Restore and SMTP Address Conflict Troubleshooting","category":"Microsoft 365","product":"Microsoft 365 / Exchange Online / Microsoft Entra ID / Microsoft Graph","platforms":["windows","macos","linux"],"vendors":["microsoft"],"products":["Microsoft 365","Exchange Online","Microsoft Entra ID","Microsoft Graph"],"technologies":["PowerShell","Exchange Online PowerShell","Microsoft Graph PowerShell","Deleted Users","Proxy Addresses","User Principal Names"],"articleCategories":["Microsoft 365","Troubleshooting"],"aliases":["restore deleted user","SMTP address conflict","proxyAddresses conflict","Conflicts occurred trying to restore user"],"tags":["PowerShell","Exchange Online PowerShell","Microsoft Graph PowerShell","Deleted Users","Proxy Addresses","User Principal Names"],"keywords":["microsoft 365 user restore and smtp address conflict troubleshooting","restore deleted user","smtp address conflict","proxyaddresses conflict","conflicts occurred trying to restore user","powershell","exchange online powershell","microsoft graph powershell","deleted users","proxy addresses","user principal names","microsoft 365","exchange online","microsoft entra id","microsoft graph"],"errorCode":"","errorMessage":"SMTP address conflict","eventId":"","severity":"High","summary":"End-to-end workflow for restoring a deleted Microsoft 365 user when an active directory or Exchange recipient owns the required UPN or SMTP proxy address.","rootCause":"Microsoft Entra ID and Exchange Online enforce uniqueness for sign-in names and mail proxy addresses. A deleted object cannot be restored unchanged while another object owns one of those values.","resolution":"1. Verify Exchange Online and Microsoft Graph modules and connections.\n2. Record the conflicting SMTP address and the active recipient's complete configuration.\n3. Record the deleted user's object ID, UPN, mail address, and deletion date.\n4. Determine whether the conflict is a UPN, primary SMTP, proxy address, mail nickname, group, contact, public-folder, or synchronized-object conflict.\n5. Identify the authoritative source and confirm which object should own each value.\n6. Change the incorrect object only after documenting mail-flow, sign-in, delegation, OneDrive, SharePoint, and synchronization impact.\n7. Wait for provisioning, then repeat the exact Exchange and Entra searches.\n8. Restore the deleted object by its recorded object ID.\n9. Verify authentication, MFA, licensing, mailbox provisioning, inbound and outbound mail, aliases, and delegated access.\n10. Document the previous value, new value, restore result, provisioning result, and remaining follow-up.","emailScript":"Hello,\n\nWe reviewed the Microsoft 365 issue related to Microsoft 365 User Restore and SMTP Address Conflict Troubleshooting. We are validating the affected directory or service configuration and applying the appropriate corrective action.\n\nWe will confirm the result after authentication, provisioning, and mail flow have been verified.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the affected account signed out while IT reviews the issue.\n2. Do not rename accounts or mailboxes unless IT requests it.\n3. Wait for confirmation that Microsoft 365 provisioning has completed.\n4. Test sign-in and email only after IT confirms the correction.","notes":"Replace every placeholder. Use least-privileged Graph permissions. Do not delete a shared mailbox or permanently delete a user merely to release an address. Exchange recipient searches do not prove that a non-mail-enabled Entra object has no conflict.","commands":[{"shell":"PowerShell","command":"Connect-ExchangeOnline -UserPrincipalName admin@domain.com","risk":"Standard"},{"shell":"PowerShell","command":"Get-ConnectionInformation","risk":"Standard"},{"shell":"PowerShell","command":"Connect-MgGraph -Scopes \"User.Read.All\",\"User.DeleteRestore.All\"","risk":"Standard"},{"shell":"PowerShell","command":"Get-MgContext","risk":"Standard"},{"shell":"PowerShell","command":"$Address = \"user@domain.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Get-EXORecipient -ResultSize Unlimited | Where-Object { $_.EmailAddresses -contains \"smtp:$Address\" } | Format-List Name,RecipientType,RecipientTypeDetails,PrimarySmtpAddress,EmailAddresses,ExternalDirectoryObjectId","risk":"Standard"},{"shell":"PowerShell","command":"Get-MgDirectoryDeletedItemAsUser -All | Select-Object Id,DisplayName,UserPrincipalName,Mail,DeletedDateTime","risk":"Standard"},{"shell":"PowerShell","command":"Restore-MgDirectoryDeletedItem -DirectoryObjectId \"DELETED-OBJECT-ID\"","risk":"Standard"}],"verification":"Confirm the restored user is active, the intended address appears on only one object, authentication and MFA work, the license and mailbox are healthy, and inbound/outbound mail and delegation succeed.","sourceDocument":"COPYCAT MICROSOFT 365 USER RESTORE AND ADDRESS CONFLICT ADD-IN LIST","lastVerified":""},{"id":365002,"title":"ExecutionPolicyOverride","category":"Microsoft 365","product":"Windows PowerShell / Active Directory / Group Policy","platforms":["windows"],"vendors":["microsoft"],"products":["Windows PowerShell","Active Directory","Group Policy"],"technologies":["PowerShell Execution Policy","Group Policy"],"articleCategories":["Microsoft 365","Troubleshooting"],"aliases":["ExecutionPolicyOverride","setting is overridden by a policy defined at a more specific scope"],"tags":["PowerShell Execution Policy","Group Policy"],"keywords":["executionpolicyoverride","setting is overridden by a policy defined at a more specific scope","powershell execution policy","group policy","windows powershell","active directory"],"errorCode":"ExecutionPolicyOverride","errorMessage":"setting is overridden by a policy defined at a more specific scope","eventId":"","severity":"Medium","summary":"A local Set-ExecutionPolicy change succeeds but a more specific scope continues to control the effective Windows PowerShell policy.","rootCause":"MachinePolicy or UserPolicy, commonly delivered through Group Policy, takes precedence over local scopes.","resolution":"Run Get-ExecutionPolicy -List, identify the controlling scope, change only the authorized Group Policy, run gpupdate /force, reopen PowerShell, and verify the effective policy.","emailScript":"Hello,\n\nWe reviewed the Microsoft 365 issue related to ExecutionPolicyOverride. We are validating the affected directory or service configuration and applying the appropriate corrective action.\n\nWe will confirm the result after authentication, provisioning, and mail flow have been verified.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the affected account signed out while IT reviews the issue.\n2. Do not rename accounts or mailboxes unless IT requests it.\n3. Wait for confirmation that Microsoft 365 provisioning has completed.\n4. Test sign-in and email only after IT confirms the correction.","notes":"Do not repeatedly use Set-ExecutionPolicy or Bypass when organizational policy controls the setting.","commands":[{"shell":"PowerShell","command":"Get-ExecutionPolicy -List","risk":"Standard"},{"shell":"PowerShell","command":"gpupdate /force","risk":"Standard"}],"verification":"Get-ExecutionPolicy -List must show the expected value at the controlling scope.","sourceDocument":"COPYCAT MICROSOFT 365 USER RESTORE AND ADDRESS CONFLICT ADD-IN LIST","lastVerified":""},{"id":365003,"title":"PackageManagement Module In Use","category":"Microsoft 365","product":"Microsoft 365","platforms":["windows","macos","linux"],"vendors":["microsoft"],"technologies":["PackageManagement","PowerShellGet","ExchangeOnlineManagement"],"articleCategories":["Microsoft 365","Troubleshooting"],"aliases":["PackageManagement Module In Use","module is currently in use"],"tags":["PackageManagement","PowerShellGet","ExchangeOnlineManagement"],"keywords":["packagemanagement module in use","module is currently in use","packagemanagement","powershellget","exchangeonlinemanagement","microsoft 365"],"errorCode":"","errorMessage":"module is currently in use","eventId":"","severity":"Low","summary":"PowerShell cannot replace or update PackageManagement because a running process has loaded the module.","rootCause":"Another PowerShell, Windows Terminal, ISE, VS Code, or automation session holds the module files open.","resolution":"Close all PowerShell hosts, reopen the required administrative context, retry the module installation, and restart the workstation if the lock remains.","emailScript":"Hello,\n\nWe reviewed the Microsoft 365 issue related to PackageManagement Module In Use. We are validating the affected directory or service configuration and applying the appropriate corrective action.\n\nWe will confirm the result after authentication, provisioning, and mail flow have been verified.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the affected account signed out while IT reviews the issue.\n2. Do not rename accounts or mailboxes unless IT requests it.\n3. Wait for confirmation that Microsoft 365 provisioning has completed.\n4. Test sign-in and email only after IT confirms the correction.","notes":"Do not manually delete a loaded module directory.","commands":[{"shell":"PowerShell","command":"Get-Module PackageManagement","risk":"Standard"},{"shell":"PowerShell","command":"Get-Module -ListAvailable PackageManagement","risk":"Standard"},{"shell":"PowerShell","command":"Get-InstalledModule PackageManagement -ErrorAction SilentlyContinue","risk":"Standard"},{"shell":"PowerShell","command":"Install-Module -Name ExchangeOnlineManagement -Force","risk":"Standard"}],"verification":"List available ExchangeOnlineManagement versions and confirm the expected version and path.","sourceDocument":"COPYCAT MICROSOFT 365 USER RESTORE AND ADDRESS CONFLICT ADD-IN LIST","lastVerified":""},{"id":365004,"title":"MsalClientException - User Canceled Authentication","category":"Microsoft 365","product":"Microsoft 365","platforms":["windows","macos","linux"],"vendors":["microsoft"],"technologies":["MSAL","Modern Authentication","MFA","OAuth"],"articleCategories":["Microsoft 365","Troubleshooting"],"aliases":["MsalClientException","User canceled authentication"],"tags":["MSAL","Modern Authentication","MFA","OAuth"],"keywords":["msalclientexception - user canceled authentication","msalclientexception","user canceled authentication","msal","modern authentication","mfa","oauth","microsoft 365"],"errorCode":"MsalClientException","errorMessage":"User canceled authentication","eventId":"","severity":"Medium","summary":"The Microsoft authentication flow ended before Exchange Online or Graph sign-in completed.","rootCause":"The browser, authentication window, MFA request, or account-selection flow was canceled, dismissed, expired, or timed out.","resolution":"Close the incomplete flow, retry with the intended administrator, complete MFA, sign out of unrelated browser accounts if needed, and review Entra sign-in logs if failure continues.","emailScript":"Hello,\n\nWe reviewed the Microsoft 365 issue related to MsalClientException - User Canceled Authentication. We are validating the affected directory or service configuration and applying the appropriate corrective action.\n\nWe will confirm the result after authentication, provisioning, and mail flow have been verified.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the affected account signed out while IT reviews the issue.\n2. Do not rename accounts or mailboxes unless IT requests it.\n3. Wait for confirmation that Microsoft 365 provisioning has completed.\n4. Test sign-in and email only after IT confirms the correction.","notes":"","commands":[{"shell":"PowerShell","command":"Connect-ExchangeOnline -UserPrincipalName admin@domain.com","risk":"Standard"},{"shell":"PowerShell","command":"Connect-MgGraph -Scopes \"User.Read.All\",\"User.DeleteRestore.All\"","risk":"Standard"},{"shell":"PowerShell","command":"Get-ConnectionInformation","risk":"Standard"},{"shell":"PowerShell","command":"Get-MgContext","risk":"Standard"}],"verification":"Confirm the expected account, tenant, authentication type, and least-required permissions.","sourceDocument":"COPYCAT MICROSOFT 365 USER RESTORE AND ADDRESS CONFLICT ADD-IN LIST","lastVerified":""},{"id":365005,"title":"Exchange Online Connection Banner","category":"Microsoft 365","product":"Microsoft 365","platforms":["windows","macos","linux"],"vendors":["microsoft"],"technologies":["ExchangeOnlineManagement","REST API"],"articleCategories":["Microsoft 365","Informational Message"],"aliases":["Exchange Online Connection Banner","This V3 EXO PowerShell module contains new REST API backed"],"tags":["ExchangeOnlineManagement","REST API"],"keywords":["exchange online connection banner","this v3 exo powershell module contains new rest api backed","exchangeonlinemanagement","rest api","microsoft 365"],"errorCode":"","errorMessage":"This V3 EXO PowerShell module contains new REST API backed","eventId":"","severity":"Low","summary":"The Exchange Online V3 module displays REST-backed cmdlet and connection information after connection.","rootCause":"This is an informational module banner, not a failure.","resolution":"No corrective action is required. Verify the active connection before continuing.","emailScript":"Hello,\n\nWe reviewed the Microsoft 365 issue related to Exchange Online Connection Banner. We are validating the affected directory or service configuration and applying the appropriate corrective action.\n\nWe will confirm the result after authentication, provisioning, and mail flow have been verified.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the affected account signed out while IT reviews the issue.\n2. Do not rename accounts or mailboxes unless IT requests it.\n3. Wait for confirmation that Microsoft 365 provisioning has completed.\n4. Test sign-in and email only after IT confirms the correction.","notes":"Informational entry; do not count this banner as an error.","commands":[{"shell":"PowerShell","command":"Get-ConnectionInformation","risk":"Standard"}],"verification":"Get-ConnectionInformation shows the intended active session.","sourceDocument":"COPYCAT MICROSOFT 365 USER RESTORE AND ADDRESS CONFLICT ADD-IN LIST","lastVerified":""},{"id":365006,"title":"User Restore Conflict","category":"Microsoft 365","product":"Microsoft Entra ID / Microsoft Graph / Exchange Online","platforms":["windows","macos","linux"],"vendors":["microsoft"],"products":["Microsoft Entra ID","Microsoft Graph","Exchange Online"],"technologies":["Deleted Users","Directory Objects","UPN","Proxy Addresses"],"articleCategories":["Microsoft 365","Troubleshooting"],"aliases":["User Restore Conflict","Conflicts occurred trying to restore user","Please resolve conflicts"],"tags":["Deleted Users","Directory Objects","UPN","Proxy Addresses"],"keywords":["user restore conflict","conflicts occurred trying to restore user","please resolve conflicts","deleted users","directory objects","upn","proxy addresses","microsoft entra id","microsoft graph","exchange online"],"errorCode":"","errorMessage":"Conflicts occurred trying to restore user","eventId":"","severity":"High","summary":"Microsoft Entra cannot restore a deleted user because an active object owns a required unique UPN, SMTP address, mail nickname, or directory value.","rootCause":"An active user, mailbox, group, contact, mail user, public folder, or synchronized object holds the value required by the deleted object.","resolution":"Record both objects, search Exchange recipients and deleted Graph users, confirm final ownership and authoritative source, change the incorrect object, wait for provisioning, repeat exact searches, and restore by the recorded deleted-object ID.","emailScript":"Hello,\n\nWe reviewed the Microsoft 365 issue related to User Restore Conflict. We are validating the affected directory or service configuration and applying the appropriate corrective action.\n\nWe will confirm the result after authentication, provisioning, and mail flow have been verified.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the affected account signed out while IT reviews the issue.\n2. Do not rename accounts or mailboxes unless IT requests it.\n3. Wait for confirmation that Microsoft 365 provisioning has completed.\n4. Test sign-in and email only after IT confirms the correction.","notes":"","commands":[{"shell":"PowerShell","command":"$Address = \"user@domain.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Get-EXORecipient -ResultSize Unlimited | Where-Object { $_.EmailAddresses -contains \"smtp:$Address\" } | Format-List Name,RecipientType,RecipientTypeDetails,PrimarySmtpAddress,EmailAddresses,ExternalDirectoryObjectId","risk":"Standard"},{"shell":"PowerShell","command":"Get-MgDirectoryDeletedItemAsUser -All | Select-Object Id,DisplayName,UserPrincipalName,Mail,DeletedDateTime","risk":"Standard"},{"shell":"PowerShell","command":"Restore-MgDirectoryDeletedItem -DirectoryObjectId \"DELETED-OBJECT-ID\"","risk":"Standard"}],"verification":"Confirm the user is restored, the UPN and SMTP values are unique, sign-in works, and mailbox and mail flow are healthy.","sourceDocument":"COPYCAT MICROSOFT 365 USER RESTORE AND ADDRESS CONFLICT ADD-IN LIST","lastVerified":""},{"id":365007,"title":"UPN Conflict","category":"Microsoft 365","product":"Microsoft Entra ID / Microsoft Graph","platforms":["windows","macos","linux"],"vendors":["microsoft"],"products":["Microsoft Entra ID","Microsoft Graph"],"technologies":["User Principal Name","Directory Objects"],"articleCategories":["Microsoft 365","Troubleshooting"],"aliases":["UPN Conflict","UPN already exists"],"tags":["User Principal Name","Directory Objects"],"keywords":["upn conflict","upn already exists","user principal name","directory objects","microsoft entra id","microsoft graph"],"errorCode":"","errorMessage":"UPN already exists","eventId":"","severity":"High","summary":"Another active directory object owns the User Principal Name required by a deleted user.","rootCause":"User Principal Names must be unique in the applicable directory context.","resolution":"Locate the active owner, confirm intended ownership, assign an approved temporary UPN to the incorrect object at its authoritative source, wait for provisioning, and retry restoration.","emailScript":"Hello,\n\nWe reviewed the Microsoft 365 issue related to UPN Conflict. We are validating the affected directory or service configuration and applying the appropriate corrective action.\n\nWe will confirm the result after authentication, provisioning, and mail flow have been verified.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the affected account signed out while IT reviews the issue.\n2. Do not rename accounts or mailboxes unless IT requests it.\n3. Wait for confirmation that Microsoft 365 provisioning has completed.\n4. Test sign-in and email only after IT confirms the correction.","notes":"Assess application, OneDrive, SharePoint, licensing, sign-in, and synchronization impact before changing a UPN.","commands":[{"shell":"PowerShell","command":"$UPN = \"deleteduser@domain.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Get-MgUser -Filter \"userPrincipalName eq '$UPN'\" | Select-Object Id,DisplayName,UserPrincipalName,Mail,AccountEnabled","risk":"Standard"}],"verification":"The UPN search returns only the intended object.","sourceDocument":"COPYCAT MICROSOFT 365 USER RESTORE AND ADDRESS CONFLICT ADD-IN LIST","lastVerified":""},{"id":365008,"title":"Proxy Address Conflict","category":"Microsoft 365","product":"Exchange Online / Microsoft Entra ID","platforms":["windows","macos","linux"],"vendors":["microsoft"],"products":["Exchange Online","Microsoft Entra ID"],"technologies":["proxyAddresses","SMTP","Exchange Recipients"],"articleCategories":["Microsoft 365","Troubleshooting"],"aliases":["Proxy Address Conflict","Another object with the same value for property proxyAddresses already exists","SMTP address already exists"],"tags":["proxyAddresses","SMTP","Exchange Recipients"],"keywords":["proxy address conflict","another object with the same value for property proxyaddresses already exists","smtp address already exists","proxyaddresses","smtp","exchange recipients","exchange online","microsoft entra id"],"errorCode":"","errorMessage":"Another object with the same value for property proxyAddresses already exists","eventId":"","severity":"High","summary":"An SMTP proxy address being assigned or restored already exists on another Exchange or Entra object.","rootCause":"A proxy address can be assigned to only one object at a time.","resolution":"Run the exact address search, record the complete recipient configuration, confirm ownership, remove or change the address on the incorrect authoritative object, wait for provisioning, repeat the search, and retry assignment or restoration.","emailScript":"Hello,\n\nWe reviewed the Microsoft 365 issue related to Proxy Address Conflict. We are validating the affected directory or service configuration and applying the appropriate corrective action.\n\nWe will confirm the result after authentication, provisioning, and mail flow have been verified.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the affected account signed out while IT reviews the issue.\n2. Do not rename accounts or mailboxes unless IT requests it.\n3. Wait for confirmation that Microsoft 365 provisioning has completed.\n4. Test sign-in and email only after IT confirms the correction.","notes":"Use -contains for an exact proxy-address match. A blank Exchange result does not exclude a non-mail-enabled Entra or synchronized-source conflict.","commands":[{"shell":"PowerShell","command":"$Address = \"user@domain.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Get-EXORecipient -ResultSize Unlimited | Where-Object { $_.EmailAddresses -contains \"smtp:$Address\" } | Format-List Name,RecipientType,RecipientTypeDetails,PrimarySmtpAddress,EmailAddresses,ExternalDirectoryObjectId","risk":"Standard"}],"verification":"The exact SMTP address appears on only the intended recipient.","sourceDocument":"COPYCAT MICROSOFT 365 USER RESTORE AND ADDRESS CONFLICT ADD-IN LIST","lastVerified":""},{"id":365009,"title":"Get-MsolUser Not Recognized","category":"Microsoft 365","product":"MSOnline / Microsoft Graph / Microsoft Entra ID","platforms":["windows"],"vendors":["microsoft"],"products":["MSOnline","Microsoft Graph","Microsoft Entra ID"],"technologies":["PowerShell","MSOnline","Microsoft Graph PowerShell"],"articleCategories":["Microsoft 365","Troubleshooting"],"aliases":["Get-MsolUser Not Recognized","Get-MsolUser is not recognized","MSOnline deprecated"],"tags":["PowerShell","MSOnline","Microsoft Graph PowerShell"],"keywords":["get-msoluser not recognized","get-msoluser is not recognized","msonline deprecated","powershell","msonline","microsoft graph powershell","microsoft graph","microsoft entra id"],"errorCode":"","errorMessage":"Get-MsolUser is not recognized","eventId":"","severity":"Medium","summary":"The legacy MSOnline Get-MsolUser cmdlet is unavailable in the current PowerShell session.","rootCause":"MSOnline is absent, not imported, unsupported in the current host, or intentionally replaced by Microsoft Graph PowerShell.","resolution":"Migrate the task deliberately to Microsoft Graph: install the Graph module if required, connect with appropriate scopes, and use Get-MgUser with explicitly selected properties.","emailScript":"Hello,\n\nWe reviewed the Microsoft 365 issue related to Get-MsolUser Not Recognized. We are validating the affected directory or service configuration and applying the appropriate corrective action.\n\nWe will confirm the result after authentication, provisioning, and mail flow have been verified.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the affected account signed out while IT reviews the issue.\n2. Do not rename accounts or mailboxes unless IT requests it.\n3. Wait for confirmation that Microsoft 365 provisioning has completed.\n4. Test sign-in and email only after IT confirms the correction.","notes":"Graph cmdlets do not necessarily use the same parameters or output properties as MSOnline.","commands":[{"shell":"PowerShell","command":"Install-Module Microsoft.Graph -Scope CurrentUser","risk":"Standard"},{"shell":"PowerShell","command":"Connect-MgGraph","risk":"Standard"},{"shell":"PowerShell","command":"Get-MgUser -All","risk":"Standard"},{"shell":"PowerShell","command":"Get-MgUser -UserId \"user@domain.com\"","risk":"Standard"}],"verification":"Get-Command Get-MgUser and Get-MgContext return the expected command and tenant context.","sourceDocument":"COPYCAT MICROSOFT 365 USER RESTORE AND ADDRESS CONFLICT ADD-IN LIST","lastVerified":""},{"id":365010,"title":"ExpressionsMustBeFirstInPipeline","category":"Microsoft 365","product":"PowerShell","platforms":["windows","macos","linux"],"vendors":["microsoft"],"technologies":["PowerShell Pipeline"],"articleCategories":["Microsoft 365","Troubleshooting"],"aliases":["ExpressionsMustBeFirstInPipeline","Expressions are only allowed as the first element of a pipeline"],"tags":["PowerShell Pipeline"],"keywords":["expressionsmustbefirstinpipeline","expressions are only allowed as the first element of a pipeline","powershell pipeline","powershell"],"errorCode":"","errorMessage":"Expressions are only allowed as the first element of a pipeline","eventId":"","severity":"Low","summary":"PowerShell reports that expressions are allowed only as the first pipeline element.","rootCause":"Accidental text, a copied line number, or an invalid expression follows a pipeline operator.","resolution":"Remove the accidental content and place a valid command such as Select-Object or Format-Table after the pipeline operator.","emailScript":"Hello,\n\nWe reviewed the Microsoft 365 issue related to ExpressionsMustBeFirstInPipeline. We are validating the affected directory or service configuration and applying the appropriate corrective action.\n\nWe will confirm the result after authentication, provisioning, and mail flow have been verified.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the affected account signed out while IT reviews the issue.\n2. Do not rename accounts or mailboxes unless IT requests it.\n3. Wait for confirmation that Microsoft 365 provisioning has completed.\n4. Test sign-in and email only after IT confirms the correction.","notes":"","commands":[{"shell":"PowerShell","command":"Get-MgDirectoryDeletedItemAsUser -All | Select-Object Id,DisplayName,UserPrincipalName,Mail,DeletedDateTime","risk":"Standard"}],"verification":"The corrected pipeline produces output without a parser error.","sourceDocument":"COPYCAT MICROSOFT 365 USER RESTORE AND ADDRESS CONFLICT ADD-IN LIST","lastVerified":""},{"id":365011,"title":"CouldNotAutoloadMatchingModule","category":"Microsoft 365","product":"Microsoft Graph PowerShell","platforms":["windows","macos","linux"],"vendors":["microsoft"],"technologies":["Microsoft.Graph.Authentication","Microsoft.Graph.Identity.DirectoryManagement","Module Autoloading"],"articleCategories":["Microsoft 365","Troubleshooting"],"aliases":["CouldNotAutoloadMatchingModule","command was found in the module but the module could not be loaded"],"tags":["Microsoft.Graph.Authentication","Microsoft.Graph.Identity.DirectoryManagement","Module Autoloading"],"keywords":["couldnotautoloadmatchingmodule","command was found in the module but the module could not be loaded","microsoft.graph.authentication","microsoft.graph.identity.directorymanagement","module autoloading","microsoft graph powershell"],"errorCode":"","errorMessage":"command was found in the module but the module could not be loaded","eventId":"","severity":"Medium","summary":"PowerShell found a Microsoft Graph command but could not load its owning module.","rootCause":"The Graph installation or dependency is missing, corrupt, inconsistent, blocked, installed in another scope, or stale in the current session.","resolution":"Close other sessions, inspect available modules and command sources, import Authentication and Identity.DirectoryManagement explicitly, record verbose errors, and repair or update only the inconsistent installation.","emailScript":"Hello,\n\nWe reviewed the Microsoft 365 issue related to CouldNotAutoloadMatchingModule. We are validating the affected directory or service configuration and applying the appropriate corrective action.\n\nWe will confirm the result after authentication, provisioning, and mail flow have been verified.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the affected account signed out while IT reviews the issue.\n2. Do not rename accounts or mailboxes unless IT requests it.\n3. Wait for confirmation that Microsoft 365 provisioning has completed.\n4. Test sign-in and email only after IT confirms the correction.","notes":"Do not use AllowClobber or delete all modules before identifying the failed component.","commands":[{"shell":"PowerShell","command":"Get-Module -ListAvailable Microsoft.Graph* | Sort-Object Name,Version | Format-Table Name,Version,Path","risk":"Standard"},{"shell":"PowerShell","command":"Get-Command Connect-MgGraph -All","risk":"Standard"},{"shell":"PowerShell","command":"Import-Module Microsoft.Graph.Authentication -Verbose","risk":"Standard"},{"shell":"PowerShell","command":"Import-Module Microsoft.Graph.Identity.DirectoryManagement -Verbose","risk":"Standard"}],"verification":"Required Graph commands resolve and Get-MgContext displays the intended connection.","sourceDocument":"COPYCAT MICROSOFT 365 USER RESTORE AND ADDRESS CONFLICT ADD-IN LIST","lastVerified":""},{"id":365012,"title":"Microsoft Graph Already Installed","category":"Microsoft 365","product":"Microsoft Graph PowerShell","platforms":["windows","macos","linux"],"vendors":["microsoft"],"technologies":["PowerShell Modules","Module Versions"],"articleCategories":["Microsoft 365","Troubleshooting"],"aliases":["Microsoft Graph Already Installed","Version X is already installed"],"tags":["PowerShell Modules","Module Versions"],"keywords":["microsoft graph already installed","version x is already installed","powershell modules","module versions","microsoft graph powershell"],"errorCode":"","errorMessage":"Version X is already installed","eventId":"","severity":"Low","summary":"The requested Microsoft Graph module version is already installed or another installed version affects the requested action.","rootCause":"The installation request duplicates or conflicts with an existing module version.","resolution":"Inspect installed and available versions. Update or force-reinstall only after testing compatibility with active automation.","emailScript":"Hello,\n\nWe reviewed the Microsoft 365 issue related to Microsoft Graph Already Installed. We are validating the affected directory or service configuration and applying the appropriate corrective action.\n\nWe will confirm the result after authentication, provisioning, and mail flow have been verified.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the affected account signed out while IT reviews the issue.\n2. Do not rename accounts or mailboxes unless IT requests it.\n3. Wait for confirmation that Microsoft 365 provisioning has completed.\n4. Test sign-in and email only after IT confirms the correction.","notes":"","commands":[{"shell":"PowerShell","command":"Get-InstalledModule Microsoft.Graph -ErrorAction SilentlyContinue","risk":"Standard"},{"shell":"PowerShell","command":"Get-Module -ListAvailable Microsoft.Graph* | Sort-Object Name,Version | Format-Table Name,Version,Path","risk":"Standard"},{"shell":"PowerShell","command":"Update-Module Microsoft.Graph","risk":"Standard"},{"shell":"PowerShell","command":"Install-Module Microsoft.Graph -Scope CurrentUser -Force","risk":"Standard"}],"verification":"The intended Microsoft.Graph version and module path are present.","sourceDocument":"COPYCAT MICROSOFT 365 USER RESTORE AND ADDRESS CONFLICT ADD-IN LIST","lastVerified":""},{"id":365013,"title":"CommandAlreadyAvailable","category":"Microsoft 365","product":"Microsoft 365","platforms":["windows","macos","linux"],"vendors":["microsoft"],"technologies":["PowerShell","Command Resolution","Module Conflict"],"articleCategories":["Microsoft 365","Troubleshooting"],"aliases":["CommandAlreadyAvailable","This module may override existing commands"],"tags":["PowerShell","Command Resolution","Module Conflict"],"keywords":["commandalreadyavailable","this module may override existing commands","powershell","command resolution","module conflict","microsoft 365"],"errorCode":"","errorMessage":"This module may override existing commands","eventId":"","severity":"Medium","summary":"A module installation may override a command name already supplied by another module.","rootCause":"Two installed or imported modules export the same command name.","resolution":"Identify every command source and version. Use AllowClobber only when replacement is understood, tested, and approved, then verify which command resolves.","emailScript":"Hello,\n\nWe reviewed the Microsoft 365 issue related to CommandAlreadyAvailable. We are validating the affected directory or service configuration and applying the appropriate corrective action.\n\nWe will confirm the result after authentication, provisioning, and mail flow have been verified.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the affected account signed out while IT reviews the issue.\n2. Do not rename accounts or mailboxes unless IT requests it.\n3. Wait for confirmation that Microsoft 365 provisioning has completed.\n4. Test sign-in and email only after IT confirms the correction.","notes":"AllowClobber permits replacement; it does not prove the resulting resolution is correct.","commands":[{"shell":"PowerShell","command":"Get-Command \"CommandName\" -All | Format-Table Name,CommandType,Source,Version","risk":"Standard"},{"shell":"PowerShell","command":"Install-Module Microsoft.Graph -AllowClobber -Force","risk":"Standard"}],"verification":"Get-Command shows that PowerShell resolves the intended source.","sourceDocument":"COPYCAT MICROSOFT 365 USER RESTORE AND ADDRESS CONFLICT ADD-IN LIST","lastVerified":""},{"id":365014,"title":"Connect-MgGraph Not Recognized","category":"Microsoft 365","product":"Microsoft Graph PowerShell","platforms":["windows","macos","linux"],"vendors":["microsoft"],"technologies":["Microsoft.Graph.Authentication"],"articleCategories":["Microsoft 365","Troubleshooting"],"aliases":["Connect-MgGraph Not Recognized","Connect-MgGraph was found but the module could not be loaded"],"tags":["Microsoft.Graph.Authentication"],"keywords":["connect-mggraph not recognized","connect-mggraph was found but the module could not be loaded","microsoft.graph.authentication","microsoft graph powershell"],"errorCode":"","errorMessage":"Connect-MgGraph was found but the module could not be loaded","eventId":"","severity":"Medium","summary":"Connect-MgGraph is unavailable or its authentication module cannot load.","rootCause":"Microsoft.Graph.Authentication is absent, corrupt, installed for another user or edition, blocked, or in conflict with another version.","resolution":"Inspect command and module paths, import Authentication explicitly, install Graph in the correct scope if missing, then connect with only the required scopes.","emailScript":"Hello,\n\nWe reviewed the Microsoft 365 issue related to Connect-MgGraph Not Recognized. We are validating the affected directory or service configuration and applying the appropriate corrective action.\n\nWe will confirm the result after authentication, provisioning, and mail flow have been verified.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the affected account signed out while IT reviews the issue.\n2. Do not rename accounts or mailboxes unless IT requests it.\n3. Wait for confirmation that Microsoft 365 provisioning has completed.\n4. Test sign-in and email only after IT confirms the correction.","notes":"","commands":[{"shell":"PowerShell","command":"Get-Command Connect-MgGraph -All","risk":"Standard"},{"shell":"PowerShell","command":"Get-Module -ListAvailable Microsoft.Graph.Authentication","risk":"Standard"},{"shell":"PowerShell","command":"$env:PSModulePath -split [IO.Path]::PathSeparator","risk":"Standard"},{"shell":"PowerShell","command":"Import-Module Microsoft.Graph.Authentication","risk":"Standard"},{"shell":"PowerShell","command":"Install-Module Microsoft.Graph -Scope CurrentUser","risk":"Standard"},{"shell":"PowerShell","command":"Connect-MgGraph -Scopes \"User.Read.All\",\"User.DeleteRestore.All\"","risk":"Standard"}],"verification":"Get-MgContext shows the correct account, tenant, authentication type, and required scopes.","sourceDocument":"COPYCAT MICROSOFT 365 USER RESTORE AND ADDRESS CONFLICT ADD-IN LIST","lastVerified":""},{"id":365015,"title":"NamedParameterNotFound - PrimarySmtpAddress","category":"Microsoft 365","product":"Exchange Online PowerShell / PowerShell","platforms":["windows","macos","linux"],"vendors":["microsoft"],"products":["Exchange Online PowerShell","PowerShell"],"technologies":["Set-Mailbox","PrimarySmtpAddress","Command Resolution"],"articleCategories":["Microsoft 365","Troubleshooting"],"aliases":["NamedParameterNotFound","A parameter cannot be found that matches parameter name PrimarySmtpAddress"],"tags":["Set-Mailbox","PrimarySmtpAddress","Command Resolution"],"keywords":["namedparameternotfound - primarysmtpaddress","namedparameternotfound","a parameter cannot be found that matches parameter name primarysmtpaddress","set-mailbox","primarysmtpaddress","command resolution","exchange online powershell","powershell"],"errorCode":"","errorMessage":"A parameter cannot be found that matches parameter name PrimarySmtpAddress","eventId":"","severity":"Medium","summary":"The resolved Set-Mailbox command does not expose the requested PrimarySmtpAddress parameter.","rootCause":"PowerShell may resolve an unexpected command, lack an Exchange Online session, load an incomplete module, use the wrong parameter set, or target an object managed at another authoritative source.","resolution":"Inspect every Set-Mailbox command source, confirm the Exchange connection, review help and parameters, and modify synchronized objects at the authoritative on-premises source.","emailScript":"Hello,\n\nWe reviewed the Microsoft 365 issue related to NamedParameterNotFound - PrimarySmtpAddress. We are validating the affected directory or service configuration and applying the appropriate corrective action.\n\nWe will confirm the result after authentication, provisioning, and mail flow have been verified.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the affected account signed out while IT reviews the issue.\n2. Do not rename accounts or mailboxes unless IT requests it.\n3. Wait for confirmation that Microsoft 365 provisioning has completed.\n4. Test sign-in and email only after IT confirms the correction.","notes":"","commands":[{"shell":"PowerShell","command":"Get-Command Set-Mailbox -All | Format-List Name,CommandType,Source,Version,Definition","risk":"Standard"},{"shell":"PowerShell","command":"Get-Help Set-Mailbox -Full","risk":"Standard"},{"shell":"PowerShell","command":"Get-Command Set-Mailbox | Select-Object -ExpandProperty Parameters","risk":"Standard"},{"shell":"PowerShell","command":"Get-ConnectionInformation","risk":"Standard"},{"shell":"PowerShell","command":"Connect-ExchangeOnline -UserPrincipalName admin@domain.com","risk":"Standard"}],"verification":"The expected Exchange Online command resolves and its help lists the supported parameter.","sourceDocument":"COPYCAT MICROSOFT 365 USER RESTORE AND ADDRESS CONFLICT ADD-IN LIST","lastVerified":""},{"id":365016,"title":"Shared Mailbox and Deleted User Address Conflict","category":"Microsoft 365","product":"Exchange Online / Microsoft Entra ID / Microsoft Graph","platforms":["windows","macos","linux"],"vendors":["microsoft"],"products":["Exchange Online","Microsoft Entra ID","Microsoft Graph"],"technologies":["Shared Mailbox","Deleted User","SMTP","Proxy Addresses"],"articleCategories":["Microsoft 365","Troubleshooting"],"aliases":["Shared Mailbox and Deleted User Address Conflict","shared mailbox using deleted user address"],"tags":["Shared Mailbox","Deleted User","SMTP","Proxy Addresses"],"keywords":["shared mailbox and deleted user address conflict","shared mailbox using deleted user address","shared mailbox","deleted user","smtp","proxy addresses","exchange online","microsoft entra id","microsoft graph"],"errorCode":"","errorMessage":"shared mailbox using deleted user address","eventId":"","severity":"High","summary":"A shared or user mailbox owns the SMTP address required to restore a deleted user.","rootCause":"The active Exchange recipient and deleted Entra object cannot simultaneously own the same proxy address.","resolution":"Sanitize identifiers, record both objects and delegation, confirm intended ownership, change the incorrect authoritative object, wait for provisioning, repeat the exact recipient search, restore the user, and verify uniqueness and mail flow.","emailScript":"Hello,\n\nWe reviewed the Microsoft 365 issue related to Shared Mailbox and Deleted User Address Conflict. We are validating the affected directory or service configuration and applying the appropriate corrective action.\n\nWe will confirm the result after authentication, provisioning, and mail flow have been verified.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the affected account signed out while IT reviews the issue.\n2. Do not rename accounts or mailboxes unless IT requests it.\n3. Wait for confirmation that Microsoft 365 provisioning has completed.\n4. Test sign-in and email only after IT confirms the correction.","notes":"Public examples use SharedMailboxName, DeletedUserName, domain.com, DELETED-OBJECT-ID, and admin@domain.com only.","commands":[{"shell":"PowerShell","command":"$Address = \"sharedmailbox@example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Get-EXORecipient -ResultSize Unlimited | Where-Object { $_.EmailAddresses -contains \"smtp:$Address\" } | Format-List Name,RecipientType,RecipientTypeDetails,PrimarySmtpAddress,EmailAddresses,ExternalDirectoryObjectId","risk":"Standard"}],"verification":"The address exists only on the intended object and shared-mailbox access and mail flow remain correct.","sourceDocument":"COPYCAT MICROSOFT 365 USER RESTORE AND ADDRESS CONFLICT ADD-IN LIST","lastVerified":""},{"id":365017,"title":"Microsoft Graph Deleted User Search","category":"Microsoft 365","product":"Microsoft Graph / Microsoft Entra ID","platforms":["windows","macos","linux"],"vendors":["microsoft"],"products":["Microsoft Graph","Microsoft Entra ID"],"technologies":["Deleted Users","Directory Deleted Items"],"articleCategories":["Microsoft 365","Troubleshooting"],"aliases":["Microsoft Graph Deleted User Search","Get-MgDirectoryDeletedItemAsUser"],"tags":["Deleted Users","Directory Deleted Items"],"keywords":["microsoft graph deleted user search","get-mgdirectorydeleteditemasuser","deleted users","directory deleted items","microsoft graph","microsoft entra id"],"errorCode":"","errorMessage":"Get-MgDirectoryDeletedItemAsUser","eventId":"","severity":"Medium","summary":"Locate recently deleted Microsoft Entra users by user-specific Graph commands before restoration.","rootCause":"A restore workflow requires the exact deleted directory object ID and intended identity values.","resolution":"Connect with least-required permissions, list deleted users as users, match UPN or mail exactly, and record the object ID and deletion details before making changes.","emailScript":"Hello,\n\nWe reviewed the Microsoft 365 issue related to Microsoft Graph Deleted User Search. We are validating the affected directory or service configuration and applying the appropriate corrective action.\n\nWe will confirm the result after authentication, provisioning, and mail flow have been verified.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the affected account signed out while IT reviews the issue.\n2. Do not rename accounts or mailboxes unless IT requests it.\n3. Wait for confirmation that Microsoft 365 provisioning has completed.\n4. Test sign-in and email only after IT confirms the correction.","notes":"","commands":[{"shell":"PowerShell","command":"Connect-MgGraph -Scopes \"User.Read.All\",\"User.DeleteRestore.All\"","risk":"Standard"},{"shell":"PowerShell","command":"Get-MgDirectoryDeletedItemAsUser -All | Select-Object Id,DisplayName,UserPrincipalName,Mail,DeletedDateTime","risk":"Standard"},{"shell":"PowerShell","command":"$Address = \"user@domain.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Get-MgDirectoryDeletedItemAsUser -All | Where-Object { $_.UserPrincipalName -eq $Address -or $_.Mail -eq $Address } | Format-List Id,DisplayName,UserPrincipalName,Mail,DeletedDateTime","risk":"Standard"}],"verification":"The intended deleted user is identified and its object ID is recorded.","sourceDocument":"COPYCAT MICROSOFT 365 USER RESTORE AND ADDRESS CONFLICT ADD-IN LIST","lastVerified":""},{"id":365018,"title":"Microsoft Graph Deleted User Restore","category":"Microsoft 365","product":"Microsoft Graph / Microsoft Entra ID","platforms":["windows","macos","linux"],"vendors":["microsoft"],"products":["Microsoft Graph","Microsoft Entra ID"],"technologies":["User Restoration","Directory Deleted Items"],"articleCategories":["Microsoft 365","Troubleshooting"],"aliases":["Microsoft Graph Deleted User Restore","Restore-MgDirectoryDeletedItem"],"tags":["User Restoration","Directory Deleted Items"],"keywords":["microsoft graph deleted user restore","restore-mgdirectorydeleteditem","user restoration","directory deleted items","microsoft graph","microsoft entra id"],"errorCode":"","errorMessage":"Restore-MgDirectoryDeletedItem","eventId":"","severity":"High","summary":"Restore a verified deleted Microsoft Entra directory object by its recorded object ID.","rootCause":"The user remains in deleted items and any conflicting unique values have been cleared from incorrect objects.","resolution":"Confirm ownership and conflict clearance, restore using the recorded object ID, then query the active user and validate identity, licensing, authentication, and mailbox provisioning.","emailScript":"Hello,\n\nWe reviewed the Microsoft 365 issue related to Microsoft Graph Deleted User Restore. We are validating the affected directory or service configuration and applying the appropriate corrective action.\n\nWe will confirm the result after authentication, provisioning, and mail flow have been verified.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the affected account signed out while IT reviews the issue.\n2. Do not rename accounts or mailboxes unless IT requests it.\n3. Wait for confirmation that Microsoft 365 provisioning has completed.\n4. Test sign-in and email only after IT confirms the correction.","notes":"Do not restore repeatedly before correcting conflicts. Record the object ID before restoration.","commands":[{"shell":"PowerShell","command":"Restore-MgDirectoryDeletedItem -DirectoryObjectId \"DELETED-OBJECT-ID\"","risk":"Standard"},{"shell":"PowerShell","command":"Get-MgUser -UserId \"restoreduser@domain.com\" -Property Id,DisplayName,UserPrincipalName,Mail,ProxyAddresses,AccountEnabled | Format-List Id,DisplayName,UserPrincipalName,Mail,ProxyAddresses,AccountEnabled","risk":"Standard"}],"verification":"The user is active with the intended UPN and proxy addresses, and sign-in and service provisioning succeed.","sourceDocument":"COPYCAT MICROSOFT 365 USER RESTORE AND ADDRESS CONFLICT ADD-IN LIST","lastVerified":""},{"id":365019,"title":"Exchange Online Recipient Address Search","category":"Microsoft 365","product":"Exchange Online","platforms":["windows","macos","linux"],"vendors":["microsoft"],"technologies":["Get-EXORecipient","EmailAddresses","SMTP"],"articleCategories":["Microsoft 365","Troubleshooting"],"aliases":["Exchange Online Recipient Address Search","Get-EXORecipient email address conflict"],"tags":["Get-EXORecipient","EmailAddresses","SMTP"],"keywords":["exchange online recipient address search","get-exorecipient email address conflict","get-exorecipient","emailaddresses","smtp","exchange online"],"errorCode":"","errorMessage":"Get-EXORecipient email address conflict","eventId":"","severity":"Medium","summary":"Search every Exchange Online mail-enabled recipient for an exact SMTP proxy address.","rootCause":"An address conflict may be held by a mailbox, group, contact, mail user, or mail-enabled public folder.","resolution":"Use an exact -contains search against EmailAddresses, record recipient type and external object ID, and use partial regex matching only when partial discovery is intentional.","emailScript":"Hello,\n\nWe reviewed the Microsoft 365 issue related to Exchange Online Recipient Address Search. We are validating the affected directory or service configuration and applying the appropriate corrective action.\n\nWe will confirm the result after authentication, provisioning, and mail flow have been verified.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the affected account signed out while IT reviews the issue.\n2. Do not rename accounts or mailboxes unless IT requests it.\n3. Wait for confirmation that Microsoft 365 provisioning has completed.\n4. Test sign-in and email only after IT confirms the correction.","notes":"Get-EXORecipient does not prove that no non-mail-enabled Entra or synchronized-source object holds a conflicting value.","commands":[{"shell":"PowerShell","command":"$Address = \"user@domain.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Get-EXORecipient -ResultSize Unlimited | Where-Object { $_.EmailAddresses -contains \"smtp:$Address\" } | Format-List Name,RecipientType,RecipientTypeDetails,PrimarySmtpAddress,EmailAddresses,ExternalDirectoryObjectId","risk":"Standard"}],"verification":"The exact address appears only on the intended mail-enabled recipient.","sourceDocument":"COPYCAT MICROSOFT 365 USER RESTORE AND ADDRESS CONFLICT ADD-IN LIST","lastVerified":""},{"id":365020,"title":"Exchange Online Address Propagation Delay","category":"Microsoft 365","product":"Exchange Online / Microsoft Entra ID","platforms":["windows","macos","linux"],"vendors":["microsoft"],"products":["Exchange Online","Microsoft Entra ID"],"technologies":["Provisioning","Directory Synchronization","Proxy Addresses"],"articleCategories":["Microsoft 365","Troubleshooting"],"aliases":["Exchange Online Address Propagation Delay","SMTP address propagation delay"],"tags":["Provisioning","Directory Synchronization","Proxy Addresses"],"keywords":["exchange online address propagation delay","smtp address propagation delay","provisioning","directory synchronization","proxy addresses","exchange online","microsoft entra id"],"errorCode":"","errorMessage":"SMTP address propagation delay","eventId":"","severity":"Medium","summary":"A recently changed or removed address remains visible while Exchange Online and Microsoft Entra provisioning completes.","rootCause":"Directory synchronization, recipient provisioning, or service replication has not completed the preceding change.","resolution":"Stop making repeated changes, record the timestamp and source of authority, wait for provisioning, and repeat exact Exchange and Entra queries until the old ownership is cleared.","emailScript":"Hello,\n\nWe reviewed the Microsoft 365 issue related to Exchange Online Address Propagation Delay. We are validating the affected directory or service configuration and applying the appropriate corrective action.\n\nWe will confirm the result after authentication, provisioning, and mail flow have been verified.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the affected account signed out while IT reviews the issue.\n2. Do not rename accounts or mailboxes unless IT requests it.\n3. Wait for confirmation that Microsoft 365 provisioning has completed.\n4. Test sign-in and email only after IT confirms the correction.","notes":"","commands":[{"shell":"PowerShell","command":"Get-ConnectionInformation","risk":"Standard"},{"shell":"PowerShell","command":"$Address = \"user@domain.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Get-EXORecipient -ResultSize Unlimited | Where-Object { $_.EmailAddresses -contains \"smtp:$Address\" }","risk":"Standard"}],"verification":"Exchange and Entra queries show the intended final owner and no stale assignment.","sourceDocument":"COPYCAT MICROSOFT 365 USER RESTORE AND ADDRESS CONFLICT ADD-IN LIST","lastVerified":""},{"id":365021,"title":"Exchange Online and Entra Object Conflict","category":"Microsoft 365","product":"Exchange Online / Microsoft Entra ID / Microsoft Graph","platforms":["windows","macos","linux"],"vendors":["microsoft"],"products":["Exchange Online","Microsoft Entra ID","Microsoft Graph"],"technologies":["Directory Objects","Synchronization","Proxy Addresses"],"articleCategories":["Microsoft 365","Troubleshooting"],"aliases":["Exchange Online and Entra Object Conflict","blank Get-EXORecipient result duplicate proxyAddresses"],"tags":["Directory Objects","Synchronization","Proxy Addresses"],"keywords":["exchange online and entra object conflict","blank get-exorecipient result duplicate proxyaddresses","directory objects","synchronization","proxy addresses","exchange online","microsoft entra id","microsoft graph"],"errorCode":"","errorMessage":"blank Get-EXORecipient result duplicate proxyAddresses","eventId":"","severity":"High","summary":"Exchange Online returns no matching mail recipient, but Microsoft Entra still reports a duplicate unique value.","rootCause":"The conflict may belong to a non-mail-enabled Entra object, a deleted object, or an on-premises synchronized source not represented by the Exchange recipient search.","resolution":"Search active and deleted Entra users, inspect synchronization and authoritative source, correct the owning object there, wait for provisioning, and retry the original operation.","emailScript":"Hello,\n\nWe reviewed the Microsoft 365 issue related to Exchange Online and Entra Object Conflict. We are validating the affected directory or service configuration and applying the appropriate corrective action.\n\nWe will confirm the result after authentication, provisioning, and mail flow have been verified.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the affected account signed out while IT reviews the issue.\n2. Do not rename accounts or mailboxes unless IT requests it.\n3. Wait for confirmation that Microsoft 365 provisioning has completed.\n4. Test sign-in and email only after IT confirms the correction.","notes":"","commands":[{"shell":"PowerShell","command":"Get-MgUser -Filter \"userPrincipalName eq 'user@domain.com'\"","risk":"Standard"},{"shell":"PowerShell","command":"Get-MgDirectoryDeletedItemAsUser -All | Select-Object Id,DisplayName,UserPrincipalName,Mail,DeletedDateTime","risk":"Standard"}],"verification":"Both Exchange and Entra searches confirm only the intended object owns the value.","sourceDocument":"COPYCAT MICROSOFT 365 USER RESTORE AND ADDRESS CONFLICT ADD-IN LIST","lastVerified":""},{"id":365022,"title":"PowerShell Command Source Conflict","category":"Microsoft 365","product":"PowerShell / Exchange Online PowerShell / Microsoft Graph PowerShell","platforms":["windows","macos","linux"],"vendors":["microsoft"],"products":["PowerShell","Exchange Online PowerShell","Microsoft Graph PowerShell"],"technologies":["Command Resolution","Module Conflict"],"articleCategories":["Microsoft 365","Troubleshooting"],"aliases":["PowerShell Command Source Conflict","unexpected command source"],"tags":["Command Resolution","Module Conflict"],"keywords":["powershell command source conflict","unexpected command source","command resolution","module conflict","powershell","exchange online powershell","microsoft graph powershell"],"errorCode":"","errorMessage":"unexpected command source","eventId":"","severity":"Medium","summary":"PowerShell resolves a command name from an unexpected module, function, or session.","rootCause":"Multiple command sources export the same name or a local function shadows the expected cloud cmdlet.","resolution":"List every command source, compare module name and version, remove or avoid only the incorrect session source, reconnect to the required service, and verify resolution.","emailScript":"Hello,\n\nWe reviewed the Microsoft 365 issue related to PowerShell Command Source Conflict. We are validating the affected directory or service configuration and applying the appropriate corrective action.\n\nWe will confirm the result after authentication, provisioning, and mail flow have been verified.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the affected account signed out while IT reviews the issue.\n2. Do not rename accounts or mailboxes unless IT requests it.\n3. Wait for confirmation that Microsoft 365 provisioning has completed.\n4. Test sign-in and email only after IT confirms the correction.","notes":"","commands":[{"shell":"PowerShell","command":"Get-Command \"CommandName\" -All | Format-Table Name,CommandType,Source,Version","risk":"Standard"},{"shell":"PowerShell","command":"Get-Command Set-Mailbox -All | Format-List Name,CommandType,Source,Version,Definition","risk":"Standard"}],"verification":"The command resolves from the intended module and exposes the expected parameters.","sourceDocument":"COPYCAT MICROSOFT 365 USER RESTORE AND ADDRESS CONFLICT ADD-IN LIST","lastVerified":""},{"id":365023,"title":"PowerShell Module Version Conflict","category":"Microsoft 365","product":"PowerShell / Exchange Online PowerShell / Microsoft Graph PowerShell","platforms":["windows","macos","linux"],"vendors":["microsoft"],"products":["PowerShell","Exchange Online PowerShell","Microsoft Graph PowerShell"],"technologies":["Module Versions","PSModulePath","PowerShellGet"],"articleCategories":["Microsoft 365","Troubleshooting"],"aliases":["PowerShell Module Version Conflict","conflicting module versions"],"tags":["Module Versions","PSModulePath","PowerShellGet"],"keywords":["powershell module version conflict","conflicting module versions","module versions","psmodulepath","powershellget","powershell","exchange online powershell","microsoft graph powershell"],"errorCode":"","errorMessage":"conflicting module versions","eventId":"","severity":"Medium","summary":"Multiple or inconsistent Exchange Online or Microsoft Graph module versions cause loading or command-resolution failures.","rootCause":"Different versions exist across scopes or hosts, an update is incomplete, or the current process has stale module state.","resolution":"Close other sessions, list installed and available versions and paths, select the supported version, update or reinstall only after compatibility review, and reopen a clean session.","emailScript":"Hello,\n\nWe reviewed the Microsoft 365 issue related to PowerShell Module Version Conflict. We are validating the affected directory or service configuration and applying the appropriate corrective action.\n\nWe will confirm the result after authentication, provisioning, and mail flow have been verified.\n\nThank you,\n\nIT Support","faqSteps":"1. Keep the affected account signed out while IT reviews the issue.\n2. Do not rename accounts or mailboxes unless IT requests it.\n3. Wait for confirmation that Microsoft 365 provisioning has completed.\n4. Test sign-in and email only after IT confirms the correction.","notes":"","commands":[{"shell":"PowerShell","command":"Get-Module -ListAvailable Microsoft.Graph* | Sort-Object Name,Version | Format-Table Name,Version,Path","risk":"Standard"},{"shell":"PowerShell","command":"Get-Module -ListAvailable ExchangeOnlineManagement | Sort-Object Version -Descending | Format-Table Name,Version,Path","risk":"Standard"},{"shell":"PowerShell","command":"Get-InstalledModule","risk":"Standard"},{"shell":"PowerShell","command":"$env:PSModulePath -split [IO.Path]::PathSeparator","risk":"Standard"}],"verification":"Only intended supported versions resolve in the clean session and required commands load successfully.","sourceDocument":"COPYCAT MICROSOFT 365 USER RESTORE AND ADDRESS CONFLICT ADD-IN LIST","lastVerified":""},{"id":50000,"title":"EPERM (1) - Operation not permitted","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EPERM"],"keywords":["1","exit 1","error 1","EPERM","Operation not permitted","Linux errno","0x01","linux","unix","bash","shell"],"errorCode":"1","eventId":"","severity":"Medium","summary":"Linux errno 1 (EPERM) means: Operation not permitted. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EPERM because the requested operation encountered operation not permitted. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 1 or review errno(3) to confirm EPERM on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported operation not permitted.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 1; hexadecimal 0x01; symbolic name EPERM. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EPERM"],"aliases":["1"]},{"id":50001,"title":"ENOENT (2) - No such file or directory","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOENT"],"keywords":["2","exit 2","error 2","ENOENT","No such file or directory","Linux errno","0x02","linux","unix","bash","shell"],"errorCode":"2","eventId":"","severity":"Medium","summary":"Linux errno 2 (ENOENT) means: No such file or directory. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOENT because the requested operation encountered no such file or directory. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 2 or review errno(3) to confirm ENOENT on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported no such file or directory.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 2; hexadecimal 0x02; symbolic name ENOENT. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOENT"],"aliases":["2"]},{"id":50002,"title":"ESRCH (3) - No such process","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ESRCH"],"keywords":["3","exit 3","error 3","ESRCH","No such process","Linux errno","0x03","linux","unix","bash","shell"],"errorCode":"3","eventId":"","severity":"Medium","summary":"Linux errno 3 (ESRCH) means: No such process. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ESRCH because the requested operation encountered no such process. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 3 or review errno(3) to confirm ESRCH on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported no such process.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 3; hexadecimal 0x03; symbolic name ESRCH. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ESRCH"],"aliases":["3"]},{"id":50003,"title":"EINTR (4) - Interrupted system call","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EINTR"],"keywords":["4","exit 4","error 4","EINTR","Interrupted system call","Linux errno","0x04","linux","unix","bash","shell"],"errorCode":"4","eventId":"","severity":"Medium","summary":"Linux errno 4 (EINTR) means: Interrupted system call. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EINTR because the requested operation encountered interrupted system call. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 4 or review errno(3) to confirm EINTR on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported interrupted system call.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 4; hexadecimal 0x04; symbolic name EINTR. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EINTR"],"aliases":["4"]},{"id":50004,"title":"EIO (5) - Input/output error","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EIO"],"keywords":["5","exit 5","error 5","EIO","Input/output error","Linux errno","0x05","linux","unix","bash","shell"],"errorCode":"5","eventId":"","severity":"Medium","summary":"Linux errno 5 (EIO) means: Input/output error. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EIO because the requested operation encountered input/output error. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 5 or review errno(3) to confirm EIO on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported input/output error.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 5; hexadecimal 0x05; symbolic name EIO. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EIO"],"aliases":["5"]},{"id":50005,"title":"ENXIO (6) - No such device or address","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENXIO"],"keywords":["6","exit 6","error 6","ENXIO","No such device or address","Linux errno","0x06","linux","unix","bash","shell"],"errorCode":"6","eventId":"","severity":"Medium","summary":"Linux errno 6 (ENXIO) means: No such device or address. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENXIO because the requested operation encountered no such device or address. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 6 or review errno(3) to confirm ENXIO on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported no such device or address.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 6; hexadecimal 0x06; symbolic name ENXIO. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENXIO"],"aliases":["6"]},{"id":50006,"title":"E2BIG (7) - Argument list too long","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","E2BIG"],"keywords":["7","exit 7","error 7","E2BIG","Argument list too long","Linux errno","0x07","linux","unix","bash","shell"],"errorCode":"7","eventId":"","severity":"Medium","summary":"Linux errno 7 (E2BIG) means: Argument list too long. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with E2BIG because the requested operation encountered argument list too long. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 7 or review errno(3) to confirm E2BIG on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported argument list too long.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 7; hexadecimal 0x07; symbolic name E2BIG. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","E2BIG"],"aliases":["7"]},{"id":50007,"title":"ENOEXEC (8) - Exec format error","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOEXEC"],"keywords":["8","exit 8","error 8","ENOEXEC","Exec format error","Linux errno","0x08","linux","unix","bash","shell"],"errorCode":"8","eventId":"","severity":"Medium","summary":"Linux errno 8 (ENOEXEC) means: Exec format error. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOEXEC because the requested operation encountered exec format error. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 8 or review errno(3) to confirm ENOEXEC on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported exec format error.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 8; hexadecimal 0x08; symbolic name ENOEXEC. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOEXEC"],"aliases":["8"]},{"id":50008,"title":"EBADF (9) - Bad file descriptor","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EBADF"],"keywords":["9","exit 9","error 9","EBADF","Bad file descriptor","Linux errno","0x09","linux","unix","bash","shell"],"errorCode":"9","eventId":"","severity":"Medium","summary":"Linux errno 9 (EBADF) means: Bad file descriptor. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EBADF because the requested operation encountered bad file descriptor. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 9 or review errno(3) to confirm EBADF on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported bad file descriptor.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 9; hexadecimal 0x09; symbolic name EBADF. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EBADF"],"aliases":["9"]},{"id":50009,"title":"ECHILD (10) - No child processes","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ECHILD"],"keywords":["10","exit 10","error 10","ECHILD","No child processes","Linux errno","0x0a","linux","unix","bash","shell"],"errorCode":"10","eventId":"","severity":"Medium","summary":"Linux errno 10 (ECHILD) means: No child processes. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ECHILD because the requested operation encountered no child processes. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 10 or review errno(3) to confirm ECHILD on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported no child processes.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 10; hexadecimal 0x0a; symbolic name ECHILD. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ECHILD"],"aliases":["10"]},{"id":50010,"title":"EAGAIN (11) - Resource temporarily unavailable","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EAGAIN"],"keywords":["11","exit 11","error 11","EAGAIN","Resource temporarily unavailable","Linux errno","0x0b","linux","unix","bash","shell"],"errorCode":"11","eventId":"","severity":"Medium","summary":"Linux errno 11 (EAGAIN) means: Resource temporarily unavailable. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EAGAIN because the requested operation encountered resource temporarily unavailable. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 11 or review errno(3) to confirm EAGAIN on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported resource temporarily unavailable.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 11; hexadecimal 0x0b; symbolic name EAGAIN. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EAGAIN"],"aliases":["11"]},{"id":50011,"title":"EWOULDBLOCK (11) - Resource temporarily unavailable","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EWOULDBLOCK"],"keywords":["11","exit 11","error 11","EWOULDBLOCK","Resource temporarily unavailable","Linux errno","0x0b","linux","unix","bash","shell"],"errorCode":"11","eventId":"","severity":"Medium","summary":"Linux errno 11 (EWOULDBLOCK) means: Resource temporarily unavailable. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EWOULDBLOCK because the requested operation encountered resource temporarily unavailable. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 11 or review errno(3) to confirm EWOULDBLOCK on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported resource temporarily unavailable.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 11; hexadecimal 0x0b; symbolic name EWOULDBLOCK. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EWOULDBLOCK"],"aliases":["11"]},{"id":50012,"title":"ENOMEM (12) - Cannot allocate memory","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOMEM"],"keywords":["12","exit 12","error 12","ENOMEM","Cannot allocate memory","Linux errno","0x0c","linux","unix","bash","shell"],"errorCode":"12","eventId":"","severity":"High","summary":"Linux errno 12 (ENOMEM) means: Cannot allocate memory. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOMEM because the requested operation encountered cannot allocate memory. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 12 or review errno(3) to confirm ENOMEM on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported cannot allocate memory.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 12; hexadecimal 0x0c; symbolic name ENOMEM. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOMEM"],"aliases":["12"]},{"id":50013,"title":"EACCES (13) - Permission denied","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EACCES"],"keywords":["13","exit 13","error 13","EACCES","Permission denied","Linux errno","0x0d","linux","unix","bash","shell"],"errorCode":"13","eventId":"","severity":"Medium","summary":"Linux errno 13 (EACCES) means: Permission denied. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EACCES because the requested operation encountered permission denied. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 13 or review errno(3) to confirm EACCES on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported permission denied.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 13; hexadecimal 0x0d; symbolic name EACCES. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EACCES"],"aliases":["13"]},{"id":50014,"title":"EFAULT (14) - Bad address","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EFAULT"],"keywords":["14","exit 14","error 14","EFAULT","Bad address","Linux errno","0x0e","linux","unix","bash","shell"],"errorCode":"14","eventId":"","severity":"Medium","summary":"Linux errno 14 (EFAULT) means: Bad address. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EFAULT because the requested operation encountered bad address. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 14 or review errno(3) to confirm EFAULT on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported bad address.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 14; hexadecimal 0x0e; symbolic name EFAULT. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EFAULT"],"aliases":["14"]},{"id":50015,"title":"ENOTBLK (15) - Block device required","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOTBLK"],"keywords":["15","exit 15","error 15","ENOTBLK","Block device required","Linux errno","0x0f","linux","unix","bash","shell"],"errorCode":"15","eventId":"","severity":"Medium","summary":"Linux errno 15 (ENOTBLK) means: Block device required. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOTBLK because the requested operation encountered block device required. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 15 or review errno(3) to confirm ENOTBLK on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported block device required.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 15; hexadecimal 0x0f; symbolic name ENOTBLK. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOTBLK"],"aliases":["15"]},{"id":50016,"title":"EBUSY (16) - Device or resource busy","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EBUSY"],"keywords":["16","exit 16","error 16","EBUSY","Device or resource busy","Linux errno","0x10","linux","unix","bash","shell"],"errorCode":"16","eventId":"","severity":"Medium","summary":"Linux errno 16 (EBUSY) means: Device or resource busy. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EBUSY because the requested operation encountered device or resource busy. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 16 or review errno(3) to confirm EBUSY on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported device or resource busy.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 16; hexadecimal 0x10; symbolic name EBUSY. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EBUSY"],"aliases":["16"]},{"id":50017,"title":"EEXIST (17) - File exists","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EEXIST"],"keywords":["17","exit 17","error 17","EEXIST","File exists","Linux errno","0x11","linux","unix","bash","shell"],"errorCode":"17","eventId":"","severity":"Medium","summary":"Linux errno 17 (EEXIST) means: File exists. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EEXIST because the requested operation encountered file exists. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 17 or review errno(3) to confirm EEXIST on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported file exists.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 17; hexadecimal 0x11; symbolic name EEXIST. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EEXIST"],"aliases":["17"]},{"id":50018,"title":"EXDEV (18) - Invalid cross-device link","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EXDEV"],"keywords":["18","exit 18","error 18","EXDEV","Invalid cross-device link","Linux errno","0x12","linux","unix","bash","shell"],"errorCode":"18","eventId":"","severity":"Medium","summary":"Linux errno 18 (EXDEV) means: Invalid cross-device link. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EXDEV because the requested operation encountered invalid cross-device link. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 18 or review errno(3) to confirm EXDEV on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported invalid cross-device link.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 18; hexadecimal 0x12; symbolic name EXDEV. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EXDEV"],"aliases":["18"]},{"id":50019,"title":"ENODEV (19) - No such device","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENODEV"],"keywords":["19","exit 19","error 19","ENODEV","No such device","Linux errno","0x13","linux","unix","bash","shell"],"errorCode":"19","eventId":"","severity":"Medium","summary":"Linux errno 19 (ENODEV) means: No such device. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENODEV because the requested operation encountered no such device. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 19 or review errno(3) to confirm ENODEV on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported no such device.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 19; hexadecimal 0x13; symbolic name ENODEV. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENODEV"],"aliases":["19"]},{"id":50020,"title":"ENOTDIR (20) - Not a directory","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOTDIR"],"keywords":["20","exit 20","error 20","ENOTDIR","Not a directory","Linux errno","0x14","linux","unix","bash","shell"],"errorCode":"20","eventId":"","severity":"Medium","summary":"Linux errno 20 (ENOTDIR) means: Not a directory. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOTDIR because the requested operation encountered not a directory. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 20 or review errno(3) to confirm ENOTDIR on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported not a directory.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 20; hexadecimal 0x14; symbolic name ENOTDIR. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOTDIR"],"aliases":["20"]},{"id":50021,"title":"EISDIR (21) - Is a directory","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EISDIR"],"keywords":["21","exit 21","error 21","EISDIR","Is a directory","Linux errno","0x15","linux","unix","bash","shell"],"errorCode":"21","eventId":"","severity":"Medium","summary":"Linux errno 21 (EISDIR) means: Is a directory. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EISDIR because the requested operation encountered is a directory. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 21 or review errno(3) to confirm EISDIR on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported is a directory.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 21; hexadecimal 0x15; symbolic name EISDIR. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EISDIR"],"aliases":["21"]},{"id":50022,"title":"EINVAL (22) - Invalid argument","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EINVAL"],"keywords":["22","exit 22","error 22","EINVAL","Invalid argument","Linux errno","0x16","linux","unix","bash","shell"],"errorCode":"22","eventId":"","severity":"Medium","summary":"Linux errno 22 (EINVAL) means: Invalid argument. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EINVAL because the requested operation encountered invalid argument. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 22 or review errno(3) to confirm EINVAL on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported invalid argument.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 22; hexadecimal 0x16; symbolic name EINVAL. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EINVAL"],"aliases":["22"]},{"id":50023,"title":"ENFILE (23) - Too many open files in system","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENFILE"],"keywords":["23","exit 23","error 23","ENFILE","Too many open files in system","Linux errno","0x17","linux","unix","bash","shell"],"errorCode":"23","eventId":"","severity":"Medium","summary":"Linux errno 23 (ENFILE) means: Too many open files in system. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENFILE because the requested operation encountered too many open files in system. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 23 or review errno(3) to confirm ENFILE on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported too many open files in system.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 23; hexadecimal 0x17; symbolic name ENFILE. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENFILE"],"aliases":["23"]},{"id":50024,"title":"EMFILE (24) - Too many open files","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EMFILE"],"keywords":["24","exit 24","error 24","EMFILE","Too many open files","Linux errno","0x18","linux","unix","bash","shell"],"errorCode":"24","eventId":"","severity":"Medium","summary":"Linux errno 24 (EMFILE) means: Too many open files. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EMFILE because the requested operation encountered too many open files. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 24 or review errno(3) to confirm EMFILE on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported too many open files.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 24; hexadecimal 0x18; symbolic name EMFILE. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EMFILE"],"aliases":["24"]},{"id":50025,"title":"ENOTTY (25) - Inappropriate ioctl for device","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOTTY"],"keywords":["25","exit 25","error 25","ENOTTY","Inappropriate ioctl for device","Linux errno","0x19","linux","unix","bash","shell"],"errorCode":"25","eventId":"","severity":"Medium","summary":"Linux errno 25 (ENOTTY) means: Inappropriate ioctl for device. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOTTY because the requested operation encountered inappropriate ioctl for device. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 25 or review errno(3) to confirm ENOTTY on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported inappropriate ioctl for device.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 25; hexadecimal 0x19; symbolic name ENOTTY. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOTTY"],"aliases":["25"]},{"id":50026,"title":"ETXTBSY (26) - Text file busy","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ETXTBSY"],"keywords":["26","exit 26","error 26","ETXTBSY","Text file busy","Linux errno","0x1a","linux","unix","bash","shell"],"errorCode":"26","eventId":"","severity":"Medium","summary":"Linux errno 26 (ETXTBSY) means: Text file busy. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ETXTBSY because the requested operation encountered text file busy. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 26 or review errno(3) to confirm ETXTBSY on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported text file busy.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 26; hexadecimal 0x1a; symbolic name ETXTBSY. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ETXTBSY"],"aliases":["26"]},{"id":50027,"title":"EFBIG (27) - File too large","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EFBIG"],"keywords":["27","exit 27","error 27","EFBIG","File too large","Linux errno","0x1b","linux","unix","bash","shell"],"errorCode":"27","eventId":"","severity":"Medium","summary":"Linux errno 27 (EFBIG) means: File too large. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EFBIG because the requested operation encountered file too large. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 27 or review errno(3) to confirm EFBIG on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported file too large.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 27; hexadecimal 0x1b; symbolic name EFBIG. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EFBIG"],"aliases":["27"]},{"id":50028,"title":"ENOSPC (28) - No space left on device","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOSPC"],"keywords":["28","exit 28","error 28","ENOSPC","No space left on device","Linux errno","0x1c","linux","unix","bash","shell"],"errorCode":"28","eventId":"","severity":"Medium","summary":"Linux errno 28 (ENOSPC) means: No space left on device. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOSPC because the requested operation encountered no space left on device. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 28 or review errno(3) to confirm ENOSPC on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported no space left on device.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 28; hexadecimal 0x1c; symbolic name ENOSPC. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOSPC"],"aliases":["28"]},{"id":50029,"title":"ESPIPE (29) - Illegal seek","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ESPIPE"],"keywords":["29","exit 29","error 29","ESPIPE","Illegal seek","Linux errno","0x1d","linux","unix","bash","shell"],"errorCode":"29","eventId":"","severity":"Medium","summary":"Linux errno 29 (ESPIPE) means: Illegal seek. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ESPIPE because the requested operation encountered illegal seek. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 29 or review errno(3) to confirm ESPIPE on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported illegal seek.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 29; hexadecimal 0x1d; symbolic name ESPIPE. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ESPIPE"],"aliases":["29"]},{"id":50030,"title":"EROFS (30) - Read-only file system","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EROFS"],"keywords":["30","exit 30","error 30","EROFS","Read-only file system","Linux errno","0x1e","linux","unix","bash","shell"],"errorCode":"30","eventId":"","severity":"Medium","summary":"Linux errno 30 (EROFS) means: Read-only file system. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EROFS because the requested operation encountered read-only file system. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 30 or review errno(3) to confirm EROFS on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported read-only file system.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 30; hexadecimal 0x1e; symbolic name EROFS. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EROFS"],"aliases":["30"]},{"id":50031,"title":"EMLINK (31) - Too many links","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EMLINK"],"keywords":["31","exit 31","error 31","EMLINK","Too many links","Linux errno","0x1f","linux","unix","bash","shell"],"errorCode":"31","eventId":"","severity":"Medium","summary":"Linux errno 31 (EMLINK) means: Too many links. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EMLINK because the requested operation encountered too many links. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 31 or review errno(3) to confirm EMLINK on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported too many links.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 31; hexadecimal 0x1f; symbolic name EMLINK. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EMLINK"],"aliases":["31"]},{"id":50032,"title":"EPIPE (32) - Broken pipe","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EPIPE"],"keywords":["32","exit 32","error 32","EPIPE","Broken pipe","Linux errno","0x20","linux","unix","bash","shell"],"errorCode":"32","eventId":"","severity":"Medium","summary":"Linux errno 32 (EPIPE) means: Broken pipe. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EPIPE because the requested operation encountered broken pipe. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 32 or review errno(3) to confirm EPIPE on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported broken pipe.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 32; hexadecimal 0x20; symbolic name EPIPE. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EPIPE"],"aliases":["32"]},{"id":50033,"title":"EDOM (33) - Numerical argument out of domain","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EDOM"],"keywords":["33","exit 33","error 33","EDOM","Numerical argument out of domain","Linux errno","0x21","linux","unix","bash","shell"],"errorCode":"33","eventId":"","severity":"Medium","summary":"Linux errno 33 (EDOM) means: Numerical argument out of domain. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EDOM because the requested operation encountered numerical argument out of domain. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 33 or review errno(3) to confirm EDOM on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported numerical argument out of domain.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 33; hexadecimal 0x21; symbolic name EDOM. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EDOM"],"aliases":["33"]},{"id":50034,"title":"ERANGE (34) - Numerical result out of range","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ERANGE"],"keywords":["34","exit 34","error 34","ERANGE","Numerical result out of range","Linux errno","0x22","linux","unix","bash","shell"],"errorCode":"34","eventId":"","severity":"Medium","summary":"Linux errno 34 (ERANGE) means: Numerical result out of range. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ERANGE because the requested operation encountered numerical result out of range. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 34 or review errno(3) to confirm ERANGE on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported numerical result out of range.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 34; hexadecimal 0x22; symbolic name ERANGE. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ERANGE"],"aliases":["34"]},{"id":50035,"title":"EDEADLK (35) - Resource deadlock avoided","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EDEADLK"],"keywords":["35","exit 35","error 35","EDEADLK","Resource deadlock avoided","Linux errno","0x23","linux","unix","bash","shell"],"errorCode":"35","eventId":"","severity":"Medium","summary":"Linux errno 35 (EDEADLK) means: Resource deadlock avoided. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EDEADLK because the requested operation encountered resource deadlock avoided. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 35 or review errno(3) to confirm EDEADLK on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported resource deadlock avoided.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 35; hexadecimal 0x23; symbolic name EDEADLK. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EDEADLK"],"aliases":["35"]},{"id":50036,"title":"EDEADLOCK (35) - Resource deadlock avoided","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EDEADLOCK"],"keywords":["35","exit 35","error 35","EDEADLOCK","Resource deadlock avoided","Linux errno","0x23","linux","unix","bash","shell"],"errorCode":"35","eventId":"","severity":"Medium","summary":"Linux errno 35 (EDEADLOCK) means: Resource deadlock avoided. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EDEADLOCK because the requested operation encountered resource deadlock avoided. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 35 or review errno(3) to confirm EDEADLOCK on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported resource deadlock avoided.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 35; hexadecimal 0x23; symbolic name EDEADLOCK. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EDEADLOCK"],"aliases":["35"]},{"id":50037,"title":"ENAMETOOLONG (36) - File name too long","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENAMETOOLONG"],"keywords":["36","exit 36","error 36","ENAMETOOLONG","File name too long","Linux errno","0x24","linux","unix","bash","shell"],"errorCode":"36","eventId":"","severity":"Medium","summary":"Linux errno 36 (ENAMETOOLONG) means: File name too long. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENAMETOOLONG because the requested operation encountered file name too long. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 36 or review errno(3) to confirm ENAMETOOLONG on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported file name too long.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 36; hexadecimal 0x24; symbolic name ENAMETOOLONG. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENAMETOOLONG"],"aliases":["36"]},{"id":50038,"title":"ENOLCK (37) - No locks available","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOLCK"],"keywords":["37","exit 37","error 37","ENOLCK","No locks available","Linux errno","0x25","linux","unix","bash","shell"],"errorCode":"37","eventId":"","severity":"Medium","summary":"Linux errno 37 (ENOLCK) means: No locks available. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOLCK because the requested operation encountered no locks available. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 37 or review errno(3) to confirm ENOLCK on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported no locks available.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 37; hexadecimal 0x25; symbolic name ENOLCK. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOLCK"],"aliases":["37"]},{"id":50039,"title":"ENOSYS (38) - Function not implemented","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOSYS"],"keywords":["38","exit 38","error 38","ENOSYS","Function not implemented","Linux errno","0x26","linux","unix","bash","shell"],"errorCode":"38","eventId":"","severity":"Medium","summary":"Linux errno 38 (ENOSYS) means: Function not implemented. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOSYS because the requested operation encountered function not implemented. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 38 or review errno(3) to confirm ENOSYS on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported function not implemented.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 38; hexadecimal 0x26; symbolic name ENOSYS. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOSYS"],"aliases":["38"]},{"id":50040,"title":"ENOTEMPTY (39) - Directory not empty","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOTEMPTY"],"keywords":["39","exit 39","error 39","ENOTEMPTY","Directory not empty","Linux errno","0x27","linux","unix","bash","shell"],"errorCode":"39","eventId":"","severity":"Medium","summary":"Linux errno 39 (ENOTEMPTY) means: Directory not empty. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOTEMPTY because the requested operation encountered directory not empty. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 39 or review errno(3) to confirm ENOTEMPTY on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported directory not empty.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 39; hexadecimal 0x27; symbolic name ENOTEMPTY. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOTEMPTY"],"aliases":["39"]},{"id":50041,"title":"ELOOP (40) - Too many levels of symbolic links","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ELOOP"],"keywords":["40","exit 40","error 40","ELOOP","Too many levels of symbolic links","Linux errno","0x28","linux","unix","bash","shell"],"errorCode":"40","eventId":"","severity":"Medium","summary":"Linux errno 40 (ELOOP) means: Too many levels of symbolic links. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ELOOP because the requested operation encountered too many levels of symbolic links. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 40 or review errno(3) to confirm ELOOP on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported too many levels of symbolic links.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 40; hexadecimal 0x28; symbolic name ELOOP. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ELOOP"],"aliases":["40"]},{"id":50042,"title":"ENOMSG (42) - No message of desired type","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOMSG"],"keywords":["42","exit 42","error 42","ENOMSG","No message of desired type","Linux errno","0x2a","linux","unix","bash","shell"],"errorCode":"42","eventId":"","severity":"Medium","summary":"Linux errno 42 (ENOMSG) means: No message of desired type. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOMSG because the requested operation encountered no message of desired type. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 42 or review errno(3) to confirm ENOMSG on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported no message of desired type.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 42; hexadecimal 0x2a; symbolic name ENOMSG. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOMSG"],"aliases":["42"]},{"id":50043,"title":"EIDRM (43) - Identifier removed","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EIDRM"],"keywords":["43","exit 43","error 43","EIDRM","Identifier removed","Linux errno","0x2b","linux","unix","bash","shell"],"errorCode":"43","eventId":"","severity":"Medium","summary":"Linux errno 43 (EIDRM) means: Identifier removed. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EIDRM because the requested operation encountered identifier removed. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 43 or review errno(3) to confirm EIDRM on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported identifier removed.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 43; hexadecimal 0x2b; symbolic name EIDRM. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EIDRM"],"aliases":["43"]},{"id":50044,"title":"ECHRNG (44) - Channel number out of range","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ECHRNG"],"keywords":["44","exit 44","error 44","ECHRNG","Channel number out of range","Linux errno","0x2c","linux","unix","bash","shell"],"errorCode":"44","eventId":"","severity":"Medium","summary":"Linux errno 44 (ECHRNG) means: Channel number out of range. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ECHRNG because the requested operation encountered channel number out of range. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 44 or review errno(3) to confirm ECHRNG on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported channel number out of range.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 44; hexadecimal 0x2c; symbolic name ECHRNG. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ECHRNG"],"aliases":["44"]},{"id":50045,"title":"EL2NSYNC (45) - Level 2 not synchronized","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EL2NSYNC"],"keywords":["45","exit 45","error 45","EL2NSYNC","Level 2 not synchronized","Linux errno","0x2d","linux","unix","bash","shell"],"errorCode":"45","eventId":"","severity":"Medium","summary":"Linux errno 45 (EL2NSYNC) means: Level 2 not synchronized. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EL2NSYNC because the requested operation encountered level 2 not synchronized. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 45 or review errno(3) to confirm EL2NSYNC on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported level 2 not synchronized.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 45; hexadecimal 0x2d; symbolic name EL2NSYNC. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EL2NSYNC"],"aliases":["45"]},{"id":50046,"title":"EL3HLT (46) - Level 3 halted","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EL3HLT"],"keywords":["46","exit 46","error 46","EL3HLT","Level 3 halted","Linux errno","0x2e","linux","unix","bash","shell"],"errorCode":"46","eventId":"","severity":"Medium","summary":"Linux errno 46 (EL3HLT) means: Level 3 halted. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EL3HLT because the requested operation encountered level 3 halted. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 46 or review errno(3) to confirm EL3HLT on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported level 3 halted.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 46; hexadecimal 0x2e; symbolic name EL3HLT. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EL3HLT"],"aliases":["46"]},{"id":50047,"title":"EL3RST (47) - Level 3 reset","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EL3RST"],"keywords":["47","exit 47","error 47","EL3RST","Level 3 reset","Linux errno","0x2f","linux","unix","bash","shell"],"errorCode":"47","eventId":"","severity":"Medium","summary":"Linux errno 47 (EL3RST) means: Level 3 reset. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EL3RST because the requested operation encountered level 3 reset. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 47 or review errno(3) to confirm EL3RST on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported level 3 reset.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 47; hexadecimal 0x2f; symbolic name EL3RST. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EL3RST"],"aliases":["47"]},{"id":50048,"title":"ELNRNG (48) - Link number out of range","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ELNRNG"],"keywords":["48","exit 48","error 48","ELNRNG","Link number out of range","Linux errno","0x30","linux","unix","bash","shell"],"errorCode":"48","eventId":"","severity":"Medium","summary":"Linux errno 48 (ELNRNG) means: Link number out of range. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ELNRNG because the requested operation encountered link number out of range. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 48 or review errno(3) to confirm ELNRNG on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported link number out of range.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 48; hexadecimal 0x30; symbolic name ELNRNG. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ELNRNG"],"aliases":["48"]},{"id":50049,"title":"EUNATCH (49) - Protocol driver not attached","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EUNATCH"],"keywords":["49","exit 49","error 49","EUNATCH","Protocol driver not attached","Linux errno","0x31","linux","unix","bash","shell"],"errorCode":"49","eventId":"","severity":"Medium","summary":"Linux errno 49 (EUNATCH) means: Protocol driver not attached. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EUNATCH because the requested operation encountered protocol driver not attached. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 49 or review errno(3) to confirm EUNATCH on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported protocol driver not attached.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 49; hexadecimal 0x31; symbolic name EUNATCH. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EUNATCH"],"aliases":["49"]},{"id":50050,"title":"ENOCSI (50) - No CSI structure available","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOCSI"],"keywords":["50","exit 50","error 50","ENOCSI","No CSI structure available","Linux errno","0x32","linux","unix","bash","shell"],"errorCode":"50","eventId":"","severity":"Medium","summary":"Linux errno 50 (ENOCSI) means: No CSI structure available. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOCSI because the requested operation encountered no csi structure available. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 50 or review errno(3) to confirm ENOCSI on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported no csi structure available.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 50; hexadecimal 0x32; symbolic name ENOCSI. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOCSI"],"aliases":["50"]},{"id":50051,"title":"EL2HLT (51) - Level 2 halted","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EL2HLT"],"keywords":["51","exit 51","error 51","EL2HLT","Level 2 halted","Linux errno","0x33","linux","unix","bash","shell"],"errorCode":"51","eventId":"","severity":"Medium","summary":"Linux errno 51 (EL2HLT) means: Level 2 halted. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EL2HLT because the requested operation encountered level 2 halted. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 51 or review errno(3) to confirm EL2HLT on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported level 2 halted.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 51; hexadecimal 0x33; symbolic name EL2HLT. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EL2HLT"],"aliases":["51"]},{"id":50052,"title":"EBADE (52) - Invalid exchange","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EBADE"],"keywords":["52","exit 52","error 52","EBADE","Invalid exchange","Linux errno","0x34","linux","unix","bash","shell"],"errorCode":"52","eventId":"","severity":"Medium","summary":"Linux errno 52 (EBADE) means: Invalid exchange. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EBADE because the requested operation encountered invalid exchange. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 52 or review errno(3) to confirm EBADE on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported invalid exchange.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 52; hexadecimal 0x34; symbolic name EBADE. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EBADE"],"aliases":["52"]},{"id":50053,"title":"EBADR (53) - Invalid request descriptor","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EBADR"],"keywords":["53","exit 53","error 53","EBADR","Invalid request descriptor","Linux errno","0x35","linux","unix","bash","shell"],"errorCode":"53","eventId":"","severity":"Medium","summary":"Linux errno 53 (EBADR) means: Invalid request descriptor. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EBADR because the requested operation encountered invalid request descriptor. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 53 or review errno(3) to confirm EBADR on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported invalid request descriptor.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 53; hexadecimal 0x35; symbolic name EBADR. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EBADR"],"aliases":["53"]},{"id":50054,"title":"EXFULL (54) - Exchange full","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EXFULL"],"keywords":["54","exit 54","error 54","EXFULL","Exchange full","Linux errno","0x36","linux","unix","bash","shell"],"errorCode":"54","eventId":"","severity":"Medium","summary":"Linux errno 54 (EXFULL) means: Exchange full. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EXFULL because the requested operation encountered exchange full. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 54 or review errno(3) to confirm EXFULL on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported exchange full.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 54; hexadecimal 0x36; symbolic name EXFULL. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EXFULL"],"aliases":["54"]},{"id":50055,"title":"ENOANO (55) - No anode","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOANO"],"keywords":["55","exit 55","error 55","ENOANO","No anode","Linux errno","0x37","linux","unix","bash","shell"],"errorCode":"55","eventId":"","severity":"Medium","summary":"Linux errno 55 (ENOANO) means: No anode. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOANO because the requested operation encountered no anode. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 55 or review errno(3) to confirm ENOANO on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported no anode.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 55; hexadecimal 0x37; symbolic name ENOANO. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOANO"],"aliases":["55"]},{"id":50056,"title":"EBADRQC (56) - Invalid request code","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EBADRQC"],"keywords":["56","exit 56","error 56","EBADRQC","Invalid request code","Linux errno","0x38","linux","unix","bash","shell"],"errorCode":"56","eventId":"","severity":"Medium","summary":"Linux errno 56 (EBADRQC) means: Invalid request code. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EBADRQC because the requested operation encountered invalid request code. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 56 or review errno(3) to confirm EBADRQC on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported invalid request code.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 56; hexadecimal 0x38; symbolic name EBADRQC. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EBADRQC"],"aliases":["56"]},{"id":50057,"title":"EBADSLT (57) - Invalid slot","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EBADSLT"],"keywords":["57","exit 57","error 57","EBADSLT","Invalid slot","Linux errno","0x39","linux","unix","bash","shell"],"errorCode":"57","eventId":"","severity":"Medium","summary":"Linux errno 57 (EBADSLT) means: Invalid slot. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EBADSLT because the requested operation encountered invalid slot. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 57 or review errno(3) to confirm EBADSLT on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported invalid slot.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 57; hexadecimal 0x39; symbolic name EBADSLT. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EBADSLT"],"aliases":["57"]},{"id":50058,"title":"EBFONT (59) - Bad font file format","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EBFONT"],"keywords":["59","exit 59","error 59","EBFONT","Bad font file format","Linux errno","0x3b","linux","unix","bash","shell"],"errorCode":"59","eventId":"","severity":"Medium","summary":"Linux errno 59 (EBFONT) means: Bad font file format. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EBFONT because the requested operation encountered bad font file format. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 59 or review errno(3) to confirm EBFONT on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported bad font file format.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 59; hexadecimal 0x3b; symbolic name EBFONT. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EBFONT"],"aliases":["59"]},{"id":50059,"title":"ENOSTR (60) - Device not a stream","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOSTR"],"keywords":["60","exit 60","error 60","ENOSTR","Device not a stream","Linux errno","0x3c","linux","unix","bash","shell"],"errorCode":"60","eventId":"","severity":"Medium","summary":"Linux errno 60 (ENOSTR) means: Device not a stream. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOSTR because the requested operation encountered device not a stream. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 60 or review errno(3) to confirm ENOSTR on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported device not a stream.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 60; hexadecimal 0x3c; symbolic name ENOSTR. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOSTR"],"aliases":["60"]},{"id":50060,"title":"ENODATA (61) - No data available","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENODATA"],"keywords":["61","exit 61","error 61","ENODATA","No data available","Linux errno","0x3d","linux","unix","bash","shell"],"errorCode":"61","eventId":"","severity":"Medium","summary":"Linux errno 61 (ENODATA) means: No data available. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENODATA because the requested operation encountered no data available. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 61 or review errno(3) to confirm ENODATA on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported no data available.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 61; hexadecimal 0x3d; symbolic name ENODATA. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENODATA"],"aliases":["61"]},{"id":50061,"title":"ETIME (62) - Timer expired","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ETIME"],"keywords":["62","exit 62","error 62","ETIME","Timer expired","Linux errno","0x3e","linux","unix","bash","shell"],"errorCode":"62","eventId":"","severity":"Medium","summary":"Linux errno 62 (ETIME) means: Timer expired. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ETIME because the requested operation encountered timer expired. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 62 or review errno(3) to confirm ETIME on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported timer expired.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 62; hexadecimal 0x3e; symbolic name ETIME. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ETIME"],"aliases":["62"]},{"id":50062,"title":"ENOSR (63) - Out of streams resources","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOSR"],"keywords":["63","exit 63","error 63","ENOSR","Out of streams resources","Linux errno","0x3f","linux","unix","bash","shell"],"errorCode":"63","eventId":"","severity":"Medium","summary":"Linux errno 63 (ENOSR) means: Out of streams resources. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOSR because the requested operation encountered out of streams resources. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 63 or review errno(3) to confirm ENOSR on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported out of streams resources.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 63; hexadecimal 0x3f; symbolic name ENOSR. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOSR"],"aliases":["63"]},{"id":50063,"title":"ENONET (64) - Machine is not on the network","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENONET"],"keywords":["64","exit 64","error 64","ENONET","Machine is not on the network","Linux errno","0x40","linux","unix","bash","shell"],"errorCode":"64","eventId":"","severity":"Medium","summary":"Linux errno 64 (ENONET) means: Machine is not on the network. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENONET because the requested operation encountered machine is not on the network. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 64 or review errno(3) to confirm ENONET on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported machine is not on the network.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 64; hexadecimal 0x40; symbolic name ENONET. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENONET"],"aliases":["64"]},{"id":50064,"title":"ENOPKG (65) - Package not installed","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOPKG"],"keywords":["65","exit 65","error 65","ENOPKG","Package not installed","Linux errno","0x41","linux","unix","bash","shell"],"errorCode":"65","eventId":"","severity":"Medium","summary":"Linux errno 65 (ENOPKG) means: Package not installed. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOPKG because the requested operation encountered package not installed. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 65 or review errno(3) to confirm ENOPKG on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported package not installed.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 65; hexadecimal 0x41; symbolic name ENOPKG. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOPKG"],"aliases":["65"]},{"id":50065,"title":"EREMOTE (66) - Object is remote","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EREMOTE"],"keywords":["66","exit 66","error 66","EREMOTE","Object is remote","Linux errno","0x42","linux","unix","bash","shell"],"errorCode":"66","eventId":"","severity":"Medium","summary":"Linux errno 66 (EREMOTE) means: Object is remote. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EREMOTE because the requested operation encountered object is remote. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 66 or review errno(3) to confirm EREMOTE on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported object is remote.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 66; hexadecimal 0x42; symbolic name EREMOTE. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EREMOTE"],"aliases":["66"]},{"id":50066,"title":"ENOLINK (67) - Link has been severed","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOLINK"],"keywords":["67","exit 67","error 67","ENOLINK","Link has been severed","Linux errno","0x43","linux","unix","bash","shell"],"errorCode":"67","eventId":"","severity":"Medium","summary":"Linux errno 67 (ENOLINK) means: Link has been severed. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOLINK because the requested operation encountered link has been severed. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 67 or review errno(3) to confirm ENOLINK on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported link has been severed.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 67; hexadecimal 0x43; symbolic name ENOLINK. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOLINK"],"aliases":["67"]},{"id":50067,"title":"EADV (68) - Advertise error","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EADV"],"keywords":["68","exit 68","error 68","EADV","Advertise error","Linux errno","0x44","linux","unix","bash","shell"],"errorCode":"68","eventId":"","severity":"Medium","summary":"Linux errno 68 (EADV) means: Advertise error. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EADV because the requested operation encountered advertise error. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 68 or review errno(3) to confirm EADV on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported advertise error.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 68; hexadecimal 0x44; symbolic name EADV. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EADV"],"aliases":["68"]},{"id":50068,"title":"ESRMNT (69) - Srmount error","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ESRMNT"],"keywords":["69","exit 69","error 69","ESRMNT","Srmount error","Linux errno","0x45","linux","unix","bash","shell"],"errorCode":"69","eventId":"","severity":"Medium","summary":"Linux errno 69 (ESRMNT) means: Srmount error. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ESRMNT because the requested operation encountered srmount error. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 69 or review errno(3) to confirm ESRMNT on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported srmount error.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 69; hexadecimal 0x45; symbolic name ESRMNT. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ESRMNT"],"aliases":["69"]},{"id":50069,"title":"ECOMM (70) - Communication error on send","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ECOMM"],"keywords":["70","exit 70","error 70","ECOMM","Communication error on send","Linux errno","0x46","linux","unix","bash","shell"],"errorCode":"70","eventId":"","severity":"Medium","summary":"Linux errno 70 (ECOMM) means: Communication error on send. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ECOMM because the requested operation encountered communication error on send. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 70 or review errno(3) to confirm ECOMM on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported communication error on send.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 70; hexadecimal 0x46; symbolic name ECOMM. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ECOMM"],"aliases":["70"]},{"id":50070,"title":"EPROTO (71) - Protocol error","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EPROTO"],"keywords":["71","exit 71","error 71","EPROTO","Protocol error","Linux errno","0x47","linux","unix","bash","shell"],"errorCode":"71","eventId":"","severity":"Medium","summary":"Linux errno 71 (EPROTO) means: Protocol error. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EPROTO because the requested operation encountered protocol error. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 71 or review errno(3) to confirm EPROTO on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported protocol error.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 71; hexadecimal 0x47; symbolic name EPROTO. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EPROTO"],"aliases":["71"]},{"id":50071,"title":"EMULTIHOP (72) - Multihop attempted","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EMULTIHOP"],"keywords":["72","exit 72","error 72","EMULTIHOP","Multihop attempted","Linux errno","0x48","linux","unix","bash","shell"],"errorCode":"72","eventId":"","severity":"Medium","summary":"Linux errno 72 (EMULTIHOP) means: Multihop attempted. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EMULTIHOP because the requested operation encountered multihop attempted. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 72 or review errno(3) to confirm EMULTIHOP on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported multihop attempted.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 72; hexadecimal 0x48; symbolic name EMULTIHOP. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EMULTIHOP"],"aliases":["72"]},{"id":50072,"title":"EDOTDOT (73) - RFS specific error","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EDOTDOT"],"keywords":["73","exit 73","error 73","EDOTDOT","RFS specific error","Linux errno","0x49","linux","unix","bash","shell"],"errorCode":"73","eventId":"","severity":"Medium","summary":"Linux errno 73 (EDOTDOT) means: RFS specific error. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EDOTDOT because the requested operation encountered rfs specific error. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 73 or review errno(3) to confirm EDOTDOT on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported rfs specific error.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 73; hexadecimal 0x49; symbolic name EDOTDOT. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EDOTDOT"],"aliases":["73"]},{"id":50073,"title":"EBADMSG (74) - Bad message","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EBADMSG"],"keywords":["74","exit 74","error 74","EBADMSG","Bad message","Linux errno","0x4a","linux","unix","bash","shell"],"errorCode":"74","eventId":"","severity":"Medium","summary":"Linux errno 74 (EBADMSG) means: Bad message. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EBADMSG because the requested operation encountered bad message. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 74 or review errno(3) to confirm EBADMSG on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported bad message.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 74; hexadecimal 0x4a; symbolic name EBADMSG. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EBADMSG"],"aliases":["74"]},{"id":50074,"title":"EOVERFLOW (75) - Value too large for defined data type","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EOVERFLOW"],"keywords":["75","exit 75","error 75","EOVERFLOW","Value too large for defined data type","Linux errno","0x4b","linux","unix","bash","shell"],"errorCode":"75","eventId":"","severity":"Medium","summary":"Linux errno 75 (EOVERFLOW) means: Value too large for defined data type. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EOVERFLOW because the requested operation encountered value too large for defined data type. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 75 or review errno(3) to confirm EOVERFLOW on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported value too large for defined data type.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 75; hexadecimal 0x4b; symbolic name EOVERFLOW. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EOVERFLOW"],"aliases":["75"]},{"id":50075,"title":"ENOTUNIQ (76) - Name not unique on network","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOTUNIQ"],"keywords":["76","exit 76","error 76","ENOTUNIQ","Name not unique on network","Linux errno","0x4c","linux","unix","bash","shell"],"errorCode":"76","eventId":"","severity":"Medium","summary":"Linux errno 76 (ENOTUNIQ) means: Name not unique on network. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOTUNIQ because the requested operation encountered name not unique on network. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 76 or review errno(3) to confirm ENOTUNIQ on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported name not unique on network.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 76; hexadecimal 0x4c; symbolic name ENOTUNIQ. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOTUNIQ"],"aliases":["76"]},{"id":50076,"title":"EBADFD (77) - File descriptor in bad state","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EBADFD"],"keywords":["77","exit 77","error 77","EBADFD","File descriptor in bad state","Linux errno","0x4d","linux","unix","bash","shell"],"errorCode":"77","eventId":"","severity":"Medium","summary":"Linux errno 77 (EBADFD) means: File descriptor in bad state. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EBADFD because the requested operation encountered file descriptor in bad state. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 77 or review errno(3) to confirm EBADFD on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported file descriptor in bad state.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 77; hexadecimal 0x4d; symbolic name EBADFD. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EBADFD"],"aliases":["77"]},{"id":50077,"title":"EREMCHG (78) - Remote address changed","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EREMCHG"],"keywords":["78","exit 78","error 78","EREMCHG","Remote address changed","Linux errno","0x4e","linux","unix","bash","shell"],"errorCode":"78","eventId":"","severity":"Medium","summary":"Linux errno 78 (EREMCHG) means: Remote address changed. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EREMCHG because the requested operation encountered remote address changed. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 78 or review errno(3) to confirm EREMCHG on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported remote address changed.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 78; hexadecimal 0x4e; symbolic name EREMCHG. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EREMCHG"],"aliases":["78"]},{"id":50078,"title":"ELIBACC (79) - Cannot access a needed shared library","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ELIBACC"],"keywords":["79","exit 79","error 79","ELIBACC","Cannot access a needed shared library","Linux errno","0x4f","linux","unix","bash","shell"],"errorCode":"79","eventId":"","severity":"Medium","summary":"Linux errno 79 (ELIBACC) means: Cannot access a needed shared library. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ELIBACC because the requested operation encountered cannot access a needed shared library. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 79 or review errno(3) to confirm ELIBACC on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported cannot access a needed shared library.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 79; hexadecimal 0x4f; symbolic name ELIBACC. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ELIBACC"],"aliases":["79"]},{"id":50079,"title":"ELIBBAD (80) - Accessing a corrupted shared library","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ELIBBAD"],"keywords":["80","exit 80","error 80","ELIBBAD","Accessing a corrupted shared library","Linux errno","0x50","linux","unix","bash","shell"],"errorCode":"80","eventId":"","severity":"Medium","summary":"Linux errno 80 (ELIBBAD) means: Accessing a corrupted shared library. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ELIBBAD because the requested operation encountered accessing a corrupted shared library. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 80 or review errno(3) to confirm ELIBBAD on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported accessing a corrupted shared library.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 80; hexadecimal 0x50; symbolic name ELIBBAD. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ELIBBAD"],"aliases":["80"]},{"id":50080,"title":"ELIBSCN (81) - .lib section in a.out corrupted","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ELIBSCN"],"keywords":["81","exit 81","error 81","ELIBSCN",".lib section in a.out corrupted","Linux errno","0x51","linux","unix","bash","shell"],"errorCode":"81","eventId":"","severity":"Medium","summary":"Linux errno 81 (ELIBSCN) means: .lib section in a.out corrupted. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ELIBSCN because the requested operation encountered .lib section in a.out corrupted. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 81 or review errno(3) to confirm ELIBSCN on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported .lib section in a.out corrupted.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 81; hexadecimal 0x51; symbolic name ELIBSCN. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ELIBSCN"],"aliases":["81"]},{"id":50081,"title":"ELIBMAX (82) - Attempting to link in too many shared libraries","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ELIBMAX"],"keywords":["82","exit 82","error 82","ELIBMAX","Attempting to link in too many shared libraries","Linux errno","0x52","linux","unix","bash","shell"],"errorCode":"82","eventId":"","severity":"Medium","summary":"Linux errno 82 (ELIBMAX) means: Attempting to link in too many shared libraries. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ELIBMAX because the requested operation encountered attempting to link in too many shared libraries. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 82 or review errno(3) to confirm ELIBMAX on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported attempting to link in too many shared libraries.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 82; hexadecimal 0x52; symbolic name ELIBMAX. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ELIBMAX"],"aliases":["82"]},{"id":50082,"title":"ELIBEXEC (83) - Cannot execute a shared library directly","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ELIBEXEC"],"keywords":["83","exit 83","error 83","ELIBEXEC","Cannot execute a shared library directly","Linux errno","0x53","linux","unix","bash","shell"],"errorCode":"83","eventId":"","severity":"Medium","summary":"Linux errno 83 (ELIBEXEC) means: Cannot execute a shared library directly. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ELIBEXEC because the requested operation encountered cannot execute a shared library directly. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 83 or review errno(3) to confirm ELIBEXEC on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported cannot execute a shared library directly.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 83; hexadecimal 0x53; symbolic name ELIBEXEC. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ELIBEXEC"],"aliases":["83"]},{"id":50083,"title":"EILSEQ (84) - Invalid or incomplete multibyte or wide character","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EILSEQ"],"keywords":["84","exit 84","error 84","EILSEQ","Invalid or incomplete multibyte or wide character","Linux errno","0x54","linux","unix","bash","shell"],"errorCode":"84","eventId":"","severity":"Medium","summary":"Linux errno 84 (EILSEQ) means: Invalid or incomplete multibyte or wide character. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EILSEQ because the requested operation encountered invalid or incomplete multibyte or wide character. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 84 or review errno(3) to confirm EILSEQ on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported invalid or incomplete multibyte or wide character.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 84; hexadecimal 0x54; symbolic name EILSEQ. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EILSEQ"],"aliases":["84"]},{"id":50084,"title":"ERESTART (85) - Interrupted system call should be restarted","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ERESTART"],"keywords":["85","exit 85","error 85","ERESTART","Interrupted system call should be restarted","Linux errno","0x55","linux","unix","bash","shell"],"errorCode":"85","eventId":"","severity":"Medium","summary":"Linux errno 85 (ERESTART) means: Interrupted system call should be restarted. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ERESTART because the requested operation encountered interrupted system call should be restarted. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 85 or review errno(3) to confirm ERESTART on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported interrupted system call should be restarted.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 85; hexadecimal 0x55; symbolic name ERESTART. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ERESTART"],"aliases":["85"]},{"id":50085,"title":"ESTRPIPE (86) - Streams pipe error","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ESTRPIPE"],"keywords":["86","exit 86","error 86","ESTRPIPE","Streams pipe error","Linux errno","0x56","linux","unix","bash","shell"],"errorCode":"86","eventId":"","severity":"Medium","summary":"Linux errno 86 (ESTRPIPE) means: Streams pipe error. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ESTRPIPE because the requested operation encountered streams pipe error. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 86 or review errno(3) to confirm ESTRPIPE on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported streams pipe error.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 86; hexadecimal 0x56; symbolic name ESTRPIPE. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ESTRPIPE"],"aliases":["86"]},{"id":50086,"title":"EUSERS (87) - Too many users","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EUSERS"],"keywords":["87","exit 87","error 87","EUSERS","Too many users","Linux errno","0x57","linux","unix","bash","shell"],"errorCode":"87","eventId":"","severity":"Medium","summary":"Linux errno 87 (EUSERS) means: Too many users. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EUSERS because the requested operation encountered too many users. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 87 or review errno(3) to confirm EUSERS on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported too many users.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 87; hexadecimal 0x57; symbolic name EUSERS. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EUSERS"],"aliases":["87"]},{"id":50087,"title":"ENOTSOCK (88) - Socket operation on non-socket","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOTSOCK"],"keywords":["88","exit 88","error 88","ENOTSOCK","Socket operation on non-socket","Linux errno","0x58","linux","unix","bash","shell"],"errorCode":"88","eventId":"","severity":"Medium","summary":"Linux errno 88 (ENOTSOCK) means: Socket operation on non-socket. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOTSOCK because the requested operation encountered socket operation on non-socket. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 88 or review errno(3) to confirm ENOTSOCK on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported socket operation on non-socket.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 88; hexadecimal 0x58; symbolic name ENOTSOCK. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOTSOCK"],"aliases":["88"]},{"id":50088,"title":"EDESTADDRREQ (89) - Destination address required","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EDESTADDRREQ"],"keywords":["89","exit 89","error 89","EDESTADDRREQ","Destination address required","Linux errno","0x59","linux","unix","bash","shell"],"errorCode":"89","eventId":"","severity":"Medium","summary":"Linux errno 89 (EDESTADDRREQ) means: Destination address required. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EDESTADDRREQ because the requested operation encountered destination address required. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 89 or review errno(3) to confirm EDESTADDRREQ on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported destination address required.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 89; hexadecimal 0x59; symbolic name EDESTADDRREQ. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EDESTADDRREQ"],"aliases":["89"]},{"id":50089,"title":"EMSGSIZE (90) - Message too long","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EMSGSIZE"],"keywords":["90","exit 90","error 90","EMSGSIZE","Message too long","Linux errno","0x5a","linux","unix","bash","shell"],"errorCode":"90","eventId":"","severity":"Medium","summary":"Linux errno 90 (EMSGSIZE) means: Message too long. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EMSGSIZE because the requested operation encountered message too long. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 90 or review errno(3) to confirm EMSGSIZE on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported message too long.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 90; hexadecimal 0x5a; symbolic name EMSGSIZE. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EMSGSIZE"],"aliases":["90"]},{"id":50090,"title":"EPROTOTYPE (91) - Protocol wrong type for socket","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EPROTOTYPE"],"keywords":["91","exit 91","error 91","EPROTOTYPE","Protocol wrong type for socket","Linux errno","0x5b","linux","unix","bash","shell"],"errorCode":"91","eventId":"","severity":"Medium","summary":"Linux errno 91 (EPROTOTYPE) means: Protocol wrong type for socket. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EPROTOTYPE because the requested operation encountered protocol wrong type for socket. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 91 or review errno(3) to confirm EPROTOTYPE on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported protocol wrong type for socket.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 91; hexadecimal 0x5b; symbolic name EPROTOTYPE. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EPROTOTYPE"],"aliases":["91"]},{"id":50091,"title":"ENOPROTOOPT (92) - Protocol not available","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOPROTOOPT"],"keywords":["92","exit 92","error 92","ENOPROTOOPT","Protocol not available","Linux errno","0x5c","linux","unix","bash","shell"],"errorCode":"92","eventId":"","severity":"Medium","summary":"Linux errno 92 (ENOPROTOOPT) means: Protocol not available. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOPROTOOPT because the requested operation encountered protocol not available. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 92 or review errno(3) to confirm ENOPROTOOPT on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported protocol not available.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 92; hexadecimal 0x5c; symbolic name ENOPROTOOPT. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOPROTOOPT"],"aliases":["92"]},{"id":50092,"title":"EPROTONOSUPPORT (93) - Protocol not supported","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EPROTONOSUPPORT"],"keywords":["93","exit 93","error 93","EPROTONOSUPPORT","Protocol not supported","Linux errno","0x5d","linux","unix","bash","shell"],"errorCode":"93","eventId":"","severity":"Medium","summary":"Linux errno 93 (EPROTONOSUPPORT) means: Protocol not supported. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EPROTONOSUPPORT because the requested operation encountered protocol not supported. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 93 or review errno(3) to confirm EPROTONOSUPPORT on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported protocol not supported.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 93; hexadecimal 0x5d; symbolic name EPROTONOSUPPORT. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EPROTONOSUPPORT"],"aliases":["93"]},{"id":50093,"title":"ESOCKTNOSUPPORT (94) - Socket type not supported","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ESOCKTNOSUPPORT"],"keywords":["94","exit 94","error 94","ESOCKTNOSUPPORT","Socket type not supported","Linux errno","0x5e","linux","unix","bash","shell"],"errorCode":"94","eventId":"","severity":"Medium","summary":"Linux errno 94 (ESOCKTNOSUPPORT) means: Socket type not supported. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ESOCKTNOSUPPORT because the requested operation encountered socket type not supported. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 94 or review errno(3) to confirm ESOCKTNOSUPPORT on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported socket type not supported.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 94; hexadecimal 0x5e; symbolic name ESOCKTNOSUPPORT. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ESOCKTNOSUPPORT"],"aliases":["94"]},{"id":50094,"title":"EOPNOTSUPP (95) - Operation not supported","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EOPNOTSUPP"],"keywords":["95","exit 95","error 95","EOPNOTSUPP","Operation not supported","Linux errno","0x5f","linux","unix","bash","shell"],"errorCode":"95","eventId":"","severity":"Medium","summary":"Linux errno 95 (EOPNOTSUPP) means: Operation not supported. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EOPNOTSUPP because the requested operation encountered operation not supported. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 95 or review errno(3) to confirm EOPNOTSUPP on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported operation not supported.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 95; hexadecimal 0x5f; symbolic name EOPNOTSUPP. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EOPNOTSUPP"],"aliases":["95"]},{"id":50095,"title":"ENOTSUP (95) - Operation not supported","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOTSUP"],"keywords":["95","exit 95","error 95","ENOTSUP","Operation not supported","Linux errno","0x5f","linux","unix","bash","shell"],"errorCode":"95","eventId":"","severity":"Medium","summary":"Linux errno 95 (ENOTSUP) means: Operation not supported. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOTSUP because the requested operation encountered operation not supported. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 95 or review errno(3) to confirm ENOTSUP on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported operation not supported.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 95; hexadecimal 0x5f; symbolic name ENOTSUP. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOTSUP"],"aliases":["95"]},{"id":50096,"title":"EPFNOSUPPORT (96) - Protocol family not supported","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EPFNOSUPPORT"],"keywords":["96","exit 96","error 96","EPFNOSUPPORT","Protocol family not supported","Linux errno","0x60","linux","unix","bash","shell"],"errorCode":"96","eventId":"","severity":"Medium","summary":"Linux errno 96 (EPFNOSUPPORT) means: Protocol family not supported. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EPFNOSUPPORT because the requested operation encountered protocol family not supported. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 96 or review errno(3) to confirm EPFNOSUPPORT on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported protocol family not supported.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 96; hexadecimal 0x60; symbolic name EPFNOSUPPORT. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EPFNOSUPPORT"],"aliases":["96"]},{"id":50097,"title":"EAFNOSUPPORT (97) - Address family not supported by protocol","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EAFNOSUPPORT"],"keywords":["97","exit 97","error 97","EAFNOSUPPORT","Address family not supported by protocol","Linux errno","0x61","linux","unix","bash","shell"],"errorCode":"97","eventId":"","severity":"Medium","summary":"Linux errno 97 (EAFNOSUPPORT) means: Address family not supported by protocol. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EAFNOSUPPORT because the requested operation encountered address family not supported by protocol. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 97 or review errno(3) to confirm EAFNOSUPPORT on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported address family not supported by protocol.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 97; hexadecimal 0x61; symbolic name EAFNOSUPPORT. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EAFNOSUPPORT"],"aliases":["97"]},{"id":50098,"title":"EADDRINUSE (98) - Address already in use","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EADDRINUSE"],"keywords":["98","exit 98","error 98","EADDRINUSE","Address already in use","Linux errno","0x62","linux","unix","bash","shell"],"errorCode":"98","eventId":"","severity":"Medium","summary":"Linux errno 98 (EADDRINUSE) means: Address already in use. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EADDRINUSE because the requested operation encountered address already in use. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 98 or review errno(3) to confirm EADDRINUSE on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported address already in use.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 98; hexadecimal 0x62; symbolic name EADDRINUSE. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EADDRINUSE"],"aliases":["98"]},{"id":50099,"title":"EADDRNOTAVAIL (99) - Cannot assign requested address","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EADDRNOTAVAIL"],"keywords":["99","exit 99","error 99","EADDRNOTAVAIL","Cannot assign requested address","Linux errno","0x63","linux","unix","bash","shell"],"errorCode":"99","eventId":"","severity":"Medium","summary":"Linux errno 99 (EADDRNOTAVAIL) means: Cannot assign requested address. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EADDRNOTAVAIL because the requested operation encountered cannot assign requested address. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 99 or review errno(3) to confirm EADDRNOTAVAIL on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported cannot assign requested address.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 99; hexadecimal 0x63; symbolic name EADDRNOTAVAIL. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EADDRNOTAVAIL"],"aliases":["99"]},{"id":50100,"title":"ENETDOWN (100) - Network is down","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENETDOWN"],"keywords":["100","exit 100","error 100","ENETDOWN","Network is down","Linux errno","0x64","linux","unix","bash","shell"],"errorCode":"100","eventId":"","severity":"Medium","summary":"Linux errno 100 (ENETDOWN) means: Network is down. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENETDOWN because the requested operation encountered network is down. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 100 or review errno(3) to confirm ENETDOWN on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported network is down.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 100; hexadecimal 0x64; symbolic name ENETDOWN. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENETDOWN"],"aliases":["100"]},{"id":50101,"title":"ENETUNREACH (101) - Network is unreachable","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENETUNREACH"],"keywords":["101","exit 101","error 101","ENETUNREACH","Network is unreachable","Linux errno","0x65","linux","unix","bash","shell"],"errorCode":"101","eventId":"","severity":"Medium","summary":"Linux errno 101 (ENETUNREACH) means: Network is unreachable. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENETUNREACH because the requested operation encountered network is unreachable. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 101 or review errno(3) to confirm ENETUNREACH on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported network is unreachable.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 101; hexadecimal 0x65; symbolic name ENETUNREACH. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENETUNREACH"],"aliases":["101"]},{"id":50102,"title":"ENETRESET (102) - Network dropped connection on reset","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENETRESET"],"keywords":["102","exit 102","error 102","ENETRESET","Network dropped connection on reset","Linux errno","0x66","linux","unix","bash","shell"],"errorCode":"102","eventId":"","severity":"Medium","summary":"Linux errno 102 (ENETRESET) means: Network dropped connection on reset. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENETRESET because the requested operation encountered network dropped connection on reset. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 102 or review errno(3) to confirm ENETRESET on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported network dropped connection on reset.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 102; hexadecimal 0x66; symbolic name ENETRESET. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENETRESET"],"aliases":["102"]},{"id":50103,"title":"ECONNABORTED (103) - Software caused connection abort","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ECONNABORTED"],"keywords":["103","exit 103","error 103","ECONNABORTED","Software caused connection abort","Linux errno","0x67","linux","unix","bash","shell"],"errorCode":"103","eventId":"","severity":"Medium","summary":"Linux errno 103 (ECONNABORTED) means: Software caused connection abort. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ECONNABORTED because the requested operation encountered software caused connection abort. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 103 or review errno(3) to confirm ECONNABORTED on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported software caused connection abort.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 103; hexadecimal 0x67; symbolic name ECONNABORTED. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ECONNABORTED"],"aliases":["103"]},{"id":50104,"title":"ECONNRESET (104) - Connection reset by peer","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ECONNRESET"],"keywords":["104","exit 104","error 104","ECONNRESET","Connection reset by peer","Linux errno","0x68","linux","unix","bash","shell"],"errorCode":"104","eventId":"","severity":"Medium","summary":"Linux errno 104 (ECONNRESET) means: Connection reset by peer. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ECONNRESET because the requested operation encountered connection reset by peer. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 104 or review errno(3) to confirm ECONNRESET on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported connection reset by peer.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 104; hexadecimal 0x68; symbolic name ECONNRESET. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ECONNRESET"],"aliases":["104"]},{"id":50105,"title":"ENOBUFS (105) - No buffer space available","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOBUFS"],"keywords":["105","exit 105","error 105","ENOBUFS","No buffer space available","Linux errno","0x69","linux","unix","bash","shell"],"errorCode":"105","eventId":"","severity":"Medium","summary":"Linux errno 105 (ENOBUFS) means: No buffer space available. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOBUFS because the requested operation encountered no buffer space available. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 105 or review errno(3) to confirm ENOBUFS on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported no buffer space available.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 105; hexadecimal 0x69; symbolic name ENOBUFS. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOBUFS"],"aliases":["105"]},{"id":50106,"title":"EISCONN (106) - Transport endpoint is already connected","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EISCONN"],"keywords":["106","exit 106","error 106","EISCONN","Transport endpoint is already connected","Linux errno","0x6a","linux","unix","bash","shell"],"errorCode":"106","eventId":"","severity":"Medium","summary":"Linux errno 106 (EISCONN) means: Transport endpoint is already connected. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EISCONN because the requested operation encountered transport endpoint is already connected. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 106 or review errno(3) to confirm EISCONN on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported transport endpoint is already connected.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 106; hexadecimal 0x6a; symbolic name EISCONN. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EISCONN"],"aliases":["106"]},{"id":50107,"title":"ENOTCONN (107) - Transport endpoint is not connected","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOTCONN"],"keywords":["107","exit 107","error 107","ENOTCONN","Transport endpoint is not connected","Linux errno","0x6b","linux","unix","bash","shell"],"errorCode":"107","eventId":"","severity":"Medium","summary":"Linux errno 107 (ENOTCONN) means: Transport endpoint is not connected. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOTCONN because the requested operation encountered transport endpoint is not connected. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 107 or review errno(3) to confirm ENOTCONN on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported transport endpoint is not connected.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 107; hexadecimal 0x6b; symbolic name ENOTCONN. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOTCONN"],"aliases":["107"]},{"id":50108,"title":"ESHUTDOWN (108) - Cannot send after transport endpoint shutdown","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ESHUTDOWN"],"keywords":["108","exit 108","error 108","ESHUTDOWN","Cannot send after transport endpoint shutdown","Linux errno","0x6c","linux","unix","bash","shell"],"errorCode":"108","eventId":"","severity":"Medium","summary":"Linux errno 108 (ESHUTDOWN) means: Cannot send after transport endpoint shutdown. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ESHUTDOWN because the requested operation encountered cannot send after transport endpoint shutdown. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 108 or review errno(3) to confirm ESHUTDOWN on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported cannot send after transport endpoint shutdown.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 108; hexadecimal 0x6c; symbolic name ESHUTDOWN. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ESHUTDOWN"],"aliases":["108"]},{"id":50109,"title":"ETOOMANYREFS (109) - Too many references: cannot splice","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ETOOMANYREFS"],"keywords":["109","exit 109","error 109","ETOOMANYREFS","Too many references: cannot splice","Linux errno","0x6d","linux","unix","bash","shell"],"errorCode":"109","eventId":"","severity":"Medium","summary":"Linux errno 109 (ETOOMANYREFS) means: Too many references: cannot splice. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ETOOMANYREFS because the requested operation encountered too many references: cannot splice. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 109 or review errno(3) to confirm ETOOMANYREFS on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported too many references: cannot splice.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 109; hexadecimal 0x6d; symbolic name ETOOMANYREFS. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ETOOMANYREFS"],"aliases":["109"]},{"id":50110,"title":"ETIMEDOUT (110) - Connection timed out","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ETIMEDOUT"],"keywords":["110","exit 110","error 110","ETIMEDOUT","Connection timed out","Linux errno","0x6e","linux","unix","bash","shell"],"errorCode":"110","eventId":"","severity":"Medium","summary":"Linux errno 110 (ETIMEDOUT) means: Connection timed out. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ETIMEDOUT because the requested operation encountered connection timed out. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 110 or review errno(3) to confirm ETIMEDOUT on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported connection timed out.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 110; hexadecimal 0x6e; symbolic name ETIMEDOUT. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ETIMEDOUT"],"aliases":["110"]},{"id":50111,"title":"ECONNREFUSED (111) - Connection refused","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ECONNREFUSED"],"keywords":["111","exit 111","error 111","ECONNREFUSED","Connection refused","Linux errno","0x6f","linux","unix","bash","shell"],"errorCode":"111","eventId":"","severity":"Medium","summary":"Linux errno 111 (ECONNREFUSED) means: Connection refused. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ECONNREFUSED because the requested operation encountered connection refused. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 111 or review errno(3) to confirm ECONNREFUSED on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported connection refused.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 111; hexadecimal 0x6f; symbolic name ECONNREFUSED. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ECONNREFUSED"],"aliases":["111"]},{"id":50112,"title":"EHOSTDOWN (112) - Host is down","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EHOSTDOWN"],"keywords":["112","exit 112","error 112","EHOSTDOWN","Host is down","Linux errno","0x70","linux","unix","bash","shell"],"errorCode":"112","eventId":"","severity":"Medium","summary":"Linux errno 112 (EHOSTDOWN) means: Host is down. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EHOSTDOWN because the requested operation encountered host is down. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 112 or review errno(3) to confirm EHOSTDOWN on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported host is down.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 112; hexadecimal 0x70; symbolic name EHOSTDOWN. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EHOSTDOWN"],"aliases":["112"]},{"id":50113,"title":"EHOSTUNREACH (113) - No route to host","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EHOSTUNREACH"],"keywords":["113","exit 113","error 113","EHOSTUNREACH","No route to host","Linux errno","0x71","linux","unix","bash","shell"],"errorCode":"113","eventId":"","severity":"Medium","summary":"Linux errno 113 (EHOSTUNREACH) means: No route to host. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EHOSTUNREACH because the requested operation encountered no route to host. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 113 or review errno(3) to confirm EHOSTUNREACH on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported no route to host.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 113; hexadecimal 0x71; symbolic name EHOSTUNREACH. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EHOSTUNREACH"],"aliases":["113"]},{"id":50114,"title":"EALREADY (114) - Operation already in progress","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EALREADY"],"keywords":["114","exit 114","error 114","EALREADY","Operation already in progress","Linux errno","0x72","linux","unix","bash","shell"],"errorCode":"114","eventId":"","severity":"Medium","summary":"Linux errno 114 (EALREADY) means: Operation already in progress. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EALREADY because the requested operation encountered operation already in progress. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 114 or review errno(3) to confirm EALREADY on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported operation already in progress.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 114; hexadecimal 0x72; symbolic name EALREADY. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EALREADY"],"aliases":["114"]},{"id":50115,"title":"EINPROGRESS (115) - Operation now in progress","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EINPROGRESS"],"keywords":["115","exit 115","error 115","EINPROGRESS","Operation now in progress","Linux errno","0x73","linux","unix","bash","shell"],"errorCode":"115","eventId":"","severity":"Medium","summary":"Linux errno 115 (EINPROGRESS) means: Operation now in progress. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EINPROGRESS because the requested operation encountered operation now in progress. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 115 or review errno(3) to confirm EINPROGRESS on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported operation now in progress.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 115; hexadecimal 0x73; symbolic name EINPROGRESS. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EINPROGRESS"],"aliases":["115"]},{"id":50116,"title":"ESTALE (116) - Stale file handle","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ESTALE"],"keywords":["116","exit 116","error 116","ESTALE","Stale file handle","Linux errno","0x74","linux","unix","bash","shell"],"errorCode":"116","eventId":"","severity":"Medium","summary":"Linux errno 116 (ESTALE) means: Stale file handle. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ESTALE because the requested operation encountered stale file handle. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 116 or review errno(3) to confirm ESTALE on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported stale file handle.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 116; hexadecimal 0x74; symbolic name ESTALE. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ESTALE"],"aliases":["116"]},{"id":50117,"title":"EUCLEAN (117) - Structure needs cleaning","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EUCLEAN"],"keywords":["117","exit 117","error 117","EUCLEAN","Structure needs cleaning","Linux errno","0x75","linux","unix","bash","shell"],"errorCode":"117","eventId":"","severity":"Medium","summary":"Linux errno 117 (EUCLEAN) means: Structure needs cleaning. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EUCLEAN because the requested operation encountered structure needs cleaning. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 117 or review errno(3) to confirm EUCLEAN on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported structure needs cleaning.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 117; hexadecimal 0x75; symbolic name EUCLEAN. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EUCLEAN"],"aliases":["117"]},{"id":50118,"title":"ENOTNAM (118) - Not a XENIX named type file","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOTNAM"],"keywords":["118","exit 118","error 118","ENOTNAM","Not a XENIX named type file","Linux errno","0x76","linux","unix","bash","shell"],"errorCode":"118","eventId":"","severity":"Medium","summary":"Linux errno 118 (ENOTNAM) means: Not a XENIX named type file. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOTNAM because the requested operation encountered not a xenix named type file. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 118 or review errno(3) to confirm ENOTNAM on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported not a xenix named type file.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 118; hexadecimal 0x76; symbolic name ENOTNAM. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOTNAM"],"aliases":["118"]},{"id":50119,"title":"ENAVAIL (119) - No XENIX semaphores available","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENAVAIL"],"keywords":["119","exit 119","error 119","ENAVAIL","No XENIX semaphores available","Linux errno","0x77","linux","unix","bash","shell"],"errorCode":"119","eventId":"","severity":"Medium","summary":"Linux errno 119 (ENAVAIL) means: No XENIX semaphores available. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENAVAIL because the requested operation encountered no xenix semaphores available. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 119 or review errno(3) to confirm ENAVAIL on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported no xenix semaphores available.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 119; hexadecimal 0x77; symbolic name ENAVAIL. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENAVAIL"],"aliases":["119"]},{"id":50120,"title":"EISNAM (120) - Is a named type file","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EISNAM"],"keywords":["120","exit 120","error 120","EISNAM","Is a named type file","Linux errno","0x78","linux","unix","bash","shell"],"errorCode":"120","eventId":"","severity":"Medium","summary":"Linux errno 120 (EISNAM) means: Is a named type file. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EISNAM because the requested operation encountered is a named type file. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 120 or review errno(3) to confirm EISNAM on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported is a named type file.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 120; hexadecimal 0x78; symbolic name EISNAM. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EISNAM"],"aliases":["120"]},{"id":50121,"title":"EREMOTEIO (121) - Remote I/O error","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EREMOTEIO"],"keywords":["121","exit 121","error 121","EREMOTEIO","Remote I/O error","Linux errno","0x79","linux","unix","bash","shell"],"errorCode":"121","eventId":"","severity":"Medium","summary":"Linux errno 121 (EREMOTEIO) means: Remote I/O error. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EREMOTEIO because the requested operation encountered remote i/o error. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 121 or review errno(3) to confirm EREMOTEIO on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported remote i/o error.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 121; hexadecimal 0x79; symbolic name EREMOTEIO. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EREMOTEIO"],"aliases":["121"]},{"id":50122,"title":"EDQUOT (122) - Disk quota exceeded","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EDQUOT"],"keywords":["122","exit 122","error 122","EDQUOT","Disk quota exceeded","Linux errno","0x7a","linux","unix","bash","shell"],"errorCode":"122","eventId":"","severity":"Medium","summary":"Linux errno 122 (EDQUOT) means: Disk quota exceeded. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EDQUOT because the requested operation encountered disk quota exceeded. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 122 or review errno(3) to confirm EDQUOT on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported disk quota exceeded.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 122; hexadecimal 0x7a; symbolic name EDQUOT. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EDQUOT"],"aliases":["122"]},{"id":50123,"title":"ENOMEDIUM (123) - No medium found","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOMEDIUM"],"keywords":["123","exit 123","error 123","ENOMEDIUM","No medium found","Linux errno","0x7b","linux","unix","bash","shell"],"errorCode":"123","eventId":"","severity":"Medium","summary":"Linux errno 123 (ENOMEDIUM) means: No medium found. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOMEDIUM because the requested operation encountered no medium found. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 123 or review errno(3) to confirm ENOMEDIUM on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported no medium found.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 123; hexadecimal 0x7b; symbolic name ENOMEDIUM. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOMEDIUM"],"aliases":["123"]},{"id":50124,"title":"EMEDIUMTYPE (124) - Wrong medium type","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EMEDIUMTYPE"],"keywords":["124","exit 124","error 124","EMEDIUMTYPE","Wrong medium type","Linux errno","0x7c","linux","unix","bash","shell"],"errorCode":"124","eventId":"","severity":"Medium","summary":"Linux errno 124 (EMEDIUMTYPE) means: Wrong medium type. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EMEDIUMTYPE because the requested operation encountered wrong medium type. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 124 or review errno(3) to confirm EMEDIUMTYPE on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported wrong medium type.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 124; hexadecimal 0x7c; symbolic name EMEDIUMTYPE. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EMEDIUMTYPE"],"aliases":["124"]},{"id":50125,"title":"ECANCELED (125) - Operation canceled","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ECANCELED"],"keywords":["125","exit 125","error 125","ECANCELED","Operation canceled","Linux errno","0x7d","linux","unix","bash","shell"],"errorCode":"125","eventId":"","severity":"Medium","summary":"Linux errno 125 (ECANCELED) means: Operation canceled. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ECANCELED because the requested operation encountered operation canceled. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 125 or review errno(3) to confirm ECANCELED on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported operation canceled.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 125; hexadecimal 0x7d; symbolic name ECANCELED. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ECANCELED"],"aliases":["125"]},{"id":50126,"title":"ENOKEY (126) - Required key not available","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOKEY"],"keywords":["126","exit 126","error 126","ENOKEY","Required key not available","Linux errno","0x7e","linux","unix","bash","shell"],"errorCode":"126","eventId":"","severity":"Medium","summary":"Linux errno 126 (ENOKEY) means: Required key not available. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOKEY because the requested operation encountered required key not available. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 126 or review errno(3) to confirm ENOKEY on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported required key not available.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 126; hexadecimal 0x7e; symbolic name ENOKEY. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOKEY"],"aliases":["126"]},{"id":50127,"title":"EKEYEXPIRED (127) - Key has expired","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EKEYEXPIRED"],"keywords":["127","exit 127","error 127","EKEYEXPIRED","Key has expired","Linux errno","0x7f","linux","unix","bash","shell"],"errorCode":"127","eventId":"","severity":"Medium","summary":"Linux errno 127 (EKEYEXPIRED) means: Key has expired. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EKEYEXPIRED because the requested operation encountered key has expired. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 127 or review errno(3) to confirm EKEYEXPIRED on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported key has expired.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 127; hexadecimal 0x7f; symbolic name EKEYEXPIRED. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EKEYEXPIRED"],"aliases":["127"]},{"id":50128,"title":"EKEYREVOKED (128) - Key has been revoked","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EKEYREVOKED"],"keywords":["128","exit 128","error 128","EKEYREVOKED","Key has been revoked","Linux errno","0x80","linux","unix","bash","shell"],"errorCode":"128","eventId":"","severity":"Medium","summary":"Linux errno 128 (EKEYREVOKED) means: Key has been revoked. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EKEYREVOKED because the requested operation encountered key has been revoked. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 128 or review errno(3) to confirm EKEYREVOKED on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported key has been revoked.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 128; hexadecimal 0x80; symbolic name EKEYREVOKED. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EKEYREVOKED"],"aliases":["128"]},{"id":50129,"title":"EKEYREJECTED (129) - Key was rejected by service","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EKEYREJECTED"],"keywords":["129","exit 129","error 129","EKEYREJECTED","Key was rejected by service","Linux errno","0x81","linux","unix","bash","shell"],"errorCode":"129","eventId":"","severity":"Medium","summary":"Linux errno 129 (EKEYREJECTED) means: Key was rejected by service. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EKEYREJECTED because the requested operation encountered key was rejected by service. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 129 or review errno(3) to confirm EKEYREJECTED on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported key was rejected by service.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 129; hexadecimal 0x81; symbolic name EKEYREJECTED. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EKEYREJECTED"],"aliases":["129"]},{"id":50130,"title":"EOWNERDEAD (130) - Owner died","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EOWNERDEAD"],"keywords":["130","exit 130","error 130","EOWNERDEAD","Owner died","Linux errno","0x82","linux","unix","bash","shell"],"errorCode":"130","eventId":"","severity":"Medium","summary":"Linux errno 130 (EOWNERDEAD) means: Owner died. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EOWNERDEAD because the requested operation encountered owner died. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 130 or review errno(3) to confirm EOWNERDEAD on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported owner died.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 130; hexadecimal 0x82; symbolic name EOWNERDEAD. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EOWNERDEAD"],"aliases":["130"]},{"id":50131,"title":"ENOTRECOVERABLE (131) - State not recoverable","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ENOTRECOVERABLE"],"keywords":["131","exit 131","error 131","ENOTRECOVERABLE","State not recoverable","Linux errno","0x83","linux","unix","bash","shell"],"errorCode":"131","eventId":"","severity":"Medium","summary":"Linux errno 131 (ENOTRECOVERABLE) means: State not recoverable. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ENOTRECOVERABLE because the requested operation encountered state not recoverable. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 131 or review errno(3) to confirm ENOTRECOVERABLE on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported state not recoverable.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 131; hexadecimal 0x83; symbolic name ENOTRECOVERABLE. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ENOTRECOVERABLE"],"aliases":["131"]},{"id":50132,"title":"ERFKILL (132) - Operation not possible due to RF-kill","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","ERFKILL"],"keywords":["132","exit 132","error 132","ERFKILL","Operation not possible due to RF-kill","Linux errno","0x84","linux","unix","bash","shell"],"errorCode":"132","eventId":"","severity":"Medium","summary":"Linux errno 132 (ERFKILL) means: Operation not possible due to RF-kill. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with ERFKILL because the requested operation encountered operation not possible due to rf-kill. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 132 or review errno(3) to confirm ERFKILL on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported operation not possible due to rf-kill.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 132; hexadecimal 0x84; symbolic name ERFKILL. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","ERFKILL"],"aliases":["132"]},{"id":50133,"title":"EHWPOISON (133) - Memory page has hardware error","category":"Linux","product":"Linux / POSIX","tags":["Linux errno","errno","EHWPOISON"],"keywords":["133","exit 133","error 133","EHWPOISON","Memory page has hardware error","Linux errno","0x85","linux","unix","bash","shell"],"errorCode":"133","eventId":"","severity":"High","summary":"Linux errno 133 (EHWPOISON) means: Memory page has hardware error. The number-to-symbol mapping is common on x86 and ARM Linux but should be confirmed for the target ABI.","rootCause":"A system or library call failed with EHWPOISON because the requested operation encountered memory page has hardware error. The calling program and surrounding logs identify the exact resource or operation.","resolution":"1. Capture the failing command, system call, timestamp, and complete error text.\n2. Run errno 133 or review errno(3) to confirm EHWPOISON on the target system.\n3. Check the affected path, permissions, process, resource, device, or network state.\n4. Correct the confirmed cause and retry the operation.\n5. Verify the command returns exit status 0 and review relevant logs.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported memory page has hardware error.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux errno. Decimal 133; hexadecimal 0x85; symbolic name EHWPOISON. Verify mappings with errno(3), strerror(3), or the errno utility.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux"],"technologies":["Linux errno","errno","EHWPOISON"],"aliases":["133"]},{"id":50200,"title":"Success (0) - Command completed successfully","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Success"],"keywords":["0","exit 0","error 0","Success","Command completed successfully","Linux shell exit","linux","unix","bash","shell"],"errorCode":"0","eventId":"","severity":"Low","summary":"Shell exit status 0 indicates: Command completed successfully. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 0 after encountering command completed successfully. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported command completed successfully.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Success"],"aliases":["0"]},{"id":50201,"title":"General (1) - Unspecified command or application failure","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","General"],"keywords":["1","exit 1","error 1","General","Unspecified command or application failure","Linux shell exit","linux","unix","bash","shell"],"errorCode":"1","eventId":"","severity":"Medium","summary":"Shell exit status 1 indicates: Unspecified command or application failure. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 1 after encountering unspecified command or application failure. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported unspecified command or application failure.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","General"],"aliases":["1"]},{"id":50202,"title":"Misuse (2) - Shell syntax or builtin usage error","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Misuse"],"keywords":["2","exit 2","error 2","Misuse","Shell syntax or builtin usage error","Linux shell exit","linux","unix","bash","shell"],"errorCode":"2","eventId":"","severity":"Medium","summary":"Shell exit status 2 indicates: Shell syntax or builtin usage error. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 2 after encountering shell syntax or builtin usage error. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported shell syntax or builtin usage error.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Misuse"],"aliases":["2"]},{"id":50203,"title":"Command (64) - Incorrect command syntax or arguments","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Command"],"keywords":["64","exit 64","error 64","Command","Incorrect command syntax or arguments","Linux shell exit","linux","unix","bash","shell"],"errorCode":"64","eventId":"","severity":"Medium","summary":"Shell exit status 64 indicates: Incorrect command syntax or arguments. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 64 after encountering incorrect command syntax or arguments. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported incorrect command syntax or arguments.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Command"],"aliases":["64"]},{"id":50204,"title":"Data (65) - Input data is malformed","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Data"],"keywords":["65","exit 65","error 65","Data","Input data is malformed","Linux shell exit","linux","unix","bash","shell"],"errorCode":"65","eventId":"","severity":"Medium","summary":"Shell exit status 65 indicates: Input data is malformed. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 65 after encountering input data is malformed. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported input data is malformed.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Data"],"aliases":["65"]},{"id":50205,"title":"Cannot (66) - Input file is missing or unreadable","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Cannot"],"keywords":["66","exit 66","error 66","Cannot","Input file is missing or unreadable","Linux shell exit","linux","unix","bash","shell"],"errorCode":"66","eventId":"","severity":"Medium","summary":"Shell exit status 66 indicates: Input file is missing or unreadable. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 66 after encountering input file is missing or unreadable. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported input file is missing or unreadable.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Cannot"],"aliases":["66"]},{"id":50206,"title":"Addressee (67) - Requested user or entity was not found","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Addressee"],"keywords":["67","exit 67","error 67","Addressee","Requested user or entity was not found","Linux shell exit","linux","unix","bash","shell"],"errorCode":"67","eventId":"","severity":"Medium","summary":"Shell exit status 67 indicates: Requested user or entity was not found. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 67 after encountering requested user or entity was not found. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported requested user or entity was not found.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Addressee"],"aliases":["67"]},{"id":50207,"title":"Hostname (68) - Network host could not be resolved or reached","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Hostname"],"keywords":["68","exit 68","error 68","Hostname","Network host could not be resolved or reached","Linux shell exit","linux","unix","bash","shell"],"errorCode":"68","eventId":"","severity":"Medium","summary":"Shell exit status 68 indicates: Network host could not be resolved or reached. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 68 after encountering network host could not be resolved or reached. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported network host could not be resolved or reached.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Hostname"],"aliases":["68"]},{"id":50208,"title":"Service (69) - Required service is offline or unavailable","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Service"],"keywords":["69","exit 69","error 69","Service","Required service is offline or unavailable","Linux shell exit","linux","unix","bash","shell"],"errorCode":"69","eventId":"","severity":"Medium","summary":"Shell exit status 69 indicates: Required service is offline or unavailable. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 69 after encountering required service is offline or unavailable. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported required service is offline or unavailable.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Service"],"aliases":["69"]},{"id":50209,"title":"Internal (70) - Application detected an internal failure","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Internal"],"keywords":["70","exit 70","error 70","Internal","Application detected an internal failure","Linux shell exit","linux","unix","bash","shell"],"errorCode":"70","eventId":"","severity":"Medium","summary":"Shell exit status 70 indicates: Application detected an internal failure. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 70 after encountering application detected an internal failure. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported application detected an internal failure.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Internal"],"aliases":["70"]},{"id":50210,"title":"System (71) - Operating-system or kernel-level failure","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","System"],"keywords":["71","exit 71","error 71","System","Operating-system or kernel-level failure","Linux shell exit","linux","unix","bash","shell"],"errorCode":"71","eventId":"","severity":"High","summary":"Shell exit status 71 indicates: Operating-system or kernel-level failure. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 71 after encountering operating-system or kernel-level failure. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported operating-system or kernel-level failure.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","System"],"aliases":["71"]},{"id":50211,"title":"Critical (72) - A required operating-system file is absent","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Critical"],"keywords":["72","exit 72","error 72","Critical","A required operating-system file is absent","Linux shell exit","linux","unix","bash","shell"],"errorCode":"72","eventId":"","severity":"Medium","summary":"Shell exit status 72 indicates: A required operating-system file is absent. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 72 after encountering a required operating-system file is absent. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported a required operating-system file is absent.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Critical"],"aliases":["72"]},{"id":50212,"title":"Cannot (73) - Permission or storage prevents output creation","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Cannot"],"keywords":["73","exit 73","error 73","Cannot","Permission or storage prevents output creation","Linux shell exit","linux","unix","bash","shell"],"errorCode":"73","eventId":"","severity":"Medium","summary":"Shell exit status 73 indicates: Permission or storage prevents output creation. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 73 after encountering permission or storage prevents output creation. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported permission or storage prevents output creation.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Cannot"],"aliases":["73"]},{"id":50213,"title":"I/O (74) - Disk or network read/write failure","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","I/O"],"keywords":["74","exit 74","error 74","I/O","Disk or network read/write failure","Linux shell exit","linux","unix","bash","shell"],"errorCode":"74","eventId":"","severity":"Medium","summary":"Shell exit status 74 indicates: Disk or network read/write failure. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 74 after encountering disk or network read/write failure. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported disk or network read/write failure.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","I/O"],"aliases":["74"]},{"id":50214,"title":"Temporary (75) - Recoverable condition; retry may succeed","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Temporary"],"keywords":["75","exit 75","error 75","Temporary","Recoverable condition; retry may succeed","Linux shell exit","linux","unix","bash","shell"],"errorCode":"75","eventId":"","severity":"Medium","summary":"Shell exit status 75 indicates: Recoverable condition; retry may succeed. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 75 after encountering recoverable condition; retry may succeed. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported recoverable condition; retry may succeed.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Temporary"],"aliases":["75"]},{"id":50215,"title":"Remote (76) - Remote systems disagree on protocol","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Remote"],"keywords":["76","exit 76","error 76","Remote","Remote systems disagree on protocol","Linux shell exit","linux","unix","bash","shell"],"errorCode":"76","eventId":"","severity":"Medium","summary":"Shell exit status 76 indicates: Remote systems disagree on protocol. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 76 after encountering remote systems disagree on protocol. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported remote systems disagree on protocol.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Remote"],"aliases":["76"]},{"id":50216,"title":"Permission (77) - User lacks required permissions","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Permission"],"keywords":["77","exit 77","error 77","Permission","User lacks required permissions","Linux shell exit","linux","unix","bash","shell"],"errorCode":"77","eventId":"","severity":"Medium","summary":"Shell exit status 77 indicates: User lacks required permissions. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 77 after encountering user lacks required permissions. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported user lacks required permissions.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Permission"],"aliases":["77"]},{"id":50217,"title":"Configuration (78) - Configuration is invalid","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Configuration"],"keywords":["78","exit 78","error 78","Configuration","Configuration is invalid","Linux shell exit","linux","unix","bash","shell"],"errorCode":"78","eventId":"","severity":"Medium","summary":"Shell exit status 78 indicates: Configuration is invalid. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 78 after encountering configuration is invalid. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported configuration is invalid.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Configuration"],"aliases":["78"]},{"id":50218,"title":"Permission (79) - Application-specific permission failure","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Permission"],"keywords":["79","exit 79","error 79","Permission","Application-specific permission failure","Linux shell exit","linux","unix","bash","shell"],"errorCode":"79","eventId":"","severity":"Medium","summary":"Shell exit status 79 indicates: Application-specific permission failure. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 79 after encountering application-specific permission failure. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported application-specific permission failure.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Permission"],"aliases":["79"]},{"id":50219,"title":"Remote (100) - Application-specific remote host failure","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Remote"],"keywords":["100","exit 100","error 100","Remote","Application-specific remote host failure","Linux shell exit","linux","unix","bash","shell"],"errorCode":"100","eventId":"","severity":"Medium","summary":"Shell exit status 100 indicates: Application-specific remote host failure. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 100 after encountering application-specific remote host failure. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported application-specific remote host failure.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Remote"],"aliases":["100"]},{"id":50220,"title":"Capabilities (101) - Required Linux capability is missing","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Capabilities"],"keywords":["101","exit 101","error 101","Capabilities","Required Linux capability is missing","Linux shell exit","linux","unix","bash","shell"],"errorCode":"101","eventId":"","severity":"Medium","summary":"Shell exit status 101 indicates: Required Linux capability is missing. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 101 after encountering required linux capability is missing. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported required linux capability is missing.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Capabilities"],"aliases":["101"]},{"id":50221,"title":"Filesystem (102) - Mount, disk, or read-only filesystem problem","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Filesystem"],"keywords":["102","exit 102","error 102","Filesystem","Mount, disk, or read-only filesystem problem","Linux shell exit","linux","unix","bash","shell"],"errorCode":"102","eventId":"","severity":"Medium","summary":"Shell exit status 102 indicates: Mount, disk, or read-only filesystem problem. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 102 after encountering mount, disk, or read-only filesystem problem. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported mount, disk, or read-only filesystem problem.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Filesystem"],"aliases":["102"]},{"id":50222,"title":"Service (108) - Daemon failed to start or respond","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Service"],"keywords":["108","exit 108","error 108","Service","Daemon failed to start or respond","Linux shell exit","linux","unix","bash","shell"],"errorCode":"108","eventId":"","severity":"Medium","summary":"Shell exit status 108 indicates: Daemon failed to start or respond. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 108 after encountering daemon failed to start or respond. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported daemon failed to start or respond.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Service"],"aliases":["108"]},{"id":50223,"title":"Temporary (109) - Application-specific retryable failure","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Temporary"],"keywords":["109","exit 109","error 109","Temporary","Application-specific retryable failure","Linux shell exit","linux","unix","bash","shell"],"errorCode":"109","eventId":"","severity":"Medium","summary":"Shell exit status 109 indicates: Application-specific retryable failure. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 109 after encountering application-specific retryable failure. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported application-specific retryable failure.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Temporary"],"aliases":["109"]},{"id":50224,"title":"Timeout (124) - GNU timeout reports that the command exceeded its limit","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Timeout"],"keywords":["124","exit 124","error 124","Timeout","GNU timeout reports that the command exceeded its limit","Linux shell exit","linux","unix","bash","shell"],"errorCode":"124","eventId":"","severity":"Medium","summary":"Shell exit status 124 indicates: GNU timeout reports that the command exceeded its limit. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 124 after encountering gnu timeout reports that the command exceeded its limit. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported gnu timeout reports that the command exceeded its limit.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Timeout"],"aliases":["124"]},{"id":50225,"title":"Partial (125) - Tool reported mixed results or partial failure","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Partial"],"keywords":["125","exit 125","error 125","Partial","Tool reported mixed results or partial failure","Linux shell exit","linux","unix","bash","shell"],"errorCode":"125","eventId":"","severity":"Medium","summary":"Shell exit status 125 indicates: Tool reported mixed results or partial failure. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 125 after encountering tool reported mixed results or partial failure. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported tool reported mixed results or partial failure.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Partial"],"aliases":["125"]},{"id":50226,"title":"Command (126) - Command exists but cannot be executed","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Command"],"keywords":["126","exit 126","error 126","Command","Command exists but cannot be executed","Linux shell exit","linux","unix","bash","shell"],"errorCode":"126","eventId":"","severity":"Medium","summary":"Shell exit status 126 indicates: Command exists but cannot be executed. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 126 after encountering command exists but cannot be executed. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported command exists but cannot be executed.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Command"],"aliases":["126"]},{"id":50227,"title":"Command (127) - Shell could not locate the command in PATH","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Command"],"keywords":["127","exit 127","error 127","Command","Shell could not locate the command in PATH","Linux shell exit","linux","unix","bash","shell"],"errorCode":"127","eventId":"","severity":"Medium","summary":"Shell exit status 127 indicates: Shell could not locate the command in PATH. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 127 after encountering shell could not locate the command in path. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported shell could not locate the command in path.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Command"],"aliases":["127"]},{"id":50228,"title":"Invalid (128) - Invalid value was passed to exit","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Invalid"],"keywords":["128","exit 128","error 128","Invalid","Invalid value was passed to exit","Linux shell exit","linux","unix","bash","shell"],"errorCode":"128","eventId":"","severity":"Medium","summary":"Shell exit status 128 indicates: Invalid value was passed to exit. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 128 after encountering invalid value was passed to exit. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported invalid value was passed to exit.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Invalid"],"aliases":["128"]},{"id":50229,"title":"Success (200) - Custom application-specific status","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Success"],"keywords":["200","exit 200","error 200","Success","Custom application-specific status","Linux shell exit","linux","unix","bash","shell"],"errorCode":"200","eventId":"","severity":"Medium","summary":"Shell exit status 200 indicates: Custom application-specific status. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 200 after encountering custom application-specific status. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported custom application-specific status.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Success"],"aliases":["200"]},{"id":50230,"title":"Runtime (201) - Custom status used by some compute environments","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Runtime"],"keywords":["201","exit 201","error 201","Runtime","Custom status used by some compute environments","Linux shell exit","linux","unix","bash","shell"],"errorCode":"201","eventId":"","severity":"Medium","summary":"Shell exit status 201 indicates: Custom status used by some compute environments. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 201 after encountering custom status used by some compute environments. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported custom status used by some compute environments.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Runtime"],"aliases":["201"]},{"id":50231,"title":"External (202) - Custom CI/CD or application status","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","External"],"keywords":["202","exit 202","error 202","External","Custom CI/CD or application status","Linux shell exit","linux","unix","bash","shell"],"errorCode":"202","eventId":"","severity":"Medium","summary":"Shell exit status 202 indicates: Custom CI/CD or application status. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 202 after encountering custom ci/cd or application status. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported custom ci/cd or application status.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","External"],"aliases":["202"]},{"id":50232,"title":"Checksum (203) - Custom package or deployment status","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Checksum"],"keywords":["203","exit 203","error 203","Checksum","Custom package or deployment status","Linux shell exit","linux","unix","bash","shell"],"errorCode":"203","eventId":"","severity":"Medium","summary":"Shell exit status 203 indicates: Custom package or deployment status. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 203 after encountering custom package or deployment status. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported custom package or deployment status.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Checksum"],"aliases":["203"]},{"id":50233,"title":"Graceful (250) - Custom daemon status","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Graceful"],"keywords":["250","exit 250","error 250","Graceful","Custom daemon status","Linux shell exit","linux","unix","bash","shell"],"errorCode":"250","eventId":"","severity":"Medium","summary":"Shell exit status 250 indicates: Custom daemon status. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 250 after encountering custom daemon status. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported custom daemon status.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Graceful"],"aliases":["250"]},{"id":50234,"title":"Dry (253) - Custom deployment-tool status","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Dry"],"keywords":["253","exit 253","error 253","Dry","Custom deployment-tool status","Linux shell exit","linux","unix","bash","shell"],"errorCode":"253","eventId":"","severity":"Medium","summary":"Shell exit status 253 indicates: Custom deployment-tool status. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 253 after encountering custom deployment-tool status. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported custom deployment-tool status.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Dry"],"aliases":["253"]},{"id":50235,"title":"Not (254) - Custom pre-check status","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Not"],"keywords":["254","exit 254","error 254","Not","Custom pre-check status","Linux shell exit","linux","unix","bash","shell"],"errorCode":"254","eventId":"","severity":"Medium","summary":"Shell exit status 254 indicates: Custom pre-check status. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 254 after encountering custom pre-check status. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported custom pre-check status.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Not"],"aliases":["254"]},{"id":50236,"title":"Exit (255) - Exit value overflowed or is reserved","category":"Linux","product":"Linux Shell","tags":["Linux shell exit","Exit Status","Exit"],"keywords":["255","exit 255","error 255","Exit","Exit value overflowed or is reserved","Linux shell exit","linux","unix","bash","shell"],"errorCode":"255","eventId":"","severity":"Medium","summary":"Shell exit status 255 indicates: Exit value overflowed or is reserved. Exit meanings can be application-specific, so confirm the command's documentation.","rootCause":"The command returned 255 after encountering exit value overflowed or is reserved. Codes outside widely standardized shell values may be defined by the individual tool.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported exit value overflowed or is reserved.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux shell exit. Application-specific exit codes must be verified against the tool's documentation.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Shell"],"technologies":["Linux shell exit","Exit Status","Exit"],"aliases":["255"]},{"id":50300,"title":"SIGHUP (129) - Terminal hung up","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGHUP"],"keywords":["129","exit 129","error 129","SIGHUP","Terminal hung up","Linux signal exit","linux","unix","bash","shell"],"errorCode":"129","eventId":"","severity":"Medium","summary":"Shell exit status 129 usually indicates SIGHUP: Terminal hung up. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGHUP. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported terminal hung up.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGHUP"],"aliases":["129"]},{"id":50301,"title":"SIGINT (130) - Interrupted from the terminal, commonly Ctrl+C","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGINT"],"keywords":["130","exit 130","error 130","SIGINT","Interrupted from the terminal, commonly Ctrl+C","Linux signal exit","linux","unix","bash","shell"],"errorCode":"130","eventId":"","severity":"Medium","summary":"Shell exit status 130 usually indicates SIGINT: Interrupted from the terminal, commonly Ctrl+C. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGINT. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported interrupted from the terminal, commonly ctrl+c.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGINT"],"aliases":["130"]},{"id":50302,"title":"SIGQUIT (131) - Quit and optionally produced a core dump","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGQUIT"],"keywords":["131","exit 131","error 131","SIGQUIT","Quit and optionally produced a core dump","Linux signal exit","linux","unix","bash","shell"],"errorCode":"131","eventId":"","severity":"Medium","summary":"Shell exit status 131 usually indicates SIGQUIT: Quit and optionally produced a core dump. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGQUIT. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported quit and optionally produced a core dump.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGQUIT"],"aliases":["131"]},{"id":50303,"title":"SIGILL (132) - Illegal instruction","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGILL"],"keywords":["132","exit 132","error 132","SIGILL","Illegal instruction","Linux signal exit","linux","unix","bash","shell"],"errorCode":"132","eventId":"","severity":"Medium","summary":"Shell exit status 132 usually indicates SIGILL: Illegal instruction. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGILL. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported illegal instruction.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGILL"],"aliases":["132"]},{"id":50304,"title":"SIGTRAP (133) - Trace or breakpoint trap","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGTRAP"],"keywords":["133","exit 133","error 133","SIGTRAP","Trace or breakpoint trap","Linux signal exit","linux","unix","bash","shell"],"errorCode":"133","eventId":"","severity":"Medium","summary":"Shell exit status 133 usually indicates SIGTRAP: Trace or breakpoint trap. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGTRAP. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported trace or breakpoint trap.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGTRAP"],"aliases":["133"]},{"id":50305,"title":"SIGABRT (134) - Process aborted","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGABRT"],"keywords":["134","exit 134","error 134","SIGABRT","Process aborted","Linux signal exit","linux","unix","bash","shell"],"errorCode":"134","eventId":"","severity":"Medium","summary":"Shell exit status 134 usually indicates SIGABRT: Process aborted. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGABRT. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported process aborted.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGABRT"],"aliases":["134"]},{"id":50306,"title":"SIGBUS (135) - Bus error or invalid memory access","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGBUS"],"keywords":["135","exit 135","error 135","SIGBUS","Bus error or invalid memory access","Linux signal exit","linux","unix","bash","shell"],"errorCode":"135","eventId":"","severity":"High","summary":"Shell exit status 135 usually indicates SIGBUS: Bus error or invalid memory access. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGBUS. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported bus error or invalid memory access.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGBUS"],"aliases":["135"]},{"id":50307,"title":"SIGFPE (136) - Floating-point exception","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGFPE"],"keywords":["136","exit 136","error 136","SIGFPE","Floating-point exception","Linux signal exit","linux","unix","bash","shell"],"errorCode":"136","eventId":"","severity":"Medium","summary":"Shell exit status 136 usually indicates SIGFPE: Floating-point exception. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGFPE. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported floating-point exception.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGFPE"],"aliases":["136"]},{"id":50308,"title":"SIGKILL (137) - Process was forcibly killed","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGKILL"],"keywords":["137","exit 137","error 137","SIGKILL","Process was forcibly killed","Linux signal exit","linux","unix","bash","shell"],"errorCode":"137","eventId":"","severity":"High","summary":"Shell exit status 137 usually indicates SIGKILL: Process was forcibly killed. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGKILL. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported process was forcibly killed.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGKILL"],"aliases":["137"]},{"id":50309,"title":"SIGUSR1 (138) - User-defined signal 1","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGUSR1"],"keywords":["138","exit 138","error 138","SIGUSR1","User-defined signal 1","Linux signal exit","linux","unix","bash","shell"],"errorCode":"138","eventId":"","severity":"Medium","summary":"Shell exit status 138 usually indicates SIGUSR1: User-defined signal 1. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGUSR1. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported user-defined signal 1.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGUSR1"],"aliases":["138"]},{"id":50310,"title":"SIGSEGV (139) - Segmentation fault","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGSEGV"],"keywords":["139","exit 139","error 139","SIGSEGV","Segmentation fault","Linux signal exit","linux","unix","bash","shell"],"errorCode":"139","eventId":"","severity":"High","summary":"Shell exit status 139 usually indicates SIGSEGV: Segmentation fault. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGSEGV. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported segmentation fault.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGSEGV"],"aliases":["139"]},{"id":50311,"title":"SIGUSR2 (140) - User-defined signal 2","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGUSR2"],"keywords":["140","exit 140","error 140","SIGUSR2","User-defined signal 2","Linux signal exit","linux","unix","bash","shell"],"errorCode":"140","eventId":"","severity":"Medium","summary":"Shell exit status 140 usually indicates SIGUSR2: User-defined signal 2. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGUSR2. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported user-defined signal 2.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGUSR2"],"aliases":["140"]},{"id":50312,"title":"SIGPIPE (141) - Broken pipe","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGPIPE"],"keywords":["141","exit 141","error 141","SIGPIPE","Broken pipe","Linux signal exit","linux","unix","bash","shell"],"errorCode":"141","eventId":"","severity":"Medium","summary":"Shell exit status 141 usually indicates SIGPIPE: Broken pipe. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGPIPE. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported broken pipe.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGPIPE"],"aliases":["141"]},{"id":50313,"title":"SIGALRM (142) - Timer expired","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGALRM"],"keywords":["142","exit 142","error 142","SIGALRM","Timer expired","Linux signal exit","linux","unix","bash","shell"],"errorCode":"142","eventId":"","severity":"Medium","summary":"Shell exit status 142 usually indicates SIGALRM: Timer expired. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGALRM. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported timer expired.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGALRM"],"aliases":["142"]},{"id":50314,"title":"SIGTERM (143) - Termination requested","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGTERM"],"keywords":["143","exit 143","error 143","SIGTERM","Termination requested","Linux signal exit","linux","unix","bash","shell"],"errorCode":"143","eventId":"","severity":"Medium","summary":"Shell exit status 143 usually indicates SIGTERM: Termination requested. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGTERM. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported termination requested.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGTERM"],"aliases":["143"]},{"id":50315,"title":"SIGSTKFLT (144) - Stack fault","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGSTKFLT"],"keywords":["144","exit 144","error 144","SIGSTKFLT","Stack fault","Linux signal exit","linux","unix","bash","shell"],"errorCode":"144","eventId":"","severity":"Medium","summary":"Shell exit status 144 usually indicates SIGSTKFLT: Stack fault. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGSTKFLT. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported stack fault.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGSTKFLT"],"aliases":["144"]},{"id":50316,"title":"SIGCHLD (145) - Child process stopped or exited","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGCHLD"],"keywords":["145","exit 145","error 145","SIGCHLD","Child process stopped or exited","Linux signal exit","linux","unix","bash","shell"],"errorCode":"145","eventId":"","severity":"Medium","summary":"Shell exit status 145 usually indicates SIGCHLD: Child process stopped or exited. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGCHLD. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported child process stopped or exited.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGCHLD"],"aliases":["145"]},{"id":50317,"title":"SIGCONT (146) - Continued after being stopped","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGCONT"],"keywords":["146","exit 146","error 146","SIGCONT","Continued after being stopped","Linux signal exit","linux","unix","bash","shell"],"errorCode":"146","eventId":"","severity":"Medium","summary":"Shell exit status 146 usually indicates SIGCONT: Continued after being stopped. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGCONT. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported continued after being stopped.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGCONT"],"aliases":["146"]},{"id":50318,"title":"SIGSTOP (147) - Process was stopped","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGSTOP"],"keywords":["147","exit 147","error 147","SIGSTOP","Process was stopped","Linux signal exit","linux","unix","bash","shell"],"errorCode":"147","eventId":"","severity":"Medium","summary":"Shell exit status 147 usually indicates SIGSTOP: Process was stopped. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGSTOP. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported process was stopped.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGSTOP"],"aliases":["147"]},{"id":50319,"title":"SIGTSTP (148) - Terminal stop, commonly Ctrl+Z","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGTSTP"],"keywords":["148","exit 148","error 148","SIGTSTP","Terminal stop, commonly Ctrl+Z","Linux signal exit","linux","unix","bash","shell"],"errorCode":"148","eventId":"","severity":"Medium","summary":"Shell exit status 148 usually indicates SIGTSTP: Terminal stop, commonly Ctrl+Z. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGTSTP. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported terminal stop, commonly ctrl+z.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGTSTP"],"aliases":["148"]},{"id":50320,"title":"SIGTTIN (149) - Background process attempted terminal input","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGTTIN"],"keywords":["149","exit 149","error 149","SIGTTIN","Background process attempted terminal input","Linux signal exit","linux","unix","bash","shell"],"errorCode":"149","eventId":"","severity":"Medium","summary":"Shell exit status 149 usually indicates SIGTTIN: Background process attempted terminal input. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGTTIN. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported background process attempted terminal input.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGTTIN"],"aliases":["149"]},{"id":50321,"title":"SIGTTOU (150) - Background process attempted terminal output","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGTTOU"],"keywords":["150","exit 150","error 150","SIGTTOU","Background process attempted terminal output","Linux signal exit","linux","unix","bash","shell"],"errorCode":"150","eventId":"","severity":"Medium","summary":"Shell exit status 150 usually indicates SIGTTOU: Background process attempted terminal output. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGTTOU. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported background process attempted terminal output.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGTTOU"],"aliases":["150"]},{"id":50322,"title":"SIGURG (151) - Urgent socket data","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGURG"],"keywords":["151","exit 151","error 151","SIGURG","Urgent socket data","Linux signal exit","linux","unix","bash","shell"],"errorCode":"151","eventId":"","severity":"Medium","summary":"Shell exit status 151 usually indicates SIGURG: Urgent socket data. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGURG. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported urgent socket data.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGURG"],"aliases":["151"]},{"id":50323,"title":"SIGXCPU (152) - CPU time limit exceeded","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGXCPU"],"keywords":["152","exit 152","error 152","SIGXCPU","CPU time limit exceeded","Linux signal exit","linux","unix","bash","shell"],"errorCode":"152","eventId":"","severity":"Medium","summary":"Shell exit status 152 usually indicates SIGXCPU: CPU time limit exceeded. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGXCPU. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported cpu time limit exceeded.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGXCPU"],"aliases":["152"]},{"id":50324,"title":"SIGXFSZ (153) - File size limit exceeded","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGXFSZ"],"keywords":["153","exit 153","error 153","SIGXFSZ","File size limit exceeded","Linux signal exit","linux","unix","bash","shell"],"errorCode":"153","eventId":"","severity":"Medium","summary":"Shell exit status 153 usually indicates SIGXFSZ: File size limit exceeded. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGXFSZ. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported file size limit exceeded.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGXFSZ"],"aliases":["153"]},{"id":50325,"title":"SIGVTALRM (154) - Virtual timer expired","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGVTALRM"],"keywords":["154","exit 154","error 154","SIGVTALRM","Virtual timer expired","Linux signal exit","linux","unix","bash","shell"],"errorCode":"154","eventId":"","severity":"Medium","summary":"Shell exit status 154 usually indicates SIGVTALRM: Virtual timer expired. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGVTALRM. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported virtual timer expired.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGVTALRM"],"aliases":["154"]},{"id":50326,"title":"SIGPROF (155) - Profiling timer expired","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGPROF"],"keywords":["155","exit 155","error 155","SIGPROF","Profiling timer expired","Linux signal exit","linux","unix","bash","shell"],"errorCode":"155","eventId":"","severity":"Medium","summary":"Shell exit status 155 usually indicates SIGPROF: Profiling timer expired. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGPROF. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported profiling timer expired.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGPROF"],"aliases":["155"]},{"id":50327,"title":"SIGWINCH (156) - Terminal window size changed","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGWINCH"],"keywords":["156","exit 156","error 156","SIGWINCH","Terminal window size changed","Linux signal exit","linux","unix","bash","shell"],"errorCode":"156","eventId":"","severity":"Medium","summary":"Shell exit status 156 usually indicates SIGWINCH: Terminal window size changed. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGWINCH. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported terminal window size changed.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGWINCH"],"aliases":["156"]},{"id":50328,"title":"SIGIO (157) - Asynchronous I/O is available","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGIO"],"keywords":["157","exit 157","error 157","SIGIO","Asynchronous I/O is available","Linux signal exit","linux","unix","bash","shell"],"errorCode":"157","eventId":"","severity":"Medium","summary":"Shell exit status 157 usually indicates SIGIO: Asynchronous I/O is available. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGIO. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported asynchronous i/o is available.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGIO"],"aliases":["157"]},{"id":50329,"title":"SIGPWR (158) - Power failure notification","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGPWR"],"keywords":["158","exit 158","error 158","SIGPWR","Power failure notification","Linux signal exit","linux","unix","bash","shell"],"errorCode":"158","eventId":"","severity":"Medium","summary":"Shell exit status 158 usually indicates SIGPWR: Power failure notification. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGPWR. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported power failure notification.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGPWR"],"aliases":["158"]},{"id":50330,"title":"SIGSYS (159) - Bad system call","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGSYS"],"keywords":["159","exit 159","error 159","SIGSYS","Bad system call","Linux signal exit","linux","unix","bash","shell"],"errorCode":"159","eventId":"","severity":"Medium","summary":"Shell exit status 159 usually indicates SIGSYS: Bad system call. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGSYS. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported bad system call.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGSYS"],"aliases":["159"]},{"id":50331,"title":"SIGRTMIN (162) - First real-time signal","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGRTMIN"],"keywords":["162","exit 162","error 162","SIGRTMIN","First real-time signal","Linux signal exit","linux","unix","bash","shell"],"errorCode":"162","eventId":"","severity":"Medium","summary":"Shell exit status 162 usually indicates SIGRTMIN: First real-time signal. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGRTMIN. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported first real-time signal.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGRTMIN"],"aliases":["162"]},{"id":50332,"title":"SIGRTMIN+1 (163) - Real-time application signal","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGRTMIN+1"],"keywords":["163","exit 163","error 163","SIGRTMIN+1","Real-time application signal","Linux signal exit","linux","unix","bash","shell"],"errorCode":"163","eventId":"","severity":"Medium","summary":"Shell exit status 163 usually indicates SIGRTMIN+1: Real-time application signal. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGRTMIN+1. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported real-time application signal.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGRTMIN+1"],"aliases":["163"]},{"id":50333,"title":"SIGRTMAX (191) - Last typical real-time signal","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","SIGRTMAX"],"keywords":["191","exit 191","error 191","SIGRTMAX","Last typical real-time signal","Linux signal exit","linux","unix","bash","shell"],"errorCode":"191","eventId":"","severity":"Medium","summary":"Shell exit status 191 usually indicates SIGRTMAX: Last typical real-time signal. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving SIGRTMAX. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported last typical real-time signal.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","SIGRTMAX"],"aliases":["191"]},{"id":50334,"title":"Beyond (192) - Invalid or unused on most systems","category":"Linux","product":"Linux Signals","tags":["Linux signal exit","Signal","Beyond"],"keywords":["192","exit 192","error 192","Beyond","Invalid or unused on most systems","Linux signal exit","linux","unix","bash","shell"],"errorCode":"192","eventId":"","severity":"Medium","summary":"Shell exit status 192 usually indicates Beyond: Invalid or unused on most systems. Signal-derived statuses use 128 plus the signal number.","rootCause":"The process terminated after receiving Beyond. Determine which user, service, kernel condition, resource limit, or supervisor sent the signal.","resolution":"1. Re-run the command without discarding standard error.\n2. Immediately run printf '%s\\n' \"$?\" to confirm the exit status.\n3. Review the command's manual page and service or journal logs.\n4. Correct the confirmed permission, syntax, dependency, resource, or signal condition.\n5. Retry and confirm exit status 0.","emailScript":"Hello,\n\nWe reviewed the Linux issue and found that the affected command reported invalid or unused on most systems.\n\nWe are checking the related permissions, resources, configuration, and logs, then will retry the operation and confirm it completes successfully.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Try the action one more time.\n2. Note the exact time and complete message shown.\n3. Do not repeatedly restart or force-stop the system.\n4. Send the message and timestamp to IT Support.","notes":"Namespace: Linux signal exit. This value follows the common 128 + signal convention; signal numbering can vary by platform. Use kill -l and the command documentation to confirm.","sourceDocument":"Linux error codes.docx","platforms":["linux"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Linux Signals"],"technologies":["Linux signal exit","Signal","Beyond"],"aliases":["192"]},{"id":51000,"title":"DOS ERROR 1 - Invalid function number","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["1","0x01","01h","DOS error 1","Invalid function number","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"1 / 01h","eventId":"","severity":"Medium","summary":"DOS error 1 indicates invalid function number. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported invalid function number while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported invalid function number.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 1; hexadecimal 01h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["1 / 01h"]},{"id":51001,"title":"DOS ERROR 2 - File not found","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["2","0x02","02h","DOS error 2","File not found","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"2 / 02h","eventId":"","severity":"Medium","summary":"DOS error 2 indicates file not found. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported file not found while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported file not found.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 2; hexadecimal 02h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["2 / 02h"]},{"id":51002,"title":"DOS ERROR 3 - Path not found","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["3","0x03","03h","DOS error 3","Path not found","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"3 / 03h","eventId":"","severity":"Medium","summary":"DOS error 3 indicates path not found. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported path not found while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported path not found.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 3; hexadecimal 03h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["3 / 03h"]},{"id":51003,"title":"DOS ERROR 4 - Too many open files","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["4","0x04","04h","DOS error 4","Too many open files","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"4 / 04h","eventId":"","severity":"Medium","summary":"DOS error 4 indicates too many open files. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported too many open files while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported too many open files.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 4; hexadecimal 04h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["4 / 04h"]},{"id":51004,"title":"DOS ERROR 5 - Access denied","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["5","0x05","05h","DOS error 5","Access denied","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"5 / 05h","eventId":"","severity":"Medium","summary":"DOS error 5 indicates access denied. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported access denied while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported access denied.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 5; hexadecimal 05h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["5 / 05h"]},{"id":51005,"title":"DOS ERROR 6 - Invalid handle","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["6","0x06","06h","DOS error 6","Invalid handle","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"6 / 06h","eventId":"","severity":"Medium","summary":"DOS error 6 indicates invalid handle. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported invalid handle while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported invalid handle.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 6; hexadecimal 06h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["6 / 06h"]},{"id":51006,"title":"DOS ERROR 7 - Memory control blocks destroyed","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["7","0x07","07h","DOS error 7","Memory control blocks destroyed","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"7 / 07h","eventId":"","severity":"Medium","summary":"DOS error 7 indicates memory control blocks destroyed. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported memory control blocks destroyed while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported memory control blocks destroyed.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 7; hexadecimal 07h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nset\nmem /c","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["7 / 07h"]},{"id":51007,"title":"DOS ERROR 8 - Insufficient memory","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["8","0x08","08h","DOS error 8","Insufficient memory","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"8 / 08h","eventId":"","severity":"Medium","summary":"DOS error 8 indicates insufficient memory. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported insufficient memory while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported insufficient memory.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 8; hexadecimal 08h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nset\nmem /c","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["8 / 08h"]},{"id":51008,"title":"DOS ERROR 9 - Invalid memory block address","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["9","0x09","09h","DOS error 9","Invalid memory block address","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"9 / 09h","eventId":"","severity":"Medium","summary":"DOS error 9 indicates invalid memory block address. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported invalid memory block address while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported invalid memory block address.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 9; hexadecimal 09h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nset\nmem /c","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["9 / 09h"]},{"id":51009,"title":"DOS ERROR 10 - Invalid environment","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["10","0x0A","0Ah","DOS error 10","Invalid environment","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"10 / 0Ah","eventId":"","severity":"Medium","summary":"DOS error 10 indicates invalid environment. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported invalid environment while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported invalid environment.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 10; hexadecimal 0Ah. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nset\nmem /c","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["10 / 0Ah"]},{"id":51010,"title":"DOS ERROR 11 - Invalid executable format","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["11","0x0B","0Bh","DOS error 11","Invalid executable format","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"11 / 0Bh","eventId":"","severity":"Medium","summary":"DOS error 11 indicates invalid executable format. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported invalid executable format while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported invalid executable format.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 11; hexadecimal 0Bh. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nhelp","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["11 / 0Bh"]},{"id":51011,"title":"DOS ERROR 12 - Invalid access mode","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["12","0x0C","0Ch","DOS error 12","Invalid access mode","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"12 / 0Ch","eventId":"","severity":"Medium","summary":"DOS error 12 indicates invalid access mode. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported invalid access mode while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported invalid access mode.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 12; hexadecimal 0Ch. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["12 / 0Ch"]},{"id":51012,"title":"DOS ERROR 13 - Invalid data","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["13","0x0D","0Dh","DOS error 13","Invalid data","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"13 / 0Dh","eventId":"","severity":"Medium","summary":"DOS error 13 indicates invalid data. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported invalid data while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported invalid data.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 13; hexadecimal 0Dh. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["13 / 0Dh"]},{"id":51013,"title":"DOS ERROR 14 - Reserved","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["14","0x0E","0Eh","DOS error 14","Reserved","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"14 / 0Eh","eventId":"","severity":"Low","summary":"DOS error 14 indicates reserved. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported reserved while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported reserved.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 14; hexadecimal 0Eh. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["14 / 0Eh"]},{"id":51014,"title":"DOS ERROR 15 - Invalid drive specified","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["15","0x0F","0Fh","DOS error 15","Invalid drive specified","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"15 / 0Fh","eventId":"","severity":"Medium","summary":"DOS error 15 indicates invalid drive specified. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported invalid drive specified while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported invalid drive specified.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 15; hexadecimal 0Fh. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["15 / 0Fh"]},{"id":51015,"title":"DOS ERROR 16 - Attempt to remove current directory","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["16","0x10","10h","DOS error 16","Attempt to remove current directory","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"16 / 10h","eventId":"","severity":"Medium","summary":"DOS error 16 indicates attempt to remove current directory. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported attempt to remove current directory while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported attempt to remove current directory.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 16; hexadecimal 10h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["16 / 10h"]},{"id":51016,"title":"DOS ERROR 17 - Not same device","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["17","0x11","11h","DOS error 17","Not same device","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"17 / 11h","eventId":"","severity":"Medium","summary":"DOS error 17 indicates not same device. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported not same device while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported not same device.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 17; hexadecimal 11h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["17 / 11h"]},{"id":51017,"title":"DOS ERROR 18 - No more files","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["18","0x12","12h","DOS error 18","No more files","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"18 / 12h","eventId":"","severity":"Medium","summary":"DOS error 18 indicates no more files. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported no more files while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported no more files.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 18; hexadecimal 12h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["18 / 12h"]},{"id":51018,"title":"DOS ERROR 19 - Write-protected disk","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["19","0x13","13h","DOS error 19","Write-protected disk","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"19 / 13h","eventId":"","severity":"Medium","summary":"DOS error 19 indicates write-protected disk. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported write-protected disk while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported write-protected disk.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 19; hexadecimal 13h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["19 / 13h"]},{"id":51019,"title":"DOS ERROR 20 - Unknown unit","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["20","0x14","14h","DOS error 20","Unknown unit","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"20 / 14h","eventId":"","severity":"Medium","summary":"DOS error 20 indicates unknown unit. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported unknown unit while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported unknown unit.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 20; hexadecimal 14h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["20 / 14h"]},{"id":51020,"title":"DOS ERROR 21 - Drive not ready","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["21","0x15","15h","DOS error 21","Drive not ready","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"21 / 15h","eventId":"","severity":"Medium","summary":"DOS error 21 indicates drive not ready. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported drive not ready while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported drive not ready.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 21; hexadecimal 15h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["21 / 15h"]},{"id":51021,"title":"DOS ERROR 22 - Unknown command","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["22","0x16","16h","DOS error 22","Unknown command","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"22 / 16h","eventId":"","severity":"Medium","summary":"DOS error 22 indicates unknown command. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported unknown command while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported unknown command.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 22; hexadecimal 16h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nhelp","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["22 / 16h"]},{"id":51022,"title":"DOS ERROR 23 - CRC data error","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["23","0x17","17h","DOS error 23","CRC data error","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"23 / 17h","eventId":"","severity":"High","summary":"DOS error 23 indicates crc data error. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported crc data error while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported crc data error.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 23; hexadecimal 17h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["23 / 17h"]},{"id":51023,"title":"DOS ERROR 24 - Bad request structure length","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["24","0x18","18h","DOS error 24","Bad request structure length","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"24 / 18h","eventId":"","severity":"Medium","summary":"DOS error 24 indicates bad request structure length. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported bad request structure length while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported bad request structure length.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 24; hexadecimal 18h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["24 / 18h"]},{"id":51024,"title":"DOS ERROR 25 - Seek error","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["25","0x19","19h","DOS error 25","Seek error","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"25 / 19h","eventId":"","severity":"Medium","summary":"DOS error 25 indicates seek error. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported seek error while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported seek error.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 25; hexadecimal 19h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["25 / 19h"]},{"id":51025,"title":"DOS ERROR 26 - Unknown media type","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["26","0x1A","1Ah","DOS error 26","Unknown media type","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"26 / 1Ah","eventId":"","severity":"Medium","summary":"DOS error 26 indicates unknown media type. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported unknown media type while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported unknown media type.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 26; hexadecimal 1Ah. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["26 / 1Ah"]},{"id":51026,"title":"DOS ERROR 27 - Sector not found","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["27","0x1B","1Bh","DOS error 27","Sector not found","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"27 / 1Bh","eventId":"","severity":"Medium","summary":"DOS error 27 indicates sector not found. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported sector not found while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported sector not found.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 27; hexadecimal 1Bh. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["27 / 1Bh"]},{"id":51027,"title":"DOS ERROR 28 - Printer out of paper","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["28","0x1C","1Ch","DOS error 28","Printer out of paper","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"28 / 1Ch","eventId":"","severity":"Medium","summary":"DOS error 28 indicates printer out of paper. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported printer out of paper while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported printer out of paper.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 28; hexadecimal 1Ch. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["28 / 1Ch"]},{"id":51028,"title":"DOS ERROR 29 - Write fault","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["29","0x1D","1Dh","DOS error 29","Write fault","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"29 / 1Dh","eventId":"","severity":"High","summary":"DOS error 29 indicates write fault. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported write fault while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported write fault.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 29; hexadecimal 1Dh. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["29 / 1Dh"]},{"id":51029,"title":"DOS ERROR 30 - Read fault","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["30","0x1E","1Eh","DOS error 30","Read fault","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"30 / 1Eh","eventId":"","severity":"High","summary":"DOS error 30 indicates read fault. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported read fault while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported read fault.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 30; hexadecimal 1Eh. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["30 / 1Eh"]},{"id":51030,"title":"DOS ERROR 31 - General failure","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["31","0x1F","1Fh","DOS error 31","General failure","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"31 / 1Fh","eventId":"","severity":"Medium","summary":"DOS error 31 indicates general failure. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported general failure while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported general failure.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 31; hexadecimal 1Fh. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["31 / 1Fh"]},{"id":51031,"title":"DOS ERROR 32 - Sharing violation","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["32","0x20","20h","DOS error 32","Sharing violation","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"32 / 20h","eventId":"","severity":"Medium","summary":"DOS error 32 indicates sharing violation. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported sharing violation while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported sharing violation.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 32; hexadecimal 20h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["32 / 20h"]},{"id":51032,"title":"DOS ERROR 33 - Lock violation","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["33","0x21","21h","DOS error 33","Lock violation","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"33 / 21h","eventId":"","severity":"Medium","summary":"DOS error 33 indicates lock violation. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported lock violation while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported lock violation.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 33; hexadecimal 21h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["33 / 21h"]},{"id":51033,"title":"DOS ERROR 34 - Invalid disk change","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["34","0x22","22h","DOS error 34","Invalid disk change","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"34 / 22h","eventId":"","severity":"Medium","summary":"DOS error 34 indicates invalid disk change. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported invalid disk change while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported invalid disk change.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 34; hexadecimal 22h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["34 / 22h"]},{"id":51034,"title":"DOS ERROR 35 - FCB unavailable","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["35","0x23","23h","DOS error 35","FCB unavailable","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"35 / 23h","eventId":"","severity":"Medium","summary":"DOS error 35 indicates fcb unavailable. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported fcb unavailable while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported fcb unavailable.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 35; hexadecimal 23h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["35 / 23h"]},{"id":51035,"title":"DOS ERROR 36 - Sharing buffer overflow","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["36","0x24","24h","DOS error 36","Sharing buffer overflow","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"36 / 24h","eventId":"","severity":"High","summary":"DOS error 36 indicates sharing buffer overflow. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported sharing buffer overflow while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported sharing buffer overflow.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 36; hexadecimal 24h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["36 / 24h"]},{"id":51036,"title":"DOS ERROR 38 - Unable to complete file operation","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["38","0x26","26h","DOS error 38","Unable to complete file operation","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"38 / 26h","eventId":"","severity":"Medium","summary":"DOS error 38 indicates unable to complete file operation. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported unable to complete file operation while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported unable to complete file operation.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 38; hexadecimal 26h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["38 / 26h"]},{"id":51037,"title":"DOS ERROR 50 - Network request not supported","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["50","0x32","32h","DOS error 50","Network request not supported","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"50 / 32h","eventId":"","severity":"Medium","summary":"DOS error 50 indicates network request not supported. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported network request not supported while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported network request not supported.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 50; hexadecimal 32h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nnet use\nnet view","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["50 / 32h"]},{"id":51038,"title":"DOS ERROR 51 - Remote computer not listening","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["51","0x33","33h","DOS error 51","Remote computer not listening","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"51 / 33h","eventId":"","severity":"Medium","summary":"DOS error 51 indicates remote computer not listening. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported remote computer not listening while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported remote computer not listening.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 51; hexadecimal 33h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nnet use\nnet view","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["51 / 33h"]},{"id":51039,"title":"DOS ERROR 52 - Duplicate name on network","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["52","0x34","34h","DOS error 52","Duplicate name on network","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"52 / 34h","eventId":"","severity":"Medium","summary":"DOS error 52 indicates duplicate name on network. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported duplicate name on network while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported duplicate name on network.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 52; hexadecimal 34h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nnet use\nnet view","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["52 / 34h"]},{"id":51040,"title":"DOS ERROR 53 - Network name not found","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["53","0x35","35h","DOS error 53","Network name not found","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"53 / 35h","eventId":"","severity":"Medium","summary":"DOS error 53 indicates network name not found. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported network name not found while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported network name not found.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 53; hexadecimal 35h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nnet use\nnet view","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["53 / 35h"]},{"id":51041,"title":"DOS ERROR 54 - Network busy","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["54","0x36","36h","DOS error 54","Network busy","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"54 / 36h","eventId":"","severity":"Medium","summary":"DOS error 54 indicates network busy. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported network busy while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported network busy.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 54; hexadecimal 36h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nnet use\nnet view","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["54 / 36h"]},{"id":51042,"title":"DOS ERROR 55 - Network device no longer exists","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["55","0x37","37h","DOS error 55","Network device no longer exists","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"55 / 37h","eventId":"","severity":"Medium","summary":"DOS error 55 indicates network device no longer exists. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported network device no longer exists while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported network device no longer exists.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 55; hexadecimal 37h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nnet use\nnet view","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["55 / 37h"]},{"id":51043,"title":"DOS ERROR 56 - NetBIOS command limit exceeded","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["56","0x38","38h","DOS error 56","NetBIOS command limit exceeded","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"56 / 38h","eventId":"","severity":"Medium","summary":"DOS error 56 indicates netbios command limit exceeded. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported netbios command limit exceeded while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported netbios command limit exceeded.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 56; hexadecimal 38h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nnet use\nnet view\nhelp","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["56 / 38h"]},{"id":51044,"title":"DOS ERROR 57 - Network adapter hardware error","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["57","0x39","39h","DOS error 57","Network adapter hardware error","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"57 / 39h","eventId":"","severity":"High","summary":"DOS error 57 indicates network adapter hardware error. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported network adapter hardware error while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported network adapter hardware error.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 57; hexadecimal 39h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nnet use\nnet view","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["57 / 39h"]},{"id":51045,"title":"DOS ERROR 58 - Incorrect network response","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["58","0x3A","3Ah","DOS error 58","Incorrect network response","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"58 / 3Ah","eventId":"","severity":"Medium","summary":"DOS error 58 indicates incorrect network response. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported incorrect network response while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported incorrect network response.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 58; hexadecimal 3Ah. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nnet use\nnet view","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["58 / 3Ah"]},{"id":51046,"title":"DOS ERROR 59 - Unexpected network error","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["59","0x3B","3Bh","DOS error 59","Unexpected network error","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"59 / 3Bh","eventId":"","severity":"Medium","summary":"DOS error 59 indicates unexpected network error. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported unexpected network error while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported unexpected network error.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 59; hexadecimal 3Bh. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nnet use\nnet view","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["59 / 3Bh"]},{"id":51047,"title":"DOS ERROR 60 - Incompatible remote adapter","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["60","0x3C","3Ch","DOS error 60","Incompatible remote adapter","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"60 / 3Ch","eventId":"","severity":"Medium","summary":"DOS error 60 indicates incompatible remote adapter. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported incompatible remote adapter while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported incompatible remote adapter.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 60; hexadecimal 3Ch. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nnet use\nnet view","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["60 / 3Ch"]},{"id":51048,"title":"DOS ERROR 61 - Print queue full","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["61","0x3D","3Dh","DOS error 61","Print queue full","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"61 / 3Dh","eventId":"","severity":"Medium","summary":"DOS error 61 indicates print queue full. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported print queue full while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported print queue full.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 61; hexadecimal 3Dh. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["61 / 3Dh"]},{"id":51049,"title":"DOS ERROR 62 - No space for print file","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["62","0x3E","3Eh","DOS error 62","No space for print file","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"62 / 3Eh","eventId":"","severity":"Medium","summary":"DOS error 62 indicates no space for print file. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported no space for print file while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported no space for print file.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 62; hexadecimal 3Eh. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["62 / 3Eh"]},{"id":51050,"title":"DOS ERROR 63 - Print file deleted","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["63","0x3F","3Fh","DOS error 63","Print file deleted","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"63 / 3Fh","eventId":"","severity":"Medium","summary":"DOS error 63 indicates print file deleted. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported print file deleted while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported print file deleted.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 63; hexadecimal 3Fh. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["63 / 3Fh"]},{"id":51051,"title":"DOS ERROR 64 - Network name deleted","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["64","0x40","40h","DOS error 64","Network name deleted","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"64 / 40h","eventId":"","severity":"Medium","summary":"DOS error 64 indicates network name deleted. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported network name deleted while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported network name deleted.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 64; hexadecimal 40h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nnet use\nnet view","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["64 / 40h"]},{"id":51052,"title":"DOS ERROR 65 - Network access denied","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["65","0x41","41h","DOS error 65","Network access denied","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"65 / 41h","eventId":"","severity":"Medium","summary":"DOS error 65 indicates network access denied. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported network access denied while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported network access denied.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 65; hexadecimal 41h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nnet use\nnet view","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["65 / 41h"]},{"id":51053,"title":"DOS ERROR 66 - Network device type incorrect","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["66","0x42","42h","DOS error 66","Network device type incorrect","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"66 / 42h","eventId":"","severity":"Medium","summary":"DOS error 66 indicates network device type incorrect. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported network device type incorrect while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported network device type incorrect.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 66; hexadecimal 42h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nnet use\nnet view","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["66 / 42h"]},{"id":51054,"title":"DOS ERROR 67 - Network name not found","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["67","0x43","43h","DOS error 67","Network name not found","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"67 / 43h","eventId":"","severity":"Medium","summary":"DOS error 67 indicates network name not found. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported network name not found while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported network name not found.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 67; hexadecimal 43h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nnet use\nnet view","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["67 / 43h"]},{"id":51055,"title":"DOS ERROR 68 - Network name limit exceeded","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["68","0x44","44h","DOS error 68","Network name limit exceeded","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"68 / 44h","eventId":"","severity":"Medium","summary":"DOS error 68 indicates network name limit exceeded. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported network name limit exceeded while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported network name limit exceeded.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 68; hexadecimal 44h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nnet use\nnet view","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["68 / 44h"]},{"id":51056,"title":"DOS ERROR 69 - NetBIOS session limit exceeded","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["69","0x45","45h","DOS error 69","NetBIOS session limit exceeded","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"69 / 45h","eventId":"","severity":"Medium","summary":"DOS error 69 indicates netbios session limit exceeded. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported netbios session limit exceeded while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported netbios session limit exceeded.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 69; hexadecimal 45h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nnet use\nnet view","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["69 / 45h"]},{"id":51057,"title":"DOS ERROR 70 - Temporarily paused","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["70","0x46","46h","DOS error 70","Temporarily paused","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"70 / 46h","eventId":"","severity":"Medium","summary":"DOS error 70 indicates temporarily paused. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported temporarily paused while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported temporarily paused.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 70; hexadecimal 46h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["70 / 46h"]},{"id":51058,"title":"DOS ERROR 71 - Network request not accepted","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["71","0x47","47h","DOS error 71","Network request not accepted","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"71 / 47h","eventId":"","severity":"Medium","summary":"DOS error 71 indicates network request not accepted. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported network request not accepted while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported network request not accepted.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 71; hexadecimal 47h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nnet use\nnet view","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["71 / 47h"]},{"id":51059,"title":"DOS ERROR 72 - Print or disk redirection paused","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["72","0x48","48h","DOS error 72","Print or disk redirection paused","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"72 / 48h","eventId":"","severity":"Medium","summary":"DOS error 72 indicates print or disk redirection paused. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported print or disk redirection paused while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported print or disk redirection paused.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 72; hexadecimal 48h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk\nnet use\nnet view","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["72 / 48h"]},{"id":51060,"title":"DOS ERROR 80 - File already exists","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["80","0x50","50h","DOS error 80","File already exists","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"80 / 50h","eventId":"","severity":"Medium","summary":"DOS error 80 indicates file already exists. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported file already exists while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported file already exists.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 80; hexadecimal 50h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["80 / 50h"]},{"id":51061,"title":"DOS ERROR 82 - Cannot make directory entry","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["82","0x52","52h","DOS error 82","Cannot make directory entry","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"82 / 52h","eventId":"","severity":"Medium","summary":"DOS error 82 indicates cannot make directory entry. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported cannot make directory entry while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported cannot make directory entry.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 82; hexadecimal 52h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["82 / 52h"]},{"id":51062,"title":"DOS ERROR 83 - Fail on INT 24","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["83","0x53","53h","DOS error 83","Fail on INT 24","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"83 / 53h","eventId":"","severity":"Medium","summary":"DOS error 83 indicates fail on int 24. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported fail on int 24 while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported fail on int 24.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 83; hexadecimal 53h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["83 / 53h"]},{"id":51063,"title":"DOS ERROR 84 - Too many redirections","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["84","0x54","54h","DOS error 84","Too many redirections","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"84 / 54h","eventId":"","severity":"Medium","summary":"DOS error 84 indicates too many redirections. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported too many redirections while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported too many redirections.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 84; hexadecimal 54h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nnet use\nnet view","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["84 / 54h"]},{"id":51064,"title":"DOS ERROR 85 - Duplicate redirection","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["85","0x55","55h","DOS error 85","Duplicate redirection","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"85 / 55h","eventId":"","severity":"Medium","summary":"DOS error 85 indicates duplicate redirection. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported duplicate redirection while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported duplicate redirection.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 85; hexadecimal 55h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nnet use\nnet view","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["85 / 55h"]},{"id":51065,"title":"DOS ERROR 86 - Invalid password","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["86","0x56","56h","DOS error 86","Invalid password","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"86 / 56h","eventId":"","severity":"Medium","summary":"DOS error 86 indicates invalid password. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported invalid password while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported invalid password.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 86; hexadecimal 56h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["86 / 56h"]},{"id":51066,"title":"DOS ERROR 87 - Invalid parameter","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["87","0x57","57h","DOS error 87","Invalid parameter","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"87 / 57h","eventId":"","severity":"Medium","summary":"DOS error 87 indicates invalid parameter. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported invalid parameter while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported invalid parameter.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 87; hexadecimal 57h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nhelp","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["87 / 57h"]},{"id":51067,"title":"DOS ERROR 88 - Network device fault","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["88","0x58","58h","DOS error 88","Network device fault","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"88 / 58h","eventId":"","severity":"High","summary":"DOS error 88 indicates network device fault. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported network device fault while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported network device fault.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 88; hexadecimal 58h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nnet use\nnet view","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["88 / 58h"]},{"id":51068,"title":"DOS ERROR 89 - Function not supported by network","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["89","0x59","59h","DOS error 89","Function not supported by network","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"89 / 59h","eventId":"","severity":"Medium","summary":"DOS error 89 indicates function not supported by network. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported function not supported by network while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported function not supported by network.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 89; hexadecimal 59h. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nnet use\nnet view","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["89 / 59h"]},{"id":51069,"title":"DOS ERROR 90 - Required system component not installed","category":"DOS / Legacy","product":"MS-DOS / INT 21h","tags":["DOS","Legacy","error"],"keywords":["90","0x5A","5Ah","DOS error 90","Required system component not installed","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"90 / 5Ah","eventId":"","severity":"Medium","summary":"DOS error 90 indicates required system component not installed. This canonical meaning follows the DOS INT 21h extended-error table.","rootCause":"The operation reported required system component not installed while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported required system component not installed.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error. Decimal 90; hexadecimal 5Ah. Codes 1-12 may be returned directly in AX; later values can be obtained through INT 21h Function 59h. Conflicting duplicate source wording was normalized against the extended-error table.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["MS-DOS"],"technologies":["DOS","Legacy","error"],"aliases":["90 / 5Ah"]},{"id":51100,"title":"DOS PARSE 1 - Too many parameters","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","parse"],"keywords":["1","DOS parse 1","Too many parameters","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"PARSE 1","eventId":"","severity":"Medium","summary":"DOS parse 1 indicates too many parameters. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported too many parameters while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported too many parameters.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS parse. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nhelp","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","parse"],"aliases":["PARSE 1"]},{"id":51101,"title":"DOS PARSE 2 - Required parameter missing","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","parse"],"keywords":["2","DOS parse 2","Required parameter missing","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"PARSE 2","eventId":"","severity":"Medium","summary":"DOS parse 2 indicates required parameter missing. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported required parameter missing while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported required parameter missing.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS parse. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nhelp","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","parse"],"aliases":["PARSE 2"]},{"id":51102,"title":"DOS PARSE 3 - Invalid switch","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","parse"],"keywords":["3","DOS parse 3","Invalid switch","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"PARSE 3","eventId":"","severity":"Medium","summary":"DOS parse 3 indicates invalid switch. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported invalid switch while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported invalid switch.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS parse. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nhelp","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","parse"],"aliases":["PARSE 3"]},{"id":51103,"title":"DOS PARSE 4 - Invalid keyword","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","parse"],"keywords":["4","DOS parse 4","Invalid keyword","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"PARSE 4","eventId":"","severity":"Medium","summary":"DOS parse 4 indicates invalid keyword. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported invalid keyword while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported invalid keyword.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS parse. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nhelp","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","parse"],"aliases":["PARSE 4"]},{"id":51104,"title":"DOS PARSE 6 - Parameter value not in allowed range","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","parse"],"keywords":["6","DOS parse 6","Parameter value not in allowed range","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"PARSE 6","eventId":"","severity":"Medium","summary":"DOS parse 6 indicates parameter value not in allowed range. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported parameter value not in allowed range while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported parameter value not in allowed range.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS parse. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nhelp","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","parse"],"aliases":["PARSE 6"]},{"id":51105,"title":"DOS PARSE 7 - Parameter value not allowed","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","parse"],"keywords":["7","DOS parse 7","Parameter value not allowed","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"PARSE 7","eventId":"","severity":"Medium","summary":"DOS parse 7 indicates parameter value not allowed. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported parameter value not allowed while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported parameter value not allowed.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS parse. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nhelp","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","parse"],"aliases":["PARSE 7"]},{"id":51106,"title":"DOS PARSE 8 - Parameter value not allowed","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","parse"],"keywords":["8","DOS parse 8","Parameter value not allowed","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"PARSE 8","eventId":"","severity":"Medium","summary":"DOS parse 8 indicates parameter value not allowed. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported parameter value not allowed while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported parameter value not allowed.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS parse. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nhelp","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","parse"],"aliases":["PARSE 8"]},{"id":51107,"title":"DOS PARSE 9 - Parameter format not correct","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","parse"],"keywords":["9","DOS parse 9","Parameter format not correct","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"PARSE 9","eventId":"","severity":"Medium","summary":"DOS parse 9 indicates parameter format not correct. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported parameter format not correct while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported parameter format not correct.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS parse. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nhelp","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","parse"],"aliases":["PARSE 9"]},{"id":51108,"title":"DOS PARSE 10 - Invalid parameter","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","parse"],"keywords":["10","DOS parse 10","Invalid parameter","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"PARSE 10","eventId":"","severity":"Medium","summary":"DOS parse 10 indicates invalid parameter. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported invalid parameter while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported invalid parameter.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS parse. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nhelp","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","parse"],"aliases":["PARSE 10"]},{"id":51109,"title":"DOS PARSE 11 - Invalid parameter combination","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","parse"],"keywords":["11","DOS parse 11","Invalid parameter combination","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"PARSE 11","eventId":"","severity":"Medium","summary":"DOS parse 11 indicates invalid parameter combination. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported invalid parameter combination while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported invalid parameter combination.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS parse. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nhelp","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","parse"],"aliases":["PARSE 11"]},{"id":51200,"title":"DOS I/O ERROR 100 - Disk read error","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","I/O error"],"keywords":["100","DOS I/O error 100","Disk read error","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"I/O ERROR 100","eventId":"","severity":"Medium","summary":"DOS I/O error 100 indicates disk read error. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported disk read error while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported disk read error.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS I/O error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","I/O error"],"aliases":["I/O ERROR 100"]},{"id":51201,"title":"DOS I/O ERROR 101 - Disk write error","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","I/O error"],"keywords":["101","DOS I/O error 101","Disk write error","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"I/O ERROR 101","eventId":"","severity":"Medium","summary":"DOS I/O error 101 indicates disk write error. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported disk write error while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported disk write error.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS I/O error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","I/O error"],"aliases":["I/O ERROR 101"]},{"id":51202,"title":"DOS I/O ERROR 102 - File not assigned","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","I/O error"],"keywords":["102","DOS I/O error 102","File not assigned","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"I/O ERROR 102","eventId":"","severity":"Medium","summary":"DOS I/O error 102 indicates file not assigned. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported file not assigned while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported file not assigned.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS I/O error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","I/O error"],"aliases":["I/O ERROR 102"]},{"id":51203,"title":"DOS I/O ERROR 103 - File not open","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","I/O error"],"keywords":["103","DOS I/O error 103","File not open","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"I/O ERROR 103","eventId":"","severity":"Medium","summary":"DOS I/O error 103 indicates file not open. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported file not open while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported file not open.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS I/O error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","I/O error"],"aliases":["I/O ERROR 103"]},{"id":51204,"title":"DOS I/O ERROR 104 - File not open for input","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","I/O error"],"keywords":["104","DOS I/O error 104","File not open for input","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"I/O ERROR 104","eventId":"","severity":"Medium","summary":"DOS I/O error 104 indicates file not open for input. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported file not open for input while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported file not open for input.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS I/O error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","I/O error"],"aliases":["I/O ERROR 104"]},{"id":51205,"title":"DOS I/O ERROR 105 - File not open for output","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","I/O error"],"keywords":["105","DOS I/O error 105","File not open for output","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"I/O ERROR 105","eventId":"","severity":"Medium","summary":"DOS I/O error 105 indicates file not open for output. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported file not open for output while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported file not open for output.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS I/O error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","I/O error"],"aliases":["I/O ERROR 105"]},{"id":51206,"title":"DOS I/O ERROR 106 - Invalid numeric format","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","I/O error"],"keywords":["106","DOS I/O error 106","Invalid numeric format","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"I/O ERROR 106","eventId":"","severity":"Medium","summary":"DOS I/O error 106 indicates invalid numeric format. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported invalid numeric format while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported invalid numeric format.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS I/O error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nhelp","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","I/O error"],"aliases":["I/O ERROR 106"]},{"id":51300,"title":"DOS CRITICAL ERROR 150 - Disk is write-protected","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","critical error"],"keywords":["150","DOS critical error 150","Disk is write-protected","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"CRITICAL ERROR 150","eventId":"","severity":"Medium","summary":"DOS critical error 150 indicates disk is write-protected. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported disk is write-protected while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported disk is write-protected.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS critical error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","critical error"],"aliases":["CRITICAL ERROR 150"]},{"id":51301,"title":"DOS CRITICAL ERROR 151 - Unknown unit","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","critical error"],"keywords":["151","DOS critical error 151","Unknown unit","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"CRITICAL ERROR 151","eventId":"","severity":"Medium","summary":"DOS critical error 151 indicates unknown unit. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported unknown unit while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported unknown unit.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS critical error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","critical error"],"aliases":["CRITICAL ERROR 151"]},{"id":51302,"title":"DOS CRITICAL ERROR 152 - Drive not ready","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","critical error"],"keywords":["152","DOS critical error 152","Drive not ready","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"CRITICAL ERROR 152","eventId":"","severity":"Medium","summary":"DOS critical error 152 indicates drive not ready. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported drive not ready while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported drive not ready.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS critical error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","critical error"],"aliases":["CRITICAL ERROR 152"]},{"id":51303,"title":"DOS CRITICAL ERROR 153 - Unknown command","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","critical error"],"keywords":["153","DOS critical error 153","Unknown command","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"CRITICAL ERROR 153","eventId":"","severity":"Medium","summary":"DOS critical error 153 indicates unknown command. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported unknown command while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported unknown command.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS critical error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nhelp","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","critical error"],"aliases":["CRITICAL ERROR 153"]},{"id":51304,"title":"DOS CRITICAL ERROR 154 - CRC error in data","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","critical error"],"keywords":["154","DOS critical error 154","CRC error in data","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"CRITICAL ERROR 154","eventId":"","severity":"High","summary":"DOS critical error 154 indicates crc error in data. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported crc error in data while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported crc error in data.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS critical error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","critical error"],"aliases":["CRITICAL ERROR 154"]},{"id":51305,"title":"DOS CRITICAL ERROR 155 - Bad drive request structure length","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","critical error"],"keywords":["155","DOS critical error 155","Bad drive request structure length","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"CRITICAL ERROR 155","eventId":"","severity":"Medium","summary":"DOS critical error 155 indicates bad drive request structure length. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported bad drive request structure length while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported bad drive request structure length.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS critical error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","critical error"],"aliases":["CRITICAL ERROR 155"]},{"id":51306,"title":"DOS CRITICAL ERROR 156 - Disk seek error","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","critical error"],"keywords":["156","DOS critical error 156","Disk seek error","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"CRITICAL ERROR 156","eventId":"","severity":"Medium","summary":"DOS critical error 156 indicates disk seek error. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported disk seek error while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported disk seek error.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS critical error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","critical error"],"aliases":["CRITICAL ERROR 156"]},{"id":51307,"title":"DOS CRITICAL ERROR 157 - Unknown media type","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","critical error"],"keywords":["157","DOS critical error 157","Unknown media type","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"CRITICAL ERROR 157","eventId":"","severity":"Medium","summary":"DOS critical error 157 indicates unknown media type. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported unknown media type while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported unknown media type.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS critical error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","critical error"],"aliases":["CRITICAL ERROR 157"]},{"id":51308,"title":"DOS CRITICAL ERROR 158 - Sector not found","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","critical error"],"keywords":["158","DOS critical error 158","Sector not found","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"CRITICAL ERROR 158","eventId":"","severity":"Medium","summary":"DOS critical error 158 indicates sector not found. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported sector not found while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported sector not found.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS critical error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","critical error"],"aliases":["CRITICAL ERROR 158"]},{"id":51309,"title":"DOS CRITICAL ERROR 159 - Printer out of paper","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","critical error"],"keywords":["159","DOS critical error 159","Printer out of paper","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"CRITICAL ERROR 159","eventId":"","severity":"Medium","summary":"DOS critical error 159 indicates printer out of paper. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported printer out of paper while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported printer out of paper.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS critical error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","critical error"],"aliases":["CRITICAL ERROR 159"]},{"id":51310,"title":"DOS CRITICAL ERROR 160 - Device write fault","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","critical error"],"keywords":["160","DOS critical error 160","Device write fault","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"CRITICAL ERROR 160","eventId":"","severity":"High","summary":"DOS critical error 160 indicates device write fault. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported device write fault while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported device write fault.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS critical error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","critical error"],"aliases":["CRITICAL ERROR 160"]},{"id":51311,"title":"DOS CRITICAL ERROR 161 - Device read fault","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","critical error"],"keywords":["161","DOS critical error 161","Device read fault","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"CRITICAL ERROR 161","eventId":"","severity":"High","summary":"DOS critical error 161 indicates device read fault. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported device read fault while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported device read fault.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS critical error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","critical error"],"aliases":["CRITICAL ERROR 161"]},{"id":51312,"title":"DOS CRITICAL ERROR 162 - Hardware failure","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","critical error"],"keywords":["162","DOS critical error 162","Hardware failure","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"CRITICAL ERROR 162","eventId":"","severity":"High","summary":"DOS critical error 162 indicates hardware failure. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported hardware failure while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported hardware failure.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS critical error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","critical error"],"aliases":["CRITICAL ERROR 162"]},{"id":51400,"title":"DOS FATAL ERROR 200 - Division by zero","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","fatal error"],"keywords":["200","DOS fatal error 200","Division by zero","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"FATAL ERROR 200","eventId":"","severity":"High","summary":"DOS fatal error 200 indicates division by zero. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported division by zero while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported division by zero.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS fatal error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","fatal error"],"aliases":["FATAL ERROR 200"]},{"id":51401,"title":"DOS FATAL ERROR 201 - Range check error","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","fatal error"],"keywords":["201","DOS fatal error 201","Range check error","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"FATAL ERROR 201","eventId":"","severity":"High","summary":"DOS fatal error 201 indicates range check error. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported range check error while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported range check error.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS fatal error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","fatal error"],"aliases":["FATAL ERROR 201"]},{"id":51402,"title":"DOS FATAL ERROR 202 - Stack overflow","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","fatal error"],"keywords":["202","DOS fatal error 202","Stack overflow","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"FATAL ERROR 202","eventId":"","severity":"High","summary":"DOS fatal error 202 indicates stack overflow. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported stack overflow while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported stack overflow.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS fatal error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","fatal error"],"aliases":["FATAL ERROR 202"]},{"id":51403,"title":"DOS FATAL ERROR 203 - Heap overflow","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","fatal error"],"keywords":["203","DOS fatal error 203","Heap overflow","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"FATAL ERROR 203","eventId":"","severity":"High","summary":"DOS fatal error 203 indicates heap overflow. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported heap overflow while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported heap overflow.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS fatal error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","fatal error"],"aliases":["FATAL ERROR 203"]},{"id":51404,"title":"DOS FATAL ERROR 204 - Invalid pointer operation","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","fatal error"],"keywords":["204","DOS fatal error 204","Invalid pointer operation","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"FATAL ERROR 204","eventId":"","severity":"High","summary":"DOS fatal error 204 indicates invalid pointer operation. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported invalid pointer operation while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported invalid pointer operation.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS fatal error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","fatal error"],"aliases":["FATAL ERROR 204"]},{"id":51405,"title":"DOS FATAL ERROR 205 - Floating-point overflow","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","fatal error"],"keywords":["205","DOS fatal error 205","Floating-point overflow","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"FATAL ERROR 205","eventId":"","severity":"High","summary":"DOS fatal error 205 indicates floating-point overflow. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported floating-point overflow while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported floating-point overflow.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS fatal error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","fatal error"],"aliases":["FATAL ERROR 205"]},{"id":51406,"title":"DOS FATAL ERROR 206 - Floating-point underflow","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","fatal error"],"keywords":["206","DOS fatal error 206","Floating-point underflow","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"FATAL ERROR 206","eventId":"","severity":"High","summary":"DOS fatal error 206 indicates floating-point underflow. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported floating-point underflow while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported floating-point underflow.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS fatal error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","fatal error"],"aliases":["FATAL ERROR 206"]},{"id":51407,"title":"DOS FATAL ERROR 207 - Invalid floating-point operation","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","fatal error"],"keywords":["207","DOS fatal error 207","Invalid floating-point operation","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"FATAL ERROR 207","eventId":"","severity":"High","summary":"DOS fatal error 207 indicates invalid floating-point operation. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported invalid floating-point operation while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported invalid floating-point operation.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS fatal error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","fatal error"],"aliases":["FATAL ERROR 207"]},{"id":51408,"title":"DOS FATAL ERROR 208 - Overlay manager not installed","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","fatal error"],"keywords":["208","DOS fatal error 208","Overlay manager not installed","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"FATAL ERROR 208","eventId":"","severity":"High","summary":"DOS fatal error 208 indicates overlay manager not installed. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported overlay manager not installed while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported overlay manager not installed.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS fatal error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","fatal error"],"aliases":["FATAL ERROR 208"]},{"id":51409,"title":"DOS FATAL ERROR 209 - Overlay file read error","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","fatal error"],"keywords":["209","DOS fatal error 209","Overlay file read error","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"FATAL ERROR 209","eventId":"","severity":"High","summary":"DOS fatal error 209 indicates overlay file read error. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported overlay file read error while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported overlay file read error.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS fatal error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","fatal error"],"aliases":["FATAL ERROR 209"]},{"id":51410,"title":"DOS FATAL ERROR 210 - Object not initialized","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","fatal error"],"keywords":["210","DOS fatal error 210","Object not initialized","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"FATAL ERROR 210","eventId":"","severity":"High","summary":"DOS fatal error 210 indicates object not initialized. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported object not initialized while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported object not initialized.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS fatal error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","fatal error"],"aliases":["FATAL ERROR 210"]},{"id":51411,"title":"DOS FATAL ERROR 211 - Call to abstract method","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","fatal error"],"keywords":["211","DOS fatal error 211","Call to abstract method","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"FATAL ERROR 211","eventId":"","severity":"High","summary":"DOS fatal error 211 indicates call to abstract method. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported call to abstract method while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported call to abstract method.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS fatal error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","fatal error"],"aliases":["FATAL ERROR 211"]},{"id":51412,"title":"DOS FATAL ERROR 212 - Stream registration error","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","fatal error"],"keywords":["212","DOS fatal error 212","Stream registration error","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"FATAL ERROR 212","eventId":"","severity":"High","summary":"DOS fatal error 212 indicates stream registration error. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported stream registration error while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported stream registration error.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS fatal error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","fatal error"],"aliases":["FATAL ERROR 212"]},{"id":51413,"title":"DOS FATAL ERROR 213 - Collection index out of range","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","fatal error"],"keywords":["213","DOS fatal error 213","Collection index out of range","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"FATAL ERROR 213","eventId":"","severity":"High","summary":"DOS fatal error 213 indicates collection index out of range. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported collection index out of range while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported collection index out of range.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS fatal error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","fatal error"],"aliases":["FATAL ERROR 213"]},{"id":51414,"title":"DOS FATAL ERROR 214 - Collection overflow","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","fatal error"],"keywords":["214","DOS fatal error 214","Collection overflow","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"FATAL ERROR 214","eventId":"","severity":"High","summary":"DOS fatal error 214 indicates collection overflow. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported collection overflow while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported collection overflow.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS fatal error. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","fatal error"],"aliases":["FATAL ERROR 214"]},{"id":51500,"title":"DOS ERROR CLASS 01 - Out of resources or space","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","error class"],"keywords":["01","DOS error class 01","Out of resources or space","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"ERROR CLASS 01","eventId":"","severity":"Medium","summary":"DOS error class 01 indicates out of resources or space. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported out of resources or space while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported out of resources or space.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error class. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","error class"],"aliases":["ERROR CLASS 01"]},{"id":51501,"title":"DOS ERROR CLASS 02 - Temporary situation such as a file lock","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","error class"],"keywords":["02","DOS error class 02","Temporary situation such as a file lock","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"ERROR CLASS 02","eventId":"","severity":"Low","summary":"DOS error class 02 indicates temporary situation such as a file lock. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported temporary situation such as a file lock while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported temporary situation such as a file lock.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error class. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","error class"],"aliases":["ERROR CLASS 02"]},{"id":51502,"title":"DOS ERROR CLASS 03 - Authorization or permission denied","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","error class"],"keywords":["03","DOS error class 03","Authorization or permission denied","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"ERROR CLASS 03","eventId":"","severity":"Medium","summary":"DOS error class 03 indicates authorization or permission denied. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported authorization or permission denied while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported authorization or permission denied.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error class. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","error class"],"aliases":["ERROR CLASS 03"]},{"id":51503,"title":"DOS ERROR CLASS 04 - Internal system error","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","error class"],"keywords":["04","DOS error class 04","Internal system error","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"ERROR CLASS 04","eventId":"","severity":"Medium","summary":"DOS error class 04 indicates internal system error. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported internal system error while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported internal system error.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error class. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","error class"],"aliases":["ERROR CLASS 04"]},{"id":51504,"title":"DOS ERROR CLASS 05 - Hardware failure","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","error class"],"keywords":["05","DOS error class 05","Hardware failure","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"ERROR CLASS 05","eventId":"","severity":"High","summary":"DOS error class 05 indicates hardware failure. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported hardware failure while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported hardware failure.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error class. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","error class"],"aliases":["ERROR CLASS 05"]},{"id":51505,"title":"DOS ERROR CLASS 06 - System failure or invalid configuration","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","error class"],"keywords":["06","DOS error class 06","System failure or invalid configuration","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"ERROR CLASS 06","eventId":"","severity":"Medium","summary":"DOS error class 06 indicates system failure or invalid configuration. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported system failure or invalid configuration while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported system failure or invalid configuration.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error class. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","error class"],"aliases":["ERROR CLASS 06"]},{"id":51506,"title":"DOS ERROR CLASS 07 - Application error or inconsistent request","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","error class"],"keywords":["07","DOS error class 07","Application error or inconsistent request","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"ERROR CLASS 07","eventId":"","severity":"Medium","summary":"DOS error class 07 indicates application error or inconsistent request. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported application error or inconsistent request while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported application error or inconsistent request.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error class. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","error class"],"aliases":["ERROR CLASS 07"]},{"id":51507,"title":"DOS ERROR CLASS 08 - File or item not found","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","error class"],"keywords":["08","DOS error class 08","File or item not found","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"ERROR CLASS 08","eventId":"","severity":"Medium","summary":"DOS error class 08 indicates file or item not found. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported file or item not found while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported file or item not found.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error class. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","error class"],"aliases":["ERROR CLASS 08"]},{"id":51508,"title":"DOS ERROR CLASS 09 - Invalid file or item format","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","error class"],"keywords":["09","DOS error class 09","Invalid file or item format","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"ERROR CLASS 09","eventId":"","severity":"Medium","summary":"DOS error class 09 indicates invalid file or item format. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported invalid file or item format while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported invalid file or item format.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error class. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk\nhelp","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","error class"],"aliases":["ERROR CLASS 09"]},{"id":51509,"title":"DOS ERROR CLASS 0A - File or item locked","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","error class"],"keywords":["0A","DOS error class 0A","File or item locked","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"ERROR CLASS 0A","eventId":"","severity":"Medium","summary":"DOS error class 0A indicates file or item locked. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported file or item locked while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported file or item locked.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error class. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","error class"],"aliases":["ERROR CLASS 0A"]},{"id":51510,"title":"DOS ERROR CLASS 0B - Media, ECC, CRC, or disk failure","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","error class"],"keywords":["0B","DOS error class 0B","Media, ECC, CRC, or disk failure","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"ERROR CLASS 0B","eventId":"","severity":"High","summary":"DOS error class 0B indicates media, ecc, crc, or disk failure. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported media, ecc, crc, or disk failure while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported media, ecc, crc, or disk failure.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error class. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","error class"],"aliases":["ERROR CLASS 0B"]},{"id":51511,"title":"DOS ERROR CLASS 0C - Item already exists","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","error class"],"keywords":["0C","DOS error class 0C","Item already exists","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"ERROR CLASS 0C","eventId":"","severity":"Medium","summary":"DOS error class 0C indicates item already exists. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported item already exists while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported item already exists.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error class. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","error class"],"aliases":["ERROR CLASS 0C"]},{"id":51512,"title":"DOS ERROR CLASS 0D - Unknown or inappropriate classification","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","error class"],"keywords":["0D","DOS error class 0D","Unknown or inappropriate classification","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"ERROR CLASS 0D","eventId":"","severity":"Medium","summary":"DOS error class 0D indicates unknown or inappropriate classification. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported unknown or inappropriate classification while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported unknown or inappropriate classification.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error class. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","error class"],"aliases":["ERROR CLASS 0D"]},{"id":51600,"title":"DOS ACTION CODE 01 - Retry the operation a few times and re-prompt","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","action code"],"keywords":["01","DOS action code 01","Retry the operation a few times and re-prompt","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"ACTION CODE 01","eventId":"","severity":"Medium","summary":"DOS action code 01 indicates retry the operation a few times and re-prompt. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported retry the operation a few times and re-prompt while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported retry the operation a few times and re-prompt.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS action code. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","action code"],"aliases":["ACTION CODE 01"]},{"id":51601,"title":"DOS ACTION CODE 02 - Pause and retry the operation","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","action code"],"keywords":["02","DOS action code 02","Pause and retry the operation","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"ACTION CODE 02","eventId":"","severity":"Medium","summary":"DOS action code 02 indicates pause and retry the operation. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported pause and retry the operation while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported pause and retry the operation.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS action code. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","action code"],"aliases":["ACTION CODE 02"]},{"id":51602,"title":"DOS ACTION CODE 03 - Prompt the user to re-enter input","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","action code"],"keywords":["03","DOS action code 03","Prompt the user to re-enter input","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"ACTION CODE 03","eventId":"","severity":"Medium","summary":"DOS action code 03 indicates prompt the user to re-enter input. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported prompt the user to re-enter input while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported prompt the user to re-enter input.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS action code. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","action code"],"aliases":["ACTION CODE 03"]},{"id":51603,"title":"DOS ACTION CODE 04 - Abort with orderly cleanup","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","action code"],"keywords":["04","DOS action code 04","Abort with orderly cleanup","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"ACTION CODE 04","eventId":"","severity":"Medium","summary":"DOS action code 04 indicates abort with orderly cleanup. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported abort with orderly cleanup while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported abort with orderly cleanup.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS action code. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","action code"],"aliases":["ACTION CODE 04"]},{"id":51604,"title":"DOS ACTION CODE 05 - Abort immediately without cleanup","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","action code"],"keywords":["05","DOS action code 05","Abort immediately without cleanup","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"ACTION CODE 05","eventId":"","severity":"Medium","summary":"DOS action code 05 indicates abort immediately without cleanup. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported abort immediately without cleanup while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported abort immediately without cleanup.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS action code. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\ndir\nattrib\nchkdsk","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","action code"],"aliases":["ACTION CODE 05"]},{"id":51605,"title":"DOS ACTION CODE 06 - Ignore the error","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","action code"],"keywords":["06","DOS action code 06","Ignore the error","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"ACTION CODE 06","eventId":"","severity":"Medium","summary":"DOS action code 06 indicates ignore the error. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported ignore the error while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported ignore the error.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS action code. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","action code"],"aliases":["ACTION CODE 06"]},{"id":51606,"title":"DOS ACTION CODE 07 - Request user intervention, then retry","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","action code"],"keywords":["07","DOS action code 07","Request user intervention, then retry","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"ACTION CODE 07","eventId":"","severity":"Medium","summary":"DOS action code 07 indicates request user intervention, then retry. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported request user intervention, then retry while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported request user intervention, then retry.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS action code. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","action code"],"aliases":["ACTION CODE 07"]},{"id":51700,"title":"DOS ERROR LOCUS 01 - Unknown location","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","error locus"],"keywords":["01","DOS error locus 01","Unknown location","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"ERROR LOCUS 01","eventId":"","severity":"Medium","summary":"DOS error locus 01 indicates unknown location. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported unknown location while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported unknown location.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error locus. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","error locus"],"aliases":["ERROR LOCUS 01"]},{"id":51701,"title":"DOS ERROR LOCUS 02 - Block device","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","error locus"],"keywords":["02","DOS error locus 02","Block device","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"ERROR LOCUS 02","eventId":"","severity":"Medium","summary":"DOS error locus 02 indicates block device. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported block device while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported block device.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error locus. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","error locus"],"aliases":["ERROR LOCUS 02"]},{"id":51702,"title":"DOS ERROR LOCUS 03 - Network","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","error locus"],"keywords":["03","DOS error locus 03","Network","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"ERROR LOCUS 03","eventId":"","severity":"Medium","summary":"DOS error locus 03 indicates network. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported network while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported network.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error locus. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nnet use\nnet view","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","error locus"],"aliases":["ERROR LOCUS 03"]},{"id":51703,"title":"DOS ERROR LOCUS 04 - Serial device","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","error locus"],"keywords":["04","DOS error locus 04","Serial device","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"ERROR LOCUS 04","eventId":"","severity":"Medium","summary":"DOS error locus 04 indicates serial device. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported serial device while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported serial device.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error locus. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","error locus"],"aliases":["ERROR LOCUS 04"]},{"id":51704,"title":"DOS ERROR LOCUS 05 - Memory","category":"DOS / Legacy","product":"DOS / Legacy Runtime","tags":["DOS","Legacy","error locus"],"keywords":["05","DOS error locus 05","Memory","DOS","MS-DOS","command prompt","INT 21h","INT 24h"],"errorCode":"ERROR LOCUS 05","eventId":"","severity":"Medium","summary":"DOS error locus 05 indicates memory. Interpret the value within its named error family rather than as a generic DOS code.","rootCause":"The operation reported memory while processing a legacy DOS command, device, file, network request, or runtime operation. Exact causes depend on the program, DOS version, redirector, and hardware or emulation environment.","resolution":"1. Record the command, program, DOS version, and complete message.\n2. Run ver and echo %ERRORLEVEL% to capture the environment and returned status.\n3. Use the read-only checks below that apply to the affected file, disk, memory, or network resource.\n4. Correct the confirmed path, syntax, permission, device, capacity, or connectivity problem.\n5. Retry and confirm the command completes normally.","emailScript":"Hello,\n\nWe reviewed the legacy command-line issue and found that it reported memory.\n\nWe are checking the affected command, file, device, or network resource and will retry the operation after correcting the confirmed cause.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"1. Note the complete message and command that was entered.\n2. Do not format a disk or repeatedly power off the computer.\n3. Confirm any removable disk, cable, printer, or network connection is available.\n4. Send the exact message to IT Support.","notes":"Namespace: DOS error locus. This family reuses numbers found in other DOS namespaces; do not merge it with INT 21h meanings.\n\nRelevant read-only commands:\nver\necho %ERRORLEVEL%\nset\nmem /c","sourceDocument":"User-provided DOS error-code compilation","platforms":["windows"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["DOS"],"technologies":["DOS","Legacy","error locus"],"aliases":["ERROR LOCUS 05"]},{"id":52000,"title":"C64 KERNAL 1 - TOO MANY FILES","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 KERNAL","Error Message"],"keywords":["C64 KERNAL 1 - TOO MANY FILES","1 / $01","More files are open than the KERNAL can manage","Commodore 64","C64","CBM","C64 KERNAL","BASIC V2","KERNAL","1541"],"errorCode":"1 / $01","eventId":"","severity":"Low","summary":"More files are open than the KERNAL can manage","rootCause":"More files are open than the KERNAL can manage. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 KERNAL 1 - TOO MANY FILES.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 KERNAL.\nBASIC message: TOO MANY FILES. KERNAL execution address: $F6FB. The carry flag indicates a KERNAL routine error and the accumulator returns the code where applicable.\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 KERNAL","Error Message"],"aliases":["1 / $01"]},{"id":52001,"title":"C64 KERNAL 2 - FILE OPEN","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 KERNAL","Error Message"],"keywords":["C64 KERNAL 2 - FILE OPEN","2 / $02","The requested logical file number is already open","Commodore 64","C64","CBM","C64 KERNAL","BASIC V2","KERNAL","1541"],"errorCode":"2 / $02","eventId":"","severity":"Low","summary":"The requested logical file number is already open","rootCause":"The requested logical file number is already open. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 KERNAL 2 - FILE OPEN.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 KERNAL.\nBASIC message: FILE OPEN. KERNAL execution address: $F6FE. The carry flag indicates a KERNAL routine error and the accumulator returns the code where applicable.\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 KERNAL","Error Message"],"aliases":["2 / $02"]},{"id":52002,"title":"C64 KERNAL 3 - FILE NOT OPEN","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 KERNAL","Error Message"],"keywords":["C64 KERNAL 3 - FILE NOT OPEN","3 / $03","The requested logical file was not opened first","Commodore 64","C64","CBM","C64 KERNAL","BASIC V2","KERNAL","1541"],"errorCode":"3 / $03","eventId":"","severity":"Low","summary":"The requested logical file was not opened first","rootCause":"The requested logical file was not opened first. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 KERNAL 3 - FILE NOT OPEN.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 KERNAL.\nBASIC message: FILE NOT OPEN. KERNAL execution address: $F701. The carry flag indicates a KERNAL routine error and the accumulator returns the code where applicable.\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 KERNAL","Error Message"],"aliases":["3 / $03"]},{"id":52003,"title":"C64 KERNAL 4 - FILE NOT FOUND","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 KERNAL","Error Message"],"keywords":["C64 KERNAL 4 - FILE NOT FOUND","4 / $04","The requested tape or disk file was not found","Commodore 64","C64","CBM","C64 KERNAL","BASIC V2","KERNAL","1541"],"errorCode":"4 / $04","eventId":"","severity":"Low","summary":"The requested tape or disk file was not found","rootCause":"The requested tape or disk file was not found. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 KERNAL 4 - FILE NOT FOUND.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 KERNAL.\nBASIC message: FILE NOT FOUND. KERNAL execution address: $F704. The carry flag indicates a KERNAL routine error and the accumulator returns the code where applicable.\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 KERNAL","Error Message"],"aliases":["4 / $04"]},{"id":52004,"title":"C64 KERNAL 5 - DEVICE NOT PRESENT","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 KERNAL","Error Message"],"keywords":["C64 KERNAL 5 - DEVICE NOT PRESENT","5 / $05","The requested I/O device did not respond","Commodore 64","C64","CBM","C64 KERNAL","BASIC V2","KERNAL","1541"],"errorCode":"5 / $05","eventId":"","severity":"Medium","summary":"The requested I/O device did not respond","rootCause":"The requested I/O device did not respond. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 KERNAL 5 - DEVICE NOT PRESENT.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 KERNAL.\nBASIC message: DEVICE NOT PRESENT. KERNAL execution address: $F707. The carry flag indicates a KERNAL routine error and the accumulator returns the code where applicable.\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 KERNAL","Error Message"],"aliases":["5 / $05"]},{"id":52005,"title":"C64 KERNAL 6 - NOT INPUT FILE","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 KERNAL","Error Message"],"keywords":["C64 KERNAL 6 - NOT INPUT FILE","6 / $06","The file was opened for output rather than input","Commodore 64","C64","CBM","C64 KERNAL","BASIC V2","KERNAL","1541"],"errorCode":"6 / $06","eventId":"","severity":"Low","summary":"The file was opened for output rather than input","rootCause":"The file was opened for output rather than input. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 KERNAL 6 - NOT INPUT FILE.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 KERNAL.\nBASIC message: NOT INPUT FILE. KERNAL execution address: $F70A. The carry flag indicates a KERNAL routine error and the accumulator returns the code where applicable.\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 KERNAL","Error Message"],"aliases":["6 / $06"]},{"id":52006,"title":"C64 KERNAL 7 - NOT OUTPUT FILE","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 KERNAL","Error Message"],"keywords":["C64 KERNAL 7 - NOT OUTPUT FILE","7 / $07","The file was opened for input rather than output","Commodore 64","C64","CBM","C64 KERNAL","BASIC V2","KERNAL","1541"],"errorCode":"7 / $07","eventId":"","severity":"Low","summary":"The file was opened for input rather than output","rootCause":"The file was opened for input rather than output. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 KERNAL 7 - NOT OUTPUT FILE.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 KERNAL.\nBASIC message: NOT OUTPUT FILE. KERNAL execution address: $F70D. The carry flag indicates a KERNAL routine error and the accumulator returns the code where applicable.\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 KERNAL","Error Message"],"aliases":["7 / $07"]},{"id":52007,"title":"C64 KERNAL 8 - MISSING FILENAME","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 KERNAL","Error Message"],"keywords":["C64 KERNAL 8 - MISSING FILENAME","8 / $08","The file operation did not include a filename","Commodore 64","C64","CBM","C64 KERNAL","BASIC V2","KERNAL","1541"],"errorCode":"8 / $08","eventId":"","severity":"Low","summary":"The file operation did not include a filename","rootCause":"The file operation did not include a filename. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 KERNAL 8 - MISSING FILENAME.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 KERNAL.\nBASIC message: MISSING FILENAME. KERNAL execution address: $F710. The carry flag indicates a KERNAL routine error and the accumulator returns the code where applicable.\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 KERNAL","Error Message"],"aliases":["8 / $08"]},{"id":52008,"title":"C64 KERNAL 9 - ILLEGAL DEVICE NUMBER","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 KERNAL","Error Message"],"keywords":["C64 KERNAL 9 - ILLEGAL DEVICE NUMBER","9 / $09","The specified device number is invalid","Commodore 64","C64","CBM","C64 KERNAL","BASIC V2","KERNAL","1541"],"errorCode":"9 / $09","eventId":"","severity":"Medium","summary":"The specified device number is invalid","rootCause":"The specified device number is invalid. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 KERNAL 9 - ILLEGAL DEVICE NUMBER.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 KERNAL.\nBASIC message: ILLEGAL DEVICE NUMBER. KERNAL execution address: $F713. The carry flag indicates a KERNAL routine error and the accumulator returns the code where applicable.\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 KERNAL","Error Message"],"aliases":["9 / $09"]},{"id":52100,"title":"C64 BASIC - BAD DATA","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - BAD DATA","BAD DATA","String data was read when numeric data was expected","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"BAD DATA","eventId":"","severity":"Low","summary":"String data was read when numeric data was expected","rootCause":"String data was read when numeric data was expected. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - BAD DATA.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["BAD DATA"]},{"id":52101,"title":"C64 BASIC - BAD SUBSCRIPT","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - BAD SUBSCRIPT","BAD SUBSCRIPT","An array element is outside the range established by DIM","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"BAD SUBSCRIPT","eventId":"","severity":"Low","summary":"An array element is outside the range established by DIM","rootCause":"An array element is outside the range established by DIM. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - BAD SUBSCRIPT.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["BAD SUBSCRIPT"]},{"id":52102,"title":"C64 BASIC - BREAK","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - BREAK","BREAK","Program execution stopped after the STOP key was pressed","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"BREAK","eventId":"","severity":"Low","summary":"Program execution stopped after the STOP key was pressed","rootCause":"Program execution stopped after the STOP key was pressed. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - BREAK.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["BREAK"]},{"id":52103,"title":"C64 BASIC - CAN'T CONTINUE","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - CAN'T CONTINUE","CAN'T CONTINUE","CONT cannot resume because the program was not run, an error occurred, or a line was edited","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"CAN'T CONTINUE","eventId":"","severity":"Low","summary":"CONT cannot resume because the program was not run, an error occurred, or a line was edited","rootCause":"CONT cannot resume because the program was not run, an error occurred, or a line was edited. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - CAN'T CONTINUE.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["CAN'T CONTINUE"]},{"id":52104,"title":"C64 BASIC - DEVICE NOT PRESENT","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - DEVICE NOT PRESENT","DEVICE NOT PRESENT","The required I/O device was unavailable for the requested file operation","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"DEVICE NOT PRESENT","eventId":"","severity":"Medium","summary":"The required I/O device was unavailable for the requested file operation","rootCause":"The required I/O device was unavailable for the requested file operation. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - DEVICE NOT PRESENT.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["DEVICE NOT PRESENT"]},{"id":52105,"title":"C64 BASIC - DIVISION BY ZERO","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - DIVISION BY ZERO","DIVISION BY ZERO","A calculation attempted to divide by zero","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"DIVISION BY ZERO","eventId":"","severity":"Low","summary":"A calculation attempted to divide by zero","rootCause":"A calculation attempted to divide by zero. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - DIVISION BY ZERO.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["DIVISION BY ZERO"]},{"id":52106,"title":"C64 BASIC - EXTRA IGNORED","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - EXTRA IGNORED","EXTRA IGNORED","More INPUT values were entered than the program requested","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"EXTRA IGNORED","eventId":"","severity":"Low","summary":"More INPUT values were entered than the program requested","rootCause":"More INPUT values were entered than the program requested. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - EXTRA IGNORED.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["EXTRA IGNORED"]},{"id":52107,"title":"C64 BASIC - FILE NOT FOUND","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - FILE NOT FOUND","FILE NOT FOUND","The named disk file does not exist or the end of tape was reached","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"FILE NOT FOUND","eventId":"","severity":"Low","summary":"The named disk file does not exist or the end of tape was reached","rootCause":"The named disk file does not exist or the end of tape was reached. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - FILE NOT FOUND.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["FILE NOT FOUND"]},{"id":52108,"title":"C64 BASIC - FILE NOT OPEN","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - FILE NOT OPEN","FILE NOT OPEN","CLOSE, CMD, PRINT#, INPUT#, or GET# referenced a file that was not open","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"FILE NOT OPEN","eventId":"","severity":"Low","summary":"CLOSE, CMD, PRINT#, INPUT#, or GET# referenced a file that was not open","rootCause":"CLOSE, CMD, PRINT#, INPUT#, or GET# referenced a file that was not open. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - FILE NOT OPEN.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["FILE NOT OPEN"]},{"id":52109,"title":"C64 BASIC - FILE OPEN","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - FILE OPEN","FILE OPEN","The program attempted to reuse an open logical file number","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"FILE OPEN","eventId":"","severity":"Low","summary":"The program attempted to reuse an open logical file number","rootCause":"The program attempted to reuse an open logical file number. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - FILE OPEN.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["FILE OPEN"]},{"id":52110,"title":"C64 BASIC - FORMULA TOO COMPLEX","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - FORMULA TOO COMPLEX","FORMULA TOO COMPLEX","An expression contains excessive nesting, parentheses, or string complexity","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"FORMULA TOO COMPLEX","eventId":"","severity":"Low","summary":"An expression contains excessive nesting, parentheses, or string complexity","rootCause":"An expression contains excessive nesting, parentheses, or string complexity. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - FORMULA TOO COMPLEX.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["FORMULA TOO COMPLEX"]},{"id":52111,"title":"C64 BASIC - ILLEGAL DIRECT","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - ILLEGAL DIRECT","ILLEGAL DIRECT","INPUT was entered in direct mode instead of within a program","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"ILLEGAL DIRECT","eventId":"","severity":"Low","summary":"INPUT was entered in direct mode instead of within a program","rootCause":"INPUT was entered in direct mode instead of within a program. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - ILLEGAL DIRECT.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["ILLEGAL DIRECT"]},{"id":52112,"title":"C64 BASIC - ILLEGAL QUANTITY","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - ILLEGAL QUANTITY","ILLEGAL QUANTITY","A function or statement argument is outside its permitted range","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"ILLEGAL QUANTITY","eventId":"","severity":"Low","summary":"A function or statement argument is outside its permitted range","rootCause":"A function or statement argument is outside its permitted range. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - ILLEGAL QUANTITY.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["ILLEGAL QUANTITY"]},{"id":52113,"title":"C64 BASIC - LOAD","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - LOAD","LOAD","The program stored on tape could not be loaded correctly","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"LOAD","eventId":"","severity":"Medium","summary":"The program stored on tape could not be loaded correctly","rootCause":"The program stored on tape could not be loaded correctly. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - LOAD.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["LOAD"]},{"id":52114,"title":"C64 BASIC - NEXT WITHOUT FOR","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - NEXT WITHOUT FOR","NEXT WITHOUT FOR","A NEXT statement has no matching FOR loop or uses the wrong variable","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"NEXT WITHOUT FOR","eventId":"","severity":"Low","summary":"A NEXT statement has no matching FOR loop or uses the wrong variable","rootCause":"A NEXT statement has no matching FOR loop or uses the wrong variable. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - NEXT WITHOUT FOR.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["NEXT WITHOUT FOR"]},{"id":52115,"title":"C64 BASIC - NOT INPUT FILE","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - NOT INPUT FILE","NOT INPUT FILE","INPUT# or GET# referenced a file opened only for output","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"NOT INPUT FILE","eventId":"","severity":"Low","summary":"INPUT# or GET# referenced a file opened only for output","rootCause":"INPUT# or GET# referenced a file opened only for output. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - NOT INPUT FILE.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["NOT INPUT FILE"]},{"id":52116,"title":"C64 BASIC - NOT OUTPUT FILE","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - NOT OUTPUT FILE","NOT OUTPUT FILE","PRINT# referenced a file opened only for input","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"NOT OUTPUT FILE","eventId":"","severity":"Low","summary":"PRINT# referenced a file opened only for input","rootCause":"PRINT# referenced a file opened only for input. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - NOT OUTPUT FILE.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["NOT OUTPUT FILE"]},{"id":52117,"title":"C64 BASIC - OUT OF DATA","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - OUT OF DATA","OUT OF DATA","READ executed after all DATA values were consumed","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"OUT OF DATA","eventId":"","severity":"Low","summary":"READ executed after all DATA values were consumed","rootCause":"READ executed after all DATA values were consumed. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - OUT OF DATA.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["OUT OF DATA"]},{"id":52118,"title":"C64 BASIC - OUT OF MEMORY","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - OUT OF MEMORY","OUT OF MEMORY","Available RAM, FOR-loop stack, or GOSUB stack capacity was exhausted","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"OUT OF MEMORY","eventId":"","severity":"Medium","summary":"Available RAM, FOR-loop stack, or GOSUB stack capacity was exhausted","rootCause":"Available RAM, FOR-loop stack, or GOSUB stack capacity was exhausted. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - OUT OF MEMORY.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["OUT OF MEMORY"]},{"id":52119,"title":"C64 BASIC - OVERFLOW","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - OVERFLOW","OVERFLOW","A calculation exceeded the largest supported numeric value","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"OVERFLOW","eventId":"","severity":"Medium","summary":"A calculation exceeded the largest supported numeric value","rootCause":"A calculation exceeded the largest supported numeric value. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - OVERFLOW.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["OVERFLOW"]},{"id":52120,"title":"C64 BASIC - REDIM'D ARRAY","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - REDIM'D ARRAY","REDIM'D ARRAY","DIM attempted to dimension an array that was already dimensioned or used","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"REDIM'D ARRAY","eventId":"","severity":"Low","summary":"DIM attempted to dimension an array that was already dimensioned or used","rootCause":"DIM attempted to dimension an array that was already dimensioned or used. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - REDIM'D ARRAY.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["REDIM'D ARRAY"]},{"id":52121,"title":"C64 BASIC - REDO FROM START","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - REDO FROM START","REDO FROM START","INPUT received characters when the program expected a number","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"REDO FROM START","eventId":"","severity":"Low","summary":"INPUT received characters when the program expected a number","rootCause":"INPUT received characters when the program expected a number. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - REDO FROM START.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["REDO FROM START"]},{"id":52122,"title":"C64 BASIC - RETURN WITHOUT GOSUB","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - RETURN WITHOUT GOSUB","RETURN WITHOUT GOSUB","RETURN executed without an active GOSUB","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"RETURN WITHOUT GOSUB","eventId":"","severity":"Low","summary":"RETURN executed without an active GOSUB","rootCause":"RETURN executed without an active GOSUB. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - RETURN WITHOUT GOSUB.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["RETURN WITHOUT GOSUB"]},{"id":52123,"title":"C64 BASIC - STRING TOO LONG","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - STRING TOO LONG","STRING TOO LONG","A string exceeded the 255-character limit","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"STRING TOO LONG","eventId":"","severity":"Low","summary":"A string exceeded the 255-character limit","rootCause":"A string exceeded the 255-character limit. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - STRING TOO LONG.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["STRING TOO LONG"]},{"id":52124,"title":"C64 BASIC - SYNTAX ERROR","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - SYNTAX ERROR","SYNTAX ERROR","BASIC could not recognize the statement because of spelling, punctuation, or structure","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"SYNTAX ERROR","eventId":"","severity":"Low","summary":"BASIC could not recognize the statement because of spelling, punctuation, or structure","rootCause":"BASIC could not recognize the statement because of spelling, punctuation, or structure. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - SYNTAX ERROR.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["SYNTAX ERROR"]},{"id":52125,"title":"C64 BASIC - TYPE MISMATCH","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - TYPE MISMATCH","TYPE MISMATCH","A numeric value was used where a string was required, or the reverse","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"TYPE MISMATCH","eventId":"","severity":"Low","summary":"A numeric value was used where a string was required, or the reverse","rootCause":"A numeric value was used where a string was required, or the reverse. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - TYPE MISMATCH.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["TYPE MISMATCH"]},{"id":52126,"title":"C64 BASIC - UNDEF'D FUNCTION","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - UNDEF'D FUNCTION","UNDEF'D FUNCTION","A user-defined function was referenced before DEF FN defined it","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"UNDEF'D FUNCTION","eventId":"","severity":"Low","summary":"A user-defined function was referenced before DEF FN defined it","rootCause":"A user-defined function was referenced before DEF FN defined it. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - UNDEF'D FUNCTION.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["UNDEF'D FUNCTION"]},{"id":52127,"title":"C64 BASIC - UNDEF'D STATEMENT","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - UNDEF'D STATEMENT","UNDEF'D STATEMENT","GOTO, GOSUB, or RUN referenced a line number that does not exist","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"UNDEF'D STATEMENT","eventId":"","severity":"Low","summary":"GOTO, GOSUB, or RUN referenced a line number that does not exist","rootCause":"GOTO, GOSUB, or RUN referenced a line number that does not exist. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - UNDEF'D STATEMENT.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["UNDEF'D STATEMENT"]},{"id":52128,"title":"C64 BASIC - VERIFY","category":"Commodore 64","product":"Commodore 64 BASIC V2 / KERNAL","tags":["Commodore 64","C64","C64 BASIC V2","Error Message"],"keywords":["C64 BASIC - VERIFY","VERIFY","The program on tape or disk does not match the program currently in memory","Commodore 64","C64","CBM","C64 BASIC V2","BASIC V2","KERNAL","1541"],"errorCode":"VERIFY","eventId":"","severity":"Medium","summary":"The program on tape or disk does not match the program currently in memory","rootCause":"The program on tape or disk does not match the program currently in memory. Common causes include incorrect BASIC syntax or program state, an invalid logical file operation, unavailable media or hardware, or a mismatch between the requested operation and how the file was opened.","resolution":"1. Record the complete BASIC or KERNAL message and the command or program line.\n2. Use LIST to inspect the affected line and correct filenames, device numbers, logical file numbers, punctuation, variables, or control flow.\n3. For disk operations, confirm the drive is powered, connected, addressed correctly, and can read a known-good directory with LOAD \"$\",8 followed by LIST.\n4. Close conflicting logical files or restart only after saving recoverable program text.\n5. Retry and confirm the operation completes without the message.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 BASIC - VERIFY.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 BASIC V2.\n\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64 BASIC V2"],"technologies":["Commodore 64","C64","C64 BASIC V2","Error Message"],"aliases":["VERIFY"]},{"id":52200,"title":"C64 Hardware - Blank Screen on Power Up","category":"Commodore 64","product":"Commodore 64 / 1541","tags":["Commodore 64","C64","C64 hardware diagnostic","Hardware"],"keywords":["C64 Hardware - Blank Screen on Power Up","Possible power-supply, KERNAL ROM, PLA, 6510 MPU, VIC-II, RAM, or support-circuit failure","Commodore 64","C64","CBM","C64 hardware diagnostic","BASIC V2","KERNAL","1541"],"errorCode":"","eventId":"","severity":"High","summary":"Possible power-supply, KERNAL ROM, PLA, 6510 MPU, VIC-II, RAM, or support-circuit failure","rootCause":"The symptom can be produced by power, cabling, socket, board, IC, ROM, RAM, peripheral, media, or alignment faults. The listed components are diagnostic candidates, not proof that a chip should be replaced.","resolution":"1. Power off the C64 and peripherals before connecting, disconnecting, or opening hardware.\n2. Verify the correct external power supply voltages with qualified equipment; an over-voltage C64 supply can damage chips.\n3. Check cables, sockets, removable media, visible damage, and known-good external components.\n4. Run a diagnostic cartridge or test disk when available and record the exact screen, LED, and drive behavior.\n5. Have an experienced vintage-computer technician test voltages, clocks, reset, buses, and candidate ICs before replacement.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 Hardware - Blank Screen on Power Up.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 hardware diagnostic.\nObserved symptom: Blank Screen on Power Up. Historical candidate causes: Possible power-supply, KERNAL ROM, PLA, 6510 MPU, VIC-II, RAM, or support-circuit failure. Treat component lists as a diagnostic starting point only.\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64"],"technologies":["Commodore 64","C64","C64 hardware diagnostic","Hardware"],"aliases":[]},{"id":52201,"title":"C64 Hardware - Out of Memory on Power Up","category":"Commodore 64","product":"Commodore 64 / 1541","tags":["Commodore 64","C64","C64 hardware diagnostic","Hardware"],"keywords":["C64 Hardware - Out of Memory on Power Up","Possible failed 4164 RAM or related memory circuitry","Commodore 64","C64","CBM","C64 hardware diagnostic","BASIC V2","KERNAL","1541"],"errorCode":"","eventId":"","severity":"High","summary":"Possible failed 4164 RAM or related memory circuitry","rootCause":"The symptom can be produced by power, cabling, socket, board, IC, ROM, RAM, peripheral, media, or alignment faults. The listed components are diagnostic candidates, not proof that a chip should be replaced.","resolution":"1. Power off the C64 and peripherals before connecting, disconnecting, or opening hardware.\n2. Verify the correct external power supply voltages with qualified equipment; an over-voltage C64 supply can damage chips.\n3. Check cables, sockets, removable media, visible damage, and known-good external components.\n4. Run a diagnostic cartridge or test disk when available and record the exact screen, LED, and drive behavior.\n5. Have an experienced vintage-computer technician test voltages, clocks, reset, buses, and candidate ICs before replacement.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 Hardware - Out of Memory on Power Up.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 hardware diagnostic.\nObserved symptom: Out of Memory on Power Up. Historical candidate causes: Possible failed 4164 RAM or related memory circuitry. Treat component lists as a diagnostic starting point only.\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64"],"technologies":["Commodore 64","C64","C64 hardware diagnostic","Hardware"],"aliases":[]},{"id":52202,"title":"C64 Hardware - No Cursor or Intermittent Blank Screen","category":"Commodore 64","product":"Commodore 64 / 1541","tags":["Commodore 64","C64","C64 hardware diagnostic","Hardware"],"keywords":["C64 Hardware - No Cursor or Intermittent Blank Screen","Possible CIA, logic, MPU, ROM, VIC-II, or connection fault","Commodore 64","C64","CBM","C64 hardware diagnostic","BASIC V2","KERNAL","1541"],"errorCode":"","eventId":"","severity":"High","summary":"Possible CIA, logic, MPU, ROM, VIC-II, or connection fault","rootCause":"The symptom can be produced by power, cabling, socket, board, IC, ROM, RAM, peripheral, media, or alignment faults. The listed components are diagnostic candidates, not proof that a chip should be replaced.","resolution":"1. Power off the C64 and peripherals before connecting, disconnecting, or opening hardware.\n2. Verify the correct external power supply voltages with qualified equipment; an over-voltage C64 supply can damage chips.\n3. Check cables, sockets, removable media, visible damage, and known-good external components.\n4. Run a diagnostic cartridge or test disk when available and record the exact screen, LED, and drive behavior.\n5. Have an experienced vintage-computer technician test voltages, clocks, reset, buses, and candidate ICs before replacement.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 Hardware - No Cursor or Intermittent Blank Screen.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 hardware diagnostic.\nObserved symptom: No Cursor or Intermittent Blank Screen. Historical candidate causes: Possible CIA, logic, MPU, ROM, VIC-II, or connection fault. Treat component lists as a diagnostic starting point only.\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64"],"technologies":["Commodore 64","C64","C64 hardware diagnostic","Hardware"],"aliases":[]},{"id":52203,"title":"C64 Hardware - Device Not Present When Using Disk","category":"Commodore 64","product":"Commodore 64 / 1541","tags":["Commodore 64","C64","C64 hardware diagnostic","Hardware"],"keywords":["C64 Hardware - Device Not Present When Using Disk","Check serial cabling and power first; possible 6510, CIA, buffer, or drive-side fault","Commodore 64","C64","CBM","C64 hardware diagnostic","BASIC V2","KERNAL","1541"],"errorCode":"","eventId":"","severity":"High","summary":"Check serial cabling and power first; possible 6510, CIA, buffer, or drive-side fault","rootCause":"The symptom can be produced by power, cabling, socket, board, IC, ROM, RAM, peripheral, media, or alignment faults. The listed components are diagnostic candidates, not proof that a chip should be replaced.","resolution":"1. Power off the C64 and peripherals before connecting, disconnecting, or opening hardware.\n2. Verify the correct external power supply voltages with qualified equipment; an over-voltage C64 supply can damage chips.\n3. Check cables, sockets, removable media, visible damage, and known-good external components.\n4. Run a diagnostic cartridge or test disk when available and record the exact screen, LED, and drive behavior.\n5. Have an experienced vintage-computer technician test voltages, clocks, reset, buses, and candidate ICs before replacement.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 Hardware - Device Not Present When Using Disk.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 hardware diagnostic.\nObserved symptom: Device Not Present When Using Disk. Historical candidate causes: Check serial cabling and power first; possible 6510, CIA, buffer, or drive-side fault. Treat component lists as a diagnostic starting point only.\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64"],"technologies":["Commodore 64","C64","C64 hardware diagnostic","Hardware"],"aliases":[]},{"id":52204,"title":"C64 Hardware - No Sound or Distorted Sound","category":"Commodore 64","product":"Commodore 64 / 1541","tags":["Commodore 64","C64","C64 hardware diagnostic","Hardware"],"keywords":["C64 Hardware - No Sound or Distorted Sound","Possible SID, audio path, RF modulator, power, or external audio fault","Commodore 64","C64","CBM","C64 hardware diagnostic","BASIC V2","KERNAL","1541"],"errorCode":"","eventId":"","severity":"High","summary":"Possible SID, audio path, RF modulator, power, or external audio fault","rootCause":"The symptom can be produced by power, cabling, socket, board, IC, ROM, RAM, peripheral, media, or alignment faults. The listed components are diagnostic candidates, not proof that a chip should be replaced.","resolution":"1. Power off the C64 and peripherals before connecting, disconnecting, or opening hardware.\n2. Verify the correct external power supply voltages with qualified equipment; an over-voltage C64 supply can damage chips.\n3. Check cables, sockets, removable media, visible damage, and known-good external components.\n4. Run a diagnostic cartridge or test disk when available and record the exact screen, LED, and drive behavior.\n5. Have an experienced vintage-computer technician test voltages, clocks, reset, buses, and candidate ICs before replacement.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 Hardware - No Sound or Distorted Sound.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 hardware diagnostic.\nObserved symptom: No Sound or Distorted Sound. Historical candidate causes: Possible SID, audio path, RF modulator, power, or external audio fault. Treat component lists as a diagnostic starting point only.\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64"],"technologies":["Commodore 64","C64","C64 hardware diagnostic","Hardware"],"aliases":[]},{"id":52205,"title":"C64 Hardware - Keyboard Does Not Function Correctly","category":"Commodore 64","product":"Commodore 64 / 1541","tags":["Commodore 64","C64","C64 hardware diagnostic","Hardware"],"keywords":["C64 Hardware - Keyboard Does Not Function Correctly","Possible CIA, keyboard matrix, connector, ROM, or power fault","Commodore 64","C64","CBM","C64 hardware diagnostic","BASIC V2","KERNAL","1541"],"errorCode":"","eventId":"","severity":"High","summary":"Possible CIA, keyboard matrix, connector, ROM, or power fault","rootCause":"The symptom can be produced by power, cabling, socket, board, IC, ROM, RAM, peripheral, media, or alignment faults. The listed components are diagnostic candidates, not proof that a chip should be replaced.","resolution":"1. Power off the C64 and peripherals before connecting, disconnecting, or opening hardware.\n2. Verify the correct external power supply voltages with qualified equipment; an over-voltage C64 supply can damage chips.\n3. Check cables, sockets, removable media, visible damage, and known-good external components.\n4. Run a diagnostic cartridge or test disk when available and record the exact screen, LED, and drive behavior.\n5. Have an experienced vintage-computer technician test voltages, clocks, reset, buses, and candidate ICs before replacement.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 Hardware - Keyboard Does Not Function Correctly.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 hardware diagnostic.\nObserved symptom: Keyboard Does Not Function Correctly. Historical candidate causes: Possible CIA, keyboard matrix, connector, ROM, or power fault. Treat component lists as a diagnostic starting point only.\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64"],"technologies":["Commodore 64","C64","C64 hardware diagnostic","Hardware"],"aliases":[]},{"id":52206,"title":"C64 Hardware - 1541 Motor Runs and LED Stays On","category":"Commodore 64","product":"Commodore 64 / 1541","tags":["Commodore 64","C64","C64 hardware diagnostic","Hardware"],"keywords":["C64 Hardware - 1541 Motor Runs and LED Stays On","Common candidates include DOS ROM, 6502, 6522, RAM, reset logic, or power supply","Commodore 64","C64","CBM","C64 hardware diagnostic","BASIC V2","KERNAL","1541"],"errorCode":"","eventId":"","severity":"High","summary":"Common candidates include DOS ROM, 6502, 6522, RAM, reset logic, or power supply","rootCause":"The symptom can be produced by power, cabling, socket, board, IC, ROM, RAM, peripheral, media, or alignment faults. The listed components are diagnostic candidates, not proof that a chip should be replaced.","resolution":"1. Power off the C64 and peripherals before connecting, disconnecting, or opening hardware.\n2. Verify the correct external power supply voltages with qualified equipment; an over-voltage C64 supply can damage chips.\n3. Check cables, sockets, removable media, visible damage, and known-good external components.\n4. Run a diagnostic cartridge or test disk when available and record the exact screen, LED, and drive behavior.\n5. Have an experienced vintage-computer technician test voltages, clocks, reset, buses, and candidate ICs before replacement.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 Hardware - 1541 Motor Runs and LED Stays On.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 hardware diagnostic.\nObserved symptom: 1541 Motor Runs and LED Stays On. Historical candidate causes: Common candidates include DOS ROM, 6502, 6522, RAM, reset logic, or power supply. Treat component lists as a diagnostic starting point only.\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64"],"technologies":["Commodore 64","C64","C64 hardware diagnostic","Hardware"],"aliases":[]},{"id":52207,"title":"C64 Hardware - 1541 File Not Found on Known-Good Disk","category":"Commodore 64","product":"Commodore 64 / 1541","tags":["Commodore 64","C64","C64 hardware diagnostic","Hardware"],"keywords":["C64 Hardware - 1541 File Not Found on Known-Good Disk","Possible dirty head, sticky rails, alignment, stop adjustment, media, or read-channel fault","Commodore 64","C64","CBM","C64 hardware diagnostic","BASIC V2","KERNAL","1541"],"errorCode":"","eventId":"","severity":"High","summary":"Possible dirty head, sticky rails, alignment, stop adjustment, media, or read-channel fault","rootCause":"The symptom can be produced by power, cabling, socket, board, IC, ROM, RAM, peripheral, media, or alignment faults. The listed components are diagnostic candidates, not proof that a chip should be replaced.","resolution":"1. Power off the C64 and peripherals before connecting, disconnecting, or opening hardware.\n2. Verify the correct external power supply voltages with qualified equipment; an over-voltage C64 supply can damage chips.\n3. Check cables, sockets, removable media, visible damage, and known-good external components.\n4. Run a diagnostic cartridge or test disk when available and record the exact screen, LED, and drive behavior.\n5. Have an experienced vintage-computer technician test voltages, clocks, reset, buses, and candidate ICs before replacement.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 Hardware - 1541 File Not Found on Known-Good Disk.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 hardware diagnostic.\nObserved symptom: 1541 File Not Found on Known-Good Disk. Historical candidate causes: Possible dirty head, sticky rails, alignment, stop adjustment, media, or read-channel fault. Treat component lists as a diagnostic starting point only.\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64"],"technologies":["Commodore 64","C64","C64 hardware diagnostic","Hardware"],"aliases":[]},{"id":52208,"title":"C64 Hardware - 1541 Intermittent Loading","category":"Commodore 64","product":"Commodore 64 / 1541","tags":["Commodore 64","C64","C64 hardware diagnostic","Hardware"],"keywords":["C64 Hardware - 1541 Intermittent Loading","Possible ROM, alignment, serial connection, power, stepper, or read-channel fault","Commodore 64","C64","CBM","C64 hardware diagnostic","BASIC V2","KERNAL","1541"],"errorCode":"","eventId":"","severity":"High","summary":"Possible ROM, alignment, serial connection, power, stepper, or read-channel fault","rootCause":"The symptom can be produced by power, cabling, socket, board, IC, ROM, RAM, peripheral, media, or alignment faults. The listed components are diagnostic candidates, not proof that a chip should be replaced.","resolution":"1. Power off the C64 and peripherals before connecting, disconnecting, or opening hardware.\n2. Verify the correct external power supply voltages with qualified equipment; an over-voltage C64 supply can damage chips.\n3. Check cables, sockets, removable media, visible damage, and known-good external components.\n4. Run a diagnostic cartridge or test disk when available and record the exact screen, LED, and drive behavior.\n5. Have an experienced vintage-computer technician test voltages, clocks, reset, buses, and candidate ICs before replacement.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 Hardware - 1541 Intermittent Loading.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 hardware diagnostic.\nObserved symptom: 1541 Intermittent Loading. Historical candidate causes: Possible ROM, alignment, serial connection, power, stepper, or read-channel fault. Treat component lists as a diagnostic starting point only.\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64"],"technologies":["Commodore 64","C64","C64 hardware diagnostic","Hardware"],"aliases":[]},{"id":52209,"title":"C64 Hardware - 1541 LEDs Flicker Then Go Out","category":"Commodore 64","product":"Commodore 64 / 1541","tags":["Commodore 64","C64","C64 hardware diagnostic","Hardware"],"keywords":["C64 Hardware - 1541 LEDs Flicker Then Go Out","Possible failing rectifier, regulator, transformer, fuse, or supply rail under load","Commodore 64","C64","CBM","C64 hardware diagnostic","BASIC V2","KERNAL","1541"],"errorCode":"","eventId":"","severity":"High","summary":"Possible failing rectifier, regulator, transformer, fuse, or supply rail under load","rootCause":"The symptom can be produced by power, cabling, socket, board, IC, ROM, RAM, peripheral, media, or alignment faults. The listed components are diagnostic candidates, not proof that a chip should be replaced.","resolution":"1. Power off the C64 and peripherals before connecting, disconnecting, or opening hardware.\n2. Verify the correct external power supply voltages with qualified equipment; an over-voltage C64 supply can damage chips.\n3. Check cables, sockets, removable media, visible damage, and known-good external components.\n4. Run a diagnostic cartridge or test disk when available and record the exact screen, LED, and drive behavior.\n5. Have an experienced vintage-computer technician test voltages, clocks, reset, buses, and candidate ICs before replacement.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 Hardware - 1541 LEDs Flicker Then Go Out.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 hardware diagnostic.\nObserved symptom: 1541 LEDs Flicker Then Go Out. Historical candidate causes: Possible failing rectifier, regulator, transformer, fuse, or supply rail under load. Treat component lists as a diagnostic starting point only.\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64"],"technologies":["Commodore 64","C64","C64 hardware diagnostic","Hardware"],"aliases":[]},{"id":52210,"title":"C64 Hardware - Scrolling Band or Wavy Display","category":"Commodore 64","product":"Commodore 64 / 1541","tags":["Commodore 64","C64","C64 hardware diagnostic","Hardware"],"keywords":["C64 Hardware - Scrolling Band or Wavy Display","Check external power supply, regulator, video circuitry, grounding, and VIC-II clock stability","Commodore 64","C64","CBM","C64 hardware diagnostic","BASIC V2","KERNAL","1541"],"errorCode":"","eventId":"","severity":"High","summary":"Check external power supply, regulator, video circuitry, grounding, and VIC-II clock stability","rootCause":"The symptom can be produced by power, cabling, socket, board, IC, ROM, RAM, peripheral, media, or alignment faults. The listed components are diagnostic candidates, not proof that a chip should be replaced.","resolution":"1. Power off the C64 and peripherals before connecting, disconnecting, or opening hardware.\n2. Verify the correct external power supply voltages with qualified equipment; an over-voltage C64 supply can damage chips.\n3. Check cables, sockets, removable media, visible damage, and known-good external components.\n4. Run a diagnostic cartridge or test disk when available and record the exact screen, LED, and drive behavior.\n5. Have an experienced vintage-computer technician test voltages, clocks, reset, buses, and candidate ICs before replacement.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 Hardware - Scrolling Band or Wavy Display.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 hardware diagnostic.\nObserved symptom: Scrolling Band or Wavy Display. Historical candidate causes: Check external power supply, regulator, video circuitry, grounding, and VIC-II clock stability. Treat component lists as a diagnostic starting point only.\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64"],"technologies":["Commodore 64","C64","C64 hardware diagnostic","Hardware"],"aliases":[]},{"id":52211,"title":"C64 Hardware - Garbage or Flashing Characters","category":"Commodore 64","product":"Commodore 64 / 1541","tags":["Commodore 64","C64","C64 hardware diagnostic","Hardware"],"keywords":["C64 Hardware - Garbage or Flashing Characters","Possible RAM, PLA, VIC-II, character ROM, CIA, logic, or power-supply fault","Commodore 64","C64","CBM","C64 hardware diagnostic","BASIC V2","KERNAL","1541"],"errorCode":"","eventId":"","severity":"High","summary":"Possible RAM, PLA, VIC-II, character ROM, CIA, logic, or power-supply fault","rootCause":"The symptom can be produced by power, cabling, socket, board, IC, ROM, RAM, peripheral, media, or alignment faults. The listed components are diagnostic candidates, not proof that a chip should be replaced.","resolution":"1. Power off the C64 and peripherals before connecting, disconnecting, or opening hardware.\n2. Verify the correct external power supply voltages with qualified equipment; an over-voltage C64 supply can damage chips.\n3. Check cables, sockets, removable media, visible damage, and known-good external components.\n4. Run a diagnostic cartridge or test disk when available and record the exact screen, LED, and drive behavior.\n5. Have an experienced vintage-computer technician test voltages, clocks, reset, buses, and candidate ICs before replacement.","emailScript":"Hello,\n\nWe reviewed the Commodore 64 issue and identified C64 Hardware - Garbage or Flashing Characters.\n\nWe are checking the program, connected device, media, cabling, and power conditions before applying the least invasive correction.\n\nPlease avoid repeatedly power-cycling or opening the equipment until testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete message and what you entered immediately before it appeared.\n2. Turn off the computer before reconnecting a disk drive, cassette, cartridge, joystick, or cable.\n3. Do not open the power supply or computer unless you are trained to service vintage electronics.\n4. Send IT Support a clear screen photo and the device setup.","notes":"Namespace: C64 hardware diagnostic.\nObserved symptom: Garbage or Flashing Characters. Historical candidate causes: Possible RAM, PLA, VIC-II, character ROM, CIA, logic, or power-supply fault. Treat component lists as a diagnostic starting point only.\n\nHistorical sources and credit:\n- Commodore 64 Programmer's Reference Guide and User's Guide (Commodore Business Machines)\n- Project 64, managed by Cris Berneburg; diagnostic etext assembled by The Basic Bombardier (C-DIAG10.TXT, June 1996)\n- The Commodore Diagnostician by Ian Perry\n- Ray's C-64 Problems Solved and archived repair notes by Ray Carlsen\n- Archived comp.sys.cbm contributors, including Brian Heyboer and other credited posters in the supplied etext\n- Online C64 reference transcription credited to Sami Rautiainen\n- The Pictorial C64 Fault Guide: https://www.pictorial64.com/\n\nThese contributors preserved and organized the original information; CopyCat only normalizes it for search and troubleshooting.","sourceDocument":"Commodore manuals; Project 64 C-DIAG10.TXT; Pictorial64; user-supplied C64 references","sourceAuthority":"Commodore Business Machines / credited historical preservation contributors","platforms":["c64"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08","vendors":["Commodore 64"],"technologies":["Commodore 64","C64","C64 hardware diagnostic","Hardware"],"aliases":[]},{"id":52500,"title":"Color BASIC /0 - Division By Zero","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Division By Zero"],"keywords":["Color BASIC /0 - Division By Zero","/0","A calculation attempted to divide a number by zero.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"/0","eventId":"","severity":"Low","summary":"A calculation attempted to divide a number by zero.","rootCause":"A calculation attempted to divide a number by zero.","resolution":"1. Record the complete ?/0 ERROR message and line number.\n2. Inspect the expression and prevent a zero divisor before the division is evaluated.\n3. Use LIST to verify the corrected program line.\n4. RUN the program again and confirm the error no longer occurs.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC /0 - Division By Zero.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix G meaning: A calculation attempted to divide a number by zero.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Division By Zero"],"aliases":["/0"]},{"id":52501,"title":"Color BASIC AO - Already Open","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Already Open"],"keywords":["Color BASIC AO - Already Open","AO","The program attempted to open a data file that is already open.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"AO","eventId":"","severity":"Medium","summary":"The program attempted to open a data file that is already open.","rootCause":"The program attempted to open a data file that is already open.","resolution":"1. Record the complete ?AO ERROR message and line number.\n2. Use a different file number or CLOSE the existing file before opening it again.\n3. Use LIST to verify the corrected program line.\n4. RUN the program again and confirm the error no longer occurs.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC AO - Already Open.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix G meaning: The program attempted to open a data file that is already open.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Already Open"],"aliases":["AO"]},{"id":52502,"title":"Color BASIC BS - Bad Subscript","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Bad Subscript"],"keywords":["Color BASIC BS - Bad Subscript","BS","An array subscript is outside the range reserved by DIM.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"BS","eventId":"","severity":"Low","summary":"An array subscript is outside the range reserved by DIM.","rootCause":"An array subscript is outside the range reserved by DIM.","resolution":"1. Record the complete ?BS ERROR message and line number.\n2. Check every array index and place a DIM statement large enough for the highest required element before the array is used.\n3. Use LIST to verify the corrected program line.\n4. RUN the program again and confirm the error no longer occurs.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC BS - Bad Subscript.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix G meaning: An array subscript is outside the range reserved by DIM.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Bad Subscript"],"aliases":["BS"]},{"id":52503,"title":"Color BASIC CN - Can't Continue","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Can't Continue"],"keywords":["Color BASIC CN - Can't Continue","CN","CONT cannot resume because execution reached END or the prior program state is no longer resumable.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"CN","eventId":"","severity":"Low","summary":"CONT cannot resume because execution reached END or the prior program state is no longer resumable.","rootCause":"CONT cannot resume because execution reached END or the prior program state is no longer resumable.","resolution":"1. Record the complete ?CN ERROR message and line number.\n2. Use RUN to restart the program; use CONT only after a resumable BREAK without editing the program.\n3. Use LIST to verify the corrected program line.\n4. RUN the program again and confirm the error no longer occurs.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC CN - Can't Continue.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix G meaning: CONT cannot resume because execution reached END or the prior program state is no longer resumable.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Can't Continue"],"aliases":["CN"]},{"id":52504,"title":"Color BASIC DD - Redimensioned Array","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Redimensioned Array"],"keywords":["Color BASIC DD - Redimensioned Array","DD","The program attempted to dimension the same array more than once.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"DD","eventId":"","severity":"Low","summary":"The program attempted to dimension the same array more than once.","rootCause":"The program attempted to dimension the same array more than once.","resolution":"1. Record the complete ?DD ERROR message and line number.\n2. Keep one DIM statement for the array and size it before the array is first referenced.\n3. Use LIST to verify the corrected program line.\n4. RUN the program again and confirm the error no longer occurs.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC DD - Redimensioned Array.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix G meaning: The program attempted to dimension the same array more than once.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Redimensioned Array"],"aliases":["DD"]},{"id":52505,"title":"Color BASIC DN - Device Number Error","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Device Number Error"],"keywords":["Color BASIC DN - Device Number Error","DN","OPEN, CLOSE, PRINT, or INPUT used a device number other than 0, -1, or -2.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"DN","eventId":"","severity":"Low","summary":"OPEN, CLOSE, PRINT, or INPUT used a device number other than 0, -1, or -2.","rootCause":"OPEN, CLOSE, PRINT, or INPUT used a device number other than 0, -1, or -2.","resolution":"1. Record the complete ?DN ERROR message and line number.\n2. Correct the device number to one supported by this Color BASIC edition and confirm the intended cassette or screen operation.\n3. Use LIST to verify the corrected program line.\n4. RUN the program again and confirm the error no longer occurs.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC DN - Device Number Error.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix G meaning: OPEN, CLOSE, PRINT, or INPUT used a device number other than 0, -1, or -2.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Device Number Error"],"aliases":["DN"]},{"id":52506,"title":"Color BASIC DS - Direct Statement In File","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Direct Statement In File"],"keywords":["Color BASIC DS - Direct Statement In File","DS","A loaded data file contains a direct statement, often because a program was saved without line numbers.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"DS","eventId":"","severity":"Medium","summary":"A loaded data file contains a direct statement, often because a program was saved without line numbers.","rootCause":"A loaded data file contains a direct statement, often because a program was saved without line numbers.","resolution":"1. Record the complete ?DS ERROR message and line number.\n2. Inspect the cassette contents and resave the program with valid numbered program lines.\n3. Use LIST to verify the corrected program line.\n4. RUN the program again and confirm the error no longer occurs.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC DS - Direct Statement In File.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix G meaning: A loaded data file contains a direct statement, often because a program was saved without line numbers.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Direct Statement In File"],"aliases":["DS"]},{"id":52507,"title":"Color BASIC FC - Illegal Function Call","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Illegal Function Call"],"keywords":["Color BASIC FC - Illegal Function Call","FC","A BASIC function or statement received a parameter outside its permitted range.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"FC","eventId":"","severity":"Low","summary":"A BASIC function or statement received a parameter outside its permitted range.","rootCause":"A BASIC function or statement received a parameter outside its permitted range.","resolution":"1. Record the complete ?FC ERROR message and line number.\n2. Check the command's allowed range; examples include SOUND values from 1 through 255, CLS color values from 0 through 8, valid string lengths, and nonnegative array indexes.\n3. Use LIST to verify the corrected program line.\n4. RUN the program again and confirm the error no longer occurs.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC FC - Illegal Function Call.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix G meaning: A BASIC function or statement received a parameter outside its permitted range.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Illegal Function Call"],"aliases":["FC"]},{"id":52508,"title":"Color BASIC FD - Bad File Data","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Bad File Data"],"keywords":["Color BASIC FD - Bad File Data","FD","File input or output used a variable type that does not match the stored data.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"FD","eventId":"","severity":"Medium","summary":"File input or output used a variable type that does not match the stored data.","rootCause":"File input or output used a variable type that does not match the stored data.","resolution":"1. Record the complete ?FD ERROR message and line number.\n2. Match numeric variables to numeric data and string variables to string data, then recreate malformed cassette data if necessary.\n3. Use LIST to verify the corrected program line.\n4. RUN the program again and confirm the error no longer occurs.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC FD - Bad File Data.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix G meaning: File input or output used a variable type that does not match the stored data.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Bad File Data"],"aliases":["FD"]},{"id":52509,"title":"Color BASIC FM - Bad File Mode","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Bad File Mode"],"keywords":["Color BASIC FM - Bad File Mode","FM","The program tried to INPUT from a file opened for output or PRINT to a file opened for input.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"FM","eventId":"","severity":"Medium","summary":"The program tried to INPUT from a file opened for output or PRINT to a file opened for input.","rootCause":"The program tried to INPUT from a file opened for output or PRINT to a file opened for input.","resolution":"1. Record the complete ?FM ERROR message and line number.\n2. Check the OPEN mode and reopen the file for the direction the program actually uses.\n3. Use LIST to verify the corrected program line.\n4. RUN the program again and confirm the error no longer occurs.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC FM - Bad File Mode.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix G meaning: The program tried to INPUT from a file opened for output or PRINT to a file opened for input.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Bad File Mode"],"aliases":["FM"]},{"id":52510,"title":"Color BASIC ID - Illegal Direct Statement","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Illegal Direct Statement"],"keywords":["Color BASIC ID - Illegal Direct Statement","ID","INPUT was entered as a direct command even though it can only run inside a program line.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"ID","eventId":"","severity":"Low","summary":"INPUT was entered as a direct command even though it can only run inside a program line.","rootCause":"INPUT was entered as a direct command even though it can only run inside a program line.","resolution":"1. Record the complete ?ID ERROR message and line number.\n2. Place INPUT in a numbered program line and execute the program with RUN.\n3. Use LIST to verify the corrected program line.\n4. RUN the program again and confirm the error no longer occurs.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC ID - Illegal Direct Statement.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix G meaning: INPUT was entered as a direct command even though it can only run inside a program line.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Illegal Direct Statement"],"aliases":["ID"]},{"id":52511,"title":"Color BASIC IE - Input Past End Of File","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Input Past End Of File"],"keywords":["Color BASIC IE - Input Past End Of File","IE","INPUT attempted to read beyond the available file data.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"IE","eventId":"","severity":"Medium","summary":"INPUT attempted to read beyond the available file data.","rootCause":"INPUT attempted to read beyond the available file data.","resolution":"1. Record the complete ?IE ERROR message and line number.\n2. Use EOF to detect the end of the file and CLOSE the file when the end is reached.\n3. Use LIST to verify the corrected program line.\n4. RUN the program again and confirm the error no longer occurs.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC IE - Input Past End Of File.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix G meaning: INPUT attempted to read beyond the available file data.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Input Past End Of File"],"aliases":["IE"]},{"id":52512,"title":"Color BASIC IO - Input/Output Error","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Input/Output Error"],"keywords":["Color BASIC IO - Input/Output Error","IO","A cassette program or data operation failed, commonly because the tape could not be read reliably.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"IO","eventId":"","severity":"Low","summary":"A cassette program or data operation failed, commonly because the tape could not be read reliably.","rootCause":"A cassette program or data operation failed, commonly because the tape could not be read reliably.","resolution":"1. Record the complete ?IO ERROR message and line number.\n2. Check recorder power, cable connections, volume and tone settings, tape position, and media condition; rewind and retry with a known-good recording.\n3. Use LIST to verify the corrected program line.\n4. RUN the program again and confirm the error no longer occurs.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC IO - Input/Output Error.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix G meaning: A cassette program or data operation failed, commonly because the tape could not be read reliably.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Input/Output Error"],"aliases":["IO"]},{"id":52513,"title":"Color BASIC LS - String Too Long","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","String Too Long"],"keywords":["Color BASIC LS - String Too Long","LS","A string exceeded Color BASIC's 255-character limit.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"LS","eventId":"","severity":"Low","summary":"A string exceeded Color BASIC's 255-character limit.","rootCause":"A string exceeded Color BASIC's 255-character limit.","resolution":"1. Record the complete ?LS ERROR message and line number.\n2. Shorten the value or divide it into multiple strings of no more than 255 characters each.\n3. Use LIST to verify the corrected program line.\n4. RUN the program again and confirm the error no longer occurs.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC LS - String Too Long.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix G meaning: A string exceeded Color BASIC's 255-character limit.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","String Too Long"],"aliases":["LS"]},{"id":52514,"title":"Color BASIC NF - NEXT Without FOR","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","NEXT Without FOR"],"keywords":["Color BASIC NF - NEXT Without FOR","NF","NEXT has no matching FOR statement or nested NEXT statements are in the wrong order.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"NF","eventId":"","severity":"Low","summary":"NEXT has no matching FOR statement or nested NEXT statements are in the wrong order.","rootCause":"NEXT has no matching FOR statement or nested NEXT statements are in the wrong order.","resolution":"1. Record the complete ?NF ERROR message and line number.\n2. Match each NEXT to its FOR variable and close nested loops in reverse order.\n3. Use LIST to verify the corrected program line.\n4. RUN the program again and confirm the error no longer occurs.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC NF - NEXT Without FOR.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix G meaning: NEXT has no matching FOR statement or nested NEXT statements are in the wrong order.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","NEXT Without FOR"],"aliases":["NF"]},{"id":52515,"title":"Color BASIC NO - File Not Open","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","File Not Open"],"keywords":["Color BASIC NO - File Not Open","NO","A file input or output statement referenced a file that was not opened.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"NO","eventId":"","severity":"Medium","summary":"A file input or output statement referenced a file that was not opened.","rootCause":"A file input or output statement referenced a file that was not opened.","resolution":"1. Record the complete ?NO ERROR message and line number.\n2. OPEN the required file with the correct file number and mode before using INPUT, PRINT, or CLOSE.\n3. Use LIST to verify the corrected program line.\n4. RUN the program again and confirm the error no longer occurs.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC NO - File Not Open.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix G meaning: A file input or output statement referenced a file that was not opened.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","File Not Open"],"aliases":["NO"]},{"id":52516,"title":"Color BASIC OD - Out Of Data","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Out Of Data"],"keywords":["Color BASIC OD - Out Of Data","OD","READ executed after all values in DATA statements had already been consumed.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"OD","eventId":"","severity":"Low","summary":"READ executed after all values in DATA statements had already been consumed.","rootCause":"READ executed after all values in DATA statements had already been consumed.","resolution":"1. Record the complete ?OD ERROR message and line number.\n2. Add the missing DATA values, reduce the number of READ operations, or use RESTORE before rereading the data.\n3. Use LIST to verify the corrected program line.\n4. RUN the program again and confirm the error no longer occurs.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC OD - Out Of Data.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix G meaning: READ executed after all values in DATA statements had already been consumed.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Out Of Data"],"aliases":["OD"]},{"id":52517,"title":"Color BASIC OM - Out Of Memory","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Out Of Memory"],"keywords":["Color BASIC OM - Out Of Memory","OM","All available Color Computer memory has been used or reserved.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"OM","eventId":"","severity":"Medium","summary":"All available Color Computer memory has been used or reserved.","rootCause":"All available Color Computer memory has been used or reserved.","resolution":"1. Record the complete ?OM ERROR message and line number.\n2. Save the program, remove unnecessary lines or variables, reduce array sizes and nesting, then reload and retest.\n3. Use LIST to verify the corrected program line.\n4. RUN the program again and confirm the error no longer occurs.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC OM - Out Of Memory.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix G meaning: All available Color Computer memory has been used or reserved.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Out Of Memory"],"aliases":["OM"]},{"id":52518,"title":"Color BASIC OS - Out Of String Space","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Out Of String Space"],"keywords":["Color BASIC OS - Out Of String Space","OS","String operations exhausted the memory available for strings.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"OS","eventId":"","severity":"Medium","summary":"String operations exhausted the memory available for strings.","rootCause":"String operations exhausted the memory available for strings.","resolution":"1. Record the complete ?OS ERROR message and line number.\n2. Use CLEAR at the beginning of the program to reserve sufficient string space and reduce unnecessary string variables or concatenation.\n3. Use LIST to verify the corrected program line.\n4. RUN the program again and confirm the error no longer occurs.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC OS - Out Of String Space.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix G meaning: String operations exhausted the memory available for strings.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Out Of String Space"],"aliases":["OS"]},{"id":52519,"title":"Color BASIC OV - Overflow","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Overflow"],"keywords":["Color BASIC OV - Overflow","OV","A numeric result is too large for Color BASIC to represent.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"OV","eventId":"","severity":"Low","summary":"A numeric result is too large for Color BASIC to represent.","rootCause":"A numeric result is too large for Color BASIC to represent.","resolution":"1. Record the complete ?OV ERROR message and line number.\n2. Check the formula and input values, then rescale or break up the calculation so intermediate and final results remain within range.\n3. Use LIST to verify the corrected program line.\n4. RUN the program again and confirm the error no longer occurs.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC OV - Overflow.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix G meaning: A numeric result is too large for Color BASIC to represent.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Overflow"],"aliases":["OV"]},{"id":52520,"title":"Color BASIC RG - RETURN Without GOSUB","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","RETURN Without GOSUB"],"keywords":["Color BASIC RG - RETURN Without GOSUB","RG","RETURN executed without a matching active GOSUB.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"RG","eventId":"","severity":"Low","summary":"RETURN executed without a matching active GOSUB.","rootCause":"RETURN executed without a matching active GOSUB.","resolution":"1. Record the complete ?RG ERROR message and line number.\n2. Trace the control flow and ensure the subroutine is entered with GOSUB before RETURN can execute.\n3. Use LIST to verify the corrected program line.\n4. RUN the program again and confirm the error no longer occurs.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC RG - RETURN Without GOSUB.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix G meaning: RETURN executed without a matching active GOSUB.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","RETURN Without GOSUB"],"aliases":["RG"]},{"id":52521,"title":"Color BASIC SN - Syntax Error","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Syntax Error"],"keywords":["Color BASIC SN - Syntax Error","SN","Color BASIC could not parse a command because of spelling, punctuation, parentheses, or an illegal character.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"SN","eventId":"","severity":"Low","summary":"Color BASIC could not parse a command because of spelling, punctuation, parentheses, or an illegal character.","rootCause":"Color BASIC could not parse a command because of spelling, punctuation, parentheses, or an illegal character.","resolution":"1. Record the complete ?SN ERROR message and line number.\n2. Use LIST to inspect the reported line, correct the command name and punctuation, and re-enter the line.\n3. Use LIST to verify the corrected program line.\n4. RUN the program again and confirm the error no longer occurs.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC SN - Syntax Error.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix G meaning: Color BASIC could not parse a command because of spelling, punctuation, parentheses, or an illegal character.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Syntax Error"],"aliases":["SN"]},{"id":52522,"title":"Color BASIC ST - String Formula Too Complex","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","String Formula Too Complex"],"keywords":["Color BASIC ST - String Formula Too Complex","ST","A string expression is too complex for Color BASIC to evaluate.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"ST","eventId":"","severity":"Low","summary":"A string expression is too complex for Color BASIC to evaluate.","rootCause":"A string expression is too complex for Color BASIC to evaluate.","resolution":"1. Record the complete ?ST ERROR message and line number.\n2. Split the expression into shorter operations and store intermediate results in separate string variables.\n3. Use LIST to verify the corrected program line.\n4. RUN the program again and confirm the error no longer occurs.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC ST - String Formula Too Complex.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix G meaning: A string expression is too complex for Color BASIC to evaluate.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","String Formula Too Complex"],"aliases":["ST"]},{"id":52523,"title":"Color BASIC TM - Type Mismatch","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Type Mismatch"],"keywords":["Color BASIC TM - Type Mismatch","TM","The program assigned numeric data to a string variable or string data to a numeric variable.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"TM","eventId":"","severity":"Low","summary":"The program assigned numeric data to a string variable or string data to a numeric variable.","rootCause":"The program assigned numeric data to a string variable or string data to a numeric variable.","resolution":"1. Record the complete ?TM ERROR message and line number.\n2. Use dollar-sign variables for strings and numeric variables for numbers; convert with VAL when a numeric string must become a number.\n3. Use LIST to verify the corrected program line.\n4. RUN the program again and confirm the error no longer occurs.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC TM - Type Mismatch.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix G meaning: The program assigned numeric data to a string variable or string data to a numeric variable.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Type Mismatch"],"aliases":["TM"]},{"id":52524,"title":"Color BASIC UL - Undefined Line","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Undefined Line"],"keywords":["Color BASIC UL - Undefined Line","UL","GOTO, GOSUB, or another branch references a line number that does not exist.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"UL","eventId":"","severity":"Low","summary":"GOTO, GOSUB, or another branch references a line number that does not exist.","rootCause":"GOTO, GOSUB, or another branch references a line number that does not exist.","resolution":"1. Record the complete ?UL ERROR message and line number.\n2. Use LIST to locate the branch and change its target to an existing program line.\n3. Use LIST to verify the corrected program line.\n4. RUN the program again and confirm the error no longer occurs.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC UL - Undefined Line.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix G meaning: GOTO, GOSUB, or another branch references a line number that does not exist.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Error Message","Undefined Line"],"aliases":["UL"]},{"id":52600,"title":"Color BASIC Command - CLOAD","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","CLOAD"],"keywords":["Color BASIC Command - CLOAD","Loads the first cassette program, or the named program when a name is supplied.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Loads the first cassette program, or the named program when a name is supplied.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: CLOAD \"PROGRAM\"\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - CLOAD.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: CLOAD \"PROGRAM\"","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Loads the first cassette program, or the named program when a name is supplied.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"CLOAD \"PROGRAM\"","risk":"Read-only"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","CLOAD"],"aliases":[]},{"id":52601,"title":"Color BASIC Command - CLS","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","CLS"],"keywords":["Color BASIC Command - CLS","Clears the screen to green or to the specified Color BASIC color code.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Clears the screen to green or to the specified Color BASIC color code.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: CLS(3)\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - CLS.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: CLS(3)","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Clears the screen to green or to the specified Color BASIC color code.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"CLS(3)","risk":"Read-only"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","CLS"],"aliases":[]},{"id":52602,"title":"Color BASIC Command - CSAVE","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","CSAVE"],"keywords":["Color BASIC Command - CSAVE","Saves the current program to cassette, optionally using a name of up to eight letters.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Saves the current program to cassette, optionally using a name of up to eight letters.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: CSAVE \"PROGRAM\"\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - CSAVE.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: CSAVE \"PROGRAM\"","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Saves the current program to cassette, optionally using a name of up to eight letters.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"CSAVE \"PROGRAM\"","risk":"Config Change"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","CSAVE"],"aliases":[]},{"id":52603,"title":"Color BASIC Command - DATA","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","DATA"],"keywords":["Color BASIC Command - DATA","Stores values in a program for later assignment by READ.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Stores values in a program for later assignment by READ.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: DATA 5,3,PEARS\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - DATA.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: DATA 5,3,PEARS","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Stores values in a program for later assignment by READ.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"DATA 5,3,PEARS","risk":"Read-only"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","DATA"],"aliases":[]},{"id":52604,"title":"Color BASIC Command - END","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","END"],"keywords":["Color BASIC Command - END","Ends program execution.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Ends program execution.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: END\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - END.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: END","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Ends program execution.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"END","risk":"Read-only"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","END"],"aliases":[]},{"id":52605,"title":"Color BASIC Command - FOR / TO / STEP / NEXT","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","FOR / TO / STEP / NEXT"],"keywords":["Color BASIC Command - FOR / TO / STEP / NEXT","Repeats a program section across a numeric range; STEP changes the increment.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Repeats a program section across a numeric range; STEP changes the increment.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: FOR X=1 TO 10 STEP 2 : NEXT X\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - FOR / TO / STEP / NEXT.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: FOR X=1 TO 10 STEP 2 : NEXT X","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Repeats a program section across a numeric range; STEP changes the increment.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"FOR X=1 TO 10 STEP 2 : NEXT X","risk":"Read-only"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","FOR / TO / STEP / NEXT"],"aliases":[]},{"id":52606,"title":"Color BASIC Command - GOSUB","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","GOSUB"],"keywords":["Color BASIC Command - GOSUB","Transfers execution to a subroutine at the specified line number.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Transfers execution to a subroutine at the specified line number.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: GOSUB 500\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - GOSUB.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: GOSUB 500","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Transfers execution to a subroutine at the specified line number.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"GOSUB 500","risk":"Read-only"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","GOSUB"],"aliases":[]},{"id":52607,"title":"Color BASIC Command - GOTO","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","GOTO"],"keywords":["Color BASIC Command - GOTO","Transfers execution to the specified program line.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Transfers execution to the specified program line.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: GOTO 300\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - GOTO.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: GOTO 300","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Transfers execution to the specified program line.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"GOTO 300","risk":"Read-only"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","GOTO"],"aliases":[]},{"id":52608,"title":"Color BASIC Command - IF / THEN","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","IF / THEN"],"keywords":["Color BASIC Command - IF / THEN","Tests a relationship and executes the instruction after THEN when it is true.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Tests a relationship and executes the instruction after THEN when it is true.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: IF A=5 THEN 300\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - IF / THEN.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: IF A=5 THEN 300","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Tests a relationship and executes the instruction after THEN when it is true.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"IF A=5 THEN 300","risk":"Read-only"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","IF / THEN"],"aliases":[]},{"id":52609,"title":"Color BASIC Command - INKEY$","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","INKEY$"],"keywords":["Color BASIC Command - INKEY$","Returns the key currently being pressed, or an empty string when no key is pressed.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Returns the key currently being pressed, or an empty string when no key is pressed.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: A$=INKEY$\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - INKEY$.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: A$=INKEY$","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Returns the key currently being pressed, or an empty string when no key is pressed.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"A$=INKEY$","risk":"Read-only"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","INKEY$"],"aliases":[]},{"id":52610,"title":"Color BASIC Command - INPUT","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","INPUT"],"keywords":["Color BASIC Command - INPUT","Pauses a running program and accepts keyboard input into a variable.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Pauses a running program and accepts keyboard input into a variable.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: INPUT \"NAME\";N$\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - INPUT.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: INPUT \"NAME\";N$","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Pauses a running program and accepts keyboard input into a variable.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"INPUT \"NAME\";N$","risk":"Read-only"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","INPUT"],"aliases":[]},{"id":52611,"title":"Color BASIC Command - INT","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","INT"],"keywords":["Color BASIC Command - INT","Converts a number to an integer.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Converts a number to an integer.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: X=INT(5.2)\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - INT.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: X=INT(5.2)","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Converts a number to an integer.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"X=INT(5.2)","risk":"Read-only"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","INT"],"aliases":[]},{"id":52612,"title":"Color BASIC Command - JOYSTK","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","JOYSTK"],"keywords":["Color BASIC Command - JOYSTK","Returns a horizontal or vertical coordinate for the left or right joystick using selector 0 through 3.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Returns a horizontal or vertical coordinate for the left or right joystick using selector 0 through 3.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: M=JOYSTK(0)\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - JOYSTK.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: M=JOYSTK(0)","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Returns a horizontal or vertical coordinate for the left or right joystick using selector 0 through 3.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"M=JOYSTK(0)","risk":"Read-only"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","JOYSTK"],"aliases":[]},{"id":52613,"title":"Color BASIC Command - LIST","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","LIST"],"keywords":["Color BASIC Command - LIST","Displays all program lines or a selected line or range.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Displays all program lines or a selected line or range.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: LIST 50-85\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - LIST.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: LIST 50-85","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Displays all program lines or a selected line or range.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"LIST 50-85","risk":"Read-only"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","LIST"],"aliases":[]},{"id":52614,"title":"Color BASIC Command - NEW","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","NEW"],"keywords":["Color BASIC Command - NEW","Erases the program and variables currently held in memory.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Medium","summary":"Erases the program and variables currently held in memory.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: NEW\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - NEW.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: NEW","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Erases the program and variables currently held in memory.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"NEW","risk":"Config Change"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","NEW"],"aliases":[]},{"id":52615,"title":"Color BASIC Command - PEEK","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","PEEK"],"keywords":["Color BASIC Command - PEEK","Returns the byte stored at the specified memory location.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Medium","summary":"Returns the byte stored at the specified memory location.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: A=PEEK(32076)\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - PEEK.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: A=PEEK(32076)","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Returns the byte stored at the specified memory location.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"A=PEEK(32076)","risk":"Read-only"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","PEEK"],"aliases":[]},{"id":52616,"title":"Color BASIC Command - PRINT","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","PRINT"],"keywords":["Color BASIC Command - PRINT","Displays text, variables, or calculation results on the screen.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Displays text, variables, or calculation results on the screen.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: PRINT \"HI\"\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - PRINT.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: PRINT \"HI\"","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Displays text, variables, or calculation results on the screen.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"PRINT \"HI\"","risk":"Read-only"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","PRINT"],"aliases":[]},{"id":52617,"title":"Color BASIC Command - PRINT @","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","PRINT @"],"keywords":["Color BASIC Command - PRINT @","Displays output beginning at the specified text-screen position.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Displays output beginning at the specified text-screen position.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: PRINT @ 256,\"HI\"\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - PRINT @.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: PRINT @ 256,\"HI\"","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Displays output beginning at the specified text-screen position.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"PRINT @ 256,\"HI\"","risk":"Read-only"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","PRINT @"],"aliases":[]},{"id":52618,"title":"Color BASIC Command - READ","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","READ"],"keywords":["Color BASIC Command - READ","Takes the next value from DATA and assigns it to a variable.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Takes the next value from DATA and assigns it to a variable.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: READ A$\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - READ.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: READ A$","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Takes the next value from DATA and assigns it to a variable.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"READ A$","risk":"Read-only"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","READ"],"aliases":[]},{"id":52619,"title":"Color BASIC Command - REM","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","REM"],"keywords":["Color BASIC Command - REM","Adds a comment that Color BASIC ignores during execution.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Adds a comment that Color BASIC ignores during execution.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: REM THIS IS IGNORED\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - REM.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: REM THIS IS IGNORED","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Adds a comment that Color BASIC ignores during execution.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"REM THIS IS IGNORED","risk":"Read-only"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","REM"],"aliases":[]},{"id":52620,"title":"Color BASIC Command - RESET","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","RESET"],"keywords":["Color BASIC Command - RESET","Erases a dot previously drawn at the specified graphics location.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Erases a dot previously drawn at the specified graphics location.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: RESET(14,15)\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - RESET.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: RESET(14,15)","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Erases a dot previously drawn at the specified graphics location.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"RESET(14,15)","risk":"Config Change"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","RESET"],"aliases":[]},{"id":52621,"title":"Color BASIC Command - RESTORE","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","RESTORE"],"keywords":["Color BASIC Command - RESTORE","Moves the DATA pointer back to the first DATA item.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Moves the DATA pointer back to the first DATA item.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: RESTORE\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - RESTORE.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: RESTORE","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Moves the DATA pointer back to the first DATA item.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"RESTORE","risk":"Read-only"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","RESTORE"],"aliases":[]},{"id":52622,"title":"Color BASIC Command - RETURN","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","RETURN"],"keywords":["Color BASIC Command - RETURN","Returns from a subroutine to the statement following its active GOSUB.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Returns from a subroutine to the statement following its active GOSUB.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: RETURN\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - RETURN.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: RETURN","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Returns from a subroutine to the statement following its active GOSUB.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"RETURN","risk":"Read-only"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","RETURN"],"aliases":[]},{"id":52623,"title":"Color BASIC Command - RND","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","RND"],"keywords":["Color BASIC Command - RND","Returns a random integer from 1 through the supplied number.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Returns a random integer from 1 through the supplied number.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: A=RND(10)\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - RND.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: A=RND(10)","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Returns a random integer from 1 through the supplied number.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"A=RND(10)","risk":"Read-only"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","RND"],"aliases":[]},{"id":52624,"title":"Color BASIC Command - RUN","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","RUN"],"keywords":["Color BASIC Command - RUN","Starts execution of the program in memory.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Medium","summary":"Starts execution of the program in memory.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: RUN\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - RUN.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: RUN","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Starts execution of the program in memory.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"RUN","risk":"Read-only"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","RUN"],"aliases":[]},{"id":52625,"title":"Color BASIC Command - SET","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","SET"],"keywords":["Color BASIC Command - SET","Draws a dot at the specified horizontal and vertical location using the specified color.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Draws a dot at the specified horizontal and vertical location using the specified color.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: SET(14,13,3)\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - SET.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: SET(14,13,3)","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Draws a dot at the specified horizontal and vertical location using the specified color.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"SET(14,13,3)","risk":"Config Change"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","SET"],"aliases":[]},{"id":52626,"title":"Color BASIC Command - SKIPF","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","SKIPF"],"keywords":["Color BASIC Command - SKIPF","Advances cassette tape to the end of the next program or the named program.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Advances cassette tape to the end of the next program or the named program.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: SKIPF \"PROGRAM\"\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - SKIPF.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: SKIPF \"PROGRAM\"","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Advances cassette tape to the end of the next program or the named program.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"SKIPF \"PROGRAM\"","risk":"Config Change"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","SKIPF"],"aliases":[]},{"id":52627,"title":"Color BASIC Command - SOUND","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","SOUND"],"keywords":["Color BASIC Command - SOUND","Plays a tone and duration; both values are from 1 through 255.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Plays a tone and duration; both values are from 1 through 255.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: SOUND 128,3\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - SOUND.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: SOUND 128,3","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Plays a tone and duration; both values are from 1 through 255.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"SOUND 128,3","risk":"Config Change"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","SOUND"],"aliases":[]},{"id":52628,"title":"Color BASIC Command - VAL","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","VAL"],"keywords":["Color BASIC Command - VAL","Converts the numeric contents of a string into a number.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Converts the numeric contents of a string into a number.","rootCause":"This is a historical Color BASIC command reference rather than an error condition.","resolution":"1. Preserve the current program before experimenting.\n2. Enter the command using the documented Color BASIC form.\n3. Example from the book: A=VAL(B$)\n4. Check the screen, program listing, cassette, sound, or graphics result as appropriate.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to Color BASIC Command - VAL.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"This command is used on a TRS-80 Color Computer running Color BASIC. Example: A=VAL(B$)","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix H purpose: Converts the numeric contents of a string into a number.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","commands":[{"shell":"Color BASIC","command":"A=VAL(B$)","risk":"Read-only"}],"vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Command Reference","VAL"],"aliases":[]},{"id":52650,"title":"TRS-80 Color BASIC Color Codes","category":"Tandy TRS-80","product":"TRS-80 Color Computer / Color BASIC","tags":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Reference","Graphics","Color Codes"],"keywords":["TRS-80 Color BASIC Color Codes","Color BASIC uses codes 0 through 8 for black, green, yellow, blue, red, buff, cyan, magenta, and orange.","Tandy","Radio Shack","TRS-80","TRS 80","Color Computer","CoCo","Color BASIC","1981","legacy computer"],"errorCode":"","eventId":"","severity":"Low","summary":"Color BASIC uses codes 0 through 8 for black, green, yellow, blue, red, buff, cyan, magenta, and orange.","rootCause":"This is a reference for CLS and SET color parameters, not an error condition.","resolution":"Use 0 black, 1 green, 2 yellow, 3 blue, 4 red, 5 buff, 6 cyan, 7 magenta, or 8 orange. Display shades can vary with the connected television. With SET, color 0 leaves the cell color unchanged.","emailScript":"Hello,\n\nWe reviewed the TRS-80 Color Computer issue related to TRS-80 Color BASIC Color Codes.\n\nWe are checking the Color BASIC program, cassette data, and connected equipment before making changes.\n\nPlease preserve the original tape or program and let us know exactly what appeared on screen.\n\nThank you,\n\nIT Support","faqSteps":"1. Write down the complete two-character error and any line number shown.\n2. Save or photograph the program listing before changing it.\n3. Check cassette cables and media without opening powered equipment.\n4. Send support the command or numbered line that produced the message.","notes":"Historical scope: Radio Shack TRS-80 Color Computer Color BASIC, 1981 edition. Syntax and device behavior may differ in Extended Color BASIC, Disk BASIC, later CoCo models, emulators, or other TRS-80 families.\n\nAppendix B documents the nine Color BASIC color codes.","sourceDocument":"Getting Started With Color Basic (1981)_text.pdf","sourceAuthority":"Radio Shack","platforms":["trs80"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13","vendors":["TRS-80 Color Computer"],"technologies":["Tandy","TRS-80","Color Computer","Color BASIC","Legacy","Reference","Graphics","Color Codes"],"aliases":[]},{"id":53000,"title":"FortiOS 1 - Generic CLI Syntax Error","category":"Fortinet","product":"FortiGate / FortiOS 8.0.0","tags":["Fortinet","FortiGate","FortiOS","Firewall","CLI","Return Code"],"keywords":["1","return code 1","Command fail. Return code 1","Generic CLI Syntax Error","FortiOS CLI error","FortiGate command parse error","firewall troubleshooting"],"errorCode":"1","eventId":"","severity":"Low","summary":"The command does not match the syntax accepted at the current CLI level.","rootCause":"A misspelled keyword, incorrect hierarchy, omitted required value, unsupported option, or firmware/model difference commonly produces this response.","resolution":"1. Record the complete prompt, command, parser message, return code, FortiGate model, FortiOS build, and VDOM context.\n2. Use ? at the current prompt and tree for a broader command map. Confirm the configuration branch, spelling, required values, FortiOS release, FortiGate model, and enabled features before retrying.\n3. Review the current configuration before any change and preserve a backup or recovery path.\n4. Retry the corrected command in the intended scope.\n5. Show the affected object and validate service behavior without exposing secrets.","emailScript":"Hello,\n\nWe reviewed the FortiGate configuration issue and identified FortiOS return code 1: Generic CLI Syntax Error.\n\nWe are validating the command against the firewall model, software version, permissions, and current configuration before applying the least disruptive correction.\n\nPlease let us know if there is an approved change window or recent firewall change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The firewall rejected a configuration command with return code 1. Please do not repeatedly retry or alter firewall settings. Send IT Support the full message, approximate time, firewall name, and what change was being attempted; remove passwords, tokens, private keys, and other secrets.","notes":"Source table description: Generic CLI Syntax Error.\nFortiOS displays a summary followed by “Command fail. Return code 1” when command execution fails. A return code identifies an error family, not a universal root cause; the surrounding parser message and configuration context are required.\n\nVersion scope: The code definition was imported from the FortiOS 8.0.0 Administration Guide. Command availability can vary by FortiOS build, FortiGate model, hardware, VDOM mode, feature visibility, and administrator permissions.\nSafety: Start with read-only discovery. Review and back up configuration before mutation. Do not paste secrets or full sensitive configurations into tickets.","commands":[{"shell":"FortiOS CLI","command":"?","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FortiOS CLI","command":"tree","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"FortiOS-8.0.0-Administration_Guide.pdf, CLI troubleshooting cheat sheet — CLI error codes","sourceAuthority":"Fortinet","namespace":"FORTIOS-CLI","platforms":["firewalls"],"lastVerified":"2026-08-08","vendors":["Fortinet"],"products":["FortiGate","FortiOS 8.0.0"],"technologies":["Firewall","FortiOS CLI","Network Security"],"articleCategories":["Firewalls","Fortinet","Networking","Security","CLI Errors"],"aliases":["1","Return code 1","Generic CLI Syntax Error"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08"},{"id":53001,"title":"FortiOS -1 - Invalid Length of Value","category":"Fortinet","product":"FortiGate / FortiOS 8.0.0","tags":["Fortinet","FortiGate","FortiOS","Firewall","CLI","Return Code"],"keywords":["-1","return code -1","Command fail. Return code -1","Invalid Length of Value","FortiOS CLI error","FortiGate command parse error","firewall troubleshooting"],"errorCode":"-1","eventId":"","severity":"Low","summary":"A supplied value is shorter or longer than the field permits.","rootCause":"The value violates the field's length constraint or contains formatting that changes its accepted length.","resolution":"1. Record the complete prompt, command, parser message, return code, FortiGate model, FortiOS build, and VDOM context.\n2. Use ? or the matching FortiOS CLI reference to identify the field constraint, then supply a value within the documented limit.\n3. Review the current configuration before any change and preserve a backup or recovery path.\n4. Retry the corrected command in the intended scope.\n5. Show the affected object and validate service behavior without exposing secrets.","emailScript":"Hello,\n\nWe reviewed the FortiGate configuration issue and identified FortiOS return code -1: Invalid Length of Value.\n\nWe are validating the command against the firewall model, software version, permissions, and current configuration before applying the least disruptive correction.\n\nPlease let us know if there is an approved change window or recent firewall change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The firewall rejected a configuration command with return code -1. Please do not repeatedly retry or alter firewall settings. Send IT Support the full message, approximate time, firewall name, and what change was being attempted; remove passwords, tokens, private keys, and other secrets.","notes":"Source table description: Invalid Length of Value.\nFortiOS displays a summary followed by “Command fail. Return code -1” when command execution fails. A return code identifies an error family, not a universal root cause; the surrounding parser message and configuration context are required.\n\nVersion scope: The code definition was imported from the FortiOS 8.0.0 Administration Guide. Command availability can vary by FortiOS build, FortiGate model, hardware, VDOM mode, feature visibility, and administrator permissions.\nSafety: Start with read-only discovery. Review and back up configuration before mutation. Do not paste secrets or full sensitive configurations into tickets.","commands":[{"shell":"FortiOS CLI","command":"?","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FortiOS CLI","command":"tree","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FortiOS CLI","command":"show","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"FortiOS-8.0.0-Administration_Guide.pdf, CLI troubleshooting cheat sheet — CLI error codes","sourceAuthority":"Fortinet","namespace":"FORTIOS-CLI","platforms":["firewalls"],"lastVerified":"2026-08-08","vendors":["Fortinet"],"products":["FortiGate","FortiOS 8.0.0"],"technologies":["Firewall","FortiOS CLI","Network Security"],"articleCategories":["Firewalls","Fortinet","Networking","Security","CLI Errors"],"aliases":["-1","Return code -1","Invalid Length of Value"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08"},{"id":53002,"title":"FortiOS -4 - Maximum Number of Entries Reached","category":"Fortinet","product":"FortiGate / FortiOS 8.0.0","tags":["Fortinet","FortiGate","FortiOS","Firewall","CLI","Return Code"],"keywords":["-4","return code -4","Command fail. Return code -4","Maximum Number of Entries Reached","FortiOS CLI error","FortiGate command parse error","firewall troubleshooting"],"errorCode":"-4","eventId":"","severity":"Medium","summary":"FortiOS cannot add another entry to the selected configuration table.","rootCause":"The table has reached a platform, feature, license, or configuration limit.","resolution":"1. Record the complete prompt, command, parser message, return code, FortiGate model, FortiOS build, and VDOM context.\n2. Inspect the existing table and the model/version limit. Reuse or consolidate an approved entry, or remove an obsolete entry only after dependency review and change approval.\n3. Review the current configuration before any change and preserve a backup or recovery path.\n4. Retry the corrected command in the intended scope.\n5. Show the affected object and validate service behavior without exposing secrets.","emailScript":"Hello,\n\nWe reviewed the FortiGate configuration issue and identified FortiOS return code -4: Maximum Number of Entries Reached.\n\nWe are validating the command against the firewall model, software version, permissions, and current configuration before applying the least disruptive correction.\n\nPlease let us know if there is an approved change window or recent firewall change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The firewall rejected a configuration command with return code -4. Please do not repeatedly retry or alter firewall settings. Send IT Support the full message, approximate time, firewall name, and what change was being attempted; remove passwords, tokens, private keys, and other secrets.","notes":"Source table description: Maximum Number of Entries Reached.\nFortiOS displays a summary followed by “Command fail. Return code -4” when command execution fails. A return code identifies an error family, not a universal root cause; the surrounding parser message and configuration context are required.\n\nVersion scope: The code definition was imported from the FortiOS 8.0.0 Administration Guide. Command availability can vary by FortiOS build, FortiGate model, hardware, VDOM mode, feature visibility, and administrator permissions.\nSafety: Start with read-only discovery. Review and back up configuration before mutation. Do not paste secrets or full sensitive configurations into tickets.","commands":[{"shell":"FortiOS CLI","command":"?","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FortiOS CLI","command":"tree","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FortiOS CLI","command":"show","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"FortiOS-8.0.0-Administration_Guide.pdf, CLI troubleshooting cheat sheet — CLI error codes","sourceAuthority":"Fortinet","namespace":"FORTIOS-CLI","platforms":["firewalls"],"lastVerified":"2026-08-08","vendors":["Fortinet"],"products":["FortiGate","FortiOS 8.0.0"],"technologies":["Firewall","FortiOS CLI","Network Security"],"articleCategories":["Firewalls","Fortinet","Networking","Security","CLI Errors"],"aliases":["-4","Return code -4","Maximum Number of Entries Reached"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08"},{"id":53003,"title":"FortiOS -5 - Duplicate Entry Already Exists","category":"Fortinet","product":"FortiGate / FortiOS 8.0.0","tags":["Fortinet","FortiGate","FortiOS","Firewall","CLI","Return Code"],"keywords":["-5","return code -5","Command fail. Return code -5","Duplicate Entry Already Exists","FortiOS CLI error","FortiGate command parse error","firewall troubleshooting"],"errorCode":"-5","eventId":"","severity":"Low","summary":"The requested table key or object already exists.","rootCause":"An object with the same name, ID, sequence, address, or other unique key is already present.","resolution":"1. Record the complete prompt, command, parser message, return code, FortiGate model, FortiOS build, and VDOM context.\n2. Show the current table, locate the duplicate, and edit the intended existing object or choose a genuinely unique key. Do not delete the existing object until references and impact are known.\n3. Review the current configuration before any change and preserve a backup or recovery path.\n4. Retry the corrected command in the intended scope.\n5. Show the affected object and validate service behavior without exposing secrets.","emailScript":"Hello,\n\nWe reviewed the FortiGate configuration issue and identified FortiOS return code -5: Duplicate Entry Already Exists.\n\nWe are validating the command against the firewall model, software version, permissions, and current configuration before applying the least disruptive correction.\n\nPlease let us know if there is an approved change window or recent firewall change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The firewall rejected a configuration command with return code -5. Please do not repeatedly retry or alter firewall settings. Send IT Support the full message, approximate time, firewall name, and what change was being attempted; remove passwords, tokens, private keys, and other secrets.","notes":"Source table description: Duplicate Entry Already Exists.\nFortiOS displays a summary followed by “Command fail. Return code -5” when command execution fails. A return code identifies an error family, not a universal root cause; the surrounding parser message and configuration context are required.\n\nVersion scope: The code definition was imported from the FortiOS 8.0.0 Administration Guide. Command availability can vary by FortiOS build, FortiGate model, hardware, VDOM mode, feature visibility, and administrator permissions.\nSafety: Start with read-only discovery. Review and back up configuration before mutation. Do not paste secrets or full sensitive configurations into tickets.","commands":[{"shell":"FortiOS CLI","command":"?","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FortiOS CLI","command":"tree","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FortiOS CLI","command":"show","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"FortiOS-8.0.0-Administration_Guide.pdf, CLI troubleshooting cheat sheet — CLI error codes","sourceAuthority":"Fortinet","namespace":"FORTIOS-CLI","platforms":["firewalls"],"lastVerified":"2026-08-08","vendors":["Fortinet"],"products":["FortiGate","FortiOS 8.0.0"],"technologies":["Firewall","FortiOS CLI","Network Security"],"articleCategories":["Firewalls","Fortinet","Networking","Security","CLI Errors"],"aliases":["-5","Return code -5","Duplicate Entry Already Exists"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08"},{"id":53004,"title":"FortiOS -8 - Invalid IP Address","category":"Fortinet","product":"FortiGate / FortiOS 8.0.0","tags":["Fortinet","FortiGate","FortiOS","Firewall","CLI","Return Code"],"keywords":["-8","return code -8","Command fail. Return code -8","Invalid IP Address","FortiOS CLI error","FortiGate command parse error","firewall troubleshooting"],"errorCode":"-8","eventId":"","severity":"Low","summary":"FortiOS rejected the supplied IP address or subnet value.","rootCause":"The address, mask, prefix, range, family, or field-specific notation is invalid.","resolution":"1. Record the complete prompt, command, parser message, return code, FortiGate model, FortiOS build, and VDOM context.\n2. Verify the required IPv4 or IPv6 format with ?, correct the address and mask or prefix, and confirm it is valid for that field before retrying.\n3. Review the current configuration before any change and preserve a backup or recovery path.\n4. Retry the corrected command in the intended scope.\n5. Show the affected object and validate service behavior without exposing secrets.","emailScript":"Hello,\n\nWe reviewed the FortiGate configuration issue and identified FortiOS return code -8: Invalid IP Address.\n\nWe are validating the command against the firewall model, software version, permissions, and current configuration before applying the least disruptive correction.\n\nPlease let us know if there is an approved change window or recent firewall change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The firewall rejected a configuration command with return code -8. Please do not repeatedly retry or alter firewall settings. Send IT Support the full message, approximate time, firewall name, and what change was being attempted; remove passwords, tokens, private keys, and other secrets.","notes":"Source table description: Invalid IP Address.\nFortiOS displays a summary followed by “Command fail. Return code -8” when command execution fails. A return code identifies an error family, not a universal root cause; the surrounding parser message and configuration context are required.\n\nVersion scope: The code definition was imported from the FortiOS 8.0.0 Administration Guide. Command availability can vary by FortiOS build, FortiGate model, hardware, VDOM mode, feature visibility, and administrator permissions.\nSafety: Start with read-only discovery. Review and back up configuration before mutation. Do not paste secrets or full sensitive configurations into tickets.","commands":[{"shell":"FortiOS CLI","command":"?","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FortiOS CLI","command":"tree","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FortiOS CLI","command":"show","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"FortiOS-8.0.0-Administration_Guide.pdf, CLI troubleshooting cheat sheet — CLI error codes","sourceAuthority":"Fortinet","namespace":"FORTIOS-CLI","platforms":["firewalls"],"lastVerified":"2026-08-08","vendors":["Fortinet"],"products":["FortiGate","FortiOS 8.0.0"],"technologies":["Firewall","FortiOS CLI","Network Security"],"articleCategories":["Firewalls","Fortinet","Networking","Security","CLI Errors"],"aliases":["-8","Return code -8","Invalid IP Address"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08"},{"id":53005,"title":"FortiOS -37 - Permission Denied","category":"Fortinet","product":"FortiGate / FortiOS 8.0.0","tags":["Fortinet","FortiGate","FortiOS","Firewall","CLI","Return Code"],"keywords":["-37","return code -37","Command fail. Return code -37","Permission Denied","FortiOS CLI error","FortiGate command parse error","firewall troubleshooting"],"errorCode":"-37","eventId":"","severity":"High","summary":"The current administrator is not authorized to perform the requested CLI operation.","rootCause":"The admin profile, VDOM assignment, access mode, workspace state, or command permission does not allow the operation.","resolution":"1. Record the complete prompt, command, parser message, return code, FortiGate model, FortiOS build, and VDOM context.\n2. Confirm the correct administrative account and VDOM context. Have an authorized administrator review the assigned admin profile and workflow; do not bypass role controls or elevate privileges without approval.\n3. Review the current configuration before any change and preserve a backup or recovery path.\n4. Retry the corrected command in the intended scope.\n5. Show the affected object and validate service behavior without exposing secrets.","emailScript":"Hello,\n\nWe reviewed the FortiGate configuration issue and identified FortiOS return code -37: Permission Denied.\n\nWe are validating the command against the firewall model, software version, permissions, and current configuration before applying the least disruptive correction.\n\nPlease let us know if there is an approved change window or recent firewall change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The firewall rejected a configuration command with return code -37. Please do not repeatedly retry or alter firewall settings. Send IT Support the full message, approximate time, firewall name, and what change was being attempted; remove passwords, tokens, private keys, and other secrets.","notes":"Source table description: Permission Denied.\nFortiOS displays a summary followed by “Command fail. Return code -37” when command execution fails. A return code identifies an error family, not a universal root cause; the surrounding parser message and configuration context are required.\n\nVersion scope: The code definition was imported from the FortiOS 8.0.0 Administration Guide. Command availability can vary by FortiOS build, FortiGate model, hardware, VDOM mode, feature visibility, and administrator permissions.\nSafety: Start with read-only discovery. Review and back up configuration before mutation. Do not paste secrets or full sensitive configurations into tickets.","commands":[{"shell":"FortiOS CLI","command":"?","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FortiOS CLI","command":"tree","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FortiOS CLI","command":"show","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"FortiOS-8.0.0-Administration_Guide.pdf, CLI troubleshooting cheat sheet — CLI error codes","sourceAuthority":"Fortinet","namespace":"FORTIOS-CLI","platforms":["firewalls"],"lastVerified":"2026-08-08","vendors":["Fortinet"],"products":["FortiGate","FortiOS 8.0.0"],"technologies":["Firewall","FortiOS CLI","Network Security"],"articleCategories":["Firewalls","Fortinet","Networking","Security","CLI Errors"],"aliases":["-37","Return code -37","Permission Denied"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08"},{"id":53006,"title":"FortiOS -56 - Empty Values Are Not Allowed","category":"Fortinet","product":"FortiGate / FortiOS 8.0.0","tags":["Fortinet","FortiGate","FortiOS","Firewall","CLI","Return Code"],"keywords":["-56","return code -56","Command fail. Return code -56","Empty Values Are Not Allowed","FortiOS CLI error","FortiGate command parse error","firewall troubleshooting"],"errorCode":"-56","eventId":"","severity":"Low","summary":"A required CLI field was submitted without a value.","rootCause":"A mandatory value is blank, a variable expanded to an empty string, or a script omitted the value after set.","resolution":"1. Record the complete prompt, command, parser message, return code, FortiGate model, FortiOS build, and VDOM context.\n2. Use ? to confirm the field's accepted values, supply the required value, and inspect automation variables or quoting before rerunning the command.\n3. Review the current configuration before any change and preserve a backup or recovery path.\n4. Retry the corrected command in the intended scope.\n5. Show the affected object and validate service behavior without exposing secrets.","emailScript":"Hello,\n\nWe reviewed the FortiGate configuration issue and identified FortiOS return code -56: Empty Values Are Not Allowed.\n\nWe are validating the command against the firewall model, software version, permissions, and current configuration before applying the least disruptive correction.\n\nPlease let us know if there is an approved change window or recent firewall change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The firewall rejected a configuration command with return code -56. Please do not repeatedly retry or alter firewall settings. Send IT Support the full message, approximate time, firewall name, and what change was being attempted; remove passwords, tokens, private keys, and other secrets.","notes":"Source table description: Empty Values Are Not Allowed.\nFortiOS displays a summary followed by “Command fail. Return code -56” when command execution fails. A return code identifies an error family, not a universal root cause; the surrounding parser message and configuration context are required.\n\nVersion scope: The code definition was imported from the FortiOS 8.0.0 Administration Guide. Command availability can vary by FortiOS build, FortiGate model, hardware, VDOM mode, feature visibility, and administrator permissions.\nSafety: Start with read-only discovery. Review and back up configuration before mutation. Do not paste secrets or full sensitive configurations into tickets.","commands":[{"shell":"FortiOS CLI","command":"?","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FortiOS CLI","command":"tree","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FortiOS CLI","command":"show","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"FortiOS-8.0.0-Administration_Guide.pdf, CLI troubleshooting cheat sheet — CLI error codes","sourceAuthority":"Fortinet","namespace":"FORTIOS-CLI","platforms":["firewalls"],"lastVerified":"2026-08-08","vendors":["Fortinet"],"products":["FortiGate","FortiOS 8.0.0"],"technologies":["Firewall","FortiOS CLI","Network Security"],"articleCategories":["Firewalls","Fortinet","Networking","Security","CLI Errors"],"aliases":["-56","Return code -56","Empty Values Are Not Allowed"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08"},{"id":53007,"title":"FortiOS -61 - Input Not as Expected","category":"Fortinet","product":"FortiGate / FortiOS 8.0.0","tags":["Fortinet","FortiGate","FortiOS","Firewall","CLI","Return Code"],"keywords":["-61","return code -61","Command fail. Return code -61","Input Not as Expected","FortiOS CLI error","FortiGate command parse error","firewall troubleshooting"],"errorCode":"-61","eventId":"","severity":"Low","summary":"The CLI parser did not accept the keyword or value at its current position.","rootCause":"Common causes include wrong hierarchy or order, an unavailable model/feature option, changed firmware syntax, a missing prerequisite object or interface, or an intentionally removed command.","resolution":"1. Record the complete prompt, command, parser message, return code, FortiGate model, FortiOS build, and VDOM context.\n2. Check ? at the exact prompt and compare the live tree with the CLI reference for the installed release and model. Confirm prerequisite objects and required fields, then correct the command order or supported syntax; do not force a removed command.\n3. Review the current configuration before any change and preserve a backup or recovery path.\n4. Retry the corrected command in the intended scope.\n5. Show the affected object and validate service behavior without exposing secrets.","emailScript":"Hello,\n\nWe reviewed the FortiGate configuration issue and identified FortiOS return code -61: Input Not as Expected.\n\nWe are validating the command against the firewall model, software version, permissions, and current configuration before applying the least disruptive correction.\n\nPlease let us know if there is an approved change window or recent firewall change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The firewall rejected a configuration command with return code -61. Please do not repeatedly retry or alter firewall settings. Send IT Support the full message, approximate time, firewall name, and what change was being attempted; remove passwords, tokens, private keys, and other secrets.","notes":"Source table description: Input Not as Expected.\nFortiOS displays a summary followed by “Command fail. Return code -61” when command execution fails. A return code identifies an error family, not a universal root cause; the surrounding parser message and configuration context are required.\n\nVersion scope: The code definition was imported from the FortiOS 8.0.0 Administration Guide. Command availability can vary by FortiOS build, FortiGate model, hardware, VDOM mode, feature visibility, and administrator permissions.\nSafety: Start with read-only discovery. Review and back up configuration before mutation. Do not paste secrets or full sensitive configurations into tickets.","commands":[{"shell":"FortiOS CLI","command":"?","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FortiOS CLI","command":"tree","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FortiOS CLI","command":"show","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"FortiOS-8.0.0-Administration_Guide.pdf, CLI troubleshooting cheat sheet — CLI error codes","sourceAuthority":"Fortinet","namespace":"FORTIOS-CLI","platforms":["firewalls"],"lastVerified":"2026-08-08","vendors":["Fortinet"],"products":["FortiGate","FortiOS 8.0.0"],"technologies":["Firewall","FortiOS CLI","Network Security"],"articleCategories":["Firewalls","Fortinet","Networking","Security","CLI Errors"],"aliases":["-61","Return code -61","Input Not as Expected"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08"},{"id":53008,"title":"FortiOS -160 - CFG_ER_GENERIC","category":"Fortinet","product":"FortiGate / FortiOS 8.0.0","tags":["Fortinet","FortiGate","FortiOS","Firewall","CLI","Return Code"],"keywords":["-160","return code -160","Command fail. Return code -160","CFG_ER_GENERIC","FortiOS CLI error","FortiGate command parse error","firewall troubleshooting"],"errorCode":"-160","eventId":"","severity":"Medium","summary":"FortiOS returned a generic configuration error without a more specific public return-code description.","rootCause":"A dependency, object reference, validation rule, feature state, or platform-specific configuration constraint rejected the change.","resolution":"1. Record the complete prompt, command, parser message, return code, FortiGate model, FortiOS build, and VDOM context.\n2. Capture the complete command and parser output, show the affected configuration scope, verify referenced objects and feature availability, and reproduce only in an approved test context. Escalate with firmware, model, configuration scope, and timestamp if the specific constraint remains unclear.\n3. Review the current configuration before any change and preserve a backup or recovery path.\n4. Retry the corrected command in the intended scope.\n5. Show the affected object and validate service behavior without exposing secrets.","emailScript":"Hello,\n\nWe reviewed the FortiGate configuration issue and identified FortiOS return code -160: CFG_ER_GENERIC.\n\nWe are validating the command against the firewall model, software version, permissions, and current configuration before applying the least disruptive correction.\n\nPlease let us know if there is an approved change window or recent firewall change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The firewall rejected a configuration command with return code -160. Please do not repeatedly retry or alter firewall settings. Send IT Support the full message, approximate time, firewall name, and what change was being attempted; remove passwords, tokens, private keys, and other secrets.","notes":"Source table description: CFG_ER_GENERIC.\nFortiOS displays a summary followed by “Command fail. Return code -160” when command execution fails. A return code identifies an error family, not a universal root cause; the surrounding parser message and configuration context are required.\n\nVersion scope: The code definition was imported from the FortiOS 8.0.0 Administration Guide. Command availability can vary by FortiOS build, FortiGate model, hardware, VDOM mode, feature visibility, and administrator permissions.\nSafety: Start with read-only discovery. Review and back up configuration before mutation. Do not paste secrets or full sensitive configurations into tickets.","commands":[{"shell":"FortiOS CLI","command":"?","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FortiOS CLI","command":"tree","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FortiOS CLI","command":"show","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"FortiOS-8.0.0-Administration_Guide.pdf, CLI troubleshooting cheat sheet — CLI error codes","sourceAuthority":"Fortinet","namespace":"FORTIOS-CLI","platforms":["firewalls"],"lastVerified":"2026-08-08","vendors":["Fortinet"],"products":["FortiGate","FortiOS 8.0.0"],"technologies":["Firewall","FortiOS CLI","Network Security"],"articleCategories":["Firewalls","Fortinet","Networking","Security","CLI Errors"],"aliases":["-160","Return code -160","CFG_ER_GENERIC"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08"},{"id":53009,"title":"FortiOS -553 - Configuration Name Conflict","category":"Fortinet","product":"FortiGate / FortiOS 8.0.0","tags":["Fortinet","FortiGate","FortiOS","Firewall","CLI","Return Code"],"keywords":["-553","return code -553","Command fail. Return code -553","Configuration Name Conflict","FortiOS CLI error","FortiGate command parse error","firewall troubleshooting"],"errorCode":"-553","eventId":"","severity":"Medium","summary":"The proposed name conflicts with an interface, VDOM, switch interface, zone, or hardware-switch interface name.","rootCause":"FortiOS requires names to remain unique across overlapping configuration namespaces.","resolution":"1. Record the complete prompt, command, parser message, return code, FortiGate model, FortiOS build, and VDOM context.\n2. Inspect the relevant interface, VDOM, switch-interface, zone, and hardware-switch configuration for the existing name. Choose a unique approved name or rename an existing object only after dependency and outage-impact review.\n3. Review the current configuration before any change and preserve a backup or recovery path.\n4. Retry the corrected command in the intended scope.\n5. Show the affected object and validate service behavior without exposing secrets.","emailScript":"Hello,\n\nWe reviewed the FortiGate configuration issue and identified FortiOS return code -553: Configuration Name Conflict.\n\nWe are validating the command against the firewall model, software version, permissions, and current configuration before applying the least disruptive correction.\n\nPlease let us know if there is an approved change window or recent firewall change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The firewall rejected a configuration command with return code -553. Please do not repeatedly retry or alter firewall settings. Send IT Support the full message, approximate time, firewall name, and what change was being attempted; remove passwords, tokens, private keys, and other secrets.","notes":"Source table description: Configuration Name Conflict.\nFortiOS displays a summary followed by “Command fail. Return code -553” when command execution fails. A return code identifies an error family, not a universal root cause; the surrounding parser message and configuration context are required.\n\nVersion scope: The code definition was imported from the FortiOS 8.0.0 Administration Guide. Command availability can vary by FortiOS build, FortiGate model, hardware, VDOM mode, feature visibility, and administrator permissions.\nSafety: Start with read-only discovery. Review and back up configuration before mutation. Do not paste secrets or full sensitive configurations into tickets.","commands":[{"shell":"FortiOS CLI","command":"?","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FortiOS CLI","command":"tree","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FortiOS CLI","command":"show","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"FortiOS-8.0.0-Administration_Guide.pdf, CLI troubleshooting cheat sheet — CLI error codes","sourceAuthority":"Fortinet","namespace":"FORTIOS-CLI","platforms":["firewalls"],"lastVerified":"2026-08-08","vendors":["Fortinet"],"products":["FortiGate","FortiOS 8.0.0"],"technologies":["Firewall","FortiOS CLI","Network Security"],"articleCategories":["Firewalls","Fortinet","Networking","Security","CLI Errors"],"aliases":["-553","Return code -553","Configuration Name Conflict"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08"},{"id":53010,"title":"FortiOS -651 - Input Value Is Invalid","category":"Fortinet","product":"FortiGate / FortiOS 8.0.0","tags":["Fortinet","FortiGate","FortiOS","Firewall","CLI","Return Code"],"keywords":["-651","return code -651","Command fail. Return code -651","Input Value Is Invalid","FortiOS CLI error","FortiGate command parse error","firewall troubleshooting"],"errorCode":"-651","eventId":"","severity":"Medium","summary":"A value is syntactically present but is not valid for the selected object or field.","rootCause":"The value can violate a range or naming rule, reference the wrong object type, use an interface that belongs to a zone, or be unsupported by the current release/model. Fortinet documents examples involving spaces in SD-WAN rule names and selecting a zone member instead of the zone in a firewall policy.","resolution":"1. Record the complete prompt, command, parser message, return code, FortiGate model, FortiOS build, and VDOM context.\n2. Use ? to validate the field's allowed format and inspect referenced objects. Remove unsupported characters where documented; if an interface belongs to a zone, reference the zone when the policy requires it. Confirm the correction against the installed FortiOS release before saving.\n3. Review the current configuration before any change and preserve a backup or recovery path.\n4. Retry the corrected command in the intended scope.\n5. Show the affected object and validate service behavior without exposing secrets.","emailScript":"Hello,\n\nWe reviewed the FortiGate configuration issue and identified FortiOS return code -651: Input Value Is Invalid.\n\nWe are validating the command against the firewall model, software version, permissions, and current configuration before applying the least disruptive correction.\n\nPlease let us know if there is an approved change window or recent firewall change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The firewall rejected a configuration command with return code -651. Please do not repeatedly retry or alter firewall settings. Send IT Support the full message, approximate time, firewall name, and what change was being attempted; remove passwords, tokens, private keys, and other secrets.","notes":"Source table description: Input Value Is Invalid.\nFortiOS displays a summary followed by “Command fail. Return code -651” when command execution fails. A return code identifies an error family, not a universal root cause; the surrounding parser message and configuration context are required.\n\nVersion scope: The code definition was imported from the FortiOS 8.0.0 Administration Guide. Command availability can vary by FortiOS build, FortiGate model, hardware, VDOM mode, feature visibility, and administrator permissions.\nSafety: Start with read-only discovery. Review and back up configuration before mutation. Do not paste secrets or full sensitive configurations into tickets.","commands":[{"shell":"FortiOS CLI","command":"?","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FortiOS CLI","command":"tree","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FortiOS CLI","command":"show","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"FortiOS-8.0.0-Administration_Guide.pdf, CLI troubleshooting cheat sheet — CLI error codes","sourceAuthority":"Fortinet","namespace":"FORTIOS-CLI","platforms":["firewalls"],"lastVerified":"2026-08-08","vendors":["Fortinet"],"products":["FortiGate","FortiOS 8.0.0"],"technologies":["Firewall","FortiOS CLI","Network Security"],"articleCategories":["Firewalls","Fortinet","Networking","Security","CLI Errors"],"aliases":["-651","Return code -651","Input Value Is Invalid"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08"},{"id":53020,"title":"FortiOS CLI Command Failure - Diagnostic Workflow","category":"Fortinet","product":"FortiGate / FortiOS","tags":["Fortinet","FortiGate","FortiOS","Firewall","CLI","Troubleshooting"],"keywords":["FortiOS CLI error","command fail","command parse error","return code","question mark","command tree","firewall CLI"],"errorCode":"","eventId":"","severity":"Medium","summary":"A safe evidence-first workflow for diagnosing FortiOS CLI parse and configuration failures before changing firewall settings.","rootCause":"FortiOS commands and options can vary by firmware, FortiGate model, hardware, enabled feature, operating mode, VDOM context, administrator profile, and required object dependencies.","resolution":"1. Capture the full prompt, command, parser line, return code, model, FortiOS build, VDOM, and time.\n2. Enter ? at the exact CLI level to see valid commands and values.\n3. Use tree or a scoped tree branch to confirm command availability.\n4. Use show at the affected scope to understand existing configuration and object references.\n5. Compare with the CLI reference for the installed release—not merely the newest release.\n6. Correct only the confirmed syntax, context, permission, dependency, or naming issue under change control.\n7. Show the resulting object and validate traffic or service behavior.\n8. Escalate with sanitized evidence and a configuration backup when the constraint remains unclear.","emailScript":"Hello,\n\nWe are reviewing a FortiGate command failure. We will confirm the firewall model, software build, permissions, and current configuration before making a controlled correction.\n\nPlease share the approximate time and intended change, and let us know if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete error message and describe the intended firewall change. Do not share passwords, tokens, private keys, pre-shared keys, or an unredacted full configuration.","notes":"The live ? and tree output are authoritative for options exposed by that device and release. A missing option can reflect model, hardware, mode, feature, permission, or firmware differences—not necessarily corruption. Avoid blind configuration deletion, firmware downgrade, factory reset, or firewall reboot as generic fixes.","commands":[{"shell":"FortiOS CLI","command":"?","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FortiOS CLI","command":"tree","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FortiOS CLI","command":"get system status","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FortiOS CLI","command":"show","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"FortiOS-8.0.0-Administration_Guide.pdf; Fortinet FortiOS CLI reference","sourceAuthority":"Fortinet","namespace":"FORTIOS-CLI","platforms":["firewalls"],"lastVerified":"2026-08-08","vendors":["Fortinet"],"products":["FortiGate","FortiOS"],"technologies":["Firewall","FortiOS CLI","Network Security"],"articleCategories":["Firewalls","Fortinet","Networking","Security","CLI Errors"],"aliases":["FortiGate command fail","FortiOS command parse error"],"dateAdded":"2026-08-08","lastUpdated":"2026-08-08"},{"id":55000,"title":"SonicOS API 200 E_OK - Success","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","200 OK","E_OK"],"keywords":["E_OK","200 E_OK","HTTP 200","OK","Success.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_OK","eventId":"","severity":"Low","summary":"SonicOS API returned 200 OK with E_OK: Success.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 200 E_OK must be interpreted as a pair.","resolution":"1. Capture the 200 E_OK response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Confirm the returned state and intended configuration; no error repair is required unless the message or resulting state is unexpected.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 200 E_OK: Success.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 200 OK. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Success.\nHTTP pairing: 200 OK / E_OK\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 2xx"],"aliases":["E_OK","200 E_OK","SonicOS E_OK"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55001,"title":"SonicOS API 200 E_WARNING - Warning; review the detail warning in the message field","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","200 OK","E_WARNING"],"keywords":["E_WARNING","200 E_WARNING","HTTP 200","OK","Warning; review the detail warning in the message field.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_WARNING","eventId":"","severity":"Low","summary":"SonicOS API returned 200 OK with E_WARNING: Warning; review the detail warning in the message field.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 200 E_WARNING must be interpreted as a pair.","resolution":"1. Capture the 200 E_WARNING response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Read the response message and confirm whether the requested state is safe and complete before treating the call as successful.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 200 E_WARNING: Warning; review the detail warning in the message field.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 200 OK. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Warning; review the detail warning in the message field.\nHTTP pairing: 200 OK / E_WARNING\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 2xx"],"aliases":["E_WARNING","200 E_WARNING","SonicOS E_WARNING"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55002,"title":"SonicOS API 200 E_NO_CHANGE - No changes made","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","200 OK","E_NO_CHANGE"],"keywords":["E_NO_CHANGE","200 E_NO_CHANGE","HTTP 200","OK","No changes made.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_NO_CHANGE","eventId":"","severity":"Low","summary":"SonicOS API returned 200 OK with E_NO_CHANGE: No changes made.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 200 E_NO_CHANGE must be interpreted as a pair.","resolution":"1. Capture the 200 E_NO_CHANGE response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Confirm the returned state and intended configuration; no error repair is required unless the message or resulting state is unexpected.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 200 E_NO_CHANGE: No changes made.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 200 OK. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: No changes made.\nHTTP pairing: 200 OK / E_NO_CHANGE\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 2xx"],"aliases":["E_NO_CHANGE","200 E_NO_CHANGE","SonicOS E_NO_CHANGE"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55003,"title":"SonicOS API 200 E_CANCEL - Cancelled","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","200 OK","E_CANCEL"],"keywords":["E_CANCEL","200 E_CANCEL","HTTP 200","OK","Cancelled.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_CANCEL","eventId":"","severity":"Low","summary":"SonicOS API returned 200 OK with E_CANCEL: Cancelled.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 200 E_CANCEL must be interpreted as a pair.","resolution":"1. Capture the 200 E_CANCEL response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Confirm the returned state and intended configuration; no error repair is required unless the message or resulting state is unexpected.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 200 E_CANCEL: Cancelled.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 200 OK. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Cancelled.\nHTTP pairing: 200 OK / E_CANCEL\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 2xx"],"aliases":["E_CANCEL","200 E_CANCEL","SonicOS E_CANCEL"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55004,"title":"SonicOS API 200 E_USER_CANCELLED - User cancelled","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","200 OK","E_USER_CANCELLED"],"keywords":["E_USER_CANCELLED","200 E_USER_CANCELLED","HTTP 200","OK","User cancelled.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_USER_CANCELLED","eventId":"","severity":"Low","summary":"SonicOS API returned 200 OK with E_USER_CANCELLED: User cancelled.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 200 E_USER_CANCELLED must be interpreted as a pair.","resolution":"1. Capture the 200 E_USER_CANCELLED response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Confirm the returned state and intended configuration; no error repair is required unless the message or resulting state is unexpected.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 200 E_USER_CANCELLED: User cancelled.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 200 OK. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: User cancelled.\nHTTP pairing: 200 OK / E_USER_CANCELLED\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 2xx"],"aliases":["E_USER_CANCELLED","200 E_USER_CANCELLED","SonicOS E_USER_CANCELLED"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55005,"title":"SonicOS API 200 E_EXIT_LOGOUT - User logout","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","200 OK","E_EXIT_LOGOUT"],"keywords":["E_EXIT_LOGOUT","200 E_EXIT_LOGOUT","HTTP 200","OK","User logout.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_EXIT_LOGOUT","eventId":"","severity":"Low","summary":"SonicOS API returned 200 OK with E_EXIT_LOGOUT: User logout.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 200 E_EXIT_LOGOUT must be interpreted as a pair.","resolution":"1. Capture the 200 E_EXIT_LOGOUT response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Confirm the returned state and intended configuration; no error repair is required unless the message or resulting state is unexpected.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 200 E_EXIT_LOGOUT: User logout.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 200 OK. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: User logout.\nHTTP pairing: 200 OK / E_EXIT_LOGOUT\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 2xx"],"aliases":["E_EXIT_LOGOUT","200 E_EXIT_LOGOUT","SonicOS E_EXIT_LOGOUT"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55006,"title":"SonicOS API 200 E_EXT_TERMINATE - Session terminated","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","200 OK","E_EXT_TERMINATE"],"keywords":["E_EXT_TERMINATE","200 E_EXT_TERMINATE","HTTP 200","OK","Session terminated.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_EXT_TERMINATE","eventId":"","severity":"Low","summary":"SonicOS API returned 200 OK with E_EXT_TERMINATE: Session terminated.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 200 E_EXT_TERMINATE must be interpreted as a pair.","resolution":"1. Capture the 200 E_EXT_TERMINATE response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Confirm the returned state and intended configuration; no error repair is required unless the message or resulting state is unexpected.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 200 E_EXT_TERMINATE: Session terminated.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 200 OK. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Session terminated.\nHTTP pairing: 200 OK / E_EXT_TERMINATE\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 2xx"],"aliases":["E_EXT_TERMINATE","200 E_EXT_TERMINATE","SonicOS E_EXT_TERMINATE"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55007,"title":"SonicOS API 200 E_POLICYBANNER_CANCELED - Login aborted because the policy banner was not accepted","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","200 OK","E_POLICYBANNER_CANCELED"],"keywords":["E_POLICYBANNER_CANCELED","200 E_POLICYBANNER_CANCELED","HTTP 200","OK","Login aborted because the policy banner was not accepted.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_POLICYBANNER_CANCELED","eventId":"","severity":"Low","summary":"SonicOS API returned 200 OK with E_POLICYBANNER_CANCELED: Login aborted because the policy banner was not accepted.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 200 E_POLICYBANNER_CANCELED must be interpreted as a pair.","resolution":"1. Capture the 200 E_POLICYBANNER_CANCELED response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Confirm the returned state and intended configuration; no error repair is required unless the message or resulting state is unexpected.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 200 E_POLICYBANNER_CANCELED: Login aborted because the policy banner was not accepted.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 200 OK. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Login aborted because the policy banner was not accepted.\nHTTP pairing: 200 OK / E_POLICYBANNER_CANCELED\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 2xx"],"aliases":["E_POLICYBANNER_CANCELED","200 E_POLICYBANNER_CANCELED","SonicOS E_POLICYBANNER_CANCELED"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55008,"title":"SonicOS API 200 E_TEST_FAILED - The test result was a failure","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","200 OK","E_TEST_FAILED"],"keywords":["E_TEST_FAILED","200 E_TEST_FAILED","HTTP 200","OK","The test result was a failure.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_TEST_FAILED","eventId":"","severity":"Low","summary":"SonicOS API returned 200 OK with E_TEST_FAILED: The test result was a failure.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 200 E_TEST_FAILED must be interpreted as a pair.","resolution":"1. Capture the 200 E_TEST_FAILED response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Inspect the test detail and the tested object's state; correct the evidenced condition and run the test once more.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 200 E_TEST_FAILED: The test result was a failure.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 200 OK. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: The test result was a failure.\nHTTP pairing: 200 OK / E_TEST_FAILED\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 2xx"],"aliases":["E_TEST_FAILED","200 E_TEST_FAILED","SonicOS E_TEST_FAILED"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55009,"title":"SonicOS API 400 E_INVALID_API_CALL - Invalid API call","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","400 Bad Request","E_INVALID_API_CALL"],"keywords":["E_INVALID_API_CALL","400 E_INVALID_API_CALL","HTTP 400","Bad Request","Invalid API call.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_INVALID_API_CALL","eventId":"","severity":"Medium","summary":"SonicOS API returned 400 Bad Request with E_INVALID_API_CALL: Invalid API call.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 400 E_INVALID_API_CALL must be interpreted as a pair.","resolution":"1. Capture the 400 E_INVALID_API_CALL response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Compare the endpoint, HTTP method, content type, JSON body, object name, parameters, ranges, and current SonicOS API schema. Use the response message to correct only the rejected input.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 400 E_INVALID_API_CALL: Invalid API call.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 400 Bad Request. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Invalid API call.\nHTTP pairing: 400 Bad Request / E_INVALID_API_CALL\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_INVALID_API_CALL","400 E_INVALID_API_CALL","SonicOS E_INVALID_API_CALL"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55010,"title":"SonicOS API 400 E_INVALID_FXN_ARG - Invalid API argument","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","400 Bad Request","E_INVALID_FXN_ARG"],"keywords":["E_INVALID_FXN_ARG","400 E_INVALID_FXN_ARG","HTTP 400","Bad Request","Invalid API argument.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_INVALID_FXN_ARG","eventId":"","severity":"Medium","summary":"SonicOS API returned 400 Bad Request with E_INVALID_FXN_ARG: Invalid API argument.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 400 E_INVALID_FXN_ARG must be interpreted as a pair.","resolution":"1. Capture the 400 E_INVALID_FXN_ARG response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Compare the endpoint, HTTP method, content type, JSON body, object name, parameters, ranges, and current SonicOS API schema. Use the response message to correct only the rejected input.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 400 E_INVALID_FXN_ARG: Invalid API argument.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 400 Bad Request. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Invalid API argument.\nHTTP pairing: 400 Bad Request / E_INVALID_FXN_ARG\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_INVALID_FXN_ARG","400 E_INVALID_FXN_ARG","SonicOS E_INVALID_FXN_ARG"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55011,"title":"SonicOS API 400 E_EXISTS - Already exists","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","400 Bad Request","E_EXISTS"],"keywords":["E_EXISTS","400 E_EXISTS","HTTP 400","Bad Request","Already exists.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_EXISTS","eventId":"","severity":"Medium","summary":"SonicOS API returned 400 Bad Request with E_EXISTS: Already exists.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 400 E_EXISTS must be interpreted as a pair.","resolution":"1. Capture the 400 E_EXISTS response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Compare the endpoint, HTTP method, content type, JSON body, object name, parameters, ranges, and current SonicOS API schema. Use the response message to correct only the rejected input.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 400 E_EXISTS: Already exists.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 400 Bad Request. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Already exists.\nHTTP pairing: 400 Bad Request / E_EXISTS\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_EXISTS","400 E_EXISTS","SonicOS E_EXISTS"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55012,"title":"SonicOS API 400 E_NO_MATCH - No matching command found","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","400 Bad Request","E_NO_MATCH"],"keywords":["E_NO_MATCH","400 E_NO_MATCH","HTTP 400","Bad Request","No matching command found.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_NO_MATCH","eventId":"","severity":"Medium","summary":"SonicOS API returned 400 Bad Request with E_NO_MATCH: No matching command found.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 400 E_NO_MATCH must be interpreted as a pair.","resolution":"1. Capture the 400 E_NO_MATCH response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Compare the endpoint, HTTP method, content type, JSON body, object name, parameters, ranges, and current SonicOS API schema. Use the response message to correct only the rejected input.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 400 E_NO_MATCH: No matching command found.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 400 Bad Request. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: No matching command found.\nHTTP pairing: 400 Bad Request / E_NO_MATCH\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_NO_MATCH","400 E_NO_MATCH","SonicOS E_NO_MATCH"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55013,"title":"SonicOS API 400 E_AMBIGUOUS_CMD - Ambiguous command","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","400 Bad Request","E_AMBIGUOUS_CMD"],"keywords":["E_AMBIGUOUS_CMD","400 E_AMBIGUOUS_CMD","HTTP 400","Bad Request","Ambiguous command.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_AMBIGUOUS_CMD","eventId":"","severity":"Medium","summary":"SonicOS API returned 400 Bad Request with E_AMBIGUOUS_CMD: Ambiguous command.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 400 E_AMBIGUOUS_CMD must be interpreted as a pair.","resolution":"1. Capture the 400 E_AMBIGUOUS_CMD response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Compare the endpoint, HTTP method, content type, JSON body, object name, parameters, ranges, and current SonicOS API schema. Use the response message to correct only the rejected input.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 400 E_AMBIGUOUS_CMD: Ambiguous command.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 400 Bad Request. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Ambiguous command.\nHTTP pairing: 400 Bad Request / E_AMBIGUOUS_CMD\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_AMBIGUOUS_CMD","400 E_AMBIGUOUS_CMD","SonicOS E_AMBIGUOUS_CMD"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55014,"title":"SonicOS API 400 E_AMBIGUOUS_PARAM - Ambiguous parameter","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","400 Bad Request","E_AMBIGUOUS_PARAM"],"keywords":["E_AMBIGUOUS_PARAM","400 E_AMBIGUOUS_PARAM","HTTP 400","Bad Request","Ambiguous parameter.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_AMBIGUOUS_PARAM","eventId":"","severity":"Medium","summary":"SonicOS API returned 400 Bad Request with E_AMBIGUOUS_PARAM: Ambiguous parameter.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 400 E_AMBIGUOUS_PARAM must be interpreted as a pair.","resolution":"1. Capture the 400 E_AMBIGUOUS_PARAM response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Compare the endpoint, HTTP method, content type, JSON body, object name, parameters, ranges, and current SonicOS API schema. Use the response message to correct only the rejected input.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 400 E_AMBIGUOUS_PARAM: Ambiguous parameter.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 400 Bad Request. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Ambiguous parameter.\nHTTP pairing: 400 Bad Request / E_AMBIGUOUS_PARAM\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_AMBIGUOUS_PARAM","400 E_AMBIGUOUS_PARAM","SonicOS E_AMBIGUOUS_PARAM"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55015,"title":"SonicOS API 400 E_SYNTAX - Invalid input detected","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","400 Bad Request","E_SYNTAX"],"keywords":["E_SYNTAX","400 E_SYNTAX","HTTP 400","Bad Request","Invalid input detected.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_SYNTAX","eventId":"","severity":"Medium","summary":"SonicOS API returned 400 Bad Request with E_SYNTAX: Invalid input detected.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 400 E_SYNTAX must be interpreted as a pair.","resolution":"1. Capture the 400 E_SYNTAX response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Compare the endpoint, HTTP method, content type, JSON body, object name, parameters, ranges, and current SonicOS API schema. Use the response message to correct only the rejected input.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 400 E_SYNTAX: Invalid input detected.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 400 Bad Request. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Invalid input detected.\nHTTP pairing: 400 Bad Request / E_SYNTAX\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_SYNTAX","400 E_SYNTAX","SonicOS E_SYNTAX"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55016,"title":"SonicOS API 400 E_INCOMPLETE_CMD - Incomplete command","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","400 Bad Request","E_INCOMPLETE_CMD"],"keywords":["E_INCOMPLETE_CMD","400 E_INCOMPLETE_CMD","HTTP 400","Bad Request","Incomplete command.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_INCOMPLETE_CMD","eventId":"","severity":"Medium","summary":"SonicOS API returned 400 Bad Request with E_INCOMPLETE_CMD: Incomplete command.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 400 E_INCOMPLETE_CMD must be interpreted as a pair.","resolution":"1. Capture the 400 E_INCOMPLETE_CMD response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Compare the endpoint, HTTP method, content type, JSON body, object name, parameters, ranges, and current SonicOS API schema. Use the response message to correct only the rejected input.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 400 E_INCOMPLETE_CMD: Incomplete command.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 400 Bad Request. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Incomplete command.\nHTTP pairing: 400 Bad Request / E_INCOMPLETE_CMD\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_INCOMPLETE_CMD","400 E_INCOMPLETE_CMD","SonicOS E_INCOMPLETE_CMD"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55017,"title":"SonicOS API 400 E_EXTRA_TEXT - Extra text detected","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","400 Bad Request","E_EXTRA_TEXT"],"keywords":["E_EXTRA_TEXT","400 E_EXTRA_TEXT","HTTP 400","Bad Request","Extra text detected.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_EXTRA_TEXT","eventId":"","severity":"Medium","summary":"SonicOS API returned 400 Bad Request with E_EXTRA_TEXT: Extra text detected.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 400 E_EXTRA_TEXT must be interpreted as a pair.","resolution":"1. Capture the 400 E_EXTRA_TEXT response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Compare the endpoint, HTTP method, content type, JSON body, object name, parameters, ranges, and current SonicOS API schema. Use the response message to correct only the rejected input.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 400 E_EXTRA_TEXT: Extra text detected.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 400 Bad Request. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Extra text detected.\nHTTP pairing: 400 Bad Request / E_EXTRA_TEXT\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_EXTRA_TEXT","400 E_EXTRA_TEXT","SonicOS E_EXTRA_TEXT"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55018,"title":"SonicOS API 400 E_RANGE - Out of bounds condition","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","400 Bad Request","E_RANGE"],"keywords":["E_RANGE","400 E_RANGE","HTTP 400","Bad Request","Out of bounds condition.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_RANGE","eventId":"","severity":"Medium","summary":"SonicOS API returned 400 Bad Request with E_RANGE: Out of bounds condition.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 400 E_RANGE must be interpreted as a pair.","resolution":"1. Capture the 400 E_RANGE response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Compare the endpoint, HTTP method, content type, JSON body, object name, parameters, ranges, and current SonicOS API schema. Use the response message to correct only the rejected input.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 400 E_RANGE: Out of bounds condition.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 400 Bad Request. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Out of bounds condition.\nHTTP pairing: 400 Bad Request / E_RANGE\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_RANGE","400 E_RANGE","SonicOS E_RANGE"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55019,"title":"SonicOS API 400 E_ACCESS_DENIED - SSLVPN login is disabled or the request did not arrive through the SSLVPN port","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","400 Bad Request","E_ACCESS_DENIED"],"keywords":["E_ACCESS_DENIED","400 E_ACCESS_DENIED","HTTP 400","Bad Request","SSLVPN login is disabled or the request did not arrive through the SSLVPN port.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_ACCESS_DENIED","eventId":"","severity":"Medium","summary":"SonicOS API returned 400 Bad Request with E_ACCESS_DENIED: SSLVPN login is disabled or the request did not arrive through the SSLVPN port.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 400 E_ACCESS_DENIED must be interpreted as a pair.","resolution":"1. Capture the 400 E_ACCESS_DENIED response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Compare the endpoint, HTTP method, content type, JSON body, object name, parameters, ranges, and current SonicOS API schema. Use the response message to correct only the rejected input.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 400 E_ACCESS_DENIED: SSLVPN login is disabled or the request did not arrive through the SSLVPN port.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 400 Bad Request. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: SSLVPN login is disabled or the request did not arrive through the SSLVPN port.\nHTTP pairing: 400 Bad Request / E_ACCESS_DENIED\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_ACCESS_DENIED","400 E_ACCESS_DENIED","SonicOS E_ACCESS_DENIED"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55020,"title":"SonicOS API 400 E_ERROR - Error; review the detail error in the message field","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","400 Bad Request","E_ERROR"],"keywords":["E_ERROR","400 E_ERROR","HTTP 400","Bad Request","Error; review the detail error in the message field.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_ERROR","eventId":"","severity":"Medium","summary":"SonicOS API returned 400 Bad Request with E_ERROR: Error; review the detail error in the message field.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 400 E_ERROR must be interpreted as a pair.","resolution":"1. Capture the 400 E_ERROR response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Compare the endpoint, HTTP method, content type, JSON body, object name, parameters, ranges, and current SonicOS API schema. Use the response message to correct only the rejected input.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 400 E_ERROR: Error; review the detail error in the message field.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 400 Bad Request. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Error; review the detail error in the message field.\nHTTP pairing: 400 Bad Request / E_ERROR\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_ERROR","400 E_ERROR","SonicOS E_ERROR"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55021,"title":"SonicOS API 401 E_UNAUTHORIZED - Unauthorized","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","401 Unauthorized","E_UNAUTHORIZED"],"keywords":["E_UNAUTHORIZED","401 E_UNAUTHORIZED","HTTP 401","Unauthorized","Unauthorized.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_UNAUTHORIZED","eventId":"","severity":"Medium","summary":"SonicOS API returned 401 Unauthorized with E_UNAUTHORIZED: Unauthorized.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 401 E_UNAUTHORIZED must be interpreted as a pair.","resolution":"1. Capture the 401 E_UNAUTHORIZED response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Verify the API account, authentication method, session state, client-certificate requirement, lockout status, and login-attempt policy. Do not bypass authentication controls.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 401 E_UNAUTHORIZED: Unauthorized.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 401 Unauthorized. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Unauthorized.\nHTTP pairing: 401 Unauthorized / E_UNAUTHORIZED\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_UNAUTHORIZED","401 E_UNAUTHORIZED","SonicOS E_UNAUTHORIZED"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55022,"title":"SonicOS API 401 E_MAX_LOGIN_ATTEMPTS - Maximum login attempts exceeded","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","401 Unauthorized","E_MAX_LOGIN_ATTEMPTS"],"keywords":["E_MAX_LOGIN_ATTEMPTS","401 E_MAX_LOGIN_ATTEMPTS","HTTP 401","Unauthorized","Maximum login attempts exceeded.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_MAX_LOGIN_ATTEMPTS","eventId":"","severity":"Medium","summary":"SonicOS API returned 401 Unauthorized with E_MAX_LOGIN_ATTEMPTS: Maximum login attempts exceeded.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 401 E_MAX_LOGIN_ATTEMPTS must be interpreted as a pair.","resolution":"1. Capture the 401 E_MAX_LOGIN_ATTEMPTS response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Verify the API account, authentication method, session state, client-certificate requirement, lockout status, and login-attempt policy. Do not bypass authentication controls.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 401 E_MAX_LOGIN_ATTEMPTS: Maximum login attempts exceeded.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 401 Unauthorized. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Maximum login attempts exceeded.\nHTTP pairing: 401 Unauthorized / E_MAX_LOGIN_ATTEMPTS\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_MAX_LOGIN_ATTEMPTS","401 E_MAX_LOGIN_ATTEMPTS","SonicOS E_MAX_LOGIN_ATTEMPTS"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55023,"title":"SonicOS API 401 E_USER_LOCKOUT - User is locked out","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","401 Unauthorized","E_USER_LOCKOUT"],"keywords":["E_USER_LOCKOUT","401 E_USER_LOCKOUT","HTTP 401","Unauthorized","User is locked out.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_USER_LOCKOUT","eventId":"","severity":"Medium","summary":"SonicOS API returned 401 Unauthorized with E_USER_LOCKOUT: User is locked out.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 401 E_USER_LOCKOUT must be interpreted as a pair.","resolution":"1. Capture the 401 E_USER_LOCKOUT response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Verify the API account, authentication method, session state, client-certificate requirement, lockout status, and login-attempt policy. Do not bypass authentication controls.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 401 E_USER_LOCKOUT: User is locked out.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 401 Unauthorized. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: User is locked out.\nHTTP pairing: 401 Unauthorized / E_USER_LOCKOUT\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_USER_LOCKOUT","401 E_USER_LOCKOUT","SonicOS E_USER_LOCKOUT"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55024,"title":"SonicOS API 401 E_REQUIRE_CLIENT_CERT - Client-certificate login is required","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","401 Unauthorized","E_REQUIRE_CLIENT_CERT"],"keywords":["E_REQUIRE_CLIENT_CERT","401 E_REQUIRE_CLIENT_CERT","HTTP 401","Unauthorized","Client-certificate login is required.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_REQUIRE_CLIENT_CERT","eventId":"","severity":"Medium","summary":"SonicOS API returned 401 Unauthorized with E_REQUIRE_CLIENT_CERT: Client-certificate login is required.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 401 E_REQUIRE_CLIENT_CERT must be interpreted as a pair.","resolution":"1. Capture the 401 E_REQUIRE_CLIENT_CERT response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Verify the API account, authentication method, session state, client-certificate requirement, lockout status, and login-attempt policy. Do not bypass authentication controls.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 401 E_REQUIRE_CLIENT_CERT: Client-certificate login is required.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 401 Unauthorized. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Client-certificate login is required.\nHTTP pairing: 401 Unauthorized / E_REQUIRE_CLIENT_CERT\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_REQUIRE_CLIENT_CERT","401 E_REQUIRE_CLIENT_CERT","SonicOS E_REQUIRE_CLIENT_CERT"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55025,"title":"SonicOS API 401 E_NO_CLIENT_CERT - Client-certificate login is not supported","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","401 Unauthorized","E_NO_CLIENT_CERT"],"keywords":["E_NO_CLIENT_CERT","401 E_NO_CLIENT_CERT","HTTP 401","Unauthorized","Client-certificate login is not supported.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_NO_CLIENT_CERT","eventId":"","severity":"Medium","summary":"SonicOS API returned 401 Unauthorized with E_NO_CLIENT_CERT: Client-certificate login is not supported.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 401 E_NO_CLIENT_CERT must be interpreted as a pair.","resolution":"1. Capture the 401 E_NO_CLIENT_CERT response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Verify the API account, authentication method, session state, client-certificate requirement, lockout status, and login-attempt policy. Do not bypass authentication controls.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 401 E_NO_CLIENT_CERT: Client-certificate login is not supported.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 401 Unauthorized. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Client-certificate login is not supported.\nHTTP pairing: 401 Unauthorized / E_NO_CLIENT_CERT\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_NO_CLIENT_CERT","401 E_NO_CLIENT_CERT","SonicOS E_NO_CLIENT_CERT"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55026,"title":"SonicOS API 403 E_ACCESS_DENIED - Access denied","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","403 Forbidden","E_ACCESS_DENIED"],"keywords":["E_ACCESS_DENIED","403 E_ACCESS_DENIED","HTTP 403","Forbidden","Access denied.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_ACCESS_DENIED","eventId":"","severity":"Medium","summary":"SonicOS API returned 403 Forbidden with E_ACCESS_DENIED: Access denied.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 403 E_ACCESS_DENIED must be interpreted as a pair.","resolution":"1. Capture the 403 E_ACCESS_DENIED response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Confirm that SonicOS API or SSLVPN access is enabled as applicable and that the authenticated administrator role is authorized for the requested operation.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 403 E_ACCESS_DENIED: Access denied.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 403 Forbidden. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Access denied.\nHTTP pairing: 403 Forbidden / E_ACCESS_DENIED\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_ACCESS_DENIED","403 E_ACCESS_DENIED","SonicOS E_ACCESS_DENIED"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55027,"title":"SonicOS API 403 E_DISABLED - Service is disabled","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","403 Forbidden","E_DISABLED"],"keywords":["E_DISABLED","403 E_DISABLED","HTTP 403","Forbidden","Service is disabled.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_DISABLED","eventId":"","severity":"Medium","summary":"SonicOS API returned 403 Forbidden with E_DISABLED: Service is disabled.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 403 E_DISABLED must be interpreted as a pair.","resolution":"1. Capture the 403 E_DISABLED response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Confirm that SonicOS API or SSLVPN access is enabled as applicable and that the authenticated administrator role is authorized for the requested operation.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 403 E_DISABLED: Service is disabled.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 403 Forbidden. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Service is disabled.\nHTTP pairing: 403 Forbidden / E_DISABLED\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_DISABLED","403 E_DISABLED","SonicOS E_DISABLED"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55028,"title":"SonicOS API 404 E_NOT_FOUND - Not found","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","404 Not Found","E_NOT_FOUND"],"keywords":["E_NOT_FOUND","404 E_NOT_FOUND","HTTP 404","Not Found","Not found.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_NOT_FOUND","eventId":"","severity":"Medium","summary":"SonicOS API returned 404 Not Found with E_NOT_FOUND: Not found.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 404 E_NOT_FOUND must be interpreted as a pair.","resolution":"1. Capture the 404 E_NOT_FOUND response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Verify the endpoint, API version, object identifier, resource existence, and OpenAPI availability on the installed SonicOS release.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 404 E_NOT_FOUND: Not found.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 404 Not Found. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Not found.\nHTTP pairing: 404 Not Found / E_NOT_FOUND\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_NOT_FOUND","404 E_NOT_FOUND","SonicOS E_NOT_FOUND"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55029,"title":"SonicOS API 404 E_ERROR - Not found","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","404 Not Found","E_ERROR"],"keywords":["E_ERROR","404 E_ERROR","HTTP 404","Not Found","Not found.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_ERROR","eventId":"","severity":"Medium","summary":"SonicOS API returned 404 Not Found with E_ERROR: Not found.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 404 E_ERROR must be interpreted as a pair.","resolution":"1. Capture the 404 E_ERROR response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Verify the endpoint, API version, object identifier, resource existence, and OpenAPI availability on the installed SonicOS release.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 404 E_ERROR: Not found.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 404 Not Found. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Not found.\nHTTP pairing: 404 Not Found / E_ERROR\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_ERROR","404 E_ERROR","SonicOS E_ERROR"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55030,"title":"SonicOS API 405 E_DISABLED - Feature is currently disabled","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","405 Method Not Allowed","E_DISABLED"],"keywords":["E_DISABLED","405 E_DISABLED","HTTP 405","Method Not Allowed","Feature is currently disabled.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_DISABLED","eventId":"","severity":"Medium","summary":"SonicOS API returned 405 Method Not Allowed with E_DISABLED: Feature is currently disabled.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 405 E_DISABLED must be interpreted as a pair.","resolution":"1. Capture the 405 E_DISABLED response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Verify the HTTP method, administrator mode, HA role, feature state, license, and whether the session is read-only before changing configuration.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 405 E_DISABLED: Feature is currently disabled.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 405 Method Not Allowed. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Feature is currently disabled.\nHTTP pairing: 405 Method Not Allowed / E_DISABLED\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_DISABLED","405 E_DISABLED","SonicOS E_DISABLED"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55031,"title":"SonicOS API 405 E_UNLICENSED - Licensing must be activated for this feature","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","405 Method Not Allowed","E_UNLICENSED"],"keywords":["E_UNLICENSED","405 E_UNLICENSED","HTTP 405","Method Not Allowed","Licensing must be activated for this feature.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_UNLICENSED","eventId":"","severity":"Medium","summary":"SonicOS API returned 405 Method Not Allowed with E_UNLICENSED: Licensing must be activated for this feature.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 405 E_UNLICENSED must be interpreted as a pair.","resolution":"1. Capture the 405 E_UNLICENSED response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Verify the HTTP method, administrator mode, HA role, feature state, license, and whether the session is read-only before changing configuration.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 405 E_UNLICENSED: Licensing must be activated for this feature.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 405 Method Not Allowed. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Licensing must be activated for this feature.\nHTTP pairing: 405 Method Not Allowed / E_UNLICENSED\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_UNLICENSED","405 E_UNLICENSED","SonicOS E_UNLICENSED"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55032,"title":"SonicOS API 405 E_HA_IDLE - An idle HA firewall cannot be configured","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","405 Method Not Allowed","E_HA_IDLE"],"keywords":["E_HA_IDLE","405 E_HA_IDLE","HTTP 405","Method Not Allowed","An idle HA firewall cannot be configured.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_HA_IDLE","eventId":"","severity":"Medium","summary":"SonicOS API returned 405 Method Not Allowed with E_HA_IDLE: An idle HA firewall cannot be configured.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 405 E_HA_IDLE must be interpreted as a pair.","resolution":"1. Capture the 405 E_HA_IDLE response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Verify the HTTP method, administrator mode, HA role, feature state, license, and whether the session is read-only before changing configuration.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 405 E_HA_IDLE: An idle HA firewall cannot be configured.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 405 Method Not Allowed. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: An idle HA firewall cannot be configured.\nHTTP pairing: 405 Method Not Allowed / E_HA_IDLE\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_HA_IDLE","405 E_HA_IDLE","SonicOS E_HA_IDLE"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55033,"title":"SonicOS API 405 E_READ_ONLY - Read-only context","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","405 Method Not Allowed","E_READ_ONLY"],"keywords":["E_READ_ONLY","405 E_READ_ONLY","HTTP 405","Method Not Allowed","Read-only context.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_READ_ONLY","eventId":"","severity":"Medium","summary":"SonicOS API returned 405 Method Not Allowed with E_READ_ONLY: Read-only context.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 405 E_READ_ONLY must be interpreted as a pair.","resolution":"1. Capture the 405 E_READ_ONLY response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Verify the HTTP method, administrator mode, HA role, feature state, license, and whether the session is read-only before changing configuration.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 405 E_READ_ONLY: Read-only context.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 405 Method Not Allowed. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Read-only context.\nHTTP pairing: 405 Method Not Allowed / E_READ_ONLY\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_READ_ONLY","405 E_READ_ONLY","SonicOS E_READ_ONLY"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55034,"title":"SonicOS API 405 E_NON_CONFIG - Non-configuration mode","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","405 Method Not Allowed","E_NON_CONFIG"],"keywords":["E_NON_CONFIG","405 E_NON_CONFIG","HTTP 405","Method Not Allowed","Non-configuration mode.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_NON_CONFIG","eventId":"","severity":"Medium","summary":"SonicOS API returned 405 Method Not Allowed with E_NON_CONFIG: Non-configuration mode.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 405 E_NON_CONFIG must be interpreted as a pair.","resolution":"1. Capture the 405 E_NON_CONFIG response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Verify the HTTP method, administrator mode, HA role, feature state, license, and whether the session is read-only before changing configuration.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 405 E_NON_CONFIG: Non-configuration mode.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 405 Method Not Allowed. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Non-configuration mode.\nHTTP pairing: 405 Method Not Allowed / E_NON_CONFIG\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_NON_CONFIG","405 E_NON_CONFIG","SonicOS E_NON_CONFIG"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55035,"title":"SonicOS API 405 E_INVALID_API_CALL - The API does not support the requested method","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","405 Method Not Allowed","E_INVALID_API_CALL"],"keywords":["E_INVALID_API_CALL","405 E_INVALID_API_CALL","HTTP 405","Method Not Allowed","The API does not support the requested method.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_INVALID_API_CALL","eventId":"","severity":"Medium","summary":"SonicOS API returned 405 Method Not Allowed with E_INVALID_API_CALL: The API does not support the requested method.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 405 E_INVALID_API_CALL must be interpreted as a pair.","resolution":"1. Capture the 405 E_INVALID_API_CALL response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Verify the HTTP method, administrator mode, HA role, feature state, license, and whether the session is read-only before changing configuration.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 405 E_INVALID_API_CALL: The API does not support the requested method.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 405 Method Not Allowed. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: The API does not support the requested method.\nHTTP pairing: 405 Method Not Allowed / E_INVALID_API_CALL\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_INVALID_API_CALL","405 E_INVALID_API_CALL","SonicOS E_INVALID_API_CALL"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55036,"title":"SonicOS API 405 E_ERROR - The operation is not allowed in the current mode","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","405 Method Not Allowed","E_ERROR"],"keywords":["E_ERROR","405 E_ERROR","HTTP 405","Method Not Allowed","The operation is not allowed in the current mode.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_ERROR","eventId":"","severity":"Medium","summary":"SonicOS API returned 405 Method Not Allowed with E_ERROR: The operation is not allowed in the current mode.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 405 E_ERROR must be interpreted as a pair.","resolution":"1. Capture the 405 E_ERROR response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Verify the HTTP method, administrator mode, HA role, feature state, license, and whether the session is read-only before changing configuration.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 405 E_ERROR: The operation is not allowed in the current mode.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 405 Method Not Allowed. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: The operation is not allowed in the current mode.\nHTTP pairing: 405 Method Not Allowed / E_ERROR\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_ERROR","405 E_ERROR","SonicOS E_ERROR"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55037,"title":"SonicOS API 406 E_INVALID_API_CA - The API does not support the requested content type","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","406 Not Acceptable","E_INVALID_API_CA"],"keywords":["E_INVALID_API_CA","406 E_INVALID_API_CA","HTTP 406","Not Acceptable","The API does not support the requested content type.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_INVALID_API_CA","eventId":"","severity":"Medium","summary":"SonicOS API returned 406 Not Acceptable with E_INVALID_API_CA: The API does not support the requested content type.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 406 E_INVALID_API_CA must be interpreted as a pair.","resolution":"1. Capture the 406 E_INVALID_API_CA response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Set Accept and Content-Type to formats supported by the endpoint and installed SonicOS API version.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 406 E_INVALID_API_CA: The API does not support the requested content type.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 406 Not Acceptable. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: The API does not support the requested content type.\nHTTP pairing: 406 Not Acceptable / E_INVALID_API_CA\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_INVALID_API_CA","406 E_INVALID_API_CA","SonicOS E_INVALID_API_CA"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55038,"title":"SonicOS API 413 E_TOO_BIG - The maximum request-body size was exceeded","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","413 Payload Too Large","E_TOO_BIG"],"keywords":["E_TOO_BIG","413 E_TOO_BIG","HTTP 413","Payload Too Large","The maximum request-body size was exceeded.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_TOO_BIG","eventId":"","severity":"Medium","summary":"SonicOS API returned 413 Payload Too Large with E_TOO_BIG: The maximum request-body size was exceeded.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 413 E_TOO_BIG must be interpreted as a pair.","resolution":"1. Capture the 413 E_TOO_BIG response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Reduce or divide the request body according to the endpoint schema; do not raise limits without confirming appliance and release support.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 413 E_TOO_BIG: The maximum request-body size was exceeded.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 413 Payload Too Large. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: The maximum request-body size was exceeded.\nHTTP pairing: 413 Payload Too Large / E_TOO_BIG\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_TOO_BIG","413 E_TOO_BIG","SonicOS E_TOO_BIG"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55039,"title":"SonicOS API 414 E_INVALID_API_CALL - The API endpoint URI is too long","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","414 URI Too Long","E_INVALID_API_CALL"],"keywords":["E_INVALID_API_CALL","414 E_INVALID_API_CALL","HTTP 414","URI Too Long","The API endpoint URI is too long.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_INVALID_API_CALL","eventId":"","severity":"Medium","summary":"SonicOS API returned 414 URI Too Long with E_INVALID_API_CALL: The API endpoint URI is too long.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 414 E_INVALID_API_CALL must be interpreted as a pair.","resolution":"1. Capture the 414 E_INVALID_API_CALL response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Correct or shorten the endpoint and query string; move data to a request body only when that endpoint and method support it.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 414 E_INVALID_API_CALL: The API endpoint URI is too long.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 414 URI Too Long. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: The API endpoint URI is too long.\nHTTP pairing: 414 URI Too Long / E_INVALID_API_CALL\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 4xx"],"aliases":["E_INVALID_API_CALL","414 E_INVALID_API_CALL","SonicOS E_INVALID_API_CALL"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55040,"title":"SonicOS API 500 E_ERROR - Internal error; review the detail error in the message field","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","500 Internal Server Error","E_ERROR"],"keywords":["E_ERROR","500 E_ERROR","HTTP 500","Internal Server Error","Internal error; review the detail error in the message field.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_ERROR","eventId":"","severity":"High","summary":"SonicOS API returned 500 Internal Server Error with E_ERROR: Internal error; review the detail error in the message field.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 500 E_ERROR must be interpreted as a pair.","resolution":"1. Capture the 500 E_ERROR response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Capture the response message, request ID, timestamp, endpoint, method, SonicOS version, HA state, and sanitized logs. Check resource and session health, then escalate persistent internal failures with evidence.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 500 E_ERROR: Internal error; review the detail error in the message field.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 500 Internal Server Error. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Internal error; review the detail error in the message field.\nHTTP pairing: 500 Internal Server Error / E_ERROR\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 5xx"],"aliases":["E_ERROR","500 E_ERROR","SonicOS E_ERROR"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55041,"title":"SonicOS API 500 E_TIME_OUT - Session timed out","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","500 Internal Server Error","E_TIME_OUT"],"keywords":["E_TIME_OUT","500 E_TIME_OUT","HTTP 500","Internal Server Error","Session timed out.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_TIME_OUT","eventId":"","severity":"High","summary":"SonicOS API returned 500 Internal Server Error with E_TIME_OUT: Session timed out.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 500 E_TIME_OUT must be interpreted as a pair.","resolution":"1. Capture the 500 E_TIME_OUT response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Capture the response message, request ID, timestamp, endpoint, method, SonicOS version, HA state, and sanitized logs. Check resource and session health, then escalate persistent internal failures with evidence.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 500 E_TIME_OUT: Session timed out.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 500 Internal Server Error. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Session timed out.\nHTTP pairing: 500 Internal Server Error / E_TIME_OUT\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 5xx"],"aliases":["E_TIME_OUT","500 E_TIME_OUT","SonicOS E_TIME_OUT"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55042,"title":"SonicOS API 500 E_LOST_CONN - Connection lost","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","500 Internal Server Error","E_LOST_CONN"],"keywords":["E_LOST_CONN","500 E_LOST_CONN","HTTP 500","Internal Server Error","Connection lost.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_LOST_CONN","eventId":"","severity":"High","summary":"SonicOS API returned 500 Internal Server Error with E_LOST_CONN: Connection lost.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 500 E_LOST_CONN must be interpreted as a pair.","resolution":"1. Capture the 500 E_LOST_CONN response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Capture the response message, request ID, timestamp, endpoint, method, SonicOS version, HA state, and sanitized logs. Check resource and session health, then escalate persistent internal failures with evidence.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 500 E_LOST_CONN: Connection lost.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 500 Internal Server Error. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Connection lost.\nHTTP pairing: 500 Internal Server Error / E_LOST_CONN\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 5xx"],"aliases":["E_LOST_CONN","500 E_LOST_CONN","SonicOS E_LOST_CONN"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55043,"title":"SonicOS API 500 E_PIPE_TIME_OUT - CLI pipe execution script timed out","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","500 Internal Server Error","E_PIPE_TIME_OUT"],"keywords":["E_PIPE_TIME_OUT","500 E_PIPE_TIME_OUT","HTTP 500","Internal Server Error","CLI pipe execution script timed out.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_PIPE_TIME_OUT","eventId":"","severity":"High","summary":"SonicOS API returned 500 Internal Server Error with E_PIPE_TIME_OUT: CLI pipe execution script timed out.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 500 E_PIPE_TIME_OUT must be interpreted as a pair.","resolution":"1. Capture the 500 E_PIPE_TIME_OUT response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Capture the response message, request ID, timestamp, endpoint, method, SonicOS version, HA state, and sanitized logs. Check resource and session health, then escalate persistent internal failures with evidence.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 500 E_PIPE_TIME_OUT: CLI pipe execution script timed out.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 500 Internal Server Error. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: CLI pipe execution script timed out.\nHTTP pairing: 500 Internal Server Error / E_PIPE_TIME_OUT\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 5xx"],"aliases":["E_PIPE_TIME_OUT","500 E_PIPE_TIME_OUT","SonicOS E_PIPE_TIME_OUT"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55044,"title":"SonicOS API 500 E_OUT_OF_MEM - Out of memory","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","500 Internal Server Error","E_OUT_OF_MEM"],"keywords":["E_OUT_OF_MEM","500 E_OUT_OF_MEM","HTTP 500","Internal Server Error","Out of memory.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_OUT_OF_MEM","eventId":"","severity":"High","summary":"SonicOS API returned 500 Internal Server Error with E_OUT_OF_MEM: Out of memory.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 500 E_OUT_OF_MEM must be interpreted as a pair.","resolution":"1. Capture the 500 E_OUT_OF_MEM response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Capture the response message, request ID, timestamp, endpoint, method, SonicOS version, HA state, and sanitized logs. Check resource and session health, then escalate persistent internal failures with evidence.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 500 E_OUT_OF_MEM: Out of memory.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 500 Internal Server Error. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Out of memory.\nHTTP pairing: 500 Internal Server Error / E_OUT_OF_MEM\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 5xx"],"aliases":["E_OUT_OF_MEM","500 E_OUT_OF_MEM","SonicOS E_OUT_OF_MEM"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55045,"title":"SonicOS API 500 E_NOT_FOUND - Unable to access the OpenAPI specification","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","500 Internal Server Error","E_NOT_FOUND"],"keywords":["E_NOT_FOUND","500 E_NOT_FOUND","HTTP 500","Internal Server Error","Unable to access the OpenAPI specification.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_NOT_FOUND","eventId":"","severity":"High","summary":"SonicOS API returned 500 Internal Server Error with E_NOT_FOUND: Unable to access the OpenAPI specification.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 500 E_NOT_FOUND must be interpreted as a pair.","resolution":"1. Capture the 500 E_NOT_FOUND response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Capture the response message, request ID, timestamp, endpoint, method, SonicOS version, HA state, and sanitized logs. Check resource and session health, then escalate persistent internal failures with evidence.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 500 E_NOT_FOUND: Unable to access the OpenAPI specification.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 500 Internal Server Error. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Unable to access the OpenAPI specification.\nHTTP pairing: 500 Internal Server Error / E_NOT_FOUND\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 5xx"],"aliases":["E_NOT_FOUND","500 E_NOT_FOUND","SonicOS E_NOT_FOUND"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55046,"title":"SonicOS API 503 E_OUT_OF_MEM - Out of memory","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","503 Service Unavailable","E_OUT_OF_MEM"],"keywords":["E_OUT_OF_MEM","503 E_OUT_OF_MEM","HTTP 503","Service Unavailable","Out of memory.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_OUT_OF_MEM","eventId":"","severity":"High","summary":"SonicOS API returned 503 Service Unavailable with E_OUT_OF_MEM: Out of memory.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 503 E_OUT_OF_MEM must be interpreted as a pair.","resolution":"1. Capture the 503 E_OUT_OF_MEM response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Check appliance resources and active API sessions, close confirmed stale sessions, wait briefly, and retry only when the operation is safe to repeat.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 503 E_OUT_OF_MEM: Out of memory.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 503 Service Unavailable. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Out of memory.\nHTTP pairing: 503 Service Unavailable / E_OUT_OF_MEM\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 5xx"],"aliases":["E_OUT_OF_MEM","503 E_OUT_OF_MEM","SonicOS E_OUT_OF_MEM"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55047,"title":"SonicOS API 503 E_ACCESS_DENIED - Connection not allowed because the maximum number of sessions was reached","category":"SonicWall","product":"SonicWall / SonicOS API","tags":["SonicWall","SonicOS","Firewall","REST API","503 Service Unavailable","E_ACCESS_DENIED"],"keywords":["E_ACCESS_DENIED","503 E_ACCESS_DENIED","HTTP 503","Service Unavailable","Connection not allowed because the maximum number of sessions was reached.","SonicOS API error","SonicWall API response","firewall API"],"errorCode":"E_ACCESS_DENIED","eventId":"","severity":"High","summary":"SonicOS API returned 503 Service Unavailable with E_ACCESS_DENIED: Connection not allowed because the maximum number of sessions was reached.","rootCause":"The exact cause depends on the HTTP status, symbolic SonicOS response, request context, and detail message. The same symbolic name can be reused under different HTTP statuses, so 503 E_ACCESS_DENIED must be interpreted as a pair.","resolution":"1. Capture the 503 E_ACCESS_DENIED response, safe response details, endpoint, method, timestamp, request ID, SonicOS version, and HA role. Redact credentials, cookies, tokens, API keys, and private configuration.\n2. Check appliance resources and active API sessions, close confirmed stale sessions, wait briefly, and retry only when the operation is safe to repeat.\n3. Retry only when the operation is idempotent or duplicate-operation risk has been reviewed.\n4. Validate the intended firewall state and relevant logs after correction.","emailScript":"Hello,\n\nWe reviewed the SonicWall request and identified SonicOS API response 503 E_ACCESS_DENIED: Connection not allowed because the maximum number of sessions was reached.\n\nWe are validating the request, firewall state, and response details before applying the least disruptive correction.\n\nPlease let us know if there was a recent firewall change or an approved maintenance window we should consider.\n\nThank you,\n\nIT Support","faqSteps":"The SonicWall returned 503 Service Unavailable. Please send IT Support the approximate time and what action was attempted. Do not share passwords, tokens, API keys, cookies, private keys, or an unredacted configuration.","notes":"Official description: Connection not allowed because the maximum number of sessions was reached.\nHTTP pairing: 503 Service Unavailable / E_ACCESS_DENIED\n\nSonicWall reuses some symbolic identifiers under multiple HTTP statuses. Search and record both values to avoid applying guidance for the wrong context. SonicOS API is an alternative to the SonicOS CLI for supported configuration functions. Endpoint support can vary by SonicOS generation, release, appliance, license, HA role, feature state, and administrator permissions.","commands":[],"sourceDocument":"List of Error Codes for SonicOS API Calls.pdf","sourceAuthority":"SonicWall","namespace":"SONICOS-API","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicOS","SonicOS API"],"technologies":["Firewall","REST API","HTTP","Network Security"],"articleCategories":["Firewalls","SonicWall","Networking","Security","API Errors","HTTP 5xx"],"aliases":["E_ACCESS_DENIED","503 E_ACCESS_DENIED","SonicOS E_ACCESS_DENIED"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55200,"title":"SonicWall Switch CLI - System","category":"SonicWall","product":"SonicWall Switch 1.3.1","tags":["SonicWall","Switch","CLI","System","Network Infrastructure"],"keywords":["System","CLI navigation, sessions, users, privilege, configuration mode, diagnostics, and general switch operation.","SonicWall Switch CLI","Switch 1.3.1","managed switch","network command","help [command]","show privilege","show cli","show users","show history"],"errorCode":"","eventId":"","severity":"Low","summary":"Reference for SonicWall Switch 1.3.1 System CLI commands. CLI navigation, sessions, users, privilege, configuration mode, diagnostics, and general switch operation.","rootCause":"Command failures commonly result from using the wrong CLI mode, omitting a required value, selecting an invalid range, lacking privilege, referencing an unavailable feature, or applying syntax from a different switch firmware release.","resolution":"1. Record the complete prompt, mode, command, parser message, switch model, firmware version, and affected ports or VLANs.\n2. Use help at the current prompt and compare the live command tree with the guide for the installed release.\n3. Start with the read-only show commands listed in this article.\n4. Review dependencies, current and saved configuration, management-path impact, and rollback before any configuration command.\n5. Apply only the verified change during an approved window and validate management access and intended network behavior.","emailScript":"Hello,\n\nWe are reviewing the SonicWall switch System configuration. We will confirm the firmware, current settings, dependencies, and management-path impact before making a controlled change.\n\nPlease let us know if there is a maintenance window or recent network change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the switch name, port or VLAN involved, exact message, and approximate time. Do not change switch settings or share passwords, SNMP secrets, RADIUS keys, or an unredacted configuration.","notes":"Guide scope: SonicWall Switch Command Line Interface 1.3.1.\nCommand family: System.\nCLI navigation, sessions, users, privilege, configuration mode, diagnostics, and general switch operation.\n\nThe guide documents objectives, syntax, parameters, and required CLI mode. Required values appear in angle brackets, optional values in square brackets, and alternatives are separated by a pipe. A displayed command must be entered on one line. Command availability can vary by switch model and firmware.","commands":[{"shell":"SonicWall Switch CLI","command":"help [command]","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"SonicWall Switch CLI","command":"show privilege","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"SonicWall Switch CLI","command":"show cli","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"SonicWall Switch CLI","command":"show users","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"SonicWall Switch CLI","command":"show history","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"switch-cli_reference_guide.pdf","sourceAuthority":"SonicWall","namespace":"SONICWALL-SWITCH-CLI","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicWall Switch","Switch 1.3.1"],"technologies":["Managed Switch","CLI","System"],"articleCategories":["Firewalls","SonicWall","Networking","Switching","CLI Reference"],"aliases":["SonicWall System","Switch CLI System"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55201,"title":"SonicWall Switch CLI - ACL","category":"SonicWall","product":"SonicWall Switch 1.3.1","tags":["SonicWall","Switch","CLI","ACL","Network Infrastructure"],"keywords":["ACL","IPv4, MAC, TCP, UDP, ICMP, EtherType, and binding access-control list commands.","SonicWall Switch CLI","Switch 1.3.1","managed switch","network command","show access-lists","show access-group"],"errorCode":"","eventId":"","severity":"Medium","summary":"Reference for SonicWall Switch 1.3.1 ACL CLI commands. IPv4, MAC, TCP, UDP, ICMP, EtherType, and binding access-control list commands.","rootCause":"Command failures commonly result from using the wrong CLI mode, omitting a required value, selecting an invalid range, lacking privilege, referencing an unavailable feature, or applying syntax from a different switch firmware release.","resolution":"1. Record the complete prompt, mode, command, parser message, switch model, firmware version, and affected ports or VLANs.\n2. Use help at the current prompt and compare the live command tree with the guide for the installed release.\n3. Start with the read-only show commands listed in this article.\n4. Review dependencies, current and saved configuration, management-path impact, and rollback before any configuration command.\n5. Apply only the verified change during an approved window and validate management access and intended network behavior.","emailScript":"Hello,\n\nWe are reviewing the SonicWall switch ACL configuration. We will confirm the firmware, current settings, dependencies, and management-path impact before making a controlled change.\n\nPlease let us know if there is a maintenance window or recent network change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the switch name, port or VLAN involved, exact message, and approximate time. Do not change switch settings or share passwords, SNMP secrets, RADIUS keys, or an unredacted configuration.","notes":"Guide scope: SonicWall Switch Command Line Interface 1.3.1.\nCommand family: ACL.\nIPv4, MAC, TCP, UDP, ICMP, EtherType, and binding access-control list commands.\n\nThe guide documents objectives, syntax, parameters, and required CLI mode. Required values appear in angle brackets, optional values in square brackets, and alternatives are separated by a pipe. A displayed command must be entered on one line. Command availability can vary by switch model and firmware.","commands":[{"shell":"SonicWall Switch CLI","command":"show access-lists","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"SonicWall Switch CLI","command":"show access-group","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"switch-cli_reference_guide.pdf","sourceAuthority":"SonicWall","namespace":"SONICWALL-SWITCH-CLI","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicWall Switch","Switch 1.3.1"],"technologies":["Managed Switch","CLI","ACL"],"articleCategories":["Firewalls","SonicWall","Networking","Switching","CLI Reference"],"aliases":["SonicWall ACL","Switch CLI ACL"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55202,"title":"SonicWall Switch CLI - DNS","category":"SonicWall","product":"SonicWall Switch 1.3.1","tags":["SonicWall","Switch","CLI","DNS","Network Infrastructure"],"keywords":["DNS","DNS name-server configuration and inspection.","SonicWall Switch CLI","Switch 1.3.1","managed switch","network command","show ip dns name-server"],"errorCode":"","eventId":"","severity":"Low","summary":"Reference for SonicWall Switch 1.3.1 DNS CLI commands. DNS name-server configuration and inspection.","rootCause":"Command failures commonly result from using the wrong CLI mode, omitting a required value, selecting an invalid range, lacking privilege, referencing an unavailable feature, or applying syntax from a different switch firmware release.","resolution":"1. Record the complete prompt, mode, command, parser message, switch model, firmware version, and affected ports or VLANs.\n2. Use help at the current prompt and compare the live command tree with the guide for the installed release.\n3. Start with the read-only show commands listed in this article.\n4. Review dependencies, current and saved configuration, management-path impact, and rollback before any configuration command.\n5. Apply only the verified change during an approved window and validate management access and intended network behavior.","emailScript":"Hello,\n\nWe are reviewing the SonicWall switch DNS configuration. We will confirm the firmware, current settings, dependencies, and management-path impact before making a controlled change.\n\nPlease let us know if there is a maintenance window or recent network change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the switch name, port or VLAN involved, exact message, and approximate time. Do not change switch settings or share passwords, SNMP secrets, RADIUS keys, or an unredacted configuration.","notes":"Guide scope: SonicWall Switch Command Line Interface 1.3.1.\nCommand family: DNS.\nDNS name-server configuration and inspection.\n\nThe guide documents objectives, syntax, parameters, and required CLI mode. Required values appear in angle brackets, optional values in square brackets, and alternatives are separated by a pipe. A displayed command must be entered on one line. Command availability can vary by switch model and firmware.","commands":[{"shell":"SonicWall Switch CLI","command":"show ip dns name-server","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"switch-cli_reference_guide.pdf","sourceAuthority":"SonicWall","namespace":"SONICWALL-SWITCH-CLI","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicWall Switch","Switch 1.3.1"],"technologies":["Managed Switch","CLI","DNS"],"articleCategories":["Firewalls","SonicWall","Networking","Switching","CLI Reference"],"aliases":["SonicWall DNS","Switch CLI DNS"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55203,"title":"SonicWall Switch CLI - Energy Efficient Ethernet","category":"SonicWall","product":"SonicWall Switch 1.3.1","tags":["SonicWall","Switch","CLI","Energy Efficient Ethernet","Network Infrastructure"],"keywords":["Energy Efficient Ethernet","EEE interface configuration.","SonicWall Switch CLI","Switch 1.3.1","managed switch","network command"],"errorCode":"","eventId":"","severity":"Low","summary":"Reference for SonicWall Switch 1.3.1 Energy Efficient Ethernet CLI commands. EEE interface configuration.","rootCause":"Command failures commonly result from using the wrong CLI mode, omitting a required value, selecting an invalid range, lacking privilege, referencing an unavailable feature, or applying syntax from a different switch firmware release.","resolution":"1. Record the complete prompt, mode, command, parser message, switch model, firmware version, and affected ports or VLANs.\n2. Use help at the current prompt and compare the live command tree with the guide for the installed release.\n3. Start with the read-only show commands listed in this article.\n4. Review dependencies, current and saved configuration, management-path impact, and rollback before any configuration command.\n5. Apply only the verified change during an approved window and validate management access and intended network behavior.","emailScript":"Hello,\n\nWe are reviewing the SonicWall switch Energy Efficient Ethernet configuration. We will confirm the firmware, current settings, dependencies, and management-path impact before making a controlled change.\n\nPlease let us know if there is a maintenance window or recent network change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the switch name, port or VLAN involved, exact message, and approximate time. Do not change switch settings or share passwords, SNMP secrets, RADIUS keys, or an unredacted configuration.","notes":"Guide scope: SonicWall Switch Command Line Interface 1.3.1.\nCommand family: Energy Efficient Ethernet.\nEEE interface configuration.\n\nThe guide documents objectives, syntax, parameters, and required CLI mode. Required values appear in angle brackets, optional values in square brackets, and alternatives are separated by a pipe. A displayed command must be entered on one line. Command availability can vary by switch model and firmware.","commands":[],"sourceDocument":"switch-cli_reference_guide.pdf","sourceAuthority":"SonicWall","namespace":"SONICWALL-SWITCH-CLI","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicWall Switch","Switch 1.3.1"],"technologies":["Managed Switch","CLI","Energy Efficient Ethernet"],"articleCategories":["Firewalls","SonicWall","Networking","Switching","CLI Reference"],"aliases":["SonicWall Energy Efficient Ethernet","Switch CLI Energy Efficient Ethernet"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55204,"title":"SonicWall Switch CLI - IGMP Snooping","category":"SonicWall","product":"SonicWall Switch 1.3.1","tags":["SonicWall","Switch","CLI","IGMP Snooping","Network Infrastructure"],"keywords":["IGMP Snooping","Multicast snooping, querier, router-port, filtering, and group inspection.","SonicWall Switch CLI","Switch 1.3.1","managed switch","network command","show ip igmp snooping","show ip igmp snooping groups"],"errorCode":"","eventId":"","severity":"Low","summary":"Reference for SonicWall Switch 1.3.1 IGMP Snooping CLI commands. Multicast snooping, querier, router-port, filtering, and group inspection.","rootCause":"Command failures commonly result from using the wrong CLI mode, omitting a required value, selecting an invalid range, lacking privilege, referencing an unavailable feature, or applying syntax from a different switch firmware release.","resolution":"1. Record the complete prompt, mode, command, parser message, switch model, firmware version, and affected ports or VLANs.\n2. Use help at the current prompt and compare the live command tree with the guide for the installed release.\n3. Start with the read-only show commands listed in this article.\n4. Review dependencies, current and saved configuration, management-path impact, and rollback before any configuration command.\n5. Apply only the verified change during an approved window and validate management access and intended network behavior.","emailScript":"Hello,\n\nWe are reviewing the SonicWall switch IGMP Snooping configuration. We will confirm the firmware, current settings, dependencies, and management-path impact before making a controlled change.\n\nPlease let us know if there is a maintenance window or recent network change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the switch name, port or VLAN involved, exact message, and approximate time. Do not change switch settings or share passwords, SNMP secrets, RADIUS keys, or an unredacted configuration.","notes":"Guide scope: SonicWall Switch Command Line Interface 1.3.1.\nCommand family: IGMP Snooping.\nMulticast snooping, querier, router-port, filtering, and group inspection.\n\nThe guide documents objectives, syntax, parameters, and required CLI mode. Required values appear in angle brackets, optional values in square brackets, and alternatives are separated by a pipe. A displayed command must be entered on one line. Command availability can vary by switch model and firmware.","commands":[{"shell":"SonicWall Switch CLI","command":"show ip igmp snooping","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"SonicWall Switch CLI","command":"show ip igmp snooping groups","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"switch-cli_reference_guide.pdf","sourceAuthority":"SonicWall","namespace":"SONICWALL-SWITCH-CLI","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicWall Switch","Switch 1.3.1"],"technologies":["Managed Switch","CLI","IGMP Snooping"],"articleCategories":["Firewalls","SonicWall","Networking","Switching","CLI Reference"],"aliases":["SonicWall IGMP Snooping","Switch CLI IGMP Snooping"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55205,"title":"SonicWall Switch CLI - IP Routing and ARP","category":"SonicWall","product":"SonicWall Switch 1.3.1","tags":["SonicWall","Switch","CLI","IP Routing and ARP","Network Infrastructure"],"keywords":["IP Routing and ARP","Static routes, ARP entries, timeouts, and routing or neighbor inspection.","SonicWall Switch CLI","Switch 1.3.1","managed switch","network command","show ip route","show ip arp"],"errorCode":"","eventId":"","severity":"Medium","summary":"Reference for SonicWall Switch 1.3.1 IP Routing and ARP CLI commands. Static routes, ARP entries, timeouts, and routing or neighbor inspection.","rootCause":"Command failures commonly result from using the wrong CLI mode, omitting a required value, selecting an invalid range, lacking privilege, referencing an unavailable feature, or applying syntax from a different switch firmware release.","resolution":"1. Record the complete prompt, mode, command, parser message, switch model, firmware version, and affected ports or VLANs.\n2. Use help at the current prompt and compare the live command tree with the guide for the installed release.\n3. Start with the read-only show commands listed in this article.\n4. Review dependencies, current and saved configuration, management-path impact, and rollback before any configuration command.\n5. Apply only the verified change during an approved window and validate management access and intended network behavior.","emailScript":"Hello,\n\nWe are reviewing the SonicWall switch IP Routing and ARP configuration. We will confirm the firmware, current settings, dependencies, and management-path impact before making a controlled change.\n\nPlease let us know if there is a maintenance window or recent network change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the switch name, port or VLAN involved, exact message, and approximate time. Do not change switch settings or share passwords, SNMP secrets, RADIUS keys, or an unredacted configuration.","notes":"Guide scope: SonicWall Switch Command Line Interface 1.3.1.\nCommand family: IP Routing and ARP.\nStatic routes, ARP entries, timeouts, and routing or neighbor inspection.\n\nThe guide documents objectives, syntax, parameters, and required CLI mode. Required values appear in angle brackets, optional values in square brackets, and alternatives are separated by a pipe. A displayed command must be entered on one line. Command availability can vary by switch model and firmware.","commands":[{"shell":"SonicWall Switch CLI","command":"show ip route","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"SonicWall Switch CLI","command":"show ip arp","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"switch-cli_reference_guide.pdf","sourceAuthority":"SonicWall","namespace":"SONICWALL-SWITCH-CLI","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicWall Switch","Switch 1.3.1"],"technologies":["Managed Switch","CLI","IP Routing and ARP"],"articleCategories":["Firewalls","SonicWall","Networking","Switching","CLI Reference"],"aliases":["SonicWall IP Routing and ARP","Switch CLI IP Routing and ARP"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55206,"title":"SonicWall Switch CLI - Link Aggregation","category":"SonicWall","product":"SonicWall Switch 1.3.1","tags":["SonicWall","Switch","CLI","Link Aggregation","Network Infrastructure"],"keywords":["Link Aggregation","LACP, port channels, load balancing, and EtherChannel inspection.","SonicWall Switch CLI","Switch 1.3.1","managed switch","network command","show etherchannel summary","show etherchannel detail"],"errorCode":"","eventId":"","severity":"Low","summary":"Reference for SonicWall Switch 1.3.1 Link Aggregation CLI commands. LACP, port channels, load balancing, and EtherChannel inspection.","rootCause":"Command failures commonly result from using the wrong CLI mode, omitting a required value, selecting an invalid range, lacking privilege, referencing an unavailable feature, or applying syntax from a different switch firmware release.","resolution":"1. Record the complete prompt, mode, command, parser message, switch model, firmware version, and affected ports or VLANs.\n2. Use help at the current prompt and compare the live command tree with the guide for the installed release.\n3. Start with the read-only show commands listed in this article.\n4. Review dependencies, current and saved configuration, management-path impact, and rollback before any configuration command.\n5. Apply only the verified change during an approved window and validate management access and intended network behavior.","emailScript":"Hello,\n\nWe are reviewing the SonicWall switch Link Aggregation configuration. We will confirm the firmware, current settings, dependencies, and management-path impact before making a controlled change.\n\nPlease let us know if there is a maintenance window or recent network change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the switch name, port or VLAN involved, exact message, and approximate time. Do not change switch settings or share passwords, SNMP secrets, RADIUS keys, or an unredacted configuration.","notes":"Guide scope: SonicWall Switch Command Line Interface 1.3.1.\nCommand family: Link Aggregation.\nLACP, port channels, load balancing, and EtherChannel inspection.\n\nThe guide documents objectives, syntax, parameters, and required CLI mode. Required values appear in angle brackets, optional values in square brackets, and alternatives are separated by a pipe. A displayed command must be entered on one line. Command availability can vary by switch model and firmware.","commands":[{"shell":"SonicWall Switch CLI","command":"show etherchannel summary","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"SonicWall Switch CLI","command":"show etherchannel detail","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"switch-cli_reference_guide.pdf","sourceAuthority":"SonicWall","namespace":"SONICWALL-SWITCH-CLI","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicWall Switch","Switch 1.3.1"],"technologies":["Managed Switch","CLI","Link Aggregation"],"articleCategories":["Firewalls","SonicWall","Networking","Switching","CLI Reference"],"aliases":["SonicWall Link Aggregation","Switch CLI Link Aggregation"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55207,"title":"SonicWall Switch CLI - Loopback Detection","category":"SonicWall","product":"SonicWall Switch 1.3.1","tags":["SonicWall","Switch","CLI","Loopback Detection","Network Infrastructure"],"keywords":["Loopback Detection","Loop detection state and affected-port inspection.","SonicWall Switch CLI","Switch 1.3.1","managed switch","network command","show lbd state","show lbd port state"],"errorCode":"","eventId":"","severity":"Low","summary":"Reference for SonicWall Switch 1.3.1 Loopback Detection CLI commands. Loop detection state and affected-port inspection.","rootCause":"Command failures commonly result from using the wrong CLI mode, omitting a required value, selecting an invalid range, lacking privilege, referencing an unavailable feature, or applying syntax from a different switch firmware release.","resolution":"1. Record the complete prompt, mode, command, parser message, switch model, firmware version, and affected ports or VLANs.\n2. Use help at the current prompt and compare the live command tree with the guide for the installed release.\n3. Start with the read-only show commands listed in this article.\n4. Review dependencies, current and saved configuration, management-path impact, and rollback before any configuration command.\n5. Apply only the verified change during an approved window and validate management access and intended network behavior.","emailScript":"Hello,\n\nWe are reviewing the SonicWall switch Loopback Detection configuration. We will confirm the firmware, current settings, dependencies, and management-path impact before making a controlled change.\n\nPlease let us know if there is a maintenance window or recent network change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the switch name, port or VLAN involved, exact message, and approximate time. Do not change switch settings or share passwords, SNMP secrets, RADIUS keys, or an unredacted configuration.","notes":"Guide scope: SonicWall Switch Command Line Interface 1.3.1.\nCommand family: Loopback Detection.\nLoop detection state and affected-port inspection.\n\nThe guide documents objectives, syntax, parameters, and required CLI mode. Required values appear in angle brackets, optional values in square brackets, and alternatives are separated by a pipe. A displayed command must be entered on one line. Command availability can vary by switch model and firmware.","commands":[{"shell":"SonicWall Switch CLI","command":"show lbd state","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"SonicWall Switch CLI","command":"show lbd port state","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"switch-cli_reference_guide.pdf","sourceAuthority":"SonicWall","namespace":"SONICWALL-SWITCH-CLI","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicWall Switch","Switch 1.3.1"],"technologies":["Managed Switch","CLI","Loopback Detection"],"articleCategories":["Firewalls","SonicWall","Networking","Switching","CLI Reference"],"aliases":["SonicWall Loopback Detection","Switch CLI Loopback Detection"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55208,"title":"SonicWall Switch CLI - LLDP","category":"SonicWall","product":"SonicWall Switch 1.3.1","tags":["SonicWall","Switch","CLI","LLDP","Network Infrastructure"],"keywords":["LLDP","LLDP service, timers, local interfaces, and neighbor discovery.","SonicWall Switch CLI","Switch 1.3.1","managed switch","network command","show lldp","show lldp neighbors detail"],"errorCode":"","eventId":"","severity":"Low","summary":"Reference for SonicWall Switch 1.3.1 LLDP CLI commands. LLDP service, timers, local interfaces, and neighbor discovery.","rootCause":"Command failures commonly result from using the wrong CLI mode, omitting a required value, selecting an invalid range, lacking privilege, referencing an unavailable feature, or applying syntax from a different switch firmware release.","resolution":"1. Record the complete prompt, mode, command, parser message, switch model, firmware version, and affected ports or VLANs.\n2. Use help at the current prompt and compare the live command tree with the guide for the installed release.\n3. Start with the read-only show commands listed in this article.\n4. Review dependencies, current and saved configuration, management-path impact, and rollback before any configuration command.\n5. Apply only the verified change during an approved window and validate management access and intended network behavior.","emailScript":"Hello,\n\nWe are reviewing the SonicWall switch LLDP configuration. We will confirm the firmware, current settings, dependencies, and management-path impact before making a controlled change.\n\nPlease let us know if there is a maintenance window or recent network change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the switch name, port or VLAN involved, exact message, and approximate time. Do not change switch settings or share passwords, SNMP secrets, RADIUS keys, or an unredacted configuration.","notes":"Guide scope: SonicWall Switch Command Line Interface 1.3.1.\nCommand family: LLDP.\nLLDP service, timers, local interfaces, and neighbor discovery.\n\nThe guide documents objectives, syntax, parameters, and required CLI mode. Required values appear in angle brackets, optional values in square brackets, and alternatives are separated by a pipe. A displayed command must be entered on one line. Command availability can vary by switch model and firmware.","commands":[{"shell":"SonicWall Switch CLI","command":"show lldp","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"SonicWall Switch CLI","command":"show lldp neighbors detail","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"switch-cli_reference_guide.pdf","sourceAuthority":"SonicWall","namespace":"SONICWALL-SWITCH-CLI","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicWall Switch","Switch 1.3.1"],"technologies":["Managed Switch","CLI","LLDP"],"articleCategories":["Firewalls","SonicWall","Networking","Switching","CLI Reference"],"aliases":["SonicWall LLDP","Switch CLI LLDP"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55209,"title":"SonicWall Switch CLI - Port Mirroring","category":"SonicWall","product":"SonicWall Switch 1.3.1","tags":["SonicWall","Switch","CLI","Port Mirroring","Network Infrastructure"],"keywords":["Port Mirroring","Monitor-session source, destination, and session inspection.","SonicWall Switch CLI","Switch 1.3.1","managed switch","network command","show monitor all detail"],"errorCode":"","eventId":"","severity":"Low","summary":"Reference for SonicWall Switch 1.3.1 Port Mirroring CLI commands. Monitor-session source, destination, and session inspection.","rootCause":"Command failures commonly result from using the wrong CLI mode, omitting a required value, selecting an invalid range, lacking privilege, referencing an unavailable feature, or applying syntax from a different switch firmware release.","resolution":"1. Record the complete prompt, mode, command, parser message, switch model, firmware version, and affected ports or VLANs.\n2. Use help at the current prompt and compare the live command tree with the guide for the installed release.\n3. Start with the read-only show commands listed in this article.\n4. Review dependencies, current and saved configuration, management-path impact, and rollback before any configuration command.\n5. Apply only the verified change during an approved window and validate management access and intended network behavior.","emailScript":"Hello,\n\nWe are reviewing the SonicWall switch Port Mirroring configuration. We will confirm the firmware, current settings, dependencies, and management-path impact before making a controlled change.\n\nPlease let us know if there is a maintenance window or recent network change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the switch name, port or VLAN involved, exact message, and approximate time. Do not change switch settings or share passwords, SNMP secrets, RADIUS keys, or an unredacted configuration.","notes":"Guide scope: SonicWall Switch Command Line Interface 1.3.1.\nCommand family: Port Mirroring.\nMonitor-session source, destination, and session inspection.\n\nThe guide documents objectives, syntax, parameters, and required CLI mode. Required values appear in angle brackets, optional values in square brackets, and alternatives are separated by a pipe. A displayed command must be entered on one line. Command availability can vary by switch model and firmware.","commands":[{"shell":"SonicWall Switch CLI","command":"show monitor all detail","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"switch-cli_reference_guide.pdf","sourceAuthority":"SonicWall","namespace":"SONICWALL-SWITCH-CLI","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicWall Switch","Switch 1.3.1"],"technologies":["Managed Switch","CLI","Port Mirroring"],"articleCategories":["Firewalls","SonicWall","Networking","Switching","CLI Reference"],"aliases":["SonicWall Port Mirroring","Switch CLI Port Mirroring"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55210,"title":"SonicWall Switch CLI - 802.1X","category":"SonicWall","product":"SonicWall Switch 1.3.1","tags":["SonicWall","Switch","CLI","802.1X","Network Infrastructure"],"keywords":["802.1X","Port-based access control, guest VLANs, supplicants, timers, and authentication state.","SonicWall Switch CLI","Switch 1.3.1","managed switch","network command","show dot1x","show dot1x statistics"],"errorCode":"","eventId":"","severity":"Medium","summary":"Reference for SonicWall Switch 1.3.1 802.1X CLI commands. Port-based access control, guest VLANs, supplicants, timers, and authentication state.","rootCause":"Command failures commonly result from using the wrong CLI mode, omitting a required value, selecting an invalid range, lacking privilege, referencing an unavailable feature, or applying syntax from a different switch firmware release.","resolution":"1. Record the complete prompt, mode, command, parser message, switch model, firmware version, and affected ports or VLANs.\n2. Use help at the current prompt and compare the live command tree with the guide for the installed release.\n3. Start with the read-only show commands listed in this article.\n4. Review dependencies, current and saved configuration, management-path impact, and rollback before any configuration command.\n5. Apply only the verified change during an approved window and validate management access and intended network behavior.","emailScript":"Hello,\n\nWe are reviewing the SonicWall switch 802.1X configuration. We will confirm the firmware, current settings, dependencies, and management-path impact before making a controlled change.\n\nPlease let us know if there is a maintenance window or recent network change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the switch name, port or VLAN involved, exact message, and approximate time. Do not change switch settings or share passwords, SNMP secrets, RADIUS keys, or an unredacted configuration.","notes":"Guide scope: SonicWall Switch Command Line Interface 1.3.1.\nCommand family: 802.1X.\nPort-based access control, guest VLANs, supplicants, timers, and authentication state.\n\nThe guide documents objectives, syntax, parameters, and required CLI mode. Required values appear in angle brackets, optional values in square brackets, and alternatives are separated by a pipe. A displayed command must be entered on one line. Command availability can vary by switch model and firmware.","commands":[{"shell":"SonicWall Switch CLI","command":"show dot1x","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"SonicWall Switch CLI","command":"show dot1x statistics","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"switch-cli_reference_guide.pdf","sourceAuthority":"SonicWall","namespace":"SONICWALL-SWITCH-CLI","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicWall Switch","Switch 1.3.1"],"technologies":["Managed Switch","CLI","802.1X"],"articleCategories":["Firewalls","SonicWall","Networking","Switching","CLI Reference"],"aliases":["SonicWall 802.1X","Switch CLI 802.1X"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55211,"title":"SonicWall Switch CLI - Power over Ethernet","category":"SonicWall","product":"SonicWall Switch 1.3.1","tags":["SonicWall","Switch","CLI","Power over Ethernet","Network Infrastructure"],"keywords":["Power over Ethernet","PoE enablement, limits, priority, and power inspection.","SonicWall Switch CLI","Switch 1.3.1","managed switch","network command","show power inline","show power detail"],"errorCode":"","eventId":"","severity":"Medium","summary":"Reference for SonicWall Switch 1.3.1 Power over Ethernet CLI commands. PoE enablement, limits, priority, and power inspection.","rootCause":"Command failures commonly result from using the wrong CLI mode, omitting a required value, selecting an invalid range, lacking privilege, referencing an unavailable feature, or applying syntax from a different switch firmware release.","resolution":"1. Record the complete prompt, mode, command, parser message, switch model, firmware version, and affected ports or VLANs.\n2. Use help at the current prompt and compare the live command tree with the guide for the installed release.\n3. Start with the read-only show commands listed in this article.\n4. Review dependencies, current and saved configuration, management-path impact, and rollback before any configuration command.\n5. Apply only the verified change during an approved window and validate management access and intended network behavior.","emailScript":"Hello,\n\nWe are reviewing the SonicWall switch Power over Ethernet configuration. We will confirm the firmware, current settings, dependencies, and management-path impact before making a controlled change.\n\nPlease let us know if there is a maintenance window or recent network change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the switch name, port or VLAN involved, exact message, and approximate time. Do not change switch settings or share passwords, SNMP secrets, RADIUS keys, or an unredacted configuration.","notes":"Guide scope: SonicWall Switch Command Line Interface 1.3.1.\nCommand family: Power over Ethernet.\nPoE enablement, limits, priority, and power inspection.\n\nThe guide documents objectives, syntax, parameters, and required CLI mode. Required values appear in angle brackets, optional values in square brackets, and alternatives are separated by a pipe. A displayed command must be entered on one line. Command availability can vary by switch model and firmware.","commands":[{"shell":"SonicWall Switch CLI","command":"show power inline","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"SonicWall Switch CLI","command":"show power detail","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"switch-cli_reference_guide.pdf","sourceAuthority":"SonicWall","namespace":"SONICWALL-SWITCH-CLI","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicWall Switch","Switch 1.3.1"],"technologies":["Managed Switch","CLI","Power over Ethernet"],"articleCategories":["Firewalls","SonicWall","Networking","Switching","CLI Reference"],"aliases":["SonicWall Power over Ethernet","Switch CLI Power over Ethernet"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55212,"title":"SonicWall Switch CLI - Quality of Service","category":"SonicWall","product":"SonicWall Switch 1.3.1","tags":["SonicWall","Switch","CLI","Quality of Service","Network Infrastructure"],"keywords":["Quality of Service","Storm control, rate limiting, trust, classification, policy, scheduling, and statistics.","SonicWall Switch CLI","Switch 1.3.1","managed switch","network command","show qos","show policy-map"],"errorCode":"","eventId":"","severity":"Low","summary":"Reference for SonicWall Switch 1.3.1 Quality of Service CLI commands. Storm control, rate limiting, trust, classification, policy, scheduling, and statistics.","rootCause":"Command failures commonly result from using the wrong CLI mode, omitting a required value, selecting an invalid range, lacking privilege, referencing an unavailable feature, or applying syntax from a different switch firmware release.","resolution":"1. Record the complete prompt, mode, command, parser message, switch model, firmware version, and affected ports or VLANs.\n2. Use help at the current prompt and compare the live command tree with the guide for the installed release.\n3. Start with the read-only show commands listed in this article.\n4. Review dependencies, current and saved configuration, management-path impact, and rollback before any configuration command.\n5. Apply only the verified change during an approved window and validate management access and intended network behavior.","emailScript":"Hello,\n\nWe are reviewing the SonicWall switch Quality of Service configuration. We will confirm the firmware, current settings, dependencies, and management-path impact before making a controlled change.\n\nPlease let us know if there is a maintenance window or recent network change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the switch name, port or VLAN involved, exact message, and approximate time. Do not change switch settings or share passwords, SNMP secrets, RADIUS keys, or an unredacted configuration.","notes":"Guide scope: SonicWall Switch Command Line Interface 1.3.1.\nCommand family: Quality of Service.\nStorm control, rate limiting, trust, classification, policy, scheduling, and statistics.\n\nThe guide documents objectives, syntax, parameters, and required CLI mode. Required values appear in angle brackets, optional values in square brackets, and alternatives are separated by a pipe. A displayed command must be entered on one line. Command availability can vary by switch model and firmware.","commands":[{"shell":"SonicWall Switch CLI","command":"show qos","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"SonicWall Switch CLI","command":"show policy-map","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"switch-cli_reference_guide.pdf","sourceAuthority":"SonicWall","namespace":"SONICWALL-SWITCH-CLI","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicWall Switch","Switch 1.3.1"],"technologies":["Managed Switch","CLI","Quality of Service"],"articleCategories":["Firewalls","SonicWall","Networking","Switching","CLI Reference"],"aliases":["SonicWall Quality of Service","Switch CLI Quality of Service"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55213,"title":"SonicWall Switch CLI - RADIUS","category":"SonicWall","product":"SonicWall Switch 1.3.1","tags":["SonicWall","Switch","CLI","RADIUS","Network Infrastructure"],"keywords":["RADIUS","RADIUS server configuration and authentication statistics.","SonicWall Switch CLI","Switch 1.3.1","managed switch","network command","show radius server","show radius statistics"],"errorCode":"","eventId":"","severity":"Low","summary":"Reference for SonicWall Switch 1.3.1 RADIUS CLI commands. RADIUS server configuration and authentication statistics.","rootCause":"Command failures commonly result from using the wrong CLI mode, omitting a required value, selecting an invalid range, lacking privilege, referencing an unavailable feature, or applying syntax from a different switch firmware release.","resolution":"1. Record the complete prompt, mode, command, parser message, switch model, firmware version, and affected ports or VLANs.\n2. Use help at the current prompt and compare the live command tree with the guide for the installed release.\n3. Start with the read-only show commands listed in this article.\n4. Review dependencies, current and saved configuration, management-path impact, and rollback before any configuration command.\n5. Apply only the verified change during an approved window and validate management access and intended network behavior.","emailScript":"Hello,\n\nWe are reviewing the SonicWall switch RADIUS configuration. We will confirm the firmware, current settings, dependencies, and management-path impact before making a controlled change.\n\nPlease let us know if there is a maintenance window or recent network change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the switch name, port or VLAN involved, exact message, and approximate time. Do not change switch settings or share passwords, SNMP secrets, RADIUS keys, or an unredacted configuration.","notes":"Guide scope: SonicWall Switch Command Line Interface 1.3.1.\nCommand family: RADIUS.\nRADIUS server configuration and authentication statistics.\n\nThe guide documents objectives, syntax, parameters, and required CLI mode. Required values appear in angle brackets, optional values in square brackets, and alternatives are separated by a pipe. A displayed command must be entered on one line. Command availability can vary by switch model and firmware.","commands":[{"shell":"SonicWall Switch CLI","command":"show radius server","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"SonicWall Switch CLI","command":"show radius statistics","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"switch-cli_reference_guide.pdf","sourceAuthority":"SonicWall","namespace":"SONICWALL-SWITCH-CLI","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicWall Switch","Switch 1.3.1"],"technologies":["Managed Switch","CLI","RADIUS"],"articleCategories":["Firewalls","SonicWall","Networking","Switching","CLI Reference"],"aliases":["SonicWall RADIUS","Switch CLI RADIUS"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55214,"title":"SonicWall Switch CLI - RMON","category":"SonicWall","product":"SonicWall Switch 1.3.1","tags":["SonicWall","Switch","CLI","RMON","Network Infrastructure"],"keywords":["RMON","RMON alarms, events, statistics, and history.","SonicWall Switch CLI","Switch 1.3.1","managed switch","network command","show rmon statistics","show rmon alarms","show rmon events"],"errorCode":"","eventId":"","severity":"Low","summary":"Reference for SonicWall Switch 1.3.1 RMON CLI commands. RMON alarms, events, statistics, and history.","rootCause":"Command failures commonly result from using the wrong CLI mode, omitting a required value, selecting an invalid range, lacking privilege, referencing an unavailable feature, or applying syntax from a different switch firmware release.","resolution":"1. Record the complete prompt, mode, command, parser message, switch model, firmware version, and affected ports or VLANs.\n2. Use help at the current prompt and compare the live command tree with the guide for the installed release.\n3. Start with the read-only show commands listed in this article.\n4. Review dependencies, current and saved configuration, management-path impact, and rollback before any configuration command.\n5. Apply only the verified change during an approved window and validate management access and intended network behavior.","emailScript":"Hello,\n\nWe are reviewing the SonicWall switch RMON configuration. We will confirm the firmware, current settings, dependencies, and management-path impact before making a controlled change.\n\nPlease let us know if there is a maintenance window or recent network change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the switch name, port or VLAN involved, exact message, and approximate time. Do not change switch settings or share passwords, SNMP secrets, RADIUS keys, or an unredacted configuration.","notes":"Guide scope: SonicWall Switch Command Line Interface 1.3.1.\nCommand family: RMON.\nRMON alarms, events, statistics, and history.\n\nThe guide documents objectives, syntax, parameters, and required CLI mode. Required values appear in angle brackets, optional values in square brackets, and alternatives are separated by a pipe. A displayed command must be entered on one line. Command availability can vary by switch model and firmware.","commands":[{"shell":"SonicWall Switch CLI","command":"show rmon statistics","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"SonicWall Switch CLI","command":"show rmon alarms","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"SonicWall Switch CLI","command":"show rmon events","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"switch-cli_reference_guide.pdf","sourceAuthority":"SonicWall","namespace":"SONICWALL-SWITCH-CLI","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicWall Switch","Switch 1.3.1"],"technologies":["Managed Switch","CLI","RMON"],"articleCategories":["Firewalls","SonicWall","Networking","Switching","CLI Reference"],"aliases":["SonicWall RMON","Switch CLI RMON"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55215,"title":"SonicWall Switch CLI - SNMP","category":"SonicWall","product":"SonicWall Switch 1.3.1","tags":["SonicWall","Switch","CLI","SNMP","Network Infrastructure"],"keywords":["SNMP","SNMP agents, communities, groups, access, views, targets, users, and inspection.","SonicWall Switch CLI","Switch 1.3.1","managed switch","network command","show snmp","show snmp engineID"],"errorCode":"","eventId":"","severity":"Low","summary":"Reference for SonicWall Switch 1.3.1 SNMP CLI commands. SNMP agents, communities, groups, access, views, targets, users, and inspection.","rootCause":"Command failures commonly result from using the wrong CLI mode, omitting a required value, selecting an invalid range, lacking privilege, referencing an unavailable feature, or applying syntax from a different switch firmware release.","resolution":"1. Record the complete prompt, mode, command, parser message, switch model, firmware version, and affected ports or VLANs.\n2. Use help at the current prompt and compare the live command tree with the guide for the installed release.\n3. Start with the read-only show commands listed in this article.\n4. Review dependencies, current and saved configuration, management-path impact, and rollback before any configuration command.\n5. Apply only the verified change during an approved window and validate management access and intended network behavior.","emailScript":"Hello,\n\nWe are reviewing the SonicWall switch SNMP configuration. We will confirm the firmware, current settings, dependencies, and management-path impact before making a controlled change.\n\nPlease let us know if there is a maintenance window or recent network change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the switch name, port or VLAN involved, exact message, and approximate time. Do not change switch settings or share passwords, SNMP secrets, RADIUS keys, or an unredacted configuration.","notes":"Guide scope: SonicWall Switch Command Line Interface 1.3.1.\nCommand family: SNMP.\nSNMP agents, communities, groups, access, views, targets, users, and inspection.\n\nThe guide documents objectives, syntax, parameters, and required CLI mode. Required values appear in angle brackets, optional values in square brackets, and alternatives are separated by a pipe. A displayed command must be entered on one line. Command availability can vary by switch model and firmware.","commands":[{"shell":"SonicWall Switch CLI","command":"show snmp","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"SonicWall Switch CLI","command":"show snmp engineID","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"switch-cli_reference_guide.pdf","sourceAuthority":"SonicWall","namespace":"SONICWALL-SWITCH-CLI","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicWall Switch","Switch 1.3.1"],"technologies":["Managed Switch","CLI","SNMP"],"articleCategories":["Firewalls","SonicWall","Networking","Switching","CLI Reference"],"aliases":["SonicWall SNMP","Switch CLI SNMP"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55216,"title":"SonicWall Switch CLI - MAC Authentication Bypass","category":"SonicWall","product":"SonicWall Switch 1.3.1","tags":["SonicWall","Switch","CLI","MAC Authentication Bypass","Network Infrastructure"],"keywords":["MAC Authentication Bypass","MAB and hybrid 802.1X authentication modes and host inspection.","SonicWall Switch CLI","Switch 1.3.1","managed switch","network command","show dot1x authenticated host","show dot1x interface"],"errorCode":"","eventId":"","severity":"Low","summary":"Reference for SonicWall Switch 1.3.1 MAC Authentication Bypass CLI commands. MAB and hybrid 802.1X authentication modes and host inspection.","rootCause":"Command failures commonly result from using the wrong CLI mode, omitting a required value, selecting an invalid range, lacking privilege, referencing an unavailable feature, or applying syntax from a different switch firmware release.","resolution":"1. Record the complete prompt, mode, command, parser message, switch model, firmware version, and affected ports or VLANs.\n2. Use help at the current prompt and compare the live command tree with the guide for the installed release.\n3. Start with the read-only show commands listed in this article.\n4. Review dependencies, current and saved configuration, management-path impact, and rollback before any configuration command.\n5. Apply only the verified change during an approved window and validate management access and intended network behavior.","emailScript":"Hello,\n\nWe are reviewing the SonicWall switch MAC Authentication Bypass configuration. We will confirm the firmware, current settings, dependencies, and management-path impact before making a controlled change.\n\nPlease let us know if there is a maintenance window or recent network change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the switch name, port or VLAN involved, exact message, and approximate time. Do not change switch settings or share passwords, SNMP secrets, RADIUS keys, or an unredacted configuration.","notes":"Guide scope: SonicWall Switch Command Line Interface 1.3.1.\nCommand family: MAC Authentication Bypass.\nMAB and hybrid 802.1X authentication modes and host inspection.\n\nThe guide documents objectives, syntax, parameters, and required CLI mode. Required values appear in angle brackets, optional values in square brackets, and alternatives are separated by a pipe. A displayed command must be entered on one line. Command availability can vary by switch model and firmware.","commands":[{"shell":"SonicWall Switch CLI","command":"show dot1x authenticated host","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"SonicWall Switch CLI","command":"show dot1x interface","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"switch-cli_reference_guide.pdf","sourceAuthority":"SonicWall","namespace":"SONICWALL-SWITCH-CLI","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicWall Switch","Switch 1.3.1"],"technologies":["Managed Switch","CLI","MAC Authentication Bypass"],"articleCategories":["Firewalls","SonicWall","Networking","Switching","CLI Reference"],"aliases":["SonicWall MAC Authentication Bypass","Switch CLI MAC Authentication Bypass"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55217,"title":"SonicWall Switch CLI - SNTP","category":"SonicWall","product":"SonicWall Switch 1.3.1","tags":["SonicWall","Switch","CLI","SNTP","Network Infrastructure"],"keywords":["SNTP","Time-server, timezone, daylight-saving, clock, and synchronization status.","SonicWall Switch CLI","Switch 1.3.1","managed switch","network command","show sntp clock","show sntp status"],"errorCode":"","eventId":"","severity":"Low","summary":"Reference for SonicWall Switch 1.3.1 SNTP CLI commands. Time-server, timezone, daylight-saving, clock, and synchronization status.","rootCause":"Command failures commonly result from using the wrong CLI mode, omitting a required value, selecting an invalid range, lacking privilege, referencing an unavailable feature, or applying syntax from a different switch firmware release.","resolution":"1. Record the complete prompt, mode, command, parser message, switch model, firmware version, and affected ports or VLANs.\n2. Use help at the current prompt and compare the live command tree with the guide for the installed release.\n3. Start with the read-only show commands listed in this article.\n4. Review dependencies, current and saved configuration, management-path impact, and rollback before any configuration command.\n5. Apply only the verified change during an approved window and validate management access and intended network behavior.","emailScript":"Hello,\n\nWe are reviewing the SonicWall switch SNTP configuration. We will confirm the firmware, current settings, dependencies, and management-path impact before making a controlled change.\n\nPlease let us know if there is a maintenance window or recent network change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the switch name, port or VLAN involved, exact message, and approximate time. Do not change switch settings or share passwords, SNMP secrets, RADIUS keys, or an unredacted configuration.","notes":"Guide scope: SonicWall Switch Command Line Interface 1.3.1.\nCommand family: SNTP.\nTime-server, timezone, daylight-saving, clock, and synchronization status.\n\nThe guide documents objectives, syntax, parameters, and required CLI mode. Required values appear in angle brackets, optional values in square brackets, and alternatives are separated by a pipe. A displayed command must be entered on one line. Command availability can vary by switch model and firmware.","commands":[{"shell":"SonicWall Switch CLI","command":"show sntp clock","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"SonicWall Switch CLI","command":"show sntp status","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"switch-cli_reference_guide.pdf","sourceAuthority":"SonicWall","namespace":"SONICWALL-SWITCH-CLI","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicWall Switch","Switch 1.3.1"],"technologies":["Managed Switch","CLI","SNTP"],"articleCategories":["Firewalls","SonicWall","Networking","Switching","CLI Reference"],"aliases":["SonicWall SNTP","Switch CLI SNTP"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55218,"title":"SonicWall Switch CLI - Spanning Tree","category":"SonicWall","product":"SonicWall Switch 1.3.1","tags":["SonicWall","Switch","CLI","Spanning Tree","Network Infrastructure"],"keywords":["Spanning Tree","RSTP or MST configuration, priorities, timers, costs, guards, and topology inspection.","SonicWall Switch CLI","Switch 1.3.1","managed switch","network command","show spanning-tree","show spanning-tree detail"],"errorCode":"","eventId":"","severity":"Medium","summary":"Reference for SonicWall Switch 1.3.1 Spanning Tree CLI commands. RSTP or MST configuration, priorities, timers, costs, guards, and topology inspection.","rootCause":"Command failures commonly result from using the wrong CLI mode, omitting a required value, selecting an invalid range, lacking privilege, referencing an unavailable feature, or applying syntax from a different switch firmware release.","resolution":"1. Record the complete prompt, mode, command, parser message, switch model, firmware version, and affected ports or VLANs.\n2. Use help at the current prompt and compare the live command tree with the guide for the installed release.\n3. Start with the read-only show commands listed in this article.\n4. Review dependencies, current and saved configuration, management-path impact, and rollback before any configuration command.\n5. Apply only the verified change during an approved window and validate management access and intended network behavior.","emailScript":"Hello,\n\nWe are reviewing the SonicWall switch Spanning Tree configuration. We will confirm the firmware, current settings, dependencies, and management-path impact before making a controlled change.\n\nPlease let us know if there is a maintenance window or recent network change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the switch name, port or VLAN involved, exact message, and approximate time. Do not change switch settings or share passwords, SNMP secrets, RADIUS keys, or an unredacted configuration.","notes":"Guide scope: SonicWall Switch Command Line Interface 1.3.1.\nCommand family: Spanning Tree.\nRSTP or MST configuration, priorities, timers, costs, guards, and topology inspection.\n\nThe guide documents objectives, syntax, parameters, and required CLI mode. Required values appear in angle brackets, optional values in square brackets, and alternatives are separated by a pipe. A displayed command must be entered on one line. Command availability can vary by switch model and firmware.","commands":[{"shell":"SonicWall Switch CLI","command":"show spanning-tree","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"SonicWall Switch CLI","command":"show spanning-tree detail","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"switch-cli_reference_guide.pdf","sourceAuthority":"SonicWall","namespace":"SONICWALL-SWITCH-CLI","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicWall Switch","Switch 1.3.1"],"technologies":["Managed Switch","CLI","Spanning Tree"],"articleCategories":["Firewalls","SonicWall","Networking","Switching","CLI Reference"],"aliases":["SonicWall Spanning Tree","Switch CLI Spanning Tree"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55219,"title":"SonicWall Switch CLI - SSH","category":"SonicWall","product":"SonicWall Switch 1.3.1","tags":["SonicWall","Switch","CLI","SSH","Network Infrastructure"],"keywords":["SSH","SSH server configuration and inspection.","SonicWall Switch CLI","Switch 1.3.1","managed switch","network command","show ssh configuration"],"errorCode":"","eventId":"","severity":"Low","summary":"Reference for SonicWall Switch 1.3.1 SSH CLI commands. SSH server configuration and inspection.","rootCause":"Command failures commonly result from using the wrong CLI mode, omitting a required value, selecting an invalid range, lacking privilege, referencing an unavailable feature, or applying syntax from a different switch firmware release.","resolution":"1. Record the complete prompt, mode, command, parser message, switch model, firmware version, and affected ports or VLANs.\n2. Use help at the current prompt and compare the live command tree with the guide for the installed release.\n3. Start with the read-only show commands listed in this article.\n4. Review dependencies, current and saved configuration, management-path impact, and rollback before any configuration command.\n5. Apply only the verified change during an approved window and validate management access and intended network behavior.","emailScript":"Hello,\n\nWe are reviewing the SonicWall switch SSH configuration. We will confirm the firmware, current settings, dependencies, and management-path impact before making a controlled change.\n\nPlease let us know if there is a maintenance window or recent network change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the switch name, port or VLAN involved, exact message, and approximate time. Do not change switch settings or share passwords, SNMP secrets, RADIUS keys, or an unredacted configuration.","notes":"Guide scope: SonicWall Switch Command Line Interface 1.3.1.\nCommand family: SSH.\nSSH server configuration and inspection.\n\nThe guide documents objectives, syntax, parameters, and required CLI mode. Required values appear in angle brackets, optional values in square brackets, and alternatives are separated by a pipe. A displayed command must be entered on one line. Command availability can vary by switch model and firmware.","commands":[{"shell":"SonicWall Switch CLI","command":"show ssh configuration","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"switch-cli_reference_guide.pdf","sourceAuthority":"SonicWall","namespace":"SONICWALL-SWITCH-CLI","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicWall Switch","Switch 1.3.1"],"technologies":["Managed Switch","CLI","SSH"],"articleCategories":["Firewalls","SonicWall","Networking","Switching","CLI Reference"],"aliases":["SonicWall SSH","Switch CLI SSH"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55220,"title":"SonicWall Switch CLI - Syslog","category":"SonicWall","product":"SonicWall Switch 1.3.1","tags":["SonicWall","Switch","CLI","Syslog","Network Infrastructure"],"keywords":["Syslog","Local logging, remote syslog servers, severity, and log inspection.","SonicWall Switch CLI","Switch 1.3.1","managed switch","network command","show logging","show logging-server"],"errorCode":"","eventId":"","severity":"Low","summary":"Reference for SonicWall Switch 1.3.1 Syslog CLI commands. Local logging, remote syslog servers, severity, and log inspection.","rootCause":"Command failures commonly result from using the wrong CLI mode, omitting a required value, selecting an invalid range, lacking privilege, referencing an unavailable feature, or applying syntax from a different switch firmware release.","resolution":"1. Record the complete prompt, mode, command, parser message, switch model, firmware version, and affected ports or VLANs.\n2. Use help at the current prompt and compare the live command tree with the guide for the installed release.\n3. Start with the read-only show commands listed in this article.\n4. Review dependencies, current and saved configuration, management-path impact, and rollback before any configuration command.\n5. Apply only the verified change during an approved window and validate management access and intended network behavior.","emailScript":"Hello,\n\nWe are reviewing the SonicWall switch Syslog configuration. We will confirm the firmware, current settings, dependencies, and management-path impact before making a controlled change.\n\nPlease let us know if there is a maintenance window or recent network change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the switch name, port or VLAN involved, exact message, and approximate time. Do not change switch settings or share passwords, SNMP secrets, RADIUS keys, or an unredacted configuration.","notes":"Guide scope: SonicWall Switch Command Line Interface 1.3.1.\nCommand family: Syslog.\nLocal logging, remote syslog servers, severity, and log inspection.\n\nThe guide documents objectives, syntax, parameters, and required CLI mode. Required values appear in angle brackets, optional values in square brackets, and alternatives are separated by a pipe. A displayed command must be entered on one line. Command availability can vary by switch model and firmware.","commands":[{"shell":"SonicWall Switch CLI","command":"show logging","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"SonicWall Switch CLI","command":"show logging-server","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"switch-cli_reference_guide.pdf","sourceAuthority":"SonicWall","namespace":"SONICWALL-SWITCH-CLI","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicWall Switch","Switch 1.3.1"],"technologies":["Managed Switch","CLI","Syslog"],"articleCategories":["Firewalls","SonicWall","Networking","Switching","CLI Reference"],"aliases":["SonicWall Syslog","Switch CLI Syslog"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55221,"title":"SonicWall Switch CLI - VLAN","category":"SonicWall","product":"SonicWall Switch 1.3.1","tags":["SonicWall","Switch","CLI","VLAN","Network Infrastructure"],"keywords":["VLAN","VLAN creation, membership, tagging, PVID, ingress filtering, and VLAN inspection.","SonicWall Switch CLI","Switch 1.3.1","managed switch","network command","show vlan brief","show vlan summary"],"errorCode":"","eventId":"","severity":"Medium","summary":"Reference for SonicWall Switch 1.3.1 VLAN CLI commands. VLAN creation, membership, tagging, PVID, ingress filtering, and VLAN inspection.","rootCause":"Command failures commonly result from using the wrong CLI mode, omitting a required value, selecting an invalid range, lacking privilege, referencing an unavailable feature, or applying syntax from a different switch firmware release.","resolution":"1. Record the complete prompt, mode, command, parser message, switch model, firmware version, and affected ports or VLANs.\n2. Use help at the current prompt and compare the live command tree with the guide for the installed release.\n3. Start with the read-only show commands listed in this article.\n4. Review dependencies, current and saved configuration, management-path impact, and rollback before any configuration command.\n5. Apply only the verified change during an approved window and validate management access and intended network behavior.","emailScript":"Hello,\n\nWe are reviewing the SonicWall switch VLAN configuration. We will confirm the firmware, current settings, dependencies, and management-path impact before making a controlled change.\n\nPlease let us know if there is a maintenance window or recent network change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the switch name, port or VLAN involved, exact message, and approximate time. Do not change switch settings or share passwords, SNMP secrets, RADIUS keys, or an unredacted configuration.","notes":"Guide scope: SonicWall Switch Command Line Interface 1.3.1.\nCommand family: VLAN.\nVLAN creation, membership, tagging, PVID, ingress filtering, and VLAN inspection.\n\nThe guide documents objectives, syntax, parameters, and required CLI mode. Required values appear in angle brackets, optional values in square brackets, and alternatives are separated by a pipe. A displayed command must be entered on one line. Command availability can vary by switch model and firmware.","commands":[{"shell":"SonicWall Switch CLI","command":"show vlan brief","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"SonicWall Switch CLI","command":"show vlan summary","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"switch-cli_reference_guide.pdf","sourceAuthority":"SonicWall","namespace":"SONICWALL-SWITCH-CLI","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicWall Switch","Switch 1.3.1"],"technologies":["Managed Switch","CLI","VLAN"],"articleCategories":["Firewalls","SonicWall","Networking","Switching","CLI Reference"],"aliases":["SonicWall VLAN","Switch CLI VLAN"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":55222,"title":"SonicWall Switch CLI - Voice VLAN","category":"SonicWall","product":"SonicWall Switch 1.3.1","tags":["SonicWall","Switch","CLI","Voice VLAN","Network Infrastructure"],"keywords":["Voice VLAN","Voice VLAN state, OUI, CoS, DSCP, LLDP-MED, and interface configuration.","SonicWall Switch CLI","Switch 1.3.1","managed switch","network command","show voice vlan","show voice vlan oui-table"],"errorCode":"","eventId":"","severity":"Medium","summary":"Reference for SonicWall Switch 1.3.1 Voice VLAN CLI commands. Voice VLAN state, OUI, CoS, DSCP, LLDP-MED, and interface configuration.","rootCause":"Command failures commonly result from using the wrong CLI mode, omitting a required value, selecting an invalid range, lacking privilege, referencing an unavailable feature, or applying syntax from a different switch firmware release.","resolution":"1. Record the complete prompt, mode, command, parser message, switch model, firmware version, and affected ports or VLANs.\n2. Use help at the current prompt and compare the live command tree with the guide for the installed release.\n3. Start with the read-only show commands listed in this article.\n4. Review dependencies, current and saved configuration, management-path impact, and rollback before any configuration command.\n5. Apply only the verified change during an approved window and validate management access and intended network behavior.","emailScript":"Hello,\n\nWe are reviewing the SonicWall switch Voice VLAN configuration. We will confirm the firmware, current settings, dependencies, and management-path impact before making a controlled change.\n\nPlease let us know if there is a maintenance window or recent network change we should consider.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the switch name, port or VLAN involved, exact message, and approximate time. Do not change switch settings or share passwords, SNMP secrets, RADIUS keys, or an unredacted configuration.","notes":"Guide scope: SonicWall Switch Command Line Interface 1.3.1.\nCommand family: Voice VLAN.\nVoice VLAN state, OUI, CoS, DSCP, LLDP-MED, and interface configuration.\n\nThe guide documents objectives, syntax, parameters, and required CLI mode. Required values appear in angle brackets, optional values in square brackets, and alternatives are separated by a pipe. A displayed command must be entered on one line. Command availability can vary by switch model and firmware.","commands":[{"shell":"SonicWall Switch CLI","command":"show voice vlan","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"SonicWall Switch CLI","command":"show voice vlan oui-table","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"switch-cli_reference_guide.pdf","sourceAuthority":"SonicWall","namespace":"SONICWALL-SWITCH-CLI","platforms":["firewalls"],"lastVerified":"2026-08-10","vendors":["SonicWall"],"products":["SonicWall Switch","Switch 1.3.1"],"technologies":["Managed Switch","CLI","Voice VLAN"],"articleCategories":["Firewalls","SonicWall","Networking","Switching","CLI Reference"],"aliases":["SonicWall Voice VLAN","Switch CLI Voice VLAN"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56000,"title":"Ruckus ICX - Diagnose Copper Cable with TDR","category":"Ruckus","product":"FastIron 09.0.10","tags":["Ruckus","Network Appliance","FastIron","ICX","Cabling","TDR"],"keywords":["Ruckus ICX - Diagnose Copper Cable with TDR","FastIron 09.0.10","Virtual Cable Test results identify open, terminated, and other copper-pair conditions on supported ICX ports.","icx-cable-tdr","Ruckus Networks","CommScope","Vistance Networks","FastIron","ICX","Cabling","TDR","show cable-diagnostics tdr <stack-id>/<slot>/<port>"],"errorCode":"","eventId":"","severity":"Medium","summary":"Virtual Cable Test results identify open, terminated, and other copper-pair conditions on supported ICX ports.","rootCause":"A damaged, disconnected, incorrectly terminated, or unsupported copper path can cause link failure or instability.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Run the read-only TDR result command for the exact stack/slot/port and interpret every pair. Correlate the result with link state and test the patch lead and permanent link before replacing switch hardware.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus ICX - Diagnose Copper Cable with TDR.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: FastIron 09.0.10.\nSource: fastiron-09010-commandref-1.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[{"shell":"FastIron CLI","command":"show cable-diagnostics tdr <stack-id>/<slot>/<port>","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"fastiron-09010-commandref-1.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-FASTIRON-CLI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","FastIron","ICX","Cabling","TDR"],"articleCategories":["Networking","Ruckus","FastIron","ICX","Cabling","TDR"],"aliases":["icx-cable-tdr","ICX - Diagnose Copper Cable with TDR"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56001,"title":"Ruckus ICX - Cable Signal Error Counters","category":"Ruckus","product":"FastIron 09.0.10","tags":["Ruckus","Network Appliance","FastIron","ICX","Cabling","Physical Layer"],"keywords":["Ruckus ICX - Cable Signal Error Counters","FastIron 09.0.10","Cable signal error counters help identify degraded physical-layer links.","icx-cable-errors","Ruckus Networks","CommScope","Vistance Networks","FastIron","ICX","Cabling","Physical Layer","show cable-signal-error-count","show interfaces brief"],"errorCode":"","eventId":"","severity":"Medium","summary":"Cable signal error counters help identify degraded physical-layer links.","rootCause":"Bad media, connectors, optics, interference, negotiation, or failing ports can increase errors.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Capture interface statistics and cable-signal error counts twice across a measured interval. Compare both ends, speed/duplex, optics, and known-good media.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus ICX - Cable Signal Error Counters.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: FastIron 09.0.10.\nSource: fastiron-09010-commandref-1.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[{"shell":"FastIron CLI","command":"show cable-signal-error-count","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FastIron CLI","command":"show interfaces brief","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"fastiron-09010-commandref-1.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-FASTIRON-CLI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","FastIron","ICX","Cabling","Physical Layer"],"articleCategories":["Networking","Ruckus","FastIron","ICX","Cabling","Physical Layer"],"aliases":["icx-cable-errors","ICX - Cable Signal Error Counters"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56002,"title":"Ruckus ICX - Collect FastIron Logs","category":"Ruckus","product":"FastIron 09.0.10 / 10.0.10","tags":["Ruckus","Network Appliance","FastIron","ICX","Syslog","Logging"],"keywords":["Ruckus ICX - Collect FastIron Logs","FastIron 09.0.10 / 10.0.10","FastIron logging commands expose buffered, persistent, configuration-change, and remote syslog evidence.","icx-logging","Ruckus Networks","CommScope","Vistance Networks","FastIron","ICX","Syslog","Logging","show clock","show logging","show running-config | include logging"],"errorCode":"","eventId":"","severity":"Low","summary":"FastIron logging commands expose buffered, persistent, configuration-change, and remote syslog evidence.","rootCause":"Without a synchronized clock and retained logs, link, authentication, routing, stacking, and management failures are difficult to correlate.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Confirm time first, capture the logging configuration and current buffer, then correlate severity, facility, source, and timestamp with the external syslog receiver.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus ICX - Collect FastIron Logs.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: FastIron 09.0.10 / 10.0.10.\nSource: fastiron-09010-commandref-1.pdf; ruckus_fastiron_management_configuration_guide,_10_0_10_2026-08-10-08-43-15.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[{"shell":"FastIron CLI","command":"show clock","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FastIron CLI","command":"show logging","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FastIron CLI","command":"show running-config | include logging","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"fastiron-09010-commandref-1.pdf; ruckus_fastiron_management_configuration_guide,_10_0_10_2026-08-10-08-43-15.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-FASTIRON-CLI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","FastIron","ICX","Syslog","Logging"],"articleCategories":["Networking","Ruckus","FastIron","ICX","Syslog","Logging"],"aliases":["icx-logging","ICX - Collect FastIron Logs"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56003,"title":"Ruckus ICX - Link Error Disabled Port","category":"Ruckus","product":"FastIron 09.0.10","tags":["Ruckus","Network Appliance","FastIron","ICX","Errdisable","Ports"],"keywords":["Ruckus ICX - Link Error Disabled Port","FastIron 09.0.10","FastIron can disable a link after configured error thresholds are crossed.","icx-link-error-disable","Ruckus Networks","CommScope","Vistance Networks","FastIron","ICX","Errdisable","Ports","show link-error-disable","show interfaces brief","show logging"],"errorCode":"","eventId":"","severity":"High","summary":"FastIron can disable a link after configured error thresholds are crossed.","rootCause":"Excess physical errors, configured protection thresholds, unstable media, or a peer issue can place a port into link-error-disable state.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Inspect the disabled state, port counters, logs, transceiver, and peer. Correct the physical cause before using an approved recovery action; repeated blind re-enablement can create instability.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus ICX - Link Error Disabled Port.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: FastIron 09.0.10.\nSource: fastiron-09010-commandref-1.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[{"shell":"FastIron CLI","command":"show link-error-disable","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FastIron CLI","command":"show interfaces brief","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FastIron CLI","command":"show logging","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"fastiron-09010-commandref-1.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-FASTIRON-CLI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","FastIron","ICX","Errdisable","Ports"],"articleCategories":["Networking","Ruckus","FastIron","ICX","Errdisable","Ports"],"aliases":["icx-link-error-disable","ICX - Link Error Disabled Port"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56004,"title":"Ruckus ICX - Loop Detection Disabled Port","category":"Ruckus","product":"FastIron 09.0.10 / 10.0.10","tags":["Ruckus","Network Appliance","FastIron","ICX","Loop Detection","Spanning Tree"],"keywords":["Ruckus ICX - Loop Detection Disabled Port","FastIron 09.0.10 / 10.0.10","Loop detection can shut a port to protect the network when a Layer 2 loop is observed.","icx-loop-disable","Ruckus Networks","CommScope","Vistance Networks","FastIron","ICX","Loop Detection","Spanning Tree","show loop-detection status","show loop-detect no-shutdown-status","show spanning-tree","show logging"],"errorCode":"","eventId":"","severity":"High","summary":"Loop detection can shut a port to protect the network when a Layer 2 loop is observed.","rootCause":"An accidental patch loop, unmanaged switch, bridging device, incorrect topology, or protection-policy event can trigger shutdown.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Inspect loop-detection status, spanning tree, MAC movement, and logs. Physically trace and remove the loop before recovering the port under change control.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus ICX - Loop Detection Disabled Port.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: FastIron 09.0.10 / 10.0.10.\nSource: fastiron-09010-commandref-1.pdf; ruckus_fastiron_management_configuration_guide,_10_0_10_2026-08-10-08-43-15.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[{"shell":"FastIron CLI","command":"show loop-detection status","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FastIron CLI","command":"show loop-detect no-shutdown-status","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FastIron CLI","command":"show spanning-tree","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FastIron CLI","command":"show logging","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"fastiron-09010-commandref-1.pdf; ruckus_fastiron_management_configuration_guide,_10_0_10_2026-08-10-08-43-15.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-FASTIRON-CLI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","FastIron","ICX","Loop Detection","Spanning Tree"],"articleCategories":["Networking","Ruckus","FastIron","ICX","Loop Detection","Spanning Tree"],"aliases":["icx-loop-disable","ICX - Loop Detection Disabled Port"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56005,"title":"Ruckus ICX - PoE Internal Hardware Fault or Non-PD State","category":"Ruckus","product":"FastIron 10.0.10","tags":["Ruckus","Network Appliance","FastIron","ICX","PoE","Hardware"],"keywords":["Ruckus ICX - PoE Internal Hardware Fault or Non-PD State","FastIron 10.0.10","The PoE status can show internal hardware fault or a powered device stuck in a non-PD state.","internal h/w fault","icx-poe-fault","Ruckus Networks","CommScope","Vistance Networks","FastIron","ICX","PoE","Hardware","show inline power","show inline power <stack-id>"],"errorCode":"internal h/w fault","eventId":"","severity":"High","summary":"The PoE status can show internal hardware fault or a powered device stuck in a non-PD state.","rootCause":"Documented causes include PoE-chip failure, data-link coupling behavior, high concentrated load and temperature, or external voltage on switch-to-switch PoE ports.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Use show inline power to identify exact ports, power budget, state, and fault. For internal hardware fault, remove powered devices and follow Ruckus hardware support guidance. Distribute high-power loads and remove unintended external power; use interface or inline-power cycling only in an approved window.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus ICX - PoE Internal Hardware Fault or Non-PD State.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: FastIron 10.0.10.\nSource: ruckus_fastiron_management_configuration_guide,_10_0_10_2026-08-10-08-43-15.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[{"shell":"FastIron CLI","command":"show inline power","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FastIron CLI","command":"show inline power <stack-id>","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ruckus_fastiron_management_configuration_guide,_10_0_10_2026-08-10-08-43-15.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-FASTIRON","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","FastIron","ICX","PoE","Hardware"],"articleCategories":["Networking","Ruckus","FastIron","ICX","PoE","Hardware"],"aliases":["icx-poe-fault","ICX - PoE Internal Hardware Fault or Non-PD State"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56006,"title":"Ruckus ICX - SmartZone or Ruckus One Connection Failure","category":"Ruckus","product":"FastIron 10.0.10","tags":["Ruckus","Network Appliance","FastIron","ICX","SmartZone","Ruckus One","TLS"],"keywords":["Ruckus ICX - SmartZone or Ruckus One Connection Failure","FastIron 10.0.10","An ICX switch cannot register with or maintain its management connection to SmartZone or Ruckus One.","error 60","icx-manager-connect","Ruckus Networks","CommScope","Vistance Networks","FastIron","ICX","SmartZone","Ruckus One","TLS","show version | include UFI","show hmon client status all-clients","show clock","dm verify-device-certs","show manager status","show manager log"],"errorCode":"error 60","eventId":"","severity":"High","summary":"An ICX switch cannot register with or maintain its management connection to SmartZone or Ruckus One.","rootCause":"Missing UFI, incomplete upgrade processes, incorrect clock, invalid device certificate, DNS or routing failure, missing registrar configuration, or a stuck manager state are documented causes.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Validate UFI, hmon clients, clock, hardware certificate, registrar, DNS, reachability, manager state, and manager log in that order. Error 60 during discovery indicates SSL validation commonly caused by incorrect system time; configure NTP. An invalid TPM device certificate requires RMA rather than bypass.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus ICX - SmartZone or Ruckus One Connection Failure.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: FastIron 10.0.10.\nSource: ruckus_fastiron_management_configuration_guide,_10_0_10_2026-08-10-08-43-15.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[{"shell":"FastIron CLI","command":"show version | include UFI","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FastIron CLI","command":"show hmon client status all-clients","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FastIron CLI","command":"show clock","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FastIron CLI","command":"dm verify-device-certs","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FastIron CLI","command":"show manager status","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FastIron CLI","command":"show manager log","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ruckus_fastiron_management_configuration_guide,_10_0_10_2026-08-10-08-43-15.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-FASTIRON-MANAGER","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","FastIron","ICX","SmartZone","Ruckus One","TLS"],"articleCategories":["Networking","Ruckus","FastIron","ICX","SmartZone","Ruckus One","TLS"],"aliases":["icx-manager-connect","ICX - SmartZone or Ruckus One Connection Failure"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56007,"title":"Ruckus ICX - Manager Agent Stuck in Query or Connecting","category":"Ruckus","product":"FastIron 10.0.10","tags":["Ruckus","Network Appliance","FastIron","ICX","SmartZone","Ruckus One"],"keywords":["Ruckus ICX - Manager Agent Stuck in Query or Connecting","FastIron 10.0.10","The FastIron manager agent remains in Query or Connecting instead of reaching a connected state.","icx-manager-query","Ruckus Networks","CommScope","Vistance Networks","FastIron","ICX","SmartZone","Ruckus One","show manager status","show manager log","show clock","traceroute <REGISTRAR-IP>"],"errorCode":"","eventId":"","severity":"High","summary":"The FastIron manager agent remains in Query or Connecting instead of reaching a connected state.","rootCause":"Query commonly indicates registrar, DNS, reachability, time, or certificate discovery trouble; Connecting indicates registration completed but the management session did not finish.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Review show manager status counters and show manager log. For Query, verify DNS and trace the registrar or configured controller. If Connecting persists after validated connectivity and time, collect evidence and contact Ruckus Support.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus ICX - Manager Agent Stuck in Query or Connecting.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: FastIron 10.0.10.\nSource: ruckus_fastiron_management_configuration_guide,_10_0_10_2026-08-10-08-43-15.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[{"shell":"FastIron CLI","command":"show manager status","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FastIron CLI","command":"show manager log","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FastIron CLI","command":"show clock","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FastIron CLI","command":"traceroute <REGISTRAR-IP>","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ruckus_fastiron_management_configuration_guide,_10_0_10_2026-08-10-08-43-15.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-FASTIRON-MANAGER","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","FastIron","ICX","SmartZone","Ruckus One"],"articleCategories":["Networking","Ruckus","FastIron","ICX","SmartZone","Ruckus One"],"aliases":["icx-manager-query","ICX - Manager Agent Stuck in Query or Connecting"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56008,"title":"Ruckus ICX - Inspect FastIron License State","category":"Ruckus","product":"FastIron 09.0.10","tags":["Ruckus","Network Appliance","FastIron","ICX","Licensing"],"keywords":["Ruckus ICX - Inspect FastIron License State","FastIron 09.0.10","FastIron license commands show installed and unit-specific entitlement state.","icx-license","Ruckus Networks","CommScope","Vistance Networks","FastIron","ICX","Licensing","show license","show license installed","show license unit"],"errorCode":"","eventId":"","severity":"Medium","summary":"FastIron license commands show installed and unit-specific entitlement state.","rootCause":"A missing, mismatched, expired, or incorrectly assigned license can make a licensed feature unavailable.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Capture chassis identity, software version, installed licenses, and unit license state. Verify entitlement and platform support before installing or deleting any license.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus ICX - Inspect FastIron License State.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: FastIron 09.0.10.\nSource: fastiron-09010-commandref-1.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[{"shell":"FastIron CLI","command":"show license","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FastIron CLI","command":"show license installed","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FastIron CLI","command":"show license unit","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"fastiron-09010-commandref-1.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-FASTIRON-CLI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","FastIron","ICX","Licensing"],"articleCategories":["Networking","Ruckus","FastIron","ICX","Licensing"],"aliases":["icx-license","ICX - Inspect FastIron License State"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56009,"title":"Ruckus ICX - RESTCONF Service Status","category":"Ruckus","product":"FastIron 09.0.10","tags":["Ruckus","Network Appliance","FastIron","ICX","RESTCONF","API"],"keywords":["Ruckus ICX - RESTCONF Service Status","FastIron 09.0.10","The RESTCONF status command confirms the FastIron management API state.","icx-restconf","Ruckus Networks","CommScope","Vistance Networks","FastIron","ICX","RESTCONF","API","show restconf status","show ip http status"],"errorCode":"","eventId":"","severity":"Medium","summary":"The RESTCONF status command confirms the FastIron management API state.","rootCause":"The service can be disabled, unreachable, unauthorized, unlicensed, incorrectly addressed, or affected by TLS and management VRF configuration.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Capture RESTCONF status, HTTP service status, running service configuration, management VRF, reachability, TLS, and authentication evidence before enabling or changing the API.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus ICX - RESTCONF Service Status.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: FastIron 09.0.10.\nSource: fastiron-09010-commandref-1.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[{"shell":"FastIron CLI","command":"show restconf status","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FastIron CLI","command":"show ip http status","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"fastiron-09010-commandref-1.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-FASTIRON-CLI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","FastIron","ICX","RESTCONF","API"],"articleCategories":["Networking","Ruckus","FastIron","ICX","RESTCONF","API"],"aliases":["icx-restconf","ICX - RESTCONF Service Status"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56010,"title":"Ruckus ICX - NTP and Clock Validation","category":"Ruckus","product":"FastIron 09.0.10 / 10.0.10","tags":["Ruckus","Network Appliance","FastIron","ICX","NTP","Time"],"keywords":["Ruckus ICX - NTP and Clock Validation","FastIron 09.0.10 / 10.0.10","Accurate switch time is required for trustworthy logs and certificate-based cloud management.","icx-ntp","Ruckus Networks","CommScope","Vistance Networks","FastIron","ICX","NTP","Time","show clock","show ntp status","show running-config | include ntp"],"errorCode":"","eventId":"","severity":"Medium","summary":"Accurate switch time is required for trustworthy logs and certificate-based cloud management.","rootCause":"Unreachable NTP servers, DNS, routing, VRF, source-interface, authentication, or clock configuration can prevent synchronization.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Compare the clock and NTP status, verify server reachability from the correct VRF/source, and correlate NTP logs. Do not reset NTP as a first step.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus ICX - NTP and Clock Validation.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: FastIron 09.0.10 / 10.0.10.\nSource: fastiron-09010-commandref-1.pdf; ruckus_fastiron_management_configuration_guide,_10_0_10_2026-08-10-08-43-15.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[{"shell":"FastIron CLI","command":"show clock","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FastIron CLI","command":"show ntp status","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FastIron CLI","command":"show running-config | include ntp","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"fastiron-09010-commandref-1.pdf; ruckus_fastiron_management_configuration_guide,_10_0_10_2026-08-10-08-43-15.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-FASTIRON-CLI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","FastIron","ICX","NTP","Time"],"articleCategories":["Networking","Ruckus","FastIron","ICX","NTP","Time"],"aliases":["icx-ntp","ICX - NTP and Clock Validation"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56011,"title":"Ruckus ICX - Stack Zero-Touch Status","category":"Ruckus","product":"FastIron 09.0.10 / 10.0.10","tags":["Ruckus","Network Appliance","FastIron","ICX","Stacking","Zero Touch"],"keywords":["Ruckus ICX - Stack Zero-Touch Status","FastIron 09.0.10 / 10.0.10","FastIron stack zero-touch logs and status expose discovery and formation progress.","icx-stack-ztp","Ruckus Networks","CommScope","Vistance Networks","FastIron","ICX","Stacking","Zero Touch","show stack zero-touch status","show stack zero-touch log","show stack"],"errorCode":"","eventId":"","severity":"High","summary":"FastIron stack zero-touch logs and status expose discovery and formation progress.","rootCause":"Stack topology, cabling, suggested IDs, firmware group, approval state, or saved configuration can prevent automated formation.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Capture zero-touch status and logs plus stack topology and version. Confirm the SmartZone firmware group and intended active controller before changing stack configuration.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus ICX - Stack Zero-Touch Status.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: FastIron 09.0.10 / 10.0.10.\nSource: fastiron-09010-commandref-1.pdf; ruckus_fastiron_management_configuration_guide,_10_0_10_2026-08-10-08-43-15.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[{"shell":"FastIron CLI","command":"show stack zero-touch status","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FastIron CLI","command":"show stack zero-touch log","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"FastIron CLI","command":"show stack","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"fastiron-09010-commandref-1.pdf; ruckus_fastiron_management_configuration_guide,_10_0_10_2026-08-10-08-43-15.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-FASTIRON-CLI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","FastIron","ICX","Stacking","Zero Touch"],"articleCategories":["Networking","Ruckus","FastIron","ICX","Stacking","Zero Touch"],"aliases":["icx-stack-ztp","ICX - Stack Zero-Touch Status"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56012,"title":"Ruckus Network Director - CLI Network Troubleshooting Tools","category":"Ruckus","product":"Ruckus Network Director 4.0","tags":["Ruckus","Network Appliance","Network Director","CLI","Diagnostics"],"keywords":["Ruckus Network Director - CLI Network Troubleshooting Tools","Ruckus Network Director 4.0","Network Director provides scoped CLI tools for route, DNS, packet, port, and reachability testing.","rnd-network-tools","Ruckus Networks","CommScope","Vistance Networks","Network Director","CLI","Diagnostics","network-tools help","network-tools ping <HOST>","network-tools traceroute <HOST>","network-tools nslookup <HOST>","network-tools dig <HOST>","network-tools nc <HOST> <PORT>"],"errorCode":"","eventId":"","severity":"Low","summary":"Network Director provides scoped CLI tools for route, DNS, packet, port, and reachability testing.","rootCause":"Deployment and license connectivity can fail because of DNS, routing, packet filtering, port reachability, or upstream path problems.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Use network-tools help, then choose the narrowest safe test. Limit tcpdump by interface, host, port, and count; packet captures can contain sensitive traffic.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus Network Director - CLI Network Troubleshooting Tools.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: Ruckus Network Director 4.0.\nSource: ruckus_network_director_user_guide,_4_0_2026-08-10-08-41-48.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[{"shell":"RND CLI","command":"network-tools help","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"RND CLI","command":"network-tools ping <HOST>","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"RND CLI","command":"network-tools traceroute <HOST>","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"RND CLI","command":"network-tools nslookup <HOST>","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"RND CLI","command":"network-tools dig <HOST>","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"RND CLI","command":"network-tools nc <HOST> <PORT>","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ruckus_network_director_user_guide,_4_0_2026-08-10-08-41-48.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-RND","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","Network Director","CLI","Diagnostics"],"articleCategories":["Networking","Ruckus","Network Director","CLI","Diagnostics"],"aliases":["rnd-network-tools","Network Director - CLI Network Troubleshooting Tools"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56013,"title":"Ruckus Network Director - Collect Application Logs","category":"Ruckus","product":"Ruckus Network Director 4.0","tags":["Ruckus","Network Appliance","Network Director","Logging","AP Discovery"],"keywords":["Ruckus Network Director - Collect Application Logs","Ruckus Network Director 4.0","Application logs cover web, SmartZone sync, AP discovery, configuration backup, and license synchronization processes.","rnd-logs","Ruckus Networks","CommScope","Vistance Networks","Network Director","Logging","AP Discovery"],"errorCode":"","eventId":"","severity":"Low","summary":"Application logs cover web, SmartZone sync, AP discovery, configuration backup, and license synchronization processes.","rootCause":"The responsible process and severity cannot be identified from a user-facing symptom alone.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Filter the relevant log type and severity, refresh, and download only the time-bounded files needed. Preserve original timestamps and sanitize sensitive data.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus Network Director - Collect Application Logs.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: Ruckus Network Director 4.0.\nSource: ruckus_network_director_user_guide,_4_0_2026-08-10-08-41-48.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_network_director_user_guide,_4_0_2026-08-10-08-41-48.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-RND","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","Network Director","Logging","AP Discovery"],"articleCategories":["Networking","Ruckus","Network Director","Logging","AP Discovery"],"aliases":["rnd-logs","Network Director - Collect Application Logs"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56014,"title":"Ruckus Network Director - Configuration Backup and Restore","category":"Ruckus","product":"Ruckus Network Director 4.0","tags":["Ruckus","Network Appliance","Network Director","Backup","Restore"],"keywords":["Ruckus Network Director - Configuration Backup and Restore","Ruckus Network Director 4.0","Network Director can export its database configuration and restore it from an uploaded backup.","rnd-backup","Ruckus Networks","CommScope","Vistance Networks","Network Director","Backup","Restore"],"errorCode":"","eventId":"","severity":"High","summary":"Network Director can export its database configuration and restore it from an uploaded backup.","rootCause":"A failed node, bad change, or migration can require restoration, but import replaces current RND data.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Download and protect a current export. Validate backup origin and compatibility before restore. Treat upload as a high-impact change because it replaces all current Network Director data.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus Network Director - Configuration Backup and Restore.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: Ruckus Network Director 4.0.\nSource: ruckus_network_director_user_guide,_4_0_2026-08-10-08-41-48.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_network_director_user_guide,_4_0_2026-08-10-08-41-48.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-RND","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","Network Director","Backup","Restore"],"articleCategories":["Networking","Ruckus","Network Director","Backup","Restore"],"aliases":["rnd-backup","Network Director - Configuration Backup and Restore"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56015,"title":"Ruckus Network Director - Not Enough Device Licenses","category":"Ruckus","product":"Ruckus Network Director 4.0","tags":["Ruckus","Network Appliance","Network Director","Licensing","Flexera"],"keywords":["Ruckus Network Director - Not Enough Device Licenses","Ruckus Network Director 4.0","Network Director reports that not enough device licenses are available and can reject or randomly limit AP onboarding during a batch operation.","Not enough device licenses are available for this operation","rnd-license-shortage","Ruckus Networks","CommScope","Vistance Networks","Network Director","Licensing","Flexera"],"errorCode":"Not enough device licenses are available for this operation","eventId":"","severity":"High","summary":"Network Director reports that not enough device licenses are available and can reject or randomly limit AP onboarding during a batch operation.","rootCause":"The current AP count equals or exceeds licensed capacity, the trial or RTU data is stale, or Flexera synchronization has not completed.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Open Admin > Licenses, compare capacity and usage, synchronize with the license server, and verify Flexera allocation. Add or reassign capacity before retrying onboarding; do not repeatedly batch onboard when capacity is insufficient.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus Network Director - Not Enough Device Licenses.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: Ruckus Network Director 4.0.\nSource: ruckus_network_director_user_guide,_4_0_2026-08-10-08-41-48.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_network_director_user_guide,_4_0_2026-08-10-08-41-48.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-RND","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","Network Director","Licensing","Flexera"],"articleCategories":["Networking","Ruckus","Network Director","Licensing","Flexera"],"aliases":["rnd-license-shortage","Network Director - Not Enough Device Licenses"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56016,"title":"Ruckus One - Subscription Courtesy Period and Expiration","category":"Ruckus","product":"Ruckus One Subscriptions","tags":["Ruckus","Network Appliance","Ruckus One","Licensing","Subscription"],"keywords":["Ruckus One - Subscription Courtesy Period and Expiration","Ruckus One Subscriptions","A lapsed subscription enters a documented 60-day courtesy period; configuration is retained for 90 days after that period, subject to the guide's stated behavior.","ruckus-one-expiry","Ruckus Networks","CommScope","Vistance Networks","Ruckus One","Licensing","Subscription"],"errorCode":"","eventId":"","severity":"High","summary":"A lapsed subscription enters a documented 60-day courtesy period; configuration is retained for 90 days after that period, subject to the guide's stated behavior.","rootCause":"A paid or trial subscription expired or was not renewed or allocated to the tenant and devices.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Review Administration > Subscriptions, expiration, time left, status, and license gap. Coordinate renewal before the courtesy period ends and export critical configuration and inventory under policy.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus One - Subscription Courtesy Period and Expiration.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: Ruckus One Subscriptions.\nSource: ruckus_one_subscriptions_licensing_guide_2026-08-10-08-45-37.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_one_subscriptions_licensing_guide_2026-08-10-08-45-37.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-ONE","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","Ruckus One","Licensing","Subscription"],"articleCategories":["Networking","Ruckus","Ruckus One","Licensing","Subscription"],"aliases":["ruckus-one-expiry","One - Subscription Courtesy Period and Expiration"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56017,"title":"Ruckus One - License Compliance Shortage","category":"Ruckus","product":"Ruckus One Subscriptions","tags":["Ruckus","Network Appliance","Ruckus One","Licensing","MSP","Compliance"],"keywords":["Ruckus One - License Compliance Shortage","Ruckus One Subscriptions","A red compliance indicator or negative Licenses Available / Gap value means allocated subscriptions do not cover configured devices.","negative license gap","ruckus-one-shortage","Ruckus Networks","CommScope","Vistance Networks","Ruckus One","Licensing","MSP","Compliance"],"errorCode":"negative license gap","eventId":"","severity":"High","summary":"A red compliance indicator or negative Licenses Available / Gap value means allocated subscriptions do not cover configured devices.","rootCause":"Device consumption exceeds active paid, trial, or assigned licenses, or MSP allocation is assigned to the wrong account.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Compare configured devices, licenses used, active and assigned licenses, and the gap for the correct REC or MSP scope. Purchase, renew, or reassign the required count and refresh the portal.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus One - License Compliance Shortage.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: Ruckus One Subscriptions.\nSource: ruckus_one_subscriptions_licensing_guide_2026-08-10-08-45-37.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_one_subscriptions_licensing_guide_2026-08-10-08-45-37.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-ONE","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","Ruckus One","Licensing","MSP","Compliance"],"articleCategories":["Networking","Ruckus","Ruckus One","Licensing","MSP","Compliance"],"aliases":["ruckus-one-shortage","One - License Compliance Shortage"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56018,"title":"Ruckus One - Subscription Not Visible After Activation","category":"Ruckus","product":"Ruckus One Subscriptions","tags":["Ruckus","Network Appliance","Ruckus One","Licensing","Activation"],"keywords":["Ruckus One - Subscription Not Visible After Activation","Ruckus One Subscriptions","An activated Ruckus One subscription does not appear or remains inactive in the cloud portal.","ruckus-one-activation","Ruckus Networks","CommScope","Vistance Networks","Ruckus One","Licensing","Activation"],"errorCode":"","eventId":"","severity":"Medium","summary":"An activated Ruckus One subscription does not appear or remains inactive in the cloud portal.","rootCause":"The unique activation code was not activated, the entitlement belongs to another support account, allocation is incomplete, or portal data has not refreshed.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Verify the Ruckus Support account and activation code, then inspect Administration > Subscriptions for part number, device count, dates, and status. Refresh after entitlement allocation; escalate with order and entitlement evidence without sharing the activation code publicly.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus One - Subscription Not Visible After Activation.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: Ruckus One Subscriptions.\nSource: ruckus_one_subscriptions_licensing_guide_2026-08-10-08-45-37.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_one_subscriptions_licensing_guide_2026-08-10-08-45-37.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-ONE","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","Ruckus One","Licensing","Activation"],"articleCategories":["Networking","Ruckus","Ruckus One","Licensing","Activation"],"aliases":["ruckus-one-activation","One - Subscription Not Visible After Activation"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56019,"title":"Ruckus IoT Controller - Database Backup and Restore","category":"Ruckus","product":"Ruckus IoT Controller 3.1.0.0 GA","tags":["Ruckus","Network Appliance","IoT Controller","Backup","Restore"],"keywords":["Ruckus IoT Controller - Database Backup and Restore","Ruckus IoT Controller 3.1.0.0 GA","The IoT Controller retains one database backup; creating a new backup overwrites the current retained file.","iot-backup","Ruckus Networks","CommScope","Vistance Networks","IoT Controller","Backup","Restore"],"errorCode":"","eventId":"","severity":"High","summary":"The IoT Controller retains one database backup; creating a new backup overwrites the current retained file.","rootCause":"A backup may be missing, overwritten, incompatible, corrupt, or restored to the wrong controller.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Download the existing backup before creating another. Validate the tar.gz origin and version, schedule restore downtime, and preserve rollback. Restore replaces controller state and must be treated as high impact.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus IoT Controller - Database Backup and Restore.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: Ruckus IoT Controller 3.1.0.0 GA.\nSource: ruckus_iot_controller_configuration_guide,_3_1_0_0_ga_2026-08-10-08-56-41.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_iot_controller_configuration_guide,_3_1_0_0_ga_2026-08-10-08-56-41.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-IOT","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","IoT Controller","Backup","Restore"],"articleCategories":["Networking","Ruckus","IoT Controller","Backup","Restore"],"aliases":["iot-backup","IoT Controller - Database Backup and Restore"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56020,"title":"Ruckus IoT Controller - License Upload","category":"Ruckus","product":"Ruckus IoT Controller 3.1.0.0 GA","tags":["Ruckus","Network Appliance","IoT Controller","Licensing"],"keywords":["Ruckus IoT Controller - License Upload","Ruckus IoT Controller 3.1.0.0 GA","The controller supports INSTANCE-IOTC and CONTAINER-IOT-RCAP licenses and can upload primary or secondary license files.","iot-license","Ruckus Networks","CommScope","Vistance Networks","IoT Controller","Licensing"],"errorCode":"","eventId":"","severity":"High","summary":"The controller supports INSTANCE-IOTC and CONTAINER-IOT-RCAP licenses and can upload primary or secondary license files.","rootCause":"The license file can be missing, assigned to another instance, invalid, expired, incompatible, or uploaded in the wrong slot.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Confirm controller identity, deployment type, entitlement, file integrity, and primary or secondary slot. Preserve the current license evidence before upload and verify services afterward.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus IoT Controller - License Upload.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: Ruckus IoT Controller 3.1.0.0 GA.\nSource: ruckus_iot_controller_configuration_guide,_3_1_0_0_ga_2026-08-10-08-56-41.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_iot_controller_configuration_guide,_3_1_0_0_ga_2026-08-10-08-56-41.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-IOT","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","IoT Controller","Licensing"],"articleCategories":["Networking","Ruckus","IoT Controller","Licensing"],"aliases":["iot-license","IoT Controller - License Upload"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56021,"title":"Ruckus ZoneDirector - Safe Debug Evidence Collection","category":"Ruckus","product":"ZoneDirector 10.5.1","tags":["Ruckus","Network Appliance","ZoneDirector","Debug","Logging"],"keywords":["Ruckus ZoneDirector - Safe Debug Evidence Collection","ZoneDirector 10.5.1","The privileged debug context provides show, log, remote AP, core-dump, and support evidence commands.","zd-debug","Ruckus Networks","CommScope","Vistance Networks","ZoneDirector","Debug","Logging","debug","help","show logs","show configuration_change_log","show remote-troubleshooting"],"errorCode":"","eventId":"","severity":"Low","summary":"The privileged debug context provides show, log, remote AP, core-dump, and support evidence commands.","rootCause":"Controller or AP failures often require component-specific evidence unavailable from the normal UI.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Enter debug, use help or list-all, and begin with show commands. Save debug information to an approved destination. Enable broad logs or remote troubleshooting only for a bounded period with support approval.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus ZoneDirector - Safe Debug Evidence Collection.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: ZoneDirector 10.5.1.\nSource: ruckus_zonedirector_10_5_1_command_line_interface_reference_guide_2026-08-10-08-50-23.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[{"shell":"ZoneDirector CLI","command":"debug","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"ZoneDirector Debug CLI","command":"help","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"ZoneDirector Debug CLI","command":"show logs","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"ZoneDirector Debug CLI","command":"show configuration_change_log","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"ZoneDirector Debug CLI","command":"show remote-troubleshooting","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ruckus_zonedirector_10_5_1_command_line_interface_reference_guide_2026-08-10-08-50-23.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-ZD","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","ZoneDirector","Debug","Logging"],"articleCategories":["Networking","Ruckus","ZoneDirector","Debug","Logging"],"aliases":["zd-debug","ZoneDirector - Safe Debug Evidence Collection"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56022,"title":"Ruckus ZoneDirector - Inspect AP and Client State","category":"Ruckus","product":"ZoneDirector 10.5.1","tags":["Ruckus","Network Appliance","ZoneDirector","Access Point","Clients"],"keywords":["Ruckus ZoneDirector - Inspect AP and Client State","ZoneDirector 10.5.1","ZoneDirector debug show commands list AP configuration and connected client state.","zd-ap-state","Ruckus Networks","CommScope","Vistance Networks","ZoneDirector","Access Point","Clients","show ap","show station"],"errorCode":"","eventId":"","severity":"Medium","summary":"ZoneDirector debug show commands list AP configuration and connected client state.","rootCause":"AP adoption, WLAN, addressing, radio, link, or client association state can diverge from the intended controller configuration.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Capture show ap and show station output for the affected MAC only, then compare director, IP, WLAN, radio, link, and client fields with the intended zone and policy.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus ZoneDirector - Inspect AP and Client State.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: ZoneDirector 10.5.1.\nSource: ruckus_zonedirector_10_5_1_command_line_interface_reference_guide_2026-08-10-08-50-23.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[{"shell":"ZoneDirector Debug CLI","command":"show ap","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"ZoneDirector Debug CLI","command":"show station","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ruckus_zonedirector_10_5_1_command_line_interface_reference_guide_2026-08-10-08-50-23.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-ZD","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","ZoneDirector","Access Point","Clients"],"articleCategories":["Networking","Ruckus","ZoneDirector","Access Point","Clients"],"aliases":["zd-ap-state","ZoneDirector - Inspect AP and Client State"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56023,"title":"Ruckus ZoneDirector - Remote AP CLI Diagnostics","category":"Ruckus","product":"ZoneDirector 10.5.1","tags":["Ruckus","Network Appliance","ZoneDirector","Access Point","Remote CLI"],"keywords":["Ruckus ZoneDirector - Remote AP CLI Diagnostics","ZoneDirector 10.5.1","remote_ap_cli executes an AP CLI command through the controller for one or all connected APs.","zd-remote-ap","Ruckus Networks","CommScope","Vistance Networks","ZoneDirector","Access Point","Remote CLI","remote_ap_cli -a <AP-MAC> \"get director\""],"errorCode":"","eventId":"","severity":"Medium","summary":"remote_ap_cli executes an AP CLI command through the controller for one or all connected APs.","rootCause":"Remote AP state sometimes requires direct read-only inspection, but controller policy can overwrite AP-side changes after restart or reconnection.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Target a single AP by MAC and run a documented read-only get command first. Avoid -A unless the command and scale are reviewed. Do not use remote AP CLI for persistent configuration that should be controller-managed.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus ZoneDirector - Remote AP CLI Diagnostics.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: ZoneDirector 10.5.1.\nSource: ruckus_zonedirector_10_5_1_command_line_interface_reference_guide_2026-08-10-08-50-23.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[{"shell":"ZoneDirector Debug CLI","command":"remote_ap_cli -a <AP-MAC> \"get director\"","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ruckus_zonedirector_10_5_1_command_line_interface_reference_guide_2026-08-10-08-50-23.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-ZD","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","ZoneDirector","Access Point","Remote CLI"],"articleCategories":["Networking","Ruckus","ZoneDirector","Access Point","Remote CLI"],"aliases":["zd-remote-ap","ZoneDirector - Remote AP CLI Diagnostics"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56024,"title":"Ruckus ZoneDirector - Save and Restore Configuration","category":"Ruckus","product":"ZoneDirector 10.5.1","tags":["Ruckus","Network Appliance","ZoneDirector","Backup","Restore"],"keywords":["Ruckus ZoneDirector - Save and Restore Configuration","ZoneDirector 10.5.1","ZoneDirector debug commands can save configuration and restore all, failover, or policy scopes.","zd-backup-restore","Ruckus Networks","CommScope","Vistance Networks","ZoneDirector","Backup","Restore","save-config <TFTP-IP> <FILE-NAME>","restore [all | failover | policy]"],"errorCode":"","eventId":"","severity":"High","summary":"ZoneDirector debug commands can save configuration and restore all, failover, or policy scopes.","rootCause":"Recovery or migration may require a known-good configuration, but selecting the wrong scope or image can overwrite critical controller settings.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Use save-config first and verify the file at the approved TFTP destination. Confirm version, controller, restore scope, addressing impact, outage window, and rollback before executing any restore.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus ZoneDirector - Save and Restore Configuration.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: ZoneDirector 10.5.1.\nSource: ruckus_zonedirector_10_5_1_command_line_interface_reference_guide_2026-08-10-08-50-23.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[{"shell":"ZoneDirector Debug CLI","command":"save-config <TFTP-IP> <FILE-NAME>","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"ZoneDirector Debug CLI","command":"restore [all | failover | policy]","risk":"High","safetyLevel":"High Impact"}],"sourceDocument":"ruckus_zonedirector_10_5_1_command_line_interface_reference_guide_2026-08-10-08-50-23.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-ZD","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","ZoneDirector","Backup","Restore"],"articleCategories":["Networking","Ruckus","ZoneDirector","Backup","Restore"],"aliases":["zd-backup-restore","ZoneDirector - Save and Restore Configuration"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56025,"title":"SmartZone 815:upgradeClusterFailed - ruckusSCGUpgradeFailedTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGUpgradeFailedTrap",".1.3.6.1.4.1.25053.2.10.1.3","815:upgradeClusterFailed"],"keywords":["SmartZone 815:upgradeClusterFailed - ruckusSCGUpgradeFailedTrap","SmartZone vSZ-H 7.2.0","Controller cluster upgrade failed.","815","ruckusSCGUpgradeFailedTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGUpgradeFailedTrap",".1.3.6.1.4.1.25053.2.10.1.3","815:upgradeClusterFailed"],"errorCode":"815","eventId":"","severity":"Major","summary":"Controller cluster upgrade failed.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.3, event 815:upgradeClusterFailed, severity Major, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 815:upgradeClusterFailed - ruckusSCGUpgradeFailedTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGUpgradeFailedTrap",".1.3.6.1.4.1.25053.2.10.1.3","815:upgradeClusterFailed"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGUpgradeFailedTrap",".1.3.6.1.4.1.25053.2.10.1.3","815:upgradeClusterFailed"],"aliases":["ruckusSCGUpgradeFailedTrap","SmartZone 815:upgradeClusterFailed - ruckusSCGUpgradeFailedTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56026,"title":"SmartZone 303:apConnectionLost - ruckusSCGAPDisconnectedTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGAPDisconnectedTrap",".1.3.6.1.4.1.25053.2.10.1.23","303:apConnectionLost"],"keywords":["SmartZone 303:apConnectionLost - ruckusSCGAPDisconnectedTrap","SmartZone vSZ-H 7.2.0","An AP connection was lost.","303","ruckusSCGAPDisconnectedTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGAPDisconnectedTrap",".1.3.6.1.4.1.25053.2.10.1.23","303:apConnectionLost"],"errorCode":"303","eventId":"","severity":"Major","summary":"An AP connection was lost.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.23, event 303:apConnectionLost, severity Major, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 303:apConnectionLost - ruckusSCGAPDisconnectedTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGAPDisconnectedTrap",".1.3.6.1.4.1.25053.2.10.1.23","303:apConnectionLost"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGAPDisconnectedTrap",".1.3.6.1.4.1.25053.2.10.1.23","303:apConnectionLost"],"aliases":["ruckusSCGAPDisconnectedTrap","SmartZone 303:apConnectionLost - ruckusSCGAPDisconnectedTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56027,"title":"SmartZone 314:apHeartbeatLost - ruckusSCGAPLostHeartbeatTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGAPLostHeartbeatTrap",".1.3.6.1.4.1.25053.2.10.1.24","314:apHeartbeatLost"],"keywords":["SmartZone 314:apHeartbeatLost - ruckusSCGAPLostHeartbeatTrap","SmartZone vSZ-H 7.2.0","The controller lost the AP heartbeat.","314","ruckusSCGAPLostHeartbeatTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGAPLostHeartbeatTrap",".1.3.6.1.4.1.25053.2.10.1.24","314:apHeartbeatLost"],"errorCode":"314","eventId":"","severity":"Informational","summary":"The controller lost the AP heartbeat.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.24, event 314:apHeartbeatLost, severity Informational, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 314:apHeartbeatLost - ruckusSCGAPLostHeartbeatTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGAPLostHeartbeatTrap",".1.3.6.1.4.1.25053.2.10.1.24","314:apHeartbeatLost"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGAPLostHeartbeatTrap",".1.3.6.1.4.1.25053.2.10.1.24","314:apHeartbeatLost"],"aliases":["ruckusSCGAPLostHeartbeatTrap","SmartZone 314:apHeartbeatLost - ruckusSCGAPLostHeartbeatTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56028,"title":"SmartZone 105:apStatusRejected - ruckusSCGAPRejectedTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGAPRejectedTrap",".1.3.6.1.4.1.25053.2.10.1.28","105:apStatusRejected"],"keywords":["SmartZone 105:apStatusRejected - ruckusSCGAPRejectedTrap","SmartZone vSZ-H 7.2.0","An AP was rejected by the controller.","105","ruckusSCGAPRejectedTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGAPRejectedTrap",".1.3.6.1.4.1.25053.2.10.1.28","105:apStatusRejected"],"errorCode":"105","eventId":"","severity":"Minor","summary":"An AP was rejected by the controller.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.28, event 105:apStatusRejected, severity Minor, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 105:apStatusRejected - ruckusSCGAPRejectedTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGAPRejectedTrap",".1.3.6.1.4.1.25053.2.10.1.28","105:apStatusRejected"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGAPRejectedTrap",".1.3.6.1.4.1.25053.2.10.1.28","105:apStatusRejected"],"aliases":["ruckusSCGAPRejectedTrap","SmartZone 105:apStatusRejected - ruckusSCGAPRejectedTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56029,"title":"SmartZone 111:apConfUpdateFailed - ruckusSCGAPConfUpdateFailedTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGAPConfUpdateFailedTrap",".1.3.6.1.4.1.25053.2.10.1.29","111:apConfUpdateFailed"],"keywords":["SmartZone 111:apConfUpdateFailed - ruckusSCGAPConfUpdateFailedTrap","SmartZone vSZ-H 7.2.0","An AP configuration update failed.","111","ruckusSCGAPConfUpdateFailedTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGAPConfUpdateFailedTrap",".1.3.6.1.4.1.25053.2.10.1.29","111:apConfUpdateFailed"],"errorCode":"111","eventId":"","severity":"Major","summary":"An AP configuration update failed.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.29, event 111:apConfUpdateFailed, severity Major, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 111:apConfUpdateFailed - ruckusSCGAPConfUpdateFailedTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGAPConfUpdateFailedTrap",".1.3.6.1.4.1.25053.2.10.1.29","111:apConfUpdateFailed"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGAPConfUpdateFailedTrap",".1.3.6.1.4.1.25053.2.10.1.29","111:apConfUpdateFailed"],"aliases":["ruckusSCGAPConfUpdateFailedTrap","SmartZone 111:apConfUpdateFailed - ruckusSCGAPConfUpdateFailedTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56030,"title":"SmartZone 102:apDiscoveryFail - ruckusSCGAPDiscoveryFailTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGAPDiscoveryFailTrap",".1.3.6.1.4.1.25053.2.10.1.33","102:apDiscoveryFail"],"keywords":["SmartZone 102:apDiscoveryFail - ruckusSCGAPDiscoveryFailTrap","SmartZone vSZ-H 7.2.0","AP discovery failed.","102","ruckusSCGAPDiscoveryFailTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGAPDiscoveryFailTrap",".1.3.6.1.4.1.25053.2.10.1.33","102:apDiscoveryFail"],"errorCode":"102","eventId":"","severity":"Major","summary":"AP discovery failed.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.33, event 102:apDiscoveryFail, severity Major, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 102:apDiscoveryFail - ruckusSCGAPDiscoveryFailTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGAPDiscoveryFailTrap",".1.3.6.1.4.1.25053.2.10.1.33","102:apDiscoveryFail"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGAPDiscoveryFailTrap",".1.3.6.1.4.1.25053.2.10.1.33","102:apDiscoveryFail"],"aliases":["ruckusSCGAPDiscoveryFailTrap","SmartZone 102:apDiscoveryFail - ruckusSCGAPDiscoveryFailTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56031,"title":"SmartZone 107:apFirmwareUpdateFailed - ruckusSCGAPFirmwareUpdateFailedTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGAPFirmwareUpdateFailedTrap",".1.3.6.1.4.1.25053.2.10.1.34","107:apFirmwareUpdateFailed"],"keywords":["SmartZone 107:apFirmwareUpdateFailed - ruckusSCGAPFirmwareUpdateFailedTrap","SmartZone vSZ-H 7.2.0","An AP firmware update failed.","107","ruckusSCGAPFirmwareUpdateFailedTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGAPFirmwareUpdateFailedTrap",".1.3.6.1.4.1.25053.2.10.1.34","107:apFirmwareUpdateFailed"],"errorCode":"107","eventId":"","severity":"Major","summary":"An AP firmware update failed.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.34, event 107:apFirmwareUpdateFailed, severity Major, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 107:apFirmwareUpdateFailed - ruckusSCGAPFirmwareUpdateFailedTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGAPFirmwareUpdateFailedTrap",".1.3.6.1.4.1.25053.2.10.1.34","107:apFirmwareUpdateFailed"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGAPFirmwareUpdateFailedTrap",".1.3.6.1.4.1.25053.2.10.1.34","107:apFirmwareUpdateFailed"],"aliases":["ruckusSCGAPFirmwareUpdateFailedTrap","SmartZone 107:apFirmwareUpdateFailed - ruckusSCGAPFirmwareUpdateFailedTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56032,"title":"SmartZone 115:apJoinZoneFailed - ruckusSCGAPJoinZoneFailedTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGAPJoinZoneFailedTrap",".1.3.6.1.4.1.25053.2.10.1.40","115:apJoinZoneFailed"],"keywords":["SmartZone 115:apJoinZoneFailed - ruckusSCGAPJoinZoneFailedTrap","SmartZone vSZ-H 7.2.0","An AP failed to join the specified zone.","115","ruckusSCGAPJoinZoneFailedTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGAPJoinZoneFailedTrap",".1.3.6.1.4.1.25053.2.10.1.40","115:apJoinZoneFailed"],"errorCode":"115","eventId":"","severity":"Major","summary":"An AP failed to join the specified zone.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.40, event 115:apJoinZoneFailed, severity Major, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 115:apJoinZoneFailed - ruckusSCGAPJoinZoneFailedTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGAPJoinZoneFailedTrap",".1.3.6.1.4.1.25053.2.10.1.40","115:apJoinZoneFailed"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGAPJoinZoneFailedTrap",".1.3.6.1.4.1.25053.2.10.1.40","115:apJoinZoneFailed"],"aliases":["ruckusSCGAPJoinZoneFailedTrap","SmartZone 115:apJoinZoneFailed - ruckusSCGAPJoinZoneFailedTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56033,"title":"SmartZone 702:apLBSAuthFailed - ruckusSCGAPLBSAuthFailedTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGAPLBSAuthFailedTrap",".1.3.6.1.4.1.25053.2.10.1.57","702:apLBSAuthFailed"],"keywords":["SmartZone 702:apLBSAuthFailed - ruckusSCGAPLBSAuthFailedTrap","SmartZone vSZ-H 7.2.0","AP authentication to the location server failed.","702","ruckusSCGAPLBSAuthFailedTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGAPLBSAuthFailedTrap",".1.3.6.1.4.1.25053.2.10.1.57","702:apLBSAuthFailed"],"errorCode":"702","eventId":"","severity":"Major","summary":"AP authentication to the location server failed.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.57, event 702:apLBSAuthFailed, severity Major, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 702:apLBSAuthFailed - ruckusSCGAPLBSAuthFailedTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGAPLBSAuthFailedTrap",".1.3.6.1.4.1.25053.2.10.1.57","702:apLBSAuthFailed"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGAPLBSAuthFailedTrap",".1.3.6.1.4.1.25053.2.10.1.57","702:apLBSAuthFailed"],"aliases":["ruckusSCGAPLBSAuthFailedTrap","SmartZone 702:apLBSAuthFailed - ruckusSCGAPLBSAuthFailedTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56034,"title":"SmartZone 704:apLBSConnectFailed - ruckusSCGAPLBSConnectFailedTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGAPLBSConnectFailedTrap",".1.3.6.1.4.1.25053.2.10.1.58","704:apLBSConnectFailed"],"keywords":["SmartZone 704:apLBSConnectFailed - ruckusSCGAPLBSConnectFailedTrap","SmartZone vSZ-H 7.2.0","An AP could not connect to the location server.","704","ruckusSCGAPLBSConnectFailedTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGAPLBSConnectFailedTrap",".1.3.6.1.4.1.25053.2.10.1.58","704:apLBSConnectFailed"],"errorCode":"704","eventId":"","severity":"Major","summary":"An AP could not connect to the location server.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.58, event 704:apLBSConnectFailed, severity Major, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 704:apLBSConnectFailed - ruckusSCGAPLBSConnectFailedTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGAPLBSConnectFailedTrap",".1.3.6.1.4.1.25053.2.10.1.58","704:apLBSConnectFailed"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGAPLBSConnectFailedTrap",".1.3.6.1.4.1.25053.2.10.1.58","704:apLBSConnectFailed"],"aliases":["ruckusSCGAPLBSConnectFailedTrap","SmartZone 704:apLBSConnectFailed - ruckusSCGAPLBSConnectFailedTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56035,"title":"SmartZone 609:apBuildTunnelFailed - ruckusSCGAPTunnelBuildFailedTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGAPTunnelBuildFailedTrap",".1.3.6.1.4.1.25053.2.10.1.60","609:apBuildTunnelFailed"],"keywords":["SmartZone 609:apBuildTunnelFailed - ruckusSCGAPTunnelBuildFailedTrap","SmartZone vSZ-H 7.2.0","The AP could not build its data-plane tunnel.","609","ruckusSCGAPTunnelBuildFailedTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGAPTunnelBuildFailedTrap",".1.3.6.1.4.1.25053.2.10.1.60","609:apBuildTunnelFailed"],"errorCode":"609","eventId":"","severity":"Informational","summary":"The AP could not build its data-plane tunnel.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.60, event 609:apBuildTunnelFailed, severity Informational, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 609:apBuildTunnelFailed - ruckusSCGAPTunnelBuildFailedTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGAPTunnelBuildFailedTrap",".1.3.6.1.4.1.25053.2.10.1.60","609:apBuildTunnelFailed"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGAPTunnelBuildFailedTrap",".1.3.6.1.4.1.25053.2.10.1.60","609:apBuildTunnelFailed"],"aliases":["ruckusSCGAPTunnelBuildFailedTrap","SmartZone 609:apBuildTunnelFailed - ruckusSCGAPTunnelBuildFailedTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56036,"title":"SmartZone 610:apTunnelDisconnected - ruckusSCGAPTunnelDisconnectedTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGAPTunnelDisconnectedTrap",".1.3.6.1.4.1.25053.2.10.1.62","610:apTunnelDisconnected"],"keywords":["SmartZone 610:apTunnelDisconnected - ruckusSCGAPTunnelDisconnectedTrap","SmartZone vSZ-H 7.2.0","The AP data-plane tunnel disconnected.","610","ruckusSCGAPTunnelDisconnectedTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGAPTunnelDisconnectedTrap",".1.3.6.1.4.1.25053.2.10.1.62","610:apTunnelDisconnected"],"errorCode":"610","eventId":"","severity":"Informational","summary":"The AP data-plane tunnel disconnected.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.62, event 610:apTunnelDisconnected, severity Informational, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 610:apTunnelDisconnected - ruckusSCGAPTunnelDisconnectedTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGAPTunnelDisconnectedTrap",".1.3.6.1.4.1.25053.2.10.1.62","610:apTunnelDisconnected"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGAPTunnelDisconnectedTrap",".1.3.6.1.4.1.25053.2.10.1.62","610:apTunnelDisconnected"],"aliases":["ruckusSCGAPTunnelDisconnectedTrap","SmartZone 610:apTunnelDisconnected - ruckusSCGAPTunnelDisconnectedTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56037,"title":"SmartZone 513:dpDisconnected - ruckusSCGDPDisconnectedTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGDPDisconnectedTrap",".1.3.6.1.4.1.25053.2.10.1.72","513:dpDisconnected"],"keywords":["SmartZone 513:dpDisconnected - ruckusSCGDPDisconnectedTrap","SmartZone vSZ-H 7.2.0","A data-plane component disconnected.","513","ruckusSCGDPDisconnectedTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGDPDisconnectedTrap",".1.3.6.1.4.1.25053.2.10.1.72","513:dpDisconnected"],"errorCode":"513","eventId":"","severity":"Critical","summary":"A data-plane component disconnected.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.72, event 513:dpDisconnected, severity Critical, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 513:dpDisconnected - ruckusSCGDPDisconnectedTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGDPDisconnectedTrap",".1.3.6.1.4.1.25053.2.10.1.72","513:dpDisconnected"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGDPDisconnectedTrap",".1.3.6.1.4.1.25053.2.10.1.72","513:dpDisconnected"],"aliases":["ruckusSCGDPDisconnectedTrap","SmartZone 513:dpDisconnected - ruckusSCGDPDisconnectedTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56038,"title":"SmartZone 514:dpPhyInterfaceDown - ruckusSCGDPPhyInterfaceDownTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGDPPhyInterfaceDownTrap",".1.3.6.1.4.1.25053.2.10.1.73","514:dpPhyInterfaceDown"],"keywords":["SmartZone 514:dpPhyInterfaceDown - ruckusSCGDPPhyInterfaceDownTrap","SmartZone vSZ-H 7.2.0","A data-plane physical interface is down.","514","ruckusSCGDPPhyInterfaceDownTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGDPPhyInterfaceDownTrap",".1.3.6.1.4.1.25053.2.10.1.73","514:dpPhyInterfaceDown"],"errorCode":"514","eventId":"","severity":"Critical","summary":"A data-plane physical interface is down.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.73, event 514:dpPhyInterfaceDown, severity Critical, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 514:dpPhyInterfaceDown - ruckusSCGDPPhyInterfaceDownTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGDPPhyInterfaceDownTrap",".1.3.6.1.4.1.25053.2.10.1.73","514:dpPhyInterfaceDown"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGDPPhyInterfaceDownTrap",".1.3.6.1.4.1.25053.2.10.1.73","514:dpPhyInterfaceDown"],"aliases":["ruckusSCGDPPhyInterfaceDownTrap","SmartZone 514:dpPhyInterfaceDown - ruckusSCGDPPhyInterfaceDownTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56039,"title":"SmartZone 517:dpPktPoolCriticalLow - ruckusSCGDPPktPoolCriticalLowTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGDPPktPoolCriticalLowTrap",".1.3.6.1.4.1.25053.2.10.1.91","517:dpPktPoolCriticalLow"],"keywords":["SmartZone 517:dpPktPoolCriticalLow - ruckusSCGDPPktPoolCriticalLowTrap","SmartZone vSZ-H 7.2.0","The data-core packet pool crossed its critical low-water mark.","517","ruckusSCGDPPktPoolCriticalLowTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGDPPktPoolCriticalLowTrap",".1.3.6.1.4.1.25053.2.10.1.91","517:dpPktPoolCriticalLow"],"errorCode":"517","eventId":"","severity":"Major","summary":"The data-core packet pool crossed its critical low-water mark.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.91, event 517:dpPktPoolCriticalLow, severity Major, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 517:dpPktPoolCriticalLow - ruckusSCGDPPktPoolCriticalLowTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGDPPktPoolCriticalLowTrap",".1.3.6.1.4.1.25053.2.10.1.91","517:dpPktPoolCriticalLow"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGDPPktPoolCriticalLowTrap",".1.3.6.1.4.1.25053.2.10.1.91","517:dpPktPoolCriticalLow"],"aliases":["ruckusSCGDPPktPoolCriticalLowTrap","SmartZone 517:dpPktPoolCriticalLow - ruckusSCGDPPktPoolCriticalLowTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56040,"title":"SmartZone 519:dpCoreDead - ruckusSCGDPCoreDeadTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGDPCoreDeadTrap",".1.3.6.1.4.1.25053.2.10.1.93","519:dpCoreDead"],"keywords":["SmartZone 519:dpCoreDead - ruckusSCGDPCoreDeadTrap","SmartZone vSZ-H 7.2.0","A data-plane core was detected as dead.","519","ruckusSCGDPCoreDeadTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGDPCoreDeadTrap",".1.3.6.1.4.1.25053.2.10.1.93","519:dpCoreDead"],"errorCode":"519","eventId":"","severity":"Critical","summary":"A data-plane core was detected as dead.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.93, event 519:dpCoreDead, severity Critical, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 519:dpCoreDead - ruckusSCGDPCoreDeadTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGDPCoreDeadTrap",".1.3.6.1.4.1.25053.2.10.1.93","519:dpCoreDead"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGDPCoreDeadTrap",".1.3.6.1.4.1.25053.2.10.1.93","519:dpCoreDead"],"aliases":["ruckusSCGDPCoreDeadTrap","SmartZone 519:dpCoreDead - ruckusSCGDPCoreDeadTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56041,"title":"SmartZone 553:dpUpgradeFailed - ruckusSCGDPUpgradeFailedTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGDPUpgradeFailedTrap",".1.3.6.1.4.1.25053.2.10.1.98","553:dpUpgradeFailed"],"keywords":["SmartZone 553:dpUpgradeFailed - ruckusSCGDPUpgradeFailedTrap","SmartZone vSZ-H 7.2.0","A data-plane upgrade failed.","553","ruckusSCGDPUpgradeFailedTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGDPUpgradeFailedTrap",".1.3.6.1.4.1.25053.2.10.1.98","553:dpUpgradeFailed"],"errorCode":"553","eventId":"","severity":"Major","summary":"A data-plane upgrade failed.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.98, event 553:dpUpgradeFailed, severity Major, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 553:dpUpgradeFailed - ruckusSCGDPUpgradeFailedTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGDPUpgradeFailedTrap",".1.3.6.1.4.1.25053.2.10.1.98","553:dpUpgradeFailed"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGDPUpgradeFailedTrap",".1.3.6.1.4.1.25053.2.10.1.98","553:dpUpgradeFailed"],"aliases":["ruckusSCGDPUpgradeFailedTrap","SmartZone 553:dpUpgradeFailed - ruckusSCGDPUpgradeFailedTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56042,"title":"SmartZone 803:newNodeJoinFailed - ruckusSCGNodeJoinFailedTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGNodeJoinFailedTrap",".1.3.6.1.4.1.25053.2.10.1.200","803:newNodeJoinFailed"],"keywords":["SmartZone 803:newNodeJoinFailed - ruckusSCGNodeJoinFailedTrap","SmartZone vSZ-H 7.2.0","A new controller node failed to join the cluster.","803","ruckusSCGNodeJoinFailedTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGNodeJoinFailedTrap",".1.3.6.1.4.1.25053.2.10.1.200","803:newNodeJoinFailed"],"errorCode":"803","eventId":"","severity":"Critical","summary":"A new controller node failed to join the cluster.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.200, event 803:newNodeJoinFailed, severity Critical, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 803:newNodeJoinFailed - ruckusSCGNodeJoinFailedTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGNodeJoinFailedTrap",".1.3.6.1.4.1.25053.2.10.1.200","803:newNodeJoinFailed"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGNodeJoinFailedTrap",".1.3.6.1.4.1.25053.2.10.1.200","803:newNodeJoinFailed"],"aliases":["ruckusSCGNodeJoinFailedTrap","SmartZone 803:newNodeJoinFailed - ruckusSCGNodeJoinFailedTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56043,"title":"SmartZone 805:removeNodeFailed - ruckusSCGNodeRemoveFailedTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGNodeRemoveFailedTrap",".1.3.6.1.4.1.25053.2.10.1.201","805:removeNodeFailed"],"keywords":["SmartZone 805:removeNodeFailed - ruckusSCGNodeRemoveFailedTrap","SmartZone vSZ-H 7.2.0","Removal of a controller node failed.","805","ruckusSCGNodeRemoveFailedTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGNodeRemoveFailedTrap",".1.3.6.1.4.1.25053.2.10.1.201","805:removeNodeFailed"],"errorCode":"805","eventId":"","severity":"Major","summary":"Removal of a controller node failed.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.201, event 805:removeNodeFailed, severity Major, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 805:removeNodeFailed - ruckusSCGNodeRemoveFailedTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGNodeRemoveFailedTrap",".1.3.6.1.4.1.25053.2.10.1.201","805:removeNodeFailed"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGNodeRemoveFailedTrap",".1.3.6.1.4.1.25053.2.10.1.201","805:removeNodeFailed"],"aliases":["ruckusSCGNodeRemoveFailedTrap","SmartZone 805:removeNodeFailed - ruckusSCGNodeRemoveFailedTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56044,"title":"SmartZone 806:nodeOutOfService - ruckusSCGNodeOutOfServiceTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGNodeOutOfServiceTrap",".1.3.6.1.4.1.25053.2.10.1.202","806:nodeOutOfService"],"keywords":["SmartZone 806:nodeOutOfService - ruckusSCGNodeOutOfServiceTrap","SmartZone vSZ-H 7.2.0","A controller node is out of service.","806","ruckusSCGNodeOutOfServiceTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGNodeOutOfServiceTrap",".1.3.6.1.4.1.25053.2.10.1.202","806:nodeOutOfService"],"errorCode":"806","eventId":"","severity":"Critical","summary":"A controller node is out of service.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.202, event 806:nodeOutOfService, severity Critical, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 806:nodeOutOfService - ruckusSCGNodeOutOfServiceTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGNodeOutOfServiceTrap",".1.3.6.1.4.1.25053.2.10.1.202","806:nodeOutOfService"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGNodeOutOfServiceTrap",".1.3.6.1.4.1.25053.2.10.1.202","806:nodeOutOfService"],"aliases":["ruckusSCGNodeOutOfServiceTrap","SmartZone 806:nodeOutOfService - ruckusSCGNodeOutOfServiceTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56045,"title":"SmartZone 810:backupClusterFailed - ruckusSCGClusterBackupFailedTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGClusterBackupFailedTrap",".1.3.6.1.4.1.25053.2.10.1.204","810:backupClusterFailed"],"keywords":["SmartZone 810:backupClusterFailed - ruckusSCGClusterBackupFailedTrap","SmartZone vSZ-H 7.2.0","Cluster backup creation failed.","810","ruckusSCGClusterBackupFailedTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGClusterBackupFailedTrap",".1.3.6.1.4.1.25053.2.10.1.204","810:backupClusterFailed"],"errorCode":"810","eventId":"","severity":"Major","summary":"Cluster backup creation failed.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.204, event 810:backupClusterFailed, severity Major, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 810:backupClusterFailed - ruckusSCGClusterBackupFailedTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGClusterBackupFailedTrap",".1.3.6.1.4.1.25053.2.10.1.204","810:backupClusterFailed"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGClusterBackupFailedTrap",".1.3.6.1.4.1.25053.2.10.1.204","810:backupClusterFailed"],"aliases":["ruckusSCGClusterBackupFailedTrap","SmartZone 810:backupClusterFailed - ruckusSCGClusterBackupFailedTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56046,"title":"SmartZone 812:restoreClusterFailed - ruckusSCGClusterRestoreFailedTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGClusterRestoreFailedTrap",".1.3.6.1.4.1.25053.2.10.1.205","812:restoreClusterFailed"],"keywords":["SmartZone 812:restoreClusterFailed - ruckusSCGClusterRestoreFailedTrap","SmartZone vSZ-H 7.2.0","Cluster backup restoration failed.","812","ruckusSCGClusterRestoreFailedTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGClusterRestoreFailedTrap",".1.3.6.1.4.1.25053.2.10.1.205","812:restoreClusterFailed"],"errorCode":"812","eventId":"","severity":"Major","summary":"Cluster backup restoration failed.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.205, event 812:restoreClusterFailed, severity Major, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 812:restoreClusterFailed - ruckusSCGClusterRestoreFailedTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGClusterRestoreFailedTrap",".1.3.6.1.4.1.25053.2.10.1.205","812:restoreClusterFailed"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGClusterRestoreFailedTrap",".1.3.6.1.4.1.25053.2.10.1.205","812:restoreClusterFailed"],"aliases":["ruckusSCGClusterRestoreFailedTrap","SmartZone 812:restoreClusterFailed - ruckusSCGClusterRestoreFailedTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56047,"title":"SmartZone 816:clusterAppStop - ruckusSCGClusterAppStoppedTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGClusterAppStoppedTrap",".1.3.6.1.4.1.25053.2.10.1.206","816:clusterAppStop"],"keywords":["SmartZone 816:clusterAppStop - ruckusSCGClusterAppStoppedTrap","SmartZone vSZ-H 7.2.0","A controller cluster application stopped.","816","ruckusSCGClusterAppStoppedTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGClusterAppStoppedTrap",".1.3.6.1.4.1.25053.2.10.1.206","816:clusterAppStop"],"errorCode":"816","eventId":"","severity":"Critical","summary":"A controller cluster application stopped.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.206, event 816:clusterAppStop, severity Critical, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 816:clusterAppStop - ruckusSCGClusterAppStoppedTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGClusterAppStoppedTrap",".1.3.6.1.4.1.25053.2.10.1.206","816:clusterAppStop"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGClusterAppStoppedTrap",".1.3.6.1.4.1.25053.2.10.1.206","816:clusterAppStop"],"aliases":["ruckusSCGClusterAppStoppedTrap","SmartZone 816:clusterAppStop - ruckusSCGClusterAppStoppedTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56048,"title":"SmartZone 821:nodeBondInterfaceDown - ruckusSCGNodeBondInterfaceDownTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGNodeBondInterfaceDownTrap",".1.3.6.1.4.1.25053.2.10.1.207","821:nodeBondInterfaceDown"],"keywords":["SmartZone 821:nodeBondInterfaceDown - ruckusSCGNodeBondInterfaceDownTrap","SmartZone vSZ-H 7.2.0","A controller node bond interface is down.","821","ruckusSCGNodeBondInterfaceDownTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGNodeBondInterfaceDownTrap",".1.3.6.1.4.1.25053.2.10.1.207","821:nodeBondInterfaceDown"],"errorCode":"821","eventId":"","severity":"Major","summary":"A controller node bond interface is down.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.207, event 821:nodeBondInterfaceDown, severity Major, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 821:nodeBondInterfaceDown - ruckusSCGNodeBondInterfaceDownTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGNodeBondInterfaceDownTrap",".1.3.6.1.4.1.25053.2.10.1.207","821:nodeBondInterfaceDown"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGNodeBondInterfaceDownTrap",".1.3.6.1.4.1.25053.2.10.1.207","821:nodeBondInterfaceDown"],"aliases":["ruckusSCGNodeBondInterfaceDownTrap","SmartZone 821:nodeBondInterfaceDown - ruckusSCGNodeBondInterfaceDownTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56049,"title":"SmartZone 824:nodePhyInterfaceDown - ruckusSCGNodePhyInterfaceDownTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGNodePhyInterfaceDownTrap",".1.3.6.1.4.1.25053.2.10.1.208","824:nodePhyInterfaceDown"],"keywords":["SmartZone 824:nodePhyInterfaceDown - ruckusSCGNodePhyInterfaceDownTrap","SmartZone vSZ-H 7.2.0","A controller node physical interface is down.","824","ruckusSCGNodePhyInterfaceDownTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGNodePhyInterfaceDownTrap",".1.3.6.1.4.1.25053.2.10.1.208","824:nodePhyInterfaceDown"],"errorCode":"824","eventId":"","severity":"Critical","summary":"A controller node physical interface is down.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.208, event 824:nodePhyInterfaceDown, severity Critical, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 824:nodePhyInterfaceDown - ruckusSCGNodePhyInterfaceDownTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGNodePhyInterfaceDownTrap",".1.3.6.1.4.1.25053.2.10.1.208","824:nodePhyInterfaceDown"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGNodePhyInterfaceDownTrap",".1.3.6.1.4.1.25053.2.10.1.208","824:nodePhyInterfaceDown"],"aliases":["ruckusSCGNodePhyInterfaceDownTrap","SmartZone 824:nodePhyInterfaceDown - ruckusSCGNodePhyInterfaceDownTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56050,"title":"SmartZone 862:clusterCfgBackupFailed - ruckusSCGClusterCfgBackupFailedTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGClusterCfgBackupFailedTrap",".1.3.6.1.4.1.25053.2.10.1.226","862:clusterCfgBackupFailed"],"keywords":["SmartZone 862:clusterCfgBackupFailed - ruckusSCGClusterCfgBackupFailedTrap","SmartZone vSZ-H 7.2.0","A configuration backup failed.","862","ruckusSCGClusterCfgBackupFailedTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGClusterCfgBackupFailedTrap",".1.3.6.1.4.1.25053.2.10.1.226","862:clusterCfgBackupFailed"],"errorCode":"862","eventId":"","severity":"Major","summary":"A configuration backup failed.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.226, event 862:clusterCfgBackupFailed, severity Major, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 862:clusterCfgBackupFailed - ruckusSCGClusterCfgBackupFailedTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGClusterCfgBackupFailedTrap",".1.3.6.1.4.1.25053.2.10.1.226","862:clusterCfgBackupFailed"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGClusterCfgBackupFailedTrap",".1.3.6.1.4.1.25053.2.10.1.226","862:clusterCfgBackupFailed"],"aliases":["ruckusSCGClusterCfgBackupFailedTrap","SmartZone 862:clusterCfgBackupFailed - ruckusSCGClusterCfgBackupFailedTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56051,"title":"SmartZone 864:clusterCfgRestoreFailed - ruckusSCGClusterCfgRestoreFailedTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGClusterCfgRestoreFailedTrap",".1.3.6.1.4.1.25053.2.10.1.228","864:clusterCfgRestoreFailed"],"keywords":["SmartZone 864:clusterCfgRestoreFailed - ruckusSCGClusterCfgRestoreFailedTrap","SmartZone vSZ-H 7.2.0","A configuration restoration failed.","864","ruckusSCGClusterCfgRestoreFailedTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGClusterCfgRestoreFailedTrap",".1.3.6.1.4.1.25053.2.10.1.228","864:clusterCfgRestoreFailed"],"errorCode":"864","eventId":"","severity":"Major","summary":"A configuration restoration failed.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.228, event 864:clusterCfgRestoreFailed, severity Major, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 864:clusterCfgRestoreFailed - ruckusSCGClusterCfgRestoreFailedTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGClusterCfgRestoreFailedTrap",".1.3.6.1.4.1.25053.2.10.1.228","864:clusterCfgRestoreFailed"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGClusterCfgRestoreFailedTrap",".1.3.6.1.4.1.25053.2.10.1.228","864:clusterCfgRestoreFailed"],"aliases":["ruckusSCGClusterCfgRestoreFailedTrap","SmartZone 864:clusterCfgRestoreFailed - ruckusSCGClusterCfgRestoreFailedTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56052,"title":"SmartZone 832:uploadClusterFailed - ruckusSCGClusterUploadFailedTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGClusterUploadFailedTrap",".1.3.6.1.4.1.25053.2.10.1.230","832:uploadClusterFailed"],"keywords":["SmartZone 832:uploadClusterFailed - ruckusSCGClusterUploadFailedTrap","SmartZone vSZ-H 7.2.0","A cluster upload failed.","832","ruckusSCGClusterUploadFailedTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGClusterUploadFailedTrap",".1.3.6.1.4.1.25053.2.10.1.230","832:uploadClusterFailed"],"errorCode":"832","eventId":"","severity":"Major","summary":"A cluster upload failed.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.230, event 832:uploadClusterFailed, severity Major, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 832:uploadClusterFailed - ruckusSCGClusterUploadFailedTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGClusterUploadFailedTrap",".1.3.6.1.4.1.25053.2.10.1.230","832:uploadClusterFailed"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGClusterUploadFailedTrap",".1.3.6.1.4.1.25053.2.10.1.230","832:uploadClusterFailed"],"aliases":["ruckusSCGClusterUploadFailedTrap","SmartZone 832:uploadClusterFailed - ruckusSCGClusterUploadFailedTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56053,"title":"SmartZone 843:clusterOutOfService - ruckusSCGClusterOutOfServiceTrap","category":"Ruckus","product":"SmartZone vSZ-H 7.2.0","tags":["Ruckus","Network Appliance","SmartZone","SNMP","Trap","ruckusSCGClusterOutOfServiceTrap",".1.3.6.1.4.1.25053.2.10.1.231","843:clusterOutOfService"],"keywords":["SmartZone 843:clusterOutOfService - ruckusSCGClusterOutOfServiceTrap","SmartZone vSZ-H 7.2.0","The cluster is out of service.","843","ruckusSCGClusterOutOfServiceTrap","Ruckus Networks","CommScope","Vistance Networks","SmartZone","SNMP","Trap","ruckusSCGClusterOutOfServiceTrap",".1.3.6.1.4.1.25053.2.10.1.231","843:clusterOutOfService"],"errorCode":"843","eventId":"","severity":"Critical","summary":"The cluster is out of service.","rootCause":"The trap reports a SmartZone event; its bindings, event description, affected object, topology, and surrounding controller logs are required to determine the underlying cause.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Decode the trap with the RUCKUS-EVENT-MIB. Correlate OID .1.3.6.1.4.1.25053.2.10.1.231, event 843:clusterOutOfService, severity Critical, affected node/AP/data-plane identifiers, reason binding, and timestamp. Check for the documented clearing trap and validate service rather than clearing the alarm manually.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified SmartZone 843:clusterOutOfService - ruckusSCGClusterOutOfServiceTrap.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: SmartZone vSZ-H 7.2.0.\nSource: ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_smartzone_(lt-ga)_snmp_reference_guide_(vsz-h),_7_2_0_2026-08-10-08-47-16.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-SMARTZONE-SNMP","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","SmartZone","SNMP","Trap","ruckusSCGClusterOutOfServiceTrap",".1.3.6.1.4.1.25053.2.10.1.231","843:clusterOutOfService"],"articleCategories":["Networking","Ruckus","SmartZone","SNMP","Trap","ruckusSCGClusterOutOfServiceTrap",".1.3.6.1.4.1.25053.2.10.1.231","843:clusterOutOfService"],"aliases":["ruckusSCGClusterOutOfServiceTrap","SmartZone 843:clusterOutOfService - ruckusSCGClusterOutOfServiceTrap"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56054,"title":"Ruckus WAN Gateway CVE-2025-26465 - OpenSSH Client Host Verification Error","category":"Ruckus","product":"Ruckus WAN Gateway Build 16.048","tags":["Ruckus","Network Appliance","WAN Gateway","Release Fix","Upgrade"],"keywords":["Ruckus WAN Gateway CVE-2025-26465 - OpenSSH Client Host Verification Error","Ruckus WAN Gateway Build 16.048","An on-path attacker could impersonate a server under documented conditions when VerifyHostKeyDNS is enabled.","CVE-2025-26465","CVE-2025-26465","Ruckus Networks","CommScope","Vistance Networks","WAN Gateway","Release Fix","Upgrade"],"errorCode":"CVE-2025-26465","eventId":"","severity":"Critical","summary":"An on-path attacker could impersonate a server under documented conditions when VerifyHostKeyDNS is enabled.","rootCause":"An on-path attacker could impersonate a server under documented conditions when VerifyHostKeyDNS is enabled.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Update to a Ruckus WAN Gateway build containing the FreeBSD/OpenSSH security update, then verify the installed daemon version and SSH policy.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus WAN Gateway CVE-2025-26465 - OpenSSH Client Host Verification Error.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: Ruckus WAN Gateway Build 16.048.\nSource: ruckus_wan_gateway_build_16_048_release_notes_2026-08-10-08-53-51.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_wan_gateway_build_16_048_release_notes_2026-08-10-08-53-51.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-WAN-GATEWAY","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","WAN Gateway","Release Fix","Upgrade"],"articleCategories":["Networking","Ruckus","WAN Gateway","Release Fix","Upgrade"],"aliases":["CVE-2025-26465","WAN Gateway CVE-2025-26465 - OpenSSH Client Host Verification Error"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56055,"title":"Ruckus WAN Gateway CVE-2025-26466 - OpenSSH SSH2_MSG_PING Denial of Service","category":"Ruckus","product":"Ruckus WAN Gateway Build 16.048","tags":["Ruckus","Network Appliance","WAN Gateway","Release Fix","Upgrade"],"keywords":["Ruckus WAN Gateway CVE-2025-26466 - OpenSSH SSH2_MSG_PING Denial of Service","Ruckus WAN Gateway Build 16.048","OpenSSH client and server resource exhaustion can occur while handling SSH2_MSG_PING packets.","CVE-2025-26466","CVE-2025-26466","Ruckus Networks","CommScope","Vistance Networks","WAN Gateway","Release Fix","Upgrade"],"errorCode":"CVE-2025-26466","eventId":"","severity":"Critical","summary":"OpenSSH client and server resource exhaustion can occur while handling SSH2_MSG_PING packets.","rootCause":"OpenSSH client and server resource exhaustion can occur while handling SSH2_MSG_PING packets.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Update to a fixed Ruckus WAN Gateway build and monitor SSH exposure and resource use.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus WAN Gateway CVE-2025-26466 - OpenSSH SSH2_MSG_PING Denial of Service.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: Ruckus WAN Gateway Build 16.048.\nSource: ruckus_wan_gateway_build_16_048_release_notes_2026-08-10-08-53-51.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_wan_gateway_build_16_048_release_notes_2026-08-10-08-53-51.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-WAN-GATEWAY","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","WAN Gateway","Release Fix","Upgrade"],"articleCategories":["Networking","Ruckus","WAN Gateway","Release Fix","Upgrade"],"aliases":["CVE-2025-26466","WAN Gateway CVE-2025-26466 - OpenSSH SSH2_MSG_PING Denial of Service"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56056,"title":"Ruckus WAN Gateway 16.039 - Remote URL Request Property File Retrieval Failure","category":"Ruckus","product":"Ruckus WAN Gateway Build 16.048","tags":["Ruckus","Network Appliance","WAN Gateway","Release Fix","Upgrade"],"keywords":["Ruckus WAN Gateway 16.039 - Remote URL Request Property File Retrieval Failure","Ruckus WAN Gateway Build 16.048","Models using Request Properties could fail to retrieve files from a remote URL, including configuration templates.","16.039","16.039","Ruckus Networks","CommScope","Vistance Networks","WAN Gateway","Release Fix","Upgrade"],"errorCode":"16.039","eventId":"","severity":"High","summary":"Models using Request Properties could fail to retrieve files from a remote URL, including configuration templates.","rootCause":"Models using Request Properties could fail to retrieve files from a remote URL, including configuration templates.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Upgrade to Build 16.048 or a later approved build, then re-test the remote URL, CA trust, authorization, and template retrieval.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus WAN Gateway 16.039 - Remote URL Request Property File Retrieval Failure.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: Ruckus WAN Gateway Build 16.048.\nSource: ruckus_wan_gateway_build_16_048_release_notes_2026-08-10-08-53-51.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_wan_gateway_build_16_048_release_notes_2026-08-10-08-53-51.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-WAN-GATEWAY","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","WAN Gateway","Release Fix","Upgrade"],"articleCategories":["Networking","Ruckus","WAN Gateway","Release Fix","Upgrade"],"aliases":["16.039","WAN Gateway 16.039 - Remote URL Request Property File Retrieval Failure"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56057,"title":"Ruckus WAN Gateway 16.041 - Sub-Account Creation Failure","category":"Ruckus","product":"Ruckus WAN Gateway Build 16.048","tags":["Ruckus","Network Appliance","WAN Gateway","Release Fix","Upgrade"],"keywords":["Ruckus WAN Gateway 16.041 - Sub-Account Creation Failure","Ruckus WAN Gateway Build 16.048","A software defect prevented creation of sub-accounts.","16.041","16.041","Ruckus Networks","CommScope","Vistance Networks","WAN Gateway","Release Fix","Upgrade"],"errorCode":"16.041","eventId":"","severity":"High","summary":"A software defect prevented creation of sub-accounts.","rootCause":"A software defect prevented creation of sub-accounts.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Upgrade to Build 16.048 or later and retry with an authorized account.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus WAN Gateway 16.041 - Sub-Account Creation Failure.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: Ruckus WAN Gateway Build 16.048.\nSource: ruckus_wan_gateway_build_16_048_release_notes_2026-08-10-08-53-51.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_wan_gateway_build_16_048_release_notes_2026-08-10-08-53-51.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-WAN-GATEWAY","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","WAN Gateway","Release Fix","Upgrade"],"articleCategories":["Networking","Ruckus","WAN Gateway","Release Fix","Upgrade"],"aliases":["16.041","WAN Gateway 16.041 - Sub-Account Creation Failure"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56058,"title":"Ruckus WAN Gateway 16.042 - SSEd Timeout During RWG Upgrade","category":"Ruckus","product":"Ruckus WAN Gateway Build 16.048","tags":["Ruckus","Network Appliance","WAN Gateway","Release Fix","Upgrade"],"keywords":["Ruckus WAN Gateway 16.042 - SSEd Timeout During RWG Upgrade","Ruckus WAN Gateway Build 16.048","SSEd timeout handling could fail during an rxg upgrade.","16.042","16.042","Ruckus Networks","CommScope","Vistance Networks","WAN Gateway","Release Fix","Upgrade"],"errorCode":"16.042","eventId":"","severity":"High","summary":"SSEd timeout handling could fail during an rxg upgrade.","rootCause":"SSEd timeout handling could fail during an rxg upgrade.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Upgrade using the fixed build in an approved window and preserve upgrade logs.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus WAN Gateway 16.042 - SSEd Timeout During RWG Upgrade.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: Ruckus WAN Gateway Build 16.048.\nSource: ruckus_wan_gateway_build_16_048_release_notes_2026-08-10-08-53-51.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_wan_gateway_build_16_048_release_notes_2026-08-10-08-53-51.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-WAN-GATEWAY","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","WAN Gateway","Release Fix","Upgrade"],"articleCategories":["Networking","Ruckus","WAN Gateway","Release Fix","Upgrade"],"aliases":["16.042","WAN Gateway 16.042 - SSEd Timeout During RWG Upgrade"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56059,"title":"Ruckus WAN Gateway 16.043 - Restore Log Streaming and rxgd Stopped","category":"Ruckus","product":"Ruckus WAN Gateway Build 16.048","tags":["Ruckus","Network Appliance","WAN Gateway","Release Fix","Upgrade"],"keywords":["Ruckus WAN Gateway 16.043 - Restore Log Streaming and rxgd Stopped","Ruckus WAN Gateway Build 16.048","Restore logging and the interface-remap dialog could fail to appear after hardware changed, leaving rxgd stopped without a front-end update.","16.043","16.043","Ruckus Networks","CommScope","Vistance Networks","WAN Gateway","Release Fix","Upgrade"],"errorCode":"16.043","eventId":"","severity":"High","summary":"Restore logging and the interface-remap dialog could fail to appear after hardware changed, leaving rxgd stopped without a front-end update.","rootCause":"Restore logging and the interface-remap dialog could fail to appear after hardware changed, leaving rxgd stopped without a front-end update.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Use Build 16.048 or later, capture restore and service logs, complete required interface remapping, and verify rxgd and the UI.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus WAN Gateway 16.043 - Restore Log Streaming and rxgd Stopped.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: Ruckus WAN Gateway Build 16.048.\nSource: ruckus_wan_gateway_build_16_048_release_notes_2026-08-10-08-53-51.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_wan_gateway_build_16_048_release_notes_2026-08-10-08-53-51.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-WAN-GATEWAY","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","WAN Gateway","Release Fix","Upgrade"],"articleCategories":["Networking","Ruckus","WAN Gateway","Release Fix","Upgrade"],"aliases":["16.043","WAN Gateway 16.043 - Restore Log Streaming and rxgd Stopped"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":56060,"title":"Ruckus WAN Gateway 16.044 - Missing CA Root Certificates During Upgrade","category":"Ruckus","product":"Ruckus WAN Gateway Build 16.048","tags":["Ruckus","Network Appliance","WAN Gateway","Release Fix","Upgrade"],"keywords":["Ruckus WAN Gateway 16.044 - Missing CA Root Certificates During Upgrade","Ruckus WAN Gateway Build 16.048","Upgrade handling of missing root CA certificates and factory-reset root CA symlinks was defective.","16.044","16.044","Ruckus Networks","CommScope","Vistance Networks","WAN Gateway","Release Fix","Upgrade"],"errorCode":"16.044","eventId":"","severity":"High","summary":"Upgrade handling of missing root CA certificates and factory-reset root CA symlinks was defective.","rootCause":"Upgrade handling of missing root CA certificates and factory-reset root CA symlinks was defective.","resolution":"1. Record the appliance, model, software build, affected site or object, timestamp, and complete sanitized message.\n2. Upgrade to the fixed build, verify the approved CA bundle and symlinks, and never substitute private keys for root certificates.\n3. Start with read-only evidence and compare the live command help or UI with documentation for the installed release.\n4. Review dependencies, management-path impact, backup, approval, and rollback before changing configuration.\n5. Validate the original operation and monitor matching logs, alarms, or traps.","emailScript":"Hello,\n\nWe reviewed the Ruckus issue and identified Ruckus WAN Gateway 16.044 - Missing CA Root Certificates During Upgrade.\n\nWe are validating the current appliance state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, approximate time, device or site name, and what stopped working. Do not share passwords, license keys, SNMP secrets, API tokens, private keys, or an unredacted configuration.","notes":"Product/version scope: Ruckus WAN Gateway Build 16.048.\nSource: ruckus_wan_gateway_build_16_048_release_notes_2026-08-10-08-53-51.pdf.\n\nCommands and menus can differ by model, license, role, topology, and software build. Placeholders must be replaced deliberately. Debug capture can expose client, network, and credential-adjacent data; sanitize before sharing.","commands":[],"sourceDocument":"ruckus_wan_gateway_build_16_048_release_notes_2026-08-10-08-53-51.pdf","sourceAuthority":"Ruckus Networks / Vistance Networks","namespace":"RUCKUS-WAN-GATEWAY","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ruckus Networks","Vistance Networks"],"technologies":["Networking","WAN Gateway","Release Fix","Upgrade"],"articleCategories":["Networking","Ruckus","WAN Gateway","Release Fix","Upgrade"],"aliases":["16.044","WAN Gateway 16.044 - Missing CA Root Certificates During Upgrade"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":57000,"title":"Adtran AOS - %Ambiguous command","category":"Adtran","product":"Adtran AOS R10.1.0 / NetVanta / Total Access 900","tags":["Adtran","AOS","Network Appliance","CLI Error","Parser"],"keywords":["Adtran AOS - %Ambiguous command","AOS could match the abbreviated entry to more than one command.","%Ambiguous command","Adtran","ADTRAN Operating System","AOS R10.1.0","NetVanta","Total Access 900","CLI Error","Parser","?"],"errorCode":"%Ambiguous command","eventId":"","severity":"Low","summary":"AOS could match the abbreviated entry to more than one command.","rootCause":"The entry is too short to identify one command uniquely, or it is not valid in the current command mode.","resolution":"1. Record the complete prompt, command mode, command, caret position or response, device model, AOS version, and timestamp.\n2. Enter ? to list valid completions, type enough characters to make the command unique, and confirm the current mode before retrying.\n3. Use ? at the exact prompt and compare live help with the command reference for the installed release.\n4. Start with read-only show commands; review configuration, management-path impact, backup, approval, and rollback before mutation.\n5. Validate the original service and preserve sanitized evidence.","emailScript":"Hello,\n\nWe reviewed the Adtran network issue and identified Adtran AOS - %Ambiguous command.\n\nWe are validating the device model, software release, current state, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, device name, affected service, approximate time, and what changed. Do not share passwords, SNMP community strings, RADIUS secrets, VPN keys, certificates, packet captures, or an unredacted configuration.","notes":"Version scope: AOS R10.1.0 command reference, June 2012 (legacy). The supplied copy was archived through ManualsLib; current product documentation should be checked at https://docs.adtran.com/all-documentation before making a change.\n\nAOS is used across multiple Adtran NetVanta and Total Access 900 products, but commands vary by model, installed modules, feature set, license, privilege, command mode, and AOS release. A command present in this legacy guide is not proof that it is supported or secure on a current device.","commands":[{"shell":"AOS CLI","command":"?","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"78d013.pdf; Adtran AOS R10.1.0 Command Reference Guide 60000CRG0-35E","sourceAuthority":"Adtran","namespace":"ADTRAN-AOS","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Adtran"],"products":["Adtran AOS R10.1.0","NetVanta","Total Access 900"],"technologies":["Networking","AOS CLI","CLI Error","Parser"],"articleCategories":["Networking","Adtran","CLI","CLI Error","Parser"],"aliases":["%Ambiguous command","%Ambiguous command"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":57001,"title":"Adtran AOS - %Unrecognized command","category":"Adtran","product":"Adtran AOS R10.1.0 / NetVanta / Total Access 900","tags":["Adtran","AOS","Network Appliance","CLI Error","Parser"],"keywords":["Adtran AOS - %Unrecognized command","AOS does not recognize the entered command at the current prompt.","%Unrecognized command","Adtran","ADTRAN Operating System","AOS R10.1.0","NetVanta","Total Access 900","CLI Error","Parser","?"],"errorCode":"%Unrecognized command","eventId":"","severity":"Low","summary":"AOS does not recognize the entered command at the current prompt.","rootCause":"The command can be misspelled, unsupported by this model or release, unavailable in the current mode, or abbreviated with too few correct characters.","resolution":"1. Record the complete prompt, command mode, command, caret position or response, device model, AOS version, and timestamp.\n2. Use ? at the current prompt, verify spelling and command mode, and check the installed AOS release and platform support.\n3. Use ? at the exact prompt and compare live help with the command reference for the installed release.\n4. Start with read-only show commands; review configuration, management-path impact, backup, approval, and rollback before mutation.\n5. Validate the original service and preserve sanitized evidence.","emailScript":"Hello,\n\nWe reviewed the Adtran network issue and identified Adtran AOS - %Unrecognized command.\n\nWe are validating the device model, software release, current state, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, device name, affected service, approximate time, and what changed. Do not share passwords, SNMP community strings, RADIUS secrets, VPN keys, certificates, packet captures, or an unredacted configuration.","notes":"Version scope: AOS R10.1.0 command reference, June 2012 (legacy). The supplied copy was archived through ManualsLib; current product documentation should be checked at https://docs.adtran.com/all-documentation before making a change.\n\nAOS is used across multiple Adtran NetVanta and Total Access 900 products, but commands vary by model, installed modules, feature set, license, privilege, command mode, and AOS release. A command present in this legacy guide is not proof that it is supported or secure on a current device.","commands":[{"shell":"AOS CLI","command":"?","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"78d013.pdf; Adtran AOS R10.1.0 Command Reference Guide 60000CRG0-35E","sourceAuthority":"Adtran","namespace":"ADTRAN-AOS","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Adtran"],"products":["Adtran AOS R10.1.0","NetVanta","Total Access 900"],"technologies":["Networking","AOS CLI","CLI Error","Parser"],"articleCategories":["Networking","Adtran","CLI","CLI Error","Parser"],"aliases":["%Unrecognized command","%Unrecognized command"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":57002,"title":"Adtran AOS - %Invalid or incomplete command","category":"Adtran","product":"Adtran AOS R10.1.0 / NetVanta / Total Access 900","tags":["Adtran","AOS","Network Appliance","CLI Error","Parser"],"keywords":["Adtran AOS - %Invalid or incomplete command","AOS recognized part of the command but required information is missing or invalid for the current mode.","%Invalid or incomplete command","Adtran","ADTRAN Operating System","AOS R10.1.0","NetVanta","Total Access 900","CLI Error","Parser","?"],"errorCode":"%Invalid or incomplete command","eventId":"","severity":"Low","summary":"AOS recognized part of the command but required information is missing or invalid for the current mode.","rootCause":"A required keyword or value was omitted, the command belongs to another mode, or a supplied value does not satisfy the syntax.","resolution":"1. Record the complete prompt, command mode, command, caret position or response, device model, AOS version, and timestamp.\n2. Enter ? immediately after the accepted portion to display required keywords and values, then complete the command using the live syntax.\n3. Use ? at the exact prompt and compare live help with the command reference for the installed release.\n4. Start with read-only show commands; review configuration, management-path impact, backup, approval, and rollback before mutation.\n5. Validate the original service and preserve sanitized evidence.","emailScript":"Hello,\n\nWe reviewed the Adtran network issue and identified Adtran AOS - %Invalid or incomplete command.\n\nWe are validating the device model, software release, current state, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, device name, affected service, approximate time, and what changed. Do not share passwords, SNMP community strings, RADIUS secrets, VPN keys, certificates, packet captures, or an unredacted configuration.","notes":"Version scope: AOS R10.1.0 command reference, June 2012 (legacy). The supplied copy was archived through ManualsLib; current product documentation should be checked at https://docs.adtran.com/all-documentation before making a change.\n\nAOS is used across multiple Adtran NetVanta and Total Access 900 products, but commands vary by model, installed modules, feature set, license, privilege, command mode, and AOS release. A command present in this legacy guide is not proof that it is supported or secure on a current device.","commands":[{"shell":"AOS CLI","command":"?","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"78d013.pdf; Adtran AOS R10.1.0 Command Reference Guide 60000CRG0-35E","sourceAuthority":"Adtran","namespace":"ADTRAN-AOS","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Adtran"],"products":["Adtran AOS R10.1.0","NetVanta","Total Access 900"],"technologies":["Networking","AOS CLI","CLI Error","Parser"],"articleCategories":["Networking","Adtran","CLI","CLI Error","Parser"],"aliases":["%Invalid or incomplete command","%Invalid or incomplete command"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":57003,"title":"Adtran AOS - %Invalid input detected at ^ marker","category":"Adtran","product":"Adtran AOS R10.1.0 / NetVanta / Total Access 900","tags":["Adtran","AOS","Network Appliance","CLI Error","Parser"],"keywords":["Adtran AOS - %Invalid input detected at ^ marker","AOS located invalid command input at the displayed caret position.","%Invalid input detected at ^ marker","Adtran","ADTRAN Operating System","AOS R10.1.0","NetVanta","Total Access 900","CLI Error","Parser","?"],"errorCode":"%Invalid input detected at ^ marker","eventId":"","severity":"Low","summary":"AOS located invalid command input at the displayed caret position.","rootCause":"The keyword, value, punctuation, or order at the caret does not match syntax accepted in the current command mode.","resolution":"1. Record the complete prompt, command mode, command, caret position or response, device model, AOS version, and timestamp.\n2. Read the caret position, keep the accepted prefix, and enter ? at that point to list applicable syntax. Correct only the marked portion.\n3. Use ? at the exact prompt and compare live help with the command reference for the installed release.\n4. Start with read-only show commands; review configuration, management-path impact, backup, approval, and rollback before mutation.\n5. Validate the original service and preserve sanitized evidence.","emailScript":"Hello,\n\nWe reviewed the Adtran network issue and identified Adtran AOS - %Invalid input detected at ^ marker.\n\nWe are validating the device model, software release, current state, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, device name, affected service, approximate time, and what changed. Do not share passwords, SNMP community strings, RADIUS secrets, VPN keys, certificates, packet captures, or an unredacted configuration.","notes":"Version scope: AOS R10.1.0 command reference, June 2012 (legacy). The supplied copy was archived through ManualsLib; current product documentation should be checked at https://docs.adtran.com/all-documentation before making a change.\n\nAOS is used across multiple Adtran NetVanta and Total Access 900 products, but commands vary by model, installed modules, feature set, license, privilege, command mode, and AOS release. A command present in this legacy guide is not proof that it is supported or secure on a current device.","commands":[{"shell":"AOS CLI","command":"?","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"78d013.pdf; Adtran AOS R10.1.0 Command Reference Guide 60000CRG0-35E","sourceAuthority":"Adtran","namespace":"ADTRAN-AOS","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Adtran"],"products":["Adtran AOS R10.1.0","NetVanta","Total Access 900"],"technologies":["Networking","AOS CLI","CLI Error","Parser"],"articleCategories":["Networking","Adtran","CLI","CLI Error","Parser"],"aliases":["%Invalid input detected at ^ marker","%Invalid input detected at ^ marker"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":57004,"title":"Adtran AOS - CLI Modes and Context","category":"Adtran","product":"Adtran AOS R10.1.0 / NetVanta / Total Access 900","tags":["Adtran","AOS","Network Appliance","CLI","Command Mode"],"keywords":["Adtran AOS - CLI Modes and Context","AOS commands are organized into basic, enable, global configuration, line, interface, routing, policy, voice, and security contexts.","Adtran","ADTRAN Operating System","AOS R10.1.0","NetVanta","Total Access 900","CLI","Command Mode","?","show history","show users"],"errorCode":"","eventId":"","severity":"Low","summary":"AOS commands are organized into basic, enable, global configuration, line, interface, routing, policy, voice, and security contexts.","rootCause":"A valid command can be rejected when entered at the wrong privilege or configuration level.","resolution":"1. Record the complete prompt, command mode, command, caret position or response, device model, AOS version, and timestamp.\n2. Record the prompt, use ? to inspect the current context, and navigate only to the documented mode. Use show history and show users where supported to understand the session.\n3. Use ? at the exact prompt and compare live help with the command reference for the installed release.\n4. Start with read-only show commands; review configuration, management-path impact, backup, approval, and rollback before mutation.\n5. Validate the original service and preserve sanitized evidence.","emailScript":"Hello,\n\nWe reviewed the Adtran network issue and identified Adtran AOS - CLI Modes and Context.\n\nWe are validating the device model, software release, current state, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, device name, affected service, approximate time, and what changed. Do not share passwords, SNMP community strings, RADIUS secrets, VPN keys, certificates, packet captures, or an unredacted configuration.","notes":"Version scope: AOS R10.1.0 command reference, June 2012 (legacy). The supplied copy was archived through ManualsLib; current product documentation should be checked at https://docs.adtran.com/all-documentation before making a change.\n\nAOS is used across multiple Adtran NetVanta and Total Access 900 products, but commands vary by model, installed modules, feature set, license, privilege, command mode, and AOS release. A command present in this legacy guide is not proof that it is supported or secure on a current device.","commands":[{"shell":"AOS CLI","command":"?","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show history","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show users","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"78d013.pdf; Adtran AOS R10.1.0 Command Reference Guide 60000CRG0-35E","sourceAuthority":"Adtran","namespace":"ADTRAN-AOS","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Adtran"],"products":["Adtran AOS R10.1.0","NetVanta","Total Access 900"],"technologies":["Networking","AOS CLI","CLI","Command Mode"],"articleCategories":["Networking","Adtran","CLI","CLI","Command Mode"],"aliases":["CLI Modes and Context"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":57005,"title":"Adtran AOS - Collect Show Tech Support Bundle","category":"Adtran","product":"Adtran AOS R10.1.0 / NetVanta / Total Access 900","tags":["Adtran","AOS","Network Appliance","Diagnostics","Support Bundle"],"keywords":["Adtran AOS - Collect Show Tech Support Bundle","The show tech command creates showtech.txt in flash; show tech terminal displays the collected output in real time.","Adtran","ADTRAN Operating System","AOS R10.1.0","NetVanta","Total Access 900","Diagnostics","Support Bundle","show tech","show tech terminal"],"errorCode":"","eventId":"","severity":"Medium","summary":"The show tech command creates showtech.txt in flash; show tech terminal displays the collected output in real time.","rootCause":"Complex faults can require version, module, flash, configuration, interface, and service evidence that individual commands may omit.","resolution":"1. Record the complete prompt, command mode, command, caret position or response, device model, AOS version, and timestamp.\n2. Confirm sufficient flash and handling policy, run show tech, copy the resulting file to an approved secure location, and sanitize configuration, addresses, identifiers, and secrets before sharing.\n3. Use ? at the exact prompt and compare live help with the command reference for the installed release.\n4. Start with read-only show commands; review configuration, management-path impact, backup, approval, and rollback before mutation.\n5. Validate the original service and preserve sanitized evidence.","emailScript":"Hello,\n\nWe reviewed the Adtran network issue and identified Adtran AOS - Collect Show Tech Support Bundle.\n\nWe are validating the device model, software release, current state, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, device name, affected service, approximate time, and what changed. Do not share passwords, SNMP community strings, RADIUS secrets, VPN keys, certificates, packet captures, or an unredacted configuration.","notes":"Version scope: AOS R10.1.0 command reference, June 2012 (legacy). The supplied copy was archived through ManualsLib; current product documentation should be checked at https://docs.adtran.com/all-documentation before making a change.\n\nAOS is used across multiple Adtran NetVanta and Total Access 900 products, but commands vary by model, installed modules, feature set, license, privilege, command mode, and AOS release. A command present in this legacy guide is not proof that it is supported or secure on a current device.","commands":[{"shell":"AOS CLI","command":"show tech","risk":"Standard","safetyLevel":"Low-Risk Temporary"},{"shell":"AOS CLI","command":"show tech terminal","risk":"Standard","safetyLevel":"Low-Risk Temporary"}],"sourceDocument":"78d013.pdf; Adtran AOS R10.1.0 Command Reference Guide 60000CRG0-35E","sourceAuthority":"Adtran","namespace":"ADTRAN-AOS","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Adtran"],"products":["Adtran AOS R10.1.0","NetVanta","Total Access 900"],"technologies":["Networking","AOS CLI","Diagnostics","Support Bundle"],"articleCategories":["Networking","Adtran","CLI","Diagnostics","Support Bundle"],"aliases":["Collect Show Tech Support Bundle"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":57006,"title":"Adtran AOS - System Health and Inventory","category":"Adtran","product":"Adtran AOS R10.1.0 / NetVanta / Total Access 900","tags":["Adtran","AOS","Network Appliance","Diagnostics","Hardware"],"keywords":["Adtran AOS - System Health and Inventory","Read-only system commands identify software, modules, memory, temperature, flash, power, and overall appliance state.","Adtran","ADTRAN Operating System","AOS R10.1.0","NetVanta","Total Access 900","Diagnostics","Hardware","show version","show system","show modules","show memory","show temperature","show flash","show clock"],"errorCode":"","eventId":"","severity":"High","summary":"Read-only system commands identify software, modules, memory, temperature, flash, power, and overall appliance state.","rootCause":"Resource exhaustion, thermal trouble, module failure, storage problems, or an unexpected image can cause broad instability.","resolution":"1. Record the complete prompt, command mode, command, caret position or response, device model, AOS version, and timestamp.\n2. Capture version, system, module, memory, temperature, flash, and clock output. Compare values with the hardware guide and correlate alarms before rebooting or replacing hardware.\n3. Use ? at the exact prompt and compare live help with the command reference for the installed release.\n4. Start with read-only show commands; review configuration, management-path impact, backup, approval, and rollback before mutation.\n5. Validate the original service and preserve sanitized evidence.","emailScript":"Hello,\n\nWe reviewed the Adtran network issue and identified Adtran AOS - System Health and Inventory.\n\nWe are validating the device model, software release, current state, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, device name, affected service, approximate time, and what changed. Do not share passwords, SNMP community strings, RADIUS secrets, VPN keys, certificates, packet captures, or an unredacted configuration.","notes":"Version scope: AOS R10.1.0 command reference, June 2012 (legacy). The supplied copy was archived through ManualsLib; current product documentation should be checked at https://docs.adtran.com/all-documentation before making a change.\n\nAOS is used across multiple Adtran NetVanta and Total Access 900 products, but commands vary by model, installed modules, feature set, license, privilege, command mode, and AOS release. A command present in this legacy guide is not proof that it is supported or secure on a current device.","commands":[{"shell":"AOS CLI","command":"show version","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show system","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show modules","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show memory","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show temperature","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show flash","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show clock","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"78d013.pdf; Adtran AOS R10.1.0 Command Reference Guide 60000CRG0-35E","sourceAuthority":"Adtran","namespace":"ADTRAN-AOS","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Adtran"],"products":["Adtran AOS R10.1.0","NetVanta","Total Access 900"],"technologies":["Networking","AOS CLI","Diagnostics","Hardware"],"articleCategories":["Networking","Adtran","CLI","Diagnostics","Hardware"],"aliases":["System Health and Inventory"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":57007,"title":"Adtran AOS - Interface and Connection Diagnostics","category":"Adtran","product":"Adtran AOS R10.1.0 / NetVanta / Total Access 900","tags":["Adtran","AOS","Network Appliance","Interfaces","Connectivity"],"keywords":["Adtran AOS - Interface and Connection Diagnostics","Interface and connection output identifies link, addressing, encapsulation, counters, and active connection state.","Adtran","ADTRAN Operating System","AOS R10.1.0","NetVanta","Total Access 900","Interfaces","Connectivity","show interfaces","show connections"],"errorCode":"","eventId":"","severity":"Medium","summary":"Interface and connection output identifies link, addressing, encapsulation, counters, and active connection state.","rootCause":"Media, negotiation, errors, addressing, subinterface, encapsulation, or peer state can interrupt service.","resolution":"1. Record the complete prompt, command mode, command, caret position or response, device model, AOS version, and timestamp.\n2. Capture show interfaces and show connections, then compare administrative and operational state, counters, addressing, and peer configuration on both ends.\n3. Use ? at the exact prompt and compare live help with the command reference for the installed release.\n4. Start with read-only show commands; review configuration, management-path impact, backup, approval, and rollback before mutation.\n5. Validate the original service and preserve sanitized evidence.","emailScript":"Hello,\n\nWe reviewed the Adtran network issue and identified Adtran AOS - Interface and Connection Diagnostics.\n\nWe are validating the device model, software release, current state, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, device name, affected service, approximate time, and what changed. Do not share passwords, SNMP community strings, RADIUS secrets, VPN keys, certificates, packet captures, or an unredacted configuration.","notes":"Version scope: AOS R10.1.0 command reference, June 2012 (legacy). The supplied copy was archived through ManualsLib; current product documentation should be checked at https://docs.adtran.com/all-documentation before making a change.\n\nAOS is used across multiple Adtran NetVanta and Total Access 900 products, but commands vary by model, installed modules, feature set, license, privilege, command mode, and AOS release. A command present in this legacy guide is not proof that it is supported or secure on a current device.","commands":[{"shell":"AOS CLI","command":"show interfaces","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show connections","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"78d013.pdf; Adtran AOS R10.1.0 Command Reference Guide 60000CRG0-35E","sourceAuthority":"Adtran","namespace":"ADTRAN-AOS","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Adtran"],"products":["Adtran AOS R10.1.0","NetVanta","Total Access 900"],"technologies":["Networking","AOS CLI","Interfaces","Connectivity"],"articleCategories":["Networking","Adtran","CLI","Interfaces","Connectivity"],"aliases":["Interface and Connection Diagnostics"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":57008,"title":"Adtran AOS - Routing Table and IP Traffic Diagnostics","category":"Adtran","product":"Adtran AOS R10.1.0 / NetVanta / Total Access 900","tags":["Adtran","AOS","Network Appliance","Routing","IP"],"keywords":["Adtran AOS - Routing Table and IP Traffic Diagnostics","AOS route, protocol, and traffic views show forwarding decisions and IP-layer counters.","Adtran","ADTRAN Operating System","AOS R10.1.0","NetVanta","Total Access 900","Routing","IP","show ip route","show ip protocols","show ip traffic","show arp","show hosts"],"errorCode":"","eventId":"","severity":"High","summary":"AOS route, protocol, and traffic views show forwarding decisions and IP-layer counters.","rootCause":"A missing route, wrong next hop, protocol state, policy, or rising discard/error counter can cause reachability failures.","resolution":"1. Record the complete prompt, command mode, command, caret position or response, device model, AOS version, and timestamp.\n2. Capture routes, protocols, traffic counters, ARP, and host resolution. Trace the expected destination and verify return routing before changing a route.\n3. Use ? at the exact prompt and compare live help with the command reference for the installed release.\n4. Start with read-only show commands; review configuration, management-path impact, backup, approval, and rollback before mutation.\n5. Validate the original service and preserve sanitized evidence.","emailScript":"Hello,\n\nWe reviewed the Adtran network issue and identified Adtran AOS - Routing Table and IP Traffic Diagnostics.\n\nWe are validating the device model, software release, current state, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, device name, affected service, approximate time, and what changed. Do not share passwords, SNMP community strings, RADIUS secrets, VPN keys, certificates, packet captures, or an unredacted configuration.","notes":"Version scope: AOS R10.1.0 command reference, June 2012 (legacy). The supplied copy was archived through ManualsLib; current product documentation should be checked at https://docs.adtran.com/all-documentation before making a change.\n\nAOS is used across multiple Adtran NetVanta and Total Access 900 products, but commands vary by model, installed modules, feature set, license, privilege, command mode, and AOS release. A command present in this legacy guide is not proof that it is supported or secure on a current device.","commands":[{"shell":"AOS CLI","command":"show ip route","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show ip protocols","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show ip traffic","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show arp","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show hosts","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"78d013.pdf; Adtran AOS R10.1.0 Command Reference Guide 60000CRG0-35E","sourceAuthority":"Adtran","namespace":"ADTRAN-AOS","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Adtran"],"products":["Adtran AOS R10.1.0","NetVanta","Total Access 900"],"technologies":["Networking","AOS CLI","Routing","IP"],"articleCategories":["Networking","Adtran","CLI","Routing","IP"],"aliases":["Routing Table and IP Traffic Diagnostics"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":57009,"title":"Adtran AOS - OSPF Neighbor and Database Diagnostics","category":"Adtran","product":"Adtran AOS R10.1.0 / NetVanta / Total Access 900","tags":["Adtran","AOS","Network Appliance","Routing","OSPF"],"keywords":["Adtran AOS - OSPF Neighbor and Database Diagnostics","OSPF show commands expose neighbor state, interfaces, LSDB content, routes, and protocol configuration.","Adtran","ADTRAN Operating System","AOS R10.1.0","NetVanta","Total Access 900","Routing","OSPF","show ip ospf","show ip ospf neighbor","show ip ospf interface","show ip ospf database","show ip route"],"errorCode":"","eventId":"","severity":"High","summary":"OSPF show commands expose neighbor state, interfaces, LSDB content, routes, and protocol configuration.","rootCause":"Area, authentication, timer, MTU, network type, addressing, filtering, or reachability mismatches can prevent adjacency or route installation.","resolution":"1. Record the complete prompt, command mode, command, caret position or response, device model, AOS version, and timestamp.\n2. Capture OSPF overview, neighbor, interface, database, route, and logs on both peers. Compare parameters before enabling debug, and bound any debug collection.\n3. Use ? at the exact prompt and compare live help with the command reference for the installed release.\n4. Start with read-only show commands; review configuration, management-path impact, backup, approval, and rollback before mutation.\n5. Validate the original service and preserve sanitized evidence.","emailScript":"Hello,\n\nWe reviewed the Adtran network issue and identified Adtran AOS - OSPF Neighbor and Database Diagnostics.\n\nWe are validating the device model, software release, current state, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, device name, affected service, approximate time, and what changed. Do not share passwords, SNMP community strings, RADIUS secrets, VPN keys, certificates, packet captures, or an unredacted configuration.","notes":"Version scope: AOS R10.1.0 command reference, June 2012 (legacy). The supplied copy was archived through ManualsLib; current product documentation should be checked at https://docs.adtran.com/all-documentation before making a change.\n\nAOS is used across multiple Adtran NetVanta and Total Access 900 products, but commands vary by model, installed modules, feature set, license, privilege, command mode, and AOS release. A command present in this legacy guide is not proof that it is supported or secure on a current device.","commands":[{"shell":"AOS CLI","command":"show ip ospf","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show ip ospf neighbor","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show ip ospf interface","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show ip ospf database","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show ip route","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"78d013.pdf; Adtran AOS R10.1.0 Command Reference Guide 60000CRG0-35E","sourceAuthority":"Adtran","namespace":"ADTRAN-AOS","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Adtran"],"products":["Adtran AOS R10.1.0","NetVanta","Total Access 900"],"technologies":["Networking","AOS CLI","Routing","OSPF"],"articleCategories":["Networking","Adtran","CLI","Routing","OSPF"],"aliases":["OSPF Neighbor and Database Diagnostics"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":57010,"title":"Adtran AOS - BGP Neighbor and Route Diagnostics","category":"Adtran","product":"Adtran AOS R10.1.0 / NetVanta / Total Access 900","tags":["Adtran","AOS","Network Appliance","Routing","BGP"],"keywords":["Adtran AOS - BGP Neighbor and Route Diagnostics","BGP views show session state, neighbors, learned paths, and routing policy results.","Adtran","ADTRAN Operating System","AOS R10.1.0","NetVanta","Total Access 900","Routing","BGP","show bgp","show ip route"],"errorCode":"","eventId":"","severity":"High","summary":"BGP views show session state, neighbors, learned paths, and routing policy results.","rootCause":"Reachability, AS number, source, authentication, address family, policy, timer, or upstream conditions can prevent establishment or route exchange.","resolution":"1. Record the complete prompt, command mode, command, caret position or response, device model, AOS version, and timestamp.\n2. Capture BGP summary and affected neighbor details plus route and configuration evidence. Compare both peers and policy before clearing a session.\n3. Use ? at the exact prompt and compare live help with the command reference for the installed release.\n4. Start with read-only show commands; review configuration, management-path impact, backup, approval, and rollback before mutation.\n5. Validate the original service and preserve sanitized evidence.","emailScript":"Hello,\n\nWe reviewed the Adtran network issue and identified Adtran AOS - BGP Neighbor and Route Diagnostics.\n\nWe are validating the device model, software release, current state, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, device name, affected service, approximate time, and what changed. Do not share passwords, SNMP community strings, RADIUS secrets, VPN keys, certificates, packet captures, or an unredacted configuration.","notes":"Version scope: AOS R10.1.0 command reference, June 2012 (legacy). The supplied copy was archived through ManualsLib; current product documentation should be checked at https://docs.adtran.com/all-documentation before making a change.\n\nAOS is used across multiple Adtran NetVanta and Total Access 900 products, but commands vary by model, installed modules, feature set, license, privilege, command mode, and AOS release. A command present in this legacy guide is not proof that it is supported or secure on a current device.","commands":[{"shell":"AOS CLI","command":"show bgp","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show ip route","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"78d013.pdf; Adtran AOS R10.1.0 Command Reference Guide 60000CRG0-35E","sourceAuthority":"Adtran","namespace":"ADTRAN-AOS","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Adtran"],"products":["Adtran AOS R10.1.0","NetVanta","Total Access 900"],"technologies":["Networking","AOS CLI","Routing","BGP"],"articleCategories":["Networking","Adtran","CLI","Routing","BGP"],"aliases":["BGP Neighbor and Route Diagnostics"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":57011,"title":"Adtran AOS - DHCP Binding Diagnostics","category":"Adtran","product":"Adtran AOS R10.1.0 / NetVanta / Total Access 900","tags":["Adtran","AOS","Network Appliance","DHCP","Addressing"],"keywords":["Adtran AOS - DHCP Binding Diagnostics","The DHCP binding table shows leases assigned by supported AOS DHCP services.","Adtran","ADTRAN Operating System","AOS R10.1.0","NetVanta","Total Access 900","DHCP","Addressing","show ip dhcp binding","show interfaces","show vlan"],"errorCode":"","eventId":"","severity":"Medium","summary":"The DHCP binding table shows leases assigned by supported AOS DHCP services.","rootCause":"Scope exhaustion, relay, VLAN, server reachability, exclusions, conflicts, or client behavior can prevent addressing.","resolution":"1. Record the complete prompt, command mode, command, caret position or response, device model, AOS version, and timestamp.\n2. Capture bindings, interface/VLAN state, DHCP configuration, routes, and relevant counters. Verify the authoritative DHCP server and relay path before clearing leases.\n3. Use ? at the exact prompt and compare live help with the command reference for the installed release.\n4. Start with read-only show commands; review configuration, management-path impact, backup, approval, and rollback before mutation.\n5. Validate the original service and preserve sanitized evidence.","emailScript":"Hello,\n\nWe reviewed the Adtran network issue and identified Adtran AOS - DHCP Binding Diagnostics.\n\nWe are validating the device model, software release, current state, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, device name, affected service, approximate time, and what changed. Do not share passwords, SNMP community strings, RADIUS secrets, VPN keys, certificates, packet captures, or an unredacted configuration.","notes":"Version scope: AOS R10.1.0 command reference, June 2012 (legacy). The supplied copy was archived through ManualsLib; current product documentation should be checked at https://docs.adtran.com/all-documentation before making a change.\n\nAOS is used across multiple Adtran NetVanta and Total Access 900 products, but commands vary by model, installed modules, feature set, license, privilege, command mode, and AOS release. A command present in this legacy guide is not proof that it is supported or secure on a current device.","commands":[{"shell":"AOS CLI","command":"show ip dhcp binding","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show interfaces","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show vlan","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"78d013.pdf; Adtran AOS R10.1.0 Command Reference Guide 60000CRG0-35E","sourceAuthority":"Adtran","namespace":"ADTRAN-AOS","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Adtran"],"products":["Adtran AOS R10.1.0","NetVanta","Total Access 900"],"technologies":["Networking","AOS CLI","DHCP","Addressing"],"articleCategories":["Networking","Adtran","CLI","DHCP","Addressing"],"aliases":["DHCP Binding Diagnostics"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":57012,"title":"Adtran AOS - VLAN and Bridge Diagnostics","category":"Adtran","product":"Adtran AOS R10.1.0 / NetVanta / Total Access 900","tags":["Adtran","AOS","Network Appliance","Switching","VLAN","Bridge"],"keywords":["Adtran AOS - VLAN and Bridge Diagnostics","VLAN, bridge, GVRP, and interface state identify Layer 2 membership and forwarding behavior.","Adtran","ADTRAN Operating System","AOS R10.1.0","NetVanta","Total Access 900","Switching","VLAN","Bridge","show vlan","show bridge","show gvrp configuration","show gvrp statistics","show interfaces"],"errorCode":"","eventId":"","severity":"High","summary":"VLAN, bridge, GVRP, and interface state identify Layer 2 membership and forwarding behavior.","rootCause":"Wrong access/trunk mode, allowed VLANs, tagging, PVID, bridge state, or dynamic registration can isolate devices.","resolution":"1. Record the complete prompt, command mode, command, caret position or response, device model, AOS version, and timestamp.\n2. Capture VLAN, bridge, GVRP, LLDP, and interface output. Trace the VLAN end to end before changing membership or trunks.\n3. Use ? at the exact prompt and compare live help with the command reference for the installed release.\n4. Start with read-only show commands; review configuration, management-path impact, backup, approval, and rollback before mutation.\n5. Validate the original service and preserve sanitized evidence.","emailScript":"Hello,\n\nWe reviewed the Adtran network issue and identified Adtran AOS - VLAN and Bridge Diagnostics.\n\nWe are validating the device model, software release, current state, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, device name, affected service, approximate time, and what changed. Do not share passwords, SNMP community strings, RADIUS secrets, VPN keys, certificates, packet captures, or an unredacted configuration.","notes":"Version scope: AOS R10.1.0 command reference, June 2012 (legacy). The supplied copy was archived through ManualsLib; current product documentation should be checked at https://docs.adtran.com/all-documentation before making a change.\n\nAOS is used across multiple Adtran NetVanta and Total Access 900 products, but commands vary by model, installed modules, feature set, license, privilege, command mode, and AOS release. A command present in this legacy guide is not proof that it is supported or secure on a current device.","commands":[{"shell":"AOS CLI","command":"show vlan","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show bridge","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show gvrp configuration","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show gvrp statistics","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show interfaces","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"78d013.pdf; Adtran AOS R10.1.0 Command Reference Guide 60000CRG0-35E","sourceAuthority":"Adtran","namespace":"ADTRAN-AOS","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Adtran"],"products":["Adtran AOS R10.1.0","NetVanta","Total Access 900"],"technologies":["Networking","AOS CLI","Switching","VLAN","Bridge"],"articleCategories":["Networking","Adtran","CLI","Switching","VLAN","Bridge"],"aliases":["VLAN and Bridge Diagnostics"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":57013,"title":"Adtran AOS - LLDP Neighbor Diagnostics","category":"Adtran","product":"Adtran AOS R10.1.0 / NetVanta / Total Access 900","tags":["Adtran","AOS","Network Appliance","LLDP","Topology"],"keywords":["Adtran AOS - LLDP Neighbor Diagnostics","LLDP output identifies connected peers and advertised interface information.","Adtran","ADTRAN Operating System","AOS R10.1.0","NetVanta","Total Access 900","LLDP","Topology","show lldp","show lldp interface","show lldp neighbors"],"errorCode":"","eventId":"","severity":"Low","summary":"LLDP output identifies connected peers and advertised interface information.","rootCause":"Cabling, disabled LLDP, VLAN mismatch, intermediate equipment, or a neighbor issue can make topology differ from documentation.","resolution":"1. Record the complete prompt, command mode, command, caret position or response, device model, AOS version, and timestamp.\n2. Capture LLDP overview, interface, and neighbors plus local interface state. Compare chassis, port, management, and capability data with the intended topology.\n3. Use ? at the exact prompt and compare live help with the command reference for the installed release.\n4. Start with read-only show commands; review configuration, management-path impact, backup, approval, and rollback before mutation.\n5. Validate the original service and preserve sanitized evidence.","emailScript":"Hello,\n\nWe reviewed the Adtran network issue and identified Adtran AOS - LLDP Neighbor Diagnostics.\n\nWe are validating the device model, software release, current state, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, device name, affected service, approximate time, and what changed. Do not share passwords, SNMP community strings, RADIUS secrets, VPN keys, certificates, packet captures, or an unredacted configuration.","notes":"Version scope: AOS R10.1.0 command reference, June 2012 (legacy). The supplied copy was archived through ManualsLib; current product documentation should be checked at https://docs.adtran.com/all-documentation before making a change.\n\nAOS is used across multiple Adtran NetVanta and Total Access 900 products, but commands vary by model, installed modules, feature set, license, privilege, command mode, and AOS release. A command present in this legacy guide is not proof that it is supported or secure on a current device.","commands":[{"shell":"AOS CLI","command":"show lldp","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show lldp interface","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show lldp neighbors","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"78d013.pdf; Adtran AOS R10.1.0 Command Reference Guide 60000CRG0-35E","sourceAuthority":"Adtran","namespace":"ADTRAN-AOS","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Adtran"],"products":["Adtran AOS R10.1.0","NetVanta","Total Access 900"],"technologies":["Networking","AOS CLI","LLDP","Topology"],"articleCategories":["Networking","Adtran","CLI","LLDP","Topology"],"aliases":["LLDP Neighbor Diagnostics"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":57014,"title":"Adtran AOS - PoE Device Not Powered","category":"Adtran","product":"Adtran AOS R10.1.0 / NetVanta / Total Access 900","tags":["Adtran","AOS","Network Appliance","PoE","Hardware"],"keywords":["Adtran AOS - PoE Device Not Powered","Power inline output shows supported powered-device state and allocation.","Adtran","ADTRAN Operating System","AOS R10.1.0","NetVanta","Total Access 900","PoE","Hardware","show power inline","show temperature","show interfaces"],"errorCode":"","eventId":"","severity":"High","summary":"Power inline output shows supported powered-device state and allocation.","rootCause":"PoE can fail because of budget, port configuration, cabling, classification, hardware, temperature, or an unsupported powered device.","resolution":"1. Record the complete prompt, command mode, command, caret position or response, device model, AOS version, and timestamp.\n2. Capture show power inline, temperature, system, and interface state. Check total and per-port budget and test known-good media/device before power cycling or changing allocation.\n3. Use ? at the exact prompt and compare live help with the command reference for the installed release.\n4. Start with read-only show commands; review configuration, management-path impact, backup, approval, and rollback before mutation.\n5. Validate the original service and preserve sanitized evidence.","emailScript":"Hello,\n\nWe reviewed the Adtran network issue and identified Adtran AOS - PoE Device Not Powered.\n\nWe are validating the device model, software release, current state, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, device name, affected service, approximate time, and what changed. Do not share passwords, SNMP community strings, RADIUS secrets, VPN keys, certificates, packet captures, or an unredacted configuration.","notes":"Version scope: AOS R10.1.0 command reference, June 2012 (legacy). The supplied copy was archived through ManualsLib; current product documentation should be checked at https://docs.adtran.com/all-documentation before making a change.\n\nAOS is used across multiple Adtran NetVanta and Total Access 900 products, but commands vary by model, installed modules, feature set, license, privilege, command mode, and AOS release. A command present in this legacy guide is not proof that it is supported or secure on a current device.","commands":[{"shell":"AOS CLI","command":"show power inline","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show temperature","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show interfaces","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"78d013.pdf; Adtran AOS R10.1.0 Command Reference Guide 60000CRG0-35E","sourceAuthority":"Adtran","namespace":"ADTRAN-AOS","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Adtran"],"products":["Adtran AOS R10.1.0","NetVanta","Total Access 900"],"technologies":["Networking","AOS CLI","PoE","Hardware"],"articleCategories":["Networking","Adtran","CLI","PoE","Hardware"],"aliases":["PoE Device Not Powered"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":57015,"title":"Adtran AOS - NTP Synchronization Failure","category":"Adtran","product":"Adtran AOS R10.1.0 / NetVanta / Total Access 900","tags":["Adtran","AOS","Network Appliance","NTP","Time"],"keywords":["Adtran AOS - NTP Synchronization Failure","NTP association and status views show time peers and synchronization state.","Adtran","ADTRAN Operating System","AOS R10.1.0","NetVanta","Total Access 900","NTP","Time","show clock","show ntp associations","show ntp status","show ip route"],"errorCode":"","eventId":"","severity":"Medium","summary":"NTP association and status views show time peers and synchronization state.","rootCause":"Server reachability, DNS, routes, source interface, authentication, access policy, or clock offset can prevent synchronization.","resolution":"1. Record the complete prompt, command mode, command, caret position or response, device model, AOS version, and timestamp.\n2. Capture clock, NTP associations, status, routes, and server reachability. Correct the evidenced path or configuration and verify synchronized state before certificate or log troubleshooting.\n3. Use ? at the exact prompt and compare live help with the command reference for the installed release.\n4. Start with read-only show commands; review configuration, management-path impact, backup, approval, and rollback before mutation.\n5. Validate the original service and preserve sanitized evidence.","emailScript":"Hello,\n\nWe reviewed the Adtran network issue and identified Adtran AOS - NTP Synchronization Failure.\n\nWe are validating the device model, software release, current state, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, device name, affected service, approximate time, and what changed. Do not share passwords, SNMP community strings, RADIUS secrets, VPN keys, certificates, packet captures, or an unredacted configuration.","notes":"Version scope: AOS R10.1.0 command reference, June 2012 (legacy). The supplied copy was archived through ManualsLib; current product documentation should be checked at https://docs.adtran.com/all-documentation before making a change.\n\nAOS is used across multiple Adtran NetVanta and Total Access 900 products, but commands vary by model, installed modules, feature set, license, privilege, command mode, and AOS release. A command present in this legacy guide is not proof that it is supported or secure on a current device.","commands":[{"shell":"AOS CLI","command":"show clock","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show ntp associations","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show ntp status","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show ip route","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"78d013.pdf; Adtran AOS R10.1.0 Command Reference Guide 60000CRG0-35E","sourceAuthority":"Adtran","namespace":"ADTRAN-AOS","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Adtran"],"products":["Adtran AOS R10.1.0","NetVanta","Total Access 900"],"technologies":["Networking","AOS CLI","NTP","Time"],"articleCategories":["Networking","Adtran","CLI","NTP","Time"],"aliases":["NTP Synchronization Failure"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":57016,"title":"Adtran AOS - RADIUS and AAA Authentication Diagnostics","category":"Adtran","product":"Adtran AOS R10.1.0 / NetVanta / Total Access 900","tags":["Adtran","AOS","Network Appliance","RADIUS","AAA","Authentication"],"keywords":["Adtran AOS - RADIUS and AAA Authentication Diagnostics","RADIUS statistics and AAA configuration help distinguish reachability, rejection, timeout, and accounting problems.","Adtran","ADTRAN Operating System","AOS R10.1.0","NetVanta","Total Access 900","RADIUS","AAA","Authentication","show radius statistics","show users","show clock","show ip route"],"errorCode":"","eventId":"","severity":"High","summary":"RADIUS statistics and AAA configuration help distinguish reachability, rejection, timeout, and accounting problems.","rootCause":"Server reachability, source address, shared secret, port, policy, user data, time, or server health can break authentication.","resolution":"1. Record the complete prompt, command mode, command, caret position or response, device model, AOS version, and timestamp.\n2. Capture sanitized AAA configuration, RADIUS statistics, routes, clock, and server logs. Verify reachability and matching client identity without displaying or changing the shared secret.\n3. Use ? at the exact prompt and compare live help with the command reference for the installed release.\n4. Start with read-only show commands; review configuration, management-path impact, backup, approval, and rollback before mutation.\n5. Validate the original service and preserve sanitized evidence.","emailScript":"Hello,\n\nWe reviewed the Adtran network issue and identified Adtran AOS - RADIUS and AAA Authentication Diagnostics.\n\nWe are validating the device model, software release, current state, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, device name, affected service, approximate time, and what changed. Do not share passwords, SNMP community strings, RADIUS secrets, VPN keys, certificates, packet captures, or an unredacted configuration.","notes":"Version scope: AOS R10.1.0 command reference, June 2012 (legacy). The supplied copy was archived through ManualsLib; current product documentation should be checked at https://docs.adtran.com/all-documentation before making a change.\n\nAOS is used across multiple Adtran NetVanta and Total Access 900 products, but commands vary by model, installed modules, feature set, license, privilege, command mode, and AOS release. A command present in this legacy guide is not proof that it is supported or secure on a current device.","commands":[{"shell":"AOS CLI","command":"show radius statistics","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show users","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show clock","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show ip route","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"78d013.pdf; Adtran AOS R10.1.0 Command Reference Guide 60000CRG0-35E","sourceAuthority":"Adtran","namespace":"ADTRAN-AOS","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Adtran"],"products":["Adtran AOS R10.1.0","NetVanta","Total Access 900"],"technologies":["Networking","AOS CLI","RADIUS","AAA","Authentication"],"articleCategories":["Networking","Adtran","CLI","RADIUS","AAA","Authentication"],"aliases":["RADIUS and AAA Authentication Diagnostics"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":57017,"title":"Adtran AOS - Stack Health Diagnostics","category":"Adtran","product":"Adtran AOS R10.1.0 / NetVanta / Total Access 900","tags":["Adtran","AOS","Network Appliance","Stacking","Switching"],"keywords":["Adtran AOS - Stack Health Diagnostics","AOS stack output identifies members and stack state on supported platforms.","Adtran","ADTRAN Operating System","AOS R10.1.0","NetVanta","Total Access 900","Stacking","Switching","show stack","show version","show modules","show system"],"errorCode":"","eventId":"","severity":"Critical","summary":"AOS stack output identifies members and stack state on supported platforms.","rootCause":"Cabling, stack ports, member ID, image mismatch, power, topology, or hardware conditions can impair a stack.","resolution":"1. Record the complete prompt, command mode, command, caret position or response, device model, AOS version, and timestamp.\n2. Capture stack, version, modules, system, interfaces, and logs from the active unit. Preserve management access and redundancy before reseating or rebooting members.\n3. Use ? at the exact prompt and compare live help with the command reference for the installed release.\n4. Start with read-only show commands; review configuration, management-path impact, backup, approval, and rollback before mutation.\n5. Validate the original service and preserve sanitized evidence.","emailScript":"Hello,\n\nWe reviewed the Adtran network issue and identified Adtran AOS - Stack Health Diagnostics.\n\nWe are validating the device model, software release, current state, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, device name, affected service, approximate time, and what changed. Do not share passwords, SNMP community strings, RADIUS secrets, VPN keys, certificates, packet captures, or an unredacted configuration.","notes":"Version scope: AOS R10.1.0 command reference, June 2012 (legacy). The supplied copy was archived through ManualsLib; current product documentation should be checked at https://docs.adtran.com/all-documentation before making a change.\n\nAOS is used across multiple Adtran NetVanta and Total Access 900 products, but commands vary by model, installed modules, feature set, license, privilege, command mode, and AOS release. A command present in this legacy guide is not proof that it is supported or secure on a current device.","commands":[{"shell":"AOS CLI","command":"show stack","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show version","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show modules","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show system","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"78d013.pdf; Adtran AOS R10.1.0 Command Reference Guide 60000CRG0-35E","sourceAuthority":"Adtran","namespace":"ADTRAN-AOS","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Adtran"],"products":["Adtran AOS R10.1.0","NetVanta","Total Access 900"],"technologies":["Networking","AOS CLI","Stacking","Switching"],"articleCategories":["Networking","Adtran","CLI","Stacking","Switching"],"aliases":["Stack Health Diagnostics"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":57018,"title":"Adtran AOS - IGMP and Multicast Diagnostics","category":"Adtran","product":"Adtran AOS R10.1.0 / NetVanta / Total Access 900","tags":["Adtran","AOS","Network Appliance","IGMP","Multicast"],"keywords":["Adtran AOS - IGMP and Multicast Diagnostics","IGMP group, interface, snooping, and multicast-route views identify receivers and forwarding state.","Adtran","ADTRAN Operating System","AOS R10.1.0","NetVanta","Total Access 900","IGMP","Multicast","show ip igmp groups","show ip igmp interface","show ip igmp snooping","show ip mroute","show vlan"],"errorCode":"","eventId":"","severity":"High","summary":"IGMP group, interface, snooping, and multicast-route views identify receivers and forwarding state.","rootCause":"Querier, VLAN, snooping, PIM, route, source, receiver, or timer state can interrupt multicast delivery.","resolution":"1. Record the complete prompt, command mode, command, caret position or response, device model, AOS version, and timestamp.\n2. Capture IGMP groups/interfaces/snooping, multicast routes, IP routes, and VLAN state. Follow the source-to-receiver tree before changing snooping or routing.\n3. Use ? at the exact prompt and compare live help with the command reference for the installed release.\n4. Start with read-only show commands; review configuration, management-path impact, backup, approval, and rollback before mutation.\n5. Validate the original service and preserve sanitized evidence.","emailScript":"Hello,\n\nWe reviewed the Adtran network issue and identified Adtran AOS - IGMP and Multicast Diagnostics.\n\nWe are validating the device model, software release, current state, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, device name, affected service, approximate time, and what changed. Do not share passwords, SNMP community strings, RADIUS secrets, VPN keys, certificates, packet captures, or an unredacted configuration.","notes":"Version scope: AOS R10.1.0 command reference, June 2012 (legacy). The supplied copy was archived through ManualsLib; current product documentation should be checked at https://docs.adtran.com/all-documentation before making a change.\n\nAOS is used across multiple Adtran NetVanta and Total Access 900 products, but commands vary by model, installed modules, feature set, license, privilege, command mode, and AOS release. A command present in this legacy guide is not proof that it is supported or secure on a current device.","commands":[{"shell":"AOS CLI","command":"show ip igmp groups","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show ip igmp interface","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show ip igmp snooping","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show ip mroute","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show vlan","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"78d013.pdf; Adtran AOS R10.1.0 Command Reference Guide 60000CRG0-35E","sourceAuthority":"Adtran","namespace":"ADTRAN-AOS","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Adtran"],"products":["Adtran AOS R10.1.0","NetVanta","Total Access 900"],"technologies":["Networking","AOS CLI","IGMP","Multicast"],"articleCategories":["Networking","Adtran","CLI","IGMP","Multicast"],"aliases":["IGMP and Multicast Diagnostics"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":57019,"title":"Adtran AOS - Packet Capture Workflow","category":"Adtran","product":"Adtran AOS R10.1.0 / NetVanta / Total Access 900","tags":["Adtran","AOS","Network Appliance","Packet Capture","PCAP","Diagnostics"],"keywords":["Adtran AOS - Packet Capture Workflow","AOS packet-capture functions can collect traffic for protocol and path analysis on supported products.","Adtran","ADTRAN Operating System","AOS R10.1.0","NetVanta","Total Access 900","Packet Capture","PCAP","Diagnostics","show packet-capture"],"errorCode":"","eventId":"","severity":"High","summary":"AOS packet-capture functions can collect traffic for protocol and path analysis on supported products.","rootCause":"Control-plane and packet symptoms can require header/timing evidence that counters alone do not provide.","resolution":"1. Record the complete prompt, command mode, command, caret position or response, device model, AOS version, and timestamp.\n2. Define the narrowest approved capture by interface, host, protocol, port, duration, and size. Start, stop, export, and sanitize it promptly; packet captures can contain credentials and personal data.\n3. Use ? at the exact prompt and compare live help with the command reference for the installed release.\n4. Start with read-only show commands; review configuration, management-path impact, backup, approval, and rollback before mutation.\n5. Validate the original service and preserve sanitized evidence.","emailScript":"Hello,\n\nWe reviewed the Adtran network issue and identified Adtran AOS - Packet Capture Workflow.\n\nWe are validating the device model, software release, current state, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, device name, affected service, approximate time, and what changed. Do not share passwords, SNMP community strings, RADIUS secrets, VPN keys, certificates, packet captures, or an unredacted configuration.","notes":"Version scope: AOS R10.1.0 command reference, June 2012 (legacy). The supplied copy was archived through ManualsLib; current product documentation should be checked at https://docs.adtran.com/all-documentation before making a change.\n\nAOS is used across multiple Adtran NetVanta and Total Access 900 products, but commands vary by model, installed modules, feature set, license, privilege, command mode, and AOS release. A command present in this legacy guide is not proof that it is supported or secure on a current device.","commands":[{"shell":"AOS CLI","command":"show packet-capture","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"78d013.pdf; Adtran AOS R10.1.0 Command Reference Guide 60000CRG0-35E","sourceAuthority":"Adtran","namespace":"ADTRAN-AOS","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Adtran"],"products":["Adtran AOS R10.1.0","NetVanta","Total Access 900"],"technologies":["Networking","AOS CLI","Packet Capture","PCAP","Diagnostics"],"articleCategories":["Networking","Adtran","CLI","Packet Capture","PCAP","Diagnostics"],"aliases":["Packet Capture Workflow"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":57020,"title":"Adtran AOS - SNMP Agent and Monitoring Diagnostics","category":"Adtran","product":"Adtran AOS R10.1.0 / NetVanta / Total Access 900","tags":["Adtran","AOS","Network Appliance","SNMP","Monitoring"],"keywords":["Adtran AOS - SNMP Agent and Monitoring Diagnostics","SNMP status and configuration determine whether monitoring can query the appliance and receive notifications.","Adtran","ADTRAN Operating System","AOS R10.1.0","NetVanta","Total Access 900","SNMP","Monitoring","show snmp","show ip route","show clock"],"errorCode":"","eventId":"","severity":"Medium","summary":"SNMP status and configuration determine whether monitoring can query the appliance and receive notifications.","rootCause":"Agent state, ACL, source, version, credentials, engine/user configuration, routing, or manager settings can break monitoring.","resolution":"1. Record the complete prompt, command mode, command, caret position or response, device model, AOS version, and timestamp.\n2. Capture show snmp, routes, clock, and sanitized configuration. Test from the authorized manager and compare version/security settings without exposing community strings or keys.\n3. Use ? at the exact prompt and compare live help with the command reference for the installed release.\n4. Start with read-only show commands; review configuration, management-path impact, backup, approval, and rollback before mutation.\n5. Validate the original service and preserve sanitized evidence.","emailScript":"Hello,\n\nWe reviewed the Adtran network issue and identified Adtran AOS - SNMP Agent and Monitoring Diagnostics.\n\nWe are validating the device model, software release, current state, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, device name, affected service, approximate time, and what changed. Do not share passwords, SNMP community strings, RADIUS secrets, VPN keys, certificates, packet captures, or an unredacted configuration.","notes":"Version scope: AOS R10.1.0 command reference, June 2012 (legacy). The supplied copy was archived through ManualsLib; current product documentation should be checked at https://docs.adtran.com/all-documentation before making a change.\n\nAOS is used across multiple Adtran NetVanta and Total Access 900 products, but commands vary by model, installed modules, feature set, license, privilege, command mode, and AOS release. A command present in this legacy guide is not proof that it is supported or secure on a current device.","commands":[{"shell":"AOS CLI","command":"show snmp","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show ip route","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show clock","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"78d013.pdf; Adtran AOS R10.1.0 Command Reference Guide 60000CRG0-35E","sourceAuthority":"Adtran","namespace":"ADTRAN-AOS","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Adtran"],"products":["Adtran AOS R10.1.0","NetVanta","Total Access 900"],"technologies":["Networking","AOS CLI","SNMP","Monitoring"],"articleCategories":["Networking","Adtran","CLI","SNMP","Monitoring"],"aliases":["SNMP Agent and Monitoring Diagnostics"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":57021,"title":"Adtran AOS - QoS Policy Diagnostics","category":"Adtran","product":"Adtran AOS R10.1.0 / NetVanta / Total Access 900","tags":["Adtran","AOS","Network Appliance","QoS","DSCP","CoS"],"keywords":["Adtran AOS - QoS Policy Diagnostics","QoS and map views show classification, marking, queuing, and policy state.","Adtran","ADTRAN Operating System","AOS R10.1.0","NetVanta","Total Access 900","QoS","DSCP","CoS","show qos","show qos map","show interfaces"],"errorCode":"","eventId":"","severity":"High","summary":"QoS and map views show classification, marking, queuing, and policy state.","rootCause":"Wrong match criteria, DSCP/CoS mapping, interface application, bandwidth assumptions, or congestion can degrade priority traffic.","resolution":"1. Record the complete prompt, command mode, command, caret position or response, device model, AOS version, and timestamp.\n2. Capture QoS, maps, interface counters, and traffic evidence. Verify classification and marking hop by hop before changing queue or bandwidth policy.\n3. Use ? at the exact prompt and compare live help with the command reference for the installed release.\n4. Start with read-only show commands; review configuration, management-path impact, backup, approval, and rollback before mutation.\n5. Validate the original service and preserve sanitized evidence.","emailScript":"Hello,\n\nWe reviewed the Adtran network issue and identified Adtran AOS - QoS Policy Diagnostics.\n\nWe are validating the device model, software release, current state, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, device name, affected service, approximate time, and what changed. Do not share passwords, SNMP community strings, RADIUS secrets, VPN keys, certificates, packet captures, or an unredacted configuration.","notes":"Version scope: AOS R10.1.0 command reference, June 2012 (legacy). The supplied copy was archived through ManualsLib; current product documentation should be checked at https://docs.adtran.com/all-documentation before making a change.\n\nAOS is used across multiple Adtran NetVanta and Total Access 900 products, but commands vary by model, installed modules, feature set, license, privilege, command mode, and AOS release. A command present in this legacy guide is not proof that it is supported or secure on a current device.","commands":[{"shell":"AOS CLI","command":"show qos","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show qos map","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show interfaces","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"78d013.pdf; Adtran AOS R10.1.0 Command Reference Guide 60000CRG0-35E","sourceAuthority":"Adtran","namespace":"ADTRAN-AOS","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Adtran"],"products":["Adtran AOS R10.1.0","NetVanta","Total Access 900"],"technologies":["Networking","AOS CLI","QoS","DSCP","CoS"],"articleCategories":["Networking","Adtran","CLI","QoS","DSCP","CoS"],"aliases":["QoS Policy Diagnostics"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":57022,"title":"Adtran AOS - Voice and SIP Service Diagnostics","category":"Adtran","product":"Adtran AOS R10.1.0 / NetVanta / Total Access 900","tags":["Adtran","AOS","Network Appliance","Voice","SIP","RTP","VQM"],"keywords":["Adtran AOS - Voice and SIP Service Diagnostics","AOS supports SIP, voice trunks, lines, CODECs, VQM, and related call services on applicable products.","Adtran","ADTRAN Operating System","AOS R10.1.0","NetVanta","Total Access 900","Voice","SIP","RTP","VQM","show connections","show ip route","show interfaces"],"errorCode":"","eventId":"","severity":"High","summary":"AOS supports SIP, voice trunks, lines, CODECs, VQM, and related call services on applicable products.","rootCause":"Registration, routing, DNS, NAT, firewall, authentication, CODEC, signaling, media, clocking, or provider conditions can affect calls.","resolution":"1. Record the complete prompt, command mode, command, caret position or response, device model, AOS version, and timestamp.\n2. Capture sanitized call, trunk, line, registration, route, interface, and VQM evidence available on the exact product. Separate SIP signaling from RTP media symptoms before changing voice policy.\n3. Use ? at the exact prompt and compare live help with the command reference for the installed release.\n4. Start with read-only show commands; review configuration, management-path impact, backup, approval, and rollback before mutation.\n5. Validate the original service and preserve sanitized evidence.","emailScript":"Hello,\n\nWe reviewed the Adtran network issue and identified Adtran AOS - Voice and SIP Service Diagnostics.\n\nWe are validating the device model, software release, current state, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, device name, affected service, approximate time, and what changed. Do not share passwords, SNMP community strings, RADIUS secrets, VPN keys, certificates, packet captures, or an unredacted configuration.","notes":"Version scope: AOS R10.1.0 command reference, June 2012 (legacy). The supplied copy was archived through ManualsLib; current product documentation should be checked at https://docs.adtran.com/all-documentation before making a change.\n\nAOS is used across multiple Adtran NetVanta and Total Access 900 products, but commands vary by model, installed modules, feature set, license, privilege, command mode, and AOS release. A command present in this legacy guide is not proof that it is supported or secure on a current device.","commands":[{"shell":"AOS CLI","command":"show connections","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show ip route","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"AOS CLI","command":"show interfaces","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"78d013.pdf; Adtran AOS R10.1.0 Command Reference Guide 60000CRG0-35E","sourceAuthority":"Adtran","namespace":"ADTRAN-AOS","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Adtran"],"products":["Adtran AOS R10.1.0","NetVanta","Total Access 900"],"technologies":["Networking","AOS CLI","Voice","SIP","RTP","VQM"],"articleCategories":["Networking","Adtran","CLI","Voice","SIP","RTP","VQM"],"aliases":["Voice and SIP Service Diagnostics"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":58000,"title":"api.authentication.missing-credentials - Missing Credentials","category":"Ubiquiti","product":"UniFi Network API v9.3.43","tags":["Ubiquiti","UniFi","Network Appliance","API","Authentication","HTTP 401"],"keywords":["api.authentication.missing-credentials - Missing Credentials","UniFi Network API v9.3.43","The API request did not include usable authentication credentials.","api.authentication.missing-credentials","Ubiquiti","UniFi","UniFi OS","UDM","Dream Machine","API","Authentication","HTTP 401"],"errorCode":"api.authentication.missing-credentials","eventId":"","severity":"High","summary":"The API request did not include usable authentication credentials.","rootCause":"The X-API-Key header is absent, empty, expired, invalid, or supplied to the wrong endpoint.","resolution":"1. Record the exact message or LED sequence, device model, UniFi OS and application versions, timestamp, and the operation being attempted.\n2. Verify the endpoint and API-key header without logging the secret. Replace or reissue the key if necessary, then retry one request.\n3. Preserve a current backup and management access before configuration changes, firmware recovery, or reset actions.\n4. Validate adoption, internet access, affected services, and matching logs after the correction.","emailScript":"Hello,\n\nWe reviewed the Ubiquiti UniFi issue and identified api.authentication.missing-credentials - Missing Credentials.\n\nWe are checking the device state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message or a short video of the LED pattern, the device model, approximate time, and what stopped working. Do not factory-reset the device unless instructed; a reset can remove configuration.","notes":"Source: UniFi Network API v9.3.43 Errors.\nVerified: 2026-08-10.\n\nLED meanings are model-specific and animation speed can vary. API failures should retain the sanitized status code, API code, message, timestamp, request path, and request/trace ID. Never include API keys, credentials, private addresses, or an unredacted support file in a ticket.","commands":[],"sourceDocument":"UniFi Network API v9.3.43 Errors","sourceAuthority":"Ubiquiti","namespace":"UBIQUITI-UNIFI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ubiquiti"],"technologies":["Networking","UniFi","API","Authentication","HTTP 401"],"articleCategories":["Networking","Ubiquiti","API","Authentication","HTTP 401"],"aliases":["api.authentication.missing-credentials","api.authentication.missing-credentials - Missing Credentials"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":58001,"title":"api.rate-limit.exceeded - Rate Limit Exceeded","category":"Ubiquiti","product":"UniFi Network API v9.3.43","tags":["Ubiquiti","UniFi","Network Appliance","API","HTTP 429","Rate Limit"],"keywords":["api.rate-limit.exceeded - Rate Limit Exceeded","UniFi Network API v9.3.43","The request rate exceeded the API allowance.","api.rate-limit.exceeded","Ubiquiti","UniFi","UniFi OS","UDM","Dream Machine","API","HTTP 429","Rate Limit"],"errorCode":"api.rate-limit.exceeded","eventId":"","severity":"Medium","summary":"The request rate exceeded the API allowance.","rootCause":"A client is sending too many requests, retrying in a tight loop, or failing to honor server rate-limit guidance.","resolution":"1. Record the exact message or LED sequence, device model, UniFi OS and application versions, timestamp, and the operation being attempted.\n2. Pause requests, honor Retry-After when present, and implement exponential backoff with jitter. Reduce polling and retry only idempotent operations.\n3. Preserve a current backup and management access before configuration changes, firmware recovery, or reset actions.\n4. Validate adoption, internet access, affected services, and matching logs after the correction.","emailScript":"Hello,\n\nWe reviewed the Ubiquiti UniFi issue and identified api.rate-limit.exceeded - Rate Limit Exceeded.\n\nWe are checking the device state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message or a short video of the LED pattern, the device model, approximate time, and what stopped working. Do not factory-reset the device unless instructed; a reset can remove configuration.","notes":"Source: UniFi Network API v9.3.43 Errors.\nVerified: 2026-08-10.\n\nLED meanings are model-specific and animation speed can vary. API failures should retain the sanitized status code, API code, message, timestamp, request path, and request/trace ID. Never include API keys, credentials, private addresses, or an unredacted support file in a ticket.","commands":[],"sourceDocument":"UniFi Network API v9.3.43 Errors","sourceAuthority":"Ubiquiti","namespace":"UBIQUITI-UNIFI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ubiquiti"],"technologies":["Networking","UniFi","API","HTTP 429","Rate Limit"],"articleCategories":["Networking","Ubiquiti","API","HTTP 429","Rate Limit"],"aliases":["api.rate-limit.exceeded","api.rate-limit.exceeded - Rate Limit Exceeded"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":58002,"title":"UniFi API 400 - Bad Request","category":"Ubiquiti","product":"UniFi Network API v9.3.43","tags":["Ubiquiti","UniFi","Network Appliance","API","Bad Request"],"keywords":["UniFi API 400 - Bad Request","UniFi Network API v9.3.43","The API rejected an improperly formed request or invalid parameter.","400","Ubiquiti","UniFi","UniFi OS","UDM","Dream Machine","API","Bad Request"],"errorCode":"400","eventId":"","severity":"Medium","summary":"The API rejected an improperly formed request or invalid parameter.","rootCause":"Malformed JSON, an invalid identifier or value, missing required data, or an endpoint/version mismatch can produce HTTP 400.","resolution":"1. Record the exact message or LED sequence, device model, UniFi OS and application versions, timestamp, and the operation being attempted.\n2. Compare the method, path, headers, content type, and sanitized body with the versioned API schema; correct the invalid field and retry.\n3. Preserve a current backup and management access before configuration changes, firmware recovery, or reset actions.\n4. Validate adoption, internet access, affected services, and matching logs after the correction.","emailScript":"Hello,\n\nWe reviewed the Ubiquiti UniFi issue and identified UniFi API 400 - Bad Request.\n\nWe are checking the device state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message or a short video of the LED pattern, the device model, approximate time, and what stopped working. Do not factory-reset the device unless instructed; a reset can remove configuration.","notes":"Source: UniFi Network API v9.3.43 Errors.\nVerified: 2026-08-10.\n\nLED meanings are model-specific and animation speed can vary. API failures should retain the sanitized status code, API code, message, timestamp, request path, and request/trace ID. Never include API keys, credentials, private addresses, or an unredacted support file in a ticket.","commands":[],"sourceDocument":"UniFi Network API v9.3.43 Errors","sourceAuthority":"Ubiquiti","namespace":"UBIQUITI-UNIFI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ubiquiti"],"technologies":["Networking","UniFi","API","Bad Request"],"articleCategories":["Networking","Ubiquiti","API","Bad Request"],"aliases":["400","API 400 - Bad Request"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":58003,"title":"UniFi API 401 - Unauthorized","category":"Ubiquiti","product":"UniFi Network API v9.3.43","tags":["Ubiquiti","UniFi","Network Appliance","API","Authentication"],"keywords":["UniFi API 401 - Unauthorized","UniFi Network API v9.3.43","The API could not authenticate the request.","401","Ubiquiti","UniFi","UniFi OS","UDM","Dream Machine","API","Authentication"],"errorCode":"401","eventId":"","severity":"High","summary":"The API could not authenticate the request.","rootCause":"The API key can be missing, invalid, expired, revoked, or sent using the wrong header.","resolution":"1. Record the exact message or LED sequence, device model, UniFi OS and application versions, timestamp, and the operation being attempted.\n2. Verify X-API-Key placement, key status, account, console, and endpoint. Rotate an exposed key rather than reusing it.\n3. Preserve a current backup and management access before configuration changes, firmware recovery, or reset actions.\n4. Validate adoption, internet access, affected services, and matching logs after the correction.","emailScript":"Hello,\n\nWe reviewed the Ubiquiti UniFi issue and identified UniFi API 401 - Unauthorized.\n\nWe are checking the device state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message or a short video of the LED pattern, the device model, approximate time, and what stopped working. Do not factory-reset the device unless instructed; a reset can remove configuration.","notes":"Source: UniFi Network API v9.3.43 Errors.\nVerified: 2026-08-10.\n\nLED meanings are model-specific and animation speed can vary. API failures should retain the sanitized status code, API code, message, timestamp, request path, and request/trace ID. Never include API keys, credentials, private addresses, or an unredacted support file in a ticket.","commands":[],"sourceDocument":"UniFi Network API v9.3.43 Errors","sourceAuthority":"Ubiquiti","namespace":"UBIQUITI-UNIFI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ubiquiti"],"technologies":["Networking","UniFi","API","Authentication"],"articleCategories":["Networking","Ubiquiti","API","Authentication"],"aliases":["401","API 401 - Unauthorized"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":58004,"title":"UniFi API 403 - Forbidden","category":"Ubiquiti","product":"UniFi Network API v9.3.43","tags":["Ubiquiti","UniFi","Network Appliance","API","Authorization"],"keywords":["UniFi API 403 - Forbidden","UniFi Network API v9.3.43","Authentication succeeded, but the caller is not permitted to perform the operation.","403","Ubiquiti","UniFi","UniFi OS","UDM","Dream Machine","API","Authorization"],"errorCode":"403","eventId":"","severity":"High","summary":"Authentication succeeded, but the caller is not permitted to perform the operation.","rootCause":"The key owner, role, application scope, site access, or read/write permission does not cover the requested resource.","resolution":"1. Record the exact message or LED sequence, device model, UniFi OS and application versions, timestamp, and the operation being attempted.\n2. Confirm the key owner and least-privilege permissions for the target console, site, application, and operation; do not work around authorization controls.\n3. Preserve a current backup and management access before configuration changes, firmware recovery, or reset actions.\n4. Validate adoption, internet access, affected services, and matching logs after the correction.","emailScript":"Hello,\n\nWe reviewed the Ubiquiti UniFi issue and identified UniFi API 403 - Forbidden.\n\nWe are checking the device state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message or a short video of the LED pattern, the device model, approximate time, and what stopped working. Do not factory-reset the device unless instructed; a reset can remove configuration.","notes":"Source: UniFi Network API v9.3.43 Errors.\nVerified: 2026-08-10.\n\nLED meanings are model-specific and animation speed can vary. API failures should retain the sanitized status code, API code, message, timestamp, request path, and request/trace ID. Never include API keys, credentials, private addresses, or an unredacted support file in a ticket.","commands":[],"sourceDocument":"UniFi Network API v9.3.43 Errors","sourceAuthority":"Ubiquiti","namespace":"UBIQUITI-UNIFI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ubiquiti"],"technologies":["Networking","UniFi","API","Authorization"],"articleCategories":["Networking","Ubiquiti","API","Authorization"],"aliases":["403","API 403 - Forbidden"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":58005,"title":"UniFi API 404 - Resource Not Found","category":"Ubiquiti","product":"UniFi Network API v9.3.43","tags":["Ubiquiti","UniFi","Network Appliance","API","Not Found"],"keywords":["UniFi API 404 - Resource Not Found","UniFi Network API v9.3.43","The requested UniFi API resource or endpoint could not be found.","404","Ubiquiti","UniFi","UniFi OS","UDM","Dream Machine","API","Not Found"],"errorCode":"404","eventId":"","severity":"Medium","summary":"The requested UniFi API resource or endpoint could not be found.","rootCause":"A stale site/device ID, deleted object, wrong API version, or incorrect request path is common.","resolution":"1. Record the exact message or LED sequence, device model, UniFi OS and application versions, timestamp, and the operation being attempted.\n2. List the parent collection, verify the resource identifier and versioned path, and account for deletion or moved resources before retrying.\n3. Preserve a current backup and management access before configuration changes, firmware recovery, or reset actions.\n4. Validate adoption, internet access, affected services, and matching logs after the correction.","emailScript":"Hello,\n\nWe reviewed the Ubiquiti UniFi issue and identified UniFi API 404 - Resource Not Found.\n\nWe are checking the device state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message or a short video of the LED pattern, the device model, approximate time, and what stopped working. Do not factory-reset the device unless instructed; a reset can remove configuration.","notes":"Source: UniFi Network API v9.3.43 Errors.\nVerified: 2026-08-10.\n\nLED meanings are model-specific and animation speed can vary. API failures should retain the sanitized status code, API code, message, timestamp, request path, and request/trace ID. Never include API keys, credentials, private addresses, or an unredacted support file in a ticket.","commands":[],"sourceDocument":"UniFi Network API v9.3.43 Errors","sourceAuthority":"Ubiquiti","namespace":"UBIQUITI-UNIFI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ubiquiti"],"technologies":["Networking","UniFi","API","Not Found"],"articleCategories":["Networking","Ubiquiti","API","Not Found"],"aliases":["404","API 404 - Resource Not Found"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":58006,"title":"UniFi API 408 - Connector Request Timeout","category":"Ubiquiti","product":"UniFi Network API Connector","tags":["Ubiquiti","UniFi","Network Appliance","API","Timeout","Connector"],"keywords":["UniFi API 408 - Connector Request Timeout","UniFi Network API Connector","A proxied request did not complete within the connector time limit.","408","Ubiquiti","UniFi","UniFi OS","UDM","Dream Machine","API","Timeout","Connector"],"errorCode":"408","eventId":"","severity":"High","summary":"A proxied request did not complete within the connector time limit.","rootCause":"The remote console, application, upstream path, or requested operation is slow or unreachable.","resolution":"1. Record the exact message or LED sequence, device model, UniFi OS and application versions, timestamp, and the operation being attempted.\n2. Check console/application health and connectivity, reduce request scope, and retry an idempotent request with bounded backoff; avoid blindly retrying writes.\n3. Preserve a current backup and management access before configuration changes, firmware recovery, or reset actions.\n4. Validate adoption, internet access, affected services, and matching logs after the correction.","emailScript":"Hello,\n\nWe reviewed the Ubiquiti UniFi issue and identified UniFi API 408 - Connector Request Timeout.\n\nWe are checking the device state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message or a short video of the LED pattern, the device model, approximate time, and what stopped working. Do not factory-reset the device unless instructed; a reset can remove configuration.","notes":"Source: UniFi Network API v9.3.43 Connector documentation.\nVerified: 2026-08-10.\n\nLED meanings are model-specific and animation speed can vary. API failures should retain the sanitized status code, API code, message, timestamp, request path, and request/trace ID. Never include API keys, credentials, private addresses, or an unredacted support file in a ticket.","commands":[],"sourceDocument":"UniFi Network API v9.3.43 Connector documentation","sourceAuthority":"Ubiquiti","namespace":"UBIQUITI-UNIFI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ubiquiti"],"technologies":["Networking","UniFi","API","Timeout","Connector"],"articleCategories":["Networking","Ubiquiti","API","Timeout","Connector"],"aliases":["408","API 408 - Connector Request Timeout"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":58007,"title":"UniFi API 500 - Internal Server Error","category":"Ubiquiti","product":"UniFi Network API v9.3.43","tags":["Ubiquiti","UniFi","Network Appliance","API","Server Error","requestId"],"keywords":["UniFi API 500 - Internal Server Error","UniFi Network API v9.3.43","The service encountered an unexpected internal failure.","500","Ubiquiti","UniFi","UniFi OS","UDM","Dream Machine","API","Server Error","requestId"],"errorCode":"500","eventId":"","severity":"High","summary":"The service encountered an unexpected internal failure.","rootCause":"A server-side application fault, transient dependency failure, or software defect can return HTTP 500.","resolution":"1. Record the exact message or LED sequence, device model, UniFi OS and application versions, timestamp, and the operation being attempted.\n2. Retain the requestId, timestamp, requestPath, API/application version, and sanitized response. Retry safely with backoff, then provide the requestId to Ubiquiti support if persistent.\n3. Preserve a current backup and management access before configuration changes, firmware recovery, or reset actions.\n4. Validate adoption, internet access, affected services, and matching logs after the correction.","emailScript":"Hello,\n\nWe reviewed the Ubiquiti UniFi issue and identified UniFi API 500 - Internal Server Error.\n\nWe are checking the device state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message or a short video of the LED pattern, the device model, approximate time, and what stopped working. Do not factory-reset the device unless instructed; a reset can remove configuration.","notes":"Source: UniFi Network API v9.3.43 Errors.\nVerified: 2026-08-10.\n\nLED meanings are model-specific and animation speed can vary. API failures should retain the sanitized status code, API code, message, timestamp, request path, and request/trace ID. Never include API keys, credentials, private addresses, or an unredacted support file in a ticket.","commands":[],"sourceDocument":"UniFi Network API v9.3.43 Errors","sourceAuthority":"Ubiquiti","namespace":"UBIQUITI-UNIFI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ubiquiti"],"technologies":["Networking","UniFi","API","Server Error","requestId"],"articleCategories":["Networking","Ubiquiti","API","Server Error","requestId"],"aliases":["500","API 500 - Internal Server Error"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":58008,"title":"UniFi API 502 - Bad Gateway","category":"Ubiquiti","product":"UniFi Network API Connector","tags":["Ubiquiti","UniFi","Network Appliance","API","Bad Gateway","Connector"],"keywords":["UniFi API 502 - Bad Gateway","UniFi Network API Connector","The connector received an invalid response from an upstream console or application.","502","Ubiquiti","UniFi","UniFi OS","UDM","Dream Machine","API","Bad Gateway","Connector"],"errorCode":"502","eventId":"","severity":"High","summary":"The connector received an invalid response from an upstream console or application.","rootCause":"The remote console/application can be unavailable, restarting, incompatible, or unable to return a valid response.","resolution":"1. Record the exact message or LED sequence, device model, UniFi OS and application versions, timestamp, and the operation being attempted.\n2. Check remote console reachability, UniFi application state, versions, and service incidents. Retry safe requests with backoff and preserve the request ID.\n3. Preserve a current backup and management access before configuration changes, firmware recovery, or reset actions.\n4. Validate adoption, internet access, affected services, and matching logs after the correction.","emailScript":"Hello,\n\nWe reviewed the Ubiquiti UniFi issue and identified UniFi API 502 - Bad Gateway.\n\nWe are checking the device state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message or a short video of the LED pattern, the device model, approximate time, and what stopped working. Do not factory-reset the device unless instructed; a reset can remove configuration.","notes":"Source: UniFi Network API v9.3.43 Connector documentation.\nVerified: 2026-08-10.\n\nLED meanings are model-specific and animation speed can vary. API failures should retain the sanitized status code, API code, message, timestamp, request path, and request/trace ID. Never include API keys, credentials, private addresses, or an unredacted support file in a ticket.","commands":[],"sourceDocument":"UniFi Network API v9.3.43 Connector documentation","sourceAuthority":"Ubiquiti","namespace":"UBIQUITI-UNIFI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ubiquiti"],"technologies":["Networking","UniFi","API","Bad Gateway","Connector"],"articleCategories":["Networking","Ubiquiti","API","Bad Gateway","Connector"],"aliases":["502","API 502 - Bad Gateway"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":58009,"title":"UniFi Gateway Configuration Commit Error","category":"Ubiquiti","product":"UniFi Cloud Gateway / UDM","tags":["Ubiquiti","UniFi","Network Appliance","Gateway","Commit Error","Firewall","Routing"],"keywords":["UniFi Gateway Configuration Commit Error","UniFi Cloud Gateway / UDM","A gateway configuration change failed to commit, so the intended firewall, IP set, route, or related setting may not be active.","Ubiquiti","UniFi","UniFi OS","UDM","Dream Machine","Gateway","Commit Error","Firewall","Routing"],"errorCode":"","eventId":"","severity":"High","summary":"A gateway configuration change failed to commit, so the intended firewall, IP set, route, or related setting may not be active.","rootCause":"Conflicting objects, invalid or unsupported configuration, stale state, or an application defect can cause the generated configuration to fail.","resolution":"1. Record the exact message or LED sequence, device model, UniFi OS and application versions, timestamp, and the operation being attempted.\n2. Capture the complete commit error and recent change, verify the running state, and revert only the implicated change through the supported interface. Update supported software and escalate with sanitized support data if repeatable.\n3. Preserve a current backup and management access before configuration changes, firmware recovery, or reset actions.\n4. Validate adoption, internet access, affected services, and matching logs after the correction.","emailScript":"Hello,\n\nWe reviewed the Ubiquiti UniFi issue and identified UniFi Gateway Configuration Commit Error.\n\nWe are checking the device state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message or a short video of the LED pattern, the device model, approximate time, and what stopped working. Do not factory-reset the device unless instructed; a reset can remove configuration.","notes":"Source: Ubiquiti Community report; technician guidance.\nVerified: 2026-08-10.\n\nLED meanings are model-specific and animation speed can vary. API failures should retain the sanitized status code, API code, message, timestamp, request path, and request/trace ID. Never include API keys, credentials, private addresses, or an unredacted support file in a ticket.","commands":[],"sourceDocument":"Ubiquiti Community report; technician guidance","sourceAuthority":"Ubiquiti","namespace":"UBIQUITI-UNIFI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ubiquiti"],"technologies":["Networking","UniFi","Gateway","Commit Error","Firewall","Routing"],"articleCategories":["Networking","Ubiquiti","Gateway","Commit Error","Firewall","Routing"],"aliases":["Gateway Configuration Commit Error"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":58010,"title":"UniFi Setup - Unexpected Error","category":"Ubiquiti","product":"UniFi Cloud Gateway / UDM","tags":["Ubiquiti","UniFi","Network Appliance","Setup","Adoption","Provisioning","Recovery"],"keywords":["UniFi Setup - Unexpected Error","UniFi Cloud Gateway / UDM","Initial setup or adoption stopped with an unexpected-error message.","Ubiquiti","UniFi","UniFi OS","UDM","Dream Machine","Setup","Adoption","Provisioning","Recovery"],"errorCode":"","eventId":"","severity":"High","summary":"Initial setup or adoption stopped with an unexpected-error message.","rootCause":"Connectivity, account access, provisioning state, firmware, service availability, or incomplete prior setup can interrupt onboarding.","resolution":"1. Record the exact message or LED sequence, device model, UniFi OS and application versions, timestamp, and the operation being attempted.\n2. Confirm WAN, DNS, time, account access, and service status; power-cycle once and retry. Use official recovery guidance only if setup remains blocked, preserving or exporting any available backup before reset.\n3. Preserve a current backup and management access before configuration changes, firmware recovery, or reset actions.\n4. Validate adoption, internet access, affected services, and matching logs after the correction.","emailScript":"Hello,\n\nWe reviewed the Ubiquiti UniFi issue and identified UniFi Setup - Unexpected Error.\n\nWe are checking the device state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message or a short video of the LED pattern, the device model, approximate time, and what stopped working. Do not factory-reset the device unless instructed; a reset can remove configuration.","notes":"Source: Ubiquiti Community report; Ubiquiti recovery guidance.\nVerified: 2026-08-10.\n\nLED meanings are model-specific and animation speed can vary. API failures should retain the sanitized status code, API code, message, timestamp, request path, and request/trace ID. Never include API keys, credentials, private addresses, or an unredacted support file in a ticket.","commands":[],"sourceDocument":"Ubiquiti Community report; Ubiquiti recovery guidance","sourceAuthority":"Ubiquiti","namespace":"UBIQUITI-UNIFI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ubiquiti"],"technologies":["Networking","UniFi","Setup","Adoption","Provisioning","Recovery"],"articleCategories":["Networking","Ubiquiti","Setup","Adoption","Provisioning","Recovery"],"aliases":["Setup - Unexpected Error"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":58011,"title":"UniFi LED - Flashing White / Off","category":"Ubiquiti","product":"UniFi devices and UDM base model","tags":["Ubiquiti","UniFi","Network Appliance","LED","Boot","Initializing"],"keywords":["UniFi LED - Flashing White / Off","UniFi devices and UDM base model","A white/off flash about every half-second indicates that the device is initializing and booting.","Ubiquiti","UniFi","UniFi OS","UDM","Dream Machine","LED","Boot","Initializing"],"errorCode":"","eventId":"","severity":"Low","summary":"A white/off flash about every half-second indicates that the device is initializing and booting.","rootCause":"This is normally a transitional boot state; an unusually long duration can indicate power, firmware, storage, or boot trouble.","resolution":"1. Record the exact message or LED sequence, device model, UniFi OS and application versions, timestamp, and the operation being attempted.\n2. Allow boot to complete without interruption. If the pattern persists beyond the model's normal startup time, verify stable power and consult the model guide or Ubiquiti support before recovery.\n3. Preserve a current backup and management access before configuration changes, firmware recovery, or reset actions.\n4. Validate adoption, internet access, affected services, and matching logs after the correction.","emailScript":"Hello,\n\nWe reviewed the Ubiquiti UniFi issue and identified UniFi LED - Flashing White / Off.\n\nWe are checking the device state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message or a short video of the LED pattern, the device model, approximate time, and what stopped working. Do not factory-reset the device unless instructed; a reset can remove configuration.","notes":"Source: Ubiquiti Help Center - Understanding Device LED Status Indicators.\nVerified: 2026-08-10.\n\nLED meanings are model-specific and animation speed can vary. API failures should retain the sanitized status code, API code, message, timestamp, request path, and request/trace ID. Never include API keys, credentials, private addresses, or an unredacted support file in a ticket.","commands":[],"sourceDocument":"Ubiquiti Help Center - Understanding Device LED Status Indicators","sourceAuthority":"Ubiquiti","namespace":"UBIQUITI-UNIFI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ubiquiti"],"technologies":["Networking","UniFi","LED","Boot","Initializing"],"articleCategories":["Networking","Ubiquiti","LED","Boot","Initializing"],"aliases":["LED - Flashing White / Off"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":58012,"title":"UniFi LED - Steady White","category":"Ubiquiti","product":"UniFi devices and UDM base model","tags":["Ubiquiti","UniFi","Network Appliance","LED","Adoption","Factory Default"],"keywords":["UniFi LED - Steady White","UniFi devices and UDM base model","A steady white status LED means the device is ready for adoption.","Ubiquiti","UniFi","UniFi OS","UDM","Dream Machine","LED","Adoption","Factory Default"],"errorCode":"","eventId":"","severity":"Low","summary":"A steady white status LED means the device is ready for adoption.","rootCause":"The device is at factory-default or otherwise awaiting adoption by a UniFi application.","resolution":"1. Record the exact message or LED sequence, device model, UniFi OS and application versions, timestamp, and the operation being attempted.\n2. Open the authorized UniFi application, confirm Layer 2/3 reachability and inform/adoption requirements, then adopt the intended device into the correct site.\n3. Preserve a current backup and management access before configuration changes, firmware recovery, or reset actions.\n4. Validate adoption, internet access, affected services, and matching logs after the correction.","emailScript":"Hello,\n\nWe reviewed the Ubiquiti UniFi issue and identified UniFi LED - Steady White.\n\nWe are checking the device state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message or a short video of the LED pattern, the device model, approximate time, and what stopped working. Do not factory-reset the device unless instructed; a reset can remove configuration.","notes":"Source: Ubiquiti Help Center - Understanding Device LED Status Indicators.\nVerified: 2026-08-10.\n\nLED meanings are model-specific and animation speed can vary. API failures should retain the sanitized status code, API code, message, timestamp, request path, and request/trace ID. Never include API keys, credentials, private addresses, or an unredacted support file in a ticket.","commands":[],"sourceDocument":"Ubiquiti Help Center - Understanding Device LED Status Indicators","sourceAuthority":"Ubiquiti","namespace":"UBIQUITI-UNIFI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ubiquiti"],"technologies":["Networking","UniFi","LED","Adoption","Factory Default"],"articleCategories":["Networking","Ubiquiti","LED","Adoption","Factory Default"],"aliases":["LED - Steady White"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":58013,"title":"UniFi LED - Steady Blue","category":"Ubiquiti","product":"UniFi devices and UDM base model","tags":["Ubiquiti","UniFi","Network Appliance","LED","Normal","Adopted"],"keywords":["UniFi LED - Steady Blue","UniFi devices and UDM base model","A steady blue LED means the device is adopted and in normal operating mode.","Ubiquiti","UniFi","UniFi OS","UDM","Dream Machine","LED","Normal","Adopted"],"errorCode":"","eventId":"","severity":"Low","summary":"A steady blue LED means the device is adopted and in normal operating mode.","rootCause":"This is a normal status indication and does not by itself prove every client or upstream service is healthy.","resolution":"1. Record the exact message or LED sequence, device model, UniFi OS and application versions, timestamp, and the operation being attempted.\n2. If users still report trouble, troubleshoot the affected service, client, uplink, VLAN, or internet path rather than treating the steady blue LED as an error.\n3. Preserve a current backup and management access before configuration changes, firmware recovery, or reset actions.\n4. Validate adoption, internet access, affected services, and matching logs after the correction.","emailScript":"Hello,\n\nWe reviewed the Ubiquiti UniFi issue and identified UniFi LED - Steady Blue.\n\nWe are checking the device state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message or a short video of the LED pattern, the device model, approximate time, and what stopped working. Do not factory-reset the device unless instructed; a reset can remove configuration.","notes":"Source: Ubiquiti Help Center - Understanding Device LED Status Indicators.\nVerified: 2026-08-10.\n\nLED meanings are model-specific and animation speed can vary. API failures should retain the sanitized status code, API code, message, timestamp, request path, and request/trace ID. Never include API keys, credentials, private addresses, or an unredacted support file in a ticket.","commands":[],"sourceDocument":"Ubiquiti Help Center - Understanding Device LED Status Indicators","sourceAuthority":"Ubiquiti","namespace":"UBIQUITI-UNIFI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ubiquiti"],"technologies":["Networking","UniFi","LED","Normal","Adopted"],"articleCategories":["Networking","Ubiquiti","LED","Normal","Adopted"],"aliases":["LED - Steady Blue"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":58014,"title":"UDM LED - Blue and Off Every 5 Seconds","category":"Ubiquiti","product":"UniFi Dream Machine","tags":["Ubiquiti","UniFi","Network Appliance","LED","UDM","WAN","Internet"],"keywords":["UDM LED - Blue and Off Every 5 Seconds","UniFi Dream Machine","A UDM blue LED that flashes off every five seconds indicates no internet connection.","Ubiquiti","UniFi","UniFi OS","UDM","Dream Machine","LED","UDM","WAN","Internet"],"errorCode":"","eventId":"","severity":"High","summary":"A UDM blue LED that flashes off every five seconds indicates no internet connection.","rootCause":"WAN link, addressing, authentication, modem/ONT, ISP service, DNS, routing, or gateway configuration can prevent internet access.","resolution":"1. Record the exact message or LED sequence, device model, UniFi OS and application versions, timestamp, and the operation being attempted.\n2. Check WAN physical state, assigned address, upstream modem/ONT and ISP status, then validate routing and DNS. Avoid factory reset for an upstream outage.\n3. Preserve a current backup and management access before configuration changes, firmware recovery, or reset actions.\n4. Validate adoption, internet access, affected services, and matching logs after the correction.","emailScript":"Hello,\n\nWe reviewed the Ubiquiti UniFi issue and identified UDM LED - Blue and Off Every 5 Seconds.\n\nWe are checking the device state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message or a short video of the LED pattern, the device model, approximate time, and what stopped working. Do not factory-reset the device unless instructed; a reset can remove configuration.","notes":"Source: Ubiquiti Help Center - Understanding Device LED Status Indicators.\nVerified: 2026-08-10.\n\nLED meanings are model-specific and animation speed can vary. API failures should retain the sanitized status code, API code, message, timestamp, request path, and request/trace ID. Never include API keys, credentials, private addresses, or an unredacted support file in a ticket.","commands":[],"sourceDocument":"Ubiquiti Help Center - Understanding Device LED Status Indicators","sourceAuthority":"Ubiquiti","namespace":"UBIQUITI-UNIFI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ubiquiti"],"technologies":["Networking","UniFi","LED","UDM","WAN","Internet"],"articleCategories":["Networking","Ubiquiti","LED","UDM","WAN","Internet"],"aliases":["UDM LED - Blue and Off Every 5 Seconds"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":58015,"title":"UniFi LED - Flashing White-Blue-Off","category":"Ubiquiti","product":"UniFi devices","tags":["Ubiquiti","UniFi","Network Appliance","LED","TFTP","Recovery"],"keywords":["UniFi LED - Flashing White-Blue-Off","UniFi devices","The white-blue-off sequence indicates TFTP mode.","Ubiquiti","UniFi","UniFi OS","UDM","Dream Machine","LED","TFTP","Recovery"],"errorCode":"","eventId":"","severity":"High","summary":"The white-blue-off sequence indicates TFTP mode.","rootCause":"The reset button was held during power-on, the button is jammed, or recovery mode was intentionally entered.","resolution":"1. Record the exact message or LED sequence, device model, UniFi OS and application versions, timestamp, and the operation being attempted.\n2. If unintentional, verify the reset button moves freely and restart normally. If recovery is required, follow the exact official procedure and firmware for the model; do not interrupt flashing.\n3. Preserve a current backup and management access before configuration changes, firmware recovery, or reset actions.\n4. Validate adoption, internet access, affected services, and matching logs after the correction.","emailScript":"Hello,\n\nWe reviewed the Ubiquiti UniFi issue and identified UniFi LED - Flashing White-Blue-Off.\n\nWe are checking the device state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message or a short video of the LED pattern, the device model, approximate time, and what stopped working. Do not factory-reset the device unless instructed; a reset can remove configuration.","notes":"Source: Ubiquiti Help Center - Understanding Device LED Status Indicators.\nVerified: 2026-08-10.\n\nLED meanings are model-specific and animation speed can vary. API failures should retain the sanitized status code, API code, message, timestamp, request path, and request/trace ID. Never include API keys, credentials, private addresses, or an unredacted support file in a ticket.","commands":[],"sourceDocument":"Ubiquiti Help Center - Understanding Device LED Status Indicators","sourceAuthority":"Ubiquiti","namespace":"UBIQUITI-UNIFI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ubiquiti"],"technologies":["Networking","UniFi","LED","TFTP","Recovery"],"articleCategories":["Networking","Ubiquiti","LED","TFTP","Recovery"],"aliases":["LED - Flashing White-Blue-Off"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":58016,"title":"UniFi LED - Off","category":"Ubiquiti","product":"UniFi devices","tags":["Ubiquiti","UniFi","Network Appliance","LED","Offline","PoE","Power"],"keywords":["UniFi LED - Off","UniFi devices","An unlit status LED can indicate that the device is offline.","Ubiquiti","UniFi","UniFi OS","UDM","Dream Machine","LED","Offline","PoE","Power"],"errorCode":"","eventId":"","severity":"High","summary":"An unlit status LED can indicate that the device is offline.","rootCause":"Loss of power, PoE, cabling, port link, upstream switching, or hardware failure can leave the device offline; configured LED disablement must also be considered.","resolution":"1. Record the exact message or LED sequence, device model, UniFi OS and application versions, timestamp, and the operation being attempted.\n2. Verify that LEDs were not disabled, then check power or PoE budget, injector, Ethernet cable, switch port, and model-specific hardware guidance with known-good components.\n3. Preserve a current backup and management access before configuration changes, firmware recovery, or reset actions.\n4. Validate adoption, internet access, affected services, and matching logs after the correction.","emailScript":"Hello,\n\nWe reviewed the Ubiquiti UniFi issue and identified UniFi LED - Off.\n\nWe are checking the device state, software version, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network change or if a maintenance window is required.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message or a short video of the LED pattern, the device model, approximate time, and what stopped working. Do not factory-reset the device unless instructed; a reset can remove configuration.","notes":"Source: Ubiquiti Help Center - Understanding Device LED Status Indicators.\nVerified: 2026-08-10.\n\nLED meanings are model-specific and animation speed can vary. API failures should retain the sanitized status code, API code, message, timestamp, request path, and request/trace ID. Never include API keys, credentials, private addresses, or an unredacted support file in a ticket.","commands":[],"sourceDocument":"Ubiquiti Help Center - Understanding Device LED Status Indicators","sourceAuthority":"Ubiquiti","namespace":"UBIQUITI-UNIFI","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Ubiquiti"],"technologies":["Networking","UniFi","LED","Offline","PoE","Power"],"articleCategories":["Networking","Ubiquiti","LED","Offline","PoE","Power"],"aliases":["LED - Off"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":59000,"title":"Verkada API 200 - OK","category":"Verkada","product":"Verkada API","tags":["Verkada","Command","Physical Security","Network Appliance","API","Success"],"keywords":["Verkada API 200 - OK","The Verkada API successfully processed the request.","200","Verkada","Verkada Command","camera","cloud camera","PoE","API","Success"],"errorCode":"200","eventId":"","severity":"Low","summary":"The Verkada API successfully processed the request.","rootCause":"This is a success response rather than a fault; an empty or unexpected result can still reflect filters, permissions, pagination, or resource state.","resolution":"1. Record the exact API response or LED color/count sequence, camera model and serial, Command status, timestamp, and recent change.\n2. Validate the returned schema, identifiers, pagination, and expected data before treating the workflow as complete.\n3. Use a known-good, correctly rated PoE source, short patch cable, and switch port when isolation is required.\n4. Validate recording, Command connectivity, live view, time, and the original operation after correction.","emailScript":"Hello,\n\nWe reviewed the Verkada issue and identified Verkada API 200 - OK.\n\nWe are checking camera power, network connectivity, cloud communication, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network or firewall change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact LED colors and number of flashes, camera model, approximate time, and what appears in Verkada Command. Do not share API keys, support tokens, footage, credentials, or unrestricted camera links.","notes":"Source: Verkada API General Troubleshooting.\nScope: Verkada API.\nVerified: 2026-08-10.\n\nLED behavior varies by device family and firmware. Do not infer a camera error from access-controller, gateway, intercom, or third-party-lock LEDs. API evidence must be sanitized; rotate exposed keys and restrict footage/support-token access.","commands":[],"sourceDocument":"Verkada API General Troubleshooting","sourceAuthority":"Verkada","namespace":"VERKADA","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Verkada"],"technologies":["Physical Security","Video Surveillance","Networking","API","Success"],"articleCategories":["Networking","Verkada","Cameras","API","Success"],"aliases":["200","API 200 - OK"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":59001,"title":"Verkada API 400 - Bad Request","category":"Verkada","product":"Verkada API","tags":["Verkada","Command","Physical Security","Network Appliance","API","Bad Request"],"keywords":["Verkada API 400 - Bad Request","The API could not process the supplied request.","400","Verkada","Verkada Command","camera","cloud camera","PoE","API","Bad Request"],"errorCode":"400","eventId":"","severity":"Medium","summary":"The API could not process the supplied request.","rootCause":"An incorrect camera ID, event type UID, schema, parameter, body, or request format can produce HTTP 400.","resolution":"1. Record the exact API response or LED color/count sequence, camera model and serial, Command status, timestamp, and recent change.\n2. Compare the method, URL, headers, identifiers, and sanitized body with the current endpoint schema; correct the rejected input and retry.\n3. Use a known-good, correctly rated PoE source, short patch cable, and switch port when isolation is required.\n4. Validate recording, Command connectivity, live view, time, and the original operation after correction.","emailScript":"Hello,\n\nWe reviewed the Verkada issue and identified Verkada API 400 - Bad Request.\n\nWe are checking camera power, network connectivity, cloud communication, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network or firewall change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact LED colors and number of flashes, camera model, approximate time, and what appears in Verkada Command. Do not share API keys, support tokens, footage, credentials, or unrestricted camera links.","notes":"Source: Verkada API General Troubleshooting.\nScope: Verkada API.\nVerified: 2026-08-10.\n\nLED behavior varies by device family and firmware. Do not infer a camera error from access-controller, gateway, intercom, or third-party-lock LEDs. API evidence must be sanitized; rotate exposed keys and restrict footage/support-token access.","commands":[],"sourceDocument":"Verkada API General Troubleshooting","sourceAuthority":"Verkada","namespace":"VERKADA","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Verkada"],"technologies":["Physical Security","Video Surveillance","Networking","API","Bad Request"],"articleCategories":["Networking","Verkada","Cameras","API","Bad Request"],"aliases":["400","API 400 - Bad Request"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":59002,"title":"Verkada API 401 - Unauthorized","category":"Verkada","product":"Verkada API","tags":["Verkada","Command","Physical Security","Network Appliance","API","Authentication","API Key"],"keywords":["Verkada API 401 - Unauthorized","The API key is missing or invalid.","401","Verkada","Verkada Command","camera","cloud camera","PoE","API","Authentication","API Key"],"errorCode":"401","eventId":"","severity":"High","summary":"The API key is missing or invalid.","rootCause":"The key may be absent, malformed, expired, revoked, or supplied incorrectly.","resolution":"1. Record the exact API response or LED color/count sequence, camera model and serial, Command status, timestamp, and recent change.\n2. Verify key integrity and expiration without logging it. Replace or rotate the key when necessary and test one least-privilege request.\n3. Use a known-good, correctly rated PoE source, short patch cable, and switch port when isolation is required.\n4. Validate recording, Command connectivity, live view, time, and the original operation after correction.","emailScript":"Hello,\n\nWe reviewed the Verkada issue and identified Verkada API 401 - Unauthorized.\n\nWe are checking camera power, network connectivity, cloud communication, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network or firewall change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact LED colors and number of flashes, camera model, approximate time, and what appears in Verkada Command. Do not share API keys, support tokens, footage, credentials, or unrestricted camera links.","notes":"Source: Verkada API General Troubleshooting.\nScope: Verkada API.\nVerified: 2026-08-10.\n\nLED behavior varies by device family and firmware. Do not infer a camera error from access-controller, gateway, intercom, or third-party-lock LEDs. API evidence must be sanitized; rotate exposed keys and restrict footage/support-token access.","commands":[],"sourceDocument":"Verkada API General Troubleshooting","sourceAuthority":"Verkada","namespace":"VERKADA","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Verkada"],"technologies":["Physical Security","Video Surveillance","Networking","API","Authentication","API Key"],"articleCategories":["Networking","Verkada","Cameras","API","Authentication","API Key"],"aliases":["401","API 401 - Unauthorized"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":59003,"title":"Verkada API 403 - Forbidden","category":"Verkada","product":"Verkada API","tags":["Verkada","Command","Physical Security","Network Appliance","API","Authorization","Permissions"],"keywords":["Verkada API 403 - Forbidden","The API key does not have permission for the requested operation.","403","Verkada","Verkada Command","camera","cloud camera","PoE","API","Authorization","Permissions"],"errorCode":"403","eventId":"","severity":"High","summary":"The API key does not have permission for the requested operation.","rootCause":"The key lacks required read/write permission, organization access, endpoint authorization, or applicable scope.","resolution":"1. Record the exact API response or LED color/count sequence, camera model and serial, Command status, timestamp, and recent change.\n2. Confirm the organization, endpoint, and least-privilege read/write permissions. Do not broaden access beyond the integration requirement.\n3. Use a known-good, correctly rated PoE source, short patch cable, and switch port when isolation is required.\n4. Validate recording, Command connectivity, live view, time, and the original operation after correction.","emailScript":"Hello,\n\nWe reviewed the Verkada issue and identified Verkada API 403 - Forbidden.\n\nWe are checking camera power, network connectivity, cloud communication, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network or firewall change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact LED colors and number of flashes, camera model, approximate time, and what appears in Verkada Command. Do not share API keys, support tokens, footage, credentials, or unrestricted camera links.","notes":"Source: Verkada API General Troubleshooting.\nScope: Verkada API.\nVerified: 2026-08-10.\n\nLED behavior varies by device family and firmware. Do not infer a camera error from access-controller, gateway, intercom, or third-party-lock LEDs. API evidence must be sanitized; rotate exposed keys and restrict footage/support-token access.","commands":[],"sourceDocument":"Verkada API General Troubleshooting","sourceAuthority":"Verkada","namespace":"VERKADA","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Verkada"],"technologies":["Physical Security","Video Surveillance","Networking","API","Authorization","Permissions"],"articleCategories":["Networking","Verkada","Cameras","API","Authorization","Permissions"],"aliases":["403","API 403 - Forbidden"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":59004,"title":"Verkada API 404 - Not Found","category":"Verkada","product":"Verkada API","tags":["Verkada","Command","Physical Security","Network Appliance","API","Not Found"],"keywords":["Verkada API 404 - Not Found","The requested API resource or URL does not exist.","404","Verkada","Verkada Command","camera","cloud camera","PoE","API","Not Found"],"errorCode":"404","eventId":"","severity":"Medium","summary":"The requested API resource or URL does not exist.","rootCause":"A wrong URL, unsupported method, stale or incorrect identifier, deleted resource, or formatting error can return HTTP 404.","resolution":"1. Record the exact API response or LED color/count sequence, camera model and serial, Command status, timestamp, and recent change.\n2. Verify the current API base URL, endpoint path, request method, identifier, and formatting; list the parent collection when supported.\n3. Use a known-good, correctly rated PoE source, short patch cable, and switch port when isolation is required.\n4. Validate recording, Command connectivity, live view, time, and the original operation after correction.","emailScript":"Hello,\n\nWe reviewed the Verkada issue and identified Verkada API 404 - Not Found.\n\nWe are checking camera power, network connectivity, cloud communication, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network or firewall change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact LED colors and number of flashes, camera model, approximate time, and what appears in Verkada Command. Do not share API keys, support tokens, footage, credentials, or unrestricted camera links.","notes":"Source: Verkada API General Troubleshooting.\nScope: Verkada API.\nVerified: 2026-08-10.\n\nLED behavior varies by device family and firmware. Do not infer a camera error from access-controller, gateway, intercom, or third-party-lock LEDs. API evidence must be sanitized; rotate exposed keys and restrict footage/support-token access.","commands":[],"sourceDocument":"Verkada API General Troubleshooting","sourceAuthority":"Verkada","namespace":"VERKADA","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Verkada"],"technologies":["Physical Security","Video Surveillance","Networking","API","Not Found"],"articleCategories":["Networking","Verkada","Cameras","API","Not Found"],"aliases":["404","API 404 - Not Found"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":59005,"title":"Verkada API 429 - Too Many Requests","category":"Verkada","product":"Verkada API","tags":["Verkada","Command","Physical Security","Network Appliance","API","Rate Limit","Retry"],"keywords":["Verkada API 429 - Too Many Requests","The API rate limit was exceeded.","429","Verkada","Verkada Command","camera","cloud camera","PoE","API","Rate Limit","Retry"],"errorCode":"429","eventId":"","severity":"Medium","summary":"The API rate limit was exceeded.","rootCause":"Polling or retry volume exceeded the allowed request rate.","resolution":"1. Record the exact API response or LED color/count sequence, camera model and serial, Command status, timestamp, and recent change.\n2. Pause requests, honor any server retry guidance, and implement bounded exponential backoff with jitter. Reduce polling and retry only safe operations.\n3. Use a known-good, correctly rated PoE source, short patch cable, and switch port when isolation is required.\n4. Validate recording, Command connectivity, live view, time, and the original operation after correction.","emailScript":"Hello,\n\nWe reviewed the Verkada issue and identified Verkada API 429 - Too Many Requests.\n\nWe are checking camera power, network connectivity, cloud communication, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network or firewall change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact LED colors and number of flashes, camera model, approximate time, and what appears in Verkada Command. Do not share API keys, support tokens, footage, credentials, or unrestricted camera links.","notes":"Source: Verkada API General Troubleshooting.\nScope: Verkada API.\nVerified: 2026-08-10.\n\nLED behavior varies by device family and firmware. Do not infer a camera error from access-controller, gateway, intercom, or third-party-lock LEDs. API evidence must be sanitized; rotate exposed keys and restrict footage/support-token access.","commands":[],"sourceDocument":"Verkada API General Troubleshooting","sourceAuthority":"Verkada","namespace":"VERKADA","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Verkada"],"technologies":["Physical Security","Video Surveillance","Networking","API","Rate Limit","Retry"],"articleCategories":["Networking","Verkada","Cameras","API","Rate Limit","Retry"],"aliases":["429","API 429 - Too Many Requests"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":59006,"title":"Verkada API 5xx - Server Error","category":"Verkada","product":"Verkada API","tags":["Verkada","Command","Physical Security","Network Appliance","API","Server Error","Cloud"],"keywords":["Verkada API 5xx - Server Error","Verkada could not process the request because of a server-side failure.","5xx","Verkada","Verkada Command","camera","cloud camera","PoE","API","Server Error","Cloud"],"errorCode":"5xx","eventId":"","severity":"High","summary":"Verkada could not process the request because of a server-side failure.","rootCause":"A cloud-service incident, transient dependency failure, or endpoint defect can produce a 5xx response.","resolution":"1. Record the exact API response or LED color/count sequence, camera model and serial, Command status, timestamp, and recent change.\n2. Check status.verkada.com, preserve the sanitized response and timestamp, and retry safe operations with backoff. Contact Verkada Support if persistent.\n3. Use a known-good, correctly rated PoE source, short patch cable, and switch port when isolation is required.\n4. Validate recording, Command connectivity, live view, time, and the original operation after correction.","emailScript":"Hello,\n\nWe reviewed the Verkada issue and identified Verkada API 5xx - Server Error.\n\nWe are checking camera power, network connectivity, cloud communication, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network or firewall change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact LED colors and number of flashes, camera model, approximate time, and what appears in Verkada Command. Do not share API keys, support tokens, footage, credentials, or unrestricted camera links.","notes":"Source: Verkada API General Troubleshooting.\nScope: Verkada API.\nVerified: 2026-08-10.\n\nLED behavior varies by device family and firmware. Do not infer a camera error from access-controller, gateway, intercom, or third-party-lock LEDs. API evidence must be sanitized; rotate exposed keys and restrict footage/support-token access.","commands":[],"sourceDocument":"Verkada API General Troubleshooting","sourceAuthority":"Verkada","namespace":"VERKADA","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Verkada"],"technologies":["Physical Security","Video Surveillance","Networking","API","Server Error","Cloud"],"articleCategories":["Networking","Verkada","Cameras","API","Server Error","Cloud"],"aliases":["5xx","API 5xx - Server Error"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":59007,"title":"Verkada Camera LED - Solid Orange","category":"Verkada","product":"Verkada Cameras","tags":["Verkada","Command","Physical Security","Network Appliance","LED","Solid Orange","Boot","PoE"],"keywords":["Verkada Camera LED - Solid Orange","The camera is powered on and booting; a prolonged state can indicate insufficient PoE or a failed boot.","Verkada","Verkada Command","camera","cloud camera","PoE","LED","Solid Orange","Boot","PoE"],"errorCode":"","eventId":"","severity":"High","summary":"The camera is powered on and booting; a prolonged state can indicate insufficient PoE or a failed boot.","rootCause":"Normal initialization, inadequate PoE, cabling loss, a bad port, or a boot fault can keep the LED orange.","resolution":"1. Record the exact API response or LED color/count sequence, camera model and serial, Command status, timestamp, and recent change.\n2. Allow the documented boot window, then test the correct PoE standard with a known-good short cable and port. Contact Verkada Support if it remains orange.\n3. Use a known-good, correctly rated PoE source, short patch cable, and switch port when isolation is required.\n4. Validate recording, Command connectivity, live view, time, and the original operation after correction.","emailScript":"Hello,\n\nWe reviewed the Verkada issue and identified Verkada Camera LED - Solid Orange.\n\nWe are checking camera power, network connectivity, cloud communication, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network or firewall change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact LED colors and number of flashes, camera model, approximate time, and what appears in Verkada Command. Do not share API keys, support tokens, footage, credentials, or unrestricted camera links.","notes":"Source: Verkada Camera LED Status Indicators; Camera Deployment.\nScope: Verkada Cameras.\nVerified: 2026-08-10.\n\nLED behavior varies by device family and firmware. Do not infer a camera error from access-controller, gateway, intercom, or third-party-lock LEDs. API evidence must be sanitized; rotate exposed keys and restrict footage/support-token access.","commands":[],"sourceDocument":"Verkada Camera LED Status Indicators; Camera Deployment","sourceAuthority":"Verkada","namespace":"VERKADA","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Verkada"],"technologies":["Physical Security","Video Surveillance","Networking","LED","Solid Orange","Boot","PoE"],"articleCategories":["Networking","Verkada","Cameras","LED","Solid Orange","Boot","PoE"],"aliases":["Camera LED - Solid Orange"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":59008,"title":"Verkada Camera LED - Flashing Orange","category":"Verkada","product":"Verkada Cameras","tags":["Verkada","Command","Physical Security","Network Appliance","LED","Flashing Orange","Firmware Update"],"keywords":["Verkada Camera LED - Flashing Orange","The camera is updating firmware; a prolonged pattern can mean the upgrade cannot finish.","Verkada","Verkada Command","camera","cloud camera","PoE","LED","Flashing Orange","Firmware Update"],"errorCode":"","eventId":"","severity":"High","summary":"The camera is updating firmware; a prolonged pattern can mean the upgrade cannot finish.","rootCause":"Network instability, power interruption, endpoint reachability, or update failure can stall firmware installation.","resolution":"1. Record the exact API response or LED color/count sequence, camera model and serial, Command status, timestamp, and recent change.\n2. Do not interrupt a normal update. If it persists for 30 minutes, use a known-good direct network connection and stable PoE, wait again, then contact Verkada Support.\n3. Use a known-good, correctly rated PoE source, short patch cable, and switch port when isolation is required.\n4. Validate recording, Command connectivity, live view, time, and the original operation after correction.","emailScript":"Hello,\n\nWe reviewed the Verkada issue and identified Verkada Camera LED - Flashing Orange.\n\nWe are checking camera power, network connectivity, cloud communication, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network or firewall change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact LED colors and number of flashes, camera model, approximate time, and what appears in Verkada Command. Do not share API keys, support tokens, footage, credentials, or unrestricted camera links.","notes":"Source: Verkada Camera LED Status Indicators; Camera Deployment.\nScope: Verkada Cameras.\nVerified: 2026-08-10.\n\nLED behavior varies by device family and firmware. Do not infer a camera error from access-controller, gateway, intercom, or third-party-lock LEDs. API evidence must be sanitized; rotate exposed keys and restrict footage/support-token access.","commands":[],"sourceDocument":"Verkada Camera LED Status Indicators; Camera Deployment","sourceAuthority":"Verkada","namespace":"VERKADA","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Verkada"],"technologies":["Physical Security","Video Surveillance","Networking","LED","Flashing Orange","Firmware Update"],"articleCategories":["Networking","Verkada","Cameras","LED","Flashing Orange","Firmware Update"],"aliases":["Camera LED - Flashing Orange"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":59009,"title":"Verkada Camera LED - Solid Blue","category":"Verkada","product":"Verkada Cameras","tags":["Verkada","Command","Physical Security","Network Appliance","LED","Solid Blue","Recording","Online"],"keywords":["Verkada Camera LED - Solid Blue","The camera is running, connected, and recording data.","Verkada","Verkada Command","camera","cloud camera","PoE","LED","Solid Blue","Recording","Online"],"errorCode":"","eventId":"","severity":"Low","summary":"The camera is running, connected, and recording data.","rootCause":"This is normal camera status; if Command reports offline, the camera may not be added under the matching serial number.","resolution":"1. Record the exact API response or LED color/count sequence, camera model and serial, Command status, timestamp, and recent change.\n2. If Command disagrees, compare the physical serial with the Command record and add the correct camera. Otherwise troubleshoot the specific viewing or recording symptom.\n3. Use a known-good, correctly rated PoE source, short patch cable, and switch port when isolation is required.\n4. Validate recording, Command connectivity, live view, time, and the original operation after correction.","emailScript":"Hello,\n\nWe reviewed the Verkada issue and identified Verkada Camera LED - Solid Blue.\n\nWe are checking camera power, network connectivity, cloud communication, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network or firewall change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact LED colors and number of flashes, camera model, approximate time, and what appears in Verkada Command. Do not share API keys, support tokens, footage, credentials, or unrestricted camera links.","notes":"Source: Verkada Camera LED Status Indicators; Troubleshoot Offline Camera.\nScope: Verkada Cameras.\nVerified: 2026-08-10.\n\nLED behavior varies by device family and firmware. Do not infer a camera error from access-controller, gateway, intercom, or third-party-lock LEDs. API evidence must be sanitized; rotate exposed keys and restrict footage/support-token access.","commands":[],"sourceDocument":"Verkada Camera LED Status Indicators; Troubleshoot Offline Camera","sourceAuthority":"Verkada","namespace":"VERKADA","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Verkada"],"technologies":["Physical Security","Video Surveillance","Networking","LED","Solid Blue","Recording","Online"],"articleCategories":["Networking","Verkada","Cameras","LED","Solid Blue","Recording","Online"],"aliases":["Camera LED - Solid Blue"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":59010,"title":"Verkada Camera LED - Flashing Blue","category":"Verkada","product":"Verkada Cameras","tags":["Verkada","Command","Physical Security","Network Appliance","LED","Flashing Blue","Offline","Command"],"keywords":["Verkada Camera LED - Flashing Blue","The camera is recording locally but cannot reach Verkada Command; this pattern is primarily associated with factory firmware.","Verkada","Verkada Command","camera","cloud camera","PoE","LED","Flashing Blue","Offline","Command"],"errorCode":"","eventId":"","severity":"High","summary":"The camera is recording locally but cannot reach Verkada Command; this pattern is primarily associated with factory firmware.","rootCause":"DHCP, DNS, gateway, NTP/NTS, HTTPS, firewall, TLS inspection, cabling, or internet reachability can block Command connectivity.","resolution":"1. Record the exact API response or LED color/count sequence, camera model and serial, Command status, timestamp, and recent change.\n2. Verify addressing, DNS, time, required Verkada endpoints and ports, and exemption from TLS decryption. Test known-good media and contact support if connectivity checks pass.\n3. Use a known-good, correctly rated PoE source, short patch cable, and switch port when isolation is required.\n4. Validate recording, Command connectivity, live view, time, and the original operation after correction.","emailScript":"Hello,\n\nWe reviewed the Verkada issue and identified Verkada Camera LED - Flashing Blue.\n\nWe are checking camera power, network connectivity, cloud communication, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network or firewall change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact LED colors and number of flashes, camera model, approximate time, and what appears in Verkada Command. Do not share API keys, support tokens, footage, credentials, or unrestricted camera links.","notes":"Source: Verkada Camera LED Status Indicators; Troubleshoot Offline Camera.\nScope: Verkada Cameras.\nVerified: 2026-08-10.\n\nLED behavior varies by device family and firmware. Do not infer a camera error from access-controller, gateway, intercom, or third-party-lock LEDs. API evidence must be sanitized; rotate exposed keys and restrict footage/support-token access.","commands":[],"sourceDocument":"Verkada Camera LED Status Indicators; Troubleshoot Offline Camera","sourceAuthority":"Verkada","namespace":"VERKADA","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Verkada"],"technologies":["Physical Security","Video Surveillance","Networking","LED","Flashing Blue","Offline","Command"],"articleCategories":["Networking","Verkada","Cameras","LED","Flashing Blue","Offline","Command"],"aliases":["Camera LED - Flashing Blue"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":59011,"title":"Verkada Camera LED - Solid Red","category":"Verkada","product":"Verkada CD63 / CF83 Cameras","tags":["Verkada","Command","Physical Security","Network Appliance","LED","Solid Red","Hardware"],"keywords":["Verkada Camera LED - Solid Red","On supported CD63 and CF83 cameras, solid red indicates a condition requiring Verkada Support.","Verkada","Verkada Command","camera","cloud camera","PoE","LED","Solid Red","Hardware"],"errorCode":"","eventId":"","severity":"Critical","summary":"On supported CD63 and CF83 cameras, solid red indicates a condition requiring Verkada Support.","rootCause":"A critical camera or hardware condition is suspected; this exterior status is not documented for every model.","resolution":"1. Record the exact API response or LED color/count sequence, camera model and serial, Command status, timestamp, and recent change.\n2. Record the model, serial, Command state, power source, and LED behavior, then contact Verkada Support. Do not disassemble or repeatedly power-cycle the camera.\n3. Use a known-good, correctly rated PoE source, short patch cable, and switch port when isolation is required.\n4. Validate recording, Command connectivity, live view, time, and the original operation after correction.","emailScript":"Hello,\n\nWe reviewed the Verkada issue and identified Verkada Camera LED - Solid Red.\n\nWe are checking camera power, network connectivity, cloud communication, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network or firewall change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact LED colors and number of flashes, camera model, approximate time, and what appears in Verkada Command. Do not share API keys, support tokens, footage, credentials, or unrestricted camera links.","notes":"Source: Verkada Camera LED Status Indicators.\nScope: Verkada CD63 / CF83 Cameras.\nVerified: 2026-08-10.\n\nLED behavior varies by device family and firmware. Do not infer a camera error from access-controller, gateway, intercom, or third-party-lock LEDs. API evidence must be sanitized; rotate exposed keys and restrict footage/support-token access.","commands":[],"sourceDocument":"Verkada Camera LED Status Indicators","sourceAuthority":"Verkada","namespace":"VERKADA","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Verkada"],"technologies":["Physical Security","Video Surveillance","Networking","LED","Solid Red","Hardware"],"articleCategories":["Networking","Verkada","Cameras","LED","Solid Red","Hardware"],"aliases":["Camera LED - Solid Red"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":59012,"title":"Verkada Camera LED - No Light","category":"Verkada","product":"Verkada Cameras","tags":["Verkada","Command","Physical Security","Network Appliance","LED","No Light","Power","PoE"],"keywords":["Verkada Camera LED - No Light","The camera status LED is not illuminated and the camera may not be receiving power.","Verkada","Verkada Command","camera","cloud camera","PoE","LED","No Light","Power","PoE"],"errorCode":"","eventId":"","severity":"Critical","summary":"The camera status LED is not illuminated and the camera may not be receiving power.","rootCause":"A disabled LED setting, failed PoE negotiation, insufficient budget, bad injector, cable, switch port, or hardware can cause this state.","resolution":"1. Record the exact API response or LED color/count sequence, camera model and serial, Command status, timestamp, and recent change.\n2. Confirm the LED is not administratively disabled, then test correct PoE, budget, a known-good short cable and switch port or rated injector. Escalate if it remains unpowered.\n3. Use a known-good, correctly rated PoE source, short patch cable, and switch port when isolation is required.\n4. Validate recording, Command connectivity, live view, time, and the original operation after correction.","emailScript":"Hello,\n\nWe reviewed the Verkada issue and identified Verkada Camera LED - No Light.\n\nWe are checking camera power, network connectivity, cloud communication, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network or firewall change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact LED colors and number of flashes, camera model, approximate time, and what appears in Verkada Command. Do not share API keys, support tokens, footage, credentials, or unrestricted camera links.","notes":"Source: Verkada Camera Deployment; Troubleshoot Offline Camera.\nScope: Verkada Cameras.\nVerified: 2026-08-10.\n\nLED behavior varies by device family and firmware. Do not infer a camera error from access-controller, gateway, intercom, or third-party-lock LEDs. API evidence must be sanitized; rotate exposed keys and restrict footage/support-token access.","commands":[],"sourceDocument":"Verkada Camera Deployment; Troubleshoot Offline Camera","sourceAuthority":"Verkada","namespace":"VERKADA","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Verkada"],"technologies":["Physical Security","Video Surveillance","Networking","LED","No Light","Power","PoE"],"articleCategories":["Networking","Verkada","Cameras","LED","No Light","Power","PoE"],"aliases":["Camera LED - No Light"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":59013,"title":"Verkada LED 1 Blue + 1 Orange - Ethernet Link Failure","category":"Verkada","product":"Verkada Cameras","tags":["Verkada","Command","Physical Security","Network Appliance","LED Code","Ethernet","Switch Port"],"keywords":["Verkada LED 1 Blue + 1 Orange - Ethernet Link Failure","The camera has PoE but cannot connect to the switch.","1B-1O","Verkada","Verkada Command","camera","cloud camera","PoE","LED Code","Ethernet","Switch Port"],"errorCode":"1B-1O","eventId":"","severity":"High","summary":"The camera has PoE but cannot connect to the switch.","rootCause":"Physical Ethernet link, termination, cable, connector, port, negotiation, or switch state is failing.","resolution":"1. Record the exact API response or LED color/count sequence, camera model and serial, Command status, timestamp, and recent change.\n2. Verify physical-layer status and test a known-good short cable and enabled switch port with the required PoE.\n3. Use a known-good, correctly rated PoE source, short patch cable, and switch port when isolation is required.\n4. Validate recording, Command connectivity, live view, time, and the original operation after correction.","emailScript":"Hello,\n\nWe reviewed the Verkada issue and identified Verkada LED 1 Blue + 1 Orange - Ethernet Link Failure.\n\nWe are checking camera power, network connectivity, cloud communication, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network or firewall change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact LED colors and number of flashes, camera model, approximate time, and what appears in Verkada Command. Do not share API keys, support tokens, footage, credentials, or unrestricted camera links.","notes":"Source: Verkada Camera LED Status Indicators.\nScope: Verkada Cameras.\nVerified: 2026-08-10.\n\nLED behavior varies by device family and firmware. Do not infer a camera error from access-controller, gateway, intercom, or third-party-lock LEDs. API evidence must be sanitized; rotate exposed keys and restrict footage/support-token access.","commands":[],"sourceDocument":"Verkada Camera LED Status Indicators","sourceAuthority":"Verkada","namespace":"VERKADA","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Verkada"],"technologies":["Physical Security","Video Surveillance","Networking","LED Code","Ethernet","Switch Port"],"articleCategories":["Networking","Verkada","Cameras","LED Code","Ethernet","Switch Port"],"aliases":["1B-1O","LED 1 Blue + 1 Orange - Ethernet Link Failure"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":59014,"title":"Verkada LED 1 Blue + 2 Orange - No IP Address","category":"Verkada","product":"Verkada Cameras","tags":["Verkada","Command","Physical Security","Network Appliance","LED Code","DHCP","IP Address"],"keywords":["Verkada LED 1 Blue + 2 Orange - No IP Address","The camera has not received an IP address.","1B-2O","Verkada","Verkada Command","camera","cloud camera","PoE","LED Code","DHCP","IP Address"],"errorCode":"1B-2O","eventId":"","severity":"High","summary":"The camera has not received an IP address.","rootCause":"DHCP is absent or unreachable, the scope is exhausted, the VLAN is wrong, or relay/switch configuration blocks assignment.","resolution":"1. Record the exact API response or LED color/count sequence, camera model and serial, Command status, timestamp, and recent change.\n2. Verify VLAN membership and that a reachable DHCP server has available addresses; confirm a unique lease for the camera MAC.\n3. Use a known-good, correctly rated PoE source, short patch cable, and switch port when isolation is required.\n4. Validate recording, Command connectivity, live view, time, and the original operation after correction.","emailScript":"Hello,\n\nWe reviewed the Verkada issue and identified Verkada LED 1 Blue + 2 Orange - No IP Address.\n\nWe are checking camera power, network connectivity, cloud communication, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network or firewall change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact LED colors and number of flashes, camera model, approximate time, and what appears in Verkada Command. Do not share API keys, support tokens, footage, credentials, or unrestricted camera links.","notes":"Source: Verkada Camera LED Status Indicators.\nScope: Verkada Cameras.\nVerified: 2026-08-10.\n\nLED behavior varies by device family and firmware. Do not infer a camera error from access-controller, gateway, intercom, or third-party-lock LEDs. API evidence must be sanitized; rotate exposed keys and restrict footage/support-token access.","commands":[],"sourceDocument":"Verkada Camera LED Status Indicators","sourceAuthority":"Verkada","namespace":"VERKADA","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Verkada"],"technologies":["Physical Security","Video Surveillance","Networking","LED Code","DHCP","IP Address"],"articleCategories":["Networking","Verkada","Cameras","LED Code","DHCP","IP Address"],"aliases":["1B-2O","LED 1 Blue + 2 Orange - No IP Address"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":59015,"title":"Verkada LED 1 Blue + 3 Orange - Gateway Unreachable","category":"Verkada","product":"Verkada Cameras","tags":["Verkada","Command","Physical Security","Network Appliance","LED Code","Gateway","Routing"],"keywords":["Verkada LED 1 Blue + 3 Orange - Gateway Unreachable","The camera cannot reach its configured default gateway.","1B-3O","Verkada","Verkada Command","camera","cloud camera","PoE","LED Code","Gateway","Routing"],"errorCode":"1B-3O","eventId":"","severity":"High","summary":"The camera cannot reach its configured default gateway.","rootCause":"The camera address, mask, gateway, VLAN, switching path, or gateway state is incorrect.","resolution":"1. Record the exact API response or LED color/count sequence, camera model and serial, Command status, timestamp, and recent change.\n2. Verify the assigned address, subnet mask, gateway, VLAN, ARP path, and gateway operation from the same segment.\n3. Use a known-good, correctly rated PoE source, short patch cable, and switch port when isolation is required.\n4. Validate recording, Command connectivity, live view, time, and the original operation after correction.","emailScript":"Hello,\n\nWe reviewed the Verkada issue and identified Verkada LED 1 Blue + 3 Orange - Gateway Unreachable.\n\nWe are checking camera power, network connectivity, cloud communication, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network or firewall change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact LED colors and number of flashes, camera model, approximate time, and what appears in Verkada Command. Do not share API keys, support tokens, footage, credentials, or unrestricted camera links.","notes":"Source: Verkada Camera LED Status Indicators.\nScope: Verkada Cameras.\nVerified: 2026-08-10.\n\nLED behavior varies by device family and firmware. Do not infer a camera error from access-controller, gateway, intercom, or third-party-lock LEDs. API evidence must be sanitized; rotate exposed keys and restrict footage/support-token access.","commands":[],"sourceDocument":"Verkada Camera LED Status Indicators","sourceAuthority":"Verkada","namespace":"VERKADA","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Verkada"],"technologies":["Physical Security","Video Surveillance","Networking","LED Code","Gateway","Routing"],"articleCategories":["Networking","Verkada","Cameras","LED Code","Gateway","Routing"],"aliases":["1B-3O","LED 1 Blue + 3 Orange - Gateway Unreachable"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":59016,"title":"Verkada LED 1 Blue + 4 Orange - Duplicate IP","category":"Verkada","product":"Verkada Cameras","tags":["Verkada","Command","Physical Security","Network Appliance","LED Code","Duplicate IP","Address Conflict"],"keywords":["Verkada LED 1 Blue + 4 Orange - Duplicate IP","The camera detected another device using its IP address.","1B-4O","Verkada","Verkada Command","camera","cloud camera","PoE","LED Code","Duplicate IP","Address Conflict"],"errorCode":"1B-4O","eventId":"","severity":"High","summary":"The camera detected another device using its IP address.","rootCause":"A static-address collision, stale reservation, duplicate manual configuration, or DHCP conflict exists.","resolution":"1. Record the exact API response or LED color/count sequence, camera model and serial, Command status, timestamp, and recent change.\n2. Identify both MAC addresses, assign unique addresses or enable corrected DHCP, clear stale state carefully, and verify the conflict stops.\n3. Use a known-good, correctly rated PoE source, short patch cable, and switch port when isolation is required.\n4. Validate recording, Command connectivity, live view, time, and the original operation after correction.","emailScript":"Hello,\n\nWe reviewed the Verkada issue and identified Verkada LED 1 Blue + 4 Orange - Duplicate IP.\n\nWe are checking camera power, network connectivity, cloud communication, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network or firewall change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact LED colors and number of flashes, camera model, approximate time, and what appears in Verkada Command. Do not share API keys, support tokens, footage, credentials, or unrestricted camera links.","notes":"Source: Verkada Camera LED Status Indicators.\nScope: Verkada Cameras.\nVerified: 2026-08-10.\n\nLED behavior varies by device family and firmware. Do not infer a camera error from access-controller, gateway, intercom, or third-party-lock LEDs. API evidence must be sanitized; rotate exposed keys and restrict footage/support-token access.","commands":[],"sourceDocument":"Verkada Camera LED Status Indicators","sourceAuthority":"Verkada","namespace":"VERKADA","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Verkada"],"technologies":["Physical Security","Video Surveillance","Networking","LED Code","Duplicate IP","Address Conflict"],"articleCategories":["Networking","Verkada","Cameras","LED Code","Duplicate IP","Address Conflict"],"aliases":["1B-4O","LED 1 Blue + 4 Orange - Duplicate IP"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":59017,"title":"Verkada LED 1 Blue + 5 Orange - DNS Failure","category":"Verkada","product":"Verkada Cameras","tags":["Verkada","Command","Physical Security","Network Appliance","LED Code","DNS","Name Resolution"],"keywords":["Verkada LED 1 Blue + 5 Orange - DNS Failure","The camera cannot resolve Verkada hostnames.","1B-5O","Verkada","Verkada Command","camera","cloud camera","PoE","LED Code","DNS","Name Resolution"],"errorCode":"1B-5O","eventId":"","severity":"High","summary":"The camera cannot resolve Verkada hostnames.","rootCause":"The configured DNS server is unreachable, blocked, unhealthy, or unable to resolve required Verkada names.","resolution":"1. Record the exact API response or LED color/count sequence, camera model and serial, Command status, timestamp, and recent change.\n2. Verify the camera VLAN can reach a functioning DNS server and resolve required Verkada hostnames without interception or filtering errors.\n3. Use a known-good, correctly rated PoE source, short patch cable, and switch port when isolation is required.\n4. Validate recording, Command connectivity, live view, time, and the original operation after correction.","emailScript":"Hello,\n\nWe reviewed the Verkada issue and identified Verkada LED 1 Blue + 5 Orange - DNS Failure.\n\nWe are checking camera power, network connectivity, cloud communication, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network or firewall change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact LED colors and number of flashes, camera model, approximate time, and what appears in Verkada Command. Do not share API keys, support tokens, footage, credentials, or unrestricted camera links.","notes":"Source: Verkada Camera LED Status Indicators.\nScope: Verkada Cameras.\nVerified: 2026-08-10.\n\nLED behavior varies by device family and firmware. Do not infer a camera error from access-controller, gateway, intercom, or third-party-lock LEDs. API evidence must be sanitized; rotate exposed keys and restrict footage/support-token access.","commands":[],"sourceDocument":"Verkada Camera LED Status Indicators","sourceAuthority":"Verkada","namespace":"VERKADA","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Verkada"],"technologies":["Physical Security","Video Surveillance","Networking","LED Code","DNS","Name Resolution"],"articleCategories":["Networking","Verkada","Cameras","LED Code","DNS","Name Resolution"],"aliases":["1B-5O","LED 1 Blue + 5 Orange - DNS Failure"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":59018,"title":"Verkada LED 1 Blue + 6 Orange - NTP Failure","category":"Verkada","product":"Verkada Cameras","tags":["Verkada","Command","Physical Security","Network Appliance","LED Code","NTP","NTS","Time"],"keywords":["Verkada LED 1 Blue + 6 Orange - NTP Failure","The camera cannot receive a response from its time service.","1B-6O","Verkada","Verkada Command","camera","cloud camera","PoE","LED Code","NTP","NTS","Time"],"errorCode":"1B-6O","eventId":"","severity":"High","summary":"The camera cannot receive a response from its time service.","rootCause":"NTP/NTS reachability, firewall policy, DNS, routing, or time-server availability is preventing synchronization.","resolution":"1. Record the exact API response or LED color/count sequence, camera model and serial, Command status, timestamp, and recent change.\n2. Verify the documented time servers and required UDP 123 or TCP 4460 paths, DNS resolution, and firewall policy; do not redirect time traffic silently.\n3. Use a known-good, correctly rated PoE source, short patch cable, and switch port when isolation is required.\n4. Validate recording, Command connectivity, live view, time, and the original operation after correction.","emailScript":"Hello,\n\nWe reviewed the Verkada issue and identified Verkada LED 1 Blue + 6 Orange - NTP Failure.\n\nWe are checking camera power, network connectivity, cloud communication, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network or firewall change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact LED colors and number of flashes, camera model, approximate time, and what appears in Verkada Command. Do not share API keys, support tokens, footage, credentials, or unrestricted camera links.","notes":"Source: Verkada Camera LED Status Indicators.\nScope: Verkada Cameras.\nVerified: 2026-08-10.\n\nLED behavior varies by device family and firmware. Do not infer a camera error from access-controller, gateway, intercom, or third-party-lock LEDs. API evidence must be sanitized; rotate exposed keys and restrict footage/support-token access.","commands":[],"sourceDocument":"Verkada Camera LED Status Indicators","sourceAuthority":"Verkada","namespace":"VERKADA","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Verkada"],"technologies":["Physical Security","Video Surveillance","Networking","LED Code","NTP","NTS","Time"],"articleCategories":["Networking","Verkada","Cameras","LED Code","NTP","NTS","Time"],"aliases":["1B-6O","LED 1 Blue + 6 Orange - NTP Failure"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":59019,"title":"Verkada LED 1 Blue + 7 Orange - SSL Certification Failure","category":"Verkada","product":"Verkada Cameras","tags":["Verkada","Command","Physical Security","Network Appliance","LED Code","TLS","SSL Inspection","Certificate"],"keywords":["Verkada LED 1 Blue + 7 Orange - SSL Certification Failure","The camera cannot certify its TLS connection to Verkada endpoints.","1B-7O","Verkada","Verkada Command","camera","cloud camera","PoE","LED Code","TLS","SSL Inspection","Certificate"],"errorCode":"1B-7O","eventId":"","severity":"High","summary":"The camera cannot certify its TLS connection to Verkada endpoints.","rootCause":"TLS/SSL inspection commonly presents an untrusted replacement certificate or otherwise disrupts the handshake.","resolution":"1. Record the exact API response or LED color/count sequence, camera model and serial, Command status, timestamp, and recent change.\n2. Inspect the certificate presented on the camera path and exempt documented Verkada camera traffic from TLS decryption as required by Verkada guidance.\n3. Use a known-good, correctly rated PoE source, short patch cable, and switch port when isolation is required.\n4. Validate recording, Command connectivity, live view, time, and the original operation after correction.","emailScript":"Hello,\n\nWe reviewed the Verkada issue and identified Verkada LED 1 Blue + 7 Orange - SSL Certification Failure.\n\nWe are checking camera power, network connectivity, cloud communication, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network or firewall change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact LED colors and number of flashes, camera model, approximate time, and what appears in Verkada Command. Do not share API keys, support tokens, footage, credentials, or unrestricted camera links.","notes":"Source: Verkada Camera LED Status Indicators.\nScope: Verkada Cameras.\nVerified: 2026-08-10.\n\nLED behavior varies by device family and firmware. Do not infer a camera error from access-controller, gateway, intercom, or third-party-lock LEDs. API evidence must be sanitized; rotate exposed keys and restrict footage/support-token access.","commands":[],"sourceDocument":"Verkada Camera LED Status Indicators","sourceAuthority":"Verkada","namespace":"VERKADA","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Verkada"],"technologies":["Physical Security","Video Surveillance","Networking","LED Code","TLS","SSL Inspection","Certificate"],"articleCategories":["Networking","Verkada","Cameras","LED Code","TLS","SSL Inspection","Certificate"],"aliases":["1B-7O","LED 1 Blue + 7 Orange - SSL Certification Failure"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":59020,"title":"Verkada LED 1 Blue + 8 Orange - Endpoint Unreachable","category":"Verkada","product":"Verkada Cameras","tags":["Verkada","Command","Physical Security","Network Appliance","LED Code","Firewall","Endpoint","Cloud"],"keywords":["Verkada LED 1 Blue + 8 Orange - Endpoint Unreachable","At least one required Verkada endpoint is unreachable after boot.","1B-8O","Verkada","Verkada Command","camera","cloud camera","PoE","LED Code","Firewall","Endpoint","Cloud"],"errorCode":"1B-8O","eventId":"","severity":"High","summary":"At least one required Verkada endpoint is unreachable after boot.","rootCause":"Firewall, routing, DNS, proxy, internet, regional endpoint, or service availability is blocking required communication.","resolution":"1. Record the exact API response or LED color/count sequence, camera model and serial, Command status, timestamp, and recent change.\n2. Compare outbound policy with Verkada's current required network settings, test DNS and the exact regional endpoints, and check Verkada service status.\n3. Use a known-good, correctly rated PoE source, short patch cable, and switch port when isolation is required.\n4. Validate recording, Command connectivity, live view, time, and the original operation after correction.","emailScript":"Hello,\n\nWe reviewed the Verkada issue and identified Verkada LED 1 Blue + 8 Orange - Endpoint Unreachable.\n\nWe are checking camera power, network connectivity, cloud communication, and supporting logs before applying the least disruptive correction.\n\nPlease let us know if there was a recent network or firewall change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact LED colors and number of flashes, camera model, approximate time, and what appears in Verkada Command. Do not share API keys, support tokens, footage, credentials, or unrestricted camera links.","notes":"Source: Verkada Camera LED Status Indicators.\nScope: Verkada Cameras.\nVerified: 2026-08-10.\n\nLED behavior varies by device family and firmware. Do not infer a camera error from access-controller, gateway, intercom, or third-party-lock LEDs. API evidence must be sanitized; rotate exposed keys and restrict footage/support-token access.","commands":[],"sourceDocument":"Verkada Camera LED Status Indicators","sourceAuthority":"Verkada","namespace":"VERKADA","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Verkada"],"technologies":["Physical Security","Video Surveillance","Networking","LED Code","Firewall","Endpoint","Cloud"],"articleCategories":["Networking","Verkada","Cameras","LED Code","Firewall","Endpoint","Cloud"],"aliases":["1B-8O","LED 1 Blue + 8 Orange - Endpoint Unreachable"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60000,"title":"MiCollab - Service Temporarily Unavailable or Bad Gateway","category":"Mitel","product":"MiCollab Client Service 10.0","tags":["Mitel","Unified Communications","Telephony","MSL","JBoss","Provisioning"],"keywords":["MiCollab - Service Temporarily Unavailable or Bad Gateway","MiCollab Client Service 10.0","The MSL server displays Service Temporarily Unavailable or Bad Gateway while provisioning MiCollab Client Service.","Mitel","PBX","VoIP","SIP","MSL","JBoss","Provisioning"],"errorCode":"","eventId":"","severity":"High","summary":"The MSL server displays Service Temporarily Unavailable or Bad Gateway while provisioning MiCollab Client Service.","rootCause":"The status page can reload while the web server or JBoss application server is restarting.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Allow services to finish starting, use the documented ServiceLink Blades action to clear the message, and confirm JBoss and the configuration page are healthy.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCollab - Service Temporarily Unavailable or Bad Gateway.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiCollab Client Administrator Guide.pdf.\nProduct scope: MiCollab Client Service 10.0.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiCollab Client Administrator Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","MSL","JBoss","Provisioning"],"articleCategories":["Mitel","VoIP","Telephony","MSL","JBoss","Provisioning"],"aliases":["MiCollab - Service Temporarily Unavailable or Bad Gateway"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60001,"title":"MiCollab - Invalid Voice Mail System","category":"Mitel","product":"MiCollab Client Service 10.0","tags":["Mitel","Unified Communications","Telephony","Voicemail","Provisioning"],"keywords":["MiCollab - Invalid Voice Mail System","MiCollab Client Service 10.0","The synchronized or provisioned voicemail system is invalid.","Mitel","PBX","VoIP","SIP","Voicemail","Provisioning"],"errorCode":"","eventId":"","severity":"Medium","summary":"The synchronized or provisioned voicemail system is invalid.","rootCause":"The account references a voicemail system that is absent, unsupported, or incorrectly provisioned.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Select and provision a valid voicemail system for the user, synchronize again, and verify voicemail access.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCollab - Invalid Voice Mail System.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiCollab Client Administrator Guide.pdf.\nProduct scope: MiCollab Client Service 10.0.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiCollab Client Administrator Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Voicemail","Provisioning"],"articleCategories":["Mitel","VoIP","Telephony","Voicemail","Provisioning"],"aliases":["MiCollab - Invalid Voice Mail System"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60002,"title":"MiCollab - Authentication Failed","category":"Mitel","product":"MiCollab Client Service 10.0","tags":["Mitel","Unified Communications","Telephony","Authentication","Login"],"keywords":["MiCollab - Authentication Failed","MiCollab Client Service 10.0","MiCollab rejected a user authentication attempt.","Mitel","PBX","VoIP","SIP","Authentication","Login"],"errorCode":"","eventId":"","severity":"High","summary":"MiCollab rejected a user authentication attempt.","rootCause":"The supplied username or password is invalid, or the account is not provisioned as expected.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Verify the intended account and enter valid credentials; check lockout, provisioning, directory synchronization, and authentication logs if it persists.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCollab - Authentication Failed.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiCollab Client Administrator Guide.pdf.\nProduct scope: MiCollab Client Service 10.0.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiCollab Client Administrator Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Authentication","Login"],"articleCategories":["Mitel","VoIP","Telephony","Authentication","Login"],"aliases":["MiCollab - Authentication Failed"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60003,"title":"MiCollab - Password Too Short","category":"Mitel","product":"MiCollab Client Service 10.0","tags":["Mitel","Unified Communications","Telephony","Authentication","Password Policy"],"keywords":["MiCollab - Password Too Short","MiCollab Client Service 10.0","The supplied user password does not meet the minimum length requirement.","Mitel","PBX","VoIP","SIP","Authentication","Password Policy"],"errorCode":"","eventId":"","severity":"Medium","summary":"The supplied user password does not meet the minimum length requirement.","rootCause":"The password is shorter than the configured or product-required minimum.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Set a longer policy-compliant password through the approved identity workflow, then retry without exposing the password in logs or tickets.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCollab - Password Too Short.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiCollab Client Administrator Guide.pdf.\nProduct scope: MiCollab Client Service 10.0.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiCollab Client Administrator Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Authentication","Password Policy"],"articleCategories":["Mitel","VoIP","Telephony","Authentication","Password Policy"],"aliases":["MiCollab - Password Too Short"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60004,"title":"MiCollab LDAP - Error Establishing LDAP Context","category":"Mitel","product":"MiCollab Client Service 10.0","tags":["Mitel","Unified Communications","Telephony","LDAP","AD Sync","Directory"],"keywords":["MiCollab LDAP - Error Establishing LDAP Context","MiCollab Client Service 10.0","MiCollab cannot establish an LDAP context with the configured directory URL.","Mitel","PBX","VoIP","SIP","LDAP","AD Sync","Directory"],"errorCode":"","eventId":"","severity":"High","summary":"MiCollab cannot establish an LDAP context with the configured directory URL.","rootCause":"The LDAP server address, port, URL, DNS, routing, firewall, TLS, or service availability is incorrect.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Verify the LDAP URL, hostname resolution, port, directory availability, certificate trust, and network path from MiCollab before synchronizing again.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCollab LDAP - Error Establishing LDAP Context.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiCollab Client Administrator Guide.pdf.\nProduct scope: MiCollab Client Service 10.0.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiCollab Client Administrator Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","LDAP","AD Sync","Directory"],"articleCategories":["Mitel","VoIP","Telephony","LDAP","AD Sync","Directory"],"aliases":["MiCollab LDAP - Error Establishing LDAP Context"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60005,"title":"MiCollab LDAP 49 / Data 525 - Invalid Credentials or User Not Found","category":"Mitel","product":"MiCollab Client Service 10.0","tags":["Mitel","Unified Communications","Telephony","LDAP","Active Directory","Bind Account"],"keywords":["MiCollab LDAP 49 / Data 525 - Invalid Credentials or User Not Found","MiCollab Client Service 10.0","LDAP error 49 with data 525 indicates that directory authentication could not locate or authenticate the configured user.","LDAP 49 / 525","Mitel","PBX","VoIP","SIP","LDAP","Active Directory","Bind Account"],"errorCode":"LDAP 49 / 525","eventId":"","severity":"High","summary":"LDAP error 49 with data 525 indicates that directory authentication could not locate or authenticate the configured user.","rootCause":"The bind username format, account, password, directory realm, or saved credentials are incorrect.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Confirm the bind identity and accepted username format, update the saved credential securely, and retry a limited synchronization.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCollab LDAP 49 / Data 525 - Invalid Credentials or User Not Found.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiCollab Client Administrator Guide.pdf.\nProduct scope: MiCollab Client Service 10.0.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiCollab Client Administrator Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","LDAP","Active Directory","Bind Account"],"articleCategories":["Mitel","VoIP","Telephony","LDAP","Active Directory","Bind Account"],"aliases":["LDAP 49 / 525","MiCollab LDAP 49 / Data 525 - Invalid Credentials or User Not Found"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60006,"title":"MiCollab LDAP 12 - Unavailable Critical Extension","category":"Mitel","product":"MiCollab Client Service 10.0","tags":["Mitel","Unified Communications","Telephony","LDAP","Critical Extension","Compatibility"],"keywords":["MiCollab LDAP 12 - Unavailable Critical Extension","MiCollab Client Service 10.0","The LDAP server rejected a requested critical extension.","LDAP 12","Mitel","PBX","VoIP","SIP","LDAP","Critical Extension","Compatibility"],"errorCode":"LDAP 12","eventId":"","severity":"High","summary":"The LDAP server rejected a requested critical extension.","rootCause":"The server does not support the requested LDAP control or the configured synchronization behavior is incompatible.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Confirm directory-server compatibility and supported controls, review the exact LDAP response, and adjust the synchronizer only according to Mitel and directory guidance.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCollab LDAP 12 - Unavailable Critical Extension.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiCollab Client Administrator Guide.pdf.\nProduct scope: MiCollab Client Service 10.0.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiCollab Client Administrator Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","LDAP","Critical Extension","Compatibility"],"articleCategories":["Mitel","VoIP","Telephony","LDAP","Critical Extension","Compatibility"],"aliases":["LDAP 12","MiCollab LDAP 12 - Unavailable Critical Extension"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60007,"title":"MiCollab - PBX Authentication or Version Incompatibility","category":"Mitel","product":"MiCollab Client Service 10.0 / MiVoice Business","tags":["Mitel","Unified Communications","Telephony","MiVoice Business","Compatibility","Synchronization"],"keywords":["MiCollab - PBX Authentication or Version Incompatibility","MiCollab Client Service 10.0 / MiVoice Business","MiCollab cannot authenticate to or correctly exchange synchronization data with MiVoice Business.","Mitel","PBX","VoIP","SIP","MiVoice Business","Compatibility","Synchronization"],"errorCode":"","eventId":"","severity":"High","summary":"MiCollab cannot authenticate to or correctly exchange synchronization data with MiVoice Business.","rootCause":"MiCollab and MiVoice Business releases can be incompatible, or credentials and integration configuration can be wrong.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Check the Mitel compatibility matrix and both product versions, validate integration credentials, then upgrade through a supported path if required.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCollab - PBX Authentication or Version Incompatibility.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiCollab Client Administrator Guide.pdf.\nProduct scope: MiCollab Client Service 10.0 / MiVoice Business.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiCollab Client Administrator Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","MiVoice Business","Compatibility","Synchronization"],"articleCategories":["Mitel","VoIP","Telephony","MiVoice Business","Compatibility","Synchronization"],"aliases":["MiCollab - PBX Authentication or Version Incompatibility"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60008,"title":"MiCollab - Version Request or Fetch Failed","category":"Mitel","product":"MiCollab Client Service 10.0 / MiVoice Business","tags":["Mitel","Unified Communications","Telephony","MiVoice Business","Version","Synchronization"],"keywords":["MiCollab - Version Request or Fetch Failed","MiCollab Client Service 10.0 / MiVoice Business","MiCollab could not retrieve a compatible MiVoice Business version response.","Mitel","PBX","VoIP","SIP","MiVoice Business","Version","Synchronization"],"errorCode":"","eventId":"","severity":"High","summary":"MiCollab could not retrieve a compatible MiVoice Business version response.","rootCause":"Network reachability, service state, authentication, or unsupported product-version pairing can prevent the version exchange.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Verify PBX reachability and services, then compare releases with the compatibility matrix and use a supported upgrade path.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCollab - Version Request or Fetch Failed.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiCollab Client Administrator Guide.pdf.\nProduct scope: MiCollab Client Service 10.0 / MiVoice Business.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiCollab Client Administrator Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","MiVoice Business","Version","Synchronization"],"articleCategories":["Mitel","VoIP","Telephony","MiVoice Business","Version","Synchronization"],"aliases":["MiCollab - Version Request or Fetch Failed"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60009,"title":"MiCollab Collaboration Sync - Unknown Host Exception","category":"Mitel","product":"MiCollab Client Service 10.0","tags":["Mitel","Unified Communications","Telephony","Collaboration Server","DNS","Synchronization"],"keywords":["MiCollab Collaboration Sync - Unknown Host Exception","MiCollab Client Service 10.0","MiCollab cannot resolve the Collaboration Server hostname during synchronization.","Mitel","PBX","VoIP","SIP","Collaboration Server","DNS","Synchronization"],"errorCode":"","eventId":"","severity":"High","summary":"MiCollab cannot resolve the Collaboration Server hostname during synchronization.","rootCause":"DNS configuration, search suffix, hostname spelling, record availability, or resolver reachability is incorrect.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Correct DNS or the configured hostname, verify resolution from MiCollab, restart MiCollab Client Service if appropriate, and retry Sync Now.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCollab Collaboration Sync - Unknown Host Exception.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiCollab Client Administrator Guide.pdf.\nProduct scope: MiCollab Client Service 10.0.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiCollab Client Administrator Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Collaboration Server","DNS","Synchronization"],"articleCategories":["Mitel","VoIP","Telephony","Collaboration Server","DNS","Synchronization"],"aliases":["MiCollab Collaboration Sync - Unknown Host Exception"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60010,"title":"MiCollab - Rejecting Invalid SIP Message","category":"Mitel","product":"MiCollab Client Service 10.0","tags":["Mitel","Unified Communications","Telephony","SIP","Invalid Message","Protocol"],"keywords":["MiCollab - Rejecting Invalid SIP Message","MiCollab Client Service 10.0","MiCollab rejected a SIP message that did not satisfy expected syntax or protocol behavior.","Mitel","PBX","VoIP","SIP","SIP","Invalid Message","Protocol"],"errorCode":"","eventId":"","severity":"High","summary":"MiCollab rejected a SIP message that did not satisfy expected syntax or protocol behavior.","rootCause":"A client, gateway, intermediary, corruption, unsupported extension, or malformed integration generated invalid SIP.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Identify the sending IP and sanitized message, validate it against the supported SIP behavior, and correct the originating client or intermediary.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCollab - Rejecting Invalid SIP Message.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiCollab Client Administrator Guide.pdf.\nProduct scope: MiCollab Client Service 10.0.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiCollab Client Administrator Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","SIP","Invalid Message","Protocol"],"articleCategories":["Mitel","VoIP","Telephony","SIP","Invalid Message","Protocol"],"aliases":["MiCollab - Rejecting Invalid SIP Message"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60011,"title":"MiCollab - Subscription Queue Size Reached","category":"Mitel","product":"MiCollab Client Service 10.0","tags":["Mitel","Unified Communications","Telephony","Subscription","Queue","Performance"],"keywords":["MiCollab - Subscription Queue Size Reached","MiCollab Client Service 10.0","Pending notifications for a subscription exceeded what the subscriber was consuming.","Mitel","PBX","VoIP","SIP","Subscription","Queue","Performance"],"errorCode":"","eventId":"","severity":"Medium","summary":"Pending notifications for a subscription exceeded what the subscriber was consuming.","rootCause":"A slow or disconnected client, notification burst, resource pressure, or a stuck subscription can grow the queue.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Identify the subscription and client, check service and network health, monitor queue recovery, and restart or remediate only the affected component if evidenced.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCollab - Subscription Queue Size Reached.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiCollab Client Administrator Guide.pdf.\nProduct scope: MiCollab Client Service 10.0.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiCollab Client Administrator Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Subscription","Queue","Performance"],"articleCategories":["Mitel","VoIP","Telephony","Subscription","Queue","Performance"],"aliases":["MiCollab - Subscription Queue Size Reached"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60012,"title":"MiCollab Watchdog - CPU Congestion","category":"Mitel","product":"MiCollab Client Service 10.0","tags":["Mitel","Unified Communications","Telephony","Watchdog","CPU","DB_CHECK","Performance"],"keywords":["MiCollab Watchdog - CPU Congestion","MiCollab Client Service 10.0","The watchdog reports DB_CHECK CPU congestion with yellow, orange, or red severity levels.","Mitel","PBX","VoIP","SIP","Watchdog","CPU","DB_CHECK","Performance"],"errorCode":"","eventId":"","severity":"High","summary":"The watchdog reports DB_CHECK CPU congestion with yellow, orange, or red severity levels.","rootCause":"Sustained workload, runaway service activity, synchronization volume, insufficient resources, or platform contention raised CPU utilization.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Correlate the alarm with process, synchronization, call, and virtualization metrics; correct the workload or capacity cause before changing thresholds.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCollab Watchdog - CPU Congestion.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiCollab Client Administrator Guide.pdf.\nProduct scope: MiCollab Client Service 10.0.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiCollab Client Administrator Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Watchdog","CPU","DB_CHECK","Performance"],"articleCategories":["Mitel","VoIP","Telephony","Watchdog","CPU","DB_CHECK","Performance"],"aliases":["MiCollab Watchdog - CPU Congestion"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60013,"title":"SXERR_DEVICE_ALREADY_MONITORED","category":"Mitel","product":"MiCollab Client Service 10.0 / MiTAI","tags":["Mitel","Unified Communications","Telephony","MiTAI","Device Monitoring"],"keywords":["SXERR_DEVICE_ALREADY_MONITORED","MiCollab Client Service 10.0 / MiTAI","MiTAI received a request to monitor a device that was already monitored.","SXERR_DEVICE_ALREADY_MONITORED","Mitel","PBX","VoIP","SIP","MiTAI","Device Monitoring"],"errorCode":"SXERR_DEVICE_ALREADY_MONITORED","eventId":"","severity":"Low","summary":"MiTAI received a request to monitor a device that was already monitored.","rootCause":"MiCollab attempted duplicate monitoring, often making this a warning rather than a service failure.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Confirm whether monitoring is already active, check for duplicate account/device state, and investigate repeated requests only if functionality is affected.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified SXERR_DEVICE_ALREADY_MONITORED.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiCollab Client Administrator Guide.pdf.\nProduct scope: MiCollab Client Service 10.0 / MiTAI.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiCollab Client Administrator Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","MiTAI","Device Monitoring"],"articleCategories":["Mitel","VoIP","Telephony","MiTAI","Device Monitoring"],"aliases":["SXERR_DEVICE_ALREADY_MONITORED","SXERR_DEVICE_ALREADY_MONITORED"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60014,"title":"SXERR_FEATURE_NOT_ALLOWED","category":"Mitel","product":"MiCollab Client Service 10.0 / MiTAI","tags":["Mitel","Unified Communications","Telephony","MiTAI","Class of Service","Call Control"],"keywords":["SXERR_FEATURE_NOT_ALLOWED","MiCollab Client Service 10.0 / MiTAI","A MiTAI call-processing request was not allowed in the device's current state.","SXERR_FEATURE_NOT_ALLOWED","Mitel","PBX","VoIP","SIP","MiTAI","Class of Service","Call Control"],"errorCode":"SXERR_FEATURE_NOT_ALLOWED","eventId":"","severity":"Medium","summary":"A MiTAI call-processing request was not allowed in the device's current state.","rootCause":"Switch configuration, feature availability, class of service, or the live call/device state prevents the operation.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Verify device state, feature programming, class of service, and supported invocation sequence before retrying.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified SXERR_FEATURE_NOT_ALLOWED.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiCollab Client Administrator Guide.pdf.\nProduct scope: MiCollab Client Service 10.0 / MiTAI.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiCollab Client Administrator Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","MiTAI","Class of Service","Call Control"],"articleCategories":["Mitel","VoIP","Telephony","MiTAI","Class of Service","Call Control"],"aliases":["SXERR_FEATURE_NOT_ALLOWED","SXERR_FEATURE_NOT_ALLOWED"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60015,"title":"SXERR_PRIVILEDGE_VIOLATION","category":"Mitel","product":"MiCollab Client Service 10.0 / MiTAI","tags":["Mitel","Unified Communications","Telephony","MiTAI","Privilege","Class of Service"],"keywords":["SXERR_PRIVILEDGE_VIOLATION","MiCollab Client Service 10.0 / MiTAI","The MiTAI service invoker lacks sufficient privileges for the requested operation.","SXERR_PRIVILEDGE_VIOLATION","Mitel","PBX","VoIP","SIP","MiTAI","Privilege","Class of Service"],"errorCode":"SXERR_PRIVILEDGE_VIOLATION","eventId":"","severity":"High","summary":"The MiTAI service invoker lacks sufficient privileges for the requested operation.","rootCause":"The device class of service or integration identity does not permit the function.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Review the exact operation and least-privilege class-of-service assignment; correct authorized provisioning rather than bypassing controls.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified SXERR_PRIVILEDGE_VIOLATION.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiCollab Client Administrator Guide.pdf.\nProduct scope: MiCollab Client Service 10.0 / MiTAI.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiCollab Client Administrator Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","MiTAI","Privilege","Class of Service"],"articleCategories":["Mitel","VoIP","Telephony","MiTAI","Privilege","Class of Service"],"aliases":["SXERR_PRIVILEDGE_VIOLATION","SXERR_PRIVILEDGE_VIOLATION"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60016,"title":"SXERR_MITAI_SERVER_TIMEOUT_ERROR","category":"Mitel","product":"MiCollab Client Service 10.0 / MiTAI","tags":["Mitel","Unified Communications","Telephony","MiTAI","Timeout","PBX"],"keywords":["SXERR_MITAI_SERVER_TIMEOUT_ERROR","MiCollab Client Service 10.0 / MiTAI","A MiTAI API invocation timed out because the MiTAI server connection was unavailable or unresponsive.","SXERR_MITAI_SERVER_TIMEOUT_ERROR","Mitel","PBX","VoIP","SIP","MiTAI","Timeout","PBX"],"errorCode":"SXERR_MITAI_SERVER_TIMEOUT_ERROR","eventId":"","severity":"High","summary":"A MiTAI API invocation timed out because the MiTAI server connection was unavailable or unresponsive.","rootCause":"Network interruption, PBX or MiTAI service state, overload, or compatibility trouble can prevent a timely response.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Verify MiTAI/PBX services and connectivity, correlate server logs and load, restore the supported connection, and retry once stable.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified SXERR_MITAI_SERVER_TIMEOUT_ERROR.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiCollab Client Administrator Guide.pdf.\nProduct scope: MiCollab Client Service 10.0 / MiTAI.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiCollab Client Administrator Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","MiTAI","Timeout","PBX"],"articleCategories":["Mitel","VoIP","Telephony","MiTAI","Timeout","PBX"],"aliases":["SXERR_MITAI_SERVER_TIMEOUT_ERROR","SXERR_MITAI_SERVER_TIMEOUT_ERROR"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60017,"title":"MiCollab AWV - Failed to Reach MBG Audio Gateway","category":"Mitel","product":"MiCollab Audio, Web and Video 9.7","tags":["Mitel","Unified Communications","Telephony","AWV","MBG","WebRTC","Audio"],"keywords":["MiCollab AWV - Failed to Reach MBG Audio Gateway","MiCollab Audio, Web and Video 9.7","The Web Client cannot reach the configured MiVoice Border Gateway audio service.","Mitel","PBX","VoIP","SIP","AWV","MBG","WebRTC","Audio"],"errorCode":"","eventId":"","severity":"High","summary":"The Web Client cannot reach the configured MiVoice Border Gateway audio service.","rootCause":"Internet connectivity, DNS, firewall policy, MBG FQDN or port configuration, or MBG service state is wrong.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Verify stable client connectivity and that the configured MBG FQDN and port are reachable and correct in MBG WebRTC settings.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCollab AWV - Failed to Reach MBG Audio Gateway.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiCollab 9.7 online troubleshooting.\nProduct scope: MiCollab Audio, Web and Video 9.7.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiCollab 9.7 online troubleshooting","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","AWV","MBG","WebRTC","Audio"],"articleCategories":["Mitel","VoIP","Telephony","AWV","MBG","WebRTC","Audio"],"aliases":["MiCollab AWV - Failed to Reach MBG Audio Gateway"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60018,"title":"MiCollab AWV - MBG Audio Gateway Authentication Failed","category":"Mitel","product":"MiCollab Audio, Web and Video 9.7","tags":["Mitel","Unified Communications","Telephony","AWV","MBG","WebRTC","Shared Secret"],"keywords":["MiCollab AWV - MBG Audio Gateway Authentication Failed","MiCollab Audio, Web and Video 9.7","The AWV Web Client reached MBG but audio-gateway authentication failed.","Mitel","PBX","VoIP","SIP","AWV","MBG","WebRTC","Shared Secret"],"errorCode":"","eventId":"","severity":"High","summary":"The AWV Web Client reached MBG but audio-gateway authentication failed.","rootCause":"The WebRTC web-server shared secret configured between AWV and MBG does not match.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Have an authorized administrator compare and securely reset the WebRTC shared secret on both systems; never paste it into logs or tickets.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCollab AWV - MBG Audio Gateway Authentication Failed.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiCollab 9.7 online troubleshooting.\nProduct scope: MiCollab Audio, Web and Video 9.7.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiCollab 9.7 online troubleshooting","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","AWV","MBG","WebRTC","Shared Secret"],"articleCategories":["Mitel","VoIP","Telephony","AWV","MBG","WebRTC","Shared Secret"],"aliases":["MiCollab AWV - MBG Audio Gateway Authentication Failed"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60019,"title":"MiCollab AWV - No Audio Device Detected","category":"Mitel","product":"MiCollab Audio, Web and Video 9.7","tags":["Mitel","Unified Communications","Telephony","AWV","Audio Device","Microphone","Browser"],"keywords":["MiCollab AWV - No Audio Device Detected","MiCollab Audio, Web and Video 9.7","The Web Client cannot find a usable microphone or audio device.","Mitel","PBX","VoIP","SIP","AWV","Audio Device","Microphone","Browser"],"errorCode":"","eventId":"","severity":"Medium","summary":"The Web Client cannot find a usable microphone or audio device.","rootCause":"No device is attached, the OS or browser selected another device, permission is blocked, or the driver/device is unavailable.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Connect and select a working audio device, allow microphone access for the site, verify operating-system audio settings, and rejoin the call.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCollab AWV - No Audio Device Detected.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiCollab 9.7 online troubleshooting.\nProduct scope: MiCollab Audio, Web and Video 9.7.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiCollab 9.7 online troubleshooting","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","AWV","Audio Device","Microphone","Browser"],"articleCategories":["Mitel","VoIP","Telephony","AWV","Audio Device","Microphone","Browser"],"aliases":["MiCollab AWV - No Audio Device Detected"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60020,"title":"MiVoice Business - Internal DHCP Not Supplying Addresses","category":"Mitel","product":"MiVoice Business 10.0","tags":["Mitel","Unified Communications","Telephony","DHCP","IP Phones","Initial Setup"],"keywords":["MiVoice Business - Internal DHCP Not Supplying Addresses","MiVoice Business 10.0","After installation, the internal DHCP server does not assign addresses to IP devices.","Mitel","PBX","VoIP","SIP","DHCP","IP Phones","Initial Setup"],"errorCode":"","eventId":"","severity":"High","summary":"After installation, the internal DHCP server does not assign addresses to IP devices.","rootCause":"The MiVoice Business internal DHCP server is not enabled by default.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Determine the authoritative DHCP design; if the internal server is intended, enable and configure it through Server Manager, then verify scope, options, VLAN, and leases.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Business - Internal DHCP Not Supplying Addresses.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: mivoice_business_trbl.pdf.\nProduct scope: MiVoice Business 10.0.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"mivoice_business_trbl.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","DHCP","IP Phones","Initial Setup"],"articleCategories":["Mitel","VoIP","Telephony","DHCP","IP Phones","Initial Setup"],"aliases":["MiVoice Business - Internal DHCP Not Supplying Addresses"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60021,"title":"MiVoice Business - System Unable to Boot","category":"Mitel","product":"MiVoice Business 10.0 / 3300 ICP","tags":["Mitel","Unified Communications","Telephony","3300 ICP","Boot","Recovery"],"keywords":["MiVoice Business - System Unable to Boot","MiVoice Business 10.0 / 3300 ICP","The MiVoice Business system cannot boot from its expected system partition or image.","Mitel","PBX","VoIP","SIP","3300 ICP","Boot","Recovery"],"errorCode":"","eventId":"","severity":"Critical","summary":"The MiVoice Business system cannot boot from its expected system partition or image.","rootCause":"Software partition damage, storage trouble, failed upgrade, boot configuration, or hardware can prevent startup.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Preserve console evidence and backups, follow the documented Server Manager, SSH, or maintenance-port recovery path for the exact controller, and escalate before destructive recovery.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Business - System Unable to Boot.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: mivoice_business_trbl.pdf.\nProduct scope: MiVoice Business 10.0 / 3300 ICP.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"mivoice_business_trbl.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","3300 ICP","Boot","Recovery"],"articleCategories":["Mitel","VoIP","Telephony","3300 ICP","Boot","Recovery"],"aliases":["MiVoice Business - System Unable to Boot"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60022,"title":"MiVoice Business - Backup or Restore Failure","category":"Mitel","product":"MiVoice Business 10.0","tags":["Mitel","Unified Communications","Telephony","Backup","Restore","Database"],"keywords":["MiVoice Business - Backup or Restore Failure","MiVoice Business 10.0","A scheduled or manual system backup or restore does not complete successfully.","Mitel","PBX","VoIP","SIP","Backup","Restore","Database"],"errorCode":"","eventId":"","severity":"Critical","summary":"A scheduled or manual system backup or restore does not complete successfully.","rootCause":"Storage, credentials, network share, space, permissions, database consistency, version compatibility, or service state can interrupt the operation.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Capture the exact maintenance-log error, validate destination access and capacity, confirm release compatibility, and test a new backup before relying on recovery media.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Business - Backup or Restore Failure.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: mivoice_business_trbl.pdf.\nProduct scope: MiVoice Business 10.0.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"mivoice_business_trbl.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Backup","Restore","Database"],"articleCategories":["Mitel","VoIP","Telephony","Backup","Restore","Database"],"aliases":["MiVoice Business - Backup or Restore Failure"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60023,"title":"MiVoice Business - System Data Synchronization Failure","category":"Mitel","product":"MiVoice Business 10.0","tags":["Mitel","Unified Communications","Telephony","Synchronization","Cluster","Replication"],"keywords":["MiVoice Business - System Data Synchronization Failure","MiVoice Business 10.0","Clustered or networked system data does not synchronize correctly between nodes.","Mitel","PBX","VoIP","SIP","Synchronization","Cluster","Replication"],"errorCode":"","eventId":"","severity":"Critical","summary":"Clustered or networked system data does not synchronize correctly between nodes.","rootCause":"Node reachability, database state, version mismatch, trust, replication backlog, or object-specific distribution errors can stop synchronization.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Identify the failed nodes and data type, inspect synchronization and maintenance logs, verify reachability and version alignment, then repair the evidenced distribution issue.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Business - System Data Synchronization Failure.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: mivoice_business_trbl.pdf.\nProduct scope: MiVoice Business 10.0.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"mivoice_business_trbl.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Synchronization","Cluster","Replication"],"articleCategories":["Mitel","VoIP","Telephony","Synchronization","Cluster","Replication"],"aliases":["MiVoice Business - System Data Synchronization Failure"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60024,"title":"MiVoice Business - Invalid Service Level Change","category":"Mitel","product":"MiVoice Business","tags":["Mitel","Unified Communications","Telephony","Service Level","User and Services Configuration","Extension","Keys","Hunt Groups","Ring Groups","Pickup Groups","Page Groups","Class of Service"],"keywords":["MiVoice Business - Invalid Service Level Change","MiVoice Business","MiVoice Business refuses to change an extension's Service Level in User and Services Configuration.","Invalid service level change","Mitel","PBX","VoIP","SIP","Service Level","User and Services Configuration","Extension","Keys","Hunt Groups","Ring Groups","Pickup Groups","Page Groups","Class of Service"],"errorCode":"Invalid service level change","eventId":"","severity":"High","summary":"MiVoice Business refuses to change an extension's Service Level in User and Services Configuration.","rootCause":"The extension remains referenced by programmed keys, line appearances, BLFs, speed dials, Hunt Groups, Ring Groups, Pickup Groups, Page Groups, or another dependent system object. The system blocks the change to avoid leaving inconsistent programming.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Recommended — clear dependencies: document the current user, voicemail, Class of Service, keys, line appearances, and group memberships; remove the extension's assigned keys and remove it from Hunt, Ring, Pickup, and Page Groups; change and save the Service Level; then deliberately restore only the required keys and memberships. Alternative — delete and recreate: use only after documenting the complete configuration and confirming backup and rollback; if deletion reports another dependency, remove that reference first; recreate the same extension with the intended Service Level and restore the validated configuration.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Business - Invalid Service Level Change.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: User-supplied MiVoice Business troubleshooting procedure.\nProduct scope: MiVoice Business.\nReview status: Needs verification before publication.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.\n\nDeleting and recreating an extension can affect voicemail association, mailbox access, keys, line appearances, groups, Class of Service, forwarding, licensing, emergency-location data, and active service. Use an approved maintenance window, capture screenshots or an export, confirm rollback, and validate inbound, outbound, voicemail, transfer, group, and emergency-calling behavior afterward.","commands":[],"sourceDocument":"User-supplied MiVoice Business troubleshooting procedure","sourceAuthority":"User-supplied MSP procedure","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Service Level","User and Services Configuration","Extension","Keys","Hunt Groups","Ring Groups","Pickup Groups","Page Groups","Class of Service"],"articleCategories":["Mitel","VoIP","Telephony","Service Level","User and Services Configuration","Extension","Keys","Hunt Groups","Ring Groups","Pickup Groups","Page Groups","Class of Service"],"aliases":["Invalid service level change","MiVoice Business - Invalid Service Level Change"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":60025,"title":"MiVoice Connect - Collect Server Logs","category":"Mitel","product":"MiVoice Connect Maintenance Guide 2019","tags":["Mitel","Unified Communications","Telephony","Logs","Diagnostics","ServerLog"],"keywords":["MiVoice Connect - Collect Server Logs","MiVoice Connect Maintenance Guide 2019","Mitel support troubleshooting requires a bounded collection of the relevant server logs.","Mitel","PBX","VoIP","SIP","Logs","Diagnostics","ServerLog","ServerLog.exe -?"],"errorCode":"","eventId":"","severity":"Low","summary":"Mitel support troubleshooting requires a bounded collection of the relevant server logs.","rootCause":"Distributed services create separate engineering logs, so an incomplete time range or component selection can omit the fault evidence.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Use the supported ServerLog utility or log-collection interface for the affected component and narrow time range; sanitize and transfer the archive securely.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Connect - Collect Server Logs.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: 6MiVoice Connect Maintenance Guide.pdf.\nProduct scope: MiVoice Connect Maintenance Guide 2019.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[{"shell":"Windows Shell","command":"ServerLog.exe -?","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"6MiVoice Connect Maintenance Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Logs","Diagnostics","ServerLog"],"articleCategories":["Mitel","VoIP","Telephony","Logs","Diagnostics","ServerLog"],"aliases":["MiVoice Connect - Collect Server Logs"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60026,"title":"MiVoice Connect Voice Switch - No DHCP Address","category":"Mitel","product":"MiVoice Connect Maintenance Guide 2019","tags":["Mitel","Unified Communications","Telephony","Voice Switch","DHCP","Boot"],"keywords":["MiVoice Connect Voice Switch - No DHCP Address","MiVoice Connect Maintenance Guide 2019","A new or reset voice switch continues polling because it cannot obtain an IP address.","Mitel","PBX","VoIP","SIP","Voice Switch","DHCP","Boot"],"errorCode":"","eventId":"","severity":"High","summary":"A new or reset voice switch continues polling because it cannot obtain an IP address.","rootCause":"DHCP is unavailable, the VLAN or relay is wrong, the scope is exhausted, or required boot options are missing.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Verify switch-port VLAN, DHCP scope, relay, reservations, and required options. Use the maintenance interface for deliberate static configuration only when DHCP is not part of the design.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Connect Voice Switch - No DHCP Address.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: 6MiVoice Connect Maintenance Guide.pdf.\nProduct scope: MiVoice Connect Maintenance Guide 2019.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"6MiVoice Connect Maintenance Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Voice Switch","DHCP","Boot"],"articleCategories":["Mitel","VoIP","Telephony","Voice Switch","DHCP","Boot"],"aliases":["MiVoice Connect Voice Switch - No DHCP Address"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60027,"title":"MiVoice Connect - Voice Switch Packet Capture","category":"Mitel","product":"MiVoice Connect Maintenance Guide 2019","tags":["Mitel","Unified Communications","Telephony","Packet Capture","tcpdump","Diagnostics"],"keywords":["MiVoice Connect - Voice Switch Packet Capture","MiVoice Connect Maintenance Guide 2019","Packet evidence is required to diagnose signaling, trunk, or switch-network behavior.","Mitel","PBX","VoIP","SIP","Packet Capture","tcpdump","Diagnostics","tcpdump -C 10 -W 3 -w /var/log/tcpdump.pcap"],"errorCode":"","eventId":"","severity":"High","summary":"Packet evidence is required to diagnose signaling, trunk, or switch-network behavior.","rootCause":"Counters and logs may not show the packets, timing, retransmissions, or negotiation involved in the failure.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Define the narrowest interface, duration, and problem window; use the supported Remote Packet Capture or bounded tcpdump workflow, stop promptly, and protect voice data.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Connect - Voice Switch Packet Capture.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: 6MiVoice Connect Maintenance Guide.pdf.\nProduct scope: MiVoice Connect Maintenance Guide 2019.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[{"shell":"Mitel CLI","command":"tcpdump -C 10 -W 3 -w /var/log/tcpdump.pcap","risk":"Standard","safetyLevel":"Low-Risk Temporary"}],"sourceDocument":"6MiVoice Connect Maintenance Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Packet Capture","tcpdump","Diagnostics"],"articleCategories":["Mitel","VoIP","Telephony","Packet Capture","tcpdump","Diagnostics"],"aliases":["MiVoice Connect - Voice Switch Packet Capture"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60028,"title":"MiVoice Connect - CompactFlash File System Not Mounted","category":"Mitel","product":"MiVoice Connect Voicemail-Enabled Switch","tags":["Mitel","Unified Communications","Telephony","CompactFlash","Voicemail","Storage"],"keywords":["MiVoice Connect - CompactFlash File System Not Mounted","MiVoice Connect Voicemail-Enabled Switch","The /cf file system is absent from service-status output, leaving voicemail and persistent logs without their expected CompactFlash storage.","Mitel","PBX","VoIP","SIP","CompactFlash","Voicemail","Storage","getsvcstatus all"],"errorCode":"","eventId":"","severity":"Critical","summary":"The /cf file system is absent from service-status output, leaving voicemail and persistent logs without their expected CompactFlash storage.","rootCause":"A damaged, failed, unmounted, or inaccessible CompactFlash device or file system is suspected.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Run read-only service status, perform an authorized on-demand voicemail backup immediately if possible, and follow Mitel support guidance before replacing or repairing storage.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Connect - CompactFlash File System Not Mounted.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: 6MiVoice Connect Maintenance Guide.pdf.\nProduct scope: MiVoice Connect Voicemail-Enabled Switch.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[{"shell":"Mitel CLI","command":"getsvcstatus all","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"6MiVoice Connect Maintenance Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","CompactFlash","Voicemail","Storage"],"articleCategories":["Mitel","VoIP","Telephony","CompactFlash","Voicemail","Storage"],"aliases":["MiVoice Connect - CompactFlash File System Not Mounted"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60029,"title":"MiVoice Connect Phone - 802.1X Authentication Failed","category":"Mitel","product":"MiVoice Connect 400-Series IP Phones","tags":["Mitel","Unified Communications","Telephony","IP Phone","802.1X","RADIUS","Authentication"],"keywords":["MiVoice Connect Phone - 802.1X Authentication Failed","MiVoice Connect 400-Series IP Phones","The phone cannot authenticate to the access network using 802.1X.","Mitel","PBX","VoIP","SIP","IP Phone","802.1X","RADIUS","Authentication"],"errorCode":"","eventId":"","severity":"High","summary":"The phone cannot authenticate to the access network using 802.1X.","rootCause":"Credentials, certificate, VLAN, switch authentication policy, RADIUS reachability, time, or supplicant configuration is incorrect.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Reboot once as documented, then verify the LAN's 802.1X configuration, RADIUS decision, phone identity, certificate trust, and time synchronization.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Connect Phone - 802.1X Authentication Failed.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: 6MiVoice Connect Maintenance Guide.pdf.\nProduct scope: MiVoice Connect 400-Series IP Phones.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"6MiVoice Connect Maintenance Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","IP Phone","802.1X","RADIUS","Authentication"],"articleCategories":["Mitel","VoIP","Telephony","IP Phone","802.1X","RADIUS","Authentication"],"aliases":["MiVoice Connect Phone - 802.1X Authentication Failed"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60030,"title":"MiVoice Connect Phone - Download Failed or File Missing","category":"Mitel","product":"MiVoice Connect 400-Series IP Phones","tags":["Mitel","Unified Communications","Telephony","IP Phone","Firmware","HTTP Resources"],"keywords":["MiVoice Connect Phone - Download Failed or File Missing","MiVoice Connect 400-Series IP Phones","The phone cannot download required firmware, configuration, or resource files.","Mitel","PBX","VoIP","SIP","IP Phone","Firmware","HTTP Resources"],"errorCode":"","eventId":"","severity":"High","summary":"The phone cannot download required firmware, configuration, or resource files.","rootCause":"The dedicated httpResources server or Headquarters server is unavailable, the file is missing, or configuration references an invalid resource.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Check the configured download server and Headquarters service, verify the exact referenced file and release, and correct the server-side package or path.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Connect Phone - Download Failed or File Missing.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: 6MiVoice Connect Maintenance Guide.pdf.\nProduct scope: MiVoice Connect 400-Series IP Phones.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"6MiVoice Connect Maintenance Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","IP Phone","Firmware","HTTP Resources"],"articleCategories":["Mitel","VoIP","Telephony","IP Phone","Firmware","HTTP Resources"],"aliases":["MiVoice Connect Phone - Download Failed or File Missing"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60031,"title":"MiVoice Connect Phone - Error Applying Hotfixes","category":"Mitel","product":"MiVoice Connect 400-Series IP Phones","tags":["Mitel","Unified Communications","Telephony","IP Phone","Hotfix","Firmware"],"keywords":["MiVoice Connect Phone - Error Applying Hotfixes","MiVoice Connect 400-Series IP Phones","A phone could not apply a configured hotfix.","Mitel","PBX","VoIP","SIP","IP Phone","Hotfix","Firmware"],"errorCode":"","eventId":"","severity":"High","summary":"A phone could not apply a configured hotfix.","rootCause":"The hotfix does not apply to the installed phone model or current firmware release, or its files are inconsistent.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Confirm model and release applicability; remove an inapplicable hotfix from configuration or install the correct supported package on the server.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Connect Phone - Error Applying Hotfixes.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: 6MiVoice Connect Maintenance Guide.pdf.\nProduct scope: MiVoice Connect 400-Series IP Phones.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"6MiVoice Connect Maintenance Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","IP Phone","Hotfix","Firmware"],"articleCategories":["Mitel","VoIP","Telephony","IP Phone","Hotfix","Firmware"],"aliases":["MiVoice Connect Phone - Error Applying Hotfixes"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60032,"title":"MiVoice Connect Phone - No Ethernet Link Detected","category":"Mitel","product":"MiVoice Connect 400-Series IP Phones","tags":["Mitel","Unified Communications","Telephony","IP Phone","Ethernet","PoE"],"keywords":["MiVoice Connect Phone - No Ethernet Link Detected","MiVoice Connect 400-Series IP Phones","The phone reports no Ethernet link outside the normal transient reboot sequence.","Mitel","PBX","VoIP","SIP","IP Phone","Ethernet","PoE"],"errorCode":"","eventId":"","severity":"High","summary":"The phone reports no Ethernet link outside the normal transient reboot sequence.","rootCause":"Cabling, switch port, PoE, negotiation, VLAN, or phone hardware is preventing link.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Ignore only the documented transient boot message; otherwise test a known-good cable and enabled PoE port, then verify link and switch counters.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Connect Phone - No Ethernet Link Detected.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: 6MiVoice Connect Maintenance Guide.pdf.\nProduct scope: MiVoice Connect 400-Series IP Phones.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"6MiVoice Connect Maintenance Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","IP Phone","Ethernet","PoE"],"articleCategories":["Mitel","VoIP","Telephony","IP Phone","Ethernet","PoE"],"aliases":["MiVoice Connect Phone - No Ethernet Link Detected"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60033,"title":"MiVoice Connect Phone - No Service / SIP Authorization Failed","category":"Mitel","product":"MiVoice Connect 400-Series IP Phones","tags":["Mitel","Unified Communications","Telephony","IP Phone","SIP","Authorization","No Service"],"keywords":["MiVoice Connect Phone - No Service / SIP Authorization Failed","MiVoice Connect 400-Series IP Phones","The phone cannot obtain call service because SIP authorization failed.","Mitel","PBX","VoIP","SIP","IP Phone","SIP","Authorization","No Service"],"errorCode":"","eventId":"","severity":"High","summary":"The phone cannot obtain call service because SIP authorization failed.","rootCause":"Phone assignment, credentials, server reachability, time, configuration, version, or registration state is wrong.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Open the phone's detailed error view, use its Ping or Traceroute diagnostics, verify Headquarters/CAS reachability and assignment, and review SIP/server logs.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Connect Phone - No Service / SIP Authorization Failed.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: 6MiVoice Connect Maintenance Guide.pdf.\nProduct scope: MiVoice Connect 400-Series IP Phones.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"6MiVoice Connect Maintenance Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","IP Phone","SIP","Authorization","No Service"],"articleCategories":["Mitel","VoIP","Telephony","IP Phone","SIP","Authorization","No Service"],"aliases":["MiVoice Connect Phone - No Service / SIP Authorization Failed"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60034,"title":"MiVoice Connect Phone - User Assignment CAS Connection Failure","category":"Mitel","product":"MiVoice Connect 400-Series IP Phones","tags":["Mitel","Unified Communications","Telephony","IP Phone","CAS","User Assignment"],"keywords":["MiVoice Connect Phone - User Assignment CAS Connection Failure","MiVoice Connect 400-Series IP Phones","The phone cannot contact the Client Application Server during user assignment.","Mitel","PBX","VoIP","SIP","IP Phone","CAS","User Assignment"],"errorCode":"","eventId":"","severity":"High","summary":"The phone cannot contact the Client Application Server during user assignment.","rootCause":"CAS or Headquarters service state, DNS, routing, firewall, addressing, or server configuration is preventing the connection.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Verify CAS and Headquarters status, phone addressing and gateway, DNS and network path, then retry assignment after connectivity is restored.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Connect Phone - User Assignment CAS Connection Failure.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: 6MiVoice Connect Maintenance Guide.pdf.\nProduct scope: MiVoice Connect 400-Series IP Phones.\nVerified: 2026-08-10.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"6MiVoice Connect Maintenance Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-10","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","IP Phone","CAS","User Assignment"],"articleCategories":["Mitel","VoIP","Telephony","IP Phone","CAS","User Assignment"],"aliases":["MiVoice Connect Phone - User Assignment CAS Connection Failure"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":60100,"title":"MiCC Installation - Prerequisite Check Failed","category":"Mitel","product":"MiContact Center Enterprise / Business","tags":["Mitel","Unified Communications","Telephony","Installation","Windows Server","Prerequisites"],"keywords":["MiCC Installation - Prerequisite Check Failed","MiContact Center Enterprise / Business","The installer warns or stops because required Windows, IIS, SQL, domain, or product prerequisites are not satisfied.","Prerequisite check failed","Mitel","PBX","VoIP","SIP","Installation","Windows Server","Prerequisites"],"errorCode":"Prerequisite check failed","eventId":"","severity":"High","summary":"The installer warns or stops because required Windows, IIS, SQL, domain, or product prerequisites are not satisfied.","rootCause":"Required Windows roles, supported versions, updates, permissions, or dependent services are missing or incompatible.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Review the prerequisite and installation logs, compare the server to the current compatibility matrix, install the required supported components, reboot when requested, and rerun the check.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCC Installation - Prerequisite Check Failed.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Installation-Preparation.pdf; MiContactCenter_InstallationandAdministrationGuide_SIP.pdf.\nProduct scope: MiContact Center Enterprise / Business.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"Installation-Preparation.pdf; MiContactCenter_InstallationandAdministrationGuide_SIP.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Installation","Windows Server","Prerequisites"],"articleCategories":["Mitel","VoIP","Telephony","Installation","Windows Server","Prerequisites"],"aliases":["Prerequisite check failed","MiCC Installation - Prerequisite Check Failed"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60101,"title":"MiCC Installation - Required IIS or .NET Features Missing","category":"Mitel","product":"MiContact Center Enterprise / Business","tags":["Mitel","Unified Communications","Telephony","IIS",".NET","Windows Features"],"keywords":["MiCC Installation - Required IIS or .NET Features Missing","MiContact Center Enterprise / Business","MiCC setup or its web applications fail because required IIS role services or .NET features are absent.","Mitel","PBX","VoIP","SIP","IIS",".NET","Windows Features"],"errorCode":"","eventId":"","severity":"High","summary":"MiCC setup or its web applications fail because required IIS role services or .NET features are absent.","rootCause":"The Windows Server role configuration does not include the IIS management compatibility, ASP.NET, authentication, or .NET components required by the installed MiCC release.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Use the release-specific installation guide to add only the required Windows roles and features, reboot, rerun setup, and validate the MiCC web applications and services.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCC Installation - Required IIS or .NET Features Missing.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Installation-Preparation.pdf.\nProduct scope: MiContact Center Enterprise / Business.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"Installation-Preparation.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","IIS",".NET","Windows Features"],"articleCategories":["Mitel","VoIP","Telephony","IIS",".NET","Windows Features"],"aliases":["MiCC Installation - Required IIS or .NET Features Missing"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60102,"title":"MiCC Installation - Domain Membership or Time Synchronization Failure","category":"Mitel","product":"MiContact Center Enterprise / Business","tags":["Mitel","Unified Communications","Telephony","Active Directory","DNS","NTP","Domain Join"],"keywords":["MiCC Installation - Domain Membership or Time Synchronization Failure","MiContact Center Enterprise / Business","Installation, authentication, certificates, or service communication can fail when the production server is outside the intended Windows domain or its clock is incorrect.","Mitel","PBX","VoIP","SIP","Active Directory","DNS","NTP","Domain Join","w32tm /query /status","whoami /fqdn"],"errorCode":"","eventId":"","severity":"High","summary":"Installation, authentication, certificates, or service communication can fail when the production server is outside the intended Windows domain or its clock is incorrect.","rootCause":"Domain join, DNS, domain-controller reachability, NTP, or time-zone configuration is incomplete.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Verify supported domain membership, DNS and domain-controller reachability, synchronize time from the approved source, then retest authentication and service communication before continuing setup.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCC Installation - Domain Membership or Time Synchronization Failure.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Installation-Preparation.pdf.\nProduct scope: MiContact Center Enterprise / Business.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[{"shell":"CMD","command":"w32tm /query /status","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"CMD","command":"whoami /fqdn","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Installation-Preparation.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Active Directory","DNS","NTP","Domain Join"],"articleCategories":["Mitel","VoIP","Telephony","Active Directory","DNS","NTP","Domain Join"],"aliases":["MiCC Installation - Domain Membership or Time Synchronization Failure"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60103,"title":"MiCC SQL - Unsupported Case-Sensitive Collation","category":"Mitel","product":"MiContact Center Enterprise","tags":["Mitel","Unified Communications","Telephony","SQL Server","Collation","Database"],"keywords":["MiCC SQL - Unsupported Case-Sensitive Collation","MiContact Center Enterprise","MiCC Enterprise database installation or operation is unsupported on a case-sensitive SQL Server collation.","Case-sensitive SQL collation","Mitel","PBX","VoIP","SIP","SQL Server","Collation","Database","SELECT SERVERPROPERTY('Collation') AS ServerCollation;"],"errorCode":"Case-sensitive SQL collation","eventId":"","severity":"Critical","summary":"MiCC Enterprise database installation or operation is unsupported on a case-sensitive SQL Server collation.","rootCause":"The SQL instance or target database uses case-sensitive rather than case-insensitive collation.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Record the instance and database collations, confirm the supported case-insensitive collation with the current matrix, and rebuild or migrate through an approved database change plan; do not change production collation in place without vendor and DBA review.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCC SQL - Unsupported Case-Sensitive Collation.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Installation-Preparation.pdf.\nProduct scope: MiContact Center Enterprise.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[{"shell":"SQL","command":"SELECT SERVERPROPERTY('Collation') AS ServerCollation;","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Installation-Preparation.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","SQL Server","Collation","Database"],"articleCategories":["Mitel","VoIP","Telephony","SQL Server","Collation","Database"],"aliases":["Case-sensitive SQL collation","MiCC SQL - Unsupported Case-Sensitive Collation"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60104,"title":"MiCC SQL - TCP Port or Named Instance Not Detected","category":"Mitel","product":"MiContact Center Enterprise","tags":["Mitel","Unified Communications","Telephony","SQL Server","TCP/IP","Named Instance"],"keywords":["MiCC SQL - TCP Port or Named Instance Not Detected","MiContact Center Enterprise","MiCC setup cannot locate or connect to the SQL Server instance.","Mitel","PBX","VoIP","SIP","SQL Server","TCP/IP","Named Instance","Test-NetConnection <sql-server> -Port <sql-port>"],"errorCode":"","eventId":"","severity":"High","summary":"MiCC setup cannot locate or connect to the SQL Server instance.","rootCause":"SQL TCP/IP is disabled, a dynamic named-instance port cannot be discovered, the configured port differs from setup, or a firewall blocks it.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Enable SQL TCP/IP as supported, assign and document a static port for the named instance when required, enter the same port in MiCC setup, scope the firewall rule, and validate the connection.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCC SQL - TCP Port or Named Instance Not Detected.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Installation-Preparation.pdf.\nProduct scope: MiContact Center Enterprise.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[{"shell":"PowerShell","command":"Test-NetConnection <sql-server> -Port <sql-port>","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Installation-Preparation.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","SQL Server","TCP/IP","Named Instance"],"articleCategories":["Mitel","VoIP","Telephony","SQL Server","TCP/IP","Named Instance"],"aliases":["MiCC SQL - TCP Port or Named Instance Not Detected"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60105,"title":"MiCC SSL - Valid Certificate Not Bound to Port 443","category":"Mitel","product":"MiContact Center Business","tags":["Mitel","Unified Communications","Telephony","TLS","Certificate","IIS","HTTPS"],"keywords":["MiCC SSL - Valid Certificate Not Bound to Port 443","MiContact Center Business","An SSL-enabled MiCC Enterprise Server fails to connect because HTTPS has no valid certificate binding.","Security Certificate Error","Mitel","PBX","VoIP","SIP","TLS","Certificate","IIS","HTTPS","Get-ChildItem Cert:\\LocalMachine\\My | Select-Object Subject,Thumbprint,NotAfter"],"errorCode":"Security Certificate Error","eventId":"","severity":"High","summary":"An SSL-enabled MiCC Enterprise Server fails to connect because HTTPS has no valid certificate binding.","rootCause":"The certificate is missing, expired, untrusted, lacks the required private key or name, or is not bound to TCP 443 in IIS.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Confirm the FQDN matches the certificate, validate trust and private-key access, bind the approved certificate to HTTPS port 443 in IIS, restart the affected service or IIS during an approved window, and retest.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCC SSL - Valid Certificate Not Bound to Port 443.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiContactCenter_InstallationandAdministrationGuide_SIP.pdf; MiVoice Business Console Security Certificate Error.\nProduct scope: MiContact Center Business.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[{"shell":"PowerShell","command":"Get-ChildItem Cert:\\LocalMachine\\My | Select-Object Subject,Thumbprint,NotAfter","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"MiContactCenter_InstallationandAdministrationGuide_SIP.pdf; MiVoice Business Console Security Certificate Error","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","TLS","Certificate","IIS","HTTPS"],"articleCategories":["Mitel","VoIP","Telephony","TLS","Certificate","IIS","HTTPS"],"aliases":["Security Certificate Error","MiCC SSL - Valid Certificate Not Bound to Port 443"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60106,"title":"CFG0005 - MiCC License Server Failure","category":"Mitel","product":"MiContact Center","tags":["Mitel","Unified Communications","Telephony","Licensing","prairieFyre","Proxy","Firewall"],"keywords":["CFG0005 - MiCC License Server Failure","MiContact Center","The prairieFyre licensing service cannot communicate with Contact Center Management and licensing fails.","CFG0005","Mitel","PBX","VoIP","SIP","Licensing","prairieFyre","Proxy","Firewall"],"errorCode":"CFG0005","eventId":"","severity":"High","summary":"The prairieFyre licensing service cannot communicate with Contact Center Management and licensing fails.","rootCause":"Outbound connectivity, proxy, firewall, Internet access, registration, or licensing-service availability is preventing communication.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Confirm the license service and CCM are running, test approved outbound connectivity, review proxy and scoped firewall rules, then retry registration or use the documented offline licensing process.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified CFG0005 - MiCC License Server Failure.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Mitel CFG0005 License Server Failure.\nProduct scope: MiContact Center.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"Mitel CFG0005 License Server Failure","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Licensing","prairieFyre","Proxy","Firewall"],"articleCategories":["Mitel","VoIP","Telephony","Licensing","prairieFyre","Proxy","Firewall"],"aliases":["CFG0005","CFG0005 - MiCC License Server Failure"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60107,"title":"SMA0001 - Unable to Connect to Server Monitoring Agent","category":"Mitel","product":"MiContact Center","tags":["Mitel","Unified Communications","Telephony","Server Monitoring Agent","Windows Service","Monitoring"],"keywords":["SMA0001 - Unable to Connect to Server Monitoring Agent","MiContact Center","MiCC cannot connect to the prairieFyre Server Monitoring Agent.","SMA0001","Mitel","PBX","VoIP","SIP","Server Monitoring Agent","Windows Service","Monitoring","services.msc"],"errorCode":"SMA0001","eventId":"","severity":"High","summary":"MiCC cannot connect to the prairieFyre Server Monitoring Agent.","rootCause":"The monitoring-agent Windows service is stopped, starting, unhealthy, or unreachable.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Open Services, start or restart the prairieFyre Server Monitoring Agent during an approved window, review ServerMonitoringAgent.txt, and confirm monitoring resumes.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified SMA0001 - Unable to Connect to Server Monitoring Agent.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Mitel SMA0001.\nProduct scope: MiContact Center.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[{"shell":"CMD","command":"services.msc","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Mitel SMA0001","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Server Monitoring Agent","Windows Service","Monitoring"],"articleCategories":["Mitel","VoIP","Telephony","Server Monitoring Agent","Windows Service","Monitoring"],"aliases":["SMA0001","SMA0001 - Unable to Connect to Server Monitoring Agent"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60108,"title":"DSS0005 - MiCC Phone Synchronization Failed","category":"Mitel","product":"MiContact Center","tags":["Mitel","Unified Communications","Telephony","Phone Sync","Active Directory","Data Synchronization"],"keywords":["DSS0005 - MiCC Phone Synchronization Failed","MiContact Center","Phone synchronization fails while MiCC reads directory or PBX data.","DSS0005","Mitel","PBX","VoIP","SIP","Phone Sync","Active Directory","Data Synchronization"],"errorCode":"DSS0005","eventId":"","severity":"High","summary":"Phone synchronization fails while MiCC reads directory or PBX data.","rootCause":"The Enterprise Server cannot reach Active Directory, domain membership is unhealthy, or the Data Synchronization Service encountered an error.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Verify the server is a healthy domain member and can reach a domain controller, then review prairieFyre.Services.DataSynchronizationService.TXT and retry synchronization after correcting the evidenced fault.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified DSS0005 - MiCC Phone Synchronization Failed.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Mitel DSS0005.\nProduct scope: MiContact Center.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"Mitel DSS0005","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Phone Sync","Active Directory","Data Synchronization"],"articleCategories":["Mitel","VoIP","Telephony","Phone Sync","Active Directory","Data Synchronization"],"aliases":["DSS0005","DSS0005 - MiCC Phone Synchronization Failed"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60109,"title":"CFG0008 - MiCC Client Communication Ports Blocked","category":"Mitel","product":"MiContact Center Client","tags":["Mitel","Unified Communications","Telephony","Firewall","Ports 7000-7003","ContactCenterClient"],"keywords":["CFG0008 - MiCC Client Communication Ports Blocked","MiContact Center Client","The client cannot communicate with MiCC because required client ports are blocked.","CFG0008","Mitel","PBX","VoIP","SIP","Firewall","Ports 7000-7003","ContactCenterClient","Test-NetConnection <micc-server> -Port 7001"],"errorCode":"CFG0008","eventId":"","severity":"High","summary":"The client cannot communicate with MiCC because required client ports are blocked.","rootCause":"Host or network firewall policy blocks TCP 7000 through 7003 or the ContactCenterClient application.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Confirm the release-specific port requirement, create approved least-scope inbound and outbound rules for the required ports or application, and retest; do not disable the firewall broadly.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified CFG0008 - MiCC Client Communication Ports Blocked.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Mitel CFG0008.\nProduct scope: MiContact Center Client.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[{"shell":"PowerShell","command":"Test-NetConnection <micc-server> -Port 7001","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Mitel CFG0008","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Firewall","Ports 7000-7003","ContactCenterClient"],"articleCategories":["Mitel","VoIP","Telephony","Firewall","Ports 7000-7003","ContactCenterClient"],"aliases":["CFG0008","CFG0008 - MiCC Client Communication Ports Blocked"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60110,"title":"MiCC IVR - Workflow Validation Errors","category":"Mitel","product":"MiContact Center Business IVR","tags":["Mitel","Unified Communications","Telephony","IVR","Workflow","Validation"],"keywords":["MiCC IVR - Workflow Validation Errors","MiContact Center Business IVR","An IVR workflow displays red or yellow validation indicators and cannot be safely activated.","Mitel","PBX","VoIP","SIP","IVR","Workflow","Validation"],"errorCode":"","eventId":"","severity":"High","summary":"An IVR workflow displays red or yellow validation indicators and cannot be safely activated.","rootCause":"Required activity properties, connections, variables, paths, or referenced resources are missing or invalid.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Open the Validation pane, correct every error and review each warning, validate again, then test the workflow in a non-production path before activation.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCC IVR - Workflow Validation Errors.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiContactCenter_InstallationandAdministrationGuide_SIP.pdf.\nProduct scope: MiContact Center Business IVR.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiContactCenter_InstallationandAdministrationGuide_SIP.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","IVR","Workflow","Validation"],"articleCategories":["Mitel","VoIP","Telephony","IVR","Workflow","Validation"],"aliases":["MiCC IVR - Workflow Validation Errors"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60111,"title":"MiCC IVR - Execute Activity or PowerShell Script Failed","category":"Mitel","product":"MiContact Center Business IVR","tags":["Mitel","Unified Communications","Telephony","IVR","PowerShell","Execute Activity","XML"],"keywords":["MiCC IVR - Execute Activity or PowerShell Script Failed","MiContact Center Business IVR","An Execute activity routes to Failure or does not return the expected result.","Mitel","PBX","VoIP","SIP","IVR","PowerShell","Execute Activity","XML","Get-ExecutionPolicy -List"],"errorCode":"","eventId":"","severity":"High","summary":"An Execute activity routes to Failure or does not return the expected result.","rootCause":"The executable or script path is unavailable, permissions or execution policy block it, parameters are invalid, or returned XML contains unescaped reserved characters.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Confirm the approved UNC path and service-account access, validate parameters and script signing/policy, sanitize XML output, map the returned result, and test outside production before enabling the workflow.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCC IVR - Execute Activity or PowerShell Script Failed.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiContactCenter_InstallationandAdministrationGuide_SIP.pdf.\nProduct scope: MiContact Center Business IVR.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[{"shell":"PowerShell","command":"Get-ExecutionPolicy -List","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"MiContactCenter_InstallationandAdministrationGuide_SIP.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","IVR","PowerShell","Execute Activity","XML"],"articleCategories":["Mitel","VoIP","Telephony","IVR","PowerShell","Execute Activity","XML"],"aliases":["MiCC IVR - Execute Activity or PowerShell Script Failed"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60112,"title":"MiCollab PBX Sync - AuthData Sign Failed","category":"Mitel","product":"MiCollab Client Service 9.8","tags":["Mitel","Unified Communications","Telephony","PBX Sync","Certificate","Version Compatibility"],"keywords":["MiCollab PBX Sync - AuthData Sign Failed","MiCollab Client Service 9.8","PBX synchronization reports that AuthData signing failed.","AuthData Sign failed","Mitel","PBX","VoIP","SIP","PBX Sync","Certificate","Version Compatibility"],"errorCode":"AuthData Sign failed","eventId":"","severity":"High","summary":"PBX synchronization reports that AuthData signing failed.","rootCause":"The authentication certificate is invalid or the MiCollab and MiVoice Business versions are incompatible.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Validate the authentication certificate and supported product-version pairing, correct the certificate or upgrade path, then retry synchronization and review the synchronization logs.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCollab PBX Sync - AuthData Sign Failed.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiCollab 9.8 uca_pbx_sync_errors.\nProduct scope: MiCollab Client Service 9.8.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiCollab 9.8 uca_pbx_sync_errors","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","PBX Sync","Certificate","Version Compatibility"],"articleCategories":["Mitel","VoIP","Telephony","PBX Sync","Certificate","Version Compatibility"],"aliases":["AuthData Sign failed","MiCollab PBX Sync - AuthData Sign Failed"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60113,"title":"MiCollab PBX Sync - SOAP Login Failed or Rejected","category":"Mitel","product":"MiCollab Client Service 9.8","tags":["Mitel","Unified Communications","Telephony","PBX Sync","SOAP","Authentication"],"keywords":["MiCollab PBX Sync - SOAP Login Failed or Rejected","MiCollab Client Service 9.8","PBX synchronization cannot authenticate its SOAP session.","Soap login failed / rejected","Mitel","PBX","VoIP","SIP","PBX Sync","SOAP","Authentication"],"errorCode":"Soap login failed / rejected","eventId":"","severity":"High","summary":"PBX synchronization cannot authenticate its SOAP session.","rootCause":"The PBX node address, username, password, permissions, or SOAP service state is incorrect.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Verify the intended PBX node and dedicated account, reset credentials through an approved process if required, confirm the account permissions and SOAP service, and retry synchronization.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCollab PBX Sync - SOAP Login Failed or Rejected.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiCollab 9.8 uca_pbx_sync_errors.\nProduct scope: MiCollab Client Service 9.8.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiCollab 9.8 uca_pbx_sync_errors","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","PBX Sync","SOAP","Authentication"],"articleCategories":["Mitel","VoIP","Telephony","PBX Sync","SOAP","Authentication"],"aliases":["Soap login failed / rejected","MiCollab PBX Sync - SOAP Login Failed or Rejected"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60114,"title":"MiCollab PBX Sync - DSM Internal Error","category":"Mitel","product":"MiCollab Client Service 9.8","tags":["Mitel","Unified Communications","Telephony","PBX Sync","DSM","Logs"],"keywords":["MiCollab PBX Sync - DSM Internal Error","MiCollab Client Service 9.8","PBX synchronization reports an internal DSM error.","DSM internal error","Mitel","PBX","VoIP","SIP","PBX Sync","DSM","Logs"],"errorCode":"DSM internal error","eventId":"","severity":"High","summary":"PBX synchronization reports an internal DSM error.","rootCause":"The synchronization component encountered an internal application or data-processing failure.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Preserve dsm.log and matching timestamps, confirm version compatibility and service health, retry once after evidence collection, and escalate with a support package if it recurs.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCollab PBX Sync - DSM Internal Error.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiCollab 9.8 uca_pbx_sync_errors.\nProduct scope: MiCollab Client Service 9.8.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiCollab 9.8 uca_pbx_sync_errors","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","PBX Sync","DSM","Logs"],"articleCategories":["Mitel","VoIP","Telephony","PBX Sync","DSM","Logs"],"aliases":["DSM internal error","MiCollab PBX Sync - DSM Internal Error"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60115,"title":"MiCollab PBX Sync - No Subscriber License Instances","category":"Mitel","product":"MiCollab Client Service 9.8","tags":["Mitel","Unified Communications","Telephony","PBX Sync","Licensing","Subscriber"],"keywords":["MiCollab PBX Sync - No Subscriber License Instances","MiCollab Client Service 9.8","MiCollab cannot create a subscriber because no license instance is available.","No license instances for subscriber creation","Mitel","PBX","VoIP","SIP","PBX Sync","Licensing","Subscriber"],"errorCode":"No license instances for subscriber creation","eventId":"","severity":"High","summary":"MiCollab cannot create a subscriber because no license instance is available.","rootCause":"The required subscriber license is exhausted, absent, unapplied, or the feature profile is not assigned correctly.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Check current license entitlement and consumption, apply a valid license or supported feature profile, assign it to the subscriber, and synchronize again.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCollab PBX Sync - No Subscriber License Instances.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiCollab 9.8 uca_pbx_sync_errors.\nProduct scope: MiCollab Client Service 9.8.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiCollab 9.8 uca_pbx_sync_errors","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","PBX Sync","Licensing","Subscriber"],"articleCategories":["Mitel","VoIP","Telephony","PBX Sync","Licensing","Subscriber"],"aliases":["No license instances for subscriber creation","MiCollab PBX Sync - No Subscriber License Instances"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60116,"title":"MX-ONE Service Node Manager - Unable to Start After Installation","category":"Mitel","product":"MX-ONE Service Node Manager","tags":["Mitel","Unified Communications","Telephony","MX-ONE","SNM","JBoss","Installation Logs"],"keywords":["MX-ONE Service Node Manager - Unable to Start After Installation","MX-ONE Service Node Manager","Service Node Manager does not start after installation.","Unable to start after installation","Mitel","PBX","VoIP","SIP","MX-ONE","SNM","JBoss","Installation Logs","systemctl status postgresql.service","systemctl status jboss.service"],"errorCode":"Unable to start after installation","eventId":"","severity":"Critical","summary":"Service Node Manager does not start after installation.","rootCause":"The package, database, web application, or JBoss installation failed or a dependent service is unhealthy.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Review mts_install.log, the versioned RPM log, application_log.log, and JBoss server.log; correct the first installation error and validate each dependent service before retrying.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MX-ONE Service Node Manager - Unable to Start After Installation.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: 7_1545-ANF90115.pdf.\nProduct scope: MX-ONE Service Node Manager.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[{"shell":"Linux","command":"systemctl status postgresql.service","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"Linux","command":"systemctl status jboss.service","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"7_1545-ANF90115.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["linux"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","MX-ONE","SNM","JBoss","Installation Logs"],"articleCategories":["Mitel","VoIP","Telephony","MX-ONE","SNM","JBoss","Installation Logs"],"aliases":["Unable to start after installation","MX-ONE Service Node Manager - Unable to Start After Installation"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60117,"title":"MX-ONE Service Node Manager - Not Authorized to Access","category":"Mitel","product":"MX-ONE Service Node Manager","tags":["Mitel","Unified Communications","Telephony","MX-ONE","PostgreSQL","Authorization"],"keywords":["MX-ONE Service Node Manager - Not Authorized to Access","MX-ONE Service Node Manager","The web application displays that the user is not authorized to access MX-ONE Manager.","You are not authorized to access MX-ONE Manager","Mitel","PBX","VoIP","SIP","MX-ONE","PostgreSQL","Authorization","systemctl status postgresql.service"],"errorCode":"You are not authorized to access MX-ONE Manager","eventId":"","severity":"High","summary":"The web application displays that the user is not authorized to access MX-ONE Manager.","rootCause":"The PostgreSQL database is unavailable or required menu relations are missing, so authorization data cannot be read.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Check PostgreSQL service state and JBoss server.log for SQL errors such as a missing mecs_last_menu relation; restore database health and escalate before schema changes.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MX-ONE Service Node Manager - Not Authorized to Access.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: 7_1545-ANF90115.pdf.\nProduct scope: MX-ONE Service Node Manager.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[{"shell":"Linux","command":"systemctl status postgresql.service","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"7_1545-ANF90115.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["linux"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","MX-ONE","PostgreSQL","Authorization"],"articleCategories":["Mitel","VoIP","Telephony","MX-ONE","PostgreSQL","Authorization"],"aliases":["You are not authorized to access MX-ONE Manager","MX-ONE Service Node Manager - Not Authorized to Access"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60118,"title":"MX-ONE Service Node Manager - Login Locked or Authentication Misconfigured","category":"Mitel","product":"MX-ONE Service Node Manager","tags":["Mitel","Unified Communications","Telephony","MX-ONE","Account Lockout","AD Authentication"],"keywords":["MX-ONE Service Node Manager - Login Locked or Authentication Misconfigured","MX-ONE Service Node Manager","A valid administrator cannot log in to Service Node Manager.","Unable to log in","Mitel","PBX","VoIP","SIP","MX-ONE","Account Lockout","AD Authentication","sudo webserver_config"],"errorCode":"Unable to log in","eventId":"","severity":"High","summary":"A valid administrator cannot log in to Service Node Manager.","rootCause":"The account is locked after repeated failures, credentials are wrong, or PM, Linux-group, or AD authentication is configured incorrectly.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Check Caps Lock and account identity, have an authorized administrator unlock the account in Provisioning Manager, then verify the configured authentication method and required PM or snlev group privileges.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MX-ONE Service Node Manager - Login Locked or Authentication Misconfigured.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: 7_1545-ANF90115.pdf.\nProduct scope: MX-ONE Service Node Manager.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[{"shell":"Linux","command":"sudo webserver_config","risk":"Standard","safetyLevel":"Config Change"}],"sourceDocument":"7_1545-ANF90115.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["linux"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","MX-ONE","Account Lockout","AD Authentication"],"articleCategories":["Mitel","VoIP","Telephony","MX-ONE","Account Lockout","AD Authentication"],"aliases":["Unable to log in","MX-ONE Service Node Manager - Login Locked or Authentication Misconfigured"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60119,"title":"MX-ONE IP Phone Software - Required Tomcat Folder Missing","category":"Mitel","product":"MX-ONE IP Phone Software Server","tags":["Mitel","Unified Communications","Telephony","MX-ONE","Tomcat","Phone Firmware"],"keywords":["MX-ONE IP Phone Software - Required Tomcat Folder Missing","MX-ONE IP Phone Software Server","A phone-software task cannot find its boot, language, license, or configuration files.","Configuration file missing","Mitel","PBX","VoIP","SIP","MX-ONE","Tomcat","Phone Firmware"],"errorCode":"Configuration file missing","eventId":"","severity":"High","summary":"A phone-software task cannot find its boot, language, license, or configuration files.","rootCause":"The model folder such as dbc42x02, dbc43x01, or dbc44x01 is missing from the configured Tomcat root, or the configured address and port point elsewhere.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Confirm the phone model and release, verify the required folder and files exist under the configured Tomcat root with read access, then verify the server address and port in both the phone server and MX-ONE configuration.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MX-ONE IP Phone Software - Required Tomcat Folder Missing.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: 7_1545-ANF90115.pdf; 32_1531-ANF90114.pdf.\nProduct scope: MX-ONE IP Phone Software Server.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"7_1545-ANF90115.pdf; 32_1531-ANF90114.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","MX-ONE","Tomcat","Phone Firmware"],"articleCategories":["Mitel","VoIP","Telephony","MX-ONE","Tomcat","Phone Firmware"],"aliases":["Configuration file missing","MX-ONE IP Phone Software - Required Tomcat Folder Missing"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60120,"title":"MX-ONE IP Phone Software - Java Runtime Missing","category":"Mitel","product":"MX-ONE IP Phone Software Server","tags":["Mitel","Unified Communications","Telephony","MX-ONE","Java","Tomcat"],"keywords":["MX-ONE IP Phone Software - Java Runtime Missing","MX-ONE IP Phone Software Server","The IP Phone Software Server installer or Tomcat application cannot start.","Java runtime missing","Mitel","PBX","VoIP","SIP","MX-ONE","Java","Tomcat","java -version"],"errorCode":"Java runtime missing","eventId":"","severity":"High","summary":"The IP Phone Software Server installer or Tomcat application cannot start.","rootCause":"A release-supported Java runtime is absent, the architecture is wrong, or Java paths reference a removed runtime.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Check the product release matrix for the supported Java distribution and architecture, install that supported runtime, validate Java and service paths, and restart the application service.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MX-ONE IP Phone Software - Java Runtime Missing.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: 32_1531-ANF90114.pdf.\nProduct scope: MX-ONE IP Phone Software Server.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[{"shell":"CMD","command":"java -version","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"32_1531-ANF90114.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","MX-ONE","Java","Tomcat"],"articleCategories":["Mitel","VoIP","Telephony","MX-ONE","Java","Tomcat"],"aliases":["Java runtime missing","MX-ONE IP Phone Software - Java Runtime Missing"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60121,"title":"MX-ONE IP Phone Software - Installation Path Too Long","category":"Mitel","product":"MX-ONE IP Phone Software Server","tags":["Mitel","Unified Communications","Telephony","MX-ONE","NSIS","Path Length"],"keywords":["MX-ONE IP Phone Software - Installation Path Too Long","MX-ONE IP Phone Software Server","The NSIS-based installer fails or behaves unexpectedly when installed under a long path.","NSIS path limit","Mitel","PBX","VoIP","SIP","MX-ONE","NSIS","Path Length"],"errorCode":"NSIS path limit","eventId":"","severity":"Medium","summary":"The NSIS-based installer fails or behaves unexpectedly when installed under a long path.","rootCause":"The selected path approaches the installer's documented 1024-character path limit after nested files are expanded.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Use an approved short local installation path such as a dedicated folder under C:\\, rerun setup, and verify service paths and content; do not move a completed installation manually.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MX-ONE IP Phone Software - Installation Path Too Long.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: 32_1531-ANF90114.pdf.\nProduct scope: MX-ONE IP Phone Software Server.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"32_1531-ANF90114.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","MX-ONE","NSIS","Path Length"],"articleCategories":["Mitel","VoIP","Telephony","MX-ONE","NSIS","Path Length"],"aliases":["NSIS path limit","MX-ONE IP Phone Software - Installation Path Too Long"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60122,"title":"MX-ONE IP Phone Software - Tomcat and IIS Port Conflict","category":"Mitel","product":"MX-ONE IP Phone Software Server","tags":["Mitel","Unified Communications","Telephony","MX-ONE","Tomcat","IIS","Port 8080"],"keywords":["MX-ONE IP Phone Software - Tomcat and IIS Port Conflict","MX-ONE IP Phone Software Server","The phone-software web service does not start or phones reach the wrong web server.","Port conflict","Mitel","PBX","VoIP","SIP","MX-ONE","Tomcat","IIS","Port 8080","netstat -ano | findstr LISTENING"],"errorCode":"Port conflict","eventId":"","severity":"High","summary":"The phone-software web service does not start or phones reach the wrong web server.","rootCause":"Tomcat and IIS are configured to listen on the same port, or the Tomcat server.xml port does not match MX-ONE configuration.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Identify current listeners, assign supported non-conflicting ports, make the Tomcat and MX-ONE settings match, restart only the affected service, and test a phone-file request.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MX-ONE IP Phone Software - Tomcat and IIS Port Conflict.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: 32_1531-ANF90114.pdf.\nProduct scope: MX-ONE IP Phone Software Server.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[{"shell":"CMD","command":"netstat -ano | findstr LISTENING","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"32_1531-ANF90114.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","MX-ONE","Tomcat","IIS","Port 8080"],"articleCategories":["Mitel","VoIP","Telephony","MX-ONE","Tomcat","IIS","Port 8080"],"aliases":["Port conflict","MX-ONE IP Phone Software - Tomcat and IIS Port Conflict"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60123,"title":"MX-ONE IP Phone Software - Firmware File Not Downloaded","category":"Mitel","product":"MX-ONE IP Phone Software Server","tags":["Mitel","Unified Communications","Telephony","MX-ONE","IIS","MIME","Firmware"],"keywords":["MX-ONE IP Phone Software - Firmware File Not Downloaded","MX-ONE IP Phone Software Server","Phones cannot download firmware or configuration files from IIS or Tomcat.","File not found","Mitel","PBX","VoIP","SIP","MX-ONE","IIS","MIME","Firmware"],"errorCode":"File not found","eventId":"","severity":"High","summary":"Phones cannot download firmware or configuration files from IIS or Tomcat.","rootCause":"Virtual directories, MIME mappings, model folders, subnet mapping, file permissions, or the configured server URL are incomplete.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Confirm the requested URL and server log, verify model folders and Users read access, configure only the documented virtual directories and MIME types, and test the exact file with an authorized client.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MX-ONE IP Phone Software - Firmware File Not Downloaded.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: 32_1531-ANF90114.pdf.\nProduct scope: MX-ONE IP Phone Software Server.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"32_1531-ANF90114.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","MX-ONE","IIS","MIME","Firmware"],"articleCategories":["Mitel","VoIP","Telephony","MX-ONE","IIS","MIME","Firmware"],"aliases":["File not found","MX-ONE IP Phone Software - Firmware File Not Downloaded"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60124,"title":"MiVoice Connect Installation - Windows Updates, Roles, or Reboot Pending","category":"Mitel","product":"MiVoice Connect / MiContact Center Business","tags":["Mitel","Unified Communications","Telephony","Installation","Windows Server","Pending Reboot"],"keywords":["MiVoice Connect Installation - Windows Updates, Roles, or Reboot Pending","MiVoice Connect / MiContact Center Business","MiVoice Connect PBX installation fails or behaves unpredictably on a newly prepared Windows Server.","Mitel","PBX","VoIP","SIP","Installation","Windows Server","Pending Reboot"],"errorCode":"","eventId":"","severity":"High","summary":"MiVoice Connect PBX installation fails or behaves unpredictably on a newly prepared Windows Server.","rootCause":"Required Windows patches, server roles and features, or the restart after installing them was skipped.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Apply the release-supported Windows updates first, install all required roles and features, restart the server, confirm no reboot is pending, and then begin PBX software installation.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Connect Installation - Windows Updates, Roles, or Reboot Pending.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Installing and Configuring MiVoice Connect with MiContact Center Business Guide.pdf.\nProduct scope: MiVoice Connect / MiContact Center Business.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"Installing and Configuring MiVoice Connect with MiContact Center Business Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Installation","Windows Server","Pending Reboot"],"articleCategories":["Mitel","VoIP","Telephony","Installation","Windows Server","Pending Reboot"],"aliases":["MiVoice Connect Installation - Windows Updates, Roles, or Reboot Pending"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60125,"title":"MiVoice Connect to MiCC - CTI Server Port 5007 Unreachable","category":"Mitel","product":"MiVoice Connect / MiContact Center Business","tags":["Mitel","Unified Communications","Telephony","CTI","Port 5007","DVS"],"keywords":["MiVoice Connect to MiCC - CTI Server Port 5007 Unreachable","MiVoice Connect / MiContact Center Business","MiCC cannot establish CTI communication with the MiVoice Connect distributed voice server.","CTI connection failed","Mitel","PBX","VoIP","SIP","CTI","Port 5007","DVS","Test-NetConnection <DVS-IP> -Port 5007"],"errorCode":"CTI connection failed","eventId":"","severity":"Critical","summary":"MiCC cannot establish CTI communication with the MiVoice Connect distributed voice server.","rootCause":"The CTI server URL or DVS IP is wrong, TCP 5007 is blocked, or the voice service is unavailable.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Confirm the intended DVS address and tcp://<DVS-IP>:5007 setting, test the network path, review service logs, and validate call events after restoring connectivity.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Connect to MiCC - CTI Server Port 5007 Unreachable.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Installing and Configuring MiVoice Connect with MiContact Center Business Guide.pdf.\nProduct scope: MiVoice Connect / MiContact Center Business.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[{"shell":"PowerShell","command":"Test-NetConnection <DVS-IP> -Port 5007","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Installing and Configuring MiVoice Connect with MiContact Center Business Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows","network-appliances"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","CTI","Port 5007","DVS"],"articleCategories":["Mitel","VoIP","Telephony","CTI","Port 5007","DVS"],"aliases":["CTI connection failed","MiVoice Connect to MiCC - CTI Server Port 5007 Unreachable"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60126,"title":"MiVoice Connect to MiCC - Agent Calls Route to Voicemail","category":"Mitel","product":"MiVoice Connect / MiContact Center Business","tags":["Mitel","Unified Communications","Telephony","Call Routing","Voicemail","Requeue Timer"],"keywords":["MiVoice Connect to MiCC - Agent Calls Route to Voicemail","MiVoice Connect / MiContact Center Business","Queued calls reach an agent's voicemail instead of returning to the contact-center queue.","Mitel","PBX","VoIP","SIP","Call Routing","Voicemail","Requeue Timer"],"errorCode":"","eventId":"","severity":"High","summary":"Queued calls reach an agent's voicemail instead of returning to the contact-center queue.","rootCause":"The voicemail forwarding timer is shorter than the contact-center requeue timer, or Forward after rings and call-stack settings do not match the integration guidance.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Review the supported integration settings, set the voicemail timer longer than the requeue timer, verify Forward after rings and call-stack depth, then test answered, unanswered, and requeued calls.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Connect to MiCC - Agent Calls Route to Voicemail.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Installing and Configuring MiVoice Connect with MiContact Center Business Guide.pdf.\nProduct scope: MiVoice Connect / MiContact Center Business.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"Installing and Configuring MiVoice Connect with MiContact Center Business Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Call Routing","Voicemail","Requeue Timer"],"articleCategories":["Mitel","VoIP","Telephony","Call Routing","Voicemail","Requeue Timer"],"aliases":["MiVoice Connect to MiCC - Agent Calls Route to Voicemail"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60127,"title":"MiVoice Connect to MiCC - Line URI Does Not Match Extension","category":"Mitel","product":"MiVoice Connect / MiContact Center Business","tags":["Mitel","Unified Communications","Telephony","Line URI","SIP","Extension"],"keywords":["MiVoice Connect to MiCC - Line URI Does Not Match Extension","MiVoice Connect / MiContact Center Business","An agent, route point, or SIP endpoint does not associate correctly with its extension.","Line URI mismatch","Mitel","PBX","VoIP","SIP","Line URI","SIP","Extension"],"errorCode":"Line URI mismatch","eventId":"","severity":"High","summary":"An agent, route point, or SIP endpoint does not associate correctly with its extension.","rootCause":"The configured Line URI differs from the assigned extension or uses the wrong format.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Compare the Line URI and extension exactly, correct the authoritative record, synchronize or restart only as documented, and validate inbound, outbound, transfer, and queue behavior.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Connect to MiCC - Line URI Does Not Match Extension.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Installing and Configuring MiVoice Connect with MiContact Center Business Guide.pdf.\nProduct scope: MiVoice Connect / MiContact Center Business.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"Installing and Configuring MiVoice Connect with MiContact Center Business Guide.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Line URI","SIP","Extension"],"articleCategories":["Mitel","VoIP","Telephony","Line URI","SIP","Extension"],"aliases":["Line URI mismatch","MiVoice Connect to MiCC - Line URI Does Not Match Extension"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60128,"title":"MiVoice Office 250 6900 Phone - Configuration Server Lost After Reboot","category":"Mitel","product":"MiVoice Office 250 / 6900 IP Phones","tags":["Mitel","Unified Communications","Telephony","6900 Phone","DHCP Option 66","MCS","Port 8202"],"keywords":["MiVoice Office 250 6900 Phone - Configuration Server Lost After Reboot","MiVoice Office 250 / 6900 IP Phones","A 6900 handset loses or does not retain its configuration-server details after reboot.","Mitel","PBX","VoIP","SIP","6900 Phone","DHCP Option 66","MCS","Port 8202"],"errorCode":"","eventId":"","severity":"High","summary":"A 6900 handset loses or does not retain its configuration-server details after reboot.","rootCause":"DHCP option 66 or mDNS does not supply the MCS address, Client Locations contains the wrong DNS path, or the locally stored HTTPS server value was not committed.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Verify Client Locations and DHCP option 66 or mDNS, default the phone or set the approved HTTPS server and port 8202, force the setting to store if required, then reboot and confirm it persists.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Office 250 6900 Phone - Configuration Server Lost After Reboot.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiVoice Office 250 - 6900 Handset Engineering Guidelines.pdf.\nProduct scope: MiVoice Office 250 / 6900 IP Phones.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiVoice Office 250 - 6900 Handset Engineering Guidelines.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","6900 Phone","DHCP Option 66","MCS","Port 8202"],"articleCategories":["Mitel","VoIP","Telephony","6900 Phone","DHCP Option 66","MCS","Port 8202"],"aliases":["MiVoice Office 250 6900 Phone - Configuration Server Lost After Reboot"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60129,"title":"MiVoice Office 250 6900 Phone - No Service / 401 Authorization Failure","category":"Mitel","product":"MiVoice Office 250 / 6900 IP Phones","tags":["Mitel","Unified Communications","Telephony","6900 Phone","No Service","SIP 401","MCS"],"keywords":["MiVoice Office 250 6900 Phone - No Service / 401 Authorization Failure","MiVoice Office 250 / 6900 IP Phones","A 6900 handset displays No Service and its lifecycle log shows SIP registration authorization failure.","401 RegisteredState=REFUSED","Mitel","PBX","VoIP","SIP","6900 Phone","No Service","SIP 401","MCS"],"errorCode":"401 RegisteredState=REFUSED","eventId":"","severity":"High","summary":"A 6900 handset displays No Service and its lifecycle log shows SIP registration authorization failure.","rootCause":"The SIP device username or password differs between the PBX and Mitel Communication Service, or registration/listening settings are wrong.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Compare the device username and password in the PBX and MCS without exposing the secret, confirm the SIP UDP listening setting required by the release, push the corrected configuration, and verify registration and calling.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Office 250 6900 Phone - No Service / 401 Authorization Failure.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiVoice Office 250 - 6900 Handset Engineering Guidelines.pdf.\nProduct scope: MiVoice Office 250 / 6900 IP Phones.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiVoice Office 250 - 6900 Handset Engineering Guidelines.pdf","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","6900 Phone","No Service","SIP 401","MCS"],"articleCategories":["Mitel","VoIP","Telephony","6900 Phone","No Service","SIP 401","MCS"],"aliases":["401 RegisteredState=REFUSED","MiVoice Office 250 6900 Phone - No Service / 401 Authorization Failure"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60130,"title":"MiVoice Business Migration - Software Load Verification Failed","category":"Mitel","product":"MiVoice Business Migration Tool","tags":["Mitel","Unified Communications","Telephony","Migration","Software Load","BranchCache"],"keywords":["MiVoice Business Migration - Software Load Verification Failed","MiVoice Business Migration Tool","Migration stops because the staged software load cannot be verified.","Failed to verify the software load","Mitel","PBX","VoIP","SIP","Migration","Software Load","BranchCache"],"errorCode":"Failed to verify the software load","eventId":"","severity":"Critical","summary":"Migration stops because the staged software load cannot be verified.","rootCause":"The repository is wrong or incomplete, required files are missing, BranchCache HTTPS is blocked, or network quality interrupted transfer.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Verify the selected repository and required files, test the approved HTTPS/network path, restage the load, and retry only after validation.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Business Migration - Software Load Verification Failed.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Mitel MiVoice Business Migration Tool: Migration failure.\nProduct scope: MiVoice Business Migration Tool.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"Mitel MiVoice Business Migration Tool: Migration failure","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Migration","Software Load","BranchCache"],"articleCategories":["Mitel","VoIP","Telephony","Migration","Software Load","BranchCache"],"aliases":["Failed to verify the software load","MiVoice Business Migration - Software Load Verification Failed"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60131,"title":"MiVoice Business Migration - Insufficient vmail Disk Space","category":"Mitel","product":"MiVoice Business Migration Tool","tags":["Mitel","Unified Communications","Telephony","Migration","Disk Space","vmail"],"keywords":["MiVoice Business Migration - Insufficient vmail Disk Space","MiVoice Business Migration Tool","Migration aborts while transferring files because the target lacks working space.","FTP file to system aborted","Mitel","PBX","VoIP","SIP","Migration","Disk Space","vmail","df -h /vmail"],"errorCode":"FTP file to system aborted","eventId":"","severity":"Critical","summary":"Migration aborts while transferring files because the target lacks working space.","rootCause":"The /vmail partition has less than the documented free-space requirement for migration.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Measure /vmail usage, preserve required backups and voicemail data, free or expand storage through an approved plan until at least 3 GB is available, then retry and monitor capacity.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Business Migration - Insufficient vmail Disk Space.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Mitel MiVoice Business Migration Tool: Migration failure.\nProduct scope: MiVoice Business Migration Tool.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[{"shell":"Linux","command":"df -h /vmail","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Mitel MiVoice Business Migration Tool: Migration failure","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["linux"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Migration","Disk Space","vmail"],"articleCategories":["Mitel","VoIP","Telephony","Migration","Disk Space","vmail"],"aliases":["FTP file to system aborted","MiVoice Business Migration - Insufficient vmail Disk Space"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60132,"title":"MiVoice Business Migration - Boot ROM Upgrade Failed","category":"Mitel","product":"MiVoice Business Migration Tool","tags":["Mitel","Unified Communications","Telephony","Migration","Boot ROM","Recovery"],"keywords":["MiVoice Business Migration - Boot ROM Upgrade Failed","MiVoice Business Migration Tool","The controller boot-ROM upgrade fails or returns a failed result during migration.","Failed to upgrade the bootrom","Mitel","PBX","VoIP","SIP","Migration","Boot ROM","Recovery"],"errorCode":"Failed to upgrade the bootrom","eventId":"","severity":"Critical","summary":"The controller boot-ROM upgrade fails or returns a failed result during migration.","rootCause":"Power or network interruption, an unsupported image, or boot-ROM transfer or programming failure interrupted the operation.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Stabilize power and network, verify the approved load and controller support, collect migration logs, and retry through the documented tool; use serial recovery only with Mitel support and a maintenance window.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Business Migration - Boot ROM Upgrade Failed.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Mitel MiVoice Business Migration Tool: Migration failure.\nProduct scope: MiVoice Business Migration Tool.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"Mitel MiVoice Business Migration Tool: Migration failure","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Migration","Boot ROM","Recovery"],"articleCategories":["Mitel","VoIP","Telephony","Migration","Boot ROM","Recovery"],"aliases":["Failed to upgrade the bootrom","MiVoice Business Migration - Boot ROM Upgrade Failed"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60133,"title":"MiVoice Business Migration - Online Licensing or AMC Connection Failed","category":"Mitel","product":"MiVoice Business Migration Tool","tags":["Mitel","Unified Communications","Telephony","Migration","AMC","ARID","Licensing"],"keywords":["MiVoice Business Migration - Online Licensing or AMC Connection Failed","MiVoice Business Migration Tool","The migrated system cannot obtain or synchronize its license online.","Online licensing failed","Mitel","PBX","VoIP","SIP","Migration","AMC","ARID","Licensing"],"errorCode":"Online licensing failed","eventId":"","severity":"Critical","summary":"The migrated system cannot obtain or synchronize its license online.","rootCause":"AMC is unreachable, the ARID is invalid, outbound communication is blocked, or entitlement is not synchronized.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Verify the ARID and entitlement, test approved AMC connectivity, run the documented synchronization, or use the official offline licensing workflow; confirm the system is licensed before service validation.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Business Migration - Online Licensing or AMC Connection Failed.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Mitel MiVoice Business Migration Tool: Migration failure.\nProduct scope: MiVoice Business Migration Tool.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"Mitel MiVoice Business Migration Tool: Migration failure","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Migration","AMC","ARID","Licensing"],"articleCategories":["Mitel","VoIP","Telephony","Migration","AMC","ARID","Licensing"],"aliases":["Online licensing failed","MiVoice Business Migration - Online Licensing or AMC Connection Failed"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60134,"title":"MiVoice Business Migration - Voicemail Backup or Restore Failed","category":"Mitel","product":"MiVoice Business Migration Tool","tags":["Mitel","Unified Communications","Telephony","Migration","Voicemail","Backup","Data Loss Risk"],"keywords":["MiVoice Business Migration - Voicemail Backup or Restore Failed","MiVoice Business Migration Tool","Migration cannot back up or restore voicemail data safely.","Voicemail backup/restore failed","Mitel","PBX","VoIP","SIP","Migration","Voicemail","Backup","Data Loss Risk"],"errorCode":"Voicemail backup/restore failed","eventId":"","severity":"Critical","summary":"Migration cannot back up or restore voicemail data safely.","rootCause":"Voicemail data exceeds a supported threshold, storage is insufficient, the archive is incomplete, or transfer and restore failed.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Stop before accepting data-loss risk, preserve the existing system and logs, confirm supported voicemail size and free space, complete and verify a manual backup when documented, then retry with Mitel support if needed.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Business Migration - Voicemail Backup or Restore Failed.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Mitel MiVoice Business Migration Tool: Migration failure.\nProduct scope: MiVoice Business Migration Tool.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"Mitel MiVoice Business Migration Tool: Migration failure","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Migration","Voicemail","Backup","Data Loss Risk"],"articleCategories":["Mitel","VoIP","Telephony","Migration","Voicemail","Backup","Data Loss Risk"],"aliases":["Voicemail backup/restore failed","MiVoice Business Migration - Voicemail Backup or Restore Failed"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60135,"title":"MiVoice Business Migration - AX ataDriveInit Failed","category":"Mitel","product":"MiVoice Business AX Controller","tags":["Mitel","Unified Communications","Telephony","AX Controller","CompactFlash","Boot"],"keywords":["MiVoice Business Migration - AX ataDriveInit Failed","MiVoice Business AX Controller","An AX controller reports ataDrv: ataDriveInit failed during boot or migration.","ataDrv: ataDriveInit failed","Mitel","PBX","VoIP","SIP","AX Controller","CompactFlash","Boot"],"errorCode":"ataDrv: ataDriveInit failed","eventId":"","severity":"Critical","summary":"An AX controller reports ataDrv: ataDriveInit failed during boot or migration.","rootCause":"The CompactFlash media is not seated, is unreadable, or has failed.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Power down only under the documented hardware procedure, inspect and reseat supported media if authorized, preserve diagnostic evidence, and replace or reimage media only through the approved Mitel recovery plan.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Business Migration - AX ataDriveInit Failed.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Mitel MiVoice Business Migration Tool: Migration failure.\nProduct scope: MiVoice Business AX Controller.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"Mitel MiVoice Business Migration Tool: Migration failure","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","AX Controller","CompactFlash","Boot"],"articleCategories":["Mitel","VoIP","Telephony","AX Controller","CompactFlash","Boot"],"aliases":["ataDrv: ataDriveInit failed","MiVoice Business Migration - AX ataDriveInit Failed"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60136,"title":"MiVoice Business Migration - Can't Load Boot File","category":"Mitel","product":"MiVoice Business AX Controller","tags":["Mitel","Unified Communications","Telephony","AX Controller","Boot Image","RTC8260"],"keywords":["MiVoice Business Migration - Can't Load Boot File","MiVoice Business AX Controller","The controller cannot load its boot image.","Can't load boot file!!","Mitel","PBX","VoIP","SIP","AX Controller","Boot Image","RTC8260"],"errorCode":"Can't load boot file!!","eventId":"","severity":"Critical","summary":"The controller cannot load its boot image.","rootCause":"The RTC8260 boot file or CompactFlash image is missing, corrupt, unreadable, or incompatible.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Confirm the exact controller and approved image, collect console output, protect the existing media, and use the Mitel-documented recovery or media-replacement procedure; do not write an unverified image.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiVoice Business Migration - Can't Load Boot File.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Mitel MiVoice Business Migration Tool: Migration failure.\nProduct scope: MiVoice Business AX Controller.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"Mitel MiVoice Business Migration Tool: Migration failure","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["network-appliances"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","AX Controller","Boot Image","RTC8260"],"articleCategories":["Mitel","VoIP","Telephony","AX Controller","Boot Image","RTC8260"],"aliases":["Can't load boot file!!","MiVoice Business Migration - Can't Load Boot File"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60137,"title":"Mitel Recovery - License Check Failed After Hardware Change","category":"Mitel","product":"Mitel Applications / AMC Licensing","tags":["Mitel","Unified Communications","Telephony","Disaster Recovery","AMC","ARID","Hardware Identity","Swing Server"],"keywords":["Mitel Recovery - License Check Failed After Hardware Change","Mitel Applications / AMC Licensing","A restored or temporary server reports a failed license check, License Violation, invalid ARID, or hardware-identity mismatch after moving to different hardware or a new virtual machine.","License Violation / Failed license check","Mitel","PBX","VoIP","SIP","Disaster Recovery","AMC","ARID","Hardware Identity","Swing Server"],"errorCode":"License Violation / Failed license check","eventId":"","severity":"Critical","summary":"A restored or temporary server reports a failed license check, License Violation, invalid ARID, or hardware-identity mismatch after moving to different hardware or a new virtual machine.","rootCause":"The licensed application identity no longer matches the server identity presented to the Mitel Application Management Center, or the ARID and local license database are invalid or stale.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Keep the original production instance isolated, record the ARID, system ID, old and new hardware identities, and exact alarm, then follow the product-specific transfer or recovery process with Mitel or the authorized reseller. Sync with AMC only after confirming the correct entitlement and authoritative server; do not rely on an assumed universal grace period.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified Mitel Recovery - License Check Failed After Hardware Change.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Mitel MBG License Check; MCS Restore & Rollback Procedures.\nProduct scope: Mitel Applications / AMC Licensing.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"Mitel MBG License Check; MCS Restore & Rollback Procedures","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows","network-appliances"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Disaster Recovery","AMC","ARID","Hardware Identity","Swing Server"],"articleCategories":["Mitel","VoIP","Telephony","Disaster Recovery","AMC","ARID","Hardware Identity","Swing Server"],"aliases":["License Violation / Failed license check","Recovery - License Check Failed After Hardware Change"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60138,"title":"ALM0041 - MiCC Client Server Version Mismatch","category":"Mitel","product":"MiContact Center","tags":["Mitel","Unified Communications","Telephony","Client Version","Server Version","Rollback","prairieFyre"],"keywords":["ALM0041 - MiCC Client Server Version Mismatch","MiContact Center","MiCC reports that a client computer is running older software than the server, which can compromise client functionality.","ALM0041","Mitel","PBX","VoIP","SIP","Client Version","Server Version","Rollback","prairieFyre"],"errorCode":"ALM0041","eventId":"","severity":"Medium","summary":"MiCC reports that a client computer is running older software than the server, which can compromise client functionality.","rootCause":"The prairieFyre or MiCC client build does not match the server after an upgrade, rollback, restore, or staggered deployment.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Identify the client raising the alarm, compare its exact build with the server and current compatibility matrix, update the client with the supported matching package, and validate login and contact-center functions.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified ALM0041 - MiCC Client Server Version Mismatch.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Mitel ALM0041 Client Server Version Mismatch.\nProduct scope: MiContact Center.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"Mitel ALM0041 Client Server Version Mismatch","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Client Version","Server Version","Rollback","prairieFyre"],"articleCategories":["Mitel","VoIP","Telephony","Client Version","Server Version","Rollback","prairieFyre"],"aliases":["ALM0041","ALM0041 - MiCC Client Server Version Mismatch"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60139,"title":"Mitel Restore - Backup Version or Schema Incompatible","category":"Mitel","product":"Mitel Communication Service / MiContact Center","tags":["Mitel","Unified Communications","Telephony","Database Restore","Schema","Version Compatibility","Data Loss Risk"],"keywords":["Mitel Restore - Backup Version or Schema Incompatible","Mitel Communication Service / MiContact Center","A database restore fails validation or the application becomes unstable after restoring data across software revisions.","Database Restore Verification Fail","Mitel","PBX","VoIP","SIP","Database Restore","Schema","Version Compatibility","Data Loss Risk"],"errorCode":"Database Restore Verification Fail","eventId":"","severity":"Critical","summary":"A database restore fails validation or the application becomes unstable after restoring data across software revisions.","rootCause":"The backup schema was created by a different product build, or software was rolled back without restoring the matching pre-upgrade databases.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Record the exact source and target builds, preserve all backups, install the supported build required by the backup or use the documented rollback sequence, stop the watchdog before other MCS services, and restore only under a tested recovery plan. Confirm with Mitel support before crossing versions.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified Mitel Restore - Backup Version or Schema Incompatible.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MCS Restore & Rollback Procedures; MiCollab Backup Server Data.\nProduct scope: Mitel Communication Service / MiContact Center.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MCS Restore & Rollback Procedures; MiCollab Backup Server Data","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Database Restore","Schema","Version Compatibility","Data Loss Risk"],"articleCategories":["Mitel","VoIP","Telephony","Database Restore","Schema","Version Compatibility","Data Loss Risk"],"aliases":["Database Restore Verification Fail","Restore - Backup Version or Schema Incompatible"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60140,"title":"MiCollab Restore - Backup Filename Contains Spaces","category":"Mitel","product":"MiCollab Server 9.7","tags":["Mitel","Unified Communications","Telephony","Backup","Restore","TGZ","AES256","Filename"],"keywords":["MiCollab Restore - Backup Filename Contains Spaces","MiCollab Server 9.7","MiCollab cannot verify or restore a .tgz or .aes256 backup whose filename contains spaces.","Backup restore filename error","Mitel","PBX","VoIP","SIP","Backup","Restore","TGZ","AES256","Filename"],"errorCode":"Backup restore filename error","eventId":"","severity":"High","summary":"MiCollab cannot verify or restore a .tgz or .aes256 backup whose filename contains spaces.","rootCause":"The MiCollab backup and restore utilities require a supported extension and a filename without spaces.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Preserve the original, make a controlled copy with no spaces and the correct .tgz or .aes256 extension, use Verify backup file before restoration, confirm the encryption password is available, and restore only through the documented disaster-recovery workflow.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified MiCollab Restore - Backup Filename Contains Spaces.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MiCollab 9.7 Backup Server Data.\nProduct scope: MiCollab Server 9.7.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[],"sourceDocument":"MiCollab 9.7 Backup Server Data","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["linux","network-appliances"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Backup","Restore","TGZ","AES256","Filename"],"articleCategories":["Mitel","VoIP","Telephony","Backup","Restore","TGZ","AES256","Filename"],"aliases":["Backup restore filename error","MiCollab Restore - Backup Filename Contains Spaces"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60141,"title":"Mitel Swing Server - Duplicate Hostname or IP Conflict","category":"Mitel","product":"Mitel Windows Server Applications","tags":["Mitel","Unified Communications","Telephony","Disaster Recovery","DNS","NetBIOS","IP Conflict","Split Brain"],"keywords":["Mitel Swing Server - Duplicate Hostname or IP Conflict","Mitel Windows Server Applications","Phones, clients, gateways, or Windows report No Service, host not found, duplicate name, or duplicate IP while a recovery server is introduced.","Duplicate IP / Host not found / No Service","Mitel","PBX","VoIP","SIP","Disaster Recovery","DNS","NetBIOS","IP Conflict","Split Brain","ipconfig /all","arp -a","Resolve-DnsName <production-hostname>"],"errorCode":"Duplicate IP / Host not found / No Service","eventId":"","severity":"Critical","summary":"Phones, clients, gateways, or Windows report No Service, host not found, duplicate name, or duplicate IP while a recovery server is introduced.","rootCause":"The original and recovery servers are simultaneously reachable with the same production identity, or endpoints still resolve and route to the inactive identity.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Build and validate the recovery server on an isolated network. Before assigning the production hostname or IP, prove the original server is shut down or disconnected from every production VLAN, document DNS and DHCP state, change only the approved identity, clear stale resolution where appropriate, and verify there is exactly one authoritative server before reconnecting clients.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified Mitel Swing Server - Duplicate Hostname or IP Conflict.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: MCS Restore & Rollback Procedures; 6900 Diagnostics.\nProduct scope: Mitel Windows Server Applications.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[{"shell":"CMD","command":"ipconfig /all","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"CMD","command":"arp -a","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Resolve-DnsName <production-hostname>","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"MCS Restore & Rollback Procedures; 6900 Diagnostics","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Disaster Recovery","DNS","NetBIOS","IP Conflict","Split Brain"],"articleCategories":["Mitel","VoIP","Telephony","Disaster Recovery","DNS","NetBIOS","IP Conflict","Split Brain"],"aliases":["Duplicate IP / Host not found / No Service","Swing Server - Duplicate Hostname or IP Conflict"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60142,"title":"Mitel Windows Service - Logon Failure After Recovery","category":"Mitel","product":"Mitel Windows Server Applications","tags":["Mitel","Unified Communications","Telephony","Windows Service","Log on as a service","Least Privilege","SMA0001"],"keywords":["Mitel Windows Service - Logon Failure After Recovery","Mitel Windows Server Applications","Mitel, prairieFyre, watchdog, or monitoring services fail to start after a clone, domain change, or recovery.","Error 1069 / service logon failure","Mitel","PBX","VoIP","SIP","Windows Service","Log on as a service","Least Privilege","SMA0001","sc.exe query <service-name>","Get-WinEvent -FilterHashtable @{LogName='System'; Id=7000,7001,7009,7038} -MaxEvents 30"],"errorCode":"Error 1069 / service logon failure","eventId":"","severity":"Critical","summary":"Mitel, prairieFyre, watchdog, or monitoring services fail to start after a clone, domain change, or recovery.","rootCause":"The configured service identity is unavailable, its password changed, domain trust is unhealthy, or the account lacks the required Log on as a service right.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Record the service name and Windows System event, verify domain and DNS health, identify the vendor-documented service identity, restore only the required user right through policy, and update credentials using an approved least-privilege service account. Never assign a Domain Admin account merely to make the service start.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified Mitel Windows Service - Logon Failure After Recovery.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Mitel SMA0001; Windows service recovery guidance.\nProduct scope: Mitel Windows Server Applications.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[{"shell":"CMD","command":"sc.exe query <service-name>","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='System'; Id=7000,7001,7009,7038} -MaxEvents 30","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Mitel SMA0001; Windows service recovery guidance","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","Windows Service","Log on as a service","Least Privilege","SMA0001"],"articleCategories":["Mitel","VoIP","Telephony","Windows Service","Log on as a service","Least Privilege","SMA0001"],"aliases":["Error 1069 / service logon failure","Windows Service - Logon Failure After Recovery"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60143,"title":"VMware Restore - Ghost Network Adapter Breaks Mitel Binding","category":"Mitel","product":"Virtualized Mitel Windows Server","tags":["Mitel","Unified Communications","Telephony","VMware","Ghost NIC","VMXNET3","Static IP","Network Binding"],"keywords":["VMware Restore - Ghost Network Adapter Breaks Mitel Binding","Virtualized Mitel Windows Server","A restored or migrated Windows VM loses its static IP, reports that the address is already assigned, or Mitel services bind to a disconnected adapter.","IP address already assigned to another adapter","Mitel","PBX","VoIP","SIP","VMware","Ghost NIC","VMXNET3","Static IP","Network Binding","set devmgr_show_nonpresent_devices=1","devmgmt.msc","Get-NetAdapter -IncludeHidden | Format-Table Name,InterfaceDescription,Status,MacAddress"],"errorCode":"IP address already assigned to another adapter","eventId":"","severity":"Critical","summary":"A restored or migrated Windows VM loses its static IP, reports that the address is already assigned, or Mitel services bind to a disconnected adapter.","rootCause":"VM hardware was re-enumerated and Windows retained a hidden prior NIC while the active vNIC received a new device identity or configuration.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Keep the VM isolated, inventory active and hidden adapters, record IP, routes, DNS, MAC, and bindings, confirm the active vNIC and supported VMware tools, then remove only a positively identified stale adapter during an approved window. Reapply the documented network configuration and validate server, phone, client, and gateway paths before production connection.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified VMware Restore - Ghost Network Adapter Breaks Mitel Binding.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Broadcom KB 432699; Mitel recovery guidance.\nProduct scope: Virtualized Mitel Windows Server.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[{"shell":"CMD","command":"set devmgr_show_nonpresent_devices=1","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"CMD","command":"devmgmt.msc","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-NetAdapter -IncludeHidden | Format-Table Name,InterfaceDescription,Status,MacAddress","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Broadcom KB 432699; Mitel recovery guidance","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","VMware","Ghost NIC","VMXNET3","Static IP","Network Binding"],"articleCategories":["Mitel","VoIP","Telephony","VMware","Ghost NIC","VMXNET3","Static IP","Network Binding"],"aliases":["IP address already assigned to another adapter","VMware Restore - Ghost Network Adapter Breaks Mitel Binding"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60144,"title":"VMware Restore - Mitel Time Drift and Certificate or SIP Failures","category":"Mitel","product":"Virtualized Mitel Windows Server","tags":["Mitel","Unified Communications","Telephony","VMware","NTP","Time Drift","SIP","TLS"],"keywords":["VMware Restore - Mitel Time Drift and Certificate or SIP Failures","Virtualized Mitel Windows Server","After restore or migration, SIP registration, database synchronization, authentication, or TLS validation fails while the guest clock is wrong.","Time synchronization failure","Mitel","PBX","VoIP","SIP","VMware","NTP","Time Drift","SIP","TLS","w32tm /query /status","w32tm /query /source"],"errorCode":"Time synchronization failure","eventId":"","severity":"Critical","summary":"After restore or migration, SIP registration, database synchronization, authentication, or TLS validation fails while the guest clock is wrong.","rootCause":"The restored guest retained an old timestamp, migration paused its timekeeping, the ESXi host or guest source is unsynchronized, or competing time providers cause steps or drift.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Keep the duplicate instance isolated, verify ESXi and authoritative Windows time sources, record current offset and VMware time settings, correct time according to the supported domain and virtualization design before enabling Mitel traffic, then validate certificates, SIP registrations, database synchronization, and logs. Do not assume a time jump itself corrupted transaction logs without database evidence.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified VMware Restore - Mitel Time Drift and Certificate or SIP Failures.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Broadcom KB 335071 and 313874; Mitel installation guidance.\nProduct scope: Virtualized Mitel Windows Server.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[{"shell":"CMD","command":"w32tm /query /status","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"CMD","command":"w32tm /query /source","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Broadcom KB 335071 and 313874; Mitel installation guidance","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","VMware","NTP","Time Drift","SIP","TLS"],"articleCategories":["Mitel","VoIP","Telephony","VMware","NTP","Time Drift","SIP","TLS"],"aliases":["Time synchronization failure","VMware Restore - Mitel Time Drift and Certificate or SIP Failures"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":60145,"title":"SQL Server Recovering After Crash-Consistent Mitel VM Restore","category":"Mitel","product":"Virtualized Mitel Windows Server / SQL Server","tags":["Mitel","Unified Communications","Telephony","VMware","SQL Server","Crash Recovery","Database","ALM0021"],"keywords":["SQL Server Recovering After Crash-Consistent Mitel VM Restore","Virtualized Mitel Windows Server / SQL Server","A restored Mitel server is unavailable while one or more SQL databases report RECOVERING, RECOVERY_PENDING, or SUSPECT.","RECOVERING / RECOVERY_PENDING / SUSPECT","Mitel","PBX","VoIP","SIP","VMware","SQL Server","Crash Recovery","Database","ALM0021","SELECT name,state_desc FROM sys.databases ORDER BY name;","Get-Service MSSQL* | Select-Object Name,Status"],"errorCode":"RECOVERING / RECOVERY_PENDING / SUSPECT","eventId":"","severity":"Critical","summary":"A restored Mitel server is unavailable while one or more SQL databases report RECOVERING, RECOVERY_PENDING, or SUSPECT.","rootCause":"A crash-consistent snapshot requires SQL crash recovery, or missing files, storage, permissions, I/O faults, or resource limitations prevent recovery.","resolution":"1. Record the complete message, product release, affected node, user or device, timestamp, call direction, and recent change.\n2. Do not repeatedly restart SQL or Mitel services. Query database state and SQL error logs, distinguish transient RECOVERING from RECOVERY_PENDING or SUSPECT, verify storage and I/O health, and allow normal recovery to complete while progress continues. Escalate with logs and restore from a verified application-consistent backup when recovery fails; do not use a fixed waiting period or DBCC repair without DBA and Mitel approval.\n3. Start with read-only status, logs, licensing, addressing, DNS, time, certificates, and network-path evidence.\n4. Validate registration, calling, media, synchronization, redundancy, and the original symptom after correction.","emailScript":"Hello,\n\nWe reviewed the Mitel communications issue and identified SQL Server Recovering After Crash-Consistent Mitel VM Restore.\n\nWe are validating the affected service, device, account, and network path before applying the least disruptive correction.\n\nPlease let us know which calls or features are affected and when the issue began.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the exact message, affected extension or device, approximate time, call direction, and whether audio, voicemail, presence, or login is affected. Do not send passwords, shared secrets, API keys, unredacted call records, packet captures, or voicemail content.","notes":"Source: Microsoft SQL Server Database States; Mitel recovery guidance.\nProduct scope: Virtualized Mitel Windows Server / SQL Server.\nVerified: 2026-08-14.\n\nMitel commands, menus, services, and log paths vary significantly by product and release. MiCollab, MiVoice Business, MiVoice Connect, and MX-ONE are not interchangeable. Collect voice data and packet captures only with authorization and sanitize telephone numbers, credentials, and personal data.","commands":[{"shell":"SQL","command":"SELECT name,state_desc FROM sys.databases ORDER BY name;","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-Service MSSQL* | Select-Object Name,Status","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft SQL Server Database States; Mitel recovery guidance","sourceAuthority":"Mitel","namespace":"MITEL","platforms":["windows"],"lastVerified":"2026-08-14","vendors":["Mitel"],"technologies":["Unified Communications","Telephony","VMware","SQL Server","Crash Recovery","Database","ALM0021"],"articleCategories":["Mitel","VoIP","Telephony","VMware","SQL Server","Crash Recovery","Database","ALM0021"],"aliases":["RECOVERING / RECOVERY_PENDING / SUSPECT","SQL Server Recovering After Crash-Consistent Mitel VM Restore"],"dateAdded":"2026-08-14","lastUpdated":"2026-08-14"},{"id":61000,"title":"Docker Exit 0 - Successful Container Command","category":"Docker","product":"Docker Engine / Docker Desktop / Docker Compose","tags":["Docker","Containers","DevOps","Exit Code","Success"],"keywords":["Docker Exit 0 - Successful Container Command","The container command completed and returned exit status 0.","0","Docker Engine","Docker Desktop","Docker Compose","container","image","daemon","Exit Code","Success","docker logs <container>"],"errorCode":"0","eventId":"","severity":"Low","summary":"The container command completed and returned exit status 0.","rootCause":"This is normally success, but a long-running service that exits cleanly may still have an application lifecycle or configuration problem.","resolution":"1. Record the exact command, complete error, Docker/Compose version, host OS and architecture, container or service name, image digest/tag, and timestamp.\n2. Review container logs and the image entrypoint when the workload was expected to remain running; confirm that a one-shot job produced its intended result.\n3. Inspect logs, state, configuration, resource pressure, and daemon events before restarting services or deleting resources.\n4. Reproduce with the smallest safe command and validate application health, persistence, networking, and restart behavior.","emailScript":"Hello,\n\nWe reviewed the container issue and identified Docker Exit 0 - Successful Container Command.\n\nWe are validating the application logs, container state, host resources, and Docker configuration before applying the least disruptive correction.\n\nPlease let us know if there was a recent deployment or configuration change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete error, approximate time, application or stack name, and what changed. Do not send registry passwords, tokens, environment files, secrets, private image contents, database volumes, or unredacted logs.","notes":"Sources: Docker Error Codes Complete Reference 2026 (Optimum-Web, LinkedIn), normalized against Docker documentation.\nVerified: 2026-08-10.\n\nOnly docker run exit codes 125, 126, and 127 have Docker-defined meanings; other values are returned by the container command and may follow shell/signal conventions. Exit 137 is commonly SIGKILL and may indicate OOM, but must be confirmed. Cleanup, ownership, daemon restart, and resource-limit changes require impact review, backup, and rollback.","commands":[{"shell":"Docker CLI","command":"docker logs <container>","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Docker Error Codes Complete Reference 2026; Docker Docs","sourceAuthority":"Docker documentation; Optimum-Web community reference","namespace":"DOCKER","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["Docker"],"products":["Docker Engine","Docker Desktop","Docker Compose"],"technologies":["Containers","OCI","DevOps","Exit Code","Success"],"articleCategories":["Docker","Containers","Exit Code","Success"],"aliases":["0","Exit 0 - Successful Container Command"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":61001,"title":"Docker Exit 1 - Generic Application Error","category":"Docker","product":"Docker Engine / Docker Desktop / Docker Compose","tags":["Docker","Containers","DevOps","Exit Code","Application"],"keywords":["Docker Exit 1 - Generic Application Error","The command inside the container returned a generic failure.","1","Docker Engine","Docker Desktop","Docker Compose","container","image","daemon","Exit Code","Application","docker logs <container>","docker inspect <container>"],"errorCode":"1","eventId":"","severity":"High","summary":"The command inside the container returned a generic failure.","rootCause":"An application exception, invalid configuration, missing environment value, dependency failure, startup error, or explicit application exit can return 1.","resolution":"1. Record the exact command, complete error, Docker/Compose version, host OS and architecture, container or service name, image digest/tag, and timestamp.\n2. Inspect logs, image configuration, environment variable names, mounted configuration, and dependency reachability; follow the application's own error immediately before the exit.\n3. Inspect logs, state, configuration, resource pressure, and daemon events before restarting services or deleting resources.\n4. Reproduce with the smallest safe command and validate application health, persistence, networking, and restart behavior.","emailScript":"Hello,\n\nWe reviewed the container issue and identified Docker Exit 1 - Generic Application Error.\n\nWe are validating the application logs, container state, host resources, and Docker configuration before applying the least disruptive correction.\n\nPlease let us know if there was a recent deployment or configuration change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete error, approximate time, application or stack name, and what changed. Do not send registry passwords, tokens, environment files, secrets, private image contents, database volumes, or unredacted logs.","notes":"Sources: Docker Error Codes Complete Reference 2026 (Optimum-Web, LinkedIn), normalized against Docker documentation.\nVerified: 2026-08-10.\n\nOnly docker run exit codes 125, 126, and 127 have Docker-defined meanings; other values are returned by the container command and may follow shell/signal conventions. Exit 137 is commonly SIGKILL and may indicate OOM, but must be confirmed. Cleanup, ownership, daemon restart, and resource-limit changes require impact review, backup, and rollback.","commands":[{"shell":"Docker CLI","command":"docker logs <container>","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"Docker CLI","command":"docker inspect <container>","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Docker Error Codes Complete Reference 2026; Docker Docs","sourceAuthority":"Docker documentation; Optimum-Web community reference","namespace":"DOCKER","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["Docker"],"products":["Docker Engine","Docker Desktop","Docker Compose"],"technologies":["Containers","OCI","DevOps","Exit Code","Application"],"articleCategories":["Docker","Containers","Exit Code","Application"],"aliases":["1","Exit 1 - Generic Application Error"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":61002,"title":"Docker Exit 125 - Docker Failed to Run Container","category":"Docker","product":"Docker Engine / Docker Desktop / Docker Compose","tags":["Docker","Containers","DevOps","Exit Code","Daemon","docker run"],"keywords":["Docker Exit 125 - Docker Failed to Run Container","Docker itself failed before the container command could run.","125","Docker Engine","Docker Desktop","Docker Compose","container","image","daemon","Exit Code","Daemon","docker run","docker info","docker ps -a"],"errorCode":"125","eventId":"","severity":"High","summary":"Docker itself failed before the container command could run.","rootCause":"An invalid docker run option, name or port conflict, daemon/runtime problem, incompatible request, or invalid configuration can cause exit 125.","resolution":"1. Record the exact command, complete error, Docker/Compose version, host OS and architecture, container or service name, image digest/tag, and timestamp.\n2. Read the daemon/CLI error preceding the code and correct that specific request. Verify daemon status and configuration; do not restart it automatically for a syntax or naming error.\n3. Inspect logs, state, configuration, resource pressure, and daemon events before restarting services or deleting resources.\n4. Reproduce with the smallest safe command and validate application health, persistence, networking, and restart behavior.","emailScript":"Hello,\n\nWe reviewed the container issue and identified Docker Exit 125 - Docker Failed to Run Container.\n\nWe are validating the application logs, container state, host resources, and Docker configuration before applying the least disruptive correction.\n\nPlease let us know if there was a recent deployment or configuration change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete error, approximate time, application or stack name, and what changed. Do not send registry passwords, tokens, environment files, secrets, private image contents, database volumes, or unredacted logs.","notes":"Sources: Docker Error Codes Complete Reference 2026 (Optimum-Web, LinkedIn), normalized against Docker documentation.\nVerified: 2026-08-10.\n\nOnly docker run exit codes 125, 126, and 127 have Docker-defined meanings; other values are returned by the container command and may follow shell/signal conventions. Exit 137 is commonly SIGKILL and may indicate OOM, but must be confirmed. Cleanup, ownership, daemon restart, and resource-limit changes require impact review, backup, and rollback.","commands":[{"shell":"Docker CLI","command":"docker info","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"Docker CLI","command":"docker ps -a","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Docker Error Codes Complete Reference 2026; Docker Docs","sourceAuthority":"Docker documentation; Optimum-Web community reference","namespace":"DOCKER","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["Docker"],"products":["Docker Engine","Docker Desktop","Docker Compose"],"technologies":["Containers","OCI","DevOps","Exit Code","Daemon","docker run"],"articleCategories":["Docker","Containers","Exit Code","Daemon","docker run"],"aliases":["125","Exit 125 - Docker Failed to Run Container"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":61003,"title":"Docker Exit 126 - Container Command Cannot Be Invoked","category":"Docker","product":"Docker Engine / Docker Desktop / Docker Compose","tags":["Docker","Containers","DevOps","Exit Code","ENTRYPOINT","Permissions"],"keywords":["Docker Exit 126 - Container Command Cannot Be Invoked","The requested container command exists but cannot be invoked.","126","Docker Engine","Docker Desktop","Docker Compose","container","image","daemon","Exit Code","ENTRYPOINT","Permissions","docker image inspect <image>"],"errorCode":"126","eventId":"","severity":"High","summary":"The requested container command exists but cannot be invoked.","rootCause":"Execute permission, directory-vs-file confusion, interpreter/shebang, mount options, architecture, or file format can prevent execution.","resolution":"1. Record the exact command, complete error, Docker/Compose version, host OS and architecture, container or service name, image digest/tag, and timestamp.\n2. Inspect the image entrypoint/CMD and target file metadata, interpreter, mount, and architecture; rebuild with the correct executable permissions and runtime.\n3. Inspect logs, state, configuration, resource pressure, and daemon events before restarting services or deleting resources.\n4. Reproduce with the smallest safe command and validate application health, persistence, networking, and restart behavior.","emailScript":"Hello,\n\nWe reviewed the container issue and identified Docker Exit 126 - Container Command Cannot Be Invoked.\n\nWe are validating the application logs, container state, host resources, and Docker configuration before applying the least disruptive correction.\n\nPlease let us know if there was a recent deployment or configuration change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete error, approximate time, application or stack name, and what changed. Do not send registry passwords, tokens, environment files, secrets, private image contents, database volumes, or unredacted logs.","notes":"Sources: Docker Error Codes Complete Reference 2026 (Optimum-Web, LinkedIn), normalized against Docker documentation.\nVerified: 2026-08-10.\n\nOnly docker run exit codes 125, 126, and 127 have Docker-defined meanings; other values are returned by the container command and may follow shell/signal conventions. Exit 137 is commonly SIGKILL and may indicate OOM, but must be confirmed. Cleanup, ownership, daemon restart, and resource-limit changes require impact review, backup, and rollback.","commands":[{"shell":"Docker CLI","command":"docker image inspect <image>","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Docker Error Codes Complete Reference 2026; Docker Docs","sourceAuthority":"Docker documentation; Optimum-Web community reference","namespace":"DOCKER","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["Docker"],"products":["Docker Engine","Docker Desktop","Docker Compose"],"technologies":["Containers","OCI","DevOps","Exit Code","ENTRYPOINT","Permissions"],"articleCategories":["Docker","Containers","Exit Code","ENTRYPOINT","Permissions"],"aliases":["126","Exit 126 - Container Command Cannot Be Invoked"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":61004,"title":"Docker Exit 127 - Container Command Not Found","category":"Docker","product":"Docker Engine / Docker Desktop / Docker Compose","tags":["Docker","Containers","DevOps","Exit Code","Command Not Found","PATH"],"keywords":["Docker Exit 127 - Container Command Not Found","Docker could not find the requested command inside the container.","127","Docker Engine","Docker Desktop","Docker Compose","container","image","daemon","Exit Code","Command Not Found","PATH","docker image inspect <image>"],"errorCode":"127","eventId":"","severity":"High","summary":"Docker could not find the requested command inside the container.","rootCause":"A typo, incorrect path, absent package, wrong build stage, PATH configuration, or overwritten bind mount can hide the executable.","resolution":"1. Record the exact command, complete error, Docker/Compose version, host OS and architecture, container or service name, image digest/tag, and timestamp.\n2. Inspect the image configuration and filesystem using an available shell or Docker Debug, verify the final build stage, and use the correct absolute executable path.\n3. Inspect logs, state, configuration, resource pressure, and daemon events before restarting services or deleting resources.\n4. Reproduce with the smallest safe command and validate application health, persistence, networking, and restart behavior.","emailScript":"Hello,\n\nWe reviewed the container issue and identified Docker Exit 127 - Container Command Not Found.\n\nWe are validating the application logs, container state, host resources, and Docker configuration before applying the least disruptive correction.\n\nPlease let us know if there was a recent deployment or configuration change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete error, approximate time, application or stack name, and what changed. Do not send registry passwords, tokens, environment files, secrets, private image contents, database volumes, or unredacted logs.","notes":"Sources: Docker Error Codes Complete Reference 2026 (Optimum-Web, LinkedIn), normalized against Docker documentation.\nVerified: 2026-08-10.\n\nOnly docker run exit codes 125, 126, and 127 have Docker-defined meanings; other values are returned by the container command and may follow shell/signal conventions. Exit 137 is commonly SIGKILL and may indicate OOM, but must be confirmed. Cleanup, ownership, daemon restart, and resource-limit changes require impact review, backup, and rollback.","commands":[{"shell":"Docker CLI","command":"docker image inspect <image>","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Docker Error Codes Complete Reference 2026; Docker Docs","sourceAuthority":"Docker documentation; Optimum-Web community reference","namespace":"DOCKER","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["Docker"],"products":["Docker Engine","Docker Desktop","Docker Compose"],"technologies":["Containers","OCI","DevOps","Exit Code","Command Not Found","PATH"],"articleCategories":["Docker","Containers","Exit Code","Command Not Found","PATH"],"aliases":["127","Exit 127 - Container Command Not Found"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":61005,"title":"Docker Exit 137 - SIGKILL / Possible OOM","category":"Docker","product":"Docker Engine / Docker Desktop / Docker Compose","tags":["Docker","Containers","DevOps","Exit Code","SIGKILL","OOM","Memory"],"keywords":["Docker Exit 137 - SIGKILL / Possible OOM","The container command ended with 137, commonly representing signal 9 (SIGKILL); OOM is one important but not exclusive cause.","137","Docker Engine","Docker Desktop","Docker Compose","container","image","daemon","Exit Code","SIGKILL","OOM","Memory","docker inspect <container> --format '{{json .State}}'","docker stats --no-stream <container>"],"errorCode":"137","eventId":"","severity":"Critical","summary":"The container command ended with 137, commonly representing signal 9 (SIGKILL); OOM is one important but not exclusive cause.","rootCause":"A container or host OOM kill, manual kill, runtime shutdown, orchestrator action, or enforced timeout can send SIGKILL.","resolution":"1. Record the exact command, complete error, Docker/Compose version, host OS and architecture, container or service name, image digest/tag, and timestamp.\n2. Check State.OOMKilled, container events, host kernel logs, memory limit and usage, and orchestrator history. Fix a confirmed leak or capacity/limit issue rather than merely raising memory.\n3. Inspect logs, state, configuration, resource pressure, and daemon events before restarting services or deleting resources.\n4. Reproduce with the smallest safe command and validate application health, persistence, networking, and restart behavior.","emailScript":"Hello,\n\nWe reviewed the container issue and identified Docker Exit 137 - SIGKILL / Possible OOM.\n\nWe are validating the application logs, container state, host resources, and Docker configuration before applying the least disruptive correction.\n\nPlease let us know if there was a recent deployment or configuration change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete error, approximate time, application or stack name, and what changed. Do not send registry passwords, tokens, environment files, secrets, private image contents, database volumes, or unredacted logs.","notes":"Sources: Docker Error Codes Complete Reference 2026 (Optimum-Web, LinkedIn), normalized against Docker documentation.\nVerified: 2026-08-10.\n\nOnly docker run exit codes 125, 126, and 127 have Docker-defined meanings; other values are returned by the container command and may follow shell/signal conventions. Exit 137 is commonly SIGKILL and may indicate OOM, but must be confirmed. Cleanup, ownership, daemon restart, and resource-limit changes require impact review, backup, and rollback.","commands":[{"shell":"Docker CLI","command":"docker inspect <container> --format '{{json .State}}'","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"Docker CLI","command":"docker stats --no-stream <container>","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Docker Error Codes Complete Reference 2026; Docker Docs","sourceAuthority":"Docker documentation; Optimum-Web community reference","namespace":"DOCKER","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["Docker"],"products":["Docker Engine","Docker Desktop","Docker Compose"],"technologies":["Containers","OCI","DevOps","Exit Code","SIGKILL","OOM","Memory"],"articleCategories":["Docker","Containers","Exit Code","SIGKILL","OOM","Memory"],"aliases":["137","Exit 137 - SIGKILL / Possible OOM"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":61006,"title":"Docker Exit 139 - Segmentation Fault","category":"Docker","product":"Docker Engine / Docker Desktop / Docker Compose","tags":["Docker","Containers","DevOps","Exit Code","SIGSEGV","Segmentation Fault"],"keywords":["Docker Exit 139 - Segmentation Fault","The container command terminated after a segmentation fault, commonly signal 11.","139","Docker Engine","Docker Desktop","Docker Compose","container","image","daemon","Exit Code","SIGSEGV","Segmentation Fault","docker image inspect <image>","docker inspect <container>"],"errorCode":"139","eventId":"","severity":"Critical","summary":"The container command terminated after a segmentation fault, commonly signal 11.","rootCause":"Application memory corruption, incompatible native library, architecture mismatch, stack exhaustion, or runtime defect can cause SIGSEGV.","resolution":"1. Record the exact command, complete error, Docker/Compose version, host OS and architecture, container or service name, image digest/tag, and timestamp.\n2. Collect application logs and an approved core dump, verify image architecture and native dependencies, reproduce against the exact image digest, and debug the application rather than Docker alone.\n3. Inspect logs, state, configuration, resource pressure, and daemon events before restarting services or deleting resources.\n4. Reproduce with the smallest safe command and validate application health, persistence, networking, and restart behavior.","emailScript":"Hello,\n\nWe reviewed the container issue and identified Docker Exit 139 - Segmentation Fault.\n\nWe are validating the application logs, container state, host resources, and Docker configuration before applying the least disruptive correction.\n\nPlease let us know if there was a recent deployment or configuration change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete error, approximate time, application or stack name, and what changed. Do not send registry passwords, tokens, environment files, secrets, private image contents, database volumes, or unredacted logs.","notes":"Sources: Docker Error Codes Complete Reference 2026 (Optimum-Web, LinkedIn), normalized against Docker documentation.\nVerified: 2026-08-10.\n\nOnly docker run exit codes 125, 126, and 127 have Docker-defined meanings; other values are returned by the container command and may follow shell/signal conventions. Exit 137 is commonly SIGKILL and may indicate OOM, but must be confirmed. Cleanup, ownership, daemon restart, and resource-limit changes require impact review, backup, and rollback.","commands":[{"shell":"Docker CLI","command":"docker image inspect <image>","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"Docker CLI","command":"docker inspect <container>","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Docker Error Codes Complete Reference 2026; Docker Docs","sourceAuthority":"Docker documentation; Optimum-Web community reference","namespace":"DOCKER","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["Docker"],"products":["Docker Engine","Docker Desktop","Docker Compose"],"technologies":["Containers","OCI","DevOps","Exit Code","SIGSEGV","Segmentation Fault"],"articleCategories":["Docker","Containers","Exit Code","SIGSEGV","Segmentation Fault"],"aliases":["139","Exit 139 - Segmentation Fault"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":61007,"title":"Docker Exit 143 - SIGTERM","category":"Docker","product":"Docker Engine / Docker Desktop / Docker Compose","tags":["Docker","Containers","DevOps","Exit Code","SIGTERM","Shutdown"],"keywords":["Docker Exit 143 - SIGTERM","The container command exited after SIGTERM, commonly the normal result of docker stop or an orchestrator shutdown.","143","Docker Engine","Docker Desktop","Docker Compose","container","image","daemon","Exit Code","SIGTERM","Shutdown","docker events --since <timestamp> --until <timestamp>","docker inspect <container>"],"errorCode":"143","eventId":"","severity":"Medium","summary":"The container command exited after SIGTERM, commonly the normal result of docker stop or an orchestrator shutdown.","rootCause":"An intentional stop, deployment, health remediation, scheduler action, host shutdown, or application lifecycle event sent SIGTERM.","resolution":"1. Record the exact command, complete error, Docker/Compose version, host OS and architecture, container or service name, image digest/tag, and timestamp.\n2. Correlate Docker events and deployment history, confirm the application handled its shutdown grace period, and investigate only when the termination was unexpected or data was not flushed.\n3. Inspect logs, state, configuration, resource pressure, and daemon events before restarting services or deleting resources.\n4. Reproduce with the smallest safe command and validate application health, persistence, networking, and restart behavior.","emailScript":"Hello,\n\nWe reviewed the container issue and identified Docker Exit 143 - SIGTERM.\n\nWe are validating the application logs, container state, host resources, and Docker configuration before applying the least disruptive correction.\n\nPlease let us know if there was a recent deployment or configuration change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete error, approximate time, application or stack name, and what changed. Do not send registry passwords, tokens, environment files, secrets, private image contents, database volumes, or unredacted logs.","notes":"Sources: Docker Error Codes Complete Reference 2026 (Optimum-Web, LinkedIn), normalized against Docker documentation.\nVerified: 2026-08-10.\n\nOnly docker run exit codes 125, 126, and 127 have Docker-defined meanings; other values are returned by the container command and may follow shell/signal conventions. Exit 137 is commonly SIGKILL and may indicate OOM, but must be confirmed. Cleanup, ownership, daemon restart, and resource-limit changes require impact review, backup, and rollback.","commands":[{"shell":"Docker CLI","command":"docker events --since <timestamp> --until <timestamp>","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"Docker CLI","command":"docker inspect <container>","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Docker Error Codes Complete Reference 2026; Docker Docs","sourceAuthority":"Docker documentation; Optimum-Web community reference","namespace":"DOCKER","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["Docker"],"products":["Docker Engine","Docker Desktop","Docker Compose"],"technologies":["Containers","OCI","DevOps","Exit Code","SIGTERM","Shutdown"],"articleCategories":["Docker","Containers","Exit Code","SIGTERM","Shutdown"],"aliases":["143","Exit 143 - SIGTERM"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":61008,"title":"Docker - Cannot Connect to the Docker Daemon","category":"Docker","product":"Docker Engine / Docker Desktop / Docker Compose","tags":["Docker","Containers","DevOps","Daemon","Socket","Docker Context"],"keywords":["Docker - Cannot Connect to the Docker Daemon","The Docker client cannot reach the configured daemon endpoint.","Docker Engine","Docker Desktop","Docker Compose","container","image","daemon","Daemon","Socket","Docker Context","docker context show","docker context ls","docker info"],"errorCode":"","eventId":"","severity":"High","summary":"The Docker client cannot reach the configured daemon endpoint.","rootCause":"The daemon or Docker Desktop is stopped, the active context/DOCKER_HOST is wrong, the socket or named pipe is unavailable, permissions are insufficient, or remote TLS/connectivity is failing.","resolution":"1. Record the exact command, complete error, Docker/Compose version, host OS and architecture, container or service name, image digest/tag, and timestamp.\n2. Check the active context and endpoint, Docker Desktop or daemon status, socket permissions and remote connectivity. Start or restart the daemon only after assessing host workload impact.\n3. Inspect logs, state, configuration, resource pressure, and daemon events before restarting services or deleting resources.\n4. Reproduce with the smallest safe command and validate application health, persistence, networking, and restart behavior.","emailScript":"Hello,\n\nWe reviewed the container issue and identified Docker - Cannot Connect to the Docker Daemon.\n\nWe are validating the application logs, container state, host resources, and Docker configuration before applying the least disruptive correction.\n\nPlease let us know if there was a recent deployment or configuration change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete error, approximate time, application or stack name, and what changed. Do not send registry passwords, tokens, environment files, secrets, private image contents, database volumes, or unredacted logs.","notes":"Sources: Docker Error Codes Complete Reference 2026 (Optimum-Web, LinkedIn), normalized against Docker documentation.\nVerified: 2026-08-10.\n\nOnly docker run exit codes 125, 126, and 127 have Docker-defined meanings; other values are returned by the container command and may follow shell/signal conventions. Exit 137 is commonly SIGKILL and may indicate OOM, but must be confirmed. Cleanup, ownership, daemon restart, and resource-limit changes require impact review, backup, and rollback.","commands":[{"shell":"Docker CLI","command":"docker context show","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"Docker CLI","command":"docker context ls","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"Docker CLI","command":"docker info","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Docker Error Codes Complete Reference 2026; Docker Docs","sourceAuthority":"Docker documentation; Optimum-Web community reference","namespace":"DOCKER","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["Docker"],"products":["Docker Engine","Docker Desktop","Docker Compose"],"technologies":["Containers","OCI","DevOps","Daemon","Socket","Docker Context"],"articleCategories":["Docker","Containers","Daemon","Socket","Docker Context"],"aliases":["- Cannot Connect to the Docker Daemon"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":61009,"title":"Docker - Port Is Already Allocated","category":"Docker","product":"Docker Engine / Docker Desktop / Docker Compose","tags":["Docker","Containers","DevOps","Networking","Port Conflict","Bind"],"keywords":["Docker - Port Is Already Allocated","A requested host port cannot be published because another process or container already owns it.","Docker Engine","Docker Desktop","Docker Compose","container","image","daemon","Networking","Port Conflict","Bind","docker ps --format '{{.ID}} {{.Names}} {{.Ports}}'"],"errorCode":"","eventId":"","severity":"High","summary":"A requested host port cannot be published because another process or container already owns it.","rootCause":"A running or stopped/restarting container, host service, duplicate Compose project, or conflicting bind address uses the port.","resolution":"1. Record the exact command, complete error, Docker/Compose version, host OS and architecture, container or service name, image digest/tag, and timestamp.\n2. Identify the listener and owning container, decide which service should retain the port, then stop the approved conflict or deliberately publish a different host port.\n3. Inspect logs, state, configuration, resource pressure, and daemon events before restarting services or deleting resources.\n4. Reproduce with the smallest safe command and validate application health, persistence, networking, and restart behavior.","emailScript":"Hello,\n\nWe reviewed the container issue and identified Docker - Port Is Already Allocated.\n\nWe are validating the application logs, container state, host resources, and Docker configuration before applying the least disruptive correction.\n\nPlease let us know if there was a recent deployment or configuration change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete error, approximate time, application or stack name, and what changed. Do not send registry passwords, tokens, environment files, secrets, private image contents, database volumes, or unredacted logs.","notes":"Sources: Docker Error Codes Complete Reference 2026 (Optimum-Web, LinkedIn), normalized against Docker documentation.\nVerified: 2026-08-10.\n\nOnly docker run exit codes 125, 126, and 127 have Docker-defined meanings; other values are returned by the container command and may follow shell/signal conventions. Exit 137 is commonly SIGKILL and may indicate OOM, but must be confirmed. Cleanup, ownership, daemon restart, and resource-limit changes require impact review, backup, and rollback.","commands":[{"shell":"Docker CLI","command":"docker ps --format '{{.ID}} {{.Names}} {{.Ports}}'","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Docker Error Codes Complete Reference 2026; Docker Docs","sourceAuthority":"Docker documentation; Optimum-Web community reference","namespace":"DOCKER","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["Docker"],"products":["Docker Engine","Docker Desktop","Docker Compose"],"technologies":["Containers","OCI","DevOps","Networking","Port Conflict","Bind"],"articleCategories":["Docker","Containers","Networking","Port Conflict","Bind"],"aliases":["- Port Is Already Allocated"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":61010,"title":"Docker Container - DNS Resolution Failure","category":"Docker","product":"Docker Engine / Docker Desktop / Docker Compose","tags":["Docker","Containers","DevOps","Networking","DNS","Service Discovery"],"keywords":["Docker Container - DNS Resolution Failure","A container cannot resolve an external or service hostname.","Docker Engine","Docker Desktop","Docker Compose","container","image","daemon","Networking","DNS","Service Discovery","docker inspect <container>","docker network inspect <network>"],"errorCode":"","eventId":"","severity":"High","summary":"A container cannot resolve an external or service hostname.","rootCause":"Embedded DNS, host resolver, VPN, proxy, daemon DNS configuration, network attachment, search domain, upstream DNS, or service naming is wrong.","resolution":"1. Record the exact command, complete error, Docker/Compose version, host OS and architecture, container or service name, image digest/tag, and timestamp.\n2. Test resolution inside the affected network, compare host and container DNS, verify Compose service names and network membership, and correct the actual resolver path. Avoid hard-coding public DNS without policy approval.\n3. Inspect logs, state, configuration, resource pressure, and daemon events before restarting services or deleting resources.\n4. Reproduce with the smallest safe command and validate application health, persistence, networking, and restart behavior.","emailScript":"Hello,\n\nWe reviewed the container issue and identified Docker Container - DNS Resolution Failure.\n\nWe are validating the application logs, container state, host resources, and Docker configuration before applying the least disruptive correction.\n\nPlease let us know if there was a recent deployment or configuration change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete error, approximate time, application or stack name, and what changed. Do not send registry passwords, tokens, environment files, secrets, private image contents, database volumes, or unredacted logs.","notes":"Sources: Docker Error Codes Complete Reference 2026 (Optimum-Web, LinkedIn), normalized against Docker documentation.\nVerified: 2026-08-10.\n\nOnly docker run exit codes 125, 126, and 127 have Docker-defined meanings; other values are returned by the container command and may follow shell/signal conventions. Exit 137 is commonly SIGKILL and may indicate OOM, but must be confirmed. Cleanup, ownership, daemon restart, and resource-limit changes require impact review, backup, and rollback.","commands":[{"shell":"Docker CLI","command":"docker inspect <container>","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"Docker CLI","command":"docker network inspect <network>","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Docker Error Codes Complete Reference 2026; Docker Docs","sourceAuthority":"Docker documentation; Optimum-Web community reference","namespace":"DOCKER","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["Docker"],"products":["Docker Engine","Docker Desktop","Docker Compose"],"technologies":["Containers","OCI","DevOps","Networking","DNS","Service Discovery"],"articleCategories":["Docker","Containers","Networking","DNS","Service Discovery"],"aliases":["Container - DNS Resolution Failure"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":61011,"title":"Docker - No Space Left on Device","category":"Docker","product":"Docker Engine / Docker Desktop / Docker Compose","tags":["Docker","Containers","DevOps","Storage","Disk Full","Inodes"],"keywords":["Docker - No Space Left on Device","Docker or the container host exhausted a filesystem, inode pool, storage-driver allocation, or log capacity.","Docker Engine","Docker Desktop","Docker Compose","container","image","daemon","Storage","Disk Full","Inodes","docker system df -v","docker ps -a --size"],"errorCode":"","eventId":"","severity":"Critical","summary":"Docker or the container host exhausted a filesystem, inode pool, storage-driver allocation, or log capacity.","rootCause":"Images, layers, build cache, stopped containers, logs, writable layers, volumes, or unrelated host data consumed the available resource.","resolution":"1. Record the exact command, complete error, Docker/Compose version, host OS and architecture, container or service name, image digest/tag, and timestamp.\n2. Use filesystem and Docker disk-usage evidence to identify the consumer. Back up persistent data and remove only explicitly approved unused resources; do not begin with a blanket prune.\n3. Inspect logs, state, configuration, resource pressure, and daemon events before restarting services or deleting resources.\n4. Reproduce with the smallest safe command and validate application health, persistence, networking, and restart behavior.","emailScript":"Hello,\n\nWe reviewed the container issue and identified Docker - No Space Left on Device.\n\nWe are validating the application logs, container state, host resources, and Docker configuration before applying the least disruptive correction.\n\nPlease let us know if there was a recent deployment or configuration change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete error, approximate time, application or stack name, and what changed. Do not send registry passwords, tokens, environment files, secrets, private image contents, database volumes, or unredacted logs.","notes":"Sources: Docker Error Codes Complete Reference 2026 (Optimum-Web, LinkedIn), normalized against Docker documentation.\nVerified: 2026-08-10.\n\nOnly docker run exit codes 125, 126, and 127 have Docker-defined meanings; other values are returned by the container command and may follow shell/signal conventions. Exit 137 is commonly SIGKILL and may indicate OOM, but must be confirmed. Cleanup, ownership, daemon restart, and resource-limit changes require impact review, backup, and rollback.","commands":[{"shell":"Docker CLI","command":"docker system df -v","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"Docker CLI","command":"docker ps -a --size","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Docker Error Codes Complete Reference 2026; Docker Docs","sourceAuthority":"Docker documentation; Optimum-Web community reference","namespace":"DOCKER","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["Docker"],"products":["Docker Engine","Docker Desktop","Docker Compose"],"technologies":["Containers","OCI","DevOps","Storage","Disk Full","Inodes"],"articleCategories":["Docker","Containers","Storage","Disk Full","Inodes"],"aliases":["- No Space Left on Device"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":61012,"title":"Docker Volume - Permission Denied","category":"Docker","product":"Docker Engine / Docker Desktop / Docker Compose","tags":["Docker","Containers","DevOps","Storage","Volume","Permission Denied","UID","SELinux"],"keywords":["Docker Volume - Permission Denied","A process inside the container cannot access a bind mount or volume path.","Docker Engine","Docker Desktop","Docker Compose","container","image","daemon","Storage","Volume","Permission Denied","UID","SELinux","docker inspect <container>"],"errorCode":"","eventId":"","severity":"High","summary":"A process inside the container cannot access a bind mount or volume path.","rootCause":"Container UID/GID, host ownership, mode bits, SELinux/AppArmor policy, read-only mounts, rootless mapping, or Docker Desktop file sharing does not permit access.","resolution":"1. Record the exact command, complete error, Docker/Compose version, host OS and architecture, container or service name, image digest/tag, and timestamp.\n2. Determine the container's runtime identity and mount type, inspect host security labels and permissions, and grant the narrowest required access. Do not recursively chown an unknown production data tree.\n3. Inspect logs, state, configuration, resource pressure, and daemon events before restarting services or deleting resources.\n4. Reproduce with the smallest safe command and validate application health, persistence, networking, and restart behavior.","emailScript":"Hello,\n\nWe reviewed the container issue and identified Docker Volume - Permission Denied.\n\nWe are validating the application logs, container state, host resources, and Docker configuration before applying the least disruptive correction.\n\nPlease let us know if there was a recent deployment or configuration change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete error, approximate time, application or stack name, and what changed. Do not send registry passwords, tokens, environment files, secrets, private image contents, database volumes, or unredacted logs.","notes":"Sources: Docker Error Codes Complete Reference 2026 (Optimum-Web, LinkedIn), normalized against Docker documentation.\nVerified: 2026-08-10.\n\nOnly docker run exit codes 125, 126, and 127 have Docker-defined meanings; other values are returned by the container command and may follow shell/signal conventions. Exit 137 is commonly SIGKILL and may indicate OOM, but must be confirmed. Cleanup, ownership, daemon restart, and resource-limit changes require impact review, backup, and rollback.","commands":[{"shell":"Docker CLI","command":"docker inspect <container>","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Docker Error Codes Complete Reference 2026; Docker Docs","sourceAuthority":"Docker documentation; Optimum-Web community reference","namespace":"DOCKER","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["Docker"],"products":["Docker Engine","Docker Desktop","Docker Compose"],"technologies":["Containers","OCI","DevOps","Storage","Volume","Permission Denied","UID","SELinux"],"articleCategories":["Docker","Containers","Storage","Volume","Permission Denied","UID","SELinux"],"aliases":["Volume - Permission Denied"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":61013,"title":"Docker Pull - Access Denied or Repository Does Not Exist","category":"Docker","product":"Docker Engine / Docker Desktop / Docker Compose","tags":["Docker","Containers","DevOps","Image","Registry","Authentication","Pull"],"keywords":["Docker Pull - Access Denied or Repository Does Not Exist","Docker cannot pull the requested image because the reference is wrong or registry authorization failed.","Docker Engine","Docker Desktop","Docker Compose","container","image","daemon","Image","Registry","Authentication","Pull","docker image inspect <image>","docker pull <registry>/<repository>:<tag>"],"errorCode":"","eventId":"","severity":"High","summary":"Docker cannot pull the requested image because the reference is wrong or registry authorization failed.","rootCause":"The registry, repository, namespace, case-sensitive name, tag, platform, login, token scope, or organization permission is incorrect.","resolution":"1. Record the exact command, complete error, Docker/Compose version, host OS and architecture, container or service name, image digest/tag, and timestamp.\n2. Verify the full image reference and tag, registry availability, credential helper, account entitlement and token scope. Authenticate interactively or through an approved secret mechanism, never on a shared command line.\n3. Inspect logs, state, configuration, resource pressure, and daemon events before restarting services or deleting resources.\n4. Reproduce with the smallest safe command and validate application health, persistence, networking, and restart behavior.","emailScript":"Hello,\n\nWe reviewed the container issue and identified Docker Pull - Access Denied or Repository Does Not Exist.\n\nWe are validating the application logs, container state, host resources, and Docker configuration before applying the least disruptive correction.\n\nPlease let us know if there was a recent deployment or configuration change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete error, approximate time, application or stack name, and what changed. Do not send registry passwords, tokens, environment files, secrets, private image contents, database volumes, or unredacted logs.","notes":"Sources: Docker Error Codes Complete Reference 2026 (Optimum-Web, LinkedIn), normalized against Docker documentation.\nVerified: 2026-08-10.\n\nOnly docker run exit codes 125, 126, and 127 have Docker-defined meanings; other values are returned by the container command and may follow shell/signal conventions. Exit 137 is commonly SIGKILL and may indicate OOM, but must be confirmed. Cleanup, ownership, daemon restart, and resource-limit changes require impact review, backup, and rollback.","commands":[{"shell":"Docker CLI","command":"docker image inspect <image>","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"Docker CLI","command":"docker pull <registry>/<repository>:<tag>","risk":"Standard","safetyLevel":"Config Change"}],"sourceDocument":"Docker Error Codes Complete Reference 2026; Docker Docs","sourceAuthority":"Docker documentation; Optimum-Web community reference","namespace":"DOCKER","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["Docker"],"products":["Docker Engine","Docker Desktop","Docker Compose"],"technologies":["Containers","OCI","DevOps","Image","Registry","Authentication","Pull"],"articleCategories":["Docker","Containers","Image","Registry","Authentication","Pull"],"aliases":["Pull - Access Denied or Repository Does Not Exist"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":61014,"title":"Docker Build - Unexpected Cache Miss or Slow Build","category":"Docker","product":"Docker Engine / Docker Desktop / Docker Compose","tags":["Docker","Containers","DevOps","BuildKit","Dockerfile","Cache"],"keywords":["Docker Build - Unexpected Cache Miss or Slow Build","A build repeatedly executes layers that were expected to be cached.","Docker Engine","Docker Desktop","Docker Compose","container","image","daemon","BuildKit","Dockerfile","Cache","docker buildx build --progress=plain <context>"],"errorCode":"","eventId":"","severity":"Medium","summary":"A build repeatedly executes layers that were expected to be cached.","rootCause":"Dockerfile instruction order, changed build context, broad COPY, timestamps, build arguments, base-image changes, missing cache source, or .dockerignore content invalidated cache keys.","resolution":"1. Record the exact command, complete error, Docker/Compose version, host OS and architecture, container or service name, image digest/tag, and timestamp.\n2. Review plain-progress build output and Dockerfile ordering, narrow the build context, copy dependency manifests before frequently changing source, and verify cache import/export configuration.\n3. Inspect logs, state, configuration, resource pressure, and daemon events before restarting services or deleting resources.\n4. Reproduce with the smallest safe command and validate application health, persistence, networking, and restart behavior.","emailScript":"Hello,\n\nWe reviewed the container issue and identified Docker Build - Unexpected Cache Miss or Slow Build.\n\nWe are validating the application logs, container state, host resources, and Docker configuration before applying the least disruptive correction.\n\nPlease let us know if there was a recent deployment or configuration change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete error, approximate time, application or stack name, and what changed. Do not send registry passwords, tokens, environment files, secrets, private image contents, database volumes, or unredacted logs.","notes":"Sources: Docker Error Codes Complete Reference 2026 (Optimum-Web, LinkedIn), normalized against Docker documentation.\nVerified: 2026-08-10.\n\nOnly docker run exit codes 125, 126, and 127 have Docker-defined meanings; other values are returned by the container command and may follow shell/signal conventions. Exit 137 is commonly SIGKILL and may indicate OOM, but must be confirmed. Cleanup, ownership, daemon restart, and resource-limit changes require impact review, backup, and rollback.","commands":[{"shell":"Docker CLI","command":"docker buildx build --progress=plain <context>","risk":"Low","safetyLevel":"Low-Risk Temporary"}],"sourceDocument":"Docker Error Codes Complete Reference 2026; Docker Docs","sourceAuthority":"Docker documentation; Optimum-Web community reference","namespace":"DOCKER","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["Docker"],"products":["Docker Engine","Docker Desktop","Docker Compose"],"technologies":["Containers","OCI","DevOps","BuildKit","Dockerfile","Cache"],"articleCategories":["Docker","Containers","BuildKit","Dockerfile","Cache"],"aliases":["Build - Unexpected Cache Miss or Slow Build"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":61015,"title":"Docker Compose - Dependency Starts Before It Is Ready","category":"Docker","product":"Docker Engine / Docker Desktop / Docker Compose","tags":["Docker","Containers","DevOps","Compose","depends_on","Healthcheck","Startup"],"keywords":["Docker Compose - Dependency Starts Before It Is Ready","A dependent service starts after its dependency is running but before that dependency can accept requests.","Docker Engine","Docker Desktop","Docker Compose","container","image","daemon","Compose","depends_on","Healthcheck","Startup","docker compose ps","docker compose logs <service>"],"errorCode":"","eventId":"","severity":"High","summary":"A dependent service starts after its dependency is running but before that dependency can accept requests.","rootCause":"Short-form depends_on controls order but does not prove application readiness; the dependency lacks a meaningful healthcheck or the client lacks retry behavior.","resolution":"1. Record the exact command, complete error, Docker/Compose version, host OS and architecture, container or service name, image digest/tag, and timestamp.\n2. Add a workload-specific healthcheck and long-form depends_on condition service_healthy where appropriate, plus bounded application retry/backoff. Validate failure and recovery behavior.\n3. Inspect logs, state, configuration, resource pressure, and daemon events before restarting services or deleting resources.\n4. Reproduce with the smallest safe command and validate application health, persistence, networking, and restart behavior.","emailScript":"Hello,\n\nWe reviewed the container issue and identified Docker Compose - Dependency Starts Before It Is Ready.\n\nWe are validating the application logs, container state, host resources, and Docker configuration before applying the least disruptive correction.\n\nPlease let us know if there was a recent deployment or configuration change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete error, approximate time, application or stack name, and what changed. Do not send registry passwords, tokens, environment files, secrets, private image contents, database volumes, or unredacted logs.","notes":"Sources: Docker Error Codes Complete Reference 2026 (Optimum-Web, LinkedIn), normalized against Docker documentation.\nVerified: 2026-08-10.\n\nOnly docker run exit codes 125, 126, and 127 have Docker-defined meanings; other values are returned by the container command and may follow shell/signal conventions. Exit 137 is commonly SIGKILL and may indicate OOM, but must be confirmed. Cleanup, ownership, daemon restart, and resource-limit changes require impact review, backup, and rollback.","commands":[{"shell":"Docker CLI","command":"docker compose ps","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"Docker CLI","command":"docker compose logs <service>","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Docker Error Codes Complete Reference 2026; Docker Docs","sourceAuthority":"Docker documentation; Optimum-Web community reference","namespace":"DOCKER","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["Docker"],"products":["Docker Engine","Docker Desktop","Docker Compose"],"technologies":["Containers","OCI","DevOps","Compose","depends_on","Healthcheck","Startup"],"articleCategories":["Docker","Containers","Compose","depends_on","Healthcheck","Startup"],"aliases":["Compose - Dependency Starts Before It Is Ready"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":61016,"title":"Docker Compose - Network Already Exists or Has Incorrect Labels","category":"Docker","product":"Docker Engine / Docker Desktop / Docker Compose","tags":["Docker","Containers","DevOps","Compose","Network","Resource Conflict"],"keywords":["Docker Compose - Network Already Exists or Has Incorrect Labels","Compose encountered a pre-existing network that conflicts with the project model or expected ownership labels.","Docker Engine","Docker Desktop","Docker Compose","container","image","daemon","Compose","Network","Resource Conflict","docker network inspect <network>","docker compose config"],"errorCode":"","eventId":"","severity":"Medium","summary":"Compose encountered a pre-existing network that conflicts with the project model or expected ownership labels.","rootCause":"A previous project, renamed directory, manual network, changed Compose project name, or orphaned resource uses the same network name.","resolution":"1. Record the exact command, complete error, Docker/Compose version, host OS and architecture, container or service name, image digest/tag, and timestamp.\n2. Inspect the network labels and attached containers, confirm intended project ownership, and either declare it external, use a unique name, or remove it only after all dependencies are identified.\n3. Inspect logs, state, configuration, resource pressure, and daemon events before restarting services or deleting resources.\n4. Reproduce with the smallest safe command and validate application health, persistence, networking, and restart behavior.","emailScript":"Hello,\n\nWe reviewed the container issue and identified Docker Compose - Network Already Exists or Has Incorrect Labels.\n\nWe are validating the application logs, container state, host resources, and Docker configuration before applying the least disruptive correction.\n\nPlease let us know if there was a recent deployment or configuration change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete error, approximate time, application or stack name, and what changed. Do not send registry passwords, tokens, environment files, secrets, private image contents, database volumes, or unredacted logs.","notes":"Sources: Docker Error Codes Complete Reference 2026 (Optimum-Web, LinkedIn), normalized against Docker documentation.\nVerified: 2026-08-10.\n\nOnly docker run exit codes 125, 126, and 127 have Docker-defined meanings; other values are returned by the container command and may follow shell/signal conventions. Exit 137 is commonly SIGKILL and may indicate OOM, but must be confirmed. Cleanup, ownership, daemon restart, and resource-limit changes require impact review, backup, and rollback.","commands":[{"shell":"Docker CLI","command":"docker network inspect <network>","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"Docker CLI","command":"docker compose config","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Docker Error Codes Complete Reference 2026; Docker Docs","sourceAuthority":"Docker documentation; Optimum-Web community reference","namespace":"DOCKER","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["Docker"],"products":["Docker Engine","Docker Desktop","Docker Compose"],"technologies":["Containers","OCI","DevOps","Compose","Network","Resource Conflict"],"articleCategories":["Docker","Containers","Compose","Network","Resource Conflict"],"aliases":["Compose - Network Already Exists or Has Incorrect Labels"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":61017,"title":"Docker - Network Not Found","category":"Docker","product":"Docker Engine / Docker Desktop / Docker Compose","tags":["Docker","Containers","DevOps","Networking","Compose","Missing Network"],"keywords":["Docker - Network Not Found","A container or Compose service references a Docker network that no longer exists.","Docker Engine","Docker Desktop","Docker Compose","container","image","daemon","Networking","Compose","Missing Network","docker network ls","docker compose config"],"errorCode":"","eventId":"","severity":"High","summary":"A container or Compose service references a Docker network that no longer exists.","rootCause":"The network was removed, the wrong context or project is active, Compose resources are stale, or an external network was never created.","resolution":"1. Record the exact command, complete error, Docker/Compose version, host OS and architecture, container or service name, image digest/tag, and timestamp.\n2. Confirm Docker context and the intended network declaration, inspect existing networks, recreate through the owning Compose project, or provision the documented external network.\n3. Inspect logs, state, configuration, resource pressure, and daemon events before restarting services or deleting resources.\n4. Reproduce with the smallest safe command and validate application health, persistence, networking, and restart behavior.","emailScript":"Hello,\n\nWe reviewed the container issue and identified Docker - Network Not Found.\n\nWe are validating the application logs, container state, host resources, and Docker configuration before applying the least disruptive correction.\n\nPlease let us know if there was a recent deployment or configuration change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete error, approximate time, application or stack name, and what changed. Do not send registry passwords, tokens, environment files, secrets, private image contents, database volumes, or unredacted logs.","notes":"Sources: Docker Error Codes Complete Reference 2026 (Optimum-Web, LinkedIn), normalized against Docker documentation.\nVerified: 2026-08-10.\n\nOnly docker run exit codes 125, 126, and 127 have Docker-defined meanings; other values are returned by the container command and may follow shell/signal conventions. Exit 137 is commonly SIGKILL and may indicate OOM, but must be confirmed. Cleanup, ownership, daemon restart, and resource-limit changes require impact review, backup, and rollback.","commands":[{"shell":"Docker CLI","command":"docker network ls","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"Docker CLI","command":"docker compose config","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Docker Error Codes Complete Reference 2026; Docker Docs","sourceAuthority":"Docker documentation; Optimum-Web community reference","namespace":"DOCKER","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["Docker"],"products":["Docker Engine","Docker Desktop","Docker Compose"],"technologies":["Containers","OCI","DevOps","Networking","Compose","Missing Network"],"articleCategories":["Docker","Containers","Networking","Compose","Missing Network"],"aliases":["- Network Not Found"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":61018,"title":"Docker Compose - Invalid YAML or Configuration","category":"Docker","product":"Docker Engine / Docker Desktop / Docker Compose","tags":["Docker","Containers","DevOps","Compose","YAML","Configuration"],"keywords":["Docker Compose - Invalid YAML or Configuration","Compose cannot parse, interpolate, or validate the project configuration.","Docker Engine","Docker Desktop","Docker Compose","container","image","daemon","Compose","YAML","Configuration","docker compose config"],"errorCode":"","eventId":"","severity":"High","summary":"Compose cannot parse, interpolate, or validate the project configuration.","rootCause":"YAML indentation/type errors, unsupported attributes, unresolved variables, duplicate keys, invalid merges, or Compose-version differences can invalidate the model.","resolution":"1. Record the exact command, complete error, Docker/Compose version, host OS and architecture, container or service name, image digest/tag, and timestamp.\n2. Run docker compose config to render and validate the model, correct the first reported file/line or required variable, and review the resolved output for accidental secret exposure.\n3. Inspect logs, state, configuration, resource pressure, and daemon events before restarting services or deleting resources.\n4. Reproduce with the smallest safe command and validate application health, persistence, networking, and restart behavior.","emailScript":"Hello,\n\nWe reviewed the container issue and identified Docker Compose - Invalid YAML or Configuration.\n\nWe are validating the application logs, container state, host resources, and Docker configuration before applying the least disruptive correction.\n\nPlease let us know if there was a recent deployment or configuration change.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete error, approximate time, application or stack name, and what changed. Do not send registry passwords, tokens, environment files, secrets, private image contents, database volumes, or unredacted logs.","notes":"Sources: Docker Error Codes Complete Reference 2026 (Optimum-Web, LinkedIn), normalized against Docker documentation.\nVerified: 2026-08-10.\n\nOnly docker run exit codes 125, 126, and 127 have Docker-defined meanings; other values are returned by the container command and may follow shell/signal conventions. Exit 137 is commonly SIGKILL and may indicate OOM, but must be confirmed. Cleanup, ownership, daemon restart, and resource-limit changes require impact review, backup, and rollback.","commands":[{"shell":"Docker CLI","command":"docker compose config","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Docker Error Codes Complete Reference 2026; Docker Docs","sourceAuthority":"Docker documentation; Optimum-Web community reference","namespace":"DOCKER","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["Docker"],"products":["Docker Engine","Docker Desktop","Docker Compose"],"technologies":["Containers","OCI","DevOps","Compose","YAML","Configuration"],"articleCategories":["Docker","Containers","Compose","YAML","Configuration"],"aliases":["Compose - Invalid YAML or Configuration"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62000,"title":"Error 5 - Access Denied to Agent Due to EFS File Encryption","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","General Backup","EFS","Permissions","SYSTEM"],"keywords":["Error 5","Access Denied to Agent Due to EFS File Encryption","General Backup","The backup service runs as NT AUTHORITY\\SYSTEM, which cannot read the selected EFS-encrypted object or lacks the required access.","NinjaOne","NinjaRMM","backup agent","RMM","EFS","Permissions","SYSTEM"],"errorCode":"Error 5","eventId":"","severity":"High","summary":"NinjaOne reports access denied to agent due to efs file encryption during general backup.","rootCause":"The backup service runs as NT AUTHORITY\\SYSTEM, which cannot read the selected EFS-encrypted object or lacks the required access.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Identify the exact object and encryption owner, confirm recoverability and policy, then grant only the required SYSTEM access or use an approved EFS-aware protection design. Do not decrypt data without authorization.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 5 - Access Denied to Agent Due to EFS File Encryption.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: General Backup.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","EFS","Permissions","SYSTEM"],"articleCategories":["NinjaOne","General Backup","EFS","Permissions","SYSTEM"],"aliases":["NinjaOne Error 5","Access Denied to Agent Due to EFS File Encryption"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62001,"title":"Error 13 - Missing or Insufficient Permissions - Access Denied","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","General Backup","Permissions","SYSTEM","ACL"],"keywords":["Error 13","Missing or Insufficient Permissions - Access Denied","General Backup","NT AUTHORITY\\SYSTEM lacks access to one or more selected files or folders.","NinjaOne","NinjaRMM","backup agent","RMM","Permissions","SYSTEM","ACL"],"errorCode":"Error 13","eventId":"","severity":"High","summary":"NinjaOne reports missing or insufficient permissions - access denied during general backup.","rootCause":"NT AUTHORITY\\SYSTEM lacks access to one or more selected files or folders.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Locate the denied object, inspect effective permissions and inheritance, and grant the backup service only the access required by policy.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 13 - Missing or Insufficient Permissions - Access Denied.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: General Backup.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","Permissions","SYSTEM","ACL"],"articleCategories":["NinjaOne","General Backup","Permissions","SYSTEM","ACL"],"aliases":["NinjaOne Error 13","Missing or Insufficient Permissions - Access Denied"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62002,"title":"Error 20 - Individual File Deleted as Folder Backup Path","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","General Backup"],"keywords":["Error 20","Individual File Deleted as Folder Backup Path","General Backup","A configured folder backup path now refers to a file that was deleted or no longer matches the expected folder selection.","NinjaOne","NinjaRMM","backup agent","RMM"],"errorCode":"Error 20","eventId":"","severity":"High","summary":"NinjaOne reports individual file deleted as folder backup path during general backup.","rootCause":"A configured folder backup path now refers to a file that was deleted or no longer matches the expected folder selection.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Review the plan's selected paths and current filesystem, remove or correct only the stale selection, and confirm the intended folder still exists before retrying.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 20 - Individual File Deleted as Folder Backup Path.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: General Backup.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM"],"articleCategories":["NinjaOne","General Backup"],"aliases":["NinjaOne Error 20","Individual File Deleted as Folder Backup Path"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62003,"title":"Error 131 - Connection Lost During Backup Operation","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","General Backup","Connectivity","Transfer"],"keywords":["Error 131","Connection Lost During Backup Operation","General Backup","The endpoint lost connectivity to its backup destination or cloud service while transferring data.","NinjaOne","NinjaRMM","backup agent","RMM","Connectivity","Transfer"],"errorCode":"Error 131","eventId":"","severity":"High","summary":"NinjaOne reports connection lost during backup operation during general backup.","rootCause":"The endpoint lost connectivity to its backup destination or cloud service while transferring data.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Correlate network, proxy, firewall, VPN, sleep, interface, and service-status events; restore a stable supported path and resume or retry according to job state.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 131 - Connection Lost During Backup Operation.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: General Backup.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","Connectivity","Transfer"],"articleCategories":["NinjaOne","General Backup","Connectivity","Transfer"],"aliases":["NinjaOne Error 131","Connection Lost During Backup Operation"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62004,"title":"Error 150 - Database Error","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","General Backup","Database","Repository"],"keywords":["Error 150","Database Error","General Backup","The backup agent or repository encountered a database access, consistency, locking, resource, or service problem.","NinjaOne","NinjaRMM","backup agent","RMM","Database","Repository"],"errorCode":"Error 150","eventId":"","severity":"Critical","summary":"NinjaOne reports database error during general backup.","rootCause":"The backup agent or repository encountered a database access, consistency, locking, resource, or service problem.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Preserve the job and agent logs, verify service/storage health and free space, and contact NinjaOne Support before rebuilding or deleting any backup database.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 150 - Database Error.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: General Backup.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","Database","Repository"],"articleCategories":["NinjaOne","General Backup","Database","Repository"],"aliases":["NinjaOne Error 150","Database Error"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62005,"title":"Error 310 - Unable to Backup Volume","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","General Backup","Volume","Image Backup"],"keywords":["Error 310","Unable to Backup Volume","General Backup","The selected volume is unavailable, unsupported, offline, inaccessible, or cannot be processed by the image/backup subsystem.","NinjaOne","NinjaRMM","backup agent","RMM","Volume","Image Backup"],"errorCode":"Error 310","eventId":"","severity":"Critical","summary":"NinjaOne reports unable to backup volume during general backup.","rootCause":"The selected volume is unavailable, unsupported, offline, inaccessible, or cannot be processed by the image/backup subsystem.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Verify volume identity, online state, filesystem, permissions, health, exclusions, and VSS state where applicable; correct the underlying volume condition.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 310 - Unable to Backup Volume.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: General Backup.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","Volume","Image Backup"],"articleCategories":["NinjaOne","General Backup","Volume","Image Backup"],"aliases":["NinjaOne Error 310","Unable to Backup Volume"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62006,"title":"Error 342 - NAS Write Error","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","General Backup","NAS","Write Error","Network Storage"],"keywords":["Error 342","NAS Write Error","General Backup","The agent cannot write backup data to the configured network-attached storage destination.","NinjaOne","NinjaRMM","backup agent","RMM","NAS","Write Error","Network Storage"],"errorCode":"Error 342","eventId":"","severity":"Critical","summary":"NinjaOne reports nas write error during general backup.","rootCause":"The agent cannot write backup data to the configured network-attached storage destination.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Verify NAS availability, share path, credentials, permissions, quota, free space, protocol compatibility, and network stability using a controlled test file.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 342 - NAS Write Error.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: General Backup.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","NAS","Write Error","Network Storage"],"articleCategories":["NinjaOne","General Backup","NAS","Write Error","Network Storage"],"aliases":["NinjaOne Error 342","NAS Write Error"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62007,"title":"Error 344 - Network Storage Low Space","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","General Backup","NAS","Low Space","Capacity"],"keywords":["Error 344","Network Storage Low Space","General Backup","The configured network-storage destination is approaching its free-space threshold.","NinjaOne","NinjaRMM","backup agent","RMM","NAS","Low Space","Capacity"],"errorCode":"Error 344","eventId":"","severity":"High","summary":"NinjaOne reports network storage low space during general backup.","rootCause":"The configured network-storage destination is approaching its free-space threshold.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Measure usable capacity and retention growth, confirm repository ownership, and expand capacity or perform policy-approved retention cleanup without deleting active backup chains.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 344 - Network Storage Low Space.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: General Backup.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","NAS","Low Space","Capacity"],"articleCategories":["NinjaOne","General Backup","NAS","Low Space","Capacity"],"aliases":["NinjaOne Error 344","Network Storage Low Space"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62008,"title":"Error 345 - Critically Low Free Space on NAS","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","General Backup","NAS","Disk Full","Capacity"],"keywords":["Error 345","Critically Low Free Space on NAS","General Backup","The NAS destination has critically low capacity and may be unable to safely continue the backup.","NinjaOne","NinjaRMM","backup agent","RMM","NAS","Disk Full","Capacity"],"errorCode":"Error 345","eventId":"","severity":"Critical","summary":"NinjaOne reports critically low free space on nas during general backup.","rootCause":"The NAS destination has critically low capacity and may be unable to safely continue the backup.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Pause risky retries, verify repository integrity and capacity, then expand storage or perform vendor-supported retention cleanup with confirmed recovery points.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 345 - Critically Low Free Space on NAS.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: General Backup.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","NAS","Disk Full","Capacity"],"articleCategories":["NinjaOne","General Backup","NAS","Disk Full","Capacity"],"aliases":["NinjaOne Error 345","Critically Low Free Space on NAS"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62009,"title":"Error 360 - Cloud Communication Error","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","General Backup","Cloud","TLS","Proxy","Firewall"],"keywords":["Error 360","Cloud Communication Error","General Backup","The endpoint cannot reliably communicate with the NinjaOne Backup cloud service.","NinjaOne","NinjaRMM","backup agent","RMM","Cloud","TLS","Proxy","Firewall"],"errorCode":"Error 360","eventId":"","severity":"High","summary":"NinjaOne reports cloud communication error during general backup.","rootCause":"The endpoint cannot reliably communicate with the NinjaOne Backup cloud service.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Check NinjaOne status, DNS, time, TLS inspection, proxy, firewall allowlisting, routing, and endpoint connectivity; preserve the exact cloud/agent response.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 360 - Cloud Communication Error.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: General Backup.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","Cloud","TLS","Proxy","Firewall"],"articleCategories":["NinjaOne","General Backup","Cloud","TLS","Proxy","Firewall"],"aliases":["NinjaOne Error 360","Cloud Communication Error"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62010,"title":"Error 371 - Error Reading File or Folder","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","General Backup","Read Error","Filesystem"],"keywords":["Error 371","Error Reading File or Folder","General Backup","The agent cannot read a selected source object because it is unavailable, locked, damaged, encrypted, or inaccessible.","NinjaOne","NinjaRMM","backup agent","RMM","Read Error","Filesystem"],"errorCode":"Error 371","eventId":"","severity":"High","summary":"NinjaOne reports error reading file or folder during general backup.","rootCause":"The agent cannot read a selected source object because it is unavailable, locked, damaged, encrypted, or inaccessible.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Identify the exact path, verify existence, filesystem health, permissions, encryption, locks and exclusions, then retry only the affected plan.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 371 - Error Reading File or Folder.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: General Backup.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","Read Error","Filesystem"],"articleCategories":["NinjaOne","General Backup","Read Error","Filesystem"],"aliases":["NinjaOne Error 371","Error Reading File or Folder"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62011,"title":"Error 375 - Backup Job Cancelled","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","General Backup","Cancelled","Audit"],"keywords":["Error 375","Backup Job Cancelled","General Backup","The job was cancelled by a user, policy, service lifecycle, shutdown, schedule overlap, or external control.","NinjaOne","NinjaRMM","backup agent","RMM","Cancelled","Audit"],"errorCode":"Error 375","eventId":"","severity":"Medium","summary":"NinjaOne reports backup job cancelled during general backup.","rootCause":"The job was cancelled by a user, policy, service lifecycle, shutdown, schedule overlap, or external control.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Review audit/job history and endpoint events to identify who or what cancelled it; correct unintended scheduling or lifecycle behavior before retrying.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 375 - Backup Job Cancelled.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: General Backup.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","Cancelled","Audit"],"articleCategories":["NinjaOne","General Backup","Cancelled","Audit"],"aliases":["NinjaOne Error 375","Backup Job Cancelled"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62012,"title":"Error 10053 - Connection Aborted by Host Machine","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","General Backup","Winsock","Connection Aborted","TCP"],"keywords":["Error 10053","Connection Aborted by Host Machine","General Backup","The local host or its network stack aborted an established backup connection.","NinjaOne","NinjaRMM","backup agent","RMM","Winsock","Connection Aborted","TCP"],"errorCode":"Error 10053","eventId":"","severity":"High","summary":"NinjaOne reports connection aborted by host machine during general backup.","rootCause":"The local host or its network stack aborted an established backup connection.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Correlate endpoint firewall/security software, TCP, sleep/reboot, interface, proxy and agent-service events; correct the local abort cause.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 10053 - Connection Aborted by Host Machine.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: General Backup.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","Winsock","Connection Aborted","TCP"],"articleCategories":["NinjaOne","General Backup","Winsock","Connection Aborted","TCP"],"aliases":["NinjaOne Error 10053","Connection Aborted by Host Machine"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62013,"title":"Error 10054 - Connection Reset by Host Machine","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","General Backup","Winsock","Connection Reset","TCP"],"keywords":["Error 10054","Connection Reset by Host Machine","General Backup","An established connection was forcibly reset by the peer or an intermediary.","NinjaOne","NinjaRMM","backup agent","RMM","Winsock","Connection Reset","TCP"],"errorCode":"Error 10054","eventId":"","severity":"High","summary":"NinjaOne reports connection reset by host machine during general backup.","rootCause":"An established connection was forcibly reset by the peer or an intermediary.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Correlate both endpoints plus firewall, proxy, NAT, VPN and security-device logs, then correct the component sending the reset.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 10054 - Connection Reset by Host Machine.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: General Backup.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","Winsock","Connection Reset","TCP"],"articleCategories":["NinjaOne","General Backup","Winsock","Connection Reset","TCP"],"aliases":["NinjaOne Error 10054","Connection Reset by Host Machine"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62014,"title":"Error 306 - Snapshot Deleted While Uploading","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","Image Backup","Snapshot","VSS","Upload"],"keywords":["Error 306","Snapshot Deleted While Uploading","Image Backup","The image snapshot disappeared before its upload completed.","NinjaOne","NinjaRMM","backup agent","RMM","Snapshot","VSS","Upload"],"errorCode":"Error 306","eventId":"","severity":"Critical","summary":"NinjaOne reports snapshot deleted while uploading during image backup.","rootCause":"The image snapshot disappeared before its upload completed.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Determine whether snapshot cleanup, VSS limits, storage pressure, reboot, another backup product, or manual action removed it; preserve sufficient snapshot space and prevent conflicting cleanup.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 306 - Snapshot Deleted While Uploading.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: Image Backup.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","Snapshot","VSS","Upload"],"articleCategories":["NinjaOne","Image Backup","Snapshot","VSS","Upload"],"aliases":["NinjaOne Error 306","Snapshot Deleted While Uploading"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62015,"title":"Error 307 - Volume Has Less Than 20 Percent Free Space","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","Image Backup","VSS","Low Disk Space","Snapshot"],"keywords":["Error 307","Volume Has Less Than 20 Percent Free Space","Image Backup","The source volume has less than 20% free space and may not have enough working space for a VSS snapshot.","NinjaOne","NinjaRMM","backup agent","RMM","VSS","Low Disk Space","Snapshot"],"errorCode":"Error 307","eventId":"","severity":"High","summary":"NinjaOne reports volume has less than 20 percent free space during image backup.","rootCause":"The source volume has less than 20% free space and may not have enough working space for a VSS snapshot.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Measure free and shadow-storage space, identify safe capacity recovery or expansion, and avoid deleting restore points or data without approval.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 307 - Volume Has Less Than 20 Percent Free Space.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: Image Backup.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","VSS","Low Disk Space","Snapshot"],"articleCategories":["NinjaOne","Image Backup","VSS","Low Disk Space","Snapshot"],"aliases":["NinjaOne Error 307","Volume Has Less Than 20 Percent Free Space"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62016,"title":"Error 308 - Unable to Determine Free Space","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","Image Backup","Volume","Free Space","Storage"],"keywords":["Error 308","Unable to Determine Free Space","Image Backup","The agent cannot query usable free space for the selected volume.","NinjaOne","NinjaRMM","backup agent","RMM","Volume","Free Space","Storage"],"errorCode":"Error 308","eventId":"","severity":"High","summary":"NinjaOne reports unable to determine free space during image backup.","rootCause":"The agent cannot query usable free space for the selected volume.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Verify volume online state, filesystem health, mount identity, permissions, storage provider, and operating-system disk queries before retrying.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 308 - Unable to Determine Free Space.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: Image Backup.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","Volume","Free Space","Storage"],"articleCategories":["NinjaOne","Image Backup","Volume","Free Space","Storage"],"aliases":["NinjaOne Error 308","Unable to Determine Free Space"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62017,"title":"Error 326 - Fast Delta Failed","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","Image Backup","Fast Delta","Incremental","Backup Chain"],"keywords":["Error 326","Fast Delta Failed","Image Backup","The optimized delta process could not calculate or transfer the expected changed blocks.","NinjaOne","NinjaRMM","backup agent","RMM","Fast Delta","Incremental","Backup Chain"],"errorCode":"Error 326","eventId":"","severity":"High","summary":"NinjaOne reports fast delta failed during image backup.","rootCause":"The optimized delta process could not calculate or transfer the expected changed blocks.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Preserve logs and chain state, verify source/repository integrity, storage and snapshot health, and allow NinjaOne's supported fallback or support-guided repair rather than deleting the chain.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 326 - Fast Delta Failed.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: Image Backup.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","Fast Delta","Incremental","Backup Chain"],"articleCategories":["NinjaOne","Image Backup","Fast Delta","Incremental","Backup Chain"],"aliases":["NinjaOne Error 326","Fast Delta Failed"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62018,"title":"Error 328 - VSS Writer Error","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","Image Backup","VSS","VSS Writer","Snapshot"],"keywords":["Error 328","VSS Writer Error","Image Backup","One or more Windows VSS writers is failed, unstable, or unable to participate in the snapshot.","NinjaOne","NinjaRMM","backup agent","RMM","VSS","VSS Writer","Snapshot"],"errorCode":"Error 328","eventId":"","severity":"Critical","summary":"NinjaOne reports vss writer error during image backup.","rootCause":"One or more Windows VSS writers is failed, unstable, or unable to participate in the snapshot.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Capture vssadmin writer/provider state and event logs, identify the owning application/service, and repair that writer using its vendor guidance before retrying.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 328 - VSS Writer Error.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: Image Backup.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","VSS","VSS Writer","Snapshot"],"articleCategories":["NinjaOne","Image Backup","VSS","VSS Writer","Snapshot"],"aliases":["NinjaOne Error 328","VSS Writer Error"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62019,"title":"Error 132 - VSS Error","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","Image Backup","VSS","Snapshot","Shadow Copy"],"keywords":["Error 132","VSS Error","Image Backup","Windows Volume Shadow Copy Service could not create or maintain the required snapshot.","NinjaOne","NinjaRMM","backup agent","RMM","VSS","Snapshot","Shadow Copy"],"errorCode":"Error 132","eventId":"","severity":"Critical","summary":"NinjaOne reports vss error during image backup.","rootCause":"Windows Volume Shadow Copy Service could not create or maintain the required snapshot.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Capture the exact VSS error, writers, providers, shadow storage and events; correct the failing provider, writer, capacity or service condition without blanket component resets.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 132 - VSS Error.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: Image Backup.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","VSS","Snapshot","Shadow Copy"],"articleCategories":["NinjaOne","Image Backup","VSS","Snapshot","Shadow Copy"],"aliases":["NinjaOne Error 132","VSS Error"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62020,"title":"Error 311 - INTEGRITY_CHECK_TOO_MANY_ERRORS_FAILED","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","Integrity Check","Integrity Check","Repository","Corruption"],"keywords":["Error 311","INTEGRITY_CHECK_TOO_MANY_ERRORS_FAILED","Integrity Check","The repository integrity check found more errors than it could safely tolerate or repair.","NinjaOne","NinjaRMM","backup agent","RMM","Integrity Check","Repository","Corruption"],"errorCode":"Error 311","eventId":"","severity":"Critical","summary":"NinjaOne reports integrity_check_too_many_errors_failed during integrity check.","rootCause":"The repository integrity check found more errors than it could safely tolerate or repair.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Stop treating the repository as verified, preserve all evidence and copies, assess storage health, and contact NinjaOne Support before modifying or removing repository data.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 311 - INTEGRITY_CHECK_TOO_MANY_ERRORS_FAILED.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: Integrity Check.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","Integrity Check","Repository","Corruption"],"articleCategories":["NinjaOne","Integrity Check","Integrity Check","Repository","Corruption"],"aliases":["NinjaOne Error 311","INTEGRITY_CHECK_TOO_MANY_ERRORS_FAILED"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62021,"title":"Error 312 - Existing Backup Repository Root Missing","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","Integrity Check","Repository","Missing Path","NAS"],"keywords":["Error 312","Existing Backup Repository Root Missing","Integrity Check","The configured root folder for an existing NinjaOne Backup repository cannot be found.","NinjaOne","NinjaRMM","backup agent","RMM","Repository","Missing Path","NAS"],"errorCode":"Error 312","eventId":"","severity":"Critical","summary":"NinjaOne reports existing backup repository root missing during integrity check.","rootCause":"The configured root folder for an existing NinjaOne Backup repository cannot be found.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Verify the exact mount/share/path and repository identity, restore destination availability, and do not create an empty replacement folder over a missing repository without support guidance.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 312 - Existing Backup Repository Root Missing.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: Integrity Check.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","Repository","Missing Path","NAS"],"articleCategories":["NinjaOne","Integrity Check","Repository","Missing Path","NAS"],"aliases":["NinjaOne Error 312","Existing Backup Repository Root Missing"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62022,"title":"Error 313 - File Not Found","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","Integrity Check","Integrity Check","File Missing","Repository"],"keywords":["Error 313","File Not Found","Integrity Check","A file expected by the repository integrity process is absent.","NinjaOne","NinjaRMM","backup agent","RMM","Integrity Check","File Missing","Repository"],"errorCode":"Error 313","eventId":"","severity":"Critical","summary":"NinjaOne reports file not found during integrity check.","rootCause":"A file expected by the repository integrity process is absent.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Confirm path, mount and repository completeness, check security/quarantine and storage events, and preserve remaining chain data for support-led recovery.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 313 - File Not Found.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: Integrity Check.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","Integrity Check","File Missing","Repository"],"articleCategories":["NinjaOne","Integrity Check","Integrity Check","File Missing","Repository"],"aliases":["NinjaOne Error 313","File Not Found"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62023,"title":"Error 314 - Inconsistent File","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","Integrity Check","Integrity Check","Inconsistent","Repository"],"keywords":["Error 314","Inconsistent File","Integrity Check","A repository file does not match the expected metadata or content state.","NinjaOne","NinjaRMM","backup agent","RMM","Integrity Check","Inconsistent","Repository"],"errorCode":"Error 314","eventId":"","severity":"Critical","summary":"NinjaOne reports inconsistent file during integrity check.","rootCause":"A repository file does not match the expected metadata or content state.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Preserve the inconsistent object and logs, verify storage hardware/filesystem and concurrent access, and use NinjaOne-supported integrity recovery rather than manual replacement.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 314 - Inconsistent File.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: Integrity Check.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","Integrity Check","Inconsistent","Repository"],"articleCategories":["NinjaOne","Integrity Check","Integrity Check","Inconsistent","Repository"],"aliases":["NinjaOne Error 314","Inconsistent File"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62024,"title":"Error 303 - NAS Path Not Set Up on Device","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","Pre-Flight Check"],"keywords":["Error 303","NAS Path Not Set Up on Device","Pre-Flight Check","The backup plan expects network storage but the endpoint has no usable NAS path configuration.","NinjaOne","NinjaRMM","backup agent","RMM"],"errorCode":"Error 303","eventId":"","severity":"High","summary":"NinjaOne reports nas path not set up on device during pre-flight check.","rootCause":"The backup plan expects network storage but the endpoint has no usable NAS path configuration.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Configure the intended UNC/network-storage path and approved credentials for the device, then validate reachability and write access before running the plan.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 303 - NAS Path Not Set Up on Device.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: Pre-Flight Check.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM"],"articleCategories":["NinjaOne","Pre-Flight Check"],"aliases":["NinjaOne Error 303","NAS Path Not Set Up on Device"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62025,"title":"Error 305 - Unable to Access Local Storage","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","Pre-Flight Check","Local Storage","Destination"],"keywords":["Error 305","Unable to Access Local Storage","Pre-Flight Check","The agent cannot reach or use the configured local backup destination.","NinjaOne","NinjaRMM","backup agent","RMM","Local Storage","Destination"],"errorCode":"Error 305","eventId":"","severity":"High","summary":"NinjaOne reports unable to access local storage during pre-flight check.","rootCause":"The agent cannot reach or use the configured local backup destination.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Verify disk/mount availability, path, permissions, free space, filesystem health, encryption and removable-media state.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 305 - Unable to Access Local Storage.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: Pre-Flight Check.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","Local Storage","Destination"],"articleCategories":["NinjaOne","Pre-Flight Check","Local Storage","Destination"],"aliases":["NinjaOne Error 305","Unable to Access Local Storage"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62026,"title":"Error 315 - Network Storage Credentials Failed","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","Pre-Flight Check","NAS","Authentication","Credentials"],"keywords":["Error 315","Network Storage Credentials Failed","Pre-Flight Check","Authentication to the network-storage device failed.","NinjaOne","NinjaRMM","backup agent","RMM","NAS","Authentication","Credentials"],"errorCode":"Error 315","eventId":"","severity":"High","summary":"NinjaOne reports network storage credentials failed during pre-flight check.","rootCause":"Authentication to the network-storage device failed.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Verify the intended credential, username format, account status, share authorization, SMB/NAS compatibility and time; update the stored secret through the approved NinjaOne workflow.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 315 - Network Storage Credentials Failed.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: Pre-Flight Check.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","NAS","Authentication","Credentials"],"articleCategories":["NinjaOne","Pre-Flight Check","NAS","Authentication","Credentials"],"aliases":["NinjaOne Error 315","Network Storage Credentials Failed"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62027,"title":"Error 316 - No Host Found","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","Pre-Flight Check","DNS","NAS","Host Not Found"],"keywords":["Error 316","No Host Found","Pre-Flight Check","The configured storage host cannot be resolved or reached.","NinjaOne","NinjaRMM","backup agent","RMM","DNS","NAS","Host Not Found"],"errorCode":"Error 316","eventId":"","severity":"High","summary":"NinjaOne reports no host found during pre-flight check.","rootCause":"The configured storage host cannot be resolved or reached.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Verify hostname spelling, DNS, suffix, IP routing, VPN, firewall and NAS availability from the protected endpoint.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 316 - No Host Found.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: Pre-Flight Check.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","DNS","NAS","Host Not Found"],"articleCategories":["NinjaOne","Pre-Flight Check","DNS","NAS","Host Not Found"],"aliases":["NinjaOne Error 316","No Host Found"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62028,"title":"Error 317 - Unable to Request Credentials","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","Pre-Flight Check"],"keywords":["Error 317","Unable to Request Credentials","Pre-Flight Check","The agent could not obtain the credentials required for the configured destination.","NinjaOne","NinjaRMM","backup agent","RMM"],"errorCode":"Error 317","eventId":"","severity":"High","summary":"NinjaOne reports unable to request credentials during pre-flight check.","rootCause":"The agent could not obtain the credentials required for the configured destination.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Check device/plan assignment, credential record availability, agent communication and authorization, then reselect an approved credential without exposing it.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 317 - Unable to Request Credentials.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: Pre-Flight Check.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM"],"articleCategories":["NinjaOne","Pre-Flight Check"],"aliases":["NinjaOne Error 317","Unable to Request Credentials"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62029,"title":"Error 318 - Not Defined","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","Pre-Flight Check","Undefined","Support Escalation"],"keywords":["Error 318","Not Defined","Pre-Flight Check","NinjaOne's public error index does not define a specific cause for Error 318.","NinjaOne","NinjaRMM","backup agent","RMM","Undefined","Support Escalation"],"errorCode":"Error 318","eventId":"","severity":"Unknown","summary":"NinjaOne reports not defined during pre-flight check.","rootCause":"NinjaOne's public error index does not define a specific cause for Error 318.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Collect the complete job, pre-flight and agent context and contact NinjaOne Support. Do not infer a fix solely from the numeric code.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 318 - Not Defined.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: Pre-Flight Check.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","Undefined","Support Escalation"],"articleCategories":["NinjaOne","Pre-Flight Check","Undefined","Support Escalation"],"aliases":["NinjaOne Error 318","Not Defined"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62030,"title":"Error 319 - NAS Timed Out","category":"NinjaOne","product":"NinjaOne Device Backup","tags":["NinjaOne","Pre-Flight Check","NAS","Timeout","Network Storage"],"keywords":["Error 319","NAS Timed Out","Pre-Flight Check","The network-storage destination did not respond within the allowed time.","NinjaOne","NinjaRMM","backup agent","RMM","NAS","Timeout","Network Storage"],"errorCode":"Error 319","eventId":"","severity":"High","summary":"NinjaOne reports nas timed out during pre-flight check.","rootCause":"The network-storage destination did not respond within the allowed time.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Measure DNS, routing, latency, loss, SMB/NAS service and storage load; correct the timeout source and validate a controlled read/write operation.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified Error 319 - NAS Timed Out.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: Pre-Flight Check.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["cross-platform"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","NAS","Timeout","Network Storage"],"articleCategories":["NinjaOne","Pre-Flight Check","NAS","Timeout","Network Storage"],"aliases":["NinjaOne Error 319","NAS Timed Out"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":62031,"title":"550 5.7.520 / AS(7555) - Access Denied - External Forwarding Disabled","category":"NinjaOne","product":"NinjaOne Ticketing","tags":["NinjaOne","NinjaOne Ticketing SMTP","Ticketing","SMTP","Exchange Online","External Forwarding"],"keywords":["550 5.7.520 / AS(7555)","Access Denied - External Forwarding Disabled","NinjaOne Ticketing SMTP","Exchange Online outbound-spam or mail-flow policy blocks automatic forwarding to the external NinjaOne Ticketing address.","NinjaOne","NinjaRMM","backup agent","RMM","Ticketing","SMTP","Exchange Online","External Forwarding"],"errorCode":"550 5.7.520 / AS(7555)","eventId":"","severity":"High","summary":"NinjaOne reports access denied - external forwarding disabled during ninjaone ticketing smtp.","rootCause":"Exchange Online outbound-spam or mail-flow policy blocks automatic forwarding to the external NinjaOne Ticketing address.","resolution":"1. Record the protected device, plan, destination, job ID, timestamp, complete message, agent version, and last successful run.\n2. Use a narrowly scoped Exchange Online outbound-spam policy or approved mail-flow design for the required sender/domain, review transport rules, and test without enabling external forwarding tenant-wide.\n3. Confirm source readability, destination availability, credentials, capacity, connectivity, exclusions, and relevant operating-system logs.\n4. Retry only after correcting the evidenced condition, then validate completion and perform an approved restore test.","emailScript":"Hello,\n\nWe reviewed the NinjaOne issue and identified 550 5.7.520 / AS(7555) - Access Denied - External Forwarding Disabled.\n\nWe are validating the protected data, backup destination, permissions, storage capacity, and connectivity before retrying the job.\n\nPlease keep the device powered on and connected while we complete testing.\n\nThank you,\n\nIT Support","faqSteps":"Please keep the device powered on and connected. Send IT Support the time of the failure and affected backup plan, but do not send passwords, recovery keys, repository credentials, private data, or screenshots containing secrets.","notes":"Source: NinjaOne Device Backup: Troubleshooting Error Codes, last updated June 3, 2026.\nGroup: NinjaOne Ticketing SMTP.\nVerified: 2026-08-10.\n\nA successful retry is not a restore test. Do not delete snapshots, repositories, backup roots, encryption keys, or destination data as a first response. Credential, permission, VSS, EFS, database, and NAS changes require backup/rollback planning and least privilege.","commands":[],"sourceDocument":"NinjaOne Device Backup: Troubleshooting Error Codes","sourceAuthority":"NinjaOne","namespace":"NINJAONE","platforms":["platform-neutral"],"lastVerified":"2026-08-10","vendors":["NinjaOne"],"technologies":["Backup","RMM","Ticketing","SMTP","Exchange Online","External Forwarding"],"articleCategories":["NinjaOne","NinjaOne Ticketing SMTP","Ticketing","SMTP","Exchange Online","External Forwarding"],"aliases":["NinjaOne 550 5.7.520 / AS(7555)","Access Denied - External Forwarding Disabled"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63000,"title":"80192EFE - Device Enrollment Service Communication Failure","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment","Connectivity","Device Registration"],"keywords":["80192EFE","80192EFE","Device Enrollment Service Communication Failure","Windows cannot complete work-or-school device authentication or reach the enrollment service. Likely factors include proxy, firewall, DNS or TLS inspection interference; stale or partial Entra/Intune registration; an old Windows build; enrollment restrictions; device limits; licensing; Hybrid Join; or Autopilot conflicts.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd","Connectivity","Device Registration"],"errorCode":"80192EFE","eventId":"","severity":"High","summary":"Microsoft Intune reports device enrollment service communication failure while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"Windows cannot complete work-or-school device authentication or reach the enrollment service. Likely factors include proxy, firewall, DNS or TLS inspection interference; stale or partial Entra/Intune registration; an old Windows build; enrollment restrictions; device limits; licensing; Hybrid Join; or Autopilot conflicts.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Test Microsoft sign-in and enrollment endpoints over TCP 443, fully update Windows, verify an eligible Intune license and MDM scope, inspect enrollment restrictions and device limits, then compare Entra, Intune, and Autopilot records. Treat stale-object removal or account disconnection as a controlled last step after ownership and recovery checks.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 80192EFE - Device Enrollment Service Communication Failure.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"User-supplied MSP workflow; Microsoft diagnostics","namespace":"INTUNE","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot","Connectivity","Device Registration"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 80192EFE","Device Enrollment Service Communication Failure"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63001,"title":"0x8007064C - Device Already Enrolled","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0x8007064C","8007064C","Device Already Enrolled","An existing MDM enrollment, artifact, or management record remains.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0x8007064C","eventId":"","severity":"High","summary":"Microsoft Intune reports device already enrolled while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"An existing MDM enrollment, artifact, or management record remains.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Identify the current authority and repair the intended enrollment or remove only a confirmed stale record through an approved re-enrollment plan.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x8007064C - Device Already Enrolled.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 0x8007064C","Device Already Enrolled"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63002,"title":"8018000A - User Tried to Enroll an Already Enrolled Device","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["8018000A","8018000A","User Tried to Enroll an Already Enrolled Device","The device is already enrolled under Intune or another MDM authority, or stale state remains.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"8018000A","eventId":"","severity":"High","summary":"Microsoft Intune reports user tried to enroll an already enrolled device while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"The device is already enrolled under Intune or another MDM authority, or stale state remains.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Compare local registration with Intune and Entra records, then retire only the verified stale enrollment.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 8018000A - User Tried to Enroll an Already Enrolled Device.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 8018000A","User Tried to Enroll an Already Enrolled Device"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63003,"title":"80180026 - Enrollment Blocked by Licensing or Management Conflict","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["80180026","80180026","Enrollment Blocked by Licensing or Management Conflict","The user lacks an eligible license or another management client or policy prevents MDM enrollment.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"80180026","eventId":"","severity":"High","summary":"Microsoft Intune reports enrollment blocked by licensing or management conflict while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"The user lacks an eligible license or another management client or policy prevents MDM enrollment.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Verify Intune entitlement, MDM user scope and authority; resolve any legacy Intune PC client or competing MDM enrollment.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 80180026 - Enrollment Blocked by Licensing or Management Conflict.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 80180026","Enrollment Blocked by Licensing or Management Conflict"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63004,"title":"0x80CF4017 - Legacy Intune PC Client Conflicts with MDM","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0x80CF4017","80CF4017","Legacy Intune PC Client Conflicts with MDM","The legacy Intune PC client prevents modern MDM enrollment.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0x80CF4017","eventId":"","severity":"High","summary":"Microsoft Intune reports legacy intune pc client conflicts with mdm while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"The legacy Intune PC client prevents modern MDM enrollment.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Confirm the intended management model and follow Microsoft's supported legacy-client retirement procedure.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x80CF4017 - Legacy Intune PC Client Conflicts with MDM.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 0x80CF4017","Legacy Intune PC Client Conflicts with MDM"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63006,"title":"0x80180002 - Device Management Server Authentication Failed","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0x80180002","80180002","Device Management Server Authentication Failed","The enrollment client cannot authenticate the user, device, tenant, or MDM request.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0x80180002","eventId":"","severity":"High","summary":"Microsoft Intune reports device management server authentication failed while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"The enrollment client cannot authenticate the user, device, tenant, or MDM request.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Validate sign-in, tenant discovery, time, tokens, Conditional Access, network path, and service health.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x80180002 - Device Management Server Authentication Failed.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 0x80180002","Device Management Server Authentication Failed"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63007,"title":"0x8018002B - Automatic MDM Enrollment Failed","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0x8018002B","8018002B","Automatic MDM Enrollment Failed","GPO auto-enrollment cannot complete because scope, credentials, registration, task, licensing, or connectivity is unhealthy.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0x8018002B","eventId":"","severity":"High","summary":"Microsoft Intune reports automatic mdm enrollment failed while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"GPO auto-enrollment cannot complete because scope, credentials, registration, task, licensing, or connectivity is unhealthy.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Verify Entra join, MDM scope, license, GPO targeting, EnterpriseMgmt scheduled tasks, events, and connectivity.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x8018002B - Automatic MDM Enrollment Failed.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 0x8018002B","Automatic MDM Enrollment Failed"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63009,"title":"0x80180022 - Windows Build or Edition Not Supported for Enrollment","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0x80180022","80180022","Windows Build or Edition Not Supported for Enrollment","The Windows version or edition does not support the requested operation.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0x80180022","eventId":"","severity":"High","summary":"Microsoft Intune reports windows build or edition not supported for enrollment while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"The Windows version or edition does not support the requested operation.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Confirm current platform requirements and install a supported update or edition.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x80180022 - Windows Build or Edition Not Supported for Enrollment.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 0x80180022","Windows Build or Edition Not Supported for Enrollment"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63011,"title":"0x80070774 - Autopilot Cannot Reach a Domain Controller","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0x80070774","80070774","Autopilot Cannot Reach a Domain Controller","Hybrid Entra join cannot locate or communicate with a domain controller.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0x80070774","eventId":"","severity":"High","summary":"Microsoft Intune reports autopilot cannot reach a domain controller while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"Hybrid Entra join cannot locate or communicate with a domain controller.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Verify VPN/corporate reachability, DNS SRV records, domain controllers, Offline Domain Join profile, and Intune Connector.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x80070774 - Autopilot Cannot Reach a Domain Controller.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 0x80070774","Autopilot Cannot Reach a Domain Controller"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63012,"title":"0x801C0003 - User Not Authorized to Enroll","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0x801C0003","801C0003","User Not Authorized to Enroll","The user is outside MDM scope, unlicensed, over quota, or blocked by restrictions.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0x801C0003","eventId":"","severity":"High","summary":"Microsoft Intune reports user not authorized to enroll while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"The user is outside MDM scope, unlicensed, over quota, or blocked by restrictions.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Verify user, license, MDM scope, Entra quota, Intune device limit, restrictions, and Conditional Access.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x801C0003 - User Not Authorized to Enroll.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 0x801C0003","User Not Authorized to Enroll"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63013,"title":"80180003 - User Not Authorized to Enroll Device","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["80180003","80180003","User Not Authorized to Enroll Device","Enrollment restrictions, limits, scope, licensing, or tenant policy denies enrollment.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"80180003","eventId":"","severity":"High","summary":"Microsoft Intune reports user not authorized to enroll device while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"Enrollment restrictions, limits, scope, licensing, or tenant policy denies enrollment.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Review the enrollment failure report and restriction priority; correct the narrowly identified condition.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 80180003 - User Not Authorized to Enroll Device.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 80180003","User Not Authorized to Enroll Device"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63014,"title":"0xCAA9001F - Co-managed Hybrid Device Token or Enrollment Failure","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0xCAA9001F","CAA9001F","Co-managed Hybrid Device Token or Enrollment Failure","A co-managed hybrid device cannot obtain or use the identity token required for enrollment.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0xCAA9001F","eventId":"","severity":"High","summary":"Microsoft Intune reports co-managed hybrid device token or enrollment failure while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"A co-managed hybrid device cannot obtain or use the identity token required for enrollment.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Inspect PRT/device state, WAM/AAD logs, co-management scope, MDM scope, scheduled task, and proxy context.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0xCAA9001F - Co-managed Hybrid Device Token or Enrollment Failure.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 0xCAA9001F","Co-managed Hybrid Device Token or Enrollment Failure"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63015,"title":"0xCAA2000C - Authentication Interaction Required","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0xCAA2000C","CAA2000C","Authentication Interaction Required","Cached identity state cannot satisfy sign-in and interactive consent, MFA, or Conditional Access is required.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0xCAA2000C","eventId":"","severity":"High","summary":"Microsoft Intune reports authentication interaction required while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"Cached identity state cannot satisfy sign-in and interactive consent, MFA, or Conditional Access is required.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Review Entra sign-in and WAM/AAD logs, confirm time/network, then complete the approved interactive requirement.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0xCAA2000C - Authentication Interaction Required.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 0xCAA2000C","Authentication Interaction Required"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63016,"title":"0x80180023 - Enrollment Response or Server Data Invalid","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0x80180023","80180023","Enrollment Response or Server Data Invalid","The client received an enrollment response it could not process.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0x80180023","eventId":"","severity":"High","summary":"Microsoft Intune reports enrollment response or server data invalid while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"The client received an enrollment response it could not process.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Capture events and correlation details; validate MDM URLs, tenant, proxy, certificate, and TLS handling.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x80180023 - Enrollment Response or Server Data Invalid.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 0x80180023","Enrollment Response or Server Data Invalid"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63017,"title":"0x800706D9 - No More Endpoints Available from Endpoint Mapper","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0x800706D9","800706D9","No More Endpoints Available from Endpoint Mapper","A Windows service or RPC/firewall dependency is stopped, disabled, or damaged.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0x800706D9","eventId":"","severity":"High","summary":"Microsoft Intune reports no more endpoints available from endpoint mapper while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"A Windows service or RPC/firewall dependency is stopped, disabled, or damaged.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Check service and System logs, firewall service, RPC dependencies, and policy; do not broadly disable the firewall.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x800706D9 - No More Endpoints Available from Endpoint Mapper.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 0x800706D9","No More Endpoints Available from Endpoint Mapper"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63018,"title":"0x801C03F2 - Device Object Not Found or Not Synchronized","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0x801C03F2","801C03F2","Device Object Not Found or Not Synchronized","The cloud service cannot find the expected device object, often during Hybrid Join sync.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0x801C03F2","eventId":"","severity":"High","summary":"Microsoft Intune reports device object not found or not synchronized while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"The cloud service cannot find the expected device object, often during Hybrid Join sync.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Verify the AD object, Entra Connect scope/sync, SCP, and registration events; confirm the cloud object.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x801C03F2 - Device Object Not Found or Not Synchronized.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 0x801C03F2","Device Object Not Found or Not Synchronized"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63019,"title":"0x80090016 - Keyset Does Not Exist","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0x80090016","80090016","Keyset Does Not Exist","TPM-backed or user authentication key material is missing or inconsistent with registration.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0x80090016","eventId":"","severity":"High","summary":"Microsoft Intune reports keyset does not exist while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"TPM-backed or user authentication key material is missing or inconsistent with registration.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Review TPM, Hello, AAD and registration events; confirm recovery escrow before key-container, TPM, or re-registration repair.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x80090016 - Keyset Does Not Exist.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 0x80090016","Keyset Does Not Exist"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63020,"title":"0x87D1FDF3 - MDM Certificate Registration Point Request Not Found","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0x87D1FDF3","87D1FDF3","MDM Certificate Registration Point Request Not Found","Intune cannot locate the certificate-registration request.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0x87D1FDF3","eventId":"","severity":"High","summary":"Microsoft Intune reports mdm certificate registration point request not found while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"Intune cannot locate the certificate-registration request.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Correlate Intune, connector and NDES logs; verify connector health, request identity, and profile assignment.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x87D1FDF3 - MDM Certificate Registration Point Request Not Found.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 0x87D1FDF3","MDM Certificate Registration Point Request Not Found"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63021,"title":"0x87D1FDF2 - NDES URL Not Found","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0x87D1FDF2","87D1FDF2","NDES URL Not Found","The certificate profile or connector cannot resolve a usable NDES URL.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0x87D1FDF2","eventId":"","severity":"High","summary":"Microsoft Intune reports ndes url not found while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"The certificate profile or connector cannot resolve a usable NDES URL.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Verify the SCEP URL, NDES service, connector, DNS, and HTTPS reachability.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x87D1FDF2 - NDES URL Not Found.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 0x87D1FDF2","NDES URL Not Found"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63022,"title":"0x87D1FDF1 - MDM Certificate Registration Certificate Information Not Found","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0x87D1FDF1","87D1FDF1","MDM Certificate Registration Certificate Information Not Found","Required certificate metadata is missing.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0x87D1FDF1","eventId":"","severity":"High","summary":"Microsoft Intune reports mdm certificate registration certificate information not found while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"Required certificate metadata is missing.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Inspect Certificate Connector and NDES logs, profile assignment, and certificate template configuration.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x87D1FDF1 - MDM Certificate Registration Certificate Information Not Found.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 0x87D1FDF1","MDM Certificate Registration Certificate Information Not Found"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63023,"title":"0x87D1FDF0 - Configuration Item Certificate Information Not Found","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0x87D1FDF0","87D1FDF0","Configuration Item Certificate Information Not Found","The configuration item lacks required certificate information.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0x87D1FDF0","eventId":"","severity":"High","summary":"Microsoft Intune reports configuration item certificate information not found while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"The configuration item lacks required certificate information.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Confirm the certificate profile and dependencies are valid, assigned, synchronized, and processed by the connector.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x87D1FDF0 - Configuration Item Certificate Information Not Found.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 0x87D1FDF0","Configuration Item Certificate Information Not Found"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63024,"title":"0x87D1FDEF - Failed to Evaluate the Rule","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0x87D1FDEF","87D1FDEF","Failed to Evaluate the Rule","The device could not evaluate an Intune configuration or compliance rule.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0x87D1FDEF","eventId":"","severity":"High","summary":"Microsoft Intune reports failed to evaluate the rule while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"The device could not evaluate an Intune configuration or compliance rule.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Identify the setting and CSP, confirm applicability and data type, and correct the rule or prerequisite.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x87D1FDEF - Failed to Evaluate the Rule.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 0x87D1FDEF","Failed to Evaluate the Rule"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63025,"title":"0x87D1FDEE - Setting Lost Conflict Resolution","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0x87D1FDEE","87D1FDEE","Setting Lost Conflict Resolution","Another applicable policy won conflict resolution.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0x87D1FDEE","eventId":"","severity":"High","summary":"Microsoft Intune reports setting lost conflict resolution while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"Another applicable policy won conflict resolution.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Use per-setting status and diagnostics to identify competing sources; consolidate or change assignment intentionally.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x87D1FDEE - Setting Lost Conflict Resolution.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 0x87D1FDEE","Setting Lost Conflict Resolution"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63026,"title":"0x87D1FDED - Unsupported Setting Discovery Source","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0x87D1FDED","87D1FDED","Unsupported Setting Discovery Source","The client does not support the discovery source used by the setting.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0x87D1FDED","eventId":"","severity":"High","summary":"Microsoft Intune reports unsupported setting discovery source while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"The client does not support the discovery source used by the setting.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Verify Windows/CSP support, policy type and management channel; replace or retarget the setting.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x87D1FDED - Unsupported Setting Discovery Source.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 0x87D1FDED","Unsupported Setting Discovery Source"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63027,"title":"0x87D1FDEC - Referenced Setting Not Found in Configuration Item","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0x87D1FDEC","87D1FDEC","Referenced Setting Not Found in Configuration Item","A policy rule refers to an absent setting.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0x87D1FDEC","eventId":"","severity":"High","summary":"Microsoft Intune reports referenced setting not found in configuration item while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"A policy rule refers to an absent setting.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Identify the malformed or stale profile and recreate it with a supported template or CSP.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x87D1FDEC - Referenced Setting Not Found in Configuration Item.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 0x87D1FDEC","Referenced Setting Not Found in Configuration Item"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63028,"title":"0x87D1FDEB - Setting Data Type Conversion Failed","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0x87D1FDEB","87D1FDEB","Setting Data Type Conversion Failed","The policy value cannot be converted to the required data type.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0x87D1FDEB","eventId":"","severity":"High","summary":"Microsoft Intune reports setting data type conversion failed while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"The policy value cannot be converted to the required data type.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Compare the configured value with the CSP schema and allowed format, correct it, and sync.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x87D1FDEB - Setting Data Type Conversion Failed.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 0x87D1FDEB","Setting Data Type Conversion Failed"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63029,"title":"0x87D1FDEA - Invalid Parameter to CIM Setting","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0x87D1FDEA","87D1FDEA","Invalid Parameter to CIM Setting","A policy supplied a parameter rejected by the target CIM setting.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0x87D1FDEA","eventId":"","severity":"High","summary":"Microsoft Intune reports invalid parameter to cim setting while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"A policy supplied a parameter rejected by the target CIM setting.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Validate allowed parameter names, values, and platform support, then correct the policy.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x87D1FDEA - Invalid Parameter to CIM Setting.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 0x87D1FDEA","Invalid Parameter to CIM Setting"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63030,"title":"0x87D1FDE9 - Setting Not Applicable to This Device","category":"Microsoft Intune","product":"Microsoft Intune / Microsoft Entra ID","tags":["Microsoft Intune","MDM","Windows Enrollment"],"keywords":["0x87D1FDE9","87D1FDE9","Setting Not Applicable to This Device","The setting does not apply to this platform, edition, version, ownership, mode, or prerequisites.","Intune","Microsoft Endpoint Manager","MEM","MDM","Company Portal","Entra ID","Azure AD","device enrollment","Access work or school","Autopilot","dsregcmd"],"errorCode":"0x87D1FDE9","eventId":"","severity":"Low","summary":"Microsoft Intune reports setting not applicable to this device while enrolling, registering, configuring, or evaluating a managed device.","rootCause":"The setting does not apply to this platform, edition, version, ownership, mode, or prerequisites.","resolution":"1. Record the complete error, enrollment method, user, device, tenant, Windows build, timestamp, and correlation ID when available.\n2. Run dsregcmd /status and review AzureAdJoined, DomainJoined, WorkplaceJoined, DeviceAuthStatus, AzureAdPrt, TenantId, and WamDefaultSet.\n3. Review DeviceManagement-Enterprise-Diagnostics-Provider/Admin events at the failure time.\n4. Confirm applicability and assignments; retarget or satisfy the prerequisite.\n5. Retry only after correcting the evidenced condition; confirm the device is healthy in Entra ID and Intune and receives an expected policy.","emailScript":"Hello,\n\nWe reviewed the device-enrollment issue and identified 0x87D1FDE9 - Setting Not Applicable to This Device.\n\nWe are checking device registration, Microsoft service connectivity, enrollment permissions, licensing, and existing management records before retrying enrollment.\n\nPlease keep the computer powered on and connected, and let us know before resetting or re-enrolling it.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to a stable network. Save your work, note the time the message appears, and send IT Support the complete error text. Do not disconnect the work account, reset Windows, or delete a device record unless IT has confirmed the recovery and re-enrollment plan.","notes":"Sources: Microsoft Learn Intune troubleshooting documentation and troubleshoot-mem-intune.pdf. Reviewed 2026-08-10.\n\nBefore disconnecting a work account or removing an Entra, Intune, or Autopilot object, confirm device ownership, authoritative record, BitLocker recovery-key escrow, local administrator access, Autopilot assignment, compliance/Conditional Access impact, and a tested re-enrollment path. Do not disable firewall, proxy, TLS inspection, or security policy broadly; use logs and approved scoped exceptions.","commands":[{"shell":"CMD","command":"dsregcmd /status","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection login.microsoftonline.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Test-NetConnection enrollment.manage.microsoft.com -Port 443","risk":"Low"},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber","risk":"Low"},{"shell":"CMD","command":"eventvwr.msc","risk":"Low"}],"sourceDocument":"troubleshoot-mem-intune.pdf; Microsoft Learn Intune troubleshooting","sourceAuthority":"Microsoft","namespace":"INTUNE","platforms":["windows"],"lastVerified":"2026-08-10","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Entra ID","Windows"],"technologies":["MDM","Microsoft Entra Join","Windows Autopilot"],"articleCategories":["Microsoft Intune","Windows Enrollment","Device Management"],"aliases":["Intune 0x87D1FDE9","Setting Not Applicable to This Device"],"dateAdded":"2026-08-10","lastUpdated":"2026-08-10"},{"id":63032,"title":"0x80070001 - Intune Win32 App Returned Incorrect Function","category":"Microsoft Intune","product":"Microsoft Intune Management Extension","tags":["Microsoft Intune","Win32 App","Intune Management Extension","IME","Windows Autopilot","Enrollment Status Page","Detection Rule","SYSTEM Context","ERROR_INVALID_FUNCTION"],"keywords":["0x80070001","80070001","ERROR_INVALID_FUNCTION","error 1","incorrect function","invalid function","Intune","Win32 app","IME","Intune Management Extension","Autopilot","ESP","app install failed","detection rule","install command","uninstall command","PowerShell quoting","command line arguments","SYSTEM context","PSADT","AppWorkload.log","AppActionProcessor.log","AgentExecutor.log"],"errorCode":"0x80070001","eventId":"","severity":"Medium","summary":"Intune surfaced HRESULT 0x80070001 while installing or detecting a Win32 application. The HRESULT wraps Windows ERROR_INVALID_FUNCTION (1, “Incorrect function”); it is a generic result, so the adjacent Intune Management Extension and installer logs are needed to identify the failed command, script, detection rule, or execution context.","rootCause":"Common causes include a misspelled or malformed installation command, incorrect quote escaping, an installer argument the executable does not support, a package that assumes the wrong working directory, or user-profile and mapped-drive dependencies that are unavailable when the app runs as SYSTEM. A file, registry, MSI, or custom-script detection rule can also report the wrong result because of an incorrect path, registry view, product code, architecture, output stream, or exit code. The numeric HRESULT alone does not prove which condition occurred.","resolution":"1. In Intune, record the app name and version, assignment intent, install behavior, failed device, timestamp, reported exit code, and whether the failure occurred during Autopilot ESP or a later deployment.\n2. Review AppWorkload.log for the app installation sequence and AppActionProcessor.log for applicability and detection. Use IntuneManagementExtension.log for check-in and policy-processing context; use AgentExecutor.log when PowerShell execution is involved.\n3. Compare the configured install and uninstall commands with the vendor's silent-install syntax. Correct spelling, quoting, switches, relative paths, and wrapper parameters.\n4. Reproduce the package in a controlled test device under the same User or SYSTEM context selected in Intune. Do not assume user-profile variables, HKCU, interactive prompts, or mapped drives exist in SYSTEM context.\n5. Test the detection rule independently. For a custom script, Intune requires exit code 0 and text on STDOUT to report the app as detected; nonzero exit, empty STDOUT, or any STDERR output is evaluated as not installed. Verify 32-bit versus 64-bit registry and script settings.\n6. Repackage the app if it depends on files outside the .intunewin content or an unspecified working directory. Upload the corrected package, sync the test device, and retry.\n7. Confirm the app reports Installed, the detection rule returns the intended result, and Autopilot ESP completes when applicable.","emailScript":"Hello,\n\nWe reviewed the application deployment issue. Windows returned a general “Incorrect function” result while Intune was installing or checking the application.\n\nWe are reviewing the application command, installation context, and detection settings, then we will retry the corrected deployment. Please keep the computer powered on and connected to the internet.\n\nThank you,\n\nIT Support","faqSteps":"Keep the computer powered on and connected to the internet. Note the application name and the approximate time the message appeared, then send that information to IT Support. Do not repeatedly reinstall the application or reset the computer unless IT asks you to do so.","notes":"0x80070001 is HRESULT_FROM_WIN32(ERROR_INVALID_FUNCTION); decimal Win32 error 1 means “Incorrect function.” It is not unique to Intune and should be correlated with the IME operation and the child installer's native exit details. Community-maintained code lists were used as discovery sources; Microsoft documentation controls the code meaning, IME log locations, and detection-script behavior. A reported PSADT wrapper typo is a useful example, not a universal diagnosis.\n\nPrimary sources: Microsoft Learn, Intune Management Extension for Windows; Troubleshoot Win32 App Issues; Add and Assign Win32 Apps to Microsoft Intune; Microsoft Windows error-code documentation. Discovery sources supplied 2026-08-21: tplant.com.au, blog.mindcore.dk, call4cloud.nl, scotscottmca.com, jackdjd.com, modernworkplaceguides.com, and jannikreinhard.com.","commands":[{"shell":"PowerShell","command":"Get-Service IntuneManagementExtension | Select-Object Status,Name,DisplayName","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-Content 'C:\\ProgramData\\Microsoft\\IntuneManagementExtension\\Logs\\AppWorkload.log' -Tail 200","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-Content 'C:\\ProgramData\\Microsoft\\IntuneManagementExtension\\Logs\\AppActionProcessor.log' -Tail 200","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-Content 'C:\\ProgramData\\Microsoft\\IntuneManagementExtension\\Logs\\IntuneManagementExtension.log' -Tail 200","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-Content 'C:\\ProgramData\\Microsoft\\IntuneManagementExtension\\Logs\\AgentExecutor.log' -Tail 200","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Learn Intune Management Extension and Win32 app documentation; community Intune code references","sourceAuthority":"Microsoft","namespace":"INTUNE-APP","platforms":["windows"],"lastVerified":"2026-08-21","vendors":["Microsoft"],"products":["Microsoft Intune","Microsoft Intune Management Extension","Windows"],"technologies":["Win32 App Management","Intune Management Extension","Windows Autopilot","PowerShell"],"articleCategories":["Microsoft Intune","Application Deployment","Windows Autopilot"],"aliases":["Intune 0x80070001","ERROR_INVALID_FUNCTION","Incorrect function","Win32 app error 1"],"dateAdded":"2026-08-21","lastUpdated":"2026-08-21"},{"id":68000,"title":"Exchange Audit Event 25000 - Undocumented Exchange mailbox operation","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25000","Exchange"],"keywords":["25000","event 25000","event id 25000","Undocumented Exchange mailbox operation","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25000"],"errorCode":"","eventId":"25000","severity":"Low","summary":"Exchange Audit event 25000 records: Undocumented Exchange mailbox operation","rootCause":"The configured audit source recorded this activity: Undocumented Exchange mailbox operation It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25000.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Undocumented Exchange mailbox operation\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25000\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25000} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25000","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25000","Event ID 25000","Undocumented Exchange mailbox operation"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68001,"title":"Exchange Audit Event 25001 - Operation Copy - Copy item to another Exchange mailbox folder","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25001","Exchange"],"keywords":["25001","event 25001","event id 25001","Operation Copy - Copy item to another Exchange mailbox folder","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25001"],"errorCode":"","eventId":"25001","severity":"Low","summary":"Exchange Audit event 25001 records: Operation Copy - Copy item to another Exchange mailbox folder","rootCause":"The configured audit source recorded this activity: Operation Copy - Copy item to another Exchange mailbox folder It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25001.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Operation Copy - Copy item to another Exchange mailbox folder\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25001\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25001} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25001","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25001","Event ID 25001","Operation Copy - Copy item to another Exchange mailbox folder"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68002,"title":"Exchange Audit Event 25002 - Operation Create - Create item in Exchange mailbox","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25002","Exchange"],"keywords":["25002","event 25002","event id 25002","Operation Create - Create item in Exchange mailbox","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25002"],"errorCode":"","eventId":"25002","severity":"Low","summary":"Exchange Audit event 25002 records: Operation Create - Create item in Exchange mailbox","rootCause":"The configured audit source recorded this activity: Operation Create - Create item in Exchange mailbox It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25002.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Operation Create - Create item in Exchange mailbox\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25002\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25002} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25002","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25002","Event ID 25002","Operation Create - Create item in Exchange mailbox"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68003,"title":"Exchange Audit Event 25003 - Operation FolderBind - Access Exchange mailbox folder","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25003","Exchange"],"keywords":["25003","event 25003","event id 25003","Operation FolderBind - Access Exchange mailbox folder","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25003"],"errorCode":"","eventId":"25003","severity":"Low","summary":"Exchange Audit event 25003 records: Operation FolderBind - Access Exchange mailbox folder","rootCause":"The configured audit source recorded this activity: Operation FolderBind - Access Exchange mailbox folder It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25003.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Operation FolderBind - Access Exchange mailbox folder\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25003\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25003} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25003","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25003","Event ID 25003","Operation FolderBind - Access Exchange mailbox folder"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68004,"title":"Exchange Audit Event 25004 - Operation HardDelete - Delete Exchange mailbox item permanently from Recoverable Items folder","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25004","Exchange"],"keywords":["25004","event 25004","event id 25004","Operation HardDelete - Delete Exchange mailbox item permanently from Recoverable Items folder","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25004"],"errorCode":"","eventId":"25004","severity":"Low","summary":"Exchange Audit event 25004 records: Operation HardDelete - Delete Exchange mailbox item permanently from Recoverable Items folder","rootCause":"The configured audit source recorded this activity: Operation HardDelete - Delete Exchange mailbox item permanently from Recoverable Items folder It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25004.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Operation HardDelete - Delete Exchange mailbox item permanently from Recoverable Items folder\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25004\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25004} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25004","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25004","Event ID 25004","Operation HardDelete - Delete Exchange mailbox item permanently from Recoverable Items folder"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68005,"title":"Exchange Audit Event 25005 - Operation MessageBind - Access Exchange mailbox item","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25005","Exchange"],"keywords":["25005","event 25005","event id 25005","Operation MessageBind - Access Exchange mailbox item","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25005"],"errorCode":"","eventId":"25005","severity":"Low","summary":"Exchange Audit event 25005 records: Operation MessageBind - Access Exchange mailbox item","rootCause":"The configured audit source recorded this activity: Operation MessageBind - Access Exchange mailbox item It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25005.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Operation MessageBind - Access Exchange mailbox item\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25005\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25005} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25005","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25005","Event ID 25005","Operation MessageBind - Access Exchange mailbox item"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68006,"title":"Exchange Audit Event 25006 - Operation Move - Move item to another Exchange mailbox folder","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25006","Exchange"],"keywords":["25006","event 25006","event id 25006","Operation Move - Move item to another Exchange mailbox folder","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25006"],"errorCode":"","eventId":"25006","severity":"Low","summary":"Exchange Audit event 25006 records: Operation Move - Move item to another Exchange mailbox folder","rootCause":"The configured audit source recorded this activity: Operation Move - Move item to another Exchange mailbox folder It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25006.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Operation Move - Move item to another Exchange mailbox folder\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25006\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25006} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25006","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25006","Event ID 25006","Operation Move - Move item to another Exchange mailbox folder"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68007,"title":"Exchange Audit Event 25007 - Operation MoveToDeletedItems - Move Exchange mailbox item to Deleted Items folder","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25007","Exchange"],"keywords":["25007","event 25007","event id 25007","Operation MoveToDeletedItems - Move Exchange mailbox item to Deleted Items folder","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25007"],"errorCode":"","eventId":"25007","severity":"High","summary":"Exchange Audit event 25007 records: Operation MoveToDeletedItems - Move Exchange mailbox item to Deleted Items folder","rootCause":"The event records a state-changing operation: Operation MoveToDeletedItems - Move Exchange mailbox item to Deleted Items folder It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25007.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Operation MoveToDeletedItems - Move Exchange mailbox item to Deleted Items folder\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25007\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25007} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25007","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25007","Event ID 25007","Operation MoveToDeletedItems - Move Exchange mailbox item to Deleted Items folder"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68008,"title":"Exchange Audit Event 25008 - Operation SendAs - Send message using Send As Exchange mailbox permissions","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25008","Exchange"],"keywords":["25008","event 25008","event id 25008","Operation SendAs - Send message using Send As Exchange mailbox permissions","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25008"],"errorCode":"","eventId":"25008","severity":"Medium","summary":"Exchange Audit event 25008 records: Operation SendAs - Send message using Send As Exchange mailbox permissions","rootCause":"The configured audit source recorded this activity: Operation SendAs - Send message using Send As Exchange mailbox permissions It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25008.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Operation SendAs - Send message using Send As Exchange mailbox permissions\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25008\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25008} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25008","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25008","Event ID 25008","Operation SendAs - Send message using Send As Exchange mailbox permissions"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68009,"title":"Exchange Audit Event 25009 - Operation SendOnBehalf - Send message using Send on Behalf Exchange mailbox permissions","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25009","Exchange"],"keywords":["25009","event 25009","event id 25009","Operation SendOnBehalf - Send message using Send on Behalf Exchange mailbox permissions","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25009"],"errorCode":"","eventId":"25009","severity":"Medium","summary":"Exchange Audit event 25009 records: Operation SendOnBehalf - Send message using Send on Behalf Exchange mailbox permissions","rootCause":"The configured audit source recorded this activity: Operation SendOnBehalf - Send message using Send on Behalf Exchange mailbox permissions It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25009.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Operation SendOnBehalf - Send message using Send on Behalf Exchange mailbox permissions\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25009\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25009} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25009","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25009","Event ID 25009","Operation SendOnBehalf - Send message using Send on Behalf Exchange mailbox permissions"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68010,"title":"Exchange Audit Event 25010 - Operation SoftDelete - Delete Exchange mailbox item from Deleted Items folder","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25010","Exchange"],"keywords":["25010","event 25010","event id 25010","Operation SoftDelete - Delete Exchange mailbox item from Deleted Items folder","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25010"],"errorCode":"","eventId":"25010","severity":"High","summary":"Exchange Audit event 25010 records: Operation SoftDelete - Delete Exchange mailbox item from Deleted Items folder","rootCause":"The event records a state-changing operation: Operation SoftDelete - Delete Exchange mailbox item from Deleted Items folder It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25010.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Operation SoftDelete - Delete Exchange mailbox item from Deleted Items folder\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25010\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25010} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25010","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25010","Event ID 25010","Operation SoftDelete - Delete Exchange mailbox item from Deleted Items folder"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68011,"title":"Exchange Audit Event 25011 - Operation Update - Update Exchange mailbox item's properties","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25011","Exchange"],"keywords":["25011","event 25011","event id 25011","Operation Update - Update Exchange mailbox item's properties","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25011"],"errorCode":"","eventId":"25011","severity":"Low","summary":"Exchange Audit event 25011 records: Operation Update - Update Exchange mailbox item's properties","rootCause":"The configured audit source recorded this activity: Operation Update - Update Exchange mailbox item's properties It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25011.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Operation Update - Update Exchange mailbox item's properties\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25011\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25011} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25011","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25011","Event ID 25011","Operation Update - Update Exchange mailbox item's properties"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68012,"title":"Exchange Audit Event 25100 - Information Event - Mailbox audit policy applied / Undocumented Exchange admin operation","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25100","Exchange"],"keywords":["25100","event 25100","event id 25100","Information Event - Mailbox audit policy applied / Undocumented Exchange admin operation","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25100"],"errorCode":"","eventId":"25100","severity":"Medium","summary":"Exchange Audit event 25100 records: Information Event - Mailbox audit policy applied / Undocumented Exchange admin operation","rootCause":"The configured audit source recorded this activity: Information Event - Mailbox audit policy applied / Undocumented Exchange admin operation It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25100.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Information Event - Mailbox audit policy applied / Undocumented Exchange admin operation\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25100\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25100} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25100","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25100","Event ID 25100","Information Event - Mailbox audit policy applied / Undocumented Exchange admin operation"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68013,"title":"Exchange Audit Event 25101 - Add-ADPermission Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25101","Exchange"],"keywords":["25101","event 25101","event id 25101","Add-ADPermission Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25101"],"errorCode":"","eventId":"25101","severity":"Medium","summary":"Exchange Audit event 25101 records: Add-ADPermission Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Add-ADPermission Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25101.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add-ADPermission Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25101\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25101} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25101","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25101","Event ID 25101","Add-ADPermission Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68014,"title":"Exchange Audit Event 25102 - Add-AvailabilityAddressSpace Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25102","Exchange"],"keywords":["25102","event 25102","event id 25102","Add-AvailabilityAddressSpace Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25102"],"errorCode":"","eventId":"25102","severity":"Low","summary":"Exchange Audit event 25102 records: Add-AvailabilityAddressSpace Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Add-AvailabilityAddressSpace Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25102.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add-AvailabilityAddressSpace Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25102\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25102} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25102","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25102","Event ID 25102","Add-AvailabilityAddressSpace Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68015,"title":"Exchange Audit Event 25103 - Add-ContentFilterPhrase Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25103","Exchange"],"keywords":["25103","event 25103","event id 25103","Add-ContentFilterPhrase Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25103"],"errorCode":"","eventId":"25103","severity":"Low","summary":"Exchange Audit event 25103 records: Add-ContentFilterPhrase Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Add-ContentFilterPhrase Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25103.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add-ContentFilterPhrase Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25103\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25103} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25103","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25103","Event ID 25103","Add-ContentFilterPhrase Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68016,"title":"Exchange Audit Event 25104 - Add-DatabaseAvailabilityGroupServer Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25104","Exchange"],"keywords":["25104","event 25104","event id 25104","Add-DatabaseAvailabilityGroupServer Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25104"],"errorCode":"","eventId":"25104","severity":"Medium","summary":"Exchange Audit event 25104 records: Add-DatabaseAvailabilityGroupServer Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Add-DatabaseAvailabilityGroupServer Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25104.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add-DatabaseAvailabilityGroupServer Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25104\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25104} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25104","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25104","Event ID 25104","Add-DatabaseAvailabilityGroupServer Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68017,"title":"Exchange Audit Event 25105 - Add-DistributionGroupMember Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25105","Exchange"],"keywords":["25105","event 25105","event id 25105","Add-DistributionGroupMember Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25105"],"errorCode":"","eventId":"25105","severity":"Medium","summary":"Exchange Audit event 25105 records: Add-DistributionGroupMember Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Add-DistributionGroupMember Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25105.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add-DistributionGroupMember Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25105\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25105} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25105","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25105","Event ID 25105","Add-DistributionGroupMember Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68018,"title":"Exchange Audit Event 25106 - Add-FederatedDomain Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25106","Exchange"],"keywords":["25106","event 25106","event id 25106","Add-FederatedDomain Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25106"],"errorCode":"","eventId":"25106","severity":"Low","summary":"Exchange Audit event 25106 records: Add-FederatedDomain Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Add-FederatedDomain Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25106.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add-FederatedDomain Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25106\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25106} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25106","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25106","Event ID 25106","Add-FederatedDomain Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68019,"title":"Exchange Audit Event 25107 - Add-IPAllowListEntry Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25107","Exchange"],"keywords":["25107","event 25107","event id 25107","Add-IPAllowListEntry Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25107"],"errorCode":"","eventId":"25107","severity":"Low","summary":"Exchange Audit event 25107 records: Add-IPAllowListEntry Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Add-IPAllowListEntry Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25107.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add-IPAllowListEntry Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25107\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25107} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25107","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25107","Event ID 25107","Add-IPAllowListEntry Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68020,"title":"Exchange Audit Event 25108 - Add-IPAllowListProvider Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25108","Exchange"],"keywords":["25108","event 25108","event id 25108","Add-IPAllowListProvider Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25108"],"errorCode":"","eventId":"25108","severity":"Low","summary":"Exchange Audit event 25108 records: Add-IPAllowListProvider Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Add-IPAllowListProvider Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25108.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add-IPAllowListProvider Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25108\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25108} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25108","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25108","Event ID 25108","Add-IPAllowListProvider Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68021,"title":"Exchange Audit Event 25109 - Add-IPBlockListEntry Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25109","Exchange"],"keywords":["25109","event 25109","event id 25109","Add-IPBlockListEntry Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25109"],"errorCode":"","eventId":"25109","severity":"Low","summary":"Exchange Audit event 25109 records: Add-IPBlockListEntry Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Add-IPBlockListEntry Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25109.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add-IPBlockListEntry Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25109\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25109} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25109","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25109","Event ID 25109","Add-IPBlockListEntry Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68022,"title":"Exchange Audit Event 25110 - Add-IPBlockListProvider Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25110","Exchange"],"keywords":["25110","event 25110","event id 25110","Add-IPBlockListProvider Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25110"],"errorCode":"","eventId":"25110","severity":"Low","summary":"Exchange Audit event 25110 records: Add-IPBlockListProvider Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Add-IPBlockListProvider Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25110.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add-IPBlockListProvider Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25110\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25110} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25110","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25110","Event ID 25110","Add-IPBlockListProvider Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68023,"title":"Exchange Audit Event 25111 - Add-MailboxDatabaseCopy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25111","Exchange"],"keywords":["25111","event 25111","event id 25111","Add-MailboxDatabaseCopy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25111"],"errorCode":"","eventId":"25111","severity":"Low","summary":"Exchange Audit event 25111 records: Add-MailboxDatabaseCopy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Add-MailboxDatabaseCopy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25111.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add-MailboxDatabaseCopy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25111\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25111} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25111","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25111","Event ID 25111","Add-MailboxDatabaseCopy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68024,"title":"Exchange Audit Event 25112 - Add-MailboxFolderPermission Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25112","Exchange"],"keywords":["25112","event 25112","event id 25112","Add-MailboxFolderPermission Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25112"],"errorCode":"","eventId":"25112","severity":"Medium","summary":"Exchange Audit event 25112 records: Add-MailboxFolderPermission Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Add-MailboxFolderPermission Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25112.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add-MailboxFolderPermission Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25112\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25112} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25112","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25112","Event ID 25112","Add-MailboxFolderPermission Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68025,"title":"Exchange Audit Event 25113 - Add-MailboxPermission Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25113","Exchange"],"keywords":["25113","event 25113","event id 25113","Add-MailboxPermission Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25113"],"errorCode":"","eventId":"25113","severity":"Medium","summary":"Exchange Audit event 25113 records: Add-MailboxPermission Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Add-MailboxPermission Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25113.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add-MailboxPermission Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25113\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25113} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25113","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25113","Event ID 25113","Add-MailboxPermission Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68026,"title":"Exchange Audit Event 25114 - Add-ManagementRoleEntry Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25114","Exchange"],"keywords":["25114","event 25114","event id 25114","Add-ManagementRoleEntry Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25114"],"errorCode":"","eventId":"25114","severity":"Medium","summary":"Exchange Audit event 25114 records: Add-ManagementRoleEntry Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Add-ManagementRoleEntry Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25114.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add-ManagementRoleEntry Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25114\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25114} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25114","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25114","Event ID 25114","Add-ManagementRoleEntry Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68027,"title":"Exchange Audit Event 25115 - Add-PublicFolderAdministrativePermission Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25115","Exchange"],"keywords":["25115","event 25115","event id 25115","Add-PublicFolderAdministrativePermission Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25115"],"errorCode":"","eventId":"25115","severity":"Medium","summary":"Exchange Audit event 25115 records: Add-PublicFolderAdministrativePermission Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Add-PublicFolderAdministrativePermission Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25115.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add-PublicFolderAdministrativePermission Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25115\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25115} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25115","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25115","Event ID 25115","Add-PublicFolderAdministrativePermission Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68028,"title":"Exchange Audit Event 25116 - Add-PublicFolderClientPermission Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25116","Exchange"],"keywords":["25116","event 25116","event id 25116","Add-PublicFolderClientPermission Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25116"],"errorCode":"","eventId":"25116","severity":"Medium","summary":"Exchange Audit event 25116 records: Add-PublicFolderClientPermission Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Add-PublicFolderClientPermission Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25116.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add-PublicFolderClientPermission Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25116\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25116} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25116","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25116","Event ID 25116","Add-PublicFolderClientPermission Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68029,"title":"Exchange Audit Event 25117 - Add-RoleGroupMember Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25117","Exchange"],"keywords":["25117","event 25117","event id 25117","Add-RoleGroupMember Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25117"],"errorCode":"","eventId":"25117","severity":"Medium","summary":"Exchange Audit event 25117 records: Add-RoleGroupMember Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Add-RoleGroupMember Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25117.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add-RoleGroupMember Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25117\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25117} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25117","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25117","Event ID 25117","Add-RoleGroupMember Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68030,"title":"Exchange Audit Event 25118 - Clean-MailboxDatabase Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25118","Exchange"],"keywords":["25118","event 25118","event id 25118","Clean-MailboxDatabase Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25118"],"errorCode":"","eventId":"25118","severity":"Low","summary":"Exchange Audit event 25118 records: Clean-MailboxDatabase Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Clean-MailboxDatabase Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25118.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Clean-MailboxDatabase Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25118\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25118} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25118","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25118","Event ID 25118","Clean-MailboxDatabase Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68031,"title":"Exchange Audit Event 25119 - Clear-ActiveSyncDevice Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25119","Exchange"],"keywords":["25119","event 25119","event id 25119","Clear-ActiveSyncDevice Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25119"],"errorCode":"","eventId":"25119","severity":"Low","summary":"Exchange Audit event 25119 records: Clear-ActiveSyncDevice Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Clear-ActiveSyncDevice Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25119.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Clear-ActiveSyncDevice Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25119\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25119} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25119","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25119","Event ID 25119","Clear-ActiveSyncDevice Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68032,"title":"Exchange Audit Event 25120 - Clear-TextMessagingAccount Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25120","Exchange"],"keywords":["25120","event 25120","event id 25120","Clear-TextMessagingAccount Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25120"],"errorCode":"","eventId":"25120","severity":"Low","summary":"Exchange Audit event 25120 records: Clear-TextMessagingAccount Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Clear-TextMessagingAccount Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25120.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Clear-TextMessagingAccount Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25120\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25120} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25120","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25120","Event ID 25120","Clear-TextMessagingAccount Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68033,"title":"Exchange Audit Event 25121 - Compare-TextMessagingVerificationCode Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25121","Exchange"],"keywords":["25121","event 25121","event id 25121","Compare-TextMessagingVerificationCode Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25121"],"errorCode":"","eventId":"25121","severity":"Low","summary":"Exchange Audit event 25121 records: Compare-TextMessagingVerificationCode Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Compare-TextMessagingVerificationCode Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25121.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Compare-TextMessagingVerificationCode Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25121\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25121} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25121","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25121","Event ID 25121","Compare-TextMessagingVerificationCode Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68034,"title":"Exchange Audit Event 25122 - Connect-Mailbox Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25122","Exchange"],"keywords":["25122","event 25122","event id 25122","Connect-Mailbox Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25122"],"errorCode":"","eventId":"25122","severity":"Low","summary":"Exchange Audit event 25122 records: Connect-Mailbox Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Connect-Mailbox Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25122.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Connect-Mailbox Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25122\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25122} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25122","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25122","Event ID 25122","Connect-Mailbox Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68035,"title":"Exchange Audit Event 25123 - Disable-AddressListPaging Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25123","Exchange"],"keywords":["25123","event 25123","event id 25123","Disable-AddressListPaging Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25123"],"errorCode":"","eventId":"25123","severity":"Low","summary":"Exchange Audit event 25123 records: Disable-AddressListPaging Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Disable-AddressListPaging Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25123.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Disable-AddressListPaging Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25123\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25123} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25123","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25123","Event ID 25123","Disable-AddressListPaging Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68036,"title":"Exchange Audit Event 25124 - Disable-CmdletExtensionAgent Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25124","Exchange"],"keywords":["25124","event 25124","event id 25124","Disable-CmdletExtensionAgent Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25124"],"errorCode":"","eventId":"25124","severity":"Low","summary":"Exchange Audit event 25124 records: Disable-CmdletExtensionAgent Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Disable-CmdletExtensionAgent Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25124.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Disable-CmdletExtensionAgent Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25124\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25124} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25124","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25124","Event ID 25124","Disable-CmdletExtensionAgent Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68037,"title":"Exchange Audit Event 25125 - Disable-DistributionGroup Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25125","Exchange"],"keywords":["25125","event 25125","event id 25125","Disable-DistributionGroup Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25125"],"errorCode":"","eventId":"25125","severity":"Medium","summary":"Exchange Audit event 25125 records: Disable-DistributionGroup Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Disable-DistributionGroup Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25125.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Disable-DistributionGroup Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25125\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25125} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25125","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25125","Event ID 25125","Disable-DistributionGroup Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68038,"title":"Exchange Audit Event 25126 - Disable-InboxRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25126","Exchange"],"keywords":["25126","event 25126","event id 25126","Disable-InboxRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25126"],"errorCode":"","eventId":"25126","severity":"Low","summary":"Exchange Audit event 25126 records: Disable-InboxRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Disable-InboxRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25126.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Disable-InboxRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25126\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25126} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25126","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25126","Event ID 25126","Disable-InboxRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68039,"title":"Exchange Audit Event 25127 - Disable-JournalRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25127","Exchange"],"keywords":["25127","event 25127","event id 25127","Disable-JournalRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25127"],"errorCode":"","eventId":"25127","severity":"Low","summary":"Exchange Audit event 25127 records: Disable-JournalRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Disable-JournalRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25127.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Disable-JournalRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25127\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25127} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25127","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25127","Event ID 25127","Disable-JournalRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68040,"title":"Exchange Audit Event 25128 - Disable-Mailbox Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25128","Exchange"],"keywords":["25128","event 25128","event id 25128","Disable-Mailbox Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25128"],"errorCode":"","eventId":"25128","severity":"Low","summary":"Exchange Audit event 25128 records: Disable-Mailbox Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Disable-Mailbox Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25128.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Disable-Mailbox Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25128\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25128} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25128","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25128","Event ID 25128","Disable-Mailbox Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68041,"title":"Exchange Audit Event 25129 - Disable-MailContact Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25129","Exchange"],"keywords":["25129","event 25129","event id 25129","Disable-MailContact Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25129"],"errorCode":"","eventId":"25129","severity":"Low","summary":"Exchange Audit event 25129 records: Disable-MailContact Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Disable-MailContact Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25129.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Disable-MailContact Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25129\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25129} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25129","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25129","Event ID 25129","Disable-MailContact Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68042,"title":"Exchange Audit Event 25130 - Disable-MailPublicFolder Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25130","Exchange"],"keywords":["25130","event 25130","event id 25130","Disable-MailPublicFolder Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25130"],"errorCode":"","eventId":"25130","severity":"Low","summary":"Exchange Audit event 25130 records: Disable-MailPublicFolder Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Disable-MailPublicFolder Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25130.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Disable-MailPublicFolder Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25130\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25130} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25130","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25130","Event ID 25130","Disable-MailPublicFolder Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68043,"title":"Exchange Audit Event 25131 - Disable-MailUser Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25131","Exchange"],"keywords":["25131","event 25131","event id 25131","Disable-MailUser Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25131"],"errorCode":"","eventId":"25131","severity":"Low","summary":"Exchange Audit event 25131 records: Disable-MailUser Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Disable-MailUser Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25131.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Disable-MailUser Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25131\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25131} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25131","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25131","Event ID 25131","Disable-MailUser Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68044,"title":"Exchange Audit Event 25132 - Disable-OutlookAnywhere Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25132","Exchange"],"keywords":["25132","event 25132","event id 25132","Disable-OutlookAnywhere Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25132"],"errorCode":"","eventId":"25132","severity":"Low","summary":"Exchange Audit event 25132 records: Disable-OutlookAnywhere Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Disable-OutlookAnywhere Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25132.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Disable-OutlookAnywhere Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25132\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25132} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25132","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25132","Event ID 25132","Disable-OutlookAnywhere Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68045,"title":"Exchange Audit Event 25133 - Disable-OutlookProtectionRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25133","Exchange"],"keywords":["25133","event 25133","event id 25133","Disable-OutlookProtectionRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25133"],"errorCode":"","eventId":"25133","severity":"Low","summary":"Exchange Audit event 25133 records: Disable-OutlookProtectionRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Disable-OutlookProtectionRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25133.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Disable-OutlookProtectionRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25133\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25133} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25133","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25133","Event ID 25133","Disable-OutlookProtectionRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68046,"title":"Exchange Audit Event 25134 - Disable-RemoteMailbox Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25134","Exchange"],"keywords":["25134","event 25134","event id 25134","Disable-RemoteMailbox Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25134"],"errorCode":"","eventId":"25134","severity":"Low","summary":"Exchange Audit event 25134 records: Disable-RemoteMailbox Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Disable-RemoteMailbox Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25134.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Disable-RemoteMailbox Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25134\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25134} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25134","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25134","Event ID 25134","Disable-RemoteMailbox Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68047,"title":"Exchange Audit Event 25135 - Disable-ServiceEmailChannel Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25135","Exchange"],"keywords":["25135","event 25135","event id 25135","Disable-ServiceEmailChannel Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25135"],"errorCode":"","eventId":"25135","severity":"Low","summary":"Exchange Audit event 25135 records: Disable-ServiceEmailChannel Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Disable-ServiceEmailChannel Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25135.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Disable-ServiceEmailChannel Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25135\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25135} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25135","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25135","Event ID 25135","Disable-ServiceEmailChannel Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68048,"title":"Exchange Audit Event 25136 - Disable-TransportAgent Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25136","Exchange"],"keywords":["25136","event 25136","event id 25136","Disable-TransportAgent Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25136"],"errorCode":"","eventId":"25136","severity":"Low","summary":"Exchange Audit event 25136 records: Disable-TransportAgent Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Disable-TransportAgent Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25136.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Disable-TransportAgent Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25136\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25136} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25136","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25136","Event ID 25136","Disable-TransportAgent Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68049,"title":"Exchange Audit Event 25137 - Disable-TransportRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25137","Exchange"],"keywords":["25137","event 25137","event id 25137","Disable-TransportRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25137"],"errorCode":"","eventId":"25137","severity":"Low","summary":"Exchange Audit event 25137 records: Disable-TransportRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Disable-TransportRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25137.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Disable-TransportRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25137\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25137} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25137","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25137","Event ID 25137","Disable-TransportRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68050,"title":"Exchange Audit Event 25138 - Disable-UMAutoAttendant Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25138","Exchange"],"keywords":["25138","event 25138","event id 25138","Disable-UMAutoAttendant Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25138"],"errorCode":"","eventId":"25138","severity":"Low","summary":"Exchange Audit event 25138 records: Disable-UMAutoAttendant Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Disable-UMAutoAttendant Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25138.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Disable-UMAutoAttendant Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25138\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25138} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25138","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25138","Event ID 25138","Disable-UMAutoAttendant Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68051,"title":"Exchange Audit Event 25139 - Disable-UMIPGateway Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25139","Exchange"],"keywords":["25139","event 25139","event id 25139","Disable-UMIPGateway Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25139"],"errorCode":"","eventId":"25139","severity":"Low","summary":"Exchange Audit event 25139 records: Disable-UMIPGateway Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Disable-UMIPGateway Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25139.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Disable-UMIPGateway Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25139\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25139} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25139","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25139","Event ID 25139","Disable-UMIPGateway Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68052,"title":"Exchange Audit Event 25140 - Disable-UMMailbox Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25140","Exchange"],"keywords":["25140","event 25140","event id 25140","Disable-UMMailbox Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25140"],"errorCode":"","eventId":"25140","severity":"Low","summary":"Exchange Audit event 25140 records: Disable-UMMailbox Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Disable-UMMailbox Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25140.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Disable-UMMailbox Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25140\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25140} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25140","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25140","Event ID 25140","Disable-UMMailbox Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68053,"title":"Exchange Audit Event 25141 - Disable-UMServer Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25141","Exchange"],"keywords":["25141","event 25141","event id 25141","Disable-UMServer Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25141"],"errorCode":"","eventId":"25141","severity":"Low","summary":"Exchange Audit event 25141 records: Disable-UMServer Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Disable-UMServer Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25141.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Disable-UMServer Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25141\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25141} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25141","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25141","Event ID 25141","Disable-UMServer Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68054,"title":"Exchange Audit Event 25142 - Dismount-Database Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25142","Exchange"],"keywords":["25142","event 25142","event id 25142","Dismount-Database Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25142"],"errorCode":"","eventId":"25142","severity":"Low","summary":"Exchange Audit event 25142 records: Dismount-Database Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Dismount-Database Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25142.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Dismount-Database Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25142\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25142} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25142","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25142","Event ID 25142","Dismount-Database Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68055,"title":"Exchange Audit Event 25143 - Enable-AddressListPaging Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25143","Exchange"],"keywords":["25143","event 25143","event id 25143","Enable-AddressListPaging Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25143"],"errorCode":"","eventId":"25143","severity":"Low","summary":"Exchange Audit event 25143 records: Enable-AddressListPaging Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-AddressListPaging Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25143.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-AddressListPaging Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25143\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25143} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25143","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25143","Event ID 25143","Enable-AddressListPaging Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68056,"title":"Exchange Audit Event 25144 - Enable-AntispamUpdates Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25144","Exchange"],"keywords":["25144","event 25144","event id 25144","Enable-AntispamUpdates Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25144"],"errorCode":"","eventId":"25144","severity":"Low","summary":"Exchange Audit event 25144 records: Enable-AntispamUpdates Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-AntispamUpdates Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25144.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-AntispamUpdates Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25144\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25144} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25144","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25144","Event ID 25144","Enable-AntispamUpdates Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68057,"title":"Exchange Audit Event 25145 - Enable-CmdletExtensionAgent Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25145","Exchange"],"keywords":["25145","event 25145","event id 25145","Enable-CmdletExtensionAgent Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25145"],"errorCode":"","eventId":"25145","severity":"Low","summary":"Exchange Audit event 25145 records: Enable-CmdletExtensionAgent Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-CmdletExtensionAgent Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25145.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-CmdletExtensionAgent Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25145\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25145} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25145","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25145","Event ID 25145","Enable-CmdletExtensionAgent Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68058,"title":"Exchange Audit Event 25146 - Enable-DistributionGroup Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25146","Exchange"],"keywords":["25146","event 25146","event id 25146","Enable-DistributionGroup Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25146"],"errorCode":"","eventId":"25146","severity":"Medium","summary":"Exchange Audit event 25146 records: Enable-DistributionGroup Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-DistributionGroup Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25146.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-DistributionGroup Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25146\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25146} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25146","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25146","Event ID 25146","Enable-DistributionGroup Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68059,"title":"Exchange Audit Event 25147 - Enable-ExchangeCertificate Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25147","Exchange"],"keywords":["25147","event 25147","event id 25147","Enable-ExchangeCertificate Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25147"],"errorCode":"","eventId":"25147","severity":"Medium","summary":"Exchange Audit event 25147 records: Enable-ExchangeCertificate Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-ExchangeCertificate Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25147.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-ExchangeCertificate Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25147\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25147} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25147","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25147","Event ID 25147","Enable-ExchangeCertificate Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68060,"title":"Exchange Audit Event 25148 - Enable-InboxRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25148","Exchange"],"keywords":["25148","event 25148","event id 25148","Enable-InboxRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25148"],"errorCode":"","eventId":"25148","severity":"Low","summary":"Exchange Audit event 25148 records: Enable-InboxRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-InboxRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25148.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-InboxRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25148\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25148} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25148","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25148","Event ID 25148","Enable-InboxRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68061,"title":"Exchange Audit Event 25149 - Enable-JournalRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25149","Exchange"],"keywords":["25149","event 25149","event id 25149","Enable-JournalRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25149"],"errorCode":"","eventId":"25149","severity":"Low","summary":"Exchange Audit event 25149 records: Enable-JournalRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-JournalRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25149.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-JournalRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25149\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25149} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25149","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25149","Event ID 25149","Enable-JournalRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68062,"title":"Exchange Audit Event 25150 - Enable-Mailbox Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25150","Exchange"],"keywords":["25150","event 25150","event id 25150","Enable-Mailbox Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25150"],"errorCode":"","eventId":"25150","severity":"Low","summary":"Exchange Audit event 25150 records: Enable-Mailbox Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-Mailbox Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25150.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-Mailbox Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25150\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25150} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25150","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25150","Event ID 25150","Enable-Mailbox Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68063,"title":"Exchange Audit Event 25151 - Enable-MailContact Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25151","Exchange"],"keywords":["25151","event 25151","event id 25151","Enable-MailContact Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25151"],"errorCode":"","eventId":"25151","severity":"Low","summary":"Exchange Audit event 25151 records: Enable-MailContact Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-MailContact Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25151.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-MailContact Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25151\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25151} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25151","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25151","Event ID 25151","Enable-MailContact Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68064,"title":"Exchange Audit Event 25152 - Enable-MailPublicFolder Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25152","Exchange"],"keywords":["25152","event 25152","event id 25152","Enable-MailPublicFolder Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25152"],"errorCode":"","eventId":"25152","severity":"Low","summary":"Exchange Audit event 25152 records: Enable-MailPublicFolder Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-MailPublicFolder Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25152.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-MailPublicFolder Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25152\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25152} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25152","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25152","Event ID 25152","Enable-MailPublicFolder Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68065,"title":"Exchange Audit Event 25153 - Enable-MailUser Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25153","Exchange"],"keywords":["25153","event 25153","event id 25153","Enable-MailUser Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25153"],"errorCode":"","eventId":"25153","severity":"Low","summary":"Exchange Audit event 25153 records: Enable-MailUser Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-MailUser Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25153.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-MailUser Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25153\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25153} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25153","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25153","Event ID 25153","Enable-MailUser Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68066,"title":"Exchange Audit Event 25154 - Enable-OutlookAnywhere Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25154","Exchange"],"keywords":["25154","event 25154","event id 25154","Enable-OutlookAnywhere Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25154"],"errorCode":"","eventId":"25154","severity":"Low","summary":"Exchange Audit event 25154 records: Enable-OutlookAnywhere Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-OutlookAnywhere Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25154.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-OutlookAnywhere Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25154\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25154} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25154","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25154","Event ID 25154","Enable-OutlookAnywhere Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68067,"title":"Exchange Audit Event 25155 - Enable-OutlookProtectionRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25155","Exchange"],"keywords":["25155","event 25155","event id 25155","Enable-OutlookProtectionRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25155"],"errorCode":"","eventId":"25155","severity":"Low","summary":"Exchange Audit event 25155 records: Enable-OutlookProtectionRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-OutlookProtectionRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25155.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-OutlookProtectionRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25155\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25155} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25155","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25155","Event ID 25155","Enable-OutlookProtectionRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68068,"title":"Exchange Audit Event 25156 - Enable-RemoteMailbox Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25156","Exchange"],"keywords":["25156","event 25156","event id 25156","Enable-RemoteMailbox Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25156"],"errorCode":"","eventId":"25156","severity":"Low","summary":"Exchange Audit event 25156 records: Enable-RemoteMailbox Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-RemoteMailbox Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25156.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-RemoteMailbox Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25156\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25156} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25156","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25156","Event ID 25156","Enable-RemoteMailbox Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68069,"title":"Exchange Audit Event 25157 - Enable-ServiceEmailChannel Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25157","Exchange"],"keywords":["25157","event 25157","event id 25157","Enable-ServiceEmailChannel Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25157"],"errorCode":"","eventId":"25157","severity":"Low","summary":"Exchange Audit event 25157 records: Enable-ServiceEmailChannel Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-ServiceEmailChannel Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25157.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-ServiceEmailChannel Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25157\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25157} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25157","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25157","Event ID 25157","Enable-ServiceEmailChannel Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68070,"title":"Exchange Audit Event 25158 - Enable-TransportAgent Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25158","Exchange"],"keywords":["25158","event 25158","event id 25158","Enable-TransportAgent Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25158"],"errorCode":"","eventId":"25158","severity":"Low","summary":"Exchange Audit event 25158 records: Enable-TransportAgent Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-TransportAgent Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25158.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-TransportAgent Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25158\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25158} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25158","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25158","Event ID 25158","Enable-TransportAgent Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68071,"title":"Exchange Audit Event 25159 - Enable-TransportRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25159","Exchange"],"keywords":["25159","event 25159","event id 25159","Enable-TransportRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25159"],"errorCode":"","eventId":"25159","severity":"Low","summary":"Exchange Audit event 25159 records: Enable-TransportRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-TransportRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25159.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-TransportRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25159\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25159} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25159","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25159","Event ID 25159","Enable-TransportRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68072,"title":"Exchange Audit Event 25160 - Enable-UMAutoAttendant Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25160","Exchange"],"keywords":["25160","event 25160","event id 25160","Enable-UMAutoAttendant Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25160"],"errorCode":"","eventId":"25160","severity":"Low","summary":"Exchange Audit event 25160 records: Enable-UMAutoAttendant Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-UMAutoAttendant Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25160.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-UMAutoAttendant Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25160\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25160} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25160","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25160","Event ID 25160","Enable-UMAutoAttendant Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68073,"title":"Exchange Audit Event 25161 - Enable-UMIPGateway Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25161","Exchange"],"keywords":["25161","event 25161","event id 25161","Enable-UMIPGateway Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25161"],"errorCode":"","eventId":"25161","severity":"Low","summary":"Exchange Audit event 25161 records: Enable-UMIPGateway Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-UMIPGateway Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25161.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-UMIPGateway Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25161\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25161} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25161","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25161","Event ID 25161","Enable-UMIPGateway Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68074,"title":"Exchange Audit Event 25162 - Enable-UMMailbox Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25162","Exchange"],"keywords":["25162","event 25162","event id 25162","Enable-UMMailbox Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25162"],"errorCode":"","eventId":"25162","severity":"Low","summary":"Exchange Audit event 25162 records: Enable-UMMailbox Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-UMMailbox Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25162.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-UMMailbox Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25162\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25162} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25162","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25162","Event ID 25162","Enable-UMMailbox Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68075,"title":"Exchange Audit Event 25163 - Enable-UMServer Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25163","Exchange"],"keywords":["25163","event 25163","event id 25163","Enable-UMServer Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25163"],"errorCode":"","eventId":"25163","severity":"Low","summary":"Exchange Audit event 25163 records: Enable-UMServer Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-UMServer Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25163.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-UMServer Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25163\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25163} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25163","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25163","Event ID 25163","Enable-UMServer Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68076,"title":"Exchange Audit Event 25164 - Export-ActiveSyncLog Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25164","Exchange"],"keywords":["25164","event 25164","event id 25164","Export-ActiveSyncLog Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25164"],"errorCode":"","eventId":"25164","severity":"Low","summary":"Exchange Audit event 25164 records: Export-ActiveSyncLog Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Export-ActiveSyncLog Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25164.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Export-ActiveSyncLog Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25164\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25164} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25164","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25164","Event ID 25164","Export-ActiveSyncLog Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68077,"title":"Exchange Audit Event 25165 - Export-AutoDiscoverConfig Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25165","Exchange"],"keywords":["25165","event 25165","event id 25165","Export-AutoDiscoverConfig Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25165"],"errorCode":"","eventId":"25165","severity":"Low","summary":"Exchange Audit event 25165 records: Export-AutoDiscoverConfig Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Export-AutoDiscoverConfig Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25165.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Export-AutoDiscoverConfig Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25165\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25165} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25165","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25165","Event ID 25165","Export-AutoDiscoverConfig Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68078,"title":"Exchange Audit Event 25166 - Export-ExchangeCertificate Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25166","Exchange"],"keywords":["25166","event 25166","event id 25166","Export-ExchangeCertificate Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25166"],"errorCode":"","eventId":"25166","severity":"Medium","summary":"Exchange Audit event 25166 records: Export-ExchangeCertificate Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Export-ExchangeCertificate Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25166.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Export-ExchangeCertificate Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25166\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25166} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25166","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25166","Event ID 25166","Export-ExchangeCertificate Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68079,"title":"Exchange Audit Event 25167 - Export-JournalRuleCollection Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25167","Exchange"],"keywords":["25167","event 25167","event id 25167","Export-JournalRuleCollection Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25167"],"errorCode":"","eventId":"25167","severity":"Low","summary":"Exchange Audit event 25167 records: Export-JournalRuleCollection Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Export-JournalRuleCollection Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25167.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Export-JournalRuleCollection Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25167\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25167} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25167","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25167","Event ID 25167","Export-JournalRuleCollection Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68080,"title":"Exchange Audit Event 25168 - Export-MailboxDiagnosticLogs Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25168","Exchange"],"keywords":["25168","event 25168","event id 25168","Export-MailboxDiagnosticLogs Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25168"],"errorCode":"","eventId":"25168","severity":"Low","summary":"Exchange Audit event 25168 records: Export-MailboxDiagnosticLogs Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Export-MailboxDiagnosticLogs Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25168.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Export-MailboxDiagnosticLogs Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25168\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25168} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25168","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25168","Event ID 25168","Export-MailboxDiagnosticLogs Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68081,"title":"Exchange Audit Event 25169 - Export-Message Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25169","Exchange"],"keywords":["25169","event 25169","event id 25169","Export-Message Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25169"],"errorCode":"","eventId":"25169","severity":"Low","summary":"Exchange Audit event 25169 records: Export-Message Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Export-Message Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25169.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Export-Message Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25169\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25169} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25169","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25169","Event ID 25169","Export-Message Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68082,"title":"Exchange Audit Event 25170 - Export-RecipientDataProperty Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25170","Exchange"],"keywords":["25170","event 25170","event id 25170","Export-RecipientDataProperty Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25170"],"errorCode":"","eventId":"25170","severity":"Low","summary":"Exchange Audit event 25170 records: Export-RecipientDataProperty Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Export-RecipientDataProperty Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25170.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Export-RecipientDataProperty Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25170\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25170} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25170","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25170","Event ID 25170","Export-RecipientDataProperty Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68083,"title":"Exchange Audit Event 25171 - Export-TransportRuleCollection Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25171","Exchange"],"keywords":["25171","event 25171","event id 25171","Export-TransportRuleCollection Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25171"],"errorCode":"","eventId":"25171","severity":"Low","summary":"Exchange Audit event 25171 records: Export-TransportRuleCollection Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Export-TransportRuleCollection Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25171.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Export-TransportRuleCollection Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25171\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25171} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25171","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25171","Event ID 25171","Export-TransportRuleCollection Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68084,"title":"Exchange Audit Event 25172 - Export-UMCallDataRecord Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25172","Exchange"],"keywords":["25172","event 25172","event id 25172","Export-UMCallDataRecord Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25172"],"errorCode":"","eventId":"25172","severity":"Low","summary":"Exchange Audit event 25172 records: Export-UMCallDataRecord Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Export-UMCallDataRecord Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25172.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Export-UMCallDataRecord Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25172\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25172} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25172","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25172","Event ID 25172","Export-UMCallDataRecord Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68085,"title":"Exchange Audit Event 25173 - Export-UMPrompt Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25173","Exchange"],"keywords":["25173","event 25173","event id 25173","Export-UMPrompt Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25173"],"errorCode":"","eventId":"25173","severity":"Low","summary":"Exchange Audit event 25173 records: Export-UMPrompt Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Export-UMPrompt Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25173.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Export-UMPrompt Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25173\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25173} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25173","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25173","Event ID 25173","Export-UMPrompt Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68086,"title":"Exchange Audit Event 25174 - Import-ExchangeCertificate Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25174","Exchange"],"keywords":["25174","event 25174","event id 25174","Import-ExchangeCertificate Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25174"],"errorCode":"","eventId":"25174","severity":"Medium","summary":"Exchange Audit event 25174 records: Import-ExchangeCertificate Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Import-ExchangeCertificate Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25174.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Import-ExchangeCertificate Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25174\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25174} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25174","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25174","Event ID 25174","Import-ExchangeCertificate Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68087,"title":"Exchange Audit Event 25175 - Import-JournalRuleCollection Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25175","Exchange"],"keywords":["25175","event 25175","event id 25175","Import-JournalRuleCollection Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25175"],"errorCode":"","eventId":"25175","severity":"Low","summary":"Exchange Audit event 25175 records: Import-JournalRuleCollection Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Import-JournalRuleCollection Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25175.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Import-JournalRuleCollection Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25175\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25175} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25175","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25175","Event ID 25175","Import-JournalRuleCollection Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68088,"title":"Exchange Audit Event 25176 - Import-RecipientDataProperty Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25176","Exchange"],"keywords":["25176","event 25176","event id 25176","Import-RecipientDataProperty Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25176"],"errorCode":"","eventId":"25176","severity":"Low","summary":"Exchange Audit event 25176 records: Import-RecipientDataProperty Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Import-RecipientDataProperty Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25176.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Import-RecipientDataProperty Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25176\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25176} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25176","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25176","Event ID 25176","Import-RecipientDataProperty Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68089,"title":"Exchange Audit Event 25177 - Import-TransportRuleCollection Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25177","Exchange"],"keywords":["25177","event 25177","event id 25177","Import-TransportRuleCollection Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25177"],"errorCode":"","eventId":"25177","severity":"Low","summary":"Exchange Audit event 25177 records: Import-TransportRuleCollection Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Import-TransportRuleCollection Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25177.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Import-TransportRuleCollection Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25177\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25177} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25177","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25177","Event ID 25177","Import-TransportRuleCollection Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68090,"title":"Exchange Audit Event 25178 - Import-UMPrompt Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25178","Exchange"],"keywords":["25178","event 25178","event id 25178","Import-UMPrompt Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25178"],"errorCode":"","eventId":"25178","severity":"Low","summary":"Exchange Audit event 25178 records: Import-UMPrompt Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Import-UMPrompt Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25178.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Import-UMPrompt Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25178\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25178} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25178","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25178","Event ID 25178","Import-UMPrompt Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68091,"title":"Exchange Audit Event 25179 - Install-TransportAgent Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25179","Exchange"],"keywords":["25179","event 25179","event id 25179","Install-TransportAgent Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25179"],"errorCode":"","eventId":"25179","severity":"Low","summary":"Exchange Audit event 25179 records: Install-TransportAgent Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Install-TransportAgent Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25179.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Install-TransportAgent Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25179\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25179} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25179","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25179","Event ID 25179","Install-TransportAgent Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68092,"title":"Exchange Audit Event 25180 - Mount-Database Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25180","Exchange"],"keywords":["25180","event 25180","event id 25180","Mount-Database Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25180"],"errorCode":"","eventId":"25180","severity":"Low","summary":"Exchange Audit event 25180 records: Mount-Database Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Mount-Database Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25180.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Mount-Database Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25180\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25180} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25180","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25180","Event ID 25180","Mount-Database Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68093,"title":"Exchange Audit Event 25181 - Move-ActiveMailboxDatabase Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25181","Exchange"],"keywords":["25181","event 25181","event id 25181","Move-ActiveMailboxDatabase Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25181"],"errorCode":"","eventId":"25181","severity":"Low","summary":"Exchange Audit event 25181 records: Move-ActiveMailboxDatabase Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Move-ActiveMailboxDatabase Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25181.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Move-ActiveMailboxDatabase Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25181\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25181} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25181","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25181","Event ID 25181","Move-ActiveMailboxDatabase Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68094,"title":"Exchange Audit Event 25182 - Move-AddressList Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25182","Exchange"],"keywords":["25182","event 25182","event id 25182","Move-AddressList Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25182"],"errorCode":"","eventId":"25182","severity":"Low","summary":"Exchange Audit event 25182 records: Move-AddressList Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Move-AddressList Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25182.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Move-AddressList Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25182\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25182} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25182","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25182","Event ID 25182","Move-AddressList Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68095,"title":"Exchange Audit Event 25183 - Move-DatabasePath Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25183","Exchange"],"keywords":["25183","event 25183","event id 25183","Move-DatabasePath Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25183"],"errorCode":"","eventId":"25183","severity":"Low","summary":"Exchange Audit event 25183 records: Move-DatabasePath Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Move-DatabasePath Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25183.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Move-DatabasePath Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25183\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25183} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25183","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25183","Event ID 25183","Move-DatabasePath Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68096,"title":"Exchange Audit Event 25184 - Move-OfflineAddressBook Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25184","Exchange"],"keywords":["25184","event 25184","event id 25184","Move-OfflineAddressBook Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25184"],"errorCode":"","eventId":"25184","severity":"Low","summary":"Exchange Audit event 25184 records: Move-OfflineAddressBook Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Move-OfflineAddressBook Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25184.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Move-OfflineAddressBook Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25184\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25184} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25184","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25184","Event ID 25184","Move-OfflineAddressBook Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68097,"title":"Exchange Audit Event 25185 - New-AcceptedDomain Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25185","Exchange"],"keywords":["25185","event 25185","event id 25185","New-AcceptedDomain Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25185"],"errorCode":"","eventId":"25185","severity":"Low","summary":"Exchange Audit event 25185 records: New-AcceptedDomain Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-AcceptedDomain Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25185.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-AcceptedDomain Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25185\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25185} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25185","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25185","Event ID 25185","New-AcceptedDomain Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68098,"title":"Exchange Audit Event 25186 - New-ActiveSyncDeviceAccessRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25186","Exchange"],"keywords":["25186","event 25186","event id 25186","New-ActiveSyncDeviceAccessRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25186"],"errorCode":"","eventId":"25186","severity":"Low","summary":"Exchange Audit event 25186 records: New-ActiveSyncDeviceAccessRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-ActiveSyncDeviceAccessRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25186.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-ActiveSyncDeviceAccessRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25186\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25186} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25186","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25186","Event ID 25186","New-ActiveSyncDeviceAccessRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68099,"title":"Exchange Audit Event 25187 - New-ActiveSyncMailboxPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25187","Exchange"],"keywords":["25187","event 25187","event id 25187","New-ActiveSyncMailboxPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25187"],"errorCode":"","eventId":"25187","severity":"Medium","summary":"Exchange Audit event 25187 records: New-ActiveSyncMailboxPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-ActiveSyncMailboxPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25187.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-ActiveSyncMailboxPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25187\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25187} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25187","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25187","Event ID 25187","New-ActiveSyncMailboxPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68100,"title":"Exchange Audit Event 25188 - New-ActiveSyncVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25188","Exchange"],"keywords":["25188","event 25188","event id 25188","New-ActiveSyncVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25188"],"errorCode":"","eventId":"25188","severity":"Low","summary":"Exchange Audit event 25188 records: New-ActiveSyncVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-ActiveSyncVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25188.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-ActiveSyncVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25188\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25188} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25188","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25188","Event ID 25188","New-ActiveSyncVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68101,"title":"Exchange Audit Event 25189 - New-AddressList Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25189","Exchange"],"keywords":["25189","event 25189","event id 25189","New-AddressList Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25189"],"errorCode":"","eventId":"25189","severity":"Low","summary":"Exchange Audit event 25189 records: New-AddressList Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-AddressList Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25189.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-AddressList Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25189\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25189} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25189","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25189","Event ID 25189","New-AddressList Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68102,"title":"Exchange Audit Event 25190 - New-AdminAuditLogSearch Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25190","Exchange"],"keywords":["25190","event 25190","event id 25190","New-AdminAuditLogSearch Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25190"],"errorCode":"","eventId":"25190","severity":"Low","summary":"Exchange Audit event 25190 records: New-AdminAuditLogSearch Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-AdminAuditLogSearch Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25190.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-AdminAuditLogSearch Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25190\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25190} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25190","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25190","Event ID 25190","New-AdminAuditLogSearch Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68103,"title":"Exchange Audit Event 25191 - New-AutodiscoverVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25191","Exchange"],"keywords":["25191","event 25191","event id 25191","New-AutodiscoverVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25191"],"errorCode":"","eventId":"25191","severity":"Low","summary":"Exchange Audit event 25191 records: New-AutodiscoverVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-AutodiscoverVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25191.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-AutodiscoverVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25191\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25191} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25191","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25191","Event ID 25191","New-AutodiscoverVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68104,"title":"Exchange Audit Event 25192 - New-AvailabilityReportOutage Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25192","Exchange"],"keywords":["25192","event 25192","event id 25192","New-AvailabilityReportOutage Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25192"],"errorCode":"","eventId":"25192","severity":"Low","summary":"Exchange Audit event 25192 records: New-AvailabilityReportOutage Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-AvailabilityReportOutage Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25192.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-AvailabilityReportOutage Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25192\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25192} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25192","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25192","Event ID 25192","New-AvailabilityReportOutage Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68105,"title":"Exchange Audit Event 25193 - New-ClientAccessArray Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25193","Exchange"],"keywords":["25193","event 25193","event id 25193","New-ClientAccessArray Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25193"],"errorCode":"","eventId":"25193","severity":"Low","summary":"Exchange Audit event 25193 records: New-ClientAccessArray Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-ClientAccessArray Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25193.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-ClientAccessArray Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25193\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25193} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25193","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25193","Event ID 25193","New-ClientAccessArray Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68106,"title":"Exchange Audit Event 25194 - New-DatabaseAvailabilityGroup Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25194","Exchange"],"keywords":["25194","event 25194","event id 25194","New-DatabaseAvailabilityGroup Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25194"],"errorCode":"","eventId":"25194","severity":"Medium","summary":"Exchange Audit event 25194 records: New-DatabaseAvailabilityGroup Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-DatabaseAvailabilityGroup Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25194.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-DatabaseAvailabilityGroup Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25194\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25194} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25194","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25194","Event ID 25194","New-DatabaseAvailabilityGroup Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68107,"title":"Exchange Audit Event 25195 - New-DatabaseAvailabilityGroupNetwork Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25195","Exchange"],"keywords":["25195","event 25195","event id 25195","New-DatabaseAvailabilityGroupNetwork Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25195"],"errorCode":"","eventId":"25195","severity":"Medium","summary":"Exchange Audit event 25195 records: New-DatabaseAvailabilityGroupNetwork Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-DatabaseAvailabilityGroupNetwork Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25195.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-DatabaseAvailabilityGroupNetwork Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25195\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25195} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25195","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25195","Event ID 25195","New-DatabaseAvailabilityGroupNetwork Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68108,"title":"Exchange Audit Event 25196 - New-DeliveryAgentConnector Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25196","Exchange"],"keywords":["25196","event 25196","event id 25196","New-DeliveryAgentConnector Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25196"],"errorCode":"","eventId":"25196","severity":"Low","summary":"Exchange Audit event 25196 records: New-DeliveryAgentConnector Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-DeliveryAgentConnector Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25196.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-DeliveryAgentConnector Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25196\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25196} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25196","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25196","Event ID 25196","New-DeliveryAgentConnector Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68109,"title":"Exchange Audit Event 25197 - New-DistributionGroup Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25197","Exchange"],"keywords":["25197","event 25197","event id 25197","New-DistributionGroup Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25197"],"errorCode":"","eventId":"25197","severity":"Medium","summary":"Exchange Audit event 25197 records: New-DistributionGroup Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-DistributionGroup Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25197.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-DistributionGroup Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25197\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25197} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25197","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25197","Event ID 25197","New-DistributionGroup Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68110,"title":"Exchange Audit Event 25198 - New-DynamicDistributionGroup Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25198","Exchange"],"keywords":["25198","event 25198","event id 25198","New-DynamicDistributionGroup Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25198"],"errorCode":"","eventId":"25198","severity":"Medium","summary":"Exchange Audit event 25198 records: New-DynamicDistributionGroup Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-DynamicDistributionGroup Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25198.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-DynamicDistributionGroup Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25198\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25198} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25198","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25198","Event ID 25198","New-DynamicDistributionGroup Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68111,"title":"Exchange Audit Event 25199 - New-EcpVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25199","Exchange"],"keywords":["25199","event 25199","event id 25199","New-EcpVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25199"],"errorCode":"","eventId":"25199","severity":"Low","summary":"Exchange Audit event 25199 records: New-EcpVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-EcpVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25199.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-EcpVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25199\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25199} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25199","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25199","Event ID 25199","New-EcpVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68112,"title":"Exchange Audit Event 25200 - New-EdgeSubscription Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25200","Exchange"],"keywords":["25200","event 25200","event id 25200","New-EdgeSubscription Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25200"],"errorCode":"","eventId":"25200","severity":"Low","summary":"Exchange Audit event 25200 records: New-EdgeSubscription Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-EdgeSubscription Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25200.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-EdgeSubscription Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25200\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25200} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25200","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25200","Event ID 25200","New-EdgeSubscription Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68113,"title":"Exchange Audit Event 25201 - New-EdgeSyncServiceConfig Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25201","Exchange"],"keywords":["25201","event 25201","event id 25201","New-EdgeSyncServiceConfig Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25201"],"errorCode":"","eventId":"25201","severity":"Low","summary":"Exchange Audit event 25201 records: New-EdgeSyncServiceConfig Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-EdgeSyncServiceConfig Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25201.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-EdgeSyncServiceConfig Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25201\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25201} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25201","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25201","Event ID 25201","New-EdgeSyncServiceConfig Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68114,"title":"Exchange Audit Event 25202 - New-EmailAddressPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25202","Exchange"],"keywords":["25202","event 25202","event id 25202","New-EmailAddressPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25202"],"errorCode":"","eventId":"25202","severity":"Medium","summary":"Exchange Audit event 25202 records: New-EmailAddressPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-EmailAddressPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25202.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-EmailAddressPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25202\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25202} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25202","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25202","Event ID 25202","New-EmailAddressPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68115,"title":"Exchange Audit Event 25203 - New-ExchangeCertificate Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25203","Exchange"],"keywords":["25203","event 25203","event id 25203","New-ExchangeCertificate Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25203"],"errorCode":"","eventId":"25203","severity":"Medium","summary":"Exchange Audit event 25203 records: New-ExchangeCertificate Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-ExchangeCertificate Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25203.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-ExchangeCertificate Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25203\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25203} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25203","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25203","Event ID 25203","New-ExchangeCertificate Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68116,"title":"Exchange Audit Event 25204 - New-FederationTrust Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25204","Exchange"],"keywords":["25204","event 25204","event id 25204","New-FederationTrust Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25204"],"errorCode":"","eventId":"25204","severity":"Medium","summary":"Exchange Audit event 25204 records: New-FederationTrust Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-FederationTrust Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25204.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-FederationTrust Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25204\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25204} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25204","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25204","Event ID 25204","New-FederationTrust Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68117,"title":"Exchange Audit Event 25205 - New-ForeignConnector Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25205","Exchange"],"keywords":["25205","event 25205","event id 25205","New-ForeignConnector Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25205"],"errorCode":"","eventId":"25205","severity":"Low","summary":"Exchange Audit event 25205 records: New-ForeignConnector Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-ForeignConnector Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25205.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-ForeignConnector Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25205\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25205} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25205","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25205","Event ID 25205","New-ForeignConnector Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68118,"title":"Exchange Audit Event 25206 - New-GlobalAddressList Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25206","Exchange"],"keywords":["25206","event 25206","event id 25206","New-GlobalAddressList Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25206"],"errorCode":"","eventId":"25206","severity":"Low","summary":"Exchange Audit event 25206 records: New-GlobalAddressList Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-GlobalAddressList Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25206.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-GlobalAddressList Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25206\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25206} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25206","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25206","Event ID 25206","New-GlobalAddressList Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68119,"title":"Exchange Audit Event 25207 - New-InboxRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25207","Exchange"],"keywords":["25207","event 25207","event id 25207","New-InboxRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25207"],"errorCode":"","eventId":"25207","severity":"Low","summary":"Exchange Audit event 25207 records: New-InboxRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-InboxRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25207.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-InboxRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25207\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25207} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25207","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25207","Event ID 25207","New-InboxRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68120,"title":"Exchange Audit Event 25208 - New-JournalRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25208","Exchange"],"keywords":["25208","event 25208","event id 25208","New-JournalRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25208"],"errorCode":"","eventId":"25208","severity":"Low","summary":"Exchange Audit event 25208 records: New-JournalRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-JournalRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25208.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-JournalRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25208\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25208} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25208","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25208","Event ID 25208","New-JournalRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68121,"title":"Exchange Audit Event 25209 - New-Mailbox Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25209","Exchange"],"keywords":["25209","event 25209","event id 25209","New-Mailbox Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25209"],"errorCode":"","eventId":"25209","severity":"Low","summary":"Exchange Audit event 25209 records: New-Mailbox Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-Mailbox Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25209.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-Mailbox Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25209\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25209} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25209","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25209","Event ID 25209","New-Mailbox Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68122,"title":"Exchange Audit Event 25210 - New-MailboxAuditLogSearch Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25210","Exchange"],"keywords":["25210","event 25210","event id 25210","New-MailboxAuditLogSearch Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25210"],"errorCode":"","eventId":"25210","severity":"Low","summary":"Exchange Audit event 25210 records: New-MailboxAuditLogSearch Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-MailboxAuditLogSearch Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25210.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-MailboxAuditLogSearch Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25210\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25210} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25210","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25210","Event ID 25210","New-MailboxAuditLogSearch Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68123,"title":"Exchange Audit Event 25211 - New-MailboxDatabase Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25211","Exchange"],"keywords":["25211","event 25211","event id 25211","New-MailboxDatabase Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25211"],"errorCode":"","eventId":"25211","severity":"Low","summary":"Exchange Audit event 25211 records: New-MailboxDatabase Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-MailboxDatabase Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25211.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-MailboxDatabase Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25211\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25211} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25211","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25211","Event ID 25211","New-MailboxDatabase Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68124,"title":"Exchange Audit Event 25212 - New-MailboxFolder Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25212","Exchange"],"keywords":["25212","event 25212","event id 25212","New-MailboxFolder Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25212"],"errorCode":"","eventId":"25212","severity":"Low","summary":"Exchange Audit event 25212 records: New-MailboxFolder Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-MailboxFolder Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25212.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-MailboxFolder Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25212\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25212} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25212","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25212","Event ID 25212","New-MailboxFolder Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68125,"title":"Exchange Audit Event 25213 - New-MailboxRepairRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25213","Exchange"],"keywords":["25213","event 25213","event id 25213","New-MailboxRepairRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25213"],"errorCode":"","eventId":"25213","severity":"Low","summary":"Exchange Audit event 25213 records: New-MailboxRepairRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-MailboxRepairRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25213.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-MailboxRepairRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25213\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25213} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25213","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25213","Event ID 25213","New-MailboxRepairRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68126,"title":"Exchange Audit Event 25214 - New-MailboxRestoreRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25214","Exchange"],"keywords":["25214","event 25214","event id 25214","New-MailboxRestoreRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25214"],"errorCode":"","eventId":"25214","severity":"Low","summary":"Exchange Audit event 25214 records: New-MailboxRestoreRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-MailboxRestoreRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25214.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-MailboxRestoreRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25214\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25214} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25214","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25214","Event ID 25214","New-MailboxRestoreRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68127,"title":"Exchange Audit Event 25215 - New-MailContact Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25215","Exchange"],"keywords":["25215","event 25215","event id 25215","New-MailContact Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25215"],"errorCode":"","eventId":"25215","severity":"Low","summary":"Exchange Audit event 25215 records: New-MailContact Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-MailContact Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25215.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-MailContact Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25215\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25215} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25215","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25215","Event ID 25215","New-MailContact Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68128,"title":"Exchange Audit Event 25216 - New-MailMessage Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25216","Exchange"],"keywords":["25216","event 25216","event id 25216","New-MailMessage Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25216"],"errorCode":"","eventId":"25216","severity":"Low","summary":"Exchange Audit event 25216 records: New-MailMessage Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-MailMessage Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25216.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-MailMessage Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25216\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25216} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25216","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25216","Event ID 25216","New-MailMessage Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68129,"title":"Exchange Audit Event 25217 - New-MailUser Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25217","Exchange"],"keywords":["25217","event 25217","event id 25217","New-MailUser Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25217"],"errorCode":"","eventId":"25217","severity":"Low","summary":"Exchange Audit event 25217 records: New-MailUser Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-MailUser Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25217.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-MailUser Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25217\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25217} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25217","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25217","Event ID 25217","New-MailUser Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68130,"title":"Exchange Audit Event 25218 - New-ManagedContentSettings Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25218","Exchange"],"keywords":["25218","event 25218","event id 25218","New-ManagedContentSettings Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25218"],"errorCode":"","eventId":"25218","severity":"Low","summary":"Exchange Audit event 25218 records: New-ManagedContentSettings Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-ManagedContentSettings Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25218.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-ManagedContentSettings Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25218\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25218} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25218","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25218","Event ID 25218","New-ManagedContentSettings Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68131,"title":"Exchange Audit Event 25219 - New-ManagedFolder Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25219","Exchange"],"keywords":["25219","event 25219","event id 25219","New-ManagedFolder Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25219"],"errorCode":"","eventId":"25219","severity":"Low","summary":"Exchange Audit event 25219 records: New-ManagedFolder Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-ManagedFolder Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25219.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-ManagedFolder Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25219\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25219} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25219","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25219","Event ID 25219","New-ManagedFolder Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68132,"title":"Exchange Audit Event 25220 - New-ManagedFolderMailboxPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25220","Exchange"],"keywords":["25220","event 25220","event id 25220","New-ManagedFolderMailboxPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25220"],"errorCode":"","eventId":"25220","severity":"Medium","summary":"Exchange Audit event 25220 records: New-ManagedFolderMailboxPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-ManagedFolderMailboxPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25220.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-ManagedFolderMailboxPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25220\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25220} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25220","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25220","Event ID 25220","New-ManagedFolderMailboxPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68133,"title":"Exchange Audit Event 25221 - New-ManagementRole Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25221","Exchange"],"keywords":["25221","event 25221","event id 25221","New-ManagementRole Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25221"],"errorCode":"","eventId":"25221","severity":"Medium","summary":"Exchange Audit event 25221 records: New-ManagementRole Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-ManagementRole Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25221.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-ManagementRole Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25221\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25221} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25221","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25221","Event ID 25221","New-ManagementRole Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68134,"title":"Exchange Audit Event 25222 - New-ManagementRoleAssignment Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25222","Exchange"],"keywords":["25222","event 25222","event id 25222","New-ManagementRoleAssignment Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25222"],"errorCode":"","eventId":"25222","severity":"Medium","summary":"Exchange Audit event 25222 records: New-ManagementRoleAssignment Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-ManagementRoleAssignment Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25222.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-ManagementRoleAssignment Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25222\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25222} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25222","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25222","Event ID 25222","New-ManagementRoleAssignment Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68135,"title":"Exchange Audit Event 25223 - New-ManagementScope Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25223","Exchange"],"keywords":["25223","event 25223","event id 25223","New-ManagementScope Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25223"],"errorCode":"","eventId":"25223","severity":"Low","summary":"Exchange Audit event 25223 records: New-ManagementScope Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-ManagementScope Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25223.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-ManagementScope Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25223\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25223} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25223","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25223","Event ID 25223","New-ManagementScope Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68136,"title":"Exchange Audit Event 25224 - New-MessageClassification Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25224","Exchange"],"keywords":["25224","event 25224","event id 25224","New-MessageClassification Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25224"],"errorCode":"","eventId":"25224","severity":"Low","summary":"Exchange Audit event 25224 records: New-MessageClassification Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-MessageClassification Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25224.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-MessageClassification Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25224\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25224} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25224","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25224","Event ID 25224","New-MessageClassification Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68137,"title":"Exchange Audit Event 25225 - New-MoveRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25225","Exchange"],"keywords":["25225","event 25225","event id 25225","New-MoveRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25225"],"errorCode":"","eventId":"25225","severity":"Low","summary":"Exchange Audit event 25225 records: New-MoveRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-MoveRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25225.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-MoveRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25225\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25225} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25225","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25225","Event ID 25225","New-MoveRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68138,"title":"Exchange Audit Event 25226 - New-OabVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25226","Exchange"],"keywords":["25226","event 25226","event id 25226","New-OabVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25226"],"errorCode":"","eventId":"25226","severity":"Low","summary":"Exchange Audit event 25226 records: New-OabVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-OabVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25226.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-OabVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25226\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25226} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25226","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25226","Event ID 25226","New-OabVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68139,"title":"Exchange Audit Event 25227 - New-OfflineAddressBook Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25227","Exchange"],"keywords":["25227","event 25227","event id 25227","New-OfflineAddressBook Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25227"],"errorCode":"","eventId":"25227","severity":"Low","summary":"Exchange Audit event 25227 records: New-OfflineAddressBook Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-OfflineAddressBook Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25227.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-OfflineAddressBook Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25227\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25227} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25227","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25227","Event ID 25227","New-OfflineAddressBook Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68140,"title":"Exchange Audit Event 25228 - New-OrganizationRelationship Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25228","Exchange"],"keywords":["25228","event 25228","event id 25228","New-OrganizationRelationship Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25228"],"errorCode":"","eventId":"25228","severity":"Low","summary":"Exchange Audit event 25228 records: New-OrganizationRelationship Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-OrganizationRelationship Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25228.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-OrganizationRelationship Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25228\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25228} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25228","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25228","Event ID 25228","New-OrganizationRelationship Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68141,"title":"Exchange Audit Event 25229 - New-OutlookProtectionRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25229","Exchange"],"keywords":["25229","event 25229","event id 25229","New-OutlookProtectionRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25229"],"errorCode":"","eventId":"25229","severity":"Low","summary":"Exchange Audit event 25229 records: New-OutlookProtectionRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-OutlookProtectionRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25229.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-OutlookProtectionRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25229\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25229} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25229","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25229","Event ID 25229","New-OutlookProtectionRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68142,"title":"Exchange Audit Event 25230 - New-OutlookProvider Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25230","Exchange"],"keywords":["25230","event 25230","event id 25230","New-OutlookProvider Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25230"],"errorCode":"","eventId":"25230","severity":"Low","summary":"Exchange Audit event 25230 records: New-OutlookProvider Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-OutlookProvider Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25230.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-OutlookProvider Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25230\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25230} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25230","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25230","Event ID 25230","New-OutlookProvider Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68143,"title":"Exchange Audit Event 25231 - New-OwaMailboxPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25231","Exchange"],"keywords":["25231","event 25231","event id 25231","New-OwaMailboxPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25231"],"errorCode":"","eventId":"25231","severity":"Medium","summary":"Exchange Audit event 25231 records: New-OwaMailboxPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-OwaMailboxPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25231.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-OwaMailboxPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25231\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25231} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25231","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25231","Event ID 25231","New-OwaMailboxPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68144,"title":"Exchange Audit Event 25232 - New-OwaVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25232","Exchange"],"keywords":["25232","event 25232","event id 25232","New-OwaVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25232"],"errorCode":"","eventId":"25232","severity":"Low","summary":"Exchange Audit event 25232 records: New-OwaVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-OwaVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25232.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-OwaVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25232\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25232} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25232","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25232","Event ID 25232","New-OwaVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68145,"title":"Exchange Audit Event 25233 - New-PublicFolder Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25233","Exchange"],"keywords":["25233","event 25233","event id 25233","New-PublicFolder Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25233"],"errorCode":"","eventId":"25233","severity":"Low","summary":"Exchange Audit event 25233 records: New-PublicFolder Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-PublicFolder Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25233.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-PublicFolder Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25233\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25233} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25233","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25233","Event ID 25233","New-PublicFolder Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68146,"title":"Exchange Audit Event 25234 - New-PublicFolderDatabase Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25234","Exchange"],"keywords":["25234","event 25234","event id 25234","New-PublicFolderDatabase Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25234"],"errorCode":"","eventId":"25234","severity":"Low","summary":"Exchange Audit event 25234 records: New-PublicFolderDatabase Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-PublicFolderDatabase Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25234.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-PublicFolderDatabase Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25234\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25234} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25234","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25234","Event ID 25234","New-PublicFolderDatabase Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68147,"title":"Exchange Audit Event 25235 - New-PublicFolderDatabaseRepairRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25235","Exchange"],"keywords":["25235","event 25235","event id 25235","New-PublicFolderDatabaseRepairRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25235"],"errorCode":"","eventId":"25235","severity":"Low","summary":"Exchange Audit event 25235 records: New-PublicFolderDatabaseRepairRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-PublicFolderDatabaseRepairRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25235.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-PublicFolderDatabaseRepairRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25235\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25235} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25235","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25235","Event ID 25235","New-PublicFolderDatabaseRepairRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68148,"title":"Exchange Audit Event 25236 - New-ReceiveConnector Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25236","Exchange"],"keywords":["25236","event 25236","event id 25236","New-ReceiveConnector Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25236"],"errorCode":"","eventId":"25236","severity":"Low","summary":"Exchange Audit event 25236 records: New-ReceiveConnector Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-ReceiveConnector Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25236.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-ReceiveConnector Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25236\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25236} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25236","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25236","Event ID 25236","New-ReceiveConnector Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68149,"title":"Exchange Audit Event 25237 - New-RemoteDomain Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25237","Exchange"],"keywords":["25237","event 25237","event id 25237","New-RemoteDomain Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25237"],"errorCode":"","eventId":"25237","severity":"Low","summary":"Exchange Audit event 25237 records: New-RemoteDomain Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-RemoteDomain Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25237.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-RemoteDomain Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25237\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25237} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25237","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25237","Event ID 25237","New-RemoteDomain Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68150,"title":"Exchange Audit Event 25238 - New-RemoteMailbox Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25238","Exchange"],"keywords":["25238","event 25238","event id 25238","New-RemoteMailbox Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25238"],"errorCode":"","eventId":"25238","severity":"Low","summary":"Exchange Audit event 25238 records: New-RemoteMailbox Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-RemoteMailbox Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25238.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-RemoteMailbox Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25238\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25238} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25238","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25238","Event ID 25238","New-RemoteMailbox Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68151,"title":"Exchange Audit Event 25239 - New-RetentionPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25239","Exchange"],"keywords":["25239","event 25239","event id 25239","New-RetentionPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25239"],"errorCode":"","eventId":"25239","severity":"Medium","summary":"Exchange Audit event 25239 records: New-RetentionPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-RetentionPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25239.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-RetentionPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25239\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25239} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25239","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25239","Event ID 25239","New-RetentionPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68152,"title":"Exchange Audit Event 25240 - New-RetentionPolicyTag Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25240","Exchange"],"keywords":["25240","event 25240","event id 25240","New-RetentionPolicyTag Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25240"],"errorCode":"","eventId":"25240","severity":"Medium","summary":"Exchange Audit event 25240 records: New-RetentionPolicyTag Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-RetentionPolicyTag Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25240.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-RetentionPolicyTag Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25240\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25240} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25240","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25240","Event ID 25240","New-RetentionPolicyTag Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68153,"title":"Exchange Audit Event 25241 - New-RoleAssignmentPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25241","Exchange"],"keywords":["25241","event 25241","event id 25241","New-RoleAssignmentPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25241"],"errorCode":"","eventId":"25241","severity":"Medium","summary":"Exchange Audit event 25241 records: New-RoleAssignmentPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-RoleAssignmentPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25241.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-RoleAssignmentPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25241\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25241} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25241","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25241","Event ID 25241","New-RoleAssignmentPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68154,"title":"Exchange Audit Event 25242 - New-RoleGroup Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25242","Exchange"],"keywords":["25242","event 25242","event id 25242","New-RoleGroup Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25242"],"errorCode":"","eventId":"25242","severity":"Medium","summary":"Exchange Audit event 25242 records: New-RoleGroup Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-RoleGroup Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25242.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-RoleGroup Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25242\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25242} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25242","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25242","Event ID 25242","New-RoleGroup Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68155,"title":"Exchange Audit Event 25243 - New-RoutingGroupConnector Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25243","Exchange"],"keywords":["25243","event 25243","event id 25243","New-RoutingGroupConnector Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25243"],"errorCode":"","eventId":"25243","severity":"Medium","summary":"Exchange Audit event 25243 records: New-RoutingGroupConnector Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-RoutingGroupConnector Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25243.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-RoutingGroupConnector Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25243\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25243} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25243","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25243","Event ID 25243","New-RoutingGroupConnector Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68156,"title":"Exchange Audit Event 25244 - New-RpcClientAccess Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25244","Exchange"],"keywords":["25244","event 25244","event id 25244","New-RpcClientAccess Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25244"],"errorCode":"","eventId":"25244","severity":"Low","summary":"Exchange Audit event 25244 records: New-RpcClientAccess Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-RpcClientAccess Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25244.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-RpcClientAccess Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25244\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25244} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25244","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25244","Event ID 25244","New-RpcClientAccess Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68157,"title":"Exchange Audit Event 25245 - New-SendConnector Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25245","Exchange"],"keywords":["25245","event 25245","event id 25245","New-SendConnector Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25245"],"errorCode":"","eventId":"25245","severity":"Low","summary":"Exchange Audit event 25245 records: New-SendConnector Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-SendConnector Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25245.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-SendConnector Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25245\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25245} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25245","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25245","Event ID 25245","New-SendConnector Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68158,"title":"Exchange Audit Event 25246 - New-SharingPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25246","Exchange"],"keywords":["25246","event 25246","event id 25246","New-SharingPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25246"],"errorCode":"","eventId":"25246","severity":"Medium","summary":"Exchange Audit event 25246 records: New-SharingPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-SharingPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25246.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-SharingPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25246\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25246} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25246","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25246","Event ID 25246","New-SharingPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68159,"title":"Exchange Audit Event 25247 - New-SystemMessage Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25247","Exchange"],"keywords":["25247","event 25247","event id 25247","New-SystemMessage Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25247"],"errorCode":"","eventId":"25247","severity":"Low","summary":"Exchange Audit event 25247 records: New-SystemMessage Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-SystemMessage Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25247.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-SystemMessage Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25247\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25247} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25247","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25247","Event ID 25247","New-SystemMessage Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68160,"title":"Exchange Audit Event 25248 - New-ThrottlingPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25248","Exchange"],"keywords":["25248","event 25248","event id 25248","New-ThrottlingPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25248"],"errorCode":"","eventId":"25248","severity":"Medium","summary":"Exchange Audit event 25248 records: New-ThrottlingPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-ThrottlingPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25248.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-ThrottlingPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25248\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25248} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25248","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25248","Event ID 25248","New-ThrottlingPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68161,"title":"Exchange Audit Event 25249 - New-TransportRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25249","Exchange"],"keywords":["25249","event 25249","event id 25249","New-TransportRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25249"],"errorCode":"","eventId":"25249","severity":"Low","summary":"Exchange Audit event 25249 records: New-TransportRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-TransportRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25249.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-TransportRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25249\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25249} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25249","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25249","Event ID 25249","New-TransportRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68162,"title":"Exchange Audit Event 25250 - New-UMAutoAttendant Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25250","Exchange"],"keywords":["25250","event 25250","event id 25250","New-UMAutoAttendant Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25250"],"errorCode":"","eventId":"25250","severity":"Low","summary":"Exchange Audit event 25250 records: New-UMAutoAttendant Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-UMAutoAttendant Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25250.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-UMAutoAttendant Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25250\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25250} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25250","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25250","Event ID 25250","New-UMAutoAttendant Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68163,"title":"Exchange Audit Event 25251 - New-UMDialPlan Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25251","Exchange"],"keywords":["25251","event 25251","event id 25251","New-UMDialPlan Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25251"],"errorCode":"","eventId":"25251","severity":"Low","summary":"Exchange Audit event 25251 records: New-UMDialPlan Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-UMDialPlan Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25251.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-UMDialPlan Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25251\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25251} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25251","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25251","Event ID 25251","New-UMDialPlan Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68164,"title":"Exchange Audit Event 25252 - New-UMHuntGroup Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25252","Exchange"],"keywords":["25252","event 25252","event id 25252","New-UMHuntGroup Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25252"],"errorCode":"","eventId":"25252","severity":"Medium","summary":"Exchange Audit event 25252 records: New-UMHuntGroup Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-UMHuntGroup Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25252.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-UMHuntGroup Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25252\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25252} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25252","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25252","Event ID 25252","New-UMHuntGroup Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68165,"title":"Exchange Audit Event 25253 - New-UMIPGateway Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25253","Exchange"],"keywords":["25253","event 25253","event id 25253","New-UMIPGateway Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25253"],"errorCode":"","eventId":"25253","severity":"Low","summary":"Exchange Audit event 25253 records: New-UMIPGateway Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-UMIPGateway Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25253.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-UMIPGateway Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25253\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25253} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25253","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25253","Event ID 25253","New-UMIPGateway Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68166,"title":"Exchange Audit Event 25254 - New-UMMailboxPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25254","Exchange"],"keywords":["25254","event 25254","event id 25254","New-UMMailboxPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25254"],"errorCode":"","eventId":"25254","severity":"Medium","summary":"Exchange Audit event 25254 records: New-UMMailboxPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-UMMailboxPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25254.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-UMMailboxPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25254\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25254} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25254","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25254","Event ID 25254","New-UMMailboxPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68167,"title":"Exchange Audit Event 25255 - New-WebServicesVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25255","Exchange"],"keywords":["25255","event 25255","event id 25255","New-WebServicesVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25255"],"errorCode":"","eventId":"25255","severity":"Low","summary":"Exchange Audit event 25255 records: New-WebServicesVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-WebServicesVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25255.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-WebServicesVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25255\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25255} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25255","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25255","Event ID 25255","New-WebServicesVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68168,"title":"Exchange Audit Event 25256 - New-X400AuthoritativeDomain Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25256","Exchange"],"keywords":["25256","event 25256","event id 25256","New-X400AuthoritativeDomain Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25256"],"errorCode":"","eventId":"25256","severity":"Low","summary":"Exchange Audit event 25256 records: New-X400AuthoritativeDomain Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-X400AuthoritativeDomain Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25256.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-X400AuthoritativeDomain Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25256\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25256} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25256","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25256","Event ID 25256","New-X400AuthoritativeDomain Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68169,"title":"Exchange Audit Event 25257 - Remove-AcceptedDomain Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25257","Exchange"],"keywords":["25257","event 25257","event id 25257","Remove-AcceptedDomain Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25257"],"errorCode":"","eventId":"25257","severity":"Low","summary":"Exchange Audit event 25257 records: Remove-AcceptedDomain Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-AcceptedDomain Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25257.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-AcceptedDomain Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25257\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25257} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25257","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25257","Event ID 25257","Remove-AcceptedDomain Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68170,"title":"Exchange Audit Event 25258 - Remove-ActiveSyncDevice Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25258","Exchange"],"keywords":["25258","event 25258","event id 25258","Remove-ActiveSyncDevice Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25258"],"errorCode":"","eventId":"25258","severity":"Low","summary":"Exchange Audit event 25258 records: Remove-ActiveSyncDevice Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-ActiveSyncDevice Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25258.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-ActiveSyncDevice Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25258\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25258} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25258","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25258","Event ID 25258","Remove-ActiveSyncDevice Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68171,"title":"Exchange Audit Event 25259 - Remove-ActiveSyncDeviceAccessRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25259","Exchange"],"keywords":["25259","event 25259","event id 25259","Remove-ActiveSyncDeviceAccessRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25259"],"errorCode":"","eventId":"25259","severity":"Low","summary":"Exchange Audit event 25259 records: Remove-ActiveSyncDeviceAccessRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-ActiveSyncDeviceAccessRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25259.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-ActiveSyncDeviceAccessRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25259\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25259} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25259","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25259","Event ID 25259","Remove-ActiveSyncDeviceAccessRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68172,"title":"Exchange Audit Event 25260 - Remove-ActiveSyncDeviceClass Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25260","Exchange"],"keywords":["25260","event 25260","event id 25260","Remove-ActiveSyncDeviceClass Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25260"],"errorCode":"","eventId":"25260","severity":"Low","summary":"Exchange Audit event 25260 records: Remove-ActiveSyncDeviceClass Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-ActiveSyncDeviceClass Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25260.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-ActiveSyncDeviceClass Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25260\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25260} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25260","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25260","Event ID 25260","Remove-ActiveSyncDeviceClass Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68173,"title":"Exchange Audit Event 25261 - Remove-ActiveSyncMailboxPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25261","Exchange"],"keywords":["25261","event 25261","event id 25261","Remove-ActiveSyncMailboxPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25261"],"errorCode":"","eventId":"25261","severity":"Medium","summary":"Exchange Audit event 25261 records: Remove-ActiveSyncMailboxPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-ActiveSyncMailboxPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25261.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-ActiveSyncMailboxPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25261\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25261} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25261","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25261","Event ID 25261","Remove-ActiveSyncMailboxPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68174,"title":"Exchange Audit Event 25262 - Remove-ActiveSyncVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25262","Exchange"],"keywords":["25262","event 25262","event id 25262","Remove-ActiveSyncVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25262"],"errorCode":"","eventId":"25262","severity":"Low","summary":"Exchange Audit event 25262 records: Remove-ActiveSyncVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-ActiveSyncVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25262.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-ActiveSyncVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25262\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25262} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25262","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25262","Event ID 25262","Remove-ActiveSyncVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68175,"title":"Exchange Audit Event 25263 - Remove-AddressList Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25263","Exchange"],"keywords":["25263","event 25263","event id 25263","Remove-AddressList Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25263"],"errorCode":"","eventId":"25263","severity":"Low","summary":"Exchange Audit event 25263 records: Remove-AddressList Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-AddressList Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25263.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-AddressList Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25263\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25263} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25263","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25263","Event ID 25263","Remove-AddressList Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68176,"title":"Exchange Audit Event 25264 - Remove-ADPermission Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25264","Exchange"],"keywords":["25264","event 25264","event id 25264","Remove-ADPermission Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25264"],"errorCode":"","eventId":"25264","severity":"Medium","summary":"Exchange Audit event 25264 records: Remove-ADPermission Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-ADPermission Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25264.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-ADPermission Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25264\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25264} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25264","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25264","Event ID 25264","Remove-ADPermission Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68177,"title":"Exchange Audit Event 25265 - Remove-AutodiscoverVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25265","Exchange"],"keywords":["25265","event 25265","event id 25265","Remove-AutodiscoverVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25265"],"errorCode":"","eventId":"25265","severity":"Low","summary":"Exchange Audit event 25265 records: Remove-AutodiscoverVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-AutodiscoverVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25265.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-AutodiscoverVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25265\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25265} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25265","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25265","Event ID 25265","Remove-AutodiscoverVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68178,"title":"Exchange Audit Event 25266 - Remove-AvailabilityAddressSpace Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25266","Exchange"],"keywords":["25266","event 25266","event id 25266","Remove-AvailabilityAddressSpace Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25266"],"errorCode":"","eventId":"25266","severity":"Low","summary":"Exchange Audit event 25266 records: Remove-AvailabilityAddressSpace Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-AvailabilityAddressSpace Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25266.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-AvailabilityAddressSpace Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25266\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25266} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25266","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25266","Event ID 25266","Remove-AvailabilityAddressSpace Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68179,"title":"Exchange Audit Event 25267 - Remove-AvailabilityReportOutage Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25267","Exchange"],"keywords":["25267","event 25267","event id 25267","Remove-AvailabilityReportOutage Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25267"],"errorCode":"","eventId":"25267","severity":"Low","summary":"Exchange Audit event 25267 records: Remove-AvailabilityReportOutage Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-AvailabilityReportOutage Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25267.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-AvailabilityReportOutage Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25267\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25267} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25267","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25267","Event ID 25267","Remove-AvailabilityReportOutage Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68180,"title":"Exchange Audit Event 25268 - Remove-ClientAccessArray Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25268","Exchange"],"keywords":["25268","event 25268","event id 25268","Remove-ClientAccessArray Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25268"],"errorCode":"","eventId":"25268","severity":"Low","summary":"Exchange Audit event 25268 records: Remove-ClientAccessArray Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-ClientAccessArray Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25268.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-ClientAccessArray Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25268\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25268} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25268","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25268","Event ID 25268","Remove-ClientAccessArray Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68181,"title":"Exchange Audit Event 25269 - Remove-ContentFilterPhrase Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25269","Exchange"],"keywords":["25269","event 25269","event id 25269","Remove-ContentFilterPhrase Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25269"],"errorCode":"","eventId":"25269","severity":"Low","summary":"Exchange Audit event 25269 records: Remove-ContentFilterPhrase Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-ContentFilterPhrase Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25269.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-ContentFilterPhrase Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25269\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25269} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25269","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25269","Event ID 25269","Remove-ContentFilterPhrase Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68182,"title":"Exchange Audit Event 25270 - Remove-DatabaseAvailabilityGroup Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25270","Exchange"],"keywords":["25270","event 25270","event id 25270","Remove-DatabaseAvailabilityGroup Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25270"],"errorCode":"","eventId":"25270","severity":"Medium","summary":"Exchange Audit event 25270 records: Remove-DatabaseAvailabilityGroup Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-DatabaseAvailabilityGroup Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25270.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-DatabaseAvailabilityGroup Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25270\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25270} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25270","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25270","Event ID 25270","Remove-DatabaseAvailabilityGroup Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68183,"title":"Exchange Audit Event 25271 - Remove-DatabaseAvailabilityGroupNetwork Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25271","Exchange"],"keywords":["25271","event 25271","event id 25271","Remove-DatabaseAvailabilityGroupNetwork Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25271"],"errorCode":"","eventId":"25271","severity":"Medium","summary":"Exchange Audit event 25271 records: Remove-DatabaseAvailabilityGroupNetwork Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-DatabaseAvailabilityGroupNetwork Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25271.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-DatabaseAvailabilityGroupNetwork Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25271\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25271} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25271","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25271","Event ID 25271","Remove-DatabaseAvailabilityGroupNetwork Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68184,"title":"Exchange Audit Event 25272 - Remove-DatabaseAvailabilityGroupServer Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25272","Exchange"],"keywords":["25272","event 25272","event id 25272","Remove-DatabaseAvailabilityGroupServer Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25272"],"errorCode":"","eventId":"25272","severity":"Medium","summary":"Exchange Audit event 25272 records: Remove-DatabaseAvailabilityGroupServer Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-DatabaseAvailabilityGroupServer Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25272.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-DatabaseAvailabilityGroupServer Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25272\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25272} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25272","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25272","Event ID 25272","Remove-DatabaseAvailabilityGroupServer Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68185,"title":"Exchange Audit Event 25273 - Remove-DeliveryAgentConnector Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25273","Exchange"],"keywords":["25273","event 25273","event id 25273","Remove-DeliveryAgentConnector Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25273"],"errorCode":"","eventId":"25273","severity":"Low","summary":"Exchange Audit event 25273 records: Remove-DeliveryAgentConnector Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-DeliveryAgentConnector Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25273.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-DeliveryAgentConnector Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25273\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25273} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25273","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25273","Event ID 25273","Remove-DeliveryAgentConnector Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68186,"title":"Exchange Audit Event 25274 - Remove-DistributionGroup Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25274","Exchange"],"keywords":["25274","event 25274","event id 25274","Remove-DistributionGroup Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25274"],"errorCode":"","eventId":"25274","severity":"Medium","summary":"Exchange Audit event 25274 records: Remove-DistributionGroup Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-DistributionGroup Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25274.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-DistributionGroup Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25274\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25274} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25274","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25274","Event ID 25274","Remove-DistributionGroup Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68187,"title":"Exchange Audit Event 25275 - Remove-DistributionGroupMember Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25275","Exchange"],"keywords":["25275","event 25275","event id 25275","Remove-DistributionGroupMember Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25275"],"errorCode":"","eventId":"25275","severity":"Medium","summary":"Exchange Audit event 25275 records: Remove-DistributionGroupMember Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-DistributionGroupMember Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25275.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-DistributionGroupMember Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25275\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25275} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25275","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25275","Event ID 25275","Remove-DistributionGroupMember Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68188,"title":"Exchange Audit Event 25276 - Remove-DynamicDistributionGroup Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25276","Exchange"],"keywords":["25276","event 25276","event id 25276","Remove-DynamicDistributionGroup Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25276"],"errorCode":"","eventId":"25276","severity":"Medium","summary":"Exchange Audit event 25276 records: Remove-DynamicDistributionGroup Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-DynamicDistributionGroup Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25276.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-DynamicDistributionGroup Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25276\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25276} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25276","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25276","Event ID 25276","Remove-DynamicDistributionGroup Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68189,"title":"Exchange Audit Event 25277 - Remove-EcpVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25277","Exchange"],"keywords":["25277","event 25277","event id 25277","Remove-EcpVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25277"],"errorCode":"","eventId":"25277","severity":"Low","summary":"Exchange Audit event 25277 records: Remove-EcpVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-EcpVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25277.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-EcpVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25277\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25277} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25277","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25277","Event ID 25277","Remove-EcpVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68190,"title":"Exchange Audit Event 25278 - Remove-EdgeSubscription Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25278","Exchange"],"keywords":["25278","event 25278","event id 25278","Remove-EdgeSubscription Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25278"],"errorCode":"","eventId":"25278","severity":"Low","summary":"Exchange Audit event 25278 records: Remove-EdgeSubscription Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-EdgeSubscription Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25278.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-EdgeSubscription Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25278\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25278} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25278","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25278","Event ID 25278","Remove-EdgeSubscription Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68191,"title":"Exchange Audit Event 25279 - Remove-EmailAddressPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25279","Exchange"],"keywords":["25279","event 25279","event id 25279","Remove-EmailAddressPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25279"],"errorCode":"","eventId":"25279","severity":"Medium","summary":"Exchange Audit event 25279 records: Remove-EmailAddressPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-EmailAddressPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25279.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-EmailAddressPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25279\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25279} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25279","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25279","Event ID 25279","Remove-EmailAddressPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68192,"title":"Exchange Audit Event 25280 - Remove-ExchangeCertificate Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25280","Exchange"],"keywords":["25280","event 25280","event id 25280","Remove-ExchangeCertificate Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25280"],"errorCode":"","eventId":"25280","severity":"Medium","summary":"Exchange Audit event 25280 records: Remove-ExchangeCertificate Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-ExchangeCertificate Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25280.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-ExchangeCertificate Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25280\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25280} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25280","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25280","Event ID 25280","Remove-ExchangeCertificate Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68193,"title":"Exchange Audit Event 25281 - Remove-FederatedDomain Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25281","Exchange"],"keywords":["25281","event 25281","event id 25281","Remove-FederatedDomain Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25281"],"errorCode":"","eventId":"25281","severity":"Low","summary":"Exchange Audit event 25281 records: Remove-FederatedDomain Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-FederatedDomain Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25281.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-FederatedDomain Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25281\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25281} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25281","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25281","Event ID 25281","Remove-FederatedDomain Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68194,"title":"Exchange Audit Event 25282 - Remove-FederationTrust Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25282","Exchange"],"keywords":["25282","event 25282","event id 25282","Remove-FederationTrust Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25282"],"errorCode":"","eventId":"25282","severity":"Medium","summary":"Exchange Audit event 25282 records: Remove-FederationTrust Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-FederationTrust Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25282.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-FederationTrust Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25282\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25282} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25282","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25282","Event ID 25282","Remove-FederationTrust Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68195,"title":"Exchange Audit Event 25283 - Remove-ForeignConnector Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25283","Exchange"],"keywords":["25283","event 25283","event id 25283","Remove-ForeignConnector Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25283"],"errorCode":"","eventId":"25283","severity":"Low","summary":"Exchange Audit event 25283 records: Remove-ForeignConnector Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-ForeignConnector Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25283.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-ForeignConnector Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25283\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25283} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25283","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25283","Event ID 25283","Remove-ForeignConnector Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68196,"title":"Exchange Audit Event 25284 - Remove-GlobalAddressList Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25284","Exchange"],"keywords":["25284","event 25284","event id 25284","Remove-GlobalAddressList Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25284"],"errorCode":"","eventId":"25284","severity":"Low","summary":"Exchange Audit event 25284 records: Remove-GlobalAddressList Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-GlobalAddressList Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25284.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-GlobalAddressList Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25284\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25284} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25284","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25284","Event ID 25284","Remove-GlobalAddressList Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68197,"title":"Exchange Audit Event 25285 - Remove-InboxRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25285","Exchange"],"keywords":["25285","event 25285","event id 25285","Remove-InboxRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25285"],"errorCode":"","eventId":"25285","severity":"Low","summary":"Exchange Audit event 25285 records: Remove-InboxRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-InboxRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25285.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-InboxRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25285\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25285} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25285","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25285","Event ID 25285","Remove-InboxRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68198,"title":"Exchange Audit Event 25286 - Remove-IPAllowListEntry Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25286","Exchange"],"keywords":["25286","event 25286","event id 25286","Remove-IPAllowListEntry Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25286"],"errorCode":"","eventId":"25286","severity":"Low","summary":"Exchange Audit event 25286 records: Remove-IPAllowListEntry Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-IPAllowListEntry Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25286.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-IPAllowListEntry Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25286\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25286} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25286","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25286","Event ID 25286","Remove-IPAllowListEntry Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68199,"title":"Exchange Audit Event 25287 - Remove-IPAllowListProvider Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25287","Exchange"],"keywords":["25287","event 25287","event id 25287","Remove-IPAllowListProvider Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25287"],"errorCode":"","eventId":"25287","severity":"Low","summary":"Exchange Audit event 25287 records: Remove-IPAllowListProvider Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-IPAllowListProvider Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25287.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-IPAllowListProvider Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25287\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25287} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25287","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25287","Event ID 25287","Remove-IPAllowListProvider Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68200,"title":"Exchange Audit Event 25288 - Remove-IPBlockListEntry Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25288","Exchange"],"keywords":["25288","event 25288","event id 25288","Remove-IPBlockListEntry Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25288"],"errorCode":"","eventId":"25288","severity":"Low","summary":"Exchange Audit event 25288 records: Remove-IPBlockListEntry Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-IPBlockListEntry Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25288.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-IPBlockListEntry Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25288\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25288} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25288","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25288","Event ID 25288","Remove-IPBlockListEntry Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68201,"title":"Exchange Audit Event 25289 - Remove-IPBlockListProvider Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25289","Exchange"],"keywords":["25289","event 25289","event id 25289","Remove-IPBlockListProvider Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25289"],"errorCode":"","eventId":"25289","severity":"Low","summary":"Exchange Audit event 25289 records: Remove-IPBlockListProvider Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-IPBlockListProvider Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25289.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-IPBlockListProvider Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25289\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25289} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25289","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25289","Event ID 25289","Remove-IPBlockListProvider Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68202,"title":"Exchange Audit Event 25290 - Remove-JournalRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25290","Exchange"],"keywords":["25290","event 25290","event id 25290","Remove-JournalRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25290"],"errorCode":"","eventId":"25290","severity":"Low","summary":"Exchange Audit event 25290 records: Remove-JournalRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-JournalRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25290.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-JournalRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25290\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25290} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25290","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25290","Event ID 25290","Remove-JournalRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68203,"title":"Exchange Audit Event 25291 - Remove-Mailbox Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25291","Exchange"],"keywords":["25291","event 25291","event id 25291","Remove-Mailbox Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25291"],"errorCode":"","eventId":"25291","severity":"Low","summary":"Exchange Audit event 25291 records: Remove-Mailbox Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-Mailbox Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25291.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-Mailbox Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25291\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25291} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25291","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25291","Event ID 25291","Remove-Mailbox Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68204,"title":"Exchange Audit Event 25292 - Remove-MailboxDatabase Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25292","Exchange"],"keywords":["25292","event 25292","event id 25292","Remove-MailboxDatabase Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25292"],"errorCode":"","eventId":"25292","severity":"Low","summary":"Exchange Audit event 25292 records: Remove-MailboxDatabase Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-MailboxDatabase Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25292.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-MailboxDatabase Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25292\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25292} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25292","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25292","Event ID 25292","Remove-MailboxDatabase Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68205,"title":"Exchange Audit Event 25293 - Remove-MailboxDatabaseCopy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25293","Exchange"],"keywords":["25293","event 25293","event id 25293","Remove-MailboxDatabaseCopy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25293"],"errorCode":"","eventId":"25293","severity":"Low","summary":"Exchange Audit event 25293 records: Remove-MailboxDatabaseCopy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-MailboxDatabaseCopy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25293.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-MailboxDatabaseCopy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25293\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25293} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25293","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25293","Event ID 25293","Remove-MailboxDatabaseCopy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68206,"title":"Exchange Audit Event 25294 - Remove-MailboxFolderPermission Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25294","Exchange"],"keywords":["25294","event 25294","event id 25294","Remove-MailboxFolderPermission Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25294"],"errorCode":"","eventId":"25294","severity":"Medium","summary":"Exchange Audit event 25294 records: Remove-MailboxFolderPermission Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-MailboxFolderPermission Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25294.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-MailboxFolderPermission Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25294\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25294} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25294","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25294","Event ID 25294","Remove-MailboxFolderPermission Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68207,"title":"Exchange Audit Event 25295 - Remove-MailboxPermission Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25295","Exchange"],"keywords":["25295","event 25295","event id 25295","Remove-MailboxPermission Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25295"],"errorCode":"","eventId":"25295","severity":"Medium","summary":"Exchange Audit event 25295 records: Remove-MailboxPermission Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-MailboxPermission Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25295.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-MailboxPermission Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25295\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25295} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25295","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25295","Event ID 25295","Remove-MailboxPermission Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68208,"title":"Exchange Audit Event 25296 - Remove-MailboxRestoreRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25296","Exchange"],"keywords":["25296","event 25296","event id 25296","Remove-MailboxRestoreRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25296"],"errorCode":"","eventId":"25296","severity":"Low","summary":"Exchange Audit event 25296 records: Remove-MailboxRestoreRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-MailboxRestoreRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25296.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-MailboxRestoreRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25296\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25296} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25296","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25296","Event ID 25296","Remove-MailboxRestoreRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68209,"title":"Exchange Audit Event 25297 - Remove-MailContact Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25297","Exchange"],"keywords":["25297","event 25297","event id 25297","Remove-MailContact Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25297"],"errorCode":"","eventId":"25297","severity":"Low","summary":"Exchange Audit event 25297 records: Remove-MailContact Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-MailContact Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25297.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-MailContact Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25297\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25297} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25297","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25297","Event ID 25297","Remove-MailContact Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68210,"title":"Exchange Audit Event 25298 - Remove-MailUser Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25298","Exchange"],"keywords":["25298","event 25298","event id 25298","Remove-MailUser Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25298"],"errorCode":"","eventId":"25298","severity":"Low","summary":"Exchange Audit event 25298 records: Remove-MailUser Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-MailUser Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25298.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-MailUser Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25298\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25298} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25298","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25298","Event ID 25298","Remove-MailUser Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68211,"title":"Exchange Audit Event 25299 - Remove-ManagedContentSettings Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25299","Exchange"],"keywords":["25299","event 25299","event id 25299","Remove-ManagedContentSettings Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25299"],"errorCode":"","eventId":"25299","severity":"Low","summary":"Exchange Audit event 25299 records: Remove-ManagedContentSettings Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-ManagedContentSettings Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25299.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-ManagedContentSettings Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25299\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25299} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25299","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25299","Event ID 25299","Remove-ManagedContentSettings Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68212,"title":"Exchange Audit Event 25300 - Remove-ManagedFolder Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25300","Exchange"],"keywords":["25300","event 25300","event id 25300","Remove-ManagedFolder Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25300"],"errorCode":"","eventId":"25300","severity":"Low","summary":"Exchange Audit event 25300 records: Remove-ManagedFolder Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-ManagedFolder Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25300.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-ManagedFolder Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25300\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25300} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25300","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25300","Event ID 25300","Remove-ManagedFolder Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68213,"title":"Exchange Audit Event 25301 - Remove-ManagedFolderMailboxPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25301","Exchange"],"keywords":["25301","event 25301","event id 25301","Remove-ManagedFolderMailboxPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25301"],"errorCode":"","eventId":"25301","severity":"Medium","summary":"Exchange Audit event 25301 records: Remove-ManagedFolderMailboxPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-ManagedFolderMailboxPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25301.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-ManagedFolderMailboxPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25301\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25301} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25301","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25301","Event ID 25301","Remove-ManagedFolderMailboxPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68214,"title":"Exchange Audit Event 25302 - Remove-ManagementRole Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25302","Exchange"],"keywords":["25302","event 25302","event id 25302","Remove-ManagementRole Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25302"],"errorCode":"","eventId":"25302","severity":"Medium","summary":"Exchange Audit event 25302 records: Remove-ManagementRole Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-ManagementRole Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25302.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-ManagementRole Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25302\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25302} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25302","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25302","Event ID 25302","Remove-ManagementRole Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68215,"title":"Exchange Audit Event 25303 - Remove-ManagementRoleAssignment Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25303","Exchange"],"keywords":["25303","event 25303","event id 25303","Remove-ManagementRoleAssignment Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25303"],"errorCode":"","eventId":"25303","severity":"Medium","summary":"Exchange Audit event 25303 records: Remove-ManagementRoleAssignment Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-ManagementRoleAssignment Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25303.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-ManagementRoleAssignment Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25303\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25303} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25303","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25303","Event ID 25303","Remove-ManagementRoleAssignment Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68216,"title":"Exchange Audit Event 25304 - Remove-ManagementRoleEntry Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25304","Exchange"],"keywords":["25304","event 25304","event id 25304","Remove-ManagementRoleEntry Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25304"],"errorCode":"","eventId":"25304","severity":"Medium","summary":"Exchange Audit event 25304 records: Remove-ManagementRoleEntry Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-ManagementRoleEntry Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25304.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-ManagementRoleEntry Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25304\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25304} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25304","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25304","Event ID 25304","Remove-ManagementRoleEntry Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68217,"title":"Exchange Audit Event 25305 - Remove-ManagementScope Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25305","Exchange"],"keywords":["25305","event 25305","event id 25305","Remove-ManagementScope Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25305"],"errorCode":"","eventId":"25305","severity":"Low","summary":"Exchange Audit event 25305 records: Remove-ManagementScope Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-ManagementScope Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25305.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-ManagementScope Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25305\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25305} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25305","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25305","Event ID 25305","Remove-ManagementScope Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68218,"title":"Exchange Audit Event 25306 - Remove-Message Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25306","Exchange"],"keywords":["25306","event 25306","event id 25306","Remove-Message Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25306"],"errorCode":"","eventId":"25306","severity":"Low","summary":"Exchange Audit event 25306 records: Remove-Message Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-Message Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25306.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-Message Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25306\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25306} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25306","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25306","Event ID 25306","Remove-Message Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68219,"title":"Exchange Audit Event 25307 - Remove-MessageClassification Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25307","Exchange"],"keywords":["25307","event 25307","event id 25307","Remove-MessageClassification Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25307"],"errorCode":"","eventId":"25307","severity":"Low","summary":"Exchange Audit event 25307 records: Remove-MessageClassification Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-MessageClassification Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25307.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-MessageClassification Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25307\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25307} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25307","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25307","Event ID 25307","Remove-MessageClassification Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68220,"title":"Exchange Audit Event 25308 - Remove-MoveRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25308","Exchange"],"keywords":["25308","event 25308","event id 25308","Remove-MoveRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25308"],"errorCode":"","eventId":"25308","severity":"Low","summary":"Exchange Audit event 25308 records: Remove-MoveRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-MoveRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25308.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-MoveRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25308\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25308} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25308","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25308","Event ID 25308","Remove-MoveRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68221,"title":"Exchange Audit Event 25309 - Remove-OabVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25309","Exchange"],"keywords":["25309","event 25309","event id 25309","Remove-OabVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25309"],"errorCode":"","eventId":"25309","severity":"Low","summary":"Exchange Audit event 25309 records: Remove-OabVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-OabVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25309.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-OabVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25309\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25309} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25309","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25309","Event ID 25309","Remove-OabVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68222,"title":"Exchange Audit Event 25310 - Remove-OfflineAddressBook Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25310","Exchange"],"keywords":["25310","event 25310","event id 25310","Remove-OfflineAddressBook Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25310"],"errorCode":"","eventId":"25310","severity":"Low","summary":"Exchange Audit event 25310 records: Remove-OfflineAddressBook Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-OfflineAddressBook Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25310.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-OfflineAddressBook Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25310\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25310} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25310","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25310","Event ID 25310","Remove-OfflineAddressBook Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68223,"title":"Exchange Audit Event 25311 - Remove-OrganizationRelationship Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25311","Exchange"],"keywords":["25311","event 25311","event id 25311","Remove-OrganizationRelationship Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25311"],"errorCode":"","eventId":"25311","severity":"Low","summary":"Exchange Audit event 25311 records: Remove-OrganizationRelationship Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-OrganizationRelationship Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25311.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-OrganizationRelationship Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25311\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25311} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25311","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25311","Event ID 25311","Remove-OrganizationRelationship Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68224,"title":"Exchange Audit Event 25312 - Remove-OutlookProtectionRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25312","Exchange"],"keywords":["25312","event 25312","event id 25312","Remove-OutlookProtectionRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25312"],"errorCode":"","eventId":"25312","severity":"Low","summary":"Exchange Audit event 25312 records: Remove-OutlookProtectionRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-OutlookProtectionRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25312.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-OutlookProtectionRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25312\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25312} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25312","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25312","Event ID 25312","Remove-OutlookProtectionRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68225,"title":"Exchange Audit Event 25313 - Remove-OutlookProvider Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25313","Exchange"],"keywords":["25313","event 25313","event id 25313","Remove-OutlookProvider Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25313"],"errorCode":"","eventId":"25313","severity":"Low","summary":"Exchange Audit event 25313 records: Remove-OutlookProvider Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-OutlookProvider Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25313.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-OutlookProvider Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25313\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25313} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25313","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25313","Event ID 25313","Remove-OutlookProvider Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68226,"title":"Exchange Audit Event 25314 - Remove-OwaMailboxPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25314","Exchange"],"keywords":["25314","event 25314","event id 25314","Remove-OwaMailboxPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25314"],"errorCode":"","eventId":"25314","severity":"Medium","summary":"Exchange Audit event 25314 records: Remove-OwaMailboxPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-OwaMailboxPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25314.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-OwaMailboxPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25314\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25314} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25314","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25314","Event ID 25314","Remove-OwaMailboxPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68227,"title":"Exchange Audit Event 25315 - Remove-OwaVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25315","Exchange"],"keywords":["25315","event 25315","event id 25315","Remove-OwaVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25315"],"errorCode":"","eventId":"25315","severity":"Low","summary":"Exchange Audit event 25315 records: Remove-OwaVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-OwaVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25315.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-OwaVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25315\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25315} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25315","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25315","Event ID 25315","Remove-OwaVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68228,"title":"Exchange Audit Event 25316 - Remove-PublicFolder Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25316","Exchange"],"keywords":["25316","event 25316","event id 25316","Remove-PublicFolder Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25316"],"errorCode":"","eventId":"25316","severity":"Low","summary":"Exchange Audit event 25316 records: Remove-PublicFolder Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-PublicFolder Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25316.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-PublicFolder Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25316\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25316} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25316","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25316","Event ID 25316","Remove-PublicFolder Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68229,"title":"Exchange Audit Event 25317 - Remove-PublicFolderAdministrativePermission Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25317","Exchange"],"keywords":["25317","event 25317","event id 25317","Remove-PublicFolderAdministrativePermission Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25317"],"errorCode":"","eventId":"25317","severity":"Medium","summary":"Exchange Audit event 25317 records: Remove-PublicFolderAdministrativePermission Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-PublicFolderAdministrativePermission Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25317.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-PublicFolderAdministrativePermission Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25317\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25317} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25317","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25317","Event ID 25317","Remove-PublicFolderAdministrativePermission Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68230,"title":"Exchange Audit Event 25318 - Remove-PublicFolderClientPermission Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25318","Exchange"],"keywords":["25318","event 25318","event id 25318","Remove-PublicFolderClientPermission Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25318"],"errorCode":"","eventId":"25318","severity":"Medium","summary":"Exchange Audit event 25318 records: Remove-PublicFolderClientPermission Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-PublicFolderClientPermission Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25318.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-PublicFolderClientPermission Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25318\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25318} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25318","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25318","Event ID 25318","Remove-PublicFolderClientPermission Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68231,"title":"Exchange Audit Event 25319 - Remove-PublicFolderDatabase Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25319","Exchange"],"keywords":["25319","event 25319","event id 25319","Remove-PublicFolderDatabase Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25319"],"errorCode":"","eventId":"25319","severity":"Low","summary":"Exchange Audit event 25319 records: Remove-PublicFolderDatabase Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-PublicFolderDatabase Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25319.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-PublicFolderDatabase Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25319\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25319} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25319","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25319","Event ID 25319","Remove-PublicFolderDatabase Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68232,"title":"Exchange Audit Event 25320 - Remove-ReceiveConnector Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25320","Exchange"],"keywords":["25320","event 25320","event id 25320","Remove-ReceiveConnector Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25320"],"errorCode":"","eventId":"25320","severity":"Low","summary":"Exchange Audit event 25320 records: Remove-ReceiveConnector Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-ReceiveConnector Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25320.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-ReceiveConnector Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25320\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25320} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25320","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25320","Event ID 25320","Remove-ReceiveConnector Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68233,"title":"Exchange Audit Event 25321 - Remove-RemoteDomain Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25321","Exchange"],"keywords":["25321","event 25321","event id 25321","Remove-RemoteDomain Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25321"],"errorCode":"","eventId":"25321","severity":"Low","summary":"Exchange Audit event 25321 records: Remove-RemoteDomain Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-RemoteDomain Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25321.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-RemoteDomain Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25321\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25321} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25321","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25321","Event ID 25321","Remove-RemoteDomain Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68234,"title":"Exchange Audit Event 25322 - Remove-RemoteMailbox Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25322","Exchange"],"keywords":["25322","event 25322","event id 25322","Remove-RemoteMailbox Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25322"],"errorCode":"","eventId":"25322","severity":"Low","summary":"Exchange Audit event 25322 records: Remove-RemoteMailbox Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-RemoteMailbox Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25322.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-RemoteMailbox Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25322\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25322} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25322","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25322","Event ID 25322","Remove-RemoteMailbox Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68235,"title":"Exchange Audit Event 25323 - Remove-RetentionPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25323","Exchange"],"keywords":["25323","event 25323","event id 25323","Remove-RetentionPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25323"],"errorCode":"","eventId":"25323","severity":"Medium","summary":"Exchange Audit event 25323 records: Remove-RetentionPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-RetentionPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25323.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-RetentionPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25323\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25323} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25323","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25323","Event ID 25323","Remove-RetentionPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68236,"title":"Exchange Audit Event 25324 - Remove-RetentionPolicyTag Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25324","Exchange"],"keywords":["25324","event 25324","event id 25324","Remove-RetentionPolicyTag Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25324"],"errorCode":"","eventId":"25324","severity":"Medium","summary":"Exchange Audit event 25324 records: Remove-RetentionPolicyTag Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-RetentionPolicyTag Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25324.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-RetentionPolicyTag Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25324\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25324} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25324","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25324","Event ID 25324","Remove-RetentionPolicyTag Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68237,"title":"Exchange Audit Event 25325 - Remove-RoleAssignmentPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25325","Exchange"],"keywords":["25325","event 25325","event id 25325","Remove-RoleAssignmentPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25325"],"errorCode":"","eventId":"25325","severity":"Medium","summary":"Exchange Audit event 25325 records: Remove-RoleAssignmentPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-RoleAssignmentPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25325.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-RoleAssignmentPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25325\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25325} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25325","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25325","Event ID 25325","Remove-RoleAssignmentPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68238,"title":"Exchange Audit Event 25326 - Remove-RoleGroup Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25326","Exchange"],"keywords":["25326","event 25326","event id 25326","Remove-RoleGroup Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25326"],"errorCode":"","eventId":"25326","severity":"Medium","summary":"Exchange Audit event 25326 records: Remove-RoleGroup Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-RoleGroup Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25326.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-RoleGroup Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25326\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25326} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25326","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25326","Event ID 25326","Remove-RoleGroup Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68239,"title":"Exchange Audit Event 25327 - Remove-RoleGroupMember Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25327","Exchange"],"keywords":["25327","event 25327","event id 25327","Remove-RoleGroupMember Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25327"],"errorCode":"","eventId":"25327","severity":"Medium","summary":"Exchange Audit event 25327 records: Remove-RoleGroupMember Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-RoleGroupMember Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25327.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-RoleGroupMember Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25327\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25327} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25327","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25327","Event ID 25327","Remove-RoleGroupMember Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68240,"title":"Exchange Audit Event 25328 - Remove-RoutingGroupConnector Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25328","Exchange"],"keywords":["25328","event 25328","event id 25328","Remove-RoutingGroupConnector Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25328"],"errorCode":"","eventId":"25328","severity":"Medium","summary":"Exchange Audit event 25328 records: Remove-RoutingGroupConnector Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-RoutingGroupConnector Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25328.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-RoutingGroupConnector Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25328\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25328} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25328","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25328","Event ID 25328","Remove-RoutingGroupConnector Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68241,"title":"Exchange Audit Event 25329 - Remove-RpcClientAccess Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25329","Exchange"],"keywords":["25329","event 25329","event id 25329","Remove-RpcClientAccess Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25329"],"errorCode":"","eventId":"25329","severity":"Low","summary":"Exchange Audit event 25329 records: Remove-RpcClientAccess Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-RpcClientAccess Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25329.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-RpcClientAccess Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25329\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25329} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25329","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25329","Event ID 25329","Remove-RpcClientAccess Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68242,"title":"Exchange Audit Event 25330 - Remove-SendConnector Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25330","Exchange"],"keywords":["25330","event 25330","event id 25330","Remove-SendConnector Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25330"],"errorCode":"","eventId":"25330","severity":"Low","summary":"Exchange Audit event 25330 records: Remove-SendConnector Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-SendConnector Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25330.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-SendConnector Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25330\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25330} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25330","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25330","Event ID 25330","Remove-SendConnector Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68243,"title":"Exchange Audit Event 25331 - Remove-SharingPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25331","Exchange"],"keywords":["25331","event 25331","event id 25331","Remove-SharingPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25331"],"errorCode":"","eventId":"25331","severity":"Medium","summary":"Exchange Audit event 25331 records: Remove-SharingPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-SharingPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25331.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-SharingPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25331\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25331} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25331","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25331","Event ID 25331","Remove-SharingPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68244,"title":"Exchange Audit Event 25332 - Remove-StoreMailbox Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25332","Exchange"],"keywords":["25332","event 25332","event id 25332","Remove-StoreMailbox Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25332"],"errorCode":"","eventId":"25332","severity":"Low","summary":"Exchange Audit event 25332 records: Remove-StoreMailbox Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-StoreMailbox Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25332.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-StoreMailbox Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25332\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25332} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25332","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25332","Event ID 25332","Remove-StoreMailbox Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68245,"title":"Exchange Audit Event 25333 - Remove-SystemMessage Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25333","Exchange"],"keywords":["25333","event 25333","event id 25333","Remove-SystemMessage Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25333"],"errorCode":"","eventId":"25333","severity":"Low","summary":"Exchange Audit event 25333 records: Remove-SystemMessage Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-SystemMessage Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25333.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-SystemMessage Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25333\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25333} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25333","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25333","Event ID 25333","Remove-SystemMessage Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68246,"title":"Exchange Audit Event 25334 - Remove-ThrottlingPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25334","Exchange"],"keywords":["25334","event 25334","event id 25334","Remove-ThrottlingPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25334"],"errorCode":"","eventId":"25334","severity":"Medium","summary":"Exchange Audit event 25334 records: Remove-ThrottlingPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-ThrottlingPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25334.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-ThrottlingPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25334\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25334} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25334","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25334","Event ID 25334","Remove-ThrottlingPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68247,"title":"Exchange Audit Event 25335 - Remove-TransportRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25335","Exchange"],"keywords":["25335","event 25335","event id 25335","Remove-TransportRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25335"],"errorCode":"","eventId":"25335","severity":"Low","summary":"Exchange Audit event 25335 records: Remove-TransportRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-TransportRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25335.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-TransportRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25335\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25335} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25335","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25335","Event ID 25335","Remove-TransportRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68248,"title":"Exchange Audit Event 25336 - Remove-UMAutoAttendant Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25336","Exchange"],"keywords":["25336","event 25336","event id 25336","Remove-UMAutoAttendant Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25336"],"errorCode":"","eventId":"25336","severity":"Low","summary":"Exchange Audit event 25336 records: Remove-UMAutoAttendant Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-UMAutoAttendant Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25336.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-UMAutoAttendant Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25336\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25336} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25336","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25336","Event ID 25336","Remove-UMAutoAttendant Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68249,"title":"Exchange Audit Event 25337 - Remove-UMDialPlan Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25337","Exchange"],"keywords":["25337","event 25337","event id 25337","Remove-UMDialPlan Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25337"],"errorCode":"","eventId":"25337","severity":"Low","summary":"Exchange Audit event 25337 records: Remove-UMDialPlan Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-UMDialPlan Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25337.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-UMDialPlan Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25337\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25337} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25337","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25337","Event ID 25337","Remove-UMDialPlan Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68250,"title":"Exchange Audit Event 25338 - Remove-UMHuntGroup Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25338","Exchange"],"keywords":["25338","event 25338","event id 25338","Remove-UMHuntGroup Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25338"],"errorCode":"","eventId":"25338","severity":"Medium","summary":"Exchange Audit event 25338 records: Remove-UMHuntGroup Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-UMHuntGroup Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25338.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-UMHuntGroup Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25338\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25338} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25338","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25338","Event ID 25338","Remove-UMHuntGroup Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68251,"title":"Exchange Audit Event 25339 - Remove-UMIPGateway Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25339","Exchange"],"keywords":["25339","event 25339","event id 25339","Remove-UMIPGateway Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25339"],"errorCode":"","eventId":"25339","severity":"Low","summary":"Exchange Audit event 25339 records: Remove-UMIPGateway Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-UMIPGateway Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25339.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-UMIPGateway Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25339\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25339} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25339","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25339","Event ID 25339","Remove-UMIPGateway Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68252,"title":"Exchange Audit Event 25340 - Remove-UMMailboxPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25340","Exchange"],"keywords":["25340","event 25340","event id 25340","Remove-UMMailboxPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25340"],"errorCode":"","eventId":"25340","severity":"Medium","summary":"Exchange Audit event 25340 records: Remove-UMMailboxPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-UMMailboxPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25340.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-UMMailboxPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25340\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25340} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25340","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25340","Event ID 25340","Remove-UMMailboxPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68253,"title":"Exchange Audit Event 25341 - Remove-WebServicesVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25341","Exchange"],"keywords":["25341","event 25341","event id 25341","Remove-WebServicesVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25341"],"errorCode":"","eventId":"25341","severity":"Low","summary":"Exchange Audit event 25341 records: Remove-WebServicesVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-WebServicesVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25341.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-WebServicesVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25341\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25341} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25341","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25341","Event ID 25341","Remove-WebServicesVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68254,"title":"Exchange Audit Event 25342 - Remove-X400AuthoritativeDomain Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25342","Exchange"],"keywords":["25342","event 25342","event id 25342","Remove-X400AuthoritativeDomain Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25342"],"errorCode":"","eventId":"25342","severity":"Low","summary":"Exchange Audit event 25342 records: Remove-X400AuthoritativeDomain Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-X400AuthoritativeDomain Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25342.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-X400AuthoritativeDomain Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25342\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25342} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25342","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25342","Event ID 25342","Remove-X400AuthoritativeDomain Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68255,"title":"Exchange Audit Event 25343 - Restore-DatabaseAvailabilityGroup Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25343","Exchange"],"keywords":["25343","event 25343","event id 25343","Restore-DatabaseAvailabilityGroup Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25343"],"errorCode":"","eventId":"25343","severity":"Medium","summary":"Exchange Audit event 25343 records: Restore-DatabaseAvailabilityGroup Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Restore-DatabaseAvailabilityGroup Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25343.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Restore-DatabaseAvailabilityGroup Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25343\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25343} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25343","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25343","Event ID 25343","Restore-DatabaseAvailabilityGroup Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68256,"title":"Exchange Audit Event 25344 - Restore-DetailsTemplate Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25344","Exchange"],"keywords":["25344","event 25344","event id 25344","Restore-DetailsTemplate Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25344"],"errorCode":"","eventId":"25344","severity":"Low","summary":"Exchange Audit event 25344 records: Restore-DetailsTemplate Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Restore-DetailsTemplate Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25344.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Restore-DetailsTemplate Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25344\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25344} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25344","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25344","Event ID 25344","Restore-DetailsTemplate Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68257,"title":"Exchange Audit Event 25345 - Restore-Mailbox Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25345","Exchange"],"keywords":["25345","event 25345","event id 25345","Restore-Mailbox Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25345"],"errorCode":"","eventId":"25345","severity":"Low","summary":"Exchange Audit event 25345 records: Restore-Mailbox Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Restore-Mailbox Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25345.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Restore-Mailbox Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25345\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25345} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25345","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25345","Event ID 25345","Restore-Mailbox Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68258,"title":"Exchange Audit Event 25346 - Resume-MailboxDatabaseCopy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25346","Exchange"],"keywords":["25346","event 25346","event id 25346","Resume-MailboxDatabaseCopy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25346"],"errorCode":"","eventId":"25346","severity":"Low","summary":"Exchange Audit event 25346 records: Resume-MailboxDatabaseCopy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Resume-MailboxDatabaseCopy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25346.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Resume-MailboxDatabaseCopy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25346\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25346} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25346","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25346","Event ID 25346","Resume-MailboxDatabaseCopy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68259,"title":"Exchange Audit Event 25347 - Resume-MailboxExportRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25347","Exchange"],"keywords":["25347","event 25347","event id 25347","Resume-MailboxExportRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25347"],"errorCode":"","eventId":"25347","severity":"Low","summary":"Exchange Audit event 25347 records: Resume-MailboxExportRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Resume-MailboxExportRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25347.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Resume-MailboxExportRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25347\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25347} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25347","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25347","Event ID 25347","Resume-MailboxExportRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68260,"title":"Exchange Audit Event 25348 - Resume-MailboxRestoreRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25348","Exchange"],"keywords":["25348","event 25348","event id 25348","Resume-MailboxRestoreRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25348"],"errorCode":"","eventId":"25348","severity":"Low","summary":"Exchange Audit event 25348 records: Resume-MailboxRestoreRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Resume-MailboxRestoreRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25348.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Resume-MailboxRestoreRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25348\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25348} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25348","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25348","Event ID 25348","Resume-MailboxRestoreRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68261,"title":"Exchange Audit Event 25349 - Resume-Message Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25349","Exchange"],"keywords":["25349","event 25349","event id 25349","Resume-Message Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25349"],"errorCode":"","eventId":"25349","severity":"Low","summary":"Exchange Audit event 25349 records: Resume-Message Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Resume-Message Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25349.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Resume-Message Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25349\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25349} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25349","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25349","Event ID 25349","Resume-Message Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68262,"title":"Exchange Audit Event 25350 - Resume-MoveRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25350","Exchange"],"keywords":["25350","event 25350","event id 25350","Resume-MoveRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25350"],"errorCode":"","eventId":"25350","severity":"Low","summary":"Exchange Audit event 25350 records: Resume-MoveRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Resume-MoveRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25350.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Resume-MoveRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25350\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25350} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25350","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25350","Event ID 25350","Resume-MoveRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68263,"title":"Exchange Audit Event 25351 - Resume-PublicFolderReplication Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25351","Exchange"],"keywords":["25351","event 25351","event id 25351","Resume-PublicFolderReplication Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25351"],"errorCode":"","eventId":"25351","severity":"Low","summary":"Exchange Audit event 25351 records: Resume-PublicFolderReplication Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Resume-PublicFolderReplication Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25351.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Resume-PublicFolderReplication Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25351\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25351} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25351","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25351","Event ID 25351","Resume-PublicFolderReplication Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68264,"title":"Exchange Audit Event 25352 - Resume-Queue Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25352","Exchange"],"keywords":["25352","event 25352","event id 25352","Resume-Queue Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25352"],"errorCode":"","eventId":"25352","severity":"Low","summary":"Exchange Audit event 25352 records: Resume-Queue Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Resume-Queue Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25352.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Resume-Queue Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25352\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25352} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25352","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25352","Event ID 25352","Resume-Queue Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68265,"title":"Exchange Audit Event 25353 - Retry-Queue Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25353","Exchange"],"keywords":["25353","event 25353","event id 25353","Retry-Queue Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25353"],"errorCode":"","eventId":"25353","severity":"Low","summary":"Exchange Audit event 25353 records: Retry-Queue Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Retry-Queue Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25353.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Retry-Queue Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25353\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25353} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25353","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25353","Event ID 25353","Retry-Queue Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68266,"title":"Exchange Audit Event 25354 - Send-TextMessagingVerificationCode Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25354","Exchange"],"keywords":["25354","event 25354","event id 25354","Send-TextMessagingVerificationCode Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25354"],"errorCode":"","eventId":"25354","severity":"Low","summary":"Exchange Audit event 25354 records: Send-TextMessagingVerificationCode Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Send-TextMessagingVerificationCode Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25354.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Send-TextMessagingVerificationCode Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25354\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25354} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25354","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25354","Event ID 25354","Send-TextMessagingVerificationCode Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68267,"title":"Exchange Audit Event 25355 - Set-AcceptedDomain Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25355","Exchange"],"keywords":["25355","event 25355","event id 25355","Set-AcceptedDomain Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25355"],"errorCode":"","eventId":"25355","severity":"Low","summary":"Exchange Audit event 25355 records: Set-AcceptedDomain Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-AcceptedDomain Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25355.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-AcceptedDomain Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25355\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25355} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25355","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25355","Event ID 25355","Set-AcceptedDomain Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68268,"title":"Exchange Audit Event 25356 - Set-ActiveSyncDeviceAccessRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25356","Exchange"],"keywords":["25356","event 25356","event id 25356","Set-ActiveSyncDeviceAccessRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25356"],"errorCode":"","eventId":"25356","severity":"Low","summary":"Exchange Audit event 25356 records: Set-ActiveSyncDeviceAccessRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ActiveSyncDeviceAccessRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25356.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ActiveSyncDeviceAccessRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25356\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25356} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25356","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25356","Event ID 25356","Set-ActiveSyncDeviceAccessRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68269,"title":"Exchange Audit Event 25357 - Set-ActiveSyncMailboxPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25357","Exchange"],"keywords":["25357","event 25357","event id 25357","Set-ActiveSyncMailboxPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25357"],"errorCode":"","eventId":"25357","severity":"Medium","summary":"Exchange Audit event 25357 records: Set-ActiveSyncMailboxPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ActiveSyncMailboxPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25357.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ActiveSyncMailboxPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25357\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25357} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25357","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25357","Event ID 25357","Set-ActiveSyncMailboxPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68270,"title":"Exchange Audit Event 25358 - Set-ActiveSyncOrganizationSettings Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25358","Exchange"],"keywords":["25358","event 25358","event id 25358","Set-ActiveSyncOrganizationSettings Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25358"],"errorCode":"","eventId":"25358","severity":"Low","summary":"Exchange Audit event 25358 records: Set-ActiveSyncOrganizationSettings Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ActiveSyncOrganizationSettings Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25358.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ActiveSyncOrganizationSettings Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25358\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25358} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25358","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25358","Event ID 25358","Set-ActiveSyncOrganizationSettings Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68271,"title":"Exchange Audit Event 25359 - Set-ActiveSyncVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25359","Exchange"],"keywords":["25359","event 25359","event id 25359","Set-ActiveSyncVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25359"],"errorCode":"","eventId":"25359","severity":"Low","summary":"Exchange Audit event 25359 records: Set-ActiveSyncVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ActiveSyncVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25359.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ActiveSyncVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25359\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25359} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25359","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25359","Event ID 25359","Set-ActiveSyncVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68272,"title":"Exchange Audit Event 25360 - Set-AddressList Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25360","Exchange"],"keywords":["25360","event 25360","event id 25360","Set-AddressList Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25360"],"errorCode":"","eventId":"25360","severity":"Low","summary":"Exchange Audit event 25360 records: Set-AddressList Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-AddressList Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25360.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-AddressList Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25360\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25360} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25360","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25360","Event ID 25360","Set-AddressList Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68273,"title":"Exchange Audit Event 25361 - Set-AdminAuditLogConfig Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25361","Exchange"],"keywords":["25361","event 25361","event id 25361","Set-AdminAuditLogConfig Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25361"],"errorCode":"","eventId":"25361","severity":"Low","summary":"Exchange Audit event 25361 records: Set-AdminAuditLogConfig Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-AdminAuditLogConfig Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25361.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-AdminAuditLogConfig Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25361\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25361} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25361","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25361","Event ID 25361","Set-AdminAuditLogConfig Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68274,"title":"Exchange Audit Event 25362 - Set-ADServerSettings Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25362","Exchange"],"keywords":["25362","event 25362","event id 25362","Set-ADServerSettings Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25362"],"errorCode":"","eventId":"25362","severity":"Low","summary":"Exchange Audit event 25362 records: Set-ADServerSettings Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ADServerSettings Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25362.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ADServerSettings Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25362\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25362} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25362","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25362","Event ID 25362","Set-ADServerSettings Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68275,"title":"Exchange Audit Event 25363 - Set-ADSite Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25363","Exchange"],"keywords":["25363","event 25363","event id 25363","Set-ADSite Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25363"],"errorCode":"","eventId":"25363","severity":"Low","summary":"Exchange Audit event 25363 records: Set-ADSite Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ADSite Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25363.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ADSite Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25363\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25363} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25363","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25363","Event ID 25363","Set-ADSite Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68276,"title":"Exchange Audit Event 25364 - Set-AdSiteLink Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25364","Exchange"],"keywords":["25364","event 25364","event id 25364","Set-AdSiteLink Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25364"],"errorCode":"","eventId":"25364","severity":"Low","summary":"Exchange Audit event 25364 records: Set-AdSiteLink Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-AdSiteLink Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25364.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-AdSiteLink Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25364\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25364} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25364","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25364","Event ID 25364","Set-AdSiteLink Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68277,"title":"Exchange Audit Event 25365 - Set-AutodiscoverVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25365","Exchange"],"keywords":["25365","event 25365","event id 25365","Set-AutodiscoverVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25365"],"errorCode":"","eventId":"25365","severity":"Low","summary":"Exchange Audit event 25365 records: Set-AutodiscoverVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-AutodiscoverVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25365.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-AutodiscoverVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25365\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25365} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25365","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25365","Event ID 25365","Set-AutodiscoverVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68278,"title":"Exchange Audit Event 25366 - Set-AvailabilityConfig Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25366","Exchange"],"keywords":["25366","event 25366","event id 25366","Set-AvailabilityConfig Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25366"],"errorCode":"","eventId":"25366","severity":"Low","summary":"Exchange Audit event 25366 records: Set-AvailabilityConfig Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-AvailabilityConfig Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25366.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-AvailabilityConfig Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25366\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25366} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25366","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25366","Event ID 25366","Set-AvailabilityConfig Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68279,"title":"Exchange Audit Event 25367 - Set-AvailabilityReportOutage Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25367","Exchange"],"keywords":["25367","event 25367","event id 25367","Set-AvailabilityReportOutage Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25367"],"errorCode":"","eventId":"25367","severity":"Low","summary":"Exchange Audit event 25367 records: Set-AvailabilityReportOutage Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-AvailabilityReportOutage Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25367.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-AvailabilityReportOutage Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25367\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25367} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25367","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25367","Event ID 25367","Set-AvailabilityReportOutage Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68280,"title":"Exchange Audit Event 25368 - Set-CalendarNotification Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25368","Exchange"],"keywords":["25368","event 25368","event id 25368","Set-CalendarNotification Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25368"],"errorCode":"","eventId":"25368","severity":"Low","summary":"Exchange Audit event 25368 records: Set-CalendarNotification Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-CalendarNotification Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25368.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-CalendarNotification Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25368\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25368} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25368","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25368","Event ID 25368","Set-CalendarNotification Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68281,"title":"Exchange Audit Event 25369 - Set-CalendarProcessing Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25369","Exchange"],"keywords":["25369","event 25369","event id 25369","Set-CalendarProcessing Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25369"],"errorCode":"","eventId":"25369","severity":"Low","summary":"Exchange Audit event 25369 records: Set-CalendarProcessing Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-CalendarProcessing Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25369.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-CalendarProcessing Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25369\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25369} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25369","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25369","Event ID 25369","Set-CalendarProcessing Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68282,"title":"Exchange Audit Event 25370 - Set-CASMailbox Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25370","Exchange"],"keywords":["25370","event 25370","event id 25370","Set-CASMailbox Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25370"],"errorCode":"","eventId":"25370","severity":"Low","summary":"Exchange Audit event 25370 records: Set-CASMailbox Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-CASMailbox Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25370.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-CASMailbox Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25370\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25370} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25370","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25370","Event ID 25370","Set-CASMailbox Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68283,"title":"Exchange Audit Event 25371 - Set-ClientAccessArray Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25371","Exchange"],"keywords":["25371","event 25371","event id 25371","Set-ClientAccessArray Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25371"],"errorCode":"","eventId":"25371","severity":"Low","summary":"Exchange Audit event 25371 records: Set-ClientAccessArray Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ClientAccessArray Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25371.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ClientAccessArray Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25371\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25371} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25371","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25371","Event ID 25371","Set-ClientAccessArray Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68284,"title":"Exchange Audit Event 25372 - Set-ClientAccessServer Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25372","Exchange"],"keywords":["25372","event 25372","event id 25372","Set-ClientAccessServer Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25372"],"errorCode":"","eventId":"25372","severity":"Low","summary":"Exchange Audit event 25372 records: Set-ClientAccessServer Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ClientAccessServer Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25372.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ClientAccessServer Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25372\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25372} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25372","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25372","Event ID 25372","Set-ClientAccessServer Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68285,"title":"Exchange Audit Event 25373 - Set-CmdletExtensionAgent Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25373","Exchange"],"keywords":["25373","event 25373","event id 25373","Set-CmdletExtensionAgent Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25373"],"errorCode":"","eventId":"25373","severity":"Low","summary":"Exchange Audit event 25373 records: Set-CmdletExtensionAgent Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-CmdletExtensionAgent Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25373.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-CmdletExtensionAgent Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25373\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25373} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25373","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25373","Event ID 25373","Set-CmdletExtensionAgent Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68286,"title":"Exchange Audit Event 25374 - Set-Contact Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25374","Exchange"],"keywords":["25374","event 25374","event id 25374","Set-Contact Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25374"],"errorCode":"","eventId":"25374","severity":"Low","summary":"Exchange Audit event 25374 records: Set-Contact Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-Contact Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25374.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-Contact Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25374\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25374} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25374","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25374","Event ID 25374","Set-Contact Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68287,"title":"Exchange Audit Event 25375 - Set-ContentFilterConfig Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25375","Exchange"],"keywords":["25375","event 25375","event id 25375","Set-ContentFilterConfig Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25375"],"errorCode":"","eventId":"25375","severity":"Low","summary":"Exchange Audit event 25375 records: Set-ContentFilterConfig Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ContentFilterConfig Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25375.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ContentFilterConfig Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25375\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25375} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25375","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25375","Event ID 25375","Set-ContentFilterConfig Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68288,"title":"Exchange Audit Event 25376 - Set-DatabaseAvailabilityGroup Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25376","Exchange"],"keywords":["25376","event 25376","event id 25376","Set-DatabaseAvailabilityGroup Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25376"],"errorCode":"","eventId":"25376","severity":"Medium","summary":"Exchange Audit event 25376 records: Set-DatabaseAvailabilityGroup Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-DatabaseAvailabilityGroup Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25376.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-DatabaseAvailabilityGroup Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25376\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25376} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25376","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25376","Event ID 25376","Set-DatabaseAvailabilityGroup Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68289,"title":"Exchange Audit Event 25377 - Set-DatabaseAvailabilityGroupNetwork Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25377","Exchange"],"keywords":["25377","event 25377","event id 25377","Set-DatabaseAvailabilityGroupNetwork Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25377"],"errorCode":"","eventId":"25377","severity":"Medium","summary":"Exchange Audit event 25377 records: Set-DatabaseAvailabilityGroupNetwork Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-DatabaseAvailabilityGroupNetwork Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25377.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-DatabaseAvailabilityGroupNetwork Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25377\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25377} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25377","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25377","Event ID 25377","Set-DatabaseAvailabilityGroupNetwork Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68290,"title":"Exchange Audit Event 25378 - Set-DeliveryAgentConnector Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25378","Exchange"],"keywords":["25378","event 25378","event id 25378","Set-DeliveryAgentConnector Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25378"],"errorCode":"","eventId":"25378","severity":"Low","summary":"Exchange Audit event 25378 records: Set-DeliveryAgentConnector Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-DeliveryAgentConnector Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25378.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-DeliveryAgentConnector Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25378\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25378} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25378","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25378","Event ID 25378","Set-DeliveryAgentConnector Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68291,"title":"Exchange Audit Event 25379 - Set-DetailsTemplate Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25379","Exchange"],"keywords":["25379","event 25379","event id 25379","Set-DetailsTemplate Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25379"],"errorCode":"","eventId":"25379","severity":"Low","summary":"Exchange Audit event 25379 records: Set-DetailsTemplate Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-DetailsTemplate Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25379.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-DetailsTemplate Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25379\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25379} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25379","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25379","Event ID 25379","Set-DetailsTemplate Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68292,"title":"Exchange Audit Event 25380 - Set-DistributionGroup Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25380","Exchange"],"keywords":["25380","event 25380","event id 25380","Set-DistributionGroup Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25380"],"errorCode":"","eventId":"25380","severity":"Medium","summary":"Exchange Audit event 25380 records: Set-DistributionGroup Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-DistributionGroup Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25380.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-DistributionGroup Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25380\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25380} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25380","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25380","Event ID 25380","Set-DistributionGroup Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68293,"title":"Exchange Audit Event 25381 - Set-DynamicDistributionGroup Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25381","Exchange"],"keywords":["25381","event 25381","event id 25381","Set-DynamicDistributionGroup Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25381"],"errorCode":"","eventId":"25381","severity":"Medium","summary":"Exchange Audit event 25381 records: Set-DynamicDistributionGroup Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-DynamicDistributionGroup Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25381.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-DynamicDistributionGroup Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25381\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25381} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25381","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25381","Event ID 25381","Set-DynamicDistributionGroup Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68294,"title":"Exchange Audit Event 25382 - Set-EcpVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25382","Exchange"],"keywords":["25382","event 25382","event id 25382","Set-EcpVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25382"],"errorCode":"","eventId":"25382","severity":"Low","summary":"Exchange Audit event 25382 records: Set-EcpVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-EcpVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25382.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-EcpVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25382\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25382} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25382","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25382","Event ID 25382","Set-EcpVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68295,"title":"Exchange Audit Event 25383 - Set-EdgeSyncServiceConfig Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25383","Exchange"],"keywords":["25383","event 25383","event id 25383","Set-EdgeSyncServiceConfig Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25383"],"errorCode":"","eventId":"25383","severity":"Low","summary":"Exchange Audit event 25383 records: Set-EdgeSyncServiceConfig Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-EdgeSyncServiceConfig Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25383.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-EdgeSyncServiceConfig Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25383\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25383} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25383","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25383","Event ID 25383","Set-EdgeSyncServiceConfig Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68296,"title":"Exchange Audit Event 25384 - Set-EmailAddressPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25384","Exchange"],"keywords":["25384","event 25384","event id 25384","Set-EmailAddressPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25384"],"errorCode":"","eventId":"25384","severity":"Medium","summary":"Exchange Audit event 25384 records: Set-EmailAddressPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-EmailAddressPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25384.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-EmailAddressPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25384\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25384} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25384","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25384","Event ID 25384","Set-EmailAddressPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68297,"title":"Exchange Audit Event 25385 - Set-EventLogLevel Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25385","Exchange"],"keywords":["25385","event 25385","event id 25385","Set-EventLogLevel Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25385"],"errorCode":"","eventId":"25385","severity":"Low","summary":"Exchange Audit event 25385 records: Set-EventLogLevel Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-EventLogLevel Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25385.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-EventLogLevel Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25385\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25385} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25385","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25385","Event ID 25385","Set-EventLogLevel Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68298,"title":"Exchange Audit Event 25386 - Set-ExchangeAssistanceConfig Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25386","Exchange"],"keywords":["25386","event 25386","event id 25386","Set-ExchangeAssistanceConfig Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25386"],"errorCode":"","eventId":"25386","severity":"Low","summary":"Exchange Audit event 25386 records: Set-ExchangeAssistanceConfig Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ExchangeAssistanceConfig Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25386.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ExchangeAssistanceConfig Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25386\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25386} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25386","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25386","Event ID 25386","Set-ExchangeAssistanceConfig Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68299,"title":"Exchange Audit Event 25387 - Set-ExchangeServer Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25387","Exchange"],"keywords":["25387","event 25387","event id 25387","Set-ExchangeServer Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25387"],"errorCode":"","eventId":"25387","severity":"Low","summary":"Exchange Audit event 25387 records: Set-ExchangeServer Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ExchangeServer Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25387.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ExchangeServer Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25387\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25387} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25387","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25387","Event ID 25387","Set-ExchangeServer Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68300,"title":"Exchange Audit Event 25388 - Set-FederatedOrganizationIdentifier Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25388","Exchange"],"keywords":["25388","event 25388","event id 25388","Set-FederatedOrganizationIdentifier Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25388"],"errorCode":"","eventId":"25388","severity":"Low","summary":"Exchange Audit event 25388 records: Set-FederatedOrganizationIdentifier Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-FederatedOrganizationIdentifier Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25388.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-FederatedOrganizationIdentifier Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25388\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25388} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25388","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25388","Event ID 25388","Set-FederatedOrganizationIdentifier Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68301,"title":"Exchange Audit Event 25389 - Set-FederationTrust Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25389","Exchange"],"keywords":["25389","event 25389","event id 25389","Set-FederationTrust Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25389"],"errorCode":"","eventId":"25389","severity":"Medium","summary":"Exchange Audit event 25389 records: Set-FederationTrust Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-FederationTrust Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25389.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-FederationTrust Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25389\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25389} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25389","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25389","Event ID 25389","Set-FederationTrust Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68302,"title":"Exchange Audit Event 25390 - Set-ForeignConnector Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25390","Exchange"],"keywords":["25390","event 25390","event id 25390","Set-ForeignConnector Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25390"],"errorCode":"","eventId":"25390","severity":"Low","summary":"Exchange Audit event 25390 records: Set-ForeignConnector Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ForeignConnector Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25390.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ForeignConnector Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25390\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25390} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25390","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25390","Event ID 25390","Set-ForeignConnector Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68303,"title":"Exchange Audit Event 25391 - Set-GlobalAddressList Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25391","Exchange"],"keywords":["25391","event 25391","event id 25391","Set-GlobalAddressList Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25391"],"errorCode":"","eventId":"25391","severity":"Low","summary":"Exchange Audit event 25391 records: Set-GlobalAddressList Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-GlobalAddressList Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25391.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-GlobalAddressList Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25391\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25391} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25391","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25391","Event ID 25391","Set-GlobalAddressList Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68304,"title":"Exchange Audit Event 25392 - Set-Group Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25392","Exchange"],"keywords":["25392","event 25392","event id 25392","Set-Group Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25392"],"errorCode":"","eventId":"25392","severity":"Medium","summary":"Exchange Audit event 25392 records: Set-Group Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-Group Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25392.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-Group Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25392\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25392} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25392","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25392","Event ID 25392","Set-Group Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68305,"title":"Exchange Audit Event 25393 - Set-ImapSettings Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25393","Exchange"],"keywords":["25393","event 25393","event id 25393","Set-ImapSettings Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25393"],"errorCode":"","eventId":"25393","severity":"Low","summary":"Exchange Audit event 25393 records: Set-ImapSettings Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ImapSettings Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25393.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ImapSettings Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25393\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25393} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25393","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25393","Event ID 25393","Set-ImapSettings Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68306,"title":"Exchange Audit Event 25394 - Set-InboxRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25394","Exchange"],"keywords":["25394","event 25394","event id 25394","Set-InboxRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25394"],"errorCode":"","eventId":"25394","severity":"Low","summary":"Exchange Audit event 25394 records: Set-InboxRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-InboxRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25394.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-InboxRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25394\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25394} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25394","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25394","Event ID 25394","Set-InboxRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68307,"title":"Exchange Audit Event 25395 - Set-IPAllowListConfig Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25395","Exchange"],"keywords":["25395","event 25395","event id 25395","Set-IPAllowListConfig Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25395"],"errorCode":"","eventId":"25395","severity":"Low","summary":"Exchange Audit event 25395 records: Set-IPAllowListConfig Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-IPAllowListConfig Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25395.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-IPAllowListConfig Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25395\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25395} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25395","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25395","Event ID 25395","Set-IPAllowListConfig Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68308,"title":"Exchange Audit Event 25396 - Set-IPAllowListProvider Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25396","Exchange"],"keywords":["25396","event 25396","event id 25396","Set-IPAllowListProvider Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25396"],"errorCode":"","eventId":"25396","severity":"Low","summary":"Exchange Audit event 25396 records: Set-IPAllowListProvider Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-IPAllowListProvider Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25396.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-IPAllowListProvider Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25396\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25396} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25396","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25396","Event ID 25396","Set-IPAllowListProvider Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68309,"title":"Exchange Audit Event 25397 - Set-IPAllowListProvidersConfig Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25397","Exchange"],"keywords":["25397","event 25397","event id 25397","Set-IPAllowListProvidersConfig Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25397"],"errorCode":"","eventId":"25397","severity":"Low","summary":"Exchange Audit event 25397 records: Set-IPAllowListProvidersConfig Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-IPAllowListProvidersConfig Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25397.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-IPAllowListProvidersConfig Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25397\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25397} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25397","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25397","Event ID 25397","Set-IPAllowListProvidersConfig Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68310,"title":"Exchange Audit Event 25398 - Set-IPBlockListConfig Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25398","Exchange"],"keywords":["25398","event 25398","event id 25398","Set-IPBlockListConfig Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25398"],"errorCode":"","eventId":"25398","severity":"Low","summary":"Exchange Audit event 25398 records: Set-IPBlockListConfig Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-IPBlockListConfig Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25398.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-IPBlockListConfig Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25398\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25398} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25398","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25398","Event ID 25398","Set-IPBlockListConfig Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68311,"title":"Exchange Audit Event 25399 - Set-IPBlockListProvider Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25399","Exchange"],"keywords":["25399","event 25399","event id 25399","Set-IPBlockListProvider Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25399"],"errorCode":"","eventId":"25399","severity":"Low","summary":"Exchange Audit event 25399 records: Set-IPBlockListProvider Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-IPBlockListProvider Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25399.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-IPBlockListProvider Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25399\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25399} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25399","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25399","Event ID 25399","Set-IPBlockListProvider Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68312,"title":"Exchange Audit Event 25400 - Set-IPBlockListProvidersConfig Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25400","Exchange"],"keywords":["25400","event 25400","event id 25400","Set-IPBlockListProvidersConfig Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25400"],"errorCode":"","eventId":"25400","severity":"Low","summary":"Exchange Audit event 25400 records: Set-IPBlockListProvidersConfig Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-IPBlockListProvidersConfig Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25400.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-IPBlockListProvidersConfig Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25400\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25400} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25400","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25400","Event ID 25400","Set-IPBlockListProvidersConfig Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68313,"title":"Exchange Audit Event 25401 - Set-IRMConfiguration Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25401","Exchange"],"keywords":["25401","event 25401","event id 25401","Set-IRMConfiguration Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25401"],"errorCode":"","eventId":"25401","severity":"Low","summary":"Exchange Audit event 25401 records: Set-IRMConfiguration Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-IRMConfiguration Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25401.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-IRMConfiguration Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25401\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25401} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25401","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25401","Event ID 25401","Set-IRMConfiguration Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68314,"title":"Exchange Audit Event 25402 - Set-JournalRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25402","Exchange"],"keywords":["25402","event 25402","event id 25402","Set-JournalRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25402"],"errorCode":"","eventId":"25402","severity":"Low","summary":"Exchange Audit event 25402 records: Set-JournalRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-JournalRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25402.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-JournalRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25402\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25402} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25402","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25402","Event ID 25402","Set-JournalRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68315,"title":"Exchange Audit Event 25403 - Set-Mailbox Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25403","Exchange"],"keywords":["25403","event 25403","event id 25403","Set-Mailbox Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25403"],"errorCode":"","eventId":"25403","severity":"Low","summary":"Exchange Audit event 25403 records: Set-Mailbox Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-Mailbox Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25403.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-Mailbox Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25403\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25403} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25403","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25403","Event ID 25403","Set-Mailbox Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68316,"title":"Exchange Audit Event 25404 - Set-MailboxAuditBypassAssociation Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25404","Exchange"],"keywords":["25404","event 25404","event id 25404","Set-MailboxAuditBypassAssociation Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25404"],"errorCode":"","eventId":"25404","severity":"Low","summary":"Exchange Audit event 25404 records: Set-MailboxAuditBypassAssociation Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MailboxAuditBypassAssociation Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25404.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MailboxAuditBypassAssociation Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25404\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25404} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25404","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25404","Event ID 25404","Set-MailboxAuditBypassAssociation Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68317,"title":"Exchange Audit Event 25405 - Set-MailboxAutoReplyConfiguration Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25405","Exchange"],"keywords":["25405","event 25405","event id 25405","Set-MailboxAutoReplyConfiguration Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25405"],"errorCode":"","eventId":"25405","severity":"Low","summary":"Exchange Audit event 25405 records: Set-MailboxAutoReplyConfiguration Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MailboxAutoReplyConfiguration Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25405.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MailboxAutoReplyConfiguration Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25405\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25405} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25405","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25405","Event ID 25405","Set-MailboxAutoReplyConfiguration Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68318,"title":"Exchange Audit Event 25406 - Set-MailboxCalendarConfiguration Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25406","Exchange"],"keywords":["25406","event 25406","event id 25406","Set-MailboxCalendarConfiguration Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25406"],"errorCode":"","eventId":"25406","severity":"Low","summary":"Exchange Audit event 25406 records: Set-MailboxCalendarConfiguration Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MailboxCalendarConfiguration Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25406.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MailboxCalendarConfiguration Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25406\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25406} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25406","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25406","Event ID 25406","Set-MailboxCalendarConfiguration Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68319,"title":"Exchange Audit Event 25407 - Set-MailboxCalendarFolder Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25407","Exchange"],"keywords":["25407","event 25407","event id 25407","Set-MailboxCalendarFolder Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25407"],"errorCode":"","eventId":"25407","severity":"Low","summary":"Exchange Audit event 25407 records: Set-MailboxCalendarFolder Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MailboxCalendarFolder Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25407.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MailboxCalendarFolder Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25407\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25407} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25407","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25407","Event ID 25407","Set-MailboxCalendarFolder Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68320,"title":"Exchange Audit Event 25408 - Set-MailboxDatabase Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25408","Exchange"],"keywords":["25408","event 25408","event id 25408","Set-MailboxDatabase Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25408"],"errorCode":"","eventId":"25408","severity":"Low","summary":"Exchange Audit event 25408 records: Set-MailboxDatabase Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MailboxDatabase Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25408.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MailboxDatabase Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25408\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25408} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25408","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25408","Event ID 25408","Set-MailboxDatabase Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68321,"title":"Exchange Audit Event 25409 - Set-MailboxDatabaseCopy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25409","Exchange"],"keywords":["25409","event 25409","event id 25409","Set-MailboxDatabaseCopy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25409"],"errorCode":"","eventId":"25409","severity":"Low","summary":"Exchange Audit event 25409 records: Set-MailboxDatabaseCopy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MailboxDatabaseCopy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25409.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MailboxDatabaseCopy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25409\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25409} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25409","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25409","Event ID 25409","Set-MailboxDatabaseCopy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68322,"title":"Exchange Audit Event 25410 - Set-MailboxFolderPermission Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25410","Exchange"],"keywords":["25410","event 25410","event id 25410","Set-MailboxFolderPermission Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25410"],"errorCode":"","eventId":"25410","severity":"Medium","summary":"Exchange Audit event 25410 records: Set-MailboxFolderPermission Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MailboxFolderPermission Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25410.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MailboxFolderPermission Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25410\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25410} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25410","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25410","Event ID 25410","Set-MailboxFolderPermission Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68323,"title":"Exchange Audit Event 25411 - Set-MailboxJunkEmailConfiguration Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25411","Exchange"],"keywords":["25411","event 25411","event id 25411","Set-MailboxJunkEmailConfiguration Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25411"],"errorCode":"","eventId":"25411","severity":"Low","summary":"Exchange Audit event 25411 records: Set-MailboxJunkEmailConfiguration Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MailboxJunkEmailConfiguration Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25411.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MailboxJunkEmailConfiguration Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25411\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25411} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25411","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25411","Event ID 25411","Set-MailboxJunkEmailConfiguration Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68324,"title":"Exchange Audit Event 25412 - Set-MailboxMessageConfiguration Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25412","Exchange"],"keywords":["25412","event 25412","event id 25412","Set-MailboxMessageConfiguration Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25412"],"errorCode":"","eventId":"25412","severity":"Low","summary":"Exchange Audit event 25412 records: Set-MailboxMessageConfiguration Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MailboxMessageConfiguration Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25412.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MailboxMessageConfiguration Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25412\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25412} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25412","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25412","Event ID 25412","Set-MailboxMessageConfiguration Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68325,"title":"Exchange Audit Event 25413 - Set-MailboxRegionalConfiguration Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25413","Exchange"],"keywords":["25413","event 25413","event id 25413","Set-MailboxRegionalConfiguration Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25413"],"errorCode":"","eventId":"25413","severity":"Low","summary":"Exchange Audit event 25413 records: Set-MailboxRegionalConfiguration Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MailboxRegionalConfiguration Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25413.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MailboxRegionalConfiguration Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25413\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25413} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25413","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25413","Event ID 25413","Set-MailboxRegionalConfiguration Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68326,"title":"Exchange Audit Event 25414 - Set-MailboxRestoreRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25414","Exchange"],"keywords":["25414","event 25414","event id 25414","Set-MailboxRestoreRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25414"],"errorCode":"","eventId":"25414","severity":"Low","summary":"Exchange Audit event 25414 records: Set-MailboxRestoreRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MailboxRestoreRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25414.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MailboxRestoreRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25414\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25414} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25414","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25414","Event ID 25414","Set-MailboxRestoreRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68327,"title":"Exchange Audit Event 25415 - Set-MailboxServer Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25415","Exchange"],"keywords":["25415","event 25415","event id 25415","Set-MailboxServer Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25415"],"errorCode":"","eventId":"25415","severity":"Low","summary":"Exchange Audit event 25415 records: Set-MailboxServer Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MailboxServer Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25415.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MailboxServer Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25415\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25415} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25415","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25415","Event ID 25415","Set-MailboxServer Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68328,"title":"Exchange Audit Event 25416 - Set-MailboxSpellingConfiguration Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25416","Exchange"],"keywords":["25416","event 25416","event id 25416","Set-MailboxSpellingConfiguration Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25416"],"errorCode":"","eventId":"25416","severity":"Low","summary":"Exchange Audit event 25416 records: Set-MailboxSpellingConfiguration Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MailboxSpellingConfiguration Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25416.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MailboxSpellingConfiguration Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25416\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25416} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25416","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25416","Event ID 25416","Set-MailboxSpellingConfiguration Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68329,"title":"Exchange Audit Event 25417 - Set-MailContact Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25417","Exchange"],"keywords":["25417","event 25417","event id 25417","Set-MailContact Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25417"],"errorCode":"","eventId":"25417","severity":"Low","summary":"Exchange Audit event 25417 records: Set-MailContact Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MailContact Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25417.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MailContact Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25417\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25417} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25417","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25417","Event ID 25417","Set-MailContact Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68330,"title":"Exchange Audit Event 25418 - Set-MailPublicFolder Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25418","Exchange"],"keywords":["25418","event 25418","event id 25418","Set-MailPublicFolder Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25418"],"errorCode":"","eventId":"25418","severity":"Low","summary":"Exchange Audit event 25418 records: Set-MailPublicFolder Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MailPublicFolder Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25418.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MailPublicFolder Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25418\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25418} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25418","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25418","Event ID 25418","Set-MailPublicFolder Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68331,"title":"Exchange Audit Event 25419 - Set-MailUser Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25419","Exchange"],"keywords":["25419","event 25419","event id 25419","Set-MailUser Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25419"],"errorCode":"","eventId":"25419","severity":"Low","summary":"Exchange Audit event 25419 records: Set-MailUser Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MailUser Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25419.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MailUser Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25419\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25419} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25419","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25419","Event ID 25419","Set-MailUser Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68332,"title":"Exchange Audit Event 25420 - Set-ManagedContentSettings Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25420","Exchange"],"keywords":["25420","event 25420","event id 25420","Set-ManagedContentSettings Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25420"],"errorCode":"","eventId":"25420","severity":"Low","summary":"Exchange Audit event 25420 records: Set-ManagedContentSettings Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ManagedContentSettings Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25420.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ManagedContentSettings Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25420\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25420} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25420","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25420","Event ID 25420","Set-ManagedContentSettings Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68333,"title":"Exchange Audit Event 25421 - Set-ManagedFolder Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25421","Exchange"],"keywords":["25421","event 25421","event id 25421","Set-ManagedFolder Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25421"],"errorCode":"","eventId":"25421","severity":"Low","summary":"Exchange Audit event 25421 records: Set-ManagedFolder Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ManagedFolder Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25421.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ManagedFolder Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25421\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25421} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25421","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25421","Event ID 25421","Set-ManagedFolder Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68334,"title":"Exchange Audit Event 25422 - Set-ManagedFolderMailboxPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25422","Exchange"],"keywords":["25422","event 25422","event id 25422","Set-ManagedFolderMailboxPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25422"],"errorCode":"","eventId":"25422","severity":"Medium","summary":"Exchange Audit event 25422 records: Set-ManagedFolderMailboxPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ManagedFolderMailboxPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25422.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ManagedFolderMailboxPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25422\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25422} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25422","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25422","Event ID 25422","Set-ManagedFolderMailboxPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68335,"title":"Exchange Audit Event 25423 - Set-ManagementRoleAssignment Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25423","Exchange"],"keywords":["25423","event 25423","event id 25423","Set-ManagementRoleAssignment Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25423"],"errorCode":"","eventId":"25423","severity":"Medium","summary":"Exchange Audit event 25423 records: Set-ManagementRoleAssignment Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ManagementRoleAssignment Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25423.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ManagementRoleAssignment Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25423\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25423} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25423","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25423","Event ID 25423","Set-ManagementRoleAssignment Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68336,"title":"Exchange Audit Event 25424 - Set-ManagementRoleEntry Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25424","Exchange"],"keywords":["25424","event 25424","event id 25424","Set-ManagementRoleEntry Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25424"],"errorCode":"","eventId":"25424","severity":"Medium","summary":"Exchange Audit event 25424 records: Set-ManagementRoleEntry Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ManagementRoleEntry Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25424.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ManagementRoleEntry Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25424\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25424} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25424","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25424","Event ID 25424","Set-ManagementRoleEntry Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68337,"title":"Exchange Audit Event 25425 - Set-ManagementScope Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25425","Exchange"],"keywords":["25425","event 25425","event id 25425","Set-ManagementScope Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25425"],"errorCode":"","eventId":"25425","severity":"Low","summary":"Exchange Audit event 25425 records: Set-ManagementScope Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ManagementScope Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25425.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ManagementScope Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25425\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25425} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25425","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25425","Event ID 25425","Set-ManagementScope Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68338,"title":"Exchange Audit Event 25426 - Set-MessageClassification Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25426","Exchange"],"keywords":["25426","event 25426","event id 25426","Set-MessageClassification Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25426"],"errorCode":"","eventId":"25426","severity":"Low","summary":"Exchange Audit event 25426 records: Set-MessageClassification Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MessageClassification Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25426.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MessageClassification Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25426\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25426} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25426","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25426","Event ID 25426","Set-MessageClassification Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68339,"title":"Exchange Audit Event 25427 - Set-MoveRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25427","Exchange"],"keywords":["25427","event 25427","event id 25427","Set-MoveRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25427"],"errorCode":"","eventId":"25427","severity":"Low","summary":"Exchange Audit event 25427 records: Set-MoveRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MoveRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25427.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MoveRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25427\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25427} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25427","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25427","Event ID 25427","Set-MoveRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68340,"title":"Exchange Audit Event 25428 - Set-OabVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25428","Exchange"],"keywords":["25428","event 25428","event id 25428","Set-OabVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25428"],"errorCode":"","eventId":"25428","severity":"Low","summary":"Exchange Audit event 25428 records: Set-OabVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-OabVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25428.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-OabVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25428\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25428} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25428","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25428","Event ID 25428","Set-OabVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68341,"title":"Exchange Audit Event 25429 - Set-OfflineAddressBook Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25429","Exchange"],"keywords":["25429","event 25429","event id 25429","Set-OfflineAddressBook Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25429"],"errorCode":"","eventId":"25429","severity":"Low","summary":"Exchange Audit event 25429 records: Set-OfflineAddressBook Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-OfflineAddressBook Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25429.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-OfflineAddressBook Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25429\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25429} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25429","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25429","Event ID 25429","Set-OfflineAddressBook Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68342,"title":"Exchange Audit Event 25430 - Set-OrganizationConfig Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25430","Exchange"],"keywords":["25430","event 25430","event id 25430","Set-OrganizationConfig Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25430"],"errorCode":"","eventId":"25430","severity":"Low","summary":"Exchange Audit event 25430 records: Set-OrganizationConfig Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-OrganizationConfig Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25430.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-OrganizationConfig Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25430\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25430} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25430","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25430","Event ID 25430","Set-OrganizationConfig Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68343,"title":"Exchange Audit Event 25431 - Set-OrganizationRelationship Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25431","Exchange"],"keywords":["25431","event 25431","event id 25431","Set-OrganizationRelationship Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25431"],"errorCode":"","eventId":"25431","severity":"Low","summary":"Exchange Audit event 25431 records: Set-OrganizationRelationship Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-OrganizationRelationship Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25431.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-OrganizationRelationship Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25431\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25431} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25431","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25431","Event ID 25431","Set-OrganizationRelationship Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68344,"title":"Exchange Audit Event 25432 - Set-OutlookAnywhere Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25432","Exchange"],"keywords":["25432","event 25432","event id 25432","Set-OutlookAnywhere Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25432"],"errorCode":"","eventId":"25432","severity":"Low","summary":"Exchange Audit event 25432 records: Set-OutlookAnywhere Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-OutlookAnywhere Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25432.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-OutlookAnywhere Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25432\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25432} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25432","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25432","Event ID 25432","Set-OutlookAnywhere Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68345,"title":"Exchange Audit Event 25433 - Set-OutlookProtectionRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25433","Exchange"],"keywords":["25433","event 25433","event id 25433","Set-OutlookProtectionRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25433"],"errorCode":"","eventId":"25433","severity":"Low","summary":"Exchange Audit event 25433 records: Set-OutlookProtectionRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-OutlookProtectionRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25433.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-OutlookProtectionRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25433\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25433} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25433","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25433","Event ID 25433","Set-OutlookProtectionRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68346,"title":"Exchange Audit Event 25434 - Set-OutlookProvider Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25434","Exchange"],"keywords":["25434","event 25434","event id 25434","Set-OutlookProvider Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25434"],"errorCode":"","eventId":"25434","severity":"Low","summary":"Exchange Audit event 25434 records: Set-OutlookProvider Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-OutlookProvider Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25434.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-OutlookProvider Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25434\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25434} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25434","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25434","Event ID 25434","Set-OutlookProvider Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68347,"title":"Exchange Audit Event 25435 - Set-OwaMailboxPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25435","Exchange"],"keywords":["25435","event 25435","event id 25435","Set-OwaMailboxPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25435"],"errorCode":"","eventId":"25435","severity":"Medium","summary":"Exchange Audit event 25435 records: Set-OwaMailboxPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-OwaMailboxPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25435.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-OwaMailboxPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25435\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25435} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25435","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25435","Event ID 25435","Set-OwaMailboxPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68348,"title":"Exchange Audit Event 25436 - Set-OwaVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25436","Exchange"],"keywords":["25436","event 25436","event id 25436","Set-OwaVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25436"],"errorCode":"","eventId":"25436","severity":"Low","summary":"Exchange Audit event 25436 records: Set-OwaVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-OwaVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25436.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-OwaVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25436\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25436} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25436","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25436","Event ID 25436","Set-OwaVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68349,"title":"Exchange Audit Event 25437 - Set-PopSettings Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25437","Exchange"],"keywords":["25437","event 25437","event id 25437","Set-PopSettings Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25437"],"errorCode":"","eventId":"25437","severity":"Low","summary":"Exchange Audit event 25437 records: Set-PopSettings Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-PopSettings Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25437.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-PopSettings Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25437\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25437} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25437","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25437","Event ID 25437","Set-PopSettings Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68350,"title":"Exchange Audit Event 25438 - Set-PowerShellVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25438","Exchange"],"keywords":["25438","event 25438","event id 25438","Set-PowerShellVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25438"],"errorCode":"","eventId":"25438","severity":"Low","summary":"Exchange Audit event 25438 records: Set-PowerShellVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-PowerShellVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25438.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-PowerShellVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25438\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25438} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25438","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25438","Event ID 25438","Set-PowerShellVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68351,"title":"Exchange Audit Event 25439 - Set-PublicFolder Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25439","Exchange"],"keywords":["25439","event 25439","event id 25439","Set-PublicFolder Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25439"],"errorCode":"","eventId":"25439","severity":"Low","summary":"Exchange Audit event 25439 records: Set-PublicFolder Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-PublicFolder Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25439.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-PublicFolder Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25439\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25439} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25439","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25439","Event ID 25439","Set-PublicFolder Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68352,"title":"Exchange Audit Event 25440 - Set-PublicFolderDatabase Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25440","Exchange"],"keywords":["25440","event 25440","event id 25440","Set-PublicFolderDatabase Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25440"],"errorCode":"","eventId":"25440","severity":"Low","summary":"Exchange Audit event 25440 records: Set-PublicFolderDatabase Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-PublicFolderDatabase Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25440.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-PublicFolderDatabase Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25440\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25440} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25440","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25440","Event ID 25440","Set-PublicFolderDatabase Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68353,"title":"Exchange Audit Event 25441 - Set-ReceiveConnector Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25441","Exchange"],"keywords":["25441","event 25441","event id 25441","Set-ReceiveConnector Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25441"],"errorCode":"","eventId":"25441","severity":"Low","summary":"Exchange Audit event 25441 records: Set-ReceiveConnector Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ReceiveConnector Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25441.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ReceiveConnector Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25441\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25441} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25441","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25441","Event ID 25441","Set-ReceiveConnector Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68354,"title":"Exchange Audit Event 25442 - Set-RecipientFilterConfig Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25442","Exchange"],"keywords":["25442","event 25442","event id 25442","Set-RecipientFilterConfig Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25442"],"errorCode":"","eventId":"25442","severity":"Low","summary":"Exchange Audit event 25442 records: Set-RecipientFilterConfig Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-RecipientFilterConfig Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25442.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-RecipientFilterConfig Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25442\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25442} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25442","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25442","Event ID 25442","Set-RecipientFilterConfig Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68355,"title":"Exchange Audit Event 25443 - Set-RemoteDomain Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25443","Exchange"],"keywords":["25443","event 25443","event id 25443","Set-RemoteDomain Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25443"],"errorCode":"","eventId":"25443","severity":"Low","summary":"Exchange Audit event 25443 records: Set-RemoteDomain Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-RemoteDomain Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25443.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-RemoteDomain Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25443\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25443} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25443","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25443","Event ID 25443","Set-RemoteDomain Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68356,"title":"Exchange Audit Event 25444 - Set-RemoteMailbox Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25444","Exchange"],"keywords":["25444","event 25444","event id 25444","Set-RemoteMailbox Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25444"],"errorCode":"","eventId":"25444","severity":"Low","summary":"Exchange Audit event 25444 records: Set-RemoteMailbox Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-RemoteMailbox Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25444.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-RemoteMailbox Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25444\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25444} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25444","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25444","Event ID 25444","Set-RemoteMailbox Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68357,"title":"Exchange Audit Event 25445 - Set-ResourceConfig Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25445","Exchange"],"keywords":["25445","event 25445","event id 25445","Set-ResourceConfig Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25445"],"errorCode":"","eventId":"25445","severity":"Low","summary":"Exchange Audit event 25445 records: Set-ResourceConfig Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ResourceConfig Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25445.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ResourceConfig Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25445\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25445} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25445","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25445","Event ID 25445","Set-ResourceConfig Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68358,"title":"Exchange Audit Event 25446 - Set-RetentionPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25446","Exchange"],"keywords":["25446","event 25446","event id 25446","Set-RetentionPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25446"],"errorCode":"","eventId":"25446","severity":"Medium","summary":"Exchange Audit event 25446 records: Set-RetentionPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-RetentionPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25446.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-RetentionPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25446\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25446} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25446","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25446","Event ID 25446","Set-RetentionPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68359,"title":"Exchange Audit Event 25447 - Set-RetentionPolicyTag Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25447","Exchange"],"keywords":["25447","event 25447","event id 25447","Set-RetentionPolicyTag Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25447"],"errorCode":"","eventId":"25447","severity":"Medium","summary":"Exchange Audit event 25447 records: Set-RetentionPolicyTag Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-RetentionPolicyTag Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25447.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-RetentionPolicyTag Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25447\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25447} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25447","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25447","Event ID 25447","Set-RetentionPolicyTag Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68360,"title":"Exchange Audit Event 25448 - Set-RoleAssignmentPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25448","Exchange"],"keywords":["25448","event 25448","event id 25448","Set-RoleAssignmentPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25448"],"errorCode":"","eventId":"25448","severity":"Medium","summary":"Exchange Audit event 25448 records: Set-RoleAssignmentPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-RoleAssignmentPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25448.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-RoleAssignmentPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25448\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25448} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25448","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25448","Event ID 25448","Set-RoleAssignmentPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68361,"title":"Exchange Audit Event 25449 - Set-RoleGroup Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25449","Exchange"],"keywords":["25449","event 25449","event id 25449","Set-RoleGroup Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25449"],"errorCode":"","eventId":"25449","severity":"Medium","summary":"Exchange Audit event 25449 records: Set-RoleGroup Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-RoleGroup Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25449.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-RoleGroup Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25449\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25449} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25449","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25449","Event ID 25449","Set-RoleGroup Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68362,"title":"Exchange Audit Event 25450 - Set-RoutingGroupConnector Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25450","Exchange"],"keywords":["25450","event 25450","event id 25450","Set-RoutingGroupConnector Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25450"],"errorCode":"","eventId":"25450","severity":"Medium","summary":"Exchange Audit event 25450 records: Set-RoutingGroupConnector Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-RoutingGroupConnector Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25450.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-RoutingGroupConnector Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25450\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25450} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25450","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25450","Event ID 25450","Set-RoutingGroupConnector Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68363,"title":"Exchange Audit Event 25451 - Set-RpcClientAccess Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25451","Exchange"],"keywords":["25451","event 25451","event id 25451","Set-RpcClientAccess Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25451"],"errorCode":"","eventId":"25451","severity":"Low","summary":"Exchange Audit event 25451 records: Set-RpcClientAccess Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-RpcClientAccess Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25451.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-RpcClientAccess Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25451\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25451} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25451","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25451","Event ID 25451","Set-RpcClientAccess Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68364,"title":"Exchange Audit Event 25452 - Set-SendConnector Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25452","Exchange"],"keywords":["25452","event 25452","event id 25452","Set-SendConnector Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25452"],"errorCode":"","eventId":"25452","severity":"Low","summary":"Exchange Audit event 25452 records: Set-SendConnector Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-SendConnector Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25452.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-SendConnector Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25452\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25452} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25452","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25452","Event ID 25452","Set-SendConnector Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68365,"title":"Exchange Audit Event 25453 - Set-SenderFilterConfig Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25453","Exchange"],"keywords":["25453","event 25453","event id 25453","Set-SenderFilterConfig Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25453"],"errorCode":"","eventId":"25453","severity":"Low","summary":"Exchange Audit event 25453 records: Set-SenderFilterConfig Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-SenderFilterConfig Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25453.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-SenderFilterConfig Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25453\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25453} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25453","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25453","Event ID 25453","Set-SenderFilterConfig Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68366,"title":"Exchange Audit Event 25454 - Set-SenderIdConfig Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25454","Exchange"],"keywords":["25454","event 25454","event id 25454","Set-SenderIdConfig Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25454"],"errorCode":"","eventId":"25454","severity":"Low","summary":"Exchange Audit event 25454 records: Set-SenderIdConfig Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-SenderIdConfig Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25454.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-SenderIdConfig Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25454\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25454} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25454","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25454","Event ID 25454","Set-SenderIdConfig Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68367,"title":"Exchange Audit Event 25455 - Set-SenderReputationConfig Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25455","Exchange"],"keywords":["25455","event 25455","event id 25455","Set-SenderReputationConfig Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25455"],"errorCode":"","eventId":"25455","severity":"Low","summary":"Exchange Audit event 25455 records: Set-SenderReputationConfig Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-SenderReputationConfig Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25455.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-SenderReputationConfig Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25455\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25455} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25455","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25455","Event ID 25455","Set-SenderReputationConfig Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68368,"title":"Exchange Audit Event 25456 - Set-SharingPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25456","Exchange"],"keywords":["25456","event 25456","event id 25456","Set-SharingPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25456"],"errorCode":"","eventId":"25456","severity":"Medium","summary":"Exchange Audit event 25456 records: Set-SharingPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-SharingPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25456.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-SharingPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25456\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25456} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25456","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25456","Event ID 25456","Set-SharingPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68369,"title":"Exchange Audit Event 25457 - Set-SystemMessage Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25457","Exchange"],"keywords":["25457","event 25457","event id 25457","Set-SystemMessage Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25457"],"errorCode":"","eventId":"25457","severity":"Low","summary":"Exchange Audit event 25457 records: Set-SystemMessage Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-SystemMessage Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25457.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-SystemMessage Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25457\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25457} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25457","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25457","Event ID 25457","Set-SystemMessage Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68370,"title":"Exchange Audit Event 25458 - Set-TextMessagingAccount Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25458","Exchange"],"keywords":["25458","event 25458","event id 25458","Set-TextMessagingAccount Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25458"],"errorCode":"","eventId":"25458","severity":"Low","summary":"Exchange Audit event 25458 records: Set-TextMessagingAccount Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-TextMessagingAccount Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25458.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-TextMessagingAccount Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25458\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25458} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25458","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25458","Event ID 25458","Set-TextMessagingAccount Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68371,"title":"Exchange Audit Event 25459 - Set-ThrottlingPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25459","Exchange"],"keywords":["25459","event 25459","event id 25459","Set-ThrottlingPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25459"],"errorCode":"","eventId":"25459","severity":"Medium","summary":"Exchange Audit event 25459 records: Set-ThrottlingPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ThrottlingPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25459.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ThrottlingPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25459\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25459} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25459","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25459","Event ID 25459","Set-ThrottlingPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68372,"title":"Exchange Audit Event 25460 - Set-ThrottlingPolicyAssociation Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25460","Exchange"],"keywords":["25460","event 25460","event id 25460","Set-ThrottlingPolicyAssociation Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25460"],"errorCode":"","eventId":"25460","severity":"Medium","summary":"Exchange Audit event 25460 records: Set-ThrottlingPolicyAssociation Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ThrottlingPolicyAssociation Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25460.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ThrottlingPolicyAssociation Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25460\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25460} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25460","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25460","Event ID 25460","Set-ThrottlingPolicyAssociation Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68373,"title":"Exchange Audit Event 25461 - Set-TransportAgent Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25461","Exchange"],"keywords":["25461","event 25461","event id 25461","Set-TransportAgent Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25461"],"errorCode":"","eventId":"25461","severity":"Low","summary":"Exchange Audit event 25461 records: Set-TransportAgent Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-TransportAgent Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25461.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-TransportAgent Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25461\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25461} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25461","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25461","Event ID 25461","Set-TransportAgent Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68374,"title":"Exchange Audit Event 25462 - Set-TransportConfig Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25462","Exchange"],"keywords":["25462","event 25462","event id 25462","Set-TransportConfig Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25462"],"errorCode":"","eventId":"25462","severity":"Low","summary":"Exchange Audit event 25462 records: Set-TransportConfig Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-TransportConfig Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25462.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-TransportConfig Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25462\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25462} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25462","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25462","Event ID 25462","Set-TransportConfig Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68375,"title":"Exchange Audit Event 25463 - Set-TransportRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25463","Exchange"],"keywords":["25463","event 25463","event id 25463","Set-TransportRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25463"],"errorCode":"","eventId":"25463","severity":"Low","summary":"Exchange Audit event 25463 records: Set-TransportRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-TransportRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25463.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-TransportRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25463\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25463} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25463","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25463","Event ID 25463","Set-TransportRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68376,"title":"Exchange Audit Event 25464 - Set-TransportServer Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25464","Exchange"],"keywords":["25464","event 25464","event id 25464","Set-TransportServer Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25464"],"errorCode":"","eventId":"25464","severity":"Low","summary":"Exchange Audit event 25464 records: Set-TransportServer Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-TransportServer Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25464.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-TransportServer Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25464\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25464} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25464","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25464","Event ID 25464","Set-TransportServer Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68377,"title":"Exchange Audit Event 25465 - Set-UMAutoAttendant Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25465","Exchange"],"keywords":["25465","event 25465","event id 25465","Set-UMAutoAttendant Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25465"],"errorCode":"","eventId":"25465","severity":"Low","summary":"Exchange Audit event 25465 records: Set-UMAutoAttendant Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-UMAutoAttendant Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25465.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-UMAutoAttendant Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25465\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25465} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25465","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25465","Event ID 25465","Set-UMAutoAttendant Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68378,"title":"Exchange Audit Event 25466 - Set-UMDialPlan Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25466","Exchange"],"keywords":["25466","event 25466","event id 25466","Set-UMDialPlan Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25466"],"errorCode":"","eventId":"25466","severity":"Low","summary":"Exchange Audit event 25466 records: Set-UMDialPlan Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-UMDialPlan Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25466.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-UMDialPlan Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25466\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25466} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25466","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25466","Event ID 25466","Set-UMDialPlan Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68379,"title":"Exchange Audit Event 25467 - Set-UMIPGateway Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25467","Exchange"],"keywords":["25467","event 25467","event id 25467","Set-UMIPGateway Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25467"],"errorCode":"","eventId":"25467","severity":"Low","summary":"Exchange Audit event 25467 records: Set-UMIPGateway Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-UMIPGateway Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25467.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-UMIPGateway Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25467\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25467} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25467","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25467","Event ID 25467","Set-UMIPGateway Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68380,"title":"Exchange Audit Event 25468 - Set-UMMailbox Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25468","Exchange"],"keywords":["25468","event 25468","event id 25468","Set-UMMailbox Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25468"],"errorCode":"","eventId":"25468","severity":"Low","summary":"Exchange Audit event 25468 records: Set-UMMailbox Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-UMMailbox Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25468.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-UMMailbox Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25468\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25468} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25468","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25468","Event ID 25468","Set-UMMailbox Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68381,"title":"Exchange Audit Event 25469 - Set-UMMailboxPIN Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25469","Exchange"],"keywords":["25469","event 25469","event id 25469","Set-UMMailboxPIN Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25469"],"errorCode":"","eventId":"25469","severity":"Low","summary":"Exchange Audit event 25469 records: Set-UMMailboxPIN Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-UMMailboxPIN Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25469.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-UMMailboxPIN Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25469\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25469} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25469","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25469","Event ID 25469","Set-UMMailboxPIN Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68382,"title":"Exchange Audit Event 25470 - Set-UMMailboxPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25470","Exchange"],"keywords":["25470","event 25470","event id 25470","Set-UMMailboxPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25470"],"errorCode":"","eventId":"25470","severity":"Medium","summary":"Exchange Audit event 25470 records: Set-UMMailboxPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-UMMailboxPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25470.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-UMMailboxPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25470\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25470} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25470","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25470","Event ID 25470","Set-UMMailboxPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68383,"title":"Exchange Audit Event 25471 - Set-UmServer Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25471","Exchange"],"keywords":["25471","event 25471","event id 25471","Set-UmServer Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25471"],"errorCode":"","eventId":"25471","severity":"Low","summary":"Exchange Audit event 25471 records: Set-UmServer Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-UmServer Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25471.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-UmServer Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25471\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25471} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25471","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25471","Event ID 25471","Set-UmServer Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68384,"title":"Exchange Audit Event 25472 - Set-User Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25472","Exchange"],"keywords":["25472","event 25472","event id 25472","Set-User Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25472"],"errorCode":"","eventId":"25472","severity":"Low","summary":"Exchange Audit event 25472 records: Set-User Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-User Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25472.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-User Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25472\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25472} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25472","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25472","Event ID 25472","Set-User Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68385,"title":"Exchange Audit Event 25473 - Set-WebServicesVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25473","Exchange"],"keywords":["25473","event 25473","event id 25473","Set-WebServicesVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25473"],"errorCode":"","eventId":"25473","severity":"Low","summary":"Exchange Audit event 25473 records: Set-WebServicesVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-WebServicesVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25473.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-WebServicesVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25473\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25473} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25473","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25473","Event ID 25473","Set-WebServicesVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68386,"title":"Exchange Audit Event 25474 - Set-X400AuthoritativeDomain Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25474","Exchange"],"keywords":["25474","event 25474","event id 25474","Set-X400AuthoritativeDomain Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25474"],"errorCode":"","eventId":"25474","severity":"Low","summary":"Exchange Audit event 25474 records: Set-X400AuthoritativeDomain Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-X400AuthoritativeDomain Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25474.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-X400AuthoritativeDomain Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25474\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25474} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25474","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25474","Event ID 25474","Set-X400AuthoritativeDomain Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68387,"title":"Exchange Audit Event 25475 - Start-DatabaseAvailabilityGroup Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25475","Exchange"],"keywords":["25475","event 25475","event id 25475","Start-DatabaseAvailabilityGroup Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25475"],"errorCode":"","eventId":"25475","severity":"Medium","summary":"Exchange Audit event 25475 records: Start-DatabaseAvailabilityGroup Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Start-DatabaseAvailabilityGroup Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25475.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Start-DatabaseAvailabilityGroup Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25475\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25475} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25475","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25475","Event ID 25475","Start-DatabaseAvailabilityGroup Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68388,"title":"Exchange Audit Event 25476 - Start-EdgeSynchronization Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25476","Exchange"],"keywords":["25476","event 25476","event id 25476","Start-EdgeSynchronization Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25476"],"errorCode":"","eventId":"25476","severity":"Low","summary":"Exchange Audit event 25476 records: Start-EdgeSynchronization Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Start-EdgeSynchronization Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25476.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Start-EdgeSynchronization Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25476\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25476} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25476","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25476","Event ID 25476","Start-EdgeSynchronization Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68389,"title":"Exchange Audit Event 25477 - Start-ManagedFolderAssistant Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25477","Exchange"],"keywords":["25477","event 25477","event id 25477","Start-ManagedFolderAssistant Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25477"],"errorCode":"","eventId":"25477","severity":"Low","summary":"Exchange Audit event 25477 records: Start-ManagedFolderAssistant Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Start-ManagedFolderAssistant Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25477.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Start-ManagedFolderAssistant Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25477\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25477} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25477","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25477","Event ID 25477","Start-ManagedFolderAssistant Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68390,"title":"Exchange Audit Event 25478 - Start-RetentionAutoTagLearning Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25478","Exchange"],"keywords":["25478","event 25478","event id 25478","Start-RetentionAutoTagLearning Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25478"],"errorCode":"","eventId":"25478","severity":"Low","summary":"Exchange Audit event 25478 records: Start-RetentionAutoTagLearning Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Start-RetentionAutoTagLearning Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25478.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Start-RetentionAutoTagLearning Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25478\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25478} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25478","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25478","Event ID 25478","Start-RetentionAutoTagLearning Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68391,"title":"Exchange Audit Event 25479 - Stop-DatabaseAvailabilityGroup Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25479","Exchange"],"keywords":["25479","event 25479","event id 25479","Stop-DatabaseAvailabilityGroup Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25479"],"errorCode":"","eventId":"25479","severity":"Medium","summary":"Exchange Audit event 25479 records: Stop-DatabaseAvailabilityGroup Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Stop-DatabaseAvailabilityGroup Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25479.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Stop-DatabaseAvailabilityGroup Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25479\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25479} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25479","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25479","Event ID 25479","Stop-DatabaseAvailabilityGroup Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68392,"title":"Exchange Audit Event 25480 - Stop-ManagedFolderAssistant Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25480","Exchange"],"keywords":["25480","event 25480","event id 25480","Stop-ManagedFolderAssistant Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25480"],"errorCode":"","eventId":"25480","severity":"Low","summary":"Exchange Audit event 25480 records: Stop-ManagedFolderAssistant Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Stop-ManagedFolderAssistant Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25480.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Stop-ManagedFolderAssistant Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25480\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25480} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25480","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25480","Event ID 25480","Stop-ManagedFolderAssistant Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68393,"title":"Exchange Audit Event 25481 - Suspend-MailboxDatabaseCopy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25481","Exchange"],"keywords":["25481","event 25481","event id 25481","Suspend-MailboxDatabaseCopy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25481"],"errorCode":"","eventId":"25481","severity":"Low","summary":"Exchange Audit event 25481 records: Suspend-MailboxDatabaseCopy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Suspend-MailboxDatabaseCopy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25481.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Suspend-MailboxDatabaseCopy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25481\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25481} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25481","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25481","Event ID 25481","Suspend-MailboxDatabaseCopy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68394,"title":"Exchange Audit Event 25482 - Suspend-MailboxRestoreRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25482","Exchange"],"keywords":["25482","event 25482","event id 25482","Suspend-MailboxRestoreRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25482"],"errorCode":"","eventId":"25482","severity":"Low","summary":"Exchange Audit event 25482 records: Suspend-MailboxRestoreRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Suspend-MailboxRestoreRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25482.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Suspend-MailboxRestoreRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25482\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25482} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25482","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25482","Event ID 25482","Suspend-MailboxRestoreRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68395,"title":"Exchange Audit Event 25483 - Suspend-Message Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25483","Exchange"],"keywords":["25483","event 25483","event id 25483","Suspend-Message Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25483"],"errorCode":"","eventId":"25483","severity":"Low","summary":"Exchange Audit event 25483 records: Suspend-Message Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Suspend-Message Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25483.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Suspend-Message Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25483\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25483} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25483","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25483","Event ID 25483","Suspend-Message Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68396,"title":"Exchange Audit Event 25484 - Suspend-MoveRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25484","Exchange"],"keywords":["25484","event 25484","event id 25484","Suspend-MoveRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25484"],"errorCode":"","eventId":"25484","severity":"Low","summary":"Exchange Audit event 25484 records: Suspend-MoveRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Suspend-MoveRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25484.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Suspend-MoveRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25484\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25484} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25484","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25484","Event ID 25484","Suspend-MoveRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68397,"title":"Exchange Audit Event 25485 - Suspend-PublicFolderReplication Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25485","Exchange"],"keywords":["25485","event 25485","event id 25485","Suspend-PublicFolderReplication Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25485"],"errorCode":"","eventId":"25485","severity":"Low","summary":"Exchange Audit event 25485 records: Suspend-PublicFolderReplication Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Suspend-PublicFolderReplication Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25485.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Suspend-PublicFolderReplication Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25485\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25485} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25485","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25485","Event ID 25485","Suspend-PublicFolderReplication Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68398,"title":"Exchange Audit Event 25486 - Suspend-Queue Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25486","Exchange"],"keywords":["25486","event 25486","event id 25486","Suspend-Queue Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25486"],"errorCode":"","eventId":"25486","severity":"Low","summary":"Exchange Audit event 25486 records: Suspend-Queue Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Suspend-Queue Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25486.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Suspend-Queue Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25486\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25486} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25486","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25486","Event ID 25486","Suspend-Queue Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68399,"title":"Exchange Audit Event 25487 - Test-ActiveSyncConnectivity Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25487","Exchange"],"keywords":["25487","event 25487","event id 25487","Test-ActiveSyncConnectivity Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25487"],"errorCode":"","eventId":"25487","severity":"Low","summary":"Exchange Audit event 25487 records: Test-ActiveSyncConnectivity Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-ActiveSyncConnectivity Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25487.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-ActiveSyncConnectivity Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25487\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25487} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25487","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25487","Event ID 25487","Test-ActiveSyncConnectivity Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68400,"title":"Exchange Audit Event 25488 - Test-AssistantHealth Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25488","Exchange"],"keywords":["25488","event 25488","event id 25488","Test-AssistantHealth Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25488"],"errorCode":"","eventId":"25488","severity":"Low","summary":"Exchange Audit event 25488 records: Test-AssistantHealth Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-AssistantHealth Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25488.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-AssistantHealth Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25488\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25488} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25488","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25488","Event ID 25488","Test-AssistantHealth Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68401,"title":"Exchange Audit Event 25489 - Test-CalendarConnectivity Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25489","Exchange"],"keywords":["25489","event 25489","event id 25489","Test-CalendarConnectivity Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25489"],"errorCode":"","eventId":"25489","severity":"Low","summary":"Exchange Audit event 25489 records: Test-CalendarConnectivity Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-CalendarConnectivity Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25489.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-CalendarConnectivity Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25489\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25489} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25489","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25489","Event ID 25489","Test-CalendarConnectivity Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68402,"title":"Exchange Audit Event 25490 - Test-EcpConnectivity Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25490","Exchange"],"keywords":["25490","event 25490","event id 25490","Test-EcpConnectivity Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25490"],"errorCode":"","eventId":"25490","severity":"Low","summary":"Exchange Audit event 25490 records: Test-EcpConnectivity Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-EcpConnectivity Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25490.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-EcpConnectivity Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25490\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25490} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25490","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25490","Event ID 25490","Test-EcpConnectivity Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68403,"title":"Exchange Audit Event 25491 - Test-EdgeSynchronization Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25491","Exchange"],"keywords":["25491","event 25491","event id 25491","Test-EdgeSynchronization Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25491"],"errorCode":"","eventId":"25491","severity":"Low","summary":"Exchange Audit event 25491 records: Test-EdgeSynchronization Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-EdgeSynchronization Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25491.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-EdgeSynchronization Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25491\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25491} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25491","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25491","Event ID 25491","Test-EdgeSynchronization Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68404,"title":"Exchange Audit Event 25492 - Test-ExchangeSearch Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25492","Exchange"],"keywords":["25492","event 25492","event id 25492","Test-ExchangeSearch Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25492"],"errorCode":"","eventId":"25492","severity":"Low","summary":"Exchange Audit event 25492 records: Test-ExchangeSearch Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-ExchangeSearch Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25492.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-ExchangeSearch Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25492\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25492} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25492","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25492","Event ID 25492","Test-ExchangeSearch Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68405,"title":"Exchange Audit Event 25493 - Test-FederationTrust Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25493","Exchange"],"keywords":["25493","event 25493","event id 25493","Test-FederationTrust Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25493"],"errorCode":"","eventId":"25493","severity":"Medium","summary":"Exchange Audit event 25493 records: Test-FederationTrust Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-FederationTrust Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25493.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-FederationTrust Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25493\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25493} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25493","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25493","Event ID 25493","Test-FederationTrust Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68406,"title":"Exchange Audit Event 25494 - Test-FederationTrustCertificate Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25494","Exchange"],"keywords":["25494","event 25494","event id 25494","Test-FederationTrustCertificate Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25494"],"errorCode":"","eventId":"25494","severity":"Medium","summary":"Exchange Audit event 25494 records: Test-FederationTrustCertificate Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-FederationTrustCertificate Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25494.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-FederationTrustCertificate Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25494\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25494} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25494","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25494","Event ID 25494","Test-FederationTrustCertificate Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68407,"title":"Exchange Audit Event 25495 - Test-ImapConnectivity Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25495","Exchange"],"keywords":["25495","event 25495","event id 25495","Test-ImapConnectivity Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25495"],"errorCode":"","eventId":"25495","severity":"Low","summary":"Exchange Audit event 25495 records: Test-ImapConnectivity Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-ImapConnectivity Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25495.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-ImapConnectivity Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25495\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25495} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25495","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25495","Event ID 25495","Test-ImapConnectivity Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68408,"title":"Exchange Audit Event 25496 - Test-IPAllowListProvider Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25496","Exchange"],"keywords":["25496","event 25496","event id 25496","Test-IPAllowListProvider Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25496"],"errorCode":"","eventId":"25496","severity":"Low","summary":"Exchange Audit event 25496 records: Test-IPAllowListProvider Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-IPAllowListProvider Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25496.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-IPAllowListProvider Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25496\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25496} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25496","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25496","Event ID 25496","Test-IPAllowListProvider Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68409,"title":"Exchange Audit Event 25497 - Test-IPBlockListProvider Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25497","Exchange"],"keywords":["25497","event 25497","event id 25497","Test-IPBlockListProvider Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25497"],"errorCode":"","eventId":"25497","severity":"Low","summary":"Exchange Audit event 25497 records: Test-IPBlockListProvider Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-IPBlockListProvider Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25497.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-IPBlockListProvider Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25497\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25497} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25497","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25497","Event ID 25497","Test-IPBlockListProvider Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68410,"title":"Exchange Audit Event 25498 - Test-IRMConfiguration Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25498","Exchange"],"keywords":["25498","event 25498","event id 25498","Test-IRMConfiguration Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25498"],"errorCode":"","eventId":"25498","severity":"Low","summary":"Exchange Audit event 25498 records: Test-IRMConfiguration Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-IRMConfiguration Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25498.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-IRMConfiguration Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25498\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25498} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25498","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25498","Event ID 25498","Test-IRMConfiguration Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68411,"title":"Exchange Audit Event 25499 - Test-Mailflow Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25499","Exchange"],"keywords":["25499","event 25499","event id 25499","Test-Mailflow Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25499"],"errorCode":"","eventId":"25499","severity":"Low","summary":"Exchange Audit event 25499 records: Test-Mailflow Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-Mailflow Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25499.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-Mailflow Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25499\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25499} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25499","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25499","Event ID 25499","Test-Mailflow Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68412,"title":"Exchange Audit Event 25500 - Test-MAPIConnectivity Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25500","Exchange"],"keywords":["25500","event 25500","event id 25500","Test-MAPIConnectivity Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25500"],"errorCode":"","eventId":"25500","severity":"Low","summary":"Exchange Audit event 25500 records: Test-MAPIConnectivity Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-MAPIConnectivity Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25500.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-MAPIConnectivity Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25500\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25500} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25500","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25500","Event ID 25500","Test-MAPIConnectivity Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68413,"title":"Exchange Audit Event 25501 - Test-MRSHealth Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25501","Exchange"],"keywords":["25501","event 25501","event id 25501","Test-MRSHealth Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25501"],"errorCode":"","eventId":"25501","severity":"Low","summary":"Exchange Audit event 25501 records: Test-MRSHealth Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-MRSHealth Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25501.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-MRSHealth Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25501\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25501} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25501","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25501","Event ID 25501","Test-MRSHealth Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68414,"title":"Exchange Audit Event 25502 - Test-OrganizationRelationship Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25502","Exchange"],"keywords":["25502","event 25502","event id 25502","Test-OrganizationRelationship Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25502"],"errorCode":"","eventId":"25502","severity":"Low","summary":"Exchange Audit event 25502 records: Test-OrganizationRelationship Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-OrganizationRelationship Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25502.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-OrganizationRelationship Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25502\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25502} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25502","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25502","Event ID 25502","Test-OrganizationRelationship Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68415,"title":"Exchange Audit Event 25503 - Test-OutlookConnectivity Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25503","Exchange"],"keywords":["25503","event 25503","event id 25503","Test-OutlookConnectivity Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25503"],"errorCode":"","eventId":"25503","severity":"Low","summary":"Exchange Audit event 25503 records: Test-OutlookConnectivity Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-OutlookConnectivity Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25503.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-OutlookConnectivity Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25503\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25503} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25503","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25503","Event ID 25503","Test-OutlookConnectivity Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68416,"title":"Exchange Audit Event 25504 - Test-OutlookWebServices Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25504","Exchange"],"keywords":["25504","event 25504","event id 25504","Test-OutlookWebServices Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25504"],"errorCode":"","eventId":"25504","severity":"Low","summary":"Exchange Audit event 25504 records: Test-OutlookWebServices Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-OutlookWebServices Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25504.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-OutlookWebServices Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25504\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25504} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25504","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25504","Event ID 25504","Test-OutlookWebServices Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68417,"title":"Exchange Audit Event 25505 - Test-OwaConnectivity Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25505","Exchange"],"keywords":["25505","event 25505","event id 25505","Test-OwaConnectivity Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25505"],"errorCode":"","eventId":"25505","severity":"Low","summary":"Exchange Audit event 25505 records: Test-OwaConnectivity Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-OwaConnectivity Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25505.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-OwaConnectivity Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25505\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25505} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25505","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25505","Event ID 25505","Test-OwaConnectivity Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68418,"title":"Exchange Audit Event 25506 - Test-PopConnectivity Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25506","Exchange"],"keywords":["25506","event 25506","event id 25506","Test-PopConnectivity Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25506"],"errorCode":"","eventId":"25506","severity":"Low","summary":"Exchange Audit event 25506 records: Test-PopConnectivity Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-PopConnectivity Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25506.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-PopConnectivity Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25506\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25506} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25506","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25506","Event ID 25506","Test-PopConnectivity Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68419,"title":"Exchange Audit Event 25507 - Test-PowerShellConnectivity Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25507","Exchange"],"keywords":["25507","event 25507","event id 25507","Test-PowerShellConnectivity Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25507"],"errorCode":"","eventId":"25507","severity":"Low","summary":"Exchange Audit event 25507 records: Test-PowerShellConnectivity Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-PowerShellConnectivity Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25507.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-PowerShellConnectivity Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25507\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25507} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25507","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25507","Event ID 25507","Test-PowerShellConnectivity Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68420,"title":"Exchange Audit Event 25508 - Test-ReplicationHealth Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25508","Exchange"],"keywords":["25508","event 25508","event id 25508","Test-ReplicationHealth Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25508"],"errorCode":"","eventId":"25508","severity":"Low","summary":"Exchange Audit event 25508 records: Test-ReplicationHealth Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-ReplicationHealth Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25508.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-ReplicationHealth Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25508\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25508} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25508","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25508","Event ID 25508","Test-ReplicationHealth Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68421,"title":"Exchange Audit Event 25509 - Test-SenderId Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25509","Exchange"],"keywords":["25509","event 25509","event id 25509","Test-SenderId Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25509"],"errorCode":"","eventId":"25509","severity":"Low","summary":"Exchange Audit event 25509 records: Test-SenderId Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-SenderId Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25509.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-SenderId Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25509\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25509} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25509","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25509","Event ID 25509","Test-SenderId Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68422,"title":"Exchange Audit Event 25510 - Test-ServiceHealth Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25510","Exchange"],"keywords":["25510","event 25510","event id 25510","Test-ServiceHealth Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25510"],"errorCode":"","eventId":"25510","severity":"Low","summary":"Exchange Audit event 25510 records: Test-ServiceHealth Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-ServiceHealth Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25510.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-ServiceHealth Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25510\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25510} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25510","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25510","Event ID 25510","Test-ServiceHealth Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68423,"title":"Exchange Audit Event 25511 - Test-SmtpConnectivity Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25511","Exchange"],"keywords":["25511","event 25511","event id 25511","Test-SmtpConnectivity Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25511"],"errorCode":"","eventId":"25511","severity":"Low","summary":"Exchange Audit event 25511 records: Test-SmtpConnectivity Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-SmtpConnectivity Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25511.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-SmtpConnectivity Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25511\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25511} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25511","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25511","Event ID 25511","Test-SmtpConnectivity Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68424,"title":"Exchange Audit Event 25512 - Test-SystemHealth Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25512","Exchange"],"keywords":["25512","event 25512","event id 25512","Test-SystemHealth Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25512"],"errorCode":"","eventId":"25512","severity":"Low","summary":"Exchange Audit event 25512 records: Test-SystemHealth Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-SystemHealth Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25512.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-SystemHealth Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25512\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25512} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25512","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25512","Event ID 25512","Test-SystemHealth Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68425,"title":"Exchange Audit Event 25513 - Test-UMConnectivity Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25513","Exchange"],"keywords":["25513","event 25513","event id 25513","Test-UMConnectivity Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25513"],"errorCode":"","eventId":"25513","severity":"Low","summary":"Exchange Audit event 25513 records: Test-UMConnectivity Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-UMConnectivity Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25513.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-UMConnectivity Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25513\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25513} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25513","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25513","Event ID 25513","Test-UMConnectivity Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68426,"title":"Exchange Audit Event 25514 - Test-WebServicesConnectivity Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25514","Exchange"],"keywords":["25514","event 25514","event id 25514","Test-WebServicesConnectivity Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25514"],"errorCode":"","eventId":"25514","severity":"Low","summary":"Exchange Audit event 25514 records: Test-WebServicesConnectivity Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-WebServicesConnectivity Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25514.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-WebServicesConnectivity Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25514\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25514} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25514","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25514","Event ID 25514","Test-WebServicesConnectivity Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68427,"title":"Exchange Audit Event 25515 - Uninstall-TransportAgent Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25515","Exchange"],"keywords":["25515","event 25515","event id 25515","Uninstall-TransportAgent Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25515"],"errorCode":"","eventId":"25515","severity":"Low","summary":"Exchange Audit event 25515 records: Uninstall-TransportAgent Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Uninstall-TransportAgent Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25515.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Uninstall-TransportAgent Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25515\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25515} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25515","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25515","Event ID 25515","Uninstall-TransportAgent Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68428,"title":"Exchange Audit Event 25516 - Update-AddressList Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25516","Exchange"],"keywords":["25516","event 25516","event id 25516","Update-AddressList Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25516"],"errorCode":"","eventId":"25516","severity":"Low","summary":"Exchange Audit event 25516 records: Update-AddressList Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Update-AddressList Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25516.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Update-AddressList Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25516\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25516} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25516","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25516","Event ID 25516","Update-AddressList Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68429,"title":"Exchange Audit Event 25517 - Update-DistributionGroupMember Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25517","Exchange"],"keywords":["25517","event 25517","event id 25517","Update-DistributionGroupMember Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25517"],"errorCode":"","eventId":"25517","severity":"Medium","summary":"Exchange Audit event 25517 records: Update-DistributionGroupMember Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Update-DistributionGroupMember Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25517.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Update-DistributionGroupMember Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25517\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25517} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25517","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25517","Event ID 25517","Update-DistributionGroupMember Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68430,"title":"Exchange Audit Event 25518 - Update-EmailAddressPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25518","Exchange"],"keywords":["25518","event 25518","event id 25518","Update-EmailAddressPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25518"],"errorCode":"","eventId":"25518","severity":"Medium","summary":"Exchange Audit event 25518 records: Update-EmailAddressPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Update-EmailAddressPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25518.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Update-EmailAddressPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25518\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25518} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25518","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25518","Event ID 25518","Update-EmailAddressPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68431,"title":"Exchange Audit Event 25519 - Update-FileDistributionService Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25519","Exchange"],"keywords":["25519","event 25519","event id 25519","Update-FileDistributionService Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25519"],"errorCode":"","eventId":"25519","severity":"Low","summary":"Exchange Audit event 25519 records: Update-FileDistributionService Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Update-FileDistributionService Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25519.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Update-FileDistributionService Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25519\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25519} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25519","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25519","Event ID 25519","Update-FileDistributionService Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68432,"title":"Exchange Audit Event 25520 - Update-GlobalAddressList Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25520","Exchange"],"keywords":["25520","event 25520","event id 25520","Update-GlobalAddressList Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25520"],"errorCode":"","eventId":"25520","severity":"Low","summary":"Exchange Audit event 25520 records: Update-GlobalAddressList Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Update-GlobalAddressList Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25520.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Update-GlobalAddressList Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25520\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25520} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25520","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25520","Event ID 25520","Update-GlobalAddressList Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68433,"title":"Exchange Audit Event 25521 - Update-MailboxDatabaseCopy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25521","Exchange"],"keywords":["25521","event 25521","event id 25521","Update-MailboxDatabaseCopy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25521"],"errorCode":"","eventId":"25521","severity":"Low","summary":"Exchange Audit event 25521 records: Update-MailboxDatabaseCopy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Update-MailboxDatabaseCopy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25521.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Update-MailboxDatabaseCopy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25521\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25521} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25521","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25521","Event ID 25521","Update-MailboxDatabaseCopy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68434,"title":"Exchange Audit Event 25522 - Update-OfflineAddressBook Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25522","Exchange"],"keywords":["25522","event 25522","event id 25522","Update-OfflineAddressBook Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25522"],"errorCode":"","eventId":"25522","severity":"Low","summary":"Exchange Audit event 25522 records: Update-OfflineAddressBook Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Update-OfflineAddressBook Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25522.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Update-OfflineAddressBook Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25522\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25522} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25522","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25522","Event ID 25522","Update-OfflineAddressBook Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68435,"title":"Exchange Audit Event 25523 - Update-PublicFolder Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25523","Exchange"],"keywords":["25523","event 25523","event id 25523","Update-PublicFolder Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25523"],"errorCode":"","eventId":"25523","severity":"Low","summary":"Exchange Audit event 25523 records: Update-PublicFolder Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Update-PublicFolder Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25523.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Update-PublicFolder Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25523\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25523} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25523","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25523","Event ID 25523","Update-PublicFolder Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68436,"title":"Exchange Audit Event 25524 - Update-PublicFolderHierarchy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25524","Exchange"],"keywords":["25524","event 25524","event id 25524","Update-PublicFolderHierarchy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25524"],"errorCode":"","eventId":"25524","severity":"Low","summary":"Exchange Audit event 25524 records: Update-PublicFolderHierarchy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Update-PublicFolderHierarchy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25524.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Update-PublicFolderHierarchy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25524\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25524} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25524","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25524","Event ID 25524","Update-PublicFolderHierarchy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68437,"title":"Exchange Audit Event 25525 - Update-Recipient Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25525","Exchange"],"keywords":["25525","event 25525","event id 25525","Update-Recipient Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25525"],"errorCode":"","eventId":"25525","severity":"Low","summary":"Exchange Audit event 25525 records: Update-Recipient Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Update-Recipient Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25525.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Update-Recipient Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25525\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25525} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25525","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25525","Event ID 25525","Update-Recipient Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68438,"title":"Exchange Audit Event 25526 - Update-RoleGroupMember Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25526","Exchange"],"keywords":["25526","event 25526","event id 25526","Update-RoleGroupMember Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25526"],"errorCode":"","eventId":"25526","severity":"Medium","summary":"Exchange Audit event 25526 records: Update-RoleGroupMember Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Update-RoleGroupMember Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25526.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Update-RoleGroupMember Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25526\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25526} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25526","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25526","Event ID 25526","Update-RoleGroupMember Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68439,"title":"Exchange Audit Event 25527 - Update-SafeList Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25527","Exchange"],"keywords":["25527","event 25527","event id 25527","Update-SafeList Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25527"],"errorCode":"","eventId":"25527","severity":"Low","summary":"Exchange Audit event 25527 records: Update-SafeList Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Update-SafeList Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25527.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Update-SafeList Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25527\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25527} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25527","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25527","Event ID 25527","Update-SafeList Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68440,"title":"Exchange Audit Event 25528 - Write-AdminAuditLog Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25528","Exchange"],"keywords":["25528","event 25528","event id 25528","Write-AdminAuditLog Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25528"],"errorCode":"","eventId":"25528","severity":"Low","summary":"Exchange Audit event 25528 records: Write-AdminAuditLog Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Write-AdminAuditLog Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25528.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Write-AdminAuditLog Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25528\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25528} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25528","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25528","Event ID 25528","Write-AdminAuditLog Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68441,"title":"Exchange Audit Event 25529 - Add-GlobalMonitoringOverride Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25529","Exchange"],"keywords":["25529","event 25529","event id 25529","Add-GlobalMonitoringOverride Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25529"],"errorCode":"","eventId":"25529","severity":"Low","summary":"Exchange Audit event 25529 records: Add-GlobalMonitoringOverride Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Add-GlobalMonitoringOverride Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25529.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add-GlobalMonitoringOverride Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25529\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25529} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25529","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25529","Event ID 25529","Add-GlobalMonitoringOverride Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68442,"title":"Exchange Audit Event 25530 - Add-ResubmitRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25530","Exchange"],"keywords":["25530","event 25530","event id 25530","Add-ResubmitRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25530"],"errorCode":"","eventId":"25530","severity":"Low","summary":"Exchange Audit event 25530 records: Add-ResubmitRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Add-ResubmitRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25530.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add-ResubmitRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25530\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25530} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25530","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25530","Event ID 25530","Add-ResubmitRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68443,"title":"Exchange Audit Event 25531 - Add-ServerMonitoringOverride Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25531","Exchange"],"keywords":["25531","event 25531","event id 25531","Add-ServerMonitoringOverride Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25531"],"errorCode":"","eventId":"25531","severity":"Low","summary":"Exchange Audit event 25531 records: Add-ServerMonitoringOverride Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Add-ServerMonitoringOverride Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25531.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add-ServerMonitoringOverride Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25531\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25531} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25531","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25531","Event ID 25531","Add-ServerMonitoringOverride Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68444,"title":"Exchange Audit Event 25532 - Clear-MobileDevice Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25532","Exchange"],"keywords":["25532","event 25532","event id 25532","Clear-MobileDevice Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25532"],"errorCode":"","eventId":"25532","severity":"Low","summary":"Exchange Audit event 25532 records: Clear-MobileDevice Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Clear-MobileDevice Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25532.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Clear-MobileDevice Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25532\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25532} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25532","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25532","Event ID 25532","Clear-MobileDevice Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68445,"title":"Exchange Audit Event 25533 - Complete-MigrationBatch Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25533","Exchange"],"keywords":["25533","event 25533","event id 25533","Complete-MigrationBatch Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25533"],"errorCode":"","eventId":"25533","severity":"Low","summary":"Exchange Audit event 25533 records: Complete-MigrationBatch Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Complete-MigrationBatch Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25533.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Complete-MigrationBatch Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25533\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25533} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25533","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25533","Event ID 25533","Complete-MigrationBatch Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68446,"title":"Exchange Audit Event 25534 - Disable-App Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25534","Exchange"],"keywords":["25534","event 25534","event id 25534","Disable-App Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25534"],"errorCode":"","eventId":"25534","severity":"Low","summary":"Exchange Audit event 25534 records: Disable-App Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Disable-App Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25534.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Disable-App Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25534\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25534} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25534","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25534","Event ID 25534","Disable-App Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68447,"title":"Exchange Audit Event 25535 - Disable-MailboxQuarantine Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25535","Exchange"],"keywords":["25535","event 25535","event id 25535","Disable-MailboxQuarantine Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25535"],"errorCode":"","eventId":"25535","severity":"Low","summary":"Exchange Audit event 25535 records: Disable-MailboxQuarantine Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Disable-MailboxQuarantine Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25535.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Disable-MailboxQuarantine Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25535\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25535} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25535","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25535","Event ID 25535","Disable-MailboxQuarantine Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68448,"title":"Exchange Audit Event 25536 - Disable-UMCallAnsweringRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25536","Exchange"],"keywords":["25536","event 25536","event id 25536","Disable-UMCallAnsweringRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25536"],"errorCode":"","eventId":"25536","severity":"Low","summary":"Exchange Audit event 25536 records: Disable-UMCallAnsweringRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Disable-UMCallAnsweringRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25536.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Disable-UMCallAnsweringRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25536\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25536} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25536","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25536","Event ID 25536","Disable-UMCallAnsweringRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68449,"title":"Exchange Audit Event 25537 - Disable-UMService Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25537","Exchange"],"keywords":["25537","event 25537","event id 25537","Disable-UMService Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25537"],"errorCode":"","eventId":"25537","severity":"Low","summary":"Exchange Audit event 25537 records: Disable-UMService Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Disable-UMService Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25537.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Disable-UMService Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25537\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25537} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25537","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25537","Event ID 25537","Disable-UMService Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68450,"title":"Exchange Audit Event 25538 - Dump-ProvisioningCache Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25538","Exchange"],"keywords":["25538","event 25538","event id 25538","Dump-ProvisioningCache Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25538"],"errorCode":"","eventId":"25538","severity":"Low","summary":"Exchange Audit event 25538 records: Dump-ProvisioningCache Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Dump-ProvisioningCache Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25538.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Dump-ProvisioningCache Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25538\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25538} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25538","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25538","Event ID 25538","Dump-ProvisioningCache Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68451,"title":"Exchange Audit Event 25539 - Enable-App Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25539","Exchange"],"keywords":["25539","event 25539","event id 25539","Enable-App Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25539"],"errorCode":"","eventId":"25539","severity":"Low","summary":"Exchange Audit event 25539 records: Enable-App Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-App Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25539.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-App Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25539\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25539} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25539","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25539","Event ID 25539","Enable-App Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68452,"title":"Exchange Audit Event 25540 - Enable-MailboxQuarantine Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25540","Exchange"],"keywords":["25540","event 25540","event id 25540","Enable-MailboxQuarantine Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25540"],"errorCode":"","eventId":"25540","severity":"Low","summary":"Exchange Audit event 25540 records: Enable-MailboxQuarantine Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-MailboxQuarantine Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25540.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-MailboxQuarantine Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25540\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25540} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25540","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25540","Event ID 25540","Enable-MailboxQuarantine Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68453,"title":"Exchange Audit Event 25541 - Enable-UMCallAnsweringRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25541","Exchange"],"keywords":["25541","event 25541","event id 25541","Enable-UMCallAnsweringRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25541"],"errorCode":"","eventId":"25541","severity":"Low","summary":"Exchange Audit event 25541 records: Enable-UMCallAnsweringRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-UMCallAnsweringRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25541.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-UMCallAnsweringRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25541\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25541} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25541","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25541","Event ID 25541","Enable-UMCallAnsweringRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68454,"title":"Exchange Audit Event 25542 - Enable-UMService Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25542","Exchange"],"keywords":["25542","event 25542","event id 25542","Enable-UMService Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25542"],"errorCode":"","eventId":"25542","severity":"Low","summary":"Exchange Audit event 25542 records: Enable-UMService Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-UMService Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25542.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-UMService Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25542\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25542} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25542","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25542","Event ID 25542","Enable-UMService Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68455,"title":"Exchange Audit Event 25543 - Export-DlpPolicyCollection Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25543","Exchange"],"keywords":["25543","event 25543","event id 25543","Export-DlpPolicyCollection Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25543"],"errorCode":"","eventId":"25543","severity":"Medium","summary":"Exchange Audit event 25543 records: Export-DlpPolicyCollection Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Export-DlpPolicyCollection Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25543.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Export-DlpPolicyCollection Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25543\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25543} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25543","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25543","Event ID 25543","Export-DlpPolicyCollection Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68456,"title":"Exchange Audit Event 25544 - Export-MigrationReport Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25544","Exchange"],"keywords":["25544","event 25544","event id 25544","Export-MigrationReport Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25544"],"errorCode":"","eventId":"25544","severity":"Low","summary":"Exchange Audit event 25544 records: Export-MigrationReport Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Export-MigrationReport Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25544.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Export-MigrationReport Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25544\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25544} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25544","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25544","Event ID 25544","Export-MigrationReport Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68457,"title":"Exchange Audit Event 25545 - Import-DlpPolicyCollection Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25545","Exchange"],"keywords":["25545","event 25545","event id 25545","Import-DlpPolicyCollection Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25545"],"errorCode":"","eventId":"25545","severity":"Medium","summary":"Exchange Audit event 25545 records: Import-DlpPolicyCollection Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Import-DlpPolicyCollection Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25545.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Import-DlpPolicyCollection Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25545\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25545} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25545","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25545","Event ID 25545","Import-DlpPolicyCollection Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68458,"title":"Exchange Audit Event 25546 - Import-DlpPolicyTemplate Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25546","Exchange"],"keywords":["25546","event 25546","event id 25546","Import-DlpPolicyTemplate Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25546"],"errorCode":"","eventId":"25546","severity":"Medium","summary":"Exchange Audit event 25546 records: Import-DlpPolicyTemplate Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Import-DlpPolicyTemplate Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25546.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Import-DlpPolicyTemplate Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25546\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25546} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25546","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25546","Event ID 25546","Import-DlpPolicyTemplate Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68459,"title":"Exchange Audit Event 25547 - Invoke-MonitoringProbe Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25547","Exchange"],"keywords":["25547","event 25547","event id 25547","Invoke-MonitoringProbe Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25547"],"errorCode":"","eventId":"25547","severity":"Low","summary":"Exchange Audit event 25547 records: Invoke-MonitoringProbe Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Invoke-MonitoringProbe Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25547.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Invoke-MonitoringProbe Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25547\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25547} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25547","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25547","Event ID 25547","Invoke-MonitoringProbe Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68460,"title":"Exchange Audit Event 25548 - New-AddressBookPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25548","Exchange"],"keywords":["25548","event 25548","event id 25548","New-AddressBookPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25548"],"errorCode":"","eventId":"25548","severity":"Medium","summary":"Exchange Audit event 25548 records: New-AddressBookPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-AddressBookPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25548.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-AddressBookPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25548\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25548} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25548","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25548","Event ID 25548","New-AddressBookPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68461,"title":"Exchange Audit Event 25549 - New-App Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25549","Exchange"],"keywords":["25549","event 25549","event id 25549","New-App Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25549"],"errorCode":"","eventId":"25549","severity":"Low","summary":"Exchange Audit event 25549 records: New-App Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-App Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25549.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-App Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25549\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25549} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25549","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25549","Event ID 25549","New-App Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68462,"title":"Exchange Audit Event 25550 - New-AuthServer Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25550","Exchange"],"keywords":["25550","event 25550","event id 25550","New-AuthServer Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25550"],"errorCode":"","eventId":"25550","severity":"Low","summary":"Exchange Audit event 25550 records: New-AuthServer Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-AuthServer Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25550.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-AuthServer Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25550\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25550} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25550","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25550","Event ID 25550","New-AuthServer Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68463,"title":"Exchange Audit Event 25551 - New-ClassificationRuleCollection Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25551","Exchange"],"keywords":["25551","event 25551","event id 25551","New-ClassificationRuleCollection Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25551"],"errorCode":"","eventId":"25551","severity":"Low","summary":"Exchange Audit event 25551 records: New-ClassificationRuleCollection Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-ClassificationRuleCollection Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25551.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-ClassificationRuleCollection Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25551\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25551} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25551","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25551","Event ID 25551","New-ClassificationRuleCollection Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68464,"title":"Exchange Audit Event 25552 - New-DlpPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25552","Exchange"],"keywords":["25552","event 25552","event id 25552","New-DlpPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25552"],"errorCode":"","eventId":"25552","severity":"Medium","summary":"Exchange Audit event 25552 records: New-DlpPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-DlpPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25552.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-DlpPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25552\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25552} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25552","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25552","Event ID 25552","New-DlpPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68465,"title":"Exchange Audit Event 25553 - New-HybridConfiguration Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25553","Exchange"],"keywords":["25553","event 25553","event id 25553","New-HybridConfiguration Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25553"],"errorCode":"","eventId":"25553","severity":"Low","summary":"Exchange Audit event 25553 records: New-HybridConfiguration Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-HybridConfiguration Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25553.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-HybridConfiguration Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25553\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25553} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25553","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25553","Event ID 25553","New-HybridConfiguration Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68466,"title":"Exchange Audit Event 25554 - New-MailboxExportRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25554","Exchange"],"keywords":["25554","event 25554","event id 25554","New-MailboxExportRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25554"],"errorCode":"","eventId":"25554","severity":"Low","summary":"Exchange Audit event 25554 records: New-MailboxExportRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-MailboxExportRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25554.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-MailboxExportRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25554\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25554} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25554","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25554","Event ID 25554","New-MailboxExportRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68467,"title":"Exchange Audit Event 25555 - New-MailboxImportRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25555","Exchange"],"keywords":["25555","event 25555","event id 25555","New-MailboxImportRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25555"],"errorCode":"","eventId":"25555","severity":"Low","summary":"Exchange Audit event 25555 records: New-MailboxImportRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-MailboxImportRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25555.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-MailboxImportRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25555\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25555} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25555","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25555","Event ID 25555","New-MailboxImportRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68468,"title":"Exchange Audit Event 25556 - New-MailboxSearch Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25556","Exchange"],"keywords":["25556","event 25556","event id 25556","New-MailboxSearch Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25556"],"errorCode":"","eventId":"25556","severity":"Low","summary":"Exchange Audit event 25556 records: New-MailboxSearch Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-MailboxSearch Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25556.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-MailboxSearch Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25556\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25556} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25556","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25556","Event ID 25556","New-MailboxSearch Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68469,"title":"Exchange Audit Event 25557 - New-MalwareFilterPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25557","Exchange"],"keywords":["25557","event 25557","event id 25557","New-MalwareFilterPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25557"],"errorCode":"","eventId":"25557","severity":"Critical","summary":"Exchange Audit event 25557 records: New-MalwareFilterPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-MalwareFilterPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25557.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-MalwareFilterPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25557\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25557} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25557","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25557","Event ID 25557","New-MalwareFilterPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68470,"title":"Exchange Audit Event 25558 - New-MigrationBatch Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25558","Exchange"],"keywords":["25558","event 25558","event id 25558","New-MigrationBatch Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25558"],"errorCode":"","eventId":"25558","severity":"Low","summary":"Exchange Audit event 25558 records: New-MigrationBatch Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-MigrationBatch Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25558.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-MigrationBatch Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25558\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25558} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25558","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25558","Event ID 25558","New-MigrationBatch Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68471,"title":"Exchange Audit Event 25559 - New-MigrationEndpoint Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25559","Exchange"],"keywords":["25559","event 25559","event id 25559","New-MigrationEndpoint Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25559"],"errorCode":"","eventId":"25559","severity":"Low","summary":"Exchange Audit event 25559 records: New-MigrationEndpoint Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-MigrationEndpoint Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25559.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-MigrationEndpoint Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25559\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25559} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25559","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25559","Event ID 25559","New-MigrationEndpoint Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68472,"title":"Exchange Audit Event 25560 - New-MobileDeviceMailboxPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25560","Exchange"],"keywords":["25560","event 25560","event id 25560","New-MobileDeviceMailboxPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25560"],"errorCode":"","eventId":"25560","severity":"Medium","summary":"Exchange Audit event 25560 records: New-MobileDeviceMailboxPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-MobileDeviceMailboxPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25560.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-MobileDeviceMailboxPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25560\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25560} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25560","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25560","Event ID 25560","New-MobileDeviceMailboxPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68473,"title":"Exchange Audit Event 25561 - New-OnPremisesOrganization Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25561","Exchange"],"keywords":["25561","event 25561","event id 25561","New-OnPremisesOrganization Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25561"],"errorCode":"","eventId":"25561","severity":"Low","summary":"Exchange Audit event 25561 records: New-OnPremisesOrganization Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-OnPremisesOrganization Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25561.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-OnPremisesOrganization Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25561\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25561} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25561","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25561","Event ID 25561","New-OnPremisesOrganization Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68474,"title":"Exchange Audit Event 25562 - New-PartnerApplication Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25562","Exchange"],"keywords":["25562","event 25562","event id 25562","New-PartnerApplication Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25562"],"errorCode":"","eventId":"25562","severity":"Low","summary":"Exchange Audit event 25562 records: New-PartnerApplication Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-PartnerApplication Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25562.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-PartnerApplication Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25562\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25562} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25562","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25562","Event ID 25562","New-PartnerApplication Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68475,"title":"Exchange Audit Event 25563 - New-PolicyTipConfig Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25563","Exchange"],"keywords":["25563","event 25563","event id 25563","New-PolicyTipConfig Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25563"],"errorCode":"","eventId":"25563","severity":"Medium","summary":"Exchange Audit event 25563 records: New-PolicyTipConfig Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-PolicyTipConfig Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25563.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-PolicyTipConfig Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25563\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25563} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25563","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25563","Event ID 25563","New-PolicyTipConfig Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68476,"title":"Exchange Audit Event 25564 - New-PowerShellVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25564","Exchange"],"keywords":["25564","event 25564","event id 25564","New-PowerShellVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25564"],"errorCode":"","eventId":"25564","severity":"Low","summary":"Exchange Audit event 25564 records: New-PowerShellVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-PowerShellVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25564.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-PowerShellVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25564\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25564} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25564","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25564","Event ID 25564","New-PowerShellVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68477,"title":"Exchange Audit Event 25565 - New-PublicFolderMigrationRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25565","Exchange"],"keywords":["25565","event 25565","event id 25565","New-PublicFolderMigrationRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25565"],"errorCode":"","eventId":"25565","severity":"Low","summary":"Exchange Audit event 25565 records: New-PublicFolderMigrationRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-PublicFolderMigrationRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25565.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-PublicFolderMigrationRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25565\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25565} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25565","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25565","Event ID 25565","New-PublicFolderMigrationRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68478,"title":"Exchange Audit Event 25566 - New-ResourcePolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25566","Exchange"],"keywords":["25566","event 25566","event id 25566","New-ResourcePolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25566"],"errorCode":"","eventId":"25566","severity":"Medium","summary":"Exchange Audit event 25566 records: New-ResourcePolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-ResourcePolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25566.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-ResourcePolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25566\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25566} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25566","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25566","Event ID 25566","New-ResourcePolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68479,"title":"Exchange Audit Event 25567 - New-SiteMailboxProvisioningPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25567","Exchange"],"keywords":["25567","event 25567","event id 25567","New-SiteMailboxProvisioningPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25567"],"errorCode":"","eventId":"25567","severity":"Medium","summary":"Exchange Audit event 25567 records: New-SiteMailboxProvisioningPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-SiteMailboxProvisioningPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25567.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-SiteMailboxProvisioningPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25567\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25567} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25567","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25567","Event ID 25567","New-SiteMailboxProvisioningPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68480,"title":"Exchange Audit Event 25568 - New-SyncMailPublicFolder Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25568","Exchange"],"keywords":["25568","event 25568","event id 25568","New-SyncMailPublicFolder Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25568"],"errorCode":"","eventId":"25568","severity":"Low","summary":"Exchange Audit event 25568 records: New-SyncMailPublicFolder Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-SyncMailPublicFolder Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25568.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-SyncMailPublicFolder Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25568\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25568} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25568","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25568","Event ID 25568","New-SyncMailPublicFolder Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68481,"title":"Exchange Audit Event 25569 - New-UMCallAnsweringRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25569","Exchange"],"keywords":["25569","event 25569","event id 25569","New-UMCallAnsweringRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25569"],"errorCode":"","eventId":"25569","severity":"Low","summary":"Exchange Audit event 25569 records: New-UMCallAnsweringRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-UMCallAnsweringRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25569.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-UMCallAnsweringRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25569\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25569} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25569","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25569","Event ID 25569","New-UMCallAnsweringRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68482,"title":"Exchange Audit Event 25570 - New-WorkloadManagementPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25570","Exchange"],"keywords":["25570","event 25570","event id 25570","New-WorkloadManagementPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25570"],"errorCode":"","eventId":"25570","severity":"Medium","summary":"Exchange Audit event 25570 records: New-WorkloadManagementPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-WorkloadManagementPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25570.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-WorkloadManagementPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25570\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25570} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25570","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25570","Event ID 25570","New-WorkloadManagementPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68483,"title":"Exchange Audit Event 25571 - New-WorkloadPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25571","Exchange"],"keywords":["25571","event 25571","event id 25571","New-WorkloadPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25571"],"errorCode":"","eventId":"25571","severity":"Medium","summary":"Exchange Audit event 25571 records: New-WorkloadPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-WorkloadPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25571.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-WorkloadPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25571\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25571} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25571","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25571","Event ID 25571","New-WorkloadPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68484,"title":"Exchange Audit Event 25572 - Redirect-Message Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25572","Exchange"],"keywords":["25572","event 25572","event id 25572","Redirect-Message Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25572"],"errorCode":"","eventId":"25572","severity":"Low","summary":"Exchange Audit event 25572 records: Redirect-Message Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Redirect-Message Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25572.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Redirect-Message Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25572\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25572} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25572","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25572","Event ID 25572","Redirect-Message Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68485,"title":"Exchange Audit Event 25573 - Remove-AddressBookPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25573","Exchange"],"keywords":["25573","event 25573","event id 25573","Remove-AddressBookPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25573"],"errorCode":"","eventId":"25573","severity":"Medium","summary":"Exchange Audit event 25573 records: Remove-AddressBookPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-AddressBookPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25573.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-AddressBookPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25573\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25573} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25573","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25573","Event ID 25573","Remove-AddressBookPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68486,"title":"Exchange Audit Event 25574 - Remove-App Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25574","Exchange"],"keywords":["25574","event 25574","event id 25574","Remove-App Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25574"],"errorCode":"","eventId":"25574","severity":"Low","summary":"Exchange Audit event 25574 records: Remove-App Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-App Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25574.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-App Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25574\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25574} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25574","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25574","Event ID 25574","Remove-App Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68487,"title":"Exchange Audit Event 25575 - Remove-AuthServer Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25575","Exchange"],"keywords":["25575","event 25575","event id 25575","Remove-AuthServer Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25575"],"errorCode":"","eventId":"25575","severity":"Low","summary":"Exchange Audit event 25575 records: Remove-AuthServer Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-AuthServer Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25575.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-AuthServer Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25575\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25575} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25575","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25575","Event ID 25575","Remove-AuthServer Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68488,"title":"Exchange Audit Event 25576 - Remove-ClassificationRuleCollection Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25576","Exchange"],"keywords":["25576","event 25576","event id 25576","Remove-ClassificationRuleCollection Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25576"],"errorCode":"","eventId":"25576","severity":"Low","summary":"Exchange Audit event 25576 records: Remove-ClassificationRuleCollection Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-ClassificationRuleCollection Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25576.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-ClassificationRuleCollection Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25576\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25576} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25576","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25576","Event ID 25576","Remove-ClassificationRuleCollection Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68489,"title":"Exchange Audit Event 25577 - Remove-DlpPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25577","Exchange"],"keywords":["25577","event 25577","event id 25577","Remove-DlpPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25577"],"errorCode":"","eventId":"25577","severity":"Medium","summary":"Exchange Audit event 25577 records: Remove-DlpPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-DlpPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25577.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-DlpPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25577\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25577} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25577","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25577","Event ID 25577","Remove-DlpPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68490,"title":"Exchange Audit Event 25578 - Remove-DlpPolicyTemplate Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25578","Exchange"],"keywords":["25578","event 25578","event id 25578","Remove-DlpPolicyTemplate Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25578"],"errorCode":"","eventId":"25578","severity":"Medium","summary":"Exchange Audit event 25578 records: Remove-DlpPolicyTemplate Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-DlpPolicyTemplate Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25578.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-DlpPolicyTemplate Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25578\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25578} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25578","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25578","Event ID 25578","Remove-DlpPolicyTemplate Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68491,"title":"Exchange Audit Event 25579 - Remove-GlobalMonitoringOverride Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25579","Exchange"],"keywords":["25579","event 25579","event id 25579","Remove-GlobalMonitoringOverride Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25579"],"errorCode":"","eventId":"25579","severity":"Low","summary":"Exchange Audit event 25579 records: Remove-GlobalMonitoringOverride Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-GlobalMonitoringOverride Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25579.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-GlobalMonitoringOverride Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25579\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25579} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25579","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25579","Event ID 25579","Remove-GlobalMonitoringOverride Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68492,"title":"Exchange Audit Event 25580 - Remove-HybridConfiguration Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25580","Exchange"],"keywords":["25580","event 25580","event id 25580","Remove-HybridConfiguration Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25580"],"errorCode":"","eventId":"25580","severity":"Low","summary":"Exchange Audit event 25580 records: Remove-HybridConfiguration Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-HybridConfiguration Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25580.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-HybridConfiguration Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25580\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25580} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25580","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25580","Event ID 25580","Remove-HybridConfiguration Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68493,"title":"Exchange Audit Event 25581 - Remove-LinkedUser Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25581","Exchange"],"keywords":["25581","event 25581","event id 25581","Remove-LinkedUser Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25581"],"errorCode":"","eventId":"25581","severity":"Low","summary":"Exchange Audit event 25581 records: Remove-LinkedUser Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-LinkedUser Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25581.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-LinkedUser Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25581\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25581} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25581","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25581","Event ID 25581","Remove-LinkedUser Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68494,"title":"Exchange Audit Event 25582 - Remove-MailboxExportRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25582","Exchange"],"keywords":["25582","event 25582","event id 25582","Remove-MailboxExportRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25582"],"errorCode":"","eventId":"25582","severity":"Low","summary":"Exchange Audit event 25582 records: Remove-MailboxExportRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-MailboxExportRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25582.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-MailboxExportRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25582\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25582} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25582","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25582","Event ID 25582","Remove-MailboxExportRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68495,"title":"Exchange Audit Event 25583 - Remove-MailboxImportRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25583","Exchange"],"keywords":["25583","event 25583","event id 25583","Remove-MailboxImportRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25583"],"errorCode":"","eventId":"25583","severity":"Low","summary":"Exchange Audit event 25583 records: Remove-MailboxImportRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-MailboxImportRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25583.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-MailboxImportRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25583\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25583} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25583","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25583","Event ID 25583","Remove-MailboxImportRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68496,"title":"Exchange Audit Event 25584 - Remove-MailboxSearch Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25584","Exchange"],"keywords":["25584","event 25584","event id 25584","Remove-MailboxSearch Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25584"],"errorCode":"","eventId":"25584","severity":"Low","summary":"Exchange Audit event 25584 records: Remove-MailboxSearch Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-MailboxSearch Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25584.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-MailboxSearch Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25584\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25584} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25584","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25584","Event ID 25584","Remove-MailboxSearch Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68497,"title":"Exchange Audit Event 25585 - Remove-MalwareFilterPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25585","Exchange"],"keywords":["25585","event 25585","event id 25585","Remove-MalwareFilterPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25585"],"errorCode":"","eventId":"25585","severity":"Critical","summary":"Exchange Audit event 25585 records: Remove-MalwareFilterPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-MalwareFilterPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25585.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-MalwareFilterPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25585\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25585} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25585","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25585","Event ID 25585","Remove-MalwareFilterPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68498,"title":"Exchange Audit Event 25586 - Remove-MalwareFilterRecoveryItem Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25586","Exchange"],"keywords":["25586","event 25586","event id 25586","Remove-MalwareFilterRecoveryItem Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25586"],"errorCode":"","eventId":"25586","severity":"Critical","summary":"Exchange Audit event 25586 records: Remove-MalwareFilterRecoveryItem Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-MalwareFilterRecoveryItem Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25586.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-MalwareFilterRecoveryItem Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25586\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25586} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25586","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25586","Event ID 25586","Remove-MalwareFilterRecoveryItem Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68499,"title":"Exchange Audit Event 25587 - Remove-MigrationBatch Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25587","Exchange"],"keywords":["25587","event 25587","event id 25587","Remove-MigrationBatch Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25587"],"errorCode":"","eventId":"25587","severity":"Low","summary":"Exchange Audit event 25587 records: Remove-MigrationBatch Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-MigrationBatch Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25587.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-MigrationBatch Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25587\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25587} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25587","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25587","Event ID 25587","Remove-MigrationBatch Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68500,"title":"Exchange Audit Event 25588 - Remove-MigrationEndpoint Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25588","Exchange"],"keywords":["25588","event 25588","event id 25588","Remove-MigrationEndpoint Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25588"],"errorCode":"","eventId":"25588","severity":"Low","summary":"Exchange Audit event 25588 records: Remove-MigrationEndpoint Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-MigrationEndpoint Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25588.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-MigrationEndpoint Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25588\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25588} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25588","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25588","Event ID 25588","Remove-MigrationEndpoint Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68501,"title":"Exchange Audit Event 25589 - Remove-MigrationUser Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25589","Exchange"],"keywords":["25589","event 25589","event id 25589","Remove-MigrationUser Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25589"],"errorCode":"","eventId":"25589","severity":"Low","summary":"Exchange Audit event 25589 records: Remove-MigrationUser Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-MigrationUser Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25589.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-MigrationUser Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25589\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25589} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25589","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25589","Event ID 25589","Remove-MigrationUser Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68502,"title":"Exchange Audit Event 25590 - Remove-MobileDevice Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25590","Exchange"],"keywords":["25590","event 25590","event id 25590","Remove-MobileDevice Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25590"],"errorCode":"","eventId":"25590","severity":"Low","summary":"Exchange Audit event 25590 records: Remove-MobileDevice Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-MobileDevice Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25590.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-MobileDevice Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25590\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25590} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25590","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25590","Event ID 25590","Remove-MobileDevice Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68503,"title":"Exchange Audit Event 25591 - Remove-MobileDeviceMailboxPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25591","Exchange"],"keywords":["25591","event 25591","event id 25591","Remove-MobileDeviceMailboxPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25591"],"errorCode":"","eventId":"25591","severity":"Medium","summary":"Exchange Audit event 25591 records: Remove-MobileDeviceMailboxPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-MobileDeviceMailboxPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25591.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-MobileDeviceMailboxPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25591\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25591} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25591","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25591","Event ID 25591","Remove-MobileDeviceMailboxPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68504,"title":"Exchange Audit Event 25592 - Remove-OnPremisesOrganization Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25592","Exchange"],"keywords":["25592","event 25592","event id 25592","Remove-OnPremisesOrganization Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25592"],"errorCode":"","eventId":"25592","severity":"Low","summary":"Exchange Audit event 25592 records: Remove-OnPremisesOrganization Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-OnPremisesOrganization Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25592.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-OnPremisesOrganization Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25592\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25592} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25592","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25592","Event ID 25592","Remove-OnPremisesOrganization Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68505,"title":"Exchange Audit Event 25593 - Remove-PartnerApplication Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25593","Exchange"],"keywords":["25593","event 25593","event id 25593","Remove-PartnerApplication Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25593"],"errorCode":"","eventId":"25593","severity":"Low","summary":"Exchange Audit event 25593 records: Remove-PartnerApplication Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-PartnerApplication Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25593.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-PartnerApplication Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25593\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25593} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25593","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25593","Event ID 25593","Remove-PartnerApplication Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68506,"title":"Exchange Audit Event 25594 - Remove-PolicyTipConfig Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25594","Exchange"],"keywords":["25594","event 25594","event id 25594","Remove-PolicyTipConfig Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25594"],"errorCode":"","eventId":"25594","severity":"Medium","summary":"Exchange Audit event 25594 records: Remove-PolicyTipConfig Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-PolicyTipConfig Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25594.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-PolicyTipConfig Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25594\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25594} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25594","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25594","Event ID 25594","Remove-PolicyTipConfig Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68507,"title":"Exchange Audit Event 25595 - Remove-PowerShellVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25595","Exchange"],"keywords":["25595","event 25595","event id 25595","Remove-PowerShellVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25595"],"errorCode":"","eventId":"25595","severity":"Low","summary":"Exchange Audit event 25595 records: Remove-PowerShellVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-PowerShellVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25595.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-PowerShellVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25595\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25595} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25595","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25595","Event ID 25595","Remove-PowerShellVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68508,"title":"Exchange Audit Event 25596 - Remove-PublicFolderMigrationRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25596","Exchange"],"keywords":["25596","event 25596","event id 25596","Remove-PublicFolderMigrationRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25596"],"errorCode":"","eventId":"25596","severity":"Low","summary":"Exchange Audit event 25596 records: Remove-PublicFolderMigrationRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-PublicFolderMigrationRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25596.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-PublicFolderMigrationRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25596\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25596} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25596","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25596","Event ID 25596","Remove-PublicFolderMigrationRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68509,"title":"Exchange Audit Event 25597 - Remove-ResourcePolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25597","Exchange"],"keywords":["25597","event 25597","event id 25597","Remove-ResourcePolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25597"],"errorCode":"","eventId":"25597","severity":"Medium","summary":"Exchange Audit event 25597 records: Remove-ResourcePolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-ResourcePolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25597.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-ResourcePolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25597\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25597} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25597","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25597","Event ID 25597","Remove-ResourcePolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68510,"title":"Exchange Audit Event 25598 - Remove-ResubmitRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25598","Exchange"],"keywords":["25598","event 25598","event id 25598","Remove-ResubmitRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25598"],"errorCode":"","eventId":"25598","severity":"Low","summary":"Exchange Audit event 25598 records: Remove-ResubmitRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-ResubmitRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25598.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-ResubmitRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25598\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25598} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25598","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25598","Event ID 25598","Remove-ResubmitRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68511,"title":"Exchange Audit Event 25599 - Remove-SiteMailboxProvisioningPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25599","Exchange"],"keywords":["25599","event 25599","event id 25599","Remove-SiteMailboxProvisioningPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25599"],"errorCode":"","eventId":"25599","severity":"Medium","summary":"Exchange Audit event 25599 records: Remove-SiteMailboxProvisioningPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-SiteMailboxProvisioningPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25599.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-SiteMailboxProvisioningPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25599\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25599} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25599","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25599","Event ID 25599","Remove-SiteMailboxProvisioningPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68512,"title":"Exchange Audit Event 25600 - Remove-UMCallAnsweringRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25600","Exchange"],"keywords":["25600","event 25600","event id 25600","Remove-UMCallAnsweringRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25600"],"errorCode":"","eventId":"25600","severity":"Low","summary":"Exchange Audit event 25600 records: Remove-UMCallAnsweringRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-UMCallAnsweringRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25600.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-UMCallAnsweringRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25600\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25600} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25600","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25600","Event ID 25600","Remove-UMCallAnsweringRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68513,"title":"Exchange Audit Event 25601 - Remove-UserPhoto Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25601","Exchange"],"keywords":["25601","event 25601","event id 25601","Remove-UserPhoto Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25601"],"errorCode":"","eventId":"25601","severity":"Low","summary":"Exchange Audit event 25601 records: Remove-UserPhoto Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-UserPhoto Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25601.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-UserPhoto Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25601\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25601} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25601","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25601","Event ID 25601","Remove-UserPhoto Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68514,"title":"Exchange Audit Event 25602 - Remove-WorkloadManagementPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25602","Exchange"],"keywords":["25602","event 25602","event id 25602","Remove-WorkloadManagementPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25602"],"errorCode":"","eventId":"25602","severity":"Medium","summary":"Exchange Audit event 25602 records: Remove-WorkloadManagementPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-WorkloadManagementPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25602.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-WorkloadManagementPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25602\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25602} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25602","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25602","Event ID 25602","Remove-WorkloadManagementPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68515,"title":"Exchange Audit Event 25603 - Remove-WorkloadPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25603","Exchange"],"keywords":["25603","event 25603","event id 25603","Remove-WorkloadPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25603"],"errorCode":"","eventId":"25603","severity":"Medium","summary":"Exchange Audit event 25603 records: Remove-WorkloadPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-WorkloadPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25603.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-WorkloadPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25603\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25603} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25603","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25603","Event ID 25603","Remove-WorkloadPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68516,"title":"Exchange Audit Event 25604 - Reset-ProvisioningCache Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25604","Exchange"],"keywords":["25604","event 25604","event id 25604","Reset-ProvisioningCache Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25604"],"errorCode":"","eventId":"25604","severity":"Medium","summary":"Exchange Audit event 25604 records: Reset-ProvisioningCache Exchange cmdlet issued","rootCause":"The event records a state-changing operation: Reset-ProvisioningCache Exchange cmdlet issued It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25604.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Reset-ProvisioningCache Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25604\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25604} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25604","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25604","Event ID 25604","Reset-ProvisioningCache Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68517,"title":"Exchange Audit Event 25605 - Resume-MailboxImportRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25605","Exchange"],"keywords":["25605","event 25605","event id 25605","Resume-MailboxImportRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25605"],"errorCode":"","eventId":"25605","severity":"Low","summary":"Exchange Audit event 25605 records: Resume-MailboxImportRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Resume-MailboxImportRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25605.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Resume-MailboxImportRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25605\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25605} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25605","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25605","Event ID 25605","Resume-MailboxImportRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68518,"title":"Exchange Audit Event 25606 - Resume-MalwareFilterRecoveryItem Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25606","Exchange"],"keywords":["25606","event 25606","event id 25606","Resume-MalwareFilterRecoveryItem Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25606"],"errorCode":"","eventId":"25606","severity":"Critical","summary":"Exchange Audit event 25606 records: Resume-MalwareFilterRecoveryItem Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Resume-MalwareFilterRecoveryItem Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25606.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Resume-MalwareFilterRecoveryItem Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25606\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25606} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25606","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25606","Event ID 25606","Resume-MalwareFilterRecoveryItem Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68519,"title":"Exchange Audit Event 25607 - Resume-PublicFolderMigrationRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25607","Exchange"],"keywords":["25607","event 25607","event id 25607","Resume-PublicFolderMigrationRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25607"],"errorCode":"","eventId":"25607","severity":"Low","summary":"Exchange Audit event 25607 records: Resume-PublicFolderMigrationRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Resume-PublicFolderMigrationRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25607.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Resume-PublicFolderMigrationRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25607\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25607} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25607","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25607","Event ID 25607","Resume-PublicFolderMigrationRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68520,"title":"Exchange Audit Event 25608 - Set-ActiveSyncDeviceAccessRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25608","Exchange"],"keywords":["25608","event 25608","event id 25608","Set-ActiveSyncDeviceAccessRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25608"],"errorCode":"","eventId":"25608","severity":"Low","summary":"Exchange Audit event 25608 records: Set-ActiveSyncDeviceAccessRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ActiveSyncDeviceAccessRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25608.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ActiveSyncDeviceAccessRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25608\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25608} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25608","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25608","Event ID 25608","Set-ActiveSyncDeviceAccessRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68521,"title":"Exchange Audit Event 25609 - Set-AddressBookPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25609","Exchange"],"keywords":["25609","event 25609","event id 25609","Set-AddressBookPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25609"],"errorCode":"","eventId":"25609","severity":"Medium","summary":"Exchange Audit event 25609 records: Set-AddressBookPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-AddressBookPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25609.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-AddressBookPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25609\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25609} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25609","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25609","Event ID 25609","Set-AddressBookPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68522,"title":"Exchange Audit Event 25610 - Set-App Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25610","Exchange"],"keywords":["25610","event 25610","event id 25610","Set-App Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25610"],"errorCode":"","eventId":"25610","severity":"Low","summary":"Exchange Audit event 25610 records: Set-App Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-App Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25610.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-App Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25610\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25610} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25610","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25610","Event ID 25610","Set-App Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68523,"title":"Exchange Audit Event 25611 - Set-AuthConfig Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25611","Exchange"],"keywords":["25611","event 25611","event id 25611","Set-AuthConfig Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25611"],"errorCode":"","eventId":"25611","severity":"Low","summary":"Exchange Audit event 25611 records: Set-AuthConfig Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-AuthConfig Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25611.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-AuthConfig Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25611\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25611} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25611","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25611","Event ID 25611","Set-AuthConfig Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68524,"title":"Exchange Audit Event 25612 - Set-AuthServer Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25612","Exchange"],"keywords":["25612","event 25612","event id 25612","Set-AuthServer Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25612"],"errorCode":"","eventId":"25612","severity":"Low","summary":"Exchange Audit event 25612 records: Set-AuthServer Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-AuthServer Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25612.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-AuthServer Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25612\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25612} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25612","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25612","Event ID 25612","Set-AuthServer Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68525,"title":"Exchange Audit Event 25613 - Set-ClassificationRuleCollection Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25613","Exchange"],"keywords":["25613","event 25613","event id 25613","Set-ClassificationRuleCollection Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25613"],"errorCode":"","eventId":"25613","severity":"Low","summary":"Exchange Audit event 25613 records: Set-ClassificationRuleCollection Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ClassificationRuleCollection Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25613.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ClassificationRuleCollection Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25613\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25613} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25613","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25613","Event ID 25613","Set-ClassificationRuleCollection Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68526,"title":"Exchange Audit Event 25614 - Set-DlpPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25614","Exchange"],"keywords":["25614","event 25614","event id 25614","Set-DlpPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25614"],"errorCode":"","eventId":"25614","severity":"Medium","summary":"Exchange Audit event 25614 records: Set-DlpPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-DlpPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25614.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-DlpPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25614\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25614} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25614","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25614","Event ID 25614","Set-DlpPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68527,"title":"Exchange Audit Event 25615 - Set-FrontendTransportService Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25615","Exchange"],"keywords":["25615","event 25615","event id 25615","Set-FrontendTransportService Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25615"],"errorCode":"","eventId":"25615","severity":"Low","summary":"Exchange Audit event 25615 records: Set-FrontendTransportService Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-FrontendTransportService Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25615.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-FrontendTransportService Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25615\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25615} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25615","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25615","Event ID 25615","Set-FrontendTransportService Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68528,"title":"Exchange Audit Event 25616 - Set-HybridConfiguration Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25616","Exchange"],"keywords":["25616","event 25616","event id 25616","Set-HybridConfiguration Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25616"],"errorCode":"","eventId":"25616","severity":"Low","summary":"Exchange Audit event 25616 records: Set-HybridConfiguration Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-HybridConfiguration Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25616.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-HybridConfiguration Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25616\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25616} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25616","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25616","Event ID 25616","Set-HybridConfiguration Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68529,"title":"Exchange Audit Event 25617 - Set-HybridMailflow Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25617","Exchange"],"keywords":["25617","event 25617","event id 25617","Set-HybridMailflow Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25617"],"errorCode":"","eventId":"25617","severity":"Low","summary":"Exchange Audit event 25617 records: Set-HybridMailflow Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-HybridMailflow Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25617.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-HybridMailflow Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25617\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25617} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25617","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25617","Event ID 25617","Set-HybridMailflow Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68530,"title":"Exchange Audit Event 25618 - Set-MailboxExportRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25618","Exchange"],"keywords":["25618","event 25618","event id 25618","Set-MailboxExportRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25618"],"errorCode":"","eventId":"25618","severity":"Low","summary":"Exchange Audit event 25618 records: Set-MailboxExportRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MailboxExportRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25618.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MailboxExportRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25618\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25618} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25618","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25618","Event ID 25618","Set-MailboxExportRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68531,"title":"Exchange Audit Event 25619 - Set-MailboxImportRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25619","Exchange"],"keywords":["25619","event 25619","event id 25619","Set-MailboxImportRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25619"],"errorCode":"","eventId":"25619","severity":"Low","summary":"Exchange Audit event 25619 records: Set-MailboxImportRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MailboxImportRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25619.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MailboxImportRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25619\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25619} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25619","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25619","Event ID 25619","Set-MailboxImportRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68532,"title":"Exchange Audit Event 25620 - Set-MailboxSearch Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25620","Exchange"],"keywords":["25620","event 25620","event id 25620","Set-MailboxSearch Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25620"],"errorCode":"","eventId":"25620","severity":"Low","summary":"Exchange Audit event 25620 records: Set-MailboxSearch Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MailboxSearch Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25620.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MailboxSearch Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25620\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25620} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25620","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25620","Event ID 25620","Set-MailboxSearch Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68533,"title":"Exchange Audit Event 25621 - Set-MailboxTransportService Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25621","Exchange"],"keywords":["25621","event 25621","event id 25621","Set-MailboxTransportService Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25621"],"errorCode":"","eventId":"25621","severity":"Low","summary":"Exchange Audit event 25621 records: Set-MailboxTransportService Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MailboxTransportService Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25621.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MailboxTransportService Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25621\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25621} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25621","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25621","Event ID 25621","Set-MailboxTransportService Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68534,"title":"Exchange Audit Event 25622 - Set-MalwareFilteringServer Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25622","Exchange"],"keywords":["25622","event 25622","event id 25622","Set-MalwareFilteringServer Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25622"],"errorCode":"","eventId":"25622","severity":"Critical","summary":"Exchange Audit event 25622 records: Set-MalwareFilteringServer Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MalwareFilteringServer Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25622.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MalwareFilteringServer Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25622\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25622} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25622","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25622","Event ID 25622","Set-MalwareFilteringServer Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68535,"title":"Exchange Audit Event 25623 - Set-MalwareFilterPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25623","Exchange"],"keywords":["25623","event 25623","event id 25623","Set-MalwareFilterPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25623"],"errorCode":"","eventId":"25623","severity":"Critical","summary":"Exchange Audit event 25623 records: Set-MalwareFilterPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MalwareFilterPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25623.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MalwareFilterPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25623\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25623} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25623","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25623","Event ID 25623","Set-MalwareFilterPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68536,"title":"Exchange Audit Event 25624 - Set-MigrationBatch Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25624","Exchange"],"keywords":["25624","event 25624","event id 25624","Set-MigrationBatch Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25624"],"errorCode":"","eventId":"25624","severity":"Low","summary":"Exchange Audit event 25624 records: Set-MigrationBatch Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MigrationBatch Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25624.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MigrationBatch Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25624\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25624} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25624","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25624","Event ID 25624","Set-MigrationBatch Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68537,"title":"Exchange Audit Event 25625 - Set-MigrationConfig Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25625","Exchange"],"keywords":["25625","event 25625","event id 25625","Set-MigrationConfig Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25625"],"errorCode":"","eventId":"25625","severity":"Low","summary":"Exchange Audit event 25625 records: Set-MigrationConfig Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MigrationConfig Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25625.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MigrationConfig Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25625\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25625} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25625","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25625","Event ID 25625","Set-MigrationConfig Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68538,"title":"Exchange Audit Event 25626 - Set-MigrationEndpoint Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25626","Exchange"],"keywords":["25626","event 25626","event id 25626","Set-MigrationEndpoint Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25626"],"errorCode":"","eventId":"25626","severity":"Low","summary":"Exchange Audit event 25626 records: Set-MigrationEndpoint Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MigrationEndpoint Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25626.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MigrationEndpoint Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25626\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25626} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25626","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25626","Event ID 25626","Set-MigrationEndpoint Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68539,"title":"Exchange Audit Event 25627 - Set-MobileDeviceMailboxPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25627","Exchange"],"keywords":["25627","event 25627","event id 25627","Set-MobileDeviceMailboxPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25627"],"errorCode":"","eventId":"25627","severity":"Medium","summary":"Exchange Audit event 25627 records: Set-MobileDeviceMailboxPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MobileDeviceMailboxPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25627.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MobileDeviceMailboxPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25627\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25627} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25627","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25627","Event ID 25627","Set-MobileDeviceMailboxPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68540,"title":"Exchange Audit Event 25628 - Set-Notification Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25628","Exchange"],"keywords":["25628","event 25628","event id 25628","Set-Notification Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25628"],"errorCode":"","eventId":"25628","severity":"Low","summary":"Exchange Audit event 25628 records: Set-Notification Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-Notification Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25628.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-Notification Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25628\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25628} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25628","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25628","Event ID 25628","Set-Notification Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68541,"title":"Exchange Audit Event 25629 - Set-OnPremisesOrganization Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25629","Exchange"],"keywords":["25629","event 25629","event id 25629","Set-OnPremisesOrganization Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25629"],"errorCode":"","eventId":"25629","severity":"Low","summary":"Exchange Audit event 25629 records: Set-OnPremisesOrganization Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-OnPremisesOrganization Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25629.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-OnPremisesOrganization Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25629\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25629} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25629","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25629","Event ID 25629","Set-OnPremisesOrganization Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68542,"title":"Exchange Audit Event 25630 - Set-PartnerApplication Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25630","Exchange"],"keywords":["25630","event 25630","event id 25630","Set-PartnerApplication Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25630"],"errorCode":"","eventId":"25630","severity":"Low","summary":"Exchange Audit event 25630 records: Set-PartnerApplication Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-PartnerApplication Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25630.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-PartnerApplication Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25630\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25630} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25630","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25630","Event ID 25630","Set-PartnerApplication Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68543,"title":"Exchange Audit Event 25631 - Set-PendingFederatedDomain Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25631","Exchange"],"keywords":["25631","event 25631","event id 25631","Set-PendingFederatedDomain Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25631"],"errorCode":"","eventId":"25631","severity":"Low","summary":"Exchange Audit event 25631 records: Set-PendingFederatedDomain Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-PendingFederatedDomain Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25631.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-PendingFederatedDomain Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25631\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25631} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25631","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25631","Event ID 25631","Set-PendingFederatedDomain Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68544,"title":"Exchange Audit Event 25632 - Set-PolicyTipConfig Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25632","Exchange"],"keywords":["25632","event 25632","event id 25632","Set-PolicyTipConfig Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25632"],"errorCode":"","eventId":"25632","severity":"Medium","summary":"Exchange Audit event 25632 records: Set-PolicyTipConfig Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-PolicyTipConfig Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25632.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-PolicyTipConfig Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25632\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25632} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25632","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25632","Event ID 25632","Set-PolicyTipConfig Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68545,"title":"Exchange Audit Event 25633 - Set-PublicFolderMigrationRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25633","Exchange"],"keywords":["25633","event 25633","event id 25633","Set-PublicFolderMigrationRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25633"],"errorCode":"","eventId":"25633","severity":"Low","summary":"Exchange Audit event 25633 records: Set-PublicFolderMigrationRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-PublicFolderMigrationRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25633.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-PublicFolderMigrationRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25633\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25633} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25633","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25633","Event ID 25633","Set-PublicFolderMigrationRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68546,"title":"Exchange Audit Event 25634 - Set-ResourcePolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25634","Exchange"],"keywords":["25634","event 25634","event id 25634","Set-ResourcePolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25634"],"errorCode":"","eventId":"25634","severity":"Medium","summary":"Exchange Audit event 25634 records: Set-ResourcePolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ResourcePolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25634.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ResourcePolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25634\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25634} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25634","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25634","Event ID 25634","Set-ResourcePolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68547,"title":"Exchange Audit Event 25635 - Set-ResubmitRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25635","Exchange"],"keywords":["25635","event 25635","event id 25635","Set-ResubmitRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25635"],"errorCode":"","eventId":"25635","severity":"Low","summary":"Exchange Audit event 25635 records: Set-ResubmitRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ResubmitRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25635.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ResubmitRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25635\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25635} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25635","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25635","Event ID 25635","Set-ResubmitRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68548,"title":"Exchange Audit Event 25636 - Set-RMSTemplate Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25636","Exchange"],"keywords":["25636","event 25636","event id 25636","Set-RMSTemplate Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25636"],"errorCode":"","eventId":"25636","severity":"Low","summary":"Exchange Audit event 25636 records: Set-RMSTemplate Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-RMSTemplate Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25636.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-RMSTemplate Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25636\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25636} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25636","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25636","Event ID 25636","Set-RMSTemplate Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68549,"title":"Exchange Audit Event 25637 - Set-ServerComponentState Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25637","Exchange"],"keywords":["25637","event 25637","event id 25637","Set-ServerComponentState Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25637"],"errorCode":"","eventId":"25637","severity":"Low","summary":"Exchange Audit event 25637 records: Set-ServerComponentState Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ServerComponentState Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25637.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ServerComponentState Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25637\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25637} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25637","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25637","Event ID 25637","Set-ServerComponentState Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68550,"title":"Exchange Audit Event 25638 - Set-ServerMonitor Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25638","Exchange"],"keywords":["25638","event 25638","event id 25638","Set-ServerMonitor Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25638"],"errorCode":"","eventId":"25638","severity":"Low","summary":"Exchange Audit event 25638 records: Set-ServerMonitor Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ServerMonitor Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25638.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ServerMonitor Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25638\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25638} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25638","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25638","Event ID 25638","Set-ServerMonitor Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68551,"title":"Exchange Audit Event 25639 - Set-SiteMailbox Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25639","Exchange"],"keywords":["25639","event 25639","event id 25639","Set-SiteMailbox Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25639"],"errorCode":"","eventId":"25639","severity":"Low","summary":"Exchange Audit event 25639 records: Set-SiteMailbox Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-SiteMailbox Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25639.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-SiteMailbox Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25639\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25639} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25639","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25639","Event ID 25639","Set-SiteMailbox Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68552,"title":"Exchange Audit Event 25640 - Set-SiteMailboxProvisioningPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25640","Exchange"],"keywords":["25640","event 25640","event id 25640","Set-SiteMailboxProvisioningPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25640"],"errorCode":"","eventId":"25640","severity":"Medium","summary":"Exchange Audit event 25640 records: Set-SiteMailboxProvisioningPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-SiteMailboxProvisioningPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25640.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-SiteMailboxProvisioningPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25640\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25640} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25640","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25640","Event ID 25640","Set-SiteMailboxProvisioningPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68553,"title":"Exchange Audit Event 25641 - Set-TransportService Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25641","Exchange"],"keywords":["25641","event 25641","event id 25641","Set-TransportService Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25641"],"errorCode":"","eventId":"25641","severity":"Low","summary":"Exchange Audit event 25641 records: Set-TransportService Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-TransportService Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25641.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-TransportService Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25641\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25641} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25641","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25641","Event ID 25641","Set-TransportService Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68554,"title":"Exchange Audit Event 25642 - Set-UMCallAnsweringRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25642","Exchange"],"keywords":["25642","event 25642","event id 25642","Set-UMCallAnsweringRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25642"],"errorCode":"","eventId":"25642","severity":"Low","summary":"Exchange Audit event 25642 records: Set-UMCallAnsweringRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-UMCallAnsweringRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25642.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-UMCallAnsweringRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25642\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25642} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25642","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25642","Event ID 25642","Set-UMCallAnsweringRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68555,"title":"Exchange Audit Event 25643 - Set-UMCallRouterSettings Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25643","Exchange"],"keywords":["25643","event 25643","event id 25643","Set-UMCallRouterSettings Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25643"],"errorCode":"","eventId":"25643","severity":"Low","summary":"Exchange Audit event 25643 records: Set-UMCallRouterSettings Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-UMCallRouterSettings Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25643.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-UMCallRouterSettings Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25643\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25643} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25643","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25643","Event ID 25643","Set-UMCallRouterSettings Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68556,"title":"Exchange Audit Event 25644 - Set-UMService Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25644","Exchange"],"keywords":["25644","event 25644","event id 25644","Set-UMService Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25644"],"errorCode":"","eventId":"25644","severity":"Low","summary":"Exchange Audit event 25644 records: Set-UMService Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-UMService Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25644.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-UMService Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25644\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25644} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25644","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25644","Event ID 25644","Set-UMService Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68557,"title":"Exchange Audit Event 25645 - Set-UserPhoto Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25645","Exchange"],"keywords":["25645","event 25645","event id 25645","Set-UserPhoto Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25645"],"errorCode":"","eventId":"25645","severity":"Low","summary":"Exchange Audit event 25645 records: Set-UserPhoto Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-UserPhoto Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25645.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-UserPhoto Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25645\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25645} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25645","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25645","Event ID 25645","Set-UserPhoto Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68558,"title":"Exchange Audit Event 25646 - Set-WorkloadPolicy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25646","Exchange"],"keywords":["25646","event 25646","event id 25646","Set-WorkloadPolicy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25646"],"errorCode":"","eventId":"25646","severity":"Medium","summary":"Exchange Audit event 25646 records: Set-WorkloadPolicy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-WorkloadPolicy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25646.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-WorkloadPolicy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25646\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25646} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25646","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25646","Event ID 25646","Set-WorkloadPolicy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68559,"title":"Exchange Audit Event 25647 - Start-MailboxSearch Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25647","Exchange"],"keywords":["25647","event 25647","event id 25647","Start-MailboxSearch Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25647"],"errorCode":"","eventId":"25647","severity":"Low","summary":"Exchange Audit event 25647 records: Start-MailboxSearch Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Start-MailboxSearch Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25647.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Start-MailboxSearch Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25647\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25647} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25647","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25647","Event ID 25647","Start-MailboxSearch Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68560,"title":"Exchange Audit Event 25648 - Start-MigrationBatch Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25648","Exchange"],"keywords":["25648","event 25648","event id 25648","Start-MigrationBatch Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25648"],"errorCode":"","eventId":"25648","severity":"Low","summary":"Exchange Audit event 25648 records: Start-MigrationBatch Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Start-MigrationBatch Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25648.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Start-MigrationBatch Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25648\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25648} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25648","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25648","Event ID 25648","Start-MigrationBatch Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68561,"title":"Exchange Audit Event 25649 - Stop-MailboxSearch Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25649","Exchange"],"keywords":["25649","event 25649","event id 25649","Stop-MailboxSearch Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25649"],"errorCode":"","eventId":"25649","severity":"Low","summary":"Exchange Audit event 25649 records: Stop-MailboxSearch Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Stop-MailboxSearch Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25649.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Stop-MailboxSearch Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25649\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25649} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25649","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25649","Event ID 25649","Stop-MailboxSearch Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68562,"title":"Exchange Audit Event 25650 - Stop-MigrationBatch Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25650","Exchange"],"keywords":["25650","event 25650","event id 25650","Stop-MigrationBatch Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25650"],"errorCode":"","eventId":"25650","severity":"Low","summary":"Exchange Audit event 25650 records: Stop-MigrationBatch Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Stop-MigrationBatch Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25650.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Stop-MigrationBatch Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25650\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25650} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25650","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25650","Event ID 25650","Stop-MigrationBatch Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68563,"title":"Exchange Audit Event 25651 - Suspend-MailboxExportRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25651","Exchange"],"keywords":["25651","event 25651","event id 25651","Suspend-MailboxExportRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25651"],"errorCode":"","eventId":"25651","severity":"Low","summary":"Exchange Audit event 25651 records: Suspend-MailboxExportRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Suspend-MailboxExportRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25651.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Suspend-MailboxExportRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25651\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25651} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25651","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25651","Event ID 25651","Suspend-MailboxExportRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68564,"title":"Exchange Audit Event 25652 - Suspend-MailboxImportRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25652","Exchange"],"keywords":["25652","event 25652","event id 25652","Suspend-MailboxImportRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25652"],"errorCode":"","eventId":"25652","severity":"Low","summary":"Exchange Audit event 25652 records: Suspend-MailboxImportRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Suspend-MailboxImportRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25652.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Suspend-MailboxImportRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25652\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25652} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25652","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25652","Event ID 25652","Suspend-MailboxImportRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68565,"title":"Exchange Audit Event 25653 - Suspend-PublicFolderMigrationRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25653","Exchange"],"keywords":["25653","event 25653","event id 25653","Suspend-PublicFolderMigrationRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25653"],"errorCode":"","eventId":"25653","severity":"Low","summary":"Exchange Audit event 25653 records: Suspend-PublicFolderMigrationRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Suspend-PublicFolderMigrationRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25653.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Suspend-PublicFolderMigrationRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25653\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25653} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25653","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25653","Event ID 25653","Suspend-PublicFolderMigrationRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68566,"title":"Exchange Audit Event 25654 - Test-ArchiveConnectivity Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25654","Exchange"],"keywords":["25654","event 25654","event id 25654","Test-ArchiveConnectivity Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25654"],"errorCode":"","eventId":"25654","severity":"Low","summary":"Exchange Audit event 25654 records: Test-ArchiveConnectivity Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-ArchiveConnectivity Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25654.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-ArchiveConnectivity Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25654\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25654} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25654","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25654","Event ID 25654","Test-ArchiveConnectivity Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68567,"title":"Exchange Audit Event 25655 - Test-MigrationServerAvailability Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25655","Exchange"],"keywords":["25655","event 25655","event id 25655","Test-MigrationServerAvailability Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25655"],"errorCode":"","eventId":"25655","severity":"Low","summary":"Exchange Audit event 25655 records: Test-MigrationServerAvailability Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-MigrationServerAvailability Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25655.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-MigrationServerAvailability Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25655\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25655} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25655","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25655","Event ID 25655","Test-MigrationServerAvailability Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68568,"title":"Exchange Audit Event 25656 - Test-OAuthConnectivity Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25656","Exchange"],"keywords":["25656","event 25656","event id 25656","Test-OAuthConnectivity Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25656"],"errorCode":"","eventId":"25656","severity":"Low","summary":"Exchange Audit event 25656 records: Test-OAuthConnectivity Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-OAuthConnectivity Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25656.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-OAuthConnectivity Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25656\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25656} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25656","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25656","Event ID 25656","Test-OAuthConnectivity Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68569,"title":"Exchange Audit Event 25657 - Test-SiteMailbox Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25657","Exchange"],"keywords":["25657","event 25657","event id 25657","Test-SiteMailbox Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25657"],"errorCode":"","eventId":"25657","severity":"Low","summary":"Exchange Audit event 25657 records: Test-SiteMailbox Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-SiteMailbox Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25657.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-SiteMailbox Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25657\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25657} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25657","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25657","Event ID 25657","Test-SiteMailbox Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68570,"title":"Exchange Audit Event 25658 - Update-HybridConfiguration Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25658","Exchange"],"keywords":["25658","event 25658","event id 25658","Update-HybridConfiguration Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25658"],"errorCode":"","eventId":"25658","severity":"Low","summary":"Exchange Audit event 25658 records: Update-HybridConfiguration Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Update-HybridConfiguration Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25658.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Update-HybridConfiguration Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25658\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25658} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25658","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25658","Event ID 25658","Update-HybridConfiguration Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68571,"title":"Exchange Audit Event 25659 - Update-PublicFolderMailbox Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25659","Exchange"],"keywords":["25659","event 25659","event id 25659","Update-PublicFolderMailbox Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25659"],"errorCode":"","eventId":"25659","severity":"Low","summary":"Exchange Audit event 25659 records: Update-PublicFolderMailbox Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Update-PublicFolderMailbox Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25659.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Update-PublicFolderMailbox Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25659\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25659} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25659","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25659","Event ID 25659","Update-PublicFolderMailbox Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68572,"title":"Exchange Audit Event 25660 - Update-SiteMailbox Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25660","Exchange"],"keywords":["25660","event 25660","event id 25660","Update-SiteMailbox Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25660"],"errorCode":"","eventId":"25660","severity":"Low","summary":"Exchange Audit event 25660 records: Update-SiteMailbox Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Update-SiteMailbox Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25660.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Update-SiteMailbox Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25660\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25660} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25660","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25660","Event ID 25660","Update-SiteMailbox Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68573,"title":"Exchange Audit Event 25661 - Add-AttachmentFilterEntry Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25661","Exchange"],"keywords":["25661","event 25661","event id 25661","Add-AttachmentFilterEntry Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25661"],"errorCode":"","eventId":"25661","severity":"Low","summary":"Exchange Audit event 25661 records: Add-AttachmentFilterEntry Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Add-AttachmentFilterEntry Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25661.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add-AttachmentFilterEntry Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25661\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25661} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25661","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25661","Event ID 25661","Add-AttachmentFilterEntry Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68574,"title":"Exchange Audit Event 25662 - Remove-AttachmentFilterEntry Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25662","Exchange"],"keywords":["25662","event 25662","event id 25662","Remove-AttachmentFilterEntry Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25662"],"errorCode":"","eventId":"25662","severity":"Low","summary":"Exchange Audit event 25662 records: Remove-AttachmentFilterEntry Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-AttachmentFilterEntry Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25662.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-AttachmentFilterEntry Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25662\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25662} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25662","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25662","Event ID 25662","Remove-AttachmentFilterEntry Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68575,"title":"Exchange Audit Event 25663 - New-AddressRewriteEntry Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25663","Exchange"],"keywords":["25663","event 25663","event id 25663","New-AddressRewriteEntry Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25663"],"errorCode":"","eventId":"25663","severity":"Low","summary":"Exchange Audit event 25663 records: New-AddressRewriteEntry Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-AddressRewriteEntry Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25663.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-AddressRewriteEntry Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25663\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25663} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25663","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25663","Event ID 25663","New-AddressRewriteEntry Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68576,"title":"Exchange Audit Event 25664 - Remove-AddressRewriteEntry Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25664","Exchange"],"keywords":["25664","event 25664","event id 25664","Remove-AddressRewriteEntry Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25664"],"errorCode":"","eventId":"25664","severity":"Low","summary":"Exchange Audit event 25664 records: Remove-AddressRewriteEntry Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-AddressRewriteEntry Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25664.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-AddressRewriteEntry Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25664\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25664} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25664","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25664","Event ID 25664","Remove-AddressRewriteEntry Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68577,"title":"Exchange Audit Event 25665 - Set-AddressRewriteEntry Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25665","Exchange"],"keywords":["25665","event 25665","event id 25665","Set-AddressRewriteEntry Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25665"],"errorCode":"","eventId":"25665","severity":"Low","summary":"Exchange Audit event 25665 records: Set-AddressRewriteEntry Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-AddressRewriteEntry Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25665.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-AddressRewriteEntry Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25665\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25665} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25665","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25665","Event ID 25665","Set-AddressRewriteEntry Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68578,"title":"Exchange Audit Event 25666 - Set-AttachmentFilterListConfig Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25666","Exchange"],"keywords":["25666","event 25666","event id 25666","Set-AttachmentFilterListConfig Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25666"],"errorCode":"","eventId":"25666","severity":"Low","summary":"Exchange Audit event 25666 records: Set-AttachmentFilterListConfig Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-AttachmentFilterListConfig Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25666.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-AttachmentFilterListConfig Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25666\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25666} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25666","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25666","Event ID 25666","Set-AttachmentFilterListConfig Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68579,"title":"Exchange Audit Event 25667 - Set-MailboxSentItemsConfiguration Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25667","Exchange"],"keywords":["25667","event 25667","event id 25667","Set-MailboxSentItemsConfiguration Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25667"],"errorCode":"","eventId":"25667","severity":"Low","summary":"Exchange Audit event 25667 records: Set-MailboxSentItemsConfiguration Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MailboxSentItemsConfiguration Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25667.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MailboxSentItemsConfiguration Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25667\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25667} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25667","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25667","Event ID 25667","Set-MailboxSentItemsConfiguration Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68580,"title":"Exchange Audit Event 25668 - Update-MovedMailbox Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25668","Exchange"],"keywords":["25668","event 25668","event id 25668","Update-MovedMailbox Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25668"],"errorCode":"","eventId":"25668","severity":"Low","summary":"Exchange Audit event 25668 records: Update-MovedMailbox Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Update-MovedMailbox Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25668.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Update-MovedMailbox Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25668\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25668} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25668","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25668","Event ID 25668","Update-MovedMailbox Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68581,"title":"Exchange Audit Event 25669 - Disable-MalwareFilterRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25669","Exchange"],"keywords":["25669","event 25669","event id 25669","Disable-MalwareFilterRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25669"],"errorCode":"","eventId":"25669","severity":"Critical","summary":"Exchange Audit event 25669 records: Disable-MalwareFilterRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Disable-MalwareFilterRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25669.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Disable-MalwareFilterRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25669\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25669} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25669","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25669","Event ID 25669","Disable-MalwareFilterRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68582,"title":"Exchange Audit Event 25670 - Enable-MalwareFilterRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25670","Exchange"],"keywords":["25670","event 25670","event id 25670","Enable-MalwareFilterRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25670"],"errorCode":"","eventId":"25670","severity":"Critical","summary":"Exchange Audit event 25670 records: Enable-MalwareFilterRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-MalwareFilterRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25670.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-MalwareFilterRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25670\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25670} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25670","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25670","Event ID 25670","Enable-MalwareFilterRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68583,"title":"Exchange Audit Event 25671 - New-MalwareFilterRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25671","Exchange"],"keywords":["25671","event 25671","event id 25671","New-MalwareFilterRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25671"],"errorCode":"","eventId":"25671","severity":"Critical","summary":"Exchange Audit event 25671 records: New-MalwareFilterRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-MalwareFilterRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25671.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-MalwareFilterRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25671\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25671} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25671","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25671","Event ID 25671","New-MalwareFilterRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68584,"title":"Exchange Audit Event 25672 - Remove-MalwareFilterRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25672","Exchange"],"keywords":["25672","event 25672","event id 25672","Remove-MalwareFilterRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25672"],"errorCode":"","eventId":"25672","severity":"Critical","summary":"Exchange Audit event 25672 records: Remove-MalwareFilterRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-MalwareFilterRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25672.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-MalwareFilterRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25672\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25672} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25672","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25672","Event ID 25672","Remove-MalwareFilterRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68585,"title":"Exchange Audit Event 25673 - Set-MalwareFilterRule Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25673","Exchange"],"keywords":["25673","event 25673","event id 25673","Set-MalwareFilterRule Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25673"],"errorCode":"","eventId":"25673","severity":"Critical","summary":"Exchange Audit event 25673 records: Set-MalwareFilterRule Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MalwareFilterRule Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25673.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MalwareFilterRule Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25673\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25673} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25673","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25673","Event ID 25673","Set-MalwareFilterRule Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68586,"title":"Exchange Audit Event 25674 - Remove-MailboxRepairRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25674","Exchange"],"keywords":["25674","event 25674","event id 25674","Remove-MailboxRepairRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25674"],"errorCode":"","eventId":"25674","severity":"Low","summary":"Exchange Audit event 25674 records: Remove-MailboxRepairRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-MailboxRepairRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25674.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-MailboxRepairRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25674\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25674} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25674","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25674","Event ID 25674","Remove-MailboxRepairRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68587,"title":"Exchange Audit Event 25675 - Remove-ServerMonitoringOverride Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25675","Exchange"],"keywords":["25675","event 25675","event id 25675","Remove-ServerMonitoringOverride Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25675"],"errorCode":"","eventId":"25675","severity":"Low","summary":"Exchange Audit event 25675 records: Remove-ServerMonitoringOverride Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-ServerMonitoringOverride Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25675.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-ServerMonitoringOverride Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25675\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25675} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25675","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25675","Event ID 25675","Remove-ServerMonitoringOverride Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68588,"title":"Exchange Audit Event 25676 - Update-ExchangeHelp Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25676","Exchange"],"keywords":["25676","event 25676","event id 25676","Update-ExchangeHelp Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25676"],"errorCode":"","eventId":"25676","severity":"Low","summary":"Exchange Audit event 25676 records: Update-ExchangeHelp Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Update-ExchangeHelp Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25676.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Update-ExchangeHelp Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25676\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25676} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25676","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25676","Event ID 25676","Update-ExchangeHelp Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68589,"title":"Exchange Audit Event 25677 - Update-StoreMailboxState Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25677","Exchange"],"keywords":["25677","event 25677","event id 25677","Update-StoreMailboxState Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25677"],"errorCode":"","eventId":"25677","severity":"Low","summary":"Exchange Audit event 25677 records: Update-StoreMailboxState Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Update-StoreMailboxState Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25677.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Update-StoreMailboxState Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25677\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25677} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25677","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25677","Event ID 25677","Update-StoreMailboxState Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68590,"title":"Exchange Audit Event 25678 - Disable-PushNotificationProxy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25678","Exchange"],"keywords":["25678","event 25678","event id 25678","Disable-PushNotificationProxy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25678"],"errorCode":"","eventId":"25678","severity":"Low","summary":"Exchange Audit event 25678 records: Disable-PushNotificationProxy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Disable-PushNotificationProxy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25678.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Disable-PushNotificationProxy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25678\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25678} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25678","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25678","Event ID 25678","Disable-PushNotificationProxy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68591,"title":"Exchange Audit Event 25679 - Enable-PushNotificationProxy Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25679","Exchange"],"keywords":["25679","event 25679","event id 25679","Enable-PushNotificationProxy Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25679"],"errorCode":"","eventId":"25679","severity":"Low","summary":"Exchange Audit event 25679 records: Enable-PushNotificationProxy Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Enable-PushNotificationProxy Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25679.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Enable-PushNotificationProxy Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25679\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25679} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25679","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25679","Event ID 25679","Enable-PushNotificationProxy Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68592,"title":"Exchange Audit Event 25680 - New-PublicFolderMoveRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25680","Exchange"],"keywords":["25680","event 25680","event id 25680","New-PublicFolderMoveRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25680"],"errorCode":"","eventId":"25680","severity":"Low","summary":"Exchange Audit event 25680 records: New-PublicFolderMoveRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-PublicFolderMoveRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25680.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-PublicFolderMoveRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25680\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25680} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25680","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25680","Event ID 25680","New-PublicFolderMoveRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68593,"title":"Exchange Audit Event 25681 - Remove-PublicFolderMoveRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25681","Exchange"],"keywords":["25681","event 25681","event id 25681","Remove-PublicFolderMoveRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25681"],"errorCode":"","eventId":"25681","severity":"Low","summary":"Exchange Audit event 25681 records: Remove-PublicFolderMoveRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-PublicFolderMoveRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25681.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-PublicFolderMoveRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25681\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25681} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25681","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25681","Event ID 25681","Remove-PublicFolderMoveRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68594,"title":"Exchange Audit Event 25682 - Resume-PublicFolderMoveRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25682","Exchange"],"keywords":["25682","event 25682","event id 25682","Resume-PublicFolderMoveRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25682"],"errorCode":"","eventId":"25682","severity":"Low","summary":"Exchange Audit event 25682 records: Resume-PublicFolderMoveRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Resume-PublicFolderMoveRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25682.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Resume-PublicFolderMoveRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25682\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25682} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25682","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25682","Event ID 25682","Resume-PublicFolderMoveRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68595,"title":"Exchange Audit Event 25683 - Set-PublicFolderMoveRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25683","Exchange"],"keywords":["25683","event 25683","event id 25683","Set-PublicFolderMoveRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25683"],"errorCode":"","eventId":"25683","severity":"Low","summary":"Exchange Audit event 25683 records: Set-PublicFolderMoveRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-PublicFolderMoveRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25683.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-PublicFolderMoveRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25683\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25683} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25683","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25683","Event ID 25683","Set-PublicFolderMoveRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68596,"title":"Exchange Audit Event 25684 - Suspend-PublicFolderMoveRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25684","Exchange"],"keywords":["25684","event 25684","event id 25684","Suspend-PublicFolderMoveRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25684"],"errorCode":"","eventId":"25684","severity":"Low","summary":"Exchange Audit event 25684 records: Suspend-PublicFolderMoveRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Suspend-PublicFolderMoveRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25684.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Suspend-PublicFolderMoveRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25684\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25684} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25684","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25684","Event ID 25684","Suspend-PublicFolderMoveRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68597,"title":"Exchange Audit Event 25685 - Update-DatabaseSchema Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25685","Exchange"],"keywords":["25685","event 25685","event id 25685","Update-DatabaseSchema Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25685"],"errorCode":"","eventId":"25685","severity":"Low","summary":"Exchange Audit event 25685 records: Update-DatabaseSchema Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Update-DatabaseSchema Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25685.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Update-DatabaseSchema Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25685\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25685} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25685","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25685","Event ID 25685","Update-DatabaseSchema Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68598,"title":"Exchange Audit Event 25686 - Set-SearchDocumentFormat Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25686","Exchange"],"keywords":["25686","event 25686","event id 25686","Set-SearchDocumentFormat Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25686"],"errorCode":"","eventId":"25686","severity":"Low","summary":"Exchange Audit event 25686 records: Set-SearchDocumentFormat Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-SearchDocumentFormat Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25686.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-SearchDocumentFormat Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25686\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25686} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25686","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25686","Event ID 25686","Set-SearchDocumentFormat Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68599,"title":"Exchange Audit Event 25687 - New-AuthRedirect Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25687","Exchange"],"keywords":["25687","event 25687","event id 25687","New-AuthRedirect Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25687"],"errorCode":"","eventId":"25687","severity":"Low","summary":"Exchange Audit event 25687 records: New-AuthRedirect Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-AuthRedirect Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25687.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-AuthRedirect Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25687\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25687} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25687","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25687","Event ID 25687","New-AuthRedirect Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68600,"title":"Exchange Audit Event 25688 - New-CompliancePolicySyncNotification Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25688","Exchange"],"keywords":["25688","event 25688","event id 25688","New-CompliancePolicySyncNotification Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25688"],"errorCode":"","eventId":"25688","severity":"Medium","summary":"Exchange Audit event 25688 records: New-CompliancePolicySyncNotification Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-CompliancePolicySyncNotification Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25688.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-CompliancePolicySyncNotification Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25688\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25688} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25688","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25688","Event ID 25688","New-CompliancePolicySyncNotification Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68601,"title":"Exchange Audit Event 25689 - New-ComplianceServiceVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25689","Exchange"],"keywords":["25689","event 25689","event id 25689","New-ComplianceServiceVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25689"],"errorCode":"","eventId":"25689","severity":"Low","summary":"Exchange Audit event 25689 records: New-ComplianceServiceVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-ComplianceServiceVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25689.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-ComplianceServiceVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25689\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25689} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25689","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25689","Event ID 25689","New-ComplianceServiceVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68602,"title":"Exchange Audit Event 25690 - New-DatabaseAvailabilityGroupConfiguration Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25690","Exchange"],"keywords":["25690","event 25690","event id 25690","New-DatabaseAvailabilityGroupConfiguration Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25690"],"errorCode":"","eventId":"25690","severity":"Medium","summary":"Exchange Audit event 25690 records: New-DatabaseAvailabilityGroupConfiguration Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-DatabaseAvailabilityGroupConfiguration Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25690.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-DatabaseAvailabilityGroupConfiguration Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25690\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25690} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25690","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25690","Event ID 25690","New-DatabaseAvailabilityGroupConfiguration Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68603,"title":"Exchange Audit Event 25691 - New-DataClassification Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25691","Exchange"],"keywords":["25691","event 25691","event id 25691","New-DataClassification Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25691"],"errorCode":"","eventId":"25691","severity":"Low","summary":"Exchange Audit event 25691 records: New-DataClassification Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-DataClassification Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25691.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-DataClassification Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25691\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25691} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25691","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25691","Event ID 25691","New-DataClassification Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68604,"title":"Exchange Audit Event 25692 - New-Fingerprint Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25692","Exchange"],"keywords":["25692","event 25692","event id 25692","New-Fingerprint Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25692"],"errorCode":"","eventId":"25692","severity":"Low","summary":"Exchange Audit event 25692 records: New-Fingerprint Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-Fingerprint Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25692.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-Fingerprint Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25692\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25692} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25692","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25692","Event ID 25692","New-Fingerprint Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68605,"title":"Exchange Audit Event 25693 - New-IntraOrganizationConnector Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25693","Exchange"],"keywords":["25693","event 25693","event id 25693","New-IntraOrganizationConnector Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25693"],"errorCode":"","eventId":"25693","severity":"Low","summary":"Exchange Audit event 25693 records: New-IntraOrganizationConnector Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-IntraOrganizationConnector Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25693.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-IntraOrganizationConnector Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25693\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25693} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25693","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25693","Event ID 25693","New-IntraOrganizationConnector Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68606,"title":"Exchange Audit Event 25694 - New-MailboxDeliveryVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25694","Exchange"],"keywords":["25694","event 25694","event id 25694","New-MailboxDeliveryVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25694"],"errorCode":"","eventId":"25694","severity":"Low","summary":"Exchange Audit event 25694 records: New-MailboxDeliveryVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-MailboxDeliveryVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25694.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-MailboxDeliveryVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25694\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25694} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25694","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25694","Event ID 25694","New-MailboxDeliveryVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68607,"title":"Exchange Audit Event 25695 - New-MapiVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25695","Exchange"],"keywords":["25695","event 25695","event id 25695","New-MapiVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25695"],"errorCode":"","eventId":"25695","severity":"Low","summary":"Exchange Audit event 25695 records: New-MapiVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-MapiVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25695.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-MapiVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25695\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25695} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25695","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25695","Event ID 25695","New-MapiVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68608,"title":"Exchange Audit Event 25696 - New-OutlookServiceVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25696","Exchange"],"keywords":["25696","event 25696","event id 25696","New-OutlookServiceVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25696"],"errorCode":"","eventId":"25696","severity":"Low","summary":"Exchange Audit event 25696 records: New-OutlookServiceVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-OutlookServiceVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25696.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-OutlookServiceVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25696\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25696} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25696","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25696","Event ID 25696","New-OutlookServiceVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68609,"title":"Exchange Audit Event 25697 - New-RestVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25697","Exchange"],"keywords":["25697","event 25697","event id 25697","New-RestVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25697"],"errorCode":"","eventId":"25697","severity":"Low","summary":"Exchange Audit event 25697 records: New-RestVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-RestVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25697.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-RestVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25697\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25697} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25697","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25697","Event ID 25697","New-RestVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68610,"title":"Exchange Audit Event 25698 - New-SearchDocumentFormat Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25698","Exchange"],"keywords":["25698","event 25698","event id 25698","New-SearchDocumentFormat Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25698"],"errorCode":"","eventId":"25698","severity":"Low","summary":"Exchange Audit event 25698 records: New-SearchDocumentFormat Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-SearchDocumentFormat Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25698.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-SearchDocumentFormat Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25698\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25698} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25698","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25698","Event ID 25698","New-SearchDocumentFormat Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68611,"title":"Exchange Audit Event 25699 - New-SettingOverride Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25699","Exchange"],"keywords":["25699","event 25699","event id 25699","New-SettingOverride Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25699"],"errorCode":"","eventId":"25699","severity":"Low","summary":"Exchange Audit event 25699 records: New-SettingOverride Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-SettingOverride Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25699.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-SettingOverride Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25699\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25699} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25699","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25699","Event ID 25699","New-SettingOverride Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68612,"title":"Exchange Audit Event 25700 - New-SiteMailbox Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25700","Exchange"],"keywords":["25700","event 25700","event id 25700","New-SiteMailbox Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25700"],"errorCode":"","eventId":"25700","severity":"Low","summary":"Exchange Audit event 25700 records: New-SiteMailbox Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: New-SiteMailbox Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25700.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New-SiteMailbox Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25700\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25700} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25700","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25700","Event ID 25700","New-SiteMailbox Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68613,"title":"Exchange Audit Event 25701 - Remove-AuthRedirect Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25701","Exchange"],"keywords":["25701","event 25701","event id 25701","Remove-AuthRedirect Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25701"],"errorCode":"","eventId":"25701","severity":"Low","summary":"Exchange Audit event 25701 records: Remove-AuthRedirect Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-AuthRedirect Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25701.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-AuthRedirect Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25701\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25701} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25701","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25701","Event ID 25701","Remove-AuthRedirect Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68614,"title":"Exchange Audit Event 25702 - Remove-CompliancePolicySyncNotification Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25702","Exchange"],"keywords":["25702","event 25702","event id 25702","Remove-CompliancePolicySyncNotification Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25702"],"errorCode":"","eventId":"25702","severity":"Medium","summary":"Exchange Audit event 25702 records: Remove-CompliancePolicySyncNotification Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-CompliancePolicySyncNotification Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25702.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-CompliancePolicySyncNotification Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25702\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25702} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25702","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25702","Event ID 25702","Remove-CompliancePolicySyncNotification Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68615,"title":"Exchange Audit Event 25703 - Remove-ComplianceServiceVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25703","Exchange"],"keywords":["25703","event 25703","event id 25703","Remove-ComplianceServiceVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25703"],"errorCode":"","eventId":"25703","severity":"Low","summary":"Exchange Audit event 25703 records: Remove-ComplianceServiceVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-ComplianceServiceVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25703.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-ComplianceServiceVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25703\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25703} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25703","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25703","Event ID 25703","Remove-ComplianceServiceVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68616,"title":"Exchange Audit Event 25704 - Remove-DatabaseAvailabilityGroupConfiguration Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25704","Exchange"],"keywords":["25704","event 25704","event id 25704","Remove-DatabaseAvailabilityGroupConfiguration Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25704"],"errorCode":"","eventId":"25704","severity":"Medium","summary":"Exchange Audit event 25704 records: Remove-DatabaseAvailabilityGroupConfiguration Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-DatabaseAvailabilityGroupConfiguration Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25704.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-DatabaseAvailabilityGroupConfiguration Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25704\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25704} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25704","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25704","Event ID 25704","Remove-DatabaseAvailabilityGroupConfiguration Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68617,"title":"Exchange Audit Event 25705 - Remove-DataClassification Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25705","Exchange"],"keywords":["25705","event 25705","event id 25705","Remove-DataClassification Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25705"],"errorCode":"","eventId":"25705","severity":"Low","summary":"Exchange Audit event 25705 records: Remove-DataClassification Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-DataClassification Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25705.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-DataClassification Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25705\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25705} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25705","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25705","Event ID 25705","Remove-DataClassification Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68618,"title":"Exchange Audit Event 25706 - Remove-IntraOrganizationConnector Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25706","Exchange"],"keywords":["25706","event 25706","event id 25706","Remove-IntraOrganizationConnector Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25706"],"errorCode":"","eventId":"25706","severity":"Low","summary":"Exchange Audit event 25706 records: Remove-IntraOrganizationConnector Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-IntraOrganizationConnector Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25706.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-IntraOrganizationConnector Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25706\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25706} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25706","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25706","Event ID 25706","Remove-IntraOrganizationConnector Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68619,"title":"Exchange Audit Event 25707 - Remove-MailboxDeliveryVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25707","Exchange"],"keywords":["25707","event 25707","event id 25707","Remove-MailboxDeliveryVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25707"],"errorCode":"","eventId":"25707","severity":"Low","summary":"Exchange Audit event 25707 records: Remove-MailboxDeliveryVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-MailboxDeliveryVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25707.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-MailboxDeliveryVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25707\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25707} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25707","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25707","Event ID 25707","Remove-MailboxDeliveryVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68620,"title":"Exchange Audit Event 25708 - Remove-MapiVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25708","Exchange"],"keywords":["25708","event 25708","event id 25708","Remove-MapiVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25708"],"errorCode":"","eventId":"25708","severity":"Low","summary":"Exchange Audit event 25708 records: Remove-MapiVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-MapiVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25708.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-MapiVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25708\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25708} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25708","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25708","Event ID 25708","Remove-MapiVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68621,"title":"Exchange Audit Event 25709 - Remove-OutlookServiceVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25709","Exchange"],"keywords":["25709","event 25709","event id 25709","Remove-OutlookServiceVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25709"],"errorCode":"","eventId":"25709","severity":"Low","summary":"Exchange Audit event 25709 records: Remove-OutlookServiceVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-OutlookServiceVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25709.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-OutlookServiceVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25709\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25709} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25709","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25709","Event ID 25709","Remove-OutlookServiceVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68622,"title":"Exchange Audit Event 25710 - Remove-PublicFolderMailboxMigrationRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25710","Exchange"],"keywords":["25710","event 25710","event id 25710","Remove-PublicFolderMailboxMigrationRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25710"],"errorCode":"","eventId":"25710","severity":"Low","summary":"Exchange Audit event 25710 records: Remove-PublicFolderMailboxMigrationRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-PublicFolderMailboxMigrationRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25710.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-PublicFolderMailboxMigrationRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25710\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25710} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25710","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25710","Event ID 25710","Remove-PublicFolderMailboxMigrationRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68623,"title":"Exchange Audit Event 25711 - Remove-PushNotificationSubscription Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25711","Exchange"],"keywords":["25711","event 25711","event id 25711","Remove-PushNotificationSubscription Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25711"],"errorCode":"","eventId":"25711","severity":"Low","summary":"Exchange Audit event 25711 records: Remove-PushNotificationSubscription Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-PushNotificationSubscription Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25711.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-PushNotificationSubscription Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25711\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25711} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25711","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25711","Event ID 25711","Remove-PushNotificationSubscription Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68624,"title":"Exchange Audit Event 25712 - Remove-RestVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25712","Exchange"],"keywords":["25712","event 25712","event id 25712","Remove-RestVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25712"],"errorCode":"","eventId":"25712","severity":"Low","summary":"Exchange Audit event 25712 records: Remove-RestVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-RestVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25712.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-RestVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25712\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25712} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25712","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25712","Event ID 25712","Remove-RestVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68625,"title":"Exchange Audit Event 25713 - Remove-SearchDocumentFormat Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25713","Exchange"],"keywords":["25713","event 25713","event id 25713","Remove-SearchDocumentFormat Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25713"],"errorCode":"","eventId":"25713","severity":"Low","summary":"Exchange Audit event 25713 records: Remove-SearchDocumentFormat Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-SearchDocumentFormat Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25713.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-SearchDocumentFormat Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25713\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25713} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25713","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25713","Event ID 25713","Remove-SearchDocumentFormat Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68626,"title":"Exchange Audit Event 25714 - Remove-SettingOverride Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25714","Exchange"],"keywords":["25714","event 25714","event id 25714","Remove-SettingOverride Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25714"],"errorCode":"","eventId":"25714","severity":"Low","summary":"Exchange Audit event 25714 records: Remove-SettingOverride Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-SettingOverride Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25714.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-SettingOverride Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25714\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25714} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25714","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25714","Event ID 25714","Remove-SettingOverride Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68627,"title":"Exchange Audit Event 25715 - Remove-SyncMailPublicFolder Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25715","Exchange"],"keywords":["25715","event 25715","event id 25715","Remove-SyncMailPublicFolder Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25715"],"errorCode":"","eventId":"25715","severity":"Low","summary":"Exchange Audit event 25715 records: Remove-SyncMailPublicFolder Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Remove-SyncMailPublicFolder Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25715.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove-SyncMailPublicFolder Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25715\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25715} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25715","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25715","Event ID 25715","Remove-SyncMailPublicFolder Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68628,"title":"Exchange Audit Event 25716 - Resume-PublicFolderMailboxMigrationRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25716","Exchange"],"keywords":["25716","event 25716","event id 25716","Resume-PublicFolderMailboxMigrationRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25716"],"errorCode":"","eventId":"25716","severity":"Low","summary":"Exchange Audit event 25716 records: Resume-PublicFolderMailboxMigrationRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Resume-PublicFolderMailboxMigrationRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25716.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Resume-PublicFolderMailboxMigrationRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25716\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25716} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25716","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25716","Event ID 25716","Resume-PublicFolderMailboxMigrationRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68629,"title":"Exchange Audit Event 25717 - Send-MapiSubmitSystemProbe Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25717","Exchange"],"keywords":["25717","event 25717","event id 25717","Send-MapiSubmitSystemProbe Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25717"],"errorCode":"","eventId":"25717","severity":"Low","summary":"Exchange Audit event 25717 records: Send-MapiSubmitSystemProbe Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Send-MapiSubmitSystemProbe Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25717.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Send-MapiSubmitSystemProbe Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25717\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25717} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25717","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25717","Event ID 25717","Send-MapiSubmitSystemProbe Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68630,"title":"Exchange Audit Event 25718 - Set-AuthRedirect Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25718","Exchange"],"keywords":["25718","event 25718","event id 25718","Set-AuthRedirect Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25718"],"errorCode":"","eventId":"25718","severity":"Low","summary":"Exchange Audit event 25718 records: Set-AuthRedirect Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-AuthRedirect Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25718.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-AuthRedirect Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25718\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25718} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25718","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25718","Event ID 25718","Set-AuthRedirect Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68631,"title":"Exchange Audit Event 25719 - Set-ClientAccessService Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25719","Exchange"],"keywords":["25719","event 25719","event id 25719","Set-ClientAccessService Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25719"],"errorCode":"","eventId":"25719","severity":"Low","summary":"Exchange Audit event 25719 records: Set-ClientAccessService Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ClientAccessService Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25719.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ClientAccessService Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25719\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25719} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25719","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25719","Event ID 25719","Set-ClientAccessService Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68632,"title":"Exchange Audit Event 25720 - Set-Clutter Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25720","Exchange"],"keywords":["25720","event 25720","event id 25720","Set-Clutter Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25720"],"errorCode":"","eventId":"25720","severity":"Low","summary":"Exchange Audit event 25720 records: Set-Clutter Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-Clutter Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25720.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-Clutter Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25720\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25720} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25720","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25720","Event ID 25720","Set-Clutter Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68633,"title":"Exchange Audit Event 25721 - Set-ComplianceServiceVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25721","Exchange"],"keywords":["25721","event 25721","event id 25721","Set-ComplianceServiceVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25721"],"errorCode":"","eventId":"25721","severity":"Low","summary":"Exchange Audit event 25721 records: Set-ComplianceServiceVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ComplianceServiceVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25721.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ComplianceServiceVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25721\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25721} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25721","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25721","Event ID 25721","Set-ComplianceServiceVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68634,"title":"Exchange Audit Event 25722 - Set-ConsumerMailbox Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25722","Exchange"],"keywords":["25722","event 25722","event id 25722","Set-ConsumerMailbox Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25722"],"errorCode":"","eventId":"25722","severity":"Low","summary":"Exchange Audit event 25722 records: Set-ConsumerMailbox Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-ConsumerMailbox Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25722.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-ConsumerMailbox Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25722\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25722} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25722","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25722","Event ID 25722","Set-ConsumerMailbox Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68635,"title":"Exchange Audit Event 25723 - Set-DatabaseAvailabilityGroupConfiguration Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25723","Exchange"],"keywords":["25723","event 25723","event id 25723","Set-DatabaseAvailabilityGroupConfiguration Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25723"],"errorCode":"","eventId":"25723","severity":"Medium","summary":"Exchange Audit event 25723 records: Set-DatabaseAvailabilityGroupConfiguration Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-DatabaseAvailabilityGroupConfiguration Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25723.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-DatabaseAvailabilityGroupConfiguration Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25723\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25723} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25723","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25723","Event ID 25723","Set-DatabaseAvailabilityGroupConfiguration Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68636,"title":"Exchange Audit Event 25724 - Set-DataClassification Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25724","Exchange"],"keywords":["25724","event 25724","event id 25724","Set-DataClassification Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25724"],"errorCode":"","eventId":"25724","severity":"Low","summary":"Exchange Audit event 25724 records: Set-DataClassification Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-DataClassification Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25724.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-DataClassification Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25724\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25724} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25724","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25724","Event ID 25724","Set-DataClassification Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68637,"title":"Exchange Audit Event 25725 - Set-IntraOrganizationConnector Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25725","Exchange"],"keywords":["25725","event 25725","event id 25725","Set-IntraOrganizationConnector Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25725"],"errorCode":"","eventId":"25725","severity":"Low","summary":"Exchange Audit event 25725 records: Set-IntraOrganizationConnector Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-IntraOrganizationConnector Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25725.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-IntraOrganizationConnector Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25725\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25725} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25725","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25725","Event ID 25725","Set-IntraOrganizationConnector Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68638,"title":"Exchange Audit Event 25726 - Set-LogExportVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25726","Exchange"],"keywords":["25726","event 25726","event id 25726","Set-LogExportVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25726"],"errorCode":"","eventId":"25726","severity":"Low","summary":"Exchange Audit event 25726 records: Set-LogExportVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-LogExportVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25726.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-LogExportVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25726\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25726} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25726","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25726","Event ID 25726","Set-LogExportVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68639,"title":"Exchange Audit Event 25727 - Set-MailboxDeliveryVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25727","Exchange"],"keywords":["25727","event 25727","event id 25727","Set-MailboxDeliveryVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25727"],"errorCode":"","eventId":"25727","severity":"Low","summary":"Exchange Audit event 25727 records: Set-MailboxDeliveryVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MailboxDeliveryVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25727.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MailboxDeliveryVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25727\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25727} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25727","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25727","Event ID 25727","Set-MailboxDeliveryVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68640,"title":"Exchange Audit Event 25728 - Set-MapiVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25728","Exchange"],"keywords":["25728","event 25728","event id 25728","Set-MapiVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25728"],"errorCode":"","eventId":"25728","severity":"Low","summary":"Exchange Audit event 25728 records: Set-MapiVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-MapiVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25728.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-MapiVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25728\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25728} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25728","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25728","Event ID 25728","Set-MapiVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68641,"title":"Exchange Audit Event 25729 - Set-OutlookServiceVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25729","Exchange"],"keywords":["25729","event 25729","event id 25729","Set-OutlookServiceVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25729"],"errorCode":"","eventId":"25729","severity":"Low","summary":"Exchange Audit event 25729 records: Set-OutlookServiceVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-OutlookServiceVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25729.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-OutlookServiceVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25729\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25729} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25729","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25729","Event ID 25729","Set-OutlookServiceVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68642,"title":"Exchange Audit Event 25730 - Set-PublicFolderMailboxMigrationRequest Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25730","Exchange"],"keywords":["25730","event 25730","event id 25730","Set-PublicFolderMailboxMigrationRequest Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25730"],"errorCode":"","eventId":"25730","severity":"Low","summary":"Exchange Audit event 25730 records: Set-PublicFolderMailboxMigrationRequest Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-PublicFolderMailboxMigrationRequest Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25730.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-PublicFolderMailboxMigrationRequest Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25730\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25730} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25730","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25730","Event ID 25730","Set-PublicFolderMailboxMigrationRequest Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68643,"title":"Exchange Audit Event 25731 - Set-RestVirtualDirectory Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25731","Exchange"],"keywords":["25731","event 25731","event id 25731","Set-RestVirtualDirectory Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25731"],"errorCode":"","eventId":"25731","severity":"Low","summary":"Exchange Audit event 25731 records: Set-RestVirtualDirectory Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-RestVirtualDirectory Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25731.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-RestVirtualDirectory Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25731\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25731} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25731","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25731","Event ID 25731","Set-RestVirtualDirectory Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68644,"title":"Exchange Audit Event 25732 - Set-SettingOverride Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25732","Exchange"],"keywords":["25732","event 25732","event id 25732","Set-SettingOverride Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25732"],"errorCode":"","eventId":"25732","severity":"Low","summary":"Exchange Audit event 25732 records: Set-SettingOverride Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-SettingOverride Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25732.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-SettingOverride Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25732\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25732} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25732","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25732","Event ID 25732","Set-SettingOverride Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68645,"title":"Exchange Audit Event 25733 - Set-SmimeConfig Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25733","Exchange"],"keywords":["25733","event 25733","event id 25733","Set-SmimeConfig Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25733"],"errorCode":"","eventId":"25733","severity":"Low","summary":"Exchange Audit event 25733 records: Set-SmimeConfig Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-SmimeConfig Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25733.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-SmimeConfig Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25733\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25733} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25733","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25733","Event ID 25733","Set-SmimeConfig Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68646,"title":"Exchange Audit Event 25734 - Set-SubmissionMalwareFilteringServer Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25734","Exchange"],"keywords":["25734","event 25734","event id 25734","Set-SubmissionMalwareFilteringServer Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25734"],"errorCode":"","eventId":"25734","severity":"Critical","summary":"Exchange Audit event 25734 records: Set-SubmissionMalwareFilteringServer Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-SubmissionMalwareFilteringServer Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25734.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-SubmissionMalwareFilteringServer Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25734\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25734} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25734","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25734","Event ID 25734","Set-SubmissionMalwareFilteringServer Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68647,"title":"Exchange Audit Event 25735 - Set-UMMailboxConfiguration Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25735","Exchange"],"keywords":["25735","event 25735","event id 25735","Set-UMMailboxConfiguration Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25735"],"errorCode":"","eventId":"25735","severity":"Low","summary":"Exchange Audit event 25735 records: Set-UMMailboxConfiguration Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-UMMailboxConfiguration Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25735.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-UMMailboxConfiguration Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25735\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25735} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25735","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25735","Event ID 25735","Set-UMMailboxConfiguration Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68648,"title":"Exchange Audit Event 25736 - Set-UnifiedAuditSetting Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25736","Exchange"],"keywords":["25736","event 25736","event id 25736","Set-UnifiedAuditSetting Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25736"],"errorCode":"","eventId":"25736","severity":"Low","summary":"Exchange Audit event 25736 records: Set-UnifiedAuditSetting Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Set-UnifiedAuditSetting Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25736.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set-UnifiedAuditSetting Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25736\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25736} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25736","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25736","Event ID 25736","Set-UnifiedAuditSetting Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68649,"title":"Exchange Audit Event 25737 - Start-AuditAssistant Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25737","Exchange"],"keywords":["25737","event 25737","event id 25737","Start-AuditAssistant Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25737"],"errorCode":"","eventId":"25737","severity":"Low","summary":"Exchange Audit event 25737 records: Start-AuditAssistant Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Start-AuditAssistant Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25737.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Start-AuditAssistant Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25737\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25737} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25737","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25737","Event ID 25737","Start-AuditAssistant Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68650,"title":"Exchange Audit Event 25738 - Start-UMPhoneSession Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25738","Exchange"],"keywords":["25738","event 25738","event id 25738","Start-UMPhoneSession Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25738"],"errorCode":"","eventId":"25738","severity":"Low","summary":"Exchange Audit event 25738 records: Start-UMPhoneSession Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Start-UMPhoneSession Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25738.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Start-UMPhoneSession Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25738\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25738} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25738","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25738","Event ID 25738","Start-UMPhoneSession Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68651,"title":"Exchange Audit Event 25739 - Stop-UMPhoneSession Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25739","Exchange"],"keywords":["25739","event 25739","event id 25739","Stop-UMPhoneSession Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25739"],"errorCode":"","eventId":"25739","severity":"Low","summary":"Exchange Audit event 25739 records: Stop-UMPhoneSession Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Stop-UMPhoneSession Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25739.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Stop-UMPhoneSession Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25739\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25739} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25739","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25739","Event ID 25739","Stop-UMPhoneSession Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68652,"title":"Exchange Audit Event 25740 - Test-DataClassification Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25740","Exchange"],"keywords":["25740","event 25740","event id 25740","Test-DataClassification Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25740"],"errorCode":"","eventId":"25740","severity":"Low","summary":"Exchange Audit event 25740 records: Test-DataClassification Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-DataClassification Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25740.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-DataClassification Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25740\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25740} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25740","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25740","Event ID 25740","Test-DataClassification Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68653,"title":"Exchange Audit Event 25741 - Test-TextExtraction Exchange cmdlet issued","category":"Exchange","product":"Exchange Audit via LOGbinder EX","tags":["Exchange Audit","Audit Event","Event ID 25741","Exchange"],"keywords":["25741","event 25741","event id 25741","Test-TextExtraction Exchange cmdlet issued","Exchange Audit","Exchange Audit via LOGbinder EX","EXCHANGE-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25741"],"errorCode":"","eventId":"25741","severity":"Low","summary":"Exchange Audit event 25741 records: Test-TextExtraction Exchange cmdlet issued","rootCause":"The configured audit source recorded this activity: Test-TextExtraction Exchange cmdlet issued It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Exchange Audit event 25741.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Test-TextExtraction Exchange cmdlet issued\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder Exchange audit integration. It is not a native Exchange product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25741\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25741} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25741","namespace":"EXCHANGE-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Exchange","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","Exchange Audit"],"articleCategories":["Security Logs","Audit Events","Exchange Audit","Exchange"],"aliases":["Exchange Audit 25741","Event ID 25741","Test-TextExtraction Exchange cmdlet issued"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68654,"title":"SharePoint Audit Event 11 - Site collection audit policy changed","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 11","SharePoint"],"keywords":["11","event 11","event id 11","Site collection audit policy changed","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=11"],"errorCode":"","eventId":"11","severity":"Medium","summary":"SharePoint Audit event 11 records: Site collection audit policy changed","rootCause":"The event records a state-changing operation: Site collection audit policy changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 11.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Site collection audit policy changed\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=11\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=11} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=11","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 11","Event ID 11","Site collection audit policy changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68655,"title":"SharePoint Audit Event 12 - Audit policy changed","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 12","SharePoint"],"keywords":["12","event 12","event id 12","Audit policy changed","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=12"],"errorCode":"","eventId":"12","severity":"Medium","summary":"SharePoint Audit event 12 records: Audit policy changed","rootCause":"The event records a state-changing operation: Audit policy changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 12.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Audit policy changed\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=12\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=12} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=12","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 12","Event ID 12","Audit policy changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68656,"title":"SharePoint Audit Event 13 - Document checked in","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 13","SharePoint"],"keywords":["13","event 13","event id 13","Document checked in","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=13"],"errorCode":"","eventId":"13","severity":"Low","summary":"SharePoint Audit event 13 records: Document checked in","rootCause":"The configured audit source recorded this activity: Document checked in It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 13.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Document checked in\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=13\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=13} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=13","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 13","Event ID 13","Document checked in"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68657,"title":"SharePoint Audit Event 14 - Document checked out","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 14","SharePoint"],"keywords":["14","event 14","event id 14","Document checked out","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=14"],"errorCode":"","eventId":"14","severity":"Low","summary":"SharePoint Audit event 14 records: Document checked out","rootCause":"The configured audit source recorded this activity: Document checked out It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 14.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Document checked out\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=14\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=14} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=14","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 14","Event ID 14","Document checked out"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68658,"title":"SharePoint Audit Event 15 - Child object deleted","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 15","SharePoint"],"keywords":["15","event 15","event id 15","Child object deleted","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=15"],"errorCode":"","eventId":"15","severity":"High","summary":"SharePoint Audit event 15 records: Child object deleted","rootCause":"The event records a state-changing operation: Child object deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 15.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Child object deleted\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=15\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=15} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=15","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 15","Event ID 15","Child object deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68659,"title":"SharePoint Audit Event 16 - Child object moved","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 16","SharePoint"],"keywords":["16","event 16","event id 16","Child object moved","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=16"],"errorCode":"","eventId":"16","severity":"Low","summary":"SharePoint Audit event 16 records: Child object moved","rootCause":"The configured audit source recorded this activity: Child object moved It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 16.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Child object moved\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=16\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=16} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=16","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 16","Event ID 16","Child object moved"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68660,"title":"SharePoint Audit Event 17 - Object copied","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 17","SharePoint"],"keywords":["17","event 17","event id 17","Object copied","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=17"],"errorCode":"","eventId":"17","severity":"Low","summary":"SharePoint Audit event 17 records: Object copied","rootCause":"The configured audit source recorded this activity: Object copied It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 17.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Object copied\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=17\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=17} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=17","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 17","Event ID 17","Object copied"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68661,"title":"SharePoint Audit Event 18 - Custom event","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 18","SharePoint"],"keywords":["18","event 18","event id 18","Custom event","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=18"],"errorCode":"","eventId":"18","severity":"Low","summary":"SharePoint Audit event 18 records: Custom event","rootCause":"The configured audit source recorded this activity: Custom event It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 18.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Custom event\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=18\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=18} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=18","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 18","Event ID 18","Custom event"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68662,"title":"SharePoint Audit Event 19 - Object deleted","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 19","SharePoint"],"keywords":["19","event 19","event id 19","Object deleted","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=19"],"errorCode":"","eventId":"19","severity":"High","summary":"SharePoint Audit event 19 records: Object deleted","rootCause":"The event records a state-changing operation: Object deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 19.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Object deleted\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=19\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=19} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=19","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 19","Event ID 19","Object deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68663,"title":"SharePoint Audit Event 20 - SharePoint audit logs deleted","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 20","SharePoint"],"keywords":["20","event 20","event id 20","SharePoint audit logs deleted","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=20"],"errorCode":"","eventId":"20","severity":"High","summary":"SharePoint Audit event 20 records: SharePoint audit logs deleted","rootCause":"The event records a state-changing operation: SharePoint audit logs deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 20.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: SharePoint audit logs deleted\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=20\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=20} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=20","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 20","Event ID 20","SharePoint audit logs deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68664,"title":"SharePoint Audit Event 21 - Object moved","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 21","SharePoint"],"keywords":["21","event 21","event id 21","Object moved","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=21"],"errorCode":"","eventId":"21","severity":"Low","summary":"SharePoint Audit event 21 records: Object moved","rootCause":"The configured audit source recorded this activity: Object moved It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 21.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Object moved\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=21\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=21} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=21","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 21","Event ID 21","Object moved"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68665,"title":"SharePoint Audit Event 22 - Object profile changed","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 22","SharePoint"],"keywords":["22","event 22","event id 22","Object profile changed","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=22"],"errorCode":"","eventId":"22","severity":"Medium","summary":"SharePoint Audit event 22 records: Object profile changed","rootCause":"The event records a state-changing operation: Object profile changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 22.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Object profile changed\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=22\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=22} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=22","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 22","Event ID 22","Object profile changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68666,"title":"SharePoint Audit Event 23 - SharePoint object structure changed","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 23","SharePoint"],"keywords":["23","event 23","event id 23","SharePoint object structure changed","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=23"],"errorCode":"","eventId":"23","severity":"Medium","summary":"SharePoint Audit event 23 records: SharePoint object structure changed","rootCause":"The event records a state-changing operation: SharePoint object structure changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 23.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: SharePoint object structure changed\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=23\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=23} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=23","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 23","Event ID 23","SharePoint object structure changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68667,"title":"SharePoint Audit Event 24 - Search performed","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 24","SharePoint"],"keywords":["24","event 24","event id 24","Search performed","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24"],"errorCode":"","eventId":"24","severity":"Low","summary":"SharePoint Audit event 24 records: Search performed","rootCause":"The configured audit source recorded this activity: Search performed It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 24.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Search performed\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 24","Event ID 24","Search performed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68668,"title":"SharePoint Audit Event 25 - SharePoint group created","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 25","SharePoint"],"keywords":["25","event 25","event id 25","SharePoint group created","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25"],"errorCode":"","eventId":"25","severity":"Medium","summary":"SharePoint Audit event 25 records: SharePoint group created","rootCause":"The event records a state-changing operation: SharePoint group created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 25.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: SharePoint group created\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=25} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 25","Event ID 25","SharePoint group created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68669,"title":"SharePoint Audit Event 26 - SharePoint group deleted","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 26","SharePoint"],"keywords":["26","event 26","event id 26","SharePoint group deleted","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=26"],"errorCode":"","eventId":"26","severity":"High","summary":"SharePoint Audit event 26 records: SharePoint group deleted","rootCause":"The event records a state-changing operation: SharePoint group deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 26.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: SharePoint group deleted\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=26\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=26} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=26","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 26","Event ID 26","SharePoint group deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68670,"title":"SharePoint Audit Event 27 - SharePoint group member added","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 27","SharePoint"],"keywords":["27","event 27","event id 27","SharePoint group member added","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=27"],"errorCode":"","eventId":"27","severity":"Medium","summary":"SharePoint Audit event 27 records: SharePoint group member added","rootCause":"The event records a state-changing operation: SharePoint group member added It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 27.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: SharePoint group member added\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=27\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=27} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=27","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 27","Event ID 27","SharePoint group member added"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68671,"title":"SharePoint Audit Event 28 - SharePoint group member removed","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 28","SharePoint"],"keywords":["28","event 28","event id 28","SharePoint group member removed","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=28"],"errorCode":"","eventId":"28","severity":"Medium","summary":"SharePoint Audit event 28 records: SharePoint group member removed","rootCause":"The event records a state-changing operation: SharePoint group member removed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 28.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: SharePoint group member removed\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=28\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=28} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=28","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 28","Event ID 28","SharePoint group member removed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68672,"title":"SharePoint Audit Event 29 - Unique permissions created","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 29","SharePoint"],"keywords":["29","event 29","event id 29","Unique permissions created","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=29"],"errorCode":"","eventId":"29","severity":"Medium","summary":"SharePoint Audit event 29 records: Unique permissions created","rootCause":"The event records a state-changing operation: Unique permissions created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 29.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Unique permissions created\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=29\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=29} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=29","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 29","Event ID 29","Unique permissions created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68673,"title":"SharePoint Audit Event 30 - Unique permissions removed","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 30","SharePoint"],"keywords":["30","event 30","event id 30","Unique permissions removed","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=30"],"errorCode":"","eventId":"30","severity":"Medium","summary":"SharePoint Audit event 30 records: Unique permissions removed","rootCause":"The event records a state-changing operation: Unique permissions removed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 30.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Unique permissions removed\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=30\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=30} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=30","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 30","Event ID 30","Unique permissions removed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68674,"title":"SharePoint Audit Event 31 - Permissions updated","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 31","SharePoint"],"keywords":["31","event 31","event id 31","Permissions updated","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=31"],"errorCode":"","eventId":"31","severity":"Medium","summary":"SharePoint Audit event 31 records: Permissions updated","rootCause":"The configured audit source recorded this activity: Permissions updated It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 31.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Permissions updated\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=31\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=31} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=31","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 31","Event ID 31","Permissions updated"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68675,"title":"SharePoint Audit Event 32 - Permissions removed","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 32","SharePoint"],"keywords":["32","event 32","event id 32","Permissions removed","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=32"],"errorCode":"","eventId":"32","severity":"Medium","summary":"SharePoint Audit event 32 records: Permissions removed","rootCause":"The event records a state-changing operation: Permissions removed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 32.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Permissions removed\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=32\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=32} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=32","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 32","Event ID 32","Permissions removed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68676,"title":"SharePoint Audit Event 33 - Unique permission levels created","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 33","SharePoint"],"keywords":["33","event 33","event id 33","Unique permission levels created","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=33"],"errorCode":"","eventId":"33","severity":"Medium","summary":"SharePoint Audit event 33 records: Unique permission levels created","rootCause":"The event records a state-changing operation: Unique permission levels created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 33.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Unique permission levels created\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=33\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=33} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=33","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 33","Event ID 33","Unique permission levels created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68677,"title":"SharePoint Audit Event 34 - Permission level created","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 34","SharePoint"],"keywords":["34","event 34","event id 34","Permission level created","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=34"],"errorCode":"","eventId":"34","severity":"Medium","summary":"SharePoint Audit event 34 records: Permission level created","rootCause":"The event records a state-changing operation: Permission level created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 34.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Permission level created\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=34\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=34} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=34","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 34","Event ID 34","Permission level created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68678,"title":"SharePoint Audit Event 35 - Permission level deleted","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 35","SharePoint"],"keywords":["35","event 35","event id 35","Permission level deleted","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=35"],"errorCode":"","eventId":"35","severity":"High","summary":"SharePoint Audit event 35 records: Permission level deleted","rootCause":"The event records a state-changing operation: Permission level deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 35.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Permission level deleted\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=35\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=35} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=35","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 35","Event ID 35","Permission level deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68679,"title":"SharePoint Audit Event 36 - Permission level modified","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 36","SharePoint"],"keywords":["36","event 36","event id 36","Permission level modified","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=36"],"errorCode":"","eventId":"36","severity":"Medium","summary":"SharePoint Audit event 36 records: Permission level modified","rootCause":"The event records a state-changing operation: Permission level modified It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 36.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Permission level modified\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=36\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=36} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=36","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 36","Event ID 36","Permission level modified"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68680,"title":"SharePoint Audit Event 37 - SharePoint site collection administrator added","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 37","SharePoint"],"keywords":["37","event 37","event id 37","SharePoint site collection administrator added","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=37"],"errorCode":"","eventId":"37","severity":"Medium","summary":"SharePoint Audit event 37 records: SharePoint site collection administrator added","rootCause":"The event records a state-changing operation: SharePoint site collection administrator added It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 37.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: SharePoint site collection administrator added\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=37\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=37} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=37","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 37","Event ID 37","SharePoint site collection administrator added"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68681,"title":"SharePoint Audit Event 38 - SharePoint site collection administrator removed","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 38","SharePoint"],"keywords":["38","event 38","event id 38","SharePoint site collection administrator removed","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=38"],"errorCode":"","eventId":"38","severity":"Medium","summary":"SharePoint Audit event 38 records: SharePoint site collection administrator removed","rootCause":"The event records a state-changing operation: SharePoint site collection administrator removed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 38.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: SharePoint site collection administrator removed\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=38\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=38} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=38","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 38","Event ID 38","SharePoint site collection administrator removed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68682,"title":"SharePoint Audit Event 39 - Object restored","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 39","SharePoint"],"keywords":["39","event 39","event id 39","Object restored","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=39"],"errorCode":"","eventId":"39","severity":"Low","summary":"SharePoint Audit event 39 records: Object restored","rootCause":"The configured audit source recorded this activity: Object restored It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 39.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Object restored\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=39\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=39} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=39","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 39","Event ID 39","Object restored"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68683,"title":"SharePoint Audit Event 40 - Site collection updated","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 40","SharePoint"],"keywords":["40","event 40","event id 40","Site collection updated","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=40"],"errorCode":"","eventId":"40","severity":"Low","summary":"SharePoint Audit event 40 records: Site collection updated","rootCause":"The configured audit source recorded this activity: Site collection updated It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 40.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Site collection updated\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=40\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=40} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=40","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 40","Event ID 40","Site collection updated"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68684,"title":"SharePoint Audit Event 41 - Web updated","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 41","SharePoint"],"keywords":["41","event 41","event id 41","Web updated","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=41"],"errorCode":"","eventId":"41","severity":"Low","summary":"SharePoint Audit event 41 records: Web updated","rootCause":"The configured audit source recorded this activity: Web updated It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 41.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Web updated\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=41\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=41} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=41","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 41","Event ID 41","Web updated"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68685,"title":"SharePoint Audit Event 42 - Document library updated","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 42","SharePoint"],"keywords":["42","event 42","event id 42","Document library updated","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=42"],"errorCode":"","eventId":"42","severity":"Low","summary":"SharePoint Audit event 42 records: Document library updated","rootCause":"The configured audit source recorded this activity: Document library updated It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 42.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Document library updated\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=42\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=42} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=42","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 42","Event ID 42","Document library updated"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68686,"title":"SharePoint Audit Event 43 - Document updated","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 43","SharePoint"],"keywords":["43","event 43","event id 43","Document updated","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=43"],"errorCode":"","eventId":"43","severity":"Low","summary":"SharePoint Audit event 43 records: Document updated","rootCause":"The configured audit source recorded this activity: Document updated It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 43.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Document updated\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=43\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=43} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=43","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 43","Event ID 43","Document updated"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68687,"title":"SharePoint Audit Event 44 - List updated","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 44","SharePoint"],"keywords":["44","event 44","event id 44","List updated","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=44"],"errorCode":"","eventId":"44","severity":"Low","summary":"SharePoint Audit event 44 records: List updated","rootCause":"The configured audit source recorded this activity: List updated It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 44.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: List updated\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=44\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=44} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=44","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 44","Event ID 44","List updated"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68688,"title":"SharePoint Audit Event 45 - List item updated","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 45","SharePoint"],"keywords":["45","event 45","event id 45","List item updated","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=45"],"errorCode":"","eventId":"45","severity":"Low","summary":"SharePoint Audit event 45 records: List item updated","rootCause":"The configured audit source recorded this activity: List item updated It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 45.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: List item updated\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=45\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=45} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=45","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 45","Event ID 45","List item updated"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68689,"title":"SharePoint Audit Event 46 - Folder updated","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 46","SharePoint"],"keywords":["46","event 46","event id 46","Folder updated","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=46"],"errorCode":"","eventId":"46","severity":"Low","summary":"SharePoint Audit event 46 records: Folder updated","rootCause":"The configured audit source recorded this activity: Folder updated It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 46.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Folder updated\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=46\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=46} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=46","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 46","Event ID 46","Folder updated"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68690,"title":"SharePoint Audit Event 47 - Document viewed","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 47","SharePoint"],"keywords":["47","event 47","event id 47","Document viewed","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=47"],"errorCode":"","eventId":"47","severity":"Low","summary":"SharePoint Audit event 47 records: Document viewed","rootCause":"The configured audit source recorded this activity: Document viewed It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 47.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Document viewed\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=47\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=47} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=47","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 47","Event ID 47","Document viewed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68691,"title":"SharePoint Audit Event 48 - Document library viewed","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 48","SharePoint"],"keywords":["48","event 48","event id 48","Document library viewed","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=48"],"errorCode":"","eventId":"48","severity":"Low","summary":"SharePoint Audit event 48 records: Document library viewed","rootCause":"The configured audit source recorded this activity: Document library viewed It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 48.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Document library viewed\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=48\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=48} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=48","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 48","Event ID 48","Document library viewed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68692,"title":"SharePoint Audit Event 49 - List viewed","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 49","SharePoint"],"keywords":["49","event 49","event id 49","List viewed","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=49"],"errorCode":"","eventId":"49","severity":"Low","summary":"SharePoint Audit event 49 records: List viewed","rootCause":"The configured audit source recorded this activity: List viewed It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 49.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: List viewed\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=49\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=49} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=49","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 49","Event ID 49","List viewed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68693,"title":"SharePoint Audit Event 50 - Object viewed","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 50","SharePoint"],"keywords":["50","event 50","event id 50","Object viewed","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=50"],"errorCode":"","eventId":"50","severity":"Low","summary":"SharePoint Audit event 50 records: Object viewed","rootCause":"The configured audit source recorded this activity: Object viewed It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 50.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Object viewed\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=50\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=50} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=50","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 50","Event ID 50","Object viewed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68694,"title":"SharePoint Audit Event 51 - Workflow accessed","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 51","SharePoint"],"keywords":["51","event 51","event id 51","Workflow accessed","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=51"],"errorCode":"","eventId":"51","severity":"Low","summary":"SharePoint Audit event 51 records: Workflow accessed","rootCause":"The configured audit source recorded this activity: Workflow accessed It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 51.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Workflow accessed\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=51\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=51} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=51","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 51","Event ID 51","Workflow accessed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68695,"title":"SharePoint Audit Event 52 - Information management policy created","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 52","SharePoint"],"keywords":["52","event 52","event id 52","Information management policy created","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=52"],"errorCode":"","eventId":"52","severity":"Medium","summary":"SharePoint Audit event 52 records: Information management policy created","rootCause":"The event records a state-changing operation: Information management policy created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 52.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Information management policy created\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=52\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=52} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=52","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 52","Event ID 52","Information management policy created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68696,"title":"SharePoint Audit Event 53 - Information management policy changed","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 53","SharePoint"],"keywords":["53","event 53","event id 53","Information management policy changed","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=53"],"errorCode":"","eventId":"53","severity":"Medium","summary":"SharePoint Audit event 53 records: Information management policy changed","rootCause":"The event records a state-changing operation: Information management policy changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 53.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Information management policy changed\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=53\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=53} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=53","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 53","Event ID 53","Information management policy changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68697,"title":"SharePoint Audit Event 54 - Site collection information management policy created","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 54","SharePoint"],"keywords":["54","event 54","event id 54","Site collection information management policy created","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=54"],"errorCode":"","eventId":"54","severity":"Medium","summary":"SharePoint Audit event 54 records: Site collection information management policy created","rootCause":"The event records a state-changing operation: Site collection information management policy created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 54.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Site collection information management policy created\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=54\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=54} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=54","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 54","Event ID 54","Site collection information management policy created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68698,"title":"SharePoint Audit Event 55 - Site collection information management policy changed","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 55","SharePoint"],"keywords":["55","event 55","event id 55","Site collection information management policy changed","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=55"],"errorCode":"","eventId":"55","severity":"Medium","summary":"SharePoint Audit event 55 records: Site collection information management policy changed","rootCause":"The event records a state-changing operation: Site collection information management policy changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 55.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Site collection information management policy changed\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=55\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=55} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=55","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 55","Event ID 55","Site collection information management policy changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68699,"title":"SharePoint Audit Event 56 - Export of objects started","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 56","SharePoint"],"keywords":["56","event 56","event id 56","Export of objects started","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=56"],"errorCode":"","eventId":"56","severity":"Low","summary":"SharePoint Audit event 56 records: Export of objects started","rootCause":"The configured audit source recorded this activity: Export of objects started It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 56.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Export of objects started\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=56\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=56} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=56","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 56","Event ID 56","Export of objects started"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68700,"title":"SharePoint Audit Event 57 - Export of objects completed","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 57","SharePoint"],"keywords":["57","event 57","event id 57","Export of objects completed","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=57"],"errorCode":"","eventId":"57","severity":"Low","summary":"SharePoint Audit event 57 records: Export of objects completed","rootCause":"The configured audit source recorded this activity: Export of objects completed It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 57.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Export of objects completed\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=57\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=57} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=57","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 57","Event ID 57","Export of objects completed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68701,"title":"SharePoint Audit Event 58 - Import of objects started","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 58","SharePoint"],"keywords":["58","event 58","event id 58","Import of objects started","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=58"],"errorCode":"","eventId":"58","severity":"Low","summary":"SharePoint Audit event 58 records: Import of objects started","rootCause":"The configured audit source recorded this activity: Import of objects started It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 58.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Import of objects started\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=58\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=58} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=58","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 58","Event ID 58","Import of objects started"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68702,"title":"SharePoint Audit Event 59 - Import of objects completed","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 59","SharePoint"],"keywords":["59","event 59","event id 59","Import of objects completed","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=59"],"errorCode":"","eventId":"59","severity":"Low","summary":"SharePoint Audit event 59 records: Import of objects completed","rootCause":"The configured audit source recorded this activity: Import of objects completed It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 59.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Import of objects completed\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=59\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=59} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=59","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 59","Event ID 59","Import of objects completed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68703,"title":"SharePoint Audit Event 60 - Possible tampering warning","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 60","SharePoint"],"keywords":["60","event 60","event id 60","Possible tampering warning","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=60"],"errorCode":"","eventId":"60","severity":"Critical","summary":"SharePoint Audit event 60 records: Possible tampering warning","rootCause":"The configured audit source recorded this activity: Possible tampering warning It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 60.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Possible tampering warning\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=60\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=60} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=60","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 60","Event ID 60","Possible tampering warning"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68704,"title":"SharePoint Audit Event 61 - Retention policy processed","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 61","SharePoint"],"keywords":["61","event 61","event id 61","Retention policy processed","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=61"],"errorCode":"","eventId":"61","severity":"Medium","summary":"SharePoint Audit event 61 records: Retention policy processed","rootCause":"The configured audit source recorded this activity: Retention policy processed It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 61.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Retention policy processed\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=61\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=61} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=61","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 61","Event ID 61","Retention policy processed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68705,"title":"SharePoint Audit Event 62 - Document fragment updated","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 62","SharePoint"],"keywords":["62","event 62","event id 62","Document fragment updated","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=62"],"errorCode":"","eventId":"62","severity":"Low","summary":"SharePoint Audit event 62 records: Document fragment updated","rootCause":"The configured audit source recorded this activity: Document fragment updated It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 62.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Document fragment updated\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=62\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=62} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=62","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 62","Event ID 62","Document fragment updated"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68706,"title":"SharePoint Audit Event 63 - Content type imported","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 63","SharePoint"],"keywords":["63","event 63","event id 63","Content type imported","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=63"],"errorCode":"","eventId":"63","severity":"Low","summary":"SharePoint Audit event 63 records: Content type imported","rootCause":"The configured audit source recorded this activity: Content type imported It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 63.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Content type imported\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=63\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=63} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=63","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 63","Event ID 63","Content type imported"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68707,"title":"SharePoint Audit Event 64 - Information management policy deleted","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 64","SharePoint"],"keywords":["64","event 64","event id 64","Information management policy deleted","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=64"],"errorCode":"","eventId":"64","severity":"High","summary":"SharePoint Audit event 64 records: Information management policy deleted","rootCause":"The event records a state-changing operation: Information management policy deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 64.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Information management policy deleted\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=64\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=64} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=64","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 64","Event ID 64","Information management policy deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68708,"title":"SharePoint Audit Event 65 - Item declared as a record","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 65","SharePoint"],"keywords":["65","event 65","event id 65","Item declared as a record","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=65"],"errorCode":"","eventId":"65","severity":"Low","summary":"SharePoint Audit event 65 records: Item declared as a record","rootCause":"The configured audit source recorded this activity: Item declared as a record It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 65.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Item declared as a record\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=65\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=65} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=65","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 65","Event ID 65","Item declared as a record"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68709,"title":"SharePoint Audit Event 66 - Item undeclared as a record","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 66","SharePoint"],"keywords":["66","event 66","event id 66","Item undeclared as a record","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=66"],"errorCode":"","eventId":"66","severity":"Low","summary":"SharePoint Audit event 66 records: Item undeclared as a record","rootCause":"The configured audit source recorded this activity: Item undeclared as a record It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 66.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Item undeclared as a record\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=66\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=66} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=66","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 66","Event ID 66","Item undeclared as a record"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68710,"title":"SharePoint Audit Event 67 - Netwrix SharePoint Audit Event","category":"Microsoft 365","product":"SharePoint Audit via LOGbinder SP","tags":["SharePoint Audit","Audit Event","Event ID 67","SharePoint"],"keywords":["67","event 67","event id 67","Netwrix SharePoint Audit Event","SharePoint Audit","SharePoint Audit via LOGbinder SP","SHAREPOINT-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=67"],"errorCode":"","eventId":"67","severity":"Low","summary":"SharePoint Audit event 67 records: Netwrix SharePoint Audit Event","rootCause":"The configured audit source recorded this activity: Netwrix SharePoint Audit Event It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SharePoint Audit event 67.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Netwrix SharePoint Audit Event\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SharePoint audit integration. It is not a native SharePoint product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=67\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=67} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=67","namespace":"SHAREPOINT-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SharePoint","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SharePoint Audit"],"articleCategories":["Security Logs","Audit Events","SharePoint Audit","SharePoint"],"aliases":["SharePoint Audit 67","Event ID 67","Netwrix SharePoint Audit Event"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68711,"title":"SQL Server Audit Event 24000 - SQL audit event","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24000","SQL Server"],"keywords":["24000","event 24000","event id 24000","SQL audit event","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24000"],"errorCode":"","eventId":"24000","severity":"Low","summary":"SQL Server Audit event 24000 records: SQL audit event","rootCause":"The configured audit source recorded this activity: SQL audit event It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24000.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: SQL audit event\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24000\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24000} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24000","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24000","Event ID 24000","SQL audit event"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68712,"title":"SQL Server Audit Event 24001 - Login succeeded (action_id LGIS)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24001","SQL Server"],"keywords":["24001","event 24001","event id 24001","Login succeeded (action_id LGIS)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24001"],"errorCode":"","eventId":"24001","severity":"Low","summary":"SQL Server Audit event 24001 records: Login succeeded (action_id LGIS)","rootCause":"The configured audit source recorded this activity: Login succeeded (action_id LGIS) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24001.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Login succeeded (action_id LGIS)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24001\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24001} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24001","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24001","Event ID 24001","Login succeeded (action_id LGIS)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68713,"title":"SQL Server Audit Event 24002 - Logout succeeded (action_id LGO)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24002","SQL Server"],"keywords":["24002","event 24002","event id 24002","Logout succeeded (action_id LGO)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24002"],"errorCode":"","eventId":"24002","severity":"Low","summary":"SQL Server Audit event 24002 records: Logout succeeded (action_id LGO)","rootCause":"The configured audit source recorded this activity: Logout succeeded (action_id LGO) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24002.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Logout succeeded (action_id LGO)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24002\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24002} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24002","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24002","Event ID 24002","Logout succeeded (action_id LGO)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68714,"title":"SQL Server Audit Event 24003 - Login failed (action_id LGIF)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24003","SQL Server"],"keywords":["24003","event 24003","event id 24003","Login failed (action_id LGIF)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24003"],"errorCode":"","eventId":"24003","severity":"High","summary":"SQL Server Audit event 24003 records: Login failed (action_id LGIF)","rootCause":"The audited operation reported a failure: Login failed (action_id LGIF) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24003.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Login failed (action_id LGIF)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24003\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24003} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24003","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24003","Event ID 24003","Login failed (action_id LGIF)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68715,"title":"SQL Server Audit Event 24004 - Change own password succeeded (action_id PWCS; class_type LX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24004","SQL Server"],"keywords":["24004","event 24004","event id 24004","Change own password succeeded (action_id PWCS; class_type LX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24004"],"errorCode":"","eventId":"24004","severity":"Medium","summary":"SQL Server Audit event 24004 records: Change own password succeeded (action_id PWCS; class_type LX)","rootCause":"The configured audit source recorded this activity: Change own password succeeded (action_id PWCS; class_type LX) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24004.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Change own password succeeded (action_id PWCS; class_type LX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24004\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24004} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24004","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24004","Event ID 24004","Change own password succeeded (action_id PWCS; class_type LX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68716,"title":"SQL Server Audit Event 24005 - Change own password failed (action_id PWCS; class_type LX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24005","SQL Server"],"keywords":["24005","event 24005","event id 24005","Change own password failed (action_id PWCS; class_type LX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24005"],"errorCode":"","eventId":"24005","severity":"High","summary":"SQL Server Audit event 24005 records: Change own password failed (action_id PWCS; class_type LX)","rootCause":"The audited operation reported a failure: Change own password failed (action_id PWCS; class_type LX) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24005.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Change own password failed (action_id PWCS; class_type LX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24005\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24005} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24005","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24005","Event ID 24005","Change own password failed (action_id PWCS; class_type LX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68717,"title":"SQL Server Audit Event 24006 - Change password succeeded (action_id PWC class_type LX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24006","SQL Server"],"keywords":["24006","event 24006","event id 24006","Change password succeeded (action_id PWC class_type LX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24006"],"errorCode":"","eventId":"24006","severity":"Medium","summary":"SQL Server Audit event 24006 records: Change password succeeded (action_id PWC class_type LX)","rootCause":"The configured audit source recorded this activity: Change password succeeded (action_id PWC class_type LX) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24006.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Change password succeeded (action_id PWC class_type LX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24006\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24006} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24006","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24006","Event ID 24006","Change password succeeded (action_id PWC class_type LX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68718,"title":"SQL Server Audit Event 24007 - Change password failed (action_id PWC class_type LX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24007","SQL Server"],"keywords":["24007","event 24007","event id 24007","Change password failed (action_id PWC class_type LX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24007"],"errorCode":"","eventId":"24007","severity":"High","summary":"SQL Server Audit event 24007 records: Change password failed (action_id PWC class_type LX)","rootCause":"The audited operation reported a failure: Change password failed (action_id PWC class_type LX) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24007.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Change password failed (action_id PWC class_type LX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24007\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24007} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24007","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24007","Event ID 24007","Change password failed (action_id PWC class_type LX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68719,"title":"SQL Server Audit Event 24008 - Reset own password succeeded (action_id PWRS; class_type LX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24008","SQL Server"],"keywords":["24008","event 24008","event id 24008","Reset own password succeeded (action_id PWRS; class_type LX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24008"],"errorCode":"","eventId":"24008","severity":"Medium","summary":"SQL Server Audit event 24008 records: Reset own password succeeded (action_id PWRS; class_type LX)","rootCause":"The event records a state-changing operation: Reset own password succeeded (action_id PWRS; class_type LX) It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24008.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Reset own password succeeded (action_id PWRS; class_type LX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24008\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24008} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24008","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24008","Event ID 24008","Reset own password succeeded (action_id PWRS; class_type LX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68720,"title":"SQL Server Audit Event 24009 - Reset own password failed (action_id PWRS; class_type LX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24009","SQL Server"],"keywords":["24009","event 24009","event id 24009","Reset own password failed (action_id PWRS; class_type LX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24009"],"errorCode":"","eventId":"24009","severity":"High","summary":"SQL Server Audit event 24009 records: Reset own password failed (action_id PWRS; class_type LX)","rootCause":"The audited operation reported a failure: Reset own password failed (action_id PWRS; class_type LX) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24009.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Reset own password failed (action_id PWRS; class_type LX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24009\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24009} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24009","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24009","Event ID 24009","Reset own password failed (action_id PWRS; class_type LX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68721,"title":"SQL Server Audit Event 24010 - Reset password succeeded (action_id PWR; class_type LX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24010","SQL Server"],"keywords":["24010","event 24010","event id 24010","Reset password succeeded (action_id PWR; class_type LX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24010"],"errorCode":"","eventId":"24010","severity":"Medium","summary":"SQL Server Audit event 24010 records: Reset password succeeded (action_id PWR; class_type LX)","rootCause":"The event records a state-changing operation: Reset password succeeded (action_id PWR; class_type LX) It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24010.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Reset password succeeded (action_id PWR; class_type LX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24010\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24010} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24010","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24010","Event ID 24010","Reset password succeeded (action_id PWR; class_type LX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68722,"title":"SQL Server Audit Event 24011 - Reset password failed (action_id PWR; class_type LX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24011","SQL Server"],"keywords":["24011","event 24011","event id 24011","Reset password failed (action_id PWR; class_type LX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24011"],"errorCode":"","eventId":"24011","severity":"High","summary":"SQL Server Audit event 24011 records: Reset password failed (action_id PWR; class_type LX)","rootCause":"The audited operation reported a failure: Reset password failed (action_id PWR; class_type LX) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24011.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Reset password failed (action_id PWR; class_type LX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24011\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24011} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24011","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24011","Event ID 24011","Reset password failed (action_id PWR; class_type LX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68723,"title":"SQL Server Audit Event 24012 - Must change password (action_id PWMC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24012","SQL Server"],"keywords":["24012","event 24012","event id 24012","Must change password (action_id PWMC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24012"],"errorCode":"","eventId":"24012","severity":"Medium","summary":"SQL Server Audit event 24012 records: Must change password (action_id PWMC)","rootCause":"The configured audit source recorded this activity: Must change password (action_id PWMC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24012.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Must change password (action_id PWMC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24012\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24012} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24012","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24012","Event ID 24012","Must change password (action_id PWMC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68724,"title":"SQL Server Audit Event 24013 - Account unlocked (action_id PWU)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24013","SQL Server"],"keywords":["24013","event 24013","event id 24013","Account unlocked (action_id PWU)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24013"],"errorCode":"","eventId":"24013","severity":"Low","summary":"SQL Server Audit event 24013 records: Account unlocked (action_id PWU)","rootCause":"The configured audit source recorded this activity: Account unlocked (action_id PWU) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24013.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Account unlocked (action_id PWU)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24013\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24013} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24013","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24013","Event ID 24013","Account unlocked (action_id PWU)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68725,"title":"SQL Server Audit Event 24014 - Change application role password succeeded (action_id PWC; class_type AR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24014","SQL Server"],"keywords":["24014","event 24014","event id 24014","Change application role password succeeded (action_id PWC; class_type AR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24014"],"errorCode":"","eventId":"24014","severity":"Medium","summary":"SQL Server Audit event 24014 records: Change application role password succeeded (action_id PWC; class_type AR)","rootCause":"The configured audit source recorded this activity: Change application role password succeeded (action_id PWC; class_type AR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24014.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Change application role password succeeded (action_id PWC; class_type AR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24014\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24014} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24014","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24014","Event ID 24014","Change application role password succeeded (action_id PWC; class_type AR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68726,"title":"SQL Server Audit Event 24015 - Change application role password failed (action_id PWC class_type AR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24015","SQL Server"],"keywords":["24015","event 24015","event id 24015","Change application role password failed (action_id PWC class_type AR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24015"],"errorCode":"","eventId":"24015","severity":"High","summary":"SQL Server Audit event 24015 records: Change application role password failed (action_id PWC class_type AR)","rootCause":"The audited operation reported a failure: Change application role password failed (action_id PWC class_type AR) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24015.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Change application role password failed (action_id PWC class_type AR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24015\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24015} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24015","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24015","Event ID 24015","Change application role password failed (action_id PWC class_type AR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68727,"title":"SQL Server Audit Event 24016 - Add member to server role succeeded (action_id APRL class_type SG)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24016","SQL Server"],"keywords":["24016","event 24016","event id 24016","Add member to server role succeeded (action_id APRL class_type SG)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24016"],"errorCode":"","eventId":"24016","severity":"Medium","summary":"SQL Server Audit event 24016 records: Add member to server role succeeded (action_id APRL class_type SG)","rootCause":"The configured audit source recorded this activity: Add member to server role succeeded (action_id APRL class_type SG) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24016.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add member to server role succeeded (action_id APRL class_type SG)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24016\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24016} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24016","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24016","Event ID 24016","Add member to server role succeeded (action_id APRL class_type SG)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68728,"title":"SQL Server Audit Event 24017 - Add member to server role failed (action_id APRL class_type SG)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24017","SQL Server"],"keywords":["24017","event 24017","event id 24017","Add member to server role failed (action_id APRL class_type SG)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24017"],"errorCode":"","eventId":"24017","severity":"High","summary":"SQL Server Audit event 24017 records: Add member to server role failed (action_id APRL class_type SG)","rootCause":"The audited operation reported a failure: Add member to server role failed (action_id APRL class_type SG) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24017.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add member to server role failed (action_id APRL class_type SG)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24017\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24017} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24017","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24017","Event ID 24017","Add member to server role failed (action_id APRL class_type SG)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68729,"title":"SQL Server Audit Event 24018 - Remove member from server role succeeded (action_id DPRL class_type SG)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24018","SQL Server"],"keywords":["24018","event 24018","event id 24018","Remove member from server role succeeded (action_id DPRL class_type SG)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24018"],"errorCode":"","eventId":"24018","severity":"Medium","summary":"SQL Server Audit event 24018 records: Remove member from server role succeeded (action_id DPRL class_type SG)","rootCause":"The configured audit source recorded this activity: Remove member from server role succeeded (action_id DPRL class_type SG) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24018.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove member from server role succeeded (action_id DPRL class_type SG)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24018\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24018} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24018","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24018","Event ID 24018","Remove member from server role succeeded (action_id DPRL class_type SG)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68730,"title":"SQL Server Audit Event 24019 - Remove member from server role failed (action_id DPRL class_type SG)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24019","SQL Server"],"keywords":["24019","event 24019","event id 24019","Remove member from server role failed (action_id DPRL class_type SG)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24019"],"errorCode":"","eventId":"24019","severity":"High","summary":"SQL Server Audit event 24019 records: Remove member from server role failed (action_id DPRL class_type SG)","rootCause":"The audited operation reported a failure: Remove member from server role failed (action_id DPRL class_type SG) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24019.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove member from server role failed (action_id DPRL class_type SG)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24019\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24019} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24019","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24019","Event ID 24019","Remove member from server role failed (action_id DPRL class_type SG)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68731,"title":"SQL Server Audit Event 24020 - Add member to database role succeeded (action_id APRL class_type RL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24020","SQL Server"],"keywords":["24020","event 24020","event id 24020","Add member to database role succeeded (action_id APRL class_type RL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24020"],"errorCode":"","eventId":"24020","severity":"Medium","summary":"SQL Server Audit event 24020 records: Add member to database role succeeded (action_id APRL class_type RL)","rootCause":"The configured audit source recorded this activity: Add member to database role succeeded (action_id APRL class_type RL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24020.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add member to database role succeeded (action_id APRL class_type RL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24020\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24020} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24020","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24020","Event ID 24020","Add member to database role succeeded (action_id APRL class_type RL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68732,"title":"SQL Server Audit Event 24021 - Add member to database role failed (action_id APRL class_type RL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24021","SQL Server"],"keywords":["24021","event 24021","event id 24021","Add member to database role failed (action_id APRL class_type RL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24021"],"errorCode":"","eventId":"24021","severity":"High","summary":"SQL Server Audit event 24021 records: Add member to database role failed (action_id APRL class_type RL)","rootCause":"The audited operation reported a failure: Add member to database role failed (action_id APRL class_type RL) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24021.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add member to database role failed (action_id APRL class_type RL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24021\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24021} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24021","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24021","Event ID 24021","Add member to database role failed (action_id APRL class_type RL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68733,"title":"SQL Server Audit Event 24022 - Remove member from database role succeeded (action_id DPRL class_type RL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24022","SQL Server"],"keywords":["24022","event 24022","event id 24022","Remove member from database role succeeded (action_id DPRL class_type RL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24022"],"errorCode":"","eventId":"24022","severity":"Medium","summary":"SQL Server Audit event 24022 records: Remove member from database role succeeded (action_id DPRL class_type RL)","rootCause":"The configured audit source recorded this activity: Remove member from database role succeeded (action_id DPRL class_type RL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24022.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove member from database role succeeded (action_id DPRL class_type RL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24022\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24022} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24022","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24022","Event ID 24022","Remove member from database role succeeded (action_id DPRL class_type RL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68734,"title":"SQL Server Audit Event 24023 - Remove member from database role failed (action_id DPRL class_type RL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24023","SQL Server"],"keywords":["24023","event 24023","event id 24023","Remove member from database role failed (action_id DPRL class_type RL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24023"],"errorCode":"","eventId":"24023","severity":"High","summary":"SQL Server Audit event 24023 records: Remove member from database role failed (action_id DPRL class_type RL)","rootCause":"The audited operation reported a failure: Remove member from database role failed (action_id DPRL class_type RL) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24023.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Remove member from database role failed (action_id DPRL class_type RL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24023\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24023} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24023","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24023","Event ID 24023","Remove member from database role failed (action_id DPRL class_type RL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68735,"title":"SQL Server Audit Event 24024 - Issued database backup command (action_id BA class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24024","SQL Server"],"keywords":["24024","event 24024","event id 24024","Issued database backup command (action_id BA class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24024"],"errorCode":"","eventId":"24024","severity":"Low","summary":"SQL Server Audit event 24024 records: Issued database backup command (action_id BA class_type DB)","rootCause":"The configured audit source recorded this activity: Issued database backup command (action_id BA class_type DB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24024.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued database backup command (action_id BA class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24024\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24024} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24024","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24024","Event ID 24024","Issued database backup command (action_id BA class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68736,"title":"SQL Server Audit Event 24025 - Issued transaction log backup command (action_id BAL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24025","SQL Server"],"keywords":["24025","event 24025","event id 24025","Issued transaction log backup command (action_id BAL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24025"],"errorCode":"","eventId":"24025","severity":"Low","summary":"SQL Server Audit event 24025 records: Issued transaction log backup command (action_id BAL)","rootCause":"The configured audit source recorded this activity: Issued transaction log backup command (action_id BAL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24025.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued transaction log backup command (action_id BAL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24025\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24025} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24025","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24025","Event ID 24025","Issued transaction log backup command (action_id BAL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68737,"title":"SQL Server Audit Event 24026 - Issued database restore command (action_id RS class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24026","SQL Server"],"keywords":["24026","event 24026","event id 24026","Issued database restore command (action_id RS class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24026"],"errorCode":"","eventId":"24026","severity":"Low","summary":"SQL Server Audit event 24026 records: Issued database restore command (action_id RS class_type DB)","rootCause":"The configured audit source recorded this activity: Issued database restore command (action_id RS class_type DB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24026.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued database restore command (action_id RS class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24026\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24026} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24026","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24026","Event ID 24026","Issued database restore command (action_id RS class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68738,"title":"SQL Server Audit Event 24027 - Issued transaction log restore command (action_id RS class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24027","SQL Server"],"keywords":["24027","event 24027","event id 24027","Issued transaction log restore command (action_id RS class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24027"],"errorCode":"","eventId":"24027","severity":"Low","summary":"SQL Server Audit event 24027 records: Issued transaction log restore command (action_id RS class_type DB)","rootCause":"The configured audit source recorded this activity: Issued transaction log restore command (action_id RS class_type DB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24027.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued transaction log restore command (action_id RS class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24027\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24027} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24027","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24027","Event ID 24027","Issued transaction log restore command (action_id RS class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68739,"title":"SQL Server Audit Event 24028 - Issued database console command (action_id DBCC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24028","SQL Server"],"keywords":["24028","event 24028","event id 24028","Issued database console command (action_id DBCC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24028"],"errorCode":"","eventId":"24028","severity":"Low","summary":"SQL Server Audit event 24028 records: Issued database console command (action_id DBCC)","rootCause":"The configured audit source recorded this activity: Issued database console command (action_id DBCC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24028.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued database console command (action_id DBCC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24028\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24028} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24028","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24028","Event ID 24028","Issued database console command (action_id DBCC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68740,"title":"SQL Server Audit Event 24029 - Issued a bulk administration command (action_id ADBO)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24029","SQL Server"],"keywords":["24029","event 24029","event id 24029","Issued a bulk administration command (action_id ADBO)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24029"],"errorCode":"","eventId":"24029","severity":"Low","summary":"SQL Server Audit event 24029 records: Issued a bulk administration command (action_id ADBO)","rootCause":"The configured audit source recorded this activity: Issued a bulk administration command (action_id ADBO) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24029.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a bulk administration command (action_id ADBO)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24029\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24029} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24029","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24029","Event ID 24029","Issued a bulk administration command (action_id ADBO)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68741,"title":"SQL Server Audit Event 24030 - Issued an alter connection command (action_id ALCN)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24030","SQL Server"],"keywords":["24030","event 24030","event id 24030","Issued an alter connection command (action_id ALCN)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24030"],"errorCode":"","eventId":"24030","severity":"Low","summary":"SQL Server Audit event 24030 records: Issued an alter connection command (action_id ALCN)","rootCause":"The configured audit source recorded this activity: Issued an alter connection command (action_id ALCN) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24030.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued an alter connection command (action_id ALCN)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24030\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24030} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24030","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24030","Event ID 24030","Issued an alter connection command (action_id ALCN)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68742,"title":"SQL Server Audit Event 24031 - Issued an alter resources command (action_id ALRS)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24031","SQL Server"],"keywords":["24031","event 24031","event id 24031","Issued an alter resources command (action_id ALRS)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24031"],"errorCode":"","eventId":"24031","severity":"Low","summary":"SQL Server Audit event 24031 records: Issued an alter resources command (action_id ALRS)","rootCause":"The configured audit source recorded this activity: Issued an alter resources command (action_id ALRS) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24031.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued an alter resources command (action_id ALRS)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24031\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24031} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24031","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24031","Event ID 24031","Issued an alter resources command (action_id ALRS)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68743,"title":"SQL Server Audit Event 24032 - Issued an alter server state command (action_id ALSS)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24032","SQL Server"],"keywords":["24032","event 24032","event id 24032","Issued an alter server state command (action_id ALSS)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24032"],"errorCode":"","eventId":"24032","severity":"Low","summary":"SQL Server Audit event 24032 records: Issued an alter server state command (action_id ALSS)","rootCause":"The configured audit source recorded this activity: Issued an alter server state command (action_id ALSS) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24032.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued an alter server state command (action_id ALSS)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24032\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24032} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24032","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24032","Event ID 24032","Issued an alter server state command (action_id ALSS)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68744,"title":"SQL Server Audit Event 24033 - Issued an alter server settings command (action_id ALST)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24033","SQL Server"],"keywords":["24033","event 24033","event id 24033","Issued an alter server settings command (action_id ALST)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24033"],"errorCode":"","eventId":"24033","severity":"Low","summary":"SQL Server Audit event 24033 records: Issued an alter server settings command (action_id ALST)","rootCause":"The configured audit source recorded this activity: Issued an alter server settings command (action_id ALST) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24033.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued an alter server settings command (action_id ALST)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24033\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24033} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24033","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24033","Event ID 24033","Issued an alter server settings command (action_id ALST)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68745,"title":"SQL Server Audit Event 24034 - Issued a view server state command (action_id VSST)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24034","SQL Server"],"keywords":["24034","event 24034","event id 24034","Issued a view server state command (action_id VSST)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24034"],"errorCode":"","eventId":"24034","severity":"Low","summary":"SQL Server Audit event 24034 records: Issued a view server state command (action_id VSST)","rootCause":"The configured audit source recorded this activity: Issued a view server state command (action_id VSST) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24034.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a view server state command (action_id VSST)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24034\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24034} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24034","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24034","Event ID 24034","Issued a view server state command (action_id VSST)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68746,"title":"SQL Server Audit Event 24035 - Issued an external access assembly command (action_id XA)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24035","SQL Server"],"keywords":["24035","event 24035","event id 24035","Issued an external access assembly command (action_id XA)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24035"],"errorCode":"","eventId":"24035","severity":"Low","summary":"SQL Server Audit event 24035 records: Issued an external access assembly command (action_id XA)","rootCause":"The configured audit source recorded this activity: Issued an external access assembly command (action_id XA) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24035.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued an external access assembly command (action_id XA)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24035\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24035} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24035","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24035","Event ID 24035","Issued an external access assembly command (action_id XA)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68747,"title":"SQL Server Audit Event 24036 - Issued an unsafe assembly command (action_id XU)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24036","SQL Server"],"keywords":["24036","event 24036","event id 24036","Issued an unsafe assembly command (action_id XU)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24036"],"errorCode":"","eventId":"24036","severity":"Low","summary":"SQL Server Audit event 24036 records: Issued an unsafe assembly command (action_id XU)","rootCause":"The configured audit source recorded this activity: Issued an unsafe assembly command (action_id XU) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24036.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued an unsafe assembly command (action_id XU)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24036\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24036} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24036","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24036","Event ID 24036","Issued an unsafe assembly command (action_id XU)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68748,"title":"SQL Server Audit Event 24037 - Issued an alter resource governor command (action_id ALRS class_type RG)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24037","SQL Server"],"keywords":["24037","event 24037","event id 24037","Issued an alter resource governor command (action_id ALRS class_type RG)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24037"],"errorCode":"","eventId":"24037","severity":"Low","summary":"SQL Server Audit event 24037 records: Issued an alter resource governor command (action_id ALRS class_type RG)","rootCause":"The configured audit source recorded this activity: Issued an alter resource governor command (action_id ALRS class_type RG) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24037.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued an alter resource governor command (action_id ALRS class_type RG)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24037\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24037} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24037","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24037","Event ID 24037","Issued an alter resource governor command (action_id ALRS class_type RG)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68749,"title":"SQL Server Audit Event 24038 - Issued a database authenticate command (action_id AUTH)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24038","SQL Server"],"keywords":["24038","event 24038","event id 24038","Issued a database authenticate command (action_id AUTH)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24038"],"errorCode":"","eventId":"24038","severity":"Low","summary":"SQL Server Audit event 24038 records: Issued a database authenticate command (action_id AUTH)","rootCause":"The configured audit source recorded this activity: Issued a database authenticate command (action_id AUTH) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24038.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a database authenticate command (action_id AUTH)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24038\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24038} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24038","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24038","Event ID 24038","Issued a database authenticate command (action_id AUTH)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68750,"title":"SQL Server Audit Event 24039 - Issued a database checkpoint command (action_id CP)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24039","SQL Server"],"keywords":["24039","event 24039","event id 24039","Issued a database checkpoint command (action_id CP)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24039"],"errorCode":"","eventId":"24039","severity":"Low","summary":"SQL Server Audit event 24039 records: Issued a database checkpoint command (action_id CP)","rootCause":"The configured audit source recorded this activity: Issued a database checkpoint command (action_id CP) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24039.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a database checkpoint command (action_id CP)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24039\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24039} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24039","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24039","Event ID 24039","Issued a database checkpoint command (action_id CP)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68751,"title":"SQL Server Audit Event 24040 - Issued a database show plan command (action_id SPLN)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24040","SQL Server"],"keywords":["24040","event 24040","event id 24040","Issued a database show plan command (action_id SPLN)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24040"],"errorCode":"","eventId":"24040","severity":"Low","summary":"SQL Server Audit event 24040 records: Issued a database show plan command (action_id SPLN)","rootCause":"The configured audit source recorded this activity: Issued a database show plan command (action_id SPLN) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24040.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a database show plan command (action_id SPLN)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24040\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24040} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24040","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24040","Event ID 24040","Issued a database show plan command (action_id SPLN)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68752,"title":"SQL Server Audit Event 24041 - Issued a subscribe to query information command (action_id SUQN)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24041","SQL Server"],"keywords":["24041","event 24041","event id 24041","Issued a subscribe to query information command (action_id SUQN)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24041"],"errorCode":"","eventId":"24041","severity":"Low","summary":"SQL Server Audit event 24041 records: Issued a subscribe to query information command (action_id SUQN)","rootCause":"The configured audit source recorded this activity: Issued a subscribe to query information command (action_id SUQN) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24041.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a subscribe to query information command (action_id SUQN)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24041\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24041} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24041","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24041","Event ID 24041","Issued a subscribe to query information command (action_id SUQN)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68753,"title":"SQL Server Audit Event 24042 - Issued a view database state command (action_id VDST)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24042","SQL Server"],"keywords":["24042","event 24042","event id 24042","Issued a view database state command (action_id VDST)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24042"],"errorCode":"","eventId":"24042","severity":"Low","summary":"SQL Server Audit event 24042 records: Issued a view database state command (action_id VDST)","rootCause":"The configured audit source recorded this activity: Issued a view database state command (action_id VDST) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24042.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a view database state command (action_id VDST)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24042\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24042} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24042","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24042","Event ID 24042","Issued a view database state command (action_id VDST)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68754,"title":"SQL Server Audit Event 24043 - Issued a change server audit command (action_id AL class_type A)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24043","SQL Server"],"keywords":["24043","event 24043","event id 24043","Issued a change server audit command (action_id AL class_type A)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24043"],"errorCode":"","eventId":"24043","severity":"Low","summary":"SQL Server Audit event 24043 records: Issued a change server audit command (action_id AL class_type A)","rootCause":"The configured audit source recorded this activity: Issued a change server audit command (action_id AL class_type A) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24043.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change server audit command (action_id AL class_type A)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24043\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24043} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24043","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24043","Event ID 24043","Issued a change server audit command (action_id AL class_type A)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68755,"title":"SQL Server Audit Event 24044 - Issued a change server audit specification command (action_id AL class_type SA)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24044","SQL Server"],"keywords":["24044","event 24044","event id 24044","Issued a change server audit specification command (action_id AL class_type SA)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24044"],"errorCode":"","eventId":"24044","severity":"Low","summary":"SQL Server Audit event 24044 records: Issued a change server audit specification command (action_id AL class_type SA)","rootCause":"The configured audit source recorded this activity: Issued a change server audit specification command (action_id AL class_type SA) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24044.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change server audit specification command (action_id AL class_type SA)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24044\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24044} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24044","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24044","Event ID 24044","Issued a change server audit specification command (action_id AL class_type SA)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68756,"title":"SQL Server Audit Event 24045 - Issued a change database audit specification command (action_id AL class_type DA)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24045","SQL Server"],"keywords":["24045","event 24045","event id 24045","Issued a change database audit specification command (action_id AL class_type DA)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24045"],"errorCode":"","eventId":"24045","severity":"Low","summary":"SQL Server Audit event 24045 records: Issued a change database audit specification command (action_id AL class_type DA)","rootCause":"The configured audit source recorded this activity: Issued a change database audit specification command (action_id AL class_type DA) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24045.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change database audit specification command (action_id AL class_type DA)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24045\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24045} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24045","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24045","Event ID 24045","Issued a change database audit specification command (action_id AL class_type DA)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68757,"title":"SQL Server Audit Event 24046 - Issued a create server audit command (action_id CR class_type A)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24046","SQL Server"],"keywords":["24046","event 24046","event id 24046","Issued a create server audit command (action_id CR class_type A)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24046"],"errorCode":"","eventId":"24046","severity":"Low","summary":"SQL Server Audit event 24046 records: Issued a create server audit command (action_id CR class_type A)","rootCause":"The configured audit source recorded this activity: Issued a create server audit command (action_id CR class_type A) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24046.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create server audit command (action_id CR class_type A)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24046\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24046} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24046","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24046","Event ID 24046","Issued a create server audit command (action_id CR class_type A)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68758,"title":"SQL Server Audit Event 24047 - Issued a create server audit specification command (action_id CR class_type SA)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24047","SQL Server"],"keywords":["24047","event 24047","event id 24047","Issued a create server audit specification command (action_id CR class_type SA)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24047"],"errorCode":"","eventId":"24047","severity":"Low","summary":"SQL Server Audit event 24047 records: Issued a create server audit specification command (action_id CR class_type SA)","rootCause":"The configured audit source recorded this activity: Issued a create server audit specification command (action_id CR class_type SA) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24047.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create server audit specification command (action_id CR class_type SA)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24047\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24047} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24047","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24047","Event ID 24047","Issued a create server audit specification command (action_id CR class_type SA)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68759,"title":"SQL Server Audit Event 24048 - Issued a create database audit specification command (action_id CR class_type DA)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24048","SQL Server"],"keywords":["24048","event 24048","event id 24048","Issued a create database audit specification command (action_id CR class_type DA)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24048"],"errorCode":"","eventId":"24048","severity":"Low","summary":"SQL Server Audit event 24048 records: Issued a create database audit specification command (action_id CR class_type DA)","rootCause":"The configured audit source recorded this activity: Issued a create database audit specification command (action_id CR class_type DA) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24048.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create database audit specification command (action_id CR class_type DA)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24048\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24048} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24048","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24048","Event ID 24048","Issued a create database audit specification command (action_id CR class_type DA)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68760,"title":"SQL Server Audit Event 24049 - Issued a delete server audit command (action_id DR class_type A)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24049","SQL Server"],"keywords":["24049","event 24049","event id 24049","Issued a delete server audit command (action_id DR class_type A)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24049"],"errorCode":"","eventId":"24049","severity":"Low","summary":"SQL Server Audit event 24049 records: Issued a delete server audit command (action_id DR class_type A)","rootCause":"The configured audit source recorded this activity: Issued a delete server audit command (action_id DR class_type A) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24049.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete server audit command (action_id DR class_type A)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24049\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24049} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24049","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24049","Event ID 24049","Issued a delete server audit command (action_id DR class_type A)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68761,"title":"SQL Server Audit Event 24050 - Issued a delete server audit specification command (action_id DR class_type SA)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24050","SQL Server"],"keywords":["24050","event 24050","event id 24050","Issued a delete server audit specification command (action_id DR class_type SA)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24050"],"errorCode":"","eventId":"24050","severity":"Low","summary":"SQL Server Audit event 24050 records: Issued a delete server audit specification command (action_id DR class_type SA)","rootCause":"The configured audit source recorded this activity: Issued a delete server audit specification command (action_id DR class_type SA) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24050.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete server audit specification command (action_id DR class_type SA)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24050\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24050} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24050","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24050","Event ID 24050","Issued a delete server audit specification command (action_id DR class_type SA)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68762,"title":"SQL Server Audit Event 24051 - Issued a delete database audit specification command (action_id DR class_type DA)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24051","SQL Server"],"keywords":["24051","event 24051","event id 24051","Issued a delete database audit specification command (action_id DR class_type DA)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24051"],"errorCode":"","eventId":"24051","severity":"Low","summary":"SQL Server Audit event 24051 records: Issued a delete database audit specification command (action_id DR class_type DA)","rootCause":"The configured audit source recorded this activity: Issued a delete database audit specification command (action_id DR class_type DA) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24051.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete database audit specification command (action_id DR class_type DA)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24051\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24051} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24051","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24051","Event ID 24051","Issued a delete database audit specification command (action_id DR class_type DA)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68763,"title":"SQL Server Audit Event 24052 - Audit failure (action_id AUSF)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24052","SQL Server"],"keywords":["24052","event 24052","event id 24052","Audit failure (action_id AUSF)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24052"],"errorCode":"","eventId":"24052","severity":"High","summary":"SQL Server Audit event 24052 records: Audit failure (action_id AUSF)","rootCause":"The audited operation reported a failure: Audit failure (action_id AUSF) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24052.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Audit failure (action_id AUSF)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24052\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24052} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24052","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24052","Event ID 24052","Audit failure (action_id AUSF)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68764,"title":"SQL Server Audit Event 24053 - Audit session changed (action_id AUSC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24053","SQL Server"],"keywords":["24053","event 24053","event id 24053","Audit session changed (action_id AUSC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24053"],"errorCode":"","eventId":"24053","severity":"Medium","summary":"SQL Server Audit event 24053 records: Audit session changed (action_id AUSC)","rootCause":"The event records a state-changing operation: Audit session changed (action_id AUSC) It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24053.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Audit session changed (action_id AUSC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24053\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24053} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24053","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24053","Event ID 24053","Audit session changed (action_id AUSC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68765,"title":"SQL Server Audit Event 24054 - Started SQL server (action_id SVSR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24054","SQL Server"],"keywords":["24054","event 24054","event id 24054","Started SQL server (action_id SVSR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24054"],"errorCode":"","eventId":"24054","severity":"Low","summary":"SQL Server Audit event 24054 records: Started SQL server (action_id SVSR)","rootCause":"The configured audit source recorded this activity: Started SQL server (action_id SVSR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24054.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Started SQL server (action_id SVSR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24054\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24054} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24054","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24054","Event ID 24054","Started SQL server (action_id SVSR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68766,"title":"SQL Server Audit Event 24055 - Paused SQL server (action_id SVPD)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24055","SQL Server"],"keywords":["24055","event 24055","event id 24055","Paused SQL server (action_id SVPD)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24055"],"errorCode":"","eventId":"24055","severity":"Low","summary":"SQL Server Audit event 24055 records: Paused SQL server (action_id SVPD)","rootCause":"The configured audit source recorded this activity: Paused SQL server (action_id SVPD) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24055.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Paused SQL server (action_id SVPD)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24055\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24055} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24055","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24055","Event ID 24055","Paused SQL server (action_id SVPD)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68767,"title":"SQL Server Audit Event 24056 - Resumed SQL server (action_id SVCN)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24056","SQL Server"],"keywords":["24056","event 24056","event id 24056","Resumed SQL server (action_id SVCN)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24056"],"errorCode":"","eventId":"24056","severity":"Low","summary":"SQL Server Audit event 24056 records: Resumed SQL server (action_id SVCN)","rootCause":"The configured audit source recorded this activity: Resumed SQL server (action_id SVCN) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24056.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Resumed SQL server (action_id SVCN)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24056\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24056} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24056","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24056","Event ID 24056","Resumed SQL server (action_id SVCN)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68768,"title":"SQL Server Audit Event 24057 - Stopped SQL server (action_id SVSD)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24057","SQL Server"],"keywords":["24057","event 24057","event id 24057","Stopped SQL server (action_id SVSD)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24057"],"errorCode":"","eventId":"24057","severity":"High","summary":"SQL Server Audit event 24057 records: Stopped SQL server (action_id SVSD)","rootCause":"The configured audit source recorded this activity: Stopped SQL server (action_id SVSD) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24057.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Stopped SQL server (action_id SVSD)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24057\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24057} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24057","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24057","Event ID 24057","Stopped SQL server (action_id SVSD)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68769,"title":"SQL Server Audit Event 24058 - Issued a create server object command (action_id CR; class_type AG, EP, SD, SE, T)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24058","SQL Server"],"keywords":["24058","event 24058","event id 24058","Issued a create server object command (action_id CR; class_type AG, EP, SD, SE, T)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24058"],"errorCode":"","eventId":"24058","severity":"Low","summary":"SQL Server Audit event 24058 records: Issued a create server object command (action_id CR; class_type AG, EP, SD, SE, T)","rootCause":"The configured audit source recorded this activity: Issued a create server object command (action_id CR; class_type AG, EP, SD, SE, T) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24058.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create server object command (action_id CR; class_type AG, EP, SD, SE, T)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24058\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24058} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24058","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24058","Event ID 24058","Issued a create server object command (action_id CR; class_type AG, EP, SD, SE, T)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68770,"title":"SQL Server Audit Event 24059 - Issued a change server object command (action_id AL; class_type AG, EP, SD, SE, T)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24059","SQL Server"],"keywords":["24059","event 24059","event id 24059","Issued a change server object command (action_id AL; class_type AG, EP, SD, SE, T)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24059"],"errorCode":"","eventId":"24059","severity":"Low","summary":"SQL Server Audit event 24059 records: Issued a change server object command (action_id AL; class_type AG, EP, SD, SE, T)","rootCause":"The configured audit source recorded this activity: Issued a change server object command (action_id AL; class_type AG, EP, SD, SE, T) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24059.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change server object command (action_id AL; class_type AG, EP, SD, SE, T)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24059\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24059} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24059","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24059","Event ID 24059","Issued a change server object command (action_id AL; class_type AG, EP, SD, SE, T)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68771,"title":"SQL Server Audit Event 24060 - Issued a delete server object command (action_id DR; class_type AG, EP, SD, SE, T)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24060","SQL Server"],"keywords":["24060","event 24060","event id 24060","Issued a delete server object command (action_id DR; class_type AG, EP, SD, SE, T)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24060"],"errorCode":"","eventId":"24060","severity":"Low","summary":"SQL Server Audit event 24060 records: Issued a delete server object command (action_id DR; class_type AG, EP, SD, SE, T)","rootCause":"The configured audit source recorded this activity: Issued a delete server object command (action_id DR; class_type AG, EP, SD, SE, T) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24060.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete server object command (action_id DR; class_type AG, EP, SD, SE, T)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24060\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24060} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24060","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24060","Event ID 24060","Issued a delete server object command (action_id DR; class_type AG, EP, SD, SE, T)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68772,"title":"SQL Server Audit Event 24061 - Issued a create server setting command (action_id CR class_type SR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24061","SQL Server"],"keywords":["24061","event 24061","event id 24061","Issued a create server setting command (action_id CR class_type SR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24061"],"errorCode":"","eventId":"24061","severity":"Low","summary":"SQL Server Audit event 24061 records: Issued a create server setting command (action_id CR class_type SR)","rootCause":"The configured audit source recorded this activity: Issued a create server setting command (action_id CR class_type SR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24061.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create server setting command (action_id CR class_type SR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24061\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24061} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24061","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24061","Event ID 24061","Issued a create server setting command (action_id CR class_type SR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68773,"title":"SQL Server Audit Event 24062 - Issued a change server setting command (action_id AL class_type SR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24062","SQL Server"],"keywords":["24062","event 24062","event id 24062","Issued a change server setting command (action_id AL class_type SR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24062"],"errorCode":"","eventId":"24062","severity":"Low","summary":"SQL Server Audit event 24062 records: Issued a change server setting command (action_id AL class_type SR)","rootCause":"The configured audit source recorded this activity: Issued a change server setting command (action_id AL class_type SR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24062.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change server setting command (action_id AL class_type SR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24062\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24062} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24062","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24062","Event ID 24062","Issued a change server setting command (action_id AL class_type SR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68774,"title":"SQL Server Audit Event 24063 - Issued a delete server setting command (action_id DR class_type SR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24063","SQL Server"],"keywords":["24063","event 24063","event id 24063","Issued a delete server setting command (action_id DR class_type SR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24063"],"errorCode":"","eventId":"24063","severity":"Low","summary":"SQL Server Audit event 24063 records: Issued a delete server setting command (action_id DR class_type SR)","rootCause":"The configured audit source recorded this activity: Issued a delete server setting command (action_id DR class_type SR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24063.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete server setting command (action_id DR class_type SR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24063\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24063} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24063","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24063","Event ID 24063","Issued a delete server setting command (action_id DR class_type SR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68775,"title":"SQL Server Audit Event 24064 - Issued a create server cryptographic provider command (action_id CR class_type CP)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24064","SQL Server"],"keywords":["24064","event 24064","event id 24064","Issued a create server cryptographic provider command (action_id CR class_type CP)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24064"],"errorCode":"","eventId":"24064","severity":"Low","summary":"SQL Server Audit event 24064 records: Issued a create server cryptographic provider command (action_id CR class_type CP)","rootCause":"The configured audit source recorded this activity: Issued a create server cryptographic provider command (action_id CR class_type CP) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24064.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create server cryptographic provider command (action_id CR class_type CP)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24064\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24064} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24064","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24064","Event ID 24064","Issued a create server cryptographic provider command (action_id CR class_type CP)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68776,"title":"SQL Server Audit Event 24065 - Issued a delete server cryptographic provider command (action_id DR class_type CP)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24065","SQL Server"],"keywords":["24065","event 24065","event id 24065","Issued a delete server cryptographic provider command (action_id DR class_type CP)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24065"],"errorCode":"","eventId":"24065","severity":"Low","summary":"SQL Server Audit event 24065 records: Issued a delete server cryptographic provider command (action_id DR class_type CP)","rootCause":"The configured audit source recorded this activity: Issued a delete server cryptographic provider command (action_id DR class_type CP) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24065.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete server cryptographic provider command (action_id DR class_type CP)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24065\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24065} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24065","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24065","Event ID 24065","Issued a delete server cryptographic provider command (action_id DR class_type CP)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68777,"title":"SQL Server Audit Event 24066 - Issued a change server cryptographic provider command (action_id AL class_type CP)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24066","SQL Server"],"keywords":["24066","event 24066","event id 24066","Issued a change server cryptographic provider command (action_id AL class_type CP)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24066"],"errorCode":"","eventId":"24066","severity":"Low","summary":"SQL Server Audit event 24066 records: Issued a change server cryptographic provider command (action_id AL class_type CP)","rootCause":"The configured audit source recorded this activity: Issued a change server cryptographic provider command (action_id AL class_type CP) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24066.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change server cryptographic provider command (action_id AL class_type CP)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24066\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24066} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24066","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24066","Event ID 24066","Issued a change server cryptographic provider command (action_id AL class_type CP)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68778,"title":"SQL Server Audit Event 24067 - Issued a create server credential command (action_id CR class_type CD)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24067","SQL Server"],"keywords":["24067","event 24067","event id 24067","Issued a create server credential command (action_id CR class_type CD)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24067"],"errorCode":"","eventId":"24067","severity":"Low","summary":"SQL Server Audit event 24067 records: Issued a create server credential command (action_id CR class_type CD)","rootCause":"The configured audit source recorded this activity: Issued a create server credential command (action_id CR class_type CD) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24067.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create server credential command (action_id CR class_type CD)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24067\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24067} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24067","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24067","Event ID 24067","Issued a create server credential command (action_id CR class_type CD)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68779,"title":"SQL Server Audit Event 24068 - Issued a delete server credential command (action_id DR class_type CD)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24068","SQL Server"],"keywords":["24068","event 24068","event id 24068","Issued a delete server credential command (action_id DR class_type CD)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24068"],"errorCode":"","eventId":"24068","severity":"Low","summary":"SQL Server Audit event 24068 records: Issued a delete server credential command (action_id DR class_type CD)","rootCause":"The configured audit source recorded this activity: Issued a delete server credential command (action_id DR class_type CD) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24068.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete server credential command (action_id DR class_type CD)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24068\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24068} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24068","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24068","Event ID 24068","Issued a delete server credential command (action_id DR class_type CD)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68780,"title":"SQL Server Audit Event 24069 - Issued a change server credential command (action_id AL class_type CD)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24069","SQL Server"],"keywords":["24069","event 24069","event id 24069","Issued a change server credential command (action_id AL class_type CD)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24069"],"errorCode":"","eventId":"24069","severity":"Low","summary":"SQL Server Audit event 24069 records: Issued a change server credential command (action_id AL class_type CD)","rootCause":"The configured audit source recorded this activity: Issued a change server credential command (action_id AL class_type CD) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24069.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change server credential command (action_id AL class_type CD)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24069\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24069} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24069","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24069","Event ID 24069","Issued a change server credential command (action_id AL class_type CD)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68781,"title":"SQL Server Audit Event 24070 - Issued a change server master key command (action_id AL class_type MK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24070","SQL Server"],"keywords":["24070","event 24070","event id 24070","Issued a change server master key command (action_id AL class_type MK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24070"],"errorCode":"","eventId":"24070","severity":"Low","summary":"SQL Server Audit event 24070 records: Issued a change server master key command (action_id AL class_type MK)","rootCause":"The configured audit source recorded this activity: Issued a change server master key command (action_id AL class_type MK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24070.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change server master key command (action_id AL class_type MK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24070\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24070} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24070","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24070","Event ID 24070","Issued a change server master key command (action_id AL class_type MK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68782,"title":"SQL Server Audit Event 24071 - Issued a back up server master key command (action_id BA class_type MK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24071","SQL Server"],"keywords":["24071","event 24071","event id 24071","Issued a back up server master key command (action_id BA class_type MK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24071"],"errorCode":"","eventId":"24071","severity":"Low","summary":"SQL Server Audit event 24071 records: Issued a back up server master key command (action_id BA class_type MK)","rootCause":"The configured audit source recorded this activity: Issued a back up server master key command (action_id BA class_type MK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24071.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a back up server master key command (action_id BA class_type MK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24071\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24071} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24071","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24071","Event ID 24071","Issued a back up server master key command (action_id BA class_type MK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68783,"title":"SQL Server Audit Event 24072 - Issued a restore server master key command (action_id RS class_type MK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24072","SQL Server"],"keywords":["24072","event 24072","event id 24072","Issued a restore server master key command (action_id RS class_type MK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24072"],"errorCode":"","eventId":"24072","severity":"Low","summary":"SQL Server Audit event 24072 records: Issued a restore server master key command (action_id RS class_type MK)","rootCause":"The configured audit source recorded this activity: Issued a restore server master key command (action_id RS class_type MK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24072.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a restore server master key command (action_id RS class_type MK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24072\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24072} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24072","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24072","Event ID 24072","Issued a restore server master key command (action_id RS class_type MK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68784,"title":"SQL Server Audit Event 24073 - Issued a map server credential to login command (action_id CMLG)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24073","SQL Server"],"keywords":["24073","event 24073","event id 24073","Issued a map server credential to login command (action_id CMLG)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24073"],"errorCode":"","eventId":"24073","severity":"Low","summary":"SQL Server Audit event 24073 records: Issued a map server credential to login command (action_id CMLG)","rootCause":"The configured audit source recorded this activity: Issued a map server credential to login command (action_id CMLG) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24073.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a map server credential to login command (action_id CMLG)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24073\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24073} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24073","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24073","Event ID 24073","Issued a map server credential to login command (action_id CMLG)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68785,"title":"SQL Server Audit Event 24074 - Issued a remove map between server credential and login command (action_id NMLG)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24074","SQL Server"],"keywords":["24074","event 24074","event id 24074","Issued a remove map between server credential and login command (action_id NMLG)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24074"],"errorCode":"","eventId":"24074","severity":"Low","summary":"SQL Server Audit event 24074 records: Issued a remove map between server credential and login command (action_id NMLG)","rootCause":"The configured audit source recorded this activity: Issued a remove map between server credential and login command (action_id NMLG) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24074.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a remove map between server credential and login command (action_id NMLG)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24074\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24074} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24074","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24074","Event ID 24074","Issued a remove map between server credential and login command (action_id NMLG)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68786,"title":"SQL Server Audit Event 24075 - Issued a create server principal command (action_id CR class_type LX, SL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24075","SQL Server"],"keywords":["24075","event 24075","event id 24075","Issued a create server principal command (action_id CR class_type LX, SL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24075"],"errorCode":"","eventId":"24075","severity":"Low","summary":"SQL Server Audit event 24075 records: Issued a create server principal command (action_id CR class_type LX, SL)","rootCause":"The configured audit source recorded this activity: Issued a create server principal command (action_id CR class_type LX, SL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24075.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create server principal command (action_id CR class_type LX, SL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24075\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24075} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24075","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24075","Event ID 24075","Issued a create server principal command (action_id CR class_type LX, SL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68787,"title":"SQL Server Audit Event 24076 - Issued a delete server principal command (action_id DR class_type LX, SL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24076","SQL Server"],"keywords":["24076","event 24076","event id 24076","Issued a delete server principal command (action_id DR class_type LX, SL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24076"],"errorCode":"","eventId":"24076","severity":"Low","summary":"SQL Server Audit event 24076 records: Issued a delete server principal command (action_id DR class_type LX, SL)","rootCause":"The configured audit source recorded this activity: Issued a delete server principal command (action_id DR class_type LX, SL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24076.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete server principal command (action_id DR class_type LX, SL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24076\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24076} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24076","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24076","Event ID 24076","Issued a delete server principal command (action_id DR class_type LX, SL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68788,"title":"SQL Server Audit Event 24077 - Issued a change server principal credentials command (action_id CCLG)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24077","SQL Server"],"keywords":["24077","event 24077","event id 24077","Issued a change server principal credentials command (action_id CCLG)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24077"],"errorCode":"","eventId":"24077","severity":"Low","summary":"SQL Server Audit event 24077 records: Issued a change server principal credentials command (action_id CCLG)","rootCause":"The configured audit source recorded this activity: Issued a change server principal credentials command (action_id CCLG) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24077.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change server principal credentials command (action_id CCLG)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24077\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24077} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24077","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24077","Event ID 24077","Issued a change server principal credentials command (action_id CCLG)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68789,"title":"SQL Server Audit Event 24078 - Issued a disable server principal command (action_id LGDA)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24078","SQL Server"],"keywords":["24078","event 24078","event id 24078","Issued a disable server principal command (action_id LGDA)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24078"],"errorCode":"","eventId":"24078","severity":"Low","summary":"SQL Server Audit event 24078 records: Issued a disable server principal command (action_id LGDA)","rootCause":"The configured audit source recorded this activity: Issued a disable server principal command (action_id LGDA) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24078.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a disable server principal command (action_id LGDA)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24078\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24078} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24078","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24078","Event ID 24078","Issued a disable server principal command (action_id LGDA)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68790,"title":"SQL Server Audit Event 24079 - Issued a change server principal default database command (action_id LGDB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24079","SQL Server"],"keywords":["24079","event 24079","event id 24079","Issued a change server principal default database command (action_id LGDB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24079"],"errorCode":"","eventId":"24079","severity":"Low","summary":"SQL Server Audit event 24079 records: Issued a change server principal default database command (action_id LGDB)","rootCause":"The configured audit source recorded this activity: Issued a change server principal default database command (action_id LGDB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24079.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change server principal default database command (action_id LGDB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24079\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24079} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24079","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24079","Event ID 24079","Issued a change server principal default database command (action_id LGDB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68791,"title":"SQL Server Audit Event 24080 - Issued an enable server principal command (action_id LGEA)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24080","SQL Server"],"keywords":["24080","event 24080","event id 24080","Issued an enable server principal command (action_id LGEA)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24080"],"errorCode":"","eventId":"24080","severity":"Low","summary":"SQL Server Audit event 24080 records: Issued an enable server principal command (action_id LGEA)","rootCause":"The configured audit source recorded this activity: Issued an enable server principal command (action_id LGEA) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24080.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued an enable server principal command (action_id LGEA)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24080\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24080} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24080","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24080","Event ID 24080","Issued an enable server principal command (action_id LGEA)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68792,"title":"SQL Server Audit Event 24081 - Issued a change server principal default language command (action_id LGLG)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24081","SQL Server"],"keywords":["24081","event 24081","event id 24081","Issued a change server principal default language command (action_id LGLG)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24081"],"errorCode":"","eventId":"24081","severity":"Low","summary":"SQL Server Audit event 24081 records: Issued a change server principal default language command (action_id LGLG)","rootCause":"The configured audit source recorded this activity: Issued a change server principal default language command (action_id LGLG) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24081.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change server principal default language command (action_id LGLG)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24081\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24081} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24081","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24081","Event ID 24081","Issued a change server principal default language command (action_id LGLG)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68793,"title":"SQL Server Audit Event 24082 - Issued a change server principal password expiration command (action_id PWEX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24082","SQL Server"],"keywords":["24082","event 24082","event id 24082","Issued a change server principal password expiration command (action_id PWEX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24082"],"errorCode":"","eventId":"24082","severity":"Medium","summary":"SQL Server Audit event 24082 records: Issued a change server principal password expiration command (action_id PWEX)","rootCause":"The configured audit source recorded this activity: Issued a change server principal password expiration command (action_id PWEX) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24082.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change server principal password expiration command (action_id PWEX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24082\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24082} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24082","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24082","Event ID 24082","Issued a change server principal password expiration command (action_id PWEX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68794,"title":"SQL Server Audit Event 24083 - Issued a change server principal password policy command (action_id PWPL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24083","SQL Server"],"keywords":["24083","event 24083","event id 24083","Issued a change server principal password policy command (action_id PWPL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24083"],"errorCode":"","eventId":"24083","severity":"Medium","summary":"SQL Server Audit event 24083 records: Issued a change server principal password policy command (action_id PWPL)","rootCause":"The configured audit source recorded this activity: Issued a change server principal password policy command (action_id PWPL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24083.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change server principal password policy command (action_id PWPL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24083\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24083} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24083","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24083","Event ID 24083","Issued a change server principal password policy command (action_id PWPL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68795,"title":"SQL Server Audit Event 24084 - Issued a change server principal name command (action_id LGNM)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24084","SQL Server"],"keywords":["24084","event 24084","event id 24084","Issued a change server principal name command (action_id LGNM)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24084"],"errorCode":"","eventId":"24084","severity":"Low","summary":"SQL Server Audit event 24084 records: Issued a change server principal name command (action_id LGNM)","rootCause":"The configured audit source recorded this activity: Issued a change server principal name command (action_id LGNM) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24084.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change server principal name command (action_id LGNM)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24084\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24084} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24084","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24084","Event ID 24084","Issued a change server principal name command (action_id LGNM)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68796,"title":"SQL Server Audit Event 24085 - Issued a create database command (action_id CR class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24085","SQL Server"],"keywords":["24085","event 24085","event id 24085","Issued a create database command (action_id CR class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24085"],"errorCode":"","eventId":"24085","severity":"Low","summary":"SQL Server Audit event 24085 records: Issued a create database command (action_id CR class_type DB)","rootCause":"The configured audit source recorded this activity: Issued a create database command (action_id CR class_type DB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24085.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create database command (action_id CR class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24085\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24085} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24085","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24085","Event ID 24085","Issued a create database command (action_id CR class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68797,"title":"SQL Server Audit Event 24086 - Issued a change database command (action_id AL class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24086","SQL Server"],"keywords":["24086","event 24086","event id 24086","Issued a change database command (action_id AL class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24086"],"errorCode":"","eventId":"24086","severity":"Low","summary":"SQL Server Audit event 24086 records: Issued a change database command (action_id AL class_type DB)","rootCause":"The configured audit source recorded this activity: Issued a change database command (action_id AL class_type DB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24086.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change database command (action_id AL class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24086\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24086} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24086","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24086","Event ID 24086","Issued a change database command (action_id AL class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68798,"title":"SQL Server Audit Event 24087 - Issued a delete database command (action_id DR class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24087","SQL Server"],"keywords":["24087","event 24087","event id 24087","Issued a delete database command (action_id DR class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24087"],"errorCode":"","eventId":"24087","severity":"Low","summary":"SQL Server Audit event 24087 records: Issued a delete database command (action_id DR class_type DB)","rootCause":"The configured audit source recorded this activity: Issued a delete database command (action_id DR class_type DB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24087.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete database command (action_id DR class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24087\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24087} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24087","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24087","Event ID 24087","Issued a delete database command (action_id DR class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68799,"title":"SQL Server Audit Event 24088 - Issued a create certificate command (action_id CR class_type CR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24088","SQL Server"],"keywords":["24088","event 24088","event id 24088","Issued a create certificate command (action_id CR class_type CR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24088"],"errorCode":"","eventId":"24088","severity":"Medium","summary":"SQL Server Audit event 24088 records: Issued a create certificate command (action_id CR class_type CR)","rootCause":"The configured audit source recorded this activity: Issued a create certificate command (action_id CR class_type CR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24088.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create certificate command (action_id CR class_type CR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24088\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24088} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24088","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24088","Event ID 24088","Issued a create certificate command (action_id CR class_type CR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68800,"title":"SQL Server Audit Event 24089 - Issued a change certificate command (action_id AL class_type CR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24089","SQL Server"],"keywords":["24089","event 24089","event id 24089","Issued a change certificate command (action_id AL class_type CR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24089"],"errorCode":"","eventId":"24089","severity":"Medium","summary":"SQL Server Audit event 24089 records: Issued a change certificate command (action_id AL class_type CR)","rootCause":"The configured audit source recorded this activity: Issued a change certificate command (action_id AL class_type CR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24089.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change certificate command (action_id AL class_type CR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24089\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24089} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24089","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24089","Event ID 24089","Issued a change certificate command (action_id AL class_type CR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68801,"title":"SQL Server Audit Event 24090 - Issued a delete certificate command (action_id DR class_type CR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24090","SQL Server"],"keywords":["24090","event 24090","event id 24090","Issued a delete certificate command (action_id DR class_type CR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24090"],"errorCode":"","eventId":"24090","severity":"Medium","summary":"SQL Server Audit event 24090 records: Issued a delete certificate command (action_id DR class_type CR)","rootCause":"The configured audit source recorded this activity: Issued a delete certificate command (action_id DR class_type CR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24090.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete certificate command (action_id DR class_type CR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24090\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24090} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24090","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24090","Event ID 24090","Issued a delete certificate command (action_id DR class_type CR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68802,"title":"SQL Server Audit Event 24091 - Issued a back up certificate command (action_id BA class_type CR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24091","SQL Server"],"keywords":["24091","event 24091","event id 24091","Issued a back up certificate command (action_id BA class_type CR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24091"],"errorCode":"","eventId":"24091","severity":"Medium","summary":"SQL Server Audit event 24091 records: Issued a back up certificate command (action_id BA class_type CR)","rootCause":"The configured audit source recorded this activity: Issued a back up certificate command (action_id BA class_type CR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24091.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a back up certificate command (action_id BA class_type CR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24091\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24091} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24091","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24091","Event ID 24091","Issued a back up certificate command (action_id BA class_type CR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68803,"title":"SQL Server Audit Event 24092 - Issued an access certificate command (action_id AS class_type CR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24092","SQL Server"],"keywords":["24092","event 24092","event id 24092","Issued an access certificate command (action_id AS class_type CR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24092"],"errorCode":"","eventId":"24092","severity":"Medium","summary":"SQL Server Audit event 24092 records: Issued an access certificate command (action_id AS class_type CR)","rootCause":"The configured audit source recorded this activity: Issued an access certificate command (action_id AS class_type CR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24092.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued an access certificate command (action_id AS class_type CR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24092\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24092} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24092","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24092","Event ID 24092","Issued an access certificate command (action_id AS class_type CR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68804,"title":"SQL Server Audit Event 24093 - Issued a create asymmetric key command (action_id CR class_type AK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24093","SQL Server"],"keywords":["24093","event 24093","event id 24093","Issued a create asymmetric key command (action_id CR class_type AK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24093"],"errorCode":"","eventId":"24093","severity":"Low","summary":"SQL Server Audit event 24093 records: Issued a create asymmetric key command (action_id CR class_type AK)","rootCause":"The configured audit source recorded this activity: Issued a create asymmetric key command (action_id CR class_type AK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24093.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create asymmetric key command (action_id CR class_type AK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24093\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24093} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24093","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24093","Event ID 24093","Issued a create asymmetric key command (action_id CR class_type AK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68805,"title":"SQL Server Audit Event 24094 - Issued a change asymmetric key command (action_id AL class_type AK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24094","SQL Server"],"keywords":["24094","event 24094","event id 24094","Issued a change asymmetric key command (action_id AL class_type AK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24094"],"errorCode":"","eventId":"24094","severity":"Low","summary":"SQL Server Audit event 24094 records: Issued a change asymmetric key command (action_id AL class_type AK)","rootCause":"The configured audit source recorded this activity: Issued a change asymmetric key command (action_id AL class_type AK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24094.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change asymmetric key command (action_id AL class_type AK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24094\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24094} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24094","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24094","Event ID 24094","Issued a change asymmetric key command (action_id AL class_type AK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68806,"title":"SQL Server Audit Event 24095 - Issued a delete asymmetric key command (action_id DR class_type AK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24095","SQL Server"],"keywords":["24095","event 24095","event id 24095","Issued a delete asymmetric key command (action_id DR class_type AK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24095"],"errorCode":"","eventId":"24095","severity":"Low","summary":"SQL Server Audit event 24095 records: Issued a delete asymmetric key command (action_id DR class_type AK)","rootCause":"The configured audit source recorded this activity: Issued a delete asymmetric key command (action_id DR class_type AK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24095.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete asymmetric key command (action_id DR class_type AK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24095\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24095} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24095","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24095","Event ID 24095","Issued a delete asymmetric key command (action_id DR class_type AK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68807,"title":"SQL Server Audit Event 24096 - Issued an access asymmetric key command (action_id AS class_type AK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24096","SQL Server"],"keywords":["24096","event 24096","event id 24096","Issued an access asymmetric key command (action_id AS class_type AK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24096"],"errorCode":"","eventId":"24096","severity":"Low","summary":"SQL Server Audit event 24096 records: Issued an access asymmetric key command (action_id AS class_type AK)","rootCause":"The configured audit source recorded this activity: Issued an access asymmetric key command (action_id AS class_type AK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24096.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued an access asymmetric key command (action_id AS class_type AK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24096\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24096} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24096","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24096","Event ID 24096","Issued an access asymmetric key command (action_id AS class_type AK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68808,"title":"SQL Server Audit Event 24097 - Issued a create database master key command (action_id CR class_type MK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24097","SQL Server"],"keywords":["24097","event 24097","event id 24097","Issued a create database master key command (action_id CR class_type MK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24097"],"errorCode":"","eventId":"24097","severity":"Low","summary":"SQL Server Audit event 24097 records: Issued a create database master key command (action_id CR class_type MK)","rootCause":"The configured audit source recorded this activity: Issued a create database master key command (action_id CR class_type MK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24097.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create database master key command (action_id CR class_type MK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24097\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24097} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24097","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24097","Event ID 24097","Issued a create database master key command (action_id CR class_type MK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68809,"title":"SQL Server Audit Event 24098 - Issued a change database master key command (action_id AL class_type MK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24098","SQL Server"],"keywords":["24098","event 24098","event id 24098","Issued a change database master key command (action_id AL class_type MK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24098"],"errorCode":"","eventId":"24098","severity":"Low","summary":"SQL Server Audit event 24098 records: Issued a change database master key command (action_id AL class_type MK)","rootCause":"The configured audit source recorded this activity: Issued a change database master key command (action_id AL class_type MK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24098.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change database master key command (action_id AL class_type MK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24098\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24098} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24098","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24098","Event ID 24098","Issued a change database master key command (action_id AL class_type MK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68810,"title":"SQL Server Audit Event 24099 - Issued a delete database master key command (action_id DR class_type MK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24099","SQL Server"],"keywords":["24099","event 24099","event id 24099","Issued a delete database master key command (action_id DR class_type MK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24099"],"errorCode":"","eventId":"24099","severity":"Low","summary":"SQL Server Audit event 24099 records: Issued a delete database master key command (action_id DR class_type MK)","rootCause":"The configured audit source recorded this activity: Issued a delete database master key command (action_id DR class_type MK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24099.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete database master key command (action_id DR class_type MK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24099\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24099} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24099","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24099","Event ID 24099","Issued a delete database master key command (action_id DR class_type MK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68811,"title":"SQL Server Audit Event 24100 - Issued a back up database master key command (action_id BA class_type MK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24100","SQL Server"],"keywords":["24100","event 24100","event id 24100","Issued a back up database master key command (action_id BA class_type MK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24100"],"errorCode":"","eventId":"24100","severity":"Low","summary":"SQL Server Audit event 24100 records: Issued a back up database master key command (action_id BA class_type MK)","rootCause":"The configured audit source recorded this activity: Issued a back up database master key command (action_id BA class_type MK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24100.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a back up database master key command (action_id BA class_type MK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24100\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24100} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24100","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24100","Event ID 24100","Issued a back up database master key command (action_id BA class_type MK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68812,"title":"SQL Server Audit Event 24101 - Issued a restore database master key command (action_id RS class_type MK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24101","SQL Server"],"keywords":["24101","event 24101","event id 24101","Issued a restore database master key command (action_id RS class_type MK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24101"],"errorCode":"","eventId":"24101","severity":"Low","summary":"SQL Server Audit event 24101 records: Issued a restore database master key command (action_id RS class_type MK)","rootCause":"The configured audit source recorded this activity: Issued a restore database master key command (action_id RS class_type MK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24101.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a restore database master key command (action_id RS class_type MK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24101\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24101} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24101","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24101","Event ID 24101","Issued a restore database master key command (action_id RS class_type MK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68813,"title":"SQL Server Audit Event 24102 - Issued an open database master key command (action_id OP class_type MK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24102","SQL Server"],"keywords":["24102","event 24102","event id 24102","Issued an open database master key command (action_id OP class_type MK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24102"],"errorCode":"","eventId":"24102","severity":"Low","summary":"SQL Server Audit event 24102 records: Issued an open database master key command (action_id OP class_type MK)","rootCause":"The configured audit source recorded this activity: Issued an open database master key command (action_id OP class_type MK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24102.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued an open database master key command (action_id OP class_type MK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24102\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24102} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24102","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24102","Event ID 24102","Issued an open database master key command (action_id OP class_type MK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68814,"title":"SQL Server Audit Event 24103 - Issued a create database symmetric key command (action_id CR class_type SK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24103","SQL Server"],"keywords":["24103","event 24103","event id 24103","Issued a create database symmetric key command (action_id CR class_type SK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24103"],"errorCode":"","eventId":"24103","severity":"Low","summary":"SQL Server Audit event 24103 records: Issued a create database symmetric key command (action_id CR class_type SK)","rootCause":"The configured audit source recorded this activity: Issued a create database symmetric key command (action_id CR class_type SK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24103.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create database symmetric key command (action_id CR class_type SK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24103\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24103} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24103","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24103","Event ID 24103","Issued a create database symmetric key command (action_id CR class_type SK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68815,"title":"SQL Server Audit Event 24104 - Issued a change database symmetric key command (action_id AL class_type SK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24104","SQL Server"],"keywords":["24104","event 24104","event id 24104","Issued a change database symmetric key command (action_id AL class_type SK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24104"],"errorCode":"","eventId":"24104","severity":"Low","summary":"SQL Server Audit event 24104 records: Issued a change database symmetric key command (action_id AL class_type SK)","rootCause":"The configured audit source recorded this activity: Issued a change database symmetric key command (action_id AL class_type SK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24104.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change database symmetric key command (action_id AL class_type SK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24104\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24104} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24104","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24104","Event ID 24104","Issued a change database symmetric key command (action_id AL class_type SK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68816,"title":"SQL Server Audit Event 24105 - Issued a delete database symmetric key command (action_id DR class_type SK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24105","SQL Server"],"keywords":["24105","event 24105","event id 24105","Issued a delete database symmetric key command (action_id DR class_type SK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24105"],"errorCode":"","eventId":"24105","severity":"Low","summary":"SQL Server Audit event 24105 records: Issued a delete database symmetric key command (action_id DR class_type SK)","rootCause":"The configured audit source recorded this activity: Issued a delete database symmetric key command (action_id DR class_type SK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24105.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete database symmetric key command (action_id DR class_type SK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24105\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24105} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24105","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24105","Event ID 24105","Issued a delete database symmetric key command (action_id DR class_type SK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68817,"title":"SQL Server Audit Event 24106 - Issued a back up database symmetric key command (action_id BA class_type SK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24106","SQL Server"],"keywords":["24106","event 24106","event id 24106","Issued a back up database symmetric key command (action_id BA class_type SK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24106"],"errorCode":"","eventId":"24106","severity":"Low","summary":"SQL Server Audit event 24106 records: Issued a back up database symmetric key command (action_id BA class_type SK)","rootCause":"The configured audit source recorded this activity: Issued a back up database symmetric key command (action_id BA class_type SK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24106.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a back up database symmetric key command (action_id BA class_type SK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24106\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24106} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24106","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24106","Event ID 24106","Issued a back up database symmetric key command (action_id BA class_type SK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68818,"title":"SQL Server Audit Event 24107 - Issued an open database symmetric key command (action_id OP class_type SK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24107","SQL Server"],"keywords":["24107","event 24107","event id 24107","Issued an open database symmetric key command (action_id OP class_type SK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24107"],"errorCode":"","eventId":"24107","severity":"Low","summary":"SQL Server Audit event 24107 records: Issued an open database symmetric key command (action_id OP class_type SK)","rootCause":"The configured audit source recorded this activity: Issued an open database symmetric key command (action_id OP class_type SK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24107.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued an open database symmetric key command (action_id OP class_type SK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24107\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24107} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24107","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24107","Event ID 24107","Issued an open database symmetric key command (action_id OP class_type SK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68819,"title":"SQL Server Audit Event 24108 - Issued a create database object command (action_id CR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24108","SQL Server"],"keywords":["24108","event 24108","event id 24108","Issued a create database object command (action_id CR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24108"],"errorCode":"","eventId":"24108","severity":"Low","summary":"SQL Server Audit event 24108 records: Issued a create database object command (action_id CR)","rootCause":"The configured audit source recorded this activity: Issued a create database object command (action_id CR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24108.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create database object command (action_id CR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24108\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24108} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24108","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24108","Event ID 24108","Issued a create database object command (action_id CR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68820,"title":"SQL Server Audit Event 24109 - Issued a change database object command (action_id AL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24109","SQL Server"],"keywords":["24109","event 24109","event id 24109","Issued a change database object command (action_id AL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24109"],"errorCode":"","eventId":"24109","severity":"Low","summary":"SQL Server Audit event 24109 records: Issued a change database object command (action_id AL)","rootCause":"The configured audit source recorded this activity: Issued a change database object command (action_id AL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24109.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change database object command (action_id AL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24109\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24109} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24109","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24109","Event ID 24109","Issued a change database object command (action_id AL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68821,"title":"SQL Server Audit Event 24110 - Issued a delete database object command (action_id DR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24110","SQL Server"],"keywords":["24110","event 24110","event id 24110","Issued a delete database object command (action_id DR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24110"],"errorCode":"","eventId":"24110","severity":"Low","summary":"SQL Server Audit event 24110 records: Issued a delete database object command (action_id DR)","rootCause":"The configured audit source recorded this activity: Issued a delete database object command (action_id DR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24110.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete database object command (action_id DR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24110\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24110} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24110","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24110","Event ID 24110","Issued a delete database object command (action_id DR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68822,"title":"SQL Server Audit Event 24111 - Issued an access database object command (action_id AS)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24111","SQL Server"],"keywords":["24111","event 24111","event id 24111","Issued an access database object command (action_id AS)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24111"],"errorCode":"","eventId":"24111","severity":"Low","summary":"SQL Server Audit event 24111 records: Issued an access database object command (action_id AS)","rootCause":"The configured audit source recorded this activity: Issued an access database object command (action_id AS) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24111.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued an access database object command (action_id AS)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24111\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24111} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24111","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24111","Event ID 24111","Issued an access database object command (action_id AS)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68823,"title":"SQL Server Audit Event 24112 - Issued a create assembly command (action_id CR class_type AS)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24112","SQL Server"],"keywords":["24112","event 24112","event id 24112","Issued a create assembly command (action_id CR class_type AS)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24112"],"errorCode":"","eventId":"24112","severity":"Low","summary":"SQL Server Audit event 24112 records: Issued a create assembly command (action_id CR class_type AS)","rootCause":"The configured audit source recorded this activity: Issued a create assembly command (action_id CR class_type AS) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24112.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create assembly command (action_id CR class_type AS)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24112\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24112} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24112","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24112","Event ID 24112","Issued a create assembly command (action_id CR class_type AS)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68824,"title":"SQL Server Audit Event 24113 - Issued a change assembly command (action_id AL class_type AS)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24113","SQL Server"],"keywords":["24113","event 24113","event id 24113","Issued a change assembly command (action_id AL class_type AS)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24113"],"errorCode":"","eventId":"24113","severity":"Low","summary":"SQL Server Audit event 24113 records: Issued a change assembly command (action_id AL class_type AS)","rootCause":"The configured audit source recorded this activity: Issued a change assembly command (action_id AL class_type AS) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24113.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change assembly command (action_id AL class_type AS)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24113\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24113} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24113","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24113","Event ID 24113","Issued a change assembly command (action_id AL class_type AS)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68825,"title":"SQL Server Audit Event 24114 - Issued a delete assembly command (action_id DR class_type AS)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24114","SQL Server"],"keywords":["24114","event 24114","event id 24114","Issued a delete assembly command (action_id DR class_type AS)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24114"],"errorCode":"","eventId":"24114","severity":"Low","summary":"SQL Server Audit event 24114 records: Issued a delete assembly command (action_id DR class_type AS)","rootCause":"The configured audit source recorded this activity: Issued a delete assembly command (action_id DR class_type AS) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24114.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete assembly command (action_id DR class_type AS)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24114\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24114} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24114","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24114","Event ID 24114","Issued a delete assembly command (action_id DR class_type AS)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68826,"title":"SQL Server Audit Event 24115 - Issued a create schema command (action_id CR class_type SC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24115","SQL Server"],"keywords":["24115","event 24115","event id 24115","Issued a create schema command (action_id CR class_type SC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24115"],"errorCode":"","eventId":"24115","severity":"Low","summary":"SQL Server Audit event 24115 records: Issued a create schema command (action_id CR class_type SC)","rootCause":"The configured audit source recorded this activity: Issued a create schema command (action_id CR class_type SC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24115.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create schema command (action_id CR class_type SC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24115\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24115} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24115","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24115","Event ID 24115","Issued a create schema command (action_id CR class_type SC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68827,"title":"SQL Server Audit Event 24116 - Issued a change schema command (action_id AL class_type SC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24116","SQL Server"],"keywords":["24116","event 24116","event id 24116","Issued a change schema command (action_id AL class_type SC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24116"],"errorCode":"","eventId":"24116","severity":"Low","summary":"SQL Server Audit event 24116 records: Issued a change schema command (action_id AL class_type SC)","rootCause":"The configured audit source recorded this activity: Issued a change schema command (action_id AL class_type SC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24116.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change schema command (action_id AL class_type SC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24116\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24116} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24116","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24116","Event ID 24116","Issued a change schema command (action_id AL class_type SC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68828,"title":"SQL Server Audit Event 24117 - Issued a delete schema command (action_id DR class_type SC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24117","SQL Server"],"keywords":["24117","event 24117","event id 24117","Issued a delete schema command (action_id DR class_type SC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24117"],"errorCode":"","eventId":"24117","severity":"Low","summary":"SQL Server Audit event 24117 records: Issued a delete schema command (action_id DR class_type SC)","rootCause":"The configured audit source recorded this activity: Issued a delete schema command (action_id DR class_type SC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24117.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete schema command (action_id DR class_type SC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24117\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24117} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24117","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24117","Event ID 24117","Issued a delete schema command (action_id DR class_type SC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68829,"title":"SQL Server Audit Event 24118 - Issued a create database encryption key command (action_id CR class_type DK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24118","SQL Server"],"keywords":["24118","event 24118","event id 24118","Issued a create database encryption key command (action_id CR class_type DK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24118"],"errorCode":"","eventId":"24118","severity":"Low","summary":"SQL Server Audit event 24118 records: Issued a create database encryption key command (action_id CR class_type DK)","rootCause":"The configured audit source recorded this activity: Issued a create database encryption key command (action_id CR class_type DK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24118.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create database encryption key command (action_id CR class_type DK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24118\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24118} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24118","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24118","Event ID 24118","Issued a create database encryption key command (action_id CR class_type DK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68830,"title":"SQL Server Audit Event 24119 - Issued a change database encryption key command (action_id AL class_type DK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24119","SQL Server"],"keywords":["24119","event 24119","event id 24119","Issued a change database encryption key command (action_id AL class_type DK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24119"],"errorCode":"","eventId":"24119","severity":"Low","summary":"SQL Server Audit event 24119 records: Issued a change database encryption key command (action_id AL class_type DK)","rootCause":"The configured audit source recorded this activity: Issued a change database encryption key command (action_id AL class_type DK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24119.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change database encryption key command (action_id AL class_type DK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24119\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24119} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24119","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24119","Event ID 24119","Issued a change database encryption key command (action_id AL class_type DK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68831,"title":"SQL Server Audit Event 24120 - Issued a delete database encryption key command (action_id DR class_type DK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24120","SQL Server"],"keywords":["24120","event 24120","event id 24120","Issued a delete database encryption key command (action_id DR class_type DK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24120"],"errorCode":"","eventId":"24120","severity":"Low","summary":"SQL Server Audit event 24120 records: Issued a delete database encryption key command (action_id DR class_type DK)","rootCause":"The configured audit source recorded this activity: Issued a delete database encryption key command (action_id DR class_type DK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24120.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete database encryption key command (action_id DR class_type DK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24120\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24120} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24120","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24120","Event ID 24120","Issued a delete database encryption key command (action_id DR class_type DK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68832,"title":"SQL Server Audit Event 24121 - Issued a create database user command (action_id CR; class_type US)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24121","SQL Server"],"keywords":["24121","event 24121","event id 24121","Issued a create database user command (action_id CR; class_type US)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24121"],"errorCode":"","eventId":"24121","severity":"Low","summary":"SQL Server Audit event 24121 records: Issued a create database user command (action_id CR; class_type US)","rootCause":"The configured audit source recorded this activity: Issued a create database user command (action_id CR; class_type US) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24121.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create database user command (action_id CR; class_type US)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24121\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24121} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24121","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24121","Event ID 24121","Issued a create database user command (action_id CR; class_type US)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68833,"title":"SQL Server Audit Event 24122 - Issued a change database user command (action_id AL; class_type US)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24122","SQL Server"],"keywords":["24122","event 24122","event id 24122","Issued a change database user command (action_id AL; class_type US)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24122"],"errorCode":"","eventId":"24122","severity":"Low","summary":"SQL Server Audit event 24122 records: Issued a change database user command (action_id AL; class_type US)","rootCause":"The configured audit source recorded this activity: Issued a change database user command (action_id AL; class_type US) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24122.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change database user command (action_id AL; class_type US)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24122\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24122} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24122","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24122","Event ID 24122","Issued a change database user command (action_id AL; class_type US)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68834,"title":"SQL Server Audit Event 24123 - Issued a delete database user command (action_id DR; class_type US)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24123","SQL Server"],"keywords":["24123","event 24123","event id 24123","Issued a delete database user command (action_id DR; class_type US)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24123"],"errorCode":"","eventId":"24123","severity":"Low","summary":"SQL Server Audit event 24123 records: Issued a delete database user command (action_id DR; class_type US)","rootCause":"The configured audit source recorded this activity: Issued a delete database user command (action_id DR; class_type US) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24123.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete database user command (action_id DR; class_type US)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24123\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24123} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24123","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24123","Event ID 24123","Issued a delete database user command (action_id DR; class_type US)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68835,"title":"SQL Server Audit Event 24124 - Issued a create database role command (action_id CR class_type RL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24124","SQL Server"],"keywords":["24124","event 24124","event id 24124","Issued a create database role command (action_id CR class_type RL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24124"],"errorCode":"","eventId":"24124","severity":"Medium","summary":"SQL Server Audit event 24124 records: Issued a create database role command (action_id CR class_type RL)","rootCause":"The configured audit source recorded this activity: Issued a create database role command (action_id CR class_type RL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24124.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create database role command (action_id CR class_type RL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24124\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24124} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24124","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24124","Event ID 24124","Issued a create database role command (action_id CR class_type RL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68836,"title":"SQL Server Audit Event 24125 - Issued a change database role command (action_id AL class_type RL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24125","SQL Server"],"keywords":["24125","event 24125","event id 24125","Issued a change database role command (action_id AL class_type RL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24125"],"errorCode":"","eventId":"24125","severity":"Medium","summary":"SQL Server Audit event 24125 records: Issued a change database role command (action_id AL class_type RL)","rootCause":"The configured audit source recorded this activity: Issued a change database role command (action_id AL class_type RL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24125.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change database role command (action_id AL class_type RL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24125\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24125} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24125","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24125","Event ID 24125","Issued a change database role command (action_id AL class_type RL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68837,"title":"SQL Server Audit Event 24126 - Issued a delete database role command (action_id DR class_type RL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24126","SQL Server"],"keywords":["24126","event 24126","event id 24126","Issued a delete database role command (action_id DR class_type RL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24126"],"errorCode":"","eventId":"24126","severity":"Medium","summary":"SQL Server Audit event 24126 records: Issued a delete database role command (action_id DR class_type RL)","rootCause":"The configured audit source recorded this activity: Issued a delete database role command (action_id DR class_type RL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24126.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete database role command (action_id DR class_type RL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24126\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24126} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24126","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24126","Event ID 24126","Issued a delete database role command (action_id DR class_type RL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68838,"title":"SQL Server Audit Event 24127 - Issued a create application role command (action_id CR class_type AR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24127","SQL Server"],"keywords":["24127","event 24127","event id 24127","Issued a create application role command (action_id CR class_type AR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24127"],"errorCode":"","eventId":"24127","severity":"Medium","summary":"SQL Server Audit event 24127 records: Issued a create application role command (action_id CR class_type AR)","rootCause":"The configured audit source recorded this activity: Issued a create application role command (action_id CR class_type AR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24127.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create application role command (action_id CR class_type AR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24127\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24127} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24127","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24127","Event ID 24127","Issued a create application role command (action_id CR class_type AR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68839,"title":"SQL Server Audit Event 24128 - Issued a change application role command (action_id AL class_type AR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24128","SQL Server"],"keywords":["24128","event 24128","event id 24128","Issued a change application role command (action_id AL class_type AR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24128"],"errorCode":"","eventId":"24128","severity":"Medium","summary":"SQL Server Audit event 24128 records: Issued a change application role command (action_id AL class_type AR)","rootCause":"The configured audit source recorded this activity: Issued a change application role command (action_id AL class_type AR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24128.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change application role command (action_id AL class_type AR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24128\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24128} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24128","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24128","Event ID 24128","Issued a change application role command (action_id AL class_type AR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68840,"title":"SQL Server Audit Event 24129 - Issued a delete application role command (action_id DR class_type AR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24129","SQL Server"],"keywords":["24129","event 24129","event id 24129","Issued a delete application role command (action_id DR class_type AR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24129"],"errorCode":"","eventId":"24129","severity":"Medium","summary":"SQL Server Audit event 24129 records: Issued a delete application role command (action_id DR class_type AR)","rootCause":"The configured audit source recorded this activity: Issued a delete application role command (action_id DR class_type AR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24129.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete application role command (action_id DR class_type AR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24129\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24129} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24129","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24129","Event ID 24129","Issued a delete application role command (action_id DR class_type AR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68841,"title":"SQL Server Audit Event 24130 - Issued a change database user login command (action_id USAF)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24130","SQL Server"],"keywords":["24130","event 24130","event id 24130","Issued a change database user login command (action_id USAF)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24130"],"errorCode":"","eventId":"24130","severity":"Low","summary":"SQL Server Audit event 24130 records: Issued a change database user login command (action_id USAF)","rootCause":"The configured audit source recorded this activity: Issued a change database user login command (action_id USAF) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24130.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change database user login command (action_id USAF)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24130\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24130} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24130","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24130","Event ID 24130","Issued a change database user login command (action_id USAF)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68842,"title":"SQL Server Audit Event 24131 - Issued an auto-change database user login command (action_id USLG)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24131","SQL Server"],"keywords":["24131","event 24131","event id 24131","Issued an auto-change database user login command (action_id USLG)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24131"],"errorCode":"","eventId":"24131","severity":"Low","summary":"SQL Server Audit event 24131 records: Issued an auto-change database user login command (action_id USLG)","rootCause":"The configured audit source recorded this activity: Issued an auto-change database user login command (action_id USLG) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24131.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued an auto-change database user login command (action_id USLG)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24131\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24131} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24131","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24131","Event ID 24131","Issued an auto-change database user login command (action_id USLG)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68843,"title":"SQL Server Audit Event 24132 - Issued a create schema object command (action_id CR class_type D)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24132","SQL Server"],"keywords":["24132","event 24132","event id 24132","Issued a create schema object command (action_id CR class_type D)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24132"],"errorCode":"","eventId":"24132","severity":"Low","summary":"SQL Server Audit event 24132 records: Issued a create schema object command (action_id CR class_type D)","rootCause":"The configured audit source recorded this activity: Issued a create schema object command (action_id CR class_type D) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24132.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create schema object command (action_id CR class_type D)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24132\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24132} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24132","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24132","Event ID 24132","Issued a create schema object command (action_id CR class_type D)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68844,"title":"SQL Server Audit Event 24133 - Issued a change schema object command (action_id AL class_type D)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24133","SQL Server"],"keywords":["24133","event 24133","event id 24133","Issued a change schema object command (action_id AL class_type D)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24133"],"errorCode":"","eventId":"24133","severity":"Low","summary":"SQL Server Audit event 24133 records: Issued a change schema object command (action_id AL class_type D)","rootCause":"The configured audit source recorded this activity: Issued a change schema object command (action_id AL class_type D) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24133.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change schema object command (action_id AL class_type D)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24133\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24133} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24133","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24133","Event ID 24133","Issued a change schema object command (action_id AL class_type D)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68845,"title":"SQL Server Audit Event 24134 - Issued a delete schema object command (action_id DR class_type D)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24134","SQL Server"],"keywords":["24134","event 24134","event id 24134","Issued a delete schema object command (action_id DR class_type D)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24134"],"errorCode":"","eventId":"24134","severity":"Low","summary":"SQL Server Audit event 24134 records: Issued a delete schema object command (action_id DR class_type D)","rootCause":"The configured audit source recorded this activity: Issued a delete schema object command (action_id DR class_type D) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24134.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete schema object command (action_id DR class_type D)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24134\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24134} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24134","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24134","Event ID 24134","Issued a delete schema object command (action_id DR class_type D)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68846,"title":"SQL Server Audit Event 24135 - Issued a transfer schema object command (action_id TRO class_type D)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24135","SQL Server"],"keywords":["24135","event 24135","event id 24135","Issued a transfer schema object command (action_id TRO class_type D)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24135"],"errorCode":"","eventId":"24135","severity":"Low","summary":"SQL Server Audit event 24135 records: Issued a transfer schema object command (action_id TRO class_type D)","rootCause":"The configured audit source recorded this activity: Issued a transfer schema object command (action_id TRO class_type D) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24135.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a transfer schema object command (action_id TRO class_type D)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24135\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24135} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24135","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24135","Event ID 24135","Issued a transfer schema object command (action_id TRO class_type D)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68847,"title":"SQL Server Audit Event 24136 - Issued a create schema type command (action_id CR class_type TY)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24136","SQL Server"],"keywords":["24136","event 24136","event id 24136","Issued a create schema type command (action_id CR class_type TY)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24136"],"errorCode":"","eventId":"24136","severity":"Low","summary":"SQL Server Audit event 24136 records: Issued a create schema type command (action_id CR class_type TY)","rootCause":"The configured audit source recorded this activity: Issued a create schema type command (action_id CR class_type TY) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24136.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create schema type command (action_id CR class_type TY)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24136\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24136} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24136","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24136","Event ID 24136","Issued a create schema type command (action_id CR class_type TY)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68848,"title":"SQL Server Audit Event 24137 - Issued a change schema type command (action_id AL class_type TY)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24137","SQL Server"],"keywords":["24137","event 24137","event id 24137","Issued a change schema type command (action_id AL class_type TY)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24137"],"errorCode":"","eventId":"24137","severity":"Low","summary":"SQL Server Audit event 24137 records: Issued a change schema type command (action_id AL class_type TY)","rootCause":"The configured audit source recorded this activity: Issued a change schema type command (action_id AL class_type TY) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24137.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change schema type command (action_id AL class_type TY)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24137\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24137} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24137","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24137","Event ID 24137","Issued a change schema type command (action_id AL class_type TY)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68849,"title":"SQL Server Audit Event 24138 - Issued a delete schema type command (action_id DR class_type TY)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24138","SQL Server"],"keywords":["24138","event 24138","event id 24138","Issued a delete schema type command (action_id DR class_type TY)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24138"],"errorCode":"","eventId":"24138","severity":"Low","summary":"SQL Server Audit event 24138 records: Issued a delete schema type command (action_id DR class_type TY)","rootCause":"The configured audit source recorded this activity: Issued a delete schema type command (action_id DR class_type TY) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24138.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete schema type command (action_id DR class_type TY)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24138\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24138} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24138","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24138","Event ID 24138","Issued a delete schema type command (action_id DR class_type TY)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68850,"title":"SQL Server Audit Event 24139 - Issued a transfer schema type command (action_id TRO class_type TY)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24139","SQL Server"],"keywords":["24139","event 24139","event id 24139","Issued a transfer schema type command (action_id TRO class_type TY)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24139"],"errorCode":"","eventId":"24139","severity":"Low","summary":"SQL Server Audit event 24139 records: Issued a transfer schema type command (action_id TRO class_type TY)","rootCause":"The configured audit source recorded this activity: Issued a transfer schema type command (action_id TRO class_type TY) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24139.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a transfer schema type command (action_id TRO class_type TY)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24139\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24139} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24139","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24139","Event ID 24139","Issued a transfer schema type command (action_id TRO class_type TY)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68851,"title":"SQL Server Audit Event 24140 - Issued a create XML schema collection command (action_id CR class_type SX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24140","SQL Server"],"keywords":["24140","event 24140","event id 24140","Issued a create XML schema collection command (action_id CR class_type SX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24140"],"errorCode":"","eventId":"24140","severity":"Low","summary":"SQL Server Audit event 24140 records: Issued a create XML schema collection command (action_id CR class_type SX)","rootCause":"The configured audit source recorded this activity: Issued a create XML schema collection command (action_id CR class_type SX) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24140.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create XML schema collection command (action_id CR class_type SX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24140\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24140} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24140","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24140","Event ID 24140","Issued a create XML schema collection command (action_id CR class_type SX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68852,"title":"SQL Server Audit Event 24141 - Issued a change XML schema collection command (action_id AL class_type SX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24141","SQL Server"],"keywords":["24141","event 24141","event id 24141","Issued a change XML schema collection command (action_id AL class_type SX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24141"],"errorCode":"","eventId":"24141","severity":"Low","summary":"SQL Server Audit event 24141 records: Issued a change XML schema collection command (action_id AL class_type SX)","rootCause":"The configured audit source recorded this activity: Issued a change XML schema collection command (action_id AL class_type SX) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24141.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change XML schema collection command (action_id AL class_type SX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24141\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24141} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24141","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24141","Event ID 24141","Issued a change XML schema collection command (action_id AL class_type SX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68853,"title":"SQL Server Audit Event 24142 - Issued a delete XML schema collection command (action_id DR class_type SX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24142","SQL Server"],"keywords":["24142","event 24142","event id 24142","Issued a delete XML schema collection command (action_id DR class_type SX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24142"],"errorCode":"","eventId":"24142","severity":"Low","summary":"SQL Server Audit event 24142 records: Issued a delete XML schema collection command (action_id DR class_type SX)","rootCause":"The configured audit source recorded this activity: Issued a delete XML schema collection command (action_id DR class_type SX) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24142.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete XML schema collection command (action_id DR class_type SX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24142\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24142} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24142","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24142","Event ID 24142","Issued a delete XML schema collection command (action_id DR class_type SX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68854,"title":"SQL Server Audit Event 24143 - Issued a transfer XML schema collection command (action_id TRO class_type SX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24143","SQL Server"],"keywords":["24143","event 24143","event id 24143","Issued a transfer XML schema collection command (action_id TRO class_type SX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24143"],"errorCode":"","eventId":"24143","severity":"Low","summary":"SQL Server Audit event 24143 records: Issued a transfer XML schema collection command (action_id TRO class_type SX)","rootCause":"The configured audit source recorded this activity: Issued a transfer XML schema collection command (action_id TRO class_type SX) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24143.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a transfer XML schema collection command (action_id TRO class_type SX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24143\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24143} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24143","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24143","Event ID 24143","Issued a transfer XML schema collection command (action_id TRO class_type SX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68855,"title":"SQL Server Audit Event 24144 - Issued an impersonate within server scope command (action_id IMP; class_type LX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24144","SQL Server"],"keywords":["24144","event 24144","event id 24144","Issued an impersonate within server scope command (action_id IMP; class_type LX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24144"],"errorCode":"","eventId":"24144","severity":"Low","summary":"SQL Server Audit event 24144 records: Issued an impersonate within server scope command (action_id IMP; class_type LX)","rootCause":"The configured audit source recorded this activity: Issued an impersonate within server scope command (action_id IMP; class_type LX) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24144.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued an impersonate within server scope command (action_id IMP; class_type LX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24144\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24144} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24144","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24144","Event ID 24144","Issued an impersonate within server scope command (action_id IMP; class_type LX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68856,"title":"SQL Server Audit Event 24145 - Issued an impersonate within database scope command (action_id IMP; class_type US)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24145","SQL Server"],"keywords":["24145","event 24145","event id 24145","Issued an impersonate within database scope command (action_id IMP; class_type US)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24145"],"errorCode":"","eventId":"24145","severity":"Low","summary":"SQL Server Audit event 24145 records: Issued an impersonate within database scope command (action_id IMP; class_type US)","rootCause":"The configured audit source recorded this activity: Issued an impersonate within database scope command (action_id IMP; class_type US) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24145.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued an impersonate within database scope command (action_id IMP; class_type US)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24145\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24145} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24145","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24145","Event ID 24145","Issued an impersonate within database scope command (action_id IMP; class_type US)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68857,"title":"SQL Server Audit Event 24146 - Issued a change server object owner command (action_id TO class_type SG)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24146","SQL Server"],"keywords":["24146","event 24146","event id 24146","Issued a change server object owner command (action_id TO class_type SG)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24146"],"errorCode":"","eventId":"24146","severity":"Low","summary":"SQL Server Audit event 24146 records: Issued a change server object owner command (action_id TO class_type SG)","rootCause":"The configured audit source recorded this activity: Issued a change server object owner command (action_id TO class_type SG) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24146.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change server object owner command (action_id TO class_type SG)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24146\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24146} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24146","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24146","Event ID 24146","Issued a change server object owner command (action_id TO class_type SG)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68858,"title":"SQL Server Audit Event 24147 - Issued a change database owner command (action_id TO class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24147","SQL Server"],"keywords":["24147","event 24147","event id 24147","Issued a change database owner command (action_id TO class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24147"],"errorCode":"","eventId":"24147","severity":"Low","summary":"SQL Server Audit event 24147 records: Issued a change database owner command (action_id TO class_type DB)","rootCause":"The configured audit source recorded this activity: Issued a change database owner command (action_id TO class_type DB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24147.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change database owner command (action_id TO class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24147\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24147} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24147","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24147","Event ID 24147","Issued a change database owner command (action_id TO class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68859,"title":"SQL Server Audit Event 24148 - Issued a change schema owner command (action_id TO class_type SC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24148","SQL Server"],"keywords":["24148","event 24148","event id 24148","Issued a change schema owner command (action_id TO class_type SC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24148"],"errorCode":"","eventId":"24148","severity":"Low","summary":"SQL Server Audit event 24148 records: Issued a change schema owner command (action_id TO class_type SC)","rootCause":"The configured audit source recorded this activity: Issued a change schema owner command (action_id TO class_type SC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24148.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change schema owner command (action_id TO class_type SC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24148\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24148} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24148","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24148","Event ID 24148","Issued a change schema owner command (action_id TO class_type SC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68860,"title":"SQL Server Audit Event 24150 - Issued a change role owner command (action_id TO class_type RL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24150","SQL Server"],"keywords":["24150","event 24150","event id 24150","Issued a change role owner command (action_id TO class_type RL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24150"],"errorCode":"","eventId":"24150","severity":"Medium","summary":"SQL Server Audit event 24150 records: Issued a change role owner command (action_id TO class_type RL)","rootCause":"The configured audit source recorded this activity: Issued a change role owner command (action_id TO class_type RL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24150.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change role owner command (action_id TO class_type RL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24150\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24150} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24150","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24150","Event ID 24150","Issued a change role owner command (action_id TO class_type RL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68861,"title":"SQL Server Audit Event 24151 - Issued a change database object owner command (action_id TO)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24151","SQL Server"],"keywords":["24151","event 24151","event id 24151","Issued a change database object owner command (action_id TO)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24151"],"errorCode":"","eventId":"24151","severity":"Low","summary":"SQL Server Audit event 24151 records: Issued a change database object owner command (action_id TO)","rootCause":"The configured audit source recorded this activity: Issued a change database object owner command (action_id TO) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24151.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change database object owner command (action_id TO)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24151\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24151} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24151","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24151","Event ID 24151","Issued a change database object owner command (action_id TO)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68862,"title":"SQL Server Audit Event 24152 - Issued a change symmetric key owner command (action_id TO class_type SK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24152","SQL Server"],"keywords":["24152","event 24152","event id 24152","Issued a change symmetric key owner command (action_id TO class_type SK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24152"],"errorCode":"","eventId":"24152","severity":"Low","summary":"SQL Server Audit event 24152 records: Issued a change symmetric key owner command (action_id TO class_type SK)","rootCause":"The configured audit source recorded this activity: Issued a change symmetric key owner command (action_id TO class_type SK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24152.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change symmetric key owner command (action_id TO class_type SK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24152\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24152} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24152","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24152","Event ID 24152","Issued a change symmetric key owner command (action_id TO class_type SK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68863,"title":"SQL Server Audit Event 24153 - Issued a change certificate owner command (action_id TO class_type CR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24153","SQL Server"],"keywords":["24153","event 24153","event id 24153","Issued a change certificate owner command (action_id TO class_type CR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24153"],"errorCode":"","eventId":"24153","severity":"Medium","summary":"SQL Server Audit event 24153 records: Issued a change certificate owner command (action_id TO class_type CR)","rootCause":"The configured audit source recorded this activity: Issued a change certificate owner command (action_id TO class_type CR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24153.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change certificate owner command (action_id TO class_type CR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24153\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24153} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24153","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24153","Event ID 24153","Issued a change certificate owner command (action_id TO class_type CR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68864,"title":"SQL Server Audit Event 24154 - Issued a change asymmetric key owner command (action_id TO class_type AK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24154","SQL Server"],"keywords":["24154","event 24154","event id 24154","Issued a change asymmetric key owner command (action_id TO class_type AK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24154"],"errorCode":"","eventId":"24154","severity":"Low","summary":"SQL Server Audit event 24154 records: Issued a change asymmetric key owner command (action_id TO class_type AK)","rootCause":"The configured audit source recorded this activity: Issued a change asymmetric key owner command (action_id TO class_type AK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24154.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change asymmetric key owner command (action_id TO class_type AK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24154\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24154} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24154","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24154","Event ID 24154","Issued a change asymmetric key owner command (action_id TO class_type AK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68865,"title":"SQL Server Audit Event 24155 - Issued a change schema object owner command (action_id TO class_type OB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24155","SQL Server"],"keywords":["24155","event 24155","event id 24155","Issued a change schema object owner command (action_id TO class_type OB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24155"],"errorCode":"","eventId":"24155","severity":"Low","summary":"SQL Server Audit event 24155 records: Issued a change schema object owner command (action_id TO class_type OB)","rootCause":"The configured audit source recorded this activity: Issued a change schema object owner command (action_id TO class_type OB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24155.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change schema object owner command (action_id TO class_type OB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24155\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24155} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24155","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24155","Event ID 24155","Issued a change schema object owner command (action_id TO class_type OB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68866,"title":"SQL Server Audit Event 24156 - Issued a change schema type owner command (action_id TO class_type TY)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24156","SQL Server"],"keywords":["24156","event 24156","event id 24156","Issued a change schema type owner command (action_id TO class_type TY)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24156"],"errorCode":"","eventId":"24156","severity":"Low","summary":"SQL Server Audit event 24156 records: Issued a change schema type owner command (action_id TO class_type TY)","rootCause":"The configured audit source recorded this activity: Issued a change schema type owner command (action_id TO class_type TY) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24156.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change schema type owner command (action_id TO class_type TY)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24156\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24156} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24156","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24156","Event ID 24156","Issued a change schema type owner command (action_id TO class_type TY)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68867,"title":"SQL Server Audit Event 24157 - Issued a change XML schema collection owner command (action_id TO class_type SX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24157","SQL Server"],"keywords":["24157","event 24157","event id 24157","Issued a change XML schema collection owner command (action_id TO class_type SX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24157"],"errorCode":"","eventId":"24157","severity":"Low","summary":"SQL Server Audit event 24157 records: Issued a change XML schema collection owner command (action_id TO class_type SX)","rootCause":"The configured audit source recorded this activity: Issued a change XML schema collection owner command (action_id TO class_type SX) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24157.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change XML schema collection owner command (action_id TO class_type SX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24157\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24157} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24157","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24157","Event ID 24157","Issued a change XML schema collection owner command (action_id TO class_type SX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68868,"title":"SQL Server Audit Event 24158 - Grant server permissions succeeded (action_id G class_type SR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24158","SQL Server"],"keywords":["24158","event 24158","event id 24158","Grant server permissions succeeded (action_id G class_type SR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24158"],"errorCode":"","eventId":"24158","severity":"Medium","summary":"SQL Server Audit event 24158 records: Grant server permissions succeeded (action_id G class_type SR)","rootCause":"The configured audit source recorded this activity: Grant server permissions succeeded (action_id G class_type SR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24158.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Grant server permissions succeeded (action_id G class_type SR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24158\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24158} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24158","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24158","Event ID 24158","Grant server permissions succeeded (action_id G class_type SR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68869,"title":"SQL Server Audit Event 24159 - Grant server permissions failed (action_id G class_type SR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24159","SQL Server"],"keywords":["24159","event 24159","event id 24159","Grant server permissions failed (action_id G class_type SR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24159"],"errorCode":"","eventId":"24159","severity":"High","summary":"SQL Server Audit event 24159 records: Grant server permissions failed (action_id G class_type SR)","rootCause":"The audited operation reported a failure: Grant server permissions failed (action_id G class_type SR) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24159.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Grant server permissions failed (action_id G class_type SR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24159\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24159} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24159","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24159","Event ID 24159","Grant server permissions failed (action_id G class_type SR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68870,"title":"SQL Server Audit Event 24160 - Grant server permissions with grant succeeded (action_id GWG class_type SR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24160","SQL Server"],"keywords":["24160","event 24160","event id 24160","Grant server permissions with grant succeeded (action_id GWG class_type SR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24160"],"errorCode":"","eventId":"24160","severity":"Medium","summary":"SQL Server Audit event 24160 records: Grant server permissions with grant succeeded (action_id GWG class_type SR)","rootCause":"The configured audit source recorded this activity: Grant server permissions with grant succeeded (action_id GWG class_type SR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24160.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Grant server permissions with grant succeeded (action_id GWG class_type SR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24160\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24160} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24160","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24160","Event ID 24160","Grant server permissions with grant succeeded (action_id GWG class_type SR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68871,"title":"SQL Server Audit Event 24161 - Grant server permissions with grant failed (action_id GWG class_type SR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24161","SQL Server"],"keywords":["24161","event 24161","event id 24161","Grant server permissions with grant failed (action_id GWG class_type SR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24161"],"errorCode":"","eventId":"24161","severity":"High","summary":"SQL Server Audit event 24161 records: Grant server permissions with grant failed (action_id GWG class_type SR)","rootCause":"The audited operation reported a failure: Grant server permissions with grant failed (action_id GWG class_type SR) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24161.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Grant server permissions with grant failed (action_id GWG class_type SR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24161\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24161} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24161","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24161","Event ID 24161","Grant server permissions with grant failed (action_id GWG class_type SR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68872,"title":"SQL Server Audit Event 24162 - Deny server permissions succeeded (action_id D class_type SR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24162","SQL Server"],"keywords":["24162","event 24162","event id 24162","Deny server permissions succeeded (action_id D class_type SR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24162"],"errorCode":"","eventId":"24162","severity":"Medium","summary":"SQL Server Audit event 24162 records: Deny server permissions succeeded (action_id D class_type SR)","rootCause":"The configured audit source recorded this activity: Deny server permissions succeeded (action_id D class_type SR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24162.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Deny server permissions succeeded (action_id D class_type SR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24162\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24162} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24162","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24162","Event ID 24162","Deny server permissions succeeded (action_id D class_type SR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68873,"title":"SQL Server Audit Event 24163 - Deny server permissions failed (action_id D class_type SR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24163","SQL Server"],"keywords":["24163","event 24163","event id 24163","Deny server permissions failed (action_id D class_type SR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24163"],"errorCode":"","eventId":"24163","severity":"High","summary":"SQL Server Audit event 24163 records: Deny server permissions failed (action_id D class_type SR)","rootCause":"The audited operation reported a failure: Deny server permissions failed (action_id D class_type SR) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24163.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Deny server permissions failed (action_id D class_type SR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24163\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24163} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24163","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24163","Event ID 24163","Deny server permissions failed (action_id D class_type SR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68874,"title":"SQL Server Audit Event 24164 - Deny server permissions with cascade succeeded (action_id DWC class_type SR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24164","SQL Server"],"keywords":["24164","event 24164","event id 24164","Deny server permissions with cascade succeeded (action_id DWC class_type SR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24164"],"errorCode":"","eventId":"24164","severity":"Medium","summary":"SQL Server Audit event 24164 records: Deny server permissions with cascade succeeded (action_id DWC class_type SR)","rootCause":"The configured audit source recorded this activity: Deny server permissions with cascade succeeded (action_id DWC class_type SR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24164.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Deny server permissions with cascade succeeded (action_id DWC class_type SR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24164\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24164} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24164","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24164","Event ID 24164","Deny server permissions with cascade succeeded (action_id DWC class_type SR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68875,"title":"SQL Server Audit Event 24165 - Deny server permissions with cascade failed (action_id DWC class_type SR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24165","SQL Server"],"keywords":["24165","event 24165","event id 24165","Deny server permissions with cascade failed (action_id DWC class_type SR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24165"],"errorCode":"","eventId":"24165","severity":"High","summary":"SQL Server Audit event 24165 records: Deny server permissions with cascade failed (action_id DWC class_type SR)","rootCause":"The audited operation reported a failure: Deny server permissions with cascade failed (action_id DWC class_type SR) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24165.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Deny server permissions with cascade failed (action_id DWC class_type SR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24165\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24165} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24165","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24165","Event ID 24165","Deny server permissions with cascade failed (action_id DWC class_type SR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68876,"title":"SQL Server Audit Event 24166 - Revoke server permissions succeeded (action_id R class_type SR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24166","SQL Server"],"keywords":["24166","event 24166","event id 24166","Revoke server permissions succeeded (action_id R class_type SR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24166"],"errorCode":"","eventId":"24166","severity":"Medium","summary":"SQL Server Audit event 24166 records: Revoke server permissions succeeded (action_id R class_type SR)","rootCause":"The configured audit source recorded this activity: Revoke server permissions succeeded (action_id R class_type SR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24166.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Revoke server permissions succeeded (action_id R class_type SR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24166\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24166} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24166","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24166","Event ID 24166","Revoke server permissions succeeded (action_id R class_type SR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68877,"title":"SQL Server Audit Event 24167 - Revoke server permissions failed (action_id R class_type SR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24167","SQL Server"],"keywords":["24167","event 24167","event id 24167","Revoke server permissions failed (action_id R class_type SR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24167"],"errorCode":"","eventId":"24167","severity":"High","summary":"SQL Server Audit event 24167 records: Revoke server permissions failed (action_id R class_type SR)","rootCause":"The audited operation reported a failure: Revoke server permissions failed (action_id R class_type SR) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24167.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Revoke server permissions failed (action_id R class_type SR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24167\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24167} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24167","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24167","Event ID 24167","Revoke server permissions failed (action_id R class_type SR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68878,"title":"SQL Server Audit Event 24168 - Revoke server permissions with grant succeeded (action_id RWG class_type SR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24168","SQL Server"],"keywords":["24168","event 24168","event id 24168","Revoke server permissions with grant succeeded (action_id RWG class_type SR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24168"],"errorCode":"","eventId":"24168","severity":"Medium","summary":"SQL Server Audit event 24168 records: Revoke server permissions with grant succeeded (action_id RWG class_type SR)","rootCause":"The configured audit source recorded this activity: Revoke server permissions with grant succeeded (action_id RWG class_type SR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24168.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Revoke server permissions with grant succeeded (action_id RWG class_type SR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24168\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24168} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24168","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24168","Event ID 24168","Revoke server permissions with grant succeeded (action_id RWG class_type SR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68879,"title":"SQL Server Audit Event 24169 - Revoke server permissions with grant failed (action_id RWG class_type SR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24169","SQL Server"],"keywords":["24169","event 24169","event id 24169","Revoke server permissions with grant failed (action_id RWG class_type SR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24169"],"errorCode":"","eventId":"24169","severity":"High","summary":"SQL Server Audit event 24169 records: Revoke server permissions with grant failed (action_id RWG class_type SR)","rootCause":"The audited operation reported a failure: Revoke server permissions with grant failed (action_id RWG class_type SR) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24169.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Revoke server permissions with grant failed (action_id RWG class_type SR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24169\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24169} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24169","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24169","Event ID 24169","Revoke server permissions with grant failed (action_id RWG class_type SR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68880,"title":"SQL Server Audit Event 24170 - Revoke server permissions with cascade succeeded (action_id RWC class_type SR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24170","SQL Server"],"keywords":["24170","event 24170","event id 24170","Revoke server permissions with cascade succeeded (action_id RWC class_type SR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24170"],"errorCode":"","eventId":"24170","severity":"Medium","summary":"SQL Server Audit event 24170 records: Revoke server permissions with cascade succeeded (action_id RWC class_type SR)","rootCause":"The configured audit source recorded this activity: Revoke server permissions with cascade succeeded (action_id RWC class_type SR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24170.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Revoke server permissions with cascade succeeded (action_id RWC class_type SR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24170\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24170} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24170","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24170","Event ID 24170","Revoke server permissions with cascade succeeded (action_id RWC class_type SR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68881,"title":"SQL Server Audit Event 24171 - Revoke server permissions with cascade failed (action_id RWC class_type SR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24171","SQL Server"],"keywords":["24171","event 24171","event id 24171","Revoke server permissions with cascade failed (action_id RWC class_type SR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24171"],"errorCode":"","eventId":"24171","severity":"High","summary":"SQL Server Audit event 24171 records: Revoke server permissions with cascade failed (action_id RWC class_type SR)","rootCause":"The audited operation reported a failure: Revoke server permissions with cascade failed (action_id RWC class_type SR) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24171.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Revoke server permissions with cascade failed (action_id RWC class_type SR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24171\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24171} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24171","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24171","Event ID 24171","Revoke server permissions with cascade failed (action_id RWC class_type SR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68882,"title":"SQL Server Audit Event 24172 - Issued grant server object permissions command (action_id G; class_type LX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24172","SQL Server"],"keywords":["24172","event 24172","event id 24172","Issued grant server object permissions command (action_id G; class_type LX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24172"],"errorCode":"","eventId":"24172","severity":"Medium","summary":"SQL Server Audit event 24172 records: Issued grant server object permissions command (action_id G; class_type LX)","rootCause":"The configured audit source recorded this activity: Issued grant server object permissions command (action_id G; class_type LX) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24172.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant server object permissions command (action_id G; class_type LX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24172\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24172} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24172","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24172","Event ID 24172","Issued grant server object permissions command (action_id G; class_type LX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68883,"title":"SQL Server Audit Event 24173 - Issued grant server object permissions with grant command (action_id GWG; class_type LX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24173","SQL Server"],"keywords":["24173","event 24173","event id 24173","Issued grant server object permissions with grant command (action_id GWG; class_type LX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24173"],"errorCode":"","eventId":"24173","severity":"Medium","summary":"SQL Server Audit event 24173 records: Issued grant server object permissions with grant command (action_id GWG; class_type LX)","rootCause":"The configured audit source recorded this activity: Issued grant server object permissions with grant command (action_id GWG; class_type LX) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24173.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant server object permissions with grant command (action_id GWG; class_type LX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24173\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24173} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24173","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24173","Event ID 24173","Issued grant server object permissions with grant command (action_id GWG; class_type LX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68884,"title":"SQL Server Audit Event 24174 - Issued deny server object permissions command (action_id D; class_type LX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24174","SQL Server"],"keywords":["24174","event 24174","event id 24174","Issued deny server object permissions command (action_id D; class_type LX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24174"],"errorCode":"","eventId":"24174","severity":"Medium","summary":"SQL Server Audit event 24174 records: Issued deny server object permissions command (action_id D; class_type LX)","rootCause":"The configured audit source recorded this activity: Issued deny server object permissions command (action_id D; class_type LX) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24174.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny server object permissions command (action_id D; class_type LX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24174\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24174} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24174","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24174","Event ID 24174","Issued deny server object permissions command (action_id D; class_type LX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68885,"title":"SQL Server Audit Event 24175 - Issued deny server object permissions with cascade command (action_id DWC; class_type LX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24175","SQL Server"],"keywords":["24175","event 24175","event id 24175","Issued deny server object permissions with cascade command (action_id DWC; class_type LX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24175"],"errorCode":"","eventId":"24175","severity":"Medium","summary":"SQL Server Audit event 24175 records: Issued deny server object permissions with cascade command (action_id DWC; class_type LX)","rootCause":"The configured audit source recorded this activity: Issued deny server object permissions with cascade command (action_id DWC; class_type LX) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24175.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny server object permissions with cascade command (action_id DWC; class_type LX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24175\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24175} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24175","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24175","Event ID 24175","Issued deny server object permissions with cascade command (action_id DWC; class_type LX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68886,"title":"SQL Server Audit Event 24176 - Issued revoke server object permissions command (action_id R; class_type LX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24176","SQL Server"],"keywords":["24176","event 24176","event id 24176","Issued revoke server object permissions command (action_id R; class_type LX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24176"],"errorCode":"","eventId":"24176","severity":"Medium","summary":"SQL Server Audit event 24176 records: Issued revoke server object permissions command (action_id R; class_type LX)","rootCause":"The configured audit source recorded this activity: Issued revoke server object permissions command (action_id R; class_type LX) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24176.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke server object permissions command (action_id R; class_type LX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24176\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24176} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24176","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24176","Event ID 24176","Issued revoke server object permissions command (action_id R; class_type LX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68887,"title":"SQL Server Audit Event 24177 - Issued revoke server object permissions with grant command (action_id; RWG class_type LX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24177","SQL Server"],"keywords":["24177","event 24177","event id 24177","Issued revoke server object permissions with grant command (action_id; RWG class_type LX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24177"],"errorCode":"","eventId":"24177","severity":"Medium","summary":"SQL Server Audit event 24177 records: Issued revoke server object permissions with grant command (action_id; RWG class_type LX)","rootCause":"The configured audit source recorded this activity: Issued revoke server object permissions with grant command (action_id; RWG class_type LX) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24177.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke server object permissions with grant command (action_id; RWG class_type LX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24177\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24177} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24177","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24177","Event ID 24177","Issued revoke server object permissions with grant command (action_id; RWG class_type LX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68888,"title":"SQL Server Audit Event 24178 - Issued revoke server object permissions with cascade command (action_id RWC; class_type LX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24178","SQL Server"],"keywords":["24178","event 24178","event id 24178","Issued revoke server object permissions with cascade command (action_id RWC; class_type LX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24178"],"errorCode":"","eventId":"24178","severity":"Medium","summary":"SQL Server Audit event 24178 records: Issued revoke server object permissions with cascade command (action_id RWC; class_type LX)","rootCause":"The configured audit source recorded this activity: Issued revoke server object permissions with cascade command (action_id RWC; class_type LX) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24178.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke server object permissions with cascade command (action_id RWC; class_type LX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24178\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24178} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24178","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24178","Event ID 24178","Issued revoke server object permissions with cascade command (action_id RWC; class_type LX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68889,"title":"SQL Server Audit Event 24179 - Grant database permissions succeeded (action_id G class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24179","SQL Server"],"keywords":["24179","event 24179","event id 24179","Grant database permissions succeeded (action_id G class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24179"],"errorCode":"","eventId":"24179","severity":"Medium","summary":"SQL Server Audit event 24179 records: Grant database permissions succeeded (action_id G class_type DB)","rootCause":"The configured audit source recorded this activity: Grant database permissions succeeded (action_id G class_type DB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24179.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Grant database permissions succeeded (action_id G class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24179\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24179} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24179","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24179","Event ID 24179","Grant database permissions succeeded (action_id G class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68890,"title":"SQL Server Audit Event 24180 - Grant database permissions failed (action_id G class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24180","SQL Server"],"keywords":["24180","event 24180","event id 24180","Grant database permissions failed (action_id G class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24180"],"errorCode":"","eventId":"24180","severity":"High","summary":"SQL Server Audit event 24180 records: Grant database permissions failed (action_id G class_type DB)","rootCause":"The audited operation reported a failure: Grant database permissions failed (action_id G class_type DB) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24180.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Grant database permissions failed (action_id G class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24180\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24180} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24180","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24180","Event ID 24180","Grant database permissions failed (action_id G class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68891,"title":"SQL Server Audit Event 24181 - Grant database permissions with grant succeeded (action_id GWG class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24181","SQL Server"],"keywords":["24181","event 24181","event id 24181","Grant database permissions with grant succeeded (action_id GWG class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24181"],"errorCode":"","eventId":"24181","severity":"Medium","summary":"SQL Server Audit event 24181 records: Grant database permissions with grant succeeded (action_id GWG class_type DB)","rootCause":"The configured audit source recorded this activity: Grant database permissions with grant succeeded (action_id GWG class_type DB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24181.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Grant database permissions with grant succeeded (action_id GWG class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24181\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24181} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24181","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24181","Event ID 24181","Grant database permissions with grant succeeded (action_id GWG class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68892,"title":"SQL Server Audit Event 24182 - Grant database permissions with grant failed (action_id GWG class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24182","SQL Server"],"keywords":["24182","event 24182","event id 24182","Grant database permissions with grant failed (action_id GWG class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24182"],"errorCode":"","eventId":"24182","severity":"High","summary":"SQL Server Audit event 24182 records: Grant database permissions with grant failed (action_id GWG class_type DB)","rootCause":"The audited operation reported a failure: Grant database permissions with grant failed (action_id GWG class_type DB) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24182.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Grant database permissions with grant failed (action_id GWG class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24182\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24182} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24182","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24182","Event ID 24182","Grant database permissions with grant failed (action_id GWG class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68893,"title":"SQL Server Audit Event 24183 - Deny database permissions succeeded (action_id D class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24183","SQL Server"],"keywords":["24183","event 24183","event id 24183","Deny database permissions succeeded (action_id D class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24183"],"errorCode":"","eventId":"24183","severity":"Medium","summary":"SQL Server Audit event 24183 records: Deny database permissions succeeded (action_id D class_type DB)","rootCause":"The configured audit source recorded this activity: Deny database permissions succeeded (action_id D class_type DB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24183.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Deny database permissions succeeded (action_id D class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24183\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24183} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24183","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24183","Event ID 24183","Deny database permissions succeeded (action_id D class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68894,"title":"SQL Server Audit Event 24184 - Deny database permissions failed (action_id D class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24184","SQL Server"],"keywords":["24184","event 24184","event id 24184","Deny database permissions failed (action_id D class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24184"],"errorCode":"","eventId":"24184","severity":"High","summary":"SQL Server Audit event 24184 records: Deny database permissions failed (action_id D class_type DB)","rootCause":"The audited operation reported a failure: Deny database permissions failed (action_id D class_type DB) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24184.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Deny database permissions failed (action_id D class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24184\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24184} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24184","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24184","Event ID 24184","Deny database permissions failed (action_id D class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68895,"title":"SQL Server Audit Event 24185 - Deny database permissions with cascade succeeded (action_id DWC class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24185","SQL Server"],"keywords":["24185","event 24185","event id 24185","Deny database permissions with cascade succeeded (action_id DWC class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24185"],"errorCode":"","eventId":"24185","severity":"Medium","summary":"SQL Server Audit event 24185 records: Deny database permissions with cascade succeeded (action_id DWC class_type DB)","rootCause":"The configured audit source recorded this activity: Deny database permissions with cascade succeeded (action_id DWC class_type DB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24185.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Deny database permissions with cascade succeeded (action_id DWC class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24185\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24185} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24185","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24185","Event ID 24185","Deny database permissions with cascade succeeded (action_id DWC class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68896,"title":"SQL Server Audit Event 24186 - Deny database permissions with cascade failed (action_id DWC class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24186","SQL Server"],"keywords":["24186","event 24186","event id 24186","Deny database permissions with cascade failed (action_id DWC class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24186"],"errorCode":"","eventId":"24186","severity":"High","summary":"SQL Server Audit event 24186 records: Deny database permissions with cascade failed (action_id DWC class_type DB)","rootCause":"The audited operation reported a failure: Deny database permissions with cascade failed (action_id DWC class_type DB) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24186.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Deny database permissions with cascade failed (action_id DWC class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24186\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24186} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24186","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24186","Event ID 24186","Deny database permissions with cascade failed (action_id DWC class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68897,"title":"SQL Server Audit Event 24187 - Revoke database permissions succeeded (action_id R class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24187","SQL Server"],"keywords":["24187","event 24187","event id 24187","Revoke database permissions succeeded (action_id R class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24187"],"errorCode":"","eventId":"24187","severity":"Medium","summary":"SQL Server Audit event 24187 records: Revoke database permissions succeeded (action_id R class_type DB)","rootCause":"The configured audit source recorded this activity: Revoke database permissions succeeded (action_id R class_type DB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24187.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Revoke database permissions succeeded (action_id R class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24187\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24187} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24187","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24187","Event ID 24187","Revoke database permissions succeeded (action_id R class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68898,"title":"SQL Server Audit Event 24188 - Revoke database permissions failed (action_id R class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24188","SQL Server"],"keywords":["24188","event 24188","event id 24188","Revoke database permissions failed (action_id R class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24188"],"errorCode":"","eventId":"24188","severity":"High","summary":"SQL Server Audit event 24188 records: Revoke database permissions failed (action_id R class_type DB)","rootCause":"The audited operation reported a failure: Revoke database permissions failed (action_id R class_type DB) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24188.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Revoke database permissions failed (action_id R class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24188\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24188} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24188","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24188","Event ID 24188","Revoke database permissions failed (action_id R class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68899,"title":"SQL Server Audit Event 24189 - Revoke database permissions with grant succeeded (action_id RWG class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24189","SQL Server"],"keywords":["24189","event 24189","event id 24189","Revoke database permissions with grant succeeded (action_id RWG class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24189"],"errorCode":"","eventId":"24189","severity":"Medium","summary":"SQL Server Audit event 24189 records: Revoke database permissions with grant succeeded (action_id RWG class_type DB)","rootCause":"The configured audit source recorded this activity: Revoke database permissions with grant succeeded (action_id RWG class_type DB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24189.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Revoke database permissions with grant succeeded (action_id RWG class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24189\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24189} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24189","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24189","Event ID 24189","Revoke database permissions with grant succeeded (action_id RWG class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68900,"title":"SQL Server Audit Event 24190 - Revoke database permissions with grant failed (action_id RWG class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24190","SQL Server"],"keywords":["24190","event 24190","event id 24190","Revoke database permissions with grant failed (action_id RWG class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24190"],"errorCode":"","eventId":"24190","severity":"High","summary":"SQL Server Audit event 24190 records: Revoke database permissions with grant failed (action_id RWG class_type DB)","rootCause":"The audited operation reported a failure: Revoke database permissions with grant failed (action_id RWG class_type DB) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24190.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Revoke database permissions with grant failed (action_id RWG class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24190\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24190} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24190","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24190","Event ID 24190","Revoke database permissions with grant failed (action_id RWG class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68901,"title":"SQL Server Audit Event 24191 - Revoke database permissions with cascade succeeded (action_id RWC class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24191","SQL Server"],"keywords":["24191","event 24191","event id 24191","Revoke database permissions with cascade succeeded (action_id RWC class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24191"],"errorCode":"","eventId":"24191","severity":"Medium","summary":"SQL Server Audit event 24191 records: Revoke database permissions with cascade succeeded (action_id RWC class_type DB)","rootCause":"The configured audit source recorded this activity: Revoke database permissions with cascade succeeded (action_id RWC class_type DB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24191.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Revoke database permissions with cascade succeeded (action_id RWC class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24191\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24191} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24191","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24191","Event ID 24191","Revoke database permissions with cascade succeeded (action_id RWC class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68902,"title":"SQL Server Audit Event 24192 - Revoke database permissions with cascade failed (action_id RWC class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24192","SQL Server"],"keywords":["24192","event 24192","event id 24192","Revoke database permissions with cascade failed (action_id RWC class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24192"],"errorCode":"","eventId":"24192","severity":"High","summary":"SQL Server Audit event 24192 records: Revoke database permissions with cascade failed (action_id RWC class_type DB)","rootCause":"The audited operation reported a failure: Revoke database permissions with cascade failed (action_id RWC class_type DB) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24192.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Revoke database permissions with cascade failed (action_id RWC class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24192\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24192} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24192","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24192","Event ID 24192","Revoke database permissions with cascade failed (action_id RWC class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68903,"title":"SQL Server Audit Event 24193 - Issued grant database object permissions command (action_id G class_type US)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24193","SQL Server"],"keywords":["24193","event 24193","event id 24193","Issued grant database object permissions command (action_id G class_type US)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24193"],"errorCode":"","eventId":"24193","severity":"Medium","summary":"SQL Server Audit event 24193 records: Issued grant database object permissions command (action_id G class_type US)","rootCause":"The configured audit source recorded this activity: Issued grant database object permissions command (action_id G class_type US) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24193.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant database object permissions command (action_id G class_type US)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24193\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24193} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24193","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24193","Event ID 24193","Issued grant database object permissions command (action_id G class_type US)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68904,"title":"SQL Server Audit Event 24194 - Issued grant database object permissions with grant command (action_id GWG; class_type US)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24194","SQL Server"],"keywords":["24194","event 24194","event id 24194","Issued grant database object permissions with grant command (action_id GWG; class_type US)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24194"],"errorCode":"","eventId":"24194","severity":"Medium","summary":"SQL Server Audit event 24194 records: Issued grant database object permissions with grant command (action_id GWG; class_type US)","rootCause":"The configured audit source recorded this activity: Issued grant database object permissions with grant command (action_id GWG; class_type US) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24194.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant database object permissions with grant command (action_id GWG; class_type US)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24194\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24194} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24194","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24194","Event ID 24194","Issued grant database object permissions with grant command (action_id GWG; class_type US)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68905,"title":"SQL Server Audit Event 24195 - Issued deny database object permissions command (action_id D; class_type US)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24195","SQL Server"],"keywords":["24195","event 24195","event id 24195","Issued deny database object permissions command (action_id D; class_type US)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24195"],"errorCode":"","eventId":"24195","severity":"Medium","summary":"SQL Server Audit event 24195 records: Issued deny database object permissions command (action_id D; class_type US)","rootCause":"The configured audit source recorded this activity: Issued deny database object permissions command (action_id D; class_type US) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24195.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny database object permissions command (action_id D; class_type US)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24195\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24195} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24195","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24195","Event ID 24195","Issued deny database object permissions command (action_id D; class_type US)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68906,"title":"SQL Server Audit Event 24196 - Issued deny database object permissions with cascade command (action_id DWC; class_type US)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24196","SQL Server"],"keywords":["24196","event 24196","event id 24196","Issued deny database object permissions with cascade command (action_id DWC; class_type US)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24196"],"errorCode":"","eventId":"24196","severity":"Medium","summary":"SQL Server Audit event 24196 records: Issued deny database object permissions with cascade command (action_id DWC; class_type US)","rootCause":"The configured audit source recorded this activity: Issued deny database object permissions with cascade command (action_id DWC; class_type US) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24196.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny database object permissions with cascade command (action_id DWC; class_type US)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24196\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24196} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24196","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24196","Event ID 24196","Issued deny database object permissions with cascade command (action_id DWC; class_type US)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68907,"title":"SQL Server Audit Event 24197 - Issued revoke database object permissions command (action_id R; class_type US)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24197","SQL Server"],"keywords":["24197","event 24197","event id 24197","Issued revoke database object permissions command (action_id R; class_type US)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24197"],"errorCode":"","eventId":"24197","severity":"Medium","summary":"SQL Server Audit event 24197 records: Issued revoke database object permissions command (action_id R; class_type US)","rootCause":"The configured audit source recorded this activity: Issued revoke database object permissions command (action_id R; class_type US) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24197.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke database object permissions command (action_id R; class_type US)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24197\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24197} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24197","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24197","Event ID 24197","Issued revoke database object permissions command (action_id R; class_type US)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68908,"title":"SQL Server Audit Event 24198 - Issued revoke database object permissions with grant command (action_id RWG; class_type US)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24198","SQL Server"],"keywords":["24198","event 24198","event id 24198","Issued revoke database object permissions with grant command (action_id RWG; class_type US)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24198"],"errorCode":"","eventId":"24198","severity":"Medium","summary":"SQL Server Audit event 24198 records: Issued revoke database object permissions with grant command (action_id RWG; class_type US)","rootCause":"The configured audit source recorded this activity: Issued revoke database object permissions with grant command (action_id RWG; class_type US) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24198.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke database object permissions with grant command (action_id RWG; class_type US)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24198\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24198} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24198","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24198","Event ID 24198","Issued revoke database object permissions with grant command (action_id RWG; class_type US)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68909,"title":"SQL Server Audit Event 24199 - Issued revoke database object permissions with cascade command (action_id RWC; class_type US)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24199","SQL Server"],"keywords":["24199","event 24199","event id 24199","Issued revoke database object permissions with cascade command (action_id RWC; class_type US)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24199"],"errorCode":"","eventId":"24199","severity":"Medium","summary":"SQL Server Audit event 24199 records: Issued revoke database object permissions with cascade command (action_id RWC; class_type US)","rootCause":"The configured audit source recorded this activity: Issued revoke database object permissions with cascade command (action_id RWC; class_type US) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24199.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke database object permissions with cascade command (action_id RWC; class_type US)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24199\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24199} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24199","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24199","Event ID 24199","Issued revoke database object permissions with cascade command (action_id RWC; class_type US)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68910,"title":"SQL Server Audit Event 24200 - Issued grant schema permissions command (action_id G class_type SC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24200","SQL Server"],"keywords":["24200","event 24200","event id 24200","Issued grant schema permissions command (action_id G class_type SC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24200"],"errorCode":"","eventId":"24200","severity":"Medium","summary":"SQL Server Audit event 24200 records: Issued grant schema permissions command (action_id G class_type SC)","rootCause":"The configured audit source recorded this activity: Issued grant schema permissions command (action_id G class_type SC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24200.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant schema permissions command (action_id G class_type SC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24200\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24200} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24200","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24200","Event ID 24200","Issued grant schema permissions command (action_id G class_type SC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68911,"title":"SQL Server Audit Event 24201 - Issued grant schema permissions with grant command (action_id GWG class_type SC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24201","SQL Server"],"keywords":["24201","event 24201","event id 24201","Issued grant schema permissions with grant command (action_id GWG class_type SC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24201"],"errorCode":"","eventId":"24201","severity":"Medium","summary":"SQL Server Audit event 24201 records: Issued grant schema permissions with grant command (action_id GWG class_type SC)","rootCause":"The configured audit source recorded this activity: Issued grant schema permissions with grant command (action_id GWG class_type SC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24201.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant schema permissions with grant command (action_id GWG class_type SC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24201\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24201} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24201","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24201","Event ID 24201","Issued grant schema permissions with grant command (action_id GWG class_type SC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68912,"title":"SQL Server Audit Event 24202 - Issued deny schema permissions command (action_id D class_type SC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24202","SQL Server"],"keywords":["24202","event 24202","event id 24202","Issued deny schema permissions command (action_id D class_type SC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24202"],"errorCode":"","eventId":"24202","severity":"Medium","summary":"SQL Server Audit event 24202 records: Issued deny schema permissions command (action_id D class_type SC)","rootCause":"The configured audit source recorded this activity: Issued deny schema permissions command (action_id D class_type SC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24202.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny schema permissions command (action_id D class_type SC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24202\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24202} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24202","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24202","Event ID 24202","Issued deny schema permissions command (action_id D class_type SC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68913,"title":"SQL Server Audit Event 24203 - Issued deny schema permissions with cascade command (action_id DWC class_type SC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24203","SQL Server"],"keywords":["24203","event 24203","event id 24203","Issued deny schema permissions with cascade command (action_id DWC class_type SC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24203"],"errorCode":"","eventId":"24203","severity":"Medium","summary":"SQL Server Audit event 24203 records: Issued deny schema permissions with cascade command (action_id DWC class_type SC)","rootCause":"The configured audit source recorded this activity: Issued deny schema permissions with cascade command (action_id DWC class_type SC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24203.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny schema permissions with cascade command (action_id DWC class_type SC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24203\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24203} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24203","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24203","Event ID 24203","Issued deny schema permissions with cascade command (action_id DWC class_type SC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68914,"title":"SQL Server Audit Event 24204 - Issued revoke schema permissions command (action_id R class_type SC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24204","SQL Server"],"keywords":["24204","event 24204","event id 24204","Issued revoke schema permissions command (action_id R class_type SC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24204"],"errorCode":"","eventId":"24204","severity":"Medium","summary":"SQL Server Audit event 24204 records: Issued revoke schema permissions command (action_id R class_type SC)","rootCause":"The configured audit source recorded this activity: Issued revoke schema permissions command (action_id R class_type SC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24204.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke schema permissions command (action_id R class_type SC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24204\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24204} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24204","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24204","Event ID 24204","Issued revoke schema permissions command (action_id R class_type SC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68915,"title":"SQL Server Audit Event 24205 - Issued revoke schema permissions with grant command (action_id RWG class_type SC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24205","SQL Server"],"keywords":["24205","event 24205","event id 24205","Issued revoke schema permissions with grant command (action_id RWG class_type SC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24205"],"errorCode":"","eventId":"24205","severity":"Medium","summary":"SQL Server Audit event 24205 records: Issued revoke schema permissions with grant command (action_id RWG class_type SC)","rootCause":"The configured audit source recorded this activity: Issued revoke schema permissions with grant command (action_id RWG class_type SC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24205.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke schema permissions with grant command (action_id RWG class_type SC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24205\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24205} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24205","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24205","Event ID 24205","Issued revoke schema permissions with grant command (action_id RWG class_type SC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68916,"title":"SQL Server Audit Event 24206 - Issued revoke schema permissions with cascade command (action_id RWC class_type SC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24206","SQL Server"],"keywords":["24206","event 24206","event id 24206","Issued revoke schema permissions with cascade command (action_id RWC class_type SC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24206"],"errorCode":"","eventId":"24206","severity":"Medium","summary":"SQL Server Audit event 24206 records: Issued revoke schema permissions with cascade command (action_id RWC class_type SC)","rootCause":"The configured audit source recorded this activity: Issued revoke schema permissions with cascade command (action_id RWC class_type SC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24206.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke schema permissions with cascade command (action_id RWC class_type SC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24206\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24206} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24206","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24206","Event ID 24206","Issued revoke schema permissions with cascade command (action_id RWC class_type SC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68917,"title":"SQL Server Audit Event 24207 - Issued grant assembly permissions command (action_id G class_type AS)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24207","SQL Server"],"keywords":["24207","event 24207","event id 24207","Issued grant assembly permissions command (action_id G class_type AS)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24207"],"errorCode":"","eventId":"24207","severity":"Medium","summary":"SQL Server Audit event 24207 records: Issued grant assembly permissions command (action_id G class_type AS)","rootCause":"The configured audit source recorded this activity: Issued grant assembly permissions command (action_id G class_type AS) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24207.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant assembly permissions command (action_id G class_type AS)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24207\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24207} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24207","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24207","Event ID 24207","Issued grant assembly permissions command (action_id G class_type AS)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68918,"title":"SQL Server Audit Event 24208 - Issued grant assembly permissions with grant command (action_id GWG class_type AS)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24208","SQL Server"],"keywords":["24208","event 24208","event id 24208","Issued grant assembly permissions with grant command (action_id GWG class_type AS)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24208"],"errorCode":"","eventId":"24208","severity":"Medium","summary":"SQL Server Audit event 24208 records: Issued grant assembly permissions with grant command (action_id GWG class_type AS)","rootCause":"The configured audit source recorded this activity: Issued grant assembly permissions with grant command (action_id GWG class_type AS) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24208.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant assembly permissions with grant command (action_id GWG class_type AS)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24208\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24208} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24208","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24208","Event ID 24208","Issued grant assembly permissions with grant command (action_id GWG class_type AS)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68919,"title":"SQL Server Audit Event 24209 - Issued deny assembly permissions command (action_id D class_type AS)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24209","SQL Server"],"keywords":["24209","event 24209","event id 24209","Issued deny assembly permissions command (action_id D class_type AS)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24209"],"errorCode":"","eventId":"24209","severity":"Medium","summary":"SQL Server Audit event 24209 records: Issued deny assembly permissions command (action_id D class_type AS)","rootCause":"The configured audit source recorded this activity: Issued deny assembly permissions command (action_id D class_type AS) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24209.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny assembly permissions command (action_id D class_type AS)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24209\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24209} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24209","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24209","Event ID 24209","Issued deny assembly permissions command (action_id D class_type AS)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68920,"title":"SQL Server Audit Event 24210 - Issued deny assembly permissions with cascade command (action_id DWC class_type AS)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24210","SQL Server"],"keywords":["24210","event 24210","event id 24210","Issued deny assembly permissions with cascade command (action_id DWC class_type AS)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24210"],"errorCode":"","eventId":"24210","severity":"Medium","summary":"SQL Server Audit event 24210 records: Issued deny assembly permissions with cascade command (action_id DWC class_type AS)","rootCause":"The configured audit source recorded this activity: Issued deny assembly permissions with cascade command (action_id DWC class_type AS) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24210.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny assembly permissions with cascade command (action_id DWC class_type AS)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24210\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24210} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24210","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24210","Event ID 24210","Issued deny assembly permissions with cascade command (action_id DWC class_type AS)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68921,"title":"SQL Server Audit Event 24211 - Issued revoke assembly permissions command (action_id R class_type AS)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24211","SQL Server"],"keywords":["24211","event 24211","event id 24211","Issued revoke assembly permissions command (action_id R class_type AS)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24211"],"errorCode":"","eventId":"24211","severity":"Medium","summary":"SQL Server Audit event 24211 records: Issued revoke assembly permissions command (action_id R class_type AS)","rootCause":"The configured audit source recorded this activity: Issued revoke assembly permissions command (action_id R class_type AS) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24211.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke assembly permissions command (action_id R class_type AS)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24211\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24211} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24211","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24211","Event ID 24211","Issued revoke assembly permissions command (action_id R class_type AS)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68922,"title":"SQL Server Audit Event 24212 - Issued revoke assembly permissions with grant command (action_id RWG class_type AS)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24212","SQL Server"],"keywords":["24212","event 24212","event id 24212","Issued revoke assembly permissions with grant command (action_id RWG class_type AS)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24212"],"errorCode":"","eventId":"24212","severity":"Medium","summary":"SQL Server Audit event 24212 records: Issued revoke assembly permissions with grant command (action_id RWG class_type AS)","rootCause":"The configured audit source recorded this activity: Issued revoke assembly permissions with grant command (action_id RWG class_type AS) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24212.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke assembly permissions with grant command (action_id RWG class_type AS)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24212\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24212} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24212","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24212","Event ID 24212","Issued revoke assembly permissions with grant command (action_id RWG class_type AS)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68923,"title":"SQL Server Audit Event 24213 - Issued revoke assembly permissions with cascade command (action_id RWC class_type AS)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24213","SQL Server"],"keywords":["24213","event 24213","event id 24213","Issued revoke assembly permissions with cascade command (action_id RWC class_type AS)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24213"],"errorCode":"","eventId":"24213","severity":"Medium","summary":"SQL Server Audit event 24213 records: Issued revoke assembly permissions with cascade command (action_id RWC class_type AS)","rootCause":"The configured audit source recorded this activity: Issued revoke assembly permissions with cascade command (action_id RWC class_type AS) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24213.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke assembly permissions with cascade command (action_id RWC class_type AS)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24213\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24213} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24213","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24213","Event ID 24213","Issued revoke assembly permissions with cascade command (action_id RWC class_type AS)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68924,"title":"SQL Server Audit Event 24214 - Issued grant database role permissions command (action_id G class_type RL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24214","SQL Server"],"keywords":["24214","event 24214","event id 24214","Issued grant database role permissions command (action_id G class_type RL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24214"],"errorCode":"","eventId":"24214","severity":"Medium","summary":"SQL Server Audit event 24214 records: Issued grant database role permissions command (action_id G class_type RL)","rootCause":"The configured audit source recorded this activity: Issued grant database role permissions command (action_id G class_type RL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24214.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant database role permissions command (action_id G class_type RL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24214\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24214} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24214","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24214","Event ID 24214","Issued grant database role permissions command (action_id G class_type RL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68925,"title":"SQL Server Audit Event 24215 - Issued grant database role permissions with grant command (action_id GWG class_type RL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24215","SQL Server"],"keywords":["24215","event 24215","event id 24215","Issued grant database role permissions with grant command (action_id GWG class_type RL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24215"],"errorCode":"","eventId":"24215","severity":"Medium","summary":"SQL Server Audit event 24215 records: Issued grant database role permissions with grant command (action_id GWG class_type RL)","rootCause":"The configured audit source recorded this activity: Issued grant database role permissions with grant command (action_id GWG class_type RL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24215.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant database role permissions with grant command (action_id GWG class_type RL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24215\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24215} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24215","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24215","Event ID 24215","Issued grant database role permissions with grant command (action_id GWG class_type RL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68926,"title":"SQL Server Audit Event 24216 - Issued deny database role permissions command (action_id D class_type RL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24216","SQL Server"],"keywords":["24216","event 24216","event id 24216","Issued deny database role permissions command (action_id D class_type RL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24216"],"errorCode":"","eventId":"24216","severity":"Medium","summary":"SQL Server Audit event 24216 records: Issued deny database role permissions command (action_id D class_type RL)","rootCause":"The configured audit source recorded this activity: Issued deny database role permissions command (action_id D class_type RL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24216.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny database role permissions command (action_id D class_type RL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24216\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24216} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24216","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24216","Event ID 24216","Issued deny database role permissions command (action_id D class_type RL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68927,"title":"SQL Server Audit Event 24217 - Issued deny database role permissions with cascade command (action_id DWC class_type RL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24217","SQL Server"],"keywords":["24217","event 24217","event id 24217","Issued deny database role permissions with cascade command (action_id DWC class_type RL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24217"],"errorCode":"","eventId":"24217","severity":"Medium","summary":"SQL Server Audit event 24217 records: Issued deny database role permissions with cascade command (action_id DWC class_type RL)","rootCause":"The configured audit source recorded this activity: Issued deny database role permissions with cascade command (action_id DWC class_type RL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24217.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny database role permissions with cascade command (action_id DWC class_type RL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24217\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24217} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24217","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24217","Event ID 24217","Issued deny database role permissions with cascade command (action_id DWC class_type RL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68928,"title":"SQL Server Audit Event 24218 - Issued revoke database role permissions command (action_id R class_type RL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24218","SQL Server"],"keywords":["24218","event 24218","event id 24218","Issued revoke database role permissions command (action_id R class_type RL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24218"],"errorCode":"","eventId":"24218","severity":"Medium","summary":"SQL Server Audit event 24218 records: Issued revoke database role permissions command (action_id R class_type RL)","rootCause":"The configured audit source recorded this activity: Issued revoke database role permissions command (action_id R class_type RL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24218.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke database role permissions command (action_id R class_type RL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24218\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24218} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24218","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24218","Event ID 24218","Issued revoke database role permissions command (action_id R class_type RL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68929,"title":"SQL Server Audit Event 24219 - Issued revoke database role permissions with grant command (action_id RWG class_type RL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24219","SQL Server"],"keywords":["24219","event 24219","event id 24219","Issued revoke database role permissions with grant command (action_id RWG class_type RL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24219"],"errorCode":"","eventId":"24219","severity":"Medium","summary":"SQL Server Audit event 24219 records: Issued revoke database role permissions with grant command (action_id RWG class_type RL)","rootCause":"The configured audit source recorded this activity: Issued revoke database role permissions with grant command (action_id RWG class_type RL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24219.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke database role permissions with grant command (action_id RWG class_type RL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24219\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24219} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24219","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24219","Event ID 24219","Issued revoke database role permissions with grant command (action_id RWG class_type RL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68930,"title":"SQL Server Audit Event 24220 - Issued revoke database role permissions with cascade command (action_id RWC class_type RL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24220","SQL Server"],"keywords":["24220","event 24220","event id 24220","Issued revoke database role permissions with cascade command (action_id RWC class_type RL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24220"],"errorCode":"","eventId":"24220","severity":"Medium","summary":"SQL Server Audit event 24220 records: Issued revoke database role permissions with cascade command (action_id RWC class_type RL)","rootCause":"The configured audit source recorded this activity: Issued revoke database role permissions with cascade command (action_id RWC class_type RL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24220.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke database role permissions with cascade command (action_id RWC class_type RL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24220\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24220} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24220","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24220","Event ID 24220","Issued revoke database role permissions with cascade command (action_id RWC class_type RL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68931,"title":"SQL Server Audit Event 24221 - Issued grant application role permissions command (action_id G class_type AR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24221","SQL Server"],"keywords":["24221","event 24221","event id 24221","Issued grant application role permissions command (action_id G class_type AR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24221"],"errorCode":"","eventId":"24221","severity":"Medium","summary":"SQL Server Audit event 24221 records: Issued grant application role permissions command (action_id G class_type AR)","rootCause":"The configured audit source recorded this activity: Issued grant application role permissions command (action_id G class_type AR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24221.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant application role permissions command (action_id G class_type AR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24221\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24221} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24221","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24221","Event ID 24221","Issued grant application role permissions command (action_id G class_type AR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68932,"title":"SQL Server Audit Event 24222 - Issued grant application role permissions with grant command (action_id GWG class_type AR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24222","SQL Server"],"keywords":["24222","event 24222","event id 24222","Issued grant application role permissions with grant command (action_id GWG class_type AR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24222"],"errorCode":"","eventId":"24222","severity":"Medium","summary":"SQL Server Audit event 24222 records: Issued grant application role permissions with grant command (action_id GWG class_type AR)","rootCause":"The configured audit source recorded this activity: Issued grant application role permissions with grant command (action_id GWG class_type AR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24222.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant application role permissions with grant command (action_id GWG class_type AR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24222\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24222} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24222","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24222","Event ID 24222","Issued grant application role permissions with grant command (action_id GWG class_type AR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68933,"title":"SQL Server Audit Event 24223 - Issued deny application role permissions command (action_id D class_type AR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24223","SQL Server"],"keywords":["24223","event 24223","event id 24223","Issued deny application role permissions command (action_id D class_type AR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24223"],"errorCode":"","eventId":"24223","severity":"Medium","summary":"SQL Server Audit event 24223 records: Issued deny application role permissions command (action_id D class_type AR)","rootCause":"The configured audit source recorded this activity: Issued deny application role permissions command (action_id D class_type AR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24223.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny application role permissions command (action_id D class_type AR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24223\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24223} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24223","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24223","Event ID 24223","Issued deny application role permissions command (action_id D class_type AR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68934,"title":"SQL Server Audit Event 24224 - Issued deny application role permissions with cascade command (action_id DWC class_type AR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24224","SQL Server"],"keywords":["24224","event 24224","event id 24224","Issued deny application role permissions with cascade command (action_id DWC class_type AR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24224"],"errorCode":"","eventId":"24224","severity":"Medium","summary":"SQL Server Audit event 24224 records: Issued deny application role permissions with cascade command (action_id DWC class_type AR)","rootCause":"The configured audit source recorded this activity: Issued deny application role permissions with cascade command (action_id DWC class_type AR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24224.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny application role permissions with cascade command (action_id DWC class_type AR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24224\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24224} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24224","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24224","Event ID 24224","Issued deny application role permissions with cascade command (action_id DWC class_type AR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68935,"title":"SQL Server Audit Event 24225 - Issued revoke application role permissions command (action_id R class_type AR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24225","SQL Server"],"keywords":["24225","event 24225","event id 24225","Issued revoke application role permissions command (action_id R class_type AR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24225"],"errorCode":"","eventId":"24225","severity":"Medium","summary":"SQL Server Audit event 24225 records: Issued revoke application role permissions command (action_id R class_type AR)","rootCause":"The configured audit source recorded this activity: Issued revoke application role permissions command (action_id R class_type AR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24225.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke application role permissions command (action_id R class_type AR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24225\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24225} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24225","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24225","Event ID 24225","Issued revoke application role permissions command (action_id R class_type AR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68936,"title":"SQL Server Audit Event 24226 - Issued revoke application role permissions with grant command (action_id RWG class_type AR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24226","SQL Server"],"keywords":["24226","event 24226","event id 24226","Issued revoke application role permissions with grant command (action_id RWG class_type AR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24226"],"errorCode":"","eventId":"24226","severity":"Medium","summary":"SQL Server Audit event 24226 records: Issued revoke application role permissions with grant command (action_id RWG class_type AR)","rootCause":"The configured audit source recorded this activity: Issued revoke application role permissions with grant command (action_id RWG class_type AR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24226.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke application role permissions with grant command (action_id RWG class_type AR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24226\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24226} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24226","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24226","Event ID 24226","Issued revoke application role permissions with grant command (action_id RWG class_type AR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68937,"title":"SQL Server Audit Event 24227 - Issued revoke application role permissions with cascade command (action_id RWC class_type AR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24227","SQL Server"],"keywords":["24227","event 24227","event id 24227","Issued revoke application role permissions with cascade command (action_id RWC class_type AR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24227"],"errorCode":"","eventId":"24227","severity":"Medium","summary":"SQL Server Audit event 24227 records: Issued revoke application role permissions with cascade command (action_id RWC class_type AR)","rootCause":"The configured audit source recorded this activity: Issued revoke application role permissions with cascade command (action_id RWC class_type AR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24227.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke application role permissions with cascade command (action_id RWC class_type AR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24227\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24227} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24227","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24227","Event ID 24227","Issued revoke application role permissions with cascade command (action_id RWC class_type AR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68938,"title":"SQL Server Audit Event 24228 - Issued grant symmetric key permissions command (action_id G class_type SK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24228","SQL Server"],"keywords":["24228","event 24228","event id 24228","Issued grant symmetric key permissions command (action_id G class_type SK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24228"],"errorCode":"","eventId":"24228","severity":"Medium","summary":"SQL Server Audit event 24228 records: Issued grant symmetric key permissions command (action_id G class_type SK)","rootCause":"The configured audit source recorded this activity: Issued grant symmetric key permissions command (action_id G class_type SK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24228.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant symmetric key permissions command (action_id G class_type SK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24228\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24228} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24228","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24228","Event ID 24228","Issued grant symmetric key permissions command (action_id G class_type SK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68939,"title":"SQL Server Audit Event 24229 - Issued grant symmetric key permissions with grant command (action_id GWG class_type SK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24229","SQL Server"],"keywords":["24229","event 24229","event id 24229","Issued grant symmetric key permissions with grant command (action_id GWG class_type SK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24229"],"errorCode":"","eventId":"24229","severity":"Medium","summary":"SQL Server Audit event 24229 records: Issued grant symmetric key permissions with grant command (action_id GWG class_type SK)","rootCause":"The configured audit source recorded this activity: Issued grant symmetric key permissions with grant command (action_id GWG class_type SK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24229.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant symmetric key permissions with grant command (action_id GWG class_type SK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24229\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24229} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24229","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24229","Event ID 24229","Issued grant symmetric key permissions with grant command (action_id GWG class_type SK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68940,"title":"SQL Server Audit Event 24230 - Issued deny symmetric key permissions command (action_id D class_type SK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24230","SQL Server"],"keywords":["24230","event 24230","event id 24230","Issued deny symmetric key permissions command (action_id D class_type SK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24230"],"errorCode":"","eventId":"24230","severity":"Medium","summary":"SQL Server Audit event 24230 records: Issued deny symmetric key permissions command (action_id D class_type SK)","rootCause":"The configured audit source recorded this activity: Issued deny symmetric key permissions command (action_id D class_type SK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24230.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny symmetric key permissions command (action_id D class_type SK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24230\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24230} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24230","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24230","Event ID 24230","Issued deny symmetric key permissions command (action_id D class_type SK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68941,"title":"SQL Server Audit Event 24231 - Issued deny symmetric key permissions with cascade command (action_id DWC class_type SK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24231","SQL Server"],"keywords":["24231","event 24231","event id 24231","Issued deny symmetric key permissions with cascade command (action_id DWC class_type SK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24231"],"errorCode":"","eventId":"24231","severity":"Medium","summary":"SQL Server Audit event 24231 records: Issued deny symmetric key permissions with cascade command (action_id DWC class_type SK)","rootCause":"The configured audit source recorded this activity: Issued deny symmetric key permissions with cascade command (action_id DWC class_type SK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24231.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny symmetric key permissions with cascade command (action_id DWC class_type SK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24231\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24231} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24231","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24231","Event ID 24231","Issued deny symmetric key permissions with cascade command (action_id DWC class_type SK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68942,"title":"SQL Server Audit Event 24232 - Issued revoke symmetric key permissions command (action_id R class_type SK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24232","SQL Server"],"keywords":["24232","event 24232","event id 24232","Issued revoke symmetric key permissions command (action_id R class_type SK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24232"],"errorCode":"","eventId":"24232","severity":"Medium","summary":"SQL Server Audit event 24232 records: Issued revoke symmetric key permissions command (action_id R class_type SK)","rootCause":"The configured audit source recorded this activity: Issued revoke symmetric key permissions command (action_id R class_type SK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24232.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke symmetric key permissions command (action_id R class_type SK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24232\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24232} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24232","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24232","Event ID 24232","Issued revoke symmetric key permissions command (action_id R class_type SK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68943,"title":"SQL Server Audit Event 24233 - Issued revoke symmetric key permissions with grant command (action_id RWG class_type SK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24233","SQL Server"],"keywords":["24233","event 24233","event id 24233","Issued revoke symmetric key permissions with grant command (action_id RWG class_type SK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24233"],"errorCode":"","eventId":"24233","severity":"Medium","summary":"SQL Server Audit event 24233 records: Issued revoke symmetric key permissions with grant command (action_id RWG class_type SK)","rootCause":"The configured audit source recorded this activity: Issued revoke symmetric key permissions with grant command (action_id RWG class_type SK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24233.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke symmetric key permissions with grant command (action_id RWG class_type SK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24233\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24233} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24233","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24233","Event ID 24233","Issued revoke symmetric key permissions with grant command (action_id RWG class_type SK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68944,"title":"SQL Server Audit Event 24234 - Issued revoke symmetric key permissions with cascade command (action_id RWC class_type SK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24234","SQL Server"],"keywords":["24234","event 24234","event id 24234","Issued revoke symmetric key permissions with cascade command (action_id RWC class_type SK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24234"],"errorCode":"","eventId":"24234","severity":"Medium","summary":"SQL Server Audit event 24234 records: Issued revoke symmetric key permissions with cascade command (action_id RWC class_type SK)","rootCause":"The configured audit source recorded this activity: Issued revoke symmetric key permissions with cascade command (action_id RWC class_type SK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24234.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke symmetric key permissions with cascade command (action_id RWC class_type SK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24234\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24234} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24234","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24234","Event ID 24234","Issued revoke symmetric key permissions with cascade command (action_id RWC class_type SK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68945,"title":"SQL Server Audit Event 24235 - Issued grant certificate permissions command (action_id G class_type CR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24235","SQL Server"],"keywords":["24235","event 24235","event id 24235","Issued grant certificate permissions command (action_id G class_type CR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24235"],"errorCode":"","eventId":"24235","severity":"Medium","summary":"SQL Server Audit event 24235 records: Issued grant certificate permissions command (action_id G class_type CR)","rootCause":"The configured audit source recorded this activity: Issued grant certificate permissions command (action_id G class_type CR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24235.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant certificate permissions command (action_id G class_type CR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24235\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24235} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24235","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24235","Event ID 24235","Issued grant certificate permissions command (action_id G class_type CR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68946,"title":"SQL Server Audit Event 24236 - Issued grant certificate permissions with grant command (action_id GWG class_type CR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24236","SQL Server"],"keywords":["24236","event 24236","event id 24236","Issued grant certificate permissions with grant command (action_id GWG class_type CR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24236"],"errorCode":"","eventId":"24236","severity":"Medium","summary":"SQL Server Audit event 24236 records: Issued grant certificate permissions with grant command (action_id GWG class_type CR)","rootCause":"The configured audit source recorded this activity: Issued grant certificate permissions with grant command (action_id GWG class_type CR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24236.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant certificate permissions with grant command (action_id GWG class_type CR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24236\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24236} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24236","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24236","Event ID 24236","Issued grant certificate permissions with grant command (action_id GWG class_type CR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68947,"title":"SQL Server Audit Event 24237 - Issued deny certificate permissions command (action_id D class_type CR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24237","SQL Server"],"keywords":["24237","event 24237","event id 24237","Issued deny certificate permissions command (action_id D class_type CR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24237"],"errorCode":"","eventId":"24237","severity":"Medium","summary":"SQL Server Audit event 24237 records: Issued deny certificate permissions command (action_id D class_type CR)","rootCause":"The configured audit source recorded this activity: Issued deny certificate permissions command (action_id D class_type CR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24237.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny certificate permissions command (action_id D class_type CR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24237\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24237} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24237","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24237","Event ID 24237","Issued deny certificate permissions command (action_id D class_type CR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68948,"title":"SQL Server Audit Event 24238 - Issued deny certificate permissions with cascade command (action_id DWC class_type CR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24238","SQL Server"],"keywords":["24238","event 24238","event id 24238","Issued deny certificate permissions with cascade command (action_id DWC class_type CR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24238"],"errorCode":"","eventId":"24238","severity":"Medium","summary":"SQL Server Audit event 24238 records: Issued deny certificate permissions with cascade command (action_id DWC class_type CR)","rootCause":"The configured audit source recorded this activity: Issued deny certificate permissions with cascade command (action_id DWC class_type CR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24238.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny certificate permissions with cascade command (action_id DWC class_type CR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24238\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24238} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24238","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24238","Event ID 24238","Issued deny certificate permissions with cascade command (action_id DWC class_type CR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68949,"title":"SQL Server Audit Event 24239 - Issued revoke certificate permissions command (action_id R class_type CR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24239","SQL Server"],"keywords":["24239","event 24239","event id 24239","Issued revoke certificate permissions command (action_id R class_type CR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24239"],"errorCode":"","eventId":"24239","severity":"Medium","summary":"SQL Server Audit event 24239 records: Issued revoke certificate permissions command (action_id R class_type CR)","rootCause":"The configured audit source recorded this activity: Issued revoke certificate permissions command (action_id R class_type CR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24239.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke certificate permissions command (action_id R class_type CR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24239\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24239} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24239","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24239","Event ID 24239","Issued revoke certificate permissions command (action_id R class_type CR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68950,"title":"SQL Server Audit Event 24240 - Issued revoke certificate permissions with grant command (action_id RWG class_type CR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24240","SQL Server"],"keywords":["24240","event 24240","event id 24240","Issued revoke certificate permissions with grant command (action_id RWG class_type CR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24240"],"errorCode":"","eventId":"24240","severity":"Medium","summary":"SQL Server Audit event 24240 records: Issued revoke certificate permissions with grant command (action_id RWG class_type CR)","rootCause":"The configured audit source recorded this activity: Issued revoke certificate permissions with grant command (action_id RWG class_type CR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24240.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke certificate permissions with grant command (action_id RWG class_type CR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24240\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24240} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24240","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24240","Event ID 24240","Issued revoke certificate permissions with grant command (action_id RWG class_type CR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68951,"title":"SQL Server Audit Event 24241 - Issued revoke certificate permissions with cascade command (action_id RWC class_type CR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24241","SQL Server"],"keywords":["24241","event 24241","event id 24241","Issued revoke certificate permissions with cascade command (action_id RWC class_type CR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24241"],"errorCode":"","eventId":"24241","severity":"Medium","summary":"SQL Server Audit event 24241 records: Issued revoke certificate permissions with cascade command (action_id RWC class_type CR)","rootCause":"The configured audit source recorded this activity: Issued revoke certificate permissions with cascade command (action_id RWC class_type CR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24241.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke certificate permissions with cascade command (action_id RWC class_type CR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24241\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24241} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24241","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24241","Event ID 24241","Issued revoke certificate permissions with cascade command (action_id RWC class_type CR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68952,"title":"SQL Server Audit Event 24242 - Issued grant asymmetric key permissions command (action_id G class_type AK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24242","SQL Server"],"keywords":["24242","event 24242","event id 24242","Issued grant asymmetric key permissions command (action_id G class_type AK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24242"],"errorCode":"","eventId":"24242","severity":"Medium","summary":"SQL Server Audit event 24242 records: Issued grant asymmetric key permissions command (action_id G class_type AK)","rootCause":"The configured audit source recorded this activity: Issued grant asymmetric key permissions command (action_id G class_type AK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24242.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant asymmetric key permissions command (action_id G class_type AK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24242\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24242} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24242","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24242","Event ID 24242","Issued grant asymmetric key permissions command (action_id G class_type AK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68953,"title":"SQL Server Audit Event 24243 - Issued grant asymmetric key permissions with grant command (action_id GWG class_type AK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24243","SQL Server"],"keywords":["24243","event 24243","event id 24243","Issued grant asymmetric key permissions with grant command (action_id GWG class_type AK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24243"],"errorCode":"","eventId":"24243","severity":"Medium","summary":"SQL Server Audit event 24243 records: Issued grant asymmetric key permissions with grant command (action_id GWG class_type AK)","rootCause":"The configured audit source recorded this activity: Issued grant asymmetric key permissions with grant command (action_id GWG class_type AK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24243.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant asymmetric key permissions with grant command (action_id GWG class_type AK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24243\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24243} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24243","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24243","Event ID 24243","Issued grant asymmetric key permissions with grant command (action_id GWG class_type AK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68954,"title":"SQL Server Audit Event 24244 - Issued deny asymmetric key permissions command (action_id D class_type AK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24244","SQL Server"],"keywords":["24244","event 24244","event id 24244","Issued deny asymmetric key permissions command (action_id D class_type AK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24244"],"errorCode":"","eventId":"24244","severity":"Medium","summary":"SQL Server Audit event 24244 records: Issued deny asymmetric key permissions command (action_id D class_type AK)","rootCause":"The configured audit source recorded this activity: Issued deny asymmetric key permissions command (action_id D class_type AK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24244.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny asymmetric key permissions command (action_id D class_type AK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24244\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24244} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24244","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24244","Event ID 24244","Issued deny asymmetric key permissions command (action_id D class_type AK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68955,"title":"SQL Server Audit Event 24245 - Issued deny asymmetric key permissions with cascade command (action_id DWC class_type AK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24245","SQL Server"],"keywords":["24245","event 24245","event id 24245","Issued deny asymmetric key permissions with cascade command (action_id DWC class_type AK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24245"],"errorCode":"","eventId":"24245","severity":"Medium","summary":"SQL Server Audit event 24245 records: Issued deny asymmetric key permissions with cascade command (action_id DWC class_type AK)","rootCause":"The configured audit source recorded this activity: Issued deny asymmetric key permissions with cascade command (action_id DWC class_type AK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24245.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny asymmetric key permissions with cascade command (action_id DWC class_type AK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24245\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24245} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24245","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24245","Event ID 24245","Issued deny asymmetric key permissions with cascade command (action_id DWC class_type AK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68956,"title":"SQL Server Audit Event 24246 - Issued revoke asymmetric key permissions command (action_id R class_type AK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24246","SQL Server"],"keywords":["24246","event 24246","event id 24246","Issued revoke asymmetric key permissions command (action_id R class_type AK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24246"],"errorCode":"","eventId":"24246","severity":"Medium","summary":"SQL Server Audit event 24246 records: Issued revoke asymmetric key permissions command (action_id R class_type AK)","rootCause":"The configured audit source recorded this activity: Issued revoke asymmetric key permissions command (action_id R class_type AK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24246.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke asymmetric key permissions command (action_id R class_type AK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24246\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24246} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24246","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24246","Event ID 24246","Issued revoke asymmetric key permissions command (action_id R class_type AK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68957,"title":"SQL Server Audit Event 24247 - Issued revoke asymmetric key permissions with grant command (action_id RWG class_type AK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24247","SQL Server"],"keywords":["24247","event 24247","event id 24247","Issued revoke asymmetric key permissions with grant command (action_id RWG class_type AK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24247"],"errorCode":"","eventId":"24247","severity":"Medium","summary":"SQL Server Audit event 24247 records: Issued revoke asymmetric key permissions with grant command (action_id RWG class_type AK)","rootCause":"The configured audit source recorded this activity: Issued revoke asymmetric key permissions with grant command (action_id RWG class_type AK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24247.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke asymmetric key permissions with grant command (action_id RWG class_type AK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24247\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24247} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24247","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24247","Event ID 24247","Issued revoke asymmetric key permissions with grant command (action_id RWG class_type AK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68958,"title":"SQL Server Audit Event 24248 - Issued revoke asymmetric key permissions with cascade command (action_id RWC class_type AK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24248","SQL Server"],"keywords":["24248","event 24248","event id 24248","Issued revoke asymmetric key permissions with cascade command (action_id RWC class_type AK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24248"],"errorCode":"","eventId":"24248","severity":"Medium","summary":"SQL Server Audit event 24248 records: Issued revoke asymmetric key permissions with cascade command (action_id RWC class_type AK)","rootCause":"The configured audit source recorded this activity: Issued revoke asymmetric key permissions with cascade command (action_id RWC class_type AK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24248.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke asymmetric key permissions with cascade command (action_id RWC class_type AK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24248\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24248} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24248","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24248","Event ID 24248","Issued revoke asymmetric key permissions with cascade command (action_id RWC class_type AK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68959,"title":"SQL Server Audit Event 24249 - Issued grant schema object permissions command (action_id G class_type OB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24249","SQL Server"],"keywords":["24249","event 24249","event id 24249","Issued grant schema object permissions command (action_id G class_type OB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24249"],"errorCode":"","eventId":"24249","severity":"Medium","summary":"SQL Server Audit event 24249 records: Issued grant schema object permissions command (action_id G class_type OB)","rootCause":"The configured audit source recorded this activity: Issued grant schema object permissions command (action_id G class_type OB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24249.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant schema object permissions command (action_id G class_type OB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24249\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24249} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24249","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24249","Event ID 24249","Issued grant schema object permissions command (action_id G class_type OB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68960,"title":"SQL Server Audit Event 24250 - Issued grant schema object permissions with grant command (action_id GWG class_type OB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24250","SQL Server"],"keywords":["24250","event 24250","event id 24250","Issued grant schema object permissions with grant command (action_id GWG class_type OB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24250"],"errorCode":"","eventId":"24250","severity":"Medium","summary":"SQL Server Audit event 24250 records: Issued grant schema object permissions with grant command (action_id GWG class_type OB)","rootCause":"The configured audit source recorded this activity: Issued grant schema object permissions with grant command (action_id GWG class_type OB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24250.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant schema object permissions with grant command (action_id GWG class_type OB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24250\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24250} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24250","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24250","Event ID 24250","Issued grant schema object permissions with grant command (action_id GWG class_type OB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68961,"title":"SQL Server Audit Event 24251 - Issued deny schema object permissions command (action_id D class_type OB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24251","SQL Server"],"keywords":["24251","event 24251","event id 24251","Issued deny schema object permissions command (action_id D class_type OB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24251"],"errorCode":"","eventId":"24251","severity":"Medium","summary":"SQL Server Audit event 24251 records: Issued deny schema object permissions command (action_id D class_type OB)","rootCause":"The configured audit source recorded this activity: Issued deny schema object permissions command (action_id D class_type OB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24251.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny schema object permissions command (action_id D class_type OB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24251\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24251} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24251","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24251","Event ID 24251","Issued deny schema object permissions command (action_id D class_type OB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68962,"title":"SQL Server Audit Event 24252 - Issued deny schema object permissions with cascade command (action_id DWC class_type OB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24252","SQL Server"],"keywords":["24252","event 24252","event id 24252","Issued deny schema object permissions with cascade command (action_id DWC class_type OB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24252"],"errorCode":"","eventId":"24252","severity":"Medium","summary":"SQL Server Audit event 24252 records: Issued deny schema object permissions with cascade command (action_id DWC class_type OB)","rootCause":"The configured audit source recorded this activity: Issued deny schema object permissions with cascade command (action_id DWC class_type OB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24252.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny schema object permissions with cascade command (action_id DWC class_type OB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24252\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24252} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24252","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24252","Event ID 24252","Issued deny schema object permissions with cascade command (action_id DWC class_type OB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68963,"title":"SQL Server Audit Event 24253 - Issued revoke schema object permissions command (action_id R class_type OB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24253","SQL Server"],"keywords":["24253","event 24253","event id 24253","Issued revoke schema object permissions command (action_id R class_type OB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24253"],"errorCode":"","eventId":"24253","severity":"Medium","summary":"SQL Server Audit event 24253 records: Issued revoke schema object permissions command (action_id R class_type OB)","rootCause":"The configured audit source recorded this activity: Issued revoke schema object permissions command (action_id R class_type OB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24253.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke schema object permissions command (action_id R class_type OB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24253\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24253} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24253","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24253","Event ID 24253","Issued revoke schema object permissions command (action_id R class_type OB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68964,"title":"SQL Server Audit Event 24254 - Issued revoke schema object permissions with grant command (action_id RWG class_type OB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24254","SQL Server"],"keywords":["24254","event 24254","event id 24254","Issued revoke schema object permissions with grant command (action_id RWG class_type OB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24254"],"errorCode":"","eventId":"24254","severity":"Medium","summary":"SQL Server Audit event 24254 records: Issued revoke schema object permissions with grant command (action_id RWG class_type OB)","rootCause":"The configured audit source recorded this activity: Issued revoke schema object permissions with grant command (action_id RWG class_type OB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24254.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke schema object permissions with grant command (action_id RWG class_type OB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24254\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24254} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24254","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24254","Event ID 24254","Issued revoke schema object permissions with grant command (action_id RWG class_type OB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68965,"title":"SQL Server Audit Event 24255 - Issued revoke schema object permissions with cascade command (action_id RWC class_type OB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24255","SQL Server"],"keywords":["24255","event 24255","event id 24255","Issued revoke schema object permissions with cascade command (action_id RWC class_type OB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24255"],"errorCode":"","eventId":"24255","severity":"Medium","summary":"SQL Server Audit event 24255 records: Issued revoke schema object permissions with cascade command (action_id RWC class_type OB)","rootCause":"The configured audit source recorded this activity: Issued revoke schema object permissions with cascade command (action_id RWC class_type OB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24255.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke schema object permissions with cascade command (action_id RWC class_type OB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24255\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24255} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24255","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24255","Event ID 24255","Issued revoke schema object permissions with cascade command (action_id RWC class_type OB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68966,"title":"SQL Server Audit Event 24256 - Issued grant schema type permissions command (action_id G class_type TY)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24256","SQL Server"],"keywords":["24256","event 24256","event id 24256","Issued grant schema type permissions command (action_id G class_type TY)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24256"],"errorCode":"","eventId":"24256","severity":"Medium","summary":"SQL Server Audit event 24256 records: Issued grant schema type permissions command (action_id G class_type TY)","rootCause":"The configured audit source recorded this activity: Issued grant schema type permissions command (action_id G class_type TY) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24256.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant schema type permissions command (action_id G class_type TY)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24256\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24256} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24256","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24256","Event ID 24256","Issued grant schema type permissions command (action_id G class_type TY)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68967,"title":"SQL Server Audit Event 24257 - Issued grant schema type permissions with grant command (action_id GWG class_type TY)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24257","SQL Server"],"keywords":["24257","event 24257","event id 24257","Issued grant schema type permissions with grant command (action_id GWG class_type TY)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24257"],"errorCode":"","eventId":"24257","severity":"Medium","summary":"SQL Server Audit event 24257 records: Issued grant schema type permissions with grant command (action_id GWG class_type TY)","rootCause":"The configured audit source recorded this activity: Issued grant schema type permissions with grant command (action_id GWG class_type TY) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24257.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant schema type permissions with grant command (action_id GWG class_type TY)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24257\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24257} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24257","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24257","Event ID 24257","Issued grant schema type permissions with grant command (action_id GWG class_type TY)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68968,"title":"SQL Server Audit Event 24258 - Issued deny schema type permissions command (action_id D class_type TY)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24258","SQL Server"],"keywords":["24258","event 24258","event id 24258","Issued deny schema type permissions command (action_id D class_type TY)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24258"],"errorCode":"","eventId":"24258","severity":"Medium","summary":"SQL Server Audit event 24258 records: Issued deny schema type permissions command (action_id D class_type TY)","rootCause":"The configured audit source recorded this activity: Issued deny schema type permissions command (action_id D class_type TY) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24258.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny schema type permissions command (action_id D class_type TY)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24258\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24258} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24258","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24258","Event ID 24258","Issued deny schema type permissions command (action_id D class_type TY)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68969,"title":"SQL Server Audit Event 24259 - Issued deny schema type permissions with cascade command (action_id DWC class_type TY)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24259","SQL Server"],"keywords":["24259","event 24259","event id 24259","Issued deny schema type permissions with cascade command (action_id DWC class_type TY)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24259"],"errorCode":"","eventId":"24259","severity":"Medium","summary":"SQL Server Audit event 24259 records: Issued deny schema type permissions with cascade command (action_id DWC class_type TY)","rootCause":"The configured audit source recorded this activity: Issued deny schema type permissions with cascade command (action_id DWC class_type TY) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24259.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny schema type permissions with cascade command (action_id DWC class_type TY)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24259\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24259} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24259","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24259","Event ID 24259","Issued deny schema type permissions with cascade command (action_id DWC class_type TY)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68970,"title":"SQL Server Audit Event 24260 - Issued revoke schema type permissions command (action_id R class_type TY)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24260","SQL Server"],"keywords":["24260","event 24260","event id 24260","Issued revoke schema type permissions command (action_id R class_type TY)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24260"],"errorCode":"","eventId":"24260","severity":"Medium","summary":"SQL Server Audit event 24260 records: Issued revoke schema type permissions command (action_id R class_type TY)","rootCause":"The configured audit source recorded this activity: Issued revoke schema type permissions command (action_id R class_type TY) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24260.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke schema type permissions command (action_id R class_type TY)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24260\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24260} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24260","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24260","Event ID 24260","Issued revoke schema type permissions command (action_id R class_type TY)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68971,"title":"SQL Server Audit Event 24261 - Issued revoke schema type permissions with grant command (action_id RWG class_type TY)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24261","SQL Server"],"keywords":["24261","event 24261","event id 24261","Issued revoke schema type permissions with grant command (action_id RWG class_type TY)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24261"],"errorCode":"","eventId":"24261","severity":"Medium","summary":"SQL Server Audit event 24261 records: Issued revoke schema type permissions with grant command (action_id RWG class_type TY)","rootCause":"The configured audit source recorded this activity: Issued revoke schema type permissions with grant command (action_id RWG class_type TY) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24261.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke schema type permissions with grant command (action_id RWG class_type TY)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24261\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24261} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24261","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24261","Event ID 24261","Issued revoke schema type permissions with grant command (action_id RWG class_type TY)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68972,"title":"SQL Server Audit Event 24262 - Issued revoke schema type permissions with cascade command (action_id RWC class_type TY)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24262","SQL Server"],"keywords":["24262","event 24262","event id 24262","Issued revoke schema type permissions with cascade command (action_id RWC class_type TY)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24262"],"errorCode":"","eventId":"24262","severity":"Medium","summary":"SQL Server Audit event 24262 records: Issued revoke schema type permissions with cascade command (action_id RWC class_type TY)","rootCause":"The configured audit source recorded this activity: Issued revoke schema type permissions with cascade command (action_id RWC class_type TY) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24262.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke schema type permissions with cascade command (action_id RWC class_type TY)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24262\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24262} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24262","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24262","Event ID 24262","Issued revoke schema type permissions with cascade command (action_id RWC class_type TY)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68973,"title":"SQL Server Audit Event 24263 - Issued grant XML schema collection permissions command (action_id G class_type SX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24263","SQL Server"],"keywords":["24263","event 24263","event id 24263","Issued grant XML schema collection permissions command (action_id G class_type SX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24263"],"errorCode":"","eventId":"24263","severity":"Medium","summary":"SQL Server Audit event 24263 records: Issued grant XML schema collection permissions command (action_id G class_type SX)","rootCause":"The configured audit source recorded this activity: Issued grant XML schema collection permissions command (action_id G class_type SX) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24263.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant XML schema collection permissions command (action_id G class_type SX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24263\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24263} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24263","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24263","Event ID 24263","Issued grant XML schema collection permissions command (action_id G class_type SX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68974,"title":"SQL Server Audit Event 24264 - Issued grant XML schema collection permissions with grant command (action_id GWG class_type SX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24264","SQL Server"],"keywords":["24264","event 24264","event id 24264","Issued grant XML schema collection permissions with grant command (action_id GWG class_type SX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24264"],"errorCode":"","eventId":"24264","severity":"Medium","summary":"SQL Server Audit event 24264 records: Issued grant XML schema collection permissions with grant command (action_id GWG class_type SX)","rootCause":"The configured audit source recorded this activity: Issued grant XML schema collection permissions with grant command (action_id GWG class_type SX) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24264.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant XML schema collection permissions with grant command (action_id GWG class_type SX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24264\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24264} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24264","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24264","Event ID 24264","Issued grant XML schema collection permissions with grant command (action_id GWG class_type SX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68975,"title":"SQL Server Audit Event 24265 - Issued deny XML schema collection permissions command (action_id D class_type SX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24265","SQL Server"],"keywords":["24265","event 24265","event id 24265","Issued deny XML schema collection permissions command (action_id D class_type SX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24265"],"errorCode":"","eventId":"24265","severity":"Medium","summary":"SQL Server Audit event 24265 records: Issued deny XML schema collection permissions command (action_id D class_type SX)","rootCause":"The configured audit source recorded this activity: Issued deny XML schema collection permissions command (action_id D class_type SX) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24265.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny XML schema collection permissions command (action_id D class_type SX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24265\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24265} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24265","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24265","Event ID 24265","Issued deny XML schema collection permissions command (action_id D class_type SX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68976,"title":"SQL Server Audit Event 24266 - Issued deny XML schema collection permissions with cascade command (action_id DWC class_type SX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24266","SQL Server"],"keywords":["24266","event 24266","event id 24266","Issued deny XML schema collection permissions with cascade command (action_id DWC class_type SX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24266"],"errorCode":"","eventId":"24266","severity":"Medium","summary":"SQL Server Audit event 24266 records: Issued deny XML schema collection permissions with cascade command (action_id DWC class_type SX)","rootCause":"The configured audit source recorded this activity: Issued deny XML schema collection permissions with cascade command (action_id DWC class_type SX) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24266.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny XML schema collection permissions with cascade command (action_id DWC class_type SX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24266\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24266} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24266","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24266","Event ID 24266","Issued deny XML schema collection permissions with cascade command (action_id DWC class_type SX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68977,"title":"SQL Server Audit Event 24267 - Issued revoke XML schema collection permissions command (action_id R class_type SX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24267","SQL Server"],"keywords":["24267","event 24267","event id 24267","Issued revoke XML schema collection permissions command (action_id R class_type SX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24267"],"errorCode":"","eventId":"24267","severity":"Medium","summary":"SQL Server Audit event 24267 records: Issued revoke XML schema collection permissions command (action_id R class_type SX)","rootCause":"The configured audit source recorded this activity: Issued revoke XML schema collection permissions command (action_id R class_type SX) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24267.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke XML schema collection permissions command (action_id R class_type SX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24267\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24267} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24267","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24267","Event ID 24267","Issued revoke XML schema collection permissions command (action_id R class_type SX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68978,"title":"SQL Server Audit Event 24268 - Issued revoke XML schema collection permissions with grant command (action_id RWG class_type SX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24268","SQL Server"],"keywords":["24268","event 24268","event id 24268","Issued revoke XML schema collection permissions with grant command (action_id RWG class_type SX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24268"],"errorCode":"","eventId":"24268","severity":"Medium","summary":"SQL Server Audit event 24268 records: Issued revoke XML schema collection permissions with grant command (action_id RWG class_type SX)","rootCause":"The configured audit source recorded this activity: Issued revoke XML schema collection permissions with grant command (action_id RWG class_type SX) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24268.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke XML schema collection permissions with grant command (action_id RWG class_type SX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24268\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24268} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24268","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24268","Event ID 24268","Issued revoke XML schema collection permissions with grant command (action_id RWG class_type SX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68979,"title":"SQL Server Audit Event 24269 - Issued revoke XML schema collection permissions with cascade command (action_id RWC class_type SX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24269","SQL Server"],"keywords":["24269","event 24269","event id 24269","Issued revoke XML schema collection permissions with cascade command (action_id RWC class_type SX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24269"],"errorCode":"","eventId":"24269","severity":"Medium","summary":"SQL Server Audit event 24269 records: Issued revoke XML schema collection permissions with cascade command (action_id RWC class_type SX)","rootCause":"The configured audit source recorded this activity: Issued revoke XML schema collection permissions with cascade command (action_id RWC class_type SX) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24269.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke XML schema collection permissions with cascade command (action_id RWC class_type SX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24269\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24269} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24269","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24269","Event ID 24269","Issued revoke XML schema collection permissions with cascade command (action_id RWC class_type SX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68980,"title":"SQL Server Audit Event 24270 - Issued reference database object permissions command (action_id RF)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24270","SQL Server"],"keywords":["24270","event 24270","event id 24270","Issued reference database object permissions command (action_id RF)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24270"],"errorCode":"","eventId":"24270","severity":"Medium","summary":"SQL Server Audit event 24270 records: Issued reference database object permissions command (action_id RF)","rootCause":"The configured audit source recorded this activity: Issued reference database object permissions command (action_id RF) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24270.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued reference database object permissions command (action_id RF)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24270\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24270} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24270","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24270","Event ID 24270","Issued reference database object permissions command (action_id RF)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68981,"title":"SQL Server Audit Event 24271 - Issued send service request command (action_id SN)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24271","SQL Server"],"keywords":["24271","event 24271","event id 24271","Issued send service request command (action_id SN)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24271"],"errorCode":"","eventId":"24271","severity":"Low","summary":"SQL Server Audit event 24271 records: Issued send service request command (action_id SN)","rootCause":"The configured audit source recorded this activity: Issued send service request command (action_id SN) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24271.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued send service request command (action_id SN)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24271\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24271} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24271","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24271","Event ID 24271","Issued send service request command (action_id SN)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68982,"title":"SQL Server Audit Event 24272 - Issued check permissions with schema command (action_id VWCT)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24272","SQL Server"],"keywords":["24272","event 24272","event id 24272","Issued check permissions with schema command (action_id VWCT)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24272"],"errorCode":"","eventId":"24272","severity":"Medium","summary":"SQL Server Audit event 24272 records: Issued check permissions with schema command (action_id VWCT)","rootCause":"The configured audit source recorded this activity: Issued check permissions with schema command (action_id VWCT) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24272.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued check permissions with schema command (action_id VWCT)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24272\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24272} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24272","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24272","Event ID 24272","Issued check permissions with schema command (action_id VWCT)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68983,"title":"SQL Server Audit Event 24273 - Issued use service broker transport security command (action_id LGB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24273","SQL Server"],"keywords":["24273","event 24273","event id 24273","Issued use service broker transport security command (action_id LGB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24273"],"errorCode":"","eventId":"24273","severity":"Low","summary":"SQL Server Audit event 24273 records: Issued use service broker transport security command (action_id LGB)","rootCause":"The configured audit source recorded this activity: Issued use service broker transport security command (action_id LGB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24273.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued use service broker transport security command (action_id LGB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24273\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24273} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24273","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24273","Event ID 24273","Issued use service broker transport security command (action_id LGB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68984,"title":"SQL Server Audit Event 24274 - Issued use database mirroring transport security command (action_id LGM)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24274","SQL Server"],"keywords":["24274","event 24274","event id 24274","Issued use database mirroring transport security command (action_id LGM)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24274"],"errorCode":"","eventId":"24274","severity":"Low","summary":"SQL Server Audit event 24274 records: Issued use database mirroring transport security command (action_id LGM)","rootCause":"The configured audit source recorded this activity: Issued use database mirroring transport security command (action_id LGM) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24274.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued use database mirroring transport security command (action_id LGM)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24274\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24274} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24274","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24274","Event ID 24274","Issued use database mirroring transport security command (action_id LGM)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68985,"title":"SQL Server Audit Event 24275 - Issued alter trace command (action_id ALTR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24275","SQL Server"],"keywords":["24275","event 24275","event id 24275","Issued alter trace command (action_id ALTR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24275"],"errorCode":"","eventId":"24275","severity":"Low","summary":"SQL Server Audit event 24275 records: Issued alter trace command (action_id ALTR)","rootCause":"The configured audit source recorded this activity: Issued alter trace command (action_id ALTR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24275.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued alter trace command (action_id ALTR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24275\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24275} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24275","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24275","Event ID 24275","Issued alter trace command (action_id ALTR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68986,"title":"SQL Server Audit Event 24276 - Issued start trace command (action_id TASA)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24276","SQL Server"],"keywords":["24276","event 24276","event id 24276","Issued start trace command (action_id TASA)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24276"],"errorCode":"","eventId":"24276","severity":"Low","summary":"SQL Server Audit event 24276 records: Issued start trace command (action_id TASA)","rootCause":"The configured audit source recorded this activity: Issued start trace command (action_id TASA) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24276.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued start trace command (action_id TASA)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24276\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24276} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24276","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24276","Event ID 24276","Issued start trace command (action_id TASA)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68987,"title":"SQL Server Audit Event 24277 - Issued stop trace command (action_id TASP)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24277","SQL Server"],"keywords":["24277","event 24277","event id 24277","Issued stop trace command (action_id TASP)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24277"],"errorCode":"","eventId":"24277","severity":"Low","summary":"SQL Server Audit event 24277 records: Issued stop trace command (action_id TASP)","rootCause":"The configured audit source recorded this activity: Issued stop trace command (action_id TASP) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24277.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued stop trace command (action_id TASP)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24277\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24277} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24277","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24277","Event ID 24277","Issued stop trace command (action_id TASP)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68988,"title":"SQL Server Audit Event 24278 - Issued enable trace C2 audit mode command (action_id C2ON)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24278","SQL Server"],"keywords":["24278","event 24278","event id 24278","Issued enable trace C2 audit mode command (action_id C2ON)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24278"],"errorCode":"","eventId":"24278","severity":"Low","summary":"SQL Server Audit event 24278 records: Issued enable trace C2 audit mode command (action_id C2ON)","rootCause":"The configured audit source recorded this activity: Issued enable trace C2 audit mode command (action_id C2ON) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24278.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued enable trace C2 audit mode command (action_id C2ON)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24278\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24278} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24278","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24278","Event ID 24278","Issued enable trace C2 audit mode command (action_id C2ON)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68989,"title":"SQL Server Audit Event 24279 - Issued disable trace C2 audit mode command (action_id C2OF)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24279","SQL Server"],"keywords":["24279","event 24279","event id 24279","Issued disable trace C2 audit mode command (action_id C2OF)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24279"],"errorCode":"","eventId":"24279","severity":"Low","summary":"SQL Server Audit event 24279 records: Issued disable trace C2 audit mode command (action_id C2OF)","rootCause":"The configured audit source recorded this activity: Issued disable trace C2 audit mode command (action_id C2OF) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24279.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued disable trace C2 audit mode command (action_id C2OF)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24279\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24279} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24279","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24279","Event ID 24279","Issued disable trace C2 audit mode command (action_id C2OF)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68990,"title":"SQL Server Audit Event 24280 - Issued server full-text command (action_id FT)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24280","SQL Server"],"keywords":["24280","event 24280","event id 24280","Issued server full-text command (action_id FT)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24280"],"errorCode":"","eventId":"24280","severity":"Low","summary":"SQL Server Audit event 24280 records: Issued server full-text command (action_id FT)","rootCause":"The configured audit source recorded this activity: Issued server full-text command (action_id FT) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24280.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued server full-text command (action_id FT)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24280\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24280} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24280","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24280","Event ID 24280","Issued server full-text command (action_id FT)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68991,"title":"SQL Server Audit Event 24281 - Issued select command (action_id SL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24281","SQL Server"],"keywords":["24281","event 24281","event id 24281","Issued select command (action_id SL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24281"],"errorCode":"","eventId":"24281","severity":"Low","summary":"SQL Server Audit event 24281 records: Issued select command (action_id SL)","rootCause":"The configured audit source recorded this activity: Issued select command (action_id SL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24281.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued select command (action_id SL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24281\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24281} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24281","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24281","Event ID 24281","Issued select command (action_id SL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68992,"title":"SQL Server Audit Event 24282 - Issued update command (action_id UP)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24282","SQL Server"],"keywords":["24282","event 24282","event id 24282","Issued update command (action_id UP)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24282"],"errorCode":"","eventId":"24282","severity":"Low","summary":"SQL Server Audit event 24282 records: Issued update command (action_id UP)","rootCause":"The configured audit source recorded this activity: Issued update command (action_id UP) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24282.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued update command (action_id UP)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24282\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24282} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24282","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24282","Event ID 24282","Issued update command (action_id UP)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68993,"title":"SQL Server Audit Event 24283 - Issued insert command (action_id IN)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24283","SQL Server"],"keywords":["24283","event 24283","event id 24283","Issued insert command (action_id IN)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24283"],"errorCode":"","eventId":"24283","severity":"Low","summary":"SQL Server Audit event 24283 records: Issued insert command (action_id IN)","rootCause":"The configured audit source recorded this activity: Issued insert command (action_id IN) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24283.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued insert command (action_id IN)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24283\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24283} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24283","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24283","Event ID 24283","Issued insert command (action_id IN)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68994,"title":"SQL Server Audit Event 24284 - Issued delete command (action_id DL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24284","SQL Server"],"keywords":["24284","event 24284","event id 24284","Issued delete command (action_id DL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24284"],"errorCode":"","eventId":"24284","severity":"Low","summary":"SQL Server Audit event 24284 records: Issued delete command (action_id DL)","rootCause":"The configured audit source recorded this activity: Issued delete command (action_id DL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24284.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued delete command (action_id DL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24284\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24284} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24284","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24284","Event ID 24284","Issued delete command (action_id DL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68995,"title":"SQL Server Audit Event 24285 - Issued execute command (action_id EX)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24285","SQL Server"],"keywords":["24285","event 24285","event id 24285","Issued execute command (action_id EX)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24285"],"errorCode":"","eventId":"24285","severity":"Low","summary":"SQL Server Audit event 24285 records: Issued execute command (action_id EX)","rootCause":"The configured audit source recorded this activity: Issued execute command (action_id EX) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24285.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued execute command (action_id EX)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24285\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24285} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24285","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24285","Event ID 24285","Issued execute command (action_id EX)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68996,"title":"SQL Server Audit Event 24286 - Issued receive command (action_id RC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24286","SQL Server"],"keywords":["24286","event 24286","event id 24286","Issued receive command (action_id RC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24286"],"errorCode":"","eventId":"24286","severity":"Low","summary":"SQL Server Audit event 24286 records: Issued receive command (action_id RC)","rootCause":"The configured audit source recorded this activity: Issued receive command (action_id RC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24286.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued receive command (action_id RC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24286\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24286} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24286","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24286","Event ID 24286","Issued receive command (action_id RC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68997,"title":"SQL Server Audit Event 24287 - Issued check references command (action_id RF)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24287","SQL Server"],"keywords":["24287","event 24287","event id 24287","Issued check references command (action_id RF)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24287"],"errorCode":"","eventId":"24287","severity":"Low","summary":"SQL Server Audit event 24287 records: Issued check references command (action_id RF)","rootCause":"The configured audit source recorded this activity: Issued check references command (action_id RF) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24287.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued check references command (action_id RF)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24287\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24287} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24287","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24287","Event ID 24287","Issued check references command (action_id RF)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68998,"title":"SQL Server Audit Event 24288 - Issued a create user-defined server role command (action_id CR class_type SG)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24288","SQL Server"],"keywords":["24288","event 24288","event id 24288","Issued a create user-defined server role command (action_id CR class_type SG)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24288"],"errorCode":"","eventId":"24288","severity":"Medium","summary":"SQL Server Audit event 24288 records: Issued a create user-defined server role command (action_id CR class_type SG)","rootCause":"The configured audit source recorded this activity: Issued a create user-defined server role command (action_id CR class_type SG) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24288.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create user-defined server role command (action_id CR class_type SG)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24288\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24288} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24288","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24288","Event ID 24288","Issued a create user-defined server role command (action_id CR class_type SG)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":68999,"title":"SQL Server Audit Event 24289 - Issued a change user-defined server role command (action_id AL class_type SG)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24289","SQL Server"],"keywords":["24289","event 24289","event id 24289","Issued a change user-defined server role command (action_id AL class_type SG)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24289"],"errorCode":"","eventId":"24289","severity":"Medium","summary":"SQL Server Audit event 24289 records: Issued a change user-defined server role command (action_id AL class_type SG)","rootCause":"The configured audit source recorded this activity: Issued a change user-defined server role command (action_id AL class_type SG) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24289.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change user-defined server role command (action_id AL class_type SG)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24289\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24289} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24289","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24289","Event ID 24289","Issued a change user-defined server role command (action_id AL class_type SG)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69000,"title":"SQL Server Audit Event 24290 - Issued a delete user-defined server role command (action_id DR class_type SG)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24290","SQL Server"],"keywords":["24290","event 24290","event id 24290","Issued a delete user-defined server role command (action_id DR class_type SG)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24290"],"errorCode":"","eventId":"24290","severity":"Medium","summary":"SQL Server Audit event 24290 records: Issued a delete user-defined server role command (action_id DR class_type SG)","rootCause":"The configured audit source recorded this activity: Issued a delete user-defined server role command (action_id DR class_type SG) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24290.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete user-defined server role command (action_id DR class_type SG)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24290\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24290} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24290","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24290","Event ID 24290","Issued a delete user-defined server role command (action_id DR class_type SG)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69001,"title":"SQL Server Audit Event 24291 - Issued grant user-defined server role permissions command (action_id G class_type SG)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24291","SQL Server"],"keywords":["24291","event 24291","event id 24291","Issued grant user-defined server role permissions command (action_id G class_type SG)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24291"],"errorCode":"","eventId":"24291","severity":"Medium","summary":"SQL Server Audit event 24291 records: Issued grant user-defined server role permissions command (action_id G class_type SG)","rootCause":"The configured audit source recorded this activity: Issued grant user-defined server role permissions command (action_id G class_type SG) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24291.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant user-defined server role permissions command (action_id G class_type SG)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24291\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24291} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24291","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24291","Event ID 24291","Issued grant user-defined server role permissions command (action_id G class_type SG)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69002,"title":"SQL Server Audit Event 24292 - Issued grant user-defined server role permissions with grant command (action_id GWG class_type SG)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24292","SQL Server"],"keywords":["24292","event 24292","event id 24292","Issued grant user-defined server role permissions with grant command (action_id GWG class_type SG)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24292"],"errorCode":"","eventId":"24292","severity":"Medium","summary":"SQL Server Audit event 24292 records: Issued grant user-defined server role permissions with grant command (action_id GWG class_type SG)","rootCause":"The configured audit source recorded this activity: Issued grant user-defined server role permissions with grant command (action_id GWG class_type SG) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24292.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued grant user-defined server role permissions with grant command (action_id GWG class_type SG)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24292\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24292} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24292","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24292","Event ID 24292","Issued grant user-defined server role permissions with grant command (action_id GWG class_type SG)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69003,"title":"SQL Server Audit Event 24293 - Issued deny user-defined server role permissions command (action_id D class_type SG)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24293","SQL Server"],"keywords":["24293","event 24293","event id 24293","Issued deny user-defined server role permissions command (action_id D class_type SG)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24293"],"errorCode":"","eventId":"24293","severity":"Medium","summary":"SQL Server Audit event 24293 records: Issued deny user-defined server role permissions command (action_id D class_type SG)","rootCause":"The configured audit source recorded this activity: Issued deny user-defined server role permissions command (action_id D class_type SG) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24293.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny user-defined server role permissions command (action_id D class_type SG)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24293\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24293} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24293","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24293","Event ID 24293","Issued deny user-defined server role permissions command (action_id D class_type SG)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69004,"title":"SQL Server Audit Event 24294 - Issued deny user-defined server role permissions with cascade command (action_id DWC class_type SG)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24294","SQL Server"],"keywords":["24294","event 24294","event id 24294","Issued deny user-defined server role permissions with cascade command (action_id DWC class_type SG)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24294"],"errorCode":"","eventId":"24294","severity":"Medium","summary":"SQL Server Audit event 24294 records: Issued deny user-defined server role permissions with cascade command (action_id DWC class_type SG)","rootCause":"The configured audit source recorded this activity: Issued deny user-defined server role permissions with cascade command (action_id DWC class_type SG) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24294.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued deny user-defined server role permissions with cascade command (action_id DWC class_type SG)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24294\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24294} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24294","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24294","Event ID 24294","Issued deny user-defined server role permissions with cascade command (action_id DWC class_type SG)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69005,"title":"SQL Server Audit Event 24295 - Issued revoke user-defined server role permissions command (action_id R class_type SG)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24295","SQL Server"],"keywords":["24295","event 24295","event id 24295","Issued revoke user-defined server role permissions command (action_id R class_type SG)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24295"],"errorCode":"","eventId":"24295","severity":"Medium","summary":"SQL Server Audit event 24295 records: Issued revoke user-defined server role permissions command (action_id R class_type SG)","rootCause":"The configured audit source recorded this activity: Issued revoke user-defined server role permissions command (action_id R class_type SG) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24295.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke user-defined server role permissions command (action_id R class_type SG)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24295\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24295} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24295","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24295","Event ID 24295","Issued revoke user-defined server role permissions command (action_id R class_type SG)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69006,"title":"SQL Server Audit Event 24296 - Issued revoke user-defined server role permissions with grant command (action_id RWG class_type SG)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24296","SQL Server"],"keywords":["24296","event 24296","event id 24296","Issued revoke user-defined server role permissions with grant command (action_id RWG class_type SG)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24296"],"errorCode":"","eventId":"24296","severity":"Medium","summary":"SQL Server Audit event 24296 records: Issued revoke user-defined server role permissions with grant command (action_id RWG class_type SG)","rootCause":"The configured audit source recorded this activity: Issued revoke user-defined server role permissions with grant command (action_id RWG class_type SG) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24296.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke user-defined server role permissions with grant command (action_id RWG class_type SG)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24296\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24296} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24296","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24296","Event ID 24296","Issued revoke user-defined server role permissions with grant command (action_id RWG class_type SG)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69007,"title":"SQL Server Audit Event 24297 - Issued revoke user-defined server role permissions with cascade command (action_id RWC class_type SG)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24297","SQL Server"],"keywords":["24297","event 24297","event id 24297","Issued revoke user-defined server role permissions with cascade command (action_id RWC class_type SG)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24297"],"errorCode":"","eventId":"24297","severity":"Medium","summary":"SQL Server Audit event 24297 records: Issued revoke user-defined server role permissions with cascade command (action_id RWC class_type SG)","rootCause":"The configured audit source recorded this activity: Issued revoke user-defined server role permissions with cascade command (action_id RWC class_type SG) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24297.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued revoke user-defined server role permissions with cascade command (action_id RWC class_type SG)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24297\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24297} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24297","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24297","Event ID 24297","Issued revoke user-defined server role permissions with cascade command (action_id RWC class_type SG)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69008,"title":"SQL Server Audit Event 24298 - Database login succeeded (action_id DBAS)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24298","SQL Server"],"keywords":["24298","event 24298","event id 24298","Database login succeeded (action_id DBAS)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24298"],"errorCode":"","eventId":"24298","severity":"Low","summary":"SQL Server Audit event 24298 records: Database login succeeded (action_id DBAS)","rootCause":"The configured audit source recorded this activity: Database login succeeded (action_id DBAS) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24298.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Database login succeeded (action_id DBAS)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24298\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24298} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24298","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24298","Event ID 24298","Database login succeeded (action_id DBAS)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69009,"title":"SQL Server Audit Event 24299 - Database login failed (action_id DBAF)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24299","SQL Server"],"keywords":["24299","event 24299","event id 24299","Database login failed (action_id DBAF)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24299"],"errorCode":"","eventId":"24299","severity":"High","summary":"SQL Server Audit event 24299 records: Database login failed (action_id DBAF)","rootCause":"The audited operation reported a failure: Database login failed (action_id DBAF) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24299.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Database login failed (action_id DBAF)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24299\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24299} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24299","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24299","Event ID 24299","Database login failed (action_id DBAF)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69010,"title":"SQL Server Audit Event 24300 - Database logout successful (action_id DAGL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24300","SQL Server"],"keywords":["24300","event 24300","event id 24300","Database logout successful (action_id DAGL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24300"],"errorCode":"","eventId":"24300","severity":"Low","summary":"SQL Server Audit event 24300 records: Database logout successful (action_id DAGL)","rootCause":"The configured audit source recorded this activity: Database logout successful (action_id DAGL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24300.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Database logout successful (action_id DAGL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24300\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24300} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24300","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24300","Event ID 24300","Database logout successful (action_id DAGL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69011,"title":"SQL Server Audit Event 24301 - Change password succeeded (action_id PWC; class_type US)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24301","SQL Server"],"keywords":["24301","event 24301","event id 24301","Change password succeeded (action_id PWC; class_type US)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24301"],"errorCode":"","eventId":"24301","severity":"Medium","summary":"SQL Server Audit event 24301 records: Change password succeeded (action_id PWC; class_type US)","rootCause":"The configured audit source recorded this activity: Change password succeeded (action_id PWC; class_type US) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24301.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Change password succeeded (action_id PWC; class_type US)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24301\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24301} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24301","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24301","Event ID 24301","Change password succeeded (action_id PWC; class_type US)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69012,"title":"SQL Server Audit Event 24302 - Change password failed (action_id PWC; class_type US)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24302","SQL Server"],"keywords":["24302","event 24302","event id 24302","Change password failed (action_id PWC; class_type US)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24302"],"errorCode":"","eventId":"24302","severity":"High","summary":"SQL Server Audit event 24302 records: Change password failed (action_id PWC; class_type US)","rootCause":"The audited operation reported a failure: Change password failed (action_id PWC; class_type US) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24302.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Change password failed (action_id PWC; class_type US)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24302\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24302} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24302","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24302","Event ID 24302","Change password failed (action_id PWC; class_type US)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69013,"title":"SQL Server Audit Event 24303 - Change own password succeeded (action_id PWCS; class_type US)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24303","SQL Server"],"keywords":["24303","event 24303","event id 24303","Change own password succeeded (action_id PWCS; class_type US)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24303"],"errorCode":"","eventId":"24303","severity":"Medium","summary":"SQL Server Audit event 24303 records: Change own password succeeded (action_id PWCS; class_type US)","rootCause":"The configured audit source recorded this activity: Change own password succeeded (action_id PWCS; class_type US) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24303.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Change own password succeeded (action_id PWCS; class_type US)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24303\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24303} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24303","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24303","Event ID 24303","Change own password succeeded (action_id PWCS; class_type US)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69014,"title":"SQL Server Audit Event 24304 - Change own password failed (action_id PWCS; class_type US)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24304","SQL Server"],"keywords":["24304","event 24304","event id 24304","Change own password failed (action_id PWCS; class_type US)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24304"],"errorCode":"","eventId":"24304","severity":"High","summary":"SQL Server Audit event 24304 records: Change own password failed (action_id PWCS; class_type US)","rootCause":"The audited operation reported a failure: Change own password failed (action_id PWCS; class_type US) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24304.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Change own password failed (action_id PWCS; class_type US)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24304\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24304} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24304","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24304","Event ID 24304","Change own password failed (action_id PWCS; class_type US)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69015,"title":"SQL Server Audit Event 24305 - Reset own password succeeded (action_id PWRS; class_type US)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24305","SQL Server"],"keywords":["24305","event 24305","event id 24305","Reset own password succeeded (action_id PWRS; class_type US)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24305"],"errorCode":"","eventId":"24305","severity":"Medium","summary":"SQL Server Audit event 24305 records: Reset own password succeeded (action_id PWRS; class_type US)","rootCause":"The event records a state-changing operation: Reset own password succeeded (action_id PWRS; class_type US) It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24305.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Reset own password succeeded (action_id PWRS; class_type US)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24305\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24305} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24305","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24305","Event ID 24305","Reset own password succeeded (action_id PWRS; class_type US)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69016,"title":"SQL Server Audit Event 24306 - Reset own password failed (action_id PWRS; class_type US)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24306","SQL Server"],"keywords":["24306","event 24306","event id 24306","Reset own password failed (action_id PWRS; class_type US)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24306"],"errorCode":"","eventId":"24306","severity":"High","summary":"SQL Server Audit event 24306 records: Reset own password failed (action_id PWRS; class_type US)","rootCause":"The audited operation reported a failure: Reset own password failed (action_id PWRS; class_type US) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24306.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Reset own password failed (action_id PWRS; class_type US)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24306\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24306} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24306","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24306","Event ID 24306","Reset own password failed (action_id PWRS; class_type US)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69017,"title":"SQL Server Audit Event 24307 - Reset password succeeded (action_id PWR; class_type US)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24307","SQL Server"],"keywords":["24307","event 24307","event id 24307","Reset password succeeded (action_id PWR; class_type US)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24307"],"errorCode":"","eventId":"24307","severity":"Medium","summary":"SQL Server Audit event 24307 records: Reset password succeeded (action_id PWR; class_type US)","rootCause":"The event records a state-changing operation: Reset password succeeded (action_id PWR; class_type US) It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24307.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Reset password succeeded (action_id PWR; class_type US)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24307\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24307} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24307","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24307","Event ID 24307","Reset password succeeded (action_id PWR; class_type US)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69018,"title":"SQL Server Audit Event 24308 - Reset password failed (action_id PWR; class_type US)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24308","SQL Server"],"keywords":["24308","event 24308","event id 24308","Reset password failed (action_id PWR; class_type US)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24308"],"errorCode":"","eventId":"24308","severity":"High","summary":"SQL Server Audit event 24308 records: Reset password failed (action_id PWR; class_type US)","rootCause":"The audited operation reported a failure: Reset password failed (action_id PWR; class_type US) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24308.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Reset password failed (action_id PWR; class_type US)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24308\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24308} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24308","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24308","Event ID 24308","Reset password failed (action_id PWR; class_type US)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69019,"title":"SQL Server Audit Event 24309 - Copy password (action_id USTC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24309","SQL Server"],"keywords":["24309","event 24309","event id 24309","Copy password (action_id USTC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24309"],"errorCode":"","eventId":"24309","severity":"Medium","summary":"SQL Server Audit event 24309 records: Copy password (action_id USTC)","rootCause":"The configured audit source recorded this activity: Copy password (action_id USTC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24309.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Copy password (action_id USTC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24309\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24309} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24309","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24309","Event ID 24309","Copy password (action_id USTC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69020,"title":"SQL Server Audit Event 24310 - User-defined SQL audit event (action_id UDAU)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24310","SQL Server"],"keywords":["24310","event 24310","event id 24310","User-defined SQL audit event (action_id UDAU)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24310"],"errorCode":"","eventId":"24310","severity":"Low","summary":"SQL Server Audit event 24310 records: User-defined SQL audit event (action_id UDAU)","rootCause":"The configured audit source recorded this activity: User-defined SQL audit event (action_id UDAU) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24310.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: User-defined SQL audit event (action_id UDAU)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24310\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24310} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24310","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24310","Event ID 24310","User-defined SQL audit event (action_id UDAU)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69021,"title":"SQL Server Audit Event 24311 - Issued a change database audit command (action_id AL class_type DU)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24311","SQL Server"],"keywords":["24311","event 24311","event id 24311","Issued a change database audit command (action_id AL class_type DU)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24311"],"errorCode":"","eventId":"24311","severity":"Low","summary":"SQL Server Audit event 24311 records: Issued a change database audit command (action_id AL class_type DU)","rootCause":"The configured audit source recorded this activity: Issued a change database audit command (action_id AL class_type DU) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24311.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change database audit command (action_id AL class_type DU)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24311\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24311} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24311","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24311","Event ID 24311","Issued a change database audit command (action_id AL class_type DU)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69022,"title":"SQL Server Audit Event 24312 - Issued a create database audit command (action_id CR class_type DU)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24312","SQL Server"],"keywords":["24312","event 24312","event id 24312","Issued a create database audit command (action_id CR class_type DU)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24312"],"errorCode":"","eventId":"24312","severity":"Low","summary":"SQL Server Audit event 24312 records: Issued a create database audit command (action_id CR class_type DU)","rootCause":"The configured audit source recorded this activity: Issued a create database audit command (action_id CR class_type DU) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24312.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create database audit command (action_id CR class_type DU)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24312\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24312} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24312","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24312","Event ID 24312","Issued a create database audit command (action_id CR class_type DU)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69023,"title":"SQL Server Audit Event 24313 - Issued a delete database audit command (action_id DR class_type DU)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24313","SQL Server"],"keywords":["24313","event 24313","event id 24313","Issued a delete database audit command (action_id DR class_type DU)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24313"],"errorCode":"","eventId":"24313","severity":"Low","summary":"SQL Server Audit event 24313 records: Issued a delete database audit command (action_id DR class_type DU)","rootCause":"The configured audit source recorded this activity: Issued a delete database audit command (action_id DR class_type DU) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24313.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete database audit command (action_id DR class_type DU)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24313\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24313} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24313","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24313","Event ID 24313","Issued a delete database audit command (action_id DR class_type DU)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69024,"title":"SQL Server Audit Event 24314 - Issued a begin transaction command (action_id TXBG)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24314","SQL Server"],"keywords":["24314","event 24314","event id 24314","Issued a begin transaction command (action_id TXBG)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24314"],"errorCode":"","eventId":"24314","severity":"Low","summary":"SQL Server Audit event 24314 records: Issued a begin transaction command (action_id TXBG)","rootCause":"The configured audit source recorded this activity: Issued a begin transaction command (action_id TXBG) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24314.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a begin transaction command (action_id TXBG)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24314\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24314} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24314","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24314","Event ID 24314","Issued a begin transaction command (action_id TXBG)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69025,"title":"SQL Server Audit Event 24315 - Issued a commit transaction command (action_id TXCM)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24315","SQL Server"],"keywords":["24315","event 24315","event id 24315","Issued a commit transaction command (action_id TXCM)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24315"],"errorCode":"","eventId":"24315","severity":"Low","summary":"SQL Server Audit event 24315 records: Issued a commit transaction command (action_id TXCM)","rootCause":"The configured audit source recorded this activity: Issued a commit transaction command (action_id TXCM) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24315.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a commit transaction command (action_id TXCM)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24315\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24315} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24315","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24315","Event ID 24315","Issued a commit transaction command (action_id TXCM)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69026,"title":"SQL Server Audit Event 24316 - Issued a rollback transaction command (action_id TXRB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24316","SQL Server"],"keywords":["24316","event 24316","event id 24316","Issued a rollback transaction command (action_id TXRB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24316"],"errorCode":"","eventId":"24316","severity":"Low","summary":"SQL Server Audit event 24316 records: Issued a rollback transaction command (action_id TXRB)","rootCause":"The configured audit source recorded this activity: Issued a rollback transaction command (action_id TXRB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24316.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a rollback transaction command (action_id TXRB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24316\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24316} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24316","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24316","Event ID 24316","Issued a rollback transaction command (action_id TXRB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69027,"title":"SQL Server Audit Event 24317 - Issued a create column master key command (action_id CR; class_type CM)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24317","SQL Server"],"keywords":["24317","event 24317","event id 24317","Issued a create column master key command (action_id CR; class_type CM)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24317"],"errorCode":"","eventId":"24317","severity":"Low","summary":"SQL Server Audit event 24317 records: Issued a create column master key command (action_id CR; class_type CM)","rootCause":"The configured audit source recorded this activity: Issued a create column master key command (action_id CR; class_type CM) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24317.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create column master key command (action_id CR; class_type CM)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24317\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24317} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24317","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24317","Event ID 24317","Issued a create column master key command (action_id CR; class_type CM)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69028,"title":"SQL Server Audit Event 24318 - Issued a delete column master key command (action_id DR; class_type CM)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24318","SQL Server"],"keywords":["24318","event 24318","event id 24318","Issued a delete column master key command (action_id DR; class_type CM)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24318"],"errorCode":"","eventId":"24318","severity":"Low","summary":"SQL Server Audit event 24318 records: Issued a delete column master key command (action_id DR; class_type CM)","rootCause":"The configured audit source recorded this activity: Issued a delete column master key command (action_id DR; class_type CM) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24318.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete column master key command (action_id DR; class_type CM)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24318\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24318} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24318","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24318","Event ID 24318","Issued a delete column master key command (action_id DR; class_type CM)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69029,"title":"SQL Server Audit Event 24319 - A column master key was viewed (action_id VW; class_type CM)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24319","SQL Server"],"keywords":["24319","event 24319","event id 24319","A column master key was viewed (action_id VW; class_type CM)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24319"],"errorCode":"","eventId":"24319","severity":"Low","summary":"SQL Server Audit event 24319 records: A column master key was viewed (action_id VW; class_type CM)","rootCause":"The configured audit source recorded this activity: A column master key was viewed (action_id VW; class_type CM) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24319.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A column master key was viewed (action_id VW; class_type CM)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24319\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24319} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24319","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24319","Event ID 24319","A column master key was viewed (action_id VW; class_type CM)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69030,"title":"SQL Server Audit Event 24320 - Issued a create column encryption key command (action_id CR; class_type CK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24320","SQL Server"],"keywords":["24320","event 24320","event id 24320","Issued a create column encryption key command (action_id CR; class_type CK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24320"],"errorCode":"","eventId":"24320","severity":"Low","summary":"SQL Server Audit event 24320 records: Issued a create column encryption key command (action_id CR; class_type CK)","rootCause":"The configured audit source recorded this activity: Issued a create column encryption key command (action_id CR; class_type CK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24320.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create column encryption key command (action_id CR; class_type CK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24320\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24320} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24320","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24320","Event ID 24320","Issued a create column encryption key command (action_id CR; class_type CK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69031,"title":"SQL Server Audit Event 24321 - Issued a change column encryption key command (action_id AL; class_type CK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24321","SQL Server"],"keywords":["24321","event 24321","event id 24321","Issued a change column encryption key command (action_id AL; class_type CK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24321"],"errorCode":"","eventId":"24321","severity":"Low","summary":"SQL Server Audit event 24321 records: Issued a change column encryption key command (action_id AL; class_type CK)","rootCause":"The configured audit source recorded this activity: Issued a change column encryption key command (action_id AL; class_type CK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24321.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change column encryption key command (action_id AL; class_type CK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24321\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24321} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24321","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24321","Event ID 24321","Issued a change column encryption key command (action_id AL; class_type CK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69032,"title":"SQL Server Audit Event 24322 - Issued a delete column encryption key command (action_id DR; class_type CK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24322","SQL Server"],"keywords":["24322","event 24322","event id 24322","Issued a delete column encryption key command (action_id DR; class_type CK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24322"],"errorCode":"","eventId":"24322","severity":"Low","summary":"SQL Server Audit event 24322 records: Issued a delete column encryption key command (action_id DR; class_type CK)","rootCause":"The configured audit source recorded this activity: Issued a delete column encryption key command (action_id DR; class_type CK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24322.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete column encryption key command (action_id DR; class_type CK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24322\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24322} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24322","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24322","Event ID 24322","Issued a delete column encryption key command (action_id DR; class_type CK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69033,"title":"SQL Server Audit Event 24323 - A column encryption key was viewed (action_id VW; class_type CK)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24323","SQL Server"],"keywords":["24323","event 24323","event id 24323","A column encryption key was viewed (action_id VW; class_type CK)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24323"],"errorCode":"","eventId":"24323","severity":"Low","summary":"SQL Server Audit event 24323 records: A column encryption key was viewed (action_id VW; class_type CK)","rootCause":"The configured audit source recorded this activity: A column encryption key was viewed (action_id VW; class_type CK) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24323.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A column encryption key was viewed (action_id VW; class_type CK)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24323\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24323} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24323","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24323","Event ID 24323","A column encryption key was viewed (action_id VW; class_type CK)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69034,"title":"SQL Server Audit Event 24324 - Issued a create database credential command (action_id CR; class_type DC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24324","SQL Server"],"keywords":["24324","event 24324","event id 24324","Issued a create database credential command (action_id CR; class_type DC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24324"],"errorCode":"","eventId":"24324","severity":"Low","summary":"SQL Server Audit event 24324 records: Issued a create database credential command (action_id CR; class_type DC)","rootCause":"The configured audit source recorded this activity: Issued a create database credential command (action_id CR; class_type DC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24324.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create database credential command (action_id CR; class_type DC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24324\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24324} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24324","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24324","Event ID 24324","Issued a create database credential command (action_id CR; class_type DC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69035,"title":"SQL Server Audit Event 24325 - Issued a change database credential command (action_id AL; class_type DC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24325","SQL Server"],"keywords":["24325","event 24325","event id 24325","Issued a change database credential command (action_id AL; class_type DC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24325"],"errorCode":"","eventId":"24325","severity":"Low","summary":"SQL Server Audit event 24325 records: Issued a change database credential command (action_id AL; class_type DC)","rootCause":"The configured audit source recorded this activity: Issued a change database credential command (action_id AL; class_type DC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24325.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change database credential command (action_id AL; class_type DC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24325\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24325} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24325","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24325","Event ID 24325","Issued a change database credential command (action_id AL; class_type DC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69036,"title":"SQL Server Audit Event 24326 - Issued a delete database credential command (action_id DR; class_type DC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24326","SQL Server"],"keywords":["24326","event 24326","event id 24326","Issued a delete database credential command (action_id DR; class_type DC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24326"],"errorCode":"","eventId":"24326","severity":"Low","summary":"SQL Server Audit event 24326 records: Issued a delete database credential command (action_id DR; class_type DC)","rootCause":"The configured audit source recorded this activity: Issued a delete database credential command (action_id DR; class_type DC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24326.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete database credential command (action_id DR; class_type DC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24326\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24326} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24326","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24326","Event ID 24326","Issued a delete database credential command (action_id DR; class_type DC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69037,"title":"SQL Server Audit Event 24327 - Issued a change database scoped configuration command (action_id AL; class_type DS)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24327","SQL Server"],"keywords":["24327","event 24327","event id 24327","Issued a change database scoped configuration command (action_id AL; class_type DS)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24327"],"errorCode":"","eventId":"24327","severity":"Low","summary":"SQL Server Audit event 24327 records: Issued a change database scoped configuration command (action_id AL; class_type DS)","rootCause":"The configured audit source recorded this activity: Issued a change database scoped configuration command (action_id AL; class_type DS) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24327.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change database scoped configuration command (action_id AL; class_type DS)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24327\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24327} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24327","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24327","Event ID 24327","Issued a change database scoped configuration command (action_id AL; class_type DS)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69038,"title":"SQL Server Audit Event 24328 - Issued a create external data source command (action_id CR; class_type ED)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24328","SQL Server"],"keywords":["24328","event 24328","event id 24328","Issued a create external data source command (action_id CR; class_type ED)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24328"],"errorCode":"","eventId":"24328","severity":"Low","summary":"SQL Server Audit event 24328 records: Issued a create external data source command (action_id CR; class_type ED)","rootCause":"The configured audit source recorded this activity: Issued a create external data source command (action_id CR; class_type ED) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24328.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create external data source command (action_id CR; class_type ED)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24328\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24328} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24328","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24328","Event ID 24328","Issued a create external data source command (action_id CR; class_type ED)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69039,"title":"SQL Server Audit Event 24329 - Issued a change external data source command (action_id AL; class_type ED)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24329","SQL Server"],"keywords":["24329","event 24329","event id 24329","Issued a change external data source command (action_id AL; class_type ED)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24329"],"errorCode":"","eventId":"24329","severity":"Low","summary":"SQL Server Audit event 24329 records: Issued a change external data source command (action_id AL; class_type ED)","rootCause":"The configured audit source recorded this activity: Issued a change external data source command (action_id AL; class_type ED) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24329.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change external data source command (action_id AL; class_type ED)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24329\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24329} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24329","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24329","Event ID 24329","Issued a change external data source command (action_id AL; class_type ED)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69040,"title":"SQL Server Audit Event 24330 - Issued a delete external data source command (action_id DR; class_type ED)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24330","SQL Server"],"keywords":["24330","event 24330","event id 24330","Issued a delete external data source command (action_id DR; class_type ED)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24330"],"errorCode":"","eventId":"24330","severity":"Low","summary":"SQL Server Audit event 24330 records: Issued a delete external data source command (action_id DR; class_type ED)","rootCause":"The configured audit source recorded this activity: Issued a delete external data source command (action_id DR; class_type ED) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24330.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete external data source command (action_id DR; class_type ED)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24330\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24330} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24330","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24330","Event ID 24330","Issued a delete external data source command (action_id DR; class_type ED)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69041,"title":"SQL Server Audit Event 24331 - Issued a create external file format command (action_id CR; class_type EF)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24331","SQL Server"],"keywords":["24331","event 24331","event id 24331","Issued a create external file format command (action_id CR; class_type EF)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24331"],"errorCode":"","eventId":"24331","severity":"Low","summary":"SQL Server Audit event 24331 records: Issued a create external file format command (action_id CR; class_type EF)","rootCause":"The configured audit source recorded this activity: Issued a create external file format command (action_id CR; class_type EF) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24331.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create external file format command (action_id CR; class_type EF)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24331\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24331} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24331","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24331","Event ID 24331","Issued a create external file format command (action_id CR; class_type EF)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69042,"title":"SQL Server Audit Event 24332 - Issued a delete external file format command (action_id DR; class_type EF)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24332","SQL Server"],"keywords":["24332","event 24332","event id 24332","Issued a delete external file format command (action_id DR; class_type EF)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24332"],"errorCode":"","eventId":"24332","severity":"Low","summary":"SQL Server Audit event 24332 records: Issued a delete external file format command (action_id DR; class_type EF)","rootCause":"The configured audit source recorded this activity: Issued a delete external file format command (action_id DR; class_type EF) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24332.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete external file format command (action_id DR; class_type EF)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24332\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24332} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24332","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24332","Event ID 24332","Issued a delete external file format command (action_id DR; class_type EF)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69043,"title":"SQL Server Audit Event 24333 - Issued a create external resource pool command (action_id CR; class_type ER)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24333","SQL Server"],"keywords":["24333","event 24333","event id 24333","Issued a create external resource pool command (action_id CR; class_type ER)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24333"],"errorCode":"","eventId":"24333","severity":"Low","summary":"SQL Server Audit event 24333 records: Issued a create external resource pool command (action_id CR; class_type ER)","rootCause":"The configured audit source recorded this activity: Issued a create external resource pool command (action_id CR; class_type ER) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24333.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create external resource pool command (action_id CR; class_type ER)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24333\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24333} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24333","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24333","Event ID 24333","Issued a create external resource pool command (action_id CR; class_type ER)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69044,"title":"SQL Server Audit Event 24334 - Issued a change external resource pool command (action_id AL; class_type ER)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24334","SQL Server"],"keywords":["24334","event 24334","event id 24334","Issued a change external resource pool command (action_id AL; class_type ER)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24334"],"errorCode":"","eventId":"24334","severity":"Low","summary":"SQL Server Audit event 24334 records: Issued a change external resource pool command (action_id AL; class_type ER)","rootCause":"The configured audit source recorded this activity: Issued a change external resource pool command (action_id AL; class_type ER) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24334.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change external resource pool command (action_id AL; class_type ER)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24334\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24334} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24334","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24334","Event ID 24334","Issued a change external resource pool command (action_id AL; class_type ER)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69045,"title":"SQL Server Audit Event 24335 - Issued a delete external resource pool command (action_id DR; class_type ER)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24335","SQL Server"],"keywords":["24335","event 24335","event id 24335","Issued a delete external resource pool command (action_id DR; class_type ER)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24335"],"errorCode":"","eventId":"24335","severity":"Low","summary":"SQL Server Audit event 24335 records: Issued a delete external resource pool command (action_id DR; class_type ER)","rootCause":"The configured audit source recorded this activity: Issued a delete external resource pool command (action_id DR; class_type ER) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24335.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a delete external resource pool command (action_id DR; class_type ER)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24335\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24335} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24335","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24335","Event ID 24335","Issued a delete external resource pool command (action_id DR; class_type ER)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69046,"title":"SQL Server Audit Event 24336 - Statement rollback (action_id UNDO; class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24336","SQL Server"],"keywords":["24336","event 24336","event id 24336","Statement rollback (action_id UNDO; class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24336"],"errorCode":"","eventId":"24336","severity":"Low","summary":"SQL Server Audit event 24336 records: Statement rollback (action_id UNDO; class_type DB)","rootCause":"The configured audit source recorded this activity: Statement rollback (action_id UNDO; class_type DB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24336.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Statement rollback (action_id UNDO; class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24336\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24336} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24336","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24336","Event ID 24336","Statement rollback (action_id UNDO; class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69047,"title":"SQL Server Audit Event 24337 - Global transaction login (action_id LGG)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24337","SQL Server"],"keywords":["24337","event 24337","event id 24337","Global transaction login (action_id LGG)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24337"],"errorCode":"","eventId":"24337","severity":"Low","summary":"SQL Server Audit event 24337 records: Global transaction login (action_id LGG)","rootCause":"The configured audit source recorded this activity: Global transaction login (action_id LGG) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24337.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Global transaction login (action_id LGG)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24337\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24337} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24337","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24337","Event ID 24337","Global transaction login (action_id LGG)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69048,"title":"SQL Server Audit Event 24338 - Grant permissions on a database scoped credential succeeded (action_id G; class_type DC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24338","SQL Server"],"keywords":["24338","event 24338","event id 24338","Grant permissions on a database scoped credential succeeded (action_id G; class_type DC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24338"],"errorCode":"","eventId":"24338","severity":"Medium","summary":"SQL Server Audit event 24338 records: Grant permissions on a database scoped credential succeeded (action_id G; class_type DC)","rootCause":"The configured audit source recorded this activity: Grant permissions on a database scoped credential succeeded (action_id G; class_type DC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24338.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Grant permissions on a database scoped credential succeeded (action_id G; class_type DC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24338\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24338} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24338","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24338","Event ID 24338","Grant permissions on a database scoped credential succeeded (action_id G; class_type DC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69049,"title":"SQL Server Audit Event 24339 - Grant permissions on a database scoped credential failed (action_id G; class_type DC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24339","SQL Server"],"keywords":["24339","event 24339","event id 24339","Grant permissions on a database scoped credential failed (action_id G; class_type DC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24339"],"errorCode":"","eventId":"24339","severity":"High","summary":"SQL Server Audit event 24339 records: Grant permissions on a database scoped credential failed (action_id G; class_type DC)","rootCause":"The audited operation reported a failure: Grant permissions on a database scoped credential failed (action_id G; class_type DC) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24339.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Grant permissions on a database scoped credential failed (action_id G; class_type DC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24339\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24339} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24339","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24339","Event ID 24339","Grant permissions on a database scoped credential failed (action_id G; class_type DC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69050,"title":"SQL Server Audit Event 24340 - Grant permissions on a database scoped credential with grant succeeded (action_id GWG; class_type DC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24340","SQL Server"],"keywords":["24340","event 24340","event id 24340","Grant permissions on a database scoped credential with grant succeeded (action_id GWG; class_type DC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24340"],"errorCode":"","eventId":"24340","severity":"Medium","summary":"SQL Server Audit event 24340 records: Grant permissions on a database scoped credential with grant succeeded (action_id GWG; class_type DC)","rootCause":"The configured audit source recorded this activity: Grant permissions on a database scoped credential with grant succeeded (action_id GWG; class_type DC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24340.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Grant permissions on a database scoped credential with grant succeeded (action_id GWG; class_type DC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24340\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24340} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24340","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24340","Event ID 24340","Grant permissions on a database scoped credential with grant succeeded (action_id GWG; class_type DC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69051,"title":"SQL Server Audit Event 24341 - Grant permissions on a database scoped credential with grant failed (action_id GWG; class_type DC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24341","SQL Server"],"keywords":["24341","event 24341","event id 24341","Grant permissions on a database scoped credential with grant failed (action_id GWG; class_type DC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24341"],"errorCode":"","eventId":"24341","severity":"High","summary":"SQL Server Audit event 24341 records: Grant permissions on a database scoped credential with grant failed (action_id GWG; class_type DC)","rootCause":"The audited operation reported a failure: Grant permissions on a database scoped credential with grant failed (action_id GWG; class_type DC) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24341.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Grant permissions on a database scoped credential with grant failed (action_id GWG; class_type DC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24341\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24341} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24341","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24341","Event ID 24341","Grant permissions on a database scoped credential with grant failed (action_id GWG; class_type DC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69052,"title":"SQL Server Audit Event 24342 - Deny permissions on a database scoped credential succeeded (action_id D; class_type DC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24342","SQL Server"],"keywords":["24342","event 24342","event id 24342","Deny permissions on a database scoped credential succeeded (action_id D; class_type DC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24342"],"errorCode":"","eventId":"24342","severity":"Medium","summary":"SQL Server Audit event 24342 records: Deny permissions on a database scoped credential succeeded (action_id D; class_type DC)","rootCause":"The configured audit source recorded this activity: Deny permissions on a database scoped credential succeeded (action_id D; class_type DC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24342.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Deny permissions on a database scoped credential succeeded (action_id D; class_type DC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24342\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24342} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24342","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24342","Event ID 24342","Deny permissions on a database scoped credential succeeded (action_id D; class_type DC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69053,"title":"SQL Server Audit Event 24343 - Deny permissions on a database scoped credential failed (action_id D; class_type DC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24343","SQL Server"],"keywords":["24343","event 24343","event id 24343","Deny permissions on a database scoped credential failed (action_id D; class_type DC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24343"],"errorCode":"","eventId":"24343","severity":"High","summary":"SQL Server Audit event 24343 records: Deny permissions on a database scoped credential failed (action_id D; class_type DC)","rootCause":"The audited operation reported a failure: Deny permissions on a database scoped credential failed (action_id D; class_type DC) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24343.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Deny permissions on a database scoped credential failed (action_id D; class_type DC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24343\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24343} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24343","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24343","Event ID 24343","Deny permissions on a database scoped credential failed (action_id D; class_type DC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69054,"title":"SQL Server Audit Event 24344 - Deny permissions on a database scoped credential with cascade succeeded (action_id DWC; class_type DC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24344","SQL Server"],"keywords":["24344","event 24344","event id 24344","Deny permissions on a database scoped credential with cascade succeeded (action_id DWC; class_type DC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24344"],"errorCode":"","eventId":"24344","severity":"Medium","summary":"SQL Server Audit event 24344 records: Deny permissions on a database scoped credential with cascade succeeded (action_id DWC; class_type DC)","rootCause":"The configured audit source recorded this activity: Deny permissions on a database scoped credential with cascade succeeded (action_id DWC; class_type DC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24344.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Deny permissions on a database scoped credential with cascade succeeded (action_id DWC; class_type DC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24344\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24344} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24344","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24344","Event ID 24344","Deny permissions on a database scoped credential with cascade succeeded (action_id DWC; class_type DC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69055,"title":"SQL Server Audit Event 24345 - Deny permissions on a database scoped credential with cascade failed (action_id DWC; class_type DC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24345","SQL Server"],"keywords":["24345","event 24345","event id 24345","Deny permissions on a database scoped credential with cascade failed (action_id DWC; class_type DC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24345"],"errorCode":"","eventId":"24345","severity":"High","summary":"SQL Server Audit event 24345 records: Deny permissions on a database scoped credential with cascade failed (action_id DWC; class_type DC)","rootCause":"The audited operation reported a failure: Deny permissions on a database scoped credential with cascade failed (action_id DWC; class_type DC) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24345.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Deny permissions on a database scoped credential with cascade failed (action_id DWC; class_type DC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24345\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24345} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24345","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24345","Event ID 24345","Deny permissions on a database scoped credential with cascade failed (action_id DWC; class_type DC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69056,"title":"SQL Server Audit Event 24346 - Revoke permissions on a database scoped credential succeeded (action_id R; class_type DC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24346","SQL Server"],"keywords":["24346","event 24346","event id 24346","Revoke permissions on a database scoped credential succeeded (action_id R; class_type DC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24346"],"errorCode":"","eventId":"24346","severity":"Medium","summary":"SQL Server Audit event 24346 records: Revoke permissions on a database scoped credential succeeded (action_id R; class_type DC)","rootCause":"The configured audit source recorded this activity: Revoke permissions on a database scoped credential succeeded (action_id R; class_type DC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24346.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Revoke permissions on a database scoped credential succeeded (action_id R; class_type DC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24346\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24346} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24346","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24346","Event ID 24346","Revoke permissions on a database scoped credential succeeded (action_id R; class_type DC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69057,"title":"SQL Server Audit Event 24347 - Revoke permissions on a database scoped credential failed (action_id R; class_type DC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24347","SQL Server"],"keywords":["24347","event 24347","event id 24347","Revoke permissions on a database scoped credential failed (action_id R; class_type DC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24347"],"errorCode":"","eventId":"24347","severity":"High","summary":"SQL Server Audit event 24347 records: Revoke permissions on a database scoped credential failed (action_id R; class_type DC)","rootCause":"The audited operation reported a failure: Revoke permissions on a database scoped credential failed (action_id R; class_type DC) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24347.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Revoke permissions on a database scoped credential failed (action_id R; class_type DC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24347\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24347} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24347","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24347","Event ID 24347","Revoke permissions on a database scoped credential failed (action_id R; class_type DC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69058,"title":"SQL Server Audit Event 24348 - Revoke permissions with cascade on a database scoped credential succeeded (action_id RWC; class_type DC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24348","SQL Server"],"keywords":["24348","event 24348","event id 24348","Revoke permissions with cascade on a database scoped credential succeeded (action_id RWC; class_type DC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24348"],"errorCode":"","eventId":"24348","severity":"Medium","summary":"SQL Server Audit event 24348 records: Revoke permissions with cascade on a database scoped credential succeeded (action_id RWC; class_type DC)","rootCause":"The configured audit source recorded this activity: Revoke permissions with cascade on a database scoped credential succeeded (action_id RWC; class_type DC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24348.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Revoke permissions with cascade on a database scoped credential succeeded (action_id RWC; class_type DC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24348\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24348} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24348","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24348","Event ID 24348","Revoke permissions with cascade on a database scoped credential succeeded (action_id RWC; class_type DC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69059,"title":"SQL Server Audit Event 24349 - Issued a change assembly owner command (action_id TO class_type AS)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24349","SQL Server"],"keywords":["24349","event 24349","event id 24349","Issued a change assembly owner command (action_id TO class_type AS)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24349"],"errorCode":"","eventId":"24349","severity":"Low","summary":"SQL Server Audit event 24349 records: Issued a change assembly owner command (action_id TO class_type AS)","rootCause":"The configured audit source recorded this activity: Issued a change assembly owner command (action_id TO class_type AS) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24349.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change assembly owner command (action_id TO class_type AS)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24349\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24349} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24349","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24349","Event ID 24349","Issued a change assembly owner command (action_id TO class_type AS)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69060,"title":"SQL Server Audit Event 24350 - Revoke permissions with cascade on a database scoped credential failed (action_id RWC; class_type DC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24350","SQL Server"],"keywords":["24350","event 24350","event id 24350","Revoke permissions with cascade on a database scoped credential failed (action_id RWC; class_type DC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24350"],"errorCode":"","eventId":"24350","severity":"High","summary":"SQL Server Audit event 24350 records: Revoke permissions with cascade on a database scoped credential failed (action_id RWC; class_type DC)","rootCause":"The audited operation reported a failure: Revoke permissions with cascade on a database scoped credential failed (action_id RWC; class_type DC) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24350.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Revoke permissions with cascade on a database scoped credential failed (action_id RWC; class_type DC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24350\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24350} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24350","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24350","Event ID 24350","Revoke permissions with cascade on a database scoped credential failed (action_id RWC; class_type DC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69061,"title":"SQL Server Audit Event 24351 - Revoke permissions with grant on a database scoped credential succeeded (action_id RWG; class_type DC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24351","SQL Server"],"keywords":["24351","event 24351","event id 24351","Revoke permissions with grant on a database scoped credential succeeded (action_id RWG; class_type DC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24351"],"errorCode":"","eventId":"24351","severity":"Medium","summary":"SQL Server Audit event 24351 records: Revoke permissions with grant on a database scoped credential succeeded (action_id RWG; class_type DC)","rootCause":"The configured audit source recorded this activity: Revoke permissions with grant on a database scoped credential succeeded (action_id RWG; class_type DC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24351.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Revoke permissions with grant on a database scoped credential succeeded (action_id RWG; class_type DC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24351\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24351} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24351","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24351","Event ID 24351","Revoke permissions with grant on a database scoped credential succeeded (action_id RWG; class_type DC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69062,"title":"SQL Server Audit Event 24352 - Revoke permissions with grant on a database scoped credential failed (action_id RWG; class_type DC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24352","SQL Server"],"keywords":["24352","event 24352","event id 24352","Revoke permissions with grant on a database scoped credential failed (action_id RWG; class_type DC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24352"],"errorCode":"","eventId":"24352","severity":"High","summary":"SQL Server Audit event 24352 records: Revoke permissions with grant on a database scoped credential failed (action_id RWG; class_type DC)","rootCause":"The audited operation reported a failure: Revoke permissions with grant on a database scoped credential failed (action_id RWG; class_type DC) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24352.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Revoke permissions with grant on a database scoped credential failed (action_id RWG; class_type DC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24352\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24352} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24352","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24352","Event ID 24352","Revoke permissions with grant on a database scoped credential failed (action_id RWG; class_type DC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69063,"title":"SQL Server Audit Event 24353 - Issued a change database scoped credential owner command (action_id TO; class_type DC)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24353","SQL Server"],"keywords":["24353","event 24353","event id 24353","Issued a change database scoped credential owner command (action_id TO; class_type DC)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24353"],"errorCode":"","eventId":"24353","severity":"Low","summary":"SQL Server Audit event 24353 records: Issued a change database scoped credential owner command (action_id TO; class_type DC)","rootCause":"The configured audit source recorded this activity: Issued a change database scoped credential owner command (action_id TO; class_type DC) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24353.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change database scoped credential owner command (action_id TO; class_type DC)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24353\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24353} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24353","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24353","Event ID 24353","Issued a change database scoped credential owner command (action_id TO; class_type DC)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69064,"title":"SQL Server Audit Event 24354 - Issued a create external library command (action_id CR; class_type EL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24354","SQL Server"],"keywords":["24354","event 24354","event id 24354","Issued a create external library command (action_id CR; class_type EL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24354"],"errorCode":"","eventId":"24354","severity":"Low","summary":"SQL Server Audit event 24354 records: Issued a create external library command (action_id CR; class_type EL)","rootCause":"The configured audit source recorded this activity: Issued a create external library command (action_id CR; class_type EL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24354.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create external library command (action_id CR; class_type EL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24354\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24354} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24354","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24354","Event ID 24354","Issued a create external library command (action_id CR; class_type EL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69065,"title":"SQL Server Audit Event 24355 - Issued a change external library command (action_id AL; class_type EL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24355","SQL Server"],"keywords":["24355","event 24355","event id 24355","Issued a change external library command (action_id AL; class_type EL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24355"],"errorCode":"","eventId":"24355","severity":"Low","summary":"SQL Server Audit event 24355 records: Issued a change external library command (action_id AL; class_type EL)","rootCause":"The configured audit source recorded this activity: Issued a change external library command (action_id AL; class_type EL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24355.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change external library command (action_id AL; class_type EL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24355\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24355} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24355","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24355","Event ID 24355","Issued a change external library command (action_id AL; class_type EL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69066,"title":"SQL Server Audit Event 24356 - Issued a drop external library command (action_id DR; class_type EL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24356","SQL Server"],"keywords":["24356","event 24356","event id 24356","Issued a drop external library command (action_id DR; class_type EL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24356"],"errorCode":"","eventId":"24356","severity":"Low","summary":"SQL Server Audit event 24356 records: Issued a drop external library command (action_id DR; class_type EL)","rootCause":"The configured audit source recorded this activity: Issued a drop external library command (action_id DR; class_type EL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24356.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a drop external library command (action_id DR; class_type EL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24356\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24356} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24356","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24356","Event ID 24356","Issued a drop external library command (action_id DR; class_type EL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69067,"title":"SQL Server Audit Event 24357 - Grant permissions on an external library succeeded (action_id G; class_type EL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24357","SQL Server"],"keywords":["24357","event 24357","event id 24357","Grant permissions on an external library succeeded (action_id G; class_type EL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24357"],"errorCode":"","eventId":"24357","severity":"Medium","summary":"SQL Server Audit event 24357 records: Grant permissions on an external library succeeded (action_id G; class_type EL)","rootCause":"The configured audit source recorded this activity: Grant permissions on an external library succeeded (action_id G; class_type EL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24357.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Grant permissions on an external library succeeded (action_id G; class_type EL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24357\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24357} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24357","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24357","Event ID 24357","Grant permissions on an external library succeeded (action_id G; class_type EL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69068,"title":"SQL Server Audit Event 24358 - Grant permissions on an external library failed (action_id G; class_type EL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24358","SQL Server"],"keywords":["24358","event 24358","event id 24358","Grant permissions on an external library failed (action_id G; class_type EL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24358"],"errorCode":"","eventId":"24358","severity":"High","summary":"SQL Server Audit event 24358 records: Grant permissions on an external library failed (action_id G; class_type EL)","rootCause":"The audited operation reported a failure: Grant permissions on an external library failed (action_id G; class_type EL) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24358.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Grant permissions on an external library failed (action_id G; class_type EL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24358\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24358} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24358","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24358","Event ID 24358","Grant permissions on an external library failed (action_id G; class_type EL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69069,"title":"SQL Server Audit Event 24359 - Grant permissions on an external library with grant succeeded (action_id GWG; class_type EL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24359","SQL Server"],"keywords":["24359","event 24359","event id 24359","Grant permissions on an external library with grant succeeded (action_id GWG; class_type EL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24359"],"errorCode":"","eventId":"24359","severity":"Medium","summary":"SQL Server Audit event 24359 records: Grant permissions on an external library with grant succeeded (action_id GWG; class_type EL)","rootCause":"The configured audit source recorded this activity: Grant permissions on an external library with grant succeeded (action_id GWG; class_type EL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24359.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Grant permissions on an external library with grant succeeded (action_id GWG; class_type EL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24359\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24359} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24359","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24359","Event ID 24359","Grant permissions on an external library with grant succeeded (action_id GWG; class_type EL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69070,"title":"SQL Server Audit Event 24360 - Grant permissions on an external library with grant failed (action_id GWG; class_type EL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24360","SQL Server"],"keywords":["24360","event 24360","event id 24360","Grant permissions on an external library with grant failed (action_id GWG; class_type EL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24360"],"errorCode":"","eventId":"24360","severity":"High","summary":"SQL Server Audit event 24360 records: Grant permissions on an external library with grant failed (action_id GWG; class_type EL)","rootCause":"The audited operation reported a failure: Grant permissions on an external library with grant failed (action_id GWG; class_type EL) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24360.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Grant permissions on an external library with grant failed (action_id GWG; class_type EL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24360\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24360} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24360","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24360","Event ID 24360","Grant permissions on an external library with grant failed (action_id GWG; class_type EL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69071,"title":"SQL Server Audit Event 24361 - Deny permissions on an external library succeeded (action_id D; class_type EL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24361","SQL Server"],"keywords":["24361","event 24361","event id 24361","Deny permissions on an external library succeeded (action_id D; class_type EL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24361"],"errorCode":"","eventId":"24361","severity":"Medium","summary":"SQL Server Audit event 24361 records: Deny permissions on an external library succeeded (action_id D; class_type EL)","rootCause":"The configured audit source recorded this activity: Deny permissions on an external library succeeded (action_id D; class_type EL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24361.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Deny permissions on an external library succeeded (action_id D; class_type EL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24361\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24361} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24361","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24361","Event ID 24361","Deny permissions on an external library succeeded (action_id D; class_type EL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69072,"title":"SQL Server Audit Event 24362 - Deny permissions on an external library failed (action_id D; class_type EL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24362","SQL Server"],"keywords":["24362","event 24362","event id 24362","Deny permissions on an external library failed (action_id D; class_type EL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24362"],"errorCode":"","eventId":"24362","severity":"High","summary":"SQL Server Audit event 24362 records: Deny permissions on an external library failed (action_id D; class_type EL)","rootCause":"The audited operation reported a failure: Deny permissions on an external library failed (action_id D; class_type EL) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24362.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Deny permissions on an external library failed (action_id D; class_type EL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24362\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24362} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24362","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24362","Event ID 24362","Deny permissions on an external library failed (action_id D; class_type EL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69073,"title":"SQL Server Audit Event 24363 - Deny permissions on an external library with cascade succeeded (action_id DWC; class_type EL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24363","SQL Server"],"keywords":["24363","event 24363","event id 24363","Deny permissions on an external library with cascade succeeded (action_id DWC; class_type EL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24363"],"errorCode":"","eventId":"24363","severity":"Medium","summary":"SQL Server Audit event 24363 records: Deny permissions on an external library with cascade succeeded (action_id DWC; class_type EL)","rootCause":"The configured audit source recorded this activity: Deny permissions on an external library with cascade succeeded (action_id DWC; class_type EL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24363.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Deny permissions on an external library with cascade succeeded (action_id DWC; class_type EL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24363\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24363} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24363","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24363","Event ID 24363","Deny permissions on an external library with cascade succeeded (action_id DWC; class_type EL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69074,"title":"SQL Server Audit Event 24364 - Deny permissions on an external library with cascade failed (action_id DWC; class_type EL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24364","SQL Server"],"keywords":["24364","event 24364","event id 24364","Deny permissions on an external library with cascade failed (action_id DWC; class_type EL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24364"],"errorCode":"","eventId":"24364","severity":"High","summary":"SQL Server Audit event 24364 records: Deny permissions on an external library with cascade failed (action_id DWC; class_type EL)","rootCause":"The audited operation reported a failure: Deny permissions on an external library with cascade failed (action_id DWC; class_type EL) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24364.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Deny permissions on an external library with cascade failed (action_id DWC; class_type EL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24364\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24364} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24364","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24364","Event ID 24364","Deny permissions on an external library with cascade failed (action_id DWC; class_type EL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69075,"title":"SQL Server Audit Event 24365 - Revoke permissions on an external library succeeded (action_id R; class_type EL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24365","SQL Server"],"keywords":["24365","event 24365","event id 24365","Revoke permissions on an external library succeeded (action_id R; class_type EL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24365"],"errorCode":"","eventId":"24365","severity":"Medium","summary":"SQL Server Audit event 24365 records: Revoke permissions on an external library succeeded (action_id R; class_type EL)","rootCause":"The configured audit source recorded this activity: Revoke permissions on an external library succeeded (action_id R; class_type EL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24365.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Revoke permissions on an external library succeeded (action_id R; class_type EL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24365\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24365} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24365","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24365","Event ID 24365","Revoke permissions on an external library succeeded (action_id R; class_type EL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69076,"title":"SQL Server Audit Event 24366 - Revoke permissions on an external library failed (action_id R; class_type EL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24366","SQL Server"],"keywords":["24366","event 24366","event id 24366","Revoke permissions on an external library failed (action_id R; class_type EL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24366"],"errorCode":"","eventId":"24366","severity":"High","summary":"SQL Server Audit event 24366 records: Revoke permissions on an external library failed (action_id R; class_type EL)","rootCause":"The audited operation reported a failure: Revoke permissions on an external library failed (action_id R; class_type EL) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24366.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Revoke permissions on an external library failed (action_id R; class_type EL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24366\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24366} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24366","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24366","Event ID 24366","Revoke permissions on an external library failed (action_id R; class_type EL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69077,"title":"SQL Server Audit Event 24367 - Revoke permissions with cascade on an external library succeeded (action_id RWC; class_type EL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24367","SQL Server"],"keywords":["24367","event 24367","event id 24367","Revoke permissions with cascade on an external library succeeded (action_id RWC; class_type EL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24367"],"errorCode":"","eventId":"24367","severity":"Medium","summary":"SQL Server Audit event 24367 records: Revoke permissions with cascade on an external library succeeded (action_id RWC; class_type EL)","rootCause":"The configured audit source recorded this activity: Revoke permissions with cascade on an external library succeeded (action_id RWC; class_type EL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24367.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Revoke permissions with cascade on an external library succeeded (action_id RWC; class_type EL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24367\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24367} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24367","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24367","Event ID 24367","Revoke permissions with cascade on an external library succeeded (action_id RWC; class_type EL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69078,"title":"SQL Server Audit Event 24368 - Revoke permissions with cascade on an external library failed (action_id RWC; class_type EL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24368","SQL Server"],"keywords":["24368","event 24368","event id 24368","Revoke permissions with cascade on an external library failed (action_id RWC; class_type EL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24368"],"errorCode":"","eventId":"24368","severity":"High","summary":"SQL Server Audit event 24368 records: Revoke permissions with cascade on an external library failed (action_id RWC; class_type EL)","rootCause":"The audited operation reported a failure: Revoke permissions with cascade on an external library failed (action_id RWC; class_type EL) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24368.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Revoke permissions with cascade on an external library failed (action_id RWC; class_type EL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24368\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24368} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24368","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24368","Event ID 24368","Revoke permissions with cascade on an external library failed (action_id RWC; class_type EL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69079,"title":"SQL Server Audit Event 24369 - Revoke permissions with grant on an external library succeeded (action_id RWG; class_type EL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24369","SQL Server"],"keywords":["24369","event 24369","event id 24369","Revoke permissions with grant on an external library succeeded (action_id RWG; class_type EL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24369"],"errorCode":"","eventId":"24369","severity":"Medium","summary":"SQL Server Audit event 24369 records: Revoke permissions with grant on an external library succeeded (action_id RWG; class_type EL)","rootCause":"The configured audit source recorded this activity: Revoke permissions with grant on an external library succeeded (action_id RWG; class_type EL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24369.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Revoke permissions with grant on an external library succeeded (action_id RWG; class_type EL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24369\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24369} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24369","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24369","Event ID 24369","Revoke permissions with grant on an external library succeeded (action_id RWG; class_type EL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69080,"title":"SQL Server Audit Event 24370 - Revoke permissions with grant on an external library failed (action_id RWG; class_type EL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24370","SQL Server"],"keywords":["24370","event 24370","event id 24370","Revoke permissions with grant on an external library failed (action_id RWG; class_type EL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24370"],"errorCode":"","eventId":"24370","severity":"High","summary":"SQL Server Audit event 24370 records: Revoke permissions with grant on an external library failed (action_id RWG; class_type EL)","rootCause":"The audited operation reported a failure: Revoke permissions with grant on an external library failed (action_id RWG; class_type EL) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24370.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Revoke permissions with grant on an external library failed (action_id RWG; class_type EL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24370\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24370} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24370","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24370","Event ID 24370","Revoke permissions with grant on an external library failed (action_id RWG; class_type EL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69081,"title":"SQL Server Audit Event 24371 - Issued a create database scoped resource governor command (action_id CR; class_type DR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24371","SQL Server"],"keywords":["24371","event 24371","event id 24371","Issued a create database scoped resource governor command (action_id CR; class_type DR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24371"],"errorCode":"","eventId":"24371","severity":"Low","summary":"SQL Server Audit event 24371 records: Issued a create database scoped resource governor command (action_id CR; class_type DR)","rootCause":"The configured audit source recorded this activity: Issued a create database scoped resource governor command (action_id CR; class_type DR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24371.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create database scoped resource governor command (action_id CR; class_type DR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24371\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24371} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24371","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24371","Event ID 24371","Issued a create database scoped resource governor command (action_id CR; class_type DR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69082,"title":"SQL Server Audit Event 24372 - Issued a change database scoped resource governor command (action_id AL; class_type DR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24372","SQL Server"],"keywords":["24372","event 24372","event id 24372","Issued a change database scoped resource governor command (action_id AL; class_type DR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24372"],"errorCode":"","eventId":"24372","severity":"Low","summary":"SQL Server Audit event 24372 records: Issued a change database scoped resource governor command (action_id AL; class_type DR)","rootCause":"The configured audit source recorded this activity: Issued a change database scoped resource governor command (action_id AL; class_type DR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24372.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change database scoped resource governor command (action_id AL; class_type DR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24372\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24372} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24372","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24372","Event ID 24372","Issued a change database scoped resource governor command (action_id AL; class_type DR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69083,"title":"SQL Server Audit Event 24373 - Issued a drop database scoped resource governor command (action_id DR; class_type DR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24373","SQL Server"],"keywords":["24373","event 24373","event id 24373","Issued a drop database scoped resource governor command (action_id DR; class_type DR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24373"],"errorCode":"","eventId":"24373","severity":"Low","summary":"SQL Server Audit event 24373 records: Issued a drop database scoped resource governor command (action_id DR; class_type DR)","rootCause":"The configured audit source recorded this activity: Issued a drop database scoped resource governor command (action_id DR; class_type DR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24373.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a drop database scoped resource governor command (action_id DR; class_type DR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24373\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24373} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24373","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24373","Event ID 24373","Issued a drop database scoped resource governor command (action_id DR; class_type DR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69084,"title":"SQL Server Audit Event 24374 - Issued a database bulk administration command (action_id DABO; class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24374","SQL Server"],"keywords":["24374","event 24374","event id 24374","Issued a database bulk administration command (action_id DABO; class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24374"],"errorCode":"","eventId":"24374","severity":"Low","summary":"SQL Server Audit event 24374 records: Issued a database bulk administration command (action_id DABO; class_type DB)","rootCause":"The configured audit source recorded this activity: Issued a database bulk administration command (action_id DABO; class_type DB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24374.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a database bulk administration command (action_id DABO; class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24374\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24374} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24374","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24374","Event ID 24374","Issued a database bulk administration command (action_id DABO; class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69085,"title":"SQL Server Audit Event 24375 - Command to change permission failed (action_id D, DWC, G, GWG, R, RWC, RWG; class_type DC, EL)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24375","SQL Server"],"keywords":["24375","event 24375","event id 24375","Command to change permission failed (action_id D, DWC, G, GWG, R, RWC, RWG; class_type DC, EL)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24375"],"errorCode":"","eventId":"24375","severity":"High","summary":"SQL Server Audit event 24375 records: Command to change permission failed (action_id D, DWC, G, GWG, R, RWC, RWG; class_type DC, EL)","rootCause":"The audited operation reported a failure: Command to change permission failed (action_id D, DWC, G, GWG, R, RWC, RWG; class_type DC, EL) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24375.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Command to change permission failed (action_id D, DWC, G, GWG, R, RWC, RWG; class_type DC, EL)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24375\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24375} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24375","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24375","Event ID 24375","Command to change permission failed (action_id D, DWC, G, GWG, R, RWC, RWG; class_type DC, EL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69086,"title":"SQL Server Audit Event 24376 - Issued a change database sensitivity classification command (action_id SCCG; class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24376","SQL Server"],"keywords":["24376","event 24376","event id 24376","Issued a change database sensitivity classification command (action_id SCCG; class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24376"],"errorCode":"","eventId":"24376","severity":"Low","summary":"SQL Server Audit event 24376 records: Issued a change database sensitivity classification command (action_id SCCG; class_type DB)","rootCause":"The configured audit source recorded this activity: Issued a change database sensitivity classification command (action_id SCCG; class_type DB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24376.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change database sensitivity classification command (action_id SCCG; class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24376\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24376} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24376","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24376","Event ID 24376","Issued a change database sensitivity classification command (action_id SCCG; class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69087,"title":"SQL Server Audit Event 24377 - Issued a change server sensitivity classification command (action_id SCCG; class_type SR)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24377","SQL Server"],"keywords":["24377","event 24377","event id 24377","Issued a change server sensitivity classification command (action_id SCCG; class_type SR)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24377"],"errorCode":"","eventId":"24377","severity":"Low","summary":"SQL Server Audit event 24377 records: Issued a change server sensitivity classification command (action_id SCCG; class_type SR)","rootCause":"The configured audit source recorded this activity: Issued a change server sensitivity classification command (action_id SCCG; class_type SR) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24377.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a change server sensitivity classification command (action_id SCCG; class_type SR)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24377\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24377} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24377","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24377","Event ID 24377","Issued a change server sensitivity classification command (action_id SCCG; class_type SR)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69088,"title":"SQL Server Audit Event 24378 - Issued an add sensitivity classification command (action_id ADSC; class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24378","SQL Server"],"keywords":["24378","event 24378","event id 24378","Issued an add sensitivity classification command (action_id ADSC; class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24378"],"errorCode":"","eventId":"24378","severity":"Low","summary":"SQL Server Audit event 24378 records: Issued an add sensitivity classification command (action_id ADSC; class_type DB)","rootCause":"The configured audit source recorded this activity: Issued an add sensitivity classification command (action_id ADSC; class_type DB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24378.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued an add sensitivity classification command (action_id ADSC; class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24378\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24378} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24378","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24378","Event ID 24378","Issued an add sensitivity classification command (action_id ADSC; class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69089,"title":"SQL Server Audit Event 24379 - Issued a drop sensitivity classification command (action_id DRSC; class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24379","SQL Server"],"keywords":["24379","event 24379","event id 24379","Issued a drop sensitivity classification command (action_id DRSC; class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24379"],"errorCode":"","eventId":"24379","severity":"Low","summary":"SQL Server Audit event 24379 records: Issued a drop sensitivity classification command (action_id DRSC; class_type DB)","rootCause":"The configured audit source recorded this activity: Issued a drop sensitivity classification command (action_id DRSC; class_type DB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24379.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a drop sensitivity classification command (action_id DRSC; class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24379\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24379} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24379","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24379","Event ID 24379","Issued a drop sensitivity classification command (action_id DRSC; class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69090,"title":"SQL Server Audit Event 24380 - Issued a deny credential command (action_id D, DWC; class_type CD)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24380","SQL Server"],"keywords":["24380","event 24380","event id 24380","Issued a deny credential command (action_id D, DWC; class_type CD)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24380"],"errorCode":"","eventId":"24380","severity":"Low","summary":"SQL Server Audit event 24380 records: Issued a deny credential command (action_id D, DWC; class_type CD)","rootCause":"The configured audit source recorded this activity: Issued a deny credential command (action_id D, DWC; class_type CD) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24380.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a deny credential command (action_id D, DWC; class_type CD)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24380\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24380} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24380","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24380","Event ID 24380","Issued a deny credential command (action_id D, DWC; class_type CD)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69091,"title":"SQL Server Audit Event 24381 - Issued a grant credential command (action_id G, GWG; class_type CD)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24381","SQL Server"],"keywords":["24381","event 24381","event id 24381","Issued a grant credential command (action_id G, GWG; class_type CD)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24381"],"errorCode":"","eventId":"24381","severity":"Low","summary":"SQL Server Audit event 24381 records: Issued a grant credential command (action_id G, GWG; class_type CD)","rootCause":"The configured audit source recorded this activity: Issued a grant credential command (action_id G, GWG; class_type CD) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24381.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a grant credential command (action_id G, GWG; class_type CD)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24381\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24381} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24381","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24381","Event ID 24381","Issued a grant credential command (action_id G, GWG; class_type CD)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69092,"title":"SQL Server Audit Event 24382 - Issued a revoke credential command (action_id R, RWC, RWG; class_type CD)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24382","SQL Server"],"keywords":["24382","event 24382","event id 24382","Issued a revoke credential command (action_id R, RWC, RWG; class_type CD)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24382"],"errorCode":"","eventId":"24382","severity":"Low","summary":"SQL Server Audit event 24382 records: Issued a revoke credential command (action_id R, RWC, RWG; class_type CD)","rootCause":"The configured audit source recorded this activity: Issued a revoke credential command (action_id R, RWC, RWG; class_type CD) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24382.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a revoke credential command (action_id R, RWC, RWG; class_type CD)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24382\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24382} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24382","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24382","Event ID 24382","Issued a revoke credential command (action_id R, RWC, RWG; class_type CD)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69093,"title":"SQL Server Audit Event 24383 - Issued a ledger operation command (action_id ALRC, GDLR, VFLR; class_type DB and action_id ALLR, ENLR; class_type OB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24383","SQL Server"],"keywords":["24383","event 24383","event id 24383","Issued a ledger operation command (action_id ALRC, GDLR, VFLR; class_type DB and action_id ALLR, ENLR; class_type OB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24383"],"errorCode":"","eventId":"24383","severity":"Low","summary":"SQL Server Audit event 24383 records: Issued a ledger operation command (action_id ALRC, GDLR, VFLR; class_type DB and action_id ALLR, ENLR; class_type OB)","rootCause":"The configured audit source recorded this activity: Issued a ledger operation command (action_id ALRC, GDLR, VFLR; class_type DB and action_id ALLR, ENLR; class_type OB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24383.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a ledger operation command (action_id ALRC, GDLR, VFLR; class_type DB and action_id ALLR, ENLR; class_type OB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24383\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24383} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24383","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24383","Event ID 24383","Issued a ledger operation command (action_id ALRC, GDLR, VFLR; class_type DB and action_id ALLR, ENLR; class_type OB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69094,"title":"SQL Server Audit Event 24384 - Issued an external governance policy pull command (action_id EGDP, EGFP; class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24384","SQL Server"],"keywords":["24384","event 24384","event id 24384","Issued an external governance policy pull command (action_id EGDP, EGFP; class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24384"],"errorCode":"","eventId":"24384","severity":"Medium","summary":"SQL Server Audit event 24384 records: Issued an external governance policy pull command (action_id EGDP, EGFP; class_type DB)","rootCause":"The configured audit source recorded this activity: Issued an external governance policy pull command (action_id EGDP, EGFP; class_type DB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24384.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued an external governance policy pull command (action_id EGDP, EGFP; class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24384\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24384} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24384","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24384","Event ID 24384","Issued an external governance policy pull command (action_id EGDP, EGFP; class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69095,"title":"SQL Server Audit Event 24385 - A sensitive call or batch completed (action_id SBC, SRC; class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24385","SQL Server"],"keywords":["24385","event 24385","event id 24385","A sensitive call or batch completed (action_id SBC, SRC; class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24385"],"errorCode":"","eventId":"24385","severity":"Low","summary":"SQL Server Audit event 24385 records: A sensitive call or batch completed (action_id SBC, SRC; class_type DB)","rootCause":"The configured audit source recorded this activity: A sensitive call or batch completed (action_id SBC, SRC; class_type DB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24385.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A sensitive call or batch completed (action_id SBC, SRC; class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24385\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24385} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24385","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24385","Event ID 24385","A sensitive call or batch completed (action_id SBC, SRC; class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69096,"title":"SQL Server Audit Event 24386 - Issued an external streaming job operation command (action_id AL, CR, DR; class_type EJ)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24386","SQL Server"],"keywords":["24386","event 24386","event id 24386","Issued an external streaming job operation command (action_id AL, CR, DR; class_type EJ)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24386"],"errorCode":"","eventId":"24386","severity":"Low","summary":"SQL Server Audit event 24386 records: Issued an external streaming job operation command (action_id AL, CR, DR; class_type EJ)","rootCause":"The configured audit source recorded this activity: Issued an external streaming job operation command (action_id AL, CR, DR; class_type EJ) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24386.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued an external streaming job operation command (action_id AL, CR, DR; class_type EJ)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24386\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24386} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24386","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24386","Event ID 24386","Issued an external streaming job operation command (action_id AL, CR, DR; class_type EJ)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69097,"title":"SQL Server Audit Event 24387 - Issued an external stream operation command (action_id AL, CR, DR; class_type ES)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24387","SQL Server"],"keywords":["24387","event 24387","event id 24387","Issued an external stream operation command (action_id AL, CR, DR; class_type ES)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24387"],"errorCode":"","eventId":"24387","severity":"Low","summary":"SQL Server Audit event 24387 records: Issued an external stream operation command (action_id AL, CR, DR; class_type ES)","rootCause":"The configured audit source recorded this activity: Issued an external stream operation command (action_id AL, CR, DR; class_type ES) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24387.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued an external stream operation command (action_id AL, CR, DR; class_type ES)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24387\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24387} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24387","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24387","Event ID 24387","Issued an external stream operation command (action_id AL, CR, DR; class_type ES)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69098,"title":"SQL Server Audit Event 24388 - Issued an alter external model command (action_id AL; class_type EM)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24388","SQL Server"],"keywords":["24388","event 24388","event id 24388","Issued an alter external model command (action_id AL; class_type EM)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24388"],"errorCode":"","eventId":"24388","severity":"Low","summary":"SQL Server Audit event 24388 records: Issued an alter external model command (action_id AL; class_type EM)","rootCause":"The configured audit source recorded this activity: Issued an alter external model command (action_id AL; class_type EM) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24388.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued an alter external model command (action_id AL; class_type EM)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24388\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24388} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24388","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24388","Event ID 24388","Issued an alter external model command (action_id AL; class_type EM)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69099,"title":"SQL Server Audit Event 24389 - Issued a create external model command (action_id CR; class_type EM)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24389","SQL Server"],"keywords":["24389","event 24389","event id 24389","Issued a create external model command (action_id CR; class_type EM)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24389"],"errorCode":"","eventId":"24389","severity":"Low","summary":"SQL Server Audit event 24389 records: Issued a create external model command (action_id CR; class_type EM)","rootCause":"The configured audit source recorded this activity: Issued a create external model command (action_id CR; class_type EM) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24389.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a create external model command (action_id CR; class_type EM)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24389\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24389} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24389","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24389","Event ID 24389","Issued a create external model command (action_id CR; class_type EM)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69100,"title":"SQL Server Audit Event 24390 - Issued a drop external model command (action_id DR; class_type EM)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24390","SQL Server"],"keywords":["24390","event 24390","event id 24390","Issued a drop external model command (action_id DR; class_type EM)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24390"],"errorCode":"","eventId":"24390","severity":"Low","summary":"SQL Server Audit event 24390 records: Issued a drop external model command (action_id DR; class_type EM)","rootCause":"The configured audit source recorded this activity: Issued a drop external model command (action_id DR; class_type EM) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24390.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a drop external model command (action_id DR; class_type EM)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24390\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24390} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24390","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24390","Event ID 24390","Issued a drop external model command (action_id DR; class_type EM)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69101,"title":"SQL Server Audit Event 24391 - Issued a deny external model permission command (action_id D; class_type EM)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24391","SQL Server"],"keywords":["24391","event 24391","event id 24391","Issued a deny external model permission command (action_id D; class_type EM)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24391"],"errorCode":"","eventId":"24391","severity":"Medium","summary":"SQL Server Audit event 24391 records: Issued a deny external model permission command (action_id D; class_type EM)","rootCause":"The configured audit source recorded this activity: Issued a deny external model permission command (action_id D; class_type EM) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24391.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a deny external model permission command (action_id D; class_type EM)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24391\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24391} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24391","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24391","Event ID 24391","Issued a deny external model permission command (action_id D; class_type EM)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69102,"title":"SQL Server Audit Event 24392 - Issued a deny with cascade external model permission command (action_id DWC; class_type EM)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24392","SQL Server"],"keywords":["24392","event 24392","event id 24392","Issued a deny with cascade external model permission command (action_id DWC; class_type EM)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24392"],"errorCode":"","eventId":"24392","severity":"Medium","summary":"SQL Server Audit event 24392 records: Issued a deny with cascade external model permission command (action_id DWC; class_type EM)","rootCause":"The configured audit source recorded this activity: Issued a deny with cascade external model permission command (action_id DWC; class_type EM) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24392.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a deny with cascade external model permission command (action_id DWC; class_type EM)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24392\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24392} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24392","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24392","Event ID 24392","Issued a deny with cascade external model permission command (action_id DWC; class_type EM)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69103,"title":"SQL Server Audit Event 24393 - Issued an execute external model permission command (action_id EX; class_type EM)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24393","SQL Server"],"keywords":["24393","event 24393","event id 24393","Issued an execute external model permission command (action_id EX; class_type EM)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24393"],"errorCode":"","eventId":"24393","severity":"Medium","summary":"SQL Server Audit event 24393 records: Issued an execute external model permission command (action_id EX; class_type EM)","rootCause":"The configured audit source recorded this activity: Issued an execute external model permission command (action_id EX; class_type EM) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24393.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued an execute external model permission command (action_id EX; class_type EM)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24393\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24393} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24393","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24393","Event ID 24393","Issued an execute external model permission command (action_id EX; class_type EM)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69104,"title":"SQL Server Audit Event 24394 - Issued a grant external model permission command (action_id G; class_type EM)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24394","SQL Server"],"keywords":["24394","event 24394","event id 24394","Issued a grant external model permission command (action_id G; class_type EM)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24394"],"errorCode":"","eventId":"24394","severity":"Medium","summary":"SQL Server Audit event 24394 records: Issued a grant external model permission command (action_id G; class_type EM)","rootCause":"The configured audit source recorded this activity: Issued a grant external model permission command (action_id G; class_type EM) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24394.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a grant external model permission command (action_id G; class_type EM)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24394\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24394} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24394","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24394","Event ID 24394","Issued a grant external model permission command (action_id G; class_type EM)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69105,"title":"SQL Server Audit Event 24395 - Issued a grant with grant external model permission command (action_id GWG; class_type EM)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24395","SQL Server"],"keywords":["24395","event 24395","event id 24395","Issued a grant with grant external model permission command (action_id GWG; class_type EM)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24395"],"errorCode":"","eventId":"24395","severity":"Medium","summary":"SQL Server Audit event 24395 records: Issued a grant with grant external model permission command (action_id GWG; class_type EM)","rootCause":"The configured audit source recorded this activity: Issued a grant with grant external model permission command (action_id GWG; class_type EM) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24395.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a grant with grant external model permission command (action_id GWG; class_type EM)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24395\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24395} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24395","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24395","Event ID 24395","Issued a grant with grant external model permission command (action_id GWG; class_type EM)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69106,"title":"SQL Server Audit Event 24396 - Issued a revoke external model permission command (action_id R; class_type EM)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24396","SQL Server"],"keywords":["24396","event 24396","event id 24396","Issued a revoke external model permission command (action_id R; class_type EM)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24396"],"errorCode":"","eventId":"24396","severity":"Medium","summary":"SQL Server Audit event 24396 records: Issued a revoke external model permission command (action_id R; class_type EM)","rootCause":"The configured audit source recorded this activity: Issued a revoke external model permission command (action_id R; class_type EM) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24396.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a revoke external model permission command (action_id R; class_type EM)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24396\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24396} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24396","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24396","Event ID 24396","Issued a revoke external model permission command (action_id R; class_type EM)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69107,"title":"SQL Server Audit Event 24397 - Issued a revoke with cascade external model permission command (action_id RWC; class_type EM)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24397","SQL Server"],"keywords":["24397","event 24397","event id 24397","Issued a revoke with cascade external model permission command (action_id RWC; class_type EM)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24397"],"errorCode":"","eventId":"24397","severity":"Medium","summary":"SQL Server Audit event 24397 records: Issued a revoke with cascade external model permission command (action_id RWC; class_type EM)","rootCause":"The configured audit source recorded this activity: Issued a revoke with cascade external model permission command (action_id RWC; class_type EM) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24397.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a revoke with cascade external model permission command (action_id RWC; class_type EM)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24397\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24397} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24397","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24397","Event ID 24397","Issued a revoke with cascade external model permission command (action_id RWC; class_type EM)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69108,"title":"SQL Server Audit Event 24398 - Issued a revoke with grant external model permission command (action_id RWG; class_type EM)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24398","SQL Server"],"keywords":["24398","event 24398","event id 24398","Issued a revoke with grant external model permission command (action_id RWG; class_type EM)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24398"],"errorCode":"","eventId":"24398","severity":"Medium","summary":"SQL Server Audit event 24398 records: Issued a revoke with grant external model permission command (action_id RWG; class_type EM)","rootCause":"The configured audit source recorded this activity: Issued a revoke with grant external model permission command (action_id RWG; class_type EM) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24398.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a revoke with grant external model permission command (action_id RWG; class_type EM)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24398\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24398} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24398","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24398","Event ID 24398","Issued a revoke with grant external model permission command (action_id RWG; class_type EM)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69109,"title":"SQL Server Audit Event 24399 - Issued a take external model ownership command (action_id TO; class_type EM)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24399","SQL Server"],"keywords":["24399","event 24399","event id 24399","Issued a take external model ownership command (action_id TO; class_type EM)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24399"],"errorCode":"","eventId":"24399","severity":"Low","summary":"SQL Server Audit event 24399 records: Issued a take external model ownership command (action_id TO; class_type EM)","rootCause":"The configured audit source recorded this activity: Issued a take external model ownership command (action_id TO; class_type EM) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24399.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Issued a take external model ownership command (action_id TO; class_type EM)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24399\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24399} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24399","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24399","Event ID 24399","Issued a take external model ownership command (action_id TO; class_type EM)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69110,"title":"SQL Server Audit Event 24400 - Batch start succeeded (action_id BST; class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24400","SQL Server"],"keywords":["24400","event 24400","event id 24400","Batch start succeeded (action_id BST; class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24400"],"errorCode":"","eventId":"24400","severity":"Low","summary":"SQL Server Audit event 24400 records: Batch start succeeded (action_id BST; class_type DB)","rootCause":"The configured audit source recorded this activity: Batch start succeeded (action_id BST; class_type DB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24400.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Batch start succeeded (action_id BST; class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24400\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24400} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24400","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24400","Event ID 24400","Batch start succeeded (action_id BST; class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69111,"title":"SQL Server Audit Event 24401 - Batch start failed (action_id BST; class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24401","SQL Server"],"keywords":["24401","event 24401","event id 24401","Batch start failed (action_id BST; class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24401"],"errorCode":"","eventId":"24401","severity":"High","summary":"SQL Server Audit event 24401 records: Batch start failed (action_id BST; class_type DB)","rootCause":"The audited operation reported a failure: Batch start failed (action_id BST; class_type DB) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24401.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Batch start failed (action_id BST; class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24401\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24401} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24401","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24401","Event ID 24401","Batch start failed (action_id BST; class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69112,"title":"SQL Server Audit Event 24402 - Batch complete succeeded (action_id BCM; class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24402","SQL Server"],"keywords":["24402","event 24402","event id 24402","Batch complete succeeded (action_id BCM; class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24402"],"errorCode":"","eventId":"24402","severity":"Low","summary":"SQL Server Audit event 24402 records: Batch complete succeeded (action_id BCM; class_type DB)","rootCause":"The configured audit source recorded this activity: Batch complete succeeded (action_id BCM; class_type DB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24402.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Batch complete succeeded (action_id BCM; class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24402\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24402} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24402","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24402","Event ID 24402","Batch complete succeeded (action_id BCM; class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69113,"title":"SQL Server Audit Event 24403 - Batch complete failed (action_id BCM; class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24403","SQL Server"],"keywords":["24403","event 24403","event id 24403","Batch complete failed (action_id BCM; class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24403"],"errorCode":"","eventId":"24403","severity":"High","summary":"SQL Server Audit event 24403 records: Batch complete failed (action_id BCM; class_type DB)","rootCause":"The audited operation reported a failure: Batch complete failed (action_id BCM; class_type DB) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24403.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Batch complete failed (action_id BCM; class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24403\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24403} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24403","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24403","Event ID 24403","Batch complete failed (action_id BCM; class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69114,"title":"SQL Server Audit Event 24404 - RPC start succeeded (action_id RST; class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24404","SQL Server"],"keywords":["24404","event 24404","event id 24404","RPC start succeeded (action_id RST; class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24404"],"errorCode":"","eventId":"24404","severity":"Low","summary":"SQL Server Audit event 24404 records: RPC start succeeded (action_id RST; class_type DB)","rootCause":"The configured audit source recorded this activity: RPC start succeeded (action_id RST; class_type DB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24404.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: RPC start succeeded (action_id RST; class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24404\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24404} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24404","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24404","Event ID 24404","RPC start succeeded (action_id RST; class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69115,"title":"SQL Server Audit Event 24405 - RPC start failed (action_id RST; class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24405","SQL Server"],"keywords":["24405","event 24405","event id 24405","RPC start failed (action_id RST; class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24405"],"errorCode":"","eventId":"24405","severity":"High","summary":"SQL Server Audit event 24405 records: RPC start failed (action_id RST; class_type DB)","rootCause":"The audited operation reported a failure: RPC start failed (action_id RST; class_type DB) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24405.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: RPC start failed (action_id RST; class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24405\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24405} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24405","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24405","Event ID 24405","RPC start failed (action_id RST; class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69116,"title":"SQL Server Audit Event 24406 - RPC complete succeeded (action_id RCM; class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24406","SQL Server"],"keywords":["24406","event 24406","event id 24406","RPC complete succeeded (action_id RCM; class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24406"],"errorCode":"","eventId":"24406","severity":"Low","summary":"SQL Server Audit event 24406 records: RPC complete succeeded (action_id RCM; class_type DB)","rootCause":"The configured audit source recorded this activity: RPC complete succeeded (action_id RCM; class_type DB) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24406.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: RPC complete succeeded (action_id RCM; class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24406\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24406} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24406","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24406","Event ID 24406","RPC complete succeeded (action_id RCM; class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69117,"title":"SQL Server Audit Event 24407 - RPC complete failed (action_id RCM; class_type DB)","category":"Windows Server","product":"SQL Server Audit via LOGbinder SQL","tags":["SQL Server Audit","Audit Event","Event ID 24407","SQL Server"],"keywords":["24407","event 24407","event id 24407","RPC complete failed (action_id RCM; class_type DB)","SQL Server Audit","SQL Server Audit via LOGbinder SQL","SQLSERVER-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24407"],"errorCode":"","eventId":"24407","severity":"High","summary":"SQL Server Audit event 24407 records: RPC complete failed (action_id RCM; class_type DB)","rootCause":"The audited operation reported a failure: RPC complete failed (action_id RCM; class_type DB) The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as SQL Server Audit event 24407.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: RPC complete failed (action_id RCM; class_type DB)\n\nContext: This ID is emitted into the Windows Security log by the applicable LOGbinder SQL Server audit integration. It is not a native SQL Server product error code and may not exist where that integration is not installed.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24407\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=24407} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24407","namespace":"SQLSERVER-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["SQL Server","LOGbinder"],"technologies":["Windows Event Log","Audit Logging","SQL Server Audit"],"articleCategories":["Security Logs","Audit Events","SQL Server Audit","SQL Server"],"aliases":["SQL Server Audit 24407","Event ID 24407","RPC complete failed (action_id RCM; class_type DB)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69118,"title":"Sysmon Event 1 - Process creation","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 1","Sysmon"],"keywords":["1","event 1","event id 1","Process creation","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90001"],"errorCode":"","eventId":"1","severity":"Low","summary":"Sysmon event 1 records: Process creation","rootCause":"The configured audit source recorded this activity: Process creation It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 1.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Process creation\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90001\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=1} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90001","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 1","Event ID 1","Process creation"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69119,"title":"Sysmon Event 2 - A process changed a file creation time","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 2","Sysmon"],"keywords":["2","event 2","event id 2","A process changed a file creation time","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90002"],"errorCode":"","eventId":"2","severity":"Medium","summary":"Sysmon event 2 records: A process changed a file creation time","rootCause":"The event records a state-changing operation: A process changed a file creation time It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 2.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A process changed a file creation time\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90002\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=2} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90002","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 2","Event ID 2","A process changed a file creation time"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69120,"title":"Sysmon Event 3 - Network connection detected","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 3","Sysmon"],"keywords":["3","event 3","event id 3","Network connection detected","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90003"],"errorCode":"","eventId":"3","severity":"Low","summary":"Sysmon event 3 records: Network connection detected","rootCause":"The configured audit source recorded this activity: Network connection detected It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 3.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Network connection detected\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90003\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=3} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90003","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 3","Event ID 3","Network connection detected"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69121,"title":"Sysmon Event 4 - Sysmon service state changed","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 4","Sysmon"],"keywords":["4","event 4","event id 4","Sysmon service state changed","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90004"],"errorCode":"","eventId":"4","severity":"Medium","summary":"Sysmon event 4 records: Sysmon service state changed","rootCause":"The event records a state-changing operation: Sysmon service state changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 4.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Sysmon service state changed\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90004\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=4} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90004","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 4","Event ID 4","Sysmon service state changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69122,"title":"Sysmon Event 5 - Process terminated","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 5","Sysmon"],"keywords":["5","event 5","event id 5","Process terminated","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90005"],"errorCode":"","eventId":"5","severity":"Low","summary":"Sysmon event 5 records: Process terminated","rootCause":"The configured audit source recorded this activity: Process terminated It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 5.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Process terminated\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90005\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=5} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90005","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 5","Event ID 5","Process terminated"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69123,"title":"Sysmon Event 6 - Driver loaded","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 6","Sysmon"],"keywords":["6","event 6","event id 6","Driver loaded","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90006"],"errorCode":"","eventId":"6","severity":"Low","summary":"Sysmon event 6 records: Driver loaded","rootCause":"The configured audit source recorded this activity: Driver loaded It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 6.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Driver loaded\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90006\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=6} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90006","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 6","Event ID 6","Driver loaded"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69124,"title":"Sysmon Event 7 - Image loaded","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 7","Sysmon"],"keywords":["7","event 7","event id 7","Image loaded","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90007"],"errorCode":"","eventId":"7","severity":"Low","summary":"Sysmon event 7 records: Image loaded","rootCause":"The configured audit source recorded this activity: Image loaded It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 7.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Image loaded\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90007\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=7} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90007","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 7","Event ID 7","Image loaded"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69125,"title":"Sysmon Event 8 - CreateRemoteThread","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 8","Sysmon"],"keywords":["8","event 8","event id 8","CreateRemoteThread","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90008"],"errorCode":"","eventId":"8","severity":"Low","summary":"Sysmon event 8 records: CreateRemoteThread","rootCause":"The configured audit source recorded this activity: CreateRemoteThread It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 8.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: CreateRemoteThread\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90008\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=8} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90008","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 8","Event ID 8","CreateRemoteThread"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69126,"title":"Sysmon Event 9 - RawAccessRead","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 9","Sysmon"],"keywords":["9","event 9","event id 9","RawAccessRead","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90009"],"errorCode":"","eventId":"9","severity":"Low","summary":"Sysmon event 9 records: RawAccessRead","rootCause":"The configured audit source recorded this activity: RawAccessRead It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 9.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: RawAccessRead\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90009\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=9} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90009","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 9","Event ID 9","RawAccessRead"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69127,"title":"Sysmon Event 10 - ProcessAccess","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 10","Sysmon"],"keywords":["10","event 10","event id 10","ProcessAccess","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90010"],"errorCode":"","eventId":"10","severity":"Low","summary":"Sysmon event 10 records: ProcessAccess","rootCause":"The configured audit source recorded this activity: ProcessAccess It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 10.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: ProcessAccess\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90010\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=10} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90010","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 10","Event ID 10","ProcessAccess"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69128,"title":"Sysmon Event 11 - FileCreate","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 11","Sysmon"],"keywords":["11","event 11","event id 11","FileCreate","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90011"],"errorCode":"","eventId":"11","severity":"Low","summary":"Sysmon event 11 records: FileCreate","rootCause":"The configured audit source recorded this activity: FileCreate It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 11.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: FileCreate\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90011\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=11} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90011","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 11","Event ID 11","FileCreate"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69129,"title":"Sysmon Event 12 - RegistryEvent (Object create and delete)","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 12","Sysmon"],"keywords":["12","event 12","event id 12","RegistryEvent (Object create and delete)","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90012"],"errorCode":"","eventId":"12","severity":"Low","summary":"Sysmon event 12 records: RegistryEvent (Object create and delete)","rootCause":"The configured audit source recorded this activity: RegistryEvent (Object create and delete) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 12.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: RegistryEvent (Object create and delete)\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90012\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=12} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90012","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 12","Event ID 12","RegistryEvent (Object create and delete)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69130,"title":"Sysmon Event 13 - RegistryEvent (Value Set)","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 13","Sysmon"],"keywords":["13","event 13","event id 13","RegistryEvent (Value Set)","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90013"],"errorCode":"","eventId":"13","severity":"Low","summary":"Sysmon event 13 records: RegistryEvent (Value Set)","rootCause":"The configured audit source recorded this activity: RegistryEvent (Value Set) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 13.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: RegistryEvent (Value Set)\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90013\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=13} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90013","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 13","Event ID 13","RegistryEvent (Value Set)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69131,"title":"Sysmon Event 14 - RegistryEvent (Key and Value Rename)","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 14","Sysmon"],"keywords":["14","event 14","event id 14","RegistryEvent (Key and Value Rename)","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90014"],"errorCode":"","eventId":"14","severity":"Low","summary":"Sysmon event 14 records: RegistryEvent (Key and Value Rename)","rootCause":"The configured audit source recorded this activity: RegistryEvent (Key and Value Rename) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 14.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: RegistryEvent (Key and Value Rename)\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90014\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=14} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90014","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 14","Event ID 14","RegistryEvent (Key and Value Rename)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69132,"title":"Sysmon Event 15 - FileCreateStreamHash","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 15","Sysmon"],"keywords":["15","event 15","event id 15","FileCreateStreamHash","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90015"],"errorCode":"","eventId":"15","severity":"Low","summary":"Sysmon event 15 records: FileCreateStreamHash","rootCause":"The configured audit source recorded this activity: FileCreateStreamHash It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 15.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: FileCreateStreamHash\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90015\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=15} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90015","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 15","Event ID 15","FileCreateStreamHash"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69133,"title":"Sysmon Event 16 - Sysmon config state changed","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 16","Sysmon"],"keywords":["16","event 16","event id 16","Sysmon config state changed","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90016"],"errorCode":"","eventId":"16","severity":"Medium","summary":"Sysmon event 16 records: Sysmon config state changed","rootCause":"The event records a state-changing operation: Sysmon config state changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 16.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Sysmon config state changed\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90016\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=16} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90016","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 16","Event ID 16","Sysmon config state changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69134,"title":"Sysmon Event 17 - Pipe created","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 17","Sysmon"],"keywords":["17","event 17","event id 17","Pipe created","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90017"],"errorCode":"","eventId":"17","severity":"Medium","summary":"Sysmon event 17 records: Pipe created","rootCause":"The event records a state-changing operation: Pipe created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 17.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Pipe created\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90017\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=17} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90017","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 17","Event ID 17","Pipe created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69135,"title":"Sysmon Event 18 - Pipe connected","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 18","Sysmon"],"keywords":["18","event 18","event id 18","Pipe connected","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90018"],"errorCode":"","eventId":"18","severity":"Low","summary":"Sysmon event 18 records: Pipe connected","rootCause":"The configured audit source recorded this activity: Pipe connected It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 18.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Pipe connected\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90018\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=18} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90018","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 18","Event ID 18","Pipe connected"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69136,"title":"Sysmon Event 19 - WmiEventFilter activity detected","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 19","Sysmon"],"keywords":["19","event 19","event id 19","WmiEventFilter activity detected","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90019"],"errorCode":"","eventId":"19","severity":"Low","summary":"Sysmon event 19 records: WmiEventFilter activity detected","rootCause":"The configured audit source recorded this activity: WmiEventFilter activity detected It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 19.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: WmiEventFilter activity detected\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90019\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=19} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90019","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 19","Event ID 19","WmiEventFilter activity detected"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69137,"title":"Sysmon Event 20 - WmiEventConsumer activity detected","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 20","Sysmon"],"keywords":["20","event 20","event id 20","WmiEventConsumer activity detected","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90020"],"errorCode":"","eventId":"20","severity":"Low","summary":"Sysmon event 20 records: WmiEventConsumer activity detected","rootCause":"The configured audit source recorded this activity: WmiEventConsumer activity detected It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 20.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: WmiEventConsumer activity detected\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90020\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=20} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90020","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 20","Event ID 20","WmiEventConsumer activity detected"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69138,"title":"Sysmon Event 21 - WmiEventConsumerToFilter activity detected","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 21","Sysmon"],"keywords":["21","event 21","event id 21","WmiEventConsumerToFilter activity detected","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90021"],"errorCode":"","eventId":"21","severity":"Low","summary":"Sysmon event 21 records: WmiEventConsumerToFilter activity detected","rootCause":"The configured audit source recorded this activity: WmiEventConsumerToFilter activity detected It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 21.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: WmiEventConsumerToFilter activity detected\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90021\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=21} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90021","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 21","Event ID 21","WmiEventConsumerToFilter activity detected"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69139,"title":"Sysmon Event 22 - DNSEvent","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 22","Sysmon"],"keywords":["22","event 22","event id 22","DNSEvent","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90022"],"errorCode":"","eventId":"22","severity":"Low","summary":"Sysmon event 22 records: DNSEvent","rootCause":"The configured audit source recorded this activity: DNSEvent It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 22.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: DNSEvent\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90022\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=22} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90022","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 22","Event ID 22","DNSEvent"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69140,"title":"Sysmon Event 23 - FileDelete","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 23","Sysmon"],"keywords":["23","event 23","event id 23","FileDelete","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90023"],"errorCode":"","eventId":"23","severity":"Low","summary":"Sysmon event 23 records: FileDelete","rootCause":"The configured audit source recorded this activity: FileDelete It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 23.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: FileDelete\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90023\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=23} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90023","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 23","Event ID 23","FileDelete"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69141,"title":"Sysmon Event 24 - ClipboardChange","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 24","Sysmon"],"keywords":["24","event 24","event id 24","ClipboardChange","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90024"],"errorCode":"","eventId":"24","severity":"Low","summary":"Sysmon event 24 records: ClipboardChange","rootCause":"The configured audit source recorded this activity: ClipboardChange It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 24.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: ClipboardChange\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90024\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=24} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90024","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 24","Event ID 24","ClipboardChange"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69142,"title":"Sysmon Event 25 - Process Tampering","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 25","Sysmon"],"keywords":["25","event 25","event id 25","Process Tampering","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90025"],"errorCode":"","eventId":"25","severity":"Critical","summary":"Sysmon event 25 records: Process Tampering","rootCause":"The configured audit source recorded this activity: Process Tampering It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 25.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Process Tampering\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90025\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=25} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90025","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 25","Event ID 25","Process Tampering"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69143,"title":"Sysmon Event 26 - File Delete Logged","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 26","Sysmon"],"keywords":["26","event 26","event id 26","File Delete Logged","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90026"],"errorCode":"","eventId":"26","severity":"Low","summary":"Sysmon event 26 records: File Delete Logged","rootCause":"The configured audit source recorded this activity: File Delete Logged It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 26.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: File Delete Logged\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90026\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=26} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90026","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 26","Event ID 26","File Delete Logged"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69144,"title":"Sysmon Event 27 - File Block Executable","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 27","Sysmon"],"keywords":["27","event 27","event id 27","File Block Executable","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90027"],"errorCode":"","eventId":"27","severity":"Low","summary":"Sysmon event 27 records: File Block Executable","rootCause":"The configured audit source recorded this activity: File Block Executable It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 27.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: File Block Executable\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90027\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=27} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90027","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 27","Event ID 27","File Block Executable"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69145,"title":"Sysmon Event 28 - File Block Shredding","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 28","Sysmon"],"keywords":["28","event 28","event id 28","File Block Shredding","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90028"],"errorCode":"","eventId":"28","severity":"Low","summary":"Sysmon event 28 records: File Block Shredding","rootCause":"The configured audit source recorded this activity: File Block Shredding It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 28.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: File Block Shredding\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90028\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=28} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90028","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 28","Event ID 28","File Block Shredding"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69146,"title":"Sysmon Event 29 - File Executable Detected","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 29","Sysmon"],"keywords":["29","event 29","event id 29","File Executable Detected","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90029"],"errorCode":"","eventId":"29","severity":"Low","summary":"Sysmon event 29 records: File Executable Detected","rootCause":"The configured audit source recorded this activity: File Executable Detected It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 29.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: File Executable Detected\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90029\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=29} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90029","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 29","Event ID 29","File Executable Detected"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69147,"title":"Sysmon Event 225 - Error","category":"Security","product":"Microsoft Sysinternals Sysmon","tags":["Sysmon","Audit Event","Event ID 225","Sysmon"],"keywords":["225","event 225","event id 225","Error","Sysmon","Microsoft Sysinternals Sysmon","SYSMON","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90225"],"errorCode":"","eventId":"225","severity":"High","summary":"Sysmon event 225 records: Error","rootCause":"The audited operation reported a failure: Error The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Sysmon event 225.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Error\n\nContext: This is a Microsoft Sysinternals Sysmon Operational event. Sysmon records telemetry according to the installed configuration; the event is evidence, not a verdict.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90225\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=225} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90225","namespace":"SYSMON","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Sysmon"],"articleCategories":["Security Logs","Audit Events","Sysmon","Sysmon"],"aliases":["Sysmon 225","Event ID 225","Error"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69148,"title":"Windows Security Event 512 - Windows NT is starting up","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 512","Windows"],"keywords":["512","event 512","event id 512","Windows NT is starting up","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=512"],"errorCode":"","eventId":"512","severity":"Low","summary":"Windows Security event 512 records: Windows NT is starting up","rootCause":"The configured audit source recorded this activity: Windows NT is starting up It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 512.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Windows NT is starting up\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=512\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=512} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=512","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 512","Event ID 512","Windows NT is starting up"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69149,"title":"Windows Security Event 513 - Windows is shutting down","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 513","Windows"],"keywords":["513","event 513","event id 513","Windows is shutting down","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=513"],"errorCode":"","eventId":"513","severity":"Low","summary":"Windows Security event 513 records: Windows is shutting down","rootCause":"The configured audit source recorded this activity: Windows is shutting down It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 513.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Windows is shutting down\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=513\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=513} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=513","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 513","Event ID 513","Windows is shutting down"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69150,"title":"Windows Security Event 514 - An authentication package has been loaded by the Local Security Authority","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 514","Windows"],"keywords":["514","event 514","event id 514","An authentication package has been loaded by the Local Security Authority","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=514"],"errorCode":"","eventId":"514","severity":"Low","summary":"Windows Security event 514 records: An authentication package has been loaded by the Local Security Authority","rootCause":"The configured audit source recorded this activity: An authentication package has been loaded by the Local Security Authority It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 514.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An authentication package has been loaded by the Local Security Authority\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=514\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=514} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=514","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 514","Event ID 514","An authentication package has been loaded by the Local Security Authority"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69151,"title":"Windows Security Event 515 - A trusted logon process has registered with the Local Security Authority","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 515","Windows"],"keywords":["515","event 515","event id 515","A trusted logon process has registered with the Local Security Authority","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=515"],"errorCode":"","eventId":"515","severity":"Medium","summary":"Windows Security event 515 records: A trusted logon process has registered with the Local Security Authority","rootCause":"The configured audit source recorded this activity: A trusted logon process has registered with the Local Security Authority It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 515.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A trusted logon process has registered with the Local Security Authority\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=515\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=515} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=515","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 515","Event ID 515","A trusted logon process has registered with the Local Security Authority"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69152,"title":"Windows Security Event 516 - Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 516","Windows"],"keywords":["516","event 516","event id 516","Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=516"],"errorCode":"","eventId":"516","severity":"Low","summary":"Windows Security event 516 records: Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits","rootCause":"The configured audit source recorded this activity: Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 516.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=516\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=516} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=516","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 516","Event ID 516","Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69153,"title":"Windows Security Event 517 - The audit log was cleared","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 517","Windows"],"keywords":["517","event 517","event id 517","The audit log was cleared","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=517"],"errorCode":"","eventId":"517","severity":"Critical","summary":"Windows Security event 517 records: The audit log was cleared","rootCause":"The configured audit source recorded this activity: The audit log was cleared It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 517.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The audit log was cleared\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=517\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=517} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=517","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 517","Event ID 517","The audit log was cleared"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69154,"title":"Windows Security Event 518 - A notification package has been loaded by the Security Account Manager","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 518","Windows"],"keywords":["518","event 518","event id 518","A notification package has been loaded by the Security Account Manager","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=518"],"errorCode":"","eventId":"518","severity":"Low","summary":"Windows Security event 518 records: A notification package has been loaded by the Security Account Manager","rootCause":"The configured audit source recorded this activity: A notification package has been loaded by the Security Account Manager It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 518.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A notification package has been loaded by the Security Account Manager\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=518\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=518} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=518","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 518","Event ID 518","A notification package has been loaded by the Security Account Manager"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69155,"title":"Windows Security Event 519 - A process is using an invalid local procedure call (LPC) port","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 519","Windows"],"keywords":["519","event 519","event id 519","A process is using an invalid local procedure call (LPC) port","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=519"],"errorCode":"","eventId":"519","severity":"High","summary":"Windows Security event 519 records: A process is using an invalid local procedure call (LPC) port","rootCause":"The audited operation reported a failure: A process is using an invalid local procedure call (LPC) port The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 519.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A process is using an invalid local procedure call (LPC) port\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=519\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=519} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=519","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 519","Event ID 519","A process is using an invalid local procedure call (LPC) port"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69156,"title":"Windows Security Event 520 - The system time was changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 520","Windows"],"keywords":["520","event 520","event id 520","The system time was changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=520"],"errorCode":"","eventId":"520","severity":"Medium","summary":"Windows Security event 520 records: The system time was changed","rootCause":"The event records a state-changing operation: The system time was changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 520.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The system time was changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=520\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=520} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=520","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 520","Event ID 520","The system time was changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69157,"title":"Windows Security Event 521 - Unable to log events to security log","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 521","Windows"],"keywords":["521","event 521","event id 521","Unable to log events to security log","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=521"],"errorCode":"","eventId":"521","severity":"High","summary":"Windows Security event 521 records: Unable to log events to security log","rootCause":"The audited operation reported a failure: Unable to log events to security log The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 521.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Unable to log events to security log\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=521\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=521} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=521","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 521","Event ID 521","Unable to log events to security log"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69158,"title":"Windows Security Event 528 - Successful Logon","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 528","Windows"],"keywords":["528","event 528","event id 528","Successful Logon","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=528"],"errorCode":"","eventId":"528","severity":"Low","summary":"Windows Security event 528 records: Successful Logon","rootCause":"The configured audit source recorded this activity: Successful Logon It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 528.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Successful Logon\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=528\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=528} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=528","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 528","Event ID 528","Successful Logon"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69159,"title":"Windows Security Event 529 - Logon Failure - Unknown user name or bad password","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 529","Windows"],"keywords":["529","event 529","event id 529","Logon Failure - Unknown user name or bad password","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=529"],"errorCode":"","eventId":"529","severity":"High","summary":"Windows Security event 529 records: Logon Failure - Unknown user name or bad password","rootCause":"The audited operation reported a failure: Logon Failure - Unknown user name or bad password The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 529.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Logon Failure - Unknown user name or bad password\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=529\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=529} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=529","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 529","Event ID 529","Logon Failure - Unknown user name or bad password"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69160,"title":"Windows Security Event 530 - Logon Failure - Account logon time restriction violation","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 530","Windows"],"keywords":["530","event 530","event id 530","Logon Failure - Account logon time restriction violation","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=530"],"errorCode":"","eventId":"530","severity":"High","summary":"Windows Security event 530 records: Logon Failure - Account logon time restriction violation","rootCause":"The audited operation reported a failure: Logon Failure - Account logon time restriction violation The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 530.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Logon Failure - Account logon time restriction violation\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=530\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=530} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=530","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 530","Event ID 530","Logon Failure - Account logon time restriction violation"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69161,"title":"Windows Security Event 531 - Logon Failure - Account currently disabled","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 531","Windows"],"keywords":["531","event 531","event id 531","Logon Failure - Account currently disabled","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=531"],"errorCode":"","eventId":"531","severity":"High","summary":"Windows Security event 531 records: Logon Failure - Account currently disabled","rootCause":"The audited operation reported a failure: Logon Failure - Account currently disabled The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 531.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Logon Failure - Account currently disabled\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=531\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=531} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=531","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 531","Event ID 531","Logon Failure - Account currently disabled"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69162,"title":"Windows Security Event 532 - Logon Failure - The specified user account has expired","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 532","Windows"],"keywords":["532","event 532","event id 532","Logon Failure - The specified user account has expired","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=532"],"errorCode":"","eventId":"532","severity":"High","summary":"Windows Security event 532 records: Logon Failure - The specified user account has expired","rootCause":"The audited operation reported a failure: Logon Failure - The specified user account has expired The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 532.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Logon Failure - The specified user account has expired\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=532\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=532} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=532","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 532","Event ID 532","Logon Failure - The specified user account has expired"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69163,"title":"Windows Security Event 533 - Logon Failure - User not allowed to logon at this computer","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 533","Windows"],"keywords":["533","event 533","event id 533","Logon Failure - User not allowed to logon at this computer","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=533"],"errorCode":"","eventId":"533","severity":"High","summary":"Windows Security event 533 records: Logon Failure - User not allowed to logon at this computer","rootCause":"The audited operation reported a failure: Logon Failure - User not allowed to logon at this computer The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 533.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Logon Failure - User not allowed to logon at this computer\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=533\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=533} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=533","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 533","Event ID 533","Logon Failure - User not allowed to logon at this computer"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69164,"title":"Windows Security Event 534 - Logon Failure - The user has not been granted the requested logon type at this machine","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 534","Windows"],"keywords":["534","event 534","event id 534","Logon Failure - The user has not been granted the requested logon type at this machine","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=534"],"errorCode":"","eventId":"534","severity":"High","summary":"Windows Security event 534 records: Logon Failure - The user has not been granted the requested logon type at this machine","rootCause":"The audited operation reported a failure: Logon Failure - The user has not been granted the requested logon type at this machine The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 534.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Logon Failure - The user has not been granted the requested logon type at this machine\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=534\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=534} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=534","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 534","Event ID 534","Logon Failure - The user has not been granted the requested logon type at this machine"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69165,"title":"Windows Security Event 535 - Logon Failure - The specified account's password has expired","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 535","Windows"],"keywords":["535","event 535","event id 535","Logon Failure - The specified account's password has expired","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=535"],"errorCode":"","eventId":"535","severity":"High","summary":"Windows Security event 535 records: Logon Failure - The specified account's password has expired","rootCause":"The audited operation reported a failure: Logon Failure - The specified account's password has expired The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 535.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Logon Failure - The specified account's password has expired\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=535\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=535} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=535","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 535","Event ID 535","Logon Failure - The specified account's password has expired"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69166,"title":"Windows Security Event 536 - Logon Failure - The NetLogon component is not active","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 536","Windows"],"keywords":["536","event 536","event id 536","Logon Failure - The NetLogon component is not active","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=536"],"errorCode":"","eventId":"536","severity":"High","summary":"Windows Security event 536 records: Logon Failure - The NetLogon component is not active","rootCause":"The audited operation reported a failure: Logon Failure - The NetLogon component is not active The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 536.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Logon Failure - The NetLogon component is not active\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=536\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=536} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=536","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 536","Event ID 536","Logon Failure - The NetLogon component is not active"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69167,"title":"Windows Security Event 537 - Logon failure - The logon attempt failed for other reasons.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 537","Windows"],"keywords":["537","event 537","event id 537","Logon failure - The logon attempt failed for other reasons.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=537"],"errorCode":"","eventId":"537","severity":"High","summary":"Windows Security event 537 records: Logon failure - The logon attempt failed for other reasons.","rootCause":"The audited operation reported a failure: Logon failure - The logon attempt failed for other reasons. The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 537.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Logon failure - The logon attempt failed for other reasons.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=537\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=537} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=537","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 537","Event ID 537","Logon failure - The logon attempt failed for other reasons."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69168,"title":"Windows Security Event 538 - User Logoff","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 538","Windows"],"keywords":["538","event 538","event id 538","User Logoff","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=538"],"errorCode":"","eventId":"538","severity":"Low","summary":"Windows Security event 538 records: User Logoff","rootCause":"The configured audit source recorded this activity: User Logoff It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 538.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: User Logoff\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=538\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=538} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=538","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 538","Event ID 538","User Logoff"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69169,"title":"Windows Security Event 539 - Logon Failure - Account locked out","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 539","Windows"],"keywords":["539","event 539","event id 539","Logon Failure - Account locked out","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=539"],"errorCode":"","eventId":"539","severity":"High","summary":"Windows Security event 539 records: Logon Failure - Account locked out","rootCause":"The audited operation reported a failure: Logon Failure - Account locked out The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 539.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Logon Failure - Account locked out\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=539\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=539} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=539","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 539","Event ID 539","Logon Failure - Account locked out"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69170,"title":"Windows Security Event 540 - Successful Network Logon","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 540","Windows"],"keywords":["540","event 540","event id 540","Successful Network Logon","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=540"],"errorCode":"","eventId":"540","severity":"Low","summary":"Windows Security event 540 records: Successful Network Logon","rootCause":"The configured audit source recorded this activity: Successful Network Logon It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 540.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Successful Network Logon\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=540\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=540} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=540","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 540","Event ID 540","Successful Network Logon"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69171,"title":"Windows Security Event 551 - User initiated logoff","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 551","Windows"],"keywords":["551","event 551","event id 551","User initiated logoff","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=551"],"errorCode":"","eventId":"551","severity":"Low","summary":"Windows Security event 551 records: User initiated logoff","rootCause":"The configured audit source recorded this activity: User initiated logoff It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 551.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: User initiated logoff\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=551\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=551} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=551","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 551","Event ID 551","User initiated logoff"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69172,"title":"Windows Security Event 552 - Logon attempt using explicit credentials","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 552","Windows"],"keywords":["552","event 552","event id 552","Logon attempt using explicit credentials","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=552"],"errorCode":"","eventId":"552","severity":"Low","summary":"Windows Security event 552 records: Logon attempt using explicit credentials","rootCause":"The configured audit source recorded this activity: Logon attempt using explicit credentials It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 552.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Logon attempt using explicit credentials\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=552\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=552} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=552","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 552","Event ID 552","Logon attempt using explicit credentials"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69173,"title":"Windows Security Event 560 - Object Open","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 560","Windows"],"keywords":["560","event 560","event id 560","Object Open","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=560"],"errorCode":"","eventId":"560","severity":"Low","summary":"Windows Security event 560 records: Object Open","rootCause":"The configured audit source recorded this activity: Object Open It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 560.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Object Open\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=560\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=560} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=560","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 560","Event ID 560","Object Open"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69174,"title":"Windows Security Event 561 - Handle Allocated","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 561","Windows"],"keywords":["561","event 561","event id 561","Handle Allocated","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=561"],"errorCode":"","eventId":"561","severity":"Low","summary":"Windows Security event 561 records: Handle Allocated","rootCause":"The configured audit source recorded this activity: Handle Allocated It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 561.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Handle Allocated\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=561\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=561} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=561","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 561","Event ID 561","Handle Allocated"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69175,"title":"Windows Security Event 562 - Handle Closed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 562","Windows"],"keywords":["562","event 562","event id 562","Handle Closed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=562"],"errorCode":"","eventId":"562","severity":"Low","summary":"Windows Security event 562 records: Handle Closed","rootCause":"The configured audit source recorded this activity: Handle Closed It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 562.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Handle Closed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=562\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=562} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=562","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 562","Event ID 562","Handle Closed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69176,"title":"Windows Security Event 563 - Object Open for Delete","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 563","Windows"],"keywords":["563","event 563","event id 563","Object Open for Delete","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=563"],"errorCode":"","eventId":"563","severity":"Low","summary":"Windows Security event 563 records: Object Open for Delete","rootCause":"The configured audit source recorded this activity: Object Open for Delete It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 563.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Object Open for Delete\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=563\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=563} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=563","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 563","Event ID 563","Object Open for Delete"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69177,"title":"Windows Security Event 564 - Object Deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 564","Windows"],"keywords":["564","event 564","event id 564","Object Deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=564"],"errorCode":"","eventId":"564","severity":"High","summary":"Windows Security event 564 records: Object Deleted","rootCause":"The event records a state-changing operation: Object Deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 564.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Object Deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=564\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=564} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=564","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 564","Event ID 564","Object Deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69178,"title":"Windows Security Event 565 - Object Open (Active Directory)","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 565","Windows"],"keywords":["565","event 565","event id 565","Object Open (Active Directory)","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=565"],"errorCode":"","eventId":"565","severity":"Low","summary":"Windows Security event 565 records: Object Open (Active Directory)","rootCause":"The configured audit source recorded this activity: Object Open (Active Directory) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 565.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Object Open (Active Directory)\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=565\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=565} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=565","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 565","Event ID 565","Object Open (Active Directory)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69179,"title":"Windows Security Event 566 - Object Operation (W3 Active Directory)","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 566","Windows"],"keywords":["566","event 566","event id 566","Object Operation (W3 Active Directory)","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=566"],"errorCode":"","eventId":"566","severity":"Low","summary":"Windows Security event 566 records: Object Operation (W3 Active Directory)","rootCause":"The configured audit source recorded this activity: Object Operation (W3 Active Directory) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 566.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Object Operation (W3 Active Directory)\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=566\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=566} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=566","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 566","Event ID 566","Object Operation (W3 Active Directory)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69180,"title":"Windows Security Event 567 - Object Access Attempt","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 567","Windows"],"keywords":["567","event 567","event id 567","Object Access Attempt","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=567"],"errorCode":"","eventId":"567","severity":"Low","summary":"Windows Security event 567 records: Object Access Attempt","rootCause":"The configured audit source recorded this activity: Object Access Attempt It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 567.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Object Access Attempt\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=567\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=567} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=567","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 567","Event ID 567","Object Access Attempt"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69181,"title":"Windows Security Event 576 - Special privileges assigned to new logon","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 576","Windows"],"keywords":["576","event 576","event id 576","Special privileges assigned to new logon","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=576"],"errorCode":"","eventId":"576","severity":"Medium","summary":"Windows Security event 576 records: Special privileges assigned to new logon","rootCause":"The configured audit source recorded this activity: Special privileges assigned to new logon It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 576.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Special privileges assigned to new logon\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=576\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=576} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=576","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 576","Event ID 576","Special privileges assigned to new logon"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69182,"title":"Windows Security Event 577 - Privileged Service Called","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 577","Windows"],"keywords":["577","event 577","event id 577","Privileged Service Called","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=577"],"errorCode":"","eventId":"577","severity":"Medium","summary":"Windows Security event 577 records: Privileged Service Called","rootCause":"The configured audit source recorded this activity: Privileged Service Called It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 577.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Privileged Service Called\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=577\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=577} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=577","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 577","Event ID 577","Privileged Service Called"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69183,"title":"Windows Security Event 578 - Privileged object operation","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 578","Windows"],"keywords":["578","event 578","event id 578","Privileged object operation","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=578"],"errorCode":"","eventId":"578","severity":"Medium","summary":"Windows Security event 578 records: Privileged object operation","rootCause":"The configured audit source recorded this activity: Privileged object operation It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 578.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Privileged object operation\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=578\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=578} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=578","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 578","Event ID 578","Privileged object operation"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69184,"title":"Windows Security Event 592 - A new process has been created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 592","Windows"],"keywords":["592","event 592","event id 592","A new process has been created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=592"],"errorCode":"","eventId":"592","severity":"Medium","summary":"Windows Security event 592 records: A new process has been created","rootCause":"The event records a state-changing operation: A new process has been created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 592.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A new process has been created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=592\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=592} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=592","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 592","Event ID 592","A new process has been created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69185,"title":"Windows Security Event 593 - A process has exited","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 593","Windows"],"keywords":["593","event 593","event id 593","A process has exited","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=593"],"errorCode":"","eventId":"593","severity":"Low","summary":"Windows Security event 593 records: A process has exited","rootCause":"The configured audit source recorded this activity: A process has exited It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 593.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A process has exited\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=593\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=593} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=593","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 593","Event ID 593","A process has exited"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69186,"title":"Windows Security Event 594 - A handle to an object has been duplicated","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 594","Windows"],"keywords":["594","event 594","event id 594","A handle to an object has been duplicated","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=594"],"errorCode":"","eventId":"594","severity":"Low","summary":"Windows Security event 594 records: A handle to an object has been duplicated","rootCause":"The configured audit source recorded this activity: A handle to an object has been duplicated It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 594.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A handle to an object has been duplicated\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=594\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=594} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=594","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 594","Event ID 594","A handle to an object has been duplicated"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69187,"title":"Windows Security Event 595 - Indirect access to an object has been obtained","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 595","Windows"],"keywords":["595","event 595","event id 595","Indirect access to an object has been obtained","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=595"],"errorCode":"","eventId":"595","severity":"Low","summary":"Windows Security event 595 records: Indirect access to an object has been obtained","rootCause":"The configured audit source recorded this activity: Indirect access to an object has been obtained It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 595.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Indirect access to an object has been obtained\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=595\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=595} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=595","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 595","Event ID 595","Indirect access to an object has been obtained"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69188,"title":"Windows Security Event 596 - Backup of data protection master key","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 596","Windows"],"keywords":["596","event 596","event id 596","Backup of data protection master key","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=596"],"errorCode":"","eventId":"596","severity":"Low","summary":"Windows Security event 596 records: Backup of data protection master key","rootCause":"The configured audit source recorded this activity: Backup of data protection master key It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 596.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Backup of data protection master key\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=596\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=596} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=596","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 596","Event ID 596","Backup of data protection master key"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69189,"title":"Windows Security Event 600 - A process was assigned a primary token","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 600","Windows"],"keywords":["600","event 600","event id 600","A process was assigned a primary token","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=600"],"errorCode":"","eventId":"600","severity":"Low","summary":"Windows Security event 600 records: A process was assigned a primary token","rootCause":"The configured audit source recorded this activity: A process was assigned a primary token It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 600.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A process was assigned a primary token\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=600\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=600} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=600","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 600","Event ID 600","A process was assigned a primary token"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69190,"title":"Windows Security Event 601 - Attempt to install service","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 601","Windows"],"keywords":["601","event 601","event id 601","Attempt to install service","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=601"],"errorCode":"","eventId":"601","severity":"Low","summary":"Windows Security event 601 records: Attempt to install service","rootCause":"The configured audit source recorded this activity: Attempt to install service It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 601.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Attempt to install service\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=601\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=601} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=601","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 601","Event ID 601","Attempt to install service"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69191,"title":"Windows Security Event 602 - Scheduled Task created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 602","Windows"],"keywords":["602","event 602","event id 602","Scheduled Task created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=602"],"errorCode":"","eventId":"602","severity":"Medium","summary":"Windows Security event 602 records: Scheduled Task created","rootCause":"The event records a state-changing operation: Scheduled Task created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 602.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Scheduled Task created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=602\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=602} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=602","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 602","Event ID 602","Scheduled Task created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69192,"title":"Windows Security Event 608 - User Right Assigned","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 608","Windows"],"keywords":["608","event 608","event id 608","User Right Assigned","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=608"],"errorCode":"","eventId":"608","severity":"Low","summary":"Windows Security event 608 records: User Right Assigned","rootCause":"The configured audit source recorded this activity: User Right Assigned It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 608.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: User Right Assigned\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=608\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=608} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=608","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 608","Event ID 608","User Right Assigned"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69193,"title":"Windows Security Event 609 - User Right Removed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 609","Windows"],"keywords":["609","event 609","event id 609","User Right Removed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=609"],"errorCode":"","eventId":"609","severity":"Medium","summary":"Windows Security event 609 records: User Right Removed","rootCause":"The event records a state-changing operation: User Right Removed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 609.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: User Right Removed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=609\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=609} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=609","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 609","Event ID 609","User Right Removed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69194,"title":"Windows Security Event 610 - New Trusted Domain","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 610","Windows"],"keywords":["610","event 610","event id 610","New Trusted Domain","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=610"],"errorCode":"","eventId":"610","severity":"Medium","summary":"Windows Security event 610 records: New Trusted Domain","rootCause":"The configured audit source recorded this activity: New Trusted Domain It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 610.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: New Trusted Domain\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=610\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=610} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=610","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 610","Event ID 610","New Trusted Domain"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69195,"title":"Windows Security Event 611 - Removing Trusted Domain","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 611","Windows"],"keywords":["611","event 611","event id 611","Removing Trusted Domain","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=611"],"errorCode":"","eventId":"611","severity":"Medium","summary":"Windows Security event 611 records: Removing Trusted Domain","rootCause":"The configured audit source recorded this activity: Removing Trusted Domain It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 611.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Removing Trusted Domain\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=611\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=611} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=611","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 611","Event ID 611","Removing Trusted Domain"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69196,"title":"Windows Security Event 612 - Audit Policy Change","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 612","Windows"],"keywords":["612","event 612","event id 612","Audit Policy Change","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=612"],"errorCode":"","eventId":"612","severity":"Medium","summary":"Windows Security event 612 records: Audit Policy Change","rootCause":"The configured audit source recorded this activity: Audit Policy Change It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 612.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Audit Policy Change\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=612\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=612} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=612","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 612","Event ID 612","Audit Policy Change"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69197,"title":"Windows Security Event 613 - IPSec policy agent started","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 613","Windows"],"keywords":["613","event 613","event id 613","IPSec policy agent started","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=613"],"errorCode":"","eventId":"613","severity":"Medium","summary":"Windows Security event 613 records: IPSec policy agent started","rootCause":"The configured audit source recorded this activity: IPSec policy agent started It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 613.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: IPSec policy agent started\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=613\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=613} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=613","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 613","Event ID 613","IPSec policy agent started"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69198,"title":"Windows Security Event 614 - IPSec policy agent disabled","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 614","Windows"],"keywords":["614","event 614","event id 614","IPSec policy agent disabled","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=614"],"errorCode":"","eventId":"614","severity":"High","summary":"Windows Security event 614 records: IPSec policy agent disabled","rootCause":"The event records a state-changing operation: IPSec policy agent disabled It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 614.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: IPSec policy agent disabled\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=614\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=614} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=614","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 614","Event ID 614","IPSec policy agent disabled"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69199,"title":"Windows Security Event 615 - IPSEC PolicyAgent Service","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 615","Windows"],"keywords":["615","event 615","event id 615","IPSEC PolicyAgent Service","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=615"],"errorCode":"","eventId":"615","severity":"Medium","summary":"Windows Security event 615 records: IPSEC PolicyAgent Service","rootCause":"The configured audit source recorded this activity: IPSEC PolicyAgent Service It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 615.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: IPSEC PolicyAgent Service\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=615\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=615} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=615","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 615","Event ID 615","IPSEC PolicyAgent Service"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69200,"title":"Windows Security Event 616 - IPSec policy agent encountered a potentially serious failure.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 616","Windows"],"keywords":["616","event 616","event id 616","IPSec policy agent encountered a potentially serious failure.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=616"],"errorCode":"","eventId":"616","severity":"High","summary":"Windows Security event 616 records: IPSec policy agent encountered a potentially serious failure.","rootCause":"The audited operation reported a failure: IPSec policy agent encountered a potentially serious failure. The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 616.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: IPSec policy agent encountered a potentially serious failure.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=616\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=616} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=616","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 616","Event ID 616","IPSec policy agent encountered a potentially serious failure."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69201,"title":"Windows Security Event 617 - Kerberos Policy Changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 617","Windows"],"keywords":["617","event 617","event id 617","Kerberos Policy Changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=617"],"errorCode":"","eventId":"617","severity":"Medium","summary":"Windows Security event 617 records: Kerberos Policy Changed","rootCause":"The event records a state-changing operation: Kerberos Policy Changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 617.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Kerberos Policy Changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=617\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=617} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=617","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 617","Event ID 617","Kerberos Policy Changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69202,"title":"Windows Security Event 618 - Encrypted Data Recovery Policy Changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 618","Windows"],"keywords":["618","event 618","event id 618","Encrypted Data Recovery Policy Changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=618"],"errorCode":"","eventId":"618","severity":"Medium","summary":"Windows Security event 618 records: Encrypted Data Recovery Policy Changed","rootCause":"The event records a state-changing operation: Encrypted Data Recovery Policy Changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 618.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Encrypted Data Recovery Policy Changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=618\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=618} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=618","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 618","Event ID 618","Encrypted Data Recovery Policy Changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69203,"title":"Windows Security Event 619 - Quality of Service Policy Changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 619","Windows"],"keywords":["619","event 619","event id 619","Quality of Service Policy Changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=619"],"errorCode":"","eventId":"619","severity":"Medium","summary":"Windows Security event 619 records: Quality of Service Policy Changed","rootCause":"The event records a state-changing operation: Quality of Service Policy Changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 619.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Quality of Service Policy Changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=619\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=619} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=619","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 619","Event ID 619","Quality of Service Policy Changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69204,"title":"Windows Security Event 620 - Trusted Domain Information Modified","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 620","Windows"],"keywords":["620","event 620","event id 620","Trusted Domain Information Modified","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=620"],"errorCode":"","eventId":"620","severity":"Medium","summary":"Windows Security event 620 records: Trusted Domain Information Modified","rootCause":"The event records a state-changing operation: Trusted Domain Information Modified It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 620.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Trusted Domain Information Modified\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=620\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=620} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=620","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 620","Event ID 620","Trusted Domain Information Modified"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69205,"title":"Windows Security Event 621 - System Security Access Granted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 621","Windows"],"keywords":["621","event 621","event id 621","System Security Access Granted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=621"],"errorCode":"","eventId":"621","severity":"Low","summary":"Windows Security event 621 records: System Security Access Granted","rootCause":"The configured audit source recorded this activity: System Security Access Granted It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 621.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: System Security Access Granted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=621\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=621} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=621","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 621","Event ID 621","System Security Access Granted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69206,"title":"Windows Security Event 622 - System Security Access Removed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 622","Windows"],"keywords":["622","event 622","event id 622","System Security Access Removed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=622"],"errorCode":"","eventId":"622","severity":"Medium","summary":"Windows Security event 622 records: System Security Access Removed","rootCause":"The event records a state-changing operation: System Security Access Removed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 622.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: System Security Access Removed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=622\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=622} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=622","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 622","Event ID 622","System Security Access Removed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69207,"title":"Windows Security Event 623 - Per User Audit Policy was refreshed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 623","Windows"],"keywords":["623","event 623","event id 623","Per User Audit Policy was refreshed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=623"],"errorCode":"","eventId":"623","severity":"Medium","summary":"Windows Security event 623 records: Per User Audit Policy was refreshed","rootCause":"The configured audit source recorded this activity: Per User Audit Policy was refreshed It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 623.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Per User Audit Policy was refreshed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=623\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=623} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=623","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 623","Event ID 623","Per User Audit Policy was refreshed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69208,"title":"Windows Security Event 624 - User Account Created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 624","Windows"],"keywords":["624","event 624","event id 624","User Account Created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=624"],"errorCode":"","eventId":"624","severity":"Medium","summary":"Windows Security event 624 records: User Account Created","rootCause":"The event records a state-changing operation: User Account Created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 624.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: User Account Created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=624\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=624} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=624","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 624","Event ID 624","User Account Created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69209,"title":"Windows Security Event 625 - User Account Type Changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 625","Windows"],"keywords":["625","event 625","event id 625","User Account Type Changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=625"],"errorCode":"","eventId":"625","severity":"Medium","summary":"Windows Security event 625 records: User Account Type Changed","rootCause":"The event records a state-changing operation: User Account Type Changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 625.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: User Account Type Changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=625\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=625} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=625","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 625","Event ID 625","User Account Type Changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69210,"title":"Windows Security Event 626 - User Account Enabled","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 626","Windows"],"keywords":["626","event 626","event id 626","User Account Enabled","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=626"],"errorCode":"","eventId":"626","severity":"Medium","summary":"Windows Security event 626 records: User Account Enabled","rootCause":"The event records a state-changing operation: User Account Enabled It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 626.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: User Account Enabled\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=626\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=626} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=626","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 626","Event ID 626","User Account Enabled"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69211,"title":"Windows Security Event 627 - Change Password Attempt","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 627","Windows"],"keywords":["627","event 627","event id 627","Change Password Attempt","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=627"],"errorCode":"","eventId":"627","severity":"Medium","summary":"Windows Security event 627 records: Change Password Attempt","rootCause":"The configured audit source recorded this activity: Change Password Attempt It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 627.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Change Password Attempt\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=627\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=627} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=627","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 627","Event ID 627","Change Password Attempt"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69212,"title":"Windows Security Event 628 - User Account password set","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 628","Windows"],"keywords":["628","event 628","event id 628","User Account password set","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=628"],"errorCode":"","eventId":"628","severity":"Medium","summary":"Windows Security event 628 records: User Account password set","rootCause":"The configured audit source recorded this activity: User Account password set It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 628.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: User Account password set\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=628\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=628} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=628","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 628","Event ID 628","User Account password set"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69213,"title":"Windows Security Event 629 - User Account Disabled","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 629","Windows"],"keywords":["629","event 629","event id 629","User Account Disabled","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=629"],"errorCode":"","eventId":"629","severity":"High","summary":"Windows Security event 629 records: User Account Disabled","rootCause":"The event records a state-changing operation: User Account Disabled It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 629.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: User Account Disabled\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=629\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=629} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=629","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 629","Event ID 629","User Account Disabled"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69214,"title":"Windows Security Event 630 - User Account Deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 630","Windows"],"keywords":["630","event 630","event id 630","User Account Deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=630"],"errorCode":"","eventId":"630","severity":"High","summary":"Windows Security event 630 records: User Account Deleted","rootCause":"The event records a state-changing operation: User Account Deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 630.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: User Account Deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=630\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=630} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=630","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 630","Event ID 630","User Account Deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69215,"title":"Windows Security Event 631 - Security Enabled Global Group Created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 631","Windows"],"keywords":["631","event 631","event id 631","Security Enabled Global Group Created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=631"],"errorCode":"","eventId":"631","severity":"Medium","summary":"Windows Security event 631 records: Security Enabled Global Group Created","rootCause":"The event records a state-changing operation: Security Enabled Global Group Created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 631.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Enabled Global Group Created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=631\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=631} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=631","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 631","Event ID 631","Security Enabled Global Group Created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69216,"title":"Windows Security Event 632 - Security Enabled Global Group Member Added","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 632","Windows"],"keywords":["632","event 632","event id 632","Security Enabled Global Group Member Added","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=632"],"errorCode":"","eventId":"632","severity":"Medium","summary":"Windows Security event 632 records: Security Enabled Global Group Member Added","rootCause":"The event records a state-changing operation: Security Enabled Global Group Member Added It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 632.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Enabled Global Group Member Added\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=632\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=632} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=632","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 632","Event ID 632","Security Enabled Global Group Member Added"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69217,"title":"Windows Security Event 633 - Security Enabled Global Group Member Removed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 633","Windows"],"keywords":["633","event 633","event id 633","Security Enabled Global Group Member Removed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=633"],"errorCode":"","eventId":"633","severity":"Medium","summary":"Windows Security event 633 records: Security Enabled Global Group Member Removed","rootCause":"The event records a state-changing operation: Security Enabled Global Group Member Removed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 633.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Enabled Global Group Member Removed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=633\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=633} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=633","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 633","Event ID 633","Security Enabled Global Group Member Removed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69218,"title":"Windows Security Event 634 - Security Enabled Global Group Deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 634","Windows"],"keywords":["634","event 634","event id 634","Security Enabled Global Group Deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=634"],"errorCode":"","eventId":"634","severity":"High","summary":"Windows Security event 634 records: Security Enabled Global Group Deleted","rootCause":"The event records a state-changing operation: Security Enabled Global Group Deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 634.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Enabled Global Group Deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=634\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=634} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=634","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 634","Event ID 634","Security Enabled Global Group Deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69219,"title":"Windows Security Event 635 - Security Enabled Local Group Created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 635","Windows"],"keywords":["635","event 635","event id 635","Security Enabled Local Group Created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=635"],"errorCode":"","eventId":"635","severity":"Medium","summary":"Windows Security event 635 records: Security Enabled Local Group Created","rootCause":"The event records a state-changing operation: Security Enabled Local Group Created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 635.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Enabled Local Group Created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=635\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=635} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=635","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 635","Event ID 635","Security Enabled Local Group Created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69220,"title":"Windows Security Event 636 - Security Enabled Local Group Member Added","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 636","Windows"],"keywords":["636","event 636","event id 636","Security Enabled Local Group Member Added","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=636"],"errorCode":"","eventId":"636","severity":"Medium","summary":"Windows Security event 636 records: Security Enabled Local Group Member Added","rootCause":"The event records a state-changing operation: Security Enabled Local Group Member Added It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 636.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Enabled Local Group Member Added\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=636\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=636} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=636","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 636","Event ID 636","Security Enabled Local Group Member Added"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69221,"title":"Windows Security Event 637 - Security Enabled Local Group Member Removed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 637","Windows"],"keywords":["637","event 637","event id 637","Security Enabled Local Group Member Removed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=637"],"errorCode":"","eventId":"637","severity":"Medium","summary":"Windows Security event 637 records: Security Enabled Local Group Member Removed","rootCause":"The event records a state-changing operation: Security Enabled Local Group Member Removed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 637.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Enabled Local Group Member Removed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=637\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=637} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=637","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 637","Event ID 637","Security Enabled Local Group Member Removed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69222,"title":"Windows Security Event 638 - Security Enabled Local Group Deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 638","Windows"],"keywords":["638","event 638","event id 638","Security Enabled Local Group Deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=638"],"errorCode":"","eventId":"638","severity":"High","summary":"Windows Security event 638 records: Security Enabled Local Group Deleted","rootCause":"The event records a state-changing operation: Security Enabled Local Group Deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 638.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Enabled Local Group Deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=638\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=638} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=638","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 638","Event ID 638","Security Enabled Local Group Deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69223,"title":"Windows Security Event 639 - Security Enabled Local Group Changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 639","Windows"],"keywords":["639","event 639","event id 639","Security Enabled Local Group Changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=639"],"errorCode":"","eventId":"639","severity":"Medium","summary":"Windows Security event 639 records: Security Enabled Local Group Changed","rootCause":"The event records a state-changing operation: Security Enabled Local Group Changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 639.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Enabled Local Group Changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=639\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=639} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=639","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 639","Event ID 639","Security Enabled Local Group Changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69224,"title":"Windows Security Event 640 - General Account Database Change","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 640","Windows"],"keywords":["640","event 640","event id 640","General Account Database Change","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=640"],"errorCode":"","eventId":"640","severity":"Low","summary":"Windows Security event 640 records: General Account Database Change","rootCause":"The configured audit source recorded this activity: General Account Database Change It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 640.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: General Account Database Change\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=640\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=640} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=640","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 640","Event ID 640","General Account Database Change"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69225,"title":"Windows Security Event 641 - Security Enabled Global Group Changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 641","Windows"],"keywords":["641","event 641","event id 641","Security Enabled Global Group Changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=641"],"errorCode":"","eventId":"641","severity":"Medium","summary":"Windows Security event 641 records: Security Enabled Global Group Changed","rootCause":"The event records a state-changing operation: Security Enabled Global Group Changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 641.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Enabled Global Group Changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=641\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=641} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=641","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 641","Event ID 641","Security Enabled Global Group Changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69226,"title":"Windows Security Event 642 - User Account Changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 642","Windows"],"keywords":["642","event 642","event id 642","User Account Changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=642"],"errorCode":"","eventId":"642","severity":"Medium","summary":"Windows Security event 642 records: User Account Changed","rootCause":"The event records a state-changing operation: User Account Changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 642.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: User Account Changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=642\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=642} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=642","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 642","Event ID 642","User Account Changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69227,"title":"Windows Security Event 643 - Domain Policy Changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 643","Windows"],"keywords":["643","event 643","event id 643","Domain Policy Changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=643"],"errorCode":"","eventId":"643","severity":"Medium","summary":"Windows Security event 643 records: Domain Policy Changed","rootCause":"The event records a state-changing operation: Domain Policy Changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 643.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Domain Policy Changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=643\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=643} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=643","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 643","Event ID 643","Domain Policy Changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69228,"title":"Windows Security Event 644 - User Account Locked Out","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 644","Windows"],"keywords":["644","event 644","event id 644","User Account Locked Out","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=644"],"errorCode":"","eventId":"644","severity":"Low","summary":"Windows Security event 644 records: User Account Locked Out","rootCause":"The configured audit source recorded this activity: User Account Locked Out It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 644.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: User Account Locked Out\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=644\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=644} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=644","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 644","Event ID 644","User Account Locked Out"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69229,"title":"Windows Security Event 645 - Computer Account Created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 645","Windows"],"keywords":["645","event 645","event id 645","Computer Account Created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=645"],"errorCode":"","eventId":"645","severity":"Medium","summary":"Windows Security event 645 records: Computer Account Created","rootCause":"The event records a state-changing operation: Computer Account Created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 645.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Computer Account Created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=645\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=645} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=645","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 645","Event ID 645","Computer Account Created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69230,"title":"Windows Security Event 646 - Computer Account Changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 646","Windows"],"keywords":["646","event 646","event id 646","Computer Account Changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=646"],"errorCode":"","eventId":"646","severity":"Medium","summary":"Windows Security event 646 records: Computer Account Changed","rootCause":"The event records a state-changing operation: Computer Account Changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 646.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Computer Account Changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=646\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=646} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=646","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 646","Event ID 646","Computer Account Changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69231,"title":"Windows Security Event 647 - Computer Account Deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 647","Windows"],"keywords":["647","event 647","event id 647","Computer Account Deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=647"],"errorCode":"","eventId":"647","severity":"High","summary":"Windows Security event 647 records: Computer Account Deleted","rootCause":"The event records a state-changing operation: Computer Account Deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 647.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Computer Account Deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=647\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=647} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=647","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 647","Event ID 647","Computer Account Deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69232,"title":"Windows Security Event 648 - Security Disabled Local Group Created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 648","Windows"],"keywords":["648","event 648","event id 648","Security Disabled Local Group Created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=648"],"errorCode":"","eventId":"648","severity":"High","summary":"Windows Security event 648 records: Security Disabled Local Group Created","rootCause":"The event records a state-changing operation: Security Disabled Local Group Created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 648.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Disabled Local Group Created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=648\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=648} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=648","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 648","Event ID 648","Security Disabled Local Group Created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69233,"title":"Windows Security Event 649 - Security Disabled Local Group Changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 649","Windows"],"keywords":["649","event 649","event id 649","Security Disabled Local Group Changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=649"],"errorCode":"","eventId":"649","severity":"High","summary":"Windows Security event 649 records: Security Disabled Local Group Changed","rootCause":"The event records a state-changing operation: Security Disabled Local Group Changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 649.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Disabled Local Group Changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=649\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=649} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=649","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 649","Event ID 649","Security Disabled Local Group Changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69234,"title":"Windows Security Event 650 - Security Disabled Local Group Member Added","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 650","Windows"],"keywords":["650","event 650","event id 650","Security Disabled Local Group Member Added","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=650"],"errorCode":"","eventId":"650","severity":"High","summary":"Windows Security event 650 records: Security Disabled Local Group Member Added","rootCause":"The event records a state-changing operation: Security Disabled Local Group Member Added It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 650.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Disabled Local Group Member Added\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=650\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=650} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=650","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 650","Event ID 650","Security Disabled Local Group Member Added"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69235,"title":"Windows Security Event 651 - Security Disabled Local Group Member Removed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 651","Windows"],"keywords":["651","event 651","event id 651","Security Disabled Local Group Member Removed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=651"],"errorCode":"","eventId":"651","severity":"High","summary":"Windows Security event 651 records: Security Disabled Local Group Member Removed","rootCause":"The event records a state-changing operation: Security Disabled Local Group Member Removed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 651.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Disabled Local Group Member Removed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=651\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=651} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=651","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 651","Event ID 651","Security Disabled Local Group Member Removed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69236,"title":"Windows Security Event 652 - Security Disabled Local Group Deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 652","Windows"],"keywords":["652","event 652","event id 652","Security Disabled Local Group Deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=652"],"errorCode":"","eventId":"652","severity":"High","summary":"Windows Security event 652 records: Security Disabled Local Group Deleted","rootCause":"The event records a state-changing operation: Security Disabled Local Group Deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 652.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Disabled Local Group Deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=652\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=652} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=652","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 652","Event ID 652","Security Disabled Local Group Deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69237,"title":"Windows Security Event 653 - Security Disabled Global Group Created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 653","Windows"],"keywords":["653","event 653","event id 653","Security Disabled Global Group Created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=653"],"errorCode":"","eventId":"653","severity":"High","summary":"Windows Security event 653 records: Security Disabled Global Group Created","rootCause":"The event records a state-changing operation: Security Disabled Global Group Created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 653.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Disabled Global Group Created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=653\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=653} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=653","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 653","Event ID 653","Security Disabled Global Group Created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69238,"title":"Windows Security Event 654 - Security Disabled Global Group Changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 654","Windows"],"keywords":["654","event 654","event id 654","Security Disabled Global Group Changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=654"],"errorCode":"","eventId":"654","severity":"High","summary":"Windows Security event 654 records: Security Disabled Global Group Changed","rootCause":"The event records a state-changing operation: Security Disabled Global Group Changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 654.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Disabled Global Group Changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=654\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=654} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=654","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 654","Event ID 654","Security Disabled Global Group Changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69239,"title":"Windows Security Event 655 - Security Disabled Global Group Member Added","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 655","Windows"],"keywords":["655","event 655","event id 655","Security Disabled Global Group Member Added","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=655"],"errorCode":"","eventId":"655","severity":"High","summary":"Windows Security event 655 records: Security Disabled Global Group Member Added","rootCause":"The event records a state-changing operation: Security Disabled Global Group Member Added It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 655.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Disabled Global Group Member Added\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=655\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=655} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=655","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 655","Event ID 655","Security Disabled Global Group Member Added"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69240,"title":"Windows Security Event 656 - Security Disabled Global Group Member Removed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 656","Windows"],"keywords":["656","event 656","event id 656","Security Disabled Global Group Member Removed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=656"],"errorCode":"","eventId":"656","severity":"High","summary":"Windows Security event 656 records: Security Disabled Global Group Member Removed","rootCause":"The event records a state-changing operation: Security Disabled Global Group Member Removed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 656.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Disabled Global Group Member Removed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=656\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=656} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=656","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 656","Event ID 656","Security Disabled Global Group Member Removed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69241,"title":"Windows Security Event 657 - Security Disabled Global Group Deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 657","Windows"],"keywords":["657","event 657","event id 657","Security Disabled Global Group Deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=657"],"errorCode":"","eventId":"657","severity":"High","summary":"Windows Security event 657 records: Security Disabled Global Group Deleted","rootCause":"The event records a state-changing operation: Security Disabled Global Group Deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 657.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Disabled Global Group Deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=657\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=657} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=657","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 657","Event ID 657","Security Disabled Global Group Deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69242,"title":"Windows Security Event 658 - Security Enabled Universal Group Created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 658","Windows"],"keywords":["658","event 658","event id 658","Security Enabled Universal Group Created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=658"],"errorCode":"","eventId":"658","severity":"Medium","summary":"Windows Security event 658 records: Security Enabled Universal Group Created","rootCause":"The event records a state-changing operation: Security Enabled Universal Group Created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 658.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Enabled Universal Group Created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=658\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=658} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=658","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 658","Event ID 658","Security Enabled Universal Group Created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69243,"title":"Windows Security Event 659 - Security Enabled Universal Group Changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 659","Windows"],"keywords":["659","event 659","event id 659","Security Enabled Universal Group Changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=659"],"errorCode":"","eventId":"659","severity":"Medium","summary":"Windows Security event 659 records: Security Enabled Universal Group Changed","rootCause":"The event records a state-changing operation: Security Enabled Universal Group Changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 659.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Enabled Universal Group Changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=659\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=659} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=659","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 659","Event ID 659","Security Enabled Universal Group Changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69244,"title":"Windows Security Event 660 - Security Enabled Universal Group Member Added","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 660","Windows"],"keywords":["660","event 660","event id 660","Security Enabled Universal Group Member Added","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=660"],"errorCode":"","eventId":"660","severity":"Medium","summary":"Windows Security event 660 records: Security Enabled Universal Group Member Added","rootCause":"The event records a state-changing operation: Security Enabled Universal Group Member Added It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 660.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Enabled Universal Group Member Added\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=660\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=660} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=660","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 660","Event ID 660","Security Enabled Universal Group Member Added"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69245,"title":"Windows Security Event 661 - Security Enabled Universal Group Member Removed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 661","Windows"],"keywords":["661","event 661","event id 661","Security Enabled Universal Group Member Removed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=661"],"errorCode":"","eventId":"661","severity":"Medium","summary":"Windows Security event 661 records: Security Enabled Universal Group Member Removed","rootCause":"The event records a state-changing operation: Security Enabled Universal Group Member Removed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 661.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Enabled Universal Group Member Removed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=661\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=661} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=661","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 661","Event ID 661","Security Enabled Universal Group Member Removed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69246,"title":"Windows Security Event 662 - Security Enabled Universal Group Deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 662","Windows"],"keywords":["662","event 662","event id 662","Security Enabled Universal Group Deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=662"],"errorCode":"","eventId":"662","severity":"High","summary":"Windows Security event 662 records: Security Enabled Universal Group Deleted","rootCause":"The event records a state-changing operation: Security Enabled Universal Group Deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 662.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Enabled Universal Group Deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=662\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=662} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=662","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 662","Event ID 662","Security Enabled Universal Group Deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69247,"title":"Windows Security Event 663 - Security Disabled Universal Group Created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 663","Windows"],"keywords":["663","event 663","event id 663","Security Disabled Universal Group Created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=663"],"errorCode":"","eventId":"663","severity":"High","summary":"Windows Security event 663 records: Security Disabled Universal Group Created","rootCause":"The event records a state-changing operation: Security Disabled Universal Group Created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 663.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Disabled Universal Group Created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=663\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=663} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=663","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 663","Event ID 663","Security Disabled Universal Group Created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69248,"title":"Windows Security Event 664 - Security Disabled Universal Group Changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 664","Windows"],"keywords":["664","event 664","event id 664","Security Disabled Universal Group Changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=664"],"errorCode":"","eventId":"664","severity":"High","summary":"Windows Security event 664 records: Security Disabled Universal Group Changed","rootCause":"The event records a state-changing operation: Security Disabled Universal Group Changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 664.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Disabled Universal Group Changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=664\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=664} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=664","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 664","Event ID 664","Security Disabled Universal Group Changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69249,"title":"Windows Security Event 665 - Security Disabled Universal Group Member Added","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 665","Windows"],"keywords":["665","event 665","event id 665","Security Disabled Universal Group Member Added","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=665"],"errorCode":"","eventId":"665","severity":"High","summary":"Windows Security event 665 records: Security Disabled Universal Group Member Added","rootCause":"The event records a state-changing operation: Security Disabled Universal Group Member Added It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 665.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Disabled Universal Group Member Added\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=665\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=665} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=665","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 665","Event ID 665","Security Disabled Universal Group Member Added"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69250,"title":"Windows Security Event 666 - Security Disabled Universal Group Member Removed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 666","Windows"],"keywords":["666","event 666","event id 666","Security Disabled Universal Group Member Removed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=666"],"errorCode":"","eventId":"666","severity":"High","summary":"Windows Security event 666 records: Security Disabled Universal Group Member Removed","rootCause":"The event records a state-changing operation: Security Disabled Universal Group Member Removed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 666.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Disabled Universal Group Member Removed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=666\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=666} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=666","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 666","Event ID 666","Security Disabled Universal Group Member Removed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69251,"title":"Windows Security Event 667 - Security Disabled Universal Group Deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 667","Windows"],"keywords":["667","event 667","event id 667","Security Disabled Universal Group Deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=667"],"errorCode":"","eventId":"667","severity":"High","summary":"Windows Security event 667 records: Security Disabled Universal Group Deleted","rootCause":"The event records a state-changing operation: Security Disabled Universal Group Deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 667.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security Disabled Universal Group Deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=667\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=667} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=667","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 667","Event ID 667","Security Disabled Universal Group Deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69252,"title":"Windows Security Event 668 - Group Type Changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 668","Windows"],"keywords":["668","event 668","event id 668","Group Type Changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=668"],"errorCode":"","eventId":"668","severity":"Medium","summary":"Windows Security event 668 records: Group Type Changed","rootCause":"The event records a state-changing operation: Group Type Changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 668.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Group Type Changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=668\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=668} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=668","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 668","Event ID 668","Group Type Changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69253,"title":"Windows Security Event 669 - Add SID History","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 669","Windows"],"keywords":["669","event 669","event id 669","Add SID History","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=669"],"errorCode":"","eventId":"669","severity":"Low","summary":"Windows Security event 669 records: Add SID History","rootCause":"The configured audit source recorded this activity: Add SID History It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 669.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add SID History\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=669\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=669} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=669","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 669","Event ID 669","Add SID History"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69254,"title":"Windows Security Event 670 - Add SID History","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 670","Windows"],"keywords":["670","event 670","event id 670","Add SID History","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=670"],"errorCode":"","eventId":"670","severity":"Low","summary":"Windows Security event 670 records: Add SID History","rootCause":"The configured audit source recorded this activity: Add SID History It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 670.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Add SID History\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=670\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=670} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=670","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 670","Event ID 670","Add SID History"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69255,"title":"Windows Security Event 671 - User Account Unlocked","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 671","Windows"],"keywords":["671","event 671","event id 671","User Account Unlocked","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=671"],"errorCode":"","eventId":"671","severity":"Low","summary":"Windows Security event 671 records: User Account Unlocked","rootCause":"The configured audit source recorded this activity: User Account Unlocked It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 671.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: User Account Unlocked\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=671\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=671} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=671","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 671","Event ID 671","User Account Unlocked"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69256,"title":"Windows Security Event 672 - Authentication Ticket Granted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 672","Windows"],"keywords":["672","event 672","event id 672","Authentication Ticket Granted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=672"],"errorCode":"","eventId":"672","severity":"Low","summary":"Windows Security event 672 records: Authentication Ticket Granted","rootCause":"The configured audit source recorded this activity: Authentication Ticket Granted It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 672.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Authentication Ticket Granted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=672\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=672} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=672","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 672","Event ID 672","Authentication Ticket Granted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69257,"title":"Windows Security Event 673 - Service Ticket Granted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 673","Windows"],"keywords":["673","event 673","event id 673","Service Ticket Granted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=673"],"errorCode":"","eventId":"673","severity":"Low","summary":"Windows Security event 673 records: Service Ticket Granted","rootCause":"The configured audit source recorded this activity: Service Ticket Granted It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 673.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Service Ticket Granted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=673\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=673} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=673","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 673","Event ID 673","Service Ticket Granted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69258,"title":"Windows Security Event 674 - Ticket Granted Renewed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 674","Windows"],"keywords":["674","event 674","event id 674","Ticket Granted Renewed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=674"],"errorCode":"","eventId":"674","severity":"Low","summary":"Windows Security event 674 records: Ticket Granted Renewed","rootCause":"The configured audit source recorded this activity: Ticket Granted Renewed It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 674.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Ticket Granted Renewed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=674\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=674} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=674","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 674","Event ID 674","Ticket Granted Renewed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69259,"title":"Windows Security Event 675 - Pre-authentication failed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 675","Windows"],"keywords":["675","event 675","event id 675","Pre-authentication failed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=675"],"errorCode":"","eventId":"675","severity":"High","summary":"Windows Security event 675 records: Pre-authentication failed","rootCause":"The audited operation reported a failure: Pre-authentication failed The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 675.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Pre-authentication failed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=675\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=675} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=675","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 675","Event ID 675","Pre-authentication failed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69260,"title":"Windows Security Event 676 - Authentication Ticket Request Failed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 676","Windows"],"keywords":["676","event 676","event id 676","Authentication Ticket Request Failed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=676"],"errorCode":"","eventId":"676","severity":"High","summary":"Windows Security event 676 records: Authentication Ticket Request Failed","rootCause":"The audited operation reported a failure: Authentication Ticket Request Failed The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 676.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Authentication Ticket Request Failed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=676\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=676} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=676","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 676","Event ID 676","Authentication Ticket Request Failed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69261,"title":"Windows Security Event 677 - Service Ticket Request Failed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 677","Windows"],"keywords":["677","event 677","event id 677","Service Ticket Request Failed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=677"],"errorCode":"","eventId":"677","severity":"High","summary":"Windows Security event 677 records: Service Ticket Request Failed","rootCause":"The audited operation reported a failure: Service Ticket Request Failed The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 677.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Service Ticket Request Failed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=677\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=677} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=677","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 677","Event ID 677","Service Ticket Request Failed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69262,"title":"Windows Security Event 678 - Account Mapped for Logon by","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 678","Windows"],"keywords":["678","event 678","event id 678","Account Mapped for Logon by","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=678"],"errorCode":"","eventId":"678","severity":"Low","summary":"Windows Security event 678 records: Account Mapped for Logon by","rootCause":"The configured audit source recorded this activity: Account Mapped for Logon by It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 678.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Account Mapped for Logon by\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=678\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=678} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=678","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 678","Event ID 678","Account Mapped for Logon by"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69263,"title":"Windows Security Event 679 - The name: %2 could not be mapped for logon by: %1","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 679","Windows"],"keywords":["679","event 679","event id 679","The name: %2 could not be mapped for logon by: %1","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=679"],"errorCode":"","eventId":"679","severity":"High","summary":"Windows Security event 679 records: The name: %2 could not be mapped for logon by: %1","rootCause":"The audited operation reported a failure: The name: %2 could not be mapped for logon by: %1 The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 679.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The name: %2 could not be mapped for logon by: %1\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=679\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=679} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=679","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 679","Event ID 679","The name: %2 could not be mapped for logon by: %1"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69264,"title":"Windows Security Event 680 - Account Used for Logon by","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 680","Windows"],"keywords":["680","event 680","event id 680","Account Used for Logon by","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=680"],"errorCode":"","eventId":"680","severity":"Low","summary":"Windows Security event 680 records: Account Used for Logon by","rootCause":"The configured audit source recorded this activity: Account Used for Logon by It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 680.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Account Used for Logon by\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=680\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=680} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=680","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 680","Event ID 680","Account Used for Logon by"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69265,"title":"Windows Security Event 681 - The logon to account: %2 by: %1 from workstation: %3 failed.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 681","Windows"],"keywords":["681","event 681","event id 681","The logon to account: %2 by: %1 from workstation: %3 failed.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=681"],"errorCode":"","eventId":"681","severity":"High","summary":"Windows Security event 681 records: The logon to account: %2 by: %1 from workstation: %3 failed.","rootCause":"The audited operation reported a failure: The logon to account: %2 by: %1 from workstation: %3 failed. The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 681.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The logon to account: %2 by: %1 from workstation: %3 failed.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=681\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=681} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=681","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 681","Event ID 681","The logon to account: %2 by: %1 from workstation: %3 failed."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69266,"title":"Windows Security Event 682 - Session reconnected to winstation","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 682","Windows"],"keywords":["682","event 682","event id 682","Session reconnected to winstation","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=682"],"errorCode":"","eventId":"682","severity":"Low","summary":"Windows Security event 682 records: Session reconnected to winstation","rootCause":"The configured audit source recorded this activity: Session reconnected to winstation It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 682.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Session reconnected to winstation\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=682\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=682} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=682","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 682","Event ID 682","Session reconnected to winstation"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69267,"title":"Windows Security Event 683 - Session disconnected from winstation","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 683","Windows"],"keywords":["683","event 683","event id 683","Session disconnected from winstation","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=683"],"errorCode":"","eventId":"683","severity":"Low","summary":"Windows Security event 683 records: Session disconnected from winstation","rootCause":"The configured audit source recorded this activity: Session disconnected from winstation It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 683.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Session disconnected from winstation\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=683\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=683} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=683","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 683","Event ID 683","Session disconnected from winstation"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69268,"title":"Windows Security Event 684 - Set ACLs of members in administrators groups","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 684","Windows"],"keywords":["684","event 684","event id 684","Set ACLs of members in administrators groups","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=684"],"errorCode":"","eventId":"684","severity":"Medium","summary":"Windows Security event 684 records: Set ACLs of members in administrators groups","rootCause":"The configured audit source recorded this activity: Set ACLs of members in administrators groups It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 684.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Set ACLs of members in administrators groups\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=684\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=684} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=684","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 684","Event ID 684","Set ACLs of members in administrators groups"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69269,"title":"Windows Security Event 685 - Account Name Changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 685","Windows"],"keywords":["685","event 685","event id 685","Account Name Changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=685"],"errorCode":"","eventId":"685","severity":"Medium","summary":"Windows Security event 685 records: Account Name Changed","rootCause":"The event records a state-changing operation: Account Name Changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 685.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Account Name Changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=685\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=685} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=685","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 685","Event ID 685","Account Name Changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69270,"title":"Windows Security Event 686 - Password of the following user accessed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 686","Windows"],"keywords":["686","event 686","event id 686","Password of the following user accessed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=686"],"errorCode":"","eventId":"686","severity":"Medium","summary":"Windows Security event 686 records: Password of the following user accessed","rootCause":"The configured audit source recorded this activity: Password of the following user accessed It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 686.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Password of the following user accessed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=686\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=686} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=686","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 686","Event ID 686","Password of the following user accessed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69271,"title":"Windows Security Event 687 - Basic Application Group Created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 687","Windows"],"keywords":["687","event 687","event id 687","Basic Application Group Created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=687"],"errorCode":"","eventId":"687","severity":"Medium","summary":"Windows Security event 687 records: Basic Application Group Created","rootCause":"The event records a state-changing operation: Basic Application Group Created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 687.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Basic Application Group Created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=687\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=687} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=687","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 687","Event ID 687","Basic Application Group Created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69272,"title":"Windows Security Event 688 - Basic Application Group Changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 688","Windows"],"keywords":["688","event 688","event id 688","Basic Application Group Changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=688"],"errorCode":"","eventId":"688","severity":"Medium","summary":"Windows Security event 688 records: Basic Application Group Changed","rootCause":"The event records a state-changing operation: Basic Application Group Changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 688.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Basic Application Group Changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=688\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=688} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=688","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 688","Event ID 688","Basic Application Group Changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69273,"title":"Windows Security Event 689 - Basic Application Group Member Added","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 689","Windows"],"keywords":["689","event 689","event id 689","Basic Application Group Member Added","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=689"],"errorCode":"","eventId":"689","severity":"Medium","summary":"Windows Security event 689 records: Basic Application Group Member Added","rootCause":"The event records a state-changing operation: Basic Application Group Member Added It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 689.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Basic Application Group Member Added\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=689\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=689} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=689","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 689","Event ID 689","Basic Application Group Member Added"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69274,"title":"Windows Security Event 690 - Basic Application Group Member Removed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 690","Windows"],"keywords":["690","event 690","event id 690","Basic Application Group Member Removed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=690"],"errorCode":"","eventId":"690","severity":"Medium","summary":"Windows Security event 690 records: Basic Application Group Member Removed","rootCause":"The event records a state-changing operation: Basic Application Group Member Removed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 690.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Basic Application Group Member Removed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=690\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=690} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=690","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 690","Event ID 690","Basic Application Group Member Removed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69275,"title":"Windows Security Event 691 - Basic Application Group Non-Member Added","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 691","Windows"],"keywords":["691","event 691","event id 691","Basic Application Group Non-Member Added","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=691"],"errorCode":"","eventId":"691","severity":"Medium","summary":"Windows Security event 691 records: Basic Application Group Non-Member Added","rootCause":"The event records a state-changing operation: Basic Application Group Non-Member Added It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 691.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Basic Application Group Non-Member Added\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=691\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=691} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=691","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 691","Event ID 691","Basic Application Group Non-Member Added"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69276,"title":"Windows Security Event 692 - Basic Application Group Non-Member Removed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 692","Windows"],"keywords":["692","event 692","event id 692","Basic Application Group Non-Member Removed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=692"],"errorCode":"","eventId":"692","severity":"Medium","summary":"Windows Security event 692 records: Basic Application Group Non-Member Removed","rootCause":"The event records a state-changing operation: Basic Application Group Non-Member Removed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 692.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Basic Application Group Non-Member Removed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=692\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=692} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=692","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 692","Event ID 692","Basic Application Group Non-Member Removed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69277,"title":"Windows Security Event 693 - Basic Application Group Deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 693","Windows"],"keywords":["693","event 693","event id 693","Basic Application Group Deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=693"],"errorCode":"","eventId":"693","severity":"High","summary":"Windows Security event 693 records: Basic Application Group Deleted","rootCause":"The event records a state-changing operation: Basic Application Group Deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 693.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Basic Application Group Deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=693\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=693} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=693","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 693","Event ID 693","Basic Application Group Deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69278,"title":"Windows Security Event 694 - LDAP Query Group Created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 694","Windows"],"keywords":["694","event 694","event id 694","LDAP Query Group Created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=694"],"errorCode":"","eventId":"694","severity":"Medium","summary":"Windows Security event 694 records: LDAP Query Group Created","rootCause":"The event records a state-changing operation: LDAP Query Group Created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 694.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: LDAP Query Group Created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=694\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=694} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=694","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 694","Event ID 694","LDAP Query Group Created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69279,"title":"Windows Security Event 695 - LDAP Query Group Changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 695","Windows"],"keywords":["695","event 695","event id 695","LDAP Query Group Changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=695"],"errorCode":"","eventId":"695","severity":"Medium","summary":"Windows Security event 695 records: LDAP Query Group Changed","rootCause":"The event records a state-changing operation: LDAP Query Group Changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 695.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: LDAP Query Group Changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=695\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=695} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=695","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 695","Event ID 695","LDAP Query Group Changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69280,"title":"Windows Security Event 696 - LDAP Query Group Deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 696","Windows"],"keywords":["696","event 696","event id 696","LDAP Query Group Deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=696"],"errorCode":"","eventId":"696","severity":"High","summary":"Windows Security event 696 records: LDAP Query Group Deleted","rootCause":"The event records a state-changing operation: LDAP Query Group Deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 696.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: LDAP Query Group Deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=696\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=696} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=696","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 696","Event ID 696","LDAP Query Group Deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69281,"title":"Windows Security Event 697 - Password Policy Checking API is called","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 697","Windows"],"keywords":["697","event 697","event id 697","Password Policy Checking API is called","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=697"],"errorCode":"","eventId":"697","severity":"Medium","summary":"Windows Security event 697 records: Password Policy Checking API is called","rootCause":"The configured audit source recorded this activity: Password Policy Checking API is called It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 697.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Password Policy Checking API is called\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=697\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=697} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=697","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 697","Event ID 697","Password Policy Checking API is called"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69282,"title":"Windows Security Event 806 - Per User Audit Policy was refreshed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 806","Windows"],"keywords":["806","event 806","event id 806","Per User Audit Policy was refreshed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=806"],"errorCode":"","eventId":"806","severity":"Medium","summary":"Windows Security event 806 records: Per User Audit Policy was refreshed","rootCause":"The configured audit source recorded this activity: Per User Audit Policy was refreshed It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 806.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Per User Audit Policy was refreshed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=806\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=806} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=806","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 806","Event ID 806","Per User Audit Policy was refreshed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69283,"title":"Windows Security Event 807 - Per user auditing policy set for user","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 807","Windows"],"keywords":["807","event 807","event id 807","Per user auditing policy set for user","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=807"],"errorCode":"","eventId":"807","severity":"Medium","summary":"Windows Security event 807 records: Per user auditing policy set for user","rootCause":"The configured audit source recorded this activity: Per user auditing policy set for user It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 807.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Per user auditing policy set for user\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=807\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=807} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=807","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 807","Event ID 807","Per user auditing policy set for user"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69284,"title":"Windows Security Event 808 - A security event source has attempted to register","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 808","Windows"],"keywords":["808","event 808","event id 808","A security event source has attempted to register","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=808"],"errorCode":"","eventId":"808","severity":"Low","summary":"Windows Security event 808 records: A security event source has attempted to register","rootCause":"The configured audit source recorded this activity: A security event source has attempted to register It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 808.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A security event source has attempted to register\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=808\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=808} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=808","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 808","Event ID 808","A security event source has attempted to register"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69285,"title":"Windows Security Event 809 - A security event source has attempted to unregister","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 809","Windows"],"keywords":["809","event 809","event id 809","A security event source has attempted to unregister","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=809"],"errorCode":"","eventId":"809","severity":"Low","summary":"Windows Security event 809 records: A security event source has attempted to unregister","rootCause":"The configured audit source recorded this activity: A security event source has attempted to unregister It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 809.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A security event source has attempted to unregister\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=809\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=809} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=809","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 809","Event ID 809","A security event source has attempted to unregister"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69286,"title":"Windows Security Event 848 - The following policy was active when the Windows Firewall started","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 848","Windows"],"keywords":["848","event 848","event id 848","The following policy was active when the Windows Firewall started","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=848"],"errorCode":"","eventId":"848","severity":"Medium","summary":"Windows Security event 848 records: The following policy was active when the Windows Firewall started","rootCause":"The configured audit source recorded this activity: The following policy was active when the Windows Firewall started It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 848.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The following policy was active when the Windows Firewall started\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=848\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=848} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=848","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 848","Event ID 848","The following policy was active when the Windows Firewall started"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69287,"title":"Windows Security Event 849 - An application was listed as an exception when the Windows Firewall started","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 849","Windows"],"keywords":["849","event 849","event id 849","An application was listed as an exception when the Windows Firewall started","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=849"],"errorCode":"","eventId":"849","severity":"Medium","summary":"Windows Security event 849 records: An application was listed as an exception when the Windows Firewall started","rootCause":"The configured audit source recorded this activity: An application was listed as an exception when the Windows Firewall started It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 849.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An application was listed as an exception when the Windows Firewall started\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=849\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=849} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=849","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 849","Event ID 849","An application was listed as an exception when the Windows Firewall started"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69288,"title":"Windows Security Event 850 - A port was listed as an exception when the Windows Firewall started","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 850","Windows"],"keywords":["850","event 850","event id 850","A port was listed as an exception when the Windows Firewall started","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=850"],"errorCode":"","eventId":"850","severity":"Medium","summary":"Windows Security event 850 records: A port was listed as an exception when the Windows Firewall started","rootCause":"The configured audit source recorded this activity: A port was listed as an exception when the Windows Firewall started It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 850.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A port was listed as an exception when the Windows Firewall started\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=850\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=850} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=850","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 850","Event ID 850","A port was listed as an exception when the Windows Firewall started"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69289,"title":"Windows Security Event 851 - A change has been made to the Windows Firewall application exception list","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 851","Windows"],"keywords":["851","event 851","event id 851","A change has been made to the Windows Firewall application exception list","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=851"],"errorCode":"","eventId":"851","severity":"Medium","summary":"Windows Security event 851 records: A change has been made to the Windows Firewall application exception list","rootCause":"The configured audit source recorded this activity: A change has been made to the Windows Firewall application exception list It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 851.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A change has been made to the Windows Firewall application exception list\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=851\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=851} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=851","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 851","Event ID 851","A change has been made to the Windows Firewall application exception list"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69290,"title":"Windows Security Event 852 - A change has been made to the Windows Firewall port exception list","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 852","Windows"],"keywords":["852","event 852","event id 852","A change has been made to the Windows Firewall port exception list","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=852"],"errorCode":"","eventId":"852","severity":"Medium","summary":"Windows Security event 852 records: A change has been made to the Windows Firewall port exception list","rootCause":"The configured audit source recorded this activity: A change has been made to the Windows Firewall port exception list It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 852.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A change has been made to the Windows Firewall port exception list\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=852\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=852} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=852","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 852","Event ID 852","A change has been made to the Windows Firewall port exception list"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69291,"title":"Windows Security Event 853 - The Windows Firewall operational mode has changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 853","Windows"],"keywords":["853","event 853","event id 853","The Windows Firewall operational mode has changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=853"],"errorCode":"","eventId":"853","severity":"Medium","summary":"Windows Security event 853 records: The Windows Firewall operational mode has changed","rootCause":"The event records a state-changing operation: The Windows Firewall operational mode has changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 853.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Firewall operational mode has changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=853\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=853} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=853","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 853","Event ID 853","The Windows Firewall operational mode has changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69292,"title":"Windows Security Event 854 - The Windows Firewall logging settings have changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 854","Windows"],"keywords":["854","event 854","event id 854","The Windows Firewall logging settings have changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=854"],"errorCode":"","eventId":"854","severity":"Medium","summary":"Windows Security event 854 records: The Windows Firewall logging settings have changed","rootCause":"The event records a state-changing operation: The Windows Firewall logging settings have changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 854.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Firewall logging settings have changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=854\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=854} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=854","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 854","Event ID 854","The Windows Firewall logging settings have changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69293,"title":"Windows Security Event 855 - A Windows Firewall ICMP setting has changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 855","Windows"],"keywords":["855","event 855","event id 855","A Windows Firewall ICMP setting has changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=855"],"errorCode":"","eventId":"855","severity":"Medium","summary":"Windows Security event 855 records: A Windows Firewall ICMP setting has changed","rootCause":"The event records a state-changing operation: A Windows Firewall ICMP setting has changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 855.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A Windows Firewall ICMP setting has changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=855\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=855} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=855","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 855","Event ID 855","A Windows Firewall ICMP setting has changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69294,"title":"Windows Security Event 856 - The Windows Firewall setting to allow unicast responses to multicast/broadcast traffic has changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 856","Windows"],"keywords":["856","event 856","event id 856","The Windows Firewall setting to allow unicast responses to multicast/broadcast traffic has changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=856"],"errorCode":"","eventId":"856","severity":"Medium","summary":"Windows Security event 856 records: The Windows Firewall setting to allow unicast responses to multicast/broadcast traffic has changed","rootCause":"The event records a state-changing operation: The Windows Firewall setting to allow unicast responses to multicast/broadcast traffic has changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 856.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Firewall setting to allow unicast responses to multicast/broadcast traffic has changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=856\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=856} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=856","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 856","Event ID 856","The Windows Firewall setting to allow unicast responses to multicast/broadcast traffic has changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69295,"title":"Windows Security Event 857 - The Windows Firewall setting to allow remote administration, allowing port TCP 135 and DCOM/RPC, has changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 857","Windows"],"keywords":["857","event 857","event id 857","The Windows Firewall setting to allow remote administration, allowing port TCP 135 and DCOM/RPC, has changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=857"],"errorCode":"","eventId":"857","severity":"Medium","summary":"Windows Security event 857 records: The Windows Firewall setting to allow remote administration, allowing port TCP 135 and DCOM/RPC, has changed","rootCause":"The event records a state-changing operation: The Windows Firewall setting to allow remote administration, allowing port TCP 135 and DCOM/RPC, has changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 857.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Firewall setting to allow remote administration, allowing port TCP 135 and DCOM/RPC, has changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=857\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=857} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=857","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 857","Event ID 857","The Windows Firewall setting to allow remote administration, allowing port TCP 135 and DCOM/RPC, has changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69296,"title":"Windows Security Event 858 - Windows Firewall group policy settings have been applied","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 858","Windows"],"keywords":["858","event 858","event id 858","Windows Firewall group policy settings have been applied","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=858"],"errorCode":"","eventId":"858","severity":"Medium","summary":"Windows Security event 858 records: Windows Firewall group policy settings have been applied","rootCause":"The configured audit source recorded this activity: Windows Firewall group policy settings have been applied It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 858.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Windows Firewall group policy settings have been applied\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=858\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=858} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=858","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 858","Event ID 858","Windows Firewall group policy settings have been applied"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69297,"title":"Windows Security Event 859 - The Windows Firewall group policy settings have been removed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 859","Windows"],"keywords":["859","event 859","event id 859","The Windows Firewall group policy settings have been removed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=859"],"errorCode":"","eventId":"859","severity":"Medium","summary":"Windows Security event 859 records: The Windows Firewall group policy settings have been removed","rootCause":"The event records a state-changing operation: The Windows Firewall group policy settings have been removed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 859.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Firewall group policy settings have been removed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=859\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=859} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=859","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 859","Event ID 859","The Windows Firewall group policy settings have been removed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69298,"title":"Windows Security Event 860 - The Windows Firewall has switched the active policy profile","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 860","Windows"],"keywords":["860","event 860","event id 860","The Windows Firewall has switched the active policy profile","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=860"],"errorCode":"","eventId":"860","severity":"Medium","summary":"Windows Security event 860 records: The Windows Firewall has switched the active policy profile","rootCause":"The configured audit source recorded this activity: The Windows Firewall has switched the active policy profile It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 860.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Firewall has switched the active policy profile\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=860\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=860} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=860","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 860","Event ID 860","The Windows Firewall has switched the active policy profile"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69299,"title":"Windows Security Event 861 - The Windows Firewall has detected an application listening for incoming traffic","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 861","Windows"],"keywords":["861","event 861","event id 861","The Windows Firewall has detected an application listening for incoming traffic","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=861"],"errorCode":"","eventId":"861","severity":"Medium","summary":"Windows Security event 861 records: The Windows Firewall has detected an application listening for incoming traffic","rootCause":"The configured audit source recorded this activity: The Windows Firewall has detected an application listening for incoming traffic It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 861.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Firewall has detected an application listening for incoming traffic\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=861\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=861} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=861","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 861","Event ID 861","The Windows Firewall has detected an application listening for incoming traffic"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69300,"title":"Windows Security Event 1100 - The event logging service has shut down","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 1100","Windows"],"keywords":["1100","event 1100","event id 1100","The event logging service has shut down","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1100"],"errorCode":"","eventId":"1100","severity":"Low","summary":"Windows Security event 1100 records: The event logging service has shut down","rootCause":"The configured audit source recorded this activity: The event logging service has shut down It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 1100.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The event logging service has shut down\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1100\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=1100} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1100","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 1100","Event ID 1100","The event logging service has shut down"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69301,"title":"Windows Security Event 1101 - Audit events have been dropped by the transport.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 1101","Windows"],"keywords":["1101","event 1101","event id 1101","Audit events have been dropped by the transport.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1101"],"errorCode":"","eventId":"1101","severity":"Critical","summary":"Windows Security event 1101 records: Audit events have been dropped by the transport.","rootCause":"The configured audit source recorded this activity: Audit events have been dropped by the transport. It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 1101.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Audit events have been dropped by the transport.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1101\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=1101} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1101","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 1101","Event ID 1101","Audit events have been dropped by the transport."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69302,"title":"Windows Security Event 1102 - The audit log was cleared","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 1102","Windows"],"keywords":["1102","event 1102","event id 1102","The audit log was cleared","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1102"],"errorCode":"","eventId":"1102","severity":"Critical","summary":"Windows Security event 1102 records: The audit log was cleared","rootCause":"The configured audit source recorded this activity: The audit log was cleared It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 1102.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The audit log was cleared\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1102\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=1102} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1102","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 1102","Event ID 1102","The audit log was cleared"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69303,"title":"Windows Security Event 1104 - The security Log is now full","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 1104","Windows"],"keywords":["1104","event 1104","event id 1104","The security Log is now full","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1104"],"errorCode":"","eventId":"1104","severity":"Low","summary":"Windows Security event 1104 records: The security Log is now full","rootCause":"The configured audit source recorded this activity: The security Log is now full It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 1104.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The security Log is now full\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1104\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=1104} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1104","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 1104","Event ID 1104","The security Log is now full"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69304,"title":"Windows Security Event 1105 - Event log automatic backup","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 1105","Windows"],"keywords":["1105","event 1105","event id 1105","Event log automatic backup","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1105"],"errorCode":"","eventId":"1105","severity":"Low","summary":"Windows Security event 1105 records: Event log automatic backup","rootCause":"The configured audit source recorded this activity: Event log automatic backup It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 1105.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Event log automatic backup\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1105\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=1105} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1105","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 1105","Event ID 1105","Event log automatic backup"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69305,"title":"Windows Security Event 1108 - The event logging service encountered an error","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 1108","Windows"],"keywords":["1108","event 1108","event id 1108","The event logging service encountered an error","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1108"],"errorCode":"","eventId":"1108","severity":"High","summary":"Windows Security event 1108 records: The event logging service encountered an error","rootCause":"The audited operation reported a failure: The event logging service encountered an error The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 1108.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The event logging service encountered an error\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1108\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=1108} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1108","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 1108","Event ID 1108","The event logging service encountered an error"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69306,"title":"Windows Security Event 4608 - Windows is starting up","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4608","Windows"],"keywords":["4608","event 4608","event id 4608","Windows is starting up","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4608"],"errorCode":"","eventId":"4608","severity":"Low","summary":"Windows Security event 4608 records: Windows is starting up","rootCause":"The configured audit source recorded this activity: Windows is starting up It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4608.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Windows is starting up\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4608\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4608} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4608","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4608","Event ID 4608","Windows is starting up"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69307,"title":"Windows Security Event 4609 - Windows is shutting down","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4609","Windows"],"keywords":["4609","event 4609","event id 4609","Windows is shutting down","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4609"],"errorCode":"","eventId":"4609","severity":"Low","summary":"Windows Security event 4609 records: Windows is shutting down","rootCause":"The configured audit source recorded this activity: Windows is shutting down It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4609.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Windows is shutting down\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4609\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4609} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4609","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4609","Event ID 4609","Windows is shutting down"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69308,"title":"Windows Security Event 4610 - An authentication package has been loaded by the Local Security Authority","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4610","Windows"],"keywords":["4610","event 4610","event id 4610","An authentication package has been loaded by the Local Security Authority","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4610"],"errorCode":"","eventId":"4610","severity":"Low","summary":"Windows Security event 4610 records: An authentication package has been loaded by the Local Security Authority","rootCause":"The configured audit source recorded this activity: An authentication package has been loaded by the Local Security Authority It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4610.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An authentication package has been loaded by the Local Security Authority\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4610\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4610} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4610","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4610","Event ID 4610","An authentication package has been loaded by the Local Security Authority"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69309,"title":"Windows Security Event 4611 - A trusted logon process has been registered with the Local Security Authority","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4611","Windows"],"keywords":["4611","event 4611","event id 4611","A trusted logon process has been registered with the Local Security Authority","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4611"],"errorCode":"","eventId":"4611","severity":"Medium","summary":"Windows Security event 4611 records: A trusted logon process has been registered with the Local Security Authority","rootCause":"The configured audit source recorded this activity: A trusted logon process has been registered with the Local Security Authority It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4611.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A trusted logon process has been registered with the Local Security Authority\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4611\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4611} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4611","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4611","Event ID 4611","A trusted logon process has been registered with the Local Security Authority"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69310,"title":"Windows Security Event 4612 - Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4612","Windows"],"keywords":["4612","event 4612","event id 4612","Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4612"],"errorCode":"","eventId":"4612","severity":"Low","summary":"Windows Security event 4612 records: Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits.","rootCause":"The configured audit source recorded this activity: Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits. It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4612.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4612\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4612} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4612","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4612","Event ID 4612","Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69311,"title":"Windows Security Event 4614 - A notification package has been loaded by the Security Account Manager.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4614","Windows"],"keywords":["4614","event 4614","event id 4614","A notification package has been loaded by the Security Account Manager.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4614"],"errorCode":"","eventId":"4614","severity":"Low","summary":"Windows Security event 4614 records: A notification package has been loaded by the Security Account Manager.","rootCause":"The configured audit source recorded this activity: A notification package has been loaded by the Security Account Manager. It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4614.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A notification package has been loaded by the Security Account Manager.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4614\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4614} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4614","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4614","Event ID 4614","A notification package has been loaded by the Security Account Manager."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69312,"title":"Windows Security Event 4615 - Invalid use of LPC port","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4615","Windows"],"keywords":["4615","event 4615","event id 4615","Invalid use of LPC port","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4615"],"errorCode":"","eventId":"4615","severity":"High","summary":"Windows Security event 4615 records: Invalid use of LPC port","rootCause":"The audited operation reported a failure: Invalid use of LPC port The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4615.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Invalid use of LPC port\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4615\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4615} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4615","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4615","Event ID 4615","Invalid use of LPC port"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69313,"title":"Windows Security Event 4616 - The system time was changed.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4616","Windows"],"keywords":["4616","event 4616","event id 4616","The system time was changed.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4616"],"errorCode":"","eventId":"4616","severity":"Medium","summary":"Windows Security event 4616 records: The system time was changed.","rootCause":"The event records a state-changing operation: The system time was changed. It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4616.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The system time was changed.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4616\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4616} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4616","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4616","Event ID 4616","The system time was changed."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69314,"title":"Windows Security Event 4618 - A monitored security event pattern has occurred","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4618","Windows"],"keywords":["4618","event 4618","event id 4618","A monitored security event pattern has occurred","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4618"],"errorCode":"","eventId":"4618","severity":"Low","summary":"Windows Security event 4618 records: A monitored security event pattern has occurred","rootCause":"The configured audit source recorded this activity: A monitored security event pattern has occurred It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4618.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A monitored security event pattern has occurred\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4618\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4618} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4618","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4618","Event ID 4618","A monitored security event pattern has occurred"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69315,"title":"Windows Security Event 4621 - Administrator recovered system from CrashOnAuditFail","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4621","Windows"],"keywords":["4621","event 4621","event id 4621","Administrator recovered system from CrashOnAuditFail","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4621"],"errorCode":"","eventId":"4621","severity":"Low","summary":"Windows Security event 4621 records: Administrator recovered system from CrashOnAuditFail","rootCause":"The configured audit source recorded this activity: Administrator recovered system from CrashOnAuditFail It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4621.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Administrator recovered system from CrashOnAuditFail\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4621\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4621} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4621","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4621","Event ID 4621","Administrator recovered system from CrashOnAuditFail"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69316,"title":"Windows Security Event 4622 - A security package has been loaded by the Local Security Authority.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4622","Windows"],"keywords":["4622","event 4622","event id 4622","A security package has been loaded by the Local Security Authority.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4622"],"errorCode":"","eventId":"4622","severity":"Low","summary":"Windows Security event 4622 records: A security package has been loaded by the Local Security Authority.","rootCause":"The configured audit source recorded this activity: A security package has been loaded by the Local Security Authority. It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4622.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A security package has been loaded by the Local Security Authority.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4622\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4622} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4622","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4622","Event ID 4622","A security package has been loaded by the Local Security Authority."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69317,"title":"Windows Security Event 4624 - An account was successfully logged on","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4624","Windows"],"keywords":["4624","event 4624","event id 4624","An account was successfully logged on","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4624"],"errorCode":"","eventId":"4624","severity":"Low","summary":"Windows Security event 4624 records: An account was successfully logged on","rootCause":"The configured audit source recorded this activity: An account was successfully logged on It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4624.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An account was successfully logged on\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4624\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4624} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4624","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4624","Event ID 4624","An account was successfully logged on"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69318,"title":"Windows Security Event 4625 - An account failed to log on","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4625","Windows"],"keywords":["4625","event 4625","event id 4625","An account failed to log on","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4625"],"errorCode":"","eventId":"4625","severity":"High","summary":"Windows Security event 4625 records: An account failed to log on","rootCause":"The audited operation reported a failure: An account failed to log on The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4625.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An account failed to log on\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4625\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4625","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4625","Event ID 4625","An account failed to log on"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69319,"title":"Windows Security Event 4626 - User/Device claims information","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4626","Windows"],"keywords":["4626","event 4626","event id 4626","User/Device claims information","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4626"],"errorCode":"","eventId":"4626","severity":"Low","summary":"Windows Security event 4626 records: User/Device claims information","rootCause":"The configured audit source recorded this activity: User/Device claims information It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4626.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: User/Device claims information\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4626\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4626} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4626","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4626","Event ID 4626","User/Device claims information"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69320,"title":"Windows Security Event 4627 - Group membership information.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4627","Windows"],"keywords":["4627","event 4627","event id 4627","Group membership information.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4627"],"errorCode":"","eventId":"4627","severity":"Medium","summary":"Windows Security event 4627 records: Group membership information.","rootCause":"The configured audit source recorded this activity: Group membership information. It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4627.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Group membership information.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4627\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4627} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4627","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4627","Event ID 4627","Group membership information."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69321,"title":"Windows Security Event 4634 - An account was logged off","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4634","Windows"],"keywords":["4634","event 4634","event id 4634","An account was logged off","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4634"],"errorCode":"","eventId":"4634","severity":"Low","summary":"Windows Security event 4634 records: An account was logged off","rootCause":"The configured audit source recorded this activity: An account was logged off It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4634.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An account was logged off\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4634\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4634} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4634","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4634","Event ID 4634","An account was logged off"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69322,"title":"Windows Security Event 4646 - IKE DoS-prevention mode started","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4646","Windows"],"keywords":["4646","event 4646","event id 4646","IKE DoS-prevention mode started","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4646"],"errorCode":"","eventId":"4646","severity":"Low","summary":"Windows Security event 4646 records: IKE DoS-prevention mode started","rootCause":"The configured audit source recorded this activity: IKE DoS-prevention mode started It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4646.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: IKE DoS-prevention mode started\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4646\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4646} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4646","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4646","Event ID 4646","IKE DoS-prevention mode started"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69323,"title":"Windows Security Event 4647 - User initiated logoff","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4647","Windows"],"keywords":["4647","event 4647","event id 4647","User initiated logoff","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4647"],"errorCode":"","eventId":"4647","severity":"Low","summary":"Windows Security event 4647 records: User initiated logoff","rootCause":"The configured audit source recorded this activity: User initiated logoff It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4647.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: User initiated logoff\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4647\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4647} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4647","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4647","Event ID 4647","User initiated logoff"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69324,"title":"Windows Security Event 4648 - A logon was attempted using explicit credentials","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4648","Windows"],"keywords":["4648","event 4648","event id 4648","A logon was attempted using explicit credentials","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4648"],"errorCode":"","eventId":"4648","severity":"Low","summary":"Windows Security event 4648 records: A logon was attempted using explicit credentials","rootCause":"The configured audit source recorded this activity: A logon was attempted using explicit credentials It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4648.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A logon was attempted using explicit credentials\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4648\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4648} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4648","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4648","Event ID 4648","A logon was attempted using explicit credentials"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69325,"title":"Windows Security Event 4649 - A replay attack was detected","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4649","Windows"],"keywords":["4649","event 4649","event id 4649","A replay attack was detected","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4649"],"errorCode":"","eventId":"4649","severity":"Low","summary":"Windows Security event 4649 records: A replay attack was detected","rootCause":"The configured audit source recorded this activity: A replay attack was detected It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4649.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A replay attack was detected\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4649\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4649} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4649","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4649","Event ID 4649","A replay attack was detected"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69326,"title":"Windows Security Event 4650 - An IPsec Main Mode security association was established","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4650","Windows"],"keywords":["4650","event 4650","event id 4650","An IPsec Main Mode security association was established","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4650"],"errorCode":"","eventId":"4650","severity":"Medium","summary":"Windows Security event 4650 records: An IPsec Main Mode security association was established","rootCause":"The configured audit source recorded this activity: An IPsec Main Mode security association was established It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4650.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An IPsec Main Mode security association was established\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4650\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4650} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4650","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4650","Event ID 4650","An IPsec Main Mode security association was established"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69327,"title":"Windows Security Event 4651 - An IPsec Main Mode security association was established","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4651","Windows"],"keywords":["4651","event 4651","event id 4651","An IPsec Main Mode security association was established","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4651"],"errorCode":"","eventId":"4651","severity":"Medium","summary":"Windows Security event 4651 records: An IPsec Main Mode security association was established","rootCause":"The configured audit source recorded this activity: An IPsec Main Mode security association was established It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4651.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An IPsec Main Mode security association was established\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4651\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4651} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4651","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4651","Event ID 4651","An IPsec Main Mode security association was established"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69328,"title":"Windows Security Event 4652 - An IPsec Main Mode negotiation failed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4652","Windows"],"keywords":["4652","event 4652","event id 4652","An IPsec Main Mode negotiation failed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4652"],"errorCode":"","eventId":"4652","severity":"High","summary":"Windows Security event 4652 records: An IPsec Main Mode negotiation failed","rootCause":"The audited operation reported a failure: An IPsec Main Mode negotiation failed The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4652.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An IPsec Main Mode negotiation failed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4652\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4652} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4652","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4652","Event ID 4652","An IPsec Main Mode negotiation failed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69329,"title":"Windows Security Event 4653 - An IPsec Main Mode negotiation failed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4653","Windows"],"keywords":["4653","event 4653","event id 4653","An IPsec Main Mode negotiation failed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4653"],"errorCode":"","eventId":"4653","severity":"High","summary":"Windows Security event 4653 records: An IPsec Main Mode negotiation failed","rootCause":"The audited operation reported a failure: An IPsec Main Mode negotiation failed The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4653.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An IPsec Main Mode negotiation failed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4653\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4653} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4653","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4653","Event ID 4653","An IPsec Main Mode negotiation failed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69330,"title":"Windows Security Event 4654 - An IPsec Quick Mode negotiation failed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4654","Windows"],"keywords":["4654","event 4654","event id 4654","An IPsec Quick Mode negotiation failed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4654"],"errorCode":"","eventId":"4654","severity":"High","summary":"Windows Security event 4654 records: An IPsec Quick Mode negotiation failed","rootCause":"The audited operation reported a failure: An IPsec Quick Mode negotiation failed The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4654.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An IPsec Quick Mode negotiation failed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4654\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4654} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4654","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4654","Event ID 4654","An IPsec Quick Mode negotiation failed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69331,"title":"Windows Security Event 4655 - An IPsec Main Mode security association ended","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4655","Windows"],"keywords":["4655","event 4655","event id 4655","An IPsec Main Mode security association ended","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4655"],"errorCode":"","eventId":"4655","severity":"Medium","summary":"Windows Security event 4655 records: An IPsec Main Mode security association ended","rootCause":"The configured audit source recorded this activity: An IPsec Main Mode security association ended It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4655.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An IPsec Main Mode security association ended\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4655\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4655} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4655","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4655","Event ID 4655","An IPsec Main Mode security association ended"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69332,"title":"Windows Security Event 4656 - A handle to an object was requested","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4656","Windows"],"keywords":["4656","event 4656","event id 4656","A handle to an object was requested","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4656"],"errorCode":"","eventId":"4656","severity":"Low","summary":"Windows Security event 4656 records: A handle to an object was requested","rootCause":"The configured audit source recorded this activity: A handle to an object was requested It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4656.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A handle to an object was requested\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4656\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4656} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4656","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4656","Event ID 4656","A handle to an object was requested"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69333,"title":"Windows Security Event 4657 - A registry value was modified","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4657","Windows"],"keywords":["4657","event 4657","event id 4657","A registry value was modified","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4657"],"errorCode":"","eventId":"4657","severity":"Medium","summary":"Windows Security event 4657 records: A registry value was modified","rootCause":"The event records a state-changing operation: A registry value was modified It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4657.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A registry value was modified\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4657\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4657} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4657","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4657","Event ID 4657","A registry value was modified"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69334,"title":"Windows Security Event 4658 - The handle to an object was closed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4658","Windows"],"keywords":["4658","event 4658","event id 4658","The handle to an object was closed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4658"],"errorCode":"","eventId":"4658","severity":"Low","summary":"Windows Security event 4658 records: The handle to an object was closed","rootCause":"The configured audit source recorded this activity: The handle to an object was closed It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4658.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The handle to an object was closed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4658\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4658} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4658","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4658","Event ID 4658","The handle to an object was closed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69335,"title":"Windows Security Event 4659 - A handle to an object was requested with intent to delete","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4659","Windows"],"keywords":["4659","event 4659","event id 4659","A handle to an object was requested with intent to delete","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4659"],"errorCode":"","eventId":"4659","severity":"Low","summary":"Windows Security event 4659 records: A handle to an object was requested with intent to delete","rootCause":"The configured audit source recorded this activity: A handle to an object was requested with intent to delete It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4659.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A handle to an object was requested with intent to delete\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4659\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4659} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4659","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4659","Event ID 4659","A handle to an object was requested with intent to delete"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69336,"title":"Windows Security Event 4660 - An object was deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4660","Windows"],"keywords":["4660","event 4660","event id 4660","An object was deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4660"],"errorCode":"","eventId":"4660","severity":"High","summary":"Windows Security event 4660 records: An object was deleted","rootCause":"The event records a state-changing operation: An object was deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4660.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An object was deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4660\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4660} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4660","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4660","Event ID 4660","An object was deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69337,"title":"Windows Security Event 4661 - A handle to an object was requested","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4661","Windows"],"keywords":["4661","event 4661","event id 4661","A handle to an object was requested","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4661"],"errorCode":"","eventId":"4661","severity":"Low","summary":"Windows Security event 4661 records: A handle to an object was requested","rootCause":"The configured audit source recorded this activity: A handle to an object was requested It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4661.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A handle to an object was requested\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4661\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4661} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4661","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4661","Event ID 4661","A handle to an object was requested"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69338,"title":"Windows Security Event 4662 - An operation was performed on an object","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4662","Windows"],"keywords":["4662","event 4662","event id 4662","An operation was performed on an object","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4662"],"errorCode":"","eventId":"4662","severity":"Low","summary":"Windows Security event 4662 records: An operation was performed on an object","rootCause":"The configured audit source recorded this activity: An operation was performed on an object It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4662.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An operation was performed on an object\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4662\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4662} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4662","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4662","Event ID 4662","An operation was performed on an object"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69339,"title":"Windows Security Event 4663 - An attempt was made to access an object","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4663","Windows"],"keywords":["4663","event 4663","event id 4663","An attempt was made to access an object","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4663"],"errorCode":"","eventId":"4663","severity":"Low","summary":"Windows Security event 4663 records: An attempt was made to access an object","rootCause":"The configured audit source recorded this activity: An attempt was made to access an object It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4663.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An attempt was made to access an object\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4663\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4663} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4663","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4663","Event ID 4663","An attempt was made to access an object"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69340,"title":"Windows Security Event 4664 - An attempt was made to create a hard link","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4664","Windows"],"keywords":["4664","event 4664","event id 4664","An attempt was made to create a hard link","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4664"],"errorCode":"","eventId":"4664","severity":"Low","summary":"Windows Security event 4664 records: An attempt was made to create a hard link","rootCause":"The configured audit source recorded this activity: An attempt was made to create a hard link It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4664.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An attempt was made to create a hard link\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4664\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4664} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4664","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4664","Event ID 4664","An attempt was made to create a hard link"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69341,"title":"Windows Security Event 4665 - An attempt was made to create an application client context.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4665","Windows"],"keywords":["4665","event 4665","event id 4665","An attempt was made to create an application client context.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4665"],"errorCode":"","eventId":"4665","severity":"Low","summary":"Windows Security event 4665 records: An attempt was made to create an application client context.","rootCause":"The configured audit source recorded this activity: An attempt was made to create an application client context. It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4665.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An attempt was made to create an application client context.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4665\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4665} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4665","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4665","Event ID 4665","An attempt was made to create an application client context."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69342,"title":"Windows Security Event 4666 - An application attempted an operation","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4666","Windows"],"keywords":["4666","event 4666","event id 4666","An application attempted an operation","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4666"],"errorCode":"","eventId":"4666","severity":"Low","summary":"Windows Security event 4666 records: An application attempted an operation","rootCause":"The configured audit source recorded this activity: An application attempted an operation It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4666.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An application attempted an operation\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4666\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4666} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4666","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4666","Event ID 4666","An application attempted an operation"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69343,"title":"Windows Security Event 4667 - An application client context was deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4667","Windows"],"keywords":["4667","event 4667","event id 4667","An application client context was deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4667"],"errorCode":"","eventId":"4667","severity":"High","summary":"Windows Security event 4667 records: An application client context was deleted","rootCause":"The event records a state-changing operation: An application client context was deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4667.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An application client context was deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4667\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4667} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4667","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4667","Event ID 4667","An application client context was deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69344,"title":"Windows Security Event 4668 - An application was initialized","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4668","Windows"],"keywords":["4668","event 4668","event id 4668","An application was initialized","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4668"],"errorCode":"","eventId":"4668","severity":"Low","summary":"Windows Security event 4668 records: An application was initialized","rootCause":"The configured audit source recorded this activity: An application was initialized It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4668.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An application was initialized\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4668\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4668} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4668","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4668","Event ID 4668","An application was initialized"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69345,"title":"Windows Security Event 4670 - Permissions on an object were changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4670","Windows"],"keywords":["4670","event 4670","event id 4670","Permissions on an object were changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4670"],"errorCode":"","eventId":"4670","severity":"Medium","summary":"Windows Security event 4670 records: Permissions on an object were changed","rootCause":"The event records a state-changing operation: Permissions on an object were changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4670.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Permissions on an object were changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4670\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4670} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4670","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4670","Event ID 4670","Permissions on an object were changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69346,"title":"Windows Security Event 4671 - An application attempted to access a blocked ordinal through the TBS","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4671","Windows"],"keywords":["4671","event 4671","event id 4671","An application attempted to access a blocked ordinal through the TBS","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4671"],"errorCode":"","eventId":"4671","severity":"High","summary":"Windows Security event 4671 records: An application attempted to access a blocked ordinal through the TBS","rootCause":"The audited operation reported a failure: An application attempted to access a blocked ordinal through the TBS The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4671.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An application attempted to access a blocked ordinal through the TBS\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4671\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4671} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4671","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4671","Event ID 4671","An application attempted to access a blocked ordinal through the TBS"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69347,"title":"Windows Security Event 4672 - Special privileges assigned to new logon","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4672","Windows"],"keywords":["4672","event 4672","event id 4672","Special privileges assigned to new logon","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4672"],"errorCode":"","eventId":"4672","severity":"Medium","summary":"Windows Security event 4672 records: Special privileges assigned to new logon","rootCause":"The configured audit source recorded this activity: Special privileges assigned to new logon It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4672.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Special privileges assigned to new logon\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4672\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4672} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4672","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4672","Event ID 4672","Special privileges assigned to new logon"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69348,"title":"Windows Security Event 4673 - A privileged service was called","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4673","Windows"],"keywords":["4673","event 4673","event id 4673","A privileged service was called","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4673"],"errorCode":"","eventId":"4673","severity":"Medium","summary":"Windows Security event 4673 records: A privileged service was called","rootCause":"The configured audit source recorded this activity: A privileged service was called It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4673.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A privileged service was called\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4673\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4673} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4673","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4673","Event ID 4673","A privileged service was called"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69349,"title":"Windows Security Event 4674 - An operation was attempted on a privileged object","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4674","Windows"],"keywords":["4674","event 4674","event id 4674","An operation was attempted on a privileged object","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4674"],"errorCode":"","eventId":"4674","severity":"Medium","summary":"Windows Security event 4674 records: An operation was attempted on a privileged object","rootCause":"The configured audit source recorded this activity: An operation was attempted on a privileged object It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4674.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An operation was attempted on a privileged object\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4674\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4674} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4674","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4674","Event ID 4674","An operation was attempted on a privileged object"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69350,"title":"Windows Security Event 4675 - SIDs were filtered","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4675","Windows"],"keywords":["4675","event 4675","event id 4675","SIDs were filtered","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4675"],"errorCode":"","eventId":"4675","severity":"Low","summary":"Windows Security event 4675 records: SIDs were filtered","rootCause":"The configured audit source recorded this activity: SIDs were filtered It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4675.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: SIDs were filtered\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4675\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4675} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4675","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4675","Event ID 4675","SIDs were filtered"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69351,"title":"Windows Security Event 4688 - A new process has been created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4688","Windows"],"keywords":["4688","event 4688","event id 4688","A new process has been created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4688"],"errorCode":"","eventId":"4688","severity":"Medium","summary":"Windows Security event 4688 records: A new process has been created","rootCause":"The event records a state-changing operation: A new process has been created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4688.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A new process has been created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4688\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4688} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4688","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4688","Event ID 4688","A new process has been created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69352,"title":"Windows Security Event 4689 - A process has exited","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4689","Windows"],"keywords":["4689","event 4689","event id 4689","A process has exited","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4689"],"errorCode":"","eventId":"4689","severity":"Low","summary":"Windows Security event 4689 records: A process has exited","rootCause":"The configured audit source recorded this activity: A process has exited It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4689.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A process has exited\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4689\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4689} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4689","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4689","Event ID 4689","A process has exited"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69353,"title":"Windows Security Event 4690 - An attempt was made to duplicate a handle to an object","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4690","Windows"],"keywords":["4690","event 4690","event id 4690","An attempt was made to duplicate a handle to an object","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4690"],"errorCode":"","eventId":"4690","severity":"Low","summary":"Windows Security event 4690 records: An attempt was made to duplicate a handle to an object","rootCause":"The configured audit source recorded this activity: An attempt was made to duplicate a handle to an object It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4690.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An attempt was made to duplicate a handle to an object\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4690\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4690} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4690","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4690","Event ID 4690","An attempt was made to duplicate a handle to an object"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69354,"title":"Windows Security Event 4691 - Indirect access to an object was requested","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4691","Windows"],"keywords":["4691","event 4691","event id 4691","Indirect access to an object was requested","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4691"],"errorCode":"","eventId":"4691","severity":"Low","summary":"Windows Security event 4691 records: Indirect access to an object was requested","rootCause":"The configured audit source recorded this activity: Indirect access to an object was requested It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4691.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Indirect access to an object was requested\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4691\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4691} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4691","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4691","Event ID 4691","Indirect access to an object was requested"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69355,"title":"Windows Security Event 4692 - Backup of data protection master key was attempted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4692","Windows"],"keywords":["4692","event 4692","event id 4692","Backup of data protection master key was attempted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4692"],"errorCode":"","eventId":"4692","severity":"Low","summary":"Windows Security event 4692 records: Backup of data protection master key was attempted","rootCause":"The configured audit source recorded this activity: Backup of data protection master key was attempted It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4692.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Backup of data protection master key was attempted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4692\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4692} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4692","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4692","Event ID 4692","Backup of data protection master key was attempted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69356,"title":"Windows Security Event 4693 - Recovery of data protection master key was attempted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4693","Windows"],"keywords":["4693","event 4693","event id 4693","Recovery of data protection master key was attempted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4693"],"errorCode":"","eventId":"4693","severity":"Low","summary":"Windows Security event 4693 records: Recovery of data protection master key was attempted","rootCause":"The configured audit source recorded this activity: Recovery of data protection master key was attempted It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4693.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Recovery of data protection master key was attempted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4693\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4693} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4693","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4693","Event ID 4693","Recovery of data protection master key was attempted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69357,"title":"Windows Security Event 4694 - Protection of auditable protected data was attempted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4694","Windows"],"keywords":["4694","event 4694","event id 4694","Protection of auditable protected data was attempted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4694"],"errorCode":"","eventId":"4694","severity":"Low","summary":"Windows Security event 4694 records: Protection of auditable protected data was attempted","rootCause":"The configured audit source recorded this activity: Protection of auditable protected data was attempted It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4694.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Protection of auditable protected data was attempted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4694\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4694} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4694","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4694","Event ID 4694","Protection of auditable protected data was attempted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69358,"title":"Windows Security Event 4695 - Unprotection of auditable protected data was attempted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4695","Windows"],"keywords":["4695","event 4695","event id 4695","Unprotection of auditable protected data was attempted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4695"],"errorCode":"","eventId":"4695","severity":"Low","summary":"Windows Security event 4695 records: Unprotection of auditable protected data was attempted","rootCause":"The configured audit source recorded this activity: Unprotection of auditable protected data was attempted It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4695.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Unprotection of auditable protected data was attempted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4695\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4695} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4695","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4695","Event ID 4695","Unprotection of auditable protected data was attempted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69359,"title":"Windows Security Event 4696 - A primary token was assigned to process","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4696","Windows"],"keywords":["4696","event 4696","event id 4696","A primary token was assigned to process","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4696"],"errorCode":"","eventId":"4696","severity":"Low","summary":"Windows Security event 4696 records: A primary token was assigned to process","rootCause":"The configured audit source recorded this activity: A primary token was assigned to process It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4696.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A primary token was assigned to process\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4696\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4696} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4696","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4696","Event ID 4696","A primary token was assigned to process"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69360,"title":"Windows Security Event 4697 - A service was installed in the system","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4697","Windows"],"keywords":["4697","event 4697","event id 4697","A service was installed in the system","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4697"],"errorCode":"","eventId":"4697","severity":"Medium","summary":"Windows Security event 4697 records: A service was installed in the system","rootCause":"The event records a state-changing operation: A service was installed in the system It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4697.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A service was installed in the system\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4697\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4697} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4697","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4697","Event ID 4697","A service was installed in the system"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69361,"title":"Windows Security Event 4698 - A scheduled task was created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4698","Windows"],"keywords":["4698","event 4698","event id 4698","A scheduled task was created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4698"],"errorCode":"","eventId":"4698","severity":"Medium","summary":"Windows Security event 4698 records: A scheduled task was created","rootCause":"The event records a state-changing operation: A scheduled task was created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4698.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A scheduled task was created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4698\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4698} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4698","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4698","Event ID 4698","A scheduled task was created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69362,"title":"Windows Security Event 4699 - A scheduled task was deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4699","Windows"],"keywords":["4699","event 4699","event id 4699","A scheduled task was deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4699"],"errorCode":"","eventId":"4699","severity":"High","summary":"Windows Security event 4699 records: A scheduled task was deleted","rootCause":"The event records a state-changing operation: A scheduled task was deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4699.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A scheduled task was deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4699\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4699} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4699","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4699","Event ID 4699","A scheduled task was deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69363,"title":"Windows Security Event 4700 - A scheduled task was enabled","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4700","Windows"],"keywords":["4700","event 4700","event id 4700","A scheduled task was enabled","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4700"],"errorCode":"","eventId":"4700","severity":"Medium","summary":"Windows Security event 4700 records: A scheduled task was enabled","rootCause":"The event records a state-changing operation: A scheduled task was enabled It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4700.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A scheduled task was enabled\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4700\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4700} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4700","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4700","Event ID 4700","A scheduled task was enabled"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69364,"title":"Windows Security Event 4701 - A scheduled task was disabled","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4701","Windows"],"keywords":["4701","event 4701","event id 4701","A scheduled task was disabled","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4701"],"errorCode":"","eventId":"4701","severity":"High","summary":"Windows Security event 4701 records: A scheduled task was disabled","rootCause":"The event records a state-changing operation: A scheduled task was disabled It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4701.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A scheduled task was disabled\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4701\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4701} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4701","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4701","Event ID 4701","A scheduled task was disabled"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69365,"title":"Windows Security Event 4702 - A scheduled task was updated","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4702","Windows"],"keywords":["4702","event 4702","event id 4702","A scheduled task was updated","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4702"],"errorCode":"","eventId":"4702","severity":"Low","summary":"Windows Security event 4702 records: A scheduled task was updated","rootCause":"The configured audit source recorded this activity: A scheduled task was updated It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4702.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A scheduled task was updated\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4702\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4702} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4702","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4702","Event ID 4702","A scheduled task was updated"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69366,"title":"Windows Security Event 4703 - A token right was adjusted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4703","Windows"],"keywords":["4703","event 4703","event id 4703","A token right was adjusted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4703"],"errorCode":"","eventId":"4703","severity":"Low","summary":"Windows Security event 4703 records: A token right was adjusted","rootCause":"The configured audit source recorded this activity: A token right was adjusted It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4703.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A token right was adjusted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4703\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4703} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4703","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4703","Event ID 4703","A token right was adjusted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69367,"title":"Windows Security Event 4704 - A user right was assigned","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4704","Windows"],"keywords":["4704","event 4704","event id 4704","A user right was assigned","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4704"],"errorCode":"","eventId":"4704","severity":"Low","summary":"Windows Security event 4704 records: A user right was assigned","rootCause":"The configured audit source recorded this activity: A user right was assigned It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4704.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A user right was assigned\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4704\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4704} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4704","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4704","Event ID 4704","A user right was assigned"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69368,"title":"Windows Security Event 4705 - A user right was removed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4705","Windows"],"keywords":["4705","event 4705","event id 4705","A user right was removed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4705"],"errorCode":"","eventId":"4705","severity":"Medium","summary":"Windows Security event 4705 records: A user right was removed","rootCause":"The event records a state-changing operation: A user right was removed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4705.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A user right was removed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4705\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4705} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4705","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4705","Event ID 4705","A user right was removed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69369,"title":"Windows Security Event 4706 - A new trust was created to a domain","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4706","Windows"],"keywords":["4706","event 4706","event id 4706","A new trust was created to a domain","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4706"],"errorCode":"","eventId":"4706","severity":"Medium","summary":"Windows Security event 4706 records: A new trust was created to a domain","rootCause":"The event records a state-changing operation: A new trust was created to a domain It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4706.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A new trust was created to a domain\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4706\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4706} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4706","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4706","Event ID 4706","A new trust was created to a domain"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69370,"title":"Windows Security Event 4707 - A trust to a domain was removed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4707","Windows"],"keywords":["4707","event 4707","event id 4707","A trust to a domain was removed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4707"],"errorCode":"","eventId":"4707","severity":"Medium","summary":"Windows Security event 4707 records: A trust to a domain was removed","rootCause":"The event records a state-changing operation: A trust to a domain was removed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4707.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A trust to a domain was removed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4707\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4707} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4707","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4707","Event ID 4707","A trust to a domain was removed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69371,"title":"Windows Security Event 4709 - IPsec Services was started","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4709","Windows"],"keywords":["4709","event 4709","event id 4709","IPsec Services was started","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4709"],"errorCode":"","eventId":"4709","severity":"Medium","summary":"Windows Security event 4709 records: IPsec Services was started","rootCause":"The configured audit source recorded this activity: IPsec Services was started It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4709.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: IPsec Services was started\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4709\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4709} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4709","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4709","Event ID 4709","IPsec Services was started"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69372,"title":"Windows Security Event 4710 - IPsec Services was disabled","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4710","Windows"],"keywords":["4710","event 4710","event id 4710","IPsec Services was disabled","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4710"],"errorCode":"","eventId":"4710","severity":"High","summary":"Windows Security event 4710 records: IPsec Services was disabled","rootCause":"The event records a state-changing operation: IPsec Services was disabled It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4710.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: IPsec Services was disabled\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4710\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4710} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4710","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4710","Event ID 4710","IPsec Services was disabled"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69373,"title":"Windows Security Event 4711 - PAStore Engine (1%)","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4711","Windows"],"keywords":["4711","event 4711","event id 4711","PAStore Engine (1%)","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4711"],"errorCode":"","eventId":"4711","severity":"Low","summary":"Windows Security event 4711 records: PAStore Engine (1%)","rootCause":"The configured audit source recorded this activity: PAStore Engine (1%) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4711.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: PAStore Engine (1%)\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4711\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4711} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4711","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4711","Event ID 4711","PAStore Engine (1%)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69374,"title":"Windows Security Event 4712 - IPsec Services encountered a potentially serious failure","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4712","Windows"],"keywords":["4712","event 4712","event id 4712","IPsec Services encountered a potentially serious failure","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4712"],"errorCode":"","eventId":"4712","severity":"High","summary":"Windows Security event 4712 records: IPsec Services encountered a potentially serious failure","rootCause":"The audited operation reported a failure: IPsec Services encountered a potentially serious failure The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4712.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: IPsec Services encountered a potentially serious failure\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4712\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4712} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4712","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4712","Event ID 4712","IPsec Services encountered a potentially serious failure"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69375,"title":"Windows Security Event 4713 - Kerberos policy was changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4713","Windows"],"keywords":["4713","event 4713","event id 4713","Kerberos policy was changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4713"],"errorCode":"","eventId":"4713","severity":"Medium","summary":"Windows Security event 4713 records: Kerberos policy was changed","rootCause":"The event records a state-changing operation: Kerberos policy was changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4713.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Kerberos policy was changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4713\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4713} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4713","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4713","Event ID 4713","Kerberos policy was changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69376,"title":"Windows Security Event 4714 - Encrypted data recovery policy was changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4714","Windows"],"keywords":["4714","event 4714","event id 4714","Encrypted data recovery policy was changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4714"],"errorCode":"","eventId":"4714","severity":"Medium","summary":"Windows Security event 4714 records: Encrypted data recovery policy was changed","rootCause":"The event records a state-changing operation: Encrypted data recovery policy was changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4714.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Encrypted data recovery policy was changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4714\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4714} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4714","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4714","Event ID 4714","Encrypted data recovery policy was changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69377,"title":"Windows Security Event 4715 - The audit policy (SACL) on an object was changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4715","Windows"],"keywords":["4715","event 4715","event id 4715","The audit policy (SACL) on an object was changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4715"],"errorCode":"","eventId":"4715","severity":"Medium","summary":"Windows Security event 4715 records: The audit policy (SACL) on an object was changed","rootCause":"The event records a state-changing operation: The audit policy (SACL) on an object was changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4715.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The audit policy (SACL) on an object was changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4715\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4715} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4715","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4715","Event ID 4715","The audit policy (SACL) on an object was changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69378,"title":"Windows Security Event 4716 - Trusted domain information was modified","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4716","Windows"],"keywords":["4716","event 4716","event id 4716","Trusted domain information was modified","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4716"],"errorCode":"","eventId":"4716","severity":"Medium","summary":"Windows Security event 4716 records: Trusted domain information was modified","rootCause":"The event records a state-changing operation: Trusted domain information was modified It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4716.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Trusted domain information was modified\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4716\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4716} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4716","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4716","Event ID 4716","Trusted domain information was modified"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69379,"title":"Windows Security Event 4717 - System security access was granted to an account","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4717","Windows"],"keywords":["4717","event 4717","event id 4717","System security access was granted to an account","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4717"],"errorCode":"","eventId":"4717","severity":"Low","summary":"Windows Security event 4717 records: System security access was granted to an account","rootCause":"The configured audit source recorded this activity: System security access was granted to an account It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4717.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: System security access was granted to an account\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4717\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4717} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4717","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4717","Event ID 4717","System security access was granted to an account"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69380,"title":"Windows Security Event 4718 - System security access was removed from an account","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4718","Windows"],"keywords":["4718","event 4718","event id 4718","System security access was removed from an account","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4718"],"errorCode":"","eventId":"4718","severity":"Medium","summary":"Windows Security event 4718 records: System security access was removed from an account","rootCause":"The event records a state-changing operation: System security access was removed from an account It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4718.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: System security access was removed from an account\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4718\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4718} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4718","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4718","Event ID 4718","System security access was removed from an account"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69381,"title":"Windows Security Event 4719 - System audit policy was changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4719","Windows"],"keywords":["4719","event 4719","event id 4719","System audit policy was changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4719"],"errorCode":"","eventId":"4719","severity":"Medium","summary":"Windows Security event 4719 records: System audit policy was changed","rootCause":"The event records a state-changing operation: System audit policy was changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4719.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: System audit policy was changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4719\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4719} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4719","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4719","Event ID 4719","System audit policy was changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69382,"title":"Windows Security Event 4720 - A user account was created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4720","Windows"],"keywords":["4720","event 4720","event id 4720","A user account was created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4720"],"errorCode":"","eventId":"4720","severity":"Medium","summary":"Windows Security event 4720 records: A user account was created","rootCause":"The event records a state-changing operation: A user account was created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4720.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A user account was created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4720\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4720} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4720","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4720","Event ID 4720","A user account was created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69383,"title":"Windows Security Event 4722 - A user account was enabled","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4722","Windows"],"keywords":["4722","event 4722","event id 4722","A user account was enabled","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4722"],"errorCode":"","eventId":"4722","severity":"Medium","summary":"Windows Security event 4722 records: A user account was enabled","rootCause":"The event records a state-changing operation: A user account was enabled It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4722.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A user account was enabled\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4722\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4722} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4722","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4722","Event ID 4722","A user account was enabled"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69384,"title":"Windows Security Event 4723 - An attempt was made to change an account's password","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4723","Windows"],"keywords":["4723","event 4723","event id 4723","An attempt was made to change an account's password","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4723"],"errorCode":"","eventId":"4723","severity":"Medium","summary":"Windows Security event 4723 records: An attempt was made to change an account's password","rootCause":"The configured audit source recorded this activity: An attempt was made to change an account's password It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4723.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An attempt was made to change an account's password\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4723\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4723} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4723","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4723","Event ID 4723","An attempt was made to change an account's password"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69385,"title":"Windows Security Event 4724 - An attempt was made to reset an accounts password","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4724","Windows"],"keywords":["4724","event 4724","event id 4724","An attempt was made to reset an accounts password","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4724"],"errorCode":"","eventId":"4724","severity":"Medium","summary":"Windows Security event 4724 records: An attempt was made to reset an accounts password","rootCause":"The event records a state-changing operation: An attempt was made to reset an accounts password It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4724.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An attempt was made to reset an accounts password\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4724\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4724} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4724","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4724","Event ID 4724","An attempt was made to reset an accounts password"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69386,"title":"Windows Security Event 4725 - A user account was disabled","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4725","Windows"],"keywords":["4725","event 4725","event id 4725","A user account was disabled","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4725"],"errorCode":"","eventId":"4725","severity":"High","summary":"Windows Security event 4725 records: A user account was disabled","rootCause":"The event records a state-changing operation: A user account was disabled It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4725.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A user account was disabled\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4725\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4725} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4725","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4725","Event ID 4725","A user account was disabled"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69387,"title":"Windows Security Event 4726 - A user account was deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4726","Windows"],"keywords":["4726","event 4726","event id 4726","A user account was deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4726"],"errorCode":"","eventId":"4726","severity":"High","summary":"Windows Security event 4726 records: A user account was deleted","rootCause":"The event records a state-changing operation: A user account was deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4726.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A user account was deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4726\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4726} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4726","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4726","Event ID 4726","A user account was deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69388,"title":"Windows Security Event 4727 - A security-enabled global group was created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4727","Windows"],"keywords":["4727","event 4727","event id 4727","A security-enabled global group was created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4727"],"errorCode":"","eventId":"4727","severity":"Medium","summary":"Windows Security event 4727 records: A security-enabled global group was created","rootCause":"The event records a state-changing operation: A security-enabled global group was created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4727.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A security-enabled global group was created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4727\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4727} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4727","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4727","Event ID 4727","A security-enabled global group was created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69389,"title":"Windows Security Event 4728 - A member was added to a security-enabled global group","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4728","Windows"],"keywords":["4728","event 4728","event id 4728","A member was added to a security-enabled global group","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4728"],"errorCode":"","eventId":"4728","severity":"Medium","summary":"Windows Security event 4728 records: A member was added to a security-enabled global group","rootCause":"The event records a state-changing operation: A member was added to a security-enabled global group It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4728.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A member was added to a security-enabled global group\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4728\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4728} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4728","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4728","Event ID 4728","A member was added to a security-enabled global group"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69390,"title":"Windows Security Event 4729 - A member was removed from a security-enabled global group","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4729","Windows"],"keywords":["4729","event 4729","event id 4729","A member was removed from a security-enabled global group","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4729"],"errorCode":"","eventId":"4729","severity":"Medium","summary":"Windows Security event 4729 records: A member was removed from a security-enabled global group","rootCause":"The event records a state-changing operation: A member was removed from a security-enabled global group It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4729.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A member was removed from a security-enabled global group\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4729\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4729} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4729","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4729","Event ID 4729","A member was removed from a security-enabled global group"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69391,"title":"Windows Security Event 4730 - A security-enabled global group was deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4730","Windows"],"keywords":["4730","event 4730","event id 4730","A security-enabled global group was deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4730"],"errorCode":"","eventId":"4730","severity":"High","summary":"Windows Security event 4730 records: A security-enabled global group was deleted","rootCause":"The event records a state-changing operation: A security-enabled global group was deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4730.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A security-enabled global group was deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4730\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4730} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4730","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4730","Event ID 4730","A security-enabled global group was deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69392,"title":"Windows Security Event 4731 - A security-enabled local group was created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4731","Windows"],"keywords":["4731","event 4731","event id 4731","A security-enabled local group was created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4731"],"errorCode":"","eventId":"4731","severity":"Medium","summary":"Windows Security event 4731 records: A security-enabled local group was created","rootCause":"The event records a state-changing operation: A security-enabled local group was created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4731.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A security-enabled local group was created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4731\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4731} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4731","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4731","Event ID 4731","A security-enabled local group was created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69393,"title":"Windows Security Event 4732 - A member was added to a security-enabled local group","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4732","Windows"],"keywords":["4732","event 4732","event id 4732","A member was added to a security-enabled local group","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4732"],"errorCode":"","eventId":"4732","severity":"Medium","summary":"Windows Security event 4732 records: A member was added to a security-enabled local group","rootCause":"The event records a state-changing operation: A member was added to a security-enabled local group It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4732.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A member was added to a security-enabled local group\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4732\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4732} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4732","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4732","Event ID 4732","A member was added to a security-enabled local group"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69394,"title":"Windows Security Event 4733 - A member was removed from a security-enabled local group","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4733","Windows"],"keywords":["4733","event 4733","event id 4733","A member was removed from a security-enabled local group","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4733"],"errorCode":"","eventId":"4733","severity":"Medium","summary":"Windows Security event 4733 records: A member was removed from a security-enabled local group","rootCause":"The event records a state-changing operation: A member was removed from a security-enabled local group It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4733.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A member was removed from a security-enabled local group\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4733\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4733} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4733","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4733","Event ID 4733","A member was removed from a security-enabled local group"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69395,"title":"Windows Security Event 4734 - A security-enabled local group was deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4734","Windows"],"keywords":["4734","event 4734","event id 4734","A security-enabled local group was deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4734"],"errorCode":"","eventId":"4734","severity":"High","summary":"Windows Security event 4734 records: A security-enabled local group was deleted","rootCause":"The event records a state-changing operation: A security-enabled local group was deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4734.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A security-enabled local group was deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4734\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4734} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4734","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4734","Event ID 4734","A security-enabled local group was deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69396,"title":"Windows Security Event 4735 - A security-enabled local group was changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4735","Windows"],"keywords":["4735","event 4735","event id 4735","A security-enabled local group was changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4735"],"errorCode":"","eventId":"4735","severity":"Medium","summary":"Windows Security event 4735 records: A security-enabled local group was changed","rootCause":"The event records a state-changing operation: A security-enabled local group was changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4735.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A security-enabled local group was changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4735\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4735} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4735","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4735","Event ID 4735","A security-enabled local group was changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69397,"title":"Windows Security Event 4737 - A security-enabled global group was changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4737","Windows"],"keywords":["4737","event 4737","event id 4737","A security-enabled global group was changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4737"],"errorCode":"","eventId":"4737","severity":"Medium","summary":"Windows Security event 4737 records: A security-enabled global group was changed","rootCause":"The event records a state-changing operation: A security-enabled global group was changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4737.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A security-enabled global group was changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4737\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4737} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4737","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4737","Event ID 4737","A security-enabled global group was changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69398,"title":"Windows Security Event 4738 - A user account was changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4738","Windows"],"keywords":["4738","event 4738","event id 4738","A user account was changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4738"],"errorCode":"","eventId":"4738","severity":"Medium","summary":"Windows Security event 4738 records: A user account was changed","rootCause":"The event records a state-changing operation: A user account was changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4738.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A user account was changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4738\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4738} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4738","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4738","Event ID 4738","A user account was changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69399,"title":"Windows Security Event 4739 - Domain Policy was changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4739","Windows"],"keywords":["4739","event 4739","event id 4739","Domain Policy was changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4739"],"errorCode":"","eventId":"4739","severity":"Medium","summary":"Windows Security event 4739 records: Domain Policy was changed","rootCause":"The event records a state-changing operation: Domain Policy was changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4739.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Domain Policy was changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4739\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4739} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4739","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4739","Event ID 4739","Domain Policy was changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69400,"title":"Windows Security Event 4740 - A user account was locked out","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4740","Windows"],"keywords":["4740","event 4740","event id 4740","A user account was locked out","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4740"],"errorCode":"","eventId":"4740","severity":"Critical","summary":"Windows Security event 4740 records: A user account was locked out","rootCause":"The configured audit source recorded this activity: A user account was locked out It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4740.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A user account was locked out\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4740\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4740} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4740","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4740","Event ID 4740","A user account was locked out"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69401,"title":"Windows Security Event 4741 - A computer account was created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4741","Windows"],"keywords":["4741","event 4741","event id 4741","A computer account was created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4741"],"errorCode":"","eventId":"4741","severity":"Medium","summary":"Windows Security event 4741 records: A computer account was created","rootCause":"The event records a state-changing operation: A computer account was created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4741.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A computer account was created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4741\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4741} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4741","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4741","Event ID 4741","A computer account was created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69402,"title":"Windows Security Event 4742 - A computer account was changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4742","Windows"],"keywords":["4742","event 4742","event id 4742","A computer account was changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4742"],"errorCode":"","eventId":"4742","severity":"Medium","summary":"Windows Security event 4742 records: A computer account was changed","rootCause":"The event records a state-changing operation: A computer account was changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4742.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A computer account was changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4742\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4742} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4742","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4742","Event ID 4742","A computer account was changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69403,"title":"Windows Security Event 4743 - A computer account was deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4743","Windows"],"keywords":["4743","event 4743","event id 4743","A computer account was deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4743"],"errorCode":"","eventId":"4743","severity":"High","summary":"Windows Security event 4743 records: A computer account was deleted","rootCause":"The event records a state-changing operation: A computer account was deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4743.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A computer account was deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4743\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4743} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4743","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4743","Event ID 4743","A computer account was deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69404,"title":"Windows Security Event 4744 - A security-disabled local group was created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4744","Windows"],"keywords":["4744","event 4744","event id 4744","A security-disabled local group was created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4744"],"errorCode":"","eventId":"4744","severity":"High","summary":"Windows Security event 4744 records: A security-disabled local group was created","rootCause":"The event records a state-changing operation: A security-disabled local group was created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4744.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A security-disabled local group was created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4744\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4744} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4744","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4744","Event ID 4744","A security-disabled local group was created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69405,"title":"Windows Security Event 4745 - A security-disabled local group was changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4745","Windows"],"keywords":["4745","event 4745","event id 4745","A security-disabled local group was changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4745"],"errorCode":"","eventId":"4745","severity":"High","summary":"Windows Security event 4745 records: A security-disabled local group was changed","rootCause":"The event records a state-changing operation: A security-disabled local group was changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4745.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A security-disabled local group was changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4745\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4745} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4745","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4745","Event ID 4745","A security-disabled local group was changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69406,"title":"Windows Security Event 4746 - A member was added to a security-disabled local group","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4746","Windows"],"keywords":["4746","event 4746","event id 4746","A member was added to a security-disabled local group","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4746"],"errorCode":"","eventId":"4746","severity":"High","summary":"Windows Security event 4746 records: A member was added to a security-disabled local group","rootCause":"The event records a state-changing operation: A member was added to a security-disabled local group It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4746.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A member was added to a security-disabled local group\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4746\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4746} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4746","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4746","Event ID 4746","A member was added to a security-disabled local group"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69407,"title":"Windows Security Event 4747 - A member was removed from a security-disabled local group","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4747","Windows"],"keywords":["4747","event 4747","event id 4747","A member was removed from a security-disabled local group","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4747"],"errorCode":"","eventId":"4747","severity":"High","summary":"Windows Security event 4747 records: A member was removed from a security-disabled local group","rootCause":"The event records a state-changing operation: A member was removed from a security-disabled local group It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4747.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A member was removed from a security-disabled local group\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4747\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4747} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4747","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4747","Event ID 4747","A member was removed from a security-disabled local group"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69408,"title":"Windows Security Event 4748 - A security-disabled local group was deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4748","Windows"],"keywords":["4748","event 4748","event id 4748","A security-disabled local group was deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4748"],"errorCode":"","eventId":"4748","severity":"High","summary":"Windows Security event 4748 records: A security-disabled local group was deleted","rootCause":"The event records a state-changing operation: A security-disabled local group was deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4748.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A security-disabled local group was deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4748\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4748} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4748","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4748","Event ID 4748","A security-disabled local group was deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69409,"title":"Windows Security Event 4749 - A security-disabled global group was created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4749","Windows"],"keywords":["4749","event 4749","event id 4749","A security-disabled global group was created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4749"],"errorCode":"","eventId":"4749","severity":"High","summary":"Windows Security event 4749 records: A security-disabled global group was created","rootCause":"The event records a state-changing operation: A security-disabled global group was created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4749.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A security-disabled global group was created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4749\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4749} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4749","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4749","Event ID 4749","A security-disabled global group was created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69410,"title":"Windows Security Event 4750 - A security-disabled global group was changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4750","Windows"],"keywords":["4750","event 4750","event id 4750","A security-disabled global group was changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4750"],"errorCode":"","eventId":"4750","severity":"High","summary":"Windows Security event 4750 records: A security-disabled global group was changed","rootCause":"The event records a state-changing operation: A security-disabled global group was changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4750.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A security-disabled global group was changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4750\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4750} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4750","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4750","Event ID 4750","A security-disabled global group was changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69411,"title":"Windows Security Event 4751 - A member was added to a security-disabled global group","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4751","Windows"],"keywords":["4751","event 4751","event id 4751","A member was added to a security-disabled global group","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4751"],"errorCode":"","eventId":"4751","severity":"High","summary":"Windows Security event 4751 records: A member was added to a security-disabled global group","rootCause":"The event records a state-changing operation: A member was added to a security-disabled global group It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4751.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A member was added to a security-disabled global group\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4751\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4751} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4751","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4751","Event ID 4751","A member was added to a security-disabled global group"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69412,"title":"Windows Security Event 4752 - A member was removed from a security-disabled global group","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4752","Windows"],"keywords":["4752","event 4752","event id 4752","A member was removed from a security-disabled global group","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4752"],"errorCode":"","eventId":"4752","severity":"High","summary":"Windows Security event 4752 records: A member was removed from a security-disabled global group","rootCause":"The event records a state-changing operation: A member was removed from a security-disabled global group It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4752.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A member was removed from a security-disabled global group\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4752\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4752} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4752","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4752","Event ID 4752","A member was removed from a security-disabled global group"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69413,"title":"Windows Security Event 4753 - A security-disabled global group was deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4753","Windows"],"keywords":["4753","event 4753","event id 4753","A security-disabled global group was deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4753"],"errorCode":"","eventId":"4753","severity":"High","summary":"Windows Security event 4753 records: A security-disabled global group was deleted","rootCause":"The event records a state-changing operation: A security-disabled global group was deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4753.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A security-disabled global group was deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4753\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4753} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4753","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4753","Event ID 4753","A security-disabled global group was deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69414,"title":"Windows Security Event 4754 - A security-enabled universal group was created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4754","Windows"],"keywords":["4754","event 4754","event id 4754","A security-enabled universal group was created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4754"],"errorCode":"","eventId":"4754","severity":"Medium","summary":"Windows Security event 4754 records: A security-enabled universal group was created","rootCause":"The event records a state-changing operation: A security-enabled universal group was created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4754.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A security-enabled universal group was created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4754\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4754} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4754","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4754","Event ID 4754","A security-enabled universal group was created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69415,"title":"Windows Security Event 4755 - A security-enabled universal group was changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4755","Windows"],"keywords":["4755","event 4755","event id 4755","A security-enabled universal group was changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4755"],"errorCode":"","eventId":"4755","severity":"Medium","summary":"Windows Security event 4755 records: A security-enabled universal group was changed","rootCause":"The event records a state-changing operation: A security-enabled universal group was changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4755.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A security-enabled universal group was changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4755\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4755} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4755","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4755","Event ID 4755","A security-enabled universal group was changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69416,"title":"Windows Security Event 4756 - A member was added to a security-enabled universal group","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4756","Windows"],"keywords":["4756","event 4756","event id 4756","A member was added to a security-enabled universal group","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4756"],"errorCode":"","eventId":"4756","severity":"Medium","summary":"Windows Security event 4756 records: A member was added to a security-enabled universal group","rootCause":"The event records a state-changing operation: A member was added to a security-enabled universal group It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4756.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A member was added to a security-enabled universal group\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4756\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4756} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4756","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4756","Event ID 4756","A member was added to a security-enabled universal group"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69417,"title":"Windows Security Event 4757 - A member was removed from a security-enabled universal group","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4757","Windows"],"keywords":["4757","event 4757","event id 4757","A member was removed from a security-enabled universal group","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4757"],"errorCode":"","eventId":"4757","severity":"Medium","summary":"Windows Security event 4757 records: A member was removed from a security-enabled universal group","rootCause":"The event records a state-changing operation: A member was removed from a security-enabled universal group It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4757.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A member was removed from a security-enabled universal group\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4757\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4757} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4757","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4757","Event ID 4757","A member was removed from a security-enabled universal group"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69418,"title":"Windows Security Event 4758 - A security-enabled universal group was deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4758","Windows"],"keywords":["4758","event 4758","event id 4758","A security-enabled universal group was deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4758"],"errorCode":"","eventId":"4758","severity":"High","summary":"Windows Security event 4758 records: A security-enabled universal group was deleted","rootCause":"The event records a state-changing operation: A security-enabled universal group was deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4758.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A security-enabled universal group was deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4758\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4758} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4758","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4758","Event ID 4758","A security-enabled universal group was deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69419,"title":"Windows Security Event 4759 - A security-disabled universal group was created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4759","Windows"],"keywords":["4759","event 4759","event id 4759","A security-disabled universal group was created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4759"],"errorCode":"","eventId":"4759","severity":"High","summary":"Windows Security event 4759 records: A security-disabled universal group was created","rootCause":"The event records a state-changing operation: A security-disabled universal group was created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4759.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A security-disabled universal group was created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4759\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4759} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4759","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4759","Event ID 4759","A security-disabled universal group was created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69420,"title":"Windows Security Event 4760 - A security-disabled universal group was changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4760","Windows"],"keywords":["4760","event 4760","event id 4760","A security-disabled universal group was changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4760"],"errorCode":"","eventId":"4760","severity":"High","summary":"Windows Security event 4760 records: A security-disabled universal group was changed","rootCause":"The event records a state-changing operation: A security-disabled universal group was changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4760.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A security-disabled universal group was changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4760\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4760} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4760","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4760","Event ID 4760","A security-disabled universal group was changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69421,"title":"Windows Security Event 4761 - A member was added to a security-disabled universal group","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4761","Windows"],"keywords":["4761","event 4761","event id 4761","A member was added to a security-disabled universal group","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4761"],"errorCode":"","eventId":"4761","severity":"High","summary":"Windows Security event 4761 records: A member was added to a security-disabled universal group","rootCause":"The event records a state-changing operation: A member was added to a security-disabled universal group It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4761.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A member was added to a security-disabled universal group\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4761\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4761} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4761","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4761","Event ID 4761","A member was added to a security-disabled universal group"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69422,"title":"Windows Security Event 4762 - A member was removed from a security-disabled universal group","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4762","Windows"],"keywords":["4762","event 4762","event id 4762","A member was removed from a security-disabled universal group","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4762"],"errorCode":"","eventId":"4762","severity":"High","summary":"Windows Security event 4762 records: A member was removed from a security-disabled universal group","rootCause":"The event records a state-changing operation: A member was removed from a security-disabled universal group It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4762.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A member was removed from a security-disabled universal group\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4762\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4762} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4762","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4762","Event ID 4762","A member was removed from a security-disabled universal group"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69423,"title":"Windows Security Event 4763 - A security-disabled universal group was deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4763","Windows"],"keywords":["4763","event 4763","event id 4763","A security-disabled universal group was deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4763"],"errorCode":"","eventId":"4763","severity":"High","summary":"Windows Security event 4763 records: A security-disabled universal group was deleted","rootCause":"The event records a state-changing operation: A security-disabled universal group was deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4763.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A security-disabled universal group was deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4763\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4763} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4763","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4763","Event ID 4763","A security-disabled universal group was deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69424,"title":"Windows Security Event 4764 - A groups type was changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4764","Windows"],"keywords":["4764","event 4764","event id 4764","A groups type was changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4764"],"errorCode":"","eventId":"4764","severity":"Medium","summary":"Windows Security event 4764 records: A groups type was changed","rootCause":"The event records a state-changing operation: A groups type was changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4764.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A groups type was changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4764\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4764} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4764","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4764","Event ID 4764","A groups type was changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69425,"title":"Windows Security Event 4765 - SID History was added to an account","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4765","Windows"],"keywords":["4765","event 4765","event id 4765","SID History was added to an account","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4765"],"errorCode":"","eventId":"4765","severity":"Medium","summary":"Windows Security event 4765 records: SID History was added to an account","rootCause":"The event records a state-changing operation: SID History was added to an account It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4765.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: SID History was added to an account\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4765\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4765} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4765","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4765","Event ID 4765","SID History was added to an account"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69426,"title":"Windows Security Event 4766 - An attempt to add SID History to an account failed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4766","Windows"],"keywords":["4766","event 4766","event id 4766","An attempt to add SID History to an account failed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4766"],"errorCode":"","eventId":"4766","severity":"High","summary":"Windows Security event 4766 records: An attempt to add SID History to an account failed","rootCause":"The audited operation reported a failure: An attempt to add SID History to an account failed The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4766.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An attempt to add SID History to an account failed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4766\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4766} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4766","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4766","Event ID 4766","An attempt to add SID History to an account failed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69427,"title":"Windows Security Event 4767 - A user account was unlocked","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4767","Windows"],"keywords":["4767","event 4767","event id 4767","A user account was unlocked","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4767"],"errorCode":"","eventId":"4767","severity":"Low","summary":"Windows Security event 4767 records: A user account was unlocked","rootCause":"The configured audit source recorded this activity: A user account was unlocked It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4767.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A user account was unlocked\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4767\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4767} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4767","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4767","Event ID 4767","A user account was unlocked"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69428,"title":"Windows Security Event 4768 - A Kerberos authentication ticket (TGT) was requested","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4768","Windows"],"keywords":["4768","event 4768","event id 4768","A Kerberos authentication ticket (TGT) was requested","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4768"],"errorCode":"","eventId":"4768","severity":"Low","summary":"Windows Security event 4768 records: A Kerberos authentication ticket (TGT) was requested","rootCause":"The configured audit source recorded this activity: A Kerberos authentication ticket (TGT) was requested It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4768.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A Kerberos authentication ticket (TGT) was requested\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4768\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4768} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4768","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4768","Event ID 4768","A Kerberos authentication ticket (TGT) was requested"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69429,"title":"Windows Security Event 4769 - A Kerberos service ticket was requested","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4769","Windows"],"keywords":["4769","event 4769","event id 4769","A Kerberos service ticket was requested","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4769"],"errorCode":"","eventId":"4769","severity":"Low","summary":"Windows Security event 4769 records: A Kerberos service ticket was requested","rootCause":"The configured audit source recorded this activity: A Kerberos service ticket was requested It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4769.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A Kerberos service ticket was requested\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4769\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4769} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4769","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4769","Event ID 4769","A Kerberos service ticket was requested"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69430,"title":"Windows Security Event 4770 - A Kerberos service ticket was renewed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4770","Windows"],"keywords":["4770","event 4770","event id 4770","A Kerberos service ticket was renewed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4770"],"errorCode":"","eventId":"4770","severity":"Low","summary":"Windows Security event 4770 records: A Kerberos service ticket was renewed","rootCause":"The configured audit source recorded this activity: A Kerberos service ticket was renewed It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4770.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A Kerberos service ticket was renewed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4770\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4770} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4770","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4770","Event ID 4770","A Kerberos service ticket was renewed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69431,"title":"Windows Security Event 4771 - Kerberos pre-authentication failed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4771","Windows"],"keywords":["4771","event 4771","event id 4771","Kerberos pre-authentication failed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4771"],"errorCode":"","eventId":"4771","severity":"High","summary":"Windows Security event 4771 records: Kerberos pre-authentication failed","rootCause":"The audited operation reported a failure: Kerberos pre-authentication failed The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4771.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Kerberos pre-authentication failed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4771\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4771} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4771","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4771","Event ID 4771","Kerberos pre-authentication failed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69432,"title":"Windows Security Event 4772 - A Kerberos authentication ticket request failed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4772","Windows"],"keywords":["4772","event 4772","event id 4772","A Kerberos authentication ticket request failed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4772"],"errorCode":"","eventId":"4772","severity":"High","summary":"Windows Security event 4772 records: A Kerberos authentication ticket request failed","rootCause":"The audited operation reported a failure: A Kerberos authentication ticket request failed The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4772.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A Kerberos authentication ticket request failed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4772\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4772} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4772","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4772","Event ID 4772","A Kerberos authentication ticket request failed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69433,"title":"Windows Security Event 4773 - A Kerberos service ticket request failed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4773","Windows"],"keywords":["4773","event 4773","event id 4773","A Kerberos service ticket request failed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4773"],"errorCode":"","eventId":"4773","severity":"High","summary":"Windows Security event 4773 records: A Kerberos service ticket request failed","rootCause":"The audited operation reported a failure: A Kerberos service ticket request failed The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4773.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A Kerberos service ticket request failed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4773\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4773} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4773","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4773","Event ID 4773","A Kerberos service ticket request failed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69434,"title":"Windows Security Event 4774 - An account was mapped for logon","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4774","Windows"],"keywords":["4774","event 4774","event id 4774","An account was mapped for logon","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4774"],"errorCode":"","eventId":"4774","severity":"Low","summary":"Windows Security event 4774 records: An account was mapped for logon","rootCause":"The configured audit source recorded this activity: An account was mapped for logon It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4774.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An account was mapped for logon\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4774\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4774} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4774","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4774","Event ID 4774","An account was mapped for logon"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69435,"title":"Windows Security Event 4775 - An account could not be mapped for logon","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4775","Windows"],"keywords":["4775","event 4775","event id 4775","An account could not be mapped for logon","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4775"],"errorCode":"","eventId":"4775","severity":"High","summary":"Windows Security event 4775 records: An account could not be mapped for logon","rootCause":"The audited operation reported a failure: An account could not be mapped for logon The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4775.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An account could not be mapped for logon\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4775\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4775} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4775","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4775","Event ID 4775","An account could not be mapped for logon"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69436,"title":"Windows Security Event 4776 - The domain controller attempted to validate the credentials for an account","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4776","Windows"],"keywords":["4776","event 4776","event id 4776","The domain controller attempted to validate the credentials for an account","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4776"],"errorCode":"","eventId":"4776","severity":"Low","summary":"Windows Security event 4776 records: The domain controller attempted to validate the credentials for an account","rootCause":"The configured audit source recorded this activity: The domain controller attempted to validate the credentials for an account It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4776.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The domain controller attempted to validate the credentials for an account\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4776\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4776} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4776","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4776","Event ID 4776","The domain controller attempted to validate the credentials for an account"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69437,"title":"Windows Security Event 4777 - The domain controller failed to validate the credentials for an account","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4777","Windows"],"keywords":["4777","event 4777","event id 4777","The domain controller failed to validate the credentials for an account","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4777"],"errorCode":"","eventId":"4777","severity":"High","summary":"Windows Security event 4777 records: The domain controller failed to validate the credentials for an account","rootCause":"The audited operation reported a failure: The domain controller failed to validate the credentials for an account The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4777.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The domain controller failed to validate the credentials for an account\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4777\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4777} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4777","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4777","Event ID 4777","The domain controller failed to validate the credentials for an account"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69438,"title":"Windows Security Event 4778 - A session was reconnected to a Window Station","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4778","Windows"],"keywords":["4778","event 4778","event id 4778","A session was reconnected to a Window Station","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4778"],"errorCode":"","eventId":"4778","severity":"Low","summary":"Windows Security event 4778 records: A session was reconnected to a Window Station","rootCause":"The configured audit source recorded this activity: A session was reconnected to a Window Station It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4778.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A session was reconnected to a Window Station\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4778\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4778} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4778","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4778","Event ID 4778","A session was reconnected to a Window Station"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69439,"title":"Windows Security Event 4779 - A session was disconnected from a Window Station","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4779","Windows"],"keywords":["4779","event 4779","event id 4779","A session was disconnected from a Window Station","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4779"],"errorCode":"","eventId":"4779","severity":"Low","summary":"Windows Security event 4779 records: A session was disconnected from a Window Station","rootCause":"The configured audit source recorded this activity: A session was disconnected from a Window Station It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4779.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A session was disconnected from a Window Station\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4779\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4779} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4779","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4779","Event ID 4779","A session was disconnected from a Window Station"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69440,"title":"Windows Security Event 4780 - The ACL was set on accounts which are members of administrators groups","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4780","Windows"],"keywords":["4780","event 4780","event id 4780","The ACL was set on accounts which are members of administrators groups","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4780"],"errorCode":"","eventId":"4780","severity":"Medium","summary":"Windows Security event 4780 records: The ACL was set on accounts which are members of administrators groups","rootCause":"The configured audit source recorded this activity: The ACL was set on accounts which are members of administrators groups It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4780.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The ACL was set on accounts which are members of administrators groups\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4780\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4780} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4780","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4780","Event ID 4780","The ACL was set on accounts which are members of administrators groups"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69441,"title":"Windows Security Event 4781 - The name of an account was changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4781","Windows"],"keywords":["4781","event 4781","event id 4781","The name of an account was changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4781"],"errorCode":"","eventId":"4781","severity":"Medium","summary":"Windows Security event 4781 records: The name of an account was changed","rootCause":"The event records a state-changing operation: The name of an account was changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4781.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The name of an account was changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4781\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4781} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4781","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4781","Event ID 4781","The name of an account was changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69442,"title":"Windows Security Event 4782 - The password hash an account was accessed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4782","Windows"],"keywords":["4782","event 4782","event id 4782","The password hash an account was accessed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4782"],"errorCode":"","eventId":"4782","severity":"Medium","summary":"Windows Security event 4782 records: The password hash an account was accessed","rootCause":"The configured audit source recorded this activity: The password hash an account was accessed It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4782.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The password hash an account was accessed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4782\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4782} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4782","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4782","Event ID 4782","The password hash an account was accessed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69443,"title":"Windows Security Event 4783 - A basic application group was created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4783","Windows"],"keywords":["4783","event 4783","event id 4783","A basic application group was created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4783"],"errorCode":"","eventId":"4783","severity":"Medium","summary":"Windows Security event 4783 records: A basic application group was created","rootCause":"The event records a state-changing operation: A basic application group was created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4783.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A basic application group was created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4783\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4783} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4783","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4783","Event ID 4783","A basic application group was created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69444,"title":"Windows Security Event 4784 - A basic application group was changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4784","Windows"],"keywords":["4784","event 4784","event id 4784","A basic application group was changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4784"],"errorCode":"","eventId":"4784","severity":"Medium","summary":"Windows Security event 4784 records: A basic application group was changed","rootCause":"The event records a state-changing operation: A basic application group was changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4784.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A basic application group was changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4784\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4784} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4784","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4784","Event ID 4784","A basic application group was changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69445,"title":"Windows Security Event 4785 - A member was added to a basic application group","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4785","Windows"],"keywords":["4785","event 4785","event id 4785","A member was added to a basic application group","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4785"],"errorCode":"","eventId":"4785","severity":"Medium","summary":"Windows Security event 4785 records: A member was added to a basic application group","rootCause":"The event records a state-changing operation: A member was added to a basic application group It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4785.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A member was added to a basic application group\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4785\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4785} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4785","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4785","Event ID 4785","A member was added to a basic application group"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69446,"title":"Windows Security Event 4786 - A member was removed from a basic application group","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4786","Windows"],"keywords":["4786","event 4786","event id 4786","A member was removed from a basic application group","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4786"],"errorCode":"","eventId":"4786","severity":"Medium","summary":"Windows Security event 4786 records: A member was removed from a basic application group","rootCause":"The event records a state-changing operation: A member was removed from a basic application group It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4786.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A member was removed from a basic application group\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4786\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4786} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4786","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4786","Event ID 4786","A member was removed from a basic application group"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69447,"title":"Windows Security Event 4787 - A non-member was added to a basic application group","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4787","Windows"],"keywords":["4787","event 4787","event id 4787","A non-member was added to a basic application group","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4787"],"errorCode":"","eventId":"4787","severity":"Medium","summary":"Windows Security event 4787 records: A non-member was added to a basic application group","rootCause":"The event records a state-changing operation: A non-member was added to a basic application group It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4787.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A non-member was added to a basic application group\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4787\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4787} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4787","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4787","Event ID 4787","A non-member was added to a basic application group"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69448,"title":"Windows Security Event 4788 - A non-member was removed from a basic application group..","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4788","Windows"],"keywords":["4788","event 4788","event id 4788","A non-member was removed from a basic application group..","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4788"],"errorCode":"","eventId":"4788","severity":"Medium","summary":"Windows Security event 4788 records: A non-member was removed from a basic application group..","rootCause":"The event records a state-changing operation: A non-member was removed from a basic application group.. It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4788.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A non-member was removed from a basic application group..\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4788\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4788} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4788","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4788","Event ID 4788","A non-member was removed from a basic application group.."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69449,"title":"Windows Security Event 4789 - A basic application group was deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4789","Windows"],"keywords":["4789","event 4789","event id 4789","A basic application group was deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4789"],"errorCode":"","eventId":"4789","severity":"High","summary":"Windows Security event 4789 records: A basic application group was deleted","rootCause":"The event records a state-changing operation: A basic application group was deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4789.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A basic application group was deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4789\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4789} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4789","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4789","Event ID 4789","A basic application group was deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69450,"title":"Windows Security Event 4790 - An LDAP query group was created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4790","Windows"],"keywords":["4790","event 4790","event id 4790","An LDAP query group was created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4790"],"errorCode":"","eventId":"4790","severity":"Medium","summary":"Windows Security event 4790 records: An LDAP query group was created","rootCause":"The event records a state-changing operation: An LDAP query group was created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4790.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An LDAP query group was created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4790\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4790} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4790","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4790","Event ID 4790","An LDAP query group was created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69451,"title":"Windows Security Event 4791 - A basic application group was changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4791","Windows"],"keywords":["4791","event 4791","event id 4791","A basic application group was changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4791"],"errorCode":"","eventId":"4791","severity":"Medium","summary":"Windows Security event 4791 records: A basic application group was changed","rootCause":"The event records a state-changing operation: A basic application group was changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4791.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A basic application group was changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4791\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4791} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4791","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4791","Event ID 4791","A basic application group was changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69452,"title":"Windows Security Event 4792 - An LDAP query group was deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4792","Windows"],"keywords":["4792","event 4792","event id 4792","An LDAP query group was deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4792"],"errorCode":"","eventId":"4792","severity":"High","summary":"Windows Security event 4792 records: An LDAP query group was deleted","rootCause":"The event records a state-changing operation: An LDAP query group was deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4792.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An LDAP query group was deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4792\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4792} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4792","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4792","Event ID 4792","An LDAP query group was deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69453,"title":"Windows Security Event 4793 - The Password Policy Checking API was called","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4793","Windows"],"keywords":["4793","event 4793","event id 4793","The Password Policy Checking API was called","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4793"],"errorCode":"","eventId":"4793","severity":"Medium","summary":"Windows Security event 4793 records: The Password Policy Checking API was called","rootCause":"The configured audit source recorded this activity: The Password Policy Checking API was called It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4793.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Password Policy Checking API was called\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4793\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4793} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4793","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4793","Event ID 4793","The Password Policy Checking API was called"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69454,"title":"Windows Security Event 4794 - An attempt was made to set the Directory Services Restore Mode administrator password","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4794","Windows"],"keywords":["4794","event 4794","event id 4794","An attempt was made to set the Directory Services Restore Mode administrator password","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4794"],"errorCode":"","eventId":"4794","severity":"Medium","summary":"Windows Security event 4794 records: An attempt was made to set the Directory Services Restore Mode administrator password","rootCause":"The configured audit source recorded this activity: An attempt was made to set the Directory Services Restore Mode administrator password It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4794.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An attempt was made to set the Directory Services Restore Mode administrator password\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4794\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4794} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4794","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4794","Event ID 4794","An attempt was made to set the Directory Services Restore Mode administrator password"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69455,"title":"Windows Security Event 4797 - An attempt was made to query the existence of a blank password for an account","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4797","Windows"],"keywords":["4797","event 4797","event id 4797","An attempt was made to query the existence of a blank password for an account","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4797"],"errorCode":"","eventId":"4797","severity":"Medium","summary":"Windows Security event 4797 records: An attempt was made to query the existence of a blank password for an account","rootCause":"The configured audit source recorded this activity: An attempt was made to query the existence of a blank password for an account It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4797.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An attempt was made to query the existence of a blank password for an account\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4797\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4797} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4797","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4797","Event ID 4797","An attempt was made to query the existence of a blank password for an account"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69456,"title":"Windows Security Event 4798 - A user's local group membership was enumerated.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4798","Windows"],"keywords":["4798","event 4798","event id 4798","A user's local group membership was enumerated.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4798"],"errorCode":"","eventId":"4798","severity":"Medium","summary":"Windows Security event 4798 records: A user's local group membership was enumerated.","rootCause":"The configured audit source recorded this activity: A user's local group membership was enumerated. It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4798.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A user's local group membership was enumerated.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4798\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4798} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4798","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4798","Event ID 4798","A user's local group membership was enumerated."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69457,"title":"Windows Security Event 4799 - A security-enabled local group membership was enumerated","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4799","Windows"],"keywords":["4799","event 4799","event id 4799","A security-enabled local group membership was enumerated","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4799"],"errorCode":"","eventId":"4799","severity":"Medium","summary":"Windows Security event 4799 records: A security-enabled local group membership was enumerated","rootCause":"The event records a state-changing operation: A security-enabled local group membership was enumerated It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4799.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A security-enabled local group membership was enumerated\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4799\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4799} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4799","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4799","Event ID 4799","A security-enabled local group membership was enumerated"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69458,"title":"Windows Security Event 4800 - The workstation was locked","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4800","Windows"],"keywords":["4800","event 4800","event id 4800","The workstation was locked","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4800"],"errorCode":"","eventId":"4800","severity":"Low","summary":"Windows Security event 4800 records: The workstation was locked","rootCause":"The configured audit source recorded this activity: The workstation was locked It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4800.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The workstation was locked\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4800\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4800} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4800","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4800","Event ID 4800","The workstation was locked"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69459,"title":"Windows Security Event 4801 - The workstation was unlocked","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4801","Windows"],"keywords":["4801","event 4801","event id 4801","The workstation was unlocked","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4801"],"errorCode":"","eventId":"4801","severity":"Low","summary":"Windows Security event 4801 records: The workstation was unlocked","rootCause":"The configured audit source recorded this activity: The workstation was unlocked It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4801.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The workstation was unlocked\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4801\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4801} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4801","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4801","Event ID 4801","The workstation was unlocked"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69460,"title":"Windows Security Event 4802 - The screen saver was invoked","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4802","Windows"],"keywords":["4802","event 4802","event id 4802","The screen saver was invoked","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4802"],"errorCode":"","eventId":"4802","severity":"Low","summary":"Windows Security event 4802 records: The screen saver was invoked","rootCause":"The configured audit source recorded this activity: The screen saver was invoked It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4802.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The screen saver was invoked\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4802\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4802} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4802","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4802","Event ID 4802","The screen saver was invoked"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69461,"title":"Windows Security Event 4803 - The screen saver was dismissed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4803","Windows"],"keywords":["4803","event 4803","event id 4803","The screen saver was dismissed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4803"],"errorCode":"","eventId":"4803","severity":"Low","summary":"Windows Security event 4803 records: The screen saver was dismissed","rootCause":"The configured audit source recorded this activity: The screen saver was dismissed It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4803.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The screen saver was dismissed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4803\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4803} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4803","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4803","Event ID 4803","The screen saver was dismissed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69462,"title":"Windows Security Event 4816 - RPC detected an integrity violation while decrypting an incoming message","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4816","Windows"],"keywords":["4816","event 4816","event id 4816","RPC detected an integrity violation while decrypting an incoming message","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4816"],"errorCode":"","eventId":"4816","severity":"High","summary":"Windows Security event 4816 records: RPC detected an integrity violation while decrypting an incoming message","rootCause":"The audited operation reported a failure: RPC detected an integrity violation while decrypting an incoming message The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4816.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: RPC detected an integrity violation while decrypting an incoming message\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4816\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4816} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4816","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4816","Event ID 4816","RPC detected an integrity violation while decrypting an incoming message"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69463,"title":"Windows Security Event 4817 - Auditing settings on object were changed.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4817","Windows"],"keywords":["4817","event 4817","event id 4817","Auditing settings on object were changed.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4817"],"errorCode":"","eventId":"4817","severity":"Medium","summary":"Windows Security event 4817 records: Auditing settings on object were changed.","rootCause":"The event records a state-changing operation: Auditing settings on object were changed. It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4817.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Auditing settings on object were changed.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4817\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4817} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4817","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4817","Event ID 4817","Auditing settings on object were changed."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69464,"title":"Windows Security Event 4818 - Proposed Central Access Policy does not grant the same access permissions as the current Central Access Policy","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4818","Windows"],"keywords":["4818","event 4818","event id 4818","Proposed Central Access Policy does not grant the same access permissions as the current Central Access Policy","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4818"],"errorCode":"","eventId":"4818","severity":"Medium","summary":"Windows Security event 4818 records: Proposed Central Access Policy does not grant the same access permissions as the current Central Access Policy","rootCause":"The configured audit source recorded this activity: Proposed Central Access Policy does not grant the same access permissions as the current Central Access Policy It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4818.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Proposed Central Access Policy does not grant the same access permissions as the current Central Access Policy\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4818\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4818} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4818","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4818","Event ID 4818","Proposed Central Access Policy does not grant the same access permissions as the current Central Access Policy"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69465,"title":"Windows Security Event 4819 - Central Access Policies on the machine have been changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4819","Windows"],"keywords":["4819","event 4819","event id 4819","Central Access Policies on the machine have been changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4819"],"errorCode":"","eventId":"4819","severity":"Medium","summary":"Windows Security event 4819 records: Central Access Policies on the machine have been changed","rootCause":"The event records a state-changing operation: Central Access Policies on the machine have been changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4819.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Central Access Policies on the machine have been changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4819\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4819} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4819","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4819","Event ID 4819","Central Access Policies on the machine have been changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69466,"title":"Windows Security Event 4820 - A Kerberos Ticket-granting-ticket (TGT) was denied because the device does not meet the access control restrictions","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4820","Windows"],"keywords":["4820","event 4820","event id 4820","A Kerberos Ticket-granting-ticket (TGT) was denied because the device does not meet the access control restrictions","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4820"],"errorCode":"","eventId":"4820","severity":"High","summary":"Windows Security event 4820 records: A Kerberos Ticket-granting-ticket (TGT) was denied because the device does not meet the access control restrictions","rootCause":"The audited operation reported a failure: A Kerberos Ticket-granting-ticket (TGT) was denied because the device does not meet the access control restrictions The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4820.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A Kerberos Ticket-granting-ticket (TGT) was denied because the device does not meet the access control restrictions\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4820\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4820} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4820","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4820","Event ID 4820","A Kerberos Ticket-granting-ticket (TGT) was denied because the device does not meet the access control restrictions"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69467,"title":"Windows Security Event 4821 - A Kerberos service ticket was denied because the user, device, or both does not meet the access control restrictions","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4821","Windows"],"keywords":["4821","event 4821","event id 4821","A Kerberos service ticket was denied because the user, device, or both does not meet the access control restrictions","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4821"],"errorCode":"","eventId":"4821","severity":"High","summary":"Windows Security event 4821 records: A Kerberos service ticket was denied because the user, device, or both does not meet the access control restrictions","rootCause":"The audited operation reported a failure: A Kerberos service ticket was denied because the user, device, or both does not meet the access control restrictions The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4821.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A Kerberos service ticket was denied because the user, device, or both does not meet the access control restrictions\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4821\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4821} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4821","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4821","Event ID 4821","A Kerberos service ticket was denied because the user, device, or both does not meet the access control restrictions"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69468,"title":"Windows Security Event 4822 - NTLM authentication failed because the account was a member of the Protected User group","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4822","Windows"],"keywords":["4822","event 4822","event id 4822","NTLM authentication failed because the account was a member of the Protected User group","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4822"],"errorCode":"","eventId":"4822","severity":"High","summary":"Windows Security event 4822 records: NTLM authentication failed because the account was a member of the Protected User group","rootCause":"The audited operation reported a failure: NTLM authentication failed because the account was a member of the Protected User group The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4822.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: NTLM authentication failed because the account was a member of the Protected User group\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4822\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4822} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4822","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4822","Event ID 4822","NTLM authentication failed because the account was a member of the Protected User group"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69469,"title":"Windows Security Event 4823 - NTLM authentication failed because access control restrictions are required","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4823","Windows"],"keywords":["4823","event 4823","event id 4823","NTLM authentication failed because access control restrictions are required","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4823"],"errorCode":"","eventId":"4823","severity":"High","summary":"Windows Security event 4823 records: NTLM authentication failed because access control restrictions are required","rootCause":"The audited operation reported a failure: NTLM authentication failed because access control restrictions are required The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4823.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: NTLM authentication failed because access control restrictions are required\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4823\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4823} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4823","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4823","Event ID 4823","NTLM authentication failed because access control restrictions are required"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69470,"title":"Windows Security Event 4824 - Kerberos preauthentication by using DES or RC4 failed because the account was a member of the Protected User group","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4824","Windows"],"keywords":["4824","event 4824","event id 4824","Kerberos preauthentication by using DES or RC4 failed because the account was a member of the Protected User group","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4824"],"errorCode":"","eventId":"4824","severity":"High","summary":"Windows Security event 4824 records: Kerberos preauthentication by using DES or RC4 failed because the account was a member of the Protected User group","rootCause":"The audited operation reported a failure: Kerberos preauthentication by using DES or RC4 failed because the account was a member of the Protected User group The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4824.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Kerberos preauthentication by using DES or RC4 failed because the account was a member of the Protected User group\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4824\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4824} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4824","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4824","Event ID 4824","Kerberos preauthentication by using DES or RC4 failed because the account was a member of the Protected User group"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69471,"title":"Windows Security Event 4825 - A user was denied the access to Remote Desktop. By default, users are allowed to connect only if they are members of the Remote Desktop Users group or Administrators group","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4825","Windows"],"keywords":["4825","event 4825","event id 4825","A user was denied the access to Remote Desktop. By default, users are allowed to connect only if they are members of the Remote Desktop Users group or Administrators group","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4825"],"errorCode":"","eventId":"4825","severity":"High","summary":"Windows Security event 4825 records: A user was denied the access to Remote Desktop. By default, users are allowed to connect only if they are members of the Remote Desktop Users group or Administrators group","rootCause":"The audited operation reported a failure: A user was denied the access to Remote Desktop. By default, users are allowed to connect only if they are members of the Remote Desktop Users group or Administrators group The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4825.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A user was denied the access to Remote Desktop. By default, users are allowed to connect only if they are members of the Remote Desktop Users group or Administrators group\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4825\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4825} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4825","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4825","Event ID 4825","A user was denied the access to Remote Desktop. By default, users are allowed to connect only if they are members of the Remote Desktop Users group or Administrators group"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69472,"title":"Windows Security Event 4826 - Boot Configuration Data loaded","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4826","Windows"],"keywords":["4826","event 4826","event id 4826","Boot Configuration Data loaded","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4826"],"errorCode":"","eventId":"4826","severity":"Low","summary":"Windows Security event 4826 records: Boot Configuration Data loaded","rootCause":"The configured audit source recorded this activity: Boot Configuration Data loaded It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4826.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Boot Configuration Data loaded\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4826\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4826} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4826","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4826","Event ID 4826","Boot Configuration Data loaded"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69473,"title":"Windows Security Event 4830 - SID History was removed from an account","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4830","Windows"],"keywords":["4830","event 4830","event id 4830","SID History was removed from an account","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4830"],"errorCode":"","eventId":"4830","severity":"Medium","summary":"Windows Security event 4830 records: SID History was removed from an account","rootCause":"The event records a state-changing operation: SID History was removed from an account It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4830.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: SID History was removed from an account\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4830\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4830} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4830","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4830","Event ID 4830","SID History was removed from an account"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69474,"title":"Windows Security Event 4864 - A namespace collision was detected","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4864","Windows"],"keywords":["4864","event 4864","event id 4864","A namespace collision was detected","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4864"],"errorCode":"","eventId":"4864","severity":"Low","summary":"Windows Security event 4864 records: A namespace collision was detected","rootCause":"The configured audit source recorded this activity: A namespace collision was detected It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4864.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A namespace collision was detected\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4864\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4864} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4864","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4864","Event ID 4864","A namespace collision was detected"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69475,"title":"Windows Security Event 4865 - A trusted forest information entry was added","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4865","Windows"],"keywords":["4865","event 4865","event id 4865","A trusted forest information entry was added","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4865"],"errorCode":"","eventId":"4865","severity":"Medium","summary":"Windows Security event 4865 records: A trusted forest information entry was added","rootCause":"The event records a state-changing operation: A trusted forest information entry was added It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4865.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A trusted forest information entry was added\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4865\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4865} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4865","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4865","Event ID 4865","A trusted forest information entry was added"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69476,"title":"Windows Security Event 4866 - A trusted forest information entry was removed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4866","Windows"],"keywords":["4866","event 4866","event id 4866","A trusted forest information entry was removed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4866"],"errorCode":"","eventId":"4866","severity":"Medium","summary":"Windows Security event 4866 records: A trusted forest information entry was removed","rootCause":"The event records a state-changing operation: A trusted forest information entry was removed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4866.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A trusted forest information entry was removed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4866\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4866} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4866","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4866","Event ID 4866","A trusted forest information entry was removed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69477,"title":"Windows Security Event 4867 - A trusted forest information entry was modified","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4867","Windows"],"keywords":["4867","event 4867","event id 4867","A trusted forest information entry was modified","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4867"],"errorCode":"","eventId":"4867","severity":"Medium","summary":"Windows Security event 4867 records: A trusted forest information entry was modified","rootCause":"The event records a state-changing operation: A trusted forest information entry was modified It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4867.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A trusted forest information entry was modified\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4867\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4867} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4867","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4867","Event ID 4867","A trusted forest information entry was modified"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69478,"title":"Windows Security Event 4868 - The certificate manager denied a pending certificate request","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4868","Windows"],"keywords":["4868","event 4868","event id 4868","The certificate manager denied a pending certificate request","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4868"],"errorCode":"","eventId":"4868","severity":"High","summary":"Windows Security event 4868 records: The certificate manager denied a pending certificate request","rootCause":"The audited operation reported a failure: The certificate manager denied a pending certificate request The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4868.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The certificate manager denied a pending certificate request\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4868\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4868} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4868","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4868","Event ID 4868","The certificate manager denied a pending certificate request"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69479,"title":"Windows Security Event 4869 - Certificate Services received a resubmitted certificate request","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4869","Windows"],"keywords":["4869","event 4869","event id 4869","Certificate Services received a resubmitted certificate request","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4869"],"errorCode":"","eventId":"4869","severity":"Medium","summary":"Windows Security event 4869 records: Certificate Services received a resubmitted certificate request","rootCause":"The configured audit source recorded this activity: Certificate Services received a resubmitted certificate request It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4869.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Certificate Services received a resubmitted certificate request\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4869\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4869} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4869","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4869","Event ID 4869","Certificate Services received a resubmitted certificate request"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69480,"title":"Windows Security Event 4870 - Certificate Services revoked a certificate","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4870","Windows"],"keywords":["4870","event 4870","event id 4870","Certificate Services revoked a certificate","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4870"],"errorCode":"","eventId":"4870","severity":"High","summary":"Windows Security event 4870 records: Certificate Services revoked a certificate","rootCause":"The event records a state-changing operation: Certificate Services revoked a certificate It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4870.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Certificate Services revoked a certificate\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4870\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4870} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4870","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4870","Event ID 4870","Certificate Services revoked a certificate"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69481,"title":"Windows Security Event 4871 - Certificate Services received a request to publish the certificate revocation list (CRL)","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4871","Windows"],"keywords":["4871","event 4871","event id 4871","Certificate Services received a request to publish the certificate revocation list (CRL)","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4871"],"errorCode":"","eventId":"4871","severity":"Medium","summary":"Windows Security event 4871 records: Certificate Services received a request to publish the certificate revocation list (CRL)","rootCause":"The configured audit source recorded this activity: Certificate Services received a request to publish the certificate revocation list (CRL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4871.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Certificate Services received a request to publish the certificate revocation list (CRL)\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4871\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4871} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4871","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4871","Event ID 4871","Certificate Services received a request to publish the certificate revocation list (CRL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69482,"title":"Windows Security Event 4872 - Certificate Services published the certificate revocation list (CRL)","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4872","Windows"],"keywords":["4872","event 4872","event id 4872","Certificate Services published the certificate revocation list (CRL)","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4872"],"errorCode":"","eventId":"4872","severity":"Medium","summary":"Windows Security event 4872 records: Certificate Services published the certificate revocation list (CRL)","rootCause":"The configured audit source recorded this activity: Certificate Services published the certificate revocation list (CRL) It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4872.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Certificate Services published the certificate revocation list (CRL)\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4872\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4872} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4872","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4872","Event ID 4872","Certificate Services published the certificate revocation list (CRL)"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69483,"title":"Windows Security Event 4873 - A certificate request extension changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4873","Windows"],"keywords":["4873","event 4873","event id 4873","A certificate request extension changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4873"],"errorCode":"","eventId":"4873","severity":"Medium","summary":"Windows Security event 4873 records: A certificate request extension changed","rootCause":"The event records a state-changing operation: A certificate request extension changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4873.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A certificate request extension changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4873\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4873} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4873","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4873","Event ID 4873","A certificate request extension changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69484,"title":"Windows Security Event 4874 - One or more certificate request attributes changed.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4874","Windows"],"keywords":["4874","event 4874","event id 4874","One or more certificate request attributes changed.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4874"],"errorCode":"","eventId":"4874","severity":"Medium","summary":"Windows Security event 4874 records: One or more certificate request attributes changed.","rootCause":"The event records a state-changing operation: One or more certificate request attributes changed. It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4874.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: One or more certificate request attributes changed.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4874\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4874} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4874","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4874","Event ID 4874","One or more certificate request attributes changed."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69485,"title":"Windows Security Event 4875 - Certificate Services received a request to shut down","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4875","Windows"],"keywords":["4875","event 4875","event id 4875","Certificate Services received a request to shut down","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4875"],"errorCode":"","eventId":"4875","severity":"Medium","summary":"Windows Security event 4875 records: Certificate Services received a request to shut down","rootCause":"The configured audit source recorded this activity: Certificate Services received a request to shut down It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4875.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Certificate Services received a request to shut down\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4875\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4875} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4875","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4875","Event ID 4875","Certificate Services received a request to shut down"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69486,"title":"Windows Security Event 4876 - Certificate Services backup started","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4876","Windows"],"keywords":["4876","event 4876","event id 4876","Certificate Services backup started","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4876"],"errorCode":"","eventId":"4876","severity":"Medium","summary":"Windows Security event 4876 records: Certificate Services backup started","rootCause":"The configured audit source recorded this activity: Certificate Services backup started It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4876.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Certificate Services backup started\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4876\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4876} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4876","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4876","Event ID 4876","Certificate Services backup started"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69487,"title":"Windows Security Event 4877 - Certificate Services backup completed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4877","Windows"],"keywords":["4877","event 4877","event id 4877","Certificate Services backup completed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4877"],"errorCode":"","eventId":"4877","severity":"Medium","summary":"Windows Security event 4877 records: Certificate Services backup completed","rootCause":"The configured audit source recorded this activity: Certificate Services backup completed It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4877.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Certificate Services backup completed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4877\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4877} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4877","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4877","Event ID 4877","Certificate Services backup completed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69488,"title":"Windows Security Event 4878 - Certificate Services restore started","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4878","Windows"],"keywords":["4878","event 4878","event id 4878","Certificate Services restore started","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4878"],"errorCode":"","eventId":"4878","severity":"Medium","summary":"Windows Security event 4878 records: Certificate Services restore started","rootCause":"The configured audit source recorded this activity: Certificate Services restore started It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4878.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Certificate Services restore started\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4878\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4878} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4878","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4878","Event ID 4878","Certificate Services restore started"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69489,"title":"Windows Security Event 4879 - Certificate Services restore completed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4879","Windows"],"keywords":["4879","event 4879","event id 4879","Certificate Services restore completed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4879"],"errorCode":"","eventId":"4879","severity":"Medium","summary":"Windows Security event 4879 records: Certificate Services restore completed","rootCause":"The configured audit source recorded this activity: Certificate Services restore completed It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4879.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Certificate Services restore completed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4879\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4879} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4879","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4879","Event ID 4879","Certificate Services restore completed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69490,"title":"Windows Security Event 4880 - Certificate Services started","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4880","Windows"],"keywords":["4880","event 4880","event id 4880","Certificate Services started","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4880"],"errorCode":"","eventId":"4880","severity":"Medium","summary":"Windows Security event 4880 records: Certificate Services started","rootCause":"The configured audit source recorded this activity: Certificate Services started It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4880.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Certificate Services started\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4880\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4880} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4880","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4880","Event ID 4880","Certificate Services started"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69491,"title":"Windows Security Event 4881 - Certificate Services stopped","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4881","Windows"],"keywords":["4881","event 4881","event id 4881","Certificate Services stopped","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4881"],"errorCode":"","eventId":"4881","severity":"High","summary":"Windows Security event 4881 records: Certificate Services stopped","rootCause":"The configured audit source recorded this activity: Certificate Services stopped It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4881.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Certificate Services stopped\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4881\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4881} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4881","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4881","Event ID 4881","Certificate Services stopped"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69492,"title":"Windows Security Event 4882 - The security permissions for Certificate Services changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4882","Windows"],"keywords":["4882","event 4882","event id 4882","The security permissions for Certificate Services changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4882"],"errorCode":"","eventId":"4882","severity":"Medium","summary":"Windows Security event 4882 records: The security permissions for Certificate Services changed","rootCause":"The event records a state-changing operation: The security permissions for Certificate Services changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4882.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The security permissions for Certificate Services changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4882\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4882} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4882","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4882","Event ID 4882","The security permissions for Certificate Services changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69493,"title":"Windows Security Event 4883 - Certificate Services retrieved an archived key","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4883","Windows"],"keywords":["4883","event 4883","event id 4883","Certificate Services retrieved an archived key","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4883"],"errorCode":"","eventId":"4883","severity":"Medium","summary":"Windows Security event 4883 records: Certificate Services retrieved an archived key","rootCause":"The configured audit source recorded this activity: Certificate Services retrieved an archived key It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4883.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Certificate Services retrieved an archived key\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4883\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4883} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4883","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4883","Event ID 4883","Certificate Services retrieved an archived key"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69494,"title":"Windows Security Event 4884 - Certificate Services imported a certificate into its database","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4884","Windows"],"keywords":["4884","event 4884","event id 4884","Certificate Services imported a certificate into its database","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4884"],"errorCode":"","eventId":"4884","severity":"Medium","summary":"Windows Security event 4884 records: Certificate Services imported a certificate into its database","rootCause":"The configured audit source recorded this activity: Certificate Services imported a certificate into its database It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4884.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Certificate Services imported a certificate into its database\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4884\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4884} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4884","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4884","Event ID 4884","Certificate Services imported a certificate into its database"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69495,"title":"Windows Security Event 4885 - The audit filter for Certificate Services changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4885","Windows"],"keywords":["4885","event 4885","event id 4885","The audit filter for Certificate Services changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4885"],"errorCode":"","eventId":"4885","severity":"Medium","summary":"Windows Security event 4885 records: The audit filter for Certificate Services changed","rootCause":"The event records a state-changing operation: The audit filter for Certificate Services changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4885.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The audit filter for Certificate Services changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4885\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4885} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4885","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4885","Event ID 4885","The audit filter for Certificate Services changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69496,"title":"Windows Security Event 4886 - Certificate Services received a certificate request","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4886","Windows"],"keywords":["4886","event 4886","event id 4886","Certificate Services received a certificate request","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4886"],"errorCode":"","eventId":"4886","severity":"Medium","summary":"Windows Security event 4886 records: Certificate Services received a certificate request","rootCause":"The configured audit source recorded this activity: Certificate Services received a certificate request It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4886.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Certificate Services received a certificate request\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4886\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4886} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4886","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4886","Event ID 4886","Certificate Services received a certificate request"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69497,"title":"Windows Security Event 4887 - Certificate Services approved a certificate request and issued a certificate","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4887","Windows"],"keywords":["4887","event 4887","event id 4887","Certificate Services approved a certificate request and issued a certificate","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4887"],"errorCode":"","eventId":"4887","severity":"Medium","summary":"Windows Security event 4887 records: Certificate Services approved a certificate request and issued a certificate","rootCause":"The configured audit source recorded this activity: Certificate Services approved a certificate request and issued a certificate It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4887.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Certificate Services approved a certificate request and issued a certificate\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4887\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4887} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4887","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4887","Event ID 4887","Certificate Services approved a certificate request and issued a certificate"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69498,"title":"Windows Security Event 4888 - Certificate Services denied a certificate request","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4888","Windows"],"keywords":["4888","event 4888","event id 4888","Certificate Services denied a certificate request","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4888"],"errorCode":"","eventId":"4888","severity":"High","summary":"Windows Security event 4888 records: Certificate Services denied a certificate request","rootCause":"The audited operation reported a failure: Certificate Services denied a certificate request The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4888.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Certificate Services denied a certificate request\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4888\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4888} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4888","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4888","Event ID 4888","Certificate Services denied a certificate request"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69499,"title":"Windows Security Event 4889 - Certificate Services set the status of a certificate request to pending","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4889","Windows"],"keywords":["4889","event 4889","event id 4889","Certificate Services set the status of a certificate request to pending","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4889"],"errorCode":"","eventId":"4889","severity":"Medium","summary":"Windows Security event 4889 records: Certificate Services set the status of a certificate request to pending","rootCause":"The configured audit source recorded this activity: Certificate Services set the status of a certificate request to pending It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4889.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Certificate Services set the status of a certificate request to pending\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4889\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4889} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4889","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4889","Event ID 4889","Certificate Services set the status of a certificate request to pending"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69500,"title":"Windows Security Event 4890 - The certificate manager settings for Certificate Services changed.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4890","Windows"],"keywords":["4890","event 4890","event id 4890","The certificate manager settings for Certificate Services changed.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4890"],"errorCode":"","eventId":"4890","severity":"Medium","summary":"Windows Security event 4890 records: The certificate manager settings for Certificate Services changed.","rootCause":"The event records a state-changing operation: The certificate manager settings for Certificate Services changed. It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4890.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The certificate manager settings for Certificate Services changed.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4890\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4890} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4890","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4890","Event ID 4890","The certificate manager settings for Certificate Services changed."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69501,"title":"Windows Security Event 4891 - A configuration entry changed in Certificate Services","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4891","Windows"],"keywords":["4891","event 4891","event id 4891","A configuration entry changed in Certificate Services","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4891"],"errorCode":"","eventId":"4891","severity":"Medium","summary":"Windows Security event 4891 records: A configuration entry changed in Certificate Services","rootCause":"The event records a state-changing operation: A configuration entry changed in Certificate Services It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4891.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A configuration entry changed in Certificate Services\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4891\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4891} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4891","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4891","Event ID 4891","A configuration entry changed in Certificate Services"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69502,"title":"Windows Security Event 4892 - A property of Certificate Services changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4892","Windows"],"keywords":["4892","event 4892","event id 4892","A property of Certificate Services changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4892"],"errorCode":"","eventId":"4892","severity":"Medium","summary":"Windows Security event 4892 records: A property of Certificate Services changed","rootCause":"The event records a state-changing operation: A property of Certificate Services changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4892.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A property of Certificate Services changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4892\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4892} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4892","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4892","Event ID 4892","A property of Certificate Services changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69503,"title":"Windows Security Event 4893 - Certificate Services archived a key","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4893","Windows"],"keywords":["4893","event 4893","event id 4893","Certificate Services archived a key","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4893"],"errorCode":"","eventId":"4893","severity":"Medium","summary":"Windows Security event 4893 records: Certificate Services archived a key","rootCause":"The configured audit source recorded this activity: Certificate Services archived a key It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4893.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Certificate Services archived a key\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4893\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4893} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4893","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4893","Event ID 4893","Certificate Services archived a key"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69504,"title":"Windows Security Event 4894 - Certificate Services imported and archived a key","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4894","Windows"],"keywords":["4894","event 4894","event id 4894","Certificate Services imported and archived a key","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4894"],"errorCode":"","eventId":"4894","severity":"Medium","summary":"Windows Security event 4894 records: Certificate Services imported and archived a key","rootCause":"The configured audit source recorded this activity: Certificate Services imported and archived a key It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4894.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Certificate Services imported and archived a key\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4894\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4894} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4894","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4894","Event ID 4894","Certificate Services imported and archived a key"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69505,"title":"Windows Security Event 4895 - Certificate Services published the CA certificate to Active Directory Domain Services","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4895","Windows"],"keywords":["4895","event 4895","event id 4895","Certificate Services published the CA certificate to Active Directory Domain Services","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4895"],"errorCode":"","eventId":"4895","severity":"Medium","summary":"Windows Security event 4895 records: Certificate Services published the CA certificate to Active Directory Domain Services","rootCause":"The configured audit source recorded this activity: Certificate Services published the CA certificate to Active Directory Domain Services It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4895.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Certificate Services published the CA certificate to Active Directory Domain Services\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4895\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4895} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4895","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4895","Event ID 4895","Certificate Services published the CA certificate to Active Directory Domain Services"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69506,"title":"Windows Security Event 4896 - One or more rows have been deleted from the certificate database","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4896","Windows"],"keywords":["4896","event 4896","event id 4896","One or more rows have been deleted from the certificate database","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4896"],"errorCode":"","eventId":"4896","severity":"High","summary":"Windows Security event 4896 records: One or more rows have been deleted from the certificate database","rootCause":"The event records a state-changing operation: One or more rows have been deleted from the certificate database It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4896.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: One or more rows have been deleted from the certificate database\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4896\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4896} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4896","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4896","Event ID 4896","One or more rows have been deleted from the certificate database"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69507,"title":"Windows Security Event 4897 - Role separation enabled","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4897","Windows"],"keywords":["4897","event 4897","event id 4897","Role separation enabled","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4897"],"errorCode":"","eventId":"4897","severity":"Medium","summary":"Windows Security event 4897 records: Role separation enabled","rootCause":"The event records a state-changing operation: Role separation enabled It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4897.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Role separation enabled\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4897\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4897} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4897","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4897","Event ID 4897","Role separation enabled"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69508,"title":"Windows Security Event 4898 - Certificate Services loaded a template","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4898","Windows"],"keywords":["4898","event 4898","event id 4898","Certificate Services loaded a template","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4898"],"errorCode":"","eventId":"4898","severity":"Medium","summary":"Windows Security event 4898 records: Certificate Services loaded a template","rootCause":"The configured audit source recorded this activity: Certificate Services loaded a template It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4898.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Certificate Services loaded a template\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4898\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4898} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4898","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4898","Event ID 4898","Certificate Services loaded a template"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69509,"title":"Windows Security Event 4899 - A Certificate Services template was updated","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4899","Windows"],"keywords":["4899","event 4899","event id 4899","A Certificate Services template was updated","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4899"],"errorCode":"","eventId":"4899","severity":"Medium","summary":"Windows Security event 4899 records: A Certificate Services template was updated","rootCause":"The configured audit source recorded this activity: A Certificate Services template was updated It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4899.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A Certificate Services template was updated\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4899\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4899} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4899","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4899","Event ID 4899","A Certificate Services template was updated"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69510,"title":"Windows Security Event 4900 - Certificate Services template security was updated","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4900","Windows"],"keywords":["4900","event 4900","event id 4900","Certificate Services template security was updated","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4900"],"errorCode":"","eventId":"4900","severity":"Medium","summary":"Windows Security event 4900 records: Certificate Services template security was updated","rootCause":"The configured audit source recorded this activity: Certificate Services template security was updated It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4900.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Certificate Services template security was updated\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4900\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4900} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4900","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4900","Event ID 4900","Certificate Services template security was updated"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69511,"title":"Windows Security Event 4902 - The Per-user audit policy table was created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4902","Windows"],"keywords":["4902","event 4902","event id 4902","The Per-user audit policy table was created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4902"],"errorCode":"","eventId":"4902","severity":"Medium","summary":"Windows Security event 4902 records: The Per-user audit policy table was created","rootCause":"The event records a state-changing operation: The Per-user audit policy table was created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4902.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Per-user audit policy table was created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4902\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4902} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4902","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4902","Event ID 4902","The Per-user audit policy table was created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69512,"title":"Windows Security Event 4904 - An attempt was made to register a security event source","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4904","Windows"],"keywords":["4904","event 4904","event id 4904","An attempt was made to register a security event source","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4904"],"errorCode":"","eventId":"4904","severity":"Low","summary":"Windows Security event 4904 records: An attempt was made to register a security event source","rootCause":"The configured audit source recorded this activity: An attempt was made to register a security event source It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4904.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An attempt was made to register a security event source\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4904\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4904} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4904","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4904","Event ID 4904","An attempt was made to register a security event source"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69513,"title":"Windows Security Event 4905 - An attempt was made to unregister a security event source","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4905","Windows"],"keywords":["4905","event 4905","event id 4905","An attempt was made to unregister a security event source","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4905"],"errorCode":"","eventId":"4905","severity":"Low","summary":"Windows Security event 4905 records: An attempt was made to unregister a security event source","rootCause":"The configured audit source recorded this activity: An attempt was made to unregister a security event source It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4905.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An attempt was made to unregister a security event source\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4905\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4905} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4905","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4905","Event ID 4905","An attempt was made to unregister a security event source"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69514,"title":"Windows Security Event 4906 - The CrashOnAuditFail value has changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4906","Windows"],"keywords":["4906","event 4906","event id 4906","The CrashOnAuditFail value has changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4906"],"errorCode":"","eventId":"4906","severity":"Medium","summary":"Windows Security event 4906 records: The CrashOnAuditFail value has changed","rootCause":"The event records a state-changing operation: The CrashOnAuditFail value has changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4906.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The CrashOnAuditFail value has changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4906\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4906} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4906","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4906","Event ID 4906","The CrashOnAuditFail value has changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69515,"title":"Windows Security Event 4907 - Auditing settings on object were changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4907","Windows"],"keywords":["4907","event 4907","event id 4907","Auditing settings on object were changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4907"],"errorCode":"","eventId":"4907","severity":"Medium","summary":"Windows Security event 4907 records: Auditing settings on object were changed","rootCause":"The event records a state-changing operation: Auditing settings on object were changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4907.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Auditing settings on object were changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4907\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4907} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4907","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4907","Event ID 4907","Auditing settings on object were changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69516,"title":"Windows Security Event 4908 - Special Groups Logon table modified","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4908","Windows"],"keywords":["4908","event 4908","event id 4908","Special Groups Logon table modified","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4908"],"errorCode":"","eventId":"4908","severity":"Medium","summary":"Windows Security event 4908 records: Special Groups Logon table modified","rootCause":"The event records a state-changing operation: Special Groups Logon table modified It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4908.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Special Groups Logon table modified\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4908\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4908} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4908","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4908","Event ID 4908","Special Groups Logon table modified"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69517,"title":"Windows Security Event 4909 - The local policy settings for the TBS were changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4909","Windows"],"keywords":["4909","event 4909","event id 4909","The local policy settings for the TBS were changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4909"],"errorCode":"","eventId":"4909","severity":"Medium","summary":"Windows Security event 4909 records: The local policy settings for the TBS were changed","rootCause":"The event records a state-changing operation: The local policy settings for the TBS were changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4909.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The local policy settings for the TBS were changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4909\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4909} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4909","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4909","Event ID 4909","The local policy settings for the TBS were changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69518,"title":"Windows Security Event 4910 - The group policy settings for the TBS were changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4910","Windows"],"keywords":["4910","event 4910","event id 4910","The group policy settings for the TBS were changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4910"],"errorCode":"","eventId":"4910","severity":"Medium","summary":"Windows Security event 4910 records: The group policy settings for the TBS were changed","rootCause":"The event records a state-changing operation: The group policy settings for the TBS were changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4910.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The group policy settings for the TBS were changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4910\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4910} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4910","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4910","Event ID 4910","The group policy settings for the TBS were changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69519,"title":"Windows Security Event 4911 - Resource attributes of the object were changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4911","Windows"],"keywords":["4911","event 4911","event id 4911","Resource attributes of the object were changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4911"],"errorCode":"","eventId":"4911","severity":"Medium","summary":"Windows Security event 4911 records: Resource attributes of the object were changed","rootCause":"The event records a state-changing operation: Resource attributes of the object were changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4911.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Resource attributes of the object were changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4911\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4911} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4911","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4911","Event ID 4911","Resource attributes of the object were changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69520,"title":"Windows Security Event 4912 - Per User Audit Policy was changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4912","Windows"],"keywords":["4912","event 4912","event id 4912","Per User Audit Policy was changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4912"],"errorCode":"","eventId":"4912","severity":"Medium","summary":"Windows Security event 4912 records: Per User Audit Policy was changed","rootCause":"The event records a state-changing operation: Per User Audit Policy was changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4912.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Per User Audit Policy was changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4912\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4912} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4912","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4912","Event ID 4912","Per User Audit Policy was changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69521,"title":"Windows Security Event 4913 - Central Access Policy on the object was changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4913","Windows"],"keywords":["4913","event 4913","event id 4913","Central Access Policy on the object was changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4913"],"errorCode":"","eventId":"4913","severity":"Medium","summary":"Windows Security event 4913 records: Central Access Policy on the object was changed","rootCause":"The event records a state-changing operation: Central Access Policy on the object was changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4913.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Central Access Policy on the object was changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4913\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4913} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4913","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4913","Event ID 4913","Central Access Policy on the object was changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69522,"title":"Windows Security Event 4928 - An Active Directory replica source naming context was established","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4928","Windows"],"keywords":["4928","event 4928","event id 4928","An Active Directory replica source naming context was established","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4928"],"errorCode":"","eventId":"4928","severity":"Low","summary":"Windows Security event 4928 records: An Active Directory replica source naming context was established","rootCause":"The configured audit source recorded this activity: An Active Directory replica source naming context was established It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4928.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An Active Directory replica source naming context was established\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4928\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4928} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4928","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4928","Event ID 4928","An Active Directory replica source naming context was established"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69523,"title":"Windows Security Event 4929 - An Active Directory replica source naming context was removed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4929","Windows"],"keywords":["4929","event 4929","event id 4929","An Active Directory replica source naming context was removed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4929"],"errorCode":"","eventId":"4929","severity":"Medium","summary":"Windows Security event 4929 records: An Active Directory replica source naming context was removed","rootCause":"The event records a state-changing operation: An Active Directory replica source naming context was removed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4929.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An Active Directory replica source naming context was removed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4929\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4929} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4929","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4929","Event ID 4929","An Active Directory replica source naming context was removed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69524,"title":"Windows Security Event 4930 - An Active Directory replica source naming context was modified","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4930","Windows"],"keywords":["4930","event 4930","event id 4930","An Active Directory replica source naming context was modified","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4930"],"errorCode":"","eventId":"4930","severity":"Medium","summary":"Windows Security event 4930 records: An Active Directory replica source naming context was modified","rootCause":"The event records a state-changing operation: An Active Directory replica source naming context was modified It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4930.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An Active Directory replica source naming context was modified\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4930\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4930} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4930","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4930","Event ID 4930","An Active Directory replica source naming context was modified"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69525,"title":"Windows Security Event 4931 - An Active Directory replica destination naming context was modified","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4931","Windows"],"keywords":["4931","event 4931","event id 4931","An Active Directory replica destination naming context was modified","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4931"],"errorCode":"","eventId":"4931","severity":"Medium","summary":"Windows Security event 4931 records: An Active Directory replica destination naming context was modified","rootCause":"The event records a state-changing operation: An Active Directory replica destination naming context was modified It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4931.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An Active Directory replica destination naming context was modified\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4931\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4931} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4931","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4931","Event ID 4931","An Active Directory replica destination naming context was modified"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69526,"title":"Windows Security Event 4932 - Synchronization of a replica of an Active Directory naming context has begun","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4932","Windows"],"keywords":["4932","event 4932","event id 4932","Synchronization of a replica of an Active Directory naming context has begun","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4932"],"errorCode":"","eventId":"4932","severity":"Low","summary":"Windows Security event 4932 records: Synchronization of a replica of an Active Directory naming context has begun","rootCause":"The configured audit source recorded this activity: Synchronization of a replica of an Active Directory naming context has begun It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4932.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Synchronization of a replica of an Active Directory naming context has begun\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4932\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4932} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4932","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4932","Event ID 4932","Synchronization of a replica of an Active Directory naming context has begun"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69527,"title":"Windows Security Event 4933 - Synchronization of a replica of an Active Directory naming context has ended","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4933","Windows"],"keywords":["4933","event 4933","event id 4933","Synchronization of a replica of an Active Directory naming context has ended","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4933"],"errorCode":"","eventId":"4933","severity":"Low","summary":"Windows Security event 4933 records: Synchronization of a replica of an Active Directory naming context has ended","rootCause":"The configured audit source recorded this activity: Synchronization of a replica of an Active Directory naming context has ended It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4933.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Synchronization of a replica of an Active Directory naming context has ended\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4933\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4933} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4933","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4933","Event ID 4933","Synchronization of a replica of an Active Directory naming context has ended"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69528,"title":"Windows Security Event 4934 - Attributes of an Active Directory object were replicated","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4934","Windows"],"keywords":["4934","event 4934","event id 4934","Attributes of an Active Directory object were replicated","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4934"],"errorCode":"","eventId":"4934","severity":"Low","summary":"Windows Security event 4934 records: Attributes of an Active Directory object were replicated","rootCause":"The configured audit source recorded this activity: Attributes of an Active Directory object were replicated It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4934.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Attributes of an Active Directory object were replicated\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4934\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4934} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4934","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4934","Event ID 4934","Attributes of an Active Directory object were replicated"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69529,"title":"Windows Security Event 4935 - Replication failure begins","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4935","Windows"],"keywords":["4935","event 4935","event id 4935","Replication failure begins","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4935"],"errorCode":"","eventId":"4935","severity":"High","summary":"Windows Security event 4935 records: Replication failure begins","rootCause":"The audited operation reported a failure: Replication failure begins The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4935.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Replication failure begins\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4935\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4935} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4935","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4935","Event ID 4935","Replication failure begins"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69530,"title":"Windows Security Event 4936 - Replication failure ends","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4936","Windows"],"keywords":["4936","event 4936","event id 4936","Replication failure ends","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4936"],"errorCode":"","eventId":"4936","severity":"High","summary":"Windows Security event 4936 records: Replication failure ends","rootCause":"The audited operation reported a failure: Replication failure ends The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4936.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Replication failure ends\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4936\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4936} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4936","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4936","Event ID 4936","Replication failure ends"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69531,"title":"Windows Security Event 4937 - A lingering object was removed from a replica","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4937","Windows"],"keywords":["4937","event 4937","event id 4937","A lingering object was removed from a replica","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4937"],"errorCode":"","eventId":"4937","severity":"Medium","summary":"Windows Security event 4937 records: A lingering object was removed from a replica","rootCause":"The event records a state-changing operation: A lingering object was removed from a replica It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4937.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A lingering object was removed from a replica\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4937\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4937} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4937","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4937","Event ID 4937","A lingering object was removed from a replica"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69532,"title":"Windows Security Event 4944 - The following policy was active when the Windows Firewall started","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4944","Windows"],"keywords":["4944","event 4944","event id 4944","The following policy was active when the Windows Firewall started","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4944"],"errorCode":"","eventId":"4944","severity":"Medium","summary":"Windows Security event 4944 records: The following policy was active when the Windows Firewall started","rootCause":"The configured audit source recorded this activity: The following policy was active when the Windows Firewall started It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4944.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The following policy was active when the Windows Firewall started\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4944\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4944} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4944","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4944","Event ID 4944","The following policy was active when the Windows Firewall started"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69533,"title":"Windows Security Event 4945 - A rule was listed when the Windows Firewall started","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4945","Windows"],"keywords":["4945","event 4945","event id 4945","A rule was listed when the Windows Firewall started","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4945"],"errorCode":"","eventId":"4945","severity":"Medium","summary":"Windows Security event 4945 records: A rule was listed when the Windows Firewall started","rootCause":"The configured audit source recorded this activity: A rule was listed when the Windows Firewall started It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4945.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A rule was listed when the Windows Firewall started\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4945\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4945} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4945","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4945","Event ID 4945","A rule was listed when the Windows Firewall started"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69534,"title":"Windows Security Event 4946 - A change has been made to Windows Firewall exception list. A rule was added","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4946","Windows"],"keywords":["4946","event 4946","event id 4946","A change has been made to Windows Firewall exception list. A rule was added","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4946"],"errorCode":"","eventId":"4946","severity":"Medium","summary":"Windows Security event 4946 records: A change has been made to Windows Firewall exception list. A rule was added","rootCause":"The event records a state-changing operation: A change has been made to Windows Firewall exception list. A rule was added It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4946.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A change has been made to Windows Firewall exception list. A rule was added\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4946\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4946} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4946","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4946","Event ID 4946","A change has been made to Windows Firewall exception list. A rule was added"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69535,"title":"Windows Security Event 4947 - A change has been made to Windows Firewall exception list. A rule was modified","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4947","Windows"],"keywords":["4947","event 4947","event id 4947","A change has been made to Windows Firewall exception list. A rule was modified","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4947"],"errorCode":"","eventId":"4947","severity":"Medium","summary":"Windows Security event 4947 records: A change has been made to Windows Firewall exception list. A rule was modified","rootCause":"The event records a state-changing operation: A change has been made to Windows Firewall exception list. A rule was modified It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4947.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A change has been made to Windows Firewall exception list. A rule was modified\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4947\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4947} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4947","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4947","Event ID 4947","A change has been made to Windows Firewall exception list. A rule was modified"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69536,"title":"Windows Security Event 4948 - A change has been made to Windows Firewall exception list. A rule was deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4948","Windows"],"keywords":["4948","event 4948","event id 4948","A change has been made to Windows Firewall exception list. A rule was deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4948"],"errorCode":"","eventId":"4948","severity":"High","summary":"Windows Security event 4948 records: A change has been made to Windows Firewall exception list. A rule was deleted","rootCause":"The event records a state-changing operation: A change has been made to Windows Firewall exception list. A rule was deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4948.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A change has been made to Windows Firewall exception list. A rule was deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4948\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4948} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4948","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4948","Event ID 4948","A change has been made to Windows Firewall exception list. A rule was deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69537,"title":"Windows Security Event 4949 - Windows Firewall settings were restored to the default values","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4949","Windows"],"keywords":["4949","event 4949","event id 4949","Windows Firewall settings were restored to the default values","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4949"],"errorCode":"","eventId":"4949","severity":"Medium","summary":"Windows Security event 4949 records: Windows Firewall settings were restored to the default values","rootCause":"The configured audit source recorded this activity: Windows Firewall settings were restored to the default values It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4949.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Windows Firewall settings were restored to the default values\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4949\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4949} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4949","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4949","Event ID 4949","Windows Firewall settings were restored to the default values"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69538,"title":"Windows Security Event 4950 - A Windows Firewall setting has changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4950","Windows"],"keywords":["4950","event 4950","event id 4950","A Windows Firewall setting has changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4950"],"errorCode":"","eventId":"4950","severity":"Medium","summary":"Windows Security event 4950 records: A Windows Firewall setting has changed","rootCause":"The event records a state-changing operation: A Windows Firewall setting has changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4950.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A Windows Firewall setting has changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4950\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4950} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4950","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4950","Event ID 4950","A Windows Firewall setting has changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69539,"title":"Windows Security Event 4951 - A rule has been ignored because its major version number was not recognized by Windows Firewall","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4951","Windows"],"keywords":["4951","event 4951","event id 4951","A rule has been ignored because its major version number was not recognized by Windows Firewall","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4951"],"errorCode":"","eventId":"4951","severity":"Medium","summary":"Windows Security event 4951 records: A rule has been ignored because its major version number was not recognized by Windows Firewall","rootCause":"The configured audit source recorded this activity: A rule has been ignored because its major version number was not recognized by Windows Firewall It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4951.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A rule has been ignored because its major version number was not recognized by Windows Firewall\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4951\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4951} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4951","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4951","Event ID 4951","A rule has been ignored because its major version number was not recognized by Windows Firewall"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69540,"title":"Windows Security Event 4952 - Parts of a rule have been ignored because its minor version number was not recognized by Windows Firewall","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4952","Windows"],"keywords":["4952","event 4952","event id 4952","Parts of a rule have been ignored because its minor version number was not recognized by Windows Firewall","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4952"],"errorCode":"","eventId":"4952","severity":"Medium","summary":"Windows Security event 4952 records: Parts of a rule have been ignored because its minor version number was not recognized by Windows Firewall","rootCause":"The configured audit source recorded this activity: Parts of a rule have been ignored because its minor version number was not recognized by Windows Firewall It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4952.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Parts of a rule have been ignored because its minor version number was not recognized by Windows Firewall\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4952\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4952} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4952","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4952","Event ID 4952","Parts of a rule have been ignored because its minor version number was not recognized by Windows Firewall"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69541,"title":"Windows Security Event 4953 - A rule has been ignored by Windows Firewall because it could not parse the rule","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4953","Windows"],"keywords":["4953","event 4953","event id 4953","A rule has been ignored by Windows Firewall because it could not parse the rule","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4953"],"errorCode":"","eventId":"4953","severity":"High","summary":"Windows Security event 4953 records: A rule has been ignored by Windows Firewall because it could not parse the rule","rootCause":"The audited operation reported a failure: A rule has been ignored by Windows Firewall because it could not parse the rule The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4953.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A rule has been ignored by Windows Firewall because it could not parse the rule\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4953\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4953} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4953","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4953","Event ID 4953","A rule has been ignored by Windows Firewall because it could not parse the rule"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69542,"title":"Windows Security Event 4954 - Windows Firewall Group Policy settings has changed. The new settings have been applied","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4954","Windows"],"keywords":["4954","event 4954","event id 4954","Windows Firewall Group Policy settings has changed. The new settings have been applied","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4954"],"errorCode":"","eventId":"4954","severity":"Medium","summary":"Windows Security event 4954 records: Windows Firewall Group Policy settings has changed. The new settings have been applied","rootCause":"The event records a state-changing operation: Windows Firewall Group Policy settings has changed. The new settings have been applied It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4954.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Windows Firewall Group Policy settings has changed. The new settings have been applied\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4954\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4954} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4954","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4954","Event ID 4954","Windows Firewall Group Policy settings has changed. The new settings have been applied"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69543,"title":"Windows Security Event 4956 - Windows Firewall has changed the active profile","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4956","Windows"],"keywords":["4956","event 4956","event id 4956","Windows Firewall has changed the active profile","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4956"],"errorCode":"","eventId":"4956","severity":"Medium","summary":"Windows Security event 4956 records: Windows Firewall has changed the active profile","rootCause":"The event records a state-changing operation: Windows Firewall has changed the active profile It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4956.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Windows Firewall has changed the active profile\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4956\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4956} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4956","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4956","Event ID 4956","Windows Firewall has changed the active profile"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69544,"title":"Windows Security Event 4957 - Windows Firewall did not apply the following rule","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4957","Windows"],"keywords":["4957","event 4957","event id 4957","Windows Firewall did not apply the following rule","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4957"],"errorCode":"","eventId":"4957","severity":"Medium","summary":"Windows Security event 4957 records: Windows Firewall did not apply the following rule","rootCause":"The configured audit source recorded this activity: Windows Firewall did not apply the following rule It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4957.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Windows Firewall did not apply the following rule\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4957\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4957} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4957","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4957","Event ID 4957","Windows Firewall did not apply the following rule"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69545,"title":"Windows Security Event 4958 - Windows Firewall did not apply the following rule because the rule referred to items not configured on this computer","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4958","Windows"],"keywords":["4958","event 4958","event id 4958","Windows Firewall did not apply the following rule because the rule referred to items not configured on this computer","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4958"],"errorCode":"","eventId":"4958","severity":"Medium","summary":"Windows Security event 4958 records: Windows Firewall did not apply the following rule because the rule referred to items not configured on this computer","rootCause":"The configured audit source recorded this activity: Windows Firewall did not apply the following rule because the rule referred to items not configured on this computer It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4958.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Windows Firewall did not apply the following rule because the rule referred to items not configured on this computer\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4958\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4958} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4958","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4958","Event ID 4958","Windows Firewall did not apply the following rule because the rule referred to items not configured on this computer"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69546,"title":"Windows Security Event 4960 - IPsec dropped an inbound packet that failed an integrity check","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4960","Windows"],"keywords":["4960","event 4960","event id 4960","IPsec dropped an inbound packet that failed an integrity check","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4960"],"errorCode":"","eventId":"4960","severity":"High","summary":"Windows Security event 4960 records: IPsec dropped an inbound packet that failed an integrity check","rootCause":"The audited operation reported a failure: IPsec dropped an inbound packet that failed an integrity check The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4960.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: IPsec dropped an inbound packet that failed an integrity check\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4960\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4960} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4960","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4960","Event ID 4960","IPsec dropped an inbound packet that failed an integrity check"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69547,"title":"Windows Security Event 4961 - IPsec dropped an inbound packet that failed a replay check","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4961","Windows"],"keywords":["4961","event 4961","event id 4961","IPsec dropped an inbound packet that failed a replay check","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4961"],"errorCode":"","eventId":"4961","severity":"High","summary":"Windows Security event 4961 records: IPsec dropped an inbound packet that failed a replay check","rootCause":"The audited operation reported a failure: IPsec dropped an inbound packet that failed a replay check The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4961.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: IPsec dropped an inbound packet that failed a replay check\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4961\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4961} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4961","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4961","Event ID 4961","IPsec dropped an inbound packet that failed a replay check"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69548,"title":"Windows Security Event 4962 - IPsec dropped an inbound packet that failed a replay check","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4962","Windows"],"keywords":["4962","event 4962","event id 4962","IPsec dropped an inbound packet that failed a replay check","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4962"],"errorCode":"","eventId":"4962","severity":"High","summary":"Windows Security event 4962 records: IPsec dropped an inbound packet that failed a replay check","rootCause":"The audited operation reported a failure: IPsec dropped an inbound packet that failed a replay check The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4962.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: IPsec dropped an inbound packet that failed a replay check\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4962\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4962} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4962","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4962","Event ID 4962","IPsec dropped an inbound packet that failed a replay check"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69549,"title":"Windows Security Event 4963 - IPsec dropped an inbound clear text packet that should have been secured","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4963","Windows"],"keywords":["4963","event 4963","event id 4963","IPsec dropped an inbound clear text packet that should have been secured","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4963"],"errorCode":"","eventId":"4963","severity":"Medium","summary":"Windows Security event 4963 records: IPsec dropped an inbound clear text packet that should have been secured","rootCause":"The configured audit source recorded this activity: IPsec dropped an inbound clear text packet that should have been secured It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4963.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: IPsec dropped an inbound clear text packet that should have been secured\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4963\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4963} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4963","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4963","Event ID 4963","IPsec dropped an inbound clear text packet that should have been secured"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69550,"title":"Windows Security Event 4964 - Special groups have been assigned to a new logon","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4964","Windows"],"keywords":["4964","event 4964","event id 4964","Special groups have been assigned to a new logon","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4964"],"errorCode":"","eventId":"4964","severity":"Medium","summary":"Windows Security event 4964 records: Special groups have been assigned to a new logon","rootCause":"The configured audit source recorded this activity: Special groups have been assigned to a new logon It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4964.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Special groups have been assigned to a new logon\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4964\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4964} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4964","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4964","Event ID 4964","Special groups have been assigned to a new logon"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69551,"title":"Windows Security Event 4965 - IPsec received a packet from a remote computer with an incorrect Security Parameter Index (SPI).","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4965","Windows"],"keywords":["4965","event 4965","event id 4965","IPsec received a packet from a remote computer with an incorrect Security Parameter Index (SPI).","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4965"],"errorCode":"","eventId":"4965","severity":"Medium","summary":"Windows Security event 4965 records: IPsec received a packet from a remote computer with an incorrect Security Parameter Index (SPI).","rootCause":"The configured audit source recorded this activity: IPsec received a packet from a remote computer with an incorrect Security Parameter Index (SPI). It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4965.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: IPsec received a packet from a remote computer with an incorrect Security Parameter Index (SPI).\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4965\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4965} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4965","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4965","Event ID 4965","IPsec received a packet from a remote computer with an incorrect Security Parameter Index (SPI)."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69552,"title":"Windows Security Event 4976 - During Main Mode negotiation, IPsec received an invalid negotiation packet.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4976","Windows"],"keywords":["4976","event 4976","event id 4976","During Main Mode negotiation, IPsec received an invalid negotiation packet.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4976"],"errorCode":"","eventId":"4976","severity":"High","summary":"Windows Security event 4976 records: During Main Mode negotiation, IPsec received an invalid negotiation packet.","rootCause":"The audited operation reported a failure: During Main Mode negotiation, IPsec received an invalid negotiation packet. The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4976.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: During Main Mode negotiation, IPsec received an invalid negotiation packet.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4976\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4976} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4976","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4976","Event ID 4976","During Main Mode negotiation, IPsec received an invalid negotiation packet."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69553,"title":"Windows Security Event 4977 - During Quick Mode negotiation, IPsec received an invalid negotiation packet.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4977","Windows"],"keywords":["4977","event 4977","event id 4977","During Quick Mode negotiation, IPsec received an invalid negotiation packet.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4977"],"errorCode":"","eventId":"4977","severity":"High","summary":"Windows Security event 4977 records: During Quick Mode negotiation, IPsec received an invalid negotiation packet.","rootCause":"The audited operation reported a failure: During Quick Mode negotiation, IPsec received an invalid negotiation packet. The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4977.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: During Quick Mode negotiation, IPsec received an invalid negotiation packet.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4977\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4977} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4977","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4977","Event ID 4977","During Quick Mode negotiation, IPsec received an invalid negotiation packet."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69554,"title":"Windows Security Event 4978 - During Extended Mode negotiation, IPsec received an invalid negotiation packet.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4978","Windows"],"keywords":["4978","event 4978","event id 4978","During Extended Mode negotiation, IPsec received an invalid negotiation packet.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4978"],"errorCode":"","eventId":"4978","severity":"High","summary":"Windows Security event 4978 records: During Extended Mode negotiation, IPsec received an invalid negotiation packet.","rootCause":"The audited operation reported a failure: During Extended Mode negotiation, IPsec received an invalid negotiation packet. The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4978.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: During Extended Mode negotiation, IPsec received an invalid negotiation packet.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4978\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4978} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4978","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4978","Event ID 4978","During Extended Mode negotiation, IPsec received an invalid negotiation packet."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69555,"title":"Windows Security Event 4979 - IPsec Main Mode and Extended Mode security associations were established.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4979","Windows"],"keywords":["4979","event 4979","event id 4979","IPsec Main Mode and Extended Mode security associations were established.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4979"],"errorCode":"","eventId":"4979","severity":"Medium","summary":"Windows Security event 4979 records: IPsec Main Mode and Extended Mode security associations were established.","rootCause":"The configured audit source recorded this activity: IPsec Main Mode and Extended Mode security associations were established. It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4979.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: IPsec Main Mode and Extended Mode security associations were established.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4979\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4979} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4979","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4979","Event ID 4979","IPsec Main Mode and Extended Mode security associations were established."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69556,"title":"Windows Security Event 4980 - IPsec Main Mode and Extended Mode security associations were established","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4980","Windows"],"keywords":["4980","event 4980","event id 4980","IPsec Main Mode and Extended Mode security associations were established","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4980"],"errorCode":"","eventId":"4980","severity":"Medium","summary":"Windows Security event 4980 records: IPsec Main Mode and Extended Mode security associations were established","rootCause":"The configured audit source recorded this activity: IPsec Main Mode and Extended Mode security associations were established It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4980.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: IPsec Main Mode and Extended Mode security associations were established\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4980\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4980} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4980","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4980","Event ID 4980","IPsec Main Mode and Extended Mode security associations were established"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69557,"title":"Windows Security Event 4981 - IPsec Main Mode and Extended Mode security associations were established","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4981","Windows"],"keywords":["4981","event 4981","event id 4981","IPsec Main Mode and Extended Mode security associations were established","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4981"],"errorCode":"","eventId":"4981","severity":"Medium","summary":"Windows Security event 4981 records: IPsec Main Mode and Extended Mode security associations were established","rootCause":"The configured audit source recorded this activity: IPsec Main Mode and Extended Mode security associations were established It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4981.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: IPsec Main Mode and Extended Mode security associations were established\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4981\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4981} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4981","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4981","Event ID 4981","IPsec Main Mode and Extended Mode security associations were established"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69558,"title":"Windows Security Event 4982 - IPsec Main Mode and Extended Mode security associations were established","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4982","Windows"],"keywords":["4982","event 4982","event id 4982","IPsec Main Mode and Extended Mode security associations were established","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4982"],"errorCode":"","eventId":"4982","severity":"Medium","summary":"Windows Security event 4982 records: IPsec Main Mode and Extended Mode security associations were established","rootCause":"The configured audit source recorded this activity: IPsec Main Mode and Extended Mode security associations were established It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4982.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: IPsec Main Mode and Extended Mode security associations were established\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4982\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4982} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4982","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4982","Event ID 4982","IPsec Main Mode and Extended Mode security associations were established"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69559,"title":"Windows Security Event 4983 - An IPsec Extended Mode negotiation failed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4983","Windows"],"keywords":["4983","event 4983","event id 4983","An IPsec Extended Mode negotiation failed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4983"],"errorCode":"","eventId":"4983","severity":"High","summary":"Windows Security event 4983 records: An IPsec Extended Mode negotiation failed","rootCause":"The audited operation reported a failure: An IPsec Extended Mode negotiation failed The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4983.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An IPsec Extended Mode negotiation failed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4983\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4983} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4983","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4983","Event ID 4983","An IPsec Extended Mode negotiation failed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69560,"title":"Windows Security Event 4984 - An IPsec Extended Mode negotiation failed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4984","Windows"],"keywords":["4984","event 4984","event id 4984","An IPsec Extended Mode negotiation failed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4984"],"errorCode":"","eventId":"4984","severity":"High","summary":"Windows Security event 4984 records: An IPsec Extended Mode negotiation failed","rootCause":"The audited operation reported a failure: An IPsec Extended Mode negotiation failed The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4984.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An IPsec Extended Mode negotiation failed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4984\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4984} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4984","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4984","Event ID 4984","An IPsec Extended Mode negotiation failed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69561,"title":"Windows Security Event 4985 - The state of a transaction has changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 4985","Windows"],"keywords":["4985","event 4985","event id 4985","The state of a transaction has changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4985"],"errorCode":"","eventId":"4985","severity":"Medium","summary":"Windows Security event 4985 records: The state of a transaction has changed","rootCause":"The event records a state-changing operation: The state of a transaction has changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 4985.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The state of a transaction has changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4985\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4985} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4985","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 4985","Event ID 4985","The state of a transaction has changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69562,"title":"Windows Security Event 5024 - The Windows Firewall Service has started successfully","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5024","Windows"],"keywords":["5024","event 5024","event id 5024","The Windows Firewall Service has started successfully","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5024"],"errorCode":"","eventId":"5024","severity":"Medium","summary":"Windows Security event 5024 records: The Windows Firewall Service has started successfully","rootCause":"The configured audit source recorded this activity: The Windows Firewall Service has started successfully It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5024.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Firewall Service has started successfully\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5024\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5024} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5024","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5024","Event ID 5024","The Windows Firewall Service has started successfully"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69563,"title":"Windows Security Event 5025 - The Windows Firewall Service has been stopped","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5025","Windows"],"keywords":["5025","event 5025","event id 5025","The Windows Firewall Service has been stopped","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5025"],"errorCode":"","eventId":"5025","severity":"High","summary":"Windows Security event 5025 records: The Windows Firewall Service has been stopped","rootCause":"The configured audit source recorded this activity: The Windows Firewall Service has been stopped It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5025.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Firewall Service has been stopped\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5025\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5025} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5025","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5025","Event ID 5025","The Windows Firewall Service has been stopped"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69564,"title":"Windows Security Event 5027 - The Windows Firewall Service was unable to retrieve the security policy from the local storage","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5027","Windows"],"keywords":["5027","event 5027","event id 5027","The Windows Firewall Service was unable to retrieve the security policy from the local storage","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5027"],"errorCode":"","eventId":"5027","severity":"High","summary":"Windows Security event 5027 records: The Windows Firewall Service was unable to retrieve the security policy from the local storage","rootCause":"The audited operation reported a failure: The Windows Firewall Service was unable to retrieve the security policy from the local storage The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5027.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Firewall Service was unable to retrieve the security policy from the local storage\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5027\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5027} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5027","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5027","Event ID 5027","The Windows Firewall Service was unable to retrieve the security policy from the local storage"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69565,"title":"Windows Security Event 5028 - The Windows Firewall Service was unable to parse the new security policy.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5028","Windows"],"keywords":["5028","event 5028","event id 5028","The Windows Firewall Service was unable to parse the new security policy.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5028"],"errorCode":"","eventId":"5028","severity":"High","summary":"Windows Security event 5028 records: The Windows Firewall Service was unable to parse the new security policy.","rootCause":"The audited operation reported a failure: The Windows Firewall Service was unable to parse the new security policy. The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5028.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Firewall Service was unable to parse the new security policy.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5028\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5028} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5028","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5028","Event ID 5028","The Windows Firewall Service was unable to parse the new security policy."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69566,"title":"Windows Security Event 5029 - The Windows Firewall Service failed to initialize the driver","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5029","Windows"],"keywords":["5029","event 5029","event id 5029","The Windows Firewall Service failed to initialize the driver","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5029"],"errorCode":"","eventId":"5029","severity":"High","summary":"Windows Security event 5029 records: The Windows Firewall Service failed to initialize the driver","rootCause":"The audited operation reported a failure: The Windows Firewall Service failed to initialize the driver The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5029.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Firewall Service failed to initialize the driver\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5029\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5029} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5029","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5029","Event ID 5029","The Windows Firewall Service failed to initialize the driver"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69567,"title":"Windows Security Event 5030 - The Windows Firewall Service failed to start","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5030","Windows"],"keywords":["5030","event 5030","event id 5030","The Windows Firewall Service failed to start","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5030"],"errorCode":"","eventId":"5030","severity":"High","summary":"Windows Security event 5030 records: The Windows Firewall Service failed to start","rootCause":"The audited operation reported a failure: The Windows Firewall Service failed to start The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5030.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Firewall Service failed to start\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5030\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5030} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5030","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5030","Event ID 5030","The Windows Firewall Service failed to start"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69568,"title":"Windows Security Event 5031 - The Windows Firewall Service blocked an application from accepting incoming connections on the network.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5031","Windows"],"keywords":["5031","event 5031","event id 5031","The Windows Firewall Service blocked an application from accepting incoming connections on the network.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5031"],"errorCode":"","eventId":"5031","severity":"High","summary":"Windows Security event 5031 records: The Windows Firewall Service blocked an application from accepting incoming connections on the network.","rootCause":"The audited operation reported a failure: The Windows Firewall Service blocked an application from accepting incoming connections on the network. The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5031.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Firewall Service blocked an application from accepting incoming connections on the network.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5031\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5031} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5031","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5031","Event ID 5031","The Windows Firewall Service blocked an application from accepting incoming connections on the network."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69569,"title":"Windows Security Event 5032 - Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5032","Windows"],"keywords":["5032","event 5032","event id 5032","Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5032"],"errorCode":"","eventId":"5032","severity":"High","summary":"Windows Security event 5032 records: Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network","rootCause":"The audited operation reported a failure: Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5032.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5032\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5032} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5032","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5032","Event ID 5032","Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69570,"title":"Windows Security Event 5033 - The Windows Firewall Driver has started successfully","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5033","Windows"],"keywords":["5033","event 5033","event id 5033","The Windows Firewall Driver has started successfully","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5033"],"errorCode":"","eventId":"5033","severity":"Medium","summary":"Windows Security event 5033 records: The Windows Firewall Driver has started successfully","rootCause":"The configured audit source recorded this activity: The Windows Firewall Driver has started successfully It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5033.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Firewall Driver has started successfully\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5033\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5033} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5033","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5033","Event ID 5033","The Windows Firewall Driver has started successfully"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69571,"title":"Windows Security Event 5034 - The Windows Firewall Driver has been stopped","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5034","Windows"],"keywords":["5034","event 5034","event id 5034","The Windows Firewall Driver has been stopped","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5034"],"errorCode":"","eventId":"5034","severity":"High","summary":"Windows Security event 5034 records: The Windows Firewall Driver has been stopped","rootCause":"The configured audit source recorded this activity: The Windows Firewall Driver has been stopped It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5034.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Firewall Driver has been stopped\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5034\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5034} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5034","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5034","Event ID 5034","The Windows Firewall Driver has been stopped"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69572,"title":"Windows Security Event 5035 - The Windows Firewall Driver failed to start","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5035","Windows"],"keywords":["5035","event 5035","event id 5035","The Windows Firewall Driver failed to start","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5035"],"errorCode":"","eventId":"5035","severity":"High","summary":"Windows Security event 5035 records: The Windows Firewall Driver failed to start","rootCause":"The audited operation reported a failure: The Windows Firewall Driver failed to start The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5035.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Firewall Driver failed to start\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5035\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5035} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5035","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5035","Event ID 5035","The Windows Firewall Driver failed to start"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69573,"title":"Windows Security Event 5037 - The Windows Firewall Driver detected critical runtime error. Terminating","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5037","Windows"],"keywords":["5037","event 5037","event id 5037","The Windows Firewall Driver detected critical runtime error. Terminating","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5037"],"errorCode":"","eventId":"5037","severity":"Critical","summary":"Windows Security event 5037 records: The Windows Firewall Driver detected critical runtime error. Terminating","rootCause":"The audited operation reported a failure: The Windows Firewall Driver detected critical runtime error. Terminating The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5037.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Firewall Driver detected critical runtime error. Terminating\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5037\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5037} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5037","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5037","Event ID 5037","The Windows Firewall Driver detected critical runtime error. Terminating"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69574,"title":"Windows Security Event 5038 - Code integrity determined that the image hash of a file is not valid","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5038","Windows"],"keywords":["5038","event 5038","event id 5038","Code integrity determined that the image hash of a file is not valid","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5038"],"errorCode":"","eventId":"5038","severity":"Critical","summary":"Windows Security event 5038 records: Code integrity determined that the image hash of a file is not valid","rootCause":"The configured audit source recorded this activity: Code integrity determined that the image hash of a file is not valid It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5038.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Code integrity determined that the image hash of a file is not valid\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5038\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5038} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5038","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5038","Event ID 5038","Code integrity determined that the image hash of a file is not valid"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69575,"title":"Windows Security Event 5039 - A registry key was virtualized.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5039","Windows"],"keywords":["5039","event 5039","event id 5039","A registry key was virtualized.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5039"],"errorCode":"","eventId":"5039","severity":"Low","summary":"Windows Security event 5039 records: A registry key was virtualized.","rootCause":"The configured audit source recorded this activity: A registry key was virtualized. It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5039.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A registry key was virtualized.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5039\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5039} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5039","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5039","Event ID 5039","A registry key was virtualized."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69576,"title":"Windows Security Event 5040 - A change has been made to IPsec settings. An Authentication Set was added.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5040","Windows"],"keywords":["5040","event 5040","event id 5040","A change has been made to IPsec settings. An Authentication Set was added.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5040"],"errorCode":"","eventId":"5040","severity":"Medium","summary":"Windows Security event 5040 records: A change has been made to IPsec settings. An Authentication Set was added.","rootCause":"The event records a state-changing operation: A change has been made to IPsec settings. An Authentication Set was added. It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5040.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A change has been made to IPsec settings. An Authentication Set was added.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5040\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5040} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5040","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5040","Event ID 5040","A change has been made to IPsec settings. An Authentication Set was added."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69577,"title":"Windows Security Event 5041 - A change has been made to IPsec settings. An Authentication Set was modified","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5041","Windows"],"keywords":["5041","event 5041","event id 5041","A change has been made to IPsec settings. An Authentication Set was modified","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5041"],"errorCode":"","eventId":"5041","severity":"Medium","summary":"Windows Security event 5041 records: A change has been made to IPsec settings. An Authentication Set was modified","rootCause":"The event records a state-changing operation: A change has been made to IPsec settings. An Authentication Set was modified It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5041.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A change has been made to IPsec settings. An Authentication Set was modified\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5041\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5041} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5041","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5041","Event ID 5041","A change has been made to IPsec settings. An Authentication Set was modified"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69578,"title":"Windows Security Event 5042 - A change has been made to IPsec settings. An Authentication Set was deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5042","Windows"],"keywords":["5042","event 5042","event id 5042","A change has been made to IPsec settings. An Authentication Set was deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5042"],"errorCode":"","eventId":"5042","severity":"High","summary":"Windows Security event 5042 records: A change has been made to IPsec settings. An Authentication Set was deleted","rootCause":"The event records a state-changing operation: A change has been made to IPsec settings. An Authentication Set was deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5042.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A change has been made to IPsec settings. An Authentication Set was deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5042\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5042} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5042","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5042","Event ID 5042","A change has been made to IPsec settings. An Authentication Set was deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69579,"title":"Windows Security Event 5043 - A change has been made to IPsec settings. A Connection Security Rule was added","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5043","Windows"],"keywords":["5043","event 5043","event id 5043","A change has been made to IPsec settings. A Connection Security Rule was added","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5043"],"errorCode":"","eventId":"5043","severity":"Medium","summary":"Windows Security event 5043 records: A change has been made to IPsec settings. A Connection Security Rule was added","rootCause":"The event records a state-changing operation: A change has been made to IPsec settings. A Connection Security Rule was added It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5043.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A change has been made to IPsec settings. A Connection Security Rule was added\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5043\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5043} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5043","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5043","Event ID 5043","A change has been made to IPsec settings. A Connection Security Rule was added"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69580,"title":"Windows Security Event 5044 - A change has been made to IPsec settings. A Connection Security Rule was modified","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5044","Windows"],"keywords":["5044","event 5044","event id 5044","A change has been made to IPsec settings. A Connection Security Rule was modified","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5044"],"errorCode":"","eventId":"5044","severity":"Medium","summary":"Windows Security event 5044 records: A change has been made to IPsec settings. A Connection Security Rule was modified","rootCause":"The event records a state-changing operation: A change has been made to IPsec settings. A Connection Security Rule was modified It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5044.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A change has been made to IPsec settings. A Connection Security Rule was modified\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5044\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5044} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5044","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5044","Event ID 5044","A change has been made to IPsec settings. A Connection Security Rule was modified"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69581,"title":"Windows Security Event 5045 - A change has been made to IPsec settings. A Connection Security Rule was deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5045","Windows"],"keywords":["5045","event 5045","event id 5045","A change has been made to IPsec settings. A Connection Security Rule was deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5045"],"errorCode":"","eventId":"5045","severity":"High","summary":"Windows Security event 5045 records: A change has been made to IPsec settings. A Connection Security Rule was deleted","rootCause":"The event records a state-changing operation: A change has been made to IPsec settings. A Connection Security Rule was deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5045.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A change has been made to IPsec settings. A Connection Security Rule was deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5045\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5045} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5045","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5045","Event ID 5045","A change has been made to IPsec settings. A Connection Security Rule was deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69582,"title":"Windows Security Event 5046 - A change has been made to IPsec settings. A Crypto Set was added","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5046","Windows"],"keywords":["5046","event 5046","event id 5046","A change has been made to IPsec settings. A Crypto Set was added","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5046"],"errorCode":"","eventId":"5046","severity":"Medium","summary":"Windows Security event 5046 records: A change has been made to IPsec settings. A Crypto Set was added","rootCause":"The event records a state-changing operation: A change has been made to IPsec settings. A Crypto Set was added It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5046.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A change has been made to IPsec settings. A Crypto Set was added\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5046\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5046} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5046","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5046","Event ID 5046","A change has been made to IPsec settings. A Crypto Set was added"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69583,"title":"Windows Security Event 5047 - A change has been made to IPsec settings. A Crypto Set was modified","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5047","Windows"],"keywords":["5047","event 5047","event id 5047","A change has been made to IPsec settings. A Crypto Set was modified","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5047"],"errorCode":"","eventId":"5047","severity":"Medium","summary":"Windows Security event 5047 records: A change has been made to IPsec settings. A Crypto Set was modified","rootCause":"The event records a state-changing operation: A change has been made to IPsec settings. A Crypto Set was modified It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5047.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A change has been made to IPsec settings. A Crypto Set was modified\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5047\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5047} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5047","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5047","Event ID 5047","A change has been made to IPsec settings. A Crypto Set was modified"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69584,"title":"Windows Security Event 5048 - A change has been made to IPsec settings. A Crypto Set was deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5048","Windows"],"keywords":["5048","event 5048","event id 5048","A change has been made to IPsec settings. A Crypto Set was deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5048"],"errorCode":"","eventId":"5048","severity":"High","summary":"Windows Security event 5048 records: A change has been made to IPsec settings. A Crypto Set was deleted","rootCause":"The event records a state-changing operation: A change has been made to IPsec settings. A Crypto Set was deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5048.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A change has been made to IPsec settings. A Crypto Set was deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5048\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5048} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5048","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5048","Event ID 5048","A change has been made to IPsec settings. A Crypto Set was deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69585,"title":"Windows Security Event 5049 - An IPsec Security Association was deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5049","Windows"],"keywords":["5049","event 5049","event id 5049","An IPsec Security Association was deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5049"],"errorCode":"","eventId":"5049","severity":"High","summary":"Windows Security event 5049 records: An IPsec Security Association was deleted","rootCause":"The event records a state-changing operation: An IPsec Security Association was deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5049.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An IPsec Security Association was deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5049\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5049} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5049","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5049","Event ID 5049","An IPsec Security Association was deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69586,"title":"Windows Security Event 5050 - An attempt to programmatically disable the Windows Firewall using a call to INetFwProfile.FirewallEnabled(FALSE","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5050","Windows"],"keywords":["5050","event 5050","event id 5050","An attempt to programmatically disable the Windows Firewall using a call to INetFwProfile.FirewallEnabled(FALSE","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5050"],"errorCode":"","eventId":"5050","severity":"Medium","summary":"Windows Security event 5050 records: An attempt to programmatically disable the Windows Firewall using a call to INetFwProfile.FirewallEnabled(FALSE","rootCause":"The event records a state-changing operation: An attempt to programmatically disable the Windows Firewall using a call to INetFwProfile.FirewallEnabled(FALSE It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5050.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An attempt to programmatically disable the Windows Firewall using a call to INetFwProfile.FirewallEnabled(FALSE\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5050\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5050} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5050","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5050","Event ID 5050","An attempt to programmatically disable the Windows Firewall using a call to INetFwProfile.FirewallEnabled(FALSE"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69587,"title":"Windows Security Event 5051 - A file was virtualized","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5051","Windows"],"keywords":["5051","event 5051","event id 5051","A file was virtualized","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5051"],"errorCode":"","eventId":"5051","severity":"Low","summary":"Windows Security event 5051 records: A file was virtualized","rootCause":"The configured audit source recorded this activity: A file was virtualized It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5051.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A file was virtualized\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5051\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5051} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5051","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5051","Event ID 5051","A file was virtualized"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69588,"title":"Windows Security Event 5056 - A cryptographic self test was performed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5056","Windows"],"keywords":["5056","event 5056","event id 5056","A cryptographic self test was performed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5056"],"errorCode":"","eventId":"5056","severity":"Low","summary":"Windows Security event 5056 records: A cryptographic self test was performed","rootCause":"The configured audit source recorded this activity: A cryptographic self test was performed It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5056.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A cryptographic self test was performed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5056\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5056} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5056","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5056","Event ID 5056","A cryptographic self test was performed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69589,"title":"Windows Security Event 5057 - A cryptographic primitive operation failed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5057","Windows"],"keywords":["5057","event 5057","event id 5057","A cryptographic primitive operation failed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5057"],"errorCode":"","eventId":"5057","severity":"High","summary":"Windows Security event 5057 records: A cryptographic primitive operation failed","rootCause":"The audited operation reported a failure: A cryptographic primitive operation failed The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5057.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A cryptographic primitive operation failed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5057\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5057} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5057","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5057","Event ID 5057","A cryptographic primitive operation failed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69590,"title":"Windows Security Event 5058 - Key file operation","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5058","Windows"],"keywords":["5058","event 5058","event id 5058","Key file operation","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5058"],"errorCode":"","eventId":"5058","severity":"Low","summary":"Windows Security event 5058 records: Key file operation","rootCause":"The configured audit source recorded this activity: Key file operation It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5058.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Key file operation\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5058\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5058} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5058","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5058","Event ID 5058","Key file operation"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69591,"title":"Windows Security Event 5059 - Key migration operation","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5059","Windows"],"keywords":["5059","event 5059","event id 5059","Key migration operation","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5059"],"errorCode":"","eventId":"5059","severity":"Low","summary":"Windows Security event 5059 records: Key migration operation","rootCause":"The configured audit source recorded this activity: Key migration operation It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5059.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Key migration operation\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5059\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5059} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5059","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5059","Event ID 5059","Key migration operation"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69592,"title":"Windows Security Event 5060 - Verification operation failed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5060","Windows"],"keywords":["5060","event 5060","event id 5060","Verification operation failed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5060"],"errorCode":"","eventId":"5060","severity":"High","summary":"Windows Security event 5060 records: Verification operation failed","rootCause":"The audited operation reported a failure: Verification operation failed The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5060.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Verification operation failed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5060\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5060} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5060","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5060","Event ID 5060","Verification operation failed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69593,"title":"Windows Security Event 5061 - Cryptographic operation","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5061","Windows"],"keywords":["5061","event 5061","event id 5061","Cryptographic operation","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5061"],"errorCode":"","eventId":"5061","severity":"Low","summary":"Windows Security event 5061 records: Cryptographic operation","rootCause":"The configured audit source recorded this activity: Cryptographic operation It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5061.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Cryptographic operation\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5061\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5061} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5061","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5061","Event ID 5061","Cryptographic operation"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69594,"title":"Windows Security Event 5062 - A kernel-mode cryptographic self test was performed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5062","Windows"],"keywords":["5062","event 5062","event id 5062","A kernel-mode cryptographic self test was performed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5062"],"errorCode":"","eventId":"5062","severity":"Low","summary":"Windows Security event 5062 records: A kernel-mode cryptographic self test was performed","rootCause":"The configured audit source recorded this activity: A kernel-mode cryptographic self test was performed It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5062.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A kernel-mode cryptographic self test was performed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5062\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5062} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5062","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5062","Event ID 5062","A kernel-mode cryptographic self test was performed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69595,"title":"Windows Security Event 5063 - A cryptographic provider operation was attempted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5063","Windows"],"keywords":["5063","event 5063","event id 5063","A cryptographic provider operation was attempted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5063"],"errorCode":"","eventId":"5063","severity":"Low","summary":"Windows Security event 5063 records: A cryptographic provider operation was attempted","rootCause":"The configured audit source recorded this activity: A cryptographic provider operation was attempted It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5063.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A cryptographic provider operation was attempted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5063\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5063} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5063","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5063","Event ID 5063","A cryptographic provider operation was attempted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69596,"title":"Windows Security Event 5064 - A cryptographic context operation was attempted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5064","Windows"],"keywords":["5064","event 5064","event id 5064","A cryptographic context operation was attempted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5064"],"errorCode":"","eventId":"5064","severity":"Low","summary":"Windows Security event 5064 records: A cryptographic context operation was attempted","rootCause":"The configured audit source recorded this activity: A cryptographic context operation was attempted It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5064.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A cryptographic context operation was attempted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5064\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5064} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5064","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5064","Event ID 5064","A cryptographic context operation was attempted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69597,"title":"Windows Security Event 5065 - A cryptographic context modification was attempted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5065","Windows"],"keywords":["5065","event 5065","event id 5065","A cryptographic context modification was attempted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5065"],"errorCode":"","eventId":"5065","severity":"Low","summary":"Windows Security event 5065 records: A cryptographic context modification was attempted","rootCause":"The configured audit source recorded this activity: A cryptographic context modification was attempted It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5065.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A cryptographic context modification was attempted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5065\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5065} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5065","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5065","Event ID 5065","A cryptographic context modification was attempted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69598,"title":"Windows Security Event 5066 - A cryptographic function operation was attempted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5066","Windows"],"keywords":["5066","event 5066","event id 5066","A cryptographic function operation was attempted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5066"],"errorCode":"","eventId":"5066","severity":"Low","summary":"Windows Security event 5066 records: A cryptographic function operation was attempted","rootCause":"The configured audit source recorded this activity: A cryptographic function operation was attempted It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5066.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A cryptographic function operation was attempted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5066\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5066} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5066","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5066","Event ID 5066","A cryptographic function operation was attempted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69599,"title":"Windows Security Event 5067 - A cryptographic function modification was attempted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5067","Windows"],"keywords":["5067","event 5067","event id 5067","A cryptographic function modification was attempted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5067"],"errorCode":"","eventId":"5067","severity":"Low","summary":"Windows Security event 5067 records: A cryptographic function modification was attempted","rootCause":"The configured audit source recorded this activity: A cryptographic function modification was attempted It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5067.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A cryptographic function modification was attempted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5067\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5067} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5067","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5067","Event ID 5067","A cryptographic function modification was attempted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69600,"title":"Windows Security Event 5068 - A cryptographic function provider operation was attempted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5068","Windows"],"keywords":["5068","event 5068","event id 5068","A cryptographic function provider operation was attempted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5068"],"errorCode":"","eventId":"5068","severity":"Low","summary":"Windows Security event 5068 records: A cryptographic function provider operation was attempted","rootCause":"The configured audit source recorded this activity: A cryptographic function provider operation was attempted It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5068.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A cryptographic function provider operation was attempted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5068\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5068} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5068","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5068","Event ID 5068","A cryptographic function provider operation was attempted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69601,"title":"Windows Security Event 5069 - A cryptographic function property operation was attempted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5069","Windows"],"keywords":["5069","event 5069","event id 5069","A cryptographic function property operation was attempted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5069"],"errorCode":"","eventId":"5069","severity":"Low","summary":"Windows Security event 5069 records: A cryptographic function property operation was attempted","rootCause":"The configured audit source recorded this activity: A cryptographic function property operation was attempted It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5069.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A cryptographic function property operation was attempted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5069\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5069} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5069","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5069","Event ID 5069","A cryptographic function property operation was attempted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69602,"title":"Windows Security Event 5070 - A cryptographic function property operation was attempted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5070","Windows"],"keywords":["5070","event 5070","event id 5070","A cryptographic function property operation was attempted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5070"],"errorCode":"","eventId":"5070","severity":"Low","summary":"Windows Security event 5070 records: A cryptographic function property operation was attempted","rootCause":"The configured audit source recorded this activity: A cryptographic function property operation was attempted It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5070.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A cryptographic function property operation was attempted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5070\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5070} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5070","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5070","Event ID 5070","A cryptographic function property operation was attempted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69603,"title":"Windows Security Event 5071 - Key access denied by Microsoft key distribution service","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5071","Windows"],"keywords":["5071","event 5071","event id 5071","Key access denied by Microsoft key distribution service","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5071"],"errorCode":"","eventId":"5071","severity":"High","summary":"Windows Security event 5071 records: Key access denied by Microsoft key distribution service","rootCause":"The audited operation reported a failure: Key access denied by Microsoft key distribution service The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5071.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Key access denied by Microsoft key distribution service\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5071\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5071} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5071","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5071","Event ID 5071","Key access denied by Microsoft key distribution service"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69604,"title":"Windows Security Event 5120 - OCSP Responder Service Started","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5120","Windows"],"keywords":["5120","event 5120","event id 5120","OCSP Responder Service Started","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5120"],"errorCode":"","eventId":"5120","severity":"Low","summary":"Windows Security event 5120 records: OCSP Responder Service Started","rootCause":"The configured audit source recorded this activity: OCSP Responder Service Started It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5120.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: OCSP Responder Service Started\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5120\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5120} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5120","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5120","Event ID 5120","OCSP Responder Service Started"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69605,"title":"Windows Security Event 5121 - OCSP Responder Service Stopped","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5121","Windows"],"keywords":["5121","event 5121","event id 5121","OCSP Responder Service Stopped","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5121"],"errorCode":"","eventId":"5121","severity":"High","summary":"Windows Security event 5121 records: OCSP Responder Service Stopped","rootCause":"The configured audit source recorded this activity: OCSP Responder Service Stopped It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5121.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: OCSP Responder Service Stopped\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5121\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5121} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5121","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5121","Event ID 5121","OCSP Responder Service Stopped"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69606,"title":"Windows Security Event 5122 - A Configuration entry changed in the OCSP Responder Service","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5122","Windows"],"keywords":["5122","event 5122","event id 5122","A Configuration entry changed in the OCSP Responder Service","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5122"],"errorCode":"","eventId":"5122","severity":"Medium","summary":"Windows Security event 5122 records: A Configuration entry changed in the OCSP Responder Service","rootCause":"The event records a state-changing operation: A Configuration entry changed in the OCSP Responder Service It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5122.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A Configuration entry changed in the OCSP Responder Service\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5122\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5122} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5122","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5122","Event ID 5122","A Configuration entry changed in the OCSP Responder Service"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69607,"title":"Windows Security Event 5123 - A configuration entry changed in the OCSP Responder Service","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5123","Windows"],"keywords":["5123","event 5123","event id 5123","A configuration entry changed in the OCSP Responder Service","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5123"],"errorCode":"","eventId":"5123","severity":"Medium","summary":"Windows Security event 5123 records: A configuration entry changed in the OCSP Responder Service","rootCause":"The event records a state-changing operation: A configuration entry changed in the OCSP Responder Service It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5123.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A configuration entry changed in the OCSP Responder Service\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5123\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5123} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5123","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5123","Event ID 5123","A configuration entry changed in the OCSP Responder Service"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69608,"title":"Windows Security Event 5124 - A security setting was updated on OCSP Responder Service","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5124","Windows"],"keywords":["5124","event 5124","event id 5124","A security setting was updated on OCSP Responder Service","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5124"],"errorCode":"","eventId":"5124","severity":"Low","summary":"Windows Security event 5124 records: A security setting was updated on OCSP Responder Service","rootCause":"The configured audit source recorded this activity: A security setting was updated on OCSP Responder Service It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5124.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A security setting was updated on OCSP Responder Service\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5124\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5124} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5124","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5124","Event ID 5124","A security setting was updated on OCSP Responder Service"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69609,"title":"Windows Security Event 5125 - A request was submitted to OCSP Responder Service","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5125","Windows"],"keywords":["5125","event 5125","event id 5125","A request was submitted to OCSP Responder Service","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5125"],"errorCode":"","eventId":"5125","severity":"Low","summary":"Windows Security event 5125 records: A request was submitted to OCSP Responder Service","rootCause":"The configured audit source recorded this activity: A request was submitted to OCSP Responder Service It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5125.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A request was submitted to OCSP Responder Service\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5125\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5125} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5125","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5125","Event ID 5125","A request was submitted to OCSP Responder Service"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69610,"title":"Windows Security Event 5126 - Signing Certificate was automatically updated by the OCSP Responder Service","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5126","Windows"],"keywords":["5126","event 5126","event id 5126","Signing Certificate was automatically updated by the OCSP Responder Service","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5126"],"errorCode":"","eventId":"5126","severity":"Medium","summary":"Windows Security event 5126 records: Signing Certificate was automatically updated by the OCSP Responder Service","rootCause":"The configured audit source recorded this activity: Signing Certificate was automatically updated by the OCSP Responder Service It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5126.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Signing Certificate was automatically updated by the OCSP Responder Service\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5126\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5126} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5126","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5126","Event ID 5126","Signing Certificate was automatically updated by the OCSP Responder Service"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69611,"title":"Windows Security Event 5127 - The OCSP Revocation Provider successfully updated the revocation information","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5127","Windows"],"keywords":["5127","event 5127","event id 5127","The OCSP Revocation Provider successfully updated the revocation information","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5127"],"errorCode":"","eventId":"5127","severity":"Low","summary":"Windows Security event 5127 records: The OCSP Revocation Provider successfully updated the revocation information","rootCause":"The configured audit source recorded this activity: The OCSP Revocation Provider successfully updated the revocation information It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5127.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The OCSP Revocation Provider successfully updated the revocation information\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5127\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5127} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5127","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5127","Event ID 5127","The OCSP Revocation Provider successfully updated the revocation information"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69612,"title":"Windows Security Event 5136 - A directory service object was modified","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5136","Windows"],"keywords":["5136","event 5136","event id 5136","A directory service object was modified","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5136"],"errorCode":"","eventId":"5136","severity":"Medium","summary":"Windows Security event 5136 records: A directory service object was modified","rootCause":"The event records a state-changing operation: A directory service object was modified It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5136.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A directory service object was modified\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5136\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5136} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5136","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5136","Event ID 5136","A directory service object was modified"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69613,"title":"Windows Security Event 5137 - A directory service object was created","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5137","Windows"],"keywords":["5137","event 5137","event id 5137","A directory service object was created","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5137"],"errorCode":"","eventId":"5137","severity":"Medium","summary":"Windows Security event 5137 records: A directory service object was created","rootCause":"The event records a state-changing operation: A directory service object was created It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5137.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A directory service object was created\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5137\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5137} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5137","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5137","Event ID 5137","A directory service object was created"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69614,"title":"Windows Security Event 5138 - A directory service object was undeleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5138","Windows"],"keywords":["5138","event 5138","event id 5138","A directory service object was undeleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5138"],"errorCode":"","eventId":"5138","severity":"High","summary":"Windows Security event 5138 records: A directory service object was undeleted","rootCause":"The event records a state-changing operation: A directory service object was undeleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5138.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A directory service object was undeleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5138\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5138} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5138","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5138","Event ID 5138","A directory service object was undeleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69615,"title":"Windows Security Event 5139 - A directory service object was moved","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5139","Windows"],"keywords":["5139","event 5139","event id 5139","A directory service object was moved","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5139"],"errorCode":"","eventId":"5139","severity":"Low","summary":"Windows Security event 5139 records: A directory service object was moved","rootCause":"The configured audit source recorded this activity: A directory service object was moved It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5139.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A directory service object was moved\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5139\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5139} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5139","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5139","Event ID 5139","A directory service object was moved"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69616,"title":"Windows Security Event 5140 - A network share object was accessed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5140","Windows"],"keywords":["5140","event 5140","event id 5140","A network share object was accessed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5140"],"errorCode":"","eventId":"5140","severity":"Low","summary":"Windows Security event 5140 records: A network share object was accessed","rootCause":"The configured audit source recorded this activity: A network share object was accessed It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5140.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A network share object was accessed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5140\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5140} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5140","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5140","Event ID 5140","A network share object was accessed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69617,"title":"Windows Security Event 5141 - A directory service object was deleted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5141","Windows"],"keywords":["5141","event 5141","event id 5141","A directory service object was deleted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5141"],"errorCode":"","eventId":"5141","severity":"High","summary":"Windows Security event 5141 records: A directory service object was deleted","rootCause":"The event records a state-changing operation: A directory service object was deleted It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5141.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A directory service object was deleted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5141\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5141} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5141","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5141","Event ID 5141","A directory service object was deleted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69618,"title":"Windows Security Event 5142 - A network share object was added.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5142","Windows"],"keywords":["5142","event 5142","event id 5142","A network share object was added.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5142"],"errorCode":"","eventId":"5142","severity":"Medium","summary":"Windows Security event 5142 records: A network share object was added.","rootCause":"The event records a state-changing operation: A network share object was added. It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5142.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A network share object was added.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5142\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5142} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5142","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5142","Event ID 5142","A network share object was added."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69619,"title":"Windows Security Event 5143 - A network share object was modified","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5143","Windows"],"keywords":["5143","event 5143","event id 5143","A network share object was modified","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5143"],"errorCode":"","eventId":"5143","severity":"Medium","summary":"Windows Security event 5143 records: A network share object was modified","rootCause":"The event records a state-changing operation: A network share object was modified It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5143.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A network share object was modified\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5143\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5143} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5143","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5143","Event ID 5143","A network share object was modified"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69620,"title":"Windows Security Event 5144 - A network share object was deleted.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5144","Windows"],"keywords":["5144","event 5144","event id 5144","A network share object was deleted.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5144"],"errorCode":"","eventId":"5144","severity":"High","summary":"Windows Security event 5144 records: A network share object was deleted.","rootCause":"The event records a state-changing operation: A network share object was deleted. It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5144.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A network share object was deleted.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5144\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5144} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5144","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5144","Event ID 5144","A network share object was deleted."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69621,"title":"Windows Security Event 5145 - A network share object was checked to see whether client can be granted desired access","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5145","Windows"],"keywords":["5145","event 5145","event id 5145","A network share object was checked to see whether client can be granted desired access","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5145"],"errorCode":"","eventId":"5145","severity":"Low","summary":"Windows Security event 5145 records: A network share object was checked to see whether client can be granted desired access","rootCause":"The configured audit source recorded this activity: A network share object was checked to see whether client can be granted desired access It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5145.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A network share object was checked to see whether client can be granted desired access\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5145\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5145} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5145","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5145","Event ID 5145","A network share object was checked to see whether client can be granted desired access"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69622,"title":"Windows Security Event 5146 - The Windows Filtering Platform has blocked a packet","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5146","Windows"],"keywords":["5146","event 5146","event id 5146","The Windows Filtering Platform has blocked a packet","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5146"],"errorCode":"","eventId":"5146","severity":"High","summary":"Windows Security event 5146 records: The Windows Filtering Platform has blocked a packet","rootCause":"The audited operation reported a failure: The Windows Filtering Platform has blocked a packet The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5146.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Filtering Platform has blocked a packet\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5146\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5146} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5146","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5146","Event ID 5146","The Windows Filtering Platform has blocked a packet"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69623,"title":"Windows Security Event 5147 - A more restrictive Windows Filtering Platform filter has blocked a packet","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5147","Windows"],"keywords":["5147","event 5147","event id 5147","A more restrictive Windows Filtering Platform filter has blocked a packet","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5147"],"errorCode":"","eventId":"5147","severity":"High","summary":"Windows Security event 5147 records: A more restrictive Windows Filtering Platform filter has blocked a packet","rootCause":"The audited operation reported a failure: A more restrictive Windows Filtering Platform filter has blocked a packet The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5147.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A more restrictive Windows Filtering Platform filter has blocked a packet\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5147\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5147} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5147","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5147","Event ID 5147","A more restrictive Windows Filtering Platform filter has blocked a packet"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69624,"title":"Windows Security Event 5148 - The Windows Filtering Platform has detected a DoS attack and entered a defensive mode; packets associated with this attack will be discarded.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5148","Windows"],"keywords":["5148","event 5148","event id 5148","The Windows Filtering Platform has detected a DoS attack and entered a defensive mode; packets associated with this attack will be discarded.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5148"],"errorCode":"","eventId":"5148","severity":"Low","summary":"Windows Security event 5148 records: The Windows Filtering Platform has detected a DoS attack and entered a defensive mode; packets associated with this attack will be discarded.","rootCause":"The configured audit source recorded this activity: The Windows Filtering Platform has detected a DoS attack and entered a defensive mode; packets associated with this attack will be discarded. It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5148.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Filtering Platform has detected a DoS attack and entered a defensive mode; packets associated with this attack will be discarded.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5148\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5148} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5148","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5148","Event ID 5148","The Windows Filtering Platform has detected a DoS attack and entered a defensive mode; packets associated with this attack will be discarded."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69625,"title":"Windows Security Event 5149 - The DoS attack has subsided and normal processing is being resumed.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5149","Windows"],"keywords":["5149","event 5149","event id 5149","The DoS attack has subsided and normal processing is being resumed.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5149"],"errorCode":"","eventId":"5149","severity":"Low","summary":"Windows Security event 5149 records: The DoS attack has subsided and normal processing is being resumed.","rootCause":"The configured audit source recorded this activity: The DoS attack has subsided and normal processing is being resumed. It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5149.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The DoS attack has subsided and normal processing is being resumed.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5149\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5149} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5149","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5149","Event ID 5149","The DoS attack has subsided and normal processing is being resumed."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69626,"title":"Windows Security Event 5150 - The Windows Filtering Platform has blocked a packet.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5150","Windows"],"keywords":["5150","event 5150","event id 5150","The Windows Filtering Platform has blocked a packet.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5150"],"errorCode":"","eventId":"5150","severity":"High","summary":"Windows Security event 5150 records: The Windows Filtering Platform has blocked a packet.","rootCause":"The audited operation reported a failure: The Windows Filtering Platform has blocked a packet. The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5150.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Filtering Platform has blocked a packet.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5150\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5150} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5150","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5150","Event ID 5150","The Windows Filtering Platform has blocked a packet."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69627,"title":"Windows Security Event 5151 - A more restrictive Windows Filtering Platform filter has blocked a packet.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5151","Windows"],"keywords":["5151","event 5151","event id 5151","A more restrictive Windows Filtering Platform filter has blocked a packet.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5151"],"errorCode":"","eventId":"5151","severity":"High","summary":"Windows Security event 5151 records: A more restrictive Windows Filtering Platform filter has blocked a packet.","rootCause":"The audited operation reported a failure: A more restrictive Windows Filtering Platform filter has blocked a packet. The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5151.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A more restrictive Windows Filtering Platform filter has blocked a packet.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5151\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5151} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5151","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5151","Event ID 5151","A more restrictive Windows Filtering Platform filter has blocked a packet."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69628,"title":"Windows Security Event 5152 - The Windows Filtering Platform blocked a packet","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5152","Windows"],"keywords":["5152","event 5152","event id 5152","The Windows Filtering Platform blocked a packet","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5152"],"errorCode":"","eventId":"5152","severity":"High","summary":"Windows Security event 5152 records: The Windows Filtering Platform blocked a packet","rootCause":"The audited operation reported a failure: The Windows Filtering Platform blocked a packet The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5152.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Filtering Platform blocked a packet\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5152\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5152} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5152","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5152","Event ID 5152","The Windows Filtering Platform blocked a packet"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69629,"title":"Windows Security Event 5153 - A more restrictive Windows Filtering Platform filter has blocked a packet","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5153","Windows"],"keywords":["5153","event 5153","event id 5153","A more restrictive Windows Filtering Platform filter has blocked a packet","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5153"],"errorCode":"","eventId":"5153","severity":"High","summary":"Windows Security event 5153 records: A more restrictive Windows Filtering Platform filter has blocked a packet","rootCause":"The audited operation reported a failure: A more restrictive Windows Filtering Platform filter has blocked a packet The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5153.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A more restrictive Windows Filtering Platform filter has blocked a packet\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5153\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5153} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5153","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5153","Event ID 5153","A more restrictive Windows Filtering Platform filter has blocked a packet"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69630,"title":"Windows Security Event 5154 - The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5154","Windows"],"keywords":["5154","event 5154","event id 5154","The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5154"],"errorCode":"","eventId":"5154","severity":"Low","summary":"Windows Security event 5154 records: The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections","rootCause":"The configured audit source recorded this activity: The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5154.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5154\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5154} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5154","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5154","Event ID 5154","The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69631,"title":"Windows Security Event 5155 - The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5155","Windows"],"keywords":["5155","event 5155","event id 5155","The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5155"],"errorCode":"","eventId":"5155","severity":"High","summary":"Windows Security event 5155 records: The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections","rootCause":"The audited operation reported a failure: The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5155.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5155\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5155} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5155","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5155","Event ID 5155","The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69632,"title":"Windows Security Event 5156 - The Windows Filtering Platform has allowed a connection","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5156","Windows"],"keywords":["5156","event 5156","event id 5156","The Windows Filtering Platform has allowed a connection","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5156"],"errorCode":"","eventId":"5156","severity":"Low","summary":"Windows Security event 5156 records: The Windows Filtering Platform has allowed a connection","rootCause":"The configured audit source recorded this activity: The Windows Filtering Platform has allowed a connection It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5156.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Filtering Platform has allowed a connection\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5156\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5156} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5156","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5156","Event ID 5156","The Windows Filtering Platform has allowed a connection"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69633,"title":"Windows Security Event 5157 - The Windows Filtering Platform has blocked a connection","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5157","Windows"],"keywords":["5157","event 5157","event id 5157","The Windows Filtering Platform has blocked a connection","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5157"],"errorCode":"","eventId":"5157","severity":"High","summary":"Windows Security event 5157 records: The Windows Filtering Platform has blocked a connection","rootCause":"The audited operation reported a failure: The Windows Filtering Platform has blocked a connection The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5157.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Filtering Platform has blocked a connection\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5157\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5157} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5157","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5157","Event ID 5157","The Windows Filtering Platform has blocked a connection"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69634,"title":"Windows Security Event 5158 - The Windows Filtering Platform has permitted a bind to a local port","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5158","Windows"],"keywords":["5158","event 5158","event id 5158","The Windows Filtering Platform has permitted a bind to a local port","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5158"],"errorCode":"","eventId":"5158","severity":"Low","summary":"Windows Security event 5158 records: The Windows Filtering Platform has permitted a bind to a local port","rootCause":"The configured audit source recorded this activity: The Windows Filtering Platform has permitted a bind to a local port It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5158.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Filtering Platform has permitted a bind to a local port\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5158\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5158} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5158","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5158","Event ID 5158","The Windows Filtering Platform has permitted a bind to a local port"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69635,"title":"Windows Security Event 5159 - The Windows Filtering Platform has blocked a bind to a local port","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5159","Windows"],"keywords":["5159","event 5159","event id 5159","The Windows Filtering Platform has blocked a bind to a local port","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5159"],"errorCode":"","eventId":"5159","severity":"High","summary":"Windows Security event 5159 records: The Windows Filtering Platform has blocked a bind to a local port","rootCause":"The audited operation reported a failure: The Windows Filtering Platform has blocked a bind to a local port The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5159.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The Windows Filtering Platform has blocked a bind to a local port\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5159\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5159} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5159","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5159","Event ID 5159","The Windows Filtering Platform has blocked a bind to a local port"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69636,"title":"Windows Security Event 5168 - Spn check for SMB/SMB2 fails.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5168","Windows"],"keywords":["5168","event 5168","event id 5168","Spn check for SMB/SMB2 fails.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5168"],"errorCode":"","eventId":"5168","severity":"Low","summary":"Windows Security event 5168 records: Spn check for SMB/SMB2 fails.","rootCause":"The configured audit source recorded this activity: Spn check for SMB/SMB2 fails. It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5168.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Spn check for SMB/SMB2 fails.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5168\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5168} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5168","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5168","Event ID 5168","Spn check for SMB/SMB2 fails."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69637,"title":"Windows Security Event 5169 - A directory service object was modified","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5169","Windows"],"keywords":["5169","event 5169","event id 5169","A directory service object was modified","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5169"],"errorCode":"","eventId":"5169","severity":"Medium","summary":"Windows Security event 5169 records: A directory service object was modified","rootCause":"The event records a state-changing operation: A directory service object was modified It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5169.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A directory service object was modified\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5169\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5169} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5169","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5169","Event ID 5169","A directory service object was modified"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69638,"title":"Windows Security Event 5170 - A directory service object was modified during a background cleanup task","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5170","Windows"],"keywords":["5170","event 5170","event id 5170","A directory service object was modified during a background cleanup task","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5170"],"errorCode":"","eventId":"5170","severity":"Medium","summary":"Windows Security event 5170 records: A directory service object was modified during a background cleanup task","rootCause":"The event records a state-changing operation: A directory service object was modified during a background cleanup task It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5170.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A directory service object was modified during a background cleanup task\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5170\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5170} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5170","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5170","Event ID 5170","A directory service object was modified during a background cleanup task"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69639,"title":"Windows Security Event 5376 - Credential Manager credentials were backed up","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5376","Windows"],"keywords":["5376","event 5376","event id 5376","Credential Manager credentials were backed up","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5376"],"errorCode":"","eventId":"5376","severity":"Low","summary":"Windows Security event 5376 records: Credential Manager credentials were backed up","rootCause":"The configured audit source recorded this activity: Credential Manager credentials were backed up It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5376.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Credential Manager credentials were backed up\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5376\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5376} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5376","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5376","Event ID 5376","Credential Manager credentials were backed up"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69640,"title":"Windows Security Event 5377 - Credential Manager credentials were restored from a backup","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5377","Windows"],"keywords":["5377","event 5377","event id 5377","Credential Manager credentials were restored from a backup","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5377"],"errorCode":"","eventId":"5377","severity":"Low","summary":"Windows Security event 5377 records: Credential Manager credentials were restored from a backup","rootCause":"The configured audit source recorded this activity: Credential Manager credentials were restored from a backup It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5377.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Credential Manager credentials were restored from a backup\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5377\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5377} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5377","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5377","Event ID 5377","Credential Manager credentials were restored from a backup"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69641,"title":"Windows Security Event 5378 - The requested credentials delegation was disallowed by policy","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5378","Windows"],"keywords":["5378","event 5378","event id 5378","The requested credentials delegation was disallowed by policy","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5378"],"errorCode":"","eventId":"5378","severity":"Medium","summary":"Windows Security event 5378 records: The requested credentials delegation was disallowed by policy","rootCause":"The configured audit source recorded this activity: The requested credentials delegation was disallowed by policy It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5378.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The requested credentials delegation was disallowed by policy\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5378\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5378} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5378","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5378","Event ID 5378","The requested credentials delegation was disallowed by policy"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69642,"title":"Windows Security Event 5379 - Credential Manager credentials were read","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5379","Windows"],"keywords":["5379","event 5379","event id 5379","Credential Manager credentials were read","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5379"],"errorCode":"","eventId":"5379","severity":"Low","summary":"Windows Security event 5379 records: Credential Manager credentials were read","rootCause":"The configured audit source recorded this activity: Credential Manager credentials were read It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5379.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Credential Manager credentials were read\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5379\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5379} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5379","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5379","Event ID 5379","Credential Manager credentials were read"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69643,"title":"Windows Security Event 5380 - Vault Find Credential","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5380","Windows"],"keywords":["5380","event 5380","event id 5380","Vault Find Credential","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5380"],"errorCode":"","eventId":"5380","severity":"Low","summary":"Windows Security event 5380 records: Vault Find Credential","rootCause":"The configured audit source recorded this activity: Vault Find Credential It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5380.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Vault Find Credential\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5380\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5380} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5380","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5380","Event ID 5380","Vault Find Credential"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69644,"title":"Windows Security Event 5381 - Vault credentials were read","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5381","Windows"],"keywords":["5381","event 5381","event id 5381","Vault credentials were read","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5381"],"errorCode":"","eventId":"5381","severity":"Low","summary":"Windows Security event 5381 records: Vault credentials were read","rootCause":"The configured audit source recorded this activity: Vault credentials were read It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5381.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Vault credentials were read\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5381\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5381} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5381","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5381","Event ID 5381","Vault credentials were read"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69645,"title":"Windows Security Event 5382 - Vault credentials were read","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5382","Windows"],"keywords":["5382","event 5382","event id 5382","Vault credentials were read","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5382"],"errorCode":"","eventId":"5382","severity":"Low","summary":"Windows Security event 5382 records: Vault credentials were read","rootCause":"The configured audit source recorded this activity: Vault credentials were read It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5382.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Vault credentials were read\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5382\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5382} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5382","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5382","Event ID 5382","Vault credentials were read"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69646,"title":"Windows Security Event 5440 - The following callout was present when the Windows Filtering Platform Base Filtering Engine started","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5440","Windows"],"keywords":["5440","event 5440","event id 5440","The following callout was present when the Windows Filtering Platform Base Filtering Engine started","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5440"],"errorCode":"","eventId":"5440","severity":"Low","summary":"Windows Security event 5440 records: The following callout was present when the Windows Filtering Platform Base Filtering Engine started","rootCause":"The configured audit source recorded this activity: The following callout was present when the Windows Filtering Platform Base Filtering Engine started It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5440.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The following callout was present when the Windows Filtering Platform Base Filtering Engine started\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5440\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5440} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5440","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5440","Event ID 5440","The following callout was present when the Windows Filtering Platform Base Filtering Engine started"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69647,"title":"Windows Security Event 5441 - The following filter was present when the Windows Filtering Platform Base Filtering Engine started","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5441","Windows"],"keywords":["5441","event 5441","event id 5441","The following filter was present when the Windows Filtering Platform Base Filtering Engine started","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5441"],"errorCode":"","eventId":"5441","severity":"Low","summary":"Windows Security event 5441 records: The following filter was present when the Windows Filtering Platform Base Filtering Engine started","rootCause":"The configured audit source recorded this activity: The following filter was present when the Windows Filtering Platform Base Filtering Engine started It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5441.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The following filter was present when the Windows Filtering Platform Base Filtering Engine started\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5441\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5441} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5441","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5441","Event ID 5441","The following filter was present when the Windows Filtering Platform Base Filtering Engine started"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69648,"title":"Windows Security Event 5442 - The following provider was present when the Windows Filtering Platform Base Filtering Engine started","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5442","Windows"],"keywords":["5442","event 5442","event id 5442","The following provider was present when the Windows Filtering Platform Base Filtering Engine started","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5442"],"errorCode":"","eventId":"5442","severity":"Low","summary":"Windows Security event 5442 records: The following provider was present when the Windows Filtering Platform Base Filtering Engine started","rootCause":"The configured audit source recorded this activity: The following provider was present when the Windows Filtering Platform Base Filtering Engine started It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5442.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The following provider was present when the Windows Filtering Platform Base Filtering Engine started\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5442\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5442} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5442","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5442","Event ID 5442","The following provider was present when the Windows Filtering Platform Base Filtering Engine started"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69649,"title":"Windows Security Event 5443 - The following provider context was present when the Windows Filtering Platform Base Filtering Engine started","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5443","Windows"],"keywords":["5443","event 5443","event id 5443","The following provider context was present when the Windows Filtering Platform Base Filtering Engine started","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5443"],"errorCode":"","eventId":"5443","severity":"Low","summary":"Windows Security event 5443 records: The following provider context was present when the Windows Filtering Platform Base Filtering Engine started","rootCause":"The configured audit source recorded this activity: The following provider context was present when the Windows Filtering Platform Base Filtering Engine started It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5443.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The following provider context was present when the Windows Filtering Platform Base Filtering Engine started\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5443\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5443} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5443","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5443","Event ID 5443","The following provider context was present when the Windows Filtering Platform Base Filtering Engine started"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69650,"title":"Windows Security Event 5444 - The following sub-layer was present when the Windows Filtering Platform Base Filtering Engine started","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5444","Windows"],"keywords":["5444","event 5444","event id 5444","The following sub-layer was present when the Windows Filtering Platform Base Filtering Engine started","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5444"],"errorCode":"","eventId":"5444","severity":"Low","summary":"Windows Security event 5444 records: The following sub-layer was present when the Windows Filtering Platform Base Filtering Engine started","rootCause":"The configured audit source recorded this activity: The following sub-layer was present when the Windows Filtering Platform Base Filtering Engine started It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5444.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The following sub-layer was present when the Windows Filtering Platform Base Filtering Engine started\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5444\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5444} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5444","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5444","Event ID 5444","The following sub-layer was present when the Windows Filtering Platform Base Filtering Engine started"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69651,"title":"Windows Security Event 5446 - A Windows Filtering Platform callout has been changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5446","Windows"],"keywords":["5446","event 5446","event id 5446","A Windows Filtering Platform callout has been changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5446"],"errorCode":"","eventId":"5446","severity":"Medium","summary":"Windows Security event 5446 records: A Windows Filtering Platform callout has been changed","rootCause":"The event records a state-changing operation: A Windows Filtering Platform callout has been changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5446.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A Windows Filtering Platform callout has been changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5446\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5446} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5446","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5446","Event ID 5446","A Windows Filtering Platform callout has been changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69652,"title":"Windows Security Event 5447 - A Windows Filtering Platform filter has been changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5447","Windows"],"keywords":["5447","event 5447","event id 5447","A Windows Filtering Platform filter has been changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5447"],"errorCode":"","eventId":"5447","severity":"Medium","summary":"Windows Security event 5447 records: A Windows Filtering Platform filter has been changed","rootCause":"The event records a state-changing operation: A Windows Filtering Platform filter has been changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5447.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A Windows Filtering Platform filter has been changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5447\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5447} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5447","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5447","Event ID 5447","A Windows Filtering Platform filter has been changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69653,"title":"Windows Security Event 5448 - A Windows Filtering Platform provider has been changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5448","Windows"],"keywords":["5448","event 5448","event id 5448","A Windows Filtering Platform provider has been changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5448"],"errorCode":"","eventId":"5448","severity":"Medium","summary":"Windows Security event 5448 records: A Windows Filtering Platform provider has been changed","rootCause":"The event records a state-changing operation: A Windows Filtering Platform provider has been changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5448.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A Windows Filtering Platform provider has been changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5448\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5448} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5448","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5448","Event ID 5448","A Windows Filtering Platform provider has been changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69654,"title":"Windows Security Event 5449 - A Windows Filtering Platform provider context has been changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5449","Windows"],"keywords":["5449","event 5449","event id 5449","A Windows Filtering Platform provider context has been changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5449"],"errorCode":"","eventId":"5449","severity":"Medium","summary":"Windows Security event 5449 records: A Windows Filtering Platform provider context has been changed","rootCause":"The event records a state-changing operation: A Windows Filtering Platform provider context has been changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5449.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A Windows Filtering Platform provider context has been changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5449\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5449} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5449","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5449","Event ID 5449","A Windows Filtering Platform provider context has been changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69655,"title":"Windows Security Event 5450 - A Windows Filtering Platform sub-layer has been changed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5450","Windows"],"keywords":["5450","event 5450","event id 5450","A Windows Filtering Platform sub-layer has been changed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5450"],"errorCode":"","eventId":"5450","severity":"Medium","summary":"Windows Security event 5450 records: A Windows Filtering Platform sub-layer has been changed","rootCause":"The event records a state-changing operation: A Windows Filtering Platform sub-layer has been changed It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5450.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A Windows Filtering Platform sub-layer has been changed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5450\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5450} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5450","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5450","Event ID 5450","A Windows Filtering Platform sub-layer has been changed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69656,"title":"Windows Security Event 5451 - An IPsec Quick Mode security association was established","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5451","Windows"],"keywords":["5451","event 5451","event id 5451","An IPsec Quick Mode security association was established","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5451"],"errorCode":"","eventId":"5451","severity":"Medium","summary":"Windows Security event 5451 records: An IPsec Quick Mode security association was established","rootCause":"The configured audit source recorded this activity: An IPsec Quick Mode security association was established It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5451.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An IPsec Quick Mode security association was established\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5451\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5451} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5451","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5451","Event ID 5451","An IPsec Quick Mode security association was established"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69657,"title":"Windows Security Event 5452 - An IPsec Quick Mode security association ended","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5452","Windows"],"keywords":["5452","event 5452","event id 5452","An IPsec Quick Mode security association ended","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5452"],"errorCode":"","eventId":"5452","severity":"Medium","summary":"Windows Security event 5452 records: An IPsec Quick Mode security association ended","rootCause":"The configured audit source recorded this activity: An IPsec Quick Mode security association ended It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5452.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An IPsec Quick Mode security association ended\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5452\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5452} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5452","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5452","Event ID 5452","An IPsec Quick Mode security association ended"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69658,"title":"Windows Security Event 5453 - An IPsec negotiation with a remote computer failed because the IKE and AuthIP IPsec Keying Modules (IKEEXT) service is not started","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5453","Windows"],"keywords":["5453","event 5453","event id 5453","An IPsec negotiation with a remote computer failed because the IKE and AuthIP IPsec Keying Modules (IKEEXT) service is not started","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5453"],"errorCode":"","eventId":"5453","severity":"High","summary":"Windows Security event 5453 records: An IPsec negotiation with a remote computer failed because the IKE and AuthIP IPsec Keying Modules (IKEEXT) service is not started","rootCause":"The audited operation reported a failure: An IPsec negotiation with a remote computer failed because the IKE and AuthIP IPsec Keying Modules (IKEEXT) service is not started The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5453.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An IPsec negotiation with a remote computer failed because the IKE and AuthIP IPsec Keying Modules (IKEEXT) service is not started\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5453\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5453} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5453","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5453","Event ID 5453","An IPsec negotiation with a remote computer failed because the IKE and AuthIP IPsec Keying Modules (IKEEXT) service is not started"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69659,"title":"Windows Security Event 5456 - PAStore Engine applied Active Directory storage IPsec policy on the computer","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5456","Windows"],"keywords":["5456","event 5456","event id 5456","PAStore Engine applied Active Directory storage IPsec policy on the computer","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5456"],"errorCode":"","eventId":"5456","severity":"Medium","summary":"Windows Security event 5456 records: PAStore Engine applied Active Directory storage IPsec policy on the computer","rootCause":"The configured audit source recorded this activity: PAStore Engine applied Active Directory storage IPsec policy on the computer It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5456.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: PAStore Engine applied Active Directory storage IPsec policy on the computer\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5456\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5456} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5456","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5456","Event ID 5456","PAStore Engine applied Active Directory storage IPsec policy on the computer"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69660,"title":"Windows Security Event 5457 - PAStore Engine failed to apply Active Directory storage IPsec policy on the computer","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5457","Windows"],"keywords":["5457","event 5457","event id 5457","PAStore Engine failed to apply Active Directory storage IPsec policy on the computer","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5457"],"errorCode":"","eventId":"5457","severity":"High","summary":"Windows Security event 5457 records: PAStore Engine failed to apply Active Directory storage IPsec policy on the computer","rootCause":"The audited operation reported a failure: PAStore Engine failed to apply Active Directory storage IPsec policy on the computer The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5457.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: PAStore Engine failed to apply Active Directory storage IPsec policy on the computer\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5457\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5457} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5457","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5457","Event ID 5457","PAStore Engine failed to apply Active Directory storage IPsec policy on the computer"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69661,"title":"Windows Security Event 5458 - PAStore Engine applied locally cached copy of Active Directory storage IPsec policy on the computer","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5458","Windows"],"keywords":["5458","event 5458","event id 5458","PAStore Engine applied locally cached copy of Active Directory storage IPsec policy on the computer","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5458"],"errorCode":"","eventId":"5458","severity":"Medium","summary":"Windows Security event 5458 records: PAStore Engine applied locally cached copy of Active Directory storage IPsec policy on the computer","rootCause":"The configured audit source recorded this activity: PAStore Engine applied locally cached copy of Active Directory storage IPsec policy on the computer It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5458.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: PAStore Engine applied locally cached copy of Active Directory storage IPsec policy on the computer\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5458\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5458} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5458","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5458","Event ID 5458","PAStore Engine applied locally cached copy of Active Directory storage IPsec policy on the computer"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69662,"title":"Windows Security Event 5459 - PAStore Engine failed to apply locally cached copy of Active Directory storage IPsec policy on the computer","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5459","Windows"],"keywords":["5459","event 5459","event id 5459","PAStore Engine failed to apply locally cached copy of Active Directory storage IPsec policy on the computer","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5459"],"errorCode":"","eventId":"5459","severity":"High","summary":"Windows Security event 5459 records: PAStore Engine failed to apply locally cached copy of Active Directory storage IPsec policy on the computer","rootCause":"The audited operation reported a failure: PAStore Engine failed to apply locally cached copy of Active Directory storage IPsec policy on the computer The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5459.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: PAStore Engine failed to apply locally cached copy of Active Directory storage IPsec policy on the computer\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5459\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5459} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5459","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5459","Event ID 5459","PAStore Engine failed to apply locally cached copy of Active Directory storage IPsec policy on the computer"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69663,"title":"Windows Security Event 5460 - PAStore Engine applied local registry storage IPsec policy on the computer","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5460","Windows"],"keywords":["5460","event 5460","event id 5460","PAStore Engine applied local registry storage IPsec policy on the computer","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5460"],"errorCode":"","eventId":"5460","severity":"Medium","summary":"Windows Security event 5460 records: PAStore Engine applied local registry storage IPsec policy on the computer","rootCause":"The configured audit source recorded this activity: PAStore Engine applied local registry storage IPsec policy on the computer It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5460.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: PAStore Engine applied local registry storage IPsec policy on the computer\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5460\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5460} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5460","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5460","Event ID 5460","PAStore Engine applied local registry storage IPsec policy on the computer"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69664,"title":"Windows Security Event 5461 - PAStore Engine failed to apply local registry storage IPsec policy on the computer","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5461","Windows"],"keywords":["5461","event 5461","event id 5461","PAStore Engine failed to apply local registry storage IPsec policy on the computer","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5461"],"errorCode":"","eventId":"5461","severity":"High","summary":"Windows Security event 5461 records: PAStore Engine failed to apply local registry storage IPsec policy on the computer","rootCause":"The audited operation reported a failure: PAStore Engine failed to apply local registry storage IPsec policy on the computer The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5461.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: PAStore Engine failed to apply local registry storage IPsec policy on the computer\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5461\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5461} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5461","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5461","Event ID 5461","PAStore Engine failed to apply local registry storage IPsec policy on the computer"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69665,"title":"Windows Security Event 5462 - PAStore Engine failed to apply some rules of the active IPsec policy on the computer","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5462","Windows"],"keywords":["5462","event 5462","event id 5462","PAStore Engine failed to apply some rules of the active IPsec policy on the computer","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5462"],"errorCode":"","eventId":"5462","severity":"High","summary":"Windows Security event 5462 records: PAStore Engine failed to apply some rules of the active IPsec policy on the computer","rootCause":"The audited operation reported a failure: PAStore Engine failed to apply some rules of the active IPsec policy on the computer The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5462.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: PAStore Engine failed to apply some rules of the active IPsec policy on the computer\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5462\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5462} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5462","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5462","Event ID 5462","PAStore Engine failed to apply some rules of the active IPsec policy on the computer"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69666,"title":"Windows Security Event 5463 - PAStore Engine polled for changes to the active IPsec policy and detected no changes","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5463","Windows"],"keywords":["5463","event 5463","event id 5463","PAStore Engine polled for changes to the active IPsec policy and detected no changes","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5463"],"errorCode":"","eventId":"5463","severity":"Medium","summary":"Windows Security event 5463 records: PAStore Engine polled for changes to the active IPsec policy and detected no changes","rootCause":"The configured audit source recorded this activity: PAStore Engine polled for changes to the active IPsec policy and detected no changes It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5463.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: PAStore Engine polled for changes to the active IPsec policy and detected no changes\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5463\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5463} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5463","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5463","Event ID 5463","PAStore Engine polled for changes to the active IPsec policy and detected no changes"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69667,"title":"Windows Security Event 5464 - PAStore Engine polled for changes to the active IPsec policy, detected changes, and applied them to IPsec Services","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5464","Windows"],"keywords":["5464","event 5464","event id 5464","PAStore Engine polled for changes to the active IPsec policy, detected changes, and applied them to IPsec Services","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5464"],"errorCode":"","eventId":"5464","severity":"Medium","summary":"Windows Security event 5464 records: PAStore Engine polled for changes to the active IPsec policy, detected changes, and applied them to IPsec Services","rootCause":"The configured audit source recorded this activity: PAStore Engine polled for changes to the active IPsec policy, detected changes, and applied them to IPsec Services It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5464.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: PAStore Engine polled for changes to the active IPsec policy, detected changes, and applied them to IPsec Services\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5464\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5464} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5464","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5464","Event ID 5464","PAStore Engine polled for changes to the active IPsec policy, detected changes, and applied them to IPsec Services"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69668,"title":"Windows Security Event 5465 - PAStore Engine received a control for forced reloading of IPsec policy and processed the control successfully","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5465","Windows"],"keywords":["5465","event 5465","event id 5465","PAStore Engine received a control for forced reloading of IPsec policy and processed the control successfully","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5465"],"errorCode":"","eventId":"5465","severity":"Medium","summary":"Windows Security event 5465 records: PAStore Engine received a control for forced reloading of IPsec policy and processed the control successfully","rootCause":"The configured audit source recorded this activity: PAStore Engine received a control for forced reloading of IPsec policy and processed the control successfully It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5465.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: PAStore Engine received a control for forced reloading of IPsec policy and processed the control successfully\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5465\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5465} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5465","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5465","Event ID 5465","PAStore Engine received a control for forced reloading of IPsec policy and processed the control successfully"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69669,"title":"Windows Security Event 5466 - PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory cannot be reached, and will use the cached copy of the Active Directory IPsec policy instead","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5466","Windows"],"keywords":["5466","event 5466","event id 5466","PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory cannot be reached, and will use the cached copy of the Active Directory IPsec policy instead","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5466"],"errorCode":"","eventId":"5466","severity":"Medium","summary":"Windows Security event 5466 records: PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory cannot be reached, and will use the cached copy of the Active Directory IPsec policy instead","rootCause":"The configured audit source recorded this activity: PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory cannot be reached, and will use the cached copy of the Active Directory IPsec policy instead It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5466.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory cannot be reached, and will use the cached copy of the Active Directory IPsec policy instead\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5466\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5466} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5466","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5466","Event ID 5466","PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory cannot be reached, and will use the cached copy of the Active Directory IPsec policy instead"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69670,"title":"Windows Security Event 5467 - PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, and found no changes to the policy","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5467","Windows"],"keywords":["5467","event 5467","event id 5467","PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, and found no changes to the policy","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5467"],"errorCode":"","eventId":"5467","severity":"Medium","summary":"Windows Security event 5467 records: PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, and found no changes to the policy","rootCause":"The configured audit source recorded this activity: PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, and found no changes to the policy It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5467.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, and found no changes to the policy\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5467\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5467} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5467","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5467","Event ID 5467","PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, and found no changes to the policy"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69671,"title":"Windows Security Event 5468 - PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, found changes to the policy, and applied those changes","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5468","Windows"],"keywords":["5468","event 5468","event id 5468","PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, found changes to the policy, and applied those changes","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5468"],"errorCode":"","eventId":"5468","severity":"Medium","summary":"Windows Security event 5468 records: PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, found changes to the policy, and applied those changes","rootCause":"The configured audit source recorded this activity: PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, found changes to the policy, and applied those changes It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5468.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, found changes to the policy, and applied those changes\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5468\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5468} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5468","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5468","Event ID 5468","PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, found changes to the policy, and applied those changes"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69672,"title":"Windows Security Event 5471 - PAStore Engine loaded local storage IPsec policy on the computer","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5471","Windows"],"keywords":["5471","event 5471","event id 5471","PAStore Engine loaded local storage IPsec policy on the computer","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5471"],"errorCode":"","eventId":"5471","severity":"Medium","summary":"Windows Security event 5471 records: PAStore Engine loaded local storage IPsec policy on the computer","rootCause":"The configured audit source recorded this activity: PAStore Engine loaded local storage IPsec policy on the computer It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5471.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: PAStore Engine loaded local storage IPsec policy on the computer\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5471\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5471} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5471","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5471","Event ID 5471","PAStore Engine loaded local storage IPsec policy on the computer"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69673,"title":"Windows Security Event 5472 - PAStore Engine failed to load local storage IPsec policy on the computer","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5472","Windows"],"keywords":["5472","event 5472","event id 5472","PAStore Engine failed to load local storage IPsec policy on the computer","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5472"],"errorCode":"","eventId":"5472","severity":"High","summary":"Windows Security event 5472 records: PAStore Engine failed to load local storage IPsec policy on the computer","rootCause":"The audited operation reported a failure: PAStore Engine failed to load local storage IPsec policy on the computer The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5472.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: PAStore Engine failed to load local storage IPsec policy on the computer\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5472\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5472} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5472","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5472","Event ID 5472","PAStore Engine failed to load local storage IPsec policy on the computer"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69674,"title":"Windows Security Event 5473 - PAStore Engine loaded directory storage IPsec policy on the computer","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5473","Windows"],"keywords":["5473","event 5473","event id 5473","PAStore Engine loaded directory storage IPsec policy on the computer","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5473"],"errorCode":"","eventId":"5473","severity":"Medium","summary":"Windows Security event 5473 records: PAStore Engine loaded directory storage IPsec policy on the computer","rootCause":"The configured audit source recorded this activity: PAStore Engine loaded directory storage IPsec policy on the computer It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5473.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: PAStore Engine loaded directory storage IPsec policy on the computer\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5473\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5473} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5473","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5473","Event ID 5473","PAStore Engine loaded directory storage IPsec policy on the computer"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69675,"title":"Windows Security Event 5474 - PAStore Engine failed to load directory storage IPsec policy on the computer","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5474","Windows"],"keywords":["5474","event 5474","event id 5474","PAStore Engine failed to load directory storage IPsec policy on the computer","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5474"],"errorCode":"","eventId":"5474","severity":"High","summary":"Windows Security event 5474 records: PAStore Engine failed to load directory storage IPsec policy on the computer","rootCause":"The audited operation reported a failure: PAStore Engine failed to load directory storage IPsec policy on the computer The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5474.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: PAStore Engine failed to load directory storage IPsec policy on the computer\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5474\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5474} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5474","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5474","Event ID 5474","PAStore Engine failed to load directory storage IPsec policy on the computer"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69676,"title":"Windows Security Event 5477 - PAStore Engine failed to add quick mode filter","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5477","Windows"],"keywords":["5477","event 5477","event id 5477","PAStore Engine failed to add quick mode filter","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5477"],"errorCode":"","eventId":"5477","severity":"High","summary":"Windows Security event 5477 records: PAStore Engine failed to add quick mode filter","rootCause":"The audited operation reported a failure: PAStore Engine failed to add quick mode filter The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5477.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: PAStore Engine failed to add quick mode filter\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5477\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5477} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5477","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5477","Event ID 5477","PAStore Engine failed to add quick mode filter"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69677,"title":"Windows Security Event 5478 - IPsec Services has started successfully","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5478","Windows"],"keywords":["5478","event 5478","event id 5478","IPsec Services has started successfully","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5478"],"errorCode":"","eventId":"5478","severity":"Medium","summary":"Windows Security event 5478 records: IPsec Services has started successfully","rootCause":"The configured audit source recorded this activity: IPsec Services has started successfully It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5478.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: IPsec Services has started successfully\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5478\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5478} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5478","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5478","Event ID 5478","IPsec Services has started successfully"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69678,"title":"Windows Security Event 5479 - IPsec Services has been shut down successfully","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5479","Windows"],"keywords":["5479","event 5479","event id 5479","IPsec Services has been shut down successfully","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5479"],"errorCode":"","eventId":"5479","severity":"Medium","summary":"Windows Security event 5479 records: IPsec Services has been shut down successfully","rootCause":"The configured audit source recorded this activity: IPsec Services has been shut down successfully It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5479.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: IPsec Services has been shut down successfully\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5479\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5479} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5479","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5479","Event ID 5479","IPsec Services has been shut down successfully"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69679,"title":"Windows Security Event 5480 - IPsec Services failed to get the complete list of network interfaces on the computer","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5480","Windows"],"keywords":["5480","event 5480","event id 5480","IPsec Services failed to get the complete list of network interfaces on the computer","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5480"],"errorCode":"","eventId":"5480","severity":"High","summary":"Windows Security event 5480 records: IPsec Services failed to get the complete list of network interfaces on the computer","rootCause":"The audited operation reported a failure: IPsec Services failed to get the complete list of network interfaces on the computer The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5480.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: IPsec Services failed to get the complete list of network interfaces on the computer\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5480\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5480} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5480","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5480","Event ID 5480","IPsec Services failed to get the complete list of network interfaces on the computer"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69680,"title":"Windows Security Event 5483 - IPsec Services failed to initialize RPC server. IPsec Services could not be started","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5483","Windows"],"keywords":["5483","event 5483","event id 5483","IPsec Services failed to initialize RPC server. IPsec Services could not be started","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5483"],"errorCode":"","eventId":"5483","severity":"High","summary":"Windows Security event 5483 records: IPsec Services failed to initialize RPC server. IPsec Services could not be started","rootCause":"The audited operation reported a failure: IPsec Services failed to initialize RPC server. IPsec Services could not be started The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5483.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: IPsec Services failed to initialize RPC server. IPsec Services could not be started\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5483\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5483} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5483","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5483","Event ID 5483","IPsec Services failed to initialize RPC server. IPsec Services could not be started"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69681,"title":"Windows Security Event 5484 - IPsec Services has experienced a critical failure and has been shut down","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5484","Windows"],"keywords":["5484","event 5484","event id 5484","IPsec Services has experienced a critical failure and has been shut down","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5484"],"errorCode":"","eventId":"5484","severity":"Critical","summary":"Windows Security event 5484 records: IPsec Services has experienced a critical failure and has been shut down","rootCause":"The audited operation reported a failure: IPsec Services has experienced a critical failure and has been shut down The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5484.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: IPsec Services has experienced a critical failure and has been shut down\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5484\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5484} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5484","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5484","Event ID 5484","IPsec Services has experienced a critical failure and has been shut down"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69682,"title":"Windows Security Event 5485 - IPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5485","Windows"],"keywords":["5485","event 5485","event id 5485","IPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5485"],"errorCode":"","eventId":"5485","severity":"High","summary":"Windows Security event 5485 records: IPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces","rootCause":"The audited operation reported a failure: IPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5485.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: IPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5485\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5485} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5485","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5485","Event ID 5485","IPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69683,"title":"Windows Security Event 5632 - A request was made to authenticate to a wireless network","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5632","Windows"],"keywords":["5632","event 5632","event id 5632","A request was made to authenticate to a wireless network","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5632"],"errorCode":"","eventId":"5632","severity":"Low","summary":"Windows Security event 5632 records: A request was made to authenticate to a wireless network","rootCause":"The configured audit source recorded this activity: A request was made to authenticate to a wireless network It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5632.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A request was made to authenticate to a wireless network\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5632\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5632} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5632","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5632","Event ID 5632","A request was made to authenticate to a wireless network"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69684,"title":"Windows Security Event 5633 - A request was made to authenticate to a wired network","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5633","Windows"],"keywords":["5633","event 5633","event id 5633","A request was made to authenticate to a wired network","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5633"],"errorCode":"","eventId":"5633","severity":"Low","summary":"Windows Security event 5633 records: A request was made to authenticate to a wired network","rootCause":"The configured audit source recorded this activity: A request was made to authenticate to a wired network It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5633.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A request was made to authenticate to a wired network\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5633\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5633} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5633","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5633","Event ID 5633","A request was made to authenticate to a wired network"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69685,"title":"Windows Security Event 5712 - A Remote Procedure Call (RPC) was attempted","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5712","Windows"],"keywords":["5712","event 5712","event id 5712","A Remote Procedure Call (RPC) was attempted","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5712"],"errorCode":"","eventId":"5712","severity":"Low","summary":"Windows Security event 5712 records: A Remote Procedure Call (RPC) was attempted","rootCause":"The configured audit source recorded this activity: A Remote Procedure Call (RPC) was attempted It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5712.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A Remote Procedure Call (RPC) was attempted\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5712\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5712} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5712","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5712","Event ID 5712","A Remote Procedure Call (RPC) was attempted"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69686,"title":"Windows Security Event 5888 - An object in the COM+ Catalog was modified","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5888","Windows"],"keywords":["5888","event 5888","event id 5888","An object in the COM+ Catalog was modified","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5888"],"errorCode":"","eventId":"5888","severity":"Medium","summary":"Windows Security event 5888 records: An object in the COM+ Catalog was modified","rootCause":"The event records a state-changing operation: An object in the COM+ Catalog was modified It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5888.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An object in the COM+ Catalog was modified\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5888\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5888} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5888","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5888","Event ID 5888","An object in the COM+ Catalog was modified"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69687,"title":"Windows Security Event 5889 - An object was deleted from the COM+ Catalog","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5889","Windows"],"keywords":["5889","event 5889","event id 5889","An object was deleted from the COM+ Catalog","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5889"],"errorCode":"","eventId":"5889","severity":"High","summary":"Windows Security event 5889 records: An object was deleted from the COM+ Catalog","rootCause":"The event records a state-changing operation: An object was deleted from the COM+ Catalog It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5889.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An object was deleted from the COM+ Catalog\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5889\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5889} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5889","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5889","Event ID 5889","An object was deleted from the COM+ Catalog"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69688,"title":"Windows Security Event 5890 - An object was added to the COM+ Catalog","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 5890","Windows"],"keywords":["5890","event 5890","event id 5890","An object was added to the COM+ Catalog","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5890"],"errorCode":"","eventId":"5890","severity":"Medium","summary":"Windows Security event 5890 records: An object was added to the COM+ Catalog","rootCause":"The event records a state-changing operation: An object was added to the COM+ Catalog It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 5890.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: An object was added to the COM+ Catalog\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5890\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=5890} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5890","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 5890","Event ID 5890","An object was added to the COM+ Catalog"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69689,"title":"Windows Security Event 6144 - Security policy in the group policy objects has been applied successfully","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6144","Windows"],"keywords":["6144","event 6144","event id 6144","Security policy in the group policy objects has been applied successfully","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6144"],"errorCode":"","eventId":"6144","severity":"Medium","summary":"Windows Security event 6144 records: Security policy in the group policy objects has been applied successfully","rootCause":"The configured audit source recorded this activity: Security policy in the group policy objects has been applied successfully It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6144.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Security policy in the group policy objects has been applied successfully\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6144\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6144} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6144","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6144","Event ID 6144","Security policy in the group policy objects has been applied successfully"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69690,"title":"Windows Security Event 6145 - One or more errors occured while processing security policy in the group policy objects","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6145","Windows"],"keywords":["6145","event 6145","event id 6145","One or more errors occured while processing security policy in the group policy objects","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6145"],"errorCode":"","eventId":"6145","severity":"High","summary":"Windows Security event 6145 records: One or more errors occured while processing security policy in the group policy objects","rootCause":"The audited operation reported a failure: One or more errors occured while processing security policy in the group policy objects The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6145.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: One or more errors occured while processing security policy in the group policy objects\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6145\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6145} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6145","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6145","Event ID 6145","One or more errors occured while processing security policy in the group policy objects"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69691,"title":"Windows Security Event 6272 - Network Policy Server granted access to a user","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6272","Windows"],"keywords":["6272","event 6272","event id 6272","Network Policy Server granted access to a user","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6272"],"errorCode":"","eventId":"6272","severity":"Medium","summary":"Windows Security event 6272 records: Network Policy Server granted access to a user","rootCause":"The configured audit source recorded this activity: Network Policy Server granted access to a user It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6272.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Network Policy Server granted access to a user\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6272\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6272} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6272","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6272","Event ID 6272","Network Policy Server granted access to a user"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69692,"title":"Windows Security Event 6273 - Network Policy Server denied access to a user","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6273","Windows"],"keywords":["6273","event 6273","event id 6273","Network Policy Server denied access to a user","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6273"],"errorCode":"","eventId":"6273","severity":"High","summary":"Windows Security event 6273 records: Network Policy Server denied access to a user","rootCause":"The audited operation reported a failure: Network Policy Server denied access to a user The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6273.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Network Policy Server denied access to a user\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6273\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6273} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6273","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6273","Event ID 6273","Network Policy Server denied access to a user"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69693,"title":"Windows Security Event 6274 - Network Policy Server discarded the request for a user","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6274","Windows"],"keywords":["6274","event 6274","event id 6274","Network Policy Server discarded the request for a user","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6274"],"errorCode":"","eventId":"6274","severity":"Medium","summary":"Windows Security event 6274 records: Network Policy Server discarded the request for a user","rootCause":"The configured audit source recorded this activity: Network Policy Server discarded the request for a user It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6274.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Network Policy Server discarded the request for a user\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6274\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6274} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6274","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6274","Event ID 6274","Network Policy Server discarded the request for a user"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69694,"title":"Windows Security Event 6275 - Network Policy Server discarded the accounting request for a user","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6275","Windows"],"keywords":["6275","event 6275","event id 6275","Network Policy Server discarded the accounting request for a user","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6275"],"errorCode":"","eventId":"6275","severity":"Medium","summary":"Windows Security event 6275 records: Network Policy Server discarded the accounting request for a user","rootCause":"The configured audit source recorded this activity: Network Policy Server discarded the accounting request for a user It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6275.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Network Policy Server discarded the accounting request for a user\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6275\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6275} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6275","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6275","Event ID 6275","Network Policy Server discarded the accounting request for a user"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69695,"title":"Windows Security Event 6276 - Network Policy Server quarantined a user","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6276","Windows"],"keywords":["6276","event 6276","event id 6276","Network Policy Server quarantined a user","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6276"],"errorCode":"","eventId":"6276","severity":"Medium","summary":"Windows Security event 6276 records: Network Policy Server quarantined a user","rootCause":"The configured audit source recorded this activity: Network Policy Server quarantined a user It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6276.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Network Policy Server quarantined a user\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6276\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6276} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6276","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6276","Event ID 6276","Network Policy Server quarantined a user"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69696,"title":"Windows Security Event 6277 - Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6277","Windows"],"keywords":["6277","event 6277","event id 6277","Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6277"],"errorCode":"","eventId":"6277","severity":"Medium","summary":"Windows Security event 6277 records: Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy","rootCause":"The configured audit source recorded this activity: Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6277.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6277\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6277} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6277","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6277","Event ID 6277","Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69697,"title":"Windows Security Event 6278 - Network Policy Server granted full access to a user because the host met the defined health policy","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6278","Windows"],"keywords":["6278","event 6278","event id 6278","Network Policy Server granted full access to a user because the host met the defined health policy","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6278"],"errorCode":"","eventId":"6278","severity":"Medium","summary":"Windows Security event 6278 records: Network Policy Server granted full access to a user because the host met the defined health policy","rootCause":"The configured audit source recorded this activity: Network Policy Server granted full access to a user because the host met the defined health policy It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6278.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Network Policy Server granted full access to a user because the host met the defined health policy\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6278\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6278} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6278","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6278","Event ID 6278","Network Policy Server granted full access to a user because the host met the defined health policy"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69698,"title":"Windows Security Event 6279 - Network Policy Server locked the user account due to repeated failed authentication attempts","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6279","Windows"],"keywords":["6279","event 6279","event id 6279","Network Policy Server locked the user account due to repeated failed authentication attempts","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6279"],"errorCode":"","eventId":"6279","severity":"High","summary":"Windows Security event 6279 records: Network Policy Server locked the user account due to repeated failed authentication attempts","rootCause":"The audited operation reported a failure: Network Policy Server locked the user account due to repeated failed authentication attempts The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6279.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Network Policy Server locked the user account due to repeated failed authentication attempts\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6279\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6279} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6279","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6279","Event ID 6279","Network Policy Server locked the user account due to repeated failed authentication attempts"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69699,"title":"Windows Security Event 6280 - Network Policy Server unlocked the user account","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6280","Windows"],"keywords":["6280","event 6280","event id 6280","Network Policy Server unlocked the user account","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6280"],"errorCode":"","eventId":"6280","severity":"Medium","summary":"Windows Security event 6280 records: Network Policy Server unlocked the user account","rootCause":"The configured audit source recorded this activity: Network Policy Server unlocked the user account It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6280.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Network Policy Server unlocked the user account\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6280\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6280} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6280","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6280","Event ID 6280","Network Policy Server unlocked the user account"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69700,"title":"Windows Security Event 6281 - Code Integrity determined that the page hashes of an image file are not valid...","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6281","Windows"],"keywords":["6281","event 6281","event id 6281","Code Integrity determined that the page hashes of an image file are not valid...","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6281"],"errorCode":"","eventId":"6281","severity":"Critical","summary":"Windows Security event 6281 records: Code Integrity determined that the page hashes of an image file are not valid...","rootCause":"The configured audit source recorded this activity: Code Integrity determined that the page hashes of an image file are not valid... It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6281.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Code Integrity determined that the page hashes of an image file are not valid...\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6281\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6281} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6281","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6281","Event ID 6281","Code Integrity determined that the page hashes of an image file are not valid..."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69701,"title":"Windows Security Event 6400 - BranchCache: Received an incorrectly formatted response while discovering availability of content.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6400","Windows"],"keywords":["6400","event 6400","event id 6400","BranchCache: Received an incorrectly formatted response while discovering availability of content.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6400"],"errorCode":"","eventId":"6400","severity":"Low","summary":"Windows Security event 6400 records: BranchCache: Received an incorrectly formatted response while discovering availability of content.","rootCause":"The configured audit source recorded this activity: BranchCache: Received an incorrectly formatted response while discovering availability of content. It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6400.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: BranchCache: Received an incorrectly formatted response while discovering availability of content.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6400\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6400} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6400","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6400","Event ID 6400","BranchCache: Received an incorrectly formatted response while discovering availability of content."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69702,"title":"Windows Security Event 6401 - BranchCache: Received invalid data from a peer. Data discarded.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6401","Windows"],"keywords":["6401","event 6401","event id 6401","BranchCache: Received invalid data from a peer. Data discarded.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6401"],"errorCode":"","eventId":"6401","severity":"High","summary":"Windows Security event 6401 records: BranchCache: Received invalid data from a peer. Data discarded.","rootCause":"The audited operation reported a failure: BranchCache: Received invalid data from a peer. Data discarded. The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6401.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: BranchCache: Received invalid data from a peer. Data discarded.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6401\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6401} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6401","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6401","Event ID 6401","BranchCache: Received invalid data from a peer. Data discarded."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69703,"title":"Windows Security Event 6402 - BranchCache: The message to the hosted cache offering it data is incorrectly formatted.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6402","Windows"],"keywords":["6402","event 6402","event id 6402","BranchCache: The message to the hosted cache offering it data is incorrectly formatted.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6402"],"errorCode":"","eventId":"6402","severity":"Low","summary":"Windows Security event 6402 records: BranchCache: The message to the hosted cache offering it data is incorrectly formatted.","rootCause":"The configured audit source recorded this activity: BranchCache: The message to the hosted cache offering it data is incorrectly formatted. It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6402.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: BranchCache: The message to the hosted cache offering it data is incorrectly formatted.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6402\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6402} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6402","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6402","Event ID 6402","BranchCache: The message to the hosted cache offering it data is incorrectly formatted."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69704,"title":"Windows Security Event 6403 - BranchCache: The hosted cache sent an incorrectly formatted response to the client's message to offer it data.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6403","Windows"],"keywords":["6403","event 6403","event id 6403","BranchCache: The hosted cache sent an incorrectly formatted response to the client's message to offer it data.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6403"],"errorCode":"","eventId":"6403","severity":"Low","summary":"Windows Security event 6403 records: BranchCache: The hosted cache sent an incorrectly formatted response to the client's message to offer it data.","rootCause":"The configured audit source recorded this activity: BranchCache: The hosted cache sent an incorrectly formatted response to the client's message to offer it data. It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6403.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: BranchCache: The hosted cache sent an incorrectly formatted response to the client's message to offer it data.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6403\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6403} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6403","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6403","Event ID 6403","BranchCache: The hosted cache sent an incorrectly formatted response to the client's message to offer it data."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69705,"title":"Windows Security Event 6404 - BranchCache: Hosted cache could not be authenticated using the provisioned SSL certificate.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6404","Windows"],"keywords":["6404","event 6404","event id 6404","BranchCache: Hosted cache could not be authenticated using the provisioned SSL certificate.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6404"],"errorCode":"","eventId":"6404","severity":"High","summary":"Windows Security event 6404 records: BranchCache: Hosted cache could not be authenticated using the provisioned SSL certificate.","rootCause":"The audited operation reported a failure: BranchCache: Hosted cache could not be authenticated using the provisioned SSL certificate. The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6404.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: BranchCache: Hosted cache could not be authenticated using the provisioned SSL certificate.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6404\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6404} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6404","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6404","Event ID 6404","BranchCache: Hosted cache could not be authenticated using the provisioned SSL certificate."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69706,"title":"Windows Security Event 6405 - BranchCache: %2 instance(s) of event id %1 occurred.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6405","Windows"],"keywords":["6405","event 6405","event id 6405","BranchCache: %2 instance(s) of event id %1 occurred.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6405"],"errorCode":"","eventId":"6405","severity":"Low","summary":"Windows Security event 6405 records: BranchCache: %2 instance(s) of event id %1 occurred.","rootCause":"The configured audit source recorded this activity: BranchCache: %2 instance(s) of event id %1 occurred. It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6405.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: BranchCache: %2 instance(s) of event id %1 occurred.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6405\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6405} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6405","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6405","Event ID 6405","BranchCache: %2 instance(s) of event id %1 occurred."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69707,"title":"Windows Security Event 6406 - %1 registered to Windows Firewall to control filtering for the following:","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6406","Windows"],"keywords":["6406","event 6406","event id 6406","%1 registered to Windows Firewall to control filtering for the following:","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6406"],"errorCode":"","eventId":"6406","severity":"Medium","summary":"Windows Security event 6406 records: %1 registered to Windows Firewall to control filtering for the following:","rootCause":"The configured audit source recorded this activity: %1 registered to Windows Firewall to control filtering for the following: It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6406.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: %1 registered to Windows Firewall to control filtering for the following:\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6406\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6406} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6406","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6406","Event ID 6406","%1 registered to Windows Firewall to control filtering for the following:"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69708,"title":"Windows Security Event 6407 - %1","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6407","Windows"],"keywords":["6407","event 6407","event id 6407","%1","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6407"],"errorCode":"","eventId":"6407","severity":"Low","summary":"Windows Security event 6407 records: %1","rootCause":"The configured audit source recorded this activity: %1 It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6407.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: %1\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6407\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6407} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6407","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6407","Event ID 6407","%1"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69709,"title":"Windows Security Event 6408 - Registered product %1 failed and Windows Firewall is now controlling the filtering for %2.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6408","Windows"],"keywords":["6408","event 6408","event id 6408","Registered product %1 failed and Windows Firewall is now controlling the filtering for %2.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6408"],"errorCode":"","eventId":"6408","severity":"High","summary":"Windows Security event 6408 records: Registered product %1 failed and Windows Firewall is now controlling the filtering for %2.","rootCause":"The audited operation reported a failure: Registered product %1 failed and Windows Firewall is now controlling the filtering for %2. The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6408.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Registered product %1 failed and Windows Firewall is now controlling the filtering for %2.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6408\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6408} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6408","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6408","Event ID 6408","Registered product %1 failed and Windows Firewall is now controlling the filtering for %2."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69710,"title":"Windows Security Event 6409 - BranchCache: A service connection point object could not be parsed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6409","Windows"],"keywords":["6409","event 6409","event id 6409","BranchCache: A service connection point object could not be parsed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6409"],"errorCode":"","eventId":"6409","severity":"High","summary":"Windows Security event 6409 records: BranchCache: A service connection point object could not be parsed","rootCause":"The audited operation reported a failure: BranchCache: A service connection point object could not be parsed The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6409.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: BranchCache: A service connection point object could not be parsed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6409\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6409} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6409","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6409","Event ID 6409","BranchCache: A service connection point object could not be parsed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69711,"title":"Windows Security Event 6410 - Code integrity determined that a file does not meet the security requirements to load into a process. This could be due to the use of shared sections or other issues","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6410","Windows"],"keywords":["6410","event 6410","event id 6410","Code integrity determined that a file does not meet the security requirements to load into a process. This could be due to the use of shared sections or other issues","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6410"],"errorCode":"","eventId":"6410","severity":"Low","summary":"Windows Security event 6410 records: Code integrity determined that a file does not meet the security requirements to load into a process. This could be due to the use of shared sections or other issues","rootCause":"The configured audit source recorded this activity: Code integrity determined that a file does not meet the security requirements to load into a process. This could be due to the use of shared sections or other issues It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6410.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Code integrity determined that a file does not meet the security requirements to load into a process. This could be due to the use of shared sections or other issues\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6410\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6410} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6410","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6410","Event ID 6410","Code integrity determined that a file does not meet the security requirements to load into a process. This could be due to the use of shared sections or other issues"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69712,"title":"Windows Security Event 6416 - A new external device was recognized by the system.","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6416","Windows"],"keywords":["6416","event 6416","event id 6416","A new external device was recognized by the system.","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6416"],"errorCode":"","eventId":"6416","severity":"Low","summary":"Windows Security event 6416 records: A new external device was recognized by the system.","rootCause":"The configured audit source recorded this activity: A new external device was recognized by the system. It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6416.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A new external device was recognized by the system.\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6416\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6416} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6416","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6416","Event ID 6416","A new external device was recognized by the system."],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69713,"title":"Windows Security Event 6417 - The FIPS mode crypto selftests succeeded","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6417","Windows"],"keywords":["6417","event 6417","event id 6417","The FIPS mode crypto selftests succeeded","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6417"],"errorCode":"","eventId":"6417","severity":"Low","summary":"Windows Security event 6417 records: The FIPS mode crypto selftests succeeded","rootCause":"The configured audit source recorded this activity: The FIPS mode crypto selftests succeeded It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6417.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The FIPS mode crypto selftests succeeded\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6417\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6417} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6417","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6417","Event ID 6417","The FIPS mode crypto selftests succeeded"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69714,"title":"Windows Security Event 6418 - The FIPS mode crypto selftests failed","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6418","Windows"],"keywords":["6418","event 6418","event id 6418","The FIPS mode crypto selftests failed","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6418"],"errorCode":"","eventId":"6418","severity":"Critical","summary":"Windows Security event 6418 records: The FIPS mode crypto selftests failed","rootCause":"The audited operation reported a failure: The FIPS mode crypto selftests failed The complete event fields, initiating identity, target, status, and surrounding records are required to locate the failed dependency.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Identify the status, substatus, error, target, and originating process or server in the complete event. Correct only the evidenced authentication, authorization, policy, configuration, connectivity, capacity, or service condition, then repeat the original operation once and confirm the failure stops.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6418.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The FIPS mode crypto selftests failed\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6418\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6418} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6418","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6418","Event ID 6418","The FIPS mode crypto selftests failed"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69715,"title":"Windows Security Event 6419 - A request was made to disable a device","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6419","Windows"],"keywords":["6419","event 6419","event id 6419","A request was made to disable a device","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6419"],"errorCode":"","eventId":"6419","severity":"Low","summary":"Windows Security event 6419 records: A request was made to disable a device","rootCause":"The configured audit source recorded this activity: A request was made to disable a device It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6419.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A request was made to disable a device\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6419\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6419} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6419","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6419","Event ID 6419","A request was made to disable a device"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69716,"title":"Windows Security Event 6420 - A device was disabled","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6420","Windows"],"keywords":["6420","event 6420","event id 6420","A device was disabled","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6420"],"errorCode":"","eventId":"6420","severity":"High","summary":"Windows Security event 6420 records: A device was disabled","rootCause":"The event records a state-changing operation: A device was disabled It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6420.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A device was disabled\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6420\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6420} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6420","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6420","Event ID 6420","A device was disabled"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69717,"title":"Windows Security Event 6421 - A request was made to enable a device","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6421","Windows"],"keywords":["6421","event 6421","event id 6421","A request was made to enable a device","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6421"],"errorCode":"","eventId":"6421","severity":"Low","summary":"Windows Security event 6421 records: A request was made to enable a device","rootCause":"The configured audit source recorded this activity: A request was made to enable a device It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6421.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A request was made to enable a device\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6421\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6421} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6421","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6421","Event ID 6421","A request was made to enable a device"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69718,"title":"Windows Security Event 6422 - A device was enabled","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6422","Windows"],"keywords":["6422","event 6422","event id 6422","A device was enabled","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6422"],"errorCode":"","eventId":"6422","severity":"Medium","summary":"Windows Security event 6422 records: A device was enabled","rootCause":"The event records a state-changing operation: A device was enabled It may be expected administration or an unauthorized change; validate the actor, target, approval, and outcome before taking action.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Confirm the actor, target object, changed values, source host or IP, maintenance ticket, and expected result. If the action was unauthorized, preserve the original event and related evidence, follow the incident-response process, contain the affected identity or host as authorized, and reverse the change only through an approved recovery plan.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6422.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: A device was enabled\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6422\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6422} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6422","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6422","Event ID 6422","A device was enabled"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69719,"title":"Windows Security Event 6423 - The installation of this device is forbidden by system policy","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6423","Windows"],"keywords":["6423","event 6423","event id 6423","The installation of this device is forbidden by system policy","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6423"],"errorCode":"","eventId":"6423","severity":"Medium","summary":"Windows Security event 6423 records: The installation of this device is forbidden by system policy","rootCause":"The configured audit source recorded this activity: The installation of this device is forbidden by system policy It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6423.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The installation of this device is forbidden by system policy\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6423\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6423} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6423","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6423","Event ID 6423","The installation of this device is forbidden by system policy"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69720,"title":"Windows Security Event 6424 - The installation of this device was allowed, after having previously been forbidden by policy","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 6424","Windows"],"keywords":["6424","event 6424","event id 6424","The installation of this device was allowed, after having previously been forbidden by policy","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6424"],"errorCode":"","eventId":"6424","severity":"Medium","summary":"Windows Security event 6424 records: The installation of this device was allowed, after having previously been forbidden by policy","rootCause":"The configured audit source recorded this activity: The installation of this device was allowed, after having previously been forbidden by policy It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 6424.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: The installation of this device was allowed, after having previously been forbidden by policy\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6424\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=6424} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=6424","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 6424","Event ID 6424","The installation of this device was allowed, after having previously been forbidden by policy"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":69721,"title":"Windows Security Event 8191 - Highest System-Defined Audit Message Value","category":"Security","product":"Windows Security Audit Log","tags":["Windows Security","Audit Event","Event ID 8191","Windows"],"keywords":["8191","event 8191","event id 8191","Highest System-Defined Audit Message Value","Windows Security","Windows Security Audit Log","WIN-SECURITY-AUDIT","security log","audit log","event viewer","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=8191"],"errorCode":"","eventId":"8191","severity":"Low","summary":"Windows Security event 8191 records: Highest System-Defined Audit Message Value","rootCause":"The configured audit source recorded this activity: Highest System-Defined Audit Message Value It can be routine telemetry, operational evidence, or part of an incident timeline depending on the event fields and neighboring records.","resolution":"1. Export or preserve the complete event, including its XML, UTC timestamp, provider, computer, record ID, task/category, keywords, and every named field.\n2. Identify the initiating account, logon/session ID, process, source address, originating server, target object, result, status, and substatus when present.\n3. Determine whether the activity matches normal baselines and an approved user, service, host, application, or maintenance window. Correlate related logon, process, object-access, policy, directory, application, and network events before deciding whether remediation is necessary.\n4. Correlate earlier and later events from the same provider, computer, account, process, session, object, or correlation identifier.\n5. Validate the expected outcome and document whether the event was normal, a corrected operational failure, or escalated security activity.\n6. Use the linked source article for field-level guidance and examples; screenshots are examples and must not be treated as values from the affected environment.","emailScript":"Hello,\n\nWe reviewed the logged activity identified as Windows Security event 8191.\n\nWe are correlating the account, device, time, affected resource, and surrounding audit records to determine whether this was expected activity or requires corrective action.\n\nPlease preserve the original message and let us know what action was being performed at that time.\n\nThank you,\n\nIT Support","faqSteps":"Send IT Support the complete event message or exported event, the affected device or service, the approximate time, and what you were doing. Do not clear logs, delete records, disable auditing, reset accounts, or share passwords, tokens, private keys, or unredacted sensitive data.","notes":"Source description: Highest System-Defined Audit Message Value\n\nContext: This is a native Windows Security audit event. The event ID identifies the audited activity, not by itself whether the activity was malicious or whether a repair is required.\n\nReference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=8191\nEncyclopedia: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx\nBook resource: https://www.ultimatewindowssecurity.com/securitylog/book/default.aspx\n\nUltimate Windows Security is an independent third-party reference. Validate event semantics against the installed product/version and current vendor documentation. The direct article may include screenshots, field descriptions, corresponding legacy events, and examples; examples are not evidence from the affected system.","commands":[{"shell":"PowerShell","command":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=8191} -MaxEvents 20 | Format-List TimeCreated,Id,ProviderName,MachineName,Message","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"ultimate_windows_security_event_catalog.tsv; Ultimate Windows Security Log Encyclopedia","sourceAuthority":"Ultimate Windows Security","sourceUrl":"https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=8191","namespace":"WIN-SECURITY-AUDIT","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"technologies":["Windows Event Log","Audit Logging","Windows Security"],"articleCategories":["Security Logs","Audit Events","Windows Security","Windows"],"aliases":["Windows Security 8191","Event ID 8191","Highest System-Defined Audit Message Value"],"dateAdded":"2026-09-15","lastUpdated":"2026-09-15"},{"id":65000,"title":"Google Admin Console - Administrator Access Required","category":"Google Workspace","product":"Google Admin Console","tags":["Google Workspace","Google Admin","Admin Console","RBAC","Sign-in"],"keywords":["Google Admin Console - Administrator Access Required","Google Admin Console","A user reaches admin.google.com but cannot open the Admin console or administrative controls.","Administrator access required","Google Workspace","Google Admin console","Admin SDK","Directory API","Admin Console","RBAC","Sign-in"],"errorCode":"Administrator access required","eventId":"","severity":"High","summary":"A user reaches admin.google.com but cannot open the Admin console or administrative controls.","rootCause":"The signed-in account is a consumer account, an unmanaged account, or a Workspace user without an assigned administrator role.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Confirm the selected Google account and managed domain, then have a Super Admin assign the smallest documented role needed. Do not grant Super Admin merely to expose one console function.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Google Admin Console - Administrator Access Required.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace - Administrator User Guide.pdf; Google Admin Help.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace - Administrator User Guide.pdf; Google Admin Help","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Admin Console","RBAC","Sign-in"],"articleCategories":["Google Workspace","Cloud Administration","Admin Console","RBAC","Sign-in"],"aliases":["Administrator access required","Google Admin Console - Administrator Access Required"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65001,"title":"Google Workspace - Domain Ownership Not Verified","category":"Google Workspace","product":"Google Workspace / Directory API","tags":["Google Workspace","Google Admin","Domain Verification","DNS","User Creation"],"keywords":["Google Workspace - Domain Ownership Not Verified","Google Workspace / Directory API","A user, alias, or domain operation cannot proceed because Google has not verified domain ownership.","Domain not verified","Google Workspace","Google Admin console","Admin SDK","Directory API","Domain Verification","DNS","User Creation","nslookup -type=TXT <domain>"],"errorCode":"Domain not verified","eventId":"","severity":"High","summary":"A user, alias, or domain operation cannot proceed because Google has not verified domain ownership.","rootCause":"The DNS verification record is missing, incorrect, unpropagated, or was removed after setup.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Obtain Google's current verification value, publish it at the authoritative DNS provider without replacing unrelated records, verify public DNS resolution, and retry verification before creating identities on the domain.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Google Workspace - Domain Ownership Not Verified.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace - Administrator User Guide.pdf; Directory API limits and user management.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[{"shell":"Terminal","command":"nslookup -type=TXT <domain>","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Google Workspace - Administrator User Guide.pdf; Directory API limits and user management","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Domain Verification","DNS","User Creation"],"articleCategories":["Google Workspace","Cloud Administration","Domain Verification","DNS","User Creation"],"aliases":["Domain not verified","Domain Ownership Not Verified"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65002,"title":"Google Workspace - User Creation Blocked by License or Billing Limit","category":"Google Workspace","product":"Google Workspace / Directory API","tags":["Google Workspace","Google Admin","User Provisioning","Licensing","Billing"],"keywords":["Google Workspace - User Creation Blocked by License or Billing Limit","Google Workspace / Directory API","A new Workspace user cannot be created because the subscription has no available committed seat or the account configuration blocks additional users.","User creation limit","Google Workspace","Google Admin console","Admin SDK","Directory API","User Provisioning","Licensing","Billing"],"errorCode":"User creation limit","eventId":"","severity":"High","summary":"A new Workspace user cannot be created because the subscription has no available committed seat or the account configuration blocks additional users.","rootCause":"The annual commitment is exhausted, flexible-plan creation has billing impact, the subscription is suspended, or the business-email account has not unlocked full Workspace settings.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Check subscription status, available licenses, billing state, domain status, and edition restrictions; obtain approved capacity before creating the user and confirm license assignment afterward.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Google Workspace - User Creation Blocked by License or Billing Limit.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Directory API user management and limits.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Directory API user management and limits","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","User Provisioning","Licensing","Billing"],"articleCategories":["Google Workspace","Cloud Administration","User Provisioning","Licensing","Billing"],"aliases":["User creation limit","User Creation Blocked by License or Billing Limit"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65003,"title":"Google Workspace - Bulk User CSV Import Failed","category":"Google Workspace","product":"Google Admin Console","tags":["Google Workspace","Google Admin","Bulk Users","CSV","Organizational Unit"],"keywords":["Google Workspace - Bulk User CSV Import Failed","Google Admin Console","A bulk user upload rejects rows, creates incomplete users, or places users in the wrong organizational unit.","CSV import error","Google Workspace","Google Admin console","Admin SDK","Directory API","Bulk Users","CSV","Organizational Unit"],"errorCode":"CSV import error","eventId":"","severity":"High","summary":"A bulk user upload rejects rows, creates incomplete users, or places users in the wrong organizational unit.","rootCause":"Required columns, email values, passwords, quoting, encoding, or organizational-unit paths are invalid, or the uploaded template does not match the current Admin console format.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Download a fresh CSV template, validate required fields and exact OU paths, test a small batch, review row-level errors, correct the source file, and reconcile created accounts before rerunning.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Google Workspace - Bulk User CSV Import Failed.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace - Administrator User Guide.pdf; Google Admin Help.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace - Administrator User Guide.pdf; Google Admin Help","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Bulk Users","CSV","Organizational Unit"],"articleCategories":["Google Workspace","Cloud Administration","Bulk Users","CSV","Organizational Unit"],"aliases":["CSV import error","Bulk User CSV Import Failed"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65004,"title":"Google Workspace - Organizational Unit Name or Inheritance Problem","category":"Google Workspace","product":"Google Admin Console / Directory API","tags":["Google Workspace","Google Admin","Organizational Unit","Policy Inheritance","OU"],"keywords":["Google Workspace - Organizational Unit Name or Inheritance Problem","Google Admin Console / Directory API","An organizational unit cannot be created or users receive unexpected inherited settings.","Invalid organizational unit","Google Workspace","Google Admin console","Admin SDK","Directory API","Organizational Unit","Policy Inheritance","OU"],"errorCode":"Invalid organizational unit","eventId":"","severity":"High","summary":"An organizational unit cannot be created or users receive unexpected inherited settings.","rootCause":"The OU name or path is invalid, the intended parent is wrong, or a child override was mistaken for an inherited parent setting.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Map the current hierarchy and effective policy, correct the supported name or parent, change one scoped setting at a time, and validate inherited and overridden behavior with a test account before moving production users.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Google Workspace - Organizational Unit Name or Inheritance Problem.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace - Administrator User Guide.pdf; Directory API limits.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace - Administrator User Guide.pdf; Directory API limits","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Organizational Unit","Policy Inheritance","OU"],"articleCategories":["Google Workspace","Cloud Administration","Organizational Unit","Policy Inheritance","OU"],"aliases":["Invalid organizational unit","Organizational Unit Name or Inheritance Problem"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65005,"title":"Google Admin Role - Required Privileges Missing","category":"Google Workspace","product":"Google Admin Console / Directory API","tags":["Google Workspace","Google Admin","Admin Role","RBAC","Least Privilege"],"keywords":["Google Admin Role - Required Privileges Missing","Google Admin Console / Directory API","A delegated administrator can sign in but cannot complete a user, group, OU, or security operation.","Insufficient privileges","Google Workspace","Google Admin console","Admin SDK","Directory API","Admin Role","RBAC","Least Privilege"],"errorCode":"Insufficient privileges","eventId":"","severity":"High","summary":"A delegated administrator can sign in but cannot complete a user, group, OU, or security operation.","rootCause":"The assigned role lacks one or more dependent privileges or is scoped to the wrong organizational unit.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Compare the attempted function with Google's current role-to-privilege mapping, add only the required dependent privileges and OU scope, then sign in again and retest. Preserve separation of duties.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Google Admin Role - Required Privileges Missing.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace - Administrator User Guide.pdf; Directory API manage roles.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace - Administrator User Guide.pdf; Directory API manage roles","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Admin Role","RBAC","Least Privilege"],"articleCategories":["Google Workspace","Cloud Administration","Admin Role","RBAC","Least Privilege"],"aliases":["Insufficient privileges","Google Admin Role - Required Privileges Missing"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65006,"title":"Directory API 401 - Authentication Required or Invalid Token","category":"Google Workspace","product":"Google Admin SDK Directory API","tags":["Google Workspace","Google Admin","OAuth 2.0","API Authentication","Access Token"],"keywords":["Directory API 401 - Authentication Required or Invalid Token","Google Admin SDK Directory API","A Directory API request returns HTTP 401 and is not authenticated.","401 Unauthorized","Google Workspace","Google Admin console","Admin SDK","Directory API","OAuth 2.0","API Authentication","Access Token"],"errorCode":"401 Unauthorized","eventId":"","severity":"High","summary":"A Directory API request returns HTTP 401 and is not authenticated.","rootCause":"The access token is absent, expired, malformed, issued for the wrong client or subject, or cannot be refreshed.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Inspect the sanitized authentication flow, client identity, token audience and expiry, service-account delegation, and clock; obtain a new token through the supported OAuth flow and retry without logging secrets.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Directory API 401 - Authentication Required or Invalid Token.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Directory API authorization documentation.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Directory API authorization documentation","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","OAuth 2.0","API Authentication","Access Token"],"articleCategories":["Google Workspace","Cloud Administration","OAuth 2.0","API Authentication","Access Token"],"aliases":["401 Unauthorized","Directory API 401 - Authentication Required or Invalid Token"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65007,"title":"Directory API 403 - Insufficient OAuth Scope or Admin Privilege","category":"Google Workspace","product":"Google Admin SDK Directory API","tags":["Google Workspace","Google Admin","OAuth Scope","Domain-wide Delegation","Authorization"],"keywords":["Directory API 403 - Insufficient OAuth Scope or Admin Privilege","Google Admin SDK Directory API","A validly authenticated Directory API request is forbidden.","403 Forbidden","Google Workspace","Google Admin console","Admin SDK","Directory API","OAuth Scope","Domain-wide Delegation","Authorization"],"errorCode":"403 Forbidden","eventId":"","severity":"High","summary":"A validly authenticated Directory API request is forbidden.","rootCause":"The token lacks the required Directory API scope, the delegated subject lacks the necessary admin privilege, domain-wide delegation is absent or misconfigured, or policy blocks the operation.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Identify the exact method, compare it with the required least-privilege OAuth scope and administrator role, verify domain-wide delegation where applicable, reauthorize deliberately, and retry with a redacted request.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Directory API 403 - Insufficient OAuth Scope or Admin Privilege.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Directory API authorization and role documentation.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Directory API authorization and role documentation","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","OAuth Scope","Domain-wide Delegation","Authorization"],"articleCategories":["Google Workspace","Cloud Administration","OAuth Scope","Domain-wide Delegation","Authorization"],"aliases":["403 Forbidden","Directory API 403 - Insufficient OAuth Scope or Admin Privilege"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65008,"title":"Directory API 429 - Quota or Rate Limit Exceeded","category":"Google Workspace","product":"Google Admin SDK Directory API","tags":["Google Workspace","Google Admin","API Quota","Rate Limit","Exponential Backoff"],"keywords":["Directory API 429 - Quota or Rate Limit Exceeded","Google Admin SDK Directory API","The Directory API throttles an automation request because it exceeds an applicable quota or operation limit.","429 Too Many Requests","Google Workspace","Google Admin console","Admin SDK","Directory API","API Quota","Rate Limit","Exponential Backoff"],"errorCode":"429 Too Many Requests","eventId":"","severity":"High","summary":"The Directory API throttles an automation request because it exceeds an applicable quota or operation limit.","rootCause":"The client sends bursts, retries without backoff, fails to paginate efficiently, or exceeds a per-customer or per-method limit.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Stop the retry storm, identify the quota metric, add truncated exponential backoff with jitter, reduce concurrency and batch size, cache safe reads, and resume gradually while monitoring errors.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Directory API 429 - Quota or Rate Limit Exceeded.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Directory API limits and quotas.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Directory API limits and quotas","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","API Quota","Rate Limit","Exponential Backoff"],"articleCategories":["Google Workspace","Cloud Administration","API Quota","Rate Limit","Exponential Backoff"],"aliases":["429 Too Many Requests","Directory API 429 - Quota or Rate Limit Exceeded"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65009,"title":"Directory API 503 - Long Pagination Request Timed Out","category":"Google Workspace","product":"Google Admin SDK Directory API","tags":["Google Workspace","Google Admin","Pagination","nextPageToken","backendError"],"keywords":["Directory API 503 - Long Pagination Request Timed Out","Google Admin SDK Directory API","A large users or devices enumeration returns 503 Service unavailable while using nextPageToken.","503 Service unavailable","Google Workspace","Google Admin console","Admin SDK","Directory API","Pagination","nextPageToken","backendError"],"errorCode":"503 Service unavailable","eventId":"","severity":"High","summary":"A large users or devices enumeration returns 503 Service unavailable while using nextPageToken.","rootCause":"A paginated retrieval takes longer than the Directory API's documented 60-minute limit.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Partition the population with supported search filters so each enumeration completes within the limit, preserve page-token state only for its intended query, and retry failed partitions with bounded backoff.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Directory API 503 - Long Pagination Request Timed Out.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Directory API troubleshoot error codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Directory API troubleshoot error codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Pagination","nextPageToken","backendError"],"articleCategories":["Google Workspace","Cloud Administration","Pagination","nextPageToken","backendError"],"aliases":["503 Service unavailable","Directory API 503 - Long Pagination Request Timed Out"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65010,"title":"Directory API - User Search Results Are Stale","category":"Google Workspace","product":"Google Admin SDK Directory API","tags":["Google Workspace","Google Admin","User Search","Eventual Consistency","Propagation"],"keywords":["Directory API - User Search Results Are Stale","Google Admin SDK Directory API","A newly updated user does not immediately appear with the expected attributes in Directory API search results.","Search propagation delay","Google Workspace","Google Admin console","Admin SDK","Directory API","User Search","Eventual Consistency","Propagation"],"errorCode":"Search propagation delay","eventId":"","severity":"Medium","summary":"A newly updated user does not immediately appear with the expected attributes in Directory API search results.","rootCause":"Directory search indexes are eventually consistent; most updates appear within an hour, but Google documents that some can take up to 36 hours.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Retrieve the user directly by immutable ID or primary address to verify the authoritative object, record the update time, avoid duplicate provisioning, and allow documented indexing time before escalating a search-only discrepancy.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Directory API - User Search Results Are Stale.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Directory API search users.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Directory API search users","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","User Search","Eventual Consistency","Propagation"],"articleCategories":["Google Workspace","Cloud Administration","User Search","Eventual Consistency","Propagation"],"aliases":["Search propagation delay","Directory API - User Search Results Are Stale"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65011,"title":"Google Group - Member Addition Immediately After Creation Failed","category":"Google Workspace","product":"Google Groups / Directory API","tags":["Google Workspace","Google Admin","Google Groups","Group Member","Propagation"],"keywords":["Google Group - Member Addition Immediately After Creation Failed","Google Groups / Directory API","Adding a member or sending to a newly created Google Group fails immediately after group creation.","Group not ready","Google Workspace","Google Admin console","Admin SDK","Directory API","Google Groups","Group Member","Propagation"],"errorCode":"Group not ready","eventId":"","severity":"Medium","summary":"Adding a member or sending to a newly created Google Group fails immediately after group creation.","rootCause":"The new group has not finished propagating across Workspace services.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Confirm the group exists by unique ID, wait at least the documented initial propagation interval, then add members and test delivery. Use bounded retries rather than creating a duplicate group.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Google Group - Member Addition Immediately After Creation Failed.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Directory API manage groups.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Directory API manage groups","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Google Groups","Group Member","Propagation"],"articleCategories":["Google Workspace","Cloud Administration","Google Groups","Group Member","Propagation"],"aliases":["Group not ready","Google Group - Member Addition Immediately After Creation Failed"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65012,"title":"Google Group - Nested Membership Not Yet Effective","category":"Google Workspace","product":"Google Groups / Directory API","tags":["Google Workspace","Google Admin","Nested Groups","Membership","Propagation"],"keywords":["Google Group - Nested Membership Not Yet Effective","Google Groups / Directory API","Members of a child group do not immediately inherit access or membership through a parent group.","Nested group propagation delay","Google Workspace","Google Admin console","Admin SDK","Directory API","Nested Groups","Membership","Propagation"],"errorCode":"Nested group propagation delay","eventId":"","severity":"Medium","summary":"Members of a child group do not immediately inherit access or membership through a parent group.","rootCause":"Nested group membership propagation can take up to the documented interval and may not yet be reflected by the target service.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Verify direct child-to-parent membership and group types, wait through the documented propagation window, query membership again, and validate the target application's support for nested groups before changing access.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Google Group - Nested Membership Not Yet Effective.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Directory API limits and quotas.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Directory API limits and quotas","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Nested Groups","Membership","Propagation"],"articleCategories":["Google Workspace","Cloud Administration","Nested Groups","Membership","Propagation"],"aliases":["Nested group propagation delay","Google Group - Nested Membership Not Yet Effective"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65013,"title":"Directory API groups.list - customer and userKey Cannot Be Combined","category":"Google Workspace","product":"Google Admin SDK Directory API","tags":["Google Workspace","Google Admin","groups.list","Query Parameters","Google Groups"],"keywords":["Directory API groups.list - customer and userKey Cannot Be Combined","Google Admin SDK Directory API","A groups.list request returns an error when attempting to filter the account and a member in one call.","Invalid customer and userKey combination","Google Workspace","Google Admin console","Admin SDK","Directory API","groups.list","Query Parameters","Google Groups"],"errorCode":"Invalid customer and userKey combination","eventId":"","severity":"Medium","summary":"A groups.list request returns an error when attempting to filter the account and a member in one call.","rootCause":"The request includes both customer and userKey, a combination the Directory API does not support.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Make separate requests: use customer or domain to enumerate account groups, or use userKey to retrieve a member's groups. Join results locally using immutable group IDs if the workflow requires both views.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Directory API groups.list - customer and userKey Cannot Be Combined.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Directory API manage groups.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Directory API manage groups","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","groups.list","Query Parameters","Google Groups"],"articleCategories":["Google Workspace","Cloud Administration","groups.list","Query Parameters","Google Groups"],"aliases":["Invalid customer and userKey combination","Directory API groups.list - customer and userKey Cannot Be Combined"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65014,"title":"Google Workspace - User Alias Limit Reached","category":"Google Workspace","product":"Google Workspace / Directory API","tags":["Google Workspace","Google Admin","Email Alias","User Alias","Limit"],"keywords":["Google Workspace - User Alias Limit Reached","Google Workspace / Directory API","An administrator cannot add another email alias to a user.","Alias limit exceeded","Google Workspace","Google Admin console","Admin SDK","Directory API","Email Alias","User Alias","Limit"],"errorCode":"Alias limit exceeded","eventId":"","severity":"Medium","summary":"An administrator cannot add another email alias to a user.","rootCause":"The account reached Google's current limit of 30 aliases for that user or the alias is already assigned to another resource.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. List the user's aliases and search users and groups for the requested address, remove only an approved obsolete alias, or choose another address; verify mail routing after the change.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Google Workspace - User Alias Limit Reached.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace - Administrator User Guide.pdf; Directory API limits.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace - Administrator User Guide.pdf; Directory API limits","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Email Alias","User Alias","Limit"],"articleCategories":["Google Workspace","Cloud Administration","Email Alias","User Alias","Limit"],"aliases":["Alias limit exceeded","User Alias Limit Reached"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65015,"title":"Directory API - User Deletion Blocked by Google Vault Legal Hold","category":"Google Workspace","product":"Google Workspace / Google Vault","tags":["Google Workspace","Google Admin","Google Vault","Legal Hold","User Deletion"],"keywords":["Directory API - User Deletion Blocked by Google Vault Legal Hold","Google Workspace / Google Vault","Deleting a user returns an error because the account is under legal hold.","Could not delete user due to legal hold","Google Workspace","Google Admin console","Admin SDK","Directory API","Google Vault","Legal Hold","User Deletion"],"errorCode":"Could not delete user due to legal hold","eventId":"","severity":"Critical","summary":"Deleting a user returns an error because the account is under legal hold.","rootCause":"Google Vault retention or a legal hold prevents deletion to preserve governed data.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Stop the deletion workflow, preserve the error and user ID, contact the authorized Vault or legal administrator, and follow the organization's legal-hold process. Do not remove a hold solely to complete routine offboarding.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Directory API - User Deletion Blocked by Google Vault Legal Hold.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Directory API manage users.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Directory API manage users","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Google Vault","Legal Hold","User Deletion"],"articleCategories":["Google Workspace","Cloud Administration","Google Vault","Legal Hold","User Deletion"],"aliases":["Could not delete user due to legal hold","Directory API - User Deletion Blocked by Google Vault Legal Hold"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65016,"title":"Google Workspace - Restore a Recently Deleted User","category":"Google Workspace","product":"Google Admin Console / Directory API","tags":["Google Workspace","Google Admin","Undelete User","20-day Recovery","Super Admin"],"keywords":["Google Workspace - Restore a Recently Deleted User","Google Admin Console / Directory API","A Workspace user was deleted and must be recovered while still within Google's recovery window.","Deleted user restore","Google Workspace","Google Admin console","Admin SDK","Directory API","Undelete User","20-day Recovery","Super Admin"],"errorCode":"Deleted user restore","eventId":"","severity":"Critical","summary":"A Workspace user was deleted and must be recovered while still within Google's recovery window.","rootCause":"The user was deleted accidentally or before data, aliases, groups, licenses, and ownership transfers were completed.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Confirm the immutable user ID, deletion date, target OU, available license, Vault status, and name conflicts. Have a Super Admin undelete the user within the documented 20-day window, then validate sign-in, mail, groups, data, and security controls.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Google Workspace - Restore a Recently Deleted User.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Directory API manage users.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Directory API manage users","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Undelete User","20-day Recovery","Super Admin"],"articleCategories":["Google Workspace","Cloud Administration","Undelete User","20-day Recovery","Super Admin"],"aliases":["Deleted user restore","Restore a Recently Deleted User"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65017,"title":"Google Workspace Gmail - Users Are Not Receiving Mail","category":"Google Workspace","product":"Google Workspace Gmail","tags":["Google Workspace","Google Admin","Gmail","MX Records","Email Log Search","Mail Flow"],"keywords":["Google Workspace Gmail - Users Are Not Receiving Mail","Google Workspace Gmail","One or more managed users do not receive expected inbound messages.","Mail not received","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","MX Records","Email Log Search","Mail Flow","nslookup -type=MX <domain>"],"errorCode":"Mail not received","eventId":"","severity":"High","summary":"One or more managed users do not receive expected inbound messages.","rootCause":"MX records are wrong, the Workspace account or domain is suspended or incomplete, Gmail has an outage, routing or spam controls affected the message, or the sender never handed it to Google.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Verify current MX records and domain status, check the Workspace Status Dashboard, then use Email Log Search with the sender, recipient, and timestamp to identify acceptance, routing, rejection, quarantine, or delivery state.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Google Workspace Gmail - Users Are Not Receiving Mail.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace - Administrator User Guide.pdf; Google Workspace Help.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[{"shell":"Terminal","command":"nslookup -type=MX <domain>","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Google Workspace - Administrator User Guide.pdf; Google Workspace Help","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","MX Records","Email Log Search","Mail Flow"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","MX Records","Email Log Search","Mail Flow"],"aliases":["Mail not received","Google Workspace Gmail - Users Are Not Receiving Mail"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65018,"title":"Google Workspace - Domain Alias and Secondary Domain Confused","category":"Google Workspace","product":"Google Admin Console","tags":["Google Workspace","Google Admin","Domain Alias","Secondary Domain","Multiple Domains"],"keywords":["Google Workspace - Domain Alias and Secondary Domain Confused","Google Admin Console","Users cannot sign in with an alias-domain address, or administrators create the wrong type of additional domain.","Domain type mismatch","Google Workspace","Google Admin console","Admin SDK","Directory API","Domain Alias","Secondary Domain","Multiple Domains"],"errorCode":"Domain type mismatch","eventId":"","severity":"High","summary":"Users cannot sign in with an alias-domain address, or administrators create the wrong type of additional domain.","rootCause":"A domain alias supplies alternate addresses to existing users, while a secondary domain can contain distinct user accounts; their sign-in, billing, and identity behavior differs.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Document the identity requirement before adding the domain, verify ownership, choose domain alias for alternate addresses or secondary domain for distinct users, and test sign-in, mail, calendar, and sharing with pilot accounts.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Google Workspace - Domain Alias and Secondary Domain Confused.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace - Administrator User Guide.pdf; Directory API limits.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace - Administrator User Guide.pdf; Directory API limits","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Domain Alias","Secondary Domain","Multiple Domains"],"articleCategories":["Google Workspace","Cloud Administration","Domain Alias","Secondary Domain","Multiple Domains"],"aliases":["Domain type mismatch","Domain Alias and Secondary Domain Confused"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65019,"title":"Google Workspace Data Migration - Source Connection Failed","category":"Google Workspace","product":"Google Workspace Data Migration Service","tags":["Google Workspace","Google Admin","Data Migration","IMAP","Microsoft 365","Exchange"],"keywords":["Google Workspace Data Migration - Source Connection Failed","Google Workspace Data Migration Service","The Admin console cannot connect to the source Gmail, Workspace, Microsoft 365, Exchange, or IMAP environment.","Migration connection unsuccessful","Google Workspace","Google Admin console","Admin SDK","Directory API","Data Migration","IMAP","Microsoft 365","Exchange"],"errorCode":"Migration connection unsuccessful","eventId":"","severity":"High","summary":"The Admin console cannot connect to the source Gmail, Workspace, Microsoft 365, Exchange, or IMAP environment.","rootCause":"The source endpoint, protocol, port, role account, credentials, OAuth consent, TLS trust, or source-side access policy is incorrect.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Confirm the supported source type, endpoint and TLS port, test the least-privilege migration account, review source sign-in and firewall logs, and retry a single pilot mailbox before starting bulk migration.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Google Workspace Data Migration - Source Connection Failed.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace - Administrator User Guide.pdf; Google Workspace migration documentation.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace - Administrator User Guide.pdf; Google Workspace migration documentation","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Data Migration","IMAP","Microsoft 365","Exchange"],"articleCategories":["Google Workspace","Cloud Administration","Data Migration","IMAP","Microsoft 365","Exchange"],"aliases":["Migration connection unsuccessful","Google Workspace Data Migration - Source Connection Failed"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65020,"title":"Google Workspace Data Migration - CSV Mapping Errors","category":"Google Workspace","product":"Google Workspace Data Migration Service","tags":["Google Workspace","Google Admin","Data Migration","CSV","Mailbox Mapping"],"keywords":["Google Workspace Data Migration - CSV Mapping Errors","Google Workspace Data Migration Service","A bulk migration CSV contains invalid source-to-destination mappings and cannot start cleanly.","Migration CSV error","Google Workspace","Google Admin console","Admin SDK","Directory API","Data Migration","CSV","Mailbox Mapping"],"errorCode":"Migration CSV error","eventId":"","severity":"High","summary":"A bulk migration CSV contains invalid source-to-destination mappings and cannot start cleanly.","rootCause":"Addresses are malformed, destination users do not exist, columns or encoding are wrong, duplicates exist, or a mapping points to the wrong account.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Download the current template, validate every destination user, normalize encoding and addresses, remove duplicates, test a small sample, and correct all errors rather than using Ignore errors for an unreviewed production migration.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Google Workspace Data Migration - CSV Mapping Errors.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace - Administrator User Guide.pdf.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace - Administrator User Guide.pdf","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Data Migration","CSV","Mailbox Mapping"],"articleCategories":["Google Workspace","Cloud Administration","Data Migration","CSV","Mailbox Mapping"],"aliases":["Migration CSV error","Google Workspace Data Migration - CSV Mapping Errors"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65021,"title":"Google Workspace IMAP - Client Cannot Authenticate","category":"Google Workspace","product":"Google Workspace Gmail / IMAP","tags":["Google Workspace","Google Admin","IMAP","SMTP","OAuth","Port 993"],"keywords":["Google Workspace IMAP - Client Cannot Authenticate","Google Workspace Gmail / IMAP","An IMAP mail client cannot authenticate to a managed Google Workspace mailbox.","IMAP authentication failed","Google Workspace","Google Admin console","Admin SDK","Directory API","IMAP","SMTP","OAuth","Port 993","Test-NetConnection imap.gmail.com -Port 993","Test-NetConnection smtp.gmail.com -Port 587"],"errorCode":"IMAP authentication failed","eventId":"","severity":"High","summary":"An IMAP mail client cannot authenticate to a managed Google Workspace mailbox.","rootCause":"IMAP or the client is restricted by admin policy, OAuth is unsupported or misconfigured, the account requires modern authentication, or the client uses incorrect host, TLS, or port settings.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Confirm Gmail and IMAP access policy, use a currently supported OAuth-capable client, verify imap.gmail.com on TLS port 993 and smtp.gmail.com with supported TLS submission, and review account security events. Do not enable weak sign-in methods as a workaround.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Google Workspace IMAP - Client Cannot Authenticate.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace - Administrator User Guide.pdf; Google Workspace Gmail documentation.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[{"shell":"PowerShell","command":"Test-NetConnection imap.gmail.com -Port 993","risk":"Low","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Test-NetConnection smtp.gmail.com -Port 587","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Google Workspace - Administrator User Guide.pdf; Google Workspace Gmail documentation","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["cross-platform"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","IMAP","SMTP","OAuth","Port 993"],"articleCategories":["Google Workspace","Cloud Administration","IMAP","SMTP","OAuth","Port 993"],"aliases":["IMAP authentication failed","Google Workspace IMAP - Client Cannot Authenticate"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65022,"title":"GWSMO - Outlook Sync Installation or Connection Failed","category":"Google Workspace","product":"Google Workspace Sync for Microsoft Outlook","tags":["Google Workspace","Google Admin","GWSMO","Outlook","Port 443","Profile"],"keywords":["GWSMO - Outlook Sync Installation or Connection Failed","Google Workspace Sync for Microsoft Outlook","GWSMO cannot install, create a profile, or synchronize Outlook data with Google Workspace.","GWSMO sync failed","Google Workspace","Google Admin console","Admin SDK","Directory API","GWSMO","Outlook","Port 443","Profile","Test-NetConnection accounts.google.com -Port 443"],"errorCode":"GWSMO sync failed","eventId":"","severity":"High","summary":"GWSMO cannot install, create a profile, or synchronize Outlook data with Google Workspace.","rootCause":"The Outlook and installer bitness do not match, HTTPS access is blocked, the Windows or Outlook version is unsupported, the profile is damaged, or authentication and Workspace policy prevent connection.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Confirm current GWSMO support, Windows and Outlook architecture, install the matching enterprise package, test outbound HTTPS, review GWSMO trace logs and account authorization, and validate with a new test profile before replacing the user's working profile.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified GWSMO - Outlook Sync Installation or Connection Failed.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace - Administrator User Guide.pdf; Google Workspace Admin Help.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[{"shell":"PowerShell","command":"Test-NetConnection accounts.google.com -Port 443","risk":"Low","safetyLevel":"Safe Read-Only"}],"sourceDocument":"Google Workspace - Administrator User Guide.pdf; Google Workspace Admin Help","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["windows"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","GWSMO","Outlook","Port 443","Profile"],"articleCategories":["Google Workspace","Cloud Administration","GWSMO","Outlook","Port 443","Profile"],"aliases":["GWSMO sync failed","GWSMO - Outlook Sync Installation or Connection Failed"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65023,"title":"Directory API - Custom User Schema Validation Failed","category":"Google Workspace","product":"Google Admin SDK Directory API","tags":["Google Workspace","Google Admin","Custom User Fields","Schema","Directory Search"],"keywords":["Directory API - Custom User Schema Validation Failed","Google Admin SDK Directory API","Creating or updating a custom user schema fails validation or the field cannot be searched as intended.","Invalid custom schema","Google Workspace","Google Admin console","Admin SDK","Directory API","Custom User Fields","Schema","Directory Search"],"errorCode":"Invalid custom schema","eventId":"","severity":"Medium","summary":"Creating or updating a custom user schema fails validation or the field cannot be searched as intended.","rootCause":"The schema or field name, data type, multi-value definition, visibility, range, or indexed value does not match Directory API requirements.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Retrieve existing schemas, validate the proposed unique names and field types, minimize visibility, test the schema with a non-sensitive field and pilot user, then query it using the documented custom-field syntax.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Directory API - Custom User Schema Validation Failed.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Directory API manage custom user fields.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Directory API manage custom user fields","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Custom User Fields","Schema","Directory Search"],"articleCategories":["Google Workspace","Cloud Administration","Custom User Fields","Schema","Directory Search"],"aliases":["Invalid custom schema","Directory API - Custom User Schema Validation Failed"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65024,"title":"Google Admin Role - Custom Role or Assignment Limit Reached","category":"Google Workspace","product":"Google Admin SDK Directory API","tags":["Google Workspace","Google Admin","Admin Role","Role Assignment","Security Group","Quota"],"keywords":["Google Admin Role - Custom Role or Assignment Limit Reached","Google Admin SDK Directory API","Creating a custom administrator role or role assignment fails because the organization or OU reached a documented limit.","Role assignment limit exceeded","Google Workspace","Google Admin console","Admin SDK","Directory API","Admin Role","Role Assignment","Security Group","Quota"],"errorCode":"Role assignment limit exceeded","eventId":"","severity":"High","summary":"Creating a custom administrator role or role assignment fails because the organization or OU reached a documented limit.","rootCause":"The tenant has accumulated too many custom roles, per-OU assignments, or group role assignments.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Inventory active roles and assignments by immutable ID, identify redundant grants, consolidate privileges into reviewed roles or security groups, remove obsolete assignments through change control, and retry while preserving least privilege.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Google Admin Role - Custom Role or Assignment Limit Reached.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Directory API manage roles.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Directory API manage roles","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Admin Role","Role Assignment","Security Group","Quota"],"articleCategories":["Google Workspace","Cloud Administration","Admin Role","Role Assignment","Security Group","Quota"],"aliases":["Role assignment limit exceeded","Google Admin Role - Custom Role or Assignment Limit Reached"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65025,"title":"450 4.2.1 - Recipient Rate Limited","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","450","4.2.1"],"keywords":["450 4.2.1 - Recipient Rate Limited","Google Workspace Gmail / SMTP","Gmail returned 450 4.2.1: Recipient Rate Limited.","450 4.2.1","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","450","4.2.1"],"errorCode":"450 4.2.1","eventId":"","severity":"Medium","summary":"Gmail returned 450 4.2.1: Recipient Rate Limited.","rootCause":"The recipient is receiving mail too quickly or the customer's peak relay limit was exceeded.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Queue the message and retry later with exponential backoff; reduce delivery concurrency and review Gmail receiving or SMTP relay limits.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 450 4.2.1 - Recipient Rate Limited.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","450","4.2.1"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","450","4.2.1"],"aliases":["450 4.2.1","450 4.2.1 - Recipient Rate Limited"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65026,"title":"452 4.2.2 - Recipient Storage Full","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","452","4.2.2"],"keywords":["452 4.2.2 - Recipient Storage Full","Google Workspace Gmail / SMTP","Gmail returned 452 4.2.2: Recipient Storage Full.","452 4.2.2","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","452","4.2.2"],"errorCode":"452 4.2.2","eventId":"","severity":"Medium","summary":"Gmail returned 452 4.2.2: Recipient Storage Full.","rootCause":"The recipient inbox has no available storage.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Have the recipient or administrator review Workspace storage, safely remove or archive approved data, and retry after quota updates propagate.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 452 4.2.2 - Recipient Storage Full.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","452","4.2.2"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","452","4.2.2"],"aliases":["452 4.2.2","452 4.2.2 - Recipient Storage Full"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65027,"title":"451 4.3.0 - Temporary Server Rejection","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","451","4.3.0"],"keywords":["451 4.3.0 - Temporary Server Rejection","Google Workspace Gmail / SMTP","Gmail returned 451 4.3.0: Temporary Server Rejection.","451 4.3.0","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","451","4.3.0"],"errorCode":"451 4.3.0","eventId":"","severity":"Medium","summary":"Gmail returned 451 4.3.0: Temporary Server Rejection.","rootCause":"Gmail temporarily rejected the message, or one SMTP transaction targeted multiple destination domains.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Retry with bounded backoff; send different destination domains in separate transactions and preserve the SMTP transcript if failures continue.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 451 4.3.0 - Temporary Server Rejection.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","451","4.3.0"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","451","4.3.0"],"aliases":["451 4.3.0","451 4.3.0 - Temporary Server Rejection"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65028,"title":"421 4.3.0 - Temporary System Problem","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","421","4.3.0"],"keywords":["421 4.3.0 - Temporary System Problem","Google Workspace Gmail / SMTP","Gmail returned 421 4.3.0: Temporary System Problem.","421 4.3.0","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","421","4.3.0"],"errorCode":"421 4.3.0","eventId":"","severity":"Medium","summary":"Gmail returned 421 4.3.0: Temporary System Problem.","rootCause":"A temporary Gmail system condition prevented delivery.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Keep the message queued and retry later with bounded exponential backoff; check Google Workspace service status before changing configuration.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 421 4.3.0 - Temporary System Problem.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","421","4.3.0"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","421","4.3.0"],"aliases":["421 4.3.0","421 4.3.0 - Temporary System Problem"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65029,"title":"451 4.4.2 - SMTP Connection Timeout","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","451","4.4.2"],"keywords":["451 4.4.2 - SMTP Connection Timeout","Google Workspace Gmail / SMTP","Gmail returned 451 4.4.2: SMTP Connection Timeout.","451 4.4.2","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","451","4.4.2"],"errorCode":"451 4.4.2","eventId":"","severity":"Medium","summary":"Gmail returned 451 4.4.2: SMTP Connection Timeout.","rootCause":"The SMTP session timed out before the transaction completed.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Check latency, packet loss, firewall idle timers and server load, then retry the complete transaction without reusing an expired session.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 451 4.4.2 - SMTP Connection Timeout.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","451","4.4.2"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","451","4.4.2"],"aliases":["451 4.4.2","451 4.4.2 - SMTP Connection Timeout"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65030,"title":"421 4.4.5 - Gmail Server Busy","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","421","4.4.5"],"keywords":["421 4.4.5 - Gmail Server Busy","Google Workspace Gmail / SMTP","Gmail returned 421 4.4.5: Gmail Server Busy.","421 4.4.5","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","421","4.4.5"],"errorCode":"421 4.4.5","eventId":"","severity":"Medium","summary":"Gmail returned 421 4.4.5: Gmail Server Busy.","rootCause":"The receiving server is temporarily busy.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Queue the message, reduce parallel connections and retry later with exponential backoff and jitter.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 421 4.4.5 - Gmail Server Busy.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","421","4.4.5"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","421","4.4.5"],"aliases":["421 4.4.5","421 4.4.5 - Gmail Server Busy"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65031,"title":"451 4.5.0 - SMTP Protocol Violation","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","451","4.5.0"],"keywords":["451 4.5.0 - SMTP Protocol Violation","Google Workspace Gmail / SMTP","Gmail returned 451 4.5.0: SMTP Protocol Violation.","451 4.5.0","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","451","4.5.0"],"errorCode":"451 4.5.0","eventId":"","severity":"Medium","summary":"Gmail returned 451 4.5.0: SMTP Protocol Violation.","rootCause":"The sending system issued a command or transaction that violates SMTP requirements.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Capture the SMTP transcript, correct the client or relay command sequence to RFC 5321 behavior, update the mail software and retry.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 451 4.5.0 - SMTP Protocol Violation.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","451","4.5.0"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","451","4.5.0"],"aliases":["451 4.5.0","451 4.5.0 - SMTP Protocol Violation"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65032,"title":"452 4.5.3 - Too Many Recipients or Domain Policy Size","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","452","4.5.3"],"keywords":["452 4.5.3 - Too Many Recipients or Domain Policy Size","Google Workspace Gmail / SMTP","Gmail returned 452 4.5.3: Too Many Recipients or Domain Policy Size.","452 4.5.3","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","452","4.5.3"],"errorCode":"452 4.5.3","eventId":"","severity":"Medium","summary":"Gmail returned 452 4.5.3: Too Many Recipients or Domain Policy Size.","rootCause":"The transaction exceeds a recipient-count or per-domain policy limit.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Split recipients into smaller approved transactions, review routing policy and sending limits, and avoid automated retry bursts.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 452 4.5.3 - Too Many Recipients or Domain Policy Size.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","452","4.5.3"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","452","4.5.3"],"aliases":["452 4.5.3","452 4.5.3 - Too Many Recipients or Domain Policy Size"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65033,"title":"421 4.7.0 - Temporary Policy, Reputation, DNS or TLS Rejection","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","421","4.7.0"],"keywords":["421 4.7.0 - Temporary Policy, Reputation, DNS or TLS Rejection","Google Workspace Gmail / SMTP","Gmail returned 421 4.7.0: Temporary Policy, Reputation, DNS or TLS Rejection.","421 4.7.0","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","421","4.7.0"],"errorCode":"421 4.7.0","eventId":"","severity":"Medium","summary":"Gmail returned 421 4.7.0: Temporary Policy, Reputation, DNS or TLS Rejection.","rootCause":"Gmail temporarily limited the connection because of policy, allowlist, reverse-DNS, reputation, content, TLS or session conditions.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Match the complete response text, then correct the named condition: reconnect, verify allowlisting and forward-confirmed PTR, require TLS, or remediate sender reputation and content before retrying gradually.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 421 4.7.0 - Temporary Policy, Reputation, DNS or TLS Rejection.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","421","4.7.0"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","421","4.7.0"],"aliases":["421 4.7.0","421 4.7.0 - Temporary Policy, Reputation, DNS or TLS Rejection"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65034,"title":"454 4.7.0 - Temporary SMTP Authentication Failure","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","454","4.7.0"],"keywords":["454 4.7.0 - Temporary SMTP Authentication Failure","Google Workspace Gmail / SMTP","Gmail returned 454 4.7.0: Temporary SMTP Authentication Failure.","454 4.7.0","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","454","4.7.0"],"errorCode":"454 4.7.0","eventId":"","severity":"Medium","summary":"Gmail returned 454 4.7.0: Temporary SMTP Authentication Failure.","rootCause":"Too many login attempts or a temporary authentication service problem blocked SMTP authentication.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Stop repeated attempts, verify the supported OAuth or app authentication flow and account state, wait through the temporary lockout, then retry once.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 454 4.7.0 - Temporary SMTP Authentication Failure.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","454","4.7.0"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","454","4.7.0"],"aliases":["454 4.7.0","454 4.7.0 - Temporary SMTP Authentication Failure"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65035,"title":"451 4.7.23 - Sending IP PTR Mismatch","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","451","4.7.23"],"keywords":["451 4.7.23 - Sending IP PTR Mismatch","Google Workspace Gmail / SMTP","Gmail returned 451 4.7.23: Sending IP PTR Mismatch.","451 4.7.23","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","451","4.7.23"],"errorCode":"451 4.7.23","eventId":"","severity":"Medium","summary":"Gmail returned 451 4.7.23: Sending IP PTR Mismatch.","rootCause":"The sending IP lacks a PTR record or its forward DNS does not resolve back to that IP.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Publish provider-controlled reverse DNS, ensure the PTR hostname resolves forward to the same IP, verify externally, then resume mail slowly.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 451 4.7.23 - Sending IP PTR Mismatch.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","451","4.7.23"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","451","4.7.23"],"aliases":["451 4.7.23","451 4.7.23 - Sending IP PTR Mismatch"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65036,"title":"451 4.7.24 - Suspicious SPF Record","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","451","4.7.24"],"keywords":["451 4.7.24 - Suspicious SPF Record","Google Workspace Gmail / SMTP","Gmail returned 451 4.7.24: Suspicious SPF Record.","451 4.7.24","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","451","4.7.24"],"errorCode":"451 4.7.24","eventId":"","severity":"Medium","summary":"Gmail returned 451 4.7.24: Suspicious SPF Record.","rootCause":"The sending domain's SPF record contains one or more suspicious entries.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Audit the single effective SPF TXT record, remove unauthorized or invalid mechanisms through DNS change control, validate syntax and retry after propagation.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 451 4.7.24 - Suspicious SPF Record.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","451","4.7.24"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","451","4.7.24"],"aliases":["451 4.7.24","451 4.7.24 - Suspicious SPF Record"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65037,"title":"451 4.7.26 - Temporary DMARC Authentication Failure","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","451","4.7.26"],"keywords":["451 4.7.26 - Temporary DMARC Authentication Failure","Google Workspace Gmail / SMTP","Gmail returned 451 4.7.26: Temporary DMARC Authentication Failure.","451 4.7.26","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","451","4.7.26"],"errorCode":"451 4.7.26","eventId":"","severity":"Medium","summary":"Gmail returned 451 4.7.26: Temporary DMARC Authentication Failure.","rootCause":"DMARC rejects unauthenticated mail but temporary DNS failures prevented a conclusive authentication result.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Verify authoritative DNS availability and SPF/DKIM records, correct transient DNS failures, confirm alignment, then retry without weakening DMARC.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 451 4.7.26 - Temporary DMARC Authentication Failure.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","451","4.7.26"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","451","4.7.26"],"aliases":["451 4.7.26","451 4.7.26 - Temporary DMARC Authentication Failure"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65038,"title":"421 4.7.26 - Unauthenticated Mail Rate Limited","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","421","4.7.26"],"keywords":["421 4.7.26 - Unauthenticated Mail Rate Limited","Google Workspace Gmail / SMTP","Gmail returned 421 4.7.26: Unauthenticated Mail Rate Limited.","421 4.7.26","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","421","4.7.26"],"errorCode":"421 4.7.26","eventId":"","severity":"Medium","summary":"Gmail returned 421 4.7.26: Unauthenticated Mail Rate Limited.","rootCause":"Neither SPF nor DKIM passed, so Gmail temporarily rate limited the sender.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Configure and validate SPF or DKIM for all sending sources, confirm the visible From domain aligns as required, then resume with controlled volume.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 421 4.7.26 - Unauthenticated Mail Rate Limited.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","421","4.7.26"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","421","4.7.26"],"aliases":["421 4.7.26","421 4.7.26 - Unauthenticated Mail Rate Limited"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65039,"title":"421 4.7.27 - SPF Failure Rate Limited","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","421","4.7.27"],"keywords":["421 4.7.27 - SPF Failure Rate Limited","Google Workspace Gmail / SMTP","Gmail returned 421 4.7.27: SPF Failure Rate Limited.","421 4.7.27","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","421","4.7.27"],"errorCode":"421 4.7.27","eventId":"","severity":"Medium","summary":"Gmail returned 421 4.7.27: SPF Failure Rate Limited.","rootCause":"Bulk mail did not pass SPF authentication.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Authorize the actual sending service in one valid SPF record, avoid excess DNS lookups, validate the received header result and retry gradually.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 421 4.7.27 - SPF Failure Rate Limited.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","421","4.7.27"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","421","4.7.27"],"aliases":["421 4.7.27","421 4.7.27 - SPF Failure Rate Limited"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65040,"title":"421 4.7.28 - Unusual or Unsolicited Mail Rate","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","421","4.7.28"],"keywords":["421 4.7.28 - Unusual or Unsolicited Mail Rate","Google Workspace Gmail / SMTP","Gmail returned 421 4.7.28: Unusual or Unsolicited Mail Rate.","421 4.7.28","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","421","4.7.28"],"errorCode":"421 4.7.28","eventId":"","severity":"Medium","summary":"Gmail returned 421 4.7.28: Unusual or Unsolicited Mail Rate.","rootCause":"Gmail detected unusual volume, unsolicited traffic, repeated Message-IDs, or poor reputation from the sender, domain, netblock or linked URL.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Pause bulk delivery, investigate account or application abuse, correct list hygiene and Message-ID generation, monitor reputation, then ramp up only legitimate opted-in mail.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 421 4.7.28 - Unusual or Unsolicited Mail Rate.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","421","4.7.28"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","421","4.7.28"],"aliases":["421 4.7.28","421 4.7.28 - Unusual or Unsolicited Mail Rate"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65041,"title":"421 4.7.29 - TLS Required for Bulk Mail","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","421","4.7.29"],"keywords":["421 4.7.29 - TLS Required for Bulk Mail","Google Workspace Gmail / SMTP","Gmail returned 421 4.7.29: TLS Required for Bulk Mail.","421 4.7.29","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","421","4.7.29"],"errorCode":"421 4.7.29","eventId":"","severity":"Medium","summary":"Gmail returned 421 4.7.29: TLS Required for Bulk Mail.","rootCause":"Bulk mail was sent without a TLS-protected SMTP connection.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Enable STARTTLS with current protocols and trusted certificates on the outbound relay, verify negotiated TLS, then retry.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 421 4.7.29 - TLS Required for Bulk Mail.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","421","4.7.29"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","421","4.7.29"],"aliases":["421 4.7.29","421 4.7.29 - TLS Required for Bulk Mail"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65042,"title":"421 4.7.30 - DKIM Failure Rate Limited","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","421","4.7.30"],"keywords":["421 4.7.30 - DKIM Failure Rate Limited","Google Workspace Gmail / SMTP","Gmail returned 421 4.7.30: DKIM Failure Rate Limited.","421 4.7.30","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","421","4.7.30"],"errorCode":"421 4.7.30","eventId":"","severity":"Medium","summary":"Gmail returned 421 4.7.30: DKIM Failure Rate Limited.","rootCause":"Bulk mail did not pass DKIM authentication.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Verify the selector record, signing domain, canonicalization and unmodified signed headers; rotate or republish keys safely and confirm DKIM passes before retrying.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 421 4.7.30 - DKIM Failure Rate Limited.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","421","4.7.30"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","421","4.7.30"],"aliases":["421 4.7.30","421 4.7.30 - DKIM Failure Rate Limited"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65043,"title":"421 4.7.32 - DMARC Alignment Rate Limited","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","421","4.7.32"],"keywords":["421 4.7.32 - DMARC Alignment Rate Limited","Google Workspace Gmail / SMTP","Gmail returned 421 4.7.32: DMARC Alignment Rate Limited.","421 4.7.32","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","421","4.7.32"],"errorCode":"421 4.7.32","eventId":"","severity":"Medium","summary":"Gmail returned 421 4.7.32: DMARC Alignment Rate Limited.","rootCause":"The visible From domain does not align with the authenticated SPF or DKIM organizational domain.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Align the RFC5322 From domain with a passing SPF MAIL FROM or DKIM d= domain, validate DMARC and retry gradually.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 421 4.7.32 - DMARC Alignment Rate Limited.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","421","4.7.32"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","421","4.7.32"],"aliases":["421 4.7.32","421 4.7.32 - DMARC Alignment Rate Limited"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65044,"title":"421 4.7.40 - DMARC Record or Policy Missing","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","421","4.7.40"],"keywords":["421 4.7.40 - DMARC Record or Policy Missing","Google Workspace Gmail / SMTP","Gmail returned 421 4.7.40: DMARC Record or Policy Missing.","421 4.7.40","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","421","4.7.40"],"errorCode":"421 4.7.40","eventId":"","severity":"Medium","summary":"Gmail returned 421 4.7.40: DMARC Record or Policy Missing.","rootCause":"A bulk sender lacks a DMARC record or an explicit DMARC policy.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Publish a valid DMARC TXT record through change control, begin with monitored policy appropriate to the organization, validate it publicly and retry.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 421 4.7.40 - DMARC Record or Policy Missing.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","421","4.7.40"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","421","4.7.40"],"aliases":["421 4.7.40","421 4.7.40 - DMARC Record or Policy Missing"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65045,"title":"421 5.7.32 - DMARC Alignment Blocked","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","421","5.7.32"],"keywords":["421 5.7.32 - DMARC Alignment Blocked","Google Workspace Gmail / SMTP","Gmail returned 421 5.7.32: DMARC Alignment Blocked.","421 5.7.32","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","421","5.7.32"],"errorCode":"421 5.7.32","eventId":"","severity":"Medium","summary":"Gmail returned 421 5.7.32: DMARC Alignment Blocked.","rootCause":"Gmail blocked the message because the visible From domain did not align with authenticated SPF or DKIM.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Correct SPF or DKIM domain alignment and confirm DMARC passes before resending; do not bypass authentication policy.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 421 5.7.32 - DMARC Alignment Blocked.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","421","5.7.32"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","421","5.7.32"],"aliases":["421 5.7.32","421 5.7.32 - DMARC Alignment Blocked"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65046,"title":"550 5.1.1 - Recipient Account Does Not Exist","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","550","5.1.1"],"keywords":["550 5.1.1 - Recipient Account Does Not Exist","Google Workspace Gmail / SMTP","Gmail returned 550 5.1.1: Recipient Account Does Not Exist.","550 5.1.1","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.1.1"],"errorCode":"550 5.1.1","eventId":"","severity":"High","summary":"Gmail returned 550 5.1.1: Recipient Account Does Not Exist.","rootCause":"The recipient address does not map to an active Gmail account.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Check spelling and spaces, verify the user, alias or group in the Admin console, and correct the address rather than repeatedly retrying.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 550 5.1.1 - Recipient Account Does Not Exist.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.1.1"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","550","5.1.1"],"aliases":["550 5.1.1","550 5.1.1 - Recipient Account Does Not Exist"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65047,"title":"553 5.1.2 - Recipient Domain Not Found","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","553","5.1.2"],"keywords":["553 5.1.2 - Recipient Domain Not Found","Google Workspace Gmail / SMTP","Gmail returned 553 5.1.2: Recipient Domain Not Found.","553 5.1.2","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","553","5.1.2"],"errorCode":"553 5.1.2","eventId":"","severity":"High","summary":"Gmail returned 553 5.1.2: Recipient Domain Not Found.","rootCause":"DNS cannot locate the recipient domain.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Correct the domain spelling, confirm its authoritative DNS and MX records resolve publicly, and resend only after the domain is valid.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 553 5.1.2 - Recipient Domain Not Found.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","553","5.1.2"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","553","5.1.2"],"aliases":["553 5.1.2","553 5.1.2 - Recipient Domain Not Found"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65048,"title":"553 5.1.3 - Invalid Recipient Address Syntax","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","553","5.1.3"],"keywords":["553 5.1.3 - Invalid Recipient Address Syntax","Google Workspace Gmail / SMTP","Gmail returned 553 5.1.3: Invalid Recipient Address Syntax.","553 5.1.3","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","553","5.1.3"],"errorCode":"553 5.1.3","eventId":"","severity":"High","summary":"Gmail returned 553 5.1.3: Invalid Recipient Address Syntax.","rootCause":"The recipient is not a valid RFC 5321 mailbox address.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Correct the envelope recipient syntax in the application or address list and retry with a valid address.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 553 5.1.3 - Invalid Recipient Address Syntax.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","553","5.1.3"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","553","5.1.3"],"aliases":["553 5.1.3","553 5.1.3 - Invalid Recipient Address Syntax"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65049,"title":"553 5.1.7 - Invalid Sender Address Syntax","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","553","5.1.7"],"keywords":["553 5.1.7 - Invalid Sender Address Syntax","Google Workspace Gmail / SMTP","Gmail returned 553 5.1.7: Invalid Sender Address Syntax.","553 5.1.7","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","553","5.1.7"],"errorCode":"553 5.1.7","eventId":"","severity":"High","summary":"Gmail returned 553 5.1.7: Invalid Sender Address Syntax.","rootCause":"The envelope sender is not a valid RFC 5321 mailbox address.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Correct the MAIL FROM generation, application configuration or bounce address and validate it before retrying.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 553 5.1.7 - Invalid Sender Address Syntax.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","553","5.1.7"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","553","5.1.7"],"aliases":["553 5.1.7","553 5.1.7 - Invalid Sender Address Syntax"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65050,"title":"550 5.2.1 - Recipient Inactive or Receiving Limit","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","550","5.2.1"],"keywords":["550 5.2.1 - Recipient Inactive or Receiving Limit","Google Workspace Gmail / SMTP","Gmail returned 550 5.2.1: Recipient Inactive or Receiving Limit.","550 5.2.1","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.2.1"],"errorCode":"550 5.2.1","eventId":"","severity":"High","summary":"Gmail returned 550 5.2.1: Recipient Inactive or Receiving Limit.","rootCause":"The account is inactive or is receiving mail at a rate that prevents further delivery.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Have an administrator confirm the user is active and Gmail is enabled; if active, stop retries and wait for the receiving limit to clear.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 550 5.2.1 - Recipient Inactive or Receiving Limit.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.2.1"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","550","5.2.1"],"aliases":["550 5.2.1","550 5.2.1 - Recipient Inactive or Receiving Limit"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65051,"title":"552 5.2.2 - Recipient Storage Full and Inactive","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","552","5.2.2"],"keywords":["552 5.2.2 - Recipient Storage Full and Inactive","Google Workspace Gmail / SMTP","Gmail returned 552 5.2.2: Recipient Storage Full and Inactive.","552 5.2.2","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","552","5.2.2"],"errorCode":"552 5.2.2","eventId":"","severity":"High","summary":"Gmail returned 552 5.2.2: Recipient Storage Full and Inactive.","rootCause":"The recipient inbox is over quota and cannot accept mail.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Have the recipient or administrator restore available storage and account activity, allow quota state to update, then resend.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 552 5.2.2 - Recipient Storage Full and Inactive.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","552","5.2.2"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","552","5.2.2"],"aliases":["552 5.2.2","552 5.2.2 - Recipient Storage Full and Inactive"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65052,"title":"552 5.3.4 - Message, Attachment or Header Limit Exceeded","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","552","5.3.4"],"keywords":["552 5.3.4 - Message, Attachment or Header Limit Exceeded","Google Workspace Gmail / SMTP","Gmail returned 552 5.3.4: Message, Attachment or Header Limit Exceeded.","552 5.3.4","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","552","5.3.4"],"errorCode":"552 5.3.4","eventId":"","severity":"High","summary":"Gmail returned 552 5.3.4: Message, Attachment or Header Limit Exceeded.","rootCause":"The message exceeds Gmail limits for total size, attachment count, header bytes, header fields or an individual header.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Reduce attachments or use an approved file-sharing link, remove malformed or oversized headers, and resend a standards-compliant message.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 552 5.3.4 - Message, Attachment or Header Limit Exceeded.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","552","5.3.4"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","552","5.3.4"],"aliases":["552 5.3.4","552 5.3.4 - Message, Attachment or Header Limit Exceeded"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65053,"title":"550 5.4.5 - Daily Sending or Relay Limit Exceeded","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","550","5.4.5"],"keywords":["550 5.4.5 - Daily Sending or Relay Limit Exceeded","Google Workspace Gmail / SMTP","Gmail returned 550 5.4.5: Daily Sending or Relay Limit Exceeded.","550 5.4.5","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.4.5"],"errorCode":"550 5.4.5","eventId":"","severity":"High","summary":"Gmail returned 550 5.4.5: Daily Sending or Relay Limit Exceeded.","rootCause":"The user exceeded a daily Gmail or SMTP relay sending limit.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Stop sending, investigate automation or compromise, wait for the documented limit window to reset, and redesign legitimate bulk workflows within policy.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 550 5.4.5 - Daily Sending or Relay Limit Exceeded.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.4.5"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","550","5.4.5"],"aliases":["550 5.4.5","550 5.4.5 - Daily Sending or Relay Limit Exceeded"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65054,"title":"554 5.4.6 - Mail Routing Loop Over 50 Hops","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","554","5.4.6"],"keywords":["554 5.4.6 - Mail Routing Loop Over 50 Hops","Google Workspace Gmail / SMTP","Gmail returned 554 5.4.6: Mail Routing Loop Over 50 Hops.","554 5.4.6","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","554","5.4.6"],"errorCode":"554 5.4.6","eventId":"","severity":"High","summary":"Gmail returned 554 5.4.6: Mail Routing Loop Over 50 Hops.","rootCause":"The message traversed more than 50 relays, indicating a routing loop.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Trace Received headers, disable the looping route or forwarding rule under change control, test one message end-to-end and then release queued mail.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 554 5.4.6 - Mail Routing Loop Over 50 Hops.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","554","5.4.6"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","554","5.4.6"],"aliases":["554 5.4.6","554 5.4.6 - Mail Routing Loop Over 50 Hops"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65055,"title":"503 5.5.1 - SMTP Commands Out of Sequence","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","503","5.5.1"],"keywords":["503 5.5.1 - SMTP Commands Out of Sequence","Google Workspace Gmail / SMTP","Gmail returned 503 5.5.1: SMTP Commands Out of Sequence.","503 5.5.1","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","503","5.5.1"],"errorCode":"503 5.5.1","eventId":"","severity":"High","summary":"Gmail returned 503 5.5.1: SMTP Commands Out of Sequence.","rootCause":"The client sent DATA, BDAT, RCPT, HELO or another command in an invalid order.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Capture the transcript, fix the client state machine to send EHLO, MAIL FROM, RCPT TO and DATA/BDAT in the supported sequence, then retest.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 503 5.5.1 - SMTP Commands Out of Sequence.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","503","5.5.1"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","503","5.5.1"],"aliases":["503 5.5.1","503 5.5.1 - SMTP Commands Out of Sequence"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65056,"title":"502 5.5.1 - SMTP Command Unsupported","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","502","5.5.1"],"keywords":["502 5.5.1 - SMTP Command Unsupported","Google Workspace Gmail / SMTP","Gmail returned 502 5.5.1: SMTP Command Unsupported.","502 5.5.1","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","502","5.5.1"],"errorCode":"502 5.5.1","eventId":"","severity":"High","summary":"Gmail returned 502 5.5.1: SMTP Command Unsupported.","rootCause":"The client sent an unimplemented or unrecognized command.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Update or reconfigure the sender to use supported SMTP commands and stop after repeated unrecognized-command responses.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 502 5.5.1 - SMTP Command Unsupported.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","502","5.5.1"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","502","5.5.1"],"aliases":["502 5.5.1","502 5.5.1 - SMTP Command Unsupported"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65057,"title":"501 5.5.2 - SMTP Response Syntax Cannot Be Decoded","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","501","5.5.2"],"keywords":["501 5.5.2 - SMTP Response Syntax Cannot Be Decoded","Google Workspace Gmail / SMTP","Gmail returned 501 5.5.2: SMTP Response Syntax Cannot Be Decoded.","501 5.5.2","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","501","5.5.2"],"errorCode":"501 5.5.2","eventId":"","severity":"High","summary":"Gmail returned 501 5.5.2: SMTP Response Syntax Cannot Be Decoded.","rootCause":"The SMTP command or response contains invalid syntax.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Inspect the raw session for malformed arguments, line endings or encoding, correct the sending library and retest.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 501 5.5.2 - SMTP Response Syntax Cannot Be Decoded.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","501","5.5.2"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","501","5.5.2"],"aliases":["501 5.5.2","501 5.5.2 - SMTP Response Syntax Cannot Be Decoded"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65058,"title":"555 5.5.2 - SMTP Command Syntax Error","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","555","5.5.2"],"keywords":["555 5.5.2 - SMTP Command Syntax Error","Google Workspace Gmail / SMTP","Gmail returned 555 5.5.2: SMTP Command Syntax Error.","555 5.5.2","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","555","5.5.2"],"errorCode":"555 5.5.2","eventId":"","severity":"High","summary":"Gmail returned 555 5.5.2: SMTP Command Syntax Error.","rootCause":"The SMTP command parameters do not conform to the supported syntax.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Correct the client command syntax to RFC 5321 requirements, update obsolete software and retry a minimal transaction.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 555 5.5.2 - SMTP Command Syntax Error.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","555","5.5.2"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","555","5.5.2"],"aliases":["555 5.5.2","555 5.5.2 - SMTP Command Syntax Error"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65059,"title":"550 5.5.3 - Too Many Recipients","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","550","5.5.3"],"keywords":["550 5.5.3 - Too Many Recipients","Google Workspace Gmail / SMTP","Gmail returned 550 5.5.3: Too Many Recipients.","550 5.5.3","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.5.3"],"errorCode":"550 5.5.3","eventId":"","severity":"High","summary":"Gmail returned 550 5.5.3: Too Many Recipients.","rootCause":"The sender supplied more recipients than Gmail accepts in one transaction.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Split delivery into smaller policy-compliant batches and apply rate controls rather than immediately replaying the same recipient list.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 550 5.5.3 - Too Many Recipients.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.5.3"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","550","5.5.3"],"aliases":["550 5.5.3","550 5.5.3 - Too Many Recipients"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65060,"title":"501 5.5.4 - Invalid HELO or EHLO Argument","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","501","5.5.4"],"keywords":["501 5.5.4 - Invalid HELO or EHLO Argument","Google Workspace Gmail / SMTP","Gmail returned 501 5.5.4: Invalid HELO or EHLO Argument.","501 5.5.4","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","501","5.5.4"],"errorCode":"501 5.5.4","eventId":"","severity":"High","summary":"Gmail returned 501 5.5.4: Invalid HELO or EHLO Argument.","rootCause":"The HELO/EHLO name is empty or invalid.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Configure the relay to present a valid fully qualified hostname with consistent forward and reverse DNS, then reconnect.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 501 5.5.4 - Invalid HELO or EHLO Argument.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","501","5.5.4"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","501","5.5.4"],"aliases":["501 5.5.4","501 5.5.4 - Invalid HELO or EHLO Argument"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65061,"title":"554 5.6.0 - Malformed Email Message","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","554","5.6.0"],"keywords":["554 5.6.0 - Malformed Email Message","Google Workspace Gmail / SMTP","Gmail returned 554 5.6.0: Malformed Email Message.","554 5.6.0","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","554","5.6.0"],"errorCode":"554 5.6.0","eventId":"","severity":"High","summary":"Gmail returned 554 5.6.0: Malformed Email Message.","rootCause":"The message is not acceptable RFC 5322 content.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Inspect headers and MIME boundaries, correct the generating application, verify one From and Message-ID header, and resend a clean message.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 554 5.6.0 - Malformed Email Message.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","554","5.6.0"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","554","5.6.0"],"aliases":["554 5.6.0","554 5.6.0 - Malformed Email Message"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65062,"title":"552 5.7.0 - Message Blocked for Security Content","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","552","5.7.0"],"keywords":["552 5.7.0 - Message Blocked for Security Content","Google Workspace Gmail / SMTP","Gmail returned 552 5.7.0: Message Blocked for Security Content.","552 5.7.0","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","552","5.7.0"],"errorCode":"552 5.7.0","eventId":"","severity":"High","summary":"Gmail returned 552 5.7.0: Message Blocked for Security Content.","rootCause":"Gmail detected a prohibited or risky file type or message payload.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Do not disguise or rename blocked executable content; remove it and use an approved secure distribution method after security review.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 552 5.7.0 - Message Blocked for Security Content.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","552","5.7.0"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","552","5.7.0"],"aliases":["552 5.7.0","552 5.7.0 - Message Blocked for Security Content"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65063,"title":"550 5.7.0 - SMTP Relay Denied or Sending Suspended","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","550","5.7.0"],"keywords":["550 5.7.0 - SMTP Relay Denied or Sending Suspended","Google Workspace Gmail / SMTP","Gmail returned 550 5.7.0: SMTP Relay Denied or Sending Suspended.","550 5.7.0","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.7.0"],"errorCode":"550 5.7.0","eventId":"","severity":"High","summary":"Gmail returned 550 5.7.0: SMTP Relay Denied or Sending Suspended.","rootCause":"The sending IP or domain is not registered for Workspace relay, credentials are invalid, sending is denied, or the account is suspended for abuse.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Verify the relay allowlist, envelope domain and authentication settings; investigate abuse and restore the account through approved admin procedures before retrying.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 550 5.7.0 - SMTP Relay Denied or Sending Suspended.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.7.0"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","550","5.7.0"],"aliases":["550 5.7.0","550 5.7.0 - SMTP Relay Denied or Sending Suspended"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65064,"title":"554 5.7.0 - Too Many Unauthenticated Commands","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","554","5.7.0"],"keywords":["554 5.7.0 - Too Many Unauthenticated Commands","Google Workspace Gmail / SMTP","Gmail returned 554 5.7.0: Too Many Unauthenticated Commands.","554 5.7.0","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","554","5.7.0"],"errorCode":"554 5.7.0","eventId":"","severity":"High","summary":"Gmail returned 554 5.7.0: Too Many Unauthenticated Commands.","rootCause":"The client issued excessive commands without authenticating.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Stop the client, configure supported authentication before mail commands, rotate exposed credentials if indicated and reconnect once.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 554 5.7.0 - Too Many Unauthenticated Commands.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","554","5.7.0"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","554","5.7.0"],"aliases":["554 5.7.0","554 5.7.0 - Too Many Unauthenticated Commands"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65065,"title":"530 5.7.0 - Authentication or STARTTLS Required","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","530","5.7.0"],"keywords":["530 5.7.0 - Authentication or STARTTLS Required","Google Workspace Gmail / SMTP","Gmail returned 530 5.7.0: Authentication or STARTTLS Required.","530 5.7.0","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","530","5.7.0"],"errorCode":"530 5.7.0","eventId":"","severity":"High","summary":"Gmail returned 530 5.7.0: Authentication or STARTTLS Required.","rootCause":"The server requires authentication or STARTTLS before accepting the transaction.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Enable STARTTLS and supported OAuth or approved application authentication, verify certificate trust and retry without transmitting credentials in clear text.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 530 5.7.0 - Authentication or STARTTLS Required.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","530","5.7.0"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","530","5.7.0"],"aliases":["530 5.7.0","530 5.7.0 - Authentication or STARTTLS Required"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65066,"title":"550 5.7.1 - Gmail Policy, Reputation, Relay or RFC Rejection","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","550","5.7.1"],"keywords":["550 5.7.1 - Gmail Policy, Reputation, Relay or RFC Rejection","Google Workspace Gmail / SMTP","Gmail returned 550 5.7.1: Gmail Policy, Reputation, Relay or RFC Rejection.","550 5.7.1","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.7.1"],"errorCode":"550 5.7.1","eventId":"","severity":"High","summary":"Gmail returned 550 5.7.1: Gmail Policy, Reputation, Relay or RFC Rejection.","rootCause":"Gmail permanently rejected the message for policy, spam reputation, unauthorized relay, sending limits, invalid headers, IPv6 requirements or noncompliance.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Use the complete response to identify the named condition; correct policy, relay identity, PTR/authentication, reputation, limits or RFC 5322 headers before resending.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 550 5.7.1 - Gmail Policy, Reputation, Relay or RFC Rejection.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.7.1"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","550","5.7.1"],"aliases":["550 5.7.1","550 5.7.1 - Gmail Policy, Reputation, Relay or RFC Rejection"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65067,"title":"523 5.7.10 - Commands Pipelined After STARTTLS","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","523","5.7.10"],"keywords":["523 5.7.10 - Commands Pipelined After STARTTLS","Google Workspace Gmail / SMTP","Gmail returned 523 5.7.10: Commands Pipelined After STARTTLS.","523 5.7.10","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","523","5.7.10"],"errorCode":"523 5.7.10","eventId":"","severity":"High","summary":"Gmail returned 523 5.7.10: Commands Pipelined After STARTTLS.","rootCause":"The client pipelined SMTP commands after STARTTLS instead of waiting for TLS negotiation.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Disable invalid pipelining, complete the TLS handshake, issue EHLO again over the protected channel and restart the transaction.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 523 5.7.10 - Commands Pipelined After STARTTLS.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","523","5.7.10"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","523","5.7.10"],"aliases":["523 5.7.10","523 5.7.10 - Commands Pipelined After STARTTLS"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65068,"title":"501 5.7.11 - STARTTLS Syntax Parameters Not Allowed","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","501","5.7.11"],"keywords":["501 5.7.11 - STARTTLS Syntax Parameters Not Allowed","Google Workspace Gmail / SMTP","Gmail returned 501 5.7.11: STARTTLS Syntax Parameters Not Allowed.","501 5.7.11","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","501","5.7.11"],"errorCode":"501 5.7.11","eventId":"","severity":"High","summary":"Gmail returned 501 5.7.11: STARTTLS Syntax Parameters Not Allowed.","rootCause":"The client supplied parameters to a command that accepts none.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Correct the client to issue STARTTLS without parameters and update the SMTP library if it generates the invalid form.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 501 5.7.11 - STARTTLS Syntax Parameters Not Allowed.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","501","5.7.11"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","501","5.7.11"],"aliases":["501 5.7.11","501 5.7.11 - STARTTLS Syntax Parameters Not Allowed"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65069,"title":"534 5.7.14 - Browser Sign-In Required","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","534","5.7.14"],"keywords":["534 5.7.14 - Browser Sign-In Required","Google Workspace Gmail / SMTP","Gmail returned 534 5.7.14: Browser Sign-In Required.","534 5.7.14","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","534","5.7.14"],"errorCode":"534 5.7.14","eventId":"","severity":"High","summary":"Gmail returned 534 5.7.14: Browser Sign-In Required.","rootCause":"Google requires the user to complete an interactive browser sign-in or security check before SMTP access.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Have the verified user complete the Google browser sign-in and security challenge, review account alerts, then retry using supported OAuth authentication.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 534 5.7.14 - Browser Sign-In Required.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","534","5.7.14"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","534","5.7.14"],"aliases":["534 5.7.14","534 5.7.14 - Browser Sign-In Required"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65070,"title":"550 5.7.24 - Suspicious SPF Record Blocked","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","550","5.7.24"],"keywords":["550 5.7.24 - Suspicious SPF Record Blocked","Google Workspace Gmail / SMTP","Gmail returned 550 5.7.24: Suspicious SPF Record Blocked.","550 5.7.24","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.7.24"],"errorCode":"550 5.7.24","eventId":"","severity":"High","summary":"Gmail returned 550 5.7.24: Suspicious SPF Record Blocked.","rootCause":"The SPF record contains suspicious entries and Gmail permanently rejected the message.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Audit and correct the SPF record, remove unauthorized mechanisms, validate DNS and authentication results, then resend.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 550 5.7.24 - Suspicious SPF Record Blocked.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.7.24"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","550","5.7.24"],"aliases":["550 5.7.24","550 5.7.24 - Suspicious SPF Record Blocked"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65071,"title":"550 5.7.25 - Sending IP Has No Valid PTR","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","550","5.7.25"],"keywords":["550 5.7.25 - Sending IP Has No Valid PTR","Google Workspace Gmail / SMTP","Gmail returned 550 5.7.25: Sending IP Has No Valid PTR.","550 5.7.25","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.7.25"],"errorCode":"550 5.7.25","eventId":"","severity":"High","summary":"Gmail returned 550 5.7.25: Sending IP Has No Valid PTR.","rootCause":"The sending IP lacks forward-confirmed reverse DNS.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Ask the IP owner to publish a PTR whose hostname resolves back to the same IP, verify both directions and then retry.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 550 5.7.25 - Sending IP Has No Valid PTR.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.7.25"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","550","5.7.25"],"aliases":["550 5.7.25","550 5.7.25 - Sending IP Has No Valid PTR"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65072,"title":"550 5.7.26 - Sender Unauthenticated or DMARC Rejected","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","550","5.7.26"],"keywords":["550 5.7.26 - Sender Unauthenticated or DMARC Rejected","Google Workspace Gmail / SMTP","Gmail returned 550 5.7.26: Sender Unauthenticated or DMARC Rejected.","550 5.7.26","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.7.26"],"errorCode":"550 5.7.26","eventId":"","severity":"High","summary":"Gmail returned 550 5.7.26: Sender Unauthenticated or DMARC Rejected.","rootCause":"SPF and DKIM failed, SPF hard-failed, or the domain's DMARC policy rejected unauthenticated mail.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Correct SPF authorization or DKIM signing and alignment, validate DMARC results from the actual sending path, then resend; do not weaken the recipient's policy.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 550 5.7.26 - Sender Unauthenticated or DMARC Rejected.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.7.26"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","550","5.7.26"],"aliases":["550 5.7.26","550 5.7.26 - Sender Unauthenticated or DMARC Rejected"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65073,"title":"550 5.7.27 - SPF Authentication Failed","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","550","5.7.27"],"keywords":["550 5.7.27 - SPF Authentication Failed","Google Workspace Gmail / SMTP","Gmail returned 550 5.7.27: SPF Authentication Failed.","550 5.7.27","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.7.27"],"errorCode":"550 5.7.27","eventId":"","severity":"High","summary":"Gmail returned 550 5.7.27: SPF Authentication Failed.","rootCause":"Bulk mail failed SPF and was permanently rejected.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Authorize the exact sender in a valid SPF record, validate lookup count and received results, then resend from the authenticated source.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 550 5.7.27 - SPF Authentication Failed.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.7.27"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","550","5.7.27"],"aliases":["550 5.7.27","550 5.7.27 - SPF Authentication Failed"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65074,"title":"550 5.7.28 - Unsolicited Mail Rate Blocked","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","550","5.7.28"],"keywords":["550 5.7.28 - Unsolicited Mail Rate Blocked","Google Workspace Gmail / SMTP","Gmail returned 550 5.7.28: Unsolicited Mail Rate Blocked.","550 5.7.28","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.7.28"],"errorCode":"550 5.7.28","eventId":"","severity":"High","summary":"Gmail returned 550 5.7.28: Unsolicited Mail Rate Blocked.","rootCause":"Gmail permanently blocked traffic associated with unusual unsolicited volume or reputation.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Stop delivery, investigate compromise and list acquisition, remove non-consenting recipients, remediate reputation and resume only compliant mail slowly.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 550 5.7.28 - Unsolicited Mail Rate Blocked.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.7.28"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","550","5.7.28"],"aliases":["550 5.7.28","550 5.7.28 - Unsolicited Mail Rate Blocked"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65075,"title":"550 5.7.29 - TLS Missing for Bulk Mail","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","550","5.7.29"],"keywords":["550 5.7.29 - TLS Missing for Bulk Mail","Google Workspace Gmail / SMTP","Gmail returned 550 5.7.29: TLS Missing for Bulk Mail.","550 5.7.29","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.7.29"],"errorCode":"550 5.7.29","eventId":"","severity":"High","summary":"Gmail returned 550 5.7.29: TLS Missing for Bulk Mail.","rootCause":"Gmail blocked bulk mail sent without TLS.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Require STARTTLS on the outbound path with current protocols and trusted certificates, verify negotiation and resend.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 550 5.7.29 - TLS Missing for Bulk Mail.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.7.29"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","550","5.7.29"],"aliases":["550 5.7.29","550 5.7.29 - TLS Missing for Bulk Mail"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65076,"title":"550 5.7.30 - DKIM Authentication Failed","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","550","5.7.30"],"keywords":["550 5.7.30 - DKIM Authentication Failed","Google Workspace Gmail / SMTP","Gmail returned 550 5.7.30: DKIM Authentication Failed.","550 5.7.30","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.7.30"],"errorCode":"550 5.7.30","eventId":"","severity":"High","summary":"Gmail returned 550 5.7.30: DKIM Authentication Failed.","rootCause":"Bulk mail failed DKIM and was permanently rejected.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Correct signing configuration and public selector records, confirm body and signed headers are not modified in transit, then resend after DKIM passes.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 550 5.7.30 - DKIM Authentication Failed.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.7.30"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","550","5.7.30"],"aliases":["550 5.7.30","550 5.7.30 - DKIM Authentication Failed"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65077,"title":"550 5.7.40 - DMARC Record or Policy Required","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","550","5.7.40"],"keywords":["550 5.7.40 - DMARC Record or Policy Required","Google Workspace Gmail / SMTP","Gmail returned 550 5.7.40: DMARC Record or Policy Required.","550 5.7.40","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.7.40"],"errorCode":"550 5.7.40","eventId":"","severity":"High","summary":"Gmail returned 550 5.7.40: DMARC Record or Policy Required.","rootCause":"A bulk sender has no DMARC record or no stated DMARC policy.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Publish and validate an organizationally approved DMARC policy, monitor reports and ensure SPF or DKIM alignment before resending.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 550 5.7.40 - DMARC Record or Policy Required.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","550","5.7.40"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","550","5.7.40"],"aliases":["550 5.7.40","550 5.7.40 - DMARC Record or Policy Required"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65078,"title":"504 5.7.40 - Unsupported Authentication Type or XOAUTH","category":"Google Workspace","product":"Google Workspace Gmail / SMTP","tags":["Google Workspace","Google Admin","Gmail","SMTP","Email Delivery","504","5.7.40"],"keywords":["504 5.7.40 - Unsupported Authentication Type or XOAUTH","Google Workspace Gmail / SMTP","Gmail returned 504 5.7.40: Unsupported Authentication Type or XOAUTH.","504 5.7.40","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","504","5.7.40"],"errorCode":"504 5.7.40","eventId":"","severity":"High","summary":"Gmail returned 504 5.7.40: Unsupported Authentication Type or XOAUTH.","rootCause":"The client requested an unrecognized authentication method or obsolete XOAUTH.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Update the application to Google's supported OAuth 2.0 SASL mechanism or another currently approved Workspace authentication method.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified 504 5.7.40 - Unsupported Authentication Type or XOAUTH.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Gmail SMTP errors and codes.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Gmail SMTP errors and codes","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail","SMTP","Email Delivery","504","5.7.40"],"articleCategories":["Google Workspace","Cloud Administration","Gmail","SMTP","Email Delivery","504","5.7.40"],"aliases":["504 5.7.40","504 5.7.40 - Unsupported Authentication Type or XOAUTH"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65079,"title":"Google Workspace Gmail - User Cannot Sign In","category":"Google Workspace","product":"Google Workspace Gmail","tags":["Google Workspace","Google Admin","Sign-in","Gmail","2-Step Verification"],"keywords":["Google Workspace Gmail - User Cannot Sign In","Google Workspace Gmail","A managed user cannot sign in to Gmail even though the service is expected to be available.","Gmail sign-in failed","Google Workspace","Google Admin console","Admin SDK","Directory API","Sign-in","Gmail","2-Step Verification"],"errorCode":"Gmail sign-in failed","eventId":"","severity":"High","summary":"A managed user cannot sign in to Gmail even though the service is expected to be available.","rootCause":"The address or password is wrong, the account is suspended or deleted, Gmail is disabled, 2-Step Verification or a login challenge blocks access, SSO is failing, or the browser session selects the wrong identity.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Confirm the exact managed account in a private session, user and Gmail service status, license, password and SSO path; review User log events and use the appropriate password, login-challenge or 2SV recovery workflow without requesting the user's secret.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Google Workspace Gmail - User Cannot Sign In.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Google Workspace users can't sign in to Gmail accounts.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Google Workspace users can't sign in to Gmail accounts","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Sign-in","Gmail","2-Step Verification"],"articleCategories":["Google Workspace","Cloud Administration","Sign-in","Gmail","2-Step Verification"],"aliases":["Gmail sign-in failed","Google Workspace Gmail - User Cannot Sign In"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65080,"title":"Google Workspace - Google Account Already Exists","category":"Google Workspace","product":"Google Workspace Signup","tags":["Google Workspace","Google Admin","Conflicting Account","Domain Verification","Signup"],"keywords":["Google Workspace - Google Account Already Exists","Google Workspace Signup","The first administrator address cannot be used because it is already associated with another Google service.","Google Account already exists","Google Workspace","Google Admin console","Admin SDK","Directory API","Conflicting Account","Domain Verification","Signup"],"errorCode":"Google Account already exists","eventId":"","severity":"High","summary":"The first administrator address cannot be used because it is already associated with another Google service.","rootCause":"The requested address is a conflicting unmanaged Google Account.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Sign up with a different accessible address at the domain, verify the domain, then create the intended administrator address and remove unnecessary privileges from the temporary administrator. Resolve the conflicting account after setup.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Google Workspace - Google Account Already Exists.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Google Account already exists error.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Google Account already exists error","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Conflicting Account","Domain Verification","Signup"],"articleCategories":["Google Workspace","Cloud Administration","Conflicting Account","Domain Verification","Signup"],"aliases":["Google Account already exists","Google Account Already Exists"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65081,"title":"Google Admin Console - Managed Account Sign-In Failed","category":"Google Workspace","product":"Google Admin Console","tags":["Google Workspace","Google Admin","Admin Console","2SV","Context-Aware Access","Account Recovery"],"keywords":["Google Admin Console - Managed Account Sign-In Failed","Google Admin Console","An administrator cannot reach or sign in to admin.google.com.","Admin console sign-in failed","Google Workspace","Google Admin console","Admin SDK","Directory API","Admin Console","2SV","Context-Aware Access","Account Recovery"],"errorCode":"Admin console sign-in failed","eventId":"","severity":"Critical","summary":"An administrator cannot reach or sign in to admin.google.com.","rootCause":"The browser selected a consumer account, the address belongs to a domain alias, the account lacks admin rights, 2SV blocks access, the tenant is inactive, reseller credentials are required, or Context-Aware Access caused a lockout.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Try a private session with the primary-domain admin identity, verify role and tenant status, use another authorized admin for password or 2SV recovery, contact the reseller when applicable, and use Google's ownership-verification support path for total lockout. Reapply any removed Context-Aware policy immediately after recovery.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Google Admin Console - Managed Account Sign-In Failed.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Can't sign in to the Admin console.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Can't sign in to the Admin console","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Admin Console","2SV","Context-Aware Access","Account Recovery"],"articleCategories":["Google Workspace","Cloud Administration","Admin Console","2SV","Context-Aware Access","Account Recovery"],"aliases":["Admin console sign-in failed","Google Admin Console - Managed Account Sign-In Failed"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65082,"title":"Google Workspace - Identify and Secure a Compromised Account","category":"Google Workspace","product":"Google Workspace Security","tags":["Google Workspace","Google Admin","Incident Response","OAuth Tokens","Audit Logs","Security Keys"],"keywords":["Google Workspace - Identify and Secure a Compromised Account","Google Workspace Security","A user's Workspace account shows suspicious sign-ins, mail activity, settings or token use.","Suspected compromised account","Google Workspace","Google Admin console","Admin SDK","Directory API","Incident Response","OAuth Tokens","Audit Logs","Security Keys"],"errorCode":"Suspected compromised account","eventId":"","severity":"Critical","summary":"A user's Workspace account shows suspicious sign-ins, mail activity, settings or token use.","rootCause":"Credentials, session cookies, OAuth grants, app passwords, recovery details or a managed device may be compromised.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Temporarily suspend the account, which resets sign-in cookies and OAuth tokens; preserve evidence and review Admin, User, OAuth, Gmail, Drive, Groups and device activity; reset the password, revoke OAuth tokens and app passwords, remove malicious forwarding or filters, then unsuspend and enroll the verified user with phishing-resistant 2SV.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Google Workspace - Identify and Secure a Compromised Account.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Identify and secure compromised accounts.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Identify and secure compromised accounts","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Incident Response","OAuth Tokens","Audit Logs","Security Keys"],"articleCategories":["Google Workspace","Cloud Administration","Incident Response","OAuth Tokens","Audit Logs","Security Keys"],"aliases":["Suspected compromised account","Identify and Secure a Compromised Account"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65083,"title":"Google Workspace Gmail - Restore Permanently Deleted Email","category":"Google Workspace","product":"Google Workspace Gmail","tags":["Google Workspace","Google Admin","Gmail Restore","25-day Window","Google Vault","Data Recovery"],"keywords":["Google Workspace Gmail - Restore Permanently Deleted Email","Google Workspace Gmail","An administrator must recover messages after they have left a user's Trash.","Permanently deleted Gmail","Google Workspace","Google Admin console","Admin SDK","Directory API","Gmail Restore","25-day Window","Google Vault","Data Recovery"],"errorCode":"Permanently deleted Gmail","eventId":"","severity":"Critical","summary":"An administrator must recover messages after they have left a user's Trash.","rootCause":"The user deleted the messages more than 30 days ago, but they may still be within Google's additional 25-day administrator restore window or retained in Vault.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. If still in Trash, have the user restore the message. During the additional 25-day admin window, use Directory > Users > More options > Restore data, select the deletion date range and Gmail, then start Restore after confirming scope because it cannot be stopped. Beyond that window, search and export retained Vault data if a hold or retention rule applies; Vault cannot restore it directly to Gmail.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Google Workspace Gmail - Restore Permanently Deleted Email.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Restore a user's permanently deleted email.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Restore a user's permanently deleted email","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Gmail Restore","25-day Window","Google Vault","Data Recovery"],"articleCategories":["Google Workspace","Cloud Administration","Gmail Restore","25-day Window","Google Vault","Data Recovery"],"aliases":["Permanently deleted Gmail","Google Workspace Gmail - Restore Permanently Deleted Email"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65084,"title":"Google Workspace - Login Challenge or 2-Step Verification Lockout","category":"Google Workspace","product":"Google Workspace Identity","tags":["Google Workspace","Google Admin","2SV","Login Challenge","Backup Codes","Account Recovery"],"keywords":["Google Workspace - Login Challenge or 2-Step Verification Lockout","Google Workspace Identity","A user or administrator knows the password but cannot complete a login challenge or 2-Step Verification.","2-Step Verification lockout","Google Workspace","Google Admin console","Admin SDK","Directory API","2SV","Login Challenge","Backup Codes","Account Recovery"],"errorCode":"2-Step Verification lockout","eventId":"","severity":"High","summary":"A user or administrator knows the password but cannot complete a login challenge or 2-Step Verification.","rootCause":"The user lacks the enrolled factor, a suspicious-login challenge is active, an enforcement deadline passed, or an administrator lost the security key or recovery method.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. Verify the person's identity first. An authorized admin may temporarily disable a login challenge for its documented 10-minute access window or generate backup verification codes for an enrolled user. For an admin lockout, use another security administrator or Google's account-recovery flow; changing only the password does not clear a login challenge.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Google Workspace - Login Challenge or 2-Step Verification Lockout.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Troubleshoot login challenges, 2-Step Verification, and sign-in issues.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Troubleshoot login challenges, 2-Step Verification, and sign-in issues","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","2SV","Login Challenge","Backup Codes","Account Recovery"],"articleCategories":["Google Workspace","Cloud Administration","2SV","Login Challenge","Backup Codes","Account Recovery"],"aliases":["2-Step Verification lockout","Login Challenge or 2-Step Verification Lockout"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":65085,"title":"Google Workspace - Domain Already Used as Alias or Domain","category":"Google Workspace","product":"Google Workspace Domains","tags":["Google Workspace","Google Admin","Domain Conflict","Domain Alias","Secondary Domain","Reseller"],"keywords":["Google Workspace - Domain Already Used as Alias or Domain","Google Workspace Domains","A domain cannot be added because Google reports that it is already used as an alias or domain.","This domain name has already been used as an alias or domain","Google Workspace","Google Admin console","Admin SDK","Directory API","Domain Conflict","Domain Alias","Secondary Domain","Reseller"],"errorCode":"This domain name has already been used as an alias or domain","eventId":"","severity":"High","summary":"A domain cannot be added because Google reports that it is already used as an alias or domain.","rootCause":"The domain is still attached to this or another Workspace tenant, or its removal has not propagated.","resolution":"1. Record the affected account, domain, organizational unit, resource ID, timestamp, request ID, and complete message without exposing credentials or tokens.\n2. If recently removed, wait up to 24 hours, or up to 7 days for reseller-managed accounts. Confirm nobody in the organization controls the existing tenant; if ownership is unknown, submit Google's support form and complete domain-ownership verification before adding it.\n3. Review Admin audit, relevant service logs, licensing, role scope, and recent changes before modifying production data.\n4. Validate the original operation and confirm the intended user, group, domain, device, or message state.","emailScript":"Hello,\n\nWe reviewed the Google Workspace issue and identified Google Workspace - Domain Already Used as Alias or Domain.\n\nWe are checking the affected account, administrative settings, permissions, and service status before applying the appropriate correction.\n\nPlease let us know when the issue began and which users or messages are affected.\n\nThank you,\n\nIT Support","faqSteps":"Please send IT Support the complete message, affected email address or group, approximate time, and what you were trying to do. Do not send passwords, recovery codes, OAuth tokens, API keys, browser cookies, private email content, or unredacted audit exports.","notes":"Sources: Google Workspace Help - Can't add new domain to Google account.\nVerified: 2026-08-19.\n\nThe supplied Google Workspace Administrator User Guide was revised July 21, 2021 and is used only for general workflow context. Current Google documentation controls where menus, limits, authentication, licensing, or product behavior differ. Use least privilege and confirm Vault holds, data ownership, licenses, aliases, and recovery options before deleting or renaming resources.","commands":[],"sourceDocument":"Google Workspace Help - Can't add new domain to Google account","sourceAuthority":"Google","namespace":"GOOGLE-WORKSPACE","platforms":["platform-neutral"],"lastVerified":"2026-08-19","vendors":["Google"],"technologies":["Google Workspace","Admin SDK","Directory API","Domain Conflict","Domain Alias","Secondary Domain","Reseller"],"articleCategories":["Google Workspace","Cloud Administration","Domain Conflict","Domain Alias","Secondary Domain","Reseller"],"aliases":["This domain name has already been used as an alias or domain","Domain Already Used as Alias or Domain"],"dateAdded":"2026-08-19","lastUpdated":"2026-08-19"},{"id":67000,"title":"AADSTS1000104 - Resource Cloud Not Allowed on Identity Tenant","category":"Entra ID","product":"Microsoft Entra External ID / Cross-cloud B2B","tags":["Microsoft Entra ID","AADSTS","Authentication","Cross-cloud B2B","Azure Government","GCC High","DoD"],"keywords":["AADSTS1000104","XCB2BResourceCloudNotAllowedOnIdentityTenant","resource cloud not allowed","microsoftonline.us","login.microsoftonline.us","Azure Government","US Government cloud","commercial tenant","GCC","GCC High","DoD","sovereign cloud","national cloud","cross-cloud access","cross-tenant access","B2B collaboration","wrong Microsoft account"],"errorCode":"AADSTS1000104","eventId":"","severity":"High","summary":"Microsoft Entra rejected the sign-in because the requested resource belongs to a different Microsoft cloud than the user's identity tenant, and that cross-cloud relationship is not allowed. A common example is an Azure Government resource using microsoftonline.us being opened with a Commercial or GCC identity.","rootCause":"Microsoft cloud instances use separate identity, application, and resource endpoints, and their access tokens are not interchangeable. The user may have selected an account from the wrong cloud, or the resource and identity organizations may not have configured matching cross-cloud B2B collaboration. GCC uses the worldwide commercial endpoints, while GCC High and DoD use Azure Government endpoints. Custom applications can also cause this error when their authority, resource, scope, redirect URI, or app registration points to the wrong cloud.","resolution":"1. Record the affected application or link, intended account, timestamp, request ID, and correlation ID in the private support ticket; redact tenant and diagnostic identifiers from public posts.\n2. Confirm which Microsoft 365 environment owns the resource and which environment owns the user's home identity. Do not assume GCC uses microsoftonline.us: Commercial and GCC use the worldwide cloud, while GCC High and DoD use Azure Government.\n3. Use a private browser window and sign in with the intended account from the resource's cloud. If that account works, sign out of the stale session and remove only the incorrect cached account selection.\n4. If cross-cloud guest access is intended, administrators in both organizations must enable the partner Microsoft cloud, add the partner tenant ID under Cross-tenant access settings > Organizational settings, and configure the minimum required inbound and outbound B2B collaboration users, groups, and applications. Cross-cloud access is disabled by default; avoid granting access to every tenant or application unless required.\n5. Verify that the guest invitation or resource link targets the correct tenant and cloud. Reissue the invitation after the cross-cloud settings replicate if the existing guest relationship was created incorrectly.\n6. For a custom application, register or consent to the application in the correct cloud and correct its authority, resource, scope, redirect URI, and API endpoint. Tokens obtained from worldwide endpoints cannot be used against Azure Government resources, or vice versa.\n7. Review Microsoft Entra sign-in logs using the captured timestamp and correlation ID, then retry and confirm the sign-in reaches the intended resource. If settings are correct but the failure continues, open a Microsoft support case with the private diagnostic details.","emailScript":"Hello,\n\nWe reviewed the sign-in error and found that the requested Microsoft resource and the account being used are in different Microsoft cloud environments. Access between those environments is not currently permitted for this sign-in.\n\nPlease confirm the email address you intended to use and send us the application or link you were opening. We will verify the account selection and, if access is authorized, coordinate the required organization settings with the resource owner.\n\nPlease do not send your password or verification codes.\n\nThank you,\n\nIT Support","faqSteps":"1. Send IT Support the application or link you were opening, the email address you intended to use, a screenshot of the complete message, and the time it happened.\n2. Open a private or InPrivate browser window and try the link once with the intended work account.\n3. If you have accounts in more than one Microsoft organization, make sure you choose the account invited to this resource.\n4. Do not share your password, MFA code, tenant diagnostic details publicly, or repeatedly approve unexpected sign-in prompts.\n5. If the error remains, IT may need to coordinate secure cross-cloud guest access with the organization that owns the resource.","notes":"Official Microsoft symbolic name: XCB2BResourceCloudNotAllowedOnIdentityTenant. Microsoft defines AADSTS1000104 as a resource cloud that is not allowed on the identity tenant.\n\nCloud distinction: Commercial and Microsoft 365 GCC use the worldwide Azure cloud. GCC High and DoD use Azure Government; their identity authority is login.microsoftonline.us. Microsoft Graph endpoints also differ by environment, and tokens are not interchangeable.\n\nCross-cloud B2B collaboration is disabled by default and must be configured by both organizations under Microsoft cloud settings and organizational cross-tenant access settings. Apply least-privilege inbound and outbound B2B collaboration rules. B2B direct connect is not supported across cloud environments; use B2B collaboration where supported.\n\nA private browser test can identify the wrong cached account but cannot repair a tenant/cloud policy mismatch. Clearing cookies, resetting a password, or reinstalling the client should not be presented as the primary fix. Preserve request ID, correlation ID, and timestamp in a restricted ticket for sign-in-log correlation, but do not publish them in the KB.\n\nSources (verified 2026-08-20):\nhttps://learn.microsoft.com/en-us/entra/identity-platform/reference-error-codes\nhttps://learn.microsoft.com/en-us/entra/identity-platform/authentication-national-cloud\nhttps://learn.microsoft.com/en-us/graph/deployments\nhttps://learn.microsoft.com/en-us/entra/external-id/cross-cloud-settings\nhttps://learn.microsoft.com/en-us/microsoft-365/enterprise/cross-cloud-collaboration\nhttps://learn.microsoft.com/en-us/entra/external-id/cross-tenant-access-overview","commands":[],"sourceDocument":"Microsoft Entra error-code reference; Microsoft national-cloud and cross-cloud collaboration documentation","sourceAuthority":"Microsoft Learn","namespace":"AADSTS","platforms":["platform-neutral"],"lastVerified":"2026-08-20","vendors":["Microsoft"],"products":["Microsoft Entra ID","Microsoft Entra External ID","Microsoft 365","Azure Government"],"technologies":["OAuth 2.0","OpenID Connect","Cross-tenant Access","B2B Collaboration","National Clouds"],"articleCategories":["Entra ID","Authentication","Microsoft 365","Cloud Identity"],"aliases":["XCB2BResourceCloudNotAllowedOnIdentityTenant","Resource cloud microsoftonline.us is not allowed on identity tenant"],"dateAdded":"2026-08-20","lastUpdated":"2026-08-20"},{"id":64000,"title":"3 - Return without GoSub","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3","Access error 3","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Return without GoSub","Return without GoSub"],"errorCode":"3","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3: Return without GoSub","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3: Return without GoSub.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3","MS Access error 3","Return without GoSub"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64001,"title":"5 - Illegal function call","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["5","Access error 5","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Illegal function call","Illegal function call"],"errorCode":"5","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 5: Illegal function call","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 5: Illegal function call.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 5","MS Access error 5","Illegal function call"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64002,"title":"6 - Overflow","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["6","Access error 6","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Overflow","Overflow"],"errorCode":"6","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 6: Overflow","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 6: Overflow.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 6","MS Access error 6","Overflow"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64003,"title":"7 - Out of memory","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Resources"],"keywords":["7","Access error 7","Microsoft Access","MSACCESS","Jet","VBA","Resources","Out of memory","Out of memory"],"errorCode":"7","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 7: Out of memory","rootCause":"Access or Windows lacks sufficient memory, stack, handles, disk, or other resources for the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Save work, close unnecessary objects/applications, check memory, handles, disk and database size, then reproduce after a controlled restart and review for runaway queries or code.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 7: Out of memory.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Resources"],"articleCategories":["Microsoft Access","Legacy Software","Resources"],"aliases":["Microsoft Access 7","MS Access error 7","Out of memory"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64004,"title":"9 - Subscript out of range","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["9","Access error 9","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Subscript out of range","Subscript out of range"],"errorCode":"9","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 9: Subscript out of range","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 9: Subscript out of range.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 9","MS Access error 9","Subscript out of range"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64005,"title":"10 - Duplicate definition","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["10","Access error 10","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Duplicate definition","Duplicate definition"],"errorCode":"10","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 10: Duplicate definition","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 10: Duplicate definition.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 10","MS Access error 10","Duplicate definition"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64006,"title":"11 - Division by zero","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["11","Access error 11","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Division by zero","Division by zero"],"errorCode":"11","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 11: Division by zero","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 11: Division by zero.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 11","MS Access error 11","Division by zero"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64007,"title":"13 - Type mismatch","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["13","Access error 13","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Type mismatch","Type mismatch"],"errorCode":"13","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 13: Type mismatch","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 13: Type mismatch.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 13","MS Access error 13","Type mismatch"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64008,"title":"14 - Out of string space","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["14","Access error 14","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Out of string space","Out of string space"],"errorCode":"14","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 14: Out of string space","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 14: Out of string space.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 14","MS Access error 14","Out of string space"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64009,"title":"16 - String formula too complex","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["16","Access error 16","Microsoft Access","MSACCESS","Jet","VBA","Access UI","String formula too complex","String formula too complex"],"errorCode":"16","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 16: String formula too complex","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 16: String formula too complex.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 16","MS Access error 16","String formula too complex"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64010,"title":"17 - Can't continue","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["17","Access error 17","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't continue","Can't continue"],"errorCode":"17","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 17: Can't continue","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 17: Can't continue.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 17","MS Access error 17","Can't continue"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64011,"title":"19 - No Resume","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["19","Access error 19","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","No Resume","No Resume"],"errorCode":"19","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 19: No Resume","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 19: No Resume.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 19","MS Access error 19","No Resume"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64012,"title":"20 - Resume without error","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["20","Access error 20","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Resume without error","Resume without error"],"errorCode":"20","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 20: Resume without error","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 20: Resume without error.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 20","MS Access error 20","Resume without error"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64013,"title":"28 - Out of stack space","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Resources"],"keywords":["28","Access error 28","Microsoft Access","MSACCESS","Jet","VBA","Resources","Out of stack space","Out of stack space"],"errorCode":"28","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 28: Out of stack space","rootCause":"Access or Windows lacks sufficient memory, stack, handles, disk, or other resources for the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Save work, close unnecessary objects/applications, check memory, handles, disk and database size, then reproduce after a controlled restart and review for runaway queries or code.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 28: Out of stack space.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Resources"],"articleCategories":["Microsoft Access","Legacy Software","Resources"],"aliases":["Microsoft Access 28","MS Access error 28","Out of stack space"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64014,"title":"35 - Sub or Function not defined","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["35","Access error 35","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Sub or Function not defined","Sub or Function not defined"],"errorCode":"35","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 35: Sub or Function not defined","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 35: Sub or Function not defined.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 35","MS Access error 35","Sub or Function not defined"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64015,"title":"48 - Error in loading DLL","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["48","Access error 48","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Error in loading DLL","Error in loading DLL"],"errorCode":"48","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 48: Error in loading DLL","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 48: Error in loading DLL.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 48","MS Access error 48","Error in loading DLL"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64016,"title":"49 - Bad DLL calling convention","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["49","Access error 49","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Bad DLL calling convention","Bad DLL calling convention"],"errorCode":"49","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 49: Bad DLL calling convention","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 49: Bad DLL calling convention.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 49","MS Access error 49","Bad DLL calling convention"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64017,"title":"51 - Internal error","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["51","Access error 51","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Internal error","Internal error"],"errorCode":"51","eventId":"","severity":"High","summary":"Legacy Microsoft Access error 51: Internal error","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 51: Internal error.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 51","MS Access error 51","Internal error"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64018,"title":"52 - Bad file name or number","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["52","Access error 52","Microsoft Access","MSACCESS","Jet","VBA","Files","Bad file name or number","Bad file name or number"],"errorCode":"52","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 52: Bad file name or number","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 52: Bad file name or number.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 52","MS Access error 52","Bad file name or number"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64019,"title":"53 - File not found","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["53","Access error 53","Microsoft Access","MSACCESS","Jet","VBA","Files","File not found","File not found"],"errorCode":"53","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 53: File not found","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 53: File not found.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 53","MS Access error 53","File not found"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64020,"title":"54 - Bad file mode","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["54","Access error 54","Microsoft Access","MSACCESS","Jet","VBA","Files","Bad file mode","Bad file mode"],"errorCode":"54","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 54: Bad file mode","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 54: Bad file mode.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 54","MS Access error 54","Bad file mode"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64021,"title":"55 - File already open","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["55","Access error 55","Microsoft Access","MSACCESS","Jet","VBA","Files","File already open","File already open"],"errorCode":"55","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 55: File already open","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 55: File already open.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 55","MS Access error 55","File already open"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64022,"title":"57 - Device I/O error","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["57","Access error 57","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Device I/O error","Device I/O error"],"errorCode":"57","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 57: Device I/O error","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 57: Device I/O error.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 57","MS Access error 57","Device I/O error"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64023,"title":"58 - File already exists","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["58","Access error 58","Microsoft Access","MSACCESS","Jet","VBA","Files","File already exists","File already exists"],"errorCode":"58","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 58: File already exists","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 58: File already exists.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 58","MS Access error 58","File already exists"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64024,"title":"59 - Bad record length","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["59","Access error 59","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Bad record length","Bad record length"],"errorCode":"59","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 59: Bad record length","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 59: Bad record length.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 59","MS Access error 59","Bad record length"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64025,"title":"61 - Disk full","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["61","Access error 61","Microsoft Access","MSACCESS","Jet","VBA","Files","Disk full","Disk full"],"errorCode":"61","eventId":"","severity":"High","summary":"Legacy Microsoft Access error 61: Disk full","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 61: Disk full.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 61","MS Access error 61","Disk full"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64026,"title":"62 - Input past end of file","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["62","Access error 62","Microsoft Access","MSACCESS","Jet","VBA","Files","Input past end of file","Input past end of file"],"errorCode":"62","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 62: Input past end of file","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 62: Input past end of file.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 62","MS Access error 62","Input past end of file"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64027,"title":"63 - Bad record number","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["63","Access error 63","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Bad record number","Bad record number"],"errorCode":"63","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 63: Bad record number","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 63: Bad record number.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 63","MS Access error 63","Bad record number"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64028,"title":"64 - Bad file name","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["64","Access error 64","Microsoft Access","MSACCESS","Jet","VBA","Files","Bad file name","Bad file name"],"errorCode":"64","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 64: Bad file name","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 64: Bad file name.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 64","MS Access error 64","Bad file name"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64029,"title":"67 - Too many files","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["67","Access error 67","Microsoft Access","MSACCESS","Jet","VBA","Files","Too many files","Too many files"],"errorCode":"67","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 67: Too many files","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 67: Too many files.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 67","MS Access error 67","Too many files"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64030,"title":"68 - Device unavailable","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["68","Access error 68","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Device unavailable","Device unavailable"],"errorCode":"68","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 68: Device unavailable","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 68: Device unavailable.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 68","MS Access error 68","Device unavailable"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64031,"title":"70 - Permission denied","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Security"],"keywords":["70","Access error 70","Microsoft Access","MSACCESS","Jet","VBA","Security","Permission denied","Permission denied"],"errorCode":"70","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 70: Permission denied","rootCause":"The operation is blocked by credentials, permissions, ownership, read-only state, or legacy workgroup security.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify identity and least-privilege permissions, file/share rights, database ownership and legacy workgroup configuration; do not weaken security controls globally.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 70: Permission denied.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Security"],"articleCategories":["Microsoft Access","Legacy Software","Security"],"aliases":["Microsoft Access 70","MS Access error 70","Permission denied"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64032,"title":"71 - Disk not ready","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["71","Access error 71","Microsoft Access","MSACCESS","Jet","VBA","Files","Disk not ready","Disk not ready"],"errorCode":"71","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 71: Disk not ready","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 71: Disk not ready.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 71","MS Access error 71","Disk not ready"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64033,"title":"74 - Can't rename with different drive","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["74","Access error 74","Microsoft Access","MSACCESS","Jet","VBA","Files","Can't rename with different drive","Can't rename with different drive"],"errorCode":"74","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 74: Can't rename with different drive","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 74: Can't rename with different drive.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 74","MS Access error 74","Can't rename with different drive"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64034,"title":"75 - Path/File access error","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["75","Access error 75","Microsoft Access","MSACCESS","Jet","VBA","Files","Path/File access error","Path/File access error"],"errorCode":"75","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 75: Path/File access error","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 75: Path/File access error.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 75","MS Access error 75","Path/File access error"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64035,"title":"76 - Path not found","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["76","Access error 76","Microsoft Access","MSACCESS","Jet","VBA","Files","Path not found","Path not found"],"errorCode":"76","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 76: Path not found","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 76: Path not found.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 76","MS Access error 76","Path not found"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64036,"title":"90 - Compile error","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["90","Access error 90","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Compile error","Compile error"],"errorCode":"90","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 90: Compile error","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 90: Compile error.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 90","MS Access error 90","Compile error"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64037,"title":"91 - Object variable not Set","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["91","Access error 91","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Object variable not Set","Object variable not Set"],"errorCode":"91","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 91: Object variable not Set","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 91: Object variable not Set.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 91","MS Access error 91","Object variable not Set"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64038,"title":"92 - For loop not initialized","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["92","Access error 92","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","For loop not initialized","For loop not initialized"],"errorCode":"92","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 92: For loop not initialized","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 92: For loop not initialized.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 92","MS Access error 92","For loop not initialized"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64039,"title":"93 - Invalid pattern string","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["93","Access error 93","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Invalid pattern string","Invalid pattern string"],"errorCode":"93","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 93: Invalid pattern string","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 93: Invalid pattern string.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 93","MS Access error 93","Invalid pattern string"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64040,"title":"94 - Invalid use of Null","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["94","Access error 94","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Invalid use of Null","Invalid use of Null"],"errorCode":"94","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 94: Invalid use of Null","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 94: Invalid use of Null.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 94","MS Access error 94","Invalid use of Null"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64041,"title":"280 - DDE channel not fully closed; awaiting response from the other application.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","DDE"],"keywords":["280","Access error 280","Microsoft Access","MSACCESS","Jet","VBA","DDE","DDE channel not fully closed; awaiting response from the other application.","DDE channel not fully closed; awaiting response from the other application."],"errorCode":"280","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 280: DDE channel not fully closed; awaiting response from the other application.","rootCause":"A legacy Dynamic Data Exchange channel, topic, application, timeout, or data format is unavailable or inconsistent.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the target application and topic, close stale conversations, verify both applications are responsive and version-compatible, and replace DDE with supported automation where practical.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 280: DDE channel not fully closed; awaiting response from the other application..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","DDE"],"articleCategories":["Microsoft Access","Legacy Software","DDE"],"aliases":["Microsoft Access 280","MS Access error 280","DDE channel not fully closed; awaiting response from the other application."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64042,"title":"281 - No more DDE channels are available.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","DDE"],"keywords":["281","Access error 281","Microsoft Access","MSACCESS","Jet","VBA","DDE","No more DDE channels are available.","No more DDE channels are available."],"errorCode":"281","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 281: No more DDE channels are available.","rootCause":"A legacy Dynamic Data Exchange channel, topic, application, timeout, or data format is unavailable or inconsistent.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the target application and topic, close stale conversations, verify both applications are responsive and version-compatible, and replace DDE with supported automation where practical.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 281: No more DDE channels are available..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","DDE"],"articleCategories":["Microsoft Access","Legacy Software","DDE"],"aliases":["Microsoft Access 281","MS Access error 281","No more DDE channels are available."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64043,"title":"282 - Can't open DDE channel; Microsoft Access couldn't find the specified application and topic.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","DDE"],"keywords":["282","Access error 282","Microsoft Access","MSACCESS","Jet","VBA","DDE","Can't open DDE channel; Microsoft Access couldn't find the specified application and topic.","Can't open DDE channel; Microsoft Access couldn't find the specified application and topic."],"errorCode":"282","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 282: Can't open DDE channel; Microsoft Access couldn't find the specified application and topic.","rootCause":"A legacy Dynamic Data Exchange channel, topic, application, timeout, or data format is unavailable or inconsistent.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the target application and topic, close stale conversations, verify both applications are responsive and version-compatible, and replace DDE with supported automation where practical.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 282: Can't open DDE channel; Microsoft Access couldn't find the specified application and topic..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","DDE"],"articleCategories":["Microsoft Access","Legacy Software","DDE"],"aliases":["Microsoft Access 282","MS Access error 282","Can't open DDE channel; Microsoft Access couldn't find the specified application and topic."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64044,"title":"283 - Can't open DDE channel; more than one application responded.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","DDE"],"keywords":["283","Access error 283","Microsoft Access","MSACCESS","Jet","VBA","DDE","Can't open DDE channel; more than one application responded.","Can't open DDE channel; more than one application responded."],"errorCode":"283","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 283: Can't open DDE channel; more than one application responded.","rootCause":"A legacy Dynamic Data Exchange channel, topic, application, timeout, or data format is unavailable or inconsistent.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the target application and topic, close stale conversations, verify both applications are responsive and version-compatible, and replace DDE with supported automation where practical.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 283: Can't open DDE channel; more than one application responded..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","DDE"],"articleCategories":["Microsoft Access","Legacy Software","DDE"],"aliases":["Microsoft Access 283","MS Access error 283","Can't open DDE channel; more than one application responded."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64045,"title":"284 - DDE channel is locked.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","DDE"],"keywords":["284","Access error 284","Microsoft Access","MSACCESS","Jet","VBA","DDE","DDE channel is locked.","DDE channel is locked."],"errorCode":"284","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 284: DDE channel is locked.","rootCause":"A legacy Dynamic Data Exchange channel, topic, application, timeout, or data format is unavailable or inconsistent.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the target application and topic, close stale conversations, verify both applications are responsive and version-compatible, and replace DDE with supported automation where practical.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 284: DDE channel is locked..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","DDE"],"articleCategories":["Microsoft Access","Legacy Software","DDE"],"aliases":["Microsoft Access 284","MS Access error 284","DDE channel is locked."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64046,"title":"285 - The other application won't perform the DDE method or operation you attempted.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","DDE"],"keywords":["285","Access error 285","Microsoft Access","MSACCESS","Jet","VBA","DDE","The other application won't perform the DDE method or operation you attempted.","The other application won't perform the DDE method or operation you attempted."],"errorCode":"285","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 285: The other application won't perform the DDE method or operation you attempted.","rootCause":"A legacy Dynamic Data Exchange channel, topic, application, timeout, or data format is unavailable or inconsistent.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the target application and topic, close stale conversations, verify both applications are responsive and version-compatible, and replace DDE with supported automation where practical.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 285: The other application won't perform the DDE method or operation you attempted..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","DDE"],"articleCategories":["Microsoft Access","Legacy Software","DDE"],"aliases":["Microsoft Access 285","MS Access error 285","The other application won't perform the DDE method or operation you attempted."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64047,"title":"286 - Timeout while waiting for DDE response.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","DDE"],"keywords":["286","Access error 286","Microsoft Access","MSACCESS","Jet","VBA","DDE","Timeout while waiting for DDE response.","Timeout while waiting for DDE response."],"errorCode":"286","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 286: Timeout while waiting for DDE response.","rootCause":"A legacy Dynamic Data Exchange channel, topic, application, timeout, or data format is unavailable or inconsistent.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the target application and topic, close stale conversations, verify both applications are responsive and version-compatible, and replace DDE with supported automation where practical.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 286: Timeout while waiting for DDE response..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","DDE"],"articleCategories":["Microsoft Access","Legacy Software","DDE"],"aliases":["Microsoft Access 286","MS Access error 286","Timeout while waiting for DDE response."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64048,"title":"287 - Operation terminated because Esc key was pressed before completion.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["287","Access error 287","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Operation terminated because Esc key was pressed before completion.","Operation terminated because Esc key was pressed before completion."],"errorCode":"287","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 287: Operation terminated because Esc key was pressed before completion.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 287: Operation terminated because Esc key was pressed before completion..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 287","MS Access error 287","Operation terminated because Esc key was pressed before completion."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64049,"title":"288 - The other application is busy.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["288","Access error 288","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The other application is busy.","The other application is busy."],"errorCode":"288","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 288: The other application is busy.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 288: The other application is busy..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 288","MS Access error 288","The other application is busy."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64050,"title":"289 - Data not provided when requested in DDE operation.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","DDE"],"keywords":["289","Access error 289","Microsoft Access","MSACCESS","Jet","VBA","DDE","Data not provided when requested in DDE operation.","Data not provided when requested in DDE operation."],"errorCode":"289","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 289: Data not provided when requested in DDE operation.","rootCause":"A legacy Dynamic Data Exchange channel, topic, application, timeout, or data format is unavailable or inconsistent.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the target application and topic, close stale conversations, verify both applications are responsive and version-compatible, and replace DDE with supported automation where practical.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 289: Data not provided when requested in DDE operation..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","DDE"],"articleCategories":["Microsoft Access","Legacy Software","DDE"],"aliases":["Microsoft Access 289","MS Access error 289","Data not provided when requested in DDE operation."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64051,"title":"290 - Data supplied in a DDE conversation is in the wrong format.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","DDE"],"keywords":["290","Access error 290","Microsoft Access","MSACCESS","Jet","VBA","DDE","Data supplied in a DDE conversation is in the wrong format.","Data supplied in a DDE conversation is in the wrong format."],"errorCode":"290","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 290: Data supplied in a DDE conversation is in the wrong format.","rootCause":"A legacy Dynamic Data Exchange channel, topic, application, timeout, or data format is unavailable or inconsistent.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the target application and topic, close stale conversations, verify both applications are responsive and version-compatible, and replace DDE with supported automation where practical.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 290: Data supplied in a DDE conversation is in the wrong format..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","DDE"],"articleCategories":["Microsoft Access","Legacy Software","DDE"],"aliases":["Microsoft Access 290","MS Access error 290","Data supplied in a DDE conversation is in the wrong format."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64052,"title":"291 - The other application quit.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["291","Access error 291","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The other application quit.","The other application quit."],"errorCode":"291","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 291: The other application quit.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 291: The other application quit..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 291","MS Access error 291","The other application quit."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64053,"title":"292 - DDE conversation closed or changed.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","DDE"],"keywords":["292","Access error 292","Microsoft Access","MSACCESS","Jet","VBA","DDE","DDE conversation closed or changed.","DDE conversation closed or changed."],"errorCode":"292","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 292: DDE conversation closed or changed.","rootCause":"A legacy Dynamic Data Exchange channel, topic, application, timeout, or data format is unavailable or inconsistent.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the target application and topic, close stale conversations, verify both applications are responsive and version-compatible, and replace DDE with supported automation where practical.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 292: DDE conversation closed or changed..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","DDE"],"articleCategories":["Microsoft Access","Legacy Software","DDE"],"aliases":["Microsoft Access 292","MS Access error 292","DDE conversation closed or changed."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64054,"title":"293 - DDE method invoked with no channel open.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","DDE"],"keywords":["293","Access error 293","Microsoft Access","MSACCESS","Jet","VBA","DDE","DDE method invoked with no channel open.","DDE method invoked with no channel open."],"errorCode":"293","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 293: DDE method invoked with no channel open.","rootCause":"A legacy Dynamic Data Exchange channel, topic, application, timeout, or data format is unavailable or inconsistent.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the target application and topic, close stale conversations, verify both applications are responsive and version-compatible, and replace DDE with supported automation where practical.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 293: DDE method invoked with no channel open..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","DDE"],"articleCategories":["Microsoft Access","Legacy Software","DDE"],"aliases":["Microsoft Access 293","MS Access error 293","DDE method invoked with no channel open."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64055,"title":"294 - Invalid link format; can't create link to the other application.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["294","Access error 294","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Invalid link format; can't create link to the other application.","Invalid link format; can't create link to the other application."],"errorCode":"294","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 294: Invalid link format; can't create link to the other application.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 294: Invalid link format; can't create link to the other application..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 294","MS Access error 294","Invalid link format; can't create link to the other application."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64056,"title":"295 - Message queue filled; DDE message lost.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","DDE"],"keywords":["295","Access error 295","Microsoft Access","MSACCESS","Jet","VBA","DDE","Message queue filled; DDE message lost.","Message queue filled; DDE message lost."],"errorCode":"295","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 295: Message queue filled; DDE message lost.","rootCause":"A legacy Dynamic Data Exchange channel, topic, application, timeout, or data format is unavailable or inconsistent.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the target application and topic, close stale conversations, verify both applications are responsive and version-compatible, and replace DDE with supported automation where practical.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 295: Message queue filled; DDE message lost..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","DDE"],"articleCategories":["Microsoft Access","Legacy Software","DDE"],"aliases":["Microsoft Access 295","MS Access error 295","Message queue filled; DDE message lost."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64057,"title":"296 - PasteLink already performed on this control.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","DDE"],"keywords":["296","Access error 296","Microsoft Access","MSACCESS","Jet","VBA","DDE","PasteLink already performed on this control.","PasteLink already performed on this control."],"errorCode":"296","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 296: PasteLink already performed on this control.","rootCause":"A legacy Dynamic Data Exchange channel, topic, application, timeout, or data format is unavailable or inconsistent.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the target application and topic, close stale conversations, verify both applications are responsive and version-compatible, and replace DDE with supported automation where practical.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 296: PasteLink already performed on this control..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","DDE"],"articleCategories":["Microsoft Access","Legacy Software","DDE"],"aliases":["Microsoft Access 296","MS Access error 296","PasteLink already performed on this control."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64058,"title":"297 - Can't set LinkMode; invalid LinkTopic.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","DDE"],"keywords":["297","Access error 297","Microsoft Access","MSACCESS","Jet","VBA","DDE","Can't set LinkMode; invalid LinkTopic.","Can't set LinkMode; invalid LinkTopic."],"errorCode":"297","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 297: Can't set LinkMode; invalid LinkTopic.","rootCause":"A legacy Dynamic Data Exchange channel, topic, application, timeout, or data format is unavailable or inconsistent.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the target application and topic, close stale conversations, verify both applications are responsive and version-compatible, and replace DDE with supported automation where practical.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 297: Can't set LinkMode; invalid LinkTopic..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","DDE"],"articleCategories":["Microsoft Access","Legacy Software","DDE"],"aliases":["Microsoft Access 297","MS Access error 297","Can't set LinkMode; invalid LinkTopic."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64059,"title":"298 - The DDE transaction failed.  Check to ensure you have the correct version of DDEML.DLL.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","DDE"],"keywords":["298","Access error 298","Microsoft Access","MSACCESS","Jet","VBA","DDE","The DDE transaction failed.  Check to ensure you have the correct version of DDEML.DLL.","The DDE transaction failed.  Check to ensure you have the correct version of DDEML.DLL."],"errorCode":"298","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 298: The DDE transaction failed.  Check to ensure you have the correct version of DDEML.DLL.","rootCause":"A legacy Dynamic Data Exchange channel, topic, application, timeout, or data format is unavailable or inconsistent.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the target application and topic, close stale conversations, verify both applications are responsive and version-compatible, and replace DDE with supported automation where practical.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 298: The DDE transaction failed.  Check to ensure you have the correct version of DDEML.DLL..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","DDE"],"articleCategories":["Microsoft Access","Legacy Software","DDE"],"aliases":["Microsoft Access 298","MS Access error 298","The DDE transaction failed.  Check to ensure you have the correct version of DDEML.DLL."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64060,"title":"2000 - Not enough memory to start Cue Cards.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Resources"],"keywords":["2000","Access error 2000","Microsoft Access","MSACCESS","Jet","VBA","Resources","Not enough memory to start Cue Cards.","Not enough memory to start Cue Cards."],"errorCode":"2000","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2000: Not enough memory to start Cue Cards.","rootCause":"Access or Windows lacks sufficient memory, stack, handles, disk, or other resources for the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Save work, close unnecessary objects/applications, check memory, handles, disk and database size, then reproduce after a controlled restart and review for runaway queries or code.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2000: Not enough memory to start Cue Cards..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Resources"],"articleCategories":["Microsoft Access","Legacy Software","Resources"],"aliases":["Microsoft Access 2000","MS Access error 2000","Not enough memory to start Cue Cards."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64061,"title":"2001 - Operation cancelled.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2001","Access error 2001","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Operation cancelled.","Operation cancelled."],"errorCode":"2001","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2001: Operation cancelled.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2001: Operation cancelled..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2001","MS Access error 2001","Operation cancelled."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64062,"title":"2002 - Not Yet Implemented.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2002","Access error 2002","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Not Yet Implemented.","Not Yet Implemented."],"errorCode":"2002","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2002: Not Yet Implemented.","rootCause":"The requested feature or operation is unavailable in this Access/Jet version, object type, driver, or context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the Access, database-engine, file-format, and driver versions; use a supported operation or migrate the workflow before retrying.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2002: Not Yet Implemented..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2002","MS Access error 2002","Not Yet Implemented."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64063,"title":"2003 - <value> Not Yet Implemented.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2003","Access error 2003","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","| Not Yet Implemented.","<value> Not Yet Implemented."],"errorCode":"2003","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2003: <value> Not Yet Implemented.","rootCause":"The requested feature or operation is unavailable in this Access/Jet version, object type, driver, or context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the Access, database-engine, file-format, and driver versions; use a supported operation or migrate the workflow before retrying.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2003: <value> Not Yet Implemented..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2003","MS Access error 2003","| Not Yet Implemented."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64064,"title":"2004 - Out of memory.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Resources"],"keywords":["2004","Access error 2004","Microsoft Access","MSACCESS","Jet","VBA","Resources","Out of memory.","Out of memory."],"errorCode":"2004","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2004: Out of memory.","rootCause":"Access or Windows lacks sufficient memory, stack, handles, disk, or other resources for the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Save work, close unnecessary objects/applications, check memory, handles, disk and database size, then reproduce after a controlled restart and review for runaway queries or code.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2004: Out of memory..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Resources"],"articleCategories":["Microsoft Access","Legacy Software","Resources"],"aliases":["Microsoft Access 2004","MS Access error 2004","Out of memory."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64065,"title":"2005 - Not enough memory to start Microsoft Access.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Resources"],"keywords":["2005","Access error 2005","Microsoft Access","MSACCESS","Jet","VBA","Resources","Not enough memory to start Microsoft Access.","Not enough memory to start Microsoft Access."],"errorCode":"2005","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2005: Not enough memory to start Microsoft Access.","rootCause":"Access or Windows lacks sufficient memory, stack, handles, disk, or other resources for the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Save work, close unnecessary objects/applications, check memory, handles, disk and database size, then reproduce after a controlled restart and review for runaway queries or code.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2005: Not enough memory to start Microsoft Access..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Resources"],"articleCategories":["Microsoft Access","Legacy Software","Resources"],"aliases":["Microsoft Access 2005","MS Access error 2005","Not enough memory to start Microsoft Access."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64066,"title":"2006 - Not a valid document name: '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2006","Access error 2006","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Not a valid document name: '|'.","Not a valid document name: '<value>'."],"errorCode":"2006","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2006: Not a valid document name: '<value>'.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2006: Not a valid document name: '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2006","MS Access error 2006","Not a valid document name: '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64067,"title":"2007 - You already have an open document named '<value>'; you must close it before you can save or rename another document under the same name.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2007","Access error 2007","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","You already have an open document named '|'; you must close it before you can save or rename another document under the same name.","You already have an open document named '<value>'; you must close it before you can save or rename another document under the same name."],"errorCode":"2007","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2007: You already have an open document named '<value>'; you must close it before you can save or rename another document under the same name.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2007: You already have an open document named '<value>'; you must close it before you can save or rename another document under the same name..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2007","MS Access error 2007","You already have an open document named '|'; you must close it before you can save or rename another document under the same name."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64068,"title":"2008 - Document '<value>' is open; you must close it before deleting it.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2008","Access error 2008","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Document '|' is open; you must close it before deleting it.","Document '<value>' is open; you must close it before deleting it."],"errorCode":"2008","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2008: Document '<value>' is open; you must close it before deleting it.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2008: Document '<value>' is open; you must close it before deleting it..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2008","MS Access error 2008","Document '|' is open; you must close it before deleting it."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64069,"title":"2009 - Document '<value>' is open; you must close it before renaming it.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2009","Access error 2009","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Document '|' is open; you must close it before renaming it.","Document '<value>' is open; you must close it before renaming it."],"errorCode":"2009","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2009: Document '<value>' is open; you must close it before renaming it.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2009: Document '<value>' is open; you must close it before renaming it..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2009","MS Access error 2009","Document '|' is open; you must close it before renaming it."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64070,"title":"2010 - Document '<value>' is open; you must close it before cutting it.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2010","Access error 2010","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Document '|' is open; you must close it before cutting it.","Document '<value>' is open; you must close it before cutting it."],"errorCode":"2010","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2010: Document '<value>' is open; you must close it before cutting it.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2010: Document '<value>' is open; you must close it before cutting it..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2010","MS Access error 2010","Document '|' is open; you must close it before cutting it."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64071,"title":"2011 - Not a valid password.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Security"],"keywords":["2011","Access error 2011","Microsoft Access","MSACCESS","Jet","VBA","Security","Not a valid password.","Not a valid password."],"errorCode":"2011","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2011: Not a valid password.","rootCause":"The operation is blocked by credentials, permissions, ownership, read-only state, or legacy workgroup security.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify identity and least-privilege permissions, file/share rights, database ownership and legacy workgroup configuration; do not weaken security controls globally.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2011: Not a valid password..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Security"],"articleCategories":["Microsoft Access","Legacy Software","Security"],"aliases":["Microsoft Access 2011","MS Access error 2011","Not a valid password."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64072,"title":"2012 - This copy of Microsoft Access has expired.  Please get a new copy from your Microsoft distributor.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2012","Access error 2012","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","This copy of Microsoft Access has expired.  Please get a new copy from your Microsoft distributor.","This copy of Microsoft Access has expired.  Please get a new copy from your Microsoft distributor."],"errorCode":"2012","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2012: This copy of Microsoft Access has expired.  Please get a new copy from your Microsoft distributor.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2012: This copy of Microsoft Access has expired.  Please get a new copy from your Microsoft distributor..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2012","MS Access error 2012","This copy of Microsoft Access has expired.  Please get a new copy from your Microsoft distributor."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64073,"title":"2013 - This copy of Microsoft Access hasn't been personalized properly.  Please install Microsoft Access using the provided Setup program.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2013","Access error 2013","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","This copy of Microsoft Access hasn't been personalized properly.  Please install Microsoft Access using the provided Setup program.","This copy of Microsoft Access hasn't been personalized properly.  Please install Microsoft Access using the provided Setup program."],"errorCode":"2013","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2013: This copy of Microsoft Access hasn't been personalized properly.  Please install Microsoft Access using the provided Setup program.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2013: This copy of Microsoft Access hasn't been personalized properly.  Please install Microsoft Access using the provided Setup program..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2013","MS Access error 2013","This copy of Microsoft Access hasn't been personalized properly.  Please install Microsoft Access using the provided Setup program."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64074,"title":"2040 - Incompatible version of 'WIN87EM.DLL'; Microsoft Access can't run.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2040","Access error 2040","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Incompatible version of 'WIN87EM.DLL'; Microsoft Access can't run.","Incompatible version of 'WIN87EM.DLL'; Microsoft Access can't run."],"errorCode":"2040","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2040: Incompatible version of 'WIN87EM.DLL'; Microsoft Access can't run.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2040: Incompatible version of 'WIN87EM.DLL'; Microsoft Access can't run..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2040","MS Access error 2040","Incompatible version of 'WIN87EM.DLL'; Microsoft Access can't run."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64075,"title":"2041 - CE FAILED. no error was reported, though.  This is a bug!!","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2041","Access error 2041","Microsoft Access","MSACCESS","Jet","VBA","Access UI","CE FAILED. no error was reported, though.  This is a bug!!","CE FAILED. no error was reported, though.  This is a bug!!"],"errorCode":"2041","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2041: CE FAILED. no error was reported, though.  This is a bug!!","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2041: CE FAILED. no error was reported, though.  This is a bug!!.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2041","MS Access error 2041","CE FAILED. no error was reported, though.  This is a bug!!"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64076,"title":"2042 - Can't start Microsoft Access. Please try again.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2042","Access error 2042","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't start Microsoft Access. Please try again.","Can't start Microsoft Access. Please try again."],"errorCode":"2042","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2042: Can't start Microsoft Access. Please try again.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2042: Can't start Microsoft Access. Please try again..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2042","MS Access error 2042","Can't start Microsoft Access. Please try again."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64077,"title":"2043 - Can't find file: '<value>'.  Please verify that the correct path and file name are given.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["2043","Access error 2043","Microsoft Access","MSACCESS","Jet","VBA","Files","Can't find file: '|'.  Please verify that the correct path and file name are given.","Can't find file: '<value>'.  Please verify that the correct path and file name are given."],"errorCode":"2043","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2043: Can't find file: '<value>'.  Please verify that the correct path and file name are given.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2043: Can't find file: '<value>'.  Please verify that the correct path and file name are given..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 2043","MS Access error 2043","Can't find file: '|'.  Please verify that the correct path and file name are given."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64078,"title":"2044 - Currently unable to quit Microsoft Access.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2044","Access error 2044","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Currently unable to quit Microsoft Access.","Currently unable to quit Microsoft Access."],"errorCode":"2044","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2044: Currently unable to quit Microsoft Access.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2044: Currently unable to quit Microsoft Access..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2044","MS Access error 2044","Currently unable to quit Microsoft Access."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64079,"title":"2045 - An argument in the command line used to start Microsoft Access wasn't valid and was ignored.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2045","Access error 2045","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","An argument in the command line used to start Microsoft Access wasn't valid and was ignored.","An argument in the command line used to start Microsoft Access wasn't valid and was ignored."],"errorCode":"2045","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2045: An argument in the command line used to start Microsoft Access wasn't valid and was ignored.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2045: An argument in the command line used to start Microsoft Access wasn't valid and was ignored..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2045","MS Access error 2045","An argument in the command line used to start Microsoft Access wasn't valid and was ignored."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64080,"title":"2046 - Command not available: <value>.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2046","Access error 2046","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Command not available: |.","Command not available: <value>."],"errorCode":"2046","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2046: Command not available: <value>.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2046: Command not available: <value>..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2046","MS Access error 2046","Command not available: |."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64081,"title":"2047 - Incompatible version of 'MSABC100.DLL'; Microsoft Access can't run.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2047","Access error 2047","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Incompatible version of 'MSABC100.DLL'; Microsoft Access can't run.","Incompatible version of 'MSABC100.DLL'; Microsoft Access can't run."],"errorCode":"2047","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2047: Incompatible version of 'MSABC100.DLL'; Microsoft Access can't run.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2047: Incompatible version of 'MSABC100.DLL'; Microsoft Access can't run..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2047","MS Access error 2047","Incompatible version of 'MSABC100.DLL'; Microsoft Access can't run."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64082,"title":"2048 - Not enough memory to open '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Resources"],"keywords":["2048","Access error 2048","Microsoft Access","MSACCESS","Jet","VBA","Resources","Not enough memory to open '|'.","Not enough memory to open '<value>'."],"errorCode":"2048","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2048: Not enough memory to open '<value>'.","rootCause":"Access or Windows lacks sufficient memory, stack, handles, disk, or other resources for the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Save work, close unnecessary objects/applications, check memory, handles, disk and database size, then reproduce after a controlled restart and review for runaway queries or code.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2048: Not enough memory to open '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Resources"],"articleCategories":["Microsoft Access","Legacy Software","Resources"],"aliases":["Microsoft Access 2048","MS Access error 2048","Not enough memory to open '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64083,"title":"2049 - Name '<value>' contains invalid characters.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2049","Access error 2049","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Name '|' contains invalid characters.","Name '<value>' contains invalid characters."],"errorCode":"2049","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2049: Name '<value>' contains invalid characters.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2049: Name '<value>' contains invalid characters..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2049","MS Access error 2049","Name '|' contains invalid characters."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64084,"title":"2050 - OLE/DDE Timeout must be from 0 to 300 seconds.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","DDE"],"keywords":["2050","Access error 2050","Microsoft Access","MSACCESS","Jet","VBA","DDE","OLE/DDE Timeout must be from 0 to 300 seconds.","OLE/DDE Timeout must be from 0 to 300 seconds."],"errorCode":"2050","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2050: OLE/DDE Timeout must be from 0 to 300 seconds.","rootCause":"A legacy Dynamic Data Exchange channel, topic, application, timeout, or data format is unavailable or inconsistent.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the target application and topic, close stale conversations, verify both applications are responsive and version-compatible, and replace DDE with supported automation where practical.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2050: OLE/DDE Timeout must be from 0 to 300 seconds..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","DDE"],"articleCategories":["Microsoft Access","Legacy Software","DDE"],"aliases":["Microsoft Access 2050","MS Access error 2050","OLE/DDE Timeout must be from 0 to 300 seconds."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64085,"title":"2051 - The new name, '<value>', is too long.  Microsoft Access object names can't exceed 64 characters.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2051","Access error 2051","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The new name, '|', is too long.  Microsoft Access object names can't exceed 64 characters.","The new name, '<value>', is too long.  Microsoft Access object names can't exceed 64 characters."],"errorCode":"2051","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2051: The new name, '<value>', is too long.  Microsoft Access object names can't exceed 64 characters.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2051: The new name, '<value>', is too long.  Microsoft Access object names can't exceed 64 characters..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2051","MS Access error 2051","The new name, '|', is too long.  Microsoft Access object names can't exceed 64 characters."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64086,"title":"2052 - Not enough system resources to update display.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Resources"],"keywords":["2052","Access error 2052","Microsoft Access","MSACCESS","Jet","VBA","Resources","Not enough system resources to update display.","Not enough system resources to update display."],"errorCode":"2052","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2052: Not enough system resources to update display.","rootCause":"Access or Windows lacks sufficient memory, stack, handles, disk, or other resources for the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Save work, close unnecessary objects/applications, check memory, handles, disk and database size, then reproduce after a controlled restart and review for runaway queries or code.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2052: Not enough system resources to update display..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Resources"],"articleCategories":["Microsoft Access","Legacy Software","Resources"],"aliases":["Microsoft Access 2052","MS Access error 2052","Not enough system resources to update display."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64087,"title":"2053 - Wildcard characters aren't allowed in file name.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["2053","Access error 2053","Microsoft Access","MSACCESS","Jet","VBA","Files","Wildcard characters aren't allowed in file name.","Wildcard characters aren't allowed in file name."],"errorCode":"2053","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2053: Wildcard characters aren't allowed in file name.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2053: Wildcard characters aren't allowed in file name..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 2053","MS Access error 2053","Wildcard characters aren't allowed in file name."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64088,"title":"2054 - Can't change to directory; path too long.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["2054","Access error 2054","Microsoft Access","MSACCESS","Jet","VBA","Files","Can't change to directory; path too long.","Can't change to directory; path too long."],"errorCode":"2054","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2054: Can't change to directory; path too long.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2054: Can't change to directory; path too long..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 2054","MS Access error 2054","Can't change to directory; path too long."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64089,"title":"2055 - Expression not valid: '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2055","Access error 2055","Microsoft Access","MSACCESS","Jet","VBA","Queries","Expression not valid: '|'.","Expression not valid: '<value>'."],"errorCode":"2055","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2055: Expression not valid: '<value>'.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2055: Expression not valid: '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2055","MS Access error 2055","Expression not valid: '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64090,"title":"2056 - Can't supply context-sensitive Help.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2056","Access error 2056","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't supply context-sensitive Help.","Can't supply context-sensitive Help."],"errorCode":"2056","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2056: Can't supply context-sensitive Help.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2056: Can't supply context-sensitive Help..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2056","MS Access error 2056","Can't supply context-sensitive Help."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64091,"title":"2057 - Not enough stack memory left.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Resources"],"keywords":["2057","Access error 2057","Microsoft Access","MSACCESS","Jet","VBA","Resources","Not enough stack memory left.","Not enough stack memory left."],"errorCode":"2057","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2057: Not enough stack memory left.","rootCause":"Access or Windows lacks sufficient memory, stack, handles, disk, or other resources for the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Save work, close unnecessary objects/applications, check memory, handles, disk and database size, then reproduce after a controlled restart and review for runaway queries or code.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2057: Not enough stack memory left..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Resources"],"articleCategories":["Microsoft Access","Legacy Software","Resources"],"aliases":["Microsoft Access 2057","MS Access error 2057","Not enough stack memory left."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64092,"title":"2058 - Incompatible version of '<value>'; Microsoft Access can't run.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2058","Access error 2058","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Incompatible version of '|'; Microsoft Access can't run.","Incompatible version of '<value>'; Microsoft Access can't run."],"errorCode":"2058","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2058: Incompatible version of '<value>'; Microsoft Access can't run.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2058: Incompatible version of '<value>'; Microsoft Access can't run..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2058","MS Access error 2058","Incompatible version of '|'; Microsoft Access can't run."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64093,"title":"2059 - The selected name is too long for Microsoft Access.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2059","Access error 2059","Microsoft Access","MSACCESS","Jet","VBA","Queries","The selected name is too long for Microsoft Access.","The selected name is too long for Microsoft Access."],"errorCode":"2059","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2059: The selected name is too long for Microsoft Access.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2059: The selected name is too long for Microsoft Access..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2059","MS Access error 2059","The selected name is too long for Microsoft Access."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64094,"title":"2060 - Can't create a field list on an action query: '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2060","Access error 2060","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't create a field list on an action query: '|'.","Can't create a field list on an action query: '<value>'."],"errorCode":"2060","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2060: Can't create a field list on an action query: '<value>'.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2060: Can't create a field list on an action query: '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2060","MS Access error 2060","Can't create a field list on an action query: '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64095,"title":"2061 - Negative numbers aren't allowed.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2061","Access error 2061","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Negative numbers aren't allowed.","Negative numbers aren't allowed."],"errorCode":"2061","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2061: Negative numbers aren't allowed.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2061: Negative numbers aren't allowed..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2061","MS Access error 2061","Negative numbers aren't allowed."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64096,"title":"2062 - MSACCESS.INI is missing or isn't the correct version. Import/Export isn't available.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Import / Export"],"keywords":["2062","Access error 2062","Microsoft Access","MSACCESS","Jet","VBA","Import / Export","MSACCESS.INI is missing or isn't the correct version. Import/Export isn't available.","MSACCESS.INI is missing or isn't the correct version. Import/Export isn't available."],"errorCode":"2062","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2062: MSACCESS.INI is missing or isn't the correct version. Import/Export isn't available.","rootCause":"The source format, ISAM driver, specification, field mapping, file version, or destination schema is missing or incompatible.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Preserve the source, verify the import/export specification and supported driver, normalize field names and types, test a small copy, and validate row counts and rejected records.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2062: MSACCESS.INI is missing or isn't the correct version. Import/Export isn't available..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Import / Export"],"articleCategories":["Microsoft Access","Legacy Software","Import / Export"],"aliases":["Microsoft Access 2062","MS Access error 2062","MSACCESS.INI is missing or isn't the correct version. Import/Export isn't available."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64097,"title":"2063 - Can't create, open, or write to index file '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2063","Access error 2063","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't create, open, or write to index file '|'.","Can't create, open, or write to index file '<value>'."],"errorCode":"2063","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2063: Can't create, open, or write to index file '<value>'.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2063: Can't create, open, or write to index file '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2063","MS Access error 2063","Can't create, open, or write to index file '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64098,"title":"2064 - Not a valid menu bar value: '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2064","Access error 2064","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Not a valid menu bar value: '|'.","Not a valid menu bar value: '<value>'."],"errorCode":"2064","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2064: Not a valid menu bar value: '<value>'.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2064: Not a valid menu bar value: '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2064","MS Access error 2064","Not a valid menu bar value: '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64099,"title":"2065 - Not a valid name for a menu bar, menu, command, or subcommand: '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2065","Access error 2065","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Not a valid name for a menu bar, menu, command, or subcommand: '|'.","Not a valid name for a menu bar, menu, command, or subcommand: '<value>'."],"errorCode":"2065","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2065: Not a valid name for a menu bar, menu, command, or subcommand: '<value>'.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2065: Not a valid name for a menu bar, menu, command, or subcommand: '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2065","MS Access error 2065","Not a valid name for a menu bar, menu, command, or subcommand: '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64100,"title":"2066 - A display driver resolution of at least 400 x 340 pixels is required to run Microsoft Access.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["2066","Access error 2066","Microsoft Access","MSACCESS","Jet","VBA","Files","A display driver resolution of at least 400 x 340 pixels is required to run Microsoft Access.","A display driver resolution of at least 400 x 340 pixels is required to run Microsoft Access."],"errorCode":"2066","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2066: A display driver resolution of at least 400 x 340 pixels is required to run Microsoft Access.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2066: A display driver resolution of at least 400 x 340 pixels is required to run Microsoft Access..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 2066","MS Access error 2066","A display driver resolution of at least 400 x 340 pixels is required to run Microsoft Access."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64101,"title":"2067 - The AddMenu action can be used only on a menu created by an OnMenu macro.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2067","Access error 2067","Microsoft Access","MSACCESS","Jet","VBA","Access UI","The AddMenu action can be used only on a menu created by an OnMenu macro.","The AddMenu action can be used only on a menu created by an OnMenu macro."],"errorCode":"2067","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2067: The AddMenu action can be used only on a menu created by an OnMenu macro.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2067: The AddMenu action can be used only on a menu created by an OnMenu macro..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2067","MS Access error 2067","The AddMenu action can be used only on a menu created by an OnMenu macro."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64102,"title":"2068 - Help isn't available for this command.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2068","Access error 2068","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Help isn't available for this command.","Help isn't available for this command."],"errorCode":"2068","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2068: Help isn't available for this command.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2068: Help isn't available for this command..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2068","MS Access error 2068","Help isn't available for this command."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64103,"title":"2069 - The key combination '<value 1>' in '<value 2>' isn't valid and will be ignored.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2069","Access error 2069","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The key combination '|1' in '|2' isn't valid and will be ignored.","The key combination '<value 1>' in '<value 2>' isn't valid and will be ignored."],"errorCode":"2069","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2069: The key combination '<value 1>' in '<value 2>' isn't valid and will be ignored.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2069: The key combination '<value 1>' in '<value 2>' isn't valid and will be ignored..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2069","MS Access error 2069","The key combination '|1' in '|2' isn't valid and will be ignored."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64104,"title":"2070 - The key combination '<value 1>' in '<value 2>' is also assigned to another macro.  Only the first one will be used.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2070","Access error 2070","Microsoft Access","MSACCESS","Jet","VBA","Access UI","The key combination '|1' in '|2' is also assigned to another macro.  Only the first one will be used.","The key combination '<value 1>' in '<value 2>' is also assigned to another macro.  Only the first one will be used."],"errorCode":"2070","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2070: The key combination '<value 1>' in '<value 2>' is also assigned to another macro.  Only the first one will be used.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2070: The key combination '<value 1>' in '<value 2>' is also assigned to another macro.  Only the first one will be used..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2070","MS Access error 2070","The key combination '|1' in '|2' is also assigned to another macro.  Only the first one will be used."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64105,"title":"2071 - Cue Cards couldn't be started because of an incomplete setup.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2071","Access error 2071","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Cue Cards couldn't be started because of an incomplete setup.","Cue Cards couldn't be started because of an incomplete setup."],"errorCode":"2071","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2071: Cue Cards couldn't be started because of an incomplete setup.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2071: Cue Cards couldn't be started because of an incomplete setup..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2071","MS Access error 2071","Cue Cards couldn't be started because of an incomplete setup."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64106,"title":"2072 - Outdated '<value>' file.  Please reinstall Microsoft Access.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["2072","Access error 2072","Microsoft Access","MSACCESS","Jet","VBA","Files","Outdated '|' file.  Please reinstall Microsoft Access.","Outdated '<value>' file.  Please reinstall Microsoft Access."],"errorCode":"2072","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2072: Outdated '<value>' file.  Please reinstall Microsoft Access.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2072: Outdated '<value>' file.  Please reinstall Microsoft Access..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 2072","MS Access error 2072","Outdated '|' file.  Please reinstall Microsoft Access."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64107,"title":"2073 - Specification doesn't exist in this database or has no columns defined.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2073","Access error 2073","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Specification doesn't exist in this database or has no columns defined.","Specification doesn't exist in this database or has no columns defined."],"errorCode":"2073","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2073: Specification doesn't exist in this database or has no columns defined.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2073: Specification doesn't exist in this database or has no columns defined..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2073","MS Access error 2073","Specification doesn't exist in this database or has no columns defined."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64108,"title":"2074 - There was an error while attempting to communicate with Cue Cards.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2074","Access error 2074","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","There was an error while attempting to communicate with Cue Cards.","There was an error while attempting to communicate with Cue Cards."],"errorCode":"2074","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2074: There was an error while attempting to communicate with Cue Cards.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2074: There was an error while attempting to communicate with Cue Cards..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2074","MS Access error 2074","There was an error while attempting to communicate with Cue Cards."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64109,"title":"2075 - The other application couldn't be found in any of the directories in your PATH.  Please check your AUTOEXEC.BAT file.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["2075","Access error 2075","Microsoft Access","MSACCESS","Jet","VBA","Files","The other application couldn't be found in any of the directories in your PATH.  Please check your AUTOEXEC.BAT file.","The other application couldn't be found in any of the directories in your PATH.  Please check your AUTOEXEC.BAT file."],"errorCode":"2075","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2075: The other application couldn't be found in any of the directories in your PATH.  Please check your AUTOEXEC.BAT file.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2075: The other application couldn't be found in any of the directories in your PATH.  Please check your AUTOEXEC.BAT file..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 2075","MS Access error 2075","The other application couldn't be found in any of the directories in your PATH.  Please check your AUTOEXEC.BAT file."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64110,"title":"2076 - The other application couldn't be started because the .EXE file isn't valid.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["2076","Access error 2076","Microsoft Access","MSACCESS","Jet","VBA","Files","The other application couldn't be started because the .EXE file isn't valid.","The other application couldn't be started because the .EXE file isn't valid."],"errorCode":"2076","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2076: The other application couldn't be started because the .EXE file isn't valid.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2076: The other application couldn't be started because the .EXE file isn't valid..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 2076","MS Access error 2076","The other application couldn't be started because the .EXE file isn't valid."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64111,"title":"2077 - This database currently has no import/export specifications.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2077","Access error 2077","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","This database currently has no import/export specifications.","This database currently has no import/export specifications."],"errorCode":"2077","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2077: This database currently has no import/export specifications.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2077: This database currently has no import/export specifications..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2077","MS Access error 2077","This database currently has no import/export specifications."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64112,"title":"2078 - Help isn't available due to lack of available memory or improper installation of Windows or Microsoft Access.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Resources"],"keywords":["2078","Access error 2078","Microsoft Access","MSACCESS","Jet","VBA","Resources","Help isn't available due to lack of available memory or improper installation of Windows or Microsoft Access.","Help isn't available due to lack of available memory or improper installation of Windows or Microsoft Access."],"errorCode":"2078","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2078: Help isn't available due to lack of available memory or improper installation of Windows or Microsoft Access.","rootCause":"Access or Windows lacks sufficient memory, stack, handles, disk, or other resources for the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Save work, close unnecessary objects/applications, check memory, handles, disk and database size, then reproduce after a controlled restart and review for runaway queries or code.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2078: Help isn't available due to lack of available memory or improper installation of Windows or Microsoft Access..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Resources"],"articleCategories":["Microsoft Access","Legacy Software","Resources"],"aliases":["Microsoft Access 2078","MS Access error 2078","Help isn't available due to lack of available memory or improper installation of Windows or Microsoft Access."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64113,"title":"2079 - Entry Required!","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2079","Access error 2079","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Entry Required!","Entry Required!"],"errorCode":"2079","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2079: Entry Required!","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2079: Entry Required!.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2079","MS Access error 2079","Entry Required!"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64114,"title":"2080 - Application is corrupted.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2080","Access error 2080","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Application is corrupted.","Application is corrupted."],"errorCode":"2080","eventId":"","severity":"High","summary":"Legacy Microsoft Access error 2080: Application is corrupted.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2080: Application is corrupted..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2080","MS Access error 2080","Application is corrupted."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64115,"title":"2081 - Specification has too many columns for that table.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2081","Access error 2081","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Specification has too many columns for that table.","Specification has too many columns for that table."],"errorCode":"2081","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2081: Specification has too many columns for that table.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2081: Specification has too many columns for that table..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2081","MS Access error 2081","Specification has too many columns for that table."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64116,"title":"2082 - Specification column '<value>' doesn't match a table column.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2082","Access error 2082","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Specification column '|' doesn't match a table column.","Specification column '<value>' doesn't match a table column."],"errorCode":"2082","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2082: Specification column '<value>' doesn't match a table column.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2082: Specification column '<value>' doesn't match a table column..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2082","MS Access error 2082","Specification column '|' doesn't match a table column."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64117,"title":"2083 - Database is read only -- cannot create specification tables.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2083","Access error 2083","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Database is read only -- cannot create specification tables.","Database is read only -- cannot create specification tables."],"errorCode":"2083","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2083: Database is read only -- cannot create specification tables.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2083: Database is read only -- cannot create specification tables..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2083","MS Access error 2083","Database is read only -- cannot create specification tables."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64118,"title":"2084 - Start and width must be greater than 0.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2084","Access error 2084","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Start and width must be greater than 0.","Start and width must be greater than 0."],"errorCode":"2084","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2084: Start and width must be greater than 0.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2084: Start and width must be greater than 0..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2084","MS Access error 2084","Start and width must be greater than 0."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64119,"title":"2085 - ODBC Refresh Interval must be in the range of 1-3600 seconds.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","ODBC"],"keywords":["2085","Access error 2085","Microsoft Access","MSACCESS","Jet","VBA","ODBC","ODBC Refresh Interval must be in the range of 1-3600 seconds.","ODBC Refresh Interval must be in the range of 1-3600 seconds."],"errorCode":"2085","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2085: ODBC Refresh Interval must be in the range of 1-3600 seconds.","rootCause":"The Access/Jet ODBC layer, driver, data source, server, query, data type, or connection state rejected the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Capture the native ODBC error, verify DSN/connection settings, driver architecture and version, credentials, server reachability, schema and data types, then reproduce with the smallest safe query.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2085: ODBC Refresh Interval must be in the range of 1-3600 seconds..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","ODBC"],"articleCategories":["Microsoft Access","Legacy Software","ODBC"],"aliases":["Microsoft Access 2085","MS Access error 2085","ODBC Refresh Interval must be in the range of 1-3600 seconds."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64120,"title":"2086 - Some Add-In menu entries couldn't be loaded because too many were specified.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2086","Access error 2086","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Some Add-In menu entries couldn't be loaded because too many were specified.","Some Add-In menu entries couldn't be loaded because too many were specified."],"errorCode":"2086","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2086: Some Add-In menu entries couldn't be loaded because too many were specified.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2086: Some Add-In menu entries couldn't be loaded because too many were specified..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2086","MS Access error 2086","Some Add-In menu entries couldn't be loaded because too many were specified."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64121,"title":"2087 - Add-In menu expression '<value>' is too long and will be ignored.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2087","Access error 2087","Microsoft Access","MSACCESS","Jet","VBA","Queries","Add-In menu expression '|' is too long and will be ignored.","Add-In menu expression '<value>' is too long and will be ignored."],"errorCode":"2087","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2087: Add-In menu expression '<value>' is too long and will be ignored.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2087: Add-In menu expression '<value>' is too long and will be ignored..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2087","MS Access error 2087","Add-In menu expression '|' is too long and will be ignored."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64122,"title":"2088 - Add-In menu expression is empty and will be ignored.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2088","Access error 2088","Microsoft Access","MSACCESS","Jet","VBA","Queries","Add-In menu expression is empty and will be ignored.","Add-In menu expression is empty and will be ignored."],"errorCode":"2088","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2088: Add-In menu expression is empty and will be ignored.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2088: Add-In menu expression is empty and will be ignored..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2088","MS Access error 2088","Add-In menu expression is empty and will be ignored."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64123,"title":"2100 - Can't place item at this location.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2100","Access error 2100","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't place item at this location.","Can't place item at this location."],"errorCode":"2100","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2100: Can't place item at this location.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2100: Can't place item at this location..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2100","MS Access error 2100","Can't place item at this location."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64124,"title":"2101 - The setting you entered isn't valid for this property.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2101","Access error 2101","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The setting you entered isn't valid for this property.","The setting you entered isn't valid for this property."],"errorCode":"2101","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2101: The setting you entered isn't valid for this property.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2101: The setting you entered isn't valid for this property..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2101","MS Access error 2101","The setting you entered isn't valid for this property."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64125,"title":"2102 - There is no form named '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2102","Access error 2102","Microsoft Access","MSACCESS","Jet","VBA","Access UI","There is no form named '|'.","There is no form named '<value>'."],"errorCode":"2102","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2102: There is no form named '<value>'.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2102: There is no form named '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2102","MS Access error 2102","There is no form named '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64126,"title":"2103 - There is no report named '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2103","Access error 2103","Microsoft Access","MSACCESS","Jet","VBA","Access UI","There is no report named '|'.","There is no report named '<value>'."],"errorCode":"2103","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2103: There is no report named '<value>'.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2103: There is no report named '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2103","MS Access error 2103","There is no report named '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64127,"title":"2104 - You already have a control named '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2104","Access error 2104","Microsoft Access","MSACCESS","Jet","VBA","Access UI","You already have a control named '|'.","You already have a control named '<value>'."],"errorCode":"2104","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2104: You already have a control named '<value>'.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2104: You already have a control named '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2104","MS Access error 2104","You already have a control named '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64128,"title":"2105 - Can't go to specified record.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2105","Access error 2105","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't go to specified record.","Can't go to specified record."],"errorCode":"2105","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2105: Can't go to specified record.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2105: Can't go to specified record..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2105","MS Access error 2105","Can't go to specified record."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64129,"title":"2106 - There were <value> errors while loading.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2106","Access error 2106","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","There were | errors while loading.","There were <value> errors while loading."],"errorCode":"2106","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2106: There were <value> errors while loading.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2106: There were <value> errors while loading..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2106","MS Access error 2106","There were | errors while loading."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64130,"title":"2107 - The value you entered is prohibited by the validation rule set for this field.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2107","Access error 2107","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","The value you entered is prohibited by the validation rule set for this field.","The value you entered is prohibited by the validation rule set for this field."],"errorCode":"2107","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2107: The value you entered is prohibited by the validation rule set for this field.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2107: The value you entered is prohibited by the validation rule set for this field..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2107","MS Access error 2107","The value you entered is prohibited by the validation rule set for this field."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64131,"title":"2108 - The GoToControl action can't be executed until the field being edited is saved.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2108","Access error 2108","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","The GoToControl action can't be executed until the field being edited is saved.","The GoToControl action can't be executed until the field being edited is saved."],"errorCode":"2108","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2108: The GoToControl action can't be executed until the field being edited is saved.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2108: The GoToControl action can't be executed until the field being edited is saved..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2108","MS Access error 2108","The GoToControl action can't be executed until the field being edited is saved."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64132,"title":"2109 - There is no control named '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2109","Access error 2109","Microsoft Access","MSACCESS","Jet","VBA","Access UI","There is no control named '|'.","There is no control named '<value>'."],"errorCode":"2109","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2109: There is no control named '<value>'.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2109: There is no control named '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2109","MS Access error 2109","There is no control named '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64133,"title":"2110 - Can't move to control <value>.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2110","Access error 2110","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Can't move to control |.","Can't move to control <value>."],"errorCode":"2110","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2110: Can't move to control <value>.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2110: Can't move to control <value>..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2110","MS Access error 2110","Can't move to control |."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64134,"title":"2111 - Couldn't save the changes you made.  Click OK to try again, or click Cancel to undo your changes.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2111","Access error 2111","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Couldn't save the changes you made.  Click OK to try again, or click Cancel to undo your changes.","Couldn't save the changes you made.  Click OK to try again, or click Cancel to undo your changes."],"errorCode":"2111","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2111: Couldn't save the changes you made.  Click OK to try again, or click Cancel to undo your changes.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2111: Couldn't save the changes you made.  Click OK to try again, or click Cancel to undo your changes..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2111","MS Access error 2111","Couldn't save the changes you made.  Click OK to try again, or click Cancel to undo your changes."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64135,"title":"2112 - Can't paste item.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2112","Access error 2112","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't paste item.","Can't paste item."],"errorCode":"2112","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2112: Can't paste item.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2112: Can't paste item..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2112","MS Access error 2112","Can't paste item."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64136,"title":"2113 - The value you entered isn't appropriate for this field.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2113","Access error 2113","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","The value you entered isn't appropriate for this field.","The value you entered isn't appropriate for this field."],"errorCode":"2113","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2113: The value you entered isn't appropriate for this field.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2113: The value you entered isn't appropriate for this field..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2113","MS Access error 2113","The value you entered isn't appropriate for this field."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64137,"title":"2114 - Invalid file format; can't load bitmap from file <value>.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["2114","Access error 2114","Microsoft Access","MSACCESS","Jet","VBA","Files","Invalid file format; can't load bitmap from file |.","Invalid file format; can't load bitmap from file <value>."],"errorCode":"2114","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2114: Invalid file format; can't load bitmap from file <value>.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2114: Invalid file format; can't load bitmap from file <value>..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 2114","MS Access error 2114","Invalid file format; can't load bitmap from file |."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64138,"title":"2115 - Field or record can't be saved while it's being validated.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2115","Access error 2115","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Field or record can't be saved while it's being validated.","Field or record can't be saved while it's being validated."],"errorCode":"2115","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2115: Field or record can't be saved while it's being validated.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2115: Field or record can't be saved while it's being validated..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2115","MS Access error 2115","Field or record can't be saved while it's being validated."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64139,"title":"2116 - Can't restore field's previous value; choose Undo Current Record or Undo Current Field from the Edit menu.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2116","Access error 2116","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't restore field's previous value; choose Undo Current Record or Undo Current Field from the Edit menu.","Can't restore field's previous value; choose Undo Current Record or Undo Current Field from the Edit menu."],"errorCode":"2116","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2116: Can't restore field's previous value; choose Undo Current Record or Undo Current Field from the Edit menu.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2116: Can't restore field's previous value; choose Undo Current Record or Undo Current Field from the Edit menu..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2116","MS Access error 2116","Can't restore field's previous value; choose Undo Current Record or Undo Current Field from the Edit menu."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64140,"title":"2117 - Text too long.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2117","Access error 2117","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Text too long.","Text too long."],"errorCode":"2117","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2117: Text too long.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2117: Text too long..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2117","MS Access error 2117","Text too long."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64141,"title":"2118 - The Requery action can't be executed until the field is saved.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2118","Access error 2118","Microsoft Access","MSACCESS","Jet","VBA","Queries","The Requery action can't be executed until the field is saved.","The Requery action can't be executed until the field is saved."],"errorCode":"2118","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2118: The Requery action can't be executed until the field is saved.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2118: The Requery action can't be executed until the field is saved..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2118","MS Access error 2118","The Requery action can't be executed until the field is saved."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64142,"title":"2119 - The Requery action can't be used on control <value>.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2119","Access error 2119","Microsoft Access","MSACCESS","Jet","VBA","Queries","The Requery action can't be used on control |.","The Requery action can't be used on control <value>."],"errorCode":"2119","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2119: The Requery action can't be used on control <value>.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2119: The Requery action can't be used on control <value>..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2119","MS Access error 2119","The Requery action can't be used on control |."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64143,"title":"2120 - You must select an existing table or query to use a FormWizard or ReportWizard.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2120","Access error 2120","Microsoft Access","MSACCESS","Jet","VBA","Queries","You must select an existing table or query to use a FormWizard or ReportWizard.","You must select an existing table or query to use a FormWizard or ReportWizard."],"errorCode":"2120","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2120: You must select an existing table or query to use a FormWizard or ReportWizard.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2120: You must select an existing table or query to use a FormWizard or ReportWizard..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2120","MS Access error 2120","You must select an existing table or query to use a FormWizard or ReportWizard."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64144,"title":"2121 - Data corrupted; can't open form <value>.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2121","Access error 2121","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Data corrupted; can't open form |.","Data corrupted; can't open form <value>."],"errorCode":"2121","eventId":"","severity":"High","summary":"Legacy Microsoft Access error 2121: Data corrupted; can't open form <value>.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2121: Data corrupted; can't open form <value>..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2121","MS Access error 2121","Data corrupted; can't open form |."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64145,"title":"2122 - Can't view a form as a continuous form if it contains a subform or an unbound OLE object.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2122","Access error 2122","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Can't view a form as a continuous form if it contains a subform or an unbound OLE object.","Can't view a form as a continuous form if it contains a subform or an unbound OLE object."],"errorCode":"2122","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2122: Can't view a form as a continuous form if it contains a subform or an unbound OLE object.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2122: Can't view a form as a continuous form if it contains a subform or an unbound OLE object..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2122","MS Access error 2122","Can't view a form as a continuous form if it contains a subform or an unbound OLE object."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64146,"title":"2123 - Not a valid control name.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2123","Access error 2123","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Not a valid control name.","Not a valid control name."],"errorCode":"2123","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2123: Not a valid control name.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2123: Not a valid control name..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2123","MS Access error 2123","Not a valid control name."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64147,"title":"2124 - Not a valid form name.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2124","Access error 2124","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Not a valid form name.","Not a valid form name."],"errorCode":"2124","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2124: Not a valid form name.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2124: Not a valid form name..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2124","MS Access error 2124","Not a valid form name."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64148,"title":"2125 - The setting for FontSize must be from 1 to 127.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2125","Access error 2125","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The setting for FontSize must be from 1 to 127.","The setting for FontSize must be from 1 to 127."],"errorCode":"2125","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2125: The setting for FontSize must be from 1 to 127.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2125: The setting for FontSize must be from 1 to 127..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2125","MS Access error 2125","The setting for FontSize must be from 1 to 127."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64149,"title":"2126 - The setting for ColumnCount must be from 1 to 255.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2126","Access error 2126","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The setting for ColumnCount must be from 1 to 255.","The setting for ColumnCount must be from 1 to 255."],"errorCode":"2126","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2126: The setting for ColumnCount must be from 1 to 255.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2126: The setting for ColumnCount must be from 1 to 255..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2126","MS Access error 2126","The setting for ColumnCount must be from 1 to 255."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64150,"title":"2127 - The setting for BoundColumn can't be greater than the number of columns set with the ColumnCount property.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2127","Access error 2127","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The setting for BoundColumn can't be greater than the number of columns set with the ColumnCount property.","The setting for BoundColumn can't be greater than the number of columns set with the ColumnCount property."],"errorCode":"2127","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2127: The setting for BoundColumn can't be greater than the number of columns set with the ColumnCount property.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2127: The setting for BoundColumn can't be greater than the number of columns set with the ColumnCount property..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2127","MS Access error 2127","The setting for BoundColumn can't be greater than the number of columns set with the ColumnCount property."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64151,"title":"2128 - The setting for RowSourceType must be Table/Query, Value List, Field List, or the name of a valid Access Basic fill function.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2128","Access error 2128","Microsoft Access","MSACCESS","Jet","VBA","Queries","The setting for RowSourceType must be Table/Query, Value List, Field List, or the name of a valid Access Basic fill function.","The setting for RowSourceType must be Table/Query, Value List, Field List, or the name of a valid Access Basic fill function."],"errorCode":"2128","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2128: The setting for RowSourceType must be Table/Query, Value List, Field List, or the name of a valid Access Basic fill function.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2128: The setting for RowSourceType must be Table/Query, Value List, Field List, or the name of a valid Access Basic fill function..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2128","MS Access error 2128","The setting for RowSourceType must be Table/Query, Value List, Field List, or the name of a valid Access Basic fill function."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64152,"title":"2129 - The setting for DefaultEditing must be Data Entry (1), Allow Edits (2), or Read Only (3).","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Security"],"keywords":["2129","Access error 2129","Microsoft Access","MSACCESS","Jet","VBA","Security","The setting for DefaultEditing must be Data Entry (1), Allow Edits (2), or Read Only (3).","The setting for DefaultEditing must be Data Entry (1), Allow Edits (2), or Read Only (3)."],"errorCode":"2129","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2129: The setting for DefaultEditing must be Data Entry (1), Allow Edits (2), or Read Only (3).","rootCause":"The operation is blocked by credentials, permissions, ownership, read-only state, or legacy workgroup security.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify identity and least-privilege permissions, file/share rights, database ownership and legacy workgroup configuration; do not weaken security controls globally.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2129: The setting for DefaultEditing must be Data Entry (1), Allow Edits (2), or Read Only (3)..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Security"],"articleCategories":["Microsoft Access","Legacy Software","Security"],"aliases":["Microsoft Access 2129","MS Access error 2129","The setting for DefaultEditing must be Data Entry (1), Allow Edits (2), or Read Only (3)."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64153,"title":"2130 - The setting for GridX or GridY must be from 1 to 64.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2130","Access error 2130","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The setting for GridX or GridY must be from 1 to 64.","The setting for GridX or GridY must be from 1 to 64."],"errorCode":"2130","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2130: The setting for GridX or GridY must be from 1 to 64.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2130: The setting for GridX or GridY must be from 1 to 64..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2130","MS Access error 2130","The setting for GridX or GridY must be from 1 to 64."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64154,"title":"2131 - An expression can't be longer than 2,048 characters.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2131","Access error 2131","Microsoft Access","MSACCESS","Jet","VBA","Queries","An expression can't be longer than 2,048 characters.","An expression can't be longer than 2,048 characters."],"errorCode":"2131","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2131: An expression can't be longer than 2,048 characters.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2131: An expression can't be longer than 2,048 characters..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2131","MS Access error 2131","An expression can't be longer than 2,048 characters."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64155,"title":"2132 - The setting for DecimalPlaces must be from 0 to 15.  You also can enter Auto (-1) for the default.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2132","Access error 2132","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The setting for DecimalPlaces must be from 0 to 15.  You also can enter Auto (-1) for the default.","The setting for DecimalPlaces must be from 0 to 15.  You also can enter Auto (-1) for the default."],"errorCode":"2132","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2132: The setting for DecimalPlaces must be from 0 to 15.  You also can enter Auto (-1) for the default.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2132: The setting for DecimalPlaces must be from 0 to 15.  You also can enter Auto (-1) for the default..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2132","MS Access error 2132","The setting for DecimalPlaces must be from 0 to 15.  You also can enter Auto (-1) for the default."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64156,"title":"2133 - A form can't be a subform within itself.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2133","Access error 2133","Microsoft Access","MSACCESS","Jet","VBA","Access UI","A form can't be a subform within itself.","A form can't be a subform within itself."],"errorCode":"2133","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2133: A form can't be a subform within itself.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2133: A form can't be a subform within itself..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2133","MS Access error 2133","A form can't be a subform within itself."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64157,"title":"2134 - The setting for Width must be from 0 to 22 inches (55.87 cm).","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2134","Access error 2134","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The setting for Width must be from 0 to 22 inches (55.87 cm).","The setting for Width must be from 0 to 22 inches (55.87 cm)."],"errorCode":"2134","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2134: The setting for Width must be from 0 to 22 inches (55.87 cm).","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2134: The setting for Width must be from 0 to 22 inches (55.87 cm)..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2134","MS Access error 2134","The setting for Width must be from 0 to 22 inches (55.87 cm)."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64158,"title":"2135 - You can't set this property; it's read-only.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2135","Access error 2135","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","You can't set this property; it's read-only.","You can't set this property; it's read-only."],"errorCode":"2135","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2135: You can't set this property; it's read-only.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2135: You can't set this property; it's read-only..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2135","MS Access error 2135","You can't set this property; it's read-only."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64159,"title":"2136 - This property can be set only in Design view; it's read-only otherwise.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2136","Access error 2136","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","This property can be set only in Design view; it's read-only otherwise.","This property can be set only in Design view; it's read-only otherwise."],"errorCode":"2136","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2136: This property can be set only in Design view; it's read-only otherwise.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2136: This property can be set only in Design view; it's read-only otherwise..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2136","MS Access error 2136","This property can be set only in Design view; it's read-only otherwise."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64160,"title":"2137 - Can't use Find or Replace for one of the following reasons: There are no fields to search; fields have no data; data in fields can't be searched.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2137","Access error 2137","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't use Find or Replace for one of the following reasons: There are no fields to search; fields have no data; data in fields can't be searched.","Can't use Find or Replace for one of the following reasons: There are no fields to search; fields have no data; data in fields can't be searched."],"errorCode":"2137","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2137: Can't use Find or Replace for one of the following reasons: There are no fields to search; fields have no data; data in fields can't be searched.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2137: Can't use Find or Replace for one of the following reasons: There are no fields to search; fields have no data; data in fields can't be searched..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2137","MS Access error 2137","Can't use Find or Replace for one of the following reasons: There are no fields to search; fields have no data; data in fields can't be searched."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64161,"title":"2138 - Can't search field because there was an error getting its value.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2138","Access error 2138","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't search field because there was an error getting its value.","Can't search field because there was an error getting its value."],"errorCode":"2138","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2138: Can't search field because there was an error getting its value.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2138: Can't search field because there was an error getting its value..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2138","MS Access error 2138","Can't search field because there was an error getting its value."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64162,"title":"2139 - Can't replace current value of field.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2139","Access error 2139","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't replace current value of field.","Can't replace current value of field."],"errorCode":"2139","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2139: Can't replace current value of field.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2139: Can't replace current value of field..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2139","MS Access error 2139","Can't replace current value of field."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64163,"title":"2140 - Couldn't save field.  Please undo and then choose Find or Replace.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2140","Access error 2140","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't save field.  Please undo and then choose Find or Replace.","Couldn't save field.  Please undo and then choose Find or Replace."],"errorCode":"2140","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2140: Couldn't save field.  Please undo and then choose Find or Replace.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2140: Couldn't save field.  Please undo and then choose Find or Replace..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2140","MS Access error 2140","Couldn't save field.  Please undo and then choose Find or Replace."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64164,"title":"2141 - No match to replace in current field.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2141","Access error 2141","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","No match to replace in current field.","No match to replace in current field."],"errorCode":"2141","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2141: No match to replace in current field.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2141: No match to replace in current field..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2141","MS Access error 2141","No match to replace in current field."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64165,"title":"2142 - The FindRecord action requires a FindWhat argument.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2142","Access error 2142","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","The FindRecord action requires a FindWhat argument.","The FindRecord action requires a FindWhat argument."],"errorCode":"2142","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2142: The FindRecord action requires a FindWhat argument.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2142: The FindRecord action requires a FindWhat argument..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2142","MS Access error 2142","The FindRecord action requires a FindWhat argument."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64166,"title":"2143 - Search Criteria wasn't specified; use the FindRecord action or the Find command.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2143","Access error 2143","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Search Criteria wasn't specified; use the FindRecord action or the Find command.","Search Criteria wasn't specified; use the FindRecord action or the Find command."],"errorCode":"2143","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2143: Search Criteria wasn't specified; use the FindRecord action or the Find command.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2143: Search Criteria wasn't specified; use the FindRecord action or the Find command..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2143","MS Access error 2143","Search Criteria wasn't specified; use the FindRecord action or the Find command."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64167,"title":"2144 - The setting for ListRows must be from 1 to 255.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2144","Access error 2144","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The setting for ListRows must be from 1 to 255.","The setting for ListRows must be from 1 to 255."],"errorCode":"2144","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2144: The setting for ListRows must be from 1 to 255.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2144: The setting for ListRows must be from 1 to 255..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2144","MS Access error 2144","The setting for ListRows must be from 1 to 255."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64168,"title":"2145 - ColumnWidths must be one or more values from 0 to 22 inches (55.87 cm), separated by ';' or the list separator.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2145","Access error 2145","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","ColumnWidths must be one or more values from 0 to 22 inches (55.87 cm), separated by ';' or the list separator.","ColumnWidths must be one or more values from 0 to 22 inches (55.87 cm), separated by ';' or the list separator."],"errorCode":"2145","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2145: ColumnWidths must be one or more values from 0 to 22 inches (55.87 cm), separated by ';' or the list separator.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2145: ColumnWidths must be one or more values from 0 to 22 inches (55.87 cm), separated by ';' or the list separator..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2145","MS Access error 2145","ColumnWidths must be one or more values from 0 to 22 inches (55.87 cm), separated by ';' or the list separator."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64169,"title":"2146 - Couldn't save field.  Please undo and then choose the Editing Allowed command.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2146","Access error 2146","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't save field.  Please undo and then choose the Editing Allowed command.","Couldn't save field.  Please undo and then choose the Editing Allowed command."],"errorCode":"2146","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2146: Couldn't save field.  Please undo and then choose the Editing Allowed command.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2146: Couldn't save field.  Please undo and then choose the Editing Allowed command..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2146","MS Access error 2146","Couldn't save field.  Please undo and then choose the Editing Allowed command."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64170,"title":"2147 - Controls can be created only in Design view.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2147","Access error 2147","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Controls can be created only in Design view.","Controls can be created only in Design view."],"errorCode":"2147","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2147: Controls can be created only in Design view.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2147: Controls can be created only in Design view..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2147","MS Access error 2147","Controls can be created only in Design view."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64171,"title":"2148 - The section ID is invalid.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2148","Access error 2148","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The section ID is invalid.","The section ID is invalid."],"errorCode":"2148","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2148: The section ID is invalid.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2148: The section ID is invalid..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2148","MS Access error 2148","The section ID is invalid."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64172,"title":"2149 - The item type is invalid.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2149","Access error 2149","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The item type is invalid.","The item type is invalid."],"errorCode":"2149","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2149: The item type is invalid.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2149: The item type is invalid..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2149","MS Access error 2149","The item type is invalid."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64173,"title":"2150 - This control can't contain other controls.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2150","Access error 2150","Microsoft Access","MSACCESS","Jet","VBA","Access UI","This control can't contain other controls.","This control can't contain other controls."],"errorCode":"2150","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2150: This control can't contain other controls.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2150: This control can't contain other controls..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2150","MS Access error 2150","This control can't contain other controls."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64174,"title":"2151 - This control can't contain that type of control.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2151","Access error 2151","Microsoft Access","MSACCESS","Jet","VBA","Access UI","This control can't contain that type of control.","This control can't contain that type of control."],"errorCode":"2151","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2151: This control can't contain that type of control.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2151: This control can't contain that type of control..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2151","MS Access error 2151","This control can't contain that type of control."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64175,"title":"2152 - Group levels can be created only in reports.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2152","Access error 2152","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Group levels can be created only in reports.","Group levels can be created only in reports."],"errorCode":"2152","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2152: Group levels can be created only in reports.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2152: Group levels can be created only in reports..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2152","MS Access error 2152","Group levels can be created only in reports."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64176,"title":"2153 - Maximum number of group levels exceeded.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2153","Access error 2153","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Maximum number of group levels exceeded.","Maximum number of group levels exceeded."],"errorCode":"2153","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2153: Maximum number of group levels exceeded.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2153: Maximum number of group levels exceeded..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2153","MS Access error 2153","Maximum number of group levels exceeded."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64177,"title":"2154 - Can't execute this function with the Sorting and Grouping box open.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2154","Access error 2154","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't execute this function with the Sorting and Grouping box open.","Can't execute this function with the Sorting and Grouping box open."],"errorCode":"2154","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2154: Can't execute this function with the Sorting and Grouping box open.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2154: Can't execute this function with the Sorting and Grouping box open..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2154","MS Access error 2154","Can't execute this function with the Sorting and Grouping box open."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64178,"title":"2155 - Access Basic compile error.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2155","Access error 2155","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Access Basic compile error.","Access Basic compile error."],"errorCode":"2155","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2155: Access Basic compile error.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2155: Access Basic compile error..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2155","MS Access error 2155","Access Basic compile error."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64179,"title":"2156 - Access Basic compile error.  Do you want to see the error in context?","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2156","Access error 2156","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Access Basic compile error.  Do you want to see the error in context?","Access Basic compile error.  Do you want to see the error in context?"],"errorCode":"2156","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2156: Access Basic compile error.  Do you want to see the error in context?","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2156: Access Basic compile error.  Do you want to see the error in context?.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2156","MS Access error 2156","Access Basic compile error.  Do you want to see the error in context?"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64180,"title":"2157 - The page header, footer, and margins are taller than the page.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2157","Access error 2157","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The page header, footer, and margins are taller than the page.","The page header, footer, and margins are taller than the page."],"errorCode":"2157","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2157: The page header, footer, and margins are taller than the page.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2157: The page header, footer, and margins are taller than the page..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2157","MS Access error 2157","The page header, footer, and margins are taller than the page."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64181,"title":"2158 - Print and graphics methods and their associated properties can be used only while printing or previewing a report.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2158","Access error 2158","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Print and graphics methods and their associated properties can be used only while printing or previewing a report.","Print and graphics methods and their associated properties can be used only while printing or previewing a report."],"errorCode":"2158","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2158: Print and graphics methods and their associated properties can be used only while printing or previewing a report.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2158: Print and graphics methods and their associated properties can be used only while printing or previewing a report..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2158","MS Access error 2158","Print and graphics methods and their associated properties can be used only while printing or previewing a report."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64182,"title":"2159 - Not enough memory to initialize print or graphics methods.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Resources"],"keywords":["2159","Access error 2159","Microsoft Access","MSACCESS","Jet","VBA","Resources","Not enough memory to initialize print or graphics methods.","Not enough memory to initialize print or graphics methods."],"errorCode":"2159","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2159: Not enough memory to initialize print or graphics methods.","rootCause":"Access or Windows lacks sufficient memory, stack, handles, disk, or other resources for the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Save work, close unnecessary objects/applications, check memory, handles, disk and database size, then reproduce after a controlled restart and review for runaway queries or code.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2159: Not enough memory to initialize print or graphics methods..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Resources"],"articleCategories":["Microsoft Access","Legacy Software","Resources"],"aliases":["Microsoft Access 2159","MS Access error 2159","Not enough memory to initialize print or graphics methods."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64183,"title":"2160 - An error occurred while initializing print or graphics methods.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2160","Access error 2160","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","An error occurred while initializing print or graphics methods.","An error occurred while initializing print or graphics methods."],"errorCode":"2160","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2160: An error occurred while initializing print or graphics methods.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2160: An error occurred while initializing print or graphics methods..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2160","MS Access error 2160","An error occurred while initializing print or graphics methods."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64184,"title":"2161 - FindWhat argument contains an invalid expression.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2161","Access error 2161","Microsoft Access","MSACCESS","Jet","VBA","Queries","FindWhat argument contains an invalid expression.","FindWhat argument contains an invalid expression."],"errorCode":"2161","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2161: FindWhat argument contains an invalid expression.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2161: FindWhat argument contains an invalid expression..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2161","MS Access error 2161","FindWhat argument contains an invalid expression."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64185,"title":"2162 - Can't search data using current FindRecord action arguments.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2162","Access error 2162","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't search data using current FindRecord action arguments.","Can't search data using current FindRecord action arguments."],"errorCode":"2162","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2162: Can't search data using current FindRecord action arguments.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2162: Can't search data using current FindRecord action arguments..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2162","MS Access error 2162","Can't search data using current FindRecord action arguments."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64186,"title":"2163 - Page number given as an argument for the GoToPage action is out of range.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2163","Access error 2163","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Page number given as an argument for the GoToPage action is out of range.","Page number given as an argument for the GoToPage action is out of range."],"errorCode":"2163","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2163: Page number given as an argument for the GoToPage action is out of range.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2163: Page number given as an argument for the GoToPage action is out of range..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2163","MS Access error 2163","Page number given as an argument for the GoToPage action is out of range."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64187,"title":"2164 - Can't disable the control that has the focus.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2164","Access error 2164","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Can't disable the control that has the focus.","Can't disable the control that has the focus."],"errorCode":"2164","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2164: Can't disable the control that has the focus.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2164: Can't disable the control that has the focus..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2164","MS Access error 2164","Can't disable the control that has the focus."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64188,"title":"2165 - Can't hide the control that has the focus.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2165","Access error 2165","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Can't hide the control that has the focus.","Can't hide the control that has the focus."],"errorCode":"2165","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2165: Can't hide the control that has the focus.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2165: Can't hide the control that has the focus..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2165","MS Access error 2165","Can't hide the control that has the focus."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64189,"title":"2166 - Can't lock the control that has the focus.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Locking"],"keywords":["2166","Access error 2166","Microsoft Access","MSACCESS","Jet","VBA","Locking","Can't lock the control that has the focus.","Can't lock the control that has the focus."],"errorCode":"2166","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2166: Can't lock the control that has the focus.","rootCause":"The database, page, record, or object is already locked or in use by another session.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Identify active users and the locking object, coordinate closure or retry, verify share permissions and healthy lock-file cleanup, and never delete a lock file while users remain connected.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2166: Can't lock the control that has the focus..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Locking"],"articleCategories":["Microsoft Access","Legacy Software","Locking"],"aliases":["Microsoft Access 2166","MS Access error 2166","Can't lock the control that has the focus."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64190,"title":"2167 - The setting for this property is read-only and can't be modified.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2167","Access error 2167","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The setting for this property is read-only and can't be modified.","The setting for this property is read-only and can't be modified."],"errorCode":"2167","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2167: The setting for this property is read-only and can't be modified.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2167: The setting for this property is read-only and can't be modified..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2167","MS Access error 2167","The setting for this property is read-only and can't be modified."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64191,"title":"2168 - The setting for this property can be changed only with the Object/Change Link command on the Edit menu.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2168","Access error 2168","Microsoft Access","MSACCESS","Jet","VBA","Access UI","The setting for this property can be changed only with the Object/Change Link command on the Edit menu.","The setting for this property can be changed only with the Object/Change Link command on the Edit menu."],"errorCode":"2168","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2168: The setting for this property can be changed only with the Object/Change Link command on the Edit menu.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2168: The setting for this property can be changed only with the Object/Change Link command on the Edit menu..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2168","MS Access error 2168","The setting for this property can be changed only with the Object/Change Link command on the Edit menu."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64192,"title":"2169 - The record being edited can't be saved.  If you close the form, the changes you've made to the record will be lost.  Close anyway?","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2169","Access error 2169","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","The record being edited can't be saved.  If you close the form, the changes you've made to the record will be lost.  Close anyway?","The record being edited can't be saved.  If you close the form, the changes you've made to the record will be lost.  Close anyway?"],"errorCode":"2169","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2169: The record being edited can't be saved.  If you close the form, the changes you've made to the record will be lost.  Close anyway?","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2169: The record being edited can't be saved.  If you close the form, the changes you've made to the record will be lost.  Close anyway?.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2169","MS Access error 2169","The record being edited can't be saved.  If you close the form, the changes you've made to the record will be lost.  Close anyway?"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64193,"title":"2170 - Can't retrieve data for the list box.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2170","Access error 2170","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't retrieve data for the list box.","Can't retrieve data for the list box."],"errorCode":"2170","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2170: Can't retrieve data for the list box.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2170: Can't retrieve data for the list box..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2170","MS Access error 2170","Can't retrieve data for the list box."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64194,"title":"2171 - Subforms can't be nested more than three deep.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2171","Access error 2171","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Subforms can't be nested more than three deep.","Subforms can't be nested more than three deep."],"errorCode":"2171","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2171: Subforms can't be nested more than three deep.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2171: Subforms can't be nested more than three deep..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2171","MS Access error 2171","Subforms can't be nested more than three deep."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64195,"title":"2172 - Can't use a form as a subform if the form is bound to a crosstab query in which the column headings can vary.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2172","Access error 2172","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't use a form as a subform if the form is bound to a crosstab query in which the column headings can vary.","Can't use a form as a subform if the form is bound to a crosstab query in which the column headings can vary."],"errorCode":"2172","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2172: Can't use a form as a subform if the form is bound to a crosstab query in which the column headings can vary.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2172: Can't use a form as a subform if the form is bound to a crosstab query in which the column headings can vary..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2172","MS Access error 2172","Can't use a form as a subform if the form is bound to a crosstab query in which the column headings can vary."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64196,"title":"2173 - Can't search in current field '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2173","Access error 2173","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't search in current field '|'.","Can't search in current field '<value>'."],"errorCode":"2173","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2173: Can't search in current field '<value>'.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2173: Can't search in current field '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2173","MS Access error 2173","Can't search in current field '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64197,"title":"2174 - Can't end browse mode from this form event.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2174","Access error 2174","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Can't end browse mode from this form event.","Can't end browse mode from this form event."],"errorCode":"2174","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2174: Can't end browse mode from this form event.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2174: Can't end browse mode from this form event..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2174","MS Access error 2174","Can't end browse mode from this form event."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64198,"title":"2175 - Out of memory during search.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Resources"],"keywords":["2175","Access error 2175","Microsoft Access","MSACCESS","Jet","VBA","Resources","Out of memory during search.","Out of memory during search."],"errorCode":"2175","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2175: Out of memory during search.","rootCause":"Access or Windows lacks sufficient memory, stack, handles, disk, or other resources for the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Save work, close unnecessary objects/applications, check memory, handles, disk and database size, then reproduce after a controlled restart and review for runaway queries or code.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2175: Out of memory during search..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Resources"],"articleCategories":["Microsoft Access","Legacy Software","Resources"],"aliases":["Microsoft Access 2175","MS Access error 2175","Out of memory during search."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64199,"title":"2176 - The setting for this property is too long.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2176","Access error 2176","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The setting for this property is too long.","The setting for this property is too long."],"errorCode":"2176","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2176: The setting for this property is too long.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2176: The setting for this property is too long..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2176","MS Access error 2176","The setting for this property is too long."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64200,"title":"2177 - Reports may only be embedded in other reports, not in forms.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","DDE"],"keywords":["2177","Access error 2177","Microsoft Access","MSACCESS","Jet","VBA","DDE","Reports may only be embedded in other reports, not in forms.","Reports may only be embedded in other reports, not in forms."],"errorCode":"2177","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2177: Reports may only be embedded in other reports, not in forms.","rootCause":"A legacy Dynamic Data Exchange channel, topic, application, timeout, or data format is unavailable or inconsistent.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the target application and topic, close stale conversations, verify both applications are responsive and version-compatible, and replace DDE with supported automation where practical.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2177: Reports may only be embedded in other reports, not in forms..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","DDE"],"articleCategories":["Microsoft Access","Legacy Software","DDE"],"aliases":["Microsoft Access 2177","MS Access error 2177","Reports may only be embedded in other reports, not in forms."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64201,"title":"2178 - Can't add section.  Doing so would exceed maximum combined section size limit.   You must shrink one of the existing sections first.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2178","Access error 2178","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't add section.  Doing so would exceed maximum combined section size limit.   You must shrink one of the existing sections first.","Can't add section.  Doing so would exceed maximum combined section size limit.   You must shrink one of the existing sections first."],"errorCode":"2178","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2178: Can't add section.  Doing so would exceed maximum combined section size limit.   You must shrink one of the existing sections first.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2178: Can't add section.  Doing so would exceed maximum combined section size limit.   You must shrink one of the existing sections first..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2178","MS Access error 2178","Can't add section.  Doing so would exceed maximum combined section size limit.   You must shrink one of the existing sections first."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64202,"title":"2179 - Couldn't open Palette.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2179","Access error 2179","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Couldn't open Palette.","Couldn't open Palette."],"errorCode":"2179","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2179: Couldn't open Palette.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2179: Couldn't open Palette..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2179","MS Access error 2179","Couldn't open Palette."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64203,"title":"2180 - Couldn't open toolbox.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2180","Access error 2180","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Couldn't open toolbox.","Couldn't open toolbox."],"errorCode":"2180","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2180: Couldn't open toolbox.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2180: Couldn't open toolbox..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2180","MS Access error 2180","Couldn't open toolbox."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64204,"title":"2200 - Not a valid number.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2200","Access error 2200","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Not a valid number.","Not a valid number."],"errorCode":"2200","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2200: Not a valid number.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2200: Not a valid number..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2200","MS Access error 2200","Not a valid number."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64205,"title":"2201 - An error occurred while attempting to retrieve printer information for the <value 1> on <value 2>","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2201","Access error 2201","Microsoft Access","MSACCESS","Jet","VBA","Access UI","An error occurred while attempting to retrieve printer information for the |1 on |2","An error occurred while attempting to retrieve printer information for the <value 1> on <value 2>"],"errorCode":"2201","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2201: An error occurred while attempting to retrieve printer information for the <value 1> on <value 2>","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2201: An error occurred while attempting to retrieve printer information for the <value 1> on <value 2>.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2201","MS Access error 2201","An error occurred while attempting to retrieve printer information for the |1 on |2"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64206,"title":"2202 - There is no default printer.  Select or install one using the Windows Control Panel.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2202","Access error 2202","Microsoft Access","MSACCESS","Jet","VBA","Queries","There is no default printer.  Select or install one using the Windows Control Panel.","There is no default printer.  Select or install one using the Windows Control Panel."],"errorCode":"2202","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2202: There is no default printer.  Select or install one using the Windows Control Panel.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2202: There is no default printer.  Select or install one using the Windows Control Panel..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2202","MS Access error 2202","There is no default printer.  Select or install one using the Windows Control Panel."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64207,"title":"2203 - COMMDLG.DLL failed: error code '0x<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2203","Access error 2203","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","COMMDLG.DLL failed: error code '0x|'.","COMMDLG.DLL failed: error code '0x<value>'."],"errorCode":"2203","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2203: COMMDLG.DLL failed: error code '0x<value>'.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2203: COMMDLG.DLL failed: error code '0x<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2203","MS Access error 2203","COMMDLG.DLL failed: error code '0x|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64208,"title":"2204 - The 'device=<value>' entry in the WIN.INI file isn't valid.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["2204","Access error 2204","Microsoft Access","MSACCESS","Jet","VBA","Files","The 'device=|' entry in the WIN.INI file isn't valid.","The 'device=<value>' entry in the WIN.INI file isn't valid."],"errorCode":"2204","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2204: The 'device=<value>' entry in the WIN.INI file isn't valid.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2204: The 'device=<value>' entry in the WIN.INI file isn't valid..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 2204","MS Access error 2204","The 'device=|' entry in the WIN.INI file isn't valid."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64209,"title":"2205 - The default printer driver '<value>.DRV' wasn't found.  Reinstall using the Windows Control Panel.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["2205","Access error 2205","Microsoft Access","MSACCESS","Jet","VBA","Files","The default printer driver '|.DRV' wasn't found.  Reinstall using the Windows Control Panel.","The default printer driver '<value>.DRV' wasn't found.  Reinstall using the Windows Control Panel."],"errorCode":"2205","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2205: The default printer driver '<value>.DRV' wasn't found.  Reinstall using the Windows Control Panel.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2205: The default printer driver '<value>.DRV' wasn't found.  Reinstall using the Windows Control Panel..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 2205","MS Access error 2205","The default printer driver '|.DRV' wasn't found.  Reinstall using the Windows Control Panel."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64210,"title":"2206 - Not a valid page number.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2206","Access error 2206","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Not a valid page number.","Not a valid page number."],"errorCode":"2206","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2206: Not a valid page number.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2206: Not a valid page number..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2206","MS Access error 2206","Not a valid page number."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64211,"title":"2207 - Can't print macros.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2207","Access error 2207","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Can't print macros.","Can't print macros."],"errorCode":"2207","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2207: Can't print macros.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2207: Can't print macros..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2207","MS Access error 2207","Can't print macros."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64212,"title":"2220 - Couldn't open file '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["2220","Access error 2220","Microsoft Access","MSACCESS","Jet","VBA","Files","Couldn't open file '|'.","Couldn't open file '<value>'."],"errorCode":"2220","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2220: Couldn't open file '<value>'.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2220: Couldn't open file '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 2220","MS Access error 2220","Couldn't open file '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64213,"title":"2221 - Text would be too long; change cancelled.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2221","Access error 2221","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Text would be too long; change cancelled.","Text would be too long; change cancelled."],"errorCode":"2221","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2221: Text would be too long; change cancelled.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2221: Text would be too long; change cancelled..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2221","MS Access error 2221","Text would be too long; change cancelled."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64214,"title":"2222 - This control is read-only and can't be modified.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2222","Access error 2222","Microsoft Access","MSACCESS","Jet","VBA","Access UI","This control is read-only and can't be modified.","This control is read-only and can't be modified."],"errorCode":"2222","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2222: This control is read-only and can't be modified.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2222: This control is read-only and can't be modified..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2222","MS Access error 2222","This control is read-only and can't be modified."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64215,"title":"2223 - The file name '<value>' is too long.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["2223","Access error 2223","Microsoft Access","MSACCESS","Jet","VBA","Files","The file name '|' is too long.","The file name '<value>' is too long."],"errorCode":"2223","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2223: The file name '<value>' is too long.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2223: The file name '<value>' is too long..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 2223","MS Access error 2223","The file name '|' is too long."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64216,"title":"2224 - Name '<value>' contains invalid characters.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2224","Access error 2224","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Name '|' contains invalid characters.","Name '<value>' contains invalid characters."],"errorCode":"2224","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2224: Name '<value>' contains invalid characters.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2224: Name '<value>' contains invalid characters..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2224","MS Access error 2224","Name '|' contains invalid characters."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64217,"title":"2225 - Couldn't open the Clipboard.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2225","Access error 2225","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Couldn't open the Clipboard.","Couldn't open the Clipboard."],"errorCode":"2225","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2225: Couldn't open the Clipboard.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2225: Couldn't open the Clipboard..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2225","MS Access error 2225","Couldn't open the Clipboard."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64218,"title":"2226 - Can't paste.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2226","Access error 2226","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't paste.","Can't paste."],"errorCode":"2226","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2226: Can't paste.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2226: Can't paste..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2226","MS Access error 2226","Can't paste."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64219,"title":"2227 - Data format error; can't paste.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2227","Access error 2227","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Data format error; can't paste.","Data format error; can't paste."],"errorCode":"2227","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2227: Data format error; can't paste.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2227: Data format error; can't paste..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2227","MS Access error 2227","Data format error; can't paste."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64220,"title":"2228 - Can't load or save object.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2228","Access error 2228","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't load or save object.","Can't load or save object."],"errorCode":"2228","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2228: Can't load or save object.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2228: Can't load or save object..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2228","MS Access error 2228","Can't load or save object."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64221,"title":"2229 - Can't start object's source application.  Use the Windows Registration Info Editor (REGEDIT.EXE) to verify that the application is properly installed.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2229","Access error 2229","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't start object's source application.  Use the Windows Registration Info Editor (REGEDIT.EXE) to verify that the application is properly installed.","Can't start object's source application.  Use the Windows Registration Info Editor (REGEDIT.EXE) to verify that the application is properly installed."],"errorCode":"2229","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2229: Can't start object's source application.  Use the Windows Registration Info Editor (REGEDIT.EXE) to verify that the application is properly installed.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2229: Can't start object's source application.  Use the Windows Registration Info Editor (REGEDIT.EXE) to verify that the application is properly installed..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2229","MS Access error 2229","Can't start object's source application.  Use the Windows Registration Info Editor (REGEDIT.EXE) to verify that the application is properly installed."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64222,"title":"2230 - Invalid source application name.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2230","Access error 2230","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Invalid source application name.","Invalid source application name."],"errorCode":"2230","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2230: Invalid source application name.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2230: Invalid source application name..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2230","MS Access error 2230","Invalid source application name."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64223,"title":"2231 - Errors encountered during OLE operation.  The problem ID is '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2231","Access error 2231","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Errors encountered during OLE operation.  The problem ID is '|'.","Errors encountered during OLE operation.  The problem ID is '<value>'."],"errorCode":"2231","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2231: Errors encountered during OLE operation.  The problem ID is '<value>'.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2231: Errors encountered during OLE operation.  The problem ID is '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2231","MS Access error 2231","Errors encountered during OLE operation.  The problem ID is '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64224,"title":"2232 - You can't edit this object because it is no longer linked or wasn't created in an application that supports OLE.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2232","Access error 2232","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","You can't edit this object because it is no longer linked or wasn't created in an application that supports OLE.","You can't edit this object because it is no longer linked or wasn't created in an application that supports OLE."],"errorCode":"2232","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2232: You can't edit this object because it is no longer linked or wasn't created in an application that supports OLE.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2232: You can't edit this object because it is no longer linked or wasn't created in an application that supports OLE..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2232","MS Access error 2232","You can't edit this object because it is no longer linked or wasn't created in an application that supports OLE."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64225,"title":"2233 - Can't break link; this object is open for editing.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2233","Access error 2233","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't break link; this object is open for editing.","Can't break link; this object is open for editing."],"errorCode":"2233","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2233: Can't break link; this object is open for editing.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2233: Can't break link; this object is open for editing..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2233","MS Access error 2233","Can't break link; this object is open for editing."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64226,"title":"2234 - Can't paste OLE object.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2234","Access error 2234","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't paste OLE object.","Can't paste OLE object."],"errorCode":"2234","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2234: Can't paste OLE object.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2234: Can't paste OLE object..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2234","MS Access error 2234","Can't paste OLE object."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64227,"title":"2235 - There are no registered source applications.  Use the Windows Registration Info Editor (REGEDIT.EXE) to view installed servers.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2235","Access error 2235","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","There are no registered source applications.  Use the Windows Registration Info Editor (REGEDIT.EXE) to view installed servers.","There are no registered source applications.  Use the Windows Registration Info Editor (REGEDIT.EXE) to view installed servers."],"errorCode":"2235","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2235: There are no registered source applications.  Use the Windows Registration Info Editor (REGEDIT.EXE) to view installed servers.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2235: There are no registered source applications.  Use the Windows Registration Info Editor (REGEDIT.EXE) to view installed servers..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2235","MS Access error 2235","There are no registered source applications.  Use the Windows Registration Info Editor (REGEDIT.EXE) to view installed servers."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64228,"title":"2236 - Must finish creating OLE object before saving.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2236","Access error 2236","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Must finish creating OLE object before saving.","Must finish creating OLE object before saving."],"errorCode":"2236","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2236: Must finish creating OLE object before saving.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2236: Must finish creating OLE object before saving..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2236","MS Access error 2236","Must finish creating OLE object before saving."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64229,"title":"2237 - The text you enter must match an entry in the list.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2237","Access error 2237","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The text you enter must match an entry in the list.","The text you enter must match an entry in the list."],"errorCode":"2237","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2237: The text you enter must match an entry in the list.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2237: The text you enter must match an entry in the list..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2237","MS Access error 2237","The text you enter must match an entry in the list."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64230,"title":"2238 - Not a valid OLE object.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2238","Access error 2238","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Not a valid OLE object.","Not a valid OLE object."],"errorCode":"2238","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2238: Not a valid OLE object.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2238: Not a valid OLE object..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2238","MS Access error 2238","Not a valid OLE object."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64231,"title":"2239 - '<value>' is corrupted or isn't a Microsoft Access database file.  To repair, open non-read only.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2239","Access error 2239","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","'|' is corrupted or isn't a Microsoft Access database file.  To repair, open non-read only.","'<value>' is corrupted or isn't a Microsoft Access database file.  To repair, open non-read only."],"errorCode":"2239","eventId":"","severity":"High","summary":"Legacy Microsoft Access error 2239: '<value>' is corrupted or isn't a Microsoft Access database file.  To repair, open non-read only.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2239: '<value>' is corrupted or isn't a Microsoft Access database file.  To repair, open non-read only..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2239","MS Access error 2239","'|' is corrupted or isn't a Microsoft Access database file.  To repair, open non-read only."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64232,"title":"2240 - Unexpected data exchange error.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2240","Access error 2240","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Unexpected data exchange error.","Unexpected data exchange error."],"errorCode":"2240","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2240: Unexpected data exchange error.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2240: Unexpected data exchange error..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2240","MS Access error 2240","Unexpected data exchange error."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64233,"title":"2241 - The <value> object is corrupted and might not be displayed properly.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2241","Access error 2241","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The | object is corrupted and might not be displayed properly.","The <value> object is corrupted and might not be displayed properly."],"errorCode":"2241","eventId":"","severity":"High","summary":"Legacy Microsoft Access error 2241: The <value> object is corrupted and might not be displayed properly.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2241: The <value> object is corrupted and might not be displayed properly..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2241","MS Access error 2241","The | object is corrupted and might not be displayed properly."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64234,"title":"2242 - Problem communicating with object's source application.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2242","Access error 2242","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Problem communicating with object's source application.","Problem communicating with object's source application."],"errorCode":"2242","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2242: Problem communicating with object's source application.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2242: Problem communicating with object's source application..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2242","MS Access error 2242","Problem communicating with object's source application."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64235,"title":"2243 - Can't paste OLE object.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2243","Access error 2243","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't paste OLE object.","Can't paste OLE object."],"errorCode":"2243","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2243: Can't paste OLE object.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2243: Can't paste OLE object..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2243","MS Access error 2243","Can't paste OLE object."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64236,"title":"2244 - An unrecoverable error occured while reading the file '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["2244","Access error 2244","Microsoft Access","MSACCESS","Jet","VBA","Files","An unrecoverable error occured while reading the file '|'.","An unrecoverable error occured while reading the file '<value>'."],"errorCode":"2244","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2244: An unrecoverable error occured while reading the file '<value>'.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2244: An unrecoverable error occured while reading the file '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 2244","MS Access error 2244","An unrecoverable error occured while reading the file '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64237,"title":"2245 - Specified icon is corrupted.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2245","Access error 2245","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Specified icon is corrupted.","Specified icon is corrupted."],"errorCode":"2245","eventId":"","severity":"High","summary":"Legacy Microsoft Access error 2245: Specified icon is corrupted.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2245: Specified icon is corrupted..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2245","MS Access error 2245","Specified icon is corrupted."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64238,"title":"2246 - Can't run query; parameter values too large.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2246","Access error 2246","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't run query; parameter values too large.","Can't run query; parameter values too large."],"errorCode":"2246","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2246: Can't run query; parameter values too large.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2246: Can't run query; parameter values too large..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2246","MS Access error 2246","Can't run query; parameter values too large."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64239,"title":"2247 - The object in this field has been corrupted and can't be loaded.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2247","Access error 2247","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","The object in this field has been corrupted and can't be loaded.","The object in this field has been corrupted and can't be loaded."],"errorCode":"2247","eventId":"","severity":"High","summary":"Legacy Microsoft Access error 2247: The object in this field has been corrupted and can't be loaded.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2247: The object in this field has been corrupted and can't be loaded..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2247","MS Access error 2247","The object in this field has been corrupted and can't be loaded."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64240,"title":"2248 - An error occured while using an OLE object.  Operation failed.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2248","Access error 2248","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","An error occured while using an OLE object.  Operation failed.","An error occured while using an OLE object.  Operation failed."],"errorCode":"2248","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2248: An error occured while using an OLE object.  Operation failed.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2248: An error occured while using an OLE object.  Operation failed..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2248","MS Access error 2248","An error occured while using an OLE object.  Operation failed."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64241,"title":"2249 - An error occurred while communicating with the other application.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2249","Access error 2249","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","An error occurred while communicating with the other application.","An error occurred while communicating with the other application."],"errorCode":"2249","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2249: An error occurred while communicating with the other application.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2249: An error occurred while communicating with the other application..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2249","MS Access error 2249","An error occurred while communicating with the other application."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64242,"title":"2250 - Errors encountered while communicating with the source application.  Some memory couldn't be returned to the system.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Resources"],"keywords":["2250","Access error 2250","Microsoft Access","MSACCESS","Jet","VBA","Resources","Errors encountered while communicating with the source application.  Some memory couldn't be returned to the system.","Errors encountered while communicating with the source application.  Some memory couldn't be returned to the system."],"errorCode":"2250","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2250: Errors encountered while communicating with the source application.  Some memory couldn't be returned to the system.","rootCause":"Access or Windows lacks sufficient memory, stack, handles, disk, or other resources for the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Save work, close unnecessary objects/applications, check memory, handles, disk and database size, then reproduce after a controlled restart and review for runaway queries or code.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2250: Errors encountered while communicating with the source application.  Some memory couldn't be returned to the system..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Resources"],"articleCategories":["Microsoft Access","Legacy Software","Resources"],"aliases":["Microsoft Access 2250","MS Access error 2250","Errors encountered while communicating with the source application.  Some memory couldn't be returned to the system."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64243,"title":"2251 - The OLE object is linked to a file on an unknown drive.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["2251","Access error 2251","Microsoft Access","MSACCESS","Jet","VBA","Files","The OLE object is linked to a file on an unknown drive.","The OLE object is linked to a file on an unknown drive."],"errorCode":"2251","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2251: The OLE object is linked to a file on an unknown drive.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2251: The OLE object is linked to a file on an unknown drive..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 2251","MS Access error 2251","The OLE object is linked to a file on an unknown drive."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64244,"title":"2252 - Couldn't establish network connection needed to link object.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2252","Access error 2252","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Couldn't establish network connection needed to link object.","Couldn't establish network connection needed to link object."],"errorCode":"2252","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2252: Couldn't establish network connection needed to link object.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2252: Couldn't establish network connection needed to link object..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2252","MS Access error 2252","Couldn't establish network connection needed to link object."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64245,"title":"2253 - Not a valid name for the OLE object or document.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2253","Access error 2253","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Not a valid name for the OLE object or document.","Not a valid name for the OLE object or document."],"errorCode":"2253","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2253: Not a valid name for the OLE object or document.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2253: Not a valid name for the OLE object or document..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2253","MS Access error 2253","Not a valid name for the OLE object or document."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64246,"title":"2254 - Couldn't create requested new object.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2254","Access error 2254","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Couldn't create requested new object.","Couldn't create requested new object."],"errorCode":"2254","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2254: Couldn't create requested new object.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2254: Couldn't create requested new object..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2254","MS Access error 2254","Couldn't create requested new object."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64247,"title":"2255 - The source application couldn't open the document; link may not be valid.  Use the Object/Change Link command to repair the link.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2255","Access error 2255","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The source application couldn't open the document; link may not be valid.  Use the Object/Change Link command to repair the link.","The source application couldn't open the document; link may not be valid.  Use the Object/Change Link command to repair the link."],"errorCode":"2255","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2255: The source application couldn't open the document; link may not be valid.  Use the Object/Change Link command to repair the link.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2255: The source application couldn't open the document; link may not be valid.  Use the Object/Change Link command to repair the link..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2255","MS Access error 2255","The source application couldn't open the document; link may not be valid.  Use the Object/Change Link command to repair the link."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64248,"title":"2256 - An error occurred while the source application was executing a command.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2256","Access error 2256","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","An error occurred while the source application was executing a command.","An error occurred while the source application was executing a command."],"errorCode":"2256","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2256: An error occurred while the source application was executing a command.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2256: An error occurred while the source application was executing a command..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2256","MS Access error 2256","An error occurred while the source application was executing a command."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64249,"title":"2257 - An error occurred trying to hide or display the object's source application.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2257","Access error 2257","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","An error occurred trying to hide or display the object's source application.","An error occurred trying to hide or display the object's source application."],"errorCode":"2257","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2257: An error occurred trying to hide or display the object's source application.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2257: An error occurred trying to hide or display the object's source application..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2257","MS Access error 2257","An error occurred trying to hide or display the object's source application."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64250,"title":"2258 - Couldn't carry out requested operation on object.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2258","Access error 2258","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Couldn't carry out requested operation on object.","Couldn't carry out requested operation on object."],"errorCode":"2258","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2258: Couldn't carry out requested operation on object.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2258: Couldn't carry out requested operation on object..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2258","MS Access error 2258","Couldn't carry out requested operation on object."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64251,"title":"2259 - Couldn't rename the object.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2259","Access error 2259","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Couldn't rename the object.","Couldn't rename the object."],"errorCode":"2259","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2259: Couldn't rename the object.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2259: Couldn't rename the object..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2259","MS Access error 2259","Couldn't rename the object."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64252,"title":"2260 - An error occurred while sending data to the object's source application.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2260","Access error 2260","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","An error occurred while sending data to the object's source application.","An error occurred while sending data to the object's source application."],"errorCode":"2260","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2260: An error occurred while sending data to the object's source application.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2260: An error occurred while sending data to the object's source application..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2260","MS Access error 2260","An error occurred while sending data to the object's source application."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64253,"title":"2261 - The object's source application didn't supply the requested data.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2261","Access error 2261","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The object's source application didn't supply the requested data.","The object's source application didn't supply the requested data."],"errorCode":"2261","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2261: The object's source application didn't supply the requested data.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2261: The object's source application didn't supply the requested data..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2261","MS Access error 2261","The object's source application didn't supply the requested data."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64254,"title":"2262 - This value must be a number.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2262","Access error 2262","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","This value must be a number.","This value must be a number."],"errorCode":"2262","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2262: This value must be a number.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2262: This value must be a number..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2262","MS Access error 2262","This value must be a number."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64255,"title":"2263 - The number is too large.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2263","Access error 2263","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The number is too large.","The number is too large."],"errorCode":"2263","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2263: The number is too large.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2263: The number is too large..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2263","MS Access error 2263","The number is too large."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64256,"title":"2264 - Not a recognized unit of measurement.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2264","Access error 2264","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Not a recognized unit of measurement.","Not a recognized unit of measurement."],"errorCode":"2264","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2264: Not a recognized unit of measurement.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2264: Not a recognized unit of measurement..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2264","MS Access error 2264","Not a recognized unit of measurement."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64257,"title":"2265 - Must specify a unit of measurement.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2265","Access error 2265","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Must specify a unit of measurement.","Must specify a unit of measurement."],"errorCode":"2265","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2265: Must specify a unit of measurement.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2265: Must specify a unit of measurement..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2265","MS Access error 2265","Must specify a unit of measurement."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64258,"title":"2266 - '<value>' isn't a valid setting for RowSourceType property.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2266","Access error 2266","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","'|' isn't a valid setting for RowSourceType property.","'<value>' isn't a valid setting for RowSourceType property."],"errorCode":"2266","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2266: '<value>' isn't a valid setting for RowSourceType property.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2266: '<value>' isn't a valid setting for RowSourceType property..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2266","MS Access error 2266","'|' isn't a valid setting for RowSourceType property."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64259,"title":"2267 - Not enough disk space for printing.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["2267","Access error 2267","Microsoft Access","MSACCESS","Jet","VBA","Files","Not enough disk space for printing.","Not enough disk space for printing."],"errorCode":"2267","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2267: Not enough disk space for printing.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2267: Not enough disk space for printing..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 2267","MS Access error 2267","Not enough disk space for printing."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64260,"title":"2268 - Not enough memory to load some library databases.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2268","Access error 2268","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Not enough memory to load some library databases.","Not enough memory to load some library databases."],"errorCode":"2268","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2268: Not enough memory to load some library databases.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2268: Not enough memory to load some library databases..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2268","MS Access error 2268","Not enough memory to load some library databases."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64261,"title":"2269 - Some library databases couldn't be loaded because too many were specified.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2269","Access error 2269","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Some library databases couldn't be loaded because too many were specified.","Some library databases couldn't be loaded because too many were specified."],"errorCode":"2269","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2269: Some library databases couldn't be loaded because too many were specified.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2269: Some library databases couldn't be loaded because too many were specified..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2269","MS Access error 2269","Some library databases couldn't be loaded because too many were specified."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64262,"title":"2270 - Couldn't compile module in utility or library databases.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2270","Access error 2270","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't compile module in utility or library databases.","Couldn't compile module in utility or library databases."],"errorCode":"2270","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2270: Couldn't compile module in utility or library databases.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2270: Couldn't compile module in utility or library databases..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2270","MS Access error 2270","Couldn't compile module in utility or library databases."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64263,"title":"2271 - [Libraries] section missing from MSACCESS.INI; FormWizards and ReportWizards won't be available.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2271","Access error 2271","Microsoft Access","MSACCESS","Jet","VBA","Access UI","[Libraries] section missing from MSACCESS.INI; FormWizards and ReportWizards won't be available.","[Libraries] section missing from MSACCESS.INI; FormWizards and ReportWizards won't be available."],"errorCode":"2271","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2271: [Libraries] section missing from MSACCESS.INI; FormWizards and ReportWizards won't be available.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2271: [Libraries] section missing from MSACCESS.INI; FormWizards and ReportWizards won't be available..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2271","MS Access error 2271","[Libraries] section missing from MSACCESS.INI; FormWizards and ReportWizards won't be available."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64264,"title":"2272 - The setting for the Update Retry Interval must be from 0 to 1,000 milliseconds.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2272","Access error 2272","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The setting for the Update Retry Interval must be from 0 to 1,000 milliseconds.","The setting for the Update Retry Interval must be from 0 to 1,000 milliseconds."],"errorCode":"2272","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2272: The setting for the Update Retry Interval must be from 0 to 1,000 milliseconds.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2272: The setting for the Update Retry Interval must be from 0 to 1,000 milliseconds..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2272","MS Access error 2272","The setting for the Update Retry Interval must be from 0 to 1,000 milliseconds."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64265,"title":"2273 - The setting for Insert Retries must be from 0 to 10.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2273","Access error 2273","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The setting for Insert Retries must be from 0 to 10.","The setting for Insert Retries must be from 0 to 10."],"errorCode":"2273","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2273: The setting for Insert Retries must be from 0 to 10.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2273: The setting for Insert Retries must be from 0 to 10..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2273","MS Access error 2273","The setting for Insert Retries must be from 0 to 10."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64266,"title":"2274 - The database '<value>' is already open as a library database.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2274","Access error 2274","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","The database '|' is already open as a library database.","The database '<value>' is already open as a library database."],"errorCode":"2274","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2274: The database '<value>' is already open as a library database.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2274: The database '<value>' is already open as a library database..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2274","MS Access error 2274","The database '|' is already open as a library database."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64267,"title":"2275 - The string returned by the builder was too long.  Truncating result.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2275","Access error 2275","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The string returned by the builder was too long.  Truncating result.","The string returned by the builder was too long.  Truncating result."],"errorCode":"2275","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2275: The string returned by the builder was too long.  Truncating result.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2275: The string returned by the builder was too long.  Truncating result..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2275","MS Access error 2275","The string returned by the builder was too long.  Truncating result."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64268,"title":"2276 - The current window is not the window that invoked the builder. Builder failed.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2276","Access error 2276","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The current window is not the window that invoked the builder. Builder failed.","The current window is not the window that invoked the builder. Builder failed."],"errorCode":"2276","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2276: The current window is not the window that invoked the builder. Builder failed.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2276: The current window is not the window that invoked the builder. Builder failed..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2276","MS Access error 2276","The current window is not the window that invoked the builder. Builder failed."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64269,"title":"2277 - Error in font initialization.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2277","Access error 2277","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Error in font initialization.","Error in font initialization."],"errorCode":"2277","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2277: Error in font initialization.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2277: Error in font initialization..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2277","MS Access error 2277","Error in font initialization."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64270,"title":"2278 - Can't save changes to this object because you don't have permission to write to the record. Copy the object to the Clipboard if you want to save it, then choose Undo Field.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2278","Access error 2278","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't save changes to this object because you don't have permission to write to the record. Copy the object to the Clipboard if you want to save it, then choose Undo Field.","Can't save changes to this object because you don't have permission to write to the record. Copy the object to the Clipboard if you want to save it, then choose Undo Field."],"errorCode":"2278","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2278: Can't save changes to this object because you don't have permission to write to the record. Copy the object to the Clipboard if you want to save it, then choose Undo Field.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2278: Can't save changes to this object because you don't have permission to write to the record. Copy the object to the Clipboard if you want to save it, then choose Undo Field..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2278","MS Access error 2278","Can't save changes to this object because you don't have permission to write to the record. Copy the object to the Clipboard if you want to save it, then choose Undo Field."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64271,"title":"2320 - Can't display the field in which Total cell is 'Where'.  Turn off the Show option for that field.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2320","Access error 2320","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't display the field in which Total cell is 'Where'.  Turn off the Show option for that field.","Can't display the field in which Total cell is 'Where'.  Turn off the Show option for that field."],"errorCode":"2320","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2320: Can't display the field in which Total cell is 'Where'.  Turn off the Show option for that field.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2320: Can't display the field in which Total cell is 'Where'.  Turn off the Show option for that field..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2320","MS Access error 2320","Can't display the field in which Total cell is 'Where'.  Turn off the Show option for that field."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64272,"title":"2321 - Can't set criteria unless you've specified a field.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2321","Access error 2321","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't set criteria unless you've specified a field.","Can't set criteria unless you've specified a field."],"errorCode":"2321","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2321: Can't set criteria unless you've specified a field.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2321: Can't set criteria unless you've specified a field..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2321","MS Access error 2321","Can't set criteria unless you've specified a field."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64273,"title":"2322 - Can't sort on fields added to the QBE grid with the asterisk.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","DDE"],"keywords":["2322","Access error 2322","Microsoft Access","MSACCESS","Jet","VBA","DDE","Can't sort on fields added to the QBE grid with the asterisk.","Can't sort on fields added to the QBE grid with the asterisk."],"errorCode":"2322","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2322: Can't sort on fields added to the QBE grid with the asterisk.","rootCause":"A legacy Dynamic Data Exchange channel, topic, application, timeout, or data format is unavailable or inconsistent.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the target application and topic, close stale conversations, verify both applications are responsive and version-compatible, and replace DDE with supported automation where practical.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2322: Can't sort on fields added to the QBE grid with the asterisk..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","DDE"],"articleCategories":["Microsoft Access","Legacy Software","DDE"],"aliases":["Microsoft Access 2322","MS Access error 2322","Can't sort on fields added to the QBE grid with the asterisk."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64274,"title":"2323 - Can't have a Criteria clause on fields added to the QBE grid with the asterisk.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","DDE"],"keywords":["2323","Access error 2323","Microsoft Access","MSACCESS","Jet","VBA","DDE","Can't have a Criteria clause on fields added to the QBE grid with the asterisk.","Can't have a Criteria clause on fields added to the QBE grid with the asterisk."],"errorCode":"2323","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2323: Can't have a Criteria clause on fields added to the QBE grid with the asterisk.","rootCause":"A legacy Dynamic Data Exchange channel, topic, application, timeout, or data format is unavailable or inconsistent.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the target application and topic, close stale conversations, verify both applications are responsive and version-compatible, and replace DDE with supported automation where practical.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2323: Can't have a Criteria clause on fields added to the QBE grid with the asterisk..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","DDE"],"articleCategories":["Microsoft Access","Legacy Software","DDE"],"aliases":["Microsoft Access 2323","MS Access error 2323","Can't have a Criteria clause on fields added to the QBE grid with the asterisk."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64275,"title":"2324 - Can't show Totals on fields added to the QBE grid with the asterisk.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","DDE"],"keywords":["2324","Access error 2324","Microsoft Access","MSACCESS","Jet","VBA","DDE","Can't show Totals on fields added to the QBE grid with the asterisk.","Can't show Totals on fields added to the QBE grid with the asterisk."],"errorCode":"2324","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2324: Can't show Totals on fields added to the QBE grid with the asterisk.","rootCause":"A legacy Dynamic Data Exchange channel, topic, application, timeout, or data format is unavailable or inconsistent.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the target application and topic, close stale conversations, verify both applications are responsive and version-compatible, and replace DDE with supported automation where practical.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2324: Can't show Totals on fields added to the QBE grid with the asterisk..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","DDE"],"articleCategories":["Microsoft Access","Legacy Software","DDE"],"aliases":["Microsoft Access 2324","MS Access error 2324","Can't show Totals on fields added to the QBE grid with the asterisk."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64276,"title":"2325 - A field name in the LinkMasterFields property is too long.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2325","Access error 2325","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","A field name in the LinkMasterFields property is too long.","A field name in the LinkMasterFields property is too long."],"errorCode":"2325","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2325: A field name in the LinkMasterFields property is too long.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2325: A field name in the LinkMasterFields property is too long..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2325","MS Access error 2325","A field name in the LinkMasterFields property is too long."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64277,"title":"2326 - Value field can't specify Group By in the Totals cell.  Specify a function.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2326","Access error 2326","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Value field can't specify Group By in the Totals cell.  Specify a function.","Value field can't specify Group By in the Totals cell.  Specify a function."],"errorCode":"2326","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2326: Value field can't specify Group By in the Totals cell.  Specify a function.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2326: Value field can't specify Group By in the Totals cell.  Specify a function..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2326","MS Access error 2326","Value field can't specify Group By in the Totals cell.  Specify a function."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64278,"title":"2327 - Column Heading field must specify Group By in the Totals cell.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2327","Access error 2327","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Column Heading field must specify Group By in the Totals cell.","Column Heading field must specify Group By in the Totals cell."],"errorCode":"2327","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2327: Column Heading field must specify Group By in the Totals cell.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2327: Column Heading field must specify Group By in the Totals cell..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2327","MS Access error 2327","Column Heading field must specify Group By in the Totals cell."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64279,"title":"2328 - Can't run update queries for fields added to the QBE grid with the asterisk.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","DDE"],"keywords":["2328","Access error 2328","Microsoft Access","MSACCESS","Jet","VBA","DDE","Can't run update queries for fields added to the QBE grid with the asterisk.","Can't run update queries for fields added to the QBE grid with the asterisk."],"errorCode":"2328","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2328: Can't run update queries for fields added to the QBE grid with the asterisk.","rootCause":"A legacy Dynamic Data Exchange channel, topic, application, timeout, or data format is unavailable or inconsistent.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the target application and topic, close stale conversations, verify both applications are responsive and version-compatible, and replace DDE with supported automation where practical.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2328: Can't run update queries for fields added to the QBE grid with the asterisk..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","DDE"],"articleCategories":["Microsoft Access","Legacy Software","DDE"],"aliases":["Microsoft Access 2328","MS Access error 2328","Can't run update queries for fields added to the QBE grid with the asterisk."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64280,"title":"2329 - Must specify one or more Row Heading(s), one Column Heading, and one Value.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2329","Access error 2329","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Must specify one or more Row Heading(s), one Column Heading, and one Value.","Must specify one or more Row Heading(s), one Column Heading, and one Value."],"errorCode":"2329","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2329: Must specify one or more Row Heading(s), one Column Heading, and one Value.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2329: Must specify one or more Row Heading(s), one Column Heading, and one Value..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2329","MS Access error 2329","Must specify one or more Row Heading(s), one Column Heading, and one Value."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64281,"title":"2330 - Can't create join: '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2330","Access error 2330","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't create join: '|'.","Can't create join: '<value>'."],"errorCode":"2330","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2330: Can't create join: '<value>'.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2330: Can't create join: '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2330","MS Access error 2330","Can't create join: '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64282,"title":"2331 - Must specify at least one Row Heading as Group By.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2331","Access error 2331","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Must specify at least one Row Heading as Group By.","Must specify at least one Row Heading as Group By."],"errorCode":"2331","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2331: Must specify at least one Row Heading as Group By.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2331: Must specify at least one Row Heading as Group By..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2331","MS Access error 2331","Must specify at least one Row Heading as Group By."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64283,"title":"2332 - Can't match fields added to the QBE grid with the asterisk to a column or expression in an append query.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","DDE"],"keywords":["2332","Access error 2332","Microsoft Access","MSACCESS","Jet","VBA","DDE","Can't match fields added to the QBE grid with the asterisk to a column or expression in an append query.","Can't match fields added to the QBE grid with the asterisk to a column or expression in an append query."],"errorCode":"2332","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2332: Can't match fields added to the QBE grid with the asterisk to a column or expression in an append query.","rootCause":"A legacy Dynamic Data Exchange channel, topic, application, timeout, or data format is unavailable or inconsistent.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the target application and topic, close stale conversations, verify both applications are responsive and version-compatible, and replace DDE with supported automation where practical.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2332: Can't match fields added to the QBE grid with the asterisk to a column or expression in an append query..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","DDE"],"articleCategories":["Microsoft Access","Legacy Software","DDE"],"aliases":["Microsoft Access 2332","MS Access error 2332","Can't match fields added to the QBE grid with the asterisk to a column or expression in an append query."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64284,"title":"2333 - Must specify destination table for query.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2333","Access error 2333","Microsoft Access","MSACCESS","Jet","VBA","Queries","Must specify destination table for query.","Must specify destination table for query."],"errorCode":"2333","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2333: Must specify destination table for query.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2333: Must specify destination table for query..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2333","MS Access error 2333","Must specify destination table for query."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64285,"title":"2334 - '<value>' is an action query and can't be printed.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2334","Access error 2334","Microsoft Access","MSACCESS","Jet","VBA","Queries","'|' is an action query and can't be printed.","'<value>' is an action query and can't be printed."],"errorCode":"2334","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2334: '<value>' is an action query and can't be printed.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2334: '<value>' is an action query and can't be printed..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2334","MS Access error 2334","'|' is an action query and can't be printed."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64286,"title":"2335 - LinkChildFields and LinkMasterFields property settings must have the same number of fields.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2335","Access error 2335","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","LinkChildFields and LinkMasterFields property settings must have the same number of fields.","LinkChildFields and LinkMasterFields property settings must have the same number of fields."],"errorCode":"2335","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2335: LinkChildFields and LinkMasterFields property settings must have the same number of fields.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2335: LinkChildFields and LinkMasterFields property settings must have the same number of fields..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2335","MS Access error 2335","LinkChildFields and LinkMasterFields property settings must have the same number of fields."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64287,"title":"2336 - This query is based on the source database '<value 1> <value 2>'.  You can change or remove the source database specification through the SQL command on the View menu.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2336","Access error 2336","Microsoft Access","MSACCESS","Jet","VBA","Queries","This query is based on the source database '|1 |2'.  You can change or remove the source database specification through the SQL command on the View menu.","This query is based on the source database '<value 1> <value 2>'.  You can change or remove the source database specification through the SQL command on the View menu."],"errorCode":"2336","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2336: This query is based on the source database '<value 1> <value 2>'.  You can change or remove the source database specification through the SQL command on the View menu.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2336: This query is based on the source database '<value 1> <value 2>'.  You can change or remove the source database specification through the SQL command on the View menu..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2336","MS Access error 2336","This query is based on the source database '|1 |2'.  You can change or remove the source database specification through the SQL command on the View menu."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64288,"title":"2337 - Value field can't specify a Criteria clause.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2337","Access error 2337","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Value field can't specify a Criteria clause.","Value field can't specify a Criteria clause."],"errorCode":"2337","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2337: Value field can't specify a Criteria clause.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2337: Value field can't specify a Criteria clause..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2337","MS Access error 2337","Value field can't specify a Criteria clause."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64289,"title":"2338 - Expression is too long for the QBE grid and has been truncated: '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2338","Access error 2338","Microsoft Access","MSACCESS","Jet","VBA","Queries","Expression is too long for the QBE grid and has been truncated: '|'.","Expression is too long for the QBE grid and has been truncated: '<value>'."],"errorCode":"2338","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2338: Expression is too long for the QBE grid and has been truncated: '<value>'.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2338: Expression is too long for the QBE grid and has been truncated: '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2338","MS Access error 2338","Expression is too long for the QBE grid and has been truncated: '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64290,"title":"2339 - Can't create a temporary query.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2339","Access error 2339","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't create a temporary query.","Can't create a temporary query."],"errorCode":"2339","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2339: Can't create a temporary query.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2339: Can't create a temporary query..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2339","MS Access error 2339","Can't create a temporary query."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64291,"title":"2340 - Expression is too long.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2340","Access error 2340","Microsoft Access","MSACCESS","Jet","VBA","Queries","Expression is too long.","Expression is too long."],"errorCode":"2340","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2340: Expression is too long.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2340: Expression is too long..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2340","MS Access error 2340","Expression is too long."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64292,"title":"2341 - Fixed Column Headings requires a list of names.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2341","Access error 2341","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Fixed Column Headings requires a list of names.","Fixed Column Headings requires a list of names."],"errorCode":"2341","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2341: Fixed Column Headings requires a list of names.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2341: Fixed Column Headings requires a list of names..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2341","MS Access error 2341","Fixed Column Headings requires a list of names."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64293,"title":"2342 - RunSQL action can only run action query SQL statements.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2342","Access error 2342","Microsoft Access","MSACCESS","Jet","VBA","Queries","RunSQL action can only run action query SQL statements.","RunSQL action can only run action query SQL statements."],"errorCode":"2342","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2342: RunSQL action can only run action query SQL statements.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2342: RunSQL action can only run action query SQL statements..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2342","MS Access error 2342","RunSQL action can only run action query SQL statements."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64294,"title":"2360 - Missing field name.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2360","Access error 2360","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Missing field name.","Missing field name."],"errorCode":"2360","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2360: Missing field name.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2360: Missing field name..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2360","MS Access error 2360","Missing field name."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64295,"title":"2361 - Table doesn't have any fields; can't save.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2361","Access error 2361","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Table doesn't have any fields; can't save.","Table doesn't have any fields; can't save."],"errorCode":"2361","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2361: Table doesn't have any fields; can't save.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2361: Table doesn't have any fields; can't save..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2361","MS Access error 2361","Table doesn't have any fields; can't save."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64296,"title":"2362 - Duplicate field name: '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2362","Access error 2362","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Duplicate field name: '|'.","Duplicate field name: '<value>'."],"errorCode":"2362","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2362: Duplicate field name: '<value>'.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2362: Duplicate field name: '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2362","MS Access error 2362","Duplicate field name: '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64297,"title":"2363 - Only one Counter field is allowed per table.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2363","Access error 2363","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Only one Counter field is allowed per table.","Only one Counter field is allowed per table."],"errorCode":"2363","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2363: Only one Counter field is allowed per table.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2363: Only one Counter field is allowed per table..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2363","MS Access error 2363","Only one Counter field is allowed per table."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64298,"title":"2364 - Can't open table in Datasheet view.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2364","Access error 2364","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't open table in Datasheet view.","Can't open table in Datasheet view."],"errorCode":"2364","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2364: Can't open table in Datasheet view.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2364: Can't open table in Datasheet view..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2364","MS Access error 2364","Can't open table in Datasheet view."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64299,"title":"2365 - Can't create an index on a field of this data type.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2365","Access error 2365","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't create an index on a field of this data type.","Can't create an index on a field of this data type."],"errorCode":"2365","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2365: Can't create an index on a field of this data type.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2365: Can't create an index on a field of this data type..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2365","MS Access error 2365","Can't create an index on a field of this data type."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64300,"title":"2366 - Errors were encountered during save. All changes were saved except the field ordering was not saved successfully.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2366","Access error 2366","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Errors were encountered during save. All changes were saved except the field ordering was not saved successfully.","Errors were encountered during save. All changes were saved except the field ordering was not saved successfully."],"errorCode":"2366","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2366: Errors were encountered during save. All changes were saved except the field ordering was not saved successfully.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2366: Errors were encountered during save. All changes were saved except the field ordering was not saved successfully..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2366","MS Access error 2366","Errors were encountered during save. All changes were saved except the field ordering was not saved successfully."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64301,"title":"2367 - Can't create index or primary key because one or more field names aren't valid.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2367","Access error 2367","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't create index or primary key because one or more field names aren't valid.","Can't create index or primary key because one or more field names aren't valid."],"errorCode":"2367","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2367: Can't create index or primary key because one or more field names aren't valid.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2367: Can't create index or primary key because one or more field names aren't valid..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2367","MS Access error 2367","Can't create index or primary key because one or more field names aren't valid."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64302,"title":"2368 - Can't create a multiple-field index with a single field.  Use the Indexed property to create a single-field index.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2368","Access error 2368","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't create a multiple-field index with a single field.  Use the Indexed property to create a single-field index.","Can't create a multiple-field index with a single field.  Use the Indexed property to create a single-field index."],"errorCode":"2368","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2368: Can't create a multiple-field index with a single field.  Use the Indexed property to create a single-field index.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2368: Can't create a multiple-field index with a single field.  Use the Indexed property to create a single-field index..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2368","MS Access error 2368","Can't create a multiple-field index with a single field.  Use the Indexed property to create a single-field index."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64303,"title":"2369 - Missing an opening or closing bracket in index or primary key definition.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2369","Access error 2369","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Missing an opening or closing bracket in index or primary key definition.","Missing an opening or closing bracket in index or primary key definition."],"errorCode":"2369","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2369: Missing an opening or closing bracket in index or primary key definition.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2369: Missing an opening or closing bracket in index or primary key definition..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2369","MS Access error 2369","Missing an opening or closing bracket in index or primary key definition."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64304,"title":"2370 - Removing or changing the index for this field would require removal of the primary key.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2370","Access error 2370","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Removing or changing the index for this field would require removal of the primary key.","Removing or changing the index for this field would require removal of the primary key."],"errorCode":"2370","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2370: Removing or changing the index for this field would require removal of the primary key.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2370: Removing or changing the index for this field would require removal of the primary key..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2370","MS Access error 2370","Removing or changing the index for this field would require removal of the primary key."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64305,"title":"2371 - Can't create primary key. Changes weren't saved.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2371","Access error 2371","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't create primary key. Changes weren't saved.","Can't create primary key. Changes weren't saved."],"errorCode":"2371","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2371: Can't create primary key. Changes weren't saved.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2371: Can't create primary key. Changes weren't saved..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2371","MS Access error 2371","Can't create primary key. Changes weren't saved."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64306,"title":"2372 - Not a valid field name.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2372","Access error 2372","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Not a valid field name.","Not a valid field name."],"errorCode":"2372","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2372: Not a valid field name.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2372: Not a valid field name..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2372","MS Access error 2372","Not a valid field name."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64307,"title":"2373 - The setting for Field Size must be from 0 to 255.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2373","Access error 2373","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","The setting for Field Size must be from 0 to 255.","The setting for Field Size must be from 0 to 255."],"errorCode":"2373","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2373: The setting for Field Size must be from 0 to 255.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2373: The setting for Field Size must be from 0 to 255..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2373","MS Access error 2373","The setting for Field Size must be from 0 to 255."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64308,"title":"2374 - Can't create an index or primary key on more than 10 fields.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2374","Access error 2374","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't create an index or primary key on more than 10 fields.","Can't create an index or primary key on more than 10 fields."],"errorCode":"2374","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2374: Can't create an index or primary key on more than 10 fields.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2374: Can't create an index or primary key on more than 10 fields..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2374","MS Access error 2374","Can't create an index or primary key on more than 10 fields."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64309,"title":"2375 - Can't paste beyond end of table.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2375","Access error 2375","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't paste beyond end of table.","Can't paste beyond end of table."],"errorCode":"2375","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2375: Can't paste beyond end of table.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2375: Can't paste beyond end of table..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2375","MS Access error 2375","Can't paste beyond end of table."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64310,"title":"2376 - Can't create primary key; too many fields.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2376","Access error 2376","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't create primary key; too many fields.","Can't create primary key; too many fields."],"errorCode":"2376","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2376: Can't create primary key; too many fields.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2376: Can't create primary key; too many fields..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2376","MS Access error 2376","Can't create primary key; too many fields."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64311,"title":"2377 - Can't change data type to Counter in a table with data.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2377","Access error 2377","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't change data type to Counter in a table with data.","Can't change data type to Counter in a table with data."],"errorCode":"2377","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2377: Can't change data type to Counter in a table with data.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2377: Can't change data type to Counter in a table with data..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2377","MS Access error 2377","Can't change data type to Counter in a table with data."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64312,"title":"2378 - This table is read-only.  Use a different name in the Save As dialog box to save your changes.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2378","Access error 2378","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","This table is read-only.  Use a different name in the Save As dialog box to save your changes.","This table is read-only.  Use a different name in the Save As dialog box to save your changes."],"errorCode":"2378","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2378: This table is read-only.  Use a different name in the Save As dialog box to save your changes.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2378: This table is read-only.  Use a different name in the Save As dialog box to save your changes..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2378","MS Access error 2378","This table is read-only.  Use a different name in the Save As dialog box to save your changes."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64313,"title":"2379 - Can't create a primary key on a field of this data type.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2379","Access error 2379","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't create a primary key on a field of this data type.","Can't create a primary key on a field of this data type."],"errorCode":"2379","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2379: Can't create a primary key on a field of this data type.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2379: Can't create a primary key on a field of this data type..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2379","MS Access error 2379","Can't create a primary key on a field of this data type."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64314,"title":"2380 - Can't create primary key; no fields selected.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2380","Access error 2380","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't create primary key; no fields selected.","Can't create primary key; no fields selected."],"errorCode":"2380","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2380: Can't create primary key; no fields selected.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2380: Can't create primary key; no fields selected..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2380","MS Access error 2380","Can't create primary key; no fields selected."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64315,"title":"2381 - Can't create primary key; field doesn't have a name.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2381","Access error 2381","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't create primary key; field doesn't have a name.","Can't create primary key; field doesn't have a name."],"errorCode":"2381","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2381: Can't create primary key; field doesn't have a name.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2381: Can't create primary key; field doesn't have a name..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2381","MS Access error 2381","Can't create primary key; field doesn't have a name."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64316,"title":"2382 - Can't switch to Datasheet view and can't return to Design view.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2382","Access error 2382","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't switch to Datasheet view and can't return to Design view.","Can't switch to Datasheet view and can't return to Design view."],"errorCode":"2382","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2382: Can't switch to Datasheet view and can't return to Design view.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2382: Can't switch to Datasheet view and can't return to Design view..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2382","MS Access error 2382","Can't switch to Datasheet view and can't return to Design view."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64317,"title":"2383 - Couldn't change data type, because there either isn't enough disk space or enough memory.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["2383","Access error 2383","Microsoft Access","MSACCESS","Jet","VBA","Files","Couldn't change data type, because there either isn't enough disk space or enough memory.","Couldn't change data type, because there either isn't enough disk space or enough memory."],"errorCode":"2383","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2383: Couldn't change data type, because there either isn't enough disk space or enough memory.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2383: Couldn't change data type, because there either isn't enough disk space or enough memory..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 2383","MS Access error 2383","Couldn't change data type, because there either isn't enough disk space or enough memory."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64318,"title":"2384 - Can't change one field from the Counter type and add another Counter field at the same time.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2384","Access error 2384","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't change one field from the Counter type and add another Counter field at the same time.","Can't change one field from the Counter type and add another Counter field at the same time."],"errorCode":"2384","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2384: Can't change one field from the Counter type and add another Counter field at the same time.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2384: Can't change one field from the Counter type and add another Counter field at the same time..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2384","MS Access error 2384","Can't change one field from the Counter type and add another Counter field at the same time."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64319,"title":"2385 - Errors were encountered during save. <value>","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2385","Access error 2385","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Errors were encountered during save. |","Errors were encountered during save. <value>"],"errorCode":"2385","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2385: Errors were encountered during save. <value>","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2385: Errors were encountered during save. <value>.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2385","MS Access error 2385","Errors were encountered during save. |"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64320,"title":"2386 - Errors were encountered during save.  The new table was not created.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2386","Access error 2386","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Errors were encountered during save.  The new table was not created.","Errors were encountered during save.  The new table was not created."],"errorCode":"2386","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2386: Errors were encountered during save.  The new table was not created.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2386: Errors were encountered during save.  The new table was not created..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2386","MS Access error 2386","Errors were encountered during save.  The new table was not created."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64321,"title":"2387 - Can't delete table '<value>'.  It is the Primary Table in one or more relationships.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2387","Access error 2387","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't delete table '|'.  It is the Primary Table in one or more relationships.","Can't delete table '<value>'.  It is the Primary Table in one or more relationships."],"errorCode":"2387","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2387: Can't delete table '<value>'.  It is the Primary Table in one or more relationships.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2387: Can't delete table '<value>'.  It is the Primary Table in one or more relationships..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2387","MS Access error 2387","Can't delete table '|'.  It is the Primary Table in one or more relationships."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64322,"title":"2388 - Can't change primary key.  This table is the Primary Table in one or more relationships.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2388","Access error 2388","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't change primary key.  This table is the Primary Table in one or more relationships.","Can't change primary key.  This table is the Primary Table in one or more relationships."],"errorCode":"2388","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2388: Can't change primary key.  This table is the Primary Table in one or more relationships.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2388: Can't change primary key.  This table is the Primary Table in one or more relationships..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2388","MS Access error 2388","Can't change primary key.  This table is the Primary Table in one or more relationships."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64323,"title":"2389 - Can't delete field '<value>'.  It is part of one or more relationships.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2389","Access error 2389","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't delete field '|'.  It is part of one or more relationships.","Can't delete field '<value>'.  It is part of one or more relationships."],"errorCode":"2389","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2389: Can't delete field '<value>'.  It is part of one or more relationships.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2389: Can't delete field '<value>'.  It is part of one or more relationships..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2389","MS Access error 2389","Can't delete field '|'.  It is part of one or more relationships."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64324,"title":"2390 - Can't change the data type or field size of this field.  It is part of one or more relationships.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2390","Access error 2390","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't change the data type or field size of this field.  It is part of one or more relationships.","Can't change the data type or field size of this field.  It is part of one or more relationships."],"errorCode":"2390","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2390: Can't change the data type or field size of this field.  It is part of one or more relationships.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2390: Can't change the data type or field size of this field.  It is part of one or more relationships..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2390","MS Access error 2390","Can't change the data type or field size of this field.  It is part of one or more relationships."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64325,"title":"2391 - Couldn't append.  Field '<value 1>' does not exist in destination table '<value 2>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2391","Access error 2391","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't append.  Field '|1' does not exist in destination table '|2'.","Couldn't append.  Field '<value 1>' does not exist in destination table '<value 2>'."],"errorCode":"2391","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2391: Couldn't append.  Field '<value 1>' does not exist in destination table '<value 2>'.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2391: Couldn't append.  Field '<value 1>' does not exist in destination table '<value 2>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2391","MS Access error 2391","Couldn't append.  Field '|1' does not exist in destination table '|2'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64326,"title":"2400 - No room to insert.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2400","Access error 2400","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","No room to insert.","No room to insert."],"errorCode":"2400","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2400: No room to insert.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2400: No room to insert..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2400","MS Access error 2400","No room to insert."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64327,"title":"2420 - Syntax error in number","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2420","Access error 2420","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Syntax error in number","Syntax error in number"],"errorCode":"2420","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2420: Syntax error in number","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2420: Syntax error in number.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2420","MS Access error 2420","Syntax error in number"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64328,"title":"2421 - Syntax error in date","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2421","Access error 2421","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Syntax error in date","Syntax error in date"],"errorCode":"2421","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2421: Syntax error in date","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2421: Syntax error in date.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2421","MS Access error 2421","Syntax error in date"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64329,"title":"2422 - Syntax error in string","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2422","Access error 2422","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Syntax error in string","Syntax error in string"],"errorCode":"2422","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2422: Syntax error in string","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2422: Syntax error in string.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2422","MS Access error 2422","Syntax error in string"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64330,"title":"2423 - Invalid use of '.', '!', or '()'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2423","Access error 2423","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Invalid use of '.', '!', or '()'.","Invalid use of '.', '!', or '()'."],"errorCode":"2423","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2423: Invalid use of '.', '!', or '()'.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2423: Invalid use of '.', '!', or '()'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2423","MS Access error 2423","Invalid use of '.', '!', or '()'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64331,"title":"2424 - Unknown name","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2424","Access error 2424","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Unknown name","Unknown name"],"errorCode":"2424","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2424: Unknown name","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2424: Unknown name.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2424","MS Access error 2424","Unknown name"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64332,"title":"2425 - Unknown function name","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2425","Access error 2425","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Unknown function name","Unknown function name"],"errorCode":"2425","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2425: Unknown function name","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2425: Unknown function name.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2425","MS Access error 2425","Unknown function name"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64333,"title":"2426 - Function isn't available in expressions","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2426","Access error 2426","Microsoft Access","MSACCESS","Jet","VBA","Queries","Function isn't available in expressions","Function isn't available in expressions"],"errorCode":"2426","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2426: Function isn't available in expressions","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2426: Function isn't available in expressions.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2426","MS Access error 2426","Function isn't available in expressions"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64334,"title":"2427 - Object has no value","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2427","Access error 2427","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Object has no value","Object has no value"],"errorCode":"2427","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2427: Object has no value","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2427: Object has no value.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2427","MS Access error 2427","Object has no value"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64335,"title":"2428 - Invalid arguments used with domain function","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2428","Access error 2428","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Invalid arguments used with domain function","Invalid arguments used with domain function"],"errorCode":"2428","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2428: Invalid arguments used with domain function","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2428: Invalid arguments used with domain function.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2428","MS Access error 2428","Invalid arguments used with domain function"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64336,"title":"2429 - In operator without ()","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2429","Access error 2429","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","In operator without ()","In operator without ()"],"errorCode":"2429","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2429: In operator without ()","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2429: In operator without ().\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2429","MS Access error 2429","In operator without ()"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64337,"title":"2430 - Between operator without And","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2430","Access error 2430","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Between operator without And","Between operator without And"],"errorCode":"2430","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2430: Between operator without And","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2430: Between operator without And.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2430","MS Access error 2430","Between operator without And"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64338,"title":"2431 - Syntax error","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2431","Access error 2431","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Syntax error","Syntax error"],"errorCode":"2431","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2431: Syntax error","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2431: Syntax error.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2431","MS Access error 2431","Syntax error"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64339,"title":"2432 - Syntax error","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2432","Access error 2432","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Syntax error","Syntax error"],"errorCode":"2432","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2432: Syntax error","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2432: Syntax error.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2432","MS Access error 2432","Syntax error"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64340,"title":"2433 - Syntax error","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2433","Access error 2433","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Syntax error","Syntax error"],"errorCode":"2433","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2433: Syntax error","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2433: Syntax error.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2433","MS Access error 2433","Syntax error"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64341,"title":"2434 - Syntax error","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2434","Access error 2434","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Syntax error","Syntax error"],"errorCode":"2434","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2434: Syntax error","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2434: Syntax error.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2434","MS Access error 2434","Syntax error"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64342,"title":"2435 - Extra )","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2435","Access error 2435","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Extra )","Extra )"],"errorCode":"2435","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2435: Extra )","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2435: Extra ).\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2435","MS Access error 2435","Extra )"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64343,"title":"2436 - Missing ), ], or <value>","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2436","Access error 2436","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Missing ), ], or |","Missing ), ], or <value>"],"errorCode":"2436","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2436: Missing ), ], or <value>","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2436: Missing ), ], or <value>.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2436","MS Access error 2436","Missing ), ], or |"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64344,"title":"2437 - Invalid use of vertical bars","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2437","Access error 2437","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Invalid use of vertical bars","Invalid use of vertical bars"],"errorCode":"2437","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2437: Invalid use of vertical bars","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2437: Invalid use of vertical bars.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2437","MS Access error 2437","Invalid use of vertical bars"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64345,"title":"2438 - Syntax error","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2438","Access error 2438","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Syntax error","Syntax error"],"errorCode":"2438","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2438: Syntax error","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2438: Syntax error.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2438","MS Access error 2438","Syntax error"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64346,"title":"2439 - Wrong number of arguments used with function","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2439","Access error 2439","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Wrong number of arguments used with function","Wrong number of arguments used with function"],"errorCode":"2439","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2439: Wrong number of arguments used with function","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2439: Wrong number of arguments used with function.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2439","MS Access error 2439","Wrong number of arguments used with function"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64347,"title":"2440 - IIF function without ()","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2440","Access error 2440","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","IIF function without ()","IIF function without ()"],"errorCode":"2440","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2440: IIF function without ()","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2440: IIF function without ().\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2440","MS Access error 2440","IIF function without ()"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64348,"title":"2442 - Invalid use of parentheses","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2442","Access error 2442","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Invalid use of parentheses","Invalid use of parentheses"],"errorCode":"2442","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2442: Invalid use of parentheses","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2442: Invalid use of parentheses.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2442","MS Access error 2442","Invalid use of parentheses"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64349,"title":"2443 - Invalid use of Is operator","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2443","Access error 2443","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Invalid use of Is operator","Invalid use of Is operator"],"errorCode":"2443","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2443: Invalid use of Is operator","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2443: Invalid use of Is operator.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2443","MS Access error 2443","Invalid use of Is operator"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64350,"title":"2445 - Expression too complex","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2445","Access error 2445","Microsoft Access","MSACCESS","Jet","VBA","Queries","Expression too complex","Expression too complex"],"errorCode":"2445","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2445: Expression too complex","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2445: Expression too complex.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2445","MS Access error 2445","Expression too complex"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64351,"title":"2446 - Out of memory during calculation","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Resources"],"keywords":["2446","Access error 2446","Microsoft Access","MSACCESS","Jet","VBA","Resources","Out of memory during calculation","Out of memory during calculation"],"errorCode":"2446","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2446: Out of memory during calculation","rootCause":"Access or Windows lacks sufficient memory, stack, handles, disk, or other resources for the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Save work, close unnecessary objects/applications, check memory, handles, disk and database size, then reproduce after a controlled restart and review for runaway queries or code.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2446: Out of memory during calculation.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Resources"],"articleCategories":["Microsoft Access","Legacy Software","Resources"],"aliases":["Microsoft Access 2446","MS Access error 2446","Out of memory during calculation"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64352,"title":"2447 - Invalid use of '.', '!', or '()'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2447","Access error 2447","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Invalid use of '.', '!', or '()'.","Invalid use of '.', '!', or '()'."],"errorCode":"2447","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2447: Invalid use of '.', '!', or '()'.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2447: Invalid use of '.', '!', or '()'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2447","MS Access error 2447","Invalid use of '.', '!', or '()'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64353,"title":"2448 - Can't set value.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2448","Access error 2448","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't set value.","Can't set value."],"errorCode":"2448","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2448: Can't set value.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2448: Can't set value..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2448","MS Access error 2448","Can't set value."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64354,"title":"2449 - Invalid method in expression.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2449","Access error 2449","Microsoft Access","MSACCESS","Jet","VBA","Queries","Invalid method in expression.","Invalid method in expression."],"errorCode":"2449","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2449: Invalid method in expression.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2449: Invalid method in expression..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2449","MS Access error 2449","Invalid method in expression."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64355,"title":"2450 - Invalid reference to form '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2450","Access error 2450","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Invalid reference to form '|'.","Invalid reference to form '<value>'."],"errorCode":"2450","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2450: Invalid reference to form '<value>'.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2450: Invalid reference to form '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2450","MS Access error 2450","Invalid reference to form '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64356,"title":"2451 - Invalid reference to report '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2451","Access error 2451","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Invalid reference to report '|'.","Invalid reference to report '<value>'."],"errorCode":"2451","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2451: Invalid reference to report '<value>'.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2451: Invalid reference to report '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2451","MS Access error 2451","Invalid reference to report '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64357,"title":"2452 - Invalid reference to Parent property.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2452","Access error 2452","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Invalid reference to Parent property.","Invalid reference to Parent property."],"errorCode":"2452","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2452: Invalid reference to Parent property.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2452: Invalid reference to Parent property..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2452","MS Access error 2452","Invalid reference to Parent property."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64358,"title":"2453 - Invalid reference to control '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2453","Access error 2453","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Invalid reference to control '|'.","Invalid reference to control '<value>'."],"errorCode":"2453","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2453: Invalid reference to control '<value>'.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2453: Invalid reference to control '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2453","MS Access error 2453","Invalid reference to control '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64359,"title":"2454 - Invalid reference to '!<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2454","Access error 2454","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Invalid reference to '!|'.","Invalid reference to '!<value>'."],"errorCode":"2454","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2454: Invalid reference to '!<value>'.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2454: Invalid reference to '!<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2454","MS Access error 2454","Invalid reference to '!|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64360,"title":"2455 - Invalid reference to property '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2455","Access error 2455","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Invalid reference to property '|'.","Invalid reference to property '<value>'."],"errorCode":"2455","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2455: Invalid reference to property '<value>'.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2455: Invalid reference to property '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2455","MS Access error 2455","Invalid reference to property '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64361,"title":"2456 - Invalid form number reference.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2456","Access error 2456","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Invalid form number reference.","Invalid form number reference."],"errorCode":"2456","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2456: Invalid form number reference.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2456: Invalid form number reference..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2456","MS Access error 2456","Invalid form number reference."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64362,"title":"2457 - Invalid report number reference.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2457","Access error 2457","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Invalid report number reference.","Invalid report number reference."],"errorCode":"2457","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2457: Invalid report number reference.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2457: Invalid report number reference..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2457","MS Access error 2457","Invalid report number reference."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64363,"title":"2458 - Invalid control number reference.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2458","Access error 2458","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Invalid control number reference.","Invalid control number reference."],"errorCode":"2458","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2458: Invalid control number reference.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2458: Invalid control number reference..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2458","MS Access error 2458","Invalid control number reference."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64364,"title":"2459 - Can't refer to Parent property in Design view.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2459","Access error 2459","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't refer to Parent property in Design view.","Can't refer to Parent property in Design view."],"errorCode":"2459","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2459: Can't refer to Parent property in Design view.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2459: Can't refer to Parent property in Design view..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2459","MS Access error 2459","Can't refer to Parent property in Design view."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64365,"title":"2460 - Can't refer to Dynaset property in Design view.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2460","Access error 2460","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't refer to Dynaset property in Design view.","Can't refer to Dynaset property in Design view."],"errorCode":"2460","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2460: Can't refer to Dynaset property in Design view.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2460: Can't refer to Dynaset property in Design view..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2460","MS Access error 2460","Can't refer to Dynaset property in Design view."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64366,"title":"2461 - Invalid section reference.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2461","Access error 2461","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Invalid section reference.","Invalid section reference."],"errorCode":"2461","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2461: Invalid section reference.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2461: Invalid section reference..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2461","MS Access error 2461","Invalid section reference."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64367,"title":"2462 - Invalid section number reference.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2462","Access error 2462","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Invalid section number reference.","Invalid section number reference."],"errorCode":"2462","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2462: Invalid section number reference.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2462: Invalid section number reference..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2462","MS Access error 2462","Invalid section number reference."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64368,"title":"2463 - Invalid group level reference.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2463","Access error 2463","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Invalid group level reference.","Invalid group level reference."],"errorCode":"2463","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2463: Invalid group level reference.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2463: Invalid group level reference..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2463","MS Access error 2463","Invalid group level reference."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64369,"title":"2464 - Invalid group level number reference.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2464","Access error 2464","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Invalid group level number reference.","Invalid group level number reference."],"errorCode":"2464","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2464: Invalid group level number reference.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2464: Invalid group level number reference..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2464","MS Access error 2464","Invalid group level number reference."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64370,"title":"2465 - Invalid reference to field '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2465","Access error 2465","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Invalid reference to field '|'.","Invalid reference to field '<value>'."],"errorCode":"2465","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2465: Invalid reference to field '<value>'.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2465: Invalid reference to field '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2465","MS Access error 2465","Invalid reference to field '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64371,"title":"2466 - Invalid reference to Dynaset property.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2466","Access error 2466","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Invalid reference to Dynaset property.","Invalid reference to Dynaset property."],"errorCode":"2466","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2466: Invalid reference to Dynaset property.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2466: Invalid reference to Dynaset property..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2466","MS Access error 2466","Invalid reference to Dynaset property."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64372,"title":"2467 - Object referred to in expression no longer exists.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2467","Access error 2467","Microsoft Access","MSACCESS","Jet","VBA","Queries","Object referred to in expression no longer exists.","Object referred to in expression no longer exists."],"errorCode":"2467","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2467: Object referred to in expression no longer exists.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2467: Object referred to in expression no longer exists..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2467","MS Access error 2467","Object referred to in expression no longer exists."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64373,"title":"2468 - Invalid argument used with DatePart, DateAdd or DateDiff function.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2468","Access error 2468","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Invalid argument used with DatePart, DateAdd or DateDiff function.","Invalid argument used with DatePart, DateAdd or DateDiff function."],"errorCode":"2468","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2468: Invalid argument used with DatePart, DateAdd or DateDiff function.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2468: Invalid argument used with DatePart, DateAdd or DateDiff function..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2468","MS Access error 2468","Invalid argument used with DatePart, DateAdd or DateDiff function."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64374,"title":"2469 - <value 1> in validation rule: '<value 2>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2469","Access error 2469","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","|1 in validation rule: '|2'.","<value 1> in validation rule: '<value 2>'."],"errorCode":"2469","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2469: <value 1> in validation rule: '<value 2>'.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2469: <value 1> in validation rule: '<value 2>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2469","MS Access error 2469","|1 in validation rule: '|2'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64375,"title":"2470 - <value> in validation rule.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2470","Access error 2470","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","| in validation rule.","<value> in validation rule."],"errorCode":"2470","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2470: <value> in validation rule.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2470: <value> in validation rule..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2470","MS Access error 2470","| in validation rule."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64376,"title":"2471 - <value> in query.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2471","Access error 2471","Microsoft Access","MSACCESS","Jet","VBA","Queries","| in query.","<value> in query."],"errorCode":"2471","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2471: <value> in query.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2471: <value> in query..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2471","MS Access error 2471","| in query."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64377,"title":"2472 - <value> in linked master field.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2472","Access error 2472","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","| in linked master field.","<value> in linked master field."],"errorCode":"2472","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2472: <value> in linked master field.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2472: <value> in linked master field..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2472","MS Access error 2472","| in linked master field."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64378,"title":"2473 - <value 1> in '<value 2>' expression.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2473","Access error 2473","Microsoft Access","MSACCESS","Jet","VBA","Queries","|1 in '|2' expression.","<value 1> in '<value 2>' expression."],"errorCode":"2473","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2473: <value 1> in '<value 2>' expression.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2473: <value 1> in '<value 2>' expression..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2473","MS Access error 2473","|1 in '|2' expression."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64379,"title":"2474 - No control is active.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2474","Access error 2474","Microsoft Access","MSACCESS","Jet","VBA","Access UI","No control is active.","No control is active."],"errorCode":"2474","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2474: No control is active.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2474: No control is active..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2474","MS Access error 2474","No control is active."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64380,"title":"2475 - No form is active.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2475","Access error 2475","Microsoft Access","MSACCESS","Jet","VBA","Access UI","No form is active.","No form is active."],"errorCode":"2475","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2475: No form is active.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2475: No form is active..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2475","MS Access error 2475","No form is active."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64381,"title":"2476 - No report is active.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2476","Access error 2476","Microsoft Access","MSACCESS","Jet","VBA","Access UI","No report is active.","No report is active."],"errorCode":"2476","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2476: No report is active.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2476: No report is active..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2476","MS Access error 2476","No report is active."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64382,"title":"2477 - Invalid subclass '<value>' referred to in TypeOf function.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2477","Access error 2477","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Invalid subclass '|' referred to in TypeOf function.","Invalid subclass '<value>' referred to in TypeOf function."],"errorCode":"2477","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2477: Invalid subclass '<value>' referred to in TypeOf function.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2477: Invalid subclass '<value>' referred to in TypeOf function..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2477","MS Access error 2477","Invalid subclass '|' referred to in TypeOf function."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64383,"title":"2485 - Macro '<value>' not found.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2485","Access error 2485","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Macro '|' not found.","Macro '<value>' not found."],"errorCode":"2485","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2485: Macro '<value>' not found.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2485: Macro '<value>' not found..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2485","MS Access error 2485","Macro '|' not found."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64384,"title":"2486 - Can't run this action while in current code context.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2486","Access error 2486","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't run this action while in current code context.","Can't run this action while in current code context."],"errorCode":"2486","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2486: Can't run this action while in current code context.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2486: Can't run this action while in current code context..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2486","MS Access error 2486","Can't run this action while in current code context."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64385,"title":"2487 - Invalid object type.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2487","Access error 2487","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Invalid object type.","Invalid object type."],"errorCode":"2487","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2487: Invalid object type.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2487: Invalid object type..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2487","MS Access error 2487","Invalid object type."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64386,"title":"2488 - Action isn't available because current window isn't a form or report window.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2488","Access error 2488","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Action isn't available because current window isn't a form or report window.","Action isn't available because current window isn't a form or report window."],"errorCode":"2488","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2488: Action isn't available because current window isn't a form or report window.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2488: Action isn't available because current window isn't a form or report window..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2488","MS Access error 2488","Action isn't available because current window isn't a form or report window."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64387,"title":"2489 - Object '<value>' isn't open.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2489","Access error 2489","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Object '|' isn't open.","Object '<value>' isn't open."],"errorCode":"2489","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2489: Object '<value>' isn't open.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2489: Object '<value>' isn't open..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2489","MS Access error 2489","Object '|' isn't open."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64388,"title":"2490 - Options argument in Quit action isn't valid.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2490","Access error 2490","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Options argument in Quit action isn't valid.","Options argument in Quit action isn't valid."],"errorCode":"2490","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2490: Options argument in Quit action isn't valid.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2490: Options argument in Quit action isn't valid..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2490","MS Access error 2490","Options argument in Quit action isn't valid."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64389,"title":"2491 - Action isn't valid because the form or report isn't bound to a table or query.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2491","Access error 2491","Microsoft Access","MSACCESS","Jet","VBA","Queries","Action isn't valid because the form or report isn't bound to a table or query.","Action isn't valid because the form or report isn't bound to a table or query."],"errorCode":"2491","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2491: Action isn't valid because the form or report isn't bound to a table or query.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2491: Action isn't valid because the form or report isn't bound to a table or query..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2491","MS Access error 2491","Action isn't valid because the form or report isn't bound to a table or query."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64390,"title":"2492 - Can't find Macro Name '<value 2>' in Macro Group '<value 1>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2492","Access error 2492","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Can't find Macro Name '|2' in Macro Group '|1'.","Can't find Macro Name '<value 2>' in Macro Group '<value 1>'."],"errorCode":"2492","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2492: Can't find Macro Name '<value 2>' in Macro Group '<value 1>'.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2492: Can't find Macro Name '<value 2>' in Macro Group '<value 1>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2492","MS Access error 2492","Can't find Macro Name '|2' in Macro Group '|1'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64391,"title":"2493 - Action requires an Object Name argument.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2493","Access error 2493","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Action requires an Object Name argument.","Action requires an Object Name argument."],"errorCode":"2493","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2493: Action requires an Object Name argument.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2493: Action requires an Object Name argument..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2493","MS Access error 2493","Action requires an Object Name argument."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64392,"title":"2494 - Action requires a Form Name argument.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2494","Access error 2494","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Action requires a Form Name argument.","Action requires a Form Name argument."],"errorCode":"2494","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2494: Action requires a Form Name argument.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2494: Action requires a Form Name argument..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2494","MS Access error 2494","Action requires a Form Name argument."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64393,"title":"2495 - Action requires a Table Name argument.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2495","Access error 2495","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Action requires a Table Name argument.","Action requires a Table Name argument."],"errorCode":"2495","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2495: Action requires a Table Name argument.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2495: Action requires a Table Name argument..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2495","MS Access error 2495","Action requires a Table Name argument."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64394,"title":"2496 - Action requires a Query Name argument.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2496","Access error 2496","Microsoft Access","MSACCESS","Jet","VBA","Queries","Action requires a Query Name argument.","Action requires a Query Name argument."],"errorCode":"2496","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2496: Action requires a Query Name argument.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2496: Action requires a Query Name argument..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2496","MS Access error 2496","Action requires a Query Name argument."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64395,"title":"2497 - Action requires a Report Name argument.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2497","Access error 2497","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Action requires a Report Name argument.","Action requires a Report Name argument."],"errorCode":"2497","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2497: Action requires a Report Name argument.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2497: Action requires a Report Name argument..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2497","MS Access error 2497","Action requires a Report Name argument."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64396,"title":"2498 - Argument type mismatch.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2498","Access error 2498","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Argument type mismatch.","Argument type mismatch."],"errorCode":"2498","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2498: Argument type mismatch.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2498: Argument type mismatch..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2498","MS Access error 2498","Argument type mismatch."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64397,"title":"2499 - Can't use GoToRecord action on an object in Design view.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2499","Access error 2499","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't use GoToRecord action on an object in Design view.","Can't use GoToRecord action on an object in Design view."],"errorCode":"2499","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2499: Can't use GoToRecord action on an object in Design view.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2499: Can't use GoToRecord action on an object in Design view..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2499","MS Access error 2499","Can't use GoToRecord action on an object in Design view."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64398,"title":"2500 - RepeatCount argument in RunMacro action can't be less than 0.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2500","Access error 2500","Microsoft Access","MSACCESS","Jet","VBA","Access UI","RepeatCount argument in RunMacro action can't be less than 0.","RepeatCount argument in RunMacro action can't be less than 0."],"errorCode":"2500","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2500: RepeatCount argument in RunMacro action can't be less than 0.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2500: RepeatCount argument in RunMacro action can't be less than 0..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2500","MS Access error 2500","RepeatCount argument in RunMacro action can't be less than 0."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64399,"title":"2501 - Action <value> was cancelled.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2501","Access error 2501","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Action | was cancelled.","Action <value> was cancelled."],"errorCode":"2501","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2501: Action <value> was cancelled.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2501: Action <value> was cancelled..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2501","MS Access error 2501","Action | was cancelled."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64400,"title":"2502 - Action requires a Macro Name argument.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2502","Access error 2502","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Action requires a Macro Name argument.","Action requires a Macro Name argument."],"errorCode":"2502","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2502: Action requires a Macro Name argument.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2502: Action requires a Macro Name argument..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2502","MS Access error 2502","Action requires a Macro Name argument."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64401,"title":"2503 - Can't use this command with DoCmd.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2503","Access error 2503","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't use this command with DoCmd.","Can't use this command with DoCmd."],"errorCode":"2503","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2503: Can't use this command with DoCmd.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2503: Can't use this command with DoCmd..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2503","MS Access error 2503","Can't use this command with DoCmd."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64402,"title":"2504 - Action requires at least <value> argument(s).","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2504","Access error 2504","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Action requires at least | argument(s).","Action requires at least <value> argument(s)."],"errorCode":"2504","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2504: Action requires at least <value> argument(s).","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2504: Action requires at least <value> argument(s)..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2504","MS Access error 2504","Action requires at least | argument(s)."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64403,"title":"2505 - Not a valid value for argument '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2505","Access error 2505","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Not a valid value for argument '|'.","Not a valid value for argument '<value>'."],"errorCode":"2505","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2505: Not a valid value for argument '<value>'.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2505: Not a valid value for argument '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2505","MS Access error 2505","Not a valid value for argument '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64404,"title":"2506 - Not a valid value for the Transfer Type argument.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2506","Access error 2506","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Not a valid value for the Transfer Type argument.","Not a valid value for the Transfer Type argument."],"errorCode":"2506","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2506: Not a valid value for the Transfer Type argument.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2506: Not a valid value for the Transfer Type argument..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2506","MS Access error 2506","Not a valid value for the Transfer Type argument."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64405,"title":"2507 - '<value>' isn't an installed database type.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2507","Access error 2507","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","'|' isn't an installed database type.","'<value>' isn't an installed database type."],"errorCode":"2507","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2507: '<value>' isn't an installed database type.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2507: '<value>' isn't an installed database type..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2507","MS Access error 2507","'|' isn't an installed database type."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64406,"title":"2508 - Not a valid value for the Spreadsheet Type argument.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Import / Export"],"keywords":["2508","Access error 2508","Microsoft Access","MSACCESS","Jet","VBA","Import / Export","Not a valid value for the Spreadsheet Type argument.","Not a valid value for the Spreadsheet Type argument."],"errorCode":"2508","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2508: Not a valid value for the Spreadsheet Type argument.","rootCause":"The source format, ISAM driver, specification, field mapping, file version, or destination schema is missing or incompatible.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Preserve the source, verify the import/export specification and supported driver, normalize field names and types, test a small copy, and validate row counts and rejected records.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2508: Not a valid value for the Spreadsheet Type argument..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Import / Export"],"articleCategories":["Microsoft Access","Legacy Software","Import / Export"],"aliases":["Microsoft Access 2508","MS Access error 2508","Not a valid value for the Spreadsheet Type argument."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64407,"title":"2509 - Range argument can't be longer than 255 characters.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2509","Access error 2509","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Range argument can't be longer than 255 characters.","Range argument can't be longer than 255 characters."],"errorCode":"2509","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2509: Range argument can't be longer than 255 characters.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2509: Range argument can't be longer than 255 characters..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2509","MS Access error 2509","Range argument can't be longer than 255 characters."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64408,"title":"2510 - Specification Name argument can't be longer than 64 characters.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2510","Access error 2510","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Specification Name argument can't be longer than 64 characters.","Specification Name argument can't be longer than 64 characters."],"errorCode":"2510","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2510: Specification Name argument can't be longer than 64 characters.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2510: Specification Name argument can't be longer than 64 characters..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2510","MS Access error 2510","Specification Name argument can't be longer than 64 characters."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64409,"title":"2511 - A Specification Name is required for fixed-width import/export.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Import / Export"],"keywords":["2511","Access error 2511","Microsoft Access","MSACCESS","Jet","VBA","Import / Export","A Specification Name is required for fixed-width import/export.","A Specification Name is required for fixed-width import/export."],"errorCode":"2511","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2511: A Specification Name is required for fixed-width import/export.","rootCause":"The source format, ISAM driver, specification, field mapping, file version, or destination schema is missing or incompatible.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Preserve the source, verify the import/export specification and supported driver, normalize field names and types, test a small copy, and validate row counts and rejected records.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2511: A Specification Name is required for fixed-width import/export..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Import / Export"],"articleCategories":["Microsoft Access","Legacy Software","Import / Export"],"aliases":["Microsoft Access 2511","MS Access error 2511","A Specification Name is required for fixed-width import/export."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64410,"title":"2512 - Can't parse expression: '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2512","Access error 2512","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't parse expression: '|'.","Can't parse expression: '<value>'."],"errorCode":"2512","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2512: Can't parse expression: '<value>'.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2512: Can't parse expression: '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2512","MS Access error 2512","Can't parse expression: '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64411,"title":"2513 - Macro Name argument can't be longer than 64 characters.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2513","Access error 2513","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Macro Name argument can't be longer than 64 characters.","Macro Name argument can't be longer than 64 characters."],"errorCode":"2513","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2513: Macro Name argument can't be longer than 64 characters.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2513: Macro Name argument can't be longer than 64 characters..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2513","MS Access error 2513","Macro Name argument can't be longer than 64 characters."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64412,"title":"2514 - Action requires a Control Name argument.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2514","Access error 2514","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Action requires a Control Name argument.","Action requires a Control Name argument."],"errorCode":"2514","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2514: Action requires a Control Name argument.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2514: Action requires a Control Name argument..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2514","MS Access error 2514","Action requires a Control Name argument."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64413,"title":"2540 - File '<value>' is in use and can't be deleted.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["2540","Access error 2540","Microsoft Access","MSACCESS","Jet","VBA","Files","File '|' is in use and can't be deleted.","File '<value>' is in use and can't be deleted."],"errorCode":"2540","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2540: File '<value>' is in use and can't be deleted.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2540: File '<value>' is in use and can't be deleted..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 2540","MS Access error 2540","File '|' is in use and can't be deleted."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64414,"title":"2541 - The contents of the Clipboard have been deleted and can't be pasted.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2541","Access error 2541","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","The contents of the Clipboard have been deleted and can't be pasted.","The contents of the Clipboard have been deleted and can't be pasted."],"errorCode":"2541","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2541: The contents of the Clipboard have been deleted and can't be pasted.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2541: The contents of the Clipboard have been deleted and can't be pasted..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2541","MS Access error 2541","The contents of the Clipboard have been deleted and can't be pasted."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64415,"title":"2542 - Can't run macro from command line without specifying a database.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2542","Access error 2542","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't run macro from command line without specifying a database.","Can't run macro from command line without specifying a database."],"errorCode":"2542","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2542: Can't run macro from command line without specifying a database.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2542: Can't run macro from command line without specifying a database..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2542","MS Access error 2542","Can't run macro from command line without specifying a database."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64416,"title":"2543 - Can't paste an object onto itself.  You must specify a different name.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2543","Access error 2543","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't paste an object onto itself.  You must specify a different name.","Can't paste an object onto itself.  You must specify a different name."],"errorCode":"2543","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2543: Can't paste an object onto itself.  You must specify a different name.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2543: Can't paste an object onto itself.  You must specify a different name..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2543","MS Access error 2543","Can't paste an object onto itself.  You must specify a different name."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64417,"title":"2544 - There is no <value>.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2544","Access error 2544","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","There is no |.","There is no <value>."],"errorCode":"2544","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2544: There is no <value>.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2544: There is no <value>..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2544","MS Access error 2544","There is no |."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64418,"title":"2545 - You must specify a destination database or a new name in order to copy.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2545","Access error 2545","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","You must specify a destination database or a new name in order to copy.","You must specify a destination database or a new name in order to copy."],"errorCode":"2545","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2545: You must specify a destination database or a new name in order to copy.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2545: You must specify a destination database or a new name in order to copy..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2545","MS Access error 2545","You must specify a destination database or a new name in order to copy."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64419,"title":"2546 - Can't copy because nothing is selected.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2546","Access error 2546","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't copy because nothing is selected.","Can't copy because nothing is selected."],"errorCode":"2546","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2546: Can't copy because nothing is selected.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2546: Can't copy because nothing is selected..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2546","MS Access error 2546","Can't copy because nothing is selected."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64420,"title":"2547 - File '<value>' can't be deleted.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["2547","Access error 2547","Microsoft Access","MSACCESS","Jet","VBA","Files","File '|' can't be deleted.","File '<value>' can't be deleted."],"errorCode":"2547","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2547: File '<value>' can't be deleted.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2547: File '<value>' can't be deleted..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 2547","MS Access error 2547","File '|' can't be deleted."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64421,"title":"2548 - Can't copy '<value>' to itself.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2548","Access error 2548","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't copy '|' to itself.","Can't copy '<value>' to itself."],"errorCode":"2548","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2548: Can't copy '<value>' to itself.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2548: Can't copy '<value>' to itself..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2548","MS Access error 2548","Can't copy '|' to itself."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64422,"title":"2549 - Couldn't delete '<value 1>' after compacting it.  Compacted database is named '<value 2>'","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2549","Access error 2549","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't delete '|1' after compacting it.  Compacted database is named '|2'","Couldn't delete '<value 1>' after compacting it.  Compacted database is named '<value 2>'"],"errorCode":"2549","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2549: Couldn't delete '<value 1>' after compacting it.  Compacted database is named '<value 2>'","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2549: Couldn't delete '<value 1>' after compacting it.  Compacted database is named '<value 2>'.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2549","MS Access error 2549","Couldn't delete '|1' after compacting it.  Compacted database is named '|2'"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64423,"title":"2550 - Couldn't delete '<value 1>' after encrypting it.  Encrypted database is named '<value 2>'","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2550","Access error 2550","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't delete '|1' after encrypting it.  Encrypted database is named '|2'","Couldn't delete '<value 1>' after encrypting it.  Encrypted database is named '<value 2>'"],"errorCode":"2550","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2550: Couldn't delete '<value 1>' after encrypting it.  Encrypted database is named '<value 2>'","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2550: Couldn't delete '<value 1>' after encrypting it.  Encrypted database is named '<value 2>'.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2550","MS Access error 2550","Couldn't delete '|1' after encrypting it.  Encrypted database is named '|2'"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64424,"title":"2551 - Couldn't delete '<value 1>' after decrypting it.  Decrypted database is named '<value 2>'","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2551","Access error 2551","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't delete '|1' after decrypting it.  Decrypted database is named '|2'","Couldn't delete '<value 1>' after decrypting it.  Decrypted database is named '<value 2>'"],"errorCode":"2551","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2551: Couldn't delete '<value 1>' after decrypting it.  Decrypted database is named '<value 2>'","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2551: Couldn't delete '<value 1>' after decrypting it.  Decrypted database is named '<value 2>'.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2551","MS Access error 2551","Couldn't delete '|1' after decrypting it.  Decrypted database is named '|2'"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64425,"title":"2552 - Couldn't encrypt.  Only the owner of a database may encrypt it.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2552","Access error 2552","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't encrypt.  Only the owner of a database may encrypt it.","Couldn't encrypt.  Only the owner of a database may encrypt it."],"errorCode":"2552","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2552: Couldn't encrypt.  Only the owner of a database may encrypt it.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2552: Couldn't encrypt.  Only the owner of a database may encrypt it..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2552","MS Access error 2552","Couldn't encrypt.  Only the owner of a database may encrypt it."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64426,"title":"2553 - Couldn't decrypt.  Only the owner of a database may decrypt it.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2553","Access error 2553","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't decrypt.  Only the owner of a database may decrypt it.","Couldn't decrypt.  Only the owner of a database may decrypt it."],"errorCode":"2553","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2553: Couldn't decrypt.  Only the owner of a database may decrypt it.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2553: Couldn't decrypt.  Only the owner of a database may decrypt it..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2553","MS Access error 2553","Couldn't decrypt.  Only the owner of a database may decrypt it."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64427,"title":"2580 - This report is bound to a table or query that doesn't exist: '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2580","Access error 2580","Microsoft Access","MSACCESS","Jet","VBA","Queries","This report is bound to a table or query that doesn't exist: '|'.","This report is bound to a table or query that doesn't exist: '<value>'."],"errorCode":"2580","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2580: This report is bound to a table or query that doesn't exist: '<value>'.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2580: This report is bound to a table or query that doesn't exist: '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2580","MS Access error 2580","This report is bound to a table or query that doesn't exist: '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64428,"title":"2581 - You must specify a field or expression to sort on.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2581","Access error 2581","Microsoft Access","MSACCESS","Jet","VBA","Queries","You must specify a field or expression to sort on.","You must specify a field or expression to sort on."],"errorCode":"2581","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2581: You must specify a field or expression to sort on.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2581: You must specify a field or expression to sort on..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2581","MS Access error 2581","You must specify a field or expression to sort on."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64429,"title":"2582 - GroupInterval can be set to zero only when GroupOn is set to Each Value.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2582","Access error 2582","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","GroupInterval can be set to zero only when GroupOn is set to Each Value.","GroupInterval can be set to zero only when GroupOn is set to Each Value."],"errorCode":"2582","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2582: GroupInterval can be set to zero only when GroupOn is set to Each Value.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2582: GroupInterval can be set to zero only when GroupOn is set to Each Value..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2582","MS Access error 2582","GroupInterval can be set to zero only when GroupOn is set to Each Value."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64430,"title":"2583 - The ApplyFilter action can be called only from a macro run from the OnOpen property.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2583","Access error 2583","Microsoft Access","MSACCESS","Jet","VBA","Access UI","The ApplyFilter action can be called only from a macro run from the OnOpen property.","The ApplyFilter action can be called only from a macro run from the OnOpen property."],"errorCode":"2583","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2583: The ApplyFilter action can be called only from a macro run from the OnOpen property.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2583: The ApplyFilter action can be called only from a macro run from the OnOpen property..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2583","MS Access error 2583","The ApplyFilter action can be called only from a macro run from the OnOpen property."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64431,"title":"2584 - You can't use aggregate functions in a page header or footer.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2584","Access error 2584","Microsoft Access","MSACCESS","Jet","VBA","Queries","You can't use aggregate functions in a page header or footer.","You can't use aggregate functions in a page header or footer."],"errorCode":"2584","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2584: You can't use aggregate functions in a page header or footer.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2584: You can't use aggregate functions in a page header or footer..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2584","MS Access error 2584","You can't use aggregate functions in a page header or footer."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64432,"title":"2585 - Can't run this action while processing a report event.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["2585","Access error 2585","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Can't run this action while processing a report event.","Can't run this action while processing a report event."],"errorCode":"2585","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2585: Can't run this action while processing a report event.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2585: Can't run this action while processing a report event..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 2585","MS Access error 2585","Can't run this action while processing a report event."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64433,"title":"2586 - The MoveLayout and NextRecord run-time properties can't both be set to FALSE; to ensure that the report advances both have been set back to TRUE.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2586","Access error 2586","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","The MoveLayout and NextRecord run-time properties can't both be set to FALSE; to ensure that the report advances both have been set back to TRUE.","The MoveLayout and NextRecord run-time properties can't both be set to FALSE; to ensure that the report advances both have been set back to TRUE."],"errorCode":"2586","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2586: The MoveLayout and NextRecord run-time properties can't both be set to FALSE; to ensure that the report advances both have been set back to TRUE.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2586: The MoveLayout and NextRecord run-time properties can't both be set to FALSE; to ensure that the report advances both have been set back to TRUE..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2586","MS Access error 2586","The MoveLayout and NextRecord run-time properties can't both be set to FALSE; to ensure that the report advances both have been set back to TRUE."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64434,"title":"2600 - Please verify the new password by entering it in the Verify box and pressing Enter.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Security"],"keywords":["2600","Access error 2600","Microsoft Access","MSACCESS","Jet","VBA","Security","Please verify the new password by entering it in the Verify box and pressing Enter.","Please verify the new password by entering it in the Verify box and pressing Enter."],"errorCode":"2600","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2600: Please verify the new password by entering it in the Verify box and pressing Enter.","rootCause":"The operation is blocked by credentials, permissions, ownership, read-only state, or legacy workgroup security.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify identity and least-privilege permissions, file/share rights, database ownership and legacy workgroup configuration; do not weaken security controls globally.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2600: Please verify the new password by entering it in the Verify box and pressing Enter..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Security"],"articleCategories":["Microsoft Access","Legacy Software","Security"],"aliases":["Microsoft Access 2600","MS Access error 2600","Please verify the new password by entering it in the Verify box and pressing Enter."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64435,"title":"2601 - You don't have permission to read '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Security"],"keywords":["2601","Access error 2601","Microsoft Access","MSACCESS","Jet","VBA","Security","You don't have permission to read '|'.","You don't have permission to read '<value>'."],"errorCode":"2601","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2601: You don't have permission to read '<value>'.","rootCause":"The operation is blocked by credentials, permissions, ownership, read-only state, or legacy workgroup security.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify identity and least-privilege permissions, file/share rights, database ownership and legacy workgroup configuration; do not weaken security controls globally.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2601: You don't have permission to read '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Security"],"articleCategories":["Microsoft Access","Legacy Software","Security"],"aliases":["Microsoft Access 2601","MS Access error 2601","You don't have permission to read '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64436,"title":"2602 - You don't have permission to modify '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Security"],"keywords":["2602","Access error 2602","Microsoft Access","MSACCESS","Jet","VBA","Security","You don't have permission to modify '|'.","You don't have permission to modify '<value>'."],"errorCode":"2602","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2602: You don't have permission to modify '<value>'.","rootCause":"The operation is blocked by credentials, permissions, ownership, read-only state, or legacy workgroup security.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify identity and least-privilege permissions, file/share rights, database ownership and legacy workgroup configuration; do not weaken security controls globally.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2602: You don't have permission to modify '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Security"],"articleCategories":["Microsoft Access","Legacy Software","Security"],"aliases":["Microsoft Access 2602","MS Access error 2602","You don't have permission to modify '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64437,"title":"2603 - You don't have permission to execute '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Security"],"keywords":["2603","Access error 2603","Microsoft Access","MSACCESS","Jet","VBA","Security","You don't have permission to execute '|'.","You don't have permission to execute '<value>'."],"errorCode":"2603","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2603: You don't have permission to execute '<value>'.","rootCause":"The operation is blocked by credentials, permissions, ownership, read-only state, or legacy workgroup security.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify identity and least-privilege permissions, file/share rights, database ownership and legacy workgroup configuration; do not weaken security controls globally.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2603: You don't have permission to execute '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Security"],"articleCategories":["Microsoft Access","Legacy Software","Security"],"aliases":["Microsoft Access 2603","MS Access error 2603","You don't have permission to execute '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64438,"title":"2604 - You can't view this object's permissions.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Security"],"keywords":["2604","Access error 2604","Microsoft Access","MSACCESS","Jet","VBA","Security","You can't view this object's permissions.","You can't view this object's permissions."],"errorCode":"2604","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2604: You can't view this object's permissions.","rootCause":"The operation is blocked by credentials, permissions, ownership, read-only state, or legacy workgroup security.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify identity and least-privilege permissions, file/share rights, database ownership and legacy workgroup configuration; do not weaken security controls globally.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2604: You can't view this object's permissions..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Security"],"articleCategories":["Microsoft Access","Legacy Software","Security"],"aliases":["Microsoft Access 2604","MS Access error 2604","You can't view this object's permissions."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64439,"title":"2605 - Can't remove user from group '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2605","Access error 2605","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't remove user from group '|'.","Can't remove user from group '<value>'."],"errorCode":"2605","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2605: Can't remove user from group '<value>'.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2605: Can't remove user from group '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2605","MS Access error 2605","Can't remove user from group '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64440,"title":"2606 - Not a valid Microsoft Access object type.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2606","Access error 2606","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Not a valid Microsoft Access object type.","Not a valid Microsoft Access object type."],"errorCode":"2606","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2606: Not a valid Microsoft Access object type.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2606: Not a valid Microsoft Access object type..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2606","MS Access error 2606","Not a valid Microsoft Access object type."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64441,"title":"2607 - You don't have permission to cut '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Security"],"keywords":["2607","Access error 2607","Microsoft Access","MSACCESS","Jet","VBA","Security","You don't have permission to cut '|'.","You don't have permission to cut '<value>'."],"errorCode":"2607","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2607: You don't have permission to cut '<value>'.","rootCause":"The operation is blocked by credentials, permissions, ownership, read-only state, or legacy workgroup security.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify identity and least-privilege permissions, file/share rights, database ownership and legacy workgroup configuration; do not weaken security controls globally.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2607: You don't have permission to cut '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Security"],"articleCategories":["Microsoft Access","Legacy Software","Security"],"aliases":["Microsoft Access 2607","MS Access error 2607","You don't have permission to cut '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64442,"title":"2608 - You don't have permission to copy '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Security"],"keywords":["2608","Access error 2608","Microsoft Access","MSACCESS","Jet","VBA","Security","You don't have permission to copy '|'.","You don't have permission to copy '<value>'."],"errorCode":"2608","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2608: You don't have permission to copy '<value>'.","rootCause":"The operation is blocked by credentials, permissions, ownership, read-only state, or legacy workgroup security.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify identity and least-privilege permissions, file/share rights, database ownership and legacy workgroup configuration; do not weaken security controls globally.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2608: You don't have permission to copy '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Security"],"articleCategories":["Microsoft Access","Legacy Software","Security"],"aliases":["Microsoft Access 2608","MS Access error 2608","You don't have permission to copy '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64443,"title":"2609 - You don't have permission to delete '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Security"],"keywords":["2609","Access error 2609","Microsoft Access","MSACCESS","Jet","VBA","Security","You don't have permission to delete '|'.","You don't have permission to delete '<value>'."],"errorCode":"2609","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 2609: You don't have permission to delete '<value>'.","rootCause":"The operation is blocked by credentials, permissions, ownership, read-only state, or legacy workgroup security.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify identity and least-privilege permissions, file/share rights, database ownership and legacy workgroup configuration; do not weaken security controls globally.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2609: You don't have permission to delete '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Security"],"articleCategories":["Microsoft Access","Legacy Software","Security"],"aliases":["Microsoft Access 2609","MS Access error 2609","You don't have permission to delete '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64444,"title":"2610 - You must enter a Personal Identification Number consisting of four digits.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2610","Access error 2610","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","You must enter a Personal Identification Number consisting of four digits.","You must enter a Personal Identification Number consisting of four digits."],"errorCode":"2610","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2610: You must enter a Personal Identification Number consisting of four digits.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2610: You must enter a Personal Identification Number consisting of four digits..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2610","MS Access error 2610","You must enter a Personal Identification Number consisting of four digits."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64445,"title":"2611 - This account already exists.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2611","Access error 2611","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","This account already exists.","This account already exists."],"errorCode":"2611","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2611: This account already exists.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2611: This account already exists..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2611","MS Access error 2611","This account already exists."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64446,"title":"2612 - Not a valid account name.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["2612","Access error 2612","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Not a valid account name.","Not a valid account name."],"errorCode":"2612","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2612: Not a valid account name.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2612: Not a valid account name..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 2612","MS Access error 2612","Not a valid account name."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64447,"title":"2640 - The table '<value>' has no primary key.  You can't select it as the primary table in a relationship.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2640","Access error 2640","Microsoft Access","MSACCESS","Jet","VBA","Queries","The table '|' has no primary key.  You can't select it as the primary table in a relationship.","The table '<value>' has no primary key.  You can't select it as the primary table in a relationship."],"errorCode":"2640","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2640: The table '<value>' has no primary key.  You can't select it as the primary table in a relationship.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2640: The table '<value>' has no primary key.  You can't select it as the primary table in a relationship..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2640","MS Access error 2640","The table '|' has no primary key.  You can't select it as the primary table in a relationship."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64448,"title":"2641 - Can't create relationship; too many fields in <value>'s primary key.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2641","Access error 2641","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't create relationship; too many fields in |'s primary key.","Can't create relationship; too many fields in <value>'s primary key."],"errorCode":"2641","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2641: Can't create relationship; too many fields in <value>'s primary key.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2641: Can't create relationship; too many fields in <value>'s primary key..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2641","MS Access error 2641","Can't create relationship; too many fields in |'s primary key."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64449,"title":"2642 - Can't create relationship because there aren't any tables in the database.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2642","Access error 2642","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't create relationship because there aren't any tables in the database.","Can't create relationship because there aren't any tables in the database."],"errorCode":"2642","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2642: Can't create relationship because there aren't any tables in the database.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2642: Can't create relationship because there aren't any tables in the database..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2642","MS Access error 2642","Can't create relationship because there aren't any tables in the database."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64450,"title":"2643 - Can't create a one-to-one relationship between these tables.  One or more key fields don't match.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2643","Access error 2643","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't create a one-to-one relationship between these tables.  One or more key fields don't match.","Can't create a one-to-one relationship between these tables.  One or more key fields don't match."],"errorCode":"2643","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2643: Can't create a one-to-one relationship between these tables.  One or more key fields don't match.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2643: Can't create a one-to-one relationship between these tables.  One or more key fields don't match..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2643","MS Access error 2643","Can't create a one-to-one relationship between these tables.  One or more key fields don't match."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64451,"title":"2644 - Can't create a relationship between these tables.  There aren't any matching fields.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2644","Access error 2644","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't create a relationship between these tables.  There aren't any matching fields.","Can't create a relationship between these tables.  There aren't any matching fields."],"errorCode":"2644","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2644: Can't create a relationship between these tables.  There aren't any matching fields.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2644: Can't create a relationship between these tables.  There aren't any matching fields..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2644","MS Access error 2644","Can't create a relationship between these tables.  There aren't any matching fields."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64452,"title":"2645 - There are no matching fields to suggest.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2645","Access error 2645","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","There are no matching fields to suggest.","There are no matching fields to suggest."],"errorCode":"2645","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2645: There are no matching fields to suggest.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2645: There are no matching fields to suggest..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2645","MS Access error 2645","There are no matching fields to suggest."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64453,"title":"2646 - Can't create relationship.  Existing data in table '<value>' violates specified relationship.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2646","Access error 2646","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't create relationship.  Existing data in table '|' violates specified relationship.","Can't create relationship.  Existing data in table '<value>' violates specified relationship."],"errorCode":"2646","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2646: Can't create relationship.  Existing data in table '<value>' violates specified relationship.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2646: Can't create relationship.  Existing data in table '<value>' violates specified relationship..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2646","MS Access error 2646","Can't create relationship.  Existing data in table '|' violates specified relationship."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64454,"title":"2647 - Table '<value>' has no primary key.  You can't select it as the related table in a one-to-one relationship.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["2647","Access error 2647","Microsoft Access","MSACCESS","Jet","VBA","Queries","Table '|' has no primary key.  You can't select it as the related table in a one-to-one relationship.","Table '<value>' has no primary key.  You can't select it as the related table in a one-to-one relationship."],"errorCode":"2647","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2647: Table '<value>' has no primary key.  You can't select it as the related table in a one-to-one relationship.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2647: Table '<value>' has no primary key.  You can't select it as the related table in a one-to-one relationship..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 2647","MS Access error 2647","Table '|' has no primary key.  You can't select it as the related table in a one-to-one relationship."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64455,"title":"2648 - The relationship has been created as a one-to-one relationship because there is a 'No Duplicates' index on the fields specified for the related table.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["2648","Access error 2648","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","The relationship has been created as a one-to-one relationship because there is a 'No Duplicates' index on the fields specified for the related table.","The relationship has been created as a one-to-one relationship because there is a 'No Duplicates' index on the fields specified for the related table."],"errorCode":"2648","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 2648: The relationship has been created as a one-to-one relationship because there is a 'No Duplicates' index on the fields specified for the related table.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 2648: The relationship has been created as a one-to-one relationship because there is a 'No Duplicates' index on the fields specified for the related table..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 2648","MS Access error 2648","The relationship has been created as a one-to-one relationship because there is a 'No Duplicates' index on the fields specified for the related table."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64456,"title":"3000 - An internal database error (<value>) has occurred.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3000","Access error 3000","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","An internal database error (|) has occurred.","An internal database error (<value>) has occurred."],"errorCode":"3000","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3000: An internal database error (<value>) has occurred.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3000: An internal database error (<value>) has occurred..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3000","MS Access error 3000","An internal database error (|) has occurred."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64457,"title":"3001 - Invalid argument.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3001","Access error 3001","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Invalid argument.","Invalid argument."],"errorCode":"3001","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3001: Invalid argument.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3001: Invalid argument..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3001","MS Access error 3001","Invalid argument."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64458,"title":"3002 - Couldn't start session.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3002","Access error 3002","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Couldn't start session.","Couldn't start session."],"errorCode":"3002","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3002: Couldn't start session.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3002: Couldn't start session..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3002","MS Access error 3002","Couldn't start session."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64459,"title":"3003 - Couldn't start transaction; too many transactions already nested.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3003","Access error 3003","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Couldn't start transaction; too many transactions already nested.","Couldn't start transaction; too many transactions already nested."],"errorCode":"3003","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3003: Couldn't start transaction; too many transactions already nested.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3003: Couldn't start transaction; too many transactions already nested..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3003","MS Access error 3003","Couldn't start transaction; too many transactions already nested."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64460,"title":"3004 - Couldn't find database '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3004","Access error 3004","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't find database '|'.","Couldn't find database '<value>'."],"errorCode":"3004","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3004: Couldn't find database '<value>'.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3004: Couldn't find database '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3004","MS Access error 3004","Couldn't find database '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64461,"title":"3005 - '<value>' isn't a valid database name.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3005","Access error 3005","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","'|' isn't a valid database name.","'<value>' isn't a valid database name."],"errorCode":"3005","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3005: '<value>' isn't a valid database name.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3005: '<value>' isn't a valid database name..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3005","MS Access error 3005","'|' isn't a valid database name."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64462,"title":"3006 - Database '<value>' is exclusively locked.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3006","Access error 3006","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Database '|' is exclusively locked.","Database '<value>' is exclusively locked."],"errorCode":"3006","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3006: Database '<value>' is exclusively locked.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3006: Database '<value>' is exclusively locked..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3006","MS Access error 3006","Database '|' is exclusively locked."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64463,"title":"3007 - Couldn't open database '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3007","Access error 3007","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't open database '|'.","Couldn't open database '<value>'."],"errorCode":"3007","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3007: Couldn't open database '<value>'.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3007: Couldn't open database '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3007","MS Access error 3007","Couldn't open database '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64464,"title":"3008 - Table '<value>' is exclusively locked.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3008","Access error 3008","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Table '|' is exclusively locked.","Table '<value>' is exclusively locked."],"errorCode":"3008","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3008: Table '<value>' is exclusively locked.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3008: Table '<value>' is exclusively locked..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3008","MS Access error 3008","Table '|' is exclusively locked."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64465,"title":"3009 - Couldn't lock table '<value>'; currently in use.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3009","Access error 3009","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't lock table '|'; currently in use.","Couldn't lock table '<value>'; currently in use."],"errorCode":"3009","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3009: Couldn't lock table '<value>'; currently in use.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3009: Couldn't lock table '<value>'; currently in use..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3009","MS Access error 3009","Couldn't lock table '|'; currently in use."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64466,"title":"3010 - Table '<value>' already exists.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3010","Access error 3010","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Table '|' already exists.","Table '<value>' already exists."],"errorCode":"3010","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3010: Table '<value>' already exists.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3010: Table '<value>' already exists..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3010","MS Access error 3010","Table '|' already exists."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64467,"title":"3011 - Couldn't find object '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3011","Access error 3011","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Couldn't find object '|'.","Couldn't find object '<value>'."],"errorCode":"3011","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3011: Couldn't find object '<value>'.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3011: Couldn't find object '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3011","MS Access error 3011","Couldn't find object '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64468,"title":"3012 - Object '<value>' already exists.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3012","Access error 3012","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Object '|' already exists.","Object '<value>' already exists."],"errorCode":"3012","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3012: Object '<value>' already exists.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3012: Object '<value>' already exists..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3012","MS Access error 3012","Object '|' already exists."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64469,"title":"3013 - Couldn't rename installable ISAM file.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Import / Export"],"keywords":["3013","Access error 3013","Microsoft Access","MSACCESS","Jet","VBA","Import / Export","Couldn't rename installable ISAM file.","Couldn't rename installable ISAM file."],"errorCode":"3013","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3013: Couldn't rename installable ISAM file.","rootCause":"The source format, ISAM driver, specification, field mapping, file version, or destination schema is missing or incompatible.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Preserve the source, verify the import/export specification and supported driver, normalize field names and types, test a small copy, and validate row counts and rejected records.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3013: Couldn't rename installable ISAM file..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Import / Export"],"articleCategories":["Microsoft Access","Legacy Software","Import / Export"],"aliases":["Microsoft Access 3013","MS Access error 3013","Couldn't rename installable ISAM file."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64470,"title":"3014 - Can't open any more tables.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3014","Access error 3014","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't open any more tables.","Can't open any more tables."],"errorCode":"3014","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3014: Can't open any more tables.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3014: Can't open any more tables..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3014","MS Access error 3014","Can't open any more tables."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64471,"title":"3015 - '<value>' isn't an index in this table.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3015","Access error 3015","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","'|' isn't an index in this table.","'<value>' isn't an index in this table."],"errorCode":"3015","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3015: '<value>' isn't an index in this table.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3015: '<value>' isn't an index in this table..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3015","MS Access error 3015","'|' isn't an index in this table."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64472,"title":"3016 - Field won't fit in record.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3016","Access error 3016","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Field won't fit in record.","Field won't fit in record."],"errorCode":"3016","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3016: Field won't fit in record.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3016: Field won't fit in record..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3016","MS Access error 3016","Field won't fit in record."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64473,"title":"3017 - Field length is too long.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3017","Access error 3017","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Field length is too long.","Field length is too long."],"errorCode":"3017","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3017: Field length is too long.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3017: Field length is too long..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3017","MS Access error 3017","Field length is too long."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64474,"title":"3018 - Couldn't find field '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3018","Access error 3018","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't find field '|'.","Couldn't find field '<value>'."],"errorCode":"3018","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3018: Couldn't find field '<value>'.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3018: Couldn't find field '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3018","MS Access error 3018","Couldn't find field '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64475,"title":"3019 - Operation invalid without a current index.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3019","Access error 3019","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Operation invalid without a current index.","Operation invalid without a current index."],"errorCode":"3019","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3019: Operation invalid without a current index.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3019: Operation invalid without a current index..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3019","MS Access error 3019","Operation invalid without a current index."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64476,"title":"3020 - Update without AddNew or Edit.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3020","Access error 3020","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Update without AddNew or Edit.","Update without AddNew or Edit."],"errorCode":"3020","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3020: Update without AddNew or Edit.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3020: Update without AddNew or Edit..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3020","MS Access error 3020","Update without AddNew or Edit."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64477,"title":"3021 - No current record.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3021","Access error 3021","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","No current record.","No current record."],"errorCode":"3021","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3021: No current record.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3021: No current record..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3021","MS Access error 3021","No current record."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64478,"title":"3022 - Can't have duplicate key; index changes were unsuccessful.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3022","Access error 3022","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't have duplicate key; index changes were unsuccessful.","Can't have duplicate key; index changes were unsuccessful."],"errorCode":"3022","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3022: Can't have duplicate key; index changes were unsuccessful.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3022: Can't have duplicate key; index changes were unsuccessful..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3022","MS Access error 3022","Can't have duplicate key; index changes were unsuccessful."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64479,"title":"3023 - AddNew or Edit already used.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3023","Access error 3023","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","AddNew or Edit already used.","AddNew or Edit already used."],"errorCode":"3023","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3023: AddNew or Edit already used.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3023: AddNew or Edit already used..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3023","MS Access error 3023","AddNew or Edit already used."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64480,"title":"3024 - Couldn't find file '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["3024","Access error 3024","Microsoft Access","MSACCESS","Jet","VBA","Files","Couldn't find file '|'.","Couldn't find file '<value>'."],"errorCode":"3024","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3024: Couldn't find file '<value>'.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3024: Couldn't find file '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 3024","MS Access error 3024","Couldn't find file '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64481,"title":"3025 - Can't open any more files.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["3025","Access error 3025","Microsoft Access","MSACCESS","Jet","VBA","Files","Can't open any more files.","Can't open any more files."],"errorCode":"3025","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3025: Can't open any more files.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3025: Can't open any more files..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 3025","MS Access error 3025","Can't open any more files."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64482,"title":"3026 - Not enough space on disk.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["3026","Access error 3026","Microsoft Access","MSACCESS","Jet","VBA","Files","Not enough space on disk.","Not enough space on disk."],"errorCode":"3026","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3026: Not enough space on disk.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3026: Not enough space on disk..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 3026","MS Access error 3026","Not enough space on disk."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64483,"title":"3027 - Couldn't update; database is read-only.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3027","Access error 3027","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't update; database is read-only.","Couldn't update; database is read-only."],"errorCode":"3027","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3027: Couldn't update; database is read-only.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3027: Couldn't update; database is read-only..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3027","MS Access error 3027","Couldn't update; database is read-only."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64484,"title":"3028 - Couldn't start Microsoft Access because file 'SYSTEM.MDA' couldn't be opened.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["3028","Access error 3028","Microsoft Access","MSACCESS","Jet","VBA","Files","Couldn't start Microsoft Access because file 'SYSTEM.MDA' couldn't be opened.","Couldn't start Microsoft Access because file 'SYSTEM.MDA' couldn't be opened."],"errorCode":"3028","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3028: Couldn't start Microsoft Access because file 'SYSTEM.MDA' couldn't be opened.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3028: Couldn't start Microsoft Access because file 'SYSTEM.MDA' couldn't be opened..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 3028","MS Access error 3028","Couldn't start Microsoft Access because file 'SYSTEM.MDA' couldn't be opened."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64485,"title":"3029 - Not a valid account name or password.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Security"],"keywords":["3029","Access error 3029","Microsoft Access","MSACCESS","Jet","VBA","Security","Not a valid account name or password.","Not a valid account name or password."],"errorCode":"3029","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3029: Not a valid account name or password.","rootCause":"The operation is blocked by credentials, permissions, ownership, read-only state, or legacy workgroup security.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify identity and least-privilege permissions, file/share rights, database ownership and legacy workgroup configuration; do not weaken security controls globally.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3029: Not a valid account name or password..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Security"],"articleCategories":["Microsoft Access","Legacy Software","Security"],"aliases":["Microsoft Access 3029","MS Access error 3029","Not a valid account name or password."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64486,"title":"3030 - '<value>' isn't a valid account name.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3030","Access error 3030","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","'|' isn't a valid account name.","'<value>' isn't a valid account name."],"errorCode":"3030","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3030: '<value>' isn't a valid account name.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3030: '<value>' isn't a valid account name..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3030","MS Access error 3030","'|' isn't a valid account name."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64487,"title":"3031 - Not a valid password.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Security"],"keywords":["3031","Access error 3031","Microsoft Access","MSACCESS","Jet","VBA","Security","Not a valid password.","Not a valid password."],"errorCode":"3031","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3031: Not a valid password.","rootCause":"The operation is blocked by credentials, permissions, ownership, read-only state, or legacy workgroup security.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify identity and least-privilege permissions, file/share rights, database ownership and legacy workgroup configuration; do not weaken security controls globally.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3031: Not a valid password..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Security"],"articleCategories":["Microsoft Access","Legacy Software","Security"],"aliases":["Microsoft Access 3031","MS Access error 3031","Not a valid password."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64488,"title":"3032 - Can't delete account.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3032","Access error 3032","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't delete account.","Can't delete account."],"errorCode":"3032","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3032: Can't delete account.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3032: Can't delete account..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3032","MS Access error 3032","Can't delete account."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64489,"title":"3033 - No permission for '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Security"],"keywords":["3033","Access error 3033","Microsoft Access","MSACCESS","Jet","VBA","Security","No permission for '|'.","No permission for '<value>'."],"errorCode":"3033","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3033: No permission for '<value>'.","rootCause":"The operation is blocked by credentials, permissions, ownership, read-only state, or legacy workgroup security.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify identity and least-privilege permissions, file/share rights, database ownership and legacy workgroup configuration; do not weaken security controls globally.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3033: No permission for '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Security"],"articleCategories":["Microsoft Access","Legacy Software","Security"],"aliases":["Microsoft Access 3033","MS Access error 3033","No permission for '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64490,"title":"3034 - Commit or Rollback without BeginTrans.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3034","Access error 3034","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Commit or Rollback without BeginTrans.","Commit or Rollback without BeginTrans."],"errorCode":"3034","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3034: Commit or Rollback without BeginTrans.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3034: Commit or Rollback without BeginTrans..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3034","MS Access error 3034","Commit or Rollback without BeginTrans."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64491,"title":"3035 - Out of memory.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Resources"],"keywords":["3035","Access error 3035","Microsoft Access","MSACCESS","Jet","VBA","Resources","Out of memory.","Out of memory."],"errorCode":"3035","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3035: Out of memory.","rootCause":"Access or Windows lacks sufficient memory, stack, handles, disk, or other resources for the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Save work, close unnecessary objects/applications, check memory, handles, disk and database size, then reproduce after a controlled restart and review for runaway queries or code.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3035: Out of memory..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Resources"],"articleCategories":["Microsoft Access","Legacy Software","Resources"],"aliases":["Microsoft Access 3035","MS Access error 3035","Out of memory."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64492,"title":"3036 - Database has reached maximum size.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3036","Access error 3036","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Database has reached maximum size.","Database has reached maximum size."],"errorCode":"3036","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3036: Database has reached maximum size.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3036: Database has reached maximum size..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3036","MS Access error 3036","Database has reached maximum size."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64493,"title":"3037 - Can't open any more tables or queries.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3037","Access error 3037","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't open any more tables or queries.","Can't open any more tables or queries."],"errorCode":"3037","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3037: Can't open any more tables or queries.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3037: Can't open any more tables or queries..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3037","MS Access error 3037","Can't open any more tables or queries."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64494,"title":"3038 - Out of memory.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Resources"],"keywords":["3038","Access error 3038","Microsoft Access","MSACCESS","Jet","VBA","Resources","Out of memory.","Out of memory."],"errorCode":"3038","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3038: Out of memory.","rootCause":"Access or Windows lacks sufficient memory, stack, handles, disk, or other resources for the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Save work, close unnecessary objects/applications, check memory, handles, disk and database size, then reproduce after a controlled restart and review for runaway queries or code.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3038: Out of memory..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Resources"],"articleCategories":["Microsoft Access","Legacy Software","Resources"],"aliases":["Microsoft Access 3038","MS Access error 3038","Out of memory."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64495,"title":"3039 - Couldn't create index; too many indexes already defined.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3039","Access error 3039","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't create index; too many indexes already defined.","Couldn't create index; too many indexes already defined."],"errorCode":"3039","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3039: Couldn't create index; too many indexes already defined.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3039: Couldn't create index; too many indexes already defined..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3039","MS Access error 3039","Couldn't create index; too many indexes already defined."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64496,"title":"3040 - Disk I/O error during read.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["3040","Access error 3040","Microsoft Access","MSACCESS","Jet","VBA","Files","Disk I/O error during read.","Disk I/O error during read."],"errorCode":"3040","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3040: Disk I/O error during read.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3040: Disk I/O error during read..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 3040","MS Access error 3040","Disk I/O error during read."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64497,"title":"3041 - Out-of-date database format.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3041","Access error 3041","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Out-of-date database format.","Out-of-date database format."],"errorCode":"3041","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3041: Out-of-date database format.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3041: Out-of-date database format..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3041","MS Access error 3041","Out-of-date database format."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64498,"title":"3042 - Out of MS-DOS file handles.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["3042","Access error 3042","Microsoft Access","MSACCESS","Jet","VBA","Files","Out of MS-DOS file handles.","Out of MS-DOS file handles."],"errorCode":"3042","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3042: Out of MS-DOS file handles.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3042: Out of MS-DOS file handles..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 3042","MS Access error 3042","Out of MS-DOS file handles."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64499,"title":"3043 - Disk or network error.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["3043","Access error 3043","Microsoft Access","MSACCESS","Jet","VBA","Files","Disk or network error.","Disk or network error."],"errorCode":"3043","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3043: Disk or network error.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3043: Disk or network error..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 3043","MS Access error 3043","Disk or network error."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64500,"title":"3044 - '<value>' isn't a valid path.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["3044","Access error 3044","Microsoft Access","MSACCESS","Jet","VBA","Files","'|' isn't a valid path.","'<value>' isn't a valid path."],"errorCode":"3044","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3044: '<value>' isn't a valid path.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3044: '<value>' isn't a valid path..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 3044","MS Access error 3044","'|' isn't a valid path."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64501,"title":"3045 - Couldn't use '<value>'; file already in use.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["3045","Access error 3045","Microsoft Access","MSACCESS","Jet","VBA","Files","Couldn't use '|'; file already in use.","Couldn't use '<value>'; file already in use."],"errorCode":"3045","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3045: Couldn't use '<value>'; file already in use.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3045: Couldn't use '<value>'; file already in use..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 3045","MS Access error 3045","Couldn't use '|'; file already in use."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64502,"title":"3046 - Couldn't save; currently locked by another user.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Locking"],"keywords":["3046","Access error 3046","Microsoft Access","MSACCESS","Jet","VBA","Locking","Couldn't save; currently locked by another user.","Couldn't save; currently locked by another user."],"errorCode":"3046","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3046: Couldn't save; currently locked by another user.","rootCause":"The database, page, record, or object is already locked or in use by another session.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Identify active users and the locking object, coordinate closure or retry, verify share permissions and healthy lock-file cleanup, and never delete a lock file while users remain connected.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3046: Couldn't save; currently locked by another user..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Locking"],"articleCategories":["Microsoft Access","Legacy Software","Locking"],"aliases":["Microsoft Access 3046","MS Access error 3046","Couldn't save; currently locked by another user."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64503,"title":"3047 - Record is too large.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3047","Access error 3047","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Record is too large.","Record is too large."],"errorCode":"3047","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3047: Record is too large.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3047: Record is too large..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3047","MS Access error 3047","Record is too large."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64504,"title":"3048 - Can't open any more databases.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3048","Access error 3048","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't open any more databases.","Can't open any more databases."],"errorCode":"3048","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3048: Can't open any more databases.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3048: Can't open any more databases..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3048","MS Access error 3048","Can't open any more databases."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64505,"title":"3049 - '<value>' is corrupted or isn't a Microsoft Access database.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3049","Access error 3049","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","'|' is corrupted or isn't a Microsoft Access database.","'<value>' is corrupted or isn't a Microsoft Access database."],"errorCode":"3049","eventId":"","severity":"High","summary":"Legacy Microsoft Access error 3049: '<value>' is corrupted or isn't a Microsoft Access database.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3049: '<value>' is corrupted or isn't a Microsoft Access database..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3049","MS Access error 3049","'|' is corrupted or isn't a Microsoft Access database."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64506,"title":"3050 - Couldn't lock file; SHARE.EXE hasn't been loaded.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Locking"],"keywords":["3050","Access error 3050","Microsoft Access","MSACCESS","Jet","VBA","Locking","Couldn't lock file; SHARE.EXE hasn't been loaded.","Couldn't lock file; SHARE.EXE hasn't been loaded."],"errorCode":"3050","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3050: Couldn't lock file; SHARE.EXE hasn't been loaded.","rootCause":"The database, page, record, or object is already locked or in use by another session.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Identify active users and the locking object, coordinate closure or retry, verify share permissions and healthy lock-file cleanup, and never delete a lock file while users remain connected.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3050: Couldn't lock file; SHARE.EXE hasn't been loaded..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Locking"],"articleCategories":["Microsoft Access","Legacy Software","Locking"],"aliases":["Microsoft Access 3050","MS Access error 3050","Couldn't lock file; SHARE.EXE hasn't been loaded."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64507,"title":"3051 - Couldn't open file '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["3051","Access error 3051","Microsoft Access","MSACCESS","Jet","VBA","Files","Couldn't open file '|'.","Couldn't open file '<value>'."],"errorCode":"3051","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3051: Couldn't open file '<value>'.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3051: Couldn't open file '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 3051","MS Access error 3051","Couldn't open file '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64508,"title":"3052 - MS-DOS file sharing lock count exceeded.  You need to increase the number of locks installed with SHARE.EXE.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Locking"],"keywords":["3052","Access error 3052","Microsoft Access","MSACCESS","Jet","VBA","Locking","MS-DOS file sharing lock count exceeded.  You need to increase the number of locks installed with SHARE.EXE.","MS-DOS file sharing lock count exceeded.  You need to increase the number of locks installed with SHARE.EXE."],"errorCode":"3052","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3052: MS-DOS file sharing lock count exceeded.  You need to increase the number of locks installed with SHARE.EXE.","rootCause":"The database, page, record, or object is already locked or in use by another session.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Identify active users and the locking object, coordinate closure or retry, verify share permissions and healthy lock-file cleanup, and never delete a lock file while users remain connected.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3052: MS-DOS file sharing lock count exceeded.  You need to increase the number of locks installed with SHARE.EXE..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Locking"],"articleCategories":["Microsoft Access","Legacy Software","Locking"],"aliases":["Microsoft Access 3052","MS Access error 3052","MS-DOS file sharing lock count exceeded.  You need to increase the number of locks installed with SHARE.EXE."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64509,"title":"3053 - Too many client tasks.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3053","Access error 3053","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Too many client tasks.","Too many client tasks."],"errorCode":"3053","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3053: Too many client tasks.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3053: Too many client tasks..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3053","MS Access error 3053","Too many client tasks."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64510,"title":"3054 - Too many Memo or OLE object fields.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3054","Access error 3054","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Too many Memo or OLE object fields.","Too many Memo or OLE object fields."],"errorCode":"3054","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3054: Too many Memo or OLE object fields.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3054: Too many Memo or OLE object fields..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3054","MS Access error 3054","Too many Memo or OLE object fields."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64511,"title":"3055 - Not a valid file name.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["3055","Access error 3055","Microsoft Access","MSACCESS","Jet","VBA","Files","Not a valid file name.","Not a valid file name."],"errorCode":"3055","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3055: Not a valid file name.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3055: Not a valid file name..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 3055","MS Access error 3055","Not a valid file name."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64512,"title":"3056 - Couldn't repair this database.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3056","Access error 3056","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't repair this database.","Couldn't repair this database."],"errorCode":"3056","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3056: Couldn't repair this database.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3056: Couldn't repair this database..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3056","MS Access error 3056","Couldn't repair this database."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64513,"title":"3057 - Operation not supported on attached tables.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3057","Access error 3057","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Operation not supported on attached tables.","Operation not supported on attached tables."],"errorCode":"3057","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3057: Operation not supported on attached tables.","rootCause":"The requested feature or operation is unavailable in this Access/Jet version, object type, driver, or context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the Access, database-engine, file-format, and driver versions; use a supported operation or migrate the workflow before retrying.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3057: Operation not supported on attached tables..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3057","MS Access error 3057","Operation not supported on attached tables."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64514,"title":"3058 - Can't have Null value in index.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3058","Access error 3058","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't have Null value in index.","Can't have Null value in index."],"errorCode":"3058","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3058: Can't have Null value in index.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3058: Can't have Null value in index..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3058","MS Access error 3058","Can't have Null value in index."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64515,"title":"3059 - Operation canceled by user.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3059","Access error 3059","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Operation canceled by user.","Operation canceled by user."],"errorCode":"3059","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3059: Operation canceled by user.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3059: Operation canceled by user..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3059","MS Access error 3059","Operation canceled by user."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64516,"title":"3060 - Wrong data type for parameter '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3060","Access error 3060","Microsoft Access","MSACCESS","Jet","VBA","Queries","Wrong data type for parameter '|'.","Wrong data type for parameter '<value>'."],"errorCode":"3060","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3060: Wrong data type for parameter '<value>'.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3060: Wrong data type for parameter '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3060","MS Access error 3060","Wrong data type for parameter '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64517,"title":"3061 - <value 1> parameters were expected, but only <value 2> were supplied.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3061","Access error 3061","Microsoft Access","MSACCESS","Jet","VBA","Queries","|1 parameters were expected, but only |2 were supplied.","<value 1> parameters were expected, but only <value 2> were supplied."],"errorCode":"3061","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3061: <value 1> parameters were expected, but only <value 2> were supplied.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3061: <value 1> parameters were expected, but only <value 2> were supplied..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3061","MS Access error 3061","|1 parameters were expected, but only |2 were supplied."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64518,"title":"3062 - Duplicate output alias '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3062","Access error 3062","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Duplicate output alias '|'.","Duplicate output alias '<value>'."],"errorCode":"3062","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3062: Duplicate output alias '<value>'.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3062: Duplicate output alias '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3062","MS Access error 3062","Duplicate output alias '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64519,"title":"3063 - Duplicate output destination '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3063","Access error 3063","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Duplicate output destination '|'.","Duplicate output destination '<value>'."],"errorCode":"3063","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3063: Duplicate output destination '<value>'.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3063: Duplicate output destination '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3063","MS Access error 3063","Duplicate output destination '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64520,"title":"3064 - Can't open action query '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3064","Access error 3064","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't open action query '|'.","Can't open action query '<value>'."],"errorCode":"3064","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3064: Can't open action query '<value>'.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3064: Can't open action query '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3064","MS Access error 3064","Can't open action query '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64521,"title":"3065 - Can't execute a non-action query.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3065","Access error 3065","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't execute a non-action query.","Can't execute a non-action query."],"errorCode":"3065","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3065: Can't execute a non-action query.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3065: Can't execute a non-action query..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3065","MS Access error 3065","Can't execute a non-action query."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64522,"title":"3066 - Query must have at least one output field.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3066","Access error 3066","Microsoft Access","MSACCESS","Jet","VBA","Queries","Query must have at least one output field.","Query must have at least one output field."],"errorCode":"3066","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3066: Query must have at least one output field.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3066: Query must have at least one output field..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3066","MS Access error 3066","Query must have at least one output field."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64523,"title":"3067 - Query input must contain at least one table or query.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3067","Access error 3067","Microsoft Access","MSACCESS","Jet","VBA","Queries","Query input must contain at least one table or query.","Query input must contain at least one table or query."],"errorCode":"3067","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3067: Query input must contain at least one table or query.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3067: Query input must contain at least one table or query..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3067","MS Access error 3067","Query input must contain at least one table or query."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64524,"title":"3068 - Not a valid alias name.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3068","Access error 3068","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Not a valid alias name.","Not a valid alias name."],"errorCode":"3068","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3068: Not a valid alias name.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3068: Not a valid alias name..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3068","MS Access error 3068","Not a valid alias name."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64525,"title":"3069 - Can't have action query '<value>' as an input.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3069","Access error 3069","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't have action query '|' as an input.","Can't have action query '<value>' as an input."],"errorCode":"3069","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3069: Can't have action query '<value>' as an input.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3069: Can't have action query '<value>' as an input..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3069","MS Access error 3069","Can't have action query '|' as an input."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64526,"title":"3070 - Can't bind name '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3070","Access error 3070","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't bind name '|'.","Can't bind name '<value>'."],"errorCode":"3070","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3070: Can't bind name '<value>'.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3070: Can't bind name '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3070","MS Access error 3070","Can't bind name '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64527,"title":"3071 - Can't evaluate expression.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3071","Access error 3071","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't evaluate expression.","Can't evaluate expression."],"errorCode":"3071","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3071: Can't evaluate expression.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3071: Can't evaluate expression..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3071","MS Access error 3071","Can't evaluate expression."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64528,"title":"3073 - Operation must use an updatable query.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3073","Access error 3073","Microsoft Access","MSACCESS","Jet","VBA","Queries","Operation must use an updatable query.","Operation must use an updatable query."],"errorCode":"3073","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3073: Operation must use an updatable query.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3073: Operation must use an updatable query..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3073","MS Access error 3073","Operation must use an updatable query."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64529,"title":"3074 - Can't repeat table name '<value>' in FROM clause.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3074","Access error 3074","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't repeat table name '|' in FROM clause.","Can't repeat table name '<value>' in FROM clause."],"errorCode":"3074","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3074: Can't repeat table name '<value>' in FROM clause.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3074: Can't repeat table name '<value>' in FROM clause..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3074","MS Access error 3074","Can't repeat table name '|' in FROM clause."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64530,"title":"3075 - <value 1> in query expression '<value 2>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3075","Access error 3075","Microsoft Access","MSACCESS","Jet","VBA","Queries","|1 in query expression '|2'.","<value 1> in query expression '<value 2>'."],"errorCode":"3075","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3075: <value 1> in query expression '<value 2>'.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3075: <value 1> in query expression '<value 2>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3075","MS Access error 3075","|1 in query expression '|2'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64531,"title":"3076 - <value> in criteria expression.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3076","Access error 3076","Microsoft Access","MSACCESS","Jet","VBA","Queries","| in criteria expression.","<value> in criteria expression."],"errorCode":"3076","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3076: <value> in criteria expression.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3076: <value> in criteria expression..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3076","MS Access error 3076","| in criteria expression."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64532,"title":"3077 - <value> in expression.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3077","Access error 3077","Microsoft Access","MSACCESS","Jet","VBA","Queries","| in expression.","<value> in expression."],"errorCode":"3077","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3077: <value> in expression.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3077: <value> in expression..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3077","MS Access error 3077","| in expression."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64533,"title":"3078 - Couldn't find input table or query '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3078","Access error 3078","Microsoft Access","MSACCESS","Jet","VBA","Queries","Couldn't find input table or query '|'.","Couldn't find input table or query '<value>'."],"errorCode":"3078","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3078: Couldn't find input table or query '<value>'.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3078: Couldn't find input table or query '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3078","MS Access error 3078","Couldn't find input table or query '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64534,"title":"3079 - Ambiguous field reference '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3079","Access error 3079","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Ambiguous field reference '|'.","Ambiguous field reference '<value>'."],"errorCode":"3079","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3079: Ambiguous field reference '<value>'.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3079: Ambiguous field reference '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3079","MS Access error 3079","Ambiguous field reference '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64535,"title":"3080 - Joined table '<value>' not listed in FROM clause.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3080","Access error 3080","Microsoft Access","MSACCESS","Jet","VBA","Queries","Joined table '|' not listed in FROM clause.","Joined table '<value>' not listed in FROM clause."],"errorCode":"3080","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3080: Joined table '<value>' not listed in FROM clause.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3080: Joined table '<value>' not listed in FROM clause..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3080","MS Access error 3080","Joined table '|' not listed in FROM clause."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64536,"title":"3081 - Can't join more than one table with the same name (<value>).","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3081","Access error 3081","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't join more than one table with the same name (|).","Can't join more than one table with the same name (<value>)."],"errorCode":"3081","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3081: Can't join more than one table with the same name (<value>).","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3081: Can't join more than one table with the same name (<value>)..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3081","MS Access error 3081","Can't join more than one table with the same name (|)."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64537,"title":"3082 - JOIN operation '<value>' refers to a non-joined table.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3082","Access error 3082","Microsoft Access","MSACCESS","Jet","VBA","Queries","JOIN operation '|' refers to a non-joined table.","JOIN operation '<value>' refers to a non-joined table."],"errorCode":"3082","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3082: JOIN operation '<value>' refers to a non-joined table.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3082: JOIN operation '<value>' refers to a non-joined table..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3082","MS Access error 3082","JOIN operation '|' refers to a non-joined table."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64538,"title":"3083 - Can't use internal report query.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3083","Access error 3083","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't use internal report query.","Can't use internal report query."],"errorCode":"3083","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3083: Can't use internal report query.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3083: Can't use internal report query..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3083","MS Access error 3083","Can't use internal report query."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64539,"title":"3084 - Can't insert into action query.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3084","Access error 3084","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't insert into action query.","Can't insert into action query."],"errorCode":"3084","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3084: Can't insert into action query.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3084: Can't insert into action query..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3084","MS Access error 3084","Can't insert into action query."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64540,"title":"3085 - Undefined function '<value>' in expression.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3085","Access error 3085","Microsoft Access","MSACCESS","Jet","VBA","Queries","Undefined function '|' in expression.","Undefined function '<value>' in expression."],"errorCode":"3085","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3085: Undefined function '<value>' in expression.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3085: Undefined function '<value>' in expression..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3085","MS Access error 3085","Undefined function '|' in expression."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64541,"title":"3086 - Couldn't delete from specified tables.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3086","Access error 3086","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't delete from specified tables.","Couldn't delete from specified tables."],"errorCode":"3086","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3086: Couldn't delete from specified tables.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3086: Couldn't delete from specified tables..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3086","MS Access error 3086","Couldn't delete from specified tables."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64542,"title":"3087 - Too many expressions in GROUP BY clause.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3087","Access error 3087","Microsoft Access","MSACCESS","Jet","VBA","Queries","Too many expressions in GROUP BY clause.","Too many expressions in GROUP BY clause."],"errorCode":"3087","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3087: Too many expressions in GROUP BY clause.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3087: Too many expressions in GROUP BY clause..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3087","MS Access error 3087","Too many expressions in GROUP BY clause."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64543,"title":"3088 - Too many expressions in ORDER BY clause.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3088","Access error 3088","Microsoft Access","MSACCESS","Jet","VBA","Queries","Too many expressions in ORDER BY clause.","Too many expressions in ORDER BY clause."],"errorCode":"3088","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3088: Too many expressions in ORDER BY clause.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3088: Too many expressions in ORDER BY clause..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3088","MS Access error 3088","Too many expressions in ORDER BY clause."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64544,"title":"3089 - Too many expressions in DISTINCT output.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3089","Access error 3089","Microsoft Access","MSACCESS","Jet","VBA","Queries","Too many expressions in DISTINCT output.","Too many expressions in DISTINCT output."],"errorCode":"3089","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3089: Too many expressions in DISTINCT output.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3089: Too many expressions in DISTINCT output..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3089","MS Access error 3089","Too many expressions in DISTINCT output."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64545,"title":"3090 - Resultant table may not have more than one Counter field.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3090","Access error 3090","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Resultant table may not have more than one Counter field.","Resultant table may not have more than one Counter field."],"errorCode":"3090","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3090: Resultant table may not have more than one Counter field.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3090: Resultant table may not have more than one Counter field..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3090","MS Access error 3090","Resultant table may not have more than one Counter field."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64546,"title":"3091 - HAVING clause (<value>) without grouping or aggregation.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3091","Access error 3091","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","HAVING clause (|) without grouping or aggregation.","HAVING clause (<value>) without grouping or aggregation."],"errorCode":"3091","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3091: HAVING clause (<value>) without grouping or aggregation.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3091: HAVING clause (<value>) without grouping or aggregation..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3091","MS Access error 3091","HAVING clause (|) without grouping or aggregation."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64547,"title":"3092 - Can't use HAVING clause in TRANSFORM statement.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["3092","Access error 3092","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Can't use HAVING clause in TRANSFORM statement.","Can't use HAVING clause in TRANSFORM statement."],"errorCode":"3092","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3092: Can't use HAVING clause in TRANSFORM statement.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3092: Can't use HAVING clause in TRANSFORM statement..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 3092","MS Access error 3092","Can't use HAVING clause in TRANSFORM statement."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64548,"title":"3093 - ORDER BY clause (<value>) conflicts with DISTINCT.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3093","Access error 3093","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","ORDER BY clause (|) conflicts with DISTINCT.","ORDER BY clause (<value>) conflicts with DISTINCT."],"errorCode":"3093","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3093: ORDER BY clause (<value>) conflicts with DISTINCT.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3093: ORDER BY clause (<value>) conflicts with DISTINCT..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3093","MS Access error 3093","ORDER BY clause (|) conflicts with DISTINCT."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64549,"title":"3094 - ORDER BY clause (<value>) conflicts with GROUP BY clause.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3094","Access error 3094","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","ORDER BY clause (|) conflicts with GROUP BY clause.","ORDER BY clause (<value>) conflicts with GROUP BY clause."],"errorCode":"3094","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3094: ORDER BY clause (<value>) conflicts with GROUP BY clause.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3094: ORDER BY clause (<value>) conflicts with GROUP BY clause..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3094","MS Access error 3094","ORDER BY clause (|) conflicts with GROUP BY clause."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64550,"title":"3095 - Can't have aggregate function in expression (<value>).","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3095","Access error 3095","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't have aggregate function in expression (|).","Can't have aggregate function in expression (<value>)."],"errorCode":"3095","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3095: Can't have aggregate function in expression (<value>).","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3095: Can't have aggregate function in expression (<value>)..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3095","MS Access error 3095","Can't have aggregate function in expression (|)."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64551,"title":"3096 - Can't have aggregate function in WHERE clause (<value>).","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3096","Access error 3096","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't have aggregate function in WHERE clause (|).","Can't have aggregate function in WHERE clause (<value>)."],"errorCode":"3096","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3096: Can't have aggregate function in WHERE clause (<value>).","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3096: Can't have aggregate function in WHERE clause (<value>)..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3096","MS Access error 3096","Can't have aggregate function in WHERE clause (|)."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64552,"title":"3097 - Can't have aggregate function in ORDER BY clause (<value>).","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3097","Access error 3097","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't have aggregate function in ORDER BY clause (|).","Can't have aggregate function in ORDER BY clause (<value>)."],"errorCode":"3097","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3097: Can't have aggregate function in ORDER BY clause (<value>).","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3097: Can't have aggregate function in ORDER BY clause (<value>)..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3097","MS Access error 3097","Can't have aggregate function in ORDER BY clause (|)."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64553,"title":"3098 - Can't have aggregate function in GROUP BY clause (<value>).","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3098","Access error 3098","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't have aggregate function in GROUP BY clause (|).","Can't have aggregate function in GROUP BY clause (<value>)."],"errorCode":"3098","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3098: Can't have aggregate function in GROUP BY clause (<value>).","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3098: Can't have aggregate function in GROUP BY clause (<value>)..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3098","MS Access error 3098","Can't have aggregate function in GROUP BY clause (|)."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64554,"title":"3099 - Can't have aggregate function in JOIN operation (<value>).","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3099","Access error 3099","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't have aggregate function in JOIN operation (|).","Can't have aggregate function in JOIN operation (<value>)."],"errorCode":"3099","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3099: Can't have aggregate function in JOIN operation (<value>).","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3099: Can't have aggregate function in JOIN operation (<value>)..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3099","MS Access error 3099","Can't have aggregate function in JOIN operation (|)."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64555,"title":"3100 - Can't set field '<value>' in join key to Null.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3100","Access error 3100","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't set field '|' in join key to Null.","Can't set field '<value>' in join key to Null."],"errorCode":"3100","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3100: Can't set field '<value>' in join key to Null.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3100: Can't set field '<value>' in join key to Null..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3100","MS Access error 3100","Can't set field '|' in join key to Null."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64556,"title":"3101 - Join is broken by value(s) in fields '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3101","Access error 3101","Microsoft Access","MSACCESS","Jet","VBA","Queries","Join is broken by value(s) in fields '|'.","Join is broken by value(s) in fields '<value>'."],"errorCode":"3101","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3101: Join is broken by value(s) in fields '<value>'.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3101: Join is broken by value(s) in fields '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3101","MS Access error 3101","Join is broken by value(s) in fields '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64557,"title":"3102 - Circular reference caused by '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3102","Access error 3102","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Circular reference caused by '|'.","Circular reference caused by '<value>'."],"errorCode":"3102","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3102: Circular reference caused by '<value>'.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3102: Circular reference caused by '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3102","MS Access error 3102","Circular reference caused by '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64558,"title":"3103 - Circular reference caused by alias '<value>' in query definition's SELECT list.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3103","Access error 3103","Microsoft Access","MSACCESS","Jet","VBA","Queries","Circular reference caused by alias '|' in query definition's SELECT list.","Circular reference caused by alias '<value>' in query definition's SELECT list."],"errorCode":"3103","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3103: Circular reference caused by alias '<value>' in query definition's SELECT list.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3103: Circular reference caused by alias '<value>' in query definition's SELECT list..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3103","MS Access error 3103","Circular reference caused by alias '|' in query definition's SELECT list."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64559,"title":"3104 - Can't specify Fixed Column Heading '<value>' in a crosstab query more than once.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3104","Access error 3104","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't specify Fixed Column Heading '|' in a crosstab query more than once.","Can't specify Fixed Column Heading '<value>' in a crosstab query more than once."],"errorCode":"3104","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3104: Can't specify Fixed Column Heading '<value>' in a crosstab query more than once.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3104: Can't specify Fixed Column Heading '<value>' in a crosstab query more than once..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3104","MS Access error 3104","Can't specify Fixed Column Heading '|' in a crosstab query more than once."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64560,"title":"3105 - Missing destination field name in SELECT INTO statement (<value>).","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3105","Access error 3105","Microsoft Access","MSACCESS","Jet","VBA","Queries","Missing destination field name in SELECT INTO statement (|).","Missing destination field name in SELECT INTO statement (<value>)."],"errorCode":"3105","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3105: Missing destination field name in SELECT INTO statement (<value>).","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3105: Missing destination field name in SELECT INTO statement (<value>)..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3105","MS Access error 3105","Missing destination field name in SELECT INTO statement (|)."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64561,"title":"3106 - Missing destination field name in UPDATE statement (<value>).","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3106","Access error 3106","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Missing destination field name in UPDATE statement (|).","Missing destination field name in UPDATE statement (<value>)."],"errorCode":"3106","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3106: Missing destination field name in UPDATE statement (<value>).","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3106: Missing destination field name in UPDATE statement (<value>)..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3106","MS Access error 3106","Missing destination field name in UPDATE statement (|)."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64562,"title":"3107 - Couldn't insert; no insert permission for table or query '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3107","Access error 3107","Microsoft Access","MSACCESS","Jet","VBA","Queries","Couldn't insert; no insert permission for table or query '|'.","Couldn't insert; no insert permission for table or query '<value>'."],"errorCode":"3107","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3107: Couldn't insert; no insert permission for table or query '<value>'.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3107: Couldn't insert; no insert permission for table or query '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3107","MS Access error 3107","Couldn't insert; no insert permission for table or query '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64563,"title":"3108 - Couldn't replace; no replace permission for table or query '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3108","Access error 3108","Microsoft Access","MSACCESS","Jet","VBA","Queries","Couldn't replace; no replace permission for table or query '|'.","Couldn't replace; no replace permission for table or query '<value>'."],"errorCode":"3108","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3108: Couldn't replace; no replace permission for table or query '<value>'.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3108: Couldn't replace; no replace permission for table or query '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3108","MS Access error 3108","Couldn't replace; no replace permission for table or query '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64564,"title":"3109 - Couldn't delete; no delete permission for table or query '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3109","Access error 3109","Microsoft Access","MSACCESS","Jet","VBA","Queries","Couldn't delete; no delete permission for table or query '|'.","Couldn't delete; no delete permission for table or query '<value>'."],"errorCode":"3109","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3109: Couldn't delete; no delete permission for table or query '<value>'.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3109: Couldn't delete; no delete permission for table or query '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3109","MS Access error 3109","Couldn't delete; no delete permission for table or query '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64565,"title":"3110 - Couldn't read definitions; no read definitions permission for table or query '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3110","Access error 3110","Microsoft Access","MSACCESS","Jet","VBA","Queries","Couldn't read definitions; no read definitions permission for table or query '|'.","Couldn't read definitions; no read definitions permission for table or query '<value>'."],"errorCode":"3110","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3110: Couldn't read definitions; no read definitions permission for table or query '<value>'.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3110: Couldn't read definitions; no read definitions permission for table or query '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3110","MS Access error 3110","Couldn't read definitions; no read definitions permission for table or query '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64566,"title":"3111 - Couldn't create; no create permission for table or query '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3111","Access error 3111","Microsoft Access","MSACCESS","Jet","VBA","Queries","Couldn't create; no create permission for table or query '|'.","Couldn't create; no create permission for table or query '<value>'."],"errorCode":"3111","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3111: Couldn't create; no create permission for table or query '<value>'.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3111: Couldn't create; no create permission for table or query '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3111","MS Access error 3111","Couldn't create; no create permission for table or query '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64567,"title":"3112 - Couldn't read; no read permission for table or query '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3112","Access error 3112","Microsoft Access","MSACCESS","Jet","VBA","Queries","Couldn't read; no read permission for table or query '|'.","Couldn't read; no read permission for table or query '<value>'."],"errorCode":"3112","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3112: Couldn't read; no read permission for table or query '<value>'.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3112: Couldn't read; no read permission for table or query '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3112","MS Access error 3112","Couldn't read; no read permission for table or query '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64568,"title":"3113 - Can't update '<value>'; field not updatable.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3113","Access error 3113","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't update '|'; field not updatable.","Can't update '<value>'; field not updatable."],"errorCode":"3113","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3113: Can't update '<value>'; field not updatable.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3113: Can't update '<value>'; field not updatable..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3113","MS Access error 3113","Can't update '|'; field not updatable."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64569,"title":"3114 - Can't include Memo or OLE object when you select unique values (<value>).","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3114","Access error 3114","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't include Memo or OLE object when you select unique values (|).","Can't include Memo or OLE object when you select unique values (<value>)."],"errorCode":"3114","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3114: Can't include Memo or OLE object when you select unique values (<value>).","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3114: Can't include Memo or OLE object when you select unique values (<value>)..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3114","MS Access error 3114","Can't include Memo or OLE object when you select unique values (|)."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64570,"title":"3115 - Can't have Memo or OLE object in aggregate argument (<value>).","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3115","Access error 3115","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't have Memo or OLE object in aggregate argument (|).","Can't have Memo or OLE object in aggregate argument (<value>)."],"errorCode":"3115","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3115: Can't have Memo or OLE object in aggregate argument (<value>).","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3115: Can't have Memo or OLE object in aggregate argument (<value>)..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3115","MS Access error 3115","Can't have Memo or OLE object in aggregate argument (|)."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64571,"title":"3116 - Can't have Memo or OLE object in criteria (<value>) for aggregate function.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3116","Access error 3116","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't have Memo or OLE object in criteria (|) for aggregate function.","Can't have Memo or OLE object in criteria (<value>) for aggregate function."],"errorCode":"3116","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3116: Can't have Memo or OLE object in criteria (<value>) for aggregate function.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3116: Can't have Memo or OLE object in criteria (<value>) for aggregate function..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3116","MS Access error 3116","Can't have Memo or OLE object in criteria (|) for aggregate function."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64572,"title":"3117 - Can't sort on Memo or OLE object (<value>).","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3117","Access error 3117","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't sort on Memo or OLE object (|).","Can't sort on Memo or OLE object (<value>)."],"errorCode":"3117","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3117: Can't sort on Memo or OLE object (<value>).","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3117: Can't sort on Memo or OLE object (<value>)..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3117","MS Access error 3117","Can't sort on Memo or OLE object (|)."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64573,"title":"3118 - Can't join on Memo or OLE object (<value>).","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3118","Access error 3118","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't join on Memo or OLE object (|).","Can't join on Memo or OLE object (<value>)."],"errorCode":"3118","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3118: Can't join on Memo or OLE object (<value>).","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3118: Can't join on Memo or OLE object (<value>)..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3118","MS Access error 3118","Can't join on Memo or OLE object (|)."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64574,"title":"3119 - Can't group on Memo or OLE object (<value>).","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3119","Access error 3119","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Can't group on Memo or OLE object (|).","Can't group on Memo or OLE object (<value>)."],"errorCode":"3119","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3119: Can't group on Memo or OLE object (<value>).","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3119: Can't group on Memo or OLE object (<value>)..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3119","MS Access error 3119","Can't group on Memo or OLE object (|)."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64575,"title":"3120 - Can't group on fields selected with '*' (<value>).","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3120","Access error 3120","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't group on fields selected with '*' (|).","Can't group on fields selected with '*' (<value>)."],"errorCode":"3120","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3120: Can't group on fields selected with '*' (<value>).","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3120: Can't group on fields selected with '*' (<value>)..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3120","MS Access error 3120","Can't group on fields selected with '*' (|)."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64576,"title":"3121 - Can't group on fields selected with '*'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3121","Access error 3121","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't group on fields selected with '*'.","Can't group on fields selected with '*'."],"errorCode":"3121","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3121: Can't group on fields selected with '*'.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3121: Can't group on fields selected with '*'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3121","MS Access error 3121","Can't group on fields selected with '*'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64577,"title":"3122 - '<value>' not part of aggregate function or grouping.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3122","Access error 3122","Microsoft Access","MSACCESS","Jet","VBA","Queries","'|' not part of aggregate function or grouping.","'<value>' not part of aggregate function or grouping."],"errorCode":"3122","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3122: '<value>' not part of aggregate function or grouping.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3122: '<value>' not part of aggregate function or grouping..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3122","MS Access error 3122","'|' not part of aggregate function or grouping."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64578,"title":"3123 - Can't use '*' in crosstab query.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3123","Access error 3123","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't use '*' in crosstab query.","Can't use '*' in crosstab query."],"errorCode":"3123","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3123: Can't use '*' in crosstab query.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3123: Can't use '*' in crosstab query..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3123","MS Access error 3123","Can't use '*' in crosstab query."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64579,"title":"3124 - Can't input from internal report query (<value>).","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3124","Access error 3124","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't input from internal report query (|).","Can't input from internal report query (<value>)."],"errorCode":"3124","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3124: Can't input from internal report query (<value>).","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3124: Can't input from internal report query (<value>)..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3124","MS Access error 3124","Can't input from internal report query (|)."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64580,"title":"3125 - '<value>' isn't a valid name.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3125","Access error 3125","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","'|' isn't a valid name.","'<value>' isn't a valid name."],"errorCode":"3125","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3125: '<value>' isn't a valid name.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3125: '<value>' isn't a valid name..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3125","MS Access error 3125","'|' isn't a valid name."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64581,"title":"3126 - Invalid bracketing of name '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3126","Access error 3126","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Invalid bracketing of name '|'.","Invalid bracketing of name '<value>'."],"errorCode":"3126","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3126: Invalid bracketing of name '<value>'.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3126: Invalid bracketing of name '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3126","MS Access error 3126","Invalid bracketing of name '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64582,"title":"3127 - INSERT INTO statement contains unknown field name '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3127","Access error 3127","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","INSERT INTO statement contains unknown field name '|'.","INSERT INTO statement contains unknown field name '<value>'."],"errorCode":"3127","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3127: INSERT INTO statement contains unknown field name '<value>'.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3127: INSERT INTO statement contains unknown field name '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3127","MS Access error 3127","INSERT INTO statement contains unknown field name '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64583,"title":"3128 - Must specify tables to delete from.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3128","Access error 3128","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Must specify tables to delete from.","Must specify tables to delete from."],"errorCode":"3128","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3128: Must specify tables to delete from.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3128: Must specify tables to delete from..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3128","MS Access error 3128","Must specify tables to delete from."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64584,"title":"3129 - Invalid SQL statement; expected 'DELETE', 'INSERT', 'PROCEDURE', 'SELECT', or 'UPDATE'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3129","Access error 3129","Microsoft Access","MSACCESS","Jet","VBA","Queries","Invalid SQL statement; expected 'DELETE', 'INSERT', 'PROCEDURE', 'SELECT', or 'UPDATE'.","Invalid SQL statement; expected 'DELETE', 'INSERT', 'PROCEDURE', 'SELECT', or 'UPDATE'."],"errorCode":"3129","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3129: Invalid SQL statement; expected 'DELETE', 'INSERT', 'PROCEDURE', 'SELECT', or 'UPDATE'.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3129: Invalid SQL statement; expected 'DELETE', 'INSERT', 'PROCEDURE', 'SELECT', or 'UPDATE'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3129","MS Access error 3129","Invalid SQL statement; expected 'DELETE', 'INSERT', 'PROCEDURE', 'SELECT', or 'UPDATE'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64585,"title":"3130 - Syntax error in DELETE statement.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3130","Access error 3130","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Syntax error in DELETE statement.","Syntax error in DELETE statement."],"errorCode":"3130","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3130: Syntax error in DELETE statement.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3130: Syntax error in DELETE statement..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3130","MS Access error 3130","Syntax error in DELETE statement."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64586,"title":"3131 - Syntax error in FROM clause.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3131","Access error 3131","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Syntax error in FROM clause.","Syntax error in FROM clause."],"errorCode":"3131","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3131: Syntax error in FROM clause.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3131: Syntax error in FROM clause..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3131","MS Access error 3131","Syntax error in FROM clause."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64587,"title":"3132 - Syntax error in GROUP BY clause.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3132","Access error 3132","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Syntax error in GROUP BY clause.","Syntax error in GROUP BY clause."],"errorCode":"3132","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3132: Syntax error in GROUP BY clause.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3132: Syntax error in GROUP BY clause..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3132","MS Access error 3132","Syntax error in GROUP BY clause."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64588,"title":"3133 - Syntax error in HAVING clause.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3133","Access error 3133","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Syntax error in HAVING clause.","Syntax error in HAVING clause."],"errorCode":"3133","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3133: Syntax error in HAVING clause.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3133: Syntax error in HAVING clause..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3133","MS Access error 3133","Syntax error in HAVING clause."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64589,"title":"3134 - Syntax error in INSERT statement.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3134","Access error 3134","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Syntax error in INSERT statement.","Syntax error in INSERT statement."],"errorCode":"3134","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3134: Syntax error in INSERT statement.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3134: Syntax error in INSERT statement..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3134","MS Access error 3134","Syntax error in INSERT statement."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64590,"title":"3135 - Syntax error in JOIN operation.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3135","Access error 3135","Microsoft Access","MSACCESS","Jet","VBA","Queries","Syntax error in JOIN operation.","Syntax error in JOIN operation."],"errorCode":"3135","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3135: Syntax error in JOIN operation.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3135: Syntax error in JOIN operation..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3135","MS Access error 3135","Syntax error in JOIN operation."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64591,"title":"3136 - Syntax error in LEVEL clause.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3136","Access error 3136","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Syntax error in LEVEL clause.","Syntax error in LEVEL clause."],"errorCode":"3136","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3136: Syntax error in LEVEL clause.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3136: Syntax error in LEVEL clause..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3136","MS Access error 3136","Syntax error in LEVEL clause."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64592,"title":"3137 - Missing semicolon (;) at end of SQL statement.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3137","Access error 3137","Microsoft Access","MSACCESS","Jet","VBA","Queries","Missing semicolon (;) at end of SQL statement.","Missing semicolon (;) at end of SQL statement."],"errorCode":"3137","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3137: Missing semicolon (;) at end of SQL statement.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3137: Missing semicolon (;) at end of SQL statement..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3137","MS Access error 3137","Missing semicolon (;) at end of SQL statement."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64593,"title":"3138 - Syntax error in ORDER BY clause.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3138","Access error 3138","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Syntax error in ORDER BY clause.","Syntax error in ORDER BY clause."],"errorCode":"3138","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3138: Syntax error in ORDER BY clause.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3138: Syntax error in ORDER BY clause..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3138","MS Access error 3138","Syntax error in ORDER BY clause."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64594,"title":"3139 - Syntax error in PARAMETER clause.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3139","Access error 3139","Microsoft Access","MSACCESS","Jet","VBA","Queries","Syntax error in PARAMETER clause.","Syntax error in PARAMETER clause."],"errorCode":"3139","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3139: Syntax error in PARAMETER clause.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3139: Syntax error in PARAMETER clause..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3139","MS Access error 3139","Syntax error in PARAMETER clause."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64595,"title":"3140 - Syntax error in PROCEDURE clause.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3140","Access error 3140","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Syntax error in PROCEDURE clause.","Syntax error in PROCEDURE clause."],"errorCode":"3140","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3140: Syntax error in PROCEDURE clause.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3140: Syntax error in PROCEDURE clause..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3140","MS Access error 3140","Syntax error in PROCEDURE clause."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64596,"title":"3141 - Syntax error in SELECT statement.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3141","Access error 3141","Microsoft Access","MSACCESS","Jet","VBA","Queries","Syntax error in SELECT statement.","Syntax error in SELECT statement."],"errorCode":"3141","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3141: Syntax error in SELECT statement.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3141: Syntax error in SELECT statement..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3141","MS Access error 3141","Syntax error in SELECT statement."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64597,"title":"3142 - Characters found after end of SQL statement.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3142","Access error 3142","Microsoft Access","MSACCESS","Jet","VBA","Queries","Characters found after end of SQL statement.","Characters found after end of SQL statement."],"errorCode":"3142","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3142: Characters found after end of SQL statement.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3142: Characters found after end of SQL statement..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3142","MS Access error 3142","Characters found after end of SQL statement."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64598,"title":"3143 - Syntax error in TRANSFORM statement.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["3143","Access error 3143","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Syntax error in TRANSFORM statement.","Syntax error in TRANSFORM statement."],"errorCode":"3143","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3143: Syntax error in TRANSFORM statement.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3143: Syntax error in TRANSFORM statement..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 3143","MS Access error 3143","Syntax error in TRANSFORM statement."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64599,"title":"3144 - Syntax error in UPDATE statement.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3144","Access error 3144","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Syntax error in UPDATE statement.","Syntax error in UPDATE statement."],"errorCode":"3144","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3144: Syntax error in UPDATE statement.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3144: Syntax error in UPDATE statement..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3144","MS Access error 3144","Syntax error in UPDATE statement."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64600,"title":"3145 - Syntax error in WHERE clause.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3145","Access error 3145","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Syntax error in WHERE clause.","Syntax error in WHERE clause."],"errorCode":"3145","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3145: Syntax error in WHERE clause.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3145: Syntax error in WHERE clause..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3145","MS Access error 3145","Syntax error in WHERE clause."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64601,"title":"3146 - ODBC--call failed.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","ODBC"],"keywords":["3146","Access error 3146","Microsoft Access","MSACCESS","Jet","VBA","ODBC","ODBC--call failed.","ODBC--call failed."],"errorCode":"3146","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3146: ODBC--call failed.","rootCause":"The Access/Jet ODBC layer, driver, data source, server, query, data type, or connection state rejected the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Capture the native ODBC error, verify DSN/connection settings, driver architecture and version, credentials, server reachability, schema and data types, then reproduce with the smallest safe query.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3146: ODBC--call failed..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","ODBC"],"articleCategories":["Microsoft Access","Legacy Software","ODBC"],"aliases":["Microsoft Access 3146","MS Access error 3146","ODBC--call failed."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64602,"title":"3147 - ODBC--data buffer overflow.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","ODBC"],"keywords":["3147","Access error 3147","Microsoft Access","MSACCESS","Jet","VBA","ODBC","ODBC--data buffer overflow.","ODBC--data buffer overflow."],"errorCode":"3147","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3147: ODBC--data buffer overflow.","rootCause":"The Access/Jet ODBC layer, driver, data source, server, query, data type, or connection state rejected the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Capture the native ODBC error, verify DSN/connection settings, driver architecture and version, credentials, server reachability, schema and data types, then reproduce with the smallest safe query.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3147: ODBC--data buffer overflow..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","ODBC"],"articleCategories":["Microsoft Access","Legacy Software","ODBC"],"aliases":["Microsoft Access 3147","MS Access error 3147","ODBC--data buffer overflow."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64603,"title":"3148 - ODBC--connection failed.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","ODBC"],"keywords":["3148","Access error 3148","Microsoft Access","MSACCESS","Jet","VBA","ODBC","ODBC--connection failed.","ODBC--connection failed."],"errorCode":"3148","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3148: ODBC--connection failed.","rootCause":"The Access/Jet ODBC layer, driver, data source, server, query, data type, or connection state rejected the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Capture the native ODBC error, verify DSN/connection settings, driver architecture and version, credentials, server reachability, schema and data types, then reproduce with the smallest safe query.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3148: ODBC--connection failed..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","ODBC"],"articleCategories":["Microsoft Access","Legacy Software","ODBC"],"aliases":["Microsoft Access 3148","MS Access error 3148","ODBC--connection failed."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64604,"title":"3149 - ODBC--incorrect DLL.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","ODBC"],"keywords":["3149","Access error 3149","Microsoft Access","MSACCESS","Jet","VBA","ODBC","ODBC--incorrect DLL.","ODBC--incorrect DLL."],"errorCode":"3149","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3149: ODBC--incorrect DLL.","rootCause":"The Access/Jet ODBC layer, driver, data source, server, query, data type, or connection state rejected the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Capture the native ODBC error, verify DSN/connection settings, driver architecture and version, credentials, server reachability, schema and data types, then reproduce with the smallest safe query.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3149: ODBC--incorrect DLL..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","ODBC"],"articleCategories":["Microsoft Access","Legacy Software","ODBC"],"aliases":["Microsoft Access 3149","MS Access error 3149","ODBC--incorrect DLL."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64605,"title":"3150 - ODBC--missing DLL.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","ODBC"],"keywords":["3150","Access error 3150","Microsoft Access","MSACCESS","Jet","VBA","ODBC","ODBC--missing DLL.","ODBC--missing DLL."],"errorCode":"3150","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3150: ODBC--missing DLL.","rootCause":"The Access/Jet ODBC layer, driver, data source, server, query, data type, or connection state rejected the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Capture the native ODBC error, verify DSN/connection settings, driver architecture and version, credentials, server reachability, schema and data types, then reproduce with the smallest safe query.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3150: ODBC--missing DLL..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","ODBC"],"articleCategories":["Microsoft Access","Legacy Software","ODBC"],"aliases":["Microsoft Access 3150","MS Access error 3150","ODBC--missing DLL."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64606,"title":"3151 - ODBC--connection to '<value>' failed.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","ODBC"],"keywords":["3151","Access error 3151","Microsoft Access","MSACCESS","Jet","VBA","ODBC","ODBC--connection to '|' failed.","ODBC--connection to '<value>' failed."],"errorCode":"3151","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3151: ODBC--connection to '<value>' failed.","rootCause":"The Access/Jet ODBC layer, driver, data source, server, query, data type, or connection state rejected the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Capture the native ODBC error, verify DSN/connection settings, driver architecture and version, credentials, server reachability, schema and data types, then reproduce with the smallest safe query.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3151: ODBC--connection to '<value>' failed..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","ODBC"],"articleCategories":["Microsoft Access","Legacy Software","ODBC"],"aliases":["Microsoft Access 3151","MS Access error 3151","ODBC--connection to '|' failed."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64607,"title":"3152 - ODBC--incorrect driver version '<value 1>'; expected version '<value 2>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","ODBC"],"keywords":["3152","Access error 3152","Microsoft Access","MSACCESS","Jet","VBA","ODBC","ODBC--incorrect driver version '|1'; expected version '|2'.","ODBC--incorrect driver version '<value 1>'; expected version '<value 2>'."],"errorCode":"3152","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3152: ODBC--incorrect driver version '<value 1>'; expected version '<value 2>'.","rootCause":"The Access/Jet ODBC layer, driver, data source, server, query, data type, or connection state rejected the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Capture the native ODBC error, verify DSN/connection settings, driver architecture and version, credentials, server reachability, schema and data types, then reproduce with the smallest safe query.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3152: ODBC--incorrect driver version '<value 1>'; expected version '<value 2>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","ODBC"],"articleCategories":["Microsoft Access","Legacy Software","ODBC"],"aliases":["Microsoft Access 3152","MS Access error 3152","ODBC--incorrect driver version '|1'; expected version '|2'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64608,"title":"3153 - ODBC--incorrect server version '<value 1>'; expected version '<value 2>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","ODBC"],"keywords":["3153","Access error 3153","Microsoft Access","MSACCESS","Jet","VBA","ODBC","ODBC--incorrect server version '|1'; expected version '|2'.","ODBC--incorrect server version '<value 1>'; expected version '<value 2>'."],"errorCode":"3153","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3153: ODBC--incorrect server version '<value 1>'; expected version '<value 2>'.","rootCause":"The Access/Jet ODBC layer, driver, data source, server, query, data type, or connection state rejected the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Capture the native ODBC error, verify DSN/connection settings, driver architecture and version, credentials, server reachability, schema and data types, then reproduce with the smallest safe query.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3153: ODBC--incorrect server version '<value 1>'; expected version '<value 2>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","ODBC"],"articleCategories":["Microsoft Access","Legacy Software","ODBC"],"aliases":["Microsoft Access 3153","MS Access error 3153","ODBC--incorrect server version '|1'; expected version '|2'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64609,"title":"3154 - ODBC--couldn't find DLL '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","ODBC"],"keywords":["3154","Access error 3154","Microsoft Access","MSACCESS","Jet","VBA","ODBC","ODBC--couldn't find DLL '|'.","ODBC--couldn't find DLL '<value>'."],"errorCode":"3154","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3154: ODBC--couldn't find DLL '<value>'.","rootCause":"The Access/Jet ODBC layer, driver, data source, server, query, data type, or connection state rejected the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Capture the native ODBC error, verify DSN/connection settings, driver architecture and version, credentials, server reachability, schema and data types, then reproduce with the smallest safe query.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3154: ODBC--couldn't find DLL '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","ODBC"],"articleCategories":["Microsoft Access","Legacy Software","ODBC"],"aliases":["Microsoft Access 3154","MS Access error 3154","ODBC--couldn't find DLL '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64610,"title":"3155 - ODBC--insert failed.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","ODBC"],"keywords":["3155","Access error 3155","Microsoft Access","MSACCESS","Jet","VBA","ODBC","ODBC--insert failed.","ODBC--insert failed."],"errorCode":"3155","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3155: ODBC--insert failed.","rootCause":"The Access/Jet ODBC layer, driver, data source, server, query, data type, or connection state rejected the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Capture the native ODBC error, verify DSN/connection settings, driver architecture and version, credentials, server reachability, schema and data types, then reproduce with the smallest safe query.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3155: ODBC--insert failed..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","ODBC"],"articleCategories":["Microsoft Access","Legacy Software","ODBC"],"aliases":["Microsoft Access 3155","MS Access error 3155","ODBC--insert failed."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64611,"title":"3156 - ODBC--delete failed.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","ODBC"],"keywords":["3156","Access error 3156","Microsoft Access","MSACCESS","Jet","VBA","ODBC","ODBC--delete failed.","ODBC--delete failed."],"errorCode":"3156","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3156: ODBC--delete failed.","rootCause":"The Access/Jet ODBC layer, driver, data source, server, query, data type, or connection state rejected the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Capture the native ODBC error, verify DSN/connection settings, driver architecture and version, credentials, server reachability, schema and data types, then reproduce with the smallest safe query.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3156: ODBC--delete failed..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","ODBC"],"articleCategories":["Microsoft Access","Legacy Software","ODBC"],"aliases":["Microsoft Access 3156","MS Access error 3156","ODBC--delete failed."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64612,"title":"3157 - ODBC--update failed.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","ODBC"],"keywords":["3157","Access error 3157","Microsoft Access","MSACCESS","Jet","VBA","ODBC","ODBC--update failed.","ODBC--update failed."],"errorCode":"3157","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3157: ODBC--update failed.","rootCause":"The Access/Jet ODBC layer, driver, data source, server, query, data type, or connection state rejected the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Capture the native ODBC error, verify DSN/connection settings, driver architecture and version, credentials, server reachability, schema and data types, then reproduce with the smallest safe query.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3157: ODBC--update failed..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","ODBC"],"articleCategories":["Microsoft Access","Legacy Software","ODBC"],"aliases":["Microsoft Access 3157","MS Access error 3157","ODBC--update failed."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64613,"title":"3158 - Couldn't save record; currently locked by another user.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3158","Access error 3158","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't save record; currently locked by another user.","Couldn't save record; currently locked by another user."],"errorCode":"3158","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3158: Couldn't save record; currently locked by another user.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3158: Couldn't save record; currently locked by another user..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3158","MS Access error 3158","Couldn't save record; currently locked by another user."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64614,"title":"3159 - Not a valid bookmark.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3159","Access error 3159","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Not a valid bookmark.","Not a valid bookmark."],"errorCode":"3159","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3159: Not a valid bookmark.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3159: Not a valid bookmark..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3159","MS Access error 3159","Not a valid bookmark."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64615,"title":"3160 - Table isn't open.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3160","Access error 3160","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Table isn't open.","Table isn't open."],"errorCode":"3160","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3160: Table isn't open.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3160: Table isn't open..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3160","MS Access error 3160","Table isn't open."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64616,"title":"3161 - Couldn't decrypt file.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["3161","Access error 3161","Microsoft Access","MSACCESS","Jet","VBA","Files","Couldn't decrypt file.","Couldn't decrypt file."],"errorCode":"3161","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3161: Couldn't decrypt file.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3161: Couldn't decrypt file..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 3161","MS Access error 3161","Couldn't decrypt file."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64617,"title":"3162 - Null is invalid.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3162","Access error 3162","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Null is invalid.","Null is invalid."],"errorCode":"3162","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3162: Null is invalid.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3162: Null is invalid..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3162","MS Access error 3162","Null is invalid."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64618,"title":"3163 - Couldn't insert or paste; data too long for field.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3163","Access error 3163","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't insert or paste; data too long for field.","Couldn't insert or paste; data too long for field."],"errorCode":"3163","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3163: Couldn't insert or paste; data too long for field.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3163: Couldn't insert or paste; data too long for field..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3163","MS Access error 3163","Couldn't insert or paste; data too long for field."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64619,"title":"3164 - Couldn't update field.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3164","Access error 3164","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't update field.","Couldn't update field."],"errorCode":"3164","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3164: Couldn't update field.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3164: Couldn't update field..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3164","MS Access error 3164","Couldn't update field."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64620,"title":"3165 - Couldn't open .INF file.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["3165","Access error 3165","Microsoft Access","MSACCESS","Jet","VBA","Files","Couldn't open .INF file.","Couldn't open .INF file."],"errorCode":"3165","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3165: Couldn't open .INF file.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3165: Couldn't open .INF file..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 3165","MS Access error 3165","Couldn't open .INF file."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64621,"title":"3166 - Missing memo file.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["3166","Access error 3166","Microsoft Access","MSACCESS","Jet","VBA","Files","Missing memo file.","Missing memo file."],"errorCode":"3166","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3166: Missing memo file.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3166: Missing memo file..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 3166","MS Access error 3166","Missing memo file."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64622,"title":"3167 - Record is deleted.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3167","Access error 3167","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Record is deleted.","Record is deleted."],"errorCode":"3167","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3167: Record is deleted.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3167: Record is deleted..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3167","MS Access error 3167","Record is deleted."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64623,"title":"3168 - Invalid .INF file.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["3168","Access error 3168","Microsoft Access","MSACCESS","Jet","VBA","Files","Invalid .INF file.","Invalid .INF file."],"errorCode":"3168","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3168: Invalid .INF file.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3168: Invalid .INF file..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 3168","MS Access error 3168","Invalid .INF file."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64624,"title":"3169 - Illegal type in expression.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3169","Access error 3169","Microsoft Access","MSACCESS","Jet","VBA","Queries","Illegal type in expression.","Illegal type in expression."],"errorCode":"3169","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3169: Illegal type in expression.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3169: Illegal type in expression..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3169","MS Access error 3169","Illegal type in expression."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64625,"title":"3170 - Couldn't find installable ISAM.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Import / Export"],"keywords":["3170","Access error 3170","Microsoft Access","MSACCESS","Jet","VBA","Import / Export","Couldn't find installable ISAM.","Couldn't find installable ISAM."],"errorCode":"3170","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3170: Couldn't find installable ISAM.","rootCause":"The source format, ISAM driver, specification, field mapping, file version, or destination schema is missing or incompatible.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Preserve the source, verify the import/export specification and supported driver, normalize field names and types, test a small copy, and validate row counts and rejected records.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3170: Couldn't find installable ISAM..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Import / Export"],"articleCategories":["Microsoft Access","Legacy Software","Import / Export"],"aliases":["Microsoft Access 3170","MS Access error 3170","Couldn't find installable ISAM."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64626,"title":"3171 - Couldn't find net path or user name.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["3171","Access error 3171","Microsoft Access","MSACCESS","Jet","VBA","Files","Couldn't find net path or user name.","Couldn't find net path or user name."],"errorCode":"3171","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3171: Couldn't find net path or user name.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3171: Couldn't find net path or user name..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 3171","MS Access error 3171","Couldn't find net path or user name."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64627,"title":"3172 - Couldn't open PARADOX.NET.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Import / Export"],"keywords":["3172","Access error 3172","Microsoft Access","MSACCESS","Jet","VBA","Import / Export","Couldn't open PARADOX.NET.","Couldn't open PARADOX.NET."],"errorCode":"3172","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3172: Couldn't open PARADOX.NET.","rootCause":"The source format, ISAM driver, specification, field mapping, file version, or destination schema is missing or incompatible.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Preserve the source, verify the import/export specification and supported driver, normalize field names and types, test a small copy, and validate row counts and rejected records.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3172: Couldn't open PARADOX.NET..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Import / Export"],"articleCategories":["Microsoft Access","Legacy Software","Import / Export"],"aliases":["Microsoft Access 3172","MS Access error 3172","Couldn't open PARADOX.NET."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64628,"title":"3173 - Couldn't open table 'MSysAccounts' in SYSTEM.MDA.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3173","Access error 3173","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't open table 'MSysAccounts' in SYSTEM.MDA.","Couldn't open table 'MSysAccounts' in SYSTEM.MDA."],"errorCode":"3173","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3173: Couldn't open table 'MSysAccounts' in SYSTEM.MDA.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3173: Couldn't open table 'MSysAccounts' in SYSTEM.MDA..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3173","MS Access error 3173","Couldn't open table 'MSysAccounts' in SYSTEM.MDA."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64629,"title":"3174 - Couldn't open table 'MSysGroups' in SYSTEM.MDA.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3174","Access error 3174","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't open table 'MSysGroups' in SYSTEM.MDA.","Couldn't open table 'MSysGroups' in SYSTEM.MDA."],"errorCode":"3174","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3174: Couldn't open table 'MSysGroups' in SYSTEM.MDA.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3174: Couldn't open table 'MSysGroups' in SYSTEM.MDA..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3174","MS Access error 3174","Couldn't open table 'MSysGroups' in SYSTEM.MDA."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64630,"title":"3175 - Date is out of range or is in an invalid format.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["3175","Access error 3175","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Date is out of range or is in an invalid format.","Date is out of range or is in an invalid format."],"errorCode":"3175","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3175: Date is out of range or is in an invalid format.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3175: Date is out of range or is in an invalid format..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 3175","MS Access error 3175","Date is out of range or is in an invalid format."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64631,"title":"3176 - Couldn't open file '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["3176","Access error 3176","Microsoft Access","MSACCESS","Jet","VBA","Files","Couldn't open file '|'.","Couldn't open file '<value>'."],"errorCode":"3176","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3176: Couldn't open file '<value>'.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3176: Couldn't open file '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 3176","MS Access error 3176","Couldn't open file '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64632,"title":"3177 - Not a valid table name.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3177","Access error 3177","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Not a valid table name.","Not a valid table name."],"errorCode":"3177","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3177: Not a valid table name.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3177: Not a valid table name..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3177","MS Access error 3177","Not a valid table name."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64633,"title":"3178 - Out of memory.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Resources"],"keywords":["3178","Access error 3178","Microsoft Access","MSACCESS","Jet","VBA","Resources","Out of memory.","Out of memory."],"errorCode":"3178","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3178: Out of memory.","rootCause":"Access or Windows lacks sufficient memory, stack, handles, disk, or other resources for the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Save work, close unnecessary objects/applications, check memory, handles, disk and database size, then reproduce after a controlled restart and review for runaway queries or code.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3178: Out of memory..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Resources"],"articleCategories":["Microsoft Access","Legacy Software","Resources"],"aliases":["Microsoft Access 3178","MS Access error 3178","Out of memory."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64634,"title":"3179 - Encountered unexpected end of file.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["3179","Access error 3179","Microsoft Access","MSACCESS","Jet","VBA","Files","Encountered unexpected end of file.","Encountered unexpected end of file."],"errorCode":"3179","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3179: Encountered unexpected end of file.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3179: Encountered unexpected end of file..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 3179","MS Access error 3179","Encountered unexpected end of file."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64635,"title":"3180 - Couldn't write to file '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["3180","Access error 3180","Microsoft Access","MSACCESS","Jet","VBA","Files","Couldn't write to file '|'.","Couldn't write to file '<value>'."],"errorCode":"3180","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3180: Couldn't write to file '<value>'.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3180: Couldn't write to file '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 3180","MS Access error 3180","Couldn't write to file '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64636,"title":"3181 - Invalid range.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3181","Access error 3181","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Invalid range.","Invalid range."],"errorCode":"3181","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3181: Invalid range.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3181: Invalid range..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3181","MS Access error 3181","Invalid range."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64637,"title":"3182 - Invalid file format.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["3182","Access error 3182","Microsoft Access","MSACCESS","Jet","VBA","Files","Invalid file format.","Invalid file format."],"errorCode":"3182","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3182: Invalid file format.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3182: Invalid file format..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 3182","MS Access error 3182","Invalid file format."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64638,"title":"3183 - Not enough space on temporary disk.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Files"],"keywords":["3183","Access error 3183","Microsoft Access","MSACCESS","Jet","VBA","Files","Not enough space on temporary disk.","Not enough space on temporary disk."],"errorCode":"3183","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3183: Not enough space on temporary disk.","rootCause":"A required file, path, directory, drive, or storage operation is missing, inaccessible, invalid, full, or read-only.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify the exact path, existence, free space, permissions, filename, share availability and file integrity; work from a backup before repair or replacement.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3183: Not enough space on temporary disk..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Files"],"articleCategories":["Microsoft Access","Legacy Software","Files"],"aliases":["Microsoft Access 3183","MS Access error 3183","Not enough space on temporary disk."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64639,"title":"3184 - Couldn't execute query; couldn't find linked table.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3184","Access error 3184","Microsoft Access","MSACCESS","Jet","VBA","Queries","Couldn't execute query; couldn't find linked table.","Couldn't execute query; couldn't find linked table."],"errorCode":"3184","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3184: Couldn't execute query; couldn't find linked table.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3184: Couldn't execute query; couldn't find linked table..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3184","MS Access error 3184","Couldn't execute query; couldn't find linked table."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64640,"title":"3185 - SELECT INTO remote database tried to produce too many fields.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3185","Access error 3185","Microsoft Access","MSACCESS","Jet","VBA","Queries","SELECT INTO remote database tried to produce too many fields.","SELECT INTO remote database tried to produce too many fields."],"errorCode":"3185","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3185: SELECT INTO remote database tried to produce too many fields.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3185: SELECT INTO remote database tried to produce too many fields..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3185","MS Access error 3185","SELECT INTO remote database tried to produce too many fields."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64641,"title":"3186 - Couldn't save; currently locked by user '<value 2>' on machine '<value 1>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Locking"],"keywords":["3186","Access error 3186","Microsoft Access","MSACCESS","Jet","VBA","Locking","Couldn't save; currently locked by user '|2' on machine '|1'.","Couldn't save; currently locked by user '<value 2>' on machine '<value 1>'."],"errorCode":"3186","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3186: Couldn't save; currently locked by user '<value 2>' on machine '<value 1>'.","rootCause":"The database, page, record, or object is already locked or in use by another session.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Identify active users and the locking object, coordinate closure or retry, verify share permissions and healthy lock-file cleanup, and never delete a lock file while users remain connected.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3186: Couldn't save; currently locked by user '<value 2>' on machine '<value 1>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Locking"],"articleCategories":["Microsoft Access","Legacy Software","Locking"],"aliases":["Microsoft Access 3186","MS Access error 3186","Couldn't save; currently locked by user '|2' on machine '|1'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64642,"title":"3187 - Couldn't read; currently locked by user '<value 2>' on machine '<value 1>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Locking"],"keywords":["3187","Access error 3187","Microsoft Access","MSACCESS","Jet","VBA","Locking","Couldn't read; currently locked by user '|2' on machine '|1'.","Couldn't read; currently locked by user '<value 2>' on machine '<value 1>'."],"errorCode":"3187","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3187: Couldn't read; currently locked by user '<value 2>' on machine '<value 1>'.","rootCause":"The database, page, record, or object is already locked or in use by another session.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Identify active users and the locking object, coordinate closure or retry, verify share permissions and healthy lock-file cleanup, and never delete a lock file while users remain connected.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3187: Couldn't read; currently locked by user '<value 2>' on machine '<value 1>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Locking"],"articleCategories":["Microsoft Access","Legacy Software","Locking"],"aliases":["Microsoft Access 3187","MS Access error 3187","Couldn't read; currently locked by user '|2' on machine '|1'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64643,"title":"3188 - Couldn't update; currently locked by another session on this machine.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Locking"],"keywords":["3188","Access error 3188","Microsoft Access","MSACCESS","Jet","VBA","Locking","Couldn't update; currently locked by another session on this machine.","Couldn't update; currently locked by another session on this machine."],"errorCode":"3188","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3188: Couldn't update; currently locked by another session on this machine.","rootCause":"The database, page, record, or object is already locked or in use by another session.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Identify active users and the locking object, coordinate closure or retry, verify share permissions and healthy lock-file cleanup, and never delete a lock file while users remain connected.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3188: Couldn't update; currently locked by another session on this machine..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Locking"],"articleCategories":["Microsoft Access","Legacy Software","Locking"],"aliases":["Microsoft Access 3188","MS Access error 3188","Couldn't update; currently locked by another session on this machine."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64644,"title":"3189 - Table '<value 1>' is exclusively locked by user '<value 3>' on machine '<value 2>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3189","Access error 3189","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Table '|1' is exclusively locked by user '|3' on machine '|2'.","Table '<value 1>' is exclusively locked by user '<value 3>' on machine '<value 2>'."],"errorCode":"3189","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3189: Table '<value 1>' is exclusively locked by user '<value 3>' on machine '<value 2>'.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3189: Table '<value 1>' is exclusively locked by user '<value 3>' on machine '<value 2>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3189","MS Access error 3189","Table '|1' is exclusively locked by user '|3' on machine '|2'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64645,"title":"3190 - Too many fields defined.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3190","Access error 3190","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Too many fields defined.","Too many fields defined."],"errorCode":"3190","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3190: Too many fields defined.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3190: Too many fields defined..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3190","MS Access error 3190","Too many fields defined."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64646,"title":"3191 - Can't define field more than once.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3191","Access error 3191","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't define field more than once.","Can't define field more than once."],"errorCode":"3191","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3191: Can't define field more than once.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3191: Can't define field more than once..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3191","MS Access error 3191","Can't define field more than once."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64647,"title":"3192 - Couldn't find output table '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3192","Access error 3192","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't find output table '|'.","Couldn't find output table '<value>'."],"errorCode":"3192","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3192: Couldn't find output table '<value>'.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3192: Couldn't find output table '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3192","MS Access error 3192","Couldn't find output table '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64648,"title":"3193 - (unknown)","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3193","Access error 3193","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","(unknown)","(unknown)"],"errorCode":"3193","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3193: (unknown)","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3193: (unknown).\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3193","MS Access error 3193","(unknown)"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64649,"title":"3194 - (unknown)","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3194","Access error 3194","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","(unknown)","(unknown)"],"errorCode":"3194","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3194: (unknown)","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3194: (unknown).\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3194","MS Access error 3194","(unknown)"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64650,"title":"3195 - (expression)","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3195","Access error 3195","Microsoft Access","MSACCESS","Jet","VBA","Queries","(expression)","(expression)"],"errorCode":"3195","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3195: (expression)","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3195: (expression).\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3195","MS Access error 3195","(expression)"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64651,"title":"3196 - Couldn't use '<value>'; database already in use.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3196","Access error 3196","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't use '|'; database already in use.","Couldn't use '<value>'; database already in use."],"errorCode":"3196","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3196: Couldn't use '<value>'; database already in use.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3196: Couldn't use '<value>'; database already in use..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3196","MS Access error 3196","Couldn't use '|'; database already in use."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64652,"title":"3197 - Data has changed; operation stopped.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3197","Access error 3197","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Data has changed; operation stopped.","Data has changed; operation stopped."],"errorCode":"3197","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3197: Data has changed; operation stopped.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3197: Data has changed; operation stopped..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3197","MS Access error 3197","Data has changed; operation stopped."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64653,"title":"3198 - Couldn't start session.  Too many sessions already active.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3198","Access error 3198","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Couldn't start session.  Too many sessions already active.","Couldn't start session.  Too many sessions already active."],"errorCode":"3198","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3198: Couldn't start session.  Too many sessions already active.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3198: Couldn't start session.  Too many sessions already active..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3198","MS Access error 3198","Couldn't start session.  Too many sessions already active."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64654,"title":"3199 - Couldn't find reference.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3199","Access error 3199","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Couldn't find reference.","Couldn't find reference."],"errorCode":"3199","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3199: Couldn't find reference.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3199: Couldn't find reference..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3199","MS Access error 3199","Couldn't find reference."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64655,"title":"3200 - Can't delete or change record. Since related records exist in table '<value>', referential integrity rules would be violated.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3200","Access error 3200","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't delete or change record. Since related records exist in table '|', referential integrity rules would be violated.","Can't delete or change record. Since related records exist in table '<value>', referential integrity rules would be violated."],"errorCode":"3200","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3200: Can't delete or change record. Since related records exist in table '<value>', referential integrity rules would be violated.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3200: Can't delete or change record. Since related records exist in table '<value>', referential integrity rules would be violated..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3200","MS Access error 3200","Can't delete or change record. Since related records exist in table '|', referential integrity rules would be violated."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64656,"title":"3201 - Can't add or change record.  Referential integrity rules require a related record in table '<value>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3201","Access error 3201","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't add or change record.  Referential integrity rules require a related record in table '|'.","Can't add or change record.  Referential integrity rules require a related record in table '<value>'."],"errorCode":"3201","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3201: Can't add or change record.  Referential integrity rules require a related record in table '<value>'.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3201: Can't add or change record.  Referential integrity rules require a related record in table '<value>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3201","MS Access error 3201","Can't add or change record.  Referential integrity rules require a related record in table '|'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64657,"title":"3202 - Couldn't save; currently locked by another user.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Locking"],"keywords":["3202","Access error 3202","Microsoft Access","MSACCESS","Jet","VBA","Locking","Couldn't save; currently locked by another user.","Couldn't save; currently locked by another user."],"errorCode":"3202","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3202: Couldn't save; currently locked by another user.","rootCause":"The database, page, record, or object is already locked or in use by another session.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Identify active users and the locking object, coordinate closure or retry, verify share permissions and healthy lock-file cleanup, and never delete a lock file while users remain connected.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3202: Couldn't save; currently locked by another user..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Locking"],"articleCategories":["Microsoft Access","Legacy Software","Locking"],"aliases":["Microsoft Access 3202","MS Access error 3202","Couldn't save; currently locked by another user."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64658,"title":"3203 - Can't specify subquery in expression (<value>).","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3203","Access error 3203","Microsoft Access","MSACCESS","Jet","VBA","Queries","Can't specify subquery in expression (|).","Can't specify subquery in expression (<value>)."],"errorCode":"3203","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3203: Can't specify subquery in expression (<value>).","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3203: Can't specify subquery in expression (<value>)..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3203","MS Access error 3203","Can't specify subquery in expression (|)."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64659,"title":"3204 - Database already exists.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3204","Access error 3204","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Database already exists.","Database already exists."],"errorCode":"3204","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3204: Database already exists.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3204: Database already exists..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3204","MS Access error 3204","Database already exists."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64660,"title":"3205 - Too many crosstab column headers (<value>).","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3205","Access error 3205","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Too many crosstab column headers (|).","Too many crosstab column headers (<value>)."],"errorCode":"3205","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3205: Too many crosstab column headers (<value>).","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3205: Too many crosstab column headers (<value>)..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3205","MS Access error 3205","Too many crosstab column headers (|)."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64661,"title":"3206 - Can't create a relationship between a field and itself.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3206","Access error 3206","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Can't create a relationship between a field and itself.","Can't create a relationship between a field and itself."],"errorCode":"3206","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3206: Can't create a relationship between a field and itself.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3206: Can't create a relationship between a field and itself..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3206","MS Access error 3206","Can't create a relationship between a field and itself."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64662,"title":"3207 - Operation not supported on Paradox table with no primary key.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3207","Access error 3207","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Operation not supported on Paradox table with no primary key.","Operation not supported on Paradox table with no primary key."],"errorCode":"3207","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3207: Operation not supported on Paradox table with no primary key.","rootCause":"The requested feature or operation is unavailable in this Access/Jet version, object type, driver, or context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the Access, database-engine, file-format, and driver versions; use a supported operation or migrate the workflow before retrying.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3207: Operation not supported on Paradox table with no primary key..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3207","MS Access error 3207","Operation not supported on Paradox table with no primary key."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64663,"title":"3208 - Invalid Deleted entry in [dBASE ISAM] section in MSACCESS.INI.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Import / Export"],"keywords":["3208","Access error 3208","Microsoft Access","MSACCESS","Jet","VBA","Import / Export","Invalid Deleted entry in [dBASE ISAM] section in MSACCESS.INI.","Invalid Deleted entry in [dBASE ISAM] section in MSACCESS.INI."],"errorCode":"3208","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3208: Invalid Deleted entry in [dBASE ISAM] section in MSACCESS.INI.","rootCause":"The source format, ISAM driver, specification, field mapping, file version, or destination schema is missing or incompatible.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Preserve the source, verify the import/export specification and supported driver, normalize field names and types, test a small copy, and validate row counts and rejected records.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3208: Invalid Deleted entry in [dBASE ISAM] section in MSACCESS.INI..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Import / Export"],"articleCategories":["Microsoft Access","Legacy Software","Import / Export"],"aliases":["Microsoft Access 3208","MS Access error 3208","Invalid Deleted entry in [dBASE ISAM] section in MSACCESS.INI."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64664,"title":"3209 - Invalid Stats entry in [dBASE ISAM] section in MSACCESS.INI.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Import / Export"],"keywords":["3209","Access error 3209","Microsoft Access","MSACCESS","Jet","VBA","Import / Export","Invalid Stats entry in [dBASE ISAM] section in MSACCESS.INI.","Invalid Stats entry in [dBASE ISAM] section in MSACCESS.INI."],"errorCode":"3209","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3209: Invalid Stats entry in [dBASE ISAM] section in MSACCESS.INI.","rootCause":"The source format, ISAM driver, specification, field mapping, file version, or destination schema is missing or incompatible.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Preserve the source, verify the import/export specification and supported driver, normalize field names and types, test a small copy, and validate row counts and rejected records.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3209: Invalid Stats entry in [dBASE ISAM] section in MSACCESS.INI..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Import / Export"],"articleCategories":["Microsoft Access","Legacy Software","Import / Export"],"aliases":["Microsoft Access 3209","MS Access error 3209","Invalid Stats entry in [dBASE ISAM] section in MSACCESS.INI."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64665,"title":"3210 - Connect string too long.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3210","Access error 3210","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Connect string too long.","Connect string too long."],"errorCode":"3210","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3210: Connect string too long.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3210: Connect string too long..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3210","MS Access error 3210","Connect string too long."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64666,"title":"3211 - Couldn't lock table '<value 1>'; currently in use.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3211","Access error 3211","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't lock table '|1'; currently in use.","Couldn't lock table '<value 1>'; currently in use."],"errorCode":"3211","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3211: Couldn't lock table '<value 1>'; currently in use.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3211: Couldn't lock table '<value 1>'; currently in use..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3211","MS Access error 3211","Couldn't lock table '|1'; currently in use."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64667,"title":"3212 - Couldn't lock table '<value 1>'; currently in use by user '<value 3>' on machine '<value 2>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3212","Access error 3212","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't lock table '|1'; currently in use by user '|3' on machine '|2'.","Couldn't lock table '<value 1>'; currently in use by user '<value 3>' on machine '<value 2>'."],"errorCode":"3212","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3212: Couldn't lock table '<value 1>'; currently in use by user '<value 3>' on machine '<value 2>'.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3212: Couldn't lock table '<value 1>'; currently in use by user '<value 3>' on machine '<value 2>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3212","MS Access error 3212","Couldn't lock table '|1'; currently in use by user '|3' on machine '|2'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64668,"title":"3213 - Invalid Date entry in [dBASE ISAM] section in MSACCESS.INI.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Import / Export"],"keywords":["3213","Access error 3213","Microsoft Access","MSACCESS","Jet","VBA","Import / Export","Invalid Date entry in [dBASE ISAM] section in MSACCESS.INI.","Invalid Date entry in [dBASE ISAM] section in MSACCESS.INI."],"errorCode":"3213","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3213: Invalid Date entry in [dBASE ISAM] section in MSACCESS.INI.","rootCause":"The source format, ISAM driver, specification, field mapping, file version, or destination schema is missing or incompatible.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Preserve the source, verify the import/export specification and supported driver, normalize field names and types, test a small copy, and validate row counts and rejected records.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3213: Invalid Date entry in [dBASE ISAM] section in MSACCESS.INI..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Import / Export"],"articleCategories":["Microsoft Access","Legacy Software","Import / Export"],"aliases":["Microsoft Access 3213","MS Access error 3213","Invalid Date entry in [dBASE ISAM] section in MSACCESS.INI."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64669,"title":"3214 - Invalid Mark entry in [dBASE ISAM] section in MSACCESS.INI.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Import / Export"],"keywords":["3214","Access error 3214","Microsoft Access","MSACCESS","Jet","VBA","Import / Export","Invalid Mark entry in [dBASE ISAM] section in MSACCESS.INI.","Invalid Mark entry in [dBASE ISAM] section in MSACCESS.INI."],"errorCode":"3214","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3214: Invalid Mark entry in [dBASE ISAM] section in MSACCESS.INI.","rootCause":"The source format, ISAM driver, specification, field mapping, file version, or destination schema is missing or incompatible.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Preserve the source, verify the import/export specification and supported driver, normalize field names and types, test a small copy, and validate row counts and rejected records.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3214: Invalid Mark entry in [dBASE ISAM] section in MSACCESS.INI..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Import / Export"],"articleCategories":["Microsoft Access","Legacy Software","Import / Export"],"aliases":["Microsoft Access 3214","MS Access error 3214","Invalid Mark entry in [dBASE ISAM] section in MSACCESS.INI."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64670,"title":"3215 - Too many Btrieve tasks.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Btrieve"],"keywords":["3215","Access error 3215","Microsoft Access","MSACCESS","Jet","VBA","Btrieve","Too many Btrieve tasks.","Too many Btrieve tasks."],"errorCode":"3215","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3215: Too many Btrieve tasks.","rootCause":"A legacy Btrieve driver, DLL, dictionary, lock, resource, or data operation failed.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm that the application still requires Btrieve, preserve the data, verify the exact supported driver/DLL and dictionary state, and use vendor-compatible repair or migration tooling.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3215: Too many Btrieve tasks..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Btrieve"],"articleCategories":["Microsoft Access","Legacy Software","Btrieve"],"aliases":["Microsoft Access 3215","MS Access error 3215","Too many Btrieve tasks."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64671,"title":"3216 - Parameter '<value>' specified where a table name is required.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3216","Access error 3216","Microsoft Access","MSACCESS","Jet","VBA","Queries","Parameter '|' specified where a table name is required.","Parameter '<value>' specified where a table name is required."],"errorCode":"3216","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3216: Parameter '<value>' specified where a table name is required.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3216: Parameter '<value>' specified where a table name is required..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3216","MS Access error 3216","Parameter '|' specified where a table name is required."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64672,"title":"3217 - Parameter '<value>' specified where a database name is required.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3217","Access error 3217","Microsoft Access","MSACCESS","Jet","VBA","Queries","Parameter '|' specified where a database name is required.","Parameter '<value>' specified where a database name is required."],"errorCode":"3217","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3217: Parameter '<value>' specified where a database name is required.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3217: Parameter '<value>' specified where a database name is required..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3217","MS Access error 3217","Parameter '|' specified where a database name is required."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64673,"title":"3218 - Couldn't update; currently locked.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Locking"],"keywords":["3218","Access error 3218","Microsoft Access","MSACCESS","Jet","VBA","Locking","Couldn't update; currently locked.","Couldn't update; currently locked."],"errorCode":"3218","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3218: Couldn't update; currently locked.","rootCause":"The database, page, record, or object is already locked or in use by another session.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Identify active users and the locking object, coordinate closure or retry, verify share permissions and healthy lock-file cleanup, and never delete a lock file while users remain connected.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3218: Couldn't update; currently locked..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Locking"],"articleCategories":["Microsoft Access","Legacy Software","Locking"],"aliases":["Microsoft Access 3218","MS Access error 3218","Couldn't update; currently locked."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64674,"title":"3219 - Can't perform operation; it is illegal.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access UI"],"keywords":["3219","Access error 3219","Microsoft Access","MSACCESS","Jet","VBA","Access UI","Can't perform operation; it is illegal.","Can't perform operation; it is illegal."],"errorCode":"3219","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3219: Can't perform operation; it is illegal.","rootCause":"An Access object, property, control, macro, menu, form, or report is invalid, unavailable, or in the wrong state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the named object in Design view, verify references, names, properties, event code and dependencies, compile the project, and test a copy of the database.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3219: Can't perform operation; it is illegal..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access UI"],"articleCategories":["Microsoft Access","Legacy Software","Access UI"],"aliases":["Microsoft Access 3219","MS Access error 3219","Can't perform operation; it is illegal."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64675,"title":"3220 - Wrong Paradox sort sequence.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Import / Export"],"keywords":["3220","Access error 3220","Microsoft Access","MSACCESS","Jet","VBA","Import / Export","Wrong Paradox sort sequence.","Wrong Paradox sort sequence."],"errorCode":"3220","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3220: Wrong Paradox sort sequence.","rootCause":"The source format, ISAM driver, specification, field mapping, file version, or destination schema is missing or incompatible.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Preserve the source, verify the import/export specification and supported driver, normalize field names and types, test a small copy, and validate row counts and rejected records.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3220: Wrong Paradox sort sequence..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Import / Export"],"articleCategories":["Microsoft Access","Legacy Software","Import / Export"],"aliases":["Microsoft Access 3220","MS Access error 3220","Wrong Paradox sort sequence."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64676,"title":"3221 - Invalid entries in [Btrieve ISAM] section in WIN.INI.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Btrieve"],"keywords":["3221","Access error 3221","Microsoft Access","MSACCESS","Jet","VBA","Btrieve","Invalid entries in [Btrieve ISAM] section in WIN.INI.","Invalid entries in [Btrieve ISAM] section in WIN.INI."],"errorCode":"3221","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3221: Invalid entries in [Btrieve ISAM] section in WIN.INI.","rootCause":"A legacy Btrieve driver, DLL, dictionary, lock, resource, or data operation failed.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm that the application still requires Btrieve, preserve the data, verify the exact supported driver/DLL and dictionary state, and use vendor-compatible repair or migration tooling.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3221: Invalid entries in [Btrieve ISAM] section in WIN.INI..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Btrieve"],"articleCategories":["Microsoft Access","Legacy Software","Btrieve"],"aliases":["Microsoft Access 3221","MS Access error 3221","Invalid entries in [Btrieve ISAM] section in WIN.INI."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64677,"title":"3222 - Query can't contain a Database parameter.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3222","Access error 3222","Microsoft Access","MSACCESS","Jet","VBA","Queries","Query can't contain a Database parameter.","Query can't contain a Database parameter."],"errorCode":"3222","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3222: Query can't contain a Database parameter.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3222: Query can't contain a Database parameter..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3222","MS Access error 3222","Query can't contain a Database parameter."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64678,"title":"3223 - '<value>' isn't a valid parameter name.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3223","Access error 3223","Microsoft Access","MSACCESS","Jet","VBA","Queries","'|' isn't a valid parameter name.","'<value>' isn't a valid parameter name."],"errorCode":"3223","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3223: '<value>' isn't a valid parameter name.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3223: '<value>' isn't a valid parameter name..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3223","MS Access error 3223","'|' isn't a valid parameter name."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64679,"title":"3224 - Btrieve--data dictionary is corrupted.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Btrieve"],"keywords":["3224","Access error 3224","Microsoft Access","MSACCESS","Jet","VBA","Btrieve","Btrieve--data dictionary is corrupted.","Btrieve--data dictionary is corrupted."],"errorCode":"3224","eventId":"","severity":"High","summary":"Legacy Microsoft Access error 3224: Btrieve--data dictionary is corrupted.","rootCause":"A legacy Btrieve driver, DLL, dictionary, lock, resource, or data operation failed.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm that the application still requires Btrieve, preserve the data, verify the exact supported driver/DLL and dictionary state, and use vendor-compatible repair or migration tooling.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3224: Btrieve--data dictionary is corrupted..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Btrieve"],"articleCategories":["Microsoft Access","Legacy Software","Btrieve"],"aliases":["Microsoft Access 3224","MS Access error 3224","Btrieve--data dictionary is corrupted."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64680,"title":"3225 - Encountered record locking deadlock while performing Btrieve operation.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Btrieve"],"keywords":["3225","Access error 3225","Microsoft Access","MSACCESS","Jet","VBA","Btrieve","Encountered record locking deadlock while performing Btrieve operation.","Encountered record locking deadlock while performing Btrieve operation."],"errorCode":"3225","eventId":"","severity":"High","summary":"Legacy Microsoft Access error 3225: Encountered record locking deadlock while performing Btrieve operation.","rootCause":"A legacy Btrieve driver, DLL, dictionary, lock, resource, or data operation failed.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm that the application still requires Btrieve, preserve the data, verify the exact supported driver/DLL and dictionary state, and use vendor-compatible repair or migration tooling.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3225: Encountered record locking deadlock while performing Btrieve operation..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Btrieve"],"articleCategories":["Microsoft Access","Legacy Software","Btrieve"],"aliases":["Microsoft Access 3225","MS Access error 3225","Encountered record locking deadlock while performing Btrieve operation."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64681,"title":"3226 - Errors encountered while using the Btrieve DLL.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Btrieve"],"keywords":["3226","Access error 3226","Microsoft Access","MSACCESS","Jet","VBA","Btrieve","Errors encountered while using the Btrieve DLL.","Errors encountered while using the Btrieve DLL."],"errorCode":"3226","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3226: Errors encountered while using the Btrieve DLL.","rootCause":"A legacy Btrieve driver, DLL, dictionary, lock, resource, or data operation failed.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm that the application still requires Btrieve, preserve the data, verify the exact supported driver/DLL and dictionary state, and use vendor-compatible repair or migration tooling.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3226: Errors encountered while using the Btrieve DLL..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Btrieve"],"articleCategories":["Microsoft Access","Legacy Software","Btrieve"],"aliases":["Microsoft Access 3226","MS Access error 3226","Errors encountered while using the Btrieve DLL."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64682,"title":"3227 - Invalid Century entry in [dBASE ISAM] section in MSACCESS.INI.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Import / Export"],"keywords":["3227","Access error 3227","Microsoft Access","MSACCESS","Jet","VBA","Import / Export","Invalid Century entry in [dBASE ISAM] section in MSACCESS.INI.","Invalid Century entry in [dBASE ISAM] section in MSACCESS.INI."],"errorCode":"3227","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3227: Invalid Century entry in [dBASE ISAM] section in MSACCESS.INI.","rootCause":"The source format, ISAM driver, specification, field mapping, file version, or destination schema is missing or incompatible.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Preserve the source, verify the import/export specification and supported driver, normalize field names and types, test a small copy, and validate row counts and rejected records.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3227: Invalid Century entry in [dBASE ISAM] section in MSACCESS.INI..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Import / Export"],"articleCategories":["Microsoft Access","Legacy Software","Import / Export"],"aliases":["Microsoft Access 3227","MS Access error 3227","Invalid Century entry in [dBASE ISAM] section in MSACCESS.INI."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64683,"title":"3228 - Invalid CollatingSequence entry in [Paradox ISAM] section in MSACCESS.INI.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Import / Export"],"keywords":["3228","Access error 3228","Microsoft Access","MSACCESS","Jet","VBA","Import / Export","Invalid CollatingSequence entry in [Paradox ISAM] section in MSACCESS.INI.","Invalid CollatingSequence entry in [Paradox ISAM] section in MSACCESS.INI."],"errorCode":"3228","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3228: Invalid CollatingSequence entry in [Paradox ISAM] section in MSACCESS.INI.","rootCause":"The source format, ISAM driver, specification, field mapping, file version, or destination schema is missing or incompatible.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Preserve the source, verify the import/export specification and supported driver, normalize field names and types, test a small copy, and validate row counts and rejected records.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3228: Invalid CollatingSequence entry in [Paradox ISAM] section in MSACCESS.INI..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Import / Export"],"articleCategories":["Microsoft Access","Legacy Software","Import / Export"],"aliases":["Microsoft Access 3228","MS Access error 3228","Invalid CollatingSequence entry in [Paradox ISAM] section in MSACCESS.INI."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64684,"title":"3229 - Btrieve--can't change field.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Btrieve"],"keywords":["3229","Access error 3229","Microsoft Access","MSACCESS","Jet","VBA","Btrieve","Btrieve--can't change field.","Btrieve--can't change field."],"errorCode":"3229","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3229: Btrieve--can't change field.","rootCause":"A legacy Btrieve driver, DLL, dictionary, lock, resource, or data operation failed.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm that the application still requires Btrieve, preserve the data, verify the exact supported driver/DLL and dictionary state, and use vendor-compatible repair or migration tooling.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3229: Btrieve--can't change field..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Btrieve"],"articleCategories":["Microsoft Access","Legacy Software","Btrieve"],"aliases":["Microsoft Access 3229","MS Access error 3229","Btrieve--can't change field."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64685,"title":"3230 - Out-of-date Paradox lock file.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Import / Export"],"keywords":["3230","Access error 3230","Microsoft Access","MSACCESS","Jet","VBA","Import / Export","Out-of-date Paradox lock file.","Out-of-date Paradox lock file."],"errorCode":"3230","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3230: Out-of-date Paradox lock file.","rootCause":"The source format, ISAM driver, specification, field mapping, file version, or destination schema is missing or incompatible.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Preserve the source, verify the import/export specification and supported driver, normalize field names and types, test a small copy, and validate row counts and rejected records.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3230: Out-of-date Paradox lock file..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Import / Export"],"articleCategories":["Microsoft Access","Legacy Software","Import / Export"],"aliases":["Microsoft Access 3230","MS Access error 3230","Out-of-date Paradox lock file."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64686,"title":"3231 - ODBC--field would be too long; data truncated.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","ODBC"],"keywords":["3231","Access error 3231","Microsoft Access","MSACCESS","Jet","VBA","ODBC","ODBC--field would be too long; data truncated.","ODBC--field would be too long; data truncated."],"errorCode":"3231","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3231: ODBC--field would be too long; data truncated.","rootCause":"The Access/Jet ODBC layer, driver, data source, server, query, data type, or connection state rejected the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Capture the native ODBC error, verify DSN/connection settings, driver architecture and version, credentials, server reachability, schema and data types, then reproduce with the smallest safe query.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3231: ODBC--field would be too long; data truncated..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","ODBC"],"articleCategories":["Microsoft Access","Legacy Software","ODBC"],"aliases":["Microsoft Access 3231","MS Access error 3231","ODBC--field would be too long; data truncated."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64687,"title":"3232 - ODBC--couldn't create table.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","ODBC"],"keywords":["3232","Access error 3232","Microsoft Access","MSACCESS","Jet","VBA","ODBC","ODBC--couldn't create table.","ODBC--couldn't create table."],"errorCode":"3232","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3232: ODBC--couldn't create table.","rootCause":"The Access/Jet ODBC layer, driver, data source, server, query, data type, or connection state rejected the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Capture the native ODBC error, verify DSN/connection settings, driver architecture and version, credentials, server reachability, schema and data types, then reproduce with the smallest safe query.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3232: ODBC--couldn't create table..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","ODBC"],"articleCategories":["Microsoft Access","Legacy Software","ODBC"],"aliases":["Microsoft Access 3232","MS Access error 3232","ODBC--couldn't create table."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64688,"title":"3233 - ODBC--incorrect driver version.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","ODBC"],"keywords":["3233","Access error 3233","Microsoft Access","MSACCESS","Jet","VBA","ODBC","ODBC--incorrect driver version.","ODBC--incorrect driver version."],"errorCode":"3233","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3233: ODBC--incorrect driver version.","rootCause":"The Access/Jet ODBC layer, driver, data source, server, query, data type, or connection state rejected the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Capture the native ODBC error, verify DSN/connection settings, driver architecture and version, credentials, server reachability, schema and data types, then reproduce with the smallest safe query.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3233: ODBC--incorrect driver version..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","ODBC"],"articleCategories":["Microsoft Access","Legacy Software","ODBC"],"aliases":["Microsoft Access 3233","MS Access error 3233","ODBC--incorrect driver version."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64689,"title":"3234 - ODBC--server not responding.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","ODBC"],"keywords":["3234","Access error 3234","Microsoft Access","MSACCESS","Jet","VBA","ODBC","ODBC--server not responding.","ODBC--server not responding."],"errorCode":"3234","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3234: ODBC--server not responding.","rootCause":"The Access/Jet ODBC layer, driver, data source, server, query, data type, or connection state rejected the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Capture the native ODBC error, verify DSN/connection settings, driver architecture and version, credentials, server reachability, schema and data types, then reproduce with the smallest safe query.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3234: ODBC--server not responding..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","ODBC"],"articleCategories":["Microsoft Access","Legacy Software","ODBC"],"aliases":["Microsoft Access 3234","MS Access error 3234","ODBC--server not responding."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64690,"title":"3235 - ODBC--data type not supported on server.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","ODBC"],"keywords":["3235","Access error 3235","Microsoft Access","MSACCESS","Jet","VBA","ODBC","ODBC--data type not supported on server.","ODBC--data type not supported on server."],"errorCode":"3235","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3235: ODBC--data type not supported on server.","rootCause":"The requested feature or operation is unavailable in this Access/Jet version, object type, driver, or context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the Access, database-engine, file-format, and driver versions; use a supported operation or migrate the workflow before retrying.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3235: ODBC--data type not supported on server..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","ODBC"],"articleCategories":["Microsoft Access","Legacy Software","ODBC"],"aliases":["Microsoft Access 3235","MS Access error 3235","ODBC--data type not supported on server."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64691,"title":"3236 - ODBC--encountered unexpected Null value.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","ODBC"],"keywords":["3236","Access error 3236","Microsoft Access","MSACCESS","Jet","VBA","ODBC","ODBC--encountered unexpected Null value.","ODBC--encountered unexpected Null value."],"errorCode":"3236","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3236: ODBC--encountered unexpected Null value.","rootCause":"The Access/Jet ODBC layer, driver, data source, server, query, data type, or connection state rejected the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Capture the native ODBC error, verify DSN/connection settings, driver architecture and version, credentials, server reachability, schema and data types, then reproduce with the smallest safe query.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3236: ODBC--encountered unexpected Null value..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","ODBC"],"articleCategories":["Microsoft Access","Legacy Software","ODBC"],"aliases":["Microsoft Access 3236","MS Access error 3236","ODBC--encountered unexpected Null value."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64692,"title":"3237 - ODBC--unexpected type.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","ODBC"],"keywords":["3237","Access error 3237","Microsoft Access","MSACCESS","Jet","VBA","ODBC","ODBC--unexpected type.","ODBC--unexpected type."],"errorCode":"3237","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3237: ODBC--unexpected type.","rootCause":"The Access/Jet ODBC layer, driver, data source, server, query, data type, or connection state rejected the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Capture the native ODBC error, verify DSN/connection settings, driver architecture and version, credentials, server reachability, schema and data types, then reproduce with the smallest safe query.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3237: ODBC--unexpected type..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","ODBC"],"articleCategories":["Microsoft Access","Legacy Software","ODBC"],"aliases":["Microsoft Access 3237","MS Access error 3237","ODBC--unexpected type."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64693,"title":"3238 - ODBC--data out of range.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","ODBC"],"keywords":["3238","Access error 3238","Microsoft Access","MSACCESS","Jet","VBA","ODBC","ODBC--data out of range.","ODBC--data out of range."],"errorCode":"3238","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3238: ODBC--data out of range.","rootCause":"The Access/Jet ODBC layer, driver, data source, server, query, data type, or connection state rejected the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Capture the native ODBC error, verify DSN/connection settings, driver architecture and version, credentials, server reachability, schema and data types, then reproduce with the smallest safe query.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3238: ODBC--data out of range..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","ODBC"],"articleCategories":["Microsoft Access","Legacy Software","ODBC"],"aliases":["Microsoft Access 3238","MS Access error 3238","ODBC--data out of range."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64694,"title":"3239 - Too many active users.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Locking"],"keywords":["3239","Access error 3239","Microsoft Access","MSACCESS","Jet","VBA","Locking","Too many active users.","Too many active users."],"errorCode":"3239","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3239: Too many active users.","rootCause":"The database, page, record, or object is already locked or in use by another session.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Identify active users and the locking object, coordinate closure or retry, verify share permissions and healthy lock-file cleanup, and never delete a lock file while users remain connected.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3239: Too many active users..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Locking"],"articleCategories":["Microsoft Access","Legacy Software","Locking"],"aliases":["Microsoft Access 3239","MS Access error 3239","Too many active users."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64695,"title":"3240 - Btrieve--missing WBTRCALL.DLL.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Btrieve"],"keywords":["3240","Access error 3240","Microsoft Access","MSACCESS","Jet","VBA","Btrieve","Btrieve--missing WBTRCALL.DLL.","Btrieve--missing WBTRCALL.DLL."],"errorCode":"3240","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3240: Btrieve--missing WBTRCALL.DLL.","rootCause":"A legacy Btrieve driver, DLL, dictionary, lock, resource, or data operation failed.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm that the application still requires Btrieve, preserve the data, verify the exact supported driver/DLL and dictionary state, and use vendor-compatible repair or migration tooling.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3240: Btrieve--missing WBTRCALL.DLL..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Btrieve"],"articleCategories":["Microsoft Access","Legacy Software","Btrieve"],"aliases":["Microsoft Access 3240","MS Access error 3240","Btrieve--missing WBTRCALL.DLL."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64696,"title":"3241 - Btrieve--out of resources.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Btrieve"],"keywords":["3241","Access error 3241","Microsoft Access","MSACCESS","Jet","VBA","Btrieve","Btrieve--out of resources.","Btrieve--out of resources."],"errorCode":"3241","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3241: Btrieve--out of resources.","rootCause":"A legacy Btrieve driver, DLL, dictionary, lock, resource, or data operation failed.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm that the application still requires Btrieve, preserve the data, verify the exact supported driver/DLL and dictionary state, and use vendor-compatible repair or migration tooling.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3241: Btrieve--out of resources..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Btrieve"],"articleCategories":["Microsoft Access","Legacy Software","Btrieve"],"aliases":["Microsoft Access 3241","MS Access error 3241","Btrieve--out of resources."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64697,"title":"3242 - Invalid reference in SELECT statement.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3242","Access error 3242","Microsoft Access","MSACCESS","Jet","VBA","Queries","Invalid reference in SELECT statement.","Invalid reference in SELECT statement."],"errorCode":"3242","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3242: Invalid reference in SELECT statement.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3242: Invalid reference in SELECT statement..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3242","MS Access error 3242","Invalid reference in SELECT statement."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64698,"title":"3243 - None of the import field names match fields in the appended table.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3243","Access error 3243","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","None of the import field names match fields in the appended table.","None of the import field names match fields in the appended table."],"errorCode":"3243","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3243: None of the import field names match fields in the appended table.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3243: None of the import field names match fields in the appended table..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3243","MS Access error 3243","None of the import field names match fields in the appended table."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64699,"title":"3244 - Can't import password-protected spreadsheet.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Import / Export"],"keywords":["3244","Access error 3244","Microsoft Access","MSACCESS","Jet","VBA","Import / Export","Can't import password-protected spreadsheet.","Can't import password-protected spreadsheet."],"errorCode":"3244","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3244: Can't import password-protected spreadsheet.","rootCause":"The source format, ISAM driver, specification, field mapping, file version, or destination schema is missing or incompatible.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Preserve the source, verify the import/export specification and supported driver, normalize field names and types, test a small copy, and validate row counts and rejected records.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3244: Can't import password-protected spreadsheet..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Import / Export"],"articleCategories":["Microsoft Access","Legacy Software","Import / Export"],"aliases":["Microsoft Access 3244","MS Access error 3244","Can't import password-protected spreadsheet."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64700,"title":"3245 - Couldn't parse field names from first row of import table.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3245","Access error 3245","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Couldn't parse field names from first row of import table.","Couldn't parse field names from first row of import table."],"errorCode":"3245","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3245: Couldn't parse field names from first row of import table.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3245: Couldn't parse field names from first row of import table..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3245","MS Access error 3245","Couldn't parse field names from first row of import table."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64701,"title":"3246 - Operation not supported in transactions.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3246","Access error 3246","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Operation not supported in transactions.","Operation not supported in transactions."],"errorCode":"3246","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3246: Operation not supported in transactions.","rootCause":"The requested feature or operation is unavailable in this Access/Jet version, object type, driver, or context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the Access, database-engine, file-format, and driver versions; use a supported operation or migrate the workflow before retrying.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3246: Operation not supported in transactions..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3246","MS Access error 3246","Operation not supported in transactions."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64702,"title":"3247 - ODBC--linked table definition has changed.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","ODBC"],"keywords":["3247","Access error 3247","Microsoft Access","MSACCESS","Jet","VBA","ODBC","ODBC--linked table definition has changed.","ODBC--linked table definition has changed."],"errorCode":"3247","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3247: ODBC--linked table definition has changed.","rootCause":"The Access/Jet ODBC layer, driver, data source, server, query, data type, or connection state rejected the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Capture the native ODBC error, verify DSN/connection settings, driver architecture and version, credentials, server reachability, schema and data types, then reproduce with the smallest safe query.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3247: ODBC--linked table definition has changed..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","ODBC"],"articleCategories":["Microsoft Access","Legacy Software","ODBC"],"aliases":["Microsoft Access 3247","MS Access error 3247","ODBC--linked table definition has changed."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64703,"title":"3248 - Invalid NetworkAccess entry in MSACCESS.INI.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3248","Access error 3248","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Invalid NetworkAccess entry in MSACCESS.INI.","Invalid NetworkAccess entry in MSACCESS.INI."],"errorCode":"3248","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3248: Invalid NetworkAccess entry in MSACCESS.INI.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3248: Invalid NetworkAccess entry in MSACCESS.INI..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3248","MS Access error 3248","Invalid NetworkAccess entry in MSACCESS.INI."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64704,"title":"3249 - Invalid PageTimeout entry in MSACCESS.INI.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3249","Access error 3249","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Invalid PageTimeout entry in MSACCESS.INI.","Invalid PageTimeout entry in MSACCESS.INI."],"errorCode":"3249","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3249: Invalid PageTimeout entry in MSACCESS.INI.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3249: Invalid PageTimeout entry in MSACCESS.INI..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3249","MS Access error 3249","Invalid PageTimeout entry in MSACCESS.INI."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64705,"title":"3250 - Couldn't build key.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3250","Access error 3250","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Couldn't build key.","Couldn't build key."],"errorCode":"3250","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3250: Couldn't build key.","rootCause":"The Access/VBA runtime received an invalid state, value, object, call, or operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Record the failing action and code line, compile the VBA project, verify references and object state, validate input types and bounds, then reproduce in a backed-up copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3250: Couldn't build key..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3250","MS Access error 3250","Couldn't build key."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64706,"title":"3251 - Feature not available.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3251","Access error 3251","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","Feature not available.","Feature not available."],"errorCode":"3251","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3251: Feature not available.","rootCause":"The requested feature or operation is unavailable in this Access/Jet version, object type, driver, or context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Confirm the Access, database-engine, file-format, and driver versions; use a supported operation or migrate the workflow before retrying.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3251: Feature not available..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3251","MS Access error 3251","Feature not available."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64707,"title":"3252 - Illegal reentrancy during query execution.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3252","Access error 3252","Microsoft Access","MSACCESS","Jet","VBA","Queries","Illegal reentrancy during query execution.","Illegal reentrancy during query execution."],"errorCode":"3252","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3252: Illegal reentrancy during query execution.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3252: Illegal reentrancy during query execution..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3252","MS Access error 3252","Illegal reentrancy during query execution."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64708,"title":"3254 - ODBC--Can't lock all records.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","ODBC"],"keywords":["3254","Access error 3254","Microsoft Access","MSACCESS","Jet","VBA","ODBC","ODBC--Can't lock all records.","ODBC--Can't lock all records."],"errorCode":"3254","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3254: ODBC--Can't lock all records.","rootCause":"The Access/Jet ODBC layer, driver, data source, server, query, data type, or connection state rejected the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Capture the native ODBC error, verify DSN/connection settings, driver architecture and version, credentials, server reachability, schema and data types, then reproduce with the smallest safe query.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3254: ODBC--Can't lock all records..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","ODBC"],"articleCategories":["Microsoft Access","Legacy Software","ODBC"],"aliases":["Microsoft Access 3254","MS Access error 3254","ODBC--Can't lock all records."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64709,"title":"3255 - ODBC--Can't change connect string parameter.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","ODBC"],"keywords":["3255","Access error 3255","Microsoft Access","MSACCESS","Jet","VBA","ODBC","ODBC--Can't change connect string parameter.","ODBC--Can't change connect string parameter."],"errorCode":"3255","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3255: ODBC--Can't change connect string parameter.","rootCause":"The Access/Jet ODBC layer, driver, data source, server, query, data type, or connection state rejected the operation.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Capture the native ODBC error, verify DSN/connection settings, driver architecture and version, credentials, server reachability, schema and data types, then reproduce with the smallest safe query.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3255: ODBC--Can't change connect string parameter..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","ODBC"],"articleCategories":["Microsoft Access","Legacy Software","ODBC"],"aliases":["Microsoft Access 3255","MS Access error 3255","ODBC--Can't change connect string parameter."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64710,"title":"3256 - Index file not found.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3256","Access error 3256","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Index file not found.","Index file not found."],"errorCode":"3256","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3256: Index file not found.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3256: Index file not found..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3256","MS Access error 3256","Index file not found."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64711,"title":"3257 - Syntax error in WITH OWNERACCESS OPTION declaration.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Security"],"keywords":["3257","Access error 3257","Microsoft Access","MSACCESS","Jet","VBA","Security","Syntax error in WITH OWNERACCESS OPTION declaration.","Syntax error in WITH OWNERACCESS OPTION declaration."],"errorCode":"3257","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3257: Syntax error in WITH OWNERACCESS OPTION declaration.","rootCause":"The operation is blocked by credentials, permissions, ownership, read-only state, or legacy workgroup security.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Verify identity and least-privilege permissions, file/share rights, database ownership and legacy workgroup configuration; do not weaken security controls globally.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3257: Syntax error in WITH OWNERACCESS OPTION declaration..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Security"],"articleCategories":["Microsoft Access","Legacy Software","Security"],"aliases":["Microsoft Access 3257","MS Access error 3257","Syntax error in WITH OWNERACCESS OPTION declaration."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64712,"title":"3258 - Query contains ambiguous (outer) joins.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Queries"],"keywords":["3258","Access error 3258","Microsoft Access","MSACCESS","Jet","VBA","Queries","Query contains ambiguous (outer) joins.","Query contains ambiguous (outer) joins."],"errorCode":"3258","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3258: Query contains ambiguous (outer) joins.","rootCause":"The query, expression, join, parameter, reference, or value is invalid or unsupported in the current context.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Open the query in design/SQL view, validate names, types, joins, parameters and functions, reduce it to the smallest failing expression, then test against a backup copy.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3258: Query contains ambiguous (outer) joins..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Queries"],"articleCategories":["Microsoft Access","Legacy Software","Queries"],"aliases":["Microsoft Access 3258","MS Access error 3258","Query contains ambiguous (outer) joins."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64713,"title":"3259 - Invalid field data type.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3259","Access error 3259","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Invalid field data type.","Invalid field data type."],"errorCode":"3259","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3259: Invalid field data type.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3259: Invalid field data type..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3259","MS Access error 3259","Invalid field data type."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64714,"title":"3260 - Couldn't update; currently locked by user '<value 2>' on machine '<value 1>'.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Locking"],"keywords":["3260","Access error 3260","Microsoft Access","MSACCESS","Jet","VBA","Locking","Couldn't update; currently locked by user '|2' on machine '|1'.","Couldn't update; currently locked by user '<value 2>' on machine '<value 1>'."],"errorCode":"3260","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3260: Couldn't update; currently locked by user '<value 2>' on machine '<value 1>'.","rootCause":"The database, page, record, or object is already locked or in use by another session.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Identify active users and the locking object, coordinate closure or retry, verify share permissions and healthy lock-file cleanup, and never delete a lock file while users remain connected.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3260: Couldn't update; currently locked by user '<value 2>' on machine '<value 1>'..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Locking"],"articleCategories":["Microsoft Access","Legacy Software","Locking"],"aliases":["Microsoft Access 3260","MS Access error 3260","Couldn't update; currently locked by user '|2' on machine '|1'."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64715,"title":"3261 - Reserved or Undocumented Legacy Error","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3261","Access error 3261","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","|","Reserved or Undocumented Legacy Error"],"errorCode":"3261","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3261 is listed without a description in the 1993 source.","rootCause":"The legacy source provides no description for this reserved or undocumented code.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Capture the complete modern error text and operation; do not infer a repair from this numeric value alone.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3261: Reserved or Undocumented Legacy Error.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3261","MS Access error 3261","|"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64716,"title":"3262 - Reserved or Undocumented Legacy Error","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Access Runtime"],"keywords":["3262","Access error 3262","Microsoft Access","MSACCESS","Jet","VBA","Access Runtime","|","Reserved or Undocumented Legacy Error"],"errorCode":"3262","eventId":"","severity":"Low","summary":"Legacy Microsoft Access error 3262 is listed without a description in the 1993 source.","rootCause":"The legacy source provides no description for this reserved or undocumented code.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Capture the complete modern error text and operation; do not infer a repair from this numeric value alone.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3262: Reserved or Undocumented Legacy Error.\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Access Runtime"],"articleCategories":["Microsoft Access","Legacy Software","Access Runtime"],"aliases":["Microsoft Access 3262","MS Access error 3262","|"],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":64717,"title":"3263 - Invalid database object.","category":"Microsoft Access","product":"Microsoft Access 1.x / Jet Database Engine","tags":["Microsoft Access","Legacy","1993","Jet Database"],"keywords":["3263","Access error 3263","Microsoft Access","MSACCESS","Jet","VBA","Jet Database","Invalid database object.","Invalid database object."],"errorCode":"3263","eventId":"","severity":"Medium","summary":"Legacy Microsoft Access error 3263: Invalid database object.","rootCause":"The database engine encountered invalid metadata, schema, index, relation, record, or database state.","resolution":"1. Confirm the exact Access version, database format, operation, object, code line, and complete message.\n2. Back up the database, identify the affected object, confirm file-format and engine compatibility, check storage and locking, then use supported compact/repair or object recreation only on a copy first.\n3. Back up the database and reproduce against a copy before compacting, repairing, converting, deleting, or changing schema.\n4. Validate the original operation, object integrity, record counts, relationships, automation, and multi-user access after correction.","emailScript":"Hello,\n\nWe reviewed the Microsoft Access issue and identified legacy error 3263: Invalid database object..\n\nWe are checking the affected database object, file access, compatibility, and operation against a protected copy before making changes.\n\nPlease keep the database closed until IT Support confirms testing is complete.\n\nThank you,\n\nIT Support","faqSteps":"1. Close Microsoft Access if IT asks you to do so.\n2. Send IT Support the complete message and what you were doing when it appeared.\n3. Do not rename, move, compact, repair, or replace the database unless instructed.\n4. Keep any backup copies unchanged until the issue is resolved.","notes":"Source: ERLIST.TXT, described by the contributor as a 1993 Microsoft Access error list.\nLegacy scope: Microsoft Access 1.x-era Access/VBA, Jet, DDE, ODBC, ISAM, and Btrieve behavior.\nReview status: Needs verification before publication.\n\nThis record preserves historical wording, including obsolete components and placeholders. Modern Microsoft 365 Access may reuse, revise, or no longer emit this number. Confirm current behavior using the full message, Access build, bitness, file format, database engine, driver, and operation. Never run Compact and Repair without a verified backup.","commands":[],"sourceDocument":"ERLIST.TXT","sourceAuthority":"Legacy Microsoft Access error list (1993)","namespace":"MSACCESS-1993","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":["Microsoft Access","VBA","Jet","Jet Database"],"articleCategories":["Microsoft Access","Legacy Software","Jet Database"],"aliases":["Microsoft Access 3263","MS Access error 3263","Invalid database object."],"dateAdded":"2026-08-13","lastUpdated":"2026-08-13"},{"id":910000,"title":"Reset Windows Update Components","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Level 0-6","Disruptive System Repair","Administrator Required","Restart May Be Required"],"keywords":["Reset Windows Update Components","reset windows update","repair windows update","windows update reset","clear windows update cache","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"Medium","summary":"Use a staged, evidence-first Windows Update repair workflow; a complete reset is not the automatic first fix.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"Capture the exact error and environment first. Start with non-destructive checks, then component-store repair, basic cache reset, standard reset, selected aggressive repair, or an approved repair reinstall. Stop after the first level that resolves the original update failure.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. We will use the least disruptive applicable step and verify the original update afterward.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Level 0-6\nSafety level: Disruptive System Repair\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Yes\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["reset windows update","repair windows update","windows update reset","clear windows update cache"],"repairLevel":"Level 0-6","safetyLevel":"Disruptive System Repair","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"yes","parentArticleId":null,"relatedArticleIds":[910001,910002,910003,910004,910005,910006,910007,910008,910009,910010,910011,910012,910013,910014,910015,910016,910017,910018,910019,910020,910021,910022,910023,910024,910025,910026]},{"id":910001,"title":"Windows Update Troubleshooting Workflow","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Level 0-6","Evidence First","Administrator Required","Restart May Be Required"],"keywords":["Windows Update Troubleshooting Workflow","windows update stuck","windows update failed","patch compliance failed","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"Low","summary":"Choose the least disruptive repair level supported by the evidence.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"Check the failed KB, code, build, disk space, restart state, network, date and time, proxy, VPN, update authority, policy, servicing health, compatibility, storage, and timestamped logs before selecting a repair level.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. We will use the least disruptive applicable step and verify the original update afterward.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Level 0-6\nSafety level: Evidence First\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Conditional\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["windows update stuck","windows update failed","patch compliance failed"],"repairLevel":"Level 0-6","safetyLevel":"Evidence First","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"conditional","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":910002,"title":"Collect Windows Update Evidence","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Level 0","Safe Read-Only","Administrator Required","Restart May Be Required"],"keywords":["Collect Windows Update Evidence","windows update evidence","pending restart","update source","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"Low","summary":"Capture system, service, policy, proxy, storage, and failure evidence before making changes.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"Record device and OS details, failed KB, code and timestamp, update source, user impact, free space, pending restart, proxy, VPN, security product, management platform, recent changes, service state, policy, and relevant logs.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. We will use the least disruptive applicable step and verify the original update afterward.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Level 0\nSafety level: Safe Read-Only\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Conditional\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[{"shell":"CMD","command":"systeminfo","risk":"Low","safetyLevel":"Safe Read-Only","admin":true},{"shell":"PowerShell","command":"Get-ComputerInfo | Select-Object WindowsProductName,WindowsVersion,OsBuildNumber,OsArchitecture,OsLastBootUpTime","risk":"Low","safetyLevel":"Safe Read-Only","admin":true},{"shell":"PowerShell","command":"Get-Volume -DriveLetter C | Select-Object DriveLetter,Size,SizeRemaining","risk":"Low","safetyLevel":"Safe Read-Only","admin":true},{"shell":"PowerShell","command":"Get-Service wuauserv,bits,cryptsvc,msiserver,appidsvc,usosvc,dosvc | Select-Object Name,DisplayName,Status,StartType","risk":"Low","safetyLevel":"Safe Read-Only","admin":true},{"shell":"CMD","command":"netsh winhttp show proxy","risk":"Low","safetyLevel":"Safe Read-Only","admin":true},{"shell":"CMD","command":"reg query \"HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate\" /s","risk":"Low","safetyLevel":"Safe Read-Only","admin":true}],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["windows update evidence","pending restart","update source"],"repairLevel":"Level 0","safetyLevel":"Safe Read-Only","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"conditional","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":910003,"title":"Run the Windows Update Troubleshooter","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Level 1","Low Risk","Administrator Required","Restart May Be Required"],"keywords":["Run the Windows Update Troubleshooter","windows update troubleshooter","get help windows update","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"Low","summary":"Run the current supported Windows troubleshooter before resetting components.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"On supported Windows 11 versions, use Settings > System > Troubleshoot > Other troubleshooters > Windows Update > Run. Record what it found and changed. The path and Get Help behavior vary by Windows version.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. We will use the least disruptive applicable step and verify the original update afterward.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Level 1\nSafety level: Low Risk\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Conditional\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["windows update troubleshooter","get help windows update"],"repairLevel":"Level 1","safetyLevel":"Low Risk","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"conditional","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":910004,"title":"Check Windows Update Services","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Level 1","Safe Read-Only","Administrator Required","Restart May Be Required"],"keywords":["Check Windows Update Services","wuauserv","cryptsvc","msiserver","UsoSvc","DoSvc","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"Low","summary":"Inspect update services and startup configuration without assuming every service must run continuously.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"Query service state, configuration, dependencies, and timestamped events. Record exact failures before changing a service or restarting the computer.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. We will use the least disruptive applicable step and verify the original update afterward.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Level 1\nSafety level: Safe Read-Only\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Conditional\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[{"shell":"PowerShell","command":"Get-Service wuauserv,bits,cryptsvc,msiserver,appidsvc,usosvc,dosvc | Select-Object Name,DisplayName,Status,StartType","risk":"Low","safetyLevel":"Safe Read-Only","admin":true},{"shell":"CMD","command":"sc.exe query wuauserv","risk":"Low","safetyLevel":"Safe Read-Only","admin":true},{"shell":"CMD","command":"sc.exe query bits","risk":"Low","safetyLevel":"Safe Read-Only","admin":true},{"shell":"CMD","command":"sc.exe qc wuauserv","risk":"Low","safetyLevel":"Safe Read-Only","admin":true},{"shell":"CMD","command":"sc.exe qc bits","risk":"Low","safetyLevel":"Safe Read-Only","admin":true}],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["wuauserv","cryptsvc","msiserver","UsoSvc","DoSvc"],"repairLevel":"Level 1","safetyLevel":"Safe Read-Only","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"conditional","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":910005,"title":"Clear the Windows Update Download Cache","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Level 3","Disruptive","Administrator Required","Restart May Be Required"],"keywords":["Clear the Windows Update Download Cache","clear SoftwareDistribution","rename SoftwareDistribution","cache corrupted","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"Medium","summary":"Rebuild SoftwareDistribution when evidence indicates damaged cached update content.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"Confirm no update or deployment is active. Stop Windows Update and BITS, rename SoftwareDistribution to a unique backup name, restart services, retry the original update, and retain the backup until verification and retention approval.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. We will use the least disruptive applicable step and verify the original update afterward.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Level 3\nSafety level: Disruptive\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Yes\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[{"shell":"CMD","command":"net stop wuauserv","risk":"Standard","safetyLevel":"Disruptive","admin":true},{"shell":"CMD","command":"net stop bits","risk":"Standard","safetyLevel":"Disruptive","admin":true},{"shell":"CMD","command":"ren \"%SystemRoot%\\SoftwareDistribution\" \"SoftwareDistribution.old\"","risk":"Standard","safetyLevel":"Disruptive","admin":true},{"shell":"CMD","command":"net start bits","risk":"Standard","safetyLevel":"Disruptive","admin":true},{"shell":"CMD","command":"net start wuauserv","risk":"Standard","safetyLevel":"Disruptive","admin":true}],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["clear SoftwareDistribution","rename SoftwareDistribution","cache corrupted"],"repairLevel":"Level 3","safetyLevel":"Disruptive","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"yes","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":910006,"title":"Standard Windows Update Component Reset","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Level 4","Disruptive System Repair","Administrator Required","Restart May Be Required"],"keywords":["Standard Windows Update Component Reset","windows update agent reset","reset windows update services","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"Medium","summary":"Rebuild the update and catalog caches without aggressive ACL, DLL, network, or BITS-queue changes.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"Capture original state, confirm no active installation, stop required services, rename SoftwareDistribution and catroot2 using unique backup names, restart services and Windows, then verify the original KB and managed reporting.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. We will use the least disruptive applicable step and verify the original update afterward.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Level 4\nSafety level: Disruptive System Repair\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Yes\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[{"shell":"CMD","command":"net stop bits","risk":"Standard","safetyLevel":"Disruptive System Repair","admin":true},{"shell":"CMD","command":"net stop wuauserv","risk":"Standard","safetyLevel":"Disruptive System Repair","admin":true},{"shell":"CMD","command":"net stop cryptsvc","risk":"Standard","safetyLevel":"Disruptive System Repair","admin":true},{"shell":"CMD","command":"net stop msiserver","risk":"Standard","safetyLevel":"Disruptive System Repair","admin":true},{"shell":"CMD","command":"ren \"%SystemRoot%\\SoftwareDistribution\" \"SoftwareDistribution.old\"","risk":"Standard","safetyLevel":"Disruptive System Repair","admin":true},{"shell":"CMD","command":"ren \"%SystemRoot%\\System32\\catroot2\" \"catroot2.old\"","risk":"Standard","safetyLevel":"Disruptive System Repair","admin":true},{"shell":"CMD","command":"net start cryptsvc","risk":"Standard","safetyLevel":"Disruptive System Repair","admin":true},{"shell":"CMD","command":"net start bits","risk":"Standard","safetyLevel":"Disruptive System Repair","admin":true},{"shell":"CMD","command":"net start wuauserv","risk":"Standard","safetyLevel":"Disruptive System Repair","admin":true},{"shell":"CMD","command":"net start msiserver","risk":"Standard","safetyLevel":"Disruptive System Repair","admin":true}],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["windows update agent reset","reset windows update services"],"repairLevel":"Level 4","safetyLevel":"Disruptive System Repair","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"yes","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":910007,"title":"Aggressive Windows Update Component Reset","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Level 5","High Impact","Administrator Required","Restart May Be Required","Warning"],"keywords":["Aggressive Windows Update Component Reset","aggressive windows update reset","full windows update reset","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"High","summary":"Escalation hub for individually approved BITS-queue, service-ACL, DLL, proxy, or Winsock repair.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"WARNING: Do not run aggressive operations automatically. Select only the dedicated procedure supported by evidence, capture original state, confirm approval, remote recovery and restart plans, and verify all affected services afterward.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. This step can interrupt services or connectivity, so we will confirm approval and a recovery plan before continuing.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Level 5\nSafety level: High Impact\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Yes\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["aggressive windows update reset","full windows update reset"],"repairLevel":"Level 5","safetyLevel":"High Impact","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"yes","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":910008,"title":"Repair Windows Component Store with DISM","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Level 2","System Repair","Administrator Required","Restart May Be Required"],"keywords":["Repair Windows Component Store with DISM","DISM RestoreHealth","0x800F081F","component store","WinSxS","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"Medium","summary":"Check and repair the Windows component store before SFC when servicing corruption is suspected.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"Run CheckHealth, ScanHealth when required, and RestoreHealth. Review dism.log and the complete result. If source files are unavailable, use only an approved source matching edition, build, language, and architecture.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. We will use the least disruptive applicable step and verify the original update afterward.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Level 2\nSafety level: System Repair\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Conditional\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[{"shell":"CMD","command":"DISM.exe /Online /Cleanup-Image /CheckHealth","risk":"Standard","safetyLevel":"System Repair","admin":true},{"shell":"CMD","command":"DISM.exe /Online /Cleanup-Image /ScanHealth","risk":"Standard","safetyLevel":"System Repair","admin":true},{"shell":"CMD","command":"DISM.exe /Online /Cleanup-Image /RestoreHealth","risk":"Standard","safetyLevel":"System Repair","admin":true}],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["DISM RestoreHealth","0x800F081F","component store","WinSxS"],"repairLevel":"Level 2","safetyLevel":"System Repair","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"conditional","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":910009,"title":"Repair Windows System Files with SFC","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Level 2","System Repair","Administrator Required","Restart May Be Required"],"keywords":["Repair Windows System Files with SFC","SFC scannow","System File Checker","CBS corruption","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"Medium","summary":"Verify and repair protected system files after component-store health is established.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"Run SFC elevated, review CBS.log, restart when requested, and retry the original KB. A completed scan alone does not prove Windows Update is repaired.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. We will use the least disruptive applicable step and verify the original update afterward.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Level 2\nSafety level: System Repair\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Conditional\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[{"shell":"CMD","command":"sfc /scannow","risk":"Standard","safetyLevel":"System Repair","admin":true}],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["SFC scannow","System File Checker","CBS corruption"],"repairLevel":"Level 2","safetyLevel":"System Repair","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"conditional","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":910010,"title":"Rename SoftwareDistribution","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Level 3","Disruptive","Administrator Required","Restart May Be Required"],"keywords":["Rename SoftwareDistribution","SoftwareDistribution.old","DataStore","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"Medium","summary":"Preserve and replace the Windows Update working database and download cache safely.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"Stop required services, confirm the source exists, generate a unique timestamped backup name, rename rather than delete, record the path, restart services, and confirm Windows recreates the active folder. Use -WhatIf before the provided PowerShell example.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. We will use the least disruptive applicable step and verify the original update afterward.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Level 3\nSafety level: Disruptive\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Yes\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[{"shell":"PowerShell","command":"$stamp=Get-Date -Format 'yyyyMMdd-HHmmss'; Rename-Item -LiteralPath \"$env:SystemRoot\\SoftwareDistribution\" -NewName \"SoftwareDistribution.old-$stamp\" -WhatIf","risk":"Standard","safetyLevel":"Disruptive","admin":true}],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["SoftwareDistribution.old","DataStore"],"repairLevel":"Level 3","safetyLevel":"Disruptive","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"yes","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":910011,"title":"Rename catroot2","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Level 4","Disruptive","Administrator Required","Restart May Be Required"],"keywords":["Rename catroot2","catroot2.old","catalog cache","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"Medium","summary":"Rebuild the Windows servicing catalog database without touching catroot.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"Stop Cryptographic Services, confirm catroot2 exists, generate a unique backup name, rename catroot2, restart the service, and confirm recreation. Never overwrite or automatically delete an earlier backup.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. We will use the least disruptive applicable step and verify the original update afterward.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Level 4\nSafety level: Disruptive\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Yes\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[{"shell":"PowerShell","command":"$stamp=Get-Date -Format 'yyyyMMdd-HHmmss'; Rename-Item -LiteralPath \"$env:SystemRoot\\System32\\catroot2\" -NewName \"catroot2.old-$stamp\" -WhatIf","risk":"Standard","safetyLevel":"Disruptive","admin":true}],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["catroot2.old","catalog cache"],"repairLevel":"Level 4","safetyLevel":"Disruptive","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"yes","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":910012,"title":"Clear BITS Transfer Queue","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Level 5","High Impact","Administrator Required","Restart May Be Required","Warning"],"keywords":["Clear BITS Transfer Queue","qmgr.dat","qmgr files","BITS queue","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"High","summary":"Remove only a proven stale BITS job after checking ownership and deployment impact.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"WARNING: Jobs may belong to RMM, Intune, or software deployment. Inventory all jobs, identify the affected job, obtain approval, and remove only that job. Do not routinely delete qmgr files.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. This step can interrupt services or connectivity, so we will confirm approval and a recovery plan before continuing.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Level 5\nSafety level: High Impact\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Yes\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[{"shell":"PowerShell","command":"Get-BitsTransfer -AllUsers | Select-Object DisplayName,OwnerAccount,JobState,CreationTime","risk":"High","safetyLevel":"High Impact","admin":true},{"shell":"PowerShell","command":"Get-BitsTransfer -AllUsers | Where-Object DisplayName -eq '<VERIFIED JOB>' | Remove-BitsTransfer -WhatIf","risk":"High","safetyLevel":"High Impact","admin":true}],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["qmgr.dat","qmgr files","BITS queue"],"repairLevel":"Level 5","safetyLevel":"High Impact","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"yes","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":910013,"title":"Reset BITS and Windows Update Service Permissions","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Level 5","High Impact","Administrator Required","Restart May Be Required","Warning"],"keywords":["Reset BITS and Windows Update Service Permissions","service permissions","service ACL","sc sdshow","sdset","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"High","summary":"Repair a proven damaged service security descriptor using a verified version-specific baseline.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"WARNING: Export current descriptors first. Do not apply historical ACL strings without validating them for the exact supported Windows version; escalate if no trustworthy baseline is available.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. This step can interrupt services or connectivity, so we will confirm approval and a recovery plan before continuing.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Level 5\nSafety level: High Impact\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Yes\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[{"shell":"CMD","command":"sc.exe sdshow bits","risk":"High","safetyLevel":"High Impact","admin":true},{"shell":"CMD","command":"sc.exe sdshow wuauserv","risk":"High","safetyLevel":"High Impact","admin":true}],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["service permissions","service ACL","sc sdshow","sdset"],"repairLevel":"Level 5","safetyLevel":"High Impact","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"yes","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":910014,"title":"Re-register Windows Update DLLs","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Level 5","High Impact","Administrator Required","Restart May Be Required","Warning"],"keywords":["Re-register Windows Update DLLs","Windows Update DLLs","regsvr32 windows update","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"High","summary":"Register only a specifically verified update component whose COM registration is proven damaged.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"WARNING: Blanket historical regsvr32 lists contain obsolete or non-registering files. Verify existence, architecture, applicability, and registration support; log results and do not suppress diagnostic errors.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. This step can interrupt services or connectivity, so we will confirm approval and a recovery plan before continuing.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Level 5\nSafety level: High Impact\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Yes\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[{"shell":"CMD","command":"regsvr32 <VERIFIED-WINDOWS-UPDATE-COMPONENT.dll>","risk":"High","safetyLevel":"High Impact","admin":true}],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["Windows Update DLLs","regsvr32 windows update"],"repairLevel":"Level 5","safetyLevel":"High Impact","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"yes","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":910015,"title":"Reset WinHTTP Proxy for Windows Update","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Level 5","High Impact","Administrator Required","Restart May Be Required","Warning"],"keywords":["Reset WinHTTP Proxy for Windows Update","Windows Update proxy","WinHTTP proxy","0x8024401C","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"High","summary":"Reset WinHTTP only when captured evidence proves its proxy is incorrect.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"WARNING: Record current configuration and determine whether WSUS or the organization requires it. Resetting a required proxy can break updates and management; restore the approved setting after testing.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. This step can interrupt services or connectivity, so we will confirm approval and a recovery plan before continuing.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Level 5\nSafety level: High Impact\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Yes\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[{"shell":"CMD","command":"netsh winhttp show proxy","risk":"High","safetyLevel":"High Impact","admin":true},{"shell":"CMD","command":"netsh winhttp reset proxy","risk":"High","safetyLevel":"High Impact","admin":true}],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["Windows Update proxy","WinHTTP proxy","0x8024401C"],"repairLevel":"Level 5","safetyLevel":"High Impact","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"yes","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":910016,"title":"Reset Winsock After Windows Update Network Failures","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Level 5","High Impact","Administrator Required","Restart May Be Required","Warning"],"keywords":["Reset Winsock After Windows Update Network Failures","Winsock reset","Windows Update network failure","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"High","summary":"Reset Winsock only after evidence indicates catalog corruption rather than DNS, proxy, TLS, VPN, or firewall trouble.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"WARNING: Restart is required and VPN, RMM, remote desktop, security filters, and applications may be interrupted. Capture state and confirm an alternate recovery path first.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. This step can interrupt services or connectivity, so we will confirm approval and a recovery plan before continuing.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Level 5\nSafety level: High Impact\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Yes\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[{"shell":"CMD","command":"netsh winsock show catalog","risk":"High","safetyLevel":"High Impact","admin":true},{"shell":"CMD","command":"netsh winsock reset","risk":"High","safetyLevel":"High Impact","admin":true}],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["Winsock reset","Windows Update network failure"],"repairLevel":"Level 5","safetyLevel":"High Impact","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"yes","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":910017,"title":"Repair Windows Update Using PowerShell","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Level 3-5","Disruptive System Repair","Administrator Required","Restart May Be Required"],"keywords":["Repair Windows Update Using PowerShell","PowerShell Windows Update reset","reset windows update script","audit mode","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"Medium","summary":"Use explicit Audit, Basic, Standard, or individually selected Aggressive modes instead of an opaque reset script.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"Audit makes no changes; Basic resets SoftwareDistribution; Standard also resets catroot2. Aggressive operations require separate selection, warnings, confirmation, logging, rollback data, meaningful exit codes, and verification. No automation script is included until it is tested in an authorized lab.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. We will use the least disruptive applicable step and verify the original update afterward.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Level 3-5\nSafety level: Disruptive System Repair\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Yes\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["PowerShell Windows Update reset","reset windows update script","audit mode"],"repairLevel":"Level 3-5","safetyLevel":"Disruptive System Repair","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"yes","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":910018,"title":"Fix Problems Using Windows Update Repair Reinstall","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Level 6","High Impact","Administrator Required","Restart May Be Required","Warning"],"keywords":["Fix Problems Using Windows Update Repair Reinstall","repair install","in-place upgrade","reinstall current version of Windows","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"High","summary":"Use a supported repair reinstall or approved in-place repair only after lower levels fail.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"Back up data; confirm BitLocker recovery, edition, build, language, architecture, licensing, free space, application compatibility, maintenance approval, and recovery access. Use only options explicitly supported by the installed Windows version.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. This step can interrupt services or connectivity, so we will confirm approval and a recovery plan before continuing.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Level 6\nSafety level: High Impact\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Yes\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["repair install","in-place upgrade","reinstall current version of Windows"],"repairLevel":"Level 6","safetyLevel":"High Impact","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"yes","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":910019,"title":"Windows Update Reset on Managed Devices","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Managed Device","High Impact","Administrator Required","Restart May Be Required","Warning"],"keywords":["Windows Update Reset on Managed Devices","managed windows update","update ring","patch compliance failed","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"High","summary":"Identify and preserve the management authority before local update repair.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"WARNING: Obtain management approval before changing a managed endpoint. Determine whether Microsoft Update, WUfB, WSUS, Intune, Configuration Manager, or RMM controls updates. Preserve policy and agent state, coordinate maintenance, and verify reporting after repair.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. This step can interrupt services or connectivity, so we will confirm approval and a recovery plan before continuing.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Managed Device\nSafety level: High Impact\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Yes\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[{"shell":"CMD","command":"reg query \"HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate\" /s","risk":"High","safetyLevel":"High Impact","admin":true},{"shell":"CMD","command":"gpresult /h \"%TEMP%\\CopyCat-WindowsUpdate-GP.html\"","risk":"High","safetyLevel":"High Impact","admin":true}],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["managed windows update","update ring","patch compliance failed"],"repairLevel":"Managed Device","safetyLevel":"High Impact","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"yes","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":910020,"title":"Windows Update Reset on WSUS Devices","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Managed Device","High Impact","Administrator Required","Restart May Be Required","Warning"],"keywords":["Windows Update Reset on WSUS Devices","WSUS reset","WUServer","UseWUServer","DisableDualScan","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"High","summary":"Separate local cache problems from WSUS policy, reachability, approval, synchronization, and reporting failures.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"WARNING: Do not remove or bypass WSUS policy without approval. Record WSUS policy and URL, review events and server state, and confirm the client reports to the intended WSUS server after repair.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. This step can interrupt services or connectivity, so we will confirm approval and a recovery plan before continuing.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Managed Device\nSafety level: High Impact\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Yes\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[{"shell":"CMD","command":"reg query \"HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate\" /s","risk":"High","safetyLevel":"High Impact","admin":true}],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["WSUS reset","WUServer","UseWUServer","DisableDualScan"],"repairLevel":"Managed Device","safetyLevel":"High Impact","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"yes","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":910021,"title":"Windows Update Reset on Intune-Managed Devices","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Managed Device","High Impact","Administrator Required","Restart May Be Required","Warning"],"keywords":["Windows Update Reset on Intune-Managed Devices","Intune update ring","Windows Update for Business","TargetReleaseVersion","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"High","summary":"Preserve Intune update-ring and feature or quality update context before local repair.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"WARNING: Obtain management approval and do not edit policy-backed values locally. Review assigned policy and status, coordinate resets with active remediations, and verify both the original update and Intune reporting.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. This step can interrupt services or connectivity, so we will confirm approval and a recovery plan before continuing.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Managed Device\nSafety level: High Impact\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Yes\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["Intune update ring","Windows Update for Business","TargetReleaseVersion"],"repairLevel":"Managed Device","safetyLevel":"High Impact","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"yes","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":910022,"title":"Windows Update Reset on Windows Server","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Server","High Impact","Administrator Required","Restart May Be Required","Warning"],"keywords":["Windows Update Reset on Windows Server","Windows Server update reset","server patch failure","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"High","summary":"Review server roles, clusters, workloads, backup, maintenance, and reboot impact before repair.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"WARNING: Obtain maintenance approval and confirm recovery access before changing a production server. Capture update authority, roles and servicing state, coordinate application or cluster owners, maintain rollback and reconnection plans, and verify server roles—not only Windows Update—after restart.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. This step can interrupt services or connectivity, so we will confirm approval and a recovery plan before continuing.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Server\nSafety level: High Impact\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Yes\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["Windows Server update reset","server patch failure"],"repairLevel":"Server","safetyLevel":"High Impact","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"yes","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":910023,"title":"Verify Windows Update After Repair","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Verification","Safe Read-Only","Administrator Required","Restart May Be Required"],"keywords":["Verify Windows Update After Repair","verify Windows Update","patch compliance","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"Low","summary":"Prove service, cache, KB, build, reporting, and connectivity health after repair.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"Check services and cache recreation, scan and install the original KB, restart if required, confirm the expected build, review timestamped events, verify managed reporting, and retest network, proxy, VPN, RMM, and applications after network repair.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. We will use the least disruptive applicable step and verify the original update afterward.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Verification\nSafety level: Safe Read-Only\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Conditional\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[{"shell":"PowerShell","command":"Get-Service wuauserv,bits,cryptsvc,msiserver | Select-Object Name,Status,StartType","risk":"Low","safetyLevel":"Safe Read-Only","admin":true},{"shell":"PowerShell","command":"Test-Path \"$env:SystemRoot\\SoftwareDistribution\"","risk":"Low","safetyLevel":"Safe Read-Only","admin":true},{"shell":"PowerShell","command":"Test-Path \"$env:SystemRoot\\System32\\catroot2\"","risk":"Low","safetyLevel":"Safe Read-Only","admin":true},{"shell":"CMD","command":"DISM.exe /Online /Cleanup-Image /CheckHealth","risk":"Low","safetyLevel":"Safe Read-Only","admin":true},{"shell":"CMD","command":"sfc /verifyonly","risk":"Low","safetyLevel":"Safe Read-Only","admin":true}],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["verify Windows Update","patch compliance"],"repairLevel":"Verification","safetyLevel":"Safe Read-Only","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"conditional","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":910024,"title":"Windows Update Reset Did Not Resolve the Error","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Escalation","Safe Read-Only","Administrator Required","Restart May Be Required"],"keywords":["Windows Update Reset Did Not Resolve the Error","Windows Update reset failed","update still failing","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"Low","summary":"Return to root-cause analysis instead of repeating the same reset.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"Review the original code, CBS and DISM logs, WindowsUpdateClient events, SetupDiag, setup logs, repair source, storage, disk space, drivers, applications, firmware, security controls, proxy and TLS inspection, policy, and known KB issues. Escalate with evidence or consider approved Level 6 repair.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. We will use the least disruptive applicable step and verify the original update afterward.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Escalation\nSafety level: Safe Read-Only\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Conditional\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["Windows Update reset failed","update still failing"],"repairLevel":"Escalation","safetyLevel":"Safe Read-Only","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"conditional","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":910025,"title":"Windows Update Logs and Evidence","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Level 0","Safe Read-Only","Administrator Required","Restart May Be Required"],"keywords":["Windows Update Logs and Evidence","CBS.log","DISM.log","WindowsUpdate.log","SetupDiag","ReportingEvents.log","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"Low","summary":"Collect servicing, update, setup, BITS, and event evidence while protecting sensitive data.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"Review CBS.log, dism.log, ReportingEvents.log, Panther and rollback logs, SetupDiagResults.log, and WindowsUpdateClient, UpdateOrchestrator, and Bits-Client logs. Redact names, internal servers, proxies, URLs, and paths before external sharing.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. We will use the least disruptive applicable step and verify the original update afterward.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Level 0\nSafety level: Safe Read-Only\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Conditional\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[{"shell":"PowerShell","command":"Get-WindowsUpdateLog","risk":"Low","safetyLevel":"Safe Read-Only","admin":true},{"shell":"PowerShell","command":"Get-Content \"$env:windir\\Logs\\CBS\\CBS.log\" -Tail 200","risk":"Low","safetyLevel":"Safe Read-Only","admin":true},{"shell":"PowerShell","command":"Select-String -Path \"$env:windir\\Logs\\CBS\\CBS.log\" -Pattern 'error','failed','corrupt','missing'","risk":"Low","safetyLevel":"Safe Read-Only","admin":true}],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["CBS.log","DISM.log","WindowsUpdate.log","SetupDiag","ReportingEvents.log"],"repairLevel":"Level 0","safetyLevel":"Safe Read-Only","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"conditional","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":910026,"title":"Restore Windows Update Configuration After Troubleshooting","category":"Patch Management","product":"Windows Update","tags":["Windows Update","Post-Repair","Configuration Change","Administrator Required","Restart May Be Required"],"keywords":["Restore Windows Update Configuration After Troubleshooting","restore windows update settings","restore proxy","restore update policy","Windows 10","Windows 11","Windows Server","Microsoft Update","servicing","patch repair"],"errorCode":"","eventId":"","severity":"Low","summary":"Restore approved proxy, service, policy, and management state after temporary diagnostic changes.","rootCause":"Windows Update failures may originate from cache damage, servicing corruption, pending work, disk space, policy, WSUS or Intune management, proxy or TLS controls, compatibility, storage, drivers, or an active installation. A component reset is not a universal first step.","resolution":"Compare final state with captured evidence. Restore only documented approved settings, retain cache backups until validation and retention approval, restart as planned, and verify Windows Update, applications, VPN, RMM, WSUS, or Intune reporting.","emailScript":"Hello,\n\nWe reviewed the Windows Update issue and are using a staged repair process based on the error and evidence. We will use the least disruptive applicable step and verify the original update afterward.\n\nPlease save your work and let us know if a restart window must be coordinated.\n\nThank you,\n\nIT Support","faqSteps":"Please save your work and keep the computer connected to power and a stable network. Run reset commands only when instructed by IT Support. A restart or approved maintenance window may be required.","notes":"Repair level: Post-Repair\nSafety level: Configuration Change\nAdministrator required: Yes\nRestart required: Conditional; recommended after standard or higher repair\nRemote-session risk: Conditional\nReview status: Needs Verification Before Publication\n\nPreserve the exact error, KB, build, logs, service state, policy, proxy, authority, and backup names. Do not disable security, remove managed policy, overwrite backups, kill svchost.exe broadly, or claim success merely because commands completed. Commands were imported as references and were not executed during this content update.","commands":[],"sourceDocument":"COPYCAT RESET WINDOWS UPDATE COMPONENTS ARTICLE COLLECTION","sourceAuthority":"User-supplied CopyCat collection specification","namespace":"WIN-WU-REPAIR","platforms":["windows"],"lastVerified":"","vendors":["Microsoft"],"products":["Windows 10","Windows 11","Windows Server","Windows Update"],"technologies":["Windows Update","BITS","Component-Based Servicing","DISM","SFC","SoftwareDistribution","catroot2"],"articleCategories":["Windows","Windows Update","Windows Repair","Servicing","Patch Management"],"aliases":["restore windows update settings","restore proxy","restore update policy"],"repairLevel":"Post-Repair","safetyLevel":"Configuration Change","adminRequired":"yes","restartRequired":"conditional","remoteSessionRisk":"conditional","parentArticleId":910000,"relatedArticleIds":[910000]},{"id":880100,"title":"HTTP 100 Continue","category":"HTTP","product":"HTTP","tags":["1xx","Informational","Registered","IANA","IETF"],"keywords":["100","HTTP 100","Continue","HTTP status","response code","web error","API error","Informational","browser error","web server","gateway"],"errorCode":"100","eventId":"","severity":"Low","summary":"100 Continue is an HTTP informational response. The request was received and processing is continuing.","rootCause":"The responding HTTP component returned 100 Continue.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 100 Continue. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 100 Continue. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 1xx Informational\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.2.1\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 100 Continue\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.2.1","registrationStatus":"registered","responseClass":"1xx","className":"Informational","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880101,"title":"HTTP 101 Switching Protocols","category":"HTTP","product":"HTTP","tags":["1xx","Informational","Registered","IANA","IETF"],"keywords":["101","HTTP 101","Switching Protocols","HTTP status","response code","web error","API error","Informational","browser error","web server","gateway"],"errorCode":"101","eventId":"","severity":"Low","summary":"101 Switching Protocols is an HTTP informational response. The request was received and processing is continuing.","rootCause":"The responding HTTP component returned 101 Switching Protocols.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 101 Switching Protocols. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 101 Switching Protocols. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 1xx Informational\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.2.2\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 101 Switching Protocols\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.2.2","registrationStatus":"registered","responseClass":"1xx","className":"Informational","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880102,"title":"HTTP 102 Processing","category":"HTTP","product":"HTTP","tags":["1xx","Informational","Registered","IANA","IETF"],"keywords":["102","HTTP 102","Processing","HTTP status","response code","web error","API error","Informational","browser error","web server","gateway"],"errorCode":"102","eventId":"","severity":"Low","summary":"102 Processing is an HTTP informational response. The request was received and processing is continuing.","rootCause":"The responding HTTP component returned 102 Processing.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 102 Processing. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 102 Processing. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 1xx Informational\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 2518\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 102 Processing\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 2518","registrationStatus":"registered","responseClass":"1xx","className":"Informational","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880103,"title":"HTTP 103 Early Hints","category":"HTTP","product":"HTTP","tags":["1xx","Informational","Registered","IANA","IETF"],"keywords":["103","HTTP 103","Early Hints","HTTP status","response code","web error","API error","Informational","browser error","web server","gateway"],"errorCode":"103","eventId":"","severity":"Low","summary":"103 Early Hints is an HTTP informational response. The request was received and processing is continuing.","rootCause":"The responding HTTP component returned 103 Early Hints.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 103 Early Hints. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 103 Early Hints. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 1xx Informational\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 8297\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 103 Early Hints\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 8297","registrationStatus":"registered","responseClass":"1xx","className":"Informational","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880104,"title":"HTTP 104 Upload Resumption Supported","category":"HTTP","product":"HTTP","tags":["1xx","Informational","Temporary","IANA","IETF"],"keywords":["104","HTTP 104","Upload Resumption Supported","temporary registration","expires 2026-11-13","HTTP status","response code","web error","API error","Informational","browser error","web server","gateway"],"errorCode":"104","eventId":"","severity":"Low","summary":"104 Upload Resumption Supported is an HTTP informational response. The request was received and processing is continuing.","rootCause":"The responding HTTP component returned 104 Upload Resumption Supported.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 104 Upload Resumption Supported. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 104 Upload Resumption Supported. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 1xx Informational\nRegistration status: temporary\nSource authority: IANA\nDefining standard: draft-ietf-httpbis-resumable-upload-05\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\nTemporary registration expires 2026-11-13 and requires re-verification.\nSearch aliases: temporary registration; expires 2026-11-13\n\nTicket notes:\nHTTP Status: 104 Upload Resumption Supported\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"draft-ietf-httpbis-resumable-upload-05","registrationStatus":"temporary","responseClass":"1xx","className":"Informational","aliases":["temporary registration","expires 2026-11-13"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880200,"title":"HTTP 200 OK","category":"HTTP","product":"HTTP","tags":["2xx","Success","Registered","IANA","IETF"],"keywords":["200","HTTP 200","OK","HTTP status","response code","web error","API error","Success","browser error","web server","gateway"],"errorCode":"200","eventId":"","severity":"Low","summary":"200 OK is an HTTP success response. The request was received and accepted; the exact result depends on the method and code.","rootCause":"The responding HTTP component returned 200 OK.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 200 OK. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 200 OK. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 2xx Success\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.3.1\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 200 OK\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.3.1","registrationStatus":"registered","responseClass":"2xx","className":"Success","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880201,"title":"HTTP 201 Created","category":"HTTP","product":"HTTP","tags":["2xx","Success","Registered","IANA","IETF"],"keywords":["201","HTTP 201","Created","HTTP status","response code","web error","API error","Success","browser error","web server","gateway"],"errorCode":"201","eventId":"","severity":"Low","summary":"201 Created is an HTTP success response. The request was received and accepted; the exact result depends on the method and code.","rootCause":"The responding HTTP component returned 201 Created.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 201 Created. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 201 Created. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 2xx Success\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.3.2\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 201 Created\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.3.2","registrationStatus":"registered","responseClass":"2xx","className":"Success","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880202,"title":"HTTP 202 Accepted","category":"HTTP","product":"HTTP","tags":["2xx","Success","Registered","IANA","IETF"],"keywords":["202","HTTP 202","Accepted","HTTP status","response code","web error","API error","Success","browser error","web server","gateway"],"errorCode":"202","eventId":"","severity":"Low","summary":"202 Accepted is an HTTP success response. The request was received and accepted; the exact result depends on the method and code.","rootCause":"The responding HTTP component returned 202 Accepted.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 202 Accepted. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 202 Accepted. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 2xx Success\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.3.3\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 202 Accepted\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.3.3","registrationStatus":"registered","responseClass":"2xx","className":"Success","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880203,"title":"HTTP 203 Non-Authoritative Information","category":"HTTP","product":"HTTP","tags":["2xx","Success","Registered","IANA","IETF"],"keywords":["203","HTTP 203","Non-Authoritative Information","HTTP status","response code","web error","API error","Success","browser error","web server","gateway"],"errorCode":"203","eventId":"","severity":"Low","summary":"203 Non-Authoritative Information is an HTTP success response. The request was received and accepted; the exact result depends on the method and code.","rootCause":"The responding HTTP component returned 203 Non-Authoritative Information.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 203 Non-Authoritative Information. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 203 Non-Authoritative Information. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 2xx Success\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.3.4\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 203 Non-Authoritative Information\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.3.4","registrationStatus":"registered","responseClass":"2xx","className":"Success","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880204,"title":"HTTP 204 No Content","category":"HTTP","product":"HTTP","tags":["2xx","Success","Registered","IANA","IETF"],"keywords":["204","HTTP 204","No Content","HTTP status","response code","web error","API error","Success","browser error","web server","gateway"],"errorCode":"204","eventId":"","severity":"Low","summary":"204 No Content is an HTTP success response. The request was received and accepted; the exact result depends on the method and code.","rootCause":"The responding HTTP component returned 204 No Content.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 204 No Content. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 204 No Content. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 2xx Success\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.3.5\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 204 No Content\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.3.5","registrationStatus":"registered","responseClass":"2xx","className":"Success","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880205,"title":"HTTP 205 Reset Content","category":"HTTP","product":"HTTP","tags":["2xx","Success","Registered","IANA","IETF"],"keywords":["205","HTTP 205","Reset Content","HTTP status","response code","web error","API error","Success","browser error","web server","gateway"],"errorCode":"205","eventId":"","severity":"Low","summary":"205 Reset Content is an HTTP success response. The request was received and accepted; the exact result depends on the method and code.","rootCause":"The responding HTTP component returned 205 Reset Content.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 205 Reset Content. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 205 Reset Content. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 2xx Success\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.3.6\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 205 Reset Content\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.3.6","registrationStatus":"registered","responseClass":"2xx","className":"Success","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880206,"title":"HTTP 206 Partial Content","category":"HTTP","product":"HTTP","tags":["2xx","Success","Registered","IANA","IETF"],"keywords":["206","HTTP 206","Partial Content","HTTP status","response code","web error","API error","Success","browser error","web server","gateway"],"errorCode":"206","eventId":"","severity":"Low","summary":"206 Partial Content is an HTTP success response. The request was received and accepted; the exact result depends on the method and code.","rootCause":"The responding HTTP component returned 206 Partial Content.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 206 Partial Content. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 206 Partial Content. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 2xx Success\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.3.7\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 206 Partial Content\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.3.7","registrationStatus":"registered","responseClass":"2xx","className":"Success","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880207,"title":"HTTP 207 Multi-Status","category":"HTTP","product":"HTTP","tags":["2xx","Success","Registered","IANA","IETF"],"keywords":["207","HTTP 207","Multi-Status","HTTP status","response code","web error","API error","Success","browser error","web server","gateway"],"errorCode":"207","eventId":"","severity":"Low","summary":"207 Multi-Status is an HTTP success response. The request was received and accepted; the exact result depends on the method and code.","rootCause":"The responding HTTP component returned 207 Multi-Status.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 207 Multi-Status. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 207 Multi-Status. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 2xx Success\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 4918\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 207 Multi-Status\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 4918","registrationStatus":"registered","responseClass":"2xx","className":"Success","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880208,"title":"HTTP 208 Already Reported","category":"HTTP","product":"HTTP","tags":["2xx","Success","Registered","IANA","IETF"],"keywords":["208","HTTP 208","Already Reported","HTTP status","response code","web error","API error","Success","browser error","web server","gateway"],"errorCode":"208","eventId":"","severity":"Low","summary":"208 Already Reported is an HTTP success response. The request was received and accepted; the exact result depends on the method and code.","rootCause":"The responding HTTP component returned 208 Already Reported.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 208 Already Reported. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 208 Already Reported. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 2xx Success\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 5842\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 208 Already Reported\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 5842","registrationStatus":"registered","responseClass":"2xx","className":"Success","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880226,"title":"HTTP 226 IM Used","category":"HTTP","product":"HTTP","tags":["2xx","Success","Registered","IANA","IETF"],"keywords":["226","HTTP 226","IM Used","HTTP status","response code","web error","API error","Success","browser error","web server","gateway"],"errorCode":"226","eventId":"","severity":"Low","summary":"226 IM Used is an HTTP success response. The request was received and accepted; the exact result depends on the method and code.","rootCause":"The responding HTTP component returned 226 IM Used.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 226 IM Used. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 226 IM Used. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 2xx Success\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 3229\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 226 IM Used\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 3229","registrationStatus":"registered","responseClass":"2xx","className":"Success","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880300,"title":"HTTP 300 Multiple Choices","category":"HTTP","product":"HTTP","tags":["3xx","Redirection","Registered","IANA","IETF"],"keywords":["300","HTTP 300","Multiple Choices","HTTP status","response code","web error","API error","Redirection","browser error","web server","gateway"],"errorCode":"300","eventId":"","severity":"Low","summary":"300 Multiple Choices is an HTTP redirection response. Additional client action or cached-state handling is involved.","rootCause":"The responding HTTP component returned 300 Multiple Choices.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 300 Multiple Choices. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 300 Multiple Choices. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 3xx Redirection\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.4.1\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 300 Multiple Choices\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.4.1","registrationStatus":"registered","responseClass":"3xx","className":"Redirection","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880301,"title":"HTTP 301 Moved Permanently","category":"HTTP","product":"HTTP","tags":["3xx","Redirection","Registered","IANA","IETF"],"keywords":["301","HTTP 301","Moved Permanently","HTTP status","response code","web error","API error","Redirection","browser error","web server","gateway"],"errorCode":"301","eventId":"","severity":"Low","summary":"301 Moved Permanently is an HTTP redirection response. Additional client action or cached-state handling is involved.","rootCause":"The responding HTTP component returned 301 Moved Permanently.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 301 Moved Permanently. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 301 Moved Permanently. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 3xx Redirection\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.4.2\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 301 Moved Permanently\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.4.2","registrationStatus":"registered","responseClass":"3xx","className":"Redirection","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880302,"title":"HTTP 302 Found","category":"HTTP","product":"HTTP","tags":["3xx","Redirection","Registered","IANA","IETF"],"keywords":["302","HTTP 302","Found","Moved Temporarily","temporary redirect","HTTP status","response code","web error","API error","Redirection","browser error","web server","gateway"],"errorCode":"302","eventId":"","severity":"Low","summary":"302 Found is an HTTP redirection response. Additional client action or cached-state handling is involved.","rootCause":"The responding HTTP component returned 302 Found.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 302 Found. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 302 Found. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 3xx Redirection\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.4.3\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\nSearch aliases: Moved Temporarily; temporary redirect\n\nTicket notes:\nHTTP Status: 302 Found\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.4.3","registrationStatus":"registered","responseClass":"3xx","className":"Redirection","aliases":["Moved Temporarily","temporary redirect"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880303,"title":"HTTP 303 See Other","category":"HTTP","product":"HTTP","tags":["3xx","Redirection","Registered","IANA","IETF"],"keywords":["303","HTTP 303","See Other","HTTP status","response code","web error","API error","Redirection","browser error","web server","gateway"],"errorCode":"303","eventId":"","severity":"Low","summary":"303 See Other is an HTTP redirection response. Additional client action or cached-state handling is involved.","rootCause":"The responding HTTP component returned 303 See Other.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 303 See Other. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 303 See Other. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 3xx Redirection\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.4.4\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 303 See Other\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.4.4","registrationStatus":"registered","responseClass":"3xx","className":"Redirection","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880304,"title":"HTTP 304 Not Modified","category":"HTTP","product":"HTTP","tags":["3xx","Redirection","Registered","IANA","IETF"],"keywords":["304","HTTP 304","Not Modified","HTTP status","response code","web error","API error","Redirection","browser error","web server","gateway"],"errorCode":"304","eventId":"","severity":"Low","summary":"304 Not Modified is an HTTP redirection response. Additional client action or cached-state handling is involved.","rootCause":"The responding HTTP component returned 304 Not Modified.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 304 Not Modified. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 304 Not Modified. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 3xx Redirection\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.4.5\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 304 Not Modified\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.4.5","registrationStatus":"registered","responseClass":"3xx","className":"Redirection","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880305,"title":"HTTP 305 Use Proxy","category":"HTTP","product":"HTTP","tags":["3xx","Redirection","Deprecated","IANA","IETF"],"keywords":["305","HTTP 305","Use Proxy","historical proxy response","HTTP status","response code","web error","API error","Redirection","browser error","web server","gateway"],"errorCode":"305","eventId":"","severity":"Low","summary":"305 Use Proxy is an HTTP redirection response. Additional client action or cached-state handling is involved.","rootCause":"The responding HTTP component returned 305 Use Proxy.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 305 Use Proxy. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 305 Use Proxy. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 3xx Redirection\nRegistration status: deprecated\nSource authority: IANA\nDefining standard: RFC 9110 §15.4.6\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\nSearch aliases: historical proxy response\n\nTicket notes:\nHTTP Status: 305 Use Proxy\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.4.6","registrationStatus":"deprecated","responseClass":"3xx","className":"Redirection","aliases":["historical proxy response"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880306,"title":"HTTP 306 Unused","category":"HTTP","product":"HTTP","tags":["3xx","Redirection","Unused","IANA","IETF"],"keywords":["306","HTTP 306","Unused","Switch Proxy","obsolete Switch Proxy","HTTP status","response code","web error","API error","Redirection","browser error","web server","gateway"],"errorCode":"306","eventId":"","severity":"Low","summary":"306 Unused is an HTTP redirection response. Additional client action or cached-state handling is involved.","rootCause":"The responding HTTP component returned 306 Unused.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 306 Unused. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 306 Unused. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 3xx Redirection\nRegistration status: unused\nSource authority: IANA\nDefining standard: RFC 9110 §15.4.7\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\nSearch aliases: Switch Proxy; obsolete Switch Proxy\n\nTicket notes:\nHTTP Status: 306 Unused\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.4.7","registrationStatus":"unused","responseClass":"3xx","className":"Redirection","aliases":["Switch Proxy","obsolete Switch Proxy"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880307,"title":"HTTP 307 Temporary Redirect","category":"HTTP","product":"HTTP","tags":["3xx","Redirection","Registered","IANA","IETF"],"keywords":["307","HTTP 307","Temporary Redirect","HTTP status","response code","web error","API error","Redirection","browser error","web server","gateway"],"errorCode":"307","eventId":"","severity":"Low","summary":"307 Temporary Redirect is an HTTP redirection response. Additional client action or cached-state handling is involved.","rootCause":"The responding HTTP component returned 307 Temporary Redirect.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 307 Temporary Redirect. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 307 Temporary Redirect. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 3xx Redirection\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.4.8\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 307 Temporary Redirect\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.4.8","registrationStatus":"registered","responseClass":"3xx","className":"Redirection","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880308,"title":"HTTP 308 Permanent Redirect","category":"HTTP","product":"HTTP","tags":["3xx","Redirection","Registered","IANA","IETF"],"keywords":["308","HTTP 308","Permanent Redirect","HTTP status","response code","web error","API error","Redirection","browser error","web server","gateway"],"errorCode":"308","eventId":"","severity":"Low","summary":"308 Permanent Redirect is an HTTP redirection response. Additional client action or cached-state handling is involved.","rootCause":"The responding HTTP component returned 308 Permanent Redirect.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 308 Permanent Redirect. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 308 Permanent Redirect. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 3xx Redirection\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.4.9\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 308 Permanent Redirect\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.4.9","registrationStatus":"registered","responseClass":"3xx","className":"Redirection","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880400,"title":"HTTP 400 Bad Request","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["400","HTTP 400","Bad Request","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"400","eventId":"","severity":"Medium","summary":"400 Bad Request is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding HTTP component returned 400 Bad Request.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 400 Bad Request. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 400 Bad Request. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.5.1\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 400 Bad Request\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.5.1","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880401,"title":"HTTP 401 Unauthorized","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["401","HTTP 401","Unauthorized","authentication required","invalid credentials","expired token","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"401","eventId":"","severity":"Medium","summary":"401 Unauthorized is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"Credentials are missing, expired, invalid, or not accepted by the responding authentication component.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Inspect WWW-Authenticate, token lifetime, authentication flow, audience, issuer, and responding component. Do not treat 401 as identical to 403.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 401 Unauthorized. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 401 Unauthorized. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.5.2\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry after authentication only when the request and API documentation permit it.\nSearch aliases: authentication required; invalid credentials; expired token\n\nTicket notes:\nHTTP Status: 401 Unauthorized\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.5.2","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":["authentication required","invalid credentials","expired token"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880402,"title":"HTTP 402 Payment Required","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Reserved","IANA","IETF"],"keywords":["402","HTTP 402","Payment Required","payment","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"402","eventId":"","severity":"Medium","summary":"402 Payment Required is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding HTTP component returned 402 Payment Required.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 402 Payment Required. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 402 Payment Required. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: reserved\nSource authority: IANA\nDefining standard: RFC 9110 §15.5.3\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\nSearch aliases: payment\n\nTicket notes:\nHTTP Status: 402 Payment Required\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.5.3","registrationStatus":"reserved","responseClass":"4xx","className":"Client Error","aliases":["payment"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880403,"title":"HTTP 403 Forbidden","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["403","HTTP 403","Forbidden","access denied","authorization","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"403","eventId":"","severity":"Medium","summary":"403 Forbidden is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding component understood the request but refuses to fulfill it.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Confirm identity, authorization, resource policy, conditional access, network restrictions, and whether an intermediary generated the response.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 403 Forbidden. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 403 Forbidden. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.5.4\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry only after authorization or policy is corrected.\nSearch aliases: access denied; authorization\n\nTicket notes:\nHTTP Status: 403 Forbidden\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.5.4","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":["access denied","authorization"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880404,"title":"HTTP 404 Not Found","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["404","HTTP 404","Not Found","page not found","missing resource","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"404","eventId":"","severity":"Medium","summary":"404 Not Found is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding component did not find a current representation of the requested resource, or is unwilling to disclose one.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Verify URL, route, resource identifier, deployment, case sensitivity, API version, and which component returned the response.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 404 Not Found. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 404 Not Found. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.5.5\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry after correcting the resource or route; do not redirect every 404 automatically.\nSearch aliases: page not found; missing resource\n\nTicket notes:\nHTTP Status: 404 Not Found\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.5.5","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":["page not found","missing resource"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880405,"title":"HTTP 405 Method Not Allowed","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["405","HTTP 405","Method Not Allowed","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"405","eventId":"","severity":"Medium","summary":"405 Method Not Allowed is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding HTTP component returned 405 Method Not Allowed.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 405 Method Not Allowed. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 405 Method Not Allowed. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.5.6\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 405 Method Not Allowed\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.5.6","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880406,"title":"HTTP 406 Not Acceptable","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["406","HTTP 406","Not Acceptable","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"406","eventId":"","severity":"Medium","summary":"406 Not Acceptable is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding HTTP component returned 406 Not Acceptable.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 406 Not Acceptable. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 406 Not Acceptable. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.5.7\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 406 Not Acceptable\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.5.7","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880407,"title":"HTTP 407 Proxy Authentication Required","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["407","HTTP 407","Proxy Authentication Required","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"407","eventId":"","severity":"Medium","summary":"407 Proxy Authentication Required is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding HTTP component returned 407 Proxy Authentication Required.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 407 Proxy Authentication Required. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 407 Proxy Authentication Required. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.5.8\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 407 Proxy Authentication Required\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.5.8","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880408,"title":"HTTP 408 Request Timeout","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["408","HTTP 408","Request Timeout","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"408","eventId":"","severity":"Medium","summary":"408 Request Timeout is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The server did not receive a complete request within the time it was prepared to wait.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Capture timing and request size; check client upload speed, proxy timeouts, connection reuse, and server request limits.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 408 Request Timeout. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 408 Request Timeout. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.5.9\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry may be safe for an idempotent request after reviewing duplicate-operation risk.\n\nTicket notes:\nHTTP Status: 408 Request Timeout\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.5.9","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880409,"title":"HTTP 409 Conflict","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["409","HTTP 409","Conflict","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"409","eventId":"","severity":"Medium","summary":"409 Conflict is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding HTTP component returned 409 Conflict.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 409 Conflict. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 409 Conflict. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.5.10\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 409 Conflict\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.5.10","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880410,"title":"HTTP 410 Gone","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["410","HTTP 410","Gone","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"410","eventId":"","severity":"Medium","summary":"410 Gone is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding HTTP component returned 410 Gone.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 410 Gone. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 410 Gone. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.5.11\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 410 Gone\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.5.11","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880411,"title":"HTTP 411 Length Required","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["411","HTTP 411","Length Required","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"411","eventId":"","severity":"Medium","summary":"411 Length Required is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding HTTP component returned 411 Length Required.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 411 Length Required. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 411 Length Required. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.5.12\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 411 Length Required\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.5.12","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880412,"title":"HTTP 412 Precondition Failed","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["412","HTTP 412","Precondition Failed","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"412","eventId":"","severity":"Medium","summary":"412 Precondition Failed is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding HTTP component returned 412 Precondition Failed.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 412 Precondition Failed. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 412 Precondition Failed. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.5.13\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 412 Precondition Failed\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.5.13","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880413,"title":"HTTP 413 Content Too Large","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["413","HTTP 413","Content Too Large","Payload Too Large","Request Entity Too Large","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"413","eventId":"","severity":"Medium","summary":"413 Content Too Large is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The request content exceeds a limit enforced by a server or intermediary.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify the rejecting component and compare request size with application, proxy, gateway, CDN, and web-server limits.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 413 Content Too Large. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 413 Content Too Large. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.5.14\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Reduce the content or change an approved limit; honor Retry-After if supplied.\nSearch aliases: Payload Too Large; Request Entity Too Large\n\nTicket notes:\nHTTP Status: 413 Content Too Large\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.5.14","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":["Payload Too Large","Request Entity Too Large"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880414,"title":"HTTP 414 URI Too Long","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["414","HTTP 414","URI Too Long","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"414","eventId":"","severity":"Medium","summary":"414 URI Too Long is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding HTTP component returned 414 URI Too Long.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 414 URI Too Long. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 414 URI Too Long. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.5.15\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 414 URI Too Long\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.5.15","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880415,"title":"HTTP 415 Unsupported Media Type","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["415","HTTP 415","Unsupported Media Type","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"415","eventId":"","severity":"Medium","summary":"415 Unsupported Media Type is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding HTTP component returned 415 Unsupported Media Type.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 415 Unsupported Media Type. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 415 Unsupported Media Type. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.5.16\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 415 Unsupported Media Type\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.5.16","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880416,"title":"HTTP 416 Range Not Satisfiable","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["416","HTTP 416","Range Not Satisfiable","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"416","eventId":"","severity":"Medium","summary":"416 Range Not Satisfiable is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding HTTP component returned 416 Range Not Satisfiable.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 416 Range Not Satisfiable. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 416 Range Not Satisfiable. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.5.17\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 416 Range Not Satisfiable\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.5.17","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880417,"title":"HTTP 417 Expectation Failed","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["417","HTTP 417","Expectation Failed","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"417","eventId":"","severity":"Medium","summary":"417 Expectation Failed is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding HTTP component returned 417 Expectation Failed.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 417 Expectation Failed. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 417 Expectation Failed. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.5.18\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 417 Expectation Failed\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.5.18","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880418,"title":"HTTP 418 Unused","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Unused","IANA","IETF"],"keywords":["418","HTTP 418","Unused","I'm a Teapot","HTCPCP","historical humorous nonstandard","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"418","eventId":"","severity":"Medium","summary":"418 Unused is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding HTTP component returned 418 Unused.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 418 Unused. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 418 Unused. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: unused\nSource authority: IANA\nDefining standard: RFC 9110 §15.5.19\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\nSearch aliases: I'm a Teapot; HTCPCP; historical humorous nonstandard\n\nTicket notes:\nHTTP Status: 418 Unused\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.5.19","registrationStatus":"unused","responseClass":"4xx","className":"Client Error","aliases":["I'm a Teapot","HTCPCP","historical humorous nonstandard"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880421,"title":"HTTP 421 Misdirected Request","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["421","HTTP 421","Misdirected Request","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"421","eventId":"","severity":"Medium","summary":"421 Misdirected Request is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding HTTP component returned 421 Misdirected Request.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 421 Misdirected Request. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 421 Misdirected Request. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.5.20\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 421 Misdirected Request\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.5.20","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880422,"title":"HTTP 422 Unprocessable Content","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["422","HTTP 422","Unprocessable Content","Unprocessable Entity","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"422","eventId":"","severity":"Medium","summary":"422 Unprocessable Content is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The request syntax and media type may be valid, but the server cannot process the supplied instructions or fields.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Review response validation details, required fields, formats, relationships, business rules, and API schema.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 422 Unprocessable Content. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 422 Unprocessable Content. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.5.21\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry only after correcting the request content.\nSearch aliases: Unprocessable Entity\n\nTicket notes:\nHTTP Status: 422 Unprocessable Content\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.5.21","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":["Unprocessable Entity"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880423,"title":"HTTP 423 Locked","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["423","HTTP 423","Locked","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"423","eventId":"","severity":"Medium","summary":"423 Locked is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding HTTP component returned 423 Locked.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 423 Locked. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 423 Locked. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 4918\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 423 Locked\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 4918","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880424,"title":"HTTP 424 Failed Dependency","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["424","HTTP 424","Failed Dependency","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"424","eventId":"","severity":"Medium","summary":"424 Failed Dependency is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding HTTP component returned 424 Failed Dependency.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 424 Failed Dependency. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 424 Failed Dependency. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 4918\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 424 Failed Dependency\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 4918","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880425,"title":"HTTP 425 Too Early","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["425","HTTP 425","Too Early","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"425","eventId":"","severity":"Medium","summary":"425 Too Early is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding HTTP component returned 425 Too Early.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 425 Too Early. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 425 Too Early. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 8470\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 425 Too Early\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 8470","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880426,"title":"HTTP 426 Upgrade Required","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["426","HTTP 426","Upgrade Required","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"426","eventId":"","severity":"Medium","summary":"426 Upgrade Required is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding HTTP component returned 426 Upgrade Required.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 426 Upgrade Required. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 426 Upgrade Required. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.5.22\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 426 Upgrade Required\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.5.22","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880428,"title":"HTTP 428 Precondition Required","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["428","HTTP 428","Precondition Required","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"428","eventId":"","severity":"Medium","summary":"428 Precondition Required is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding HTTP component returned 428 Precondition Required.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 428 Precondition Required. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 428 Precondition Required. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 6585\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 428 Precondition Required\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 6585","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880429,"title":"HTTP 429 Too Many Requests","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["429","HTTP 429","Too Many Requests","rate limit","rate limited","Retry-After","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"429","eventId":"","severity":"Medium","summary":"429 Too Many Requests is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The requester exceeded a rate or quota policy.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Capture Retry-After and provider rate-limit headers; identify the caller, scope, concurrency, quota window, and retry behavior.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 429 Too Many Requests. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 429 Too Many Requests. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 6585\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Honor Retry-After and use bounded backoff appropriate to the request's idempotency.\nSearch aliases: rate limit; rate limited; Retry-After\n\nTicket notes:\nHTTP Status: 429 Too Many Requests\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 6585","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":["rate limit","rate limited","Retry-After"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880431,"title":"HTTP 431 Request Header Fields Too Large","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["431","HTTP 431","Request Header Fields Too Large","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"431","eventId":"","severity":"Medium","summary":"431 Request Header Fields Too Large is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding HTTP component returned 431 Request Header Fields Too Large.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 431 Request Header Fields Too Large. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 431 Request Header Fields Too Large. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 6585\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 431 Request Header Fields Too Large\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 6585","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880451,"title":"HTTP 451 Unavailable For Legal Reasons","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Registered","IANA","IETF"],"keywords":["451","HTTP 451","Unavailable For Legal Reasons","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"451","eventId":"","severity":"Medium","summary":"451 Unavailable For Legal Reasons is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding HTTP component returned 451 Unavailable For Legal Reasons.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 451 Unavailable For Legal Reasons. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 451 Unavailable For Legal Reasons. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 7725\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 451 Unavailable For Legal Reasons\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 7725","registrationStatus":"registered","responseClass":"4xx","className":"Client Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880500,"title":"HTTP 500 Internal Server Error","category":"HTTP","product":"HTTP","tags":["5xx","Server Error","Registered","IANA","IETF"],"keywords":["500","HTTP 500","Internal Server Error","HTTP status","response code","web error","API error","Server Error","browser error","web server","gateway"],"errorCode":"500","eventId":"","severity":"High","summary":"500 Internal Server Error is an HTTP server error response. A server or intermediary failed to fulfill an apparently valid request.","rootCause":"The responding application or intermediary encountered an unexpected condition.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Correlate the request ID and timestamp with application, server, proxy, and dependency logs; check recent deployments.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 500 Internal Server Error. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 500 Internal Server Error. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 5xx Server Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.6.1\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Manual review is required before retrying non-idempotent operations.\n\nTicket notes:\nHTTP Status: 500 Internal Server Error\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.6.1","registrationStatus":"registered","responseClass":"5xx","className":"Server Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880501,"title":"HTTP 501 Not Implemented","category":"HTTP","product":"HTTP","tags":["5xx","Server Error","Registered","IANA","IETF"],"keywords":["501","HTTP 501","Not Implemented","HTTP status","response code","web error","API error","Server Error","browser error","web server","gateway"],"errorCode":"501","eventId":"","severity":"High","summary":"501 Not Implemented is an HTTP server error response. A server or intermediary failed to fulfill an apparently valid request.","rootCause":"The responding HTTP component returned 501 Not Implemented.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 501 Not Implemented. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 501 Not Implemented. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 5xx Server Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.6.2\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 501 Not Implemented\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.6.2","registrationStatus":"registered","responseClass":"5xx","className":"Server Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880502,"title":"HTTP 502 Bad Gateway","category":"HTTP","product":"HTTP","tags":["5xx","Server Error","Registered","IANA","IETF"],"keywords":["502","HTTP 502","Bad Gateway","upstream error","reverse proxy","HTTP status","response code","web error","API error","Server Error","browser error","web server","gateway"],"errorCode":"502","eventId":"","severity":"High","summary":"502 Bad Gateway is an HTTP server error response. A server or intermediary failed to fulfill an apparently valid request.","rootCause":"A gateway or proxy received an invalid response from an upstream service.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify the gateway; check upstream health, DNS, TLS, port, protocol, routing, limits, and both sides' logs.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 502 Bad Gateway. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 502 Bad Gateway. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 5xx Server Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.6.3\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry after delay only when the method is safe and the upstream failure is transient.\nSearch aliases: upstream error; reverse proxy\n\nTicket notes:\nHTTP Status: 502 Bad Gateway\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.6.3","registrationStatus":"registered","responseClass":"5xx","className":"Server Error","aliases":["upstream error","reverse proxy"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880503,"title":"HTTP 503 Service Unavailable","category":"HTTP","product":"HTTP","tags":["5xx","Server Error","Registered","IANA","IETF"],"keywords":["503","HTTP 503","Service Unavailable","maintenance","overload","Retry-After","HTTP status","response code","web error","API error","Server Error","browser error","web server","gateway"],"errorCode":"503","eventId":"","severity":"High","summary":"503 Service Unavailable is an HTTP server error response. A server or intermediary failed to fulfill an apparently valid request.","rootCause":"The responding service is temporarily unable or unwilling to handle the request.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Check Retry-After, maintenance state, health checks, service status, capacity, dependencies, and load-balancer backend health.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 503 Service Unavailable. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 503 Service Unavailable. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 5xx Server Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.6.4\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Honor Retry-After; do not assume every 503 is a denial-of-service attack.\nSearch aliases: maintenance; overload; Retry-After\n\nTicket notes:\nHTTP Status: 503 Service Unavailable\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.6.4","registrationStatus":"registered","responseClass":"5xx","className":"Server Error","aliases":["maintenance","overload","Retry-After"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880504,"title":"HTTP 504 Gateway Timeout","category":"HTTP","product":"HTTP","tags":["5xx","Server Error","Registered","IANA","IETF"],"keywords":["504","HTTP 504","Gateway Timeout","upstream timeout","proxy timeout","HTTP status","response code","web error","API error","Server Error","browser error","web server","gateway"],"errorCode":"504","eventId":"","severity":"High","summary":"504 Gateway Timeout is an HTTP server error response. A server or intermediary failed to fulfill an apparently valid request.","rootCause":"A gateway or proxy did not receive a timely response from an upstream service.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify the gateway and measure duration; inspect upstream, DNS, database, dependency, connection-pool, and timeout evidence.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 504 Gateway Timeout. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 504 Gateway Timeout. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 5xx Server Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.6.5\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Do not extend every timeout without finding why the upstream request is slow.\nSearch aliases: upstream timeout; proxy timeout\n\nTicket notes:\nHTTP Status: 504 Gateway Timeout\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.6.5","registrationStatus":"registered","responseClass":"5xx","className":"Server Error","aliases":["upstream timeout","proxy timeout"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880505,"title":"HTTP 505 HTTP Version Not Supported","category":"HTTP","product":"HTTP","tags":["5xx","Server Error","Registered","IANA","IETF"],"keywords":["505","HTTP 505","HTTP Version Not Supported","HTTP status","response code","web error","API error","Server Error","browser error","web server","gateway"],"errorCode":"505","eventId":"","severity":"High","summary":"505 HTTP Version Not Supported is an HTTP server error response. A server or intermediary failed to fulfill an apparently valid request.","rootCause":"The responding HTTP component returned 505 HTTP Version Not Supported.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 505 HTTP Version Not Supported. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 505 HTTP Version Not Supported. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 5xx Server Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 9110 §15.6.6\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 505 HTTP Version Not Supported\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110 §15.6.6","registrationStatus":"registered","responseClass":"5xx","className":"Server Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880506,"title":"HTTP 506 Variant Also Negotiates","category":"HTTP","product":"HTTP","tags":["5xx","Server Error","Registered","IANA","IETF"],"keywords":["506","HTTP 506","Variant Also Negotiates","HTTP status","response code","web error","API error","Server Error","browser error","web server","gateway"],"errorCode":"506","eventId":"","severity":"High","summary":"506 Variant Also Negotiates is an HTTP server error response. A server or intermediary failed to fulfill an apparently valid request.","rootCause":"The responding HTTP component returned 506 Variant Also Negotiates.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 506 Variant Also Negotiates. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 506 Variant Also Negotiates. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 5xx Server Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 2295\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 506 Variant Also Negotiates\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 2295","registrationStatus":"registered","responseClass":"5xx","className":"Server Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880507,"title":"HTTP 507 Insufficient Storage","category":"HTTP","product":"HTTP","tags":["5xx","Server Error","Registered","IANA","IETF"],"keywords":["507","HTTP 507","Insufficient Storage","HTTP status","response code","web error","API error","Server Error","browser error","web server","gateway"],"errorCode":"507","eventId":"","severity":"High","summary":"507 Insufficient Storage is an HTTP server error response. A server or intermediary failed to fulfill an apparently valid request.","rootCause":"The responding HTTP component returned 507 Insufficient Storage.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 507 Insufficient Storage. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 507 Insufficient Storage. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 5xx Server Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 4918\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 507 Insufficient Storage\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 4918","registrationStatus":"registered","responseClass":"5xx","className":"Server Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880508,"title":"HTTP 508 Loop Detected","category":"HTTP","product":"HTTP","tags":["5xx","Server Error","Registered","IANA","IETF"],"keywords":["508","HTTP 508","Loop Detected","HTTP status","response code","web error","API error","Server Error","browser error","web server","gateway"],"errorCode":"508","eventId":"","severity":"High","summary":"508 Loop Detected is an HTTP server error response. A server or intermediary failed to fulfill an apparently valid request.","rootCause":"The responding HTTP component returned 508 Loop Detected.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 508 Loop Detected. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 508 Loop Detected. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 5xx Server Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 5842\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\n\nTicket notes:\nHTTP Status: 508 Loop Detected\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 5842","registrationStatus":"registered","responseClass":"5xx","className":"Server Error","aliases":[],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880510,"title":"HTTP 510 Not Extended","category":"HTTP","product":"HTTP","tags":["5xx","Server Error","Historical","IANA","IETF"],"keywords":["510","HTTP 510","Not Extended","obsolete HTTP extension","HTTP status","response code","web error","API error","Server Error","browser error","web server","gateway"],"errorCode":"510","eventId":"","severity":"High","summary":"510 Not Extended is an HTTP server error response. A server or intermediary failed to fulfill an apparently valid request.","rootCause":"The responding HTTP component returned 510 Not Extended.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 510 Not Extended. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 510 Not Extended. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 5xx Server Error\nRegistration status: historical\nSource authority: IANA\nDefining standard: RFC 2774\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\nSearch aliases: obsolete HTTP extension\n\nTicket notes:\nHTTP Status: 510 Not Extended\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 2774","registrationStatus":"historical","responseClass":"5xx","className":"Server Error","aliases":["obsolete HTTP extension"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":880511,"title":"HTTP 511 Network Authentication Required","category":"HTTP","product":"HTTP","tags":["5xx","Server Error","Registered","IANA","IETF"],"keywords":["511","HTTP 511","Network Authentication Required","captive portal","network access authentication","HTTP status","response code","web error","API error","Server Error","browser error","web server","gateway"],"errorCode":"511","eventId":"","severity":"High","summary":"511 Network Authentication Required is an HTTP server error response. A server or intermediary failed to fulfill an apparently valid request.","rootCause":"The client must authenticate to obtain network access, commonly through a captive portal.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Check guest Wi-Fi, network access gateways, interception, and portal authentication; do not confuse this with origin-app authentication.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 511 Network Authentication Required. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 511 Network Authentication Required. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 5xx Server Error\nRegistration status: registered\nSource authority: IANA\nDefining standard: RFC 6585\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry after completing network authentication.\nSearch aliases: captive portal; network access authentication\n\nTicket notes:\nHTTP Status: 511 Network Authentication Required\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 6585","registrationStatus":"registered","responseClass":"5xx","className":"Server Error","aliases":["captive portal","network access authentication"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"namespace":"HTTP"},{"id":881000,"title":"HTTP 105-199 Unassigned","category":"HTTP","product":"HTTP","tags":["HTTP","HTTP Status","Unassigned","IANA","IETF"],"keywords":["105-199","HTTP 105-199","Unassigned","unused HTTP code","unassigned HTTP status","HTTP status","response code","web error","API error","HTTP Status","browser error","web server","gateway"],"errorCode":"105-199","eventId":"","severity":"Low","summary":"105-199 Unassigned is an HTTP http status response. The response must be interpreted using its registered definition and request context.","rootCause":"The responding HTTP component returned 105-199 Unassigned.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 105-199 Unassigned. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 105-199 Unassigned. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: HTTP HTTP Status\nRegistration status: unassigned\nSource authority: IANA\nDefining standard: IANA HTTP Status Code Registry\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\nSearch aliases: unused HTTP code; unassigned HTTP status\n\nTicket notes:\nHTTP Status: 105-199 Unassigned\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"IANA HTTP Status Code Registry","registrationStatus":"unassigned","responseClass":"HTTP","className":"HTTP Status","aliases":["unused HTTP code","unassigned HTTP status"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[],"namespace":"HTTP"},{"id":881001,"title":"HTTP 209-225 Unassigned","category":"HTTP","product":"HTTP","tags":["HTTP","HTTP Status","Unassigned","IANA","IETF"],"keywords":["209-225","HTTP 209-225","Unassigned","unused HTTP code","unassigned HTTP status","HTTP status","response code","web error","API error","HTTP Status","browser error","web server","gateway"],"errorCode":"209-225","eventId":"","severity":"Low","summary":"209-225 Unassigned is an HTTP http status response. The response must be interpreted using its registered definition and request context.","rootCause":"The responding HTTP component returned 209-225 Unassigned.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 209-225 Unassigned. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 209-225 Unassigned. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: HTTP HTTP Status\nRegistration status: unassigned\nSource authority: IANA\nDefining standard: IANA HTTP Status Code Registry\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\nSearch aliases: unused HTTP code; unassigned HTTP status\n\nTicket notes:\nHTTP Status: 209-225 Unassigned\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"IANA HTTP Status Code Registry","registrationStatus":"unassigned","responseClass":"HTTP","className":"HTTP Status","aliases":["unused HTTP code","unassigned HTTP status"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[],"namespace":"HTTP"},{"id":881002,"title":"HTTP 227-299 Unassigned","category":"HTTP","product":"HTTP","tags":["HTTP","HTTP Status","Unassigned","IANA","IETF"],"keywords":["227-299","HTTP 227-299","Unassigned","unused HTTP code","unassigned HTTP status","HTTP status","response code","web error","API error","HTTP Status","browser error","web server","gateway"],"errorCode":"227-299","eventId":"","severity":"Low","summary":"227-299 Unassigned is an HTTP http status response. The response must be interpreted using its registered definition and request context.","rootCause":"The responding HTTP component returned 227-299 Unassigned.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 227-299 Unassigned. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 227-299 Unassigned. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: HTTP HTTP Status\nRegistration status: unassigned\nSource authority: IANA\nDefining standard: IANA HTTP Status Code Registry\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\nSearch aliases: unused HTTP code; unassigned HTTP status\n\nTicket notes:\nHTTP Status: 227-299 Unassigned\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"IANA HTTP Status Code Registry","registrationStatus":"unassigned","responseClass":"HTTP","className":"HTTP Status","aliases":["unused HTTP code","unassigned HTTP status"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[],"namespace":"HTTP"},{"id":881003,"title":"HTTP 309-399 Unassigned","category":"HTTP","product":"HTTP","tags":["HTTP","HTTP Status","Unassigned","IANA","IETF"],"keywords":["309-399","HTTP 309-399","Unassigned","unused HTTP code","unassigned HTTP status","HTTP status","response code","web error","API error","HTTP Status","browser error","web server","gateway"],"errorCode":"309-399","eventId":"","severity":"Low","summary":"309-399 Unassigned is an HTTP http status response. The response must be interpreted using its registered definition and request context.","rootCause":"The responding HTTP component returned 309-399 Unassigned.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 309-399 Unassigned. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 309-399 Unassigned. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: HTTP HTTP Status\nRegistration status: unassigned\nSource authority: IANA\nDefining standard: IANA HTTP Status Code Registry\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\nSearch aliases: unused HTTP code; unassigned HTTP status\n\nTicket notes:\nHTTP Status: 309-399 Unassigned\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"IANA HTTP Status Code Registry","registrationStatus":"unassigned","responseClass":"HTTP","className":"HTTP Status","aliases":["unused HTTP code","unassigned HTTP status"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[],"namespace":"HTTP"},{"id":881004,"title":"HTTP 419-420 Unassigned","category":"HTTP","product":"HTTP","tags":["HTTP","HTTP Status","Unassigned","IANA","IETF"],"keywords":["419-420","HTTP 419-420","Unassigned","unused HTTP code","unassigned HTTP status","HTTP status","response code","web error","API error","HTTP Status","browser error","web server","gateway"],"errorCode":"419-420","eventId":"","severity":"Medium","summary":"419-420 Unassigned is an HTTP http status response. The response must be interpreted using its registered definition and request context.","rootCause":"The responding HTTP component returned 419-420 Unassigned.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 419-420 Unassigned. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 419-420 Unassigned. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: HTTP HTTP Status\nRegistration status: unassigned\nSource authority: IANA\nDefining standard: IANA HTTP Status Code Registry\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\nSearch aliases: unused HTTP code; unassigned HTTP status\n\nTicket notes:\nHTTP Status: 419-420 Unassigned\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"IANA HTTP Status Code Registry","registrationStatus":"unassigned","responseClass":"HTTP","className":"HTTP Status","aliases":["unused HTTP code","unassigned HTTP status"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[],"namespace":"HTTP"},{"id":881005,"title":"HTTP 427 Unassigned","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Unassigned","IANA","IETF"],"keywords":["427","HTTP 427","Unassigned","unused HTTP code","unassigned HTTP status","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"427","eventId":"","severity":"Medium","summary":"427 Unassigned is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding HTTP component returned 427 Unassigned.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 427 Unassigned. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 427 Unassigned. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: unassigned\nSource authority: IANA\nDefining standard: IANA HTTP Status Code Registry\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\nSearch aliases: unused HTTP code; unassigned HTTP status\n\nTicket notes:\nHTTP Status: 427 Unassigned\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"IANA HTTP Status Code Registry","registrationStatus":"unassigned","responseClass":"4xx","className":"Client Error","aliases":["unused HTTP code","unassigned HTTP status"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[],"namespace":"HTTP"},{"id":881006,"title":"HTTP 430 Unassigned","category":"HTTP","product":"HTTP","tags":["4xx","Client Error","Unassigned","IANA","IETF"],"keywords":["430","HTTP 430","Unassigned","unused HTTP code","unassigned HTTP status","HTTP status","response code","web error","API error","Client Error","browser error","web server","gateway"],"errorCode":"430","eventId":"","severity":"Medium","summary":"430 Unassigned is an HTTP client error response. The request cannot be fulfilled in its current form; this does not prove the end user caused the problem.","rootCause":"The responding HTTP component returned 430 Unassigned.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 430 Unassigned. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 430 Unassigned. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 4xx Client Error\nRegistration status: unassigned\nSource authority: IANA\nDefining standard: IANA HTTP Status Code Registry\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\nSearch aliases: unused HTTP code; unassigned HTTP status\n\nTicket notes:\nHTTP Status: 430 Unassigned\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"IANA HTTP Status Code Registry","registrationStatus":"unassigned","responseClass":"4xx","className":"Client Error","aliases":["unused HTTP code","unassigned HTTP status"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[],"namespace":"HTTP"},{"id":881007,"title":"HTTP 432-450 Unassigned","category":"HTTP","product":"HTTP","tags":["HTTP","HTTP Status","Unassigned","IANA","IETF"],"keywords":["432-450","HTTP 432-450","Unassigned","unused HTTP code","unassigned HTTP status","HTTP status","response code","web error","API error","HTTP Status","browser error","web server","gateway"],"errorCode":"432-450","eventId":"","severity":"Medium","summary":"432-450 Unassigned is an HTTP http status response. The response must be interpreted using its registered definition and request context.","rootCause":"The responding HTTP component returned 432-450 Unassigned.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 432-450 Unassigned. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 432-450 Unassigned. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: HTTP HTTP Status\nRegistration status: unassigned\nSource authority: IANA\nDefining standard: IANA HTTP Status Code Registry\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\nSearch aliases: unused HTTP code; unassigned HTTP status\n\nTicket notes:\nHTTP Status: 432-450 Unassigned\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"IANA HTTP Status Code Registry","registrationStatus":"unassigned","responseClass":"HTTP","className":"HTTP Status","aliases":["unused HTTP code","unassigned HTTP status"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[],"namespace":"HTTP"},{"id":881008,"title":"HTTP 452-499 Unassigned","category":"HTTP","product":"HTTP","tags":["HTTP","HTTP Status","Unassigned","IANA","IETF"],"keywords":["452-499","HTTP 452-499","Unassigned","unused HTTP code","unassigned HTTP status","HTTP status","response code","web error","API error","HTTP Status","browser error","web server","gateway"],"errorCode":"452-499","eventId":"","severity":"Medium","summary":"452-499 Unassigned is an HTTP http status response. The response must be interpreted using its registered definition and request context.","rootCause":"The responding HTTP component returned 452-499 Unassigned.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 452-499 Unassigned. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 452-499 Unassigned. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: HTTP HTTP Status\nRegistration status: unassigned\nSource authority: IANA\nDefining standard: IANA HTTP Status Code Registry\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\nSearch aliases: unused HTTP code; unassigned HTTP status\n\nTicket notes:\nHTTP Status: 452-499 Unassigned\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"IANA HTTP Status Code Registry","registrationStatus":"unassigned","responseClass":"HTTP","className":"HTTP Status","aliases":["unused HTTP code","unassigned HTTP status"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[],"namespace":"HTTP"},{"id":881009,"title":"HTTP 509 Unassigned","category":"HTTP","product":"HTTP","tags":["5xx","Server Error","Unassigned","IANA","IETF"],"keywords":["509","HTTP 509","Unassigned","unused HTTP code","unassigned HTTP status","HTTP status","response code","web error","API error","Server Error","browser error","web server","gateway"],"errorCode":"509","eventId":"","severity":"High","summary":"509 Unassigned is an HTTP server error response. A server or intermediary failed to fulfill an apparently valid request.","rootCause":"The responding HTTP component returned 509 Unassigned.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 509 Unassigned. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 509 Unassigned. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: 5xx Server Error\nRegistration status: unassigned\nSource authority: IANA\nDefining standard: IANA HTTP Status Code Registry\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\nSearch aliases: unused HTTP code; unassigned HTTP status\n\nTicket notes:\nHTTP Status: 509 Unassigned\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"IANA HTTP Status Code Registry","registrationStatus":"unassigned","responseClass":"5xx","className":"Server Error","aliases":["unused HTTP code","unassigned HTTP status"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[],"namespace":"HTTP"},{"id":881010,"title":"HTTP 512-599 Unassigned","category":"HTTP","product":"HTTP","tags":["HTTP","HTTP Status","Unassigned","IANA","IETF"],"keywords":["512-599","HTTP 512-599","Unassigned","unused HTTP code","unassigned HTTP status","HTTP status","response code","web error","API error","HTTP Status","browser error","web server","gateway"],"errorCode":"512-599","eventId":"","severity":"High","summary":"512-599 Unassigned is an HTTP http status response. The response must be interpreted using its registered definition and request context.","rootCause":"The responding HTTP component returned 512-599 Unassigned.","resolution":"1. Capture the exact code and reason phrase, request method, redacted URL, timestamp, request and response headers, response body when safe, redirect chain, correlation or request ID, timing, and the server or intermediary that generated the response. Redact authorization, cookies, tokens, API keys, secrets, private query values, and personal data.\n2. Identify which component generated the response, review the defining standard, capture the complete exchange, and check component logs before changing configuration.\n3. Validate the same request against the intended component after the evidence-based correction.","emailScript":"Hello,\n\nWe reviewed the web or API request and identified HTTP 512-599 Unassigned. This response indicates that the request requires further investigation or correction based on the responding service.\n\nWe are reviewing the request details and relevant service logs and will validate the request after the corrective action.\n\nPlease let us know if the issue continues.\n\nThank you,\n\nIT Support","faqSteps":"The service returned HTTP 512-599 Unassigned. Record what you were doing and the approximate time. Retry only if instructed; repeated attempts can duplicate an action or trigger rate limits.","notes":"Protocol: HTTP\nResponse class: HTTP HTTP Status\nRegistration status: unassigned\nSource authority: IANA\nDefining standard: IANA HTTP Status Code Registry\nRegistry: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml\nRetry guidance: Retry behavior depends on the request method, idempotency, response headers, and application documentation.\nSearch aliases: unused HTTP code; unassigned HTTP status\n\nTicket notes:\nHTTP Status: 512-599 Unassigned\nRequest: [URL or endpoint]\nMethod: [GET / POST / PUT / DELETE / OTHER]\nResponding Component: [Unknown / Proxy / Gateway / Web Server / Application]\nObserved: [Timestamp]\nRoot Cause: [Confirmed cause]\nActions: [Actions completed]\nVerification: [Result]","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"IANA HTTP Status Code Registry","registrationStatus":"unassigned","responseClass":"HTTP","className":"HTTP Status","aliases":["unused HTTP code","unassigned HTTP status"],"protocol":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Web Server","Reverse Proxy","Gateway"],"articleCategories":["Web","Networking","Protocols","HTTP","API Errors"],"commands":[],"namespace":"HTTP"},{"id":880000,"title":"HTTP Response Status Codes","category":"HTTP","product":"HTTP","tags":["Protocol Reference","IANA","IETF","Platform-neutral"],"keywords":["HTTP status","response code","1xx","2xx","3xx","4xx","5xx","REST API","web error","browser error"],"errorCode":"","eventId":"","severity":"Low","summary":"HTTP status codes are three-digit responses returned by a server or intermediary after an HTTP request. The first digit identifies the response class; the full exchange and responding component are often required to determine root cause.","rootCause":"An HTTP response describes the result of a request but does not by itself prove which component or condition caused that result. Browser and transport failures can occur without any HTTP response.","resolution":"1. Capture the request and response.\n2. Identify the response class and exact code.\n3. Identify whether the origin, proxy, gateway, CDN, load balancer, authentication service, or application generated it.\n4. Review redacted headers, body, timing, correlation IDs, and matching logs.\n5. Correct the evidenced cause and validate the original request.","emailScript":"Hello,\n\nWe are reviewing the web request and its HTTP response to identify which service returned it and why. We will use the request timestamp and supporting logs to determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open browser developer tools, select Network, reproduce the request, and record the status, method, URL, timing, and safe response details. Do not share passwords, cookies, tokens, or private URLs.","notes":"Classes: 1xx Informational; 2xx Success; 3xx Redirection; 4xx Client Error; 5xx Server Error. A 4xx response does not prove the user caused the problem, and a 5xx response does not prove the origin server generated it. Source: IANA HTTP Status Code Registry; defining framework: RFC 9110.","sourceDocument":"IANA HTTP Status Code Registry","sourceAuthority":"IANA","definingStandard":"RFC 9110","registrationStatus":"reference","responseClass":"All","namespace":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"technologies":["HTTP","HTTPS","REST API","Reverse Proxy","Gateway","CDN"],"commands":[{"shell":"CMD","command":"curl -I -L \"https://example.com\"","risk":"Standard"},{"shell":"CMD","command":"curl -v \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"aliases":[]},{"id":880001,"title":"HTTP Status Codes vs Browser and Transport Errors","category":"HTTP","product":"HTTP / Networking","tags":["HTTP","Networking","Diagnostic Guide","Platform-neutral"],"keywords":["DNS failure","TLS error","connection refused","connection reset","CORS","ERR_NAME_NOT_RESOLVED","ERR_CONNECTION_REFUSED","browser error","not HTTP"],"errorCode":"","eventId":"","severity":"Medium","summary":"An HTTP status requires an HTTP response. DNS, TLS, connection, browser-offline, proxy-connect, CORS, and mixed-content failures may occur before or outside an HTTP response.","rootCause":"Technicians can misclassify browser-generated or transport-layer errors as HTTP status codes when only the visible symptom is captured.","resolution":"1. Check the browser Network panel for an actual response status.\n2. If none exists, test DNS, TCP connectivity, TLS, proxy behavior, and browser enforcement separately.\n3. Capture the exact browser or application error and timestamp.\n4. Review the relevant network and security logs.","emailScript":"Hello,\n\nWe determined that the browser message may be a network or security-layer error rather than an HTTP response. We are checking connectivity, name resolution, encryption, and proxy behavior to identify the failing layer.\n\nThank you,\n\nIT Support","faqSteps":"Record the exact browser message and time. Do not repeatedly enter credentials or bypass certificate warnings. IT Support may ask you to reproduce the issue while collecting network details.","notes":"Examples not necessarily involving HTTP responses: DNS resolution failure, TLS certificate error, connection refused, connection reset, network timeout, browser offline, proxy connection failure, CORS enforcement, mixed content, ERR_NAME_NOT_RESOLVED, ERR_CONNECTION_REFUSED, ERR_CONNECTION_RESET, and ERR_CERT_AUTHORITY_INVALID.","sourceDocument":"CopyCat HTTP Status Expansion","sourceAuthority":"IANA / IETF","definingStandard":"RFC 9110","registrationStatus":"reference","responseClass":"N/A","namespace":"HTTP","platforms":["platform-neutral"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"products":["HTTP"],"technologies":["HTTP","DNS","TLS","Networking"],"commands":[],"aliases":[]},{"id":880002,"title":"How to Check an HTTP Status Code","category":"HTTP","product":"HTTP / Web Browser","tags":["Diagnostic Guide","Browser DevTools","curl","PowerShell","Cross-platform"],"keywords":["check HTTP status","browser network panel","curl headers","Invoke-WebRequest","response headers","request ID","trace ID"],"errorCode":"","eventId":"","severity":"Low","summary":"Use browser developer tools, curl, PowerShell, or application logs to capture the exact HTTP response and identify the component that returned it.","rootCause":"Troubleshooting is delayed when only a screenshot or friendly browser message is collected without the request method, URL, timestamp, headers, timing, response body, or correlation identifiers.","resolution":"1. Open browser developer tools and select Network.\n2. Reproduce the request and select the relevant document, fetch, XHR, image, script, or API call.\n3. Record the status, method, redacted URL, safe headers, timing, and response preview.\n4. Alternatively use curl or Invoke-WebRequest to inspect the response.\n5. Correlate the exact timestamp and request ID with application, proxy, gateway, CDN, or server logs.\n6. Redact authorization, cookies, tokens, API keys, secrets, and private data before sharing evidence.","emailScript":"Hello,\n\nTo investigate the web request, we need to capture the exact HTTP response and the time it occurred. We will use that information to identify which service returned the response and review the matching logs.\n\nThank you,\n\nIT Support","faqSteps":"Open your browser's developer tools, select Network, reproduce the problem, and select the failed request. Record the status and time, but do not send passwords, cookies, tokens, or private URLs.","notes":"Do not assume the first request is the failed request. Browser developer tools may expose sensitive headers and response data; redact before attaching evidence to a ticket. PowerShell exception response behavior can vary by version.","sourceDocument":"CopyCat HTTP Status Expansion","sourceAuthority":"IANA / IETF","definingStandard":"RFC 9110","registrationStatus":"reference","responseClass":"All","namespace":"HTTP","platforms":["windows","macos","linux"],"lastVerified":"2026-08-06","vendors":["IANA","IETF"],"products":["HTTP","Web Browser"],"technologies":["HTTP","HTTPS","Browser DevTools","curl","PowerShell"],"commands":[{"shell":"CMD","command":"curl -I \"https://example.com\"","risk":"Standard"},{"shell":"CMD","command":"curl -I -L \"https://example.com\"","risk":"Standard"},{"shell":"CMD","command":"curl -v \"https://example.com\"","risk":"Standard"},{"shell":"CMD","command":"curl -D - -o response-body.txt \"https://example.com\"","risk":"Standard"},{"shell":"PowerShell","command":"Invoke-WebRequest -Uri \"https://example.com\" -Method Head","risk":"Standard"}],"aliases":[]},{"id":890000,"title":"ping - Test Basic Network Reachability","category":"Network Commands","product":"Network CLI","tags":["Basic Connectivity","Low-Risk Temporary","built-in / installed-by-default"],"keywords":["ping","continuous ping","ICMP echo","packet loss","Basic Connectivity","Low-Risk Temporary","built-in / installed-by-default","windows","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"ping is a Windows, macOS, Linux network command used for basic connectivity tasks. Availability: built-in / installed-by-default.","rootCause":"Use this command when evidence is needed for basic connectivity. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the ping command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: ping\nPlatforms: Windows, macOS, Linux\nCommand family: Basic Connectivity\nAvailability: built-in / installed-by-default\nSafety level: Low-Risk Temporary\nAdministrative rights: conditional\nPackage or module: See platform availability\nSource: Network-CLI-Commands.pdf; Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: ping\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"ping example.com","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"Terminal","command":"ping -n 10 example.com","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"Terminal","command":"ping -l 1024 example.com","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"Terminal","command":"ping -c 10 example.com","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"Terminal","command":"ping -4 example.com","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"Terminal","command":"ping -6 example.com","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"}],"sourceDocument":"Network-CLI-Commands.pdf; Built-in help or maintained manual page","sourceAuthority":"Network-CLI-Commands.pdf; Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows","macos","linux"],"lastVerified":"","vendors":[],"technologies":["Basic Connectivity"],"aliases":["continuous ping","ICMP echo","packet loss"],"commandId":"netcli-ping","canonicalName":"ping","shells":["Terminal"],"availability":"built-in / installed-by-default","safetyLevel":"Low-Risk Temporary","adminRequired":"conditional","commandFamily":"Basic Connectivity","module":"","modifying":false},{"id":890001,"title":"tracert - Trace a Network Path on Windows","category":"Network Commands","product":"Network CLI","tags":["Path Analysis","Safe Read-Only","built-in"],"keywords":["tracert","trace path","Windows traceroute","Path Analysis","Safe Read-Only","built-in","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"tracert is a Windows network command used for path analysis tasks. Availability: built-in.","rootCause":"Use this command when evidence is needed for path analysis. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the tracert command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: tracert\nPlatforms: Windows\nCommand family: Path Analysis\nAvailability: built-in\nSafety level: Safe Read-Only\nAdministrative rights: false\nPackage or module: See platform availability\nSource: Network-CLI-Commands.pdf; Microsoft Learn\nReview status: verified\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: tracert\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"CMD","command":"tracert example.com","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"CMD","command":"tracert -d example.com","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"CMD","command":"tracert -4 example.com","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"CMD","command":"tracert -6 example.com","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"Network-CLI-Commands.pdf; Microsoft Learn","sourceAuthority":"Network-CLI-Commands.pdf; Microsoft Learn","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"2026-08-06","vendors":[],"technologies":["Path Analysis"],"aliases":["trace path","Windows traceroute"],"commandId":"netcli-tracert","canonicalName":"tracert","shells":["CMD"],"availability":"built-in","safetyLevel":"Safe Read-Only","adminRequired":"false","commandFamily":"Path Analysis","module":"","modifying":false},{"id":890002,"title":"traceroute - Trace a Network Path","category":"Network Commands","product":"Network CLI","tags":["Path Analysis","Low-Risk Temporary","installed-by-default / optional-package"],"keywords":["traceroute","trace path","network hops","Path Analysis","Low-Risk Temporary","installed-by-default / optional-package","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"traceroute is a macOS, Linux network command used for path analysis tasks. Availability: installed-by-default / optional-package.","rootCause":"Use this command when evidence is needed for path analysis. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the traceroute command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: traceroute\nPlatforms: macOS, Linux\nCommand family: Path Analysis\nAvailability: installed-by-default / optional-package\nSafety level: Low-Risk Temporary\nAdministrative rights: conditional\nPackage or module: See platform availability\nSource: Network-CLI-Commands.pdf; Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: traceroute\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"traceroute example.com","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"Terminal","command":"traceroute -n example.com","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"Terminal","command":"traceroute6 example.com","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"}],"sourceDocument":"Network-CLI-Commands.pdf; Built-in help or maintained manual page","sourceAuthority":"Network-CLI-Commands.pdf; Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["macos","linux"],"lastVerified":"","vendors":[],"technologies":["Path Analysis"],"aliases":["trace path","network hops"],"commandId":"netcli-traceroute","canonicalName":"traceroute","shells":["Terminal"],"availability":"installed-by-default / optional-package","safetyLevel":"Low-Risk Temporary","adminRequired":"conditional","commandFamily":"Path Analysis","module":"","modifying":false},{"id":890003,"title":"pathping - Measure Windows Path Loss","category":"Network Commands","product":"Network CLI","tags":["Path Analysis","Low-Risk Temporary","built-in"],"keywords":["pathping","packet loss by hop","trace path","Path Analysis","Low-Risk Temporary","built-in","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"pathping is a Windows network command used for path analysis tasks. Availability: built-in.","rootCause":"Use this command when evidence is needed for path analysis. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the pathping command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: pathping\nPlatforms: Windows\nCommand family: Path Analysis\nAvailability: built-in\nSafety level: Low-Risk Temporary\nAdministrative rights: false\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: pathping\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"CMD","command":"pathping example.com","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"CMD","command":"pathping -n example.com","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"","vendors":[],"technologies":["Path Analysis"],"aliases":["packet loss by hop","trace path"],"commandId":"netcli-pathping","canonicalName":"pathping","shells":["CMD"],"availability":"built-in","safetyLevel":"Low-Risk Temporary","adminRequired":"false","commandFamily":"Path Analysis","module":"","modifying":false},{"id":890004,"title":"nslookup - Query DNS Records","category":"Network Commands","product":"Network CLI","tags":["DNS","Safe Read-Only","built-in / optional-package"],"keywords":["nslookup","DNS lookup","reverse lookup","query type","DNS","Safe Read-Only","built-in / optional-package","windows","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"nslookup is a Windows, macOS, Linux network command used for dns tasks. Availability: built-in / optional-package.","rootCause":"Use this command when evidence is needed for dns. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the nslookup command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: nslookup\nPlatforms: Windows, macOS, Linux\nCommand family: DNS\nAvailability: built-in / optional-package\nSafety level: Safe Read-Only\nAdministrative rights: false\nPackage or module: See platform availability\nSource: Network-CLI-Commands.pdf; Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: nslookup\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"nslookup example.com","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"nslookup -type=MX example.com","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"nslookup 192.0.2.10","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"Network-CLI-Commands.pdf; Built-in help or maintained manual page","sourceAuthority":"Network-CLI-Commands.pdf; Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows","macos","linux"],"lastVerified":"","vendors":[],"technologies":["DNS"],"aliases":["DNS lookup","reverse lookup","query type"],"commandId":"netcli-nslookup","canonicalName":"nslookup","shells":["Terminal"],"availability":"built-in / optional-package","safetyLevel":"Safe Read-Only","adminRequired":"false","commandFamily":"DNS","module":"","modifying":false},{"id":890005,"title":"dig - Query DNS in Detail","category":"Network Commands","product":"Network CLI","tags":["DNS","Safe Read-Only","installed-by-default / optional-package"],"keywords":["dig","DNS lookup","BIND tools","DNS trace","DNS","Safe Read-Only","installed-by-default / optional-package","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"dig is a macOS, Linux network command used for dns tasks. Availability: installed-by-default / optional-package.","rootCause":"Use this command when evidence is needed for dns. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the dig command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: dig\nPlatforms: macOS, Linux\nCommand family: DNS\nAvailability: installed-by-default / optional-package\nSafety level: Safe Read-Only\nAdministrative rights: false\nPackage or module: See platform availability\nSource: Network-CLI-Commands.pdf; Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: dig\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"dig example.com","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"dig AAAA example.com","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"dig MX example.com","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"dig @<DNS-SERVER> example.com","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"Network-CLI-Commands.pdf; Built-in help or maintained manual page","sourceAuthority":"Network-CLI-Commands.pdf; Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["macos","linux"],"lastVerified":"","vendors":[],"technologies":["DNS"],"aliases":["DNS lookup","BIND tools","DNS trace"],"commandId":"netcli-dig","canonicalName":"dig","shells":["Terminal"],"availability":"installed-by-default / optional-package","safetyLevel":"Safe Read-Only","adminRequired":"false","commandFamily":"DNS","module":"","modifying":false},{"id":890006,"title":"host - Perform a Simple DNS Lookup","category":"Network Commands","product":"Network CLI","tags":["DNS","Safe Read-Only","installed-by-default / optional-package"],"keywords":["host","DNS lookup","DNS","Safe Read-Only","installed-by-default / optional-package","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"host is a macOS, Linux network command used for dns tasks. Availability: installed-by-default / optional-package.","rootCause":"Use this command when evidence is needed for dns. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the host command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: host\nPlatforms: macOS, Linux\nCommand family: DNS\nAvailability: installed-by-default / optional-package\nSafety level: Safe Read-Only\nAdministrative rights: false\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: host\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"host example.com","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"host -t MX example.com","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"host 192.0.2.10","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["macos","linux"],"lastVerified":"","vendors":[],"technologies":["DNS"],"aliases":["DNS lookup"],"commandId":"netcli-host","canonicalName":"host","shells":["Terminal"],"availability":"installed-by-default / optional-package","safetyLevel":"Safe Read-Only","adminRequired":"false","commandFamily":"DNS","module":"","modifying":false},{"id":890007,"title":"hostname - Display the Local Host Name","category":"Network Commands","product":"Network CLI","tags":["Network Identity","Safe Read-Only","built-in"],"keywords":["hostname","computer name","host identity","Network Identity","Safe Read-Only","built-in","windows","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"hostname is a Windows, macOS, Linux network command used for network identity tasks. Availability: built-in.","rootCause":"Use this command when evidence is needed for network identity. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the hostname command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: hostname\nPlatforms: Windows, macOS, Linux\nCommand family: Network Identity\nAvailability: built-in\nSafety level: Safe Read-Only\nAdministrative rights: false\nPackage or module: See platform availability\nSource: Network-CLI-Commands.pdf; Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: hostname\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"hostname","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"Network-CLI-Commands.pdf; Built-in help or maintained manual page","sourceAuthority":"Network-CLI-Commands.pdf; Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows","macos","linux"],"lastVerified":"","vendors":[],"technologies":["Network Identity"],"aliases":["computer name","host identity"],"commandId":"netcli-hostname","canonicalName":"hostname","shells":["Terminal"],"availability":"built-in","safetyLevel":"Safe Read-Only","adminRequired":"false","commandFamily":"Network Identity","module":"","modifying":false},{"id":890008,"title":"netstat - Display Legacy Network Statistics","category":"Network Commands","product":"Network CLI","tags":["Sockets and Ports","Safe Read-Only","built-in / legacy / optional-package"],"keywords":["netstat","listening ports","routing table","legacy sockets","process using port","Sockets and Ports","Safe Read-Only","built-in / legacy / optional-package","windows","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"netstat is a Windows, macOS, Linux network command used for sockets and ports tasks. Availability: built-in / legacy / optional-package.","rootCause":"Use this command when evidence is needed for sockets and ports. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the netstat command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: netstat\nPlatforms: Windows, macOS, Linux\nCommand family: Sockets and Ports\nAvailability: built-in / legacy / optional-package\nSafety level: Safe Read-Only\nAdministrative rights: conditional\nPackage or module: See platform availability\nSource: Network-CLI-Commands.pdf; Built-in help; modern Linux replacement is ss\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: netstat\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"netstat -an","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"netstat -r","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"netstat -s","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"netstat -abno","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"Network-CLI-Commands.pdf; Built-in help; modern Linux replacement is ss","sourceAuthority":"Network-CLI-Commands.pdf; Built-in help; modern Linux replacement is ss","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows","macos","linux"],"lastVerified":"","vendors":[],"technologies":["Sockets and Ports"],"aliases":["listening ports","routing table","legacy sockets","process using port"],"commandId":"netcli-netstat","canonicalName":"netstat","shells":["Terminal"],"availability":"built-in / legacy / optional-package","safetyLevel":"Safe Read-Only","adminRequired":"conditional","commandFamily":"Sockets and Ports","module":"","modifying":false},{"id":890009,"title":"arp - Display or Modify the ARP Cache","category":"Network Commands","product":"Network CLI","tags":["ARP and Neighbor Discovery","Configuration Change","built-in / legacy"],"keywords":["arp","ARP cache","neighbor cache","ARP and Neighbor Discovery","Configuration Change","built-in / legacy","windows","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"arp is a Windows, macOS, Linux network command used for arp and neighbor discovery tasks. Availability: built-in / legacy.","rootCause":"Use this command when evidence is needed for arp and neighbor discovery. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the arp command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: arp\nPlatforms: Windows, macOS, Linux\nCommand family: ARP and Neighbor Discovery\nAvailability: built-in / legacy\nSafety level: Configuration Change\nAdministrative rights: conditional\nPackage or module: See platform availability\nSource: Network-CLI-Commands.pdf; Built-in help; modern replacements are Get-NetNeighbor and ip neighbor\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: arp\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"arp -a","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"arp -d <IP-ADDRESS>","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"}],"sourceDocument":"Network-CLI-Commands.pdf; Built-in help; modern replacements are Get-NetNeighbor and ip neighbor","sourceAuthority":"Network-CLI-Commands.pdf; Built-in help; modern replacements are Get-NetNeighbor and ip neighbor","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows","macos","linux"],"lastVerified":"","vendors":[],"technologies":["ARP and Neighbor Discovery"],"aliases":["ARP cache","neighbor cache"],"commandId":"netcli-arp","canonicalName":"arp","shells":["Terminal"],"availability":"built-in / legacy","safetyLevel":"Configuration Change","adminRequired":"conditional","commandFamily":"ARP and Neighbor Discovery","module":"","modifying":true},{"id":890010,"title":"route - Display or Modify Routes","category":"Network Commands","product":"Network CLI","tags":["Routing","High Impact","built-in / legacy"],"keywords":["route","routing table","default route","delete route","Routing","High Impact","built-in / legacy","windows","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"High","summary":"route is a Windows, macOS, Linux network command used for routing tasks. Availability: built-in / legacy.","rootCause":"Use this command when evidence is needed for routing. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the route command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: route\nPlatforms: Windows, macOS, Linux\nCommand family: Routing\nAvailability: built-in / legacy\nSafety level: High Impact\nAdministrative rights: true\nPackage or module: See platform availability\nSource: Built-in help; modern replacements are Get-NetRoute and ip route\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: route\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"route print","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"Terminal","command":"route -n get default","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"Terminal","command":"route add <DESTINATION> mask <MASK> <GATEWAY>","risk":"High","admin":true,"safetyLevel":"High Impact"}],"sourceDocument":"Built-in help; modern replacements are Get-NetRoute and ip route","sourceAuthority":"Built-in help; modern replacements are Get-NetRoute and ip route","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows","macos","linux"],"lastVerified":"","vendors":[],"technologies":["Routing"],"aliases":["routing table","default route","delete route"],"commandId":"netcli-route","canonicalName":"route","shells":["Terminal"],"availability":"built-in / legacy","safetyLevel":"High Impact","adminRequired":"true","commandFamily":"Routing","module":"","modifying":true},{"id":890011,"title":"curl - Inspect HTTP and HTTPS Connectivity","category":"Network Commands","product":"Network CLI","tags":["HTTP and HTTPS","Low-Risk Temporary","built-in / installed-by-default / version-dependent"],"keywords":["curl","HTTP headers","TLS test","REST API","check website","HTTP and HTTPS","Low-Risk Temporary","built-in / installed-by-default / version-dependent","windows","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"curl is a Windows, macOS, Linux network command used for http and https tasks. Availability: built-in / installed-by-default / version-dependent.","rootCause":"Use this command when evidence is needed for http and https. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the curl command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: curl\nPlatforms: Windows, macOS, Linux\nCommand family: HTTP and HTTPS\nAvailability: built-in / installed-by-default / version-dependent\nSafety level: Low-Risk Temporary\nAdministrative rights: false\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: curl\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"curl -I \"https://example.com\"","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"Terminal","command":"curl -I -L \"https://example.com\"","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"Terminal","command":"curl -v \"https://example.com\"","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows","macos","linux"],"lastVerified":"","vendors":[],"technologies":["HTTP and HTTPS"],"aliases":["HTTP headers","TLS test","REST API","check website"],"commandId":"netcli-curl","canonicalName":"curl","shells":["Terminal"],"availability":"built-in / installed-by-default / version-dependent","safetyLevel":"Low-Risk Temporary","adminRequired":"false","commandFamily":"HTTP and HTTPS","module":"","modifying":false},{"id":890012,"title":"ssh - Diagnose Secure Remote Access","category":"Network Commands","product":"Network CLI","tags":["SSH","Low-Risk Temporary","built-in / optional-feature / installed-by-default"],"keywords":["ssh","OpenSSH","remote shell","SSH verbose","SSH","Low-Risk Temporary","built-in / optional-feature / installed-by-default","windows","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"ssh is a Windows, macOS, Linux network command used for ssh tasks. Availability: built-in / optional-feature / installed-by-default.","rootCause":"Use this command when evidence is needed for ssh. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the ssh command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: ssh\nPlatforms: Windows, macOS, Linux\nCommand family: SSH\nAvailability: built-in / optional-feature / installed-by-default\nSafety level: Low-Risk Temporary\nAdministrative rights: false\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: ssh\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"ssh user@example.com","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"Terminal","command":"ssh -v user@example.com","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"Terminal","command":"ssh -p <PORT> user@example.com","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"Terminal","command":"ssh -o ConnectTimeout=10 user@example.com","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows","macos","linux"],"lastVerified":"","vendors":[],"technologies":["SSH"],"aliases":["OpenSSH","remote shell","SSH verbose"],"commandId":"netcli-ssh","canonicalName":"ssh","shells":["Terminal"],"availability":"built-in / optional-feature / installed-by-default","safetyLevel":"Low-Risk Temporary","adminRequired":"false","commandFamily":"SSH","module":"","modifying":false},{"id":890013,"title":"scp - Copy Files over SSH","category":"Network Commands","product":"Network CLI","tags":["SSH","Configuration Change","built-in / optional-feature / installed-by-default"],"keywords":["scp","secure copy","OpenSSH","SSH","Configuration Change","built-in / optional-feature / installed-by-default","windows","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"scp is a Windows, macOS, Linux network command used for ssh tasks. Availability: built-in / optional-feature / installed-by-default.","rootCause":"Use this command when evidence is needed for ssh. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the scp command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: scp\nPlatforms: Windows, macOS, Linux\nCommand family: SSH\nAvailability: built-in / optional-feature / installed-by-default\nSafety level: Configuration Change\nAdministrative rights: false\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: scp\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"scp file.txt user@example.com:/path/","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"scp user@example.com:/path/file.txt .","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows","macos","linux"],"lastVerified":"","vendors":[],"technologies":["SSH"],"aliases":["secure copy","OpenSSH"],"commandId":"netcli-scp","canonicalName":"scp","shells":["Terminal"],"availability":"built-in / optional-feature / installed-by-default","safetyLevel":"Configuration Change","adminRequired":"false","commandFamily":"SSH","module":"","modifying":true},{"id":890014,"title":"sftp - Transfer Files over SSH","category":"Network Commands","product":"Network CLI","tags":["SSH","Configuration Change","built-in / optional-feature / installed-by-default"],"keywords":["sftp","secure FTP","OpenSSH","SSH","Configuration Change","built-in / optional-feature / installed-by-default","windows","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"sftp is a Windows, macOS, Linux network command used for ssh tasks. Availability: built-in / optional-feature / installed-by-default.","rootCause":"Use this command when evidence is needed for ssh. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the sftp command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: sftp\nPlatforms: Windows, macOS, Linux\nCommand family: SSH\nAvailability: built-in / optional-feature / installed-by-default\nSafety level: Configuration Change\nAdministrative rights: false\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: sftp\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"sftp user@example.com","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows","macos","linux"],"lastVerified":"","vendors":[],"technologies":["SSH"],"aliases":["secure FTP","OpenSSH"],"commandId":"netcli-sftp","canonicalName":"sftp","shells":["Terminal"],"availability":"built-in / optional-feature / installed-by-default","safetyLevel":"Configuration Change","adminRequired":"false","commandFamily":"SSH","module":"","modifying":true},{"id":890015,"title":"telnet - Test Legacy Plain-Text Connectivity","category":"Network Commands","product":"Network CLI","tags":["Remote Access","Low-Risk Temporary","optional-feature / version-dependent / optional-package"],"keywords":["telnet","test TCP port","legacy remote access","Remote Access","Low-Risk Temporary","optional-feature / version-dependent / optional-package","windows","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"telnet is a Windows, macOS, Linux network command used for remote access tasks. Availability: optional-feature / version-dependent / optional-package.","rootCause":"Use this command when evidence is needed for remote access. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the telnet command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: telnet\nPlatforms: Windows, macOS, Linux\nCommand family: Remote Access\nAvailability: optional-feature / version-dependent / optional-package\nSafety level: Low-Risk Temporary\nAdministrative rights: false\nPackage or module: See platform availability\nSource: Network-CLI-Commands.pdf; Built-in or package help; prefer Test-NetConnection or nc\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: telnet\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"telnet <HOSTNAME> <PORT>","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"}],"sourceDocument":"Network-CLI-Commands.pdf; Built-in or package help; prefer Test-NetConnection or nc","sourceAuthority":"Network-CLI-Commands.pdf; Built-in or package help; prefer Test-NetConnection or nc","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows","macos","linux"],"lastVerified":"","vendors":[],"technologies":["Remote Access"],"aliases":["test TCP port","legacy remote access"],"commandId":"netcli-telnet","canonicalName":"telnet","shells":["Terminal"],"availability":"optional-feature / version-dependent / optional-package","safetyLevel":"Low-Risk Temporary","adminRequired":"false","commandFamily":"Remote Access","module":"","modifying":false},{"id":890016,"title":"nc - Test TCP or UDP Connectivity","category":"Network Commands","product":"Network CLI","tags":["Sockets and Ports","Low-Risk Temporary","installed-by-default / optional-package"],"keywords":["nc","netcat","ncat","check port","port test","Sockets and Ports","Low-Risk Temporary","installed-by-default / optional-package","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"nc is a macOS, Linux network command used for sockets and ports tasks. Availability: installed-by-default / optional-package.","rootCause":"Use this command when evidence is needed for sockets and ports. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the nc command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: nc\nPlatforms: macOS, Linux\nCommand family: Sockets and Ports\nAvailability: installed-by-default / optional-package\nSafety level: Low-Risk Temporary\nAdministrative rights: false\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: nc\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"nc -vz <HOSTNAME> <PORT>","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"Terminal","command":"nc -vzu <HOSTNAME> <PORT>","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["macos","linux"],"lastVerified":"","vendors":[],"technologies":["Sockets and Ports"],"aliases":["netcat","ncat","check port","port test"],"commandId":"netcli-nc","canonicalName":"nc","shells":["Terminal"],"availability":"installed-by-default / optional-package","safetyLevel":"Low-Risk Temporary","adminRequired":"false","commandFamily":"Sockets and Ports","module":"","modifying":false},{"id":890017,"title":"openssl - Diagnose TLS and Certificates","category":"Network Commands","product":"Network CLI","tags":["TLS and Certificates","Safe Read-Only","third-party / installed-by-default / optional-package"],"keywords":["openssl","TLS handshake","certificate test","SNI","TLS and Certificates","Safe Read-Only","third-party / installed-by-default / optional-package","windows","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"openssl is a Windows, macOS, Linux network command used for tls and certificates tasks. Availability: third-party / installed-by-default / optional-package.","rootCause":"Use this command when evidence is needed for tls and certificates. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the openssl command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: openssl\nPlatforms: Windows, macOS, Linux\nCommand family: TLS and Certificates\nAvailability: third-party / installed-by-default / optional-package\nSafety level: Safe Read-Only\nAdministrative rights: false\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: openssl\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"openssl s_client -connect example.com:443 -servername example.com","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"openssl x509 -in certificate.pem -noout -text","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows","macos","linux"],"lastVerified":"","vendors":[],"technologies":["TLS and Certificates"],"aliases":["TLS handshake","certificate test","SNI"],"commandId":"netcli-openssl","canonicalName":"openssl","shells":["Terminal"],"availability":"third-party / installed-by-default / optional-package","safetyLevel":"Safe Read-Only","adminRequired":"false","commandFamily":"TLS and Certificates","module":"","modifying":false},{"id":890018,"title":"tcpdump - Capture and Inspect Network Packets","category":"Network Commands","product":"Network CLI","tags":["Packet Capture","High Impact","installed-by-default / optional-package"],"keywords":["tcpdump","packet capture","PCAP","traffic capture","Packet Capture","High Impact","installed-by-default / optional-package","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"High","summary":"tcpdump is a macOS, Linux network command used for packet capture tasks. Availability: installed-by-default / optional-package.","rootCause":"Use this command when evidence is needed for packet capture. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the tcpdump command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: tcpdump\nPlatforms: macOS, Linux\nCommand family: Packet Capture\nAvailability: installed-by-default / optional-package\nSafety level: High Impact\nAdministrative rights: true\nPackage or module: See platform availability\nSource: tcpdump maintained manual page\nReview status: verified\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: tcpdump\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"tcpdump -D","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"Terminal","command":"tcpdump -ni <INTERFACE> host <HOST>","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"Terminal","command":"tcpdump -ni <INTERFACE> port <PORT>","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"Terminal","command":"tcpdump -ni <INTERFACE> -c 100 -w capture.pcap","risk":"High","admin":true,"safetyLevel":"High Impact"}],"sourceDocument":"tcpdump maintained manual page","sourceAuthority":"tcpdump maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["macos","linux"],"lastVerified":"2026-08-06","vendors":[],"technologies":["Packet Capture"],"aliases":["packet capture","PCAP","traffic capture"],"commandId":"netcli-tcpdump","canonicalName":"tcpdump","shells":["Terminal"],"availability":"installed-by-default / optional-package","safetyLevel":"High Impact","adminRequired":"true","commandFamily":"Packet Capture","module":"","modifying":true},{"id":890019,"title":"tshark - Capture Packets from a Terminal","category":"Network Commands","product":"Network CLI","tags":["Packet Capture","High Impact","third-party / optional-package"],"keywords":["tshark","Wireshark CLI","packet capture","PCAP","Packet Capture","High Impact","third-party / optional-package","windows","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"High","summary":"tshark is a Windows, macOS, Linux network command used for packet capture tasks. Availability: third-party / optional-package.","rootCause":"Use this command when evidence is needed for packet capture. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the tshark command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: tshark\nPlatforms: Windows, macOS, Linux\nCommand family: Packet Capture\nAvailability: third-party / optional-package\nSafety level: High Impact\nAdministrative rights: true\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: tshark\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"tshark -D","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"Terminal","command":"tshark -i <INTERFACE> -c 100","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"Terminal","command":"tshark -r capture.pcap","risk":"High","admin":true,"safetyLevel":"High Impact"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows","macos","linux"],"lastVerified":"","vendors":[],"technologies":["Packet Capture"],"aliases":["Wireshark CLI","packet capture","PCAP"],"commandId":"netcli-tshark","canonicalName":"tshark","shells":["Terminal"],"availability":"third-party / optional-package","safetyLevel":"High Impact","adminRequired":"true","commandFamily":"Packet Capture","module":"","modifying":true},{"id":890020,"title":"iperf3 - Measure Network Throughput","category":"Network Commands","product":"Network CLI","tags":["Bandwidth and Performance","Low-Risk Temporary","third-party / optional-package"],"keywords":["iperf3","bandwidth test","throughput test","iperf","Bandwidth and Performance","Low-Risk Temporary","third-party / optional-package","windows","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"iperf3 is a Windows, macOS, Linux network command used for bandwidth and performance tasks. Availability: third-party / optional-package.","rootCause":"Use this command when evidence is needed for bandwidth and performance. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the iperf3 command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: iperf3\nPlatforms: Windows, macOS, Linux\nCommand family: Bandwidth and Performance\nAvailability: third-party / optional-package\nSafety level: Low-Risk Temporary\nAdministrative rights: false\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: iperf3\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"iperf3 -s","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"Terminal","command":"iperf3 -c <SERVER>","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"Terminal","command":"iperf3 -c <SERVER> -R","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows","macos","linux"],"lastVerified":"","vendors":[],"technologies":["Bandwidth and Performance"],"aliases":["bandwidth test","throughput test","iperf"],"commandId":"netcli-iperf3","canonicalName":"iperf3","shells":["Terminal"],"availability":"third-party / optional-package","safetyLevel":"Low-Risk Temporary","adminRequired":"false","commandFamily":"Bandwidth and Performance","module":"","modifying":false},{"id":890021,"title":"mtr - Continuously Analyze a Network Path","category":"Network Commands","product":"Network CLI","tags":["Path Analysis","Low-Risk Temporary","optional-package"],"keywords":["mtr","traceroute and ping","path loss","Path Analysis","Low-Risk Temporary","optional-package","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"mtr is a macOS, Linux network command used for path analysis tasks. Availability: optional-package.","rootCause":"Use this command when evidence is needed for path analysis. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the mtr command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: mtr\nPlatforms: macOS, Linux\nCommand family: Path Analysis\nAvailability: optional-package\nSafety level: Low-Risk Temporary\nAdministrative rights: conditional\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: mtr\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"mtr example.com","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"Terminal","command":"mtr -rwzc 20 example.com","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["macos","linux"],"lastVerified":"","vendors":[],"technologies":["Path Analysis"],"aliases":["traceroute and ping","path loss"],"commandId":"netcli-mtr","canonicalName":"mtr","shells":["Terminal"],"availability":"optional-package","safetyLevel":"Low-Risk Temporary","adminRequired":"conditional","commandFamily":"Path Analysis","module":"","modifying":false},{"id":890022,"title":"ipconfig - Display Windows IP Configuration","category":"Network Commands","product":"Network CLI","tags":["Interface Configuration","Safe Read-Only","built-in"],"keywords":["ipconfig","Windows IP address","view DNS server","DHCP lease","Interface Configuration","Safe Read-Only","built-in","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"ipconfig is a Windows network command used for interface configuration tasks. Availability: built-in.","rootCause":"Use this command when evidence is needed for interface configuration. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the ipconfig command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: ipconfig\nPlatforms: Windows\nCommand family: Interface Configuration\nAvailability: built-in\nSafety level: Safe Read-Only\nAdministrative rights: false\nPackage or module: See platform availability\nSource: Network-CLI-Commands.pdf; Microsoft Learn: ipconfig\nReview status: verified\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: ipconfig\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"CMD","command":"ipconfig","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"CMD","command":"ipconfig /all","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"CMD","command":"ipconfig /displaydns","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"Network-CLI-Commands.pdf; Microsoft Learn: ipconfig","sourceAuthority":"Network-CLI-Commands.pdf; Microsoft Learn: ipconfig","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"2026-08-06","vendors":[],"technologies":["Interface Configuration"],"aliases":["Windows IP address","view DNS server","DHCP lease"],"commandId":"netcli-ipconfig","canonicalName":"ipconfig","shells":["CMD"],"availability":"built-in","safetyLevel":"Safe Read-Only","adminRequired":"false","commandFamily":"Interface Configuration","module":"","modifying":false},{"id":890023,"title":"ipconfig /release and /renew - Refresh a Windows DHCP Lease","category":"Network Commands","product":"Network CLI","tags":["DHCP","Disruptive","built-in"],"keywords":["ipconfig DHCP","renew DHCP","release DHCP","APIPA","DHCP","Disruptive","built-in","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"High","summary":"ipconfig DHCP is a Windows network command used for dhcp tasks. Availability: built-in.","rootCause":"Use this command when evidence is needed for dhcp. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the ipconfig DHCP command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: ipconfig DHCP\nPlatforms: Windows\nCommand family: DHCP\nAvailability: built-in\nSafety level: Disruptive\nAdministrative rights: true\nPackage or module: See platform availability\nSource: Network-CLI-Commands.pdf; Microsoft Learn: ipconfig\nReview status: verified\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: ipconfig DHCP\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"CMD","command":"ipconfig /release","risk":"High","admin":true,"safetyLevel":"Disruptive"},{"shell":"CMD","command":"ipconfig /renew","risk":"High","admin":true,"safetyLevel":"Disruptive"},{"shell":"CMD","command":"ipconfig /release6","risk":"High","admin":true,"safetyLevel":"Disruptive"},{"shell":"CMD","command":"ipconfig /renew6","risk":"High","admin":true,"safetyLevel":"Disruptive"}],"sourceDocument":"Network-CLI-Commands.pdf; Microsoft Learn: ipconfig","sourceAuthority":"Network-CLI-Commands.pdf; Microsoft Learn: ipconfig","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"2026-08-06","vendors":[],"technologies":["DHCP"],"aliases":["renew DHCP","release DHCP","APIPA"],"commandId":"netcli-ipconfig-dhcp","canonicalName":"ipconfig DHCP","shells":["CMD"],"availability":"built-in","safetyLevel":"Disruptive","adminRequired":"true","commandFamily":"DHCP","module":"","modifying":true},{"id":890024,"title":"ipconfig /flushdns and /registerdns - Maintain Windows DNS State","category":"Network Commands","product":"Network CLI","tags":["DNS","Configuration Change","built-in"],"keywords":["ipconfig DNS","flush DNS","register DNS","DNS cache","DNS","Configuration Change","built-in","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"ipconfig DNS is a Windows network command used for dns tasks. Availability: built-in.","rootCause":"Use this command when evidence is needed for dns. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the ipconfig DNS command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: ipconfig DNS\nPlatforms: Windows\nCommand family: DNS\nAvailability: built-in\nSafety level: Configuration Change\nAdministrative rights: true\nPackage or module: See platform availability\nSource: Network-CLI-Commands.pdf; Microsoft Learn: ipconfig\nReview status: verified\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: ipconfig DNS\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"CMD","command":"ipconfig /flushdns","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"CMD","command":"ipconfig /registerdns","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"CMD","command":"ipconfig /displaydns","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"}],"sourceDocument":"Network-CLI-Commands.pdf; Microsoft Learn: ipconfig","sourceAuthority":"Network-CLI-Commands.pdf; Microsoft Learn: ipconfig","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"2026-08-06","vendors":[],"technologies":["DNS"],"aliases":["flush DNS","register DNS","DNS cache"],"commandId":"netcli-ipconfig-dns","canonicalName":"ipconfig DNS","shells":["CMD"],"availability":"built-in","safetyLevel":"Configuration Change","adminRequired":"true","commandFamily":"DNS","module":"","modifying":true},{"id":890025,"title":"getmac - Display Windows MAC Addresses","category":"Network Commands","product":"Network CLI","tags":["Interface Configuration","Safe Read-Only","built-in"],"keywords":["getmac","MAC address","adapter address","Interface Configuration","Safe Read-Only","built-in","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"getmac is a Windows network command used for interface configuration tasks. Availability: built-in.","rootCause":"Use this command when evidence is needed for interface configuration. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the getmac command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: getmac\nPlatforms: Windows\nCommand family: Interface Configuration\nAvailability: built-in\nSafety level: Safe Read-Only\nAdministrative rights: false\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: getmac\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"CMD","command":"getmac","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"CMD","command":"getmac /v /fo list","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"","vendors":[],"technologies":["Interface Configuration"],"aliases":["MAC address","adapter address"],"commandId":"netcli-getmac","canonicalName":"getmac","shells":["CMD"],"availability":"built-in","safetyLevel":"Safe Read-Only","adminRequired":"false","commandFamily":"Interface Configuration","module":"","modifying":false},{"id":890026,"title":"nbtstat - Diagnose Windows NetBIOS Name State","category":"Network Commands","product":"Network CLI","tags":["NetBIOS","Configuration Change","built-in / legacy"],"keywords":["nbtstat","NetBIOS cache","name table","NetBIOS","Configuration Change","built-in / legacy","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"nbtstat is a Windows network command used for netbios tasks. Availability: built-in / legacy.","rootCause":"Use this command when evidence is needed for netbios. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the nbtstat command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: nbtstat\nPlatforms: Windows\nCommand family: NetBIOS\nAvailability: built-in / legacy\nSafety level: Configuration Change\nAdministrative rights: conditional\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: nbtstat\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"CMD","command":"nbtstat -n","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"},{"shell":"CMD","command":"nbtstat -c","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"},{"shell":"CMD","command":"nbtstat -A <IP-ADDRESS>","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"},{"shell":"CMD","command":"nbtstat -R","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"","vendors":[],"technologies":["NetBIOS"],"aliases":["NetBIOS cache","name table"],"commandId":"netcli-nbtstat","canonicalName":"nbtstat","shells":["CMD"],"availability":"built-in / legacy","safetyLevel":"Configuration Change","adminRequired":"conditional","commandFamily":"NetBIOS","module":"","modifying":true},{"id":890027,"title":"net use - Diagnose Windows SMB Mappings","category":"Network Commands","product":"Network CLI","tags":["SMB and File Sharing","Configuration Change","built-in"],"keywords":["net use","mapped drive","SMB share","UNC path","SMB and File Sharing","Configuration Change","built-in","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"net use is a Windows network command used for smb and file sharing tasks. Availability: built-in.","rootCause":"Use this command when evidence is needed for smb and file sharing. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the net use command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: net use\nPlatforms: Windows\nCommand family: SMB and File Sharing\nAvailability: built-in\nSafety level: Configuration Change\nAdministrative rights: conditional\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: net use\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"CMD","command":"net use","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"},{"shell":"CMD","command":"net use \\<SERVER>\\<SHARE>","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"},{"shell":"CMD","command":"net use \\<SERVER>\\<SHARE> /delete","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"","vendors":[],"technologies":["SMB and File Sharing"],"aliases":["mapped drive","SMB share","UNC path"],"commandId":"netcli-net-use","canonicalName":"net use","shells":["CMD"],"availability":"built-in","safetyLevel":"Configuration Change","adminRequired":"conditional","commandFamily":"SMB and File Sharing","module":"","modifying":true},{"id":890028,"title":"netsh interface - Inspect or Change Windows Interfaces","category":"Network Commands","product":"Network CLI","tags":["Interface Configuration","Configuration Change","built-in"],"keywords":["netsh interface","netsh IP","interface config","Interface Configuration","Configuration Change","built-in","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"netsh interface is a Windows network command used for interface configuration tasks. Availability: built-in.","rootCause":"Use this command when evidence is needed for interface configuration. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the netsh interface command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: netsh interface\nPlatforms: Windows\nCommand family: Interface Configuration\nAvailability: built-in\nSafety level: Configuration Change\nAdministrative rights: true\nPackage or module: See platform availability\nSource: Network-CLI-Commands.pdf; Microsoft Learn: netsh interface\nReview status: verified\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: netsh interface\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"CMD","command":"netsh interface show interface","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"CMD","command":"netsh interface ipv4 show config","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"CMD","command":"netsh interface ipv6 show route","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"}],"sourceDocument":"Network-CLI-Commands.pdf; Microsoft Learn: netsh interface","sourceAuthority":"Network-CLI-Commands.pdf; Microsoft Learn: netsh interface","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"2026-08-06","vendors":[],"technologies":["Interface Configuration"],"aliases":["netsh IP","interface config"],"commandId":"netcli-netsh-interface","canonicalName":"netsh interface","shells":["CMD"],"availability":"built-in","safetyLevel":"Configuration Change","adminRequired":"true","commandFamily":"Interface Configuration","module":"","modifying":true},{"id":890029,"title":"netsh winsock - Inspect or Reset the Windows Socket Catalog","category":"Network Commands","product":"Network CLI","tags":["Network Resets","Disruptive","built-in"],"keywords":["netsh winsock","Winsock reset","socket catalog","Network Resets","Disruptive","built-in","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"High","summary":"netsh winsock is a Windows network command used for network resets tasks. Availability: built-in.","rootCause":"Use this command when evidence is needed for network resets. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the netsh winsock command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: netsh winsock\nPlatforms: Windows\nCommand family: Network Resets\nAvailability: built-in\nSafety level: Disruptive\nAdministrative rights: true\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: netsh winsock\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"CMD","command":"netsh winsock show catalog","risk":"High","admin":true,"safetyLevel":"Disruptive"},{"shell":"CMD","command":"netsh winsock reset","risk":"High","admin":true,"safetyLevel":"Disruptive"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"","vendors":[],"technologies":["Network Resets"],"aliases":["Winsock reset","socket catalog"],"commandId":"netcli-netsh-winsock","canonicalName":"netsh winsock","shells":["CMD"],"availability":"built-in","safetyLevel":"Disruptive","adminRequired":"true","commandFamily":"Network Resets","module":"","modifying":true},{"id":890030,"title":"netsh winhttp - Inspect or Change the System HTTP Proxy","category":"Network Commands","product":"Network CLI","tags":["Proxy","Configuration Change","built-in"],"keywords":["netsh winhttp","Windows proxy","system proxy","Proxy","Configuration Change","built-in","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"netsh winhttp is a Windows network command used for proxy tasks. Availability: built-in.","rootCause":"Use this command when evidence is needed for proxy. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the netsh winhttp command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: netsh winhttp\nPlatforms: Windows\nCommand family: Proxy\nAvailability: built-in\nSafety level: Configuration Change\nAdministrative rights: true\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: netsh winhttp\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"CMD","command":"netsh winhttp show proxy","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"CMD","command":"netsh winhttp reset proxy","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"CMD","command":"netsh winhttp import proxy source=ie","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"","vendors":[],"technologies":["Proxy"],"aliases":["Windows proxy","system proxy"],"commandId":"netcli-netsh-winhttp","canonicalName":"netsh winhttp","shells":["CMD"],"availability":"built-in","safetyLevel":"Configuration Change","adminRequired":"true","commandFamily":"Proxy","module":"","modifying":true},{"id":890031,"title":"netsh advfirewall - Inspect Windows Firewall Policy","category":"Network Commands","product":"Network CLI","tags":["Firewall","High Impact","built-in"],"keywords":["netsh advfirewall","firewall rules","Windows Defender Firewall","Firewall","High Impact","built-in","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"High","summary":"netsh advfirewall is a Windows network command used for firewall tasks. Availability: built-in.","rootCause":"Use this command when evidence is needed for firewall. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the netsh advfirewall command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: netsh advfirewall\nPlatforms: Windows\nCommand family: Firewall\nAvailability: built-in\nSafety level: High Impact\nAdministrative rights: true\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: netsh advfirewall\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"CMD","command":"netsh advfirewall show allprofiles","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"CMD","command":"netsh advfirewall firewall show rule name=all","risk":"High","admin":true,"safetyLevel":"High Impact"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"","vendors":[],"technologies":["Firewall"],"aliases":["firewall rules","Windows Defender Firewall"],"commandId":"netcli-netsh-advfirewall","canonicalName":"netsh advfirewall","shells":["CMD"],"availability":"built-in","safetyLevel":"High Impact","adminRequired":"true","commandFamily":"Firewall","module":"","modifying":true},{"id":890032,"title":"netsh wlan - Inspect Windows Wi-Fi","category":"Network Commands","product":"Network CLI","tags":["Wi-Fi","Configuration Change","built-in"],"keywords":["netsh wlan","Wi-Fi report","wireless profiles","BSSID","Wi-Fi","Configuration Change","built-in","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"netsh wlan is a Windows network command used for wi-fi tasks. Availability: built-in.","rootCause":"Use this command when evidence is needed for wi-fi. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the netsh wlan command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: netsh wlan\nPlatforms: Windows\nCommand family: Wi-Fi\nAvailability: built-in\nSafety level: Configuration Change\nAdministrative rights: conditional\nPackage or module: See platform availability\nSource: Network-CLI-Commands.pdf; Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: netsh wlan\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"CMD","command":"netsh wlan show interfaces","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"},{"shell":"CMD","command":"netsh wlan show drivers","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"},{"shell":"CMD","command":"netsh wlan show networks mode=bssid","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"},{"shell":"CMD","command":"netsh wlan show wlanreport","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"}],"sourceDocument":"Network-CLI-Commands.pdf; Built-in help or maintained manual page","sourceAuthority":"Network-CLI-Commands.pdf; Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"","vendors":[],"technologies":["Wi-Fi"],"aliases":["Wi-Fi report","wireless profiles","BSSID"],"commandId":"netcli-netsh-wlan","canonicalName":"netsh wlan","shells":["CMD"],"availability":"built-in","safetyLevel":"Configuration Change","adminRequired":"conditional","commandFamily":"Wi-Fi","module":"","modifying":true},{"id":890033,"title":"pktmon - Capture Windows Network Packets","category":"Network Commands","product":"Network CLI","tags":["Packet Capture","High Impact","built-in / version-dependent"],"keywords":["pktmon","Packet Monitor","ETL capture","PCAPNG","Packet Capture","High Impact","built-in / version-dependent","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"High","summary":"pktmon is a Windows network command used for packet capture tasks. Availability: built-in / version-dependent.","rootCause":"Use this command when evidence is needed for packet capture. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the pktmon command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: pktmon\nPlatforms: Windows\nCommand family: Packet Capture\nAvailability: built-in / version-dependent\nSafety level: High Impact\nAdministrative rights: true\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: pktmon\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"CMD","command":"pktmon list","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"CMD","command":"pktmon filter list","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"CMD","command":"pktmon start --capture --comp nics --pkt-size 0","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"CMD","command":"pktmon stop","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"CMD","command":"pktmon etl2pcap PktMon.etl --out PktMon.pcapng","risk":"High","admin":true,"safetyLevel":"High Impact"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"","vendors":[],"technologies":["Packet Capture"],"aliases":["Packet Monitor","ETL capture","PCAPNG"],"commandId":"netcli-pktmon","canonicalName":"pktmon","shells":["CMD"],"availability":"built-in / version-dependent","safetyLevel":"High Impact","adminRequired":"true","commandFamily":"Packet Capture","module":"","modifying":true},{"id":890034,"title":"w32tm - Diagnose Windows Time Synchronization","category":"Network Commands","product":"Network CLI","tags":["Time Synchronization","Safe Read-Only","built-in"],"keywords":["w32tm","NTP","time source","clock skew","Time Synchronization","Safe Read-Only","built-in","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"w32tm is a Windows network command used for time synchronization tasks. Availability: built-in.","rootCause":"Use this command when evidence is needed for time synchronization. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the w32tm command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: w32tm\nPlatforms: Windows\nCommand family: Time Synchronization\nAvailability: built-in\nSafety level: Safe Read-Only\nAdministrative rights: conditional\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: w32tm\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"CMD","command":"w32tm /query /status","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"CMD","command":"w32tm /query /source","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"CMD","command":"w32tm /query /peers","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"CMD","command":"w32tm /stripchart /computer:<TIME-SERVER> /dataonly /samples:5","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"","vendors":[],"technologies":["Time Synchronization"],"aliases":["NTP","time source","clock skew"],"commandId":"netcli-w32tm","canonicalName":"w32tm","shells":["CMD"],"availability":"built-in","safetyLevel":"Safe Read-Only","adminRequired":"conditional","commandFamily":"Time Synchronization","module":"","modifying":false},{"id":890035,"title":"nltest - Diagnose Windows Domain Connectivity","category":"Network Commands","product":"Network CLI","tags":["Active Directory","Safe Read-Only","built-in / domain tools"],"keywords":["nltest","domain controller discovery","secure channel","Active Directory","Safe Read-Only","built-in / domain tools","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"nltest is a Windows network command used for active directory tasks. Availability: built-in / domain tools.","rootCause":"Use this command when evidence is needed for active directory. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the nltest command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: nltest\nPlatforms: Windows\nCommand family: Active Directory\nAvailability: built-in / domain tools\nSafety level: Safe Read-Only\nAdministrative rights: conditional\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: nltest\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"CMD","command":"nltest /dsgetdc:<DOMAIN>","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"CMD","command":"nltest /dclist:<DOMAIN>","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"CMD","command":"nltest /sc_query:<DOMAIN>","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"CMD","command":"nltest /sc_verify:<DOMAIN>","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"","vendors":[],"technologies":["Active Directory"],"aliases":["domain controller discovery","secure channel"],"commandId":"netcli-nltest","canonicalName":"nltest","shells":["CMD"],"availability":"built-in / domain tools","safetyLevel":"Safe Read-Only","adminRequired":"conditional","commandFamily":"Active Directory","module":"","modifying":false},{"id":890036,"title":"setspn - Inspect Active Directory Service Principal Names","category":"Network Commands","product":"Network CLI","tags":["Kerberos","Configuration Change","built-in / domain tools"],"keywords":["setspn","SPN","Kerberos duplicate","Kerberos","Configuration Change","built-in / domain tools","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"setspn is a Windows network command used for kerberos tasks. Availability: built-in / domain tools.","rootCause":"Use this command when evidence is needed for kerberos. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the setspn command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: setspn\nPlatforms: Windows\nCommand family: Kerberos\nAvailability: built-in / domain tools\nSafety level: Configuration Change\nAdministrative rights: true\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: setspn\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"CMD","command":"setspn -Q <SPN>","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"CMD","command":"setspn -X","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"CMD","command":"setspn -L <ACCOUNT>","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"","vendors":[],"technologies":["Kerberos"],"aliases":["SPN","Kerberos duplicate"],"commandId":"netcli-setspn","canonicalName":"setspn","shells":["CMD"],"availability":"built-in / domain tools","safetyLevel":"Configuration Change","adminRequired":"true","commandFamily":"Kerberos","module":"","modifying":true},{"id":890037,"title":"klist - Inspect or Purge Kerberos Tickets","category":"Network Commands","product":"Network CLI","tags":["Kerberos","Disruptive","built-in"],"keywords":["klist","Kerberos tickets","ticket cache","Kerberos","Disruptive","built-in","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"High","summary":"klist is a Windows network command used for kerberos tasks. Availability: built-in.","rootCause":"Use this command when evidence is needed for kerberos. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the klist command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: klist\nPlatforms: Windows\nCommand family: Kerberos\nAvailability: built-in\nSafety level: Disruptive\nAdministrative rights: conditional\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: klist\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"CMD","command":"klist","risk":"High","admin":false,"safetyLevel":"Disruptive"},{"shell":"CMD","command":"klist tickets","risk":"High","admin":false,"safetyLevel":"Disruptive"},{"shell":"CMD","command":"klist purge","risk":"High","admin":false,"safetyLevel":"Disruptive"},{"shell":"CMD","command":"klist get <SPN>","risk":"High","admin":false,"safetyLevel":"Disruptive"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"","vendors":[],"technologies":["Kerberos"],"aliases":["Kerberos tickets","ticket cache"],"commandId":"netcli-klist","canonicalName":"klist","shells":["CMD"],"availability":"built-in","safetyLevel":"Disruptive","adminRequired":"conditional","commandFamily":"Kerberos","module":"","modifying":true},{"id":890038,"title":"repadmin - Diagnose Active Directory Replication","category":"Network Commands","product":"Network CLI","tags":["Active Directory","Safe Read-Only","optional-feature / server tools"],"keywords":["repadmin","AD replication","domain controller","Active Directory","Safe Read-Only","optional-feature / server tools","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"repadmin is a Windows network command used for active directory tasks. Availability: optional-feature / server tools.","rootCause":"Use this command when evidence is needed for active directory. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the repadmin command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: repadmin\nPlatforms: Windows\nCommand family: Active Directory\nAvailability: optional-feature / server tools\nSafety level: Safe Read-Only\nAdministrative rights: true\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: repadmin\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"CMD","command":"repadmin /replsummary","risk":"Standard","admin":true,"safetyLevel":"Safe Read-Only"},{"shell":"CMD","command":"repadmin /showrepl","risk":"Standard","admin":true,"safetyLevel":"Safe Read-Only"},{"shell":"CMD","command":"repadmin /queue","risk":"Standard","admin":true,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"","vendors":[],"technologies":["Active Directory"],"aliases":["AD replication","domain controller"],"commandId":"netcli-repadmin","canonicalName":"repadmin","shells":["CMD"],"availability":"optional-feature / server tools","safetyLevel":"Safe Read-Only","adminRequired":"true","commandFamily":"Active Directory","module":"","modifying":false},{"id":890039,"title":"dcdiag - Test Domain Controller Health","category":"Network Commands","product":"Network CLI","tags":["Active Directory","Safe Read-Only","optional-feature / server tools"],"keywords":["dcdiag","domain controller diagnostics","AD DNS","Active Directory","Safe Read-Only","optional-feature / server tools","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"dcdiag is a Windows network command used for active directory tasks. Availability: optional-feature / server tools.","rootCause":"Use this command when evidence is needed for active directory. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the dcdiag command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: dcdiag\nPlatforms: Windows\nCommand family: Active Directory\nAvailability: optional-feature / server tools\nSafety level: Safe Read-Only\nAdministrative rights: true\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: dcdiag\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"CMD","command":"dcdiag","risk":"Standard","admin":true,"safetyLevel":"Safe Read-Only"},{"shell":"CMD","command":"dcdiag /v","risk":"Standard","admin":true,"safetyLevel":"Safe Read-Only"},{"shell":"CMD","command":"dcdiag /test:dns","risk":"Standard","admin":true,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"","vendors":[],"technologies":["Active Directory"],"aliases":["domain controller diagnostics","AD DNS"],"commandId":"netcli-dcdiag","canonicalName":"dcdiag","shells":["CMD"],"availability":"optional-feature / server tools","safetyLevel":"Safe Read-Only","adminRequired":"true","commandFamily":"Active Directory","module":"","modifying":false},{"id":890040,"title":"Get-NetAdapter - Inspect Windows Network Adapters","category":"Network Commands","product":"NetAdapter","tags":["Interface Configuration","Safe Read-Only","built-in / module-dependent"],"keywords":["Get-NetAdapter","PowerShell network adapter","link speed","Interface Configuration","Safe Read-Only","built-in / module-dependent","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"Get-NetAdapter is a Windows network command used for interface configuration tasks. Availability: built-in / module-dependent.","rootCause":"Use this command when evidence is needed for interface configuration. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the Get-NetAdapter command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: Get-NetAdapter\nPlatforms: Windows\nCommand family: Interface Configuration\nAvailability: built-in / module-dependent\nSafety level: Safe Read-Only\nAdministrative rights: false\nPackage or module: NetAdapter\nSource: Microsoft Learn: NetAdapter module\nReview status: verified\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: Get-NetAdapter\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"PowerShell","command":"Get-NetAdapter","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-NetAdapter | Format-Table Name, Status, LinkSpeed","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-NetAdapterStatistics","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Learn: NetAdapter module","sourceAuthority":"Microsoft Learn: NetAdapter module","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"2026-08-06","vendors":[],"technologies":["Interface Configuration"],"aliases":["PowerShell network adapter","link speed"],"commandId":"netcli-get-netadapter","canonicalName":"Get-NetAdapter","shells":["PowerShell"],"availability":"built-in / module-dependent","safetyLevel":"Safe Read-Only","adminRequired":"false","commandFamily":"Interface Configuration","module":"NetAdapter","modifying":false},{"id":890041,"title":"Get-NetIPConfiguration - Inspect Windows Network Configuration","category":"Network Commands","product":"NetTCPIP","tags":["Interface Configuration","Safe Read-Only","built-in / module-dependent"],"keywords":["Get-NetIPConfiguration","PowerShell IP config","default gateway","DNS server","Interface Configuration","Safe Read-Only","built-in / module-dependent","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"Get-NetIPConfiguration is a Windows network command used for interface configuration tasks. Availability: built-in / module-dependent.","rootCause":"Use this command when evidence is needed for interface configuration. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the Get-NetIPConfiguration command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: Get-NetIPConfiguration\nPlatforms: Windows\nCommand family: Interface Configuration\nAvailability: built-in / module-dependent\nSafety level: Safe Read-Only\nAdministrative rights: false\nPackage or module: NetTCPIP\nSource: Microsoft Learn: NetTCPIP module\nReview status: verified\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: Get-NetIPConfiguration\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"PowerShell","command":"Get-NetIPConfiguration","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-NetIPConfiguration -Detailed","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Learn: NetTCPIP module","sourceAuthority":"Microsoft Learn: NetTCPIP module","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"2026-08-06","vendors":[],"technologies":["Interface Configuration"],"aliases":["PowerShell IP config","default gateway","DNS server"],"commandId":"netcli-get-netipconfiguration","canonicalName":"Get-NetIPConfiguration","shells":["PowerShell"],"availability":"built-in / module-dependent","safetyLevel":"Safe Read-Only","adminRequired":"false","commandFamily":"Interface Configuration","module":"NetTCPIP","modifying":false},{"id":890042,"title":"Get-NetIPAddress - Inspect Windows IP Addresses","category":"Network Commands","product":"NetTCPIP","tags":["IPv4 Configuration","Safe Read-Only","built-in / module-dependent"],"keywords":["Get-NetIPAddress","PowerShell IP address","IPv6 address","IPv4 Configuration","Safe Read-Only","built-in / module-dependent","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"Get-NetIPAddress is a Windows network command used for ipv4 configuration tasks. Availability: built-in / module-dependent.","rootCause":"Use this command when evidence is needed for ipv4 configuration. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the Get-NetIPAddress command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: Get-NetIPAddress\nPlatforms: Windows\nCommand family: IPv4 Configuration\nAvailability: built-in / module-dependent\nSafety level: Safe Read-Only\nAdministrative rights: false\nPackage or module: NetTCPIP\nSource: Microsoft Learn: NetTCPIP module\nReview status: verified\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: Get-NetIPAddress\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"PowerShell","command":"Get-NetIPAddress","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-NetIPAddress -AddressFamily IPv4","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-NetIPAddress -AddressFamily IPv6","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Learn: NetTCPIP module","sourceAuthority":"Microsoft Learn: NetTCPIP module","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"2026-08-06","vendors":[],"technologies":["IPv4 Configuration"],"aliases":["PowerShell IP address","IPv6 address"],"commandId":"netcli-get-netipaddress","canonicalName":"Get-NetIPAddress","shells":["PowerShell"],"availability":"built-in / module-dependent","safetyLevel":"Safe Read-Only","adminRequired":"false","commandFamily":"IPv4 Configuration","module":"NetTCPIP","modifying":false},{"id":890043,"title":"Get-NetRoute - Inspect Windows Routes","category":"Network Commands","product":"NetTCPIP","tags":["Routing","Safe Read-Only","built-in / module-dependent"],"keywords":["Get-NetRoute","PowerShell routing table","default route","Routing","Safe Read-Only","built-in / module-dependent","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"Get-NetRoute is a Windows network command used for routing tasks. Availability: built-in / module-dependent.","rootCause":"Use this command when evidence is needed for routing. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the Get-NetRoute command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: Get-NetRoute\nPlatforms: Windows\nCommand family: Routing\nAvailability: built-in / module-dependent\nSafety level: Safe Read-Only\nAdministrative rights: false\nPackage or module: NetTCPIP\nSource: Microsoft Learn: NetTCPIP module\nReview status: verified\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: Get-NetRoute\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"PowerShell","command":"Get-NetRoute","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-NetRoute -AddressFamily IPv4","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-NetRoute -DestinationPrefix 0.0.0.0/0","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Learn: NetTCPIP module","sourceAuthority":"Microsoft Learn: NetTCPIP module","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"2026-08-06","vendors":[],"technologies":["Routing"],"aliases":["PowerShell routing table","default route"],"commandId":"netcli-get-netroute","canonicalName":"Get-NetRoute","shells":["PowerShell"],"availability":"built-in / module-dependent","safetyLevel":"Safe Read-Only","adminRequired":"false","commandFamily":"Routing","module":"NetTCPIP","modifying":false},{"id":890044,"title":"Resolve-DnsName - Query DNS with PowerShell","category":"Network Commands","product":"DnsClient","tags":["DNS","Safe Read-Only","built-in / module-dependent"],"keywords":["Resolve-DnsName","PowerShell DNS","DNS record","flush DNS","DNS","Safe Read-Only","built-in / module-dependent","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"Resolve-DnsName is a Windows network command used for dns tasks. Availability: built-in / module-dependent.","rootCause":"Use this command when evidence is needed for dns. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the Resolve-DnsName command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: Resolve-DnsName\nPlatforms: Windows\nCommand family: DNS\nAvailability: built-in / module-dependent\nSafety level: Safe Read-Only\nAdministrative rights: false\nPackage or module: DnsClient\nSource: Microsoft Learn: DnsClient module\nReview status: verified\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: Resolve-DnsName\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"PowerShell","command":"Resolve-DnsName example.com","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Resolve-DnsName example.com -Type AAAA","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Resolve-DnsName example.com -Server <DNS-SERVER> -DnsOnly","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Learn: DnsClient module","sourceAuthority":"Microsoft Learn: DnsClient module","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"2026-08-06","vendors":[],"technologies":["DNS"],"aliases":["PowerShell DNS","DNS record","flush DNS"],"commandId":"netcli-resolve-dnsname","canonicalName":"Resolve-DnsName","shells":["PowerShell"],"availability":"built-in / module-dependent","safetyLevel":"Safe Read-Only","adminRequired":"false","commandFamily":"DNS","module":"DnsClient","modifying":false},{"id":890045,"title":"Test-Connection - Test Network Reachability with PowerShell","category":"Network Commands","product":"Network CLI","tags":["Basic Connectivity","Low-Risk Temporary","built-in / version-dependent"],"keywords":["Test-Connection","PowerShell ping","continuous ping","Basic Connectivity","Low-Risk Temporary","built-in / version-dependent","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"Test-Connection is a Windows network command used for basic connectivity tasks. Availability: built-in / version-dependent.","rootCause":"Use this command when evidence is needed for basic connectivity. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the Test-Connection command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: Test-Connection\nPlatforms: Windows\nCommand family: Basic Connectivity\nAvailability: built-in / version-dependent\nSafety level: Low-Risk Temporary\nAdministrative rights: false\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: Test-Connection\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"PowerShell","command":"Test-Connection example.com -Count 4","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"PowerShell","command":"Test-Connection example.com -Traceroute","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"PowerShell","command":"Test-Connection example.com -IPv6","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"","vendors":[],"technologies":["Basic Connectivity"],"aliases":["PowerShell ping","continuous ping"],"commandId":"netcli-test-connection","canonicalName":"Test-Connection","shells":["PowerShell"],"availability":"built-in / version-dependent","safetyLevel":"Low-Risk Temporary","adminRequired":"false","commandFamily":"Basic Connectivity","module":"","modifying":false},{"id":890046,"title":"Test-NetConnection - Test a TCP Port or Route","category":"Network Commands","product":"NetTCPIP","tags":["Sockets and Ports","Low-Risk Temporary","built-in / module-dependent"],"keywords":["Test-NetConnection","check port 443","PowerShell port test","trace route","Sockets and Ports","Low-Risk Temporary","built-in / module-dependent","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"Test-NetConnection is a Windows network command used for sockets and ports tasks. Availability: built-in / module-dependent.","rootCause":"Use this command when evidence is needed for sockets and ports. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the Test-NetConnection command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: Test-NetConnection\nPlatforms: Windows\nCommand family: Sockets and Ports\nAvailability: built-in / module-dependent\nSafety level: Low-Risk Temporary\nAdministrative rights: false\nPackage or module: NetTCPIP\nSource: Microsoft Learn: NetTCPIP module\nReview status: verified\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: Test-NetConnection\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"PowerShell","command":"Test-NetConnection example.com","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"PowerShell","command":"Test-NetConnection example.com -Port 443","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"PowerShell","command":"Test-NetConnection example.com -TraceRoute","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"PowerShell","command":"Test-NetConnection example.com -InformationLevel Detailed","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"}],"sourceDocument":"Microsoft Learn: NetTCPIP module","sourceAuthority":"Microsoft Learn: NetTCPIP module","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"2026-08-06","vendors":[],"technologies":["Sockets and Ports"],"aliases":["check port 443","PowerShell port test","trace route"],"commandId":"netcli-test-netconnection","canonicalName":"Test-NetConnection","shells":["PowerShell"],"availability":"built-in / module-dependent","safetyLevel":"Low-Risk Temporary","adminRequired":"false","commandFamily":"Sockets and Ports","module":"NetTCPIP","modifying":false},{"id":890047,"title":"Get-NetTCPConnection - Inspect Windows TCP Sockets","category":"Network Commands","product":"NetTCPIP","tags":["Sockets and Ports","Safe Read-Only","built-in / module-dependent"],"keywords":["Get-NetTCPConnection","listening ports","process using port","PowerShell sockets","Sockets and Ports","Safe Read-Only","built-in / module-dependent","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"Get-NetTCPConnection is a Windows network command used for sockets and ports tasks. Availability: built-in / module-dependent.","rootCause":"Use this command when evidence is needed for sockets and ports. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the Get-NetTCPConnection command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: Get-NetTCPConnection\nPlatforms: Windows\nCommand family: Sockets and Ports\nAvailability: built-in / module-dependent\nSafety level: Safe Read-Only\nAdministrative rights: conditional\nPackage or module: NetTCPIP\nSource: Microsoft Learn: NetTCPIP module\nReview status: verified\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: Get-NetTCPConnection\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"PowerShell","command":"Get-NetTCPConnection","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-NetTCPConnection -State Listen","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-NetTCPConnection | Select-Object LocalAddress,LocalPort,State,OwningProcess","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Learn: NetTCPIP module","sourceAuthority":"Microsoft Learn: NetTCPIP module","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"2026-08-06","vendors":[],"technologies":["Sockets and Ports"],"aliases":["listening ports","process using port","PowerShell sockets"],"commandId":"netcli-get-nettcpconnection","canonicalName":"Get-NetTCPConnection","shells":["PowerShell"],"availability":"built-in / module-dependent","safetyLevel":"Safe Read-Only","adminRequired":"conditional","commandFamily":"Sockets and Ports","module":"NetTCPIP","modifying":false},{"id":890048,"title":"Get-NetFirewallRule - Inspect Windows Firewall Rules","category":"Network Commands","product":"NetSecurity","tags":["Firewall","Safe Read-Only","built-in / module-dependent"],"keywords":["Get-NetFirewallRule","PowerShell firewall","firewall profile","Firewall","Safe Read-Only","built-in / module-dependent","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"Get-NetFirewallRule is a Windows network command used for firewall tasks. Availability: built-in / module-dependent.","rootCause":"Use this command when evidence is needed for firewall. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the Get-NetFirewallRule command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: Get-NetFirewallRule\nPlatforms: Windows\nCommand family: Firewall\nAvailability: built-in / module-dependent\nSafety level: Safe Read-Only\nAdministrative rights: true\nPackage or module: NetSecurity\nSource: Microsoft Learn: NetSecurity module\nReview status: verified\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: Get-NetFirewallRule\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"PowerShell","command":"Get-NetFirewallProfile","risk":"Standard","admin":true,"safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-NetFirewallRule -Enabled True","risk":"Standard","admin":true,"safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-NetFirewallRule -DisplayName '<RULE-NAME>'","risk":"Standard","admin":true,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Learn: NetSecurity module","sourceAuthority":"Microsoft Learn: NetSecurity module","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"2026-08-06","vendors":[],"technologies":["Firewall"],"aliases":["PowerShell firewall","firewall profile"],"commandId":"netcli-get-netfirewallrule","canonicalName":"Get-NetFirewallRule","shells":["PowerShell"],"availability":"built-in / module-dependent","safetyLevel":"Safe Read-Only","adminRequired":"true","commandFamily":"Firewall","module":"NetSecurity","modifying":false},{"id":890049,"title":"Get-SmbConnection - Inspect Windows SMB Connections","category":"Network Commands","product":"SmbShare","tags":["SMB and File Sharing","Safe Read-Only","built-in / module-dependent"],"keywords":["Get-SmbConnection","SMB port","file share connection","port 445","SMB and File Sharing","Safe Read-Only","built-in / module-dependent","windows","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"Get-SmbConnection is a Windows network command used for smb and file sharing tasks. Availability: built-in / module-dependent.","rootCause":"Use this command when evidence is needed for smb and file sharing. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the Get-SmbConnection command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: Get-SmbConnection\nPlatforms: Windows\nCommand family: SMB and File Sharing\nAvailability: built-in / module-dependent\nSafety level: Safe Read-Only\nAdministrative rights: true\nPackage or module: SmbShare\nSource: Microsoft Learn: SmbShare module\nReview status: verified\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: Get-SmbConnection\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"PowerShell","command":"Get-SmbConnection","risk":"Standard","admin":true,"safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-SmbMapping","risk":"Standard","admin":true,"safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-SmbSession","risk":"Standard","admin":true,"safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Test-NetConnection <SERVER> -Port 445","risk":"Standard","admin":true,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"Microsoft Learn: SmbShare module","sourceAuthority":"Microsoft Learn: SmbShare module","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows"],"lastVerified":"2026-08-06","vendors":[],"technologies":["SMB and File Sharing"],"aliases":["SMB port","file share connection","port 445"],"commandId":"netcli-get-smbconnection","canonicalName":"Get-SmbConnection","shells":["PowerShell"],"availability":"built-in / module-dependent","safetyLevel":"Safe Read-Only","adminRequired":"true","commandFamily":"SMB and File Sharing","module":"SmbShare","modifying":false},{"id":890050,"title":"ifconfig - Inspect Legacy Unix Network Interfaces","category":"Network Commands","product":"Network CLI","tags":["Interface Configuration","Configuration Change","built-in on macOS / optional-package and legacy on Linux"],"keywords":["ifconfig","macOS interface","Linux legacy interface","MAC address","ip address replacement","Interface Configuration","Configuration Change","built-in on macOS / optional-package and legacy on Linux","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"ifconfig is a macOS, Linux network command used for interface configuration tasks. Availability: built-in on macOS / optional-package and legacy on Linux.","rootCause":"Use this command when evidence is needed for interface configuration. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the ifconfig command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: ifconfig\nPlatforms: macOS, Linux\nCommand family: Interface Configuration\nAvailability: built-in on macOS / optional-package and legacy on Linux\nSafety level: Configuration Change\nAdministrative rights: conditional\nPackage or module: See platform availability\nSource: Network-CLI-Commands.pdf; Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: ifconfig\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"ifconfig -a","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"ifconfig en0","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"ifconfig en1","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"}],"sourceDocument":"Network-CLI-Commands.pdf; Built-in help or maintained manual page","sourceAuthority":"Network-CLI-Commands.pdf; Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["macos","linux"],"lastVerified":"","vendors":[],"technologies":["Interface Configuration"],"aliases":["macOS interface","Linux legacy interface","MAC address","ip address replacement"],"commandId":"netcli-ifconfig","canonicalName":"ifconfig","shells":["Terminal"],"availability":"built-in on macOS / optional-package and legacy on Linux","safetyLevel":"Configuration Change","adminRequired":"conditional","commandFamily":"Interface Configuration","module":"","modifying":true},{"id":890051,"title":"networksetup - Inspect or Change macOS Network Services","category":"Network Commands","product":"Network CLI","tags":["Interface Configuration","Configuration Change","built-in"],"keywords":["networksetup","macOS DNS","Wi-Fi power","proxy settings","Interface Configuration","Configuration Change","built-in","macos","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"networksetup is a macOS network command used for interface configuration tasks. Availability: built-in.","rootCause":"Use this command when evidence is needed for interface configuration. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the networksetup command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: networksetup\nPlatforms: macOS\nCommand family: Interface Configuration\nAvailability: built-in\nSafety level: Configuration Change\nAdministrative rights: true\nPackage or module: See platform availability\nSource: macOS built-in man page; syntax requires local re-verification\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: networksetup\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"networksetup -listallhardwareports","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"networksetup -listallnetworkservices","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"networksetup -getinfo '<NETWORK-SERVICE>'","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"networksetup -getdnsservers '<NETWORK-SERVICE>'","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"}],"sourceDocument":"macOS built-in man page; syntax requires local re-verification","sourceAuthority":"macOS built-in man page; syntax requires local re-verification","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["macos"],"lastVerified":"","vendors":[],"technologies":["Interface Configuration"],"aliases":["macOS DNS","Wi-Fi power","proxy settings"],"commandId":"netcli-networksetup","canonicalName":"networksetup","shells":["Terminal"],"availability":"built-in","safetyLevel":"Configuration Change","adminRequired":"true","commandFamily":"Interface Configuration","module":"","modifying":true},{"id":890052,"title":"scutil - Inspect macOS DNS, Proxy, and VPN State","category":"Network Commands","product":"Network CLI","tags":["Network Profiles","Safe Read-Only","built-in"],"keywords":["scutil","macOS DNS","macOS proxy","VPN status","Network Profiles","Safe Read-Only","built-in","macos","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"scutil is a macOS network command used for network profiles tasks. Availability: built-in.","rootCause":"Use this command when evidence is needed for network profiles. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the scutil command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: scutil\nPlatforms: macOS\nCommand family: Network Profiles\nAvailability: built-in\nSafety level: Safe Read-Only\nAdministrative rights: false\nPackage or module: See platform availability\nSource: macOS built-in man page; syntax requires local re-verification\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: scutil\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"scutil --dns","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"scutil --proxy","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"scutil --nwi","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"scutil -r example.com","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"scutil --nc list","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"macOS built-in man page; syntax requires local re-verification","sourceAuthority":"macOS built-in man page; syntax requires local re-verification","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["macos"],"lastVerified":"","vendors":[],"technologies":["Network Profiles"],"aliases":["macOS DNS","macOS proxy","VPN status"],"commandId":"netcli-scutil","canonicalName":"scutil","shells":["Terminal"],"availability":"built-in","safetyLevel":"Safe Read-Only","adminRequired":"false","commandFamily":"Network Profiles","module":"","modifying":false},{"id":890053,"title":"dns-sd - Diagnose Bonjour and mDNS","category":"Network Commands","product":"Network CLI","tags":["mDNS and Bonjour","Low-Risk Temporary","built-in"],"keywords":["dns-sd","Bonjour browser","mDNS query","mDNS and Bonjour","Low-Risk Temporary","built-in","macos","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"dns-sd is a macOS network command used for mdns and bonjour tasks. Availability: built-in.","rootCause":"Use this command when evidence is needed for mdns and bonjour. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the dns-sd command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: dns-sd\nPlatforms: macOS\nCommand family: mDNS and Bonjour\nAvailability: built-in\nSafety level: Low-Risk Temporary\nAdministrative rights: false\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: dns-sd\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"dns-sd -B _services._dns-sd._udp local.","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"Terminal","command":"dns-sd -G v4v6 example.local","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"Terminal","command":"dns-sd -Q example.local A","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["macos"],"lastVerified":"","vendors":[],"technologies":["mDNS and Bonjour"],"aliases":["Bonjour browser","mDNS query"],"commandId":"netcli-dns-sd","canonicalName":"dns-sd","shells":["Terminal"],"availability":"built-in","safetyLevel":"Low-Risk Temporary","adminRequired":"false","commandFamily":"mDNS and Bonjour","module":"","modifying":false},{"id":890054,"title":"networkQuality - Measure macOS Network Responsiveness","category":"Network Commands","product":"Network CLI","tags":["Bandwidth and Performance","Low-Risk Temporary","built-in / version-dependent"],"keywords":["networkQuality","macOS speed test","responsiveness","RPM","Bandwidth and Performance","Low-Risk Temporary","built-in / version-dependent","macos","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"networkQuality is a macOS network command used for bandwidth and performance tasks. Availability: built-in / version-dependent.","rootCause":"Use this command when evidence is needed for bandwidth and performance. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the networkQuality command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: networkQuality\nPlatforms: macOS\nCommand family: Bandwidth and Performance\nAvailability: built-in / version-dependent\nSafety level: Low-Risk Temporary\nAdministrative rights: false\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: networkQuality\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"networkQuality","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"Terminal","command":"networkQuality -v","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"Terminal","command":"networkQuality -s","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["macos"],"lastVerified":"","vendors":[],"technologies":["Bandwidth and Performance"],"aliases":["macOS speed test","responsiveness","RPM"],"commandId":"netcli-networkquality","canonicalName":"networkQuality","shells":["Terminal"],"availability":"built-in / version-dependent","safetyLevel":"Low-Risk Temporary","adminRequired":"false","commandFamily":"Bandwidth and Performance","module":"","modifying":false},{"id":890055,"title":"dscacheutil - Query or Refresh macOS Name Cache","category":"Network Commands","product":"Network CLI","tags":["DNS","Configuration Change","built-in"],"keywords":["dscacheutil","macOS flush DNS","name cache","DNS","Configuration Change","built-in","macos","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"dscacheutil is a macOS network command used for dns tasks. Availability: built-in.","rootCause":"Use this command when evidence is needed for dns. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the dscacheutil command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: dscacheutil\nPlatforms: macOS\nCommand family: DNS\nAvailability: built-in\nSafety level: Configuration Change\nAdministrative rights: true\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: dscacheutil\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"dscacheutil -q host -a name example.com","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"dscacheutil -flushcache","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["macos"],"lastVerified":"","vendors":[],"technologies":["DNS"],"aliases":["macOS flush DNS","name cache"],"commandId":"netcli-dscacheutil","canonicalName":"dscacheutil","shells":["Terminal"],"availability":"built-in","safetyLevel":"Configuration Change","adminRequired":"true","commandFamily":"DNS","module":"","modifying":true},{"id":890056,"title":"lsof - Correlate macOS or Linux Ports with Processes","category":"Network Commands","product":"Network CLI","tags":["Processes and Services","Safe Read-Only","installed-by-default / optional-package"],"keywords":["lsof","process using port","listening ports","Processes and Services","Safe Read-Only","installed-by-default / optional-package","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"lsof is a macOS, Linux network command used for processes and services tasks. Availability: installed-by-default / optional-package.","rootCause":"Use this command when evidence is needed for processes and services. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the lsof command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: lsof\nPlatforms: macOS, Linux\nCommand family: Processes and Services\nAvailability: installed-by-default / optional-package\nSafety level: Safe Read-Only\nAdministrative rights: conditional\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: lsof\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"lsof -i","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"lsof -nP -iTCP -sTCP:LISTEN","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"lsof -iUDP","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["macos","linux"],"lastVerified":"","vendors":[],"technologies":["Processes and Services"],"aliases":["process using port","listening ports"],"commandId":"netcli-lsof","canonicalName":"lsof","shells":["Terminal"],"availability":"installed-by-default / optional-package","safetyLevel":"Safe Read-Only","adminRequired":"conditional","commandFamily":"Processes and Services","module":"","modifying":false},{"id":890057,"title":"pfctl - Inspect the macOS Packet Filter","category":"Network Commands","product":"Network CLI","tags":["Firewall","High Impact","built-in"],"keywords":["pfctl","macOS firewall","packet filter","Firewall","High Impact","built-in","macos","network command","terminal command"],"errorCode":"","eventId":"","severity":"High","summary":"pfctl is a macOS network command used for firewall tasks. Availability: built-in.","rootCause":"Use this command when evidence is needed for firewall. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the pfctl command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: pfctl\nPlatforms: macOS\nCommand family: Firewall\nAvailability: built-in\nSafety level: High Impact\nAdministrative rights: true\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: pfctl\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"pfctl -s info","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"Terminal","command":"pfctl -s rules","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"Terminal","command":"pfctl -s states","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"Terminal","command":"pfctl -s Interfaces","risk":"High","admin":true,"safetyLevel":"High Impact"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["macos"],"lastVerified":"","vendors":[],"technologies":["Firewall"],"aliases":["macOS firewall","packet filter"],"commandId":"netcli-pfctl","canonicalName":"pfctl","shells":["Terminal"],"availability":"built-in","safetyLevel":"High Impact","adminRequired":"true","commandFamily":"Firewall","module":"","modifying":true},{"id":890058,"title":"ip address - Inspect or Change Linux IP Addresses","category":"Network Commands","product":"iproute2","tags":["Interface Configuration","Configuration Change","installed-by-default / iproute2"],"keywords":["ip address","Linux IP address","iproute2","IPv6 address","Interface Configuration","Configuration Change","installed-by-default / iproute2","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"ip address is a Linux network command used for interface configuration tasks. Availability: installed-by-default / iproute2.","rootCause":"Use this command when evidence is needed for interface configuration. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the ip address command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: ip address\nPlatforms: Linux\nCommand family: Interface Configuration\nAvailability: installed-by-default / iproute2\nSafety level: Configuration Change\nAdministrative rights: true\nPackage or module: iproute2\nSource: iproute2 ip(8) maintained manual page\nReview status: verified\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: ip address\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"ip -br address","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"ip address show","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"ip -6 address show","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"ip address add <ADDRESS>/<PREFIX> dev <INTERFACE>","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"}],"sourceDocument":"iproute2 ip(8) maintained manual page","sourceAuthority":"iproute2 ip(8) maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["linux"],"lastVerified":"2026-08-06","vendors":[],"technologies":["Interface Configuration"],"aliases":["Linux IP address","iproute2","IPv6 address"],"commandId":"netcli-ip-address","canonicalName":"ip address","shells":["Terminal"],"availability":"installed-by-default / iproute2","safetyLevel":"Configuration Change","adminRequired":"true","commandFamily":"Interface Configuration","module":"iproute2","modifying":true},{"id":890059,"title":"ip link - Inspect or Change Linux Interfaces","category":"Network Commands","product":"iproute2","tags":["Interface Configuration","Disruptive","installed-by-default / iproute2"],"keywords":["ip link","Linux interface","iproute2","MTU","Interface Configuration","Disruptive","installed-by-default / iproute2","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"High","summary":"ip link is a Linux network command used for interface configuration tasks. Availability: installed-by-default / iproute2.","rootCause":"Use this command when evidence is needed for interface configuration. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the ip link command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: ip link\nPlatforms: Linux\nCommand family: Interface Configuration\nAvailability: installed-by-default / iproute2\nSafety level: Disruptive\nAdministrative rights: true\nPackage or module: iproute2\nSource: iproute2 ip(8) maintained manual page\nReview status: verified\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: ip link\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"ip -br link","risk":"High","admin":true,"safetyLevel":"Disruptive"},{"shell":"Terminal","command":"ip link show","risk":"High","admin":true,"safetyLevel":"Disruptive"},{"shell":"Terminal","command":"ip link set dev <INTERFACE> up","risk":"High","admin":true,"safetyLevel":"Disruptive"},{"shell":"Terminal","command":"ip link set dev <INTERFACE> down","risk":"High","admin":true,"safetyLevel":"Disruptive"},{"shell":"Terminal","command":"ip link set dev <INTERFACE> mtu <MTU>","risk":"High","admin":true,"safetyLevel":"Disruptive"}],"sourceDocument":"iproute2 ip(8) maintained manual page","sourceAuthority":"iproute2 ip(8) maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["linux"],"lastVerified":"2026-08-06","vendors":[],"technologies":["Interface Configuration"],"aliases":["Linux interface","iproute2","MTU"],"commandId":"netcli-ip-link","canonicalName":"ip link","shells":["Terminal"],"availability":"installed-by-default / iproute2","safetyLevel":"Disruptive","adminRequired":"true","commandFamily":"Interface Configuration","module":"iproute2","modifying":true},{"id":890060,"title":"ip route - Inspect or Change Linux Routes","category":"Network Commands","product":"iproute2","tags":["Routing","High Impact","installed-by-default / iproute2"],"keywords":["ip route","Linux routing table","default route","iproute2","IPv6 route","Routing","High Impact","installed-by-default / iproute2","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"High","summary":"ip route is a Linux network command used for routing tasks. Availability: installed-by-default / iproute2.","rootCause":"Use this command when evidence is needed for routing. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the ip route command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: ip route\nPlatforms: Linux\nCommand family: Routing\nAvailability: installed-by-default / iproute2\nSafety level: High Impact\nAdministrative rights: true\nPackage or module: iproute2\nSource: iproute2 ip(8) maintained manual page\nReview status: verified\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: ip route\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"ip route show","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"Terminal","command":"ip -6 route show","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"Terminal","command":"ip route get <DESTINATION>","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"Terminal","command":"ip route add <PREFIX> via <GATEWAY>","risk":"High","admin":true,"safetyLevel":"High Impact"}],"sourceDocument":"iproute2 ip(8) maintained manual page","sourceAuthority":"iproute2 ip(8) maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["linux"],"lastVerified":"2026-08-06","vendors":[],"technologies":["Routing"],"aliases":["Linux routing table","default route","iproute2","IPv6 route"],"commandId":"netcli-ip-route","canonicalName":"ip route","shells":["Terminal"],"availability":"installed-by-default / iproute2","safetyLevel":"High Impact","adminRequired":"true","commandFamily":"Routing","module":"iproute2","modifying":true},{"id":890061,"title":"ip neighbor - Inspect or Change Linux Neighbor Entries","category":"Network Commands","product":"iproute2","tags":["ARP and Neighbor Discovery","Configuration Change","installed-by-default / iproute2"],"keywords":["ip neighbor","Linux ARP","NDP","neighbor cache","iproute2","ARP and Neighbor Discovery","Configuration Change","installed-by-default / iproute2","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"ip neighbor is a Linux network command used for arp and neighbor discovery tasks. Availability: installed-by-default / iproute2.","rootCause":"Use this command when evidence is needed for arp and neighbor discovery. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the ip neighbor command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: ip neighbor\nPlatforms: Linux\nCommand family: ARP and Neighbor Discovery\nAvailability: installed-by-default / iproute2\nSafety level: Configuration Change\nAdministrative rights: true\nPackage or module: iproute2\nSource: iproute2 ip(8) maintained manual page\nReview status: verified\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: ip neighbor\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"ip neighbor show","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"ip -6 neighbor show","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"ip neighbor flush dev <INTERFACE>","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"}],"sourceDocument":"iproute2 ip(8) maintained manual page","sourceAuthority":"iproute2 ip(8) maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["linux"],"lastVerified":"2026-08-06","vendors":[],"technologies":["ARP and Neighbor Discovery"],"aliases":["Linux ARP","NDP","neighbor cache","iproute2"],"commandId":"netcli-ip-neighbor","canonicalName":"ip neighbor","shells":["Terminal"],"availability":"installed-by-default / iproute2","safetyLevel":"Configuration Change","adminRequired":"true","commandFamily":"ARP and Neighbor Discovery","module":"iproute2","modifying":true},{"id":890062,"title":"ip netns - Manage Linux Network Namespaces","category":"Network Commands","product":"iproute2","tags":["Network Namespaces","High Impact","installed-by-default / iproute2"],"keywords":["ip netns","network namespace","container networking","iproute2","Network Namespaces","High Impact","installed-by-default / iproute2","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"High","summary":"ip netns is a Linux network command used for network namespaces tasks. Availability: installed-by-default / iproute2.","rootCause":"Use this command when evidence is needed for network namespaces. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the ip netns command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: ip netns\nPlatforms: Linux\nCommand family: Network Namespaces\nAvailability: installed-by-default / iproute2\nSafety level: High Impact\nAdministrative rights: true\nPackage or module: iproute2\nSource: iproute2 ip(8) maintained manual page\nReview status: verified\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: ip netns\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"ip netns list","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"Terminal","command":"ip netns identify","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"Terminal","command":"ip netns exec <NAMESPACE> ip address","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"Terminal","command":"ip netns add <NAMESPACE>","risk":"High","admin":true,"safetyLevel":"High Impact"}],"sourceDocument":"iproute2 ip(8) maintained manual page","sourceAuthority":"iproute2 ip(8) maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["linux"],"lastVerified":"2026-08-06","vendors":[],"technologies":["Network Namespaces"],"aliases":["network namespace","container networking","iproute2"],"commandId":"netcli-ip-netns","canonicalName":"ip netns","shells":["Terminal"],"availability":"installed-by-default / iproute2","safetyLevel":"High Impact","adminRequired":"true","commandFamily":"Network Namespaces","module":"iproute2","modifying":true},{"id":890063,"title":"ss - Inspect Linux Sockets and Listening Ports","category":"Network Commands","product":"iproute2","tags":["Sockets and Ports","Safe Read-Only","installed-by-default / iproute2"],"keywords":["ss","Linux netstat replacement","listening ports","process using port","socket state","Sockets and Ports","Safe Read-Only","installed-by-default / iproute2","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"ss is a Linux network command used for sockets and ports tasks. Availability: installed-by-default / iproute2.","rootCause":"Use this command when evidence is needed for sockets and ports. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the ss command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: ss\nPlatforms: Linux\nCommand family: Sockets and Ports\nAvailability: installed-by-default / iproute2\nSafety level: Safe Read-Only\nAdministrative rights: conditional\nPackage or module: iproute2\nSource: ss(8) maintained manual page\nReview status: verified\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: ss\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"ss -s","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"ss -tulpn","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"ss -tan","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"ss -uan","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"ss -o","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"ss(8) maintained manual page","sourceAuthority":"ss(8) maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["linux"],"lastVerified":"2026-08-06","vendors":[],"technologies":["Sockets and Ports"],"aliases":["Linux netstat replacement","listening ports","process using port","socket state"],"commandId":"netcli-ss","canonicalName":"ss","shells":["Terminal"],"availability":"installed-by-default / iproute2","safetyLevel":"Safe Read-Only","adminRequired":"conditional","commandFamily":"Sockets and Ports","module":"iproute2","modifying":false},{"id":890064,"title":"bridge - Inspect Linux Bridge State","category":"Network Commands","product":"Network CLI","tags":["Bridging","Configuration Change","installed-by-default / iproute2"],"keywords":["bridge","Linux bridge","FDB","VLAN","iproute2","Bridging","Configuration Change","installed-by-default / iproute2","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"bridge is a Linux network command used for bridging tasks. Availability: installed-by-default / iproute2.","rootCause":"Use this command when evidence is needed for bridging. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the bridge command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: bridge\nPlatforms: Linux\nCommand family: Bridging\nAvailability: installed-by-default / iproute2\nSafety level: Configuration Change\nAdministrative rights: true\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: bridge\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"bridge link","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"bridge fdb show","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"bridge vlan show","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"bridge monitor","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["linux"],"lastVerified":"","vendors":[],"technologies":["Bridging"],"aliases":["Linux bridge","FDB","VLAN","iproute2"],"commandId":"netcli-bridge","canonicalName":"bridge","shells":["Terminal"],"availability":"installed-by-default / iproute2","safetyLevel":"Configuration Change","adminRequired":"true","commandFamily":"Bridging","module":"","modifying":true},{"id":890065,"title":"tc - Inspect Linux Traffic Control","category":"Network Commands","product":"Network CLI","tags":["QoS and Traffic Control","High Impact","installed-by-default / iproute2"],"keywords":["tc","Linux QoS","traffic shaping","qdisc","QoS and Traffic Control","High Impact","installed-by-default / iproute2","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"High","summary":"tc is a Linux network command used for qos and traffic control tasks. Availability: installed-by-default / iproute2.","rootCause":"Use this command when evidence is needed for qos and traffic control. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the tc command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: tc\nPlatforms: Linux\nCommand family: QoS and Traffic Control\nAvailability: installed-by-default / iproute2\nSafety level: High Impact\nAdministrative rights: true\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: tc\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"tc qdisc show","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"Terminal","command":"tc class show","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"Terminal","command":"tc filter show","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"Terminal","command":"tc -s qdisc show","risk":"High","admin":true,"safetyLevel":"High Impact"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["linux"],"lastVerified":"","vendors":[],"technologies":["QoS and Traffic Control"],"aliases":["Linux QoS","traffic shaping","qdisc"],"commandId":"netcli-tc","canonicalName":"tc","shells":["Terminal"],"availability":"installed-by-default / iproute2","safetyLevel":"High Impact","adminRequired":"true","commandFamily":"QoS and Traffic Control","module":"","modifying":true},{"id":890066,"title":"nmcli - Inspect or Change NetworkManager Connections","category":"Network Commands","product":"Network CLI","tags":["Network Profiles","Configuration Change","installed-by-default / distribution-dependent"],"keywords":["nmcli","NetworkManager","Linux Wi-Fi","connection profile","Network Profiles","Configuration Change","installed-by-default / distribution-dependent","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"nmcli is a Linux network command used for network profiles tasks. Availability: installed-by-default / distribution-dependent.","rootCause":"Use this command when evidence is needed for network profiles. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the nmcli command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: nmcli\nPlatforms: Linux\nCommand family: Network Profiles\nAvailability: installed-by-default / distribution-dependent\nSafety level: Configuration Change\nAdministrative rights: true\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: nmcli\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"nmcli general status","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"nmcli device status","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"nmcli device show","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"nmcli connection show --active","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"nmcli connection up '<CONNECTION>'","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["linux"],"lastVerified":"","vendors":[],"technologies":["Network Profiles"],"aliases":["NetworkManager","Linux Wi-Fi","connection profile"],"commandId":"netcli-nmcli","canonicalName":"nmcli","shells":["Terminal"],"availability":"installed-by-default / distribution-dependent","safetyLevel":"Configuration Change","adminRequired":"true","commandFamily":"Network Profiles","module":"","modifying":true},{"id":890067,"title":"resolvectl - Inspect systemd DNS Resolution","category":"Network Commands","product":"Network CLI","tags":["DNS","Configuration Change","distribution-dependent / systemd-resolved"],"keywords":["resolvectl","systemd-resolved","Linux DNS","flush DNS","DNS","Configuration Change","distribution-dependent / systemd-resolved","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"resolvectl is a Linux network command used for dns tasks. Availability: distribution-dependent / systemd-resolved.","rootCause":"Use this command when evidence is needed for dns. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the resolvectl command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: resolvectl\nPlatforms: Linux\nCommand family: DNS\nAvailability: distribution-dependent / systemd-resolved\nSafety level: Configuration Change\nAdministrative rights: conditional\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: resolvectl\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"resolvectl status","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"resolvectl query example.com","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"resolvectl statistics","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"resolvectl flush-caches","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["linux"],"lastVerified":"","vendors":[],"technologies":["DNS"],"aliases":["systemd-resolved","Linux DNS","flush DNS"],"commandId":"netcli-resolvectl","canonicalName":"resolvectl","shells":["Terminal"],"availability":"distribution-dependent / systemd-resolved","safetyLevel":"Configuration Change","adminRequired":"conditional","commandFamily":"DNS","module":"","modifying":true},{"id":890068,"title":"networkctl - Inspect systemd-networkd State","category":"Network Commands","product":"Network CLI","tags":["Network Profiles","Safe Read-Only","distribution-dependent / systemd-networkd"],"keywords":["networkctl","systemd-networkd","Linux interface","Network Profiles","Safe Read-Only","distribution-dependent / systemd-networkd","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"networkctl is a Linux network command used for network profiles tasks. Availability: distribution-dependent / systemd-networkd.","rootCause":"Use this command when evidence is needed for network profiles. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the networkctl command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: networkctl\nPlatforms: Linux\nCommand family: Network Profiles\nAvailability: distribution-dependent / systemd-networkd\nSafety level: Safe Read-Only\nAdministrative rights: conditional\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: networkctl\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"networkctl list","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"networkctl status","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"networkctl status <INTERFACE>","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["linux"],"lastVerified":"","vendors":[],"technologies":["Network Profiles"],"aliases":["systemd-networkd","Linux interface"],"commandId":"netcli-networkctl","canonicalName":"networkctl","shells":["Terminal"],"availability":"distribution-dependent / systemd-networkd","safetyLevel":"Safe Read-Only","adminRequired":"conditional","commandFamily":"Network Profiles","module":"","modifying":false},{"id":890069,"title":"journalctl - Review Linux Network Service Logs","category":"Network Commands","product":"Network CLI","tags":["Logging and Evidence Collection","Safe Read-Only","installed-by-default / systemd"],"keywords":["journalctl network","NetworkManager logs","DNS logs","network service logs","Logging and Evidence Collection","Safe Read-Only","installed-by-default / systemd","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"journalctl network is a Linux network command used for logging and evidence collection tasks. Availability: installed-by-default / systemd.","rootCause":"Use this command when evidence is needed for logging and evidence collection. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the journalctl network command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: journalctl network\nPlatforms: Linux\nCommand family: Logging and Evidence Collection\nAvailability: installed-by-default / systemd\nSafety level: Safe Read-Only\nAdministrative rights: conditional\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: journalctl network\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"journalctl -u NetworkManager --since today","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"journalctl -u systemd-networkd --since today","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"journalctl -u systemd-resolved --since today","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["linux"],"lastVerified":"","vendors":[],"technologies":["Logging and Evidence Collection"],"aliases":["NetworkManager logs","DNS logs","network service logs"],"commandId":"netcli-journalctl-network","canonicalName":"journalctl network","shells":["Terminal"],"availability":"installed-by-default / systemd","safetyLevel":"Safe Read-Only","adminRequired":"conditional","commandFamily":"Logging and Evidence Collection","module":"","modifying":false},{"id":890070,"title":"ethtool - Inspect Linux Ethernet Link State","category":"Network Commands","product":"Network CLI","tags":["Interface Configuration","Configuration Change","optional-package"],"keywords":["ethtool","link speed","duplex","driver","NIC statistics","Interface Configuration","Configuration Change","optional-package","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"ethtool is a Linux network command used for interface configuration tasks. Availability: optional-package.","rootCause":"Use this command when evidence is needed for interface configuration. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the ethtool command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: ethtool\nPlatforms: Linux\nCommand family: Interface Configuration\nAvailability: optional-package\nSafety level: Configuration Change\nAdministrative rights: true\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: ethtool\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"ethtool <INTERFACE>","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"ethtool -i <INTERFACE>","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"ethtool -S <INTERFACE>","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["linux"],"lastVerified":"","vendors":[],"technologies":["Interface Configuration"],"aliases":["link speed","duplex","driver","NIC statistics"],"commandId":"netcli-ethtool","canonicalName":"ethtool","shells":["Terminal"],"availability":"optional-package","safetyLevel":"Configuration Change","adminRequired":"true","commandFamily":"Interface Configuration","module":"","modifying":true},{"id":890071,"title":"iw - Inspect Linux Wi-Fi","category":"Network Commands","product":"Network CLI","tags":["Wi-Fi","Configuration Change","optional-package"],"keywords":["iw","Linux wireless","Wi-Fi signal","Wi-Fi","Configuration Change","optional-package","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"iw is a Linux network command used for wi-fi tasks. Availability: optional-package.","rootCause":"Use this command when evidence is needed for wi-fi. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the iw command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: iw\nPlatforms: Linux\nCommand family: Wi-Fi\nAvailability: optional-package\nSafety level: Configuration Change\nAdministrative rights: true\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: iw\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"iw dev","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"iw dev <INTERFACE> link","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"iw dev <INTERFACE> scan","risk":"Standard","admin":true,"safetyLevel":"Configuration Change"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["linux"],"lastVerified":"","vendors":[],"technologies":["Wi-Fi"],"aliases":["Linux wireless","Wi-Fi signal"],"commandId":"netcli-iw","canonicalName":"iw","shells":["Terminal"],"availability":"optional-package","safetyLevel":"Configuration Change","adminRequired":"true","commandFamily":"Wi-Fi","module":"","modifying":true},{"id":890072,"title":"rfkill - Inspect or Change Linux Radio State","category":"Network Commands","product":"Network CLI","tags":["Wi-Fi","Disruptive","optional-package"],"keywords":["rfkill","airplane mode","radio blocked","Wi-Fi","Disruptive","optional-package","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"High","summary":"rfkill is a Linux network command used for wi-fi tasks. Availability: optional-package.","rootCause":"Use this command when evidence is needed for wi-fi. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the rfkill command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: rfkill\nPlatforms: Linux\nCommand family: Wi-Fi\nAvailability: optional-package\nSafety level: Disruptive\nAdministrative rights: true\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: rfkill\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"rfkill list","risk":"High","admin":true,"safetyLevel":"Disruptive"},{"shell":"Terminal","command":"rfkill block wifi","risk":"High","admin":true,"safetyLevel":"Disruptive"},{"shell":"Terminal","command":"rfkill unblock wifi","risk":"High","admin":true,"safetyLevel":"Disruptive"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["linux"],"lastVerified":"","vendors":[],"technologies":["Wi-Fi"],"aliases":["airplane mode","radio blocked"],"commandId":"netcli-rfkill","canonicalName":"rfkill","shells":["Terminal"],"availability":"optional-package","safetyLevel":"Disruptive","adminRequired":"true","commandFamily":"Wi-Fi","module":"","modifying":true},{"id":890073,"title":"nft - Inspect Linux nftables Firewall Rules","category":"Network Commands","product":"Network CLI","tags":["Firewall","High Impact","distribution-dependent / nftables"],"keywords":["nft","nftables","Linux firewall","NAT","Firewall","High Impact","distribution-dependent / nftables","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"High","summary":"nft is a Linux network command used for firewall tasks. Availability: distribution-dependent / nftables.","rootCause":"Use this command when evidence is needed for firewall. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the nft command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: nft\nPlatforms: Linux\nCommand family: Firewall\nAvailability: distribution-dependent / nftables\nSafety level: High Impact\nAdministrative rights: true\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: nft\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"nft list ruleset","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"Terminal","command":"nft list tables","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"Terminal","command":"nft list table inet filter","risk":"High","admin":true,"safetyLevel":"High Impact"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["linux"],"lastVerified":"","vendors":[],"technologies":["Firewall"],"aliases":["nftables","Linux firewall","NAT"],"commandId":"netcli-nft","canonicalName":"nft","shells":["Terminal"],"availability":"distribution-dependent / nftables","safetyLevel":"High Impact","adminRequired":"true","commandFamily":"Firewall","module":"","modifying":true},{"id":890074,"title":"ufw - Inspect Ubuntu Firewall State","category":"Network Commands","product":"Network CLI","tags":["Firewall","High Impact","optional-package / distribution-dependent"],"keywords":["ufw","Ubuntu firewall","firewall rules","Firewall","High Impact","optional-package / distribution-dependent","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"High","summary":"ufw is a Linux network command used for firewall tasks. Availability: optional-package / distribution-dependent.","rootCause":"Use this command when evidence is needed for firewall. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the ufw command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: ufw\nPlatforms: Linux\nCommand family: Firewall\nAvailability: optional-package / distribution-dependent\nSafety level: High Impact\nAdministrative rights: true\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: ufw\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"ufw status verbose","risk":"High","admin":true,"safetyLevel":"High Impact"},{"shell":"Terminal","command":"ufw status numbered","risk":"High","admin":true,"safetyLevel":"High Impact"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["linux"],"lastVerified":"","vendors":[],"technologies":["Firewall"],"aliases":["Ubuntu firewall","firewall rules"],"commandId":"netcli-ufw","canonicalName":"ufw","shells":["Terminal"],"availability":"optional-package / distribution-dependent","safetyLevel":"High Impact","adminRequired":"true","commandFamily":"Firewall","module":"","modifying":true},{"id":890075,"title":"tracepath - Trace a Linux Path and MTU","category":"Network Commands","product":"Network CLI","tags":["MTU and Fragmentation","Low-Risk Temporary","optional-package / distribution-dependent"],"keywords":["tracepath","path MTU","trace route","PMTU","MTU and Fragmentation","Low-Risk Temporary","optional-package / distribution-dependent","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"tracepath is a Linux network command used for mtu and fragmentation tasks. Availability: optional-package / distribution-dependent.","rootCause":"Use this command when evidence is needed for mtu and fragmentation. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the tracepath command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: tracepath\nPlatforms: Linux\nCommand family: MTU and Fragmentation\nAvailability: optional-package / distribution-dependent\nSafety level: Low-Risk Temporary\nAdministrative rights: false\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: tracepath\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"tracepath example.com","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"Terminal","command":"tracepath -n example.com","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["linux"],"lastVerified":"","vendors":[],"technologies":["MTU and Fragmentation"],"aliases":["path MTU","trace route","PMTU"],"commandId":"netcli-tracepath","canonicalName":"tracepath","shells":["Terminal"],"availability":"optional-package / distribution-dependent","safetyLevel":"Low-Risk Temporary","adminRequired":"false","commandFamily":"MTU and Fragmentation","module":"","modifying":false},{"id":890076,"title":"wget - Retrieve Web Content from a Terminal","category":"Network Commands","product":"Network CLI","tags":["HTTP and HTTPS","Configuration Change","optional-package / distribution-dependent"],"keywords":["wget","download file","HTTP test","HTTP and HTTPS","Configuration Change","optional-package / distribution-dependent","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"wget is a macOS, Linux network command used for http and https tasks. Availability: optional-package / distribution-dependent.","rootCause":"Use this command when evidence is needed for http and https. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the wget command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: wget\nPlatforms: macOS, Linux\nCommand family: HTTP and HTTPS\nAvailability: optional-package / distribution-dependent\nSafety level: Configuration Change\nAdministrative rights: false\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: wget\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"wget \"https://example.com/file\"","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"},{"shell":"Terminal","command":"wget --spider \"https://example.com/file\"","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["macos","linux"],"lastVerified":"","vendors":[],"technologies":["HTTP and HTTPS"],"aliases":["download file","HTTP test"],"commandId":"netcli-wget","canonicalName":"wget","shells":["Terminal"],"availability":"optional-package / distribution-dependent","safetyLevel":"Configuration Change","adminRequired":"false","commandFamily":"HTTP and HTTPS","module":"","modifying":true},{"id":890077,"title":"ftp - Use Legacy File Transfer Protocol","category":"Network Commands","product":"Network CLI","tags":["Remote Access","Configuration Change","legacy / optional-feature / version-dependent / optional-package"],"keywords":["ftp","File Transfer Protocol","port 21","legacy file transfer","Remote Access","Configuration Change","legacy / optional-feature / version-dependent / optional-package","windows","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"ftp is a Windows, macOS, Linux network command used for remote access tasks. Availability: legacy / optional-feature / version-dependent / optional-package.","rootCause":"Use this command when evidence is needed for remote access. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the ftp command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: ftp\nPlatforms: Windows, macOS, Linux\nCommand family: Remote Access\nAvailability: legacy / optional-feature / version-dependent / optional-package\nSafety level: Configuration Change\nAdministrative rights: false\nPackage or module: See platform availability\nSource: Built-in or package help; prefer SFTP for protected transfers\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: ftp\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"ftp <HOSTNAME>","risk":"Standard","admin":false,"safetyLevel":"Configuration Change"}],"sourceDocument":"Built-in or package help; prefer SFTP for protected transfers","sourceAuthority":"Built-in or package help; prefer SFTP for protected transfers","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows","macos","linux"],"lastVerified":"","vendors":[],"technologies":["Remote Access"],"aliases":["File Transfer Protocol","port 21","legacy file transfer"],"commandId":"netcli-ftp","canonicalName":"ftp","shells":["Terminal"],"availability":"legacy / optional-feature / version-dependent / optional-package","safetyLevel":"Configuration Change","adminRequired":"false","commandFamily":"Remote Access","module":"","modifying":true},{"id":890078,"title":"ncat - Test or Relay Network Connections","category":"Network Commands","product":"Network CLI","tags":["Sockets and Ports","Low-Risk Temporary","third-party / optional-package"],"keywords":["ncat","Nmap netcat","check port","TLS port test","Sockets and Ports","Low-Risk Temporary","third-party / optional-package","windows","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"ncat is a Windows, macOS, Linux network command used for sockets and ports tasks. Availability: third-party / optional-package.","rootCause":"Use this command when evidence is needed for sockets and ports. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the ncat command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: ncat\nPlatforms: Windows, macOS, Linux\nCommand family: Sockets and Ports\nAvailability: third-party / optional-package\nSafety level: Low-Risk Temporary\nAdministrative rights: conditional\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: ncat\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"ncat -vz <HOSTNAME> <PORT>","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"},{"shell":"Terminal","command":"ncat --ssl <HOSTNAME> <PORT>","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows","macos","linux"],"lastVerified":"","vendors":[],"technologies":["Sockets and Ports"],"aliases":["Nmap netcat","check port","TLS port test"],"commandId":"netcli-ncat","canonicalName":"ncat","shells":["Terminal"],"availability":"third-party / optional-package","safetyLevel":"Low-Risk Temporary","adminRequired":"conditional","commandFamily":"Sockets and Ports","module":"","modifying":false},{"id":890079,"title":"socat - Connect or Relay Network Streams","category":"Network Commands","product":"Network CLI","tags":["Sockets and Ports","Low-Risk Temporary","optional-package"],"keywords":["socat","socket relay","port test","Sockets and Ports","Low-Risk Temporary","optional-package","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"socat is a macOS, Linux network command used for sockets and ports tasks. Availability: optional-package.","rootCause":"Use this command when evidence is needed for sockets and ports. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the socat command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: socat\nPlatforms: macOS, Linux\nCommand family: Sockets and Ports\nAvailability: optional-package\nSafety level: Low-Risk Temporary\nAdministrative rights: conditional\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: socat\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"socat - TCP:<HOSTNAME>:<PORT>,connect-timeout=10","risk":"Standard","admin":false,"safetyLevel":"Low-Risk Temporary"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["macos","linux"],"lastVerified":"","vendors":[],"technologies":["Sockets and Ports"],"aliases":["socket relay","port test"],"commandId":"netcli-socat","canonicalName":"socat","shells":["Terminal"],"availability":"optional-package","safetyLevel":"Low-Risk Temporary","adminRequired":"conditional","commandFamily":"Sockets and Ports","module":"","modifying":false},{"id":890080,"title":"whois - Query Registration Information","category":"Network Commands","product":"Network CLI","tags":["Network Identity","Safe Read-Only","version-dependent / optional-package / third-party"],"keywords":["whois","domain registration","IP registration","RIR lookup","Network Identity","Safe Read-Only","version-dependent / optional-package / third-party","windows","macos","linux","network command","terminal command"],"errorCode":"","eventId":"","severity":"Low","summary":"whois is a Windows, macOS, Linux network command used for network identity tasks. Availability: version-dependent / optional-package / third-party.","rootCause":"Use this command when evidence is needed for network identity. Confirm the local implementation and options before use because syntax and availability can differ by operating system, version, package, and shell.","resolution":"1. Confirm the target platform and command availability.\n2. Start with the read-only example when one is available.\n3. Record relevant output before making changes.\n4. Review the safety and privilege metadata.\n5. Run only against authorized systems and validate the result.","emailScript":"Hello,\n\nWe are collecting network diagnostic information using the whois command. This will help us identify the affected network layer and determine the appropriate corrective action.\n\nThank you,\n\nIT Support","faqSteps":"Open the appropriate terminal for your operating system. Run only the command supplied by IT Support. Do not include passwords, tokens, private keys, Wi-Fi keys, or unrelated private information when sharing the output.","notes":"Canonical command: whois\nPlatforms: Windows, macOS, Linux\nCommand family: Network Identity\nAvailability: version-dependent / optional-package / third-party\nSafety level: Safe Read-Only\nAdministrative rights: false\nPackage or module: See platform availability\nSource: Built-in help or maintained manual page\nReview status: needs-review\n\nDo not use modifying commands on a remotely accessed device without a recovery path. Do not disable IPv6 or a firewall as a generic fix. Packet captures and diagnostic output may contain sensitive data.\n\nNETWORK TROUBLESHOOTING NOTES\nDevice: [Device Name]\nPlatform: [Windows / macOS / Linux]\nCommand: whois\nPurpose: [What Was Tested]\nTarget: [Host, IP, Port, Interface, or Service]\nObserved Output: [Relevant Result]\nExpected Result: [Expected Result]\nFindings: [What the Result Indicates]\nActions: [Changes Completed]\nVerification: [Final Test]\nFollow-Up: [Remaining Work]","commands":[{"shell":"Terminal","command":"whois example.com","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"whois 192.0.2.10","risk":"Standard","admin":false,"safetyLevel":"Safe Read-Only"}],"sourceDocument":"Built-in help or maintained manual page","sourceAuthority":"Built-in help or maintained manual page","definingStandard":"Built-in help or maintained command documentation","registrationStatus":"command-reference","namespace":"NETCLI","platforms":["windows","macos","linux"],"lastVerified":"","vendors":[],"technologies":["Network Identity"],"aliases":["domain registration","IP registration","RIR lookup"],"commandId":"netcli-whois","canonicalName":"whois","shells":["Terminal"],"availability":"version-dependent / optional-package / third-party","safetyLevel":"Safe Read-Only","adminRequired":"false","commandFamily":"Network Identity","module":"","modifying":false},{"id":899001,"title":"Windows Basic Network Troubleshooting Sequence","category":"Network Commands","product":"Network CLI","tags":["Troubleshooting Sequence","Safe Read-Only"],"keywords":["basic connectivity","network troubleshooting sequence","windows"],"errorCode":"","eventId":"","severity":"Low","summary":"A structured evidence-first sequence for diagnosing basic connectivity on the selected platform.","rootCause":"Use this sequence to locate a failure across interface, addressing, routing, DNS, reachability, ports, and path analysis without beginning with disruptive resets.","resolution":"1. Get-NetAdapter\n2. Get-NetIPConfiguration\n3. Get-NetIPAddress\n4. Get-NetRoute\n5. Get-DnsClientServerAddress\n6. Test-Connection <GATEWAY>\n7. Resolve-DnsName <HOSTNAME>\n8. Test-NetConnection <HOSTNAME> -Port <PORT>\n9. tracert <HOSTNAME>","emailScript":"Hello,\n\nWe are completing a structured network diagnostic sequence to identify where connectivity is failing. We will review the results before making configuration changes.\n\nThank you,\n\nIT Support","faqSteps":"Run only the steps provided by IT Support and return the requested output after removing private or sensitive information.","notes":"Use placeholders appropriate to the environment. Do not assume a public test address is allowed. Preserve evidence before resets or service restarts.","commands":[{"shell":"PowerShell","command":"Get-NetAdapter","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-NetIPConfiguration","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-NetIPAddress","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-NetRoute","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Get-DnsClientServerAddress","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Test-Connection <GATEWAY>","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Resolve-DnsName <HOSTNAME>","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"PowerShell","command":"Test-NetConnection <HOSTNAME> -Port <PORT>","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"CMD","command":"tracert <HOSTNAME>","risk":"Standard","safetyLevel":"Safe Read-Only"}],"namespace":"NETCLI","platforms":["windows"],"sourceDocument":"CopyCat Network Command Library","lastVerified":"","availability":"varies by command","safetyLevel":"Safe Read-Only","adminRequired":"conditional","commandFamily":"Basic Connectivity","vendors":["Network CLI"],"technologies":["Troubleshooting Sequence","Safe Read-Only"],"aliases":[]},{"id":899002,"title":"macOS Basic Network Troubleshooting Sequence","category":"Network Commands","product":"Network CLI","tags":["Troubleshooting Sequence","Safe Read-Only"],"keywords":["basic connectivity","network troubleshooting sequence","macos"],"errorCode":"","eventId":"","severity":"Low","summary":"A structured evidence-first sequence for diagnosing basic connectivity on the selected platform.","rootCause":"Use this sequence to locate a failure across interface, addressing, routing, DNS, reachability, ports, and path analysis without beginning with disruptive resets.","resolution":"1. networksetup -listallhardwareports\n2. ifconfig -a\n3. scutil --nwi\n4. route -n get default\n5. scutil --dns\n6. ping <GATEWAY>\n7. dig <HOSTNAME>\n8. nc -vz <HOSTNAME> <PORT>\n9. traceroute <HOSTNAME>","emailScript":"Hello,\n\nWe are completing a structured network diagnostic sequence to identify where connectivity is failing. We will review the results before making configuration changes.\n\nThank you,\n\nIT Support","faqSteps":"Run only the steps provided by IT Support and return the requested output after removing private or sensitive information.","notes":"Use placeholders appropriate to the environment. Do not assume a public test address is allowed. Preserve evidence before resets or service restarts.","commands":[{"shell":"Terminal","command":"networksetup -listallhardwareports","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"ifconfig -a","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"scutil --nwi","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"route -n get default","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"scutil --dns","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"ping <GATEWAY>","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"dig <HOSTNAME>","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"nc -vz <HOSTNAME> <PORT>","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"traceroute <HOSTNAME>","risk":"Standard","safetyLevel":"Safe Read-Only"}],"namespace":"NETCLI","platforms":["macos"],"sourceDocument":"CopyCat Network Command Library","lastVerified":"","availability":"varies by command","safetyLevel":"Safe Read-Only","adminRequired":"conditional","commandFamily":"Basic Connectivity","vendors":["Network CLI"],"technologies":["Troubleshooting Sequence","Safe Read-Only"],"aliases":[]},{"id":899003,"title":"Linux Basic Network Troubleshooting Sequence","category":"Network Commands","product":"Network CLI","tags":["Troubleshooting Sequence","Safe Read-Only"],"keywords":["basic connectivity","network troubleshooting sequence","linux"],"errorCode":"","eventId":"","severity":"Low","summary":"A structured evidence-first sequence for diagnosing basic connectivity on the selected platform.","rootCause":"Use this sequence to locate a failure across interface, addressing, routing, DNS, reachability, ports, and path analysis without beginning with disruptive resets.","resolution":"1. ip -br link\n2. ip -br address\n3. ip route\n4. ip route get <DESTINATION>\n5. ip neighbor\n6. resolvectl status\n7. ping <GATEWAY>\n8. dig <HOSTNAME>\n9. ss -tulpn\n10. nc -vz <HOSTNAME> <PORT>\n11. tracepath <HOSTNAME>","emailScript":"Hello,\n\nWe are completing a structured network diagnostic sequence to identify where connectivity is failing. We will review the results before making configuration changes.\n\nThank you,\n\nIT Support","faqSteps":"Run only the steps provided by IT Support and return the requested output after removing private or sensitive information.","notes":"Use placeholders appropriate to the environment. Do not assume a public test address is allowed. Preserve evidence before resets or service restarts.","commands":[{"shell":"Terminal","command":"ip -br link","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"ip -br address","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"ip route","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"ip route get <DESTINATION>","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"ip neighbor","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"resolvectl status","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"ping <GATEWAY>","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"dig <HOSTNAME>","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"ss -tulpn","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"nc -vz <HOSTNAME> <PORT>","risk":"Standard","safetyLevel":"Safe Read-Only"},{"shell":"Terminal","command":"tracepath <HOSTNAME>","risk":"Standard","safetyLevel":"Safe Read-Only"}],"namespace":"NETCLI","platforms":["linux"],"sourceDocument":"CopyCat Network Command Library","lastVerified":"","availability":"varies by command","safetyLevel":"Safe Read-Only","adminRequired":"conditional","commandFamily":"Basic Connectivity","vendors":["Network CLI"],"technologies":["Troubleshooting Sequence","Safe Read-Only"],"aliases":[]}],"indexEntries":[{"id":"irql","term":"IRQL","expandedName":"Interrupt Request Level","shortDefinition":"A Windows kernel priority system that controls which hardware interrupts and kernel tasks may interrupt other CPU work.","fullDefinition":"IRQL stands for Interrupt Request Level. Windows uses IRQL values to prioritize hardware interrupts and kernel-mode operations. Code at higher IRQL values has stricter rules about which memory and system functions it may access; violations commonly contribute to driver-related bug checks.","plainLanguageDefinition":"IRQL decides which low-level hardware or driver task gets the CPU's attention first.","platforms":["windows"],"aliases":["Interrupt Request Level","IRQL level"],"keywords":["kernel priority","hardware interrupt","driver crash","blue screen priority"],"relatedTerms":["Kernel","Driver","Interrupt","DPC","Paged Memory","Bug Check"],"articleIds":[],"vendors":["microsoft"],"products":["windows"],"technologies":["windows-kernel","drivers","interrupts","bsod"],"categories":["acronym","windows-internals","debugging"],"relatedErrorCodes":["0x0000000A","0x000000D1"],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"active-directory","term":"Active Directory","expandedName":"Active Directory Domain Services","shortDefinition":"Microsoft's on-premises directory service for identities, computers, authentication, policy, and domain resources.","fullDefinition":"Microsoft's on-premises directory service for identities, computers, authentication, policy, and domain resources.","plainLanguageDefinition":"Microsoft's on-premises directory service for identities, computers, authentication, policy, and domain resources.","platforms":["windows"],"aliases":["AD","AD DS"],"keywords":["domain controller","directory service"],"relatedTerms":["Group Policy","Kerberos","LDAP","SYSVOL"],"articleIds":[],"vendors":["microsoft"],"products":["windows server"],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"bitlocker","term":"BitLocker","expandedName":"BitLocker Drive Encryption","shortDefinition":"Windows full-volume encryption that protects data on supported drives.","fullDefinition":"Windows full-volume encryption that protects data on supported drives.","plainLanguageDefinition":"Windows full-volume encryption that protects data on supported drives.","platforms":["windows"],"aliases":[],"keywords":["drive encryption","recovery key","TPM"],"relatedTerms":["TPM","Recovery Key","Encryption"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"bsod","term":"BSOD","expandedName":"Blue Screen of Death","shortDefinition":"A common name for the Windows stop-error screen shown after the operating system encounters a critical failure.","fullDefinition":"A common name for the Windows stop-error screen shown after the operating system encounters a critical failure.","plainLanguageDefinition":"A common name for the Windows stop-error screen shown after the operating system encounters a critical failure.","platforms":["windows"],"aliases":["Blue Screen","bug check"],"keywords":["stop code","crash dump"],"relatedTerms":["Stop Code","Kernel","Driver","IRQL"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"conditional-access","term":"Conditional Access","expandedName":"Microsoft Entra Conditional Access","shortDefinition":"Policy-based access control that evaluates signals such as identity, device, location, application, and risk before granting access.","fullDefinition":"Policy-based access control that evaluates signals such as identity, device, location, application, and risk before granting access.","plainLanguageDefinition":"Policy-based access control that evaluates signals such as identity, device, location, application, and risk before granting access.","platforms":["platform-neutral"],"aliases":["CA policy"],"keywords":["entra policy","sign-in policy"],"relatedTerms":["Entra ID","MFA","OAuth"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"dism","term":"DISM","expandedName":"Deployment Image Servicing and Management","shortDefinition":"A Windows command-line tool for servicing Windows images and repairing the component store.","fullDefinition":"A Windows command-line tool for servicing Windows images and repairing the component store.","plainLanguageDefinition":"A Windows command-line tool for servicing Windows images and repairing the component store.","platforms":["windows"],"aliases":["dism.exe"],"keywords":["component store","repair image"],"relatedTerms":["SFC","WinPE","WinRE"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":["DISM /Online /Cleanup-Image /RestoreHealth"],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"windows-update","term":"Windows Update","expandedName":"Microsoft Windows Update","shortDefinition":"The Windows servicing system that detects, downloads, stages, installs, and reports operating-system and Microsoft updates.","fullDefinition":"The Windows servicing system that detects, downloads, stages, installs, and reports operating-system and Microsoft updates.","plainLanguageDefinition":"The Windows servicing system that detects, downloads, stages, installs, and reports operating-system and Microsoft updates.","platforms":["windows"],"aliases":["Windows Update Agent","Windows Update Client"],"keywords":["patching","quality update","feature update","cumulative update"],"relatedTerms":["BITS","WSUS","DISM","Servicing Stack"],"articleIds":[910000,910001],"vendors":["microsoft"],"products":["Windows Update"],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"bits","term":"BITS","expandedName":"Background Intelligent Transfer Service","shortDefinition":"A Windows service that transfers files in the background and is used by Windows Update and other management or deployment tools.","fullDefinition":"A Windows service that transfers files in the background and is used by Windows Update and other management or deployment tools.","plainLanguageDefinition":"A Windows service that transfers files in the background and is used by Windows Update and other management or deployment tools.","platforms":["windows"],"aliases":["Background Intelligent Transfer Service"],"keywords":["qmgr.dat","BITS queue","background download"],"relatedTerms":["Windows Update","SoftwareDistribution"],"articleIds":[910004,910012],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"softwaredistribution","term":"SoftwareDistribution","expandedName":"Windows Update SoftwareDistribution folder","shortDefinition":"The local Windows Update working folder containing download, database, and reporting data that Windows can recreate after a controlled rename.","fullDefinition":"The local Windows Update working folder containing download, database, and reporting data that Windows can recreate after a controlled rename.","plainLanguageDefinition":"The local Windows Update working folder containing download, database, and reporting data that Windows can recreate after a controlled rename.","platforms":["windows"],"aliases":["Software Distribution","DataStore"],"keywords":["Windows Update cache","download cache","SoftwareDistribution.old"],"relatedTerms":["Windows Update","BITS","catroot2"],"articleIds":[910005,910010],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"catroot2","term":"catroot2","expandedName":"Windows servicing catalog cache","shortDefinition":"A Windows system folder used for update catalog and cryptographic servicing data; it is distinct from the catroot folder.","fullDefinition":"A Windows system folder used for update catalog and cryptographic servicing data; it is distinct from the catroot folder.","plainLanguageDefinition":"A Windows system folder used for update catalog and cryptographic servicing data; it is distinct from the catroot folder.","platforms":["windows"],"aliases":["catroot2.old"],"keywords":["catalog cache","cryptsvc","update signatures"],"relatedTerms":["Cryptographic Services","SoftwareDistribution"],"articleIds":[910006,910011],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"wsus","term":"WSUS","expandedName":"Windows Server Update Services","shortDefinition":"A Microsoft server role used to approve, distribute, and report Windows and Microsoft updates in managed environments.","fullDefinition":"A Microsoft server role used to approve, distribute, and report Windows and Microsoft updates in managed environments.","plainLanguageDefinition":"A Microsoft server role used to approve, distribute, and report Windows and Microsoft updates in managed environments.","platforms":["windows"],"aliases":["Windows Server Update Services"],"keywords":["WUServer","UseWUServer","update approval"],"relatedTerms":["Windows Update","Windows Update for Business"],"articleIds":[910019],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"winhttp","term":"WinHTTP","expandedName":"Windows HTTP Services","shortDefinition":"A Windows HTTP client stack with system-level proxy settings used by some services and applications.","fullDefinition":"A Windows HTTP client stack with system-level proxy settings used by some services and applications.","plainLanguageDefinition":"A Windows HTTP client stack with system-level proxy settings used by some services and applications.","platforms":["windows"],"aliases":["Windows HTTP Services"],"keywords":["netsh winhttp","system proxy","proxy reset"],"relatedTerms":["Proxy","Windows Update"],"articleIds":[910015],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"winsock","term":"Winsock","expandedName":"Windows Sockets","shortDefinition":"The Windows networking API and service-provider catalog used by applications for network communication.","fullDefinition":"The Windows networking API and service-provider catalog used by applications for network communication.","plainLanguageDefinition":"The Windows networking API and service-provider catalog used by applications for network communication.","platforms":["windows"],"aliases":["Windows Sockets"],"keywords":["Winsock catalog","network stack","netsh winsock"],"relatedTerms":["TCP/IP","Windows Update"],"articleIds":[910016],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"dns","term":"DNS","expandedName":"Domain Name System","shortDefinition":"A distributed naming system that translates host names into IP addresses and publishes other service records.","fullDefinition":"A distributed naming system that translates host names into IP addresses and publishes other service records.","plainLanguageDefinition":"A distributed naming system that translates host names into IP addresses and publishes other service records.","platforms":["platform-neutral"],"aliases":["Domain Name System"],"keywords":["name resolution","dns server"],"relatedTerms":["DHCP","TCP","IP Address"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"entra-id","term":"Entra ID","expandedName":"Microsoft Entra ID","shortDefinition":"Microsoft's cloud identity and access-management directory service.","fullDefinition":"Microsoft's cloud identity and access-management directory service.","plainLanguageDefinition":"Microsoft's cloud identity and access-management directory service.","platforms":["platform-neutral"],"aliases":["Azure AD","AAD","Microsoft Entra"],"keywords":["cloud identity","tenant","directory"],"relatedTerms":["Conditional Access","MFA","Microsoft Graph"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"event-id","term":"Event ID","expandedName":"Windows Event Identifier","shortDefinition":"A numeric identifier associated with an event source and log entry; its meaning depends on the provider and log context.","fullDefinition":"A numeric identifier associated with an event source and log entry; its meaning depends on the provider and log context.","plainLanguageDefinition":"A numeric identifier associated with an event source and log entry; its meaning depends on the provider and log context.","platforms":["windows"],"aliases":["Event Identifier"],"keywords":["event viewer","windows log"],"relatedTerms":["Event Viewer","Event Source"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"exchange-online","term":"Exchange Online","expandedName":"","shortDefinition":"Microsoft's cloud-hosted email, calendaring, and recipient-management service within Microsoft 365.","fullDefinition":"Microsoft's cloud-hosted email, calendaring, and recipient-management service within Microsoft 365.","plainLanguageDefinition":"Microsoft's cloud-hosted email, calendaring, and recipient-management service within Microsoft 365.","platforms":["platform-neutral"],"aliases":["EXO"],"keywords":["mailbox","recipient","email"],"relatedTerms":["SMTP","Proxy Address","Microsoft 365"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"filevault","term":"FileVault","expandedName":"FileVault disk encryption","shortDefinition":"macOS full-disk encryption that protects data on a Mac's startup volume.","fullDefinition":"macOS full-disk encryption that protects data on a Mac's startup volume.","plainLanguageDefinition":"macOS full-disk encryption that protects data on a Mac's startup volume.","platforms":["macos"],"aliases":[],"keywords":["mac encryption","recovery key"],"relatedTerms":["APFS","Recovery Key"],"articleIds":[],"vendors":["apple"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"graph","term":"Microsoft Graph","expandedName":"Microsoft Graph API","shortDefinition":"Microsoft's unified API for accessing supported Microsoft 365, Entra, and related cloud-service data.","fullDefinition":"Microsoft's unified API for accessing supported Microsoft 365, Entra, and related cloud-service data.","plainLanguageDefinition":"Microsoft's unified API for accessing supported Microsoft 365, Entra, and related cloud-service data.","platforms":["platform-neutral"],"aliases":["Graph","MS Graph","Microsoft Graph PowerShell"],"keywords":["graph api","Get-MgUser"],"relatedTerms":["Entra ID","OAuth","API"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"group-policy","term":"Group Policy","expandedName":"","shortDefinition":"A Windows domain and local policy system used to centrally configure user and computer settings.","fullDefinition":"A Windows domain and local policy system used to centrally configure user and computer settings.","plainLanguageDefinition":"A Windows domain and local policy system used to centrally configure user and computer settings.","platforms":["windows"],"aliases":["GPO"],"keywords":["active directory policy","gpupdate"],"relatedTerms":["Active Directory","SYSVOL"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"hresult","term":"HRESULT","expandedName":"","shortDefinition":"A 32-bit result value commonly used by Windows and COM APIs to communicate success or failure information.","fullDefinition":"A 32-bit result value commonly used by Windows and COM APIs to communicate success or failure information.","plainLanguageDefinition":"A 32-bit result value commonly used by Windows and COM APIs to communicate success or failure information.","platforms":["windows"],"aliases":[],"keywords":["COM error","facility code","0x800"],"relatedTerms":["Win32","NTSTATUS"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"kerberos","term":"Kerberos","expandedName":"","shortDefinition":"A ticket-based network authentication protocol used by Active Directory and many other systems.","fullDefinition":"A ticket-based network authentication protocol used by Active Directory and many other systems.","plainLanguageDefinition":"A ticket-based network authentication protocol used by Active Directory and many other systems.","platforms":["platform-neutral"],"aliases":[],"keywords":["ticket","KDC","authentication"],"relatedTerms":["Active Directory","SPN","Time Synchronization"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"ldap","term":"LDAP","expandedName":"Lightweight Directory Access Protocol","shortDefinition":"A protocol for querying and modifying compatible directory services.","fullDefinition":"A protocol for querying and modifying compatible directory services.","plainLanguageDefinition":"A protocol for querying and modifying compatible directory services.","platforms":["platform-neutral"],"aliases":["Lightweight Directory Access Protocol"],"keywords":["directory query"],"relatedTerms":["Active Directory","Entra ID"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"mac-address","term":"MAC Address","expandedName":"Media Access Control Address","shortDefinition":"A link-layer hardware address used to identify a network interface on a local network segment.","fullDefinition":"A link-layer hardware address used to identify a network interface on a local network segment.","plainLanguageDefinition":"A link-layer hardware address used to identify a network interface on a local network segment.","platforms":["platform-neutral"],"aliases":["Media Access Control address"],"keywords":["ethernet address","physical address"],"relatedTerms":["DHCP","IP Address","Switch"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"mfa","term":"MFA","expandedName":"Multi-Factor Authentication","shortDefinition":"Authentication that requires more than one category of evidence, such as a password plus a registered device or security key.","fullDefinition":"Authentication that requires more than one category of evidence, such as a password plus a registered device or security key.","plainLanguageDefinition":"Authentication that requires more than one category of evidence, such as a password plus a registered device or security key.","platforms":["platform-neutral"],"aliases":["Multi-Factor Authentication","two-factor authentication","2FA"],"keywords":["identity verification","authentication method"],"relatedTerms":["Conditional Access","OAuth"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"ntfs","term":"NTFS","expandedName":"New Technology File System","shortDefinition":"The primary Windows file system, supporting permissions, journaling, encryption, compression, and other features.","fullDefinition":"The primary Windows file system, supporting permissions, journaling, encryption, compression, and other features.","plainLanguageDefinition":"The primary Windows file system, supporting permissions, journaling, encryption, compression, and other features.","platforms":["windows"],"aliases":["New Technology File System"],"keywords":["windows file system","acl"],"relatedTerms":["ReFS","DACL","SACL"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"ntstatus","term":"NTSTATUS","expandedName":"","shortDefinition":"A Windows kernel and native API status-code format used to report success, warning, and error conditions.","fullDefinition":"A Windows kernel and native API status-code format used to report success, warning, and error conditions.","plainLanguageDefinition":"A Windows kernel and native API status-code format used to report success, warning, and error conditions.","platforms":["windows"],"aliases":[],"keywords":["kernel status","native api error"],"relatedTerms":["HRESULT","Win32"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"oauth","term":"OAuth","expandedName":"Open Authorization","shortDefinition":"A delegated authorization framework that lets applications obtain limited access without receiving a user's password.","fullDefinition":"A delegated authorization framework that lets applications obtain limited access without receiving a user's password.","plainLanguageDefinition":"A delegated authorization framework that lets applications obtain limited access without receiving a user's password.","platforms":["platform-neutral"],"aliases":["OAuth 2.0"],"keywords":["access token","authorization"],"relatedTerms":["MFA","Conditional Access","Microsoft Graph"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"powershell","term":"PowerShell","expandedName":"","shortDefinition":"A cross-platform command shell and automation language built around structured objects and cmdlets.","fullDefinition":"A cross-platform command shell and automation language built around structured objects and cmdlets.","plainLanguageDefinition":"A cross-platform command shell and automation language built around structured objects and cmdlets.","platforms":["windows","macos","linux"],"aliases":["pwsh","Windows PowerShell"],"keywords":["cmdlet","automation","script"],"relatedTerms":["Module","Pipeline"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"primary-smtp-address","term":"Primary SMTP Address","expandedName":"","shortDefinition":"The default reply and outbound email address for a mail-enabled recipient, conventionally represented with uppercase SMTP in proxy-address data.","fullDefinition":"The default reply and outbound email address for a mail-enabled recipient, conventionally represented with uppercase SMTP in proxy-address data.","plainLanguageDefinition":"The default reply and outbound email address for a mail-enabled recipient, conventionally represented with uppercase SMTP in proxy-address data.","platforms":["platform-neutral"],"aliases":["PrimarySmtpAddress"],"keywords":["reply address","mail address"],"relatedTerms":["SMTP","Proxy Address","proxyAddresses"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"proxy-address","term":"Proxy Address","expandedName":"","shortDefinition":"An additional address associated with a mail-enabled directory object, such as an SMTP alias.","fullDefinition":"An additional address associated with a mail-enabled directory object, such as an SMTP alias.","plainLanguageDefinition":"An additional address associated with a mail-enabled directory object, such as an SMTP alias.","platforms":["platform-neutral"],"aliases":["address alias","email alias"],"keywords":["smtp alias","recipient address"],"relatedTerms":["SMTP","Primary SMTP Address","proxyAddresses"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"proxyaddresses","term":"proxyAddresses","expandedName":"","shortDefinition":"A multi-valued directory attribute that stores email and other proxy addresses for a mail-enabled object.","fullDefinition":"A multi-valued directory attribute that stores email and other proxy addresses for a mail-enabled object.","plainLanguageDefinition":"A multi-valued directory attribute that stores email and other proxy addresses for a mail-enabled object.","platforms":["platform-neutral"],"aliases":["EmailAddresses","proxy addresses attribute"],"keywords":["duplicate proxy address","smtp alias"],"relatedTerms":["Proxy Address","Primary SMTP Address","SMTP"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"registry","term":"Registry","expandedName":"Windows Registry","shortDefinition":"A hierarchical Windows configuration database used by the operating system, applications, services, and user profiles.","fullDefinition":"A hierarchical Windows configuration database used by the operating system, applications, services, and user profiles.","plainLanguageDefinition":"A hierarchical Windows configuration database used by the operating system, applications, services, and user profiles.","platforms":["windows"],"aliases":["Windows Registry","regedit"],"keywords":["registry key","HKLM","HKCU"],"relatedTerms":["Group Policy","Win32"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"smtp","term":"SMTP","expandedName":"Simple Mail Transfer Protocol","shortDefinition":"The standard protocol used to transfer email between servers and submit outgoing mail.","fullDefinition":"The standard protocol used to transfer email between servers and submit outgoing mail.","plainLanguageDefinition":"The standard protocol used to transfer email between servers and submit outgoing mail.","platforms":["platform-neutral"],"aliases":["Simple Mail Transfer Protocol"],"keywords":["mail flow","smtp address"],"relatedTerms":["Exchange Online","Proxy Address","SPF"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"sysvol","term":"SYSVOL","expandedName":"System Volume","shortDefinition":"A replicated domain-controller share containing Group Policy and domain logon files.","fullDefinition":"A replicated domain-controller share containing Group Policy and domain logon files.","plainLanguageDefinition":"A replicated domain-controller share containing Group Policy and domain logon files.","platforms":["windows"],"aliases":["System Volume"],"keywords":["dfsr","group policy replication"],"relatedTerms":["Active Directory","Group Policy","DFSR"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"tpm","term":"TPM","expandedName":"Trusted Platform Module","shortDefinition":"A hardware-backed security component used to protect cryptographic keys and measure system integrity.","fullDefinition":"A hardware-backed security component used to protect cryptographic keys and measure system integrity.","plainLanguageDefinition":"A hardware-backed security component used to protect cryptographic keys and measure system integrity.","platforms":["platform-neutral"],"aliases":["Trusted Platform Module"],"keywords":["secure hardware","bitlocker key"],"relatedTerms":["BitLocker","UEFI"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"upn","term":"UPN","expandedName":"User Principal Name","shortDefinition":"A directory sign-in name commonly formatted like an email address, but not necessarily identical to the user's primary SMTP address.","fullDefinition":"A directory sign-in name commonly formatted like an email address, but not necessarily identical to the user's primary SMTP address.","plainLanguageDefinition":"A directory sign-in name commonly formatted like an email address, but not necessarily identical to the user's primary SMTP address.","platforms":["platform-neutral"],"aliases":["User Principal Name"],"keywords":["sign-in name","entra user"],"relatedTerms":["Entra ID","Primary SMTP Address"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"vhdx","term":"VHDX","expandedName":"Virtual Hard Disk v2","shortDefinition":"Microsoft's virtual-disk file format used by Hyper-V and supported Windows tooling.","fullDefinition":"Microsoft's virtual-disk file format used by Hyper-V and supported Windows tooling.","plainLanguageDefinition":"Microsoft's virtual-disk file format used by Hyper-V and supported Windows tooling.","platforms":["windows"],"aliases":["Virtual Hard Disk","virtual disk"],"keywords":["hyper-v disk","avhdx"],"relatedTerms":["Hyper-V","Checkpoint"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"vpn","term":"VPN","expandedName":"Virtual Private Network","shortDefinition":"An encrypted or authenticated network connection that extends access to a private network across another network.","fullDefinition":"An encrypted or authenticated network connection that extends access to a private network across another network.","plainLanguageDefinition":"An encrypted or authenticated network connection that extends access to a private network across another network.","platforms":["platform-neutral"],"aliases":["Virtual Private Network"],"keywords":["remote access","tunnel"],"relatedTerms":["IPsec","TLS"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"vss","term":"VSS","expandedName":"Volume Shadow Copy Service","shortDefinition":"A Windows service and framework for creating consistent point-in-time volume snapshots with application coordination.","fullDefinition":"A Windows service and framework for creating consistent point-in-time volume snapshots with application coordination.","plainLanguageDefinition":"A Windows service and framework for creating consistent point-in-time volume snapshots with application coordination.","platforms":["windows"],"aliases":["Volume Shadow Copy Service","Shadow Copy"],"keywords":["vss writer","snapshot","backup"],"relatedTerms":["Backup","VSS Writer"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"win32","term":"Win32","expandedName":"Windows API","shortDefinition":"The traditional native Windows application programming interface and related system conventions.","fullDefinition":"The traditional native Windows application programming interface and related system conventions.","plainLanguageDefinition":"The traditional native Windows application programming interface and related system conventions.","platforms":["windows"],"aliases":["Windows API"],"keywords":["kernel32","winerror"],"relatedTerms":["HRESULT","NTSTATUS"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"winre","term":"WinRE","expandedName":"Windows Recovery Environment","shortDefinition":"A Windows recovery environment containing startup repair, reset, command-line, and advanced recovery tools.","fullDefinition":"A Windows recovery environment containing startup repair, reset, command-line, and advanced recovery tools.","plainLanguageDefinition":"A Windows recovery environment containing startup repair, reset, command-line, and advanced recovery tools.","platforms":["windows"],"aliases":["Windows Recovery Environment"],"keywords":["startup repair","recovery"],"relatedTerms":["WinPE","BCD"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"wsus","term":"WSUS","expandedName":"Windows Server Update Services","shortDefinition":"A Windows Server role for approving and distributing Microsoft updates to managed Windows devices.","fullDefinition":"A Windows Server role for approving and distributing Microsoft updates to managed Windows devices.","plainLanguageDefinition":"A Windows Server role for approving and distributing Microsoft updates to managed Windows devices.","platforms":["windows"],"aliases":["Windows Server Update Services"],"keywords":["patch management","windows update"],"relatedTerms":["Windows Update","Group Policy"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"aad","term":"AAD","expandedName":"Azure Active Directory","shortDefinition":"The former name of Microsoft Entra ID, Microsoft's cloud identity and access-management directory service.","fullDefinition":"The former name of Microsoft Entra ID, Microsoft's cloud identity and access-management directory service.","plainLanguageDefinition":"The former name of Microsoft Entra ID, Microsoft's cloud identity and access-management directory service.","platforms":["platform-neutral"],"aliases":["Azure AD","Azure Active Directory"],"keywords":["cloud identity","Microsoft 365 sign-in","tenant"],"relatedTerms":["Entra ID","Conditional Access","MFA"],"articleIds":[],"vendors":["microsoft"],"products":["Microsoft Entra ID"],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"alias","term":"Alias","expandedName":"","shortDefinition":"An additional name or address that points to the same underlying account or destination; in Microsoft email services, an alias commonly delivers mail to the same mailbox as the primary address.","fullDefinition":"An additional name or address that points to the same underlying account or destination; in Microsoft email services, an alias commonly delivers mail to the same mailbox as the primary address.","plainLanguageDefinition":"An additional name or address that points to the same underlying account or destination; in Microsoft email services, an alias commonly delivers mail to the same mailbox as the primary address.","platforms":["platform-neutral"],"aliases":["email alias","account alias"],"keywords":["alternate email address","proxy address"],"relatedTerms":["Proxy Address","Primary SMTP Address","proxyAddresses"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"api","term":"API","expandedName":"Application Programming Interface","shortDefinition":"A defined interface and set of rules that lets software components request functions or exchange data with one another.","fullDefinition":"A defined interface and set of rules that lets software components request functions or exchange data with one another.","plainLanguageDefinition":"A defined interface and set of rules that lets software components request functions or exchange data with one another.","platforms":["platform-neutral"],"aliases":["Application Programming Interface"],"keywords":["software integration","endpoint","request","response"],"relatedTerms":["Microsoft Graph","OAuth","HTTP"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"appx","term":"AppX","expandedName":"Windows application package","shortDefinition":"A Windows application packaging and deployment format represented by .appx packages. Outside this context, appx may also abbreviate approximately or appendix.","fullDefinition":"A Windows application packaging and deployment format represented by .appx packages. Outside this context, appx may also abbreviate approximately or appendix.","plainLanguageDefinition":"A Windows application packaging and deployment format represented by .appx packages. Outside this context, appx may also abbreviate approximately or appendix.","platforms":["windows"],"aliases":[".appx","AppX package"],"keywords":["windows app package","application deployment"],"relatedTerms":["MSIX","Windows","PowerShell"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"autopilot","term":"Autopilot","expandedName":"Windows Autopilot","shortDefinition":"A Microsoft cloud service that registers, configures, and provisions new or reset Windows devices into an organization-managed state without traditional reimaging.","fullDefinition":"A Microsoft cloud service that registers, configures, and provisions new or reset Windows devices into an organization-managed state without traditional reimaging.","plainLanguageDefinition":"A Microsoft cloud service that registers, configures, and provisions new or reset Windows devices into an organization-managed state without traditional reimaging.","platforms":["windows"],"aliases":["Windows Autopilot"],"keywords":["device provisioning","zero-touch deployment","OOBE"],"relatedTerms":["Intune","ESP","OOBE","Entra ID"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"bcd","term":"BCD","expandedName":"Boot Configuration Data","shortDefinition":"The Windows boot configuration database containing boot applications, entries, and startup options for BIOS- and UEFI-based systems.","fullDefinition":"The Windows boot configuration database containing boot applications, entries, and startup options for BIOS- and UEFI-based systems.","plainLanguageDefinition":"The Windows boot configuration database containing boot applications, entries, and startup options for BIOS- and UEFI-based systems.","platforms":["windows"],"aliases":["Boot Configuration Data","BCD store"],"keywords":["windows boot","bcdedit","boot manager"],"relatedTerms":["UEFI","WinRE","WinPE"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"certificate","term":"Certificate","expandedName":"Digital certificate","shortDefinition":"A cryptographically signed electronic credential that binds a public key to an identified person, device, service, or organization.","fullDefinition":"A cryptographically signed electronic credential that binds a public key to an identified person, device, service, or organization.","plainLanguageDefinition":"A cryptographically signed electronic credential that binds a public key to an identified person, device, service, or organization.","platforms":["platform-neutral"],"aliases":["digital certificate","X.509 certificate"],"keywords":["public key","PKI","identity","encryption"],"relatedTerms":["CRL","OCSP","TLS"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"cim","term":"CIM","expandedName":"Common Information Model","shortDefinition":"An open, vendor-neutral model for describing and managing computing resources; PowerShell CIM cmdlets use it to query management providers.","fullDefinition":"An open, vendor-neutral model for describing and managing computing resources; PowerShell CIM cmdlets use it to query management providers.","plainLanguageDefinition":"An open, vendor-neutral model for describing and managing computing resources; PowerShell CIM cmdlets use it to query management providers.","platforms":["platform-neutral"],"aliases":["Common Information Model"],"keywords":["management model","CIM instance","DMTF"],"relatedTerms":["WMI","PowerShell"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"crl","term":"CRL","expandedName":"Certificate Revocation List","shortDefinition":"A certificate-authority-signed list identifying certificates revoked before their scheduled expiration.","fullDefinition":"A certificate-authority-signed list identifying certificates revoked before their scheduled expiration.","plainLanguageDefinition":"A certificate-authority-signed list identifying certificates revoked before their scheduled expiration.","platforms":["platform-neutral"],"aliases":["Certificate Revocation List"],"keywords":["certificate revocation","PKI","CA"],"relatedTerms":["Certificate","OCSP","TLS"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"dacl","term":"DACL","expandedName":"Downloadable / Discretionary Access Control List","shortDefinition":"In network access control, a downloadable ACL is a centrally defined traffic policy applied to a network session after authentication. In a Windows security descriptor, DACL instead means Discretionary Access Control List and controls which trustees are allowed or denied access.","fullDefinition":"In network access control, a downloadable ACL is a centrally defined traffic policy applied to a network session after authentication. In a Windows security descriptor, DACL instead means Discretionary Access Control List and controls which trustees are allowed or denied access.","plainLanguageDefinition":"In network access control, a downloadable ACL is a centrally defined traffic policy applied to a network session after authentication. In a Windows security descriptor, DACL instead means Discretionary Access Control List and controls which trustees are allowed or denied access.","platforms":["windows","linux"],"aliases":["Downloadable ACL","Dynamic ACL","Discretionary Access Control List","dACL"],"keywords":["RADIUS","NAC","switch policy","windows permissions","security descriptor"],"relatedTerms":["ACL","RADIUS","SACL"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"defender","term":"Defender","expandedName":"Microsoft Defender","shortDefinition":"Microsoft's family of security products for protecting endpoints, identities, email, applications, and cloud data against malware, phishing, and other threats.","fullDefinition":"Microsoft's family of security products for protecting endpoints, identities, email, applications, and cloud data against malware, phishing, and other threats.","plainLanguageDefinition":"Microsoft's family of security products for protecting endpoints, identities, email, applications, and cloud data against malware, phishing, and other threats.","platforms":["windows","macos","linux"],"aliases":["Microsoft Defender","Windows Defender"],"keywords":["endpoint security","antivirus","threat protection"],"relatedTerms":["Conditional Access","Intune"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"dhcp","term":"DHCP","expandedName":"Dynamic Host Configuration Protocol","shortDefinition":"A network protocol that automatically leases IP addresses and supplies settings such as subnet mask, gateway, and DNS servers to clients.","fullDefinition":"A network protocol that automatically leases IP addresses and supplies settings such as subnet mask, gateway, and DNS servers to clients.","plainLanguageDefinition":"A network protocol that automatically leases IP addresses and supplies settings such as subnet mask, gateway, and DNS servers to clients.","platforms":["platform-neutral"],"aliases":["Dynamic Host Configuration Protocol"],"keywords":["IP lease","scope","gateway","dns settings"],"relatedTerms":["DNS","TCP","UDP"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"dpc","term":"DPC","expandedName":"Deferred Procedure Call","shortDefinition":"A Windows kernel mechanism that defers lower-priority driver work so urgent hardware-interrupt handling can complete quickly.","fullDefinition":"A Windows kernel mechanism that defers lower-priority driver work so urgent hardware-interrupt handling can complete quickly.","plainLanguageDefinition":"A Windows kernel mechanism that defers lower-priority driver work so urgent hardware-interrupt handling can complete quickly.","platforms":["windows"],"aliases":["Deferred Procedure Call"],"keywords":["driver latency","interrupt","kernel"],"relatedTerms":["IRQL","Kernel","Driver"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"esp","term":"ESP","expandedName":"Enrollment Status Page","shortDefinition":"An Intune and Windows Autopilot provisioning page that tracks required device and user setup and can block access until assigned applications and policies finish.","fullDefinition":"An Intune and Windows Autopilot provisioning page that tracks required device and user setup and can block access until assigned applications and policies finish.","plainLanguageDefinition":"An Intune and Windows Autopilot provisioning page that tracks required device and user setup and can block access until assigned applications and policies finish.","platforms":["windows"],"aliases":["Enrollment Status Page","Intune ESP"],"keywords":["autopilot provisioning","device enrollment"],"relatedTerms":["Autopilot","Intune","OOBE"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"firmware","term":"Firmware","expandedName":"","shortDefinition":"Low-level software stored on or closely associated with hardware that initializes and controls the device's fundamental operation.","fullDefinition":"Low-level software stored on or closely associated with hardware that initializes and controls the device's fundamental operation.","plainLanguageDefinition":"Low-level software stored on or closely associated with hardware that initializes and controls the device's fundamental operation.","platforms":["platform-neutral"],"aliases":[],"keywords":["device software","hardware update","embedded software"],"relatedTerms":["UEFI","Driver"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"gpo","term":"GPO","expandedName":"Group Policy Object","shortDefinition":"A collection of Windows policy settings used to centrally configure computers and users locally or through Active Directory.","fullDefinition":"A collection of Windows policy settings used to centrally configure computers and users locally or through Active Directory.","plainLanguageDefinition":"A collection of Windows policy settings used to centrally configure computers and users locally or through Active Directory.","platforms":["windows"],"aliases":["Group Policy Object"],"keywords":["domain policy","computer policy","user policy"],"relatedTerms":["Group Policy","Active Directory","SYSVOL"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"gpt","term":"GPT","expandedName":"Generative Pre-trained Transformer / GUID Partition Table","shortDefinition":"In AI, GPT is a transformer-based language-model architecture pretrained on broad data. In storage and boot documentation, GPT means GUID Partition Table, the modern disk-partition layout commonly used with UEFI.","fullDefinition":"In AI, GPT is a transformer-based language-model architecture pretrained on broad data. In storage and boot documentation, GPT means GUID Partition Table, the modern disk-partition layout commonly used with UEFI.","plainLanguageDefinition":"In AI, GPT is a transformer-based language-model architecture pretrained on broad data. In storage and boot documentation, GPT means GUID Partition Table, the modern disk-partition layout commonly used with UEFI.","platforms":["platform-neutral"],"aliases":["Generative Pretrained Transformer","GUID Partition Table"],"keywords":["large language model","LLM","Copilot","OpenAI","disk partition","UEFI"],"relatedTerms":["API","UEFI","BCD"],"articleIds":[],"vendors":["openai","microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"intune","term":"Intune","expandedName":"Microsoft Intune","shortDefinition":"Microsoft's cloud endpoint-management service for managing devices, applications, configuration, compliance, and access across supported platforms.","fullDefinition":"Microsoft's cloud endpoint-management service for managing devices, applications, configuration, compliance, and access across supported platforms.","plainLanguageDefinition":"Microsoft's cloud endpoint-management service for managing devices, applications, configuration, compliance, and access across supported platforms.","platforms":["windows","macos","linux"],"aliases":["Microsoft Intune"],"keywords":["MDM","endpoint management","device compliance"],"relatedTerms":["MDM","Autopilot","ESP","Conditional Access"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"iops","term":"IOPS","expandedName":"Input/Output Operations Per Second","shortDefinition":"A storage-performance measurement of completed read and write operations per second; exceeding Azure VM or managed-disk limits can cause throttling and latency.","fullDefinition":"A storage-performance measurement of completed read and write operations per second; exceeding Azure VM or managed-disk limits can cause throttling and latency.","plainLanguageDefinition":"A storage-performance measurement of completed read and write operations per second; exceeding Azure VM or managed-disk limits can cause throttling and latency.","platforms":["platform-neutral"],"aliases":["Input Output Operations Per Second"],"keywords":["disk performance","storage latency","azure throttling"],"relatedTerms":["Throughput","Latency","Azure Disk"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"ipp","term":"IPP","expandedName":"Internet Printing Protocol","shortDefinition":"A standards-based protocol for submitting and managing print jobs and querying printer status, commonly over TCP port 631.","fullDefinition":"A standards-based protocol for submitting and managing print jobs and querying printer status, commonly over TCP port 631.","plainLanguageDefinition":"A standards-based protocol for submitting and managing print jobs and querying printer status, commonly over TCP port 631.","platforms":["platform-neutral"],"aliases":["Internet Printing Protocol"],"keywords":["network printing","port 631","printer status"],"relatedTerms":["PCL","TCP","Printer"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"lvm","term":"LVM","expandedName":"Logical Volume Management","shortDefinition":"A Linux storage-management layer that pools physical storage into flexible volume groups and logical volumes that can be allocated or resized.","fullDefinition":"A Linux storage-management layer that pools physical storage into flexible volume groups and logical volumes that can be allocated or resized.","plainLanguageDefinition":"A Linux storage-management layer that pools physical storage into flexible volume groups and logical volumes that can be allocated or resized.","platforms":["linux"],"aliases":["Logical Volume Manager","Logical Volume Management"],"keywords":["volume group","logical volume","physical volume"],"relatedTerms":["Linux","File System","Block Storage"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"mdm","term":"MDM","expandedName":"Mobile Device Management","shortDefinition":"A management channel used to enroll devices and deliver configuration, compliance, certificate, application, and security policy.","fullDefinition":"A management channel used to enroll devices and deliver configuration, compliance, certificate, application, and security policy.","plainLanguageDefinition":"A management channel used to enroll devices and deliver configuration, compliance, certificate, application, and security policy.","platforms":["platform-neutral"],"aliases":["Mobile Device Management"],"keywords":["device enrollment","management authority","CSP"],"relatedTerms":["Microsoft Intune","UEM","Company Portal"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"msi","term":"MSI","expandedName":"Windows Installer Package","shortDefinition":"A Windows Installer database package used to install, maintain, repair, and remove software.","fullDefinition":"A Windows Installer database package used to install, maintain, repair, and remove software.","plainLanguageDefinition":"A Windows Installer database package used to install, maintain, repair, and remove software.","platforms":["windows"],"aliases":["Windows Installer Package",".msi"],"keywords":["software installation","msiexec","installer package"],"relatedTerms":["MSIX","AppX"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"msix","term":"MSIX","expandedName":"","shortDefinition":"A modern Windows application package format designed for reliable deployment, update, and removal of desktop and Store applications.","fullDefinition":"A modern Windows application package format designed for reliable deployment, update, and removal of desktop and Store applications.","plainLanguageDefinition":"A modern Windows application package format designed for reliable deployment, update, and removal of desktop and Store applications.","platforms":["windows"],"aliases":[".msix","MSIX package"],"keywords":["windows app package","application deployment"],"relatedTerms":["MSI","AppX"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"ndr","term":"NDR","expandedName":"Non-Delivery Report","shortDefinition":"An automated Exchange or mail-system message explaining that email delivery failed, usually including an enhanced status code and diagnostic details.","fullDefinition":"An automated Exchange or mail-system message explaining that email delivery failed, usually including an enhanced status code and diagnostic details.","plainLanguageDefinition":"An automated Exchange or mail-system message explaining that email delivery failed, usually including an enhanced status code and diagnostic details.","platforms":["platform-neutral"],"aliases":["Non-Delivery Report","bounce message","delivery status notification"],"keywords":["email failed","mail flow","5.1.1"],"relatedTerms":["SMTP","Exchange Online","Mail Flow"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"nla","term":"NLA","expandedName":"Network Level Authentication / Network Location Awareness","shortDefinition":"In Remote Desktop, Network Level Authentication requires authentication before a full remote session is created. NLA can also refer to the Windows Network Location Awareness service.","fullDefinition":"In Remote Desktop, Network Level Authentication requires authentication before a full remote session is created. NLA can also refer to the Windows Network Location Awareness service.","plainLanguageDefinition":"In Remote Desktop, Network Level Authentication requires authentication before a full remote session is created. NLA can also refer to the Windows Network Location Awareness service.","platforms":["windows"],"aliases":["Network Level Authentication","Network Location Awareness"],"keywords":["remote desktop authentication","network profile"],"relatedTerms":["RDP","Windows Firewall"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"npa","term":"NPA","expandedName":"Numbering Plan Area","shortDefinition":"The telecommunications term for a three-digit geographic or non-geographic area code in the North American Numbering Plan.","fullDefinition":"The telecommunications term for a three-digit geographic or non-geographic area code in the North American Numbering Plan.","plainLanguageDefinition":"The telecommunications term for a three-digit geographic or non-geographic area code in the North American Numbering Plan.","platforms":["platform-neutral"],"aliases":["Numbering Plan Area","area code"],"keywords":["telephony","NANP","telephone number"],"relatedTerms":["VoIP","Telephony"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"ocsp","term":"OCSP","expandedName":"Online Certificate Status Protocol","shortDefinition":"A protocol for checking a certificate's current revocation status in near real time; Microsoft AD CS can provide it through the Online Responder role.","fullDefinition":"A protocol for checking a certificate's current revocation status in near real time; Microsoft AD CS can provide it through the Online Responder role.","plainLanguageDefinition":"A protocol for checking a certificate's current revocation status in near real time; Microsoft AD CS can provide it through the Online Responder role.","platforms":["platform-neutral"],"aliases":["Online Certificate Status Protocol"],"keywords":["certificate status","online responder","revocation"],"relatedTerms":["Certificate","CRL","TLS"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"onedrive","term":"OneDrive","expandedName":"Microsoft OneDrive","shortDefinition":"Microsoft's cloud file-storage and synchronization service for storing, sharing, and accessing files across supported devices and web applications.","fullDefinition":"Microsoft's cloud file-storage and synchronization service for storing, sharing, and accessing files across supported devices and web applications.","plainLanguageDefinition":"Microsoft's cloud file-storage and synchronization service for storing, sharing, and accessing files across supported devices and web applications.","platforms":["windows","macos","linux"],"aliases":["Microsoft OneDrive"],"keywords":["cloud storage","file sync","share files"],"relatedTerms":["Microsoft 365","SharePoint"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"oobe","term":"OOBE","expandedName":"Out-of-Box Experience","shortDefinition":"The first-run operating-system setup sequence used to configure regional, account, privacy, network, and device-management settings.","fullDefinition":"The first-run operating-system setup sequence used to configure regional, account, privacy, network, and device-management settings.","plainLanguageDefinition":"The first-run operating-system setup sequence used to configure regional, account, privacy, network, and device-management settings.","platforms":["windows"],"aliases":["Out-of-Box Experience"],"keywords":["first run","windows setup","device setup"],"relatedTerms":["Autopilot","ESP","Windows"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"pcl","term":"PCL","expandedName":"Printer Command Language","shortDefinition":"A Hewlett-Packard-developed page-description and printer-control language used by many printers to render text and graphics.","fullDefinition":"A Hewlett-Packard-developed page-description and printer-control language used by many printers to render text and graphics.","plainLanguageDefinition":"A Hewlett-Packard-developed page-description and printer-control language used by many printers to render text and graphics.","platforms":["platform-neutral"],"aliases":["Printer Command Language","Printer Control Language"],"keywords":["printer language","print driver"],"relatedTerms":["IPP","Printer Driver"],"articleIds":[],"vendors":["hp"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"rdp","term":"RDP","expandedName":"Remote Desktop Protocol","shortDefinition":"Microsoft's remote-display protocol for interacting with another Windows computer's graphical session across a network.","fullDefinition":"Microsoft's remote-display protocol for interacting with another Windows computer's graphical session across a network.","plainLanguageDefinition":"Microsoft's remote-display protocol for interacting with another Windows computer's graphical session across a network.","platforms":["windows"],"aliases":["Remote Desktop Protocol","Remote Desktop"],"keywords":["remote access","port 3389","terminal services","RDP-TCP listener","error 0x104"],"relatedTerms":["NLA","TLS","Windows Firewall","RD Gateway"],"articleIds":[],"vendors":["microsoft"],"products":["Remote Desktop Services","Windows Server"],"technologies":["RDP","TCP 3389"],"categories":["remote access","networking"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"device-manager","term":"Device Manager","expandedName":"Windows Device Manager","shortDefinition":"A Windows management console for viewing hardware, driver state, Plug and Play identifiers, resource assignments, and device-specific problem codes.","fullDefinition":"A Windows management console for viewing hardware, driver state, Plug and Play identifiers, resource assignments, and device-specific problem codes.","plainLanguageDefinition":"A Windows management console for viewing hardware, driver state, Plug and Play identifiers, resource assignments, and device-specific problem codes.","platforms":["windows"],"aliases":["devmgmt.msc","Device status","PnP Device Manager"],"keywords":["hardware error","driver error","problem code","yellow exclamation mark","device properties"],"relatedTerms":["Driver","Plug and Play","Hardware ID","Firmware"],"articleIds":[54000,54001,54002,54003,54004,54005,54006,54007,54008,54009,54010,54011,54012,54013,54014,54015,54016,54017,54018,54019,54020,54021,54022,54023,54024,54025,54026,54027,54028,54029,54030,54031,54032,54033,54034,54035,54036,54037],"vendors":["microsoft"],"products":["Windows 11","Windows 10"],"technologies":["Device Drivers","Plug and Play","Hardware"],"categories":["windows","hardware","drivers"],"relatedErrorCodes":[],"commands":["devmgmt.msc","pnputil /enum-devices /problem","Get-PnpDevice"],"source":"Microsoft Support - Error codes in Device Manager in Windows","reviewStatus":"verified","lastVerified":""},{"id":"refs","term":"ReFS","expandedName":"Resilient File System","shortDefinition":"A Microsoft file system designed for data integrity, availability, scalability, and resilience, first introduced with Windows Server 2012.","fullDefinition":"A Microsoft file system designed for data integrity, availability, scalability, and resilience, first introduced with Windows Server 2012.","plainLanguageDefinition":"A Microsoft file system designed for data integrity, availability, scalability, and resilience, first introduced with Windows Server 2012.","platforms":["windows"],"aliases":["Resilient File System"],"keywords":["windows file system","integrity streams"],"relatedTerms":["NTFS","Storage Spaces"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"rpc","term":"RPC","expandedName":"Remote Procedure Call","shortDefinition":"An inter-process communication model that lets software invoke a procedure in another process or host; Windows RPC commonly uses the endpoint mapper on TCP 135 plus negotiated dynamic ports.","fullDefinition":"An inter-process communication model that lets software invoke a procedure in another process or host; Windows RPC commonly uses the endpoint mapper on TCP 135 plus negotiated dynamic ports.","plainLanguageDefinition":"An inter-process communication model that lets software invoke a procedure in another process or host; Windows RPC commonly uses the endpoint mapper on TCP 135 plus negotiated dynamic ports.","platforms":["windows"],"aliases":["Remote Procedure Call","MSRPC"],"keywords":["endpoint mapper","port 135","dynamic ports"],"relatedTerms":["TCP","DCOM","Active Directory"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"sacl","term":"SACL","expandedName":"System Access Control List","shortDefinition":"A Windows security descriptor component that specifies which access attempts should generate audit events for an object.","fullDefinition":"A Windows security descriptor component that specifies which access attempts should generate audit events for an object.","plainLanguageDefinition":"A Windows security descriptor component that specifies which access attempts should generate audit events for an object.","platforms":["windows"],"aliases":["System Access Control List"],"keywords":["audit policy","security event log","object auditing"],"relatedTerms":["DACL","ACL","Event ID"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"spf","term":"SPF","expandedName":"Sender Policy Framework","shortDefinition":"An email-authentication mechanism in which a domain publishes a DNS TXT policy identifying servers authorized to send mail for that domain.","fullDefinition":"An email-authentication mechanism in which a domain publishes a DNS TXT policy identifying servers authorized to send mail for that domain.","plainLanguageDefinition":"An email-authentication mechanism in which a domain publishes a DNS TXT policy identifying servers authorized to send mail for that domain.","platforms":["platform-neutral"],"aliases":["Sender Policy Framework"],"keywords":["email authentication","dns txt","spoofing"],"relatedTerms":["DNS","SMTP","DKIM","DMARC"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"ssh","term":"SSH","expandedName":"Secure Shell","shortDefinition":"An encrypted network protocol for secure remote command-line access, administration, tunneling, and file transfer over untrusted networks.","fullDefinition":"An encrypted network protocol for secure remote command-line access, administration, tunneling, and file transfer over untrusted networks.","plainLanguageDefinition":"An encrypted network protocol for secure remote command-line access, administration, tunneling, and file transfer over untrusted networks.","platforms":["platform-neutral"],"aliases":["Secure Shell"],"keywords":["remote shell","port 22","encrypted tunnel"],"relatedTerms":["SFTP","TCP","TLS"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"stop-code","term":"Stop Code","expandedName":"Bug check code","shortDefinition":"A symbolic or numeric identifier displayed or recorded when an operating system stops after a critical failure; Windows stop codes appear with blue-screen crashes.","fullDefinition":"A symbolic or numeric identifier displayed or recorded when an operating system stops after a critical failure; Windows stop codes appear with blue-screen crashes.","plainLanguageDefinition":"A symbolic or numeric identifier displayed or recorded when an operating system stops after a critical failure; Windows stop codes appear with blue-screen crashes.","platforms":["windows"],"aliases":["bug check code","blue screen code"],"keywords":["BSOD","system crash","0x000000EF"],"relatedTerms":["BSOD","Blue Screen","Kernel","Crash Dump"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"tcp","term":"TCP","expandedName":"Transmission Control Protocol","shortDefinition":"A connection-oriented transport protocol that provides ordered, reliable delivery, retransmission, congestion control, and error detection for network data.","fullDefinition":"A connection-oriented transport protocol that provides ordered, reliable delivery, retransmission, congestion control, and error detection for network data.","plainLanguageDefinition":"A connection-oriented transport protocol that provides ordered, reliable delivery, retransmission, congestion control, and error detection for network data.","platforms":["platform-neutral"],"aliases":["Transmission Control Protocol"],"keywords":["reliable transport","connection oriented","packet order"],"relatedTerms":["UDP","IP","TLS"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"tls","term":"TLS","expandedName":"Transport Layer Security","shortDefinition":"A cryptographic protocol that authenticates peers and encrypts data in transit for HTTPS, email, APIs, and other network services.","fullDefinition":"A cryptographic protocol that authenticates peers and encrypts data in transit for HTTPS, email, APIs, and other network services.","plainLanguageDefinition":"A cryptographic protocol that authenticates peers and encrypts data in transit for HTTPS, email, APIs, and other network services.","platforms":["platform-neutral"],"aliases":["Transport Layer Security","SSL/TLS"],"keywords":["encryption in transit","https","certificate"],"relatedTerms":["Certificate","HTTPS","SSL","TCP"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"udp","term":"UDP","expandedName":"User Datagram Protocol","shortDefinition":"A connectionless transport protocol that sends independent datagrams without delivery, ordering, or retransmission guarantees, favoring low overhead and latency.","fullDefinition":"A connectionless transport protocol that sends independent datagrams without delivery, ordering, or retransmission guarantees, favoring low overhead and latency.","plainLanguageDefinition":"A connectionless transport protocol that sends independent datagrams without delivery, ordering, or retransmission guarantees, favoring low overhead and latency.","platforms":["platform-neutral"],"aliases":["User Datagram Protocol"],"keywords":["connectionless","datagram","fast transport"],"relatedTerms":["TCP","IP","DNS"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"uefi","term":"UEFI","expandedName":"Unified Extensible Firmware Interface","shortDefinition":"Modern platform firmware that initializes hardware and starts an operating-system boot loader, replacing the traditional PC BIOS model.","fullDefinition":"Modern platform firmware that initializes hardware and starts an operating-system boot loader, replacing the traditional PC BIOS model.","plainLanguageDefinition":"Modern platform firmware that initializes hardware and starts an operating-system boot loader, replacing the traditional PC BIOS model.","platforms":["platform-neutral"],"aliases":["Unified Extensible Firmware Interface"],"keywords":["firmware","secure boot","boot manager"],"relatedTerms":["Firmware","BCD","TPM"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"vhd","term":"VHD","expandedName":"Virtual Hard Disk","shortDefinition":"A Microsoft virtual-disk file format that stores partitions, file systems, files, and potentially an operating system for virtual machines or disk tooling.","fullDefinition":"A Microsoft virtual-disk file format that stores partitions, file systems, files, and potentially an operating system for virtual machines or disk tooling.","plainLanguageDefinition":"A Microsoft virtual-disk file format that stores partitions, file systems, files, and potentially an operating system for virtual machines or disk tooling.","platforms":["windows"],"aliases":["Virtual Hard Disk",".vhd"],"keywords":["virtual disk","hyper-v"],"relatedTerms":["VHDX","Hyper-V"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"wam","term":"WAM","expandedName":"Web Account Manager","shortDefinition":"In Microsoft identity troubleshooting, WAM usually refers to Windows Web Account Manager, the broker that manages application account tokens and sign-in integration. In other products, WAM may mean Web Access Management.","fullDefinition":"In Microsoft identity troubleshooting, WAM usually refers to Windows Web Account Manager, the broker that manages application account tokens and sign-in integration. In other products, WAM may mean Web Access Management.","plainLanguageDefinition":"In Microsoft identity troubleshooting, WAM usually refers to Windows Web Account Manager, the broker that manages application account tokens and sign-in integration. In other products, WAM may mean Web Access Management.","platforms":["windows"],"aliases":["Web Account Manager","Windows Account Manager","Web Access Management"],"keywords":["token broker","modern authentication","work account"],"relatedTerms":["Entra ID","OAuth","Microsoft 365"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"winpe","term":"WinPE","expandedName":"Windows Preinstallation Environment","shortDefinition":"A lightweight Windows environment used for deployment, imaging, recovery, disk preparation, and offline troubleshooting.","fullDefinition":"A lightweight Windows environment used for deployment, imaging, recovery, disk preparation, and offline troubleshooting.","plainLanguageDefinition":"A lightweight Windows environment used for deployment, imaging, recovery, disk preparation, and offline troubleshooting.","platforms":["windows"],"aliases":["Windows PE","Windows Preinstallation Environment"],"keywords":["deployment environment","imaging","recovery"],"relatedTerms":["WinRE","BCD","DISM"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"wmi","term":"WMI","expandedName":"Windows Management Instrumentation","shortDefinition":"Windows management infrastructure that exposes system, hardware, software, and configuration information to administrative tools and scripts.","fullDefinition":"Windows management infrastructure that exposes system, hardware, software, and configuration information to administrative tools and scripts.","plainLanguageDefinition":"Windows management infrastructure that exposes system, hardware, software, and configuration information to administrative tools and scripts.","platforms":["windows"],"aliases":["Windows Management Instrumentation"],"keywords":["management query","WMI class","remote management"],"relatedTerms":["CIM","PowerShell","Win32"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"sfc","term":"SFC","expandedName":"System File Checker","shortDefinition":"A Windows command-line utility that verifies protected system files and replaces damaged copies from the Windows component store when possible.","fullDefinition":"A Windows command-line utility that verifies protected system files and replaces damaged copies from the Windows component store when possible.","plainLanguageDefinition":"A Windows command-line utility that verifies protected system files and replaces damaged copies from the Windows component store when possible.","platforms":["windows"],"aliases":["System File Checker","sfc.exe"],"keywords":["system file repair","sfc scannow","windows corruption"],"relatedTerms":["DISM","WinRE","Windows"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":["sfc /scannow"],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"sql","term":"SQL","expandedName":"Structured Query Language","shortDefinition":"A standardized language for defining, querying, changing, and controlling data in relational database systems.","fullDefinition":"A standardized language for defining, querying, changing, and controlling data in relational database systems.","plainLanguageDefinition":"A standardized language for defining, querying, changing, and controlling data in relational database systems.","platforms":["platform-neutral"],"aliases":["Structured Query Language"],"keywords":["database query","relational database","select statement"],"relatedTerms":["Database","API"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"ssl","term":"SSL","expandedName":"Secure Sockets Layer","shortDefinition":"The obsolete predecessor to TLS. The term is still commonly used informally for certificates and encrypted connections, but modern systems should use supported TLS versions.","fullDefinition":"The obsolete predecessor to TLS. The term is still commonly used informally for certificates and encrypted connections, but modern systems should use supported TLS versions.","plainLanguageDefinition":"The obsolete predecessor to TLS. The term is still commonly used informally for certificates and encrypted connections, but modern systems should use supported TLS versions.","platforms":["platform-neutral"],"aliases":["Secure Sockets Layer","SSL certificate"],"keywords":["encryption","https","certificate"],"relatedTerms":["TLS","Certificate","HTTPS"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"http","term":"HTTP","expandedName":"Hypertext Transfer Protocol","shortDefinition":"An application-layer request and response protocol used by browsers, APIs, web servers, proxies, gateways, and many cloud services.","fullDefinition":"An application-layer request and response protocol used by browsers, APIs, web servers, proxies, gateways, and many cloud services.","plainLanguageDefinition":"An application-layer request and response protocol used by browsers, APIs, web servers, proxies, gateways, and many cloud services.","platforms":["platform-neutral"],"aliases":["Hypertext Transfer Protocol"],"keywords":["web protocol","HTTP response","HTTP request"],"relatedTerms":["HTTPS","Status Code","Request","Response"],"articleIds":[],"vendors":["ietf","iana"],"products":["HTTP"],"technologies":["HTTP","HTTPS"],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"http-1xx","term":"1xx","expandedName":"Informational HTTP responses","shortDefinition":"HTTP responses indicating that a request was received and processing is continuing; they are normally interim rather than final responses.","fullDefinition":"HTTP responses indicating that a request was received and processing is continuing; they are normally interim rather than final responses.","plainLanguageDefinition":"HTTP responses indicating that a request was received and processing is continuing; they are normally interim rather than final responses.","platforms":["platform-neutral"],"aliases":["Informational"],"keywords":["HTTP informational","100 Continue","103 Early Hints"],"relatedTerms":["HTTP","2xx","Status Code"],"articleIds":[],"vendors":["iana","ietf"],"products":["HTTP"],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"http-2xx","term":"2xx","expandedName":"Successful HTTP responses","shortDefinition":"HTTP responses indicating that a request was received, understood, and accepted; the precise outcome depends on the method and code.","fullDefinition":"HTTP responses indicating that a request was received, understood, and accepted; the precise outcome depends on the method and code.","plainLanguageDefinition":"HTTP responses indicating that a request was received, understood, and accepted; the precise outcome depends on the method and code.","platforms":["platform-neutral"],"aliases":["Success"],"keywords":["HTTP success","200 OK","created","no content"],"relatedTerms":["HTTP","1xx","3xx"],"articleIds":[],"vendors":["iana","ietf"],"products":["HTTP"],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"http-3xx","term":"3xx","expandedName":"HTTP redirection responses","shortDefinition":"HTTP responses indicating that additional client action or cached-state handling is needed to complete the request.","fullDefinition":"HTTP responses indicating that additional client action or cached-state handling is needed to complete the request.","plainLanguageDefinition":"HTTP responses indicating that additional client action or cached-state handling is needed to complete the request.","platforms":["platform-neutral"],"aliases":["Redirection"],"keywords":["HTTP redirect","301","302","Location header"],"relatedTerms":["HTTP","Redirect","Location Header"],"articleIds":[],"vendors":["iana","ietf"],"products":["HTTP"],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"http-4xx","term":"4xx","expandedName":"HTTP client-error responses","shortDefinition":"HTTP responses indicating that a request cannot be fulfilled in its current form; the name does not prove the end user personally caused the problem.","fullDefinition":"HTTP responses indicating that a request cannot be fulfilled in its current form; the name does not prove the end user personally caused the problem.","plainLanguageDefinition":"HTTP responses indicating that a request cannot be fulfilled in its current form; the name does not prove the end user personally caused the problem.","platforms":["platform-neutral"],"aliases":["Client Error"],"keywords":["HTTP client error","bad request","not found","rate limit"],"relatedTerms":["HTTP","Authentication","Authorization","5xx"],"articleIds":[],"vendors":["iana","ietf"],"products":["HTTP"],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"http-5xx","term":"5xx","expandedName":"HTTP server-error responses","shortDefinition":"HTTP responses indicating that a server or intermediary failed to fulfill an apparently valid request.","fullDefinition":"HTTP responses indicating that a server or intermediary failed to fulfill an apparently valid request.","plainLanguageDefinition":"HTTP responses indicating that a server or intermediary failed to fulfill an apparently valid request.","platforms":["platform-neutral"],"aliases":["Server Error"],"keywords":["HTTP server error","gateway error","service unavailable"],"relatedTerms":["HTTP","Gateway","Upstream","4xx"],"articleIds":[],"vendors":["iana","ietf"],"products":["HTTP"],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"arp","term":"ARP","expandedName":"Address Resolution Protocol","shortDefinition":"Maps IPv4 addresses to link-layer addresses on a local network segment.","fullDefinition":"Maps IPv4 addresses to link-layer addresses on a local network segment.","plainLanguageDefinition":"Maps IPv4 addresses to link-layer addresses on a local network segment.","platforms":["platform-neutral"],"aliases":["Address Resolution Protocol"],"keywords":["ARP cache","MAC lookup","neighbor"],"relatedTerms":["MAC Address","IPv4","NDP"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"icmp","term":"ICMP","expandedName":"Internet Control Message Protocol","shortDefinition":"Carries network control, reachability, and error messages used by tools such as ping and traceroute.","fullDefinition":"Carries network control, reachability, and error messages used by tools such as ping and traceroute.","plainLanguageDefinition":"Carries network control, reachability, and error messages used by tools such as ping and traceroute.","platforms":["platform-neutral"],"aliases":["Internet Control Message Protocol"],"keywords":["ping","echo request","unreachable"],"relatedTerms":["ICMPv6","Ping","Traceroute"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"ipv4","term":"IPv4","expandedName":"Internet Protocol version 4","shortDefinition":"The widely deployed Internet Protocol version that uses 32-bit addresses.","fullDefinition":"The widely deployed Internet Protocol version that uses 32-bit addresses.","plainLanguageDefinition":"The widely deployed Internet Protocol version that uses 32-bit addresses.","platforms":["platform-neutral"],"aliases":["Internet Protocol version 4"],"keywords":["IP address","subnet","default gateway"],"relatedTerms":["IPv6","CIDR","NAT"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"ipv6","term":"IPv6","expandedName":"Internet Protocol version 6","shortDefinition":"The Internet Protocol version that uses 128-bit addresses and Neighbor Discovery.","fullDefinition":"The Internet Protocol version that uses 128-bit addresses and Neighbor Discovery.","plainLanguageDefinition":"The Internet Protocol version that uses 128-bit addresses and Neighbor Discovery.","platforms":["platform-neutral"],"aliases":["Internet Protocol version 6"],"keywords":["AAAA","link-local","neighbor discovery"],"relatedTerms":["IPv4","NDP","Prefix Length"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"gateway","term":"Gateway","expandedName":"Network gateway","shortDefinition":"A device or service that forwards traffic between networks or protocol domains.","fullDefinition":"A device or service that forwards traffic between networks or protocol domains.","plainLanguageDefinition":"A device or service that forwards traffic between networks or protocol domains.","platforms":["platform-neutral"],"aliases":["Default Gateway"],"keywords":["router","next hop","gateway timeout"],"relatedTerms":["Routing Table","Router","Proxy"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"mtu","term":"MTU","expandedName":"Maximum Transmission Unit","shortDefinition":"The largest network-layer packet size an interface or path can carry without fragmentation or segmentation handling.","fullDefinition":"The largest network-layer packet size an interface or path can carry without fragmentation or segmentation handling.","plainLanguageDefinition":"The largest network-layer packet size an interface or path can carry without fragmentation or segmentation handling.","platforms":["platform-neutral"],"aliases":["Maximum Transmission Unit"],"keywords":["fragmentation","path MTU","jumbo frame"],"relatedTerms":["MSS","PMTUD","Interface"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"ttl","term":"TTL","expandedName":"Time To Live","shortDefinition":"An IP header field reduced at each routed hop to prevent packets from circulating indefinitely.","fullDefinition":"An IP header field reduced at each routed hop to prevent packets from circulating indefinitely.","plainLanguageDefinition":"An IP header field reduced at each routed hop to prevent packets from circulating indefinitely.","platforms":["platform-neutral"],"aliases":["Time To Live"],"keywords":["hop limit","traceroute","packet lifetime"],"relatedTerms":["Hop","Traceroute","IP"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"socket","term":"Socket","expandedName":"Network socket","shortDefinition":"An operating-system endpoint representing network communication, commonly identified by protocol, address, and port.","fullDefinition":"An operating-system endpoint representing network communication, commonly identified by protocol, address, and port.","plainLanguageDefinition":"An operating-system endpoint representing network communication, commonly identified by protocol, address, and port.","platforms":["platform-neutral"],"aliases":["Network Socket"],"keywords":["TCP socket","UDP socket","socket state"],"relatedTerms":["Port","TCP","UDP"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"port","term":"Port","expandedName":"Network port","shortDefinition":"A transport-layer number used to direct TCP or UDP traffic to a service or application endpoint.","fullDefinition":"A transport-layer number used to direct TCP or UDP traffic to a service or application endpoint.","plainLanguageDefinition":"A transport-layer number used to direct TCP or UDP traffic to a service or application endpoint.","platforms":["platform-neutral"],"aliases":["TCP Port","UDP Port"],"keywords":["listening port","ephemeral port","service port"],"relatedTerms":["Socket","TCP","UDP"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"nat","term":"NAT","expandedName":"Network Address Translation","shortDefinition":"Rewrites network addresses, and sometimes ports, as traffic crosses a translating device or service.","fullDefinition":"Rewrites network addresses, and sometimes ports, as traffic crosses a translating device or service.","plainLanguageDefinition":"Rewrites network addresses, and sometimes ports, as traffic crosses a translating device or service.","platforms":["platform-neutral"],"aliases":["Network Address Translation"],"keywords":["PAT","source NAT","destination NAT"],"relatedTerms":["IPv4","Firewall","Gateway"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"firewall","term":"Firewall","expandedName":"Network firewall","shortDefinition":"Enforces traffic policy using attributes such as addresses, ports, protocols, direction, application, and connection state.","fullDefinition":"Enforces traffic policy using attributes such as addresses, ports, protocols, direction, application, and connection state.","plainLanguageDefinition":"Enforces traffic policy using attributes such as addresses, ports, protocols, direction, application, and connection state.","platforms":["firewalls"],"aliases":["Stateful Firewall","Security Appliance"],"keywords":["firewall rule","packet filter","allow rule","network security appliance","FortiGate"],"relatedTerms":["Port","NAT","Packet","Fortinet","FortiGate","FortiOS","VDOM"],"articleIds":[53020],"vendors":["Fortinet"],"products":["FortiGate","FortiOS"],"technologies":["Network Security","Stateful Inspection"],"categories":["firewalls","networking","security"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"fortinet","term":"Fortinet","expandedName":"Fortinet, Inc.","shortDefinition":"A network-security vendor whose products include FortiGate firewall appliances and the FortiOS operating system.","fullDefinition":"A network-security vendor whose products include FortiGate firewall appliances and the FortiOS operating system.","plainLanguageDefinition":"A network-security vendor whose products include FortiGate firewall appliances and the FortiOS operating system.","platforms":["firewalls"],"aliases":["Fortinet firewall","Fortinet Networks"],"keywords":["FortiGate vendor","firewall manufacturer","network security"],"relatedTerms":["Firewall","FortiGate","FortiOS","VDOM"],"articleIds":[53020],"vendors":["Fortinet"],"products":["FortiGate","FortiOS"],"technologies":[],"categories":["vendor","firewalls","security"],"relatedErrorCodes":[],"commands":[],"source":"Fortinet FortiOS 8.0.0 Administration Guide","reviewStatus":"verified","lastVerified":""},{"id":"fortigate","term":"FortiGate","expandedName":"Fortinet FortiGate","shortDefinition":"Fortinet's family of physical and virtual network-security and firewall appliances.","fullDefinition":"Fortinet's family of physical and virtual network-security and firewall appliances.","plainLanguageDefinition":"Fortinet's family of physical and virtual network-security and firewall appliances.","platforms":["firewalls"],"aliases":["FortiGate firewall","FGT"],"keywords":["Fortinet appliance","NGFW","network firewall","security gateway"],"relatedTerms":["Fortinet","FortiOS","Firewall","VDOM"],"articleIds":[53020],"vendors":["Fortinet"],"products":["FortiGate"],"technologies":["Firewall","Network Security"],"categories":["product","firewalls","security"],"relatedErrorCodes":[],"commands":[],"source":"Fortinet FortiOS 8.0.0 Administration Guide","reviewStatus":"verified","lastVerified":""},{"id":"fortios","term":"FortiOS","expandedName":"Fortinet operating system","shortDefinition":"The operating system and configuration environment used by FortiGate network-security appliances.","fullDefinition":"The operating system and configuration environment used by FortiGate network-security appliances.","plainLanguageDefinition":"The operating system and configuration environment used by FortiGate network-security appliances.","platforms":["firewalls"],"aliases":["FortiGate OS","Fortinet OS"],"keywords":["FortiOS CLI","FortiOS command","FortiGate firmware","firewall operating system"],"relatedTerms":["Fortinet","FortiGate","VDOM","FortiOS CLI Return Code"],"articleIds":[53020],"vendors":["Fortinet"],"products":["FortiOS 8.0.0","FortiGate"],"technologies":["Firewall OS","CLI"],"categories":["operating system","firewalls","security"],"relatedErrorCodes":[],"commands":[],"source":"Fortinet FortiOS 8.0.0 Administration Guide","reviewStatus":"verified","lastVerified":""},{"id":"vdom","term":"VDOM","expandedName":"Virtual Domain","shortDefinition":"A FortiOS feature that divides one FortiGate into separate virtual firewall contexts with independently scoped configuration and administration.","fullDefinition":"A FortiOS feature that divides one FortiGate into separate virtual firewall contexts with independently scoped configuration and administration.","plainLanguageDefinition":"A FortiOS feature that divides one FortiGate into separate virtual firewall contexts with independently scoped configuration and administration.","platforms":["firewalls"],"aliases":["Virtual Domain","FortiGate VDOM"],"keywords":["virtual firewall","FortiOS context","VDOM administrator","multi-tenant firewall"],"relatedTerms":["FortiGate","FortiOS","Firewall"],"articleIds":[53020],"vendors":["Fortinet"],"products":["FortiGate","FortiOS"],"technologies":["Virtual Domains","Configuration Context"],"categories":["acronym","firewalls","virtualization"],"relatedErrorCodes":[],"commands":[],"source":"Fortinet FortiOS 8.0.0 Administration Guide","reviewStatus":"verified","lastVerified":""},{"id":"fortios-cli-return-code","term":"FortiOS CLI Return Code","expandedName":"FortiOS command failure return code","shortDefinition":"A numeric identifier printed after “Command fail” that classifies why a FortiOS CLI command was rejected; the surrounding parser message and configuration context are still required.","fullDefinition":"A numeric identifier printed after “Command fail” that classifies why a FortiOS CLI command was rejected; the surrounding parser message and configuration context are still required.","plainLanguageDefinition":"A numeric identifier printed after “Command fail” that classifies why a FortiOS CLI command was rejected; the surrounding parser message and configuration context are still required.","platforms":["firewalls"],"aliases":["Command fail return code","FortiGate return code","FortiOS CLI error"],"keywords":["command parse error","return code -61","return code -651","CFG_ER_GENERIC","FortiGate CLI troubleshooting"],"relatedTerms":["FortiOS","FortiGate","CLI","VDOM"],"articleIds":[53000,53001,53002,53003,53004,53005,53006,53007,53008,53009,53010,53020],"vendors":["Fortinet"],"products":["FortiGate","FortiOS 8.0.0"],"technologies":["CLI","Configuration Validation"],"categories":["error family","firewalls","troubleshooting"],"relatedErrorCodes":["1","-1","-4","-5","-8","-37","-56","-61","-160","-553","-651"],"commands":["?","tree","show"],"source":"Fortinet FortiOS 8.0.0 Administration Guide — CLI troubleshooting cheat sheet","reviewStatus":"verified","lastVerified":""},{"id":"sonicwall","term":"SonicWall","expandedName":"SonicWall network security vendor","shortDefinition":"A network-security vendor whose products include SonicWall firewalls, the SonicOS operating system, and managed switches.","fullDefinition":"A network-security vendor whose products include SonicWall firewalls, the SonicOS operating system, and managed switches.","plainLanguageDefinition":"A network-security vendor whose products include SonicWall firewalls, the SonicOS operating system, and managed switches.","platforms":["firewalls"],"aliases":["SonicWall firewall","SonicWall switch"],"keywords":["firewall manufacturer","network security appliance","SonicOS vendor"],"relatedTerms":["Firewall","SonicOS","SonicOS API","Managed Switch"],"articleIds":[55000,55200],"vendors":["SonicWall"],"products":["SonicOS","SonicWall Switch"],"technologies":[],"categories":["vendor","firewalls","security"],"relatedErrorCodes":[],"commands":[],"source":"SonicWall product documentation","reviewStatus":"verified","lastVerified":""},{"id":"sonicos","term":"SonicOS","expandedName":"SonicWall firewall operating system","shortDefinition":"The operating system and configuration environment used by SonicWall network-security appliances.","fullDefinition":"The operating system and configuration environment used by SonicWall network-security appliances.","plainLanguageDefinition":"The operating system and configuration environment used by SonicWall network-security appliances.","platforms":["firewalls"],"aliases":["SonicWall OS","SonicWall firmware"],"keywords":["SonicOS firewall","SonicOS configuration","SonicWall API"],"relatedTerms":["SonicWall","Firewall","SonicOS API"],"articleIds":[55000],"vendors":["SonicWall"],"products":["SonicOS"],"technologies":["Firewall OS","Network Security"],"categories":["operating system","firewalls","security"],"relatedErrorCodes":[],"commands":[],"source":"SonicWall SonicOS documentation","reviewStatus":"verified","lastVerified":""},{"id":"sonicos-api","term":"SonicOS API","expandedName":"SonicWall REST API","shortDefinition":"An HTTP-based alternative to the SonicOS CLI for supported firewall configuration and operational functions.","fullDefinition":"An HTTP-based alternative to the SonicOS CLI for supported firewall configuration and operational functions.","plainLanguageDefinition":"An HTTP-based alternative to the SonicOS CLI for supported firewall configuration and operational functions.","platforms":["firewalls","platform-neutral"],"aliases":["SonicWall API","SonicOS REST API"],"keywords":["SonicWall API error","E_INVALID_API_CALL","SonicOS response code","firewall automation"],"relatedTerms":["SonicWall","SonicOS","REST API","HTTP"],"articleIds":[55000,55009,55021,55026,55028,55030,55037,55038,55039,55040,55046],"vendors":["SonicWall"],"products":["SonicOS API"],"technologies":["REST API","HTTP","Firewall Automation"],"categories":["api","firewalls","networking"],"relatedErrorCodes":["E_OK","E_INVALID_API_CALL","E_UNAUTHORIZED","E_ACCESS_DENIED","E_NOT_FOUND","E_TOO_BIG","E_TIME_OUT","E_OUT_OF_MEM"],"commands":[],"source":"SonicWall — List of Error Codes for SonicOS API Calls","reviewStatus":"verified","lastVerified":""},{"id":"sonicwall-switch-cli","term":"SonicWall Switch CLI","expandedName":"SonicWall managed-switch command line","shortDefinition":"The mode-based command interface used to inspect and configure SonicWall Switch network features.","fullDefinition":"The mode-based command interface used to inspect and configure SonicWall Switch network features.","plainLanguageDefinition":"The mode-based command interface used to inspect and configure SonicWall Switch network features.","platforms":["firewalls"],"aliases":["Switch 1.3.1 CLI","SonicWall managed switch CLI"],"keywords":["SonicWall switch commands","show vlan","show spanning-tree","show lldp","show power inline"],"relatedTerms":["SonicWall","VLAN","Spanning Tree","LLDP","PoE"],"articleIds":[55200,55201,55204,55208,55211,55218,55221],"vendors":["SonicWall"],"products":["SonicWall Switch 1.3.1"],"technologies":["Managed Switch","CLI","Ethernet Switching"],"categories":["cli","switching","networking"],"relatedErrorCodes":[],"commands":["help [command]","show vlan brief","show spanning-tree","show lldp neighbors detail"],"source":"SonicWall Switch 1.3.1 CLI Reference Guide","reviewStatus":"verified","lastVerified":""},{"id":"ruckus","term":"Ruckus","expandedName":"Ruckus Networks","shortDefinition":"A networking vendor whose portfolio includes ICX switches, wireless access points, controllers, cloud management, IoT, and WAN gateway products.","fullDefinition":"A networking vendor whose portfolio includes ICX switches, wireless access points, controllers, cloud management, IoT, and WAN gateway products.","plainLanguageDefinition":"A networking vendor whose portfolio includes ICX switches, wireless access points, controllers, cloud management, IoT, and WAN gateway products.","platforms":["network-appliances"],"aliases":["Ruckus Networks","CommScope Ruckus","Vistance Networks Ruckus"],"keywords":["wireless vendor","ICX switch vendor","Wi-Fi infrastructure"],"relatedTerms":["FastIron","ICX","SmartZone","ZoneDirector","Ruckus One"],"articleIds":[56000,56006,56012,56017],"vendors":["Ruckus Networks","Vistance Networks"],"products":["ICX","SmartZone","ZoneDirector","Ruckus One"],"technologies":[],"categories":["vendor","networking","wireless"],"relatedErrorCodes":[],"commands":[],"source":"Ruckus product documentation","reviewStatus":"verified","lastVerified":""},{"id":"fastiron","term":"FastIron","expandedName":"Ruckus FastIron","shortDefinition":"The switch operating system and CLI used by supported Ruckus ICX Ethernet switches.","fullDefinition":"The switch operating system and CLI used by supported Ruckus ICX Ethernet switches.","plainLanguageDefinition":"The switch operating system and CLI used by supported Ruckus ICX Ethernet switches.","platforms":["network-appliances"],"aliases":["FastIron OS","FI"],"keywords":["ICX firmware","FastIron command","Ruckus switch OS"],"relatedTerms":["Ruckus","ICX","CLI","VLAN","PoE"],"articleIds":[56000,56001,56002,56003,56004,56005,56006,56007,56008,56009,56010,56011],"vendors":["Ruckus Networks"],"products":["FastIron 09.0.10","FastIron 10.0.10"],"technologies":["Ethernet Switching","CLI"],"categories":["operating system","switching","networking"],"relatedErrorCodes":[],"commands":[],"source":"Ruckus FastIron documentation","reviewStatus":"verified","lastVerified":""},{"id":"icx","term":"ICX","expandedName":"Ruckus ICX Switch","shortDefinition":"Ruckus's family of managed Ethernet switches running FastIron software.","fullDefinition":"Ruckus's family of managed Ethernet switches running FastIron software.","plainLanguageDefinition":"Ruckus's family of managed Ethernet switches running FastIron software.","platforms":["network-appliances"],"aliases":["Ruckus ICX","Brocade ICX"],"keywords":["campus switch","PoE switch","managed switch"],"relatedTerms":["Ruckus","FastIron","SmartZone","Ruckus One"],"articleIds":[56000,56005,56006,56007,56011],"vendors":["Ruckus Networks"],"products":["ICX"],"technologies":["Ethernet Switching","PoE","Stacking"],"categories":["product","switching","networking"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"smartzone","term":"SmartZone","expandedName":"Ruckus SmartZone","shortDefinition":"A Ruckus wireless LAN controller platform for centrally managing access points, services, clusters, data planes, alarms, and configuration.","fullDefinition":"A Ruckus wireless LAN controller platform for centrally managing access points, services, clusters, data planes, alarms, and configuration.","plainLanguageDefinition":"A Ruckus wireless LAN controller platform for centrally managing access points, services, clusters, data planes, alarms, and configuration.","platforms":["network-appliances"],"aliases":["vSZ","Virtual SmartZone","vSZ-H"],"keywords":["wireless controller","SCG","Ruckus controller"],"relatedTerms":["Ruckus","Access Point","SNMP","ZoneDirector"],"articleIds":[56024,56041,56045],"vendors":["Ruckus Networks"],"products":["SmartZone vSZ-H 7.2.0"],"technologies":["Wireless LAN Controller","SNMP"],"categories":["product","wireless","networking"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"zonedirector","term":"ZoneDirector","expandedName":"Ruckus ZoneDirector","shortDefinition":"A Ruckus on-premises wireless LAN controller with CLI, AP-management, logging, backup, and troubleshooting functions.","fullDefinition":"A Ruckus on-premises wireless LAN controller with CLI, AP-management, logging, backup, and troubleshooting functions.","plainLanguageDefinition":"A Ruckus on-premises wireless LAN controller with CLI, AP-management, logging, backup, and troubleshooting functions.","platforms":["network-appliances"],"aliases":["ZD","Ruckus ZD"],"keywords":["wireless controller","ZoneDirector CLI","remote AP CLI"],"relatedTerms":["Ruckus","SmartZone","Access Point","WLAN"],"articleIds":[56020,56021,56022,56023],"vendors":["Ruckus Networks"],"products":["ZoneDirector 10.5.1"],"technologies":["Wireless LAN Controller","CLI"],"categories":["product","wireless","networking"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"ruckus-one","term":"Ruckus One","expandedName":"Ruckus One cloud management","shortDefinition":"Ruckus's cloud service for managing supported networking devices, subscriptions, sites, and operational data.","fullDefinition":"Ruckus's cloud service for managing supported networking devices, subscriptions, sites, and operational data.","plainLanguageDefinition":"Ruckus's cloud service for managing supported networking devices, subscriptions, sites, and operational data.","platforms":["network-appliances"],"aliases":["R1","Ruckus Cloud"],"keywords":["Ruckus subscription","device registrar","cloud network management"],"relatedTerms":["Ruckus","ICX","SmartZone","License"],"articleIds":[56006,56007,56016,56017,56018],"vendors":["Ruckus Networks"],"products":["Ruckus One"],"technologies":["Cloud Management","Licensing"],"categories":["product","cloud","networking"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"ruckus-network-director","term":"Ruckus Network Director","expandedName":"RND","shortDefinition":"A Ruckus management application for AP onboarding, controller synchronization, backup, licensing, alarms, and network troubleshooting.","fullDefinition":"A Ruckus management application for AP onboarding, controller synchronization, backup, licensing, alarms, and network troubleshooting.","plainLanguageDefinition":"A Ruckus management application for AP onboarding, controller synchronization, backup, licensing, alarms, and network troubleshooting.","platforms":["network-appliances"],"aliases":["RND","Network Director"],"keywords":["network-tools","RND license","AP onboarding"],"relatedTerms":["Ruckus","SmartZone","Access Point","Flexera"],"articleIds":[56012,56013,56014,56015],"vendors":["Ruckus Networks"],"products":["Ruckus Network Director 4.0"],"technologies":["Network Management","CLI","Licensing"],"categories":["product","networking","management"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"adtran","term":"Adtran","expandedName":"Advanced Transmission","shortDefinition":"A telecommunications and networking vendor whose products include NetVanta, Total Access, optical-access, broadband, voice, and cloud-management platforms.","fullDefinition":"A telecommunications and networking vendor whose products include NetVanta, Total Access, optical-access, broadband, voice, and cloud-management platforms.","plainLanguageDefinition":"A telecommunications and networking vendor whose products include NetVanta, Total Access, optical-access, broadband, voice, and cloud-management platforms.","platforms":["network-appliances"],"aliases":["ADTRAN","Adtran Networks"],"keywords":["network vendor","access networking","telecommunications equipment"],"relatedTerms":["AOS","NetVanta","Total Access","GPON"],"articleIds":[57000,57005,57006],"vendors":["Adtran"],"products":["AOS","NetVanta","Total Access 900"],"technologies":[],"categories":["vendor","networking","telecommunications"],"relatedErrorCodes":[],"commands":[],"source":"Adtran Glossary of Acronyms, June 2022","reviewStatus":"verified","lastVerified":""},{"id":"adtran-aos","term":"AOS","expandedName":"Adtran Operating System","shortDefinition":"The command-line operating system used by multiple Adtran NetVanta and Total Access 900 products; command availability depends on platform and release.","fullDefinition":"The command-line operating system used by multiple Adtran NetVanta and Total Access 900 products; command availability depends on platform and release.","plainLanguageDefinition":"The command-line operating system used by multiple Adtran NetVanta and Total Access 900 products; command availability depends on platform and release.","platforms":["network-appliances"],"aliases":["ADTRAN Operating System","Adtran OS"],"keywords":["AOS CLI","NetVanta CLI","Total Access CLI"],"relatedTerms":["Adtran","NetVanta","Total Access","CLI"],"articleIds":[57000,57001,57002,57003,57004,57005,57006,57007,57008,57009,57010,57011,57012,57013,57014,57015,57016,57017,57018,57019,57020,57021,57022],"vendors":["Adtran"],"products":["AOS R10.1.0"],"technologies":["Network Operating System","CLI"],"categories":["operating system","networking"],"relatedErrorCodes":[],"commands":[],"source":"Adtran AOS R10.1.0 Command Reference Guide","reviewStatus":"verified","lastVerified":""},{"id":"netvanta","term":"NetVanta","expandedName":"Adtran NetVanta","shortDefinition":"An Adtran product family spanning routers, switches, unified communications, and other business networking appliances.","fullDefinition":"An Adtran product family spanning routers, switches, unified communications, and other business networking appliances.","plainLanguageDefinition":"An Adtran product family spanning routers, switches, unified communications, and other business networking appliances.","platforms":["network-appliances"],"aliases":["Adtran NetVanta"],"keywords":["NetVanta router","NetVanta switch","AOS appliance"],"relatedTerms":["Adtran","AOS","Routing","Switching"],"articleIds":[57006,57007,57008,57012],"vendors":["Adtran"],"products":["NetVanta"],"technologies":[],"categories":["product","networking"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"total-access","term":"Total Access","expandedName":"Adtran Total Access","shortDefinition":"An Adtran access and voice product family; supported Total Access 900 products use AOS.","fullDefinition":"An Adtran access and voice product family; supported Total Access 900 products use AOS.","plainLanguageDefinition":"An Adtran access and voice product family; supported Total Access 900 products use AOS.","platforms":["network-appliances"],"aliases":["TA900","Total Access 900"],"keywords":["Adtran gateway","voice gateway","access platform"],"relatedTerms":["Adtran","AOS","SIP","POTS"],"articleIds":[57021],"vendors":["Adtran"],"products":["Total Access 900"],"technologies":[],"categories":["product","telecommunications","voice"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"bsap","term":"BSAP","expandedName":"Bluesocket Access Point","shortDefinition":"Adtran's acronym for a Bluesocket wireless access point.","fullDefinition":"Adtran's acronym for a Bluesocket wireless access point.","plainLanguageDefinition":"Adtran's acronym for a Bluesocket wireless access point.","platforms":["network-appliances"],"aliases":["Bluesocket AP"],"keywords":["Adtran wireless AP","Bluesocket Wi-Fi"],"relatedTerms":["Adtran","Access Point","vWLAN"],"articleIds":[],"vendors":["Adtran"],"products":["Bluesocket"],"technologies":[],"categories":["acronym","wireless"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"ipbg","term":"IPBG","expandedName":"IP Business Gateways","shortDefinition":"Adtran's term for its IP Business Gateway product category.","fullDefinition":"Adtran's term for its IP Business Gateway product category.","plainLanguageDefinition":"Adtran's term for its IP Business Gateway product category.","platforms":["network-appliances"],"aliases":["IP Business Gateway"],"keywords":["Adtran gateway","business gateway"],"relatedTerms":["Adtran","NetVanta","AOS"],"articleIds":[],"vendors":["Adtran"],"products":[],"technologies":[],"categories":["acronym","product family"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"mosaic-cp","term":"Mosaic CP","expandedName":"Mosaic Cloud Platform","shortDefinition":"Adtran's Mosaic Cloud Platform for supported cloud-managed networking services.","fullDefinition":"Adtran's Mosaic Cloud Platform for supported cloud-managed networking services.","plainLanguageDefinition":"Adtran's Mosaic Cloud Platform for supported cloud-managed networking services.","platforms":["network-appliances"],"aliases":["Mosaic Cloud Platform"],"keywords":["Adtran cloud management","Mosaic platform"],"relatedTerms":["Adtran","Mosaic Device Manager","Mosaic Network Insights"],"articleIds":[],"vendors":["Adtran"],"products":["Mosaic Cloud Platform"],"technologies":[],"categories":["product","cloud management"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"adtran-mdm","term":"Mosaic Device Manager","expandedName":"MDM","shortDefinition":"An Adtran Mosaic application for managing supported network devices; this meaning is distinct from Mobile Device Management.","fullDefinition":"An Adtran Mosaic application for managing supported network devices; this meaning is distinct from Mobile Device Management.","plainLanguageDefinition":"An Adtran Mosaic application for managing supported network devices; this meaning is distinct from Mobile Device Management.","platforms":["network-appliances"],"aliases":["Adtran MDM","Mosaic MDM"],"keywords":["Mosaic device management","Adtran network management"],"relatedTerms":["Mosaic CP","MNI","Adtran"],"articleIds":[],"vendors":["Adtran"],"products":["Mosaic Device Manager"],"technologies":[],"categories":["product","network management"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"mni","term":"MNI","expandedName":"Mosaic Network Insights","shortDefinition":"An Adtran Mosaic analytics and network-insights product term.","fullDefinition":"An Adtran Mosaic analytics and network-insights product term.","plainLanguageDefinition":"An Adtran Mosaic analytics and network-insights product term.","platforms":["network-appliances"],"aliases":["Mosaic Network Insights"],"keywords":["Adtran analytics","network insights"],"relatedTerms":["Mosaic CP","Mosaic Device Manager","Adtran"],"articleIds":[],"vendors":["Adtran"],"products":["Mosaic Network Insights"],"technologies":[],"categories":["acronym","analytics"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"msap","term":"MSAP","expandedName":"Multi-Service Access and Aggregation Platform","shortDefinition":"A carrier access platform that combines multiple subscriber services and aggregates them toward the provider network.","fullDefinition":"A carrier access platform that combines multiple subscriber services and aggregates them toward the provider network.","plainLanguageDefinition":"A carrier access platform that combines multiple subscriber services and aggregates them toward the provider network.","platforms":["network-appliances"],"aliases":["Multi-Service Access and Aggregation Platform"],"keywords":["access platform","subscriber aggregation","carrier access"],"relatedTerms":["Adtran","OLT","DSLAM"],"articleIds":[],"vendors":["Adtran"],"products":[],"technologies":[],"categories":["acronym","access networking"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"gpon","term":"GPON","expandedName":"Gigabit Passive Optical Network","shortDefinition":"A passive optical access technology that shares downstream and upstream fiber capacity between an OLT and multiple subscriber ONTs or ONUs.","fullDefinition":"A passive optical access technology that shares downstream and upstream fiber capacity between an OLT and multiple subscriber ONTs or ONUs.","plainLanguageDefinition":"A passive optical access technology that shares downstream and upstream fiber capacity between an OLT and multiple subscriber ONTs or ONUs.","platforms":["network-appliances"],"aliases":["Gigabit Passive Optical Network"],"keywords":["fiber access","PON","FTTH"],"relatedTerms":["OLT","ONT","ONU","EPON"],"articleIds":[],"vendors":["Adtran"],"products":[],"technologies":[],"categories":["acronym","optical networking"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"epon","term":"EPON","expandedName":"Ethernet Passive Optical Networking","shortDefinition":"A passive optical access technology carrying Ethernet frames between an OLT and subscriber ONUs.","fullDefinition":"A passive optical access technology carrying Ethernet frames between an OLT and subscriber ONUs.","plainLanguageDefinition":"A passive optical access technology carrying Ethernet frames between an OLT and subscriber ONUs.","platforms":["network-appliances"],"aliases":["Ethernet Passive Optical Network","Ethernet Passive Optical Networking"],"keywords":["fiber access","PON","FTTH"],"relatedTerms":["OLT","ONU","GPON","DPoE"],"articleIds":[],"vendors":["Adtran"],"products":[],"technologies":[],"categories":["acronym","optical networking"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"olt","term":"OLT","expandedName":"Optical Line Terminal","shortDefinition":"The provider-side endpoint of a passive optical network that connects the access fiber plant to upstream services.","fullDefinition":"The provider-side endpoint of a passive optical network that connects the access fiber plant to upstream services.","plainLanguageDefinition":"The provider-side endpoint of a passive optical network that connects the access fiber plant to upstream services.","platforms":["network-appliances"],"aliases":["Optical Line Terminal"],"keywords":["PON headend","fiber access platform"],"relatedTerms":["ONT","ONU","GPON","EPON"],"articleIds":[],"vendors":["Adtran"],"products":[],"technologies":[],"categories":["acronym","optical networking"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"ont","term":"ONT","expandedName":"Optical Network Terminal","shortDefinition":"A subscriber-side optical device that terminates a passive optical network and presents customer Ethernet, voice, or other services.","fullDefinition":"A subscriber-side optical device that terminates a passive optical network and presents customer Ethernet, voice, or other services.","plainLanguageDefinition":"A subscriber-side optical device that terminates a passive optical network and presents customer Ethernet, voice, or other services.","platforms":["network-appliances"],"aliases":["Optical Network Terminal"],"keywords":["fiber customer device","PON terminal"],"relatedTerms":["OLT","ONU","GPON"],"articleIds":[],"vendors":["Adtran"],"products":[],"technologies":[],"categories":["acronym","optical networking"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"onu","term":"ONU","expandedName":"Optical Network Unit","shortDefinition":"A subscriber- or distribution-side optical endpoint used in passive optical access networks.","fullDefinition":"A subscriber- or distribution-side optical endpoint used in passive optical access networks.","plainLanguageDefinition":"A subscriber- or distribution-side optical endpoint used in passive optical access networks.","platforms":["network-appliances"],"aliases":["Optical Network Unit","Optical Network Units"],"keywords":["fiber endpoint","PON unit"],"relatedTerms":["OLT","ONT","GPON","EPON"],"articleIds":[],"vendors":["Adtran"],"products":[],"technologies":[],"categories":["acronym","optical networking"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"pon","term":"PON","expandedName":"Passive Optical Network","shortDefinition":"A point-to-multipoint fiber access network using passive splitters between the provider OLT and subscriber ONTs or ONUs.","fullDefinition":"A point-to-multipoint fiber access network using passive splitters between the provider OLT and subscriber ONTs or ONUs.","plainLanguageDefinition":"A point-to-multipoint fiber access network using passive splitters between the provider OLT and subscriber ONTs or ONUs.","platforms":["network-appliances"],"aliases":["Passive Optical Network"],"keywords":["fiber access","optical splitter","FTTH"],"relatedTerms":["GPON","EPON","OLT","ONT","ONU"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":["acronym","optical networking"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"dslam","term":"DSLAM","expandedName":"Digital Subscriber Line Access Multiplexer","shortDefinition":"A provider access device that terminates multiple subscriber DSL circuits and aggregates them toward the network.","fullDefinition":"A provider access device that terminates multiple subscriber DSL circuits and aggregates them toward the network.","plainLanguageDefinition":"A provider access device that terminates multiple subscriber DSL circuits and aggregates them toward the network.","platforms":["network-appliances"],"aliases":["Digital Subscriber Line Access Multiplexer"],"keywords":["DSL access","subscriber lines","broadband aggregation"],"relatedTerms":["ADSL","VDSL","MSAP"],"articleIds":[],"vendors":["Adtran"],"products":[],"technologies":[],"categories":["acronym","broadband"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"dpoe","term":"DPoE","expandedName":"DOCSIS Provisioning of EPON","shortDefinition":"A CableLabs specification for provisioning and managing EPON access using DOCSIS-oriented operational models.","fullDefinition":"A CableLabs specification for provisioning and managing EPON access using DOCSIS-oriented operational models.","plainLanguageDefinition":"A CableLabs specification for provisioning and managing EPON access using DOCSIS-oriented operational models.","platforms":["network-appliances"],"aliases":["DOCSIS Provisioning of EPON"],"keywords":["EPON provisioning","cable access"],"relatedTerms":["EPON","OLT","ONU"],"articleIds":[],"vendors":["Adtran"],"products":[],"technologies":[],"categories":["acronym","optical networking"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"cwmp","term":"CWMP","expandedName":"CPE WAN Management Protocol","shortDefinition":"The remote-management protocol commonly associated with TR-069 for provisioning and managing customer-premises equipment.","fullDefinition":"The remote-management protocol commonly associated with TR-069 for provisioning and managing customer-premises equipment.","plainLanguageDefinition":"The remote-management protocol commonly associated with TR-069 for provisioning and managing customer-premises equipment.","platforms":["network-appliances"],"aliases":["CPE WAN Management Protocol","TR-069"],"keywords":["remote CPE management","auto configuration"],"relatedTerms":["ACS","CPE","USP"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":["acronym","management protocol"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"acs","term":"ACS","expandedName":"Auto-Configuration Server","shortDefinition":"In broadband management, a server that provisions and manages compatible CPE through CWMP/TR-069; the acronym has other meanings in other contexts.","fullDefinition":"In broadband management, a server that provisions and manages compatible CPE through CWMP/TR-069; the acronym has other meanings in other contexts.","plainLanguageDefinition":"In broadband management, a server that provisions and manages compatible CPE through CWMP/TR-069; the acronym has other meanings in other contexts.","platforms":["network-appliances"],"aliases":["Auto Configuration Server","TR-069 ACS"],"keywords":["CPE provisioning","remote management server"],"relatedTerms":["CWMP","CPE"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":["acronym","management platform"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"vqm","term":"VQM","expandedName":"Voice Quality Monitoring","shortDefinition":"Monitoring of voice-call quality indicators such as loss, delay, jitter, and estimated Mean Opinion Score.","fullDefinition":"Monitoring of voice-call quality indicators such as loss, delay, jitter, and estimated Mean Opinion Score.","plainLanguageDefinition":"Monitoring of voice-call quality indicators such as loss, delay, jitter, and estimated Mean Opinion Score.","platforms":["network-appliances"],"aliases":["Voice Quality Monitoring"],"keywords":["VoIP quality","call quality","MOS"],"relatedTerms":["VoIP","RTP","MOS","SIP"],"articleIds":[],"vendors":["Adtran"],"products":[],"technologies":[],"categories":["acronym","voice"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"efm","term":"EFM","expandedName":"Ethernet in the First Mile","shortDefinition":"IEEE 802.3 access technologies that extend Ethernet across first-mile subscriber links.","fullDefinition":"IEEE 802.3 access technologies that extend Ethernet across first-mile subscriber links.","plainLanguageDefinition":"IEEE 802.3 access technologies that extend Ethernet across first-mile subscriber links.","platforms":["network-appliances"],"aliases":["Ethernet in the First Mile"],"keywords":["carrier Ethernet access","first mile Ethernet"],"relatedTerms":["EoCU","EoF","EPON"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":["acronym","ethernet access"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"ubiquiti","term":"Ubiquiti","expandedName":"Ubiquiti Inc.","shortDefinition":"A network-technology vendor whose UniFi portfolio includes cloud gateways, access points, switches, applications, and management APIs.","fullDefinition":"A network-technology vendor whose UniFi portfolio includes cloud gateways, access points, switches, applications, and management APIs.","plainLanguageDefinition":"A network-technology vendor whose UniFi portfolio includes cloud gateways, access points, switches, applications, and management APIs.","platforms":["network-appliances"],"aliases":["UI","UBNT"],"keywords":["UniFi vendor","Ubiquiti Networks","Dream Machine"],"relatedTerms":["UniFi","UniFi OS","UDM","Cloud Gateway"],"articleIds":[58000,58009,58010,58011],"vendors":["Ubiquiti"],"products":["UniFi"],"technologies":[],"categories":["vendor","networking"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"unifi","term":"UniFi","expandedName":"Ubiquiti UniFi","shortDefinition":"Ubiquiti's ecosystem for managing supported gateways, switching, wireless, security, and related network applications.","fullDefinition":"Ubiquiti's ecosystem for managing supported gateways, switching, wireless, security, and related network applications.","plainLanguageDefinition":"Ubiquiti's ecosystem for managing supported gateways, switching, wireless, security, and related network applications.","platforms":["network-appliances"],"aliases":["UniFi Network"],"keywords":["UniFi controller","UniFi application","UniFi console"],"relatedTerms":["Ubiquiti","UniFi OS","UDM","Adoption"],"articleIds":[58000,58001,58002,58003,58004,58005,58006,58007,58008,58009,58010,58011,58012,58013,58014,58015,58016],"vendors":["Ubiquiti"],"products":["UniFi Network"],"technologies":[],"categories":["product","networking"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"udm","term":"UDM","expandedName":"UniFi Dream Machine","shortDefinition":"A Ubiquiti UniFi cloud-gateway family that combines routing, security, management, and model-dependent applications or storage.","fullDefinition":"A Ubiquiti UniFi cloud-gateway family that combines routing, security, management, and model-dependent applications or storage.","plainLanguageDefinition":"A Ubiquiti UniFi cloud-gateway family that combines routing, security, management, and model-dependent applications or storage.","platforms":["network-appliances"],"aliases":["Dream Machine","UDM Pro","UDM SE"],"keywords":["UniFi gateway","cloud gateway","Dream Machine Pro"],"relatedTerms":["UniFi","UniFi OS","WAN","Adoption"],"articleIds":[58009,58010,58014],"vendors":["Ubiquiti"],"products":["UniFi Dream Machine"],"technologies":[],"categories":["product","gateway","networking"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"unifi-api","term":"UniFi API","expandedName":"Ubiquiti UniFi API","shortDefinition":"Versioned Ubiquiti interfaces for programmatic access to supported UniFi resources; error responses include HTTP status and machine-readable context.","fullDefinition":"Versioned Ubiquiti interfaces for programmatic access to supported UniFi resources; error responses include HTTP status and machine-readable context.","plainLanguageDefinition":"Versioned Ubiquiti interfaces for programmatic access to supported UniFi resources; error responses include HTTP status and machine-readable context.","platforms":["network-appliances"],"aliases":["UniFi Network API","UI API"],"keywords":["api.ui.com","UniFi API error","requestId"],"relatedTerms":["Ubiquiti","HTTP","API Key","Rate Limit"],"articleIds":[58000,58001,58002,58003,58004,58005,58006,58007,58008],"vendors":["Ubiquiti"],"products":["UniFi Network API v9.3.43"],"technologies":["REST API"],"categories":["api","networking"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"verkada","term":"Verkada","expandedName":"Verkada Inc.","shortDefinition":"A cloud-managed physical-security vendor whose portfolio includes cameras, access control, environmental sensors, intercoms, alarms, and connectivity products.","fullDefinition":"A cloud-managed physical-security vendor whose portfolio includes cameras, access control, environmental sensors, intercoms, alarms, and connectivity products.","plainLanguageDefinition":"A cloud-managed physical-security vendor whose portfolio includes cameras, access control, environmental sensors, intercoms, alarms, and connectivity products.","platforms":["network-appliances"],"aliases":["Verkada Command"],"keywords":["cloud camera vendor","physical security platform","video security"],"relatedTerms":["Verkada Cameras","Command","PoE","Video Surveillance"],"articleIds":[59000,59001,59002,59003,59004,59005,59006,59007,59008,59009,59010,59011,59012,59013,59014,59015,59016,59017,59018,59019,59020],"vendors":["Verkada"],"products":["Verkada Command","Verkada Cameras"],"technologies":[],"categories":["vendor","physical security","networking"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"verkada-command","term":"Verkada Command","expandedName":"Command","shortDefinition":"Verkada's cloud management platform for supported physical-security devices, users, sites, video, alerts, and integrations.","fullDefinition":"Verkada's cloud management platform for supported physical-security devices, users, sites, video, alerts, and integrations.","plainLanguageDefinition":"Verkada's cloud management platform for supported physical-security devices, users, sites, video, alerts, and integrations.","platforms":["network-appliances"],"aliases":["Command dashboard"],"keywords":["Verkada cloud","camera management","Command offline"],"relatedTerms":["Verkada","Camera","Cloud","API"],"articleIds":[59007,59009,59010],"vendors":["Verkada"],"products":["Verkada Command"],"technologies":[],"categories":["product","cloud management","physical security"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"verkada-api","term":"Verkada API","expandedName":"Verkada integration API","shortDefinition":"Verkada's HTTP APIs use conventional response status codes for supported integration operations.","fullDefinition":"Verkada's HTTP APIs use conventional response status codes for supported integration operations.","plainLanguageDefinition":"Verkada's HTTP APIs use conventional response status codes for supported integration operations.","platforms":["network-appliances"],"aliases":["Verkada integration API"],"keywords":["Verkada API key","Verkada HTTP response","apidocs.verkada.com"],"relatedTerms":["Verkada","HTTP","API Key","Rate Limit"],"articleIds":[59000,59001,59002,59003,59004,59005,59006],"vendors":["Verkada"],"products":["Verkada API"],"technologies":["REST API"],"categories":["api","physical security"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"verkada-led","term":"Verkada Camera LED","expandedName":"Verkada camera status indicator","shortDefinition":"Exterior and model-specific camera LEDs communicate boot, update, recording, cloud-connectivity, hardware, and granular network states.","fullDefinition":"Exterior and model-specific camera LEDs communicate boot, update, recording, cloud-connectivity, hardware, and granular network states.","plainLanguageDefinition":"Exterior and model-specific camera LEDs communicate boot, update, recording, cloud-connectivity, hardware, and granular network states.","platforms":["network-appliances"],"aliases":["Verkada LED code","camera light status"],"keywords":["orange blue camera light","Verkada flashing LED","camera offline LED"],"relatedTerms":["Verkada","PoE","DHCP","DNS","NTP","TLS"],"articleIds":[59007,59008,59009,59010,59011,59012,59013,59014,59015,59016,59017,59018,59019,59020],"vendors":["Verkada"],"products":["Verkada Cameras"],"technologies":[],"categories":["diagnostic indicator","camera","networking"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"google-workspace","term":"Google Workspace","expandedName":"Google Apps / G Suite","shortDefinition":"Google's cloud productivity and administration platform for managed identity, Gmail, Drive, Calendar, groups, devices, security, and collaboration.","fullDefinition":"Google's cloud productivity and administration platform for managed identity, Gmail, Drive, Calendar, groups, devices, security, and collaboration.","plainLanguageDefinition":"Google's cloud productivity and administration platform for managed identity, Gmail, Drive, Calendar, groups, devices, security, and collaboration.","platforms":["platform-neutral","cross-platform"],"aliases":["G Suite","Google Apps for Business"],"keywords":["Google tenant","Workspace admin","Google business email"],"relatedTerms":["Google Admin","Directory API","Gmail","Google Drive","Google Groups"],"articleIds":[65000,65001,65002,65003,65004,65005,65006,65007,65008,65009,65010,65011,65012,65013,65014,65015,65016,65017,65018,65019,65020,65021,65022,65023,65024],"vendors":["Google"],"products":["Google Workspace"],"technologies":[],"categories":["product","cloud productivity","identity"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"google-admin-console","term":"Google Admin Console","expandedName":"admin.google.com","shortDefinition":"The management interface for Google Workspace users, groups, organizational units, domains, applications, devices, security, billing, reports, and administrator roles.","fullDefinition":"The management interface for Google Workspace users, groups, organizational units, domains, applications, devices, security, billing, reports, and administrator roles.","plainLanguageDefinition":"The management interface for Google Workspace users, groups, organizational units, domains, applications, devices, security, billing, reports, and administrator roles.","platforms":["platform-neutral"],"aliases":["Google Admin","Workspace Admin console"],"keywords":["admin.google.com","Google administrator","Google Super Admin"],"relatedTerms":["RBAC","Organizational Unit","Admin Role","Audit"],"articleIds":[65000,65001,65002,65003,65004,65005,65014,65015,65016,65018,65023,65024],"vendors":["Google"],"products":["Google Admin Console"],"technologies":[],"categories":["administration","identity","cloud"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"google-directory-api","term":"Google Admin SDK Directory API","expandedName":"Directory API","shortDefinition":"Google's REST API for administering Workspace users, aliases, groups, members, organizational units, domains, devices, roles, schemas, and related directory resources.","fullDefinition":"Google's REST API for administering Workspace users, aliases, groups, members, organizational units, domains, devices, roles, schemas, and related directory resources.","plainLanguageDefinition":"Google's REST API for administering Workspace users, aliases, groups, members, organizational units, domains, devices, roles, schemas, and related directory resources.","platforms":["platform-neutral"],"aliases":["Admin SDK","admin.googleapis.com"],"keywords":["Google Workspace API","Directory API error","Google users API"],"relatedTerms":["OAuth 2.0","REST API","Users","Groups","RBAC"],"articleIds":[65001,65002,65004,65005,65006,65007,65008,65009,65010,65011,65012,65013,65014,65015,65016,65023,65024],"vendors":["Google"],"products":["Google Admin SDK Directory API"],"technologies":[],"categories":["api","identity","administration"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"google-organizational-unit","term":"Google Organizational Unit","expandedName":"Google Workspace OU","shortDefinition":"A hierarchical container used to scope Google Workspace settings and administrator responsibilities to selected users and devices.","fullDefinition":"A hierarchical container used to scope Google Workspace settings and administrator responsibilities to selected users and devices.","plainLanguageDefinition":"A hierarchical container used to scope Google Workspace settings and administrator responsibilities to selected users and devices.","platforms":["platform-neutral"],"aliases":["Google OU","Workspace organizational unit"],"keywords":["Google policy inheritance","move Google users","Google OU path"],"relatedTerms":["Google Admin","Policy Inheritance","RBAC"],"articleIds":[65003,65004,65005,65024],"vendors":["Google"],"products":["Google Admin Console","Directory API"],"technologies":[],"categories":["identity","policy","hierarchy"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"google-email-log-search","term":"Google Email Log Search","expandedName":"ELS","shortDefinition":"An administrator tool for tracing accepted, routed, rejected, quarantined, and delivered Gmail messages in a Google Workspace organization.","fullDefinition":"An administrator tool for tracing accepted, routed, rejected, quarantined, and delivered Gmail messages in a Google Workspace organization.","plainLanguageDefinition":"An administrator tool for tracing accepted, routed, rejected, quarantined, and delivered Gmail messages in a Google Workspace organization.","platforms":["platform-neutral"],"aliases":["ELS","Gmail log search"],"keywords":["find missing Google email","Google mail trace","Workspace message tracking"],"relatedTerms":["Gmail","MX Records","Mail Flow","Routing"],"articleIds":[65017],"vendors":["Google"],"products":["Google Workspace Gmail"],"technologies":[],"categories":["email","troubleshooting","audit"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"gmail-smtp","term":"Gmail SMTP","expandedName":"Simple Mail Transfer Protocol","shortDefinition":"Google's Gmail delivery responses combine a three-digit SMTP reply with an enhanced status such as 5.7.26 to identify authentication, policy, quota, syntax, routing, reputation, or temporary-delivery failures.","fullDefinition":"Google's Gmail delivery responses combine a three-digit SMTP reply with an enhanced status such as 5.7.26 to identify authentication, policy, quota, syntax, routing, reputation, or temporary-delivery failures.","plainLanguageDefinition":"Google's Gmail delivery responses combine a three-digit SMTP reply with an enhanced status such as 5.7.26 to identify authentication, policy, quota, syntax, routing, reputation, or temporary-delivery failures.","platforms":["platform-neutral"],"aliases":["Google SMTP","gsmtp","gcdp"],"keywords":["Gmail bounce code","Google SMTP error","enhanced mail status"],"relatedTerms":["SPF","DKIM","DMARC","TLS","Email Log Search"],"articleIds":[65025,65040,65071],"vendors":["Google"],"products":["Google Workspace Gmail"],"technologies":[],"categories":["email","protocol","troubleshooting"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"google-login-challenge","term":"Google Login Challenge","expandedName":"Identity Verification Challenge","shortDefinition":"An extra identity check triggered by suspicious activity; it differs from routinely enforced 2-Step Verification and may require a time-limited administrator recovery action.","fullDefinition":"An extra identity check triggered by suspicious activity; it differs from routinely enforced 2-Step Verification and may require a time-limited administrator recovery action.","plainLanguageDefinition":"An extra identity check triggered by suspicious activity; it differs from routinely enforced 2-Step Verification and may require a time-limited administrator recovery action.","platforms":["platform-neutral"],"aliases":["Google security challenge","2SV lockout"],"keywords":["can't pass Google verification","disable login challenge","backup verification code"],"relatedTerms":["2-Step Verification","Account Recovery","Security Key"],"articleIds":[65084],"vendors":["Google"],"products":["Google Workspace Identity"],"technologies":[],"categories":["identity","security","troubleshooting"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"google-compromised-account","term":"Google Compromised Account","expandedName":"Workspace Account Incident","shortDefinition":"A managed Google identity suspected of unauthorized sign-in, token use, mail rules, forwarding, device activity, or administrative changes.","fullDefinition":"A managed Google identity suspected of unauthorized sign-in, token use, mail rules, forwarding, device activity, or administrative changes.","plainLanguageDefinition":"A managed Google identity suspected of unauthorized sign-in, token use, mail rules, forwarding, device activity, or administrative changes.","platforms":["platform-neutral"],"aliases":["hijacked Google account","Workspace account takeover"],"keywords":["suspicious Google sign-in","malicious Gmail forwarding","revoke Google OAuth tokens"],"relatedTerms":["OAuth","User Log Events","Email Log Search","2-Step Verification"],"articleIds":[65082],"vendors":["Google"],"products":["Google Workspace Security"],"technologies":[],"categories":["security","incident response","identity"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"chromeos","term":"ChromeOS","expandedName":"Google Chrome Operating System","shortDefinition":"Google's Linux-based operating system for Chromebooks and related devices; ChromiumOS is its open-source development foundation.","fullDefinition":"Google's Linux-based operating system for Chromebooks and related devices; ChromiumOS is its open-source development foundation.","plainLanguageDefinition":"Google's Linux-based operating system for Chromebooks and related devices; ChromiumOS is its open-source development foundation.","platforms":["chromeos"],"aliases":["ChromiumOS","Chromebook OS"],"keywords":["Chromebook operating system","Chrome OS developer"],"relatedTerms":["Linux","errno","crosh"],"articleIds":[50000],"vendors":["Google","Chromium"],"products":["ChromeOS","ChromiumOS"],"technologies":[],"categories":["operating system","chromeos"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"errno","term":"errno","expandedName":"Linux error number","shortDefinition":"A per-thread integer set by many failed Linux system calls and library functions; the symbolic constant and immediate call context are required to interpret it correctly.","fullDefinition":"A per-thread integer set by many failed Linux system calls and library functions; the symbolic constant and immediate call context are required to interpret it correctly.","plainLanguageDefinition":"A per-thread integer set by many failed Linux system calls and library functions; the symbolic constant and immediate call context are required to interpret it correctly.","platforms":["linux","chromeos"],"aliases":["Linux errno","error number"],"keywords":["EPERM","ENOENT","EACCES","system call error"],"relatedTerms":["System Call","Linux","ChromeOS"],"articleIds":[50000,50001,50013],"vendors":["Chromium"],"products":["ChromiumOS"],"technologies":[],"categories":["error codes","linux","chromeos"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"system-call","term":"System Call","expandedName":"Kernel service request","shortDefinition":"A controlled request by a process to the operating-system kernel for services such as file, process, memory, device, or network operations.","fullDefinition":"A controlled request by a process to the operating-system kernel for services such as file, process, memory, device, or network operations.","plainLanguageDefinition":"A controlled request by a process to the operating-system kernel for services such as file, process, memory, device, or network operations.","platforms":["linux","chromeos"],"aliases":["syscall"],"keywords":["kernel call","strace","Linux API"],"relatedTerms":["errno","Kernel","Process"],"articleIds":[50000],"vendors":["Chromium"],"products":["ChromiumOS"],"technologies":[],"categories":["operating system","development"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"mitel","term":"Mitel","expandedName":"Mitel Networks","shortDefinition":"A unified-communications vendor whose portfolios include MiCollab, MiVoice Business, MiVoice Connect, MX-ONE, MiContact Center, phones, gateways, and collaboration services.","fullDefinition":"A unified-communications vendor whose portfolios include MiCollab, MiVoice Business, MiVoice Connect, MX-ONE, MiContact Center, phones, gateways, and collaboration services.","plainLanguageDefinition":"A unified-communications vendor whose portfolios include MiCollab, MiVoice Business, MiVoice Connect, MX-ONE, MiContact Center, phones, gateways, and collaboration services.","platforms":["network-appliances","windows","linux"],"aliases":["Mitel Networks Corporation"],"keywords":["phone system vendor","Mitel PBX","business telephony","Mitel Windows Server installation","Mitel disaster recovery"],"relatedTerms":["MiCollab","MiVoice Business","MiVoice Connect","MX-ONE","MiContact Center","VMware"],"articleIds":[60000,60001,60002,60003,60004,60005,60006,60007,60008,60009,60010,60011,60012,60013,60014,60015,60016,60017,60018,60019,60020,60021,60022,60023,60024,60025,60026,60027,60028,60029,60030,60031,60032,60033,60034,60100,60101,60102,60103,60104,60105,60106,60107,60108,60109,60110,60111,60112,60113,60114,60115,60116,60117,60118,60119,60120,60121,60122,60123,60124,60125,60126,60127,60128,60129,60130,60131,60132,60133,60134,60135,60136,60137,60138,60139,60140,60141,60142,60143,60144,60145],"vendors":["Mitel"],"products":["MiCollab","MiVoice Business","MiVoice Connect","MiContact Center","MX-ONE"],"technologies":[],"categories":["vendor","unified communications","telephony","disaster recovery"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"micollab","term":"MiCollab","expandedName":"Mitel MiCollab","shortDefinition":"Mitel's unified-communications and collaboration platform for supported desktop, mobile, web, telephony, presence, messaging, and conferencing workflows.","fullDefinition":"Mitel's unified-communications and collaboration platform for supported desktop, mobile, web, telephony, presence, messaging, and conferencing workflows.","plainLanguageDefinition":"Mitel's unified-communications and collaboration platform for supported desktop, mobile, web, telephony, presence, messaging, and conferencing workflows.","platforms":["network-appliances","cross-platform"],"aliases":["MiCollab Client","MiCollab Client Service"],"keywords":["Mitel collaboration","MiCollab server","MiCollab desktop client"],"relatedTerms":["Mitel","MiTAI","MBG","AWV"],"articleIds":[60000,60001,60002,60003,60004,60005,60006,60007,60008,60009,60010,60011,60012,60013,60014,60015,60016,60017,60018,60019],"vendors":["Mitel"],"products":["MiCollab Client Service 10.0","MiCollab AWV 9.7"],"technologies":[],"categories":["product","unified communications","collaboration"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"mivoice-business","term":"MiVoice Business","expandedName":"Mitel MiVoice Business","shortDefinition":"Mitel's enterprise communications platform, historically associated with the 3300 ICP controller family.","fullDefinition":"Mitel's enterprise communications platform, historically associated with the 3300 ICP controller family.","plainLanguageDefinition":"Mitel's enterprise communications platform, historically associated with the 3300 ICP controller family.","platforms":["network-appliances"],"aliases":["3300 ICP","MiVoice Business PBX"],"keywords":["Mitel call server","Mitel 3300","MiVoice PBX","invalid service level change"],"relatedTerms":["Mitel","MiCollab","PBX","Maintenance"],"articleIds":[60007,60008,60020,60021,60022,60023,60024],"vendors":["Mitel"],"products":["MiVoice Business 10.0","MiVoice Business"],"technologies":[],"categories":["product","PBX","telephony"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"mivoice-connect","term":"MiVoice Connect","expandedName":"Mitel MiVoice Connect","shortDefinition":"Mitel's communications platform formerly associated with ShoreTel, including Headquarters servers, distributed servers, voice switches, clients, and IP phones.","fullDefinition":"Mitel's communications platform formerly associated with ShoreTel, including Headquarters servers, distributed servers, voice switches, clients, and IP phones.","plainLanguageDefinition":"Mitel's communications platform formerly associated with ShoreTel, including Headquarters servers, distributed servers, voice switches, clients, and IP phones.","platforms":["network-appliances"],"aliases":["ShoreTel Connect","Connect Director"],"keywords":["Mitel Connect","ShoreWare","Mitel voice switch"],"relatedTerms":["Mitel","Headquarters Server","Voice Switch","400-Series IP Phone"],"articleIds":[60025,60026,60027,60028,60029,60030,60031,60032,60033,60034],"vendors":["Mitel"],"products":["MiVoice Connect"],"technologies":[],"categories":["product","PBX","telephony"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"micontact-center","term":"MiContact Center","expandedName":"Mitel MiCC","shortDefinition":"Mitel contact-center software with Windows Server, IIS, SQL Server, IVR, licensing, monitoring, synchronization, and PBX integration dependencies.","fullDefinition":"Mitel contact-center software with Windows Server, IIS, SQL Server, IVR, licensing, monitoring, synchronization, and PBX integration dependencies.","plainLanguageDefinition":"Mitel contact-center software with Windows Server, IIS, SQL Server, IVR, licensing, monitoring, synchronization, and PBX integration dependencies.","platforms":["windows","network-appliances"],"aliases":["MiCC","Contact Center Management","prairieFyre"],"keywords":["MiCC install","MiCC alarm","MiCC Enterprise","MiContact Center Business"],"relatedTerms":["IIS","SQL Server","IVR","MiVoice Connect"],"articleIds":[60100,60101,60102,60103,60104,60105,60106,60107,60108,60109,60110,60111,60112,60113,60114,60115,60124,60125,60126],"vendors":["Mitel"],"products":["MiContact Center Enterprise","MiContact Center Business"],"technologies":[],"categories":["product","contact center","windows server"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"mx-one-snm","term":"MX-ONE Service Node Manager","expandedName":"Mitel MX-ONE SNM","shortDefinition":"The MX-ONE management web application and its PostgreSQL, JBoss, authentication, and IP Phone Software Server dependencies.","fullDefinition":"The MX-ONE management web application and its PostgreSQL, JBoss, authentication, and IP Phone Software Server dependencies.","plainLanguageDefinition":"The MX-ONE management web application and its PostgreSQL, JBoss, authentication, and IP Phone Software Server dependencies.","platforms":["linux","windows","network-appliances"],"aliases":["SNM","Service Node Manager"],"keywords":["MX-ONE login","mecs_last_menu","MX-ONE IPP server"],"relatedTerms":["PostgreSQL","JBoss","Tomcat","IP Phone Software"],"articleIds":[60116,60117,60118,60119,60120,60121,60122,60123],"vendors":["Mitel"],"products":["MX-ONE Service Node Manager","MX-ONE IP Phone Software Server"],"technologies":[],"categories":["product","PBX management","phone provisioning"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"mitel-disaster-recovery","term":"Mitel Disaster Recovery","expandedName":"Mitel swing server recovery","shortDefinition":"Recovery workflows for licensing, database versions, isolated identity cutover, Windows services, VMware network devices, time synchronization, and SQL crash recovery.","fullDefinition":"Recovery workflows for licensing, database versions, isolated identity cutover, Windows services, VMware network devices, time synchronization, and SQL crash recovery.","plainLanguageDefinition":"Recovery workflows for licensing, database versions, isolated identity cutover, Windows services, VMware network devices, time synchronization, and SQL crash recovery.","platforms":["windows","network-appliances"],"aliases":["Mitel rollback","Mitel swing server","Mitel temporary server"],"keywords":["Mitel VMware restore","duplicate ARID","Mitel SQL recovery","ghost NIC"],"relatedTerms":["AMC","ARID","VMware","SQL Server","DNS","NTP"],"articleIds":[60137,60138,60139,60140,60141,60142,60143,60144,60145],"vendors":["Mitel","Broadcom","Microsoft"],"products":["Mitel Windows Server Applications"],"technologies":[],"categories":["disaster recovery","rollback","virtualization"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"mitai","term":"MiTAI","expandedName":"Mitel Telephony Application Interface","shortDefinition":"A Mitel telephony integration interface used by supported applications such as MiCollab for monitoring and call-control services.","fullDefinition":"A Mitel telephony integration interface used by supported applications such as MiCollab for monitoring and call-control services.","plainLanguageDefinition":"A Mitel telephony integration interface used by supported applications such as MiCollab for monitoring and call-control services.","platforms":["network-appliances"],"aliases":["Mitel Telephony API"],"keywords":["MiTAI error","SXERR","device monitor"],"relatedTerms":["Mitel","MiCollab","Call Control"],"articleIds":[60013,60014,60015,60016],"vendors":["Mitel"],"products":[],"technologies":["Telephony API"],"categories":["acronym","api","telephony"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"docker","term":"Docker","expandedName":"Docker container platform","shortDefinition":"A platform for building, distributing, and running container images through Docker Engine, Docker Desktop, registries, and related tooling.","fullDefinition":"A platform for building, distributing, and running container images through Docker Engine, Docker Desktop, registries, and related tooling.","plainLanguageDefinition":"A platform for building, distributing, and running container images through Docker Engine, Docker Desktop, registries, and related tooling.","platforms":["cross-platform"],"aliases":["Docker Engine","Docker Desktop"],"keywords":["container runtime","docker daemon","dockerd"],"relatedTerms":["Container","Image","Docker Compose","BuildKit"],"articleIds":[61000,61001,61002,61003,61004,61005,61006,61007,61008,61009,61010,61011,61012,61013,61014,61015,61016,61017,61018],"vendors":["Docker"],"products":["Docker Engine","Docker Desktop"],"technologies":[],"categories":["product","containers","devops"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"docker-compose","term":"Docker Compose","expandedName":"Compose","shortDefinition":"Docker's declarative model and CLI for defining and operating multi-container applications from Compose files.","fullDefinition":"Docker's declarative model and CLI for defining and operating multi-container applications from Compose files.","plainLanguageDefinition":"Docker's declarative model and CLI for defining and operating multi-container applications from Compose files.","platforms":["cross-platform"],"aliases":["docker compose","compose.yaml"],"keywords":["docker-compose","Compose stack","multi-container application"],"relatedTerms":["Docker","YAML","Healthcheck","depends_on"],"articleIds":[61015,61016,61017,61018],"vendors":["Docker"],"products":["Docker Compose"],"technologies":["Containers","YAML"],"categories":["product","orchestration","devops"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"buildkit","term":"BuildKit","expandedName":"Docker BuildKit","shortDefinition":"Docker's modern build backend for Dockerfile execution, layer caching, build graphs, secrets, and multi-platform image builds.","fullDefinition":"Docker's modern build backend for Dockerfile execution, layer caching, build graphs, secrets, and multi-platform image builds.","plainLanguageDefinition":"Docker's modern build backend for Dockerfile execution, layer caching, build graphs, secrets, and multi-platform image builds.","platforms":["cross-platform"],"aliases":["Docker Buildx"],"keywords":["docker build cache","buildx","Dockerfile builder"],"relatedTerms":["Docker","Dockerfile","Layer Cache","Image"],"articleIds":[61014],"vendors":["Docker"],"products":["Docker BuildKit","Docker Buildx"],"technologies":[],"categories":["product","build system","containers"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"oomkilled","term":"OOMKilled","expandedName":"Container out-of-memory state","shortDefinition":"A container state indicator that records whether an out-of-memory condition caused the container process to be killed; exit 137 alone is not sufficient proof.","fullDefinition":"A container state indicator that records whether an out-of-memory condition caused the container process to be killed; exit 137 alone is not sufficient proof.","plainLanguageDefinition":"A container state indicator that records whether an out-of-memory condition caused the container process to be killed; exit 137 alone is not sufficient proof.","platforms":["cross-platform"],"aliases":["OOM Killed","Out Of Memory Killed"],"keywords":["exit 137","container memory kill","State.OOMKilled"],"relatedTerms":["Docker","SIGKILL","Memory Limit","Kernel OOM"],"articleIds":[61005],"vendors":[],"products":[],"technologies":["Containers","Memory Management"],"categories":["diagnostic state","containers"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"ninjaone","term":"NinjaOne","expandedName":"NinjaOne RMM","shortDefinition":"A cloud IT operations platform for endpoint management, monitoring, automation, patching, backup, ticketing, documentation, remote access, and related MSP workflows.","fullDefinition":"A cloud IT operations platform for endpoint management, monitoring, automation, patching, backup, ticketing, documentation, remote access, and related MSP workflows.","plainLanguageDefinition":"A cloud IT operations platform for endpoint management, monitoring, automation, patching, backup, ticketing, documentation, remote access, and related MSP workflows.","platforms":["cross-platform"],"aliases":["NinjaRMM"],"keywords":["Ninja One","RMM platform","MSP management"],"relatedTerms":["NinjaOne Backup","NinjaOne Ticketing","RMM","Endpoint Management"],"articleIds":[62000,62001,62002,62003,62004,62005,62006,62007,62008,62009,62010,62011,62012,62013,62014,62015,62016,62017,62018,62019,62020,62021,62022,62023,62024,62025,62026,62027,62028,62029,62030,62031],"vendors":["NinjaOne"],"products":["NinjaOne Platform"],"technologies":[],"categories":["vendor","RMM","MSP"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"ninjaone-backup","term":"NinjaOne Backup","expandedName":"NinjaOne Device Backup","shortDefinition":"NinjaOne's endpoint backup service for supported file/folder, image, local, network-storage, cloud, integrity-check, and recovery workflows.","fullDefinition":"NinjaOne's endpoint backup service for supported file/folder, image, local, network-storage, cloud, integrity-check, and recovery workflows.","plainLanguageDefinition":"NinjaOne's endpoint backup service for supported file/folder, image, local, network-storage, cloud, integrity-check, and recovery workflows.","platforms":["cross-platform"],"aliases":["NinjaOne Device Backup"],"keywords":["Ninja backup agent","NinjaRMM backup","Ninja backup error"],"relatedTerms":["NinjaOne","VSS","NAS","Repository","Integrity Check"],"articleIds":[62000,62001,62002,62003,62004,62005,62006,62007,62008,62009,62010,62011,62012,62013,62014,62015,62016,62017,62018,62019,62020,62021,62022,62023,62024,62025,62026,62027,62028,62029,62030],"vendors":["NinjaOne"],"products":["NinjaOne Device Backup"],"technologies":[],"categories":["product","backup","data protection"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"ninjaone-ticketing","term":"NinjaOne Ticketing","expandedName":"NinjaOne ticketing system","shortDefinition":"NinjaOne's ticket-management capability for technician and end-user requests, email ingestion and notifications, workflow, and PSA operations.","fullDefinition":"NinjaOne's ticket-management capability for technician and end-user requests, email ingestion and notifications, workflow, and PSA operations.","plainLanguageDefinition":"NinjaOne's ticket-management capability for technician and end-user requests, email ingestion and notifications, workflow, and PSA operations.","platforms":["platform-neutral"],"aliases":["Ninja Ticketing"],"keywords":["NinjaOne SMTP","NinjaOne tickets","Ninja PSA"],"relatedTerms":["NinjaOne","SMTP","Exchange Online","PSA"],"articleIds":[62031],"vendors":["NinjaOne"],"products":["NinjaOne Ticketing"],"technologies":[],"categories":["product","ticketing","PSA"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"efs","term":"EFS","expandedName":"Encrypting File System","shortDefinition":"Windows file-level encryption that binds access to encryption certificates and keys; service accounts may be unable to read protected data even when ordinary ACLs appear sufficient.","fullDefinition":"Windows file-level encryption that binds access to encryption certificates and keys; service accounts may be unable to read protected data even when ordinary ACLs appear sufficient.","plainLanguageDefinition":"Windows file-level encryption that binds access to encryption certificates and keys; service accounts may be unable to read protected data even when ordinary ACLs appear sufficient.","platforms":["windows"],"aliases":["Encrypting File System"],"keywords":["encrypted file access","EFS certificate","cipher.exe"],"relatedTerms":["Windows","NTFS","Certificate","Recovery Agent"],"articleIds":[62000],"vendors":["Microsoft"],"products":[],"technologies":["Windows Security","Encryption"],"categories":["acronym","windows","security"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"microsoft-intune","term":"Microsoft Intune","expandedName":"Microsoft cloud endpoint management","shortDefinition":"Microsoft's cloud service for managing device enrollment, configuration, compliance, applications, and endpoint security.","fullDefinition":"Microsoft's cloud service for managing device enrollment, configuration, compliance, applications, and endpoint security.","plainLanguageDefinition":"Microsoft's cloud service for managing device enrollment, configuration, compliance, applications, and endpoint security.","platforms":["platform-neutral"],"aliases":["Intune","Microsoft Endpoint Manager","MEM"],"keywords":["device management","endpoint management","Intune admin center"],"relatedTerms":["MDM","Company Portal","Entra ID"],"articleIds":[],"vendors":["microsoft"],"products":["Microsoft Intune"],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"microsoft-access","term":"Microsoft Access","expandedName":"Microsoft database application","shortDefinition":"Microsoft's desktop relational-database application, including forms, reports, queries, VBA automation, and integrations with database engines and external data sources.","fullDefinition":"Microsoft's desktop relational-database application, including forms, reports, queries, VBA automation, and integrations with database engines and external data sources.","plainLanguageDefinition":"Microsoft's desktop relational-database application, including forms, reports, queries, VBA automation, and integrations with database engines and external data sources.","platforms":["windows"],"aliases":["MS Access","MSACCESS"],"keywords":["Access database","ACCDB","MDB","Access error"],"relatedTerms":["Jet","ACE","VBA","DAO"],"articleIds":[64000,64001,64002,64003,64004,64005,64006,64007,64008,64009,64010,64011,64012,64013,64014,64015,64016,64017,64018,64019,64020,64021,64022,64023,64024,64025,64026,64027,64028,64029,64030,64031,64032,64033,64034,64035,64036,64037,64038,64039,64040,64041,64042,64043,64044,64045,64046,64047,64048,64049,64050,64051,64052,64053,64054,64055,64056,64057,64058,64059,64060,64061,64062,64063,64064,64065,64066,64067,64068,64069,64070,64071,64072,64073,64074,64075,64076,64077,64078,64079,64080,64081,64082,64083,64084,64085,64086,64087,64088,64089,64090,64091,64092,64093,64094,64095,64096,64097,64098,64099,64100,64101,64102,64103,64104,64105,64106,64107,64108,64109,64110,64111,64112,64113,64114,64115,64116,64117,64118,64119,64120,64121,64122,64123,64124,64125,64126,64127,64128,64129,64130,64131,64132,64133,64134,64135,64136,64137,64138,64139,64140,64141,64142,64143,64144,64145,64146,64147,64148,64149,64150,64151,64152,64153,64154,64155,64156,64157,64158,64159,64160,64161,64162,64163,64164,64165,64166,64167,64168,64169,64170,64171,64172,64173,64174,64175,64176,64177,64178,64179,64180,64181,64182,64183,64184,64185,64186,64187,64188,64189,64190,64191,64192,64193,64194,64195,64196,64197,64198,64199,64200,64201,64202,64203,64204,64205,64206,64207,64208,64209,64210,64211,64212,64213,64214,64215,64216,64217,64218,64219,64220,64221,64222,64223,64224,64225,64226,64227,64228,64229,64230,64231,64232,64233,64234,64235,64236,64237,64238,64239,64240,64241,64242,64243,64244,64245,64246,64247,64248,64249,64250,64251,64252,64253,64254,64255,64256,64257,64258,64259,64260,64261,64262,64263,64264,64265,64266,64267,64268,64269,64270,64271,64272,64273,64274,64275,64276,64277,64278,64279,64280,64281,64282,64283,64284,64285,64286,64287,64288,64289,64290,64291,64292,64293,64294,64295,64296,64297,64298,64299,64300,64301,64302,64303,64304,64305,64306,64307,64308,64309,64310,64311,64312,64313,64314,64315,64316,64317,64318,64319,64320,64321,64322,64323,64324,64325,64326,64327,64328,64329,64330,64331,64332,64333,64334,64335,64336,64337,64338,64339,64340,64341,64342,64343,64344,64345,64346,64347,64348,64349,64350,64351,64352,64353,64354,64355,64356,64357,64358,64359,64360,64361,64362,64363,64364,64365,64366,64367,64368,64369,64370,64371,64372,64373,64374,64375,64376,64377,64378,64379,64380,64381,64382,64383,64384,64385,64386,64387,64388,64389,64390,64391,64392,64393,64394,64395,64396,64397,64398,64399,64400,64401,64402,64403,64404,64405,64406,64407,64408,64409,64410,64411,64412,64413,64414,64415,64416,64417,64418,64419,64420,64421,64422,64423,64424,64425,64426,64427,64428,64429,64430,64431,64432,64433,64434,64435,64436,64437,64438,64439,64440,64441,64442,64443,64444,64445,64446,64447,64448,64449,64450,64451,64452,64453,64454,64455,64456,64457,64458,64459,64460,64461,64462,64463,64464,64465,64466,64467,64468,64469,64470,64471,64472,64473,64474,64475,64476,64477,64478,64479,64480,64481,64482,64483,64484,64485,64486,64487,64488,64489,64490,64491,64492,64493,64494,64495,64496,64497,64498,64499,64500,64501,64502,64503,64504,64505,64506,64507,64508,64509,64510,64511,64512,64513,64514,64515,64516,64517,64518,64519,64520,64521,64522,64523,64524,64525,64526,64527,64528,64529,64530,64531,64532,64533,64534,64535,64536,64537,64538,64539,64540,64541,64542,64543,64544,64545,64546,64547,64548,64549,64550,64551,64552,64553,64554,64555,64556,64557,64558,64559,64560,64561,64562,64563,64564,64565,64566,64567,64568,64569,64570,64571,64572,64573,64574,64575,64576,64577,64578,64579,64580,64581,64582,64583,64584,64585,64586,64587,64588,64589,64590,64591,64592,64593,64594,64595,64596,64597,64598,64599,64600,64601,64602,64603,64604,64605,64606,64607,64608,64609,64610,64611,64612,64613,64614,64615,64616,64617,64618,64619,64620,64621,64622,64623,64624,64625,64626,64627,64628,64629,64630,64631,64632,64633,64634,64635,64636,64637,64638,64639,64640,64641,64642,64643,64644,64645,64646,64647,64648,64649,64650,64651,64652,64653,64654,64655,64656,64657,64658,64659,64660,64661,64662,64663,64664,64665,64666,64667,64668,64669,64670,64671,64672,64673,64674,64675,64676,64677,64678,64679,64680,64681,64682,64683,64684,64685,64686,64687,64688,64689,64690,64691,64692,64693,64694,64695,64696,64697,64698,64699,64700,64701,64702,64703,64704,64705,64706,64707,64708,64709,64710,64711,64712,64713,64714,64715,64716,64717],"vendors":["microsoft"],"products":["Microsoft Access"],"technologies":[],"categories":["product","database","legacy"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"jet","term":"Jet","expandedName":"Microsoft Jet Database Engine","shortDefinition":"The legacy database engine used by classic Microsoft Access and other Windows data-access applications.","fullDefinition":"The legacy database engine used by classic Microsoft Access and other Windows data-access applications.","plainLanguageDefinition":"The legacy database engine used by classic Microsoft Access and other Windows data-access applications.","platforms":["windows"],"aliases":["Microsoft Jet","Jet Database Engine","JET"],"keywords":["MDB","database engine","Jet error"],"relatedTerms":["Microsoft Access","DAO","ISAM","ODBC"],"articleIds":[64000,64001,64002,64003,64004,64005,64006,64007,64008,64009,64010,64011,64012,64013,64014,64015,64016,64017,64018,64019,64020,64021,64022,64023,64024,64025,64026,64027,64028,64029,64030,64031,64032,64033,64034,64035,64036,64037,64038,64039,64040,64041,64042,64043,64044,64045,64046,64047,64048,64049,64050,64051,64052,64053,64054,64055,64056,64057,64058,64059,64060,64061,64062,64063,64064,64065,64066,64067,64068,64069,64070,64071,64072,64073,64074,64075,64076,64077,64078,64079,64080,64081,64082,64083,64084,64085,64086,64087,64088,64089,64090,64091,64092,64093,64094,64095,64096,64097,64098,64099,64100,64101,64102,64103,64104,64105,64106,64107,64108,64109,64110,64111,64112,64113,64114,64115,64116,64117,64118,64119,64120,64121,64122,64123,64124,64125,64126,64127,64128,64129,64130,64131,64132,64133,64134,64135,64136,64137,64138,64139,64140,64141,64142,64143,64144,64145,64146,64147,64148,64149,64150,64151,64152,64153,64154,64155,64156,64157,64158,64159,64160,64161,64162,64163,64164,64165,64166,64167,64168,64169,64170,64171,64172,64173,64174,64175,64176,64177,64178,64179,64180,64181,64182,64183,64184,64185,64186,64187,64188,64189,64190,64191,64192,64193,64194,64195,64196,64197,64198,64199,64200,64201,64202,64203,64204,64205,64206,64207,64208,64209,64210,64211,64212,64213,64214,64215,64216,64217,64218,64219,64220,64221,64222,64223,64224,64225,64226,64227,64228,64229,64230,64231,64232,64233,64234,64235,64236,64237,64238,64239,64240,64241,64242,64243,64244,64245,64246,64247,64248,64249,64250,64251,64252,64253,64254,64255,64256,64257,64258,64259,64260,64261,64262,64263,64264,64265,64266,64267,64268,64269,64270,64271,64272,64273,64274,64275,64276,64277,64278,64279,64280,64281,64282,64283,64284,64285,64286,64287,64288,64289,64290,64291,64292,64293,64294,64295,64296,64297,64298,64299,64300,64301,64302,64303,64304,64305,64306,64307,64308,64309,64310,64311,64312,64313,64314,64315,64316,64317,64318,64319,64320,64321,64322,64323,64324,64325,64326,64327,64328,64329,64330,64331,64332,64333,64334,64335,64336,64337,64338,64339,64340,64341,64342,64343,64344,64345,64346,64347,64348,64349,64350,64351,64352,64353,64354,64355,64356,64357,64358,64359,64360,64361,64362,64363,64364,64365,64366,64367,64368,64369,64370,64371,64372,64373,64374,64375,64376,64377,64378,64379,64380,64381,64382,64383,64384,64385,64386,64387,64388,64389,64390,64391,64392,64393,64394,64395,64396,64397,64398,64399,64400,64401,64402,64403,64404,64405,64406,64407,64408,64409,64410,64411,64412,64413,64414,64415,64416,64417,64418,64419,64420,64421,64422,64423,64424,64425,64426,64427,64428,64429,64430,64431,64432,64433,64434,64435,64436,64437,64438,64439,64440,64441,64442,64443,64444,64445,64446,64447,64448,64449,64450,64451,64452,64453,64454,64455,64456,64457,64458,64459,64460,64461,64462,64463,64464,64465,64466,64467,64468,64469,64470,64471,64472,64473,64474,64475,64476,64477,64478,64479,64480,64481,64482,64483,64484,64485,64486,64487,64488,64489,64490,64491,64492,64493,64494,64495,64496,64497,64498,64499,64500,64501,64502,64503,64504,64505,64506,64507,64508,64509,64510,64511,64512,64513,64514,64515,64516,64517,64518,64519,64520,64521,64522,64523,64524,64525,64526,64527,64528,64529,64530,64531,64532,64533,64534,64535,64536,64537,64538,64539,64540,64541,64542,64543,64544,64545,64546,64547,64548,64549,64550,64551,64552,64553,64554,64555,64556,64557,64558,64559,64560,64561,64562,64563,64564,64565,64566,64567,64568,64569,64570,64571,64572,64573,64574,64575,64576,64577,64578,64579,64580,64581,64582,64583,64584,64585,64586,64587,64588,64589,64590,64591,64592,64593,64594,64595,64596,64597,64598,64599,64600,64601,64602,64603,64604,64605,64606,64607,64608,64609,64610,64611,64612,64613,64614,64615,64616,64617,64618,64619,64620,64621,64622,64623,64624,64625,64626,64627,64628,64629,64630,64631,64632,64633,64634,64635,64636,64637,64638,64639,64640,64641,64642,64643,64644,64645,64646,64647,64648,64649,64650,64651,64652,64653,64654,64655,64656,64657,64658,64659,64660,64661,64662,64663,64664,64665,64666,64667,64668,64669,64670,64671,64672,64673,64674,64675,64676,64677,64678,64679,64680,64681,64682,64683,64684,64685,64686,64687,64688,64689,64690,64691,64692,64693,64694,64695,64696,64697,64698,64699,64700,64701,64702,64703,64704,64705,64706,64707,64708,64709,64710,64711,64712,64713,64714,64715,64716,64717],"vendors":["microsoft"],"products":["Jet Database Engine"],"technologies":[],"categories":["database engine","legacy"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"dao","term":"DAO","expandedName":"Data Access Objects","shortDefinition":"A Microsoft programming interface historically used by Access and VBA to work with Jet databases, tables, queries, records, and workspaces.","fullDefinition":"A Microsoft programming interface historically used by Access and VBA to work with Jet databases, tables, queries, records, and workspaces.","plainLanguageDefinition":"A Microsoft programming interface historically used by Access and VBA to work with Jet databases, tables, queries, records, and workspaces.","platforms":["windows"],"aliases":["Data Access Objects","Microsoft DAO"],"keywords":["Recordset","Database object","Workspace"],"relatedTerms":["Microsoft Access","Jet","VBA"],"articleIds":[],"vendors":["microsoft"],"products":["Microsoft Access","Jet Database Engine"],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"company-portal","term":"Company Portal","expandedName":"Microsoft Intune Company Portal","shortDefinition":"The Microsoft application and service experience users use to register devices, install assigned applications, and view management or compliance status.","fullDefinition":"The Microsoft application and service experience users use to register devices, install assigned applications, and view management or compliance status.","plainLanguageDefinition":"The Microsoft application and service experience users use to register devices, install assigned applications, and view management or compliance status.","platforms":["windows","macos","linux"],"aliases":["Intune Company Portal"],"keywords":["enroll device","managed apps","compliance"],"relatedTerms":["Microsoft Intune","MDM","Entra ID"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"windows-autopilot","term":"Windows Autopilot","expandedName":"Microsoft Windows Autopilot","shortDefinition":"Microsoft's cloud-assisted deployment process for registering, configuring, and provisioning Windows devices for organizational use.","fullDefinition":"Microsoft's cloud-assisted deployment process for registering, configuring, and provisioning Windows devices for organizational use.","plainLanguageDefinition":"Microsoft's cloud-assisted deployment process for registering, configuring, and provisioning Windows devices for organizational use.","platforms":["windows"],"aliases":["Autopilot","Windows Autopilot Deployment"],"keywords":["OOBE","hardware hash","enrollment status page"],"relatedTerms":["Microsoft Intune","Entra Join","ESP"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"dsregcmd","term":"dsregcmd","expandedName":"Device Registration Command","shortDefinition":"A built-in Windows command used to inspect Microsoft Entra join, workplace registration, device authentication, tenant, PRT, and Windows Hello state.","fullDefinition":"A built-in Windows command used to inspect Microsoft Entra join, workplace registration, device authentication, tenant, PRT, and Windows Hello state.","plainLanguageDefinition":"A built-in Windows command used to inspect Microsoft Entra join, workplace registration, device authentication, tenant, PRT, and Windows Hello state.","platforms":["windows"],"aliases":["dsregcmd /status"],"keywords":["AzureAdJoined","DeviceAuthStatus","AzureAdPrt"],"relatedTerms":["Entra ID","Microsoft Intune","Device Registration"],"articleIds":[],"vendors":["microsoft"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"packet","term":"Packet","expandedName":"Network packet","shortDefinition":"A formatted unit of network-layer data carried through a network and encapsulated within link-layer frames.","fullDefinition":"A formatted unit of network-layer data carried through a network and encapsulated within link-layer frames.","plainLanguageDefinition":"A formatted unit of network-layer data carried through a network and encapsulated within link-layer frames.","platforms":["platform-neutral"],"aliases":["Network Packet"],"keywords":["packet capture","payload","header"],"relatedTerms":["Frame","PCAP","TCP"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"latency","term":"Latency","expandedName":"Network latency","shortDefinition":"The time required for data or a response to travel between endpoints, commonly measured as round-trip time.","fullDefinition":"The time required for data or a response to travel between endpoints, commonly measured as round-trip time.","plainLanguageDefinition":"The time required for data or a response to travel between endpoints, commonly measured as round-trip time.","platforms":["platform-neutral"],"aliases":["Round-Trip Time"],"keywords":["RTT","delay","slow network"],"relatedTerms":["Jitter","Packet Loss","Bandwidth"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"bandwidth","term":"Bandwidth","expandedName":"Network bandwidth","shortDefinition":"The theoretical or provisioned data-carrying capacity of a network path, distinct from measured throughput.","fullDefinition":"The theoretical or provisioned data-carrying capacity of a network path, distinct from measured throughput.","plainLanguageDefinition":"The theoretical or provisioned data-carrying capacity of a network path, distinct from measured throughput.","platforms":["platform-neutral"],"aliases":["Network Bandwidth"],"keywords":["link speed","capacity","throughput"],"relatedTerms":["Throughput","Duplex","Latency"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"smb","term":"SMB","expandedName":"Server Message Block","shortDefinition":"A network protocol used for shared files, printers, named pipes, and related Windows-oriented services.","fullDefinition":"A network protocol used for shared files, printers, named pipes, and related Windows-oriented services.","plainLanguageDefinition":"A network protocol used for shared files, printers, named pipes, and related Windows-oriented services.","platforms":["platform-neutral"],"aliases":["Server Message Block"],"keywords":["file share","port 445","UNC path"],"relatedTerms":["CIFS","NetBIOS","Kerberos"],"articleIds":[],"vendors":[],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"trs-80-color-computer","term":"TRS-80 Color Computer","expandedName":"Radio Shack TRS-80 Color Computer","shortDefinition":"An 8-bit Radio Shack home computer commonly called the Color Computer or CoCo.","fullDefinition":"An 8-bit Radio Shack home computer commonly called the Color Computer or CoCo.","plainLanguageDefinition":"An 8-bit Radio Shack home computer commonly called the Color Computer or CoCo.","platforms":["trs80"],"aliases":["TRS-80 CoCo","Color Computer","CoCo"],"keywords":["Radio Shack","Tandy","6809","vintage computer"],"relatedTerms":["Color BASIC","Cassette Storage"],"articleIds":[52500,52600],"vendors":["Radio Shack","Tandy"],"products":["TRS-80 Color Computer"],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"color-basic","term":"Color BASIC","expandedName":"TRS-80 Color Computer BASIC","shortDefinition":"The Microsoft-derived BASIC interpreter built into the original TRS-80 Color Computer.","fullDefinition":"The Microsoft-derived BASIC interpreter built into the original TRS-80 Color Computer.","plainLanguageDefinition":"The Microsoft-derived BASIC interpreter built into the original TRS-80 Color Computer.","platforms":["trs80"],"aliases":["Color Computer BASIC"],"keywords":["BASIC commands","two-character errors","1981"],"relatedTerms":["TRS-80 Color Computer","Color BASIC Error"],"articleIds":[52500,52600],"vendors":["Radio Shack"],"products":["Color BASIC"],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"color-basic-error","term":"Color BASIC Error","expandedName":"TRS-80 Color BASIC two-character error","shortDefinition":"A compact error identifier such as SN, FC, IO, or TM displayed by Color BASIC, optionally with a program line number.","fullDefinition":"A compact error identifier such as SN, FC, IO, or TM displayed by Color BASIC, optionally with a program line number.","plainLanguageDefinition":"A compact error identifier such as SN, FC, IO, or TM displayed by Color BASIC, optionally with a program line number.","platforms":["trs80"],"aliases":["CoCo error","two-character BASIC error"],"keywords":["SN ERROR","FC ERROR","IO ERROR","TM ERROR"],"relatedTerms":["Color BASIC","TRS-80 Color Computer"],"articleIds":[52500,52507,52512,52523],"vendors":["Radio Shack"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"trs-80-cassette","term":"TRS-80 Cassette Storage","expandedName":"Color Computer cassette program and data storage","shortDefinition":"The Color Computer's tape-based storage workflow used by commands such as CLOAD, CSAVE, and SKIPF.","fullDefinition":"The Color Computer's tape-based storage workflow used by commands such as CLOAD, CSAVE, and SKIPF.","plainLanguageDefinition":"The Color Computer's tape-based storage workflow used by commands such as CLOAD, CSAVE, and SKIPF.","platforms":["trs80"],"aliases":["CoCo cassette","CLOAD","CSAVE","SKIPF"],"keywords":["cassette recorder","tape program","IO error"],"relatedTerms":["Color BASIC","Input/Output"],"articleIds":[52512,52600,52602,52626],"vendors":["Radio Shack"],"products":[],"technologies":[],"categories":[],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""},{"id":"cross-cloud-b2b","term":"Cross-cloud B2B","expandedName":"Microsoft Entra cross-cloud B2B collaboration","shortDefinition":"Microsoft Entra collaboration between tenants in different Microsoft cloud environments, such as the worldwide commercial cloud and Azure Government.","fullDefinition":"Microsoft Entra collaboration between tenants in different Microsoft cloud environments, such as the worldwide commercial cloud and Azure Government.","plainLanguageDefinition":"Microsoft Entra collaboration between tenants in different Microsoft cloud environments, such as the worldwide commercial cloud and Azure Government.","platforms":["platform-neutral"],"aliases":["Cross-cloud collaboration","Cross-cloud access","Sovereign cloud B2B"],"keywords":["AADSTS1000104","microsoftonline.us","XCB2BResourceCloudNotAllowedOnIdentityTenant"],"relatedTerms":["Cross-tenant Access","Azure Government","GCC High","B2B Collaboration"],"articleIds":[67000],"vendors":["microsoft"],"products":["Microsoft Entra External ID"],"technologies":[],"categories":["identity","authentication","cloud"],"relatedErrorCodes":[],"commands":[],"source":"CopyCat curated technical index","reviewStatus":"verified","lastVerified":""}]}
